wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\test22\AppData\Local\Temp\_Bbmzsbjgqtrphzjybyx.vbs"
812powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Set-MpPreference -ExclusionPath C:\,'C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\outlook.exe'
1032iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2908 CREDAT:145409
1744iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2908 CREDAT:79875
2088svchost.exe C:\Windows\SysWOW64\svchost.exe
2572svchost.exe C:\Windows\SysWOW64\svchost.exe
2764edi.exe C:\Users\test22\AppData\Local\Temp\edi.exe /stext "C:\Users\test22\AppData\Local\Temp\ozdweyveusxkjlmjfnuehefwbqbf"
2564edi.exe C:\Users\test22\AppData\Local\Temp\edi.exe /stext "C:\Users\test22\AppData\Local\Temp\yuqpfrfyqapplranoypfsranjelgirf"
2180edi.exe C:\Users\test22\AppData\Local\Temp\edi.exe /stext "C:\Users\test22\AppData\Local\Temp\jwvh"
3036