Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'CTS' = '%WINDIR%\CTS.exe'
- '%TEMP%\j6zV7dY6mSXTXot.exe' --crash-reporter-parent-id=2980
- '%TEMP%\Opera Installer\j6zV7dY6mSXTXot.exe' --version
- '%TEMP%\j6zV7dY6mSXTXot.exe' --crash-reporter-parent-id=2900
- '%TEMP%\j6zV7dY6mSXTXot.exe'
- '%WINDIR%\CTS.exe'
- %TEMP%\Opera Installer\opera_installer_20170205024203.log
- %TEMP%\Opera Installer\j6zV7dY6mSXTXot.exe
- %TEMP%\Opera Installer\installer.lck
- %TEMP%\j6zV7dY6mSXTXot.exe
- %WINDIR%\CTS.exe
- %TEMP%\Opera Installer\opera_installer_20170205024202.log
- %TEMP%\Opera Installer\j6zV7dY6mSXTXot.exe
- 'au######te.geo.opera.com':443
- 'localhost':1038
- DNS ASK au######te.geo.opera.com
- ClassName: 'Shell_TrayWnd' WindowName: ''