Richard, did you happen to note what MTAs were used? I suspect it's a function of the software or default configuration rather than something postmasters deliberately setup.
It looks like some postmasters are in the virus distribution business pretty much like the MyDoom virus itself. Perhaps these postmasters need to review their bounce message policies and remove all attached files from messages being bounced.
Paul Schmehl (pauls@utdallas.edu) Adjunct Information Security Officer The University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html