403Webshell
Server IP : 209.209.40.120  /  Your IP : 216.73.217.112
Web Server : Microsoft-IIS/10.0
System : Windows NT NEWWWW 10.0 build 17763 (Windows Server 2019) i586
User : NEWWWW$ ( 0)
PHP Version : 8.3.30
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /ProgramData/Microsoft/Windows Defender/Platform/4.18.26040.7-0/zh-TW/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /ProgramData/Microsoft/Windows Defender/Platform/4.18.26040.7-0/zh-TW/ProtectionManagement.dll.mui
MZ����@���	�!�L�!This program cannot be run in DOS mode.

$=;=�yZS�yZS�yZS��Ӭ�xZS���Q�xZS�RichyZS�PEd��6X�" ,�����` �|��%8.rdata�@@.rsrc� ~@@�6X
lPP�6X$����8.rdata8.rdata$voltmdP�.rdata$zzzdbg �.rsrc$01�&��.rsrc$02 s_`^�:�d��\?X�ƥ�]�ȅ+ӝS�6X��0�H�H�`�x������������ �8�	P�
h�����
���������(�@�X�p������������� 0�!H�`�x�������� 0@P`p�������� 0@P`p���&��`'�`)�d,��X0��4���;���A���C��E�G\�xH"��K��L ��M���Qh��S���Y\
��fB�$mh��pr�t�w���{�����d���`�����|�x���X��t���p����h�MUI���x6[w��T���?��p���v��NmuB�}���MUIzh-TW�/fo�:y�Wy�rKa�v�ba�^�%R01u MAPS �^�z�v��f�X�%R�x�vMR�v��f��rKa
CleanStatePendingFullScan
PendingRebootPendingManualStepsPendingOfflineScanCriticalFailure
c�Q/f&T���\݈n͑�e��_jDefender �vMR�v"u�T�rKaNoStatusServiceNotRunning,ServiceStartedWithoutMalwareProtectionEngineEndingManualStepsAVSignaturesOutOfDateASSignaturesOutOfDateNoRecentQuickScanNoRecentFullScanSystemInitiatedScanInProgressSystemInitiatedCleanInProgressSamplesPendingSubmissionRunningInEvaluationModeRunningInNonGenuineWindowsModeProductExpiredOfflineScanRequired$ServiceShuttingDownForSystemShutdownRemediationFailedCriticallyRemediationFailedNonCriticallyNoStatusFlagsSetPlatformOutOfDatePlatformUpdateInProgressPlatformAlmostOutdated+SignatureOrPlatformEndOfLifePastOrImpending-WindowsSModeSignaturesInUseOnNonWin10SInstallDefender �WL�!j_ (N,�0���R0sxs ���R)"u�THr,g (;N���!k���D}�^��O�)
g�RHr,g (;N���!k���D}�^��O�)�Y�g Defender AS b AV =|�z�]N�g�S��܊�R��yr�_�xHr,g (;N���!k���D}�^��O�)-�S��܊�R��yr�_�x�vX[Yug ()Y) - �Y�gyr�_�x�_*g�f�eN��X[Yug\o�:y�p 65535 )Y"�S��܊�R��
N!k�f�e�v,g0WBf��0�Y�gdkBf���_*g�f�eN��dkl\'`\o�:yzz<P2��kyr�_�xHr,g (;N���!k���D}�^��O�)*2��kyr�_�x�vX[Yug ()Y) - �Y�gyr�_�x�_*g�f�eN��X[Yug\o�:y�p 65535 )Y"2��k
N!k�f�e�v,g0WBf�� - �Y�gdkBf���_*g�f�eN��dkl\'`\o�:y�pzz<PNRI yr�_�xHr,g (;N���!k���D}�^��O�),NRI yr�_�x�vX[Yug ()Y) - �Y�gyr�_�x�_*g�f�eN��X[Yug\o�:y�p 65535 )Y$NRI 
N!k�f�e�v,g0WBf�� - �Y�gdkBf���_*g�f�eN��dkl\'`\o�:y�pzz<P"
N!k�[te�c�c���Y�vBf�� - �Y�gdkBf���_*g�f�eN��dkl\'`\o�:y�pzz<P"
N!k�[te�c�cP}_g�vBf�� - �Y�gdkBf���_*g�f�eN��dkl\'`\o�:y�pzz<PcLast full scan age in days- if signatures have never been updated you will see an age of 65535 daysLast scan sourceUnknownUser�|q}	Real-timeIOAV;Signature version used for the last full scan of the device>If no full scan has successfully completed in the last 14 days-Indicates if a Defender full scan is required$Real-time scan direction enumerationBothIncomingPA	OutcomingdTime of last Quick Scan start - If this has never updated you will see a null value in this propertybTime of last Quick Scan end - If this has never updated you will see a null value in this propertyeLast quick scan age in days- if signatures have never been updated you will see an age of 65535 days.<Signature version used for the last quick scan of the device?If no quick scan has successfully completed in the last 14 days5The AM Engine version (major, minor, build, revision)If the AM Engine is enabledWSpecifies whether the computer is monitoring file and program activity on your computer)Scan all downloaded files and attachments0Specifies whether behavior monitoring is enabled1Specifies whether Antivirus protection is enabled3Specifies whether Antispyware protection is enabled2Specifies whether the machine is a virtual machine6Specifies whether the machine has tamper protection onkSpecifies the last entity that changed the TamperProtection state e.g., UI, Signatures, Intune, ATP, etc...1Specifies whether real-time protection is enabled2NRI Engine version (major, minor, build, revision)If the NRI Engine is enabled+Indicates the current Device Control state.@Indicates the current Device Control DefaultEnforcement policy. \Timestamp indicating when the last configuration update occured for device control policies.Troubleshooting (TS) mode state-Troubleshooting (TS) current state start time+Troubleshooting (TS) current state end time.Troubleshooting (TS) remaining time in minutes/Troubleshooting (TS) remaining quota in minutes%Troubleshooting (TS) quota reset time-Troubleshooting (TS) maximum quota in minutes Troubleshooting (TS) mode source)Smart App Control (SAC) mode: On/Eval/Off1Smart App Control (SAC) eval mode expiration time Defender initialization progress>Indicates the state of Controlled Configuration on this deviceP}�i�c�Hr,g/UNuP,nX�%R�xZ��v
T1z�V͑'`X�%R�x - R	�NO-N�^ؚ�V͑
^�%RX�%R�x - R	�INVALIDADWARESPYWAREPASSWORDSTEALERTROJANDOWNLOADERWORMBACKDOORREMOTEACCESSTROJANTROJANEMAILFLOODER	KEYLOGGERDIALERMONITORINGSOFTWAREBROWSERMODIFIERCOOKIE
BROWSERPLUGIN
AOLEXPLOITNUKERSECURITYDISABLERJOKEPROGRAMHOSTILEACTIVEXCONTROLSOFTWAREBUNDLERSTEALTHNOTIFIERSETTINGSMODIFIERTOOLBARREMOTECONTROLSOFTWARE	TROJANFTPPOTENTIALUNWANTEDSOFTWARE
ICQEXPLOITTROJANTELNETFILESHARINGPROGRAMMALWARE_CREATION_TOOLREMOTE_CONTROL_SOFTWARETOOLTROJAN_DENIALOFSERVICETROJAN_DROPPERTROJAN_MASSMAILERPATROJAN_MONITORINGSOFTWARETROJAN_PROXYSERVERVIRUSKNOWNUNKNOWNSPPBEHAVIOR
VULNERABILTIYPOLICYType ID - Enumeration	Known BadBehavior
Known GoodNRIZ�MzX[�rKaThreatCleanRebootRequiredManualStepsRequiredFullScanRequiredReinfectionLoopExecuted(List of resources affected by the threat Specifies if threat has executed!Specifies if the threat is activeVThis is a singleton that represents the Microsoft Antimalware service infection status7This class represents the catalog of recognized threatsUnique Threat ID	�vܕ�vU�tz�^
T1z��Bl܈Qe�vO(u�uP,n�O�n^��WX�%R�x - R	�ELAMLocalAttestationPARemoteAttestation
�SuP,nq_���vnj�nn�U
��!kuP,n0RZ��vBf��Z��rKa���f�vgяBf��܈Qe�vBf��0�WL��rKaX�%R�x - R	��]\��AQ1�ck(W�WL�NotExecutingZ��rKaX�%R�x - R	��]uP,n�]nd�����]�yd�CleanFailedPAQuarantineFailedRemoveFailedAllowFailed�]>e�h
BlockedFailedZ��rKa/����x	nd��R\O - R	�nd�����yd�AQ1�UserDefinedNoAction\��
c�Qnd��R\O/f&Tb�R�_��WL�M�Y�R\O�N�[b܈Qe - R	�!qFullScanAndRebootRequiredFullScanAndManualStepsRequiredRebootAndManualStepsRequired'FullScanAndRebootAndManualStepsRequiredFullScanAndOfflineScanRequiredRebootAndOfflineScanRequired'FullScanAndRebootAndOfflineScanRequired!ManualStepsAndOfflineScanRequired,FullScanAndManualStepsAndOfflineScanRequired*RebootAndManualStepsAndOfflineScanRequired5FullScanAndRebootAndManualStepsAndOfflineScanRequireddk^�%Rh�:y�vMRs�0}�vZ��rKa1.0Microsoft Defender 2��kߎԚ�c�c^�%RMicrosoft Defender 2��kߎԚ=|�z^�%RPA Microsoft Defender 2��kߎԚ WDO �c�c^�%RMicrosoft Defender 2��kߎԚ�_�^�%R%AQ1��|q}�{t�Tc�[/f&T�ar�ܕ�� Server SKU �v0��R�cd�
0�R��0AQ1��|q}�{t�Tf�x\P(u�j�g@b	gR�Q_�v�c�c0AQ1��|q}�{t�Tf�x\P(u�j�g@b	gR�QoR�j
T�v�c�c0AQ1��|q}�{t�Tf�x\P(u�j�g@b	gR�QU�tz�^�v�c�c0'AQ1��{t�Tf�x\P(u wdnisdrv 
\yr�[ IP MO@WD}2�L��v�}�\S�j�g0#c�Q��v�a�OYu(W [���] nj�e>Y�v)Yxe��}N�dkBf��KN�_sSg�N�N�yd�0sSBf�c�c�eT - R	�c�Q��(Wfg~^�WL��c�[�v�[te�c�c�N�[b܈Qe0�k)Yfg�efgNfg�Nfg	Nfg�Vfg�NfgmQ8l
NOIndicates what time to perform the scheduled full scan to complete remediation.9Configure the state of Remote Encryption Protection(REP).
NotConfigured=z8hܕ��rTime in minutes for which Remote Encryption Protection(REP) will block threats. 0 results in no limit enforcement.XIndicates how aggressively Remote Encryption Protection(REP) will block detected threat.MediumTSpecify the IP address and subnet exclusions from Remote Encryption Protection(REP).-��[�f�R4x�2�w� (BFP) �v�rKa0lTime in minutes for which Brute Force Prevention(BFP) will block threats. 0 results in no limit enforcement.RIndicates how aggressively Brute Force Prevention(BFP) will block detected threat.�_�f�R4x�2�w� (BFP) c�[���cd��v IP MO@W�TP[�}�0PA`Brute Force Prevention(BFP) Plugin - extend Brute Force coverage to block IPs on local networks.�Brute Force Prevention(BFP) Plugin - disables Brute Force Protection's initial 2 week learning period and starts blocking threats immediately.=Configure timeout for detections requiring additional action.zTime in minutes for a detection in the 'critically failed' state to move to either 'additional action' or 'cleared' state.UTime in minutes for a detection in the 'failed' state to move to the 'cleared' state.OSpecifies the interval that will be used for service health report, in minutes.fSpecify whether to report a Dynamic Signature dropped event. By default, such events are not reported.OSpecify the maximum percentage of CPU utilization during a scan. This policy setting allows you to configure the maximum percentage CPU utilization permitted during a scan. Valid values for this setting are a percentage represented by the integers 5 to 100. A value of 0 indicates that there should be no throttling of CPU utilization.
When set, Microsoft Defender Antivirus will check for new signatures before running a scan.  If new signatures are found they will be downloaded and installed before the scan begins.  If no new signatures are found, the scan will start based on the existing signatures.CTurn on removal of items from scan history folder. This setting defines the number of days items should be kept in the scan history folder before being permanently removed. The value represents the number of days to keep items in the folder. If set to zero, items will be kept forever and will not be automatically removed.�P(W�|q}U��e��n�rKaBf�Mb�WL��]�cz�v�c�c0c�[�c�[�v�c�c@bO(u�v�c�c^��W0�_��c�c�[te�c�c
c�[fg~^�WL��c�[�v�c�c0c�[N)Yvu-N���WL��]�c�[KN�_��c�c�vBf��0
c�[�WL��c�[KN�c�c�vBf��06CPU O(u�sP�6R�S�PWY(u�e�cz�c�c�bWY(u�e�czN���v�c�c0�-�<P�S
\�cz�c�cWY(u CPU O(u�s
NP�0(W��!k�[݈�_-��[�vBf��gQ�N�_-Nbk
g�Rw��Y�v@b	g�f�e0K���[ CheckForSignatureBeforeRunningScan0�Y�gyr�_�x(WdkBf��gQ�)R�f�e�GR-Nbk
g�Rw��Y�v@b	g�f�e0Bf���NR��p�UMO0��[�(u�eN	��[hQ'`�`1X�f�e�v�jHhqQ(u0dk-��[�S���`c�[ UNC �jHhqQ(u�O�n��NX[>eN	��v�[hQ'`�`1X�f�e0\�Nc�[�v��^#��}0R�f�e�O�n0�`�_�O(u�N�{�}R���vW[2Nb__c�[dk-��[�v<P��OR	��[hQ'`�`1X�f�e�O�n0�O�Y: {\unc1 | \unc2 }0dkn�U�-�/fzz�v0'�-��[�p True�!q֊/f&T	g_�d�AM 
g�R��
Ng(W_U�RBfw��Y�[hQ�`1X�f�e0��[�N	��[hQ'`�`1X�f�e�v�O�n��^0dk-��[�S���`c�[#��}0R
NT�[hQ'`�`1X�f�e�O�nBf��O(u�v��^0�`�_�O(u�N�{�}R���vW[2Nb__c�[dk-��[�v<P��O�O�^R	��[hQ'`�`1X�f�e�O�n0�S���v<P/f: 'InternalDefinitionUpdateServer'  'MicrosoftUpdateServer'  'MMPC'  'FileShares' &c�Q��(Wfg~^�f�e�[hQ�`1X0�-��[�p�� (0x0)�h�:y���k)Y�f�e�[hQ�`1X0-c�[�a�WL��[hQ�`1X�f�e�j�g�vBf��09h�d�-��g(W�WL��c�[�v�c�cKNMR�j�g/f&T	g�[hQ�`1X�f�e0M�[��_���܈yr�_�x�v)Yxe0-dM� SignatureUpdateLastChecked O(u00 = 
N��܈; 1 = 1 )Y; 2 = 2 )Y��Odk^��c04Bf��<P/f�N�f�e�j�g���� (\Bf) h�:y0	gHe�v<P�N�e 1 (�k\BfN!k) 0R 24 (�k)YN!k) KN��0UNC =|�z blob �}�qQ(uMOn0c�[(u�O�j�g=|�z�v���� (R�)0�ReQ Microsoft MAPS0�]\P(u�W,gPA2���Ta#j,g�c�N0AlwaysPromptSendSafeSamples	NeverSendSendAllSamples\P(u���y
k!j_0f�P-��[�S���`_U(ub\P(u��_j�c�[�c�c�T�[hQ�`1X�f�e�v���YBf��0�P-��[�S(u�ORce�c�c
\nj�n�vq_��0�O�Y��`�S�N(WqQ(u;N_j�vY萢[Ԛ[��d_jhV-NO(u��-��[��N�MQY萢[Ԛ[��d_jhVTBf�WL�'YϑX[�S�x�x�v�d\O0W�P-��[AQ1�`O�N\Bf�p�UMO-��[�cz��_jS0��_jS�����p[1 - 23]\Bf0�Y��fYܕ�e��_jSHe�a�vnj
��ˊ�gw RandomizeScheduleTaskTimes -��[0\P(uL��p�v��0\P(u IOAV �Ow�0\P(usSBf�v��0\P(uc�N�x�c�c0\P(u\X[�c�c0>\P(u��܈�[te�c�c0��܈�c�c/fN.z�V�p/�N��]�c�[�v�[g�c�c��WL��v�c�c0/�N��]�c�[�v�c�c�v�S�V�8^/f��f�(W�c�[�vBf��&N*g��_j0>\P(u��܈�_��c�c0��܈�c�c/fN.z�V�p/�N��]�c�[�v�[g�c�c��WL��v�c�c0/�N��]�c�[�v�c�c�v�S�V�8^/f��f�(W�c�[�vBf��&N*g��_j0	\P(u��P[���N�c�c0\P(u�b�S_�x�x_j�c�c0\P(u���Sޞ0\P(u(W#��}�v�}�x�x_j
N�WL��[te�c�c0Mܕ���c�c�}jHh0�WL� IOAV �c�cBf��_�_U(u0ApplyDisableNetworkScanningToIOAV
0-��[��N�x�O�}jHh�c�c_N���y(u0�x�O_N\ [\P(u�c�c�}jHh] -��[WY(u� IOAV �c�c0_U(u UI ���[!j_0buP,n0RZ�Bf
N(WvQ
N�WL��-��R\O�vZ�X�%R�x0ThreatIDDefaultAction_Actions -N�v�R\O��^�_�� ThreatIDDefaultAction_Ids -N�vX�%R�x��^�vTKuP,n0RZ�Bf
N(WvQ
N�WL��-��R\O�v�-��R\O0��N�R\O�v��^�_�� ThreatIDDefaultAction_Ids l\'`-Nc�[�v
\�aX�%R�x��^�vT0

NfZ��v�-��R\O0
NO�^�V͑'`Z��v�-��R\O0
-N�^�V͑'`Z��v�-��R\O0
ؚ�^�V͑'`Z��v�-��R\O0
�V͑�V͑'`Z��v�-��R\O0c�[ PUA ([o(W�v�W>W�a(uz_) �Ow�!j_0�]_U(uPA	AuditMode\P(u,{N!kw��Bf\���v�R��0	-��[��z�Ow�d\}0�-�ؚ+���[/�-��[�^w���z�j�g0	gHe<P 0-50 �y0#-��[ Microsoft Defender �`a�c"}2�w��}��Ow��R��0=z8h!j_-��[ [�S�cnj�e>YX[�S
k] �R��0BlockDiskModificationOnlyAuditDiskModificationOnly-c�[ Attack Surface Reduction Rules(ASR) �v�cd���v0Uc�[0�S;e�db�.~\��GR
0(ASR) X�%R�x0��GRX�%R�x�v��^�_�� AttackSurfaceReductionRules_Actions l\'`@bc�[�v
\�a�R\O��^�vT0M;e�db�.~n��GR (ASR) �v�-��R\O0�R\O�v��^�_��T(W AttackSurfaceReductionRules_Ids l\'`-Nc�[�vT��GRX�%R�x�vT0\*g-��[f�JT\AQ1��v�a(uz_�e�X� [�S�cnj�e>YX[�S
k] �R��0\�S�Ow��vnj�e>Y�e�X� [�S�cnj�e>YX[�S
k] �R��0�-����S�cnj�e>YX[�S�Ow��vnj�e>Yn�U0�[�[��d�t�X-N�O�[hQ�`1XO(u�v�jHhqQ(u0+� SharedSignaturesPath Nw�-��[Bf��S���`�P9h�d�czhV_U(u�f�e0-��[�cz�c�cBf/f&T�ar�O(uNO CPU *QHQ
k0_U(ub\P(u�jHhܖJn��{�R��0(AQ1� Microsoft Defender 2��kߎԚ�N��ϑ�N��#��}�f�e�S�
�0Odk-��[�c6R�}��Ow�/f&TAQ1�(W Windows Server 
N-��[�p\��b=z8h!j_0傺p/����EnableNetworkProtection �v�P<P\���_eu0�P-��[�c6R�}��Ow��vnj�eSU�t09�}��Ow�g�j�g�}�Amϑ�&N$R�e�[/f&TAQ1�b\��Amϑbo�:yf�JT0dk-��[g�c6R�}��Ow�g\���}�Amϑ��
N/fo�:yf�JT06_U(uBf��|q}��nBf@b�WL��]�c�[�v�c�c
Ng
\ CPU 2�L��{AmU�t0�-�<P�p 1��Vdk��n�c�c�N6qg\P(u�{Am0Jvu-��[�p TRUE Bf��Y�g�|q}O(u��`l���R�WL��GRAQ1�|~�~�]�cz�v�[te�c�c0�-�<P�p FALSE�sS�Y�g�|q}O(u��`l���R�WL���-�g�S�m�[te�c�c0'(u�Oc�[��O(u�v poxy pac0ProxyServer �v*QHQ��^ؚ�edk02(u�Oc�Q(u6b�zVf�#��c�}�Bf�ar�O(u�v�]}T
T Proxy ((u�e=|�z�f�e�T SpyNet 1XJT)0PAeuN� Proxy :O
ghV�vMO@Wn�U0a�Y�g�|q}�{t�T�`���N� Proxy 7_6R@b	g#��}�N
NAQ1��NUO�v�c#��}0��PS+T ProxyServer �T ProxyPacUrl0
NS+T IESettings �T AutoProxy uP,n0�P-��[g\P(u�}��Ow��v TLS VR�g0�P-��[g\P(u�}��Ow��v HTTP VR�g0�P-��[g\P(u�}��Ow��v DNS VR�g0�P-��[g\P(u�}��Ow��v DNS TCP VR�g0�P-��[g\P(u�}��Ow��v SSH VR�g0HAQ1��|q}�{t�T-��[݈n��N�_yr�[�S� (�S�) �c6e Microsoft Defender s^�S�f�e - AQ1��[6b
\8o2�_|vL�z�^	gN�N�c6R
k0�bS����Hr���R�k�^�l�]�^r�HAQ1��|q}�{t�T-��[݈n��N�_yr�[�S� (�S�) �c6e Microsoft Defender _�d�f�e - AQ1��[6b
\8o2�_|vL�z�^	gN�N�c6R
k0KAQ1��|q}�{t�T-��[݈n��N�_yr�[�S� (�S�) �c6e Microsoft Defender �[hQ'`�`1X�f�e - AQ1��[6b
\8o2�_|vL�z�^	gN�N�c6R
k0"AQ1��|q}�{t�Tx��d��Q_�d0s^�S�T�[hQ�`1X�f�e�f�e�v8o2�_|vL�z�^0PAJdk-��[�c6R(W Windows Nd\ RS3 /f&TAQ1�-��[�p\��b=z8h!j_0傺p/����EnableNetworkProtection �v�P<P\���_eu0`dk-��[�c6R�}��Ow�/f&TAQ1�(W Windows Server 
N_U(unj�e1XU�t0傺p/����DisableDatagramProcessing �v<P\���_eu�&N�-��p\P(u Datagram �j�g0Pdk-��[_U(u�N�}��Ow��v DNS Sinkhole �R���
\͑ EnableNetworkProtection (W\����[�Bf�v�P<P�FO(W�j�g!j_N�l	g�NUO�R��0�P-��[g\P(u�}��Ow��v#�eQ#��}�{x��R��0�P-��[g\P(u�}��Ow��v RDP VR�g0dk-��[g\P(u�}��Ow��vHe��Y�,n6eƖ�T�P��R��0dk-��[g�N��O�Njd|�Ow��O-��[7_S0O�c6R�cd���v/f&T
\݈n
N�vj�n,g0WO(u��S��0O(u?eV{-��[ HideExclusionsFromLocalAdmins �O��υj�n�S�{t,g0WO(u��v�cd�nj�e0�P-��[g\P(u�}��Ow��v FTP VR�g0!dk-��[�S_U(uHe��gsOS��NAQ1�Tek�j�g�v�}�AmϑR�c0R^�Tek�j�g0c�[HSY�_�WL��]�cz�c�c�vR�xe0dk-��[g(W�u㖒c�!j_��_UBf\P(u�z9e2�w�0�P-��[g\P(u�}��Ow��v SMTP VR�g0�P-��[g\P(u�}��Ow��v QUIC VR�g0�g-��[�}��Ow��vU��P!j_0DEPRECATED: dk-��[g\P(u_�d-N�v TDT0PAkc�[�S;e�db�.~\��GR (ASR) ��GRyr�[�cd�X�%R�x0�_�-��[/�e�X��GRX�%R�x�&N(W AttackSurfaceReductionRules_RuleSpecificExclusions l\'`-Nc�[vQP%R�cd���v0pc�[�S;e�db�.~\��GR (ASR) ��GRyr�[�cd�X�%R�x0�_�-��[/�e�X��GRyr�[�cd���v�&N(W AttackSurfaceReductionRules_RuleSpecificExclusions_Id l\'`-Nc�[vQP%RX�%R�x0(W�sbԚW�g��_U(usSBf�Ow��=|�z�f�e(OOBE)0dk-��[AQ1� IT �{t�T�p�S�{t݈n-��[He��!j_�p_U(ub\P(u0\P(u�[���f�e�_�S�v�_�S�}w��]\O0�[g�zsS�P�V0(W�_��c�cg���c�c�cd��v�jHh�T�v�0ScanRtpExclusions�yd��c�c
\q�xe�v�v
NP�i_U(uBf�8h�_
g�R\\PbkO(u [f�W��T-��[
g�R (ECS)]��N�_��c�O Microsoft Defender 2��kߎԚ�TvQ�N Defender ߎԚ�v͑'YD}T~yr�[KN�Ock0�Ockz_\g|~�~�N��[hQ'`�`1X�f�e�c�O0z_U(uBf�8h�_
g�R\g\PbkO(u OneDsCollector �g�i��N�_ Microsoft Defender 2��kߎԚ*�TvQ�N Defender ߎԚ6eƖY�,n0_U(udk-��[gq_�� Microsoft �_���X��S�zlOUL��v���R��O�YHe���}ba�T��$R0_U(u UDP RrRxS	��Nrs�_�}��Ow�_U(u UDP �c6exS	��Nrs�_�}��Ow���[�N	��[hQ'`�`1X�f�e�v�O�n��^0dk-��[�S���`�[�
NT�[hQ'`�`1X�f�e�O�n�a#�a}�v��^0�a\dk-��[<P\O�p�N�{S�R���vW[&{2N8�eQ�	c��^�g	��[hQ�`1X�f�e�O�n0�S���vxe<P�p�0InternalDefinitionUpdateServer
00MicrosoftUpdateServer
00MMPC
00FileShares
0 c�Q��(Wfg~^�f�e�[hQ�`1X0�-��[�p���h�:y�k)Y�f�e�[hQ�`1X0J�[��d�O��܈=|�z�v)Yxe0-dM� SignatureUpdateLastChecked O(u00 = 
N��܈�1 = 1 )Y�2 = 2 )Y��Odk^��c0\P(u���y
k!j_0	\P(ueQ�O2�w��|q}0-dk Cmdlet �-�g\BlO(u��x��0�c�[ -Force�GR
NgTO(u�\Bl�-��x��0c�[1XJT�RKa=|�zhc�h�N�Nb
Nc�[09h�d�-��
N��1XJTdk^��N�N0c�[�S;e�db�.~\��GR�v�cd���v0�[�[��d�t�X-N�O�[hQ�`1X�f�eO(u�v�jHhqQ(u@S0Microsoft Defender 2��kߎԚOP}Y-��[^�%R��w^�%R0ScanStateNotificationsThreatStateNotificationsSignatureStateNotificationsComputerStateNotificationss�0}�c�c��w0
ErrorOccurred
ScanCompleteds�0}Z���w0SuccessfulRemediationNonCriticalFailures�0}=|�z��w0SignaturesOutOfDates�0}�v��f���w0ScansOutOfDateComponentsChangedStateRecovered"uu WMI �N�N�v�eg�TBf��VvQ�Nnj�e0�vMR/UN�vO(u�`�l/fvu CategoryDiscriminant I{�e ThreatStateNotificationsthen Bf�dk<P\S+T ThreatIDMicrosoft Defender 2��kߎԚ�N�Nc:y^�%R��GR�v/UNX�%R�x GUID0��\���v IP MO@W0\���R\O�v^��W0
��GR�v�eT0(#��Q0#�eQ)��GR�v�
�TS�[0(TCP0UDP0�NUO)	,g_j#��c�W�v�{
W0	`��z#��c�W�v�{
W05r|hyэ�`Start time of the rule, when it was first created-r|ga�f�aEnd time of the rule, when it will expire7э�RT�RUnique identifier (GUID) of the rule to be removed.>K�|Why^�Microsoft Defender Behevioral Network Blocking Rules Class%1!s! ck(W�c�c�`�v݈n��x��S�v�c�c^��W��[���S�����N�NBf��0�c�c�]�)R�[b0Vf��c�c�`�v݈nBf|vu/���0���c�c�[te�c�c�_��c�c%1!s! %2!s!
ck(W�f�e�u�k�S��܊ߎԚ�[�!%1!s! g��R�f�e�`�v�u�k�S��܊ߎԚ�[���NTS�R�Ow��`�v݈n0�u�k�S��܊ߎԚ�[��f�e�]�)R�[b0�u�k�S��܊ߎԚ�[��f�e�]�[bFO	g/���0	�u�k�S��܊ߎԚ�[��d\O1YWe�|vuNR/���: 0x%1!x!�WL����c�cBf��_���	g ScanPath �Sxe0dk݈n�]�}(W�WL��c�c0dk݈n�]�}(W�WL��u�k�S��܊ߎԚ�[��f�e0ck(Wnd���uP,n�p�S��	g�[�v��v0�`�v݈n�vMR�l	g�NUOuP,n0R�v��v�Snd�0Vf�nd���uP,n�p�S��	g�[�v��vBf|vu/���0F�_��p�kP ThreatIDDefaultAction_Ids �Sxec�[ AThreatIDDefaultAction_Actions <P0!q�l�S�_Z�X�%R�x�v�-��R\O0/���: 0x%1!x!)�d\O1YWe�|vuNR/���: 0x%1!x!0�d\O: %2!s!0�vj: %3!s!0�`�l	g�� Y�v
kP��S�WL���Bl�v�d\O0Vf�(W�`�v݈n
N�WL� WDO �c�cBf|vu/���0dk݈n�]�}(W�WL��c�c0�����D%2 WMI �c�O��WL�PԚ�d�S�e�l-N|vu/��� %10%0

<%2 WMI �c�O�\�Ka�e�l-N|vu/��� %10%0

P%2 WMI �c�O� FireEvent �e�l-N|vu/��� %10%0

|Vf��_@b	g\O(u-N��f��]\O���k{v� %2 WMI �c�O���wBf|vu/��� %10�Sg6e0R�O��vMR�]\O���k�v��w0%0

PVf��p %2 WMI �c�O��^�z�N�N�v���WL��}Bf|vu/��� %10%0

XVf�{v� %2 WMI �c�O��N�S�_�v���S�`az_�x��wBf|vu/��� %10%0

h4VS_VERSION_INFO���e�e?�StringFileInfo�040404B0LCompanyNameMicrosoft Corporationh FileDescriptionProtection Management WMIv2 �c�O�JInternalNameProtectionManagement�.LegalCopyright� Microsoft Corporation. All rights reserved.bOriginalFilenameProtectionManagement.dll.muij%ProductNameMicrosoft� Windows� Operating System�8FileVersion4.18.26040.7 (8d846dd50fd7adca65beb1b013a5fda76a9ec807)>
ProductVersion4.18.26040.7l&PrivateBuildGitEnlistment(ContainerAdministrator)DVarFileInfo$Translation�PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX�%0�%w	*�H��
��%h0�%d10
	`�He0\
+�7�N0L0
+�70	���010
	`�He ��C��`�m�[���ZK���Y���&�l�ԛ��
�0��0��3�ݪ��D��0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20110
250619181144Z
260617181144Z0p10	UUS10U
Washington10URedmond10U
Microsoft Corporation10UMicrosoft Windows0�"0
	*�H��
�0�
��ʻt9�)C@۸H�������^'�bD�]��0��
��d{��Q���lR��K�$�BR/��N�Y�����jv�-E(t�N:L�|�%P�<�S����v�y�V܇�V�o�t�.�NԚCh��[m��Sǡ�a.l�M�'hGvP��h�L�}j�N�3'�.�+㩱Cގc�ʭ�\�O�n����h��|goVcO�:$���*n�1H:2JoT��`�Y8!����=k���98�b5T���H��H؄��v0�r0U%0
+�7
+0U�9Z�����^9!��0EU>0<�:0810UMicrosoft Corporation10U
229879+5053260U#0��)9�ėx͐��O��|U�S0WUP0N0L�J�H�Fhttp://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl%200a+U0S0Q+0�Ehttp://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0U�00
	*�H��
��hz�x�iXdzq�	L]�IY����Xq��P���I�
gV~q_�R5�ٳ�);�	��#� o.J�@�$��3o�8NnMe�bʍ	�� @����BVFLt��1���M3�4E�p�b*��q	��]�Fe��]�}��n�sb��H,zȭ+�i���+Q"�V�t}���?¥����rl��^��N�M�&sc��n�`�ԓ�l���9B�U�K�������s?�~����s�zw+a0��0���
avV0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100
111019184142Z
261019185142Z0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20110�"0
	*�H��
�0�
�����.	����i�!�i33��T����� ��ҋ�8����-|by��J?5 p���k�6u�1ݍp��7�tF�([�`#,��G�g�Q'�r��ɹ;S5|���'�����#	o�F��n�<A�ˣ?]jM�i%(\6��C
��������['�'x0�[*	k"�S`,�hS��I�a��h	sD]}�T+�y��5]l+\μ�#�on�&�6�O�'��2;A�,���w�TN�\�e�C���mw�Z$�H��C0�?0	+�70U�)9�ėx͐��O��|U�S0	+�7
SubCA0U�0U�0�0U#0��Vˏ�\bh�=��[�Κ�0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
	*�H��
��|qQ�y�n��9>�<Rn+?s��h�H�4M��&�1F�ay�8.Ek��(�����	��L
6fj���������@26v�Zƿ���Ӭ�h�b��TlP0X��|���N���|�sW�R!s4Z�V��	����~�����?�rS��c��=1e�������=����BА�_T���G�o�sNA�@�_�*��s�!(���s9_>�\`����	���Q�fG���=�*hw��Lb{��Ǻz�4Kbz����J7�-�W|�=ܸZ��ij�:��n�i!7ށ�ugӓW^)9��-���Es[���z��FX�^���g�l5��?$�5�
u�V��x,��Ј���ߺ~,c��#!�xl�X6+�̤��-����@�E�Ί\k>��p*
j�_G��c
2��6*pZ�BYqKW�~���!<��Ź���E��� ����ŕ�]b֠c �uw}=�E�����W�o3��w�bY~1�0�
0��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1.0,U%Microsoft Windows Production PCA 20113�ݪ��D��0
	`�He���0	*�H��
	1
+�70
+�710
+�70/	*�H��
	1" �/�O����+b�'�~�M��m�ZEk�z�|d0B
+�71402��Microsoft��http://www.microsoft.com0
	*�H��
�Ps�gCe���?�|�F��f��h�y�������Y!���4BP�|9YZ|\0|�;eNW��}����}��p	�Bj�>��g��8%4�@
W�a��C�C�+πx7�Q+����$	��z69�m�n��=kp����!�Z�8o6�Θ=���-a�����+ME�9���9	����Z�
~��$P��!�o���S����ҰGUC�Qd�Vja#*���=%�DS#�-��\pY�x�f����0��
+�71��0�|	*�H��
��m0�i10
	`�He0�R*�H��
	��A�=0�9
+�Y
010
	`�He X@S�}����^F�a�u@4��K�g��X�si�j:k20260425005148.388Z0��Ѥ��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1%0#UMicrosoft America Operations1'0%UnShield TSS ESN:7F00-05E0-D9471%0#UMicrosoft Time-Stamp Service���0� 0��3���n9o|I0
	*�H��
0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100
260219193949Z
270517193949Z0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1%0#UMicrosoft America Operations1'0%UnShield TSS ESN:7F00-05E0-D9471%0#UMicrosoft Time-Stamp Service0�"0
	*�H��
�0�
���8�l<,G�^�:�^l�8mN�vj\�K�ѹ�d��sy$	
CӪ�s�\�~�׼��[�Z0���!*��'����
aY<���0��/��/�L��z�X�(,�X�-tW�=$߯HN�����]�X�H�uR�ne����{�kbEE]����j�ᐗ��oA����Me��i.Y��F��<�[�\Z܋��0��I9�9��S�>��t	���aċ�l�3�IԪ��+����&�U4�����o���.�5_oW&�?�4�:�k�O��f�+|!Y����*OBN5ƹ�;xLb=�(�]��b�6�-%�ԑJn�4S����2�����y
�;L�Y�1��R��A�=���.]���f�V�T�]�o]����v�m�]O(%5�uJ��*+P�����������GD�3�5^�R�N�����8���hZj���<9՝����Nv��&sE�_�Ut�d�1��b�(]�sFՉ�S�*�Kw,+3{�+V'�[>�����-��I0�E0U�
��	fb\.<���d0U#0���]^b]����e�S5�r0_UX0V0T�R�P�Nhttp://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l+`0^0\+0�Phttp://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0U�00U%�0
+0U��0
	*�H��
����y6rU�p)�Ѣy9�ƶLX��2������`�O6�H�|&zS��}�t�o�I353
�O��H���
Ik�\@,�&Noq쪥CY3ױ�v5�ٕ8	�4k�2�j$��.6)1f�X��b��}+��<([�4}�0?L'-G�(�jTՔK�}n_G�$��5�S�dw��S8�����n����:-�t���xXZ��4�@�B���u8ۧw�߄�Tpu���~�jC��
��7(}\w��<�B`�PĴ����-�_y���>��E-I|��(-�}���x$�`B���ѣq�q���x�+*�:�p��mG������,����(:WFD�O0}
�Y$��^Ԋ>���I���5u1Z�y��)nw�
���d'�:2��7|(�|B>�%��N#����Yơ�\_���͑8�ߘ�vw�/�}E*^��@ʋj%!f����q��j�W�Uv�b[4��,�C�i\��k��M�����Z�0���!��6��0�q0�Y�3��k��I�0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100
210930182225Z
300930183225Z0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100�"0
	*�H��
�0�
���L�r!y���$y�Ղ��ҩlNu��5W�lJ�⽹>`3�\O�f��SqZ�~JZ��6g�F#���w2��`}jR�D���Fk��v��P�D�q\Q17�
8n����&S|9azĪ�ri����6�5&dژ;�{3��[~��R���b%�j�]�S���VM�ݼ��㑏�9,Q��pi
�6-p�1�5(�㴇$��ɏ~�T��U�mh;�F��z)7���E�Fn�2��0\O,�b�͹⍈䖬J��q�[g`���=� �s}A�Fu��_4���� }~�ٞE߶r/�}_��۪~6�6L�+n�Q���s�M7t�4���G��|?Lۯ^����s=CN�39L��Bh.�QF�ѽjZas�g�^�(v�3rק ��
�co�6d�[���!]_0t���عP��a�65�G������k�\RQ]�%��Pzl�r�Rą��<�7�?x�E���^ڏ�riƮ{��>j�.����0��0	+�70#	+�7*�R�dĚ���<F5)��/�0U��]^b]����e�S5�r0\U U0S0Q+�7L�}0A0?+3http://www.microsoft.com/pkiops/Docs/Repository.htm0U%0
+0	+�7
SubCA0U�0U�0�0U#0��Vˏ�\bh�=��[�Κ�0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
	*�H��
��U}�*��,g1$[�rK��o�\�>NGdx���=13�9��q6?�dl|�u9m�1��lѡ�"��fg:SMݘ��x�6.���V����i�	�{�jo�)�n�?Hu��m��m#T�xSu$W�ݟ�=��h�e��V����(U'�$�@���]='�@�8���)�ü�T�B�������j�BRu�6��as.,k{n?,	x鑲�[�I�t�쑀�=�J>f;O���2ٖ����t��Lro�u0�4�z�P�
X�@<�Tm�ctH,�NG-�q�d�$�smʎ	��WITd�s�[D�Z�k
��(�g($�8K�n�!TkjEG����^O���Lv�WT	�iD~|�als�
��Af=i��AI~~���;����>�1Q������{��p���(��6ںL���
�4�$5g+�
�挙��"��'B=%��tt[jў>�~�13}���{�8pDѐ�ȫ:�:b�pcSM��m��qj�U3X��pf�M0�50����Ѥ��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1%0#UMicrosoft America Operations1'0%UnShield TSS ESN:7F00-05E0-D9471%0#UMicrosoft Time-Stamp Service�#
0+��d(2�R�=�j������0���~0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100
	*�H��
��0"20260424155909Z20260425155909Z0t0:
+�Y
1,0*0
��0!�0H0
�cM06
+�Y
1(0&0
+�Y
�
0� �
0��0
	*�H��
�+�>
���n�TX��	���
hUeE�X�bOA���C=������+���Z��A�)�t	t�&Q�t�8�g|��{<�܉�p:�h��ၾq7;A�g�)RqM�Cu���g�>�Q�R"	s�߃�
:��7�kA�)B����9�yB��Q����4�M��&n��$#5�%��o��&
yC@��woO��JI�����%���z���'ⴶ�@�>�TAՌ�FR�9��"�.���bV9�������g1�
0�	0��0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20103���n9o|I0
	`�He��J0	*�H��
	1
*�H��
	0/	*�H��
	1" kL�J��!�������s(r�™�_��q�0��*�H��
	/1��0��0��0�� /�]j�������u����2#
��0��0���~0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20103���n9o|I0" D���2\WN��kR����/�ArY*/�%�i�'0
	*�H��
������H�7w<N��EV�5���]8�����>�`�Qf[^+���i욋c�YW���sq�$o[���R.�Ju1+���@��oSD5�*���WTL���	f�K��{�?k�T,E�9�E�Z�������Y�@�f�݌�U�io:Ϥt�0�?��ƈ?S�??0�]u�Q�>_��v'�btB��9Jcy�%^J��eꟾ��4�_W����D�Dl��;��n��{��p3�VL���y,�2h�/�����@�i�~Oϳ/q-[U.��D�X_�j3VCEcReG=����<DD�ˍ�-�e��W���$��1�^�V�{{2P�J.C*����ɀ�GE�w)H��N����$��g}Ƽ��_p�W^�,K��+G��IV��HŨ�EӀ�g�pgy
�QGL����9.�Fn�a���p	x��r��^`د`S��K~q��w`�ǽ�&�5�Y��4U:FO�����X�ki��S�Fؠ�� �u?��F�

Youez - 2016 - github.com/yon3zu
LinuXploit