Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Siggen30.6119

Добавлен в вирусную базу Dr.Web: 2024-11-19

Описание добавлено:

Technical Information

To ensure autorun and distribution
Sets the following service settings
  • [HKLM\System\CurrentControlSet\Services\WiseBootAssistant] 'Start' = '00000002'
  • [HKLM\System\CurrentControlSet\Services\WiseBootAssistant] 'ImagePath' = '%ProgramFiles(x86)%\Wise\Wise Care 365\BootTime.exe'
Creates the following services
  • 'WiseBootAssistant' %ProgramFiles(x86)%\Wise\Wise Care 365\BootTime.exe
Modifies file system
Creates the following files
  • %TEMP%\rarsfx0\cybermania.url
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-l69ng.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-u2347.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-8u871.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-lc85d.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-sgged.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-qmchn.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-34uhi.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\is-ou7jo.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-efg8r.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-716ng.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-p515e.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-s47jc.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-3cr2a.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-i84r9.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-bo7vc.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-4tqo3.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-b020k.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-dqrt2.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-vp0t3.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-qlga4.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-4jedh.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-afkrd.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-n6481.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-dl5bd.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-d5nhe.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-cgppr.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-7jhn6.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-vcka1.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-ohb8a.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-ic7fp.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-3kbbt.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-cmqkn.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-k8qe2.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-hk2f0.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-9cvuv.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-e066v.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-1u9d7.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-phq6r.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-61bg5.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-ku7ut.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-18fm5.tmp
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\wise care 365\wise care 365.lnk
  • %ALLUSERSPROFILE%\microsoft\windows\start menu\programs\wise care 365\uninstall wise care 365.lnk
  • C:\users\public\desktop\wise care 365.lnk
  • %TEMP%\is-tqr1o.tmp\introduce.url
  • %ProgramFiles(x86)%\wise\wise care 365\unins000.msg
  • %ProgramFiles(x86)%\wise\wise care 365\is-isaot.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-3dj98.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\unins000.dat
  • %TEMP%\etilqs_hxmldu9hhjmp1yi
  • %TEMP%\etilqs_v1pjqnbojjgdrma
  • %TEMP%\etilqs_hsdlfktf9heezuf
  • %TEMP%\etilqs_xixdifbym0bdbel
  • %TEMP%\etilqs_6k5vdxmsycdk5j7
  • %TEMP%\etilqs_nm7u18oj8aagxy2
  • %TEMP%\etilqs_lhgrluqbthzrtza
  • %TEMP%\etilqs_8u80vxzaorwbe93
  • %ProgramFiles(x86)%\wise\wise care 365\is-hrrcg.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-9j5sl.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-rvi2b.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-a887t.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-loasg.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-0q2vl.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-qtpsn.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-bccg8.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-9bht5.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-19um1.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-s2sa1.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-hevbj.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-t5uut.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-r9b1p.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-3nkld.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-dvehn.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-9a92g.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-auj6m.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-9j9cu.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-aaelj.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-1v70q.tmp
  • %TEMP%\etilqs_bawc1fly3dug4hy
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-v0gpn.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-6lork.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-v85d1.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-12s9k.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-g982s.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-1v9k8.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-4nqbg.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-je30v.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-bgvii.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-0u9ps.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-t04p8.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-vvqnp.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-hfafh.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-pe8hh.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-2jjjs.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-83qoo.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-n1lfg.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-rslod.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-r9boc.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-8fc9o.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-afhem.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\is-lk8il.tmp
  • %TEMP%\rarsfx0\activator.7z
  • %TEMP%\rarsfx0\wisecare365.exe
  • %TEMP%\rarsfx0\newpatch.7z
  • %TEMP%\is-e6thu.tmp\wisecare365.tmp
  • %TEMP%\is-tqr1o.tmp\_isetup\_setup64.tmp
  • %TEMP%\is-tqr1o.tmp\license.txt
  • %TEMP%\is-tqr1o.tmp\icon_128.bmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-qllnf.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-30q6n.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-o0f0r.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-s2b5s.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-v5kea.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-oep4p.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-ec8ia.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-qjl89.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-6mqha.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-15qr0.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-krs2n.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-d7lc8.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-fajv4.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-ep0eo.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-l1m5o.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-hrmgt.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-57321.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-efvls.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-7icg8.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-jfrip.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-ma9cd.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-3b98e.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-ooqgj.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-ovst3.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-m4mcs.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-6t1i4.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-rmrrg.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-efjmk.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-r4g6j.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-2venn.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-chqga.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-0d38m.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-93570.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-hff8c.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-rhl3g.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-tvhqd.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-tb6p7.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-foigf.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-c03n1.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-6nij1.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-qcldp.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-o9179.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-442ci.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-85k5n.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-api7n.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-d6a71.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-egidr.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-ual37.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-saaea.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\headers\is-rt7lp.tmp
  • %ProgramFiles(x86)%\wise\wise care 365\languages\is-2e06o.tmp
  • %TEMP%\etilqs_7bqnvjneduidxbu
Sets the 'hidden' attribute to the following files
  • %TEMP%\is-tqr1o.tmp\icon_128.bmp
Deletes the following files
  • %TEMP%\is-tqr1o.tmp\icon_128.bmp
  • %TEMP%\is-tqr1o.tmp\introduce.url
  • %TEMP%\is-tqr1o.tmp\license.txt
  • %TEMP%\is-tqr1o.tmp\_isetup\_setup64.tmp
  • %TEMP%\is-e6thu.tmp\wisecare365.tmp
Moves the following files
  • from %ProgramFiles(x86)%\wise\wise care 365\is-lk8il.tmp to %ProgramFiles(x86)%\wise\wise care 365\unins000.exe
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-qmchn.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\turkish.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-sgged.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\thai.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-lc85d.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\swedish(sweden).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-8u871.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\spanish(spain).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-u2347.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\slovenian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-l69ng.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\slovak.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-b020k.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\serbian(cyrillic).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-vp0t3.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\russian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-1u9d7.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\romanian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-ohb8a.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\portuguese(portugal).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-e066v.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\portuguese(brazil).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-9cvuv.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\polish.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-hk2f0.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\persian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-k8qe2.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\norwegian(nynorsk).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-34uhi.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\ukrainian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-cmqkn.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\norwegian(bokmal).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-ic7fp.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\lithuanian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-vcka1.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\kurdish.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-qlga4.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\korean.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-7jhn6.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\japanese.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-cgppr.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\italian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-d5nhe.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\indonesian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-dl5bd.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\hungarian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-n6481.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\hebrew.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-afkrd.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\greek.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-4jedh.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\german.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-1v70q.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\georgian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-v0gpn.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\french.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-2e06o.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\finnish.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-6lork.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\english.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-3kbbt.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\nepali.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-dqrt2.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\vietnamese.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\is-ou7jo.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\toolsv6.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-716ng.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\img\autoshutdown.svg
  • from %ProgramFiles(x86)%\wise\wise care 365\is-19um1.tmp to %ProgramFiles(x86)%\wise\wise care 365\skin.ico
  • from %ProgramFiles(x86)%\wise\wise care 365\is-hevbj.tmp to %ProgramFiles(x86)%\wise\wise care 365\sqlite3.dll
  • from %ProgramFiles(x86)%\wise\wise care 365\is-aaelj.tmp to %ProgramFiles(x86)%\wise\wise care 365\wisebootbooster.exe
  • from %ProgramFiles(x86)%\wise\wise care 365\is-t5uut.tmp to %ProgramFiles(x86)%\wise\wise care 365\wisecare365.exe
  • from %ProgramFiles(x86)%\wise\wise care 365\is-r9b1p.tmp to %ProgramFiles(x86)%\wise\wise care 365\wisedefrag.dll
  • from %ProgramFiles(x86)%\wise\wise care 365\is-3nkld.tmp to %ProgramFiles(x86)%\wise\wise care 365\wiseeraser.dll
  • from %ProgramFiles(x86)%\wise\wise care 365\is-9a92g.tmp to %ProgramFiles(x86)%\wise\wise care 365\libeay32.dll
  • from %ProgramFiles(x86)%\wise\wise care 365\is-3dj98.tmp to %ProgramFiles(x86)%\wise\wise care 365\protect.db
  • from %ProgramFiles(x86)%\wise\wise care 365\is-auj6m.tmp to %ProgramFiles(x86)%\wise\wise care 365\ssleay32.dll
  • from %ProgramFiles(x86)%\wise\wise care 365\is-9j9cu.tmp to %ProgramFiles(x86)%\wise\wise care 365\wjslib.dll
  • from %ProgramFiles(x86)%\wise\wise care 365\is-rvi2b.tmp to %ProgramFiles(x86)%\wise\wise care 365\wisetray.exe
  • from %ProgramFiles(x86)%\wise\wise care 365\is-9j5sl.tmp to %ProgramFiles(x86)%\wise\wise care 365\wiseturbo.exe
  • from %ProgramFiles(x86)%\wise\wise care 365\is-hrrcg.tmp to %ProgramFiles(x86)%\wise\wise care 365\themes_v7.txt
  • from %ProgramFiles(x86)%\wise\wise care 365\is-isaot.tmp to %ProgramFiles(x86)%\wise\wise care 365\bootlauncher.exe
  • from %ProgramFiles(x86)%\wise\wise care 365\is-9bht5.tmp to %ProgramFiles(x86)%\wise\wise care 365\rate.info
  • from %ProgramFiles(x86)%\wise\wise care 365\is-bccg8.tmp to %ProgramFiles(x86)%\wise\wise care 365\autoupdate.exe
  • from %ProgramFiles(x86)%\wise\wise care 365\is-qtpsn.tmp to %ProgramFiles(x86)%\wise\wise care 365\license.txt
  • from %ProgramFiles(x86)%\wise\wise care 365\is-0q2vl.tmp to %ProgramFiles(x86)%\wise\wise care 365\fileshredder.ico
  • from %ProgramFiles(x86)%\wise\wise care 365\is-loasg.tmp to %ProgramFiles(x86)%\wise\wise care 365\defragoptions.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\is-a887t.tmp to %ProgramFiles(x86)%\wise\wise care 365\boottime.exe
  • from %ProgramFiles(x86)%\wise\wise care 365\is-s2sa1.tmp to %ProgramFiles(x86)%\wise\wise care 365\bootpack.wpk
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-ku7ut.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\img\reminder.svg
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-61bg5.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\img\programuninstaller.svg
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-phq6r.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\img\memoryoptimizer.svg
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-efg8r.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\img\imagex.svg
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-4tqo3.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\img\gamebooster.svg
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-bo7vc.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\img\forcedeleter.svg
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-i84r9.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\img\folderhider.svg
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-3cr2a.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\img\fastsearch.svg
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-s47jc.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\img\duplicatefinder.svg
  • from %ProgramFiles(x86)%\wise\wise care 365\tools\img\is-p515e.tmp to %ProgramFiles(x86)%\wise\wise care 365\tools\img\daterecovery.svg
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-efjmk.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\dutch(nederlands).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\is-dvehn.tmp to %ProgramFiles(x86)%\wise\wise care 365\dmanager.dll
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-rmrrg.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\dutch(belgium).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-57321.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\arabic.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-krs2n.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\g6.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-t04p8.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\g5.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-rslod.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\g4.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-n1lfg.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\g3.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-83qoo.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\g2.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-2jjjs.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\g1.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-pe8hh.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\f7.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-hfafh.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\f6.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-vvqnp.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\f5.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-0u9ps.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\f4.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-8fc9o.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\f3.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-bgvii.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\f2.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-je30v.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\f1.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-4nqbg.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\f0.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-d7lc8.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\g7.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-1v9k8.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\e9.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-12s9k.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\e7.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-v85d1.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\d7.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-r9boc.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\d4.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-afhem.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\d3.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-15qr0.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\d2.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-30q6n.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\d1.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-6mqha.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\c7.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-qjl89.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\c4.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-ec8ia.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\b5.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-oep4p.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\a9.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-v5kea.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\a7.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-s2b5s.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\a6.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-o0f0r.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\a2.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-qllnf.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\a1.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-g982s.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\e8.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-fajv4.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\g8.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-qcldp.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\h1.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-hff8c.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\h2.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-chqga.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\j3.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-jfrip.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\j4.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-ma9cd.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\j6.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-ep0eo.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\j7.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-l1m5o.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\j8.png
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-hrmgt.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\abkhazian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-efvls.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\azerbaijani(latin).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-m4mcs.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\czech.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-7icg8.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\belarusian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-3b98e.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\bulgarian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-r4g6j.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\catalan.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-2venn.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\chinese(simplified).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-ooqgj.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\chinese(traditional).ini
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-ovst3.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\croatian.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-0d38m.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\j1.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-93570.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\j0.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-saaea.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\j.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-ual37.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\i8.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-egidr.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\i7.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-d6a71.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\i6.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-api7n.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\i5.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-85k5n.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\i4.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-442ci.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\i3.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-rt7lp.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\i2.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-o9179.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\i1.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-6nij1.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\h8.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-c03n1.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\h7.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-foigf.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\h6.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-tb6p7.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\h5.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-tvhqd.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\h4.png
  • from %ProgramFiles(x86)%\wise\wise care 365\headers\is-rhl3g.tmp to %ProgramFiles(x86)%\wise\wise care 365\headers\h3.png
  • from %ProgramFiles(x86)%\wise\wise care 365\languages\is-6t1i4.tmp to %ProgramFiles(x86)%\wise\wise care 365\languages\danish.ini
  • from %ProgramFiles(x86)%\wise\wise care 365\is-18fm5.tmp to %ProgramFiles(x86)%\wise\wise care 365\webview2loader.dll
Network activity
Connects to
  • 'google.com':80
  • 's.##mg.com':443
  • 'ro###.ebay.com':443
  • 'ro###.ebay.com':80
  • 'sd#####es.operacdn.com':443
  • 'ya###.opera.com':80
  • 'ft##pps.dev':443
  • 'fa###ook.com':80
  • 're###.opera.com':443
  • 're###.opera.com':80
  • 'bo##ing.com':80
  • 'si#####ck2.opera.com':80
  • 'en.###ipedia.org':80
  • 'am##on.com':443
  • 'au######te.geo.opera.com':443
  • 'se####.yahoo.com':443
  • 'bing.com':80
  • 'am##on.com':80
  • 'du###uckgo.com':443
  • 'se####.yahoo.com':80
  • 'au######te.geo.opera.com':80
  • 'en.###ipedia.org':443
  • 'bo##ing.com':443
TCP
HTTP GET requests
  • http://www.google.com/favicon.ico
  • http://www.tw##ter.com/fz139/?pa################
  • http://www.tw##ter.com/?pa################
  • http://www.ya##o.com/?il#####
  • http://ro###.ebay.com/rover/1/711-53200-19255-0/1?ic###########################################################################################################################
  • http://www.am##on.com/?ta#########################
  • http://re###.opera.com/speeddials/partner/wikipedia_org_us
  • http://re###.opera.com/speeddials/partner/youtube
  • http://re###.opera.com/speeddials/partner/product
  • http://re###.opera.com/speeddials/partner/booking_com_us
  • http://re###.opera.com/speeddials/partner/twitter_us
  • http://re###.opera.com/speeddials/partner/yahoo
  • http://re###.opera.com/speeddials/partner/ebay_us
  • http://www.tw##ter.com/favicon.ico
  • http://re###.opera.com/speeddials/partner/amazon_us
  • http://re###.opera.com/favicon.ico
  • http://www.fa###ook.com/favicon.ico
  • http://www.fa###ook.com/fz139/?ca#########################
  • http://www.fa###ook.com/campaign/landing.php?ca#########################
  • http://re###.opera.com/speeddials/partner/facebook
  • http://re###.opera.com/www.opera.com/firstrun/
  • http://si#####ck2.opera.com/?ho###################################################
  • http://en.###ipedia.org/favicon.ico
  • http://www.bing.com/s/a/bing_p.ico
  • http://www.am##on.com/favicon.ico
  • http://se####.yahoo.com/favicon.ico
  • http://au######te.geo.opera.com/geolocation/
  • http://ya###.opera.com/favicon.ico
  • http://www.bo##ing.com/index.html?ai##########################################################################################
Other
  • 'du###uckgo.com':443
  • 'se####.yahoo.com':443
  • 'au######te.geo.opera.com':443
  • 'am##on.com':443
  • 'en.###ipedia.org':443
  • 'si#####ck2.opera.com':443
  • 'ft##pps.dev':443
  • 'ya###.opera.com':443
  • 'sd#####es.operacdn.com':443
  • 'op##a.com':443
  • 'ro###.ebay.com':443
  • 'ya##o.com':443
  • 'bo##ing.com':443
UDP
  • DNS ASK google.com
  • DNS ASK s.##mg.com
  • DNS ASK ya##o.com
  • DNS ASK ro###.ebay.com
  • DNS ASK sd#####es.operacdn.com
  • DNS ASK op##a.com
  • DNS ASK ya###.opera.com
  • DNS ASK ft##pps.dev
  • DNS ASK fa###ook.com
  • DNS ASK re###.opera.com
  • DNS ASK si#####ck2.opera.com
  • DNS ASK en.###ipedia.org
  • DNS ASK bi##.#ikimedia.org
  • DNS ASK bing.com
  • DNS ASK am##on.com
  • DNS ASK du###uckgo.com
  • DNS ASK se####.yahoo.com
  • DNS ASK au######te.geo.opera.com
  • DNS ASK tw##ter.com
  • DNS ASK bo##ing.com
Miscellaneous
Searches for the following windows
  • ClassName: 'EDIT' WindowName: ''
  • ClassName: 'TFrmTrayMain' WindowName: ''
  • ClassName: 'TFrmWPMain' WindowName: ''
  • ClassName: 'TFrmMOMain' WindowName: ''
  • ClassName: 'Opera_MessageWindow' WindowName: '%APPDATA%\Opera Software\Opera Stable'
Creates and executes the following
  • '%TEMP%\rarsfx0\wisecare365.exe' /silent
  • '%TEMP%\is-e6thu.tmp\wisecare365.tmp' /SL5="$1025A,16714807,857088,%TEMP%\RarSFX0\WiseCare365.exe" /silent
Executes the following
  • '%WINDIR%\syswow64\schtasks.exe' /delete /tn \WiseCleaner\W365SkipUAC /f
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2072.12.420858334\1699336646" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2072.11.1004428097\1787890361" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2072.10.1596413778\1664252517" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2072.9.2006646503\1636135666" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2072.8.1779574153\157011919" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2072.7.1225142977\150542365" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' --type=utility --channel="2072.4.1926502305\406981181" --lang=en-US --no-sandbox --enable-proprietary-media-types-playback /prefetch:-645351001 /crash-reporter-parent-id=2596
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2072.6.1255380507\119731378" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2072.5.1092034474\1558668703" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2072.15.1962708982\747621319" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2072.4.1926502305\406981181" --lang=en-US --no-sandbox --enable-proprietary-media-types-playback /prefetch:-645351001
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=renderer --alt-high-dpi-setting=96 --disable-direct-npapi-requests --enable-deferred-image-decoding --lang=en-US --enable-proprietary-media-types-playback --disable-client-side-phishing-...
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=gpu-process --channel="2072.0.1516698553\1692885188" --enable-proprietary-media-types-playback --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,19,42 --gpu-vendor-id=0x0000 --gp...
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera_crashreporter.exe' -noautoupdate --ran-launcher -- https://ftuapps.dev/ /crash-reporter-parent-id=2072
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' -noautoupdate --ran-launcher -- https://ftuapps.dev/
  • '%ProgramFiles(x86)%\opera\launcher.exe' -noautoupdate -- "https://ftuapps.dev/"
  • '%WINDIR%\syswow64\reg.exe' add "HKLM\SOFTWARE\Classes\CLSID\{1999F9DE-571D-455B-B7C9-C1E9DB51589F}" /v "License Key" /t REG_SZ /d "8E97-AE93-A19E93-8F89-94BC" /f
  • '%WINDIR%\syswow64\reg.exe' add "HKLM\SOFTWARE\Classes\CLSID\{1999F9DE-571D-455B-B7C9-C1E9DB51589F}" /v "User Email" /t REG_SZ /d "1@1.com" /f
  • '%WINDIR%\syswow64\reg.exe' add "HKLM\SOFTWARE\Classes\CLSID\{1999F9DE-571D-455B-B7C9-C1E9DB51589F}" /v "User Name" /t REG_SZ /d "Cyber" /f
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=renderer --alt-high-dpi-setting=96 --disable-direct-npapi-requests --enable-deferred-image-decoding --lang=en-US --enable-proprietary-media-types-playback --extension-process --enable-we...
  • '%ProgramFiles(x86)%\opera\29.0.1795.47\opera.exe' --type=utility --channel="2072.16.1006591516\508478307" --lang=en-US --enable-proprietary-media-types-playback --ignored=" --type=renderer " /prefetch:-645351001
  • '%WINDIR%\syswow64\schtasks.exe' /delete /tn \WiseCleaner\W365SkipUAC /f' (with hidden window)

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке