To: Dan3 who wrote (80781 ) 5/28/2002 2:04:44 AM From: tejek Respond to of 275872 Take a look at the most recently edited/created files and try to delete any suspicious ones. But don't delete anything that you might need later - it can be hard to know which is which. Sometimes, when you can't delete a file it isn't because it's in use, but because it's marked read only or system. You can use the attrib command (attrib -s to remove system attribute, for example) to make the file eraseable. Right clicking on the file in file manager or explorer will usually let you do the same thing (pick properties, and uncheck the appropriate boxes), but you'll have to adjust the settings in folder options to let you see system files, etc, first. Attrib will sometimes work when the GUI tools won't. Dan, when I pulled up the file and tried to delete it, I got a message warning that it was working with Windows and could not be deleted at that time. Then, I found it had attached itself to the utility tab in MSCONFIG. And when I tried to get rid of it by unchecking it, it would recheck itself after I rebooted. Sometimes, a file that can't be deleted because it's in use can be renamed - then it won't be started up the next time you restart. You can also do a regedit search to try to locate the entry that's starting the executable. I thought of that but was afraid that if it was a worm, I might infect another file or at least the pathway leading to that file. Understand I know more about viruses than I do worms and I know little about viruses. :~((There are a lot of ways to screw up a windows machine, and sometimes trying to kill off a nuisance exe causes as much damage as the file itself. I was worried about that too.It is possible that the file you found was there prior to your clicking on that email[it's neither related to the email nor a virus]... As soon as I downloaded the info from the email, my pc acted weird........it slowed up and started to make all these noises like another program was running. And my pc runs pretty quiet now because I have DSL.........plus I scandisk and defrag at least once every week. In addition I had a hard time getting Nortons back up and when I did, I couldn't keep it up. That was my first real clue that I had a worm or virus. Obviously, it had been programmed to keep Nortons from working. I am really fortunate that it wasn't programmed to do more damage. This happened on Friday and I had no time to fukk with it until tonite. Can you imagine the level of damage it could have wrought in three days? YIKES!!! ted