Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Atten: dennis_l | 2nd Computer hangs terribly also


  • Please log in to reply
46 replies to this topic

#16 ramesh help

ramesh help
  • Topic Starter

  •  Avatar image
  • Members
  • 105 posts
  • ONLINE
  •  
  • Local time:09:15 PM

Posted 13 November 2024 - 05:30 AM

1) Attached. file too big

 

2) Am doing the other 2 more pending. will get back to you soon

Attached Files


Edited by ramesh help, 13 November 2024 - 05:31 AM.


BC AdBot (Login to Remove)

 


#17 ramesh help

ramesh help
  • Topic Starter

  •  Avatar image
  • Members
  • 105 posts
  • ONLINE
  •  
  • Local time:09:15 PM

Posted 13 November 2024 - 07:17 AM

Microsoft Windows [Version 10.0.22631.4391]
© Microsoft Corporation. All rights reserved.
 
C:\Windows\System32>DISM /Online /Cleanup-Image /RestoreHealth
 
Deployment Image Servicing and Management tool
Version: 10.0.22621.2792
 
Image Version: 10.0.22631.4391
 
[==========================100.0%==========================] The restore operation completed successfully.
The operation completed successfully.
 
C:\Windows\System32>


#18 ramesh help

ramesh help
  • Topic Starter

  •  Avatar image
  • Members
  • 105 posts
  • ONLINE
  •  
  • Local time:09:15 PM

Posted 13 November 2024 - 07:22 AM

only 2 windows update found.

 

attached task manager as image

 

whats next? incase you wanted to know, the machine still hangs very much.

Attached Files

  • Attached File  y1.jpg   89.14KB   0 downloads


#19 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 4,142 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:15 PM

Posted 13 November 2024 - 08:58 AM

In Windows Update click on Update History and advise which updates were installed this month.
I will check the search.txt, but in the meantime please note the times that the hangs occur today .
Also if they happen when a particular action is carried out and if you have to restart the computer to get working again.

Then please do this

FullEventLogView by Nirsoft

  • Download FullEventLogView by Nirsoft and save it to your Desktop.
  • Right click on the folder and select Extract All, to extract the folder onto your Desktop.
  • Open the fulleventlogview-x64 folder, right click on FullEventLogView (Application) and select Run as administrator.
  • Monitor the lower left hand corner of the screen until the Loading no longer appears and a total of items are listed.
  • Click Edit > Select All.
  • Click File > Save Selected Items.
  • Save the file onto your Desktop as NirsoftEV.txt
  • Please Zip and upload the file here

.

 



#20 ramesh help

ramesh help
  • Topic Starter

  •  Avatar image
  • Members
  • 105 posts
  • ONLINE
  •  
  • Local time:09:15 PM

Posted 13 November 2024 - 09:18 AM

For windows update

 

other updates
Windows Malicious Software Removal Tool x64 - v5.130 (KB890830)
 
Definition updates
Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.421.266.0) - Current Channel (Broad)
 
Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.421.251.0) - Current Channel (Broad)
 
Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.421.245.0) - Current Channel (Broad)
 
quality update
2024-11 Cumulative Update for .NET Framework 3.5 and 4.8.1 for Windows 11, version 23H2 for x64 (KB5045935)
 
2024-11 .NET 6.0.36 Update for x64 Client (KB5047486)
 
2024-10 Cumulative Update Preview for Windows 11 Version 23H2 for x64-based Systems (KB5044380)
 
2024-10 .NET 6.0.35 Security Update for x64 Client (KB5045998)
 
 
 
 
for the logview, uploded into bleepingcomputer url link but limit file of 10mb. my file is 142mb.
URL will last for 7 days via freehostting file uploader website
 
 
 
The hanging happens randomly. example starting computer afer login, or opening browser or plugin usb or open any file etc. no fixed pattern to identify exactly

Edited by ramesh help, 13 November 2024 - 09:18 AM.


#21 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 4,142 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:15 PM

Posted 13 November 2024 - 09:38 AM

I will check through the file you uploaded.

Windows Update hasn't pulled in the Cumulative November update yet.

Please try again and if there is a problem please run the Windows Updater Troubleshooter, as follows.

Select Start  > Settings  > Update & Security   > Troubleshoot > Additional troubleshooters.
Next, under Get up and running, select Windows Update > Run the troubleshooter.
If this doesn't fix things, then please advise details of any errors reported.



#22 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 4,142 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:15 PM

Posted 13 November 2024 - 10:27 AM

Here is the Kaspersky removal script for the second computer.

  • Right click on the FRST icon and select Run as administrator.
  • Highlight all of the information in the text box below then hit the Ctrl + C keys together to copy the text.
  • It is not necessary to paste the information anywhere as FRST will do this for you.
Start::
CreateRestorePoint:
CloseProcesses:
C:\Windows\System32\winevt\Logs\Kaspersky Event Log.evtx
C:\Windows\System32\Tasks_Migrated\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
C:\ProgramData\Kaspersky Lab
2024-02-14 17:14 - 2024-02-14 17:14 _____ C:\Users\user\AppData\Local\Packages\Kaspersky.ShellEx16_b81m8cbssw9gt
2023-11-22 11:07 - 2023-11-22 11:08 _____ C:\Users\user\AppData\Local\Packages\Kaspersky.ShellEx_b81m8cbssw9gt
2022-11-29 12:23 - 2022-11-29 12:23 _____ C:\Users\Default\AppData\Local\Kaspersky Lab
2023-11-22 10:42 - 2023-11-22 11:17 _____ C:\ProgramData\Kaspersky Lab Setup Files
2024-02-14 17:14 - 2024-02-14 17:14 _____ C:\ProgramData\Packages\Kaspersky.ShellEx16_b81m8cbssw9gt
2023-11-22 11:08 - 2023-11-22 11:08 _____ C:\ProgramData\Packages\Kaspersky.ShellEx_b81m8cbssw9gt
2022-11-29 12:18 - 2024-11-12 19:29 _____ C:\Program Files (x86)\Kaspersky Lab
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.3\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.3\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\UCPStorage\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.3\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.3\Temp\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.3\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Bases\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Data\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\KDSROOT\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\ipm\control\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\ipm\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.9\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.9\Temp\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.9\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.13\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.13\Temp\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.13\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.14\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.14\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.15\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-15\klhk\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-15\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.16\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.16\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-16\klhk\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-16\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\StartMenu\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-17\klhk\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-17\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klifx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\cm_km_x64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\x64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klbackupdiskx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klbackupfltx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\kldiskx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klelam_x64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klimx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klkbdfltx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klmoufltx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klpdx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klpnpfltx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klwtpx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\knepsx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.18\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.18\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-18\klhk\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-18\
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\NetworkDriverBackup\Control\Network\{4d36e972-e325-11ce-bfc1-08002be10318}\Descriptions|Kaspersky VPN
DeleteValue: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt%5Cresources.pri\1da5f2631431b27\bdcd4f7b|@{C:\Program Files\WindowsApps\Kaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt\resources.pri? ms-resource:///resources/DisplayName}
DeleteValue: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx17_1.0.0.6_x64__b81m8cbssw9gt%5Cresources.pri\1dac37c99d40acc\bdcd4f7b|@{C:\Program Files\WindowsApps\Kaspersky.ShellEx17_1.0.0.6_x64__b81m8cbssw9gt\resources.pri? ms-resource:///resources/DisplayName}
DeleteValue: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt%5Cresources.pri\1da1cf1a6f10c\bdcd4f7b|@{C:\Program Files\WindowsApps\Kaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt\resources.pri? ms-resource:///resources/DisplayName}
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.9\ksde.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\ProgramData\Kaspersky Lab\KSDE5.9\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\ProgramData\Kaspersky Lab\KSDE5.13\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 10.2\kpm.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.15\avp.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\ProgramData\Kaspersky Lab\AVP21.15\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.16\avp.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.14\ksde.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\ProgramData\Kaspersky Lab\AVP21.16\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\avp.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\ProgramData\Kaspersky Lab\AVP21.17\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.18\avp.exe
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\UserData\UninstallTimes|Kaspersky.ShellEx17_b81m8cbssw9gt
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData|KasperskyLab.Kis.UI.Toasts
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\avpui.exe
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.14\ksdeui.exe
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 10.2\kpm.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 10.2\kpm.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\KSDE5.14\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\KSDE5.14\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_DB1281A1-88E0-11EE-975F-B445068CF65B\startup.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_DB1281A1-88E0-11EE-975F-B445068CF65B\startup.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_9C608EDE-88E5-11EE-9760-B445068CF65B\startup.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_9C608EDE-88E5-11EE-9760-B445068CF65B\startup.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\AVP21.15\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\AVP21.15\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\AVP21.16\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\AVP21.16\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.ApplicationCompany
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\Kaspersky Standard 21.15
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\Kaspersky Standard 21.16
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\Kaspersky.ShellEx17_b81m8cbssw9gt
 DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab\AVP21.17\Data\Agreements\MyKaspersky
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab\AVP21.17\Data\Agreements\MyKasperskyFeatures
DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Kaspersky Event Log
DeleteKey: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt%5Cresources.pri
DeleteKey: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx17_1.0.0.6_x64__b81m8cbssw9gt%5Cresources.pri
DeleteKey: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt%5Cresources.pri
DeleteKey: HKEY_USERS\.DEFAULT\Software\KasperskyLab
DeleteKey: HKEY_USERS\.DEFAULT\Software\KasperskyLabSetup
DeleteKey: HKEY_USERS\S-1-5-19\Software\KasperskyLab
DeleteKey: HKEY_USERS\S-1-5-20\Software\KasperskyLab
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\KasperskyLab
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\KasperskyLabSetup
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\AppHost\IndexedDB\Kaspersky.ShellEx16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\AppHost\IndexedDB\Kaspersky.ShellEx_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications\Kaspersky.ShellEx16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications\Kaspersky.ShellEx17_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications\Kaspersky.ShellEx_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.kis.ui.toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.ksde.ui.toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}kaspersky labkaspersky password manager 10.2kpm.exe
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex17_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.kis.ui.toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.ksde.ui.toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}kaspersky labkaspersky password manager 10.2kpm.exe
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex17_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\KasperskyLab.Kis.UI.Toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\Kaspersky.ShellEx16_b81m8cbssw9gt!KasperskyPackageRegistrator
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\Kaspersky.ShellEx_b81m8cbssw9gt!KasperskyPackageRegistrator
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\KasperskyLab.Kis.UI.Toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\HostActivityManager\CommitHistory\Kaspersky.ShellEx16_b81m8cbssw9gt!KasperskyPackageRegistrator
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\HostActivityManager\CommitHistory\Kaspersky.ShellEx17_b81m8cbssw9gt!KasperskyPackageRegistrator
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files (x86)%5CKaspersky Lab%5CKaspersky 21.15%5Cx64%5Cresources.pri
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files (x86)%5CKaspersky Lab%5CKaspersky 21.16%5Cx64%5Cresources.pri
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\kaspersky.shellex16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\kaspersky.shellex_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PolicyCache\Kaspersky.ShellEx16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PolicyCache\Kaspersky.ShellEx17_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PolicyCache\Kaspersky.ShellEx_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Kaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Kaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Kaspersky.ShellEx16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\PackagedCom\Package\Kaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\PackagedCom\Package\Kaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\SOFTWARE\KasperskyLab
End::
  • Click on the Fix button just once and wait.
  • Please make sure you let the system restart normally. After that let the tool complete its run.
  • When it's finished FRST will generate a log in the location you ran the tool from. (Fixlog.txt).

Please copy the contents from this text file and paste into your next reply.

 



#23 ramesh help

ramesh help
  • Topic Starter

  •  Avatar image
  • Members
  • 105 posts
  • ONLINE
  •  
  • Local time:09:15 PM

Posted 13 November 2024 - 01:45 PM

Just doing 1 extra step like the other machine to provide you with the logview, uploded into bleepingcomputer url link but limit file of 10mb

URL will last for 7 days via freehostting file uploader website

Fix result of Farbar Recovery Scan Tool (x64) Version: 13-11-2024
Ran by user (14-11-2024 02:19:18) Run:5
Running from C:\Users\user\Downloads
Loaded Profiles: user
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start::
CreateRestorePoint:
CloseProcesses:
C:\Windows\System32\winevt\Logs\Kaspersky Event Log.evtx
C:\Windows\System32\Tasks_Migrated\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
C:\ProgramData\Kaspersky Lab
2024-02-14 17:14 - 2024-02-14 17:14 _____ C:\Users\user\AppData\Local\Packages\Kaspersky.ShellEx16_b81m8cbssw9gt
2023-11-22 11:07 - 2023-11-22 11:08 _____ C:\Users\user\AppData\Local\Packages\Kaspersky.ShellEx_b81m8cbssw9gt
2022-11-29 12:23 - 2022-11-29 12:23 _____ C:\Users\Default\AppData\Local\Kaspersky Lab
2023-11-22 10:42 - 2023-11-22 11:17 _____ C:\ProgramData\Kaspersky Lab Setup Files
2024-02-14 17:14 - 2024-02-14 17:14 _____ C:\ProgramData\Packages\Kaspersky.ShellEx16_b81m8cbssw9gt
2023-11-22 11:08 - 2023-11-22 11:08 _____ C:\ProgramData\Packages\Kaspersky.ShellEx_b81m8cbssw9gt
2022-11-29 12:18 - 2024-11-12 19:29 _____ C:\Program Files (x86)\Kaspersky Lab
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.3\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.3\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\UCPStorage\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.3\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.3\Temp\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.3\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Bases\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Data\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\KDSROOT\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\ipm\control\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\ipm\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.9\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.9\Temp\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.9\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.13\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.13\Temp\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.13\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.14\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\KSDE5.14\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.15\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-15\klhk\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-15\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.16\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.16\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-16\klhk\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-16\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\StartMenu\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-17\klhk\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-17\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klifx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\cm_km_x64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\x64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klbackupdiskx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klbackupfltx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\kldiskx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klelam_x64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klimx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klkbdfltx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klmoufltx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klpdx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klpnpfltx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klwtpx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\knepsx64\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.18\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\ProgramData\Kaspersky Lab\AVP21.18\Traces\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-18\klhk\
DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-18\
DeleteValue: HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\NetworkDriverBackup\Control\Network\{4d36e972-e325-11ce-bfc1-08002be10318}\Descriptions|Kaspersky VPN
DeleteValue: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt%5Cresources.pri\1da5f2631431b27\bdcd4f7b|@{C:\Program Files\WindowsApps\Kaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt\resources.pri? ms-resource:///resources/DisplayName}
DeleteValue: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx17_1.0.0.6_x64__b81m8cbssw9gt%5Cresources.pri\1dac37c99d40acc\bdcd4f7b|@{C:\Program Files\WindowsApps\Kaspersky.ShellEx17_1.0.0.6_x64__b81m8cbssw9gt\resources.pri? ms-resource:///resources/DisplayName}
DeleteValue: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt%5Cresources.pri\1da1cf1a6f10c\bdcd4f7b|@{C:\Program Files\WindowsApps\Kaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt\resources.pri? ms-resource:///resources/DisplayName}
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.9\ksde.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\ProgramData\Kaspersky Lab\KSDE5.9\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\ProgramData\Kaspersky Lab\KSDE5.13\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 10.2\kpm.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.15\avp.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\ProgramData\Kaspersky Lab\AVP21.15\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.16\avp.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.14\ksde.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\ProgramData\Kaspersky Lab\AVP21.16\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\avp.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\ProgramData\Kaspersky Lab\AVP21.17\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe
DeleteValue: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.18\avp.exe
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\UserData\UninstallTimes|Kaspersky.ShellEx17_b81m8cbssw9gt
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData|KasperskyLab.Kis.UI.Toasts
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\avpui.exe
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.14\ksdeui.exe
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 10.2\kpm.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 10.2\kpm.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\KSDE5.14\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\KSDE5.14\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_DB1281A1-88E0-11EE-975F-B445068CF65B\startup.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_DB1281A1-88E0-11EE-975F-B445068CF65B\startup.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_9C608EDE-88E5-11EE-9760-B445068CF65B\startup.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_9C608EDE-88E5-11EE-9760-B445068CF65B\startup.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\AVP21.15\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\AVP21.15\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.ApplicationCompany
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\AVP21.16\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.FriendlyAppName
DeleteValue: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\ProgramData\Kaspersky Lab\AVP21.16\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.ApplicationCompany
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\Kaspersky Standard 21.15
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\Kaspersky Standard 21.16
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\Kaspersky.ShellEx17_b81m8cbssw9gt
 DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab\AVP21.17\Data\Agreements\MyKaspersky
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab\AVP21.17\Data\Agreements\MyKasperskyFeatures
DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Kaspersky Event Log
DeleteKey: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt%5Cresources.pri
DeleteKey: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx17_1.0.0.6_x64__b81m8cbssw9gt%5Cresources.pri
DeleteKey: HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt%5Cresources.pri
DeleteKey: HKEY_USERS\.DEFAULT\Software\KasperskyLab
DeleteKey: HKEY_USERS\.DEFAULT\Software\KasperskyLabSetup
DeleteKey: HKEY_USERS\S-1-5-19\Software\KasperskyLab
DeleteKey: HKEY_USERS\S-1-5-20\Software\KasperskyLab
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\KasperskyLab
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\KasperskyLabSetup
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\AppHost\IndexedDB\Kaspersky.ShellEx16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\AppHost\IndexedDB\Kaspersky.ShellEx_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications\Kaspersky.ShellEx16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications\Kaspersky.ShellEx17_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications\Kaspersky.ShellEx_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.kis.ui.toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.ksde.ui.toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}kaspersky labkaspersky password manager 10.2kpm.exe
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex17_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.kis.ui.toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.ksde.ui.toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}kaspersky labkaspersky password manager 10.2kpm.exe
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex17_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\KasperskyLab.Kis.UI.Toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\Kaspersky.ShellEx16_b81m8cbssw9gt!KasperskyPackageRegistrator
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\Kaspersky.ShellEx_b81m8cbssw9gt!KasperskyPackageRegistrator
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\KasperskyLab.Kis.UI.Toasts
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\HostActivityManager\CommitHistory\Kaspersky.ShellEx16_b81m8cbssw9gt!KasperskyPackageRegistrator
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\HostActivityManager\CommitHistory\Kaspersky.ShellEx17_b81m8cbssw9gt!KasperskyPackageRegistrator
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files (x86)%5CKaspersky Lab%5CKaspersky 21.15%5Cx64%5Cresources.pri
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files (x86)%5CKaspersky Lab%5CKaspersky 21.16%5Cx64%5Cresources.pri
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\kaspersky.shellex16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\kaspersky.shellex_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PolicyCache\Kaspersky.ShellEx16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PolicyCache\Kaspersky.ShellEx17_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PolicyCache\Kaspersky.ShellEx_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Kaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Kaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Kaspersky.ShellEx16_b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\PackagedCom\Package\Kaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\PackagedCom\Package\Kaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt
DeleteKey: HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\SOFTWARE\KasperskyLab
End::
*****************
 
Restore point was successfully created.
Processes closed successfully.
Could not move "C:\Windows\System32\winevt\Logs\Kaspersky Event Log.evtx" => Scheduled to move on reboot.
C:\Windows\System32\Tasks_Migrated\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => moved successfully
"C:\ProgramData\Kaspersky Lab" => not found
 
"C:\Users\user\AppData\Local\Packages\Kaspersky.ShellEx16_b81m8cbssw9gt" Folder move:
 
C:\Users\user\AppData\Local\Packages\Kaspersky.ShellEx16_b81m8cbssw9gt => moved successfully
 
"C:\Users\user\AppData\Local\Packages\Kaspersky.ShellEx_b81m8cbssw9gt" Folder move:
 
C:\Users\user\AppData\Local\Packages\Kaspersky.ShellEx_b81m8cbssw9gt => moved successfully
 
"C:\Users\Default\AppData\Local\Kaspersky Lab" Folder move:
 
C:\Users\Default\AppData\Local\Kaspersky Lab => moved successfully
 
"C:\ProgramData\Kaspersky Lab Setup Files" Folder move:
 
C:\ProgramData\Kaspersky Lab Setup Files => moved successfully
 
"C:\ProgramData\Packages\Kaspersky.ShellEx16_b81m8cbssw9gt" Folder move:
 
C:\ProgramData\Packages\Kaspersky.ShellEx16_b81m8cbssw9gt => moved successfully
 
"C:\ProgramData\Packages\Kaspersky.ShellEx_b81m8cbssw9gt" Folder move:
 
C:\ProgramData\Packages\Kaspersky.ShellEx_b81m8cbssw9gt => moved successfully
 
"C:\Program Files (x86)\Kaspersky Lab" Folder move:
 
C:\Program Files (x86)\Kaspersky Lab => moved successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\AVP21.3\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\AVP21.3\Traces\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\UCPStorage\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Common Files\Kaspersky Lab\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE5.3\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE5.3\Temp\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE5.3\Traces\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Bases\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Data\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\KDSROOT\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\ipm\control\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\Kaspersky Password Manager\Preliminary_\ipm\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE5.9\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE5.9\Temp\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE5.9\Traces\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE5.13\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE5.13\Temp\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE5.13\Traces\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE5.14\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE5.14\Traces\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\AVP21.15\Traces\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-15\klhk\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-15\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\AVP21.16\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\AVP21.16\Traces\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-16\klhk\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-16\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\StartMenu\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-17\klhk\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-17\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klifx64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\cm_km_x64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\x64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klbackupdiskx64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klbackupfltx64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\kldiskx64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klelam_x64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klimx64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klkbdfltx64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klmoufltx64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klpdx64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klpnpfltx64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\klwtpx64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\knepsx64\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\AVP21.18\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\AVP21.18\Traces\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-18\klhk\" => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files (x86)\Common Files\Kaspersky Lab\K4W-21-18\" => removed successfully
"HKEY_LOCAL_MACHINE\SYSTEM\Setup\Upgrade\NetworkDriverBackup\Control\Network\{4d36e972-e325-11ce-bfc1-08002be10318}\Descriptions\\Kaspersky VPN" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt%5Cresources.pri\1da5f2631431b27\bdcd4f7b\\@{C:\Program Files\WindowsApps\Kaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt\resources.pri? ms-resource:///resources/DisplayName}" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx17_1.0.0.6_x64__b81m8cbssw9gt%5Cresources.pri\1dac37c99d40acc\bdcd4f7b\\@{C:\Program Files\WindowsApps\Kaspersky.ShellEx17_1.0.0.6_x64__b81m8cbssw9gt\resources.pri? ms-resource:///resources/DisplayName}" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt%5Cresources.pri\1da1cf1a6f10c\bdcd4f7b\\@{C:\Program Files\WindowsApps\Kaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt\resources.pri? ms-resource:///resources/DisplayName}" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.9\ksde.exe" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\ProgramData\Kaspersky Lab\KSDE5.9\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\ProgramData\Kaspersky Lab\KSDE5.13\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 10.2\kpm.exe" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.15\avp.exe" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\ProgramData\Kaspersky Lab\AVP21.15\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.16\avp.exe" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.14\ksde.exe" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\ProgramData\Kaspersky Lab\AVP21.16\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\avp.exe" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\ProgramData\Kaspersky Lab\AVP21.17\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe" => removed successfully
"HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.18\avp.exe" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\UserData\UninstallTimes\\Kaspersky.ShellEx17_b81m8cbssw9gt" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\Search\JumplistData\\KasperskyLab.Kis.UI.Toasts" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\avpui.exe" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.14\ksdeui.exe" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 10.2\kpm.exe.FriendlyAppName" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 10.2\kpm.exe.ApplicationCompany" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\ProgramData\Kaspersky Lab\KSDE5.14\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.FriendlyAppName" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\ProgramData\Kaspersky Lab\KSDE5.14\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.ApplicationCompany" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_DB1281A1-88E0-11EE-975F-B445068CF65B\startup.exe.FriendlyAppName" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_DB1281A1-88E0-11EE-975F-B445068CF65B\startup.exe.ApplicationCompany" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_9C608EDE-88E5-11EE-9760-B445068CF65B\startup.exe.FriendlyAppName" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\ProgramData\Kaspersky Lab Setup Files\KIS21.15.8.493.0.71.0\au_setup_9C608EDE-88E5-11EE-9760-B445068CF65B\startup.exe.ApplicationCompany" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\ProgramData\Kaspersky Lab\AVP21.15\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.FriendlyAppName" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\ProgramData\Kaspersky Lab\AVP21.15\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.ApplicationCompany" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\ProgramData\Kaspersky Lab\AVP21.16\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.FriendlyAppName" => removed successfully
"HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\\C:\ProgramData\Kaspersky Lab\AVP21.16\Temp\Setup\avp_7D65C94A-2E46-4ABA-A075-8DB61D2FD6CD.exe.ApplicationCompany" => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\Kaspersky Standard 21.15 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\Kaspersky Standard 21.16 => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\StateRepository\Cache\PackageFamily\Index\PackageFamilyName\Kaspersky.ShellEx17_b81m8cbssw9gt" => removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab => removed successfully
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab\AVP21.17\Data\Agreements\MyKaspersky" => not found
"HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\KasperskyLab\AVP21.17\Data\Agreements\MyKasperskyFeatures" => not found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Kaspersky Event Log => removed successfully
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt%5Cresources.pri => removed successfully
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx17_1.0.0.6_x64__b81m8cbssw9gt%5Cresources.pri => removed successfully
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files%5CWindowsApps%5CKaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt%5Cresources.pri => removed successfully
HKEY_USERS\.DEFAULT\Software\KasperskyLab => removed successfully
HKEY_USERS\.DEFAULT\Software\KasperskyLabSetup => removed successfully
HKEY_USERS\S-1-5-19\Software\KasperskyLab => removed successfully
HKEY_USERS\S-1-5-20\Software\KasperskyLab => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\KasperskyLab => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\KasperskyLabSetup => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\AppHost\IndexedDB\Kaspersky.ShellEx16_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\AppHost\IndexedDB\Kaspersky.ShellEx_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications\Kaspersky.ShellEx16_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications\Kaspersky.ShellEx17_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications\Kaspersky.ShellEx_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.kis.ui.toasts => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.ksde.ui.toasts => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}kaspersky labkaspersky password manager 10.2kpm.exe => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex16_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex17_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Cloud\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.kis.ui.toasts => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~kasperskylab.ksde.ui.toasts => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appleveltileinfo$appleveltilelist\windows.data.apps.appleveltileinfo$w~{7c5a40ef-a0fb-4bfc-874a-c0f2e0b9fa8e}kaspersky labkaspersky password manager 10.2kpm.exe => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex16_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex17_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\Current\{776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist\windows.data.apps.appmetadata$kaspersky.shellex_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\KasperskyLab.Kis.UI.Toasts => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\Kaspersky.ShellEx16_b81m8cbssw9gt!KasperskyPackageRegistrator => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\Kaspersky.ShellEx_b81m8cbssw9gt!KasperskyPackageRegistrator => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows\CurrentVersion\PushNotifications\Backup\KasperskyLab.Kis.UI.Toasts => not found
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\HostActivityManager\CommitHistory\Kaspersky.ShellEx16_b81m8cbssw9gt!KasperskyPackageRegistrator => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Microsoft\Windows NT\CurrentVersion\HostActivityManager\CommitHistory\Kaspersky.ShellEx17_b81m8cbssw9gt!KasperskyPackageRegistrator => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files (x86)%5CKaspersky Lab%5CKaspersky 21.15%5Cx64%5Cresources.pri => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\MrtCache\C:%5CProgram Files (x86)%5CKaspersky Lab%5CKaspersky 21.16%5Cx64%5Cresources.pri => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\kaspersky.shellex16_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\kaspersky.shellex_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PolicyCache\Kaspersky.ShellEx16_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PolicyCache\Kaspersky.ShellEx17_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\PolicyCache\Kaspersky.ShellEx_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Kaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\Repository\Packages\Kaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Kaspersky.ShellEx16_b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\PackagedCom\Package\Kaspersky.ShellEx16_1.0.0.5_x64__b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\PackagedCom\Package\Kaspersky.ShellEx_1.0.0.4_x64__b81m8cbssw9gt => removed successfully
HKEY_USERS\S-1-5-21-282315603-4174644128-2434468704-1001\Software\Classes\SOFTWARE\KasperskyLab => removed successfully
 
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 14-11-2024 02:38:23)
 
C:\Windows\System32\winevt\Logs\Kaspersky Event Log.evtx => Is moved successfully
 
==== End of Fixlog 02:38:23 ====


#24 ramesh help

ramesh help
  • Topic Starter

  •  Avatar image
  • Members
  • 105 posts
  • ONLINE
  •  
  • Local time:09:15 PM

Posted 13 November 2024 - 01:53 PM

I will check through the file you uploaded.

Windows Update hasn't pulled in the Cumulative November update yet.

Please try again and if there is a problem please run the Windows Updater Troubleshooter, as follows.

Select Start  > Settings  > Update & Security   > Troubleshoot > Additional troubleshooters.
Next, under Get up and running, select Windows Update > Run the troubleshooter.
If this doesn't fix things, then please advise details of any errors reported.

 

 

is this what u are finding for? if yes then its just done today

2024-11 Cumulative Update for Windows 11 Version 23H2 for x64-based Systems (KB5046633)



#25 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 4,142 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:15 PM

Posted Yesterday, 05:33 AM

Yes that's the update I was looking for.
Without having a time to zone into, it is difficult to see which error is the culprit.
There are a number of errors listed, so please make a note of the time the hangs occur and run NirsoftEV again.



#26 ramesh help

ramesh help
  • Topic Starter

  •  Avatar image
  • Members
  • 105 posts
  • ONLINE
  •  
  • Local time:09:15 PM

Posted Yesterday, 05:41 AM

what i noticed was that. example load windows to desktop. untouched. it shows 100 disk, 70-80% ram. so while waiting for you, i tried to disable services.msc 3 items to check if disk 100% or ram drops. connected user experience, windows search & 1 more forgotten. after that, i changed the pagging ram memory from auto to recommended figure shown by the system then x1.5 of 4gb (as the maximum) pagging ram. i also noticed via the task manager, via eventlog, noticed that it jumps/changes at random but most times was webview edge 2. so i decided to disable that, then via windows settings, disabled login page n direct to desktop, turned off screensaver, on edge i turned off all settings like news etc. then i noticed task manager became 0-5% disk. ram becomes like 40-60% ish. but as soon as open any file or browser, it goes hanging directly. even while browsing computer or u want to open start menu, everything freeze/hangs.

 

any chance do you think its ram or hard disk problem? i used crystal report for hdd & no critical/red marks either. all health are good. i did not test if ram could be faulty. is there a test we could do on ram perhaps?


Edited by ramesh help, Yesterday, 05:41 AM.


#27 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 4,142 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:15 PM

Posted Yesterday, 06:05 AM

It might nearly be time to consider a Windows Reset.

Here is the procedure for a memory check.

 

  • Press Windows Key+R keys to launch the Run window.
  • Type mdsched.exe and press Enter.
  • Click Restart now and check for problems (recommended).
  • Be sure to save your work before proceeding.
  • Your computer will then restart.
  • The Windows Memory Diagnostics Tool screen will launch.
  • The test may take several minutes and you will see a progress bar and a Status message showing any problems that have been detected.
  • When it has completed, your computer will automatically reboot.
  • After you log in, the test results should appear.
  • If they don't, right click the Start button and select Event Viewer from the menu.
  • Navigate to Windows Logs > System.
  • Click Find in the right pane.
  • Type MemoryDiagnostic into the find box and click Find.
  • In the Event Viewer, double-click the MemoryDiagnostics-Results source.
  • You will see the results displayed and also information about your RAM, at the bottom of the window.

 



#28 ramesh help

ramesh help
  • Topic Starter

  •  Avatar image
  • Members
  • 105 posts
  • ONLINE
  •  
  • Local time:09:15 PM

Posted Yesterday, 06:07 AM

Yes that's the update I was looking for.
Without having a time to zone into, it is difficult to see which error is the culprit.
There are a number of errors listed, so please make a note of the time the hangs occur and run NirsoftEV again.

Expiring 7 days. uploaded due to file size 100mb. Could you check from 9am-5pm today log. I see alot of X errors & also yellow !! on the log. many of those errors lead to 3-4 same error codes throughout the whole day.

http://we.tl/t-wVovVwcqmg



#29 ramesh help

ramesh help
  • Topic Starter

  •  Avatar image
  • Members
  • 105 posts
  • ONLINE
  •  
  • Local time:09:15 PM

Posted Yesterday, 06:14 AM

Based on random 3hrs scroll in the log, i noticed a common pattern of these. could u assist to check

 

Event Time Level Provider Channel Description Opcode Task Keywords Process ID Thread ID Computer User Log File
14/11/2024 6:59:33.733 PM Error Microsoft-Windows-ModernDeployment-Diagnostics-Provider Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService "Autopilot.dll WIL error was reported.
HRESULT: 0x80070491
File: onecoreuap\admin\moderndeployment\autopilot\dll\dllmain.cpp, line 128
Message: NULL" 0x1000000000000000 9768 7152 DESKTOP-AS0EIGK DESKTOP-AS0EIGK\user
 
 
 
Event Time Level Provider Channel Description Opcode Task Keywords Process ID Thread ID Computer User Log File
14/11/2024 6:59:24.270 PM Error Microsoft-Windows-StorDiag Microsoft-Windows-Storage-ClassPnP/Operational Completing a failed non-ReadWrite SCSI SRB request Completion of request. (101) Class (200) Non-Read/Write request 9792 5264 DESKTOP-AS0EIGK DESKTOP-AS0EIGK\user
 
 
 
Event Time Level Provider Channel Description Opcode Task Keywords Process ID Thread ID Computer User Log File
14/11/2024 6:48:45.666 PM Warning Microsoft-Windows-StateRepository Microsoft-Windows-StateRepository/Operational Warning 0x80670007: [sqlite3_exec] #687 Database 1C07EE88180: Try 7 (2514ms) {32B53574-E376-44B9-A2B8-C1ADC80648F2} Cpu:8 Mem:5 Io:2 TID:9336 database is locked : SQL BEGIN EXCLUSIVE /*32B53574-E376-44B9-A2B8-C1ADC80648F2*/; 1 StateRepository Keyword 2180 5156 DESKTOP-AS0EIGK NT AUTHORITY\SYSTEM
 
 
 
 
Event Time Level Provider Channel Description Opcode Task Keywords Process ID Thread ID Computer User Log File
14/11/2024 5:09:55.364 PM Warning Microsoft-Windows-CloudStore Microsoft-Windows-CloudStore/Operational Downloading {776c2a1c-3e20-4eb6-8fab-2388996278d0}$windows.data.apps.appmetadata$appmetadatalist|windows.data.apps.appmetadata${61d4736b-3325-4d4a-bd41-8bd206c6a86e} failed with error code 0x8004010A. 0x8000000000000000 6412 7860 DESKTOP-AS0EIGK DESKTOP-AS0EIGK\user


#30 dennis_l

dennis_l

  •  Avatar image
  • Malware Response Team
  • 4,142 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:15 PM

Posted Yesterday, 06:26 AM

Event Names MoAppHang and APPCRASH should, I feel, be the ones to look at first.






2 user(s) are reading this topic

1 members, 1 guests, 0 anonymous users


    ramesh help