Superscan is not much better. The Nmap-bases ones are very good, but usually the frontend fucks it up sometimes. Try
Well, I would configure it correctly instead.
*sigh* Why do you think that you'd actually have control? If the program wants to create a connection without your consent (either explicit by configuration or implicit by reaction on user-invoked events), then it will simply bypass your so-called control.Of course you won't see it because the usual way is to wait until the user starts a trusted program and then hijacks its connections. About every modern malware does so. Or actually most malware starts the program itself using IPC with the Windows shell and then suppresses the screen draws.
Then I wonder how you want to achieve any real security by running one.