403Webshell
Server IP : 209.209.40.120  /  Your IP : 216.73.217.112
Web Server : Microsoft-IIS/10.0
System : Windows NT NEWWWW 10.0 build 17763 (Windows Server 2019) i586
User : NEWWWW$ ( 0)
PHP Version : 8.3.30
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /ProgramData/Microsoft/Windows Defender/Platform/4.18.26050.15-0/zh-TW/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /ProgramData/Microsoft/Windows Defender/Platform/4.18.26050.15-0/zh-TW/ProtectionManagement.dll.mui
MZ����@���	�!�L�!This program cannot be run in DOS mode.

$=;=�yZS�yZS�yZS��Ӭ�xZS���Q�xZS�RichyZS�PEd���f{�" ,����` ����%8.rdata�@@.rsrc� �@@��f{
lPP��f{$����8.rdata8.rdata$voltmdP�.rdata$zzzdbg �.rsrc$01�&P�.rsrc$02 ��Rb��"b��oͩ+Z,���(?����f{��0�H�H�`�x������������ �8�	P�
h�����
���������(�@�X�p������������� 0�!H�`�x�������� 0@P`p�������� 0@P`p���&��`'�`)�d,��X0��4���;���A���C��E�G\�xH"��K��L ��M���Qh��S���Y\
��fB�$mh��pr�t�w���{�����d�p�ԏ�����ؚ��`��|���x�����MUI���|n����]�š�V�Y���v��NmuB�}���MUIzh-TW�/fo�:y�Wy�rKa�v�ba�^�%R01u MAPS �^�z�v��f�X�%R�x�vMR�v��f��rKa
CleanStatePendingFullScan
PendingRebootPendingManualStepsPendingOfflineScanCriticalFailure
c�Q/f&T���\݈n͑�e��_jDefender �vMR�v"u�T�rKaNoStatusServiceNotRunning,ServiceStartedWithoutMalwareProtectionEngineEndingManualStepsAVSignaturesOutOfDateASSignaturesOutOfDateNoRecentQuickScanNoRecentFullScanSystemInitiatedScanInProgressSystemInitiatedCleanInProgressSamplesPendingSubmissionRunningInEvaluationModeRunningInNonGenuineWindowsModeProductExpiredOfflineScanRequired$ServiceShuttingDownForSystemShutdownRemediationFailedCriticallyRemediationFailedNonCriticallyNoStatusFlagsSetPlatformOutOfDatePlatformUpdateInProgressPlatformAlmostOutdated+SignatureOrPlatformEndOfLifePastOrImpending-WindowsSModeSignaturesInUseOnNonWin10SInstallDefender �WL�!j_ (N,�0���R0sxs ���R)"u�THr,g (;N���!k���D}�^��O�)
g�RHr,g (;N���!k���D}�^��O�)�Y�g Defender AS b AV =|�z�]N�g�S��܊�R��yr�_�xHr,g (;N���!k���D}�^��O�)-�S��܊�R��yr�_�x�vX[Yug ()Y) - �Y�gyr�_�x�_*g�f�eN��X[Yug\o�:y�p 65535 )Y"�S��܊�R��
N!k�f�e�v,g0WBf��0�Y�gdkBf���_*g�f�eN��dkl\'`\o�:yzz<P2��kyr�_�xHr,g (;N���!k���D}�^��O�)*2��kyr�_�x�vX[Yug ()Y) - �Y�gyr�_�x�_*g�f�eN��X[Yug\o�:y�p 65535 )Y"2��k
N!k�f�e�v,g0WBf�� - �Y�gdkBf���_*g�f�eN��dkl\'`\o�:y�pzz<PNRI yr�_�xHr,g (;N���!k���D}�^��O�),NRI yr�_�x�vX[Yug ()Y) - �Y�gyr�_�x�_*g�f�eN��X[Yug\o�:y�p 65535 )Y$NRI 
N!k�f�e�v,g0WBf�� - �Y�gdkBf���_*g�f�eN��dkl\'`\o�:y�pzz<P"
N!k�[te�c�c���Y�vBf�� - �Y�gdkBf���_*g�f�eN��dkl\'`\o�:y�pzz<P"
N!k�[te�c�cP}_g�vBf�� - �Y�gdkBf���_*g�f�eN��dkl\'`\o�:y�pzz<PcLast full scan age in days- if signatures have never been updated you will see an age of 65535 daysLast scan sourceUnknownUser�|q}	Real-timeIOAV;Signature version used for the last full scan of the device>If no full scan has successfully completed in the last 14 days-Indicates if a Defender full scan is required$Real-time scan direction enumerationBothIncomingPA	OutcomingdTime of last Quick Scan start - If this has never updated you will see a null value in this propertybTime of last Quick Scan end - If this has never updated you will see a null value in this propertyeLast quick scan age in days- if signatures have never been updated you will see an age of 65535 days.<Signature version used for the last quick scan of the device?If no quick scan has successfully completed in the last 14 days5The AM Engine version (major, minor, build, revision)If the AM Engine is enabledWSpecifies whether the computer is monitoring file and program activity on your computer)Scan all downloaded files and attachments0Specifies whether behavior monitoring is enabled1Specifies whether Antivirus protection is enabled3Specifies whether Antispyware protection is enabled2Specifies whether the machine is a virtual machine6Specifies whether the machine has tamper protection onkSpecifies the last entity that changed the TamperProtection state e.g., UI, Signatures, Intune, ATP, etc...1Specifies whether real-time protection is enabled2NRI Engine version (major, minor, build, revision)If the NRI Engine is enabled+Indicates the current Device Control state.@Indicates the current Device Control DefaultEnforcement policy. \Timestamp indicating when the last configuration update occured for device control policies.Troubleshooting (TS) mode state-Troubleshooting (TS) current state start time+Troubleshooting (TS) current state end time.Troubleshooting (TS) remaining time in minutes/Troubleshooting (TS) remaining quota in minutes%Troubleshooting (TS) quota reset time-Troubleshooting (TS) maximum quota in minutes Troubleshooting (TS) mode source)Smart App Control (SAC) mode: On/Eval/Off1Smart App Control (SAC) eval mode expiration time Defender initialization progress>Indicates the state of Controlled Configuration on this deviceP}�i�c�Hr,g/UNuP,nX�%R�xZ��v
T1z�V͑'`X�%R�x - R	�NO-N�^ؚ�V͑
^�%RX�%R�x - R	�INVALIDADWARESPYWAREPASSWORDSTEALERTROJANDOWNLOADERWORMBACKDOORREMOTEACCESSTROJANTROJANEMAILFLOODER	KEYLOGGERDIALERMONITORINGSOFTWAREBROWSERMODIFIERCOOKIE
BROWSERPLUGIN
AOLEXPLOITNUKERSECURITYDISABLERJOKEPROGRAMHOSTILEACTIVEXCONTROLSOFTWAREBUNDLERSTEALTHNOTIFIERSETTINGSMODIFIERTOOLBARREMOTECONTROLSOFTWARE	TROJANFTPPOTENTIALUNWANTEDSOFTWARE
ICQEXPLOITTROJANTELNETFILESHARINGPROGRAMMALWARE_CREATION_TOOLREMOTE_CONTROL_SOFTWARETOOLTROJAN_DENIALOFSERVICETROJAN_DROPPERTROJAN_MASSMAILERPATROJAN_MONITORINGSOFTWARETROJAN_PROXYSERVERVIRUSKNOWNUNKNOWNSPPBEHAVIOR
VULNERABILTIYPOLICYType ID - Enumeration	Known BadBehavior
Known GoodNRIZ�MzX[�rKaThreatCleanRebootRequiredManualStepsRequiredFullScanRequiredReinfectionLoopExecuted(List of resources affected by the threat Specifies if threat has executed!Specifies if the threat is activeVThis is a singleton that represents the Microsoft Antimalware service infection status7This class represents the catalog of recognized threatsUnique Threat ID	�vܕ�vU�tz�^
T1z��Bl܈Qe�vO(u�uP,n�O�n^��WX�%R�x - R	�ELAMLocalAttestationPARemoteAttestation
�SuP,nq_���vnj�nn�U
��!kuP,n0RZ��vBf��Z��rKa���f�vgяBf��܈Qe�vBf��0�WL��rKaX�%R�x - R	��]\��AQ1�ck(W�WL�NotExecutingZ��rKaX�%R�x - R	��]uP,n�]nd�����]�yd�CleanFailedPAQuarantineFailedRemoveFailedAllowFailed�]>e�h
BlockedFailedZ��rKa/����x	nd��R\O - R	�nd�����yd�AQ1�UserDefinedNoAction\��
c�Qnd��R\O/f&Tb�R�_��WL�M�Y�R\O�N�[b܈Qe - R	�!qFullScanAndRebootRequiredFullScanAndManualStepsRequiredRebootAndManualStepsRequired'FullScanAndRebootAndManualStepsRequiredFullScanAndOfflineScanRequiredRebootAndOfflineScanRequired'FullScanAndRebootAndOfflineScanRequired!ManualStepsAndOfflineScanRequired,FullScanAndManualStepsAndOfflineScanRequired*RebootAndManualStepsAndOfflineScanRequired5FullScanAndRebootAndManualStepsAndOfflineScanRequireddk^�%Rh�:y�vMRs�0}�vZ��rKa1.0Microsoft Defender 2��kߎԚ�c�c^�%RMicrosoft Defender 2��kߎԚ=|�z^�%RPA Microsoft Defender 2��kߎԚ WDO �c�c^�%RMicrosoft Defender 2��kߎԚ�_�^�%R%AQ1��|q}�{t�Tc�[/f&T�ar�ܕ�� Server SKU �v0��R�cd�
0�R��0AQ1��|q}�{t�Tf�x\P(u�j�g@b	gR�Q_�v�c�c0AQ1��|q}�{t�Tf�x\P(u�j�g@b	gR�QoR�j
T�v�c�c0AQ1��|q}�{t�Tf�x\P(u�j�g@b	gR�QU�tz�^�v�c�c0'AQ1��{t�Tf�x\P(u wdnisdrv 
\yr�[ IP MO@WD}2�L��v�}�\S�j�g0#c�Q��v�a�OYu(W [���] nj�e>Y�v)Yxe��}N�dkBf��KN�_sSg�N�N�yd�0sSBf�c�c�eT - R	�c�Q��(Wfg~^�WL��c�[�v�[te�c�c�N�[b܈Qe0�k)Yfg�efgNfg�Nfg	Nfg�Vfg�NfgmQ8l
NOIndicates what time to perform the scheduled full scan to complete remediation.9Configure the state of Remote Encryption Protection(REP).
NotConfigured=z8hܕ��rTime in minutes for which Remote Encryption Protection(REP) will block threats. 0 results in no limit enforcement.XIndicates how aggressively Remote Encryption Protection(REP) will block detected threat.MediumTSpecify the IP address and subnet exclusions from Remote Encryption Protection(REP).-��[�f�R4x�2�w� (BFP) �v�rKa0lTime in minutes for which Brute Force Prevention(BFP) will block threats. 0 results in no limit enforcement.RIndicates how aggressively Brute Force Prevention(BFP) will block detected threat.�_�f�R4x�2�w� (BFP) c�[���cd��v IP MO@W�TP[�}�0PA`Brute Force Prevention(BFP) Plugin - extend Brute Force coverage to block IPs on local networks.�Brute Force Prevention(BFP) Plugin - disables Brute Force Protection's initial 2 week learning period and starts blocking threats immediately.=Configure timeout for detections requiring additional action.zTime in minutes for a detection in the 'critically failed' state to move to either 'additional action' or 'cleared' state.UTime in minutes for a detection in the 'failed' state to move to the 'cleared' state.OSpecifies the interval that will be used for service health report, in minutes.fSpecify whether to report a Dynamic Signature dropped event. By default, such events are not reported.OSpecify the maximum percentage of CPU utilization during a scan. This policy setting allows you to configure the maximum percentage CPU utilization permitted during a scan. Valid values for this setting are a percentage represented by the integers 5 to 100. A value of 0 indicates that there should be no throttling of CPU utilization.
When set, Microsoft Defender Antivirus will check for new signatures before running a scan.  If new signatures are found they will be downloaded and installed before the scan begins.  If no new signatures are found, the scan will start based on the existing signatures.CTurn on removal of items from scan history folder. This setting defines the number of days items should be kept in the scan history folder before being permanently removed. The value represents the number of days to keep items in the folder. If set to zero, items will be kept forever and will not be automatically removed.�P(W�|q}U��e��n�rKaBf�Mb�WL��]�cz�v�c�c0c�[�c�[�v�c�c@bO(u�v�c�c^��W0�_��c�c�[te�c�c
c�[fg~^�WL��c�[�v�c�c0c�[N)Yvu-N���WL��]�c�[KN�_��c�c�vBf��0
c�[�WL��c�[KN�c�c�vBf��06CPU O(u�sP�6R�S�PWY(u�e�cz�c�c�bWY(u�e�czN���v�c�c0�-�<P�S
\�cz�c�cWY(u CPU O(u�s
NP�0(W��!k�[݈�_-��[�vBf��gQ�N�_-Nbk
g�Rw��Y�v@b	g�f�e0K���[ CheckForSignatureBeforeRunningScan0�Y�gyr�_�x(WdkBf��gQ�)R�f�e�GR-Nbk
g�Rw��Y�v@b	g�f�e0Bf���NR��p�UMO0��[�(u�eN	��[hQ'`�`1X�f�e�v�jHhqQ(u0dk-��[�S���`c�[ UNC �jHhqQ(u�O�n��NX[>eN	��v�[hQ'`�`1X�f�e0\�Nc�[�v��^#��}0R�f�e�O�n0�`�_�O(u�N�{�}R���vW[2Nb__c�[dk-��[�v<P��OR	��[hQ'`�`1X�f�e�O�n0�O�Y: {\unc1 | \unc2 }0dkn�U�-�/fzz�v0'�-��[�p True�!q֊/f&T	g_�d�AM 
g�R��
Ng(W_U�RBfw��Y�[hQ�`1X�f�e0��[�N	��[hQ'`�`1X�f�e�v�O�n��^0dk-��[�S���`c�[#��}0R
NT�[hQ'`�`1X�f�e�O�nBf��O(u�v��^0�`�_�O(u�N�{�}R���vW[2Nb__c�[dk-��[�v<P��O�O�^R	��[hQ'`�`1X�f�e�O�n0�S���v<P/f: 'InternalDefinitionUpdateServer'  'MicrosoftUpdateServer'  'MMPC'  'FileShares' &c�Q��(Wfg~^�f�e�[hQ�`1X0�-��[�p�� (0x0)�h�:y���k)Y�f�e�[hQ�`1X0-c�[�a�WL��[hQ�`1X�f�e�j�g�vBf��09h�d�-��g(W�WL��c�[�v�c�cKNMR�j�g/f&T	g�[hQ�`1X�f�e0M�[��_���܈yr�_�x�v)Yxe0-dM� SignatureUpdateLastChecked O(u00 = 
N��܈; 1 = 1 )Y; 2 = 2 )Y��Odk^��c04Bf��<P/f�N�f�e�j�g���� (\Bf) h�:y0	gHe�v<P�N�e 1 (�k\BfN!k) 0R 24 (�k)YN!k) KN��0UNC =|�z blob �}�qQ(uMOn0c�[(u�O�j�g=|�z�v���� (R�)0�ReQ Microsoft MAPS0�]\P(u�W,gPA2���Ta#j,g�c�N0AlwaysPromptSendSafeSamples	NeverSendSendAllSamples\P(u���y
k!j_0f�P-��[�S���`_U(ub\P(u��_j�c�[�c�c�T�[hQ�`1X�f�e�v���YBf��0�P-��[�S(u�ORce�c�c
\nj�n�vq_��0�O�Y��`�S�N(WqQ(u;N_j�vY萢[Ԛ[��d_jhV-NO(u��-��[��N�MQY萢[Ԛ[��d_jhVTBf�WL�'YϑX[�S�x�x�v�d\O0W�P-��[AQ1�`O�N\Bf�p�UMO-��[�cz��_jS0��_jS�����p[1 - 23]\Bf0�Y��fYܕ�e��_jSHe�a�vnj
��ˊ�gw RandomizeScheduleTaskTimes -��[0\P(uL��p�v��0\P(u IOAV �Ow�0\P(usSBf�v��0\P(uc�N�x�c�c0\P(u\X[�c�c0>\P(u��܈�[te�c�c0��܈�c�c/fN.z�V�p/�N��]�c�[�v�[g�c�c��WL��v�c�c0/�N��]�c�[�v�c�c�v�S�V�8^/f��f�(W�c�[�vBf��&N*g��_j0>\P(u��܈�_��c�c0��܈�c�c/fN.z�V�p/�N��]�c�[�v�[g�c�c��WL��v�c�c0/�N��]�c�[�v�c�c�v�S�V�8^/f��f�(W�c�[�vBf��&N*g��_j0	\P(u��P[���N�c�c0\P(u�b�S_�x�x_j�c�c0\P(u���Sޞ0\P(u(W#��}�v�}�x�x_j
N�WL��[te�c�c0Mܕ���c�c�}jHh0�WL� IOAV �c�cBf��_�_U(u0ApplyDisableNetworkScanningToIOAV
0-��[��N�x�O�}jHh�c�c_N���y(u0�x�O_N\ [\P(u�c�c�}jHh] -��[WY(u� IOAV �c�c0_U(u UI ���[!j_0buP,n0RZ�Bf
N(WvQ
N�WL��-��R\O�vZ�X�%R�x0ThreatIDDefaultAction_Actions -N�v�R\O��^�_�� ThreatIDDefaultAction_Ids -N�vX�%R�x��^�vTKuP,n0RZ�Bf
N(WvQ
N�WL��-��R\O�v�-��R\O0��N�R\O�v��^�_�� ThreatIDDefaultAction_Ids l\'`-Nc�[�v
\�aX�%R�x��^�vT0

NfZ��v�-��R\O0
NO�^�V͑'`Z��v�-��R\O0
-N�^�V͑'`Z��v�-��R\O0
ؚ�^�V͑'`Z��v�-��R\O0
�V͑�V͑'`Z��v�-��R\O0c�[ PUA ([o(W�v�W>W�a(uz_) �Ow�!j_0�]_U(uPA	AuditMode\P(u,{N!kw��Bf\���v�R��0	-��[��z�Ow�d\}0�-�ؚ+���[/�-��[�^w���z�j�g0	gHe<P 0-50 �y0#-��[ Microsoft Defender �`a�c"}2�w��}��Ow��R��0=z8h!j_-��[ [�S�cnj�e>YX[�S
k] �R��0BlockDiskModificationOnlyAuditDiskModificationOnly-c�[ Attack Surface Reduction Rules(ASR) �v�cd���v0Uc�[0�S;e�db�.~\��GR
0(ASR) X�%R�x0��GRX�%R�x�v��^�_�� AttackSurfaceReductionRules_Actions l\'`@bc�[�v
\�a�R\O��^�vT0M;e�db�.~n��GR (ASR) �v�-��R\O0�R\O�v��^�_��T(W AttackSurfaceReductionRules_Ids l\'`-Nc�[�vT��GRX�%R�x�vT0\*g-��[f�JT\AQ1��v�a(uz_�e�X� [�S�cnj�e>YX[�S
k] �R��0\�S�Ow��vnj�e>Y�e�X� [�S�cnj�e>YX[�S
k] �R��0�-����S�cnj�e>YX[�S�Ow��vnj�e>Yn�U0�[�[��d�t�X-N�O�[hQ�`1XO(u�v�jHhqQ(u0+� SharedSignaturesPath Nw�-��[Bf��S���`�P9h�d�czhV_U(u�f�e0-��[�cz�c�cBf/f&T�ar�O(uNO CPU *QHQ
k0_U(ub\P(u�jHhܖJn��{�R��0(AQ1� Microsoft Defender 2��kߎԚ�N��ϑ�N��#��}�f�e�S�
�0Odk-��[�c6R�}��Ow�/f&TAQ1�(W Windows Server 
N-��[�p\��b=z8h!j_0傺p/����EnableNetworkProtection �v�P<P\���_eu0�P-��[�c6R�}��Ow��vnj�eSU�t09�}��Ow�g�j�g�}�Amϑ�&N$R�e�[/f&TAQ1�b\��Amϑbo�:yf�JT0dk-��[g�c6R�}��Ow�g\���}�Amϑ��
N/fo�:yf�JT06_U(uBf��|q}��nBf@b�WL��]�c�[�v�c�c
Ng
\ CPU 2�L��{AmU�t0�-�<P�p 1��Vdk��n�c�c�N6qg\P(u�{Am0Jvu-��[�p TRUE Bf��Y�g�|q}O(u��`l���R�WL��GRAQ1�|~�~�]�cz�v�[te�c�c0�-�<P�p FALSE�sS�Y�g�|q}O(u��`l���R�WL���-�g�S�m�[te�c�c0'(u�Oc�[��O(u�v poxy pac0ProxyServer �v*QHQ��^ؚ�edk02(u�Oc�Q(u6b�zVf�#��c�}�Bf�ar�O(u�v�]}T
T Proxy ((u�e=|�z�f�e�T SpyNet 1XJT)0PAeuN� Proxy :O
ghV�vMO@Wn�U0a�Y�g�|q}�{t�T�`���N� Proxy 7_6R@b	g#��}�N
NAQ1��NUO�v�c#��}0��PS+T ProxyServer �T ProxyPacUrl0
NS+T IESettings �T AutoProxy uP,n0�P-��[g\P(u�}��Ow��v TLS VR�g0�P-��[g\P(u�}��Ow��v HTTP VR�g0�P-��[g\P(u�}��Ow��v DNS VR�g0�P-��[g\P(u�}��Ow��v DNS TCP VR�g0�P-��[g\P(u�}��Ow��v SSH VR�g0HAQ1��|q}�{t�T-��[݈n��N�_yr�[�S� (�S�) �c6e Microsoft Defender s^�S�f�e - AQ1��[6b
\8o2�_|vL�z�^	gN�N�c6R
k0�bS����Hr���R�k�^�l�]�^r�HAQ1��|q}�{t�T-��[݈n��N�_yr�[�S� (�S�) �c6e Microsoft Defender _�d�f�e - AQ1��[6b
\8o2�_|vL�z�^	gN�N�c6R
k0KAQ1��|q}�{t�T-��[݈n��N�_yr�[�S� (�S�) �c6e Microsoft Defender �[hQ'`�`1X�f�e - AQ1��[6b
\8o2�_|vL�z�^	gN�N�c6R
k0"AQ1��|q}�{t�Tx��d��Q_�d0s^�S�T�[hQ�`1X�f�e�f�e�v8o2�_|vL�z�^0PAJdk-��[�c6R(W Windows Nd\ RS3 /f&TAQ1�-��[�p\��b=z8h!j_0傺p/����EnableNetworkProtection �v�P<P\���_eu0`dk-��[�c6R�}��Ow�/f&TAQ1�(W Windows Server 
N_U(unj�e1XU�t0傺p/����DisableDatagramProcessing �v<P\���_eu�&N�-��p\P(u Datagram �j�g0Pdk-��[_U(u�N�}��Ow��v DNS Sinkhole �R���
\͑ EnableNetworkProtection (W\����[�Bf�v�P<P�FO(W�j�g!j_N�l	g�NUO�R��0�P-��[g\P(u�}��Ow��v#�eQ#��}�{x��R��0�P-��[g\P(u�}��Ow��v RDP VR�g0dk-��[g\P(u�}��Ow��vHe��Y�,n6eƖ�T�P��R��0dk-��[g�N��O�Njd|�Ow��O-��[7_S0O�c6R�cd���v/f&T
\݈n
N�vj�n,g0WO(u��S��0O(u?eV{-��[ HideExclusionsFromLocalAdmins �O��υj�n�S�{t,g0WO(u��v�cd�nj�e0�P-��[g\P(u�}��Ow��v FTP VR�g0!dk-��[�S_U(uHe��gsOS��NAQ1�Tek�j�g�v�}�AmϑR�c0R^�Tek�j�g0c�[HSY�_�WL��]�cz�c�c�vR�xe0dk-��[g(W�u㖒c�!j_��_UBf\P(u�z9e2�w�0�P-��[g\P(u�}��Ow��v SMTP VR�g0�P-��[g\P(u�}��Ow��v QUIC VR�g0�g-��[�}��Ow��vU��P!j_0DEPRECATED: dk-��[g\P(u_�d-N�v TDT0PAkc�[�S;e�db�.~\��GR (ASR) ��GRyr�[�cd�X�%R�x0�_�-��[/�e�X��GRX�%R�x�&N(W AttackSurfaceReductionRules_RuleSpecificExclusions l\'`-Nc�[vQP%R�cd���v0pc�[�S;e�db�.~\��GR (ASR) ��GRyr�[�cd�X�%R�x0�_�-��[/�e�X��GRyr�[�cd���v�&N(W AttackSurfaceReductionRules_RuleSpecificExclusions_Id l\'`-Nc�[vQP%RX�%R�x0(W�sbԚW�g��_U(usSBf�Ow��=|�z�f�e(OOBE)0dk-��[AQ1� IT �{t�T�p�S�{t݈n-��[He��!j_�p_U(ub\P(u0\P(u�[���f�e�_�S�v�_�S�}w��]\O0�[g�zsS�P�V0(W�_��c�cg���c�c�cd��v�jHh�T�v�0ScanRtpExclusions�yd��c�c
\q�xe�v�v
NP�i_U(uBf�8h�_
g�R\\PbkO(u [f�W��T-��[
g�R (ECS)]��N�_��c�O Microsoft Defender 2��kߎԚ�TvQ�N Defender ߎԚ�v͑'YD}T~yr�[KN�Ock0�Ockz_\g|~�~�N��[hQ'`�`1X�f�e�c�O0z_U(uBf�8h�_
g�R\g\PbkO(u OneDsCollector �g�i��N�_ Microsoft Defender 2��kߎԚ*�TvQ�N Defender ߎԚ6eƖY�,n0_U(udk-��[gq_�� Microsoft �_���X��S�zlOUL��v���R��O�YHe���}ba�T��$R0_U(u UDP RrRxS	��Nrs�_�}��Ow�_U(u UDP �c6exS	��Nrs�_�}��Ow�f,o�[�R�RControls AI Agent Protection. 0=Disabled, 1=Enabled (scan and block), 2=Audit (scan and log only).�d�T��aDefine the order of sources for downloading security intelligence updates This setting allows you to define the order in which different security intelligence update sources should be contacted. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources in order. Possible values are: 'InternalDefinitionUpdateServer'  'MicrosoftUpdateServer'  'MMPC'  'FileShares' �1��[эK�Indicates the day of the week in which security intelligence updates occur. If set to zero then security intelligence update occurs daily.�ghy|W%tDefines the number of days after which a catch-up signature is warranted. Works with SignatureUpdateLastChecked. 0 = no catch-up,  1 = 1 day,  2 = 2 days, etc.j%t�1�Disable privacy mode.(BNӒv��sDisable intrusion prevention system.�j�VhyӒA user confirmation is sought by default by this cmdlet. If -Force is specified, the default confirmation is not sought from the user.b1��X�V�NSpecify reporting Dynamic Signature dropped event or not. By default, doNOT report such event.!d��R^�&TControls AI Agent Protection.>�@W�s�XSpecify the exclusions for Attack Surface Reduction Rules.S&T�Xj�RDefines a file share for security intelligence updates in virtual environments.2ghy,o1�Microsoft Defender Antivirus Preferences Class&Tgav��aCategory of Notification.1�Ӓ%tBNScanStateNotifications5tj@W|WThreatStateNotificationsr|v�hy�VSignatureStateNotificationsgэBN�`ComputerStateNotifications 1�@W�V1�Detailed Scan Notifications.hy�R�R5tErrorOccurred�`d�&T5tScanCompletedPA"5t�`1��RDetailed Threat Notifications.R�hy,or|SuccessfulRemediation|W�RR�d�NonCriticalFailure%�Nj5t1�Detailed Signature Notifications.�R,o�N�SignaturesOutOfDate$�Xv��N�`Detailed Computer Notifications.�s�VK�@WScansOutOfDate,o�R�`�aComponentsChanged%t�f^�BNStateRecovered-T�[gaӒDate and time the WMI Event was generated�grg5t@WAdditional Data. At the moment, the only use is when the CategoryDiscriminant is equal to ThreatStateNotificationsthen this value will contain the ThreatID71�1�1�5tMicrosoft Defender Antivirus Event Indication Class)K�K�ga�sUnique identifier (GUID) of the rule.э�f�RjIP address to block. �`K�[%tType of the blocking action./Ӓ�X�[�XDirection of the rule. (Outgoing, Incoming)PA)�R�ag&TProtocol of the rule. (TCP, UDP, Any)[э�fr|Range of local ports.&T�s5t�fRange of remote ports.5�[�f��fStart time of the rule, when it was first created-э�RR��REnd time of the rule, when it will expire7,o,o@WjUnique identifier (GUID) of the rule to be removed.>v�T�`эMicrosoft Defender Behevioral Network Blocking Rules ClassPA%1!s! ck(W�c�c�`�v݈n��x��S�v�c�c^��W��[���S�����N�NBf��0�c�c�]�)R�[b0Vf��c�c�`�v݈nBf|vu/���0���c�c�[te�c�c�_��c�c%1!s! %2!s!
ck(W�f�e�u�k�S��܊ߎԚ�[�!%1!s! g��R�f�e�`�v�u�k�S��܊ߎԚ�[���NTS�R�Ow��`�v݈n0�u�k�S��܊ߎԚ�[��f�e�]�)R�[b0�u�k�S��܊ߎԚ�[��f�e�]�[bFO	g/���0	�u�k�S��܊ߎԚ�[��d\O1YWe�|vuNR/���: 0x%1!x!�WL����c�cBf��_���	g ScanPath �Sxe0dk݈n�]�}(W�WL��c�c0dk݈n�]�}(W�WL��u�k�S��܊ߎԚ�[��f�e0ck(Wnd���uP,n�p�S��	g�[�v��v0�`�v݈n�vMR�l	g�NUOuP,n0R�v��v�Snd�0Vf�nd���uP,n�p�S��	g�[�v��vBf|vu/���0F�_��p�kP ThreatIDDefaultAction_Ids �Sxec�[ AThreatIDDefaultAction_Actions <P0!q�l�S�_Z�X�%R�x�v�-��R\O0/���: 0x%1!x!)�d\O1YWe�|vuNR/���: 0x%1!x!0�d\O: %2!s!0�vj: %3!s!0�`�l	g�� Y�v
kP��S�WL���Bl�v�d\O0Vf�(W�`�v݈n
N�WL� WDO �c�cBf|vu/���0dk݈n�]�}(W�WL��c�c0�����D%2 WMI �c�O��WL�PԚ�d�S�e�l-N|vu/��� %10%0

<%2 WMI �c�O�\�Ka�e�l-N|vu/��� %10%0

P%2 WMI �c�O� FireEvent �e�l-N|vu/��� %10%0

|Vf��_@b	g\O(u-N��f��]\O���k{v� %2 WMI �c�O���wBf|vu/��� %10�Sg6e0R�O��vMR�]\O���k�v��w0%0

PVf��p %2 WMI �c�O��^�z�N�N�v���WL��}Bf|vu/��� %10%0

XVf�{v� %2 WMI �c�O��N�S�_�v���S�`az_�x��wBf|vu/��� %10%0

4VS_VERSION_INFO���e�e?`StringFileInfo<040404B0LCompanyNameMicrosoft Corporationh FileDescriptionProtection Management WMIv2 �c�O�JInternalNameProtectionManagement�.LegalCopyright� Microsoft Corporation. All rights reserved.bOriginalFilenameProtectionManagement.dll.muij%ProductNameMicrosoft� Windows� Operating System�9FileVersion4.18.26050.15 (b7ae6fb185fe12f8ad81cb6d4ade5982e03d0a61)@ProductVersion4.18.26050.15DVarFileInfo$Translation�PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX�%0�%�	*�H��
��%�0�%�10
	`�He0\
+�7�N0L0
+�70	���010
	`�He ���kvSʣ�Wm�м�1��2�'_�L�m���
�0�	0��3�W���2-.�0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20110
260416190915Z
261017190915Z0p10	UUS10U
Washington10URedmond10U
Microsoft Corporation10UMicrosoft Windows0�"0
	*�H��
�0�
�֥�mlF��O%���F�k���Q�.�H�B���0��
|Ḣ�|�9b4�wۤ��cc��]Q����@~�$	���B��hn�K����u���D�@+c�,�iA�,a����晞�B���
K2؟��&���?
̡�M��~;ax�|xT�nJ2L��+����8���ܞ�-��A�G�T*���S3�<�:Cݨ�#�6J�8�ou�,bO�l��K&�*&n��`���|5M`x�O �^�U)��s�ۿ��	���0��0U%0
+�7
+0U�`\�6�ϧ4��h�N$�o*0TUM0K�I0G1-0+U$Microsoft Ireland Operations Limited10U
229879+5075120U#0��)9�ėx͐��O��|U�S0WUP0N0L�J�H�Fhttp://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl%200a+U0S0Q+0�Ehttp://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0U�00
	*�H��
��R��>���q;/
W�M95s�
�q9����V�ޏ�%���y��{��0L%�3e_�12E�8;Mx���;HB/��y�����9��-�yU�}lT���W����t,\��r'D�i���Y�Ѡۆ8
�p<:��NbC��8�<i���g���N?=N}�i;�s�6wjql`��4�$�����(t��U�vMb��}�EwTC����V�X+ls\����yφ,��5r*���0��0���
avV0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100
111019184142Z
261019185142Z0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20110�"0
	*�H��
�0�
�����.	����i�!�i33��T����� ��ҋ�8����-|by��J?5 p���k�6u�1ݍp��7�tF�([�`#,��G�g�Q'�r��ɹ;S5|���'�����#	o�F��n�<A�ˣ?]jM�i%(\6��C
��������['�'x0�[*	k"�S`,�hS��I�a��h	sD]}�T+�y��5]l+\μ�#�on�&�6�O�'��2;A�,���w�TN�\�e�C���mw�Z$�H��C0�?0	+�70U�)9�ėx͐��O��|U�S0	+�7
SubCA0U�0U�0�0U#0��Vˏ�\bh�=��[�Κ�0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
	*�H��
��|qQ�y�n��9>�<Rn+?s��h�H�4M��&�1F�ay�8.Ek��(�����	��L
6fj���������@26v�Zƿ���Ӭ�h�b��TlP0X��|���N���|�sW�R!s4Z�V��	����~�����?�rS��c��=1e�������=����BА�_T���G�o�sNA�@�_�*��s�!(���s9_>�\`����	���Q�fG���=�*hw��Lb{��Ǻz�4Kbz����J7�-�W|�=ܸZ��ij�:��n�i!7ށ�ugӓW^)9��-���Es[���z��FX�^���g�l5��?$�5�
u�V��x,��Ј���ߺ~,c��#!�xl�X6+�̤��-����@�E�Ί\k>��p*
j�_G��c
2��6*pZ�BYqKW�~���!<��Ź���E��� ����ŕ�]b֠c �uw}=�E�����W�o3��w�bY~1�-0�)0��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20113�W���2-.�0
	`�He���0	*�H��
	1
+�70
+�710
+�70/	*�H��
	1" ̖�J�^,���"6C5��(S��"�6�0B
+�71402��Microsoft��http://www.microsoft.com0
	*�H��
��ͩҎg�o`[.O�#�₼���[#P�|�_N�<��<�� �U���:I������>�5��꫍��T�E9<C�ᒹ����`-��"u�h�J��� *����������@��f��E!�<`g�e�SM=��إê}Ig�E���0H��親	��u��C���SR,8����+DdSU�o��@��7�jx�TgnI�"9��
)����������N�}��Ĝ���V�13r���0��
+�71��0��	*�H��
���0��10
	`�He0�Z*�H��
	��I�E0�A
+�Y
010
	`�He �ٚ�"��F��-�j"C�q����#-�
FY�j�!��20260531193522.682Z0��٤��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1-0+U$Microsoft Ireland Operations Limited1'0%UnShield TSS ESN:6B05-05E0-D9471%0#UMicrosoft Time-Stamp Service���0�(0��3E9�C�l0
	*�H��
0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100
250814184813Z
261113184813Z0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1-0+U$Microsoft Ireland Operations Limited1'0%UnShield TSS ESN:6B05-05E0-D9471%0#UMicrosoft Time-Stamp Service0�"0
	*�H��
�0�
�Ϲ�3/�Zʹ;��(�i�7�d�p����Hq��w�J�����v��n�3���IF�UZ�h����$.�6�
7u�Uп���&�υ2������ڧ�MS�8����T��\��g_���O��R�����ϓV�,ga\��Ei���}��KQ^�&���K<��=\�G3��e�a�|v�:a�T�*7�a3��M�\͖���?��?)j�5��v��e�TءB�����u���e9�qj��tN&����c�$Y���r!A"�a�M�s�?�ɴ���A@�q�K$xE!���[�Z��w�v�*�����D��2�
;`5$��}Bso�nj�?O��:�0v�bMɥ*V�C�i������[�h��P��a�T�U~�x���0�	3�gD��<�Dž!��4��:�ʜ�}�m��(q^�Z��<b�J̾�vJ�:����Y|C�	׾>{*�ʖ=>�"b..@`�U��x��/�`��s�Mk���I0�E0Ub}E���!��o���]f~�p0U#0���]^b]����e�S5�r0_UX0V0T�R�P�Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l+`0^0\+0�Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0U�00U%�0
+0U��0
	*�H��
��B��Lj!H��g����ͅ)3�i�v5K�f��sw\��H�}��"�{���:�}
�R�爮ÛF���l+N���-��D����4�z������wY0˚����ӦUkp�x#�I��ٮ
l+ײg��\���l�TX7�bw���?r�2���8��;���Ϛ0�W�M�TUl�2��i��S���@�1��v�7f���I�<�$�v^�/�����VԵ���n���@���#kÄk_q�xw�[�x�����b��;��:m9�^,�?1��/���%�Ӆ�G���9�gu�J��x6��Hg`%<�i�rgrӍ���D@���������rm3�n���GT�'9�X��f�dU���8@���%p#ay�/�&G��^����/�Rr
�f�u��b��
g���$�R�CÄ��ܻ�����V�+�KE1r�ߞJ�F~??Fː�b
��io������ɶB
O�1�K��o=0UɍJ�T3Lk]��a�U^&0�q0�Y�3��k��I�0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100
210930182225Z
300930183225Z0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100�"0
	*�H��
�0�
���L�r!y���$y�Ղ��ҩlNu��5W�lJ�⽹>`3�\O�f��SqZ�~JZ��6g�F#���w2��`}jR�D���Fk��v��P�D�q\Q17�
8n����&S|9azĪ�ri����6�5&dژ;�{3��[~��R���b%�j�]�S���VM�ݼ��㑏�9,Q��pi
�6-p�1�5(�㴇$��ɏ~�T��U�mh;�F��z)7���E�Fn�2��0\O,�b�͹⍈䖬J��q�[g`���=� �s}A�Fu��_4���� }~�ٞE߶r/�}_��۪~6�6L�+n�Q���s�M7t�4���G��|?Lۯ^����s=CN�39L��Bh.�QF�ѽjZas�g�^�(v�3rק ��
�co�6d�[���!]_0t���عP��a�65�G������k�\RQ]�%��Pzl�r�Rą��<�7�?x�E���^ڏ�riƮ{��>j�.����0��0	+�70#	+�7*�R�dĚ���<F5)��/�0U��]^b]����e�S5�r0\U U0S0Q+�7L�}0A0?+3http://www.microsoft.com/pkiops/Docs/Repository.htm0U%0
+0	+�7
SubCA0U�0U�0�0U#0��Vˏ�\bh�=��[�Κ�0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
	*�H��
��U}�*��,g1$[�rK��o�\�>NGdx���=13�9��q6?�dl|�u9m�1��lѡ�"��fg:SMݘ��x�6.���V����i�	�{�jo�)�n�?Hu��m��m#T�xSu$W�ݟ�=��h�e��V����(U'�$�@���]='�@�8���)�ü�T�B�������j�BRu�6��as.,k{n?,	x鑲�[�I�t�쑀�=�J>f;O���2ٖ����t��Lro�u0�4�z�P�
X�@<�Tm�ctH,�NG-�q�d�$�smʎ	��WITd�s�[D�Z�k
��(�g($�8K�n�!TkjEG����^O���Lv�WT	�iD~|�als�
��Af=i��AI~~���;����>�1Q������{��p���(��6ںL���
�4�$5g+�
�挙��"��'B=%��tt[jў>�~�13}���{�8pDѐ�ȫ:�:b�pcSM��m��qj�U3X��pf�Y0�A0���٤��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1-0+U$Microsoft Ireland Operations Limited1'0%UnShield TSS ESN:6B05-05E0-D9471%0#UMicrosoft Time-Stamp Service�#
0++*|�e]�
�Ti3w��^�5͠��0���~0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100
	*�H��
���0"20260531164243Z20260601164243Z0w0=
+�Y
1/0-0
���0
#��0@0
��506
+�Y
1(0&0
+�Y
�
0� �
0��0
	*�H��
���§��N�.t��o �0�܏�rȎ%�����H��]Wim�@��=���[��
qx#{9B$ �<��Ÿة�Ll�_�K�>0��*���݉��tuyHc�7��h�L
��[%�",�R
�����wV��U=;���x(�Z����'-H�2�Z�Z�1)eq ������뢸�\����*ٹz�ꀶ9{��O~r�A�~Oa�⥠"���L/H"�/V���dC��"eg2\�bN&�㨂p�+ˠnD;r�1�
0�	0��0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20103E9�C�l0
	`�He��J0	*�H��
	1
*�H��
	0/	*�H��
	1" �T�R�#?���2�	����a$\^�O`��X0��*�H��
	/1��0��0��0�� ,�3���N�Z\\/���P#ME�9b�43&�0��0���~0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20103E9�C�l0" ui
��-���͖MH��a�r1`��)pr��<0P0
	*�H��
�B`\��?���;h7Q,FC���6�q=y�ə�+�q�j�
ϱPM���y�ٌ��y\�r���G�.X���L��tyV����X�NZvs��O@n3Sそ���x39v)���q}��x[���-qY�.yx�"%n�S��[�k�?C�����#U��O��^
����~U��q!�����Lrt�ڗ�`4{��ʘ����}�%]9�8���`gk)xv����Y�QPf��Ԥ�m`��ܗTmU�I8b�@�'*��\����e�S|�n
��i|����}R��L�]/� E-T')6��c��sB�K:�&B�j	"�����ڻt��y|
(�rB����C[ʙ+]�6U�?����Cn�3���o�a��tb”N&ay y�S���î�:��:��?bE
�"�&?F��\u�E$,�ゎ�o���*i��E�+9Ye.���R��~���g���fҘ���Vu��V6%N)a$2o
�ӣ��<k3�����

Youez - 2016 - github.com/yon3zu
LinuXploit