Powershell.exe "Powershell" Copy-Item 'C:\Users\test22\AppData\Local\Temp\BCDGFJFJGHKJK.exe' 'C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Systddem.exe'
2820cvtres.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe"
2876explorer.exe C:\Windows\Explorer.EXE
1452