Firefox Redirect From Google

Ah, because my wife's work offer their virus protection to employees so that it is safer to work from home.
 
OK :)

Please download and run this (if you want to remove Norton; either Norton or Spyware Doctor needs to be uninstalled because only one antivirus should be used).

Post back a fresh HijackThis log afterwards, please.
 
I see.

Please download the Registry Search tool by clicking on the "hard drive" icon halfway down this page:
http://www.billsway.com/vbspage/
Save it to the desktop and run it. If you get an alert from your antivirus about scripting, choose to allow the script to run. Search for Norton and click OK. Post the logfile from the tool here for me.
 
REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "Norton" 31/08/2009 15:52:52

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{142FB276-7C38-4BB4-B475-3F9233B3EFF8}\LocalServer32]
@="\"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F743EA98-42BD-4E2C-A221-3F7B646748C7}\1.0\HELPDIR]
@="C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\Compatibility\NortonSystemInfo]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\Savrt\\"="1"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\navapsvc]
"EventMessageFile"="\"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe\""

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\navapsvc]
"DisplayName"="Norton AntiVirus Auto-Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\navapsvc]
"Description"="Handles Norton AntiVirus Auto-Protect events."

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\navapsvc]
"EventMessageFile"="\"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe\""

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\navapsvc]
"DisplayName"="Norton AntiVirus Auto-Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\navapsvc]
"Description"="Handles Norton AntiVirus Auto-Protect events."

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\navapsvc]
"EventMessageFile"="\"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe\""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\navapsvc]
"DisplayName"="Norton AntiVirus Auto-Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\navapsvc]
"Description"="Handles Norton AntiVirus Auto-Protect events."

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"c"="C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe]
"f"="C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Norton AntiVirus Corporate Edition]

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"="Norton Removal Tool"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool(2).exe"="Norton Removal Tool"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\NavNT\\vptray.exe"="Norton AntiVirus"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Norton AntiVirus]

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe"="Norton AntiVirus Auto-Protect Service"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"="URL Check List"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\BootWarn.exe"="Norton AntiVirus Boot Warning"
 
REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "Symantec" 31/08/2009 18:32:39

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\ProgID]
@="Symantec.stCheckForUpdates.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\VersionIndependentProgID]
@="Symantec.stCheckForUpdates"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\ProgID]
@="Symantec.stInetTransferItem.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\VersionIndependentProgID]
@="Symantec.stInetTransferItem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\ProgID]
@="Symantec.stInetBatchGet.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\VersionIndependentProgID]
@="Symantec.stInetBatchGet"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\ProgID]
@="Symantec.stLUProgressCallback.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\VersionIndependentProgID]
@="Symantec.stLUProgressCallback"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\ProgID]
@="Symantec.stCallbackManager.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\VersionIndependentProgID]
@="Symantec.stCallbackManager"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40800-D38D-11D3-B562-00902771A435}\InProcServer32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\LuComServerPS.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\ProgID]
@="Symantec.stLog.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\VersionIndependentProgID]
@="Symantec.stLog"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\InprocServer32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\ProductRegCom.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\ProgID]
@="Symantec.luProductReg.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\VersionIndependentProgID]
@="Symantec.luProductReg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CEFD16C-91C2-4953-986E-EE77DE2DCF94}\InprocServer32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\NetDetectController.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\InprocServer32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\ProductRegCom.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\ProgID]
@="Symantec.luGroup.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\VersionIndependentProgID]
@="Symantec.luGroup"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\ProgID]
@="Symantec.stSettings.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\VersionIndependentProgID]
@="Symantec.stSettings"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\ProgID]
@="Symantec.stHostCatalog.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\VersionIndependentProgID]
@="Symantec.stHostCatalog"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44990301-3c9d-426d-81df-aab636fa4345}]
@="Symantec Script Runner Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\ProgID]
@="Symantec.stPatchCatalog.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\VersionIndependentProgID]
@="Symantec.stPatchCatalog"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\ProgID]
@="Symantec.stPatch.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\VersionIndependentProgID]
@="Symantec.stPatch"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\ProgID]
@="Symantec.stDisScriptEngine.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\VersionIndependentProgID]
@="Symantec.stDisScriptEngine"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91581CB1-0E7B-11D1-9D93-00A0C95C1762}\ToolboxBitmap32]
@="C:\\Program Files\\Common Files\\Symantec Shared\\SSC\\webshell.dll, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\ProgID]
@="Symantec.stInetGetFile.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\VersionIndependentProgID]
@="Symantec.stInetGetFile"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\ProgID]
@="Symantec.stHost.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\VersionIndependentProgID]
@="Symantec.stHost"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\LocalServer32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\ProgID]
@="Symantec.stInetConnParms.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\VersionIndependentProgID]
@="Symantec.stInetConnParms"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LiveupdateFile\DefaultIcon]
@="C:\\Program Files\\Symantec\\LiveUpdate\\LUALL.EXE,0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CurVer]
@="Symantec.luGroup.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg\CurVer]
@="Symantec.luProductReg.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager\CurVer]
@="Symantec.stCallbackManager.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates\CurVer]
@="Symantec.stCheckForUpdates.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine\CurVer]
@="Symantec.stDisScriptEngine.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost\CurVer]
@="Symantec.stHost.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog\CurVer]
@="Symantec.stHostCatalog.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet\CurVer]
@="Symantec.stInetBatchGet.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms\CurVer]
@="Symantec.stInetConnParms.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile\CurVer]
@="Symantec.stInetGetFile.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem\CurVer]
@="Symantec.stInetTransferItem.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog\CurVer]
@="Symantec.stLog.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback\CurVer]
@="Symantec.stLUProgressCallback.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch\CurVer]
@="Symantec.stPatch.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog\CurVer]
@="Symantec.stPatchCatalog.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings\CurVer]
@="Symantec.stSettings.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SYMC.ScriptRunner]
@="Symantec Script Runner Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SYMC.ScriptRunner.1]
@="Symantec Script Runner Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{17580E52-7B07-11D2-BF1F-00A024D73444}\1.0\0\win32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\ProductRegCom.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{17580E52-7B07-11D2-BF1F-00A024D73444}\1.0\HELPDIR]
@="C:\\Program Files\\Symantec\\LiveUpdate\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{51B9BCA6-4A06-11D3-B538-00902771A435}\1.0\0\win32]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\LUCOMS~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{51B9BCA6-4A06-11D3-B538-00902771A435}\1.0\HELPDIR]
@="C:\\PROGRA~1\\Symantec\\LIVEUP~1\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6F952B50-BCEE-11D1-82D6-00A0C9749EEF}\1.0\0\win32]
@="C:\\Program Files\\Common Files\\Symantec Shared\\SSC\\vpshell2.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6F952B50-BCEE-11D1-82D6-00A0C9749EEF}\1.0\HELPDIR]
@="C:\\Program Files\\Common Files\\Symantec Shared\\SSC\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C546DD23-7302-4E47-A4C1-E8417AD4243F}\1.0\0\win32]
@="C:\\Program Files\\Symantec\\LiveUpdate\\NetDetectController.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C546DD23-7302-4E47-A4C1-E8417AD4243F}\1.0\HELPDIR]
@="C:\\Program Files\\Symantec\\LiveUpdate\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAD5CC54-0E68-11D1-9D91-00A0C95C1762}\1.0\0\win32]
@="C:\\Program Files\\Common Files\\Symantec Shared\\SSC\\webshell.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAD5CC54-0E68-11D1-9D91-00A0C95C1762}\1.0\HELPDIR]
@="C:\\Program Files\\Common Files\\Symantec Shared\\SSC\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{44990301-3C9D-426D-81DF-AAB636FA4345}\DownloadInformation]
"CODEBASE"="https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\LUALL.EXE]
@="C:\\Program Files\\Symantec\\LiveUpdate\\LUALL.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\LUALL.EXE]
"Path"="C:\\Program Files\\Symantec\\LiveUpdate"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\Common Client\\"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Common Files\\Symantec Shared\\VirusDefs\\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E53A294F83182D45A3785356A851754]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\ccInst.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\31C0682E3111780479067E7CB3B8DBB4]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\ccCharCv.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DEE68F0FC3313E4CAD8E4C3EBCBEC40]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2Text.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81A4DC21026924FB5FAF933085D236]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\ccVrTrst.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50BBD0A1CB1FD3648A16157120DF2829]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2TNEF.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50C154874C6F14B48AE0F5068BC7E626]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\DefUtDCD.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50E357748DE0DD840851872431DDB49B]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2RTF.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53DE6260589A37946977BC82BB681915]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\ccL35.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6925106EE9D0AF740BCCD43F8907862F]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2TAR.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EEA3CF07EBD65C48A3FE380BC2FF61E]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2LZ.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91F31ECC41B96D243A45422551C96C23]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2Zip.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\956B95676BE85A84DA3C38A66DE87EF4]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2RAR.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8DC89FAF3F52B3448C6E06B118C405E]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2AMG.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE842139D531885469A1CDC35A26B1F4]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\DecSDK.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB26CE3D008E2FA499FDEE6A7A5B9335]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2CAB.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE6AEA47C44CE854791235345CE87CE6]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2LHA.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1AC78A74A3296B4BA739BA5E5766344]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2SS.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1D015D543A678D4088D751CA77430A5]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2ARJ.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2EEB513BDC48C443B0FFC4606A08DFF]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2ID.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE6692E1170B7234EB5CFD71486A1C3F]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2GZIP.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F42B98E5315CA254F98CB0E739C7CEA1]
"00000000000000000000000000000000"="C:\\Program Files\\Common Files\\Symantec Shared\\Decomposers\\Dec2.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\S32EVNT1.DLL"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\SYMEVENT.SYS"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Common Files\\Symantec Shared\\SEVINST.EXE"=dword:000001f4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\LiveUpdate\\S32LIVE1.DLL"=dword:00000064

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\LiveUpdate\\S32LUIS1.DLL"=dword:00000064

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LiveUpdate1.6]
"UninstallString"="C:\\Program Files\\Symantec\\LiveUpdate\\LSETUP.EXE /U"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LiveUpdate1.6]
"DisplayName"="LiveUpdate 1.6 (Symantec Corporation)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LiveUpdate1.6]
"InstallLocation"="C:\\Program Files\\Symantec\\LiveUpdate"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LiveUpdate1.6]
"Publisher"="Symantec Corporation"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sevinst]
"QuietUninstallString"="C:\\Program Files\\Common Files\\Symantec Shared\\SEVINST.EXE /U /Q"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{503AA035-41E2-4858-B31F-1E49AC66C309}]
"DisplayIcon"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\SymWSC.exe,0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\1.5]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\1.5\RegisteredProducts]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\1.5\RegisteredProducts\{6E34DCC1-B194-11d2-A11E-00409500AD7D}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\1.5\RegisteredProducts\{DE907F20-A4A0-11d2-A985-00104B70545A}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\Sequences]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\Sequences\SYMEVENT INSTALLER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\Sequences\SYMEVENT INSTALLER\10.3]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\LiveUpdate\Sequences\SYMEVENT INSTALLER\10.3\ENGLISH]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedUsage]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedUsage]
"LiveUpdate1"="C:\\Program Files\\Symantec\\LiveUpdate"

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SharedUsage]
"LiveUpdate"="C:\\Program Files\\Symantec\\LiveUpdate"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Control Panel\MMCPL]
"SYMLIVE"="C:\\Program Files\\Symantec\\LiveUpdate\\S32LUCP1.CPL"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Internet Explorer\TypedURLs]
"url1"="http://www.symantec.com/nrtexpired"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSB8.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSBB.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC0.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC6.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD4.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD9.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSF3.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS1C.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS3E.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec]

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Internet Security]

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Norton AntiVirus]

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Shared Technology]

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Shared Technology\LiveReg]

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Shared Technology\LiveReg]
"Store Root"="C:\\Documents and Settings\\Owner\\Application Data\\Symantec"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\LiveReg\\IRALRSHL.EXE"="LiveReg Components"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"="Symantec User Session"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Symantec]

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Symantec\Shared Technology]

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Symantec\Shared Technology\LiveReg]

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Symantec\Shared Technology\LiveReg]
"Store Root"="C:\\Documents and Settings\\Owner\\Application Data\\Symantec"
 
  • Please use the following link to download ERUNT
  • Use the setup program to install ERUNT on your computer
Click Erunt.exe to backup your registry to the folder of your choice.

Note:to restore your registry, go to the folder and start ERDNT.exe

Open Notepad and copy the contents of the following box to a new file.

Code:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{142FB276-7C38-4BB4-B475-3F9233B3EFF8}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F743EA98-42BD-4E2C-A221-3F7B646748C7}\1.0\HELPDIR]
@=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\Compatibility\NortonSystemInfo]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\Savrt\\"=-

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\navapsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe"=-

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\navapsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"=-

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\navapsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSB8.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSBB.tmp\\SymNRT.exe"=-"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC0.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSC6.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD4.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSD9.tmp\\SymNRT.exe"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS1C.tmp\\SymNRT.exe"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zS3E.tmp\\SymNRT.exe"=-

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\exe]
"f"=-

[-HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Norton AntiVirus Corporate Edition]

[-HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec\Norton AntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03E0E6C2-363B-11D3-B536-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C17-24F8-11D3-B530-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\LocalServer32]
@=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A577C19-24F8-11D3-B530-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A1-6BD0-11D3-B542-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D4C11A3-6BD0-11D3-B542-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40800-D38D-11D3-B562-00902771A435}\InProcServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ED40801-D38D-11D3-B562-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\InprocServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17580E5F-7B07-11D2-BF1F-00A024D73444}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CEFD16C-91C2-4953-986E-EE77DE2DCF94}\InprocServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\InprocServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2045EFE5-99CF-11D2-B40A-00600831DD76}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B83B324-49FD-11D3-B538-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C5B6502-5731-11D3-B53D-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44990301-3c9d-426d-81df-aab636fa4345}]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C2714F-4478-11D3-B537-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C27151-4478-11D3-B537-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87D37EC8-8342-11D3-B54C-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91581CB1-0E7B-11D1-9D93-00A0C95C1762}\ToolboxBitmap32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10E2CC6-1525-11D3-B527-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8E2BDBE-5723-11D3-B53D-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\LocalServer32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\ProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE207EB8-122B-11D3-B527-00902771A435}\VersionIndependentProgID]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LiveupdateFile\DefaultIcon]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luProductReg.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCallbackManager.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stCheckForUpdates.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stDisScriptEngine.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHost.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stHostCatalog.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetBatchGet.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetConnParms.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetTransferItem.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLog.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stLUProgressCallback.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatch.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stPatchCatalog.1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stSettings.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SYMC.ScriptRunner]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SYMC.ScriptRunner.1]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{17580E52-7B07-11D2-BF1F-00A024D73444}\1.0\0\win32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{17580E52-7B07-11D2-BF1F-00A024D73444}\1.0\HELPDIR]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{51B9BCA6-4A06-11D3-B538-00902771A435}\1.0\0\win32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{51B9BCA6-4A06-11D3-B538-00902771A435}\1.0\HELPDIR]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6F952B50-BCEE-11D1-82D6-00A0C9749EEF}\1.0\0\win32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6F952B50-BCEE-11D1-82D6-00A0C9749EEF}\1.0\HELPDIR]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C546DD23-7302-4E47-A4C1-E8417AD4243F}\1.0\0\win32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C546DD23-7302-4E47-A4C1-E8417AD4243F}\1.0\HELPDIR]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAD5CC54-0E68-11D1-9D91-00A0C95C1762}\1.0\0\win32]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAD5CC54-0E68-11D1-9D91-00A0C95C1762}\1.0\HELPDIR]
@=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{44990301-3C9D-426D-81DF-AAB636FA4345}\DownloadInformation]
"CODEBASE"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\LUALL.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\Common Client\\"="-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Common Files\\Symantec Shared\\VirusDefs\\"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E53A294F83182D45A3785356A851754]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\31C0682E3111780479067E7CB3B8DBB4]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DEE68F0FC3313E4CAD8E4C3EBCBEC40]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81A4DC21026924FB5FAF933085D236]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50BBD0A1CB1FD3648A16157120DF2829]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50C154874C6F14B48AE0F5068BC7E626]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50E357748DE0DD840851872431DDB49B]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53DE6260589A37946977BC82BB681915]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6925106EE9D0AF740BCCD43F8907862F]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EEA3CF07EBD65C48A3FE380BC2FF61E]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91F31ECC41B96D243A45422551C96C23]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\956B95676BE85A84DA3C38A66DE87EF4]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8DC89FAF3F52B3448C6E06B118C405E]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE842139D531885469A1CDC35A26B1F4]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB26CE3D008E2FA499FDEE6A7A5B9335]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE6AEA47C44CE854791235345CE87CE6]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1AC78A74A3296B4BA739BA5E5766344]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1D015D543A678D4088D751CA77430A5]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2EEB513BDC48C443B0FFC4606A08DFF]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE6692E1170B7234EB5CFD71486A1C3F]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F42B98E5315CA254F98CB0E739C7CEA1]
"00000000000000000000000000000000"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\S32EVNT1.DLL"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\SYMEVENT.SYS"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Common Files\\Symantec Shared\\SEVINST.EXE"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\LiveUpdate\\S32LIVE1.DLL"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\\Program Files\\Symantec\\LiveUpdate\\S32LUIS1.DLL"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LiveUpdate1.6]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sevinst]
"QuietUninstallString"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{503AA035-41E2-4858-B31F-1E49AC66C309}]
"DisplayIcon"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Symantec]

[-HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Symantec]

[-HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Symantec]

Save it as fix.reg (save type: "All files" (*.*)) to your desktop.

It should look like this ->
reg.gif


Go to Desktop, double-click fix.reg and merge the infomation with the registry.

Reboot.

Do another search for norton and symantec and post back results, please.
 
Norton:

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "Norton" 31/08/2009 20:23:43

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"="C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe:*:Enabled:Norton Removal Tool"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"c"="C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"="Norton Removal Tool"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool(2).exe"="Norton Removal Tool"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\NavNT\\vptray.exe"="Norton AntiVirus"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe"="Norton AntiVirus Auto-Protect Service"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"="URL Check List"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\BootWarn.exe"="Norton AntiVirus Boot Warning"


symantec:

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "symantec" 31/08/2009 20:26:20

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup\CurVer]
@="Symantec.luGroup.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\Common Client\\"="1"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Control Panel\MMCPL]
"SYMLIVE"="C:\\Program Files\\Symantec\\LiveUpdate\\S32LUCP1.CPL"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Internet Explorer\TypedURLs]
"url1"="http://www.symantec.com/nrtexpired"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSB8.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSBB.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC0.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC6.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD4.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD9.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSF3.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS1C.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS3E.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\LiveReg\\IRALRSHL.EXE"="LiveReg Components"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"="Symantec User Session"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"
 
Better :)

Open Notepad and copy the contents of the following box to a new file.

Code:
Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.luGroup]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Symantec.stInetGetFile.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Symantec\\Common Client\\"=-

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Control Panel\MMCPL]
"SYMLIVE"=-

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Documents and Settings\\Ben\\Local Settings\\Temp\\7zSF3.tmp\\SymNRT.exe"=-

Save it as fix2.reg (save type: "All files" (*.*)) to your desktop.

It should look like this ->
reg.gif


Go to Desktop, double-click fix2.reg and merge the infomation with the registry.

Reboot.

  • Download RegASSASSIN by malwarebytes.org from here
  • Double-click on RegASSASSIN.exe to start RegASSASSIN
  • Copy and paste the below into the white box one at a time.


    • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC

      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NAVAPSVC

      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NAVAPSVC
  • Click Delete
  • Answer Yes to any prompts

Do another search for norton and symantec and post back results, please.
 
Regassassin could not delete the three keys:

Here are the search results:

Norton:

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "norton" 02/09/2009 18:29:55

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto-Protect Service"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"c"="C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"="Norton Removal Tool"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool(2).exe"="Norton Removal Tool"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\NavNT\\vptray.exe"="Norton AntiVirus"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe"="Norton AntiVirus Auto-Protect Service"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"="URL Check List"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\BootWarn.exe"="Norton AntiVirus Boot Warning"





REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "symantec" 02/09/2009 18:31:20

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Internet Explorer\TypedURLs]
"url1"="http://www.symantec.com/nrtexpired"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSB8.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSBB.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC0.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSC6.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD4.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSD9.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zSF3.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS1C.tmp\\SymNRT.exe"="Symantec Removal Utility"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\DOCUME~1\\Ben\\LOCALS~1\\Temp\\7zS3E.tmp\\SymNRT.exe"="Symantec Removal Utility"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\LiveReg\\IRALRSHL.EXE"="LiveReg Components"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"="Symantec User Session"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"
 
  • Go here and download subinacl.msi
  • Double click on subinacl.msi to start the installation of Subinacl
  • Click Next>
  • Select I accept and click Next>
  • Click browse
  • From the drop down menu select C:\
  • Double click on WINDOWS and then system32
  • Click OK
  • Click Install now
  • Click Finish

Then:

Save text below as remnorton.bat

@echo off
FOR %%R IN (
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC"
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_NAVAPSVC"
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NAVAPSVC"
) Do (
subinacl.exe /subkeyreg %%R /setowner=%username% /grant=%username%=F
reg delete %%R /f
)

Doubleclick it, reboot and do another search for Norton, please.
 
REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "norton" 02/09/2009 19:50:41

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"c"="C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
"i"="C:\\Documents and Settings\\Ben\\Desktop\\remnorton.bat"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\bat]
"a"="C:\\Documents and Settings\\Ben\\Desktop\\remnorton.bat"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool.exe"="Norton Removal Tool"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Documents and Settings\\Ben\\Desktop\\Norton_Removal_Tool(2).exe"="Norton Removal Tool"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"

"C:\\Documents and Settings\\Ben\\Local Settings\\Temporary Internet Files\\Content.IE5\\7GNCCPNX\\Norton_Removal_Tool[1].exe"="Norton Removal Tool"
"C:\\Documents and Settings\\Ben\\Desktop\\remnorton.bat"="remnorton"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-1007\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\NavNT\\vptray.exe"="Norton AntiVirus"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\navapsvc.exe"="Norton AntiVirus Auto-Protect Service"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\cfgwiz.exe"="Symantec Internal Component"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"="URL Check List"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"="Norton Security Center Helper"

[HKEY_USERS\S-1-5-21-1833754385-3838629134-3540252015-500\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Norton Internet Security\\Norton AntiVirus\\BootWarn.exe"="Norton AntiVirus Boot Warning"
 
Back
Top