TROJ_MYBABYPIC.A propagates via MS Outlook as an EXE attachment to an email: Subject: My baby pic !!! Message Body: Its my animated baby picture !! Attachment: mybabypic.exe When the EXE file is executed, a message box with the picture of a child is displayed. When this message box is closed, the Trojan drops several copies of itself in the Windows/System directory and adds several registry entries to enable it to execute at each Windows start up. This Trojan needs Windows Scripting Host to function and, upon execution, tries to connect to a certain Web site. In addition to this, the Trojan code also has some destructive payloads, which range from overwriting files with certain extensions to deleting certain files. For additional information about TROJ_MYBABYPIC.A please refer to our Web site at: http://www.antivirus.com/vinfo/virusencyclo/default5.asp?VName=TROJ_MYBABYPIC.A TROJ_MYBABYPIC.A is detected with Trend pattern #855 and above.