http://en.wikipedia.org/wiki/Digital_signature
The purpose of the blockchain is to establish an ordered sequence of transactions.
This is a DDOS attack on the integrity on the distributed database, which is very bad, but not able to spend Bitcoin that isn't yours.
I guess it would be possible.
The double spend attack works by convincing the other party that the transaction has completed (so they release whatever escrow is in place) and then replacing the blockchain.
(But a botnet infection could watch for wallets on a computer and cause the coins in the wallet to be spent)
When you have 51% of mining power, you can do a lot of nasty things(like stopping confirming transaction at all), but not spend someone else's bitcoins.
ASIC owners are paranoid about their earnings. They would notice they are getting less than they usually do the next day after the infection.