cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "zQBcaqxBrBs" C:\Users\test22\AppData\Local\Temp\tmp00000000
2648rundll32.exe "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\test22\AppData\Local\Temp\tmp00000000
2752editplus.exe "editplus.exe"
2900