It's not so much that, as we get new virus definitions hourly, based on the Army's contract with Symantec, and we have the latest SAV and a firewall in place.  Exchange does a poor job of filtering infected emails, even in conjunction with SAV, and when people see an email titled "Your account" from "
[email protected]," they open it.  For some reason, not everyone had the virus definitions that would have stopped that in its tracks.  We also have several users connecting remotely who don't get the network updates, and a lot of them got hit.  And since they have to call in and do their updating over 56k, the whole thing was quite a bitch.  
 Oh... we had the new updates.   Of course our remote users didn't.   Got to the point I just mailed some out a CDR with the patch and FixBlast on them.