reg.exe REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /f /v Startup /t REG_SZ /d "C:\ProgramData\Check Management v1.4.9"
2160timeout.exe timeout 4
12645552d379.exe "C:\ProgramData\Check Management v1.4.9\5552d379.exe"
2596ZH0OUCCaah2.exe "C:\Users\Public\ZH0OUCCaah2.exe"
2056