Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'NattlyDefender' = '%APPDATA%\NattlyDefender.exe'
- '%APPDATA%\Nattly\sqlite.exe'
- '%APPDATA%\Z-Nattly.exe'
- '%APPDATA%\NattlyDefender.exe'
- firefox.exe
- chrome.exe
- %APPDATA%\Nattly\sqlite.exe
- %APPDATA%\Nattly\System.Data.SQLite.dll
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\user.js
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\searchplugins\Search the Web.xml
- <Текущая директория>\Interop.Shell32.dll
- %APPDATA%\Interop.Shell32.dll
- %APPDATA%\Z-Nattly.exe
- %APPDATA%\NattlyDefender.exe
- %APPDATA%\System.Data.SQLite.dll
- 'mp###ass.com':80
- mp###ass.com/getfileinfo.php?id######
- DNS ASK mp###ass.com
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'Indicator' WindowName: '(null)'