schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN Utsysc.exe /TR "C:\Users\test22\AppData\Local\Temp\e8b5234212\Utsysc.exe" /F
2772cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "Utsysc.exe" /P "test22:N"&&CACLS "Utsysc.exe" /P "test22:R" /E&&echo Y|CACLS "..\e8b5234212" /P "test22:N"&&CACLS "..\e8b5234212" /P "test22:R" /E&&Exit
2836cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2912cacls.exe CACLS "Utsysc.exe" /P "test22:N"
2952cacls.exe CACLS "Utsysc.exe" /P "test22:R" /E
3004cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
3052cacls.exe CACLS "..\e8b5234212" /P "test22:N"
604cacls.exe CACLS "..\e8b5234212" /P "test22:R" /E
21241.exe "C:\Users\test22\AppData\Local\Temp\1000006001\1.exe"
2200rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\aca439ae61e801\cred64.dll, Main
2472rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\aca439ae61e801\cred64.dll, Main
2512netsh.exe netsh wlan show profiles
2620rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\aca439ae61e801\clip64.dll, Main
2592schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN Utsysc.exe /TR "C:\Users\test22\AppData\Local\Temp\ea7c8244c8\Utsysc.exe" /F
2416cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "Utsysc.exe" /P "test22:N"&&CACLS "Utsysc.exe" /P "test22:R" /E&&echo Y|CACLS "..\ea7c8244c8" /P "test22:N"&&CACLS "..\ea7c8244c8" /P "test22:R" /E&&Exit
2636cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
1656cacls.exe CACLS "Utsysc.exe" /P "test22:N"
560cacls.exe CACLS "Utsysc.exe" /P "test22:R" /E
2884cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
1780cacls.exe CACLS "..\ea7c8244c8" /P "test22:N"
3036cacls.exe CACLS "..\ea7c8244c8" /P "test22:R" /E
1120haloup.exe "C:\Users\test22\AppData\Local\Temp\1000080001\haloup.exe"
2136rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\465dbc52837d81\cred64.dll, Main
2876rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\465dbc52837d81\cred64.dll, Main
916netsh.exe netsh wlan show profiles
2564rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\465dbc52837d81\clip64.dll, Main
2388amers.exe "C:\Users\test22\AppData\Local\Temp\1000081001\amers.exe"
3016trafico.exe "C:\Users\test22\AppData\Local\Temp\1000009001\trafico.exe"
1996TEST32.exe "C:\Users\test22\AppData\Local\Temp\1000020001\TEST32.exe"
1520build2.exe "C:\Users\test22\AppData\Local\Temp\1000024001\build2.exe"
1456TEST32.exe "C:\Users\test22\AppData\Local\Temp\1000027001\TEST32.exe"
1792AppLaunch.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"
3708AppLaunch.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"
38563mI23vW.exe C:\Users\test22\AppData\Local\Temp\IXP004.TMP\3mI23vW.exe
4000AppLaunch.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"
3124schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN explothe.exe /TR "C:\Users\test22\AppData\Local\Temp\fefffe8cea\explothe.exe" /F
1108cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "explothe.exe" /P "test22:N"&&CACLS "explothe.exe" /P "test22:R" /E&&echo Y|CACLS "..\fefffe8cea" /P "test22:N"&&CACLS "..\fefffe8cea" /P "test22:R" /E&&Exit
3280cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
3392cacls.exe CACLS "explothe.exe" /P "test22:N"
3728cacls.exe CACLS "explothe.exe" /P "test22:R" /E
3624cacls.exe CACLS "..\fefffe8cea" /P "test22:N"
2304cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
4060cacls.exe CACLS "..\fefffe8cea" /P "test22:R" /E
35366Ye1nZ1.exe C:\Users\test22\AppData\Local\Temp\IXP001.TMP\6Ye1nZ1.exe
300cmd.exe "C:\Windows\sysnative\cmd.exe" /c "C:\Users\test22\AppData\Local\Temp\EDD5.tmp\EDF6.tmp\EDF7.bat C:\Users\test22\AppData\Local\Temp\IXP000.TMP\7wT5Ey89.exe"
2964iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:3544 CREDAT:145409
552iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:3544 CREDAT:79875
1772iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:3544 CREDAT:145411
948explorer.exe C:\Windows\Explorer.EXE
1452