The neglect of spyware and adware detection by AntiVirus Companies, eventually led to the rise of the AntiSpyware Industry. Following the lead of the first ever antispyware/adware tool - Steve Gibson's Optout, many Antispyware companies have chosen to provide a free on demand scanner and removal tool. However, there are relatively few antispyware tools with real time protection. This is less critical these days, because part of the antispyware real time protection can be covered (even improved on) by freeware HIPS including Behavior blockers and Sandboxes. Moreover Antiviruses have improved their detections abilities since the early days and the real time scanner of the antivirus can provide real time signature protection.
That said, since the earliest days of Antispyware testing , it was noticed that unlike for antiviruses detecting viruses and worms where scores in the 90% range were the norm, even the best Antispyware had less than satisfactory detection rates. Morever adware unlike many other malware (which tries to conceal itself from the user), depended on being noticed. Most users quickly figure out they have adware, and naturally try to remove it. As such for ad-ware to be effective they have to be designed in mind to resist being removed easily.
Many antiviruses provide antispyware scanning abilities (although the free version of AntiVir does not), but many users still prefer to include AntiSpyware. Unfortunately most of the free antispyware products lack good real time protection. There are basically two types of antispyware real time protection, one is the classic resident shield that scans by signatures and detects malware as files are written on the hard-disk or executed etc (just like in Antiviruses) and the other is behavior monitoring that informs you of changes to your system (autostart-ups, browser home pages etc.). The later is not as important if you intend to supplement your protection with HIPS. The former is rare in freeware products, however it is provided by Spyware Terminator (Note Spyware Terminator also has very good protection of the second kind) and Microsoft's own Windows Defender. Recently (June 2007), you can also get the Spyware Doctor™ Starter Edition - from Google which has a file guard. Spybot - Search & Destroy's Tea-timer and SpywareGuard also provide very limited protection in this area (their protection is more of the second kind with the classic signature database being outdated).
Because in the past exploiting or using ActiveX controls was a very popular manner of installing Spyware and Adware, a very popular anti-spyware device of blacklisting specific ActiveX controls was built into many popular antispyware programs like Spybot - Search & Destroy and SpywareBlaster. Also often associated with Anti-Spyware protection is blacklisting of cookies and lists of sites to be imported into Internet Explorer's restricted zones or placed into hosts file.
Note : SpywareBlaster only provides blacklisting of ActiveX controls and cookies, plus importing of sites into Internet Explorer's restricted zone. Technically this is just using the builtin features of Windows and the browser and hence does not really count as typical real-time protection. It is included here only because it is popular. See Lists_of_freeware_blocklists for more applications and lists that do similar functions.
Note : Spyware Terminator was formerly listed on the Spyware Warrior's rogue list but is now delisted.
Many malware particularly adware are very resistant to removal and require a complicated series of manual steps to completely remove all traces of it. To save time, experts have created specific fixes and tools to automate removal of specific widespread family of nasties that are hard to remove. Many of these fixes are constantly updated, as the nasties are themselves constantly upgraded. Some of the more famous ones include Gromozon Rootkit Removal Tool , SmitFraudFix , CWShredder (one of the first). RogueRemover is particularly notable for targeting rogue security products like SpyAxe, VirusBurst, and as such has a broader scope than most entries in this section.
These are generic cleaning tools often used to aid removal of malware in helper forums. Unlike other tools that are designed for removal of specific malware, the tools here are more generic and require human expertise to use properly. Hijackthis! is the most popular diagnosis tool of choice of online spyware fighters. Others tools include Deckard's System Scanner (formerly Comboscan), WinPFind. Many tools like AutoRuns and other autostart listers can also be used to detect malware.
Typically, you run Hijiackthis! , a diagnosis tool, and send the log to a human expert who will advise you on what (if anything) is wrong. The services above, allow you to upload the load to an automated service that will try to identify malicious or dangerous entries in the log. Because of omissions, false positives, and entries that may be reported as "not recognized" it is not recommended that auto analyzers be used.
Utilities that watch and warn about changes to your browser configuration (in almost all cases Internet Explorer only). Outdated. Most modern anti-malware programs such as antispyware and registry monitors have this function built in. One of the functions of the popular SpywareGuard.