EXE Files Won't Run, Browsers, PC Crash

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #16
    We will take care of all of those things tomorrow after I have made the fixlist for you.

    Not to worry about the Vulkan deal, with the FRST fix we are going to Nvidia Telemetry as well as anything else that needs to go. There is just a good deal of information to go over to write a FRST fix.

    Comment

    • paulwb
      PCHF Member
      • Nov 2016
      • 159

      #17
      Originally posted by Malnutrition
      Alright, this is a good bit of information to go over, so I will have a FRST fix for you tomorrow.

      Can you tell me what issues remain with the machine?

      Also, Download AUtoruns, and disable – untick all items under scheduled task, so long as they do not relate to Panda and then reboot.
      Much appreciated.
      OK, Scheduled Tasks items disabled in Autoruns, except for Panda files

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7041

        #18
        FRST Fix

        Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

        Comment

        • paulwb
          PCHF Member
          • Nov 2016
          • 159

          #19
          Thank you.
          I noticed the GWX Control Panel process was closed. I initially installed it to block Windows 10 software upgrade prompts. Is it no longer needed?

          OK, here is the Fixlog

          [HEADING=1]Fix result of Farbar Recovery Scan Tool (x64) Version: 20-11-2016 01
          Ran by Owner (20-11-2016 20:41:21) Run:3
          Running from C:\Users\Owner\Desktop
          Loaded Profiles: Owner (Available Profiles: Owner)
          Boot Mode: Normal[/HEADING]
          fixlist content:


          start
          CreateRestorePoint:
          CloseProcesses:
          AlternateDataStreams: C:\Windows\system32\aitstatic.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\audiodg.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\AudioEng.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\AUDIOKSE.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\AudioSes.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\blackbox.dll:$CmdTcID [130]
          AlternateDataStreams: C:\Windows\system32\charmap.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\ci.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\cryptsp.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\cryptui.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\dfshim.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\drmmgrtn.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\drmv2clt.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\EncDump.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\icardagt.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\icardres.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\IMJP10K.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\infocardapi.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\KBDBASH.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\KBDRU.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\KBDRU1.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\KBDTAT.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\KBDYAK.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\mscorier.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\mscories.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\msctf.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\msnetobj.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\msscp.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\mstsc.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\nvdispco6434725.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\nvdispco6434752.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\nvdispgenco6434725.dll:$CmdTcI D [64]
          AlternateDataStreams: C:\Windows\system32\nvdispgenco6434752.dll:$CmdTcI D [64]
          AlternateDataStreams: C:\Windows\system32\packager.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\pcadm.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\pcaevts.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\pcalua.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\pcasvc.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\pcawrk.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\perftrack.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\pku2u.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\powertracker.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\profsvc.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\rastls.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\rdpcorekmts.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\scesrv.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\termsrv.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\TSWbPrxy.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\TSWorkspace.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\TsWpfWrp.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\ubpm.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\wdi.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\winlogon.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\winsta.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\wmdrmsdk.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\WMPhoto.dll:$CmdTcID [130]
          AlternateDataStreams: C:\Windows\system32\WSManHTTPConfig.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\WSManMigrationPlugin.dll:$CmdT cID [64]
          AlternateDataStreams: C:\Windows\system32\WsmAuto.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\WsmSvc.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\WsmWmiPl.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\AudioEng.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\AUDIOKSE.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\AudioSes.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\blackbox.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\charmap.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\cryptsp.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\cryptui.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\dfshim.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\drmmgrtn.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\drmv2clt.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\icardagt.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\icardres.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\IMJP10K.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\infocardapi.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\java.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\javaw.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\javaws.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\KBDBASH.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\KBDRU.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\KBDRU1.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\KBDTAT.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\KBDYAK.DLL:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\mscorier.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\mscories.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\msctf.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\msnetobj.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\msscp.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\mstsc.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\ncsi.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\nlaapi.dll:$CmdTcID [130]
          AlternateDataStreams: C:\Windows\SysWOW64\packager.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\pku2u.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\rastls.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\scesrv.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\TSWorkspace.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\TsWpfWrp.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\ubpm.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\wdi.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\winsta.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\wmdrmsdk.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\WMPhoto.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\WSManHTTPConfig.exe:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\WSManMigrationPlugin.dll:$CmdT cID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\WsmAuto.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\WsmSvc.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\SysWOW64\WsmWmiPl.dll:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\Drivers\PEAuth.sys:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\Drivers\rdpwd.sys:$CmdTcID [64]
          AlternateDataStreams: C:\Windows\system32\Drivers\tssecsrv.sys:$CmdTcID [64]
          AlternateDataStreams: C:\Users\Owner\Desktop\fxddmalta4setup_build610.ex e:$CmdTcID [64]
          AlternateDataStreams: C:\Users\Owner\Downloads\nbr2player.msi:$CmdZnID [26]
          Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3707217111-3059912600-4169917813-1000.job => C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\58 08\g2mupdate.exe
          Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-3707217111-3059912600-4169917813-1000.job => C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\58 08\g2mupload.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
          Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
          Task: {E72EC86B-3D23-4084-BDD8-881206C004F4} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [2014-05-30] (TechSmith Corporation)
          Task: {E76D5133-5A44-4F50-BE32-F47E52A983BA} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2016-10-25]
          Task: {D0BEEEBF-CD17-4AE2-A56B-EB783685BEC7} - System32\Tasks\G2MUploadTask-S-1-5-21-3707217111-3059912600-4169917813-1000 => C:\Users\Owner\AppData\Local\Citrix\GoToMeeting\58 08\g2mupload.exe [2016-11-01] (Citrix Online, a division of Citrix Systems, Inc.)
          Task: {DBECA225-BEA2-4E24-824D-407830BC8221} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
          Task: {E72EC86B-3D23-4084-BDD8-881206C004F4} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [2014-05-30] (TechSmith Corporation)
          Task: {DBECA225-BEA2-4E24-824D-407830BC8221} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-10-25] (NVIDIA Corporation)
          Task: {C32994E5-1867-4194-ADB3-B2BEAD9904EB} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-10-25] (NVIDIA Corporation)
          Task: {7ED220D2-3F34-41E5-A3D0-1F5E1A517E5E} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-10-25] (NVIDIA Corporation)
          Task: {627D4F51-9196-43DF-A04D-B872C8B6DEFF} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-10-25] (NVIDIA Corporation)
          2014-03-02 23:54 - 2014-03-02 23:54 - 0000017 _____ () C:\Users\Owner\AppData\Local\resmon.resmoncfg
          2014-02-10 12:17 - 2014-02-10 12:17 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
          C:\Program Files\COMODO
          C:\Users\Owner\AppData\Local\ESET
          C:\Users\Owner\AppData\Local\F-Secure
          C:\Users\Owner\Desktop\esetonlinescanner_enu.exe
          C:\ProgramData\Kaspersky Lab Setup Files
          C:\Program Files (x86)\stinger
          C:\Users\Owner\Desktop\PandaCloudCleaner
          C:\Users\Owner\Desktop\tdsskiller.exe
          C:\ProgramData\Loaris
          S3 vdbus; system32\DRIVERS\vdbus.sys
          CHR StartupUrls: Default → “hxxps://www.startpage.com/”
          FF Plugin-x32: @tools.google.com/Google Update;version=3 → C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-11-15] (Google Inc.)
          FF Plugin-x32: @tools.google.com/Google Update;version=9 → C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-11-15] (Google Inc.)
          C:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLog ger\AutoLogger-Diagtrack-Listener.etl
          C:\ProgramData\Microsoft\Diagnosis\ETLLogs\Shutdow nLogger\AutoLogger-Diagtrack-Listener.etl
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18683_none_e82 2d0c3e5b060cb\diagtrack.dll
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18742_none_e84 d120fe590d4d7\diagtrack.dll
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23412_none_e8f 7003efe9645d3\diagtrack.dll
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad\diagtrack.dll
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01\diagtrack.dll
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149\diagtrack.dll
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d\diagtrack.dll
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18683_none_e82 2d0c3e5b060cb\diagtrackrunner.exe
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18742_none_e84 d120fe590d4d7\diagtrackrunner.exe
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23412_none_e8f 7003efe9645d3\diagtrackrunner.exe
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18444_none_e5b 1b7ec100d8e3b
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18467_none_e59 f18f2101b1222
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18503_none_e5d bf9380fee0247
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18551_none_e5a 3e90810185b4e
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18653_none_e5a 5eb8210168b23
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18683_none_e58 57bbe102edef6
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18742_none_e5a fbd0a100f5302
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.23412_none_e65 9ab392914c3fe
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18444_none_66295be4 60b59c2a
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18467_none_6616bcea 60c32011
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18503_none_66539d30 60961036
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18653_none_661d8f7a 60be9912
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18683_none_65fd1fb6 60d6ece5
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18742_none_66276102 60b760f1
          C:\Windows\winsxs\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d
          C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry
          C:\Program Files\NVIDIA Corporation\NvTelemetry
          C:\ProgramData\NVIDIA Corporation\Downloader\latest\NvTelemetry
          C:\Users\Owner\AppData\Local\NVIDIA Corporation\NvTelemetry
          C:\Program Files\NVIDIA Corporation\Installer2\NvTelemetry.{3DEE5278-D392-4EA2-96F0-D35F55F48AB4}
          C:\ProgramData\Microsoft\Microsoft Antimalware\Telemetry
          C:\Users\Owner\AppData\Roaming\Microsoft\Microsoft Security Client\Telemetry
          C:\Windows\AppCompat\Appraiser\Telemetry
          C:\Windows\System32\config\systemprofile\AppData\R oaming\Microsoft\Microsoft Security Client\Telemetry
          C:\Windows\winsxs\FileMaps$$_appcompat_appraiser_t elemetry_94274e99519f58a9.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\092ebd43d03d d201c10b000078078407.$$_appcompat_appraiser_teleme try_94274e99519f58a9.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\8132cd16073e d201c10b00009c07a807.$$_appcompat_appraiser_teleme try_94274e99519f58a9.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\88a47eaed43d d201c10b0000f407a002.$$_appcompat_appraiser_teleme try_94274e99519f58a9.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\a3b5830cbd3d d201c10b0000a407b007.$$_appcompat_appraiser_teleme try_94274e99519f58a9.cdf-ms
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18444_none_e5b 1b7ec100d8e3b.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18467_none_e59 f18f2101b1222.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18503_none_e5d bf9380fee0247.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18551_none_e5a 3e90810185b4e.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18653_none_e5a 5eb8210168b23.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18683_none_e58 57bbe102edef6.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18742_none_e5a fbd0a100f5302.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.23412_none_e65 9ab392914c3fe.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18444_none_66295be4 60b59c2a.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18467_none_6616bcea 60c32011.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18503_none_66539d30 60961036.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18551_none_661b8d00 60c0693d.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18653_none_661d8f7a 60be9912.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18683_none_65fd1fb6 60d6ece5.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18742_none_66276102 60b760f1.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.23412_none_66d14f31 79bcd1ed.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d.manifest
          C:\Windows\AppCompat\Appraiser\APPRAISER_Telemetry Baseline.bin
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-inventory.data_31bf3856ad364e35_6.1.7601.23412_non e_b7bb39c6464eeaab\Appraiser_TelemetryRunList.xml
          C:\Windows\winsxs\Temp\PendingRenames\b48ea09bbe3d d201c10b0000d8048807.$$_appcompat_appraiser_teleme try_94274e99519f58a9.cdf-ms
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23412_none_e8f 7003efe9645d3\CompatTelemetry.inf
          C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx
          C:\ProgramData\Microsoft\Microsoft Antimalware\Telemetry\MpTelemetry-301-0.sqm
          C:\ProgramData\Microsoft\Microsoft Antimalware\Telemetry\MpTelemetry-302-0.sqm
          C:\ProgramData\Microsoft\Microsoft Antimalware\Telemetry\MpTelemetry-303-0.sqm
          C:\ProgramData\Microsoft\Microsoft Antimalware\Telemetry\MpTelemetry-304-0.sqm
          C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User\NvTelemetry.d ll
          C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NvTelemetry.d ll
          C:\ProgramData\NVIDIA Corporation\Downloader\latest\NVI2\NvTelemetry.dll
          C:\ProgramData\NVIDIA Corporation\Downloader\latest\NvTelemetry\NvTeleme try.dll
          C:\Users\Owner\AppData\Local\NVIDIA Corporation\NvTelemetry\nvtelemetry.log
          C:\Users\Owner\AppData\Local\NVIDIA Corporation\NvTelemetry\nvtelemetry.log.bak
          C:\Program Files\NVIDIA Corporation\Installer2\NvTelemetry.{3DEE5278-D392-4EA2-96F0-D35F55F48AB4}\NvTelemetry.nvi
          C:\ProgramData\NVIDIA Corporation\Downloader\latest\NvTelemetry\NvTeleme try.nvi
          C:\Program Files\NVIDIA Corporation\Installer2\NvTelemetry.{3DEE5278-D392-4EA2-96F0-D35F55F48AB4}\NvTelemetry.NVX
          C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvTelemetryAPI.js
          C:\ProgramData\NVIDIA Corporation\Downloader\latest\nodejs\NvTelemetryAP I.js
          C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryAPI32.dll
          C:\ProgramData\NVIDIA Corporation\Downloader\latest\NvTelemetry\NvTeleme tryAPI32.dll
          C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryAPI64.dll
          C:\ProgramData\NVIDIA Corporation\Downloader\latest\NvTelemetry\NvTeleme tryAPI64.dll
          C:\ProgramData\Microsoft\Diagnosis\DownloadedSetti ngs\telemetry.ASM-WindowsDefault.json
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad\telemetry.ASM-WindowsDefault.json
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01\telemetry.ASM-WindowsDefault.json
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149\telemetry.ASM-WindowsDefault.json
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d\telemetry.ASM-WindowsDefault.json
          C:\ProgramData\Microsoft\Diagnosis\DownloadedSetti ngs\telemetry.ASM-WindowsDefault.json.bk
          C:\Program Files (x86)\Microsoft Office\Office15\1033\TelemetryDashboard.xltx
          C:\Program Files (x86)\Microsoft Office\Office15\1033\TelemetryLog.xltx
          C:\Users\Owner\AppData\Local\GWX\TelemetryStore.xm l
          C:\Users\Owner\AppData\Local\GWX\TelemetryStore.xm l.lock
          C:\Windows\winsxs\amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23396_none_ba1ea7c6 f4920e24
          C:\Windows\winsxs\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23396_none_0b8 d69aa2b6cdb3f
          C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036
          C:\Users\Owner\AppData\Local\GWX
          C:\Windows\Logs\Gwx
          C:\Program Files (x86)\UltimateOutsider\GWX Control Panel
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GWX Control Panel
          D:.Corsair.Software_Downloads\Utilities\GWX.Win.10 .Control.Panel_ver1741
          C:\Windows\winsxs\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_1927edd0b a9ec231
          C:\Windows\winsxs\FileMaps$$_system32_gwx_06654c71 d047de88.cdf-ms
          C:\Windows\winsxs\FileMaps$$_system32_gwx_download _27d68082ad334184.cdf-ms
          C:\Windows\winsxs\FileMaps$$_system32_gwx_download swap_5098c1f0e1204caf.cdf-ms
          C:\Windows\winsxs\FileMaps$$_syswow64_gwx_1bf23be3 a76673bc.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\01b7a421073e d201ee1200009c07a807.$$_system32_gwx_download_27d6 8082ad334184.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\01b7a421073e d201ef1200009c07a807.$$_system32_gwx_downloadswap_ 5098c1f0e1204caf.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\1213d599d03d d2013141000078078407.$$_syswow64_gwx_1bf23be3a7667 3bc.cdf-ms
          D:.Corsair.Software_Downloads\0AV.Alerts.Popups\20 16.05.04_GWXUX.popup.JPG
          C:\Windows\winsxs\Temp\PendingRenames\22605a9ad03d d2013c41000078078407.$$_system32_gwx_downloadswap_ 5098c1f0e1204caf.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\243737b9d43d d201ed120000f407a002.$$_system32_gwx_06654c71d047d e88.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\243737b9d43d d201ee120000f407a002.$$_system32_gwx_download_27d6 8082ad334184.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\243737b9d43d d201ef120000f407a002.$$_system32_gwx_downloadswap_ 5098c1f0e1204caf.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\6478674ed03d d201e912000078078407.$$_system32_gwx_06654c71d047d e88.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\7c7a2417bd3d d201e9120000a407b007.$$_system32_gwx_06654c71d047d e88.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\9398de99d03d d2013341000078078407.$$_system32_gwx_06654c71d047d e88.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\a055a221073e d201ed1200009c07a807.$$_system32_gwx_06654c71d047d e88.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\a1c7c079d03d d201aa2e000078078407.$$_syswow64_gwx_1bf23be3a7667 3bc.cdf-ms
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-ins_31bf3856ad364e35_6.1.7601.23396_none_a8be71bc8 1a2397b.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23396_none_ba1ea7c6 f4920e24.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23396_none_0b8 d69aa2b6cdb3f.manifest
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036.manifest
          C:\Windows\winsxs\Temp\PendingRenames\c1fe579ad03d d2013b41000078078407.$$_system32_gwx_download_27d6 8082ad334184.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\c6e47c4ed03d d201ee12000078078407.$$_system32_gwx_download_27d6 8082ad334184.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\c6e47c4ed03d d201ef12000078078407.$$_system32_gwx_downloadswap_ 5098c1f0e1204caf.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\d5f9c54d073e d201a72e00009c07a807.$$_syswow64_gwx_1bf23be3a7667 3bc.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\dee63917bd3d d201ee120000a407b007.$$_system32_gwx_download_27d6 8082ad334184.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\dee63917bd3d d201ef120000a407b007.$$_system32_gwx_downloadswap_ 5098c1f0e1204caf.cdf-ms
          C:\Windows\winsxs\Temp\PendingRenames\fc0e68e4d43d d201a02e0000f407a002.$$_syswow64_gwx_1bf23be3a7667 3bc.cdf-ms
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GWX Control Panel\GWX Control Panel User Guide.lnk
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GWX Control Panel\GWX Control Panel.lnk
          C:\Users\Public\Desktop\GWX Control Panel.lnk
          C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWX.exe
          C:\Windows\winsxs\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_1927edd0b a9ec231\GWX.exe
          D:.Corsair.Software_Downloads\Utilities\GWX.Win.10 .Control.Panel_ver1741\GWX.post.fix.Results.Asus.C orsair.JPG
          D:.Corsair.Software_Downloads\Utilities\GWX.Win.10 .Control.Panel_ver1741\GWX.Results.Asus.Corsair.JP G
          C:\Program Files (x86)\UltimateOutsider\GWX Control Panel\GWX_control_panel.exe
          C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXConfigManager.exe
          D:.Corsair.Software_Downloads\Utilities\GWX.Win.10 .Control.Panel_ver1741\GwxControlPanelLog.txt
          D:.Corsair.Software_Downloads\Utilities\GWX.Win.10 .Control.Panel_ver1741\GwxControlPanelSetup.exe
          C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXDetector.exe
          C:\Windows\winsxs\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23396_none_0b8 d69aa2b6cdb3f\GWXGC.exe
          C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXMig.inf
          C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXUI.dll
          C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXUX.exe
          C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXUXWorker.exe
          C:\Windows\System32\winevt\Logs\Microsoft-Windows-GWX-Ins%4Operational.evtx
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GWX Control Panel\Uninstall GWX Control Panel.lnk
          C:\Windows\winsxs\Manifests\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_1927edd0b a9ec231.manifest
          CMD: ipconfig /flushdns
          Emptytemp:
          reboot:
          end


          Restore point was successfully created.
          Processes closed successfully.
          C:\Windows\system32\aitstatic.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\audiodg.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\AudioEng.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\AUDIOKSE.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\AudioSes.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\audiosrv.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\blackbox.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\charmap.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\ci.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\cryptsp.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\cryptui.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\dfshim.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\drmmgrtn.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\drmv2clt.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\EncDump.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\icardagt.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\icardres.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\IMJP10K.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\infocardapi.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\KBDBASH.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\KBDRU.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\KBDRU1.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\KBDTAT.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\KBDYAK.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\mscorier.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\mscories.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\msctf.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\msnetobj.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\msscp.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\mstsc.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\nlasvc.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\nvdispco6434725.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\nvdispco6434752.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\nvdispgenco6434725.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\nvdispgenco6434752.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\packager.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\pcadm.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\pcaevts.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\pcalua.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\pcasvc.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\pcawrk.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\perftrack.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\pku2u.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\powertracker.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\profsvc.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\rastls.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\rdpcorekmts.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\scesrv.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\termsrv.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\TSWbPrxy.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\TSWorkspace.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\TsWpfWrp.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\ubpm.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\wdi.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\winlogon.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\winsta.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\wmdrmsdk.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\WMPhoto.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\WSManHTTPConfig.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\WSManMigrationPlugin.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\WsmAuto.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\WsmSvc.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\WsmWmiPl.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\AudioEng.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\AUDIOKSE.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\AudioSes.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\blackbox.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\charmap.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\cryptsp.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\cryptui.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\dfshim.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\drmmgrtn.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\drmv2clt.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\icardagt.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\icardres.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\IMJP10K.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\infocardapi.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\java.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\javaw.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\javaws.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\KBDBASH.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\KBDRU.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\KBDRU1.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\KBDTAT.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\KBDYAK.DLL => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\mscorier.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\mscories.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\msctf.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\msnetobj.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\msscp.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\mstsc.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\ncsi.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\nlaapi.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\packager.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\pku2u.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\rastls.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\scesrv.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\TSWorkspace.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\TsWpfWrp.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\ubpm.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\wdi.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\winsta.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\wmdrmsdk.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\WMPhoto.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\WSManHTTPConfig.exe => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\WSManMigrationPlugin.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\WsmAuto.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\WsmSvc.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\SysWOW64\WsmWmiPl.dll => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\Drivers\PEAuth.sys => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\Drivers\rdpwd.sys => “:$CmdTcID” ADS removed successfully.
          C:\Windows\system32\Drivers\tssecsrv.sys => “:$CmdTcID” ADS removed successfully.
          C:\Users\Owner\Desktop\fxddmalta4setup_build610.ex e => “:$CmdTcID” ADS removed successfully.
          C:\Users\Owner\Downloads\nbr2player.msi => “:$CmdZnID” ADS removed successfully.
          C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-3707217111-3059912600-4169917813-1000.job => moved successfully
          C:\Windows\Tasks\G2MUploadTask-S-1-5-21-3707217111-3059912600-4169917813-1000.job => moved successfully
          C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
          C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{E72EC86 B-3D23-4084-BDD8-881206C004F4}” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{E72EC86 B-3D23-4084-BDD8-881206C004F4}” => key removed successfully
          C:\Windows\System32\Tasks\TechSmith Updater => moved successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TechSmit h Updater” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{E76D513 3-5A44-4F50-BE32-F47E52A983BA}” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{E76D513 3-5A44-4F50-BE32-F47E52A983BA}” => key removed successfully
          C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => moved successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NvNodeLa uncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{D0BEEEB F-CD17-4AE2-A56B-EB783685BEC7}” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{D0BEEEB F-CD17-4AE2-A56B-EB783685BEC7}” => key removed successfully
          C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-3707217111-3059912600-4169917813-1000 => moved successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\G2MUploa dTask-S-1-5-21-3707217111-3059912600-4169917813-1000” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{DBECA22 5-BEA2-4E24-824D-407830BC8221}” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{DBECA22 5-BEA2-4E24-824D-407830BC8221}” => key removed successfully
          C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B 2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => moved successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NvProfil eUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}” => key removed successfully
          HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{E72EC86 B-3D23-4084-BDD8-881206C004F4} => key not found.
          C:\Windows\System32\Tasks\TechSmith Updater => not found.
          HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TechSmit h Updater => key not found.
          HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{DBECA22 5-BEA2-4E24-824D-407830BC8221} => key not found.
          C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B 2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => not found.
          HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NvProfil eUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => key not found.
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{C32994E 5-1867-4194-ADB3-B2BEAD9904EB}” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{C32994E 5-1867-4194-ADB3-B2BEAD9904EB}” => key removed successfully
          C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_ {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => moved successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NvProfil eUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{7ED220D 2-3F34-41E5-A3D0-1F5E1A517E5E}” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{7ED220D 2-3F34-41E5-A3D0-1F5E1A517E5E}” => key removed successfully
          C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => moved successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NvTmRepO nLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon{627D4F5 1-9196-43DF-A04D-B872C8B6DEFF}” => key removed successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{627D4F5 1-9196-43DF-A04D-B872C8B6DEFF}” => key removed successfully
          C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => moved successfully
          “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NvTmMon_ {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}” => key removed successfully
          C:\Users\Owner\AppData\Local\resmon.resmoncfg => moved successfully
          C:\ProgramData\DP45977C.lfl => moved successfully
          C:\Program Files\COMODO => moved successfully
          C:\Users\Owner\AppData\Local\ESET => moved successfully
          C:\Users\Owner\AppData\Local\F-Secure => moved successfully
          C:\Users\Owner\Desktop\esetonlinescanner_enu.exe => moved successfully
          C:\ProgramData\Kaspersky Lab Setup Files => moved successfully
          C:\Program Files (x86)\stinger => moved successfully
          C:\Users\Owner\Desktop\PandaCloudCleaner => moved successfully
          C:\Users\Owner\Desktop\tdsskiller.exe => moved successfully
          C:\ProgramData\Loaris => moved successfully
          vdbus => service removed successfully
          Chrome StartupUrls => removed successfully
          “HKLM\Software\Wow6432Node\MozillaPlugins@tools.google.com/Google Update;version=3” => key removed successfully
          C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll => moved successfully
          “HKLM\Software\Wow6432Node\MozillaPlugins@tools.google.com/Google Update;version=9” => key removed successfully
          C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll => not found.
          C:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLog ger\AutoLogger-Diagtrack-Listener.etl => moved successfully
          “C:\ProgramData\Microsoft\Diagnosis\ETLLogs\Shutdo wnLogger\AutoLogger-Diagtrack-Listener.etl” => not found.
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18683_none_e82 2d0c3e5b060cb\diagtrack.dll => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18742_none_e84 d120fe590d4d7\diagtrack.dll => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23412_none_e8f 7003efe9645d3\diagtrack.dll => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad\diagtrack.dll => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01\diagtrack.dll => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149\diagtrack.dll => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d\diagtrack.dll => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18683_none_e82 2d0c3e5b060cb\diagtrackrunner.exe => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.18742_none_e84 d120fe590d4d7\diagtrackrunner.exe => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23412_none_e8f 7003efe9645d3\diagtrackrunner.exe => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18444_none_e5b 1b7ec100d8e3b => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18467_none_e59 f18f2101b1222 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18503_none_e5d bf9380fee0247 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18551_none_e5a 3e90810185b4e => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18653_none_e5a 5eb8210168b23 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18683_none_e58 57bbe102edef6 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18742_none_e5a fbd0a100f5302 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.23412_none_e65 9ab392914c3fe => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18444_none_66295be4 60b59c2a => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18467_none_6616bcea 60c32011 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18503_none_66539d30 60961036 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18653_none_661d8f7a 60be9912 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18683_none_65fd1fb6 60d6ece5 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18742_none_66276102 60b760f1 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d => moved successfully
          C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry => moved successfully
          C:\Program Files\NVIDIA Corporation\NvTelemetry => moved successfully
          C:\ProgramData\NVIDIA Corporation\Downloader\latest\NvTelemetry => moved successfully
          C:\Users\Owner\AppData\Local\NVIDIA Corporation\NvTelemetry => moved successfully
          C:\Program Files\NVIDIA Corporation\Installer2\NvTelemetry.{3DEE5278-D392-4EA2-96F0-D35F55F48AB4} => moved successfully
          C:\ProgramData\Microsoft\Microsoft Antimalware\Telemetry => moved successfully
          C:\Users\Owner\AppData\Roaming\Microsoft\Microsoft Security Client\Telemetry => moved successfully
          C:\Windows\AppCompat\Appraiser\Telemetry => moved successfully
          C:\Windows\System32\config\systemprofile\AppData\R oaming\Microsoft\Microsoft Security Client\Telemetry => moved successfully
          C:\Windows\winsxs\FileMaps$$_appcompat_appraiser_t elemetry_94274e99519f58a9.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\092ebd43d03d d201c10b000078078407.$$_appcompat_appraiser_teleme try_94274e99519f58a9.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\8132cd16073e d201c10b00009c07a807.$$_appcompat_appraiser_teleme try_94274e99519f58a9.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\88a47eaed43d d201c10b0000f407a002.$$_appcompat_appraiser_teleme try_94274e99519f58a9.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\a3b5830cbd3d d201c10b0000a407b007.$$_appcompat_appraiser_teleme try_94274e99519f58a9.cdf-ms => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18444_none_e5b 1b7ec100d8e3b.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18467_none_e59 f18f2101b1222.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18503_none_e5d bf9380fee0247.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18551_none_e5a 3e90810185b4e.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18653_none_e5a 5eb8210168b23.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18683_none_e58 57bbe102edef6.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.18742_none_e5a fbd0a100f5302.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..de-compat-telemetry_31bf3856ad364e35_6.1.7601.23412_none_e65 9ab392914c3fe.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18444_none_66295be4 60b59c2a.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18467_none_6616bcea 60c32011.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18503_none_66539d30 60961036.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18551_none_661b8d00 60c0693d.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18653_none_661d8f7a 60be9912.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18683_none_65fd1fb6 60d6ece5.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.18742_none_66276102 60b760f1.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ence-telemetry-sdbs_31bf3856ad364e35_6.1.7601.23412_none_66d14f31 79bcd1ed.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-a..ion-telemetry-agent_31bf3856ad364e35_6.1.7601.17514_none_3092574 c7d41010b.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d.manifest => moved successfully
          C:\Windows\AppCompat\Appraiser\APPRAISER_Telemetry Baseline.bin => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..ence-inventory.data_31bf3856ad364e35_6.1.7601.23412_non e_b7bb39c6464eeaab\Appraiser_TelemetryRunList.xml => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\b48ea09bbe3d d201c10b0000d8048807.$$_appcompat_appraiser_teleme try_94274e99519f58a9.cdf-ms => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-a..xperience-inventory_31bf3856ad364e35_6.1.7601.23412_none_e8f 7003efe9645d3\CompatTelemetry.inf => moved successfully
          Could not move “C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx” => Scheduled to move on reboot.
          “C:\ProgramData\Microsoft\Microsoft Antimalware\Telemetry\MpTelemetry-301-0.sqm” => not found.
          “C:\ProgramData\Microsoft\Microsoft Antimalware\Telemetry\MpTelemetry-302-0.sqm” => not found.
          “C:\ProgramData\Microsoft\Microsoft Antimalware\Telemetry\MpTelemetry-303-0.sqm” => not found.
          “C:\ProgramData\Microsoft\Microsoft Antimalware\Telemetry\MpTelemetry-304-0.sqm” => not found.
          C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User\NvTelemetry.d ll => moved successfully
          C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NvTelemetry.d ll => moved successfully
          C:\ProgramData\NVIDIA Corporation\Downloader\latest\NVI2\NvTelemetry.dll => moved successfully
          “C:\ProgramData\NVIDIA Corporation\Downloader\latest\NvTelemetry\NvTeleme try.dll” => not found.
          “C:\Users\Owner\AppData\Local\NVIDIA Corporation\NvTelemetry\nvtelemetry.log” => not found.
          “C:\Users\Owner\AppData\Local\NVIDIA Corporation\NvTelemetry\nvtelemetry.log.bak” => not found.
          “C:\Program Files\NVIDIA Corporation\Installer2\NvTelemetry.{3DEE5278-D392-4EA2-96F0-D35F55F48AB4}\NvTelemetry.nvi” => not found.
          “C:\ProgramData\NVIDIA Corporation\Downloader\latest\NvTelemetry\NvTeleme try.nvi” => not found.
          “C:\Program Files\NVIDIA Corporation\Installer2\NvTelemetry.{3DEE5278-D392-4EA2-96F0-D35F55F48AB4}\NvTelemetry.NVX” => not found.
          C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvTelemetryAPI.js => moved successfully
          C:\ProgramData\NVIDIA Corporation\Downloader\latest\nodejs\NvTelemetryAP I.js => moved successfully
          “C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryAPI32.dll” => not found.
          “C:\ProgramData\NVIDIA Corporation\Downloader\latest\NvTelemetry\NvTeleme tryAPI32.dll” => not found.
          “C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryAPI64.dll” => not found.
          “C:\ProgramData\NVIDIA Corporation\Downloader\latest\NvTelemetry\NvTeleme tryAPI64.dll” => not found.
          C:\ProgramData\Microsoft\Diagnosis\DownloadedSetti ngs\telemetry.ASM-WindowsDefault.json => moved successfully
          “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18869_none_fde7d5 f71db043ad\telemetry.ASM-WindowsDefault.json” => not found.
          “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.18939_none_fe0847 a11d97ed01\telemetry.ASM-WindowsDefault.json” => not found.
          “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23072_none_fe5f78 f236dc8149\telemetry.ASM-WindowsDefault.json” => not found.
          “C:\Windows\winsxs\amd64_microsoft-windows-u..ed-telemetry-client_31bf3856ad364e35_6.1.7601.23142_none_fe7fea 9c36c42a9d\telemetry.ASM-WindowsDefault.json” => not found.
          C:\ProgramData\Microsoft\Diagnosis\DownloadedSetti ngs\telemetry.ASM-WindowsDefault.json.bk => moved successfully
          C:\Program Files (x86)\Microsoft Office\Office15\1033\TelemetryDashboard.xltx => moved successfully
          C:\Program Files (x86)\Microsoft Office\Office15\1033\TelemetryLog.xltx => moved successfully
          C:\Users\Owner\AppData\Local\GWX\TelemetryStore.xm l => moved successfully
          C:\Users\Owner\AppData\Local\GWX\TelemetryStore.xm l.lock => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23396_none_ba1ea7c6 f4920e24 => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23396_none_0b8 d69aa2b6cdb3f => moved successfully
          C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036 => moved successfully
          C:\Users\Owner\AppData\Local\GWX => moved successfully
          C:\Windows\Logs\Gwx => moved successfully
          C:\Program Files (x86)\UltimateOutsider\GWX Control Panel => moved successfully
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GWX Control Panel => moved successfully
          D:.Corsair.Software_Downloads\Utilities\GWX.Win.10 .Control.Panel_ver1741 => moved successfully
          C:\Windows\winsxs\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_1927edd0b a9ec231 => moved successfully
          C:\Windows\winsxs\FileMaps$$_system32_gwx_06654c71 d047de88.cdf-ms => moved successfully
          C:\Windows\winsxs\FileMaps$$_system32_gwx_download _27d68082ad334184.cdf-ms => moved successfully
          C:\Windows\winsxs\FileMaps$$_system32_gwx_download swap_5098c1f0e1204caf.cdf-ms => moved successfully
          C:\Windows\winsxs\FileMaps$$_syswow64_gwx_1bf23be3 a76673bc.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\01b7a421073e d201ee1200009c07a807.$$_system32_gwx_download_27d6 8082ad334184.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\01b7a421073e d201ef1200009c07a807.$$_system32_gwx_downloadswap_ 5098c1f0e1204caf.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\1213d599d03d d2013141000078078407.$$_syswow64_gwx_1bf23be3a7667 3bc.cdf-ms => moved successfully
          D:.Corsair.Software_Downloads\0AV.Alerts.Popups\20 16.05.04_GWXUX.popup.JPG => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\22605a9ad03d d2013c41000078078407.$$_system32_gwx_downloadswap_ 5098c1f0e1204caf.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\243737b9d43d d201ed120000f407a002.$$_system32_gwx_06654c71d047d e88.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\243737b9d43d d201ee120000f407a002.$$_system32_gwx_download_27d6 8082ad334184.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\243737b9d43d d201ef120000f407a002.$$_system32_gwx_downloadswap_ 5098c1f0e1204caf.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\6478674ed03d d201e912000078078407.$$_system32_gwx_06654c71d047d e88.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\7c7a2417bd3d d201e9120000a407b007.$$_system32_gwx_06654c71d047d e88.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\9398de99d03d d2013341000078078407.$$_system32_gwx_06654c71d047d e88.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\a055a221073e d201ed1200009c07a807.$$_system32_gwx_06654c71d047d e88.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\a1c7c079d03d d201aa2e000078078407.$$_syswow64_gwx_1bf23be3a7667 3bc.cdf-ms => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-ins_31bf3856ad364e35_6.1.7601.23396_none_a8be71bc8 1a2397b.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-task_31bf3856ad364e35_6.1.7601.23396_none_ba1ea7c6 f4920e24.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23396_none_0b8 d69aa2b6cdb3f.manifest => moved successfully
          C:\Windows\winsxs\Manifests\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036.manifest => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\c1fe579ad03d d2013b41000078078407.$$_system32_gwx_download_27d6 8082ad334184.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\c6e47c4ed03d d201ee12000078078407.$$_system32_gwx_download_27d6 8082ad334184.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\c6e47c4ed03d d201ef12000078078407.$$_system32_gwx_downloadswap_ 5098c1f0e1204caf.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\d5f9c54d073e d201a72e00009c07a807.$$_syswow64_gwx_1bf23be3a7667 3bc.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\dee63917bd3d d201ee120000a407b007.$$_system32_gwx_download_27d6 8082ad334184.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\dee63917bd3d d201ef120000a407b007.$$_system32_gwx_downloadswap_ 5098c1f0e1204caf.cdf-ms => moved successfully
          C:\Windows\winsxs\Temp\PendingRenames\fc0e68e4d43d d201a02e0000f407a002.$$_syswow64_gwx_1bf23be3a7667 3bc.cdf-ms => moved successfully
          “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GWX Control Panel\GWX Control Panel User Guide.lnk” => not found.
          “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GWX Control Panel\GWX Control Panel.lnk” => not found.
          C:\Users\Public\Desktop\GWX Control Panel.lnk => moved successfully
          “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWX.exe” => not found.
          “C:\Windows\winsxs\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_1927edd0b a9ec231\GWX.exe” => not found.
          “D:.Corsair.Software_Downloads\Utilities\GWX.Win.1 0.Control.Panel_ver1741\GWX.post.fix.Results.Asus. Corsair.JPG” => not found.
          “D:.Corsair.Software_Downloads\Utilities\GWX.Win.1 0.Control.Panel_ver1741\GWX.Results.Asus.Corsair.J PG” => not found.
          “C:\Program Files (x86)\UltimateOutsider\GWX Control Panel\GWX_control_panel.exe” => not found.
          “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXConfigManager.exe” => not found.
          “D:.Corsair.Software_Downloads\Utilities\GWX.Win.1 0.Control.Panel_ver1741\GwxControlPanelLog.txt” => not found.
          “D:.Corsair.Software_Downloads\Utilities\GWX.Win.1 0.Control.Panel_ver1741\GwxControlPanelSetup.exe” => not found.
          “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXDetector.exe” => not found.
          “C:\Windows\winsxs\amd64_microsoft-windows-gwx-uninstall_31bf3856ad364e35_6.1.7601.23396_none_0b8 d69aa2b6cdb3f\GWXGC.exe” => not found.
          “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXMig.inf” => not found.
          “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXUI.dll” => not found.
          “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXUX.exe” => not found.
          “C:\Windows\winsxs\amd64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_0ed3437e8 63e0036\GWXUXWorker.exe” => not found.
          C:\Windows\System32\winevt\Logs\Microsoft-Windows-GWX-Ins%4Operational.evtx => moved successfully
          “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GWX Control Panel\Uninstall GWX Control Panel.lnk” => not found.
          C:\Windows\winsxs\Manifests\wow64_microsoft-windows-gwx_31bf3856ad364e35_6.1.7601.23396_none_1927edd0b a9ec231.manifest => moved successfully

          ========= ipconfig /flushdns =========

          Windows IP Configuration

          Successfully flushed the DNS Resolver Cache.

          ========= End of CMD: =========

          =========== EmptyTemp: ==========

          BITS transfer queue => 0 B
          DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 13431677 B
          Java, Flash, Steam htmlcache => 0 B
          Windows/system/drivers => 335808 B
          Edge => 0 B
          Chrome => 12830591 B
          Firefox => 3684294 B
          Opera => 221184 B

          Temp, IE cache, history, cookies, recent:
          Default => 0 B
          Public => 0 B
          ProgramData => 0 B
          systemprofile => 128 B
          systemprofile32 => 128 B
          LocalService => 0 B
          NetworkService => 0 B
          Owner => 5192096 B

          RecycleBin => 0 B
          EmptyTemp: => 34 MB temporary data Removed.

          ================================

          Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 20-11-2016 20:42:58)

          “C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx” => Could not move

          ==== End of Fixlog 20:42:58 ====

          Comment

          • Malnutrition
            PCHF Moderator
            • Jul 2016
            • 7041

            #20
            Originally posted by paulwb
            I initially installed it to block Windows 10 software upgrade prompts
            Might be a good idea to re-install that. I did not sort the GWX stuff from your machine I just put it up for removal. What issues remain?

            Comment

            • paulwb
              PCHF Member
              • Nov 2016
              • 159

              #21
              OK, will reinstall GWX Control Panel.

              What issues remain?
              Just what was mentioned earlier …
              1. What about the VulkanRT file that shows up as a BrowserModifier? Should it be deleted?
              2. Windows Updates stall during download
              3. I noticed just now that my total RAM is 14, and should be 16.

              https://pchelpforum.net/attachments/upload_2016-11-19_0-32-22-png.836/

              Comment

              • Malnutrition
                PCHF Moderator
                • Jul 2016
                • 7041

                #22
                Originally posted by paulwb
                1. What about the VulkanRT file that shows up as a BrowserModifier? Should it be deleted?
                It is a false positive, it is your choice to remove it or not. You posted links about the issue, it is your choice to remove it or not. From a malware stance it is not malware, so choice is yours.
                Originally posted by paulwb
                1. Windows Updates stall during download
                How often does this happen? For what updates? I would not worry about it unless they are security updates. I also do not think it is a good idea to go and try fixing something unless it is happening 100% of the time… Have you tried updates since the machine has been cleaned?
                Originally posted by paulwb
                1. I noticed just now that my total RAM is 14, and should be 16.
                Should have a look here at this link.

                Comment

                • paulwb
                  PCHF Member
                  • Nov 2016
                  • 159

                  #23
                  RE:
                  2. Since Sept 2016, the only Windows updates I’m able to run are Win Defender and Malicious Software Removal tool.

                  [ATTACH]856[/ATTACH]

                  [ATTACH]857[/ATTACH]
                  1. Last checked RAM was 16GB in July 2016. I’ll check out your link.
                    [ATTACH]858[/ATTACH]

                  Comment

                  • Malnutrition
                    PCHF Moderator
                    • Jul 2016
                    • 7041

                    #24
                    Ok, lets do this to see if we can get things going…

                    install (use the direct download) the Tweaking.com - Windows all in one repair tool. Then boot Windows into Safe Mode, (Make Certain To Run This Program As Administrator) then run through the Prescan on step 2 tab. Then skip to step 5 and create a system restore point. Then go to the repair tab…

                    Notice create a registry backup is ticked by default, so no need to do so in step 5…[ATTACH]859[/ATTACH]

                    Now run the program, with the boxes ticked in the picture below.

                    Click Image Below For Better Resolution.

                    [ATTACH]860[/ATTACH]

                    May want to save picture or write down what boxes need ticked, since you will run this in Safe Mode.

                    Important: Make certain to reboot twice after running this tool!!

                    Comment

                    • paulwb
                      PCHF Member
                      • Nov 2016
                      • 159

                      #25
                      All done.
                      Windows Update now shows no updates, and stalls when Checking for updates.
                      Maybe run it again?
                      The hard drive indicator light is quite active, constantly flickering…

                      Comment

                      • Malnutrition
                        PCHF Moderator
                        • Jul 2016
                        • 7041

                        #26
                        Originally posted by paulwb
                        Windows Update now shows no updates, and stalls when Checking for updates.
                        Maybe run it again?
                        Yes after a few reboots of the machine, check again.
                        Originally posted by paulwb
                        The hard drive indicator light is quite active, constantly flickering…
                        Some report HDD activity after running the all in one tool, just use the machine a bit normally, after a few reboots things go back to normal. Also, after a couple of reboots clean it up with Privazer and then defrag the machine.

                        If you continue to have issues with updates, then might be a good idea to create a new thread in the windows area, as updates are really not my thing.

                        Comment

                        • paulwb
                          PCHF Member
                          • Nov 2016
                          • 159

                          #27
                          OK, thank you.
                          Also, would you suggest using patchmypc on this machine?
                          I know this isn’t your area but would you know of the right tool to uninstall MS Office. I need to do a reinstall.
                          Which File Copy or File Transfer would you suggest? FreeFileSync works great but is bundled with OpenCandy tracking.

                          Comment

                          • Malnutrition
                            PCHF Moderator
                            • Jul 2016
                            • 7041

                            #28
                            Originally posted by paulwb
                            Also, would you suggest using patchmypc on this machine?
                            Yes indeed.
                            Originally posted by paulwb
                            I know this isn’t your area but would you know of the right tool to uninstall MS Office. I need to do a reinstall.
                            LibreOffice is free. Also, there is this by MS.
                            Originally posted by paulwb
                            Which File Copy or File Transfer would you suggest? FreeFileSync works great but is bundled with OpenCandy tracking.
                            Just have to watch out when installing is all. Gus wrote a guide on the tool.

                            Comment

                            • paulwb
                              PCHF Member
                              • Nov 2016
                              • 159

                              #29
                              Originally posted by Malnutrition
                              Some report HDD activity after running the all in one tool, just use the machine a bit normally, after a few reboots things go back to normal. Also, after a couple of reboots clean it up with Privazer and then defrag the machine.
                              My C drive is solid state. OK to use ToolWiz Smart defrag software ?

                              Comment

                              • paulwb
                                PCHF Member
                                • Nov 2016
                                • 159

                                #30
                                Installed an older version of Freefilesync 7.9, based on recommendations found on different posts and there was no option to deselect any software offering.
                                Unchecky did not flag anything because there was nothing to check or uncheck.
                                Panda AV showed a pop up alert advising of potentially unwanted software.
                                Malwarebytes scan shows OpenCandy PUP embedded inside the freefilesync exe file.

                                [ATTACH]866[/ATTACH]

                                I ran Zemana & JRT, nothing found.
                                ZHP Cleaner found an empty key
                                FOUND key: HKLM\SYSTEM\CurrentControlSet\Services\CscService =>.Superfluous.PCSpeedUp

                                Anything else I should run to make sure nothing was installed ?

                                Comment

                                Working...