(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtkAudUService] => C:\Windows\System32\RtkAudUService64.exe [881768 2019-06-24] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [WavesSvc] => C:\Windows\System32\DriverStore\FileRepository\wavesapo75de.inf_amd64_5ff36f834a6d461a\WavesSvc64.exe [1222536 2018-12-05] (Waves Inc -> Waves Audio Ltd.)
HKLM\...\Run: [DellMobileConnectWelcome] => C:\Program Files\Dell\DellMobileConnectDrivers\DellMobileConnectWStartup.exe [313064 2018-10-05] (SCREENOVATE TECHNOLOGIES LTD. -> Screenovate Technologies Ltd.)
HKLM\...\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [527792 2017-08-09] (Open Source Developer, Robin Krom -> Greenshot)
HKLM\...\Run: [AgentAntidote32] => C:\Program Files (x86)\Druide\Antidote 9\Application\Bin32\AgentAntidote.exe [1653352 2017-09-12] (Druide Informatique Inc. -> Druide informatique inc.) [File not signed]
HKLM\...\Run: [AgentAntidote64] => C:\Program Files (x86)\Druide\Antidote 9\Application\Bin64\AgentAntidote.exe [1797736 2017-09-12] (Druide Informatique Inc. -> Druide informatique inc.) [File not signed]
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [318920 2019-05-30] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [5782336 2019-08-13] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG -> Elaborate Bytes AG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [644552 2019-07-04] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Discord] => C:\ProgramData\SquirrelMachineInstalls\Discord.exe [61370712 2019-03-15] (Discord Inc. -> Discord Inc.)
HKLM-x32\...\Run: [jswtrayutil] => C:\Program Files (x86)\Jumpstart\jswtrayutil.exe [528384 2008-09-26] (Atheros Communications, Inc.) [File not signed]
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2384984 2016-12-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup
HKU\S-1-5-20\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup
HKU\S-1-5-21-408333896-3164079283-3827766986-1001\...\Run: [Pushbullet] => D:\program\pushbullet\Pushbullet\pushbullet.exe [345600 2015-07-01] (Pushbullet inc) [File not signed]
HKU\S-1-5-21-408333896-3164079283-3827766986-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-408333896-3164079283-3827766986-1001\...\Run: [ApowersoftScreenRecorder] => C:\Program Files (x86)\Apowersoft\Apowersoft Screen Recorder Pro 2\Apowersoft Screen Recorder Pro 2.exe [3016344 2018-09-29] (Apowersoft Ltd -> Apowersoft)
HKU\S-1-5-21-408333896-3164079283-3827766986-1001\...\Run: [Clipdiary] => C:\Program Files (x86)\Clipdiary\clipdiary.exe [6735360 2019-05-06] () [File not signed]
HKU\S-1-5-21-408333896-3164079283-3827766986-1001\...\Run: [Discord] => C:\Users\pirja\AppData\Local\Discord\app-0.0.305\Discord.exe [81780056 2019-03-07] (Discord Inc. -> Discord Inc.)
HKU\S-1-5-21-408333896-3164079283-3827766986-1001\...\Run: [NoxDaemon] => C:\Users\pirja\AppData\Roaming\NoxSrv\NoxSrv.exe [116736 2019-07-12] () [File not signed]
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\system32\lagarith.dll [148992 2011-12-07] ( ) [File not signed]
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\SysWOW64\lagarith.dll [216064 2011-12-07] ( ) [File not signed]
HKLM\...\Drivers32: [msacm.vorbis] => C:\Windows\SysWOW64\vorbis.acm [1294336 2003-01-20] (HMS hxxp://hp.vector.co.jp/authors/VA012897/) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [OpenVPN_UserSetup] -> reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /f
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.100\Installer\chrmstp.exe [2019-08-21] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2019-06-30]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe (SteelSeries ApS -> SteelSeries ApS)
Startup: C:\Users\pirja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BatteryBar.lnk [2019-08-07]
ShortcutTarget: BatteryBar.lnk -> C:\Program Files\BatteryBar\BatteryBar.exe (Osiris Development -> Osiris Development)
Startup: C:\Users\pirja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2019-02-15]
ShortcutTarget: MEGAsync.lnk -> C:\Users\pirja\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited -> Mega Limited)
Startup: C:\Users\pirja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ProtonMail Bridge.lnk [2019-03-30]
ShortcutTarget: ProtonMail Bridge.lnk -> C:\Program Files\Proton Technologies AG\ProtonMail Bridge\Desktop-Bridge.exe (No File)
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {13B68E53-CF6D-4AA8-85DC-629FC7D0AC7C} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1878EDF5-1632-403F-A028-AC4C216B81AE} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {207127DF-9415-4730-A259-9032E04BD93D} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [1512920 2019-05-24] (Dell Inc. -> Dell Inc.)
Task: {2FE2F2C0-2D96-465D-9161-825648EABC8C} - System32\Tasks\HMA! Pro VPN Update => C:\Program Files (x86)\HMA! Pro VPN\VpnUpdate.exe [1474672 2019-08-12] (Privax Limited -> Privax Limited)
Task: {32156E94-9975-4D29-B7F5-41F8F7848459} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2177680 2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {3769C2A2-4973-42B2-AE69-C38C65C0D66F} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3D771F87-9A88-436F-8581-BBD7E3AE81B0} - System32\Tasks\AdobeGCInvoker-1.0-MicrosoftAccount-pirjackoy@hotmail.com => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2849872 2019-07-04] (Adobe Inc. -> Adobe Systems, Incorporated)
Task: {40AF7EAF-47F5-412F-9681-4135DB56ED61} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132 => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18744 2019-04-15] (Intel(R) Software Development Products -> Intel Corporation)
Task: {580DC558-C208-4789-8996-AB2F8A0A05F3} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
Task: {5A427DE9-CDBB-47FA-B674-D30FE9767246} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2019-08-15] (Adobe Inc. -> Adobe)
Task: {5C143FB3-8CA5-4C9C-96BE-633F937C5FF3} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {5E4BA37F-E9AA-47D1-9706-E00F0E29CCB0} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2019-02-14] (Dropbox, Inc -> Dropbox, Inc.)
Task: {6A291EBA-7B4F-4EB4-A388-A056D477321A} - System32\Tasks\IntelSURQC-Upgrade-86621605-2a0b-4128-8ffc-15514c247132-Logon => C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18744 2019-04-15] (Intel(R) Software Development Products -> Intel Corporation)
Task: {6F5045D0-65AD-4FE4-979B-E2CDE5724ACA} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\Windows\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\x64\task.vbs"
Task: {7C3EFB71-D38E-4262-97E0-A406A38FB76A} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2177680 2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {7C928B29-D7FF-4120-A320-9C1B35655A85} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27278352 2019-08-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {8DA6AC64-1220-4330-A214-06BB117C457F} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_238_pepper.exe [1452600 2019-08-15] (Adobe Inc. -> Adobe)
Task: {914ECA99-5ED2-4E79-8667-D8DDD48C8E10} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [27278352 2019-08-15] (Microsoft Corporation -> Microsoft Corporation)
Task: {A0D8644E-3276-437E-B6CD-D5801F32D631} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\Windows\explorer.exe /NOUACCHECK
Task: {AD7DE0FE-6A79-448F-A791-AB570B94A398} - System32\Tasks\ConsoleAct => C:\Windows\ConsoleAct_x64.exe [840560 2018-08-01] (WZTeam -> MSFree Inc., Ratiborus) [File not signed]
Task: {B16CE096-57EC-4EF1-A56A-B33770180AA6} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [648504 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B4567719-ACFD-4506-80F7-6624F95EBF92} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CA1999BD-1A1A-4ADA-BA50-0081B8E35F21} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6299792 2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {CE946BDA-0920-4667-A228-35A3795AE37B} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\osfinstaller.exe
Task: {D3D4E141-E983-4796-85FA-8AFD2C096EF9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-14] (Google Inc -> Google Inc.)
Task: {D69D2A2D-0E9E-42BE-9995-718F3C2E9EC7} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2019-02-14] (Dropbox, Inc -> Dropbox, Inc.)
Task: {E198A33F-D1E3-4613-AEA8-B9A618A6E94C} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E21018B4-48B8-4B77-9261-A9E5EF26385E} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3788144 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E9A6A25D-10E4-4300-AC39-5E930CBB0E6E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156968 2019-02-14] (Google Inc -> Google Inc.)
Task: {F317E543-52CE-4825-A7BE-17584584FC3C} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F91E75A9-37FD-4EC7-899E-C05A65B81A1E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [6299792 2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Task: {FDA69153-E823-46C8-ABEC-F5E64A1D0C12} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{05f2a3dc-162b-4b5b-9d7a-4cf257aedc9f}: [DhcpNameServer] 192.168.2.1 207.164.234.193
Tcpip\..\Interfaces\{ab954629-d7b3-48f5-8e9a-6319c0a11212}: [NameServer] 100.120.56.1
Tcpip\..\Interfaces\{b999b08f-b0aa-4129-b051-c5fb43bd634c}: [DhcpNameServer] 4.2.2.1
Internet Explorer:
==================
HKU\S-1-5-21-408333896-3164079283-3827766986-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://dell17win10.msn.com/?pc=DCTE
HKU\S-1-5-21-408333896-3164079283-3827766986-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
SearchScopes: HKU\S-1-5-21-408333896-3164079283-3827766986-1001 -> DefaultScope {61555BF3-C566-45DC-BD27-8F997BFA5C89} URL =
SearchScopes: HKU\S-1-5-21-408333896-3164079283-3827766986-1001 -> {61555BF3-C566-45DC-BD27-8F997BFA5C89} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_221\bin\ssv.dll [2019-07-23] (Oracle America, Inc. -> Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_221\bin\jp2ssv.dll [2019-07-23] (Oracle America, Inc. -> Oracle Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-02-25] (Eyeo GmbH -> Eyeo GmbH) [File not signed]
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH -> Eyeo GmbH) [File not signed]
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-08-20] (Microsoft Corporation -> Microsoft Corporation)
Edge:
======
DownloadDir: C:\Users\pirja\Downloads
FireFox:
========
FF DefaultProfile: 2e3397mj.default
FF DefaultProfile: x50lax2a.default
FF ProfilePath: C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11 [2019-08-25]
FF Homepage: Mozilla\Firefox\Profiles\ayiflckg.Default User11 -> about:blank
FF Extension: (TorGuard VPN Extension) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\@VPNetworksLLC.xpi [2019-08-07]
FF Extension: (Antidote) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\antidote9_firefox@druide.com.xpi [2017-11-30] [UpdateUrl:hxxps://
www.druide.com/telecharger/texteurs/Mozilla/commun/maj_antidote_mozilla.php?id=%ITEM_ID%&version=%ITEM_VERSION%&appid=%APP_ID%&appversion=%APP_VERSION%&appos=%APP_OS%&appabi=%APP_ABI%&applocale=%APP_LOCALE%;&itemstatus=%ITEM_STATUS%]
FF Extension: (ReCaptcha Solver) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\doz4@hotmail.com.xpi [2019-08-07]
FF Extension: (TubeBuddy for YouTube) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\e389d8c2-5554-4ba2-a36e-ac7a57093130@gmail.com.xpi [2019-08-23]
FF Extension: (SaveFrom.net helper) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\helper@savefrom.net.xpi [2019-08-20]
FF Extension: (HTTPS Everywhere) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\https-everywhere@eff.org.xpi [2019-08-07]
FF Extension: (Pushbullet) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\jid1-BYcQOfYfmBMd9A@jetpack.xpi [2019-08-07]
FF Extension: (Pandora Extended Shortcuts) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\pandora@bbradley.net.xpi [2019-08-07]
FF Extension: (User-Agent Switcher) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\user-agent-switcher@ninetailed.ninja.xpi [2019-08-16]
FF Extension: (minerBlock) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\xd4rker@gmail.com.xpi [2019-08-07]
FF Extension: (Stylish - Custom themes for any website) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2019-08-07]
FF Extension: (Bh Dark Mode) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\{62281241-d81e-4922-9c3e-b99fd1ebfcb2}.xpi [2019-08-07]
FF Extension: (DarkTheme) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\{99c277af-d778-4a0b-9faa-b1d8165f0a55}.xpi [2019-08-07]
FF Extension: (Dark Fox) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\{e7fe4ffe-f256-4f85-906d-072fdd698585}.xpi [2019-08-07]
FF Extension: (FTP System c.a.) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\ayiflckg.Default User11\Extensions\{ffca2acd-c848-4961-ab1a-14d45d2c9c22}.xpi [2019-08-07]
FF ProfilePath: C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default [2019-08-07]
FF user.js: detected! => C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\user.js [2019-02-15]
FF Homepage: Mozilla\Firefox\Profiles\2e3397mj.default -> about:blank
FF NewTab: Mozilla\Firefox\Profiles\2e3397mj.default -> about:blank
FF Extension: (TorGuard VPN Extension) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\@VPNetworksLLC.xpi [2019-07-01]
FF Extension: (Antidote-Firefox) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\antidote9_firefox@druide.com [2019-02-15] [Legacy]
FF Extension: (Antidote) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\antidote9_firefox@druide.com.xpi [2017-11-30] [UpdateUrl:hxxps://
www.druide.com/telecharger/texteurs/Mozilla/commun/maj_antidote_mozilla.php?id=%ITEM_ID%&version=%ITEM_VERSION%&appid=%APP_ID%&appversion=%APP_VERSION%&appos=%APP_OS%&appabi=%APP_ABI%&applocale=%APP_LOCALE%;&itemstatus=%ITEM_STATUS%]
FF Extension: (ReCaptcha Solver) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\doz4@hotmail.com.xpi [2019-07-10]
FF Extension: (Spanish (Spain) Dictionary) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\es-es@dictionaries.addons.mozilla.org.xpi [2019-02-23]
FF Extension: (French spelling dictionary) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\fr-dicollecte@dictionaries.addons.mozilla.org [2019-04-01]
FF Extension: (SaveFrom.net helper) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\helper@savefrom.net.xpi [2019-08-05]
FF Extension: (HTTPS Everywhere) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\https-everywhere@eff.org.xpi [2019-07-08]
FF Extension: (Privacy Settings) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\jid1-CKHySAadH4nL6Q@jetpack.xpi [2019-06-16]
FF Extension: (English (GB) Language Pack) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\langpack-en-GB@firefox.mozilla.org.xpi [2019-07-24]
FF Extension: (Español (España) Language Pack) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\langpack-es-ES@firefox.mozilla.org.xpi [2019-07-24]
FF Extension: (Français Language Pack) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\langpack-fr@firefox.mozilla.org.xpi [2019-07-24]
FF Extension: (British English Dictionary (Marco Pinto)) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\marcoagpinto@mail.telepac.pt.xpi [2019-07-29]
FF Extension: (minerBlock) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\xd4rker@gmail.com.xpi [2019-06-21]
FF Extension: (Kolotibablo bot) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\{228118ac-98b5-4b8f-9ed9-7c18b15c23c4}.xpi [2019-08-05] [UpdateUrl:hxxps://antcpt.com/downloads/kolotibablo/firefox/update_manifest.json]
FF Extension: (Fake video news debunker by InVID) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\{b86b6076-1d0f-4ef1-bd24-16bfe94e3eb5}.xpi [2019-07-27]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-08-05]
FF Extension: (Save time by asking Buster to solve captchas for you.) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\2e3397mj.default\Extensions\{e58d3966-3d76-4cd9-8552-1582fbc800c1}.xpi [2019-06-21]
FF ProfilePath: C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\oahddy53.default-release [2019-08-26]
FF Extension: (Antidote) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\oahddy53.default-release\Extensions\antidote9_firefox@druide.com.xpi [2019-08-09] [UpdateUrl:hxxps://
www.druide.com/telecharger/texteurs/Mozilla/commun/maj_antidote_mozilla.php?id=%ITEM_ID%&version=%ITEM_VERSION%&appid=%APP_ID%&appversion=%APP_VERSION%&appos=%APP_OS%&appabi=%APP_ABI%&applocale=%APP_LOCALE%;&itemstatus=%ITEM_STATUS%]
FF Extension: (French spelling dictionary) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\oahddy53.default-release\Extensions\fr-dicollecte@dictionaries.addons.mozilla.org.xpi [2019-08-10]
FF Extension: (Français Language Pack) - C:\Users\pirja\AppData\Roaming\Mozilla\Firefox\Profiles\oahddy53.default-release\Extensions\langpack-fr@firefox.mozilla.org.xpi [2019-08-10]
FF ProfilePath: C:\Users\pirja\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\x50lax2a.default [2019-05-30]
FF Extension: (Adblock Plus - free ad blocker) - C:\Program Files\Mozilla Firefox\browser\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [2019-02-15]
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2000-01-01] (Tracker Software Products (Canada) Ltd -> Tracker Software Products Ltd.)
FF Plugin: @java.com/DTPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\dtplugin\npDeployJava1.dll [2019-07-23] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.221.2 -> C:\Program Files\Java\jre1.8.0_221\bin\plugin2\npjp2.dll [2019-07-23] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-06-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin:
@Tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2000-01-01] (Tracker Software Products (Canada) Ltd -> Tracker Software Products Ltd.)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-12-09] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1234204.dll [2018-06-06] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2000-01-01] (Tracker Software Products (Canada) Ltd -> Tracker Software Products Ltd.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.13\npGoogleUpdate3.dll [2019-08-05] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.13\npGoogleUpdate3.dll [2019-08-05] (Google Inc -> Google LLC)
FF Plugin-x32:
@Tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2000-01-01] (Tracker Software Products (Canada) Ltd -> Tracker Software Products Ltd.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-12-09] (Adobe Systems Incorporated -> Adobe Systems)
FF Plugin HKU\S-1-5-21-408333896-3164079283-3827766986-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll [2000-01-01] (Tracker Software Products (Canada) Ltd -> Tracker Software Products Ltd.)
FF Plugin HKU\S-1-5-21-408333896-3164079283-3827766986-1001: @turbo.net/Turbo.net Plugin 3.33 -> C:\Users\pirja\AppData\Local\Turbo\19.4.1964.21\npMozillaTurboPlugin.dll [No File]
StartMenuInternet: Firefox-CA9422711AE1A81C - C:\Program Files\Firefox Developer Edition\firefox.exe
Chrome: