This is information about this nasty virus, from the Symantec Site....you can go there to obtain instruction for removal from your system.... THIS IS WHAT IS POSTED THERE: Symantec AntiVirus Research Center (SARC) http://www.symantec.com/avcenter W32.Badtrans.13312@mm Discovered on: April 11, 2001 Last Updated on: May 8, 2001 at 08:39:43 AM PDT Due to an increase in the number of submissions, W32.Badtrans.13312@mm has been upgraded to a Category 4 threat. It is a MAPI worm that replies to all unread mails in your email message folders, and drops a backdoor Trojan. Also Known As: W32/Badtrans-A, W32/Badtrans@MM, BadTrans, IWorm_Badtrans, I-Worm.Badtrans, TROJ_BADTRANS.A Category: Worm Infection Length: 13312 Virus Definitions: April 11, 2001 Threat Assessment: Wild: High Damage: Medium Distribution: High Wild: Number of infections: 50 - 999 Number of sites: More than 10 Geographical distribution: High Threat containment: Easy Removal: Easy Damage: Payload: Large scale e-mailing: It replies to all unread messages in the message folders within the default MAPI email program. Compromises security settings: It drops a backdoor Trojan. Technical description: When the worm is executed, it drops the backdoor Trojan Hkk32.exe in the \Windows folder, and then executes it. It then copies itself into the Windows folder as inetd.exe, adds a run= line to the Win.ini, and displays the following message: The next time that the computer is rebooted, the worm will wait for 5 minutes, then it will use MAPI to find all unread email messages and reply to all of them. The worm will attach itself to the email, using one of the following file names: Pics.ZIP.scr images.pif README.TXT.pif New_Napster_Site.DOC.scr news_doc.scr hamster.ZIP.scr YOU_are_FAT!.TXT.pif searchURL.scr SETUP.pif Card.pif Me_nude.AVI.pif Sorry_about_yesterday.DOC.pif s3msong.MP3.pif docs.scr Humor.TXT.pif fun.pif Removal instructions: YOU CAN GO TO THE SYMANTEC WEB-SITE FOR INSTRUCTIONS. NANC .... ^--^ ..... NANCY in CA. nwalchli@earthlink.net