We have a 2003AD environment with mixed W2K and WXP Pro machines. All laptops run BlackICE firewall (in addition to our firewall device). My BlackICE is showing hundreds of hits from another user today with event "UDP_Probe_Other". The "intruder" is the user's AD name "JoeSmith.domain.com". I looked at the machine in question - got rid of negligible spyware (mainly cookies), ran clean antivirus, didn't see any questional services or processes, disabled AEGIS protocol and IEEE. The LAN firewall shows nothing unusual. Nothing looks out of the ordinary yet for some reason her machine is bombarding me, and maybe others, with this "UDP_Probe_Other" traffic. Anyone have any ideas? Thanks.