Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Registry:
- HKEY_LOCAL_MACHINE/SOFTWARE/Policies/Microsoft/Windows Defender
- DWORD: DisableAntiSpyware, set value to 1
- Delete to enable
- Autoruns: Filter "security", disable (uncheck) Windows Security Service:
- Windows Security Service / SecurityHealthService / c:\windows\system32\securityhealthservice.exe
- Enable by re-checking the tick box
- Powershell:
- Disable: Set-MpPreference -DisableRealtimeMonitoring $true
- Enable: Set-MpPreference -DisableRealtimeMonitoring $false
- Registry File Disable: reg import E:\wd_dis.reg
- Needs run as Trusted Installer / Command Prompt with AdvancedRun
- https://www.nirsoft.net/utils/advanced_run.html
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdBoot]
- "Start"=dword:00000004
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdFilter]
- "Start"=dword:00000004
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdNisDrv]
- "Start"=dword:00000004
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend]
- "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,\
- 00,44,00,61,00,74,00,61,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,\
- 66,00,74,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,44,00,65,\
- 00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,50,00,6c,00,61,00,74,00,66,00,\
- 6f,00,72,00,6d,00,5c,00,34,00,2e,00,31,00,38,00,2e,00,32,00,32,00,30,00,31,\
- 00,2e,00,31,00,30,00,2d,00,30,00,5c,00,6e,00,75,00,6c,00,6c,00,2e,00,65,00,\
- 78,00,65,00,22,00,00,00
- "Start"=dword:00000004
- Registry File Enable: reg import E:\wd_en.reg
- Needs run as Trusted Installer / Command Prompt with AdvancedRun
- https://www.nirsoft.net/utils/advanced_run.html
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdBoot]
- "Start"=dword:00000000
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdFilter]
- "Start"=dword:00000000
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdNisDrv]
- "Start"=dword:00000003
- [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend]
- "ImagePath"=hex(2):22,00,43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
- 6d,00,44,00,61,00,74,00,61,00,5c,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,\
- 00,66,00,74,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,44,00,\
- 65,00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,50,00,6c,00,61,00,74,00,66,\
- 00,6f,00,72,00,6d,00,5c,00,34,00,2e,00,31,00,38,00,2e,00,32,00,32,00,30,00,\
- 31,00,2e,00,31,00,30,00,2d,00,30,00,5c,00,4d,00,73,00,4d,00,70,00,45,00,6e,\
- 00,67,00,2e,00,65,00,78,00,65,00,22,00,00,00
- "Start"=dword:00000002
- Reboot computer
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement