Nuke and pave.
I don’t bother trying to diagnose and repair anymore. If I really think the system is compromised then it gets sanitized by fire.
Back up the data, Scan it on another PC, nuke the system, flash latest BIOS, erase the TPM and reinstall everything.