- HEUR:Trojan.Win32.Khalesi.gen -> c:\programdata\{c1f0f13d-b464-a0d2-85e2-8cd586dec7ac}\6c4f21a2.exe ( AVAST4: Win32:Malware-gen )
- HEUR:Trojan.Win32.Khalesi.gen -> c:\users\a-technics\appdata\roaming\cavgivju\vivvhwvd.exe ( BitDefender: Gen:Trojan.Heur.RP.jqW@aOXI96pO, AVAST4: Win32:Malware-gen )
- Trojan.Win32.Agentb.jcpt -> c:\programdata\windowsmenu\westat.exe