home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
ftp2.jacobs.com
/
2015.02.ftp2.jacobs.com.tar
/
ftp2.jacobs.com
/
pub
/
mcafee.exe
/
VSE880_Win8.msi
/
Binary.VSE.xml_x64
< prev
next >
Wrap
Text File
|
2013-09-11
|
59KB
|
678 lines
<Package xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="mfehidin.xsd">
<CoreInstall>
<General>
<Version>15.1.0.500.3</Version>
<ProductId>{790352C7-6F69-4553-9BB5-0D430ABD6C64}</ProductId>
<CorePath>McAfee\SystemCore</CorePath>
<CorePath_X86>McAfee\SystemCore</CorePath_X86>
<SourcePath_X86>.\..</SourcePath_X86>
<Base>
<FileName sha256="19d1b1b7131c22310c10a5aec40739009a4915c981a3905851b5a37f01ce044f">mfehidk.sys</FileName>
<FileName sha256="21ded5ca558d3ee8ae6327f8b14ed81411ee9c1abfddef81a405a12cdaf57136">mfevtps.exe</FileName>
<FileName sha256="52ba66856e34ead3165e0589ce6b6e44f4d5d45295e47fca1f914da288148a9c">mfehidk_messages.dll</FileName>
<FileName sha256="3ef44129cd03049874e56ea2e49338d048abdad6785f7e0f8ee70663dcf5be44">mfetdi2k.sys</FileName>
<FileName sha256="8eaaece50b0166008c66ce5b01565fbb71c20f126a99ef1a76f36af706e539f3">mfewfpk.sys</FileName>
</Base>
</General>
<Feature tag="OAS" GUID="{5E8D8632-9C07-432B-A71E-ABAED95E5984}">
<Core>
<Registry key="HKLM\software\mcafee\SystemCore">
<Registry key="vscore">
<Value merge="keep_existing" type="DWORD" name="ForceSuperMode" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="LockDownEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="NoRunTimeDats" data="0x00000003"/>
<Value merge="keep_existing" type="SZ" name="PreferredLanguage" data=""/>
<Registry key="NVP">
<Value merge="keep_existing" type="DWORD" name="dwModifiedByASEM" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectAdware" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectDialers" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectJokes" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectKeyLoggers" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectPasswordCrackers" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectPotentiallyUnwantedApps" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectRemoteAdminTools" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectSpyware" data="0x00000001"/>
<Value merge="keep_existing" type="BINARY" name="DetectionExclusions" data="00,00"/>
</Registry>
<Registry key="On Access Scanner">
<Value merge="keep_existing" type="DWORD" name="ArtemisEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ArtemisLevel" data="0x00000002"/>
<Registry key="McShield">
<Registry key="Configuration">
<Value merge="keep_existing" type="DWORD" name="EOLPID" data="0x0002f4a"/>
<Value merge="keep_existing" type="SZ" name="Alert_LocalMessage" data="IDS_OAS_ALERT_LOCAL"/>
<Value merge="keep_existing" type="DWORD" name="ScanProcessesOnEnable" data="0x0000000"/>
<Value merge="keep_existing" type="BINARY" name="PPContextIDs" data="01,50,00,00,02,50,00,00,03,50,00,00,00,90,00,00"/>
<Value merge="keep_existing" type="SZ" name="RepairBackupDirectory" data="C:\QUARANTINE\"/>
<Value merge="keep_existing" type="DWORD" name="RepairBackupPUPs" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="RepairBackupViruses" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="szLogFileName" data="%DEFLOGDIR%\OnAccessScanLog.txt"/>
<Value merge="keep_existing" type="DWORD" name="EOLPID" data="0x0002f4a"/>
<Value merge="keep_existing" type="DWORD" name="OnlyUseDefaultConfig" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bScanFloppyOnShutdown" data="0x00000000"/>
<Registry key="Default">
<Value merge="keep_existing" type="DWORD" name="uSecAction" data="0x00000004"/>
<Value merge="keep_existing" type="DWORD" name="uAction" data="0x00000005"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction_Program" data="0x00000004"/>
<Value merge="keep_existing" type="DWORD" name="bNetworkScanEnabled" data="0x00000000"/>
</Registry>
<Registry key="High">
<Value merge="keep_existing" type="DWORD" name="uSecAction" data="0x00000004"/>
<Value merge="keep_existing" type="DWORD" name="bNetworkScanEnabled" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction_Program" data="0x00000004"/>
</Registry>
<Registry key="Low">
<Value merge="keep_existing" type="DWORD" name="uSecAction" data="0x00000004"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction_Program" data="0x00000004"/>
<Value merge="keep_existing" type="DWORD" name="bNetworkScanEnabled" data="0x00000000"/>
</Registry>
</Registry>
</Registry>
</Registry>
</Registry>
</Registry>
</Core>
</Feature>
<Feature tag="OAS" GUID="{5E8D8632-9C07-432B-A71E-ABAED95E5984}">
<Driver bootload="2" vtpoptions="0x100000">
<FileName sha256="a9713c7669fce5242eb1f0208e5c9b008fd612020e6254b7839ad954992e595e">mfeavfk.sys</FileName>
</Driver>
<Driver vtpoptions="0x100000">
<FileName sha256="9eff21f7a9756f7cbb782c2873e3611f0f77ccdbedcb9e080f9b4134c6b408c0">mfeapfk.sys</FileName>
</Driver>
<Driver platform="x86" vtpoptions="0x100000">
<FileName sha256="a6c8ab7d5e429f4e9bfe3a30ebb726722338bfa7f15b572feb77f167f99a68d7">mfebopk.sys</FileName>
<Registry>
<Value merge="keep_existing" type="DWORD" name="EnableDep" data="1"/>
</Registry>
</Driver>
<Driver>
<FileName sha256="87b4f558d98296701846d171e9678a01215963f001b0f492afa35682c426fc7c">mferkdet.sys</FileName>
</Driver>
<Core>
<FileName sha256="056fb308efcebfe1bc0bf765a8967c20f887d6388f39b4bb503bb017c8f43f0f">mytilus3.dll</FileName>
<FileName sha256="2e0bd396a178942e715f97aba7bf233620643eecbb623e6c41e476e3124669e0">mytilus3_server.dll</FileName>
<FileName sha256="31728d12554924fab01fdc309eb25ba5dc3b815a374b82f7057c3adda4867a3a">mytilus3_worker.dll</FileName>
<FileName sha256="fb1ea44964bee743655940a3732dd2e94e710956761bb0411c339a763670d12b">rkscan.dll</FileName>
<FileName sha256="48416970c0bfc22e0c7afc6928a7190cca110e0b65952e39b9a13ea9c66b43ad">ftl.dll</FileName>
<FileName sha256="827ea1d047d44eb1b6459c4611b431446f23392af0ed3ffb335d6413434c8f0a">lockdown.dll</FileName>
<FileName hash="no">naevent.dll</FileName>
<FileName hash="no">naievent.dll</FileName>
<FileName hash="no">mcshield.dll</FileName>
<FileName platform="x86" sha256="9ca39a23f7c6ee33462150479d5177d860edcf55e89a848497e333f496bf0753">strings.bin</FileName>
<FileName platform="x64" source="$SOURCEPATH_X86" sha256="9ca39a23f7c6ee33462150479d5177d860edcf55e89a848497e333f496bf0753">strings.bin</FileName>
<FileName sha256="0a0649f1b6aac6b16b898d3a640ccc23854bd81e4767da5a3aaa2edc08da21f0">mfeavfa.dll</FileName>
<FileName sha256="9627d0c62676e7b4415999cd0b109be990869276b492c4f0a9b40fbe67ddb2b0">mfeapfa.dll</FileName>
<FileName platform="x86" sha256="047c069a0663d61e9adabf142db402ba4713f536a612ee8a03af22374f99e2b2">mfebopa.dll</FileName>
<FileName sha256="3af159784a6d177596c616da5225da6b9c8fad04ce9e6acfc5c182cc8e434658">mfehida.dll</FileName>
<FileName sha256="16fdd9e202cadfff60478c1ec3fd71b41ee8b6b0af12eb9bc8ee9e14fa0fafa7">mferkda.dll</FileName>
<FileName sha256="a3ec892a96ddd3b7b21889ce7e6e506e581d2b929bf4e3d7192f950b08154b1a">mfevtpa.dll</FileName>
<FileName sha256="232331b6e0af10f25c3a5397a373bd70c8048820488181242854fdf31fe773f1">mfehidin.exe</FileName>
<Directory platform="x64" location="$COREPATH_X86">
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="9b2879c860c56a2d349e08e6f159d94750f6d8e3a9dbc6286201adae8a3ab16f">mytilus3.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="cbe623c20342bfb1d1b23888dfd210625935f45d736d5c789356c15eaaf31d1e">mytilus3_worker.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="f4337a8c12ec94fc329a807330e8ff32844e2e4fea2afdd2aed4120f3dd7b380">rkscan.dll</FileName>
</Directory>
<Registry key="HKLM\software\mcafee\SystemCore">
<Registry key="vscore">
<Value type="SZ" name="szInstallDir32" data="$COREPATH_X86"/>
<Value type="SZ" name="szInstallDir64" data="$COREPATH"/>
<Value merge="keep_existing" type="DWORD" name="PreScanSizeKBForArtemisScan" data="5000"/>
<Value merge="keep_existing" type="SZ" name="ArtemisScanExts" data="EXE DLL RAR MSI OCX"/>
<Value merge="keep_existing" type="DWORD" name="NoRunTimeDats" data="3"/>
<Value merge="keep_existing" type="DWORD" name="AllowVscanBofUpdates" data="1"/>
<Value merge="keep_existing" type="DWORD" name="LockDownEnabled" data="0"/>
<Value merge="keep_existing" type="DWORD" name="DebugFlags" data="0x15400000"/>
<Value merge="keep_existing" type="DWORD" name="DebugFlagsHigh" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="csDebugFlags" data="0x00007fff"/>
<Value merge="keep_existing" type="DWORD" name="EnableNtfsScan" data="0x00000001"/>
<Registry key="NVP">
<Value merge="keep_existing" type="DWORD" name="DetectRemoteAdminTools" data="00000000"/>
<Value merge="keep_existing" type="BINARY" name="DetectionExclusions" data="00,00"/>
<Value merge="keep_existing" type="DWORD" name="DetectDialers" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="DetectAdware" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="DetectPasswordCrackers" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="DetectPotentiallyUnwantedApps" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="DetectSpyware" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="DetectJokes" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="DetectKeyLoggers" data="00000000"/>
</Registry>
<Registry key="On Access Scanner">
<Registry key="McShield">
<Registry key="Configuration">
<Value merge="keep_existing" type="DWORD" name="BootPhaseTimeLimit" data="00000120"/>
<Value merge="keep_existing" type="DWORD" name="OASEnabled" data="00000003"/>
<Value merge="keep_existing" type="DWORD" name="DotVirToDenyFailedClean" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DotVirToDenyWrite" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bLogDateTime" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bDenyFloppyMountIfInfected" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="uCloseDelta" data="0x000001f4"/>
<Value merge="keep_existing" type="DWORD" name="bApplyNow" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="DotVirOnQuarantine" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="Alert_ExcludeCookies" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bDisconnectUser" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="WorkAroundAllocateCDRoms" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="Alert_AutoShowList" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bDisableScanning" data="00000000"/>
<Value merge="keep_existing" type="SZ" name="SmoothWritesExtensions" data="ini log txt"/>
<Value merge="keep_existing" type="DWORD" name="bLimitSize" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="Alert_UsersCanClean" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bLogClean" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bScanFloppyOnShutdown" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bLogSummary" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bReloadDATs" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="OnlyUseDefaultConfig" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="Alert_UsersCanRemove" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="Alert_LocalMessage" data="VirusScan Alert!"/>
<Value merge="keep_existing" type="SZ" name="szMoveToFolder" data="\quarantine\"/>
<Value merge="keep_existing" type="DWORD" name="WorkAroundAllocateFloppies" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bLoadAtStartup" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bLogSettings" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="RepairBootSectors" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bDontScanMBRSectors" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="ReportEncryptedFiles" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ScanArchiveTimeout" data="0x0000000f"/>
<Value type="DWORD" name="ScanCookies" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="ScanSetEA" data="0x1"/>
<Value merge="keep_existing" type="DWORD" name="wFlags" data="0x00001000"/>
<Value merge="keep_existing" type="DWORD" name="bLogToFile" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="wTaskType" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="uKilobytes" data="0x00000064"/>
<Value merge="keep_existing" type="DWORD" name="bLogUserName" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="Alert_UsersCanQuarantine" data="00000001"/>
<Value merge="keep_existing" type="DWORD" name="dwMaxLogSizeMB" data="00000001"/>
<Value merge="keep_existing" type="DWORD" name="wDate" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="Alert_MaxAlertsKb" data="0x000003e8"/>
<Value merge="keep_existing" type="DWORD" name="bFileCacheEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="dwLastModified" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="Alert_MaxAlertsCount" data="0x000003e8"/>
<Value merge="keep_existing" type="DWORD" name="bVScan" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="Alert_UsersCanDelete" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="ScannerThreadTimeout" data="0x0000afc8"/>
<Value merge="keep_existing" type="DWORD" name="ScannerThreadTimeoutEx" data="0x0000afc8"/>
<Value merge="keep_existing" type="DWORD" name="ScannerThreadRepairTimeout" data="0x0000afc8"/>
<Value merge="keep_existing" type="DWORD" name="ScannerThreadRepairTimeoutEx" data="0x0000afc8"/>
<Value merge="keep_existing" type="DWORD" name="wTime" data="0x00000200"/>
<Value merge="keep_existing" type="DWORD" name="LogFileFormat" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bDontScanBootSectors" data="00000000"/>
<Value merge="keep_existing" type="SZ" name="szDisconnectMessage" data="Virus Alert !!!"/>
<Value merge="keep_existing" type="SZ" name="szTaskName" data="On-Access Scan"/>
<Value merge="keep_existing" type="DWORD" name="dwExitStatus" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="EOLPID" data="0x00002ef7"/>
<Value merge="keep_existing" type="DWORD" name="UseAVVDats" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DisableCachingOfNetworkScans" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="DisablePersistentCache" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="DisableVerifyOfPersistedCache" data="00000001"/>
<Value merge="keep_existing" type="DWORD" name="WhiteListTrustedInstallers" data="00000001"/>
<Value merge="keep_existing" type="DWORD" name="WhiteListByUSN" data="00000001"/>
<Value merge="keep_existing" type="DWORD" name="DelayAllWriteScans" data="00000001"/>
<Value merge="keep_existing" type="DWORD" name="ScanProcessesOnEnable" data="0000001"/>
<Value merge="keep_existing" type="DWORD" name="ScanProcessesDelaySeconds" data="0000060"/>
<Value merge="keep_existing" type="DWORD" name="ScanProcessOnDetection" data="0000001"/>
<Value type="DWORD" name="BootCacheMinutes" merge="true" data="0xffffffff"/>
<Value merge="keep_existing" type="DWORD" name="BackgroundAllDelayedScans" data="0x1"/>
<Value merge="keep_existing" type="DWORD" name="ShortPathsOnlyOnEnabledVolumes" data="0x1"/>
<Registry key="Default">
<Value merge="keep_existing" type="DWORD" name="NetworkExtensionMode" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ReportEncryptedFiles" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="ApplyNVP" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="LocalExtensionMode" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="szIncludeExts" data=""/>
<Value merge="keep_existing" type="DWORD" name="bScanOutgoing" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction_Program" data="0x00000007"/>
<Value merge="keep_existing" type="DWORD" name="uAction_Program" data="0x00000005"/>
<Value merge="keep_existing" type="DWORD" name="NumExcludeItems" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="dwMacroHeuristicsLevel" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="uAction" data="00000000"/>
<Value merge="keep_existing" type="MULTI_SZ" name="ProcessList" data="\0"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction" data="0x00000007"/>
<Value merge="keep_existing" type="DWORD" name="dwProgramHeuristicsLevel" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bScanIncoming" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="szProgExts" data=""/>
<Value merge="keep_existing" type="DWORD" name="bNetworkScanEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ScanBackupReads" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ScanArchives" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="ScanMime" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="bDelayWriteScans" data="00000001"/>
</Registry>
<Registry key="High">
<Value merge="keep_existing" type="DWORD" name="ScanBackupReads" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ReportEncryptedFiles" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bScanIncoming" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bScanOutgoing" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bNetworkScanEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="dwProgramHeuristicsLevel" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ScanArchives" data="00000001"/>
<Value merge="keep_existing" type="DWORD" name="ApplyNVP" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction_Program" data="0x00000003"/>
<Value merge="keep_existing" type="DWORD" name="dwMacroHeuristicsLevel" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="NetworkExtensionMode" data="0x00000001"/>
<Value merge="keep_existing" type="MULTI_SZ" name="ProcessList" data="4nt.exe\0acroread.exe\0agent.exe\0aim.exe\0bearshare.exe\0Cmd.Exe\0cscript.exe\0eudora.exe\0Excel.exe\0Explorer.exe\0FileNavigator.exe\0ftp.exe\0gdonkey.exe\0gnucleus.exe\0ICQ.exe\0Iexplore.exe\0inetinfo.exe\0mirc.exe\0mobsync.exe\0mosaic.exe\0mozilla.exe\0MsAccess.exe\0MsImn.exe\0msmsgs.exe\0msn6.exe\0neo20.exe\0netscape.Exe\0netscp6.exe\0Outlook.exe\0opera.exe\0PowerPnt.exe\0tftp.exe\0Visio32.exe\0waol.exe\0WinPM-32.exe\0WinWord.Exe\0ws_ftp.exe\0wscript.exe\0wuauclt.exe\0xolox.exe\0ypager.exe\0yupdate.exe\0"/>
<Value merge="keep_existing" type="SZ" name="szIncludeExts" data=""/>
<Value merge="keep_existing" type="DWORD" name="ScanMime" data="00000000"/>
<Value merge="keep_existing" type="SZ" name="szProgExts" data=""/>
<Value merge="keep_existing" type="DWORD" name="LocalExtensionMode" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="Exclusions" data=""/>
<Value merge="keep_existing" type="DWORD" name="uAction_Program" data="0x00000005"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction" data="0x00000003"/>
<Value merge="keep_existing" type="DWORD" name="uAction" data="0x00000005"/>
<Value merge="keep_existing" type="DWORD" name="NumExcludeItems" data="00000000"/>
</Registry>
<Registry key="Low">
<Value merge="keep_existing" type="SZ" name="szIncludeExts" data=""/>
<Value merge="keep_existing" type="MULTI_SZ" name="ProcessList" data="Aexauditpls.exe\0Aexnsclient.exe\0Aexnsclienttransport.exe\0Aexnswdusr.exe\0searchindexer.exe\0"/>
<Value merge="keep_existing" type="SZ" name="szProgExts" data=""/>
<Value merge="keep_existing" type="DWORD" name="uSecAction" data="0x00000003"/>
<Value merge="keep_existing" type="DWORD" name="dwProgramHeuristicsLevel" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="uAction_Program" data="0x00000005"/>
<Value merge="keep_existing" type="DWORD" name="ScanArchives" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="ApplyNVP" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction_Program" data="0x00000003"/>
<Value merge="keep_existing" type="DWORD" name="NetworkExtensionMode" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="LocalExtensionMode" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="NumExcludeItems" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="ScanMime" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="bScanOutgoing" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bNetworkScanEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bScanIncoming" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ReportEncryptedFiles" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="dwMacroHeuristicsLevel" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="uAction" data="0x00000005"/>
<Value merge="keep_existing" type="DWORD" name="bDelayWriteScans" data="00000001"/>
</Registry>
</Registry>
</Registry>
<Registry key="BehaviourBlocking">
<Value merge="keep_existing" type="BINARY" name="AccessProtectionUserRules" data="41,63,63,65,73,73,50,72,6f,74,65,63,74,69,6f,6e,20,7b,0d,0a,7d,0d,0a"/>
<Value merge="keep_existing" type="DWORD" name="PortBlockReportMinutes" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="dwMaxLogSizeMB_Ent" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="VSIDMessage" data=""/>
<Value merge="keep_existing" type="DWORD" name="bLogToFile_Ent" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bLogToFile" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bLimitSize_Ent" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="BOPEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="dwMaxLogSizeMB" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="APEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="LogFileFormat" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="VSIDBlockOnNonVirus" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="bLimitSize" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="BOPShowMessages" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="BOPMode" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="LogFileFormat_Ent" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="VSIDBlockTimeout" data="0x0000000a"/>
<Value merge="keep_existing" type="DWORD" name="VSIDSendMessage" data="00000000"/>
<Value merge="keep_existing" type="DWORD" name="VSIDBlock" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="ProtectionType" data="Standard"/>
</Registry>
</Registry>
</Registry>
<Registry key="HKLM\system\currentcontrolset\services\eventlog\application\mclogevent">
<Value type="SZ" name="EventMessageFile" data="$COREPATH\naievent.dll"/>
<Value type="DWORD" name="TypesSupported" data="0x7"/>
</Registry>
</Registry>
</Core>
<SystemFiles>
<Directory location="drivers">
<FileName sha256="cec6a40412d8e7bb9ff087d8798448ec24797698f05143aaf63ad78420b9f13d">mfeclnk.sys</FileName>
</Directory>
</SystemFiles>
<!-- install ETW Event info to support SERVICE_TRIGGER_START. WIN8 only -->
<Process wait="true" action="onInstall" location="$SYSTEM32ROOT" winver="6200-">wevtutil.exe im ETWMcShieldStartManifest.man</Process>
<!-- WIN8+ -->
<Service location="$COREPATH" control="start_stop_restart" winver="6200-">
<FileName sha256="b45c65b90ebccc01d1a792b06966063575f95a294184f52c6bc6ca3b2ff6356e">mcshield.exe</FileName>
<ServiceName>McShield</ServiceName>
<DisplayName>McAfee McShield</DisplayName>
<Description>McAfee OnAccess Scanner</Description>
<DependOnService>mfevtp</DependOnService>
<Start>SERVICE_AUTO_START</Start>
<TriggerStart/>
</Service>
<!-- pre WIN8 -->
<Service location="$COREPATH" control="start_stop_restart" winver="5000-6199">
<FileName sha256="b45c65b90ebccc01d1a792b06966063575f95a294184f52c6bc6ca3b2ff6356e">mcshield.exe</FileName>
<ServiceName>McShield</ServiceName>
<DisplayName>McAfee McShield</DisplayName>
<Description>McAfee OnAccess Scanner</Description>
<DependOnService>mfevtp</DependOnService>
<Start>SERVICE_AUTO_START</Start>
<FailureRestart>
<ResetPeriod>1800</ResetPeriod>
<RestartCount>5</RestartCount>
<RestartDelay>5</RestartDelay>
</FailureRestart>
</Service>
</Feature>
<Feature tag="ScriptScan" GUID="{8E13DC7F-6BD9-4ED4-8362-E73FE29BD956}">
<!-- Define pre-stop and pre-start commands to stop scriptscan -->
<Process action="preStopService" service="mcshield">"$COREPATH\DAInstall.exe" -ds</Process>
<Process action="preStopService" service="mcshield" platform="x64">"$COREPATH_X86\DAInstall.exe" -ds</Process>
<Process action="postStartService" service="mcshield">"$COREPATH\DAInstall.exe" -es</Process>
<Process action="postStartService" service="mcshield" platform="x64">"$COREPATH_X86\DAInstall.exe" -es</Process>
<Core>
<!-- Add ref count of SystemCore and VSCORE keys -->
<Registry key="HKLM\software\mcafee\SystemCore"/>
<Registry key="HKLM\software\mcafee\SystemCore\vscore"/>
<!-- ScriptScan binaries on native OS. For common files, this makes them properly ref counted -->
<FileName sha256="056fb308efcebfe1bc0bf765a8967c20f887d6388f39b4bb503bb017c8f43f0f">mytilus3.dll</FileName>
<FileName sha256="31728d12554924fab01fdc309eb25ba5dc3b815a374b82f7057c3adda4867a3a">mytilus3_worker.dll</FileName>
<FileName sha256="827ea1d047d44eb1b6459c4611b431446f23392af0ed3ffb335d6413434c8f0a">lockdown.dll</FileName>
<FileName sha256="deb46c8c2e40fb7fafc20085bee0fbf45605bd445f0544ab07fd65c9f5a33df0">scriptsn.dll</FileName>
<FileName hash="no">mcshield.dll</FileName>
<FileName platform="x86" hash="no">Strings.bin</FileName>
<FileName platform="x64" hash="no" source="$SOURCEPATH_X86">strings.bin</FileName>
<FileName platform="x86">scriptff.dll</FileName>
<FileName sha256="52046b03bdecaa81a4585424d78f5a8f528f0412771038fcb98c29423fc0c1f1">dainstall.exe</FileName>
<!-- On 64-bit platform, copy 32-bit ScriptScan binaries -->
<Directory platform="x64" location="$COREPATH_X86">
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="9b2879c860c56a2d349e08e6f159d94750f6d8e3a9dbc6286201adae8a3ab16f">mytilus3.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="cbe623c20342bfb1d1b23888dfd210625935f45d736d5c789356c15eaaf31d1e">mytilus3_worker.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" hash="no">mcshield.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" hash="no">Strings.bin</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="c1b15401b7b7fe4a5822398997433b08bac84e0a3a803a4bd934e53399337deb">lockdown.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="ea862b113c76254bb20f621eb0661526d8708ab012122d2bd3ea613ac8064ccb">scriptsn.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="b92fd588d9710a3bb0aeff221462eb00b2fbdf7ce90817a1272b81ce4e2e6dcb">scriptff.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="e2a28897c5521a33ed834767c4c3a8d07b141ac8bf07bbc6f0d9629fa914c3af">ScriptFF.gif</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="1cfaac48eacbb470a8e776cb70590747d3c571b95e029d23974b48f75889e546">ScriptFF.xul</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="434ee323afd3f68c8e4c2802b049f87c99220dda5a8ee343b6c587bb14325af7">chrome.manifest</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="506354815b5d3848bc080d2507de8c847c83866d46868efc098831925505f12a">install.rdf</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="8ed35556a2ffb92b0e158c8d943616ddf07c577572c0caa89b7d50c77e5feccb">dainstall.exe</FileName>
</Directory>
</Core>
<!-- Install/upgrade Script Scan on native platform -->
<Process wait="true" action="onInstall">"DAInstall.exe" -is "$COREPATH"</Process>
<Process wait="true" action="onUpgrade">"DAInstall.exe" -is "$COREPATH"</Process>
<!-- On 64-bit platform, Install/upgrade 32-bit ScriptScan -->
<Process wait="true" platform="x64" action="onInstall">"$SOURCEPATH_X86\DAInstall.exe" -is "$COREPATH_X86"</Process>
<Process wait="true" platform="x64" action="onUpgrade">"$SOURCEPATH_X86\DAInstall.exe" -is "$COREPATH_X86"</Process>
</Feature>
<Feature tag="ScriptScan_Unregister" GUID="{FEC6DB76-C640-449B-BAB3-617F438974AE}">
<Core></Core>
<!-- Uninstall both 32-bit and 64-bit Script Scans -->
<Process wait="true" action="onUninstall">"DAInstall.exe" -us "$COREPATH"</Process>
<Process wait="true" platform="x64" action="onUninstall">"$SOURCEPATH_X86\DAInstall.exe" -us "$COREPATH_X86"</Process>
</Feature>
<Feature tag="EmailScan" GUID="{BF75E882-D431-4D41-8B13-273589CDD430}">
<!-- Define pre-stop and pre-start commands to stop scriptscan -->
<Process action="preStopService" service="mcshield">"$COREPATH\DAInstall.exe" -de</Process>
<Process action="preStopService" service="mcshield" platform="x64">"$COREPATH_X86\DAInstall.exe" -de</Process>
<Process action="postStartService" service="mcshield">"$COREPATH\DAInstall.exe" -ee</Process>
<Process action="postStartService" service="mcshield" platform="x64">"$COREPATH_X86\DAInstall.exe" -ee</Process>
<Core>
<!-- Add ref count of SystemCore and VSCORE keys -->
<Registry key="HKLM\software\mcafee\SystemCore"/>
<Registry key="HKLM\software\mcafee\SystemCore\vscore"/>
<!-- EmailScan binaries on native OS -->
<FileName hash="no">strings.bin</FileName>
<FileName hash="no">McShield.dll</FileName>
<!-- CommonShell binaries used by EmailScan -->
<FileName sha256="056fb308efcebfe1bc0bf765a8967c20f887d6388f39b4bb503bb017c8f43f0f">mytilus3.dll</FileName>
<FileName sha256="31728d12554924fab01fdc309eb25ba5dc3b815a374b82f7057c3adda4867a3a">mytilus3_worker.dll</FileName>
<!-- On 64-bit platform, install 32-bit EmailScan files -->
<Directory platform="x64" location="$COREPATH_X86">
<FileName source="$SOURCEPATH_X86" sign_source="..\release" hash="no">mcshield.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" hash="no">strings.bin</FileName>
<!-- CommonShell binaries used by EmailScan -->
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="9b2879c860c56a2d349e08e6f159d94750f6d8e3a9dbc6286201adae8a3ab16f">mytilus3.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\release" sha256="cbe623c20342bfb1d1b23888dfd210625935f45d736d5c789356c15eaaf31d1e">mytilus3_worker.dll</FileName>
</Directory>
</Core>
<!-- Install/Uninstall of EmailScan on native platform -->
<Process wait="true" action="onInstall">"DAInstall.exe" -ie "$COREPATH"</Process>
<Process wait="true" action="onUpgrade">"DAInstall.exe" -ie "$COREPATH"</Process>
<!-- Install/Uninstall of 32-bit EmailScan on 64-bit platform -->
<Process wait="true" platform="x64" action="onInstall">"$SOURCEPATH_X86\DAInstall.exe" -ie "$COREPATH_X86"</Process>
<Process wait="true" platform="x64" action="onUpgrade">"$SOURCEPATH_X86\DAInstall.exe" -ie "$COREPATH_X86"</Process>
</Feature>
<Feature tag="EmailScan_Unregister">
<Core></Core>
<Process wait="true" action="onUninstall" platform="x64">"$SOURCEPATH_X86\DAInstall.exe" -ue "$COREPATH_X86"</Process>
<Process wait="true" action="onUninstall">"DAInstall.exe" -ue "$COREPATH"</Process>
</Feature>
<Feature tag="ELAM" GUID="{C6A18CBE-A632-4C75-AB1F-7E6ECF3E610F}">
<Driver winver="6200-">
<FileName sha256="536d041c801b506168e820896c36cc55ccaf59ac0ae330a48465c78076345c5f">mfeelamk.sys</FileName>
<Start>0</Start>
<Group>Early-Launch</Group>
</Driver>
<Core>
<FileName sha256="3af159784a6d177596c616da5225da6b9c8fad04ce9e6acfc5c182cc8e434658">mfehida.dll</FileName>
<FileName sha256="3ac4e7e637eabe1b4c15d9ded0c18672b49442c28b4487c676129277597c6eb3">mfeelama.dll</FileName>
</Core>
</Feature>
<Feature tag="OAS" GUID="{5E8D8632-9C07-432B-A71E-ABAED95E5984}">
<Core>
<Registry key="HKLM\software\mcafee\SystemCore">
<Registry key="vscore">
<Value merge="keep_existing" type="DWORD" name="ForceSuperMode" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="LockDownEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="NoRunTimeDats" data="0x00000003"/>
<Value merge="keep_existing" type="SZ" name="PreferredLanguage" data=""/>
<Registry key="NVP">
<Value merge="keep_existing" type="DWORD" name="dwModifiedByASEM" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectAdware" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectDialers" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectJokes" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectKeyLoggers" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectPasswordCrackers" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectPotentiallyUnwantedApps" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectRemoteAdminTools" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="DetectSpyware" data="0x00000001"/>
</Registry>
<Registry key="On Access Scanner">
<Value merge="keep_existing" type="DWORD" name="ArtemisEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ArtemisLevel" data="0x00000002"/>
<Registry key="McShield">
<Registry key="Configuration">
<Value merge="keep_existing" type="SZ" name="Alert_LocalMessage" data="IDS_OAS_ALERT_LOCAL"/>
<Value merge="keep_existing" type="DWORD" name="ScanProcessesOnEnable" data="0x0000000"/>
<Value merge="keep_existing" type="BINARY" name="PPContextIDs" data="01,50,00,00,02,50,00,00,03,50,00,00,00,90,00,00"/>
<Value merge="keep_existing" type="SZ" name="RepairBackupDirectory" data="C:\QUARANTINE\"/>
<Value merge="keep_existing" type="DWORD" name="RepairBackupPUPs" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="RepairBackupViruses" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="szLogFileName" data="%DEFLOGDIR%\OnAccessScanLog.txt"/>
<Value merge="keep_existing" type="DWORD" name="EOLPID" data="0x0002f4a"/>
<Value merge="keep_existing" type="DWORD" name="OnlyUseDefaultConfig" data="0x00000001"/>
<Registry key="Default">
<Value merge="keep_existing" type="DWORD" name="uSecAction" data="0x00000004"/>
<Value merge="keep_existing" type="DWORD" name="uAction" data="0x00000005"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction_Program" data="0x00000004"/>
<Value merge="keep_existing" type="DWORD" name="bNetworkScanEnabled" data="0x00000000"/>
</Registry>
<Registry key="High">
<Value merge="keep_existing" type="DWORD" name="uSecAction" data="0x00000004"/>
<Value merge="keep_existing" type="DWORD" name="bNetworkScanEnabled" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction_Program" data="0x00000004"/>
</Registry>
<Registry key="Low">
<Value merge="keep_existing" type="DWORD" name="uSecAction" data="0x00000004"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction_Program" data="0x00000004"/>
<Value merge="keep_existing" type="DWORD" name="bNetworkScanEnabled" data="0x00000000"/>
</Registry>
</Registry>
<Registry key="BehaviourBlocking">
<Value type="SZ" name="ProductID" data="VIRUSCAN8800_SANITIZE"/>
<Value merge="keep_existing" type="SZ" name="AltProductID" data="ANTISPYW8800"/>
<Value merge="keep_existing" type="DWORD" name="PVSPTEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="szLogFileName" data="%DEFLOGDIR%\AccessProtectionLog.txt"/>
<Value merge="keep_existing" type="SZ" name="szLogFileName_Ent" data="%DEFLOGDIR%\BufferOverflowProtectionLog.txt"/>
</Registry>
</Registry>
</Registry>
<Registry key="MCVSSNMP">
<Value type="SZ" name="PathName" data="$COREPATH_X86\\mcvssnmp.dll"/>
</Registry>
</Registry>
</Registry>
<FileName sha256="249e3fc3aec206a60439dc7c3bf0f2690ad1348f828c1cdc6c45eb7b2b34e932">mfeapconfig.dll</FileName>
<FileName hash="no">vscan.bof</FileName>
<FileName sha256="9549d9978dd9b508b9c9b112ee8273bccaa7c3593882af4d1074975cbb247c33">mfeann.exe</FileName>
<FileName sha256="b8eb0671bdf9ed4a838be6b4a9c5d8ef57011807a1c54fa648379cbd6f390f33">entvutil.exe</FileName>
<FileName sha256="72d506342058a95d9be5e2d0db12ed3a6eb1a3f0c7757646179b7028c01f8518">adslokuu.dll</FileName>
<FileName sha256="0ccf3df724e658a5d4eab7f124aa5c5dfe93ee3c03e72e25308b2b7e9bf8e72f">csscan.exe</FileName>
<FileName sha256="a01c57597c7a094a550ef7799e150e88e72c3015fdfbe79c6ac67a42a8d02d0f">mcvssnmp.dll</FileName>
<Directory platform="x64" location="$COREPATH_X86">
<FileName source="$SOURCEPATH_X86" sign_source="..\\release" hash="no">mcshield.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\\release" sha256="ae9c1ae4eeb9b1ffed15e0f47fc69055c3eb45206c4054c5dd1337a496f04318">naevent.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\\release" sha256="c4310df00cdeb65870064846aa2c4c73cf412798c0ab1f4fa64835961a218c9f">mfehida.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\\release" sha256="338c86479800444698538003c3db2d68795383740a3b8703972087708471f448">mfeavfa.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\\release" sha256="99ef74c8a0d3cef8bdca9edbbbe99056b7069bf89c387f4df15abc82e5bafd44">mfevtpa.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\\release" sha256="8df7bb1a09c8e6def8a4565024dfe274a5304ec65cc4484dddfc2029b0c7f998">mfeapconfig.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\\release" sha256="705a8d923963eccfc402a7eb7a61c83827ec6b26ae0e4bb61a6d1072e03a915f">ftl.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\\release" sha256="2340455ac69f27cfdc7d69a671260133c1d965dba11871fa349e6b0fac9a3e1a">csscan.exe</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\\release" sha256="c7010453b759e1a62aeaa98522b2d2531b20ccdf542670d01cc3bdc55f033023">mcvssnmp.dll</FileName>
<FileName source="$SOURCEPATH_X86" sign_source="..\\release" sha256="c1b15401b7b7fe4a5822398997433b08bac84e0a3a803a4bd934e53399337deb">lockdown.dll</FileName>
</Directory>
</Core>
</Feature>
<Feature tag="ScriptScan" GUID="{8E13DC7F-6BD9-4ED4-8362-E73FE29BD956}">
<Core>
<!-- Add ref count of SystemCore and VSCORE keys -->
<Registry key="HKLM\software\mcafee\SystemCore">
<Registry key="vscore">
<Registry key="Script Scanner">
<Value merge="keep_existing" type="DWORD" name="ApplyNVP" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bUseMcShieldEngine" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="EOLPID" data="0x00002f4a"/>
<Value merge="keep_existing" type="DWORD" name="HookMode" data="0x00000001"/>
<Value merge="keep_existing" type="BINARY" name="PPContextIDs" data="01,50,00,00,02,50,00,00,03,50,00,00,03,90,00,00"/>
<Value merge="keep_existing" type="DWORD" name="ScriptScanEnabled" data="0x00000000"/>
<Value merge="keep_existing" type="SZ" name="szInstallDir32" data="$COREPATH"/>
</Registry>
</Registry>
</Registry>
</Core>
</Feature>
<Feature tag="EmailScan" GUID="{BF75E882-D431-4D41-8B13-273589CDD430}">
<Core>
<!-- Add ref count of SystemCore and VSCORE keys -->
<Registry key="HKLM\software\mcafee\SystemCore">
<Registry key="vscore">
<Registry key="Email Scanner">
<Value merge="keep_existing" type="DWORD" name="ArtemisEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ArtemisLevel" data="0x00000002"/>
<Registry key="Outlook">
<Value merge="keep_existing" type="DWORD" name="dwHelpLevel" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="EOLPID" data="0x00002f4a"/>
<Value merge="keep_existing" type="SZ" name="szBinary32" data="OtlkUI.dll"/>
<Registry key="OnDelivery">
<Value merge="keep_existing" type="DWORD" name="dwLastModified" data="0x00000000"/>
<Value merge="keep_existing" type="SZ" name="szTaskName" data="E-mail Scan"/>
<Value merge="keep_existing" type="DWORD" name="wFlags" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="wScanExitCode" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="wTaskType" data="0x00000007"/>
<Registry key="ActionOptions">
<Value merge="keep_existing" type="DWORD" name="dwPromptButton" data="0x0000003f"/>
<Value merge="keep_existing" type="DWORD" name="dwScanAction" data="0x00000002"/>
<Value merge="keep_existing" type="SZ" name="szMoveFolder" data="Quarantine"/>
<Value merge="keep_existing" type="DWORD" name="uAction" data="0x00000005"/>
<Value merge="keep_existing" type="DWORD" name="uAction_Program" data="0x00000005"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction" data="0x00000003"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction_Program" data="0x00000003"/>
</Registry>
<Registry key="AlertOptions">
<Value merge="keep_existing" type="DWORD" name="bDisplayMessage" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bDMIAlert" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="bNetworkAlert" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="bSendMailToUser" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="bSoundAlert" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="szCustomMessage" data="IDS_EMS_ONDELIVERY_CUSTOM"/>
<Value merge="keep_existing" type="SZ" name="szNetworkAlertPath" data=""/>
<Value merge="keep_existing" type="SZ" name="szSendBody" data=""/>
<Value merge="keep_existing" type="SZ" name="szSendCc" data=""/>
<Value merge="keep_existing" type="SZ" name="szSendSubject" data=""/>
<Value merge="keep_existing" type="SZ" name="szSendTo" data=""/>
</Registry>
<Registry key="DetectionOptions">
<Value merge="keep_existing" type="DWORD" name="ApplyNVP" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bScanAllMails" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="dwMacroHeuristicsLevel" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="dwProgramHeuristicsLevel" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ExtensionMode" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="MultipleExtensionsHeuristic" data="0x00000000"/>
<Value merge="keep_existing" type="BINARY" name="PPContextIDs" data="01,50,00,00,02,50,00,00,03,50,00,00,02,90,00,00"/>
<Value merge="keep_existing" type="DWORD" name="ScanArchives" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ScanMessageBodies" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ScanMime" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="szIncludeExts" data=""/>
<Value merge="keep_existing" type="SZ" name="szProgExts" data=""/>
<Value merge="keep_existing" type="DWORD" name="UseAVPServer" data="0x00000001"/>
</Registry>
<Registry key="GeneralOptions">
<Value merge="keep_existing" type="DWORD" name="ArtemisEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ArtemisLevel" data="0x00000002"/>
<Value merge="keep_existing" type="DWORD" name="bCanBeDisabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bEnabled" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bEnabledDummy" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bMailType" data="0x00000001"/>
</Registry>
<Registry key="ReportOptions">
<Value merge="keep_existing" type="DWORD" name="bLimitSize" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bLogToFile" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="dwLogEvent" data="0x000001e0"/>
<Value merge="keep_existing" type="DWORD" name="dwMaxLogSizeMB" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="LogFileFormat" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="szLogFileName" data="%DEFLOGDIR%\EmailOnDeliveryLog.txt"/>
</Registry>
</Registry>
<Registry key="OnDemand">
<Registry key="ActionOptions">
<Value merge="keep_existing" type="DWORD" name="dwPromptButton" data="0x0000003f"/>
<Value merge="keep_existing" type="DWORD" name="dwScanAction" data="0x00000002"/>
<Value merge="keep_existing" type="SZ" name="szMoveFolder" data="Quarantine"/>
<Value merge="keep_existing" type="DWORD" name="uAction" data="0x00000005"/>
<Value merge="keep_existing" type="DWORD" name="uAction_Program" data="0x00000005"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction" data="0x00000003"/>
<Value merge="keep_existing" type="DWORD" name="uSecAction_Program" data="0x00000003"/>
</Registry>
<Registry key="AlertOptions">
<Value merge="keep_existing" type="DWORD" name="bDisplayMessage" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bDMIAlert" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="bNetworkAlert" data="0x00000000"/>
<Value merge="keep_existing" type="SZ" name="bNetworkAlertPath" data=""/>
<Value merge="keep_existing" type="DWORD" name="bSendMailToUser" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="bSoundAlert" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="szCustomMessage" data="IDS_EMS_ONDEMAND_CUSTOM"/>
<Value merge="keep_existing" type="SZ" name="szNetworkAlertPath" data=""/>
<Value merge="keep_existing" type="SZ" name="szSendBody" data=""/>
<Value merge="keep_existing" type="SZ" name="szSendCc" data=""/>
<Value merge="keep_existing" type="SZ" name="szSendSubject" data=""/>
<Value merge="keep_existing" type="SZ" name="szSendTo" data=""/>
</Registry>
<Registry key="DetectionOptions">
<Value merge="keep_existing" type="DWORD" name="ApplyNVP" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bScanAllMails" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bScanInbox" data="0x00000000"/>
<Value merge="keep_existing" type="DWORD" name="dwMacroHeuristicsLevel" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="dwProgramHeuristicsLevel" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ExtensionMode" data="0x00000001"/>
<Value merge="keep_existing" type="BINARY" name="PPContextIDs" data="01,50,00,00,02,50,00,00,03,50,00,00,02,90,00,00,01,90,00,00"/>
<Value merge="keep_existing" type="BINARY" name="PPContextIDs" data="01,50,00,00,02,50,00,00,03,50,00,00,03,90,00,00,00,90,00,00"/>
<Value merge="keep_existing" type="DWORD" name="ScanArchives" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ScanMessageBodies" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="ScanMime" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="szIncludeExts" data=""/>
<Value merge="keep_existing" type="SZ" name="szProgExts" data=""/>
<Value merge="keep_existing" type="DWORD" name="UseAVPServer" data="0x00000001"/>
</Registry>
<Registry key="GeneralOptions">
<Value merge="keep_existing" type="DWORD" name="bModified" data="0x00000001"/>
</Registry>
<Registry key="ReportOptions">
<Value merge="keep_existing" type="DWORD" name="bLimitSize" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="bLogToFile" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="dwLogEvent" data="0x000001e0"/>
<Value merge="keep_existing" type="DWORD" name="dwMaxLogSizeMB" data="0x00000001"/>
<Value merge="keep_existing" type="DWORD" name="LogFileFormat" data="0x00000001"/>
<Value merge="keep_existing" type="SZ" name="szLogFileName" data="%DEFLOGDIR%\EmailOnDemandLog.txt"/>
</Registry>
</Registry>
</Registry>
</Registry>
</Registry>
</Registry>
</Core>
</Feature>
</CoreInstall>
<Signature><SignedInfo><Reference><DigestValue sha256="c7401e278614957385f74a85de70a3d85976430074d5d497596c4611a58a1618">22164954d238228183b6eef00e49eda8</DigestValue></Reference></SignedInfo><SignatureValue><![CDATA[MIIOqwYJKoZIhvcNAQcCoIIOnDCCDpgCAQExDjAMBggqhkiG9w0CBQUAMAsGCSqGSIb3DQEHAaCCDHwwggI8MIIBpQIQcLrkHRDZKTS2OMp7A8y6vzANBgkqhkiG9w0BAQIFADBfMQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xNzA1BgNVBAsTLkNsYXNzIDMgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwHhcNOTYwMTI5MDAwMDAwWhcNMjgwODAxMjM1OTU5WjBfMQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xNzA1BgNVBAsTLkNsYXNzIDMgUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMlcWZ7yG4oBFLQQ3wRA2+NXr2pFQI+EDAvRM9nZEc/uAlgfJfcqqEQFquwDH3h/npO5mgCqI33WrIWiY0XHcifM9EzGdXHSOe9PQvB13wqQxo4gb5gP+KwjX3ApNqTJhuexmiDLU6WF5z2+fZr+JEUz3HYV7Q+icWRMZS6BaEWnAgMBAAEwDQYJKoZIhvcNAQECBQADgYEAu0wSK88sJgBPFBPdpvv8ChGEjPMoHGeSL3y2xfrf8OiVvB2PbCyoUcxz2KTAU/BO1ibAdgFXgZJeIfHRsf/n0CFYzWkX40QcnBlEOYlc3JwAD1aNApntopBFTOS7EKQ98DIDDvHO+OjJUYzmYp/mn8B9t3KcyTY6a59OqP9kDWQwggS/MIIEKKADAgECAhBBkaFaOXjfz0llZjgdTHXCMA0GCSqGSIb3DQEBBQUAMF8xCzAJBgNVBAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjE3MDUGA1UECxMuQ2xhc3MgMyBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eTAeFw0wNDA3MTYwMDAwMDBaFw0xNDA3MTUyMzU5NTlaMIG0MQswCQYDVQQGEwJVUzEXMBUGA1UEChMOVmVyaVNpZ24sIEluYy4xHzAdBgNVBAsTFlZlcmlTaWduIFRydXN0IE5ldHdvcmsxOzA5BgNVBAsTMlRlcm1zIG9mIHVzZSBhdCBodHRwczovL3d3dy52ZXJpc2lnbi5jb20vcnBhIChjKTA0MS4wLAYDVQQDEyVWZXJpU2lnbiBDbGFzcyAzIENvZGUgU2lnbmluZyAyMDA0IENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvrzuvH7vg+vgN0/7AxA4vgjSjH2d+pJ/GQzCa+5CUoze0xxIEyXqwWN6+VFl7tOqO/XwlJwr+/Jm1CTa9/Wfbhk5NrzQo3YIHiInJGw4kSfihEmuG4qh/SWCLBAw6HGrKOh3SlHx7M348FTUb8DjbQqP2dhkjWOyLU4n9oUO/m3jKZnihUd8LYZ/6FePrWfCMzKREyD8qSMUmm3ChEt2aATVcSxdIfqIDSb9Hy2RK+cBVU3ybTUogt/Za1y21tmqgf1fzYO6Y53QIvypO0Jpso46tby0ng9exOosgoso/VMIlt21ASDR+aUY58DuUXA34bYFSFJIbzjqw+hse0SEuwIDAQABo4IBoDCCAZwwEgYDVR0TAQH/BAgwBgEB/wIBADBEBgNVHSAEPTA7MDkGC2CGSAGG+EUBBxcDMCowKAYIKwYBBQUHAgEWHGh0dHBzOi8vd3d3LnZlcmlzaWduLmNvbS9ycGEwMQYDVR0fBCowKDAmoCSgIoYgaHR0cDovL2NybC52ZXJpc2lnbi5jb20vcGNhMy5jcmwwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMDMA4GA1UdDwEB/wQEAwIBBjARBglghkgBhvhCAQEEBAMCAAEwKQYDVR0RBCIwIKQeMBwxGjAYBgNVBAMTEUNsYXNzM0NBMjA0OC0xLTQzMB0GA1UdDgQWBBQI9VHo+/49PWQ2fGjPW3io37nFNzCBgAYDVR0jBHkwd6FjpGEwXzELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMTcwNQYDVQQLEy5DbGFzcyAzIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5ghBwuuQdENkpNLY4ynsDzLq/MA0GCSqGSIb3DQEBBQUAA4GBAK46F7hKe1X6ZFXsQKTtSUGQmZyJvK8uHcp4I/kcGQ9/62i8MtmION7cP9OJtD+xgpbxpFq67S4m0958AW4ACgCkBpIRSAlA+RwYeWcjJOC71eFQrhv1Dt3gLoHNgKNsUk+RdVWKuiLy0upBdYgvY1V9HlRalVnK2TSBwF9e9nq1MIIFdTCCBF2gAwIBAgIQaKXIRyRS6Y1CVIjDmBwo+DANBgkqhkiG9w0BAQUFADCBtDELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQLExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTswOQYDVQQLEzJUZXJtcyBvZiB1c2UgYXQgaHR0cHM6Ly93d3cudmVyaXNpZ24uY29tL3JwYSAoYykwNDEuMCwGA1UEAxMlVmVyaVNpZ24gQ2xhc3MgMyBDb2RlIFNpZ25pbmcgMjAwNCBDQTAeFw0xMTEwMDYwMDAwMDBaFw0xMzEyMzEyMzU5NTlaMIG0MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTEUMBIGA1UEBxMLU2FudGEgQ2xhcmExFTATBgNVBAoUDE1jQWZlZSwgSW5jLjE+MDwGA1UECxM1RGlnaXRhbCBJRCBDbGFzcyAzIC0gTWljcm9zb2Z0IFNvZnR3YXJlIFZhbGlkYXRpb24gdjIxDDAKBgNVBAsUA0lJUzEVMBMGA1UEAxQMTWNBZmVlLCBJbmMuMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmMj8Ewy+9C8BaFKq0Wz8HJhLJcj/QKAeN2gRKb18jq09Dub6ZYpeXWSBwM6BugCjwbdz8AilCjWVVPfVP5bILLHXQdwgdejiB7y5g9FWxKGnhNZyMuLKL5t5IS6OpcLl2402/cPM8HawBo/DyZXqTqsRAVcJFTGdLl15CAvj0W9EO4rRWQ6y1qiuKnOJ30OmjgqgCSjXt+gP32jd7WskPKqjpF7vrmIIyB2VRmgQJpVgUlndFrM1Brg0TTff8UlUegBfRHZsbWaH8unDF6kZOBvcn4XjnbonHfeU0rngeozo/W3dzQm3RW6A4BE3IAo6rX68D68p2SuztO15s6NVMwIDAQABo4IBfzCCAXswCQYDVR0TBAIwADAOBgNVHQ8BAf8EBAMCB4AwRAYDVR0gBD0wOzA5BgtghkgBhvhFAQcXAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy52ZXJpc2lnbi5jb20vcnBhMBMGA1UdJQQMMAoGCCsGAQUFBwMDMBEGCWCGSAGG+EIBAQQEAwIEEDAWBgorBgEEAYI3AgEbBAgwBgEBAAEB/zBABgNVHR8EOTA3MDWgM6Axhi9odHRwOi8vQ1NDMy0yMDA0LWNybC52ZXJpc2lnbi5jb20vQ1NDMy0yMDA0LmNybDB1BggrBgEFBQcBAQRpMGcwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLnZlcmlzaWduLmNvbTA/BggrBgEFBQcwAoYzaHR0cDovL0NTQzMtMjAwNC1haWEudmVyaXNpZ24uY29tL0NTQzMtMjAwNC1haWEuY2VyMB8GA1UdIwQYMBaAFAj1Uej7/j09ZDZ8aM9beKjfucU3MA0GCSqGSIb3DQEBBQUAA4IBAQC8am3DDL8ZrN+r9ixaouxCf8HIIqe2yPmK7at8vDgYEacaGvpvVAoOiUsbICBiXqPr7f7j4z9sGLepTLBqsw+FmBeVwp9BNwZr5tdmdIbj3WKrbnSKxTJqnifzxbWPTt8ayJrlLSGYcV2aV0bI29edPLkYoN8RCb441qhBZ8DV37mARwPJY3zxtV9wz0U1XD/8TZFZsNoppJzgJiCAPiU5I2cg97YQZ1nRRs/fhp7WIDlhDw6M0/pNgjNkIUss3Sz7+FyvhO5RM4GczAGldC/nZYdUXvdoIDaksRk8l2uHS5BJTwf3hK7qa9FsB0537f791PAf41kElEpzeGOzQotMMYIB9DCCAfACAQEwgckwgbQxCzAJBgNVBAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjEfMB0GA1UECxMWVmVyaVNpZ24gVHJ1c3QgTmV0d29yazE7MDkGA1UECxMyVGVybXMgb2YgdXNlIGF0IGh0dHBzOi8vd3d3LnZlcmlzaWduLmNvbS9ycGEgKGMpMDQxLjAsBgNVBAMTJVZlcmlTaWduIENsYXNzIDMgQ29kZSBTaWduaW5nIDIwMDQgQ0ECEGilyEckUumNQlSIw5gcKPgwDAYIKoZIhvcNAgUFADANBgkqhkiG9w0BAQEFAASCAQCGz+/+1GcKHIzGPFMDQ2DcBptVr5oWpf42LxM0LdP9gncEULOnDn90bNDcZglrGP+MqMf6xT9XgupiBSOGPCK69dKy1Od1hhPNZswAlCY74CpJf7lMS34uFNRrr0FtBaFWY3uJ/T+nSFmLMAwfBvOKkpMtg7Riam2s3bQWh0BUrGpjLtOvscEm8Xlbh6r3p6u4afWzlIyh2wed3fPyk9DFy5wgmV0tM93Mz4DNAV1eznkpp1Rg7zJLDwwGcypNcuxIOkcyJ9ycZnudjngX8LdVlADdzX/4h5CxuCZSVCW8P99Ijb1tvcrCr91jsncTtoacEW9/JY/C6sLQWnMk9MdS]]></SignatureValue></Signature></Package>