Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\AEGIS]
"BMSrvNoRecover"=dword:0000000c
"TMBMServicePath"=hex(2):43,00,3a,00,5c,00,50,00,72,00,6f,00,67,00,72,00,61,00,\
6d,00,20,00,46,00,69,00,6c,00,65,00,73,00,5c,00,54,00,72,00,65,00,6e,00,64,\
00,20,00,4d,00,69,00,63,00,72,00,6f,00,5c,00,42,00,4d,00,5c,00,54,00,4d,00,\
42,00,4d,00,53,00,52,00,56,00,2e,00,65,00,78,00,65,00,00,00
"TMBMSRVDenyStop"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\PFW]
"WscRegistOnInstall"=dword:00000000
"AppFilter"=dword:00000001
"NoAegis"=dword:00000001
"InfNameForCfw"=hex(7):6f,00,65,00,6d,00,31,00,30,00,2e,00,69,00,6e,00,66,00,\
2c,00,6f,00,65,00,6d,00,31,00,31,00,2e,00,69,00,6e,00,66,00,00,00
"ServiceName"="Trend Micro Client/Server Security Agent 個人防火牆"
"ServiceDesc"="Personal Firewall"
"InstallPath"="C:\\Program Files\\Trend Micro\\Client Server Security Agent\\"
"StartType"=dword:00000002
"LookupLicense"=hex:89,13,34,3f,e3,34,98,0c,8a,b4,03,a8,26,8a,b4,d2
"LookupVID"=hex:bf,b0,ae,3a,53,b3,9f,dd,b6,2b,09,08,59,bb,5c,be
"WscComRegistered"=dword:00000000
"IpcPort"=dword:00009c40
"Status"=dword:00000003
"AskTimeout"=dword:00000000
"AskAction"=dword:00000001
"Protection"=dword:00000000
"IdsCtrl"=dword:fffeefff
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy]
"InfNameForTdi"=hex(7):6f,00,65,00,6d,00,39,00,2e,00,69,00,6e,00,66,00,00,00
"TempPath"="C:\\Program Files\\Trend Micro\\Client Server Security Agent\\Temp\\TmpxTmp\\"
"InstallPath"="C:\\Program Files\\Trend Micro\\Client Server Security Agent\\"
"LogPath"="C:\\Program Files\\Trend Micro\\Client Server Security Agent\\Temp\\TmpxTmp\\Log\\"
"ProxyPort"=dword:00001b57
"DefRedirectFlag"=dword:00040000
"ErrTitle"="Trend Micro Proxy Service Installation"
"ErrText"="The TmProxy module experienced a critical error. Please reinstall the program: internal error:"
"csm_60_sp2_installed"=dword:00000001
"Protection"=dword:00000000
"EnableFeedback"=dword:ffffffff
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\PluginManager]
"enable"=dword:00000001
"filename"="tmplgadp.dll"
"enableIE"=dword:00000001
"enableFirefox"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\aim]
"enable"=dword:00000001
"filename"="TmphAim.dll"
"scan"="im"
"type"=dword:00000006
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\aim\redirect]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\aim\redirect\aim-out]
"direction"=dword:00000000
"port"=dword:00000000
"process"="aim"
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http]
"enable"=dword:00000001
"scan"="http"
"filename"="TmphHttp.dll"
"type"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http\config]
"MaxHeaderCount"=dword:00000064
"MaxRequestBodyScanSize"=dword:00000400
"MaxResponseBodyScanSize"=dword:00002800
"MaxLineSize"=dword:00001ffe
"TargetRequestMethods"="GET,POST"
"MessageBodyMemorySizeLimit"=dword:00000200
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http\redirect]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http\redirect\AOL]
"process"="waol"
"port"=dword:00000050
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http\redirect\AOL11523]
"port"=dword:00002d03
"process"="waol"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http\redirect\Explorer]
"port"=dword:00000050
"process"="explorer"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http\redirect\Firefox]
"process"="firefox"
"port"=dword:00000050
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http\redirect\IE]
"process"="iexplore"
"port"=dword:00000050
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http\redirect\Netscape7]
"process"="Netscp"
"port"=dword:00000050
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http\redirect\Others80]
"process"=""
"port"=dword:00000050
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http\redirect\Others8080]
"process"=""
"port"=dword:00001f90
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\http\redirect\Others81]
"process"=""
"port"=dword:00000051
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\icq]
"scan"="im"
"enable"=dword:00000001
"filename"="TmphIcq.dll"
"type"=dword:00000005
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\icq\redirect]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\icq\redirect\icq-in]
"process"="icq"
"port"=dword:00000000
"direction"=dword:00000001
"flag"=dword:00000002
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\icq\redirect\icq-out]
"process"="icq"
"port"=dword:00000000
"direction"=dword:00000000
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\msn]
"enable"=dword:00000001
"scan"="im"
"filename"="TmphMsn.dll"
"type"=dword:00000004
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\msn\redirect]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\msn\redirect\msmsgs]
"process"="msmsgs"
"port"=dword:00000747
"flag"=dword:00000001
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\msn\redirect\msmsgs80]
"process"="msmsgs"
"port"=dword:00000050
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\msn\redirect\msnmsgr]
"process"="msnmsgr"
"port"=dword:00000747
"flag"=dword:00000001
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\msn\redirect\msnmsgr80]
"process"="msnmsgr"
"port"=dword:00000050
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\pop3]
"enable"=dword:00000001
"scan"="Pop3"
"type"=dword:00000001
"filename"="TmphPop3.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\pop3\config]
"WaitTime"=dword:00000000
"IntervalLength"=dword:00007530
"LimitSize"=dword:00000c00
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\pop3\Redirect]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\pop3\Redirect\Pop3Mailer]
"process"=""
"port"=dword:0000006e
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\smtp]
"scan"="smtp"
"enable"=dword:00000000
"filename"="TmphSMTP.dll"
"type"=dword:00000002
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\smtp\config]
"WaitTime"=dword:00000000
"LimitSize"=dword:00000c00
"IntervalLength"=dword:00007530
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\smtp\redirect]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\smtp\redirect\SmtpMailer]
"process"=""
"port"=dword:00000019
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\smtp\redirect\Submission]
"flag"=dword:00040004
"process"=""
"port"=dword:0000024b
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\ymsg]
"scan"="im"
"enable"=dword:00000001
"filename"="TmphYmsg.dll"
"type"=dword:00000007
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\ymsg\redirect]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\ymsg\redirect\ymsg70-in]
"process"="YPager"
"port"=dword:00000000
"direction"=dword:00000001
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\ymsg\redirect\ymsg70-out]
"process"="YPager"
"port"=dword:00000000
"direction"=dword:00000000
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\ymsg\redirect\ymsg75-in]
"process"="YahooMessenger"
"port"=dword:00000000
"direction"=dword:00000001
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\ymsg\redirect\ymsg75-out]
"process"="YahooMessenger"
"port"=dword:00000000
"direction"=dword:00000000
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\ymsg\redirect\ymsgshort-in]
"process"="YAHOOM~1"
"port"=dword:00000000
"direction"=dword:00000001
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\ProtocolHandler\ymsg\redirect\ymsgshort-out]
"process"="YAHOOM~1"
"port"=dword:00000000
"direction"=dword:00000000
"CancelAfMask"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\AntiSpam]
"filename"="TmpeASpm.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\AntiSpam\config]
"RulePath"="C:\\Program Files\\Trend Micro\\Client Server Security Agent\\AspmData\\"
"ScanType"=dword:00000003
"PrefixSpam"="[spam]"
"PrefixPhishing"="[spam]"
"PrefixMalicious"="[spam]"
"PrefixSuspicious"="[spam]"
"PrefixBlack"="[spam]"
"EnableImageDetection"=dword:00000001
"EnableInTheCloud"=dword:00000001
"InTheCloudTimeout"=dword:000007d0
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\HostFilter]
"Filename"="TmpeHosF.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\HostFilter\config]
"Whitelist"="HosFList.dat"
"EnablePrivateIPCheck"=dword:00000001
"NonBlock"=dword:00000001
"ExclusionExtensions"="jpg,jpeg,gif,bmp,png,mpg,mpeg,mp3,wav,wave,qt,qtm,avi,asf,asx,mov,mp4,mid,midi,swf,ram,cab,jar,class,ocx,js,css,crl"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\HttpFileScan]
"filename"="TmpeVS.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\HttpFileScan\config]
"TargetTypes"="7,4030"
"MaxScanSize"=dword:00001400
"ActionSizeThreshold"=dword:00000100
"HttpActionMode"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\HttpManager]
"filename"="TmsmHttp.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\HttpManager\config]
"ExclusionExtensions"="doc,ppt,xls,pdf,jpg,jpeg,gif,bmp,png,mpg,mpeg,mp3,wav,wave,qt,qtm,avi,asf,asx,mov,mp4,mid,midi,swf,ram,zip,lzh,gz,tar,rar,arc,exe,cab,jar,class,ocx,js,css,dll"
"UrlFilterAlertFile"="UrlFAlt.htm,UrlFErr.htm<99>,UrlFPhis.htm<4B>,UrlFDnsS.htm<97>"
"UrlFilterCredAlertFile"="UrlFCredScore.htm,UrlFCredLevel.htm<0:1:2:3>"
"HostFilterAlertFile"="HosFAlt.htm"
"HostFilterErrorFile"="HosFErr.htm"
"UrlHistoryFile"="UrlHist.log"
"PrivacyDataAlertFile"="PDPAlt.htm"
"MaxUrlHistoryCount"=dword:00000064
"MaxWebMailScanSize"=dword:00000c00
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\ImManager]
"filename"="TmsmIm.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\MailManager]
"filename"="TmsmMail.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\MailManager\config]
"BytesPerEntHdr"=dword:00008000
"WarningFile"="TmWarn.txt"
"ParamPerHdrField"=dword:00000020
"HdrPerEnt"=dword:00000040
"DisclaimerOriginalName"="original.txt"
"DisclaimerFile"="TmNewML.txt"
"EntPerMsg"=dword:00000040
"DisclaimerSubject"="Trend Micro OfficeScan detected and took action on a malicious email"
"ExtlactLvlPerMsg"=dword:00000020
"EnableDisclaimer"=dword:00000000
"DisclaimerCharset"="us-ascii"
"DisclaimerAddress"="Trend Micro"
"AddressCacheDirection"=dword:00000000
"AddressCacheFile"="MailAddr.dat"
"SpywareWarning"="TmSpyML.txt"
"SpywareSubject"="[Spyware] "
"SpywareExtension"="tm"
"MaxAddressCacheCount"=dword:00000064
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\PrivacyProtection]
"filename"="TmpePDP.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\PrivacyProtection\config]
"filename"="TmpePDP.dll"
"AccessRetryCount"=dword:0000000a
"AccessWaitTime"=dword:00000032
"CharSetEntry"=dword:0000000b
"ExtCharSetEntry"=dword:00000000
"DefaultCharSet"=dword:00000008
"DataBaseName"="PDPCfg.dat"
"BackUpDBName"="PDPCfg.bak"
"ItemEntryMax"=dword:000001f4
"ItemEntryCount"=dword:00000005
"ItemIndex00"=dword:00000000
"ItemIndex01"=dword:00000001
"ItemIndex02"=dword:00000002
"ItemIndex03"=dword:00000003
"ItemIndex04"=dword:00000004
"ItemName00"="Name"
"ItemName01"="Credit card number"
"ItemName02"="Telephone number"
"ItemName03"="Login name"
"ItemName04"="Password"
"Description00"=""
"Description01"=""
"Description02"=""
"Description03"=""
"Description04"=""
"ScanTarget00"=dword:00000111
"ScanTarget01"=dword:00000111
"ScanTarget02"=dword:00000111
"ScanTarget03"=dword:00000111
"ScanTarget04"=dword:00000111
"PrivacyData00"=hex:ee,b4,1b,81,81,d0,75,16,0e,7e,4e,f4,df,ab,7b,d0,f2,75,5a,\
a8,51,78,56,31,b4,cd,98,48,a9,f6,bc,ea,1a,9e,f9,46,f4,3a,5c,dc,4a,38,57,79,\
56,3e,55,d6
"PrivacyData01"=hex:ee,b4,1b,81,81,d0,75,16,0e,7e,4e,f4,df,ab,7b,d0,f2,75,5a,\
a8,51,78,56,31,b4,cd,98,48,a9,f6,bc,ea,1a,9e,f9,46,f4,3a,5c,dc,4a,38,57,79,\
56,3e,55,d6
"PrivacyData02"=hex:ee,b4,1b,81,81,d0,75,16,0e,7e,4e,f4,df,ab,7b,d0,f2,75,5a,\
a8,51,78,56,31,b4,cd,98,48,a9,f6,bc,ea,1a,9e,f9,46,f4,3a,5c,dc,4a,38,57,79,\
56,3e,55,d6
"PrivacyData03"=hex:ee,b4,1b,81,81,d0,75,16,0e,7e,4e,f4,df,ab,7b,d0,f2,75,5a,\
a8,51,78,56,31,b4,cd,98,48,a9,f6,bc,ea,1a,9e,f9,46,f4,3a,5c,dc,4a,38,57,79,\
56,3e,55,d6
"PrivacyData04"=hex:ee,b4,1b,81,81,d0,75,16,0e,7e,4e,f4,df,ab,7b,d0,f2,75,5a,\
a8,51,78,56,31,b4,cd,98,48,a9,f6,bc,ea,1a,9e,f9,46,f4,3a,5c,dc,4a,38,57,79,\
56,3e,55,d6
"ExclusionItemMax"=dword:00000064
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\URLFilter]
"filename"="TmpeURLF.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\URLFilter\config]
"Mode"=dword:00000000
"Blacklist"="URLBlist.dat"
"Whitelist"="URLAlist.dat"
"CategoryFile"="URLCateg.dat"
"CategoryGroupFile"="URLGroup.dat"
"CacheSize"=dword:00100000
"CacheLifetime"=dword:0000003c
"EnableServerLookup"=dword:00000001
"EnableProxy"=dword:00000000
"LookupServer"=hex:7a,e5,60,ea,b3,39,44,2c,39,79,ac,3e,49,38,13,97,f8,f6,bb,bd,\
aa,75,7c,94,59,c8,fd,4b,d9,49,3c,3a,99,fe,79,22,3d,67,b4,30,3d,ac,04,90,bc,\
28,98,3d
"LookupVID"=hex:bf,b0,ae,3a,53,b3,9f,dd,b6,2b,09,08,59,bb,5c,be
"LookupLicense"=hex:89,13,34,3f,e3,34,98,0c,8a,b4,03,a8,26,8a,b4,d2
"LookupTimeout"=dword:0000000a
"ExclusionExtensions"="mpg,mpeg,mp3,wav,wave,avi,asf,asx,mov,mp4,mid,midi,ram,cab,class,ocx,crl"
"BlockCategoryGroups"="27,49,4A,4B,4C,4D,4E,4F,50,51,52,53,54,55,56,58,"
"ErrMode"=dword:00000000
"CategoryNonBlock"=dword:00000000
"PharmingNonBlock"=dword:00000000
"NotifyAll"=dword:00000001
"RatingType"=dword:00000002
"EnableCategoryChk"=dword:00000001
"EnablePharm"=dword:00000000
"EnableTMUFELog"=dword:00000001
"TMUFELogLevel"=dword:00000004
"EnableCredibilityChk"=dword:00000001
"CredibilityNonBlock"=dword:00000000
"UserDefinedCredLevel"=dword:00000002
"UseCredibilityScore"=dword:00000001
"CredScoreThresHold"=dword:00000032
"EnablePhishChk"=dword:00000001
"PhishNonBlock"=dword:00000000
"BlockPhishCategoryGrps"="4B"
"EnableTpxDns"=dword:00000000
"EnableTmufeDns"=dword:00000000
"ProxyServer"=""
"ProxyPort"=dword:00000050
"ProxyUser"=hex:
"ProxyPassword"=hex:
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\Virus]
"Filename"="TmpeVS.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Common\Virus\config]
"Language"=dword:00000000
"KeepNumber"=dword:00000000
"PurgeBadPattern"=dword:00000001
"PatternPath"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\http]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\http\HostFilter]
"LogExtension"="HLG"
"enable"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\http\HttpFileScan]
"enable"=dword:00000001
"logExtension"="VLG,SPG"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\http\HttpFileScan\config]
"ZipClean"=dword:00000001
"ZipScan"=dword:00000001
"ExtractFileSizeLimit"=dword:00100000
"ZipLayer"=dword:00000001
"Action2nd"=dword:00000004
"Action"=dword:00000003
"IntelliTrap"=dword:00000001
"SpywareScan"=dword:00000001
"SpywareAction"=dword:00000004
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\http\HttpManager]
"enable"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\http\HttpsFilter]
"UrlFilterAlertFile"="UrlFAlt.htm,UrlFErr.htm<99>,UrlFPhis.htm<17>,UrlFDnsS.htm<97>"
"UrlFilterCredAlertFile"="UrlFCredScore.htm,UrlFCredLevel.htm<0:1:2:3>"
"HostFilterAlertFile"="HosFAlt.htm"
"HostFilterErrorFile"="HosFErr.htm"
"PrivacyDataAlertFile"="PDPAlt.htm"
"Enable"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\http\PrivacyProtection]
"logExtension"="PPG"
"enable"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\http\PrivacyProtection\config]
"SearchTableIndex"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\http\URLFilter]
"LogExtension"="ULG"
"enable"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\http\Virus]
"enable"=dword:00000000
"LogExtension"="VLG,SPG"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\http\Virus\config]
"ZipClean"=dword:00000001
"ZipScan"=dword:00000001
"ExtractFileSizeLimit"=dword:ffffffff
"ZipLayer"=dword:00000001
"Action2nd"=dword:00000004
"Action"=dword:00000003
"IntelliTrap"=dword:00000001
"SpywareScan"=dword:00000001
"SpywareAction"=dword:00000004
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\im]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\im\ImManager]
"enable"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\im\PrivacyProtection]
"enable"=dword:00000001
"logExtension"="PPG"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\im\PrivacyProtection\config]
"SearchTableIndex"=dword:00000002
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Pop3]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Pop3\AntiSpam]
"LogExtension"="ASG"
"enable"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Pop3\AntiSpam\config]
"DisabledRule"=""
"Whitelist"="ASPAList.dat"
"Blacklist"="ASPBList.dat"
"High"="4"
"Level"=dword:00000001
"Medium"="5"
"Low"="7"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Pop3\MailManager]
"enable"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Pop3\Virus]
"logExtension"="VLG"
"Enable"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\Pop3\Virus\config]
"ZipLayer"=dword:00000003
"ExtractFileSizeLimit"=dword:ffffffff
"ZipClean"=dword:00000001
"Action2nd"=dword:00000004
"Action"=dword:00000003
"ZipScan"=dword:00000001
"IntelliTrap"=dword:00000001
"SpywareScan"=dword:00000001
"SpywareAction"=dword:000000c9
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\smtp]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\smtp\MailManager]
"enable"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\smtp\PrivacyProtection]
"Enable"=dword:00000000
"logExtension"="PPG"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\smtp\PrivacyProtection\config]
"SearchTableIndex"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\smtp\Virus]
"enable"=dword:00000000
"LogExtension"="VLG,SPG"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\Scan\smtp\Virus\config]
"ZipLayer"=dword:00000001
"Action2nd"=dword:00000065
"ZipScan"=dword:00000001
"ZipClean"=dword:00000001
"ExtractFileSizeLimit"=dword:ffffffff
"Action"=dword:00000003
"IntelliTrap"=dword:00000001
"SpywareScan"=dword:00000001
"SpywareAction"=dword:00000065
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList]
"UseWhiteList"=dword:00000001
"Option"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\000OSCE]
"ProcessImageName"="TmListen.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\001OSCE]
"ProcessImageName"="PccNTMon.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\002OSCE]
"ProcessImageName"="NTRmv.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\003OSCE]
"ProcessImageName"="AutoPcc.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\004OSCE]
"ProcessImageName"="AutoPccP.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\005OSCE]
"ProcessImageName"="OfcService.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\006OSCE]
"ProcessImageName"="OfcAoSMgr.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\007OSCE]
"ProcessImageName"="OfcDBBackup.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\008OSCE]
"ProcessImageName"="OfcHotFix.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\009OSCE]
"ProcessImageName"="OfcUpdate.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\010OSCE]
"ProcessImageName"="patch.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\011OSCE]
"ProcessImageName"="VerConn.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\012OSCE]
"ProcessImageName"="IpXfer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\013OSCE]
"ProcessImageName"="SPNSXfr.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\014OSCE]
"ProcessImageName"="TMVS.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\015OSCE]
"ProcessImageName"="ClientMover.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\016OSCE]
"ProcessImageName"="NTRtScan.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\017OSCE]
"ProcessImageName"="utilChkWSS.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\018OSCE]
"ProcessImageName"="HostedAgent.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\CWAT]
"ProcessImageName"="opdcs.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\ISASERVER]
"ProcessImageName"="wspsrv.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\nsffprx]
"ProcessImageName"="nsffprx.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\OfficeCommunicator]
"ProcessImageName"="communicator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\YahooMessenger]
"ProcessImageName"="YahooMessenger.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\NSC\TmProxy\WhiteList\YahooM~1]
"ProcessImageName"="YahooM~1.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\OfcWatchDog]
"Default Retry Interval"=dword:0000003c
"Default Retry Count"=dword:00000005
"WatchDogFailureCountReset"=dword:00000e10
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion]
"DomainID"="23464A83-3EE1-41A7-83F8-B85C73EB0559"
"Application Path"="C:\\Program Files\\Trend Micro\\Client Server Security Agent\\"
"GUID"="e72ecd07-fdcd-4f99-ad79-112888ce8158"
"EnableClientEventLog"=dword:00000001
"SvcMode"="!CRYPT!107A84A86377E1E05017E5A4B03"
"Mode"=dword:00000001
"ProxyPort"=dword:00000050
"UseProxy"=dword:00000000
"ServerPort"=dword:00001f7b
"Server"="192.168.1.100"
"ProxyServer"=""
"ProxyLogin"=""
"ProxyPwd"="!CRYPT!1030F30B4758870920C4F627A3B"
"VirtualPath"="/officescan/cgi"
"DatabasePath"="\\\\BSH\\ofcscan\\FileDB"
"Domain"="Workgroup"
"LocalServerPort"=dword:00005278
"IPTemplateDeployEnable"=dword:00000000
"IPTemplateDeploy"=""
"SvcUpd"="!CRYPT!20A96EC333A67AD094B6CAD1FAD0F9FAA184C6C7833"
"SvcLog"="!CRYPT!104AF4CF95C033BE6857E5A4B03"
"SvcVisible"="!CRYPT!10546131838B5F1C12F7C544909"
"SvcCfg"="!CRYPT!104804FD2ED0284F03E7F5A4B03"
"ChangeSecurity"=dword:00000003
"AutoProxyDetection"=dword:00000000
"UseProxyAutoConfigScript"=dword:00000000
"ProxyAutoConfigScript"=""
"InstDate"="20130825"
"InstTime"="124129"
"OppFirstTimeReportCheck"=dword:00000000
"IP"="182.234.209.234"
"MAC"="3085A9467E03"
"ClientString"="201308251242170625"
"Reload"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\AEGIS]
"Enable"=dword:00000001
"SendLogPeriod"=dword:0000003c
"AskTimeOut"=dword:0000001e
"TimeOutAction"=dword:00000000
"Debug"=dword:00000000
"ProtectIntuit"=dword:00000000
"AllowSetGenericProtection"=dword:00000000
"ServerPriority"=dword:00000000
"PopupAlert"=dword:00000000
"AllowSetExceptionList"=dword:00000001
"SP_EnableRegistryKeyProtection"=dword:00000000
"SP_EnableProcessProtection"=dword:00000000
"TerminateWhenBlockForever"=dword:00000001
"EnableGenericCleanForAEGIS"=dword:00000001
"Installed"=dword:00000001
"BMFeaturesOnOff"=dword:00000003
"PopupsLowRiskMsg"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\AEGIS\Add PIDs]
"tmlisten"=dword:00000dd8
"TmProxy.exe"=dword:00000e38
"pccntmon"=dword:00000e60
"TmPfw.exe"=dword:00000f78
"pccnt"=dword:00000c94
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\AEGIS\Delete PIDs]
"Upgrade"=dword:00000eb8
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\AntiSpam Toolbar]
"Enabled"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\HostedAgent]
"ServiceID"=dword:00000001
"NoProtectionMode"=dword:00000000
"FirstBootUp"=dword:00000000
"FreeLicenseMode"=dword:00000000
"RecoveryMode"=dword:00000000
"FeatureConfigure"=dword:0000001f
"FirstBootUpTimeStamp"="!CRYPT!52885EDB5E26AACCCEAE028814DA33D9D5BED1B3D09B562165F02C81408CE8DB49572B27C6F43671B98062C3E77"
"AgentModeID"=dword:00000001
"Server"="wfbs-svc-nabu-aal.trendmicro.com"
"KeepFWDriverUntilRestart"=dword:00000000
"OnlineHelpPrefix"="http://docs.trendmicro.com/all/smb/wfbs-services/client/wfbs-svc/"
"Group"=dword:00000001
"Owner"=""
"Version"="5.2.1074"
"PrivateProxyServer"=""
"PrivateProxyEnable"=dword:00000000
"PrivateProxyPort"=dword:00000000
"PrivateProxyConfigScript"=""
"ClientUtilityPath"="wfbs-svc-nabu-aal.trendmicro.com/filer/aal/toolbar"
"CompanyKey"="4c32bb1b-d507-446f-a191-6ba42401a9d2"
"Path"="C:\\Program Files\\Trend Micro\\Client Server Security Agent\\HostedAgent\\"
"AgentGuid"="f12bc066-3d9c-4d8b-b183-fd58e9838e56"
"InstRegReturnCode"=dword:00000000
"SvcPID"=dword:00000c54
"StartCounter"=dword:00000001
"Online"=dword:00000001
"GpbByteSent"=dword:00000000
"GpbByteRecv"=dword:00000000
"HotfixByteRecv"=dword:00000000
"LicensePopupChkInterval"=dword:000493e0
"DataCenterID"=dword:00000006
"Domain"=dword:0010d38d
"Abandon"=dword:00000000
"LicenseLastStage"=dword:00000000
"LicenseStage"=dword:00000000
"OverSeatWarningPopupMode"=dword:00000000
"LicenseMergeFlag"=dword:00000000
"LicensePopupFrequency"=dword:00000000
"LicenseLastRemainingDay"=dword:00000000
"LicenseRemainingDay"=dword:00000000
"AgentPID"=dword:0000010c
"DumpGpb"=dword:00000000
"AC"="WF-FJ3B-83TKM-SW9RA-ZVQ9V-DAXBF-3PJMQ"
"BUCode"="19"
"LicenseLightStatus"=dword:00000000
"LicensePopupURL"=""
"Block"=dword:00000000
"ClientRegistered"=dword:00000001
"LastScheduleScanTime"=dword:00000000
"LastManualScanTime"=dword:00000000
"OverSeat"=dword:00000000
"LicenseType"="!CRYPT!5284D98483046515BB4E028814DA33D9D5BED1B3D09B562165F02C81408CE8DB49572B27C6F43671B98062E3974"
"LogCollectInterval"=dword:00004e20
"ClientEnvReportInterval"=dword:0000ea60
"NumberOfIAPerGroup"=dword:0000000a
"IARegistered"=dword:00000000
"AgentUID"=dword:b6ead1ea
"IsForbidUpgrade"=dword:00000000
"EnableThrottling"=dword:00000001
"ThrottlingRetryDelayInterval"=dword:00002710
"Priority"=dword:00000001
"PolicyTimeStamp"=dword:52198957
"UserLangID"=dword:00000404
"OnlineHelpBaseUrl"="http://docs.trendmicro.com/all/smb/wfbs-services/client/wfbs-svc/v5.2/zh-tw/ClientHelp/"
"CollectVirusLogInterval"=dword:0000001e
"CollectSpywareLogInterval"=dword:0000003c
"CollectAegisLogInterval"=dword:00000bb8
"CollectWtpLogInterval"=dword:00000bb8
"CollectNvLogInterval"=dword:00000bb8
"NvLogTimeStamp"=dword:00000000
"CollectEventLogInterval"=dword:0000001e
"CollectVaLogInterval"=dword:00000bb8
"CollectOppLogInterval"=dword:0000003c
"OppStatus"=dword:00000000
"CollectScanLogInterval"=dword:0000001e
"CollectUselessLogInterval"=dword:00000708
"ConnectLogsRetryInterval"=dword:00000000
"CollectUnsentLogInterval"=dword:0000001e
"ComponentSyncInterval"=dword:0036ee80
"SendTopologyInterval"=dword:000493e0
"ServerCfgSyncInterval"=dword:000493e0
"ComputerCmdTimeStamp"=dword:52198afa
"GroupCmdTimeStamp"=dword:52198a0b
"OppCmdTimeStamp"=dword:00000000
"GlobalCmdTimeStamp"=dword:00000000
"CommandLifeTime"=dword:00001c20
"FailReElectThreshold"=dword:00000005
"DelaySwitchScanMode"=dword:00000001
"RedAlertEnabled"=dword:00000001
"YellowAlertEnabled"=dword:00000000
"NotificationSequenceNumber"=hex:04,00,00,00,00,00,00,00
"DisableRedWhenMeet"=dword:00000001
"DisableYellowWhenMeet"=dword:00000001
"LicenseLightPopupSwitch"=dword:00000000
"KeepOppXml"=dword:00000000
"PurgeLogsInterval"=dword:000493e0
"ThrottlingMaximumRetryTime"=dword:000927c0
"SPNURL"="wfbs-svc500-tc.fbs10.trendmicro.com"
"NfcURL"="trewfbs-s50-zh-tw.grid-gfr.trendmicro.com"
"ResendFullTopologyThreshold"=dword:00000014
"CloudScanServiceThreshold"=dword:00000258
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\HostedAgent\RUpdate]
"UpgradeVersion"="5.2.1074/16.2.6520"
"Hotfix"="20130731202331"
"HotfixMD5"="b61760fc0f741058f95fb6e79029e306"
"RAgentDuplicateResult"=dword:00000000
"RAgentUpgradeResult"=dword:00000006
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\HostedAgent\RUpdate\Version]
@=""
"winNT_engine"="9.150.1013"
"TSCx86EngVer"="6.3.1015"
"VSAPIPattern"=dword:000f9f06
"TSCPtNo"=dword:00000522
"CFWx86EngVer"="5.8.1092"
"CfwPtnVer"=dword:0000285b
"VasPtnVer"=dword:0000008c
"VadbPtnVer"=dword:0000008c
"SSAPIx86EngVer"="6.2.3012"
"Rootkitx86EngVer"="2.8.1063"
"SSAPIPtnVer"=dword:00000595
"SSAPISSAPtnVer"=dword:00022e34
"ITrapWhitePtnVer"=dword:00015ff4
"ITrapBlackPtnVer"=dword:000042cc
"TMUFEx86EngVer"="3.0.1029"
"BMDriverx86EngVer"="2.8.1063"
"BMPlugInx86EngVer"="2.8.1063"
"PE_EN_US_PtnVer"=dword:0001d9d4
"PE_DES_PtnVer"=dword:0001d9d4
"WL_PtnVer"=dword:00021408
"BM_PtnVer"=dword:0001dee8
"WFPx86EngVer"="5.8.1092"
"TDIx86EngVer"="5.8.1092"
"NonCRCPtnVer"=dword:000f9e0c
"TMFBE25x86EngVer"="2.5.1028"
"BM_APEM_PtnVer"=dword:0002146c
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\iCRC Scan]
"ScanType"=dword:00000001
"DiagnosticDataCollectionIntervalMin"=dword:0000003c
"MaxSuspiciousFileRecordSize"=dword:00001388
"ScheduledScanServiceSearchIntervalMin"=dword:00000003
"CheckScanServerStatusTimeoutMillisec"=dword:000007d0
"QueryErrorGraceDurationSec"=dword:00000258
"QueryTotalErrorGraceFrequency"=dword:00000005
"QueryNetworkTimeoutGraceFrequency"=dword:00000005
"QueryServerErrorGraceFrequency"=dword:00000005
"QueryNetworkErrorGraceFrequency"=dword:00000005
"ReloadNow"=dword:00000000
"ScanMode"=dword:00000001
"LastConnectTimeStamp"=dword:52198c55
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\iCRC Scan\Scan Server]
"GlobalScanServerUrl"="https://wfbssvc51.icrc.trendmicro.com/"
"GlobalScanServerSSLVerifyPeer"=dword:00000001
"GlobalScanServerProxyUserName"=""
"GlobalScanServerProxyPassword"=""
"LocationProfile"=dword:00000002
"LocalScanServerUrl"="https://wfbssvc51.icrc.trendmicro.com/"
"LocalScanServerSSLVerifyPeer"=dword:00000001
"LocalScanServerAddress"="wfbssvc51.icrc.trendmicro.com"
"LocalScanServerUseProxy"=dword:00000000
"LocalScanServerProxyAddress"=""
"LocalScanServerProxyPort"=dword:00000050
"LocalScanServerProxyUserName"=""
"LocalScanServerProxyPassword"=""
"GlobalScanServerAddress"="wfbssvc51.icrc.trendmicro.com"
"GlobalScanServerUseProxy"=dword:00000000
"GlobalScanServerProxyAddress"=""
"GlobalScanServerProxyPort"=dword:00000050
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Internet Settings]
"Use Anonymous"=dword:00000001
"User name"=""
"Password"=""
"ServerPort"=dword:00001f7b
"Server"="192.168.1.100"
"UseProxy"=dword:00000000
"ProxyPort"=dword:00000050
"ProxyServer"=""
"ProxyLogin"=""
"ProxyPwd"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Location Awareness Setting]
"LocationCriteriaType"=dword:00000001
"LocationProfileCount"=dword:00000001
"LocAwarenessEnable"=dword:00000001
"LocationProfileGatewayIP000"="10.1.131.254"
"LocationProfileGatewayMAC000"="00:21:56:CA:F2:42"
"CurrentLocation"=dword:00000002
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Manual Scan Configuration]
"ScanBoot"=dword:00000001
"ScanCompressed"=dword:00000001
"ScanAllFiles"=dword:00000001
"ExtList"=".\"\",.ACE,.ARJ,.ASP,.BAT,.BIN,.BOO,.CAB,.CHM,.CLA,.CLASS,.COM,.CSC,.DAT,.DLL,.DOC,.DOT,.DRV,.EML,.EXE,.GZ,.HLP,.HTA,.HTM,.HTML,.HTT,.INI,.JAR,.JPEG,.JPG,.JS,.JSE,.LNK,.LZH,.MDB,.MPD,.MPP,.MPT,.MSG,.MSO,.NWS,.OCX,.OFT,.OVL,.PDF,.PHP,.PIF,.PL,.POT,.PPS,.PPT,.PRC,.RAR,.REG,.RTF,.SCR,.SHS,.SYS,.TAR,.VBE,.VBS,.VSD,.VSS,.VST,.VXD,.WML,.WSF,.XLA,.XLS,.XLT,.XML,.Z,.ZIP,.{*,"
"VirusFoundAction"=dword:00000005
"MoveDir"="HTTP://192.168.1.100"
"BkUpIfClean"=dword:00000001
"CompressedLayer"=dword:00000002
"CleanFailedAction"=dword:00000004
"CleanFailedMoveDir"="HTTP://192.168.1.100"
"Enable"=dword:00000001
"AllowCfg"=dword:00000001
"IntelliScan"=dword:00000000
"ActiveAction"=dword:00000001
"ScanHiddenFolder"=dword:00000001
"ScanNetwork"=dword:00000000
"EnableExclusion"=dword:00000001
"CustAction"="Universe-3-4,Joke-2-0,Trojan-2-0,Virus-3-2,Test_Virus-0-0,Packer-2-0,Generic-25-0,Other-3-2,Spyware-2-0,"
"EnableUniAct"=dword:00000000
"ScanSpeed"=dword:00000001
"IntelliTrap"=dword:00000001
"EnableSmartScan"=dword:00000001
"LowUsage"=dword:00000014
"LowSleepTime"=dword:00000006
"LowMustBelowFor"=dword:00000006
"MedUsage"=dword:00000032
"MedSleepTime"=dword:00000003
"MedMustBelowFor"=dword:00000003
"HighUsage"=dword:00000064
"HighSleepTime"=dword:00000000
"HighMustBelowFor"=dword:00000000
"ExcludedFile"=""
"ExcludedFolder"=""
"ExcludedExt"=""
"ExcludeTrendProduct"=dword:00000001
"ZipCleanOnOff"=dword:00000000
"OleLayer"=dword:00000003
"ScanOutgoing"=dword:00000001
"ScanIncoming"=dword:00000001
"ScanShutdown"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Manual Scan Configuration\Spyware Configuration]
"Enable"=dword:00000001
"AllowCfg"=dword:00000000
"ScanType"=dword:00000001
"ActionType"=dword:00000001
"EnableSpyExclusion"=dword:00000001
"ExcludeFileExtList"="MP3;"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Misc.]
"UseChinesePrimLangID"=dword:00000001
"ECSP"=dword:00000000
"UADuplicationOptValue"=dword:00000080
"wslimit_l"=dword:00989680
"wslimit_r"=dword:00989680
"wslimit_m"=dword:004c4b40
"wslimit_n"=dword:004c4b40
"wsperiod_l"=dword:00007530
"wsperiod_r"=dword:00007530
"wsperiod_m"=dword:00007530
"wsperiod_n"=dword:00007530
"TMFBE-Ver"="2.51.1007"
"ExcludeDCFiles"=dword:00000001
"DirectCheck"=dword:00000000
"EngineMin"="9.700.1001"
"ExcludeExchangeStore"=dword:00000001
"ExcludeExchangeStoreFiles"=""
"ExcludeExchangeStoreFolders"=""
"BkFileKeepDay"=dword:00000007
"FqdnFirstOnOff"=dword:00000000
"EngineZipVer"="9.700.1001"
"ProgramVer"="16.2"
"ProductName"="Trend Micro Worry-Free Business Security Services"
"BuildNum"=dword:00001978
"NoPwdProtect"=dword:00000001
"NoProgramUpgrade"=dword:00000000
"AllowMobile"=dword:00000000
"DiskReserved"=dword:0000003c
"InstallCTA"=dword:00000000
"RemoveCTA"=dword:00000000
"AllowStopScheduleScan"=dword:00000001
"AllowDelayScheduleScan"=dword:00000000
"AllowUpdateNow"=dword:00000001
"AllowUpdateFromTMAU"=dword:00000000
"Allow Uninstall"=dword:00000001
"MailScanPageOnOff"=dword:00000001
"ToolPageOnOff"=dword:00000000
"Pop3TrapOnOff"=dword:00000001
"RunPop3Trap"=dword:00000001
"OutlookScanOnOff"=dword:00000001
"ProxySettingOnOff"=dword:00000001
"Updating"=dword:00000000
"DomainType"=dword:00000000
"ReferenceHosts"=""
"RefHostsChkTimeout"=dword:00000000
"PingServerScheduleInterval"=dword:00000000
"PingServerCheckMode"=dword:00000000
"RefHostsEnable"=dword:00000000
"RefHostsChkMode"=dword:00000000
"CookieScanner"=dword:00000001
"LogCookie"=dword:00000001
"EnableAssessment"=dword:00000000
"AssessmentUntil"=dword:00000000
"EnableAutoStopScheduleScan"=dword:00000000
"ScheduleScanLimitMinutes"=dword:0000003c
"Update_Agent_Direct_Update"=dword:00000001
"EnableEventLog"=dword:00000000
"ServerID"=""
"IOTBlock"=dword:00000000
"TSCPatternVer"=dword:00000500
"TSCVAPatternVer"=dword:0000008c
"TSCRegDCTVer"=dword:00000000
"TSCCustDCTVer"=dword:00000000
"PatternVer"=dword:00000000
"PatternVer1"=dword:00000000
"NonCrcPatternVer"=dword:0000038f
"InternalNonCrcPatternVer"=dword:000f1f7c
"SpyPatternVer"=dword:00000000
"InternalPatternVer"=dword:00000000
"RTAbnormal"=dword:00000001
"TSC-Ver"="7.0.1028"
"RTNeedReloadIfSvcModeChanged"=dword:00000000
"AllowConfigNotification"=dword:00000000
"EnableScheduleScanWarning"=dword:00000000
"EnableVirEmailWarning"=dword:00000000
"DisplayPFWTab"=dword:00000001
"Security"=dword:00000000
"SP_EnableFileProtection"=dword:00000000
"ProtectCSATempFolder"=dword:00000000
"ProtectTrendBinaryOnly"=dword:00000000
"RCS"=dword:00000065
"PtnUpdActionWhenScanning"=dword:00000001
"EnableOnlineOfflineChecker"=dword:00000001
"ClientUpgradeStatus"=dword:00000000
"EnableProxyCredCheck"=dword:00000001
"ServiceStartUpTime"=hex:dd,07,08,00,00,00,19,00,0c,00,2c,00,0e,00,90,02
"AdditionalUpdateFlag"=dword:00000000
"DoSynchronize"=dword:00000000
"UpdateAgent"=dword:00000000
"TMUFE-Ver"="3.6.1012"
"InternalBloomFilterPatternVer"=dword:504fb2d0
"NonCrcPatternDate"="20130512"
"DefaultExt"="\"\",ACCDB,ACE,AMG,ARJ,BAT,BIN,BOO,BOX,BZ2,CAB,CDR,CDT,CHM,CLA,CLASS,COM,CPT,CSC,DLL,DOC,DOCM,DOCX,DOT,DOTM,DOTX,DRV,DVB,DWG,DWT,EML,EPOC,EXE,GMS,GZ,HLP,HTA,HTM,HTML,HTT,INI,JAR,JPEG,JPG,JS,JSE,JTD,JTT,LNK,LZH,MDB,MPD,MPP,MPT,MSG,MSI,MSO,MST,NWS,OBD,OCX,OFT,OVL,PDF,PHP,PIF,PL,PM,POT,POTM,POTX,PPAM,PPS,PPSM,PPSX,PPT,PPTM,PPTX,PRC,QPW,RAR,REG,RTF,SCR,SHS,SHW,SIS,SIT,SWF,SYS,TAR,VBE,VBS,VSD,VSS,VST,VXD,WMF,WML,WPD,WPT,WSF,XLA,XLAM,XLS,XLSB,XLSM,XLSX,XLT,XLTM,XLTX,XML,Z,ZIP,{*,"
"SupportTicketingURL"=""
"PccNTMonInitSleep"=dword:00000000
"TDI-Ver"="5.82.1062"
"ROOTKIT-Ver"="5.50.1070"
"AegisBMDriverVer"="2.95.1170"
"AegisBMServiceVer"="2.95.1186"
"AegisTAPtnVer"="1000"
"AegisPEPtnVer"="1.213.00"
"AegisPEPtnDESVer"=dword:0001d9d4
"AegisWLPtnVer"="1.346.00"
"AegisBMPtnVer"="1.222.00"
"AegisBMPluginPEMVer"="2.95.1186"
"AegisAPEMPtnVer"="1.343.00"
"PatternDate"="20130512"
"VsApiNT-Ver"="9.700.1001"
"TmFilter-Ver"="9.700.1001"
"TmPreFlt-Ver"="9.700.1001"
"TotalScanned"=dword:00001d58
"LastScannedFileName"="C:\\WINDOWS\\system32\\WBEM\\Logs\\wbemcore.log"
"InternalNonCrcPatternVerForSVC"=dword:000f1f7c
"IntelliTrapBlackList"=dword:000000ab
"IntelliTrapWhiteList"=dword:00000367
"InternalIntelliTrapWhiteList"=dword:0001543c
"InternalIntelliTrapBlackList"=dword:000042cc
"SSAPITMASSAPatternVer"=dword:00000000
"SSAPIPatternVer"=dword:00000577
"SSAPIPatternDate"="20130508"
"VSAPIRegCPRVer"=dword:00000000
"SSAPI-Ver"="6.2.3030"
"Running"=dword:00000001
"StartUpApplyOpp"=dword:00000000
"HotFix"=""
"IPAddress"="182.234.209.234"
"Reserve"=dword:00000000
"IntelliTrapFolders"="C:\\Documents and Settings\\TIM WU\\Local Settings\\Temporary Internet Files|"
"NotificationSequenceNumber"=hex:03,00,00,00,00,00,00,00
"AllowInstTS"=dword:00000001
"TSLocAwareConfig"=dword:00000000
"PatternTooOldWarningOnOff"=dword:00000001
"PatternTooOldDays"=dword:00000007
"ShellExtensionOnOff"=dword:00000001
"AlertDialogTitleOnOff"=dword:00000001
"ExcludeShadowCopy"=dword:00000001
"LaunchProgram"=dword:00000001
"PrgUpdate"=dword:00000000
"RefClientSatus"=dword:00000000
"SendVL"=dword:00000000
"LaunchTSCAfterUpdate"=dword:00000001
"InfectBootVirus"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\PFW]
"AllowConfigPFW"=dword:00000001
"EnablePFW"=dword:00000001
"EnableIDS"=dword:00000001
"EnablePFWAlert"=dword:00000001
"EnableActiveReport"=dword:00000000
"LogKeepDay"=dword:00000007
"info_globally_disabled"=dword:00000000
"info_server_in_setting"=dword:00000001
"info_server_out_setting"=dword:00000001
"info_addr_cnt"=dword:00000001
"info_addr0"=dword:b6ead1ea
"info_plcy0"=dword:00000004
"info_priv0"=dword:00000000
"GssTrustServer"=""
"EnableNVTrustList"=dword:00000000
"EnableBypassRule"=dword:00000000
"CFW-Ver"="5.82.1024"
"LWF-Ver"="5.82.1024"
"WFP-Ver"="5.82.1024"
"CFWPatternVer"=dword:00002859
"PFWStatus"=dword:00000001
"LastReportTime"=dword:52198bef
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\POP3 AntiSpam]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\POP3 AntiVirus]
"Enabled"=dword:00000001
"DontUseVSAPI"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Prescheduled Scan Configuration]
"ScanBoot"=dword:00000001
"ScanCompressed"=dword:00000001
"ScanAllFiles"=dword:00000001
"ExtList"=".\"\",.ACE,.ARJ,.ASP,.BAT,.BIN,.BOO,.CAB,.CHM,.CLA,.CLASS,.COM,.CSC,.DAT,.DLL,.DOC,.DOT,.DRV,.EML,.EXE,.GZ,.HLP,.HTA,.HTM,.HTML,.HTT,.INI,.JAR,.JPEG,.JPG,.JS,.JSE,.LNK,.LZH,.MDB,.MPD,.MPP,.MPT,.MSG,.MSO,.NWS,.OCX,.OFT,.OVL,.PDF,.PHP,.PIF,.PL,.POT,.PPS,.PPT,.PRC,.RAR,.REG,.RTF,.SCR,.SHS,.SYS,.TAR,.VBE,.VBS,.VSD,.VSS,.VST,.VXD,.WML,.WSF,.XLA,.XLS,.XLT,.XML,.Z,.ZIP,.{*,"
"VirusFoundAction"=dword:00000005
"MoveDir"="HTTP://192.168.1.100"
"BkUpIfClean"=dword:00000001
"CompressedLayer"=dword:00000002
"CleanFailedAction"=dword:00000004
"CleanFailedMoveDir"="HTTP://192.168.1.100"
"Frequency"=dword:00000002
"Hour"=dword:0000000c
"Minute"=dword:0000001e
"DayOfMonth"=dword:00000001
"DayOfWeek"=dword:00000001
"AmPm"=dword:00000002
"Enable"=dword:00000000
"AllowCfg"=dword:00000001
"ScanRemoveable"=dword:00000001
"ScanFixedDisk"=dword:00000001
"ScanCDRom"=dword:00000001
"IntelliScan"=dword:00000000
"ActiveAction"=dword:00000001
"PopVirusFoundAlert"=dword:00000000
"EnableExclusion"=dword:00000001
"CustAction"="Universe-3-4,Joke-2-0,Trojan-2-0,Virus-3-2,Test_Virus-0-0,Packer-2-0,Generic-25-0,Other-3-2,Spyware-2-0,"
"EnableUniAct"=dword:00000000
"ScanSpeed"=dword:00000000
"IntelliTrap"=dword:00000001
"EnableSmartScan"=dword:00000001
"LowUsage"=dword:00000014
"LowSleepTime"=dword:00000006
"LowMustBelowFor"=dword:00000006
"MedUsage"=dword:00000032
"MedSleepTime"=dword:00000003
"MedMustBelowFor"=dword:00000003
"HighUsage"=dword:00000064
"HighSleepTime"=dword:00000000
"HighMustBelowFor"=dword:00000000
"ExcludedFile"=""
"ExcludedFolder"=""
"ExcludedExt"=""
"ExcludeTrendProduct"=dword:00000001
"ZipCleanOnOff"=dword:00000000
"OleLayer"=dword:00000003
"DelayDurationStart"=dword:00000000
"PopUpWarningTime"=dword:00000000
"SuspendType"=dword:00000000
"BackupDelayCount"=dword:00000000
"CurrentDelayCount"=dword:00000000
"SettingSignature"="12f5a550a5fff506e29bf38a09deb599"
"ScanOutgoing"=dword:00000001
"ScanIncoming"=dword:00000001
"ScanShutdown"=dword:00000000
"ScanNetwork"=dword:00000000
"EnableResumeScan"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Prescheduled Scan Configuration\Spyware Configuration]
"Enable"=dword:00000000
"AllowCfg"=dword:00000000
"ScanType"=dword:00000001
"ActionType"=dword:00000001
"PopSpywareFoundAlert"=dword:00000000
"Frequency"=dword:00000002
"Hour"=dword:0000000c
"Minute"=dword:0000001e
"DayOfMonth"=dword:00000001
"DayOfWeek"=dword:00000001
"AmPm"=dword:00000002
"EnableSpyExclusion"=dword:00000001
"ExcludeFileExtList"="MP3;"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\PrivacyProtection]
"Enabled"=dword:00000001
"IMPDPAlertEnabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Real Time Scan Configuration]
"ScanCompressed"=dword:00000001
"ScanAllFiles"=dword:00000001
"VirusFoundAction"=dword:00000005
"ScanShutDown"=dword:00000000
"ExtList"=".\"\",.ACE,.ARJ,.ASP,.BAT,.BIN,.BOO,.CAB,.CHM,.CLA,.CLASS,.COM,.CSC,.DAT,.DLL,.DOC,.DOT,.DRV,.EML,.EXE,.GZ,.HLP,.HTA,.HTM,.HTML,.HTT,.INI,.JAR,.JPEG,.JPG,.JS,.JSE,.LNK,.LZH,.MDB,.MPD,.MPP,.MPT,.MSG,.MSO,.NWS,.OCX,.OFT,.OVL,.PDF,.PHP,.PIF,.PL,.POT,.PPS,.PPT,.PRC,.RAR,.REG,.RTF,.SCR,.SHS,.SYS,.TAR,.VBE,.VBS,.VSD,.VSS,.VST,.VXD,.WML,.WSF,.XLA,.XLS,.XLT,.XML,.Z,.ZIP,.{*,"
"MoveDir"="HTTP://192.168.1.100"
"BkUpIfClean"=dword:00000001
"CompressedLayer"=dword:00000002
"CleanFailedAction"=dword:00000004
"CleanFailedMoveDir"="HTTP://192.168.1.100"
"Enable"=dword:00000001
"AllowCfg"=dword:00000001
"IntelliScan"=dword:00000001
"ActiveAction"=dword:00000001
"ScanIncoming"=dword:00000001
"ScanOutgoing"=dword:00000001
"ScanNetwork"=dword:00000000
"PopVirusFoundAlert"=dword:00000000
"EnableExclusion"=dword:00000001
"CustAction"="Universe-3-4,Joke-2-0,Trojan-2-0,Virus-3-2,Test_Virus-0-0,Packer-2-0,Generic-25-0,Other-3-2,Spyware-2-0,"
"EnableUniAct"=dword:00000000
"IntelliTrap"=dword:00000001
"ExcludedFile"=""
"ExcludedFolder"=""
"ExcludedExt"=""
"ExcludeTrendProduct"=dword:00000001
"WatchDogOnOff"=dword:00000001
"ExcludeExchangeStore"=dword:00000001
"regchange_stamp"=dword:52198b2a
"EnablePassToSSAPI"=dword:00000001
"VSApiNTHome"="C:\\Program Files\\Trend Micro\\Client Server Security Agent\\"
"VirusForbiddenFolderOnOff"=dword:00000001
"GlobalLargeCompressedFileScanSetting"=dword:00000001
"CompressedFileCount"=dword:00000064
"MaximumExtractFileSize"=dword:00000002
"OleLayer"=dword:00000003
"ZipCleanOnOff"=dword:00000000
"StopRemote"=dword:00000000
"StopSchedule"=dword:00000000
"StartPccNtUpd"=dword:00000000
"Desktoppath"="C:\\Documents and Settings\\TIM WU\\桌面"
"UserName"="TIM WU"
"LocaleDateFmt"="yyyy/M/d"
"LocaleTimeFmt"="tt hh:mm:ss"
"ScanSpeed"=dword:00000000
"ScanBoot"=dword:00000000
"UpdateINI"=dword:00000000
"PatternTooOldDays"=dword:00000007
"Remote"=dword:00000000
"PreSchedule"=dword:00000000
"SpyPreSchedule"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Real Time Scan Configuration\Add PIDs]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Real Time Scan Configuration\Delete PIDs]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Real Time Scan Configuration\Spyware Configuration]
"Enable"=dword:00000001
"AllowCfg"=dword:00000000
"ActionType"=dword:00000001
"PopSpywareFoundAlert"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Scan Now Configuration]
"ScanBoot"=dword:00000001
"ScanCompressed"=dword:00000001
"ScanAllFiles"=dword:00000001
"ExtList"=".\"\",.ACE,.ARJ,.ASP,.BAT,.BIN,.BOO,.CAB,.CHM,.CLA,.CLASS,.COM,.CSC,.DAT,.DLL,.DOC,.DOT,.DRV,.EML,.EXE,.GZ,.HLP,.HTA,.HTM,.HTML,.HTT,.INI,.JAR,.JPEG,.JPG,.JS,.JSE,.LNK,.LZH,.MDB,.MPD,.MPP,.MPT,.MSG,.MSO,.NWS,.OCX,.OFT,.OVL,.PDF,.PHP,.PIF,.PL,.POT,.PPS,.PPT,.PRC,.RAR,.REG,.RTF,.SCR,.SHS,.SYS,.TAR,.VBE,.VBS,.VSD,.VSS,.VST,.VXD,.WML,.WSF,.XLA,.XLS,.XLT,.XML,.Z,.ZIP,.{*,"
"VirusFoundAction"=dword:00000005
"MoveDir"="HTTP://192.168.1.100"
"BkUpIfClean"=dword:00000001
"CompressedLayer"=dword:00000002
"CleanFailedAction"=dword:00000004
"CleanFailedMoveDir"="HTTP://192.168.1.100"
"Enable"=dword:00000001
"AllowCfg"=dword:00000001
"ScanRemoveable"=dword:00000001
"ScanFixedDisk"=dword:00000001
"ScanCDRom"=dword:00000001
"IntelliScan"=dword:00000000
"ActiveAction"=dword:00000001
"ScanHiddenFolder"=dword:00000001
"EnableExclusion"=dword:00000001
"CustAction"="Universe-3-4,Joke-2-0,Trojan-2-0,Virus-3-2,Test_Virus-0-0,Packer-2-0,Generic-25-0,Other-3-2,Spyware-2-0,"
"EnableUniAct"=dword:00000000
"ScanSpeed"=dword:00000000
"PopVirusFoundAlert"=dword:00000000
"IntelliTrap"=dword:00000001
"ScanMethod"=dword:00000000
"EnableSmartScan"=dword:00000001
"LowUsage"=dword:00000014
"LowSleepTime"=dword:00000006
"LowMustBelowFor"=dword:00000006
"MedUsage"=dword:00000032
"MedSleepTime"=dword:00000003
"MedMustBelowFor"=dword:00000003
"HighUsage"=dword:00000064
"HighSleepTime"=dword:00000000
"HighMustBelowFor"=dword:00000000
"ExcludedFile"=""
"ExcludedFolder"=""
"ExcludedExt"=""
"ExcludeTrendProduct"=dword:00000001
"ZipCleanOnOff"=dword:00000000
"OleLayer"=dword:00000003
"ScanOutgoing"=dword:00000001
"ScanIncoming"=dword:00000001
"ScanShutdown"=dword:00000000
"ScanNetwork"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Scan Now Configuration\Spyware Configuration]
"Enable"=dword:00000001
"AllowCfg"=dword:00000000
"ScanType"=dword:00000001
"ActionType"=dword:00000001
"PopSpywareFoundAlert"=dword:00000000
"EnableSpyExclusion"=dword:00000001
"ExcludeFileExtList"="MP3;"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Schedule Clean]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Schedule Update]
"ScheduleCheckGlobalSetting"=dword:00000000
"ScheduleUpdateInterval"=dword:00007080
"TimeStamp"=dword:52198afc
"AllowScheduleUpdate"=dword:00000000
"EnableDisable"=dword:00000001
"ScheduleUpdateStartWeekday"=dword:00000007
"ScheduleUpdateStartHour"=dword:00000000
"ScheduleUpdateStartMin"=dword:00000000
"ScheduleUpdateCompletePeriod"=dword:00000e10
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\SPN]
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\SPN\FeedbackModule]
"Guid"="88e1860c-4b8d-47d0-916d-2e4d06985cbd"
"ParentGuid"="88e1860c-4b8d-47d0-916d-2e4d06985cbd"
"BatchTimeIntvl"=dword:0000012c
"BatchEntryNum"=dword:0000000a
"RateLimit"=dword:00000020
"FileFeedbackEnable"=dword:00000001
"Industry"=dword:0000000e
"FbsHost"="wfbs-h30-en.fbs10.trendmicro.com"
"FbsPort"=dword:000001bb
"DnsTimeout"=dword:0000000a
"ConnTimeout"=dword:0000000a
"TransTimeout"=dword:0000012c
"BatchPoolSize"=dword:00002800
"OffHour"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\Spyware Clean]
"SpywareExclusionInfo"=""
"AdditionalThreatExclusionList"=dword:00000000
"AdditionalThreatExclusionInfo"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\TSC Status]
"VirusCount"=dword:00000000
"NeedReboot"=dword:00000000
"NeedReClean"=dword:00000000
"Status"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\URL Filtering]
"UrlFilterAlertEnabled"=dword:00000001
"EnableInOfficeFilter"=dword:00000001
"EnableOutOfficeFilter"=dword:00000001
"InOfficeRatingLevel"=dword:00000001
"OutOfficeRatingLevel"=dword:00000001
"EnableInOfficeLog"=dword:00000001
"EnableOutOfficeLog"=dword:00000001
"ThresholdHigh"=dword:00000050
"ThresholdMedium"=dword:00000041
"ThresholdLow"=dword:00000032
"RedirectPortList"=""
"ClientAWSLMaxCount"=dword:00000064
"RS"="wfbs-h30-en.url.trendmicro.com"
"ReclassifyURL"="http://global.sitesafety.trendmicro.com/"
"LogSendingPeriod"=dword:0000003c
"EnableTmProxyDNSInOffice"=dword:00000000
"EnableTmProxyDNSOutOffice"=dword:00000000
"EnableTMUFEDNSInOffice"=dword:00000000
"EnableTMUFEDNSOutOffice"=dword:00000000
"ProxyAccount"="!CRYPT!1030D529B0FA74F8D284F627A3B"
"ProxyPassword"="!CRYPT!1039D9003282DE06F404F627A3B"
"AllowApproveURL"=dword:00000001
"URLFilterFeedbackEnabled"=dword:00000001
"URLFilterFeedbackFileType"="7,4030"
"EnableTmProxyDNS"=dword:00000000
"EnableTMUFEDNS"=dword:00000000
"Enabled"=dword:00000001
"EnableLog"=dword:00000001
"PMTo"=dword:00000708
"PMFrom"=dword:00000514
"Afternoon"=dword:00000001
"AMTo"=dword:000004b0
"AMFrom"=dword:00000384
"Morning"=dword:00000001
"BusinessDays"=dword:0000003e
"BusinessTime"=dword:00000000
"FilterStrength"=dword:00000004
"EnableURLCategory"=dword:00000001
"CategoryBlockedAtWorkTime"="27,49,4A,4B,4C,4D,4E,4F,50,51,52,53,56,"
"CategoryBlockedAtLeisureTime"="27,49,4A,4B,4C,4D,4E,4F,50,51,52,53,54,55,56,58,"
[HKEY_LOCAL_MACHINE\SOFTWARE\Trendmicro\PC-cillinNTCorp\CurrentVersion\HIPS]
"AlertNSCConflictIIS7"=dword:00000000
|