• Added translations: Scottish Gaelic & Filipino
  • Added automatic cleanup for MountPoints2 registry keys.
  • Added a network repair routine for a particular case of ReasonLabs DNS install
  • Added Packages (AppXPackages) automatic clean up
  • Added automatic cleanup and repair of Authentication Packages registry value (often used by ScreenConnect)
Код:
HKLM\System\CurrentControlSet\Control\Lsa\\Authentication Packages value was missing -> restored
HKLM\System\CurrentControlSet\Control\Lsa\\Authentication Packages value contained extras -> restored
  • Like
Реакции: akok
In the case of particular miner (TROJ.BTCMiner.GoogleUP) which breaks Windows Update functionality, the tool now stops the relevant services and a few others related to Windows Update before patching the registry for a greater chance of success. Afterwards, the services are restarted. This hopefully eliminates the need for the user to patch the registry in Safe Mode, where those services are already in a stopped state.
  • Like
Реакции: Guest и akok
  • Updated task whitelist: Microsoft Intune related tasks
  • Database update
  • Like
Реакции: Guest
  • Database update
  • Added telemetry services from HP.
  • The tool no longer creates a restore point. It is recommended to create your own Restore Point or volume snapshot before running the tool if you are concerned about losing something important.
  • Like
Реакции: Guest
  • Finished adding personalized threat names to give the user a better idea of what type of infection they have. Example:
Код:
C:\Users\owner\AppData\Roaming\Microsoft\MicrosoftWeb.{7007BCC7-3202-11D1-AAD2-00E05FC1270E} (TROJ.BTCMiner.GoogleUP)
I couldn't do this everywhere due how the tool functions, but they are added where possible.
  • Fixed an issue where some folders were not being deleted
  • Process whitelist updated to include Emsisoft AV
  • HKLM...\Winlogon [Shell] and [Userinit] values checked and repairs made
  • Clearing the event viewer logs is now logged and some other logging has been revised. Example:
Код:
# Miscellaneous:

[?] AntiVirus Software: Windows Defender
[?] Event Viewer Logs were cleared
[?] Restore Point: Does Not Belong PRESCAN - Created
  • Database updated
  • Like
Реакции: Guest
-Database update
- Optimizations done by removing a couple of redundant searches
  • Like
Реакции: Guest
v7.8.2+ includes a check to ensure the user is running the latest version. Fetches the update if it's available.
  • Like
Реакции: Guest
Old name: Furtivex Malware Removal Script
Newer name: DoesNotBelong
  • Like
Реакции: Vvvyg и Guest
Several updates lately have been more focused on improving the chance that FMRS will run and complete its job on the system.
  • Process whitelist updated
  • Database updated
  • Shortcut cleaning (repair) for relevant infection which hijacks shortcut arguments as persistence mechanism
  • Output of particularly difficult / stubborn infections has been updated and the list reduced
  • Like
Реакции: Guest
v7.3.0
  • Fixed a couple of false positives. A .DLL from CyberLink's WaveEditor and folder related to 'SketchUp'
  • Process whitelist expanded. This in attempt to resolve BSODs some users may experienced running the tool
  • Attempted to fix a bug that prevents Task Scheduler detection and deletion to not occur on languages aside from English. Based on recent reports I've read, this is resolved.
  • NEW feature: Cleanup World of Warcraft junk / cache folders described in article here. Saves ~50GB storage automatically if the game is installed in the default location.
  • Database updates
  • Like
Реакции: Guest
Назад
Сверху Снизу