Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)
OtherSearch est un LSP Hijacker (pirate LSP) qui manipule le trafic sur internet, par exemple, pour modifier le contenu.
OtherSearch affiche également des publicités.
- S'installe en tant que programme, à l'insu de l'utilisateur ou parce qu'il n'a pas décoché les sponsors proposés lors de l'installation d'un logiciel gratuit légitime
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FOtherSearch%2Fwarning4.png&key=910f52648653d6d97a3c8e3be478811b94eb98528ccba8615554511bf3c91c5c)
- OtherSearch affiche ces alertes pendant l'installation
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FOtherSearch%2Fmain.png&key=5356f1cc7bfa779b77e9b5d6a6d1ee7a8ada31ed06e676f6ab1fe3185377b242)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FOtherSearch%2Fwarning1.png&key=419d491ec45654f5f4d11ba9180e19ccb8edbbb8d0ec08f9631f59f772a49cb9)
- Crée une tâche planifiée
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FOtherSearch%2Fwarning3.png&key=689477ed587a30eed37f94f60e6c39de186c8559fb9b120c0df66e2b5d25ceef)
- Affiche ce type de résultats de recherche
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=https%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FOtherSearch%2Fwarning2.png&key=6b952d7b7ca17883b4001d415754c8784606e40859b9051a7c7e44c6460b9ae1)
**********
Détection de OtherSearch dans des rapports FRST :
OtherSearch (HKLM-x32\...\OtherSearch) (Version: 3.0.3.0 - Hyrum Abel)
Task: {621B6528-1F8E-40EB-90AE-B5931F0379D6} - System32\Tasks\wbs3030 => C:\Program Files (x86)\OtherSearch\wbs3030.exe [AAAA-MM-JJ] ()
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\zdengine => ""="service"
(zdengine) C:\Program Files (x86)\OtherSearch\zdengine.exe
Winsock: Catalog9 01 C:\Windows\SysWOW64\zdengine.dll [299358 AAAA-MM-JJ] (zdengine)
Winsock: Catalog9 02 C:\Windows\SysWOW64\zdengine.dll [299358 AAAA-MM-JJ] (zdengine)
Winsock: Catalog9 03 C:\Windows\SysWOW64\zdengine.dll [299358 AAAA-MM-JJ] (zdengine)
Winsock: Catalog9 04 C:\Windows\SysWOW64\zdengine.dll [299358 AAAA-MM-JJ] (zdengine)
Winsock: Catalog9 15 C:\Windows\SysWOW64\zdengine.dll [299358 AAAA-MM-JJ] (zdengine)
Winsock: Catalog9-x64 01 C:\Windows\system32\zdengine64.dll [347726 AAAA-MM-JJ] (zdengine)
Winsock: Catalog9-x64 02 C:\Windows\system32\zdengine64.dll [347726 AAAA-MM-JJ] (zdengine)
Winsock: Catalog9-x64 03 C:\Windows\system32\zdengine64.dll [347726 AAAA-MM-JJ] (zdengine)
Winsock: Catalog9-x64 04 C:\Windows\system32\zdengine64.dll [347726 AAAA-MM-JJ] (zdengine)
Winsock: Catalog9-x64 15 C:\Windows\system32\zdengine64.dll [347726 AAAA-MM-JJ] (zdengine)
R2 zdengine; C:\Program Files (x86)\OtherSearch\zdengine.exe [1739046 AAAA-MM-JJ] (zdengine) [File not signed]
(zdengine) C:\Windows\system32\zdengine64.dll
(zdengine) C:\Windows\SysWOW64\zdengine.dll
C:\Windows\SysWOW64\zdengineOff.ini
C:\Windows\system32\zdengineOff.ini
C:\Windows\System32\Tasks\wbs3030
C:\END
C:\Program Files (x86)\OtherSearch
**********
Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable)
PUP.Optional.OtherSearch.BrwsrFlsh
PUP.Optional.Komodia.WnskRST
PUP.Optional.Komodia
PUP.Optional.Komodia.Gen
PUP.Optional.PennyBee
Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)
Source : Removal instructions for OtherSearch de Metallica - Malwarebytes Forums (https://forums.malwarebytes.org/topic/185179-removal-instructions-for-othersearch/)
Toujours infecté ? Une question avant de faire des manipulations ?
Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/ en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/