> > Content-Type: application/octet-stream;
> > name=getmsg[26].htm
> > Content-Transfer-Encoding: base64
> > Content-ID: <K1S5eo704zep2WSR>
>
> without even investigating further, i'd say, klez.
>
> pretty much taking the windows world by storm :)
>
Yeah, uses the iframe vulnerability in Outlook and Outlook Express. I
must have caught a couple of dozen of them this morning with my
filters.
John