chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0x138,0x13c,0x140,0x10c,0x144,0x7fef26c6e00,0x7fef26c6e10,0x7fef26c6e20
4612cmd.exe /c schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\GiE6UzXAHqzzY1B.exe" /tn "\WindowsAppPool\GiE6UzXAHqzzY1B"
2052schtasks.exe schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\GiE6UzXAHqzzY1B.exe" /tn "\WindowsAppPool\GiE6UzXAHqzzY1B"
3200chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0x134,0x138,0x13c,0x108,0x140,0x7fef25c6e00,0x7fef25c6e10,0x7fef25c6e20
5108cmd.exe /c schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\J9gHKT9nvgbi3o1.exe" /tn "\WindowsAppPool\J9gHKT9nvgbi3o1"
3160schtasks.exe schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\J9gHKT9nvgbi3o1.exe" /tn "\WindowsAppPool\J9gHKT9nvgbi3o1"
3336NvoO7emaO6N0CgX.exe "C:\Users\test22\AppData\Local\Temp\NvoO7emaO6N0CgX.exe"
3272cmd.exe /c schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\NvoO7emaO6N0CgX.exe" /tn "\WindowsAppPool\NvoO7emaO6N0CgX"
3364schtasks.exe schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\NvoO7emaO6N0CgX.exe" /tn "\WindowsAppPool\NvoO7emaO6N0CgX"
3692QR1quzyXCWpIaCo.exe "C:\Users\test22\AppData\Local\Temp\QR1quzyXCWpIaCo.exe"
3444cmd.exe /c schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\QR1quzyXCWpIaCo.exe" /tn "\WindowsAppPool\QR1quzyXCWpIaCo"
3604schtasks.exe schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\QR1quzyXCWpIaCo.exe" /tn "\WindowsAppPool\QR1quzyXCWpIaCo"
3944TID1kUKJVi1qfvO.exe "C:\Users\test22\AppData\Local\Temp\TID1kUKJVi1qfvO.exe"
3736AppLaunch.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"
3772cmd.exe /c schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\TID1kUKJVi1qfvO.exe" /tn "\WindowsAppPool\TID1kUKJVi1qfvO"
3932schtasks.exe schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\TID1kUKJVi1qfvO.exe" /tn "\WindowsAppPool\TID1kUKJVi1qfvO"
3264cmd.exe /c schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\W4LCHeXwJ8D8ORK.exe" /tn "\WindowsAppPool\W4LCHeXwJ8D8ORK"
3356schtasks.exe schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\W4LCHeXwJ8D8ORK.exe" /tn "\WindowsAppPool\W4LCHeXwJ8D8ORK"
28720rnK339j3YfQnJa.exe "C:\Users\test22\AppData\Local\Temp\0rnK339j3YfQnJa.exe"
3520cmd.exe /c schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\0rnK339j3YfQnJa.exe" /tn "\WindowsAppPool\0rnK339j3YfQnJa"
3856schtasks.exe schtasks /create /F /sc minute /mo 15 /tr "C:\Users\test22\AppData\Local\Temp\0rnK339j3YfQnJa.exe" /tn "\WindowsAppPool\0rnK339j3YfQnJa"
21082UP350IV.exe C:\Users\test22\AppData\Local\Temp\IXP004.TMP\2UP350IV.exe
24443zc6jy08.exe C:\Users\test22\AppData\Local\Temp\IXP003.TMP\3zc6jy08.exe
3024chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0x138,0x13c,0x140,0x10c,0x144,0x7fef25c6e00,0x7fef25c6e10,0x7fef25c6e20
4800schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN explothe.exe /TR "C:\Users\test22\AppData\Local\Temp\fefffe8cea\explothe.exe" /F
2960cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "explothe.exe" /P "test22:N"&&CACLS "explothe.exe" /P "test22:R" /E&&echo Y|CACLS "..\fefffe8cea" /P "test22:N"&&CACLS "..\fefffe8cea" /P "test22:R" /E&&Exit
1700cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2004cacls.exe CACLS "explothe.exe" /P "test22:N"
2528cacls.exe CACLS "explothe.exe" /P "test22:R" /E
2332cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
3064cacls.exe CACLS "..\fefffe8cea" /P "test22:N"
2140cacls.exe CACLS "..\fefffe8cea" /P "test22:R" /E
2252powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -executionpolicy remotesigned -File "C:\Users\test22\AppData\Local\Temp\1000010041\1.ps1"
3044iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" https://accounts.google.com/
3556iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:3556 CREDAT:145409
4008chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" https://accounts.google.com/
3876chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0x138,0x13c,0x140,0x10c,0x144,0x7fef25c6e00,0x7fef25c6e10,0x7fef25c6e20
3232AppLaunch.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"
2544AppLaunch.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"
4108chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
49883Aw3ON84.exe C:\Users\test22\AppData\Local\Temp\IXP005.TMP\3Aw3ON84.exe
3924chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0x138,0x13c,0x140,0x10c,0x144,0x7fef26c6e00,0x7fef26c6e10,0x7fef26c6e20
22325tj76QQ.exe C:\Users\test22\AppData\Local\Temp\IXP001.TMP\5tj76QQ.exe
4704cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\test22\AppData\Local\Temp\FCF4.tmp\FCF5.tmp\FCF6.bat C:\Users\test22\AppData\Local\Temp\IXP000.TMP\6gX51Dp.exe"
4784AppLaunch.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"
4348rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\006700e5a2ab05\clip64.dll, Main
4500cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\test22\AppData\Local\Temp\D54.tmp\D55.tmp\D66.bat C:\Users\test22\AppData\Local\Temp\IXP000.TMP\6RG67Gn.exe"
2644iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2456 CREDAT:145409
536iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2456 CREDAT:79877
4924