Powershell.exe "Powershell" Copy-Item 'C:\Users\test22\AppData\Local\Temp\VMNCXJFDJK.exe' 'C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SysteSHDHSHSDSm.exe'
2812RegSvcs.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"
2868explorer.exe C:\Windows\Explorer.EXE
1452