It seems our connection is back up. If anyone would like me to post logs somewhere so they can peruse them, I will. Just name what you would like to see. I think the more people that look at what happened would do me good. I, and others, can possibly learn a lot.

If anyone is interested, the infected machine is photo-documented in the link below. In contrast, the backup server I built is a K6-200 with 64MB of RAM and a 10GB IDE hard drive. It is still running RH 7.1 since I know all the gotcha's (pop3 daemon in the IMAP package. Yeah, that makes sense).

http://spmicro.com/gallery/tslightserver
_________________________
-Rob Riccardelli
80GB 16MB MK2 090000736