Contenu republié avec la permission de Malwarebytes (https://forums.malwarebytes.org/index.php?showforum=39)
Other Search 4 est un LSP hijacker (https://blog.malwarebytes.com/cybercrime/2014/10/changes-in-the-lsp-stack/) (pirate LSP) qui manipule le trafic sur internet, par exemple, pour modifier le contenu.
Other Search 4 affiche également des publicités.
- S'installe en tant que programme, à l'insu de l'utilisateur ou parce qu'il n'a pas décoché les sponsors proposés lors de l'installation d'un logiciel gratuit légitime
(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/OtherSearchupd/warning4.png&key=6b7766a60ef8652a27f0c3708f9c8013b5091652439965fca6291bac2f9fb17c)
(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/OtherSearchupd/warning3.png&key=934c3633bfc6f985f03fa33e981538d51f4606db2fde40f3d273eab0e3065aca)
- Affiche ce type de résultats de recherche
(https://forums.malwarebytes.com/applications/core/interface/imageproxy/imageproxy.php?img=https://static-cdn.malwarebytes.org/pub_images/OtherSearchupd/main.png&key=1a9c4f30d20cda70edd31fd779fd34f51ce0814cadd6f8bd8fea33230ba2c39c)
**********
Détection de Other Search 4 dans des rapports FRST :
OtherSearch (HKLM-x32\...\OtherSearch) (Version: 3.0.4.2 - Theudobald Yanko)
Task: {A3076E53-7F6F-4281-9BED-C41F7CE3CEE5} - System32\Tasks\updengine => C:\Program Files (x86)\OtherSearch\updengine.exe [2017-01-19] ()
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\zdengine => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\zdwfp => ""="Driver"
(zdengine) C:\Program Files (x86)\OtherSearch\zdengine.exe
Winsock: Catalog9 01 C:\WINDOWS\SysWOW64\zdengine.dll [301711 2017-01-30] (zdengine)
Winsock: Catalog9 02 C:\WINDOWS\SysWOW64\zdengine.dll [301711 2017-01-30] (zdengine)
Winsock: Catalog9 03 C:\WINDOWS\SysWOW64\zdengine.dll [301711 2017-01-30] (zdengine)
Winsock: Catalog9 04 C:\WINDOWS\SysWOW64\zdengine.dll [301711 2017-01-30] (zdengine)
Winsock: Catalog9 16 C:\WINDOWS\SysWOW64\zdengine.dll [301711 2017-01-30] (zdengine)
Winsock: Catalog9-x64 01 C:\WINDOWS\system32\zdengine64.dll [364303 2017-01-30] (zdengine)
Winsock: Catalog9-x64 02 C:\WINDOWS\system32\zdengine64.dll [364303 2017-01-30] (zdengine)
Winsock: Catalog9-x64 03 C:\WINDOWS\system32\zdengine64.dll [364303 2017-01-30] (zdengine)
Winsock: Catalog9-x64 04 C:\WINDOWS\system32\zdengine64.dll [364303 2017-01-30] (zdengine)
Winsock: Catalog9-x64 16 C:\WINDOWS\system32\zdengine64.dll [364303 2017-01-30] (zdengine)
R2 zdengine; C:\Program Files (x86)\OtherSearch\zdengine.exe [1660135 2017-01-30] (zdengine) [File not signed]
R2 zdwfp; C:\WINDOWS\system32\Drivers\zdwfp64.sys [46352 2016-12-14] (zdengine)
(zdengine) C:\WINDOWS\system32\zdengine64.dll
(zdengine) C:\WINDOWS\SysWOW64\zdengine.dll
C:\WINDOWS\SysWOW64\zdengineOff.ini
C:\WINDOWS\system32\zdengineOff.ini
C:\WINDOWS\System32\Tasks\updengine
C:\END
C:\Program Files (x86)\OtherSearch
(zdengine) C:\WINDOWS\system32\Drivers\zdwfp64.sys
**********
Détecté et traité par Malwarebytes en tant que PUP/LPI (Programme potentiellement Indésirable)
PUP.Optional.OtherSearch
PUP.Optional.Komodia
PUP.Optional.Komodia.WnskRST
PUP.Optional.PennyBee
Rootkit.Komodia.PUA
Rogue.TechSupportScam
Tutoriel d'utilisation Malwarebytes en images (https://forum.security-x.fr/tutoriels-317/tutoriel-malwarebytes-anti-malware-22723/)
Source : Removal instructions for Other Search 4 de Metallica - Malwarebytes Forums (https://forums.malwarebytes.com/topic/195326-removal-instructions-for-other-search-4/)
Toujours infecté ? Une question avant de faire des manipulations ?
Venez poster un nouveau sujet dans ce forum : http://forum.security-x.fr/desinfections/ en prenant soin de suivre la procédure http://forum.security-x.fr/desinfections/procedure-preliminaire/