It is not quite that simple, I would start by defining the outbound services you will allow, add these all into a service group. Then change the allow_standard rule to use that service instead of all-services. This will block most unwanted outbound traffic. That said many P2P and IM programs will use any outbound port quite successfully, Skype is famous for this.