samer wroteWhen I used XP, I had two accounts. One for admin tasks and a very limited one called " user ".
When i needed to install a program I used "Run As ".
Anyway,
For 'user', disable all changes to the registry and other methods to register at startup.
This method isn't fool-proof as they can still use some local exploit to escalate their privileges,
for that i suggest employing sand boxing methods, but then again, would that be worth the hassle?
Also, like Nuc suggested, disable autorun..
Vista is configured like that by default.
I normally use a macbook... I installed vista, and a friend online wanted to play some msn game with me, so i had to click yes to a bunch of warning boxes, next thing I know ie is infected and opens 5 tabs every time i launch it. And that was just a couple of hours after installing vista!!!
They need a new OS design... like every program must have his own data directory and is only allowed to write there...and never every, even during installation, has write access to any other part of the system... and bho's (ie plugins) shouldnt be allowed to modify ie as they please...this system could be better designed... that can be fixed though if they think the whole system over from the bottom...
Note that osx is not really that much better designed... it is better, sure, but the main reason for which there is no spyware adware on osx is lower market penetration.