Drive by installs are one way. You know those annoying pop-ups that ask if you want to install, say, Turboloader? You get the three choices of 'yes' 'no' and the little 'x' on your browser. Some pop-ups are set so clicking ANY of the three will install their crap.
More popular way to get spyware is by downloading "free" software. The price of the free software is almost always going to be spyware that, once installed, installs even MORE spyware. The old saying that nothing is free is still true.
Pop-up blockers are notorious for actually being spyware! So are 'toolbars'.
Best advice is to avoid "free" software wherever it is found.
Even if it's offered by Yahoo? I downloaded Yahoo Messenger and use it often. It comes with pop up blocker as well. Do you think we should dump it?