
Mos ago, a regular Win update utterly trashed this computer (my win8 box updated just fine). Managed to get it working again by using System Restore.
A bunch of files had been deleted. I'd backed-up quite a bit & was able to put them back, at least the missing files I located. Interestingly, I noticed it took out a lot of .html files but would tend to leave others intact, including .BAK, .css etc.
Had various strange things happen since then. Slow start-ups, at times RAM use skyrockets, etc. Most recently, I noticed my MS Security app had "shut off"- "Microsoft Antimalware Service service terminated unexpectedly"- so, here I am!
(MS AV is working fine now, by the way. I simply rebooted.)
-- I noticed some out-of-date browser folder BUs show from my scans, if they're confusing, I can move them to another folder & redo. Lemme know.
Cheers. Thanks.
##
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2019
Ran by happy (administrator) on LAPPY (ASUSTeK Computer Inc. K54C) (02-09-2019 07:40:52)
Running from C:\Users\happy\Desktop\00000
Loaded Profiles: happy (Available Profiles: happy)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2785064 2011-05-05] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.) [File not signed]
HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [97064 2011-05-05] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUSTeK Computer Inc. -> ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2319536 2011-10-18] (ASUSTeK Computer Inc. -> ASUS)
HKU\S-1-5-21-1167706805-3652461753-1077729752-1000\...\Run: [WinPatrol] => C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [1128000 2014-06-03] (BillP Studios -> BillP Studios)
HKU\S-1-5-21-1167706805-3652461753-1077729752-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Mystify.scr [242688 2010-11-20] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\windows\system32\cmd.exe /D /C start C:\windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\windows\system32\cmd.exe /D /C start C:\windows\system32\ie4uinit.exe -ClearIconCache
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk [2013-10-24]
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe () [File not signed]
Startup: C:\Users\happy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\0000-Launch_BROWSERS.cmd [2019-08-15] () [File not signed]
GroupPolicy: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0AEFE3C1-0C25-4C8F-BD16-976785226767} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {20851120-42F3-4C27-8020-70E8422C9E90} - System32\Tasks\Opera scheduled Autoupdate 1499952880 => C:\Program Files\Opera\launcher.exe [1520152 2019-08-27] (Opera Software AS -> Opera Software)
Task: {31C4EF86-EE62-488B-90E4-4438DDC78369} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [318080 2011-12-22] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {4D5FACA0-B385-4511-9192-7C3BEB163646} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [410784 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
Task: {87F619F3-E712-49E9-A5A5-80323CB92151} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [1556640 2012-06-20] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
Task: {A741CCBC-CE0F-41FC-95B4-ECF9222B1F44} - System32\Tasks\{C95A24F3-5910-45DC-BF71-3DC579D2D404} => C:\windows\system32\pcalua.exe -a "C:\Users\happy\Desktop\DOWNLOADS HERE\irfanview_plugins_437_setup.exe" -d "C:\Users\happy\Desktop\DOWNLOADS HERE"
Task: {CDC6F1D0-992A-4B6A-9F14-FA9873939549} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe [473728 2012-02-16] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
Task: {F1F666BA-3D7B-4274-8D95-4BB002002540} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {F5255F09-864E-4907-B017-417DC2FA7DC2} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{7F5F0944-5C21-41EE-8BD6-BB8AB1089EB0}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{D7A67B45-A19A-4987-8C05-DCF3D814347C}: [DhcpNameServer] 209.18.47.62 209.18.47.61
Internet Explorer:
==================
HKU\S-1-5-21-1167706805-3652461753-1077729752-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKU\S-1-5-21-1167706805-3652461753-1077729752-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
DownloadDir: C:\Users\happy\Desktop\DOWNLOADS HERE
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1167706805-3652461753-1077729752-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1167706805-3652461753-1077729752-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1482688010082
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2016-01-04] (Belarc, Inc. -> Belarc, Inc.)
FireFox:
========
FF DefaultProfile: 3vb57d2z.default
FF DefaultProfile: pmboff70.default
FF DefaultProfile: v0k5j5hr.default-1510011962003
FF DefaultProfile: n8i1vt93.default-1565580858196
FF ProfilePath: C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\n8i1vt93.default-1565580858196 [not found] <==== ATTENTION
FF DefaultProfile: 0h9ztolt.default
FF ProfilePath: C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default [2019-08-15]
FF Extension: (AdBlocker Ultimate) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\adblockultimate@adblockultimate.net.xpi [2019-08-12]
FF Extension: (Clean Links) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\clean-links@Cimbali.github.com.xpi [2019-08-12]
FF Extension: (Privacy Badger) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2019-08-12]
FF Extension: (Smart Referer) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\smart-referer@meh.paranoid.pk.xpi [2019-08-12]
FF Extension: (uBlock Origin) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\uBlock0@raymondhill.net.xpi [2019-08-12]
FF Extension: (uMatrix) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\uMatrix@raymondhill.net.xpi [2019-08-12]
FF Extension: (User-Agent Switcher) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\user-agent-switcher@ninetailed.ninja.xpi [2019-08-12]
FF Extension: (Privacy Possum) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\woop-NoopscooPsnSXQ@jetpack.xpi [2019-08-12]
FF Extension: (Referrer Switch) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{033d950a-38b9-4976-b19e-5f9ed7d78daa}.xpi [2019-08-12]
FF Extension: (Download all Images) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{32af1358-428a-446d-873e-5f8eb5f2a72e}.xpi [2019-08-12]
FF Extension: (Disable JavaScript) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{41f9e51d-35e4-4b29-af66-422ff81c8b41}.xpi [2019-08-12]
FF Extension: (Cookie Quick Manager) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{60f82f00-9ad5-4de5-b31c-b16a47c51558}.xpi [2019-08-12]
FF Extension: (User-Agent Switcher) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{75afe46a-7a50-4c6b-b866-c43a1075b071}.xpi [2019-08-12]
FF Extension: (YouTube High Definition) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2019-08-12]
FF Extension: (Markdown Viewer Webext) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{943b8007-a895-44af-a672-4f4ea548c95f}.xpi [2019-08-12]
FF Extension: (User-Agent Switcher and Manager) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{a6c4a591-f1b2-4f03-b3ff-767e5bedf4e7}.xpi [2019-08-12]
FF Extension: (Random User-Agent) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{b43b974b-1d3a-4232-b226-eaa2ac6ebb69}.xpi [2019-08-12]
FF Extension: (Web Developer) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2019-08-12]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-08-12]
FF Extension: (javascript) - C:\Users\happy\AppData\Roaming\Waterfox\Profiles\3vb57d2z.default\Extensions\{d4bc778f-3a98-44f4-9b2e-45fab92a21db}.xpi [2019-08-12]
FF ProfilePath: C:\Users\happy\AppData\Roaming\WAS_Mozilla_2017-11-6_CLEAN\SeaMonkey\Profiles\pmboff70.default [2017-10-03]
FF NetworkProxy: WAS_Mozilla_2017-11-6_CLEAN\SeaMonkey\Profiles\pmboff70.default -> share_proxy_settings", true
FF Extension: (uBlock Origin) - C:\Users\happy\AppData\Roaming\WAS_Mozilla_2017-11-6_CLEAN\SeaMonkey\Profiles\pmboff70.default\Extensions\uBlock0@raymondhill.net.xpi [2017-07-19] [Legacy]
FF Extension: (uMatrix) - C:\Users\happy\AppData\Roaming\WAS_Mozilla_2017-11-6_CLEAN\SeaMonkey\Profiles\pmboff70.default\Extensions\uMatrix@raymondhill.net.xpi [2017-07-17] [Legacy]
FF Extension: (Screengrab (fix version)) - C:\Users\happy\AppData\Roaming\WAS_Mozilla_2017-11-6_CLEAN\SeaMonkey\Profiles\pmboff70.default\Extensions\{02450914-cdd9-410f-b1da-db004e18c671}.xpi [2017-07-21] [Legacy]
FF Extension: (NoScript) - C:\Users\happy\AppData\Roaming\WAS_Mozilla_2017-11-6_CLEAN\SeaMonkey\Profiles\pmboff70.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2017-09-13] [Legacy]
FF Extension: (User Agent Switcher) - C:\Users\happy\AppData\Roaming\WAS_Mozilla_2017-11-6_CLEAN\SeaMonkey\Profiles\pmboff70.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2017-07-18] [Legacy]
FF Extension: (User Agent Switcher) - C:\Users\happy\AppData\Roaming\Mozilla\SeaMonkey\Profiles\pmboff70.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2017-07-18] [Legacy]
FF Extension: (Screengrab (fix version)) - C:\Users\happy\AppData\Roaming\Mozilla\SeaMonkey\Profiles\pmboff70.default\extensions\{02450914-cdd9-410f-b1da-db004e18c671}.xpi [2018-01-01] [Legacy]
FF Extension: (NoScript) - C:\Users\happy\AppData\Roaming\Mozilla\SeaMonkey\Profiles\pmboff70.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2018-03-30] [Legacy]
FF ProfilePath: C:\Users\happy\AppData\Roaming\WAS_Mozilla_2017-11-6_CLEAN\Firefox\Profiles\v0k5j5hr.default-1510011962003 [2017-11-16]
FF DownloadDir: C:\Users\happy\Desktop\DOWNLOADS HERE
FF Homepage: WAS_Mozilla_2017-11-6_CLEAN\Firefox\Profiles\v0k5j5hr.default-1510011962003 -> hxxps://duckduckgo.com/
FF Extension: (Policy Control - JavaScript and Flash blocker) - C:\Users\happy\AppData\Roaming\WAS_Mozilla_2017-11-6_CLEAN\Firefox\Profiles\v0k5j5hr.default-1510011962003\Extensions\jid1-gHwvGmJ8Ii9oOq@jetpack.xpi [2017-11-16]
FF Extension: (Whitelist JavaScript) - C:\Users\happy\AppData\Roaming\WAS_Mozilla_2017-11-6_CLEAN\Firefox\Profiles\v0k5j5hr.default-1510011962003\Extensions\veto@myridia.com.xpi [2017-11-16]
FF Extension: (Javascript Control) - C:\Users\happy\AppData\Roaming\WAS_Mozilla_2017-11-6_CLEAN\Firefox\Profiles\v0k5j5hr.default-1510011962003\Extensions\{591abe66-4392-4d7e-aad5-12f04be2539e}.xpi [2017-11-16]
FF ProfilePath: C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\SeaMonkey\Profiles\pmboff70.default [2017-07-18]
FF NetworkProxy: MOZ_7.17.2017.BAK\SeaMonkey\Profiles\pmboff70.default -> share_proxy_settings", true
FF Extension: (uBlock Origin) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\SeaMonkey\Profiles\pmboff70.default\Extensions\uBlock0@raymondhill.net.xpi [2017-07-17] [Legacy]
FF Extension: (uMatrix) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\SeaMonkey\Profiles\pmboff70.default\Extensions\uMatrix@raymondhill.net.xpi [2017-07-17] [Legacy]
FF Extension: (NoScript) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\SeaMonkey\Profiles\pmboff70.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2017-07-17] [Legacy]
FF ProfilePath: C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default [2017-07-18]
FF Homepage: MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default -> hxxps://duckduckgo.com/
FF Extension: (CanvasBlocker) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\CanvasBlocker@kkapsner.de.xpi [2017-07-11] [Legacy]
FF Extension: (Click&Clean) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\clickclean@hotcleaner.com [2017-07-18] [Legacy]
FF Extension: (colorPicker) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\colorPicker@colorPicker.xpi [2017-02-20] [Legacy]
FF Extension: (Firebug) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\firebug@software.joehewitt.com.xpi [2017-03-01] [Legacy]
FF Extension: (Valence) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\fxdevtools-adapters@mozilla.org [2017-07-18] [Legacy]
FF Extension: (Image Picker) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\ImagePicker@topolog.org [2017-07-18] [Legacy]
FF Extension: (DOM Inspector) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\inspector@mozilla.org [2017-07-18] [Legacy]
FF Extension: (Google search link fix) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\jid0-XWJxt5VvCXkKzQK99PhZqAn7Xbg@jetpack.xpi [2017-01-31]
FF Extension: (Random Agent Spoofer) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\jid1-AVgCeF1zoVzMjA@jetpack.xpi [2016-09-21] [Legacy]
FF Extension: (Lightbeam) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2017-03-22] [Legacy]
FF Extension: (de-t-co) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\jid1-fJE7HYlCweigaA@jetpack.xpi [2016-09-14] [Legacy]
FF Extension: (SpeedView) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\jid1-MmDjnsjlez2Sdw@jetpack.xpi [2016-12-14] [Legacy]
FF Extension: (Privacy Badger) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2017-07-11]
FF Extension: (JavaScript View) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\jid1-u9RbFp9JcoEGGw@jetpack.xpi [2016-12-14] [Legacy]
FF Extension: (Google Redirects Fixer) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\jid1-zUrvDCat3xoDSQ@jetpack.xpi [2015-12-28] [Legacy]
FF Extension: (JavaScript Deobfuscator) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\jsdeobfuscator@adblockplus.org.xpi [2016-12-06] [Legacy]
FF Extension: (Smart Referer) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\smart-referer@meh.paranoid.pk.xpi [2017-07-08] [Legacy]
FF Extension: (Status-4-Evar) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\status4evar@caligonstudios.com.xpi [2016-11-26] [Legacy]
FF Extension: (The Addon Bar (restored)) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\the-addon-bar@GeekInTraining-GiT.xpi [2016-12-14] [Legacy]
FF Extension: (ThumbsDown) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\thumbsdown@mozdev.org.xpi [2015-12-05] [Legacy]
FF Extension: (uBlock Origin) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\uBlock0@raymondhill.net.xpi [2017-06-27] [Legacy]
FF Extension: (uMatrix) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\uMatrix@raymondhill.net.xpi [2017-07-14] [Legacy]
FF Extension: (Show external css/js files) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\viewext@lissak.fr.xpi [2016-12-14] [Legacy]
FF Extension: (NoSquint Plus) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\zoomlevelplus@zoomlevelplus.net.xpi [2017-04-24] [Legacy]
FF Extension: (Zoom Page) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\zoompage@DW-dev.xpi [2017-03-03] [Legacy]
FF Extension: (Unshorten.It!) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{0a566650-a8e0-11e0-8264-0800200c9a66}.xpi [2016-04-28] [Legacy]
FF Extension: (FireShot) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2017-07-18] [Legacy]
FF Extension: (Clean Links) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{158d7cb3-7039-4a75-8e0b-3bd0a464edd2}.xpi [2016-04-27] [Legacy]
FF Extension: (Flashblock) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2017-07-18] [Legacy]
FF Extension: (HttpFox) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{4093c4de-454a-4329-8aff-c6b0b123c386}.xpi [2016-04-28] [Legacy]
FF Extension: (RefControl) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}.xpi [2016-04-28] [Legacy]
FF Extension: (ColorZilla) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}.xpi [2017-03-08]
FF Extension: (NoScript) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2017-07-01] [Legacy]
FF Extension: (YouTube High Definition) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2017-06-21] [Legacy]
FF Extension: (Live HTTP headers) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2017-07-18] [Legacy]
FF Extension: (Cookie Controller) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{ac2cfa60-bc96-11e0-962b-0800200c9a66}.xpi [2017-05-06] [Legacy]
FF Extension: (Cookies Manager+) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d} [2017-07-18] [Legacy]
FF Extension: (Web Developer) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2017-04-06] [Legacy]
FF Extension: (Adblock Plus) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-08] [Legacy]
FF Extension: (BetterPrivacy) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2016-11-01] [Legacy]
FF Extension: (Default Full Zoom Level) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{D9A7CBEC-DE1A-444f-A092-844461596C4D} [2017-07-18] [Legacy]
FF Extension: (DownThemAll!) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-09-29] [Legacy]
FF Extension: (User Agent Switcher) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2016-04-28] [Legacy]
FF Extension: (Theme Font & Size Changer) - C:\Users\happy\AppData\Roaming\MOZ_7.17.2017.BAK\Firefox\Profiles\6sbyeiyd.default\Extensions\{f69e22c7-bc50-414a-9269-0f5c344cd94c}.xpi [2017-06-17] [Legacy]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{4093c4de-454a-4329-8aff-c6b0b123c386}.xpi [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}.xpi [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\inspector@mozilla.org [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{0a566650-a8e0-11e0-8264-0800200c9a66}.xpi [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{D9A7CBEC-DE1A-444f-A092-844461596C4D} [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\status4evar@caligonstudios.com.xpi [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\viewext@lissak.fr.xpi [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\zoompage@DW-dev.xpi [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{ac2cfa60-bc96-11e0-962b-0800200c9a66}.xpi [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d} [not found]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\6sbyeiyd.default\extensions\clickclean@hotcleaner.com [not found]
FF ProfilePath: C:\Users\happy\AppData\Roaming\Mozilla\SeaMonkey\Profiles\pmboff70.default [2019-07-30]
FF NetworkProxy: Mozilla\SeaMonkey\Profiles\pmboff70.default -> share_proxy_settings", true
FF Extension: (uBlock Origin) - C:\Users\happy\AppData\Roaming\Mozilla\SeaMonkey\Profiles\pmboff70.default\Extensions\uBlock0@raymondhill.net.xpi [2017-07-19] [Legacy]
FF Extension: (uMatrix) - C:\Users\happy\AppData\Roaming\Mozilla\SeaMonkey\Profiles\pmboff70.default\Extensions\uMatrix@raymondhill.net.xpi [2017-07-17] [Legacy]
FF ProfilePath: C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release [2019-09-02]
FF Homepage: Mozilla\Firefox\Profiles\u6laa06p.default-release -> hxxps://start.duckduckgo.com/
FF Extension: (Firefox Multi-Account Containers) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\@testpilot-containers.xpi [2019-01-24]
FF Extension: (Firefox DevTools ADB Extension) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\adb@mozilla.org.xpi [2019-07-12] [UpdateUrl:hxxps://ftp.mozilla.org/pub/labs/devtools/adb-extension/win32/update.json]
FF Extension: (AdBlocker Ultimate) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\adblockultimate@adblockultimate.net.xpi [2019-08-12]
FF Extension: (CanvasBlocker) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\CanvasBlocker@kkapsner.de.xpi [2019-07-25]
FF Extension: (Clear Flash Cookies) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\clear-flash-cookies@cpeterso.com.xpi [2017-11-20]
FF Extension: (Cookie Manager) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\cookie-manager@robwu.nl.xpi [2018-10-23]
FF Extension: (Cookie AutoDelete) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\CookieAutoDelete@kennydo.com.xpi [2019-04-29]
FF Extension: (Firebug) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\firebug@software.joehewitt.com.xpi [2017-03-01] [Legacy]
FF Extension: (hotfix-update-xpi-intermediate) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\hotfix-update-xpi-intermediate@mozilla.com.xpi [2019-05-15]
FF Extension: (Google search link fix) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\jid0-XWJxt5VvCXkKzQK99PhZqAn7Xbg@jetpack.xpi [2019-07-03]
FF Extension: (Firefox Lightbeam) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\jid1-F9UJ2thwoAm5gQ@jetpack.xpi [2018-02-18]
FF Extension: (Policy Control - JavaScript and Flash blocker) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\jid1-gHwvGmJ8Ii9oOq@jetpack.xpi [2018-02-08]
FF Extension: (Privacy Badger) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2019-07-10]
FF Extension: (Double-click Image Downloader) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\jid1-xgtdawe3yyUeBQ@jetpack.xpi [2018-05-16]
FF Extension: (google-no-tracking-url) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\jid1-zUrvDCat3xoDSQ@jetpack.xpi [2017-08-22]
FF Extension: (Neat URL) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\neaturl@hugsmile.eu.xpi [2018-05-29]
FF Extension: (Nimbus Screen Capture: Screenshots, Annotate) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\nimbusscreencaptureff@everhelper.me.xpi [2019-08-08]
FF Extension: (Skip Redirect) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\skipredirect@sblask.xpi [2019-06-15]
FF Extension: (Smart Referer) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\smart-referer@meh.paranoid.pk.xpi [2018-09-21]
FF Extension: (uBlock Origin) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\uBlock0@raymondhill.net.xpi [2019-07-27]
FF Extension: (uMatrix) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\uMatrix@raymondhill.net.xpi [2018-12-28]
FF Extension: (User-Agent Switcher) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\user-agent-switcher@ninetailed.ninja.xpi [2019-08-16]
FF Extension: (Whitelist JavaScript) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\veto@myridia.com.xpi [2018-04-26]
FF Extension: (NoSquint Plus) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\zoomlevelplus@zoomlevelplus.net.xpi [2017-11-11]
FF Extension: (Zoom Page WE) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\zoompage-we@DW-dev.xpi [2019-08-29]
FF Extension: (Download all Images) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{32af1358-428a-446d-873e-5f8eb5f2a72e}.xpi [2019-07-03]
FF Extension: (HttpFox) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{4093c4de-454a-4329-8aff-c6b0b123c386}.xpi [2016-04-28] [Legacy]
FF Extension: (Javascript Control) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{591abe66-4392-4d7e-aad5-12f04be2539e}.xpi [2017-11-20]
FF Extension: (Cookie Quick Manager) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{60f82f00-9ad5-4de5-b31c-b16a47c51558}.xpi [2019-08-12]
FF Extension: (ColorZilla) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}.xpi [2017-03-08]
FF Extension: (NoScript) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2019-08-20]
FF Extension: (User-Agent Switcher) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{75afe46a-7a50-4c6b-b866-c43a1075b071}.xpi [2019-07-03]
FF Extension: (YouTube High Definition) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2019-07-11]
FF Extension: (Markdown Viewer Webext) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{943b8007-a895-44af-a672-4f4ea548c95f}.xpi [2019-07-14]
FF Extension: (Font Finder) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{a658a273-612e-489e-b4f1-5344e672f4f5}.xpi [2019-04-07]
FF Extension: (EditThisCookie) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{a6a5b521-62f8-48c1-ad86-702fd9f0e2c8}.xpi [2017-11-16]
FF Extension: (User-Agent Switcher and Manager) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{a6c4a591-f1b2-4f03-b3ff-767e5bedf4e7}.xpi [2019-08-01]
FF Extension: (Web Developer) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2017-11-16]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-08-23]
FF Extension: (HTTP Header Live) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{ed102056-8b4f-43a9-99cd-6d1b25abe87e}.xpi [2019-08-20]
FF Extension: (Theme Font & Size Changer) - C:\Users\happy\AppData\Roaming\Mozilla\Firefox\Profiles\u6laa06p.default-release\Extensions\{f69e22c7-bc50-414a-9269-0f5c344cd94c}.xpi [2017-11-15]
FF ProfilePath: C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default [2017-07-17]
FF Homepage: MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default -> hxxps://duckduckgo.com/
FF Extension: (Page Zoom Button) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\54c7d9671b9eccd9e5686a73df34ab60@button.codefisher.org.xpi [2016-08-12] [Legacy]
FF Extension: (Adblock Latitude) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\adblocklatitude@addons.palemoon.org.xpi [2017-02-17] [Legacy] [not signed]
FF Extension: (Click&Clean) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\clickclean@hotcleaner.com [2017-07-17] [Legacy]
FF Extension: (Developer Tools) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\devtools@addons.palemoon.org.xpi [2016-12-14] [Legacy] [not signed]
FF Extension: (Random Agent Spoofer) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\jid1-AVgCeF1zoVzMjA@jetpack.xpi [2015-12-08] [Legacy]
FF Extension: (Proxy Privacy Ruler) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\pxruler@Off.JustOff.xpi [2017-07-15] [Legacy]
FF Extension: (uBlock Origin) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\uBlock0@raymondhill.net.xpi [2017-06-28] [Legacy]
FF Extension: (uMatrix) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\uMatrix@raymondhill.net.xpi [2017-07-14] [Legacy]
FF Extension: (Zoom Page) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\zoompage@DW-dev.xpi [2017-03-03] [Legacy]
FF Extension: (Unshorten.It!) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{0a566650-a8e0-11e0-8264-0800200c9a66}.xpi [2016-04-28] [Legacy]
FF Extension: (FireShot) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2017-07-17] [Legacy]
FF Extension: (Clean Links) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{158d7cb3-7039-4a75-8e0b-3bd0a464edd2}.xpi [2016-04-27] [Legacy]
FF Extension: (Flashblock) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2017-07-17] [Legacy]
FF Extension: (HttpFox) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{4093c4de-454a-4329-8aff-c6b0b123c386}.xpi [2016-04-28] [Legacy]
FF Extension: (RefControl) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}.xpi [2016-04-28] [Legacy]
FF Extension: (ColorZilla) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2017-07-17] [Legacy]
FF Extension: (NoScript) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2017-07-16] [Legacy]
FF Extension: (YouTube High Definition) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2017-06-21] [Legacy]
FF Extension: (Live HTTP headers) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2017-07-17] [Legacy]
FF Extension: (Cookie Controller) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{ac2cfa60-bc96-11e0-962b-0800200c9a66}.xpi [2017-05-04] [Legacy]
FF Extension: (Cookies Manager+) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d} [2017-07-17] [Legacy]
FF Extension: (Web Developer) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2017-04-06] [Legacy]
FF Extension: (BetterPrivacy) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2015-08-18] [Legacy]
FF Extension: (User Agent Switcher) - C:\Users\happy\AppData\Roaming\MOON_PROD.BAK\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2016-04-28] [Legacy]
FF Extension: (Page Zoom Button) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\54c7d9671b9eccd9e5686a73df34ab60@button.codefisher.org.xpi [2016-08-12] [Legacy]
FF Extension: (Zoom Page) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\zoompage@DW-dev.xpi [2017-08-17] [Legacy]
FF Extension: (Flashblock) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2016-01-08] [Legacy]
FF Extension: (HttpFox) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\{4093c4de-454a-4329-8aff-c6b0b123c386}.xpi [2016-04-28] [Legacy]
FF Extension: (RefControl) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}.xpi [2016-04-28] [Legacy]
FF Extension: (ColorZilla) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2015-09-05] [Legacy]
FF Extension: (NoScript) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2017-07-16] [Legacy]
FF Extension: (Live HTTP headers) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a} [2016-04-28] [Legacy]
FF Extension: (Cookie Controller) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\{ac2cfa60-bc96-11e0-962b-0800200c9a66}.xpi [2017-08-06] [Legacy]
FF Extension: (Web Developer) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [2017-04-06] [Legacy]
FF Extension: (BetterPrivacy) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2015-08-18] [Legacy]
FF Extension: (No Name) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [not found]
FF Extension: (Click&Clean) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\clickclean@hotcleaner.com [2017-07-11] [Legacy]
FF Extension: (Cookies Manager+) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d} [2017-07-23] [Legacy]
FF ProfilePath: C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default [2019-09-02]
FF Homepage: Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default -> hxxps://start.duckduckgo.com/
FF Extension: (Adblock Latitude) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\adblocklatitude@addons.palemoon.org.xpi [2018-04-10] [Legacy] [not signed]
FF Extension: (Block Content) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\blockcont@mdsy.xpi [2019-02-03] [Legacy] [not signed]
FF Extension: (Cookies Exterminator) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\CookiesExterminator@Off.JustOff.xpi [2019-04-16] [Legacy] [not signed]
FF Extension: (Developer Tools) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\devtools@addons.palemoon.org.xpi [2016-12-14] [Legacy] [not signed]
FF Extension: (Exif Viewer) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\exif-viewer@asraskin.org.xpi [2019-04-26] [Legacy] [not signed]
FF Extension: (Random Agent Spoofer) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\jid1-AVgCeF1zoVzMjA@jetpack.xpi [2015-12-08] [Legacy]
FF Extension: (Proxy Privacy Ruler) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\pxruler@Off.JustOff.xpi [2019-04-16] [Legacy] [not signed]
FF Extension: (Save All Images) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\save-images-me@Off.JustOff.xpi [2019-04-24] [Legacy] [not signed]
FF Extension: (uBlock Origin) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\uBlock0@raymondhill.net.xpi [2017-07-20] [Legacy]
FF Extension: (uMatrix) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\uMatrix@raymondhill.net.xpi [2017-07-14] [Legacy]
FF Extension: (Unshorten.It!) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{0a566650-a8e0-11e0-8264-0800200c9a66}.xpi [2016-04-28] [Legacy]
FF Extension: (Clean Links) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{158d7cb3-7039-4a75-8e0b-3bd0a464edd2}.xpi [2016-04-27] [Legacy]
FF Extension: (YouTube High Definition) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2017-09-11] [Legacy]
FF Extension: (Cookie Permissions Button) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{8e05f2af-03be-443e-a2b5-b4375a3a1930}.xpi [2018-08-14] [Legacy] [not signed]
FF Extension: (Cookie Masters) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{a04a71f3-ce74-4134-8f86-fae693b19e44}.xpi [2018-08-04] [Legacy] [not signed]
FF Extension: (Toggle JavaScript [Enabled/Disabled]) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{b5af16a6-105d-4a14-a5a6-c2b358b06a04}.xpi [2018-08-30] [Legacy] [not signed]
FF Extension: (User Agent Switcher) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\k1c3hz7u.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2016-04-28] [Legacy]
FF ProfilePath: C:\Users\happy\AppData\Roaming\Moonchild Productions\Basilisk\Profiles\0h9ztolt.default [2019-07-12]
FF Extension: (Adblock Latitude) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Basilisk\Profiles\0h9ztolt.default\Extensions\adblocklatitude@addons.palemoon.org.xpi [2019-06-02] [Legacy] [not signed]
FF Extension: (Block Content) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Basilisk\Profiles\0h9ztolt.default\Extensions\blockcont@mdsy.xpi [2019-06-02] [Legacy] [not signed]
FF Extension: (CanvasBlocker Legacy) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Basilisk\Profiles\0h9ztolt.default\Extensions\CanvasBlocker@legacy.xpi [2019-06-02] [Legacy] [not signed]
FF Extension: (Cookies Exterminator) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Basilisk\Profiles\0h9ztolt.default\Extensions\CookiesExterminator@Off.JustOff.xpi [2019-06-02] [Legacy] [not signed]
FF Extension: (Exif Viewer) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Basilisk\Profiles\0h9ztolt.default\Extensions\exif-viewer@asraskin.org.xpi [2019-06-02] [Legacy] [not signed]
FF Extension: (ScriptBlock) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Basilisk\Profiles\0h9ztolt.default\Extensions\jsblock@4bebca82.xpi [2019-06-02] [Legacy] [not signed]
FF Extension: (Calendate) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Basilisk\Profiles\0h9ztolt.default\Extensions\{5b965352-430a-11e2-956a-13226188709b}.xpi [2019-06-02] [Legacy] [not signed]
FF Extension: (Color Identifier) - C:\Users\happy\AppData\Roaming\Moonchild Productions\Basilisk\Profiles\0h9ztolt.default\Extensions\{89850e1c-c80b-4179-81fe-79a9f313400d}.xpi [2019-06-02] [Legacy] [not signed]
FF ProfilePath: C:\Users\happy\AppData\Roaming\Avant Profiles\.default\gecko\Mozilla\Avant\Profiles\oeytmn1z.default [2015-05-03]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN -> VideoLAN)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2019-06-11] (VideoLAN -> VideoLAN)
FF Plugin HKU\S-1-5-21-1167706805-3652461753-1077729752-1000: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=3 -> C:\Users\happy\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [No File]
FF Plugin HKU\S-1-5-21-1167706805-3652461753-1077729752-1000: @updates.epicbrowser.com/Epic Privacy Browser Installer;version=9 -> C:\Users\happy\AppData\Local\Epic Privacy Browser\Installer\1.3.27.13\npEpicUpdate3.dll [No File]
Opera:
=======
OPR DownloadDir: C:\Users\happy\Desktop\DOWNLOADS HERE
OPR Extension: (Zoom for Opera) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\agocngbnphnfdhpacecdpcpfphhdmoff [2019-07-11]
OPR Extension: (uMatrix) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\clblbeknmgobkgonndomehcjpckopfeh [2018-07-11]
OPR Extension: (Live HTTP Headers) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\djlgkpdankikgjpjmknpdabbegoaokli [2018-07-11]
OPR Extension: (Custom Style Script) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\hmnbfbgbgicodipenaajdcogalomcmph [2019-06-25]
OPR Extension: (YouTube High Definition) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\jcdpccclajomeaeeoggbhglfomndjgfp [2018-07-11]
OPR Extension: (User-Agent Switcher) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\jikibpedldihacokaanimbcjipghbloo [2018-07-11]
OPR Extension: (WebRTC Leak Prevent) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\jjabaljgaabcnmcoalhaldkmcfbojkkb [2018-07-11]
OPR Extension: (uBlock Origin) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\kccohkcpppjjkkjppopfnflnebibpida [2019-07-31]
OPR Extension: (Privacy Badger) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\ldfkcgjipgfchpnojicdgpgiocoeelik [2019-07-09]
OPR Extension: (History Eraser) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\lfpoajlbkhlfoeeokbppmecpplmieedm [2018-07-11]
OPR Extension: (User-Agent Switcher and Manager) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\mdhadkjmpbhfdmmoogneplmcpoelfggp [2019-08-17]
OPR Extension: (Magic Actions for YouTubeâ„¢) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\nlffnljnicbkfhnlomjhjlebndachaka [2019-04-15]
OPR Extension: (Adblock Plus - free ad blocker) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2019-08-17]
OPR Extension: (JavaScript Switcher) - C:\Users\happy\AppData\Roaming\Opera Software\Opera Stable\Extensions\pjljfckmhjnpbcgneijeeiimpkdjccob [2018-07-11]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-02-16] (ASUSTeK Computer Inc. -> ASUS)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Windows -> Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AgereSoftModem; C:\windows\System32\DRIVERS\agrsm64.sys [1146880 2009-06-10] (Microsoft Windows -> LSI Corp)
R3 asmthub3; C:\windows\System32\DRIVERS\asmthub3.sys [130024 2011-11-22] (MCCI Internal Testing Software -> ASMedia Technology Inc)
R3 asmtxhci; C:\windows\System32\DRIVERS\asmtxhci.sys [395752 2011-11-22] (MCCI Internal Testing Software -> ASMedia Technology Inc)
S3 athr; C:\windows\System32\DRIVERS\athrx.sys [1394688 2009-06-19] (Microsoft Windows -> Atheros Communications, Inc.)
R3 kbfiltr; C:\windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] (ASUSTeK Computer Inc. -> )
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R3 NisDrv; C:\windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
R2 NPF; C:\windows\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 SiSGbeLH; C:\windows\System32\DRIVERS\SiSG664.sys [56832 2009-06-10] (Microsoft Windows -> Silicon Integrated Systems Corp.)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] (Empty Loop -> )
S3 WDC_SAM; C:\windows\System32\DRIVERS\wdcsam64.sys [23200 2015-04-30] (Microsoft Windows Hardware Compatibility Publisher -> Western Digital Technologies)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-09-02 07:08 - 2019-09-02 07:41 - 000000000 ____D C:\Users\happy\Desktop\00000
2019-09-02 05:14 - 2019-09-02 05:14 - 000003288 ____N C:\bootsqm.dat
2019-09-02 04:10 - 2019-09-02 07:40 - 000000000 ____D C:\FRST
2019-08-18 14:47 - 2019-08-18 14:48 - 000262144 _____ C:\windows\Minidump\081819-20217-01.dmp
2019-08-15 17:50 - 2019-08-15 17:50 - 000000773 _____ C:\Users\happy\Desktop\Start Tor Browser.lnk
2019-08-15 17:50 - 2019-08-15 17:50 - 000000000 ____D C:\Users\happy\Desktop\Tor Browser
2019-08-15 16:44 - 2019-08-17 18:20 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-08-12 03:45 - 2019-08-12 03:45 - 000000000 ____D C:\Users\happy\AppData\Roaming\WAS_FF_2019-8-11
2019-08-12 02:44 - 2019-08-17 18:20 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-08-12 02:44 - 2019-08-12 02:44 - 000000938 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-08-12 02:44 - 2019-08-12 02:44 - 000000926 _____ C:\Users\Public\Desktop\Firefox.lnk
2019-08-12 00:59 - 2019-08-12 00:59 - 000000896 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waterfox.lnk
2019-08-12 00:59 - 2019-08-12 00:59 - 000000884 _____ C:\Users\Public\Desktop\Waterfox.lnk
2019-08-12 00:59 - 2019-08-12 00:59 - 000000000 ____D C:\Users\happy\AppData\Roaming\Waterfox
2019-08-12 00:59 - 2019-08-12 00:59 - 000000000 ____D C:\Users\happy\AppData\Local\Waterfox
2019-08-12 00:59 - 2019-08-12 00:59 - 000000000 ____D C:\Program Files\Waterfox
2019-08-11 22:34 - 2019-08-11 22:34 - 000000000 ____D C:\Users\happy\Desktop\Old Firefox Data
2019-08-05 02:02 - 2019-08-05 02:02 - 000239398 _____ C:\Users\happy\AppData\Local\recently-used.xbel
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-09-02 07:08 - 2016-11-18 20:48 - 000000000 ____D C:\Users\happy\AppData\LocalLow\Mozilla
2019-09-02 06:53 - 2013-11-14 03:32 - 000003902 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{4A7FB7E8-812B-4EFC-8112-5440817388C6}
2019-09-02 06:53 - 2013-11-11 11:40 - 000000000 ____D C:\Users\happy\AppData\Roaming\vlc
2019-09-02 06:10 - 2013-11-11 04:36 - 000000000 ____D C:\Users\happy\Desktop\DOWNLOADS HERE
2019-09-02 05:29 - 2009-07-13 23:45 - 000018736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-09-02 05:29 - 2009-07-13 23:45 - 000018736 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-09-02 05:22 - 2013-11-11 03:44 - 000000380 _____ C:\Users\happy\AppData\Roaming\sp_data.sys
2019-09-02 05:22 - 2013-11-11 03:44 - 000000000 ___HD C:\ASUS.DAT
2019-09-02 05:21 - 2009-07-14 00:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
2019-09-02 05:06 - 2013-11-24 23:31 - 000000000 ____D C:\Users\happy\AppData\Roaming\BatteryBar
2019-09-02 05:04 - 2016-01-18 14:35 - 000000000 ____D C:\Program Files (x86)\SpywareBlaster
2019-09-02 05:04 - 2013-10-24 15:29 - 000000000 ____D C:\ProgramData\Temp
2019-09-02 05:03 - 2019-05-13 06:27 - 000002298 _____ C:\Users\happy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Vivaldi.lnk
2019-09-02 05:03 - 2019-05-13 06:27 - 000002261 _____ C:\Users\happy\Desktop\Vivaldi.lnk
2019-09-02 05:03 - 2016-08-11 06:44 - 000000000 ____D C:\Users\happy\AppData\Local\Vivaldi
2019-09-02 04:36 - 2019-04-29 16:51 - 000000000 ____D C:\Users\happy\AppData\Local\Blisk
2019-08-30 16:54 - 2017-07-13 08:34 - 000003828 _____ C:\windows\System32\Tasks\Opera scheduled Autoupdate 1499952880
2019-08-30 16:54 - 2017-07-13 08:34 - 000000000 ____D C:\Program Files\Opera
2019-08-29 11:25 - 2015-04-25 01:12 - 000000000 ____D C:\Program Files (x86)\Pale Moon
2019-08-18 14:47 - 2019-07-27 18:44 - 1096761027 _____ C:\windows\MEMORY.DMP
2019-08-18 14:47 - 2019-07-27 18:44 - 000000000 ____D C:\windows\Minidump
2019-08-18 05:35 - 2009-07-14 00:13 - 000782470 _____ C:\windows\system32\PerfStringBackup.INI
2019-08-18 05:35 - 2009-07-13 22:20 - 000000000 ____D C:\windows\inf
2019-08-18 01:39 - 2015-04-25 01:12 - 000000000 ____D C:\Users\happy\AppData\Roaming\Moonchild Productions
2019-08-15 17:50 - 2017-06-06 00:34 - 000000821 _____ C:\Users\happy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2019-08-15 17:49 - 2013-11-11 05:47 - 000000000 ____D C:\Users\happy\Desktop\OLD
2019-08-12 03:42 - 2017-11-06 19:05 - 000000000 ____D C:\Users\happy\AppData\Roaming\Mozilla
2019-08-12 00:47 - 2013-11-11 10:19 - 000000000 ____D C:\ProgramData\Mozilla
2019-08-09 20:17 - 2018-12-20 12:36 - 000000000 ____D C:\Users\happy\Desktop\pat
2019-08-08 13:27 - 2009-07-13 23:45 - 000337648 _____ C:\windows\system32\FNTCACHE.DAT
2019-08-05 03:38 - 2018-07-04 05:25 - 000000000 ____D C:\Users\happy\.gimp-2.8
2019-08-04 06:58 - 2013-11-11 03:44 - 000072472 _____ C:\Users\happy\AppData\Local\GDIPFONTCACHEV1.DAT
==================== Files in the root of some directories ================
2013-11-11 03:44 - 2019-09-02 05:22 - 000000380 _____ () C:\Users\happy\AppData\Roaming\sp_data.sys
2019-08-05 02:02 - 2019-08-05 02:02 - 000239398 _____ () C:\Users\happy\AppData\Local\recently-used.xbel
2016-01-23 18:43 - 2016-01-23 18:43 - 000007641 _____ () C:\Users\happy\AppData\Local\Resmon.ResmonCfg
==================== SigCheck ===============================
(There is no automatic fix for files that do not pass verification.)
LastRegBack: 2019-08-31 06:08
==================== End of FRST.txt ============================
##
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-08-2019
Ran by happy (02-09-2019 07:42:31)
Running from C:\Users\happy\Desktop\00000
Windows 7 Home Premium Service Pack 1 (X64) (2013-11-11 08:43:46)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1167706805-3652461753-1077729752-500 - Administrator - Disabled)
Guest (S-1-5-21-1167706805-3652461753-1077729752-501 - Limited - Disabled)
happy (S-1-5-21-1167706805-3652461753-1077729752-1000 - Administrator - Enabled) => C:\Users\happy
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
AkelPad 4.8.4 (HKLM-x32\...\AkelPad) (Version: 4.8.4 - )
Alcor Micro USB Card Reader (HKLM-x32\...\{4555BB9E-E715-4260-A178-E8EFD2B653E3}) (Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.4.0 - Asmedia Technology)
ASUS AI Recovery (HKLM-x32\...\{D39F0676-163E-4595-A917-E28F99BBD4D2}) (Version: 1.0.23 - ASUS)
ASUS FaceLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0014 - ASUS)
ASUS FancyStart (HKLM-x32\...\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}) (Version: 1.1.1 - ASUSTeK Computer Inc.)
ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.2 - ASUS)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.29 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.7 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0041 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.25 - ASUS)
ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.108.222 - eCareme Technologies, Inc.)
ASUS_Screensaver (HKLM-x32\...\ASUS_Screensaver) (Version: - )
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.9.157 - ASUSTEK)
ATK Packag