/ Published in: Windows Registry
URL: http://www.symantec.com/business/antivirus-corporate-edition
When you install Symantec Antivirus Corporate Edition, the default settings are not very secure. The following registry script will increase the security settings to a more reasonable level. This is for version 10; I suspect the settings for version 11 and 12 are stored in a similar registry location, and finding the location was the hardest part.
Expand |
Embed | Plain Text
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\PatternManager] "LockUpdatePattern"=dword:00000000 "LockUpdatePatternScheduling"=dword:00000000 "MaxDefsDaysOldAllowed"=dword:00000005 "AdminForcedLUCheckInterval"=dword:0000001e "TypeOfDownload"=dword:00000001 "DownLoadStatus"=dword:00000000 "EnableAdminForcedLU"=dword:00000001 "CheckConfigMinutes"=dword:0000003c "EnableProductUpdates"=dword:00000001 "UpdateClients"=dword:00000001 "SetClientFromServer"=dword:00000001 "AFLUDelay"=dword:0000001e [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\PatternManager\Schedule] "SkipEvent"=dword:00000000 "RandomizeDayOfWeek"=dword:00000006 "MinOfDay"=dword:00000348 "MissedEventEnabled"=dword:00000001 "LastStart"=dword:00000000 "TimeWindowMonthly"=dword:0000000b "Type"=dword:00000001 "DayOfWeek"=dword:00000000 "TimeWindowWeekly"=dword:00000003 "TimeWindowDaily"=dword:00000008 "RandomizeDayRange"=dword:0000012c "RandomizeWeekStart"=dword:00000004 "RandomizeWeekEnd"=dword:00000006 "RandomizeMinOfDay"=dword:00000031 "Enabled"=dword:00000001 "DayOfMonth"=dword:00000000 "RandomizeDayEnabled"=dword:00000000 "RandomizeWeekEnabled"=dword:00000000 "RandomizeMonthEnabled"=dword:00000000 "Created"=dword:4dbf2419 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages] [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem] "ServiceStatus"=dword:00000001 "ServiceStorageStartCode"=dword:00000000 "ClientStorageStartCode"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan] "APEOn"=dword:00000001 "APESleep"=dword:00000003 "DoCompressed"=dword:00000001 "CDRoms"=dword:00000000 "APEOff"=dword:00000000 "SystemStart"=dword:00000000 "ConfigRestart"=dword:00000001 "DenyAccess"=dword:00000002 "Reads"=dword:00000001 "Execs"=dword:00000001 "Writes"=dword:00000001 "BackupToQuarantine"=dword:00000001 "Cache"=dword:00000001 "FileCacheEntries"=dword:00000000 "Storage"=dword:00000001 "FirstMacroAction"=dword:00000003 "SecondMacroAction"=dword:00000001 "FirstAction"=dword:00000003 "SecondAction"=dword:00000001 "FirstGreywareAction"=dword:00000004 "SecondGreywareAction"=dword:00000004 "Networks"=dword:00000001 "MessageBox"=dword:00000001 "FileType"=dword:00000000 "HaveExceptionDirs"=dword:00000000 "HaveExceptionFiles"=dword:00000000 "ExcludedByExtensions"=dword:00000000 "AccessCounter"=dword:00000003 "NavexInterfaceToUse"=dword:00000002 "RespondToThreats"=dword:00000003 "OnOff"=dword:00000001 "DriveList"="" "LowLevelFormat"=dword:00000001 "ScanFloppyBROnAccess"=dword:00000001 "RemoveAlertSeconds"=dword:00000001 "HeuristicsLevel"=dword:00000002 "CheckSum"=dword:00000000 "Types"=dword:00000006 "CheckRemoveable"=dword:00000001 "Trap"=dword:00000000 "Floppys"=dword:00000001 "ZipFile"=dword:00000000 "HardDriveBRWrite"=dword:00000001 "ZipDepth"=dword:00000003 "FloppyBRWrite"=dword:00000000 "FloppyBRAction"=dword:00000005 "HardDisks"=dword:00000001 "Softmice"=dword:00000001 "Exts"="DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH" "RemoveAlert"=dword:00000000 "Heuristics"=dword:00000001 "ExcludedExtensions"="" "PrescanExclude"=dword:00000000 "CheckForBadOpCode"=dword:00000000 "ClientNotify"=dword:00000001 "ClientReportFormat"="~E~V in ~F" "HoldOnClose"=dword:00000001 "StatusDialogTitle"="Auto-Protect Results" "ScanNotifyTerminateProcess"=dword:00000001 "ScanNotifyStopService"=dword:00000001 "ScanNotifyReboot"=dword:00000002 "DisplayStatusDialog"=dword:00000001 "PreserveTimeStamp"=dword:00000001 "NetScanOnCloseDisable"=dword:00000000 "BackupToQuarantine-L"=dword:00000001 "CDRoms-L"=dword:00000001 "ExcludedByExtensions-L"=dword:00000001 "Execs-L"=dword:00000001 "Exts-L"=dword:00000001 "FileType-L"=dword:00000001 "FirstAction-L"=dword:00000001 "FirstMacroAction-L"=dword:00000001 "Floppys-L"=dword:00000001 "HaveExceptionDirs-L"=dword:00000001 "HaveExceptionFiles-L"=dword:00000001 "MessageBox-L"=dword:00000001 "Networks-L"=dword:00000001 "OnOff-L"=dword:00000001 "Reads-L"=dword:00000001 "SecondAction-L"=dword:00000001 "SecondMacroAction-L"=dword:00000001 "Types-L"=dword:00000001 "Writes-L"=dword:00000001 "APTrust"=dword:00000001 "APTrust-L"=dword:00000001 "APNetworkCache"=dword:00000000 "APNetworkCache-L"=dword:00000001 "MaxNetCacheEntries"=dword:00000000 "MaxNetCacheEntries-L"=dword:00000001 "NetworkCleanCacheTimeout"=dword:00000000 "NetworkCleanCacheTimeout-L"=dword:00000001 "SmartScan"=dword:00000001 "SmartScan-L"=dword:00000001 "OpenScanningMode"=dword:00000000 "OpenScanningMode-L"=dword:00000001 "MessageText"="Scan type: ~L Scan Event: ~E ~V File: ~P Location: ~C Computer: ~S User: ~N Action taken: ~A Date found: ~T" "MessageText-L"=dword:00000001 "StatusHWND"=dword:00000000 "DeleteInfectedOnCreate"=dword:00000001 "ThreatTracerOnOff"=dword:00000001 "ThreatTracerResolveIP"=dword:00000001 "ThreatTracerBackgroundOnOff"=dword:00000001 "ThreatTracerSleepMsecs"=dword:000003e8 "ThreatTracerAutoBlock"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan\ChecksumConfig] [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan\Expanded] "FirstAction"=dword:00000003 "SecondAction"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan\Expanded\PVID] [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan\Expanded\TCID-10] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan\Expanded\TCID-11] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan\Expanded\TCID-4] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan\Expanded\TCID-5] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan\Expanded\TCID-6] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan\Expanded\TCID-7] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan\Expanded\TCID-8] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan\Expanded\TCID-9] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail] "ServiceDLLName"="IMail.dll" "ServiceDLLPath"="C:\\Program Files\\Symantec AntiVirus\\" "ServiceDLLEntryPoint"="ImStorageInit" "Type"=dword:80000020 "ServiceStatus"=dword:00000000 "ServiceStorageStartCode"=dword:00000000 "ClientStorageStartCode"=dword:2000002b [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail\RealTimeScan] "OehOnOff"=dword:00000001 "OnOff"=dword:00000001 "ChangeMessageSubject"=dword:00000001 "Exts"="DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH,JPG,JPEG,PDF,CMD" "FileType"=dword:00000000 "FirstAction"=dword:00000003 "FirstMacroAction"=dword:00000003 "FirstOehAction"=dword:00000003 "InsertWarning"=dword:00000001 "MessageBox"=dword:00000001 "NotifySelected"=dword:00000000 "NotifySender"=dword:00000000 "SecondAction"=dword:00000001 "SecondMacroAction"=dword:00000001 "SecondOehAction"=dword:00000001 "Types"=dword:00000006 "ZipDepth"=dword:0000000a "ZipExts"="ARJ,LHA,ZIP,MME,LZH,UUE" "ZipFile"=dword:00000001 "AlertSenderServerName"="mail" "AlertSelectedServerName"="mail" "Pop3Port"=dword:0000006e "SmtpPort"=dword:00000019 "ProgressWindow"=dword:00000001 "ProgressIcon"=dword:00000001 "ScanNotifyStopService"=dword:00000001 "ScanNotifyTerminateProcess"=dword:00000001 "DisplayStatusDialog"=dword:00000001 "MessageText"="Scan type: ~L Scan Event: ~E ~V File: ~P Location: ~C Computer: ~S User: ~N Action taken: ~A Date found: ~T" [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail\RealTimeScan\Expanded] "FirstAction"=dword:00000003 "SecondAction"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail\RealTimeScan\Expanded\PVID] [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail\RealTimeScan\Expanded\TCID-10] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail\RealTimeScan\Expanded\TCID-11] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail\RealTimeScan\Expanded\TCID-4] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail\RealTimeScan\Expanded\TCID-5] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail\RealTimeScan\Expanded\TCID-6] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail\RealTimeScan\Expanded\TCID-7] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail\RealTimeScan\Expanded\TCID-8] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\InternetMail\RealTimeScan\Expanded\TCID-9] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes] "Type"=dword:80000004 "ServiceStatus"=dword:00000000 "ServiceStorageStartCode"=dword:00000000 "ClientStorageStartCode"=dword:2000002b "ServiceDLLEntryPoint"="NSE_StorageInit" "DisplayName"="LotusNotes" "ServiceDLLName"="NotesExt.dll" "ServiceDLLPath"="C:\\Program Files\\Symantec AntiVirus\\" "HookDLLName"="nLNVP.dll" "NotesWatch"=dword:0000001e [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan] "OnOff"=dword:00000001 "ChangeMessageSubject"=dword:00000001 "SecondMacroAction"=dword:00000001 "ZipExts"="ARJ,LHA,ZIP,MME,LZH,UUE" "NotifySelected"=dword:00000000 "FirstAction"=dword:00000003 "Types"=dword:00000006 "Recipients"="" "FirstMacroAction"=dword:00000003 "NotifySender"=dword:00000000 "FileType"=dword:00000000 "Reads"=dword:00000001 "MessageBox"=dword:00000001 "ZipFile"=dword:00000001 "ZipDepth"=dword:0000000a "SecondAction"=dword:00000001 "InsertWarning"=dword:00000001 "Exts"="DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH,JPG,JPEG,PDF,CMD" "ScanNotifyStopService"=dword:00000001 "ScanNotifyTerminateProcess"=dword:00000001 "DisplayStatusDialog"=dword:00000001 "MessageText"="Scan type: ~L Scan Event: ~E ~V File: ~P Location: ~C Computer: ~S User: ~N Action taken: ~A Date found: ~T" [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan\Expanded] "FirstAction"=dword:00000003 "SecondAction"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan\Expanded\PVID] [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan\Expanded\TCID-10] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan\Expanded\TCID-11] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan\Expanded\TCID-4] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan\Expanded\TCID-5] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan\Expanded\TCID-6] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan\Expanded\TCID-7] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan\Expanded\TCID-8] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan\Expanded\TCID-9] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient] "ServiceStatus"=dword:00000000 "ServiceStorageStartCode"=dword:00000000 "ClientStorageStartCode"=dword:2000002b "Type"=dword:80000002 "ServiceDLLEntryPoint"="MEC_StorageInit" "ServiceDLLPath"="C:\\Program Files\\Symantec AntiVirus\\" "ServiceDLLName"="vpmsece3.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan] "OnOff"=dword:00000001 "FirstMacroAction"=dword:00000003 "NotifySender"=dword:00000000 "FileType"=dword:00000000 "RenameExt"="VIR" "MessageBox"=dword:00000001 "ZipFile"=dword:00000001 "ZipDepth"=dword:0000000a "SecondAction"=dword:00000001 "InsertWarning"=dword:00000001 "Exts"="DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH,JPG,JPEG,PDF,CMD" "ChangeMessageSubject"=dword:00000001 "SecondMacroAction"=dword:00000001 "ZipExts"="ARJ,LHA,ZIP,MME,LZH,UUE" "NotifySelected"=dword:00000000 "FirstAction"=dword:00000003 "Types"=dword:00000006 "Recipients"="" "FirstMacroAction-L"=dword:00000001 "FirstAction-L"=dword:00000001 "SecondMacroAction-L"=dword:00000001 "SecondAction-L"=dword:00000001 "OnOff-L"=dword:00000001 "FileType-L"=dword:00000001 "MessageBox-L"=dword:00000001 "InsertWarning-L"=dword:00000001 "NotifySender-L"=dword:00000001 "NotifySelected-L"=dword:00000001 "MessageText"="Scan type: ~L Scan Event: ~E ~V File: ~P Location: ~C Computer: ~S User: ~N Action taken: ~A Date found: ~T" "MessageText-L"=dword:00000001 "ScanNotifyStopService"=dword:00000001 "ScanNotifyTerminateProcess"=dword:00000001 "DisplayStatusDialog"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan\Expanded] "FirstAction"=dword:00000003 "SecondAction"=dword:00000001 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan\Expanded\PVID] [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan\Expanded\TCID-10] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan\Expanded\TCID-11] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan\Expanded\TCID-4] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan\Expanded\TCID-5] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan\Expanded\TCID-6] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan\Expanded\TCID-7] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan\Expanded\TCID-8] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan\Expanded\TCID-9] "OverrideDefaultActions"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\SymProtect] "ServiceDLLName"="SymProtectStorage.dll" "ServiceDLLPath"="C:\\Program Files\\Symantec AntiVirus\\" "ServiceDLLEntryPoint"="StorageInit" "DisplayName"="Tamper Protection" "Type"=dword:c0000040 "ServiceStatus"=dword:00000000 "ServiceStorageStartCode"=dword:00000000 "ClientStorageStartCode"=dword:2000002b [HKEY_LOCAL_MACHINE\SOFTWARE\Intel\LANDesk\VirusProtect6\CurrentVersion\Storages\SymProtect\RealTimeScan] "LogInfectionText"="SYMANTEC TAMPER PROTECTION ALERT Target: ~Q Event Info: ~H ~J Action Taken: ~G Actor Process: ~M (PID ~K) Time: ~T" "Disabled"=dword:00000000 "MessageText"="SYMANTEC TAMPER PROTECTION ALERT Target: ~Q Event Info: ~H ~J Action Taken: ~G Actor Process: ~M (PID ~K) Time: ~T" "NotifyEventA"=dword:0000002d "MessageBox"=dword:00000000 "ProtectionProcess"=dword:00000001 "ProtectStandalone"=dword:00000001
You need to login to post a comment.
