So far not very helpful
because when it identifies OpenVPN client as behaving like a backdoor that tries to bypass LAN or another program that tries to "invisibly" send out information, it doesn't provide any clue (such as the destination IP address) so I can tell if the program has been compromised or it's just performing its legitimate function.