powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -ExecutionPolicy unrestricted -File C:\Users\test22\AppData\Local\Temp\geo.ps1
1532cmd.exe "C:\Windows\system32\cmd.exe" /c md C:\ProgramData\mssts
2920taskkill.exe taskkill /f /im dsm.exe
3020taskkill.exe taskkill /f /im dom.exe
2328taskkill.exe taskkill /f /im solr.exe
2588cmd.exe "C:\Windows\system32\cmd.exe" /c del /f /q C:\Windows\System32\config\systemprofile\dom\*
2656WMIC.exe "C:\Windows\System32\Wbem\WMIC.exe" process where "ExecutablePath like 'C:\\ProgramData\\Microsoft\\Windows\\Templates\\%'" delete
2712cmd.exe "C:\Windows\system32\cmd.exe" /c del /f /q C:\ProgramData\Microsoft\Windows\Templates\*.exe
2960WMIC.exe "C:\Windows\System32\Wbem\WMIC.exe" process where "ExecutablePath like 'C:\\ProgramData\\Microsoft\\Windows\\WER\\%'" delete
3052cmd.exe "C:\Windows\system32\cmd.exe" /c del /f /q C:\ProgramData\Microsoft\Windows\WER\*
508taskkill.exe taskkill /f /im JavaAccessBridge.exe
2620cmd.exe "C:\Windows\system32\cmd.exe" /c del /f /q C:\Users\Public\Videos\*
2704taskkill.exe taskkill /f /im kthreaddk.exe
2924taskkill.exe taskkill /f /im sysupdate.exe
2636taskkill.exe taskkill /f /im powershell.exe
2728