ghshewan - yah, I know the admins over there were wigging out over this. I haven't heard back from them and they aren't returning calls at the moment so I can only guess they are still working on this.
I just checked our exchange servers, and even our external relays, and I still don't see many copies of this virus hitting us yet... let's hope it stays that way.
and you are also correct in that it sounds like an internal machine has been infected by this virus. If/when I get a chance to talk to those guys I'll see if their security group has been able to trace it back to "patient x" yet... I'm betting it was a salespersons laptop that got infected at home and they brought it in and plugged it in to the network.