i just received a mail from

MtGox with a self extracting archive ( .exe ) purporting to be a certificate to help combat this.... no way am i opening it, it got captured by my spam services anyhow but really.. who the hell is gonna trust an executable from them now ?
Not for them.
From: can be trivially spoofed.
Don't run any .exe
Don't use windows.
Don't touch windows with 20 meter stick while doing anything related to security of more then few bucks.
Jesus, guys.
Windows is fine, and is more secure than linux. If linux would receive the same amount of malicious attacks that windows receive, linux would become unusable and would require patches for years. The security on some of the linux distros is atrocious. Linux security is achieved through obscurity. An attacker isn't going to bother writing attacks against an OS that less than 1% of people use, and those that do use linux are likely to be highly technical.