Summary
Technical details
File size of 9216 bytes.
Installation
Creates the following files on an infected computer:
-
Windows system directory (usually, C:\Windows\System32) %System%\MSFXDB32.SRG
-
Windows system directory (usually, C:\Windows\System32) %System%\<html>
-
Windows system directory (usually, C:\Windows\System32) %System%\<script type=\"text/javascript\" src=\"/js/general.js\"></script>
-
Windows system directory (usually, C:\Windows\System32) %System%\<script type=\"text/javascript\">
-
Windows system directory (usually, C:\Windows\System32) %System%\<frameset rows=\"100%,*\" frameborder=\"no\" border=\"0\" framespacing=\"0\">
-
Windows system directory (usually, C:\Windows\System32) %System%\<body bgcolor=\"#ffffff\" text=\"#000000\">
-
Windows system directory (usually, C:\Windows\System32) %System%\</html>\r
Malicious activity
Creates the following files:
-
Windows system directory (usually, C:\Windows\System32) %System%\<head>
-
Windows system directory (usually, C:\Windows\System32) %System%\<title>beneditutti.com</title>
-
Windows system directory (usually, C:\Windows\System32) %System%\ChkRequestEnc('YToyMTp7aTowO3M6MTk6IjIwMTAtMDctMDggMTk6Mzk6NTIiO2k6MTtzOjY6IjkyNTA5MSI7aToyO047aTozO3M6OTg6Ik1vemlsbGEvNC4wIChjb21wYXRpYmxlOyBNU0lFIDYuMDsgV2luZG93cyBOVCA1LjE7IFNWMTsgLk5FVCBDTFIgMi4wLjUwNzI3OyAuTkVUIENMUiAzLjAuMDQ1MDYuMzApIjtpOjQ7czoxNDY6Ii9uZXczLnBocD91c2VyS2V5PXVtZGtwemRtcHV1aXlqZ3prbWRqeXhwc2Z0eWFqa2R6cnRvaGdqbWNlc2pzaWdpYnRyeWV5Y3RuamRibmxoZXJyZWRoZ2xydm5oeXRyeG1qeGdhcnhwcG9oYWFpa3NzdGJ3dW9ybHdicXBiZHJpemJic3JpeWxscGRqeWV2eXp6IjtpOjU7czoxNDoiMjE3LjIzLjEzMi4yMjciO2k6NjtzOjE6IjIiO2k6Nztz
-
Windows system directory (usually, C:\Windows\System32) %System%\OjA6IiI7aTo4O3M6MDoiIjtpOjk7czoyOiJSVSI7aToxMDtzOjE6Ii0iO2k6MTE7czoxOiItIjtpOjEyO3M6NjoiMjI0NTEyIjtpOjEzO3M6MTU6ImJlbmVkaXR1dHRpLmNvbSI7aToxNDtzOjc1OiJodHRwOi8vc2VhcmNocG9ydGFsLmluZm9ybWF0aW9uLmNvbS8/b19pZD0xMTQwMjEmZG9tYWlubmFtZT1iZW5lZGl0dXR0aS5jb20iO2k6MTU7TjtpOjE2O047aToxNztOO2k6MTg7TjtpOjE5O047aToyMDtOO30=');
-
Windows system directory (usually, C:\Windows\System32) %System%\</script>
-
Windows system directory (usually, C:\Windows\System32) %System%\</head>
-
Windows system directory (usually, C:\Windows\System32) %System%\ <!-- SCC a2 -->
-
Windows system directory (usually, C:\Windows\System32) %System%\<noframes>
-
Windows system directory (usually, C:\Windows\System32) %System%\</body>
-
Windows system directory (usually, C:\Windows\System32) %System%\</noframes>
-
Windows system directory (usually, C:\Windows\System32) %System%\</frameset>
Ensures subsequent
Using the system registry, system services or special system files, the program can launch itself or launch the creation of its files every time the Windows OS is subsequently booted autorun of installed files:
by adding values to autorun keys in the system registry:
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"<h" = "
Windows system directory (usually, C:\Windows\System32) %System%\<head>"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"<title>beneditutti.com</ti" = "
Windows system directory (usually, C:\Windows\System32) %System%\<title>beneditutti.com</title>"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"ChkRequestEnc('YToyMTp7aTowO3M6MTk6IjIwMTAtMDctMDggMTk6Mzk6NTIiO2k6MTtzOjY6IjkyNTA5MSI7aToyO047aTozO3M6OTg6Ik1vemlsbGEvNC4wIChjb21wYXRpYmxlOyBNU0lFIDYuMDsgV2luZG93cyBOVCA1LjE7IFNWMTsgLk5FVCBDTFIgMi4wLjUwNzI3OyAuTkVUIENMUiAzLjAuMDQ1MDYuMzApIjtpOjQ7czoxNDY6Ii9uZXczLnBocD91c2VyS2V5PXVtZGtwemRtcHV1aXlqZ3prbWRqeXhwc2Z0eWFqa2R6cnRvaGdqbWNlc2pzaWdpYnRyeWV5Y3RuamRibmxoZXJyZWRoZ2xydm5oeXRyeG1qeGdhcnhwcG9oYWFpa3NzdGJ3dW9ybHdicXBiZHJpemJic3JpeWxscGRqeWV2eXp6IjtpOjU7czoxNDoiMjE3LjIzLjEzMi4yMjciO2k6NjtzOjE6IjIiO2k6" = "
Windows system directory (usually, C:\Windows\System32) %System%\ChkRequestEnc('YToyMTp7aTowO3M6MTk6IjIwMTAtMDctMDggMTk6Mzk6NTIiO2k6MTtzOjY6IjkyNTA5MSI7aToyO047aTozO3M6OTg6Ik1vemlsbGEvNC4wIChjb21wYXRpYmxlOyBNU0lFIDYuMDsgV2luZG93cyBOVCA1LjE7IFNWMTsgLk5FVCBDTFIgMi4wLjUwNzI3OyAuTkVUIENMUiAzLjAuMDQ1MDYuMzApIjtpOjQ7czoxNDY6Ii9uZXczLnBocD91c2VyS2V5PXVtZGtwemRtcHV1aXlqZ3prbWRqeXhwc2Z0eWFqa2R6cnRvaGdqbWNlc2pzaWdpYnRyeWV5Y3RuamRibmxoZXJyZWRoZ2xydm5oeXRyeG1qeGdhcnhwcG9oYWFpa3NzdGJ3dW9ybHdicXBiZHJpemJic3JpeWxscGRqeWV2eXp6IjtpOjU7czoxNDoiMjE3LjIzLjEzMi4yMjciO2k6NjtzOjE6IjIiO2k6Nztz"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"OjA6IiI7aTo4O3M6MDoiIjtpOjk7czoyOiJSVSI7aToxMDtzOjE6Ii0iO2k6MTE7czoxOiItIjtpOjEyO3M6NjoiMjI0NTEyIjtpOjEzO3M6MTU6ImJlbmVkaXR1dHRpLmNvbSI7aToxNDtzOjc1OiJodHRwOi8vc2VhcmNocG9ydGFsLmluZm9ybWF0aW9uLmNvbS8/b19pZD0xMTQwMjEmZG9tYWlubmFtZT1iZW5lZGl0dXR0aS5jb20iO2k6MTU7TjtpOjE2O047aToxNztOO2k6MTg7TjtpOjE5O047aToyMDtOO30" = "
Windows system directory (usually, C:\Windows\System32) %System%\OjA6IiI7aTo4O3M6MDoiIjtpOjk7czoyOiJSVSI7aToxMDtzOjE6Ii0iO2k6MTE7czoxOiItIjtpOjEyO3M6NjoiMjI0NTEyIjtpOjEzO3M6MTU6ImJlbmVkaXR1dHRpLmNvbSI7aToxNDtzOjc1OiJodHRwOi8vc2VhcmNocG9ydGFsLmluZm9ybWF0aW9uLmNvbS8/b19pZD0xMTQwMjEmZG9tYWlubmFtZT1iZW5lZGl0dXR0aS5jb20iO2k6MTU7TjtpOjE2O047aToxNztOO2k6MTg7TjtpOjE5O047aToyMDtOO30=');"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"</scr" = "
Windows system directory (usually, C:\Windows\System32) %System%\</script>"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"</h" = "
Windows system directory (usually, C:\Windows\System32) %System%\</head>"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"<!-- SCC a2" = "
Windows system directory (usually, C:\Windows\System32) %System%\ <!-- SCC a2 -->"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"<nofra" = "
Windows system directory (usually, C:\Windows\System32) %System%\<noframes>"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"</b" = "
Windows system directory (usually, C:\Windows\System32) %System%\</body>"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"</nofra" = "
Windows system directory (usually, C:\Windows\System32) %System%\</noframes>"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"</frame" = "
Windows system directory (usually, C:\Windows\System32) %System%\</frameset>"
Connects to to the following Internet addresses:
Communicates with the following Internet addresses:
- http://***editutti.com/new3.php?userKey=umdkpzdmpuuiyjgzkmdjyxpsftyajkdzrtohgjmcesjsigibtryeyctnjdbnlherredhglrvnhytrxmjxgarxppohaaiksstbwuorlwbqpbdrizbbsriyllpdjyevyzz
- http://***editutti.com/<html>
- http://***editutti.com/
- http://***editutti.com/<head>
- http://***editutti.com/<title>beneditutti.com</title>
- http://***editutti.com/<script type=\"text/javascript\" src=\"/js/general.js\"></script>
- http://***editutti.com/<script type=\"text/javascript\">
- http://***editutti.com/ChkRequestEnc('YToyMTp7aTowO3M6MTk6IjIwMTAtMDctMDggMTk6Mzk6NTIiO2k6MTtzOjY6IjkyNTA5MSI7aToyO047aTozO3M6OTg6Ik1vemlsbGEvNC4wIChjb21wYXRpYmxlOyBNU0lFIDYuMDsgV2luZG93cyBOVCA1LjE7IFNWMTsgLk5FVCBDTFIgMi4wLjUwNzI3OyAuTkVUIENMUiAzLjAuMDQ1MDYuMzApIjtpOjQ7czoxNDY6Ii9uZXczLnBocD91c2VyS2V5PXVtZGtwemRtcHV1aXlqZ3prbWRqeXhwc2Z0eWFqa2R6cnRvaGdqbWNlc2pzaWdpYnRyeWV5Y3RuamRibmxoZXJyZWRoZ2xydm5oeXRyeG1qeGdhcnhwcG9oYWFpa3NzdGJ3dW9ybHdicXBiZHJpemJic3JpeWxscGRqeWV2eXp6IjtpOjU7czoxNDoiMjE3LjIzLjEzMi4yMjciO2k6NjtzOjE6IjIiO2k6Nztz
- http://***editutti.com/OjA6IiI7aTo4O3M6MDoiIjtpOjk7czoyOiJSVSI7aToxMDtzOjE6Ii0iO2k6MTE7czoxOiItIjtpOjEyO3M6NjoiMjI0NTEyIjtpOjEzO3M6MTU6ImJlbmVkaXR1dHRpLmNvbSI7aToxNDtzOjc1OiJodHRwOi8vc2VhcmNocG9ydGFsLmluZm9ybWF0aW9uLmNvbS8/b19pZD0xMTQwMjEmZG9tYWlubmFtZT1iZW5lZGl0dXR0aS5jb20iO2k6MTU7TjtpOjE2O047aToxNztOO2k6MTg7TjtpOjE5O047aToyMDtOO30=');
- http://***editutti.com/</script>
- http://***editutti.com/</head>
- http://***editutti.com/<frameset rows=\"100%,*\" frameborder=\"no\" border=\"0\" framespacing=\"0\">
- http://***editutti.com/ <!-- SCC a2 -->
- http://***editutti.com/ <frame src=\"http://searchportal.information.com/?o_id=114021&domainname=beneditutti.com\">
- http://***editutti.com/<noframes>
- http://***editutti.com/<body bgcolor=\"#ffffff\" text=\"#000000\">
- http://***editutti.com/ <a href=\"http://searchportal.information.com/?o_id=114021&domainname=beneditutti.com\">Click here to enter</a>.
- http://***editutti.com/</body>
- http://***editutti.com/</noframes>
- http://***editutti.com/</frameset>
- http://***editutti.com/</html>\r
Other activities
Modifies the system registry keys:
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"(default)" = "
Windows system directory (usually, C:\Windows\System32) %System%\"
Description:
Used to automatically run files when the Windows OS boots
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Windows\CurrentVersion\Run ]
"(default)" = "
Windows system directory (usually, C:\Windows\System32) %System%\"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"<script type=\"text/javascri" = "
Windows system directory (usually, C:\Windows\System32) %System%\<script type="text/javascript">"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Windows\CurrentVersion\Run ]
"<script type=\"text/javascri" = "
Windows system directory (usually, C:\Windows\System32) %System%\<script type="text/javascript">"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"<frame src=\"http://searchportal.information.com/?o_id=114021&domainname=beneditutti.c" = "
Windows system directory (usually, C:\Windows\System32) %System%\ <frame src="http://searchportal.information.com/?o_id=114021&domainname=beneditutti.com">"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Windows\CurrentVersion\Run ]
"<frame src=\"http://searchportal.information.com/?o_id=114021&domainname=beneditutti.c" = "
Windows system directory (usually, C:\Windows\System32) %System%\ <frame src="http://searchportal.information.com/?o_id=114021&domainname=beneditutti.com">"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"<body bgcolor=\"#ffffff\" text=\"#0000" = "
Windows system directory (usually, C:\Windows\System32) %System%\<body bgcolor="#ffffff" text="#000000">"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Windows\CurrentVersion\Run ]
"<body bgcolor=\"#ffffff\" text=\"#0000" = "
Windows system directory (usually, C:\Windows\System32) %System%\<body bgcolor="#ffffff" text="#000000">"
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"<a href=\"http://searchportal.information.com/?o_id=114021&domainname=beneditutti.com\">Click here to enter<" = "
Windows system directory (usually, C:\Windows\System32) %System%\ <a href="http://searchportal.information.com/?o_id=114021&domainname=beneditutti.com">Click here to enter</a>."
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Windows\CurrentVersion\Run ]
"<a href=\"http://searchportal.information.com/?o_id=114021&domainname=beneditutti.com\">Click here to enter<" = "
Windows system directory (usually, C:\Windows\System32) %System%\ <a href="http://searchportal.information.com/?o_id=114021&domainname=beneditutti.com">Click here to enter</a>."
[
System registry hive HKEY_LOCAL_MACHINEHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ]
"</ht" = "
Windows system directory (usually, C:\Windows\System32) %System%\</html>"
[
System registry hive HKEY_CURRENT_USERHKCU\Software\Microsoft\Windows\CurrentVersion\Run ]
"</ht" = "
Windows system directory (usually, C:\Windows\System32) %System%\</html>"
Deletes the following files on an infected computer:
-
Windows system directory (usually, C:\Windows\System32) %System%\MSFXDB32.SRG