G'day Alison,The one I got from Dick had "OLSEN" as its heading and the attachment came in as OLSEN.ZIP.bat ... but I suspect that was what was mentioned way above - my ZoneAlarm may have changed the ~~~.exe to ~~~.bat. I had advised Dick that anything with two stops in it is highly suspicious ... and corporate firewalls have been advised to delete or disarm any such files.
In regard to the "Add Tune" heading, I think the bug selects keywords or titles from past e-mails of the victim, so they look authentic (rather than this being some disgruntled GUEST attacking Mudcat with a custom virus) ... I think ...
Regards,
Bob Bolton (heading off to run that de-bug file ... just in case.)