X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=etc%2Frules%2Fmcafee_av_rules.xml;h=d3b2aab721b9fd0a6f1e8297a487aba85ba6c874;hp=b3b98c23bc63be5d3e13ffe58f022d7c881d7b25;hb=6ef2f786c6c8ead94841b5f93baf9f43421f08c8;hpb=301048b51990573e58a30dc4a5bb4ec285cad554 diff --git a/etc/rules/mcafee_av_rules.xml b/etc/rules/mcafee_av_rules.xml index b3b98c2..d3b2aab 100644 --- a/etc/rules/mcafee_av_rules.xml +++ b/etc/rules/mcafee_av_rules.xml @@ -1,4 +1,5 @@ - -^259|^100|^1000|^1001|^1002|^1003|^1004|^1005|^1006|^1007|^1008|^5003|^5005|^5008|^5010|^5011|^5019|^5020|^5021|^5022|^5030|^5031|^5032|^5033|^5034|^5035|^5046|^5047|^5048|^5049|^5051|^5054|^5057|^5059|^5060|^5063|^5063 -^258|^5001|^5028|^5036|^5037|^5038|^5039|^5040|^5041|^5053|^5056|^5061|^5062|^5065 -^257|^5000|^5026|^5052|^5055 +^259$|^100$|^1000$|^1001$|^1002$|^1003$|^1004$|^1005$|^1006$|^1007$|^1008$|^5003$|^5005$|^5008$|^5010$|^5011$|^5019$|^5020$|^5021$|^5022$|^5030$|^5031$|^5032$|^5033$|^5034$|^5035$|^5046$|^5047$|^5048$|^5049$|^5051$|^5054$|^5057$|^5059$|^5060$|^5063$|^5063$ +^258$|^5001$|^5028$|^5036$|^5037$|^5038$|^5039$|^5040$|^5041$|^5053$|^5056$|^5061$|^5062$|^5065$ +^257$|^5000$|^5026$|^5052$|^5055$ quarantined|moved to quarantine|file was deleted|deleted successfully|has been deleted|message deleted|deleted after|cleaned|successfully deleted The file \.+ contain|infected with|User defined detection|scan found|error attempting to clean 10 @@ -76,7 +77,7 @@ McAfee Windows AV - Scan completed with no viruses found. - + 7500 scan was cancelled |has taken too long McAfee Windows AV - Virus scan cancelled.