powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -ExecutionPolicy unrestricted -File C:\Users\test22\AppData\Local\Temp\boy1start.ps1
316powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\Public\boy1.pif"
2812AcroRd32.exe "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" "C:\Users\test22\AppData\Local\Temp\golden.pdf"
2924powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Roaming\TfOyvHCStQAJyb.exe"
2968schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\TfOyvHCStQAJyb" /XML "C:\Users\test22\AppData\Local\Temp\tmp72C5.tmp"
3020RegSvcs.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"
2084explorer.exe C:\Windows\Explorer.EXE
1236