cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f
2276schtasks.exe schtasks /create /tn {5COA58OA-V7LD-VVME-LIJH-LESBVWGMLVKR} /tr C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe /ri 10 /st 00:00 /sc daily /du 9999:59 /f
2668cmd.exe "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" "*S-1-5-7:(R,REA,RA,RD)"
2664icacls.exe icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "*S-1-1-0:(R,REA,RA,RD)" "*S-1-5-7:(R,REA,RA,RD)"
2080cmd.exe "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "SYSTEM:(R,REA,RA,RD)"
2092icacls.exe icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "SYSTEM:(R,REA,RA,RD)"
1204cmd.exe "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Administrators:(R,REA,RA,RD)"
2704icacls.exe icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Administrators:(R,REA,RA,RD)"
1296cmd.exe "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Users:(R,REA,RA,RD)"
2412icacls.exe icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "Users:(R,REA,RA,RD)"
204cmd.exe "C:\Windows\System32\cmd.exe" /c icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "test22:(R,REA,RA,RD)"
2040icacls.exe icacls "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}" /inheritance:e /deny "test22:(R,REA,RA,RD)"
29885OEH.exe "C:\Users\test22\AppData\Local\{PY8FB7HW-FT5Q-FHEK-F5GD-50DG2N98L0QZ}\5OEH.exe"
2232