Ivor Jones wrote:
> "Desk Rabbit" <nospam@example.com> wrote in message
> news:v-SdnQcyechKQJbbnZ2dneKdnZydnZ2d@pipex.net
>
> [snip]
>
>> Nothing new. Its the W32/Mytob virus that has been around
>> since 2005-ish. Any half decent AV package will find it
>> and kill it.
>
> Almost certainly, as you say. But I hadn't seen the message text
> purporting to be from Sipgate before.
The domain name is a variable in the virus code, it just as easily been
bbc.co.uk etc..
>> http://www.sophos.co.uk/virusinfo/an...32mytobat.html
>>
>> Now, if you had posted the headers we might have been
>> able to trace the source which would have been far more
>> useful.
>
> Unfortunately I wasn't given them, only what you see, the emails were to a
> friend not me.
Then ask your friend for the headers.