iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2148 CREDAT:145409
2844untilmathematics.exe C:\Users\test22\AppData\Local\Temp\IXP002.TMP\untilmathematics.exe
2788schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN nhdues.exe /TR "C:\Users\test22\AppData\Local\Temp\1ff8bec27e\nhdues.exe" /F
2576cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "nhdues.exe" /P "test22:N"&&CACLS "nhdues.exe" /P "test22:R" /E&&echo Y|CACLS "..\1ff8bec27e" /P "test22:N"&&CACLS "..\1ff8bec27e" /P "test22:R" /E&&Exit
2736cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2948cacls.exe CACLS "nhdues.exe" /P "test22:N"
2132cacls.exe CACLS "nhdues.exe" /P "test22:R" /E
2532cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2752cacls.exe CACLS "..\1ff8bec27e" /P "test22:N"
2928cacls.exe CACLS "..\1ff8bec27e" /P "test22:R" /E
5361Dn33rKCA4dC8aXmng0BVypp.exe "C:\Users\test22\Pictures\1Dn33rKCA4dC8aXmng0BVypp.exe"
3060jsj9BnxQe1wUSt4fq4fFdIbl.exe "C:\Users\test22\Pictures\jsj9BnxQe1wUSt4fq4fFdIbl.exe"
26402v4fymhYYNWC2FFg5XXDybVC.exe "C:\Users\test22\Pictures\2v4fymhYYNWC2FFg5XXDybVC.exe"
2696vtmaPKRXAfqpNkKfnPwslgoN.exe "C:\Users\test22\Pictures\vtmaPKRXAfqpNkKfnPwslgoN.exe"
2888DhJlbLqN6jQFakonmgEZ33Ks.exe "C:\Users\test22\Pictures\DhJlbLqN6jQFakonmgEZ33Ks.exe"
3016tLqJinIq9eTQIYLlq5LobLYm.exe "C:\Users\test22\Pictures\tLqJinIq9eTQIYLlq5LobLYm.exe" --silent --allusers=0
2164