- HEUR:Trojan-Banker.Win32.Emotet.gen -> c:\windows\28123407.exe ( AVAST4: Win32:BankerX-gen [Trj] )
- HEUR:Trojan-Banker.Win32.Emotet.gen -> c:\windows\42217006.exe ( AVAST4: Win32:BankerX-gen [Trj] )
- Trojan-Ransom.Win32.Crusis.to -> c:\windows\system32\winhost.exe ( BitDefender: Gen:Trojan.Heur.FU.fmW@aaAaGKm, AVAST4: Win32:RansomX-gen [Ransom] )
- Trojan-Ransom.Win32.Crusis.to -> c:\programdata\microsoft\windows\start menu\programs\startup\winhost.exe ( BitDefender: Gen:Trojan.Heur.FU.fmW@aaAaGKm, AVAST4: Win32:RansomX-gen [Ransom] )
- Trojan-Ransom.Win32.Crusis.to -> c:\users\glavbuh\appdata\roaming\winhost.exe ( BitDefender: Gen:Trojan.Heur.FU.fmW@aaAaGKm, AVAST4: Win32:RansomX-gen [Ransom] )
- Trojan-Ransom.Win32.Crusis.to -> c:\users\glavbuh\appdata\roaming\microsoft\windows \start menu\programs\startup\winhost.exe ( BitDefender: Gen:Trojan.Heur.FU.fmW@aaAaGKm, AVAST4: Win32:RansomX-gen [Ransom] )