cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "Ghhq" C:\Users\test22\AppData\Local\Temp\n.wbk
2752WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\test22\AppData\Local\Temp\n.wbk"
2792splwow64.exe C:\Windows\splwow64.exe 12288
1684