- not-a-virus:PSWTool.Win32.ProductKey.bw -> c:\windows\system32\cpldapu\produkey.exe ( DrWEB: Tool.PassSteel.591, BitDefender: Application.Nirsoft.ProduKey.A )
- Trojan.Win32.Cidox.kbu -> c:\windows\system32\nvuzesh.dll
- Trojan.Win32.Inject.ehxu -> c:\windows\system32\03.exe ( DrWEB: BackDoor.Gurl.2, BitDefender: Backdoor.Hamweq.B )
- Trojan.Win32.Inject.ehxu -> c:\windows\system32\76.exe ( DrWEB: BackDoor.Gurl.2, BitDefender: Backdoor.Hamweq.B )
- Trojan.Win32.Inject.ehxu -> c:\recycler\s-1-5-21-0243556031-888888379-781863308-1830\zaberg.exe ( DrWEB: BackDoor.Gurl.2, BitDefender: Gen:Win32.ExplorerHijack.auY@a8On7hei )