Avira Virus Lab

DR/AutoIt.oznf

  • Name
    DR/AutoIt.oznf
  • Date discovered
    Jun 26, 2016
  • Type
    Malware
  • Impact
    Medium 
  • Reported Infections
    Medium 
  • Operating System
    Windows
  • VDF version
    7.12.101.52 (2016-06-25 10:13)

Stay safe from all these threats with Avira Free Antivirus.

Avira Free Antivirus Download Free

The term 'DR' denotes a program that is able to place a virus or malware discretely on a system.

Propagation method: The file has no spreading routine.

The file can be used by rogue users or malware to lower security settings.

  • VDF
    7.12.101.52 (2016-06-25 10:13)
  • Files
    The following files are created:
    • %DISKDRIVE%\run\License.txt
    • %DISKDRIVE%\run\Profiles\profile.ini
  • Injections
    • %WINDIR%\System32\svchost.exe{<-\ThemeApiPort}
    • %SYSDIR%\lsass.exe{<-\LsaAuthenticationPort}
    • %SYSDIR%\services.exe{<-\RPC Control\ntsvcs}
    • %SYSDIR%\svchost.exe{<-\RPC Control\DNSResolver}
  • Registry
    The following registry entries are changed:
    • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] "GlobalUserOffline" = dword:00000000 "MigrateProxy" = dword:00000001 "ProxyEnable" = dword:00000000 ProxyServer = - ProxyOverride = - AutoConfigURL = -
    • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher] "TracesProcessed" = dword:0000000d "TracesSuccessful" = dword:0000000a "LastTraceFailure" = dword:00000004
    The following registry entries are added:
    • [HKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings] "ProxyEnable" = dword:00000000
  • HTTP Requests
    • www.*****.org/licenses/gpl-3.0.txt

Help make the web safer by sending us suspicious files/URLs to analyze

Submit your file/URL or Go to support.avira.com

Why submit a suspicious file?

If you encountered a suspicious file or website that’s not in our database, we’ll analyze it and determine whether it’s harmful. Our findings are then pushed out to our millions of users with their next virus database update. If you have Avira, you’ll get that update too. Don’t have Avira? Get it on our homepage.