40390d043fe0131afcf00e297b2d350bd5d3d4bf6ead3efaef007aa635348fe7.exe "C:\Users\Administrator\AppData\Local\Temp\40390d043fe0131afcf00e297b2d350bd5d3d4bf6ead3efaef007aa635348fe7.exe"
2360reg.exe REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WindowsDef" /t REG_SZ /d "C:\Users\Administrator\AppData\Roaming\Directory\Windowsdef.exe" /f
408Windowsdef.exe "C:\Users\Administrator\AppData\Roaming\Directory\Windowsdef.exe"
1916