<ruleentry event=“registry” match=“all” allow=“false” notify=“true” customtext=“4010”>
<itementry param=“key” operator=“equalnocase” type=“ansi” value=“HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotify” />
</ruleentry>
</rulLDBX
egroup>
<rulegroup name=“block-shellex”>
<ruleentry event=“registry” match=“any” allow=“false” notify=“true” customtext=“4009”>
<!— Executable behavior —>
<itementry param=“key” operator=“equalnocase” type=“ansi” value=“HKLMSOFTWAREClassesexefile shellopencommand” />
<itementry param=“key” operator=“equalnocase” type=“ansi” value=“HKLMSOFTWAREClassesexefile shell unascLDBX ommand” />
<itementry param=“key” operator=“equalnocase” type=“ansi” value=“HKCUSOFTWAREClassesexefile shellopencommand” />
<itementry param=“key” operator=“equalnocase” type=“ansi” value=“HKCUSOFTWAREClassesexefile shell unascommand” />
</ruleentry>
</rulegroup>
<rulegroup name=“block-appinit”>
<ruleentry event=“registry” match=“all” allow=“false” notify=“LDBX !true” customtext=“4013”>
<itementry param=“key” operator=“equalnocase” type=“ansi” value=“HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWindows” />
<itementry param=“value” operator=“equalnocase” type=“ansi” value=“AppInit_DLLs” />
</ruleentry>
</rulegroup>
<ruleset name=“rs-rega-block” allow=“true”>
<rulerefentry rulegroupref=“block-run1”/>
LDBX!” <rulerefentry rulegroupref=“block-run2”/>
<rulerefentry rulegroupref=“block-run3”/>
<rulerefentry rulegroupref=“block-run4”/>
<rulerefentry rulegroupref=“block-run5”/>
<rulerefentry rulegroupref=“block-run6”/>
<rulerefentry rulegroupref=“block-shellex”/>
<rulerefentry rulegroupref=“block-appinit”/>
<rulerefentry rulegroupref=“blk-ie-search1”/>
LDBX”# <rulerefentry rulegroupref=“blk-ie-search2”/>
<rulerefentry rulegroupref=“blk-ie-search3”/>
<rulerefentry rulegroupref=“blk-ie-search4”/>
<rulerefentry rulegroupref=“blk-ie-search5”/>
<rulerefentry rulegroupref=“blk-ie-search6”/>
<rulerefentry rulegroupref=“blk-ie-search7”/>
<rulerefentry rulegroupref=“blk-ie-search8”/>
<rulerefLDBX#$entry rulegroupref=“blk-ie-search9”/>
<rulerefentry rulegroupref=“blk-ie-search10”/>
<rulerefentry rulegroupref=“blk-ie-srchdef” />
<rulerefentry rulegroupref=“blk-ie-home1”/>
<rulerefentry rulegroupref=“blk-ie-home2”/>
<rulerefentry rulegroupref=“blk-ie-lcpage1”/>
<rulerefentry rulegroupref=“blk-ie-lcpage2”/>
<rulerefentry rulegroupref=“blk-ie-stLDBX$%pgdef”/>
<rulerefentry rulegroupref=“protourreg”/>
<rulerefentry rulegroupref=“protourreg1”/>
<rulerefentry rulegroupref=“protourreg2”/>