Deckard's System Scanner (formerly Comboscan)
- File Name
- Deckard's System Scanner (formerly Comboscan) by admin
- Submitted
- 23 February 2007 - 11:37 AM
- Last Updated
- 09 April 2007 - 02:08 AM
- File Size
- 451.49K (Estimated Download Times)
- Views
- 136684
- Downloads
- 39911
This tool is compatible with Windows 2000 and up (that includes Vista).
Download a single executable and run it. ComboScan gives your standard warnings, then does the following (in order):
ComboScan produces two logs. The primary log contains everything up to and including the registry dump, and the supplementary log contains everything else. You can find both logs in C:\ComboScan.
Some additional notes:
If ComboScan downloads and installs HijackThis, installs it as %PROGRAMFILES%\HijackThis\HijackThis.exe and creates a shortcut on the Desktop.
If ComboScan cannot download HijackThis and there is no local copy of HijackThis for ComboScan to use, ComboScan will produce a HijackThis-esque log. You will still need to install HijackThis or you will need to manually fix the system as ComboScan does not provide this ability.
There is a command switch, /config, that will allow you to pick and choose which modules you want ComboScan to use.
When ComboScan is run for the first time, it will produce a full set of logs. Each subsequent run will only produce a HijackThis log along with a file and registry dump (no restore point or cleanup is performed). If you want something else -- like the driver dump -- you will need to run ComboScan with /config. If you download and run a newer copy of ComboScan, it will produce a full set of logs again the first time the new copy is run.
Download a single executable and run it. ComboScan gives your standard warnings, then does the following (in order):
- Logs if the computer is in Normal Mode, Safe Mode, or Safe Mode with Networking. No more guessing!
- Creates a restore point (Normal Mode XP and Vista only). Will try to re-enable System Restore if it was disabled.
- Cleans Temporary Files, Downloaded Program Files, Internet Cache Files, and empties the Recycle Bin on all drives.
- Searches for HijackThis on the system. If it cannot find it, it will ask the user permission to download a copy from greyknight17.com. The user also has the option of telling ComboScan where their copy of HijackThis is if they have already downloaded it.
- Renames HijackThis based on the login name and gets a log using the /autolog parameter, closing both HijackThis and the Notepad without requiring interaction from the user.
- Lists out HJT entries that the user has hidden.
- Lists out HJT backups.
- Dumps file associations (similar to SREng) and will highlight in red if something doesn't match up.
- Dumps drivers (whitelisted) and tests for pe386/Rustock.
- Dumps services (again, whitelisted).
- Dumps the Scheduled Tasks folder.
- Prints files created in the past 30 days and files modified in the past 90 days, similar to ComboFix.
- Dumps various registry load points with whitelist (very similar to ComboFix).
- Gets basic system information, such as number of CPUs, memory usage, drive information (filesystem type, space).
- Dumps Security Center information (if appropriate).
- Dumps DOS environment variables.
- Lists all user profiles on the system (and says which are administrative accounts).
- Dumps Add/Remove programs, looking in both HKLM and HKCU. Common Microsoft entries are whitelisted.
- Turns off word wrap in Notepad.
- Unhides files and shows extensions.
- Opens the logs in Notepad for the user to post.
ComboScan produces two logs. The primary log contains everything up to and including the registry dump, and the supplementary log contains everything else. You can find both logs in C:\ComboScan.
Some additional notes:
If ComboScan downloads and installs HijackThis, installs it as %PROGRAMFILES%\HijackThis\HijackThis.exe and creates a shortcut on the Desktop.
If ComboScan cannot download HijackThis and there is no local copy of HijackThis for ComboScan to use, ComboScan will produce a HijackThis-esque log. You will still need to install HijackThis or you will need to manually fix the system as ComboScan does not provide this ability.
There is a command switch, /config, that will allow you to pick and choose which modules you want ComboScan to use.
When ComboScan is run for the first time, it will produce a full set of logs. Each subsequent run will only produce a HijackThis log along with a file and registry dump (no restore point or cleanup is performed). If you want something else -- like the driver dump -- you will need to run ComboScan with /config. If you download and run a newer copy of ComboScan, it will produce a full set of logs again the first time the new copy is run.
Download File
Random Files
|
File Name: Trend Micro Hijack This In Category: Anti-malware Tools |
File Name: Kernel Detective In Category: Anti-malware Tools |
File Name: Default Document Fix for Office 2007 In Category: Software Tools |
Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or start a new topic of your own. Joining allows you to enjoy all this forum has to offer. Learn more in our 
Upload File
Add to favorites
View admin's other files
Comments
dianedmk
05 June 2008 - 06:13 PM | #1HM2K
21 April 2009 - 08:25 AM | #2Quote
08/17/2008
Your Geeks to Go admin team
Is there no update?
Since it's made using AutoIt3, can't someone just get the au3 file, and release it as open source?
If the author could kindly contact me, that'd be useful.
Thanks.
admin
06 May 2009 - 11:02 PM | #3Guest
29 May 2009 - 01:04 AM | #4Guest
24 November 2009 - 09:16 AM | #5' date=, on date=, said:
learning_to_fly
12 December 2009 - 07:37 AM | #6' date=, on date=, said:
You "said" a MOUTHFULL!!!!
Guest
14 December 2009 - 04:52 PM | #7Quote
From date=:
Jayman01
11 February 2010 - 09:32 PM | #8