k9845936.exe C:\Users\test22\AppData\Local\Temp\IXP002.TMP\k9845936.exe
2260l5196213.exe C:\Users\test22\AppData\Local\Temp\IXP002.TMP\l5196213.exe
2328schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN metado.exe /TR "C:\Users\test22\AppData\Local\Temp\a9e2a16078\metado.exe" /F
2100cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "metado.exe" /P "test22:N"&&CACLS "metado.exe" /P "test22:R" /E&&echo Y|CACLS "..\a9e2a16078" /P "test22:N"&&CACLS "..\a9e2a16078" /P "test22:R" /E&&Exit
2212cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2296cacls.exe CACLS "metado.exe" /P "test22:N"
2236cacls.exe CACLS "metado.exe" /P "test22:R" /E
2080cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2552cacls.exe CACLS "..\a9e2a16078" /P "test22:N"
2776cacls.exe CACLS "..\a9e2a16078" /P "test22:R" /E
2452rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\006700e5a2ab05\clip64.dll, Main
2376n9782940.exe C:\Users\test22\AppData\Local\Temp\IXP000.TMP\n9782940.exe
3028explorer.exe C:\Windows\Explorer.EXE
1236