Server : Apache/2.4.43 (Win64) OpenSSL/1.1.1g PHP/7.4.6 System : Windows NT USER-PC 6.1 build 7601 (Windows 7 Professional Edition Service Pack 1) AMD64 User : User ( 0) PHP Version : 7.4.6 Disable Function : NONE Directory : C:/Users/User/AppData/Local/Temp/HouseCall32/ |
<?xml version="1.0" encoding="utf-8"?> <LinkRule> <Rules> <Rule> <Type>ATTK</Type> <Platform>all</Platform> <Report>scanreport.xml</Report> <Condition>/Scan/Entries/Entry[child::DetectionSrc[text()='DeviceStack']][child::Detection[text()='Kernel Code Patch']]</Condition> <LinkID>InstToolRD</LinkID> </Rule> <Rule> <Type>ATTK</Type> <Platform>all</Platform> <Report>scanreport.xml</Report> <Condition>/Scan/Entries/Entry[child::DetectionSrc[text()='DeviceStack']][child::Detection[text()='Kernel Code Patch']]</Condition> <LinkID>InstToolCB</LinkID> </Rule> <Rule> <Type>ATTK</Type> <Platform>x86</Platform> <Report>scanreport.xml</Report> <Condition>/Scan/Entries/Entry/DetectionSrc[text()='ZeroAccess']</Condition> <LinkID>InstToolRB</LinkID> </Rule> <Rule> <Type>ATTK</Type> <Platform>x64</Platform> <Report>scanreport.xml</Report> <Condition>/Scan/Entries/Entry/DetectionSrc[text()='ZeroAccess']</Condition> <LinkID>InstToolRD</LinkID> </Rule> <Rule> <Type>ATTK</Type> <Platform>x64</Platform> <Report>scanreport.xml</Report> <Condition>/Scan/Entries/Entry/DetectionSrc[text()='ZeroAccess']</Condition> <LinkID>InstToolCB</LinkID> </Rule> <Rule> <Type>ATTK</Type> <Platform>all</Platform> <Report>scanreport.xml</Report> <Condition>/Scan/Entries/Entry/Path[text()='Boot Sector']</Condition> <LinkID>InstToolCB</LinkID> </Rule> <Rule> <Type>ATTK</Type> <Platform>all</Platform> <Report>scanreport.xml</Report> <Condition>/Scan/Entries/Entry/DetectionSrc[text()='ParasitizedMBR']</Condition> <LinkID>InstToolCB</LinkID> </Rule> <Rule> <Type>ATTK</Type> <Platform>all</Platform> <Report>scanreport.xml</Report> <Condition>/Scan/Entries/Entry[child::DetectionSrc[text()='AtrtClient']]</Condition> <LinkID>InstToolRD</LinkID> </Rule> <Rule> <Type>ATTK</Type> <Platform>all</Platform> <Report>scanreport.xml</Report> <Condition>/Scan/Entries/Entry[child::DetectionSrc[text()='AtrtClient']]</Condition> <LinkID>InstToolCB</LinkID> </Rule> <Rule> <Type>ATTK</Type> <Platform>all</Platform> <Report>scanreport.xml</Report> <Condition>/Scan/Entries/Entry[child::DetectionSrc[text()='LockedServiceCleaner']][child::ActionResult[text()='Fail']]</Condition> <LinkID>InstToolCB</LinkID> </Rule> </Rules> </LinkRule>