- Backdoor.Win32.Shiz.apti -> c:\windows\apppatch\tsqopgg.exe ( DrWEB: Trojan.PWS.Ibank.456 )
- Backdoor.Win32.Shiz.apxo -> c:\windows\apppatch\plqlaqx.exe ( DrWEB: Trojan.PWS.Ibank.456 )
- Trojan-Dropper.Win32.Cidox.kfs -> c:\windows\system32\atqcllk.dll ( AVAST4: Win32:WinLock-R [Trj] )
- Trojan-Dropper.Win32.Cidox.kfs -> c:\windows\system32\odblsje.dll ( AVAST4: Win32:WinLock-R [Trj] )
- Trojan-Dropper.Win32.Cidox.kfu -> c:\windows\system32\rnbcthl.dll ( DrWEB: Trojan.Mayachok.1 )
- Trojan-Dropper.Win32.Cidox.kfu -> c:\windows\system32\3.tmp ( DrWEB: Trojan.Mayachok.1 )
- Trojan.Win32.Agent.hvhi -> c:\windows\system32\svchos.exe ( BitDefender: Generic.PWStealer.4F1AE150, NOD32: Win32/Spy.Small.NCD trojan, AVAST4: Win32:Malware-gen )
- Virus.Win32.Neshta.a -> c:\users\qwer\doctorweb\quarantine\svchost0.com ( DrWEB: Win32.HLLP.Neshta, BitDefender: Win32.Neshta.A, NOD32: Win32/Neshta.A virus, AVAST4: Win32:Neshta )
- Virus.Win32.Neshta.a -> c:\documents and settings\qwer\doctorweb\quarantine\svchost0.com ( DrWEB: Win32.HLLP.Neshta, BitDefender: Win32.Neshta.A, NOD32: Win32/Neshta.A virus, AVAST4: Win32:Neshta )