Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdate' = '<Полный путь к файлу>'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Set-MpPreference -DisableRealtimeMonitoring $true
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath C:\
- '<SYSTEM32>\cmd.exe' /c powershell -Command Set-MpPreference -DisableRealtimeMonitoring $true
- '<SYSTEM32>\cmd.exe' /c powershell -Command Add-MpPreference -ExclusionPath C:\