Well....if MS can alter DLL's, control panel files and exe files remotely and without the users knowledge - what do they have in built to Windows XP and Vista to allow it? My first thought would have been windows update, however the article specifically says that this happened to users that had it turned off....

So I would like to know how they done something that would usually require a user to be logged in as an Admin or at least know the admin password? And what safe guards are in place to stop a malicious person remotely updating DLL's and exe files without a users knowledge......