Odd$ Guard™ by Favorable Odd$™ · Windows & Mac download

Who Can Get Into Your Computer?

Odd$ Guard is a free, read-only audit for Windows PCs and Macs. It checks remote access, administrator accounts, what starts with your computer, security settings, browser and network settings, and other signs that someone besides you could get into your computer, then explains what it found in a plain-English report.

  • Runs locally on Windows and Mac
  • Does not upload scan results
  • Does not change system settings
  • Creates local HTML and JSON reports
  • Works alongside antivirus, not a replacement

Windows: version 0.1.1, Windows 10 and 11 · Mac: version 0.1.0, macOS 13 and later (how it works on a Mac) · Not code-signed yet, see download details

Get Odd$ Guard free

Enter your email and the download unlocks right away. No account, no password and no email confirmation.

We'll use your email to send you Odd$ Guard updates and occasional tips from Favorable Odds, and you can ask us to stop at any time. Your email is delivered to us through EmailJS, our contact-form provider. Odd$ Guard itself never sends your scan results or any data from your PC anywhere.

Check it before you run it

Odd$ Guard is a plain-text PowerShell script, not a compiled program, so you can read exactly what it does. Because it looks at sensitive parts of your PC, we'd rather you verify it than take our word for it.

Verify the download

After downloading, compare the ZIP's SHA-256 hash with the one above. In PowerShell:

Get-FileHash .\OddsGuard-v0.1.1.zip -Algorithm SHA256

Or in Command Prompt:

certutil -hashfile OddsGuard-v0.1.1.zip SHA256

On a Mac, in Terminal:

shasum -a 256 ~/Downloads/OddsGuard-Mac-v0.1.0.zip

The two should match exactly. If they don't, don't run it. A hash confirms the file wasn't damaged or swapped after we published it; it can't vouch for a website that has itself been compromised.

Read the source

These are plain-text copies of the exact files inside the ZIP (the OddsGuard.ps1 copy matches the hash above):

Neither scanner contains commands that send data over the network. Each writes its results only to a Reports folder on your computer.

Not code-signed yet

Version 0.1.1 of Odd$ Guard is not signed with a code-signing certificate. Windows SmartScreen or your antivirus may warn you, because Windows can't confirm who published it and the file is new.

The launcher starts PowerShell with -NoProfile -ExecutionPolicy Bypass for that one run so an unsigned script can execute. It doesn't change your PC's PowerShell settings, but security tools do watch for that pattern.

Why it asks for administrator permission

Some checks need elevated access, such as reading Microsoft Defender's exclusion list and looking at other Windows users' folders. The launcher asks Windows for permission; choose Yes for the full picture.

If you choose No, it runs a limited scan and the report says some areas weren't checked. Either way, the scan only reads settings.

What Odd$ Guard checks

Sixteen checks, all read-only. Here is what they look at.

Remote-control software

Looks for 30 known remote-access and remote-management tools, such as AnyDesk, TeamViewer, ScreenConnect, UltraViewer and RustDesk. It searches installed programs, background services, running processes and .exe files in Downloads and Desktop folders.

It notes whether a tool can accept connections at any time, is running from a download or temporary folder, or is connected to the internet right now. IT-management tools such as Atera or NinjaOne are marked "worth a look", since IT companies use them legitimately.

See all 30 tools it looks for

Remote-control apps: AnyDesk, TeamViewer, ScreenConnect (ConnectWise Control), UltraViewer, RustDesk, AnyViewer, HopToDesk, Supremo, AeroAdmin, Ammyy Admin, SimpleHelp, NetSupport, Remote Utilities, Splashtop, LogMeIn / GoTo, Zoho Assist, RemotePC, Chrome Remote Desktop, DWService, ISL Online, MeshCentral agent, and VNC servers (TightVNC, UltraVNC, RealVNC, TigerVNC).

IT management tools: Atera, NinjaOne, Kaseya, N-able, Datto RMM, Action1, Tactical RMM, Syncro.

Windows Remote Desktop, Remote Assistance and open ports

Reports whether Windows Remote Desktop is turned on (and whether Network Level Authentication is on), whether Remote Assistance invitations are allowed, and whether this PC is listening for connections on common remote-access ports, including 22 (SSH), 3389 (Remote Desktop), 5900 to 5902 (VNC), 5938 (TeamViewer), 5985 and 5986 (Windows Remote Management), 7070 (AnyDesk), 8040 and 8041 (ScreenConnect), and 21116 and 21118 (RustDesk).

Administrator and hidden accounts

Lists the local accounts on the PC and flags extra administrator accounts, accounts hidden from the sign-in screen, and the built-in Administrator and Guest accounts if they are turned on.

Startup programs and scheduled tasks

Lists programs that start with Windows (registry Run entries and Startup folders) and non-Microsoft scheduled tasks. It flags commands with signs typical of malware, such as hidden windows, encoded commands or internet downloads, scripts that run at startup, unsigned programs in temporary or download folders, and hidden unsigned tasks.

Antivirus, exclusions, firewall and UAC

Reports whether antivirus is switched on, lists Microsoft Defender exclusions (and calls out very broad ones, like a whole drive or the Downloads folder), and checks Windows Firewall and User Account Control.

Browser extensions

For Chrome, Edge and Brave, checks for extensions forced onto the PC by policy, lists installed extensions for the Windows users it can read, and flags any whose name suggests remote desktop, remote control, remote access or screen sharing.

Network redirects and proxies

Checks the Windows hosts file for entries that redirect websites, and looks for a web proxy or a proxy setup script in the current user's settings.

What Odd$ Guard does not do

Odd$ Guard shows you who and what might be able to get in. It is an audit, not a cleaner or a shield.

It doesn't remove malware

It doesn't scan files for viruses and has no ability to delete or quarantine anything.

It isn't antivirus

It works alongside your antivirus and does not replace it. Keep your antivirus on.

It doesn't fix findings

Each finding explains what to do, but Odd$ Guard changes nothing on your PC. It only writes its report files.

It doesn't upload results

Reports stay on your PC, in the Reports folder. Nothing is sent to Favorable Odds.

Findings need a human

A flagged item is a reason to look, not proof of a break-in. Legitimate remote-access tools are flagged even when you installed them on purpose, and a clear result means these checks found nothing, not that a PC is guaranteed safe.

It covers specific things

On Windows it reads Microsoft Defender's exclusions (not other antivirus products'), checks Chrome, Edge and Brave (not Firefox), and reads local Windows accounts. On a Mac it checks Chrome, Edge and Brave (not Safari or Firefox) and doesn't list apps set to Open at Login. It doesn't run on Linux or phones.

See what the report looks like

Every scan ends with a plain-English report: what needs attention now, what's worth a look, what came back clear, and technical details for anyone helping you. Below is an excerpt of our sample report.

Sample report with example findings. No computer was scanned.

Odd$ Guard Who can get into this PC? A check by Favorable Odds Tech Solutions

2 things could let someone into this computer right now.

2 need attention now, 3 are worth a look, 12 checks came back clear.

Needs attention now urgent findings

AnyDesk can accept connections at any time

It is set up for unattended access, so anyone with its password can take control, even while nobody is at the computer.

What to do: If you do not use it on purpose, uninstall it from Settings > Apps, then change your email and bank passwords from a different device.

Technical details
AreaRemote access
Installed asAnyDesk ad 9.0.4
Background serviceAnyDesk Service (Running, starts Auto)
Online right nowYes, connected to the internet

Worth a look items to review

"support01" is another administrator on this PC

Administrators can install software and change any setting, so every admin account is a full key to this computer.

What to do: Make sure you know who uses this account. If you do not recognize it, have it disabled.

What was checked clear results

  • Clear Antivirus On: Microsoft Defender
  • Clear Firewall On for all networks
  • Clear Hidden accounts None
  • Clear Proxy settings None
  • Flagged Antivirus exclusions 2 exclusions
Excerpt of the sample report. Example data only: the account, program and folder names are made up.

View Sample Report → View Mac Sample Report → Each opens the full sample in a new tab.

How Odd$ Guard works

  1. Download Odd$ Guard

    Get the ZIP from the download section and, if you like, verify its SHA-256 hash.

  2. Extract the ZIP

    Right-click the ZIP and choose Extract All (don't drag files out of it). If Windows blocked the download, right-click the ZIP, choose Properties, tick Unblock and extract it again. Only do this if you trust the download. If the ZIP won't open, or files go missing after you extract, open Windows Security → Virus & threat protection → Protection history: Defender sometimes quarantines unsigned launchers that ask for administrator permission. Restore the file only if the SHA-256 above matches your download.

  3. Run the launcher

    Double-click Run-OddsGuard.bat inside the extracted folder.

  4. Approve the Windows prompt

    Choose Yes when Windows asks for administrator permission so every check can run. If you decline, you get a limited scan.

  5. Review the report

    The report opens in your browser when the scan finishes. Copies are saved in the Reports folder next to the script: an HTML report for people and a JSON file for tools.

Where reports go. Reports are written to the Reports folder inside the Odd$ Guard folder. If that location can't be written to (a read-only USB stick, for example), Odd$ Guard saves them to OddsGuard Reports on your Desktop instead. It briefly creates and deletes a small test file to check the folder is writable.

Tip. Run it while signed in to the Windows account you want checked. If Windows asks for a different administrator's password, per-user checks such as startup entries and proxy settings describe that administrator's profile.

Advanced options
.\OddsGuard.ps1 -DemoReport      # sample report, no scan
.\OddsGuard.ps1 -OutputDir D:\   # choose where reports go
.\OddsGuard.ps1 -NoOpen          # do not open the report when done

Who can get into your Mac?

The Mac version is a separate plain-text script that runs in Terminal. It checks the Mac's own ways in and writes the same kind of plain-English report. Version 0.1.0, for macOS 13 Ventura and later.

  1. Download it

    Get OddsGuard-Mac-v0.1.0.zip from the download section. Safari unzips it into your Downloads folder.

  2. Open Terminal

    It's in Applications › Utilities, or search for Terminal with Spotlight.

  3. Start the scan

    Type zsh and a space, drag OddsGuard.zsh from the OddsGuard-Mac folder into the Terminal window, then press Return.

  4. Allow the full scan

    Press Return and type your Mac password when asked; nothing shows as you type. Type n instead for a limited scan.

  5. Review the report

    It opens in your browser. Copies are saved in a Reports folder next to the script.

Why Terminal? Odd$ Guard for Mac isn't signed or notarized by Apple yet. Running it with zsh in Terminal works without either, and you can open the script in TextEdit and read every line first. If macOS asks whether Terminal may access your Downloads or Desktop folder, choose Allow so it can look for downloaded remote-control apps; if you don't, those folders are skipped.

Verify it. In Terminal, shasum -a 256 ~/Downloads/OddsGuard-Mac-v0.1.0.zip should print the ZIP hash in the Mac release details. You can also read the OddsGuard.zsh source.

Advanced options
zsh OddsGuard.zsh --demo          # sample report, no scan
zsh OddsGuard.zsh --output ~/Desktop  # choose where reports go
zsh OddsGuard.zsh --no-open       # do not open the report when done
zsh OddsGuard.zsh --limited       # skip the administrator-rights question

What it checks on a Mac

Remote-control software

The same 30 remote-access and IT-management tools as on Windows. It searches Applications, support folders, background items and running apps, plus .app, .dmg, .pkg and .zip downloads in Downloads and Desktop. It notes tools that start by themselves, run straight from a download or disk image, or are online right now.

Mac sharing settings and open ports

Screen Sharing and Remote Management, Remote Login (SSH) and Remote Apple Events, plus ports used by remote-control apps: 5901 and 5902 (VNC), 5938 (TeamViewer), 7070 (AnyDesk), 8040 and 8041 (ScreenConnect), and 21116 and 21118 (RustDesk).

Administrator and hidden accounts

Extra administrators, accounts hidden from the login screen, the root user and the Guest account if they're turned on, and automatic login.

Background items and scheduled jobs

Launch agents and daemons for all users, and cron jobs. It flags commands that download and run code, scripts that run in the background, and unsigned programs in temporary, download or hidden folders.

Mac security settings

Gatekeeper, System Integrity Protection, automatic security updates (which keep the built-in XProtect malware protection current), the firewall, FileVault, and sudo rules that skip the password.

Device management and profiles

Whether the Mac is enrolled in device management, and which configuration profiles are installed. Scams and adware use profiles to set proxies, trust certificates and force browser extensions.

Browsers, hosts file and proxies

Forced and installed extensions in Chrome, Edge and Brave, website redirects in /etc/hosts, and web proxies or proxy scripts in use.

View Mac Sample Report → Opens the full Mac sample in a new tab.

What's in a report, and who sees it

Only you do, unless you share it. Odd$ Guard doesn't send reports anywhere; they are files on your computer.

Because the report is written for someone who might be helping you, it includes technical detail: your computer's name, Windows account names, installed remote-access tools, program and file locations, full startup and scheduled-task commands, Microsoft Defender exclusions, hosts-file entries and proxy addresses. A Mac report also lists background items, configuration profiles and sudo rules. The JSON file holds the same findings. Read a report before you send it to anyone, and share only what you're comfortable with.

Found something you don't recognize?

Odd$ Guard tells you what it finds. Favorable Odds can help you understand what matters and what to do next.

How to check who can remotely access a Windows PC

Remote access isn't bad by itself. IT companies, family members and you may all use it on purpose. The problem is remote access you didn't set up or no longer need, which is how tech-support scams and account takeovers keep a way back into a computer. A remote access audit simply lists every way in, so you can confirm each one is yours.

You can check the main ones by hand. Odd$ Guard does all of these in a couple of minutes and puts the results in one report.

Find remote-access software

Open Settings > Apps and look for programs such as AnyDesk, TeamViewer, ScreenConnect or UltraViewer. Also look in your Downloads folder for setup or portable .exe files. Scammers often have people download a tool and open it directly, so it may not appear in your installed apps. If you didn't install one on purpose, uninstall it and change your important passwords from a different device.

Windows Remote Desktop security check

Remote Desktop lets anyone with a password for an account on the PC sign in from another computer. Home computers rarely need it. Check Settings > System > Remote Desktop, and turn it off unless you use it. Remote Assistance invitations are under System Properties > Remote.

Check administrator accounts in Windows

Administrators can install software and change any setting, so every admin account is a full key to the PC. Look at Settings > Accounts > Other users, or open an administrator command prompt and run net localgroup administrators. Watch for accounts you don't recognize, and for the built-in Administrator or Guest accounts being turned on.

Spot suspicious startup programs

Open Task Manager > Startup apps to see what launches when you sign in, and Task Scheduler for scheduled tasks. Entries that run scripts, use hidden windows or launch from Temp or Downloads folders deserve a closer look. Don't delete something blindly; if you're unsure, get it checked.

Look for antivirus exclusions

Exclusions tell Windows Security not to scan certain folders or files, and malware or scammers sometimes add them so their tools are never caught. Review them in Windows Security > Virus & threat protection > Manage settings > Exclusions, and remove anything you didn't add.

Browsers, hosts file and proxies

Extensions that share or control your screen can be removed from your browser's extensions page. The hosts file (C:\Windows\System32\drivers\etc\hosts) can redirect websites to fake pages, and a proxy under Settings > Network & internet > Proxy can route your browsing through another server. If this isn't a work PC, you rarely need either.

Odd$ Guard FAQ

What is Odd$ Guard?

Odd$ Guard is a free, read-only audit for Windows PCs and Macs. It checks for remote-access software, extra or hidden administrator accounts, suspicious startup items and scheduled tasks, weakened antivirus, firewall and User Account Control settings (on a Mac: Gatekeeper, System Integrity Protection, FileVault and device-management profiles), browser extensions, hosts-file redirects, proxies and open remote-access ports, then writes a plain-English HTML report and a JSON file. See what Odd$ Guard checks for the full list.

Is Odd$ Guard free?

Yes. Odd$ Guard is a free download. You enter your email to unlock it, with no account, password or email confirmation. We may email you about Odd$ Guard updates and Favorable Odds services, and you can ask us to stop at any time.

Does Odd$ Guard upload my scan results?

No. The script contains no commands that send data over the network, and it writes its results only to a Reports folder on your computer. You can read the script before you run it. Checking programs' publisher signatures is done by Windows or macOS itself, which may look up certificate information online, but Odd$ Guard sends nothing about your computer.

Does Odd$ Guard change anything on my PC or fix problems?

No. It only reads settings and lists what it finds. It writes its report files (and briefly creates and deletes a small test file to confirm the report folder is writable). Each finding says what you could do, but you decide and you make the change.

Is Odd$ Guard antivirus? Can it remove malware?

No. Odd$ Guard doesn't scan files for viruses and can't remove or quarantine anything. It works alongside your antivirus and does not replace it. Think of it as a checklist of the ways someone could get into your PC, not a shield.

Why does Windows warn me about Odd$ Guard?

Version 0.1.1 of Odd$ Guard is not code-signed, so Windows SmartScreen or your antivirus may warn you that it can't confirm the publisher. The launcher also starts PowerShell with an execution-policy bypass for that one run, a pattern security tools watch for. Verify the SHA-256 hash and read the source first; see check it before you run it.

Why does Odd$ Guard ask for administrator permission?

Some checks need elevated access, for example reading Microsoft Defender's exclusion list. The launcher asks Windows for permission, and if you decline it runs a limited scan and the report says which areas weren't checked. The scan itself is read-only either way.

Does a flagged item mean my PC has been hacked?

Not necessarily. A flag means "take a look". Legitimate remote-access tools are flagged even when you installed them on purpose, and IT-management tools are marked as worth a look because IT companies use them legitimately. Follow the “What to do” note under each finding, and get help if you're unsure.

Which remote-access tools does Odd$ Guard look for?

Thirty known tools, including AnyDesk, TeamViewer, ScreenConnect, UltraViewer, RustDesk, Splashtop, LogMeIn, Chrome Remote Desktop and VNC servers, plus IT-management tools such as Atera, NinjaOne, Kaseya and Datto RMM. It searches installed programs, background services, running processes and .exe files in Downloads and Desktop folders. The full list is in what Odd$ Guard checks.

Which versions of Windows does Odd$ Guard work on?

It is built for Windows 10 and 11 and runs on the Windows PowerShell 5.1 that comes with them (PowerShell 7 or newer also works). If a feature it relies on is missing on your version of Windows, that check is skipped and the report says it wasn't checked. Macs have their own version, Odd$ Guard for Mac. Neither runs on Linux or phones.

Does Odd$ Guard work on a Mac?

Yes. Odd$ Guard for Mac (version 0.1.0) is a separate script for macOS 13 Ventura and later that you run in Terminal. It looks for the same 30 remote-access tools plus the Mac's own ways in: Screen Sharing, Remote Login, extra or hidden administrator accounts, background items, Gatekeeper, System Integrity Protection, FileVault, device-management profiles, browser extensions, the hosts file and proxies. It is read-only and writes the same kind of report. It isn't signed or notarized yet, but running it with zsh in Terminal doesn't need either. See Odd$ Guard for Mac.

Where does Odd$ Guard save its reports?

In a Reports folder inside the Odd$ Guard folder: an HTML report for people and a JSON file for tools. If that folder can't be written to, such as on a read-only USB stick, it saves them to a folder called OddsGuard Reports on your Desktop. Reports stay on your PC unless you share them.

How can I check who has remote access to my PC without Odd$ Guard?

You can check the main things by hand: installed remote-access programs, Windows Remote Desktop and Remote Assistance settings, administrator accounts, startup apps and scheduled tasks, antivirus exclusions, browser extensions, the hosts file and proxy settings. Our guide to checking who can remotely access a Windows PC shows where to look.

What should I do if Odd$ Guard finds something I don't recognize?

Read the “What to do” note under that finding. For an unfamiliar remote-control app, the report suggests uninstalling it and changing your important passwords from a different device. For hidden startup commands or scheduled tasks it suggests not deleting them blindly and having a technician look. If you'd like help understanding your report, Favorable Odds can help.