Related link: http://isc.incidents.org/diary.html?date=2004-01-26

By now, everybody knows about the latest “horrible” worm (MyDoom,
Novarg, whatever). On multiple occasions it was called the “fastest
spreading worm ever”. I was looking at various anti-virus vendor sites
(linked from this URL), and it struck me as extremely odd that the
user has to MANUALLY execute the attachment to actually be infected
and no vulnerability is being exploited. How does the manual
infection coincides with the fastest spread rate ever? Sure, a bit of
social engineering (masking as the mail server message) helps, but I
still find this whole story very surprising…