My antivirus service has warned about this one. People I know have already been infected, so be careful folks & update your virus definitions immediately. Ernest Virus Alert Notification Win32.Palyh.A Alias: I-Worm.Palyh (Kaspersky), W32.HLLW.Mankx@mm (Symantec), W32/Palyh@MM (McAfee), Win32/Palyh.A.Worm Category: Win32 Type: Worm Last Modified: 5/18/2003 The My-eTrust Technical Support team has received increased numbers of infections for the Win32.Palyh.A worm and are advising clients to update their anti-virus protection immediately. CHARACTERISTICS Win32.Palyh.A is a worm which spreads via e-mail using its own SMTP engine, and through shared drives. It arrives in a message with one of the following subjects: Re: My application Re: Movie Cool screensaver Screensaver Re: My details Your password Re: Approved (Ref: 3394-65467) Approved (Ref: 38446-263) Your details The attachment name may be one of the following: application.pif movie28.pif screen_doc.pif screen_temp.pif doc_details.pif password.pif approved.pif your_details.pif The only message body observed at this time contains simply: All information is in the attached file. The worm also spoofs the 'From' address. E-mail sent by the worm appears to be from the following address: "support@microsoft.com"