It depends on what I'm trying to remove. On a brand new computer I setup a firewall and add Spybot S&D and AdAwareSE and show the user how to use them. Then I make sure they have a working Antivirus software and the computer is good for now. All patches should be installed and automatic update should be turned on with the option for user to chose when to install a new patch turned on.
If I start working on a computer with an infection, spyware / adware or a Trojan on it
For WinXP or WinME, it is advised that you turn off "System Restore" before proceeding with any viral scan. This will reduce the time required to scan a system.
How To Disable System Restore in WinXP:
For WinXP, right click on "My Computer" --> select "Properties" --> select the "System Restore" tab --> check the "Turn off System Restore" option.
How To Disable System Restore in WinME:
For WinME, right click on "My Computer" --> select "Properties" --> select the "Performance" tab --> check the "Disable System Restore" option
Next you will use an antivirus that can be run from a CD I use the "Public AntiVirus CD v. 3.82" that can be downloaded for free here:
http://nyquil-kid.dyndns.org/ This includes instruction on how to use and create the CD. You can get the MD5 checksum here and dowload instructions for Spybot S&D and AdAware.
I start with Spybot S&D, then AdAwareSE and after scanning and the computer comes up clean I bot it with an antivirus boot disk to scan for viruses (second time).
Next step after this is to make sure there are no other hidden malware / spyware.
I use About:Buster. This program removes the Home Search Assistant. (no Link)
and there is a great article here for those who would like to learn more about protecting / cleaning the computer:
http://www.mvps.org/winhelp2002/unwanted.htmFrom here you can download a custom HOSTS file and some batch files used to to turn HOSTS file editing on and off. Read up on it before you attempt this so you know what you are doing.

I add activeX blocklists to the registry
Spyware blocking tool you can read up on it there.
You can get CWShredder here:
http://www.merijn.org/files/cwshredder.ziphttp://www.spywareinfo.com/~merijn/files/cwshredder.zipThis tool will find and destroy all traces of the
CoolWebSearch (CWS) hijacker on your system. This
includes:
* Redirections to CoolWebSearch related pages
* Redirections when mistyping URLs
* Redirections when visiting Google
* Enormous IE slowdowns when typing
* IE start page/search page changing on reboot
* Sites in the IE Trusted Zone you didn't add
* Popups in Google and Yahoo when searching
* Errors at startup mentioning WIN.INI or IEDLL.EXE
* Unable to access antispyware tools or sites
HijackThis
Written by Merijn - merijn@spywareinfo.com
http://www.merijn.org/files/hijackthis.ziphttp://www.merijn.org/index.htmlI use LSP-Fix to fix winsock2 errors (no link)
QUOTE
This program attempts to correct Internet connection problems resulting from buggy or improperly-removed Layered Service Provider (LSP) software. When you start LSP-Fix, it will read the list of LSP modules from the Windows registry and verify that each module is present. If a module is missing, it is placed on the "Remove" list for removal. Advanced users can override suggested removals in the "Advanced" area. When "Finish" is pressed, the undesired entries are removed, and the remaining entries in the registry are renumbered to make them consecutive. The total module counts are then updated. Finally, the program will display a summary of the changes that were made.
http://www.xmlsp.com/pview/prcview.htmQUOTE
PrcView is a process viewer utility that displays detailed information about processes running under Windows. For each process it displays memory, threads and module usage. For each DLL it shows full path and version information. PrcView comes with a command line version that allows you to write scripts to check if a process is running, kill it, etc.
http://www.grc.com/default.htm Scroll down to the three musketeers and read up on how to use them to shut down the messenger service (Not IM) and shut down DCOM and how to turn off "Plug and Pray" (also know as Plug and Play)
This is some of the tools I use when cleaning out computers, there are more but they are for the most part command line utilities and they can render a computer useless if you use them wrong..

They are last resort tools to clean BIOS (almost never successful), Boot sector and FAT table.
Nils
Comment/Reply (w/o sign-up)