Wanted to pass this on for anyone who hasn't heard. From: [email protected] (Steve Saviello) Listowner of [email protected] (Italian Genealogy and Culture) Hi Folks! This is REAL!!! Heads up............. W32/Pretty.Park Aliases: Pretty Worm Ici pour French Translation Virus Characteristics: This is a worm that infects Windows 9x/NT files. Virus Information: This program, when run, will copy itself to FILES32.VXD in WINDOWS\SYSTEM folder. It then changes the registry key HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell\open\command and uses the VXD via the shell to run any exe file. It has been reported that the program sends email to everyone in the users address book. When it does it has also been reported that the file is sent as well. This behavior has not been duplicated by AVERT. Discovery: May 26, 1999 DAT Included: 4029 Type: Worm Risk Assessment: Low If you need to remove this worm, go to: http://www.avertlabs.com/public/datafiles/valerts/vinfo/va10184.asp and download the small file. It is a (1K) zip file. Thanks to Mike Mangeruca for bringing this to COI's attention.