Security-X

Forum Security-X => Sécurité Générale => Malwares => Discussion démarrée par: chantal11 le décembre 27, 2016, 10:22:21

Titre: TSS GMusicPlayer
Posté par: chantal11 le décembre 27, 2016, 10:22:21
Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)

TSS GMusicPlayer est un support technique frauduleux (Rogue), qui affiche intentionnellement un numéro de téléphone pour inciter l'utilisateur à appeler ce support technique frauduleux.
Un support technique frauduleux (Tech Support Scam (https://blog.malwarebytes.org/tech-support-scams/)) utilise différentes méthodes pour permettre aux utilisateurs de communiquer avec eux.
TSS GMusicPlayer est proposé en tant que lecteur de musique. 

(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/TSSGMusicPlayer/main.png&key=584d4f6614297e313c51ad9b8b8129395fdfb94506090fef322ab52237b6364c)

(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/TSSGMusicPlayer/warning3.png&key=998a523e874dd48cc6dc598451d55908cdd30074f2107a918a08cd48485b362d)


(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/TSSGMusicPlayer/warning4.png&key=57698c416b789acbceda32e33caa3a5514102096e03c24ca9a61f38871923c12)


(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/TSSGMusicPlayer/icons.png&key=fc08b42e8aec4ae6c9b67f1005454c964e374a75aa1e9b179d95791abe5f5b63)




**********

Détection de TSS GMusicPlayer dans des rapports FRST :

Citer
GMusicPlayer 1.00 (HKLM-x32\...\GMusicPlayer 1.00) (Version:  - )

() C:\Windows\track.exe
HKLM-x32\...\Run: [jj] => C:\Windows\jj.exe
HKLM-x32\...\Run: [labelexe] => C:\Windows\mycent.exe
HKLM-x32\...\Winlogon: [Shell] C:\Windows\doctormypc.exe [ ] () <=== ATTENTION
HKCU\...\Run: [jj] => C:\Windows\jj.exe [20480 2016-11-24] ()
HKCU\...\Run: [labelexe] => C:\Windows\mycent.exe [16384 2016-11-17] ()
HKCU\...\Run: [MyPc Doctor] => C:\Windows\MyPc Doctor\MyPc Doctor.exe [949248 2016-11-17] (nSOFT TECH)
HKCU\...\Winlogon: [Shell] C:\Windows\doctormypc.exe [249856 2016-12-01] () <==== ATTENTION
C:\Windows\MyPc Doctor
C:\Program Files (x86)\GMusicPlayer
C:\Windows\ClearLock.ini
C:\Windows\active.bat
C:\Windows\tt.exe
(active) C:\Windows\active.exe
C:\Windows\doctormypc.exe
C:\Windows\jj.exe


**********

Détecté et traité par Malwarebytes en tant que Trojan LockScreen
Sous la version Premium, Malwarebytes bloque le domaine recoverpcerror.com et l'IP 127.42.0.0

Citer
Trojan.LockScreen
Trojan.FakeAV
PUP.Optional.MyPCDoctor
Backdoor.Fynloski

Note : Dans certains cas, il faudra utiliser la fonctionnalité Chameleon de Malwarebytes


Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)


Source : Removal instructions for TSS GMusicPlayer de Metallica - Malwarebytes Forums (https://forums.malwarebytes.com/topic/192569-removal-instructions-for-tss-gmusicplayer/)



Toujours infecté ? Une question avant de faire des manipulations ?

Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/  en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/