Getting that stuff is largely an intelligence thing. The spyware stuff mostly happens to people who just click yes on everything that pops up on their screen and install stupid applications with bundled spyware, and some spyware brings in other spyware.
I have only ever gotten one piece of spyware on my own personal PC and it happened not while I was using the computer, but while a friend of mine was.
Now, the public computer at my work. I could spend 40 hours a week removing spyware from it. We have tried locking the sucker down, but it generates too many complaints (it is supposed to be a full function computer, our stupid chain requires it), locking it down to actually make it safe for idiots to use kills too many things. Hiding IE and making all IE references point to Firefox generates more complaints, as a few websites (our own company website included) don't work with firefox.
I can't even keep AOL off the thing, or keep the security software running. Every single day when I come in the security software has been disabled, AOL has been installed (despite the large sign on the computer that states "Do not install AOL on this computer), and every message program on the face of the earth has been installed and set to run on bootup.