Description ";Prevent registry editor and Task Manager from being disabled"
阻止注册表编辑器和进程管理器被以下程序关闭
监视所有程序
排除进程:rtvscan.exe cfgwiz.exe navw32.exe nmain.exe fssm32.exe avtask.exe kavsvc.exe giantantispywar* mmc.exe
注册表值(创建,写入,删除):
HKULM/Software/Microsoft/Windows/CurrentVersion/Policies/System:DisableRegistryTools
HKULM/Software/Microsoft/Windows/CurrentVersion/Policies/System:DisableTaskMgr
Description ";Prevent user rights policies from being altered"
保护用户权限策略
监视所有进程
排除进程:rtvscan.exe,cfgwiz.exe,navw32.exe,nmain.exe,fssm32.exe,avtask.exe,kavsvc.exe,giantantispywar*,msiexec.exe,msi*.tmp,setup.exe,ikernel.exe,*setup*.exe,_ins*._mp,amgrsrvc.exe,mmc.exe
注册表项(创建,写入,删除):
HKCCS/Control/LSA/**
HKCCS/Services/lanmanserver/parameters/**
Description ";Prevent remote creation/modification of executable and configuration files"
防止远程建立/修改可执行程序和配置文件
监视所有远程程序
对象文件(创建,写入,删除):**.exe **.scr **.ocx **.dll **.pif
文件路径:windows目录以及所有子目录下文件,%systemdrive%\*.ini
排除进程:所有framepkg.exe文件
Description "Prevent Windows Process spoofing"
防止windows进程欺骗
文件路径(创建,读取,执行,写入):所有svchost.exe,explorer.exe,ctfmon.exe,lsass.exe,csrss.exe,winlogon.exe,services.exe,smss.exe
排除文件:windows目录及其所有子目录下的svchost.exe,explorer.exe,ctfmon.exe,lsass.exe,csrss.exe,winlogon.exe,services.exe,smss.exe
Description "Protect phonebook files from password and email address stealers"
保护通讯簿的密码和电子邮件地址
监视所有进程
排除进程:rasphone.exe explorer.exe svchost.exe
文件路径(读取,删除,创建,写入):**/rasphone.pbk
Description "Prevent mass mailing worms from sending mail"
防止邮件蠕虫发送邮件
监视所有进程
排除进程:默认邮件客户端,默认浏览器,eudora.exe,msimn.exe,msn6.exe,msnmsgr.exe,neo20.exe,nlnotes.exe,outlook.exe,pine.exe,poco.exe,thebat.exe,thunderbird.exe,winpm-32.exe,explorer.exe,iexplore.exe,firefox.exe,mozilla.exe,netscp.exe,opera.exe,msn6.exe,tomcat.exe,tomcat5.exe,tomcat5w.exe,inetinfo.exe,amgrsrvc.exe,apache.exe,webproxy.exe,msexcimc.exe,ntaskldr.exe,nsmtp.exe,nrouter.exe,agent.exe,ebs.exe,firesvc.exe,modulewrapper*,msksrvr.exe,mskdetct.exe,mailscan.exe,rpcserv.exe
端口(向外):25,587
Description "Prevent creation of new executable files in the Windows folder"
防止在windows目录建立可执行文件
监视所有进程
排除进程:msiexec.exe,msi*.tmp,setup.exe,ikernel.exe,*setup*.exe,_ins*._mp,wuauclt.exe,update.exe,spuninst.exe,javatrig.exe,vbs56nen.exe,js56nen.exe,ieupdate.exe,dahotfix.exe,ie-kb*.exe,kb*.exe,fixccs.exe,sqlredis.exe,mdac_qfe.exe,dasetup.exe,setupre.exe,wintdist.exe,lucoms*,luupdate.exe,lsetup.exe,idsinst.exe,lucoms*,sevinst.exe,nv11esd.exe,tsc.exe,v3cfgu.exe,ofcservice.exe,earthagent.exe,tmlisten.exe,inodist.exe,ilaunchr.exe,ii_nt86.exe,iv_nt86.exe,cfgeng.exe,f-secu*,fspex.exe,getdbhtp.exe,fnrb32.exe,f-secure automa*,sucer.exe,ahnun000.tmp,supdate.exe,autoup.exe,pskmssvc.exe,pavagent.exe,dstest.exe,paddsupd.exe,pavsrv50.exe,avtask.exe,giantantispywar*,boxinfo.exe,rtvscan.exe,cfgwiz.exe,navw32.exe,nmain.exe,fssm32.exe,avtask.exe,kavsvc.exe,giantantispywar*,winlogon.exe,mrtstub.exe,mcscript*,frameworks*,naprdmgr.exe,frminst.exe,naimserv.exe,framepkg.exe,narepl32.exe,updaterui.exe,cmdagent.exe,cleanup.exe,fssm32.exe,tomcat.exe
文件路径(创建):windows目录下以exe和dll为后缀的文件
排除文件(创建):windows目录中downloaded program files目录及其子目录下任何文件,windows目录中SoftwareDistribution目录下Download和WebSetup文件夹中及其所有子文件夹中的任何文件。system32文件下muweb.dll,wuweb.dll,cdm.dll,iuengine.dll,wuapi.dll,wuauclt.exe,wuauclt1.exe,wuaclt.exe,wuaclt1.exe,wuaueng.dll,wuaueng1.dll,wucltui.dll,wups.dll,wups2.dll,FireNotify.dll,FireCNL.dll,FireCore.dll,FireCL.dll,FireEpo.dll,FireNHC.dll,FireSCV.dll。windows目录下temp文件夹中的ZDATAI51.DLL以及_WUTL951.DLL文件。
Description "Prevent launching of files from the Downloaded Programs folder"
防止从downloaded programs folder文件夹下启动任何项目
监视进程:iexplore.exe
文件路径(执行):downloaded program files文件夹下任何以exe为后缀的文件