This has happened to me too.
An acquaintance who had me in their address book received the KLEZ-HAMM virus (or whatever it is). The worm infiltrates the victims Microsoft Outlook address book, and using the e-mail addresses it finds there, launches itself to everyone in the address book.
For example victim has A, B, C, D, E in his address book.
The worm will mail itself, using the cover of addresses A, B, C, and D to person E. When you check the technical gobble-de-gook (not the "official" term, of course) at the end of the mail, the source will actually be the victim, even though the address in the header looks like someone totally different.
The attachment does not appear to be an .exe file, but can present itself to be a .jpg, .pdf, .zip file etc.
I've gotten in the habit of checking the header against the gobble-de-gook at the end of the mail to make sure the sender's address matches.
I also have a "hotmail" account to which I send mail from people I do know - which offers the option of scanning the attachments for viruses with McAfee online prior to downloading them. I've been lucky so far.
Love, Scully