Skip to content

If Defender is removed by windows-defender-remover, it will fail to detect threats and the process will exit. #5

Description

@bytecategory

PS C:\> Get-MpComputerStatus
Get-MpComputerStatus : Provider load failure
At line:1 char:1
+ Get-MpComputerStatus
+ ~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (MSFT_MpComputerStatus:ROOT\Microsoft\...pComputerStatus) [Get-MpComputerS
   tatus], CimException
    + FullyQualifiedErrorId : HRESULT 0x80041013,Get-MpComputerStatus

PS C:\> .\ShieldBreak.exe
[+] \??\C:\ShieldBreak_{D704F330-D6B3-4434-A383-BD2D4EF54EC4} was created.
[+] Cloud provider has been registered.
[+] Attached cloud provider to C:\ShieldBreak_{D704F330-D6B3-4434-A383-BD2D4EF54EC4}
[+] Placeholder created.
[+] \BaseNamedObjects\Restricted\WD_TARGET_{D704F330-D6B3-4434-A383-BD2D4EF54EC4} object manager directory created
[+] \BaseNamedObjects\Restricted\WD_SHADOW_{D704F330-D6B3-4434-A383-BD2D4EF54EC4} object manager directory created
[+] WD_SCAN <=> \??\C:\ShieldBreak_{D704F330-D6B3-4434-A383-BD2D4EF54EC4} object link created
[+] WD_SCAN <=> \CLFS\??\C:\ShieldBreak_{D704F330-D6B3-4434-A383-BD2D4EF54EC4} object link created
[+] Created \??\C:\ShieldBreak_{D704F330-D6B3-4434-A383-BD2D4EF54EC4}\BERLIN
[+] Copied C:\Windows\System32\ntdll.dll => C:\ShieldBreak_{D704F330-D6B3-4434-A383-BD2D4EF54EC4}\BERLIN:stream
[*] Scan initiated for \\.\globalroot\BaseNamedObjects\Restricted\WD_SHADOW_{D704F330-D6B3-4434-A383-BD2D4EF54EC4}\WD_SCAN\BERLIN
[*] Please wait...
[-] No threats found.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions