Many mass mailer type worms (MyDoom is the latest) will spoof the 'From' Field in the e-mails they send.
What happens is the virus will pick two e-mail addy's at random out of the infected systems address book. The virus will then send itself to one address and list the sender as the other address.
The person who owns the infected system rarely has their own address listed in their address book, so that addy won't be used.
Since the ISP's send the e-mail back to the addy in the 'from' field, well someone else gets it. In these cases some of the addy's are no longer valid.
I once got an infected e-mail back that had my addy as both the sender and reciept.
I'll say you are right on track with the answer your giving. It never hurts for them to do a scan just to be sure.