I haven't had a chance to try it out but there is the bleeding snort project at www.bleedingsnort.org which contains rules to detect all sort of spyware, malware, etc. >From what I've read you can use the bleeding snort rules with Snort inline on your firewall to block all sorts of malicious stuff. Hope that helps.