Yes you found the joy Click to Run. I use a music service that went to that approach. I use Appguard and I always have to turn it off to start the service as it uses Rundll32 to kick things off. When EAM quarantined it it redownloaded another copy and by then EAM figured out it was a false positive. It may have faked out the delete button because it's a non standard file in a non standard location. The new download has not been bothered. This is why I just wanted to clean it out. I didn't see it as an EAM problem, but an artifact of MS.