There haven’t been new emergency files since Jan23, so it has to be quiet if your packet filtering rules are now ok and in correct sequence.
When one arrives, Kerio will alert you if you check for new or changed executables.
I just dusted off an XP box that had Avast on it. In the log of MD5 items in Kerio is at least one of the randomName.exe jobs - see picture.
So, like I said, for me it’s on the behavior side and not the packet filtering side of the firewall.

Now, as I think about it some more, even if the fileName didn’t change, a firewall will alert to the change of contents. So yes, we do need to live with it if we want a firewall to monitor what runs, rather important protection method in my opinion :slight_smile:

Sorry about that copied post#8, I meant to edit something, messed up and gave up.