Tech question: Combofix

Recommended Videos

BeerTent

Resident Furry Pimp
May 8, 2011
1,167
0
0
My Co-workers suggested Combofix, as a really good antivir program. When I put it to the test, I realized two things.

Either Steam is a problem, and/or I've got a really nasty application in the SysWOW64 folder. Here's a dump log.

c:\users\Grayson\AppData\Roaming\chrtmp
c:\users\Grayson\AppData\Roaming\logs.dat
c:\users\Grayson\AppData\Roaming\SQLite3.dll
c:\windows\SysWow64\html
c:\windows\SysWow64\html\calendar.html
c:\windows\SysWow64\html\calendarbottom.html
c:\windows\SysWow64\html\calendartop.html
c:\windows\SysWow64\html\crystalexportdialog.htm
c:\windows\SysWow64\html\crystalprinthost.html
c:\windows\SysWow64\images
c:\windows\SysWow64\images\toolbar\calendar.gif
c:\windows\SysWow64\images\toolbar\crlogo.gif
c:\windows\SysWow64\images\toolbar\export.gif
c:\windows\SysWow64\images\toolbar\export_over.gif
c:\windows\SysWow64\images\toolbar\exportd.gif
c:\windows\SysWow64\images\toolbar\First.gif
c:\windows\SysWow64\images\toolbar\first_over.gif
c:\windows\SysWow64\images\toolbar\Firstd.gif
c:\windows\SysWow64\images\toolbar\gotopage.gif
c:\windows\SysWow64\images\toolbar\gotopage_over.gif
c:\windows\SysWow64\images\toolbar\gotopaged.gif
c:\windows\SysWow64\images\toolbar\grouptree.gif
c:\windows\SysWow64\images\toolbar\grouptree_over.gif
c:\windows\SysWow64\images\toolbar\grouptreed.gif
c:\windows\SysWow64\images\toolbar\grouptreepressed.gif
c:\windows\SysWow64\images\toolbar\Last.gif
c:\windows\SysWow64\images\toolbar\last_over.gif
c:\windows\SysWow64\images\toolbar\Lastd.gif
c:\windows\SysWow64\images\toolbar\Next.gif
c:\windows\SysWow64\images\toolbar\next_over.gif
c:\windows\SysWow64\images\toolbar\Nextd.gif
c:\windows\SysWow64\images\toolbar\Prev.gif
c:\windows\SysWow64\images\toolbar\prev_over.gif
c:\windows\SysWow64\images\toolbar\Prevd.gif
c:\windows\SysWow64\images\toolbar\print.gif
c:\windows\SysWow64\images\toolbar\print_over.gif
c:\windows\SysWow64\images\toolbar\printd.gif
c:\windows\SysWow64\images\toolbar\Refresh.gif
c:\windows\SysWow64\images\toolbar\refresh_over.gif
c:\windows\SysWow64\images\toolbar\refreshd.gif
c:\windows\SysWow64\images\toolbar\Search.gif
c:\windows\SysWow64\images\toolbar\search_over.gif
c:\windows\SysWow64\images\toolbar\searchd.gif
c:\windows\SysWow64\images\toolbar\up.gif
c:\windows\SysWow64\images\toolbar\up_over.gif
c:\windows\SysWow64\images\toolbar\upd.gif
c:\windows\SysWow64\images\tree\begindots.gif
c:\windows\SysWow64\images\tree\beginminus.gif
c:\windows\SysWow64\images\tree\beginplus.gif
c:\windows\SysWow64\images\tree\blank.gif
c:\windows\SysWow64\images\tree\blankdots.gif
c:\windows\SysWow64\images\tree\dots.gif
c:\windows\SysWow64\images\tree\lastdots.gif
c:\windows\SysWow64\images\tree\lastminus.gif
c:\windows\SysWow64\images\tree\lastplus.gif
c:\windows\SysWow64\images\tree\Magnify.gif
c:\windows\SysWow64\images\tree\minus.gif
c:\windows\SysWow64\images\tree\minusbox.gif
c:\windows\SysWow64\images\tree\plus.gif
c:\windows\SysWow64\images\tree\plusbox.gif
c:\windows\SysWow64\images\tree\singleminus.gif
c:\windows\SysWow64\images\tree\singleplus.gif
d:\steam\Steam.exe

All of these files were removed by combofix, I'm kind of curious as to what these files were for, as it appears to be a website? I really don't know. When I'm sober, my reply will not sound like a confused question. Does anyone else have these files in their SysWow64 filder.

Oh, Shit! I'm using Windows 7 Professional 64!



I've also got 3 side notes.
1. Fair warning, I'm drunk.
Fuck me, the adverts are annoying today, eh?
3. The main tech thread in this forum lists off how big a unit of measurement on a hard drive. It's wrong. A kilobyte is not 1000b, it's 1024b. I kilobit is 1000b, and is used by hardware companies to obscure the actual size of their disks to people who don't know better.


Also, my captcha is "Customer is always right", I would like to disagree. [http://notalwaysright.com/]
 

Ziadaine_v1legacy

Flamboyant Homosexual
Apr 11, 2009
1,603
0
0
SySWoW64 is all the drivers and crap for Windows 7 but they've been converted into 64bit for 64bit versions. Combofix is used for rootkits in the system registry (basically malware that attack the spine), except its was originally designed for Windows XP, not Vista and 7, and should never be used on 64 bit machines.

I used it at my old job.

Basically: Don't use ComboFix unless you know what you're doing. It's like performing open heart surgery on yourself. Your Co-Workers obviously dont know what it does and was randomlly told "hey, this is a cool Anti Virus Program" (It's not an anti-virus program also)