Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-08-2019 Ran by 12qun (19-08-2019 19:01:29) Running from C:\Users\12qun\OneDrive\Pulpit Windows 10 Pro Version 1903 18362.30 (X64) (2019-08-19 07:01:08) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= 12qun (S-1-5-21-156907257-2484602571-1260501974-1001 - Administrator - Enabled) => C:\Users\12qun Administrator (S-1-5-21-156907257-2484602571-1260501974-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-156907257-2484602571-1260501974-503 - Limited - Disabled) Guest (S-1-5-21-156907257-2484602571-1260501974-501 - Limited - Disabled) WDAGUtilityAccount (S-1-5-21-156907257-2484602571-1260501974-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) AIMP (HKLM-x32\...\AIMP) (Version: v4.51.2084, 01.12.2018 - AIMP DevTeam) AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD) Forza.Horizon.4.Ultimate.Edition-LOOTBOX version final (HKLM-x32\...\Forza.Horizon.4.Ultimate.Edition-LOOTBOX_is1) (Version: final - The) IrfanView 4.53 (64-bit) (HKLM\...\IrfanView64) (Version: 4.53 - Irfan Skiljan) Live! Cam Chat HD VF0790 Driver (1.00.07.00) (HKLM\...\Creative VF0790) (Version: - Creative Technology Ltd.) Microsoft OneDrive (HKU\S-1-5-21-156907257-2484602571-1260501974-1001\...\OneDriveSetup.exe) (Version: 19.123.0624.0005 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Opera Stable 62.0.3331.88 (HKU\S-1-5-21-156907257-2484602571-1260501974-1001\...\Opera 62.0.3331.88) (Version: 62.0.3331.88 - Opera Software) VLC media player (HKLM\...\VLC media player) (Version: 2.2.4 - VideoLAN) WinRAR 5.71 (64-bitowy) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH) Packages: ========= EdgeDevtoolsPlugin -> C:\Windows\SystemApps\Microsoft.EdgeDevtoolsPlugin_cw5n1h2txyewy [2019-08-19] (Microsoft Corporation) Mail and Calendar -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11029.20108.0_x64__8wekyb3d8bbwe [2019-08-19] (Microsoft Corporation) [MS Ad] Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2019-08-19] (Microsoft Corporation) [MS Ad] Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.2.11280.0_x86__8wekyb3d8bbwe [2019-08-19] (Microsoft Studios) [MS Ad] MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.25.20211.0_x64__8wekyb3d8bbwe [2019-08-19] (Microsoft Corporation) [MS Ad] ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ContextMenuHandlers1: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2019-08-19] (Artem Izmaylov -> AIMP DevTeam) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-05-07] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-05-07] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers4: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2019-08-19] (Artem Izmaylov -> AIMP DevTeam) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2015-11-04] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-05-07] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-05-07] (win.rar GmbH -> Alexander Roshal) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-11-04 16:40 - 2015-11-04 16:40 - 000004608 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiamenu.dll ==================== Alternate Data Streams (Whitelisted) ========= ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2019-03-19 06:49 - 2019-03-19 06:49 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-156907257-2484602571-1260501974-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg DNS Servers: 192.168.8.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: ) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [TCP Query User{3A45B4FA-61D9-4F07-A751-A429970768C9}C:\users\12qun\onedrive\pulpit\activation\activation\wdvdriver\aact.dll] => (Allow) C:\users\12qun\onedrive\pulpit\activation\activation\wdvdriver\aact.dll (WZTeam -> MSFree Inc.) [File not signed] FirewallRules: [UDP Query User{71329772-E0DA-41C0-ADDE-DDC2B72FFD48}C:\users\12qun\onedrive\pulpit\activation\activation\wdvdriver\aact.dll] => (Allow) C:\users\12qun\onedrive\pulpit\activation\activation\wdvdriver\aact.dll (WZTeam -> MSFree Inc.) [File not signed] FirewallRules: [OpenSSH-Server-In-TCP] => (Allow) %SystemRoot%\system32\OpenSSH\sshd.exe (Microsoft Windows -> ) ==================== Restore Points ========================= 19-08-2019 09:23:40 Windows Update ==================== Faulty Device Manager Devices ============= Name: Multimedia Audio Controller Description: Multimedia Audio Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Intel(R) Management Engine Interface Description: Intel(R) Management Engine Interface Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318} Manufacturer: Intel Service: HECIx64 Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/19/2019 06:54:28 PM) (Source: ESENT) (EventID: 902) (User: ) Description: svchost (6700,D,122) Unistore: The database engine detected multiple threads illegally using the same database session to perform database operations. SessionId: 0x000001BB7A2D9D40 Session-context: 0x0000000000000000 Session-context ThreadId: 0x0000000000000000 Current ThreadId: 0x00000000000018E4 Session-trace: Error: (08/19/2019 06:52:44 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program HxOutlook.exe version 16.0.11029.20104 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: 620 Start Time: 01d556ae7e243e14 Termination Time: 4294967295 Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11029.20108.0_x64__8wekyb3d8bbwe\HxOutlook.exe Report Id: 2251373f-e8c1-485a-b68b-3fc111628d88 Faulting package full name: microsoft.windowscommunicationsapps_16005.11029.20108.0_x64__8wekyb3d8bbwe Faulting package-relative application ID: microsoft.windowslive.mail Hang type: Quiesce Error: (08/19/2019 06:50:54 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: License Activation (slui.exe) failed with the following error code: hr=0x803F7001 Command-line arguments: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable Error: (08/19/2019 06:50:54 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: License Activation (slui.exe) failed with the following error code: hr=0x803F7001 Command-line arguments: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable Error: (08/19/2019 06:50:52 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: License Activation (slui.exe) failed with the following error code: hr=0x80072EE7 Command-line arguments: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=UserLogon;SessionId=4 Error: (08/19/2019 04:59:18 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: SystemSettings.exe, version: 10.0.18362.1, time stamp: 0x066bf1a5 Faulting module name: msvcrt.dll, version: 7.0.18362.1, time stamp: 0xf5bdefd7 Exception code: 0xc0000005 Fault offset: 0x000000000005e6a3 Faulting process id: 0x161c Faulting application start time: 0x01d5569ddde3b38f Faulting application path: C:\Windows\ImmersiveControlPanel\SystemSettings.exe Faulting module path: C:\Windows\System32\msvcrt.dll Report Id: f0758e57-4105-4f65-ae80-e7eeeefd990c Faulting package full name: windows.immersivecontrolpanel_10.0.2.1000_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: microsoft.windows.immersivecontrolpanel Error: (08/19/2019 03:38:17 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program WindowsCamera.exe version 2018.826.70.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: ca8 Start Time: 01d5568fb95beb3a Termination Time: 4294967295 Application Path: C:\Program Files\WindowsApps\Microsoft.WindowsCamera_2018.826.78.0_x64__8wekyb3d8bbwe\WindowsCamera.exe Report Id: b35864a2-2b52-46e1-8187-eb5cd2ae3722 Faulting package full name: Microsoft.WindowsCamera_2018.826.78.0_x64__8wekyb3d8bbwe Faulting package-relative application ID: App Hang type: Cross-thread Error: (08/19/2019 09:15:14 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: ) Description: License Activation (slui.exe) failed with the following error code: hr=0x803F7001 Command-line arguments: RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=NetworkAvailable System errors: ============= Error: (08/19/2019 06:50:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Clipboard User Service_2a9d93 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 3000 milliseconds: Restart the service. Error: (08/19/2019 06:49:17 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7THS4O7) Description: The server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} did not register with DCOM within the required timeout. Error: (08/19/2019 06:49:17 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7THS4O7) Description: The server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} did not register with DCOM within the required timeout. Error: (08/19/2019 06:49:15 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7THS4O7) Description: The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout. Error: (08/19/2019 06:49:15 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7THS4O7) Description: The server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} did not register with DCOM within the required timeout. Error: (08/19/2019 09:16:38 AM) (Source: disk) (EventID: 154) (User: ) Description: The IO operation at logical block address 0x0 for Disk 1 (PDO name: \Device\0000005d) failed due to a hardware error. Error: (08/19/2019 09:16:38 AM) (Source: disk) (EventID: 154) (User: ) Description: The IO operation at logical block address 0x0 for Disk 1 (PDO name: \Device\0000005d) failed due to a hardware error. Error: (08/19/2019 09:16:38 AM) (Source: disk) (EventID: 154) (User: ) Description: The IO operation at logical block address 0x0 for Disk 1 (PDO name: \Device\0000005d) failed due to a hardware error. ==================== Memory info =========================== BIOS: Award Software International, Inc. F3 09/10/2010 Motherboard: Gigabyte Technology Co., Ltd. H55M-S2V Processor: Intel(R) Core(TM) i5 CPU 760 @ 2.80GHz Percentage of memory in use: 25% Total physical RAM: 12247.49 MB Available physical RAM: 9101.83 MB Total Virtual: 14679.49 MB Available Virtual: 11427.27 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:361.33 GB) (Free:254.17 GB) NTFS ==>[system with boot components (obtained from drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 9A61203D) Partition 1: (Not Active) - (Size=104.4 GB) - (Type=05) Partition 2: (Active) - (Size=361.3 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================