From Newsgroup: alt.comp.os.windows-11
On Sun, 9/27/2026 1:40 PM, micky wrote:
I take lots of precautions against malware, but when I get one of those fairly big green boxes that want to install a startup program, I usually
say yes. How do I know they are not viruses in microsoft clothing?
You can do an on-demand scan of your C: drive if you want.
Microsoft has a way of doing that, built into the OS.
https://www.elevenforum.com/t/manually-scan-with-microsoft-defender-antivirus-in-windows-11.4349/
# Microsoft Defender Offline Scan
https://www.elevenforum.com/attachments/scan_with_microsoft_defender_windows_security-3-png.20417/
At one time, a previous OS like maybe Windows 7, you could
download an MSSS ISO and make a disc to scan with. I feel less
confident in the scheme used today, where the OS fabricates its
own WinPE boot material for the scan.
You also have to be paying attention, as the scan can turn over
a number of "hits", and the Summary at the end will say
that nothing was found.
Many items that function as attack surfaces, are being
scanned "on the way up" as the system boots. System32 should
be scanned for example. Maybe Program Files.
If you wanted, you could use Sysinternals Process Monitor which can record
both the shutdown sequence as well as the startup sequence. And
you might then be able to identify all the files being
opened for scanning. So you'd have some idea what gets scanned
on a normal boot sequence. The only problem today with doing
this, is procmon23.dll or similar (hidden) is not allowed
any more, and you might see a message that the attempt to
record the boot, is not going to work. In which case, you would
have to resort to some other recorders for the job (which also
use ETW).
Paul
--- Synchronet 3.22a-Linux NewsLink 1.2