Never been infected [without knowledge] with any virus/worm/trojan/zombie/rootkit/spyware/etc.
The only times I got infected was on purpose, because of testing software/environments.
Been using Win98SE [with all upgrades, extremely customized] since the day M$ started selling the upgrade on the internet [June 1999].
Dual-boot with WinXP OEM [with all upgrades, extremely customized] since the day M$ started selling it on the internet [September 2001].
Have also been using sporadically [mainly for testing purposes] WinME [with all upgrades, extremely customized].
Because of testing so much software, I sometimes use newly installed ["virgin" copies of] Win98FE, Win98SE + WinME.
Also played around at 1 time or another with a few Linux distros: Corel [don't ask], Knoppix, Ubuntu, RedHat + Novel, mostly for testing purposes.
I leave my PC on at all times [when I'm at home], and I use a cable modem connection [8 Mb/sec], which is always on.
I use only a basic firewall [Kerio 2.1.5 = freeware].
Got a basic VPN/DMZ/firewall 4-port router.
That's it. Nothing else.
Haven't used any anti-virus/anti-spyware/similar tools for ~ 6-7 years.
Whenever/if I use such tools, is only for testing purposes, or on somebody else's PC(s).
Why I don't get infected:
* Installed all OSes in directories other than default [my PC doesn't have C:\WINDOWS and never will].
* Changed all references from "C:\Program Files" to a short file name [8 chars] directory [Win98SE].
* Installed "C:\Documents And Settings" folder on different partition, under other name [short name = 8 chars] [WinXP].
* I keep important boot files [like HIMEM.SYS, IFSHLP.SYS, COMMAND.COM] in directories other than default [Win9x/ME].
* Manually + methodically "stripped" down my OSes of "dangerous" components, like Personal Web Server, FrontPage Extensions, NetBIOS, VPN, Outlook Express, Web Folders, NetMeeting, Messenger, IE Channels/IE Wallpapers, Active Desktop etc.
* I keep separate copies of important boot/system/registry/startup files, to restore them just in case, using custom batch files.
* MS IE 6.0 SP1 up to date with all security patches [official + unofficial], installed in directories other than default.
* I use MS IE only for a handful of sites that require ActiveX [which is enabled only when I access Windows Update]. For the rest of the internet I use Firefox [current release].
Sometimes I use Opera 9.01, Netscape 3.04, 4.79 + 8.1 + Maxthon [for testing only].
* I do not use M$ Java VM [JVM]. I use Sun Java instead [latest release], and customized Java permissions.
* Turned off all processes/TSRs/monitors/etc and keep startup empty [except the Kerio firewall process].
* In XP + ME I have uninstalled or turned off SR/WFP/PCHealth, Remote Desktop, Messenger, Automatic Updates, M$ Reporting tool, IE/OE Error Reporting tool etc.
* I never used and will never use any M$ software other than operating systems [and a few games they distribute but don't develop]. Example: I use OpenOffice instead of M$ Office.
* Never used backup/restore software. I do all backups/restores using custom batch files + PKZIP or 7-zip.
* I keep my registry + start/boot files "clean", by running periodically [manually, never used Scheduling Agent] custom REG, INF + BAT files.
* I always keep current copies of my main OSes on different physical hard disks and CD-Rs/DVD-Rs.
Always use at least 4 hard disks with different partitions for each OS.
And if I notice any weird behaviour, I reboot right away and replace the current OS copy with a good working one, from my most recent backups.
* I use a huge HOSTS file with over 120,000 banned servers, with all my OSes:
http://www.mdgx.com/hosts.htm
* I spend a lot of time on the internet researching, and sometimes I do visit dubious/unsafe web sites [for testing], but never got infected.
* I use batch files to periodically delete all traces of visited sites, cookies, history, temp files, browser cache, WMP cache + DRM etc.
* Disabled all WMP reporting/update features + unique ID string.
* I never used Outlook or any other offline mail client for email. I handle all my email through the web browser.
* I use email providers/hosts who use quality email filters for spam, adware + spyware [white/gray/black listing etc].
* Rarely, whenever I need to surf anonymously, I use a free proxy server.
* I customized Firefox javascript to ban dangerous interface scripts.
* I never use easy to break/same passwords.
* I don't do my banking, credit card stuff, taxes, accounting etc on the internet. I rarely buy stuff from the internet, only from a handful of web sites I trust, and always use a "protected" credit card [money back guaranteed if any unauthorized transations occur].
* I have removed all my personal info and disabled all spamming options from all my phone, internet, credit card and bank account providers [opt-out].
* Added my phone numbers to the national do-not-call directory [available only in USA].
* I subscribe to very few magazines/journals, I do no use store cards, money-saving promos etc.
Long live 98SE.
Best wishes.