Double click it to run.
Check the following items:
- suspicious files: compressed with UPX, FSG, Polycrypt, Upack and others
All the rest are already checked.
OK the prompt.
Click "scan now"
OK the prompt.
**Note
This scan will take a while so please be patient.
This tool does not fix anything. it just does a scan and generates a log.
Once done the log should pop up.
C:\suspectfile\report.txt
Post log please. It may take 3 posts to get whole logs in.
As soon as I pressed "Scan now," a notepad popped up titled "ctrld." The Systemscan is blank so I don't know if it is scanning or frozen. The popup said:
Option Explicit
on error resume next
Dim oWS : Set oWS = CreateObject("WScript.Shell")
Dim oFSO : Set oFSO = CreateObject("Scripting.FileSystemObject")
Dim sRegTmp, sOutTmp, eRegLine, aRegFileLines, sSearchFor, sSearchdll, sSearchdll2, sSearchdll3
sRegTmp = oWS.Environment("PROCESS")("SYSTEMDRIVE") & "\suspectfile\files.row "
sOutTmp = oWS.Environment("PROCESS")("SYSTEMDRIVE") & "\suspectfile\report.row"
With oFSO.OpenTextFile(sOutTmp, 8, True)
With oFSO.GetFile(sRegTmp)
aRegFileLines = Split(.OpenAsTextStream(1, 0).Read(.Size), vbcrlf)
End With
For Each eRegLine in aRegFileLines
if left (eregline,1) ="" then .writeline(eregline)
if datediff("d",left(eregline,10),date()) < 60 then
.WriteLine(eregline)
end if
Next
Erase aRegFileLines
.Close
End With
oFSO.DeleteFile(sRegTmp)
Set oWS = Nothing
Set oFSO = Nothing
WScript.Quit
Double-click on comboscan.exe to run it, and follow the prompts.
When the scan is complete, a text file will open - ComboScan.txt
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of ComboScan.txt in your thread in the HijackThis Log Help Forum.
A folder, C:\ComboScan, will also open. In it will be another text file, Supplementary.txt.
Please attach Supplementary.txt to your post.
Note: some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so.
To attach a file to a new post, simply
Click the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, and
copy and paste the following into the "Upload File from your Computer" box:
C:\ComboScan\Supplementary.txt
Click Upload.
What ComboScan will do:
create a new System Restore point in Windows XP and Vista.
clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
check some important areas of your system and produce a report for your analyst to review. ComboScan automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.
LDTate,
The bottom of Systemscan reads "step 1 of 11 in progress." But it seems there is no activity at all. Should I shut this down and follow your above instructions?
The bottom of Systemscan reads "step 1 of 11 in progress." But it seems there is no activity at all. Should I shut this down and follow your above instructions?