C:\Users\Marek>REG QUERY HKLM\SYSTEM\CurrentControlSet\Services\WinDefend /S
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend
DisplayName REG_SZ Windows Defender
ErrorControl REG_DWORD 0x1
ImagePath REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k secsvcs
Start REG_DWORD 0x3
Type REG_DWORD 0x20
Description REG_SZ @%ProgramFiles%\Windows Defender\MsMpRes.dll,-1176
DependOnService REG_MULTI_SZ RpcSs
ObjectName REG_SZ LocalSystem
ServiceSidType REG_DWORD 0x1
RequiredPrivileges REG_MULTI_SZ SeImpersonatePrivilege\0SeBackupPrivil
ege\0SeRestorePrivilege\0SeDebugPrivilege\0SeChangeNotifyPrivilege\0SeSecurityPr
ivilege\0SeShutdownPrivilege\0SeIncreaseQuotaPrivilege\0SeAssignPrimaryTokenPriv
ilege
DelayedAutoStart REG_DWORD 0x0
FailureActions REG_NONE 8051010000000000000000000300000014000000010000
0060EA00000100000060EA00000000000000000000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend\Parameters
ServiceDllUnloadOnStop REG_DWORD 0x1
ServiceDll REG_EXPAND_SZ %ProgramFiles(x86)%\Windows Defender\mpsvc.dl
l
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend\Security
Security REG_BINARY 01001480DC000000E8000000140000003000000002001C0001
00000002801400FF010F000101000000000001000000000200AC000600000000002800FF010F0001
0600000000000550000000B589FB381984C2CB5C6C236D5700776EC0026487000B28000000001001
0600000000000550000000B589FB381984C2CB5C6C236D5700776EC002648700001400FD01020001
010000000000051200000000001800FF010F0001020000000000052000000020020000000014009D
010200010100000000000504000000000014009D0102000101000000000005060000000101000000
00000512000000010100000000000512000000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend\TriggerInfo
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend\TriggerInfo\0
Type REG_DWORD 0x5
Action REG_DWORD 0x1
GUID REG_BINARY E6CA9F65DB5BA94DB1FFCA2A178D46E0