Just got this fascinating email from Tom: Lately I’ve been focusing on are your articles pertaining to the different widows patches / monthly windows
[See the full post at: How to permanently remove KB2952664, and maybe speed up your machine in the proceess]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
How to permanently remove KB2952664, and maybe speed up your machine in the proceess
Home » Forums » Newsletter and Homepage topics » How to permanently remove KB2952664, and maybe speed up your machine in the proceess
- This topic has 62 replies, 11 voices, and was last updated 7 years, 10 months ago.
Tags: KB 2952664
AuthorTopicwoody
ManagerMarch 30, 2016 at 5:22 pm #45145Viewing 56 reply threadsAuthorReplies-
PCano
GuestMarch 30, 2016 at 5:58 pm #45146WOW!
It’s never been on my computers, but I have run into several from which I could not delete it.
I installed it on a test computer it had never been on, and I know it one of the things it did was to alter Task SchedulerMicrosoftWindowsApplication Experience task, which I believe sends data to MS repeatedly. Busy MS!
Will take a look this on three of the computers I remember having the problem. -
Clairvaux
AskWoody Lounger -
Roger
GuestMarch 30, 2016 at 7:08 pm #45148Pardon my ignorance, but what is an “elevated” command prompt? Is there a difference between that and a plain-vanilla command prompt? Does its use require admin rights of some sort? Or will keying “command prompt” in the Start menu search box (Win-7 SP1) give me what I need?
Thanks for the post.
-
ch100
AskWoody_MVPMarch 30, 2016 at 7:40 pm #45149It seems that anytime the update was uninstalled, it automatically reinstalled itself almost instantly.
Tom, this is happening when you have older versions already installed and it appears that there are about 15 or more of them, I don’t know the exact number. When you uninstall the more recent one, the next most recent version will appear as installed and so on until you end uninstalling them all.
The DISM method is the ‘pro’/Sysadmin style one, Microsoft supported without doubt, but not for everyone who would likely be more comfortable using Programs and Features/Installed Updates.
Thanks for presenting it as a very good alternative and for reference as it can be used for any other bad behaving update or for updates partially installed which cause further problems in doing other updates etc. -
MikeFromMarkham
AskWoody Lounger -
B
GuestMarch 30, 2016 at 9:23 pm #45151 -
Graham
Guest -
Graham
Guest -
Lucian
Guest -
Sander
GuestMarch 31, 2016 at 4:21 am #45155This method was effective here, where no other method had succeeded. There has been no adverse after effects, however, there has been no improvement in speed, either perceived, or in tests. Still, it’s nice to be rid of it once and for all. It got by me during a WU cycle, and was the only Win 10 update on my Win 7 machine.
-
John
Guest -
Tregonsee
GuestMarch 31, 2016 at 5:07 am #45157I found over a dozen copies on my desktop computer. There were times when it was becoming sluggish, and I had done several scans for spyware without finding anything. After removing them and a reboot, it is running like new. I have created a batch file for easy access to check periodically. Many thanks for this.
-
Alex
Guest -
ch100
AskWoody_MVP -
Dimk
GuestMarch 31, 2016 at 7:59 am #45160I was able to get rid of KB 2952664 permanently by following the command prompt method mentioned here by Tom. (To be fair, I discovered this method 2 days ago in a post by a certain Lars at ghacks.net, dated October 2015. I dont’t know why this successful trick has not yet become widely known.)
Anyway, that was the last Windows 10 update in my PC.PS. Many hanks to you Woody, for your contribution in the computer world generally.
-
daniel
Guest -
Jack
Guest -
B
Guest -
daniel
Guest -
Jim in Yakima
GuestMarch 31, 2016 at 1:29 pm #45165Woody,
New instance of KB2952664 just now, upon reboot. You’ll remember my discovery last week of latent registry entries and the files in SoftwareDistribution. This is on my other Win 7 x64 Ult desktop. For certain, there is no 2952664 anywhere on that machine.
Optional, unchecked, unitalicized.
Looks like most recent affected file dates of 3-25-2016 (for x64).
-
cyberSAR
Guest -
byteme
AskWoody Plus -
woody
Manager -
Paranoid Paul
Guest -
cyberSAR
Guest -
ch100
AskWoody_MVP -
daniel
Guest -
B
Guest -
Roger
Guest -
Graham
GuestApril 1, 2016 at 1:55 am #45175I have 10 instances installed. If I remove the latest one it works. Reboot and it’s gone.
If I then try to remove the next latest one, I get an Error 1726 – The remote procedure failed. Failure configuring windows updates. Reverting changes.
The computer reboots and I now have no updates at all showing as installed.
I have to do a restore to get the system working again.
-
Paranoid Paul
Guest -
Graham
GuestApril 1, 2016 at 8:07 am #45177Finally managed to get this to work. Did some dism cleanup routines and a sfc /scannow
Found I had to remove the OLDEST instance first and work down. The last one could not be removed with dism.
Removed the last one using Windows Updates – Installed and when I rebooted (offline) it was finally gone.
Did a WU check and hid it and another one from 2014 and all is sweet – at long last!
-
poohsticks (used to be username “D.”)
GuestApril 1, 2016 at 3:41 pm #45178To anyone —
Because I know very little about interacting with the registry, I have 2 simple questions:
The instructions in the blogpost above say:
“First, from an elevated command prompt enter:
( dism /online /get-packages | findstr KB2952664 )
This pull up all KB2952664 packages.”Q1. If I type that into an elevated command prompt, do I need to include the parentheses and the spaces that appear before and after the main string?
Q2. If I type that into an elevated command prompt, and press enter, does it only pull up a list of information, and alters nothing in the registry?
I would only want to see the information (to see if any versions of 2664 are on my computer). I don’t want to go on to do the second step described in the blogpost, which is deleting the instances of 2664 via this method (due to my inexperience with the registry).
Thank you!
-
twbartender
AskWoody LoungerApril 1, 2016 at 6:19 pm #45179 -
Brady
GuestApril 1, 2016 at 8:08 pm #45180 -
Poohsticks (formerly known as “D.”)
GuestApril 6, 2016 at 3:12 pm #45181@Tom and @Brady,
Thank you for the instructions! I’ll give this a try.
—–
@Brady,Thank you for noticing, and for mentioning that you support, the thoughts that I’ve shared regarding privacy issues! 🙂
—–
P.S. I changed my username from the ubiquitous “D.” to the uncommon “Poohsticks” in the hopes that this would allow me more easily to search for the comments I leave on askwoody.com, so I could return to them later, to see if there had been any new replies to them.
The name-change experiment didn’t help much with the search function within Woody’s site, but it did help when searching the site from an external search engine.
P.P.S. Poohsticks is a game about throwing sticks into a stream from a bridge, from Winnie-the-Pooh. 🙂 -
woody
Manager -
Poohsticks (formerly known as “D.”)
GuestApril 6, 2016 at 5:08 pm #45183Woody, it’s actually not a bad search function as far as blog-based search boxes go!
I have used it here quite a bit in the last 6 months and generally I can find what I’m looking for, although the results are shown in a clunky format.
But it couldn’t find “D.” entries in the comments areas, and I don’t blame it for that!—–
Instead of moving over to Google, I thought I’d note that one might try the more privacy-minded Ixquick / Startpage search engines! 😉 😉– For searches using Google via an intermediate search engine which does not store information about you or your searches and does not provide Google with any information about you,
folks can go to Startpage.com
(Note that Startpage states that Google has agreed that Startpage can do this, so using it is not “stealing” from Google.)– For searches using a number of “other” search engines, other than Google
(they used to say that this search was based on Yahoo as the underlying search engine, but they don’t say that anymore, so maybe Yahoo asked them recently not to mention them by name)
via an intermediate search engine that doesn’t capture information about you or your searches,
folks can go to Ixquick.eu
(note the ending for that one is not “.com” but is rather “.eu” —
this is because ixquick.com was last week merged with the startpage.com search engine, but they kept the “.eu” ixquick as it was before).Personally, I prefer the ixquick.eu results over the startpage.com results, just as I prefer yahoo results over google results. ixquick.eu and startpage.com results are often different enough to make it useful to do your search via both of them.
-
Poohsticks (formerly known as “D.”)
GuestApril 6, 2016 at 5:22 pm #45184FYI, both ixquick and startpage have a number of settings you can adjust to your liking —
and you have the choice of saving your personal settings to either a cookie on your computer or recording it in a unique URL that you can bookmark (in case you don’t want to keep a cookie on your computer).
I save no cookies, so I love the convenience of having the bookmarked URL which automatically shows me the search results in the way that I’ve specified.
This shows the settings you can select from:
https://startpage.com/do/preferences?language=english&language_ui=english&nj=0&hmb=1&lmv=1—
Also, ixquick and searchpage will allow you to do “proxy” searches, where they act like they are the ones doing the search and don’t involve your personal details or ip location at all — then they show you what the page looks like, as it is being shown to them.
I find this useful when I want to click on links that I don’t know if I should 100% trust or not.
Sometimes it will show me what a webpage looks like when it’s a webpage that my Peerblock settings would have fully blocked me from seeing, but those settings aren’t triggered when it is Ixquick/Startpage that is previewing the page first.Here is their description of how that works: https://startpage.com/proxy/eng/help.html?hmb=1&lmv=1
Also here is some info on it: https://startpage.com/eng/protect-privacy-qa.html?&hmb=1&lmv=1#q13
-
Poohsticks (formerly known as “D.”)
GuestApril 6, 2016 at 5:34 pm #45185Okay, I tried entering
dism /online /get-packages | findstr KB2952664
at an elevated command prompt (open-as-administrator),
and after thinking for a minute, it just offered me a new blank command prompt beneath the original one:
“C:Windowssystem32>”I assume that means that I don’t have any KB29522664 packages on my computer (which I didn’t expect to have, so I’m glad).
-
Brady
Guest -
Peter
GuestApril 7, 2016 at 3:28 pm #45187Thanks very much to Tom for this fix, and Woody for posting it. I ran this procedure on four Windows 7 machines that I administer, and only one was clear. This had been set up recently, after I was aware of the GWX debacle and knew to block the appropriate updates from the off.
I’ll just add that if you’re on a 32 bit machine, you’ll need to substitute x86 for amd64 in the above command lines. You’ll see x86 in the results from the first step anyway, so it should be clear even if you’re not sure how many bits your Windows has.
Has anyone tried, or is there any need to remove KB3035583 in the same way? I have several versions of that too, but I’d tend to leave it well alone unless it’s actively being evil.
-
woody
Manager -
Peter
GuestApril 8, 2016 at 5:41 am #45189 -
Art Dent
GuestApril 9, 2016 at 6:48 am #45190Many thanks Tom and Woody for posting this. I have 3 Windows 7 machines and on the first one I checked out I had 4 instances of KB2952664 – versions 6.1.9.8, 6.1.10.5, 6.1.14.2 and 6.1.15.2.
Your command cleared out each instance.
I am now off to check the other two machines…
As the syntax of the command is exact (and some folks are not very tech savvy) I have reproduced your command line commands below – highlighting where the spaces are
dism^/online^/get-packages^|^findstr^KB2952664 (the ‘^’ character indicates ‘space’)
and similarly:
dism^/online^/remove-package^/PackageName:Package_for_KB2952664~31bf3856ad364e35~amd64~~6.1.1.3
No other spaces should be entered into the command string.
Hope this helps folks experiencing any difficulties.
Like Peter, I was also going to ask if I should use the same procedure to remove KB3035583.
Kind regards, Art
-
Peter
GuestApril 13, 2016 at 5:09 am #45191My work machine doesn’t have any instances of KB3035583 at all – probably down to the way update works on our corporate network.
Interestingly, I used dism to search for KB2952664 again on a previously cleared machine, and came up with four variants of version 6.1.17.5. I think this is a new version that I haven’t seen before. I most definitely didn’t opt for it to be installed, and I’m wondering where it came from. GWX Control Panel reports that I have 377.7KB in Windows 10 download folders which I didn’t have before – not a full update, obviously, but maybe a precursor for something? I have just installed other patches which all seemed innocuous.
I’m going to zap the KB2952664 packages, but keep the download folders and see what happens next.
-
Peter
GuestApril 13, 2016 at 5:27 am #45192I did more checking:
KB2952664 is in my update history. It was installed on a day when I wasn’t even here, so I suspect my IT department indiscriminately let some patches through on my behalf. How thoughtful of them. 🙂
The Win 10 download files are from when I ran the Media Creation Tool, so probably fair enough. (I wanted to ‘upgrade’ my laptop and then revert it, to make sure I qualify for free Win10 on that machine in the future.)
-
Clyde
GuestApril 15, 2016 at 7:37 pm #45193When I enter the command to remove the package (the first of two) I get the following:
Deployment Image Servicing and Management tool
Version: 6.1.7600.16385Image Version: 6.1.7601.18489
Processing 1 of 1 –
… and it just sits there, for a long time, with no apparent result.
If I eventually close out that elevated command prompt and try again “from the top” it still shows the two packages being installed.. thus, the first one attempted for removal is still there.
Any thoughts?
-
Clyde
Guest -
madaboutvoice
GuestOctober 3, 2016 at 12:33 am #45195Errrrm, According to GWX’s creator Josh Mayfield, KB2952664 is not screened by his program which I have had installed on my machine since June ’16 and I am still getting KB2952664 forced down my throat no matter what I do. Doing what is suggested in this article will get rid of previous copies of it on the machine but how to keep it out totally?
-
Chris
Guest -
MrBrian
GuestDecember 7, 2016 at 9:43 am #45197Another solution which I think would work is to use Disk Cleanup to remove superseded Windows updates. See https://support.microsoft.com/en-us/kb/2852386 for more information.
1 user thanked author for this post.
-
anonymous
GuestFebruary 24, 2017 at 6:16 pm #97196Awesome hack!!! I found seven (7) instances on my machine that I thought was so clean… now I’m looking for every known GWX KBfile to remove. Fortunately I started the process by removing the oldest (first version listed) first; some others here seem to have jumped the gun which caused additional issues. Just as “Tom” says do (include spaces as shown) and you too will have a KB2952664-free machine!!!
-
MrBrian
AskWoody_MVPApril 28, 2017 at 7:04 am #111614 -
GoneToPlaid
AskWoody LoungerApril 30, 2017 at 4:29 pm #112056Pardon my ignorance, but what is an “elevated” command prompt? Is there a difference between that and a plain-vanilla command prompt? Does its use require admin rights of some sort? Or will keying “command prompt” in the Start menu search box (Win-7 SP1) give me what I need? Thanks for the post.
Yes, an elevated command prompt is different since it gives you full Administrator rights. To launch an elevated command prompt, right-click on your Command Prompt link and then click on “Run as administrator”.
-
AlphaCharlie
AskWoody PlusMay 2, 2017 at 11:08 pm #112465Very interesting. On my Windows 7 Pro SP1 machine, I accessed the elevated prompt and typed dism /online /get-packages |findstr KB2952664
and it returned 9 entries.
Ther version numbers include 6.1.4.4, 6.1.16.0, and 6.1.20.1However, I also looked into
Control Panel > Programs > Programs and Features >Installed Updates
and typed KB2952664 in the upper right corner search box .Behold, it returns just ONE entry, and says that update was installed on 9/25/2014.
Furthermore, if I right click on it I am offered the option to uninstall.Also if I use Everything.exe to find every filename with 2952664, it locates 36 files, some are in C:\servicing\Packages
and the rest are in C:\Windows\system32\catroot\{F750E6CE-38EE-11D1……..So in the morning I am going to make a fresh backup of my hard drive (always a good idea).
Is there any chance of bricking my machine by doing
The right-click uninstall method is appealing because of its simplicity. But I ask the more experienced users here – should I just go directly to Tom’s method and do the DISM command for each version, starting with the oldest?
Thanks to Woody and Tom and all the great contributors here.
Alpha
-
MrBrian
AskWoody_MVPMay 3, 2017 at 7:46 am #112520There are two more scripts, both of them fully automated, in this post. My script there calls wusa.exe many times to uninstall a given update, which ought to uninstall the multiple installed versions in the proper order. Abbodi86’s script in that post automates the method in this topic. I can’t guarantee that my script is safe, but it worked in my test of removing 5 installed versions of KB2952664.
1 user thanked author for this post.
-
MrBrian
AskWoody_MVP -
AlphaCharlie
AskWoody PlusMay 6, 2017 at 11:35 pm #113183Well then, I did not use a script because I wanted to directly observe and learn what happens. I repeated the method in Tom’s original email:
- elevated command prompt
- dism /online /get-packages … to locate versions
- dism /online /remove-package ,… to remove oldest version
- reboot, and then repeat steps 1-3 for each version of the package
I cannot discern any speedup of my computer, nevertheless I say hooray, there are no more instances of KB2952664 that appear in response to the dism/online/getpackages search
And, there is no mention of KB2952664 in Control Panel > Programs > Programs and Features > Installed Updates
BUT, when i use Everything.exe to look for every filename with KB2952664, there are still 12 entries. Three versions each for
Package_for_KB2952664…
Package_1_forKB2952444…
Package_1_forKB2952444They all end with the file extension .CAT
and they are all in this folder:
C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}That folder is interesting, since it contains 5,636 files taking up 141 MB. The oldest file (OEM4.cat) is dated March 2007 while the newest file is “Package_817_for_KB4015549~31bf3856ad364e35~amd64~~6.1.1.3” dated March 2017.
ANYWAY, my only question now: is it a good idea to delete the .cat files with KB2952664 from this directory? They only amount to about 130KB of disk space.
Thank you!
-
MrBrian
AskWoody_MVPJuly 9, 2017 at 11:07 am #123987-
Bob99
AskWoody MVP
Viewing 56 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Enabling Secureboot
by
ITguy
1 hour, 48 minutes ago -
Windows hosting exposes additional bugs
by
Susan Bradley
6 hours, 33 minutes ago -
No more rounded corners??
by
CWBillow
2 hours, 21 minutes ago -
Android 15 and IPV6
by
Win7and10
7 hours, 38 minutes ago -
KB5058405 might fail to install with recovery error 0xc0000098 in ACPI.sys
by
Susan Bradley
18 hours, 54 minutes ago -
T-Mobile’s T-Life App has a “Screen Recording Tool” Turned on
by
Alex5723
21 hours, 36 minutes ago -
Windows 11 Insider Preview Build 26100.4202 (24H2) released to Release Preview
by
joep517
16 hours, 10 minutes ago -
Windows Update orchestration platform to update all software
by
Alex5723
1 day, 4 hours ago -
May preview updates
by
Susan Bradley
16 hours, 18 minutes ago -
Microsoft releases KB5061977 Windows 11 24H2, Server 2025 emergency out of band
by
Alex5723
7 hours, 53 minutes ago -
Just got this pop-up page while browsing
by
Alex5723
21 hours, 7 minutes ago -
KB5058379 / KB 5061768 Failures
by
crown
18 hours, 11 minutes ago -
Windows 10 23H2 Good to Update to ?
by
jkitc
2 hours, 44 minutes ago -
At last – installation of 24H2
by
Botswana12
1 day, 20 hours ago -
MS-DEFCON 4: As good as it gets
by
Susan Bradley
7 hours, 29 minutes ago -
RyTuneX optimize Windows 10/11 tool
by
Alex5723
2 days, 8 hours ago -
Can I just update from Win11 22H2 to 23H2?
by
Dave Easley
7 hours, 5 minutes ago -
Limited account permission error related to Windows Update
by
gtd12345
2 days, 22 hours ago -
Another test post
by
gtd12345
2 days, 22 hours ago -
Connect to someone else computer
by
wadeer
2 days, 16 hours ago -
Limit on User names?
by
CWBillow
2 days, 19 hours ago -
Choose the right apps for traveling
by
Peter Deegan
2 days, 9 hours ago -
BitLocker rears its head
by
Susan Bradley
1 day, 17 hours ago -
Who are you? (2025 edition)
by
Will Fastie
1 day, 16 hours ago -
AskWoody at the computer museum, round two
by
Will Fastie
2 days, 12 hours ago -
A smarter, simpler Firefox address bar
by
Alex5723
3 days, 8 hours ago -
Woody
by
Scott
3 days, 17 hours ago -
24H2 has suppressed my favoured spider
by
Davidhs
1 day, 17 hours ago -
GeForce RTX 5060 in certain motherboards could experience blank screens
by
Alex5723
4 days, 8 hours ago -
MS Office 365 Home on MAC
by
MickIver
4 days, 1 hour ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.
That was posted on the GHacks.net Website on June 7th of this year as a comment to a review of DISM++ on the site. Granted, the package he(she) got from chip.de might’ve been infected, just waiting for the right time to spring into action, but there is a post above the one quoted above that makes reference to VirusTotal’s checksum of the program and how it has shown up in other “numerous adware/malware packages”. Also granted, the poster’s name was shown as Anonymous, so that has to be taken into account as well.