Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)
Zingload est un adware (logiciel publicitaire), qui affiche des publicités intempestives indépendantes des sites visités.
Zingload est installé par un Trojan.
- S'installe en tant que programme, à l'insu de l'utilisateur ou parce qu'il n'a pas décoché les sponsors proposés lors de l'installation d'un logiciel gratuit légitime
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FZingload%2Fwarning4.png&key=5a36cfc87548fb2a6399bd9740beb10e7ffe7d40702de2d8d02292dd3cb5993d)
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FZingload%2Fmain.png&key=c336e6746bcf90150d0035773a2598febebb79ea73fdb20e5a39a3d069cd4e58)
- Modifie les paramètres des navigateurs, pour Chrome par exemple
(https://forums.malwarebytes.org/applications/core/interface/imageproxy/imageproxy.php?img=http%3A%2F%2Fstatic-cdn.malwarebytes.org%2Fpub_images%2FZingload%2Fwarning2.png&key=238f5a560d013720936b303851134715ae73f136b99da855cb39c67fe8a74916)
**********
Détection de Zingload dans des rapports FRST :
FastCompress-Zip_1.0.2.3_Release (HKLM-x32\...\FastCompress-Zip) (Version: - )
ShortcutWithArgument: C:\Users\{username}\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.zingload.com/?type=ll&uid={uid}
ShortcutWithArgument: C:\Users\{username}\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.zingload.com/?type=ll&uid={uid}
ShortcutWithArgument: C:\Users\{username}\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.zingload.com/?type=ll&uid={uid}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.zingload.com/?type=ll&uid={uid}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.zingload.com/?type=ll&uid={uid}
ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.zingload.com/?type=ll&uid={uid}
ShortcutWithArgument: C:\Users\Public\Desktop\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) -> hxxp://www.zingload.com/?type=ll&uid={uid}
ShortcutWithArgument: C:\Users\Public\Desktop\Opera.lnk -> C:\Program Files (x86)\Opera\launcher.exe (Opera Software) -> hxxp://www.zingload.com/?type=ll&uid={uid}
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.zingload.com/?type=ll&uid={uid}
FF Homepage: hxxp://www.zingload.com/?type=hp&uid={uid}
FF SearchPlugin: C:\Users\Nom_Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\nch5mqsa.default\searchplugins\zingload.xml [AAAA-MM-JJ]
StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.zingload.com/?type=ll&uid={uid}
CHR HomePage: Default -> hxxp://www.zingload.com/?type=hp&uid={uid}
CHR StartupUrls: Default -> "hxxp://www.zingload.com/?type=hp&uid={uid}"
StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe hxxp://www.zingload.com/?type=ll&uid={uid}
C:\Users\Nom_Utilisateur\AppData\Local\Temp\1468571993VkJPWtmp.exe
**********
Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable) et Trojan Downloader
PUP.Optional.Zingload
Trojan.Downloader
Tutoriel d'utilisation Malwarebytes en images (http://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-version-2/)
Source : Removal instructions for Zingload de Metallica - Malwarebytes Forums (https://forums.malwarebytes.org/topic/185771-removal-instructions-for-zingload/)
Toujours infecté ? Une question avant de faire des manipulations ?
Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/ en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/