The big step would be a setting in "User Preferences" that needs to be turned on to allow any applications to be installed, or any downloaded applications to run. That setting would have to be turned on by the user, and would turn itself off after 15 minutes. Installer and Finder trying to start applications would show a message what to do when needed (a verbal message; user has to figure out how to do it himself). Result: Users trying to install legitimate apps are slightly inconvenienced; clueless users can't install MacDefender if they try; and users who know enough to figure out how to install MacDefender should be clever enough not to do it.