@@ -868,20 +868,20 @@ class AV(Module):
868
868
("glob" , "sysvol/ProgramData/Emsisoft/Reports/scan*.txt" ),
869
869
# F-Secure
870
870
("dir" , "sysvol/ProgramData/F-Secure/Log" ),
871
- ("dir" , "sysvol/Users*/ AppData/Local/F-Secure/Log" ),
871
+ ("dir" , "AppData/Local/F-Secure/Log" , from_user_home ),
872
872
("dir" , "sysvol/ProgramData/F-Secure/Antivirus/ScheduledScanReports" ),
873
873
# HitmanPro
874
874
("dir" , "sysvol/ProgramData/HitmanPro/Logs" ),
875
875
("dir" , "sysvol/ProgramData/HitmanPro.Alert/Logs" ),
876
876
("file" , "sysvol/ProgramData/HitmanPro.Alert/excalibur.db" ),
877
- ("glob " , "sysvol/ProgramData/HitmanPro/Quarantine" ),
877
+ ("dir " , "sysvol/ProgramData/HitmanPro/Quarantine" ),
878
878
# Malwarebytes
879
879
("glob" , "sysvol/ProgramData/Malwarebytes/Malwarebytes Anti-Malware/Logs/mbam-log-*.xml" ),
880
880
("glob" , "sysvol/ProgramData/Malwarebytes/MBAMService/logs/mbamservice.log*" ),
881
- ("dir" , "sysvol/Users*/ AppData/Roaming/Malwarebytes/Malwarebytes Anti-Malware/Logs" ),
881
+ ("dir" , "AppData/Roaming/Malwarebytes/Malwarebytes Anti-Malware/Logs" , from_user_home ),
882
882
("dir" , "sysvol/ProgramData/Malwarebytes/MBAMService/ScanResults" ),
883
883
# McAfee
884
- ("dir" , "sysvol/Users/All Users/ Application Data/McAfee/DesktopProtection" ),
884
+ ("dir" , "Application Data/McAfee/DesktopProtection" , from_user_home ),
885
885
("dir" , "sysvol/ProgramData/McAfee/DesktopProtection" ),
886
886
("dir" , "sysvol/ProgramData/McAfee/Endpoint Security/Logs" ),
887
887
("dir" , "sysvol/ProgramData/McAfee/Endpoint Security/Logs_Old" ),
@@ -891,7 +891,7 @@ class AV(Module):
891
891
# RogueKiller
892
892
("glob" , "sysvol/ProgramData/RogueKiller/logs/AdliceReport_*.json" ),
893
893
# SUPERAntiSpyware
894
- ("dir" , "sysvol/Users*/ AppData/Roaming/SUPERAntiSpyware/Logs" ),
894
+ ("dir" , "AppData/Roaming/SUPERAntiSpyware/Logs" , from_user_home ),
895
895
# SecureAge
896
896
("dir" , "sysvol/ProgramData/SecureAge Technology/SecureAge/log" ),
897
897
# SentinelOne
@@ -972,7 +972,7 @@ class History(Module):
972
972
("dir" , "AppData/Local/Microsoft/Internet Explorer/Recovery" , from_user_home ),
973
973
("file" , "AppData/Local/Microsoft/Windows/History/History.IE5/index.dat" , from_user_home ),
974
974
(
975
- "file " ,
975
+ "glob " ,
976
976
"AppData/Local/Microsoft/Windows/History/History.IE5/MSHist*/index.dat" ,
977
977
from_user_home ,
978
978
),
@@ -982,7 +982,7 @@ class History(Module):
982
982
from_user_home ,
983
983
),
984
984
(
985
- "file " ,
985
+ "glob " ,
986
986
"AppData/Local/Microsoft/Windows/History/Low/History.IE5/MSHist*/index.dat" ,
987
987
from_user_home ,
988
988
),
0 commit comments