home *** CD-ROM | disk | FTP | other *** search
- <?xml version="1.0"?>
- <PRULES>
- <PRULE>
- <RULE>
- <NAME>The file contains suspicous characteristics in its structure </NAME>
- <Desc>Rule_Fake_Entry_Point </Desc>
- <ID>0</ID>
- </RULE>
- <RISK>80</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>The file contains suspicous characteristics in its structure </NAME>
- <Desc> Rule_Writable_Sections</Desc>
- <ID>1</ID>
- </RULE>
- <RISK>40</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE>
- </PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>The file contains suspicous characteristics in its structure </NAME>
- <Desc> Too many Rule_Executable_Sections</Desc>
- <ID>2</ID>
- </RULE>
- <RISK>60</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE>
- </PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>The file contains suspicous characteristics in its structure </NAME>
- <Desc>diffrences between virtual ans phisical sizes of sections</Desc>
- <ID>3</ID>
- </RULE>
- <RISK>60</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE>
- </PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>The file might be encrypted </NAME>
- <ID>4</ID>
- </RULE>
- <RULE>
- <NAME></NAME>
- <ID>5</ID>
- <VALUE>0</VALUE>
- </RULE>
- <RISK>60</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>The file is compressed/encrypted by known engine </NAME>
- <ID>5</ID>
- </RULE>
- <RISK>40</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>The file contains suspicious code flow</NAME>
- <ID>6</ID>
- </RULE>
- <RISK>40</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>The file might casue itself or other program to run after windows restart</NAME>
- <ID>7</ID>
- </RULE>
- <RISK>70</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>40</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>20</VALUE></PRULEFACTOR>
- </PRULEFACTORS></PRULE>
- <PRULE>
- <RULE>
- <NAME>The file might manipulate Anti Virus programs</NAME>
- <ID>8</ID>
- </RULE>
- <RISK>50</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>The file might try to use Internet Explorer </NAME>
- <DESC> Sequence of bytes of internet explorer clsid were detected</DESC>
- <ID>9</ID>
- </RULE>
- <RULE>
- <NAME></NAME>
- <DESC> COM_FUNCTIONS are used in the code</DESC>
- <ID>13</ID>
- </RULE>
- <RISK>0</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>Anti Debug functions or libraries were detected in code</NAME>
- <ID>10</ID>
- </RULE>
- <RISK>15</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>The file is encrypted </NAME>
- <Desc> There are no refernces to the IAT functions in the code (probably due to encryption) </Desc>
- <ID>11</ID>
- </RULE>
- <RISK>50</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE>
- </PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>The file is using VB Runtime</NAME>
- <ID>12</ID>
- </RULE>
- <RISK>0</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>0</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>0</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>0</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>0</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>0</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE>
- <NAME>The file does not contain any information on the file creator </NAME><VALUE>0</VALUE>
- <ID>17</ID>
- </RULE>
- <RULE>
- <NAME> And the file extension indicate a win32 executable file </NAME>
- <ID>35</ID>
- </RULE>
- <RISK>20</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>50</VALUE> </PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file extension indicating a screen saver</NAME>
- <ID>14</ID>
- </RULE>
- <RULE><NAME> And The file is not using the graphic library</NAME><VALUE>0</VALUE>
- <ID>32</ID>
- </RULE>
- <RISK>80</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file is using only basic functions (No User interface)</NAME>
- <ID>33</ID>
- <VALUE>0</VALUE>
- </RULE>
- <RULE><NAME> And The file is not library file</NAME>
- <ID>48</ID>
- <VALUE>0</VALUE>
- </RULE>
-
- <RISK>50</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file includes hiding 'crashes' functions </NAME>
- <ID>34</ID>
- </RULE>
- <RULE><NAME> And The file does not contain normal Windows functions</NAME>
- <ID>28</ID>
- <VALUE>0</VALUE>
- </RULE>
- <RULE><NAME> And The file does not contain Display functions</NAME>
- <ID>29</ID>
- <VALUE>0</VALUE>
- </RULE>
- <RULE><NAME> And The file is not library file</NAME>
- <ID>48</ID>
- <VALUE>0</VALUE>
- </RULE>
- <RISK>40</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>30</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
-
- <PRULE>
- <RULE><NAME>The file contains functions for changing or creating files</NAME>
- <ID>-19</ID>
- </RULE>
- <RULE><NAME> And The file does not contain normal Windows functions</NAME>
- <ID>28</ID>
- <VALUE>0</VALUE>
- </RULE>
- <RULE><NAME> And The file does not contain Display functions</NAME>
- <ID>29</ID>
- <VALUE>0</VALUE>
- </RULE>
- <RULE><NAME> And The file is not library file</NAME>
- <ID>48</ID>
- <VALUE>0</VALUE>
- </RULE>
-
- <RISK>40</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>30</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file contains functions for changing or creating files</NAME>
- <ID>-19</ID>
- </RULE>
- <RULE><NAME> And The file might manipulate outlook express files</NAME>
- <ID>40</ID>
- </RULE>
- <RISK>40</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>30</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file contains functions for changing or creating files</NAME>
- <ID>-19</ID>
- </RULE>
- <RISK>20</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>50</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>30</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file includes functions for accessing email</NAME>
- <ID>38</ID>
- </RULE>
- <RISK>50</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>40</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file includes functions for accessing email</NAME>
- <ID>37</ID>
- </RULE>
- <RISK>40</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>40</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file includes identifiers of objects for accessing email</NAME>
- <ID>36</ID>
- </RULE>
- <RISK>40</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>40</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file includes evidence indicating possible access to address book</NAME>
- <ID>39</ID>
- </RULE>
- <RISK>40</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>40</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME> The file includes data related to internet accounts information(email,web)</NAME>
- <ID>41</ID>
- </RULE>
- <RISK>40</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>40</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file contains network functions</NAME>
- <ID>25</ID>
- </RULE>
- <RISK>30</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>40</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file contains functions for accessing and changing the registry </NAME>
- <ID>-21</ID>
- </RULE>
- <RISK>30</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>40</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file contains functions for mapping others files to memory </NAME>
- <ID>42</ID>
- </RULE>
- <RISK>30</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>60</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>40</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file has suspicous rate between malicious and innocent functions</NAME>
- <ID>43</ID>
- </RULE>
- <RISK>40</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>90</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>90</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>90</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file contains internet addresses data</NAME>
- <ID>44</ID>
- </RULE>
- <RISK>30</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>90</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>90</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>90</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>70</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME></NAME>
- <ID>16</ID>
- </RULE>
- <RISK>-50</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>40</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>80</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME></NAME>
- <ID>16</ID>
- </RULE>
- <RULE><NAME></NAME>
- <ID>45</ID>
- </RULE>
- <RISK>-4000</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file is very similar to a known malicious application</NAME>
- <ID>46</ID>
-
- </RULE>
- <RISK>0</RISK>
- <TOTALRISK>95</TOTALRISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file is very similar to a known application</NAME>
- <ID>47</ID>
- </RULE>
- <RISK>0</RISK>
- <TOTALRISK>10</TOTALRISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
- <RULE><NAME>The file is an antivirus test file</NAME>
- <ID>49</ID>
- </RULE>
- <RISK>0</RISK>
- <TOTALRISK>0</TOTALRISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- <PRULE>
-
- <RULE><NAME>The file is a library file</NAME>
- <ID>48</ID>
- </RULE>
- <RISK>-900</RISK>
- <PRULEFACTORS>
- <PRULEFACTOR><CONTEXT>MAIL</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>WEB</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>LOCAL_NETWORK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>FLOPPY_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- <PRULEFACTOR><CONTEXT>CD_DISK</CONTEXT><VALUE>100</VALUE></PRULEFACTOR>
- </PRULEFACTORS>
- </PRULE>
- </PRULES>
-