Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)
Product Key est un support technique frauduleux (Rogue), qui affiche intentionnellement un numéro de téléphone pour inciter l'utilisateur à appeler ce support technique frauduleux.
Un support technique frauduleux utilise différentes méthodes pour permettre aux utilisateurs de communiquer avec eux.
Product Key utilise la valeur de Registre Winlogon-Shell (https://blog.malwarebytes.com/cybercrime/2016/05/tech-support-scammers-using-winlogon/) pour verrouiller le système.
- Affiche un faux écran de vérification Windows avec le numéro pour contacter le support frauduleux après redémarrage et quand l'utilisateur ouvre sa session
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FProductKeyTSS%2Fmain.png&key=1426a2350c473311c898ed68b0656519ea140a54ab856636bba409e7f0950ff4)
- Product Key affiche ces alertes pendant l'installation
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FProductKeyTSS%2Fwarning1.png&key=1c6258e62129ce8cf117c8ad7fbf4787ae42c8d1fe1649e150183d93e137565b)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FProductKeyTSS%2Fwarning2.png&key=3f8619c4e7057e79edfd2161336a34abfae228810ccfa82a0d3ea29004cbaa68)
- Après avoir cliqué sur "Commencer avec Product Key"
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FProductKeyTSS%2Ftheretheyarew.png&key=c0a82aa2462c50afdc41414ae128dd5c4df2c5a1c7c0d753a244af313c9301f4)
**********
Détection de Product Key dans des rapports FRST :
HKLM-x32\...\Run: [L] => C:\Program Files (x86)\Product Key\fatalerror.exe [139264 2016-07-14] ()
HKLM-x32\...\Winlogon: [Shell] C:\Program Files (x86)\Product Key\fatalerror.exe [139264 ] () <=== ATTENTION
HKCU\...\Run: [L] => C:\Program Files (x86)\Product Key\fatalerror.exe [139264 2016-07-14] ()
HKCU\...\Winlogon: [Shell] C:\Program Files (x86)\Product Key\fatalerror.exe [139264 2016-07-14] () <==== ATTENTION
C:\Program Files (x86)\Product Key
**********
Détecté et traité par Malwarebytes en tant que Rogue (logiciel frauduleux)
Rogue.TechSupportScam
Hijack.Shell
Ransom.LockScreen
Note : Dans certains cas, il faudra utiliser la fonctionnalité Chameleon de Malwarebytes
Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)
Source : Removal instructions for Product Key de Metallica - Malwarebytes Forums (https://forums.malwarebytes.org/topic/186299-removal-instructions-for-product-key/)
Toujours infecté ? Une question avant de faire des manipulations ?
Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/ en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/