False positive in still disabled rule

This commit is contained in:
Florian Roth 2017-08-05 14:53:59 +02:00
parent 44deee38c3
commit 06b5ea1891

View File

@ -2152,7 +2152,7 @@ ystem32\\lcsvsvc\.dll;80
#\\hkcmd\.exe;60;(?i)\\(System32|system32|SYSTEM32|winsxs|WinSxS|SysWOW64|SysWow64|syswow64|SYSNATIVE)\\
#(?i)\\Mc\.exe;60;(?i)\\([Mm]icrosoft [Vv]isual [Ss]tudio|Windows Kits|Microsoft SDK|microsoft sdk)
#(?i)\\MsMpEng\.exe;60;(?i)\\(Microsoft Security Client|Windows Defender|AntiMalware)
#(?i)\\msseces\.exe;60;(?i)\\Microsoft Security Center\\
#(?i)\\msseces\.exe;60;(?i)\\(Microsoft Security Center|Microsoft Security Client)\\
#(?i)\\OInfoP11\.exe;60;(?i)(\\Common Files\\Microsoft Shared\\|\\Installer\\)
#(?i)\\OleView\.exe;60;(?i)\\(Microsoft SDK|Windows Kits|[Mm]icrosoft [Vv]isual [Ss]tudio|Windows Resource Kit)
#(?i)\\rc\.exe;60;(?i)\\(Microsoft SDK|Windows Kits|[Mm]icrosoft [Vv]isual [Ss]tudio|Windows Resocue Kit|[Mm]icrosoft.[Nn][Ee][Tt])