wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\test22\AppData\Roaming\Adobe\8ZymEhuS91wN1CjUXL.vbe"
1556chcp.com chcp 65001
2880w32tm.exe w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2
2140wininit.exe "C:\Windows\System32\wevtapi\wininit.exe"
1436reg.exe reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 1 /f
288