<?xml version="1.0" encoding="UTF-8"?>
<epo:EPOPolicySchema xmlns:epo="mcafee-epo-policy" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<EPOPolicyVerInfo vermjr="5" vermin="9" verrel="1" verbld="0"/>
<EPOPolicySettings name="McAfee Default (copy)::Settings (5251B0C9-F3DC-4C23-A949-BA34ECDD42D1)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="ACIntUsr.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Altiris1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="aclient.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Altiris2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="AeXNSAgent.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Altiris3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Altiris"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (CEDC2033-DC34-46F9-82C2-62AFAD0907E0)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="aspnet_wp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value=".NETFrame1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="ConfigWizards.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value=".NETFrame2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="mscorsvw.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value=".NETFrame3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="netfxupdate.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value=".NETFrame4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value=".Net Framework"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (3C8BEB61-F4DB-4457-9CCD-EFA39406C0C5)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="RemStart.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SymPC1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="Thdefault.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SymPC2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="pcalu.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SymPC3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Symantec PcAnywhere"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (8E04C387-823C-45C1-AE09-FFA3972E2FB8)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="msmdsrv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SQL1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_10">
<Setting name="binary" value="SQLServerBackup.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SQL55"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="dexplore.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_11">
<Setting name="binary" value="MySQLInstanceConfig.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SQL56"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="mscorsvw.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SQL2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="sservice.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SQL3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="SqlWb.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SQL4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="SQLServerBackup.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SQL5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="msmdsrv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SQL51"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="mscorsvw.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SQL52"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="sservice.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SQL53"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_9">
<Setting name="binary" value="SqlWb.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SQL54"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="My SQL Server"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (64EE11F5-81F7-49E7-BE3C-08C37CC1BB72)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="crw32.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="CRP1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="agent.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="CRP2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="ISDM.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="CRP3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Crystal Reports"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (8840DD3C-74A3-4B9E-9D35-91E1B0D037EC)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="ashsimpl.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_10">
<Setting name="binary" value="aswSimp2.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast10"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_11">
<Setting name="binary" value="ashSimp2.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast11"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_12">
<Setting name="binary" value="aswBoot.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast12"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_13">
<Setting name="binary" value="ashWebSv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast13"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_14">
<Setting name="binary" value="avastsvc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast14"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="swwserv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="aswclnr.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="ashDisp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="ashserv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="aswServ.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="aswEnhcd.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="aswdisp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_9">
<Setting name="binary" value="aswSimpl.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Avast9"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Avast Virus Cleaner"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (14028856-9D9B-48BF-81D0-514B35F45CA7)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="iexplore.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="library" value="QCClient.UI.Core.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="HP_Quality_Center1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="HP Quality Center"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (C07BEE62-3728-4116-9F47-BA5B48F0E448)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="cmd.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="userinit.exe"/>
<Setting name="tag" value="Citrix_Server1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="aspnet_wp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Citrix_Server2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="w3wp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Citrix_Server3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="acregl.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Citrix_Server4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="ctxhide.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Citrix_Server5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="ImaSrv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Citrix_Server6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Citrix Metaframe Presentation Server"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (D996322C-FB6D-43DF-9F2B-41431B002FE9)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="IsntSmtp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_10">
<Setting name="binary" value="Patch.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro10"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="ReportServer.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_101">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="ReportServer.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_102">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="tmasea.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_103">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="tmasea.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_11">
<Setting name="binary" value="cmdprocessor.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro11"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_12">
<Setting name="binary" value="Pccguide.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro12"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_13">
<Setting name="binary" value="Pccmain.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro13"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_14">
<Setting name="binary" value="Tmas.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro14"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_15">
<Setting name="binary" value="iexplore.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="library" value="jupdate.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro15"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_16">
<Setting name="binary" value="tmasea.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro16"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_17">
<Setting name="binary" value="SMEX_Master.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro17"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_18">
<Setting name="binary" value="PccNT2.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro18"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_19">
<Setting name="binary" value="SfFnUp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro19"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="Scheduler.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_20">
<Setting name="binary" value="SfCtlCom.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro20"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_21">
<Setting name="binary" value="Patch.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro21"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_22">
<Setting name="binary" value="UfSeAgnt.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro22"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_23">
<Setting name="binary" value="TMBMSRV.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro23"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_24">
<Setting name="binary" value="TmProxy.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro24"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_25">
<Setting name="binary" value="coreServiceShell.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro25"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_26">
<Setting name="binary" value="SupportTool.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro26"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_27">
<Setting name="binary" value="IsntSmtp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_28">
<Setting name="binary" value="Scheduler.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_29">
<Setting name="binary" value="scheduler.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="cmd.exe"/>
<Setting name="tag" value="TrendMicro3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="scheduler.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="cmd.exe"/>
<Setting name="tag" value="TrendMicro3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_30">
<Setting name="binary" value="NTRtscan.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_31">
<Setting name="binary" value="TmListen.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_32">
<Setting name="binary" value="PccNT.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_33">
<Setting name="binary" value="Spntsvc.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_34">
<Setting name="binary" value="EarthAgent.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_35">
<Setting name="binary" value="Patch.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro10"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_36">
<Setting name="binary" value="cmdprocessor.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro11"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_37">
<Setting name="binary" value="Pccguide.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro12"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_38">
<Setting name="binary" value="Pccmain.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro13"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_39">
<Setting name="binary" value="Tmas.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro14"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="NTRtscan.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_40">
<Setting name="binary" value="iexplore.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="library" value="jupdate.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro15"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_41">
<Setting name="binary" value="tmasea.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro16"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_42">
<Setting name="binary" value="SMEX_Master.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro18"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="TmListen.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="PccNT.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="Spntsvc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="EarthAgent.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_9">
<Setting name="binary" value="supportcustomizedpackage.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TrendMicro9"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Trend Micro AV"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (CA254238-50B3-4239-804E-CA3CCD1E9431)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="RemotelyAnywhere.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="RAW1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Remotely Anywhere"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (C5B6F340-19D9-426F-BFB7-FF44EAEA533A)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="FlashplayerUpdateService.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FlashplayerUpdateService1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Flash Player"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (11FA7CCC-AAEB-4E16-B11E-2AA5B91F03EF)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="wuauclt.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="WD1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="MsMpEng.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="WD2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="mpas-fe.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="WD3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="svchost.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="library" value="mpengine.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="WD4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="MSASCui.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="WD5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Windows Defender"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (C927B36F-AB89-47AE-8422-D86D1DB600DA)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="sysocmgr.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Comp1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="cleanmgr.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Comp2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="shrpubw.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Comp3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="dfssvc.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Comp4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="wmiadap.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Comp5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="compmgmtlauncher.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Comp6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="ServerManagerLauncher.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Comp7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="SMSS.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Windows_Session_Manager1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Windows Component"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (5EB10814-763C-4D3A-94E6-BAC33ED71114)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="cqmghost.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="HPIM1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="HP/Compaq Insight Manager"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (0B0267C3-FBAA-4980-BE60-CDFD3E6A950B)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Nvidiadaemonu1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Nvidia"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (FF0D439F-ECC5-43FB-A259-0DC940F54B33)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Updater.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FProt1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="FPWin.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_101">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="FPWin.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="F-Prot AV"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (2E90172A-F5E6-4A53-9D7A-F140B199E641)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Lcfd.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TSM_Server2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="Lcfep.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TSM_Server3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="Wlcftap.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TSM_Server4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Tivoli Storage Management Server"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (DDCFC1BC-E048-4D90-A97A-34AA1B2730CE)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="InoRt.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_10">
<Setting name="binary" value="InoTask.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust10"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="install.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_101">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="casc.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_102">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="caunst.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_103">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="InoRpc.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_104">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="ITMDist.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_105">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="InoTask.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_106">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="InoRT.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_11">
<Setting name="binary" value="igateway.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust11"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_12">
<Setting name="binary" value="PPV5Updater.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust12"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_13">
<Setting name="binary" value="ppupdstub.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust13"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_14">
<Setting name="binary" value="PPActiveDetection.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust14"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_15">
<Setting name="binary" value="ppv5consumercl.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust15"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_16">
<Setting name="binary" value="ppmc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust16"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_17">
<Setting name="binary" value="casc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust17"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_18">
<Setting name="binary" value="caavguiscan.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust18"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_19">
<Setting name="binary" value="ccupdate.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust19"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="InoDist.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_20">
<Setting name="binary" value="autodown.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust20"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_21">
<Setting name="binary" value="UpdatePatch.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust21"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_22">
<Setting name="binary" value="ITMDist.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust22"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="isafe.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="cav.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="ppdoupdate.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="InocIT.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="Shellscn.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="vetmsg.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_9">
<Setting name="binary" value="PestPatrol5.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ETrust9"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="ETrust"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (934E8DE2-3B5D-4A8A-89AA-BB7359D4D687)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="w3wp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="IP2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Internet Printing"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (C851720E-4669-43DC-A7A7-B3883ECFE83C)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="svchost.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="library" value="upnphost.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="UPnP1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="USB Plug and Play"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (9EDBAD11-31BE-45FF-B92F-99C2CD9DAA09)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="caadagent.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="NetproCAAD1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="NPSrvHost.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="NetproCAAD2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Netpro Change Auditor for Active Directory"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (1F741063-9042-4FF7-849E-5A98E79AA257)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="CmafReportSrv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSE1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="Symantec.Cmaf.UI.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSE2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Symantec Mail Security"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (D33F4D3E-E7F0-4771-B543-0D684809A88E)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="AVKWCtl.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="GDATA1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="GDATA"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (68A58F40-F58C-48FB-B501-8AD35953A2DA)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="livesrv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="BTD1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdss.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_101">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdss.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_102">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdnews.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_103">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdnews.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_104">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdnagent.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_105">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdnagent.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_106">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdmcon.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_107">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdmcon.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_108">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="livesrv.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_109">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="livesrv.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_110">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdswitch.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_111">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdswitch.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_112">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdoesrv.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_113">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="bdoesrv.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="upgrepl.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="BTD2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="bdss.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="BTD3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="BitDefender"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (0700C425-B5B4-49EF-B637-367997355461)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="UEInstallService.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="BUI1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="St. Bernard UI Expert"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (26BD82BD-33EA-4B3C-B732-69B48CE135E6)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Admin.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="MicrosoftExch1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Microsoft Exchange"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (CA62F95A-A14D-4E74-90ED-0D5B2B7C8249)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="svchost.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="library" value="system32\wuauserv.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_10">
<Setting name="binary" value="MRT.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start11"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_11">
<Setting name="binary" value="poqexec.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start12"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_12">
<Setting name="binary" value="msiexec.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="winlogon.exe"/>
<Setting name="tag" value="RemoteSessionInstall1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_13">
<Setting name="binary" value="TrustedInstaller.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="services.exe"/>
<Setting name="tag" value="TrustedInstaller1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_14">
<Setting name="binary" value="drvinst.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="svchost.exe"/>
<Setting name="tag" value="DrvInst1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_15">
<Setting name="binary" value="QueryAppBlock.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start13"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_16">
<Setting name="binary" value="GWXConfigManager.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start14"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_17">
<Setting name="binary" value="System32\LogonUI.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_GdiPlus"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_18">
<Setting name="binary" value="svchost.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="library" value="system32\wups.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start15"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_19">
<Setting name="binary" value="svchost.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="library" value="system32\wups2.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start16"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="svchost.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="library" value="system32\wuaueng.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_20">
<Setting name="binary" value="TiWorker.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start17"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_21">
<Setting name="binary" value="wusa.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start18"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_22">
<Setting name="path" value="C:\Users\*\AppData\Local\Temp\*"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="true"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_23">
<Setting name="path" value="C:\Windows\SoftwareDistribution\DataStore\**"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="true"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_24">
<Setting name="path" value="C:\Windows\SoftwareDistribution\Download\**"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="true"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_25">
<Setting name="path" value="C:\Windows\System32\catroot2\**"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="true"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_26">
<Setting name="path" value="C:\Windows\WinSxS\Backup\*"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="true"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_27">
<Setting name="path" value="C:\Windows\WinSxS\Temp\**"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="true"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_28">
<Setting name="path" value="C:\Windows\WinSxS\Catalogs\**"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="true"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_29">
<Setting name="path" value="C:\Windows\WinSxS\Manifests\**"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="true"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="iexplore.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="library" value="wuweb.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_30">
<Setting name="path" value="\Windows\logs"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="wuauclt.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="svchost.exe"/>
<Setting name="tag" value="Win_Up_Start4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="update.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="svchost.exe"/>
<Setting name="tag" value="Win_Up_Start5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="bitinst.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="svchost.exe"/>
<Setting name="tag" value="Win_Up_Start7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="winlogon.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="helpctr.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start9"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_9">
<Setting name="binary" value="mscorsvw.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Win_Up_Start10"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Windows Update"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (03792578-5D55-4A75-8F5B-E620B2D1D479)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_361">
<Setting name="id" value="1"/>
<Setting name="pem_1" value="-----BEGIN CERTIFICATE-----&#xA;MIIFdTCCBF2gAwIBAgIQaKXIRyRS6Y1CVIjDmBwo+DANBgkqhkiG9w0BAQUFADCB&#xA;tDELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL&#xA;ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTswOQYDVQQLEzJUZXJtcyBvZiB1c2Ug&#xA;YXQgaHR0cHM6Ly93d3cudmVyaXNpZ24uY29tL3JwYSAoYykwNDEuMCwGA1UEAxMl&#xA;VmVyaVNpZ24gQ2xhc3MgMyBDb2RlIFNpZ25pbmcgMjAwNCBDQTAeFw0xMTEwMDYw&#xA;MDAwMDBaFw0xMzEyMzEyMzU5NTlaMIG0MQswCQYDVQQGEwJVUzETMBEGA1UECBMK&#xA;Q2FsaWZvcm5pYTEUMBIGA1UEBxMLU2FudGEgQ2xhcmExFTATBgNVBAoUDE1jQWZl&#xA;ZSwgSW5jLjE+MDwGA1UECxM1RGlnaXRhbCBJRCBDbGFzcyAzIC0gTWljcm9zb2Z0&#xA;IFNvZnR3YXJlIFZhbGlkYXRpb24gdjIxDDAKBgNVBAsUA0lJUzEVMBMGA1UEAxQM&#xA;TWNBZmVlLCBJbmMuMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmMj8&#xA;Ewy+9C8BaFKq0Wz8HJhLJcj/QKAeN2gRKb18jq09Dub6ZYpeXWSBwM6BugCjwbdz&#xA;8AilCjWVVPfVP5bILLHXQdwgdejiB7y5g9FWxKGnhNZyMuLKL5t5IS6OpcLl2402&#xA;/cPM8HawBo/DyZXqTqsRAVcJFTGdLl15CAvj0W9EO4rRWQ6y1qiuKnOJ30Omjgqg&#xA;CSjXt+gP32jd7WskPKqjpF7vrmIIyB2VRmgQJpVgUlndFrM1Brg0TTff8UlUegBf&#xA;RHZsbWaH8unDF6kZOBvcn4XjnbonHfeU0rngeozo/W3dzQm3RW6A4BE3IAo6rX68&#xA;D68p2SuztO15s6NVMwIDAQABo4IBfzCCAXswCQYDVR0TBAIwADAOBgNVHQ8BAf8E&#xA;BAMCB4AwRAYDVR0gBD0wOzA5BgtghkgBhvhFAQcXAzAqMCgGCCsGAQUFBwIBFhxo&#xA;dHRwczovL3d3dy52ZXJpc2lnbi5jb20vcnBhMBMGA1UdJQQMMAoGCCsGAQUFBwMD&#xA;MBEGCWCGSAGG+EIBAQQEAwIEEDAWBgorBgEEAYI3AgEbBAgwBgEBAAEB/zBABgNV&#xA;HR8EOTA3MDWgM6Axhi9odHRwOi8vQ1NDMy0yMDA0LWNybC52ZXJpc2lnbi5jb20v&#xA;Q1NDMy0yMDA0LmNybDB1BggrBgEFBQcBAQRpMGcwJAYIKwYBBQUHMAGGGGh0dHA6&#xA;Ly9vY3NwLnZlcmlzaWduLmNvbTA/BggrBgEFBQcwAoYzaHR0cDovL0NTQzMtMjAw&#xA;NC1haWEudmVyaXNpZ24uY29tL0NTQzMtMjAwNC1haWEuY2VyMB8GA1UdIwQYMBaA&#xA;FAj1Uej7/j09ZDZ8aM9beKjfucU3MA0GCSqGSIb3DQEBBQUAA4IBAQC8am3DDL8Z&#xA;rN+r9ixaouxCf8HIIqe2yPmK7at8vDgYEacaGvpvVAoOiUsbICBiXqPr7f7j4z9s&#xA;GLepTLBqsw+FmBeVwp9BNwZr5tdmdIbj3WKrbnSKxTJqnifzxbWPTt8ayJrlLSGY&#xA;cV2aV0bI29edPLkYoN8RCb441qhBZ8DV37mARwPJY3zxtV9wz0U1XD/8TZFZsNop&#xA;pJzgJiCAPiU5I2cg97YQZ1nRRs/fhp7WIDlhDw6M0/pNgjNkIUss3Sz7+FyvhO5R&#xA;M4GczAGldC/nZYdUXvdoIDaksRk8l2uHS5BJTwf3hK7qa9FsB0537f791PAf41kE&#xA;lEpzeGOzQotM&#xA;-----END CERTIFICATE-----&#xA;"/>
<Setting name="pem_length" value="1952"/>
<Setting name="type" value="cert"/>
</Section>
<Section name="General_Rule_369">
<Setting name="id" value="9"/>
<Setting name="pem_1" value="-----BEGIN CERTIFICATE-----&#xA;MIIE8TCCA9mgAwIBAgIQVko2HhaKgajz76raMyUI4TANBgkqhkiG9w0BAQUFADCB&#xA;tDELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL&#xA;ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTswOQYDVQQLEzJUZXJtcyBvZiB1c2Ug&#xA;YXQgaHR0cHM6Ly93d3cudmVyaXNpZ24uY29tL3JwYSAoYykwNDEuMCwGA1UEAxMl&#xA;VmVyaVNpZ24gQ2xhc3MgMyBDb2RlIFNpZ25pbmcgMjAwNCBDQTAeFw0wODA5MTMw&#xA;MDAwMDBaFw0xMTEwMDkyMzU5NTlaMIG0MQswCQYDVQQGEwJVUzETMBEGA1UECBMK&#xA;Q2FsaWZvcm5pYTEUMBIGA1UEBxMLU2FudGEgQ2xhcmExFTATBgNVBAoUDE1jQWZl&#xA;ZSwgSW5jLjE+MDwGA1UECxM1RGlnaXRhbCBJRCBDbGFzcyAzIC0gTWljcm9zb2Z0&#xA;IFNvZnR3YXJlIFZhbGlkYXRpb24gdjIxDDAKBgNVBAsUA0lJUzEVMBMGA1UEAxQM&#xA;TWNBZmVlLCBJbmMuMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQClahTb11zA&#xA;NN/vaHSR1+3wkSo3YsGx3pSbGRdFweLoWbo8FKBuqX/fl8QBLBBaX5oHWD+o0Fg0&#xA;0fqYsAQ3fcYRr2D6/vMrq2Ujr4LkvvYtxIX+bayXU+bFxc+6F5YQD8xQXX0b7jtn&#xA;XvT4q+qPnP6t0AWRQGcXFxtqFEoTEokZFQIDAQABo4IBfzCCAXswCQYDVR0TBAIw&#xA;ADAOBgNVHQ8BAf8EBAMCB4AwQAYDVR0fBDkwNzA1oDOgMYYvaHR0cDovL0NTQzMt&#xA;MjAwNC1jcmwudmVyaXNpZ24uY29tL0NTQzMtMjAwNC5jcmwwRAYDVR0gBD0wOzA5&#xA;BgtghkgBhvhFAQcXAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy52ZXJpc2ln&#xA;bi5jb20vcnBhMBMGA1UdJQQMMAoGCCsGAQUFBwMDMHUGCCsGAQUFBwEBBGkwZzAk&#xA;BggrBgEFBQcwAYYYaHR0cDovL29jc3AudmVyaXNpZ24uY29tMD8GCCsGAQUFBzAC&#xA;hjNodHRwOi8vQ1NDMy0yMDA0LWFpYS52ZXJpc2lnbi5jb20vQ1NDMy0yMDA0LWFp&#xA;YS5jZXIwHwYDVR0jBBgwFoAUCPVR6Pv+PT1kNnxoz1t4qN+5xTcwEQYJYIZIAYb4&#xA;QgEBBAQDAgQQMBYGCisGAQQBgjcCARsECDAGAQEAAQH/MA0GCSqGSIb3DQEBBQUA&#xA;A4IBAQAB1jGjh+hZT7RhGS33HVpv3fzXN7TFPI0wr820CdsBQdnjhxWw3+O27vs2&#xA;KwR2/WlD0NQUSjOy7+wy8RL1N+SW4dBmuaALl0qTiM3fKBsoCd3AMa9Or2EeQKjp&#xA;5tyknk6HGIC3i/GIzArvuR7Ve0bo3Lqg9g+lRf/ctnivcM0VH3Yq6UqPCp/88mkw&#xA;JXO6sq2FrL6MqAuR/tkQaofNdZmC5UpcJPqP5vTvd+Yx0znNAcpKcqFgkiuNccuq&#xA;4BJpmt8EAa6tIlMV071bsdZJwejl4louO6bvs47szKSveV1Si0A5q/zk3YUb5epL&#xA;6G4q7bf2it5hyepu/Pt3mkCfNdAv&#xA;-----END CERTIFICATE-----&#xA;"/>
<Setting name="pem_length" value="1773"/>
<Setting name="type" value="cert"/>
</Section>
<Section name="General_Rule_370">
<Setting name="id" value="10"/>
<Setting name="pem_1" value="-----BEGIN CERTIFICATE-----&#xA;MIIFcTCCBFmgAwIBAgIQH5nfCoBymkt8t1wcfktHPTANBgkqhkiG9w0BAQUFADCB&#xA;tDELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL&#xA;ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTswOQYDVQQLEzJUZXJtcyBvZiB1c2Ug&#xA;YXQgaHR0cHM6Ly93d3cudmVyaXNpZ24uY29tL3JwYSAoYykxMDEuMCwGA1UEAxMl&#xA;VmVyaVNpZ24gQ2xhc3MgMyBDb2RlIFNpZ25pbmcgMjAxMCBDQTAeFw0xMTA5MDYw&#xA;MDAwMDBaFw0xNDEwMDgyMzU5NTlaMIG0MQswCQYDVQQGEwJVUzETMBEGA1UECBMK&#xA;Q2FsaWZvcm5pYTEUMBIGA1UEBxMLU2FudGEgQ2xhcmExFTATBgNVBAoUDE1jQWZl&#xA;ZSwgSW5jLjE+MDwGA1UECxM1RGlnaXRhbCBJRCBDbGFzcyAzIC0gTWljcm9zb2Z0&#xA;IFNvZnR3YXJlIFZhbGlkYXRpb24gdjIxDDAKBgNVBAsUA0lJUzEVMBMGA1UEAxQM&#xA;TWNBZmVlLCBJbmMuMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmMj8&#xA;Ewy+9C8BaFKq0Wz8HJhLJcj/QKAeN2gRKb18jq09Dub6ZYpeXWSBwM6BugCjwbdz&#xA;8AilCjWVVPfVP5bILLHXQdwgdejiB7y5g9FWxKGnhNZyMuLKL5t5IS6OpcLl2402&#xA;/cPM8HawBo/DyZXqTqsRAVcJFTGdLl15CAvj0W9EO4rRWQ6y1qiuKnOJ30Omjgqg&#xA;CSjXt+gP32jd7WskPKqjpF7vrmIIyB2VRmgQJpVgUlndFrM1Brg0TTff8UlUegBf&#xA;RHZsbWaH8unDF6kZOBvcn4XjnbonHfeU0rngeozo/W3dzQm3RW6A4BE3IAo6rX68&#xA;D68p2SuztO15s6NVMwIDAQABo4IBezCCAXcwCQYDVR0TBAIwADAOBgNVHQ8BAf8E&#xA;BAMCB4AwQAYDVR0fBDkwNzA1oDOgMYYvaHR0cDovL2NzYzMtMjAxMC1jcmwudmVy&#xA;aXNpZ24uY29tL0NTQzMtMjAxMC5jcmwwRAYDVR0gBD0wOzA5BgtghkgBhvhFAQcX&#xA;AzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy52ZXJpc2lnbi5jb20vcnBhMBMG&#xA;A1UdJQQMMAoGCCsGAQUFBwMDMHEGCCsGAQUFBwEBBGUwYzAkBggrBgEFBQcwAYYY&#xA;aHR0cDovL29jc3AudmVyaXNpZ24uY29tMDsGCCsGAQUFBzAChi9odHRwOi8vY3Nj&#xA;My0yMDEwLWFpYS52ZXJpc2lnbi5jb20vQ1NDMy0yMDEwLmNlcjAfBgNVHSMEGDAW&#xA;gBTPmanqeyb0S8mOj9fwBSbv49KnnTARBglghkgBhvhCAQEEBAMCBBAwFgYKKwYB&#xA;BAGCNwIBGwQIMAYBAQABAf8wDQYJKoZIhvcNAQEFBQADggEBALUaIKnZsNSYmhbb&#xA;mF9LUU9H+riVcXYJ5n1LoYVnAPJzUTyJLsA+C4vEPd3b20JD1z/gtcZkvL5aRWIj&#xA;io47+iGy72b8jT0OyI8xfITLT+sIHRFUolO3p0rvKTUxb+nJYe5uvzyMLH/EUZ3+&#xA;nXtzSOn6s+NXxwR5avMbLJMahRituifR6HusYh6u7S/Z6+TT5/+CbwozhRLCmIWy&#xA;6BvbiFsA5UFlrMUkOcn2uwNAs3Qe0i6QQdYAjZR4IFxfQ6+vEDzfEEcXutpxnraT&#xA;taXlcQfgvOd9Z/MqSWWtBlZ1Cne6FnaWXbZJTBc1jREyCyIfho+pm3sZ2x6+0nSO&#xA;SmmWfT8=&#xA;-----END CERTIFICATE-----&#xA;"/>
<Setting name="pem_length" value="1948"/>
<Setting name="type" value="cert"/>
</Section>
<Section name="General_Rule_371">
<Setting name="id" value="11"/>
<Setting name="pem_1" value="-----BEGIN CERTIFICATE-----&#xA;MIIFdTCCBF2gAwIBAgIQXcmLmt0bMAkJg8vlO55kBjANBgkqhkiG9w0BAQUFADCB&#xA;tDELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL&#xA;ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTswOQYDVQQLEzJUZXJtcyBvZiB1c2Ug&#xA;YXQgaHR0cHM6Ly93d3cudmVyaXNpZ24uY29tL3JwYSAoYykxMDEuMCwGA1UEAxMl&#xA;VmVyaVNpZ24gQ2xhc3MgMyBDb2RlIFNpZ25pbmcgMjAxMCBDQTAeFw0xNDAzMDUw&#xA;MDAwMDBaFw0xNzAzMDQyMzU5NTlaMIG4MQswCQYDVQQGEwJVUzEPMA0GA1UECBMG&#xA;T3JlZ29uMRQwEgYDVQQHEwtTYW50YSBDbGFyYTEVMBMGA1UEChQMTWNBZmVlLCBJ&#xA;bmMuMT4wPAYDVQQLEzVEaWdpdGFsIElEIENsYXNzIDMgLSBNaWNyb3NvZnQgU29m&#xA;dHdhcmUgVmFsaWRhdGlvbiB2MjEUMBIGA1UECxQLRW5naW5lZXJpbmcxFTATBgNV&#xA;BAMUDE1jQWZlZSwgSW5jLjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB&#xA;AK0NSoWeSNyZT20TSVQ92PrFLzrdD736iXFpuZvdKy+5mZ928UxfURjWqozvSqXe&#xA;4bvJYMRtG04COoheT6GtBDy28rOT8GEpyrBVZYfjnpePyG7pFyiWiuAWo5RbphoD&#xA;aiYyE+Y+q9bpBIovN9VhiGlKstRxB/GwYTxqpAPnR3JqIXgHVUSw1jkQ2E0oLykr&#xA;5kmfR0BBXmzBVOstatB+zJk1nMDzRVlaIFFXm/6FeWqFhXDfHMsPx+EB8Yyv6OYO&#xA;XShRXJ+k8iZBnOu1IZVkyzQ6XSxrxW1KhoHBZpYDujBWCUj5Wh5NzT5m1PfERKhP&#xA;j9QpQMdRCl8qonm/y3jgLkUCAwEAAaOCAXswggF3MAkGA1UdEwQCMAAwDgYDVR0P&#xA;AQH/BAQDAgeAMEAGA1UdHwQ5MDcwNaAzoDGGL2h0dHA6Ly9jc2MzLTIwMTAtY3Js&#xA;LnZlcmlzaWduLmNvbS9DU0MzLTIwMTAuY3JsMEQGA1UdIAQ9MDswOQYLYIZIAYb4&#xA;RQEHFwMwKjAoBggrBgEFBQcCARYcaHR0cHM6Ly93d3cudmVyaXNpZ24uY29tL3Jw&#xA;YTATBgNVHSUEDDAKBggrBgEFBQcDAzBxBggrBgEFBQcBAQRlMGMwJAYIKwYBBQUH&#xA;MAGGGGh0dHA6Ly9vY3NwLnZlcmlzaWduLmNvbTA7BggrBgEFBQcwAoYvaHR0cDov&#xA;L2NzYzMtMjAxMC1haWEudmVyaXNpZ24uY29tL0NTQzMtMjAxMC5jZXIwHwYDVR0j&#xA;BBgwFoAUz5mp6nsm9EvJjo/X8AUm7+PSp50wEQYJYIZIAYb4QgEBBAQDAgQQMBYG&#xA;CisGAQQBgjcCARsECDAGAQEAAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQBrytB5WJSz&#xA;VDSTMq9yzDCO7J0K3cOoB4fdHp+wEWVmKRg8X6IRNIJVZ2GalMfqPiydWjyKTZYR&#xA;iWoYdAfNipPNC9suhI5nA4RA5Hslw9qNaNssZlJV9NTqw20K4W7XVYG9u8dsT4RP&#xA;1Mu6ikSpWOw2l6sqANMbsXO/hKAC+D1TpoOzuxsSrOjWe0tGoey6gyKk6v9MjQS7&#xA;m2I4rWd9WFxiUK/RJtQEfyKn0Tr9w4eu99hBv+U42nxPBtlRRSKBmsihzvPvGGeG&#xA;2WcETTYZyg35ner1M0rgR64tWQLa6KC/2WjMefN4oIE++LXTtJljLq+t2s7MvI7y&#xA;AKHYcVLb24UZ&#xA;-----END CERTIFICATE-----&#xA;"/>
<Setting name="pem_length" value="1952"/>
<Setting name="type" value="cert"/>
</Section>
<Section name="General_Rule_372">
<Setting name="id" value="12"/>
<Setting name="pem_1" value="-----BEGIN CERTIFICATE-----&#xA;MIIE5DCCA8ygAwIBAgIQY4WmCPvYWOtEcaAizOdrjzANBgkqhkiG9w0BAQsFADB/&#xA;MQswCQYDVQQGEwJVUzEdMBsGA1UEChMUU3ltYW50ZWMgQ29ycG9yYXRpb24xHzAd&#xA;BgNVBAsTFlN5bWFudGVjIFRydXN0IE5ldHdvcmsxMDAuBgNVBAMTJ1N5bWFudGVj&#xA;IENsYXNzIDMgU0hBMjU2IENvZGUgU2lnbmluZyBDQTAeFw0xNjA4MTYwMDAwMDBa&#xA;Fw0xOTA3MjEyMzU5NTlaMHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9y&#xA;bmlhMRQwEgYDVQQHDAtTYW50YSBDbGFyYTEVMBMGA1UECgwMTWNBZmVlLCBJbmMu&#xA;MRQwEgYDVQQLDAtFbmdpbmVlcmluZzEVMBMGA1UEAwwMTWNBZmVlLCBJbmMuMIIB&#xA;IjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAulpVWWQNNlJcniqUlNuuj9Xk&#xA;EylZ+yCJIAJW4oXhrTgUz9HB62XxwFlGlpdmMSOjHpx4xPfw6sIB+g5uR0qMAOJz&#xA;GPZmkZyCjJzkjJF6ovyejGh0m+q5xgO6WHJmQ8JFy63XQsf4Pasiyy33CacfZzIG&#xA;gXiybUG1MbjK9n0QHgjyJYKZ21CDkJ7rPbtbf65d1ZFkAmdbLF/w/ZeBJVqB3pSn&#xA;Li4I3ZNVpx42scVXSTVCO+DUzwsj0rQRafi7MiKR25KOiTexUltyIOv/G921WHSW&#xA;3g0tQkenkMRMX0umLwIX6IaLvc5EhXw+6ZSP75I1h6JW0wogJjdagM9J6JkXkQID&#xA;AQABo4IBXTCCAVkwCQYDVR0TBAIwADAOBgNVHQ8BAf8EBAMCB4AwKwYDVR0fBCQw&#xA;IjAgoB6gHIYaaHR0cDovL3N2LnN5bWNiLmNvbS9zdi5jcmwwYQYDVR0gBFowWDBW&#xA;BgZngQwBBAEwTDAjBggrBgEFBQcCARYXaHR0cHM6Ly9kLnN5bWNiLmNvbS9jcHMw&#xA;JQYIKwYBBQUHAgIwGQwXaHR0cHM6Ly9kLnN5bWNiLmNvbS9ycGEwEwYDVR0lBAww&#xA;CgYIKwYBBQUHAwMwVwYIKwYBBQUHAQEESzBJMB8GCCsGAQUFBzABhhNodHRwOi8v&#xA;c3Yuc3ltY2QuY29tMCYGCCsGAQUFBzAChhpodHRwOi8vc3Yuc3ltY2IuY29tL3N2&#xA;LmNydDAfBgNVHSMEGDAWgBSWO1PweTOXr32D7y4rzMq3hh5yZjAdBgNVHQ4EFgQU&#xA;FKFNQmzKrn5sm1t/y75L6KZr68cwDQYJKoZIhvcNAQELBQADggEBABgOLwM9TNC/&#xA;YgS25FnpZuiLrv7ikN3HH/26DIZJHwuYNGEOs9RYQKvHSTYiN4DVojOlripaCp5d&#xA;pIR/c/10QQcpv84InmUFsR8qTQO9fSjXsittgWQl/51b01mvcMkDyBEjqB1pMYec&#xA;zI57nkozGxRt85ottzdEbYpT54lqf8nwiyaZ6XxrSEc2AfNTCtC2R9q/V3CBqjvx&#xA;KTcY+oYL0uwoy+PADssr6jAScr70dUOkyVy/vUI81f+0cREcL7bX3yEtvksujaSv&#xA;ndsjx66zACL3rpcAD80D+QJzw4ZtkhCdBQ5G6KUHBpH+x2Yz9C65o73oFgU3e5r7&#xA;kZWf1g5AfoU=&#xA;-----END CERTIFICATE-----&#xA;"/>
<Setting name="pem_length" value="1757"/>
<Setting name="type" value="cert"/>
</Section>
<Section name="General_Rule_373">
<Setting name="id" value="13"/>
<Setting name="pem_1" value="-----BEGIN CERTIFICATE-----&#xA;MIIFGjCCBAKgAwIBAgIQWHzSGgXTTT3fqpEoUhz0/DANBgkqhkiG9w0BAQUFADCB&#xA;tDELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL&#xA;ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTswOQYDVQQLEzJUZXJtcyBvZiB1c2Ug&#xA;YXQgaHR0cHM6Ly93d3cudmVyaXNpZ24uY29tL3JwYSAoYykxMDEuMCwGA1UEAxMl&#xA;VmVyaVNpZ24gQ2xhc3MgMyBDb2RlIFNpZ25pbmcgMjAxMCBDQTAeFw0xNjA3MjEw&#xA;MDAwMDBaFw0xOTA3MjEyMzU5NTlaMHwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpD&#xA;YWxpZm9ybmlhMRQwEgYDVQQHEwtTYW50YSBDbGFyYTEVMBMGA1UEChQMTWNBZmVl&#xA;LCBJbmMuMRQwEgYDVQQLFAtFbmdpbmVlcmluZzEVMBMGA1UEAxQMTWNBZmVlLCBJ&#xA;bmMuMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvtqZ7J4HkyZseUJa&#xA;jI5WpyRhG3xboHAmsGso+VhmMggrd4f+SIG3TTRIj8IPhpqF24862sfs4jzDL2Id&#xA;JE98OCyT/jfsNNYh44H9iyfHBHgetf7OiW78BH69VwvA2rvchds3HBiN6G5Jlgi7&#xA;XIN7MvzUc4B87CtFCORg7PtqQIwja6JGYn+vzJrpSwYX1x4TuMhBVrhJnHP7QNAk&#xA;3UjZ6HlLlNMjSXOV6EASN85hieeC+QrhC2Ybkcd9phUJgw5cB7eIUnb92peqm+Kc&#xA;BAHFIA0W2Tsa+Lt8wUWML1hwQZaj0K7KymKmJEK7PdMpKKlOFl1wb4q7RSRkjuPW&#xA;86I5hQIDAQABo4IBXTCCAVkwCQYDVR0TBAIwADAOBgNVHQ8BAf8EBAMCB4AwKwYD&#xA;VR0fBCQwIjAgoB6gHIYaaHR0cDovL3NmLnN5bWNiLmNvbS9zZi5jcmwwYQYDVR0g&#xA;BFowWDBWBgZngQwBBAEwTDAjBggrBgEFBQcCARYXaHR0cHM6Ly9kLnN5bWNiLmNv&#xA;bS9jcHMwJQYIKwYBBQUHAgIwGQwXaHR0cHM6Ly9kLnN5bWNiLmNvbS9ycGEwEwYD&#xA;VR0lBAwwCgYIKwYBBQUHAwMwVwYIKwYBBQUHAQEESzBJMB8GCCsGAQUFBzABhhNo&#xA;dHRwOi8vc2Yuc3ltY2QuY29tMCYGCCsGAQUFBzAChhpodHRwOi8vc2Yuc3ltY2Iu&#xA;Y29tL3NmLmNydDAfBgNVHSMEGDAWgBTPmanqeyb0S8mOj9fwBSbv49KnnTAdBgNV&#xA;HQ4EFgQU6EvfupFJgvBbXBN5B2rk96NDjl8wDQYJKoZIhvcNAQEFBQADggEBAOYg&#xA;OaYjugbVJi68u7VNVfZwtx4BEju0w6f+MZhC4t2Ry9SsDYompgZGynL3OpAIimUN&#xA;5gvGA3UxSC9QXB77MaAJifD53ypIItviL/S3NN9xemPOPYQkrfwLFEN4YYhK3sBN&#xA;EVy7cfcFc90vp+4SvuzWC/RnUPHiMk1G+U5wsboNIV9/KjYuswDqf/7rcOQg0zLf&#xA;+COMQPj+brSnTYjV5hI2YFUbCoxuw8GP2WaGHgwOyeb9cSLtTpjvquvuc1bUDbe/&#xA;OjEoCgZ4a9+69nTnuu7U/biRD57oqXMpimiGqiN2cARjU9o4KzGpqFAjupswrHv8&#xA;H+ADOaSNT2iIDrvNEUw=&#xA;-----END CERTIFICATE-----&#xA;"/>
<Setting name="pem_length" value="1830"/>
<Setting name="type" value="cert"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="McAfee Publisher"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (741EB429-1E82-4D47-AB9C-75CAEB7C0678)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Symantec.MailSecurity.UI.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSMSE1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="SAVFMSEUI.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSMSE2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="SAVFMSECTRL.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSMSE3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="SAVFMSETask.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSMSE4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="HealthService.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSMSE5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="SAVFMSESp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSMSE6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="CmafReportSrv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSMSE7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="Symantec.Cmaf.UI.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSMSE8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Symantec Mail Security for Exchange"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (55FA779A-280E-4D18-89BF-D0FE9BDEDD96)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="GRPCONV.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LocalUser1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="LocalUser"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (963E6D7B-D039-46C3-AE93-7A903BFAAA51)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="BESClient.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="BigFix1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="BESClient.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="BESWebReportsServer.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="BigFix2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="BigFix Enterprise Suite"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (9F948935-07D3-49D4-A864-0DBBDC78D323)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Filemon.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FMon1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="FileMon Application"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (D840ECFC-4560-4A31-AEF8-DFDF87058E6D)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="aspnet_wp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SUS_Server1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="w3wp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SUS_Server2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Windows Server Update Services 2.0"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (D62D31FB-EC4F-4840-83E0-9D25037F02C3)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="fssm32.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FSecure1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_10">
<Setting name="binary" value="fsavgui.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FSecure11"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_11">
<Setting name="binary" value="VirusNews.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FSecure12"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="ServiceWrapper-4476822.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FSecure2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="fsm32.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FSecure4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="iLaunchr.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FSecure5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="fsbwsys.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FSecure6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="fspex.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FSecure7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="fsav32.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FSecure8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="fsma32.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="FSecure9"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_9">
<Setting name="binary" value="ServiceWrapper-7681197.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="services.exe"/>
<Setting name="tag" value="FSecure10"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="F-Secure AV"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (2BB4B279-6A07-4A61-ADF1-CAB516194338)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="iislockd.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="MST1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="msat.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_101">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="msat.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Microsoft Security Tools"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (964881E9-EBD0-4C69-94AA-BEDED8364BEE)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="ALsvc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Sophos1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="ALUpdate.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Sophos2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="savmain.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Sophos3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Sophos AV"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (810A220D-6164-4B3C-867E-74887B966651)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="luall.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_10">
<Setting name="binary" value="msi12.tmp"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton10"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="NAV_2011.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_11">
<Setting name="binary" value="VPDN_LU.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton11"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_12">
<Setting name="binary" value="ccapp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton12"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_13">
<Setting name="binary" value="navapsvc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton13"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_14">
<Setting name="binary" value="msmsgs.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton14"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_15">
<Setting name="binary" value="wuauclt.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton15"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_16">
<Setting name="binary" value="VpTray.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton16"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_17">
<Setting name="binary" value="VPC32.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton17"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_18">
<Setting name="binary" value="UpdtNv28.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton18"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_19">
<Setting name="binary" value="LRPatch.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton19"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="aupdate.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_20">
<Setting name="binary" value="CCEVTMGR.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton20"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_21">
<Setting name="binary" value="LUSETUP.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton21"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_22">
<Setting name="binary" value="NMain.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton22"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_23">
<Setting name="binary" value="LuComServer_3_0.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton23"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_24">
<Setting name="binary" value="symlcsvc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton24"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_25">
<Setting name="binary" value="ReporterSvc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton25"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_26">
<Setting name="binary" value="ccSvcHst.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton26"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_27">
<Setting name="binary" value="AppSvc32.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton27"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_28">
<Setting name="binary" value="LuComServer_3_1.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton28"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_29">
<Setting name="binary" value="UpdMgr.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton29"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="luComServer_2_6.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_30">
<Setting name="binary" value="SEVINST.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton30"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_31">
<Setting name="binary" value="DlayUpd2.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton31"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_32">
<Setting name="binary" value="LuComServer_2_7.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton32"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_33">
<Setting name="binary" value="SPA.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton33"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_34">
<Setting name="binary" value="SNDMon.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton34"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_35">
<Setting name="binary" value="DefWatch.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton35"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_36">
<Setting name="binary" value="DWHWizrd.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton36"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_37">
<Setting name="binary" value="RemStart.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton37"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_38">
<Setting name="binary" value="SymClnUp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton38"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_39">
<Setting name="binary" value="nlnhook.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton39"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="luComServer_2_5.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_40">
<Setting name="binary" value="DoScan.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton40"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_41">
<Setting name="binary" value="IcePack.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton41"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_42">
<Setting name="binary" value="NscTop.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton42"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_43">
<Setting name="binary" value="Norton_Removal_Tool.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton43"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_44">
<Setting name="binary" value="SAVScan.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton45"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_45">
<Setting name="binary" value="COHUpdt.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton46"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_46">
<Setting name="binary" value="DlayUpdt.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton47"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_47">
<Setting name="binary" value="SSAutoRN.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton48"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_48">
<Setting name="binary" value="updecabi.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton49"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_49">
<Setting name="binary" value="CfgWiz.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton50"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="rtvscan.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_50">
<Setting name="binary" value="LUUPDATE.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton51"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_51">
<Setting name="binary" value="LuCallbackProxy.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton52"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="Navw32.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="IdsInst.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="msi2.tmp"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_9">
<Setting name="binary" value="lucomserver.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Norton9"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Norton"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (F1153B3E-8B42-4D4C-8207-4C813ABF5197)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="MBExplorer.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="IIS1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="IIS"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (88DD14EA-B44F-4323-A967-64A0E125F7D7)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="daservice.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="NetproDA1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Netpro Directory Analyzer"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (1BCC8286-C3E1-4A53-921F-B4454B8EEE90)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="NTCLNSRV.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="QHeal1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="scanner.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="QHeal2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="nativscn.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="QHeal3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="EMLPROXY.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="QHeal4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="ONLNSVC.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="QHeal5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="SENSOR.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="QHeal6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Quick Heal Total Security"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (79177D49-CC72-4FD2-8ACB-02AE7D7A5786)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Apple Software Update\softwareupdate.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Apple1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Apple iTunes"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (AFE1B3C0-C7B4-478B-A5CB-C6846D95029F)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="scor_info">
<Setting name="group_name" value="Global Observation Rules (Deprecated)"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (06CC33C2-9E78-47F3-B786-04D654A35FD0)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="RpcSandraSrv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SSLite1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="SiSoftware Sandra Lite 2009"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (0045790B-49CA-4689-8A10-08118057AD32)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Msmsgs.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="WM1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Windows Messenger"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (45C5B340-1C73-4F62-84A6-A4E7CCE45DB0)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="dsm.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TSM_Client1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="dsmcsvc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="TSM_Client2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Tivoli Storage Manager Client"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (87327BDE-D804-4B0A-BAA2-54E6AEC62CDA)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Frameworkservice.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_10">
<Setting name="binary" value="Framew~1.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee10"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="frameworkservice.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_1000">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%ProgramFiles%\McAfee\Solidcore\passwd"/>
<Setting name="pattern_1" value="READ_DENIED"/>
<Setting name="rule-uuid" value="75ffb87a-f9d8-4c0a-93d4-23e78917a431"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1001">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%ProgramFiles%\McAfee\Solidcore\passwd"/>
<Setting name="pattern_1" value="READ_DENIED"/>
<Setting name="rule-uuid" value="75ffb87a-f9d8-4c0a-93d4-23e78917a431"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1002">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%ProgramW6432%\McAfee\Solidcore\passwd"/>
<Setting name="pattern_1" value="READ_DENIED"/>
<Setting name="rule-uuid" value="2b6a0ac6-4d0b-4804-bb31-b4af733858f8"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1003">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%ProgramW6432%\McAfee\Solidcore\passwd"/>
<Setting name="pattern_1" value="READ_DENIED"/>
<Setting name="rule-uuid" value="2b6a0ac6-4d0b-4804-bb31-b4af733858f8"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1004">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%ProgramFiles%\McAfee\Solidcore\passwd"/>
<Setting name="pattern_1" value="FILE_READ_UPDATE"/>
<Setting name="rule-uuid" value="06c84802-a68a-4968-a189-603e05eb3ec9"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1005">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%ProgramFiles%\McAfee\Solidcore\passwd"/>
<Setting name="pattern_1" value="FILE_READ_UPDATE"/>
<Setting name="rule-uuid" value="06c84802-a68a-4968-a189-603e05eb3ec9"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1006">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%ProgramW6432%\McAfee\Solidcore\passwd"/>
<Setting name="pattern_1" value="FILE_READ_UPDATE"/>
<Setting name="rule-uuid" value="70be3b74-24d8-4012-8c17-7b8d4c77dfd0"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1007">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%ProgramW6432%\McAfee\Solidcore\passwd"/>
<Setting name="pattern_1" value="FILE_READ_UPDATE"/>
<Setting name="rule-uuid" value="70be3b74-24d8-4012-8c17-7b8d4c77dfd0"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1008">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\searchfilterhost.exe"/>
<Setting name="rule-uuid" value="e69e8713-524e-49cb-9fe3-f6f782bee595"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1009">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\searchfilterhost.exe"/>
<Setting name="rule-uuid" value="e69e8713-524e-49cb-9fe3-f6f782bee595"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_101">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="McAfee\Common Framework\MfeServiceMgr.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_1010">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\searchindexer.exe"/>
<Setting name="rule-uuid" value="eed52145-279d-44fc-8351-d76e79e52d42"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1011">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\searchindexer.exe"/>
<Setting name="rule-uuid" value="eed52145-279d-44fc-8351-d76e79e52d42"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1012">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\searchprotocolhost.exe"/>
<Setting name="rule-uuid" value="8405b025-9ac2-4753-8505-e15ee58fdb7d"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1013">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\searchprotocolhost.exe"/>
<Setting name="rule-uuid" value="8405b025-9ac2-4753-8505-e15ee58fdb7d"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1014">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\searchprotocolhost.exe"/>
<Setting name="rule-uuid" value="a1a1c0c1-45f8-4f20-8864-961d47386e73"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1015">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\searchprotocolhost.exe"/>
<Setting name="rule-uuid" value="a1a1c0c1-45f8-4f20-8864-961d47386e73"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1016">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\searchfilterhost.exe"/>
<Setting name="rule-uuid" value="6bf1f269-c8ce-4b2d-b7c8-3c07edb54378"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1017">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\searchfilterhost.exe"/>
<Setting name="rule-uuid" value="6bf1f269-c8ce-4b2d-b7c8-3c07edb54378"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1018">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\searchfilterhost.exe"/>
<Setting name="rule-uuid" value="bec4fb99-21e2-47fe-90f1-e1ded39f1106"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1019">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\searchfilterhost.exe"/>
<Setting name="rule-uuid" value="bec4fb99-21e2-47fe-90f1-e1ded39f1106"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_102">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="McAfee\Common Framework\naPrdMgr.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_1020">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\searchindexer.exe"/>
<Setting name="rule-uuid" value="8d5a5b9f-5d6e-455a-9ce1-6de838f11248"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1021">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\searchindexer.exe"/>
<Setting name="rule-uuid" value="8d5a5b9f-5d6e-455a-9ce1-6de838f11248"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1022">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\searchindexer.exe"/>
<Setting name="rule-uuid" value="b32a4d16-2e91-4b9f-b892-3c369f39ee8a"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1023">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\searchindexer.exe"/>
<Setting name="rule-uuid" value="b32a4d16-2e91-4b9f-b892-3c369f39ee8a"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1024">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\searchprotocolhost.exe"/>
<Setting name="rule-uuid" value="98dd2b2f-44bb-41e6-8fd2-db937c6b030a"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1025">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\searchprotocolhost.exe"/>
<Setting name="rule-uuid" value="98dd2b2f-44bb-41e6-8fd2-db937c6b030a"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1026">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\cidaemon.exe"/>
<Setting name="rule-uuid" value="8d31bd76-571e-4e98-ba4d-aa19e3d06a87"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1027">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\cidaemon.exe"/>
<Setting name="rule-uuid" value="8d31bd76-571e-4e98-ba4d-aa19e3d06a87"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1028">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\System32\cidaemon.exe"/>
<Setting name="rule-uuid" value="4a7bef86-aa9f-40b0-a471-7b80c67fe074"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1029">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\System32\cidaemon.exe"/>
<Setting name="rule-uuid" value="4a7bef86-aa9f-40b0-a471-7b80c67fe074"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_103">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="McAfee\SystemCore\mcshield.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_1030">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\cidaemon.exe"/>
<Setting name="rule-uuid" value="6945e679-a9bd-451e-b762-a3862cdd5095"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1031">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\cidaemon.exe"/>
<Setting name="rule-uuid" value="6945e679-a9bd-451e-b762-a3862cdd5095"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1032">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="match-type_0" value="begins"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\Installer\"/>
<Setting name="pattern_1" value="PKG_MODIFICATION_ALLOWED_UPDATE"/>
<Setting name="rule-uuid" value="9d1ba6cd-4e3d-46ff-bc5d-c51c87613fd5"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1033">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="begins"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\Installer\"/>
<Setting name="pattern_1" value="PKG_MODIFICATION_ALLOWED_UPDATE"/>
<Setting name="rule-uuid" value="9d1ba6cd-4e3d-46ff-bc5d-c51c87613fd5"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_1034">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\System32\catroot2\dberr.txt"/>
<Setting name="pattern_1" value="FILE_MODIFIED,FILE_MODIFIED_UPDATE"/>
<Setting name="rule-uuid" value="615aab97-dfd2-4cbd-a469-1d2461199cf8"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_1035">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\System32\catroot2\dberr.txt"/>
<Setting name="pattern_1" value="FILE_MODIFIED,FILE_MODIFIED_UPDATE"/>
<Setting name="rule-uuid" value="615aab97-dfd2-4cbd-a469-1d2461199cf8"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_104">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="McCHSvc.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_105">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="McAfee\Real Time\rtclient.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_106">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="McAfee\VirusScan Enterprise\mfeann.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_107">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="McAfee\VirusScan Enterprise\VsTskMgr.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_108">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="McAfee\Common Framework\FrameworkService.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_109">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="McAfee\Real Time Server\rtserver.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_11">
<Setting name="binary" value="McScript_InUse.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee11"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_110">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfeesp.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_111">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfeesp.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_112">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="mfeesp.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_113">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfefw.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_114">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfefw.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_115">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="mfefw.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_116">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfetp.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_117">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfetp.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_118">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="mfetp.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_119">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfewc.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_12">
<Setting name="binary" value="McVSEscn.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee12"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_120">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfewc.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_121">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="mfewc.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_122">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfeconsole.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_123">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfeconsole.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_124">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="mfeconsole.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_125">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfeepaac.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_126">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mfeepaac.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_127">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="mfeepaac.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_128">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="amupdate.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_129">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="amupdate.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_13">
<Setting name="binary" value="mcvsshld.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee13"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_130">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="amupdate.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_131">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="setupTIE.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_132">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="setupTIE.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_133">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="setupTIE.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_14">
<Setting name="binary" value="mcmnhdlr.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee14"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_15">
<Setting name="binary" value="Mcvsrte.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee15"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_16">
<Setting name="binary" value="iexplore.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="library" value="mcinsctl.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee16"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_17">
<Setting name="binary" value="scan32.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee17"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_18">
<Setting name="binary" value="FramePkg.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee18"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_19">
<Setting name="binary" value="mcods.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="false"/>
<Setting name="tag" value="McAfee19"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="Msshield.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_20">
<Setting name="binary" value="mcshell.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee20"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_200">
<Setting name="cksum" value="803291bcc5aa45a0221b4016f62d63a26d3ee4af"/>
<Setting name="ruletype" value="checksum"/>
<Setting name="tag" value="MTP"/>
<Setting name="type" value="installer"/>
<Setting name="vendor" value="McAfee"/>
<Setting name="version" value="McAfee Total Protection"/>
</Section>
<Section name="General_Rule_21">
<Setting name="binary" value="myAgtSvc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee21"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_22">
<Setting name="binary" value="HtmlDlg.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee22"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_23">
<Setting name="binary" value="HIPSvc.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee23"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_24">
<Setting name="binary" value="mer.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee24"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_25">
<Setting name="binary" value="ePolicy Orchestrator\Server\bin\tomcat5.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee25"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_26">
<Setting name="binary" value="VirusScan Enterprise\VsTskMgr.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee26"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_27">
<Setting name="binary" value="VirusScan Enterprise\x64\Scan64.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee27"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_28">
<Setting name="binary" value="VirusScan Enterprise\x64\EngineServer.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee28"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_29">
<Setting name="binary" value="SBadduser.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee29"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="Mcupdate.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_30">
<Setting name="binary" value="McTray.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee30"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_31">
<Setting name="binary" value="McSACore.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee31"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_32">
<Setting name="binary" value="firesvc.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee32"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_33">
<Setting name="binary" value="Supportability\MVT\MvtApp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee33"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_34">
<Setting name="binary" value="RSSensor.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee34"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_35">
<Setting name="binary" value="FSDiscovery.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee35"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_36">
<Setting name="binary" value="FSAssessment.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee36"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_37">
<Setting name="binary" value="FSScanEngineSvc.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee37"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_38">
<Setting name="binary" value="ReportServer.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee38"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_39">
<Setting name="binary" value="FSScanCtrlSvc.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee39"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="udaterui.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_40">
<Setting name="binary" value="McSvHost.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee40"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_41">
<Setting name="binary" value="McCHSvc.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee41"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_42">
<Setting name="binary" value="ePolicy Orchestrator\EventParser.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee42"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_43">
<Setting name="binary" value="ePolicy Orchestrator\Server\bin\tomcat7.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee43"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_44">
<Setting name="binary" value="McTELSvc.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee44"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_45">
<Setting name="binary" value="McTELUpd.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee45"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_46">
<Setting name="binary" value="McAfee\Real Time\rtclient.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee46"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_47">
<Setting name="binary" value="masvc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee47"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_48">
<Setting name="binary" value="macmnsvc.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee48"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_49">
<Setting name="binary" value="macompatsvc.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee49"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="Mghtml.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_50">
<Setting name="binary" value="mvserver.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee50"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_51">
<Setting name="binary" value="McAfee\MAR\MARService.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee51"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_52">
<Setting name="binary" value="McAfee\Endpoint Security\Threat Prevention\mfetp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee52"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_53">
<Setting name="binary" value="FCPatchInstallAgent.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="MVM1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_54">
<Setting name="binary" value="FCAgent.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="MVM2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_55">
<Setting name="binary" value="McAfee\Endpoint Security\Adaptive Threat Protection\mfeatp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee53"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_56">
<Setting name="binary" value="McAfee\Endpoint Security\Threat Intelligence\mfetie.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee54"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="Mcupdmgr.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="McShield.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="McScript.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_9">
<Setting name="binary" value="Mcappins.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="McAfee9"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="McAfee"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (47028DA1-A2EF-4286-8759-4DB0C327ACC4)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="winmgmt.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SI2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="System Information"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (772E16C8-4724-43DB-88CC-E1E30828F023)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="dism.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SERVERROLES1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="audiodg.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_101">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="searchprotocolhost.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_102">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="msiexec.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_103">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="xcopy.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_104">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="update.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="true"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_105">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="naprdmgr.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_106">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="true"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="csrss.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_107">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="cygrunsrv.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="true"/>
</Section>
<Section name="General_Rule_108">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="cygrunsrv.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="true"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_109">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="cygwin1.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="true"/>
</Section>
<Section name="General_Rule_110">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="true"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="FrameworkService.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_111">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="FrameworkService.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_112">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="FrameworkService.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_113">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="true"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="lsass.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_114">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="true"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="Mcshield.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_115">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="Mcshield.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_116">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="Mcshield.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_117">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="ntdll.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_118">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="ntvdm.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="true"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_119">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="sshd.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="true"/>
</Section>
<Section name="General_Rule_120">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="sshd.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="true"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_121">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="true"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="svchost.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_122">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="true"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="system"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_123">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="true"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="%PROGRAMFILES%\McAfee\VirusScan Enterprise\VsTskMgr.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_124">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="%PROGRAMFILES%\McAfee\VirusScan Enterprise\VsTskMgr.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_125">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="%PROGRAMFILES%\McAfee\VirusScan Enterprise\VsTskMgr.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_126">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="true"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="winlogon.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_127">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="1clickfixerplus.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_128">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="1clickfixerplus.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_129">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="aspack.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_130">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="aspack.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_131">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="asprotect.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_132">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="asprotect.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_133">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="autokrypt.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_134">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="autokrypt.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_135">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="automize.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_136">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="automize.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_137">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="dap.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_138">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="getright.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_139">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="googleearth.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_140">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="googleearth.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_141">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="realplay.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_142">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="stellar phoenix fat &amp; ntfs.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_143">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="stellar phoenix fat &amp; ntfs.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_144">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="swatcher.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_145">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="swatcher.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_146">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="swdoctor.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_147">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="swdoctor.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_148">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="vsmon.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_149">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="vsmon.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_150">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="searchprotocolhost.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_151">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="msiexec.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_152">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="xcopy.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_153">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="update.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_154">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="java.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_155">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="javaw.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_156">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="searchprotocolhost.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_157">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="msiexec.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_158">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="xcopy.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_159">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="update.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_160">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="udaterui.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_161">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="browseUI.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_162">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="dxtrans.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_163">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mshtml.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_164">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="mswsock.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_165">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="ole32.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_166">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="userenv.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_167">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="version.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_168">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="wininet.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_169">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="winmm.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_170">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="wintrust.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_171">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="wsock32.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_172">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="msvcrt.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_173">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="advapi32.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_174">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="oleaut32.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_175">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="rpcrt4.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_176">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="shell32.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_177">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="netapi32.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_178">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="ws2_32.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_179">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="atl.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_180">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="crypt32.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_181">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="msvcp60.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_182">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="wmp.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_183">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="setupapi.dll"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="true"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_184">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="McShield.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="true"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_185">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="true"/>
<Setting name="file" value="webMERclient.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="tiworker.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SERVERROLES2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="DismHost.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SERVERROLES3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Default List"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (BCAE88C3-5612-40A1-867C-AFC6BB377390)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="CcmExec.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSClient1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="SMSCliUI.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSClient2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="ScanWrapper.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSClient3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="Wmiprvse.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="library" value="CcmTask.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSClient4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="Wmiprvse.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="library" value="ccmprofiler.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMSClient5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="SCCM/SMS Client"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (59E8B457-FDA9-4B4D-8866-9CDF2976362E)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="ERDAgent.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="QRM1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Quest Recovery Manager"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (6ECBB36C-AA89-459E-A3F1-08F36B201804)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Sdjexec.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="CA1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="CA Unicenter"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (A63B13F5-21A6-41A6-8A90-2CF52FA557E2)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="omnitrig.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="HPSDP1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="HP OpenView Storage Data Protector"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (28AEBF88-BEDD-4C1F-A5AD-962F2E8B4A9E)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="webfldrs.msi"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="WINDOWS1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="system32\Wsqmcons.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="WindowsSQMconsolidator1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Windows"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (67E52B15-750F-43B4-96DF-A3EE6987552A)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="w3wp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ASP1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="ASP.NET Framework"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (605DA2B3-553D-47BA-9F02-A61C59536D6D)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Google\Update\GoogleUpdate.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Google1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="Users\*\Downloads\ChromeSetup.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Chrome1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="Program Files*\*\GoogleUpdate.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Chrome2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="Program Files*\Google\Chrome\Application\*\Installer\setup.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Chrome3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Google"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (2968A63A-F7FE-4456-B08D-E37B8D999426)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="apache.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Apache1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Apache Web Server"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (E5733FA8-D54D-48BA-B215-AB7B513B7BA8)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="getlicense.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="IGoldmine1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="I Goldmine Server"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (469B1739-A56E-468C-9E2A-A749202C769B)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Pavw.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Panda1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="pavjobs.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Panda2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="ApVxdWin.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Panda3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="avlite.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Panda4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="pavsrv51.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Panda5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="TPSrv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="services.exe"/>
<Setting name="tag" value="Panda6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="PavFnSvr.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Panda7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Panda AV"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (9A5F1EA4-8C98-4B63-B858-9B94DC9F7FDD)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="sslUtility.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="IMail91"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="sslUtility.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="IMail20061"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="IMail"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (8D09FD0F-F1FD-40B8-B844-9407F6C3D495)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="RPCServ.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="MCGroupShield1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="McAfee Group shield"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (4AEDDCD0-7AEE-4F3A-8162-D10DF8D461F7)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="MOM.UI.OpsConsoleExe.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="MOM_Server1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="MOM Server"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (1611B731-FE1D-4F48-8595-3F78E94A764F)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="wuauclt.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="QHealPlus1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="scanner.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="QHealPlus2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="QUICKUP.EXE"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="QHealPlus3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Quick Heal Plus"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (375E909E-ED57-4C11-96BC-A93117AA9ED2)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="rpsetup.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMS1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="ccmsetup.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMS2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="sitecomp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMS3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="smsexec.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMS4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="slpsetup.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMS5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="wbemwrap.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMS6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="wmicore.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMS7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="reportinginstall.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SMS8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="SCCM/SMS Server"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (969DE862-B571-452F-BDCA-9177E6555886)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Tuner.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="HPRSSM1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="HP Remote Support Software Manager"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (1D1B28F4-01DB-4B41-BAEA-9B872BB804EB)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="SymCorpUI.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SEP1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_10">
<Setting name="binary" value="LUCOMS~1.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SEP10"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="SmcGui.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SEP2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="LuCallbackProxy.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SEP3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="LuComServer_3_3.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SEP4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="Rtvscan.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SEP5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="SavUI.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SEP6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="SescLU.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SEP7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="SMC.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SEP8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_9">
<Setting name="binary" value="COHUpdt.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SEP9"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Symantec Endpoint Protection"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (BD536600-5005-4DFD-9BD8-0253C783E0D5)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="HealthService.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SCOM_Server1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="MonitoringHost.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SCOM_Server2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="MOMPerfSnapshotHelper.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SCOM_Server3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="sqlservr.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SCOM_Server4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="AdtAgent.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SCOM_Server5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="System Control Operations Manager"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (67F964A9-FEE1-41D8-94EB-178E85814EBB)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="MOMAgentInstaller.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="SCOM_Client1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="System Control Operations Client"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (F0D2921F-B08F-414B-8ADF-023531075E73)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="ikernel.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="winlogon.exe"/>
<Setting name="tag" value="J2RE1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="ikernel.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="svchost.exe"/>
<Setting name="tag" value="J2RE2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="J2RE"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (49FCA257-670F-4065-98D7-AC0FA09322FC)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="fcags.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="DLP1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="McAfee\DLP\Agent\fcag.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="DLP2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="McAfee DLP Agent"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (1F176015-1779-471F-B1A8-35DE7B766343)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="armsvc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AdobeArmsvc1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="Common Files\Adobe\ARM\1.0\AdobeArm.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AdobeArmsvc2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Adobe Acrobat Update"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (64AD0943-26C5-48CC-87B6-FC49E6B16842)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="stamper.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LMS1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="Console.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LMS2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Landesk Management Suite"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (1AFD9ACD-FAB1-4BED-8BA0-76E63301F8D5)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="avp.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Ksky1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Kaspersky Internet Security"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (740CCDFB-3169-4CE9-9025-964082BFCA94)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="2Xcopy64.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="2X1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="2XConsole.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="2X2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="2X ApplicationServer and LoadBalancer"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (A5F22A55-E65D-4670-ADDC-406D7BE24210)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="avgw.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AVG1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="avgwb.dat"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AVG2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="avgupsvc.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AVG3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="avginet.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AVG4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="avgscanx.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AVG5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="avgarkt.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AVG6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="AVG AV"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (BB5F5089-F148-44DF-A03D-279CA98149A3)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="avk.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AVK1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="avkproxy.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AVK2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="avkwctl.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AVK3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="AVK"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (F996A055-680E-4F88-B438-20E6126BB578)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Bkupexec.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Veritas1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="beremote.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Veritas2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Veritas Backup"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (878ABFEC-4F99-4320-9C43-8595CEA79EEE)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="aspnet_wp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="WSUS_Server1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="w3wp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="WSUS_Server2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="wsusservice.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="WSUS_Server3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Windows Server Update Services 2.0 SP1"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (F81CA625-3B36-47EE-BD35-19AE72EA25AE)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="nserver.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_10">
<Setting name="binary" value="ncatalog.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS10"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_11">
<Setting name="binary" value="ncldbdir.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS11"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_12">
<Setting name="binary" value="ncompact.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS12"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_13">
<Setting name="binary" value="ndctest.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS13"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_14">
<Setting name="binary" value="ndecs.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS14"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_15">
<Setting name="binary" value="nfixup.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS15"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_16">
<Setting name="binary" value="nicm.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS16"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="nhttp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="namgr.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="nsched.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS4"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="nchronos.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS5"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="nstatlog.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS6"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_7">
<Setting name="binary" value="nobject.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS7"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_8">
<Setting name="binary" value="nupdall.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS8"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_9">
<Setting name="binary" value="ndesign.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="LDS9"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Lotus Domino Server"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (01E76F5A-CFDD-4BD8-A57E-FE28E5D119C0)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="twgmonit.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="IBMDirectorMon1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="IBM Director"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (96F3DD3D-5B30-4B15-A7BB-064CF55E937F)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="scor_info">
<Setting name="group_name" value="My Rules"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="false"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (12639350-DD47-4E98-9D37-829C4AE9E237)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="vsmon.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="ZoneAlarm1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="updclient.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="zoneAlarm2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Zone Alarm"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (92FCEC05-EFC1-4FC7-8112-E5C765E8974B)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="winproxy.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Winproxy1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Winproxy"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (63CD1157-1367-4D57-BBA3-5A779A546943)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="nod32.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="NOD1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="nod32kui.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="NOD2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="ekrn.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="NOD3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="NOD32 AV"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (BEE6E203-78E1-481C-AD4D-B275D511404D)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="jobeng.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="BrightStor1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="carunjob.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="BrightStor2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="BrightstorARCServe"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (9A6B7074-12E1-4BEA-8DAB-DAB944A96295)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="acadlt.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_101">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="acadlt.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_102">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="lmu.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_103">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="lmu.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_104">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="dwgviewr.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_105">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="true"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="dwgviewr.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="AutoCAD"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (B1CDD288-94C6-4E38-A6C1-BFEE1672D287)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="spoolsv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="PRINTER1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Office printer HP 2300 Series"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (FA979D44-FF89-4E24-B038-0A0AEBC5DD2F)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="aspnet_wp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value=".NETServer1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="w3wp.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value=".NETServer2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Visual Studio .Net"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (6FF1EDD7-183F-4A38-88B6-38E38516EC51)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="vnctool.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="VNC1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="VNC Server"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (8A0819B5-45A8-411A-8051-EBE3E8A55A9E)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="devenv.exe"/>
<Setting name="inherit" value="false"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="VStudio1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="vcspawn.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="VStudio2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Visual Studio"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (07B016F8-F95F-4581-B0BB-F9171A59BE9E)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="ntfrs.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AD1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="ntbackup.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="AD2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Windows AD server"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (43F35DDE-428E-4C82-B10D-0F9DA669041A)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Virtual PC.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="MVPC1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Microsoft Virtual PC"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (E007DD91-2A59-4531-B8E8-A2E626AEC376)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="Java\Java Update\jusched.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="JavaUpdate1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="Java\Java Update\jucheck.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="JavaUpdate2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Java"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (933BD63D-D482-439C-AB64-89519C23C1E4)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\lsass.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="312a1fa6-810a-4303-9c81-b2317fed0ce1"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_10">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\cmd.exe"/>
<Setting name="pattern_1" value="WRITE_DENIED"/>
<Setting name="rule-uuid" value="92129fd4-1963-479e-9264-3d71119b3814"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_11">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\cmd.exe"/>
<Setting name="pattern_1" value="EXECUTION_DENIED"/>
<Setting name="rule-uuid" value="7480985e-ad00-4aaf-a586-c56a9d752b1b"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_12">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\cmd.exe"/>
<Setting name="pattern_1" value="EXECUTION_DENIED"/>
<Setting name="rule-uuid" value="d325ed90-ddfe-4bda-bd09-20ea82090ee4"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_13">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\msiexec.exe"/>
<Setting name="pattern_1" value="FILE_CREATED"/>
<Setting name="rule-uuid" value="9390e39b-a279-4ebb-b6e9-42386a7aac85"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_14">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\msiexec.exe"/>
<Setting name="pattern_1" value="FILE_CREATED"/>
<Setting name="rule-uuid" value="18d6bcad-f3be-4519-abe5-fb35cfb1d514"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_15">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\msiexec.exe"/>
<Setting name="pattern_1" value="FILE_MODIFIED"/>
<Setting name="rule-uuid" value="5af72b32-7a9f-40b0-a648-767947939a96"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_16">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\msiexec.exe"/>
<Setting name="pattern_1" value="FILE_MODIFIED"/>
<Setting name="rule-uuid" value="544cbd49-dabe-4d6b-8cb9-6c890a5da697"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_17">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\msiexec.exe"/>
<Setting name="pattern_1" value="FILE_DELETED"/>
<Setting name="rule-uuid" value="3a291d4a-741c-4da8-8845-df6ae4bd110a"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_18">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\msiexec.exe"/>
<Setting name="pattern_1" value="FILE_DELETED"/>
<Setting name="rule-uuid" value="f9139bed-c9ae-4e1a-bb1e-76f8588c4605"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_19">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\msiexec.exe"/>
<Setting name="pattern_1" value="WRITE_DENIED"/>
<Setting name="rule-uuid" value="11c4d00a-b9ef-4b17-8c03-934ba0c4be0c"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_2">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\lsass.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="3e403e39-3b67-4d44-bd21-0619ecf43dd3"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_20">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\msiexec.exe"/>
<Setting name="pattern_1" value="WRITE_DENIED"/>
<Setting name="rule-uuid" value="51e9b699-d6f9-471b-8cf0-8e0429bb58cf"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_21">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\msiexec.exe"/>
<Setting name="pattern_1" value="EXECUTION_DENIED"/>
<Setting name="rule-uuid" value="121838a0-0fde-407f-b44d-897411e65399"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_22">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\msiexec.exe"/>
<Setting name="pattern_1" value="EXECUTION_DENIED"/>
<Setting name="rule-uuid" value="acff4935-b6dd-4259-98bc-1fe197bc2c5b"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_23">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\conhost.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="692f4604-9e04-4945-b3b1-76e8064ceb66"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_24">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\conhost.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="e5ccfc25-66f3-42a2-a492-e7f0ba593ff8"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_25">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\System32\lsm.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="e48b7159-3cd5-4a2e-b794-f89381a44754"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_26">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\lsm.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="0a48695d-e948-4bf6-96a5-c2ce04c458ab"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_27">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\System32\audiodg.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="ce8a6e1e-9fac-4db1-aaf4-d7f015f5189c"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_28">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\audiodg.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="a45d96f6-1c58-4f5e-a959-40869c39ce97"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_29">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\System32\taskeng.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="0d90313d-fe05-4014-8b2c-2bc60ba67b9f"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_3">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\cmd.exe"/>
<Setting name="pattern_1" value="FILE_CREATED"/>
<Setting name="rule-uuid" value="2701f1f9-4bbe-498e-9c00-efa448692ad3"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_30">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\taskeng.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="28ad12b0-e2c2-4a49-a00b-4a416b0d134b"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_31">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\System32\vssvc.exe"/>
<Setting name="pattern_1" value="FILE_CREATED"/>
<Setting name="rule-uuid" value="00c81636-590d-460c-a39a-f922bcb09a45"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_32">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\System32\vssvc.exe"/>
<Setting name="pattern_1" value="FILE_MODIFIED"/>
<Setting name="rule-uuid" value="48346d0a-10d0-40e0-9360-e6f679d9480f"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_33">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\System32\vssvc.exe"/>
<Setting name="pattern_1" value="FILE_DELETED"/>
<Setting name="rule-uuid" value="2bbc06c1-eda3-4668-9960-1ed01834e36d"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_34">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\vssvc.exe"/>
<Setting name="pattern_1" value="FILE_CREATED"/>
<Setting name="rule-uuid" value="38537b92-6bd0-4e5c-814e-db4529ca8cd5"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_35">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\vssvc.exe"/>
<Setting name="pattern_1" value="FILE_MODIFIED"/>
<Setting name="rule-uuid" value="94a984bf-926e-4d74-aaae-55a69ca70428"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_36">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\vssvc.exe"/>
<Setting name="pattern_1" value="FILE_DELETED"/>
<Setting name="rule-uuid" value="95af15e2-d183-469c-bd4e-1a9db3d227b5"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_37">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\searchfilterhost.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="e0ad4937-859c-48af-afa6-538cec81c4b9"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_38">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\searchindexer.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="e37d395a-236a-40df-a4b3-393bfb82a771"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_39">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\searchprotocolhost.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="8af56ada-83ec-48a2-9e42-893203388bf9"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_4">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\cmd.exe"/>
<Setting name="pattern_1" value="FILE_CREATED"/>
<Setting name="rule-uuid" value="def04341-fa0a-4dcb-95e3-9fe95e996a59"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_40">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\searchprotocolhost.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="a49d505b-941a-41aa-bd99-70c5395a91bc"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_41">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\searchfilterhost.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="833bbc11-35a3-4013-8858-944f90ad993f"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_42">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\searchfilterhost.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="fb0b43b6-2d23-4633-9690-47eb07f6dea7"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_43">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\searchindexer.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="9417196c-6539-4920-9207-013e57cbf25d"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_44">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\searchindexer.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="ec34f887-ee32-486b-b4be-08263cdd069b"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_45">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\searchprotocolhost.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="rule-uuid" value="6a7395cf-b043-4178-8196-7affb58b9b47"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_46">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="FILE_CREATED"/>
<Setting name="rule-uuid" value="613da462-7f9e-4a9d-8e5e-d0beb02b2d68"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_47">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="FILE_DELETED"/>
<Setting name="rule-uuid" value="39d87e98-5149-4a2a-89c0-d001fe225d6e"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_48">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="condition-type_2" value="File"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="contains"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="match-type_2" value="contains"/>
<Setting name="pattern_0" value="\McAfee\Real Time\rtclient.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="pattern_2" value="\cmd.exe"/>
<Setting name="rule-uuid" value="9fc3c0e5-a5d1-4d40-b324-ae80044b2a8f"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_49">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="condition-type_2" value="File"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="contains"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="match-type_2" value="contains"/>
<Setting name="pattern_0" value="\cmd.exe"/>
<Setting name="pattern_1" value="PROCESS_STARTED"/>
<Setting name="pattern_2" value="\cscript.exe"/>
<Setting name="rule-uuid" value="862e7e5d-cf38-43c8-84f6-8fbe3a3fe977"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_5">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\cmd.exe"/>
<Setting name="pattern_1" value="FILE_MODIFIED"/>
<Setting name="rule-uuid" value="b71864e5-9378-47ec-b109-054fbe7c3f78"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_50">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="contains"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="\cscript.exe"/>
<Setting name="pattern_1" value="FILE_MODIFIED"/>
<Setting name="rule-uuid" value="aa6365c2-62aa-4f62-8243-8e910b867264"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_51">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="contains"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="\cscript.exe"/>
<Setting name="pattern_1" value="EXECUTION_DENIED"/>
<Setting name="rule-uuid" value="bd4dfca0-88ce-49da-809d-e3bdae45d54c"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_52">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="contains"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="\cscript.exe"/>
<Setting name="pattern_1" value="WRITE_DENIED"/>
<Setting name="rule-uuid" value="00362223-757a-4920-95aa-bc521463472f"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_53">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Event"/>
<Setting name="condition-type_1" value="File"/>
<Setting name="condition-type_2" value="File"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="contains"/>
<Setting name="match-type_2" value="ends"/>
<Setting name="pattern_0" value="FILE_MODIFIED"/>
<Setting name="pattern_1" value="\McAfee\Real Time"/>
<Setting name="pattern_2" value=".vbs"/>
<Setting name="rule-uuid" value="02825ae9-7e7a-4dbb-ac8d-c39056ae45ca"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_6">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\cmd.exe"/>
<Setting name="pattern_1" value="FILE_MODIFIED"/>
<Setting name="rule-uuid" value="267774f7-4b5f-47d4-860b-92a3b10faf14"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_7">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\cmd.exe"/>
<Setting name="pattern_1" value="FILE_DELETED"/>
<Setting name="rule-uuid" value="5555b0aa-7329-4901-9d66-a267c0b81c9a"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_8">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\SysWOW64\cmd.exe"/>
<Setting name="pattern_1" value="FILE_DELETED"/>
<Setting name="rule-uuid" value="ae462b92-5114-41c4-8048-1a79c8c68918"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_9">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="ignore" value="true"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="%systemroot%\system32\cmd.exe"/>
<Setting name="pattern_1" value="WRITE_DENIED"/>
<Setting name="rule-uuid" value="21b8d469-fc36-4018-a818-ea61ac0e01ab"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Observation Filter Rules (Deprecated)"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (566F664D-51A5-4EFE-BA1E-59D336890936)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="beserver.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Backup1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="DLOAdminSvcu.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Backup2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_3">
<Setting name="binary" value="BkupExec.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Backup3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_4">
<Setting name="binary" value="beserver.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Backup1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_5">
<Setting name="binary" value="DLOAdminSvcu.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Backup2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_6">
<Setting name="binary" value="BkupExec.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Backup3"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Symantec Backup"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (CCC1554C-4CBF-4076-A794-A828BA9E2F6D)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*"/>
<Setting name="process-name" value="cdb.exe"/>
<Setting name="rule-description" value="Block common debuggers(cdb.exe) by default "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_10">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="opera.exe"/>
<Setting name="process-name" value="cmd.exe"/>
<Setting name="rule-description" value="Block command-prompt to be launched from common browsers(Opera) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_11">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*/&quot;{0,2}e&quot;{0,2}:.+"/>
<Setting name="process-name" value="cscript.exe"/>
<Setting name="rule-description" value="Block cscript from specifying Engine parameter to execute scripts "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_12">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\?\s*&quot;{0,2}\.&quot;{0,2}w&quot;{0,2}s&quot;{0,2}f.*"/>
<Setting name="process-name" value="cscript.exe"/>
<Setting name="rule-description" value="Block cscript from executing any file as a wsf file "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_13">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".+"/>
<Setting name="process-name" value="csi.exe"/>
<Setting name="rule-description" value="Block C# compiler by default "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_14">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".+"/>
<Setting name="process-name" value="dnx.exe"/>
<Setting name="rule-description" value="Block .NET execution environment by default "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_15">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".+"/>
<Setting name="process-name" value="fsi.exe"/>
<Setting name="rule-description" value="Block F# compiler by default "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_16">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*"/>
<Setting name="process-name" value="ieexec.exe"/>
<Setting name="rule-description" value="Block IEExec by default "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_17">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*"/>
<Setting name="process-name" value="kd.exe"/>
<Setting name="rule-description" value="Block common debuggers(kd.exe) by default "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_18">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*"/>
<Setting name="process-name" value="msbuild.exe"/>
<Setting name="rule-description" value="Block MSBuild by default can be used to execute code during build process "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_19">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*"/>
<Setting name="process-name" value="ntsd.exe"/>
<Setting name="rule-description" value="Block common debuggers(ntsd.exe) by default "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_2">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="winword.exe"/>
<Setting name="process-name" value="cmd.exe"/>
<Setting name="rule-description" value="Block command-prompt to be launched from MS Word(macro exploitation) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_20">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\.[\s&quot;&apos;]*[\({].+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell dot operator by default can be abused to make exploitable cmdlets from strings "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_21">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*&amp;[\s&quot;&apos;]*[\({].+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell &amp; operator by default can be abused to make exploitable cmdlets from strings "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_22">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*-&quot;{0,2}?$"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell from reading standard input as a powershell script "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_23">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bi[&quot;&apos;`]*c[&quot;&apos;`]*m\b.*"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell icm cmdlet. Alias for invoke-command "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_24">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bi[&quot;&apos;`]*e[&quot;&apos;`]*x\b.*"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell iex cmdlet. Alias for invoke-expression "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_25">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\.i[&quot;&apos;`]*n[&quot;&apos;`]*v[&quot;&apos;`]*o[&quot;&apos;`]*k[&quot;&apos;`]*e[&quot;&apos;`]*\(.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell invoke() function. Can be abused to execute strings as commands "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_26">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bi[&quot;&apos;`]*n[&quot;&apos;`]*v[&quot;&apos;`]*o[&quot;&apos;`]*k[&quot;&apos;`]*e[&quot;&apos;`]*-[&quot;&apos;`]*c[&quot;&apos;`]*o[&quot;&apos;`]*m[&quot;&apos;`]*m[&quot;&apos;`]*a[&quot;&apos;`]*n[&quot;&apos;`]*d\b.*"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell invoke-command cmdlet. Can be abused to execute malicious commands "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_27">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bi[&quot;&apos;`]*n[&quot;&apos;`]*v[&quot;&apos;`]*o[&quot;&apos;`]*k[&quot;&apos;`]*e[&quot;&apos;`]*-[&quot;&apos;`]*e[&quot;&apos;`]*x[&quot;&apos;`]*p[&quot;&apos;`]*r[&quot;&apos;`]*e[&quot;&apos;`]*s[&quot;&apos;`]*s[&quot;&apos;`]*i[&quot;&apos;`]*o[&quot;&apos;`]*n\b.*"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell invoke-expression cmdlet. Can be abused to execute file-less scripts "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_28">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bi[&quot;&apos;`]{0,2}p[&quot;&apos;`]{0,2}a[&quot;&apos;`]{0,2}l\b.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block import-alias to create new aliases for exploitable cmdlets "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_29">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bn[&quot;&apos;`]{0,2}a[&quot;&apos;`]{0,2}l\b.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block new-alias to create new aliases for exploitable cmdlets "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_3">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="outlook.exe"/>
<Setting name="process-name" value="cmd.exe"/>
<Setting name="rule-description" value="Block command-prompt to be launched from mail client(outlook.exe) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_30">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bn[&quot;&apos;`]{0,2}e[&quot;&apos;`]{0,2}w[&quot;&apos;`]{0,2}-[&quot;&apos;`]{0,2}a[&quot;&apos;`]{0,2}l[&quot;&apos;`]{0,2}i[&quot;&apos;`]{0,2}a[&quot;&apos;`]{0,2}s\b.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block new-alias to create new aliases for exploitable cmdlets "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_31">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bs[&quot;&apos;`]{0,2}a[&quot;&apos;`]{0,2}l\b.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block set-alias to create new aliases for exploitable cmdlets "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_32">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bs[&quot;&apos;`]{0,2}e[&quot;&apos;`]{0,2}t[&quot;&apos;`]{0,2}-[&quot;&apos;`]{0,2}a[&quot;&apos;`]{0,2}l[&quot;&apos;`]{0,2}i[&quot;&apos;`]{0,2}a[&quot;&apos;`]{0,2}s\b.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block set-alias to create new aliases for exploitable cmdlets "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_33">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bi[&quot;&apos;`]{0,2}m[&quot;&apos;`]{0,2}p[&quot;&apos;`]{0,2}o[&quot;&apos;`]{0,2}r[&quot;&apos;`]{0,2}t[&quot;&apos;`]{0,2}-[&quot;&apos;`]{0,2}a[&quot;&apos;`]{0,2}l[&quot;&apos;`]{0,2}i[&quot;&apos;`]{0,2}a[&quot;&apos;`]{0,2}s\b.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block import-alias to create new aliases for exploitable cmdlets "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_34">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*[-/\u2013\u2014\u2015]&quot;{0,2}c(?:&quot;{0,2}o(?:&quot;{0,2}m(?:&quot;{0,2}m(?:&quot;{0,2}a(?:&quot;{0,2}n(?:&quot;{0,2}d)?)?)?)?)?)?&quot;{0,2}\s+.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell -command parameter. Can be abused to execute malicious commands "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_35">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*[-/\u2013\u2014\u2015]&quot;{0,2}e(?:&quot;{0,2}n(?:&quot;{0,2}c(?:&quot;{0,2}o(?:&quot;{0,2}d(?:&quot;{0,2}e(?:&quot;{0,2}d(?:&quot;{0,2}c(?:&quot;{0,2}o(?:&quot;{0,2}m(?:&quot;{0,2}m(?:&quot;{0,2}a(?:&quot;{0,2}n(?:&quot;{0,2}d)?)?)?)?)?)?)?)?)?)?)?)?)?&quot;{0,2}\s+.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell -encodedcommand parameter. Can be abused to execute encoded malicious commands "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_36">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*[-/\u2013\u2014\u2015]&quot;{0,2}e&quot;{0,2}a&quot;{0,2}\s+.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell -encodedarguments parameter. Can be abused to pass encoded malicious arguments "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_37">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*[-/\u2013\u2014\u2015]&quot;{0,2}e&quot;{0,2}c&quot;{0,2}\s+.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell -encodedcommand parameter. Can be abused to execute encoded malicious commands "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_38">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*[-/\u2013\u2014\u2015]&quot;{0,2}e&quot;{0,2}n&quot;{0,2}c&quot;{0,2}o&quot;{0,2}d&quot;{0,2}e&quot;{0,2}d&quot;{0,2}a(?:&quot;{0,2}r(?:&quot;{0,2}g(?:&quot;{0,2}u(?:&quot;{0,2}m(?:&quot;{0,2}e(?:&quot;{0,2}n(?:&quot;{0,2}t(?:&quot;{0,2}s)?)?)?)?)?)?)?)?&quot;{0,2}\s+.+"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell -encodedarguments parameter. Can be abused to pass encoded malicious arguments "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_39">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="winword.exe"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell to be launched from MS Word(macro exploitation) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_4">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="msaccess.exe"/>
<Setting name="process-name" value="cmd.exe"/>
<Setting name="rule-description" value="Block command-prompt to be launched from MS Access(macro exploitation) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_40">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="outlook.exe"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell to be launched from e-mail client(outlook.exe) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_41">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="msaccess.exe"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell to be launched from MS Access(macro exploitation) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_42">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="excel.exe"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell to be launched from MS Excel(macro exploitation) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_43">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="powerpnt.exe"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell to be launched from MS Powerpoint(macro exploitation) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_44">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="chrome.exe"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell to be launched from common browsers(Google Chrome) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_45">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="iexplore.exe"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell to be launched from common browsers(Internet Explorer) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_46">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="firefox.exe"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell to be launched from common browsers(Mozilla Firefox) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_47">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="opera.exe"/>
<Setting name="process-name" value="powershell.exe"/>
<Setting name="rule-description" value="Block powershell to be launched from common browsers(Opera) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_48">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*"/>
<Setting name="process-name" value="powershell_ise.exe"/>
<Setting name="rule-description" value="Block Powershell ISE by default. Only needed on developer machines "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_49">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*"/>
<Setting name="process-name" value="ProcessHacker.exe"/>
<Setting name="rule-description" value="Block Process Hacker by default "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_5">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="excel.exe"/>
<Setting name="process-name" value="cmd.exe"/>
<Setting name="rule-description" value="Block command-prompt to be launched from MS Excel(macro exploitation) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_50">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*"/>
<Setting name="process-name" value="rcsi.exe"/>
<Setting name="rule-description" value="Block rcsi.exe by default "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_51">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\.&quot;{0,2}s&quot;{0,2}c&quot;{0,2}t.*"/>
<Setting name="process-name" value="regsvr32.exe"/>
<Setting name="rule-description" value="Block regsvr32 from executing .sct scripts "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_52">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\.&quot;{0,2}w&quot;{0,2}s&quot;{0,2}c.*"/>
<Setting name="process-name" value="regsvr32.exe"/>
<Setting name="rule-description" value="Block regsvr32 from executing .wsc scripts "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_53">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*s&quot;{0,2}c&quot;{0,2}r&quot;{0,2}o&quot;{0,2}b&quot;{0,2}j.*"/>
<Setting name="process-name" value="regsvr32.exe"/>
<Setting name="rule-description" value="Block regsvr32 from calling functions in scrobj.dll "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_54">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*s&quot;{0,2}c&quot;{0,2}r&quot;{0,2}r&quot;{0,2}u&quot;{0,2}n.*"/>
<Setting name="process-name" value="regsvr32.exe"/>
<Setting name="rule-description" value="Block regsvr32 from calling functions in scrrun.dll  "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_55">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*m&quot;{0,2}s&quot;{0,2}h&quot;{0,2}t&quot;{0,2}m&quot;{0,2}l.*"/>
<Setting name="process-name" value="rundll32.exe"/>
<Setting name="rule-description" value="Block rundll32 from calling functions in mshtml.dll  "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_56">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bd&quot;{0,2}e&quot;{0,2}l&quot;{0,2}e&quot;{0,2}t&quot;{0,2}e\b.+\bs&quot;{0,2}c&quot;{0,2}s&quot;{0,2}r&quot;{0,2}v&quot;{0,2}c\b.*"/>
<Setting name="process-name" value="sc.exe"/>
<Setting name="rule-description" value="Block sc delete scsrvc "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_57">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\bs&quot;{0,2}e&quot;{0,2}r&quot;{0,2}v&quot;{0,2}i&quot;{0,2}c&quot;{0,2}e\b.+\bs&quot;{0,2}c&quot;{0,2}s&quot;{0,2}r&quot;{0,2}v&quot;{0,2}c\b.+\bd&quot;{0,2}e&quot;{0,2}l&quot;{0,2}e&quot;{0,2}t&quot;{0,2}e\b.*"/>
<Setting name="process-name" value="wmic.exe"/>
<Setting name="rule-description" value="Block wmic service delete scsrvc "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_58">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*"/>
<Setting name="process-name" value="windbg.exe"/>
<Setting name="rule-description" value="Block common debuggers (windbg.exe) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_59">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*/&quot;{0,2}e&quot;{0,2}:.+"/>
<Setting name="process-name" value="wscript.exe"/>
<Setting name="rule-description" value="Block wscript from specifying Engine parameter to execute scripts "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_6">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="powerpnt.exe"/>
<Setting name="process-name" value="cmd.exe"/>
<Setting name="rule-description" value="Block command-prompt to be launched from MS Powerpoint(macro exploitation) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_60">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="command_line"/>
<Setting name="match-type_0" value="matches"/>
<Setting name="pattern_0" value=".*\?\s*&quot;{0,2}\.&quot;{0,2}w&quot;{0,2}s&quot;{0,2}f.*"/>
<Setting name="process-name" value="wscript.exe"/>
<Setting name="rule-description" value="Block wscript from executing any file as a wsf file "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_61">
<Setting name="action" value="allow"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="condition-type_1" value="command_line"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="match-type_1" value="matches"/>
<Setting name="pattern_0" value="chrome.exe"/>
<Setting name="pattern_1" value=".*mcchhost.*"/>
<Setting name="process-name" value="cmd.exe"/>
<Setting name="rule-description" value="Allow command prompt to be launched from Google Chrome to allow enablement of ENS WebControl "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_7">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="chrome.exe"/>
<Setting name="process-name" value="cmd.exe"/>
<Setting name="rule-description" value="Block command-prompt to be launched from common browsers(Google Chrome) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_8">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="iexplore.exe"/>
<Setting name="process-name" value="cmd.exe"/>
<Setting name="rule-description" value="Block command-prompt to be launched from common browsers(Internet Explorer) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="General_Rule_9">
<Setting name="action" value="block"/>
<Setting name="condition-type_0" value="parent_process_name"/>
<Setting name="match-type_0" value="equals"/>
<Setting name="pattern_0" value="firefox.exe"/>
<Setting name="process-name" value="cmd.exe"/>
<Setting name="rule-description" value="Block command-prompt to be launched from common browsers(Mozilla Firefox) "/>
<Setting name="type" value="execution-control"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Execution Control Rules"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (13EA12C0-FAD5-4595-8D76-0BB18810BD23)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="msimn.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Outlook1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Microsoft Outlook Express"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (04EF93BE-7086-41F6-96FB-8E0748A85D44)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="begins"/>
<Setting name="pattern_0" value="%ProgramFiles%\McAfee\Solidcore"/>
<Setting name="rule-uuid" value="be9cfba3-ca29-41fa-b370-816c5cd6f2d1"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_10">
<Setting name="path" value="\trendmicro"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_11">
<Setting name="path" value="\imclntinst"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="true"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_12">
<Setting name="path" value="\lastgood"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="true"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_13">
<Setting name="path" value="\scinv"/>
<Setting name="skipChangeTracking" value="true"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_14">
<Setting name="path" value="\recycled"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="true"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_15">
<Setting name="path" value="\solidcore.log"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="true"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_16">
<Setting name="path" value="\pagefile.sys"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_17">
<Setting name="path" value="\recycler"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="true"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_18">
<Setting name="path" value="\microsoft\forms"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="true"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_19">
<Setting name="path" value="fbwf.cfg"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_2">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="begins"/>
<Setting name="pattern_0" value="%ProgramFiles%\McAfee\Solidcore"/>
<Setting name="rule-uuid" value="be9cfba3-ca29-41fa-b370-816c5cd6f2d1"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_20">
<Setting name="path" value="\enum"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="true"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_21">
<Setting name="path" value="\performance"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="true"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_22">
<Setting name="path" value="\$recycle.bin"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="true"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_23">
<Setting name="path" value="\csc"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="true"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_24">
<Setting name="path" value="\system volume information"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_25">
<Setting name="path" value="\sis common store"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="true"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_26">
<Setting name="path" value="\qaquotasv4"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="true"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_27">
<Setting name="path" value="\s3diag.log"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="true"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_28">
<Setting name="path" value="\mountpointmanagerremotedatabase"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_29">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="ends"/>
<Setting name="pattern_0" value="\solidcore\_tdll.dll"/>
<Setting name="rule-uuid" value="ce5ae680-56be-494d-9e78-e2ad41bc6b51"/>
<Setting name="type" value="advanced-inv-exclusion"/>
</Section>
<Section name="General_Rule_3">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="begins"/>
<Setting name="pattern_0" value="%ProgramW6432%\McAfee\Solidcore"/>
<Setting name="rule-uuid" value="912d2da6-49b9-401a-98da-11dd2cbb27b1"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_30">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="ends"/>
<Setting name="pattern_0" value="\solidcore\_ernel32.dll"/>
<Setting name="rule-uuid" value="2c41228d-d3bb-44e1-9318-e80d168e7b70"/>
<Setting name="type" value="advanced-inv-exclusion"/>
</Section>
<Section name="General_Rule_31">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="ends"/>
<Setting name="pattern_0" value=".svn"/>
<Setting name="rule-uuid" value="94bb14bf-de21-4c5b-b351-090fdd5f6e29"/>
<Setting name="type" value="advanced-inv-exclusion"/>
</Section>
<Section name="General_Rule_32">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="ends"/>
<Setting name="pattern_0" value=".svn-base"/>
<Setting name="rule-uuid" value="b0ef4252-d15e-4a9e-bd24-4c5e7079e71d"/>
<Setting name="type" value="advanced-inv-exclusion"/>
</Section>
<Section name="General_Rule_33">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="begins"/>
<Setting name="pattern_0" value="%WINDIR%.old"/>
<Setting name="rule-uuid" value="09f45c50-db21-487f-bfa3-9988f787ac0b"/>
<Setting name="type" value="advanced-inv-exclusion"/>
</Section>
<Section name="General_Rule_34">
<Setting name="path" value="\windows\system32"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="true"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_35">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="match-type_0" value="contains"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="\compattelrunner.exe"/>
<Setting name="pattern_1" value="PKG_MODIFICATION_PREVENTED"/>
<Setting name="rule-uuid" value="c3a2fd11-b836-4f28-9751-7976e8425a9f"/>
<Setting name="type" value="mon-advanced"/>
</Section>
<Section name="General_Rule_36">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="Process"/>
<Setting name="condition-type_1" value="Event"/>
<Setting name="match-type_0" value="contains"/>
<Setting name="match-type_1" value="equals"/>
<Setting name="pattern_0" value="\compattelrunner.exe"/>
<Setting name="pattern_1" value="PKG_MODIFICATION_PREVENTED"/>
<Setting name="rule-uuid" value="c3a2fd11-b836-4f28-9751-7976e8425a9f"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_37">
<Setting name="path" value="\windows\catroot2"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_38">
<Setting name="path" value="\windows\softwaredistribution\datastore"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_39">
<Setting name="path" value="\windows\softwaredistribution\download"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_4">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="begins"/>
<Setting name="pattern_0" value="%ProgramW6432%\McAfee\Solidcore"/>
<Setting name="rule-uuid" value="912d2da6-49b9-401a-98da-11dd2cbb27b1"/>
<Setting name="type" value="ob-exclusion"/>
</Section>
<Section name="General_Rule_40">
<Setting name="path" value="\windows\winsxs\backup"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_41">
<Setting name="path" value="\windows\winsxs\catalogs"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_42">
<Setting name="path" value="\windows\winsxs\manifests"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_43">
<Setting name="path" value="\windows\winsxs\temp"/>
<Setting name="skipChangeTracking" value="false"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="true"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="General_Rule_5">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="condition-type_1" value="File"/>
<Setting name="match-type_0" value="contains"/>
<Setting name="match-type_1" value="ends"/>
<Setting name="pattern_0" value="\tanium"/>
<Setting name="pattern_1" value=".vbs"/>
<Setting name="rule-uuid" value="2c92028a-48f6-4527-b292-22f4cc7ccd7c"/>
<Setting name="type" value="advanced-inv-exclusion"/>
</Section>
<Section name="General_Rule_6">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="ends"/>
<Setting name="pattern_0" value=".rbf"/>
<Setting name="rule-uuid" value="ba803aa2-52c0-46ad-a999-1ecc17aad092"/>
<Setting name="type" value="advanced-inv-exclusion"/>
</Section>
<Section name="General_Rule_7">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="ends"/>
<Setting name="pattern_0" value=".fon"/>
<Setting name="rule-uuid" value="19d781d0-b081-439b-ae42-df46b4447a97"/>
<Setting name="type" value="advanced-inv-exclusion"/>
</Section>
<Section name="General_Rule_8">
<Setting name="action" value="exclude"/>
<Setting name="condition-type_0" value="File"/>
<Setting name="match-type_0" value="contains"/>
<Setting name="pattern_0" value="\$RECYCLE.BIN"/>
<Setting name="rule-uuid" value="dfd3bdd0-837c-468a-8466-8bd3c670cee9"/>
<Setting name="type" value="advanced-inv-exclusion"/>
</Section>
<Section name="General_Rule_9">
<Setting name="path" value="\scinvlog"/>
<Setting name="skipChangeTracking" value="true"/>
<Setting name="skipDenyWrite" value="false"/>
<Setting name="skipFileOperation" value="false"/>
<Setting name="skipFileOperation_f" value="false"/>
<Setting name="skipRegistry" value="false"/>
<Setting name="skipSolidification" value="false"/>
<Setting name="skipVolume" value="false"/>
<Setting name="type" value="skiplist"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="McAfee Exclusion Filters"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (FCEAD766-1543-4B84-9A5A-587250759138)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="svchost.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="library" value="appxdeploymentserver.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="METROAPP1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="svchost.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="library" value="wsservice.dll"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="METROAPP2"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Metro Apps"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (CBE848B5-747E-49C8-A3D8-6FE0F84A3B5A)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="dexplore.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="true"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="false"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="My SQL Server 5.0"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (171F1BE2-E1BE-410F-9BE5-CC67FCA7DF67)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="odbctst.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Oracle8i1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="OMSNTsrv.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="Oracle9i1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Oracle"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (614E09A4-F5FE-4578-9598-FF5B9B188223)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="cmd.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="userinit.exe"/>
<Setting name="tag" value="Terminal_Server1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Terminal Server"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (BD5D11DE-8170-4F2F-A216-A3C90F2B8BC8)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="General_Rule_1">
<Setting name="binary" value="updater.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="parent" value="firefox.exe"/>
<Setting name="tag" value="Firefox1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="General_Rule_100">
<Setting name="always_auth" value="false"/>
<Setting name="always_unauth" value="false"/>
<Setting name="anti_debugging_bypass" value="false"/>
<Setting name="casp_bypass" value="false"/>
<Setting name="dep_bypass" value="false"/>
<Setting name="file" value="helper.exe"/>
<Setting name="full_crawl" value="false"/>
<Setting name="installer_detection_bypass" value="false"/>
<Setting name="is_general_attr" value="true"/>
<Setting name="mangling_bypass" value="false"/>
<Setting name="parent" value="firefox.exe"/>
<Setting name="process_ctx_bypass" value="false"/>
<Setting name="process_ctx_reg_bypass" value="false"/>
<Setting name="rebase_dll" value="false"/>
<Setting name="type" value="attr"/>
<Setting name="uninstall_bypass" value="true"/>
<Setting name="vasr_force_reloc_bypass" value="false"/>
<Setting name="vasr_rand_bypass" value="false"/>
<Setting name="vasr_reloc_bypass" value="false"/>
</Section>
<Section name="General_Rule_2">
<Setting name="binary" value="Mozilla Maintenance Service\maintenanceservice.exe"/>
<Setting name="inherit" value="true"/>
<Setting name="log" value="true"/>
<Setting name="tag" value="MozillaMaintenanceService1"/>
<Setting name="type" value="updater-binary"/>
</Section>
<Section name="scor_info">
<Setting name="group_name" value="Mozilla Firefox"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicySettings name="McAfee Default (copy)::Settings (E7550B69-3437-4313-9175-E652F2448679)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" typeid="AWL Rules (Windows)" param_int="0" param_str="">
<Section name="scor_info">
<Setting name="group_name" value="Global Rules"/>
<Setting name="group_type" value="application_control"/>
<Setting name="platforms" value="WIN"/>
<Setting name="readOnly" value="true"/>
</Section>
</EPOPolicySettings>
<EPOPolicyObject name="McAfee Default (copy)" featureid="SCOR_AWL" categoryid="AWL Rules (Windows)" serverid="EPO" editflag="0" typeid="AWL Rules (Windows)">
<description></description><PolicySettings>McAfee Default (copy)::Settings (5251B0C9-F3DC-4C23-A949-BA34ECDD42D1)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (CEDC2033-DC34-46F9-82C2-62AFAD0907E0)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (3C8BEB61-F4DB-4457-9CCD-EFA39406C0C5)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (8E04C387-823C-45C1-AE09-FFA3972E2FB8)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (64EE11F5-81F7-49E7-BE3C-08C37CC1BB72)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (8840DD3C-74A3-4B9E-9D35-91E1B0D037EC)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (14028856-9D9B-48BF-81D0-514B35F45CA7)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (C07BEE62-3728-4116-9F47-BA5B48F0E448)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (D996322C-FB6D-43DF-9F2B-41431B002FE9)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (CA254238-50B3-4239-804E-CA3CCD1E9431)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (C5B6F340-19D9-426F-BFB7-FF44EAEA533A)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (11FA7CCC-AAEB-4E16-B11E-2AA5B91F03EF)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (C927B36F-AB89-47AE-8422-D86D1DB600DA)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (5EB10814-763C-4D3A-94E6-BAC33ED71114)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (0B0267C3-FBAA-4980-BE60-CDFD3E6A950B)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (FF0D439F-ECC5-43FB-A259-0DC940F54B33)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (2E90172A-F5E6-4A53-9D7A-F140B199E641)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (DDCFC1BC-E048-4D90-A97A-34AA1B2730CE)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (934E8DE2-3B5D-4A8A-89AA-BB7359D4D687)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (C851720E-4669-43DC-A7A7-B3883ECFE83C)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (9EDBAD11-31BE-45FF-B92F-99C2CD9DAA09)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (1F741063-9042-4FF7-849E-5A98E79AA257)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (D33F4D3E-E7F0-4771-B543-0D684809A88E)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (68A58F40-F58C-48FB-B501-8AD35953A2DA)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (0700C425-B5B4-49EF-B637-367997355461)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (26BD82BD-33EA-4B3C-B732-69B48CE135E6)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (CA62F95A-A14D-4E74-90ED-0D5B2B7C8249)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (03792578-5D55-4A75-8F5B-E620B2D1D479)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (741EB429-1E82-4D47-AB9C-75CAEB7C0678)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (55FA779A-280E-4D18-89BF-D0FE9BDEDD96)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (963E6D7B-D039-46C3-AE93-7A903BFAAA51)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (9F948935-07D3-49D4-A864-0DBBDC78D323)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (D840ECFC-4560-4A31-AEF8-DFDF87058E6D)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (D62D31FB-EC4F-4840-83E0-9D25037F02C3)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (2BB4B279-6A07-4A61-ADF1-CAB516194338)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (964881E9-EBD0-4C69-94AA-BEDED8364BEE)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (810A220D-6164-4B3C-867E-74887B966651)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (F1153B3E-8B42-4D4C-8207-4C813ABF5197)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (88DD14EA-B44F-4323-A967-64A0E125F7D7)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (1BCC8286-C3E1-4A53-921F-B4454B8EEE90)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (79177D49-CC72-4FD2-8ACB-02AE7D7A5786)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (AFE1B3C0-C7B4-478B-A5CB-C6846D95029F)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (06CC33C2-9E78-47F3-B786-04D654A35FD0)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (0045790B-49CA-4689-8A10-08118057AD32)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (45C5B340-1C73-4F62-84A6-A4E7CCE45DB0)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (87327BDE-D804-4B0A-BAA2-54E6AEC62CDA)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (47028DA1-A2EF-4286-8759-4DB0C327ACC4)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (772E16C8-4724-43DB-88CC-E1E30828F023)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (BCAE88C3-5612-40A1-867C-AFC6BB377390)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (59E8B457-FDA9-4B4D-8866-9CDF2976362E)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (6ECBB36C-AA89-459E-A3F1-08F36B201804)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (A63B13F5-21A6-41A6-8A90-2CF52FA557E2)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (28AEBF88-BEDD-4C1F-A5AD-962F2E8B4A9E)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (67E52B15-750F-43B4-96DF-A3EE6987552A)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (605DA2B3-553D-47BA-9F02-A61C59536D6D)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (2968A63A-F7FE-4456-B08D-E37B8D999426)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (E5733FA8-D54D-48BA-B215-AB7B513B7BA8)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (469B1739-A56E-468C-9E2A-A749202C769B)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (9A5F1EA4-8C98-4B63-B858-9B94DC9F7FDD)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (8D09FD0F-F1FD-40B8-B844-9407F6C3D495)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (4AEDDCD0-7AEE-4F3A-8162-D10DF8D461F7)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (1611B731-FE1D-4F48-8595-3F78E94A764F)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (375E909E-ED57-4C11-96BC-A93117AA9ED2)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (969DE862-B571-452F-BDCA-9177E6555886)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (1D1B28F4-01DB-4B41-BAEA-9B872BB804EB)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (BD536600-5005-4DFD-9BD8-0253C783E0D5)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (67F964A9-FEE1-41D8-94EB-178E85814EBB)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (F0D2921F-B08F-414B-8ADF-023531075E73)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (49FCA257-670F-4065-98D7-AC0FA09322FC)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (1F176015-1779-471F-B1A8-35DE7B766343)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (64AD0943-26C5-48CC-87B6-FC49E6B16842)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (1AFD9ACD-FAB1-4BED-8BA0-76E63301F8D5)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (740CCDFB-3169-4CE9-9025-964082BFCA94)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (A5F22A55-E65D-4670-ADDC-406D7BE24210)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (BB5F5089-F148-44DF-A03D-279CA98149A3)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (F996A055-680E-4F88-B438-20E6126BB578)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (878ABFEC-4F99-4320-9C43-8595CEA79EEE)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (F81CA625-3B36-47EE-BD35-19AE72EA25AE)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (01E76F5A-CFDD-4BD8-A57E-FE28E5D119C0)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (96F3DD3D-5B30-4B15-A7BB-064CF55E937F)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (12639350-DD47-4E98-9D37-829C4AE9E237)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (92FCEC05-EFC1-4FC7-8112-E5C765E8974B)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (63CD1157-1367-4D57-BBA3-5A779A546943)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (BEE6E203-78E1-481C-AD4D-B275D511404D)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (9A6B7074-12E1-4BEA-8DAB-DAB944A96295)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (B1CDD288-94C6-4E38-A6C1-BFEE1672D287)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (FA979D44-FF89-4E24-B038-0A0AEBC5DD2F)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (6FF1EDD7-183F-4A38-88B6-38E38516EC51)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (8A0819B5-45A8-411A-8051-EBE3E8A55A9E)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (07B016F8-F95F-4581-B0BB-F9171A59BE9E)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (43F35DDE-428E-4C82-B10D-0F9DA669041A)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (E007DD91-2A59-4531-B8E8-A2E626AEC376)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (933BD63D-D482-439C-AB64-89519C23C1E4)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (566F664D-51A5-4EFE-BA1E-59D336890936)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (CCC1554C-4CBF-4076-A794-A828BA9E2F6D)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (13EA12C0-FAD5-4595-8D76-0BB18810BD23)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (04EF93BE-7086-41F6-96FB-8E0748A85D44)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (FCEAD766-1543-4B84-9A5A-587250759138)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (CBE848B5-747E-49C8-A3D8-6FE0F84A3B5A)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (171F1BE2-E1BE-410F-9BE5-CC67FCA7DF67)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (614E09A4-F5FE-4578-9598-FF5B9B188223)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (BD5D11DE-8170-4F2F-A216-A3C90F2B8BC8)</PolicySettings>
<PolicySettings>McAfee Default (copy)::Settings (E7550B69-3437-4313-9175-E652F2448679)</PolicySettings>
</EPOPolicyObject>
</epo:EPOPolicySchema>