I created set of Defence+ rules today, as well as predefined ones.
And after two hours of work, I was really surpised seeing this situation:
[attachment]
Yes, system, winlogon and svchost doubled and purge says all's ok...
PS: STD,SPY,PWN,NET stands for my predef-rulesets. 15 total combinations. STD being minor(messages, monitor) and PWN major(install drivers, etc) access allowance. XXX-block this part,

-ask.