Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Hosts.44630

Добавлен в вирусную базу Dr.Web: 2018-05-04

Описание добавлено:

Technical Information

To ensure autorun and distribution:
Creates the following services:
  • [<HKLM>\SYSTEM\ControlSet001\Services\WiseBootAssistant] 'Start' = '00000002'
  • [<HKLM>\SYSTEM\ControlSet001\Services\WiseBootAssistant] 'ImagePath' = '%ProgramFiles%\Wise\Wise Care 365\BootTime.exe'
Malicious functions:
Executes the following:
  • '<SYSTEM32>\taskkill.exe' /f /im WiseCare365.exe
Modifies file system:
Creates the following files:
  • %TEMP%\aut1.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-A5CHQ.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-S4C4I.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-D0JOF.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-OIIB9.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Themes\is-1RDLK.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-P2HPR.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-E5TB4.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Themes\is-G7A6H.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\is-VVJ62.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\is-VQ2NN.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-JOFU9.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-H8N6B.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-61TIS.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Themes\is-T64DC.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Themes\is-PB9AP.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-J0NN1.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-PE4ET.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-6S01H.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-ULMIF.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-KEDMV.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-I4H0P.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-HINI1.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-00E9L.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-9FM61.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-M0ED7.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-VVKJ4.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-LUKIB.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-SQ5SC.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-80KPP.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-44155.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-34FN7.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-OLKFN.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-U97GP.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-UKG6R.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-Q21EN.tmp
  • %APPDATA%\Wise Care 365\config.ini
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-MV0FR.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-2D78M.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-PMIG4.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-4JVGG.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-FJGQK.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-900MG.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-SPVRC.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-LVBU2.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-APMG5.tmp
  • %ALLUSERSPROFILE%\Start Menu\Programs\Wise Care 365\Wise Care 365.lnk
  • %ALLUSERSPROFILE%\Desktop\Wise Care 365.lnk
  • %TEMP%\is-3RTP1.tmp\introduce.url
  • %ProgramFiles%\Wise\Wise Care 365\unins000.msg
  • %ProgramFiles%\Wise\Wise Care 365\unins000.dat
  • %ProgramFiles%\Wise\Wise Care 365\is-QOBNM.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-GO71I.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-187A3.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-1H1G3.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-64MS4.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-TU6V5.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-2148N.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-750KN.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-U77U0.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-VHJEK.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-PBOD0.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-UHCMM.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-51HT7.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-29OP3.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-QHP8C.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-98L93.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-G19HU.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-58VOB.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-VGARJ.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-HDT7F.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-SVEA0.tmp
  • %ProgramFiles%\Wise\Wise Care 365\tools\img\is-8LIKV.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-M1UTD.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-N8EVO.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-E0QQS.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-POU2C.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-O0I01.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-0IGDL.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-A8MG0.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-KA93T.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-B3H21.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-5C2IS.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-7BIVR.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-T1JP7.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-Q8F87.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-BUM4G.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-5AK88.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-R2BLI.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-J9087.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-01P6U.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-U326Q.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-Q3K6K.tmp
  • %TEMP%\is-3NPIC.tmp\~gzjcxjr.tmp
  • %ProgramFiles%\Wise\Wise Care 365\is-FBMIB.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-4O5E3.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-VFMB5.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-GTJNL.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-QVQUD.tmp
  • %CommonProgramFiles%\~gzjcxjr.ibo
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-CAC9D.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-CQFGB.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-I0ESR.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-L1TGL.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-CO6TV.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-S4VJR.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-MIJ1E.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-8DDEM.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-UKTA4.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-8V598.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-DU8AG.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-1UIAS.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-ORSFN.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-0KVTO.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-EG394.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-1OMSB.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-9BEVL.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-A4Q3U.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-UF7NB.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-0QU0H.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-MELG6.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-DU2M6.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-BBDHC.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-0KOBK.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-0UTA2.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-OP1M1.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-QSMNR.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-4ML63.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-1U5BJ.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-4TSB4.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-CEK7U.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-VBKH5.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-K07DH.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-DF52L.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-2GTGH.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-4PKB2.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-KRFEB.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-J1TPV.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-VASD8.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-NUKPL.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-N9TTT.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-2QVIH.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-DIJLR.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-4ORJM.tmp
  • %ProgramFiles%\Wise\Wise Care 365\headers\is-ED9NQ.tmp
  • %ProgramFiles%\Wise\Wise Care 365\Languages\is-6A2LU.tmp
  • %APPDATA%\Wise Care 365\config_tray.ini
Sets the 'hidden' attribute to the following files:
  • %CommonProgramFiles%\~gzjcxjr.ibo
Deletes the following files:
  • %TEMP%\aut1.tmp
  • %TEMP%\is-3RTP1.tmp\introduce.url
  • %TEMP%\is-3NPIC.tmp\~gzjcxjr.tmp
Moves the following files:
  • from %ProgramFiles%\Wise\Wise Care 365\is-FBMIB.tmp to %ProgramFiles%\Wise\Wise Care 365\unins000.exe
  • from %ProgramFiles%\Wise\Wise Care 365\Themes\is-PB9AP.tmp to %ProgramFiles%\Wise\Wise Care 365\Themes\halloween-2016.wskn
  • from %ProgramFiles%\Wise\Wise Care 365\Themes\is-T64DC.tmp to %ProgramFiles%\Wise\Wise Care 365\Themes\halloween-2016.png
  • from %ProgramFiles%\Wise\Wise Care 365\Themes\is-G7A6H.tmp to %ProgramFiles%\Wise\Wise Care 365\Themes\default.wskn
  • from %ProgramFiles%\Wise\Wise Care 365\Themes\is-1RDLK.tmp to %ProgramFiles%\Wise\Wise Care 365\Themes\chinese-new-year-2018.wskn
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-OIIB9.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Vietnamese.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-D0JOF.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Ukrainian.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-S4C4I.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Turkish.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-A5CHQ.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Thai.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-E5TB4.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Swedish(Sweden).ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-P2HPR.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Spanish(Spain).ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-J0NN1.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Slovenian.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-PE4ET.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Slovak.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-6S01H.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Serbian(Cyrillic).ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-OLKFN.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Russian.ini
  • from %ProgramFiles%\Wise\Wise Care 365\tools\is-VVJ62.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\toolsv3.txt
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-34FN7.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Romanian.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-80KPP.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Portuguese(Brazil).ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-SQ5SC.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Polish.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-LUKIB.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Persian.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-U97GP.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Norwegian(Nynorsk).ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-VVKJ4.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Norwegian(Bokmal).ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-9FM61.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Nepali.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-00E9L.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Kurdish.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-HINI1.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Korean.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-I4H0P.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Japanese.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-KEDMV.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Italian.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-ULMIF.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Hungarian.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-M0ED7.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Greek.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-SVEA0.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\German.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-M1UTD.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Georgian.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-44155.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Portuguese(Portugal).ini
  • from %ProgramFiles%\Wise\Wise Care 365\tools\is-VQ2NN.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\toolsv3.zip
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-JOFU9.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\AutoShutdown.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-H8N6B.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\DateRecovery.png
  • from %ProgramFiles%\Wise\Wise Care 365\is-G19HU.tmp to %ProgramFiles%\Wise\Wise Care 365\AutoUpdate.exe
  • from %ProgramFiles%\Wise\Wise Care 365\is-58VOB.tmp to %ProgramFiles%\Wise\Wise Care 365\Rate.info
  • from %ProgramFiles%\Wise\Wise Care 365\is-VGARJ.tmp to %ProgramFiles%\Wise\Wise Care 365\skin.ico
  • from %ProgramFiles%\Wise\Wise Care 365\is-64MS4.tmp to %ProgramFiles%\Wise\Wise Care 365\sqlite3.dll
  • from %ProgramFiles%\Wise\Wise Care 365\is-1H1G3.tmp to %ProgramFiles%\Wise\Wise Care 365\UninstallTP.exe
  • from %ProgramFiles%\Wise\Wise Care 365\is-187A3.tmp to %ProgramFiles%\Wise\Wise Care 365\WiseBootBooster.exe
  • from %ProgramFiles%\Wise\Wise Care 365\is-LVBU2.tmp to %ProgramFiles%\Wise\Wise Care 365\WiseDefrag.dll
  • from %ProgramFiles%\Wise\Wise Care 365\is-QOBNM.tmp to %ProgramFiles%\Wise\Wise Care 365\geo.db
  • from %ProgramFiles%\Wise\Wise Care 365\is-2D78M.tmp to %ProgramFiles%\Wise\Wise Care 365\WiseEraser.dll
  • from %ProgramFiles%\Wise\Wise Care 365\is-PMIG4.tmp to %ProgramFiles%\Wise\Wise Care 365\DManager.dll
  • from %ProgramFiles%\Wise\Wise Care 365\is-4JVGG.tmp to %ProgramFiles%\Wise\Wise Care 365\libeay32.dll
  • from %ProgramFiles%\Wise\Wise Care 365\is-FJGQK.tmp to %ProgramFiles%\Wise\Wise Care 365\ssleay32.dll
  • from %ProgramFiles%\Wise\Wise Care 365\is-900MG.tmp to %ProgramFiles%\Wise\Wise Care 365\WiseTray.exe
  • from %ProgramFiles%\Wise\Wise Care 365\is-APMG5.tmp to %ProgramFiles%\Wise\Wise Care 365\WiseTurbo.exe
  • from %ProgramFiles%\Wise\Wise Care 365\is-98L93.tmp to %ProgramFiles%\Wise\Wise Care 365\License.txt
  • from %ProgramFiles%\Wise\Wise Care 365\is-QHP8C.tmp to %ProgramFiles%\Wise\Wise Care 365\fileshredder.ico
  • from %ProgramFiles%\Wise\Wise Care 365\is-29OP3.tmp to %ProgramFiles%\Wise\Wise Care 365\DefragOptions.ini
  • from %ProgramFiles%\Wise\Wise Care 365\is-HDT7F.tmp to %ProgramFiles%\Wise\Wise Care 365\BootTime.exe
  • from %ProgramFiles%\Wise\Wise Care 365\is-51HT7.tmp to %ProgramFiles%\Wise\Wise Care 365\BootPack.wpk
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-PBOD0.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\wrm32.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-VHJEK.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\wgb32.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-U77U0.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\SystemMonitor.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-750KN.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\Reminder.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-2148N.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\ProgramUninstaller.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-TU6V5.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\MemoryOptimizer.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-UHCMM.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\JetSearch.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-MV0FR.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\Hotkey.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-Q21EN.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\GameBooster.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-8LIKV.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\ForceDeleter.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-UKG6R.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\FolderHider.png
  • from %ProgramFiles%\Wise\Wise Care 365\tools\img\is-61TIS.tmp to %ProgramFiles%\Wise\Wise Care 365\tools\img\DuplicateFinder.png
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-6A2LU.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\French.ini
  • from %ProgramFiles%\Wise\Wise Care 365\is-SPVRC.tmp to %ProgramFiles%\Wise\Wise Care 365\WiseCare365.exe
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-DU8AG.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Finnish.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-1OMSB.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Belarusian.ini
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-5AK88.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\g6.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-BUM4G.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\g5.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-Q8F87.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\g4.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-T1JP7.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\g3.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-7BIVR.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\g2.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-J9087.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\g1.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-R2BLI.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\f7.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-5C2IS.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\f6.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-A8MG0.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\f5.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-0IGDL.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\f4.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-O0I01.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\f3.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-POU2C.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\f2.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-E0QQS.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\f1.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-B3H21.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\f0.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-UKTA4.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\g7.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-KA93T.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\e9.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-U326Q.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\e7.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-Q3K6K.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\d7.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-MIJ1E.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\d4.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-S4VJR.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\d3.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-CO6TV.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\d2.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-L1TGL.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\d1.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-I0ESR.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\c7.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-CQFGB.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\c4.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-8DDEM.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\b5.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-CAC9D.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\a9.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-QVQUD.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\a7.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-GTJNL.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\a6.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-VFMB5.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\a2.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-4O5E3.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\a1.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-01P6U.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\e8.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-N8EVO.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\g8.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-8V598.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\h1.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-1UIAS.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\h2.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-4ML63.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\j3.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-A4Q3U.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\j4.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-UF7NB.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\j6.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-ORSFN.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\j7.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-0KVTO.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\j8.png
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-EG394.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Azerbaijan(Latin).ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-9BEVL.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Bulgarian.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-0KOBK.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Dutch(Nederlands).ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-0QU0H.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Catalan.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-OP1M1.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Chinese(Simplified).ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-QSMNR.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Chinese(Traditional).ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-MELG6.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Czech.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-DU2M6.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Danish.ini
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-BBDHC.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\Dutch(Belgium).ini
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-1U5BJ.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\j1.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-4TSB4.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\j0.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-4ORJM.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\j.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-DIJLR.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\i8.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-2QVIH.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\i7.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-N9TTT.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\i6.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-NUKPL.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\i5.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-VASD8.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\i4.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-ED9NQ.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\i3.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-J1TPV.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\i2.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-4PKB2.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\i1.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-2GTGH.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\h8.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-DF52L.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\h7.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-K07DH.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\h6.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-VBKH5.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\h5.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-CEK7U.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\h4.png
  • from %ProgramFiles%\Wise\Wise Care 365\headers\is-KRFEB.tmp to %ProgramFiles%\Wise\Wise Care 365\headers\h3.png
  • from %ProgramFiles%\Wise\Wise Care 365\Languages\is-0UTA2.tmp to %ProgramFiles%\Wise\Wise Care 365\Languages\English.ini
  • from %ProgramFiles%\Wise\Wise Care 365\is-GO71I.tmp to %ProgramFiles%\Wise\Wise Care 365\BootLauncher.exe
Modifies the HOSTS file.
Miscellaneous:
Searches for the following windows:
  • ClassName: 'TFrmTrayMain' WindowName: ''
  • ClassName: 'TFrmWPMain' WindowName: ''
  • ClassName: 'TFrmMOMain' WindowName: ''
  • ClassName: '' WindowName: ''
Creates and executes the following:
  • '%CommonProgramFiles%\~gzjcxjr.ibo' /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
  • '%TEMP%\is-3NPIC.tmp\~gzjcxjr.tmp' /SL5="$100E2,8276460,131584,%CommonProgramFiles%\~gzjcxjr.ibo" /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
  • '%ProgramFiles%\Wise\Wise Care 365\BootTime.exe'
Executes the following:
  • '<SYSTEM32>\cmd.exe' /c sc stop WiseBootAssistant
  • '<SYSTEM32>\sc.exe' stop WiseBootAssistant
  • '<SYSTEM32>\cmd.exe' /c sc delete WiseBootAssistant
  • '<SYSTEM32>\sc.exe' delete WiseBootAssistant

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке