JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser .
Firefox Redirect From Google
Security Expert: Emeritus
Then before final instructions I have to ask that have you uninstalled Norton?
I have not uninstalled Norton, but it is switched off.
Security Expert: Emeritus
I see.
Are both Spyware Doctor and Norton up-to-date?
Spyware doctor is up to date. I was never sure that Norton was updating properly or doing a good job.
Security Expert: Emeritus
OK.
Which version that Norton is?
It is Norton Antivirus Corporate Edition 7.60.926
Security Expert: Emeritus
So then I'm wondering why corporate edition is in home pc?
Ah, because my wife's work offer their virus protection to employees so that it is safer to work from home.
Security Expert: Emeritus
OK
Please download and run
this (if you want to remove Norton; either Norton or Spyware Doctor needs to be uninstalled because only one antivirus should be used).
Post back a fresh HijackThis log afterwards, please.
Security Expert: Emeritus
I see.
Please download the Registry Search tool by clicking on the "hard drive" icon halfway down this page:
http://www.billsway.com/vbspage/
Save it to the desktop and run it. If you get an alert from your antivirus about scripting, choose to allow the script to run. Search for
Norton and click OK. Post the logfile from the tool here for me.
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "Norton" 31/08/2009 15:52:52
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{142FB276-7C38-4BB4-B475-3F9233B3EFF8}\LocalServer32]
@="\"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F743EA98-42BD-4E2C-A221-3F7B646748C7}\1.0\HELPDIR]
@="C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\Compatibility\NortonSystemInfo]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\Savrt\\"="1"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\navapsvc]
"EventMessageFile"="\"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe\""
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\navapsvc]
"DisplayName"="Norton AntiVirus Auto-Protect Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\navapsvc]
"Description"="Handles Norton AntiVirus Auto-Protect events."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\navapsvc]
"EventMessageFile"="\"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe\""
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\navapsvc]
"DisplayName"="Norton AntiVirus Auto-Protect Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\navapsvc]
"Description"="Handles Norton AntiVirus Auto-Protect events."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\navapsvc]
"EventMessageFile"="\"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe\""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\navapsvc]
"DisplayName"="Norton AntiVirus Auto-Protect Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\navapsvc]
"Description"="Handles Norton AntiVirus Auto-Protect events."
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"c"="C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe]
"f"="C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Norton AntiVirus Corporate Edition]
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"="Norton Removal Tool"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool(2).exe"="Norton Removal Tool"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\NavNT\\vptray.exe"="Norton AntiVirus"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Norton AntiVirus]
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe"="Norton AntiVirus Auto-Protect Service"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"="URL Check List"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\BootWarn.exe"="Norton AntiVirus Boot Warning"
Security Expert: Emeritus
Please do same search for Symantec and post back results
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "Symantec" 31/08/2009 18:32:39
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\ProgID]
@="Symantec.stCheckForUpdates.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\VersionIndependentProgID]
@="Symantec.stCheckForUpdates"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\ProgID]
@="Symantec.stInetTransferItem.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\VersionIndependentProgID]
@="Symantec.stInetTransferItem"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\ProgID]
@="Symantec.stInetBatchGet.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\VersionIndependentProgID]
@="Symantec.stInetBatchGet"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\ProgID]
@="Symantec.stLUProgressCallback.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\VersionIndependentProgID]
@="Symantec.stLUProgressCallback"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\ProgID]
@="Symantec.stCallbackManager.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\VersionIndependentProgID]
@="Symantec.stCallbackManager"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40800-D38D-11D3-B562-00902771A435}\InProcServer32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\LuComServerPS.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\ProgID]
@="Symantec.stLog.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\VersionIndependentProgID]
@="Symantec.stLog"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\InprocServer32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\ProductRegCom.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\ProgID]
@="Symantec.luProductReg.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\VersionIndependentProgID]
@="Symantec.luProductReg"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CEFD16C-91C2-4953-986E-EE77DE2DCF94}\InprocServer32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\NetDetectController.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\InprocServer32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\ProductRegCom.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\ProgID]
@="Symantec.luGroup.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\VersionIndependentProgID]
@="Symantec.luGroup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\ProgID]
@="Symantec.stSettings.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\VersionIndependentProgID]
@="Symantec.stSettings"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\ProgID]
@="Symantec.stHostCatalog.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\VersionIndependentProgID]
@="Symantec.stHostCatalog"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44990301-3c9d-426d-81df-aab636fa4345}]
@="Symantec Script Runner Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\ProgID]
@="Symantec.stPatchCatalog.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\VersionIndependentProgID]
@="Symantec.stPatchCatalog"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\ProgID]
@="Symantec.stPatch.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\VersionIndependentProgID]
@="Symantec.stPatch"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\ProgID]
@="Symantec.stDisScriptEngine.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\VersionIndependentProgID]
@="Symantec.stDisScriptEngine"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91581CB1-0E7B-11D1-9D93-00A0C95C1762}\ToolboxBitmap32]
@="C:\\Program Files\\Common Files\\Symantec Shared\\SSC\\webshell.dll, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\ProgID]
@="Symantec.stInetGetFile.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\VersionIndependentProgID]
@="Symantec.stInetGetFile"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\ProgID]
@="Symantec.stHost.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\VersionIndependentProgID]
@="Symantec.stHost"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\ProgID]
@="Symantec.stInetConnParms.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\VersionIndependentProgID]
@="Symantec.stInetConnParms"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LiveupdateFile\DefaultIcon]
@="C:\\Program Files\\Symantec\\LiveUpdate\\LUALL.EXE,0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CurVer]
@="Symantec.luGroup.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg\CurVer]
@="Symantec.luProductReg.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager\CurVer]
@="Symantec.stCallbackManager.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates\CurVer]
@="Symantec.stCheckForUpdates.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine\CurVer]
@="Symantec.stDisScriptEngine.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost\CurVer]
@="Symantec.stHost.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog\CurVer]
@="Symantec.stHostCatalog.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet\CurVer]
@="Symantec.stInetBatchGet.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms\CurVer]
@="Symantec.stInetConnParms.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile\CurVer]
@="Symantec.stInetGetFile.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem\CurVer]
@="Symantec.stInetTransferItem.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog\CurVer]
@="Symantec.stLog.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback\CurVer]
@="Symantec.stLUProgressCallback.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch\CurVer]
@="Symantec.stPatch.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog\CurVer]
@="Symantec.stPatchCatalog.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings\CurVer]
@="Symantec.stSettings.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SYMC.ScriptRunner]
@="Symantec Script Runner Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SYMC.ScriptRunner.1]
@="Symantec Script Runner Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{17580E52-7B07-11D2-BF1F-00A024D73444}\1.0\0\win32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\ProductRegCom.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{17580E52-7B07-11D2-BF1F-00A024D73444}\1.0\HELPDIR]
@="C:\\Program Files\\Symantec\\LiveUpdate\\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{51B9BCA6-4A06-11D3-B538-00902771A435}\1.0\0\win32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{51B9BCA6-4A06-11D3-B538-00902771A435}\1.0\HELPDIR]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6F952B50-BCEE-11D1-82D6-00A0C9749EEF}\1.0\0\win32]
@="C:\\Program Files\\Common Files\\Symantec Shared\\SSC\\vpshell2.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6F952B50-BCEE-11D1-82D6-00A0C9749EEF}\1.0\HELPDIR]
@="C:\\Program Files\\Common Files\\Symantec Shared\\SSC\\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C546DD23-7302-4E47-A4C1-E8417AD4243F}\1.0\0\win32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\NetDetectController.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C546DD23-7302-4E47-A4C1-E8417AD4243F}\1.0\HELPDIR]
@="C:\\Program Files\\Symantec\\LiveUpdate\\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAD5CC54-0E68-11D1-9D91-00A0C95C1762}\1.0\0\win32]
@="C:\\Program Files\\Common Files\\Symantec Shared\\SSC\\webshell.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAD5CC54-0E68-11D1-9D91-00A0C95C1762}\1.0\HELPDIR]
@="C:\\Program Files\\Common Files\\Symantec Shared\\SSC\\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{44990301-3C9D-426D-81DF-AAB636FA4345}\DownloadInformation]
"CODEBASE"="https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\LUALL.EXE]
@="C:\\Program Files\\Symantec\\LiveUpdate\\LUALL.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\LUALL.EXE]
"Path"="C:\\Program Files\\Symantec\\LiveUpdate"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\Common Client\\"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Common Files\\Symantec Shared\\VirusDefs\\"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E53A294F83182D45A3785356A851754]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\ccInst.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\31C0682E3111780479067E7CB3B8DBB4]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\ccCharCv.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DEE68F0FC3313E4CAD8E4C3EBCBEC40]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2Text.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81A4DC21026924FB5FAF933085D236]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\ccVrTrst.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50BBD0A1CB1FD3648A16157120DF2829]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2TNEF.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50C154874C6F14B48AE0F5068BC7E626]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\DefUtDCD.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50E357748DE0DD840851872431DDB49B]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2RTF.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53DE6260589A37946977BC82BB681915]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\ccL35.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6925106EE9D0AF740BCCD43F8907862F]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2TAR.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EEA3CF07EBD65C48A3FE380BC2FF61E]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2LZ.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91F31ECC41B96D243A45422551C96C23]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2Zip.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\956B95676BE85A84DA3C38A66DE87EF4]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2RAR.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8DC89FAF3F52B3448C6E06B118C405E]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2AMG.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE842139D531885469A1CDC35A26B1F4]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\DecSDK.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB26CE3D008E2FA499FDEE6A7A5B9335]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2CAB.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE6AEA47C44CE854791235345CE87CE6]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2LHA.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1AC78A74A3296B4BA739BA5E5766344]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2SS.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1D015D543A678D4088D751CA77430A5]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2ARJ.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2EEB513BDC48C443B0FFC4606A08DFF]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2ID.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE6692E1170B7234EB5CFD71486A1C3F]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2GZIP.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F42B98E5315CA254F98CB0E739C7CEA1]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\S32EVNT1.DLL"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\SYMEVENT.SYS"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Common Files\\Symantec Shared\\SEVINST.EXE"=dword:000001f4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\LiveUpdate\\S32LIVE1.DLL"=dword:00000064
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\LiveUpdate\\S32LUIS1.DLL"=dword:00000064
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LiveUpdate1.6]
"UninstallString"="C:\\Program Files\\Symantec\\LiveUpdate\\LSETUP.EXE /U"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LiveUpdate1.6]
"DisplayName"="LiveUpdate 1.6 (Symantec Corporation)"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LiveUpdate1.6]
"InstallLocation"="C:\\Program Files\\Symantec\\LiveUpdate"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LiveUpdate1.6]
"Publisher"="Symantec Corporation"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sevinst]
"QuietUninstallString"="C:\\Program Files\\Common Files\\Symantec Shared\\SEVINST.EXE /U /Q"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{503AA035-41E2-4858-B31F-1E49AC66C309}]
"DisplayIcon"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\SymWSC.exe,0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec]
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate]
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\1.5]
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\1.5\RegisteredProducts]
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\1.5\RegisteredProducts\{6E34DCC1-B194-11d2-A11E-00409500AD7D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\1.5\RegisteredProducts\{DE907F20-A4A0-11d2-A985-00104B70545A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\Sequences]
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\Sequences\SYMEVENT INSTALLER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\Sequences\SYMEVENT INSTALLER\10.3]
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\Sequences\SYMEVENT INSTALLER\10.3\ENGLISH]
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedUsage]
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedUsage]
"LiveUpdate1"="C:\\Program Files\\Symantec\\LiveUpdate"
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedUsage]
"LiveUpdate"="C:\\Program Files\\Symantec\\LiveUpdate"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Control Panel\MMCPL]
"SYMLIVE"="C:\\Program Files\\Symantec\\LiveUpdate\\S32LUCP1.CPL"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Internet Explorer\TypedURLs]
"url1"="http://www.symantec.com/nrtexpired"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSB8.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSBB.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC0.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC6.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD4.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD9.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSF3.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS1C.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS3E.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec]
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Internet Security]
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Norton AntiVirus]
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Shared Technology]
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Shared Technology\LiveReg]
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Shared Technology\LiveReg]
"Store Root"="C:\\Documents and Settings\\Owner\\Application Data\\Symantec"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\LiveReg\\IRALRSHL.EXE"="LiveReg Components"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"="Symantec User Session"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Symantec]
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Symantec\Shared Technology]
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Symantec\Shared Technology\LiveReg]
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Symantec\Shared Technology\LiveReg]
"Store Root"="C:\\Documents and Settings\\Owner\\Application Data\\Symantec"
Security Expert: Emeritus
Please use the following link to download ERUNT
Use the setup program to install ERUNT on your computer
Click Erunt.exe to backup your registry to the folder of your choice.
Note:
to restore your registry, go to the folder and start ERDNT.exe
Open Notepad and copy the contents of the following box to a new file.
Code:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{142FB276-7C38-4BB4-B475-3F9233B3EFF8}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F743EA98-42BD-4E2C-A221-3F7B646748C7}\1.0\HELPDIR]
@=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\Compatibility\NortonSystemInfo]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\Savrt\\"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\navapsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\navapsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\navapsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"=-"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe"=-
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe]
"f"=-
[-HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Norton AntiVirus Corporate Edition]
[-HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Norton AntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40800-D38D-11D3-B562-00902771A435}\InProcServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\InprocServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CEFD16C-91C2-4953-986E-EE77DE2DCF94}\InprocServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\InprocServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44990301-3c9d-426d-81df-aab636fa4345}]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91581CB1-0E7B-11D1-9D93-00A0C95C1762}\ToolboxBitmap32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\ProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\VersionIndependentProgID]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LiveupdateFile\DefaultIcon]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SYMC.ScriptRunner]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SYMC.ScriptRunner.1]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{17580E52-7B07-11D2-BF1F-00A024D73444}\1.0\0\win32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{17580E52-7B07-11D2-BF1F-00A024D73444}\1.0\HELPDIR]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{51B9BCA6-4A06-11D3-B538-00902771A435}\1.0\0\win32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{51B9BCA6-4A06-11D3-B538-00902771A435}\1.0\HELPDIR]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6F952B50-BCEE-11D1-82D6-00A0C9749EEF}\1.0\0\win32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6F952B50-BCEE-11D1-82D6-00A0C9749EEF}\1.0\HELPDIR]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C546DD23-7302-4E47-A4C1-E8417AD4243F}\1.0\0\win32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C546DD23-7302-4E47-A4C1-E8417AD4243F}\1.0\HELPDIR]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAD5CC54-0E68-11D1-9D91-00A0C95C1762}\1.0\0\win32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAD5CC54-0E68-11D1-9D91-00A0C95C1762}\1.0\HELPDIR]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{44990301-3C9D-426D-81DF-AAB636FA4345}\DownloadInformation]
"CODEBASE"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\LUALL.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\Common Client\\"="-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Common Files\\Symantec Shared\\VirusDefs\\"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E53A294F83182D45A3785356A851754]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\31C0682E3111780479067E7CB3B8DBB4]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DEE68F0FC3313E4CAD8E4C3EBCBEC40]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81A4DC21026924FB5FAF933085D236]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50BBD0A1CB1FD3648A16157120DF2829]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50C154874C6F14B48AE0F5068BC7E626]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50E357748DE0DD840851872431DDB49B]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53DE6260589A37946977BC82BB681915]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6925106EE9D0AF740BCCD43F8907862F]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EEA3CF07EBD65C48A3FE380BC2FF61E]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91F31ECC41B96D243A45422551C96C23]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\956B95676BE85A84DA3C38A66DE87EF4]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8DC89FAF3F52B3448C6E06B118C405E]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE842139D531885469A1CDC35A26B1F4]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB26CE3D008E2FA499FDEE6A7A5B9335]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE6AEA47C44CE854791235345CE87CE6]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1AC78A74A3296B4BA739BA5E5766344]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1D015D543A678D4088D751CA77430A5]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2EEB513BDC48C443B0FFC4606A08DFF]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE6692E1170B7234EB5CFD71486A1C3F]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F42B98E5315CA254F98CB0E739C7CEA1]
"00000000000000000000000000000000"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\S32EVNT1.DLL"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\SYMEVENT.SYS"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Common Files\\Symantec Shared\\SEVINST.EXE"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\LiveUpdate\\S32LIVE1.DLL"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\LiveUpdate\\S32LUIS1.DLL"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LiveUpdate1.6]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sevinst]
"QuietUninstallString"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{503AA035-41E2-4858-B31F-1E49AC66C309}]
"DisplayIcon"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Symantec]
[-HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec]
[-HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Symantec]
Save it as fix.reg (save type: "All files" (*.*)) to your desktop.
It should look like this ->
Go to Desktop, double-click fix.reg and merge the infomation with the registry.
Reboot.
Do another search for norton and symantec and post back results, please.
Norton:
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "Norton" 31/08/2009 20:23:43
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"c"="C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"="Norton Removal Tool"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool(2).exe"="Norton Removal Tool"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\NavNT\\vptray.exe"="Norton AntiVirus"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe"="Norton AntiVirus Auto-Protect Service"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"="URL Check List"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\BootWarn.exe"="Norton AntiVirus Boot Warning"
symantec:
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "symantec" 31/08/2009 20:26:20
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CurVer]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CurVer]
@="Symantec.luGroup.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile.1\CLSID]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\Common Client\\"="1"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Control Panel\MMCPL]
"SYMLIVE"="C:\\Program Files\\Symantec\\LiveUpdate\\S32LUCP1.CPL"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Internet Explorer\TypedURLs]
"url1"="http://www.symantec.com/nrtexpired"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSB8.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSBB.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC0.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC6.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD4.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD9.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSF3.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS1C.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS3E.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\LiveReg\\IRALRSHL.EXE"="LiveReg Components"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"="Symantec User Session"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"
Security Expert: Emeritus
Better
Open Notepad and copy the contents of the following box to a new file.
Code:
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\Common Client\\"=-
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Control Panel\MMCPL]
"SYMLIVE"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"=-
Save it as fix2.reg (save type: "All files" (*.*)) to your desktop.
It should look like this ->
Go to Desktop, double-click fix2.reg and merge the infomation with the registry.
Reboot.
Download RegASSASSIN by malwarebytes.org from here
Double-click on RegASSASSIN.exe to start RegASSASSIN
Copy and paste the below into the white box one at a time.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NAVAPSVC
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NAVAPSVC
Click Delete
Answer Yes to any prompts
Do another search for norton and symantec and post back results, please.
Regassassin could not delete the three keys:
Here are the search results:
Norton:
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "norton" 02/09/2009 18:29:55
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"c"="C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"="Norton Removal Tool"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool(2).exe"="Norton Removal Tool"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\NavNT\\vptray.exe"="Norton AntiVirus"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe"="Norton AntiVirus Auto-Protect Service"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"="URL Check List"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\BootWarn.exe"="Norton AntiVirus Boot Warning"
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "symantec" 02/09/2009 18:31:20
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Internet Explorer\TypedURLs]
"url1"="http://www.symantec.com/nrtexpired"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSB8.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSBB.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC0.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC6.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD4.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD9.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSF3.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS1C.tmp\\SymNRT.exe"="Symantec Removal Utility"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS3E.tmp\\SymNRT.exe"="Symantec Removal Utility"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\LiveReg\\IRALRSHL.EXE"="LiveReg Components"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"="Symantec User Session"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"
Security Expert: Emeritus
Go here and download subinacl.msi
Double click on subinacl.msi to start the installation of Subinacl
Click Next>
Select I accept and click Next>
Click browse
From the drop down menu select C:\
Double click on WINDOWS and then system32
Click OK
Click Install now
Click Finish
Then:
Save text below as remnorton.bat
@echo off
FOR %%R IN (
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NAVAPSVC"
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NAVAPSVC"
) Do (
subinacl.exe /subkeyreg %%R /setowner=%username% /grant=%username%=F
reg delete %%R /f
)
Doubleclick it, reboot and do another search for Norton, please.
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "norton" 02/09/2009 19:50:41
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"c"="C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"i"="C:\\Documents and Settings\\Ben\\Desktop\\remnorton.bat"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bat]
"a"="C:\\Documents and Settings\\Ben\\Desktop\\remnorton.bat"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"="Norton Removal Tool"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool(2).exe"="Norton Removal Tool"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\Documents and Settings\\Ben\\Desktop\\remnorton.bat"="remnorton"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\NavNT\\vptray.exe"="Norton AntiVirus"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe"="Norton AntiVirus Auto-Protect Service"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"="URL Check List"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"
[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\BootWarn.exe"="Norton AntiVirus Boot Warning"