- HEUR:Trojan.Script.Generic -> c:windowswin.vbs ( DrWEB: Trojan.BtcMine.583, AVAST4: VBS:CoinMiner-H [Trj] )
- HEUR:Trojan.Win32.Generic -> c:usersgalaappdatalocalmicrosoftwindowstoolbar.exe ( BitDefender: Gen:Variant.Zusy.115300, AVAST4: Win32:Malware-gen )
- not-a-virus:AdWare.Win32.Amonetize.pg -> c:usersгерманappdatalocal41a18467.exe ( BitDefender: Gen:Variant.Application.Bundler.Amonetize.14 )
- not-a-virus:Monitor.Win32.KeyLogger.apf -> c:program filesckm systemslitewinckm.exe
- not-a-virus:WebToolbar.Win32.CroRi.bba -> c:program files (x86)hd+v2.157d05856-1a6c-44dc-9873-1df40136a5ad-6.exe ( BitDefender: Gen:Application.Heur.Ny1@k0V9Mjmi )
- not-a-virus:WebToolbar.Win32.CroRi.bba -> c:program files (x86)hd+v2.157d05856-1a6c-44dc-9873-1df40136a5ad-7.exe ( BitDefender: Gen:Application.Heur.Iu1@kygxPXmO )
- not-a-virus:WebToolbar.Win32.CroRi.bba -> c:program files (x86)hd+v2.1hd+v2.1-bho.dll ( BitDefender: Gen:Application.Heur.Ky9@kGWWaboi )
- Trojan-Clicker.BAT.Small.bt -> c:iexplore.bat
- Trojan.Win32.Bitminer.it -> c:usersrus_sergappdataroamingcppredistx86.exe ( BitDefender: Trojan.GenericKD.1975949 )