<?xml version="1.0" encoding="utf-8" ?>
<profile product="virusclass" version="1.0" time="20200526">
	<virusclasses>	
		<!-- 通用型 -->			
		<class defineid="0" name="common">
			<classname>
				<language id="zh-cn" text="危险程序"/> 
				<language id="en-us" text="Malware"/> 
				<language id="zh-tw" text="危險程式"/>
			</classname>
			<describe> 
				<language id="zh-cn" text="对电脑或系统具有危险的程序"/> 
				<language id="en-us" text="Dangerous program to system or computer"/>
				<language id="zh-tw" text="對電腦或系統具有危險的程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="风险程序可能会导致您的计算机系统破坏或遭到攻击，影响系统或程序正常运行"/>
				<language id="en-us" text="Suspicious programs may attack your computer and affect the system"/>
				<language id="zh-tw" text="風險程式可能會導致您的電腦系統破壞或遭到攻擊，影響系統或程式正常運行"/>
			</risk>
			<matchrules>
			</matchrules>
		</class>
		
		<!-- QCE和QOWL引擎 -->	
		<class defineid="1" name="Adware">
			<classname>
				<language id="zh-cn" text="广告程序"/> 
				<language id="en-us" text="Adware"/> 
				<language id="zh-tw" text="廣告程式"/> 
			</classname>
			<describe> <!--病毒描述
							id：语言id，目前支持中文和英文
							text：文字描述，需要显示的内容
			            -->
				<language id="zh-cn" text="广告类"/> 
				<language id="en-us" text="Adware"/>
				<language id="zh-tw" text="廣告類"/> 
			</describe>
			<risk>
			<!--风险描述
				id：语言id，目前支持中文和英文
				text：文字描述，需要显示的内容
			-->
				<language id="zh-cn" text="广告程序会在后台偷偷弹窗或下载来历不明的文件"/>
				<language id="en-us" text="Adware will open pop-up windows or download files in background"/>
				<language id="zh-tw" text="廣告程式會在後臺偷偷彈窗或下載來歷不明的文件"/>
			</risk>
			<matchrules>
				<!--
					scannerid（必须值）：扫描器的id，这个要和扫描器对应，
					name（非必要字段）：给编写者提供能够看明白的内容
					field：数据来源于报毒扫描器返回的那个数据字段
					type:数据类型
					match：匹配规则-匹配规则包括，equal（等于），begin（前包含），end（尾包含），contain（包含），in（列表中）
					value:带匹配的内容
				-->
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="adware"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="adware"/>
			</matchrules>
		</class>
		
		<class defineid="2" name="Joke">
			<classname>
				<language id="zh-cn" text="恶作剧类程序"/> 
				<language id="en-us" text="Joke"/> 
				<language id="zh-tw" text="惡作劇類程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="恶作剧程序，对电脑无持续性危害"/> 
				<language id="en-us" text="Joke viruses do not cause any continuous damage to computers"/>
				<language id="zh-tw" text="惡作劇程式，對電腦無持續性危害"/>
			</describe>
			<risk>
				<language id="zh-cn" text="恶作剧类程序通常不会对用户的计算机、文件造成破坏，但可能通过弹窗或者其他手段模仿病毒行为"/>
				<language id="en-us" text="Joke viruses typically do not cause any damage to a victim’s computers or files, but they may exhibit virus-like behavior through pop-up windows and other means"/>
				<language id="zh-tw" text="惡作劇類程式通常不會對使用者的電腦、檔造成破壞，但可能通過彈窗或者其他手段模仿病毒行為"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="in" value="joke,hoax"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="joke"/>
			</matchrules>
		</class>
		
		<class defineid="3" name="Backdoor">
			<classname>
				<language id="zh-cn" text="后门程序"/> 
				<language id="en-us" text="Backdoor"/> 
				<language id="zh-tw" text="後門程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="隐藏在电脑中，执行远程指令"/> 
				<language id="en-us" text="Backdoor viruses hide themselves in the operating system, performing remote commands"/>
				<language id="zh-tw" text="隱藏在電腦中，執行遠端指令"/>
			</describe>
			<risk>
				<language id="zh-cn" text="后门程序会隐蔽在系统运行并对被感染的系统进行远程控制"/>
				<language id="en-us" text="Backdoor viruses is hidden in system and taking remote control of the infected system"/>
				<language id="zh-tw" text="後門程式會隱蔽在系統運行並對被感染的系統進行遠端控制"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="backdoor"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="backdoor"/>
			</matchrules>
			<mobilevirus>true</mobilevirus>
		</class>
		
		<class defineid="4" name="Constructor">
			<classname>
				<language id="zh-cn" text="病毒生成器"/> 
				<language id="en-us" text="Constructor"/> 
				<language id="zh-tw" text="病毒生成器"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="用于创建恶意文件,可以生成virus、Worm、Trojan等类型"/> 
				<language id="en-us" text="Constructor viruses are used to create other malicious viruses (Worms, Trojans, and others)"/>
				<language id="zh-tw" text="用於創建惡意檔,可以生成virus、Worm、Trojan等類型"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="病毒生成器通常会在电脑中创建病毒文件，并入侵电脑"/>
				<language id="en-us" text="Constructor viruses typically create more viruses in their host computer to take control of it"/>
				<language id="zh-tw" text="病毒生成器通常會在電腦中創建病毒檔，並入侵電腦"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="constructor"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="constructor"/>
			</matchrules>
		</class>
		
		<class defineid="5" name="Dropper">
			<classname>
				<language id="zh-cn" text="木马释放器"/> 
				<language id="en-us" text="Dropper"/> 
				<language id="zh-tw" text="木馬釋放器"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="释放木马程序"/> 
				<language id="en-us" text="Dropper"/>
				<language id="zh-tw" text="釋放木馬程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="木马释放器病毒通常会在系统中运行时，释放出木马病毒文件并运行"/>
				<language id="en-us" text="When run on a system, the Dropper virus typically infects its host with Trojan virus files"/>
				<language id="zh-tw" text="木馬釋放器病毒通常會在系統中運行時，釋放出木馬病毒檔並運行"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="dropper"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="dropper"/>
			</matchrules>
			<mobilevirus>true</mobilevirus>
		</class>
		
		<class defineid="6" name="HackerTool">
			<classname>
				<language id="zh-cn" text="黑客程序"/> 
				<language id="en-us" text="HackerTool"/>		
				<language id="zh-tw" text="駭客程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="能够破坏或感染其他文件的病毒"/> 
				<language id="en-us" text="HackerTool viruses typically damage or infect other files"/>
				<language id="zh-tw" text="能夠破壞或感染其他檔的病毒"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="病毒通常会通过感染系统中的文件来破坏计算机或计算机中的文件"/>
				<language id="en-us" text="HackerTool viruses usually damage systems and files through infecting other files on the system"/>
				<language id="zh-tw" text="病毒通常會通過感染系統中的檔來破壞電腦或電腦中的檔"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="in" value="hack,hacktool,vtool,virtool"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="hackertool"/>
			</matchrules>
		</class>
	
		<class defineid="7" name="Packed">
			<classname>
				<language id="zh-cn" text="可疑加壳的程序"/> 
				<language id="en-us" text="Packed"/> 
				<language id="zh-tw" text="可疑加殼的程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="加壳的可疑程序"/> 
				<language id="en-us" text="Packed"/>
				<language id="zh-tw" text="加殼的可疑程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="加壳类程序通常被病毒文件利用，通过混淆加壳的病毒程序，试图欺骗或躲过杀毒软件检测"/>
				<language id="en-us" text="Other viruses use Packed to obscure their presence, either tricking or completely avoiding detection from antivirus software"/>
				<language id="zh-tw" text="加殼類程式通常被病毒檔利用，通過混淆加殼的病毒程式，試圖欺騙或躲過殺毒軟體檢測"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="packed"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="packed"/>
			</matchrules>
		</class>
		
		<class defineid="8" name="Rootkit">
			<classname>
				<language id="zh-cn" text="内核类恶意驱动"/> 
				<language id="en-us" text="Rootkit"/> 
				<language id="zh-tw" text="內核類惡意驅動"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="内核模块类"/> 
				<language id="en-us" text="Rootkit"/>
				<language id="zh-tw" text="內核模組類"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="使用内核技术的恶意驱动文件会感染系统内核，同时造成无法手动清除无法清除的顽固病毒"/>
				<language id="en-us" text="Kernel Rootkits infect the operating system at the kernel-level, creating stubborn viruses that can't easily be removed"/>
				<language id="zh-tw" text="使用內核技術的惡意驅動檔會感染系統內核，同時造成無法手動清除無法清除的頑固病毒"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="rootkit"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="rootkit"/>
			</matchrules>
		</class>
		<class defineid="9" name="CoinMiner">
			<classname>
				<language id="zh-cn" text="挖矿木马"/> 
				<language id="en-us" text="Mining Trojan"/> 
				<language id="zh-tw" text="挖礦木馬"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="挖矿木马"/> 
				<language id="en-us" text="Mining Trojan"/>
				<language id="zh-tw" text="挖礦木馬"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="挖矿木马利用受害者计算机的运算力进行大量运算，由此获取数字货币，影响客户业务系统运行并消耗大量电力"/>
				<language id="en-us" text="Mining Trojan  uses the computing power of the victim's computer to perform a large number of operations,  consuming a large amount of power"/>
				<language id="zh-tw" text="挖礦木馬利用受害者電腦的運算力進行大量運算，由此獲取數位貨幣，影響客戶業務系統運行並消耗大量電力"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="contain" value="CoinMiner"/>
			</matchrules>
		</class>
		<class defineid="10" name="Trojan">
			<classname>
				<language id="zh-cn" text="木马"/> 
				<language id="en-us" text="Trojan"/> 
				<language id="zh-tw" text="木馬"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="木马"/> 
				<language id="en-us" text="Trojan"/>
				<language id="zh-tw" text="木馬"/>
			</describe>
			<risk>
				<language id="zh-cn" text="木马病毒通常会在系统中，偷偷下载病毒、上传敏感数据或破坏系统"/>
				<language id="en-us" text="Trojans typically secretly download viruses onto, upload sensitive data from, or otherwise damage the system their host system"/>
				<language id="zh-tw" text="木馬病毒通常會在系統中，偷偷下載病毒、上傳敏感性資料或破壞系統"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="in" value="other,trojan,heur,qq,risk,game,mir2,psw,wow,startpage,bho,mail,huigezi,email-flooder,im-flooder,sms-flooder,spamtool,generic,p2p,spoofer"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="trojan"/>
			</matchrules>
			<mobilevirus>true</mobilevirus>
		</class>

		<class defineid="11" name="Virus">
			<classname>
				<language id="zh-cn" text="病毒"/> 
				<language id="en-us" text="Virus"/> 
				<language id="zh-tw" text="病毒"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="能够破坏或感染其他文件的病毒"/> 
				<language id="en-us" text="Viruses typically damage or infect other files"/>
				<language id="zh-tw" text="能夠破壞或感染其他檔的病毒"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="病毒通常会通过感染系统中的文件来破坏计算机或计算机中的文件"/>
				<language id="en-us" text="Viruses usually damage systems and files through infecting other files on the system"/>
				<language id="zh-tw" text="病毒通常會通過感染系統中的檔來破壞電腦或電腦中的檔"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="in" value="virus,parite,viking,heretic,cih"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="virus"/>
			</matchrules>
		</class>
		
		<class defineid="12" name="Worm">
			<classname>
				<language id="zh-cn" text="蠕虫"/> 
				<language id="en-us" text="Worm"/> 
				<language id="zh-tw" text="蠕蟲"/>
			</classname>
			<describe> 
				<language id="zh-cn" text="具备网络传播能力的病毒"/> 
				<language id="en-us" text="Worm viruses can self-replicate and spread themselves through the net"/>
				<language id="zh-tw" text="具備網路傳播能力的病毒"/>
			</describe>
			<risk>
				<language id="zh-cn" text="蠕虫病毒通常会通过不停的获得网络中存在漏洞的计算机上的部分或全部控制权来进行传播并感染系统"/>
				<language id="en-us" text="Worm viruses spreads itself through networks, gaining control of all or part of the vulnerable systems on that network"/>
				<language id="zh-tw" text="蠕蟲病毒通常會通過不停的獲得網路中存在漏洞的電腦上的部分或全部控制權來進行傳播並感染系統"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="worm"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="worm"/>
			</matchrules>
			<mobilevirus>true</mobilevirus>
		</class>
		
		<class defineid="13" name="Exploit">
			<classname>
				<language id="zh-cn" text="漏洞攻击类"/> 
				<language id="en-us" text="Exploit"/> 
				<language id="zh-tw" text="漏洞攻擊類"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="利用漏洞的攻击程序"/> 
				<language id="en-us" text="A malicious program that takes advantage of security vulnerabilities"/>
				<language id="zh-tw" text="利用漏洞的攻擊程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="漏洞攻击程序通常会后台运行并利用本机的漏洞对系统进行漏洞攻击"/>
				<language id="en-us" text="Exploits run in the background and take advantages of security vulnerabilities in its host to cause damage"/>
				<language id="zh-tw" text="漏洞攻擊程式通常會後臺運行並利用本機的漏洞對系統進行漏洞攻擊"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="exploit"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="exploit"/>
			</matchrules>
			<mobilevirus>true</mobilevirus>
		</class>		
		
		<class defineid="14" name="BAT">
			<classname>
				<language id="zh-cn" text="脚本恶意文件"/> 
				<language id="en-us" text="BAT"/> 
				<language id="zh-tw" text="腳本惡意文件"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="非PE类,bat恶意程序"/> 
				<language id="en-us" text="Non-PE bat malware"/>
				<language id="zh-tw" text="非PE類,bat惡意程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="脚本恶意文件通常用于下载运行病毒木马程序，通过邮件附件、伪装链接等方式传播"/>
				<language id="en-us" text="BAT viruses typically operate by downloading and executing Trojans on system. They spread through email attachments and malicious links"/>
				<language id="zh-tw" text="腳本惡意檔通常用於下載運行病毒木馬程式，通過郵件附件、偽裝連結等方式傳播"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="bat"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="bat"/>
			</matchrules>
		</class>		
		
		<class defineid="15" name="TrojanDownloader">
			<classname>
				<language id="zh-cn" text="下载者"/> 
				<language id="en-us" text="TrojanDownloader"/> 
				<language id="zh-tw" text="下載者"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="下载恶意程序到本地执行"/> 
				<language id="en-us" text="These viruses download malwares onto the system and executes them locally"/>
				<language id="zh-tw" text="下載惡意程式到本地執行"/>
			</describe>
			<risk>
				<language id="zh-cn" text="下载者木马通常会在系统中运行并下载恶意程序到系统中，并感染系统"/>
				<language id="en-us" text="TrojanDownloaders typically download and execute malwares on a machine, eventually infecting and taking control of the system"/>
				<language id="zh-tw" text="下載者木馬通常會在系統中運行並下載惡意程式到系統中，並感染系統"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="downloader"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="downloader"/>
			</matchrules>
			<mobilevirus>true</mobilevirus>
		</class>
		
		<class defineid="16" name="Bootkit">
			<classname>
				<language id="zh-cn" text="修改启动分区的程序"/> 
				<language id="en-us" text="Bootkit"/> 
				<language id="zh-tw" text="修改開機磁碟分割的程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="MBR类型病毒"/> 
				<language id="en-us" text="MBR Virus"/>
				<language id="zh-tw" text="MBR類型病毒"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="磁盘主引导扇区病毒，感染硬盘的引导扇区或者主引导记录进行传播的病毒"/>
				<language id="en-us" text="Bootkit viruses infect a hard disk's boot sector and master boot record to spread through the system"/>
				<language id="zh-tw" text="磁片主引導磁區病毒，感染硬碟的引導磁區或者主引導記錄進行傳播的病毒"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="boot"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="boot"/>
			</matchrules>
		</class>		
		
		<class defineid="17" name="TrojanSpy">
			<classname>
				<language id="zh-cn" text="间谍程序"/> 
				<language id="en-us" text="TrojanSpy"/> 
				<language id="zh-tw" text="間諜程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="间谍软件"/> 
				<language id="en-us" text="TrojanSpy"/>
				<language id="zh-tw" text="間諜軟體"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="间谍木马通常会在系统后台运行并上传盗取系统中的敏感信息"/>
				<language id="en-us" text="TrojanSpy viruses run in the background, logging sensitive data from the system"/>
				<language id="zh-tw" text="間諜木馬通常會在系統後臺運行並上傳盜取系統中的敏感資訊"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="spyware"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="spyware"/>
			</matchrules>
			<mobilevirus>true</mobilevirus>
		</class>		
		
		<class defineid="18" name="Dos">
			<classname>
				<language id="zh-cn" text="拒绝服务类程序"/> 
				<language id="en-us" text="DoS"/> 
				<language id="zh-tw" text="拒絕服務類程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="拒绝服务工具"/> 
				<language id="en-us" text="DoS"/>
				<language id="zh-tw" text="拒絕服務工具"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="拒绝服务类病毒通常通过对网络上某台计算机大量发送请求，使计算机成为网络僵尸傀儡主机，造成该机器繁忙，无法正常工作"/>
				<language id="en-us" text="DoS (Denial of Service) attacks typically send a large number of requests to a server from a network of bots, knocking it out of service or making it unable to function normally"/>
				<language id="zh-tw" text="拒絕服務類病毒通常通過對網路上某台電腦大量發送請求，使電腦成為網路僵屍傀儡主機，造成該機器繁忙，無法正常工作"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="dos"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="dos"/>
			</matchrules>
		</class>		
		
		<class defineid="19" name="Flooder">
			<classname>
				<language id="zh-cn" text="泛洪攻击类程序"/> 
				<language id="en-us" text="Flooder"/> 
				<language id="zh-tw" text="泛洪攻擊類程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="泛洪攻击工具"/> 
				<language id="en-us" text="Flooder"/>
				<language id="zh-tw" text="泛洪攻擊工具"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="泛洪攻击类病毒通常采用发送洪水封包的方式攻击目标IP，导致该节点瘫痪或制造大量垃圾文件，使用户系统变慢甚至无法响应"/>
				<language id="en-us" text="Flooders usually attack target IPs by sending a flood of network packets, paralyzing the node or creating a litany of junk files. This severely slows the system or renders it completely unresponsive"/>
				<language id="zh-tw" text="泛洪攻擊類病毒通常採用發送洪水封包的方式攻擊目標IP，導致該節點癱瘓或製造大量垃圾檔，使使用者系統變慢甚至無法回應"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="flooder"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="flooder"/>
			</matchrules>
		</class>
		<class defineid="20" name="TrojanBanker">
			<classname>
				<language id="zh-cn" text="网银木马"/> 
				<language id="en-us" text="TrojanBanker"/> 
				<language id="zh-tw" text="網銀木馬"/>
			</classname>
			<describe> 
				<language id="zh-cn" text="网银木马"/> 
				<language id="en-us" text="Trojan.Banker"/>
				<language id="zh-tw" text="網銀木馬"/>
			</describe>
			<risk>
				<language id="zh-cn" text="网银木马通常会在系统中运行，并劫持用户访问网银类网站，实现盗取银行或支付账号的行为"/>
				<language id="en-us" text="TrojanBanker viruses run in the background and hijack user access to online banking websites, stealing bank accounts and other payment info"/>
				<language id="zh-tw" text="網銀木馬通常會在系統中運行，並劫持用戶訪問網銀類網站，實現盜取銀行或支付帳號的行為"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="bank"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="bank"/>
			</matchrules>
			<mobilevirus>true</mobilevirus>
		</class>		
		
		<class defineid="21" name="Plugin">
			<classname>
				<language id="zh-cn" text="外挂类程序"/> 
				<language id="en-us" text="Plugin"/> 
				<language id="zh-tw" text="外掛類程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="外挂类程序"/> 
				<language id="en-us" text="Plugin"/>
				<language id="zh-tw" text="外掛類程式"/>
			</describe>
			<risk>
				<language id="zh-cn" text="外挂类程序通常是第三方游戏或工具的辅助软件，经常会被黑客用来传播木马病毒"/>
				<language id="en-us" text="Plugins are typically third-party software for video games or other tools. They are often used by hackers to spread Trojans"/>
				<language id="zh-tw" text="外掛類程式通常是協力廠商遊戲或工具的輔助軟體，經常會被駭客用來傳播木馬病毒"/>
			</risk>
			<matchrules>
				<item scannerid="1" name="qce"  field="cloud_malware_class" type="string" match="equal" value="waigua"/>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="waigua"/>
			</matchrules>
		</class>		
						
		<class defineid="22" name="VirusOrg">
			<classname>
				<language id="zh-cn" text="病毒源"/> 
				<language id="en-us" text="VirusOrg"/> 
				<language id="zh-tw" text="病毒源"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="产生Virus（感染型病毒）的程序"/> 
				<language id="en-us" text="A program capable of spawning viruses"/>
				<language id="zh-tw" text="產生Virus（感染型病毒）的程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="病毒源通常会在系统中产生感染型病毒，并且通过感染型病毒再感染其他文件"/>
				<language id="en-us" text="These programs spawn viruses which will then set out to infect and take control of the host system"/>
				<language id="zh-tw" text="病毒源通常會在系統中產生感染型病毒，並且通過感染型病毒再感染其他檔"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="virusorg"/>
			</matchrules>
		</class>		
	
		<class defineid="23" name="TrojanClicker">
			<classname>
				<language id="zh-cn" text="流量劫持类程序"/> 
				<language id="en-us" text="TrojanClicker"/> 
				<language id="zh-tw" text="流量劫持類程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="涉及到恶意点击以刷流量类型的恶意程序"/> 
				<language id="en-us" text="TrojanClickers use their host system to generate clicks and traffic"/>
				<language id="zh-tw" text="涉及到惡意點擊以刷流量類型的惡意程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="流量劫持木马通常会在系统后台运行，劫持用户访问的网站加入广告并模拟点击从而达到其盈利的目的"/>
				<language id="en-us" text="TrojanClickers run in the background, adding malicious ads to visited websites and simulating clicks to generate ad revenue"/>
				<language id="zh-tw" text="流量劫持木馬通常會在系統後臺運行，劫持使用者訪問的網站加入廣告並模擬點擊從而達到其盈利的目的"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="contain" value="trojanclicker"/>
			</matchrules>
			<mobilevirus>true</mobilevirus>
		</class>		
		
		<class defineid="24" name="TrojanProxy">
			<classname>
				<language id="zh-cn" text="代理型木马"/> 
				<language id="en-us" text="TrojanProxy"/> 
				<language id="zh-tw" text="代理型木馬"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="可以让攻击者以本机为跳板的恶意工具"/> 
				<language id="en-us" text="A malicious program that allows attackers to use its host system as a proxy"/>
				<language id="zh-tw" text="可以讓攻擊者以本機為跳板的惡意工具"/>
			</describe>
			<risk>
				<language id="zh-cn" text="代理型木马通常是运行在系统中，让攻击者通过本系统作为跳板去攻击其它系统"/>
				<language id="en-us" text="TrojanProxy viruses run in the background, allowing their source to use their host system as a proxy to attack other systems"/>
				<language id="zh-tw" text="代理型木馬通常是運行在系統中，讓攻擊者通過本系統作為跳板去攻擊其它系統"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="contain" value="trojanproxy"/>
			</matchrules>
		</class>

		<class defineid="25" name="TrojanDailer">
			<classname>
				<language id="zh-cn" text="拨号型木马"/> 
				<language id="en-us" text="TrojanDailer"/> 
				<language id="zh-tw" text="撥號型木馬"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="拨号类型木马"/> 
				<language id="en-us" text="TrojanDialer"/>
				<language id="zh-tw" text="撥號類型木馬"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="拨号型木马通常会在后台启动并通过拨号的方式拨号远程拨号服务器，从而产生高额的费用"/>
				<language id="en-us" text="TrojanDialers operate in the background, using the system to dial long-distance dial-up servers, causing the network owner to incur high dial fees"/>
				<language id="zh-tw" text="撥號型木馬通常會在後臺啟動並通過撥號的方式撥號遠端撥號伺服器，從而產生高額的費用"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="contain" value="trojandailer"/>
			</matchrules>
		</class>

		<class defineid="26" name="TrojanKeylogger">
			<classname>
				<language id="zh-cn" text="键盘记录器"/> 
				<language id="en-us" text="TrojanKeylogger"/> 
				<language id="zh-tw" text="鍵盤記錄器"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="键盘记录器"/> 
				<language id="en-us" text="TrojanKeylogger"/>
				<language id="zh-tw" text="鍵盤記錄器"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="键盘记录器木马通常会在系统中劫持系统键盘，从而记录输入内容来获取隐私信息"/>
				<language id="en-us" text="TrojanKeyloggers hijack a system's keyboard and records its inputs to log sensitive information"/>
				<language id="zh-tw" text="鍵盤記錄器木馬通常會在系統中劫持系統鍵盤，從而記錄輸入內容來獲取隱私資訊"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="contain" value="trojankeylogger"/>
			</matchrules>
		</class>		
	
		<class defineid="27" name="DDOS">
			<classname>
				<language id="zh-cn" text="分布式拒绝服务类程序"/> 
				<language id="en-us" text="DDoS"/> 
				<language id="zh-tw" text="分散式拒絕服務類程式"/>
			</classname>
			<describe> 
				<language id="zh-cn" text="分布式拒绝服务工具"/> 
				<language id="en-us" text="DDoS"/>
				<language id="zh-tw" text="分散式拒絕服務工具"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="拒绝服务类病毒通常通过对网络上某台计算机大量发送请求，使计算机成为网络僵尸傀儡主机，造成该机器繁忙，无法正常工作"/>
				<language id="en-us" text="DDoS (Distributed Denial of Service) attacks typically send a large number of requests to a server from a network of bots, knocking it out of service or making it unable to function normally"/>
				<language id="zh-tw" text="拒絕服務類病毒通常通過對網路上某台電腦大量發送請求，使電腦成為網路僵屍傀儡主機，造成該機器繁忙，無法正常工作"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="ddos"/>
			</matchrules>
		</class>
		
		<class defineid="28" name="PUA">
			<classname>
				<language id="zh-cn" text="具有潜在风险的程序"/> 
				<language id="en-us" text="PUA"/> 
				<language id="zh-tw" text="具有潛在風險的程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="Potentially Unwanted Application"/> 
				<language id="en-us" text="Potentially Unwanted Application"/>
				<language id="zh-tw" text="Potentially Unwanted Application"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="具有潜在风险的程序通常具有可能破坏计算机系统的可能"/>
				<language id="en-us" text="Potentially Unwanted Applications often have the potential to damage host systems"/>
				<language id="zh-tw" text="具有潛在風險的程式通常具有可能破壞電腦系統的可能"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="pua"/>
			</matchrules>
		</class>

		<class defineid="29" name="Ransom">
			<classname>
				<language id="zh-cn" text="勒索"/> 
				<language id="en-us" text="Ransom"/> 
				<language id="zh-tw" text="勒索"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="勒索类程序"/> 
				<language id="en-us" text="Ransomware"/>
				<language id="zh-tw" text="勒索類程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="勒索病毒通常依靠入侵系统，并将系统中使用高强度的加密方法对文件进行加密，从而达到敲诈勒索的目的"/>
				<language id="en-us" text="Ransomware invades a system, using high-strength encryption to render certain files inaccessible for the purposes of extortion"/>
				<language id="zh-tw" text="勒索病毒通常依靠入侵系統，並將系統中使用高強度的加密方法對檔進行加密，從而達到敲詐勒索的目的"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="ransom"/>
			</matchrules>
		</class>		

		<class defineid="30" name="Rogue">
			<classname>
				<language id="zh-cn" text="虚假告警类程序"/> 
				<language id="en-us" text="Rogue"/> 
				<language id="zh-tw" text="虛假告警類程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="恐吓用户，声明并不存在的威胁"/> 
				<language id="en-us" text="Attempts to scare users with nonexistent threats"/>
				<language id="zh-tw" text="恐嚇用戶，聲明並不存在的威脅"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="虚假告警通常通过虚假的告警弹窗或广告来恐吓诱导用户去点击或下载某些程序"/>
				<language id="en-us" text="Rogues will attempt to scare users into clicking on certain pages or downloading certain programs through alarming pop-ups or advertisements"/>
				<language id="zh-tw" text="虛假告警通常通過虛假的告警彈窗或廣告來恐嚇誘導用戶去點擊或下載某些程式"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="rogue"/>
			</matchrules>
		</class>

		<class defineid="31" name="Spammer">
			<classname>
				<language id="zh-cn" text="被滥用的程序"/> 
				<language id="en-us" text="Spammer"/> 
				<language id="zh-tw" text="被濫用的程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="垃圾邮件制造者"/> 
				<language id="en-us" text="Spammer"/>
				<language id="zh-tw" text="垃圾郵件製造者"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="被滥用的程序通常是某个正规的程序，但是被某些不法分子非法利用来实现某些恶意的行为的程序"/>
				<language id="en-us" text="Spammers are typically non-malicious programs that have been hijacked by hackers to achieve malicious ends"/>
				<language id="zh-tw" text="被濫用的程式通常是某個正規的程式，但是被某些不法分子非法利用來實現某些惡意的行為的程式"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="spammer"/>
			</matchrules>
		</class>
		
		<class defineid="32" name="HTML">
			<classname>
				<language id="zh-cn" text="网页恶意文件"/> 
				<language id="en-us" text="HTML"/> 
				<language id="zh-tw" text="網頁惡意文件"/>
			</classname>
			<describe> 
				<language id="zh-cn" text="非PE类, HTML恶意程序"/> 
				<language id="en-us" text="Non-PE HTML malware"/>
				<language id="zh-tw" text="非PE類, HTML惡意程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="恶意html网页意文件通常用于用于传播欺诈钓鱼，恶意木马。使访问者受骗上当或下载恶意文件"/>
				<language id="en-us" text="Malicious HTML webpages are typically used to spread phishing links and Trojans. This is achieved by tricking visitors or downloading malicious files"/>
				<language id="zh-tw" text="惡意html網頁意檔通常用於用於傳播欺詐釣魚，惡意木馬。使訪問者受騙上當或下載惡意檔"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="html"/>
			</matchrules>
		</class>

		<class defineid="33" name="JS">
			<classname>
				<language id="zh-cn" text="脚本恶意文件"/> 
				<language id="en-us" text="JS"/> 
				<language id="zh-tw" text="腳本惡意文件"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="非PE类,Javascript恶意程序"/> 
				<language id="en-us" text="Non-PE Javascript malware"/>
				<language id="zh-tw" text="非PE類,Javascript惡意程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="脚本恶意文件通常用于下载运行病毒木马程序，通过邮件附件、伪装链接等方式传播"/>
				<language id="en-us" text="Javascript viruses typically operate by downloading and executing Trojans on system. They spread through email attachments and malicious links"/>
				<language id="zh-tw" text="腳本惡意檔通常用於下載運行病毒木馬程式，通過郵件附件、偽裝連結等方式傳播"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="js"/>
			</matchrules>
		</class>

		<class defineid="34" name="VBS">
			<classname>
				<language id="zh-cn" text="脚本恶意文件"/> 
				<language id="en-us" text="VBS"/> 
				<language id="zh-tw" text="腳本惡意文件"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="非PE类,VBS恶意程序"/> 
				<language id="en-us" text="Non-PE VBS malware"/>
				<language id="zh-tw" text="非PE類,VBS惡意程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="脚本恶意文件通常用于下载运行病毒木马程序，通过邮件附件、伪装链接等方式传播"/>
				<language id="en-us" text="VBS viruses typically operate by downloading and executing Trojans on system. They spread through email attachments and malicious links"/>
				<language id="zh-tw" text="腳本惡意檔通常用於下載運行病毒木馬程式，通過郵件附件、偽裝連結等方式傳播"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="vbs"/>
			</matchrules>
		</class>

		<class defineid="35" name="POWERSHELL">
			<classname>
				<language id="zh-cn" text="脚本恶意文件"/> 
				<language id="en-us" text="POWERSHELL"/> 
				<language id="zh-tw" text="腳本惡意文件"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="非PE类,PowerShell恶意程序"/> 
				<language id="en-us" text="Non-PE PowerShell malware"/>
				<language id="zh-tw" text="非PE類,PowerShell惡意程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="脚本恶意文件通常用于下载运行病毒木马程序，通过邮件附件、伪装链接等方式传播"/>
				<language id="en-us" text="PowerShell viruses typically operate by downloading and executing Trojans on system. They spread through email attachments and malicious links"/>
				<language id="zh-tw" text="腳本惡意檔通常用於下載運行病毒木馬程式，通過郵件附件、偽裝連結等方式傳播"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="powershell"/>
			</matchrules>
		</class>
		
		<class defineid="36" name="BASH">
			<classname>
				<language id="zh-cn" text="脚本恶意文件"/> 
				<language id="en-us" text="BASH"/> 
				<language id="zh-tw" text="腳本惡意文件"/>
			</classname>
			<describe> 
				<language id="zh-cn" text="非PE类,Bash脚本恶意程序"/> 
				<language id="en-us" text="Non-PE Bash malware"/>
				<language id="zh-tw" text="非PE類,Bash腳本惡意程式"/>
			</describe>
			<risk>
				<language id="zh-cn" text="脚本恶意文件通常用于下载运行病毒木马程序，通过邮件附件、伪装链接等方式传播"/>
				<language id="en-us" text="Bash viruses typically operate by downloading and executing Trojans on system. They spread through email attachments and malicious links"/>
				<language id="zh-tw" text="腳本惡意檔通常用於下載運行病毒木馬程式，通過郵件附件、偽裝連結等方式傳播"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="bash"/>
			</matchrules>
		</class>
		
		<class defineid="37" name="Macro">
			<classname>
				<language id="zh-cn" text="宏病毒"/> 
				<language id="en-us" text="Macro"/> 
				<language id="zh-tw" text="巨集病毒"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="宏病毒"/> 
				<language id="en-us" text="Macro virus"/>
				<language id="zh-tw" text="巨集病毒"/>  
			</describe>
			<risk>
				<language id="zh-cn" text="宏病毒通常包含在办公类文件中，主要功能包括感染其他办公类文件或下载其他恶意程序并执行"/>
				<language id="en-us" text="Macro viruses are normally found within office files. They are typically used to infect other office files or to download and execute other malware"/>
				<language id="zh-tw" text="巨集病毒通常包含在辦公類檔中，主要功能包括感染其他辦公類檔或下載其他惡意程式並執行"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="macro"/>
			</matchrules>
		</class>

		<class defineid="38" name="Lnk">
			<classname>
				<language id="zh-cn" text="危险的快捷方式命令行"/> 
				<language id="en-us" text="Lnk"/> 
				<language id="zh-tw" text="危險的快捷方式命令列"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="快捷方式命令行及参数中包含恶意动作或指向恶意程序"/> 
				<language id="en-us" text="Lnk files and parameters may contain malicious operations or links to other malware"/>
				<language id="zh-tw" text="快捷方式命令列及參數中包含惡意動作或指向惡意程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="危险的快捷方式通常指向恶意程序或执行恶意的命令行，错误执行后可能导致系统被执行恶意程序或恶意脚本"/>
				<language id="en-us" text="Malicious Lnk files typically link to malware or execute malicious command line operations. Using these files without proper care may execute malware or script commands"/>
				<language id="zh-tw" text="危險的快捷方式通常指向惡意程式或執行惡意的命令列，錯誤執行後可能導致系統被執行惡意程式或惡意腳本"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="lnk"/>
			</matchrules>
		</class>	
		
		<class defineid="39" name="Trojan.Generic.B">
			<classname>
				<language id="zh-cn" text="禁止访问的程序"/> 
				<language id="en-us" text="Trojan.Generic.B"/> 
				<language id="zh-tw" text="禁止訪問的程式"/>
			</classname>
			<describe> 
				<language id="zh-cn" text="可能会给系统或电脑造成危害的禁止访问的程序"/> 
				<language id="en-us" text="Trojan.Generic.B programs may cause damage to a computer or system"/>
				<language id="zh-tw" text="可能會給系統或電腦造成危害的禁止訪問的程式"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="禁止访问的程序可能会对系统造成损害，影响系统的或程序正常运行"/>
				<language id="en-us" text="Trojan.Generic.B programs may cause damage to a system, affecting the normal operation of a machine or program"/>
				<language id="zh-tw" text="禁止訪問的程式可能會對系統造成損害，影響系統的或程式正常運行"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="Trojan.Generic.B"/>
			</matchrules>
		</class>
		
		<class defineid="40" name="TrojanPWS">
			<classname>
				<language id="zh-cn" text="窃密类程序"/> 
				<language id="en-us" text="TrojanPWS"/> 
				<language id="zh-tw" text="竊密類程式"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="盗窃凭证信息的恶意程序"/> 
				<language id="en-us" text="TrojanPWS malware steal sensitive credential data"/>
				<language id="zh-tw" text="盜竊憑證資訊的惡意程式"/>
			</describe>
			<risk>
				<language id="zh-cn" text="窃密类型程序运行后通常会窃取系统中的凭证信息，从而导致您的重要信息泄露"/>
				<language id="en-us" text="TrojanPWS viruses steal sensitive credential data found on the systems they are executed in, typically resulting in the compromise of important personal information"/>
				<language id="zh-tw" text="竊密類型程式運行後通常會竊取系統中的憑證資訊，從而導致您的重要資訊洩露"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="TrojanPWS"/>
			</matchrules>
		</class>
		
		<class defineid="41" name="Riskware">
			<classname>
				<language id="zh-cn" text="风险应用"/> 
				<language id="en-us" text="Riskware"/> 
				<language id="zh-tw" text="風險應用"/> 
			</classname>
			<describe> 
				<language id="zh-cn" text="风险的应用"/> 
				<language id="en-us" text="Risky Application"/>
				<language id="zh-tw" text="風險的應用"/> 
			</describe>
			<risk>
				<language id="zh-cn" text="该应用具有潜在风险的程序，使用可能会带来一定的损失"/>
				<language id="en-us" text="This application is a potentially risky program which may cause certain damage"/>
				<language id="zh-tw" text="該應用具有潛在風險的程式，使用可能會帶來一定的損失"/>
			</risk>
			<matchrules>
				<item scannerid="2" name="qowl" field="virus_name" type="string" match="begin" value="Riskware"/>
			</matchrules>
		</class>
		
	</virusclasses>
</profile>