Neurohazard
暮雲煙月,皓首窮經;森羅萬象,如是我聞。

【火绒】系统防御自定义规则

wpadmin~October 14, 2018 /InfoSec

【火绒】系统防御自定义规则

Contents

【火绒】系统防御自定义规则

系统防御

导入

主菜单 > 软件设置 > 系统防御 > 自定义防护 > 添加规则包

自定义规则

huorong_demo_rule_20180916.json

{
  "ver":"3.0",
  "tlb":[
    {
      "power":1,
      "name":"LOL净化",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":16,
            "res_path":"*TenioDL*.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*TP*Help*.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*Ten*Safe*.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*QTalk*.exe"
          },
          {
            "mt":1,
            "at":2,
            "res_path":"*LQT.dll"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*CrossProxy*.exe"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"DNF净化",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":16,
            "res_path":"*\\BackgroundDownloader.*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\Advert*.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\start\\Cross\\Apps\\DNFAD\\*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\TCLS\\TenProtect\\TP\\*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\Tencent\\TGuard\\TGuard.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\Tencent\\TGuard\\*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*CrossProxy*.exe"
          }
        ],
        "*\\CrossProxy.exe":[
          {
            "mt":1,
            "at":16,
            "res_path":"*\\start\\Cross\\Apps\\TP\\*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\start\\Cross\\Apps\\Trial\\*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\start\\Cross\\Apps\\DNFDataReporter\\*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\start\\Cross\\Apps\\GameSafe\\*"
          },
          {
            "mt":1,
            "at":18,
            "res_path":"*\\start\\Cross\\Apps\\DNFAD\\*"
          },
          {
            "mt":1,
            "at":18,
            "res_path":"*\\start\\Cross\\Apps\\DNFTips\\*"
          }
        ],
        "*\\system32\\services.exe":[
          {
            "mt":1,
            "at":18,
            "res_path":"C:\\Program Files (x86)\\Tencent\\TGuard\\*"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】阿里系净化",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":17,
            "res_path":"*\\AlibabaProtect\\>\\*.???"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\aliedit\\>\\HotFixTool.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\AlipaySecSvc.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\aliedit\\>\\pcas.exe"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*\\Windows\\Tasks\\AliUpdater*.job"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\AliTask.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\AliFileCheck.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\AliIMSrv.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\AliimSafe.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\AliApkInstaller.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\alicnotify.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\alipaydownloader.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\alicupsrv.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\AlibabaProtectCon.exe"
          }
        ],
        "AlibabaProtect.exe":[
          {
            "mt":1,
            "at":31,
            "res_path":"*"
          },
          {
            "mt":2,
            "at":15,
            "res_path":"*"
          }
        ],
        "alipaydownloader.exe":[
          {
            "mt":1,
            "at":31,
            "res_path":"*"
          },
          {
            "mt":2,
            "at":15,
            "res_path":"*"
          }
        ],
        "alicupsrv.exe":[
          {
            "mt":1,
            "at":31,
            "res_path":"*"
          },
          {
            "mt":2,
            "at":15,
            "res_path":"*"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止360全家桶安装",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":21,
            "res_path":"*360\\360safe\\*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\Safe360Ext"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\360Safe"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\*Qihoo*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\*softmanager360*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\*ZHUSHOU360*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\*LiveUpdate360*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\*360安全卫士*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\*360*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_USERS\\360SandBox"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\360*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"C:\\Documents and Settings\\Administrator\\Application Data\\360se\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\360\\360sd\\*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SOFTWARE\\*\\*360SD*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SOFTWARE\\*\\*SD360*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SOFTWARE\\*\\*360rp*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\360\\360safe\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\360se*\\*"
          },
          {
            "mt":1,
            "at":5,
            "res_path":"*\\360netmon*.sys"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\360SelfProtection.sys"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\360Base.dll"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\360P2SP.dll"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止百度全家桶安装",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":21,
            "res_path":"*\\BaiduSG\\>\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\*bddownload*.exe"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\Microsoft\\Windows\\CurrentVersion\\Run\\*baidu*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Windows\\SysWOW64\\config\\systemprofile\\AppData\\Local\\Temp\\Baidu*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Windows\\SysWOW64\\config\\systemprofile\\AppData\\Local\\Temp\\Fix*.exe"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*百度输入法*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*baidupinyin*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Baidu\\BaiduAn\\*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SYSTEM\\*\\Services\\Baidu*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SYSTEM\\*\\Services\\bd*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SOFTWARE\\*\\BDDownload*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SOFTWARE\\*\\百度卫士"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\BDShellExt*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Common Files\\Baidu\\BDDownload\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Common Files\\Baidu\\BaiduHips\\*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SOFTWARE\\*\\百度杀毒"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Baidu\\BaiduBrowser\\*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_CURRENT_USER\\Software\\Baidu\\*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_CURRENT_USER\\Software\\Classes\\BaiduBrowserHTML"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SOFTWARE\\*\\百度浏览器"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Baidu*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_CURRENT_USER\\Software\\Baidu*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_CURRENT_USER\\Software\\*\\*BDExExtension*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Baidu\\BaiduPinyin\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Documents and Settings\\>\\Application Data\\Baidu\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Users\\>\\AppData\\>\\Baidu\\*"
          }
        ],
        "BaiduProtect.exe":[
          {
            "mt":1,
            "at":31,
            "res_path":"*\\*.*"
          },
          {
            "mt":2,
            "at":15,
            "res_path":"*\\*"
          }
        ],
        "bddownloader.exe":[
          {
            "mt":1,
            "at":31,
            "res_path":"*\\*.*"
          },
          {
            "mt":2,
            "at":15,
            "res_path":"*\\*"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止金山全家桶安装",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":21,
            "res_path":"*\\kingsoft\\kingsoft antivirus\\*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\duba*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\Kingsoft Internet Security"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\Kingsoft\\antivirus"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\Kingsoft\\KISCommon"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\Kingsoft\\kwspriEx"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\SYSTEM\\*\\Services\\kis*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\SYSTEM\\*\\Services\\ks*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\SYSTEM\\*\\Services\\kx*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\Kingsoft\\KVip"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\kdesk"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\liebao\\*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SOFTWARE\\liebao\\*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SYSTEM\\*\\Services\\knbcenter*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\SOFTWARE\\Classes\\Liebao*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\SOFTWARE\\Clients\\StartMenuInternet\\liebao*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*KNBCenter.exe*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\DriverGenius"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\dg.exe"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\qd.exe"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\qudong.exe"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\DgService.EXE"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\SOFTWARE\\MyDrivers*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\Services\\DGPNPSEV*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\Services\\DgSafe*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\DriverGenius\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\AppData\\Roaming\\kingsoft\\*"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":0,
      "name":"【流氓快走™】[弹窗较多]阻止修改文件打开方式",
      "policies":{
        "*":[
          {
            "mt":2,
            "at":13,
            "res_path":"HKEY_CLASSES_ROOT\\.*"
          }
        ]
      },
      "verdict":1
    },
    {
      "power":0,
      "name":"【流氓快走™】[弹窗较多]阻止捆绑安装",
      "policies":{
        "*":[],
        "*inst*.exe":[
          {
            "mt":1,
            "at":16,
            "res_path":"*inst*.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*setup*.exe"
          }
        ],
        "*setup*.exe":[
          {
            "mt":1,
            "at":16,
            "res_path":"*setup*.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*inst*.exe"
          }
        ]
      },
      "verdict":1
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止篡改主页&书签",
      "policies":{
        "*":[
          {
            "mt":2,
            "at":4,
            "res_path":"*Microsoft\\Internet Explorer\\Main\\Start Page"
          },
          {
            "mt":2,
            "at":4,
            "res_path":"*Microsoft\\Internet Explorer\\Main\\Default_Page_URL"
          },
          {
            "mt":1,
            "at":4,
            "res_path":"*Microsoft\\Internet Explorer\\AboutURLs\\Tab"
          },
          {
            "mt":1,
            "at":4,
            "res_path":"*\\Google Chrome.lnk"
          },
          {
            "mt":1,
            "at":4,
            "res_path":"*\\Internet Explorer.lnk"
          },
          {
            "mt":1,
            "at":4,
            "res_path":"*\\Users\\>\\Favorites\\*"
          },
          {
            "mt":1,
            "at":4,
            "res_path":"*\\Users\\>\\AppData\\Local\\Google\\Chrome\\User Data\\>\\Bookmarks"
          },
          {
            "mt":1,
            "at":4,
            "res_path":"*\\Users\\>\\AppData\\Local\\Google\\Chrome\\User Data\\>\\Secure Preferences"
          }
        ]
      },
      "verdict":1
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止电脑管家安装",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Tencent\\QQPCMgr\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*guanjia*"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止卸载火绒",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":16,
            "res_path":"*\\Huorong\\Sysdiag\\uninst.exe"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止流氓软件驱动保护",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":21,
            "res_path":"*\\KINGDING.DLL"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\BFDrv.sys"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\fixbdsw.dll"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\system32\\bd0*.sys"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\BDArKit.sys"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\BDMNetMon.sys"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\BDMWrench.sys"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\BDDefense.sys"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\BDAntiExp.sys"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\BDEnhanceBoost.sys"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止瑞星安装",
      "policies":{
        "*":[
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_L0CAL_MACHINE\\SoftWare\\Rising\\rav"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_L0CAL_MACHINE\\SoftWare\\Rising\\rfw"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Rising\\rav\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Rising\\rfw\\*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"HKEY_L0CAL_MACHINE\\SoftWare\\Rising\\rse"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Rising\\rse\\*"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止2345全家桶安装",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":21,
            "res_path":"*\\2345Soft\\2345PCSafe\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\2345Soft\\2345Pinyin\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\2345Soft\\2345Explorer\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\AppData\\Roaming\\MiniPage_2345*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\AppData\\Roaming\\Helper_2345*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*2345*Safe*.dll"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止净广大师安装",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":21,
            "res_path":"*\\AdAnti\\*.*"
          }
        ],
        "*\\*AdAnti*.exe":[
          {
            "mt":1,
            "at":29,
            "res_path":"*\\*.sys"
          },
          {
            "mt":1,
            "at":29,
            "res_path":"*.sys"
          },
          {
            "mt":1,
            "at":29,
            "res_path":"*.exe"
          },
          {
            "mt":1,
            "at":29,
            "res_path":"*\\*.exe"
          },
          {
            "mt":1,
            "at":29,
            "res_path":"*\\*.dll"
          },
          {
            "mt":1,
            "at":29,
            "res_path":"*.dll"
          },
          {
            "mt":1,
            "at":29,
            "res_path":"*\\Windows\\system32\\*\\*.sys"
          },
          {
            "mt":2,
            "at":13,
            "res_path":"*"
          },
          {
            "mt":2,
            "at":13,
            "res_path":"*\\*"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止桌面/任务栏乱七八糟图标",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*美女*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*导航*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*购物*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*特惠*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*特卖*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*双十*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*双1*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*游戏*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*视频*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*影音*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*电影*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*大全*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*hao123*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*2345*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\Desktop\\*搜索*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*美女*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*导航*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*购物*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*特惠*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*特卖*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*双十*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*双1*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*游戏*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*视频*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*影音*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*电影*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*大全*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*搜素*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*hao123*.lnk"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\*\\AppData\\Roaming\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\TaskBar\\*2345*.lnk"
          }
        ]
      },
      "verdict":1
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止弹窗程序",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":16,
            "res_path":"*\\wpsupdate.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\wpsnotify.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\wwbizsrv.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\XLLiveUD.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\Profiles\\XLGameBox*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"\\Data\\ThunderPush\\XLGamebox*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"\\Data\\ThunderDownloader\\XLGameBox*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*迅雷游戏*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*Windows*OEM?.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*Windows*OEM??.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*Windows*KMS?.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*Windows*KMS??.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*wpsrepair*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*2345minipage*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\BFpush.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\BFpop.exe"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】阻止垃圾淘宝",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":16,
            "res_path":"*Taobao*.???"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】好压净化",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Program Files\\2345Soft\\HaoZip\\Protect\\*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\AppData\\Roaming\\HaoZip\\*"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"【流氓快走™】QQ净化",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":16,
            "res_path":"*\\Tencentdl.???"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\QQPhoneAssistant*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\QQMiniDL*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\QQProtectUpd.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\qqsafeud.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\QQPet*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.QQPet*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.QQMusic*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.QQLive*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.QQGame*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.AppStore*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.BabyQ*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.QQShow*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.Soso"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.QQVip*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.QQRing*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.Stock*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.WenWen*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Com.Tencent.XiuRoom*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\QQ\\Bin\\HotPic.dll"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\QQ\\Bin\\App*"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"QQ更新禁用",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":16,
            "res_path":"*\\txupd.exe"
          }
        ]
      },
      "verdict":0
    },
        {
      "power":1,
      "name":"多玩YY净化",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":16,
            "res_path":"*\\yypcgame.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\instlauncher.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\yygame.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\yygrender.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\duowan\\yy\\yycomstore\\2052\\*\\adb.exe"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\gsminidownloader.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\me.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\yygamestore.exe"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*BoxGameDaemonTask*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*weifang*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\yyexplorer*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\YGPreLoader*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\hjGameUpdate*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\funnyroom*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\lobby_gameab*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\yygupdate*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\yygamecrash*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\com.yy.funnyroom*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\com.yy.gameproxy*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\duowan\\*\\adb.exe"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\com.yy.gamestore*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\com.yy.yycgame*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\com.yy.apppush*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\com.yy.apphelper*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\kuaikuai*"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*\\kuaiwai*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\kuaiwai*"
          }
        ]
      },
      "verdict":0
    },
        {
      "power":1,
      "name":"迅雷净化",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":16,
            "res_path":"*\\XmpPusherSetup.exe"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\>\\AppData\\Local\\Temp\\>.td"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"C:\\Users\\>\\Thunder Network\\KKVideo\\*"
          },
          {
            "mt":2,
            "at":7,
            "res_path":"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\XLServicePlatform\\Start"
          },
          {
            "mt":1,
            "at":5,
            "res_path":"*\\kkvideo*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\kkvideo*"
          },
          {
            "mt":2,
            "at":1,
            "res_path":"*XunleiBHO*"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*Thunder\\BHO*"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*Thunder\\XLApp*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\XLMiniGame*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\XLWuxia*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Components\\Streamer*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"SoftwareCenter"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Kankan*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\ThunderMinisite*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Components\\GameDownloader*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\Components\\Tips\\TipsExtend*"
          },
          {
            "mt":1,
            "at":23,
            "res_path":"*\\XLGame*"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*\\drivers\\XLGuard*"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*\\drivers\\XLWFP*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\XLLiveUD*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\LiveUDInstaller*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\Xmp.exe"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\XLUEOPS*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\XLBugReport*"
          }
        ]
      },
      "verdict":0
    },
        {
      "power":1,
      "name":"QQ音乐净化",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":21,
            "res_path":"*moleplugin\\AdbWinApi*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*moleplugin\\AdbWinUsbApi*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*moleplugin\\AndroidDevice*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*moleplugin\\device*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*moleplugin\\extapp*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*moleplugin\\filter*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*moleplugin\\installerror*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*moleplugin\\InstallPlugin*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*moleplugin\\tadb*"
          }
        ]
      },
      "verdict":0
    },
        {
      "power":1,
      "name":"Tim净化",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":16,
            "res_path":"*\\QQPetAgent.exe"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*\\Tencent\\AndroidServer*"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*\\Tencent\\AndroidAssist*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\QQGameMicro_setup.exe"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*:\\Users\\*\\QQPet"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*\\ProgramData\\QQPet*"
          },
          {
            "mt":1,
            "at":17,
            "res_path":"*\\QzoneMusicInstall.exe"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*:\\Users\\*\\QQWifi*"
          },
          {
            "mt":1,
            "at":1,
            "res_path":"*\\Tencent\\QQPhoneAssistant*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\com.Tencent.Advertisement*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*Com.Tencent.QQPet*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*Com.Tencent.SoBar*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*Com.Tencent.PaiPai*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*Com.Tencent.Today*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*Com.Tencent.taotao*"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"蒲公英禁用",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":1,
            "res_path":"*\\Shopping Assistant*"
          },
          {
            "mt":2,
            "at":5,
            "res_path":"*\\ruyitao*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\dandelion*"
          }
        ]
      },
      "verdict":0
    },
    {
      "power":1,
      "name":"搜狗输入法净化",
      "policies":{
        "*":[
          {
            "mt":1,
            "at":21,
            "res_path":"*\\SGDownload*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\SohuNews*"
          },
          {
            "mt":1,
            "at":21,
            "res_path":"*\\SGMedalLoader*"
          },
          {
            "mt":1,
            "at":16,
            "res_path":"*\\skinbox*"
          }
        ]
      },
      "verdict":0
    }
  ]
}

广告拦截/恶意网站拦截

广告拦截

主菜单 > 软件设置 > 网络防御 > 恶意网站拦截 > 导入

用户规则分享区
http://bbs.huorong.cn/forum-45-1.html

[广告拦截类] Fk ADⅢ广告过滤规则 [12.29.2017 Update]
http://bbs.huorong.cn/thread-17862-1-1.html

Leave a Reply

Your email address will not be published. Required fields are marked *