I deal with a lot of people where the application control/out bound firewall is too confusing for novice users. I mean at work I've gotten a number of calls where someone has blocked iexplorer.exe because they had no Idea what it was.

I would say windows firewall with nod32 (its fast and its native spyware support out of the box is awesome).

JPnyc: rootkitRevealer is fun, AVG's anti rootkit isn't that bad. I try'd rootkit remover/uninstaller but I've never found anything with those so I think there bogus. I also used icesword but again, I don't see the big deal.

nihil: I pray one day avg makes a removal tool like Norton does. I hate trying to dig out avg from a system. Even using the installer then un-checking everything doesn't seem to work all the time.