Автор: ogamy
Дата сообщения: 16.04.2009 23:45
Два. Один сканировать, второй параметры
Добавлено:
NAGRIS
Что-нибудь типа такого есть в реестре?
[more=Читать дальше..]
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EB32536CA971B524097913C1F086B3D6]
"30ECB7411F0CF9C41875A6986B2D9D37"="C:\\Program Files (x86)\\McAfee\\VirusScan Enterprise\\OtlkScan.dll"
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner]
"ArtemisEnabled"=dword:00000001
"ArtemisLevel"=dword:00000004
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook]
"EOLPID"=dword:00002f14
"dwHelpLevel"=dword:00000001
"szBinary32"="OtlkUI.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDelivery]
"szTaskName"="E-mail Scan"
"dwLastModified"=dword:00000028
"wTaskType"=dword:00000007
"wFlags"=dword:00000000
"wScanEixtCode"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\ActionOptions]
"szMoveFolder"="Quarantine"
"dwPromptButton"=dword:0000003f
"uAction_Program"=dword:00000005
"dwScanAction"=dword:00000002
"uSecAction"=dword:00000003
"uSecAction_Program"=dword:00000003
"uAction"=dword:00000005
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\AlertOptions]
"szSendSubject"="Failure Delivery"
"bNetworkAlert"=dword:00000000
"szSendTo"="[@]"
"szCustomMessage"="IDS_EMS_ONDELIVERY_CUSTOM"
"bDisplayMessage"=dword:00000001
"bSendMailToUser"=dword:00000001
"szNetworkAlertPath"=""
"bSoundAlert"=dword:00000001
"bDMIAlert"=dword:00000000
"szSendCc"=""
"szSendBody"="Unable to deliver message to the following address(es) [@]
Remote host said: 554 delivery error: This user doesn't have an
account and you send VIRUS!
--- Original message follows.
[#]"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\DetectionOptions]
"PPContextIDs"=hex:01,50,00,00,02,50,00,00,03,50,00,00
"dwMacroHeuristicsLevel"=dword:00000001
"ApplyNVP"=dword:00000001
"szProgExts"=""
"ExtensionMode"=dword:00000001
"ScanMime"=dword:00000001
"ScanMessageBodies"=dword:00000001
"bScanCompressed"=dword:00000001
"UseAVPServer"=dword:00000001
"szIncludeExts"=""
"ScanArchives"=dword:00000001
"dwProgramHeuristicsLevel"=dword:00000001
"MultipleExtensionsHeuristic"=dword:00000000
"bScanAllMails"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\GeneralOptions]
"bMailType"=dword:00000001
"bCanBeDisabled"=dword:00000001
"bEnabledDummy"=dword:00000001
"bEnabled"=dword:00000001
"NOTES_szNotesAppsToExclude"="MNOTES"
"NOTES_OAScanServerDataBases"=dword:00000000
"NOTES_OAScanServerMail"=dword:00000001
"NOTES_ServerMailFolder"="!!mail\\"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\ReportOptions]
"dwMaxLogSizeMB"=dword:00000001
"dwLogEvent"=dword:00000120
"bLogToFile"=dword:00000001
"LogFileFormat"=dword:00000001
"szLogFileName"=hex(2):25,44,45,46,4c,4f,47,44,49,52,25,5c,45,6d,61,69,6c,4f,\
6e,44,65,6c,69,76,65,72,79,4c,6f,67,2e,74,78,74,00
"bLimitSize"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDemand]
"szInstallDateTime"="2008-12-9T5:7:52"
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDemand\ActionOptions]
"dwPromptButton"=dword:0000003f
"szMoveFolder"="Quarantine"
"uSecAction"=dword:00000003
"uAction_Program"=dword:00000005
"uSecAction_Program"=dword:00000003
"dwScanAction"=dword:00000002
"uAction"=dword:00000005
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDemand\AlertOptions]
"bSendMailToUser"=dword:00000000
"szSendTo"=""
"bDisplayMessage"=dword:00000001
"bSoundAlert"=dword:00000001
"szSendCc"=""
"szCustomMessage"="IDS_EMS_ONDEMAND_CUSTOM"
"szSendBody"=""
"szNetworkAlertPath"=""
"bNetworkAlertPath"=""
"bNetworkAlert"=dword:00000000
"szSendSubject"=""
"bDMIAlert"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDemand\DetectionOptions]
"ApplyNVP"=dword:00000001
"szIncludeExts"=""
"bScanAllMails"=dword:00000001
"UseAVPServer"=dword:00000001
"szProgExts"=""
"bScanCompressed"=dword:00000001
"dwProgramHeuristicsLevel"=dword:00000001
"ScanMime"=dword:00000001
"bScanInbox"=dword:00000000
"ScanMessageBodies"=dword:00000001
"PPContextIDs"=hex:01,50,00,00,02,50,00,00,03,50,00,00
"dwMacroHeuristicsLevel"=dword:00000001
"ScanArchives"=dword:00000001
"ExtensionMode"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDemand\GeneralOptions]
"bModified"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\VSCore\Email Scanner\Outlook\OnDemand\ReportOptions]
"bLogToFile"=dword:00000001
"dwLogEvent"=dword:000001e0
"bLimitSize"=dword:00000001
"LogFileFormat"=dword:00000001
"szLogFileName"="%DEFLOGDIR%\\EmailOnDemandLog.txt"
"dwMaxLogSizeMB"=dword:00000001
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook]
"EOLPID"=dword:00002f14
"dwHelpLevel"=dword:00000001
"szBinary32"="OtlkUI.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDelivery]
"szTaskName"="E-mail Scan"
"dwLastModified"=dword:00000028
"wTaskType"=dword:00000007
"wFlags"=dword:00000000
"wScanEixtCode"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\ActionOptions]
"szMoveFolder"="Quarantine"
"dwPromptButton"=dword:0000003f
"uAction_Program"=dword:00000005
"dwScanAction"=dword:00000002
"uSecAction"=dword:00000003
"uSecAction_Program"=dword:00000003
"uAction"=dword:00000005
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\AlertOptions]
"szSendSubject"="Failure Delivery"
"bNetworkAlert"=dword:00000000
"szSendTo"="[@]"
"szCustomMessage"="IDS_EMS_ONDELIVERY_CUSTOM"
"bDisplayMessage"=dword:00000001
"bSendMailToUser"=dword:00000001
"szNetworkAlertPath"=""
"bSoundAlert"=dword:00000001
"bDMIAlert"=dword:00000000
"szSendCc"=""
"szSendBody"="Unable to deliver message to the following address(es) [@]
Remote host said: 554 delivery error: This user doesn't have an
account and you send VIRUS!
--- Original message follows.
[#]"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\DetectionOptions]
"PPContextIDs"=hex:01,50,00,00,02,50,00,00,03,50,00,00
"dwMacroHeuristicsLevel"=dword:00000001
"ApplyNVP"=dword:00000001
"szProgExts"=""
"ExtensionMode"=dword:00000001
"ScanMime"=dword:00000001
"ScanMessageBodies"=dword:00000001
"bScanCompressed"=dword:00000001
"UseAVPServer"=dword:00000001
"szIncludeExts"=""
"ScanArchives"=dword:00000001
"dwProgramHeuristicsLevel"=dword:00000001
"MultipleExtensionsHeuristic"=dword:00000000
"bScanAllMails"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\GeneralOptions]
"bMailType"=dword:00000001
"bCanBeDisabled"=dword:00000001
"bEnabledDummy"=dword:00000001
"bEnabled"=dword:00000001
"NOTES_szNotesAppsToExclude"="MNOTES"
"NOTES_OAScanServerDataBases"=dword:00000000
"NOTES_OAScanServerMail"=dword:00000001
"NOTES_ServerMailFolder"="!!mail\\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDelivery\ReportOptions]
"dwMaxLogSizeMB"=dword:00000001
"dwLogEvent"=dword:00000120
"bLogToFile"=dword:00000001
"LogFileFormat"=dword:00000001
"szLogFileName"=hex(2):25,44,45,46,4c,4f,47,44,49,52,25,5c,45,6d,61,69,6c,4f,\
6e,44,65,6c,69,76,65,72,79,4c,6f,67,2e,74,78,74,00
"bLimitSize"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDemand]
"szInstallDateTime"="2008-12-9T5:7:52"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDemand\ActionOptions]
"dwPromptButton"=dword:0000003f
"szMoveFolder"="Quarantine"
"uSecAction"=dword:00000003
"uAction_Program"=dword:00000005
"uSecAction_Program"=dword:00000003
"dwScanAction"=dword:00000002
"uAction"=dword:00000005
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDemand\AlertOptions]
"bSendMailToUser"=dword:00000000
"szSendTo"=""
"bDisplayMessage"=dword:00000001
"bSoundAlert"=dword:00000001
"szSendCc"=""
"szCustomMessage"="IDS_EMS_ONDEMAND_CUSTOM"
"szSendBody"=""
"szNetworkAlertPath"=""
"bNetworkAlertPath"=""
"bNetworkAlert"=dword:00000000
"szSendSubject"=""
"bDMIAlert"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDemand\DetectionOptions]
"ApplyNVP"=dword:00000001
"szIncludeExts"=""
"bScanAllMails"=dword:00000001
"UseAVPServer"=dword:00000001
"szProgExts"=""
"bScanCompressed"=dword:00000001
"dwProgramHeuristicsLevel"=dword:00000001
"ScanMime"=dword:00000001
"bScanInbox"=dword:00000000
"ScanMessageBodies"=dword:00000001
"PPContextIDs"=hex:01,50,00,00,02,50,00,00,03,50,00,00
"dwMacroHeuristicsLevel"=dword:00000001
"ScanArchives"=dword:00000001
"ExtensionMode"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDemand\GeneralOptions]
"bModified"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\McAfee\VSCore\Email Scanner\Outlook\OnDemand\ReportOptions]
"bLogToFile"=dword:00000001
"dwLogEvent"=dword:000001e0
"bLimitSize"=dword:00000001
"LogFileFormat"=dword:00000001
"szLogFileName"="%DEFLOGDIR%\\EmailOnDemandLog.txt"
"dwMaxLogSizeMB"=dword:00000001
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\76C4E7801137A064183A00FBA07ADC85]
"30ECB7411F0CF9C41875A6986B2D9D37"="C:\\Program Files (x86)\\McAfee\\VirusScan Enterprise\\OtlkUI.dll"
[/more]
Поищи по этим файлам OtlkScan.dll OtlkUI.dll