- HEUR:Trojan.Multi.StartPageTask.a -> c:windowssystem32tasksurlopener
- Trojan.Win32.Wdfload.aiu -> c:windowstempgc3b.tmp
- Trojan.Win64.Wdfload.agm -> c:windowstempga329.tmp.exe
- Trojan.Win64.Wdfload.agm -> c:windowstempgc3d.tmp.exe
- Trojan.Win64.Wdfload.ok -> c:programdata6163h1703h2045t47626163h1703h2045t476 2.dll