John,
This notebook is a mobile workstation and comes with a fingerprint reader. For the clean boot under services hide all Microsoft services was checked then disable all was clicked. On the startup tab the disable all was also clicked. Then the notebook was
rebooted.
On regular boot there are two icons, one for password and one for finger print. Typically I just swipe my finger multiple times until it detects my finger an launches windows 7 professional. In the clean boot there was only one icon. The finger print
was not available. I clicked on the icon. The HP Client Security responded please wait. The biometric authentication is not functioning properly. There were two choices, one to wait for it to respond or to login in without it. I then entered the password
and windows then opened in the clean boot state.
The HP Client Security has been a source of problems as it can block communication with flash drives, external hard drives. For example when it comes configured it may come from the factory with pre set settings to b on a network and block these communications.
All attempts to use typical administrative rights are always trumped by any settings within the HP Client Security. For the new user this experience was painful as it was not expected that the default setting was for networks and to block USB port access.
For the clean boot I did not know how it would perform until I made the typical steps for the clean boot.
In control panel then add remove programs there are 84 programs. Most of these were pre-installed followed by updates. Sometimes if there were issues with any pre-installed software I would delet it and then reinstall it using the serial number or product
code from the HP web site. Under control panel add remoe programs there are 84 programs and in this view they are listed by installed on date:



The computer was brand new and placed into use on 9/20/2015. There are 49 items with an installation date on or after 9/20/2015. Eliminating HP, Nvidia, Intel items and drivers these are items that could easily be tested by un-installation and re-installation:
go to meeting
adobe acobat reader
adobe flash player
mozilla maintenance service
mozilla firefox
java 8 udate 73
adobe flash player 20 activex
ccleaner
speedfan
google chrome
whocrashed
spybot search and destroy
malwarebytes anti malware
cisco webex meetings
skype
samsung kies
everything
adobe shockwave player
adobe air
citrix online launcher
Of the listings spypot and speedfan would be the first suspects. However the performance during safe boot did not seem much difference from clean boot.
Somewhere in the process of Clean boot to safe boot I attempted to fine tune to reply to w32tm. I didn't know enough about the w32tm as to why it sometimes displayed the isp address and more often displayed unavailable. In safe boot I had attempted to
use the microsoft fixit and in the process it indicated that it would not complete the process in safe mode. Then I went back to regular boot and used it. I don't remember now what the result was. I do remeber seeing windows time under services. I may
have checked query source in addition to query status. Also I may have attempted manual net stop w32time fthe w32tm /unregister then w32tm /register then net start w3time. I may have tried w32tm /resync. Somewher in the process I don't think I was able
to get it to to display the ISP address. I seemed to me that if the time settings were not set optimally before running clean boot or safe mode it could make the testing inaccurate or incomplete. So I was attempting to get it in the optimal state before
either clean boot or safe mode For this I didn't know what it should display for w32tm /query /status to make it a valid test before running the clean boot or safe mode. I can repeat these again.
For malware I've never had any known malware on this notebook. I refresh spybot immunize and scan at least one or more times per day. MSE I refresh daily and run quick scans in addition to the automated scan once per week. Also I run the full scan once
per week. Malwarebytes I run once per week. I used you link to Kaspersky root kit and downloaded their software from http://support.kaspersky.com/viruses/disinfection/5350. When I attempted ti use it it was going to automatically uninstall MSE. I didn't
know whether I should allow it to uninstall MSE. Also I didn't check to see how to reinstall MSE if spybot and malwarebytes were already installed. Would they need to be removed before reinstallation?

Hp suggested running the time test in the bios. The enI were to ship it to him that that is what he would do. Unfortunately in the bios the detection is by minutes and not by seconds. Testing the bios prevents use of the computer and when using the computer
the time delay typically starts at approximately 5 seconds delay and progresses to 1 minute and 15 seconds to 1 minute and 20 seconds delay before resetting. It had kept resetting on its own at this level of delay. There were two periods of time where the
delay was greater than 1 minute and 20 seconds. That was the first 3 days after the motherboard replacement where time delays rose to over 5 minutes. On the third day after the motherboard replacement the computer was rebooted and the bios was updated. The
progressive time delay changed from over 5 minutes to back to the typical progression of up to 1 minute and 15 to 20 second delay.
The other progressive longer term time period was recent where the time delay rose to over 4 minutes. There has been no recent bios update. This has somehow returned to the typical progressive delay of up to 1 minute 15 to 20 second delay before it automatically
resets. I don;t know how or why it automatically resets back to approximately 5 seconds delay on its own when the windows time is only done once per week and this over one minute time delay and reset happens each day or probably more than once per day. If
I view the bios time which is only in minutes I am wondering whether I would likely miss it. I am wondering if it does delay in the bios whether I would be able to capture the time period that is over one minute delay before it resets itself. With the bios
only moving in minutes if this is not watched constantly the 1 minute minimum delay could be missed before it resets itself. So this may be a useful test but it appears at first to be a challenge to not see the seconds delay and wait hours to see more than
one minute delay before it resets itself.
When rerunning either clean boot or safe mode are the test invalid if the w32tm displays the specified service does not exist as an installed service?

What steps should be done and what should be displayed for administrative command prompt w32tm /query /status and or w32tm /query /source to the testing useful before starting mode? Are the timings for reboot after making changes important/unimportant
knowing that each clean boot and safe mode will require a reboot?
The Microsoft fixit https://technet.microsoft.com/en-us/library/cc738995(v=ws.10).aspx was just ran and the w32tm is /query /status is now displaying the service has not been started:

The administrative command prompt net start w32time was then entered and displayed:

It is unclear how to get the service started without errors. Using administrative command promw32tm /resync was entered and it displayed: the service has not been started

The administrative command prompt displays More help is available by typing NET HELPMSG 3521.
When I typed either NET HELPMSG 3521 or NET HELPMSG 3521. they did not work.
the unregister command w32tmplayed access is denied
the w32tm /register command was successful.
How come the registration was needed after the Microsoft fixit as it was already registered with the fixit?
the net start w32time did not work after the register and displayed: The service start failed since one or more services in the same process have an incompatible service SID type setting. A service with restricted service SID type can only coexist in
the same process with other services with a restricted SID type. If the service SID type for this service was just configured, the hosting process must be restarted in order to start this service.

It's unclear to me how to be ready with the w32tm before testing with either clean boot or safe mode. If it doesn't get to where it displays an ISP address does it make the test useful? In this case I could never get to to display anything beyond errors
or not started.
Using administrative command prompt and typing w32tm /config /update displayed the service has not been started.
entering: reg query HKLM\SYSTEM\CurrentControlSet\services\W32Time\Parameters /v ntpserver
displayed ntpserver REG_SZ time .windows.com,0x9


The time drifted in safe mode like it did with regular boot and clean boot. The difference that I noted was that in safe mode each browser opened with time ahead then there was progressive delay to time exact then time behind the progressive time behind.
In regular boot the time started with time behind and then progressed to approximately 1 minute 15 to 20 seconds and then reset.
This is information about the HP Client Security: http://h10032.www1.hp.com/ctg/Manual/c04597082
What's happening with the w32tm commands that don't start or display the status with isp?
How come the resync does not allow it to restart?
How come the fixit does an incomplete fix?
How did you want me to proceed with the Kaspersky test and un-installation of MSE
Which of the items in control panel did you want me to uninstall before retesting the time delay?
What should be the w32tm displayed result in administrative command prompt before rebooting to clean boot to make the clean boot a useful test?