I know that we're not supposed to post messages about viruses but this one sounds especially evil becuase it can attack without using an attachment and has already been discovered on some Rootsweb lists for England. Warnings and cures have been circulating on the FreeBMD site today and I include them below. Karen Hutten -------------------------------------------------------------------------------- I suspect Andrew may be along shortly to tell me off for posting virus warnings here, but this relates to a virus that does exist of some Transcribers machines, and which is being sent out in response to FreeBMD mailing list messages (I've had it arrive 3 times this morning). It cannot spread directly via the list, but you may get it as a response to list messages. This isn't a warning that claims to come from Microsoft or AOL etc. This is me telling you that the virus is out there and spreading by stealth. Description; + You will receive a reply to an e-mail that you sent (possibly to a mailing list) + The reply will quote part of your e-mail, using "-" as a quoting character instead of the more usual ">" and will have "====" on the second line + The last line of the quoted text will be truncated and end in ...' + The text "> Take a look to the attachment" will appear + A file, either news_doc.scr or New_Napster_Site.DOC.scr will be attached. How it works; .scr files are screensavers, which are really .exe files. The "doc" is really a program that once run (or previewed) in outlook express starts sending replies to messages in your inbox, spreading itself. What to do about it; I have no idea how to get rid of the virus, but if anybody has the removal instructions please post them here. The important advice is that if you get such an e-mail (or indeed any e-mail with an attachment that has a .scr extension) DELETE IT. Don't open it or preview it. AFAIK only MS Outlook Express is affected, but I could be wrong. Be very careful, this is a very cleverly designed virus intended to catch you off guard. -- Dave Mayall -------------------------------------------------------------------------------- On Fri, 20 Apr 2001 10:48:11 +0100, you wrote: >Dave, > >The repair/clean up tool is available at >http://www.symantec.com/avcenter/venc/data/[email protected] > Having just checked, it is actually a different worm; http://www.symantec.com/avcenter/venc/data/[email protected] -- Dave Mayall ==== FreeBMD-Admins Mailing List ==== Want to help FreeBMD? Go to http://freebmd.rootsweb.com/Signup.html to find out how.