Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-07-2026 Ran by Heine (administrator) on HEINE (Micro-Star International Co., Ltd. GP66 Leopard 11UG) (18-07-2026 20:11:52) Running from C:\Users\Heine\Downloads\FRST64.exe Loaded Profiles: Heine Platform: Microsoft Windows 11 Home Version 23H2 22631.6199 (X64) Language: Dansk (Danmark) Default browser: FF Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (C:\Program Files (x86)\MSI\One Dragon Center\MSI_Central_Service.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\MSI.CentralServer.exe (C:\Program Files (x86)\Steam\steam.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe (C:\Program Files\LGHUB\system_tray\lghub_system_tray.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_agent.exe (C:\Program Files\Mozilla Firefox\firefox.exe ->) (Mozilla Corporation -> Mozilla Foundation) C:\Program Files\Mozilla Firefox\crashhelper.exe (C:\Program Files\SteelSeries\GG\apps\engine\SteelSeriesEngine.exe ->) (GN Hearing A/S -> SteelSeries ApS) C:\Program Files\SteelSeries\GG\apps\engine\prism\SteelSeriesPrism.exe (C:\Program Files\SteelSeries\GG\SteelSeriesGGEZ.exe ->) (GN Hearing A/S -> SteelSeries A/S) C:\Program Files\SteelSeries\GG\apps\engine\SteelSeriesEngine.exe (C:\Program Files\SteelSeries\GG\SteelSeriesGGEZ.exe ->) (GN Hearing A/S -> SteelSeries A/S) C:\Program Files\SteelSeries\GG\apps\moments\SteelSeriesMoments.exe (C:\Program Files\SteelSeries\GG\SteelSeriesGGEZ.exe ->) (GN Hearing A/S -> SteelSeries A/S) C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe (Discord Inc. -> Discord Inc.) C:\Users\Heine\AppData\Local\Discord\app-1.0.9248\Discord.exe <6> (drivers\RivetNetworks\Killer\KAPSService.exe ->) (Intel Corporation -> Intel® Corporation) C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KAPS.exe (drivers\RivetNetworks\Killer\KNDBWMService.exe ->) (Intel Corporation -> Intel® Corporation) C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KNDBWM.exe (drivers\RivetNetworks\Killer\KSPSService.exe ->) (Intel Corporation -> Rivet Networks LLC) C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KSPS.exe (DriverStore\FileRepository\cui_dch.inf_amd64_fc1b619200a17491\igfxCUIServiceN.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_fc1b619200a17491\igfxEMN.exe (DriverStore\FileRepository\dptf_cpu.inf_amd64_c2c5b0e17a28a48f\esif_uf.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_c2c5b0e17a28a48f\dptf_helper.exe (DriverStore\FileRepository\icss_extension.inf_amd64_5a31f42a9232b755\UserAwarenessService.exe ->) (Intel Corporation -> Intel Corp) C:\WINDOWS\System32\DriverStore\FileRepository\icss_extension.inf_amd64_5a31f42a9232b755\UserAwarenessHelper.exe (explorer.exe ->) (GN Hearing A/S -> SteelSeries A/S) C:\Program Files\SteelSeries\GG\SteelSeriesGGEZ.exe (explorer.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\system_tray\lghub_system_tray.exe (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_61225a54a5775612\RtkAudUService64.exe (explorer.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\steam.exe (Microsoft Corporation -> Microsoft Corporation) C:\WINDOWS\System32\GameInputSvc.exe (Microsoft Corporation -> Windows (R) Win 7 DDK provider) C:\Program Files\Microsoft GameInput\x64\GameInputRedistService.exe (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) [File not signed] C:\Program Files\WindowsApps\9426MICRO-STARINTERNATION.DragonCenter_2.0.131.0_x64__kzh8wxbdkxb8p\DCv2\DCv2.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe <16> (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2> (NVIDIA Corporation -> NVIDIA Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_62de3bd48abb42a6\Display.NvContainer\NVDisplay.Container.exe (Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (services.exe ->) (Adobe Inc. -> Adobe Inc.) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (services.exe ->) (HP Inc. -> HP Inc.) C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe (services.exe ->) (Intel Corporation -> Intel Corp) C:\WINDOWS\System32\DriverStore\FileRepository\icss_extension.inf_amd64_5a31f42a9232b755\UserAwarenessService.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_fc1b619200a17491\igfxCUIServiceN.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_b45f13a105037dbe\jhi_service.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_c2c5b0e17a28a48f\esif_uf.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_92899f2b73e871b4\IntelCpHDCPSvc.exe (services.exe ->) (Intel Corporation -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_92a56761ef7ba712\WMIRegistrationService.exe (services.exe ->) (Intel Corporation -> Intel) C:\WINDOWS\System32\drivers\RivetNetworks\Killer\IntelNetworkHelperService.exe (services.exe ->) (Intel Corporation -> Intel) C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KillerAnalyticsService.exe (services.exe ->) (Intel Corporation -> Intel) C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KillerNetworkService.exe (services.exe ->) (Intel Corporation -> Intel) C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KillerProviderDataHelperService.exe (services.exe ->) (Intel Corporation -> Intel) C:\WINDOWS\System32\DriverStore\FileRepository\intcoed.inf_amd64_a952167d9e98b004\AS\IAS\IntelAudioService.exe (services.exe ->) (Intel Corporation -> Intel® Corporation) C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KAPSService.exe (services.exe ->) (Intel Corporation -> Intel® Corporation) C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KNDBWMService.exe (services.exe ->) (Intel Corporation -> Rivet Networks, LLC.) C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KSPSService.exe (services.exe ->) (Intel(R) pGFX 2020 -> Intel Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_78ff17a5ea060c5f\OneApp.IGCC.WinService.exe (services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\Program Files\LGHUB\lghub_updater.exe (services.exe ->) (Logitech Inc -> Logitech, Inc.) C:\WINDOWS\System32\DriverStore\FileRepository\logi_lamparray_usb.inf_amd64_194fb61e2a706bd5\logi_lamparray_service.AMD64.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (services.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\WINDOWS\System32\GameInputSvc.exe (services.exe ->) (Microsoft Corporation -> Windows (R) Win 7 DDK provider) C:\Program Files\Microsoft GameInput\x64\GameInputRedistService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe (services.exe ->) (Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe (services.exe ->) (Micro-Star International CO., LTD. -> ) C:\Program Files (x86)\MSI\MSI NBFoundation Service\Sendevsvc.exe (services.exe ->) (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\MSI NBFoundation Service\MSIAPService.exe (services.exe ->) (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\WINDOWS\SysWOW64\MSIService.exe (services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\One Dragon Center\Game_Summary\MSI_Companion_Service.exe (services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\MSI_Central_Service.exe (services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LightKeeperService.exe (services.exe ->) (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Mystic_Light_Service.exe (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_62de3bd48abb42a6\Display.NvContainer\NVDisplay.Container.exe (services.exe ->) (Plex, Inc. -> Plex, Inc.) C:\Program Files\Plex\Plex Media Server\Plex Update Service.exe (services.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_61225a54a5775612\RtkAudUService64.exe (services.exe ->) (Samsung Electronics Co., Ltd. -> Clonix & CottonCandy) C:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe (services.exe ->) (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe (services.exe ->) (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\steamservice.exe (sihost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\GCP.ML.BackgroundSysTray\IGCCTray.exe (svchost.exe ->) (EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3 -> Intel Corporation) C:\Program Files\WindowsApps\AppUp.IntelGraphicsExperience_1.100.5688.0_x64__8j3eq9eme6ctt\IGCC.exe (svchost.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.StartExperiencesApp_1.380.0.0_x64__8wekyb3d8bbwe\MicrosoftStartFeedProvider\MicrosoftStartFeedProvider.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe <3> (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\smartscreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\System32\wbem\WMIADAP.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\SystemApps\Microsoft.Windows.AppRep.ChxApp_cw5n1h2txyewy\CHXSmartScreen.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\WINDOWS\SysWOW64\wbem\WmiPrvSE.exe <2> (svchost.exe ->) (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\MSI NBFoundation Service\OmApSvcBroker.exe (Valve Corp. -> Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win64\steamwebhelper.exe <6> ==================== Registry (Whitelisted) =================== HKLM\...\Run: [RtkAudUService] => C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_61225a54a5775612\RtkAudUService64.exe [3435048 2026-04-15] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [SteelSeriesGG] => C:\Program Files\SteelSeries\GG\SteelSeriesGGEZ.exe [195640 2026-06-29] (GN Hearing A/S -> SteelSeries A/S) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [751240 2026-03-30] (Oracle America, Inc. -> Oracle Corporation) HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKLM\Software\Policies\...\system: [EnableActivityFeed] 0 HKLM\Software\Policies\...\system: [PublishUserActivities] 0 HKLM\Software\Policies\...\system: [UploadUserActivities] 0 HKLM\Software\Policies\...\system: [AllowClipboardHistory] 0 HKLM\Software\Policies\...\system: [AllowCrossDeviceClipboard] 0 HKU\S-1-5-21-1513235227-3861919680-1317406885-1001\...\Run: [MicrosoftEdgeAutoLaunch_D019BE56E58739F2B79B6F41E8F4F4AF] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4081192 2024-05-02] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-1513235227-3861919680-1317406885-1001\...\Run: [AF_uuid_2139460] => f32ec99d-6542-466c-b9a1-2abcd4a01746 (No File) HKU\S-1-5-21-1513235227-3861919680-1317406885-1001\...\Run: [AF_counter_2139460] => 51 (No File) HKU\S-1-5-21-1513235227-3861919680-1317406885-1001\...\Run: [LGHUB] => C:\Program Files\LGHUB\system_tray\lghub_system_tray.exe [26469016 2026-07-09] (Logitech Inc -> Logitech, Inc.) HKU\S-1-5-21-1513235227-3861919680-1317406885-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [45052888 2026-06-24] (Adobe Inc. -> Adobe Systems Incorporated) HKU\S-1-5-21-1513235227-3861919680-1317406885-1001\...\Policies\Explorer: [HideSCAMeetNow] 1 HKLM\...\Print\Monitors\HP D711 Status Monitor: c:\windows\system32\hpinkstsD711LM.dll [393352 2017-03-26] (Hewlett Packard -> HP Inc.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{49210152-871f-4ffa-961d-a172abcbc09d}] -> C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4468376 2026-07-03] (Google LLC -> Google LLC) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files\Google\Chrome\Application\150.0.7871.125\Installer\chrmstp.exe [7681176 2026-07-16] (Google LLC -> Google LLC) HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] -> GroupPolicy: Restriction ? <==== ATTENTION Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION ==================== Scheduled Tasks (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {3f34859a-00fa-4e30-8a6c-d744914052b3} - no filepath. <==== ATTENTION Task: {C38443A0-112C-40A3-9C74-F840E9BC98F5} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1612800 2026-01-23] (Adobe Inc. -> Adobe Inc.) Task: {041F3475-5AAE-4698-A9C8-DF3077396851} - System32\Tasks\GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem152.0.7933.0{24221C41-F285-4361-927D-40ED4D532AA5} => C:\Program Files (x86)\Google\GoogleUpdater\152.0.7933.0\updater.exe [9512088 2026-07-05] (Google LLC -> Google LLC) Task: {752038D3-7184-4CEE-B82F-23E0582D294A} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Daily => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4468376 2026-07-03] (Google LLC -> Google LLC) Task: {50F3888F-58EE-4BE4-9B4E-C29455829795} - System32\Tasks\GoogleUserPEH\RunPlatformExperienceHelper_Metrics => C:\Program Files\Google\Chrome\Application\PlatformExperienceHelper\platform_experience_helper.exe [4468376 2026-07-03] (Google LLC -> Google LLC) Task: {C75945D3-0508-4FC4-B7C2-1CDC3DBEC473} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4922296 2023-12-19] (Intel Corporation -> Intel Corporation) Task: {39203AEB-A181-47FC-87BC-3BDABE1AFBB1} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [4922296 2023-12-19] (Intel Corporation -> Intel Corporation) Task: {0D871505-B4EF-412E-B1C3-88A5AB21D0C8} - System32\Tasks\Microsoft\Office\Office Actions Server => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [16500520 2026-07-14] (Microsoft Corporation -> Microsoft Corporation) Task: {E98E6255-AA22-4550-9E91-664CF1536D6A} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28493632 2026-07-03] (Microsoft Corporation -> Microsoft Corporation) Task: {2012664E-96E7-4983-A71E-2AD6C468BBA9} - System32\Tasks\Microsoft\Office\Office Background Push Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\OFFICE16\opushutil.exe [73640 2026-07-14] (Microsoft Corporation -> Microsoft Corporation) Task: {8301132D-B97E-4EFB-9607-F2D1C8239E25} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [28493632 2026-07-03] (Microsoft Corporation -> Microsoft Corporation) Task: {ECD16A1D-64A5-4609-8DC6-36392640A2D0} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [432488 2026-07-14] (Microsoft Corporation -> Microsoft Corporation) Task: {E401CCE1-E216-4DC9-930D-534619C6F0A1} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [432488 2026-07-14] (Microsoft Corporation -> Microsoft Corporation) Task: {4B7B5A6F-C292-4E68-B679-9199D6A83DEB} - System32\Tasks\Microsoft\Office\Office Performance Monitor => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\operfmon.exe [1335576 2026-06-30] (Microsoft Corporation -> Microsoft Corporation) Task: {F6DFA62E-9983-4FF2-8FCC-E4CFE28C9078} - System32\Tasks\Microsoft\Office\Office Startup Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ActionsServer\ActionsServer.exe [16500520 2026-07-14] (Microsoft Corporation -> Microsoft Corporation) Task: {A34B9F86-2A1B-46F2-9DDF-05EE01979E0B} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_AC => %systemroot%\system32\MusNotification.exe /RunOnAC RebootDialog (No File) Task: {2EC8C288-0F01-4FD4-8B45-CA50E6F3C5D7} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot_Battery => %systemroot%\system32\MusNotification.exe /RunOnBattery RebootDialog (No File) Task: {4582F9FA-C3C9-403F-B4AC-A3EED4BB0BEA} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {0F4FB49E-E4F2-442A-90A6-A31AE0D13948} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {38522021-1D43-4144-9091-E242CE2F655F} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {F6EE3D0C-A18F-4EEB-A3A0-8FB839035C29} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpCmdRun.exe [1893920 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) Task: {ABDA3E1D-11F0-4A61-9EB1-915BB238CE50} - System32\Tasks\Mozilla\Firefox Background Update 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705152 2026-07-14] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters). Task: {F82C940D-E018-46C2-A893-9213065CA18B} - System32\Tasks\Mozilla\Firefox Background Update S-1-5-21-1513235227-3861919680-1317406885-1001 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\firefox.exe [705152 2026-07-14] (Mozilla Corporation -> Mozilla Corporation) -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\--MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask background (the data entry has 6 more characters). Task: {A35EAA5C-00FF-433A-AFA0-886FCD959F2A} - System32\Tasks\Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB => C:\Program Files\Mozilla Firefox\default-browser-agent.exe [33920 2026-07-14] (Mozilla Corporation -> Mozilla Foundation) Task: {C54804A6-7075-4BAA-8D53-54FAECE4F443} - System32\Tasks\MSI Task Host - Detect_Monitor => C:\Program Files (x86)\MSI\One Dragon Center\MSI.NotifyServer.exe [100592 2022-05-23] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) Task: {4F544C1F-4374-40A4-AEF4-E6E37F09EE05} - System32\Tasks\MSI Task Host - DisplayID => C:\Program Files (x86)\MSI\One Dragon Center\MSI.NotifyServer.exe [100592 2022-05-23] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) Task: {FF870E1C-214D-46F3-81A5-E6D7A7E98014} - System32\Tasks\MSI Task Host - LEDKeeper2_Host => C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LEDKeeper2.exe [1820280 2022-12-09] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) Task: {8EF16003-6DD5-4E0B-8C53-B070ABAD4AE2} - System32\Tasks\NahimicSvc32Run => C:\Windows\SysWOW64\NahimicSvc32.exe [1128080 2025-12-22] (SteelSeries France SASU -> Nahimic) Task: {2C83EBF4-30B0-4A90-BDCD-46395E69F011} - System32\Tasks\NahimicSvc64Run => C:\Windows\system32\NahimicSvc64.exe [1448080 2025-12-22] (SteelSeries France SASU -> Nahimic) Task: {00667D24-AC74-4F47-A9A6-A71290F0347F} - System32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA App\CEF\NVIDIA App.exe [3598960 2026-07-02] (NVIDIA Corporation -> NVIDIA Corporation) Task: {1D53CCD3-539A-47D5-872D-2E66B8917E56} - System32\Tasks\OmApSvcBroker => C:\Program Files (x86)\MSI\MSI NBFoundation Service\OmApSvcBroker.exe [961584 2024-07-04] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) Task: {DCBC8BDB-C1BD-451D-BBA7-54465B4E76CC} - System32\Tasks\OneDC_Updater => C:\Users\Heine\Documents\temp\OneDC_Updater\OneDC_Updater.exe [5311400 2021-04-16] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) Task: {5A34D73C-B5F3-458F-8560-F6AE0A7F627F} - System32\Tasks\RNIdle Task => C:\WINDOWS\System32\drivers\RivetNetworks\Killer\RNIdleTask.exe [34072 2026-02-23] (Intel Corporation -> Intel) Task: {5B15A496-7F22-41F3-8B2E-3E3907006D80} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [121595968 2023-01-16] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) -> C:\Program Files (x86)\Samsung\Samsung Magician\\/AUTOHIDE Task: {3DC81925-7CA9-4C20-A8C8-1900D001FA94} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => C:\WINDOWS\System32\Wscript.exe [200704 2025-09-24] (Microsoft Windows -> Microsoft Corporation) -> C:\Program Files\Intel\SUR\QUEENCREEK\x64\//B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs" Task: {F2E3B0E6-E1E6-49EF-B4BE-29FE43B1324B} - System32\Tasks\ZoomUpdateTaskUser-S-1-5-21-1513235227-3861919680-1317406885-1001 => C:\Users\Heine\AppData\Roaming\Zoom\bin\Zoom.exe [511872 2026-06-26] (Zoom Communications, Inc. -> Zoom Communications, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}: [DhcpDomain] webspeed.dk Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\05275647479764C69764F6271475966696: [DhcpNameServer] 192.168.94.11 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\14273756E616C66434: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\14273756E616C66434: [DhcpDomain] home Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\14355535: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\14355535F55374: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\14962745965637F51496274393630302537686A7: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\14962745965637F514962743936303F593333383: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\25567696F6E6D4944445D27416563747: [DhcpNameServer] 10.20.30.40 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\25567696F6E6D4944445D27416563747: [DhcpDomain] guest.net.rm.dk. Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\341626C65624F687D273645454: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\341626C65624F687D273645454: [DhcpDomain] webspeed.dk Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\3547F666167323937363: [DhcpNameServer] 212.10.10.4 212.10.10.5 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\44166796463794E6475627E65647F5537484A7: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\44166796463794E6475627E65647F5537484A7: [DhcpDomain] webspeed.dk Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\45865602D416273786D616C6C6F67702845747: [DhcpNameServer] 147.78.28.2 147.78.28.10 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\75966496D214136434: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\75966496D214136434: [DhcpDomain] webspeed.dk Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\75966496D223333434: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\75966496D223333434: [DhcpDomain] webspeed.dk Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\845696E65623437686A7: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\845696E65623437686A7: [DhcpDomain] home Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\845696E656537486A7: [DhcpNameServer] 212.242.40.3 212.242.40.51 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\845696E656537486A7: [DhcpDomain] home Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\845696E656537686A7: [DhcpNameServer] 212.242.40.3 212.242.40.51 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\845696E656537686A7: [DhcpDomain] home Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\A5978756C6F573032413: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\A5978756C6F573032413: [DhcpDomain] home Tcpip\..\Interfaces\{1b22cbfd-21d5-4b3f-880d-beeeb1801681}\E496E6F63702742716E6460284F64756C6: [DhcpNameServer] 10.0.0.1 Tcpip\..\Interfaces\{2cc732ee-4168-46e4-a008-7c7af6417054}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{2cc732ee-4168-46e4-a008-7c7af6417054}: [DhcpDomain] webspeed.dk FireFox: ======== FF TaskBarID: 308046B0AF4A39CB -> C:\Program Files\Mozilla Firefox FF DefaultProfile: 1znc2eij.default-release-2-1711613683999 -> 308046B0AF4A39CB FF ProfilePath: C:\Users\Heine\AppData\Roaming\Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999 [2026-07-18] FF Notifications: Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999 -> hxxps://www.facebook.com; hxxps://www.tiktok.com; hxxps://www.youtube.com FF Extension: (New Tab) - C:\Users\Heine\AppData\Roaming\Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999\Extensions\newtab@mozilla.org.xpi [2026-07-18] FF Extension: (uBlock Origin) - C:\Users\Heine\AppData\Roaming\Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999\Extensions\uBlock0@raymondhill.net.xpi [2026-07-08] FF Extension: (Dark space - The best dynamic theme) - C:\Users\Heine\AppData\Roaming\Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999\Extensions\{22b0eca1-8c02-4c0d-a5d7-6604ddd9836e}.xpi [2024-03-28] FF Extension: (ANIMATED Neutron Stars by candelora) - C:\Users\Heine\AppData\Roaming\Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999\Extensions\{2c216ba1-594a-4039-a389-b954f42ff809}.xpi [2024-03-28] FF Extension: (ANIMATED FIREFOX) - C:\Users\Heine\AppData\Roaming\Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999\Extensions\{68637f4d-f924-4aae-b062-b929b20e5ead}.xpi [2024-03-28] FF Extension: (Matte Black (Red)) - C:\Users\Heine\AppData\Roaming\Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999\Extensions\{a7589411-c5f6-41cf-8bdc-f66527d9d930}.xpi [2024-03-28] FF Extension: (Cosmic Cloud) - C:\Users\Heine\AppData\Roaming\Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999\Extensions\{cdabc232-3126-426f-8624-3d4b1609e431}.xpi [2024-03-28] FF Extension: (Fire fox Nebula by candelora) - C:\Users\Heine\AppData\Roaming\Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999\Extensions\{ce61020f-c00c-4a17-b01f-d69be0fad886}.xpi [2024-03-28] FF Extension: (Dark) - C:\Users\Heine\AppData\Roaming\Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999\Extensions\{dd5f0c02-70f9-4e87-82fa-b4d4f8541518}.xpi [2024-03-28] FF Extension: (Popup Blocker (strict)) - C:\Users\Heine\AppData\Roaming\Mozilla\Firefox\Profiles\1znc2eij.default-release-2-1711613683999\Extensions\{de22fd49-c9ab-4359-b722-b3febdc3a0b0}.xpi [2026-01-30] FF Plugin: @java.com/DTPlugin,version=11.491.2 -> C:\Program Files\Java\jre1.8.0_491\bin\dtplugin\npDeployJava1.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.491.2 -> C:\Program Files\Java\jre1.8.0_491\bin\plugin2\npjp2.dll [2026-03-30] (Oracle America, Inc. -> Oracle Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2026-06-30] (Microsoft Corporation -> Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=3.0.16 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.18 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN) FF Plugin: @videolan.org/vlc,version=3.0.20 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2023-10-30] (VideoLAN -> VideoLAN) FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2026-06-24] (Adobe Inc. -> Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2014-04-28] (Adobe Systems Incorporated -> Adobe Systems) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2026-06-30] (Microsoft Corporation -> Microsoft Corporation) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-28] (Adobe Systems Incorporated -> Adobe Systems) Edge: ======= Edge Profile: C:\Users\Heine\AppData\Local\Microsoft\Edge\User Data\Default [2025-11-26] Edge Extension: (Google Docs Offline) - C:\Users\Heine\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2024-01-22] Edge Extension: (Edge relevant text changes) - C:\Users\Heine\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\jmjflgjpcpepeafmmgdpfkogkghcpiha [2024-09-30] Edge Extension: (Microsoft Power Automate) - C:\Users\Heine\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\kagpabjoboikccfdghpdlaaopmgpgfdc [2024-09-30] Edge Extension: (AdGuard AdBlocker) - C:\Users\Heine\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\pdffkfellgipmhklpdmokmckkkfcopbh [2024-09-30] Edge HKU\S-1-5-21-1513235227-3861919680-1317406885-1001\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [kagpabjoboikccfdghpdlaaopmgpgfdc] Chrome: ======= CHR Profile: C:\Users\Heine\AppData\Local\Google\Chrome\User Data\Default [2026-06-18] CHR Extension: (Adobe Acrobat: PDF edit, convert, sign tools) - C:\Users\Heine\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2026-06-18] CHR Extension: (Betalinger i Chrome Webshop) - C:\Users\Heine\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2026-05-29] CHR HKU\S-1-5-21-1513235227-3861919680-1317406885-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] CHR HKU\S-1-5-21-1513235227-3861919680-1317406885-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ljglajjnnkapghbckkcmodicjhacbfhk] CHR HKLM-x32\...\Chrome\Extension: [aegnopegbbhjeeiganiajffnalhlkkjb] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeARMservice; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [180216 2026-01-23] (Adobe Inc. -> Adobe Inc.) S3 AntiCheatExpert Protection; C:\Program Files\AntiCheatExpert\ACE-Service64.exe [3251080 2026-06-30] (ACEVILLE PTE LTD -> ANTICHEATEXPERT.COM) S3 AntiCheatExpert Service; C:\Program Files\AntiCheatExpert\SGuard\x64\SGuardSvc64.exe [2094552 2026-02-03] (ACEVILLE PTE LTD -> ANTICHEATEXPERT.COM) S3 battlenet_helpersvc; C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe [3641040 2026-06-17] (Blizzard Entertainment, Inc. -> Blizzard Entertainment) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [15747368 2024-05-12] (BattlEye Innovations e.K. -> ) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [13397312 2026-07-03] (Microsoft Corporation -> Microsoft Corporation) R2 CMigrationService; C:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe [761408 2023-01-16] (Samsung Electronics Co., Ltd. -> Clonix & CottonCandy) S3 EABackgroundService; C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe [18076024 2026-06-27] (Electronic Arts, Inc. -> Electronic Arts) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2024-02-10] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) S3 EasyAntiCheat_EOS; C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe [985896 2026-03-15] (EasyAntiCheat Oy -> Epic Games, Inc.) S3 EpicGamesUpdater; C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesUpdater.exe [3344336 2025-12-12] (Epic Games Inc. -> Epic Games, Inc.) S3 EpicOnlineServices; C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe [934368 2021-10-01] (Epic Games Inc. -> Epic Games, Inc.) S3 FACEITService; C:\Program Files\FACEIT AC\faceitservice.exe [66828168 2023-10-18] (FACE IT LIMITED -> ) R2 GameInputRedistService; C:\Program Files\Microsoft GameInput\x64\GameInputRedistService.exe [401792 2026-05-14] (Microsoft Corporation -> Windows (R) Win 7 DDK provider) R2 HPPrintScanDoctorService; C:\Program Files\HPPrintScanDoctor\HPPrintScanDoctorService.exe [243664 2025-05-06] (HP Inc. -> HP Inc.) R3 Intel Network Helper Service; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\IntelNetworkHelperService.exe [158269224 2026-02-23] (Intel Corporation -> Intel) R2 IntelAudioService; C:\WINDOWS\System32\DriverStore\FileRepository\intcoed.inf_amd64_a952167d9e98b004\AS\IAS\IntelAudioService.exe [532960 2025-12-17] (Intel Corporation -> Intel) R2 IntelContextService; C:\WINDOWS\System32\DriverStore\FileRepository\icss_extension.inf_amd64_5a31f42a9232b755\UserAwarenessService.exe [164528 2020-11-16] (Intel Corporation -> Intel Corp) R3 KAPSService; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KAPSService.exe [79128 2026-02-23] (Intel Corporation -> Intel® Corporation) R2 Killer Analytics Service; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KillerAnalyticsService.exe [2485528 2026-02-23] (Intel Corporation -> Intel) R2 Killer Network Service; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KillerNetworkService.exe [2994456 2026-02-23] (Intel Corporation -> Intel) R2 Killer Provider Data Helper Service; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KillerProviderDataHelperService.exe [1214232 2026-02-23] (Intel Corporation -> Intel) R2 KillerSmartphoneSleepService; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KSPSService.exe [77616 2024-05-14] (Intel Corporation -> Rivet Networks, LLC.) R3 KNDBWM; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KNDBWMService.exe [79128 2026-02-23] (Intel Corporation -> Intel® Corporation) R2 LGHUBUpdaterService; C:\Program Files\LGHUB\lghub_updater.exe [20985496 2026-07-09] (Logitech Inc -> Logitech, Inc.) R2 LightKeeperService; C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\LightKeeperService.exe [86776 2020-12-23] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) R2 logi_lamparray_service; C:\WINDOWS\System32\DriverStore\FileRepository\logi_lamparray_usb.inf_amd64_194fb61e2a706bd5\logi_lamparray_service.AMD64.exe [11567496 2026-05-09] (Logitech Inc -> Logitech, Inc.) R2 MDCoreSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MpDefenderCoreService.exe [2100520 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) R2 Micro Star SCM; C:\WINDOWS\SysWOW64\MSIService.exe [168056 2019-05-07] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) R2 MSI Foundation Service; C:\Program Files (x86)\MSI\MSI NBFoundation Service\MSIAPService.exe [89000 2021-11-16] (Micro-Star International CO., LTD. -> Micro-Star International Co., Ltd.) R2 MSI Sendevsvc; C:\Program Files (x86)\MSI\MSI NBFoundation Service\Sendevsvc.exe [307624 2021-04-16] (Micro-Star International CO., LTD. -> ) R2 MSI_Central_Service; C:\Program Files (x86)\MSI\One Dragon Center\MSI_Central_Service.exe [147696 2022-05-23] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) R2 MSI_Companion_Service; C:\Program Files (x86)\MSI\One Dragon Center\Game_Summary\MSI_Companion_Service.exe [143160 2021-03-31] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star INT'L CO., LTD.) R2 Mystic_Light_Service; C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Mystic_Light_Service.exe [39760 2021-05-11] (MICRO-STAR INTERNATIONAL CO., LTD. -> Micro-Star Int'l Co., Ltd.) S4 NahimicService; C:\WINDOWS\System32\NahimicService.exe [1920656 2025-12-22] (SteelSeries France SASU -> Nahimic) R2 NVDisplay.ContainerLocalSystem; C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_62de3bd48abb42a6\Display.NvContainer\NVDisplay.Container.exe [1702632 2026-06-12] (NVIDIA Corporation -> NVIDIA Corporation) R2 PlexUpdateService; C:\Program Files\Plex\Plex Media Server\Plex Update Service.exe [920864 2024-12-16] (Plex, Inc. -> Plex, Inc.) R2 SamsungMagicianSVC; C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe [371776 2023-01-16] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.) S3 SteelSeriesGGUpdateServiceProxy; C:\Program Files\SteelSeries\GG\updateService\SteelSeriesGGUpdateServiceProxy.exe [1587712 2025-03-12] (GN Hearing A/S -> ) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\NisSrv.exe [4769792 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.26060.3008-0\MsMpEng.exe [290704 2026-07-08] (Microsoft Windows Publisher -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 ACE-ADVT; C:\WINDOWS\system32\drivers\ACE-ADVT.sys [1168048 2026-07-18] (Microsoft Windows Hardware Compatibility Publisher -> ANTICHEATEXPERT.COM) S3 ACE-BASE; C:\WINDOWS\system32\drivers\ACE-BASE.sys [4125432 2026-07-18] (Microsoft Windows Hardware Compatibility Publisher -> ANTICHEATEXPERT.COM) S3 ACE-CORE102915; C:\Program Files\AntiCheatExpert\ACE-CORE102915.sys [3923200 2026-07-18] (Microsoft Windows Hardware Compatibility Publisher -> ANTICHEATEXPERT.COM) S3 ACE-GAME; C:\WINDOWS\system32\drivers\ACE-GAME.sys [2785616 2026-04-24] (Tencent Technology (Shenzhen) Company Limited -> ANTICHEATEXPERT.COM) R1 CTIIO; C:\WINDOWS\system32\drivers\CtiIo64.sys [29208 2023-05-08] (Microsoft Windows Hardware Compatibility Publisher -> Creative Technology Innovation Co., LTd.) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus2.sys [175824 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R1 FACEIT; C:\Program Files\FACEIT AC\FACEIT_AC.sys [73517104 2023-10-18] (Microsoft Windows Hardware Compatibility Publisher -> ) S3 FXVAD; C:\WINDOWS\system32\drivers\fxvad.sys [326656 2022-05-30] (Microsoft Windows Hardware Compatibility Publisher -> Windows (R) Win 7 DDK provider) S3 GENERICDRV; C:\WINDOWS\system32\amigendrv64.sys [35200 2023-05-18] (American Megatrends, Inc. -> Windows (R) Win 7 DDK provider) R3 iaLPSS2_GPIO2_TGL; C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_tgl.inf_amd64_4fcff055ed32f652\iaLPSS2_GPIO2_TGL.sys [132072 2024-04-18] (Intel Corporation -> Intel Corporation) R3 IntcUSB; C:\WINDOWS\System32\DriverStore\FileRepository\intcusb.inf_amd64_7e96b5cfecffcac7\IntcUSB.sys [949216 2025-12-17] (Intel Corporation -> Intel(R) Corporation) R3 KfeCoSvc; C:\WINDOWS\System32\drivers\RivetNetworks\Killer\KfeCo11X64.sys [234264 2026-02-23] (Intel Corporation -> Intel Corporation.) R3 KslD; C:\WINDOWS\System32\drivers\wd\KslD.sys [82312 2026-05-20] (Microsoft Windows -> Microsoft Corporation) R3 logi_audio_surround; C:\WINDOWS\System32\DriverStore\FileRepository\logi_audio.inf_amd64_affafe6e263c4f51\logi_audio_surround.sys [44112 2025-11-22] (Microsoft Windows Hardware Compatibility Publisher -> Logitech, Inc.) R3 logi_joy_bus_enum; C:\WINDOWS\System32\drivers\logi_joy_bus_enum.x64.sys [45448 2026-04-11] (Logitech Inc -> Logitech) R3 logi_joy_vir_hid; C:\WINDOWS\System32\drivers\logi_joy_vir_hid.x64.sys [32648 2026-04-11] (Logitech Inc -> Logitech) R3 logi_joy_xlcore; C:\WINDOWS\System32\drivers\logi_joy_xlcore.x64.sys [74632 2026-04-11] (Logitech Inc -> Logitech) R3 logi_lamparray; C:\WINDOWS\System32\DriverStore\FileRepository\logi_lamparray_usb.inf_amd64_194fb61e2a706bd5\logi_lamparray.AMD64.sys [89480 2026-05-09] (Logitech Inc -> Logitech, Inc.) R3 msihid; C:\WINDOWS\System32\drivers\msihid.sys [45104 2025-11-04] (Microsoft Windows Hardware Compatibility Publisher -> SteelSeries ApS) R1 MSIO; C:\Windows\system32\drivers\MsIo64.sys [17424 2020-01-19] (Microsoft Windows Hardware Compatibility Publisher -> MICSYS Technology Co., LTd) R3 NahimicBTLink; C:\WINDOWS\System32\drivers\NahimicBTLink.sys [95968 2025-12-12] (A-Volute SAS -> Windows (R) Win 7 DDK provider) R3 Nahimic_Mirroring; C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys [95992 2025-10-14] (A-Volute SAS -> Windows (R) Win 7 DDK provider) R3 nvpcf; C:\WINDOWS\System32\drivers\nvpcf.sys [308968 2026-05-20] (NVIDIA Corporation -> NVIDIA Corporation) R2 PTIMon; C:\WINDOWS\System32\drivers\PTIMon.sys [53984 2016-04-14] (Intel Corporation -> ) R3 rt25cx21; C:\WINDOWS\System32\DriverStore\FileRepository\rt25cx21x64.inf_amd64_b5ae09afa2415d44\rt25cx21x64.sys [934944 2026-01-25] (Realtek Semiconductor Corp. -> Realtek) R3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [43568 2025-11-04] (Microsoft Windows Hardware Compatibility Publisher -> SteelSeries ApS) S3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [46136 2025-04-07] (Microsoft Windows Hardware Compatibility Publisher -> SteelSeries ApS) R3 ssps2; C:\WINDOWS\System32\drivers\ssps2.sys [39000 2026-01-19] (Microsoft Windows Hardware Compatibility Publisher -> SteelSeries ApS) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [174264 2024-10-17] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R3 SteelSeries_Sonar_VAD; C:\WINDOWS\System32\DriverStore\FileRepository\steelseries-sonar-vad.inf_amd64_036e27f3054ae1bc\SteelSeries-Sonar-VAD.sys [95912 2026-05-06] (GN Hearing A/S -> Windows (R) Win 7 DDK provider) S4 WdAiNisDrv; C:\WINDOWS\System32\drivers\wd\WdAiNisDrv.sys [50568 2026-07-08] (Microsoft Windows -> Microsoft Corporation) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [21928 2026-07-08] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WDC_SAM; C:\WINDOWS\System32\drivers\wdcsam64.sys [35584 2018-02-26] (WDKTestCert wdclab,130885612892544312 -> Western Digital Technologies, Inc.) U5 WdDevFlt; C:\Windows\System32\Drivers\WdDevFlt.sys [169232 2022-05-07] (Microsoft Windows -> Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [616880 2026-07-08] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [110984 2026-07-08] (Microsoft Windows -> Microsoft Corporation) S3 WINIO; C:\Program Files (x86)\MSI\MSI NBFoundation Service\KernCoreLib64.sys [21368 2024-12-12] (WDKTestCert bartchang,133627318470293501 -> ) S3 ACE-CORE202915; \??\C:\Program Files\AntiCheatExpert\ACE-CORE202915.sys (No File) S3 ACE-CORE302915; \??\C:\Program Files\AntiCheatExpert\ACE-CORE302915.sys (No File) S3 ace-game-0; \SystemRoot\System32\drivers\ace-game-0.sys (No File) S3 NEProtect; \??\D:\SteamLibrary\steamapps\common\Once Human\NEProtect.sys (No File) ==================== SvcHost (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2026-07-18 20:11 - 2026-07-18 20:12 - 000047644 _____ C:\Users\Heine\Downloads\FRST.txt 2026-07-18 20:11 - 2026-07-18 20:12 - 000000000 ____D C:\FRST 2026-07-18 20:11 - 2026-07-18 20:11 - 002452992 _____ (Farbar) C:\Users\Heine\Downloads\FRST64.exe 2026-07-18 20:10 - 2026-07-18 20:10 - 000331752 _____ C:\WINDOWS\system32\drivers.txt 2026-07-18 20:08 - 2026-07-18 20:08 - 000003258 _____ C:\WINDOWS\system32\Tasks\RNIdle Task 2026-07-18 14:55 - 2026-07-18 14:55 - 000468608 _____ C:\WINDOWS\system32\perfh006.dat 2026-07-18 14:55 - 2026-07-18 14:55 - 000080342 _____ C:\WINDOWS\system32\perfc006.dat 2026-07-18 10:53 - 2026-07-18 11:57 - 000000000 ___HD C:\$WINDOWS.~BT 2026-07-18 10:51 - 2026-07-18 10:51 - 000000262 __RSH C:\ProgramData\ntuser.pol 2026-07-18 10:51 - 2026-07-18 10:51 - 000000000 ___HD C:\$GetCurrent 2026-07-18 10:51 - 2026-07-18 10:51 - 000000000 ____D C:\Program Files (x86)\WindowsInstallationAssistant 2026-07-18 10:26 - 2026-07-18 20:09 - 000050064 _____ C:\WINDOWS\system32\winsock.txt 2026-07-18 10:26 - 2026-07-18 10:26 - 000014077 _____ C:\Users\Heine\AppData\LocalLow\74c06c0a103d4024915906d9e026f0a5a1ab8ebeb6a7967b824a9c4ed3bce1cc 2026-07-18 10:26 - 2026-07-18 10:26 - 000000026 _____ C:\Users\Heine\AppData\LocalLow\c3c6687dff9ccd2e8a06e5f30454a058c8581adc1da720f04c4408fc1b864aff 2026-07-17 19:03 - 2026-07-17 19:03 - 000000000 _____ C:\Recovery.txt 2026-07-17 18:00 - 2026-07-17 18:00 - 000000000 ____D C:\Users\Heine\AppData\Local\Rufus 2026-07-17 12:57 - 2026-07-17 12:57 - 000044338 _____ C:\Users\Heine\AppData\LocalLow\ec08f04a5fab75c6afddbacf130f6c31a29cd3ca28ba2e51f799c9899ce5d8a3 2026-07-17 12:57 - 2026-07-17 12:57 - 000000130 _____ C:\Users\Heine\AppData\LocalLow\ad28ab0c8038857d949925b24d5cb8cba2cdcbb4ea8b9b1bed49c2f66547ea9a 2026-07-14 16:00 - 2026-07-14 20:01 - 000000000 ____D C:\Program Files\Mozilla Firefox 2026-07-10 07:36 - 2026-07-18 12:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logi 2026-07-10 07:36 - 2026-07-10 07:36 - 000000000 ____D C:\ProgramData\Logi 2026-07-10 07:36 - 2026-07-10 07:36 - 000000000 ____D C:\Program Files\LGHUB 2026-07-08 16:03 - 2026-07-08 16:03 - 000000000 ____D C:\Program Files\Common Files\DESIGNER 2026-07-01 10:29 - 2026-07-06 12:08 - 000107923 _____ C:\Users\Heine\AppData\LocalLow\da82aeb256b4d776bc9a6e9c1772ccc0a28dfbe4769663cb0830b84a78f5f01d 2026-07-01 10:29 - 2026-07-06 12:08 - 000000298 _____ C:\Users\Heine\AppData\LocalLow\1a78f4fb69a646afbade6b8ab31fcb477d06e92c40f5cbb1acd2c98797aaa532 2026-06-29 10:49 - 2026-06-29 10:49 - 000034000 _____ C:\Users\Heine\AppData\LocalLow\f9e8f8be8b283829f749de89ff09908e167826be4ee9d2fa9123b0a46c334530 2026-06-28 17:28 - 2026-06-28 17:29 - 000000000 ____D C:\Users\Heine\AppData\Roaming\Vencord 2026-06-26 13:23 - 2026-07-18 12:53 - 000000000 ____D C:\Users\Heine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoom 2026-06-19 13:07 - 2026-06-12 19:36 - 003082800 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe 2026-06-19 13:07 - 2026-06-12 19:36 - 003082800 _____ C:\WINDOWS\system32\vulkaninfo.exe 2026-06-19 13:07 - 2026-06-12 19:36 - 002626608 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe 2026-06-19 13:07 - 2026-06-12 19:36 - 002626608 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe 2026-06-19 13:07 - 2026-06-12 19:36 - 001730096 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll 2026-06-19 13:07 - 2026-06-12 19:36 - 001730096 _____ C:\WINDOWS\system32\vulkan-1.dll 2026-06-19 13:07 - 2026-06-12 19:36 - 001542192 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll 2026-06-19 13:07 - 2026-06-12 19:36 - 001542192 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll 2026-06-19 13:07 - 2026-06-12 19:36 - 000540904 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll 2026-06-19 13:07 - 2026-06-12 19:36 - 000418024 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll 2026-06-19 13:07 - 2026-06-12 19:32 - 001592040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll 2026-06-19 13:07 - 2026-06-12 19:32 - 001408232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvml.dll 2026-06-19 13:07 - 2026-06-12 19:32 - 001238760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll 2026-06-19 13:07 - 2026-06-12 19:32 - 000676584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvofapi64.dll 2026-06-19 13:07 - 2026-06-12 19:32 - 000510696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvofapi.dll 2026-06-19 13:07 - 2026-06-12 19:31 - 028094184 _____ C:\WINDOWS\system32\nvidia-pcc.exe 2026-06-19 13:07 - 2026-06-12 19:31 - 002337512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll 2026-06-19 13:07 - 2026-06-12 19:31 - 001731304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll 2026-06-19 13:07 - 2026-06-12 19:31 - 001682152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvidia-smi.exe 2026-06-19 13:07 - 2026-06-12 19:31 - 001068264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll 2026-06-19 13:07 - 2026-06-12 19:31 - 000824040 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll 2026-06-19 13:07 - 2026-06-12 19:31 - 000469736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdebugdump.exe 2026-06-19 13:07 - 2026-06-12 19:30 - 032166632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll 2026-06-19 13:07 - 2026-06-12 19:30 - 020993768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll 2026-06-19 13:07 - 2026-06-12 19:30 - 008488168 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll 2026-06-19 13:07 - 2026-06-12 19:30 - 005925608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2026-06-19 13:07 - 2026-06-12 19:30 - 005796072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcudadebugger.dll 2026-06-19 13:07 - 2026-06-12 19:30 - 004714728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll 2026-06-19 13:07 - 2026-06-12 19:30 - 000572368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll 2026-06-19 13:07 - 2026-06-12 19:30 - 000441368 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll 2026-06-19 13:07 - 2026-06-12 19:29 - 000853736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\MCU.exe 2026-06-19 13:07 - 2026-06-12 03:41 - 000167381 _____ C:\WINDOWS\system32\nvinfo.pb ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2026-07-18 20:11 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SystemTemp 2026-07-18 20:09 - 2025-11-15 17:28 - 000000000 ____D C:\Users\Heine\AppData\Roaming\discord 2026-07-18 20:08 - 2022-02-10 16:45 - 000000000 ____D C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38 2026-07-18 20:08 - 2021-11-08 14:56 - 000000000 ____D C:\Users\Heine\AppData\Local\CrashDumps 2026-07-18 20:07 - 2026-01-31 19:39 - 000000000 ____D C:\Users\Heine\AppData\Local\Discord 2026-07-18 20:07 - 2021-11-05 14:35 - 000000000 ____D C:\Program Files (x86)\Steam 2026-07-18 20:06 - 2026-03-16 10:54 - 000000000 ____D C:\ProgramData\Realtek 2026-07-18 20:06 - 2025-12-09 12:52 - 000000000 ____D C:\ProgramData\NVIDIA 2026-07-18 20:06 - 2023-01-30 14:50 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2026-07-18 20:06 - 2023-01-30 14:43 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2026-07-18 20:06 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\ServiceState 2026-07-18 20:06 - 2022-05-07 07:24 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2026-07-18 20:06 - 2021-11-05 11:19 - 000000000 __SHD C:\Users\Heine\IntelGraphicsProfiles 2026-07-18 20:06 - 2021-04-19 04:07 - 000000000 ____D C:\Intel 2026-07-18 20:05 - 2020-12-05 22:42 - 000012288 ___SH C:\DumpStack.log.tmp 2026-07-18 19:03 - 2023-01-30 14:25 - 000000000 ____D C:\Users\Heine 2026-07-18 19:03 - 2022-05-07 07:17 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2026-07-18 18:45 - 2022-05-07 07:24 - 000000000 ___HD C:\Program Files\WindowsApps 2026-07-18 18:45 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\AppReadiness 2026-07-18 18:26 - 2026-02-03 12:01 - 000000000 ____D C:\ProgramData\AntiCheatExpert 2026-07-18 18:26 - 2026-02-03 12:00 - 000000000 ____D C:\Users\Heine\AppData\Roaming\df_launcher_global_Steam_30029601 2026-07-18 18:26 - 2025-12-12 12:23 - 000000000 ____D C:\Program Files\AntiCheatExpert 2026-07-18 18:11 - 2021-04-19 04:51 - 000000000 ____D C:\ProgramData\Common 2026-07-18 15:36 - 2026-02-03 12:01 - 004125432 _____ (ANTICHEATEXPERT.COM) C:\WINDOWS\system32\Drivers\ACE-BASE.sys 2026-07-18 15:36 - 2026-02-03 12:01 - 001168048 _____ (ANTICHEATEXPERT.COM) C:\WINDOWS\system32\Drivers\ACE-ADVT.sys 2026-07-18 14:55 - 2023-01-30 14:53 - 001383074 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2026-07-18 14:55 - 2022-05-07 07:22 - 000000000 ____D C:\WINDOWS\INF 2026-07-18 12:53 - 2026-06-05 19:20 - 000000000 ____D C:\WINDOWS\system32\VRFCAT-Plugins 2026-07-18 12:53 - 2026-04-22 13:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2026-07-18 12:53 - 2025-11-17 13:22 - 000000000 ____D C:\Users\Heine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Web-apps fra Firefox 2026-07-18 12:53 - 2025-08-05 09:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Værktøjer til Microsoft Office 2026-07-18 12:53 - 2024-11-26 14:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent 2026-07-18 12:53 - 2024-04-24 10:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp 2026-07-18 12:53 - 2023-09-11 16:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mod Organizer 2026-07-18 12:53 - 2023-08-05 19:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Remote Control Server 2026-07-18 12:53 - 2023-02-07 17:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician 2026-07-18 12:53 - 2023-01-30 14:30 - 000000000 ____D C:\Users\Heine\AppData\Roaming\Microsoft\Crypto 2026-07-18 12:53 - 2023-01-30 14:25 - 000000000 ____D C:\Users\Heine\AppData\Roaming\Microsoft\Spelling 2026-07-18 12:53 - 2022-12-12 16:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA 2026-07-18 12:53 - 2022-07-26 21:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2026-07-18 12:53 - 2022-05-17 13:59 - 000000000 ____D C:\WINDOWS\system32\gf2engine 2026-07-18 12:53 - 2022-05-07 12:27 - 000000000 ____D C:\WINDOWS\system32\Hydrogen 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 __RHD C:\Users\Public\Libraries 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\SysWOW64\InstallShield 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\WebThreatDefSvc 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\SecurityHealth 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\oobe 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\NDF 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\system32\Drivers\DriverData 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2026-07-18 12:53 - 2022-05-07 07:24 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2026-07-18 12:53 - 2022-04-30 11:10 - 000000000 ____D C:\Users\Heine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox 2026-07-18 12:53 - 2022-04-08 19:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GridinSoft Anti-Malware 2026-07-18 12:53 - 2021-11-19 21:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net 2026-07-18 12:53 - 2021-11-05 16:00 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2026-07-18 12:53 - 2021-11-05 14:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2026-07-18 12:53 - 2021-11-05 13:29 - 000000000 ____D C:\Users\Heine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc 2026-07-18 12:53 - 2021-11-05 13:17 - 000000000 ____D C:\Users\Heine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2026-07-18 12:53 - 2021-11-05 13:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2026-07-18 12:53 - 2021-04-19 03:18 - 000000000 ____D C:\Program Files\Intel 2026-07-18 12:53 - 2020-11-19 09:33 - 000000000 __RHD C:\Users\Public\AccountPictures 2026-07-18 12:53 - 2019-12-07 11:14 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy 2026-07-18 12:53 - 2019-12-07 11:14 - 000000000 ____D C:\WINDOWS\system32\MsDtc 2026-07-18 12:21 - 2021-11-05 13:48 - 000000000 ____D C:\Users\Heine\AppData\Roaming\Microsoft\Excel 2026-07-18 11:55 - 2023-03-16 10:12 - 000001623 _____ C:\WINDOWS\system32\config\VSMIDK 2026-07-18 11:49 - 2020-11-19 09:32 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2026-07-18 11:47 - 2023-01-30 14:49 - 000001908 _____ C:\WINDOWS\diagwrn.xml 2026-07-18 11:47 - 2023-01-30 14:49 - 000001908 _____ C:\WINDOWS\diagerr.xml 2026-07-18 11:09 - 2023-01-30 13:32 - 000000000 ___DC C:\WINDOWS\Panther 2026-07-18 10:53 - 2026-03-24 17:23 - 000000036 _____ C:\WINDOWS\progress.ini 2026-07-18 10:22 - 2023-05-08 19:46 - 000000000 ____D C:\ProgramData\OmApSvcBroker 2026-07-17 17:36 - 2026-06-05 18:49 - 000003834 _____ C:\WINDOWS\system32\Tasks\NVIDIA App SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2026-07-17 17:36 - 2025-03-08 15:12 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2026-07-17 13:01 - 2021-11-05 11:49 - 000000000 ____D C:\WINDOWS\system32\MRT 2026-07-17 12:59 - 2021-11-05 11:49 - 228534800 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2026-07-17 12:13 - 2025-12-09 13:17 - 000000000 ____D C:\Users\Heine\AppData\Local\D3DSCache 2026-07-17 00:58 - 2021-11-05 13:09 - 000002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2026-07-16 10:15 - 2024-05-28 18:12 - 000000000 ____D C:\Users\Heine\AppData\Roaming\steelseries-gg-client 2026-07-14 20:01 - 2022-01-06 12:49 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2026-07-14 17:15 - 2023-04-21 09:06 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla 2026-07-14 17:15 - 2022-01-06 12:49 - 000001064 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2026-07-14 09:59 - 2020-12-05 23:34 - 000000000 ____D C:\Program Files\Microsoft Office 2026-07-10 16:33 - 2021-11-05 14:35 - 000000000 ____D C:\Users\Heine\AppData\Local\Steam 2026-07-10 07:37 - 2025-05-26 10:32 - 000000000 ____D C:\Users\Heine\AppData\Roaming\G HUB 2026-07-10 07:36 - 2025-05-26 10:32 - 000000000 ____D C:\Users\Heine\AppData\Roaming\lghub 2026-07-10 07:36 - 2025-05-26 10:32 - 000000000 ____D C:\Users\Heine\AppData\Local\LGHUB 2026-07-09 11:59 - 2021-04-19 03:18 - 000000000 ____D C:\ProgramData\Package Cache 2026-07-08 21:42 - 2026-06-12 11:42 - 000481736 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy_11.dll.0 2026-07-08 21:42 - 2026-06-12 11:42 - 000481736 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy_11.dll 2026-07-08 21:42 - 2022-10-21 10:22 - 000158152 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamehelper.exe 2026-07-08 21:42 - 2022-10-21 10:22 - 000084424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgamecontrol.exe 2026-07-08 21:42 - 2021-11-18 19:49 - 000338376 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamelaunchhelper.dll 2026-07-08 21:42 - 2021-11-05 11:39 - 004561352 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll 2026-07-08 21:42 - 2021-11-05 11:39 - 001182152 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameplatformservices.dll 2026-07-08 21:42 - 2021-11-05 11:39 - 000268744 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll 2026-07-08 21:42 - 2021-11-05 11:39 - 000166344 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcuihelpers.dll 2026-07-08 08:48 - 2020-11-19 09:30 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2026-07-02 12:45 - 2026-06-05 18:49 - 001424496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll 2026-07-02 12:45 - 2026-06-05 18:49 - 001224304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll 2026-07-02 12:44 - 2021-11-07 19:21 - 000297584 _____ C:\WINDOWS\system32\FvSDK_x64.dll 2026-07-02 12:43 - 2021-11-07 19:21 - 000271472 _____ C:\WINDOWS\SysWOW64\FvSDK_x86.dll 2026-07-02 12:17 - 2026-06-05 18:49 - 000181360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll 2026-07-02 12:17 - 2026-06-05 18:49 - 000158832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap32v.dll 2026-07-02 12:16 - 2026-06-05 18:49 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat 2026-06-30 11:45 - 2021-11-05 11:19 - 000000000 ____D C:\Users\Heine\AppData\Local\Packages 2026-06-27 10:26 - 2022-12-12 16:23 - 000000000 ____D C:\ProgramData\EA Desktop 2026-06-27 08:34 - 2026-03-25 22:11 - 000000000 ____D C:\Users\Heine\AppData\Roaming\Zoom 2026-06-27 07:43 - 2025-11-05 23:19 - 000000000 ____D C:\WINDOWS\system32\Tasks\GoogleUserPEH 2026-06-26 22:22 - 2022-10-11 14:49 - 000002113 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat.lnk 2026-06-26 13:23 - 2026-03-25 22:11 - 000004254 _____ C:\WINDOWS\system32\Tasks\ZoomUpdateTaskUser-S-1-5-21-1513235227-3861919680-1317406885-1001 2026-06-19 14:23 - 2025-12-09 12:57 - 000000000 ____D C:\Users\Heine\AppData\Local\NVIDIA 2026-06-19 13:12 - 2026-03-24 17:19 - 000001392 _____ C:\Users\Heine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC Health Check.lnk 2026-06-19 13:12 - 2026-03-24 17:19 - 000000000 ____D C:\Users\Heine\AppData\Local\PCHealthCheck 2026-06-18 17:42 - 2021-11-05 11:44 - 000000000 ____D C:\Users\Heine\AppData\Local\ElevatedDiagnostics ==================== Files in the root of some directories ======== 2024-10-22 17:56 - 2024-10-22 17:56 - 000000048 ____R () C:\Users\Heine\AppData\Local\006F8CF6D6A8F1097D5BF41EDE1599A0 2022-04-08 19:47 - 2022-04-08 19:47 - 000374732 _____ () C:\Users\Heine\AppData\Local\ars.cache 2022-04-08 19:47 - 2022-04-08 19:47 - 000989153 _____ () C:\Users\Heine\AppData\Local\census.cache 2022-04-08 19:40 - 2022-04-08 19:40 - 000000036 _____ () C:\Users\Heine\AppData\Local\housecall.guid.cache ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ========================