6WCKE74G.tmp "C:\Users\test22\AppData\Local\Temp\is-PJ43B.tmp\6WCKE74G.tmp" /SL5="$5012C,4486469,58368,C:\Users\test22\AppData\Local\Temp\TCDD8B2.tmp\6WCKE74G.exe"
2804XS1WFR6F.exe "C:\Users\test22\AppData\Roaming\Microsoft\XS1WFR6F.exe"
2888explorer.exe C:\Windows\Explorer.EXE
1452