startupware.com

Reversing the Model for Spyware Removal

Virgin Windows Report–Win XP Home, SP2 OEM

Filed under: Definitions, Identification — July 10, 2005 @ 10:43 am

Just finished building a new box for a client. Took the opportunity to grab the task list. The list below is what Windows Task Manager reported as running processes immediately after installation, after hardware detection, but before any drivers were installed. No patches, no antivirus, no software installs of any kind, no exposure to the internet, or even to a CDROM other than Windows itself.

OS version: Windows XP, Service Pack 2, OEM edition
Motherboard: MSI M8M Neo-V, with AMD Sempron 2800+ processor.
Any hardware support below, if any, was autodetected during install–no software or driver installs had been run when this process list was captured:

alg.exe
csr.exe
Explorer.EXE
lsass.EXE
msiexec.exe
services.exe
smss.exe
svchost.exe (5 instances running)
System
System Idle Process
taskmgr.exe
winlogon.exe
wmiprvse.exe
wpabaln.exe
wuaudit.exe

As I (or others), build more systems, we’ll post more of these “Virgin Windows Task Lists”.

I didn’t have a chance to grab a HijackThis log of the box in this condition, but that I will next time, and get a more complete picture of just what is part of the default configuration.

No Comments »

No comments yet.

RSS feed for comments on this post. TrackBack URI

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)