a great deal of spyware/malware trojans get installed because of lax security standards with activeX or java. I don't use firefox so i'm not sure of settings details, but in IE you should never have ANY settings for activeX/java that are on 'enabled', instead they should be at 'prompt'. Now, this doesnt ALWAYS work, especially if the virus writer is exceptionally skilled and manipulating the appearance of the prompt windows.
__________________
"no amount of force can control a free man, a man whose mind is free. No, not the rack, not fission bombs, not anything. You cannot conquer a free man; the most you can do is kill him."
|