home *** CD-ROM | disk | FTP | other *** search
- ;------------- Global ------------
-
- [Global]
-
- ; Alert action IDs
- #PDM_ACTIONID_ROLLBACK =0xe2be0201
-
- ;Event Types
- #PDM_EVENT_P2P_SC_RDL = 1
- #PDM_EVENT_SC_AR = 2
- #PDM_EVENT_SC_ARsrc = 3
- #PDM_EVENT_SCN = 4
- #PDM_EVENT_P2P_SCN = 5
- #PDM_EVENT_SC2STARTUP = 6
- #PDM_EVENT_SC_MULTIPLE = 7
- #PDM_EVENT_RDR = 8
- #PDM_EVENT_REGMODIFY = 9
- #PDM_EVENT_HIDDEN_OBJ = 10
- #PDM_EVENT_INVADER = 11
- #PDM_EVENT_APPG = 12
- #PDM_EVENT_APPG_CHANGED = 13
- #PDM_EVENT_IMG_CHANGED = 14
- #PDM_EVENT_APPG_ASCHILD = 15
- #PDM_EVENT_APPG_BROWSER = 16
- #PDM_EVENT_INVADER_LOADER = 17
- #PDM_EVENT_STRANGEKEY = 18
- #PDM_EVENT_SYSCHANGE = 19
- #PDM_EVENT_HIDDEN_INSTALL = 20
- #PDM_EVENT_BUFFEROVERRUN = 21
- #PDM_EVENT_DEP = 22
-
- ;ReportInfo Events
- #PDM_HISTORY_PROCESSING = 0xE2BE0511
- #PDM_ROLLBACK_ACTION = 0xE2BE0512
- #PDM_ROLLBACK_RESULT = 0xE2BE0513
- #PDM_CREATE_HISTORY_FOLDER= 0xE2BE0514
- #PDM_TERMINATE_PROCESS = 0xE2BE0515
- #PDM_ALLOW_PROCESS_ACTION = 0xE2BE0516
- #PDM_DENY_PROCESS_ACTION = 0xE2BE0517
- #PDM_DETECT = 0xE2BE0518
- #PDM_QUARANTINE_RESULT = 0xE2BE0519
- #PDM_TERMINATING_PROCESS = 0xE2BE051A
-
- ;ReportInfo Status
- #PDM_STATUS_OK = 0xe2be0501
- #PDM_STATUS_WARNING = 0xe2be0502
- #PDM_STATUS_CRITICAL = 0xe2be0503
-
- ;PDMModifyAction
- #rga_allow =0
- #rga_ask =1
- #rga_block =2
- #rga_terminate =3
- #rga_alert =4
-
- ;enSettingsType
- #PDM_SET_SUSPICION =1
- #PDM_SET_BROWSER =2
- #PDM_SET_INVADER =3
- #PDM_SET_HIDDENCHECK =4
- #PDM_SET_SETWNDHOOK =5
- #PDM_SET_REGSTRANGE =6
- #PDM_SET_SYSCHANGE =7
-
- ;_etREgRequestType
- #eRegRequest_Modify = 0
- #eRegRequest_Read = 1
- #eRegRequest_Delete = 2
-
- #REG_NONE = 0 ;No value type
- #REG_SZ = 1 ;Unicode nul terminated string
- #REG_EXPAND_SZ = 2 ;Unicode nul terminated string (with environment variable references)
- #REG_BINARY = 3 ;Free form binary
- #REG_DWORD = 4 ;32-bit number
- #REG_DWORD_BIG_ENDIAN = 5 ;32-bit number
- #REG_LINK = 6 ;Symbolic Link (unicode)
- #REG_MULTI_SZ = 7 ;Multiple Unicode strings
- #REG_RESOURCE_LIST = 8 ;Resource list in the resource map
- #REG_FULL_RESOURCE_DESCRIPTOR = 9 ;Resource list in the hardware description
- #REG_RESOURCE_REQUIREMENTS_LIST = 10
- #REG_QWORD = 11 ;64-bit number
-
- $AlertDetails_PDM_Show_Info =EventType,PDM_IsDetailsExist
- $AlertDetails_PDM_Show_DLLs =EventType,Show_DLL_Page
- $AlertDetails_PDM_Show_ChildProcs =ChildProcList,size,!!
-
- ;-------------------------
-
- [AlertDialog_PDM_AddToExcludes]
- #PDM_EVENT_REGMODIFY = addtrustedapp:TrustedAppEdit
- #PDM_EVENT_IMG_CHANGED = dialog:PdmMakeRule
- default = dialog:ExclusionEdit
-
- [AlertDetails_PDM_Event]
- #PDM_ROLLBACK_RESULT = report:Behavior_Blocking.EventsPDM:$(BaseId)
- #PDM_TERMINATE_PROCESS = report:Behavior_Blocking.EventsPDM:$(BaseId)
- default = dialog:AlertDetails_PDM
-
- [PDM_IsDetailsExist]
- #PDM_EVENT_REGMODIFY = 1
- #PDM_EVENT_INVADER = 1
- #PDM_EVENT_IMG_CHANGED = 1
- #PDM_EVENT_APPG_ASCHILD = 1
- #PDM_EVENT_APPG_BROWSER = 1
- #PDM_EVENT_INVADER_LOADER = 1
- #PDM_EVENT_STRANGEKEY = 1
- #PDM_EVENT_SYSCHANGE = 1
- #PDM_EVENT_HIDDEN_INSTALL = 1
- #PDM_EVENT_BUFFEROVERRUN = 1
- #PDM_EVENT_DEP = 1
-
- [PDMEventLog_Action]
- 1=$(@,AlertDetailsPDM_AddInfo_Text)
- default=$(@,AlertDialog_Description_PDM)
-
- [AlertDialog_PDM_UserDescription]
- <empty>=
- default=\ ($(strUserDescription))
-
- [AlertDetails_PDM_IsDetails_1]
- 1=1
- default=$($AlertDetails_PDM_Show_DLLs,AlertDetails_PDM_IsDetails_2)
-
- [AlertDetails_PDM_IsDetails_2]
- 1=1
- default=$($AlertDetails_PDM_Show_ChildProcs)
-
- [Show_DLL_Page]
- #PDM_EVENT_IMG_CHANGED =1
-
- [AlertObjectLabel_AddInfo_PDM_Pid]
- 0=
- default=\ (PID: $(nPID))
-
- [PDM_Settings_ActionsEnum]
- #PDM_SET_SUSPICION =#rga_allow,#rga_ask,#rga_terminate
- #PDM_SET_BROWSER =#rga_allow,#rga_ask,#rga_block
- #PDM_SET_INVADER =#rga_allow,#rga_ask,#rga_block
- #PDM_SET_HIDDENCHECK =#rga_allow,#rga_ask,#rga_terminate
- #PDM_SET_SETWNDHOOK =#rga_allow,#rga_ask,#rga_block
- #PDM_SET_REGSTRANGE =#rga_allow,#rga_ask,#rga_block
- #PDM_SET_SYSCHANGE =#rga_allow,#rga_alert
-
- [BB_Status_Ordinary]
- #PDM_STATUS_OK = i(ok)
- #PDM_STATUS_WARNING = i(warning)
- #PDM_STATUS_CRITICAL = i(error)
- default = i(error)
-
- [BB_Status]
- #PDM_ALLOW_PROCESS_ACTION = i(ok)
- #PDM_DENY_PROCESS_ACTION = i(error)
- #PDM_TERMINATING_PROCESS = i(info)
- #PDM_ROLLBACK_ACTION = $(ReportInfo.nStatus,=,#PDM_STATUS_OK,BB_Status_Event_ROLLBACK_ACTION)
- default = $(ReportInfo.nStatus,BB_Status_Ordinary)
-
- [BB_Status_Event_ROLLBACK_ACTION]
- 1 = $(ReportInfo.nError,BB_Status_Ok_Err)
- default = $(ReportInfo.nStatus,BB_Status_Ordinary)
-
- [BB_Status_Ok_Err]
- 0 = i(ok)
- default = i(warning)
-
- [BB_EventError]
- 0 =
- default = : $(@,SystemError)
-