Aha--found it. whois 68.153.49.25 at twhois.arin.net It is coming from a bellsouth ISP user. I've emailed bellsouth to inform the user to clean the virus off his PC. Crow /**/