The fake installer does not just add a Defender exclusion — it uses icacls so you cannot remove it
2026-09-03Security
Microsoft documented a campaign of counterfeit vendor sites whose installers disable four Windows Update services, rename the update DLLs, set Defender exclusions and then lock the ACLs against standard users. The payload hash changes on every download, so there is no hash to block.