- Trojan-Ransom.Win32.Crusis.to -> c:\users\администратор\appdata\roaming\1st.exe ( BitDefender: Gen:Trojan.Heur.FU.fmW@aaAaGKm, AVAST4: Win32:Malware-gen )
- Trojan.VBS.BitMin.av -> c:\programdata\audiodriver\audiodriver.vbs
- Trojan.Win32.BitCoinMiner.edg -> c:\programdata\appsource\data\config1.dll
- Trojan.Win32.BitCoinMiner.edh -> c:\programdata\appsource\data\config2.dll
- UDS:DangerousObject.Multi.Generic -> c:\windows\fonts\winlogo.exe
- UDS:DangerousObject.Multi.Generic -> c:\windows\conhost\conhost.exe