where do they get them from ?
Lack of security Awareness
In my experience through clearing out infected machines i have come across, many machines Not patched
no firewall out of date AV or none at all
Couple this with P2P Email born viruses internet worms and straying away from mainstream sites the recipe for disaster is there