Техническая информация
- '<SYSTEM32>\taskkill.exe' /im MsUpEng.exe /f
- '<SYSTEM32>\net1.exe' sAop securiAo cenAer
- '<SYSTEM32>\sc.exe' stop wscsvc
- '<SYSTEM32>\sc.exe' config wuaoserv start= disablee
- '<SYSTEM32>\net1.exe' stop MsMpSvc
- '<SYSTEM32>\net1.exe' sAop MpsSvc
- '<SYSTEM32>\taskkill.exe' /im NisSrv.exe /f
- '<SYSTEM32>\taskkill.exe' /im msseces.exe /f
- '<SYSTEM32>\net.exe' stop WinDefend
- '<SYSTEM32>\net.exe' stop MsMpSvc
- '<SYSTEM32>\net1.exe' stop WinDefend
- ClassName: 'PROCMON_WINDOW_CLASS' WindowName: ''
- ClassName: 'RegMonClass' WindowName: ''
- ClassName: 'FileMonClass' WindowName: ''
- %ALLUSERSPROFILE%\Application Data\TEMP\RAIDTest
- ClassName: '' WindowName: ''