PEP2.tmp "C:\Users\test22\AppData\Local\Temp\is-196DR.tmp\PEP2.tmp" /SL5="$80178,140559,56832,C:\Users\test22\AppData\Local\Temp\PEP2.exe"
2604Kobonewuju.exe "C:\Users\test22\AppData\Local\Temp\ed-57f66-9e7-d698d-a6c0312e1dca6\Kobonewuju.exe"
2080explorer.exe C:\Windows\Explorer.EXE
1452