Will bring you a suid or sgid shell owned by lsof user (root
Optimize Windows startup items with IntegrityScanner
Mosteffective is: Easy SpyRemover