ProtocolFilter
Detects protocol filters.
Usage
ProtocolFilter:<protocl name>,<class guid>[,advanced file parameters]
Examples
ProtocolFilter:"SBI Test Entry 1","{CAFFEE60-1234-1234-1234-581735711111}","filesize>=1"
Description
- Specify name of filter first. Use an Algo-Prefix if you want. AP
- Continue by the associated class ID, which also needs to be matched. Use an Algo-Prefix if you want. AP
- To further limit the detection, you can specify advanced file parameters for the file associated with the protocol filter.
Scan Results
- The protocol filter registry key.
- The associated CLSID, if found.
- The file (usually a library) used by the protocol filter, but only if advanced file parameters were specified.