dllhost.exe "C:\Windows\System32\dllhost.exe"
5916findstr.exe findstr /V /R "^nZwSZJdQSZwKBWJCtpbfZHNwzsXALugVPsbikcLGmlTQMSJGkUUtRoHQkZmHLQyLLuVpnCdInRQPNWfBIsgQkprGKGWkWrUJtiyFXmiJDkGqaSrgKXZxBgABegmS$" Che.vsd
8168cmd.exe cmd.exe /C ver > "C:\Users\test22\AppData\Local\Temp\chrD6EC.tmp"
8888WMIC.exe wmic process get Name
5932cmd.exe cmd /c makecab /V3 "C:\Users\test22\AppData\Local\Temp\5e65aaa67ea5c920748e191e17645c6a932f8796" "C:\Users\test22\AppData\Local\Temp\chrD96F.tmp"
4468makecab.exe makecab /V3 "C:\Users\test22\AppData\Local\Temp\5e65aaa67ea5c920748e191e17645c6a932f8796" "C:\Users\test22\AppData\Local\Temp\chrD96F.tmp"
1388PING.EXE ping 127.0.0.1 -n 30
5272