To be honest, i'm semi-impressed this is still a thing. I assumed it had died in the late 90s.
It's also scary of course, that these people seem to have antivirus running and it hasn't stopped it. Seems like a pretty trivial thing to detect?
Malware authors can simply tweak or repack their code until the AV engines don't detect it anymore.
Getting around behavioral detection is harder, but possible. If malware is privileged it becomes an arms race of who can hook lowest and who can disable who.
I tend to notice a correlation between people who have problems with malware/spyware/crapware and people who have AV software installed and it's the opposite of what you might expect. Perhaps people who install it get a false sense of security?
AV software tends to be either ineffective in that it doesn't detect a lot of actual malware or it is constantly generating a lot of false positives which people just learn to ignore "Tracking cookie detected! Your life is in danger!".
I'm more of a firewall guy myself.
That's the difference between Microsoft Security Essentials and commercial AV software. One is designed to just make the more OS secure, the other also needs to advertise its presence and appear to be "doing something".
Also, apparently it was relaunched in 2010 and soon after their site was hacked[1], they also lost their source code - ahaha. No backups, 2010. Christ.
"Weird, my cd drive just opened up."