Buster wrote:nick s: Try version 1.04 and let me know if the wildcard feature works as expected.
Working well so far. For example,
machine\system\*Control*\Control\Session Manager\* captured the following deletions:
machine\SYSTEM\ControlSet001\Control\Session Manager\BootExecute = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\CriticalSectionTimeout = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\ExcludeFromKnownDlls = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\GlobalFlag = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\HeapDeCommitFreeBlockThreshold = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\HeapDeCommitTotalFreeThreshold = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\HeapSegmentCommit = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\HeapSegmentReserve = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\NumberOfInitialSessions = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\ObjectDirectories = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\ProcessorControl = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\ProtectionMode = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\ResourceTimeoutCount = deleted value key
machine\SYSTEM\ControlSet001\Control\Session Manager\SetupExecute = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\BootExecute = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\CriticalSectionTimeout = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\ExcludeFromKnownDlls = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\GlobalFlag = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\HeapDeCommitFreeBlockThreshold = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\HeapDeCommitTotalFreeThreshold = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\HeapSegmentCommit = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\HeapSegmentReserve = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\NumberOfInitialSessions = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\ObjectDirectories = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\ProcessorControl = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\ProtectionMode = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\ResourceTimeoutCount = deleted value key
machine\SYSTEM\ControlSet002\Control\Session Manager\SetupExecute = deleted value key
Buster wrote:Do you plan sharing Malware Defender's default registry rules? It would be nice!
Of course
. Since there are about 200 rules, it will take me a couple of more days to convert and organize them.