Technical Information
- User Account Control (UAC)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "<Full path to file>" -Force
- <SYSTEM32>\svchost.exe
- <SYSTEM32>\cmd.exe
- %WINDIR%\regedit.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\aspnet_wp.exe
- <SYSTEM32>\notepad.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\csc.exe
- <SYSTEM32>\calc.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\ilasm.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\vbc.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\ngen.exe
- wmplayer.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "<Full path to file>" -Force' (with hidden window)