- HEUR:Trojan.Win32.Miner.gen -> c:\programdata\windowstask\microsofthost.exe ( AVAST4: Win64:CoinminerX-gen [Trj] )
- HEUR:Trojan.Win32.Miner.gen -> c:\programdata\windowstask\appmodule.exe ( AVAST4: Win64:CoinminerX-gen [Trj] )
- not-a-virus:RemoteAdmin.Win32.RDPWrap.h -> c:\rdp\rdpwinst.exe
- Trojan.BAT.Agent.bhf -> c:\programdata\windows\install.bat ( AVAST4: Other:Malware-gen [Trj] )
- Trojan.BAT.Zapchast.dx -> c:\programdata\install\del.bat
- Trojan.VBS.Starter.mj -> c:\programdata\windows\install.vbs
- UDS:Trojan.Win32.Miner -> c:\programdata\setup\update.exe