hmmm something went wrong when I posted... Oh well, here goes again. So I got a win2k server set up on the internet as a mail server and it patches itself about once a week (ms patches). The other day I notice the traffic has just about doubled. I did a netstat -a to see connections and I see a connection originating from my machine (port 1039 standard, I know) to port 6667 on someone's IP address. So I ran a full scan with NAV and found nothing, then I went and downloaded the cleaner by moosoft and ran that and it picked up nothing. The Cleaner also comes with a component that maps processes to ports and the one above didn't even show up. Then I checked the run keys in the registry and didn't find anything suspicious looking. Anybody have any idea what's goin on I know IRC listens on port 6667 and I saw some stuff on google about people using 6667 for DoS attacks, but I checked a few and looked for the files they said were found on the attacking machines. Alas I found nothing.

Thanks for your help
Greg