2222222.exe "C:\Users\test22\AppData\Local\Temp\2222222.exe"
Powershell.exe "Powershell.exe" -ExecutionPolicy Bypass -command Copy-Item 'C:\Users\test22\AppData\Local\Temp\2222222.exe' 'C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchost.exe'
No process loaded Click on a process in the tree above to load its data.