Hello Alex_Mihaiuc , thank you for responding, and sorry for the delay with the reply, for some reason I did not get the notification, may be I accidentally turned it off.
I would like to clarify that any filter does not load, just go to filters, reset filter, add an arbitrary rule, save, and once you exited the Process Monitor and re-started it again try loading that filter. It does not. I just quickly did the above steps, and create a rule to filter: "Path contains google then include". The filter iteself works, but when saved it is not possible to load it. The file that was produced was called "Filter 0.PMF" and you can rund the following PowerShell command to produce it:
[Convert]::FromBase64String("swMAAAEYAAAAh5wAAAYAAAABDgAAAGcAbwBvAGcAbABlAAAAAAAAAAAAAAB1nAAAAAAAAAAYAAAAUAByAG8AYwBtAG8AbgAuAGUAeABlAAAAAAAAAAAAAAB1nAAAAAAAAAAYAAAAUAByAG8AYwBlAHgAcAAuAGUAeABlAAAAAAAAAAAAAAB1nAAAAAAAAAAaAAAAQQB1AHQAbwByAHUAbgBzAC4AZQB4AGUAAAAAAAAAAAAAAHWcAAAAAAAAABwAAABQAHIAbwBjAG0AbwBuADYANAAuAGUAeABlAAAAAAAAAAAAAAB1nAAAAAAAAAAcAAAAUAByAG8AYwBlAHgAcAA2ADQALgBlAHgAZQAAAAAAAAAAAAAAdZwAAAAAAAAADgAAAFMAeQBzAHQAZQBtAAAAAAAAAAAAAAB3nAAABAAAAAAQAAAASQBSAFAAXwBNAEoAXwAAAAAAAAAAAAAAd5wAAAQAAAAAEAAAAEYAQQBTAFQASQBPAF8AAAAAAAAAAAAAAHicAAAEAAAAABAAAABGAEEAUwBUACAASQBPAAAAAAAAAAAAAACHnAAABQAAAAAaAAAAcABhAGcAZQBmAGkAbABlAC4AcwB5AHMAAAAAAAAAAAAAAIecAAAFAAAAAAoAAAAkAE0AZgB0AAAAAAAAAAAAAACHnAAABQAAAAASAAAAJABNAGYAdABNAGkAcgByAAAAAAAAAAAAAACHnAAABQAAAAASAAAAJABMAG8AZwBGAGkAbABlAAAAAAAAAAAAAACHnAAABQAAAAAQAAAAJABWAG8AbAB1AG0AZQAAAAAAAAAAAAAAh5wAAAUAAAAAEgAAACQAQQB0AHQAcgBEAGUAZgAAAAAAAAAAAAAAh5wAAAUAAAAADAAAACQAUgBvAG8AdAAAAAAAAAAAAAAAh5wAAAUAAAAAEAAAACQAQgBpAHQAbQBhAHAAAAAAAAAAAAAAAIecAAAFAAAAAAwAAAAkAEIAbwBvAHQAAAAAAAAAAAAAAIecAAAFAAAAABIAAAAkAEIAYQBkAEMAbAB1AHMAAAAAAAAAAAAAAIecAAAFAAAAABAAAAAkAFMAZQBjAHUAcgBlAAAAAAAAAAAAAACHnAAABQAAAAAQAAAAJABVAHAAQwBhAHMAZQAAAAAAAAAAAAAAh5wAAAYAAAAAEAAAACQARQB4AHQAZQBuAGQAAAAAAAAAAAAAAJKcAAAAAAAAABQAAABQAHIAbwBmAGkAbABpAG4AZwAAAAAAAAAAAAAA") | Set-Content "Filter 0.PMF" -AsByteStream
Here I encoded my file as base64 so I could post it for you here.
Once again, many thanks for looking into this, really appreciated.
Andrew Savinykh