From 676b75efeda3bc531c9f4e13c7701562cae506c2 Mon Sep 17 00:00:00 2001 From: Elwali karkoub Date: Thu, 21 Mar 2019 14:42:14 +0100 Subject: [PATCH 1/7] Create 0585-VIPRE_rules.xml --- rules/0585-VIPRE_rules.xml | 554 +++++++++++++++++++++++++++++++++++++ 1 file changed, 554 insertions(+) create mode 100644 rules/0585-VIPRE_rules.xml diff --git a/rules/0585-VIPRE_rules.xml b/rules/0585-VIPRE_rules.xml new file mode 100644 index 000000000..b39d52235 --- /dev/null +++ b/rules/0585-VIPRE_rules.xml @@ -0,0 +1,554 @@ + + + + + + + 18101 + ^4097$ + VIPRE : System shutdown complete + no_full_log + + + + + 18101 + ^4098$ + VIPRE : User initiated shutdown + no_full_log + + + + 18101 + ^4099$ + VIPRE : Service started Application version + no_full_log + + + + + 18101 + ^4100$ + VIPRE : Service paused + no_full_log + + + + + 18101 + ^4101$ + VIPRE : Service resumed + no_full_log + + + + + 18101 + ^4102$ + ThreatNet : The transfer of one or more ThreatNet files failed + no_full_log + + + + 18101 + ^4103$ + ThreatNet Transfer occured + no_full_log + + + + + 18101 + ^4104$ + The start of the ThreatNet controller failed + no_full_log + + + + + + 18101 + ^4105$ + VIPRE : Active Protection enabled + no_full_log + + + + + 18101 + ^4106$ + VIPRE : Active Protection disabled + no_full_log + + + + 18101 + ^4108$ + VIPRE : Active protection could not be enabled + no_full_log + + + + + 18101 + ^4109$ + VIPRE : Active Protection could not be disabled + no_full_log + + + + + 18101 + ^4110$ + VIPRE : Active Protection requires a reboot to fully protect your computer + no_full_log + + + + + 18101 + ^4111$ + VIPRE : Active Protection could not be enabled because there are no threat definitions + no_full_log + + + + 18101 + ^4112$ + VIPRE : Manual software update downloaded + no_full_log + + + + + 18101 + ^4113$ + VIPRE : Scheduled software update downloaded + no_full_log + + + + + 18101 + ^4114$ + VIPRE was unable to complete the check for software updates + no_full_log + + + + + + 18101 + ^4115$ + VIPRE was unable to complete the check for software updates. It will retry on the next update event. + no_full_log + + + + + + 18101 + ^4116$ + VIPRE : The start of the software update controller failed + no_full_log + + + + + 18101 + ^4121$ + VIPRE : Definitions update applied + no_full_log + + + + + 18101 + ^4122$ + VIPRE : Definitions update cancelled + no_full_log + + + + + + 18101 + ^4123$ + VIPRE was unable to complete the check for threat definitions updates + no_full_log + + + + + 18101 + ^4124$ + VIPRE was unable to complete the check for threat definitions updates. It will retry on the next update event + no_full_log + + + + + + 18101 + ^4125$ + VIPRE : Start of threat definitions controller failed + no_full_log + + + + + 18101 + ^4126$ + VIPRE : Cannot update threat definitions because your registration is expired + no_full_log + + + + + 18101 + ^4129$ + VIPRE : Completed scheduled deep scan + no_full_log + + + + + 18101 + ^4130$ + VIPRE : Completed manual deep scan + no_full_log + + + + + + 18101 + ^4131$ + VIPRE : Completed scheduled quick scan + no_full_log + + + + + 18101 + ^4132$ + VIPRE : Completed manual quick scan + no_full_log + + + + + 18101 + ^4133$ + VIPRE : Completed scheduled custom scan + no_full_log + + + + + 18101 + ^4134$ + VIPRE : Completed manual custom scan + no_full_log + + + + + + + 18101 + ^4135$ + VIPRE : Scan cancelled + no_full_log + + + + + 18101 + ^4136$ + VIPRE : Reboot required + no_full_log + + + + + 18101 + ^4137$ + VIPRE : A scan of your computer failed because there are no threat definitions + no_full_log + + + + + 18101 + ^4138$ + VIPRE : Start of the scan controller failed + no_full_log + + + + + 18101 + ^4139$ + VIPRE : An item has been quarantined + no_full_log + + + + + 18101 + ^4140$ + VIPRE : An item has been restored from quarantine + no_full_log + + + + + 18101 + ^4141$ + VIPRE : An item has been deleted from quarantine + no_full_log + + + + + 18101 + ^4142$ + VIPRE : The quarantne has been purged + no_full_log + + + + + 18101 + ^4143$ + VIPRE : The quarantne controller could not be started + no_full_log + + + + + 18101 + ^4145$ + VIPRE : Email AV enabled + no_full_log + + + + + 18101 + ^4146$ + VIPRE : Email AV disabled + no_full_log + + + + + 18101 + ^4147$ + VIPRE : Email protection is enabled but the drivers are not loaded + no_full_log + + + + + 18101 + ^4148$ + VIPRE : The scan of an email item failed + no_full_log + + + + + 18101 + ^4149$ + VIPRE : The Scan of an email item failed because there are no threat definitions + no_full_log + + + + + 18101 + ^4250$ + VIPRE : Registration state changed + no_full_log + + + + + 18101 + ^4151$ + VIPRE : The registration controller could not be started + no_full_log + + + + + 18101 + ^4153$ + VIPRE : The scan control could not complete its scan + no_full_log + + + + + 18101 + ^4159$ + VIPRE : A scheduled scan was missed because the machine was powered off + no_full_log + + + + + + 18101 + ^4160$ + VIPRE : Quarantine of an item failed + no_full_log + + + + + + 18101 + ^4161$ + VIPRE : Restore of an item from quarantine failed + no_full_log + + + + + + 18101 + ^4162$ + VIPRE : Delete of an from quarantine failed + no_full_log + + + + + 18101 + ^4163$ + VIPRE : The quarantine purge failed + no_full_log + + + + + 18101 + ^4165$ + VIPRE : Firewall enabled + no_full_log + + + + + + 18101 + ^4166$ + VIPRE : Firewall disabled + no_full_log + + + + + + 18101 + ^4167$ + VIPRE : IDS enabled + no_full_log + + + + + + 18101 + ^4168$ + VIPRE : IDS disabled + no_full_log + + + + + + 18101 + ^4169$ + VIPRE : Web Filtering enabled + no_full_log + + + + + + 18101 + ^4170$ + VIPRE : Web Filtering disabled + no_full_log + + + + + + 18101 + ^4171$ + VIPRE : Bad Web Site Blocking enabled + no_full_log + + + + + + 18101 + ^4172$ + VIPRE : Bad Web Site Blocking disabled + no_full_log + + + + + 18101 + ^4173$ + VIPRE : HIPS enabled + no_full_log + + + + + 18101 + ^4174$ + VIPRE : HIPS disabled + no_full_log + + + + + + 18101 + ^4175$ + VIPRE : Firewall Resume All Traffic + no_full_log + + + + 18101 + ^4176$ + VIPRE : Firewall Stops All Traffic + no_full_log + + + + + 18101 + ^4177$ + VIPRE : Active protection blocked a process from accessing a file + no_full_log + + + + + From 2f03924253e0f04598bb84e5d969b4b9fabcdcd0 Mon Sep 17 00:00:00 2001 From: Elwali karkoub Date: Mon, 26 Aug 2019 21:12:21 +0200 Subject: [PATCH 2/7] Update 0585-VIPRE_rules.xml --- rules/0585-VIPRE_rules.xml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/rules/0585-VIPRE_rules.xml b/rules/0585-VIPRE_rules.xml index b39d52235..9fe32ba8a 100644 --- a/rules/0585-VIPRE_rules.xml +++ b/rules/0585-VIPRE_rules.xml @@ -8,6 +8,13 @@ + + 18101 + SBAMSvc + VIPRE Informational message + no_full_log + + 18101 ^4097$ From 8153927ffeab740c5c8951acca49bad921fbc47b Mon Sep 17 00:00:00 2001 From: Elwali karkoub Date: Tue, 27 Aug 2019 17:37:55 +0200 Subject: [PATCH 3/7] Update and rename 0585-VIPRE_rules.xml to 0585-vipre_rules.xml --- ...5-VIPRE_rules.xml => 0585-vipre_rules.xml} | 140 +++++++++--------- 1 file changed, 69 insertions(+), 71 deletions(-) rename rules/{0585-VIPRE_rules.xml => 0585-vipre_rules.xml} (62%) diff --git a/rules/0585-VIPRE_rules.xml b/rules/0585-vipre_rules.xml similarity index 62% rename from rules/0585-VIPRE_rules.xml rename to rules/0585-vipre_rules.xml index 9fe32ba8a..ef7487548 100644 --- a/rules/0585-VIPRE_rules.xml +++ b/rules/0585-vipre_rules.xml @@ -6,19 +6,19 @@ --> - + 18101 SBAMSvc - VIPRE Informational message + VIPRE Informational message no_full_log 18101 ^4097$ - VIPRE : System shutdown complete + System shutdown complete no_full_log @@ -26,14 +26,14 @@ 18101 ^4098$ - VIPRE : User initiated shutdown + User initiated shutdown no_full_log 18101 ^4099$ - VIPRE : Service started Application version + Service started Application version no_full_log @@ -41,7 +41,7 @@ 18101 ^4100$ - VIPRE : Service paused + Service paused no_full_log @@ -49,7 +49,7 @@ 18101 ^4101$ - VIPRE : Service resumed + Service resumed no_full_log @@ -57,14 +57,14 @@ 18101 ^4102$ - ThreatNet : The transfer of one or more ThreatNet files failed + The transfer of one or more ThreatNet files failed no_full_log 18101 ^4103$ - ThreatNet Transfer occured + Transfer occured no_full_log @@ -72,7 +72,7 @@ 18101 ^4104$ - The start of the ThreatNet controller failed + The start of the ThreatNet controller failed no_full_log @@ -81,7 +81,7 @@ 18101 ^4105$ - VIPRE : Active Protection enabled + Active Protection enabled no_full_log @@ -89,14 +89,14 @@ 18101 ^4106$ - VIPRE : Active Protection disabled + Active Protection disabled no_full_log 18101 ^4108$ - VIPRE : Active protection could not be enabled + Active protection could not be enabled no_full_log @@ -104,7 +104,7 @@ 18101 ^4109$ - VIPRE : Active Protection could not be disabled + Active Protection could not be disabled no_full_log @@ -112,7 +112,7 @@ 18101 ^4110$ - VIPRE : Active Protection requires a reboot to fully protect your computer + Active Protection requires a reboot to fully protect your computer no_full_log @@ -120,14 +120,14 @@ 18101 ^4111$ - VIPRE : Active Protection could not be enabled because there are no threat definitions + Active Protection could not be enabled because there are no threat definitions no_full_log 18101 ^4112$ - VIPRE : Manual software update downloaded + Manual software update downloaded no_full_log @@ -135,7 +135,7 @@ 18101 ^4113$ - VIPRE : Scheduled software update downloaded + Scheduled software update downloaded no_full_log @@ -143,7 +143,7 @@ 18101 ^4114$ - VIPRE was unable to complete the check for software updates + VIPRE was unable to complete the check for software updates no_full_log @@ -152,7 +152,7 @@ 18101 ^4115$ - VIPRE was unable to complete the check for software updates. It will retry on the next update event. + VIPRE was unable to complete the check for software updates. It will retry on the next update event no_full_log @@ -161,7 +161,7 @@ 18101 ^4116$ - VIPRE : The start of the software update controller failed + The start of the software update controller failed no_full_log @@ -169,7 +169,7 @@ 18101 ^4121$ - VIPRE : Definitions update applied + Definitions update applied no_full_log @@ -177,7 +177,7 @@ 18101 ^4122$ - VIPRE : Definitions update cancelled + Definitions update cancelled no_full_log @@ -186,7 +186,7 @@ 18101 ^4123$ - VIPRE was unable to complete the check for threat definitions updates + VIPRE was unable to complete the check for threat definitions updates no_full_log @@ -194,7 +194,7 @@ 18101 ^4124$ - VIPRE was unable to complete the check for threat definitions updates. It will retry on the next update event + VIPRE was unable to complete the check for threat definitions updates. It will retry on the next update event no_full_log @@ -203,7 +203,7 @@ 18101 ^4125$ - VIPRE : Start of threat definitions controller failed + Start of threat definitions controller failed no_full_log @@ -211,7 +211,7 @@ 18101 ^4126$ - VIPRE : Cannot update threat definitions because your registration is expired + Cannot update threat definitions because your registration is expired no_full_log @@ -219,7 +219,7 @@ 18101 ^4129$ - VIPRE : Completed scheduled deep scan + Completed scheduled deep scan no_full_log @@ -227,7 +227,7 @@ 18101 ^4130$ - VIPRE : Completed manual deep scan + Completed manual deep scan no_full_log @@ -236,7 +236,7 @@ 18101 ^4131$ - VIPRE : Completed scheduled quick scan + Completed scheduled quick scan no_full_log @@ -244,7 +244,7 @@ 18101 ^4132$ - VIPRE : Completed manual quick scan + Completed manual quick scan no_full_log @@ -252,7 +252,7 @@ 18101 ^4133$ - VIPRE : Completed scheduled custom scan + Completed scheduled custom scan no_full_log @@ -260,17 +260,15 @@ 18101 ^4134$ - VIPRE : Completed manual custom scan + Completed manual custom scan no_full_log - - 18101 ^4135$ - VIPRE : Scan cancelled + Scan cancelled no_full_log @@ -278,7 +276,7 @@ 18101 ^4136$ - VIPRE : Reboot required + Reboot required no_full_log @@ -286,7 +284,7 @@ 18101 ^4137$ - VIPRE : A scan of your computer failed because there are no threat definitions + A scan of your computer failed because there are no threat definitions no_full_log @@ -294,15 +292,15 @@ 18101 ^4138$ - VIPRE : Start of the scan controller failed + Start of the scan controller failed no_full_log - + 18101 ^4139$ - VIPRE : An item has been quarantined + An item has been quarantined no_full_log @@ -310,7 +308,7 @@ 18101 ^4140$ - VIPRE : An item has been restored from quarantine + An item has been restored from quarantine no_full_log @@ -318,7 +316,7 @@ 18101 ^4141$ - VIPRE : An item has been deleted from quarantine + An item has been deleted from quarantine no_full_log @@ -326,7 +324,7 @@ 18101 ^4142$ - VIPRE : The quarantne has been purged + The quarantne has been purged no_full_log @@ -334,7 +332,7 @@ 18101 ^4143$ - VIPRE : The quarantne controller could not be started + The quarantne controller could not be started no_full_log @@ -342,7 +340,7 @@ 18101 ^4145$ - VIPRE : Email AV enabled + Email AV enabled no_full_log @@ -350,7 +348,7 @@ 18101 ^4146$ - VIPRE : Email AV disabled + Email AV disabled no_full_log @@ -358,7 +356,7 @@ 18101 ^4147$ - VIPRE : Email protection is enabled but the drivers are not loaded + Email protection is enabled but the drivers are not loaded no_full_log @@ -366,7 +364,7 @@ 18101 ^4148$ - VIPRE : The scan of an email item failed + The scan of an email item failed no_full_log @@ -374,7 +372,7 @@ 18101 ^4149$ - VIPRE : The Scan of an email item failed because there are no threat definitions + The Scan of an email item failed because there are no threat definitions no_full_log @@ -382,7 +380,7 @@ 18101 ^4250$ - VIPRE : Registration state changed + Registration state changed no_full_log @@ -390,7 +388,7 @@ 18101 ^4151$ - VIPRE : The registration controller could not be started + The registration controller could not be started no_full_log @@ -398,7 +396,7 @@ 18101 ^4153$ - VIPRE : The scan control could not complete its scan + The scan control could not complete its scan no_full_log @@ -406,7 +404,7 @@ 18101 ^4159$ - VIPRE : A scheduled scan was missed because the machine was powered off + A scheduled scan was missed because the machine was powered off no_full_log @@ -415,7 +413,7 @@ 18101 ^4160$ - VIPRE : Quarantine of an item failed + Quarantine of an item failed no_full_log @@ -424,7 +422,7 @@ 18101 ^4161$ - VIPRE : Restore of an item from quarantine failed + Restore of an item from quarantine failed no_full_log @@ -433,7 +431,7 @@ 18101 ^4162$ - VIPRE : Delete of an from quarantine failed + Delete of an from quarantine failed no_full_log @@ -441,7 +439,7 @@ 18101 ^4163$ - VIPRE : The quarantine purge failed + The quarantine purge failed no_full_log @@ -449,7 +447,7 @@ 18101 ^4165$ - VIPRE : Firewall enabled + Firewall enabled no_full_log @@ -458,7 +456,7 @@ 18101 ^4166$ - VIPRE : Firewall disabled + Firewall disabled no_full_log @@ -467,7 +465,7 @@ 18101 ^4167$ - VIPRE : IDS enabled + IDS enabled no_full_log @@ -476,7 +474,7 @@ 18101 ^4168$ - VIPRE : IDS disabled + IDS disabled no_full_log @@ -485,7 +483,7 @@ 18101 ^4169$ - VIPRE : Web Filtering enabled + Web Filtering enabled no_full_log @@ -494,7 +492,7 @@ 18101 ^4170$ - VIPRE : Web Filtering disabled + Web Filtering disabled no_full_log @@ -503,7 +501,7 @@ 18101 ^4171$ - VIPRE : Bad Web Site Blocking enabled + Bad Web Site Blocking enabled no_full_log @@ -512,7 +510,7 @@ 18101 ^4172$ - VIPRE : Bad Web Site Blocking disabled + Bad Web Site Blocking disabled no_full_log @@ -520,7 +518,7 @@ 18101 ^4173$ - VIPRE : HIPS enabled + HIPS enabled no_full_log @@ -528,7 +526,7 @@ 18101 ^4174$ - VIPRE : HIPS disabled + HIPS disabled no_full_log @@ -537,14 +535,14 @@ 18101 ^4175$ - VIPRE : Firewall Resume All Traffic + Firewall Resume All Traffic no_full_log 18101 ^4176$ - VIPRE : Firewall Stops All Traffic + Firewall Stops All Traffic no_full_log @@ -552,7 +550,7 @@ 18101 ^4177$ - VIPRE : Active protection blocked a process from accessing a file + Active protection blocked a process from accessing a file no_full_log From 6e02606739d1b0bf4c3557a2ae258c472201ea45 Mon Sep 17 00:00:00 2001 From: Elwali karkoub Date: Tue, 27 Aug 2019 20:25:15 +0200 Subject: [PATCH 4/7] Update 0585-vipre_rules.xml --- rules/0585-vipre_rules.xml | 276 +++++++++++++------------------------ 1 file changed, 99 insertions(+), 177 deletions(-) diff --git a/rules/0585-vipre_rules.xml b/rules/0585-vipre_rules.xml index ef7487548..f4363b9bb 100644 --- a/rules/0585-vipre_rules.xml +++ b/rules/0585-vipre_rules.xml @@ -9,551 +9,473 @@ - 18101 + 60600 SBAMSvc VIPRE Informational message no_full_log - 18101 + 60600 ^4097$ System shutdown complete no_full_log - - - 18101 + + 60600 ^4098$ User initiated shutdown no_full_log - - 18101 + + 60600 ^4099$ Service started Application version no_full_log - - 18101 + 60600 ^4100$ Service paused no_full_log - - + - 18101 + 60600 ^4101$ Service resumed no_full_log - - 18101 + 60600 ^4102$ The transfer of one or more ThreatNet files failed no_full_log - 18101 + 60600 ^4103$ Transfer occured no_full_log - - 18101 + 60600 ^4104$ The start of the ThreatNet controller failed no_full_log - - - - 18101 + + 60600 ^4105$ Active Protection enabled no_full_log - - 18101 + 60600 ^4106$ Active Protection disabled no_full_log - - 18101 + + 60600 ^4108$ Active protection could not be enabled no_full_log - - 18101 + 60600 ^4109$ Active Protection could not be disabled no_full_log - - - 18101 + + 60600 ^4110$ Active Protection requires a reboot to fully protect your computer no_full_log - - 18101 + 60600 ^4111$ Active Protection could not be enabled because there are no threat definitions no_full_log - - 18101 + + 60600 ^4112$ Manual software update downloaded no_full_log - - 18101 + 60600 ^4113$ Scheduled software update downloaded no_full_log - - - - 18101 + + + 60600 ^4114$ VIPRE was unable to complete the check for software updates no_full_log - - - 18101 + 60600 ^4115$ VIPRE was unable to complete the check for software updates. It will retry on the next update event no_full_log - - - + - 18101 + 60600 ^4116$ The start of the software update controller failed no_full_log - - 18101 + 60600 ^4121$ Definitions update applied no_full_log - - - 18101 + + 60600 ^4122$ Definitions update cancelled no_full_log - - - 18101 + 60600 ^4123$ VIPRE was unable to complete the check for threat definitions updates no_full_log - - - 18101 + + 60600 ^4124$ VIPRE was unable to complete the check for threat definitions updates. It will retry on the next update event no_full_log - - - 18101 + 60600 ^4125$ Start of threat definitions controller failed no_full_log - - 18101 + 60600 ^4126$ Cannot update threat definitions because your registration is expired no_full_log - - 18101 + 60600 ^4129$ Completed scheduled deep scan no_full_log - - - 18101 + + 60600 ^4130$ Completed manual deep scan no_full_log - - - 18101 + 60600 ^4131$ Completed scheduled quick scan no_full_log - - + - 18101 + 60600 ^4132$ Completed manual quick scan no_full_log - - + - 18101 + 60600 ^4133$ Completed scheduled custom scan no_full_log - - + - 18101 + 60600 ^4134$ Completed manual custom scan no_full_log - - + - - 18101 + + 60600 ^4135$ Scan cancelled no_full_log - - + - 18101 + 60600 ^4136$ Reboot required no_full_log - - + - 18101 + 60600 ^4137$ A scan of your computer failed because there are no threat definitions no_full_log - - 18101 + 60600 ^4138$ Start of the scan controller failed no_full_log - - 18101 + 60600 ^4139$ An item has been quarantined no_full_log - - + - 18101 + 60600 ^4140$ An item has been restored from quarantine no_full_log - - 18101 + 60600 ^4141$ An item has been deleted from quarantine no_full_log - - 18101 + 60600 ^4142$ The quarantne has been purged no_full_log - - + - 18101 + 60600 ^4143$ The quarantne controller could not be started no_full_log - + - - - 18101 + + 60600 ^4145$ Email AV enabled no_full_log - - + - 18101 + 60600 ^4146$ Email AV disabled no_full_log - - 18101 + 60600 ^4147$ Email protection is enabled but the drivers are not loaded no_full_log - - 18101 + 60600 ^4148$ The scan of an email item failed no_full_log - + - - - 18101 + + 60600 ^4149$ The Scan of an email item failed because there are no threat definitions no_full_log - - + - - 18101 + + 60600 ^4250$ Registration state changed no_full_log - - + - 18101 + 60600 ^4151$ The registration controller could not be started no_full_log - - 18101 + 60600 ^4153$ The scan control could not complete its scan no_full_log - - 18101 + 60600 ^4159$ A scheduled scan was missed because the machine was powered off no_full_log - - - 18101 + 60600 ^4160$ Quarantine of an item failed no_full_log - - - 18101 + 60600 ^4161$ Restore of an item from quarantine failed no_full_log - - - 18101 + 60600 ^4162$ Delete of an from quarantine failed no_full_log - - + - 18101 + 60600 ^4163$ The quarantine purge failed no_full_log - - 18101 + 60600 ^4165$ Firewall enabled no_full_log - - - 18101 + 60600 ^4166$ Firewall disabled no_full_log - - - 18101 + 60600 ^4167$ IDS enabled no_full_log - - - 18101 + 60600 ^4168$ IDS disabled no_full_log - - - 18101 + 60600 ^4169$ Web Filtering enabled no_full_log - - - 18101 + 60600 ^4170$ Web Filtering disabled no_full_log - - - 18101 + 60600 ^4171$ Bad Web Site Blocking enabled no_full_log - - - 18101 + 60600 ^4172$ Bad Web Site Blocking disabled no_full_log - - 18101 + 60600 ^4173$ HIPS enabled no_full_log - - 18101 + 60600 ^4174$ HIPS disabled no_full_log - - - 18101 + 60600 ^4175$ Firewall Resume All Traffic no_full_log - 18101 + 60600 ^4176$ Firewall Stops All Traffic no_full_log - - - 18101 + + 60600 ^4177$ Active protection blocked a process from accessing a file no_full_log - From 8d5a7421e082e4e2b6bba93db6ab682427f5f2f4 Mon Sep 17 00:00:00 2001 From: Elwali karkoub Date: Tue, 27 Aug 2019 20:36:31 +0200 Subject: [PATCH 5/7] Update 0585-vipre_rules.xml --- rules/0585-vipre_rules.xml | 440 +++++++++++++++++++------------------ 1 file changed, 221 insertions(+), 219 deletions(-) diff --git a/rules/0585-vipre_rules.xml b/rules/0585-vipre_rules.xml index f4363b9bb..58b8e77ea 100644 --- a/rules/0585-vipre_rules.xml +++ b/rules/0585-vipre_rules.xml @@ -11,471 +11,473 @@ 60600 SBAMSvc - VIPRE Informational message + vipre Informational message no_full_log - + - + 60600 - ^4097$ + ^4097$ System shutdown complete no_full_log - + - + + 60600 - ^4098$ + ^4098$ User initiated shutdown no_full_log - + - + 60600 - ^4099$ + ^4099$ Service started Application version no_full_log - + - + 60600 - ^4100$ + ^4100$ Service paused no_full_log - + - + 60600 - ^4101$ + ^4101$ Service resumed no_full_log - + - + 60600 - ^4102$ - The transfer of one or more ThreatNet files failed + ^4102$ + The transfer of one or more ThreatNet files failed no_full_log - + - + 60600 - ^4103$ - Transfer occured + ^4103$ + Transfer occured no_full_log - + - + 60600 - ^4104$ - The start of the ThreatNet controller failed + ^4104$ + The start of the ThreatNet controller failed no_full_log - + - + 60600 - ^4105$ + ^4105$ Active Protection enabled no_full_log - + - + 60600 - ^4106$ + ^4106$ Active Protection disabled no_full_log - + - + 60600 - ^4108$ + ^4108$ Active protection could not be enabled no_full_log - + - + 60600 - ^4109$ + ^4109$ Active Protection could not be disabled no_full_log - + - + 60600 - ^4110$ + ^4110$ Active Protection requires a reboot to fully protect your computer no_full_log - + - + 60600 - ^4111$ + ^4111$ Active Protection could not be enabled because there are no threat definitions no_full_log - + - + 60600 - ^4112$ + ^4112$ Manual software update downloaded no_full_log - + - + 60600 - ^4113$ + ^4113$ Scheduled software update downloaded no_full_log - + - + 60600 - ^4114$ - VIPRE was unable to complete the check for software updates + ^4114$ + VIPRE was unable to complete the check for software updates no_full_log - + - + 60600 - ^4115$ - VIPRE was unable to complete the check for software updates. It will retry on the next update event + ^4115$ + VIPRE was unable to complete the check for software updates. It will retry on the next update event no_full_log - + - + 60600 - ^4116$ + ^4116$ The start of the software update controller failed no_full_log - + - + 60600 - ^4121$ + ^4121$ Definitions update applied no_full_log - + - + 60600 - ^4122$ + ^4122$ Definitions update cancelled no_full_log - + - + 60600 - ^4123$ - VIPRE was unable to complete the check for threat definitions updates + ^4123$ + VIPRE was unable to complete the check for threat definitions updates no_full_log - + - + 60600 - ^4124$ - VIPRE was unable to complete the check for threat definitions updates. It will retry on the next update event + ^4124$ + VIPRE was unable to complete the check for threat definitions updates. It will retry on the next update event no_full_log - + - + 60600 - ^4125$ + ^4125$ Start of threat definitions controller failed no_full_log - + - + 60600 - ^4126$ + ^4126$ Cannot update threat definitions because your registration is expired no_full_log - + - + 60600 - ^4129$ + ^4129$ Completed scheduled deep scan no_full_log - + - + 60600 - ^4130$ + ^4130$ Completed manual deep scan no_full_log - + - + 60600 - ^4131$ + ^4131$ Completed scheduled quick scan no_full_log - + - + 60600 - ^4132$ + ^4132$ Completed manual quick scan no_full_log - + - + 60600 - ^4133$ + ^4133$ Completed scheduled custom scan no_full_log - + - + 60600 - ^4134$ + ^4134$ Completed manual custom scan no_full_log - + - + 60600 - ^4135$ + ^4135$ Scan cancelled no_full_log - + - + 60600 - ^4136$ + ^4136$ Reboot required no_full_log - + - + 60600 - ^4137$ + ^4137$ A scan of your computer failed because there are no threat definitions no_full_log - + - + 60600 - ^4138$ + ^4138$ Start of the scan controller failed no_full_log - + - + 60600 - ^4139$ + ^4139$ An item has been quarantined no_full_log - + - + 60600 - ^4140$ + ^4140$ An item has been restored from quarantine no_full_log - + - + 60600 - ^4141$ + ^4141$ An item has been deleted from quarantine no_full_log - + - + 60600 - ^4142$ + ^4142$ The quarantne has been purged no_full_log - + - + 60600 - ^4143$ + ^4143$ The quarantne controller could not be started no_full_log - + - + 60600 - ^4145$ + ^4145$ Email AV enabled no_full_log - + - + 60600 - ^4146$ + ^4146$ Email AV disabled no_full_log - + - + 60600 - ^4147$ + ^4147$ Email protection is enabled but the drivers are not loaded no_full_log - + - + 60600 - ^4148$ + ^4148$ The scan of an email item failed no_full_log - + - + 60600 - ^4149$ + ^4149$ The Scan of an email item failed because there are no threat definitions no_full_log - + - + 60600 - ^4250$ + ^4250$ Registration state changed no_full_log - + - + 60600 - ^4151$ + ^4151$ The registration controller could not be started no_full_log - + - + 60600 - ^4153$ + ^4153$ The scan control could not complete its scan no_full_log - + - + 60600 - ^4159$ + ^4159$ A scheduled scan was missed because the machine was powered off no_full_log - + - + 60600 - ^4160$ + ^4160$ Quarantine of an item failed no_full_log - + - + 60600 - ^4161$ + ^4161$ Restore of an item from quarantine failed no_full_log - + - + 60600 - ^4162$ + ^4162$ Delete of an from quarantine failed no_full_log - + + - + 60600 - ^4163$ + ^4163$ The quarantine purge failed no_full_log - + - + 60600 - ^4165$ - Firewall enabled + ^4165$ + Firewall enabled no_full_log - + - + 60600 - ^4166$ - Firewall disabled + ^4166$ + Firewall disabled no_full_log - + - + 60600 - ^4167$ - IDS enabled + ^4167$ + IDS enabled no_full_log - + - + 60600 - ^4168$ - IDS disabled + ^4168$ + IDS disabled no_full_log - + - + 60600 - ^4169$ + ^4169$ Web Filtering enabled no_full_log - + - + 60600 - ^4170$ - Web Filtering disabled + ^4170$ + Web Filtering disabled no_full_log - + - + 60600 - ^4171$ - Bad Web Site Blocking enabled + ^4171$ + Bad Web Site Blocking enabled no_full_log - + - + 60600 - ^4172$ - Bad Web Site Blocking disabled + ^4172$ + Bad Web Site Blocking disabled no_full_log - + - + 60600 - ^4173$ - HIPS enabled + ^4173$ + HIPS enabled no_full_log - + - + 60600 - ^4174$ - HIPS disabled + ^4174$ + HIPS disabled no_full_log - + - + 60600 - ^4175$ - Firewall Resume All Traffic + ^4175$ + Firewall Resume All Traffic no_full_log - + - + 60600 - ^4176$ - Firewall Stops All Traffic + ^4176$ + Firewall Stops All Traffic no_full_log - + - + 60600 - ^4177$ - Active protection blocked a process from accessing a file + ^4177$ + Active protection blocked a process from accessing a file no_full_log - + From 2eb3609c66a877e1364bafc4e2a72297eb149425 Mon Sep 17 00:00:00 2001 From: Elwali karkoub Date: Tue, 27 Aug 2019 20:37:25 +0200 Subject: [PATCH 6/7] Update 0585-vipre_rules.xml --- rules/0585-vipre_rules.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/0585-vipre_rules.xml b/rules/0585-vipre_rules.xml index 58b8e77ea..25175b843 100644 --- a/rules/0585-vipre_rules.xml +++ b/rules/0585-vipre_rules.xml @@ -11,7 +11,7 @@ 60600 SBAMSvc - vipre Informational message + Vipre informational message no_full_log From 98fc79e81d79bcc23ad8045deea86e5f4efd219e Mon Sep 17 00:00:00 2001 From: Elwali karkoub Date: Tue, 27 Aug 2019 20:44:22 +0200 Subject: [PATCH 7/7] Update 0585-vipre_rules.xml --- rules/0585-vipre_rules.xml | 40 +++++++++++++++++++------------------- 1 file changed, 20 insertions(+), 20 deletions(-) diff --git a/rules/0585-vipre_rules.xml b/rules/0585-vipre_rules.xml index 25175b843..e74940418 100644 --- a/rules/0585-vipre_rules.xml +++ b/rules/0585-vipre_rules.xml @@ -33,7 +33,7 @@ 60600 ^4099$ - Service started Application version + Service started application version no_full_log @@ -54,7 +54,7 @@ 60600 ^4102$ - The transfer of one or more ThreatNet files failed + The transfer of one or more threatNet files failed no_full_log @@ -75,14 +75,14 @@ 60600 ^4105$ - Active Protection enabled + Active protection enabled no_full_log 60600 ^4106$ - Active Protection disabled + Active protection disabled no_full_log @@ -96,21 +96,21 @@ 60600 ^4109$ - Active Protection could not be disabled + Active protection could not be disabled no_full_log 60600 ^4110$ - Active Protection requires a reboot to fully protect your computer + Active protection requires a reboot to fully protect your computer no_full_log 60600 ^4111$ - Active Protection could not be enabled because there are no threat definitions + Active protection could not be enabled because there are no threat definitions no_full_log @@ -131,14 +131,14 @@ 60600 ^4114$ - VIPRE was unable to complete the check for software updates + Vipre was unable to complete the check for software updates no_full_log 60600 ^4115$ - VIPRE was unable to complete the check for software updates. It will retry on the next update event + Vipre was unable to complete the check for software updates. It will retry on the next update event no_full_log @@ -166,14 +166,14 @@ 60600 ^4123$ - VIPRE was unable to complete the check for threat definitions updates + Vipre was unable to complete the check for threat definitions updates no_full_log 60600 ^4124$ - VIPRE was unable to complete the check for threat definitions updates. It will retry on the next update event + Vipre was unable to complete the check for threat definitions updates. It will retry on the next update event no_full_log @@ -285,14 +285,14 @@ 60600 ^4142$ - The quarantne has been purged + The quarantine has been purged no_full_log 60600 ^4143$ - The quarantne controller could not be started + The quarantine controller could not be started no_full_log @@ -327,7 +327,7 @@ 60600 ^4149$ - The Scan of an email item failed because there are no threat definitions + The scan of an email item failed because there are no threat definitions no_full_log @@ -419,28 +419,28 @@ 60600 ^4169$ - Web Filtering enabled + Web filtering enabled no_full_log 60600 ^4170$ - Web Filtering disabled + Web filtering disabled no_full_log 60600 ^4171$ - Bad Web Site Blocking enabled + Bad web site blocking enabled no_full_log 60600 ^4172$ - Bad Web Site Blocking disabled + Bad web site blocking disabled no_full_log @@ -461,14 +461,14 @@ 60600 ^4175$ - Firewall Resume All Traffic + Firewall resume all traffic no_full_log 60600 ^4176$ - Firewall Stops All Traffic + Firewall stops all traffic no_full_log