403Webshell
Server IP : 209.209.40.120  /  Your IP : 216.73.217.112
Web Server : Microsoft-IIS/10.0
System : Windows NT NEWWWW 10.0 build 17763 (Windows Server 2019) i586
User : NEWWWW$ ( 0)
PHP Version : 8.3.30
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  C:/ProgramData/Microsoft/Windows Defender/Platform/4.18.26060.3008-0/en-GB/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : C:/ProgramData/Microsoft/Windows Defender/Platform/4.18.26060.3008-0/en-GB/DefenderDiag.dll.mui
MZ����@���	�!�L�!This program cannot be run in DOS mode.

$�;=߉ZS��ZS��ZS�Ӭ��ZS��Q��ZS�Rich�ZS�PEd�.��}�" ,�0��` �
�%8.rdata�@@.rsrc @@.��}
lPP.��}$����8.rdata8.rdata$voltmdP�.rdata$zzzdbg .rsrc$01(��.rsrc$02 ՠ(ȇ�x��'����/u��H�k���P^.��}��0�H�������%�������(�?@�EX�Fp�G��H��L��R��S��~���0��H��`��x�9��x�������������� ��8��P��h����������������3��4�r(�@�X�	p	�	�	�	�	�	�	�	�			 	0	@	P	`	p	�	�	�	�	�	�	�	�			 	0	@	P	`	p	�	�	�	�	�	�	��'���(��8*���+���-d�$/R�x0��1x��1��3r�7���8���;��>�@���O���^���c��Hi�`o���u�w�~N�h�8	���v	���
�ġ<��x�x�:�����<�\�����dN��j� �8�����TL�����!�MUI�����}J�`_����Ne�ֶ��n���������MUIen-GBhereNo issues found."No detailed information available.Supporting Data:Impact LevelFindingRecommendation
ReferencesFeedbackCategoryAnalysisErrorWarning
InformationalToggle navigationPA#Defender Diagnostic Insights ReportOverviewNetwork Communications
Deployment
OnboardingHealthUpToDatePerformance IssuesConfiguration IssuesCFAHelpASRN/ANot configured%1 hoursEverydaySundayMondayTuesday	WednesdayThursdayFridaySaturdayNeverNetwork Communications TestsMDE Deployment TestsMDE Onboarding TestsMDE Feature Health TestsMDE Up-To-Date TestsPerformance TestsConfiguration Tests$CFA (Controlled Folder Access) TestsPA$ASR (Attack Surface Reduction) TestsDisabledBlockAuditUnavailableYESNO%1 service not present
Not available
Unknown StateProcessFileTkDF�;\����5���U�
^c3� ��;��?c1@ �M /K
�HB-�� ����H#
 �a� ���/ h �9�IH��1��[B�<�mB1�4FkBWU�2<QC�O<�> �aa-�� QZ�\ ��aU)�.! ���X ,<�
8 ��� 0U_��� ��-g ��COe Y�F9+I#PAFindingsFindings2Click Analysis link to see the detail of findings.Machine InformationMachine InformationVMNameVMSize
VMLocationSubscriptionId
ResourceGroupVmId	OSVersionNumber of coresNumber of logical processorsThreads per corePhysical MemoryPageFile LocationPageFile Current UsagePageFile Allocated Base SizePageFile Peak Usage
Domain JoinedAzure AD JoinedWorkplace JoinedAzure AD Device IDEnrolment StatusOS ArchitectureSystem Boot TimeSystem-wide WinHTTP Proxy!Device is enrolled to AAD and MEM2Device is not enrolled and has never been enrolledDevice is managed by MDM AgentDevice is managed by SCCM Agent.Microsoft Endpoint Manager Configuration issue
General errorConnectivity issue)Device was enrolled and is now unenrolledDevice is pending unenrollmentPolicies assignment failurePAPolicies report failureGeneral Hybrid join failureTenant mismatch'Hybrid error - Service Connection PointCertificate errorAAD Connect misconfiguration	DNS errorClock sync issueMDE and ConfigMgrPAEDRSense Information
Sense versionSense service StatusOrganisation Id	Device IDAnti-Spoofing State GUIDDiagTrack (UTC) Service Status!Anti-Spoofing capability deployedSense Configuration versionMachineAuth IDSense service StartTypeDevice Datacentre Location-Device Onboarded via Streamlined Connectivity.Microsoft Account Sign-in Assistant Start TypePADefender AVDefender AV InformationDefender AV Service StatusDefender AV Platform Version)Defender AV Security Intelligence VersionDefender AV engine VersionDefender AV mode$Defender AV SSLOptions configurationDefender AV proxy configuration&Windows Security Centre Service Status&Windows Security Health Service Status*Defender Network Inspection Service StatusDefender Core Service StatusDefender Is Tamper Protected!Defender Tamper Protection Source(Defender Is Tamper Protection ExclusionsSmartLocker ModeDefender Anti-Spyware Defender Network Protection ModeuPlease review your network configuration and ensure required URLs are not blocked. 
For more information refer to: %1ServiceURLsyTest connection to the Microsoft Defender for Endpoint (CnC) cloud service URLs completed successfully. %1 with result %2�Test connection to the Microsoft Defender for Endpoint (CnC) cloud service URLs failed. 
The test has failed for the following URL: %1 with result %2�All test connections to Microsoft Defender for Endpoint (CnC) cloud service URLs have failed. 
The test has failed for the following URL: %1 with result %2{Test connection to the Microsoft Defender for Endpoint (Cyber) cloud service URLs completed successfully. %1 with result %2�Test connection to the Microsoft Defender for Endpoint (Cyber) cloud service URLs failed. 
The test has failed for the following URL: %1 with result %2�All test connections to Microsoft Defender for Endpoint (Cyber) cloud service URLs have failed. 
The test has failed for the following URL: %1 with result %2|Test connection to the Microsoft Defender for Endpoint (AutoIR) cloud service URLs completed successfully. %1 with result %2�Test connection to the Microsoft Defender for Endpoint (AutoIR) cloud service URLs failed. 
The test has failed for the following URL: %1 with result %2�All test connections to Microsoft Defender for Endpoint (AutoIR) cloud service URLs have failed. 
The test has failed for the following URL: %1 with result %2�Test connection to the Microsoft Defender for Endpoint (SampleUpload) cloud service URLs completed successfully. %1 with result %2�Test connection to the Microsoft Defender for Endpoint (SampleUpload) cloud service URLs failed. 
The test has failed for the following URL: %1 with result %2�All test connections to Microsoft Defender for Endpoint (SampleUpload) cloud service URLs have failed. 
The test has failed for the following URL: %1 with result %2�Test connection to the Microsoft Defender for Endpoint (MdeConfigMgr) cloud service URLs completed successfully. %1 with result %2�Test connection to the Microsoft Defender for Endpoint (MdeConfigMgr) cloud service URLs failed. 
The test has failed for the following URL: %1 with result %2�All test connections to Microsoft Defender for Endpoint (MdeConfigMgr) cloud service URLs have failed. 
The test has failed for the following URL: %1 with result %2{Test connection to the Microsoft Defender for Endpoint (OneDs) cloud service URLs completed successfully. %1 with result %2�Test connection to the Microsoft Defender for Endpoint (OneDs) cloud service URLs failed. 
The test has failed for the following URL: %1 with result %2�All test connections to Microsoft Defender for Endpoint (OneDs) cloud service URLs have failed. 
The test has failed for the following URL: %1 with result %2ZCertificate validation for the Defender for Endpoint cloud service completed successfully.&Certificate revocation was not tested.JCloud connectivity may be impaired due to certificate revocation failures.�Please ensure the following URLs are not blocked: %1 and %2. For more information please refer to %3. For detailed error information, review %4.YTest connection to the Antivirus Microsoft Defender cloud service completed successfully.ITest connection to the Antivirus Microsoft Defender cloud service failed.2If Antivirus Microsoft Defender is your primary antivirus solution or you have opted to enable EDR Block Mode, please ensure connections to AV cloud URLs are not blocked. For more information refer to: https://learn.microsoft.com/defender-endpoint/configure-network-connections-microsoft-defender-antivirus*Current network connection is not metered.)Current network connection is metered. %1�Metered Networks can limit functionality in Defender MAPS communication, for example emergency signature requests are not sent (needed for custom indicators in addition to emergency signatures).ApproachingDataLimit: %1OverDataLimit: %1Roaming: %1NetworkCostType: %1�Test connection to the Microsoft Defender for Endpoint (ECS configuration) cloud service URLs completed successfully. %1 with result %2
Test connection to the Microsoft Defender for Endpoint (ECS configuration) cloud service returned HTTP 502 Bad Gateway. This is a known intermittent issue with the Azure Application Gateway and may resolve on its own. Retry the check if this persists. %1 with result %2�All test connections to Microsoft Defender for Endpoint (ECS configuration) cloud service URLs have failed. 
The test has failed for the following URL: %1 with result %2�If you intend to enable MDE Security Configuration Management then please refer to following documentation for the list of requirements.Supported PlatformseDevice does not have the minimum patch level for MDE Security Configuration Management onboarding: %1�Device has Active Directory Name Services role installed. Support for Domain Controllers is currently in preview and requires additional configuration.�If you intend to enable MDE Security Configuration Management for Domain Controllers, then please refer to following documentation.9Use of security settings management on domain controllers}The device is running a 32-bit operating system, which is not supported for MDE Security Configuration Management onboarding.SPlease note the device OS build is not supported by MDE and cannot be onboarded: %1FPlease refer to this article for a list of supported Windows versions.F%1 on this device is not running at Protection Level that is expected.�For more information about PPL protection and why it is critical refer to this documentation. Contact Microsoft support if issue persists.PPLxPlease note the Hyper-V only server edition installed on this device is not supported by MDE and cannot be onboarded: %1XPlease refer to the MDE Supported documentation for a list of supported server editions.Supported Windows VersionsMDE Sense ServiceMDE AV Windefend ServiceWindows Security WscSvc ServiceWindows SecurityHealth Service'MDE Network Protection WdnisSvc ServiceMDE Defender Core Service+For more information, refer to the article.�Please note that this machine is running with an outdated version of Defender Platform. Platform versions older than N-2 will no longer be supported.'Microsoft Defender AntiMalware Platform>Please note that this machine is running with an outdated version of Antivirus Defender engine. After a new package version is released, support for the previous two versions is reduced to technical support only. Versions older than that are listed in this section, and are provided for technical upgrade support only.#Antivirus Microsoft Defender engine�Please note that this machine is running with outdated security intelligence version. It is recommended to apply the most recent security intelligence version to ensure optimal protection and compatibility.%Microsoft Defender Anti-Virus UpdatesPA9Sense High CPU usage is observed due to Sense NDR trafficDTry applying the Sense EDR exceptions to the following processes: %1PAHigh CPU UtilisationJMDE Platform experienced High Memory Utilisation with current MDE versionsHigh Memory UtilisationMDE Platform Update FailuresMDE Engine Update FailuresMDE Signature Update FailuresEMDE Signature Update are failing as there is already instance running_Wait for all process Instances of MpSigStub.exe is exited before trying signature update again.QMDE Windefend Service has failed to initialise successfully and stuck at stage %1eRestart the machine and update to latest defender platform and if issue persists report to Microsoft.PMDE Windefend Service has failed to shut down successfully and stuck at stage %1MUpdate to latest defender platform and if issue persists report to Microsoft.UMDE Exclusion references environment variable(s) (%1) which are not system variables.^Please review your exclusions:
'%1'
to make sure they reference correct environment variables.0Unable to retrieve Windows Defender preferences.�If you intended to implement MDE Device Configuration Management, then please refer to the following article for more information.?Verify that Windows Defender service is running and accessible.9Configure Antivirus Microsoft Defender using Group PolicyConnectivity requirements@Configure hybrid Azure Active Directory join for managed domainsM365 Security PortalPAaTroubleshoot onboarding issues related to Security Management for Microsoft Defender for EndpointDefault MDE Policies keyDefault MDE Sensor Service key Default MDE Cache directory path Default MDE Cyber directory pathDefault MDE directory path&Default MDE ProgramData directory pathDefault MDE Temp directory path Default MDE Trace directory path�Delete the registry keys related to AntiSpoofing in order to force the device to generate a new private key and re-register. Run the command %1�Nothing to do. During the duration of the time starting at Cyberthrottling start event sense cyberdata did not flow into the MDATP portal.�This device attempted to onboard through Microsoft Monitoring Agent (MMA) agent but failed as it does not support onboarding using this method.�Please refer to our online documentation to understand what onboarding method is appropriate for this device's Operating System.&MDE Onboarding Supported Configuration8The machine is associated with a specific AAD Tenant ID.�Please ensure that the AAD Tenant ID from your MDE Tenant matches the SCP Tenant ID listed above. To see your MDE Tenant Identification please refer to the M365 Security Portal6Device is anti-spoofing capable and in a stable state.CSharedSignatureRoot is configured and accessible to SYSTEM account.1SharedSignatureRoot configuration appears normal.CSharedSignatureRoot registry value is not configured or accessible.eThis is informational - verify if SharedSignatureRoot configuration is expected for your environment.+Signature update schedule configuration: %15SignatureScheduleDay: %1, SignatureUpdateInterval: %2NReview your signature update schedule settings as needed for your environment.:Configure scheduled scans for Antivirus Microsoft Defender.SignatureDefinitionUpdateFileSharesSources: %1MReview signature file shares sources settings as needed for your environment.SignatureFallbackOrder: %1HReview signature fallback order settings as needed for your environment.�Please note that this machine has a policy that only allows domain based trusted publishers to be added. This may interfere with MDE sensor which needs to install certificates to the Trusted Publisher store.�For more information, refer to the article. 
To avoid unexpected issues, remove the associated group policy configuration: Local Authenticode Flags= %1, GP Authenticode Flags = %2.TrustedPublishersPA\Unable to read Service Connection Point (SCP) from Active Directory configuration partition.GService Connection Point (SCP) contains non-supported configuration: %1DService Connection Point (SCP) contains non-supported configuration.lThe device cannot be joined to Azure AD since the SCP record is configured to join device to Enterprise DRS.]Service Connection Point (SCP) is not configured in Active Directory configuration partition.^Unable to connect to Domain Controller to retrieve Service Connection Point (SCP) information.xThere is a discrepancy between the AAD Tenant ID from your MDE Tenant and the tenant ID in the SCP Entry of your domain.�Please ensure that the AAD Tenant ID from your MDE Tenant matches the SCP Tenant ID listed above. To see your MDE Tenant Identification refer to the documentation.dThe device is managed by SCCM Agent and will not be managed by the MDE Security management solution.�Configuration Manager is recognised as the single security management authority. Defender for Endpoint will not manage security settings on devices that are already managed by Configuration Manager. 
If you wish to change this behaviour you will need to set the Manage Security settings using Configuration Manager toggle to Off. Refer to the following documentation for additional information.:Device is anti-spoofing capable but not in a stable state.fPlease refer to the guidelines in the following article. 
Contact Microsoft support if issue persists.0Microsoft Defender for Endpoint - CVE-2022-232782Microsoft Defender for Endpoint - Threat AnalyticsDefault paths are missing: %1.�Please ensure the mentioned missing path(s) exist and have not been renamed. You may need to create the missing folder(s) with system context.PAKThis device failed to onboard via Microsoft Endpoint Configuration Manager.uThis issue can happen if the registry key %1 is missing from: %2. 
To create the missing registry key you can use: %36Device is reporting to an expired Organisation ID: %1.?You should offboard the device from this organisation, and then onboard it to your current organisation.
Contact Microsoft Support if you don't have access to the offboarding script with the mentioned OrgID.
Note: To view the current OrgID, please go to the MDE portal and click on the username in the top right corner.Security CentrewPlease note the device has error 'Loading the private key for the client authentication certificate' in the OpsMgr log.pPlease uninstall and re-install MMA (Microsoft Monitoring Agent) on this device and check if the issue persists.?The local time on the device is not matching the time in Azure.vPlease check that the local system time is accurate and the correct time zone is set.
If this device is domain joined, please ensure that the 'Windows Time' service is running and the device is synchronised with your domain time. 
For more information on how to configure and control time synchronisation please refer to the article to ensure local time in BIOS is accurate.WindowsTimeLDevice is running an older version of System Center Endpoint Protection: %1.�You should upgrade to the latest available version to ensure compatibility and allow malware detections to be logged in the Defender for Endpoint security portal.=Error occurred in the security configuration management flow.
The device was successfully onboarded to Microsoft Defender for Endpoint. However, there was an error in the security configuration management flow. This could be due to the device not meeting the prerequisites for Microsoft Defender for Endpoint management channel.1Prerequisites for Microsoft Defender for Endpoint=Error occurred in the security configuration management flow.�The device was successfully onboarded to Microsoft Defender for Endpoint. However, Microsoft Endpoint Manager has not been configured through the Admin Centre to allow Microsoft Defender for Endpoint Security Configuration./Microsoft Endpoint Manager tenant configurationConnectivity issue occurred.�The device was successfully onboarded to Microsoft Defender for Endpoint. However, there was an error in the security configuration management flow which could be due to a connectivity issue. 
Verify that the device can communicate with MDE Endpoints.?Azure Active Directory and Microsoft Endpoint Manager endpointsGeneral Hybrid join failure.�The device was successfully onboarded to Microsoft Defender for Endpoint. However, there was an error in the security configuration management flow and the OS failed to perform hybrid join.
Refer to links for troubleshooting OS-level hybrid join failures.9Troubleshoot hybrid Azure Active Directory-joined devicesTenant mismatch.�The device was successfully onboarded to Microsoft Defender for Endpoint. However, there was an error in the security configuration management flow because your Microsoft Defender for Endpoint tenant ID doesn't match your Azure Active Directory tenant ID. 
Make sure that the Azure Active Directory tenant ID from your Defender for Endpoint tenant matches the tenant ID in the SCP entry of your domain.(Hybrid error - Service Connection Point.�The device was successfully onboarded to Microsoft Defender for Endpoint. However, Service Connection Point (SCP) record is not configured correctly and the device couldn't be joined to Azure Active Directory. This could be due to the SCP being configured to join Enterprise DRS. 
Make sure the SCP record points to Azure Active Directory and SCP is configured following best practices. For more information refer to the links.$Configure a service connection pointCertificate error.-The device was successfully onboarded to Microsoft Defender for Endpoint. However, there was an error in the security configuration management flow due to a device certificate error. 
The device certificate belongs to a different tenant. Verify that best practices are followed when creating profiles.Trusted certificate profilesAAD Connect misconfiguration.-The device was successfully onboarded to Microsoft Defender for Endpoint. However, there was an error in the security configuration management flow due to a misconfiguration in AAD Connect. 
To identify what is preventing the device from registering to AAD, consider running the troubleshooting tools.'Device Registration Troubleshooter ToolAFor Windows Server 2012 R2 dedicated troubleshooting instructions
DNS error.�The device was successfully onboarded to Microsoft Defender for Endpoint. However, there was an error in the security configuration management flow due to a DNS error. Check the internet connection and/or DNS settings on the device. The invalid DNS settings might be on the workstation's side. 
Active Directory requires you to use domain DNS to work properly (and not the router's address). For more information, refer to the links.Clock sync issue.�The device was successfully onboarded to Microsoft Defender for Endpoint. However, there was an error in the security configuration management flow. Verify that the clock is set correctly and is synced on the device where the error occurs.Policies download failure.�The device was successfully onboarded to Microsoft Defender for Endpoint. However, the device was unable to download the endpoint security policies from MEM. 
Verify that the device can communicate with MDE Endpoints.Unenrollment failure.�The device is currently enrolled but needs to be unenrolled. However, the unenrollment process was unsuccessful due to a transient error. 
Verify that the device can communicate with MDE Endpoints.Policies assignment failure.�The device was successfully onboarded to Microsoft Defender for Endpoint and was able to download the endpoint security policies from MEM. However, there was a failure during the assignment of the policies.Policies report failure.�The device was successfully onboarded to Microsoft Defender for Endpoint and was able to download the endpoint security policies from MEM. However, there was a failure during the report of the policies to MEM.PA]This device cannot be onboarded in current state as its ImageState inside '%1' is incomplete.�This issue can happen if OS image has performed multiple consecutive sysprep attempts and registry was set to '%1'.
Contact Microsoft support if issue persists.Windows Setup State InformationKThe ImagePath value in registry may have been tampered prior to onboarding.fPlease review this error and inspect the ImagePath (within %1) to ensure it points to a valid %2 path.)Sense cyberdata throttled events detectedMDE and ConfigMgrThe device is managed using Configuration Manager and Microsoft Defender for Endpoint. Controlling policies through both channels may cause conflicts and undesired results. 
To avoid this, endpoint security policies should be isolated to a single control plane.:Co-existence with Microsoft Endpoint Configuration ManagerEnrolment status ChangedThe device is managed using Configuration Manager and Microsoft Defender for Endpoint. The device was unenrolled from the security configuration management solution either because the enforcement scope has changed or the MDE-Management tag was removed from the device.�The %%TEMP%% (and %%TMP%%) system environment variable is not defined. This can cause failures in Windows Defender and other system components that rely on a temporary directory.�Define the TEMP and TMP system environment variables. The default value is %%SystemRoot%%\TEMP for system accounts. Verify the path exists and has appropriate permissions.�The %%TEMP%% directory is not accessible. This can cause failures in Windows Defender components that need to write temporary files.XVerify the %%TEMP%% directory exists and the current account has read/write permissions.�The %%TEMP%% directory is set to a non-default path. A non-standard TEMP path may cause issues with components that assume the default location.PA�Review whether the custom %%TEMP%% path is intentional. If unexpected, reset TEMP and TMP system environment variables to the default value (%%SystemRoot%%\TEMP for system accounts).P�@�U7 9�c.! �=� �T��	M [0_ <q<c�@!� �� (��OO[��� �D�BOS)�! MHB) �O�\]�4�U.�� e=5 ���5 �_ ��2QU�� eQ M��9�.!� ��� " �@O�H� �)4 ^
 (�\� �|�3 7�5H��� ��S _TY�5SU) VFc�!Y�cWM�, �[.!I )g �[ 3�mm��5 c� SQm�� e[� �� ��Y:U��
 �M ���V 	�L�W ��:Q�� �__�Q]. 
� �U m�U W���Ym�g��  M9 "\ �Kc�O�c/�8 ���R ��QH� �Q� ��@�-Hg @>T�[ O��5Y e� B'� �3B��!�.� �F ~_S�|bR/a m�')�M =�a ��/@T c� �;2�O �sQ e� <�UU�D! �7Um�[_�M�[ ��U YM�_�3^ 7� $�9�_^�]cT<_�YW����gY1BZc_73�V
7a_` a�.�"%�[ �? =�@�  ��.! eQ +9�Y�S�8 �SMm 3O ��WB� _5��Y��� �S����gU �3 �� \�^b� 4	�>q�g ��B: ��Kg3�! @5�m�UUW�9a �UM m+U]�  �O3 �?�_`�]g7<_�YS�c� e��:`�e_\.!Y�)�.!U_^��[7. �' ��Ym�a_�O;[ ��_�� ��W ^`b"� 4��Qq�g �W�: %1N @�] H�c� e=� eR�U a����3 ��U ��� [4�7 g[� <��3F ��-��� �#�Dc �H[g0:>.�lD���� �!;� ��� �H?<.!�: aU�O[ �_ �QB �F_g4!>� M; c=�[ ��-A�. 0B �[ Y�Omm9��� B� )K]e�>< BR ?u �#TFc �MO ��e�m�B @QO��W<��.! I� �W>cM�g)�� 	���L�@+e��[. � MO <QY �?��Y<�g/M; W��7S g� g% M��m7?gc+��FN;2��Y� )�8�OH_ a.!U��Wa g� B'� �W�Y�a1�e ��9�7W ��3 ��QV�c a7Y�/�Y��:�/Q] �__�#;m�B ���@sO� O�
iOU� JQ��a� �� c%� �M!!��-K! 5F��W�DmMIg ��W+�2BM(]): %1&d= ���T �_ [F��.!]U��::w OD2�S� g� ���Y>aQ�e ����8�3 ��� ���>�Hg �; �_ 4J@� B� �>�;>�0� cR5 .!D�@��9g U��_W-c� ��@�A+QU �S�< �. ��HT�Q�, e[�O� ��a � ��/<�SM �oY�� e=� �__�!F<�8B �� e%� �>!��W�_. 
  >��_ Y�m��7 ��� 81H-��U�-? @c%([) �Y�< e% �L��� [�]BM< 7;�+3�9<��c ��Y�42@T(U).5`Mg ��-UO�m�Fc �0�VL@a -; �%T \�[�Mm 1DcO�! ��H.!@i��B)��] �_[�?m�He ���>kY �	�SW� U���M �D�m�� � �3 \'�O `
'��B��! (� ^) �[ H�LB.! �  �% ��
�.=�R� 7��A� I�[ [�	
TUU��:<� �?LO�W� e� WA3�_��B ���K��S �>O �H�����g �; u�a �J!.! �O OHD:� g=T M?��1V�c _M	��WcC ��!�
�a �YQm �. 
 $M���7O, �%� I�a � �4�<oS.! �iU��! e%� �[_��mMIg �� c=Q @�@V	�.!_ s e�  � B-m�g��)�� �=�� 
4K ���_O I%D � ZZ V[ .! �J@�. 
 �@a 	MIB�e W�Y�_��� ai�@�S� ��O �[[-UB�D��.M�5�V �[ I>c F�-e�-��c5 �D �17[ �Mg '��� Fe�-]�O���9 �@�L�@Wc^ �5@!Q^�.� @�U� �a_W C�F �B�C �[M O�A�<m�H��� _7_Y-e^ �B
% B� �W�cQAB e[Q �Q�- �YMm a@�M��9#, ��Y <>37 /H��O<g�OF ����� �� g%� B�K7U.0���O�a��B �MH�U �MY -F�@��?� - V"-2022-232782���3QUO�g ����� ��W F��)Ic - �%S��c �;<�gW�_W7��
� �] ��89-D# ��B' �� �:� �7W_/O� �� c[ ���S�a1�e ����8�QS ��S  �@M�Fc � ].!D[��M !��U7 i@�g �[ [��a�Y c� �I[�OT ^�_ [��� Q�c)<4B �W�g7e��9 �? ae�L�!�B�.5�
U�_��g �.!8�5� �QU K@�);c ��0� �1� � 7�_�Y�"'�a <�R�FM %0a ���@.! �O M9J>03 4_ �aHU.!.6 AO4[[M _Y�F ���cW�!�~�eV�; �=�U� ��Y b:9�L.<@.
 f= �Y3�Y �Y>m g[� 30UR I4U: %1d[+_ �8 '���.!? V� g[ `�Zd �A
1�Hg �OT[ �Oe [�� �QU<WUa)��U gQ u3��� B� �=M E�T	c� ���[ (�S�#Y�m4e0\����_���\t�I��] �5�I�3 ��48	T� "=Y.!�e  Y�e.!
eVMD\�^2�Y).
 �:a� ��>/��7 c%� � �] �D c[ ��gR �� �Q]�e cR� �Q�m)_a)�8[ �U�m ��Y;� �O<��U �� 8T�.E7�)� �a 0;e�-a@�>��D# ���J>5 Lse �[ F�� ^�g SQ!�_cQY ��gR >1�.l�@�_ 5�]�W� ��H87������ e� 
<�s� �� X;a �_ K�e J!��:�. ��B�� �WA��_Q�B U_�@�3B �� �aam� @7U]�[B[.M� Q?�V#�S�g�1K �W �����5HC �a @W�7Fc�� �e��U� �U1e.!	�VO; �S�< [B�Ye-�.T�B7�aT W����H gR�_ 73��O <[U�!� e� �D�M�]e��� g=� 2:�8W� /a]�T �I� S�[>@�M -g: %1aZ��@�3�� f�^ �+�[��U W7 ��e MIL@T� �I c%+U m�[)IT. f=�U ��D ����Ag 	��9�����e� e� � @��.� :Q]� V8_@�c B% 	M;��kSQ �/@R��U (�VB'WH �6=\\&!� f���-\��:���a\�W�]Q�e\�W����!O@[w\OI�WF�4g��8\\\� \00010002) e� ��]�S /g ��e�V�_ m���<F< Oqq�3 ��=7W[ ��Y 
OKF
�)�/B� g� �� A@�m."��@[�O ai/eT[ �?� "9 YQq�WS�mM9�_bb;` 1.2 �:-QKg �YMg�1< W[  >� 7;�L:�� Q9 e'V] <4'W �. �%�] 
0� ���	� 	QF;c��-c� �� �� :���.� @0[� �8�WU< e'�B f�\ 1.2 
B��8e �U M�4L:� (uWg%�; &�� �\^�^�\�YY��c� 1�BSO<^�g\
�;gYO<\\�
�O/�C�Y����QWU\^$�""A\ W�g���@[\"� \ 1.2\>-58g).PAX�� �& 	V�=.!W] 4S� ��B I�2B�� �9 BR/[ <�%+I�. d[�_ �9 ���5B 
�IF�B-��B� B> � B��.� B.!�]7 	QH��Sm g[�B � �� �wE
=�8#��:!�Y�g%< �_ TD�LB� (H+e=V8 ��?\ZZ��\iYS�DB� �DBY>:\.!g\� �����@\^F3�BC�U��VT3_\\
&�E=\���6
=����:���B[<]\�!��).�]�	 ��  eU� �+@���BH�O��Y������ �<@���Fg +a �-]�2@ �S ��->M �T9 �[�7 e�_B. b[VU m� VH�
�g � �Y_TK�� M� � F7c��W8 O�+3.!c�� (-E: �[�� &<JU�B<�).PAControlled Folder AccessFFailed to load mde_cfa_evaluation module - CFA diagnostics unavailable3Verify MdeDiag installation and module registration:No CFA (Controlled Folder Access) detections found in logs0No action required - CFA is functioning normally-Analysed %1 suspicious files for trust statusVReview CfaTrustChecks.txt in the diagnostic output for detailed trust analysis resultsA%1 is not trusted by CFA because process image is not known good.[Add it to list of allowed apps or add an AV exclusion for this file if you trust this file.>%1 is not trusted by CFA because its parent is not known good.8%1 is not trusted by CFA because its parent is a script.A%1 is not trusted by CFA because it loaded an untrusted file: %2.R%1 is not trusted by CFA because it was injected into by an untrusted process: %2.9Add an AV exclusion for this file if you trust this file.IAdd an AV exclusion for this process if you trust it (Process Exclusion).PAProcess: %1CFA Events:  - Action: %1, Reason: %2
Taint Events:"  - TaintType: %1, TaintReason: %2Guidance: %1(%1 occurrences)PApASR %1 GUID '%2' (source: %3) has leading or trailing spaces/tabs which can prevent the rule from being applied.mRemove leading and trailing whitespace from the ASR Rule GUID in your Group Policy or registry configuration.�ASR %1 GUID '%2' (source: %3) contains curly braces. GUIDs must be specified without braces (e.g. 56a863a9-875e-4185-98a7-b882c64b5ce5).^Remove the curly braces from the ASR Rule GUID in your Group Policy or registry configuration.rASR Exclusion '%1' (source: %2) has leading or trailing spaces/tabs which can prevent the exclusion from matching.rRemove leading and trailing whitespace from the ASR exclusion path in your Group Policy or registry configuration.�ASR %1 GUID '%2' (source: %3) is not a valid GUID. Expected format: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx (e.g. 56a863a9-875e-4185-98a7-b882c64b5ce5).{Correct the ASR Rule GUID in your Group Policy or registry configuration to use valid GUID format without extra characters.��\V E!q[��H '%1' (aQsY
�: %2) ��KB�/I] 4 ��Y�?g-��O�e�UC ('..') _�#m��c. ��c�S OQ]�:�/� '..' �R7 ����gV�� 7��@o� �4c[ <� 25 m_
= LY�4�W B=0� gR� >�c�U�! FBW� [�##ae[, ])B�?B<� ����8��9! �R� �E�>Fa�M9 J5^�K �e_ � �H�� [�>@�.�7@>0� �=� \� ��:�a��� 5Ic�^ �W�'  �o!@w-O[�B��� �J]�!�cM ��e' B'�g �5] ?1e 	MD���I '..' _�mMHea. 5�5�g �O[�Q�U �� ��3>]��c �����W O�5�
� K�8-���?�	�@ T�	<q]-O; T�cS��] �� ��I�� B�� BW<.%What is Defender Diagnostic Insights?Defender Diagnostic Insights is a self-help diagnostics tool that collects and analyses the diagnostic data, and provides a report to help troubleshoot Windows virtual machine performance problems in Azure. Defender Diagnostic Insights Windows documentation is %1.'Where do I start to review this report?�Start with the Overview tab. Review the recommendations and links for the findings. Learn about how they can affect performance, and also about best practices for performance-optimised configurations. Learn more about reviewing the report %1.?What kind of data is collected by Defender Diagnostic Insights?Defender Diagnostic Insights collects information about the Windows VM, disks or storage pools configuration, performance counters, high resource consumers, logs, and various traces. Details about what kind of information is collected by Defender Diagnostic Insights is %1.P�P�P�P�h`An error occurred while running LUA module.

lAn error occurred while loading LUA file module.

TSyntax error occurred in LUA module.

@LUA memory error occurred.

@LUA general error occurred.

<LUA panic error occurred.

pLUA execution has been interrupted by stop signal.

�Failed to dynamically configure heap snapshots for process.

4VS_VERSION_INFO����e��e?tStringFileInfoP080904B0LCompanyNameMicrosoft Corporation�2FileDescriptionMicrosoft Defender for Endpoint Diagnostic EngineBInternalNamedefenderdiag.dll�.LegalCopyright� Microsoft Corporation. All rights reserved.ROriginalFilenamedefenderdiag.dll.muij%ProductNameMicrosoft� Windows� Operating System�;FileVersion4.18.26060.3008 (df1b0eba8e0e68e7272235d6dea4de3285c715b9)DProductVersion4.18.26060.3008DVarFileInfo$Translation	�PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD�%0�%y	*�H��
��%j0�%f10
	`�He0\
+�7�N0L0
+�70	���010
	`�He �ߢY0{�����z&�!�B��"Jܔ��jo�Z��
�0��0��3zk�ճ��z0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20110
260219193722Z
261017193722Z0p10	UUS10U
Washington10URedmond10U
Microsoft Corporation10UMicrosoft Windows0�"0
	*�H��
�0�
���
���xT�	�8+;�H'��h�<&�s�7\A}��;��_��=)ؔ6-� �9��
���5p^W�O���$:���dB�A�F�O�� 5��f��rvYRU_t���%�
0��b4�^����=��݌vOr�5��HT	�d���)#r�'ҳ'ϙ;��V����%=�(R64.���o�u��+j��
���A��`p�5�]�N0>iv�W��o��[3T�z+�:4aCCl@�U>���r#uN^7���v0�r0U%0
+�7
+0U��:�a8��B�~�J�$�(0EU>0<�:0810UMicrosoft Corporation10U
501107+5068660U#0��)9�ėx͐��O��|U�S0WUP0N0L�J�H�Fhttp://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl%200a+U0S0Q+0�Ehttp://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0U�00
	*�H��
��T?i�t���:�]�?�T]�hd��z������B���s��=�oY�^Sxg��+OU�J%⩺��v��/V�A���'a����Q���=5�\�����[ݻ�F,�`�
4�r�̅/�Ag�?�o�ԗ�E�H��BNN�,�g?���Q�Dp��t�
u��Wtu����
g�M.u���V&h�{�Mp�9��j�Â���,N�&&�-�ƶ��: FF�2󨺇0�P0��t\��&���؞p	>��ys0��0���
avV0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100
111019184142Z
261019185142Z0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20110�"0
	*�H��
�0�
�����.	����i�!�i33��T����� ��ҋ�8����-|by��J?5 p���k�6u�1ݍp��7�tF�([�`#,��G�g�Q'�r��ɹ;S5|���'�����#	o�F��n�<A�ˣ?]jM�i%(\6��C
��������['�'x0�[*	k"�S`,�hS��I�a��h	sD]}�T+�y��5]l+\μ�#�on�&�6�O�'��2;A�,���w�TN�\�e�C���mw�Z$�H��C0�?0	+�70U�)9�ėx͐��O��|U�S0	+�7
SubCA0U�0U�0�0U#0��Vˏ�\bh�=��[�Κ�0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
	*�H��
��|qQ�y�n��9>�<Rn+?s��h�H�4M��&�1F�ay�8.Ek��(�����	��L
6fj���������@26v�Zƿ���Ӭ�h�b��TlP0X��|���N���|�sW�R!s4Z�V��	����~�����?�rS��c��=1e�������=����BА�_T���G�o�sNA�@�_�*��s�!(���s9_>�\`����	���Q�fG���=�*hw��Lb{��Ǻz�4Kbz����J7�-�W|�=ܸZ��ij�:��n�i!7ށ�ugӓW^)9��-���Es[���z��FX�^���g�l5��?$�5�
u�V��x,��Ј���ߺ~,c��#!�xl�X6+�̤��-����@�E�Ί\k>��p*
j�_G��c
2��6*pZ�BYqKW�~���!<��Ź���E��� ����ŕ�]b֠c �uw}=�E�����W�o3��w�bY~1�0�0��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20113zk�ճ��z0
	`�He���0	*�H��
	1
+�70
+�710
+�70/	*�H��
	1" W�e��F���&������o�H̊����׵e0B
+�71402��Microsoft��http://www.microsoft.com0
	*�H��
��R/]�߱��ad�N�@ː�+����4� �Y�ā4X�g��e��O�XiUEx�S��oj���&Tb���A%-� 2�|U8f�ua���9��t�J�#s)#b4b�꺉�K�V�^��UJ6�%A���j��sB�b	z�WO9W���/�1���1m GȬGH�8FmԆ��E���u7$��I �ڙI�G�]�FU���/Ud�J#����/�O
q�&���UH�	�
���j
�ӑ;�L`V����0��
+�71��0�~	*�H��
��o0�k10
	`�He0�Q*�H��
	��@�<0�8
+�Y
010
	`�He p�z��Nκ��hA+��1�:'�V�/���_�Xj1���20260622202612.17Z0��Ѥ��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1%0#UMicrosoft America Operations1'0%UnShield TSS ESN:9600-05E0-D9471%0#UMicrosoft Time-Stamp Service���0� 0��3&5�>gC��&0
	*�H��
0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100
260219194002Z
270517194002Z0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1%0#UMicrosoft America Operations1'0%UnShield TSS ESN:9600-05E0-D9471%0#UMicrosoft Time-Stamp Service0�"0
	*�H��
�0�
����d��DQiT�ݜ�6��8=�8�#�}��xܬ�NK:Is�^S2�.��^���Q���o�b��9L�XlbVwEr�o�����7HA��'�sr7[O~^qP	�E_�F�om2A����2D�;#����"c��vk}��m~����)���Z����
�f��6N���JɆ�s��/��0�y�7v#�5
��J#fG�ٙ+|�Af��NY�!���$�:�N9�<&�{몄sQ��%l�ְ*��T�A�����6�<9+|ߚ��:k��!�h��b����cI�k�
���t�~!�LDd֑�M��m�**��s�a*�Er;nk��f�����T�
J/^�p��s=ş"Q�9(M�v����a�H��i������(}]�:nFT� �y��>��H&�KA�TLX�?���{!����)U$��3[�+��K=*���<ġ^A�k��w_�S��}*p����av1H5ǻp�xVqdІH�C���I0�E0U]���$ݘ��KU�O#3\{0U#0���]^b]����e�S5�r0_UX0V0T�R�P�Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l+`0^0\+0�Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0U�00U%�0
+0U��0
	*�H��
�6S-��
;*�Tr�Zqד�����	;���S��|8���Lٵv��N��)&��~�^���y�8.^v{�$V
�/���q�%I��؟���m���<W��	C9(�y^����!�e�na��\��v&)+�Yjd�"��>??�L��q��v.f��¸��&�W�I&Y�:��G���5
;���*3�<�e�j\�w����z.��[
Mw������,��Va�䷶4�ߝ��E�~Ep�8�gs��_���a�Z�W-_�i�O�^jj~]�Ͼ�A|
u�f��7�h�ȟ�ÐҸ���
,q�"����g���o6���B��Tc��D��P�o:�$>�V�9��w��W)�'�y�@���H�����l�����ȑ��{���.a��F����n�$}&��
��u�:�����݌�����
բ4@��
��
_����1�/����K����	Ղ�^iQ���s<;g������F�[՜S����ψ�~��+P
�e0�q0�Y�3��k��I�0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100
210930182225Z
300930183225Z0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100�"0
	*�H��
�0�
���L�r!y���$y�Ղ��ҩlNu��5W�lJ�⽹>`3�\O�f��SqZ�~JZ��6g�F#���w2��`}jR�D���Fk��v��P�D�q\Q17�
8n����&S|9azĪ�ri����6�5&dژ;�{3��[~��R���b%�j�]�S���VM�ݼ��㑏�9,Q��pi
�6-p�1�5(�㴇$��ɏ~�T��U�mh;�F��z)7���E�Fn�2��0\O,�b�͹⍈䖬J��q�[g`���=� �s}A�Fu��_4���� }~�ٞE߶r/�}_��۪~6�6L�+n�Q���s�M7t�4���G��|?Lۯ^����s=CN�39L��Bh.�QF�ѽjZas�g�^�(v�3rק ��
�co�6d�[���!]_0t���عP��a�65�G������k�\RQ]�%��Pzl�r�Rą��<�7�?x�E���^ڏ�riƮ{��>j�.����0��0	+�70#	+�7*�R�dĚ���<F5)��/�0U��]^b]����e�S5�r0\U U0S0Q+�7L�}0A0?+3http://www.microsoft.com/pkiops/Docs/Repository.htm0U%0
+0	+�7
SubCA0U�0U�0�0U#0��Vˏ�\bh�=��[�Κ�0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
	*�H��
��U}�*��,g1$[�rK��o�\�>NGdx���=13�9��q6?�dl|�u9m�1��lѡ�"��fg:SMݘ��x�6.���V����i�	�{�jo�)�n�?Hu��m��m#T�xSu$W�ݟ�=��h�e��V����(U'�$�@���]='�@�8���)�ü�T�B�������j�BRu�6��as.,k{n?,	x鑲�[�I�t�쑀�=�J>f;O���2ٖ����t��Lro�u0�4�z�P�
X�@<�Tm�ctH,�NG-�q�d�$�smʎ	��WITd�s�[D�Z�k
��(�g($�8K�n�!TkjEG����^O���Lv�WT	�iD~|�als�
��Af=i��AI~~���;����>�1Q������{��p���(��6ںL���
�4�$5g+�
�挙��"��'B=%��tt[jў>�~�13}���{�8pDѐ�ȫ:�:b�pcSM��m��qj�U3X��pf�P0�80����Ѥ��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1%0#UMicrosoft America Operations1'0%UnShield TSS ESN:9600-05E0-D9471%0#UMicrosoft Time-Stamp Service�#
0+���1�*���]��e4�"�g���0���~0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100
	*�H��
��s�0"20260622084040Z20260623084040Z0w0=
+�Y
1/0-0
��s�0
8N�0�0
���06
+�Y
1(0&0
+�Y
�
0� �
0��0
	*�H��
�#l@o��ƽf��q ��8Vu�h�fG|d�ͳV�ڃV�t��v���<�~�\���t6�S�_L\<h	z���xreT�b�U5�
 �ZWt%Y>/T�g��]ٽ�����I��[YG�
�(����Jh��<���w�ݦ��#������y�φ
�ª�����#�FfJ��p��z�7M��z��RM��# ��d=�����T"�8�_�m�
�{R�5t����Z�T�ꮓ���[��1�rYi8�1�
0�	0��0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20103&5�>gC��&0
	`�He��J0	*�H��
	1
*�H��
	0/	*�H��
	1" .��d�����Q���m�gVsʳ��EWA.nm�0��*�H��
	/1��0��0��0�� �2\agL�D��c�t�F�?uAb�ōK��*0��0���~0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20103&5�>gC��&0" ��;�E����%��x��|��*?0
	*�H��
���0��`ex�P�uP�Ե���Z��	|;wm�qQ��Y9�x�f�&���O�<�S�q�G����`��9�f�wM��q���b���:
�َ7��k1�X�g��6�s��~����_��=�\�ot���N�_
����-��3���Y̨^����Y	�K�-��/eD�����C}#j�B�� �v������m�vK.������N"l�w�Ls]��r'|��q�(3��Ĉ��ޞ8zN�EM��q"Q�/M-f�|�7:(&bym��F"���*�3��A�v��O|����T��M����Y#!�~����U��c��S���Ɯ�Jq�#�5=5ja)���&X/yB%7�]O��9
�3��6n�2�	�p`~�;)w:�Ӡ��e�%y��r�"�3}&�^c�a��yո_�U�@����jY���1���r��z2�-���k�TWG>(h\�5,�k�
�*���3���%�c�;;�I�G����2�⭳�

Youez - 2016 - github.com/yon3zu
LinuXploit