Windows
System32
WindowsPowerShell
powershell.exe
Windows
System32
WindowsPowerShell
powershell.exe
?..\..\..\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
-WindowStyle hidden -ExecutionPolicy Bypass -nologo -noprofile -File "C:\Users\%username%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\dd.ps1"
S-1-5-21-1008128293-1691262187-244381973-1001