I haven't isolated one of these, but I received a report that it did get through MailScanner3.22/f-prot3.12a (with latest definitions). Has anybody seen EML/Fortnight before? How do we catch it? http://www.europe.f-secure.com/v-descs/fortnight.shtml Thanks, Leland