Hi,
1. To display all, you can right click on the drive letter in Windows Explorer, and choose "Show All Trust Level". Currently it is read-only, but we are planning to make it editable in the future.
2. You are right, during initial full system scan, or whenever a file is trusted, the certificate that corresponding to the file will be automatically added to the trusted certificate list.
3. To understand this, first we have to understand the different between trusted application and trusted installer. All executable files created by a trusted installer will be automatically trusted without any prompting. When a trusted application starts to create an executable file, SAP will offer the user whether they want to promote it to a trusted installer, so that everything that it creates will be automatically trusted.
4. The quarantine files are stored encrypted in a certain location. Since it is encrypted, the files can no longer run.
5. Those are temporary elevation. During run-time, the process will inherit the trust of the parent process (temporarily).
6. We have analyzed how Windows Update works, and set all the necessary files to be a trusted installer to allow Windows Update to perform.