STORE.EXE is sourcing erroneous packets to address 192.168.1.xxx:xxx once every minute. Verified this with TDIMON.EXE packet capture. The packet contains nothing past the TCP level. What Exchange 5.5 tracing/logging can implemented to determine which process/person/mailbox/public folder may be sourcing this packet? It's not a SMTP or MAPI packet mind you. Thanks in advance.