Server IP : 180.180.241.3 / Your IP : 216.73.216.252 Web Server : Microsoft-IIS/7.5 System : Windows NT NETWORK-NHRC 6.1 build 7601 (Windows Server 2008 R2 Standard Edition Service Pack 1) i586 User : IUSR ( 0) PHP Version : 5.3.28 Disable Function : NONE MySQL : ON | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : C:/ProgramData/Sophos/AutoUpdate/Cache/sophos_autoupdate1.dir/decode/sed64/ |
Upload File : |
ProtectDetails 000d:integrity.dat 0005:1.0.9 000e:Sophos Limited 0003:SED 000a:2.2.4.8520 2020-06-11T21:09:45Z ProtectService 0017:Sophos Endpoint Defense 2 0 1 001d:system32\DRIVERS\SophosED.sys ProtectService 001f:Sophos Endpoint Defense Service 10 2 1 003a:%SophosProgramFilesNative%\Endpoint Defense\SEDService.exe ObjectName 000b:LocalSystem ProtectService 0020:Sophos System Protection Service 10 2 1 003a:%SophosProgramFilesNative%\Endpoint Defense\SSPService.exe ObjectName 000b:LocalSystem ProtectApplication 0049:%SophosProgramFilesNative%\Endpoint Defense\FileAnalyzerSubmitterTool.exe ProtectApplication 0043:%SophosProgramFilesNative%\Endpoint Defense\SophosFileSubmitter.exe ProtectApplication 0036:%SophosProgramFilesNative%\Endpoint Defense\SspEdr.exe ProtectApplication 0036:%SophosProgramFilesNative%\Endpoint Defense\SEDcli.exe ProtectApplication 003c:%SophosProgramFilesNative%\Endpoint Defense\SEDTelemetry.exe ProtectApplication 003f:%SophosProgramFilesNative%\Endpoint Defense\TelemetryPlugin.exe ProtectApplication 003c:%SophosProgramFilesNative%\Endpoint Defense\SSPTelemetry.exe ProtectApplication 0022:%SystemRoot%\System32\SophosNA.exe ProtectRegKey 0021:\REGISTRY\MACHINE\SOFTWARE\Sophos AllowChangeValues ProtectRegKey 002d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Sophos AllowChangeValues ProtectRegKey 0031:\REGISTRY\MACHINE\SOFTWARE\Sophos\EndpointDefense RecursiveReadOnly ProtectRegKey 0044:\REGISTRY\MACHINE\SOFTWARE\Sophos\EndpointDefense\LocalConfiguration AllowChangeValues ProtectRegKey 004b:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense AllowChangeSubKeys ProtectRegKey 0055:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\Instances RecursiveReadOnly ProtectRegKey 0051:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\Paths RecursiveReadOnly ProtectRegKey 0054:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\Scanning RecursiveReadOnly ProtectRegKey 0058:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\EventJournal RecursiveReadOnly ProtectRegKey 005c:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection RecursiveReadOnly ProtectRegKey 0067:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Components AllowChangeSubKeys ProtectRegKey 006b:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Components\SED RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Services AllowChangeSubKeys ProtectRegKey 007d:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Services\Sophos Endpoint Defense RecursiveReadOnly ProtectRegKey 0085:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Services\Sophos Endpoint Defense Service RecursiveReadOnly ProtectRegKey 0086:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\TamperProtection\Services\Sophos System Protection Service RecursiveReadOnly ProtectRegKey 0053:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense Service RecursiveReadOnly ProtectRegKey 0054:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\Sophos System Protection Service RecursiveReadOnly ProtectRegKey 0061:\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\Sophos System Protection RecursiveReadOnly ProtectRegKey 005d:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sophos Endpoint Defense RecursiveReadOnly ProtectRegKey 0051:%HKLMSophosSoftware32%\AutoUpdate\Products\{1129226C-32AB-4B72-85E1-A9CC8DFBC859} RecursiveReadOnly ProtectRegKey 0021:%HKLMSophosSoftware32%\BPALOGGING RecursiveReadOnly ProtectRegKey 002c:%HKLMSophosSoftware32%\Telemetry\Plugins\SED RecursiveReadOnly ProtectRegKey 002c:%HKLMSophosSoftware32%\Telemetry\Plugins\SSP RecursiveReadOnly ProtectRegKey 004c:%HKLMSophosSoftware32%\Remote Management System\ManagementAgent\Adapters\SED RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVService.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVAdminService.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosBootTasks.exe RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssr32.exe RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssr64.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swc_service.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_service.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_filter.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_update.exe RecursiveReadOnly ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_update_64.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lsp32_util.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lspdiag.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lspdiag_64.exe RecursiveReadOnly ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_di.exe RecursiveReadOnly ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_fc.exe RecursiveReadOnly ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WSCClient.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVCleanupService.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVTelem.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavProgress.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForceUpdateAlongSideSGN.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sav32cli.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCService.exe RecursiveReadOnly ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCDevCon.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCDevCon64.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavProxy.exe RecursiveReadOnly ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ConfigureSAV.exe RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ALSvc.exe RecursiveReadOnly ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUpdate.exe RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlMon.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GatherTelem.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SubmitTelem.exe RecursiveReadOnly ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AUTelem.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFileScanner.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFS.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssp.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDRService.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDService.exe RecursiveReadOnly ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDcli.exe RecursiveReadOnly ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDTelemetry.exe RecursiveReadOnly ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDuninstall.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SSPService.exe RecursiveReadOnly ProtectRegKey 0079:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileAnalyzerSubmitterTool.exe RecursiveReadOnly ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFileSubmitter.exe RecursiveReadOnly ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SSPTelemetry.exe RecursiveReadOnly ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SspEdr.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNA.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McsAgent.exe RecursiveReadOnly ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McsClient.exe RecursiveReadOnly ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNtpService.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSnort.exe RecursiveReadOnly ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosIPS.exe RecursiveReadOnly ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Sophos UI.exe RecursiveReadOnly ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavApi.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSafeStore32.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSafeStore64.exe RecursiveReadOnly ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM32.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM64.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hmpalert.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EXPTelem.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SLDService.exe RecursiveReadOnly ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFIMService.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFIMTelemetry.exe RecursiveReadOnly ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosHealth.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosHealthClient.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFSTelemetry.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFSVerify.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNtpTelemetry.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUITelemetry.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUpdateMgr.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SUMService.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSSEUninstall.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSSEValidator.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSMEUninstall.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSMEValidator.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosDiag.exe RecursiveReadOnly ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosESH.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MLFileInfo.exe RecursiveReadOnly ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-repair.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-setup32.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-setup64.exe RecursiveReadOnly ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sducli.exe RecursiveReadOnly ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sdugui.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EfwTelemetryPlugin.exe RecursiveReadOnly ProtectRegKey 007c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosAmsiTelemetryCollector.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVService.exe RecursiveReadOnly ProtectRegKey 007b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVAdminService.exe RecursiveReadOnly ProtectRegKey 007b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosBootTasks.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssr32.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssr64.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swc_service.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_service.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_filter.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_update.exe RecursiveReadOnly ProtectRegKey 0079:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_update_64.exe RecursiveReadOnly ProtectRegKey 007a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lsp32_util.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lspdiag.exe RecursiveReadOnly ProtectRegKey 007a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_lspdiag_64.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_di.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\swi_fc.exe RecursiveReadOnly ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WSCClient.exe RecursiveReadOnly ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVCleanupService.exe RecursiveReadOnly ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAVTelem.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavProgress.exe RecursiveReadOnly ProtectRegKey 0083:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForceUpdateAlongSideSGN.exe RecursiveReadOnly ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sav32cli.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCService.exe RecursiveReadOnly ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCDevCon.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDCDevCon64.exe RecursiveReadOnly ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavProxy.exe RecursiveReadOnly ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ConfigureSAV.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ALSvc.exe RecursiveReadOnly ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUpdate.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AlMon.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GatherTelem.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SubmitTelem.exe RecursiveReadOnly ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AUTelem.exe RecursiveReadOnly ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFileScanner.exe RecursiveReadOnly ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFS.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ssp.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDRService.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDService.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDcli.exe RecursiveReadOnly ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDTelemetry.exe RecursiveReadOnly ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SEDuninstall.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SSPService.exe RecursiveReadOnly ProtectRegKey 0085:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileAnalyzerSubmitterTool.exe RecursiveReadOnly ProtectRegKey 007f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFileSubmitter.exe RecursiveReadOnly ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SSPTelemetry.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SspEdr.exe RecursiveReadOnly ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNA.exe RecursiveReadOnly ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McsAgent.exe RecursiveReadOnly ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McsClient.exe RecursiveReadOnly ProtectRegKey 007c:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNtpService.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSnort.exe RecursiveReadOnly ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosIPS.exe RecursiveReadOnly ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Sophos UI.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SavApi.exe RecursiveReadOnly ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSafeStore32.exe RecursiveReadOnly ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSafeStore64.exe RecursiveReadOnly ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM.exe RecursiveReadOnly ProtectRegKey 007a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM32.exe RecursiveReadOnly ProtectRegKey 007a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosCleanM64.exe RecursiveReadOnly ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hmpalert.exe RecursiveReadOnly ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EXPTelem.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SLDService.exe RecursiveReadOnly ProtectRegKey 007c:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFIMService.exe RecursiveReadOnly ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFIMTelemetry.exe RecursiveReadOnly ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosHealth.exe RecursiveReadOnly ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosHealthClient.exe RecursiveReadOnly ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFSTelemetry.exe RecursiveReadOnly ProtectRegKey 007a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosFSVerify.exe RecursiveReadOnly ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosNtpTelemetry.exe RecursiveReadOnly ProtectRegKey 007d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUITelemetry.exe RecursiveReadOnly ProtectRegKey 007b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosUpdateMgr.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SUMService.exe RecursiveReadOnly ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSSEUninstall.exe RecursiveReadOnly ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSSEValidator.exe RecursiveReadOnly ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSMEUninstall.exe RecursiveReadOnly ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosSMEValidator.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosDiag.exe RecursiveReadOnly ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosESH.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MLFileInfo.exe RecursiveReadOnly ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-repair.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-setup32.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\su-setup64.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sducli.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sdugui.exe RecursiveReadOnly ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EfwTelemetryPlugin.exe RecursiveReadOnly ProtectRegKey 0088:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SophosAmsiTelemetryCollector.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVService.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVAdminService.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosBootTasks.exe RecursiveReadOnly ProtectRegKey 005e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssr32.exe RecursiveReadOnly ProtectRegKey 005e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssr64.exe RecursiveReadOnly ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swc_service.exe RecursiveReadOnly ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_service.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_filter.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_update.exe RecursiveReadOnly ProtectRegKey 0066:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_update_64.exe RecursiveReadOnly ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lsp32_util.exe RecursiveReadOnly ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lspdiag.exe RecursiveReadOnly ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lspdiag_64.exe RecursiveReadOnly ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_di.exe RecursiveReadOnly ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_fc.exe RecursiveReadOnly ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\WSCClient.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVCleanupService.exe RecursiveReadOnly ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVTelem.exe RecursiveReadOnly ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavProgress.exe RecursiveReadOnly ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ForceUpdateAlongSideSGN.exe RecursiveReadOnly ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sav32cli.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCService.exe RecursiveReadOnly ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCDevCon.exe RecursiveReadOnly ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCDevCon64.exe RecursiveReadOnly ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavProxy.exe RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ConfigureSAV.exe RecursiveReadOnly ProtectRegKey 005e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ALSvc.exe RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUpdate.exe RecursiveReadOnly ProtectRegKey 005e:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\AlMon.exe RecursiveReadOnly ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\GatherTelem.exe RecursiveReadOnly ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SubmitTelem.exe RecursiveReadOnly ProtectRegKey 0060:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\AUTelem.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFileScanner.exe RecursiveReadOnly ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFS.exe RecursiveReadOnly ProtectRegKey 005c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssp.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDRService.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDService.exe RecursiveReadOnly ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDcli.exe RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDTelemetry.exe RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDuninstall.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SSPService.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\FileAnalyzerSubmitterTool.exe RecursiveReadOnly ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFileSubmitter.exe RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SSPTelemetry.exe RecursiveReadOnly ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SspEdr.exe RecursiveReadOnly ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNA.exe RecursiveReadOnly ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\McsAgent.exe RecursiveReadOnly ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\McsClient.exe RecursiveReadOnly ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNtpService.exe RecursiveReadOnly ProtectRegKey 0064:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSnort.exe RecursiveReadOnly ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosIPS.exe RecursiveReadOnly ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\Sophos UI.exe RecursiveReadOnly ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavApi.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSafeStore32.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSafeStore64.exe RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM.exe RecursiveReadOnly ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM32.exe RecursiveReadOnly ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM64.exe RecursiveReadOnly ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\hmpalert.exe RecursiveReadOnly ProtectRegKey 0061:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\EXPTelem.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SLDService.exe RecursiveReadOnly ProtectRegKey 0069:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFIMService.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFIMTelemetry.exe RecursiveReadOnly ProtectRegKey 0065:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosHealth.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosHealthClient.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFSTelemetry.exe RecursiveReadOnly ProtectRegKey 0067:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFSVerify.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNtpTelemetry.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUITelemetry.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUpdateMgr.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SUMService.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSSEUninstall.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSSEValidator.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSMEUninstall.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSMEValidator.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosDiag.exe RecursiveReadOnly ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosESH.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\MLFileInfo.exe RecursiveReadOnly ProtectRegKey 0062:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-repair.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-setup32.exe RecursiveReadOnly ProtectRegKey 0063:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-setup64.exe RecursiveReadOnly ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sducli.exe RecursiveReadOnly ProtectRegKey 005f:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sdugui.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\EfwTelemetryPlugin.exe RecursiveReadOnly ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosAmsiTelemetryCollector.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVService.exe RecursiveReadOnly ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVAdminService.exe RecursiveReadOnly ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosBootTasks.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssr32.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssr64.exe RecursiveReadOnly ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swc_service.exe RecursiveReadOnly ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_service.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_filter.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_update.exe RecursiveReadOnly ProtectRegKey 0072:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_update_64.exe RecursiveReadOnly ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lsp32_util.exe RecursiveReadOnly ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lspdiag.exe RecursiveReadOnly ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_lspdiag_64.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_di.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\swi_fc.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\WSCClient.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVCleanupService.exe RecursiveReadOnly ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SAVTelem.exe RecursiveReadOnly ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavProgress.exe RecursiveReadOnly ProtectRegKey 007c:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ForceUpdateAlongSideSGN.exe RecursiveReadOnly ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sav32cli.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCService.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCDevCon.exe RecursiveReadOnly ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDCDevCon64.exe RecursiveReadOnly ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavProxy.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ConfigureSAV.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ALSvc.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUpdate.exe RecursiveReadOnly ProtectRegKey 006a:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\AlMon.exe RecursiveReadOnly ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\GatherTelem.exe RecursiveReadOnly ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SubmitTelem.exe RecursiveReadOnly ProtectRegKey 006c:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\AUTelem.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFileScanner.exe RecursiveReadOnly ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFS.exe RecursiveReadOnly ProtectRegKey 0068:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ssp.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SDRService.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDService.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDcli.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDTelemetry.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SEDuninstall.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SSPService.exe RecursiveReadOnly ProtectRegKey 007e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\FileAnalyzerSubmitterTool.exe RecursiveReadOnly ProtectRegKey 0078:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFileSubmitter.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SSPTelemetry.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SspEdr.exe RecursiveReadOnly ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNA.exe RecursiveReadOnly ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\McsAgent.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\McsClient.exe RecursiveReadOnly ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNtpService.exe RecursiveReadOnly ProtectRegKey 0070:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSnort.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosIPS.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\Sophos UI.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SavApi.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSafeStore32.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSafeStore64.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM.exe RecursiveReadOnly ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM32.exe RecursiveReadOnly ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosCleanM64.exe RecursiveReadOnly ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\hmpalert.exe RecursiveReadOnly ProtectRegKey 006d:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\EXPTelem.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SLDService.exe RecursiveReadOnly ProtectRegKey 0075:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFIMService.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFIMTelemetry.exe RecursiveReadOnly ProtectRegKey 0071:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosHealth.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosHealthClient.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFSTelemetry.exe RecursiveReadOnly ProtectRegKey 0073:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosFSVerify.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosNtpTelemetry.exe RecursiveReadOnly ProtectRegKey 0076:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUITelemetry.exe RecursiveReadOnly ProtectRegKey 0074:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosUpdateMgr.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SUMService.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSSEUninstall.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSSEValidator.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSMEUninstall.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosSMEValidator.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosDiag.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosESH.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\MLFileInfo.exe RecursiveReadOnly ProtectRegKey 006e:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-repair.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-setup32.exe RecursiveReadOnly ProtectRegKey 006f:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\su-setup64.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sducli.exe RecursiveReadOnly ProtectRegKey 006b:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\sdugui.exe RecursiveReadOnly ProtectRegKey 0077:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\EfwTelemetryPlugin.exe RecursiveReadOnly ProtectRegKey 0081:\REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\SophosAmsiTelemetryCollector.exe RecursiveReadOnly ProtectDirectory 0013:%SophosProgramData% AllowChangeSubDirs ProtectDirectory 0020:%SophosProgramData%\Certificates AllowChangeSubDirs ProtectDirectory 001a:%SophosProgramFilesNative% AllowChangeSubDirs ProtectDirectory 0016:%SophosProgramFiles32% AllowChangeSubDirs ProtectDirectory 002b:%SophosProgramFilesNative%\Endpoint Defense RecursiveReadOnly ProtectDirectory 0024:%SophosProgramData%\Endpoint Defense RecursiveReadOnly AttestFile 000e:SEDAdapter.dll 475808 fd1f03cad157c02ddbacfa78f90a388db490531ab7daeb3cb2074e3269727d04 AttestFile 000a:SEDcli.exe 358608 d9798d193340c173a994d2ffc39c707b209c5ed970b28b82f7cd89c2b1ceda29 AttestFile 000e:SEDService.exe 3477760 f3447c6c8572dfbc99ab204bfd64569e8078f37d37abf69cf0383d4c0f2fce31 AttestFile 0010:SEDTelemetry.exe 451600 afb0508843f57b4790ccf0970d61756eeeb8e0ae5f5e8a90663d617cb11efc73 AttestFile 0010:SEDuninstall.exe 1462912 94ef75dea5b328b18c9803353f552e76130a1ba93b6afeee146ce23a78f84d5d AttestFile 0009:Setup.dll 929816 c56bf665af92fde779808cd2f8aee7ad7ce62e192e77bc9f4b4c955da6eebc0d AttestFile 000c:SophosED.sys 1188944 33e87e27ea70c0ee42a603984eb0ff6c619c075b8d410b30f2a05b244c78c3fb AttestFile 000c:SophosEL.sys 22152 4e76c64d08b3f2860304875464fc2e63b6c47551fee911c5ff3e8856f4050219 AttestFile 0017:SophosFileSubmitter.exe 1651960 4c46b81fccf66c58db2d1717611daf6cbfad23493bad472eee98f9bf5ed654ae AttestFile 000c:SophosNA.exe 40288 c631924bd527fef5919cad9254d10bfb7facdb78c3297d427cefff003466221e AttestFile 000c:sophtlib.dll 1721328 ddbb26ede4f8ce869383d0415d69b09eed7b7c75101865b45361a7ecc695cefa AttestFile 000a:SspEdr.exe 3173560 168ab2df844bd084a0df5d5c70820fc855a934ec21c957af7158542ef4c3d9cd AttestFile 000e:SSPService.exe 10578600 1ec2d2cbc50e5f3c03a593dcddd01fff0e01f5a80a27f2f4f951f55ffa3330d4 AttestFile 0010:SSPTelemetry.exe 625688 fde491a563c69e9b422967f800204a7846904c21f25ba1a1c62fca6cf7ef8ea8 DigitalSignature 0005:TP001 RSA-2048_SHA-256 0158:KK4va6ecuQ1pl6O8PztRC5FIf830Nbr7bPzGgEdGn763YEWr5S+BbwVFi0cloLLBBdNMVL5mUW/qpRLmO+YWbDRGtKsl+Shcm1DmcSxB8XgPyZEotddR55v/kk7K5pL7bJ2lMmryliJferfqySnQZlnUjjXxYGw6IL9qdN3GJnZlw7lbY7oLPb28QyIAU2q+/LeELTtHhkr0oH6NaLreqxmGMURkwU7uIwng37FxEdVuPVzDYehxMT3hios2fvqWEXs0SChAHuddeK/7ROwzfHpNFDWWn9tRw7+JWligRQo4Xzon/qVl9Fn3+3hAwdW6E3Oj9NsXIXawRG0nOTPuLg==