DoesNotBelong

Обзоры DoesNotBelong 9.3.2

Переводчик Google

furtivex updated DoesNotBelong with a new update entry:

Threat names, Userinit, Shell, GroupPolicies, NTuser, Event Viewer Logs Output

  • Finished adding personalized threat names to give the user a better idea of what type of infection they have. Example:
Код:
C:\Users\owner\AppData\Roaming\Microsoft\MicrosoftWeb.{7007BCC7-3202-11D1-AAD2-00E05FC1270E} (TROJ.BTCMiner.GoogleUP)
I couldn't do this everywhere due how the tool functions, but they are added where possible.
  • Fixed an issue where some folders were not being deleted
  • Process whitelist updated to include Emsisoft AV...

Read the rest of this update entry...
 
furtivex updated DoesNotBelong with a new update entry:

Improved Windows Update Repair sequence

In the case of particular miner (TROJ.BTCMiner.GoogleUP) which breaks Windows Update functionality, the tool now stops the relevant services and a few others related to Windows Update before patching the registry for a greater chance of success. Afterwards, the services are restarted. This may eliminate the need for the user to patch the registry in Safe Mode, where those services are already stopped.

Read the rest of this update entry...
 
furtivex updated DoesNotBelong with a new update entry:

Translations,

  • Added translations: Scottish Gaelic & Filipino
  • Added automatic cleanup for MountPoints2 registry keys.
  • Added a network repair routine for a particular case of ReasonLabs DNS install
  • Added Packages (AppXPackages) automatic clean up
  • Added automatic cleanup and repair of Authentication Packages registry value (often used by ScreenConnect)
Код:
HKLM\System\CurrentControlSet\Control\Lsa\\Authentication Packages value was missing -> restored...

Read the rest of this update entry...
 
furtivex updated DoesNotBelong with a new update entry:

Process Handling and Bug Fixes

DoesNotBelong Changelog
=====================

v9.3.2 (10.05.2025)
- Database update

v9.3.1 (10.05.2025)
  • Improved Stage 1 - Process killing. Any console errors should now be gone. Tested on Windows 10 and 11 x64
  • On newer systems without WMIC.exe, powershell.exe is now able to terminate suspicious processes impersonating legitimate files even if they include encoded UTF8 - UTF16 filepaths. This should alleviate all previous 'binary file matches' found in logs
  • Fixed a bug that...

Read the rest of this update entry...
 
Назад
Сверху Снизу