- HEUR:Trojan.Win32.Miner.gen -> c:\windows\wmiprvsf.exe ( AVAST4: Win64:CoinminerX-gen [Trj] )
- Trojan.BAT.Zapchast.dq -> c:\programdata\network\datatm.cmd
- Trojan.Script.XMLTask.be -> \task\activesyncupdate.xml
- UDS:DangerousObject.Multi.Generic -> c:\programdata\steam\steamupdate.exe