- not-a-virus:AdWare.Win32.MMag.rp -> c:usersuserappdataroamingnewsi_1029s_inst.exe ( DrWEB: Trojan.DownLoader17.20502 )
- not-a-virus:HEUR:Downloader.Win32.AdLoad.gen -> c:usershomeappdatalocalhostinstaller951791143_mons ter.exe
- Trojan-Ransom.Win32.Shade.xl -> c:programdatawindowscsrss.exe
- Trojan.Win32.Yakes.pmcc -> f656.tmp