home *** CD-ROM | disk | FTP | other *** search
/ Clickx 23 / Clickx 23.iso / DATA / zlsSetup_60_667_000.exe / OSFWRULES_SWITCH.XML < prev    next >
Encoding:
Extensible Markup Language  |  2005-08-29  |  191.2 KB  |  1,916 lines

  1. <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
  2. <!-- Localization comment.  The locale tag for Japanese is supposed to be reversed from the standard.
  3.      that is, it should be jp-JA to work with our application. -->
  4. <ZoneLabsSettings version="1.0">
  5.     <ruleset start="afterstartup" name="runningruleset" stop="onshutdown">
  6.         <applications>
  7.             <default appsec="AskSD"/>
  8.             <osfirewall>
  9.                 <!-- Severity (and promotion/demotion) of customized OSFW Events -->
  10.                 <severity name="normal" rating="low" >
  11.                     <messages type="osfwSeverityDescription" value="normal behavior" locale="en-US" />
  12.                     <messages type="osfwSeverityDescription" value="normale Verhaltensweisen" locale="de-DE" />
  13.                     <messages type="osfwSeverityDescription" value="comportement normal" locale="fr-FR" />
  14.                     <messages type="osfwSeverityDescription" value="µ¡úσ╕╕πü¬σïòΣ╜£" locale="jp-JA" />
  15.                     <messages type="osfwSeverityDescription" value="actividad normal" locale="es-ES" />
  16.                     <messages type="osfwSeverityDescription" value="comportamento normale" locale="it-IT" />
  17.  
  18.                 </severity>
  19.  
  20.                 <severity name="suspicious" rating="medium" >
  21.                     <messages type="osfwSeverityDescription" value="suspicious behavior" locale="en-US" />
  22.                     <messages type="osfwSeverityDescription" value="verd├ñchtige Verhaltensweisen" locale="de-DE" />
  23.                     <messages type="osfwSeverityDescription" value="comportement normal" locale="fr-FR" />
  24.                     <messages type="osfwSeverityDescription" value="τûæπéÅπüùπüäσïòΣ╜£" locale="jp-JA" />
  25.                     <messages type="osfwSeverityDescription" value="actividad sospechosa" locale="es-ES" />
  26.                     <messages type="osfwSeverityDescription" value="comportamento sospetto" locale="it-IT" />
  27.                     <promotion    from="AskSDenyD"    to="AllowSDenyD" />
  28.                     <promotion    from="AskSD"        to="AllowSAskD" />
  29.                     <demotion    from="AskSDenyD"    to="DenySD" />
  30.                     <demotion    from="AskSD"        to="DenySD" />
  31.                 </severity>
  32.  
  33.                 <severity name="dangerous" rating="high" >
  34.                     <messages type="osfwSeverityDescription" value="dangerous behavior" locale="en-US" />
  35.                     <messages type="osfwSeverityDescription" value="gef├ñhrliche Verhaltensweisen" locale="de-DE" />
  36.                     <messages type="osfwSeverityDescription" value="comportement dangereux" locale="fr-FR" />
  37.                     <messages type="osfwSeverityDescription" value="σì▒ΘÖ║πü¬σïòΣ╜£" locale="jp-JA" />
  38.                     <messages type="osfwSeverityDescription" value="actividad peligrosa" locale="es-ES" />
  39.                     <messages type="osfwSeverityDescription" value="comportamento pericoloso" locale="it-IT" />
  40.                     <promotion    from="AskSD"        to="AllowSD" />
  41.                     <promotion    from="AllowSAskD"    to="AllowSD" />
  42.                     <demotion    from="AskSD"        to="AskSDenyD" />
  43.                     <demotion    from="AllowSAskD"    to="AllowSDenyD" />
  44.                 </severity>
  45.  
  46.                 <severity name="malicious" rating="high" >
  47.                     <messages type="osfwSeverityDescription" value="malicious behavior" locale="en-US" />
  48.                     <messages type="osfwSeverityDescription" value="b├╢sartige Verhaltensweisen" locale="de-DE" />
  49.                     <messages type="osfwSeverityDescription" value="comportement malveillant" locale="fr-FR" />
  50.                     <messages type="osfwSeverityDescription" value="σì▒ΘÖ║πü¬σïòΣ╜£" locale="jp-JA" />
  51.                     <messages type="osfwSeverityDescription" value="actividad maligna" locale="es-ES" />
  52.                     <messages type="osfwSeverityDescription" value="comportamento dannoso" locale="it-IT" />
  53.                 </severity>
  54.  
  55.                 <!-- Customization of Raw OSFW Events 
  56.  
  57.                      Note that customevent id numbers are used by AA, so they must not be changed or
  58.                      reused.
  59.                 -->
  60.  
  61.                     <!-- "miscellaneous" events (1001-1999) -->
  62.  
  63.                 <customevent id="1001" severityref="malicious" >
  64.                     <messages type="osfwPresentText" value="Warning! %process_name% is a malicious program and is trying to run on your computer" locale="en-US" />
  65.                     <messages type="osfwPastText" value="%process_name% is a malicious program and was trying to run on your computer" locale="en-US" />
  66.                     <messages type="osfwBlockedText" value="%process_name% is a malicious program and was prevented from running on your computer" locale="en-US" />
  67.                     <messages type="osfwPresentText" value="Warnung! %process_name% ist ein b├╢sartiges Programm, das versucht, sich auf Ihrem Computer auszuf├╝hren." locale="de-DE" />
  68.                     <messages type="osfwPastText" value="%process_name% ist ein b├╢sartiges Programm, das versucht hat, sich auf Ihrem Computer auszuf├╝hren." locale="de-DE" />
  69.                     <messages type="osfwBlockedText" value="%process_name% ist ein b├╢sartiges Programm, das daran gehindert wurde, sich auf Ihrem Computer auszuf├╝hren." locale="de-DE" />
  70.                     <messages type="osfwPresentText" value="Avertissement ! %process_name% est un programme malveillant qui tente de s'ex├⌐cuter sur votre ordinateur" locale="fr-FR" />
  71.                     <messages type="osfwPastText" value="%process_name% est un programme malveillant et a tent├⌐ de s'ex├⌐cuter sur votre ordinateur" locale="fr-FR" />
  72.                     <messages type="osfwBlockedText" value="%process_name% est un programme malveillant et n'a pas r├⌐ussi ├á s'ex├⌐cuter sur votre ordinateur" locale="fr-FR" />
  73.                     <messages type="osfwPresentText" value="Φ¡ªσæè ! %process_name% πü¿πüäπüåµé¬µäÅπü«πüéπéïπâùπâ¡πé░πâ⌐πâáπüîπé│πâ│πâöπâÑπâ╝πé┐Σ╕èπüºσ«ƒΦíîπéÆΦ⌐ªπü┐πüªπüäπü╛πüÖ" locale="jp-JA" />
  74.                     <messages type="osfwPastText" value="%process_name% πü¿πüäπüåµé¬µäÅπü«πüéπéïπâùπâ¡πé░πâ⌐πâáπüîπé│πâ│πâöπâÑπâ╝πé┐Σ╕èπüºσ«ƒΦíîπéÆΦ⌐ªπü┐πüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  75.                     <messages type="osfwBlockedText" value="%process_name% πü¿πüäπüåµé¬µäÅπü«πüéπéïπâùπâ¡πé░πâ⌐πâáπü«πé│πâ│πâöπâÑπâ╝πé┐Σ╕èπüºπü«σ«ƒΦíîπüîΘÿ▓µ¡óπüòπéîπü╛πüùπüƒ" locale="jp-JA" />
  76.                     <messages type="osfwPresentText" value="Advertencia: %process_name% es un programa maligno y est├í intentando ejecutarse en el equipo" locale="es-ES" />
  77.                     <messages type="osfwPastText" value="%process_name% es un programa maligno y ha intentando ejecutarse en el equipo" locale="es-ES" />
  78.                     <messages type="osfwBlockedText" value="%process_name% es un programa maligno y se ha impedido su ejecuci├│n en el equipo" locale="es-ES" />
  79.                     <messages type="osfwPresentText" value="Avviso! %process_name% ├¿ un programma dannoso e sta cercando di essere eseguito sul computer" locale="it-IT" />
  80.                     <messages type="osfwPastText" value="%process_name% ├¿ un programma dannoso e ha cercato di essere eseguito sul computer" locale="it-IT" />
  81.                     <messages type="osfwBlockedText" value="%process_name% ├¿ un programma dannoso ed ├¿ stata impedita la sua esecuzione sul computer" locale="it-IT" />
  82.                 </customevent>
  83.  
  84.                     <!-- "malicious" behavior (2001-2999) -->
  85.  
  86.                 <customevent id="2001" severityref="malicious" >
  87.                     <messages type="osfwPresentText" value="Warning! %process_name% is a malicious program and is trying to run on your computer" locale="en-US" />
  88.                     <messages type="osfwPastText" value="%process_name% is a malicious program and was trying to run on your computer" locale="en-US" />
  89.                     <messages type="osfwBlockedText" value="%process_name% is a malicious program and was prevented from running on your computer" locale="en-US" />
  90.                     <messages type="osfwPresentText" value="Warnung! %process_name% ist ein b├╢sartiges Programm, das versucht, sich auf Ihrem Computer auszuf├╝hren." locale="de-DE" />
  91.                     <messages type="osfwPastText" value="%process_name% ist ein b├╢sartiges Programm, das versucht hat, sich auf Ihrem Computer auszuf├╝hren." locale="de-DE" />
  92.                     <messages type="osfwBlockedText" value="%process_name% ist ein b├╢sartiges Programm, das daran gehindert wurde, sich auf Ihrem Computer auszuf├╝hren." locale="de-DE" />
  93.                     <messages type="osfwPresentText" value="Avertissement ! %process_name% est un programme malveillant qui tente de s'ex├⌐cuter sur votre ordinateur" locale="fr-FR" />
  94.                     <messages type="osfwPastText" value="%process_name% est un programme malveillant et a tent├⌐ de s'ex├⌐cuter sur votre ordinateur" locale="fr-FR" />
  95.                     <messages type="osfwBlockedText" value="%process_name% est un programme malveillant et n'a pas r├⌐ussi ├á s'ex├⌐cuter sur votre ordinateur" locale="fr-FR" />
  96.                     <messages type="osfwPresentText" value="Φ¡ªσæè ! %process_name% πü¿πüäπüåµé¬µäÅπü«πüéπéïπâùπâ¡πé░πâ⌐πâáπüîπé│πâ│πâöπâÑπâ╝πé┐Σ╕èπüºσ«ƒΦíîπéÆΦ⌐ªπü┐πüªπüäπü╛πüÖ" locale="jp-JA" />
  97.                     <messages type="osfwPastText" value="%process_name% πü¿πüäπüåµé¬µäÅπü«πüéπéïπâùπâ¡πé░πâ⌐πâáπüîπé│πâ│πâöπâÑπâ╝πé┐Σ╕èπüºσ«ƒΦíîπéÆΦ⌐ªπü┐πüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  98.                     <messages type="osfwBlockedText" value="%process_name% πü¿πüäπüåµé¬µäÅπü«πüéπéïπâùπâ¡πé░πâ⌐πâáπü«πé│πâ│πâöπâÑπâ╝πé┐Σ╕èπüºπü«σ«ƒΦíîπüîΘÿ▓µ¡óπüòπéîπü╛πüùπüƒ" locale="jp-JA" />
  99.                     <messages type="osfwPresentText" value="Advertencia: %process_name% es un programa maligno y est├í intentando ejecutarse en el equipo" locale="es-ES" />
  100.                     <messages type="osfwPastText" value="%process_name% es un programa maligno y ha intentando ejecutarse en el equipo" locale="es-ES" />
  101.                     <messages type="osfwBlockedText" value="%process_name% es un programa maligno y se ha impedido su ejecuci├│n en el equipo" locale="es-ES" />
  102.                     <messages type="osfwPresentText" value="Avviso! %process_name% ├¿ un programma dannoso e sta cercando di essere eseguito sul computer" locale="it-IT" />
  103.                     <messages type="osfwPastText" value="%process_name% ├¿ un programma dannoso e ha cercato di essere eseguito sul computer" locale="it-IT" />
  104.                     <messages type="osfwBlockedText" value="%process_name% ├¿ un programma dannoso ed ├¿ stata impedita la sua esecuzione sul computer" locale="it-IT" />
  105.                 </customevent>
  106.                 <customevent id="2002" severityref="malicious" >
  107.                     <messages type="osfwPresentText" value="%process_name% is trying to change the behavior of %product_name% by modifying the file: %file%" locale="en-US" />
  108.                     <messages type="osfwPastText" value="%process_name% was trying to change the behavior of %product_name% by modifying the file: %file%" locale="en-US" />
  109.                     <messages type="osfwBlockedText" value="%process_name% was prevented from changing the behavior of %product_name% by modifying the file: %file%" locale="en-US" />
  110.                     <messages type="osfwPresentText" value="%process_name% versucht, die Verhaltensweise von %product_name% durch Modifizierung der folgenden Datei zu ├ñndern: %file%" locale="de-DE" />
  111.                     <messages type="osfwPastText" value="%process_name% hat versucht, die Verhaltensweise von %product_name% durch Modifizierung der folgenden Datei zu ├ñndern: %file%" locale="de-DE" />
  112.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, die Verhaltensweise von %product_name% durch Modifizierung der folgenden Datei zu ├ñndern: %file%" locale="de-DE" />
  113.                     <messages type="osfwPresentText" value="%process_name% tente de modifier le comportement de %product_name% en modifiant le fichier suivant : %file%" locale="fr-FR" />
  114.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de modifier le comportement de %product_name% en modifiant le fichier suivant : %file%" locale="fr-FR" />
  115.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á modifier le comportement de %product_name% en modifiant le fichier suivant : %file%" locale="fr-FR" />
  116.                     <messages type="osfwPresentText" value="%process_name% πüîµ¼íπü«πâòπéíπéñπâ½π鯵¢╕πüìµ¢┐πüêπüª %product_name% πü«σïòΣ╜£πéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ:%file%" locale="jp-JA" />
  117.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâòπéíπéñπâ½π鯵¢╕πüìµ¢┐πüêπüª %product_name% πü«σïòΣ╜£πéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ:%file%" locale="jp-JA" />
  118.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâòπéíπéñπâ½π鯵¢╕πüìµ¢┐πüêπüª %product_name% πü«σïòΣ╜£πéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ:%file%" locale="jp-JA" />
  119.                     <messages type="osfwPresentText" value="%process_name% est├í intentando cambiar el comportamiento de %product_name% mediante la modificaci├│n del archivo: %file%" locale="es-ES" />
  120.                     <messages type="osfwPastText" value="%process_name% ha intentado cambiar el comportamiento de %product_name% mediante la modificaci├│n del archivo: %file%" locale="es-ES" />
  121.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% cambie el comportamiento de %product_name% mediante la modificaci├│n del archivo: %file%" locale="es-ES"/>
  122.                     <messages type="osfwPresentText" value="%process_name% sta cercando di cambiare il comportamento di %product_name% modificando il file seguente: %file%" locale="it-IT" />
  123.                     <messages type="osfwPastText" value="%process_name% ha cercato di cambiare il comportamento di %product_name% modificando il file seguente: %file%" locale="it-IT" />
  124.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di cambiare il comportamento di %product_name% modificando il file seguente: %file%" locale="it-IT" />
  125.                 </customevent>
  126.                 <customevent id="2003" severityref="malicious" >
  127.                     <messages type="osfwPresentText" value="%process_name% is trying to change the settings of %product_name% by modifying the registry key: %registry_key%" locale="en-US" />
  128.                     <messages type="osfwPastText" value="%process_name% was trying to change the settings of %product_name% by modifying the registry key: %registry_key%" locale="en-US" />
  129.                     <messages type="osfwBlockedText" value="%process_name% was prevented from changing the settings of %product_name% by modifying the registry key: %registry_key%" locale="en-US" />
  130.                     <messages type="osfwPresentText" value="%process_name% versucht, die Einstellungen von %product_name% durch Modifizierung des folgenden Registrierungsschl├╝ssels zu ├ñndern: %registry_key%" locale="de-DE" />
  131.                     <messages type="osfwPastText" value="%process_name% hat versucht, die Einstellungen von %product_name% durch Modifizierung des folgenden Registrierungsschl├╝ssels zu ├ñndern: %registry_key%" locale="de-DE" />
  132.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, die Einstellungen von %product_name% durch Modifizierung des folgenden Registrierungsschl├╝ssels zu ├ñndern: %registry_key%" locale="de-DE" />
  133.                     <messages type="osfwPresentText" value="%process_name% tente de modifier les param├¿tres de %product_name% en modifiant la cl├⌐ de registre suivante : %registry_key%" locale="fr-FR" />
  134.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de modifier les param├¿tres de %product_name% en modifiant la cl├⌐ de registre suivante : %registry_key%" locale="fr-FR" />
  135.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á modifier les param├¿tres de %product_name% en modifiant la cl├⌐ de registre suivante : %registry_key%" locale="fr-FR" />
  136.                     <messages type="osfwPresentText" value="%process_name% πüîµ¼íπü«πâ¼πé╕πé╣πâêπ⬠πé¡πâ╝π鯵¢╕πüìµ¢┐πüêπüª %product_name% πü«Φ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ: %registry_key%" locale="jp-JA" />
  137.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâ¼πé╕πé╣πâêπ⬠πé¡πâ╝π鯵¢╕πüìµ¢┐πüêπüª %product_name% πü«Φ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ: %registry_key%" locale="jp-JA" />
  138.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâ¼πé╕πé╣πâêπ⬠πé¡πâ╝π鯵¢╕πüìµ¢┐πüêπüª %product_name% πü«Φ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ: %registry_key%" locale="jp-JA" />
  139.                     <messages type="osfwPresentText" value="%process_name% est├í intentando cambiar la configuraci├│n de %product_name% mediante la modificaci├│n de la clave de registro: %registry_key%" locale="es-ES" />
  140.                     <messages type="osfwPastText" value="%process_name% ha intentado cambiar la configuraci├│n de %product_name% mediante la modificaci├│n de la clave de registro: %registry_key%" locale="es-ES" />
  141.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% cambie la configuraci├│n de %product_name% mediante la modificaci├│n de la clave de registro: %registry_key%" locale="es-ES" />
  142.                     <messages type="osfwPresentText" value="%process_name% sta cercando di cambiare le impostazioni di %product_name% modificando la chiave di registro seguente: %registry_key%" locale="it-IT" />
  143.                     <messages type="osfwPastText" value="%process_name% ha cercato di cambiare le impostazioni di %product_name% modificando la chiave di registro seguente: %registry_key%" locale="it-IT" />
  144.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di cambiare le impostazioni di %product_name% modificando la chiave di registro seguente: %registry_key%" locale="it-IT" />
  145.                 </customevent>
  146.  
  147.                     <!-- "dangerous" behavior (3001-3999) -->
  148.  
  149.                 <customevent id="3001" severityref="dangerous" >
  150.                     <messages type="osfwPresentText" value="%process_name% is trying to change your network settings by modifying the file: %file%" locale="en-US" />
  151.                     <messages type="osfwPastText" value="%process_name% was trying to change your network settings by modifying the file: %file%" locale="en-US" />
  152.                     <messages type="osfwBlockedText" value="%process_name% was prevented from changing your network settings by modifying the file: %file%" locale="en-US" />
  153.                     <messages type="osfwPresentText" value="%process_name% versucht, Ihre Netzwerkeinstellungen durch Modifizierung der folgenden Datei zu ├ñndern: %file%" locale="de-DE" />
  154.                     <messages type="osfwPastText" value="%process_name% hat versucht, Ihre Netzwerkeinstellungen durch Modifizierung der folgenden Datei zu ├ñndern: %file%" locale="de-DE" />
  155.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, Ihre Netzwerkeinstellungen durch Modifizierung der folgenden Datei zu ├ñndern: %file%" locale="de-DE"/>
  156.                     <messages type="osfwPresentText" value="%process_name% tente de modifier vos param├¿tres r├⌐seau en modifiant le fichier suivant : %file%" locale="fr-FR" />
  157.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de modifier vos param├¿tres r├⌐seau en modifiant le fichier suivant : %file%" locale="fr-FR" />
  158.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á modifier vos param├¿tres r├⌐seau en modifiant le fichier suivant : %file%" locale="fr-FR" />
  159.                     <messages type="osfwPresentText" value="%process_name% πüîµ¼íπü«πâòπéíπéñπâ½π鯵¢╕πüìµ¢┐πüêπüªπâìπââπâêπâ»πâ╝πé»Φ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ:%file%" locale="jp-JA" />
  160.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâòπéíπéñπâ½π鯵¢╕πüìµ¢┐πüêπüªπâìπââπâêπâ»πâ╝πé»Φ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ:%file%" locale="jp-JA" />
  161.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâòπéíπéñπâ½π鯵¢╕πüìµ¢┐πüêπüªπâìπââπâêπâ»πâ╝πé»Φ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ:%file%" locale="jp-JA" />
  162.                     <messages type="osfwPresentText" value="%process_name% est├í intentando cambiar la configuraci├│n de red mediante la modificaci├│n del archivo: %file%" locale="es-ES" />
  163.                     <messages type="osfwPastText" value="%process_name% ha intentado cambiar la configuraci├│n de red mediante la modificaci├│n del archivo: %file%" locale="es-ES" />
  164.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% cambie la configuraci├│n de red mediante la modificaci├│n del archivo: %file%" locale="es-ES" />
  165.                     <messages type="osfwPresentText" value="%process_name% sta cercando di cambiare le impostazioni di rete modificando il file seguente: %file%" locale="it-IT" />
  166.                     <messages type="osfwPastText" value="%process_name% ha cercato di cambiare le impostazioni di rete modificando il file seguente: %file%" locale="it-IT" />
  167.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di cambiare le impostazioni di rete modificando il file seguente: %file%" locale="it-IT" />
  168.                 </customevent>
  169.                 <customevent id="3002" severityref="dangerous" >
  170.                     <messages type="osfwPresentText" value="%process_name% is trying to change Windows by modifying the file: %file%" locale="en-US" />
  171.                     <messages type="osfwPastText" value="%process_name% was trying to change the configuration of Windows by modifying the file: %file%" locale="en-US" />
  172.                     <messages type="osfwBlockedText" value="%process_name% was prevented from changing the configuration of Windows by modifying the file: %file%" locale="en-US" />
  173.                     <messages type="osfwPresentText" value="%process_name% versucht, Windows durch Modifizierung der folgenden Datei zu ├ñndern: %file%" locale="de-DE" />
  174.                     <messages type="osfwPastText" value="%process_name% hat versucht, die Konfiguration von Windows durch Modifizierung der folgenden Datei zu ├ñndern: %file%" locale="de-DE" />
  175.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, die Konfiguration von Windows durch Modifizierung der folgenden Datei zu ├ñndern: %file%" locale="de-DE" />
  176.                     <messages type="osfwPresentText" value="%process_name% tente de modifier Windows en modifiant le fichier suivant : %file%" locale="fr-FR" />
  177.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de modifier Windows en modifiant le fichier suivant : %file%" locale="fr-FR" />
  178.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á modifier Windows en modifiant le fichier suivant : %file%" locale="fr-FR" />
  179.                     <messages type="osfwPresentText" value="%process_name% πüîµ¼íπü«πâòπéíπéñπâ½π鯵¢╕πüìµ¢┐πüêπüª Windows πü«Φ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ:%file%" locale="jp-JA" />
  180.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâòπéíπéñπâ½π鯵¢╕πüìµ¢┐πüêπüª Windows πü«Φ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ:%file%" locale="jp-JA" />
  181.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâòπéíπéñπâ½π鯵¢╕πüìµ¢┐πüêπüª Windows πü«Φ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ:%file%" locale="jp-JA" />
  182.                     <messages type="osfwPresentText" value="%process_name% est├í intentando cambiar la configuraci├│n de Windows mediante la modificaci├│n del archivo: %file%" locale="es-ES" />
  183.                     <messages type="osfwPastText" value="%process_name% ha intentado cambiar la configuraci├│n de Windows mediante la modificaci├│n del archivo: %file%" locale="es-ES" />
  184.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% cambie la configuraci├│n de Windows mediante la modificaci├│n del archivo: %file%" locale="es-ES" />
  185.                     <messages type="osfwPresentText" value="%process_name% sta cercando di cambiare Windows modificando il file seguente: %file%" locale="it-IT" />
  186.                     <messages type="osfwPastText" value="%process_name% ha cercato di cambiare la configurazione di Windows %product_name% modificando il file seguente: %file%" locale="it-IT" />
  187.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% cambiare la configurazione di Windows %product_name% modificando il file seguente: %file%" locale="it-IT" />
  188.                 </customevent>
  189.                 <customevent id="3003" severityref="dangerous" >
  190.                     <messages type="osfwPresentText" value="%process_name% is trying to reconfigure software by modifying the registry key: %registry_key%"    locale="en-US" />
  191.                     <messages type="osfwPastText" value="%process_name% was trying to reconfigure software by modifying the registry key: %registry_key%" locale="en-US" />
  192.                     <messages type="osfwBlockedText" value="%process_name% was prevented from reconfiguring software by modifying the registry key: %registry_key%" locale="en-US" />
  193.                     <messages type="osfwPresentText" value="%process_name% versucht, Software durch Modifizierung des folgenden Registrierungsschl├╝ssels zu ├ñndern: %registry_key%"    locale="de-DE" />
  194.                     <messages type="osfwPastText" value="%process_name% hat versucht, Software durch Modifizierung des folgenden Registrierungsschl├╝ssels zu ├ñndern: %registry_key%" locale="de-DE" />
  195.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, Software durch Modifizierung des folgenden Registrierungsschl├╝ssels zu ├ñndern: %registry_key%" locale="de-DE" />
  196.                     <messages type="osfwPresentText" value="%process_name% tente de modifier reconfigurer des logiciels en modifiant la cl├⌐ de registre suivante : %registry_key%"    locale="fr-FR" />
  197.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de modifier reconfigurer des logiciels en modifiant la cl├⌐ de registre suivante : %registry_key%" locale="fr-FR" />
  198.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á reconfigurer des logiciels en modifiant la cl├⌐ de registre suivante : %registry_key%" locale="fr-FR" />
  199.                     <messages type="osfwPresentText" value="%process_name% πüîµ¼íπü«πâ¼πé╕πé╣πâêπ⬠πé¡πâ╝π鯵¢╕πüìµ¢┐πüêπüªπé╜πâòπâêπéªπéºπéóπéÆσåìΦ¿¡σ«Üπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ: %registry_key%"    locale="jp-JA" />
  200.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâ¼πé╕πé╣πâêπ⬠πé¡πâ╝π鯵¢╕πüìµ¢┐πüêπüªπé╜πâòπâêπéªπéºπéóπéÆσåìΦ¿¡σ«Üπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ: %registry_key%" locale="jp-JA" />
  201.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâ¼πé╕πé╣πâêπ⬠πé¡πâ╝π鯵¢╕πüìµ¢┐πüêπüªπé╜πâòπâêπéªπéºπéóπéÆσåìΦ¿¡σ«Üπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ: %registry_key%" locale="jp-JA" />
  202.                     <messages type="osfwPresentText" value="%process_name% est├í intentando volver a configurar el software mediante la modificaci├│n de la clave de registro: %registry_key%"    locale="es-ES" />
  203.                     <messages type="osfwPastText" value="%process_name% ha intentado volver a configurar el software mediante la modificaci├│n de la clave de registro: %registry_key%" locale="es-ES" />
  204.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% vuelva a configurar el software mediante la modificaci├│n de la clave de registro: %registry_key%" locale="es-ES" />
  205.                     <messages type="osfwPresentText" value="%process_name% sta cercando di riconfigurare il software modificando la chiave di registro seguente: %registry_key%"    locale="it-IT" />
  206.                     <messages type="osfwPastText" value="%process_name% ha cercato di riconfigurare il software modificando la chiave di registro seguente: %registry_key%" locale="it-IT" />
  207.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di riconfigurare il software modificando la chiave di registro seguente: %registry_key%" locale="it-IT" />
  208.                 </customevent>
  209.                 <customevent id="3004" severityref="dangerous" >
  210.                     <messages type="osfwPresentText" value="%process_name% is trying to read and modify physical memory" locale="en-US" />
  211.                     <messages type="osfwPastText" value="%process_name% was trying to read and modify physical memory" locale="en-US" />
  212.                     <messages type="osfwBlockedText" value="%process_name% was prevented from reading and modifying physical memory" locale="en-US" />
  213.                     <messages type="osfwPresentText" value="%process_name% versucht, den physischen Speicher zu lesen und zu ├ñndern." locale="de-DE" />
  214.                     <messages type="osfwPastText" value="%process_name% versucht, den physischen Speicher zu lesen und zu ├ñndern." locale="de-DE" />
  215.                     <messages type="osfwBlockedText" value="%process_name% hat versucht, den physischen Speicher zu lesen und zu ├ñndern." locale="de-DE" />
  216.                     <messages type="osfwPresentText" value="%process_name% tente de lire et de modifier la m├⌐moire physique" locale="fr-FR" />
  217.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de lire et de modifier la m├⌐moire physique" locale="fr-FR" />
  218.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á lire et ├á modifier la m├⌐moire physique" locale="fr-FR" />
  219.                     <messages type="osfwPresentText" value="%process_name% πüîτë⌐τÉåπâíπâóπâ¬πéÆΦ¬¡πü┐σÅûπüúπüªσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  220.                     <messages type="osfwPastText" value="%process_name% πüîτë⌐τÉåπâíπâóπâ¬πéÆΦ¬¡πü┐σÅûπüúπüªσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  221.                     <messages type="osfwBlockedText" value="%process_name% πüîτë⌐τÉåπâíπâóπâ¬πéÆΦ¬¡πü┐σÅûπüúπüªσñëµ¢┤πüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  222.                     <messages type="osfwPresentText" value="%process_name% est├í intentando leer y modificar la memoria f├¡sica" locale="es-ES" />
  223.                     <messages type="osfwPastText" value="%process_name% ha intentado leer y modificar la memoria f├¡sica" locale="es-ES" />
  224.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% lea y modifique la memoria f├¡sica" locale="es-ES" />
  225.                     <messages type="osfwPresentText" value="%process_name% sta cercando di leggere e modificare la memoria fisica" locale="it-IT" />
  226.                     <messages type="osfwPastText" value="%process_name% ha cercato di leggere e modificare la memoria fisica" locale="it-IT" />
  227.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di leggere e modificare la memoria fisica" locale="it-IT" />
  228.                 </customevent>
  229.                 <customevent id="3005" severityref="dangerous" >
  230.                     <messages type="osfwPresentText" value="%process_name% is trying to monitor your mouse movements and keyboard strokes" locale="en-US" />
  231.                     <messages type="osfwPastText" value="%process_name% was trying to monitor your mouse movements and keyboard strokes" locale="en-US" />
  232.                     <messages type="osfwBlockedText" value="%process_name% was prevented from was prevented from monitoring your mouse and keyboard strokes" locale="en-US" />
  233.                     <messages type="osfwPresentText" value="%process_name% versucht, Ihre Mausbewegungen und Tastatureingaben zu ├╝berwachen." locale="de-DE" />
  234.                     <messages type="osfwPastText" value="%process_name% hat versucht, Ihre Mausbewegungen und Tastatureingaben zu ├╝berwachen." locale="de-DE" />
  235.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, Ihre Mausbewegungen und Tastatureingaben zu ├╝berwachen." locale="de-DE" />
  236.                     <messages type="osfwPresentText" value="%process_name% tente de surveiller votre souris et votre clavier" locale="fr-FR" />
  237.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de surveiller votre souris et votre clavier" locale="fr-FR" />
  238.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á surveiller votre souris et votre clavier" locale="fr-FR" />
  239.                     <messages type="osfwPresentText" value="%process_name% πüîπâ₧πéªπé╣πü«σïòΣ╜£πü¿πé¡πâ╝πâ£πâ╝πâëπü«σàÑσè¢πéÆπâóπâïπé┐πüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  240.                     <messages type="osfwPastText" value="%process_name% πüîπâ₧πéªπé╣πü«σïòΣ╜£πü¿πé¡πâ╝πâ£πâ╝πâëπü«σàÑσè¢πéÆπâóπâïπé┐πüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  241.                     <messages type="osfwBlockedText" value="%process_name% πüîπâ₧πéªπé╣πü«σïòΣ╜£πü¿πé¡πâ╝πâ£πâ╝πâëπü«σàÑσè¢πéÆπâóπâïπé┐πüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  242.                     <messages type="osfwPresentText" value="%process_name% est├í intentando controlar las pulsaciones del teclado y la actividad del mouse" locale="es-ES" />
  243.                     <messages type="osfwPastText" value="%process_name% ha intentado controlar las pulsaciones del teclado y la actividad del mouse" locale="es-ES" />
  244.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% controle las pulsaciones del teclado y la actividad del mouse" locale="es-ES" />
  245.                     <messages type="osfwPresentText" value="%process_name% sta cercando di monitorare i movimenti del mouse e la pressione dei tasti della tastiera" locale="it-IT" />
  246.                     <messages type="osfwPastText" value="%process_name% ha cercato di monitorare i movimenti del mouse e la pressione dei tasti della tastiera" locale="it-IT" />
  247.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di monitorare il mouse e la pressione dei tasti della tastiera" locale="it-IT" />
  248.                 </customevent>
  249.                 <customevent id="3006" severityref="dangerous" >
  250.                     <messages type="osfwPresentText" value="%process_name% is trying to load the driver: %driver%" locale="en-US" />
  251.                     <messages type="osfwPastText" value="%process_name% was trying to load the driver: %driver%" locale="en-US" />
  252.                     <messages type="osfwBlockedText" value="%process_name% was prevented from loading the driver: %driver%" locale="en-US" />
  253.                     <messages type="osfwPresentText" value="%process_name% versucht, den folgenden Treiber zu laden: %driver%" locale="de-DE" />
  254.                     <messages type="osfwPastText" value="%process_name% hat versucht, den folgenden Treiber zu laden: %driver%" locale="de-DE" />
  255.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, den folgenden Treiber zu laden: %driver%" locale="de-DE" />
  256.                     <messages type="osfwPresentText" value="%process_name% tente de charger le pilote : %driver%" locale="fr-FR" />
  257.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de charger le pilote : %driver%" locale="fr-FR" />
  258.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á charger le pilote : %driver%" locale="fr-FR" />
  259.                     <messages type="osfwPresentText" value="%process_name% πüîµ¼íπü«πâëπâ⌐πéñπâÉπéÆπâ¡πâ╝πâëπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ: %driver%" locale="jp-JA" />
  260.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâëπâ⌐πéñπâÉπéÆπâ¡πâ╝πâëπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ: %driver%" locale="jp-JA" />
  261.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâëπâ⌐πéñπâÉπéÆπâ¡πâ╝πâëπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ: %driver%" locale="jp-JA" />
  262.                     <messages type="osfwPresentText" value="%process_name% est├í intentando cargar el controlador: %driver%" locale="es-ES" />
  263.                     <messages type="osfwPastText" value="%process_name% ha intentado cargar el controlador: %driver%" locale="es-ES" />
  264.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% cargue el controlador: %driver%" locale="es-ES" />
  265.                     <messages type="osfwPresentText" value="%process_name% sta cercando di caricare il driver seguente: %driver%" locale="it-IT" />
  266.                     <messages type="osfwPastText" value="%process_name% ha cercato di caricare il driver seguente: %driver%" locale="it-IT" />
  267.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di caricare il driver seguente: %driver%" locale="it-IT" />
  268.                 </customevent>
  269.  
  270.                     <!-- "suspicious" behavoir (4001-4999) -->
  271.                 <customevent id="4001" severityref="suspicious" >
  272.                     <messages type="osfwPresentText" value="%process_name% is trying to set '%registry_value%' to run each time your computer is started" locale="en-US" />
  273.                     <messages type="osfwPastText" value="%process_name% was trying to set '%registry_value%' to run each time your computer is started" locale="en-US" />
  274.                     <messages type="osfwBlockedText" value="%process_name% was prevented from setting '%registry_value%' to run each time your computer is started" locale="en-US" />
  275.                     <messages type="osfwPresentText" value="%process_name% nimmt Einstellungen an '%registry_value%' vor, die bewirken, dass es bei jedem Computerstart ausgef├╝hrt wird." locale="de-DE" />
  276.                     <messages type="osfwPastText" value="%process_name% hat Einstellungen an '%registry_value%' vorgenommen, die bewirken, dass es bei jedem Computerstart ausgef├╝hrt wird." locale="de-DE" />
  277.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, Einstellungen an '%registry_value%' vorzunehmen, die bewirken, dass es bei jedem Computerstart ausgef├╝hrt wird." locale="de-DE" />
  278.                     <messages type="osfwPresentText" value="%process_name% tente de d├⌐finir '%registry_value%' pour ├¬tre ex├⌐cut├⌐ ├á chaque d├⌐marrage de l'ordinateur" locale="fr-FR" />
  279.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de d├⌐finir '%registry_value%' pour ├¬tre ex├⌐cut├⌐ ├á chaque d├⌐marrage de l'ordinateur" locale="fr-FR" />
  280.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á d├⌐finir '%registry_value%' pour ├¬tre ex├⌐cut├⌐ ├á chaque d├⌐marrage de l'ordinateur" locale="fr-FR" />
  281.                     <messages type="osfwPresentText" value="%process_name% πüîπÇüπé│πâ│πâöπâÑπâ╝πé┐πü«Φ╡╖σïòπü«πüƒπü│πü½ '%registry_value%' πéÆσ«ƒΦíîπüÖπéïπéêπüåπü½Φ¿¡σ«Üπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  282.                     <messages type="osfwPastText" value="%process_name% πüîπÇüπé│πâ│πâöπâÑπâ╝πé┐πü«Φ╡╖σïòπü«πüƒπü│πü½ '%registry_value%' πéÆσ«ƒΦíîπüÖπéïπéêπüåπü½Φ¿¡σ«Üπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  283.                     <messages type="osfwBlockedText" value="%process_name% πüîπé│πâ│πâöπâÑπâ╝πé┐πü«Φ╡╖σïòπü«πüƒπü│πü½ '%registry_value%' πéÆσ«ƒΦíîπüÖπéïπéêπüåπü½Φ¿¡σ«ÜπüÖπéïπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  284.                     <messages type="osfwPresentText" value="%process_name% est├í intentando configurar el valor '%registry_value%' para que se ejecute cada vez que se inicie el equipo" locale="es-ES" />
  285.                     <messages type="osfwPastText" value="%process_name% ha intentado configurar el valor '%registry_value%' para que se ejecute cada vez que se inicie el equipo" locale="es-ES" />
  286.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% configure el valor '%registry_value%' para que se ejecute cada vez que se inicie el equipo" locale="es-ES" />
  287.                     <messages type="osfwPresentText" value="%process_name% sta cercando di impostare '%registry_value%' in modo che venga eseguito all'avvio del computer" locale="it-IT" />
  288.                     <messages type="osfwPastText" value="%process_name% ha cercato di impostare '%registry_value%' in modo che venga eseguito all'avvio del computer" locale="it-IT" />
  289.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di impostare '%registry_value%' in modo che venga eseguito all'avvio del computer" locale="it-IT" />
  290.                 </customevent>
  291.                 <customevent id="4002" severityref="suspicious" >
  292.                     <messages type="osfwPresentText" value="%process_name% is trying to unload the driver: %driver%" locale="en-US" />
  293.                     <messages type="osfwPastText" value="%process_name% was trying to unload the driver: %driver%" locale="en-US" />
  294.                     <messages type="osfwBlockedText" value="%process_name% was prevented from unloading the driver: %driver%" locale="en-US" />
  295.                     <messages type="osfwPresentText" value="%process_name% versucht, den folgenden Treiber zu entladen: %driver%" locale="de-DE" />
  296.                     <messages type="osfwPastText" value="%process_name% hat versucht, den folgenden Treiber zu entladen: %driver%" locale="de-DE" />
  297.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, den folgenden Treiber zu entladen: %driver%" locale="de-DE" />
  298.                     <messages type="osfwPresentText" value="%process_name% tente de d├⌐charger le pilote : %driver%" locale="fr-FR" />
  299.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de d├⌐charger le pilote : %driver%" locale="fr-FR" />
  300.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á d├⌐charger le pilote : %driver%" locale="fr-FR" />
  301.                     <messages type="osfwPresentText" value="%process_name% πüîµ¼íπü«πâëπâ⌐πéñπâÉπéÆπéóπâ│πâ¡πâ╝πâëπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ: %driver%" locale="jp-JA" />
  302.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâëπâ⌐πéñπâÉπéÆπéóπâ│πâ¡πâ╝πâëπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ: %driver%" locale="jp-JA" />
  303.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâëπâ⌐πéñπâÉπéÆπéóπâ│πâ¡πâ╝πâëπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ: %driver%" locale="jp-JA" />
  304.                     <messages type="osfwPresentText" value="%process_name% est├í intentando descargar el controlador: %driver%" locale="es-ES" />
  305.                     <messages type="osfwPastText" value="%process_name% ha intentado descargar el controlador: %driver%" locale="es-ES" />
  306.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% descargue el controlador: %driver%" locale="es-ES" />
  307.                     <messages type="osfwPresentText" value="%process_name% sta cercando di scaricare il driver seguente: %driver%" locale="it-IT" />
  308.                     <messages type="osfwPastText" value="%process_name% ha cercato di scaricare il driver seguente: %driver%" locale="it-IT" />
  309.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di scaricare il driver seguente: %driver%" locale="it-IT" />
  310.                 </customevent>
  311.                 <customevent id="4003" severityref="suspicious" >
  312.                     <messages type="osfwPresentText" value="%process_name% is trying to connect to the driver: %driver%" locale="en-US" />
  313.                     <messages type="osfwPastText" value="%process_name% was trying to connect to the driver: %driver%" locale="en-US" />
  314.                     <messages type="osfwBlockedText" value="%process_name% was prevented from connecting to the driver: %driver%" locale="en-US" />
  315.                     <messages type="osfwPresentText" value="%process_name% versucht, eine Verbindung zu dem folgenden Treiber herzustellen: %driver%" locale="de-DE" />
  316.                     <messages type="osfwPastText" value="%process_name% hat versucht, eine Verbindung zu dem folgenden Treiber herzustellen: %driver%" locale="de-DE" />
  317.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, eine Verbindung zu dem folgenden Treiber herzustellen: %driver%" locale="de-DE" />
  318.                     <messages type="osfwPresentText" value="%process_name% tente de se connecter au pilote : %driver%" locale="fr-FR" />
  319.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de se connecter au pilote : %driver%" locale="fr-FR" />
  320.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á se connecter au pilote : %driver%" locale="fr-FR" />
  321.                     <messages type="osfwPresentText" value="%process_name% πüîµ¼íπü«πâëπâ⌐πéñπâÉπü½µÄÑτ╢Üπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ: %driver%" locale="jp-JA" />
  322.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâëπâ⌐πéñπâÉπü½µÄÑτ╢Üπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ: %driver%" locale="jp-JA" />
  323.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâëπâ⌐πéñπâÉπü½µÄÑτ╢Üπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ: %driver%" locale="jp-JA" />
  324.                     <messages type="osfwPresentText" value="%process_name% est├í intentando conectarse al controlador: %driver%" locale="es-ES" />
  325.                     <messages type="osfwPastText" value="%process_name% ha intentado conectarse al controlador: %driver%" locale="es-ES" />
  326.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% se conecte al controlador: %driver%" locale="es-ES" />
  327.                     <messages type="osfwPresentText" value="%process_name% sta cercando di connettersi al driver seguente: %driver%" locale="it-IT" />
  328.                     <messages type="osfwPastText" value="%process_name% ha cercato di connettersi al driver seguente: %driver%" locale="it-IT" />
  329.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di connettersi al driver seguente: %driver%" locale="it-IT" />
  330.                 </customevent>
  331.                 <customevent id="4004" severityref="suspicious" >
  332.                     <messages type="osfwPresentText" value="%process_name% may be trying to prevent '%registry_value%' from running each time your computer is started by modifying the registry key: %registry_key%" locale="en-US" />
  333.                     <messages type="osfwPastText" value="%process_name% may have been trying to prevent '%registry_value%' from running each time your computer is started by modifying the registry key: %registry_key%" locale="en-US" />
  334.                     <messages type="osfwBlockedText" value="%process_name% was prevented from modifying registry key: %registry_key%" locale="en-US" />
  335.                     <messages type="osfwPresentText" value="%process_name% versucht m├╢glicherweise, '%registry_value%' durch Modifizierung des folgenden Registrierungsschl├╝ssels daran zu hindern, dass es bei jedem Computerstart ausgef├╝hrt wird: %registry_key%" locale="de-DE" />
  336.                     <messages type="osfwPastText" value="%process_name% hat m├╢glicherweise versucht, '%registry_value%' durch Modifizierung des folgenden Registrierungsschl├╝ssels daran zu hindern, dass es bei jedem Computerstart ausgef├╝hrt: %registry_key%" locale="de-DE" />
  337.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, den folgenden Registrierungsschl├╝ssel zu ├ñndern: %registry_key%" locale="de-DE" />
  338.                     <messages type="osfwPresentText" value="%process_name% tente d'emp├¬cher '%registry_value%' de s'ex├⌐cuter ├á chaque d├⌐marrage de l'ordinateur en modifiant la cl├⌐ de registre : %registry_key%" locale="fr-FR" />
  339.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ d'emp├¬cher '%registry_value%' de s'ex├⌐cuter ├á chaque d├⌐marrage de l'ordinateur en modifiant la cl├⌐ de registre : %registry_key%" locale="fr-FR" />
  340.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á modifi├⌐ la cl├⌐ de registre suivante : %registry_key%" locale="fr-FR" />
  341.                     <messages type="osfwPresentText" value="%process_name% πüîπÇüπé│πâ│πâöπâÑπâ╝πé┐πü«Φ╡╖σïòπü«πüƒπü│πü½ '%registry_value%' πüîσ«ƒΦíîπüòπéîπü¬πüäπéêπüåπü½πüÖπéïπüƒπéüπü½πÇüµ¼íπü«πâ¼πé╕πé╣πâêπ⬠πé¡πâ╝π鯵¢╕πüìµ¢┐πüêπéêπüåπü¿πüùπüªπüäπéïσÅ»Φâ╜µÇºπüîπüéπéèπü╛πüÖ: %registry_key%" locale="jp-JA" />
  342.                     <messages type="osfwPastText" value="%process_name% πüîπÇüπé│πâ│πâöπâÑπâ╝πé┐πü«Φ╡╖σïòπü«πüƒπü│πü½ '%registry_value%' πüîσ«ƒΦíîπüòπéîπü¬πüäπéêπüåπü½πüÖπéïπüƒπéüπü½πÇüµ¼íπü«πâ¼πé╕πé╣πâêπ⬠πé¡πâ╝π鯵¢╕πüìµ¢┐πüêπéêπüåπü¿πüùπüªπüäπüƒσÅ»Φâ╜µÇºπüîπüéπéèπü╛πüÖ: %registry_key%" locale="jp-JA" />
  343.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâ¼πé╕πé╣πâêπ⬠πé¡πâ╝π鯵¢╕πüìµ¢┐πüêπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ: %registry_key%" locale="jp-JA" />
  344.                     <messages type="osfwPresentText" value="%process_name% est├í intentando impedir que el valor '%registry_value%' se ejecute cada vez que se inicie el equipo mediante la modificaci├│n de la clave de registro: %registry_key%" locale="es-ES" />
  345.                     <messages type="osfwPastText" value="%process_name% ha intentado impedir que el valor '%registry_value%' se ejecute cada vez que se inicie el equipo mediante la modificaci├│n de la clave de registro: %registry_key%" locale="es-ES" />
  346.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% modifique la clave de registro: %registry_key%" locale="es-ES" />
  347.                     <messages type="osfwPresentText" value="Probabile tentativo da parte di %process_name% di bloccare l'esecuzione di '%registry_value%' all'avvio del computer modificando la chiave di registro seguente: %registry_key%" locale="it-IT" />
  348.                     <messages type="osfwPastText" value="Probabile tentativo da parte di %process_name% di bloccare l'esecuzione di '%registry_value%' all'avvio del computer modificando la chiave di registro seguente: %registry_key%" locale="it-IT" />
  349.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di modificare la chiave di registro seguente: %registry_key%" locale="it-IT" />
  350.                 </customevent>
  351.                 <customevent id="4005" severityref="suspicious" >
  352.                     <messages type="osfwPresentText" value="%process_name% is trying to modify the registry value:  %registry_key%\%registry_value%" locale="en-US" />
  353.                     <messages type="osfwPastText" value="%process_name% was trying to modify the registry value:  %registry_key%\%registry_value%" locale="en-US" />
  354.                     <messages type="osfwBlockedText" value="%process_name% was prevented from modifying the registry value:  %registry_key%\%registry_value%" locale="en-US" />
  355.                     <messages type="osfwPresentText" value="%process_name% versucht, den folgenden Registrierungswert zu ├ñndern:  %registry_key%\%registry_value%" locale="de-DE" />
  356.                     <messages type="osfwPastText" value="%process_name% hat versucht, den folgenden Registrierungswert zu ├ñndern:  %registry_key%\%registry_value%" locale="de-DE" />
  357.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, den folgenden Registrierungswert zu ├ñndern:  %registry_key%\%registry_value%" locale="de-DE" />
  358.                     <messages type="osfwPresentText" value="%process_name% tente de modifier la valeur de registre :  %registry_key%\%registry_value%" locale="fr-FR" />
  359.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de modifier la valeur de registre :  %registry_key%\%registry_value%" locale="fr-FR" />
  360.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á modifi├⌐ la valeur de registre suivante :  %registry_key%\%registry_value%" locale="fr-FR" />
  361.                     <messages type="osfwPresentText" value="%process_name% πüîµ¼íπü«πâ¼πé╕πé╣πâêπâ¬σÇñπ鯵¢╕πüìµ¢┐πüêπéêπüåπü¿πüùπüªπüäπü╛πüÖ:  %registry_key%\%registry_value%" locale="jp-JA" />
  362.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâ¼πé╕πé╣πâêπâ¬σÇñπ鯵¢╕πüìµ¢┐πüêπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ:  %registry_key%\%registry_value%" locale="jp-JA" />
  363.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâ¼πé╕πé╣πâêπâ¬σÇñπ鯵¢╕πüìµ¢┐πüêπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ:  %registry_key%\%registry_value%" locale="jp-JA" />
  364.                     <messages type="osfwPresentText" value="%process_name% est├í intentando modificar el valor de registro:  %registry_key%\%registry_value%" locale="es-ES" />
  365.                     <messages type="osfwPastText" value="%process_name% ha intentado modificar el valor de registro:  %registry_key%\%registry_value%" locale="es-ES" />
  366.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% modifique el valor de registro:  %registry_key%\%registry_value%" locale="es-ES" />
  367.                     <messages type="osfwPresentText" value="%process_name% sta cercando di modificare il valore di registro seguente:  %registry_key%\%registry_value%" locale="it-IT" />
  368.                     <messages type="osfwPastText" value="%process_name% ha cercato di modificare il valore di registro seguente:  %registry_key%\%registry_value%" locale="it-IT" />
  369.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di modificare il valore registro seguente:  %registry_key%\%registry_value%" locale="it-IT" />
  370.                 </customevent>
  371.                 <customevent id="4006" severityref="suspicious" >
  372.                     <messages type="osfwPresentText" value="%process_name% is trying to change your browser search settings" locale="en-US" />
  373.                     <messages type="osfwPastText" value="%process_name% was trying to change your browser search settings" locale="en-US" />
  374.                     <messages type="osfwBlockedText" value="%process_name% was prevented from changing your browser search settings" locale="en-US" />
  375.                     <messages type="osfwPresentText" value="%process_name% versucht, die Sucheinstellungen Ihres Browsers zu ├ñndern." locale="de-DE" />
  376.                     <messages type="osfwPastText" value="%process_name% hat versucht, die Sucheinstellungen Ihres Browsers zu ├ñndern." locale="de-DE" />
  377.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, die Sucheinstellungen Ihres Browsers zu ├ñndern." locale="de-DE" />
  378.                     <messages type="osfwPresentText" value="%process_name% tente de modifier les param├¿tres de recherche de votre navigateur" locale="fr-FR" />
  379.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de modifier les param├¿tres de recherche de votre navigateur" locale="fr-FR" />
  380.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á modifier les param├¿tres de recherche de votre navigateur" locale="fr-FR" />
  381.                     <messages type="osfwPresentText" value="%process_name% πüîπâûπâ⌐πéªπé╢πü«µñ£τ┤óΦ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  382.                     <messages type="osfwPastText" value="%process_name% πüîπâûπâ⌐πéªπé╢πü«µñ£τ┤óΦ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  383.                     <messages type="osfwBlockedText" value="%process_name% πüîπâûπâ⌐πéªπé╢πü«µñ£τ┤óΦ¿¡σ«ÜπéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  384.                     <messages type="osfwPresentText" value="%process_name% est├í intentando cambiar la configuraci├│n de b├║squeda del navegador" locale="es-ES" />
  385.                     <messages type="osfwPastText" value="%process_name% ha intentado cambiar la configuraci├│n de b├║squeda del navegador" locale="es-ES" />
  386.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% cambie la configuraci├│n de b├║squeda del navegador" locale="es-ES" />
  387.                     <messages type="osfwPresentText" value="%process_name% sta cercando di modificare le impostazioni di ricerca del browser" locale="it-IT" />
  388.                     <messages type="osfwPastText" value="%process_name% ha cercato di modificare le impostazioni di ricerca del browser" locale="it-IT" />
  389.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di modificare le impostazioni di ricerca del browser" locale="it-IT" />
  390.                 </customevent>
  391.                 <customevent id="4007" severityref="suspicious" >
  392.                     <messages type="osfwPresentText" value="%process_name% is trying to change your browser home page" locale="en-US" />
  393.                     <messages type="osfwPastText" value="%process_name% was trying to change your browser home page" locale="en-US" />
  394.                     <messages type="osfwBlockedText" value="%process_name% was prevented from changing your browser home page" locale="en-US" />
  395.                     <messages type="osfwPresentText" value="%process_name% versucht, die Startseite Ihres Browsers zu ├ñndern." locale="de-DE" />
  396.                     <messages type="osfwPastText" value="%process_name% hat versucht, die Startseite Ihres Browsers zu ├ñndern." locale="de-DE" />
  397.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, die Startseite Ihres Browsers zu ├ñndern." locale="de-DE" />
  398.                     <messages type="osfwPresentText" value="%process_name% tente de modifier la page d'accueil de votre navigateur" locale="fr-FR" />
  399.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de modifier la page d'accueil de votre navigateur" locale="fr-FR" />
  400.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á modifier la page d'accueil de votre navigateur" locale="fr-FR" />
  401.                     <messages type="osfwPresentText" value="%process_name% πüîπâûπâ⌐πéªπé╢πü«πâ¢πâ╝πâá πâÜπâ╝πé╕πéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  402.                     <messages type="osfwPastText" value="%process_name% πüîπâûπâ⌐πéªπé╢πü«πâ¢πâ╝πâá πâÜπâ╝πé╕πéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  403.                     <messages type="osfwBlockedText" value="%process_name% πüîπâûπâ⌐πéªπé╢πü«πâ¢πâ╝πâá πâÜπâ╝πé╕πéÆσñëµ¢┤πüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  404.                     <messages type="osfwPresentText" value="%process_name% est├í intentando cambiar la p├ígina de inicio del navegador" locale="es-ES" />
  405.                     <messages type="osfwPastText" value="%process_name% ha intentado cambiar la p├ígina de inicio del navegador" locale="es-ES" />
  406.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% cambie la p├ígina de inicio del navegador" locale="es-ES" />
  407.                     <messages type="osfwPresentText" value="%process_name% sta cercando di modificare la pagina iniziale del browser" locale="it-IT" />
  408.                     <messages type="osfwPastText" value="%process_name% ha cercato di modificare la pagina iniziale del browser" locale="it-IT" />
  409.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di modificare la pagina iniziale del browser" locale="it-IT" />
  410.                 </customevent>
  411.  
  412.                 <!-- Normal behavior (5001-5999) -->
  413.  
  414.                 <customevent id="5001" severityref="normal" >
  415.                     <messages type="osfwPresentText" value="%process_name% is trying to load the module: %module%" locale="en-US" />
  416.                     <messages type="osfwPastText" value="%process_name% was trying to load the module: %module%" locale="en-US" />
  417.                     <messages type="osfwBlockedText" value="%process_name% was prevented from loading the module: %module%" locale="en-US" />
  418.                     <messages type="osfwPresentText" value="%process_name% versucht, das folgende Modul zu laden: %module%" locale="de-DE" />
  419.                     <messages type="osfwPastText" value="%process_name% hat versucht, das folgende Modul zu laden: %module%" locale="de-DE" />
  420.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, das folgende Modul zu laden: %module%" locale="de-DE" />
  421.                     <messages type="osfwPresentText" value="%process_name% tente de charger le module : %module%" locale="fr-FR" />
  422.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de charger le module : %module%" locale="fr-FR" />
  423.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á charger le module : %module%" locale="fr-FR" />
  424.                     <messages type="osfwPresentText" value="%process_name% πüîµ¼íπü«πâóπé╕πâÑπâ╝πâ½πéÆπâ¡πâ╝πâëπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ:%module%" locale="jp-JA" />
  425.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâóπé╕πâÑπâ╝πâ½πéÆπâ¡πâ╝πâëπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ:%module%" locale="jp-JA" />
  426.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâóπé╕πâÑπâ╝πâ½πéÆπâ¡πâ╝πâëπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ:%module%" locale="jp-JA" />
  427.                     <messages type="osfwPresentText" value="%process_name% est├í intentando cargar el m├│dulo: %module%" locale="es-ES" />
  428.                     <messages type="osfwPastText" value="%process_name% ha intentado cargar el m├│dulo: %module%" locale="es-ES" />
  429.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% cargue el m├│dulo: %module%" locale="es-ES" />
  430.                     <messages type="osfwPresentText" value="%process_name% sta cercando di caricare il modulo seguente: %module%" locale="it-IT" />
  431.                     <messages type="osfwPastText" value="%process_name% ha cercato di caricare il modulo seguente: %module%" locale="it-IT" />
  432.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di caricare il modulo seguente: %module%" locale="it-IT" />
  433.                 </customevent>
  434.  
  435.                 <!-- Severity depends upon the target process for the event (6001-6999) -->
  436.  
  437.                 <customevent id="6001" >
  438.                     <messages type="osfwPresentText"  value="%process_name% is trying to communicate with %target_process% by opening its process" locale="en-US" />
  439.                     <messages type="osfwPastText" value="%process_name% was trying to communicate with %target_process% by opening its process" locale="en-US" />
  440.                     <messages type="osfwBlockedText" value="%process_name% was prevented from to communicating with %target_process% by opening its process" locale="en-US" />
  441.                     <messages type="osfwPresentText"  value="%process_name% versucht, durch ├ûffnen des Prozesses mit %target_process% zu kommunizieren." locale="de-DE" />
  442.                     <messages type="osfwPastText" value="%process_name% hat versucht, durch ├ûffnen des Prozesses mit %target_process% zu kommunizieren." locale="de-DE" />
  443.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, durch ├ûffnen des Prozesses mit %target_process% zu kommunizieren." locale="de-DE" />
  444.                     <messages type="osfwPresentText"  value="%process_name% tente de communiquer avec %target_process% en ouvrant son processus" locale="fr-FR" />
  445.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de communiquer avec %target_process% en ouvrant son processus" locale="fr-FR" />
  446.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á communiquer avec %target_process% en ouvrant son processus" locale="fr-FR" />
  447.                     <messages type="osfwPresentText"  value="%process_name% πüî %target_process% πü«πâùπâ¡πé╗πé╣πéÆπé¬πâ╝πâùπâ│πüùπüªΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  448.                     <messages type="osfwPastText" value="%process_name% πüî %target_process% πü«πâùπâ¡πé╗πé╣πéÆπé¬πâ╝πâùπâ│πüùπüªΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  449.                     <messages type="osfwBlockedText" value="%process_name% πüî %target_process% πü«πâùπâ¡πé╗πé╣πéÆπé¬πâ╝πâùπâ│πüùπüªΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  450.                     <messages type="osfwPresentText"  value="%process_name% est├í intentando comunicarse con %target_process% abriendo su proceso" locale="es-ES" />
  451.                     <messages type="osfwPastText" value="%process_name% ha intentado comunicarse con %target_process% abriendo su proceso" locale="es-ES" />
  452.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% se comunique con %target_process% abriendo su proceso" locale="es-ES" />
  453.                     <messages type="osfwPresentText"  value="%process_name% sta cercando di comunicare con %target_process% aprendo il suo processo" locale="it-IT" />
  454.                     <messages type="osfwPastText" value="%process_name% ha cercato di comunicare con %target_process% aprendo il suo processo" locale="it-IT" />
  455.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di comunicare con %target_process% aprendo il suo processo" locale="it-IT" />
  456.                 </customevent>
  457.                 <customevent id="6002" >
  458.                     <messages type="osfwPresentText"  value="%process_name% is trying to communicate with %target_process% by opening a thread" locale="en-US" />
  459.                     <messages type="osfwPastText" value="%process_name% was trying to communicate with %target_process% by opening a thread" locale="en-US" />
  460.                     <messages type="osfwBlockedText" value="%process_name% was prevented from communicating with %target_process% by opening a thread" locale="en-US" />
  461.                     <messages type="osfwPresentText"  value="%process_name% versucht, durch ├ûffnen eines Threads mit %target_process% zu kommunizieren." locale="de-DE" />
  462.                     <messages type="osfwPastText" value="%process_name% hat versucht, durch ├ûffnen eines Threads mit %target_process% zu kommunizieren." locale="de-DE" />
  463.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, durch ├ûffnen eines Threads mit %target_process% zu kommunizieren." locale="de-DE" />
  464.                     <messages type="osfwPresentText"  value="%process_name% tente de communiquer avec %target_process% en ouvrant un thread" locale="fr-FR" />
  465.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de communiquer avec %target_process% en ouvrant un thread" locale="fr-FR" />
  466.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á communiquer avec %target_process% en ouvrant un thread" locale="fr-FR" />
  467.                     <messages type="osfwPresentText"  value="%process_name% πüîπé╣πâ¼πââπâëπéÆπé¬πâ╝πâùπâ│πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  468.                     <messages type="osfwPastText" value="%process_name% πüîπé╣πâ¼πââπâëπéÆπé¬πâ╝πâùπâ│πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  469.                     <messages type="osfwBlockedText" value="%process_name% πüîπé╣πâ¼πââπâëπéÆπé¬πâ╝πâùπâ│πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  470.                     <messages type="osfwPresentText"  value="%process_name% est├í intentando comunicarse con %target_process% abriendo un subproceso" locale="es-ES" />
  471.                     <messages type="osfwPastText" value="%process_name% ha intentado comunicarse con %target_process% abriendo un subproceso" locale="es-ES" />
  472.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% se comunique con %target_process% abriendo un subproceso" locale="es-ES" />
  473.                     <messages type="osfwPresentText"  value="%process_name% sta cercando di comunicare con %target_process% aprendo un thread" locale="it-IT" />
  474.                     <messages type="osfwPastText" value="%process_name% ha cercato di comunicare con %target_process% aprendo un thread" locale="it-IT" />
  475.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di comunicare con %target_process% aprendo un thread" locale="it-IT" />
  476.                 </customevent>
  477.                 <customevent id="6003" >
  478.                     <messages type="osfwPresentText"  value="%process_name% is trying to launch %target_process%, or use another program to gain access to privileged resources" locale="en-US" />
  479.                     <messages type="osfwPastText" value="%process_name% was trying to launch %target_process%, or use another program to gain access to privileged resources" locale="en-US" />
  480.                     <messages type="osfwBlockedText" value="%process_name% was prevented from launching %target_process%, or use another program to gain access to privileged resources" locale="en-US" />
  481.                     <messages type="osfwPresentText"  value="%process_name% versucht, %target_process% zu laden oder ein anderes Programm zu verwenden, um Zugriff auf berechtigte Ressourcen zu erhalten." locale="de-DE" />
  482.                     <messages type="osfwPastText" value="%process_name% hat versucht, %target_process% zu laden oder ein anderes Programm zu verwenden, um Zugriff auf berechtigte Ressourcen zu erhalten." locale="de-DE" />
  483.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, %target_process% zu laden oder ein anderes Programm zu verwenden, um Zugriff auf berechtigte Ressourcen zu erhalten." locale="de-DE" />
  484.                     <messages type="osfwPresentText"  value="%process_name% tente de lancer %target_process% ou d'utiliser un autre programme pour acc├⌐der aux ressources privil├⌐gi├⌐es" locale="fr-FR" />
  485.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de lancer %target_process% ou d'utiliser un autre programme pour acc├⌐der aux ressources privil├⌐gi├⌐es" locale="fr-FR" />
  486.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á lancer %target_process% ou utiliser un autre programme pour acc├⌐der aux ressources privil├⌐gi├⌐es" locale="fr-FR" />
  487.                     <messages type="osfwPresentText"  value="%process_name% πüîπÇüµ¿⌐ΘÖÉπü«σ┐àΦªüπü¬πâ¬πé╜πâ╝πé╣πü½πéóπé»πé╗πé╣πüÖπéïπüƒπéüπü½πÇü%target_process% πéÆΦ╡╖σïòπüùπÇüπü╛πüƒπü»σêÑπü«πâùπâ¡πé░πâ⌐πâáπéÆΣ╜┐τö¿πüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  488.                     <messages type="osfwPastText" value="%process_name% πüîπÇüµ¿⌐ΘÖÉπü«σ┐àΦªüπü¬πâ¬πé╜πâ╝πé╣πü½πéóπé»πé╗πé╣πüÖπéïπüƒπéüπü½πÇü%target_process% πéÆΦ╡╖σïòπüùπÇüπü╛πüƒπü»σêÑπü«πâùπâ¡πé░πâ⌐πâáπéÆΣ╜┐τö¿πüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  489.                     <messages type="osfwBlockedText" value="%process_name% πü⌐ΘÖÉπü«σ┐àΦªüπü¬πâ¬πé╜πâ╝πé╣πü½πéóπé»πé╗πé╣πüÖπéïπüƒπéüπü½ %target_process% πéÆΦ╡╖σïòπüùπÇüπü╛πüƒπü»σêÑπü«πâùπâ¡πé░πâ⌐πâáπéÆΣ╜┐τö¿πüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  490.                     <messages type="osfwPresentText"  value="%process_name% est├í intentando ejecutar %target_process% o utilizar otro programa para acceder a recursos con privilegios" locale="es-ES" />
  491.                     <messages type="osfwPastText" value="%process_name% ha intentado ejecutar %target_process% o utilizar otro programa para acceder a recursos con privilegios" locale="es-ES" />
  492.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% ejecute %target_process% o utilice otro programa para acceder a recursos con privilegios" locale="es-ES" />
  493.                     <messages type="osfwPresentText"  value="%process_name% sta cercando di avviare %target_process% o di usare un altro programma per ottenere accesso a risorse privilegiate" locale="it-IT" />
  494.                     <messages type="osfwPastText" value="%process_name% ha cercato di avviare %target_process% o di usare un altro programma per ottenere accesso a risorse privilegiate" locale="it-IT" />
  495.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di avviare %target_process% o di usare un altro programma per ottenere accesso a risorse privilegiate" locale="it-IT" />
  496.                 </customevent>
  497.                 <customevent id="6004" >
  498.                     <messages type="osfwPresentText"  value="%process_name% is trying to start" locale="en-US" />
  499.                     <messages type="osfwPastText" value="%process_name% was trying to start" locale="en-US" />
  500.                     <messages type="osfwBlockedText" value="%process_name% was prevented from starting" locale="en-US" />
  501.                     <messages type="osfwPresentText"  value="%process_name% versucht zu starten." locale="de-DE" />
  502.                     <messages type="osfwPastText" value="%process_name% hat versucht zu starten." locale="de-DE" />
  503.                     <messages type="osfwBlockedText" value="%process_name% wurde am Starten gehindert." locale="de-DE" />
  504.                     <messages type="osfwPresentText"  value="%process_name% tente de d├⌐marrer" locale="fr-FR" />
  505.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de d├⌐marrer" locale="fr-FR" />
  506.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á d├⌐marrer" locale="fr-FR" />
  507.                     <messages type="osfwPresentText"  value="%process_name% πü»Φ╡╖σïòπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  508.                     <messages type="osfwPastText" value="%process_name% πü»Φ╡╖σïòπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  509.                     <messages type="osfwBlockedText" value="%process_name% πü«Φ╡╖σïòπéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  510.                     <messages type="osfwPresentText"  value="%process_name% est├í intentando iniciarse" locale="es-ES" />
  511.                     <messages type="osfwPastText" value="%process_name% ha intentado iniciarse" locale="es-ES" />
  512.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% se inicie" locale="es-ES" />
  513.                     <messages type="osfwPresentText"  value="%process_name% sta cercando di effettuare l'avvio" locale="it-IT" />
  514.                     <messages type="osfwPastText" value="%process_name% ha cercato di effettuare l'avvio" locale="it-IT" />
  515.                     <messages type="osfwBlockedText" value="Avvio di %process_name% bloccato" locale="it-IT" />
  516.                 </customevent>
  517.                 <customevent id="6005" >
  518.                     <messages type="osfwPresentText"  value="%process_name% is trying to control the keyboard input of the process: %target_process%" locale="en-US" />
  519.                     <messages type="osfwPastText" value="%process_name% was trying to control the keyboard input of the process: %target_process%" locale="en-US" />
  520.                     <messages type="osfwBlockedText" value="%process_name% was prevented from controlling the keyboard input of the process: %target_process%" locale="en-US" />
  521.                     <messages type="osfwPresentText"  value="%process_name% versucht, die Tastatureingaben des folgenden Prozesses zu steuern: %target_process%" locale="de-DE" />
  522.                     <messages type="osfwPastText" value="%process_name% hat versucht, die Tastatureingaben des folgenden Prozesses zu steuern: %target_process%" locale="de-DE" />
  523.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, die Tastatureingaben des folgenden Prozesses zu steuern: %target_process%" locale="de-DE" />
  524.                     <messages type="osfwPresentText"  value="%process_name% tente de contr├┤ler l'entr├⌐e clavier du processus : %target_process%" locale="fr-FR" />
  525.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de contr├┤ler l'entr├⌐e clavier du processus : %target_process%" locale="fr-FR" />
  526.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á contr├┤ler l'entr├⌐e clavier du processus : %target_process%" locale="fr-FR" />
  527.                     <messages type="osfwPresentText"  value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πü«πé¡πâ╝πâ£πâ╝πâëσàÑσè¢πéÆσê╢σ╛íπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ: %target_process%" locale="jp-JA" />
  528.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πü«πé¡πâ╝πâ£πâ╝πâëσàÑσè¢πéÆσê╢σ╛íπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ: %target_process%" locale="jp-JA" />
  529.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πü«πé¡πâ╝πâ£πâ╝πâëσàÑσè¢πéÆσê╢σ╛íπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ: %target_process%" locale="jp-JA" />
  530.                     <messages type="osfwPresentText"  value="%process_name% est├í intentando controlar las entradas del teclado del proceso: %target_process%" locale="es-ES" />
  531.                     <messages type="osfwPastText" value="%process_name% ha intentado controlar las entradas del teclado del proceso: %target_process%" locale="es-ES" />
  532.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% controle las entradas del teclado del proceso: %target_process%" locale="es-ES" />
  533.                     <messages type="osfwPresentText"  value="%process_name% sta cercando di controllare l'input da tastiera per il processo seguente: %target_process%" locale="it-IT" />
  534.                     <messages type="osfwPastText" value="%process_name% ha cercato di controllare l'input da tastiera per il processo seguente: %target_process%" locale="it-IT" />
  535.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di controllare l'input da tastiera per il processo seguente: %target_process%" locale="it-IT" />
  536.                 </customevent>
  537.                 <customevent id="6006" >
  538.                     <messages type="osfwPresentText"  value="%process_name% is trying to control the mouse input of the process: %target_process%" locale="en-US" />
  539.                     <messages type="osfwPastText" value="%process_name% was trying to control the mouse input of the process: %target_process%" locale="en-US" />
  540.                     <messages type="osfwBlockedText" value="%process_name% was prevented from controlling the mouse input of the process: %target_process%" locale="en-US" />
  541.                     <messages type="osfwPresentText"  value="%process_name% versucht, die Mauseingaben des folgenden Prozesses zu steuern: %target_process%" locale="de-DE" />
  542.                     <messages type="osfwPastText" value="%process_name% hat versucht, die Mauseingaben des folgenden Prozesses zu steuern: %target_process%" locale="de-DE" />
  543.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, die Mauseingaben des folgenden Prozesses zu steuern: %target_process%" locale="de-DE" />
  544.                     <messages type="osfwPresentText"  value="%process_name% tente de contr├┤ler l'entr├⌐e souris du processus : %target_process%" locale="fr-FR" />
  545.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de contr├┤ler l'entr├⌐e souris du processus : %target_process%" locale="fr-FR" />
  546.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á contr├┤ler l'entr├⌐e souris du processus : %target_process%" locale="fr-FR" />
  547.                     <messages type="osfwPresentText"  value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πü«πâ₧πéªπé╣σàÑσè¢πéÆσê╢σ╛íπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ: %target_process%" locale="jp-JA" />
  548.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πü«πâ₧πéªπé╣σàÑσè¢πéÆσê╢σ╛íπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ: %target_process%" locale="jp-JA" />
  549.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πü«πâ₧πéªπé╣σàÑσè¢πéÆσê╢σ╛íπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ: %target_process%" locale="jp-JA" />
  550.                     <messages type="osfwPresentText"  value="%process_name% est├í intentando controlar las entradas del mouse del proceso: %target_process%" locale="es-ES" />
  551.                     <messages type="osfwPastText" value="%process_name% ha intentado controlar las entradas del mouse del proceso: %target_process%" locale="es-ES" />
  552.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% controle las entradas del mouse del proceso: %target_process%" locale="es-ES" />
  553.                     <messages type="osfwPresentText"  value="%process_name% sta cercando di controllare l'input tramite mouse per il processo seguente: %target_process%" locale="it-IT" />
  554.                     <messages type="osfwPastText" value="%process_name% ha cercato di controllare l'input tramite mouse per il processo seguente: %target_process%" locale="it-IT" />
  555.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di controllare l'input tramite mouse per il processo seguente: %target_process%" locale="it-IT" />
  556.                 </customevent>
  557.                 <customevent id="6007" >
  558.                     <messages type="osfwPresentText"  value="%process_name% is trying to communicate with %target_process% by using DDE" locale="en-US" />
  559.                     <messages type="osfwPastText" value="%process_name% was trying to communicate with %target_process% by using DDE" locale="en-US" />
  560.                     <messages type="osfwBlockedText" value="%process_name% was prevented from communicating with %target_process% by using DDE" locale="en-US" />
  561.                     <messages type="osfwPresentText"  value="%process_name% versucht, durch Verwenden von DDE mit %target_process% zu kommunizieren." locale="de-DE" />
  562.                     <messages type="osfwPastText" value="%process_name% hat versucht, durch Verwenden von DDE mit %target_process% zu kommunizieren." locale="de-DE" />
  563.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, durch Verwenden von DDE mit %target_process% zu kommunizieren." locale="de-DE" />
  564.                     <messages type="osfwPresentText"  value="%process_name% tente de communiquer avec %target_process% en utilisant DDE" locale="fr-FR" />
  565.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de communiquer avec %target_process% en utilisant DDE" locale="fr-FR" />
  566.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á communiquer avec %target_process% en utilisant DDE" locale="fr-FR" />
  567.                     <messages type="osfwPresentText"  value="%process_name% πüî DDE πéÆΣ╜┐τö¿πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  568.                     <messages type="osfwPastText" value="%process_name% πüî DDE πéÆΣ╜┐τö¿πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  569.                     <messages type="osfwBlockedText" value="%process_name% πüî DDE πéÆΣ╜┐τö¿πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  570.                     <messages type="osfwPresentText"  value="%process_name% est├í intentando comunicarse con %target_process% mediante DDE" locale="es-ES" />
  571.                     <messages type="osfwPastText" value="%process_name% ha intentado comunicarse con %target_process% mediante DDE" locale="es-ES" />
  572.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% se comunique con %target_process% mediante DDE" locale="es-ES" />
  573.                     <messages type="osfwPresentText"  value="%process_name% sta cercando di comunicare con %target_process% utilizzando DDE" locale="it-IT" />
  574.                     <messages type="osfwPastText" value="%process_name% ha cercato di comunicare con %target_process% utilizzando DDE" locale="it-IT" />
  575.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di comunicare con %target_process% utilizzando DDE" locale="it-IT" />
  576.                 </customevent>
  577.                 <customevent id="6008" >
  578.                     <messages type="osfwPresentText"  value="%process_name% is trying to communicate with %target_process% using a programming technique called a callback" locale="en-US" />
  579.                     <messages type="osfwPastText" value="%process_name% was trying to communicate with %target_process% using a programming technique called a callback" locale="en-US" />
  580.                     <messages type="osfwBlockedText" value="%process_name% was prevented from to communicating with %target_process% using a programming technique called a callback" locale="en-US" />
  581.                     <messages type="osfwPresentText"  value="%process_name% versucht, durch die als Callback (R├╝ckruf) bezeichnete Programmierungsmethode mit %target_process% zu kommunizieren." locale="de-DE" />
  582.                     <messages type="osfwPastText" value="%process_name% hat versucht, durch die als Callback (R├╝ckruf) bezeichnete Programmierungsmethode mit %target_process% zu kommunizieren." locale="de-DE" />
  583.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, durch die als Callback (R├╝ckruf) bezeichnete Programmierungsmethode mit %target_process% zu kommunizieren." locale="de-DE" />
  584.                     <messages type="osfwPresentText"  value="%process_name% tente de communiquer avec %target_process% en utilisant une technique de programmation appel├⌐e le rappel" locale="fr-FR" />
  585.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de communiquer avec %target_process% en utilisant une technique de programmation appel├⌐e le rappel" locale="fr-FR" />
  586.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á communiquer avec %target_process% en utilisant une technique de programmation appel├⌐e le rappel" locale="fr-FR" />
  587.                     <messages type="osfwPresentText"  value="%process_name% πüîπé│πâ╝πâ½πâÉπââπé»πü¿πüäπüåπâùπâ¡πé░πâ⌐πâƒπâ│πé░µèÇΦíôπéÆΣ╜┐τö¿πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  588.                     <messages type="osfwPastText" value="%process_name% πüîπé│πâ╝πâ½πâÉπââπé»πü¿πüäπüåπâùπâ¡πé░πâ⌐πâƒπâ│πé░µèÇΦíôπéÆΣ╜┐τö¿πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  589.                     <messages type="osfwBlockedText" value="%process_name% πüîπé│πâ╝πâ½πâÉπââπé»πü¿πüäπüåπâùπâ¡πé░πâ⌐πâƒπâ│πé░µèÇΦíôπéÆΣ╜┐τö¿πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  590.                     <messages type="osfwPresentText"  value="%process_name% est├í intentando comunicarse con %target_process% mediante una t├⌐cnica de programaci├│n denominada respuesta de llamada" locale="es-ES" />
  591.                     <messages type="osfwPastText" value="%process_name% ha intentado comunicarse con %target_process% mediante una t├⌐cnica de programaci├│n denominada respuesta de llamada" locale="es-ES" />
  592.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% se comunique con %target_process% mediante una t├⌐cnica de programaci├│n denominada respuesta de llamada" locale="es-ES" />
  593.                     <messages type="osfwPresentText"  value="%process_name% sta cercando di comunicare con %target_process% utilizzando una tecnica di programmazione denominata callback" locale="it-IT" />
  594.                     <messages type="osfwPastText" value="%process_name% ha cercato di comunicare con %target_process% utilizzando una tecnica di programmazione denominata callback" locale="it-IT" />
  595.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di comunicare con %target_process% utilizzando una tecnica di programmazione denominata callback" locale="it-IT" />
  596.                 </customevent>
  597.                 <customevent id="6009" >
  598.                     <messages type="osfwPresentText"  value="%process_name% is trying to inject code into: %target_process%" locale="en-US" />
  599.                     <messages type="osfwPastText" value="%process_name% was trying to inject code into: %target_process%" locale="en-US" />
  600.                     <messages type="osfwBlockedText" value="%process_name% was prevented from injecting code into: %target_process%" locale="en-US" />
  601.                     <messages type="osfwPresentText"  value="%process_name% versucht, Code einzubringen in: %target_process%" locale="de-DE" />
  602.                     <messages type="osfwPastText" value="%process_name% hat versucht, Code einzubringen in: %target_process%" locale="de-DE" />
  603.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, Code einzubringen in: %target_process%" locale="de-DE" />
  604.                     <messages type="osfwPresentText"  value="%process_name% tente d'ins├⌐rer un code dans : %target_process%" locale="fr-FR" />
  605.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ d'ins├⌐rer un code dans : %target_process%" locale="fr-FR" />
  606.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á ins├⌐rer un code dans : %target_process%" locale="fr-FR" />
  607.                     <messages type="osfwPresentText"  value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πü½πé│πâ╝πâëπ鯵î┐σàÑπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ: %target_process%" locale="jp-JA" />
  608.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πü½πé│πâ╝πâëπ鯵î┐σàÑπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ: %target_process%" locale="jp-JA" />
  609.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πü½πé│πâ╝πâëπ鯵î┐σàÑπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ: %target_process%" locale="jp-JA" />
  610.                     <messages type="osfwPresentText"  value="%process_name% est├í intentando insertar c├│ndigo en: %target_process%" locale="es-ES" />
  611.                     <messages type="osfwPastText" value="%process_name% ha intentado insertar c├│ndigo en: %target_process%" locale="es-ES" />
  612.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% inserte c├│ndigo en: %target_process%" locale="es-ES" />
  613.                     <messages type="osfwPresentText"  value="%process_name% sta cercando di inserire del codice in: %target_process%" locale="it-IT" />
  614.                     <messages type="osfwPastText" value="%process_name% ha cercato di inserire del codice in: %target_process%" locale="it-IT" />
  615.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di inserire del codice in: %target_process%" locale="it-IT" />
  616.                 </customevent>
  617.                 <customevent id="6010" >
  618.                     <messages type="osfwPresentText"  value="%process_name% is trying to terminate: %target_process%" locale="en-US" />
  619.                     <messages type="osfwPastText" value="%process_name% was trying to terminate: %target_process%" locale="en-US" />
  620.                     <messages type="osfwBlockedText" value="%process_name% was prevented from terminating: %target_process%" locale="en-US" />
  621.                     <messages type="osfwPresentText"  value="%process_name% versucht, Folgendes zu beenden: %target_process%" locale="de-DE" />
  622.                     <messages type="osfwPastText" value="%process_name% hat versucht, Folgendes zu beenden: %target_process%" locale="de-DE" />
  623.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, Folgendes zu beenden: %target_process%" locale="de-DE" />
  624.                     <messages type="osfwPresentText"  value="%process_name% tente de terminer : %target_process%" locale="fr-FR" />
  625.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de terminer : %target_process%" locale="fr-FR" />
  626.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á terminer : %target_process%" locale="fr-FR" />
  627.                     <messages type="osfwPresentText"  value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πéÆτ╡éΣ║åπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ: %target_process%" locale="jp-JA" />
  628.                     <messages type="osfwPastText" value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πéÆτ╡éΣ║åπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ: %target_process%" locale="jp-JA" />
  629.                     <messages type="osfwBlockedText" value="%process_name% πüîµ¼íπü«πâùπâ¡πé╗πé╣πéÆτ╡éΣ║åπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ: %target_process%" locale="jp-JA" />
  630.                     <messages type="osfwPresentText"  value="%process_name% est├í intentando terminar: %target_process%" locale="es-ES" />
  631.                     <messages type="osfwPastText" value="%process_name% ha intentado terminar: %target_process%" locale="es-ES" />
  632.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% termine: %target_process%" locale="es-ES" />
  633.                     <messages type="osfwPresentText"  value="%process_name% sta cercando di terminare: %target_process%" locale="it-IT" />
  634.                     <messages type="osfwPastText" value="%process_name% ha cercato di terminare: %target_process%" locale="it-IT" />
  635.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di terminare: %target_process%" locale="it-IT" />
  636.                 </customevent>
  637.                 <customevent id="6011" >
  638.                     <messages type="osfwPresentText"  value="%process_name% is trying to communicate with %target_process% using Windows messages" locale="en-US" />
  639.                     <messages type="osfwPastText" value="%process_name% was trying to communicate with %target_process% using Windows messages" locale="en-US" />
  640.                     <messages type="osfwBlockedText" value="%process_name% was prevented from communicating with %target_process% using Windows messages" locale="en-US" />
  641.                     <messages type="osfwPresentText"  value="%process_name% versucht, mit Hilfe von Windows-Meldungen mit %target_process% zu kommunizieren." locale="de-DE" />
  642.                     <messages type="osfwPastText" value="%process_name% hat versucht, mit Hilfe von Windows-Meldungen mit %target_process% zu kommunizieren." locale="de-DE" />
  643.                     <messages type="osfwBlockedText" value="%process_name% wurde daran gehindert, mit Hilfe von Windows-Meldungen mit %target_process% zu kommunizieren." locale="de-DE" />
  644.                     <messages type="osfwPresentText"  value="%process_name% tente de communiquer avec %target_process% en utilisant les messages Windows" locale="fr-FR" />
  645.                     <messages type="osfwPastText" value="%process_name% a tent├⌐ de communiquer avec %target_process% en utilisant les messages Windows" locale="fr-FR" />
  646.                     <messages type="osfwBlockedText" value="%process_name% n'a pas r├⌐ussi ├á communiquer avec %target_process% en utilisant les messages Windows" locale="fr-FR" />
  647.                     <messages type="osfwPresentText"  value="%process_name% πüî Windows πâíπââπé╗πâ╝πé╕πéÆΣ╜┐τö¿πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüªπüäπü╛πüÖ" locale="jp-JA" />
  648.                     <messages type="osfwPastText" value="%process_name% πüî Windows πâíπââπé╗πâ╝πé╕πéÆΣ╜┐τö¿πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüªπüäπü╛πüùπüƒ" locale="jp-JA" />
  649.                     <messages type="osfwBlockedText" value="%process_name% πüî Windows πâíπââπé╗πâ╝πé╕πéÆΣ╜┐τö¿πüùπüª %target_process% πü¿ΘÇÜΣ┐íπüùπéêπüåπü¿πüùπüƒπü«πéÆΘÿ▓µ¡óπüùπü╛πüùπüƒ" locale="jp-JA" />
  650.                     <messages type="osfwPresentText"  value="%process_name% est├í intentando comunicarse con %target_process% mediante mensajes de Windows" locale="es-ES" />
  651.                     <messages type="osfwPastText" value="%process_name% ha intentado comunicarse con %target_process% mediante mensajes de Windows" locale="es-ES" />
  652.                     <messages type="osfwBlockedText" value="Se ha impedido que %process_name% se comunique con %target_process% mediante mensajes de Windows" locale="es-ES" />
  653.                     <messages type="osfwPresentText"  value="%process_name% sta cercando di comunicare con %target_process% utilizzando messaggi di Windows" locale="it-IT" />
  654.                     <messages type="osfwPastText" value="%process_name% ha cercato di comunicare con %target_process% utilizzando messaggi di Windows" locale="it-IT" />
  655.                     <messages type="osfwBlockedText" value="├ê stato impedito a %process_name% di comunicare con %target_process% utilizzando messaggi di Windows" locale="it-IT" />
  656.                 </customevent>
  657.  
  658.                 <!-- 
  659.                      Rulegroups used soley to map events to customevents.  We
  660.                      can get rid of this if the evententry element is ever
  661.                      extended to allow specification of customtext.
  662.                 -->
  663.                 <!-- ASKING -->
  664.  
  665.                 <!-- Malicious behavior -->
  666.  
  667.                 <rulegroup name="rg-malwr-ask" customtext="2001" ask="true" />
  668.  
  669.                 <!-- Dangerous behavior -->
  670.  
  671.                 <rulegroup name="rg-memmp-ask" customtext="3004" ask="true" />
  672.                 <rulegroup name="rg-glbhook-ask" customtext="3005" ask="true" />
  673.                 <rulegroup name="rg-drvld-ask" customtext="3006" ask="true" />
  674.  
  675.                 <!-- Suspicious behavior -->
  676.  
  677.                 <rulegroup name="rg-drvud-ask" customtext="4002" ask="true" />
  678.                 <rulegroup name="rg-drvct-ask" customtext="4003" ask="true" />
  679.  
  680.                 <!-- Normal behavior -->
  681.  
  682.                 <rulegroup name="rg-modld-ok" customtext="5001" allow="true" notify="true" />
  683.  
  684.                 <!-- Severity depends upon the target process -->
  685.  
  686.                 <rulegroup name="rg-openp-ask" customtext="6001" ask="true" />
  687.                 <rulegroup name="rg-opent-ask" customtext="6002" ask="true" />
  688.                 <rulegroup name="rg-spawn-ask" customtext="6003" ask="true" />
  689.                 <rulegroup name="rg-start-ask" customtext="6004" ask="true" />
  690.                 <rulegroup name="rg-keybd-ask" customtext="6005" ask="true" />
  691.                 <rulegroup name="rg-mouse-ask" customtext="6006" ask="true" />
  692.                 <rulegroup name="rg-ddein-ask" customtext="6007" ask="true" />
  693.                 <rulegroup name="rg-callb-ask" customtext="6008" ask="true" />
  694.                 <rulegroup name="rg-whook-ask" customtext="6009" ask="true" />
  695.                 <rulegroup name="rg-termp-ask" customtext="6010" ask="true" />
  696.                 <rulegroup name="rg-msg-ask" customtext="6011" ask="true" />
  697.  
  698.  
  699.                 <!-- BLOCKING -->
  700.                 <!-- Malicious behavior -->
  701.  
  702.                 <rulegroup name="rg-malwr-blk" customtext="2001" allow="false" notify="true" />
  703.  
  704.                 <!-- Dangerous behavior -->
  705.  
  706.                 <rulegroup name="rg-memmp-blk" customtext="3004" allow="false" notify="true" />
  707.                 <rulegroup name="rg-glbhook-blk" customtext="3005" allow="false" notify="true" />
  708.  
  709.                 <!-- Suspicious behavior -->
  710.  
  711.                 <rulegroup name="rg-drvld-blk" customtext="3006" allow="false" notify="true" />
  712.                 <rulegroup name="rg-drvud-blk" customtext="4002" allow="false" notify="true" />
  713.                 <rulegroup name="rg-drvct-blk" customtext="4003" allow="false" notify="true" />
  714.                 <rulegroup name="rg-regall-blk" customtext="4005" allow="false" notify="true" />
  715.  
  716.    
  717.                                 <!-- Severity depends upon the target process -->
  718.  
  719.                 <rulegroup name="rg-openp-blk" customtext="6001" allow="false" notify="true" />
  720.                 <rulegroup name="rg-opent-blk" customtext="6002" allow="false" notify="true" />
  721.                 <rulegroup name="rg-spawn-blk" customtext="6003" allow="false" notify="true" />
  722.                 <rulegroup name="rg-start-blk" customtext="6004" allow="false" notify="true" />
  723.                 <rulegroup name="rg-keybd-blk" customtext="6005" allow="false" notify="true" />
  724.                 <rulegroup name="rg-mouse-blk" customtext="6006" allow="false" notify="true" />
  725.                 <rulegroup name="rg-ddein-blk" customtext="6007" allow="false" notify="true" />
  726.                 <rulegroup name="rg-callb-blk" customtext="6008" allow="false" notify="true" />
  727.                 <rulegroup name="rg-whook-blk" customtext="6009" allow="false" notify="true" />
  728.                 <rulegroup name="rg-termp-blk" customtext="6010" allow="false" notify="true" />
  729.                 <rulegroup name="rg-msg-blk" customtext="6011" allow="false" notify="true" />
  730.  
  731.                 <!-- Protect all our stuff -->
  732.  
  733. <rulegroup name="protourfiles">
  734.     <ruleentry event="file" match="any" allow="false" notify="true" customtext="2002">
  735.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINDIR\Internet Logs\BACKUP.RDB" />
  736.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINDIR\Internet Logs\IAMDB.RDB" />
  737.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINDIR\Internet Logs\ZALog.txt" />
  738.  
  739.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\camupd.dll" />      
  740.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\dbghelp.dll" />     
  741.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\osfwrules.xml" />
  742.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\plugins" />
  743.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\qrbase.dll" />      
  744.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\qrsrecl.dll" />     
  745.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\safePrograms.xml" />
  746.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\scheduler.dll" />   
  747.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\spyware.dat" />     
  748.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\srescan.dll" />     
  749.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\ssleay32.dll" />    
  750.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsavpro.dll" />     
  751.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsdb.dll" />        
  752.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsmon.exe" />       
  753.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsruledb.dll" />    
  754.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsvault.dll" />     
  755.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\ZLCommDB.xml" />    
  756.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlparser.dll" />    
  757.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlquarantine.dll" />
  758.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlsre.dll" />       
  759.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlasdbup.dat" />
  760.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlsrepluginsupd.zip" />
  761.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlsreupd.zip" />
  762.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlqrtdb.dat" />
  763.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlasdbup.dat" />
  764.  
  765.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsconfig.xml" />
  766.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsdata.dll" />
  767.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsdatant.sys" />
  768.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsinit.dll" />
  769.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsmonapi.dll" />
  770.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vspubapi.dll" />
  771.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsregexp.dll" />
  772.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsutil.dll" />
  773.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsxml.dll" />
  774.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\zlcomm.dll" />
  775.         <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\zlcommdb.dll" />
  776.  
  777.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\alert.zap" />
  778.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\email.zap" />
  779.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\expert.dll" />
  780.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\filter.zap" />
  781.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\firewall.zap" />
  782.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\framewrk.dll" />
  783.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\idlock.zap" />
  784.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\imf_editor.exe" />
  785.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\imsecure.zap" />
  786.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\multiscan.exe" />
  787.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\privacy.zap" />
  788.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\programs.zap" />
  789.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\scan.zap" />
  790.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\scan.zmx" />
  791.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\security.zap" />
  792.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\zatutor.exe" />
  793.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\zauninst.exe" />
  794.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\zlavscan.dll" />
  795.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\zonealarm.exe" />
  796.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\zlclient.exe" />
  797.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\repair\vsdb.dll" />
  798.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\repair\vsinit.dll" />
  799.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\repair\vsmon.exe" />
  800.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\repair\vsruledb.dll" />
  801.         <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\repair\vsutil.dll" />
  802.  
  803.     </ruleentry>
  804. </rulegroup>
  805. <rulegroup name="protourreg">
  806.     <ruleentry event="registry" match="any" allow="false" notify="true" customtext="3">
  807.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs" />
  808.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\MiniLog" />
  809.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\TrueVector" />
  810.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\TrueVector\LocalStoreDir" />
  811.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\TrueVector\LogStoreDir" />
  812.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions" />
  813.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.ADE" />
  814.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.ADP" />
  815.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.ASX" />
  816.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.BAS" />
  817.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.BAT" />
  818.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.CHM" />
  819.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.CMD" />
  820.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.COM" />
  821.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.CPL" />
  822.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.CRT" />
  823.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.DBX" />
  824.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.EXE" />
  825.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.HLP" />
  826.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.HTA" />
  827.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.INF" />
  828.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.INS" />
  829.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.ISP" />
  830.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.JS" />
  831.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.JSE" />
  832.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.LNK" />
  833.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MDA" />
  834.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MDB" />
  835.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MDE" />
  836.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MDZ" />
  837.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MHT" />
  838.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MSC" />
  839.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MSI" />
  840.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MSP" />
  841.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MST" />
  842.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.NCH" />
  843.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.PCD" />
  844.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.PIF" />
  845.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.PRF" />
  846.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.REG" />
  847.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.SCF" />
  848.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.SCR" />
  849.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.SCT" />
  850.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.SHB" />
  851.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.SHS" />
  852.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.URL" />
  853.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.VB" />
  854.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.VBE" />
  855.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.VBS" />
  856.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.WMS" />
  857.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.WSC" />
  858.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.WSF" />
  859.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.WSH" />
  860.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.ZIP" />
  861.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\Registration" />
  862.         <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsdatant" />
  863.         <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsdatant\enum" />
  864.         <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsdatant\parameters" />
  865.         <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsdatant\security" />
  866.         <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsmon" />
  867.         <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsmon\enum" />
  868.         <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsmon\security" />
  869.     </ruleentry>                                                                            
  870. </rulegroup>
  871.  
  872. <rulegroup name="protourreg1">
  873.     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="3">
  874.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm" />
  875.         <itementry param="value" operator="equalnocase" type="ansi" value="InstallDirectory" />
  876.     </ruleentry>
  877. </rulegroup>
  878.  
  879. <rulegroup name="protourreg2">
  880.     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="3">
  881.         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm" />
  882.         <itementry param="value" operator="equalnocase" type="ansi" value="IntegrityMode" />
  883.     </ruleentry>
  884. </rulegroup>
  885.  
  886.  
  887.                 <!-- Protect IE Settings -->
  888.  
  889.                 <!-- Block default search URL -->
  890.                 <rulegroup name="blk-ie-search1">
  891.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4006">
  892.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Internet Explorer\Search" />
  893.                         <itementry param="value" operator="equalnocase" type="ansi" value="CustomizeSearch" />
  894.                     </ruleentry>
  895.                 </rulegroup>
  896.                 <rulegroup name="blk-ie-search2">
  897.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4006">
  898.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Internet Explorer\Search" />
  899.                         <itementry param="value" operator="equalnocase" type="ansi" value="CustomSearch" />
  900.                     </ruleentry>
  901.                 </rulegroup>
  902.                 <rulegroup name="blk-ie-search3">
  903.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4006">
  904.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Internet Explorer\Search" />
  905.                         <itementry param="value" operator="equalnocase" type="ansi" value="SearchAssistant" />
  906.                     </ruleentry>
  907.                 </rulegroup>
  908.                 <rulegroup name="blk-ie-search4">
  909.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4006">
  910.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer\Search" />
  911.                         <itementry param="value" operator="equalnocase" type="ansi" value="CustomizeSearch" />
  912.                     </ruleentry>
  913.                 </rulegroup>
  914.                 <rulegroup name="blk-ie-search5">
  915.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4006">
  916.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer\Search" />
  917.                         <itementry param="value" operator="equalnocase" type="ansi" value="CustomSearch" />
  918.                     </ruleentry>
  919.                 </rulegroup>
  920.                 <rulegroup name="blk-ie-search6">
  921.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4006">
  922.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer\Search" />
  923.                         <itementry param="value" operator="equalnocase" type="ansi" value="SearchAssistant" />
  924.                     </ruleentry>
  925.                 </rulegroup>
  926.                 <rulegroup name="blk-ie-search7">
  927.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4006">
  928.                         <!-- Defines Internet Search Engines -->
  929.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer" />
  930.                         <itementry param="value" operator="equalnocase" type="ansi" value="SearchUrl" />
  931.                     </ruleentry>
  932.                 </rulegroup>
  933.                 <rulegroup name="blk-ie-search8">
  934.                     <ruleentry event="registry" match="any" allow="false" notify="true" customtext="4006">
  935.                         <!-- CLSID of App (URL Search Hook object) that defines a custom network protocol -->
  936.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" />
  937.                     </ruleentry>
  938.                 </rulegroup>
  939.  
  940.                 <!-- Block IE Home Page -->
  941.                 <rulegroup name="blk-ie-home1">
  942.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4007">
  943.                         <!-- Defines Internet Search Engines -->
  944.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer\Main" />
  945.                         <itementry param="value" operator="equalnocase" type="ansi" value="Start Page" />
  946.                     </ruleentry>
  947.                 </rulegroup>
  948.                 <rulegroup name="blk-ie-home2">
  949.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4007">
  950.                         <!-- Defines Internet Search Engines -->
  951.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Internet Explorer\Main" />
  952.                         <itementry param="value" operator="equalnocase" type="ansi" value="Start Page" />
  953.                     </ruleentry>
  954.                 </rulegroup>
  955.  
  956.  
  957.                 <!-- Ask IE Settings -->
  958.  
  959.                 <!-- Ask default search URL -->
  960.                 <rulegroup name="ask-ie-search1">
  961.                     <ruleentry event="registry" match="all" ask="true" customtext="4006">
  962.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Internet Explorer\Search" />
  963.                         <itementry param="value" operator="equalnocase" type="ansi" value="CustomizeSearch" />
  964.                     </ruleentry>
  965.                 </rulegroup>
  966.                 <rulegroup name="ask-ie-search2">
  967.                     <ruleentry event="registry" match="all" ask="true" customtext="4006">
  968.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Internet Explorer\Search" />
  969.                         <itementry param="value" operator="equalnocase" type="ansi" value="CustomSearch" />
  970.                     </ruleentry>
  971.                 </rulegroup>
  972.                 <rulegroup name="ask-ie-search3">
  973.                     <ruleentry event="registry" match="all" ask="true" customtext="4006">
  974.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Internet Explorer\Search" />
  975.                         <itementry param="value" operator="equalnocase" type="ansi" value="SearchAssistant" />
  976.                     </ruleentry>
  977.                 </rulegroup>
  978.                 <rulegroup name="ask-ie-search4">
  979.                     <ruleentry event="registry" match="all" ask="true" customtext="4006">
  980.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer\Search" />
  981.                         <itementry param="value" operator="equalnocase" type="ansi" value="CustomizeSearch" />
  982.                     </ruleentry>
  983.                 </rulegroup>
  984.                 <rulegroup name="ask-ie-search5">
  985.                     <ruleentry event="registry" match="all" ask="true" customtext="4006">
  986.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer\Search" />
  987.                         <itementry param="value" operator="equalnocase" type="ansi" value="CustomSearch" />
  988.                     </ruleentry>
  989.                 </rulegroup>
  990.                 <rulegroup name="ask-ie-search6">
  991.                     <ruleentry event="registry" match="all" ask="true" customtext="4006">
  992.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer\Search" />
  993.                         <itementry param="value" operator="equalnocase" type="ansi" value="SearchAssistant" />
  994.                     </ruleentry>
  995.                 </rulegroup>
  996.                 <rulegroup name="ask-ie-search7">
  997.                     <ruleentry event="registry" match="all" ask="true" customtext="4006">
  998.                         <!-- Defines Internet Search Engines -->
  999.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer" />
  1000.                         <itementry param="value" operator="equalnocase" type="ansi" value="SearchUrl" />
  1001.                     </ruleentry>
  1002.                 </rulegroup>
  1003.                 <rulegroup name="ask-ie-search8">
  1004.                     <ruleentry event="registry" match="any" ask="true" customtext="4006">
  1005.                         <!-- CLSID of App (URL Search Hook object) that defines a custom network protocol -->
  1006.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks" />
  1007.                     </ruleentry>
  1008.                 </rulegroup>
  1009.  
  1010.                 <!-- Ask IE Home Page -->
  1011.                 <rulegroup name="ask-ie-home1">
  1012.                     <ruleentry event="registry" match="all" ask="true" customtext="4007">
  1013.                         <!-- Defines Internet Search Engines -->
  1014.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Internet Explorer\Main" />
  1015.                         <itementry param="value" operator="equalnocase" type="ansi" value="Start Page" />
  1016.                     </ruleentry>
  1017.                 </rulegroup>
  1018.                 <rulegroup name="ask-ie-home2">
  1019.                     <ruleentry event="registry" match="all" ask="true" customtext="4007">
  1020.                         <!-- Defines Internet Search Engines -->
  1021.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Internet Explorer\Main" />
  1022.                         <itementry param="value" operator="equalnocase" type="ansi" value="Start Page" />
  1023.                     </ruleentry>
  1024.                 </rulegroup>
  1025.  
  1026.                 <!-- Ask about Windows initialization -->
  1027.                 <rulegroup name="prot-winini">
  1028.                     <ruleentry event="file" match="any" ask="true" customtext="3002">
  1029.                         <itementry param="filename" operator="equalnocase" type="ansi" value="WINDIR\win.ini" />
  1030.                         <itementry param="filename" operator="equalnocase" type="ansi" value="ROOT\autoexec.bat" />
  1031.                         <itementry param="filename" operator="equalnocase" type="ansi" value="ROOT\config.sys" />
  1032.                         <itementry param="filename" operator="equalnocase" type="ansi" value="WINDIR\system.ini" />
  1033.                     </ruleentry>
  1034.                 </rulegroup>
  1035.                 <!-- Ask about hosts -->
  1036.                 <rulegroup name="prot-hosts">
  1037.                     <ruleentry event="file" match="all" ask="true" customtext="3001">
  1038.                         <itementry param="filename" operator="equalnocase" type="ansi" value="WINDRVDIR\etc\hosts" />
  1039.                     </ruleentry>
  1040.                 </rulegroup>
  1041.                 <ruleset name="rs-files-ask" allow="true">
  1042.                     <rulerefentry rulegroupref="prot-hosts"/>
  1043.                     <rulerefentry rulegroupref="protourfiles"/>
  1044.                 </ruleset>
  1045.  
  1046.                 <!-- Block Windows initialization -->
  1047.                 <rulegroup name="block-winini">
  1048.                     <ruleentry event="file" match="any" ask="true" customtext="3002">
  1049.                         <itementry param="filename" operator="equalnocase" type="ansi" value="WINDIR\win.ini" />
  1050.                         <itementry param="filename" operator="equalnocase" type="ansi" value="ROOT\autoexec.bat" />
  1051.                         <itementry param="filename" operator="equalnocase" type="ansi" value="ROOT\config.sys" />
  1052.                         <itementry param="filename" operator="equalnocase" type="ansi" value="WINDIR\system.ini" />
  1053.                     </ruleentry>
  1054.                 </rulegroup>
  1055.                 <!-- Block about hosts -->
  1056.                 <rulegroup name="block-hosts">
  1057.                     <ruleentry event="file" match="all" ask="true" customtext="3001">
  1058.                         <itementry param="filename" operator="equalnocase" type="ansi" value="WINDRVDIR\etc\hosts" />
  1059.                     </ruleentry>
  1060.                 </rulegroup>
  1061.                 <ruleset name="rs-files-block" allow="true">
  1062.                     <rulerefentry rulegroupref="block-hosts"/>
  1063.                     <rulerefentry rulegroupref="protourfiles"/>
  1064.                 </ruleset>
  1065.  
  1066.                 <!-- Protect our files -->
  1067.                 <ruleset name="rs-files-allow" allow="true">
  1068.                     <rulerefentry rulegroupref="protourfiles"/>
  1069.                 </ruleset>
  1070.  
  1071.                 <!-- Ask about ActiveX installation -->
  1072.                 <rulegroup name="protect-classes">
  1073.                     <ruleentry event="registry" match="any" ask="true" customtext="3003">
  1074.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Classes" />
  1075.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Classes\CLSID" />
  1076.                     </ruleentry>
  1077.                 </rulegroup>
  1078.  
  1079.                 <!-- Block ActiveX installation -->
  1080.                 <rulegroup name="block-classes">
  1081.                     <ruleentry event="registry" match="any" allow="false" notify="true" customtext="3003">
  1082.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Classes" />
  1083.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Classes\CLSID" />
  1084.                     </ruleentry>
  1085.                 </rulegroup>
  1086.  
  1087.                 <!-- Ask about Startup -->
  1088.                 <rulegroup name="protect-run1">
  1089.                     <ruleentry event="registry" match="any" ask="true" customtext="4001">
  1090.                         <!-- Windows AutoRuns Registry Keys -->
  1091.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\Run" />
  1092.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices" />
  1093.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce" />
  1094.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce" />
  1095.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx" />
  1096.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" />
  1097.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\Run" />
  1098.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices" />
  1099.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce" />
  1100.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce" />
  1101.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx" />
  1102.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" />
  1103.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad" />
  1104.                     </ruleentry>
  1105.                 </rulegroup>
  1106.                 <rulegroup name="protect-run2">
  1107.                     <ruleentry event="registry" match="all" ask="true" customtext="4001">
  1108.                         <!-- Windows AutoRuns Registry Values -->
  1109.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" />
  1110.                         <itementry param="value" operator="equalnocase" type="ansi" value="Run" />
  1111.                     </ruleentry>
  1112.                 </rulegroup>
  1113.                 <rulegroup name="protect-run3">
  1114.                     <ruleentry event="registry" match="all" ask="true" customtext="4001">
  1115.                         <!-- Windows AutoRuns Registry Values -->
  1116.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" />
  1117.                         <itementry param="value" operator="equalnocase" type="ansi" value="Load" />
  1118.                     </ruleentry>
  1119.                 </rulegroup>
  1120.                 <rulegroup name="protect-run4">
  1121.                     <ruleentry event="registry" match="all" ask="true" customtext="4001">
  1122.                         <!-- Windows AutoRuns Registry Values -->
  1123.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" />
  1124.                         <itementry param="value" operator="equalnocase" type="ansi" value="Userinit" />
  1125.                     </ruleentry>
  1126.                 </rulegroup>
  1127.                 <rulegroup name="protect-run5">
  1128.                     <ruleentry event="registry" match="all" ask="true" customtext="4001">
  1129.                         <!-- Windows AutoRuns Registry Values -->
  1130.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" />
  1131.                         <itementry param="value" operator="equalnocase" type="ansi" value="Shell" />
  1132.                     </ruleentry>
  1133.                 </rulegroup>
  1134.                 
  1135.                 <!-- AskSDenyD registry protection -->
  1136.                 <ruleset name="rs-rega-asdd" allow="true">
  1137.                     <rulerefentry rulegroupref="protect-run1"/>
  1138.                     <rulerefentry rulegroupref="protect-run2"/>
  1139.                     <rulerefentry rulegroupref="protect-run3"/>
  1140.                     <rulerefentry rulegroupref="protect-run4"/>
  1141.                     <rulerefentry rulegroupref="protect-run5"/>
  1142.                     <rulerefentry rulegroupref="ask-ie-search1"/>
  1143.                     <rulerefentry rulegroupref="ask-ie-search2"/>
  1144.                     <rulerefentry rulegroupref="ask-ie-search3"/>
  1145.                     <rulerefentry rulegroupref="ask-ie-search4"/>
  1146.                     <rulerefentry rulegroupref="ask-ie-search5"/>
  1147.                     <rulerefentry rulegroupref="ask-ie-search6"/>
  1148.                     <rulerefentry rulegroupref="ask-ie-search7"/>
  1149.                     <rulerefentry rulegroupref="ask-ie-search8"/>
  1150.                     <rulerefentry rulegroupref="ask-ie-home1"/>
  1151.                     <rulerefentry rulegroupref="ask-ie-home2"/>
  1152.                     <rulerefentry rulegroupref="protourreg"/>
  1153.                     <rulerefentry rulegroupref="protourreg1"/>
  1154.                     <rulerefentry rulegroupref="protourreg2"/>
  1155.                 </ruleset>
  1156.  
  1157.                 <!-- AskSD registry protection -->
  1158.                 <ruleset name="rs-rega-asad" allow="true">
  1159.                     <rulerefentry rulegroupref="protect-run1"/>
  1160.                     <rulerefentry rulegroupref="protect-run2"/>
  1161.                     <rulerefentry rulegroupref="protect-run3"/>
  1162.                     <rulerefentry rulegroupref="protect-run4"/>
  1163.                     <rulerefentry rulegroupref="protect-run5"/>
  1164.                     <rulerefentry rulegroupref="ask-ie-search1"/>
  1165.                     <rulerefentry rulegroupref="ask-ie-search2"/>
  1166.                     <rulerefentry rulegroupref="ask-ie-search3"/>
  1167.                     <rulerefentry rulegroupref="ask-ie-search4"/>
  1168.                     <rulerefentry rulegroupref="ask-ie-search5"/>
  1169.                     <rulerefentry rulegroupref="ask-ie-search6"/>
  1170.                     <rulerefentry rulegroupref="ask-ie-search7"/>
  1171.                     <rulerefentry rulegroupref="ask-ie-search8"/>
  1172.                     <rulerefentry rulegroupref="ask-ie-home1"/>
  1173.                     <rulerefentry rulegroupref="ask-ie-home2"/>
  1174.                     <rulerefentry rulegroupref="protourreg"/>
  1175.                     <rulerefentry rulegroupref="protourreg1"/>
  1176.                     <rulerefentry rulegroupref="protourreg2"/>
  1177.                 </ruleset>
  1178.  
  1179.                 <!-- Ask about Deleting Startup -->
  1180.                 <rulegroup name="askdel-run1">
  1181.                     <ruleentry event="registry" match="any" ask="true" customtext="4004">
  1182.                         <!-- Windows AutoRuns Registry Keys -->
  1183.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\Run" />
  1184.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices" />
  1185.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" />
  1186.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\Run" />
  1187.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices" />
  1188.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" />
  1189.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad" />
  1190.                     </ruleentry>
  1191.                 </rulegroup>
  1192.                 <rulegroup name="askdel-run2">
  1193.                     <ruleentry event="registry" match="all" ask="true" customtext="4004">
  1194.                         <!-- Windows AutoRuns Registry Values -->
  1195.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" />
  1196.                         <itementry param="value" operator="equalnocase" type="ansi" value="Run" />
  1197.                     </ruleentry>
  1198.                 </rulegroup>
  1199.                 <rulegroup name="askdel-run3">
  1200.                     <ruleentry event="registry" match="all" ask="true" customtext="4004">
  1201.                         <!-- Windows AutoRuns Registry Values -->
  1202.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" />
  1203.                         <itementry param="value" operator="equalnocase" type="ansi" value="Load" />
  1204.                     </ruleentry>
  1205.                 </rulegroup>
  1206.                 <rulegroup name="askdel-run4">
  1207.                     <ruleentry event="registry" match="all" ask="true" customtext="4004">
  1208.                         <!-- Windows AutoRuns Registry Values -->
  1209.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" />
  1210.                         <itementry param="value" operator="equalnocase" type="ansi" value="Userinit" />
  1211.                     </ruleentry>
  1212.                 </rulegroup>
  1213.                 <rulegroup name="askdel-run5">
  1214.                     <ruleentry event="registry" match="all" ask="true" customtext="4004">
  1215.                         <!-- Windows AutoRuns Registry Values -->
  1216.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" />
  1217.                         <itementry param="value" operator="equalnocase" type="ansi" value="Shell" />
  1218.                     </ruleentry>
  1219.                 </rulegroup>
  1220.                 
  1221.                 <!-- AskSDenyD delete registry protection -->
  1222.                 <ruleset name="rs-regd-asdd" allow="true">
  1223.                     <rulerefentry rulegroupref="askdel-run1"/>
  1224.                     <rulerefentry rulegroupref="askdel-run2"/>
  1225.                     <rulerefentry rulegroupref="askdel-run3"/>
  1226.                     <rulerefentry rulegroupref="askdel-run4"/>
  1227.                     <rulerefentry rulegroupref="askdel-run5"/>
  1228.                     <rulerefentry rulegroupref="protourreg"/>
  1229.                     <rulerefentry rulegroupref="protourreg1"/>
  1230.                     <rulerefentry rulegroupref="protourreg2"/>
  1231.                 </ruleset>
  1232.  
  1233.                 <!-- AskSD delete registry protection -->
  1234.                 <ruleset name="rs-regd-asad" allow="true">
  1235.                     <rulerefentry rulegroupref="askdel-run1"/>
  1236.                     <rulerefentry rulegroupref="askdel-run2"/>
  1237.                     <rulerefentry rulegroupref="askdel-run3"/>
  1238.                     <rulerefentry rulegroupref="askdel-run4"/>
  1239.                     <rulerefentry rulegroupref="askdel-run5"/>
  1240.                     <rulerefentry rulegroupref="protourreg"/>
  1241.                     <rulerefentry rulegroupref="protourreg1"/>
  1242.                     <rulerefentry rulegroupref="protourreg2"/>
  1243.                 </ruleset>
  1244.  
  1245.                 <!-- AllowSAskD delete registry protection -->
  1246.                 <ruleset name="rs-regd-sad" allow="true">
  1247.                     <rulerefentry rulegroupref="protourreg"/>
  1248.                     <rulerefentry rulegroupref="protourreg1"/>
  1249.                     <rulerefentry rulegroupref="protourreg2"/>
  1250.                 </ruleset>
  1251.  
  1252.                 <!-- AllowSDenyD delete registry protection -->
  1253.                 <ruleset name="rs-regd-sdd" allow="true">
  1254.                     <rulerefentry rulegroupref="protourreg"/>
  1255.                     <rulerefentry rulegroupref="protourreg1"/>
  1256.                     <rulerefentry rulegroupref="protourreg2"/>
  1257.                 </ruleset>
  1258.  
  1259.                 <!-- Block Adding Startup -->
  1260.                 <rulegroup name="block-run1">
  1261.                     <ruleentry event="registry" match="any" allow="false" notify="true" customtext="4001">
  1262.                         <!-- Windows AutoRuns Registry Keys -->
  1263.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\Run" />
  1264.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices" />
  1265.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce" />
  1266.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce" />
  1267.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx" />
  1268.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" />
  1269.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\Run" />
  1270.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices" />
  1271.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce" />
  1272.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce" />
  1273.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx" />
  1274.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" />
  1275.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad" />
  1276.                     </ruleentry>
  1277.                 </rulegroup>
  1278.                 <rulegroup name="block-run2">
  1279.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4001">
  1280.                         <!-- Windows AutoRuns Registry Values -->
  1281.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" />
  1282.                         <itementry param="value" operator="equalnocase" type="ansi" value="Run" />
  1283.                     </ruleentry>
  1284.                 </rulegroup>
  1285.                 <rulegroup name="block-run3">
  1286.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4001">
  1287.                         <!-- Windows AutoRuns Registry Values -->
  1288.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" />
  1289.                         <itementry param="value" operator="equalnocase" type="ansi" value="Load" />
  1290.                     </ruleentry>
  1291.                 </rulegroup>
  1292.                 <rulegroup name="block-run4">
  1293.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4001">
  1294.                         <!-- Windows AutoRuns Registry Values -->
  1295.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" />
  1296.                         <itementry param="value" operator="equalnocase" type="ansi" value="Userinit" />
  1297.                     </ruleentry>
  1298.                 </rulegroup>
  1299.                 <rulegroup name="block-run5">
  1300.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4001">
  1301.                         <!-- Windows AutoRuns Registry Values -->
  1302.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" />
  1303.                         <itementry param="value" operator="equalnocase" type="ansi" value="Shell" />
  1304.                     </ruleentry>
  1305.                 </rulegroup>
  1306.  
  1307.                 <ruleset name="rs-rega-block" allow="true">
  1308.                     <rulerefentry rulegroupref="block-run1"/>
  1309.                     <rulerefentry rulegroupref="block-run2"/>
  1310.                     <rulerefentry rulegroupref="block-run3"/>
  1311.                     <rulerefentry rulegroupref="block-run4"/>
  1312.                     <rulerefentry rulegroupref="block-run5"/>
  1313.                     <rulerefentry rulegroupref="blk-ie-search1"/>
  1314.                     <rulerefentry rulegroupref="blk-ie-search2"/>
  1315.                     <rulerefentry rulegroupref="blk-ie-search3"/>
  1316.                     <rulerefentry rulegroupref="blk-ie-search4"/>
  1317.                     <rulerefentry rulegroupref="blk-ie-search5"/>
  1318.                     <rulerefentry rulegroupref="blk-ie-search6"/>
  1319.                     <rulerefentry rulegroupref="blk-ie-search7"/>
  1320.                     <rulerefentry rulegroupref="blk-ie-search8"/>
  1321.                     <rulerefentry rulegroupref="blk-ie-home1"/>
  1322.                     <rulerefentry rulegroupref="blk-ie-home2"/>
  1323.                     <rulerefentry rulegroupref="protourreg"/>
  1324.                     <rulerefentry rulegroupref="protourreg1"/>
  1325.                     <rulerefentry rulegroupref="protourreg2"/>
  1326.                 </ruleset>
  1327.  
  1328.                 <!-- Block Deleting Startup -->
  1329.                 <rulegroup name="block-run1">
  1330.                     <ruleentry event="registry" match="any" allow="false" notify="true" customtext="4004">
  1331.                         <!-- Windows AutoRuns Registry Keys -->
  1332.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\Run" />
  1333.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices" />
  1334.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce" />
  1335.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce" />
  1336.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx" />
  1337.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" />
  1338.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\Run" />
  1339.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices" />
  1340.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce" />
  1341.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce" />
  1342.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx" />
  1343.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run" />
  1344.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad" />
  1345.                     </ruleentry>
  1346.                 </rulegroup>
  1347.                 <rulegroup name="block-run2">
  1348.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4004">
  1349.                         <!-- Windows AutoRuns Registry Values -->
  1350.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" />
  1351.                         <itementry param="value" operator="equalnocase" type="ansi" value="Run" />
  1352.                     </ruleentry>
  1353.                 </rulegroup>
  1354.                 <rulegroup name="block-run3">
  1355.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4004">
  1356.                         <!-- Windows AutoRuns Registry Values -->
  1357.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" />
  1358.                         <itementry param="value" operator="equalnocase" type="ansi" value="Load" />
  1359.                     </ruleentry>
  1360.                 </rulegroup>
  1361.                 <rulegroup name="block-run4">
  1362.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4004">
  1363.                         <!-- Windows AutoRuns Registry Values -->
  1364.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" />
  1365.                         <itementry param="value" operator="equalnocase" type="ansi" value="Userinit" />
  1366.                     </ruleentry>
  1367.                 </rulegroup>
  1368.                 <rulegroup name="block-run5">
  1369.                     <ruleentry event="registry" match="all" allow="false" notify="true" customtext="4004">
  1370.                         <!-- Windows AutoRuns Registry Values -->
  1371.                         <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" />
  1372.                         <itementry param="value" operator="equalnocase" type="ansi" value="Shell" />
  1373.                     </ruleentry>
  1374.                 </rulegroup>
  1375.  
  1376.                 <ruleset name="rs-regd-block" allow="true">
  1377.                     <rulerefentry rulegroupref="block-run1"/>
  1378.                     <rulerefentry rulegroupref="block-run2"/>
  1379.                     <rulerefentry rulegroupref="block-run3"/>
  1380.                     <rulerefentry rulegroupref="block-run4"/>
  1381.                     <rulerefentry rulegroupref="block-run5"/>
  1382.                     <rulerefentry rulegroupref="blk-ie-search1"/>
  1383.                     <rulerefentry rulegroupref="blk-ie-search2"/>
  1384.                     <rulerefentry rulegroupref="blk-ie-search3"/>
  1385.                     <rulerefentry rulegroupref="blk-ie-search4"/>
  1386.                     <rulerefentry rulegroupref="blk-ie-search5"/>
  1387.                     <rulerefentry rulegroupref="blk-ie-search6"/>
  1388.                     <rulerefentry rulegroupref="blk-ie-search7"/>
  1389.                     <rulerefentry rulegroupref="blk-ie-search8"/>
  1390.                     <rulerefentry rulegroupref="blk-ie-home1"/>
  1391.                     <rulerefentry rulegroupref="blk-ie-home2"/>
  1392.                     <rulerefentry rulegroupref="protourreg"/>
  1393.                     <rulerefentry rulegroupref="protourreg1"/>
  1394.                     <rulerefentry rulegroupref="protourreg2"/>
  1395.                 </ruleset>
  1396.  
  1397.                 <!-- AllowSD and Protect our keys -->
  1398.                 <ruleset name="rs-reg-allow" allow="true">
  1399.                     <rulerefentry rulegroupref="protourreg"/>
  1400.                     <rulerefentry rulegroupref="protourreg1"/>
  1401.                     <rulerefentry rulegroupref="protourreg2"/>
  1402.                 </ruleset>
  1403.  
  1404.                 <!-- AllowSAskD and Protect our keys -->
  1405.                 <ruleset name="rs-rega-sdd" allow="true">
  1406.                     <rulerefentry rulegroupref="protourreg"/>
  1407.                     <rulerefentry rulegroupref="protourreg1"/>
  1408.                     <rulerefentry rulegroupref="protourreg2"/>
  1409.                 </ruleset>
  1410.  
  1411.                 <!-- AllowSDenyD and Protect our keys -->
  1412.                 <ruleset name="rs-rega-sad" allow="true">
  1413.                     <rulerefentry rulegroupref="protourreg"/>
  1414.                     <rulerefentry rulegroupref="protourreg1"/>
  1415.                     <rulerefentry rulegroupref="protourreg2"/>
  1416.                 </ruleset>
  1417.  
  1418.                 <!-- Public Event Groups In Ascending Order of Weight -->
  1419.  
  1420.                 <eventgroup name="DenySD" description="DenySD" weight="15" allowweightranges="0-19" severityref="normal" trustChoice="restricted" trustDisplay="restricted" trustDetail="DenySD">
  1421.  
  1422.                     <evententry class="srcproc" event="process" subevent="openprocess" rulegroupref="rg-openp-ask" />
  1423.                     <evententry class="srcproc" event="process" subevent="openthread"  rulegroupref="rg-opent-ask" />
  1424.                     <evententry class="srcproc" event="process" subevent="spawnprocess"  rulegroupref="rg-spawn-ask" />
  1425.                     <evententry class="srcproc" event="process" subevent="startupprocess" allow="true" />
  1426.                     <evententry class="srcproc" event="process" subevent="terminateprocess" rulegroupref="rg-termp-ask" />
  1427.                     <evententry class="srcproc" event="message" subevent="keyboard"  rulegroupref="rg-keybd-ask" />
  1428.                     <evententry class="srcproc" event="message" subevent="mouse"  allow="true" />
  1429.                     <evententry class="srcproc" event="message" subevent="dde"  rulegroupref="rg-ddein-ask" />
  1430.                     <evententry class="srcproc" event="message" subevent="message"  rulegroupref="rg-msg-ask" />
  1431.                     <evententry class="srcproc" event="execution" subevent="callback"  rulegroupref="rg-callb-ask" />
  1432.                     <evententry class="srcproc" event="execution" subevent="windowshook"  rulegroupref="rg-whook-ask" />
  1433.  
  1434.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook" rulegroupref="rg-glbhook-blk" />
  1435.                     <evententry class="srcproc" event="registry" subevent="setkey" rulesetref="rs-rega-block"/>
  1436.                     <evententry class="srcproc" event="registry" subevent="setvalue" rulesetref="rs-rega-block"/>
  1437.                     <evententry class="srcproc" event="registry" subevent="delkey" rulesetref="rs-regd-block"/>
  1438.                     <evententry class="srcproc" event="registry" subevent="delvalue" rulesetref="rs-regd-block"/>
  1439.                     <evententry class="srcproc" event="registry" subevent="createkey" rulesetref="rs-rega-block"/>
  1440.                     <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-block"/>
  1441.                     <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-block"/>
  1442.                     <evententry class="srcproc" event="module" subevent="load" rulegroupref="rg-modld-ok" />
  1443.                     <evententry class="srcproc" event="driver" subevent="load" rulegroupref="rg-drvld-blk" />
  1444.                     <evententry class="srcproc" event="driver" subevent="unload" rulegroupref="rg-drvud-blk" />
  1445.                     <evententry class="srcproc" event="driver" subevent="connect" rulegroupref="rg-drvct-blk" />
  1446.                     <evententry class="srcproc" event="physmem" subevent="map" rulegroupref="rg-memmp-blk" />
  1447.  
  1448.                     <evententry class="dstproc" event="process" subevent="openprocess" ask="true" />
  1449.                     <evententry class="dstproc" event="process" subevent="openthread" ask="true" />
  1450.                     <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
  1451.                     <evententry class="dstproc" event="process" subevent="terminateprocess" ask="true" />
  1452.                     <evententry class="dstproc" event="message" subevent="keyboard" ask="true" />
  1453.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1454.                     <evententry class="dstproc" event="message" subevent="dde" ask="true" />
  1455.                     <evententry class="dstproc" event="message" subevent="message"  ask="true" />
  1456.                     <evententry class="dstproc" event="execution" subevent="callback" ask="true" />
  1457.                     <evententry class="dstproc" event="execution" subevent="windowshook" ask="true" />
  1458.  
  1459.                 </eventgroup>
  1460.  
  1461.                 <eventgroup name="AskSDenyD" description="AskSDenyD" weight="25" allowweightranges="0-29" askweightranges="30-39" severityref="suspicious" trustDisplay="restricted" trustDetail="AskSDenyD">
  1462.  
  1463.                     <evententry class="srcproc" event="process" subevent="openprocess" rulegroupref="rg-openp-ask" />
  1464.                     <evententry class="srcproc" event="process" subevent="openthread"  rulegroupref="rg-opent-ask" />
  1465.                     <evententry class="srcproc" event="process" subevent="spawnprocess"  rulegroupref="rg-spawn-ask" />
  1466.                     <evententry class="srcproc" event="process" subevent="startupprocess"  allow="true" />
  1467.                     <evententry class="srcproc" event="process" subevent="terminateprocess" rulegroupref="rg-termp-ask" />
  1468.                     <evententry class="srcproc" event="message" subevent="keyboard"  rulegroupref="rg-keybd-ask" />
  1469.                     <evententry class="srcproc" event="message" subevent="mouse" allow="true" />
  1470.                     <evententry class="srcproc" event="message" subevent="dde"  rulegroupref="rg-ddein-ask" />
  1471.                     <evententry class="srcproc" event="message" subevent="message"  rulegroupref="rg-msg-ask" />
  1472.                     <evententry class="srcproc" event="execution" subevent="callback"  rulegroupref="rg-callb-ask" />
  1473.                     <evententry class="srcproc" event="execution" subevent="windowshook"  rulegroupref="rg-whook-ask" />
  1474.  
  1475.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook" rulegroupref="rg-glbhook-blk" />
  1476.                     <evententry class="srcproc" event="registry" subevent="setkey"  rulesetref="rs-rega-asdd"/>
  1477.                     <evententry class="srcproc" event="registry" subevent="setvalue"  rulesetref="rs-rega-asdd"/>
  1478.                     <evententry class="srcproc" event="registry" subevent="delkey"  rulesetref="rs-regd-asdd"/>
  1479.                     <evententry class="srcproc" event="registry" subevent="delvalue"  rulesetref="rs-regd-asdd"/>
  1480.                     <evententry class="srcproc" event="registry" subevent="createkey"  rulesetref="rs-rega-asdd"/>
  1481.                     <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-block"/>
  1482.                     <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-block"/>
  1483.                     <evententry class="srcproc" event="module" subevent="load" rulegroupref="rg-modld-ok" />
  1484.                     <evententry class="srcproc" event="driver" subevent="load"  rulegroupref="rg-drvld-blk" />
  1485.                     <evententry class="srcproc" event="driver" subevent="unload"  rulegroupref="rg-drvud-ask" />
  1486.                     <evententry class="srcproc" event="driver" subevent="connect"  allow="true" />
  1487.                     <evententry class="srcproc" event="physmem" subevent="map"  rulegroupref="rg-memmp-blk" />
  1488.  
  1489.                     <evententry class="dstproc" event="process" subevent="openprocess" ask="true" />
  1490.                     <evententry class="dstproc" event="process" subevent="openthread" ask="true" />
  1491.                     <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
  1492.                     <evententry class="dstproc" event="process" subevent="terminateprocess" ask="true" />
  1493.                     <evententry class="dstproc" event="message" subevent="keyboard" ask="true" />
  1494.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1495.                     <evententry class="dstproc" event="message" subevent="dde" ask="true" />
  1496.                     <evententry class="dstproc" event="message" subevent="message"  ask="true" />
  1497.                     <evententry class="dstproc" event="execution" subevent="callback" ask="true" />
  1498.                     <evententry class="dstproc" event="execution" subevent="windowshook" ask="true" />
  1499.  
  1500.                 </eventgroup>
  1501.  
  1502.                 <eventgroup name="AllowSDenyD" description="AllowSDenyD" weight="35" allowweightranges="0-39" severityref="suspicious" trustDisplay="trusted" trustDetail="AllowSDenyD">
  1503.  
  1504.                     <evententry class="srcproc" event="process" subevent="openprocess" rulegroupref="rg-openp-ask" />
  1505.                     <evententry class="srcproc" event="process" subevent="openthread"  rulegroupref="rg-opent-ask" />
  1506.                     <evententry class="srcproc" event="process" subevent="spawnprocess"  rulegroupref="rg-spawn-ask" />
  1507.                     <evententry class="srcproc" event="process" subevent="startupprocess"  allow="true" />
  1508.                     <evententry class="srcproc" event="process" subevent="terminateprocess" rulegroupref="rg-termp-ask" />
  1509.                     <evententry class="srcproc" event="message" subevent="keyboard"  rulegroupref="rg-keybd-ask" />
  1510.                     <evententry class="srcproc" event="message" subevent="mouse"  allow="true" />
  1511.                     <evententry class="srcproc" event="message" subevent="dde"  rulegroupref="rg-ddein-ask" />
  1512.                     <evententry class="srcproc" event="message" subevent="message"  rulegroupref="rg-msg-ask" />
  1513.                     <evententry class="srcproc" event="execution" subevent="callback"  rulegroupref="rg-callb-ask" />
  1514.                     <evententry class="srcproc" event="execution" subevent="windowshook"  rulegroupref="rg-whook-ask" />
  1515.  
  1516.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook" rulegroupref="rg-glbhook-blk" />
  1517.                     <evententry class="srcproc" event="registry" subevent="setkey" rulesetref="rs-rega-sdd"/>
  1518.                     <evententry class="srcproc" event="registry" subevent="setvalue" rulesetref="rs-rega-sdd"/>
  1519.                     <evententry class="srcproc" event="registry" subevent="delkey" rulesetref="rs-regd-sdd"/>
  1520.                     <evententry class="srcproc" event="registry" subevent="delvalue" rulesetref="rs-regd-sdd"/>
  1521.                     <evententry class="srcproc" event="registry" subevent="createkey" rulesetref="rs-rega-sdd"/>
  1522.                     <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-block"/>
  1523.                     <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-block"/>
  1524.                     <evententry class="srcproc" event="module" subevent="load" rulegroupref="rg-modld-ok" />
  1525.                     <evententry class="srcproc" event="driver" subevent="load" rulegroupref="rg-drvld-blk" />
  1526.                     <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
  1527.                     <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
  1528.                     <evententry class="srcproc" event="physmem" subevent="map" rulegroupref="rg-memmp-blk" />
  1529.  
  1530.                     <evententry class="dstproc" event="process" subevent="openprocess" ask="true" />
  1531.                     <evententry class="dstproc" event="process" subevent="openthread" ask="true" />
  1532.                     <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
  1533.                     <evententry class="dstproc" event="process" subevent="terminateprocess" ask="true" />
  1534.                     <evententry class="dstproc" event="message" subevent="keyboard" ask="true" />
  1535.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1536.                     <evententry class="dstproc" event="message" subevent="dde" ask="true" />
  1537.                     <evententry class="dstproc" event="message" subevent="message"  ask="true" />
  1538.                     <evententry class="dstproc" event="execution" subevent="callback" ask="true" />
  1539.                     <evententry class="dstproc" event="execution" subevent="windowshook" ask="true" />
  1540.  
  1541.                 </eventgroup>
  1542.  
  1543.                 <eventgroup name="AskSD" description="AskSD" weight="45" allowweightranges="0-29,40-49" askweightranges="30-39,50-69" severityref="dangerous" trustChoice="ask" trustDisplay="ask" trustDetail="AskSD">
  1544.  
  1545.                     <evententry class="srcproc" event="process" subevent="openprocess" rulegroupref="rg-openp-ask" />
  1546.                     <evententry class="srcproc" event="process" subevent="openthread"  rulegroupref="rg-opent-ask" />
  1547.                     <evententry class="srcproc" event="process" subevent="spawnprocess"  rulegroupref="rg-spawn-ask" />
  1548.                     <evententry class="srcproc" event="process" subevent="startupprocess"  ask="true" />
  1549.                     <evententry class="srcproc" event="process" subevent="terminateprocess" rulegroupref="rg-termp-ask" />
  1550.                     <evententry class="srcproc" event="message" subevent="keyboard"  rulegroupref="rg-keybd-ask" />
  1551.                     <evententry class="srcproc" event="message" subevent="mouse"  allow="true" />
  1552.                     <evententry class="srcproc" event="message" subevent="dde"  rulegroupref="rg-ddein-ask" />
  1553.                     <evententry class="srcproc" event="message" subevent="message"  rulegroupref="rg-msg-ask" />
  1554.                     <evententry class="srcproc" event="execution" subevent="callback"  rulegroupref="rg-callb-ask" />
  1555.                     <evententry class="srcproc" event="execution" subevent="windowshook"  rulegroupref="rg-whook-ask" />
  1556.  
  1557.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook"  rulegroupref="rg-glbhook-ask" />
  1558.                     <evententry class="srcproc" event="registry" subevent="setkey"  rulesetref="rs-rega-asad"/>
  1559.                     <evententry class="srcproc" event="registry" subevent="setvalue"  rulesetref="rs-rega-asad"/>
  1560.                     <evententry class="srcproc" event="registry" subevent="delkey"  rulesetref="rs-regd-asad"/>
  1561.                     <evententry class="srcproc" event="registry" subevent="delvalue"  rulesetref="rs-regd-asad"/>
  1562.                     <evententry class="srcproc" event="registry" subevent="createkey"  rulesetref="rs-rega-asad"/>
  1563.                     <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-ask"/>
  1564.                     <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-ask"/>
  1565.                     <evententry class="srcproc" event="module" subevent="load" rulegroupref="rg-modld-ok" />
  1566.                     <evententry class="srcproc" event="driver" subevent="load"  rulegroupref="rg-drvld-ask" />
  1567.                     <evententry class="srcproc" event="driver" subevent="unload"  rulegroupref="rg-drvud-ask" />
  1568.                     <evententry class="srcproc" event="driver" subevent="connect"  allow="true" />
  1569.                     <evententry class="srcproc" event="physmem" subevent="map"  rulegroupref="rg-memmp-ask" />
  1570.  
  1571.                     <evententry class="dstproc" event="process" subevent="openprocess" ask="true" />
  1572.                     <evententry class="dstproc" event="process" subevent="openthread" ask="true" />
  1573.                     <evententry class="dstproc" event="process" subevent="startupprocess" weight="FF" ask="true" />
  1574.                     <evententry class="dstproc" event="process" subevent="terminateprocess" ask="true" />
  1575.                     <evententry class="dstproc" event="message" subevent="keyboard" ask="true" />
  1576.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1577.                     <evententry class="dstproc" event="message" subevent="dde" ask="true" />
  1578.                     <evententry class="dstproc" event="message" subevent="message"  ask="true" />
  1579.                     <evententry class="dstproc" event="execution" subevent="callback" ask="true" />
  1580.                     <evententry class="dstproc" event="execution" subevent="windowshook" ask="true" />
  1581.  
  1582.                 </eventgroup>
  1583.  
  1584.                 <eventgroup name="AllowSAskD" description="AllowSAskD" weight="55" allowweightranges="0-59" askweightranges="60-69" severityref="dangerous" trustChoice="trusted" trustDisplay="trusted" trustDetail="AllowSAskD">
  1585.  
  1586.                     <evententry class="srcproc" event="process" subevent="openprocess" rulegroupref="rg-openp-ask" />
  1587.                     <evententry class="srcproc" event="process" subevent="openthread"  rulegroupref="rg-opent-ask" />
  1588.                     <evententry class="srcproc" event="process" subevent="spawnprocess"  rulegroupref="rg-spawn-ask" />
  1589.                     <evententry class="srcproc" event="process" subevent="startupprocess"  allow="true" />
  1590.                     <evententry class="srcproc" event="process" subevent="terminateprocess" rulegroupref="rg-termp-ask" />
  1591.                     <evententry class="srcproc" event="message" subevent="keyboard"  rulegroupref="rg-keybd-ask" />
  1592.                     <evententry class="srcproc" event="message" subevent="mouse"  allow="true" />
  1593.                     <evententry class="srcproc" event="message" subevent="dde"  rulegroupref="rg-ddein-ask" />
  1594.                     <evententry class="srcproc" event="message" subevent="message"  rulegroupref="rg-msg-ask" />
  1595.                     <evententry class="srcproc" event="execution" subevent="callback"  rulegroupref="rg-callb-ask" />
  1596.                     <evententry class="srcproc" event="execution" subevent="windowshook"  rulegroupref="rg-whook-ask" />
  1597.  
  1598.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook"  rulegroupref="rg-glbhook-ask" />
  1599.                     <evententry class="srcproc" event="registry" subevent="setkey" rulesetref="rs-rega-sad"/>
  1600.                     <evententry class="srcproc" event="registry" subevent="setvalue" rulesetref="rs-rega-sad"/>
  1601.                     <evententry class="srcproc" event="registry" subevent="delkey" rulesetref="rs-regd-sad"/>
  1602.                     <evententry class="srcproc" event="registry" subevent="delvalue" rulesetref="rs-regd-sad"/>
  1603.                     <evententry class="srcproc" event="registry" subevent="createkey" rulesetref="rs-rega-sad"/>
  1604.                     <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-ask"/>
  1605.                     <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-ask"/>
  1606.                     <evententry class="srcproc" event="module" subevent="load" rulegroupref="rg-modld-ok" />
  1607.                     <evententry class="srcproc" event="driver" subevent="load" rulegroupref="rg-drvld-ask" />
  1608.                     <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
  1609.                     <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
  1610.                     <evententry class="srcproc" event="physmem" subevent="map" rulegroupref="rg-memmp-ask" />
  1611.  
  1612.                     <evententry class="dstproc" event="process" subevent="openprocess" ask="true" />
  1613.                     <evententry class="dstproc" event="process" subevent="openthread" ask="true" />
  1614.                     <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
  1615.                     <evententry class="dstproc" event="process" subevent="terminateprocess" ask="true" />
  1616.                     <evententry class="dstproc" event="message" subevent="keyboard" ask="true" />
  1617.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1618.                     <evententry class="dstproc" event="message" subevent="dde" ask="true" />
  1619.                     <evententry class="dstproc" event="message" subevent="message"  ask="true" />
  1620.                     <evententry class="dstproc" event="execution" subevent="callback" ask="true" />
  1621.                     <evententry class="dstproc" event="execution" subevent="windowshook" ask="true" />
  1622.  
  1623.                 </eventgroup>
  1624.  
  1625.                 <eventgroup name="AllowSD" description="AllowSD" weight="65" allowweightranges="0-69" severityref="dangerous" trustChoice="super" trustDisplay="super" trustDetail="AllowSD">
  1626.  
  1627.                     <evententry class="srcproc" event="process" subevent="openprocess" rulegroupref="rg-openp-ask" />
  1628.                     <evententry class="srcproc" event="process" subevent="openthread"  rulegroupref="rg-opent-ask" />
  1629.                     <evententry class="srcproc" event="process" subevent="spawnprocess"  rulegroupref="rg-spawn-ask" />
  1630.                     <evententry class="srcproc" event="process" subevent="startupprocess"  allow="true" />
  1631.                     <evententry class="srcproc" event="process" subevent="terminateprocess" rulegroupref="rg-termp-ask" />
  1632.                     <evententry class="srcproc" event="message" subevent="keyboard"  rulegroupref="rg-keybd-ask" />
  1633.                     <evententry class="srcproc" event="message" subevent="mouse" weight="66" allow="true" />
  1634.                     <evententry class="srcproc" event="message" subevent="dde"  rulegroupref="rg-ddein-ask" />
  1635.                     <evententry class="srcproc" event="message" subevent="message"  rulegroupref="rg-msg-ask" />
  1636.                     <evententry class="srcproc" event="execution" subevent="callback"  rulegroupref="rg-callb-ask" />
  1637.                     <evententry class="srcproc" event="execution" subevent="windowshook"  rulegroupref="rg-whook-ask" />
  1638.  
  1639.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook"  allow="true" />
  1640.                     <evententry class="srcproc" event="registry" subevent="setvalue" rulesetref="rs-reg-allow" />
  1641.                     <evententry class="srcproc" event="registry" subevent="setkey" rulesetref="rs-reg-allow" />
  1642.                     <evententry class="srcproc" event="registry" subevent="delvalue" rulesetref="rs-reg-allow" />
  1643.                     <evententry class="srcproc" event="registry" subevent="delkey" rulesetref="rs-reg-allow" />
  1644.                     <evententry class="srcproc" event="registry" subevent="createkey" rulesetref="rs-reg-allow" />
  1645.                     <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-allow"/>
  1646.                     <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-allow"/>
  1647.                     <evententry class="srcproc" event="module" subevent="load" rulegroupref="rg-modld-ok" />
  1648.                     <evententry class="srcproc" event="driver" subevent="load" allow="true" />
  1649.                     <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
  1650.                     <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
  1651.                     <evententry class="srcproc" event="physmem" subevent="map" allow="true" />
  1652.  
  1653.                     <evententry class="dstproc" event="process" subevent="openprocess" ask="true" />
  1654.                     <evententry class="dstproc" event="process" subevent="openthread" ask="true" />
  1655.                     <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
  1656.                     <evententry class="dstproc" event="process" subevent="terminateprocess" ask="true" />
  1657.                     <evententry class="dstproc" event="message" subevent="keyboard" ask="true" />
  1658.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1659.                     <evententry class="dstproc" event="message" subevent="dde" ask="true" />
  1660.                     <evententry class="dstproc" event="message" subevent="message"  ask="true" />
  1661.                     <evententry class="dstproc" event="execution" subevent="callback" ask="true" />
  1662.                     <evententry class="dstproc" event="execution" subevent="windowshook" ask="true" />
  1663.  
  1664.                </eventgroup>
  1665.  
  1666.                 <eventgroup name="sys-level1" description="sys-level1" weight="66" allowweightranges="0-69" severityref="dangerous" trustDisplay="super">
  1667.  
  1668.                     <evententry class="srcproc" event="process" subevent="openprocess" rulegroupref="rg-openp-ask" />
  1669.                     <evententry class="srcproc" event="process" subevent="openthread"  rulegroupref="rg-opent-ask" />
  1670.                     <evententry class="srcproc" event="process" subevent="spawnprocess"  rulegroupref="rg-spawn-ask" />
  1671.                     <evententry class="srcproc" event="process" subevent="startupprocess"  allow="true" />
  1672.                     <evententry class="srcproc" event="process" subevent="terminateprocess" rulegroupref="rg-termp-ask" />
  1673.                     <evententry class="srcproc" event="message" subevent="keyboard"  rulegroupref="rg-keybd-ask" />
  1674.                     <evententry class="srcproc" event="message" subevent="mouse"  allow="true" />
  1675.                     <evententry class="srcproc" event="message" subevent="dde"  rulegroupref="rg-ddein-ask" />
  1676.                     <evententry class="srcproc" event="message" subevent="message"  rulegroupref="rg-msg-ask" />
  1677.                     <evententry class="srcproc" event="execution" subevent="callback"  rulegroupref="rg-callb-ask" />
  1678.                     <evententry class="srcproc" event="execution" subevent="windowshook"  rulegroupref="rg-whook-ask" />
  1679.  
  1680.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook"  allow="true" />
  1681.                     <evententry class="srcproc" event="registry" subevent="setvalue" rulesetref="rs-reg-allow" />
  1682.                     <evententry class="srcproc" event="registry" subevent="setkey" rulesetref="rs-reg-allow" />
  1683.                     <evententry class="srcproc" event="registry" subevent="delvalue" rulesetref="rs-reg-allow" />
  1684.                     <evententry class="srcproc" event="registry" subevent="delkey" rulesetref="rs-reg-allow" />
  1685.                     <evententry class="srcproc" event="registry" subevent="createkey" rulesetref="rs-reg-allow" />
  1686.                     <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-allow" />
  1687.                     <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-allow" />
  1688.                     <evententry class="srcproc" event="module" subevent="load" rulegroupref="rg-modld-ok" />
  1689.                     <evententry class="srcproc" event="driver" subevent="load" allow="true" />
  1690.                     <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
  1691.                     <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
  1692.                     <evententry class="srcproc" event="physmem" subevent="map" allow="true" />
  1693.  
  1694.                     <evententry class="dstproc" event="process" subevent="openprocess" ask="true" />
  1695.                     <evententry class="dstproc" event="process" subevent="openthread" ask="true" />
  1696.                     <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
  1697.                     <evententry class="dstproc" event="process" subevent="terminateprocess" ask="true" />
  1698.                     <evententry class="dstproc" event="message" subevent="keyboard" ask="true" />
  1699.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1700.                     <evententry class="dstproc" event="message" subevent="dde" ask="true" />
  1701.                     <evententry class="dstproc" event="message" subevent="message"  ask="true" />
  1702.                     <evententry class="dstproc" event="execution" subevent="callback" ask="true" />
  1703.                     <evententry class="dstproc" event="execution" subevent="windowshook" ask="true" />
  1704.  
  1705.                 </eventgroup>
  1706.  
  1707.                 <!-- like sys-level1 but without access to protected registry keys -->
  1708.                 <eventgroup name="sys-level2" description="sys-level2" weight="66" allowweightranges="0-69" severityref="dangerous" trustDisplay="super">
  1709.  
  1710.                     <evententry class="srcproc" event="process" subevent="openprocess" rulegroupref="rg-openp-ask" />
  1711.                     <evententry class="srcproc" event="process" subevent="openthread"  rulegroupref="rg-opent-ask" />
  1712.                     <evententry class="srcproc" event="process" subevent="spawnprocess"  rulegroupref="rg-spawn-ask" />
  1713.                     <evententry class="srcproc" event="process" subevent="startupprocess"  allow="true" />
  1714.                     <evententry class="srcproc" event="process" subevent="terminateprocess" rulegroupref="rg-termp-ask" />
  1715.                     <evententry class="srcproc" event="message" subevent="keyboard"  rulegroupref="rg-keybd-ask" />
  1716.                     <evententry class="srcproc" event="message" subevent="mouse"  allow="true" />
  1717.                     <evententry class="srcproc" event="message" subevent="dde"  rulegroupref="rg-ddein-ask" />
  1718.                     <evententry class="srcproc" event="message" subevent="message"  rulegroupref="rg-msg-ask" />
  1719.                     <evententry class="srcproc" event="execution" subevent="callback"  rulegroupref="rg-callb-ask" />
  1720.                     <evententry class="srcproc" event="execution" subevent="windowshook"  rulegroupref="rg-whook-ask" />
  1721.  
  1722.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook"  allow="true" />
  1723.                     <evententry class="srcproc" event="registry" subevent="setvalue" rulesetref="rs-rega-block" />
  1724.                     <evententry class="srcproc" event="registry" subevent="setkey" rulesetref="rs-rega-block" />
  1725.                     <evententry class="srcproc" event="registry" subevent="delvalue" rulesetref="rs-regd-block" />
  1726.                     <evententry class="srcproc" event="registry" subevent="delkey" rulesetref="rs-regd-block" />
  1727.                     <evententry class="srcproc" event="registry" subevent="createkey" rulesetref="rs-rega-block" />
  1728.                     <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-allow" />
  1729.                     <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-allow" />
  1730.                     <evententry class="srcproc" event="module" subevent="load" rulegroupref="rg-modld-ok" />
  1731.                     <evententry class="srcproc" event="driver" subevent="load" allow="true" />
  1732.                     <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
  1733.                     <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
  1734.                     <evententry class="srcproc" event="physmem" subevent="map" allow="true" />
  1735.  
  1736.                     <evententry class="dstproc" event="process" subevent="openprocess" ask="true" />
  1737.                     <evententry class="dstproc" event="process" subevent="openthread" ask="true" />
  1738.                     <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
  1739.                     <evententry class="dstproc" event="process" subevent="terminateprocess" ask="true" />
  1740.                     <evententry class="dstproc" event="message" subevent="keyboard" ask="true" />
  1741.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1742.                     <evententry class="dstproc" event="message" subevent="dde" ask="true" />
  1743.                     <evententry class="dstproc" event="message" subevent="message"  ask="true" />
  1744.                     <evententry class="dstproc" event="execution" subevent="callback" ask="true" />
  1745.                     <evententry class="dstproc" event="execution" subevent="windowshook" ask="true" />
  1746.  
  1747.                 </eventgroup>
  1748.  
  1749.                 <eventgroup name="sys-level3" description="sys-level3" weight="66" allowweightranges="0-69" severityref="dangerous" trustDisplay="super">
  1750.  
  1751.                     <evententry class="srcproc" event="process" subevent="openprocess"  weight="E1" allow="true" />
  1752.                     <evententry class="srcproc" event="process" subevent="openthread"  weight="E1" allow="true" />
  1753.                     <evententry class="srcproc" event="process" subevent="spawnprocess"  weight="E1" allow="true" />
  1754.                     <evententry class="srcproc" event="process" subevent="startupprocess"   weight="E1" allow="true" />
  1755.                     <evententry class="srcproc" event="process" subevent="terminateprocess"  weight="E1" allow="true" />
  1756.                     <evententry class="srcproc" event="message" subevent="keyboard"  weight="E1" allow="true" />
  1757.                     <evententry class="srcproc" event="message" subevent="mouse"  weight="E1" allow="true" />
  1758.                     <evententry class="srcproc" event="message" subevent="dde"  weight="E1" allow="true" />
  1759.                     <evententry class="srcproc" event="message" subevent="message"  weight="E1" allow="true" />
  1760.                     <evententry class="srcproc" event="execution" subevent="callback"  weight="E1" allow="true" />
  1761.                     <evententry class="srcproc" event="execution" subevent="windowshook"  weight="E1" allow="true" />
  1762.  
  1763.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook"  allow="true" />
  1764.                     <evententry class="srcproc" event="registry" subevent="setvalue" rulesetref="rs-reg-allow" />
  1765.                     <evententry class="srcproc" event="registry" subevent="setkey" rulesetref="rs-reg-allow" />
  1766.                     <evententry class="srcproc" event="registry" subevent="delvalue" rulesetref="rs-reg-allow" />
  1767.                     <evententry class="srcproc" event="registry" subevent="delkey" rulesetref="rs-reg-allow" />
  1768.                     <evententry class="srcproc" event="registry" subevent="createkey" rulesetref="rs-reg-allow" />
  1769.                     <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-allow" />
  1770.                     <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-allow" />
  1771.                     <evententry class="srcproc" event="module" subevent="load" rulegroupref="rg-modld-ok" />
  1772.                     <evententry class="srcproc" event="driver" subevent="load" allow="true" />
  1773.                     <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
  1774.                     <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
  1775.                     <evententry class="srcproc" event="physmem" subevent="map" allow="true" />
  1776.  
  1777.                     <evententry class="dstproc" event="process" subevent="openprocess" ask="true" />
  1778.                     <evententry class="dstproc" event="process" subevent="openthread" ask="true" />
  1779.                     <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
  1780.                     <evententry class="dstproc" event="process" subevent="terminateprocess" ask="true" />
  1781.                     <evententry class="dstproc" event="message" subevent="keyboard" ask="true" />
  1782.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1783.                     <evententry class="dstproc" event="message" subevent="dde" ask="true" />
  1784.                     <evententry class="dstproc" event="message" subevent="message"  ask="true" />
  1785.                     <evententry class="dstproc" event="execution" subevent="callback" ask="true" />
  1786.                     <evententry class="dstproc" event="execution" subevent="windowshook" ask="true" />
  1787.  
  1788.                 </eventgroup>
  1789.  
  1790.                 <eventgroup name="kill" description="Kill" weight="75" severityref="malicious" trustChoice="kill" trustDisplay="kill">
  1791.                     <evententry class="srcproc" event="process" subevent="openprocess" rulegroupref="rg-openp-blk" />
  1792.                     <evententry class="srcproc" event="process" subevent="openthread" rulegroupref="rg-opent-blk" />
  1793.                     <evententry class="srcproc" event="process" subevent="spawnprocess" rulegroupref="rg-spawn-blk" />
  1794.                     <evententry class="srcproc" event="process" subevent="startupprocess" rulegroupref="rg-start-blk" />
  1795.                     <evententry class="srcproc" event="process" subevent="terminateprocess" rulegroupref="rg-termp-blk" />
  1796.                     <evententry class="srcproc" event="message" subevent="keyboard" rulegroupref="rg-keybd-blk" />
  1797.                     <evententry class="srcproc" event="message" subevent="mouse" rulegroupref="rg-mouse-blk" />
  1798.                     <evententry class="srcproc" event="message" subevent="dde" rulegroupref="rg-ddein-blk" />
  1799.                     <evententry class="srcproc" event="message" subevent="message"  rulegroupref="rg-msg-blk" />
  1800.                     <evententry class="srcproc" event="execution" subevent="callback" rulegroupref="rg-callb-blk" />
  1801.                     <evententry class="srcproc" event="execution" subevent="windowshook" rulegroupref="rg-whook-blk" />
  1802.  
  1803.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook"  rulegroupref="rg-glbhook-blk" />
  1804.                     <evententry class="srcproc" event="registry" subevent="setkey" allow="false" />
  1805.                     <evententry class="srcproc" event="registry" subevent="setvalue" allow="false" />
  1806.                     <evententry class="srcproc" event="registry" subevent="delkey" allow="false" />
  1807.                     <evententry class="srcproc" event="registry" subevent="delvalue" allow="false" />
  1808.                     <evententry class="srcproc" event="registry" subevent="createkey" allow="false" />
  1809.                     <evententry class="srcproc" event="file" subevent="write" allow="false" />
  1810.                     <evententry class="srcproc" event="file" subevent="delete" allow="false" />
  1811.                     <evententry class="srcproc" event="module" subevent="load" allow="false" />
  1812.                     <evententry class="srcproc" event="driver" subevent="load" rulegroupref="rg-drvld-blk" />
  1813.                     <evententry class="srcproc" event="driver" subevent="unload" rulegroupref="rg-drvud-blk" />
  1814.                     <evententry class="srcproc" event="driver" subevent="connect" rulegroupref="rg-drvct-blk" />
  1815.                     <evententry class="srcproc" event="physmem" subevent="map" rulegroupref="rg-memmp-blk" />
  1816.  
  1817.                     <evententry class="dstproc" event="process" subevent="openprocess" allow="true" />
  1818.                     <evententry class="dstproc" event="process" subevent="openthread" allow="true" />
  1819.                     <evententry class="dstproc" event="process" subevent="startupprocess" allow="false" />
  1820.                     <evententry class="dstproc" event="process" subevent="terminateprocess" allow="true" />
  1821.                     <evententry class="dstproc" event="message" subevent="keyboard" allow="true" />
  1822.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1823.                     <evententry class="dstproc" event="message" subevent="dde" allow="true" />
  1824.                     <evententry class="dstproc" event="message" subevent="message"  allow="true" />
  1825.                     <evententry class="dstproc" event="execution" subevent="callback" allow="true" />
  1826.                     <evententry class="dstproc" event="execution" subevent="windowshook" allow="true" />
  1827.                 </eventgroup>
  1828.  
  1829.                 <eventgroup name="untrust-unprot" description="untrust-unprot" weight="20" trustDisplay="restricted">
  1830.  
  1831.                     <evententry class="srcproc" event="process" subevent="openprocess" rulegroupref="rg-openp-blk" />
  1832.                     <evententry class="srcproc" event="process" subevent="openthread" rulegroupref="rg-opent-blk" />
  1833.                     <evententry class="srcproc" event="process" subevent="spawnprocess" rulegroupref="rg-spawn-blk" />
  1834.                     <evententry class="srcproc" event="process" subevent="startupprocess" rulegroupref="rg-start-blk" />
  1835.                     <evententry class="srcproc" event="process" subevent="terminateprocess" rulegroupref="rg-termp-blk" />
  1836.                     <evententry class="srcproc" event="message" subevent="keyboard" rulegroupref="rg-keybd-blk" />
  1837.                     <evententry class="srcproc" event="message" subevent="mouse" rulegroupref="rg-mouse-blk" />
  1838.                     <evententry class="srcproc" event="message" subevent="dde" rulegroupref="rg-ddein-blk" />
  1839.                     <evententry class="srcproc" event="message" subevent="message"  rulegroupref="rg-msg-blk" />
  1840.                     <evententry class="srcproc" event="execution" subevent="callback" rulegroupref="rg-callb-blk" />
  1841.                     <evententry class="srcproc" event="execution" subevent="windowshook" rulegroupref="rg-whook-blk" />
  1842.  
  1843.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook"  rulegroupref="rg-glbhook-blk" />
  1844.                     <evententry class="srcproc" event="registry" subevent="setkey" rulesetref="rs-rega-block"/>
  1845.                     <evententry class="srcproc" event="registry" subevent="setvalue" rulesetref="rs-rega-block"/>
  1846.                     <evententry class="srcproc" event="registry" subevent="delkey" rulesetref="rs-regd-block"/>
  1847.                     <evententry class="srcproc" event="registry" subevent="delvalue" rulesetref="rs-regd-block"/>
  1848.                     <evententry class="srcproc" event="registry" subevent="createkey" rulesetref="rs-rega-block"/>
  1849.                     <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-block"/>
  1850.                     <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-block"/>
  1851.                     <evententry class="srcproc" event="module" subevent="load" allow="true" />
  1852.                     <evententry class="srcproc" event="driver" subevent="load" rulegroupref="rg-drvld-blk" />
  1853.                     <evententry class="srcproc" event="driver" subevent="unload" rulegroupref="rg-drvud-blk" />
  1854.                     <evententry class="srcproc" event="driver" subevent="connect" rulegroupref="rg-drvct-blk" />
  1855.                     <evententry class="srcproc" event="physmem" subevent="map" rulegroupref="rg-memmp-blk" />
  1856.  
  1857.                     <evententry class="dstproc" event="process" subevent="openprocess" allow="true" />
  1858.                     <evententry class="dstproc" event="process" subevent="openthread" allow="true" />
  1859.                     <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
  1860.                     <evententry class="dstproc" event="process" subevent="terminateprocess" allow="true" />
  1861.                     <evententry class="dstproc" event="message" subevent="keyboard" allow="true" />
  1862.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1863.                     <evententry class="dstproc" event="message" subevent="dde" allow="true" />
  1864.                     <evententry class="dstproc" event="message" subevent="message"  ask="true" />
  1865.                     <evententry class="dstproc" event="execution" subevent="callback" allow="true" />
  1866.                     <evententry class="dstproc" event="execution" subevent="windowshook" allow="true" />
  1867.  
  1868.                 </eventgroup>
  1869.  
  1870.                 <eventgroup name="trust-unprot" description="trust-unprot" weight="65" allowweightranges="0-69" trustDisplay="super">
  1871.  
  1872.                     <evententry class="srcproc" event="process" subevent="openprocess" rulegroupref="rg-openp-ask" />
  1873.                     <evententry class="srcproc" event="process" subevent="openthread"  rulegroupref="rg-opent-ask" />
  1874.                     <evententry class="srcproc" event="process" subevent="spawnprocess"  rulegroupref="rg-spawn-ask" />
  1875.                     <evententry class="srcproc" event="process" subevent="startupprocess"  allow="true" />
  1876.                     <evententry class="srcproc" event="process" subevent="terminateprocess" rulegroupref="rg-termp-ask" />
  1877.                     <evententry class="srcproc" event="message" subevent="keyboard"  rulegroupref="rg-keybd-ask" />
  1878.                     <evententry class="srcproc" event="message" subevent="mouse" weight="66" allow="true" />
  1879.                     <evententry class="srcproc" event="message" subevent="dde"  rulegroupref="rg-ddein-ask" />
  1880.                     <evententry class="srcproc" event="message" subevent="message"  rulegroupref="rg-msg-ask" />
  1881.                     <evententry class="srcproc" event="execution" subevent="callback"  rulegroupref="rg-callb-ask" />
  1882.                     <evententry class="srcproc" event="execution" subevent="windowshook"  rulegroupref="rg-whook-ask" />
  1883.  
  1884.                     <evententry class="srcproc" event="execution" subevent="globalwindowshook"  allow="true" />
  1885.                     <evententry class="srcproc" event="registry" subevent="setvalue" rulesetref="rs-reg-allow" />
  1886.                     <evententry class="srcproc" event="registry" subevent="setkey" rulesetref="rs-reg-allow" />
  1887.                     <evententry class="srcproc" event="registry" subevent="delvalue" rulesetref="rs-reg-allow" />
  1888.                     <evententry class="srcproc" event="registry" subevent="delkey" rulesetref="rs-reg-allow" />
  1889.                     <evententry class="srcproc" event="registry" subevent="createkey" rulesetref="rs-reg-allow" />
  1890.                     <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-allow"/>
  1891.                     <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-allow"/>
  1892.                     <evententry class="srcproc" event="module" subevent="load" rulegroupref="rg-modld-ok" />
  1893.                     <evententry class="srcproc" event="driver" subevent="load" allow="true" />
  1894.                     <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
  1895.                     <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
  1896.                     <evententry class="srcproc" event="physmem" subevent="map" allow="true" />
  1897.  
  1898.                     <evententry class="dstproc" event="process" subevent="openprocess" allow="true" />
  1899.                     <evententry class="dstproc" event="process" subevent="openthread" allow="true" />
  1900.                     <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
  1901.                     <evententry class="dstproc" event="process" subevent="terminateprocess" allow="true" />
  1902.                     <evententry class="dstproc" event="message" subevent="keyboard" allow="true" />
  1903.                     <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
  1904.                     <evententry class="dstproc" event="message" subevent="dde" allow="true" />
  1905.                     <evententry class="dstproc" event="message" subevent="message"  allow="true" />
  1906.                     <evententry class="dstproc" event="execution" subevent="callback" allow="true" />
  1907.                     <evententry class="dstproc" event="execution" subevent="windowshook" allow="true" />
  1908.  
  1909.                 </eventgroup>
  1910.  
  1911.             </osfirewall>
  1912.         </applications>
  1913.     </ruleset>
  1914. </ZoneLabsSettings>
  1915.  
  1916.