[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run] "Windows Defender"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WindowsDefender"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\MitigationOptions] "MitigationOptions_FontBocking"=- [-HKEY_CURRENT_USER\Software\Classes\ms-cxh] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Features] "MpPlatformKillbitsFromEngine"=hex:00,00,00,00,00,00,00,00 "TamperProtectionSource"=dword:00000000 "MpCapability"=hex:00,00,00,00,00,00,00,00 "TamperProtection"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender] "PUAProtection"=dword:00000000 "DisableRoutinelyTakingAction"=dword:00000001 "ServiceKeepAlive"=dword:00000000 "AllowFastServiceStartup"=dword:00000000 "DisableLocalAdminMerge"=dword:00000001 "DisableAntiSpyware"=dword:00000001 "RandomizeScheduleTaskTimes"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions] "DisableAutoExclusions"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\MpEngine] "MpEnablePus"=dword:00000000 "MpCloudBlockLevel"=dword:00000000 "MpBafsExtendedTimeout"=dword:00000000 "EnableFileHashComputation"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\NIS\Consumers\IPS] "ThrottleDetectionEventsRate"=dword:00000000 "DisableSignatureRetirement"=dword:00000001 "DisableProtocolRecognition"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager] "DisableScanningNetworkFiles"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection] "DisableRealtimeMonitoring"=dword:00000001 "DisableBehaviorMonitoring"=dword:00000001 "DisableOnAccessProtection"=dword:00000001 "DisableScanOnRealtimeEnable"=dword:00000001 "DisableIOAVProtection"=dword:00000001 "LocalSettingOverrideDisableOnAccessProtection"=dword:00000000 "LocalSettingOverrideRealtimeScanDirection"=dword:00000000 "LocalSettingOverrideDisableIOAVProtection"=dword:00000000 "LocalSettingOverrideDisableBehaviorMonitoring"=dword:00000000 "LocalSettingOverrideDisableIntrusionPreventionSystem"=dword:00000000 "LocalSettingOverrideDisableRealtimeMonitoring"=dword:00000000 "RealtimeScanDirection"=dword:00000002 "IOAVMaxSize"=dword:00000512 "DisableInformationProtectionControl"=dword:00000001 "DisableIntrusionPreventionSystem"=dword:00000001 "DisableRawWriteNotification"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Scan] "LowCpuPriority"=dword:00000001 "DisableRestorePoint"=dword:00000001 "DisableArchiveScanning"=dword:00000000 "DisableScanningNetworkFiles"=dword:00000000 "DisableCatchupFullScan"=dword:00000000 "DisableCatchupQuickScan"=dword:00000001 "DisableEmailScanning"=dword:00000000 "DisableHeuristics"=dword:00000001 "DisableReparsePointScanning"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Signature Updates] "SignatureDisableNotification"=dword:00000001 "RealtimeSignatureDelivery"=dword:00000000 "ForceUpdateFromMU"=dword:00000000 "DisableScheduledSignatureUpdateOnBattery"=dword:00000001 "UpdateOnStartUp"=dword:00000000 "SignatureUpdateCatchupInterval"=dword:00000002 "DisableUpdateOnStartupWithoutEngine"=dword:00000001 "ScheduleTime"=dword:00001440 "DisableScanOnUpdate"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet] "DisableBlockAtFirstSeen"=dword:00000001 "LocalSettingOverrideSpynetReporting"=dword:00000000 "SpynetReporting"=dword:00000000 "SubmitSamplesConsent"=dword:00000002 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\UX Configuration] "SuppressRebootNotification"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\Controlled Folder Access] "EnableControlledFolderAccess"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Windows Defender Exploit Guard\Network Protection] "EnableNetworkProtection"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender] "DisableRoutinelyTakingAction"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Microsoft Antimalware] "ServiceKeepAlive"=dword:00000000 "AllowFastServiceStartup"=dword:00000000 "DisableRoutinelyTakingAction"=dword:00000001 "DisableAntiSpyware"=dword:00000001 "DisableAntiVirus"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Microsoft Antimalware\SpyNet] "SpyNetReporting"=dword:00000000 "LocalSettingOverrideSpyNetReporting"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Reporting] "DisableEnhancedNotifications"=dword:00000001 "DisableGenericRePorts"=dword:00000001 "WppTracingLevel"=dword:00000000 "WppTracingComponents"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CI\Policy] "VerifiedAndReputablePolicyState"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdNisSvc] "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdNisDrv] "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdFilter] "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdBoot] "Start"=dword:00000004 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wcncsvc] "Start"=dword:00000004 ; SmartScreen [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AppHost] "EnableWebContentEvaluation"=dword:00000000 "PreventOverride"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\Browser\AllowSmartScreen] "value"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\SmartScreen\EnableSmartScreenInShell] "value"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\SmartScreen\EnableAppInstallControl] "value"=dword:00000000 [HKEY_CURRENT_USER\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter] "EnabledV9"=dword:00000000 "PreventOverride"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\SmartScreen\PreventOverrideForFilesInShell] "value"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Edge\SmartScreenEnabled] "(Default)"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\SmartScreen] "ConfigureAppInstallControl"="Anywhere" "ConfigureAppInstallControlEnabled"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer] "SmartScreenEnabled"="Off" [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System] "EnableSmartScreen"=dword:00000000 "EnableLUA"=dword:00000000 "EnableVirtualization"=dword:00000000 [HKEY_CURRENT_USER\Software\Microsoft\Edge\SmartScreenEnabled] @=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\SmartScreen] "ConfigureAppInstallControlEnabled"=dword:00000001 "ConfigureAppInstallControl"="Anywhere"