Skip to main content

SDSA: a second opinion for your Windows PC : Security, Malware removal, Windows, Tools

Your antivirus says everything is fine. Your friends say your account is sending them crypto scam links. Who is right?

That exact situation is why I built SDSA - Sophisticated Device Security Audit: a security checker for Windows 10 and 11 that looks at your PC the way a malware analyst would. Instead of only asking "does this file match a known virus?", it asks "what is this program actually doing?" - what starts with Windows, what sends data to the internet, what reads your saved passwords, and what has been changed to hide itself. That is how it catches brand-new malware that no antivirus has a signature for yet.

In one sentence: SDSA audits your whole PC in a minute or two, gives it a security score out of 100, explains every problem in plain English, and - only if you say yes - removes the threats in a way that can always be undone.




The real case that started it

A PC I worked on had Microsoft Defender switched on and fully up to date. Defender found nothing. Meanwhile the owner's social media account was messaging crypto scam links to all their friends, and their Netflix account had been taken over (profiles renamed, plan and language changed).

The cause was a download: a fake copy of a popular AI tool on GitHub, uploaded by a look-alike account. Four minutes after it ran, it had quietly copied itself into about twenty places on the PC under harmless-sounding names - fake "Malwarebytes", fake "Firefox service", fake "nginx", fake Windows update tasks hidden among Windows' own scheduled tasks - and it was stealing browser sessions and passwords.

SDSA caught it because of its behaviour: unsigned programs running from folders like C:\Users\Public, many copies of the same file under different names, hidden startup tasks, and constant connections to raw internet addresses. The cleanup quarantined 107 malicious files, removed every way it restarted itself, and blocked its command servers in the firewall. Antivirus signatures would have missed all of it for weeks.

Lesson: "no virus found" is not the same as "clean".

What SDSA checks

One click on Run full audit checks all of this and gives you a score from 0 to 100 (Good, Fair, Needs attention, At risk, or Compromise indicators found):

  • Running programs - digital signatures, programs pretending to be Windows files (a fake svchost.exe outside the Windows folder), programs running from places malware likes to hide, and dangerous script command lines (encoded PowerShell and similar).
  • Who is sending your data out - every program that talks to the internet during the check, which servers it contacts, and programs that "check in" with a server on a steady clock (a classic remote-control trojan habit).
  • Everything that starts with Windows - Run keys, the Startup folder, scheduled tasks (including fake ones hidden in Microsoft's folders), services, Winlogon hijacks, AppInit DLLs and WMI subscriptions.
  • Your browsers - every extension rated by what it is allowed to do (read all sites, cookies, history, intercept traffic), browser policies forced by adware, hijacked shortcuts and proxy settings.
  • Account-theft malware - Discord token-stealer code, leftover "stealer logs", password-stealing scripts, and crypto wallets that are at risk. These are what usually make an account start spamming your friends.
  • Installed apps and downloads - adware, remote-access tools you may not know about, and recently downloaded programs, including the website each one came from.
  • Windows security settings - Defender and its exclusions, firewall, Windows Update, UAC, SmartScreen, remote access, proxy, DNS servers, the hosts file, suspicious root certificates, and user accounts.
  • Rootkit check - SDSA compares several independent views of Windows (different ways of listing programs, connections and services). Anything visible in one view but hidden in another is a rootkit sign.
  • Tricks that block security tools - malware often stops you from opening Task Manager, Registry Editor, Command Prompt or your antivirus, or switches Defender off through a hidden policy. SDSA looks for all of these.

Every problem comes with what it means, the evidence, and what to do about it. For any suspicious file you can look it up on VirusTotal with one click - only the file's fingerprint (hash) is sent, never the file.





What SDSA can do about it

Emergency Quarantine (with Undo)

If the audit finds real threats, Emergency quarantine shows you exactly what it will do, and does nothing until you confirm. Then it:

  • stops the malicious programs,
  • removes everything that restarts them (startup entries, scheduled tasks, services),
  • moves the files into a quarantine folder - nothing is deleted,
  • hunts the whole PC for hidden copies of the same malware by their fingerprint,
  • blocks the malware's servers in Windows Firewall.

Every single step is recorded and can be restored from the Quarantine tab if something turns out to be a false alarm.

System Check & Repair - when malware fights back

Some malware breaks Windows on purpose so you cannot remove it: it hijacks programs so they will not open, disables security services, deletes Safe Mode, or breaks how .exe files start. SDSA's system check finds these tricks and repairs them - again with a backup of everything it changes.

If malware has blocked even SDSA itself, there is SDSA-Repair.bat, which needs nothing but Windows' own Command Prompt. It lists what it found, changes nothing until you type YES, and saves a backup of every setting first.

Bloatware cleanup

SDSA recognises around 120 preinstalled extras, sponsored apps, PC-maker junk, antivirus trials, scam "PC cleaners" and apps that sell your internet bandwidth - each rated Safe to remove, Optional or Keep, with the reason. The list is updated weekly from a community-maintained catalogue, and parts of Windows can never be selected by mistake.

Staying protected after the cleanup

  • Watch mode - SDSA remembers what your clean PC looks like and alerts you with a Windows pop-up the moment something new starts itself, starts sending data out, or begins checking in with a server on a timer. It judges programs by their behaviour, so it also catches malware nobody has seen before.
  • Tripwires - hidden decoy "passwords", "seed phrase" and "2FA codes" files full of fake data, placed where info-stealers look. Nothing legitimate ever opens them, so if anything does, SDSA names the thief.
  • Dead-man switch - if malware kills SDSA while it is watching, a small Windows task notices and raises the alarm.
  • Self-protection - SDSA fingerprints its own files and warns you if anything tampers with it.
  • History log - every scan, finding, alert and fix is saved with its date and time, and can be exported as a text file, a CSV spreadsheet or a PDF report. Handy for keeping records, or for sending to whoever is helping you.

Scan an infected PC from a USB stick

When a PC is badly infected, you should not have to install anything on it. SDSA can be copied to a USB stick together with its own copy of Python, so it runs on any Windows 10/11 PC with no installation. Reports are saved on the stick, out of the malware's reach, and the stick checks that its own files have not been tampered with. If your stick has a write-protect switch, turn it on - then nothing on the infected PC can change SDSA.

Who it helps

  • Anyone whose account was hacked - Facebook, Instagram, Discord, Netflix or email suddenly doing things you did not do. SDSA finds the info-stealer that took your sessions, and the Account safety tab walks you through recovering each account safely.
  • Anyone who downloaded something they now regret - a cracked game, a "free" tool, an AI app from an unofficial page, or an email attachment.
  • Families and the "computer person" everyone calls - check a relative's PC from a USB stick in a few minutes and get a clear report.
  • Small offices and technicians - a repeatable audit with a score, a history and exportable reports.
  • Anyone with a slow, pop-up-filled PC - adware, bad extensions and bloatware are usually the reason.

How to use it

  1. Double-click Run-Audit.bat and accept the Windows permission prompt (administrator rights let it see everything). The dashboard opens in your browser.
  2. Click Run full audit. It takes a minute or two, including a short watch of your network traffic.
  3. Read the Overview: your score and the problems sorted from most to least serious, each with what to do.
  4. If there are Critical or High threats, disconnect from the internet, click Emergency quarantine, review the list and confirm.
  5. Run the audit again to confirm the PC is clean, then turn on Watch mode so you hear about anything new straight away.
  6. If accounts were affected, change your passwords from another, clean device, and follow the Account safety checklist.

Prefer it out of the way? SDSA-Tray.bat runs it as a small shield icon next to the clock - click it to open the dashboard.

Safe by design

  • Checking never changes anything. The audit only reads.
  • You stay in control. Quarantine, repairs and app removal only happen after you confirm, and can be undone.
  • Private. The dashboard is reachable only from your own PC. Nothing is uploaded. The only online look-ups are a file fingerprint when you click VirusTotal, and the public bloatware list.
  • Transparent. SDSA always runs under its real name - it never hides from you or from Task Manager.

What SDSA is not

SDSA is not a replacement for your antivirus - keep Microsoft Defender (or your antivirus) switched on. SDSA is the second opinion that looks at behaviour instead of signatures. And no program running inside Windows can fully trust Windows once a deep (kernel-level) rootkit is installed; if SDSA reports signs of one, run the Microsoft Defender Offline scan (Windows Security > Virus & threat protection > Scan options), which checks the PC before Windows starts.

Get SDSA for USB stick

Quick questions

Does it need the internet?
No. The audit and the quarantine work offline - which is exactly how you should run them on an infected PC.

Will it delete my files?
No. Quarantined files are moved, not deleted, and can be restored with one click.

What do I need?
Windows 10 or 11. The USB version runs without installing anything; the regular version uses Python (the launcher installs the one small add-on it needs).

Get SDSA
Need help reading your report? Post it (with personal details removed) in our Facebook group or message our Facebook page.

SDSA version 1.9.0 for Windows 10/11. Also on MLEA Digital Systems.

Comments

Popular posts from this blog

How to remove yuyun Cantix virus easily.

For the average user. Files created by the virus: autorun.inf, Microsoft.Ink, Desktop.ini, all drives will be affected by this virus. Download Microsoft Security Essential and extract on the desired path. Click here for 32 bit and 64 bit . Install MSEIntall32/MSEinstall64, Note! after the installation do not restart the computer just download the updates, after updating the MSE will show updated then do a quick scan.  Optional: While scanning, download   these utilities   Cure Utility   or   Quicklock   . This utility will restore the task manager, registry editor, folder option and run. If Cure.exe won't run, download Dot net framework. this app needs dot net 2 framework. To download get here at filehippo .  Extract Cure.exe or Quicklock, on windows 7 right click then Run as administrator.on Cure.exe click Heal button then ok. On Quicklock, if the task manager and registry editor is disabled it will show the checkb...

For quick adware and malware removal without installing anti-malware

Note! Anti-virus is still needed. Removal of the following without installing anti-malware. Adware (advertising Softwares) PUP (Potentially Undesirable Program) Toolbars Hijacker (Hijack of the browser's homepage or search engine) Tools needed Download: Bitdefender ART and AdwCleaner Compatible with Windows XP, Vista, 7, 8, 8.1 in 32 & 64 bit. Nowadays PUP or potentially unwanted programs are commonly installed on computers of unaware PC users, it is because these apps were bundled with some common freeware applications used by most consumers looking for free software, most of this apps consumes more resource than your legitimate programs. To prevent this program install in your PC's make sure you read any agreement before you click yes or agree while installing the program. Signs of malware and adware installed on your computer:                         ...

Registry Cure

A simple utility program to cure the registry damage by a virus, it restores the Windows Task Manager, Run, Folder Option and Registry Editor. If the program won't run, Get Microsoft .NET Framework Version 2.0. Download  DotNet Framework 2   Download   Reg Cure