Babybear details are found on this Symantec Website Page

Statistics
Current Status:Cat 2
Wild: Low
Damage: Medium
Distribution: High
Details
Type: Worm
Infection Length: 204,800 bytes
Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me
Systems Not Affected: Windows 3.x, Macintosh, OS/2, UNIX, Linux
Description
W32.Babybear@mm is a worm written in Visual Basic. It spreads using email. Once activated, this worm damages the installations of Symantec antivirus products and may prevent them from running.

W32.Babybear@mm copies itself all over the system and creates many empty folders.
Presentation
W32.Babybear@mm will arrive as an email attachment, which has the following characteristics:

Subject: Please Confirm

Message Body:
Dear Sir or Madame, We have detected that you have placed a Order for Msn8. Before we start your Service please confirm your order. To confirm your order please check the attachement. Thanks, Microsoft Corporation Support

or as:

Subject: File You Requested

Message Body:
Hey Here is the file you wanted

The attachment name varies, but it can be any of the filenames shown in the list in step 1.
Notes]
Displays the messages:

Title: Application Error

Message: Missing .Dll File

and:

Message:
<imge with a reference to Bugbear.B>
with the text:
From the Creators of BugBear


Sends itself to all the contacts in your Address Book.

Cheers