Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'AdobeFlash' = '%APPDATA%\install_flash.exe'
- Средство контроля пользовательских учетных записей (UAC)
- '%APPDATA%\install_flash.exe'
- firefox.exe
- opera.exe
- chrome.exe
- %TEMP%\OperaPref.txt
- %TEMP%\YandexPref.txt
- %TEMP%\ChromePref.txt
- %TEMP%\fupdate.exe
- %APPDATA%\flash.xpi
- %TEMP%\pref.txt
- C:\Twains_64\51637\script.js
- C:\Twains_64\51637\icon-48.png
- C:\Twains_64\51637\background.js
- %APPDATA%\install_flash.exe
- C:\Twains_64\51637\manifest.json
- C:\Twains_64\51637\icon-16.png
- C:\Twains_64\51637\icon-128.png
- %APPDATA%\install_flash.exe
- %TEMP%\pref.txt
- %TEMP%\fupdate.exe
- %TEMP%\OperaPref.txt
- %TEMP%\ChromePref.txt
- %TEMP%\YandexPref.txt
- 'tw###ari.com':80
- tw###ari.com/crx/script.js
- tw###ari.com/crx/manifest.json
- tw###ari.com/crx/updateSky1.exe
- tw###ari.com/xpi/dosya.xpi
- tw###ari.com/crx/icon-48.png
- tw###ari.com/crx/background.js
- tw###ari.com/crx/icon-16.png
- tw###ari.com/crx/icon-128.png
- DNS ASK tw###ari.com
- ClassName: 'Indicator' WindowName: '(null)'