Hi, A particular machine in my LAN is affected by SoBig virus and is sending mails to remote sites. I need to find that IP. The only lead I have is that it is that IP which is generating maximum SMTP traffic. How do I find it out and block it (or maybe clean it)? Any ideas on this? With warm regards, -Payal -- "Visit GNU/Linux Success Stories" http://payal.staticky.com Guest-Book Section Updated.