Just as an FYI, if you are fully patched against Code Red (v1) on your IIS server, you won't be infected by the subsequent Versions. The new Versions have changed the signature (so an intrusion detection system "IDS" won't see it via the same ruleset that spotted the original) and one of them now installs a back door on your machine. You can get specific details at
www.sans.org.
Thus, if Code Red didn't kill shrapnel's server, Code Red II and III won't either.
Richard, good job applying the patch before you got nailed, even if the cure still caused pain.
Col. John