Security-X

Forum Security-X => Sécurité Générale => Malwares => Discussion démarrée par: chantal11 le décembre 27, 2016, 09:51:32

Titre: TSS Power Update
Posté par: chantal11 le décembre 27, 2016, 09:51:32
Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)

TSS Power Update est un support technique frauduleux (Rogue), qui affiche intentionnellement un numéro de téléphone pour inciter l'utilisateur à appeler ce support technique frauduleux.
Un support technique frauduleux (Tech Support Scam (https://blog.malwarebytes.org/tech-support-scams/)) utilise différentes méthodes pour permettre aux utilisateurs de communiquer avec eux.
TSS Power Update est installé avec une fausse mise à jour Adobe Flash. 

(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/TSSPowerUpdate/warning2.png&key=3e80a96e8fb99fa5eb2061b18d6dfc7b5289a35f875d01dd800216a856423b4c)

(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/TSSPowerUpdate/warning3.png&key=f5c61bdaa3d50cb40a3aa3cdc323c2b1fd97d5c582a888131b4a13354f994d46)


(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/TSSPowerUpdate/warning1.png&key=8aa593963091383e2a02ed813153c5e0108b54a1080d2507a33da9a8623134a6)

(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/TSSPowerUpdate/download.png&key=f3f705a94b60c0c74ead66eaa321ee74f088cd2bddac67f46727f6f97ffefb95)




**********

Détection de TSS Power Update dans des rapports FRST :

Citer
HKLM-x32\...\Run: [L] => C:\Program Files (x86)\Power Update\R.exe [90112 2016-08-23] ()
HKLM-x32\...\Winlogon: [Shell] C:\Program Files (x86)\Power Update\fatalerror.exe,C:\Program Files (x86)\Power Update\R.exe [90112 ] () <=== ATTENTION
HKCU\...\Run: [AdobeFlash] => C:\Program Files (x86)\Power Update\Adobeflash.exe [24576 2016-08-19] ()
HKCU\...\Run: [L] => C:\Program Files (x86)\Power Update\R.exe [90112 2016-08-23] ()
HKCU\...\Winlogon: [Shell] C:\Program Files (x86)\Power Update\R.exe [90112 2016-08-23] () <==== ATTENTION
C:\Program Files\Pc Optimizer
C:\Program Files (x86)\Power Update
C:\Program Files (x86)\Pc Optimizer


**********

Détecté et traité par Malwarebytes en tant que Rogue TechSupportScam

Citer
Rogue.TechSupportScam
Trojan.Agent
Hijack.Shell

Note : Dans certains cas, il faudra utiliser la fonctionnalité Chameleon de Malwarebytes


Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)


Source : Removal instructions for TSS Power Update de Metallica - Malwarebytes Forums (https://forums.malwarebytes.com/topic/192524-removal-instructions-for-tss-power-update/)



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/