powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -executionpolicy remotesigned -File "C:\Users\test22\AppData\Local\Temp\1000121041\to.ps1"
2248chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --new-window https://youtube.com/account?=https://accounts.google.com/v3/signin/challenge/pwd --start-fullscreen --no-first-run --disable-session-crashed-bubble --disable-infobars
2360chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef3e96e00,0x7fef3e96e10,0x7fef3e96e20
2408explorer.exe C:\Windows\Explorer.EXE
1236