Security Task Manager
A newer version of Security Task Manager is available.
This download is served from an external site
closeNOTICE: This link will open a connection to a third-party site. CNET cannot ensure the security of software that is hosted on external sites.
Sponsored Products
Excellent
Full user review
-
"tool locates tasks others cannot"
Summary
A coworker's system (XP home) was infected with everything under the sun. By rights, I should have just wiped and reinstalled, but it's interesting to me to know how to eradicate pests, so I spent time on it. I wound up with one ineradicable DLL, mad.dll, a piece of the TV Media malware. It wasn't launching a visible process, but even in safe mode, it could not be removed from the registry. It detected removal and reloaded itself at once. I wound up needing to unload it by booting the box from another live system. I might have been able to do the same with work on the key's permissions, though.
However, of all the tools I ran - AdAware, Spybot S & D, the command line Sophos scanner - only STM could even tell me that this dll was loading and persisting. I've just grabbed a copy to add to my work toolkit as well.
(Of the tools, I think their effectiveness would be ranked:
Sophos CLI in safe mode;
STM;
Ad-Aware;
Spybot.)
You sort of have to start with an aggressive tool to hose the worst offenders off the OS, then you can start looking for the remaining cruft.