Key Name: SOFTWARE\Network Associates\TVD\Shared Components\On Access Scanner\McShield\Configuration
Class Name:
Last Write Time: 6/13/02 - 12:17 PM
Value 0
Name: bDenyFloppyMountIfInfected
Type: REG_DWORD
Data: 0x1

Value 1
Name: bDontScanBootSectors
Type: REG_DWORD
Data: 0

Value 2
Name: bDontScanMBRSectors
Type: REG_DWORD
Data: 0

Value 3
Name: bFileCacheEnabled
Type: REG_DWORD
Data: 0x1

Value 4
Name: bLoadAtStartup
Type: REG_DWORD
Data: 0x1

Value 5
Name: bNetworkScanEnabled
Type: REG_DWORD
Data: 0

Value 6
Name: bScanAllFiles
Type: REG_DWORD
Data: 0

Value 7
Name: bScanAllOLE
Type: REG_DWORD
Data: 0

Value 8
Name: bScanCompressed
Type: REG_DWORD
Data: 0x1

Value 9
Name: bScanDefaultFiles
Type: REG_DWORD
Data: 0x1

Value 10
Name: bScanFloppyOnShutdown
Type: REG_DWORD
Data: 0x1

Value 11
Name: bScanIncoming
Type: REG_DWORD
Data: 0x1

Value 12
Name: bScanOutgoing
Type: REG_DWORD
Data: 0x1

Value 13
Name: DisableFilterLocalScansOptimisation
Type: REG_DWORD
Data: 0x1

Value 14
Name: DisableFilterNetworkScansOptimisation
Type: REG_DWORD
Data: 0x1

Value 15
Name: DisablePLADMinusOne
Type: REG_DWORD
Data: 0x1

Value 16
Name: DisableResetLastAccessDate
Type: REG_DWORD
Data: 0x1

Value 17
Name: DontDetectJokes
Type: REG_DWORD
Data: 0

Value 18
Name: DontDetectTrojans
Type: REG_DWORD
Data: 0

Value 19
Name: DotVirOnQuarantine
Type: REG_DWORD
Data: 0

Value 20
Name: dwDebugFlags
Type: REG_DWORD
Data: 0

Value 21
Name: dwLastModified
Type: REG_DWORD
Data: 0x13

Value 22
Name: dwMacroHeuristicsLevel
Type: REG_DWORD
Data: 0

Value 23
Name: dwProgramHeuristicsLevel
Type: REG_DWORD
Data: 0

Value 24
Name: ExcludedItem_0
Type: REG_SZ
Data: \_RESTORE\||25|1

Value 25
Name: ExcludeSFPList
Type: REG_DWORD
Data: 0x1

Value 26
Name: ExtensionFilterOption
Type: REG_DWORD
Data: 0x2

Value 27
Name: NumberOfScanners
Type: REG_DWORD
Data: 0x4

Value 28
Name: NumExcludeItems
Type: REG_DWORD
Data: 0x1

Value 29
Name: ScanArchiveFindAll
Type: REG_DWORD
Data: 0

Value 30
Name: ScanArchives
Type: REG_DWORD
Data: 0

Value 31
Name: ScanArchiveTimeout
Type: REG_DWORD
Data: 0x5

Value 32
Name: ScannerThreadTimeout
Type: REG_DWORD
Data: 0x7530

Value 33
Name: SmoothWritesExtensions
Type: REG_SZ
Data: INI

Value 34
Name: SmoothWritesTime
Type: REG_DWORD
Data: 0x1

Value 35
Name: szMoveToFolder
Type: REG_SZ
Data: C:\Program Files\Network Associates\VirusScan\Infected

Value 36
Name: szProgExts
Type: REG_SZ
Data: ::: ??_ {?? 001 002 386 3GR ACM ADT AP? ASD ASP AX? BAT BIN BO? CC? CDR CHM CLA CMD CNV CO? CP? CSC D?B DAT DEV DIF DL? DO? DRV EE? EX? FMT FO? GMS GZ? HDI HLP HT? IM? IN? JS? LIB MB? MD? MHT MOD MPD MPP MPT MRC MS? OB? OC? OL? OLE OTM OV? PCI PD? PHP PIF PLG POT PP? PRC QLB QPW QTC REG RTF SCR SH? SIS SMM SYS TD0 TGZ TLB TSP VB? VS? VWP VXD WBK WIZ WP? WRI WS? X32 XL? XML XSL XTP XX? ZL?

Value 37
Name: TSDisableAll
Type: REG_DWORD
Data: 0x1

Value 38
Name: uAction
Type: REG_DWORD
Data: 0x5

Value 39
Name: UnloadDriver
Type: REG_DWORD
Data: 0

Value 40
Name: UseEngineGFS
Type: REG_DWORD
Data: 0x1

Value 41
Name: VSDenyAccessMode
Type: REG_DWORD
Data: 0x1


Sorry it's so long!!

The fix actually only makes 2 changes to the registry.

Amends the DisablePLADMinusOne from 0 to 1.

Adds a new DWord
DisableResetLastAccessDate with a setting of 1.

Thanks

Colin