I don't readily have a copy of the file yet. I do know that it seems to be trying to connect to an IRC server and that for most of the incidents that we've found it's been coming across port 445 acccording to our IDS which is monitored by ISS. We are running Windows XP with all the latest patches due to our nifty patch link program and McAfee AV which of course is updated regularly too. Both McAfee and Microsoft have been notified of our situation and are currently try to devise a tool to combat this. So far we've found about 200 known infections across the US. We currently have it contained internally on the network due to the addition of ACL's and firewall modifications. I'll try to get the file for you as soon as possible....thanks