Mis à jour : 13 Février 2007 11:47:45 AM
Type : Applications trompeuses
Impact des risques : Moyen
Systèmes affectés : Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
Lorsque SpyFighter s'exécute, il réalise les opérations suivantes :
- Crée les fichiers suivants :
- %UserProfile%\Desktop\Spy Fighter.lnk
- %UserProfile%\Start Menu\Programs\Spy Fighter\Spy Fighter.lnk
- %SystemDrive%\Documents and Settings\All Users\Desktop\Spy Fighter.lnk
- %SystemDrive%\Documents and Settings\All Users\Start Menu\Programs\Spy Fighter\Spy Fighter.lnk
- %UserProfile%\Application Data\Microsoft\Installer\{EDBEE973-9D78-4C4C-B7BB-20380314C8A3}\_2cd672ae.exe
- %UserProfile%\Application Data\Microsoft\Installer\{EDBEE973-9D78-4C4C-B7BB-20380314C8A3}\_4ae13d6c.exe
- %ProgramFiles%\SpyFighter\200508.sf
- %ProgramFiles%\SpyFighter\200509.sf
- %ProgramFiles%\SpyFighter\200601.sf
- %ProgramFiles%\SpyFighter\200602.sf
- %ProgramFiles%\SpyFighter\ABetterInternet.dll
- %ProgramFiles%\SpyFighter\AdWare.dll
- %ProgramFiles%\SpyFighter\AdwareDatabase.dll
- %ProgramFiles%\SpyFighter\AutoUpdate.exe
- %ProgramFiles%\SpyFighter\code.dat
- %ProgramFiles%\SpyFighter\CoolWebSearch.dll
- %ProgramFiles%\SpyFighter\database.sf
- %ProgramFiles%\SpyFighter\Dialers.dll
- %ProgramFiles%\SpyFighter\History.dll
- %ProgramFiles%\SpyFighter\InstantAccessDialer.dll
- %ProgramFiles%\SpyFighter\license.rtf
- %ProgramFiles%\SpyFighter\LogRecorder.exe
- %ProgramFiles%\SpyFighter\MirarToolbar.dll
- %ProgramFiles%\SpyFighter\MySearchBar.dll
- %ProgramFiles%\SpyFighter\SearchCentrix.dll
- %ProgramFiles%\SpyFighter\SetupCustomActions.exe
- %ProgramFiles%\SpyFighter\SFReader.dll
- %ProgramFiles%\SpyFighter\SingleAdWare1.dll
- %ProgramFiles%\SpyFighter\SinglePlugins2.dll
- %ProgramFiles%\SpyFighter\SpyFighter.exe
- %ProgramFiles%\SpyFighter\WasherPlugins.dll
- %ProgramFiles%\SpyFighter\WebSearchToolbar.dll
Remarque :
%UserProfile% est une variable qui se rapporte au dossier profil de l'utilisateur en cours. Par défaut, il s'agit de C:\Documents and Settings\[Utilisateur en cours] (Windows NT/2000/XP).
%ProgramFiles% est une variable qui se rapporte au dossier program files. Par défaut, c'est C:\Program Files.
%SystemDrive% est une variable qui se rapporte au disque sur lequel Windows est installé. Par défaut, il s'agit du disque C.
- Ajoute les valeurs :
"SpyFighterMonitor" = ""%ProgramFiles%\SpyFighter\SpyFighter.exe" monitor"
"SpyFighterUpdate" = ""%ProgramFiles%\SpyFighter\AutoUpdate.exe" silent"
à la sous-clé de registre :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
de sorte qu'il soit exécuté à chaque démarrage de Windows.
- Crée les sous-clés de registre suivantes :
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\379EEBDE87D9C4C47BBB028330418C3A
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\379EEBDE87D9C4C47BBB028330418C3A
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\1650E5B16D1E56840838E4EED661B5C2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\1650E5B16D1E56840838E4EED661B5C2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\002D10914E786E5AA97747718B9A6C42
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07F9161CE577347D8D06F8AAC8F4709A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0957E30AE70BAC919C514D97098C1377
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\20111BAFA86F96528A7386EDB2C82827
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\228E1837B8ACC7E7A0BF5F43CE258F35
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\24093B47EE01E4CA21C21EDB9D97D7F0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F87B57A4CE993BC2C6039CF7C14F9AE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2FA5A3D59FB24CE633B4A2F999EB1425
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3539394C1540FF598318E39D981467C6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\379EEBDE87D9C4C47BBB028330418C3A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\440ED4749A2EB19DCB940D8430001969
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\489AF3E77CD7AEA48D354937EE9ACA6B
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EAE5B8363E38400A827E42C83553754
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64BCA2A95739F0EC62E8D8587FDFD54D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\666AFB44D8D418F7B43509D4782FD1F4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C586FBD7C9E472A11018EFF7AF2CFFB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6FD287D47E9B5D23A45DA0ADBCD22BDE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7C70D21502CDC0FB073BA3A67C36F4E2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\80BEEAB2878552E5B41D179DAE992C3C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\82842C92421EC44689FDC2FF81701515
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F98EC122C479EB95E82643D23E06620
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9ACE4CE33B53DF31D9A89D160927F416
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB27B45A83FA24F725F06789250FBED0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC150E9DA971EF9E1E1EED1550F2C33F
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3ACFC0D986BBBFADDE1177949B3E8E7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D9DAB06D1A0E8B9D0816CEC48A8D925A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DF8B8E7218774B36C372508AA818975A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\379EEBDE87D9C4C47BBB028330418C3A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\002D10914E786E5AA97747718B9A6C42
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\07F9161CE577347D8D06F8AAC8F4709A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\0957E30AE70BAC919C514D97098C1377
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\20111BAFA86F96528A7386EDB2C82827
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\228E1837B8ACC7E7A0BF5F43CE258F35
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\24093B47EE01E4CA21C21EDB9D97D7F0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\2F87B57A4CE993BC2C6039CF7C14F9AE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\2FA5A3D59FB24CE633B4A2F999EB1425
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\3539394C1540FF598318E39D981467C6
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\379EEBDE87D9C4C47BBB028330418C3A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\440ED4749A2EB19DCB940D8430001969
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\489AF3E77CD7AEA48D354937EE9ACA6B
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\4EAE5B8363E38400A827E42C83553754
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\64BCA2A95739F0EC62E8D8587FDFD54D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\666AFB44D8D418F7B43509D4782FD1F4
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\6C586FBD7C9E472A11018EFF7AF2CFFB
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\6FD287D47E9B5D23A45DA0ADBCD22BDE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\7C70D21502CDC0FB073BA3A67C36F4E2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\80BEEAB2878552E5B41D179DAE992C3C
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\82842C92421EC44689FDC2FF81701515
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\8F98EC122C479EB95E82643D23E06620
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\9ACE4CE33B53DF31D9A89D160927F416
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\BB27B45A83FA24F725F06789250FBED0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\BC150E9DA971EF9E1E1EED1550F2C33F
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\C3ACFC0D986BBBFADDE1177949B3E8E7
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\D9DAB06D1A0E8B9D0816CEC48A8D925A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Components\DF8B8E7218774B36C372508AA818975A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\[NUMERO ALEATOIRE]\Products\379EEBDE87D9C4C47BBB028330418C3A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EDBEE973-9D78-4C4C-B7BB-20380314C8A3}
HKEY_LOCAL_MACHINE\SOFTWARE\SpyFighter