Infection exposure risk concern and incomplete Avira AntiVirus uninstall - Page 2 - Virus, Trojan, Spyware, and Malware Removal Help (2024)

Fix result of Farbar Recovery Scan Tool (x64) Version: 27-07-2023
Ran by Shamus (30-07-2023 07:41:09) Run:4
Running from D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230730
Loaded Profiles: Shamus & Budgy
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
C:\Windows\WinSxS\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\OneDriveSettingSyncProvider.dll
C:\Windows\WinSxS\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\r\OneDriveSettingSyncProvider.dll
C:\Windows\WinSxS\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\f\OneDriveSettingSyncProvider.dll
C:\Windows\WinSxS\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6\OneDrive.ico
C:\Windows\WinSxS\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6\OneDrive.lnk
C:\Windows\WinSxS\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6\OneDriveSetup.exe
C:\Windows\WinSxS\Manifests\amd64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_db314eafc56dd1eb.manifest
C:\Windows\WinSxS\Manifests\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1.manifest
C:\Windows\WinSxS\Manifests\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5.manifest
C:\Windows\WinSxS\Manifests\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6.manifest
C:\Windows\WinSxS\Manifests\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0.manifest
C:\Windows\WinSxS\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\OneDriveSettingSyncProvider.dll
C:\Windows\WinSxS\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\r\OneDriveSettingSyncProvider.dll
C:\Windows\WinSxS\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\f\OneDriveSettingSyncProvider.dll
C:\Windows\WinSxS\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\SettingsHandlers_OneDriveBackup.dll
C:\Windows\WinSxS\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\r\SettingsHandlers_OneDriveBackup.dll
C:\Windows\WinSxS\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\f\SettingsHandlers_OneDriveBackup.dll
C:\Windows\WinSxS\amd64_microsoft-windows-s..ivebackup.resources_31bf3856ad364e35_10.0.19041.1_en-us_e257a95bc3c952cc\SettingsHandlers_OneDriveBackup.dll.mui
C:\Windows\SysWOW64\OneDrive.ico
C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll
C:\Windows\SysWOW64\OneDriveSetup.exe
C:\Windows\System32\OneDriveSettingSyncProvider.dll
C:\Windows\System32\SettingsHandlers_OneDriveBackup.dll
C:\Windows\System32\Tasks\OneDrive Reporting Task-S-1-5-21-3428103939-1962105336-1684995027-1002
C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3428103939-1962105336-1684995027-1002
C:\Windows\System32\en-US\SettingsHandlers_OneDriveBackup.dll.mui
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.mum
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1.mum
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.mum
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1.mum
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1.manifest
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5.manifest
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0.manifest
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\r\onedrivesettingsyncprovider.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\f\onedrivesettingsyncprovider.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\r\onedrivesettingsyncprovider.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\f\onedrivesettingsyncprovider.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\r\settingshandlers_onedrivebackup.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\f\settingshandlers_onedrivebackup.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-holoshell.appxmain_31bf3856ad364e35_10.0.19041.546_none_0193b0cedf0d3cd3\r\promo_onedrive.png
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-holoshell.appxmain_31bf3856ad364e35_10.0.19041.546_none_0193b0cedf0d3cd3\f\promo_onedrive.png
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1.manifest
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5.manifest
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0.manifest
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\r\onedrivesettingsyncprovider.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\f\onedrivesettingsyncprovider.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\r\onedrivesettingsyncprovider.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\f\onedrivesettingsyncprovider.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\r\settingshandlers_onedrivebackup.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\f\settingshandlers_onedrivebackup.dll
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-holoshell.appxmain_31bf3856ad364e35_10.0.19041.546_none_0193b0cedf0d3cd3\r\promo_onedrive.png
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-holoshell.appxmain_31bf3856ad364e35_10.0.19041.546_none_0193b0cedf0d3cd3\f\promo_onedrive.png
C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
C:\Users\TEMP.DESKTOP-F6HNTND.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
C:\Users\TEMP.DESKTOP-F6HNTND.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
C:\Users\TEMP.DESKTOP-F6HNTND\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
C:\Users\Shamus\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\SL10OXHH\onedrive.liveDeleteValue: 1].xml
C:\Users\Shamus\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\7IHTYKM5\onedrive-devices2DeleteValue: 1].svg
C:\Users\Shamus\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\221UL3MZ\icon-onedriveDeleteValue: 1].svg
C:\Users\Budgy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
C:\Users\Budgy\AppData\Roaming\Microsoft\Windows\Recent\20230721_Avira weird uninstall.lnk
C:\Users\Budgy\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\L7JPI738\onedrive.liveDeleteValue: 1].xml
2022-09-08 13:07 - 2022-09-08 13:07 _____ C:\Windows\WinSxS\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1
2022-09-08 13:07 - 2022-09-08 13:07 _____ C:\Windows\WinSxS\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5
2019-12-07 19:10 - 2019-12-07 19:53 _____ C:\Windows\WinSxS\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6
2022-09-08 13:07 - 2022-09-08 13:07 _____ C:\Windows\WinSxS\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0
2023-07-12 17:18 - 2023-07-12 17:18 _____ C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1
2023-07-12 17:18 - 2023-07-12 17:18 _____ C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5
2023-07-12 17:18 - 2023-07-12 17:18 _____ C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0
2023-06-14 19:35 - 2023-06-14 19:35 _____ C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1
2023-06-14 19:35 - 2023-06-14 19:35 _____ C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5
2023-06-14 19:35 - 2023-06-14 19:35 _____ C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0
2023-02-11 16:26 - 2023-02-11 16:26 ____R C:\Users\Shamus\OneDrive
2023-02-11 16:24 - 2023-07-27 09:52 _____ C:\Users\Shamus\AppData\Local\Microsoft\OneDrive
2023-02-11 17:48 - 2023-02-11 17:48 ____R C:\Users\Budgy\OneDrive
2023-02-11 17:48 - 2023-07-26 17:34 _____ C:\Users\Budgy\AppData\Local\Microsoft\OneDrive
2023-02-11 16:24 - 2023-02-11 16:24 _____ C:\ProgramData\Microsoft OneDrive
2023-06-30 11:39 - 2023-06-30 11:39 _____ C:\FRST\Quarantine\C\Windows\system32\Tasks\Avira
2023-02-12 23:30 - 2023-02-12 23:30 _____ C:\FRST\Quarantine\C\Users\Shamus\AppData\Local\Avira
2023-02-12 23:33 - 2023-02-12 23:33 _____ C:\FRST\Quarantine\C\Users\Budgy\AppData\Local\Avira
2023-02-19 17:49 - 2023-02-19 17:49 _____ C:\FRST\Quarantine\C\Users\Budgy\AppData\Local\AviraWebView2Cache
2023-03-07 19:07 - 2023-03-07 19:07 _____ C:\FRST\Quarantine\C\Users\Budgy\AppData\Local\AviraWebView2Cache\EBWebView\Default\IndexedDB\https_spotlight.my.avira.com_0.indexeddb.leveldb
2023-02-12 23:28 - 2023-06-30 11:45 _____ C:\FRST\Quarantine\C\ProgramData\Avira
2023-02-19 18:09 - 2023-02-19 18:09 ____C C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Avira.Spotlight._8b1fe1546fb73afe46ef2e2964b415c9d1507b57_84d0adfb_002fa9ba-4e02-42d7-b0a4-f7d3b51e5a0a
2023-02-20 18:09 - 2023-02-20 18:09 ____C C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Avira.Spotlight._8b1fe1546fb73afe46ef2e2964b415c9d1507b57_84d0adfb_a10b425e-f4d1-40fd-b662-64d4ae66b05f
2023-06-30 11:11 - 2023-06-30 11:11 ____C C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Avira.Spotlight._6d9557a98631498e12c12461e35c32ce3caf99e1_1e0aca87_84044e9a-f0f3-417b-ade4-83cf13e82cdc
2023-03-23 07:17 - 2023-03-23 07:17 ____C C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Avira.Spotlight._fa79f81228ba382bf91728bb9c15af72bf795f_39db0307_49eff039-4e19-4c57-8c43-bf77cd323883
2023-02-12 23:29 - 2023-06-28 16:49 _____ C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2023-06-14 18:06 - 2023-06-14 18:06 _____ C:\FRST\Quarantine\C\ProgramData\Avira\Security\Logs\Sentry\Avira.Spotlight.UI.Application
2023-02-12 23:29 - 2023-06-30 12:09 _____ C:\FRST\Quarantine\C\Program Files (x86)\Avira
2023-02-12 23:30 - 2023-02-12 23:30 _____ C:\FRST\Quarantine\C\Program Files\Avira
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{099EB73C-FF12-45C5-BF64-F0277733A6E2}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{099EB73C-FF12-45C5-BF64-F0277733A6E2}\InProcServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{34212D32-6E9E-11E2-BDA0-6B2B6288709B}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{34212D32-6E9E-11E2-BDA0-6B2B6288709B}\InProcServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3FC77A3B-14C6-41B6-ACC5-ED80223D81C4}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3FC77A3B-14C6-41B6-ACC5-ED80223D81C4}\InProcServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{78DE489B-7931-4f14-83B4-C56D38AC9FFA}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{86c815aa-4888-4063-b0ab-03c49f788be4}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D6ABE021-1DE0-49F4-895D-E9694D28F0A4}\InProcServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDB93701-527B-4250-B619-672EFD3C5B21}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDB93701-527B-4250-B619-672EFD3C5B21}\InProcServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{081175B7-D324-55C8-8363-E0EF340B4552}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0DF05B8F-C752-5855-86B4-4D7D89FA08D8}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{426317B8-C7D2-4647-AD76-2554806561B6}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9153BF48-3D44-4D3C-976A-FA62FFF6DDAC}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E89C17A1-D22E-4235-9A2E-F141FB977E7B}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{099EB73C-FF12-45C5-BF64-F0277733A6E2}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{099EB73C-FF12-45C5-BF64-F0277733A6E2}\InProcServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{34212D32-6E9E-11E2-BDA0-6B2B6288709B}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{34212D32-6E9E-11E2-BDA0-6B2B6288709B}\InProcServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3FC77A3B-14C6-41B6-ACC5-ED80223D81C4}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3FC77A3B-14C6-41B6-ACC5-ED80223D81C4}\InProcServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{78DE489B-7931-4f14-83B4-C56D38AC9FFA}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{D6ABE021-1DE0-49F4-895D-E9694D28F0A4}\InProcServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{DDB93701-527B-4250-B619-672EFD3C5B21}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{DDB93701-527B-4250-B619-672EFD3C5B21}\InProcServer32|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{081175B7-D324-55C8-8363-E0EF340B4552}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{0DF05B8F-C752-5855-86B4-4D7D89FA08D8}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{426317B8-C7D2-4647-AD76-2554806561B6}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneDriveFileSync|RegKeyPathRedirect
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_OneBackup_OneDriveBackup|DllPath
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageDetect\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~0.0.0.0|Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageDetect\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~0.0.0.0|Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~0.0.0.0|Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~0.0.0.0|Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~0.0.0.0|Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~0.0.0.0|Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1|InstallName
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1|InstallName
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1|InstallName
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1|InstallName
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\OptIn|URL
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\OptOut|URL
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}|Name
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}|Name
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}|Name
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}|Name
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}|RelativePath
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}|Name
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps|RegistryRoot
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps|SettingUnitId
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}|ResourceFileName
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}|MessageFileName
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}\ChannelReferences\0|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}\ChannelReferences\1|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}\ChannelReferences\2|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53464712-4078-44F8-A926-31D4A006C1F9}|Path
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53464712-4078-44F8-A926-31D4A006C1F9}|URI
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6101EE54-8F4A-472F-9A16-C703889825D7}|Path
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6101EE54-8F4A-472F-9A16-C703889825D7}|URI
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserDefaults|ExcludeProfileDirs
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\OptIn|URL
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\OptOut|URL
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}|Name
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}|Name
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}|Name
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}|Name
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}|RelativePath
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}|Name
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps|RegistryRoot
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps|SettingUnitId
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\ShellCompatibility\InboxApp|14BB934C8A478762_OneDrive_lnk_wow64.lnk
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1002|\Device\HarddiskVolume3\Users\Budgy\AppData\Local\Microsoft\OneDrive\OneDrive.exe
DeleteValue: HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|OneDriveSetup
DeleteValue: HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|OneDriveSetup
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\Environment|OneDrive
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\19.043.0304.0013_1\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\23.043.0226.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\23.107.0521.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\23.122.0611.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\23.132.0625.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\23.137.0702.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|ExcludeProfileDirs
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\grvopen|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\grvopen\DefaultIcon|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\grvopen\shell\open\command|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CMicrosoft.Windows.SecHealthUI%5CMicrosoft.Windows.SecHealthUI.pri\1d93de4f06ee54b\cb0fbae5|@{windows?ms-resource://Microsoft.Windows.SecHealthUI/resources/RansomwareProtection_HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5|@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPageGroup_GranularCloudSearch/HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5|@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPageGroup_Search_GranularCloudSearch/HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5|@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAppRequestedDownloads-2/HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5|@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAppRequestedDownloads/HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5|@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SystemSettings_Personalize_LockScreenSlideshowSource_CloudBrandName/HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\Environment|OneDrive
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.microsoft.onedrive.nucleus.auth.provider|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|OneDrive.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive|CurrentVersionPath
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive|OneDriveTrigger
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive|LastRunOneDriveVersion
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive|OduDownloadOneDriveSetupStartTime
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive|OduDownloadOneDriveSetupEndTime
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\23.147.0716.0001|InstallPath
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\23.147.0716.0001|InstallPaths
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\Accounts\Business1|OneDriveDeviceId
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\Accounts\Personal|OneDriveDeviceId
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\Capabilities\URLAssociations|Explorer.CameraRoll.Import
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{018D5C66-4533-4307-9B53-224DE2ED1FE6}|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|OneDrive
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneDriveSetup.exe|DisplayName
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneDriveSetup.exe|DisplayIcon
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneDriveSetup.exe|UninstallString
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.011.0115.0009\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.020.0125.0003\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.028.0205.0002\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.033.0212.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.038.0219.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.043.0226.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.048.0305.0002\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.054.0313.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.076.0409.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.081.0416.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.086.0423.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.091.0430.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\OneDrive.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.096.0507.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.101.0514.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.107.0521.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.114.0530.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.119.0606.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.122.0611.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.127.0618.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.132.0625.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.137.0702.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.147.0716.0001\FileSyncConfig.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers|C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\OneDrive.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|ExcludeProfileDirs
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\RegisteredApplications|OneDrive
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\.fluid\shell\open\command|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\.loop\shell\open\command|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\.note\shell\open\command|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\.whiteboard\shell\open\command|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\DefaultIcon|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{07CA83F0-DF06-4E67-89DD-E80924A49512}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{0827D883-485C-4D62-BA2C-A332DBF3D4B0}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{20894375-46AE-46E2-BAFD-CB38975CDCE6}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{2e7c0a19-0438-41e9-81e3-3ad3d64f55ba}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{5999E1EE-711E-48D2-9884-851A709F543D}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{6bb93b4e-44d8-40e2-bd97-42dbcf18a40f}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{9AA2F32D-362A-42D9-9328-24A483E2CCC3}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{A3CA1CF4-5F3E-4AC0-91B9-0D3716E1EAC3}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{F37369D9-1C22-40A0-A997-0B4D5F7B6637}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\grvopen|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\grvopen\DefaultIcon|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\grvopen\shell\open\command|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Interface\{6A821279-AB49-48F8-9A27-F6C59B4FF024}|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Interface\{A91EFACB-8B83-4B84-B797-1C8CF3AB3DCB}|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Interface\{B05D37A9-03A2-45CF-8850-F660DF0CBF07}|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Interface\{C47B67D4-BA96-44BC-AB9E-1CAC8EEA9E93}|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CMicrosoft.Windows.SecHealthUI%5CMicrosoft.Windows.SecHealthUI.pri\1d93de4f06ee54b\cb0fbae5|@{windows?ms-resource://Microsoft.Windows.SecHealthUI/resources/RansomwareProtection_HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5|@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPageGroup_GranularCloudSearch/HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5|@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPageGroup_Search_GranularCloudSearch/HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5|@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAppRequestedDownloads-2/HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5|@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAppRequestedDownloads/HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5|@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SystemSettings_Personalize_LockScreenSlideshowSource_CloudBrandName/HighKeywords}
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\mssharepointclient\DefaultIcon|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\mssharepointclient\shell\open\command|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\odopen|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\odopen\DefaultIcon|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\odopen\shell\open\command|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\OneDrive.CameraRoll.Import\shell\open\command|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{082D3FEC-D0D0-4DF6-A988-053FECE7B884}\1.0\0\win64|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{082D3FEC-D0D0-4DF6-A988-053FECE7B884}\1.0\HELPDIR|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{4B1C80DA-FA45-468F-B42B-46496BDBE0C5}\1.0\0\win64|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{4B1C80DA-FA45-468F-B42B-46496BDBE0C5}\1.0\HELPDIR|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{638805C3-4BA3-4AC8-8AAC-71A0BA2BC284}\1.0\0\win64|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{638805C3-4BA3-4AC8-8AAC-71A0BA2BC284}\1.0\HELPDIR|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{909A6CCD-6810-46C4-89DF-05BE7EB61E6C}\1.0\0\win64|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{909A6CCD-6810-46C4-89DF-05BE7EB61E6C}\1.0\HELPDIR|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{BAE13F6C-0E2A-4DEB-AA46-B8F55319347C}\1.0\0\win64|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{BAE13F6C-0E2A-4DEB-AA46-B8F55319347C}\1.0\HELPDIR|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{C9F3F6BB-3172-4CD8-9EB7-37C9BE601C87}\1.0\0\win32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{C9F3F6BB-3172-4CD8-9EB7-37C9BE601C87}\1.0\0\win64|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{C9F3F6BB-3172-4CD8-9EB7-37C9BE601C87}\1.0\HELPDIR|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{F904F88C-E60D-4327-9FA2-865AD075B400}\1.0\0\win32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{F904F88C-E60D-4327-9FA2-865AD075B400}\1.0\HELPDIR|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\DefaultIcon|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{07CA83F0-DF06-4E67-89DD-E80924A49512}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{0827D883-485C-4D62-BA2C-A332DBF3D4B0}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{20894375-46AE-46E2-BAFD-CB38975CDCE6}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{9AA2F32D-362A-42D9-9328-24A483E2CCC3}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{F37369D9-1C22-40A0-A997-0B4D5F7B6637}\LocalServer32|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\Interface\{6A821279-AB49-48F8-9A27-F6C59B4FF024}|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\Interface\{A91EFACB-8B83-4B84-B797-1C8CF3AB3DCB}|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\Interface\{B05D37A9-03A2-45CF-8850-F660DF0CBF07}|""
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\Interface\{C47B67D4-BA96-44BC-AB9E-1CAC8EEA9E93}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Launcher|AcpNamedPipeName
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Launcher|InstallationPath
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Security|ExternalNamedPipe
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Security\ConnectServices|AuthToken
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Security\Resources|Cache.Profile
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Security\Resources|Cache.Device
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\AMSI\Providers\{00000001-3DCC-4B48-A82E-E2071FE58E05}|""
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\X-AVCSD\EndpointProtection|MasterKey
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\X-AVCSD\EndpointProtection|Avira
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\X-AVCSD\Launcher|Avira
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\X-AVCSD\Launcher|MasterKey
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurity|ImagePath
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurity|DisplayName
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurity|Description
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurity|FailureCommand
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurityUpdater|ImagePath
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurityUpdater|DisplayName
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurityUpdater|Description
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1001|\Device\HarddiskVolume4\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230724_from Shamus\FRST64.exe
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1001|\Device\HarddiskVolume4\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230725\FRST64.exe
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1001|\Device\HarddiskVolume4\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230726\FRST64.exe
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1001|\Device\HarddiskVolume4\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230728\FRST64.exe
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1001|\Device\HarddiskVolume4\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230729\FRST64.exe
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BdNet|DisplayName
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BdSentry|DisplayName
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BdSentry|Description
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BdSentry\Parameters\ConfigDevice|BootOpsCfg
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BdSentry\Parameters\ConfigDevice|BootOpsLog
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EndpointProtectionService|ImagePath
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EndpointProtectionService2|ImagePath
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_elam|Description
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filesystem_filter|AviraDriverStatus
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter|AviraDriverStatus
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter|Description
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter|ClientPath
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter|LicensePath
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter|AviraRegAcl
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter|AviraFileAcl
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter|AviraProcessTrust
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter|AviraProcessProtection
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\WscAgent|RemediationPath
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\WscAgent|DisplayName
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor|ClientPath
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor|LicensePath
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor|AviraRegAcl
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor|AviraFileAcl
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor|AviraDriverStatus
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor\WscAgent|DisplayName
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor\WscAgent|RemediationPath
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL|Avira.Spotlight.UI.Application.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|Avira.Spotlight.UI.Application.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230728\FRST64.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|D:\Installers\Avira\avira_en_sptl1_610379103-1676208366__pavwws-spotlight-release.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|D:\Installers\Avira\avira_en_sptl1_589eb78b2b63221f__phpws-spotlight-release.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230724_from Shamus\FRST64.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230725\FRST64.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230728\FRST64.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230729\FRST64.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\files\4|path
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\files\5|path
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\files_bak\3|path
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\files_bak\4|path
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\Sequence|D:/D/IT issues/Lenovo_X1C/20230721_Avira weird uninstall/20230721_0854hrs_BalarcScan.pdf
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\Sequence|D:/D/IT issues/Lenovo_X1C/20230721_Avira weird uninstall/Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help - Virus, Trojan, Spyware, and Malware Removal Help.pdf
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\pdf|4
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\pdf|5
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\wps|2
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\wpsoffice|9
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\wpsoffice|10
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\wpsoffice|14
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\wps\RecentFiles\files\2|path
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\wps\RecentFiles\files_bak\2|path
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\wps\RecentFiles\Sequence|D:/D/IT issues/Lenovo_X1C/20230721_Avira weird uninstall/20230721_My case notes.docx
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL|Avira.Spotlight.UI.Application.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL|Avira.Spotlight.UI.Application.Messaging.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|Avira.Spotlight.UI.Application.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|Avira.Spotlight.UI.Application.Messaging.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppBadgeUpdated|{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Avira\Security\Avira.Spotlight.UI.Application.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Avira\Security\Avira.Spotlight.UI.Application.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230725\FRST64.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Avira\VPN\Avira.WebAppHost.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Avira\Security\Avira.Spotlight.UI.Application.exe
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST 20230722\FRST64.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST 20230722\FRST64.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230725\FRST64.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230725\FRST64.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230729\FRST64.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230729\FRST64.exe.ApplicationCompany
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\ADMX_UserExperienceVirtualization\MicrosoftOffice2013OneDriveForBusiness
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\ADMX_UserExperienceVirtualization\MicrosoftOffice2016OneDriveForBusiness
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneDriveFileSync
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_OneBackup_OneDriveBackup
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageDetect\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~0.0.0.0
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageDetect\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~0.0.0.0
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~0.0.0.0
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~0.0.0.0
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~0.0.0.0
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~0.0.0.0
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\OneDriveRamps
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft-windows-onedrive-setup_31bf3856ad364e35_none_5154c8ab59350670
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_none_3f91f088ca83ebb4
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_none_4415c8f172a00240
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_none_5ba972fd8d95c86b
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_none_4e6a7343a700c43b
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SettingSync-OneDrive/Analytic
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SettingSync-OneDrive/Debug
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SettingSync-OneDrive/Operational
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Reporting Task-S-1-5-21-3428103939-1962105336-1684995027-1002
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Standalone Update Task-S-1-5-21-3428103939-1962105336-1684995027-1002
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\CloudExperienceHostBroker.SyncEngine.OOBEOneDriveOptin
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\CloudExperienceHostBroker.SyncEngine.OOBEOneDriveOptinCore
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\CloudExperienceHostBroker.SyncEngine.OOBEOneDriveOptinCoreForUser
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.System.UserProfile.OneDriveEngagementManager
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\OneDriveRamps
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps
DeleteKey: HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\OneDrive
DeleteKey: HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\OneDrive
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\OneDrive
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.microsoft.onedrive.nucleus.auth.provider
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OneDriveFileLauncher.exe
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\ProviderId\OneDriveDesktop
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\ProviderId\OneDriveDocuments
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\ProviderId\OneDriveLocal
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\ProviderId\OneDrivePictures
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\ProviderId\OneDriveSync
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StorageProvider\OneDrive
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneDriveSetup.exe
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\AppID\OneDrive.EXE
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\OneDrive.CameraRoll.Import
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Avira_RASAPI32
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Avira_RASMANCS
DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurity
DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurityUpdater
DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\Avira Phantom VPN
DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\AviraSecurity
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Avira
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Avira
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\DOMStorage\avira.com
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\DOMStorage\spotlight.my.avira.com
DeleteKey: HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\DOMStorage\www.avira.com
cmd: chkdsk
cmd: sfc /scannow
cmd: type "C:\Window\System32\Logfiles\Srt\SrtTrail.txt"
*****************

Restore point was successfully created.
Processes closed successfully.
C:\Windows\WinSxS\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\OneDriveSettingSyncProvider.dll => moved successfully
C:\Windows\WinSxS\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\r\OneDriveSettingSyncProvider.dll => moved successfully
C:\Windows\WinSxS\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\f\OneDriveSettingSyncProvider.dll => moved successfully
C:\Windows\WinSxS\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6\OneDrive.ico => moved successfully
C:\Windows\WinSxS\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6\OneDrive.lnk => moved successfully
C:\Windows\WinSxS\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6\OneDriveSetup.exe => moved successfully
C:\Windows\WinSxS\Manifests\amd64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_db314eafc56dd1eb.manifest => moved successfully
C:\Windows\WinSxS\Manifests\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1.manifest => moved successfully
C:\Windows\WinSxS\Manifests\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5.manifest => moved successfully
C:\Windows\WinSxS\Manifests\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6.manifest => moved successfully
C:\Windows\WinSxS\Manifests\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0.manifest => moved successfully
C:\Windows\WinSxS\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\OneDriveSettingSyncProvider.dll => moved successfully
C:\Windows\WinSxS\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\r\OneDriveSettingSyncProvider.dll => moved successfully
C:\Windows\WinSxS\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\f\OneDriveSettingSyncProvider.dll => moved successfully
C:\Windows\WinSxS\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\SettingsHandlers_OneDriveBackup.dll => moved successfully
C:\Windows\WinSxS\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\r\SettingsHandlers_OneDriveBackup.dll => moved successfully
C:\Windows\WinSxS\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\f\SettingsHandlers_OneDriveBackup.dll => moved successfully
C:\Windows\WinSxS\amd64_microsoft-windows-s..ivebackup.resources_31bf3856ad364e35_10.0.19041.1_en-us_e257a95bc3c952cc\SettingsHandlers_OneDriveBackup.dll.mui => moved successfully
C:\Windows\SysWOW64\OneDrive.ico => moved successfully
C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll => moved successfully
C:\Windows\SysWOW64\OneDriveSetup.exe => moved successfully
C:\Windows\System32\OneDriveSettingSyncProvider.dll => moved successfully
C:\Windows\System32\SettingsHandlers_OneDriveBackup.dll => moved successfully
C:\Windows\System32\Tasks\OneDrive Reporting Task-S-1-5-21-3428103939-1962105336-1684995027-1002 => moved successfully
C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3428103939-1962105336-1684995027-1002 => moved successfully
C:\Windows\System32\en-US\SettingsHandlers_OneDriveBackup.dll.mui => moved successfully
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat => moved successfully
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat => moved successfully
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat => moved successfully
C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat => moved successfully
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat => moved successfully
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.mum => moved successfully
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat => moved successfully
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1.mum => moved successfully
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.cat => moved successfully
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1.mum => moved successfully
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1.cat => moved successfully
C:\Windows\servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1.mum => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1.manifest => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5.manifest => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0.manifest => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\r\onedrivesettingsyncprovider.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\f\onedrivesettingsyncprovider.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\r\onedrivesettingsyncprovider.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\f\onedrivesettingsyncprovider.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\r\settingshandlers_onedrivebackup.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\f\settingshandlers_onedrivebackup.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-holoshell.appxmain_31bf3856ad364e35_10.0.19041.546_none_0193b0cedf0d3cd3\r\promo_onedrive.png => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-holoshell.appxmain_31bf3856ad364e35_10.0.19041.546_none_0193b0cedf0d3cd3\f\promo_onedrive.png => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1.manifest => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5.manifest => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0.manifest => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\r\onedrivesettingsyncprovider.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0\f\onedrivesettingsyncprovider.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\r\onedrivesettingsyncprovider.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5\f\onedrivesettingsyncprovider.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\r\settingshandlers_onedrivebackup.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1\f\settingshandlers_onedrivebackup.dll => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-holoshell.appxmain_31bf3856ad364e35_10.0.19041.546_none_0193b0cedf0d3cd3\r\promo_onedrive.png => moved successfully
C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-holoshell.appxmain_31bf3856ad364e35_10.0.19041.546_none_0193b0cedf0d3cd3\f\promo_onedrive.png => moved successfully
C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk => moved successfully
C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk => moved successfully
C:\Users\TEMP.DESKTOP-F6HNTND.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk => moved successfully
C:\Users\TEMP.DESKTOP-F6HNTND.000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk => moved successfully
C:\Users\TEMP.DESKTOP-F6HNTND\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk => moved successfully
C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk => moved successfully
"C:\Users\Shamus\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\SL10OXHH\onedrive.liveDeleteValue: 1].xml" => not found
"C:\Users\Shamus\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\7IHTYKM5\onedrive-devices2DeleteValue: 1].svg" => not found
"C:\Users\Shamus\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\INetCache\221UL3MZ\icon-onedriveDeleteValue: 1].svg" => not found
C:\Users\Budgy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk => moved successfully
C:\Users\Budgy\AppData\Roaming\Microsoft\Windows\Recent\20230721_Avira weird uninstall.lnk => moved successfully
"C:\Users\Budgy\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\AC\Microsoft\Internet Explorer\DOMStore\L7JPI738\onedrive.liveDeleteValue: 1].xml" => not found

"C:\Windows\WinSxS\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1" folder move:

C:\Windows\WinSxS\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1 => moved successfully

"C:\Windows\WinSxS\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5" folder move:

C:\Windows\WinSxS\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5 => moved successfully

"C:\Windows\WinSxS\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6" folder move:

C:\Windows\WinSxS\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_10.0.19041.1_none_e585f901f9ce93e6 => moved successfully

"C:\Windows\WinSxS\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0" folder move:

C:\Windows\WinSxS\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0 => moved successfully

"C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1" folder move:

Could not move "C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1" => Scheduled to move on reboot.

"C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5" folder move:

Could not move "C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5" => Scheduled to move on reboot.

"C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0" folder move:

Could not move "C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3208.1.10\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0" => Scheduled to move on reboot.

"C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1" folder move:

Could not move "C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_10.0.19041.746_none_85b0efb7891980d1" => Scheduled to move on reboot.

"C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5" folder move:

Could not move "C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_43cc2896f6b4d6e5" => Scheduled to move on reboot.

"C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0" folder move:

Could not move "C:\Windows\servicing\LCU\Package_for_RollupFix~31bf3856ad364e35~amd64~~19041.3086.1.9\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_10.0.19041.1806_none_4e20d2e92b1598e0" => Scheduled to move on reboot.

"C:\Users\Shamus\OneDrive" folder move:

C:\Users\Shamus\OneDrive => moved successfully

"C:\Users\Shamus\AppData\Local\Microsoft\OneDrive" folder move:

C:\Users\Shamus\AppData\Local\Microsoft\OneDrive => moved successfully

"C:\Users\Budgy\OneDrive" folder move:

C:\Users\Budgy\OneDrive => moved successfully

"C:\Users\Budgy\AppData\Local\Microsoft\OneDrive" folder move:

C:\Users\Budgy\AppData\Local\Microsoft\OneDrive => moved successfully

"C:\ProgramData\Microsoft OneDrive" folder move:

C:\ProgramData\Microsoft OneDrive => moved successfully

"C:\FRST\Quarantine\C\Windows\system32\Tasks\Avira" folder move:

C:\FRST\Quarantine\C\Windows\system32\Tasks\Avira => moved successfully

"C:\FRST\Quarantine\C\Users\Shamus\AppData\Local\Avira" folder move:

C:\FRST\Quarantine\C\Users\Shamus\AppData\Local\Avira => moved successfully

"C:\FRST\Quarantine\C\Users\Budgy\AppData\Local\Avira" folder move:

C:\FRST\Quarantine\C\Users\Budgy\AppData\Local\Avira => moved successfully

"C:\FRST\Quarantine\C\Users\Budgy\AppData\Local\AviraWebView2Cache" folder move:

C:\FRST\Quarantine\C\Users\Budgy\AppData\Local\AviraWebView2Cache => moved successfully
"C:\FRST\Quarantine\C\Users\Budgy\AppData\Local\AviraWebView2Cache\EBWebView\Default\IndexedDB\https_spotlight.my.avira.com_0.indexeddb.leveldb" => not found

"C:\FRST\Quarantine\C\ProgramData\Avira" folder move:

C:\FRST\Quarantine\C\ProgramData\Avira => moved successfully

"C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Avira.Spotlight._8b1fe1546fb73afe46ef2e2964b415c9d1507b57_84d0adfb_002fa9ba-4e02-42d7-b0a4-f7d3b51e5a0a" folder move:

C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Avira.Spotlight._8b1fe1546fb73afe46ef2e2964b415c9d1507b57_84d0adfb_002fa9ba-4e02-42d7-b0a4-f7d3b51e5a0a => moved successfully

"C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Avira.Spotlight._8b1fe1546fb73afe46ef2e2964b415c9d1507b57_84d0adfb_a10b425e-f4d1-40fd-b662-64d4ae66b05f" folder move:

C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Avira.Spotlight._8b1fe1546fb73afe46ef2e2964b415c9d1507b57_84d0adfb_a10b425e-f4d1-40fd-b662-64d4ae66b05f => moved successfully

"C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Avira.Spotlight._6d9557a98631498e12c12461e35c32ce3caf99e1_1e0aca87_84044e9a-f0f3-417b-ade4-83cf13e82cdc" folder move:

C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Avira.Spotlight._6d9557a98631498e12c12461e35c32ce3caf99e1_1e0aca87_84044e9a-f0f3-417b-ade4-83cf13e82cdc => moved successfully

"C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Avira.Spotlight._fa79f81228ba382bf91728bb9c15af72bf795f_39db0307_49eff039-4e19-4c57-8c43-bf77cd323883" folder move:

C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_Avira.Spotlight._fa79f81228ba382bf91728bb9c15af72bf795f_39db0307_49eff039-4e19-4c57-8c43-bf77cd323883 => moved successfully

"C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira" folder move:

C:\FRST\Quarantine\C\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira => moved successfully
"C:\FRST\Quarantine\C\ProgramData\Avira\Security\Logs\Sentry\Avira.Spotlight.UI.Application" => not found

"C:\FRST\Quarantine\C\Program Files (x86)\Avira" folder move:

C:\FRST\Quarantine\C\Program Files (x86)\Avira => moved successfully

"C:\FRST\Quarantine\C\Program Files\Avira" folder move:

C:\FRST\Quarantine\C\Program Files\Avira => moved successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{099EB73C-FF12-45C5-BF64-F0277733A6E2}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{099EB73C-FF12-45C5-BF64-F0277733A6E2}\InProcServer32\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{34212D32-6E9E-11E2-BDA0-6B2B6288709B}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{34212D32-6E9E-11E2-BDA0-6B2B6288709B}\InProcServer32\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3FC77A3B-14C6-41B6-ACC5-ED80223D81C4}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3FC77A3B-14C6-41B6-ACC5-ED80223D81C4}\InProcServer32\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{78DE489B-7931-4f14-83B4-C56D38AC9FFA}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{86c815aa-4888-4063-b0ab-03c49f788be4}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D6ABE021-1DE0-49F4-895D-E9694D28F0A4}\InProcServer32\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDB93701-527B-4250-B619-672EFD3C5B21}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DDB93701-527B-4250-B619-672EFD3C5B21}\InProcServer32\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{081175B7-D324-55C8-8363-E0EF340B4552}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0DF05B8F-C752-5855-86B4-4D7D89FA08D8}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{426317B8-C7D2-4647-AD76-2554806561B6}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9153BF48-3D44-4D3C-976A-FA62FFF6DDAC}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E89C17A1-D22E-4235-9A2E-F141FB977E7B}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{099EB73C-FF12-45C5-BF64-F0277733A6E2}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{099EB73C-FF12-45C5-BF64-F0277733A6E2}\InProcServer32\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{34212D32-6E9E-11E2-BDA0-6B2B6288709B}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{34212D32-6E9E-11E2-BDA0-6B2B6288709B}\InProcServer32\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3FC77A3B-14C6-41B6-ACC5-ED80223D81C4}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3FC77A3B-14C6-41B6-ACC5-ED80223D81C4}\InProcServer32\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{78DE489B-7931-4f14-83B4-C56D38AC9FFA}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{D6ABE021-1DE0-49F4-895D-E9694D28F0A4}\InProcServer32\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{DDB93701-527B-4250-B619-672EFD3C5B21}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{DDB93701-527B-4250-B619-672EFD3C5B21}\InProcServer32\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{081175B7-D324-55C8-8363-E0EF340B4552}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{0DF05B8F-C752-5855-86B4-4D7D89FA08D8}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{426317B8-C7D2-4647-AD76-2554806561B6}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneDriveFileSync\\RegKeyPathRedirect" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_OneBackup_OneDriveBackup\\DllPath" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageDetect\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~0.0.0.0\\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageDetect\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~0.0.0.0\\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~0.0.0.0\\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~0.0.0.0\\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~0.0.0.0\\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~0.0.0.0\\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1\\InstallName" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1\\InstallName" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1\\InstallName" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1\\InstallName" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\OptIn\\URL" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\OptOut\\URL" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\\Name" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\\Name" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\\Name" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\\Name" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\\RelativePath" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\\Name" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps\\RegistryRoot" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps\\SettingUnitId" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}\\ResourceFileName" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}\\MessageFileName" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}\ChannelReferences\0\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}\ChannelReferences\1\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f43c3c35-22e2-53eb-f169-07594054779e}\ChannelReferences\2\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53464712-4078-44F8-A926-31D4A006C1F9}\\Path" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{53464712-4078-44F8-A926-31D4A006C1F9}\\URI" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6101EE54-8F4A-472F-9A16-C703889825D7}\\Path" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6101EE54-8F4A-472F-9A16-C703889825D7}\\URI" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserDefaults\\ExcludeProfileDirs" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\OptIn\\URL" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\OptOut\\URL" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE}\\Name" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{339719B5-8C47-4894-94C2-D8F77ADD44A6}\\Name" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{767E6811-49CB-4273-87C2-20F355E1085B}\\Name" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\\Name" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A52BBA46-E9E1-435f-B3D9-28DAA648C0F6}\\RelativePath" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C3F2459E-80D6-45DC-BFEF-1F769F2BE730}\\Name" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps\\RegistryRoot" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps\\SettingUnitId" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\ShellCompatibility\InboxApp\\14BB934C8A478762_OneDrive_lnk_wow64.lnk" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1002\\\Device\HarddiskVolume3\Users\Budgy\AppData\Local\Microsoft\OneDrive\OneDrive.exe" => removed successfully
"HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\OneDriveSetup" => removed successfully
"HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\OneDriveSetup" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\Environment\\OneDrive" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\19.043.0304.0013_1\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\23.043.0226.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\23.107.0521.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\23.122.0611.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\23.132.0625.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Shamus\AppData\Local\Microsoft\OneDrive\23.137.0702.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\ExcludeProfileDirs" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\grvopen\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\grvopen\DefaultIcon\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\grvopen\shell\open\command\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CMicrosoft.Windows.SecHealthUI%5CMicrosoft.Windows.SecHealthUI.pri\1d93de4f06ee54b\cb0fbae5\\@{windows?ms-resource://Microsoft.Windows.SecHealthUI/resources/RansomwareProtection_HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5\\@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPageGroup_GranularCloudSearch/HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5\\@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPageGroup_Search_GranularCloudSearch/HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5\\@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAppRequestedDownloads-2/HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5\\@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAppRequestedDownloads/HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5\\@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SystemSettings_Personalize_LockScreenSlideshowSource_CloudBrandName/HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\Environment\\OneDrive" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.microsoft.onedrive.nucleus.auth.provider\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\\OneDrive.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\\CurrentVersionPath" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\\OneDriveTrigger" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\\LastRunOneDriveVersion" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\\OduDownloadOneDriveSetupStartTime" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\\OduDownloadOneDriveSetupEndTime" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\23.147.0716.0001\\InstallPath" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\23.147.0716.0001\\InstallPaths" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\Accounts\Business1\\OneDriveDeviceId" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\Accounts\Personal\\OneDriveDeviceId" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive\Capabilities\URLAssociations\\Explorer.CameraRoll.Import" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\OneDrive" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneDriveSetup.exe\\DisplayName" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneDriveSetup.exe\\DisplayIcon" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneDriveSetup.exe\\UninstallString" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.011.0115.0009\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.020.0125.0003\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.028.0205.0002\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.033.0212.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.038.0219.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.043.0226.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.048.0305.0002\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.054.0313.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.076.0409.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.081.0416.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.086.0423.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.091.0430.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\OneDrive.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.096.0507.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.101.0514.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.107.0521.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.114.0530.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.119.0606.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.122.0611.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.127.0618.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.132.0625.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.137.0702.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\23.147.0716.0001\FileSyncConfig.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\\C:\Users\Budgy\AppData\Local\Microsoft\OneDrive\OneDrive.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\ExcludeProfileDirs" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\RegisteredApplications\\OneDrive" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\.fluid\shell\open\command\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\.loop\shell\open\command\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\.note\shell\open\command\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\.whiteboard\shell\open\command\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\DefaultIcon\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{07CA83F0-DF06-4E67-89DD-E80924A49512}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{0827D883-485C-4D62-BA2C-A332DBF3D4B0}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{20894375-46AE-46E2-BAFD-CB38975CDCE6}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{2e7c0a19-0438-41e9-81e3-3ad3d64f55ba}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{5999E1EE-711E-48D2-9884-851A709F543D}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{6bb93b4e-44d8-40e2-bd97-42dbcf18a40f}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{9AA2F32D-362A-42D9-9328-24A483E2CCC3}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{A3CA1CF4-5F3E-4AC0-91B9-0D3716E1EAC3}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\CLSID\{F37369D9-1C22-40A0-A997-0B4D5F7B6637}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\grvopen\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\grvopen\DefaultIcon\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\grvopen\shell\open\command\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Interface\{6A821279-AB49-48F8-9A27-F6C59B4FF024}\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Interface\{A91EFACB-8B83-4B84-B797-1C8CF3AB3DCB}\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Interface\{B05D37A9-03A2-45CF-8850-F660DF0CBF07}\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Interface\{C47B67D4-BA96-44BC-AB9E-1CAC8EEA9E93}\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CMicrosoft.Windows.SecHealthUI%5CMicrosoft.Windows.SecHealthUI.pri\1d93de4f06ee54b\cb0fbae5\\@{windows?ms-resource://Microsoft.Windows.SecHealthUI/resources/RansomwareProtection_HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5\\@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPageGroup_GranularCloudSearch/HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5\\@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPageGroup_Search_GranularCloudSearch/HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5\\@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAppRequestedDownloads-2/HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5\\@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SettingsPagePrivacyAppRequestedDownloads/HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\MrtCache\C:%5CWindows%5CSystemResources%5CWindows.UI.SettingsAppThreshold%5CWindows.UI.SettingsAppThreshold.pri\1d9b491a0b54480\cb0fbae5\\@{windows?ms-resource://Windows.UI.SettingsAppThreshold/SearchResources/SystemSettings_Personalize_LockScreenSlideshowSource_CloudBrandName/HighKeywords}" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\mssharepointclient\DefaultIcon\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\mssharepointclient\shell\open\command\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\odopen\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\odopen\DefaultIcon\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\odopen\shell\open\command\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\OneDrive.CameraRoll.Import\shell\open\command\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{082D3FEC-D0D0-4DF6-A988-053FECE7B884}\1.0\0\win64\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{082D3FEC-D0D0-4DF6-A988-053FECE7B884}\1.0\HELPDIR\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{4B1C80DA-FA45-468F-B42B-46496BDBE0C5}\1.0\0\win64\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{4B1C80DA-FA45-468F-B42B-46496BDBE0C5}\1.0\HELPDIR\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{638805C3-4BA3-4AC8-8AAC-71A0BA2BC284}\1.0\0\win64\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{638805C3-4BA3-4AC8-8AAC-71A0BA2BC284}\1.0\HELPDIR\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{909A6CCD-6810-46C4-89DF-05BE7EB61E6C}\1.0\0\win64\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{909A6CCD-6810-46C4-89DF-05BE7EB61E6C}\1.0\HELPDIR\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{BAE13F6C-0E2A-4DEB-AA46-B8F55319347C}\1.0\0\win64\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{BAE13F6C-0E2A-4DEB-AA46-B8F55319347C}\1.0\HELPDIR\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{C9F3F6BB-3172-4CD8-9EB7-37C9BE601C87}\1.0\0\win32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{C9F3F6BB-3172-4CD8-9EB7-37C9BE601C87}\1.0\0\win64\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{C9F3F6BB-3172-4CD8-9EB7-37C9BE601C87}\1.0\HELPDIR\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{F904F88C-E60D-4327-9FA2-865AD075B400}\1.0\0\win32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\TypeLib\{F904F88C-E60D-4327-9FA2-865AD075B400}\1.0\HELPDIR\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\DefaultIcon\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{021E4F06-9DCC-49AD-88CF-ECC2DA314C8A}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{07CA83F0-DF06-4E67-89DD-E80924A49512}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{0827D883-485C-4D62-BA2C-A332DBF3D4B0}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{20894375-46AE-46E2-BAFD-CB38975CDCE6}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{389510b7-9e58-40d7-98bf-60b911cb0ea9}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{47E6DCAF-41F8-441C-BD0E-A50D5FE6C4D1}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{917E8742-AA3B-7318-FA12-10485FB322A2}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{94269C4E-071A-4116-90E6-52E557067E4E}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{9489FEB2-1925-4D01-B788-6D912C70F7F2}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{9AA2F32D-362A-42D9-9328-24A483E2CCC3}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{A926714B-7BFC-4D08-A035-80021395FFA8}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{C5FF006E-2AE9-408C-B85B-2DFDD5449D9C}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\CLSID\{F37369D9-1C22-40A0-A997-0B4D5F7B6637}\LocalServer32\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\Interface\{6A821279-AB49-48F8-9A27-F6C59B4FF024}\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\Interface\{A91EFACB-8B83-4B84-B797-1C8CF3AB3DCB}\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\Interface\{B05D37A9-03A2-45CF-8850-F660DF0CBF07}\\" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\WOW6432Node\Interface\{C47B67D4-BA96-44BC-AB9E-1CAC8EEA9E93}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Launcher\\AcpNamedPipeName" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Launcher\\InstallationPath" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Security\\ExternalNamedPipe" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Security\ConnectServices\\AuthToken" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Security\Resources\\Cache.Profile" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira\Security\Resources\\Cache.Device" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\AMSI\Providers\{00000001-3DCC-4B48-A82E-E2071FE58E05}\\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\X-AVCSD\EndpointProtection\\MasterKey" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\X-AVCSD\EndpointProtection\\Avira" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\X-AVCSD\Launcher\\Avira" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\X-AVCSD\Launcher\\MasterKey" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurity\\ImagePath" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurity\\DisplayName" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurity\\Description" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurity\\FailureCommand" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurityUpdater\\ImagePath" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurityUpdater\\DisplayName" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurityUpdater\\Description" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1001\\\Device\HarddiskVolume4\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230724_from Shamus\FRST64.exe" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1001\\\Device\HarddiskVolume4\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230725\FRST64.exe" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1001\\\Device\HarddiskVolume4\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230726\FRST64.exe" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1001\\\Device\HarddiskVolume4\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230728\FRST64.exe" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3428103939-1962105336-1684995027-1001\\\Device\HarddiskVolume4\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230729\FRST64.exe" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BdNet\\DisplayName" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BdSentry\\DisplayName" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BdSentry\\Description" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BdSentry\Parameters\ConfigDevice\\BootOpsCfg" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BdSentry\Parameters\ConfigDevice\\BootOpsLog" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EndpointProtectionService\\ImagePath" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EndpointProtectionService2\\ImagePath" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_elam\\Description" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filesystem_filter\\AviraDriverStatus" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\\AviraDriverStatus" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\\Description" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\\ClientPath" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\\LicensePath" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\\AviraRegAcl" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\\AviraFileAcl" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\\AviraProcessTrust" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\\AviraProcessProtection" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\WscAgent\\RemediationPath" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_filter\WscAgent\\DisplayName" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor\\ClientPath" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor\\LicensePath" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor\\AviraRegAcl" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor\\AviraFileAcl" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor\\AviraDriverStatus" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor\WscAgent\\DisplayName" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rtp_process_monitor\WscAgent\\RemediationPath" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL\\Avira.Spotlight.UI.Application.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\\Avira.Spotlight.UI.Application.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230728\FRST64.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\D:\Installers\Avira\avira_en_sptl1_610379103-1676208366__pavwws-spotlight-release.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\D:\Installers\Avira\avira_en_sptl1_589eb78b2b63221f__phpws-spotlight-release.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230724_from Shamus\FRST64.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230725\FRST64.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230728\FRST64.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230729\FRST64.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\files\4\\path" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\files\5\\path" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\files_bak\3\\path" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\files_bak\4\\path" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\Sequence\\D:/D/IT issues/Lenovo_X1C/20230721_Avira weird uninstall/20230721_0854hrs_BalarcScan.pdf" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\pdf\RecentFiles\Sequence\\D:/D/IT issues/Lenovo_X1C/20230721_Avira weird uninstall/Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help - Virus, Trojan, Spyware, and Malware Removal Help.pdf" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\pdf\\4" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\pdf\\5" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\wps\\2" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\wpsoffice\\9" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\wpsoffice\\10" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\plugins\ksomisc\RecentFiles\wpsoffice\\14" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\wps\RecentFiles\files\2\\path" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\wps\RecentFiles\files_bak\2\\path" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\kingsoft\Office\6.0\wps\RecentFiles\Sequence\\D:/D/IT issues/Lenovo_X1C/20230721_Avira weird uninstall/20230721_My case notes.docx" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL\\Avira.Spotlight.UI.Application.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL\\Avira.Spotlight.UI.Application.Messaging.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\\Avira.Spotlight.UI.Application.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\\Avira.Spotlight.UI.Application.Messaging.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppBadgeUpdated\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Avira\Security\Avira.Spotlight.UI.Application.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Avira\Security\Avira.Spotlight.UI.Application.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230725\FRST64.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Avira\VPN\Avira.WebAppHost.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Avira\Security\Avira.Spotlight.UI.Application.exe" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST 20230722\FRST64.exe.FriendlyAppName" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST 20230722\FRST64.exe.ApplicationCompany" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230725\FRST64.exe.FriendlyAppName" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230725\FRST64.exe.ApplicationCompany" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230729\FRST64.exe.FriendlyAppName" => removed successfully
"HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\D:\D\IT issues\Lenovo_X1C\20230721_Avira weird uninstall\FRST_20230729\FRST64.exe.ApplicationCompany" => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\ADMX_UserExperienceVirtualization\MicrosoftOffice2013OneDriveForBusiness => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\ADMX_UserExperienceVirtualization\MicrosoftOffice2016OneDriveForBusiness => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\System\DisableOneDriveFileSync => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemSettings\SettingId\SystemSettings_OneBackup_OneDriveBackup => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageDetect\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~0.0.0.0 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageDetect\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~0.0.0.0 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~0.0.0.0 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~0.0.0.0 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~0.0.0.0 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\PackageIndex\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~0.0.0.0 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.19041.1 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.19041.1 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-OneDrive-Setup-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\OneDriveRamps => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft-windows-onedrive-setup_31bf3856ad364e35_none_5154c8ab59350670 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft-windows-s..lers-onedrivebackup_31bf3856ad364e35_none_3f91f088ca83ebb4 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_none_4415c8f172a00240 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\wow64_microsoft-windows-onedrive-setup_31bf3856ad364e35_none_5ba972fd8d95c86b => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\wow64_microsoft-windows-settingsync-onedrive_31bf3856ad364e35_none_4e6a7343a700c43b => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SettingSync-OneDrive/Analytic => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SettingSync-OneDrive/Debug => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SettingSync-OneDrive/Operational => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Reporting Task-S-1-5-21-3428103939-1962105336-1684995027-1002" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OneDrive Standalone Update Task-S-1-5-21-3428103939-1962105336-1684995027-1002" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\CloudExperienceHostBroker.SyncEngine.OOBEOneDriveOptin" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\CloudExperienceHostBroker.SyncEngine.OOBEOneDriveOptinCore" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\CloudExperienceHostBroker.SyncEngine.OOBEOneDriveOptinCoreForUser" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Internal.System.UserProfile.OneDriveEngagementManager" => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\OneDriveRamps => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SettingSync\WindowsSettingHandlers\OneDriveRamps => removed successfully
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\OneDrive => removed successfully
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\OneDrive => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Microsoft\OneDrive => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.microsoft.onedrive.nucleus.auth.provider => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\OneDrive => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OneDriveFileLauncher.exe => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\ProviderId\OneDriveDesktop => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\ProviderId\OneDriveDocuments => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\ProviderId\OneDriveLocal => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\ProviderId\OneDrivePictures => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BannerStore\ProviderId\OneDriveSync => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StorageProvider\OneDrive => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OneDriveSetup.exe => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\AppID\OneDrive.EXE => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Classes\OneDrive.CameraRoll.Import => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avira => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Avira_RASAPI32 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Avira_RASMANCS => removed successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurity => removed successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AviraSecurityUpdater => removed successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\Avira Phantom VPN => removed successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\AviraSecurity => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1001\SOFTWARE\Avira => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Avira => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\DOMStorage\avira.com => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\DOMStorage\spotlight.my.avira.com => removed successfully
HKEY_USERS\S-1-5-21-3428103939-1962105336-1684995027-1002\SOFTWARE\Microsoft\Internet Explorer\DOMStorage\www.avira.com => removed successfully

========= chkdsk =========

The type of the file system is NTFS.
Volume label is Data.

WARNING! /F parameter not specified.
Running CHKDSK in read-only mode.

Stage 1: Examining basic file system structure ...
Progress: 0 of 44032 done; Stage: 0%; Total: 0%; ETA: 0:02:08
Progress: 43193 of 44032 done; Stage: 98%; Total: 33%; ETA: 0:01:26 .
Progress: 44032 of 44032 done; Stage: 100%; Total: 34%; ETA: 0:01:26 ..


44032 file records processed.

File verification completed.
Phase duration (File record verification): 456.10 milliseconds.
Progress: 456 of 456 done; Stage: 100%; Total: 28%; ETA: 0:01:48 ...


456 large file records processed.

Phase duration (Orphan file record recovery): 0.00 milliseconds.
Progress: 0 of 0 done; Stage: 99%; Total: 28%; ETA: 0:01:48


0 bad file records processed.

Phase duration (Bad file record checking): 0.03 milliseconds.

Stage 2: Examining file name linkage ...
Progress: 904 of 904 done; Stage: 100%; Total: 58%; ETA: 0:01:05 .


904 reparse records processed.

Progress: 45345 of 55204 done; Stage: 82%; Total: 65%; ETA: 0:00:54 ..
Progress: 49117 of 55204 done; Stage: 88%; Total: 79%; ETA: 0:00:01 ...
Progress: 55204 of 55204 done; Stage: 100%; Total: 80%; ETA: 0:00:01


55204 index entries processed.

Index verification completed.
Phase duration (Index verification): 1.08 seconds.
Progress: 0 of 0 done; Stage: 99%; Total: 80%; ETA: 0:00:01 .


0 unindexed files scanned.

Phase duration (Orphan reconnection): 17.59 milliseconds.
Progress: 0 of 0 done; Stage: 99%; Total: 80%; ETA: 0:00:01 ..


0 unindexed files recovered to lost and found.

Phase duration (Orphan recovery to lost and found): 0.03 milliseconds.
Progress: 904 of 904 done; Stage: 100%; Total: 80%; ETA: 0:00:01 ...


904 reparse records processed.

Phase duration (Reparse point and Object ID verification): 6.24 milliseconds.

Stage 3: Examining security descriptors ...
Security descriptor verification completed.
Phase duration (Security descriptor verification): 1.40 milliseconds.
Progress: 0 of 0 done; Stage: 100%; Total: 99%; ETA: 0:00:00


5586 data files processed.

Phase duration (Data attribute verification): 0.03 milliseconds.

Windows has scanned the file system and found no problems.
No further action is required.

578322428 KB total disk space.
427381964 KB in 37851 files.
18628 KB in 5588 indexes.
0 KB in bad sectors.
127640 KB in use by the system.
65536 KB occupied by the log file.
150794196 KB available on disk.

4096 bytes in each allocation unit.
144580607 total allocation units on disk.
37698549 allocation units available on disk.
Total duration: 1.56 seconds (1567 ms).

========= End of CMD: =========

========= sfc /scannow =========

Beginning system scan. This process will take some time.

Beginning verification phase of system scan.

Verification 0% complete.
Verification 1% complete.
Verification 1% complete.
Verification 2% complete.
Verification 3% complete.
Verification 3% complete.
Verification 4% complete.
Verification 5% complete.
Verification 5% complete.
Verification 6% complete.
Verification 6% complete.
Verification 7% complete.
Verification 8% complete.
Verification 8% complete.
Verification 9% complete.
Verification 10% complete.
Verification 10% complete.
Verification 11% complete.
Verification 11% complete.
Verification 12% complete.
Verification 13% complete.
Verification 13% complete.
Verification 14% complete.
Verification 15% complete.
Verification 15% complete.
Verification 16% complete.
Verification 16% complete.
Verification 17% complete.
Verification 18% complete.
Verification 18% complete.
Verification 19% complete.
Verification 20% complete.
Verification 20% complete.
Verification 21% complete.
Verification 21% complete.
Verification 22% complete.
Verification 23% complete.
Verification 23% complete.
Verification 24% complete.
Verification 25% complete.
Verification 25% complete.
Verification 26% complete.
Verification 26% complete.
Verification 27% complete.
Verification 28% complete.
Verification 28% complete.
Verification 29% complete.
Verification 30% complete.
Verification 30% complete.
Verification 31% complete.
Verification 32% complete.
Verification 32% complete.
Verification 33% complete.
Verification 33% complete.
Verification 34% complete.
Verification 35% complete.
Verification 35% complete.
Verification 36% complete.
Verification 37% complete.
Verification 37% complete.
Verification 38% complete.
Verification 38% complete.
Verification 39% complete.
Verification 40% complete.
Verification 40% complete.
Verification 41% complete.
Verification 42% complete.
Verification 42% complete.
Verification 43% complete.
Verification 43% complete.
Verification 44% complete.
Verification 45% complete.
Verification 45% complete.
Verification 46% complete.
Verification 47% complete.
Verification 47% complete.
Verification 48% complete.
Verification 48% complete.
Verification 49% complete.
Verification 50% complete.
Verification 50% complete.
Verification 51% complete.
Verification 52% complete.
Verification 52% complete.
Verification 53% complete.
Verification 53% complete.
Verification 54% complete.
Verification 55% complete.
Verification 55% complete.
Verification 56% complete.
Verification 57% complete.
Verification 57% complete.
Verification 58% complete.
Verification 58% complete.
Verification 59% complete.
Verification 60% complete.
Verification 60% complete.
Verification 61% complete.
Verification 62% complete.
Verification 62% complete.
Verification 63% complete.
Verification 64% complete.
Verification 64% complete.
Verification 65% complete.
Verification 65% complete.
Verification 66% complete.
Verification 67% complete.
Verification 67% complete.
Verification 68% complete.
Verification 69% complete.
Verification 69% complete.
Verification 70% complete.
Verification 70% complete.
Verification 71% complete.
Verification 72% complete.
Verification 72% complete.
Verification 73% complete.
Verification 74% complete.
Verification 74% complete.
Verification 75% complete.
Verification 75% complete.
Verification 76% complete.
Verification 77% complete.
Verification 77% complete.
Verification 78% complete.
Verification 79% complete.
Verification 79% complete.
Verification 80% complete.
Verification 80% complete.
Verification 81% complete.
Verification 82% complete.
Verification 82% complete.
Verification 83% complete.
Verification 84% complete.
Verification 84% complete.
Verification 85% complete.
Verification 85% complete.
Verification 86% complete.
Verification 87% complete.
Verification 87% complete.
Verification 88% complete.
Verification 89% complete.
Verification 89% complete.
Verification 90% complete.
Verification 90% complete.
Verification 91% complete.
Verification 92% complete.
Verification 92% complete.
Verification 93% complete.
Verification 94% complete.
Verification 94% complete.
Verification 95% complete.
Verification 96% complete.
Verification 96% complete.
Verification 97% complete.
Verification 97% complete.
Verification 98% complete.
Verification 99% complete.
Verification 99% complete.
Verification 100% complete.

Windows Resource Protection found corrupt files but was unable to fix some of them.

For online repairs, details are included in the CBS log file located at

windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. For offline

repairs, details are included in the log file provided by the /OFFLOGFILE flag.

========= End of CMD: =========

========= type "C:\Window\System32\Logfiles\Srt\SrtTrail.txt" =========

The system cannot find the path specified.

========= End of CMD: =========

Infection exposure risk concern and incomplete Avira AntiVirus uninstall - Page 2 - Virus, Trojan, Spyware, and Malware Removal Help (2024)
Top Articles
Latest Posts
Article information

Author: Rev. Porsche Oberbrunner

Last Updated:

Views: 6011

Rating: 4.2 / 5 (73 voted)

Reviews: 88% of readers found this page helpful

Author information

Name: Rev. Porsche Oberbrunner

Birthday: 1994-06-25

Address: Suite 153 582 Lubowitz Walks, Port Alfredoborough, IN 72879-2838

Phone: +128413562823324

Job: IT Strategist

Hobby: Video gaming, Basketball, Web surfing, Book restoration, Jogging, Shooting, Fishing

Introduction: My name is Rev. Porsche Oberbrunner, I am a zany, graceful, talented, witty, determined, shiny, enchanting person who loves writing and wants to share my knowledge and understanding with you.