wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\w2.vbs
cmd.exe cmd /c ""C:\Users\test22\AppData\Roaming\WindowsUpdate\GMING.cmd" "
powershell.exe PowerShell.exe -NoProfile -ExecutionPolicy Bypass -Command C:\Users\test22\AppData\Roaming\WindowsUpdate\MXXFA.ps1
No process loaded Click on a process in the tree above to load its data.