I would like to add that some computers are configured such that the infected file appears to be innocent. (The file extension--such as .pif, .exe, etc.--does not show.)

Fortunately, I use a service that allows for automatic blocking of potentially dangerous attachments. Unless you are specifically expecting a file with the following extensions, there is good reason to be cautious:

exe, bat, scr, com, pif, chm, cpl, hta, ins, isp, ise, js, mda, mdb, mde, ade, adp, mdz, msc, prf, dbx, nch, reg, inf, vb, vbs, bas, msp, wsh

An attachment with the .pif, vbs or vb extension is almost certainly something malicious.