Malware

Rogue.ErrorWiz removal tips

Malware Removal

The Rogue.ErrorWiz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rogue.ErrorWiz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

How to determine Rogue.ErrorWiz?


File Info:

name: C138AB2EA910757FC3A4.mlw
path: /opt/CAPEv2/storage/binaries/37872b63443bffe967f220b731e73feedbf82796631a8c3289d60eaa1b939bee
crc32: 322B43D3
md5: c138ab2ea910757fc3a4500cfb468dc4
sha1: 7cc128ecf645a412994d80d32eade3fa88f1a555
sha256: 37872b63443bffe967f220b731e73feedbf82796631a8c3289d60eaa1b939bee
sha512: 6add3f5a0657eb4f163ade694fba4e1b6e53cc02e9518308dffbd9a50ef8a6824c5bff16b56d0ff9aad06e0877f62210119f05268e93fa05e7fc55b584155bc8
ssdeep: 49152:Z2gQCH95I/CXGYTWL0ernhtTsbJtOt0uRdCtjVwWzKslGSOztodL:MJCH9W/Cr6L3T+a0wdWVwkKslGSkoJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19EB5330797725679EA510AB5819EF62BEE7B9D0033B72408306E3C1FBFB67414D0639A
sha3_384: 105296372d4f49a88a32f24c2716622556570315fcf5e7fbb2d6b934db6376bb39f34ea62c8a4b577eb7453c96879d75
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: SolidQuest Inc.
FileDescription: ErrorWiz Setup
FileVersion:
LegalCopyright:
ProductName: ErrorWiz
ProductVersion:
Translation: 0x0000 0x04b0

Rogue.ErrorWiz also known as:

LionicHacktool.Win32.DeceptPCClean.3!c
DrWebProgram.Unwanted.1282
MicroWorld-eScanTrojan.GenericKD.32231797
FireEyeTrojan.GenericKD.32231797
McAfeeArtemis!C138AB2EA910
CylanceUnsafe
ZillyaTool.DeceptPCClean.Win32.1497
K7AntiVirusRiskware ( dec000381 )
AlibabaAdWare:Win32/Fraudpack.d9922748
K7GWRiskware ( dec000381 )
Cybereasonmalicious.ea9107
VirITDeceptor.ErrorWiz.F
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.R002C0DIG21
Paloaltogeneric.ml
KasperskyHoax.Win32.DeceptPCClean.pp
BitDefenderTrojan.GenericKD.32231797
NANO-AntivirusRiskware.Win32.ErrorWiz.ewdirc
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan-psw.Deceptpcclean.Suxc
Ad-AwareTrojan.GenericKD.32231797
SophosMal/Generic-R + Troj/Decept-EP
ComodoApplicUnwnt@#2ogdboj73kr5z
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DIG21
McAfee-GW-EditionArtemis!PUP
EmsisoftTrojan.GenericKD.32231797 (B)
GDataTrojan.GenericKD.32231797
JiangminHoax.DeceptPCClean.ajl
WebrootPUA.Gen
AviraTR/Fraudpack.gxj
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftMisleading:Win32/Tockeror
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.32231797
MAXmalware (ai score=100)
MalwarebytesRogue.ErrorWiz
FortinetRiskware/ErrorWiz
AVGWin32:Adware-gen [Adw]
PandaPUP/ErrorWiz

How to remove Rogue.ErrorWiz?

Rogue.ErrorWiz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment