楼主: 31538i
收起左侧

[求助] 今天开机mcafee突然变成这样子。。

[复制链接]
dier
发表于 2007-11-14 13:37:53 | 显示全部楼层
见到过,在任务管理器结束explorer,然后再重新启动explorer,会短暂的出现这个M图标,很快就会变成V图标
31538i
 楼主| 发表于 2007-11-14 17:46:49 | 显示全部楼层
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\AVEngine]
"DAT"="C:\\Program Files\\Common Files\\McAfee\\Engine\\"
"szInstallDir32"="C:\\Program Files\\Common Files\\McAfee\\Engine\\"
"EngineVersionMajor"=dword:00001450
"EngineVersionMinor"=dword:00000870
"AVDatVersion"=dword:0000142a
"AVDatDate"="2007/11/13"
"EngineVersion32Major"=dword:00001450
"EngineVersion32Minor"=dword:00000870
"AVDatVersionMinor"=dword:00000000
"AVDatDateSys"=hex:d7,07,0b,00,00,00,0d,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection]
"szMidConfigDir"="C:\\Program Files\\McAfee\\VirusScan Enterprise\\MID\\"
"InstallDate"=hex:85,02,00,00,01,ce,b5,29,29,b5,ce,01
"dwUIMode"=dword:00000000
"szLanguageID"="C:\\Program Files\\McAfee\\VirusScan Enterprise\\Res0402"
"szProductVer"="8.5.0.781"
"bNetshieldEnabled"=dword:00000001
"szInstallDateTime"="2007-10-8T19:49:56"
"szSupportURL"="https://mysupport.mcafee.com"
"dwRefreshTime"=dword:00000003
"szInstallDir"="C:\\Program Files\\McAfee\\VirusScan Enterprise\\"
"szUpdateEXE"="C:\\Program Files\\McAfee\\VirusScan Enterprise\\MCUPDATE.EXE"
"bSkipSplash"=dword:00000000
"NotifiedTime"=hex:cf,07,07,00,a6,19,1b,00,15,00,24,00,1f,00,d8,00
"bLoadAtStartup"=dword:00000001
"QuarantineAge"=dword:0000001c
"szSubmitURL"="http://www.webimmune.net?id=0000"
"szVILURL"="http://vil.nai.com/"
"bDisableDefaultTask"=dword:00000000
"bDisplayEpoTasks"=dword:00000000
"QuarantineDirectory"="C:\\Quarantine"
"bNotifyOneMonth"=dword:00000000
"Product"="McAfee VirusScan Enterprise"
"bAllowRemote"=dword:00000001
"UIPMode"=dword:00000000
"UIP"=""
"ASLicenseInformation"=hex:42,b4,c4,72,ae,9c,cb,88,3c,33,ab,b3,a3,9c,cb,88,3c,\
  33,ab,b3,a3,33,ab,b3,a3,35,82,42,2e,97,50,02,42,15,5c,a2,41
"Patch_3"="bbcpl.dll=F1|OASCpl.dll=F1,F2,F3|vstskmgr.exe=F1,F2,F3,F4|shstat.exe=F1,F2,F3|shutil.dll=F1|mcupdate.exe=F1|vsodscpl.dll=F1,F2|OASCpl.dll=F1,F2,F3|vsplugin.dll=F1,F2|ftcfg.dll=F1|scan32.exe=F1|scncfg32.exe=F1|vsupdcpl.dll=F1|mcavscv.dll=F1|mcavdetect.dll=F1"
"LicenseInformation"=hex:42,b4,c4,72,ae,d7,ff,c4,17,33,ab,b3,a3,d7,ff,c4,17,33,\
  ab,b3,a3,bb,d3,95,2b,35,82,42,2e,97,50,02,42,15,5c,a2,41
"UIPPages"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
  00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
  00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection\Alerts]
"dwAlertManagerMethod"=dword:00000001
"bSendToAlertManagerOAS"=dword:00000001
"bSendToAlertManagerAP"=dword:00000001
"SendToAlertManager"=dword:00000001
"SendToEventLog"=dword:00000001
"dwLastModified"=dword:0000001e
"szAlertManagerComputer"=""
"SendToSNMP"=dword:00000000
"bSendToAlertManagerUpdate"=dword:00000001
"bSendToAlertManagerODS"=dword:00000001
"bSendToAlertManagerEmail"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection\DefaultTask]
"bOnceADayEnabled"=dword:00000000
"bApplyNow"=dword:00000001
"dwLastModified"=dword:0000000e
"NumExcludeItems"=dword:00000000
"wFlags"=dword:0000047f
"uStartupDelay"=dword:00000005
"bNotifyAlertMgr"=dword:00000001
"bAlwaysExit"=dword:00000000
"nStartYear"=dword:00000000
"bSchedEnabled"=dword:00000000
"nRepeatInterval"=dword:00000000
"ScanArchives"=dword:00000000
"bLogUserName"=dword:00000001
"uKilobytes"=dword:00000400
"bLogSummary"=dword:00000001
"uAction"=dword:00000005
"bSchConfigChanged"=dword:00000000
"Monthly_eMonthlyOption"=dword:00000000
"szProgExts"=""
"bAutoExit"=dword:00000000
"LogFileFormat"=dword:00000001
"uScanNumItems"=dword:00000005
"bGMTTime"=dword:00000000
"nStartHour"=dword:00000000
"bLogToFile"=dword:00000001
"ApplyNVP"=dword:00000001
"nStartMinute"=dword:00000000
"bScanAllFiles"=dword:00000001
"wTaskType"=dword:00000004
"nStartMonth"=dword:00000000
"bLogSettings"=dword:00000000
"bScanAllOle"=dword:00000000
"wTime"=dword:00001119
"bLimitSize"=dword:00000001
"dwProgramHeuristicsLevel"=dword:00000001
"bSkipBootScan"=dword:00000000
"uSecAction_Program"=dword:00000004
"bSecDisplayMessage"=dword:00000000
"nStopYear"=dword:00000000
"nStartDay"=dword:00000000
"Weekly_nRepeatWeeks"=dword:00000000
"bEnabled"=dword:00000000
"wTaskAttrib"=dword:00000000
"nRandomizationWndMins"=dword:00000000
"Daily_nRepeatDays"=dword:00000000
"bSkipMemScan"=dword:00000001
"szScanItem0"="SpecialScanForRootKits"
"szLogFileName"="%DEFLOGDIR%\\OnDemandScanLog.txt"
"szScanItem2"="LocalDrives"
"nPriority"=dword:00000064
"uSecAction"=dword:00000004
"szSecCustomMessage"=""
"Monthly_nDayOfWeek"=dword:00000000
"bRepeatable"=dword:00000000
"bStopDateValid"=dword:00000000
"Idle_nIdleMinutes"=dword:00000000
"dwScanPeriod"=dword:00000000
"bDoHSM"=dword:00000000
"bScanDefaultFiles"=dword:00000000
"szTaskName"="IDS_ODS_TASKNAME_FULL_SCAN"
"Monthly_maskMonthsOfYear"=dword:00000000
"bSkipCDROM"=dword:00000000
"Monthly_nDayNumOfMonth"=dword:00000000
"uAction_Program"=dword:00000005
"dwMacroHeuristicsLevel"=dword:00000001
"eScheduleType"=dword:00000000
"Monthly_nWeekNumOfMonth"=dword:00000000
"UIType"=dword:00000001
"wDate"=dword:00000907
"nUntilHour"=dword:00000000
"dwEndTime"=dword:00000000
"wLastExec"=dword:00000000
"dwPromptActionOptions"=dword:0000001f
"ScanMime"=dword:00000000
"bRandomizationEnabled"=dword:00000000
"bScanCompressed"=dword:00000001
"uMissedTaskDelay"=dword:00000005
"szScanItem1"="SpecialMemory"
"nUntilDuration"=dword:00000000
"Weekly_maskDaysOfWeek"=dword:00000000
"bAutoScan"=dword:00000001
"nUntilMinute"=dword:00000000
"eUntilOption"=dword:00000000
"bStopScanPeriod"=dword:00000000
"szSuggestMessage"=""
"bDispMessage"=dword:00000000
"bLogScanEncryptFail"=dword:00000001
"szLastScanFile0"=""
"eRepeatOption"=dword:00000000
"bScanSubDirs"=dword:00000001
"bRunIfMissed"=dword:00000000
"nStopMonth"=dword:00000000
"nStopDay"=dword:00000000
"szScanItem3"="SpecialRegistrySpyware"
"szScanItem4"="SpecialCookiesSpyware"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection\TaskLastData]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection\TaskLastData\{21221C11-A06D-4558-B833-98E8C7F6C4D2}]
"szLastResultId"="IDS_ODS_RESULTCOMPLETE"
"szStartTime"="128365872316406250"
"szEndTime"="128365880950000000"
"nRunTime"=dword:0000035f
"nProcessScanned"=dword:00000019
"nProcessInfected"=dword:00000000
"nProcessCleaned"=dword:00000000
"nBootScanned"=dword:00000005
"nBootInfected"=dword:00000000
"nBootCleaned"=dword:00000000
"nFileScanned"=dword:00009763
"nFileInfected"=dword:00000000
"nFileCleaned"=dword:00000000
"nFileDeleted"=dword:00000000
"nFileNotScanned"=dword:0000001a
"nKeyScanned"=dword:000029ca
"nKeyInfected"=dword:00000000
"nKeyCleaned"=dword:00000000
"nKeyDeleted"=dword:00000000
"nCookieScanned"=dword:00000340
"nCookieInfected"=dword:00000000
"nCookieCleaned"=dword:00000000
"nCookieDeleted"=dword:00000000
31538i
 楼主| 发表于 2007-11-14 17:50:30 | 显示全部楼层
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection\TaskLastData\{F8D48FD9-F56E-4808-BC50-7EDC60AF76AB}]
"szLastResultId"="IDS_ODS_RESULTCANCELLED"
"szStartTime"="128361235191093750"
"szEndTime"="128361235543437500"
"nRunTime"=dword:00000023
"nProcessScanned"=dword:00000034
"nProcessInfected"=dword:00000000
"nProcessCleaned"=dword:00000000
"nBootScanned"=dword:00000000
"nBootInfected"=dword:00000000
"nBootCleaned"=dword:00000000
"nFileScanned"=dword:00000000
"nFileInfected"=dword:00000000
"nFileCleaned"=dword:00000000
"nFileDeleted"=dword:00000000
"nFileNotScanned"=dword:00000001
"nKeyScanned"=dword:00000000
"nKeyInfected"=dword:00000000
"nKeyCleaned"=dword:00000000
"nKeyDeleted"=dword:00000000
"nCookieScanned"=dword:00000000
"nCookieInfected"=dword:00000000
"nCookieCleaned"=dword:00000000
"nCookieDeleted"=dword:00000000
"nLastScanItemNumber"=dword:00000000
"szLastScanItemPosition"="C:\\WINDOWS\\0.log"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection\Tasks]
"EOLPID"=dword:00002f02
"dwLastModified"=dword:000000b0
"dwExitStatus"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection\Tasks\{21221C11-A06D-4558-B833-98E8C7F6C4D2}]
"nStopYear"=dword:00000000
"dwExitStatus"=dword:00000469
"szScanItem4"="SpecialCookiesSpyware"
"szScanItem3"="SpecialRegistrySpyware"
"dwPromptActionOptions"=dword:0000001b
"dwLastModified"=dword:0000000f
"uMissedTaskDelay"=dword:00000005
"NumExcludeItems"=dword:00000000
"nStartMonth"=dword:00000000
"dwEndTime"=dword:00000000
"wDate"=dword:00000907
"bDispMessage"=dword:00000000
"bEnabled"=dword:00000000
"bScanSubDirs"=dword:00000001
"bRunIfMissed"=dword:00000000
"bSkipMemScan"=dword:00000001
"dwProgramHeuristicsLevel"=dword:00000001
"Monthly_maskMonthsOfYear"=dword:00000000
"bSecDisplayMessage"=dword:00000000
"wTime"=dword:00001119
"bLogSummary"=dword:00000001
"uStartupDelay"=dword:00000005
"wFlags"=dword:0000047f
"szSecCustomMessage"=""
"bLimitSize"=dword:00000001
"bSkipCDROM"=dword:00000000
"wTaskType"=dword:00000004
"nStartDay"=dword:00000000
"bRandomizationEnabled"=dword:00000000
"bOnceADayEnabled"=dword:00000000
"szProgExts"=""
"bAlwaysExit"=dword:00000000
"bStopScanPeriod"=dword:00000000
"nUntilDuration"=dword:00000000
"ScanMime"=dword:00000000
"szLogFileName"="%DEFLOGDIR%\\OnDemandScanLog.txt"
"Idle_nIdleMinutes"=dword:00000000
"Weekly_nRepeatWeeks"=dword:00000000
"nStopDay"=dword:00000000
"nStartYear"=dword:00000000
"uAction_Program"=dword:00000005
"bAutoScan"=dword:00000001
"bScanDefaultFiles"=dword:00000000
"bScanAllOle"=dword:00000000
"Monthly_eMonthlyOption"=dword:00000000
"ScanArchives"=dword:00000000
"bScanCompressed"=dword:00000001
"dwScanPeriod"=dword:00000000
"nUntilMinute"=dword:00000000
"bSchedEnabled"=dword:00000000
"szScanItem2"="LocalDrives"
"bSkipBootScan"=dword:00000000
"eUntilOption"=dword:00000000
"uAction"=dword:00000005
"bStopDateValid"=dword:00000000
"bSchConfigChanged"=dword:00000000
"bRepeatable"=dword:00000000
"ApplyNVP"=dword:00000001
"eRepeatOption"=dword:00000000
"LogFileFormat"=dword:00000001
"Daily_nRepeatDays"=dword:00000000
"nUntilHour"=dword:00000000
"szScanItem0"="SpecialScanForRootKits"
"szLastScanFile0"=""
"bNotifyAlertMgr"=dword:00000001
"Monthly_nDayOfWeek"=dword:00000000
"uKilobytes"=dword:00000400
"bApplyNow"=dword:00000001
"bAutoExit"=dword:00000000
"bScanAllFiles"=dword:00000001
"Weekly_maskDaysOfWeek"=dword:00000000
"Monthly_nWeekNumOfMonth"=dword:00000000
"nStartHour"=dword:00000000
"uScanNumItems"=dword:00000005
"eScheduleType"=dword:00000000
"bLogToFile"=dword:00000001
"UIType"=dword:00000001
"bLogUserName"=dword:00000001
"wLastExec"=dword:00000000
"Monthly_nDayNumOfMonth"=dword:00000000
"bLogSettings"=dword:00000000
"nRandomizationWndMins"=dword:00000000
"nStartMinute"=dword:00000000
"bDoHSM"=dword:00000000
"nStopMonth"=dword:00000000
"dwMacroHeuristicsLevel"=dword:00000001
"uSecAction"=dword:00000004
"bLogScanEncryptFail"=dword:00000001
"bGMTTime"=dword:00000000
"szSuggestMessage"=""
"szTaskName"="IDS_ODS_TASKNAME_FULL_SCAN"
"nPriority"=dword:00000064
"uSecAction_Program"=dword:00000004
"wTaskAttrib"=dword:00000000
"szScanItem1"="SpecialMemory"
"nRepeatInterval"=dword:00000000
"bAddedToCMA"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection\Tasks\{A14CD6FC-3BA8-4703-87BF-E3247CE382F5}]
"szLastRun"="128395050607950668"
"bAddedToCMA"=dword:00000001
"dwLastModified"=dword:000000ae
"dwExitStatus"=dword:00000012
"wflags"=dword:00000000
"wDate"=dword:00000014
"Monthly_nDayNumOfMonth"=dword:00000000
"szDomain"=""
"bLogToFile"=dword:00000001
"wTaskType"=dword:00000005
"szMirrorDest"=""
"Daily_nRepeatDays"=dword:00000001
"nStartYear"=dword:000007d2
"nRandomizationWndMins"=dword:0000003c
"wTime"=dword:00000200
"Weekly_nRepeatWeeks"=dword:00000001
"nStartMonth"=dword:00000009
"szRunAfterUpdateEXE"=""
"bSchedEnabled"=dword:00000001
"uMissedTaskDelay"=dword:00000005
"eScheduleType"=dword:00000000
"szLogFileName"="%DEFLOGDIR%\\UpdateLog.txt"
"szUser"=""
"Monthly_nDayOfWeek"=dword:00000000
"eUntilOption"=dword:00000000
"Idle_nIdleMinutes"=dword:00000000
"bOnceADayEnabled"=dword:00000000
"bDoUpdate"=dword:00000001
"nStopYear"=dword:00000000
"bRunIfMissed"=dword:00000001
"Monthly_maskMonthsOfYear"=dword:00000000
"eRepeatOption"=dword:00000000
"wTaskAttrib"=dword:00000000
"bRunIfUpdateSuccess"=dword:00000000
"dwMaxLogSizeMB"=dword:00000005
"nStopMonth"=dword:00000000
"bGMTTime"=dword:00000000
"bUseLogonUser"=dword:00000000
"bSchConfigChanged"=dword:00000000
"nUntilMinute"=dword:00000000
"Monthly_eMonthlyOption"=dword:00000000
"bRepeatable"=dword:00000000
"dwLogLevel"=dword:00000004
"bMirrorTask"=dword:00000000
"bNewUpdateLogFile"=dword:00000000
"bExecAfterUpdate"=dword:00000000
"nUntilDuration"=dword:00000001
"nStartHour"=dword:00000011
"nStopDay"=dword:00000000
"bApplyNow"=dword:00000001
"uStartupDelay"=dword:00000005
"szTaskName"="IDS_TASKNAME_AUTOUPDATE"
"nStartMinute"=dword:00000000
"Weekly_maskDaysOfWeek"=dword:00000000
"bStopScanPeriod"=dword:00000000
"dwScanPeriod"=dword:00000000
"nStartDay"=dword:00000003
"nRepeatInterval"=dword:00000001
"nUntilHour"=dword:00000000
"bRandomizationEnabled"=dword:00000001
"szUpdateShellScript"=""
"bRandomizationWndMinutes"=dword:0000003c
"Monthly_nWeekNumOfMonth"=dword:00000000
"bStopDateValid"=dword:00000000
"bEnabled"=dword:00000001
"wLastExec"=dword:00000000
"LogFileFormat"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection\Tasks\{F8D48FD9-F56E-4808-BC50-7EDC60AF76AB}]
"dwExitStatus"=dword:00000469
"szScanItem8"="ProfileDir"
"szScanItem7"="TempDir"
"szScanItem6"="ProgramFilesDir"
"szScanItem5"="WinDir"
"szScanItem4"="SpecialCookiesSpyware"
"szScanItem3"="SpecialRegistrySpyware"
"nStopDay"=dword:00000000
"nStopMonth"=dword:00000000
"bRunIfMissed"=dword:00000000
"bScanSubDirs"=dword:00000001
"eRepeatOption"=dword:00000000
"szLastScanFile0"=""
"bLogScanEncryptFail"=dword:00000001
"bDispMessage"=dword:00000000
"szSuggestMessage"=""
"bStopScanPeriod"=dword:00000000
"eUntilOption"=dword:00000000
"nUntilMinute"=dword:00000000
"bAutoScan"=dword:00000001
"Weekly_maskDaysOfWeek"=dword:00000000
"nUntilDuration"=dword:00000000
"szScanItem1"="SpecialScanForRootKits"
"uMissedTaskDelay"=dword:00000005
"bScanCompressed"=dword:00000001
"bRandomizationEnabled"=dword:00000000
"ScanMime"=dword:00000000
"dwPromptActionOptions"=dword:0000001f
"wLastExec"=dword:00000000
"dwEndTime"=dword:00000000
"nUntilHour"=dword:00000000
"wDate"=dword:00000907
"UIType"=dword:00000001
"Monthly_nWeekNumOfMonth"=dword:00000000
"eScheduleType"=dword:00000000
"dwMacroHeuristicsLevel"=dword:00000001
"uAction_Program"=dword:00000005
"Monthly_nDayNumOfMonth"=dword:00000000
"bSkipCDROM"=dword:00000000
"Monthly_maskMonthsOfYear"=dword:00000000
"szTaskName"="IDS_ODS_TASKNAME_TARGETED_SCAN"
"bScanDefaultFiles"=dword:00000000
"bDoHSM"=dword:00000000
"dwScanPeriod"=dword:00000000
"Idle_nIdleMinutes"=dword:00000000
"bStopDateValid"=dword:00000000
"bRepeatable"=dword:00000000
"Monthly_nDayOfWeek"=dword:00000000
"szSecCustomMessage"=""
"uSecAction"=dword:00000004
"nPriority"=dword:00000064
"szScanItem2"="SpecialCritical"
"szLogFileName"="%DEFLOGDIR%\\OnDemandScanLog.txt"
"szScanItem0"="SpecialMemory"
"bSkipMemScan"=dword:00000001
"Daily_nRepeatDays"=dword:00000000
"nRandomizationWndMins"=dword:00000000
"wTaskAttrib"=dword:00000000
"bEnabled"=dword:00000000
"Weekly_nRepeatWeeks"=dword:00000000
"nStartDay"=dword:00000000
"nStopYear"=dword:00000000
"bSecDisplayMessage"=dword:00000000
"uSecAction_Program"=dword:00000004
"bSkipBootScan"=dword:00000000
"dwProgramHeuristicsLevel"=dword:00000001
"bLimitSize"=dword:00000001
"wTime"=dword:00001119
"bScanAllOle"=dword:00000000
"bLogSettings"=dword:00000000
"nStartMonth"=dword:00000000
"wTaskType"=dword:00000004
"bScanAllFiles"=dword:00000001
"nStartMinute"=dword:00000000
"ApplyNVP"=dword:00000001
"bLogToFile"=dword:00000001
"nStartHour"=dword:00000000
"bGMTTime"=dword:00000000
"uScanNumItems"=dword:00000009
"LogFileFormat"=dword:00000001
"bAutoExit"=dword:00000000
"szProgExts"=""
"Monthly_eMonthlyOption"=dword:00000000
"bSchConfigChanged"=dword:00000000
"uAction"=dword:00000005
"bLogSummary"=dword:00000001
"uKilobytes"=dword:00000400
"bLogUserName"=dword:00000001
"ScanArchives"=dword:00000000
"nRepeatInterval"=dword:00000000
"bSchedEnabled"=dword:00000000
"nStartYear"=dword:00000000
"bAlwaysExit"=dword:00000000
"bNotifyAlertMgr"=dword:00000001
"uStartupDelay"=dword:00000005
"wFlags"=dword:0000047f
"NumExcludeItems"=dword:00000000
"dwLastModified"=dword:00000000
"bApplyNow"=dword:00000001
"bOnceADayEnabled"=dword:00000000
"bAddedToCMA"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\ePolicy Orchestrator]
"LogLevel"=dword:00000007

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\ePolicy Orchestrator\Application Plugins]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\ePolicy Orchestrator\Application Plugins\VIRUSCAN8600]
"Product Name"="McAfee VirusScan Enterprise Workstation"
"Software ID"="VIRUSCAN8600"
"Installs CMA"=dword:00000001
"Language"="0000"
"CLSID"="{9BE8D8A1-2DB5-4A29-A95F-50C8B27820DA}"
"Version"="8.5.0.781"
"Install Path"="C:\\Program Files\\McAfee\\VirusScan Enterprise\\"
"Plugin Path"="C:\\Program Files\\McAfee\\VirusScan Enterprise\\VsPlugin.dll"
"Uninstall Command"="msiexec /x {35C03C04-3F1F-42C2-A989-A757EE691F65} REMOVE=ALL REBOOT=R /q"
"Plugin Flag"=dword:00000000
31538i
 楼主| 发表于 2007-11-14 17:51:43 | 显示全部楼层
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\ePolicy Orchestrator\Application Plugins\VSEMAS850000]
"Plugin Path"="C:\\Program Files\\McAfee\\VirusScan Enterprise\\VsPlugin.dll"
"Software ID"="VSEMAS850000"
"Plugin Flag"=dword:00000006
"Uninstall Command"="\"C:\\Program Files\\McAfee\\VirusScan Enterprise\\scan32.exe\" /UninstallMAS"
"Product Name"="McAfee AntiSpyware Enterprise Module"
"Language"="0000"
"Version"="8.5.0.163"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McTray]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore]
"LockDownEnabled"=dword:00000001
"PreferredLanguage"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\Products]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\Products\AlertManager]
"Trap ID"="TVDTrap"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\Products\NetShield NT]
"Trap ID"="TVDTrap"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\Products\VirusScan]
"Trap ID"="TVDTrap"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\Products\VShield]
"Trap ID"="TVDTrap"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapDefs]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapDefs\AntiVirus]
"Trap OID"="4"
"Trap Definition"="SOFTWARENAME;SOFTWAREVERSION;SEVERITY;MESSAGE;SOURCEIP;COMPUTERNAME;GMTTIME;TIME;TRAPURL;MESSAGEID;USERNAME;FILENAME;VIRUSNAME;TASKNAME;STATUS;OS;ENGINEVERSION;DATVERSION;"
"NAI Node"="1204"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapDefs\AntiVirus\2]
"Trap Definition"="SOFTWARENAME;SOFTWAREVERSION;SEVERITY;MESSAGE;"
"Trap OID"="5"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapDefs\TVDTrap]
"Trap Definition"="SEVERITY;SHORTDESCRIPT;LONGDESCRIPT;SOFTWARENAME;SOFTWAREVERSION;TASKNAME;OS;COMPUTERNAME;USERNAME;FILENAME;VIRUSNAME;VIRUSTYPE;ENGINEVERSION;DATVERSION;ENGINESTATUS;NUMVIRS;NUMCLEANED;NUMDELETED;NUMQUARANTINED;SCANRETURNCODE;ACCESSPROCESSNAME;SOURCEIP;PROCESSORSERIAL;GMTTIME;LOCALTIME;LANGUAGECODE;TRAPID;EVENTNAME;URL;RESOLUTION;TARGETIP;TARGETCOMPUTERNAME;MAILFROMNAME;MAILTONAME;MAILCCNAME;MAILSUBJECTLINE;MAILIDENTIFIERINFO;NOTEID;NOTESSERVERNAME;NOTESDBNAME;DOMAIN;OBRULE;CLIENTCOMPUTER;TSCLIENTID;"
"Trap OID"="9999"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\ACCESSPROCESSNAME]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.43"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\CLIENTCOMPUTER]
"OID"="12.1.41"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\COMPUTERNAME]
"OID"="1.5"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\DATVERSION]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.3"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\DOMAIN]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.38"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\ENGINESTATUS]
"TYPE"="ASN_INTEGER"
"OID"="12.1.4"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\ENGINEVERSION]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.2"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\EVENTNAME]
"OID"="12.1.44"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\FILENAME]
"OID"="12.1.7"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\GMTTIME]
"OID"="12.1.45"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\LANGUAGECODE]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.40"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\LOCALTIME]
"OID"="12.1.46"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\LONGDESCRIPT]
"OID"="1.11"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\MAILCCNAME]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.32"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\MAILFROMNAME]
"OID"="12.1.30"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\MAILIDENTIFIERINFO]
"OID"="12.1.34"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\MAILSUBJECTLINE]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.33"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\MAILTONAME]
"OID"="12.1.31"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\MESSAGE]
"OID"="1.11"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\MESSAGEID]
"TYPE"="ASN_INTEGER"
"OID"="12.1.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\NOTEID]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.35"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\NOTESDBNAME]
"OID"="12.1.37"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\NOTESSERVERNAME]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.36"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\NUMCLEANED]
"OID"="12.1.16"
"TYPE"="ASN_INTEGER"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\NUMDELETED]
"OID"="12.1.17"
"TYPE"="ASN_INTEGER"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\NUMQUARANTINED]
"TYPE"="ASN_INTEGER"
"OID"="12.1.18"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\NUMVIRS]
"TYPE"="ASN_INTEGER"
"OID"="12.1.15"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\OBRULE]
"OID"="12.1.39"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\OS]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.9"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\PROCESSORSERIAL]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.10"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\RESOLUTION]
"OID"="1.12"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\SCANRETURNCODE]
"OID"="12.1.19"
"TYPE"="ASN_INTEGER"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\SEVERITY]
"OID"="1.2"
"TYPE"="ASN_INTEGER"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\SHORTDESCRIPT]
"OID"="1.3"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\SOFTWARENAME]
"OID"="1.1"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\SOFTWAREVERSION]
"TYPE"="ASN_OCTETSTRING"
"OID"="1.17"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\SOURCEIP]
"OID"="12.1.47"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\SOURCEMAC]
"OID"="1.13"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\SOURCESEG]
"TYPE"="ASN_OCTETSTRING"
"OID"="1.6"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\STATUS]
"OID"="12.1.4"
"TYPE"="ASN_INTEGER"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\TARGETCOMPUTERNAME]
"OID"="1.15"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\TARGETIP]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.48"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\TARGETMAC]
"OID"="1.16"
"TYPE"="ASN_OCTETSTRING"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\TASKNAME]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.11"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\TIME]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.46"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\TRAPID]
"TYPE"="ASN_INTEGER"
"OID"="12.1.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\TRAPURL]
"TYPE"="ASN_OCTETSTRING"
"OID"="1.10"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\TSCLIENTID]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.42"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\URL]
"TYPE"="ASN_OCTETSTRING"
"OID"="1.10"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\USERNAME]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.8"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\VIRUSNAME]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.5"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\SNMP\TrapParams\VIRUSTYPE]
"TYPE"="ASN_OCTETSTRING"
"OID"="12.1.6"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Alert Client\VSE]
"NoIP"=dword:00000000
"SuppressAlertsBelow"=dword:00000001
"LocalConfig"=dword:00000001
"Alert Manager Logical Name"=""
"SuppressAlerts"=""
"Centralized Alerting Path"=""
"RemoteConfig"=dword:00000001
"Alert Manager Server Path"=""
"bLocalEventLog"=dword:00000001
"AlertType"=dword:00000004
"No Active Dir"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Detect]
"szInstallDir"="C:\\Program Files\\McAfee\\VirusScan Enterprise\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\McPAL]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\McPAL\CurrentVersion]
"VSE8.5"="C:\\Program Files\\McAfee\\VirusScan Enterprise\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\MCVSSNMP]
"PathName"="C:\\Program Files\\McAfee\\VirusScan Enterprise\\mcvssnmp.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\NVP]
"DetectAdware"=dword:00000001
"DetectPasswordCrackers"=dword:00000001
"DetectKeyLoggers"=dword:00000001
"DetectSpyware"=dword:00000001
"DetectDialers"=dword:00000001
"DetectionExclusions"=hex(7):61,00,64,00,77,00,61,00,72,00,65,00,2d,00,6c,00,\
  6e,00,6b,00,2e,00,67,00,65,00,6e,00,00,00,41,00,64,00,77,00,61,00,72,00,65,\
  00,2d,00,46,00,6c,00,61,00,73,00,68,00,47,00,65,00,74,00,00,00,54,00,6f,00,\
  6f,00,6c,00,2d,00,54,00,50,00,61,00,74,00,63,00,68,00,00,00,47,00,65,00,6e,\
  00,65,00,72,00,69,00,63,00,20,00,70,00,75,00,70,00,2e,00,61,00,00,00,47,00,\
  65,00,6e,00,65,00,72,00,69,00,63,00,20,00,70,00,75,00,70,00,2e,00,63,00,00,\
  00,73,00,65,00,72,00,76,00,75,00,2d,00,64,00,61,00,65,00,6d,00,6f,00,6e,00,\
  00,00,50,00,57,00,43,00,72,00,61,00,63,00,6b,00,2d,00,43,00,61,00,69,00,6e,\
  00,00,00,41,00,64,00,77,00,61,00,72,00,65,00,2d,00,32,00,2e,00,35,00,62,00,\
  35,00,36,00,2e,00,6c,00,6e,00,6b,00,00,00,52,00,65,00,6d,00,41,00,64,00,6d,\
  00,2d,00,52,00,65,00,6d,00,6f,00,74,00,65,00,41,00,64,00,6d,00,69,00,6e,00,\
  00,00,00,00
"DetectRemoteAdminTools"=dword:00000001
"DetectJokes"=dword:00000001
"DetectPotentiallyUnwantedApps"=dword:00000001
"dwModifiedByASEM"=dword:00000001
"UserDefinedDetection_0"="autorun.inf:"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner]

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\BehaviourBlocking]
"VSIDBlockOnNonVirus"=dword:00000000
"ProductID"="VIRUSCAN8600"
"VSIDBlockTimeout"=dword:0000000a
"VSIDBlock"=dword:00000001
"szLogFileName"="%DEFLOGDIR%\\AccessProtectionLog.txt"
"PVSPTEnabled"=dword:00000001
"APEnabled"=dword:00000001
"dwMaxLogSizeMB_Ent"=dword:00000001
"LogFileFormat"=dword:00000001
"dwMaxLogSizeMB"=dword:00000001
"bLogToFile_Ent"=dword:00000001
"bLimitSize"=dword:00000001
"szLogFileName_Ent"="%DEFLOGDIR%\\BufferOverflowProtectionLog.txt"
"VSIDSendMessage"=dword:00000000
"bLogToFile"=dword:00000001
"bLimitSize_Ent"=dword:00000001
"VSIDMessage"=""
"PortBlockReportMinutes"=dword:00000001
"BOPMode"=dword:00000001
"BOPShowMessages"=dword:00000001
"LogFileFormat_Ent"=dword:00000001
"BOPEnabled"=dword:00000001
"AltProductID"="ANTISPYW8500"
"ProtectionType"="Maximum"
"AccessProtectionUserRules"=hex:41,63,63,65,73,73,50,72,6f,74,65,63,74,69,6f,\
  6e,20,7b,0d,0a,55,73,65,72,50,72,6f,63,65,73,73,20,41,56,4f,31,30,20,7b,49,\
  6e,63,6c,75,64,65,20,2a,3b,45,78,63,6c,75,64,65,20,61,67,65,6e,74,2e,65,78,\
  65,20,61,6d,67,72,73,72,76,63,2e,65,78,65,20,61,70,61,63,68,65,2e,65,78,65,\
  20,65,62,73,2e,65,78,65,20,65,75,64,6f,72,61,2e,65,78,65,20,65,78,70,6c,6f,\
  72,65,72,2e,65,78,65,20,66,69,72,65,66,6f,78,2e,65,78,65,20,66,69,72,65,73,\
  76,63,2e,65,78,65,20,66,6f,78,6d,61,69,6c,2e,65,78,65,20,69,65,78,70,6c,6f,\
  72,65,2e,65,78,65,20,69,6e,65,74,69,6e,66,6f,2e,65,78,65,20,6d,61,69,6c,73,\
  63,61,6e,2e,65,78,65,20,4d,41,50,49,53,50,33,32,2e,65,78,65,20,6d,6f,64,75,\
  6c,65,77,72,61,70,70,65,72,2a,20,6d,6f,7a,69,6c,6c,61,2e,65,78,65,20,6d,73,\
  65,78,63,69,6d,63,2e,65,78,65,20,6d,73,69,6d,6e,2e,65,78,65,20,6d,73,6b,64,\
  65,74,63,74,2e,65,78,65,20,6d,73,6b,73,72,76,72,2e,65,78,65,20,6d,73,6e,36,\
  2e,65,78,65,20,6d,73,6e,6d,73,67,72,2e,65,78,65,20,6e,65,6f,32,30,2e,65,78,\
  65,20,6e,65,74,73,63,70,2e,65,78,65,20,6e,6c,6e,6f,74,65,73,2e,65,78,65,20,\
  6e,72,6f,75,74,65,72,2e,65,78,65,20,6e,73,6d,74,70,2e,65,78,65,20,6e,74,61,\
  73,6b,6c,64,72,2e,65,78,65,20,6f,70,65,72,61,2e,65,78,65,20,6f,75,74,6c,6f,\
  6f,6b,2e,65,78,65,20,4f,77,73,74,69,6d,65,72,2e,65,78,65,20,70,69,6e,65,2e,\
  65,78,65,20,70,6f,63,6f,2e,65,78,65,20,52,45,53,52,43,4d,4f,4e,2e,45,58,45,\
  20,72,70,63,73,65,72,76,2e,65,78,65,20,53,50,53,4e,6f,74,69,66,69,63,2a,20,\
  74,68,65,62,61,74,2e,65,78,65,20,74,68,75,6e,64,65,2a,2e,65,78,65,20,74,6f,\
  6d,63,61,74,2e,65,78,65,20,74,6f,6d,63,61,74,35,2e,65,78,65,20,74,6f,6d,63,\
  61,74,35,77,2e,65,78,65,20,56,4d,49,4d,42,2e,45,58,45,20,77,65,62,70,72,6f,\
  78,79,2e,65,78,65,20,57,69,6e,4d,61,69,6c,2e,65,78,65,20,77,69,6e,70,6d,2d,\
  33,32,2e,65,78,65,7d,0d,0a,7d,0d,0a

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield]
"dwFilesCleaned"=dword:00000000
"dwLastModified"=dword:0000204c
"dwFilesInfected"=dword:00000000
"dwFilesScanned"=dword:00001d64
"dwFilesMoved"=dword:00000000
"dwFilesDeleted"=dword:00000000
"szLastScanned"="D:\\Program Files\\Tencent\\QQ\\QQlog.txl"

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration]
"bStartDisabled"=dword:00000000
"EOLPID"=dword:00002f01
"PPContextIDs"=hex:01,50,00,00,02,50,00,00,03,50,00,00
"UseAVVDats"=dword:00000001
"OnlyUseDefaultConfig"=dword:00000001
"Alert_AutoShowList"=dword:00000001
"bLoadAtStartup"=dword:00000001
"bScanFloppyOnShutdown"=dword:00000001
"wTaskType"=dword:00000001
"Alert_UsersCanQuarantine"=dword:00000001
"Alert_MaxAlertsCount"=dword:000003e8
"Alert_MaxAlertsKb"=dword:000003e8
"bLogSummary"=dword:00000001
"szLogFileName"="%DEFLOGDIR%\\OnAccessScanLog.txt"
"wFlags"=dword:00004000
"bDontScanBootSectors"=dword:00000000
"uCloseDelta"=dword:000001f4
"RepairBootSectors"=dword:00000001
"bLogUserName"=dword:00000001
"dwMaxLogSizeMB"=dword:00000001
"bDontScanMBRSectors"=dword:00000000
"WorkAroundAllocateFloppies"=dword:00000001
"LogFileFormat"=dword:00000001
"RepairBackupDirectory"="C:\\Quarantine"
"bLimitSize"=dword:00000001
"Alert_UsersCanDelete"=dword:00000000
"Alert_LocalMessage"="VirusScan Alert!"
"szTaskName"="On-Access Scan"
"Alert_ExcludeCookies"=dword:00000001
"wTime"=dword:00000200
"WorkAroundAllocateCDRoms"=dword:00000001
"bDisableScanning"=dword:00000000
"Alert_UsersCanClean"=dword:00000001
"ScanArchiveTimeout"=dword:0000000f
"bLogDateTime"=dword:00000001
"bApplyNow"=dword:00000001
"RepairBackupViruses"=dword:00000001
"ScannerThreadTimeoutEx"=dword:0000afc8
"DotVirToDenyWrite"=dword:00000001
"dwExitStatus"=dword:00000000
"bDenyFloppyMountIfInfected"=dword:00000000
"bLogToFile"=dword:00000001
"Alert_UsersCanRemove"=dword:00000001
"SmoothWritesExtensions"="ini log"
"bDisconnectUser"=dword:00000000
"bVScan"=dword:00000001
"bLogClean"=dword:00000001
"bFileCacheEnabled"=dword:00000001
"dwLastModified"=dword:0000034c
"DotVirToDenyFailedClean"=dword:00000001
"RepairBackupPUPs"=dword:00000001
"uKilobytes"=dword:00000064
"bReloadDATs"=dword:00000000
"bLogSettings"=dword:00000000
"DotVirOnQuarantine"=dword:00000001
"ReportEncryptedFiles"=dword:00000001
"ScannerThreadTimeout"=dword:0000afc8
"wDate"=dword:00000000
"ScanCookies"=dword:00000000
31538i
 楼主| 发表于 2007-11-14 17:52:12 | 显示全部楼层
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration\Default]
"uAction"=dword:00000005
"NumExcludeItems"=dword:00000000
"bNetworkScanEnabled"=dword:00000000
"NetworkExtensionMode"=dword:00000001
"ScanArchives"=dword:00000000
"ReportEncryptedFiles"=dword:00000000
"uSecAction"=dword:00000004
"uAction_Program"=dword:00000005
"szIncludeExts"=""
"dwProgramHeuristicsLevel"=dword:00000001
"dwMacroHeuristicsLevel"=dword:00000001
"szProgExts"=""
"ScanBackupReads"=dword:00000001
"ScanMime"=dword:00000000
"ApplyNVP"=dword:00000001
"uSecAction_Program"=dword:00000004
"bScanOutgoing"=dword:00000001
"bScanIncoming"=dword:00000001
"LocalExtensionMode"=dword:00000001
"bScanCompressed"=dword:00000001
"ProcessList"=hex(7):00,00,00,00
"DetectPrograms"=dword:00000000
"bAppendExclusions"=dword:00000000
"szExcludeExts"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration\High]
"Exclusions"=""
"NetworkExtensionMode"=dword:00000001
"ScanArchives"=dword:00000000
"bScanIncoming"=dword:00000001
"ApplyNVP"=dword:00000001
"uSecAction_Program"=dword:00000004
"dwMacroHeuristicsLevel"=dword:00000001
"uAction_Program"=dword:00000005
"bScanOutgoing"=dword:00000001
"ProcessList"=hex(7):34,00,6e,00,74,00,2e,00,65,00,78,00,65,00,00,00,61,00,67,\
  00,65,00,6e,00,74,00,2e,00,65,00,78,00,65,00,00,00,61,00,69,00,6d,00,2e,00,\
  65,00,78,00,65,00,00,00,62,00,65,00,61,00,72,00,73,00,68,00,61,00,72,00,65,\
  00,2e,00,65,00,78,00,65,00,00,00,43,00,6d,00,64,00,2e,00,45,00,78,00,65,00,\
  00,00,63,00,73,00,63,00,72,00,69,00,70,00,74,00,2e,00,65,00,78,00,65,00,00,\
  00,65,00,75,00,64,00,6f,00,72,00,61,00,2e,00,65,00,78,00,65,00,00,00,45,00,\
  78,00,63,00,65,00,6c,00,2e,00,65,00,78,00,65,00,00,00,45,00,78,00,70,00,6c,\
  00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,65,00,00,00,46,00,69,00,6c,00,\
  65,00,4e,00,61,00,76,00,69,00,67,00,61,00,74,00,6f,00,72,00,2e,00,65,00,78,\
  00,65,00,00,00,66,00,74,00,70,00,2e,00,65,00,78,00,65,00,00,00,67,00,64,00,\
  6f,00,6e,00,6b,00,65,00,79,00,2e,00,65,00,78,00,65,00,00,00,67,00,6e,00,75,\
  00,63,00,6c,00,65,00,75,00,73,00,2e,00,65,00,78,00,65,00,00,00,49,00,43,00,\
  51,00,2e,00,65,00,78,00,65,00,00,00,49,00,65,00,78,00,70,00,6c,00,6f,00,72,\
  00,65,00,2e,00,65,00,78,00,65,00,00,00,69,00,6e,00,65,00,74,00,69,00,6e,00,\
  66,00,6f,00,2e,00,65,00,78,00,65,00,00,00,6d,00,69,00,72,00,63,00,2e,00,65,\
  00,78,00,65,00,00,00,6d,00,6f,00,62,00,73,00,79,00,6e,00,63,00,2e,00,65,00,\
  78,00,65,00,00,00,6d,00,6f,00,73,00,61,00,69,00,63,00,2e,00,65,00,78,00,65,\
  00,00,00,6d,00,6f,00,7a,00,69,00,6c,00,6c,00,61,00,2e,00,65,00,78,00,65,00,\
  00,00,4d,00,73,00,41,00,63,00,63,00,65,00,73,00,73,00,2e,00,65,00,78,00,65,\
  00,00,00,4d,00,73,00,49,00,6d,00,6e,00,2e,00,65,00,78,00,65,00,00,00,6d,00,\
  73,00,6d,00,73,00,67,00,73,00,2e,00,65,00,78,00,65,00,00,00,6d,00,73,00,6e,\
  00,36,00,2e,00,65,00,78,00,65,00,00,00,6e,00,65,00,6f,00,32,00,30,00,2e,00,\
  65,00,78,00,65,00,00,00,6e,00,65,00,74,00,73,00,63,00,61,00,70,00,65,00,2e,\
  00,45,00,78,00,65,00,00,00,6e,00,65,00,74,00,73,00,63,00,70,00,36,00,2e,00,\
  65,00,78,00,65,00,00,00,4f,00,75,00,74,00,6c,00,6f,00,6f,00,6b,00,2e,00,65,\
  00,78,00,65,00,00,00,6f,00,70,00,65,00,72,00,61,00,2e,00,65,00,78,00,65,00,\
  00,00,50,00,6f,00,77,00,65,00,72,00,50,00,6e,00,74,00,2e,00,65,00,78,00,65,\
  00,00,00,74,00,66,00,74,00,70,00,2e,00,65,00,78,00,65,00,00,00,56,00,69,00,\
  73,00,69,00,6f,00,33,00,32,00,2e,00,65,00,78,00,65,00,00,00,77,00,61,00,6f,\
  00,6c,00,2e,00,65,00,78,00,65,00,00,00,57,00,69,00,6e,00,50,00,4d,00,2d,00,\
  33,00,32,00,2e,00,65,00,78,00,65,00,00,00,57,00,69,00,6e,00,57,00,6f,00,72,\
  00,64,00,2e,00,45,00,78,00,65,00,00,00,77,00,73,00,5f,00,66,00,74,00,70,00,\
  2e,00,65,00,78,00,65,00,00,00,77,00,73,00,63,00,72,00,69,00,70,00,74,00,2e,\
  00,65,00,78,00,65,00,00,00,77,00,75,00,61,00,75,00,63,00,6c,00,74,00,2e,00,\
  65,00,78,00,65,00,00,00,78,00,6f,00,6c,00,6f,00,78,00,2e,00,65,00,78,00,65,\
  00,00,00,79,00,70,00,61,00,67,00,65,00,72,00,2e,00,65,00,78,00,65,00,00,00,\
  79,00,75,00,70,00,64,00,61,00,74,00,65,00,2e,00,65,00,78,00,65,00,00,00,00,\
  00
"uAction"=dword:00000005
"ScanBackupReads"=dword:00000001
"ScanMime"=dword:00000000
"bNetworkScanEnabled"=dword:00000000
"bScanCompressed"=dword:00000001
"uSecAction"=dword:00000004
"ReportEncryptedFiles"=dword:00000001
"NumExcludeItems"=dword:00000000
"szIncludeExts"=""
"dwProgramHeuristicsLevel"=dword:00000001
"szProgExts"=""
"LocalExtensionMode"=dword:00000001
"DetectPrograms"=dword:00000000
"bAppendExclusions"=dword:00000000
"szExcludeExts"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration\Low]
"ScanBackupReads"=dword:00000001
"ScanArchives"=dword:00000000
"ScanMime"=dword:00000000
"bScanCompressed"=dword:00000001
"uAction"=dword:00000005
"uAction_Program"=dword:00000005
"uSecAction_Program"=dword:00000004
"ProcessList"=hex(7):41,00,65,00,78,00,61,00,75,00,64,00,69,00,74,00,70,00,6c,\
  00,73,00,2e,00,65,00,78,00,65,00,00,00,41,00,65,00,78,00,6e,00,73,00,63,00,\
  6c,00,69,00,65,00,6e,00,74,00,2e,00,65,00,78,00,65,00,00,00,41,00,65,00,78,\
  00,6e,00,73,00,63,00,6c,00,69,00,65,00,6e,00,74,00,74,00,72,00,61,00,6e,00,\
  73,00,70,00,6f,00,72,00,74,00,2e,00,65,00,78,00,65,00,00,00,41,00,65,00,78,\
  00,6e,00,73,00,77,00,64,00,75,00,73,00,72,00,2e,00,65,00,78,00,65,00,00,00,\
  00,00
"bNetworkScanEnabled"=dword:00000000
"bScanOutgoing"=dword:00000001
"dwMacroHeuristicsLevel"=dword:00000000
"bScanIncoming"=dword:00000001
"NetworkExtensionMode"=dword:00000001
"LocalExtensionMode"=dword:00000001
"szIncludeExts"=""
"dwProgramHeuristicsLevel"=dword:00000000
"ReportEncryptedFiles"=dword:00000000
"NumExcludeItems"=dword:00000000
"ApplyNVP"=dword:00000001
"uSecAction"=dword:00000004
"szProgExts"=""
"DetectPrograms"=dword:00000000
"bAppendExclusions"=dword:00000000
"szExcludeExts"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Script Scanner]
"PPContextIDs"=hex:01,50,00,00,02,50,00,00,03,50,00,00
"EOLPID"=dword:00002f04
"ScriptScanEnabled"=dword:00000001
"HookMode"=dword:00000001
"ExcludedProcesses"=hex(7):00,00,00,00
31538i
 楼主| 发表于 2007-11-14 17:53:07 | 显示全部楼层
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration\Default]
"uAction"=dword:00000005
"NumExcludeItems"=dword:00000000
"bNetworkScanEnabled"=dword:00000000
"NetworkExtensionMode"=dword:00000001
"ScanArchives"=dword:00000000
"ReportEncryptedFiles"=dword:00000000
"uSecAction"=dword:00000004
"uAction_Program"=dword:00000005
"szIncludeExts"=""
"dwProgramHeuristicsLevel"=dword:00000001
"dwMacroHeuristicsLevel"=dword:00000001
"szProgExts"=""
"ScanBackupReads"=dword:00000001
"ScanMime"=dword:00000000
"ApplyNVP"=dword:00000001
"uSecAction_Program"=dword:00000004
"bScanOutgoing"=dword:00000001
"bScanIncoming"=dword:00000001
"LocalExtensionMode"=dword:00000001
"bScanCompressed"=dword:00000001
"ProcessList"=hex(7):00,00,00,00
"DetectPrograms"=dword:00000000
"bAppendExclusions"=dword:00000000
"szExcludeExts"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration\High]
"Exclusions"=""
"NetworkExtensionMode"=dword:00000001
"ScanArchives"=dword:00000000
"bScanIncoming"=dword:00000001
"ApplyNVP"=dword:00000001
"uSecAction_Program"=dword:00000004
"dwMacroHeuristicsLevel"=dword:00000001
"uAction_Program"=dword:00000005
"bScanOutgoing"=dword:00000001
"ProcessList"=hex(7):34,00,6e,00,74,00,2e,00,65,00,78,00,65,00,00,00,61,00,67,\
  00,65,00,6e,00,74,00,2e,00,65,00,78,00,65,00,00,00,61,00,69,00,6d,00,2e,00,\
  65,00,78,00,65,00,00,00,62,00,65,00,61,00,72,00,73,00,68,00,61,00,72,00,65,\
  00,2e,00,65,00,78,00,65,00,00,00,43,00,6d,00,64,00,2e,00,45,00,78,00,65,00,\
  00,00,63,00,73,00,63,00,72,00,69,00,70,00,74,00,2e,00,65,00,78,00,65,00,00,\
  00,65,00,75,00,64,00,6f,00,72,00,61,00,2e,00,65,00,78,00,65,00,00,00,45,00,\
  78,00,63,00,65,00,6c,00,2e,00,65,00,78,00,65,00,00,00,45,00,78,00,70,00,6c,\
  00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,65,00,00,00,46,00,69,00,6c,00,\
  65,00,4e,00,61,00,76,00,69,00,67,00,61,00,74,00,6f,00,72,00,2e,00,65,00,78,\
  00,65,00,00,00,66,00,74,00,70,00,2e,00,65,00,78,00,65,00,00,00,67,00,64,00,\
  6f,00,6e,00,6b,00,65,00,79,00,2e,00,65,00,78,00,65,00,00,00,67,00,6e,00,75,\
  00,63,00,6c,00,65,00,75,00,73,00,2e,00,65,00,78,00,65,00,00,00,49,00,43,00,\
  51,00,2e,00,65,00,78,00,65,00,00,00,49,00,65,00,78,00,70,00,6c,00,6f,00,72,\
  00,65,00,2e,00,65,00,78,00,65,00,00,00,69,00,6e,00,65,00,74,00,69,00,6e,00,\
  66,00,6f,00,2e,00,65,00,78,00,65,00,00,00,6d,00,69,00,72,00,63,00,2e,00,65,\
  00,78,00,65,00,00,00,6d,00,6f,00,62,00,73,00,79,00,6e,00,63,00,2e,00,65,00,\
  78,00,65,00,00,00,6d,00,6f,00,73,00,61,00,69,00,63,00,2e,00,65,00,78,00,65,\
  00,00,00,6d,00,6f,00,7a,00,69,00,6c,00,6c,00,61,00,2e,00,65,00,78,00,65,00,\
  00,00,4d,00,73,00,41,00,63,00,63,00,65,00,73,00,73,00,2e,00,65,00,78,00,65,\
  00,00,00,4d,00,73,00,49,00,6d,00,6e,00,2e,00,65,00,78,00,65,00,00,00,6d,00,\
  73,00,6d,00,73,00,67,00,73,00,2e,00,65,00,78,00,65,00,00,00,6d,00,73,00,6e,\
  00,36,00,2e,00,65,00,78,00,65,00,00,00,6e,00,65,00,6f,00,32,00,30,00,2e,00,\
  65,00,78,00,65,00,00,00,6e,00,65,00,74,00,73,00,63,00,61,00,70,00,65,00,2e,\
  00,45,00,78,00,65,00,00,00,6e,00,65,00,74,00,73,00,63,00,70,00,36,00,2e,00,\
  65,00,78,00,65,00,00,00,4f,00,75,00,74,00,6c,00,6f,00,6f,00,6b,00,2e,00,65,\
  00,78,00,65,00,00,00,6f,00,70,00,65,00,72,00,61,00,2e,00,65,00,78,00,65,00,\
  00,00,50,00,6f,00,77,00,65,00,72,00,50,00,6e,00,74,00,2e,00,65,00,78,00,65,\
  00,00,00,74,00,66,00,74,00,70,00,2e,00,65,00,78,00,65,00,00,00,56,00,69,00,\
  73,00,69,00,6f,00,33,00,32,00,2e,00,65,00,78,00,65,00,00,00,77,00,61,00,6f,\
  00,6c,00,2e,00,65,00,78,00,65,00,00,00,57,00,69,00,6e,00,50,00,4d,00,2d,00,\
  33,00,32,00,2e,00,65,00,78,00,65,00,00,00,57,00,69,00,6e,00,57,00,6f,00,72,\
  00,64,00,2e,00,45,00,78,00,65,00,00,00,77,00,73,00,5f,00,66,00,74,00,70,00,\
  2e,00,65,00,78,00,65,00,00,00,77,00,73,00,63,00,72,00,69,00,70,00,74,00,2e,\
  00,65,00,78,00,65,00,00,00,77,00,75,00,61,00,75,00,63,00,6c,00,74,00,2e,00,\
  65,00,78,00,65,00,00,00,78,00,6f,00,6c,00,6f,00,78,00,2e,00,65,00,78,00,65,\
  00,00,00,79,00,70,00,61,00,67,00,65,00,72,00,2e,00,65,00,78,00,65,00,00,00,\
  79,00,75,00,70,00,64,00,61,00,74,00,65,00,2e,00,65,00,78,00,65,00,00,00,00,\
  00
"uAction"=dword:00000005
"ScanBackupReads"=dword:00000001
"ScanMime"=dword:00000000
"bNetworkScanEnabled"=dword:00000000
"bScanCompressed"=dword:00000001
"uSecAction"=dword:00000004
"ReportEncryptedFiles"=dword:00000001
"NumExcludeItems"=dword:00000000
"szIncludeExts"=""
"dwProgramHeuristicsLevel"=dword:00000001
"szProgExts"=""
"LocalExtensionMode"=dword:00000001
"DetectPrograms"=dword:00000000
"bAppendExclusions"=dword:00000000
"szExcludeExts"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration\Low]
"ScanBackupReads"=dword:00000001
"ScanArchives"=dword:00000000
"ScanMime"=dword:00000000
"bScanCompressed"=dword:00000001
"uAction"=dword:00000005
"uAction_Program"=dword:00000005
"uSecAction_Program"=dword:00000004
"ProcessList"=hex(7):41,00,65,00,78,00,61,00,75,00,64,00,69,00,74,00,70,00,6c,\
  00,73,00,2e,00,65,00,78,00,65,00,00,00,41,00,65,00,78,00,6e,00,73,00,63,00,\
  6c,00,69,00,65,00,6e,00,74,00,2e,00,65,00,78,00,65,00,00,00,41,00,65,00,78,\
  00,6e,00,73,00,63,00,6c,00,69,00,65,00,6e,00,74,00,74,00,72,00,61,00,6e,00,\
  73,00,70,00,6f,00,72,00,74,00,2e,00,65,00,78,00,65,00,00,00,41,00,65,00,78,\
  00,6e,00,73,00,77,00,64,00,75,00,73,00,72,00,2e,00,65,00,78,00,65,00,00,00,\
  00,00
"bNetworkScanEnabled"=dword:00000000
"bScanOutgoing"=dword:00000001
"dwMacroHeuristicsLevel"=dword:00000000
"bScanIncoming"=dword:00000001
"NetworkExtensionMode"=dword:00000001
"LocalExtensionMode"=dword:00000001
"szIncludeExts"=""
"dwProgramHeuristicsLevel"=dword:00000000
"ReportEncryptedFiles"=dword:00000000
"NumExcludeItems"=dword:00000000
"ApplyNVP"=dword:00000001
"uSecAction"=dword:00000004
"szProgExts"=""
"DetectPrograms"=dword:00000000
"bAppendExclusions"=dword:00000000
"szExcludeExts"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Script Scanner]
"PPContextIDs"=hex:01,50,00,00,02,50,00,00,03,50,00,00
"EOLPID"=dword:00002f04
"ScriptScanEnabled"=dword:00000001
"HookMode"=dword:00000001
"ExcludedProcesses"=hex(7):00,00,00,00
31538i
 楼主| 发表于 2007-11-14 17:54:37 | 显示全部楼层
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration\Default]
"uAction"=dword:00000005
"NumExcludeItems"=dword:00000000
"bNetworkScanEnabled"=dword:00000000
"NetworkExtensionMode"=dword:00000001
"ScanArchives"=dword:00000000
"ReportEncryptedFiles"=dword:00000000
"uSecAction"=dword:00000004
"uAction_Program"=dword:00000005
"szIncludeExts"=""
"dwProgramHeuristicsLevel"=dword:00000001
"dwMacroHeuristicsLevel"=dword:00000001
"szProgExts"=""
"ScanBackupReads"=dword:00000001
"ScanMime"=dword:00000000
"ApplyNVP"=dword:00000001
"uSecAction_Program"=dword:00000004
"bScanOutgoing"=dword:00000001
"bScanIncoming"=dword:00000001
"LocalExtensionMode"=dword:00000001
"bScanCompressed"=dword:00000001
"ProcessList"=hex(7):00,00,00,00
"DetectPrograms"=dword:00000000
"bAppendExclusions"=dword:00000000
"szExcludeExts"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration\High]
"Exclusions"=""
"NetworkExtensionMode"=dword:00000001
"ScanArchives"=dword:00000000
"bScanIncoming"=dword:00000001
"ApplyNVP"=dword:00000001
"uSecAction_Program"=dword:00000004
"dwMacroHeuristicsLevel"=dword:00000001
"uAction_Program"=dword:00000005
"bScanOutgoing"=dword:00000001
"ProcessList"=hex(7):34,00,6e,00,74,00,2e,00,65,00,78,00,65,00,00,00,61,00,67,\
  00,65,00,6e,00,74,00,2e,00,65,00,78,00,65,00,00,00,61,00,69,00,6d,00,2e,00,\
  65,00,78,00,65,00,00,00,62,00,65,00,61,00,72,00,73,00,68,00,61,00,72,00,65,\
  00,2e,00,65,00,78,00,65,00,00,00,43,00,6d,00,64,00,2e,00,45,00,78,00,65,00,\
  00,00,63,00,73,00,63,00,72,00,69,00,70,00,74,00,2e,00,65,00,78,00,65,00,00,\
  00,65,00,75,00,64,00,6f,00,72,00,61,00,2e,00,65,00,78,00,65,00,00,00,45,00,\
  78,00,63,00,65,00,6c,00,2e,00,65,00,78,00,65,00,00,00,45,00,78,00,70,00,6c,\
  00,6f,00,72,00,65,00,72,00,2e,00,65,00,78,00,65,00,00,00,46,00,69,00,6c,00,\
  65,00,4e,00,61,00,76,00,69,00,67,00,61,00,74,00,6f,00,72,00,2e,00,65,00,78,\
  00,65,00,00,00,66,00,74,00,70,00,2e,00,65,00,78,00,65,00,00,00,67,00,64,00,\
  6f,00,6e,00,6b,00,65,00,79,00,2e,00,65,00,78,00,65,00,00,00,67,00,6e,00,75,\
  00,63,00,6c,00,65,00,75,00,73,00,2e,00,65,00,78,00,65,00,00,00,49,00,43,00,\
  51,00,2e,00,65,00,78,00,65,00,00,00,49,00,65,00,78,00,70,00,6c,00,6f,00,72,\
  00,65,00,2e,00,65,00,78,00,65,00,00,00,69,00,6e,00,65,00,74,00,69,00,6e,00,\
  66,00,6f,00,2e,00,65,00,78,00,65,00,00,00,6d,00,69,00,72,00,63,00,2e,00,65,\
  00,78,00,65,00,00,00,6d,00,6f,00,62,00,73,00,79,00,6e,00,63,00,2e,00,65,00,\
  78,00,65,00,00,00,6d,00,6f,00,73,00,61,00,69,00,63,00,2e,00,65,00,78,00,65,\
  00,00,00,6d,00,6f,00,7a,00,69,00,6c,00,6c,00,61,00,2e,00,65,00,78,00,65,00,\
  00,00,4d,00,73,00,41,00,63,00,63,00,65,00,73,00,73,00,2e,00,65,00,78,00,65,\
  00,00,00,4d,00,73,00,49,00,6d,00,6e,00,2e,00,65,00,78,00,65,00,00,00,6d,00,\
  73,00,6d,00,73,00,67,00,73,00,2e,00,65,00,78,00,65,00,00,00,6d,00,73,00,6e,\
  00,36,00,2e,00,65,00,78,00,65,00,00,00,6e,00,65,00,6f,00,32,00,30,00,2e,00,\
  65,00,78,00,65,00,00,00,6e,00,65,00,74,00,73,00,63,00,61,00,70,00,65,00,2e,\
  00,45,00,78,00,65,00,00,00,6e,00,65,00,74,00,73,00,63,00,70,00,36,00,2e,00,\
  65,00,78,00,65,00,00,00,4f,00,75,00,74,00,6c,00,6f,00,6f,00,6b,00,2e,00,65,\
  00,78,00,65,00,00,00,6f,00,70,00,65,00,72,00,61,00,2e,00,65,00,78,00,65,00,\
  00,00,50,00,6f,00,77,00,65,00,72,00,50,00,6e,00,74,00,2e,00,65,00,78,00,65,\
  00,00,00,74,00,66,00,74,00,70,00,2e,00,65,00,78,00,65,00,00,00,56,00,69,00,\
  73,00,69,00,6f,00,33,00,32,00,2e,00,65,00,78,00,65,00,00,00,77,00,61,00,6f,\
  00,6c,00,2e,00,65,00,78,00,65,00,00,00,57,00,69,00,6e,00,50,00,4d,00,2d,00,\
  33,00,32,00,2e,00,65,00,78,00,65,00,00,00,57,00,69,00,6e,00,57,00,6f,00,72,\
  00,64,00,2e,00,45,00,78,00,65,00,00,00,77,00,73,00,5f,00,66,00,74,00,70,00,\
  2e,00,65,00,78,00,65,00,00,00,77,00,73,00,63,00,72,00,69,00,70,00,74,00,2e,\
  00,65,00,78,00,65,00,00,00,77,00,75,00,61,00,75,00,63,00,6c,00,74,00,2e,00,\
  65,00,78,00,65,00,00,00,78,00,6f,00,6c,00,6f,00,78,00,2e,00,65,00,78,00,65,\
  00,00,00,79,00,70,00,61,00,67,00,65,00,72,00,2e,00,65,00,78,00,65,00,00,00,\
  79,00,75,00,70,00,64,00,61,00,74,00,65,00,2e,00,65,00,78,00,65,00,00,00,00,\
  00
"uAction"=dword:00000005
"ScanBackupReads"=dword:00000001
"ScanMime"=dword:00000000
"bNetworkScanEnabled"=dword:00000000
"bScanCompressed"=dword:00000001
"uSecAction"=dword:00000004
"ReportEncryptedFiles"=dword:00000001
"NumExcludeItems"=dword:00000000
"szIncludeExts"=""
"dwProgramHeuristicsLevel"=dword:00000001
"szProgExts"=""
"LocalExtensionMode"=dword:00000001
"DetectPrograms"=dword:00000000
"bAppendExclusions"=dword:00000000
"szExcludeExts"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\On Access Scanner\McShield\Configuration\Low]
"ScanBackupReads"=dword:00000001
"ScanArchives"=dword:00000000
"ScanMime"=dword:00000000
"bScanCompressed"=dword:00000001
"uAction"=dword:00000005
"uAction_Program"=dword:00000005
"uSecAction_Program"=dword:00000004
"ProcessList"=hex(7):41,00,65,00,78,00,61,00,75,00,64,00,69,00,74,00,70,00,6c,\
  00,73,00,2e,00,65,00,78,00,65,00,00,00,41,00,65,00,78,00,6e,00,73,00,63,00,\
  6c,00,69,00,65,00,6e,00,74,00,2e,00,65,00,78,00,65,00,00,00,41,00,65,00,78,\
  00,6e,00,73,00,63,00,6c,00,69,00,65,00,6e,00,74,00,74,00,72,00,61,00,6e,00,\
  73,00,70,00,6f,00,72,00,74,00,2e,00,65,00,78,00,65,00,00,00,41,00,65,00,78,\
  00,6e,00,73,00,77,00,64,00,75,00,73,00,72,00,2e,00,65,00,78,00,65,00,00,00,\
  00,00
"bNetworkScanEnabled"=dword:00000000
"bScanOutgoing"=dword:00000001
"dwMacroHeuristicsLevel"=dword:00000000
"bScanIncoming"=dword:00000001
"NetworkExtensionMode"=dword:00000001
"LocalExtensionMode"=dword:00000001
"szIncludeExts"=""
"dwProgramHeuristicsLevel"=dword:00000000
"ReportEncryptedFiles"=dword:00000000
"NumExcludeItems"=dword:00000000
"ApplyNVP"=dword:00000001
"uSecAction"=dword:00000004
"szProgExts"=""
"DetectPrograms"=dword:00000000
"bAppendExclusions"=dword:00000000
"szExcludeExts"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Script Scanner]
"PPContextIDs"=hex:01,50,00,00,02,50,00,00,03,50,00,00
"EOLPID"=dword:00002f04
"ScriptScanEnabled"=dword:00000001
"HookMode"=dword:00000001
"ExcludedProcesses"=hex(7):00,00,00,00
31538i
 楼主| 发表于 2007-11-14 18:00:20 | 显示全部楼层
C:\Program Files\McAfee\Common Framework\Agent.ini没有   有的是Agent.dll



好像原因就出在多了的那一个SiteAdvisor上

谢谢

[ 本帖最后由 31538i 于 2007-11-14 18:17 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
散人安
发表于 2007-11-14 18:17:05 | 显示全部楼层
原帖由 31538i 于 2007-11-14 18:00 发表
C:\Program Files\McAfee\Common Framework\Agent.ini没有   有的是Agent.dll


  找这个:
  C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Agent.ini

  你现在重启系统,仍然是 M 图标吗?还是说,偶尔变成 M 图标?
31538i
 楼主| 发表于 2007-11-14 18:22:16 | 显示全部楼层
那ePolicy Orchestrator代理也是近中午刚多出来的...变异
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 10:42 , Processed in 0.095681 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表