Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemeekdv.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemjdzjo.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtutad.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemrbiqo.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemzjrmf.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemqtstg.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemehlms.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemenpnt.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemluqcd.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemejbxz.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemmwntp.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemzdity.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemkcwjg.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemrkhve.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemfpgfo.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemmipci.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemjaxmg.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemedevv.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemzlllr.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemexlpm.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqembrffv.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemkxxze.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemkbvus.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemnlaob.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemkwcxj.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemkaynd.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemppmrm.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemnctiu.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemfmtwa.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqempdnno.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemphbdi.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemvgjlx.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtmzxc.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemdxqau.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqeminkwa.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemblrxw.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemyvldx.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemvyyfb.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemnrtao.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemnjaur.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemydrou.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemlvwuj.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemsbmrd.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemokhwk.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqembpakw.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqembxnjz.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtofau.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemogiid.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtqxll.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemfhbmh.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemjrjqn.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemrukcn.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtinkb.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemecxrz.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemjybac.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemrnzlt.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemwwlev.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemjoclo.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemhfgax.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemdgxqg.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtrxoh.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqembjmil.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemhwwwz.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemwtgur.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemkylzb.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemxauzr.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemicbjg.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemirnph.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemntxqd.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemsmeap.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemnswnp.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemnvwcu.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemzlvnp.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemcvzts.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemfvaco.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemvngjt.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemalnom.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemgeldg.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemdjwsa.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemlytds.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemamigo.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemnhzzy.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemnzotc.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemiixhd.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemxfhfv.exe'
- '%TEMP%\Sysqemeekdv.exe'
- '%TEMP%\Sysqemjdzjo.exe'
- '%TEMP%\Sysqemtutad.exe'
- '%TEMP%\Sysqemrbiqo.exe'
- '%TEMP%\Sysqemzjrmf.exe'
- '%TEMP%\Sysqemqtstg.exe'
- '%TEMP%\Sysqemehlms.exe'
- '%TEMP%\Sysqemenpnt.exe'
- '%TEMP%\Sysqemluqcd.exe'
- '%TEMP%\Sysqemejbxz.exe'
- '%TEMP%\Sysqemmwntp.exe'
- '%TEMP%\Sysqemzdity.exe'
- '%TEMP%\Sysqemkcwjg.exe'
- '%TEMP%\Sysqemrkhve.exe'
- '%TEMP%\Sysqemfpgfo.exe'
- '%TEMP%\Sysqemmipci.exe'
- '%TEMP%\Sysqemjaxmg.exe'
- '%TEMP%\Sysqemedevv.exe'
- '%TEMP%\Sysqemzlllr.exe'
- '%TEMP%\Sysqemexlpm.exe'
- '%TEMP%\Sysqembrffv.exe'
- '%TEMP%\Sysqemkxxze.exe'
- '%TEMP%\Sysqemkbvus.exe'
- '%TEMP%\Sysqemnlaob.exe'
- '%TEMP%\Sysqemkwcxj.exe'
- '%TEMP%\Sysqemkaynd.exe'
- '%TEMP%\Sysqemppmrm.exe'
- '%TEMP%\Sysqemnctiu.exe'
- '%TEMP%\Sysqemfmtwa.exe'
- '%TEMP%\Sysqempdnno.exe'
- '%TEMP%\Sysqemphbdi.exe'
- '%TEMP%\Sysqemvgjlx.exe'
- '%TEMP%\Sysqemtmzxc.exe'
- '%TEMP%\Sysqemdxqau.exe'
- '%TEMP%\Sysqeminkwa.exe'
- '%TEMP%\Sysqemblrxw.exe'
- '%TEMP%\Sysqemyvldx.exe'
- '%TEMP%\Sysqemvyyfb.exe'
- '%TEMP%\Sysqemnrtao.exe'
- '%TEMP%\Sysqemnjaur.exe'
- '%TEMP%\Sysqemydrou.exe'
- '%TEMP%\Sysqemlvwuj.exe'
- '%TEMP%\Sysqemsbmrd.exe'
- '%TEMP%\Sysqemokhwk.exe'
- '%TEMP%\Sysqembpakw.exe'
- '%TEMP%\Sysqembxnjz.exe'
- '%TEMP%\Sysqemtofau.exe'
- '%TEMP%\Sysqemogiid.exe'
- '%TEMP%\Sysqemtqxll.exe'
- '%TEMP%\Sysqemfhbmh.exe'
- '%TEMP%\Sysqemjrjqn.exe'
- '%TEMP%\Sysqemrukcn.exe'
- '%TEMP%\Sysqemtinkb.exe'
- '%TEMP%\Sysqemecxrz.exe'
- '%TEMP%\Sysqemjybac.exe'
- '%TEMP%\Sysqemrnzlt.exe'
- '%TEMP%\Sysqemwwlev.exe'
- '%TEMP%\Sysqemjoclo.exe'
- '%TEMP%\Sysqemhfgax.exe'
- '%TEMP%\Sysqemdgxqg.exe'
- '%TEMP%\Sysqemtrxoh.exe'
- '%TEMP%\Sysqembjmil.exe'
- '%TEMP%\Sysqemhwwwz.exe'
- '%TEMP%\Sysqemwtgur.exe'
- '%TEMP%\Sysqemkylzb.exe'
- '%TEMP%\Sysqemxauzr.exe'
- '%TEMP%\Sysqemicbjg.exe'
- '%TEMP%\Sysqemirnph.exe'
- '%TEMP%\Sysqemntxqd.exe'
- '%TEMP%\Sysqemsmeap.exe'
- '%TEMP%\Sysqemnswnp.exe'
- '%TEMP%\Sysqemnvwcu.exe'
- '%TEMP%\Sysqemzlvnp.exe'
- '%TEMP%\Sysqemcvzts.exe'
- '%TEMP%\Sysqemfvaco.exe'
- '%TEMP%\Sysqemvngjt.exe'
- '%TEMP%\Sysqemalnom.exe'
- '%TEMP%\Sysqemgeldg.exe'
- '%TEMP%\Sysqemdjwsa.exe'
- '%TEMP%\Sysqemlytds.exe'
- '%TEMP%\Sysqemamigo.exe'
- '%TEMP%\Sysqemnhzzy.exe'
- '%TEMP%\Sysqemnzotc.exe'
- '%TEMP%\Sysqemiixhd.exe'
- '%TEMP%\Sysqemxfhfv.exe'
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- %TEMP%\Sysqemtutad.exe
- %TEMP%\Sysqemeekdv.exe
- %TEMP%\Sysqemzjrmf.exe
- %TEMP%\Sysqemmwntp.exe
- %TEMP%\Sysqemrbiqo.exe
- %TEMP%\Sysqemenpnt.exe
- %TEMP%\Sysqemqtstg.exe
- %TEMP%\Sysqemejbxz.exe
- %TEMP%\Sysqemjdzjo.exe
- %TEMP%\Sysqemluqcd.exe
- %TEMP%\Sysqemedevv.exe
- %TEMP%\Sysqemrkhve.exe
- %TEMP%\Sysqemzdity.exe
- %TEMP%\Sysqemmipci.exe
- %TEMP%\Sysqemsbmrd.exe
- %TEMP%\Sysqemfpgfo.exe
- %TEMP%\Sysqemzlllr.exe
- %TEMP%\Sysqemjaxmg.exe
- %TEMP%\Sysqembrffv.exe
- %TEMP%\Sysqemkcwjg.exe
- %TEMP%\Sysqemexlpm.exe
- %TEMP%\Sysqemehlms.exe
- %TEMP%\Sysqemkxxze.exe
- %TEMP%\Sysqemkbvus.exe
- %TEMP%\Sysqemnlaob.exe
- %TEMP%\Sysqemkwcxj.exe
- %TEMP%\Sysqemkaynd.exe
- %TEMP%\Sysqemppmrm.exe
- %TEMP%\Sysqemnctiu.exe
- %TEMP%\Sysqemfmtwa.exe
- %TEMP%\Sysqempdnno.exe
- %TEMP%\Sysqemphbdi.exe
- %TEMP%\Sysqemvgjlx.exe
- %TEMP%\Sysqemtmzxc.exe
- %TEMP%\Sysqemdxqau.exe
- %TEMP%\Sysqeminkwa.exe
- %TEMP%\Sysqemblrxw.exe
- %TEMP%\Sysqemyvldx.exe
- %TEMP%\Sysqemvyyfb.exe
- %TEMP%\Sysqemnrtao.exe
- %TEMP%\Sysqemnjaur.exe
- %TEMP%\Sysqemydrou.exe
- %TEMP%\Sysqemlvwuj.exe
- %TEMP%\Sysqemnswnp.exe
- %TEMP%\Sysqemogiid.exe
- %TEMP%\Sysqembxnjz.exe
- %TEMP%\Sysqemtofau.exe
- %TEMP%\Sysqemtrxoh.exe
- %TEMP%\Sysqemecxrz.exe
- %TEMP%\Sysqemtinkb.exe
- %TEMP%\Sysqemjrjqn.exe
- %TEMP%\Sysqemrukcn.exe
- %TEMP%\Sysqemokhwk.exe
- %TEMP%\Sysqembpakw.exe
- %TEMP%\Sysqemdgxqg.exe
- %TEMP%\Sysqemhfgax.exe
- %TEMP%\Sysqemwwlev.exe
- %TEMP%\Sysqemjoclo.exe
- %TEMP%\qpath.ini
- %TEMP%\Sysqamqqvaqqd.exe
- %TEMP%\Sysqemwtgur.exe
- %TEMP%\Sysqembjmil.exe
- %TEMP%\Sysqemhwwwz.exe
- %TEMP%\Sysqemjybac.exe
- %TEMP%\Sysqemrnzlt.exe
- %TEMP%\Sysqemtqxll.exe
- %TEMP%\Sysqemicbjg.exe
- %TEMP%\Sysqemkylzb.exe
- %TEMP%\Sysqemntxqd.exe
- %TEMP%\Sysqemfvaco.exe
- %TEMP%\Sysqemirnph.exe
- %TEMP%\Sysqemnvwcu.exe
- %TEMP%\Sysqemsmeap.exe
- %TEMP%\Sysqemcvzts.exe
- %TEMP%\Sysqemxauzr.exe
- %TEMP%\Sysqemzlvnp.exe
- %TEMP%\Sysqemnhzzy.exe
- %TEMP%\Sysqemgeldg.exe
- %TEMP%\Sysqemvngjt.exe
- %TEMP%\Sysqemlytds.exe
- %TEMP%\Sysqemfhbmh.exe
- %TEMP%\Sysqemdjwsa.exe
- %TEMP%\Sysqemnzotc.exe
- %TEMP%\Sysqemamigo.exe
- %TEMP%\Sysqemxfhfv.exe
- %TEMP%\Sysqemalnom.exe
- %TEMP%\Sysqemiixhd.exe
- %TEMP%\Sysqemtutad.exe
- %TEMP%\Sysqemeekdv.exe
- %TEMP%\Sysqemzjrmf.exe
- %TEMP%\Sysqemmwntp.exe
- %TEMP%\Sysqemrbiqo.exe
- %TEMP%\Sysqemenpnt.exe
- %TEMP%\Sysqemqtstg.exe
- %TEMP%\Sysqemejbxz.exe
- %TEMP%\Sysqemjdzjo.exe
- %TEMP%\Sysqemluqcd.exe
- %TEMP%\Sysqemedevv.exe
- %TEMP%\Sysqemrkhve.exe
- %TEMP%\Sysqemzdity.exe
- %TEMP%\Sysqemmipci.exe
- %TEMP%\Sysqemsbmrd.exe
- %TEMP%\Sysqemfpgfo.exe
- %TEMP%\Sysqemzlllr.exe
- %TEMP%\Sysqemjaxmg.exe
- %TEMP%\Sysqembrffv.exe
- %TEMP%\Sysqemkcwjg.exe
- %TEMP%\Sysqemexlpm.exe
- %TEMP%\Sysqemehlms.exe
- %TEMP%\Sysqemkxxze.exe
- %TEMP%\Sysqemkbvus.exe
- %TEMP%\Sysqemnlaob.exe
- %TEMP%\Sysqemkwcxj.exe
- %TEMP%\Sysqemkaynd.exe
- %TEMP%\Sysqemppmrm.exe
- %TEMP%\Sysqemnctiu.exe
- %TEMP%\Sysqemfmtwa.exe
- %TEMP%\Sysqempdnno.exe
- %TEMP%\Sysqemphbdi.exe
- %TEMP%\Sysqemvgjlx.exe
- %TEMP%\Sysqemtmzxc.exe
- %TEMP%\Sysqemdxqau.exe
- %TEMP%\Sysqeminkwa.exe
- %TEMP%\Sysqemblrxw.exe
- %TEMP%\Sysqemyvldx.exe
- %TEMP%\Sysqemvyyfb.exe
- %TEMP%\Sysqemnrtao.exe
- %TEMP%\Sysqemnjaur.exe
- %TEMP%\Sysqemydrou.exe
- %TEMP%\Sysqemlvwuj.exe
- %TEMP%\Sysqembxnjz.exe
- %TEMP%\Sysqemokhwk.exe
- %TEMP%\Sysqemogiid.exe
- %TEMP%\Sysqemecxrz.exe
- %TEMP%\Sysqemtofau.exe
- %TEMP%\Sysqemjrjqn.exe
- %TEMP%\Sysqemtqxll.exe
- %TEMP%\Sysqemtinkb.exe
- %TEMP%\Sysqembpakw.exe
- %TEMP%\Sysqemrukcn.exe
- %TEMP%\Sysqemtrxoh.exe
- %TEMP%\Sysqemwwlev.exe
- %TEMP%\Sysqemjybac.exe
- %TEMP%\Sysqemhfgax.exe
- %TEMP%\Sysqemjoclo.exe
- %TEMP%\Sysqamqqvaqqd.exe
- %TEMP%\Sysqembjmil.exe
- %TEMP%\Sysqemdgxqg.exe
- %TEMP%\Sysqemwtgur.exe
- %TEMP%\Sysqemrnzlt.exe
- %TEMP%\Sysqemhwwwz.exe
- %TEMP%\Sysqemfhbmh.exe
- %TEMP%\Sysqemkylzb.exe
- %TEMP%\Sysqemxauzr.exe
- %TEMP%\Sysqemicbjg.exe
- %TEMP%\Sysqemirnph.exe
- %TEMP%\Sysqemntxqd.exe
- %TEMP%\Sysqemsmeap.exe
- %TEMP%\Sysqemnswnp.exe
- %TEMP%\Sysqemnvwcu.exe
- %TEMP%\Sysqemzlvnp.exe
- %TEMP%\Sysqemcvzts.exe
- %TEMP%\Sysqemfvaco.exe
- %TEMP%\Sysqemvngjt.exe
- %TEMP%\Sysqemalnom.exe
- %TEMP%\Sysqemgeldg.exe
- %TEMP%\Sysqemdjwsa.exe
- %TEMP%\Sysqemlytds.exe
- %TEMP%\Sysqemamigo.exe
- %TEMP%\Sysqemnhzzy.exe
- %TEMP%\Sysqemnzotc.exe
- %TEMP%\Sysqemiixhd.exe
- %TEMP%\Sysqemxfhfv.exe
- <SYSTEM32>\PerfStringBackup.TMP
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini