1. Atlantic44

    Atlantic44 Corporal

    There is a "ScreenConnect" program installed and someone else was able to connect to the computer previously. The program is showing in the taskbar, but it's not showing under the installed programs.
    Microsoft defender also quarantined several files in the downloads folder named "ziprar.exe"
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome to Major Geeks Malware Forum.

    My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

    ===================================================

    Ground Rules:
    • First, please keep in mind most of us at Major Geeks volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.
    • It is important to not run any tools or take any steps other than those I will provide for you.
    • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
    • Please take special note in my instructions whether to copy and paste, attach, or upload reports or files requested in my instructions
    • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
    ===================================================

    Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

    Please allow me some time to review what you have posted.
     
  3. Oh My!

    Oh My! Malware Expert Staff Member

    Let's start with this.

    ===================================================

    Malwarebytes AdwCleaner

    -------------------
    • Please download AdwCleaner and save it to your Desktop
    • Close all open programs and browsers
    • Right click on the icon and select Run as administrator
    • Click Scan now
    • Uncheck any detected items you would to keep then click Next
    • If a Preinstalled software was found! screen appears review it if you'd like then click OK
    • Review the list of Preinstalled software and place a check mark in those you do not wish to keep. I would recommend removing all pre-installed software
    • Click Quarantine, then Continue
    • When completed click View Log File
    • Copy and paste the contents in your reply
    • Close the AdwCleaner window
    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Close any open programs or windows because your computer will automatically reboot after FRST64 is run
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    cmd: type "C:\windows\system32\user.config"
    cmd: type "2026-03-05 08:14 - 2026-03-05 08:14 - 000000566 _____ C:\windows\system32\user.config
    2026-03-05 13:31 - 2026-03-05 08:14 - 000000566 _____ C:\windows\SysWOW64\user.config
    2026-03-05 08:14 - 2026-03-05 08:14 - 000000000 ____D C:\Users\Bumpa\AppData\Local\Deployment
    2026-03-05 08:14 - 2026-03-05 08:14 - 002510032 _____ C:\Users\Bumpa\Downloads\ScreenConnect.Client.exe 
    C:\Users\Bumpa\AppData\Local\Apps\2.0\381482WO.5WP\MTPLBB08.3MV\scre..tion_0000000000000000_0019.0009_c8a1d0ce3eec290d
    2026-03-05 09:03 - 2026-03-05 09:19 - 000000130 _____ C:\Users\Bumpa\AppData\LocalLow\0c8935a54f6f4a7da472775b22660c7a43cf83fa2a331fa20d62a83b46a9c552
    2026-03-05 09:03 - 2026-03-05 09:12 - 000140954 _____ C:\Users\Bumpa\AppData\LocalLow\649bdb4509c2ab359e4518ca3fa0f1be7d60496ff4a51497e98b3f312eb878b1
    2026-03-05 08:12 - 2026-03-05 08:15 - 000000130 _____ C:\Users\Bumpa\AppData\LocalLow\2b69882f46c3f830c9ccd2834c85e645d4a46517a6119ddc0e842c5462b15568
    2026-03-05 08:12 - 2026-03-05 08:12 - 000005880 _____ C:\Users\Bumpa\AppData\LocalLow\c0840060cc230ad3cc72a4bb94451bff5a4f25616534ac34603a1f23c0524dcd
    2026-03-05 08:12 - 2026-03-05 08:12 - 000002264 _____ C:\Users\Bumpa\AppData\LocalLow\0ff89ddde0e239c9485c3459429fe679372dedafc2201a05bf98b6bd7590ac53
    2026-03-05 08:12 - 2026-03-05 08:12 - 000000026 _____ C:\Users\Bumpa\AppData\LocalLow\e17338e501cbe4aaf025d609706a5fb453123918a6ff1489799928392178c4fd
    2026-03-05 08:12 - 2026-03-05 08:12 - 000000026 _____ C:\Users\Bumpa\AppData\LocalLow\d94a84b76f6fb9f39f7631a75687866f5b695562cdb5ee1ca5e71109bf323232
    2026-03-05 08:10 - 2026-03-05 08:12 - 000122091 _____ C:\Users\Bumpa\AppData\LocalLow\9fcaf702c64e5d2ad428b4f8f228dd4e5c4af0b5528a3707ad56abdb39ac92f3
    2026-03-05 08:10 - 2026-03-05 08:12 - 000000130 _____ C:\Users\Bumpa\AppData\LocalLow\89e2ed89ed22df71ae5165d443a4fcaaf3dd1680da408769c83624db25b368d3
    2026-03-05 14:05 - 2025-12-03 07:39 - 000000130 _____ C:\Users\Bumpa\AppData\LocalLow\8bed9e1218f8166b78cb09854d057b8f09e73a4113024495959c3553548a6e7e
    2026-03-05 13:53 - 2025-12-04 07:38 - 000000466 _____ C:\Users\Bumpa\AppData\LocalLow\c67135c718557970791a2e27b1e0a845ec98e563faa8382c5ca07475910f32d4
    2026-03-05 13:51 - 2025-12-04 07:36 - 000000130 _____ C:\Users\Bumpa\AppData\LocalLow\1ab8148715e095e3d51b6b516629d9d7be6d54485a4c7839a2037714f1583442
    2026-03-05 13:51 - 2025-12-03 07:30 - 000000130 _____ C:\Users\Bumpa\AppData\LocalLow\d9cf87df6fdc643716c4cfbd3f82f4ffb1b3cd35467a366ea0cba37c29fed781
    2026-03-05 13:49 - 2025-12-04 07:36 - 005591103 _____ C:\Users\Bumpa\AppData\LocalLow\cc8a6e487ca78923ffe500acff1608a3207f2baf08598e93da52c602f994564d
    2026-03-05 13:49 - 2025-12-03 07:30 - 000000026 _____ C:\Users\Bumpa\AppData\LocalLow\51d78c8e4fa6c635b9f05efeff87a73e8768adfc9a5e1b2825c6e3936bc17283
    2026-03-05 08:36 - 2025-12-04 07:38 - 009818157 _____ C:\Users\Bumpa\AppData\LocalLow\28a3e480d2528f6eb558eb2ad25ae25347583a4fc164b1abeed8d4b58079a333
    2026-03-04 13:07 - 2025-12-04 07:38 - 000000130 _____ C:\Users\Bumpa\AppData\LocalLow\77015e59e1a1f232156dac60761789904adf3809dcda31ecd39a167025016104
    2026-03-04 13:01 - 2025-12-10 05:58 - 000000130 _____ C:\Users\Bumpa\AppData\LocalLow\b50dc0e7c4a8eb594d38daf53b55d2c5779fc2fefb8b4fcaff266333bbbe1f60
    2026-03-04 13:01 - 2025-12-04 07:36 - 000000130 _____ C:\Users\Bumpa\AppData\LocalLow\a9ab25096b6bc3573fc6f9dc02657e3211cddd49ba2b7a1ff49f38997273d3b4
    2026-03-04 13:01 - 2025-12-03 06:23 - 000000130 _____ C:\Users\Bumpa\AppData\LocalLow\c9caa9e5bd405ad31da5ea0862a303f696a8726ea2b65d19abdd3f0a98adb90f
    2026-03-04 13:01 - 2025-12-03 06:23 - 000000130 _____ C:\Users\Bumpa\AppData\LocalLow\47f2409244f6aefadfb31440400a2225204aeb702da2b28c69bb668cccfa30fd
    SceenConnectTask: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File) 
    Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe  (No File) 
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ScreenConnect Client (c796e2f9-b40c-4458-befa-71afa3dcfd25) => ""="Service" 
    R2 ScreenConnect Client (c796e2f9-b40c-4458-befa-71afa3dcfd25); C:\Users\Bumpa\AppData\Local\Apps\2.0\381482WO.5WP\MTPLBB08.3MV\scre..tion_0000000000000000_0019.0009_c8a1d0ce3eec290d\ScreenConnect.ClientService.exe [95288 2026-03-05] (ConnectWise, LLC -> ) <==== ATTENTION 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\EGO Trimmer.jpeg:3or4kl4x13tuuug3Byamue2s4b [97] 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\EGO Trimmer.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\Image.jpg:3or4kl4x13tuuug3Byamue2s4b [97] 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\Image.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\Pam's aetna card side 2.jpeg:3or4kl4x13tuuug3Byamue2s4b [97] 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\Pam's aetna card side 2.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\Pam's aetna card.jpeg:3or4kl4x13tuuug3Byamue2s4b [97] 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\Pam's aetna card.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\Waiohai 4.jpeg:3or4kl4x13tuuug3Byamue2s4b [119] 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\Waiohai 4.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\Walgreen's RX.jpeg:3or4kl4x13tuuug3Byamue2s4b [119] 
    AlternateDataStreams: C:\Users\Bumpa\OneDrive\Documents\Walgreen's RX.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] 
    cmd: netsh winsock reset catalog
    cmd: netsh int ip reset resetlog.txt
    Reg: reg export HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Defaults\FirewallPolicy\FirewallRules C:\Firewall.reg
    C:\Firewall.reg
    cmd: netsh advfirewall reset
    cmd: netsh advfirewall set allprofiles state ON
    cmd: bitsadmin /reset /allusers
    cmd: ipconfig /flushdns
    Removeproxy:
    hosts:
    cmd: sfc /scannow
    cmd: DISM /Online /Cleanup-Image /CheckHealth
    Emptytemp:
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt
    • Please attach the file to your reply
    • Note: This step resets your Firewall settings and you may be asked later to grant permission for legitimate programs to pass through the Firewall. If you recognize the program agree to the request.
    • WARNING Regarding the Emptytemp: command, please see here before running the Fixlist.
    ===================================================

    Farbar Recovery Scan Tool SearchAll

    --------------------
    • Right click on FRST64 and select Run as administrator
    • Copy/paste the following in the Search: box
    Code:
    SearchAll: ScreenConnect;Connectwise;c796e2f9-b40c-4458-befa-71afa3dcfd25
    
    • Click Search Files
    • When completed click OK and a Search.txt document will open on your desktop
    • Attach the file to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • AdwCleaner report
    • Fixlog.txt
    • Search.txt
     
  4. Atlantic44

    Atlantic44 Corporal

    # -------------------------------
    # Malwarebytes AdwCleaner 8.7.1.626
    # -------------------------------
    # Build: 02-20-2026
    # Database: 2025-12-16.1 (Local)
    # Support: https://help.malwarebytes.com/
    #
    # -------------------------------
    # Mode: Clean
    # -------------------------------
    # Start: 03-05-2026
    # Duration: 00:00:01
    # OS: Windows 11 (Build 26200.7840)
    # Cleaned: 12
    # Failed: 0


    ***** [ Services ] *****

    No malicious services cleaned.

    ***** [ Folders ] *****

    No malicious folders cleaned.

    ***** [ Files ] *****

    No malicious files cleaned.

    ***** [ DLL ] *****

    No malicious DLLs cleaned.

    ***** [ WMI ] *****

    No malicious WMI cleaned.

    ***** [ Shortcuts ] *****

    No malicious shortcuts cleaned.

    ***** [ Tasks ] *****

    No malicious tasks cleaned.

    ***** [ Registry ] *****

    No malicious registry entries cleaned.

    ***** [ Chromium (and derivatives) ] *****

    No malicious Chromium entries cleaned.

    ***** [ Chromium URLs ] *****

    No malicious Chromium URLs cleaned.

    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries cleaned.

    ***** [ Firefox URLs ] *****

    No malicious Firefox URLs cleaned.

    ***** [ Hosts File Entries ] *****

    No malicious hosts file entries cleaned.

    ***** [ Preinstalled Software ] *****

    Deleted Preinstalled.HPCleanFLC Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run|HPSEU_Host_Launcher
    Deleted Preinstalled.HPRegistrationService Folder C:\ProgramData\HP\HP REGISTRATION SERVICE
    Deleted Preinstalled.HPSupportAssistant Folder C:\HP\SUPPORT
    Deleted Preinstalled.HPSupportAssistant Folder C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
    Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
    Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
    Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
    Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
    Deleted Preinstalled.HPSureConnect Folder C:\Program Files\HPCOMMRECOVERY
    Deleted Preinstalled.HPSureConnect Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6468C4A5-E47E-405F-B675-A70A70983EA6}
    Deleted Preinstalled.HPTouchpointAnalyticsClient Folder C:\ProgramData\HP\HP TOUCHPOINT ANALYTICS CLIENT
    Deleted Preinstalled.HPTouchpointAnalyticsClient Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}


    *************************

    [+] Delete Tracing Keys
    [+] Reset Winsock

    *************************

    AdwCleaner[S00].txt - [2802 octets] - [05/03/2026 17:10:26]

    ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
     

    Attached Files:

  5. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you.

    Now this.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Close any open programs or windows because your computer will automatically reboot after FRST64 is run
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    cmd: reg load "HKLM\Components" "C:\Windows\System32\Config\Components"
    C:\Users\Bumpa\AppData\Local\Apps\2.0\381482WO.5WP
    DeleteValue: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Bumpa\Downloads\ScreenConnect.Client.exe
    DeleteValue: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store|C:\Users\Bumpa\AppData\Local\Apps\2.0\381482WO.5WP\MTPLBB08.3MV\scre..tion_0000000000000000_0019.0009_c8a1d0ce3eec290d\ScreenConnect.WindowsClient.exe
    DeleteValue: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Bumpa\AppData\Local\Apps\2.0\381482WO.5WP\MTPLBB08.3MV\scre..tion_0000000000000000_0019.0009_c8a1d0ce3eec290d\ScreenConnect.WindowsClient.exe.FriendlyAppName
    DeleteValue: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache|C:\Users\Bumpa\AppData\Local\Apps\2.0\381482WO.5WP\MTPLBB08.3MV\scre..tion_0000000000000000_0019.0009_c8a1d0ce3eec290d\ScreenConnect.WindowsClient.exe.ApplicationCompany
    DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\ScreenConnect.WindowsClient.exe
    DeleteKey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\ScreenConnect
    DeleteKey: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\Components\scre...exe_0000000000000000_0019.0009_none_6ebe2e3293571230
    DeleteKey: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\Components\scre..core_4b14c015c87c1ad8_0019.0009_none_41c2dd2925d863d5
    DeleteKey: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\Components\scre..dows_4b14c015c87c1ad8_0019.0009_none_463ab50a62267705
    DeleteKey: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\Components\scre..ient_4b14c015c87c1ad8_0019.0009_none_a309b64d0ebc46e2
    DeleteKey: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\Components\scre..ient_4b14c015c87c1ad8_0019.0009_none_d7d83afb3527b9d9
    DeleteKey: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\Components\scre..tion_0000000000000000_0019.0009_c8a1d0ce3eec290d
    DeleteKey: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\Components\scre..tion_0000000000000000_0019.0009_fa8fa43bf78656a3
    DeleteKey: HKEY_USERS\S-1-5-21-2801342469-1093007264-601524826-1001\Software\Classes\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0\Components\scre..vice_4b14c015c87c1ad8_0019.0009_none_f3167571bb97c740
    cmd: DISM /Online /Cleanup-Image /RestoreHealth
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt
    • Please attach the file to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
     
  6. Atlantic44

    Atlantic44 Corporal

    Ok
     

    Attached Files:

  7. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the information.

    All of the ScreenConnect remnants have been removed but there is an issue with the Windows Image.

    Please zip and upload the below listed file/folder to GoFile or the file hosting site of your choice and post the download link in your reply.

    C:\Windows\Logs\CBS
    C:\Windows\Logs\DISM\dism.log
     
  8. Atlantic44

    Atlantic44 Corporal

  9. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for the information and quick reply. There is quite a bit to review so I will most likely not be replying again until tomorrow.

    Love the Jim Elliot quote.
     
  10. Atlantic44

    Atlantic44 Corporal

    Thank you.
    Sounds good.
     
  11. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for your patience.

    Please do this.

    ===================================================

    SFCFix Script

    --------------------
    • If necessary, download SFCFix.exe by niemiro and save it to your Desktop
    • Download the attached SFCFix.zip file and save it onto your Desktop leaving the default name
    • Close any open programs or windows
    • Drag the SFCFix.zip file over the SFCFix.exe icon and release it to run the fix
    • Once processed a SFCFix.txt document will open on your Desktop, with a copy placed on your Desktop as well
    • Copy and paste the contents of the SFCFix.txt report in your reply
    ===================================================

    DISM Restorehealth

    --------------------

    • Click Start, type cmd, then select Run as administrator
    • Copy and paste the below then hit Enter
    DISM /online /cleanup-image /RestoreHealth
    • If you see any result other than The operation completed successfully zip and upload the C:\Windows\CBS folder to GoFile or the file hosting site of your choice and post the download link in your reply.

    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
    • SFCFix.txt
    • DISM results?
    • Download link, if necessary
     

    Attached Files:

  12. Atlantic44

    Atlantic44 Corporal

    SFCFix version 3.0.2.1 by niemiro.
    Start time: 2026-03-06 16:23:31.173
    Microsoft Windows 10 Build 26200 - amd64
    Using .zip script file at C:\Users\Bumpa\OneDrive\Desktop\SFCFix.zip [0]




    PowerCopy::
    Successfully took permissions for file or folder C:\windows\WinSxS\amd64_microsoft-windows-lockapp.appxmain_31bf3856ad364e35_10.0.26100.1591_none_83300daf83f8b2a6
    Successfully took permissions for file or folder C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33
    Successfully took permissions for file or folder C:\windows\WinSxS\amd64_microsoft-windows-a..etedfeaturedatabase_31bf3856ad364e35_10.0.26100.1591_none_84b083aa00c60a75

    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-lockapp.appxmain_31bf3856ad364e35_10.0.26100.1591_none_83300daf83f8b2a6\DropShadow.png to C:\windows\WinSxS\amd64_microsoft-windows-lockapp.appxmain_31bf3856ad364e35_10.0.26100.1591_none_83300daf83f8b2a6\DropShadow.png.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\app.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\app.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\ApplicationTheme.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\ApplicationTheme.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\appManager.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\appManager.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\bridge.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\bridge.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudDomainJoin.DataModel.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudDomainJoin.DataModel.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\cloudexperiencehostapi.provisioning.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\cloudexperiencehostapi.provisioning.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostAPI.SyncSettings.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostAPI.SyncSettings.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostAPI.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostAPI.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.Account.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.Account.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.Cortana.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.Cortana.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.Hello.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.Hello.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.LocalNgc.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.LocalNgc.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.RetailDemo.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.RetailDemo.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.SyncEngine.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\CloudExperienceHostBroker.SyncEngine.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\ContentManagement.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\ContentManagement.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\discovery.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\discovery.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\enterprisedevicemanagement.enrollment.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\enterprisedevicemanagement.enrollment.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\environment.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\environment.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\Family.Cache.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\Family.Cache.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\globalization.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\globalization.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\GuidedSetup.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\GuidedSetup.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\helloEnrollmentPage.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\helloEnrollmentPage.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\HostedApplication.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\HostedApplication.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\localAccount.html to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\localAccount.html.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\Microsoft.CloudExperienceHost.dll to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\Microsoft.CloudExperienceHost.dll.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\Microsoft.CloudExperienceHost.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\Microsoft.CloudExperienceHost.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\microsoft.resourceaccountmanager.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\microsoft.resourceaccountmanager.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\MicrosoftAccount.Extension.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\MicrosoftAccount.Extension.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\microsoftAccount.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\microsoftAccount.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\MicrosoftAccount.TokenProvider.Core.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\MicrosoftAccount.TokenProvider.Core.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\MicrosoftAccount.TokenProvider.dll to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\MicrosoftAccount.TokenProvider.dll.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\MicrosoftAccount.TokenProvider.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\MicrosoftAccount.TokenProvider.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\MicrosoftAccount.UserOperations.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\MicrosoftAccount.UserOperations.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\navigation.json to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\navigation.json.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\navigator.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\navigator.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobe-light-frame-vm.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobe-light-frame-vm.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobe-listview-vm.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobe-listview-vm.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobeerror-main.html to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobeerror-main.html.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobehello-vm.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobehello-vm.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobelanguage-page.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobelanguage-page.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobelanguage-vm.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobelanguage-vm.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobelocalaccount-main.html to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobelocalaccount-main.html.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobesettings-multipage-main.html to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\oobesettings-multipage-main.html.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\resources.pri to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\resources.pri.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\RetailDemo.Internal.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\RetailDemo.Internal.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\rewards.js to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\rewards.js.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\settings-desktop.css to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\settings-desktop.css.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\SystemSettings.DataModel.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\SystemSettings.DataModel.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\UnifiedEnrollment.DataModel.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\UnifiedEnrollment.DataModel.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\uriRules.json to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\uriRules.json.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\userdeviceregistration.ngc.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\userdeviceregistration.ngc.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\WindowsUdk.winmd to C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33\WindowsUdk.winmd.
    Successfully copied file C:\Users\Bumpa\AppData\Local\niemiro\Archive\WinSxS\amd64_microsoft-windows-a..etedfeaturedatabase_31bf3856ad364e35_10.0.26100.1591_none_84b083aa00c60a75\shellFeatureInbox.sdb to C:\windows\WinSxS\amd64_microsoft-windows-a..etedfeaturedatabase_31bf3856ad364e35_10.0.26100.1591_none_84b083aa00c60a75\shellFeatureInbox.sdb.

    Successfully restored ownership for C:\windows\WinSxS\amd64_microsoft-windows-lockapp.appxmain_31bf3856ad364e35_10.0.26100.1591_none_83300daf83f8b2a6
    Successfully restored permissions on C:\windows\WinSxS\amd64_microsoft-windows-lockapp.appxmain_31bf3856ad364e35_10.0.26100.1591_none_83300daf83f8b2a6
    Successfully restored ownership for C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33
    Successfully restored permissions on C:\windows\WinSxS\amd64_microsoft-windows-c..riencehost.appxmain_31bf3856ad364e35_10.0.26100.1591_none_9e7873f8fda6cd33
    Successfully restored ownership for C:\windows\WinSxS\amd64_microsoft-windows-a..etedfeaturedatabase_31bf3856ad364e35_10.0.26100.1591_none_84b083aa00c60a75
    Successfully restored permissions on C:\windows\WinSxS\amd64_microsoft-windows-a..etedfeaturedatabase_31bf3856ad364e35_10.0.26100.1591_none_84b083aa00c60a75
    PowerCopy:: directive completed successfully.




    Successfully processed all directives.



    Failed to generate a complete zip file. Upload aborted.


    SFCFix version 3.0.2.1 by niemiro has completed.
    Currently storing 3 datablocks.
    Finish time: 2026-03-06 16:25:10.237
    Script hash: n3CnZ28pUVvee3G1X+B8h6GoukmEhnqWNuuvlommPfw=
    ----------------------EOF-----------------------
     
  13. Oh My!

    Oh My! Malware Expert Staff Member

    Were you able to run the DISM portion of the instructions?
     
  14. Atlantic44

    Atlantic44 Corporal

    Yes.
    It finished without any issues
     
  15. Oh My!

    Oh My! Malware Expert Staff Member

    Great.

    Looks like we are all set. Are there any remaining questions or concerns you might have before I post some tool/log clean up instructions and other information for you to consider going forward?
     
  16. Atlantic44

    Atlantic44 Corporal

    No thanks.
    Everything looks to be working.
     
  17. Oh My!

    Oh My! Malware Expert Staff Member

    Very well.

    Here is our final step and some additional information to consider.

    ===================================================

    KpRm by Kernel-panik

    --------------
    • Download KpRm and save it to your Desktop (see here if you must use Chrome)
    • Note: If the file is detected as malware it is not and it is safe to download. The detection is a false positive.
    • Right click on the icon and select Run as administrator
    • Click Yes on the Disclaimer
    • Place a check mark in Delete Tools, Create Restore Point, and Delete in 7 days
    • Click Run
    • Click OK on All operations are completed
    • KpRm will delete itself from you Desktop and you can either save or remove the report that is generated
    • You are free to remove any other tools/reports still remaining
    ===================================================

    All Clean!

    --------------

    Your computer is now clean. Please consider this going forward.

    Thank you for placing your trust in Major Geeks. It was a pleasure serving you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds