October 2, 2009
View ab63657

Add generic and PE hooks.

Török Edvin authored on 2009/10/02 23:33:11
September 24, 2009
View 081f647

win32#2

aCaB authored on 2009/09/24 23:21:51
September 1, 2009
View 006f5fe

libclamav: in bm_offmode only load sigs with non-floating absolute and relative offsets into BM matcher (load other ones into AC) and use per-file computed offset table to pick up best shifts (not enabled by default, bb#1300)

Tomasz Kojm authored on 2009/09/01 18:19:31
August 14, 2009
View 33872a4

libclamav: improve handling of signature offsets

Tomasz Kojm authored on 2009/08/14 21:38:13
July 31, 2009
View 3d478af

fix check for pe32+

aCaB authored on 2009/07/31 19:52:41
July 19, 2009
View 11643ef

check IS scan return, add IS testfiles

aCaB authored on 2009/07/19 23:22:05
July 16, 2009
View d0b31fa

Make yC able to handle more samples and variants.

Török Edvin authored on 2009/07/16 01:42:01
July 14, 2009
View 56e5821

initial IS overlay parser

aCaB authored on 2009/07/14 16:36:36
April 23, 2009
View e410198

libclamav: call cli_checkfp() whenever possible/makes sense (bb#1558)

Tomasz Kojm authored on 2009/04/23 22:24:21
April 10, 2009
View e6d1a8b

Fix some Trojan.Swizzor.Gen false positives (bb #1558).

Török Edvin authored on 2009/04/10 22:23:13
April 2, 2009
View 646c2a4

cli_parseres_special: check size before attempting to allocate. (bb #1506)

Török Edvin authored on 2009/04/02 01:39:55
March 23, 2009
View f204e8d

bb#1335

aCaB authored on 2009/03/23 23:15:43
February 12, 2009
View 871177c

return codes cleanup (bb#1159)

Tomasz Kojm authored on 2009/02/12 22:53:23
December 23, 2008
View 188914f

reset resource type, otherwise we parse all resources after a string resource as string (including images), which is wrong, because it feeds wrong statistics to cli_detect_swizz.

Török Edvin authored on 2008/12/23 19:53:20
December 6, 2008
View f27fab0

Improve Trojan.Swizzor.Gen detection: do per file statistics in addition to per string. It is amazing how a much simpler rule can do the same job better.

Török Edvin authored on 2008/12/06 23:49:00