> That usually means the client has just dropped the connection. > > If you do a tcpdump you'll probably see a TCP RST or FIN packet > coming from the client. > > I don't know why the clients are doing this. Being paranoid, do you think windows looks for ways to mess around with samba? I haven't forgotten DrDOS. Joel