The infected system polls the remote php scripts occasionally to indicate its availability:
Many of these mails are spammed by the author to entice people into opening them.
A combination of the latest DATs and the Engine will be able to detect and remove this threat. AVERT recommends users not to trust seemingly familiar or safe file icons, particularly when received via P2P clients, IRC, email or other media where users can share files.