fsav 2.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566
  1. #------------------------------------------------------------------------------
  2. # $File: fsav,v 1.13 2013/03/25 17:18:47 christos Exp $
  3. # fsav: file(1) magic for datafellows fsav virus definition files
  4. # Anthon van der Neut (anthon@mnt.org)
  5. # ftp://ftp.f-prot.com/pub/{macrdef2.zip,nomacro.def}
  6. 0 beshort 0x1575 fsav macro virus signatures
  7. >8 leshort >0 (%d-
  8. >11 byte >0 \b%02d-
  9. >10 byte >0 \b%02d)
  10. # ftp://ftp.f-prot.com/pub/sign.zip
  11. #10 ubyte <12
  12. #>9 ubyte <32
  13. #>>8 ubyte 0x0a
  14. #>>>12 ubyte 0x07
  15. #>>>>11 uleshort >0 fsav DOS/Windows virus signatures (%d-
  16. #>>>>10 byte 0 \b01-
  17. #>>>>10 byte 1 \b02-
  18. #>>>>10 byte 2 \b03-
  19. #>>>>10 byte 3 \b04-
  20. #>>>>10 byte 4 \b05-
  21. #>>>>10 byte 5 \b06-
  22. #>>>>10 byte 6 \b07-
  23. #>>>>10 byte 7 \b08-
  24. #>>>>10 byte 8 \b09-
  25. #>>>>10 byte 9 \b10-
  26. #>>>>10 byte 10 \b11-
  27. #>>>>10 byte 11 \b12-
  28. #>>>>9 ubyte >0 \b%02d)
  29. # ftp://ftp.f-prot.com/pub/sign2.zip
  30. #0 ubyte 0x62
  31. #>1 ubyte 0xF5
  32. #>>2 ubyte 0x1
  33. #>>>3 ubyte 0x1
  34. #>>>>4 ubyte 0x0e
  35. #>>>>>13 ubyte >0 fsav virus signatures
  36. #>>>>>>11 ubyte x size 0x%02x
  37. #>>>>>>12 ubyte x \b%02x
  38. #>>>>>>13 ubyte x \b%02x bytes
  39. # Joerg Jenderek: joerg dot jenderek at web dot de
  40. # http://www.clamav.net/doc/latest/html/node45.html
  41. # .cvd files start with a 512 bytes colon separated header
  42. # ClamAV-VDB:buildDate:version:signaturesNumbers:functionalityLevelRequired:MD5:Signature:builder:buildTime
  43. # + gzipped tarball files
  44. 0 string ClamAV-VDB:
  45. >11 string >\0 Clam AntiVirus database %-.23s
  46. >>34 string :
  47. >>>35 string !: \b, version
  48. >>>>35 string x \b%-.1s
  49. >>>>>36 string !:
  50. >>>>>>36 string x \b%-.1s
  51. >>>>>>>37 string !:
  52. >>>>>>>>37 string x \b%-.1s
  53. >>>>>>>>>38 string !:
  54. >>>>>>>>>>38 string x \b%-.1s
  55. >512 string \037\213 \b, gzipped
  56. >769 string ustar\0 \b, tarred
  57. # Type: Grisoft AVG AntiVirus
  58. # From: David Newgas <david@newgas.net>
  59. 0 string AVG7_ANTIVIRUS_VAULT_FILE AVG 7 Antivirus vault file data
  60. 0 string X5O!P%@AP[4\\PZX54(P^)7CC)7}$EICAR
  61. >33 string -STANDARD-ANTIVIRUS-TEST-FILE!$H+H* EICAR virus test files