I just received this information concerning the virus. rootsweb : "I'm sorry, but there is nothing you or we can do. The infected computer may have been subscribed to the list at one time and the virus happened to select that address to spoof/forge as the sender. Today's virii are so adept at forging headers that it is usually very difficult if not impossible to determine the actual sender." Pat at rootsweb also said If the full headers indicate the originating ISP, they can forward the message, including the full headers to abuse@the_isp.com. If sent soon enough, they can identify the actual sender from the Message-ID: However, most ISPs keep their logs for only 24-48 hours. Once the logs have been erased, they will not be able to identify the sender. which I suggest Ginny should do . Ginny from our list sent this : Betty.......I just received a message from the [ILHENRY] list and I do not belong to it. My ISP has a filter called Postini and it sent me a message that this was a virus and that they had contained it and I could read the message if I went to their website, which I did. Was surprised to find it from a list I had nothing to do with and wondered how it got to me. I did check who the message had originated from and it was dickmatt@yahoo.com . Perhaps you should alert the other list. ginny Do NOT, I REPEAT DO NOT OPEN ANY MAIL THAT YOU DO NOT KNOW WHO IT IS FROM EVEN IF YOU DO KNOW WHO IT IS FROM DO NOT OPEN ANY ATTACHMENTS OF ANY KIND UNLESS YOU HAVE AN UPDATED VIRUSES DETECTOR. THEN BE CAREFUL . DO NOT OPEN ANYTHING SENT FROM THIS HENRY ILL. LIST OR THE ONE IN KS . I AM POSITIVE THIS FELLOW HAS NO IDEA HE IS SENDING OUT ANYTHING. Thanks and please do be careful -- now is a great time to run back up on any of your genealogy information or other information on your computer. thanks and I am positive we will make it through this and survive just fine:-) betty