If you "cleaned" the false positive from 5805....

B

Bill Sanderson

It would be useful to see the file:

\program files\microsoft antispyware\cleaner.log

I'm open to posts of the relevant portion of this text file in the groups,
or zipped emails of the file to:

(e-mail address removed)

Thanks to anyone who can respond to this with a file showing what entries
were involved in this false positive.

--
 
G

Guest

When I received the alert, I clicked the link for more information on the
threat. None was available.

It might help to keep some small percentage of users from hosing their
Norton installations by putting some info in that space. Like, "Update your
definitions and rescan before deleting these registry keys." Just a thought.

Now, I must get back to searching for the #$&(*() Norton installer.

ts
 
G

Guest

2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
[MessageText=Scan type: ~L Scan
Event: ~E
~V
File: ~P
Location: ~C
Computer: ~S
User: ~N
Action taken: ~A
Date found: ~T
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
[NTEventLog=1
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
[AlertParent=0
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
[RenameExt=VIR
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
[LDVPEventLog=1
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
[MessageBox=1
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Common
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine1 [ProductType=VirusDef
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine1 [ProductName=Avenge 1.5 MicroDefs2 Corp
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine1 [ProductVersion=MicroDefsB.Jan
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine1 [ProductLanguage=SymAllLanguages
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine1
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine2 [ProductName=Avenge 1.5 MicroDefs2 Corp
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine2 [ProductVersion=MicroDefsB.CurDefs
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine2 [ProductType=VirusDef
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine2 [ProductLanguage=SymAllLanguages
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine2
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine3 [ProductVersion=1.0
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine3 [ProductName=AV Engine 5.0 Definitions
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine3 [ProductLanguage=English
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine3 [ProductType=VirusDef
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine3
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine4 [ProductVersion=8.0
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine4 [ProductType=Update
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine4 [ProductLanguage=English
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine4 [ProductName=Symantec AntiVirus Corporate Client NT
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines\CmdLine4
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate\CmdLines
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdate
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdateAdminSched [Installed=0
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LiveUpdateAdminSched
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Repair Options [SecondMacroAction=4
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Repair Options [FirstAction=5
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Repair Options [FirstMacroAction=5
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Repair Options [FileType=0
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Repair Options [BackUpToQuarantine=0
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Repair Options [ZipFile=1
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Repair Options [MessageBox=0
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Repair Options [ZipDepth=3
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Repair Options [SecondAction=4
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Repair Options [Status=9
2/11/2006 5:29:52 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Repair Options
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan NoZip Options [SecondMacroAction=4
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan NoZip Options [FirstAction=4
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan NoZip Options [FirstMacroAction=4
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan NoZip Options [FileType=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan NoZip Options [BackUpToQuarantine=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan NoZip Options [MessageBox=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan NoZip Options [ZipFile=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan NoZip Options [ZipDepth=3
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan NoZip Options [SecondAction=4
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan NoZip Options [Status=9
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan NoZip Options
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan Options [SecondMacroAction=4
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan Options [FirstAction=4
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan Options [FirstMacroAction=4
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan Options [FileType=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan Options [BackUpToQuarantine=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan Options [ZipFile=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan Options [MessageBox=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan Options [ZipDepth=3
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan Options [SecondAction=4
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan Options [Status=9
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\CScan Scan Options
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options [ZipFile=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options [SecondMacroAction=4
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options [ZipDepth=3
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options [Status=9
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options [MessageBox=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options [BackUpToQuarantine=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options [FileType=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options [FirstAction=5
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options [FirstMacroAction=5
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options [Logger=11
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options [SecondAction=4
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\Defwatch CScan Repair Options
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan\Directories [C:=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan\Directories
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [ZipExts=ARJ,LHA,ZIP,MME,LZH,UUE,CAB,LZ_,RTF,UU,MIM
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [SecondMacroAction=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [DoCompressed=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [FirstAction=5
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [ScanBootSector=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [Checksum=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [NeededFreeDiskSpace=30720000
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [NeededFreeDataDiskSpace=10240000
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [DisplayStatusDialog=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [Types=6
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [WantedUtilization=3
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [HaveExceptionDirs=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [FirstMacroAction=5
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [ScanMemory=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [FileType=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [ScanAllDrives=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [MessageBox=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [ZipFile=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [Logger=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [ZipDepth=3
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [ScanLocked=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [SecondAction=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan
[Exts=DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [Softmice=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [ExcludedByExtensions=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [ExcludedExtensions=
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan [PrescanExclude=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\ManualScan
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep\Directories
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [ZipExts=ARJ,LHA,ZIP,MME,LZH,UUE,CAB,LZ_,RTF,UU,MIM
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [SecondMacroAction=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [DoCompressed=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [ScanBootSector=1
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [FirstAction=5
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [Checksum=0
2/11/2006 5:29:53 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [NeededFreeDiskSpace=30720000
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [NeededFreeDataDiskSpace=10240000
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [DisplayStatusDialog=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [WantedUtilization=3
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [Types=6
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [HaveExceptionDirs=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [FirstMacroAction=5
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [ScanMemory=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [FileType=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [ScanAllDrives=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [ZipFile=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [MessageBox=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [ZipDepth=3
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [Logger=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [SecondAction=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [ScanLocked=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep [Softmice=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep
[Exts=DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans\VirusSweep
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\LocalScans
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [RandomizeDayOfWeek=6
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [RandomizeMinOfDay=49
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [RandomizeWeekEnd=6
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [RandomizeWeekStart=4
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [RandomizeDayRange=300
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [TimeWindowWeekly=3
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [TimeWindowDaily=8
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [DayOfWeek=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [Type=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [Enabled=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [TimeWindowMonthly=11
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [MinofDay=315
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [MissedEventEnabled=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [LastStart=1139652913
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [SkipEvent=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [DayOfMonth=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [RandomizeDayEnabled=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [RandomizeWeekEnabled=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [RandomizeMonthEnabled=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule [Created=1106212373
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager\Schedule
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager [MaxDefsDaysOldAllowed=9
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager [EnableAdminForcedLU=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager [AdminForcedLUCheckInterval=60
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager [TypeOfDownload=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager [UpdateClients=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager [LockUpdatePattern=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager [LockUpdatePatternScheduling=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager [EnableProductUpdates=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager [DownLoadStatus=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\PatternManager
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl [CheckForNewParentIntervalInSeconds=30
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl [CheckParentIntervalInMinutes=120
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl [FindNearestParentIntervalInMinutes=60
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl [Debug=
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl [Verbose=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl [ClientDir=Alert
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl [ManageThisComputer=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl [ProcessLoginNow=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl [ClientCount=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl [LastStatusCode=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\ProductControl
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [RepairedItemPurgeFrequency=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [RepairedItemPurgeAgeLimit=90
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [RepairedItemPurgeEnabled=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [BackupItemPurgeFrequency=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [BackupItemPurgeAgeLimit=90
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [BackupItemPurgeEnabled=1
End of first post
 
G

Guest

2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [QuarantinePurgeFrequency=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [QuarantinePurgeAgeLimit=90
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [QuarantinePurgeEnabled=1
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [ForwardingProtocol=0
2/11/2006 5:29:54 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [ScanDeliverResubmit=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [ForwardingServerRetryTimer=600
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [ForwardingServerTimer=1800
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [ForwardingEnabled=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [DefWatchMode=2
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [ForwardingPort=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [ForwardingServer=
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine [ScanDeliverEnabled=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Quarantine
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\FileSystem
[License=524E0AFD8FEBC330A683749B9BBF2BA02587FBBC76365AE3BAD35F6A29BF902B67659A0F75C22C96BFD18402863
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\FileSystem [DisplayName=File System
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\FileSystem [Type=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\FileSystem [Pages=7
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\FileSystem [GUID=
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\FileSystem
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\MicrosoftExchangeClient
[License=52499C45C1ED37843F5A2EF4CAB5CDC5FF1E577ACC33FBD47D635F6A29BF902B67659A0F75C22C96BFD624D2A10
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\MicrosoftExchangeClient [DisplayName=Microsoft Exchange
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\MicrosoftExchangeClient [GUID=
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\MicrosoftExchangeClient [Type=-2147483646
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\MicrosoftExchangeClient [Pages=2
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In\MicrosoftExchangeClient
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Snap-In
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [APESleep=30
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [APEOn=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [APEOff=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [SecondMacroAction=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [DoCompressed=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [DriveList=
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [LowLevelFormat=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [ScanFloppyBROnAccess=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [FirstAction=5
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [Writes=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [CDRoms=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [RemoveAlertSeconds=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [HeuristicsLevel=3
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [CheckSum=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [BackupToQuarantine=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [Types=6
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [HaveExceptionDirs=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [FirstMacroAction=5
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [CheckRemoveable=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [FileType=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [Reads=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [Trap=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [Floppys=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [ZipFile=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [HardDriveBRWrite=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [ZipDepth=3
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [DenyAccess=2
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [Networks=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [FloppyBRWrite=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [FloppyBRAction=5
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [SecondAction=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [Execs=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [HardDisks=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [Softmice=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan
[Exts=DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [RemoveAlert=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [Heuristics=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [ExcludedByExtensions=0
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [ExcludedExtensions=
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [MessageBox=1
2/11/2006 5:29:55 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [PrescanExclude=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [OnOff=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [Cache=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [CheckForBadOpCode=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [ClientNotify=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [ClientReportFormat=~E~V in ~F
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [HoldOnClose=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [AccessCounter=91
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [HaveExceptionFiles=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan [Storage=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem\RealTimeScan
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem [ServiceStatus=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem [ServiceStorageStartCode=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem [ClientStorageStartCode=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\Filesystem
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan
[Exts=DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [InsertWarning=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [SecondAction=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [OnOff=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [ZipDepth=3
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [ZipFile=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [MessageBox=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [RenameExt=VIR
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [FileType=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [NotifySender=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [FirstMacroAction=5
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [Recipients=
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [Types=6
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [FirstAction=5
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [ChangeMessageSubject=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [NotifySelected=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [ZipExts=ARJ,LHA,ZIP,MME,LZH,UUE
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [SecondMacroAction=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan [AccessCounter=4
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient\RealTimeScan
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient
[ServiceDLLPath=C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient [ServiceDLLEntryPoint=MEC_StorageInit
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient [Type=-2147483646
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient [ServiceDLLName=vpmsece.dll
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient [ServiceStatus=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient [ServiceStorageStartCode=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient [ClientStorageStartCode=536870955
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages\MicrosoftExchangeClient
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\Storages
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\SystemScan [NTEventLog=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\SystemScan [ForwardLogs=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\SystemScan [AlertParent=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\SystemScan [LDVPEventLog=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\SystemScan [MessageBox=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\SystemScan
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\TaskControlsII
[64b4a5ae-0799-11d1-812a-00a0c95c0756=5248B9DDE3ECD1277F0AFE79AE12BC21F09B927B40F09E1105C35F6A29BF902B67659A0F75C22C96BFD664A5B6E
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\TaskControlsII
[8e9145bd-703d-11d1-81c9-00a0c95c0756=524D5AF543EE7F5C722A597656ADCFCF8D12E99255452E7D1C635F6A29BF902B67659A0F75C22C96BFD684D5C68
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\TaskControlsII
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ClientUpdateStatus [UpdateStatus=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ClientUpdateStatus [UpdateType=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ClientUpdateStatus [UpdateOK=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ClientUpdateStatus [UpdateFail=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ClientUpdateStatus [UpdateTotalCount=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ClientUpdateStatus [UpdateCompleteTime=
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ClientUpdateStatus
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ServerUpdateStatus [UpdateStatus=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ServerUpdateStatus [UpdateType=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ServerUpdateStatus [UpdateOK=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ServerUpdateStatus [UpdateFail=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ServerUpdateStatus [UpdateTotalCount=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ServerUpdateStatus [UpdateCompleteTime=
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus\ServerUpdateStatus
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion\UpdateStatus
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[Enablevptraybubble=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[CopyControl=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion [Type=1
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[Status=0
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[ScanEngineVendor=NAV
2/11/2006 5:29:56 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[UsingPattern=2134024
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[PatternFileDate=
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[PatternFileRevision=8
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[PatternFileSequence=51745
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[ScanEngineVersion=67174415
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[MyProcessID=1480
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[InstalledProducts=-2147483645
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[Orientation=1
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[ProductVersion=614335264
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[DisableSplashScreen=1
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion [Home
Directory=C:\Program Files\Symantec_Client_Security\Symantec AntiVirus
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[VirusEngine=i2ldvp3.dll
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[ClientType=2
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[ProcessGRC=1
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[HeuristicLevel=2
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[CurrentPatternName=
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[ScanEngineHelpFile=C:\Program Files\Symantec_Client_Security\Symantec
AntiVirus\enunxp32.hlp
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[LogonWatchTimeout=1000
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[LicenseNumber=00141V-11CQ-1112
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[IgnoreStatus3=1
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[Connected=0
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[AllowSkipEvent=3
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[AgentIPPort=2967
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[AgentIpxPort=33345
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[Parent=
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[ClientScan=0
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[OSVer_PlatformId=2
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[OSVer_MajorVer=5
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[OSVer_MinorVer=1
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion [GUID=
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[LocalMAC=
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[RunUserScans=1
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[NoWarnPattern=
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[ClientPushNoneElapsedTime=0
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[TimeOfLastScan=
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
[TimeOfLastVirus=
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6\CurrentVersion
2/11/2006 5:29:57 AM::Removing registry value
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6
2/11/2006 5:29:57 AM::Removing registry key
HKEY_LOCAL_MACHINE\Software\Intel\Landesk\VirusProtect6
2/11/2006 5:30:05 AM::Clean Threat PWS.Bancos.A (ID:17148) Complete
2/11/2006 5:30:08 AM::Remove Threat (ID:17148) Complete
2/11/2006 5:30:09 AM::Unititializing Clean
End of 2nd post
 
B

Bill Sanderson

I agree that having more background info on the supposed threat being
detected would help. When I've found a threat warning in an unexpected
circumstance, I've generally done some research to find what really should
constitute that threat, in terms of executables in place on a system.
Unfortunately, this information can be hard to find, and isn't consistent
among different vendors.

False positives are a problem for every antispyware vendor. I don't expect
this to be the last one I ever see.

Here's my suggestions for Norton/Symantec recovery:

1) use System Restore to a restore point before Midnight Thursday.

2) use the setup program off the original Symantec/Norton media.

3) Use an automated or manual uninstaller--here are some good links to
those:

Manual:

http://service1.symantec.com/SUPPOR...4291648Automated:www.symantec.com/autotools--"Tom Savage" <Tom (e-mail address removed)> wrote in messagenews:[email protected]...> When I received the alert, I clicked the link for more information on the> threat. None was available.>> It might help to keep some small percentage of users from hosing their> Norton installations by putting some info in that space. Like, "Updateyour> definitions and rescan before deleting these registry keys." Just athought.>> Now, I must get back to searching for the #$&(*() Norton installer.>> ts>> "Bill Sanderson" wrote:>>> It would be useful to see the file:>>>> \program files\microsoft antispyware\cleaner.log>>>> I'm open to posts of the relevant portion of this text file in thegroups,>> or zipped emails of the file to:>>>> (e-mail address removed)>>>> Thanks to anyone who can respond to this with a file showing what entries>> were involved in this false positive.>>>> -->>>>>>>>
 
G

Guest

Bill, I'll try to send you the log since it's way too long to post here.
I'm having one heck of a time cleaning up after this mess. After removing &
reinstalling Antivirus, I have computers doing all sorts of wacky things.
One is rebooting over 4 times this morning and creating dumps. Two won't
open Winword (From office2003) but they do open excel. Several computers had
outlook issues. A few froze upon first login this morning. Meanwhile I'm so
busy trying to fix these supposedly "fixed" workstations that I don't have
time to try to "fix" the other (maybe "break" would be a more appropriate
word?) Many of them I have to do a full manual remove of symantec in order
to reinstall it.

Thanks,
Paula (an unhappy camper today and for the rest of the week it looks like.)
 
B

Bill Sanderson

Thanks--I'll pass that on to the team working on this incident--they are
very interested in seeing them.

I want to continue to urge anyone who is still feeling the pain from this
incident to get me those logs via email, if possible--they are helpful.
 
G

Guest

Just to let you know, this "false-positive" also trashed my WinFAXPro, which
is also a Symantec product. I've uninstalled and reinstalled it several
times, and cannot get it to work.
 
G

Guest

Daryl, We have several workstations that fax things using our fax server but
we don't use winfax pro. However I wonder if the 2 workstations that won't
open microsoft word might have been ones that used to have winfax pro
installed in the past... hmmmm? It's odd because there are two other
workstations right next to them that also fax and those 2 people are working
just fine.

Well, I'm rebuilding a fresh pc so that I can swap out the one that keeps
core dumping to see if I can find out more. If I find anything useful, I'll
post it.

Good Luck to you too!
Paula

Ps. Just want to mention that some people have pointed out in a rather
high-handed way that Microsoft Antispyware is still Beta and we shouldn't be
using it. Well I won't apologize for installing it on our company's
workstations. We're on a tight budget and this "Beta" works far better than
anything else I have tried to keep our workstations clean. Until I installed
it we had adware all over the place - so after I fix all these workstations -
you can bet I'm going to maybe modify my workstation settings... but I'm
going to keep using Microsoft Antispyware!
 
B

Bill Sanderson

Paula said:
Ps. Just want to mention that some people have pointed out in a rather
high-handed way that Microsoft Antispyware is still Beta and we shouldn't
be
using it. Well I won't apologize for installing it on our company's
workstations. We're on a tight budget and this "Beta" works far better
than
anything else I have tried to keep our workstations clean. Until I
installed
it we had adware all over the place - so after I fix all these
workstations -
you can bet I'm going to maybe modify my workstation settings... but I'm
going to keep using Microsoft Antispyware!

Thanks for your posts, Paula. I try not to play the "beta" card in relation
to this incident. I don't think that the definition creation process is any
less rigorous because it is for a "beta" consisting of more than 25 million
users.

I would encourage all users to move to Windows Defender--the beta2 product
mentioned for so long, is now available:

http://www.microsoft.com/downloads/...e7-da2b-4a6a-afa4-f7f14e605a0d&DisplayLang=en

If you are installing on Windows 2000, you'll need to precede the above
installation file with:

http://www.microsoft.com/downloads/...9c-df12-4d41-933c-be590feaa05a&DisplayLang=en

Expand, and place the .DLL file in \winnt\system32, or as appropriate for
your installation.
 
B

Bill Sanderson

Daryl--I know that in looking over the uninstall instructions for a Symantec
product they mentioned that ALL Symantec products had to be uninstalled for
the method to be effective.

You need to get in touch with Symantec about this issue. I would recommend
giving them a call--I'm told that help for this specific issue should be
available without the usual charges, but I haven't any direct experience to
point to.

--
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top