Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'SystemUpdate' = '<Полный путь к файлу>'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Set-MpPreference -DisableRealtimeMonitoring $true"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath C:\"
- '<SYSTEM32>\net.exe' stop WinDefend /y
- '<DNS_SERVER>':53
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Set-MpPreference -DisableRealtimeMonitoring $true"
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Add-MpPreference -ExclusionPath C:\"
- '<SYSTEM32>\cmd.exe' /c net stop WinDefend /y
- '<SYSTEM32>\net1.exe' stop WinDefend /y