Geeks to Go Forums: Deckard's System Scanner (formerly Comboscan) - Geeks to Go Forums

Jump to content

i Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or start a new topic of your own. Joining allows you to enjoy all this forum has to offer. Learn more in our Welcome Guide. What are you waiting for? Click here to join for free today!
  Download File

Browse Other Categories

Deckard's System Scanner (formerly Comboscan) Rate File: - - - - - 1 Votes

File Name
Deckard's System Scanner (formerly Comboscan) by admin 
Submitted
23 February 2007 - 11:37 AM
Last Updated
09 April 2007 - 02:08 AM
File Size
451.49K (Estimated Download Times)
Views
136684
Downloads
39911
This tool is compatible with Windows 2000 and up (that includes Vista).

Download a single executable and run it. ComboScan gives your standard warnings, then does the following (in order):
  • Logs if the computer is in Normal Mode, Safe Mode, or Safe Mode with Networking. No more guessing!
  • Creates a restore point (Normal Mode XP and Vista only). Will try to re-enable System Restore if it was disabled.
  • Cleans Temporary Files, Downloaded Program Files, Internet Cache Files, and empties the Recycle Bin on all drives.
  • Searches for HijackThis on the system. If it cannot find it, it will ask the user permission to download a copy from greyknight17.com. The user also has the option of telling ComboScan where their copy of HijackThis is if they have already downloaded it.
  • Renames HijackThis based on the login name and gets a log using the /autolog parameter, closing both HijackThis and the Notepad without requiring interaction from the user.
  • Lists out HJT entries that the user has hidden.
  • Lists out HJT backups.
  • Dumps file associations (similar to SREng) and will highlight in red if something doesn't match up.
  • Dumps drivers (whitelisted) and tests for pe386/Rustock.
  • Dumps services (again, whitelisted).
  • Dumps the Scheduled Tasks folder.
  • Prints files created in the past 30 days and files modified in the past 90 days, similar to ComboFix.
  • Dumps various registry load points with whitelist (very similar to ComboFix).
  • Gets basic system information, such as number of CPUs, memory usage, drive information (filesystem type, space).
  • Dumps Security Center information (if appropriate).
  • Dumps DOS environment variables.
  • Lists all user profiles on the system (and says which are administrative accounts).
  • Dumps Add/Remove programs, looking in both HKLM and HKCU. Common Microsoft entries are whitelisted.
  • Turns off word wrap in Notepad.
  • Unhides files and shows extensions.
  • Opens the logs in Notepad for the user to post.
In all, it takes anywhere from 1-5 minutes to do all the above, depending on the system.

ComboScan produces two logs. The primary log contains everything up to and including the registry dump, and the supplementary log contains everything else. You can find both logs in C:\ComboScan.

Some additional notes:

If ComboScan downloads and installs HijackThis, installs it as %PROGRAMFILES%\HijackThis\HijackThis.exe and creates a shortcut on the Desktop.

If ComboScan cannot download HijackThis and there is no local copy of HijackThis for ComboScan to use, ComboScan will produce a HijackThis-esque log. You will still need to install HijackThis or you will need to manually fix the system as ComboScan does not provide this ability. :happy:

There is a command switch, /config, that will allow you to pick and choose which modules you want ComboScan to use.

When ComboScan is run for the first time, it will produce a full set of logs. Each subsequent run will only produce a HijackThis log along with a file and registry dump (no restore point or cleanup is performed). If you want something else -- like the driver dump -- you will need to run ComboScan with /config. If you download and run a newer copy of ComboScan, it will produce a full set of logs again the first time the new copy is run.
Screenshot

  Download File
Page 1 of 1

Comments

dianedmk 

05 June 2008 - 06:13 PM | #1
Regarding Deskard Scanner, I had two problems happen when I ran the file. First, my system clock didn't reappear for quite some time and when it did it was set to military time with no A.M. or P.M., etc. Not really a big deal except my registry scanner now thinks I havent run it in 65 days(lol). The other problem tho I have not resolved. The scanner moved four of my downloaded program files to a backup folder. I tried to copy the folders back to Windows and I cannot copy or move them. Anyone know how I can restore them? I use and need these particular files and windows is reporting the associated programs as damaged. I guess if I have to I can redownload and reinstall, but it would be easier to find a way to restore the files from Deskard's folder. Suggestions?

HM2K 

21 April 2009 - 08:25 AM | #2
http://deckard.geekstogo.com/dss.htm

Quote

Deckard's System Scanner interacts with a specific rootkit (tdssserv) in a way that may make your system unusable (altering the svchost netsvcs registry entry). This download link has been removed until a fix is released by Deckard. For your own protection, please do not attempt to download this tool from other sites.

08/17/2008

Your Geeks to Go admin team


Is there no update?

Since it's made using AutoIt3, can't someone just get the au3 file, and release it as open source?

If the author could kindly contact me, that'd be useful.

Thanks.

admin 

06 May 2009 - 11:02 PM | #3
The developer has not been heard from in many months. There is no update.

Guest 

29 May 2009 - 01:04 AM | #4
I'm so glad I read through the comments before I downloaded this!

Guest 

24 November 2009 - 09:16 AM | #5

' date=, on date=, said:

I'm so glad I read through the comments before I downloaded this!

learning_to_fly 

12 December 2009 - 07:37 AM | #6

' date=, on date=, said:

I'm so glad I read through the comments before I downloaded this!


You "said" a MOUTHFULL!!!!

Guest 

14 December 2009 - 04:52 PM | #7

Quote

From date=:

I'm so glad I read through the comments before I downloaded this!


Jayman01 

11 February 2010 - 09:32 PM | #8
always read through before starting, just to make sure you completely understand. goes for all the forums here. goes for everywhere you go.
Page 1 of 1

  


Toggle random files Random Files

Screenshot

File Name: Trend Micro Hijack This™
In Category: Anti-malware Tools
Screenshot

File Name: Kernel Detective
In Category: Anti-malware Tools
Screenshot

File Name: Default Document Fix for Office 2007
In Category: Software Tools

Download Statistics

Total Files
35
Total Categories
3
Total Authors
10
Total Downloads
706,193
Latest File
The latest file submitted was Memtest86 by admin  (submitted 17 August 2010 - 12:29 AM)

10 user(s) active in the past 15 minutes
10 guests, 0 Anonymous Users


Advertisements do not imply our endorsement of that product or service. Join to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising | Contact | Link to us