4.exe "C:\Users\test22\AppData\Local\Temp\New Feature\4.exe"
4892makecab.exe "C:\Windows\System32\makecab.exe"
8324cmd.exe "C:\Windows\System32\cmd.exe" /c BthUrthcwxEfMsumfqXYizJVlrwLy & aOjvhFz & rqIoiOXdvDFoGVGSQocaKqeC & weQrftByCXXfYk & cmd < Rimanete.sys
3660findstr.exe findstr /V /R "^EOCmSOcMUldAFhuCjnQpQGIsybMgkFJxaeXvTqwrKyOwYUPusMdeSUPYylzxeiAfBWoDdJIkbMnLSGzlIGXmgGBbhYdJGHwDEnAwMjPIttFuvrymRoMcpwqUcK$" Torno.sys
9132Troppe.exe.com C:\Users\test22\AppData\Roaming\XUGnyWzvizFylweeYySuMujumtetYJCSWAxQzDvzHFJJKYdtmVYluyoQHAZwTfnnRNpJGjIxJnnubDcANYErKaLRaEoTEcmailSXPHbhjDAHGear\Troppe.exe.com u
5256PING.EXE ping 127.0.0.1 -n 30
6696