403Webshell
Server IP : 209.209.40.120  /  Your IP : 216.73.217.112
Web Server : Microsoft-IIS/10.0
System : Windows NT NEWWWW 10.0 build 17763 (Windows Server 2019) i586
User : NEWWWW$ ( 0)
PHP Version : 8.3.30
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /ProgramData/Microsoft/Windows Defender/Platform/4.18.26040.7-0/zh-CN/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /ProgramData/Microsoft/Windows Defender/Platform/4.18.26040.7-0/zh-CN/ProtectionManagement.dll.mui
MZ����@���	�!�L�!This program cannot be run in DOS mode.

$=;=�yZS�yZS�yZS��Ӭ�xZS���Q�xZS�RichyZS�PEd��6X�" ,~���` t{��%8.rdata�@@.rsrc� |@@�6X
lPP�6X$����8.rdata8.rdata$voltmdP�.rdata$zzzdbg �.rsrc$01�&��.rsrc$02 s_`^�:�d��\?X�ƥ�]�ȅ+ӝS�6X��0�H�H�`�x������������ �8�	P�
h�����
���������(�@�X�p������������� 0�!H�`�x�������� 0@P`p�������� 0@P`p���&��`'�`)�d,��P0��4��<���A���C��E�$G\��H��K��L$��M���Q0��Sf�(YZ
��f��tlr��o���s��Dv���z���~v���������t������"��� ��,�H�MUI���x6[w��T���?��p���v��NmuB�}���MUIzh-CNُ/fN*N>f:y�W,g�r`�v�ba�{|01u MAPS R�^�v���{:g IDS_MR�v���{:g�r`
CleanStatePendingFullScan
PendingRebootPendingManualStepsPendingOfflineScanCriticalFailure
c:y/f&T���͑/T��YDefender �vS_MR�N�T�r`NoStatusServiceNotRunning,ServiceStartedWithoutMalwareProtectionEngineEndingManualStepsAVSignaturesOutOfDateASSignaturesOutOfDateNoRecentQuickScanNoRecentFullScanSystemInitiatedScanInProgressSystemInitiatedCleanInProgressSamplesPendingSubmissionRunningInEvaluationModeRunningInNonGenuineWindowsModeProductExpiredOfflineScanRequired$ServiceShuttingDownForSystemShutdownRemediationFailedCriticallyRemediationFailedNonCriticallyNoStatusFlagsSetPlatformOutOfDatePlatformUpdateInProgressPlatformAlmostOutdated+SignatureOrPlatformEndOfLifePastOrImpending-WindowsSModeSignaturesInUseOnNonWin10SInstallDefender ЏL�!j_�nf�0���R0sxs ���R	��N�THr,g(;N��0!k��0�Q�0�O��)
g�RHr,g(;N��0!k��0�Q�0�O��)�Y�g Defender AS b AV ~{
T�]Ǐg�S�
�o��Nyr�_Hr,g(;N��0!k��0�Q�0�O��)'�S�
�o��Nyr�_gP�()Y) - �Y�gyr�_�N*g�f�e�RgP�\>f:y:N 65535 )Y'
N!k�f�e�S�
�o��N�v,g0W�e�0�Y�gdky��N*g�f�e�Rdk^\'`-N\>f:y null <P2��u�ko��Nyr�_Hr,g(;N��0!k��0�Q�0�O��)'2��u�ko��Nyr�_gP�()Y) - �Y�gyr�_�N*g�f�e�RgP�\>f:y:N 65535 )Y)
N!k�f�e2��u�ko��N�v,g0W�e� - �Y�gdky��N*g�f�e�Rdk^\'`-N\>f:y null <PNRI yr�_Hr,g(;N��0!k��0�Q�0�O��)*NRI yr�_gP�(�N)Y:NUSMO) - �Y�gyr�_�N*g�f�e�RgP�\>f:y:N 65535 )YPA)
N!k�f�e NRI �v,g0W�e� - �Y�gdky��N*g�f�e�R�^\'`-N\>f:y null <P%
N!k�[hQkb�c_�Y�e� - �Y�gdky��N*g�f�e�Rdk^\'`-N\>f:y null <P%
N!k�[hQkb�c�~_g�e� - �Y�gdky��N*g�f�e�Rdk^\'`-N\>f:y null <PcLast full scan age in days- if signatures have never been updated you will see an age of 65535 daysLast scan sourceUnknownUser�|�~	Real-timeIOAV;Signature version used for the last full scan of the device>If no full scan has successfully completed in the last 14 days-Indicates if a Defender full scan is required$Real-time scan direction enumerationBothIncoming	OutcomingdTime of last Quick Scan start - If this has never updated you will see a null value in this propertybTime of last Quick Scan end - If this has never updated you will see a null value in this propertyeLast quick scan age in days- if signatures have never been updated you will see an age of 65535 days.<Signature version used for the last quick scan of the device?If no quick scan has successfully completed in the last 14 days5The AM Engine version (major, minor, build, revision)If the AM Engine is enabledWSpecifies whether the computer is monitoring file and program activity on your computer)Scan all downloaded files and attachments0Specifies whether behavior monitoring is enabled1Specifies whether Antivirus protection is enabled3Specifies whether Antispyware protection is enabled2Specifies whether the machine is a virtual machine6Specifies whether the machine has tamper protection onkSpecifies the last entity that changed the TamperProtection state e.g., UI, Signatures, Intune, ATP, etc...1Specifies whether real-time protection is enabled2NRI Engine version (major, minor, build, revision)If the NRI Engine is enabled+Indicates the current Device Control state.@Indicates the current Device Control DefaultEnforcement policy. \Timestamp indicating when the last configuration update occured for device control policies.Troubleshooting (TS) mode state-Troubleshooting (TS) current state start time+Troubleshooting (TS) current state end time.Troubleshooting (TS) remaining time in minutes/Troubleshooting (TS) remaining quota in minutes%Troubleshooting (TS) quota reset time-Troubleshooting (TS) maximum quota in minutes Troubleshooting (TS) mode source)Smart App Control (SAC) mode: On/Eval/Off1Smart App Control (SAC) eval mode expiration time Defender initialization progress>Indicates the state of Controlled Configuration on this device�g�gHr,g/UN�hKm IDZ��
T�y%N͑'` ID - �g>NNO-NI{ؚ%N͑
{|+R ID - �g>NINVALIDADWARESPYWAREPASSWORDSTEALERTROJANDOWNLOADERPAWORMBACKDOORREMOTEACCESSTROJANTROJANEMAILFLOODER	KEYLOGGERDIALERMONITORINGSOFTWAREBROWSERMODIFIERCOOKIE
BROWSERPLUGIN
AOLEXPLOITNUKERSECURITYDISABLERJOKEPROGRAMHOSTILEACTIVEXCONTROLSOFTWAREBUNDLERSTEALTHNOTIFIERSETTINGSMODIFIERTOOLBARREMOTECONTROLSOFTWARE	TROJANFTPPOTENTIALUNWANTEDSOFTWARE
ICQEXPLOITTROJANTELNETFILESHARINGPROGRAMMALWARE_CREATION_TOOLREMOTE_CONTROL_SOFTWARETOOLTROJAN_DENIALOFSERVICETROJAN_DROPPERTROJAN_MASSMAILERPATROJAN_MONITORINGSOFTWARETROJAN_PROXYSERVERVIRUSKNOWNUNKNOWNSPPBEHAVIOR
VULNERABILTIYPOLICYType ID - Enumeration	Known BadBehavior
Known GoodNRIZ��Gl;`�r`ThreatCleanRebootRequiredManualStepsRequiredFullScanRequiredReinfectionLoopExecuted(List of resources affected by the threat Specifies if threat has executed!Specifies if the threat is activeVThis is a singleton that represents the Microsoft Antimalware service infection status7This class represents the catalog of recognized threatsUnique Threat ID@b�m�S�vۏz
T�y��Bl�N�Ock�v(u7b
�hKm�n{|�W ID - �g>NELAMLocalAttestationPARemoteAttestation
�S�hKmq_�T�vD��nRh�R�YZ���hKm�e�Z���r`�vg�e�f9e�e��O
Y�v�e�0gbL��r` ID - �g>N�];�bkAQ��ck(WYtNotExecutingZ���r` ID - �g>N�hKm0R�]nt�]���y�] Rd�CleanFailedQuarantineFailedRemoveFailedAllowFailed�]_(u
BlockedFailedZ���r`���Nx	nd��d\O - �g>Nnt���y Rd�AQ��UserDefinedNoAction;�bk
c�[nd��d\O/f&Tb�R���gbL�vQ�N�d\OMb���[b�Ock - �g>N�eFullScanAndRebootRequiredFullScanAndManualStepsRequiredRebootAndManualStepsRequired'FullScanAndRebootAndManualStepsRequiredFullScanAndOfflineScanRequiredRebootAndOfflineScanRequired'FullScanAndRebootAndOfflineScanRequired!ManualStepsAndOfflineScanRequired,FullScanAndManualStepsAndOfflineScanRequired*RebootAndManualStepsAndOfflineScanRequired5FullScanAndRebootAndManualStepsAndOfflineScanRequiredُ/fN*Nh�:yZ���vS_MR��~�r`�v{|1.0Microsoft Defender 2��u�kkb�c{|Microsoft Defender 2��u�k~{
T{|Microsoft Defender 2��u�k WDO kb�c{|Microsoft Defender 2��u�k�hKm�O�S{|AQ���{tXTc�[/f&T�^sQ�
g�RhV SKU �vꁨR�cd��R��0AQ���{tXTfnx�ybkkb�c�e�h�gR�Q�v�NUO_0AQ���{tXTfnx�ybkkb�c�e�h�gR�Q�v�NUOibU\0AQ���{tXTfnx�ybkkb�c�e�h�gR�Q�v�NUOۏz0,AQ���{tXTfnx�y(u(WN�~yr�[�v IP 0W@W
N�Ǐ wdnisdrv ۏL�Q�~pencS�h�g0c:yy�(W Rd�MR�^�OYu(W���y�e�N9Y-N�v)Ype0�[�ekb�c�eT - �g>Nc:yfg�QgbL���R�v�[hQkb�c�N�[b�Ock0�k)Yfg�efgNfg�Nfg	Nfg�Vfg�NfgmQ�N
NOIndicates what time to perform the scheduled full scan to complete remediation.9Configure the state of Remote Encryption Protection(REP).*gM�n�v�[8hsQ�rTime in minutes for which Remote Encryption Protection(REP) will block threats. 0 results in no limit enforcement.XIndicates how aggressively Remote Encryption Protection(REP) will block detected threat.MediumTSpecify the IP address and subnet exclusions from Remote Encryption Protection(REP).M�n�f�R2��b(BFP)�v�r`0lTime in minutes for which Brute Force Prevention(BFP) will block threats. 0 results in no limit enforcement.RIndicates how aggressively Brute Force Prevention(BFP) will block detected threat.c�[�f�R2��b(BFP)-N�v IP 0W@W�TP[Q�cd�y�0PA`Brute Force Prevention(BFP) Plugin - extend Brute Force coverage to block IPs on local networks.�Brute Force Prevention(BFP) Plugin - disables Brute Force Protection's initial 2 week learning period and starts blocking threats immediately.=Configure timeout for detections requiring additional action.zTime in minutes for a detection in the 'critically failed' state to move to either 'additional action' or 'cleared' state.UTime in minutes for a detection in the 'failed' state to move to the 'cleared' state.OSpecifies the interval that will be used for service health report, in minutes.fSpecify whether to report a Dynamic Signature dropped event. By default, such events are not reported.OSpecify the maximum percentage of CPU utilization during a scan. This policy setting allows you to configure the maximum percentage CPU utilization permitted during a scan. Valid values for this setting are a percentage represented by the integers 5 to 100. A value of 0 indicates that there should be no throttling of CPU utilization.
When set, Microsoft Defender Antivirus will check for new signatures before running a scan.  If new signatures are found they will be downloaded and installed before the scan begins.  If no new signatures are found, the scan will start based on the existing signatures.CTurn on removal of items from scan history folder. This setting defines the number of days items should be kept in the scan history folder before being permanently removed. The value represents the number of days to keep items in the folder. If set to zero, items will be kept forever and will not be automatically removed.�NS_�|�~Y�Nzz�r`�e�Mb	cgq��RЏL�kb�c0c�[��(u�N��R�vkb�c�vkb�c{|�W0�_�kb�c�[hQkb�c
c�[fg�QЏL���R�vkb�c0c�[(WN)Y�v�NHN�e�ЏL���R�v�_�kb�c0PAc�[(WN)Y�v�NHN�e�ЏL���R�vkb�c03CPU O(uP�6R�S���^(u�N��Rkb�cb��Rkb�c�Tꁚ[INkb�c0؞��<P�N\ CPU O(uP�6R�^(u�N��Rkb�c0(W'}�c@w��!k�[ňT�v�]M�n�e�Q-Nbk@b	g
g�R/T�R�v�f�e0J�f�N CheckForSignatureBeforeRunningScan0�Y�g~{
T(Wdk�e�Qb�R�f�e�R-Nbk@b	g
g�R/T�R�v�f�e0�e��NR��:NUSMO0v�[IN(u�NN}��[hQ�`�b�f�e�v�e�NqQ�N0dk��nAQ��`OM�n(u�NN}��[hQ�`�b�f�e�v UNC �e�NqQ�N�n0ُ�N�n\	cgqc�[�vz��^T��|0dk��n�v<P�^�g>N�[hQ�`�b�f�e�n�T*N�nKN�(u�z�~R��0�O�Y: {\unc1 | \unc2 }0�Rh�؞��:Nzz0)�Y�g��n:N true�AM 
g�R\
NO(W/T�R�e/T�R�[hQ�`�b�f�e��e��/f&TX[(W_�d0��[IN(u�NN}��[hQzf���f�e�v�n�vz��^0dk��nAQ��`O�[IN�^ޏ�c�v
NT�[hQzf���f�e�n�vz��^0dk��n�v<P�^\O:N	cz��^�g>N�[hQzf���f�e�n�v�N�z�~R���vW[&{2N��eQ0�S���v<P:N: "InternalDefinitionUpdateServer"0"MicrosoftUpdateServer"0"MMPC"0"FileShares" )c:y(Wfg�QۏL��[hQ�`�b�f�e0�Y�g��n:N��(0x0)�R�k)Y��OۏL��[hQ�`�b�f�e0#c�[�Su�[hQ�`�b�f�e�h�g�v�e�0؞���`�QN�O(W��Rkb�cKNMR�h�g~{
T0I�[INb���f�e~{
TKNMR�v)Ype0�S�NO(u SignatureUpdateLastChecked00 = �e�f�e�1 = 1 )Y�2 = 2 )Y�I{I{0)�e�<P�N�f�e�h�g��v\�epeh�:y0	gHe<P��V:N 1(�k\�e)0R 24(�k)YN!k)0UNC ~{
T blob Q�~qQ�NMOn0c�[\(u�N�h�g~{
T�v�e����NR��:NUSMO0�ReQ Microsoft MAPS0�]�y(u�W,gؚ�~Ta�c�N7h,g0AlwaysPromptSendSafeSamples	NeverSendSendAllSamples�y(u���y!j_0c��nAQ��`O/T(ub�y(u��:g��n��R�vkb�c_�Y�e�T��R�v�[hQ�`�b�f�e_�Y�e�0dk��n(u�NRM�kb�c�[D��n�vq_�T0�O�Y��[�S�N(WqQ�N;N:g�veg�[Z��b:g-NO(u��N2�bkY*Neg�[Z��b:gT�egbL�'Yϑ`S(u�x�v�v�d\O0WO(udk��n��S�N�N\�e:NUSMOM�n��^hV��:gS0��:g�:N [1 - 23] \�e0	gsQ��:gHe�g�v��~�Oo`����h�g RandomizeScheduleTaskTimes ��n0�y(uL�:N�vƉ0�y(u IOAV �O�b0�y(u�[�e�vƉ0�y(u�,gkb�c0�y(uX[chkb�c0C�y(u�f�e�[hQkb�c0�f�ekb�c/fc1u�N�Ǐ�N��R�v�[gkb�c�/T�R�vkb�c0�8^�ُ�N��R�vkb�c/f1u�N���{:g(W��R�v�e�Y�NsQ핶r`��Ǐ�v0C�y(u�f�e�_�kb�c0�f�ekb�c/fc1u�N�Ǐ�N��R�v�[gkb�c�/T�R�vkb�c0�8^�ُ�N��R�vkb�c/f1u�N���{:g(W��R�v�e�Y�NsQ핶r`��Ǐ�v0PA	�y(u5uP[���Nkb�c0�y(u�S�y�Rq��RhVkb�c0�y(u؏�S�p0�ybk(W�] f\�vQ�~q��RhV
NЏL��[hQkb�c0N�y(ukb�cQ�~�e�N0gbL� IOAV kb�c�Nnx�OT�e�y(uQ�~�e�Nkb�c�e��_{�/T(u  ApplyDisableNetworkScanningToIOAV  ��n0��nx�O �y(ukb�cQ�~�e�N ��n_N�^(u�N IOAV kb�c0/T(u UI ��[!j_0gZ�� ID��hKm0Rُ�NZ���e�
N�^�[vQgbL�؞���d\O0����N ThreatIDDefaultAction_Ids -N ID �v�vTz��^c�[ ThreatIDDefaultAction_Actions -N�v�d\OOZ���v؞���d\O��hKm0Rُ�NZ���e�
N�^�[vQgbL�؞���d\O0����N ThreatIDDefaultAction_Ids ^\'`-Nc�[�v�v�^ ID z��^c�[ُ�N�d\O0
*g�wZ���v؞���d\O0%N͑'`:N NO �vZ���v؞���d\O0%N͑'`:N -NI{ Z���v؞���d\O0%N͑'`:N ؚ �vZ���v؞���d\O0%N͑'`:N %N͑ �vZ���v؞���d\O0c�[ PUA (\o(W
N�S"kΏ�^(uz�^)2��b!j_0�]/T(uPA	AuditMode�y(u ��!kw0R�e;�bk 0M�n�N�O�b�~+R0؞��ؚ+���[�]M�n�^��v�N�h�g�e�0	gHe<P:N 0-50 �y0!M�n Microsoft Defender ;e�Q2��bQ�~�O�b�R��0�[8h!j_M�n�S�c�e�N9Y���CgP��R��0BlockDiskModificationOnlyAuditDiskModificationOnlyc�[;e�Qb��Q\ĉR�v�cd�y�0Qcf;e�Qb��Q\ĉR (ASR) Id0ĉR Id ���N AttackSurfaceReductionRules_Actions ^\'`-Ncf�vT��d\O�vz��^�vT0L;e�Qb��Q\ĉR�ASR	��v؞���d\O0�d\O�_{�N(WAttackSurfaceReductionRules_Ids ^\'`-Nc�[�vT�ĉR ID �vz��^�vT0*gM�nf�JT\AQ���v�^(uz�^�m�R0R"�S�c�e�N9Y���"�R��0\�S�O�b�v�e�N9Y�m�R� �S�c�e�N9Y���CgP� �R��0؞���`�QN�S�S�c�e�N9Y����O�b�v�e�N9YRh�0:NZ��b�s�X-N�v�[hQzf���[IN�e�NqQ�N0+N SharedSignaturesPath Nw�M�n�e��NAQ��9hnc��Rz�^/T(u�f�e0M�n/f&T�^(W��Rkb�cg�O(uNO CPU OHQ�~0/T(ub�y(u�e�N�T^���{�R��0+AQ�� Microsoft Defender 2��u�k�Ǐ	cAmϑ��9��vޏ�cۏL��f�e�T��O0Sdk��n�c6R/f&TAQ��(WWindows Server
N\Q�~�O�bM�n:N;�bkb�[8h!j_0�Y�g:N false�R\�_eu EnableNetworkProtection �v<P0dk��n�c6R(u�NQ�~�O�b�vpenc�bYt09Q�~�O�b�h�gQ�~Amϑ�v^nx�[/fAQ��؏/f;�bkAmϑ�؏/f>f:yf�JT0dk��n�c6RQ�~�O�b/f&T;�bkQ�~Amϑ��
N/f>f:yf�JT0//T(uT��|�~zz�eЏL��v��Rkb�c\
NOP�6R CPU0؞��<P:N 1��Vdk�N\�[zz�kb�c�y(uP�6R0P��n:N TRUE �e��Y�g�|�~(W5u`l�O5uNЏL��RAQ��	c��RۏL��[hQkb�c0؞��<P:N FALSE �e�sS؞���`�QN��Y�g�|�~(W_cOW�v5u�nNЏL��RO�S�m�[hQkb�c0!(u�Nc�[��O(u�v�Nt PAC0ProxyServer OHQ�Ndky�0-(u�Nc:yS_�[7b�z\Ջޏ�c0RQ�~(ۏL�~{
T�f�e�T SpyNet �bJT)�e�^O(u�v�]}T
T�Nt0PA��:NvQ�~Ǐ�Nt
g�RhV�v0W@WRh�0[�Y�g�{tXT^g�Ǐ�Nt:_6R@b	gޏ�c�FO
NAQ���NUO�v�cޏ�c�ُ�NS�b ProxyServer �T ProxyPacUrl�FO
NS�b IESettings �T AutoProxy �hKm0dk��n�y(uQ�~�O�b�v TLS R�g0dk��n�y(uQ�~�O�b�v HTTP R�g0dk��n�y(uQ�~�O�b�v DNS R�g0dk��n�y(uQ�~�O�b�v DNS TCP R�g0dk��n�y(uQ�~�O�b�v SSH R�g0IAQ���{tXT\��YM�n:N�Nyr�[�S� �ring	� �c6e Microsoft Defender s^�S�f�e - AQ���[7b�[�ek�S^Ǐz�b	gN�[�v�c6RCg0Beta Hr,g��ȉ�]�fX[^�l�]�^ߏDAQ���{tXT\��YM�n:N�Nyr�[�S��W	��c6e Microsoft Defender _�d�f�e - AQ���[7b�[�ek�S^Ǐz�b	gN�[�v�c6RCg0FAQ���{tXT\��YM�n:N�Nyr�[�S��c6e Microsoft Defender �[hQ�`�b�f�e(�S�) - AQ���[7b(W�ek�S^Ǐz-NۏL�N�N�c6R0AQ���{tXT	��b��Q_�d0s^�S�T�[hQ�`�b�f�e�v�ek�S^Ǐz0PAPdk��n�c6R/f&TAQ��(W RS3 �v�z�SNB\\Q�~�O�bM�n:N;�bk!j_b�[8h!j_0�Y�g:N false�R\�_eu EnableNetworkProtection �v<P0\dk��n�c6R/f&TAQ��Q�~�O�b(WWindows Server
N/T(upenc�bYt0�Y�g:N false�\�_eu DisableDatagramProcessing �v<P�v^؞��:N�y(upenc�b�h�g0Fdk��n:NQ�~�O�b/T(u DNS �c6ehV�R����[
\͑WW�T�[8h�v EnableNetworkProtection �v<P�(W�h�g!j_N
NgbL��NUO\O0dk��n�y(uQ�~�O�b�veQ�zޏ�c[{	�0dk��n�y(uQ�~�O�b�v RDP R�g0dk��n�y(u�NQ�~�O�b6eƖ�T�S�'`��e�Km0dk��n�Ǐ�O�Nh~{�O�bM�n:_S0N�c6R�cd�y�/f&T�[��Y
N�vh�Q,g0W(u7b�S��0O(uV{eu��n HideExclusionsFromLocalAdmins ��υeg�h�Q(u7b�T�{t,g0W(u7b�v�cd�y�0dk��n�y(uQ�~�O�b�v FTP R�g0dk��n/T(u'`��OS��NAQ��Tek�h�g�vQ�~AmRbc0R_ek�h�g0c�[(WHSYKNTЏL���Rkb�c�vR��pe0Sb_Ee���cd�!j_�e�dk��n\�y(u�{9e2��b0dk��n�y(uQ�~�O�b�v SMTP R�g0dk��n�y(uQ�~�O�b�v QUIC R�g0ُO��nQ�~�O�b�v�O��!j_0DEPRECATED: dk��n(W_�d-N�y(u TDT0PAhc�[;e�Qb��Q\ĉR (ASR) ĉRyr�[�cd� Id0�����n/�m�RĉR Id�v^(W AttackSurfaceReductionRules_RuleSpecificExclusions ^\'`-Nc�[�v�^�v�cd�0kc�[;e�Qb��Q\ĉR (ASR) ĉRyr�[�v�cd�0�����n/�m�RĉRyr�[�cd��v^(W AttackSurfaceReductionRules_RuleSpecificExclusions_Id ^\'`-Nc�[�v�^�v Id0(W��!kЏL�SO�� (OOBE) g�/T(u�[�e�O�b�T~{
T�f�e0!dk��nAQ�� IT �{tXT(WXb�{��Y�v/T(ub�y(u!j_NM�n'`��!j_0�ybkX[�~�b�N�R�[E��f�eX[0�[\�zsSԏ�V0(W�_�kb�cg�kb�c�cd��e�N�T�vU_0ScanRtpExclusions
 Rd�kb�c�~zpe�v
NP�e/T(uT�8h�_
g�R\\PbkO(uՋ���TM�n
g�R(ECS)�_�:N Microsoft Defender 2��u�ko��N�TvQ�N Defender o��N�c�Oyr�[�N�~�~�vsQ.��Oe�z�^0\�~�~�Ǐ�[hQzf���f�e�c�O�Oe�z�^0w/T(uT�8h�_
g�R\\PbkO(u OneDsCollector Fh�g�N Microsoft Defender 2��u�k �TvQ�N Defender o��N6eƖe�Kmpenc0/T(udk��n�S��Oq_�T Microsoft �_�Ƌ+R�T㉳Q���O�Y'`��ba�Tb0/T(u UDP R�kxS}��N�c�OQ�~�O�b/T(u UDP �c6exS}��N�c�OQ�~�O�b��[IN(u�NN}��[hQzf���f�e�v�n�vz��^0dk��nAQ��`O�[IN�^ޏ�c�v
NT�[hQzf���f�e�n�vz��^0dk��n�v<P�^\O:N	cz��^�g>N�[hQzf���f�e�n�v�N�z�~R���vW[&{2N��eQ0�S���v<P:N: "InternalDefinitionUpdateServer"0"MicrosoftUpdateServer"0"MMPC"0"FileShares" $c:y(Wfg�QۏL��[hQ�`�b�f�e0�Y�g��n:N���R�k)Y��OۏL��[hQ�`�b�f�e0I�[INb���f�e~{
TKNMR�v)Ype0�S�NO(u SignatureUpdateLastChecked00 = �e�f�e�1 = 1 )Y�2 = 2 )Y�I{I{0�y(u���y!j_0PA	�y(ueQ�O2��b�|�~04؞���`�QN�dk cmdlet ����_(u7bnx��0�Y�gc�[ -Force�R
NۏL�؞���`�QN@b��v(u7bnx��0c�[/f&T�bJT�R`~{
T"N_�N�N0؞���`�QN�
N�bJTdk{|�N�N0c�[;e�Qb��Q\ĉR�v�cd�y�0:NZ��b�s�X-N�v�[hQzf���f�e�[IN�e�NqQ�N0Microsoft Defender 2��u�k��	�y�{|��w{|+R0ScanStateNotificationsThreatStateNotificationsSignatureStateNotificationsComputerStateNotifications��~�vkb�c��w0
ErrorOccurred
ScanCompleted��~�vZ����w0SuccessfulRemediationPANonCriticalFailure��~�v~{
T��w0SignaturesOutOfDate	��~�v���{:g��w0ScansOutOfDateComponentsChangedStateRecoveredub WMI �N�N�v�eg�T�e�TvQ�Npenc0�vMR�N(W CategoryDiscriminant I{�N ThreatStateNotificationsthen �v�`�QNO(u�dk<P\S+T ThreatIDMicrosoft Defender 2��u�k�N�Nc:y{|ĉR�v/UNhƋ&{(GUID)0��;�bk�v IP 0W@W0;�bk�d\O�v{|�W0
ĉR�v�eT0( O�Q� OeQ)ĉR�vOS��0(TCP0UDP0�NUO),g0W�z�S�v��V0܏z�z�S�v��V05�^P_q[D�Start time of the rule, when it was first created-D�1U`�d�End time of the rule, when it will expire7`�1Uc�OUnique identifier (GUID) of the rule to be removed.>c�c�Hs1UMicrosoft Defender Behevioral Network Blocking Rules ClassPA%1!s! ck(Wkb�c`O�v��Yُ�S�����N�N�e��wQSO�S�Q�N@b	��vkb�c{|�W0kb�c�]b�R�[b0\Ջkb�c`O�v��Y�eG�0R��0ꁚ[INkb�c�[hQkb�c�_�kb�c%1!s! %2!s!
ck(W�f�e�u�k�T�
�o��N�[IN!%1!s! �SꁨR�f�e`O�v�u�k�T�
�o��N�[IN��N.^�R�O�b`O�v��Y0PA�u�k�T�
�o��N�[IN�f�e�]b�R�[b0�u�k�T�
�o��N�[IN�f�e�]�[b�FO�Q�s��0	�u�k�T�
�o��N�[IN�d\O1Y%���Q�s�NN��: 0x%1!x!ЏL�ꁚ[INkb�c�e��� ScanPath �Spe0dk��Y
N�](WgbL�kb�c0dk��Y
N�](WgbL��u�k�T�
�o��N�[IN�f�e0�](Wnd��hKm0R�v�S��	g�[�vy��v0`O�v��Y
NS_MR�l	g�NUO�]�hKm0R�v;m�Ry��v�S�Ond�0\Ջnd��]�hKm:N�S��	g�[�vy��v�eG�0R��0D�^:N�k*N ThreatIDDefaultAction_Ids �Spec�[ ThreatIDDefaultAction_Actions <P0�e�l���SZ�� ID �v؞���d\O0��: 0x%1!x!)�d\O1Y%���Q�s�NN��: 0x%1!x!0�d\O: %2!s!0�vh: %3!s!0`O�vCgP�
N����e�lgbL���Bl�v�d\O0\Ջ(W`O�v��Y
NЏL� WDO kb�c�eG�0R��0dk��Y
N�](WgbL�kb�c0�����D%2 WMI �c�Oz�^�[�O�h"}�e�l-NX[(W�� %10%0

@%2 WMI �c�Oz�^Y�`�e�l-NX[(W�� %10%0

P%2 WMI �c�Oz�^ FireEvent �e�l-NX[(W�� %10%0

x\Ջ�N@b	g;m�R�v���{:gO݋�l�Q %2 WMI �c�Oz�^��w�e�Q�s�� %10�SO6e0Reg�S_MRO݋�v��w0%0

P\Ջ:N %2 WMI �c�Oz�^R�^�N�N�vƉ�~z�e�Q�s�� %10%0

T\Ջ:N�vƉ�Sv`ao��N��w�l�Q %2 WMI �c�Oz�^�e�Q�s�� %10%0

H4VS_VERSION_INFO���e�e?�StringFileInfo�080404B0LCompanyNameMicrosoft CorporationHFileDescription�O�b�{t WMIv2 �c�Oz�^JInternalNameProtectionManagement�.LegalCopyright� Microsoft Corporation. All rights reserved.bOriginalFilenameProtectionManagement.dll.muij%ProductNameMicrosoft� Windows� Operating System�8FileVersion4.18.26040.7 (8d846dd50fd7adca65beb1b013a5fda76a9ec807)>
ProductVersion4.18.26040.7l&PrivateBuildGitEnlistment(ContainerAdministrator)DVarFileInfo$Translation�PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD�%0�%�	*�H��
��%�0�%�10
	`�He0\
+�7�N0L0
+�70	���010
	`�He 2F���v@UWP��U����+:u$�d��
�0�	0��3A��˭)O0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20110
250619181143Z
260617181143Z0p10	UUS10U
Washington10URedmond10U
Microsoft Corporation10UMicrosoft Windows0�"0
	*�H��
�0�
��y���K1�C�*$"�W%W�H��(v|3}�_0�sȔ��ɫO�}k�WS(�"�����@�C�p�6o��
w ,lc��(
���T-^����䐧�͍��ӑd��Χ�������1p�8��d�������k
�w�D�wB');j��@�&��r�zv;$�0�����c�J���,�?7H��o���.-��)��r<�
�q��S$j|��A]�G_�Z���೉�n����-���s
����2����0��0U%0
+�7
+0U�xԏ���~.I��Ԡ�|�@�0TUM0K�I0G1-0+U$Microsoft Ireland Operations Limited10U
229879+5053360U#0��)9�ėx͐��O��|U�S0WUP0N0L�J�H�Fhttp://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl%200a+U0S0Q+0�Ehttp://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0U�00
	*�H��
�;ܴ�W6��K26KV�j> b�j}��BE>��Ұ=Y�'��*���_�u��Y�V��u{Y��2Bon�%�ęW�eW�>Z�I̎��#M,����Nⷅ�&8T�E�⇃������bw�폥i�R�O���"{KN���x�="t��a�w�H+GB�����S���8�#X��q�:Ӏ�g�ړ�jp*;�mH�I���-�NQ�;yOك��9��f��ڨ�l��V���X��/�1t1�3���
x��	0��0���
avV0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100
111019184142Z
261019185142Z0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20110�"0
	*�H��
�0�
�����.	����i�!�i33��T����� ��ҋ�8����-|by��J?5 p���k�6u�1ݍp��7�tF�([�`#,��G�g�Q'�r��ɹ;S5|���'�����#	o�F��n�<A�ˣ?]jM�i%(\6��C
��������['�'x0�[*	k"�S`,�hS��I�a��h	sD]}�T+�y��5]l+\μ�#�on�&�6�O�'��2;A�,���w�TN�\�e�C���mw�Z$�H��C0�?0	+�70U�)9�ėx͐��O��|U�S0	+�7
SubCA0U�0U�0�0U#0��Vˏ�\bh�=��[�Κ�0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
	*�H��
��|qQ�y�n��9>�<Rn+?s��h�H�4M��&�1F�ay�8.Ek��(�����	��L
6fj���������@26v�Zƿ���Ӭ�h�b��TlP0X��|���N���|�sW�R!s4Z�V��	����~�����?�rS��c��=1e�������=����BА�_T���G�o�sNA�@�_�*��s�!(���s9_>�\`����	���Q�fG���=�*hw��Lb{��Ǻz�4Kbz����J7�-�W|�=ܸZ��ij�:��n�i!7ށ�ugӓW^)9��-���Es[���z��FX�^���g�l5��?$�5�
u�V��x,��Ј���ߺ~,c��#!�xl�X6+�̤��-����@�E�Ί\k>��p*
j�_G��c
2��6*pZ�BYqKW�~���!<��Ź���E��� ����ŕ�]b֠c �uw}=�E�����W�o3��w�bY~1�*0�&0��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20113A��˭)O0
	`�He���0	*�H��
	1
+�70
+�710
+�70/	*�H��
	1" ��,K��k)�_�@
���u���ZH��Ow0B
+�71402��Microsoft��http://www.microsoft.com0
	*�H��
�U�F����1��L�F۟��}��g�K��2�ab���Fp�T<>v��#�a������6�1d�w&D�I����2>11��m���ܛ�\� >�Yj��$�AG;������Z��I��Ie�,Ji��Ђ��;,���+8��e����忄2�T��i��d�U�y,�1�����خv��&$x��l7��;�3��,�v�d>9Ao/�~�,�k��7��w�W$1g���j=��ϳԶ��!B����`}h���0��
+�71��0��	*�H��
���0��10
	`�He0�Z*�H��
	��I�E0�A
+�Y
010
	`�He �:�ow<�\Tk��2Vm�qX`J��q*I�i�L�Ȍ20260425005136.573Z0��٤��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1-0+U$Microsoft Ireland Operations Limited1'0%UnShield TSS ESN:6B05-05E0-D9471%0#UMicrosoft Time-Stamp Service���0�(0��3E9�C�l0
	*�H��
0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100
250814184813Z
261113184813Z0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1-0+U$Microsoft Ireland Operations Limited1'0%UnShield TSS ESN:6B05-05E0-D9471%0#UMicrosoft Time-Stamp Service0�"0
	*�H��
�0�
�Ϲ�3/�Zʹ;��(�i�7�d�p����Hq��w�J�����v��n�3���IF�UZ�h����$.�6�
7u�Uп���&�υ2������ڧ�MS�8����T��\��g_���O��R�����ϓV�,ga\��Ei���}��KQ^�&���K<��=\�G3��e�a�|v�:a�T�*7�a3��M�\͖���?��?)j�5��v��e�TءB�����u���e9�qj��tN&����c�$Y���r!A"�a�M�s�?�ɴ���A@�q�K$xE!���[�Z��w�v�*�����D��2�
;`5$��}Bso�nj�?O��:�0v�bMɥ*V�C�i������[�h��P��a�T�U~�x���0�	3�gD��<�Dž!��4��:�ʜ�}�m��(q^�Z��<b�J̾�vJ�:����Y|C�	׾>{*�ʖ=>�"b..@`�U��x��/�`��s�Mk���I0�E0Ub}E���!��o���]f~�p0U#0���]^b]����e�S5�r0_UX0V0T�R�P�Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l+`0^0\+0�Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0U�00U%�0
+0U��0
	*�H��
��B��Lj!H��g����ͅ)3�i�v5K�f��sw\��H�}��"�{���:�}
�R�爮ÛF���l+N���-��D����4�z������wY0˚����ӦUkp�x#�I��ٮ
l+ײg��\���l�TX7�bw���?r�2���8��;���Ϛ0�W�M�TUl�2��i��S���@�1��v�7f���I�<�$�v^�/�����VԵ���n���@���#kÄk_q�xw�[�x�����b��;��:m9�^,�?1��/���%�Ӆ�G���9�gu�J��x6��Hg`%<�i�rgrӍ���D@���������rm3�n���GT�'9�X��f�dU���8@���%p#ay�/�&G��^����/�Rr
�f�u��b��
g���$�R�CÄ��ܻ�����V�+�KE1r�ߞJ�F~??Fː�b
��io������ɶB
O�1�K��o=0UɍJ�T3Lk]��a�U^&0�q0�Y�3��k��I�0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100
210930182225Z
300930183225Z0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100�"0
	*�H��
�0�
���L�r!y���$y�Ղ��ҩlNu��5W�lJ�⽹>`3�\O�f��SqZ�~JZ��6g�F#���w2��`}jR�D���Fk��v��P�D�q\Q17�
8n����&S|9azĪ�ri����6�5&dژ;�{3��[~��R���b%�j�]�S���VM�ݼ��㑏�9,Q��pi
�6-p�1�5(�㴇$��ɏ~�T��U�mh;�F��z)7���E�Fn�2��0\O,�b�͹⍈䖬J��q�[g`���=� �s}A�Fu��_4���� }~�ٞE߶r/�}_��۪~6�6L�+n�Q���s�M7t�4���G��|?Lۯ^����s=CN�39L��Bh.�QF�ѽjZas�g�^�(v�3rק ��
�co�6d�[���!]_0t���عP��a�65�G������k�\RQ]�%��Pzl�r�Rą��<�7�?x�E���^ڏ�riƮ{��>j�.����0��0	+�70#	+�7*�R�dĚ���<F5)��/�0U��]^b]����e�S5�r0\U U0S0Q+�7L�}0A0?+3http://www.microsoft.com/pkiops/Docs/Repository.htm0U%0
+0	+�7
SubCA0U�0U�0�0U#0��Vˏ�\bh�=��[�Κ�0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
	*�H��
��U}�*��,g1$[�rK��o�\�>NGdx���=13�9��q6?�dl|�u9m�1��lѡ�"��fg:SMݘ��x�6.���V����i�	�{�jo�)�n�?Hu��m��m#T�xSu$W�ݟ�=��h�e��V����(U'�$�@���]='�@�8���)�ü�T�B�������j�BRu�6��as.,k{n?,	x鑲�[�I�t�쑀�=�J>f;O���2ٖ����t��Lro�u0�4�z�P�
X�@<�Tm�ctH,�NG-�q�d�$�smʎ	��WITd�s�[D�Z�k
��(�g($�8K�n�!TkjEG����^O���Lv�WT	�iD~|�als�
��Af=i��AI~~���;����>�1Q������{��p���(��6ںL���
�4�$5g+�
�挙��"��'B=%��tt[jў>�~�13}���{�8pDѐ�ȫ:�:b�pcSM��m��qj�U3X��pf�V0�>0���٤��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1-0+U$Microsoft Ireland Operations Limited1'0%UnShield TSS ESN:6B05-05E0-D9471%0#UMicrosoft Time-Stamp Service�#
0++*|�e]�
�Ti3w��^�5͠��0���~0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100
	*�H��
�t*0"20260424225850Z20260425225850Z0t0:
+�Y
1,0*0
�t*0�0�0
�Ū06
+�Y
1(0&0
+�Y
�
0� �
0��0
	*�H��
��* 9��r17���h|�aэ�*�����gp�@�8e��iS[{�t��ZR`���5�J�j�N3J}ZU�"j^�\1@���şEY��*�a�osb�8��+t,J�$Ӷ*�X帼H>88���B��Εx~�$�0Ў5�2�й3fiGyL�y��^�k�ok�$��l��G����!�[�\��QFނ�}��ֿ(:����,YT2=Iz���D���>D'�9ܝc��fa[���*�,1�
0�	0��0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20103E9�C�l0
	`�He��J0	*�H��
	1
*�H��
	0/	*�H��
	1" �x�]�m@���GJ�?>R@�o�
��+�Lv0��*�H��
	/1��0��0��0�� ,�3���N�Z\\/���P#ME�9b�43&�0��0���~0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20103E9�C�l0" E.QYKsJ��懭>[P� �T�eKTN��0
	*�H��
�<�: SP�ul�����\;�{�)���>�r��A��<�.4=�Y�E;o}K0���O��C��?[̾҆�:~FZ�O�PW%�凬�&H�rr	y�kN���JhF��G8�^����~Q�F��E��T��%�%��z���>H��"�
1�w��u��Wzz|��d���{M�#���E]�u"�i�_Թ��K�����Ɲ0�
��q���C�
ɋDp�f�����Eq�v
Ʌ� �#NV��Q+�d���Dž�MIM���<c��l���7lq�.��^n�l\(p���kN�똤�Hq�_I�ů�}���f�в��l�t�z�^-%�T0U��iz��#�o̷��@�,���WS]��>_��. Y��hR�\4nX��3�,���h"@f$0d(�x-|$[����_c�[�2��8���cՋ3>��k�
�Z�+y�B!�Pu��_e��&��|�hM�G���-���b��r�w��Z��4���

Youez - 2016 - github.com/yon3zu
LinuXploit