[KEYS] !KEY!=$REGROOT$ AlertDirectory=S\\JHENTAV1\VPALERT$ Connected=D1 LogFileRollOverDays=D30 LogFrequency=D0 DisableSplashScreen=D1 Parent=SJHENTAV1 RemoteHomeDirectory=S\\JHENTAV1\VPHOME GRCUpdateTime=B00082506100D2119B702 ParentPattern=D2479632 BackRevCounter=D0 !KEY!=$REGROOT$\AddressCache !KEY!=$REGROOT$\AddressCache\JHENTAV1 Address_0=B0020000020000B9700000AB510520000000000000000000000000000000000000000 Protocol=SAddress_0 good=D1 !KEY!=$REGROOT$\AdministratorOnly !KEY!=$REGROOT$\AdministratorOnly\General DisplayOutdatedMessage=D1 ShowVPIcon=D1 SSPowerMgmt=D1 StartupScansEnabled=D0 DisplayMissingDefMessage=D1 WindowsSecurityCenterControl=D0 AntiVirusDisableNotify=D0 WSCDefsUpToDate=D10 WarnAfterDays=D7 PattRemediationMaxAttempts=D2 RunBrowser=D0 PatternWarningMessage=SYour virus definitions are currently out of date. Please run LiveUpdate or contact your system administrator on how to update them. StartupScansLocked=D1 RunLoggedOutUsersScheduledScans=D0 EnableDefwatchQuickscan=D1 !KEY!=$REGROOT$\AdministratorOnly\Security LockUnloadServices=D0 NetScanPassword=S1084A085DC6BD2D755D4D6A7726 UseScanNetDrivePassword=D0 UseVPUninstallPassword=D1 VPUninstallPassword=S1084A085DC6BD2D755D4D6A7726 !KEY!=$REGROOT$\Common AlertParent=D1 ForwardLogs=D1 LDVPCommonConfiguration=D1 MessageBox=D1 NTCommonConfiguration=D1 RenameExt=SVIR NTEventLog=D1 LDVPEventLog=D1 !KEY!=$REGROOT$\Common\ForwardEvents !KEY!=$REGROOT$\Common\ForwardEvents\0 2=D1 26=D1 27=D1 28=D0 29=D0 30=D1 31=D1 32=D1 33=D1 18=D0 25=D1 24=D0 23=D0 22=D1 21=D1 20=D0 16=D0 14=D1 13=D1 12=D0 7=D1 6=D0 5=D1 4=D0 3=D1 19=D0 34=D0 35=D0 37=D0 39=D0 40=D1 45=D1 52=D1 53=D0 54=D1 55=D1 56=D0 57=D1 58=D1 59=D1 60=D1 61=D0 62=D1 65=D1 66=D1 46=D1 47=D0 48=D1 49=D1 50=D1 51=D1 11=D1 !KEY!=$REGROOT$\Common\ForwardEvents\47 472001=D1 472000=D0 472004=D0 472003=D1 !KEY!=$REGROOT$\Common\ForwardEvents\49 492002=D1 492001=D1 492000=D0 492003=D1 !KEY!=$REGROOT$\LiveUpdateSource EncryptPassword=D1 UseDefault=D1 !KEY!=$REGROOT$\LocalScans !KEY!=$REGROOT$\LocalScans\ManualScan FileType=D0 FirstAction=D5 FirstMacroAction=D5 Logger=D1 MessageBox=D0 ScanAllDrives=D1 ScanBootSector=D1 ScanMemory=D1 SecondAction=D1 SecondMacroAction=D1 Softmice=D1 Types=D6 ZipDepth=D3 ZipExts=SARJ,LHA,ZIP,MME,LZH,UUE,CAB,LZ_,RTF,UU,MIM ZipFile=D1 ShowStatusDialog=D0 DisplayStatusDialog=D0 Exts=SDOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH,JPG,JPEG Checksum=D0 NeededFreeDiskSpace=D30720000 !KEY!=$REGROOT$\ManualScan !KEY!=$REGROOT$\ManualScan\ChecksumConfig FirstAction=D4 SecondAction=D4 !KEY!=$REGROOT$\PatternManager AdminForcedLUCheckInterval=D30 CheckConfigMinutes=D60 EnableAdminForcedLU=D1 EnableProductUpdates=D0 LockUpdatePattern=D0 LockUpdatePatternScheduling=D0 MaxDefsDaysOldAllowed=D3 UpdateClients=D1 TypeOfDownload=D1 SetClientFromServer=D1 AFLUDelay=D30 !KEY!=$REGROOT$\PatternManager\Schedule DayOfMonth=D0 DayOfWeek=D5 Enabled=D0 MinOfDay=D1200 MissedEventEnabled=D1 RandomizationGenerate=D17 RandomizeDayEnabled=D1 RandomizeDayRange=D480 RandomizeMonthEnabled=D0 RandomizeWeekEnabled=D1 RandomizeWeekEnd=D6 RandomizeWeekStart=D4 SkipEvent=D0 TimeWindowDaily=D8 TimeWindowWeekly=D3 Type=D2 Created=D1023404379 !KEY!=$REGROOT$\ProductControl ManageThisComputer=D0 !KEY!=$REGROOT$\Quarantine BackupItemPurgeAgeLimit=D90 BackupItemPurgeEnabled=D1 BackupItemPurgeFrequency=D0 DefWatchMode=D0 ForwardingEnabled=D0 ForwardingPort=D0 ForwardingProtocol=D0 ForwardingServer=S ForwardingServerRetryTimer=D600 ForwardingServerTimer=D1800 QuarantinePurgeAgeLimit=D90 QuarantinePurgeEnabled=D1 QuarantinePurgeFrequency=D0 RepairedItemPurgeAgeLimit=D90 RepairedItemPurgeEnabled=D1 RepairedItemPurgeFrequency=D0 ScanDeliverEnabled=D0 ScanDeliverResubmit=D0 !KEY!=$REGROOT$\Storages !KEY!=$REGROOT$\Storages\FileSystem !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan APTrust=D1 APNetworkCache=D0 MaxNetCacheEntries=D0 NetworkCleanCacheTimeout=D0 AccessCounter=D7 APBlockingSecurityRisks=D1 HaveExceptionDirs=D1 HaveExceptionFiles=D1 ExcludedByExtensions=D1 CheckSumTempExts=SEXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,CMD,DOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,JSE,VBE,SH,SHB,WSF,WSH,PL,PM,CSH,PDF,JPG,JPEG,ARJ,LHA,ZIP,MME,LZH,UUE,AMG,IMZ,CAB,LZ Heuristics=D1 HeuristicsLevel=D2 SkipShutDownFloppyCheck=D0 ScanFloppyBROnAccess=D1 FloppyBRAction=D5 LowLevelFormat=D1 HardDriveBRWrite=D1 FloppyBRWrite=D0 RemoveAlert=D0 RemoveAlertSeconds=D1 SystemStart=D0 DeleteInfectedOnCreate=D1 PreserveTimeStamp=D1 !APEOn=D1 !APESleep=D60 ThreatTracerOnOff=D1 ThreatTracerResolveIP=D1 ThreatTracerBackgroundOnOff=D1 ThreatTracerSleepMsecs=D1000 ThreatTracerAutoBlock=D1 Writes=D1 Reads=D1 Execs=D1 BackupToQuarantine=D1 Storage=D0 ConfigRestart=D1 Cache=D1 FileCacheEntries=D0 CheckSumTempExts-D=D1 FirstMacroAction=D5 SecondMacroAction=D1 FirstAction=D5 SecondAction=D1 ScanNotifyStopService=D0 ScanNotifyTerminateProcess=D0 DisplayStatusDialog=D0 MessageText=SScan type: ~L Scan\nEvent: ~E\n~V\nFile: ~P\nLocation: ~C\nComputer: ~S\nUser: ~N\nAction taken: ~A\nDate found: ~T MessageBox=D1 RespondToThreats=D3 Networks=D0 SmartScan=D1 !OnOff=D1 CDRoms=D0 !Floppys=D1 FileType=D0 CheckRemovable=D1 DenyAccess=D2 DoCompressed=D0 DriveList=S Exts=SDOT,DOC,HTML,HTT,HTM,VBS,JS,SHS,PPT,MSO,POT,RTF,MDB,JTD,HLP,INF,INI,HTA,MP?,OBD,OBT,PPS,SMM,VSD,VST,XL?,VSS,EXE,COM,BIN,SYS,DLL,OCX,VXD,BAT,BTM,CSC,PIF,386,CLA,OV?,DRV,SCR,ACM,ACV,ADT,AX,CPL,CSH,JSE,PL,PM,SH,SHB,VBE,WSF,WSH,JPG,JPEG FirstGreywareAction=D4 HardDisks=D1 HoldOnClose=D1 SecondGreywareAction=D4 Softmice=D1 Trap=D0 Types=D6 ZipDepth=D3 ZipExts=SARJ,LHA,ZIP,MME,LZH,UUE,CAB,LZ_,RTF,UU,MIM ZipFile=D0 FirstOehAction=D1 SecondOehAction=D3 !OpenScanningMode=D0 !UseVolumeInfoList=D0 !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\ChecksumConfig FirstAction=D4 SecondAction=D4 !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\Expanded FirstAction=D1 SecondAction=D4 !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\Expanded\PVID !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\Expanded\TCID-10 OverrideDefaultActions=D0 FirstAction=S SecondAction=S FirstAction-D=D1 SecondAction-D=D1 ExceptionsLock=D0 !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\Expanded\TCID-11 OverrideDefaultActions=D0 FirstAction=S SecondAction=S FirstAction-D=D1 SecondAction-D=D1 ExceptionsLock=D0 !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\Expanded\TCID-4 OverrideDefaultActions=D0 FirstAction=S SecondAction=S FirstAction-D=D1 SecondAction-D=D1 ExceptionsLock=D0 !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\Expanded\TCID-5 OverrideDefaultActions=D0 FirstAction=S SecondAction=S FirstAction-D=D1 SecondAction-D=D1 ExceptionsLock=D0 !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\Expanded\TCID-6 OverrideDefaultActions=D0 FirstAction=S SecondAction=S FirstAction-D=D1 SecondAction-D=D1 ExceptionsLock=D0 !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\Expanded\TCID-7 OverrideDefaultActions=D0 FirstAction=S SecondAction=S FirstAction-D=D1 SecondAction-D=D1 ExceptionsLock=D0 !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\Expanded\TCID-8 OverrideDefaultActions=D0 FirstAction=S SecondAction=S FirstAction-D=D1 SecondAction-D=D1 ExceptionsLock=D0 !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\Expanded\TCID-9 OverrideDefaultActions=D0 FirstAction=S SecondAction=S FirstAction-D=D1 SecondAction-D=D1 ExceptionsLock=D0 !KEY!=$REGROOT$\Storages\FileSystem\RealTimeScan\NoScanDir !KEY!=$REGROOT$\Storages\InternetMail !KEY!=$REGROOT$\Storages\InternetMail\RealTimeScan AlertSenderServerName=Smail AlertSelectedServerName=Smail ZipFile=D1 ZipDepth=D3 ChangeMessageSubject=D1 FirstMacroAction=D5 FirstAction=D5 FirstOehAction=D1 SecondMacroAction=D1 SecondAction=D1 SecondOehAction=D3 OnOff=D1 OehOnOff=D1 FileType=D0 MessageBox=D1 InsertWarning=D1 NotifySender=D0 NotifySelected=D0 PopTlsDetect=D1 SmtpTlsDetect=D1 AccessCounter=D3 FirstGreywareAction=D4 SecondGreywareAction=D4 !KEY!=$REGROOT$\Storages\LotusNotes !KEY!=$REGROOT$\Storages\LotusNotes\RealTimeScan ZipFile=D1 ZipDepth=D3 ChangeMessageSubject=D1 FirstMacroAction=D5 FirstAction=D5 SecondMacroAction=D1 SecondAction=D1 OnOff=D1 FileType=D0 MessageBox=D1 InsertWarning=D1 NotifySender=D0 NotifySelected=D0 AccessCounter=D3 FirstGreywareAction=D4 SecondGreywareAction=D4 FirstOehAction=D1 SecondOehAction=D3 !KEY!=$REGROOT$\Storages\MicrosoftExchangeClient !KEY!=$REGROOT$\Storages\MicrosoftExchangeClient\RealTimeScan ZipFile=D1 ZipDepth=D3 ChangeMessageSubject=D1 FirstMacroAction=D5 FirstAction=D5 SecondMacroAction=D1 SecondAction=D1 OnOff=D1 FileType=D0 MessageBox=D1 InsertWarning=D1 NotifySender=D0 NotifySelected=D0 AccessCounter=D3 FirstGreywareAction=D4 SecondGreywareAction=D4 FirstOehAction=D1 SecondOehAction=D3 !KEY!=$REGROOT$\Storages\SymProtect !KEY!=$REGROOT$\Storages\SymProtect\RealTimeScan NotifyEventA=D45 MessageText=SSYMANTEC TAMPER PROTECTION ALERT\n\nTarget: ~Q\nEvent Info: ~H ~J\nAction Taken: ~G\nActor Process: ~M (PID ~K)\nTime: ~T LogInfectionText=SSYMANTEC TAMPER PROTECTION ALERT\n\nTarget: ~Q\nEvent Info: ~H ~J\nAction Taken: ~G\nActor Process: ~M (PID ~K)\nTime: ~T !Disabled=D1 ProtectionProcess=D0 ProtectStandalone=D0 MessageBox=D0