One unique feature of Spybot was and still is that it is able to read the Windows registry of inactive drivers and users, making it the perfect choice to scan a system while booting from another drive or a CD to avoid active malware hindering the scan.
In this context, manual autostart analysis was and still is important to forensics and people trying to self diagnose yet unidentified malware, so we created a tool that was able to display a wide range of autostart entries (and browser extensions) even for inactive drives, exporting this as HijackThis logs, and our own, more detailed, logs.
It also introduces LASSHes, a kind of hash of startup entries that helps to quickly identify good system entries, since their LASSHes are known.
This tool is also included under the name Startup Tools in Spybot itself.