wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\test22\AppData\Local\Temp\Yfgimyclsfw.vbs"
1168AcroRd32.exe "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\test22\AppData\Local\Temp\Nqlkczemlz11720120210713093002.pdf"
2868explorer.exe C:\Windows\Explorer.EXE
1236powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Start-Sleep -s 5; Remove-Item -Path "C:\Users\test22\AppData\Local\Temp\Sonytec.exe" -Force
1792chcp.com chcp 65001
3028netsh.exe netsh wlan show profile
2548findstr.exe findstr All
2824