Contributed By: 59e5aaf4
IBM's pcsnp.exe calls cmd.exe /c mkdir C:\Temp from processes such as mpnotify.exe and lsass.exe. Read the writeup for this; it's amazing.
pcsnp.exe
cmd.exe /c mkdir C:\Temp
mpnotify.exe
lsass.exe