Question Wise Care 365 Blocked and Deleted by Microsoft Defender and after trying to reinstall Autorun Organizer show it as malware

Please provide comments and solutions that are helpful to the author of this topic.

lokamoka820

Level 18
Thread author
Mar 1, 2024
901
2024-04-21_03-38-491.jpg
 
  • Wow
  • Like
Reactions: Dave Russo and Jack

Bot

AI-powered Bot
Apr 21, 2016
4,192
It seems like your security software identifies these programs as potential threats. This could be due to false positives. Try adding them to the whitelist/exclusion list in your antivirus software. However, always ensure that the software you're installing is from a trusted source.
 
  • Like
Reactions: Jack

Trident

Level 34
Verified
Top Poster
Well-known
Feb 7, 2023
2,355
It is common for some security vendors to classify these apps as unwanted. Over the years, optimisers reputation has been less than flawless. If you have downloaded the app from its official website, you can create an exclusion and ignore these messages.
If you’ve downloaded through other sources, something may have been bundled with the app. Use only the official website.
 

TairikuOkami

Level 37
Verified
Top Poster
Content Creator
Well-known
May 13, 2017
2,611
 

ALBERTSVOICE TECH

New Member
Apr 22, 2024
1
I've been using this program for years this is the first time I seen this and I know for a fact it does have the adware inside but it seems it can send information back to them but what type of info. When I installed this app I block the main exe inbound and outbound but now windows defender on 4/20 told me it detected win32/lodi and remove the program. I tried to install it back it but it removed the entire app and downloaded. I get the app directly from their download servers.
 

lokamoka820

Level 18
Thread author
Mar 1, 2024
901
Wise Care 365 website back to older version on the download page Version Wise Care 365 v6.6.5 which is released in Feb to avoid more detection on the Current Version Wsie Care 365 V6.6.6, but if you download the portable version it will still get the malware.

More antiviruses detect it now including Avast.
 

SpectraShadow83

Level 2
Jun 26, 2019
53
Version 6.7.1 is also detected on Virustotal by various security vendors... I have always used this software without any problems... My question is, aren't they boycotting it because it's Chinese?
 

lokamoka820

Level 18
Thread author
Mar 1, 2024
901
Version 6.7.1 is also detected on Virustotal by various security vendors... I have always used this software without any problems... My question is, aren't they boycotting it because it's Chinese?
No the problem only with wise Care 365, but Wise Disk Cleaner and Wise Registry Cleaner have no problems at all.

I guess that because of the Bootup Booster Service included in Wise Care 365.
 
  • Like
Reactions: SpectraShadow83

lokamoka820

Level 18
Thread author
Mar 1, 2024
901
Here we go again, MS Defender blocks Wise Care 365 again as PUA, but this time it asks about the action instead of remove by default, awesome.

2024-09-15 16 47 36.png 2024-09-15 16 48 03.png
 
  • Like
Reactions: Pat MacKnife

lokamoka820

Level 18
Thread author
Mar 1, 2024
901

No. Microsoft and other AV block or delete based upon the product reputation as scareware (misleading product messages). That is why the recent detection is:

Misleading:Win32/Lodi​

The most resent detection is: PUA:Win32/PCClean
 

bazang

Level 5
Jul 3, 2024
224
The most resent detection is: PUA:Win32/PCClean
It can be any of them:

- PUA: Win32/WiseCare (2017)
- Misleading: Win32/Lodi (2024)
- PUA: Win32/PCClean (2024)

These detections (signatures) are all still in Microsoft's active Defender signatures database. Sometimes you can get different detection signatures for the same file. There can be variations between Windows 10 and 11 and even between different build numbers of Windows or the Defender detection engine.

No matter what it is as a dedicated user of WiseCleaner it will be a PITA for you. Best just to create an Allow exception in Defender.

Microsoft Security is going to keep generating new signatures for programs such as Wise until the publisher joins their Partnership program and pays all the money and jumps through all the hoops to get Microsoft to leave them alone. Essentially that is an accurate characterization of it. Otherwise the development teams has contact Microsoft and submit infos every single time a new signature is created.

Most, if not all, of these detections are based upon Microsoft categorizing the product's reputation as "suspicious."
 
Last edited:
  • +Reputation
Reactions: lokamoka820

lokamoka820

Level 18
Thread author
Mar 1, 2024
901
It can be any of them:

- PUA: Win32/WiseCare (2017)
- Misleading: Win32/Lodi (2024)
- PUA: Win32/PCClean (2024)

These detections (signatures) are all still in Microsoft's active Defender signatures database. Sometimes you can get different detection signatures for the same file. There can be variations between Windows 10 and 11 and even between different build numbers of Windows or the Defender detection engine.

No matter what it is as a dedicated user of WiseCleaner it will be a PITA for you. Best just to create an Allow exception in Defender.

Microsoft Security is going to keep generating new signatures for programs such as Wise until the publisher joins their Partnership program and pays all the money and jumps through all the hoops to get Microsoft to leave them alone. Essentially that is an accurate characterization of it. Otherwise the development teams has contact Microsoft and submit infos every single time a new signature is created.

Most, if not all, of these detections are based upon Microsoft categorizing the product's reputation as "suspicious."
If I understand you well, is Microsoft use MS Defender to get money by doing this?
 

bazang

Level 5
Jul 3, 2024
224
If I understand you well, is Microsoft use MS Defender to get money by doing this?
Not directly. Some software publishers pay the money and go through the process of extended validation to obtain a permanent whitelisting by Microsoft of the Authenticode digital signature. Others join one of the various Microsoft industry initiatives.

Microsoft is average in its fight against PUA whereas Kaspersky essentially allows most any PUA to be installed. Each security software publisher has differences based upon those making the decisions to block PUAs. Some decision makers want to crack-down on software they think are not good for end users while others leave it to the end user to figure out a software is a problem.
 
Last edited:
  • +Reputation
Reactions: lokamoka820

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top