- Backdoor.Win32.Shiz.eyxl -> c:\windows\apppatch\pquekcq.exe
- Trojan-Spy.Win32.Carberp.nmf -> c:\users\николай\appdata\roaming\microsoft\windows \start menu\programs\startup\8quxfjzvhm8.exe
- Trojan-Spy.Win32.Carberp.npm -> c:\users\вовка\appdata\roaming\microsoft\windows\s tart menu\programs\startup\nyhnfznvtik.exe