Avira Virus Lab
TR/Autoit.QX
-
NameTR/Autoit.QX
-
Date discoveredApr 20, 2018
-
TypeMalware
-
ImpactMedium
-
Reported InfectionsLow
-
Operating SystemWindows
-
VDF version7.14.53.162 (2018-04-20 16:05)
The term 'TR' denotes a trojan horse that is able to spy out data, violate your privacy, or perform unwanted modifications to the system.
-
VDF7.14.53.162 (2018-04-20 16:05)
-
Network activityArray
-
ProcessesArrayArray
-
FilesThe following files are deleted:
- %APPDATA%\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db
- %WINDIR%\SysWOW64\ieframe.dll
- %WINDIR%\winsxs\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms
- %TEMPDIR%\%executed_sample%
- %WINDIR%\Globalization\Sorting\sortdefault.nls
- %APPDATA%\Local\Microsoft\Windows\Caches\cversions.1.db
- %USERPATH%\Desktop\desktop.ini
- %SYSDIR%\WindowsPowerShell\v1.0\powershell.exe
- %WINDIR%\SysWOW64\ieframe.dll
- %WINDIR%\winsxs\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms
- %TEMPDIR%\%executed_sample%
- %WINDIR%\Globalization\Sorting\sortdefault.nls
- %APPDATA%\Local\Microsoft\Windows\Caches\cversions.1.db
- %USERPATH%\Desktop\desktop.ini
- %SYSDIR%\WindowsPowerShell\v1.0\powershell.exe
-
RegistryThe following registry entries are added:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap ("ProxyBypass": "") ("IntranetName": "") ("UNCAsIntranet": "0x00000000") ("AutoDetect": "0x01000000")
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap ("ProxyBypass": "") ("IntranetName": "")
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ ("UNCAsIntranet": "0")
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ ("AutoDetect": "1")
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap ("ProxyBypass": "") ("IntranetName": "") ("UNCAsIntranet": "0x00000000") ("AutoDetect": "0x01000000")
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ ("UNCAsIntranet": "0")
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ ("AutoDetect": "1")
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap ("ProxyBypass": "") ("IntranetName": "") ("UNCAsIntranet": "0x00000000") ("AutoDetect": "0x01000000")
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap ("ProxyBypass": "") ("IntranetName": "")
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ ("ProxyBypass": "")
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ ("IntranetName": "")
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ ("ProxyBypass": "")
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ ("IntranetName": "")
-
AliasesESET: Win32/TrojanDownloader.Autoit.OGS trojanG Data: AIT:Trojan.Autoit.DIJ
Help make the web safer by sending us suspicious files/URLs to analyze
Submit your file/URL or Go to support.avira.comWhy submit a suspicious file?
If you encountered a suspicious file or website that’s not in our database, we’ll analyze it and determine whether it’s harmful. Our findings are then pushed out to our millions of users with their next virus database update. If you have Avira, you’ll get that update too. Don’t have Avira? Get it on our homepage.
