Your antivirus says everything is fine. Your friends say your account is sending them crypto scam links. Who is right?
That exact situation is why I built SDSA - Sophisticated Device Security Audit: a security checker for Windows 10 and 11 that looks at your PC the way a malware analyst would. Instead of only asking "does this file match a known virus?", it asks "what is this program actually doing?" - what starts with Windows, what sends data to the internet, what reads your saved passwords, and what has been changed to hide itself. That is how it catches brand-new malware that no antivirus has a signature for yet.
The real case that started it
A PC I worked on had Microsoft Defender switched on and fully up to date. Defender found nothing. Meanwhile the owner's social media account was messaging crypto scam links to all their friends, and their Netflix account had been taken over (profiles renamed, plan and language changed).
The cause was a download: a fake copy of a popular AI tool on GitHub, uploaded by a look-alike account. Four minutes after it ran, it had quietly copied itself into about twenty places on the PC under harmless-sounding names - fake "Malwarebytes", fake "Firefox service", fake "nginx", fake Windows update tasks hidden among Windows' own scheduled tasks - and it was stealing browser sessions and passwords.
SDSA caught it because of its behaviour: unsigned programs running from folders like C:\Users\Public, many copies of the same file under different names, hidden startup tasks, and constant connections to raw internet addresses. The cleanup quarantined 107 malicious files, removed every way it restarted itself, and blocked its command servers in the firewall. Antivirus signatures would have missed all of it for weeks.
Lesson: "no virus found" is not the same as "clean".
What SDSA checks
One click on Run full audit checks all of this and gives you a score from 0 to 100 (Good, Fair, Needs attention, At risk, or Compromise indicators found):
- Running programs - digital signatures, programs pretending to be Windows files (a fake
svchost.exeoutside the Windows folder), programs running from places malware likes to hide, and dangerous script command lines (encoded PowerShell and similar). - Who is sending your data out - every program that talks to the internet during the check, which servers it contacts, and programs that "check in" with a server on a steady clock (a classic remote-control trojan habit).
- Everything that starts with Windows - Run keys, the Startup folder, scheduled tasks (including fake ones hidden in Microsoft's folders), services, Winlogon hijacks, AppInit DLLs and WMI subscriptions.
- Your browsers - every extension rated by what it is allowed to do (read all sites, cookies, history, intercept traffic), browser policies forced by adware, hijacked shortcuts and proxy settings.
- Account-theft malware - Discord token-stealer code, leftover "stealer logs", password-stealing scripts, and crypto wallets that are at risk. These are what usually make an account start spamming your friends.
- Installed apps and downloads - adware, remote-access tools you may not know about, and recently downloaded programs, including the website each one came from.
- Windows security settings - Defender and its exclusions, firewall, Windows Update, UAC, SmartScreen, remote access, proxy, DNS servers, the hosts file, suspicious root certificates, and user accounts.
- Rootkit check - SDSA compares several independent views of Windows (different ways of listing programs, connections and services). Anything visible in one view but hidden in another is a rootkit sign.
- Tricks that block security tools - malware often stops you from opening Task Manager, Registry Editor, Command Prompt or your antivirus, or switches Defender off through a hidden policy. SDSA looks for all of these.
Every problem comes with what it means, the evidence, and what to do about it. For any suspicious file you can look it up on VirusTotal with one click - only the file's fingerprint (hash) is sent, never the file.
What SDSA can do about it
Emergency Quarantine (with Undo)
If the audit finds real threats, Emergency quarantine shows you exactly what it will do, and does nothing until you confirm. Then it:
- stops the malicious programs,
- removes everything that restarts them (startup entries, scheduled tasks, services),
- moves the files into a quarantine folder - nothing is deleted,
- hunts the whole PC for hidden copies of the same malware by their fingerprint,
- blocks the malware's servers in Windows Firewall.
Every single step is recorded and can be restored from the Quarantine tab if something turns out to be a false alarm.
System Check & Repair - when malware fights back
Some malware breaks Windows on purpose so you cannot remove it: it hijacks programs so they will not open, disables security services, deletes Safe Mode, or breaks how .exe files start. SDSA's system check finds these tricks and repairs them - again with a backup of everything it changes.
If malware has blocked even SDSA itself, there is SDSA-Repair.bat, which needs nothing but Windows' own Command Prompt. It lists what it found, changes nothing until you type YES, and saves a backup of every setting first.
Bloatware cleanup
SDSA recognises around 120 preinstalled extras, sponsored apps, PC-maker junk, antivirus trials, scam "PC cleaners" and apps that sell your internet bandwidth - each rated Safe to remove, Optional or Keep, with the reason. The list is updated weekly from a community-maintained catalogue, and parts of Windows can never be selected by mistake.
Staying protected after the cleanup
- Watch mode - SDSA remembers what your clean PC looks like and alerts you with a Windows pop-up the moment something new starts itself, starts sending data out, or begins checking in with a server on a timer. It judges programs by their behaviour, so it also catches malware nobody has seen before.
- Tripwires - hidden decoy "passwords", "seed phrase" and "2FA codes" files full of fake data, placed where info-stealers look. Nothing legitimate ever opens them, so if anything does, SDSA names the thief.
- Dead-man switch - if malware kills SDSA while it is watching, a small Windows task notices and raises the alarm.
- Self-protection - SDSA fingerprints its own files and warns you if anything tampers with it.
- History log - every scan, finding, alert and fix is saved with its date and time, and can be exported as a text file, a CSV spreadsheet or a PDF report. Handy for keeping records, or for sending to whoever is helping you.
Scan an infected PC from a USB stick
When a PC is badly infected, you should not have to install anything on it. SDSA can be copied to a USB stick together with its own copy of Python, so it runs on any Windows 10/11 PC with no installation. Reports are saved on the stick, out of the malware's reach, and the stick checks that its own files have not been tampered with. If your stick has a write-protect switch, turn it on - then nothing on the infected PC can change SDSA.
Who it helps
- Anyone whose account was hacked - Facebook, Instagram, Discord, Netflix or email suddenly doing things you did not do. SDSA finds the info-stealer that took your sessions, and the Account safety tab walks you through recovering each account safely.
- Anyone who downloaded something they now regret - a cracked game, a "free" tool, an AI app from an unofficial page, or an email attachment.
- Families and the "computer person" everyone calls - check a relative's PC from a USB stick in a few minutes and get a clear report.
- Small offices and technicians - a repeatable audit with a score, a history and exportable reports.
- Anyone with a slow, pop-up-filled PC - adware, bad extensions and bloatware are usually the reason.
How to use it
- Double-click Run-Audit.bat and accept the Windows permission prompt (administrator rights let it see everything). The dashboard opens in your browser.
- Click Run full audit. It takes a minute or two, including a short watch of your network traffic.
- Read the Overview: your score and the problems sorted from most to least serious, each with what to do.
- If there are Critical or High threats, disconnect from the internet, click Emergency quarantine, review the list and confirm.
- Run the audit again to confirm the PC is clean, then turn on Watch mode so you hear about anything new straight away.
- If accounts were affected, change your passwords from another, clean device, and follow the Account safety checklist.
Prefer it out of the way? SDSA-Tray.bat runs it as a small shield icon next to the clock - click it to open the dashboard.
Safe by design
- Checking never changes anything. The audit only reads.
- You stay in control. Quarantine, repairs and app removal only happen after you confirm, and can be undone.
- Private. The dashboard is reachable only from your own PC. Nothing is uploaded. The only online look-ups are a file fingerprint when you click VirusTotal, and the public bloatware list.
- Transparent. SDSA always runs under its real name - it never hides from you or from Task Manager.
What SDSA is not
SDSA is not a replacement for your antivirus - keep Microsoft Defender (or your antivirus) switched on. SDSA is the second opinion that looks at behaviour instead of signatures. And no program running inside Windows can fully trust Windows once a deep (kernel-level) rootkit is installed; if SDSA reports signs of one, run the Microsoft Defender Offline scan (Windows Security > Virus & threat protection > Scan options), which checks the PC before Windows starts.
Get SDSA for USB stick
Quick questions
Does it need the internet?
No. The audit and the quarantine work offline - which is exactly how you should run them on an infected PC.
Will it delete my files?
No. Quarantined files are moved, not deleted, and can be restored with one click.
What do I need?
Windows 10 or 11. The USB version runs without installing anything; the regular version uses Python (the launcher installs the one small add-on it needs).
Need help reading your report? Post it (with personal details removed) in our Facebook group or message our Facebook page.
SDSA version 1.9.0 for Windows 10/11. Also on MLEA Digital Systems.
Comments
Post a Comment
Please feel free to write your comments.