Skip to content

JerryLinLinLin/AV_Detection_Dump

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

17 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Antivirus Detection Name Dump

Table of Contents

About

This project contains the CSV files of malware detection names from some antivirus products, and a PowerShell script for dumping the detection entries.

Getting Started

Each subfolder contains dump CSV files with vendor's name and date. File name ends with BASE contains names from a vendor's scan engine, and others may be different depended on the sources of detection (e.g. behavior protection).

Prerequisites

To run the PowerShell script:

  1. Download the Windows Sysinternals and add it to PATH, or install it from Microsoft Store.

  2. Disable the PPL (Protected Processes Light) using PPLKiller, or use Microsoft Windows 7 (it does not serve the PPL).

  3. Disable Self-Protection Module of AV if possible.

Note: You may need to updating the PowerShell (v4.0 or later) and .NET Framework (v4.5 or later) in order to run this script in Windows 7.

Usage

powershell -executionpolicy bypass -File .\AV_DUMP.ps1 <Name>

List of Supported Vendors

Name PPL Need to Disable SP Detection Source Accuracy
Huorong No No BASE High
Kaspersky Yes Yes BASE, PDM Medium
Malwarebytes Yes No BASE, DDS High

Releases

No releases published

Packages

No packages published