some virses get the the e-mail addresses stored in the infected computer, and e-mails itself using the email addresses it got. so the one sendint the email is not andrew, but a computer that has ndrews email address stored in its address book. below i s a quotation from symantec
"W32.Sobig.F@mm is a mass-mailing, network-aware worm that sends itself to all the email addresses it finds in the files that have the following extensions:
* .dbx
* .eml
* .hlp
* .htm
* .html
* .mht
* .wab
* .txt
The worm uses its own SMTP engine to propagate and attempts to create a copy of itself on accessible network shares, but fails due to bugs in the code.
Email routine details
The email message has the following characteristics:
From: Spoofed address (which means that the sender in the "From" field is most likely not the real sender). The worm may also use the address,
admin@internet.com, as the sender.
NOTES:
o The spoofed addresses and the Send To addresses are both taken from the files found on the computer. Also, the worm may use the settings of the infected computer's settings to check for an SMTP server to contact.
o The choice of the internet.com domain appears to be arbitrary and does not have any connection to the actual domain or its parent company."