DonatShell
Server IP : 180.180.241.3  /  Your IP : 216.73.216.252
Web Server : Microsoft-IIS/7.5
System : Windows NT NETWORK-NHRC 6.1 build 7601 (Windows Server 2008 R2 Standard Edition Service Pack 1) i586
User : IUSR ( 0)
PHP Version : 5.3.28
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  C:/ProgramData/Sophos/AutoUpdate/Cache/sophos_autoupdate1.dir/decode/sed64/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : C:/ProgramData/Sophos/AutoUpdate/Cache/sophos_autoupdate1.dir/decode/sed64/integrity.dat
ProtectDetails 000d:integrity.dat 0005:1.0.9 000e:Sophos Limited 0003:SED 000a:2.2.4.8520 2020-06-11T21:09:45Z
ProtectService 0017:Sophos Endpoint Defense 2 0 1 001d:system32\DRIVERS\SophosED.sys
ProtectService 001f:Sophos Endpoint Defense Service 10 2 1 003a:%SophosProgramFilesNative%\Endpoint Defense\SEDService.exe ObjectName 000b:LocalSystem
ProtectService 0020:Sophos System Protection Service 10 2 1 003a:%SophosProgramFilesNative%\Endpoint Defense\SSPService.exe ObjectName 000b:LocalSystem
ProtectApplication 0049:%SophosProgramFilesNative%\Endpoint Defense\FileAnalyzerSubmitterTool.exe
ProtectApplication 0043:%SophosProgramFilesNative%\Endpoint Defense\SophosFileSubmitter.exe
ProtectApplication 0036:%SophosProgramFilesNative%\Endpoint Defense\SspEdr.exe
ProtectApplication 0036:%SophosProgramFilesNative%\Endpoint Defense\SEDcli.exe
ProtectApplication 003c:%SophosProgramFilesNative%\Endpoint Defense\SEDTelemetry.exe
ProtectApplication 003f:%SophosProgramFilesNative%\Endpoint Defense\TelemetryPlugin.exe
ProtectApplication 003c:%SophosProgramFilesNative%\Endpoint Defense\SSPTelemetry.exe
ProtectApplication 0022:%SystemRoot%\System32\SophosNA.exe
ProtectRegKey 0021:\REGISTRY\MACHINE\SOFTWARE\Sophos AllowChangeValues
ProtectRegKey 002d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Sophos AllowChangeValues
ProtectRegKey 0031:\REGISTRY\MACHINE\SOFTWARE\Sophos\EndpointDefense RecursiveReadOnly
ProtectRegKey 0044:\REGISTRY\MACHINE\SOFTWARE\Sophos\EndpointDefense\LocalConfiguration AllowChangeValues
ProtectRegKey 004b:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense AllowChangeSubKeys
ProtectRegKey 0055:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\Instances RecursiveReadOnly
ProtectRegKey 0051:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\Paths RecursiveReadOnly
ProtectRegKey 0054:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\Scanning RecursiveReadOnly
ProtectRegKey 0058:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\EventJournal RecursiveReadOnly
ProtectRegKey 005c:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection RecursiveReadOnly
ProtectRegKey 0067:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Components AllowChangeSubKeys
ProtectRegKey 006b:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Components\SED RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Services AllowChangeSubKeys
ProtectRegKey 007d:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Services\Sophos Endpoint Defense RecursiveReadOnly
ProtectRegKey 0085:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Services\Sophos Endpoint Defense Service RecursiveReadOnly
ProtectRegKey 0086:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Services\Sophos System Protection Service RecursiveReadOnly
ProtectRegKey 0053:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense Service RecursiveReadOnly
ProtectRegKey 0054:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos System Protection Service RecursiveReadOnly
ProtectRegKey 0061:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\Sophos System Protection RecursiveReadOnly
ProtectRegKey 005d:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sophos Endpoint Defense RecursiveReadOnly
ProtectRegKey 0051:%HKLMSophosSoftware32%\AutoUpdate\Products\{1129226C-32AB-4B72-85E1-A9CC8DFBC859} RecursiveReadOnly
ProtectRegKey 0021:%HKLMSophosSoftware32%\BPALOGGING RecursiveReadOnly
ProtectRegKey 002c:%HKLMSophosSoftware32%\Telemetry\Plugins\SED RecursiveReadOnly
ProtectRegKey 002c:%HKLMSophosSoftware32%\Telemetry\Plugins\SSP RecursiveReadOnly
ProtectRegKey 004c:%HKLMSophosSoftware32%\Remote Management System\ManagementAgent\Adapters\SED RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVService.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVAdminService.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosBootTasks.exe RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssr32.exe RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssr64.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swc_service.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_service.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_filter.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_update.exe RecursiveReadOnly
ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_update_64.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lsp32_util.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lspdiag.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lspdiag_64.exe RecursiveReadOnly
ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_di.exe RecursiveReadOnly
ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_fc.exe RecursiveReadOnly
ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WSCClient.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVCleanupService.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVTelem.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavProgress.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForceUpdateAlongSideSGN.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sav32cli.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCService.exe RecursiveReadOnly
ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCDevCon.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCDevCon64.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavProxy.exe RecursiveReadOnly
ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ConfigureSAV.exe RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ALSvc.exe RecursiveReadOnly
ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUpdate.exe RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlMon.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GatherTelem.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SubmitTelem.exe RecursiveReadOnly
ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AUTelem.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFileScanner.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFS.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssp.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDRService.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDService.exe RecursiveReadOnly
ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDcli.exe RecursiveReadOnly
ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDTelemetry.exe RecursiveReadOnly
ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDuninstall.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SSPService.exe RecursiveReadOnly
ProtectRegKey 0079:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileAnalyzerSubmitterTool.exe RecursiveReadOnly
ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFileSubmitter.exe RecursiveReadOnly
ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SSPTelemetry.exe RecursiveReadOnly
ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SspEdr.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNA.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McsAgent.exe RecursiveReadOnly
ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McsClient.exe RecursiveReadOnly
ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNtpService.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSnort.exe RecursiveReadOnly
ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosIPS.exe RecursiveReadOnly
ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Sophos UI.exe RecursiveReadOnly
ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavApi.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSafeStore32.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSafeStore64.exe RecursiveReadOnly
ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM32.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM64.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hmpalert.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EXPTelem.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SLDService.exe RecursiveReadOnly
ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFIMService.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFIMTelemetry.exe RecursiveReadOnly
ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosHealth.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosHealthClient.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFSTelemetry.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFSVerify.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNtpTelemetry.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUITelemetry.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUpdateMgr.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SUMService.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSSEUninstall.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSSEValidator.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSMEUninstall.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSMEValidator.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosDiag.exe RecursiveReadOnly
ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosESH.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MLFileInfo.exe RecursiveReadOnly
ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-repair.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-setup32.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-setup64.exe RecursiveReadOnly
ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sducli.exe RecursiveReadOnly
ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sdugui.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EfwTelemetryPlugin.exe RecursiveReadOnly
ProtectRegKey 007c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosAmsiTelemetryCollector.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVService.exe RecursiveReadOnly
ProtectRegKey 007b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVAdminService.exe RecursiveReadOnly
ProtectRegKey 007b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosBootTasks.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssr32.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssr64.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swc_service.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_service.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_filter.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_update.exe RecursiveReadOnly
ProtectRegKey 0079:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_update_64.exe RecursiveReadOnly
ProtectRegKey 007a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lsp32_util.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lspdiag.exe RecursiveReadOnly
ProtectRegKey 007a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lspdiag_64.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_di.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_fc.exe RecursiveReadOnly
ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WSCClient.exe RecursiveReadOnly
ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVCleanupService.exe RecursiveReadOnly
ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVTelem.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavProgress.exe RecursiveReadOnly
ProtectRegKey 0083:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForceUpdateAlongSideSGN.exe RecursiveReadOnly
ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sav32cli.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCService.exe RecursiveReadOnly
ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCDevCon.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCDevCon64.exe RecursiveReadOnly
ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavProxy.exe RecursiveReadOnly
ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ConfigureSAV.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ALSvc.exe RecursiveReadOnly
ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUpdate.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlMon.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GatherTelem.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SubmitTelem.exe RecursiveReadOnly
ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AUTelem.exe RecursiveReadOnly
ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFileScanner.exe RecursiveReadOnly
ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFS.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssp.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDRService.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDService.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDcli.exe RecursiveReadOnly
ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDTelemetry.exe RecursiveReadOnly
ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDuninstall.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SSPService.exe RecursiveReadOnly
ProtectRegKey 0085:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileAnalyzerSubmitterTool.exe RecursiveReadOnly
ProtectRegKey 007f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFileSubmitter.exe RecursiveReadOnly
ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SSPTelemetry.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SspEdr.exe RecursiveReadOnly
ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNA.exe RecursiveReadOnly
ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McsAgent.exe RecursiveReadOnly
ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McsClient.exe RecursiveReadOnly
ProtectRegKey 007c:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNtpService.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSnort.exe RecursiveReadOnly
ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosIPS.exe RecursiveReadOnly
ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Sophos UI.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavApi.exe RecursiveReadOnly
ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSafeStore32.exe RecursiveReadOnly
ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSafeStore64.exe RecursiveReadOnly
ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM.exe RecursiveReadOnly
ProtectRegKey 007a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM32.exe RecursiveReadOnly
ProtectRegKey 007a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM64.exe RecursiveReadOnly
ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hmpalert.exe RecursiveReadOnly
ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EXPTelem.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SLDService.exe RecursiveReadOnly
ProtectRegKey 007c:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFIMService.exe RecursiveReadOnly
ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFIMTelemetry.exe RecursiveReadOnly
ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosHealth.exe RecursiveReadOnly
ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosHealthClient.exe RecursiveReadOnly
ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFSTelemetry.exe RecursiveReadOnly
ProtectRegKey 007a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFSVerify.exe RecursiveReadOnly
ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNtpTelemetry.exe RecursiveReadOnly
ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUITelemetry.exe RecursiveReadOnly
ProtectRegKey 007b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUpdateMgr.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SUMService.exe RecursiveReadOnly
ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSSEUninstall.exe RecursiveReadOnly
ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSSEValidator.exe RecursiveReadOnly
ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSMEUninstall.exe RecursiveReadOnly
ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSMEValidator.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosDiag.exe RecursiveReadOnly
ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosESH.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MLFileInfo.exe RecursiveReadOnly
ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-repair.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-setup32.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-setup64.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sducli.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sdugui.exe RecursiveReadOnly
ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EfwTelemetryPlugin.exe RecursiveReadOnly
ProtectRegKey 0088:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosAmsiTelemetryCollector.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVService.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVAdminService.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosBootTasks.exe RecursiveReadOnly
ProtectRegKey 005e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssr32.exe RecursiveReadOnly
ProtectRegKey 005e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssr64.exe RecursiveReadOnly
ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swc_service.exe RecursiveReadOnly
ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_service.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_filter.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_update.exe RecursiveReadOnly
ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_update_64.exe RecursiveReadOnly
ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lsp32_util.exe RecursiveReadOnly
ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lspdiag.exe RecursiveReadOnly
ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lspdiag_64.exe RecursiveReadOnly
ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_di.exe RecursiveReadOnly
ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_fc.exe RecursiveReadOnly
ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\WSCClient.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVCleanupService.exe RecursiveReadOnly
ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVTelem.exe RecursiveReadOnly
ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavProgress.exe RecursiveReadOnly
ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ForceUpdateAlongSideSGN.exe RecursiveReadOnly
ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sav32cli.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCService.exe RecursiveReadOnly
ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCDevCon.exe RecursiveReadOnly
ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCDevCon64.exe RecursiveReadOnly
ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavProxy.exe RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ConfigureSAV.exe RecursiveReadOnly
ProtectRegKey 005e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ALSvc.exe RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUpdate.exe RecursiveReadOnly
ProtectRegKey 005e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\AlMon.exe RecursiveReadOnly
ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\GatherTelem.exe RecursiveReadOnly
ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SubmitTelem.exe RecursiveReadOnly
ProtectRegKey 0060:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\AUTelem.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFileScanner.exe RecursiveReadOnly
ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFS.exe RecursiveReadOnly
ProtectRegKey 005c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssp.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDRService.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDService.exe RecursiveReadOnly
ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDcli.exe RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDTelemetry.exe RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDuninstall.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SSPService.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\FileAnalyzerSubmitterTool.exe RecursiveReadOnly
ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFileSubmitter.exe RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SSPTelemetry.exe RecursiveReadOnly
ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SspEdr.exe RecursiveReadOnly
ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNA.exe RecursiveReadOnly
ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\McsAgent.exe RecursiveReadOnly
ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\McsClient.exe RecursiveReadOnly
ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNtpService.exe RecursiveReadOnly
ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSnort.exe RecursiveReadOnly
ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosIPS.exe RecursiveReadOnly
ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\Sophos UI.exe RecursiveReadOnly
ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavApi.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSafeStore32.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSafeStore64.exe RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM.exe RecursiveReadOnly
ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM32.exe RecursiveReadOnly
ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM64.exe RecursiveReadOnly
ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\hmpalert.exe RecursiveReadOnly
ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\EXPTelem.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SLDService.exe RecursiveReadOnly
ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFIMService.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFIMTelemetry.exe RecursiveReadOnly
ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosHealth.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosHealthClient.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFSTelemetry.exe RecursiveReadOnly
ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFSVerify.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNtpTelemetry.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUITelemetry.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUpdateMgr.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SUMService.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSSEUninstall.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSSEValidator.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSMEUninstall.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSMEValidator.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosDiag.exe RecursiveReadOnly
ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosESH.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\MLFileInfo.exe RecursiveReadOnly
ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-repair.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-setup32.exe RecursiveReadOnly
ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-setup64.exe RecursiveReadOnly
ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sducli.exe RecursiveReadOnly
ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sdugui.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\EfwTelemetryPlugin.exe RecursiveReadOnly
ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosAmsiTelemetryCollector.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVService.exe RecursiveReadOnly
ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVAdminService.exe RecursiveReadOnly
ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosBootTasks.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssr32.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssr64.exe RecursiveReadOnly
ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swc_service.exe RecursiveReadOnly
ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_service.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_filter.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_update.exe RecursiveReadOnly
ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_update_64.exe RecursiveReadOnly
ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lsp32_util.exe RecursiveReadOnly
ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lspdiag.exe RecursiveReadOnly
ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lspdiag_64.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_di.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_fc.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\WSCClient.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVCleanupService.exe RecursiveReadOnly
ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVTelem.exe RecursiveReadOnly
ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavProgress.exe RecursiveReadOnly
ProtectRegKey 007c:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ForceUpdateAlongSideSGN.exe RecursiveReadOnly
ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sav32cli.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCService.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCDevCon.exe RecursiveReadOnly
ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCDevCon64.exe RecursiveReadOnly
ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavProxy.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ConfigureSAV.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ALSvc.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUpdate.exe RecursiveReadOnly
ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\AlMon.exe RecursiveReadOnly
ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\GatherTelem.exe RecursiveReadOnly
ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SubmitTelem.exe RecursiveReadOnly
ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\AUTelem.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFileScanner.exe RecursiveReadOnly
ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFS.exe RecursiveReadOnly
ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssp.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDRService.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDService.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDcli.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDTelemetry.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDuninstall.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SSPService.exe RecursiveReadOnly
ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\FileAnalyzerSubmitterTool.exe RecursiveReadOnly
ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFileSubmitter.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SSPTelemetry.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SspEdr.exe RecursiveReadOnly
ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNA.exe RecursiveReadOnly
ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\McsAgent.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\McsClient.exe RecursiveReadOnly
ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNtpService.exe RecursiveReadOnly
ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSnort.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosIPS.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\Sophos UI.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavApi.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSafeStore32.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSafeStore64.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM.exe RecursiveReadOnly
ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM32.exe RecursiveReadOnly
ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM64.exe RecursiveReadOnly
ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\hmpalert.exe RecursiveReadOnly
ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\EXPTelem.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SLDService.exe RecursiveReadOnly
ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFIMService.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFIMTelemetry.exe RecursiveReadOnly
ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosHealth.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosHealthClient.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFSTelemetry.exe RecursiveReadOnly
ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFSVerify.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNtpTelemetry.exe RecursiveReadOnly
ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUITelemetry.exe RecursiveReadOnly
ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUpdateMgr.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SUMService.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSSEUninstall.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSSEValidator.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSMEUninstall.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSMEValidator.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosDiag.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosESH.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\MLFileInfo.exe RecursiveReadOnly
ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-repair.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-setup32.exe RecursiveReadOnly
ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-setup64.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sducli.exe RecursiveReadOnly
ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sdugui.exe RecursiveReadOnly
ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\EfwTelemetryPlugin.exe RecursiveReadOnly
ProtectRegKey 0081:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosAmsiTelemetryCollector.exe RecursiveReadOnly
ProtectDirectory 0013:%SophosProgramData% AllowChangeSubDirs
ProtectDirectory 0020:%SophosProgramData%\Certificates AllowChangeSubDirs
ProtectDirectory 001a:%SophosProgramFilesNative% AllowChangeSubDirs
ProtectDirectory 0016:%SophosProgramFiles32% AllowChangeSubDirs
ProtectDirectory 002b:%SophosProgramFilesNative%\Endpoint Defense RecursiveReadOnly
ProtectDirectory 0024:%SophosProgramData%\Endpoint Defense RecursiveReadOnly
AttestFile 000e:SEDAdapter.dll 475808 fd1f03cad157c02ddbacfa78f90a388db490531ab7daeb3cb2074e3269727d04
AttestFile 000a:SEDcli.exe 358608 d9798d193340c173a994d2ffc39c707b209c5ed970b28b82f7cd89c2b1ceda29
AttestFile 000e:SEDService.exe 3477760 f3447c6c8572dfbc99ab204bfd64569e8078f37d37abf69cf0383d4c0f2fce31
AttestFile 0010:SEDTelemetry.exe 451600 afb0508843f57b4790ccf0970d61756eeeb8e0ae5f5e8a90663d617cb11efc73
AttestFile 0010:SEDuninstall.exe 1462912 94ef75dea5b328b18c9803353f552e76130a1ba93b6afeee146ce23a78f84d5d
AttestFile 0009:Setup.dll 929816 c56bf665af92fde779808cd2f8aee7ad7ce62e192e77bc9f4b4c955da6eebc0d
AttestFile 000c:SophosED.sys 1188944 33e87e27ea70c0ee42a603984eb0ff6c619c075b8d410b30f2a05b244c78c3fb
AttestFile 000c:SophosEL.sys 22152 4e76c64d08b3f2860304875464fc2e63b6c47551fee911c5ff3e8856f4050219
AttestFile 0017:SophosFileSubmitter.exe 1651960 4c46b81fccf66c58db2d1717611daf6cbfad23493bad472eee98f9bf5ed654ae
AttestFile 000c:SophosNA.exe 40288 c631924bd527fef5919cad9254d10bfb7facdb78c3297d427cefff003466221e
AttestFile 000c:sophtlib.dll 1721328 ddbb26ede4f8ce869383d0415d69b09eed7b7c75101865b45361a7ecc695cefa
AttestFile 000a:SspEdr.exe 3173560 168ab2df844bd084a0df5d5c70820fc855a934ec21c957af7158542ef4c3d9cd
AttestFile 000e:SSPService.exe 10578600 1ec2d2cbc50e5f3c03a593dcddd01fff0e01f5a80a27f2f4f951f55ffa3330d4
AttestFile 0010:SSPTelemetry.exe 625688 fde491a563c69e9b422967f800204a7846904c21f25ba1a1c62fca6cf7ef8ea8
DigitalSignature 0005:TP001 RSA-2048_SHA-256 0158:KK4va6ecuQ1pl6O8PztRC5FIf830Nbr7bPzGgEdGn763YEWr5S+BbwVFi0cloLLBBdNMVL5mUW/qpRLmO+YWbDRGtKsl+Shcm1DmcSxB8XgPyZEotddR55v/kk7K5pL7bJ2lMmryliJferfqySnQZlnUjjXxYGw6IL9qdN3GJnZlw7lbY7oLPb28QyIAU2q+/LeELTtHhkr0oH6NaLreqxmGMURkwU7uIwng37FxEdVuPVzDYehxMT3hios2fvqWEXs0SChAHuddeK/7ROwzfHpNFDWWn9tRw7+JWligRQo4Xzon/qVl9Fn3+3hAwdW6E3Oj9NsXIXawRG0nOTPuLg==

Anon7 - 2022
AnonSec Team