Hmm. I just found this info about how to extract the files from the virus. dd if=file.xls.bat bs=512 skip=268 of=file.xls You need access to linux though as dd is a linux tool. Not sure if their is a Windows equivelant. I'm sure it wouldn't be too hard to make one though. Anyway, i'm sure you know the moral implications of looking at other peoples files... Just thought you may be interested. Regards, David Stubbs WEB: www.nti-uk.com TEL UK: 07968 397782 > -----Original Message----- > From: pic microcontroller discussion list > [mailto:PICLIST@MITVMA.MIT.EDU]On Behalf Of David Stubbs > Sent: 25 July 2001 7:42 PM > To: PICLIST@MITVMA.MIT.EDU > Subject: Re: [OT]: Heads up! Lots of Virus incoming? > > > Hey, > > Seems stupid that Windows will run any win32 executable even if the > extension is changed. That's just asking for trouble. Has anyone ever run > this file? What does it do? I just wonder what it does with the personal > info it collects and how this is a threat except for people who > examine the > file finding the confidential information. > > I hate people who write virus's. I hope that somebody catches this kid. > > Regards, > > David Stubbs > > WEB: www.nti-uk.com > TEL UK: 07968 397782 > > > > -----Original Message----- > > From: pic microcontroller discussion list > > [mailto:PICLIST@MITVMA.MIT.EDU]On Behalf Of Roman Black > > Sent: 25 July 2001 4:21 PM > > To: PICLIST@MITVMA.MIT.EDU > > Subject: Re: [OT]: Heads up! Lots of Virus incoming? > > > > > > Spehro Pefhany wrote: > > > > > > At 11:15 AM 7/25/01 +0100, you wrote: > > > >Looks like a kids assignment or something. Any ideas? > > > > > > It apparently grabs a legitimate file from "My Documents" and > > > attaches itself to the file. This is probably the biggest risk with > > > the virus- your private information is being distributed. > > > > > > As far as not knowing how to run it, I think if you use MS products > > > such as Outlook Express it would be matter of clicking on the > > > attachment. Most anybody can do that. > > > > > > Hi everyone, this virus is going BESERK on the motorbike > > lists, mainly "moms and pops" type people who use their > > new computer like a consumer. Most using MS Outlook. > > :o( > > > > I expect this to be BIG NEWS in a few days, it has to get > > the media's attention soon. > > > > Also a warning re the info above, there is gossip that > > the virus picks VALID EMAIL SUBJECTS FROM YOUR ADDRESS BOOK. > > That is why it's going beserk, people who you have emailed > > re a topic might get emailed back by the virus with the > > same subject listed. VERY nasty. > > > > I notice James has been silent and the list has been slow, > > anyone guessing the poor guy's going crazy chasing viruses?? > > :o) > > -Roman > > > > -- > > http://www.piclist.com hint: To leave the PICList > > mailto:piclist-unsubscribe-request@mitvma.mit.edu > > > > > > -- > http://www.piclist.com hint: To leave the PICList > mailto:piclist-unsubscribe-request@mitvma.mit.edu > > -- http://www.piclist.com hint: The PICList is archived three different ways. See http://www.piclist.com/#archives for details.