home *** CD-ROM | disk | FTP | other *** search
- <osfirewall>
-
- <rulegroup name="protourfiles">
- <ruleentry event="file" match="any" allow="false" notify="true" customtext="2002">
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINDIR\Internet Logs\BACKUP.RDB" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINDIR\Internet Logs\IAMDB.RDB" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINDIR\Internet Logs\ZALog.txt" />
-
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\avsys\ScanningProcess.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\avsys\Monitor.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\avsys\klif.sys" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\avsys\kave.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\avsys\FSSync.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\avsys\prloader.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\avsys\inv.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\avsys\appinfo.kli" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\avsys\00140FFE.key" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\avsys\000F529D.key" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\av.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\boot.dat" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\cafix.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\camupd.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\cerbprovider.pvx" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\dbghelp.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\imsecure.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\lib" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\osfwrules.xml" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\plugins" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\qrbase.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\qrsrecl.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\oemconfig.xml" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\safePrograms.xml" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\scheduler.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\spyware.dat" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\srescan.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\ssleay32.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\streamapi" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsavpro.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsdb.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsinit.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsmon.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsruledb.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsvault.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\ZLCommDB.xml" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlparser.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlquarantine.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlsre.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlasdbup.dat" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlsrepluginsupd.zip" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlsreupd.zip" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlqrtdb.dat" />
-
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vswmi.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\fbl.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\featuremap.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\streamapi.config.xml" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsmon.config.xml" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\updating.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\updclient.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\vsmondll.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\zlupdate.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\ZoneAlarm.xml" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\lib\zlsvc.zip.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\lib\zpy.zip.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\lib\pyd\_socket.pyd" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\lib\pyd\pyexpat.pyd" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\lib\pyd\pyvsinit.pyd" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\lib\pyd\signedDll.pyd" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\plugins\rpc_server\manifest.xml" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\plugins\rpc_server\rpc_server.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\plugins\vsmon_plugin\manifest.xml" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\plugins\vsmon_plugin\vsmon_plugin.dll" />
-
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\streamapi\httpblocker\httpblocker.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\streamapi\httpblocker\manifest.xml" />
-
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\streamapi\imslsp\imslsp.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\streamapi\imslsp\manifest.xml" />
-
- <itementry param="filename" operator="equalnocase" type="ansi" value="VSDATANTDIR\vsconfig.xml" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsdata.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="VSDATANTDIR\vsdatant.sys" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsinit.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsmonapi.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vspubapi.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsregexp.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsutil.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\vsxml.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\zlcomm.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\zlcommdb.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\zpeng24.dll" />
-
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\alert.zap" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\email.zap" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\expert.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\filter.zap" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\firewall.zap" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\framewrk.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\idlock.zap" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\imf_editor.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\imsecure.zap" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\multiscan.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\privacy.zap" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\programs.zap" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\scan.zap" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\scan.zmx" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\security.zap" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\vsinit.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\zatutor.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\zauninst.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\zlavscan.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\zonealarm.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\zlclient.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\repair\vsdb.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\repair\vsinit.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\repair\vsmon.exe" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\repair\vsruledb.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="ZLDIR\repair\vsutil.dll" />
- <itementry param="filename" operator="equalnocase" type="ansi" value="WINSYSDIR\Zonelabs\srescan.sys" />
- </ruleentry>
- </rulegroup>
- <rulegroup name="protourreg">
- <ruleentry event="registry" match="any" allow="false" notify="true" customtext="2003">
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\MiniLog" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\TrueVector" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\TrueVector\LocalStoreDir" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\TrueVector\LogStoreDir" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.ADE" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.ADP" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.ASX" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.BAS" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.BAT" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.CHM" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.CMD" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.COM" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.CPL" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.CRT" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.DBX" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.DLL" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.EML" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.EXE" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.HLP" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.HTA" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.INF" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.INS" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.ISP" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.JS" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.JSE" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.LNK" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MDA" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MDB" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MDE" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MDZ" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MHT" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MSC" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MSI" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MSP" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.MST" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.NCH" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.OCX" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.PCD" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.PIF" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.PRF" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.RAR" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.REG" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.SCF" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.SCR" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.SCT" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.SHB" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.SHS" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.SYS" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.URL" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.VB" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.VBE" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.VBS" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.WMS" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.WSC" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.WSF" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.WSH" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\MailSafe Extensions\.ZIP" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm\Registration" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsdatant" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsdatant\enum" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsdatant\parameters" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsdatant\security" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsmon" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsmon\enum" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\Vsmon\security" />
- <itementry param="key" operator="equalnocase" type="ansi" value="HKCS\Services\srescan" />
- </ruleentry>
- </rulegroup>
-
- <rulegroup name="protourreg1">
- <ruleentry event="registry" match="all" allow="false" notify="true" customtext="2003">
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm" />
- <itementry param="value" operator="equalnocase" type="ansi" value="InstallDirectory" />
- </ruleentry>
- </rulegroup>
-
- <rulegroup name="protourreg2">
- <ruleentry event="registry" match="all" allow="false" notify="true" customtext="2003">
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm" />
- <itementry param="value" operator="equalnocase" type="ansi" value="IntegrityMode" />
- </ruleentry>
- </rulegroup>
-
- <rulegroup name="protourreg3">
- <ruleentry event="registry" match="all" allow="false" notify="true" customtext="2003">
- <itementry param="key" operator="equalnocase" type="ansi" value="HKLM\SOFTWARE\Zone Labs\ZoneAlarm" />
- <itementry param="value" operator="equalnocase" type="ansi" value="AltDir" />
- </ruleentry>
- </rulegroup>
-
- <imageentry
- imagename="ScanningProcess.exe"
- eventgroupref="ZLServiceGroup">
- <itementry
- param="md5"
- operator="equal"
- type="binary"
- value="81cdf1aa-b2ed1d5d-dafef8d1-f1368782"
- />
- </imageentry>
- <imageentry
- imagename="Monitor.exe"
- eventgroupref="ZLServiceGroup">
- <itementry
- param="md5"
- operator="equal"
- type="binary"
- value="23846d4e-bf6d6665-ffb19aa6-c61ea830"
- />
- </imageentry>
-
-
- <ruleset name="rs-reg-block" allow="true">
- <rulerefentry rulegroupref="protourreg"/>
- </ruleset>
-
- <ruleset name="rs-file-block" allow="true">
- <rulerefentry rulegroupref="protourfiles"/>
- </ruleset>
-
-
- <eventgroup name="ZLDefaultGroup" description="ZLDefaultGroup" weight="00" allowweightranges="FE-FE" default="true" severityref="suspicious">
- <evententry class="srcproc" event="process" subevent="openprocess" ask="true" />
- <evententry class="srcproc" event="process" subevent="openthread" allow="true" />
- <evententry class="srcproc" event="process" subevent="spawnprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="startupprocess" ask="true" />
- <evententry class="srcproc" event="process" subevent="terminateprocess" ask="true" />
- <evententry class="srcproc" event="process" subevent="oleconnect" ask="true" />
- <evententry class="srcproc" event="message" subevent="keyboard" ask="true" />
- <evententry class="srcproc" event="message" subevent="mouse" ask="true" />
- <evententry class="srcproc" event="message" subevent="dde" ask="true" />
- <evententry class="srcproc" event="message" subevent="message" allow="true" />
- <evententry class="srcproc" event="execution" subevent="callback" allow="true" />
- <evententry class="srcproc" event="execution" subevent="windowshook" allow="true" />
- <evententry class="srcproc" event="execution" subevent="globalwindowshook" allow="true" />
-
- <evententry class="srcproc" event="registry" subevent="setkey" rulesetref="rs-reg-block"/>
- <evententry class="srcproc" event="registry" subevent="setvalue" rulesetref="rs-reg-block"/>
- <evententry class="srcproc" event="registry" subevent="delkey" rulesetref="rs-reg-block"/>
- <evententry class="srcproc" event="registry" subevent="delvalue" rulesetref="rs-reg-block"/>
- <evententry class="srcproc" event="registry" subevent="createkey" rulesetref="rs-reg-block"/>
-
- <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-file-block"/>
- <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-file-block"/>
-
- <evententry class="srcproc" event="module" subevent="load" notify="true" />
- <evententry class="srcproc" event="driver" subevent="load" allow="true" />
- <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
- <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
- <evententry class="srcproc" event="driver" subevent="create" allow="true" />
- <evententry class="srcproc" event="driver" subevent="modify" allow="true" />
- <evententry class="srcproc" event="driver" subevent="delete" allow="true" />
- <evententry class="srcproc" event="physmem" subevent="map" allow="true" />
- <evententry class="dstproc" event="process" subevent="openprocess" allow="true" />
- <evententry class="dstproc" event="process" subevent="openthread" allow="true" />
- <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
- <evententry class="dstproc" event="process" subevent="terminateprocess" allow="true" />
- <evententry class="dstproc" event="process" subevent="oleconnect" allow="true" />
- <evententry class="dstproc" event="message" subevent="keyboard" allow="true" />
- <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
- <evententry class="dstproc" event="message" subevent="dde" allow="true" />
- <evententry class="dstproc" event="message" subevent="message" allow="true" />
- <evententry class="dstproc" event="execution" subevent="callback" allow="true" />
- <evententry class="dstproc" event="execution" subevent="windowshook" allow="true" />
- </eventgroup>
-
- <eventgroup name="ZLDebug" description="ZLDebugGroup" weight="FE" allowweightranges="0-FE" severityref="dangerous">
- <evententry class="srcproc" event="process" subevent="openprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="openthread" allow="true" />
- <evententry class="srcproc" event="process" subevent="spawnprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="startupprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="terminateprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="oleconnect" allow="true" />
- <evententry class="srcproc" event="message" subevent="keyboard" allow="true" />
- <evententry class="srcproc" event="message" subevent="mouse" allow="true" />
- <evententry class="srcproc" event="message" subevent="dde" allow="true" />
- <evententry class="srcproc" event="message" subevent="message" allow="true" />
- <evententry class="srcproc" event="execution" subevent="callback" allow="true" />
- <evententry class="srcproc" event="execution" subevent="windowshook" allow="true" />
- <evententry class="srcproc" event="execution" subevent="globalwindowshook" allow="true" />
- <evententry class="srcproc" event="registry" subevent="setkey" allow="true" />
- <evententry class="srcproc" event="registry" subevent="setvalue" allow="true" />
- <evententry class="srcproc" event="registry" subevent="delkey" allow="true" />
- <evententry class="srcproc" event="registry" subevent="delvalue" allow="true" />
- <evententry class="srcproc" event="registry" subevent="createkey" allow="true" />
- <evententry class="srcproc" event="file" subevent="write" allow="true" />
- <evententry class="srcproc" event="file" subevent="delete" allow="true" />
- <evententry class="srcproc" event="module" subevent="load" allow="true" />
- <evententry class="srcproc" event="driver" subevent="load" allow="true" />
- <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
- <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
- <evententry class="srcproc" event="driver" subevent="create" allow="true" />
- <evententry class="srcproc" event="driver" subevent="modify" allow="true" />
- <evententry class="srcproc" event="driver" subevent="delete" allow="true" />
- <evententry class="srcproc" event="physmem" subevent="map" allow="true" />
- <evententry class="dstproc" event="process" subevent="openprocess" allow="true" />
- <evententry class="dstproc" event="process" subevent="openthread" allow="true" />
- <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
- <evententry class="dstproc" event="process" subevent="terminateprocess" allow="true" />
- <evententry class="dstproc" event="process" subevent="oleconnect" allow="true" />
- <evententry class="dstproc" event="message" subevent="keyboard" allow="true" />
- <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
- <evententry class="dstproc" event="message" subevent="dde" allow="true" />
- <evententry class="dstproc" event="message" subevent="message" allow="true" />
- <evententry class="dstproc" event="execution" subevent="callback" allow="true" />
- <evententry class="dstproc" event="execution" subevent="windowshook" allow="true" />
- </eventgroup>
-
- <eventgroup name="ZLServiceGroup" description="ZLServiceGroup" weight="E0" allowweightranges="0-E0,FE-FE" severityref="dangerous">
- <evententry class="srcproc" event="process" subevent="openprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="openthread" allow="true" />
- <evententry class="srcproc" event="process" subevent="spawnprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="startupprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="terminateprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="oleconnect" allow="true" />
- <evententry class="srcproc" event="message" subevent="keyboard" allow="true" />
- <evententry class="srcproc" event="message" subevent="mouse" allow="true" />
- <evententry class="srcproc" event="message" subevent="dde" allow="true" />
- <evententry class="srcproc" event="message" subevent="message" allow="true" />
- <evententry class="srcproc" event="execution" subevent="callback" allow="true" />
- <evententry class="srcproc" event="execution" subevent="windowshook" allow="true" />
- <evententry class="srcproc" event="execution" subevent="globalwindowshook" allow="true" />
- <evententry class="srcproc" event="registry" subevent="setkey" allow="true" />
- <evententry class="srcproc" event="registry" subevent="setvalue" allow="true" />
- <evententry class="srcproc" event="registry" subevent="delkey" allow="true" />
- <evententry class="srcproc" event="registry" subevent="delvalue" allow="true" />
- <evententry class="srcproc" event="registry" subevent="createkey" allow="true" />
- <evententry class="srcproc" event="file" subevent="write" allow="true" />
- <evententry class="srcproc" event="file" subevent="delete" allow="true" />
- <evententry class="srcproc" event="module" subevent="load" allow="true" />
- <evententry class="srcproc" event="driver" subevent="load" allow="true" />
- <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
- <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
- <evententry class="srcproc" event="driver" subevent="create" allow="true" />
- <evententry class="srcproc" event="driver" subevent="modify" allow="true" />
- <evententry class="srcproc" event="driver" subevent="delete" allow="true" />
- <evententry class="srcproc" event="physmem" subevent="map" allow="true" />
- <evententry class="dstproc" event="process" subevent="openprocess" allow="false" />
- <evententry class="dstproc" event="process" subevent="openthread" allow="false" />
- <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
- <evententry class="dstproc" event="process" subevent="terminateprocess" allow="false" />
- <evententry class="dstproc" event="process" subevent="oleconnect" allow="false" />
- <evententry class="dstproc" event="message" subevent="keyboard" allow="false" />
- <evententry class="dstproc" event="message" subevent="mouse" allow="false" />
- <evententry class="dstproc" event="message" subevent="dde" allow="false" />
- <evententry class="dstproc" event="message" subevent="message" allow="false" />
- <evententry class="dstproc" event="execution" subevent="callback" allow="false" />
- <evententry class="dstproc" event="execution" subevent="windowshook" allow="false" />
- </eventgroup>
-
- <eventgroup name="ZLClientGroup" description="ZLClientGroup" weight="66" allowweightranges="0-66,FE-FE" severityref="dangerous">
- <evententry class="srcproc" event="process" subevent="openprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="openthread" allow="true" />
- <evententry class="srcproc" event="process" subevent="spawnprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="startupprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="terminateprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="oleconnect" allow="true" />
- <evententry class="srcproc" event="message" subevent="keyboard" allow="true" />
- <evententry class="srcproc" event="message" subevent="mouse" allow="true" />
- <evententry class="srcproc" event="message" subevent="dde" allow="true" />
- <evententry class="srcproc" event="message" subevent="message" allow="true" />
- <evententry class="srcproc" event="execution" subevent="callback" allow="true" />
- <evententry class="srcproc" event="execution" subevent="windowshook" allow="true" />
- <evententry class="srcproc" event="execution" subevent="globalwindowshook" allow="true" />
- <evententry class="srcproc" event="registry" subevent="setkey" allow="true" />
- <evententry class="srcproc" event="registry" subevent="setvalue" allow="true" />
- <evententry class="srcproc" event="registry" subevent="delkey" allow="true" />
- <evententry class="srcproc" event="registry" subevent="delvalue" allow="true" />
- <evententry class="srcproc" event="registry" subevent="createkey" allow="true" />
- <evententry class="srcproc" event="file" subevent="write" allow="true" />
- <evententry class="srcproc" event="file" subevent="delete" allow="true" />
- <evententry class="srcproc" event="module" subevent="load" allow="true" />
- <evententry class="srcproc" event="driver" subevent="load" allow="true" />
- <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
- <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
- <evententry class="srcproc" event="driver" subevent="create" allow="true" />
- <evententry class="srcproc" event="driver" subevent="modify" allow="true" />
- <evententry class="srcproc" event="driver" subevent="delete" allow="true" />
- <evententry class="srcproc" event="physmem" subevent="map" allow="true" />
- <evententry class="dstproc" event="process" subevent="openprocess" allow="false" />
- <evententry class="dstproc" event="process" subevent="openthread" allow="false" />
- <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
- <evententry class="dstproc" event="process" subevent="terminateprocess" allow="false" />
- <evententry class="dstproc" event="process" subevent="oleconnect" allow="false" />
- <evententry class="dstproc" event="message" subevent="keyboard" allow="false" />
- <evententry class="dstproc" event="message" subevent="mouse" allow="false" />
- <evententry class="dstproc" event="message" subevent="dde" allow="false" />
- <evententry class="dstproc" event="message" subevent="message" allow="false" />
- <evententry class="dstproc" event="execution" subevent="callback" allow="false" />
- <evententry class="dstproc" event="execution" subevent="windowshook" allow="false" />
- </eventgroup>
- <eventgroup name="ZLSignedApps" description="ZLSignedApps" weight="65" allowweightranges="0-66,FE-FE" severityref="dangerous">
- <evententry class="srcproc" event="process" subevent="openprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="openthread" allow="true" />
- <evententry class="srcproc" event="process" subevent="spawnprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="startupprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="terminateprocess" allow="true" />
- <evententry class="srcproc" event="process" subevent="oleconnect" allow="true" />
- <evententry class="srcproc" event="message" subevent="keyboard" allow="true" />
- <evententry class="srcproc" event="message" subevent="mouse" allow="true" />
- <evententry class="srcproc" event="message" subevent="dde" allow="true" />
- <evententry class="srcproc" event="message" subevent="message" allow="true" />
- <evententry class="srcproc" event="execution" subevent="callback" allow="true" />
- <evententry class="srcproc" event="execution" subevent="windowshook" allow="true" />
- <evententry class="srcproc" event="execution" subevent="globalwindowshook" allow="true" />
- <evententry class="srcproc" event="registry" subevent="setkey" allow="true" />
- <evententry class="srcproc" event="registry" subevent="setvalue" allow="true" />
- <evententry class="srcproc" event="registry" subevent="delkey" allow="true" />
- <evententry class="srcproc" event="registry" subevent="delvalue" allow="true" />
- <evententry class="srcproc" event="registry" subevent="createkey" allow="true" />
- <evententry class="srcproc" event="file" subevent="write" allow="true" />
- <evententry class="srcproc" event="file" subevent="delete" allow="true" />
- <evententry class="srcproc" event="module" subevent="load" allow="true" />
- <evententry class="srcproc" event="driver" subevent="load" allow="true" />
- <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
- <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
- <evententry class="srcproc" event="driver" subevent="create" allow="true" />
- <evententry class="srcproc" event="driver" subevent="modify" allow="true" />
- <evententry class="srcproc" event="driver" subevent="delete" allow="true" />
- <evententry class="srcproc" event="physmem" subevent="map" allow="true" />
- <evententry class="dstproc" event="process" subevent="openprocess" allow="false" />
- <evententry class="dstproc" event="process" subevent="openthread" allow="false" />
- <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
- <evententry class="dstproc" event="process" subevent="terminateprocess" allow="false" />
- <evententry class="dstproc" event="process" subevent="oleconnect" allow="false" />
- <evententry class="dstproc" event="message" subevent="keyboard" allow="false" />
- <evententry class="dstproc" event="message" subevent="mouse" allow="false" />
- <evententry class="dstproc" event="message" subevent="dde" allow="false" />
- <evententry class="dstproc" event="message" subevent="message" allow="false" />
- <evententry class="dstproc" event="execution" subevent="callback" allow="false" />
- <evententry class="dstproc" event="execution" subevent="windowshook" allow="false" />
- </eventgroup>
- <eventgroup name="sys-level3" description="sys-level3" weight="66" allowweightranges="0-69,FE-FE" severityref="dangerous" trustDisplay="super">
-
- <evententry class="srcproc" event="process" subevent="openprocess" weight="E1" allow="true" />
- <evententry class="srcproc" event="process" subevent="openthread" weight="E1" allow="true" />
- <evententry class="srcproc" event="process" subevent="spawnprocess" weight="E1" allow="true" />
- <evententry class="srcproc" event="process" subevent="startupprocess" weight="E1" allow="true" />
- <evententry class="srcproc" event="process" subevent="terminateprocess" weight="E1" allow="true" />
- <evententry class="srcproc" event="process" subevent="oleconnect" weight="E1" allow="true" />
- <evententry class="srcproc" event="message" subevent="keyboard" weight="E1" allow="true" />
- <evententry class="srcproc" event="message" subevent="mouse" weight="E1" allow="true" />
- <evententry class="srcproc" event="message" subevent="dde" weight="E1" allow="true" />
- <evententry class="srcproc" event="message" subevent="message" weight="E1" allow="true" />
- <evententry class="srcproc" event="execution" subevent="callback" weight="E1" allow="true" />
- <evententry class="srcproc" event="execution" subevent="windowshook" weight="E1" allow="true" />
-
- <evententry class="srcproc" event="execution" subevent="globalwindowshook" allow="true" />
- <evententry class="srcproc" event="registry" subevent="setvalue" rulesetref="rs-reg-allow" />
- <evententry class="srcproc" event="registry" subevent="setkey" rulesetref="rs-reg-allow" />
- <evententry class="srcproc" event="registry" subevent="delvalue" rulesetref="rs-reg-allow" />
- <evententry class="srcproc" event="registry" subevent="delkey" rulesetref="rs-reg-allow" />
- <evententry class="srcproc" event="registry" subevent="createkey" rulesetref="rs-reg-allow" />
- <evententry class="srcproc" event="file" subevent="write" rulesetref="rs-files-allow" />
- <evententry class="srcproc" event="file" subevent="delete" rulesetref="rs-files-allow" />
- <evententry class="srcproc" event="module" subevent="load" rulegroupref="rg-modld-ok" />
- <evententry class="srcproc" event="driver" subevent="load" allow="true" />
- <evententry class="srcproc" event="driver" subevent="unload" allow="true" />
- <evententry class="srcproc" event="driver" subevent="connect" allow="true" />
- <evententry class="srcproc" event="driver" subevent="create" allow="true" />
- <evententry class="srcproc" event="driver" subevent="modify" allow="true" />
- <evententry class="srcproc" event="driver" subevent="delete" allow="true" />
- <evententry class="srcproc" event="physmem" subevent="map" allow="true" />
-
- <evententry class="dstproc" event="process" subevent="openprocess" ask="true" />
- <evententry class="dstproc" event="process" subevent="openthread" ask="true" />
- <evententry class="dstproc" event="process" subevent="startupprocess" allow="true" />
- <evententry class="dstproc" event="process" subevent="terminateprocess" ask="true" />
- <evententry class="dstproc" event="process" subevent="oleconnect" ask="true" />
- <evententry class="dstproc" event="message" subevent="keyboard" ask="true" />
- <evententry class="dstproc" event="message" subevent="mouse" allow="true" />
- <evententry class="dstproc" event="message" subevent="dde" ask="true" />
- <evententry class="dstproc" event="message" subevent="message" ask="true" />
- <evententry class="dstproc" event="execution" subevent="callback" ask="true" />
- <evententry class="dstproc" event="execution" subevent="windowshook" ask="true" />
-
- </eventgroup>
-
- <imageentry
- imagename="iclient.exe"
- eventgroupref="ZLClientGroup">
- <itementry
- param="md5"
- operator="equal"
- type="binary"
- value="43fbddce-e66aa62c-af54ecd6-9c64b15d"
- />
- </imageentry>
- <imageentry
- imagename="zlclient.exe"
- eventgroupref="ZLClientGroup">
- <itementry
- param="md5"
- operator="equal"
- type="binary"
- value="3e1731c5-5f77d150-791d4c7e-87ad4e5c"
- />
- </imageentry>
- <imageentry
- imagename="vsmon.exe"
- eventgroupref="ZLServiceGroup">
- <itementry
- param="md5"
- operator="equal"
- type="binary"
- value="de716616-65a86a23-05918e8b-91acedb9"
- />
- </imageentry>
- <imageentry
- imagename="updclient.exe"
- eventgroupref="ZLClientGroup">
- <itementry
- param="md5"
- operator="equal"
- type="binary"
- value="9aa2cea5-c63143fb-dcc93537-1dce00a1"
- />
- </imageentry>
- <imageentry
- imagename="userdump.exe"
- eventgroupref="ZLServiceGroup">
- <itementry
- param="md5"
- operator="equal"
- type="binary"
- value="065b463f-6ed0b195-027ed99c-0c3b3250"
- />
- </imageentry>
- <imageentry
- imagename="csrss.exe"
- eventgroupref="sys-level3">
- <itementry
- param="path"
- operator="equalnocase"
- type="ansi"
- value="WINSYSDIR\csrss.exe"
- />
- </imageentry>
- <imageentry
- imagename="lsass.exe"
- eventgroupref="sys-level3">
- <itementry
- param="path"
- operator="equalnocase"
- type="ansi"
- value="WINSYSDIR\lsass.exe"
- />
- </imageentry>
- <imageentry
- imagename="umdh.exe"
- eventgroupref="ZLDebug">
- <itementry
- param="md5"
- operator="equal"
- type="binary"
- value="f7501800-45b7d5fb-849143b5-c4f4071d"
- />
- </imageentry>
- <imageentry
- imagename="umdh.exe"
- eventgroupref="ZLDebug">
- <itementry
- param="md5"
- operator="equal"
- type="binary"
- value="2D62A217-5AFEC25C-B020CE2D-B63DC25D"
- />
- </imageentry>
- <imageentry
- imagename="umdh.exe"
- eventgroupref="ZLDebug">
- <itementry
- param="md5"
- operator="equal"
- type="binary"
- value="F51A70B3-1EEA2849-97010B6F-F750455D"
- />
- </imageentry>
- <imageentry
- imagename="umdh.exe"
- eventgroupref="ZLDebug">
- <itementry
- param="md5"
- operator="equal"
- type="binary"
- value="94C8F0B5-5BAB646E-DE45AE5C-9C2DDF8D"
- />
- </imageentry>
-
- </osfirewall>
-