Yer, I've had several similar to this.
I use Mailwasher and this allows me to preview a message before downloading it. I can also preview the raw message and this reveals the sender's IP address. When I can be bothered, I copy this address and go and paste it into the second box in the middle column of:
http://www.dnsstuff.com/
If it turns out to be from a UK source (and especially NTL) I'll download it. Norton AV will replace the attachment with a simple virus message and then I copy and paste it to the an abuse report for the ISP.
NTL have an abuse report form you can fill in here:
http://www.ntlworld.com/netreport/
...but note I have never ever received any indication from NTL that this does any good. On the other hand, Energis provide loads of follow up information.