Fix result of Farbar Recovery Scan Tool (x64) Version: 18-06-2017 01 Ran by MerryZ (20-06-2017 20:22:28) Run:3 Running from C:\Users\MerryZ\Downloads Loaded Profiles: MerryZ (Available Profiles: MerryZ & Merry Z & Administrator & DefaultAppPool) Boot Mode: Normal ============================================== fixlist content: ***************** CloseProcesses: Unlock: C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe Unlock: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\gzserv CMD: SC stop gzserv DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\gzserv C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe Unlock: C:\Program Files\Bitdefender C:\Program Files\Bitdefender S2 gzserv; "C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe" /service [X] Unlock: C:\WINDOWS\System32\DRIVERS\gzflt.sys Unlock: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\gzflt DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\gzflt CMD: SC stop gzflt R1 gzflt; C:\WINDOWS\System32\DRIVERS\gzflt.sys [148696 2013-04-22] (BitDefender LLC) CHR Extension: (Chrome Remote Desktop) - C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2016-03-01] UNLOCK: C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp CHR Extension: (Savings Button: Deals + Cash Back) - C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmhdchlgkaelnphlklcdddpigfiblbhb [2017-06-18] CustomCLSID: HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\MerryZ\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\MerryZ\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\MerryZ\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\MerryZ\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\MerryZ\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\MerryZ\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\MerryZ\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File CustomCLSID: HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\MerryZ\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File Task: {041BCFEC-E15A-4545-BC45-31BBDA9B3142} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {0ECE70FC-FB17-431F-8DDA-458E20273C5F} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {1E0C8420-CC1C-460C-8158-CDCAFC31FC58} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe Task: {1EFE5FE9-F00C-4DAB-B615-5FC79A4F1484} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe Task: {221258DA-5948-464F-878E-DBF81FEC6D2B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe Task: {26EBB551-E1EC-44EE-AD0E-7DB285117188} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe Task: {2FFB4E15-E84D-4ED3-B81A-DC2BF642EF1B} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION Task: {308DE6B6-93AB-4C0B-8419-67AD94E607A6} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: {374DD734-61F9-4B96-984C-1A4A25027C3D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {38042427-598C-4006-A612-90E418AA0C11} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {3819A1E2-72A5-4260-94A1-3EA3C80E97A9} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION Task: {3BA27DB0-2E7F-44F9-98F8-A63E79425481} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {4797C0B6-D2D7-4FDD-9FD2-288DC0B09959} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {4FC91937-4328-4DFC-9DE2-641BE4974272} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe Task: {506FBDE0-4C5D-4CAA-80A7-24A87511DBA0} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {51272E91-C75A-49B8-8F3F-0676A36C3CE7} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION Task: {52E65B80-DAF5-4B8F-B565-7A69EBA12BCB} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe Task: {5696A2BE-4441-4F43-A723-B81BDF0FB398} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe Task: {5B9F8DBD-E9E5-4727-A437-965C22720049} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe Task: {688FF4C8-646C-48B8-8812-4B47A8CFC9EA} - \PCKeeper updater -> No File <==== ATTENTION Task: {6F588AF2-6B41-4EBA-981E-4A331CB435B2} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {6F5D3602-0C0C-49FD-8224-B3851110E1DE} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {909C4D1F-31C4-4B2E-AE2A-4D790E97C708} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe Task: {983D9123-CA73-4E57-92D9-DFC27FD9D716} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {9A7BF25C-8F5A-4369-AD21-5A6B5A4E5FB5} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe Task: {A4E5BD94-23AE-4920-9C9B-9D528DCBD822} - System32\Tasks\{400080EE-6B69-4339-B529-DCEB0B42ACB6} => C:\Program Files (x86)\Panda Security\Panda Security Protection\JobLauncher.exe Task: {A9A2825A-6C09-455B-888E-F281740651D7} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe Task: {B4253CFD-C0FA-44E0-A711-48184356BD81} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe Task: {B7ADC32D-5F3C-4110-832F-A8F76A54C381} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {D1782380-25B1-4279-8ECD-B1F5DED86804} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {D2F913A4-F43B-4375-B488-E9B9F9856A7A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe Task: {DB912175-F053-4031-9CC2-D124D79FF756} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe Task: {DC6AFBE2-DAAA-4108-9044-C1AC8F86F07D} - \Microsoft\Windows\Setup\GWXTriggers\Time-Weekend -> No File <==== ATTENTION Task: {E1B04E13-9C21-46C5-BDBF-CCD93447F57A} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe Task: {E768183E-30A7-4AC8-9779-47CC7E3FCF80} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {EDC05B86-5F20-40D0-A71E-3BF7BFF98E02} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {EEF4F990-CCD1-452E-9082-238CC14AD9ED} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {F62A39BC-5768-48C5-9CDC-5B23D4293167} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe Task: {F6587A0C-87F5-4C8A-8A0E-01F277D426E6} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe Task: C:\WINDOWS\Tasks\EPSON WF-2650 Series Update {7994C7D7-CFC6-4CD2-9E02-347096AE6BB6}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSMBE.EXE :/EXE:{7994C7D7-CFC6-4CD2-9E02-347096AE6BB6} /F:Update SYSTEM ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi Task: C:\WINDOWS\Tasks\EPSON WF-2650 Series Update {7C680D3A-30B6-4197-B0A4-99DA01E49500}.job => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSMBE.EXE :/EXE:{7C680D3A-30B6-4197-B0A4-99DA01E49500} /F:Update WORKGROUP\MERRYZ-PC$ ĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi ShortcutWithArgument: C:\Users\MerryZ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1" --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp ShortcutWithArgument: C:\Users\MerryZ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1" AlternateDataStreams: C:\Users\MerryZ\Downloads\ChromeSetup.exe:BDU [0] AlternateDataStreams: C:\Users\MerryZ\Downloads\CouponPrinterCPS.exe:BDU [0] AlternateDataStreams: C:\Users\MerryZ\Downloads\drfone-for-android_full1464_550.exe:BDU [0] AlternateDataStreams: C:\Users\MerryZ\Downloads\epson16365.exe:BDU [0] AlternateDataStreams: C:\Users\MerryZ\Downloads\FileFormatConverters.exe:BDU [0] AlternateDataStreams: C:\Users\MerryZ\Downloads\gimp-2.8.14-setup-1.exe:BDU [0] AlternateDataStreams: C:\Users\MerryZ\Downloads\KindleForPC-installer.exe:BDU [0] AlternateDataStreams: C:\Users\MerryZ\Downloads\msgr11us.exe:BDU [0] AlternateDataStreams: C:\Users\MerryZ\Downloads\picasa39-setup (1).exe:BDU [0] AlternateDataStreams: C:\Users\MerryZ\Downloads\vcredist_x64.exe:BDU [0] AlternateDataStreams: C:\Users\MerryZ\Downloads\vcredist_x86.exe:BDU [0] AlternateDataStreams: C:\Users\MerryZ\Downloads\vc_redist.x64.exe:BDU [0] CMD: powercfg -h off CMD: sc config NetTcpActivator startup= disabled CMD: sc config BstHdDrv startup= demand CMD: for /F "tokens=*" %1 in ('wevtutil.exe el') DO wevtutil.exe cl "%1" ***************** Processes closed successfully. "C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe" => not found. "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\gzserv" => key could not be unlocked ========= SC stop gzserv ========= [SC] ControlService FAILED 1062: The service has not been started. ========= End of CMD: ========= HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\gzserv => key could not remove, key could be protected "C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe" => not found. "C:\Program Files\Bitdefender" => not found. "C:\Program Files\Bitdefender" => not found. HKLM\System\CurrentControlSet\Services\gzserv => key could not remove, key could be protected "C:\WINDOWS\System32\DRIVERS\gzflt.sys" => could not be unlocked "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\gzflt" => key could not be unlocked HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\gzflt => key could not remove, key could be protected ========= SC stop gzflt ========= [SC] ControlService FAILED 1052: The requested control is not valid for this service. ========= End of CMD: ========= gzflt => Unable to stop service. HKLM\System\CurrentControlSet\Services\gzflt => key could not remove, key could be protected C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp => moved successfully "C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp" => not found. "C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp" => not found. C:\Users\MerryZ\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hmhdchlgkaelnphlklcdddpigfiblbhb => moved successfully HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856} => key removed successfully HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4} => key removed successfully HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247} => key removed successfully HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04} => key removed successfully HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A} => key removed successfully HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA} => key removed successfully HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2} => key removed successfully HKU\S-1-5-21-2720924552-1951368585-1981068937-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{041BCFEC-E15A-4545-BC45-31BBDA9B3142} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{041BCFEC-E15A-4545-BC45-31BBDA9B3142} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0ECE70FC-FB17-431F-8DDA-458E20273C5F} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0ECE70FC-FB17-431F-8DDA-458E20273C5F} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscovery => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1E0C8420-CC1C-460C-8158-CDCAFC31FC58} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E0C8420-CC1C-460C-8158-CDCAFC31FC58} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ehDRMInit => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{1EFE5FE9-F00C-4DAB-B615-5FC79A4F1484} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EFE5FE9-F00C-4DAB-B615-5FC79A4F1484} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RecordingRestart => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{221258DA-5948-464F-878E-DBF81FEC6D2B} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{221258DA-5948-464F-878E-DBF81FEC6D2B} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate_scheduled => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{26EBB551-E1EC-44EE-AD0E-7DB285117188} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26EBB551-E1EC-44EE-AD0E-7DB285117188} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\InstallPlayReady => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2FFB4E15-E84D-4ED3-B81A-DC2BF642EF1B} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2FFB4E15-E84D-4ED3-B81A-DC2BF642EF1B} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{308DE6B6-93AB-4C0B-8419-67AD94E607A6} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{308DE6B6-93AB-4C0B-8419-67AD94E607A6} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ActivateWindowsSearch => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{374DD734-61F9-4B96-984C-1A4A25027C3D} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{374DD734-61F9-4B96-984C-1A4A25027C3D} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{38042427-598C-4006-A612-90E418AA0C11} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{38042427-598C-4006-A612-90E418AA0C11} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3819A1E2-72A5-4260-94A1-3EA3C80E97A9} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3819A1E2-72A5-4260-94A1-3EA3C80E97A9} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3BA27DB0-2E7F-44F9-98F8-A63E79425481} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3BA27DB0-2E7F-44F9-98F8-A63E79425481} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4797C0B6-D2D7-4FDD-9FD2-288DC0B09959} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4797C0B6-D2D7-4FDD-9FD2-288DC0B09959} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4FC91937-4328-4DFC-9DE2-641BE4974272} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4FC91937-4328-4DFC-9DE2-641BE4974272} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURActivate => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{506FBDE0-4C5D-4CAA-80A7-24A87511DBA0} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{506FBDE0-4C5D-4CAA-80A7-24A87511DBA0} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrRecoveryTask => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{51272E91-C75A-49B8-8F3F-0676A36C3CE7} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{51272E91-C75A-49B8-8F3F-0676A36C3CE7} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{52E65B80-DAF5-4B8F-B565-7A69EBA12BCB} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{52E65B80-DAF5-4B8F-B565-7A69EBA12BCB} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURDiscovery => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5696A2BE-4441-4F43-A723-B81BDF0FB398} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5696A2BE-4441-4F43-A723-B81BDF0FB398} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\mcupdate => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5B9F8DBD-E9E5-4727-A437-965C22720049} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B9F8DBD-E9E5-4727-A437-965C22720049} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ConfigureInternetTimeService => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{688FF4C8-646C-48B8-8812-4B47A8CFC9EA} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{688FF4C8-646C-48B8-8812-4B47A8CFC9EA} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PCKeeper updater => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6F588AF2-6B41-4EBA-981E-4A331CB435B2} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F588AF2-6B41-4EBA-981E-4A331CB435B2} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6F5D3602-0C0C-49FD-8224-B3851110E1DE} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F5D3602-0C0C-49FD-8224-B3851110E1DE} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{909C4D1F-31C4-4B2E-AE2A-4D790E97C708} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{909C4D1F-31C4-4B2E-AE2A-4D790E97C708} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\StartRecording => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\StartRecording => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{983D9123-CA73-4E57-92D9-DFC27FD9D716} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{983D9123-CA73-4E57-92D9-DFC27FD9D716} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9A7BF25C-8F5A-4369-AD21-5A6B5A4E5FB5} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9A7BF25C-8F5A-4369-AD21-5A6B5A4E5FB5} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PeriodicScanRetry => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A4E5BD94-23AE-4920-9C9B-9D528DCBD822} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4E5BD94-23AE-4920-9C9B-9D528DCBD822} => key removed successfully C:\WINDOWS\System32\Tasks\{400080EE-6B69-4339-B529-DCEB0B42ACB6} => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{400080EE-6B69-4339-B529-DCEB0B42ACB6} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A9A2825A-6C09-455B-888E-F281740651D7} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9A2825A-6C09-455B-888E-F281740651D7} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\UpdateRecordPath => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B4253CFD-C0FA-44E0-A711-48184356BD81} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4253CFD-C0FA-44E0-A711-48184356BD81} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrScheduleTask => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B7ADC32D-5F3C-4110-832F-A8F76A54C381} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7ADC32D-5F3C-4110-832F-A8F76A54C381} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW2 => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D1782380-25B1-4279-8ECD-B1F5DED86804} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D1782380-25B1-4279-8ECD-B1F5DED86804} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D2F913A4-F43B-4375-B488-E9B9F9856A7A} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D2F913A4-F43B-4375-B488-E9B9F9856A7A} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW1 => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DB912175-F053-4031-9CC2-D124D79FF756} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB912175-F053-4031-9CC2-D124D79FF756} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DC6AFBE2-DAAA-4108-9044-C1AC8F86F07D} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DC6AFBE2-DAAA-4108-9044-C1AC8F86F07D} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-Weekend => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{E1B04E13-9C21-46C5-BDBF-CCD93447F57A} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1B04E13-9C21-46C5-BDBF-CCD93447F57A} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\DispatchRecoveryTasks => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E768183E-30A7-4AC8-9779-47CC7E3FCF80} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E768183E-30A7-4AC8-9779-47CC7E3FCF80} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EDC05B86-5F20-40D0-A71E-3BF7BFF98E02} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EDC05B86-5F20-40D0-A71E-3BF7BFF98E02} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EEF4F990-CCD1-452E-9082-238CC14AD9ED} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EEF4F990-CCD1-452E-9082-238CC14AD9ED} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F62A39BC-5768-48C5-9CDC-5B23D4293167} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F62A39BC-5768-48C5-9CDC-5B23D4293167} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ReindexSearchRoot => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F6587A0C-87F5-4C8A-8A0E-01F277D426E6} => key removed successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6587A0C-87F5-4C8A-8A0E-01F277D426E6} => key removed successfully C:\WINDOWS\System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => moved successfully HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RegisterSearch => key removed successfully C:\WINDOWS\Tasks\EPSON WF-2650 Series Update {7994C7D7-CFC6-4CD2-9E02-347096AE6BB6}.job => moved successfully C:\WINDOWS\Tasks\EPSON WF-2650 Series Update {7C680D3A-30B6-4197-B0A4-99DA01E49500}.job => moved successfully C:\Users\MerryZ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk => Shortcut argument removed successfully. C:\Users\MerryZ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk => Shortcut argument removed successfully. C:\Users\MerryZ\Downloads\ChromeSetup.exe => ":BDU" ADS removed successfully. C:\Users\MerryZ\Downloads\CouponPrinterCPS.exe => ":BDU" ADS removed successfully. C:\Users\MerryZ\Downloads\drfone-for-android_full1464_550.exe => ":BDU" ADS removed successfully. C:\Users\MerryZ\Downloads\epson16365.exe => ":BDU" ADS removed successfully. C:\Users\MerryZ\Downloads\FileFormatConverters.exe => ":BDU" ADS removed successfully. C:\Users\MerryZ\Downloads\gimp-2.8.14-setup-1.exe => ":BDU" ADS removed successfully. C:\Users\MerryZ\Downloads\KindleForPC-installer.exe => ":BDU" ADS removed successfully. C:\Users\MerryZ\Downloads\msgr11us.exe => ":BDU" ADS removed successfully. C:\Users\MerryZ\Downloads\picasa39-setup (1).exe => ":BDU" ADS removed successfully. C:\Users\MerryZ\Downloads\vcredist_x64.exe => ":BDU" ADS removed successfully. C:\Users\MerryZ\Downloads\vcredist_x86.exe => ":BDU" ADS removed successfully. C:\Users\MerryZ\Downloads\vc_redist.x64.exe => ":BDU" ADS removed successfully. ========= powercfg -h off ========= ========= End of CMD: ========= ========= sc config NetTcpActivator startup= disabled ========= DESCRIPTION: Modifies a service entry in the registry and Service Database. USAGE: sc config [service name] ... OPTIONS: NOTE: The option name includes the equal sign. A space is required between the equal sign and the value. type= start= error= binPath= group= tag= depend= obj= DisplayName= password= ========= End of CMD: ========= ========= sc config BstHdDrv startup= demand ========= DESCRIPTION: Modifies a service entry in the registry and Service Database. USAGE: sc config [service name] ... OPTIONS: NOTE: The option name includes the equal sign. A space is required between the equal sign and the value. type= start= error= binPath= group= tag= depend= obj= DisplayName= password= ========= End of CMD: ========= ========= for /F "tokens=*" %1 in ('wevtutil.exe el') DO wevtutil.exe cl "%1" ========= Failed to clear log Microsoft-Windows-LiveId/Analytic. Access is denied. Failed to clear log Microsoft-Windows-LiveId/Operational. Access is denied. Failed to clear log Microsoft-Windows-USBVideo/Analytic. The instance name passed was not recognized as valid by a WMI data provider. ========= End of CMD: ========= Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 20-06-2017 20:24:11) Result of scheduled keys to remove after reboot: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\gzserv => key could not remove, key could be protected HKLM\System\CurrentControlSet\Services\gzserv => key could not remove, key could be protected HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\gzflt => key could not remove, key could be protected HKLM\System\CurrentControlSet\Services\gzflt => key could not remove, key could be protected ==== End of Fixlog 20:24:11 ====