Send this info back out to your list - someone on it is no doubt the source of these recurring "Snow White" mailings. Obviously someone with both you and Hans in their Windows address book, so the list seems like high odds. Perhaps a lurker? You might verify with other list members that they've seen this virus before - you know we have! I will send mail to the ISP, just in case they care... Anyway, here's my analysis of the IP address where the message came from... ayers (ppp059-pm-p7.tcsn.net [ 207.114.212.59 ]) The name "ayers" is assigned at the PC by the user and is TOTALLY arbitrary. The host portion of the IP (ppp059-pm-p7) probably indicates a dial-in user. The domain portion of the IP (tcsn.net) indicates the service provider (ISP). Domain Name: TCSN.NET Administrative Contact, Billing Contact: Fitton, Arnie (AF455) [log in to unmask] The Computer Shop Netlink 1306 Pine St Paso Robles, CA 93446 805-227-7000 Technical Contact: Domain Administration (DA2570-ORG) [log in to unmask] TCSN 1306 Pine Street Paso Robles, CA 93446 US 805-227-7000 Fax- 805-237-0951 Record last updated on 03-Nov-1997. Record expires on 11-Apr-2001. Record created on 10-Apr-1996. Database last updated on 15-Mar-2001 07:39:43 EST. Domain servers in listed order: DNS1.TCSN.NET 206.190.91.1 DNS2.TCSN.NET 206.190.91.2 The host was not on-line (or at least not responding to ping) when I gathered this info, so I was unable to scan it to determine more info. Good luck, guys - we'll all be happy if the source of this virus is found & fixed. (B.) ---------- Bradley D. Moore ~ [log in to unmask] Senior Network Engineer ~ 317-577-1460 Black Box Network Services of Indiana ~ http://www.netuci.com/ Paul E. Ayers Sales Manager Black Box Network Services Indiana Operations 317.577.1460 [log in to unmask] www.blackbox.com ---------------------------------------------------------------------- To sign-off Parkinsn send a message to: mailto:[log in to unmask] In the body of the message put: signoff parkinsn