Not trying to change the topic much here but when trying to block against zero day threats you should get HIPS enabled properly and not as much to do with the firewall. This would have given you a 100% level of protection for the registry of your windows systems.
By default HIPS has three boxes checked to allow you the ability to slowly see what HIPS has seen then you use the authorization selection two selections below the HIPS selection and you can then decide what to authenticate.
After doing this you will de-select or Un-check Alert Only in the HIPS selection leaving the other two checked. This setting blocks newly launched processes (Even good ones ) from making changes to your registries without you first authorizing them.
Even if it is a Brand New virus that Nobody is detecting for!