Hi, have you tried to track down how these tickets entered the RT system? The presence of such an executable is a very strong indicator for a worm mail, but it seems strange that the subject refers to RT. Cheers, Hans-Martin