I find CounterSpy to have useful feature and option than MBAM:
- CounterSpy has quick overview of the program (if it’s up-to-date, if a scan has been done, world-wide threat level notice and quick detection statistics).
- More scan options is what CounterSpy has: Whether you will choose to run a quick, deep or custom scan. CounterSpy let you choose to scan for more file extensions, look for rootkit before a scan. MBAM will also look for rootkit but it’s nice to be able to customize the scanner.
- Allow/Block Manager: CounterSpy let you add (browse to add) any items you want it to allow. MBAM do not have this option but it has “Ignore List” but you cannot manually add items into unless MBAM detected it and you want it ignored.
- Update and Scan Scheduler: CounterSpy will allow you to create and edit single or multiple scan or update schedule. MBAM only allow modifying the time when the program will run a scan or update.
- UI access: I noticed that you can continue access the UI of CounterSpy during a scan. This is neat if you plan to take a look on any areas of the program while it is running a scan. MBAM will not let you touch its UI while the scan is running.
- Extra tools: MBAM includes FileAssassin while CounterSpy has PC Explorer, Privacy Tools [History Cleaner and File Eraser (secure deletion of files)] and Diagnostic Tools to log.
- Logs: CounterSpy history log viewer is very neat. It will display the real-time protection’s activity, program and scan logs. MBAM will only log the scan.
Both programs have Quarantine Manager, Built-in Updater and context menu and custom scan options. The frequency of detection updates by MBAM is often (many times a day!) than CounterSpy but both is releasing their updated detections on daily basis to keep us protected from new and variants of any malware they can detect. I like though the IP Blocking feature in MBAM but the option to manage what it will block or allow (in case some IP in use by bad guys is shared with good guys which is known as "shared hosting", end-users will be able to manage which to allow without disabling the IP Protection) and the acitivity log of blocked IPs are not currently available.