Security-X

Forum Security-X => Sécurité Générale => Malwares => Discussion démarrée par: chantal11 le juin 10, 2016, 15:59:54

Titre: TechSmart
Posté par: chantal11 le juin 10, 2016, 15:59:54
Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)

TechSmart est un adware (logiciel publicitaire), qui affiche des publicités intempestives indépendantes des sites visités.


(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FTechSmart%2Fmain.png&key=ecbba6829e9c90c08f72a6f4e0ca032ed6d1f1e8a668943897d8176493f241b3)



(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FTechSmart%2Fwarning1.png&key=bf09ef28515f478f4f65d5896f31f0b5b9a30976659d99d7786d0d3d39199671)



**********

Détection de TechSmart dans des rapports FRST :

Citer
Task: {5B06CF43-569E-4150-B1C8-1C98479F7E91} - System32\Tasks\Network Checker => C:\Users\{username}\AppData\Roaming\Network Checker\Network Checker.exe [AAAA-MM-JJ] ()
Task: {702248C0-48B7-4E9F-AAE4-F1BBF4292ED1} - System32\Tasks\Techsmart Computer Service => C:\Program Files (x86)\Techsmart Computer\ittask.exe [AAAA-MM-JJ] (East CH Soft)
Task: {7FAA750D-C9C8-4B61-A2DF-E762AE4712F4} - System32\Tasks\Network Checker Logon => C:\Users\{username}\AppData\Roaming\Network Checker\Network Checker.exe [AAAA-MM-JJ] ()
() C:\Program Files (x86)\Techsmart Computer\mgwz.dll

(The Privoxy team - www.privoxy.org) C:\Program Files (x86)\Techsmart Computer\privoxy.exe
ProxyEnable: [{currentuserID}] => Proxy is enabled.
ProxyServer: [{currentuserID}] => 127.0.0.1:8118
R2 PrivoxyService; C:\Program Files (x86)\Techsmart Computer\privoxy.exe [371200 AAAA-MM-JJ] (The Privoxy team - www.privoxy.org) [File not signed]
C:\Windows\System32\Tasks\Network Checker
C:\Windows\System32\Tasks\Network Checker Logon
C:\Windows\System32\Tasks\Techsmart Computer Service
C:\Users\Nom_Utilisateur\AppData\Roaming\Network Checker
C:\Program Files (x86)\Techsmart Computer

**********

Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable).

Citer
PUP.Optional.Privoxy
PUP.Optional.PrxySvrRST
PUM.Optional.ProxyHijacker


Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)


Source : Removal instructions for TechSmart de Metallica - Malwarebytes Forums (https://forums.malwarebytes.org/topic/182318-removal-instructions-for-techsmart/)



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/