schtasks.exe schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 HR" /sc HOURLY /rl HIGHEST
2756schtasks.exe schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 LG" /sc ONLOGON /rl HIGHEST
2840GCJM2BjvEnYGmelfoaDl.exe "C:\Users\test22\AppData\Local\Temp\heidiawcqm451S0Vs\GCJM2BjvEnYGmelfoaDl.exe"
744iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2088 CREDAT:145409
192chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" https://www.youtube.com
3068chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=65.0.3325.181 --initial-client-data=0x88,0x8c,0x90,0x84,0x94,0x7fef3e9f1e8,0x7fef3e9f1f8,0x7fef3e9f208
2116chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=1632 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6
3104chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" https://www.facebook.com/video
1892chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=65.0.3325.181 --initial-client-data=0x88,0x8c,0x90,0x84,0x94,0x7fef3e9f1e8,0x7fef3e9f1f8,0x7fef3e9f208
2424chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=1256 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6
1400chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" https://accounts.google.com
1736chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=65.0.3325.181 --initial-client-data=0x88,0x8c,0x90,0x84,0x94,0x7fef3e9f1e8,0x7fef3e9f1f8,0x7fef3e9f208
936chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=1616 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6
3184crashreporter.exe "C:\Program Files\Mozilla Firefox\crashreporter.exe" "C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\minidumps\9d1d02e8-e52e-4b7c-a24c-39f14a1c6ae0.dmp"
2472minidump-analyzer.exe "C:\Program Files\Mozilla Firefox\minidump-analyzer.exe" "C:\Users\test22\AppData\Roaming\Mozilla\Firefox\Profiles\qxo5wa6x.default-release\minidumps\9d1d02e8-e52e-4b7c-a24c-39f14a1c6ae0.dmp"
3556crashreporter.exe "C:\Program Files\Mozilla Firefox\crashreporter.exe" "C:\Users\test22\AppData\Local\Temp\\c3c87995-676e-4f72-8350-9111d3bc0359.dmp"
3080minidump-analyzer.exe "C:\Program Files\Mozilla Firefox\minidump-analyzer.exe" "C:\Users\test22\AppData\Local\Temp\\c3c87995-676e-4f72-8350-9111d3bc0359.dmp"
3612crashreporter.exe "C:\Program Files\Mozilla Firefox\crashreporter.exe" "C:\Users\test22\AppData\Local\Temp\\6ba4bacf-9712-4944-82ed-c3b1ff9122cc.dmp"
3976minidump-analyzer.exe "C:\Program Files\Mozilla Firefox\minidump-analyzer.exe" "C:\Users\test22\AppData\Local\Temp\\6ba4bacf-9712-4944-82ed-c3b1ff9122cc.dmp"
3228reZ6hWk3uTMCU8DEiLuN.exe "C:\Users\test22\AppData\Local\Temp\heidiawcqm451S0Vs\reZ6hWk3uTMCU8DEiLuN.exe"
2620gGsdfWLuIIWuTEAQRw0I.exe "C:\Users\test22\AppData\Local\Temp\heidiawcqm451S0Vs\gGsdfWLuIIWuTEAQRw0I.exe"
452mfiHK3tvHMJf4FRrzQj9.exe "C:\Users\test22\AppData\Local\Temp\heidiawcqm451S0Vs\mfiHK3tvHMJf4FRrzQj9.exe"
1332gn2NF5bKoBfySMlY_Quu.exe "C:\Users\test22\AppData\Local\Temp\heidiawcqm451S0Vs\gn2NF5bKoBfySMlY_Quu.exe"
3056explorer.exe C:\Windows\Explorer.EXE
1452