Technical Information
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemrqwml.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemdleak.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemyuvoe.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtatyc.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemmafjn.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemlqijk.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemdquuv.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemwtyls.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemlqosu.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemdfxnk.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemoeual.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqembyknc.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemzzkhb.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemwlvov.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemgzyer.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemojkuv.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqembesiu.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemyesbl.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemomcii.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemgxryv.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemsozmn.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemsokpe.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqempsnrg.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemautmk.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemfzwsr.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemksvcv.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemamcic.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemiiuop.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemkkiyl.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemuglgg.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemlroex.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtwbpu.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemvyiyq.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtyhsh.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemfpmsd.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemiudyi.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemvwmhq.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemvgclw.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemybucf.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemibixd.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemsfeah.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemxogmo.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemvcarb.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemgxvyq.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtlynm.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemcdssk.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemzbayo.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemfgknx.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemvcqnu.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemqtcwo.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemwtcox.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemtnjqj.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemhnkdo.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemunbro.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqempynli.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemexaqg.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemlqshl.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemggfco.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemlvxue.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqembwnav.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemssxjd.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemjhymt.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemzwwtv.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemrkdyv.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemhwkik.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemrbbcp.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemeafyi.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemevyjq.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemragkn.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemhfrdx.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemznhcm.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemveclv.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemfkthb.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemsxbww.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemkeczm.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemhhcxx.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemzhoii.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqempwmhk.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqempktlc.exe'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '%TEMP%\Sysqemewaez.exe'
- '%TEMP%\Sysqemyuvoe.exe'
- '%TEMP%\Sysqemrqwml.exe'
- '%TEMP%\Sysqemtatyc.exe'
- '%TEMP%\Sysqemmafjn.exe'
- '%TEMP%\Sysqemdleak.exe'
- '%TEMP%\Sysqemwtyls.exe'
- '%TEMP%\Sysqemlqijk.exe'
- '%TEMP%\Sysqemlqosu.exe'
- '%TEMP%\Sysqemdfxnk.exe'
- '%TEMP%\Sysqembesiu.exe'
- '%TEMP%\Sysqemzzkhb.exe'
- '%TEMP%\Sysqemoeual.exe'
- '%TEMP%\Sysqemwlvov.exe'
- '%TEMP%\Sysqemgzyer.exe'
- '%TEMP%\Sysqembyknc.exe'
- '%TEMP%\Sysqemyesbl.exe'
- '%TEMP%\Sysqemojkuv.exe'
- '%TEMP%\Sysqemomcii.exe'
- '%TEMP%\Sysqemgxryv.exe'
- '%TEMP%\Sysqemdquuv.exe'
- '%TEMP%\Sysqempsnrg.exe'
- '%TEMP%\Sysqemsozmn.exe'
- '%TEMP%\Sysqemautmk.exe'
- '%TEMP%\Sysqemfzwsr.exe'
- '%TEMP%\Sysqemsokpe.exe'
- '%TEMP%\Sysqemiiuop.exe'
- '%TEMP%\Sysqemksvcv.exe'
- '%TEMP%\Sysqemkkiyl.exe'
- '%TEMP%\Sysqemuglgg.exe'
- '%TEMP%\Sysqemvwmhq.exe'
- '%TEMP%\Sysqemvyiyq.exe'
- '%TEMP%\Sysqemlroex.exe'
- '%TEMP%\Sysqemtyhsh.exe'
- '%TEMP%\Sysqemfpmsd.exe'
- '%TEMP%\Sysqemtwbpu.exe'
- '%TEMP%\Sysqemvgclw.exe'
- '%TEMP%\Sysqemiudyi.exe'
- '%TEMP%\Sysqemybucf.exe'
- '%TEMP%\Sysqemibixd.exe'
- '%TEMP%\Sysqemeafyi.exe'
- '%TEMP%\Sysqemvcarb.exe'
- '%TEMP%\Sysqemsfeah.exe'
- '%TEMP%\Sysqemgxvyq.exe'
- '%TEMP%\Sysqemtlynm.exe'
- '%TEMP%\Sysqemxogmo.exe'
- '%TEMP%\Sysqemfgknx.exe'
- '%TEMP%\Sysqemcdssk.exe'
- '%TEMP%\Sysqemvcqnu.exe'
- '%TEMP%\Sysqemqtcwo.exe'
- '%TEMP%\Sysqemlqshl.exe'
- '%TEMP%\Sysqemhnkdo.exe'
- '%TEMP%\Sysqemwtcox.exe'
- '%TEMP%\Sysqemunbro.exe'
- '%TEMP%\Sysqempynli.exe'
- '%TEMP%\Sysqemtnjqj.exe'
- '%TEMP%\Sysqemggfco.exe'
- '%TEMP%\Sysqemexaqg.exe'
- '%TEMP%\Sysqemlvxue.exe'
- '%TEMP%\Sysqembwnav.exe'
- '%TEMP%\Sysqemzbayo.exe'
- '%TEMP%\Sysqemzwwtv.exe'
- '%TEMP%\Sysqemssxjd.exe'
- '%TEMP%\Sysqemrkdyv.exe'
- '%TEMP%\Sysqemhwkik.exe'
- '%TEMP%\Sysqemjhymt.exe'
- '%TEMP%\Sysqemevyjq.exe'
- '%TEMP%\Sysqemrbbcp.exe'
- '%TEMP%\Sysqemragkn.exe'
- '%TEMP%\Sysqemhfrdx.exe'
- '%TEMP%\Sysqemzhoii.exe'
- '%TEMP%\Sysqemfkthb.exe'
- '%TEMP%\Sysqemznhcm.exe'
- '%TEMP%\Sysqemsxbww.exe'
- '%TEMP%\Sysqemkeczm.exe'
- '%TEMP%\Sysqemveclv.exe'
- '%TEMP%\Sysqempwmhk.exe'
- '%TEMP%\Sysqemhhcxx.exe'
- '%TEMP%\Sysqempktlc.exe'
- '%TEMP%\Sysqemewaez.exe'
- %TEMP%\Sysqemyuvoe.exe
- %TEMP%\Sysqemrqwml.exe
- %TEMP%\Sysqemmafjn.exe
- %TEMP%\Sysqembesiu.exe
- %TEMP%\Sysqemtatyc.exe
- %TEMP%\Sysqemwtyls.exe
- %TEMP%\Sysqemlqijk.exe
- %TEMP%\Sysqemdfxnk.exe
- %TEMP%\Sysqemdleak.exe
- %TEMP%\Sysqemlqosu.exe
- %TEMP%\Sysqemzzkhb.exe
- %TEMP%\Sysqemoeual.exe
- %TEMP%\Sysqemgzyer.exe
- %TEMP%\Sysqemeafyi.exe
- %TEMP%\Sysqemwlvov.exe
- %TEMP%\Sysqemyesbl.exe
- %TEMP%\Sysqemojkuv.exe
- %TEMP%\Sysqemgxryv.exe
- %TEMP%\Sysqembyknc.exe
- %TEMP%\Sysqemomcii.exe
- %TEMP%\Sysqemdquuv.exe
- %TEMP%\Sysqemsozmn.exe
- %TEMP%\Sysqemsokpe.exe
- %TEMP%\Sysqempsnrg.exe
- %TEMP%\Sysqemautmk.exe
- %TEMP%\Sysqemfzwsr.exe
- %TEMP%\Sysqemksvcv.exe
- %TEMP%\Sysqemamcic.exe
- %TEMP%\Sysqemiiuop.exe
- %TEMP%\Sysqemkkiyl.exe
- %TEMP%\Sysqemuglgg.exe
- %TEMP%\Sysqemlroex.exe
- %TEMP%\Sysqemtwbpu.exe
- %TEMP%\Sysqemvyiyq.exe
- %TEMP%\Sysqemtyhsh.exe
- %TEMP%\Sysqemfpmsd.exe
- %TEMP%\Sysqemiudyi.exe
- %TEMP%\Sysqemvwmhq.exe
- %TEMP%\Sysqemvgclw.exe
- %TEMP%\Sysqemybucf.exe
- %TEMP%\Sysqemibixd.exe
- %TEMP%\Sysqemtlynm.exe
- %TEMP%\Sysqemvcarb.exe
- %TEMP%\Sysqemgxvyq.exe
- %TEMP%\Sysqemexaqg.exe
- %TEMP%\Sysqemlqshl.exe
- %TEMP%\Sysqemqtcwo.exe
- %TEMP%\Sysqemfgknx.exe
- %TEMP%\Sysqemvcqnu.exe
- %TEMP%\Sysqemsfeah.exe
- %TEMP%\Sysqemxogmo.exe
- %TEMP%\Sysqempynli.exe
- %TEMP%\Sysqemhnkdo.exe
- %TEMP%\Sysqemunbro.exe
- %TEMP%\qpath.ini
- %TEMP%\Sysqamqqvaqqd.exe
- %TEMP%\Sysqembwnav.exe
- %TEMP%\Sysqemggfco.exe
- %TEMP%\Sysqemlvxue.exe
- %TEMP%\Sysqemwtcox.exe
- %TEMP%\Sysqemtnjqj.exe
- %TEMP%\Sysqemcdssk.exe
- %TEMP%\Sysqemzwwtv.exe
- %TEMP%\Sysqemssxjd.exe
- %TEMP%\Sysqemhwkik.exe
- %TEMP%\Sysqemzhoii.exe
- %TEMP%\Sysqemrkdyv.exe
- %TEMP%\Sysqemevyjq.exe
- %TEMP%\Sysqemrbbcp.exe
- %TEMP%\Sysqemhfrdx.exe
- %TEMP%\Sysqemjhymt.exe
- %TEMP%\Sysqemragkn.exe
- %TEMP%\Sysqemfkthb.exe
- %TEMP%\Sysqemznhcm.exe
- %TEMP%\Sysqemkeczm.exe
- %TEMP%\Sysqemzbayo.exe
- %TEMP%\Sysqemsxbww.exe
- %TEMP%\Sysqempwmhk.exe
- %TEMP%\Sysqemhhcxx.exe
- %TEMP%\Sysqemewaez.exe
- %TEMP%\Sysqemveclv.exe
- %TEMP%\Sysqempktlc.exe
- %TEMP%\Sysqemrqwml.exe
- %TEMP%\Sysqemdleak.exe
- %TEMP%\Sysqemyuvoe.exe
- %TEMP%\Sysqemtatyc.exe
- %TEMP%\Sysqemmafjn.exe
- %TEMP%\Sysqemlqijk.exe
- %TEMP%\Sysqemdquuv.exe
- %TEMP%\Sysqemwtyls.exe
- %TEMP%\Sysqemlqosu.exe
- %TEMP%\Sysqemdfxnk.exe
- %TEMP%\Sysqemoeual.exe
- %TEMP%\Sysqembyknc.exe
- %TEMP%\Sysqemzzkhb.exe
- %TEMP%\Sysqemwlvov.exe
- %TEMP%\Sysqemgzyer.exe
- %TEMP%\Sysqemojkuv.exe
- %TEMP%\Sysqembesiu.exe
- %TEMP%\Sysqemyesbl.exe
- %TEMP%\Sysqemomcii.exe
- %TEMP%\Sysqemgxryv.exe
- %TEMP%\Sysqemsozmn.exe
- %TEMP%\Sysqemsokpe.exe
- %TEMP%\Sysqempsnrg.exe
- %TEMP%\Sysqemautmk.exe
- %TEMP%\Sysqemfzwsr.exe
- %TEMP%\Sysqemksvcv.exe
- %TEMP%\Sysqemamcic.exe
- %TEMP%\Sysqemiiuop.exe
- %TEMP%\Sysqemkkiyl.exe
- %TEMP%\Sysqemuglgg.exe
- %TEMP%\Sysqemlroex.exe
- %TEMP%\Sysqemtwbpu.exe
- %TEMP%\Sysqemvyiyq.exe
- %TEMP%\Sysqemtyhsh.exe
- %TEMP%\Sysqemfpmsd.exe
- %TEMP%\Sysqemiudyi.exe
- %TEMP%\Sysqemvwmhq.exe
- %TEMP%\Sysqemvgclw.exe
- %TEMP%\Sysqemybucf.exe
- %TEMP%\Sysqemibixd.exe
- %TEMP%\Sysqemeafyi.exe
- %TEMP%\Sysqemvcarb.exe
- %TEMP%\Sysqemsfeah.exe
- %TEMP%\Sysqemtlynm.exe
- %TEMP%\Sysqemlqshl.exe
- %TEMP%\Sysqemgxvyq.exe
- %TEMP%\Sysqemfgknx.exe
- %TEMP%\Sysqemcdssk.exe
- %TEMP%\Sysqemqtcwo.exe
- %TEMP%\Sysqemxogmo.exe
- %TEMP%\Sysqemvcqnu.exe
- %TEMP%\Sysqemhnkdo.exe
- %TEMP%\Sysqemwtcox.exe
- %TEMP%\Sysqempynli.exe
- %TEMP%\Sysqemunbro.exe
- %TEMP%\Sysqamqqvaqqd.exe
- %TEMP%\Sysqemggfco.exe
- %TEMP%\Sysqemexaqg.exe
- %TEMP%\Sysqembwnav.exe
- %TEMP%\Sysqemtnjqj.exe
- %TEMP%\Sysqemlvxue.exe
- %TEMP%\Sysqemzwwtv.exe
- %TEMP%\Sysqemssxjd.exe
- %TEMP%\Sysqemhwkik.exe
- %TEMP%\Sysqemzhoii.exe
- %TEMP%\Sysqemrkdyv.exe
- %TEMP%\Sysqemevyjq.exe
- %TEMP%\Sysqemrbbcp.exe
- %TEMP%\Sysqemhfrdx.exe
- %TEMP%\Sysqemjhymt.exe
- %TEMP%\Sysqemragkn.exe
- %TEMP%\Sysqemfkthb.exe
- %TEMP%\Sysqemznhcm.exe
- %TEMP%\Sysqemkeczm.exe
- %TEMP%\Sysqemzbayo.exe
- %TEMP%\Sysqemsxbww.exe
- %TEMP%\Sysqempwmhk.exe
- %TEMP%\Sysqemhhcxx.exe
- %TEMP%\Sysqemewaez.exe
- %TEMP%\Sysqemveclv.exe
- %TEMP%\Sysqempktlc.exe