All the AV companies are calling this new outbreak "Doomjuice" Symantec: http://www.sarc.com/avcenter/venc/data/w32.hllw.doomjuice.html McAfee: http://vil.nai.com/vil/content/v_101002.htm Sophos: http://www.sophos.com/virusinfo/analyses/w32doomjuicea.html Trend: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_DOOMJUICE.A Etc. They all have it as a low-incidence in the wild. What I don't understand is that if it hasn't spread, what caused the attack against Microsoft this morning? Larry Seltzer eWEEK.com Security Center Editor http://security.eweek.com/ larryseltzer@ziffdavis.com