• how do I know statup programs are not viruses??

    From micky@NONONOmisc07@fmguy.com to alt.comp.os.windows-11 on Sun Sep 27 20:40:26 2026
    From Newsgroup: alt.comp.os.windows-11

    I take lots of precautions against malware, but when I get one of those
    fairly big green boxes that want to install a startup program, I usually
    say yes. How do I know they are not viruses in microsoft clothing?
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Paul@nospam@needed.invalid to alt.comp.os.windows-11 on Sun Sep 27 15:41:30 2026
    From Newsgroup: alt.comp.os.windows-11

    On Sun, 9/27/2026 1:40 PM, micky wrote:
    I take lots of precautions against malware, but when I get one of those fairly big green boxes that want to install a startup program, I usually
    say yes. How do I know they are not viruses in microsoft clothing?


    You can do an on-demand scan of your C: drive if you want.

    Microsoft has a way of doing that, built into the OS.

    https://www.elevenforum.com/t/manually-scan-with-microsoft-defender-antivirus-in-windows-11.4349/

    # Microsoft Defender Offline Scan

    https://www.elevenforum.com/attachments/scan_with_microsoft_defender_windows_security-3-png.20417/

    At one time, a previous OS like maybe Windows 7, you could
    download an MSSS ISO and make a disc to scan with. I feel less
    confident in the scheme used today, where the OS fabricates its
    own WinPE boot material for the scan.

    You also have to be paying attention, as the scan can turn over
    a number of "hits", and the Summary at the end will say
    that nothing was found.

    Many items that function as attack surfaces, are being
    scanned "on the way up" as the system boots. System32 should
    be scanned for example. Maybe Program Files.

    If you wanted, you could use Sysinternals Process Monitor which can record
    both the shutdown sequence as well as the startup sequence. And
    you might then be able to identify all the files being
    opened for scanning. So you'd have some idea what gets scanned
    on a normal boot sequence. The only problem today with doing
    this, is procmon23.dll or similar (hidden) is not allowed
    any more, and you might see a message that the attempt to
    record the boot, is not going to work. In which case, you would
    have to resort to some other recorders for the job (which also
    use ETW).

    Paul
    --- Synchronet 3.22a-Linux NewsLink 1.2