Where is your access-list is the entry for www? Try re-writing your access-list and putting it at the very top to ensure you are not stepping on your own toes (the rule of thumb I have always heard is specific to general...)
Secondly, take a look at using 'ip accounting access-violations' and 'show ip accounting access-violations' to give you an idea of if anything is making it to your list and where it is being denied.
You can also turn on logging (either console - although its sometimes tricky that way -- or to a syslog server) and that will give you the packets as they are being denied. You will need to turn on 'debug ip access-list detail' and/or 'debug ip access-list lookup' (I can't remember which...).
Hope this helps a bit,
Paul Kincaid
P.S. wybnormal -- f.y.i. 100 is within the extended list.