Merge pull request #2460 from phantinuss/master

fix: FP in Aviar installer
This commit is contained in:
Florian Roth
2021-12-17 19:55:02 +01:00
committed by GitHub
@@ -17,8 +17,10 @@ detection:
Image|endswith: '.exe'
filter_null:
Image: null
filter_msi:
filter_starts:
Image|startswith: 'C:\Windows\Installer\MSI'
filter_pstarts:
ParentImage|startswith: 'C:\ProgramData\Avira\'
filter_avira:
Image|startswith: 'C:\Windows\Temp\'
Image|endswith: '\avira_speedup_setup_update.tmp'