Hey Guys,
5805 flags PWS.Bancos.A, DO NOT Remove. I made that fatal mistake late last
night at work and home. It wipes out all of the registry keys for Symantec.
After it removed thoses 340 or so registry keys, you can't even un-install
the software. The only thing I found to work was go back to a Restore Point
before the keys were removed. Un-Install Norton, re-boot, and re-install
Norton. And pray that was all it touched. Below is a snippet of what will
be removed if you did remove PWS.Bancos.A
Spyware Scan Details
Start Date: 2/9/2006 11:52:36 PM
End Date: 2/10/2006 12:22:23 AM
Total Time: 29 mins 47 secs
Detected Threats
PWS.Bancos.A Password Stealer more information...
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such
as a security exploit, and should be removed.
Infected registry keys/values detected
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ComCache 8e9145bd-703d-11d1-81c9-00a0c95c0756 LDVPView
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan FileType 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan ScanAllDrives 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan MessageBox 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan ZipFile 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan Logger 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan ZipDepth 3
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan ScanLocked 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan SecondAction 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan
Exts
DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan Softmice 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common ForwardLogs 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan ExcludedByExtensions 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan ExcludedExtensions
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan PrescanExclude 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep ZipExts ARJ,LHA,ZIP,MME,LZH,UUE,CAB,LZ_,RTF,UU,MIM
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep SecondMacroAction 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep DoCompressed 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep ScanBootSector 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep FirstAction 5
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep Checksum 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep NeededFreeDiskSpace 30720000
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common SelectedMessage Symantec AntiVirus found a virus in an attachment from ~D.
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep NeededFreeDataDiskSpace 10240000
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep DisplayStatusDialog 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep WantedUtilization 3
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep Types 6
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep HaveExceptionDirs 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep FirstMacroAction 5
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep ScanMemory 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep FileType 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep ScanAllDrives 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep ZipFile 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common SelectedSubject Virus Found in message "~U"
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep MessageBox 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep ZipDepth 3
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep Logger 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep SecondAction 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep ScanLocked 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep Softmice 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep
Exts
DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule RandomizeDayOfWeek 6
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule RandomizeMinOfDay 49
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule RandomizeWeekEnd 6
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
SelectedInfectionInformation Attachment: ~O ~V Action taken: ~A File status:
~Z
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule RandomizeWeekStart 4
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule RandomizeDayRange 300
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule TimeWindowWeekly 3
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule TimeWindowDaily 8
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule DayOfWeek 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule Type 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule Enabled 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule TimeWindowMonthly 11
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule MinofDay 1080
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule MissedEventEnabled 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common WarningMessage Symantec AntiVirus found a virus in an attachment from ~D.
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule DayOfMonth 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule RandomizeDayEnabled 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule RandomizeWeekEnabled 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule RandomizeMonthEnabled 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule Created 1137296761
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule SkipEvent 3
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule LastStart 1139277603
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager MaxDefsDaysOldAllowed 9
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager EnableAdminForcedLU 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager AdminForcedLUCheckInterval 60
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common WarningSubject Virus Found in message "~U"
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager TypeOfDownload 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager UpdateClients 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager LockUpdatePattern 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager LockUpdatePatternScheduling 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager EnableProductUpdates 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager DownLoadStatus 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl CheckForNewParentIntervalInSeconds 30
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl CheckParentIntervalInMinutes 120
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl FindNearestParentIntervalInMinutes 60
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl Debug
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
WarningInfectionInformation Attachment: ~O ~V Action taken: ~A File status:
~Z
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl Verbose 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl ClientDir Alert
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl ManageThisComputer 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl ProcessLoginNow 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl ClientCount 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl LastStatusCode 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine RepairedItemPurgeFrequency 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine RepairedItemPurgeAgeLimit 90
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine RepairedItemPurgeEnabled 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine BackupItemPurgeFrequency 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
SenderMessage Symantec AntiVirus found a virus in an attachment you (~D) sent
to ~I. To ensure the recipient(s) are able to use the files you sent, perform
a virus scan on your computer, clean any infected files, then resend this
attachment.
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine BackupItemPurgeAgeLimit 90
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine BackupItemPurgeEnabled 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine QuarantinePurgeFrequency 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine QuarantinePurgeAgeLimit 90
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine QuarantinePurgeEnabled 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine ForwardingProtocol 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine ScanDeliverResubmit 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine ForwardingServerRetryTimer 600
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine ForwardingServerTimer 1800
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine ForwardingEnabled 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common SenderSubject Virus Found in message "~U"
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine DefWatchMode 2
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine ForwardingPort 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine ForwardingServer
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine ScanDeliverEnabled 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\FileSystem
License
524E0AFD8FEBC330A683749B9BBF2BA02587FBBC76365AE3BAD35F6A29BF902B67659A0F75C22C96BFD18402863
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\FileSystem DisplayName File System
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\FileSystem Type 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\FileSystem Pages 7
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\FileSystem GUID
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\LotusNotes
License
524864207A044C97C616621E97771D2C169E577ACC33FBD47D635F6A29BF902B67659A0F75C22C96BFD1A4D5B68
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\AdministratorOnly\General ShowVPIcon 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
SenderInfectionInformation Attachment: ~O ~V Action taken: ~A File status: ~Z
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\LotusNotes DisplayName Lotus Notes
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\LotusNotes GUID
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\LotusNotes Type -2147483644
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\LotusNotes Pages 2
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\MicrosoftExchangeClient
License
52499C45C1ED37843F5A2EF4CAB5CDC5FF1E577ACC33FBD47D635F6A29BF902B67659A0F75C22C96BFD624D2A10
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\MicrosoftExchangeClient DisplayName Microsoft Exchange
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\MicrosoftExchangeClient GUID
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\MicrosoftExchangeClient Type -2147483646
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\MicrosoftExchangeClient Pages 2
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan APESleep 30
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
MessageText Scan type: ~L Scan Event: ~E ~V File: ~P Location: ~C Computer:
~S User: ~N Action taken: ~A Date found: ~T
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan APEOn 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan APEOff 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan SecondMacroAction 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan DoCompressed 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan DriveList
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan LowLevelFormat 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan ScanFloppyBROnAccess 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan FirstAction 5
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan Writes 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan CDRoms 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common NTEventLog 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan RemoveAlertSeconds 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan HeuristicsLevel 2
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan CheckSum 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan BackupToQuarantine 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan Types 6
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan HaveExceptionDirs 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan FirstMacroAction 5
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan CheckRemoveable 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan FileType 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan Reads 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common AlertParent 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan Trap 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan Floppys 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan ZipFile 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan HardDriveBRWrite 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan ZipDepth 3
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan DenyAccess 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan Networks 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan FloppyBRWrite 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan FloppyBRAction 5
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan SecondAction 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common RenameExt VIR
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan Execs 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan HardDisks 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan Softmice 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan
Exts
DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan RemoveAlert 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan Heuristics 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan ExcludedByExtensions 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan ExcludedExtensions
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan MessageBox 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan PrescanExclude 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common LDVPEventLog 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan OnOff 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan Cache 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan CheckForBadOpCode 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan ClientNotify 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan ClientReportFormat ~E~V in ~F
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan HoldOnClose 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem ServiceStatus 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem ServiceStorageStartCode 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem ClientStorageStartCode 0
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\LotusNotes\RealTimeScan SecondMacroAction 1
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common MessageBox 1