misrepresentad a tiny bit
...and leaving out some other notes as well.
A) Yes, it DOWNLOADS to the Applications folder, but it does not "install" There is not installer at all in fact, it is simply a single-file executable.
B) It only does this if the user has previously told OS X not to bother them about future files being moved to the applications folder. The default is a prompt anytime anything is placed in this folder, regardless of the source.
C) By downloading the the Applications folder instead of the Downloads folder in the dock, nor by providing a disk image on the desktop to "install" from, many mac users will be confused. Some might not readily find the app at all after it "installs."
D) as the program was never "installed" running it the first time is a manual action, and it will further prompt a warning about running untrusted applications downloaded from the Internet. If somehow they manage to make it download by itself without a promt, the user may never know it;s there to bother to run it, and if they do they will see this warning and know it to be an app they have never run before that did not come with the mac or any other trusted application run through a true installer.
E) Since it's not installed, there is no auto-launch, and it will not be running in the background without it being manually launched. no dock icon (unless it's running) might be a clue to people who think it to be a legit app that an AV app that does not launch with OS X is not a real AV app. Unlike a real AV app, even if it was running, and generated a pop-up (from the background) it would not produce a system level alert, but would be forced to dance in the dock to get the user's attention, another hiont it is not an intergrated security application.
F) after all this, they still have to trick the infected user into giving them a credit card. Its not a worm running monitoring activity, it can't access protected user data or monitor web activity, it has to actually trick the user, and can only do that when manually run?
Big deal, they have a handy trick to self-install on some macs, after already tricking a user to their web site portal, but they have crippled its true usefulness as a worm/trojan since it can't auto-run, and also removing it is as simple as dragging to the trash.