AqLCNUYV_7AvOx5vhd2uahj6.exe "C:\Users\test22\Pictures\Minor Policy\AqLCNUYV_7AvOx5vhd2uahj6.exe"
2260rundll32.exe "C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL "C:\Users\test22\AppData\Local\Temp\7zS4D82C877\GJ5.A"
1152rundll32.exe C:\Windows\system32\RunDll32.exe Shell32.dll,Control_RunDLL "C:\Users\test22\AppData\Local\Temp\7zS4D82C877\GJ5.A"
2404rundll32.exe "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\shell32.dll",#44 "C:\Users\test22\AppData\Local\Temp\7zS4D82C877\GJ5.A"
2068KHOWPA_NrCHzAtN1rLIYWalB.exe "C:\Users\test22\Pictures\Minor Policy\KHOWPA_NrCHzAtN1rLIYWalB.exe"
2212AppLaunch.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"
1592PLutVJwMhKkBWy0I4dDNw_rf.exe "C:\Users\test22\Pictures\Minor Policy\PLutVJwMhKkBWy0I4dDNw_rf.exe"
2224E4520MDs1ERkljMZ6fnSAHxW.exe "C:\Users\test22\Documents\E4520MDs1ERkljMZ6fnSAHxW.exe"
3296schtasks.exe schtasks /create /f /RU "test22" /tr "C:\Program Files (x86)\PowerControl\PowerControl_Svc.exe" /tn "PowerControl HR" /sc HOURLY /rl HIGHEST
3372schtasks.exe schtasks /create /f /RU "test22" /tr "C:\Program Files (x86)\PowerControl\PowerControl_Svc.exe" /tn "PowerControl LG" /sc ONLOGON /rl HIGHEST
3516rzNSDBWnOuUp9KZQf1vEEBO8.exe "C:\Users\test22\Pictures\Minor Policy\rzNSDBWnOuUp9KZQf1vEEBO8.exe"
22401ge81gE7.exe C:\Users\test22\AppData\Local\Temp\IXP003.TMP\1ge81gE7.exe
22322eX5046.exe C:\Users\test22\AppData\Local\Temp\IXP003.TMP\2eX5046.exe
3868b_BfHcqb3_uTLEMqIjzZAgrW.exe "C:\Users\test22\Pictures\Minor Policy\b_BfHcqb3_uTLEMqIjzZAgrW.exe"
2268UzT3o_eh7ilHUsbNqgRDNpMT.exe "C:\Users\test22\Pictures\Minor Policy\UzT3o_eh7ilHUsbNqgRDNpMT.exe"
286838fcARWiRHfIEOuzqwSxrDuR.exe "C:\Users\test22\Pictures\Minor Policy\38fcARWiRHfIEOuzqwSxrDuR.exe"
2960po63wWbfrnNk9KmTiSB5uUws.exe "C:\Users\test22\Pictures\Minor Policy\po63wWbfrnNk9KmTiSB5uUws.exe"
1064XsoKeqrHlRgEydtPbMRBlV7C.exe "C:\Users\test22\Pictures\Minor Policy\XsoKeqrHlRgEydtPbMRBlV7C.exe"
1528XSZhrhE_Sfn_MkbKHwdmoqte.exe "C:\Users\test22\Pictures\Minor Policy\XSZhrhE_Sfn_MkbKHwdmoqte.exe"
1852vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe"
2804Bl6sYsQfyg42QbS0gcJUBZ4E.exe "C:\Users\test22\Pictures\Minor Policy\Bl6sYsQfyg42QbS0gcJUBZ4E.exe"
1780schtasks.exe schtasks /create /f /RU "test22" /tr "C:\ProgramData\WinTrackerSP\WinTrackerSP.exe" /tn "WinTrackerSP HR" /sc HOURLY /rl HIGHEST
2452schtasks.exe schtasks /create /f /RU "test22" /tr "C:\ProgramData\WinTrackerSP\WinTrackerSP.exe" /tn "WinTrackerSP LG" /sc ONLOGON /rl HIGHEST
3132Bl6sYsQfyg42QbS0gcJUBZ4E.exe "C:\Users\test22\Pictures\Minor Policy\Bl6sYsQfyg42QbS0gcJUBZ4E.exe"
4024qnsEAxgbAJ6_unx_zSEOUHz2.exe "C:\Users\test22\Pictures\Minor Policy\qnsEAxgbAJ6_unx_zSEOUHz2.exe"
1808qnsEAxgbAJ6_unx_zSEOUHz2.exe "C:\Users\test22\Pictures\Minor Policy\qnsEAxgbAJ6_unx_zSEOUHz2.exe"
2532icacls.exe icacls "C:\Users\test22\AppData\Local\31ff5d08-974d-447f-a18d-b1e6ddd2a356" /deny *S-1-1-0:(OI)(CI)(DE,DC)
3544qnsEAxgbAJ6_unx_zSEOUHz2.exe "C:\Users\test22\Pictures\Minor Policy\qnsEAxgbAJ6_unx_zSEOUHz2.exe" --Admin IsNotAutoStart IsNotTask
3736qnsEAxgbAJ6_unx_zSEOUHz2.exe "C:\Users\test22\Pictures\Minor Policy\qnsEAxgbAJ6_unx_zSEOUHz2.exe" --Admin IsNotAutoStart IsNotTask
3936L7QWnBrun6KRKkmF94SkLylb.exe "C:\Users\test22\Pictures\Minor Policy\L7QWnBrun6KRKkmF94SkLylb.exe"
2860explorer.exe C:\Windows\Explorer.EXE
1452