Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: trojaner eingefangen?

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 07.03.2019, 15:30   #1
bersem
 
trojaner eingefangen? - Standard

trojaner eingefangen?



Hallo allerseits,

bin neu hier. Habe das mulmige Gefühl dass jemand sich Zugriff auf mein PC verschafft hat.

Hab vor kurzem ein OTL-Scan als Benutzer gemacht den ich hier poste damit es jemand auswertet und mir weiterhilft..

Vielen Dank im Voraus !

LG

OTL.txt


Code:
ATTFilter
OTL Extras logfile created on: 07.03.2019 14:10:52 - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\bersem\Desktop
 Professional  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.17763.0)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,24 Gb Total Physical Memory | 2,22 Gb Available Physical Memory | 68,67% Memory free
7,23 Gb Paging File | 5,19 Gb Available in Paging File | 71,79% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152,41 Gb Total Space | 27,36 Gb Free Space | 17,95% Space Free | Partition Type: NTFS
 
Computer Name: USER-PC | User Name: bersem | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\WINDOWS\winhlp32.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office16\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [mplayerc.enqueue] -- "C:\Program Files\K-Lite Codec Pack\MPC-HC\mpc-hc.exe" /add "%1" (MPC-HC Team)
Directory [mplayerc.play] -- "C:\Program Files\K-Lite Codec Pack\MPC-HC\mpc-hc.exe" "%1" (MPC-HC Team)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Powershell] -- powershell.exe -noexit -command Set-Location '%V' (Microsoft Corporation)
Directory [UpdateEncryptionSettings] -- Reg Error: Key error.
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Feature]
"DisableAvCheck" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\CBP]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\DPA]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\SecurityApp]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\SecurityApp\WebProtection]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{42CD32AD-AFD7-4D44-8FE6-23545A9B29AF}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\opera\58.0.3135.68\opera.exe | 
"{9717403B-B921-4943-8655-DF2886688336}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\opera\58.0.3135.79\opera.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08B9FFBE-0A0E-4E9C-B959-32B31524A467}" = dir=out | name=microsoft pay | 
"{0BA81A35-1937-4143-A6DB-F7AA7F7FCADE}" = dir=out | name=onenote | 
"{12A3AB2B-DA11-434F-B8E6-5112DD12B262}" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | 
"{171494DC-9986-46AC-B430-C45A03C7E78C}" = dir=in | name=onenote | 
"{194B80B4-B578-4B65-BFFC-37329E6FF132}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} | 
"{1D60A15E-2381-4289-9DFB-784A7B71A140}" = dir=in | name=@{microsoft.windows.photos_2019.18114.17710.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} | 
"{1E08EE6A-3408-4BB9-90E4-AFC283025E72}" = dir=out | name=xbox game bar | 
"{1FC2EF96-B96D-419F-B296-8B44EC842A44}" = dir=out | name=@{microsoft.lockapp_10.0.17763.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} | 
"{214A75BA-C185-4052-956C-FB36BA6CE75B}" = dir=in | name=@{microsoft.windows.cortana_1.11.5.17763_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} | 
"{22C4A797-6520-458B-A7DD-F05F7206C53C}" = dir=out | name=@{microsoft.bingsports_4.28.3242.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} | 
"{26F5BC1D-5117-4A72-8B62-E41AE5B39D90}" = dir=in | name=@{microsoft.xboxgamingoverlay_2.26.28001.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.xboxgamingoverlay/resources/gamebar} | 
"{36AFE774-165A-49DD-AB11-1878CAB426DF}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.17763.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | 
"{394F0584-C2E2-4E6E-8AE9-D775D4358DE0}" = dir=out | name=windows_ie_ac_001 | 
"{3E0FC964-BB81-48C5-B623-96AFD4D504A2}" = dir=out | name=@{microsoft.windowscamera_2018.825.120.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowscamera/resources/appstorename} | 
"{4114AC8A-EE4F-4FFF-9000-B8D23FD1F808}" = dir=in | name=@{microsoft.windowscommunicationsapps_16005.11231.20192.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/appmanifest_outlookdesktop_displayname} | 
"{42F1F3D1-3F1F-45C9-BC2F-72A2440907DF}" = dir=out | name=@{microsoft.desktopappinstaller_1.0.30311.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.desktopappinstaller/resources/appdisplayname} | 
"{42FE6514-4E46-4EFD-92BC-FDCDAC43A09A}" = dir=in | name=@{microsoft.win32webviewhost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.win32webviewhost/resources/displayname} | 
"{45EC2C87-D837-4734-A7B2-3B9D872BF6DD}" = dir=in | name=microsoft sticky notes | 
"{47CBE536-2B8D-43E5-A651-7EF6A7D97F37}" = dir=out | name=@{microsoft.bingfinance_4.28.3242.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} | 
"{5077105D-5FF7-43DD-A656-407ED0451EDC}" = dir=out | name=@{microsoft.messaging_4.1901.10241.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.messaging/resources/appstorename} | 
"{510F4EF8-37FE-4B62-85D9-93EB8D64943F}" = dir=out | name=@{microsoft.yourphone_1.0.20453.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.yourphone/resources/appname} | 
"{583C46D0-665C-4579-923F-E7D0FFE0DBD6}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.17763.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | 
"{5F726B36-1400-4017-9D17-85DA19E1050C}" = dir=in | name=@{microsoft.yourphone_1.0.20453.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.yourphone/resources/appname} | 
"{5FE67EC3-FE30-40EF-8810-61484AFA959F}" = dir=out | name=@{microsoft.windowsstore_11811.1001.18.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} | 
"{658A7882-FB25-4C8E-BE86-8158477810CD}" = dir=out | name=@{microsoft.storepurchaseapp_11811.1001.18.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.storepurchaseapp/resources/displaytitle} | 
"{66C4F343-9045-4F00-A422-51D611FD4AEC}" = protocol=6 | dir=in | app=c:\program files\microsoft\skype for desktop\skype.exe | 
"{67D77465-CE4C-4EFE-910B-D70AD7CD4AE5}" = dir=in | name=@{microsoft.windowsstore_11811.1001.18.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} | 
"{67E5DCED-37A2-4762-A3F5-F12140C8769C}" = dir=out | name=@{microsoft.xboxgamingoverlay_2.26.28001.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.xboxgamingoverlay/resources/gamebar} | 
"{6C167E34-B2FB-4EA9-9DB5-4EA7F8BA53C6}" = dir=in | name=kodi | 
"{6D238767-A530-426B-BDF3-14B87802E849}" = dir=out | name=@{microsoft.windows.cortana_1.11.5.17763_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} | 
"{70067D1F-5019-43AD-A0BD-CA1A35265337}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} | 
"{712F56F1-835B-45E8-8301-B1F217EE056F}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | 
"{71CFC24F-ECDB-4FF4-B891-DC2DBE4B5FEF}" = dir=in | name=@{microsoft.microsoftedge_44.17763.1.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | 
"{75CC3503-226B-4261-A393-C6C81D4548F2}" = dir=out | name=@{microsoft.windows.secureassessmentbrowser_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.secureassessmentbrowser/resources/packagedisplayname} | 
"{7615E757-E1B2-4E37-AAEE-93385EB76B57}" = dir=in | name=skype | 
"{7AA165F7-242D-4C0F-8194-2E55EC285657}" = dir=out | name=microsoft sticky notes | 
"{887D27F8-0202-48C5-83CC-999A8A6595F5}" = dir=in | name=@{microsoft.zunemusic_10.19011.11311.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | 
"{8885494F-6B9D-4400-911C-45B15022CB76}" = dir=in | app=c:\program files\itunes\itunes.exe | 
"{96977796-1AD9-40B0-8AAE-565E180D469F}" = dir=out | name=@{microsoft.windows.peopleexperiencehost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.peopleexperiencehost/resources/pkgdisplayname} | 
"{971478B0-6BC6-44DB-B5F4-55E1B6441CF7}" = dir=out | name=@{microsoft.gethelp_10.1706.13371.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.gethelp/resources/appdisplayname} | 
"{98C80423-3953-4AA4-89AA-FD587CABA260}" = protocol=17 | dir=in | app=c:\program files\microsoft\skype for desktop\skype.exe | 
"{9D17B289-2BAC-4B2A-BD9C-8E1290784352}" = dir=out | name=@{microsoft.oneconnect_5.1902.361.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.oneconnect/oneconnectstrings/oneconnect/appstorename} | 
"{9F7486A3-B473-4141-9C7C-6CB125F490CC}" = dir=out | name=@{microsoft.zunemusic_10.19011.11311.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | 
"{A4022D16-92CF-4CC9-91C7-7013158E2F9B}" = dir=out | name=@{microsoft.windowsmaps_5.1812.10071.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowsmaps/resources/appstorename} | 
"{AA240FE6-F8B0-4BA7-9BE0-B3ED7A4C585E}" = dir=out | name=@{microsoft.windows.photos_2019.18114.17710.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} | 
"{AEB4618B-6455-4BB4-8767-ABAE8A5B6C20}" = dir=out | name=kodi | 
"{B0D72956-7753-4558-9A7E-16C1D76A6ABE}" = dir=out | name=@{microsoft.microsoftedge_44.17763.1.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | 
"{B3868436-87BC-4A34-8F1B-91AC6CA80291}" = dir=out | name=@{microsoft.windows.apprep.chxapp_1000.17763.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.apprep.chxapp/resources/displayname} | 
"{B5EE667D-F603-46F1-86E0-A16B6C2DEDDD}" = dir=out | name=@{microsoft.windows.sechealthui_10.0.17763.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.windows.sechealthui/resources/packagedisplayname} | 
"{B6B11E6B-7695-4B44-9B80-C027CE908CC0}" = dir=out | name=microsoft solitaire collection | 
"{BA832173-F728-4DED-A4F8-878AEDDB7817}" = dir=out | name=@{microsoft.ppiprojection_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} | 
"{BB91ECCD-7B3C-460A-8421-88F61F3AFACE}" = dir=in | name=@{microsoft.ppiprojection_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} | 
"{BCD023B7-87AC-4936-9F99-0F3585801667}" = dir=out | name=@{microsoft.windowscalculator_10.1812.10048.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowscalculator/resources/appstorename} | 
"{BF575D3F-9140-4750-81AD-A7F950B50AFA}" = dir=out | name=@{microsoft.accountscontrol_10.0.17763.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} | 
"{C06667CE-D489-406D-8852-E9D58D44FBE1}" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | 
"{C0A58834-24EE-4D48-BE41-4479616CFBB6}" = dir=out | name=@{microsoft.bingnews_4.28.3242.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithtagline} | 
"{C1E2B8A0-584E-4767-8A95-4164325E92F5}" = dir=out | name=xbox tcui | 
"{C247DED7-81EA-4507-BBAD-ADE0AF985E15}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.17763.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} | 
"{C29E2BF1-92FA-4E70-97AD-0753B5FA7F8C}" = dir=out | name=@{microsoft.zunevideo_10.19021.10411.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | 
"{C2A75908-2E45-40B6-A195-7C077B0D7B83}" = dir=out | name=@{microsoft.win32webviewhost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.win32webviewhost/resources/displayname} | 
"{C4A57CE5-E922-4CF4-80B3-A57C38197C70}" = dir=out | name=skype | 
"{C94F8DBD-DD82-40C3-87E0-70EE6C20CBFE}" = dir=in | name=@{microsoft.oneconnect_5.1902.361.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.oneconnect/oneconnectstrings/oneconnect/appstorename} | 
"{C9D953D8-2C9F-4709-9590-0A943F13A618}" = dir=out | name=@{microsoft.bingweather_4.28.10351.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} | 
"{CAFB65EB-C746-43A8-BA76-381B01B28B7D}" = dir=out | name=@{microsoft.windowscommunicationsapps_16005.11231.20192.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/appmanifest_outlookdesktop_displayname} | 
"{CD0C587F-DD0E-4C26-95ED-4EB8D2B2B6C9}" = dir=out | name=@{microsoft.windows.oobenetworkcaptiveportal_10.0.17763.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.windows.oobenetworkcaptiveportal/resources/appdisplayname} | 
"{CDE7CFF6-2F18-42CF-B9C1-269EB4C8D760}" = dir=in | app=c:\program files\common files\apple\apple application support\apsdaemon.exe | 
"{D1B1A0FF-D592-48D5-BF4A-5084ECCBF59A}" = dir=in | name=@{microsoft.messaging_4.1901.10241.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.messaging/resources/appstorename} | 
"{D874FB33-8140-4DD1-ACB0-F900E0EE7F86}" = dir=in | name=@{microsoft.desktopappinstaller_1.0.30311.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.desktopappinstaller/resources/appdisplayname} | 
"{DA6B463A-C5CB-43BB-AA50-2B3D271B8B94}" = dir=in | name=microsoft solitaire collection | 
"{DC8111BC-ECDD-4C9D-8F22-51284694D5A8}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | 
"{DF5122CC-4BA9-4741-A534-7B4F7974D5D2}" = dir=out | name=@{microsoft.windows.narratorquickstart_10.0.17763.1_neutral_neutral_8wekyb3d8bbwe?ms-resource://microsoft.windows.narratorquickstart/resources/appdisplayname} | 
"{E8A88052-87E9-4B6E-8D05-60C185BE18A7}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.17763.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} | 
"{E9CA8A56-F048-4FAA-A3DB-05014767CDA8}" = dir=out | name=@{microsoft.people_10.1812.10232.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.people/resources/appstorename} | 
"{EED6B05C-CD05-4DB0-A1A7-9A9138920963}" = dir=out | name=@{microsoft.getstarted_7.3.20251.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.getstarted/resources/appstorename} | 
"{F7573100-213F-4385-BE15-C51068831FCD}" = dir=out | name=shell input application | 
"{F84C678E-50CA-46B5-8940-71CA8F3629C1}" = dir=in | name=@{microsoft.zunevideo_10.19021.10411.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07502F61-F772-48D9-BF95-5A2DA1B756AC}" = PLEOMAX Web Camera
"{08208143-777D-4A06-BB54-71BF0AD1BB70}" = IPTInstaller
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.13
"{097A0B4C-1568-4735-8C3D-4CB265A115C8}" = Viber
"{09E218A5-2C33-4E05-905E-F622440C1F83}_is1" = NetClientOCX Version 6.4.1.0
"{1052502B-4C91-43F9-B160-AE39ED57C9F0}" = Elevated Installer
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{179324FF-7B16-4BA8-9836-055CAAEE4F08}" = SDFormatter
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F32180102F0}" = Java 8 Update 102
"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
"{29BAAF65-09E5-4F52-8D15-2FAF2E23A8DC}" = WinUSB Drivers ext
"{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}" = LG United Mobile Driver
"{2EDEB67C-6C6C-4767-9E90-B57BFEFD606F}" = Windows Device Recovery Tool 3.11.34101
"{30E6FC43-C31F-4968-9A06-AA38E3C3CF73}" = TomTom HOME
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{38057B80-AA2C-3359-A048-FC6A5F972997}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU
"{387843EE-375D-4E28-8436-F73E3E3D02D7}" = Maui META 3G ver 6.1316.1
"{3F0F5AB4-C9CE-4226-8393-E9CFF8369D9D}" = Emergency Download Driver
"{3FC90BF7-B316-40DF-819C-A06D70E5ED2E}" = Xperia Companion
"{4412F224-3849-4461-A3E9-DEEF8D252790}" = Visual Studio C++ 10.0 Runtime
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CEEE5D0-F905-4688-B9F9-ECC710507796}" = HTC Driver Installer
"{4DC59BF3-0D72-3CE8-BFEF-1E8FAF689EB0}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"{4fd02573-5f12-4ae4-8027-c63f8e1115af}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{5199DC5B-D596-4FAA-B464-51E57BCB7872}" = Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{537575D6-3B96-474C-BD8F-DFF667363DBD}" = Naviextras Toolbox Prerequesities
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{5A659BE5-849B-484E-A83B-DCB78407F3A4}" = Apple Application Support (32-Bit)
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{69BCE4AC-9572-3271-A2FB-9423BDA36A43}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{6E83C075-0805-4D11-B403-8BAC84374B81}" = Avira
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7209d085-ed88-4a08-beb2-c49db2b9e838}" = FFU Loader Driver 1.0.0
"{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}" = Smart Switch
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{7E5D2C4B-E9B9-46AA-B5A2-448B29007DDD}" = iTunes
"{80FA650C-6157-4959-9E2B-977CADCBFC3C}" = FFU Loader Driver 1.0.0
"{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}" = Skype Click to Call
"{88547073-C566-4895-9005-EBE98EA3F7C7}" = Samsung Kies3
"{8BE893D4-107C-4867-9B71-A3CF2C917C0E}" = Windows 10 Update and Privacy Settings
"{90160000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2016
"{90160000-0015-0407-0000-0000000FF1CE}" = Microsoft Access MUI (German) 2016
"{90160000-0016-0407-0000-0000000FF1CE}" = Microsoft Excel MUI (German) 2016
"{90160000-0018-0407-0000-0000000FF1CE}" = Microsoft PowerPoint MUI (German) 2016
"{90160000-0019-0407-0000-0000000FF1CE}" = Microsoft Publisher MUI (German) 2016
"{90160000-001A-0407-0000-0000000FF1CE}" = Microsoft Outlook MUI (German) 2016
"{90160000-001B-0407-0000-0000000FF1CE}" = Microsoft Word MUI (German) 2016
"{90160000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Korrekturhilfen 2016 – Deutsch
"{90160000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proofing Tools 2016 - English
"{90160000-001F-040C-0000-0000000FF1CE}" = Outils de vérification linguistique 2016 de Microsoft Office*- Français
"{90160000-001F-0410-0000-0000000FF1CE}" = Strumenti di correzione di Microsoft Office 2016 - Italiano
"{90160000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2016
"{90160000-0044-0407-0000-0000000FF1CE}" = Microsoft InfoPath MUI (German) 2016
"{90160000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2016
"{90160000-0090-0407-0000-0000000FF1CE}" = Microsoft DCF MUI (German) 2016
"{90160000-00A1-0407-0000-0000000FF1CE}" = Microsoft OneNote MUI (German) 2016
"{90160000-00BA-0407-0000-0000000FF1CE}" = Microsoft Groove MUI (German) 2016
"{90160000-00E1-0407-0000-0000000FF1CE}" = Microsoft Office OSM MUI (German) 2016
"{90160000-00E2-0407-0000-0000000FF1CE}" = Microsoft Office OSM UX MUI (German) 2016
"{90160000-012B-0407-0000-0000000FF1CE}" = Microsoft Skype for Business MUI (German) 2016
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile-Gerätecenter
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{9755918A-CDF8-4F1E-8453-6359CF1A330A}" = WinUsb CoInstallers
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D2A75FE-8CE1-4297-AEC1-A097D47BACE9}" = Lumia UEFI Blue Driver
"{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1" = Revo Uninstaller 2.0.5
"{A30EA700-5515-48F0-88B0-9E99DC356B88}" = Apple Software Update
"{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}" = 
"{A4A0B236-6046-4CAB-8177-1EAF61112C75}" = WinUSB Compatible ID Drivers
"{ABDE67C4-5876-4CDB-82A9-0CBACECC1C4A}" = Apple Mobile Device Support
"{AC76BA86-0804-1033-1959-001824311644}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1031-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Deutsch
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B4FDB1F4-F79D-4A6A-8CBF-CF638CF6BB63}" = QPST 2.7
"{B69D41C7-8878-4FD4-B0A1-C3F588C0F39B}" = TVCenter
"{BBF2AC74-720C-3CB3-8291-5E34039232FA}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215
"{BCC7CA85-E57F-452D-BB44-15A1CE018BD0}" = Garmin Express
"{bd8bd200-9a60-4969-b267-6b565f36e3da}" = Garmin Express
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{C0E08D8D-6076-4117-B644-2AF34F35B757}" = Universal Adb Driver
"{c4570e47-39e0-450b-a02c-d64965cbf0f0}" = Windows Device Recovery Tool 3.11.34101
"{C6457771-434B-4955-9944-A9BB1452772C}" = Quamotion iMobileDevice for Windows
"{C9A7E6A6-110D-4DBC-A8E2-F634613B5A8C}_is1" = Mobile Upgrade S Gotu2v5.2.1
"{CCF298AF-9CE1-4B26-B251-486E98A34789}" = Windows 7 USB/DVD Download Tool
"{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
"{D045DF86-7FF9-4CF2-919A-7BD172A43AAC}" = Xperia Companion Service
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = Samsung USB Driver for Mobile Phones
"{D168AAD0-6686-47C1-B599-CDD4888B9D1A}" = Bonjour
"{DA9C865D-6762-4931-8588-0B13B7A0796B}" = Garmin Express Tray
"{DE042823-C359-4B87-B66B-308057E8B6AF}" = Camtasia Studio 7
"{e2803110-78b3-4664-a479-3611a381656a}" = Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215
"{E64275CF-27C4-4BC9-8690-2BC2D1C2CF31}" = iCloud
"{E64F69D8-38FE-48B8-95AB-CC676FA636F1}" = ANT Drivers Installer x86
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile-Gerätecenter: Treiberupdate
"{efee6944-1231-492a-a157-93409130a098}" = Xperia Companion
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony PC Companion 2.10.303
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{fd422d82-916c-4aca-bc42-67b7eb9925c4}" = Avira
"{FE83F463-7E61-4B18-9FA0-B94B90A0B6B9}" = Nero Burning ROM 10
"{FF0EA481-42DB-A8AE-8356-48C09F7D953D}" = Windows IP Over USB
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"01D4AA89568B59E5941907D403E3B682EE413AB7" = Windows-Treiberpaket - Microsoft USBDevice  (02/19/2016 1.0.0.0)
"0FC9CED990518C1E946B3B95FD59B3B0785AD9B1" = Windows-Treiberpaket - Gionee Communication Equipment Co.,Ltd. (winusb) AndroidUsbDeviceClass  (04/21/2012 1.0.0000.00000)
"17511B846BE9E9EFA71436DFC880EAD7E4CA1A3A" = Windows-Treiberpaket - Gionee (gnusbnet) Net  (04/21/2012 1.0.0000.00000)
"1A5F38038762A5BC1BE1542877A474DFFDBF4A49" = Windows-Treiberpaket - Gionee Communication Equipment Co.,Ltd. (WinUSB) AndroidUsbDeviceClass  (04/21/2012 1.0.0000.00000)
"3E13462B4D2FE32916015DDA53F5A1DC2BAC9B11" = Windows Driver Package - SpreadTrum (sprd_enum) USB  (02/11/2012 2.4.0.27)
"450B7CBC371CAEC6A328083977AA7A09E7AE5D29" = Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass  (08/27/2012 7.0.0000.00001)
"4D6A4FCE2980678F71AC013D7A3BB39D141EAA26" = Windows-Treiberpaket - libusb-win32 (libusb0) libusb-win32 devices  (03/01/2015 1.2.6.0)
"5C5E744460BC89BBF2EB89161A4F60936B22A1B5" = Windows-Treiberpaket - Qualcomm Incorporated (qcusbser) Ports  (01/30/2012 2.0.9.1)
"625B1BC24FDCB32BB62A4A7EF2EB2A31E4A0DCC7" = Windows-Treiberpaket - Gionee Communication Equipment Co.,Ltd. (gnusbser) Modem  (04/21/2012 1.0.0000.00000)
"6C89719A41410334FF3B6B56B79EC975B9153A07" = Windows-Treiberpaket - libusb-win32 WorldCup_Device (01/18/2012 1.2.6.0)
"78FCD4595A8B18BF01F3375593207912EA704A85" = Windows-Treiberpaket - DriverCoding (DCCOMBUS) USB  (01/11/2012 1.0.1.0)
"7-Zip" = 7-Zip 15.12
"9EAF5C6317C122BCD76E5372013631B6C91D06FC" = Windows-Treiberpaket - Gionee Communication Equipment Co.,Ltd. (gnusbser) Ports  (04/21/2012 1.0.0000.00000)
"A4A3BF1EC3B48586178C2C6285019B2D9B0670C4" = Windows-Treiberpaket - Qualcomm Incorporated (qcusbser) Modem  (01/30/2012 2.0.9.1)
"Adobe Flash Player NPAPI" = Adobe Flash Player 32 NPAPI
"Adobe Flash Player PPAPI" = Adobe Flash Player 32 PPAPI
"Avira Antivirus" = Avira Antivirus
"CCleaner" = CCleaner
"Content Manager" = Content Manager
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.38
"D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2" = Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1)
"D89B66FA53594B71ACB68093FD8CE3B2E8959162" = Windows-Treiberpaket - Qualcomm (qcusbnet) Net  (01/30/2012 1.0.7.2)
"dreamboxEDIT" = dreamboxEDIT -- The one and only settings editor for your Dreambox
"ESET Online Scanner" = ESET Online Scanner v3
"F9D2A789F9CFF8CEC36B544F53877C80F1F73C46" = Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201)
"Flashtool" = Flashtool
"Google Chrome" = Google Chrome
"HaaliMkx" = Haali Media Splitter
"HashTab" = HashTab 5.0.0.19
"InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}" = Smart Switch
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}" = Samsung Kies3
"Made4U_is1" = Katalog/MadeForYou v1.6.118
"Microsoft Visual Studio 2010 Tools for Office Runtime (x86)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU" = Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU
"Mozilla Firefox 65.0.2 (x86 de)" = Mozilla Firefox 65.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MyDriveConnect" = TomTom MyDrive Connect 4.1.5.3181
"NetSurveillance" = NetSurveillance
"Notepad++" = Notepad++
"Office16.PROPLUS" = Microsoft Office Professional Plus 2016
"Opera 58.0.3135.79" = Opera Stable 58.0.3135.79
"plist Editor Pro" = plist Editor Pro 2.1.0
"PotPlayer" = Daum PotPlayer 1.6.54915
"Realterm" = Realterm 2.0.0.70_SignedWrapper
"Skype_is1" = Skype Version 8.40
"SLABCOMM&10C4&EA60" = Silicon Laboratories CP210x USB to UART Bridge (Driver Removal)
"Update Engine" = Sony Mobile Update Engine
"VLC media player" = VLC media player
"Winamp" = Winamp
"WinRAR archiver" = WinRAR 5.30 Beta 3 (32-Bit)
"WorldUnlock Codes Calculator" = WorldUnlock Codes Calculator
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3889012066-4205385009-3576731210-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{7de2db6a-6f4b-4b45-82b9-57d5d7f1c952}" = Viber
"58d94f3ce2c27db0" = Dell System Detect
"BitTorrent" = BitTorrent
"OneDriveSetup.exe" = Microsoft OneDrive
"uTorrent" = µTorrent
"WhatsApp" = WhatsApp
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 02.03.2019 05:37:34 | Computer Name = user-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Flashtool\FlashTool64.exe".
Die
 abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0""
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
 "sxstrace.exe".
 
Error - 02.03.2019 05:40:20 | Computer Name = user-PC | Source = SecurityCenter | ID = 17
Description = 
 
Error - 02.03.2019 06:16:33 | Computer Name = user-PC | Source = SecurityCenter | ID = 17
Description = 
 
Error - 02.03.2019 09:37:37 | Computer Name = user-PC | Source = SecurityCenter | ID = 17
Description = 
 
Error - 02.03.2019 13:39:45 | Computer Name = user-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: Avira.ServiceHost.exe, Version: 1.2.129.13789,
 Zeitstempel: 0x5c63f40d  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0,
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0115e6be  ID des fehlerhaften
 Prozesses: 0x16c  Startzeit der fehlerhaften Anwendung: 0x01d4cdf073d28324  Pfad der
 fehlerhaften Anwendung: C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe  Pfad
 des fehlerhaften Moduls: unknown  Berichtskennung: 3d14626e-1713-42a5-a8ce-a73099b8e982
Vollständiger
 Name des fehlerhaften Pakets: ?  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist: ?
 
Error - 03.03.2019 14:37:56 | Computer Name = user-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: Explorer.EXE, Version: 10.0.17763.107,
 Zeitstempel: 0x0d9046f5  Name des fehlerhaften Moduls: combase.dll, Version: 10.0.17763.253,
 Zeitstempel: 0xa3f81b2d  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000859ea  ID des fehlerhaften
 Prozesses: 0x1f58  Startzeit der fehlerhaften Anwendung: 0x01d4d198b31759e9  Pfad der
 fehlerhaften Anwendung: C:\WINDOWS\Explorer.EXE  Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\combase.dll
Berichtskennung:
 5543eb54-e426-46e4-ae3a-86a2382fe04f  Vollständiger Name des fehlerhaften Pakets:
 ?  Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ?
 
Error - 04.03.2019 16:40:00 | Computer Name = user-PC | Source = Application Hang | ID = 1002
Description = Das Programm LockApp.exe Version 10.0.17763.134 hat die Interaktion
 mit Windows beendet und wurde geschlossen. Überprüfen Sie den Problemverlauf in
 der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum
 Problem zu suchen.    Prozess-ID: fa8    Startzeit: 01d4d2614b0d6452    Beendigungszeit: 4294967295

Anwendungspfad:
 C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe    Bericht-ID: 2998b643-c426-4113-a3f9-387c8873a0ab

Vollständiger
 Name des fehlerhaften Pakets: Microsoft.LockApp_10.0.17763.1_neutral__cw5n1h2txyewy

Relative
 Anwendungs-ID des fehlerhaften Pakets: WindowsDefaultLockScreen    Absturztyp: Quiesce

 
Error - 06.03.2019 15:25:12 | Computer Name = user-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: CCleaner.exe, Version: 5.50.0.6911,
 Zeitstempel: 0x5bfebb34  Name des fehlerhaften Moduls: CCleaner.exe, Version: 5.50.0.6911,
 Zeitstempel: 0x5bfebb34  Ausnahmecode: 0xc0000005  Fehleroffset: 0x004ad57d  ID des fehlerhaften
 Prozesses: 0xa5c  Startzeit der fehlerhaften Anwendung: 0x01d4d45206ec9147  Pfad der
 fehlerhaften Anwendung: C:\Program Files\CCleaner\CCleaner.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files\CCleaner\CCleaner.exe  Berichtskennung: 0afd84eb-ead7-4cca-bd1c-dfa2fde0ed25
Vollständiger
 Name des fehlerhaften Pakets: ?  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist: ?
 
Error - 07.03.2019 09:03:50 | Computer Name = user-PC | Source = Application Hang | ID = 1002
Description = Das Programm OTL.exe Version 3.2.69.0 hat die Interaktion mit Windows
 beendet und wurde geschlossen. Überprüfen Sie den Problemverlauf in der Systemsteuerung
 "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID:
 2074    Startzeit: 01d4d4e569145746    Beendigungszeit: 4294967295    Anwendungspfad: C:\Users\bersem\Desktop\OTL.exe

Bericht-ID:
 ddc0ee02-e73f-4308-b8e5-bb77762ab538    Vollständiger Name des fehlerhaften Pakets:
 ?    Relative Anwendungs-ID des fehlerhaften Pakets: ?    Absturztyp: Top level window 
is idle  
 
Error - 07.03.2019 09:10:30 | Computer Name = user-PC | Source = Application Hang | ID = 1002
Description = Das Programm OTL.exe Version 3.2.69.0 hat die Interaktion mit Windows
 beendet und wurde geschlossen. Überprüfen Sie den Problemverlauf in der Systemsteuerung
 "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID:
 1fa0    Startzeit: 01d4d4e673d928ca    Beendigungszeit: 4294967295    Anwendungspfad: C:\Users\bersem\Desktop\OTL.exe

Bericht-ID:
 e1f3f14b-9705-457e-9d1b-3d67c7839a73    Vollständiger Name des fehlerhaften Pakets:
 ?    Relative Anwendungs-ID des fehlerhaften Pakets: ?    Absturztyp: Top level window 
is idle  
 
[ Parameters Events ]
OTL encountered an error while reading this event log. It may be corrupt.
[ State Events ]
OTL encountered an error while reading this event log. It may be corrupt.
Error - 06.03.2019 10:03:29 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 10:03:42 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 12:19:14 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 12:19:29 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 13:49:09 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 13:49:26 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 14:15:07 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 14:15:20 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 07.03.2019 04:37:28 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 07.03.2019 04:37:39 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
 
< End of report >
         
Extras

Code:
ATTFilter
OTL Extras logfile created on: 07.03.2019 14:10:52 - Run 2
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\bersem\Desktop
 Professional  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.17763.0)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
 
3,24 Gb Total Physical Memory | 2,22 Gb Available Physical Memory | 68,67% Memory free
7,23 Gb Paging File | 5,19 Gb Available in Paging File | 71,79% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152,41 Gb Total Space | 27,36 Gb Free Space | 17,95% Space Free | Partition Type: NTFS
 
Computer Name: USER-PC | User Name: bersem | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\WINDOWS\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\WINDOWS\winhlp32.exe (Microsoft Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office16\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [mplayerc.enqueue] -- "C:\Program Files\K-Lite Codec Pack\MPC-HC\mpc-hc.exe" /add "%1" (MPC-HC Team)
Directory [mplayerc.play] -- "C:\Program Files\K-Lite Codec Pack\MPC-HC\mpc-hc.exe" "%1" (MPC-HC Team)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Powershell] -- powershell.exe -noexit -command Set-Location '%V' (Microsoft Corporation)
Directory [UpdateEncryptionSettings] -- Reg Error: Key error.
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Feature]
"DisableAvCheck" = 1
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\CBP]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\DPA]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\SecurityApp]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Provider\SecurityApp\WebProtection]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{42CD32AD-AFD7-4D44-8FE6-23545A9B29AF}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\opera\58.0.3135.68\opera.exe | 
"{9717403B-B921-4943-8655-DF2886688336}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\opera\58.0.3135.79\opera.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08B9FFBE-0A0E-4E9C-B959-32B31524A467}" = dir=out | name=microsoft pay | 
"{0BA81A35-1937-4143-A6DB-F7AA7F7FCADE}" = dir=out | name=onenote | 
"{12A3AB2B-DA11-434F-B8E6-5112DD12B262}" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | 
"{171494DC-9986-46AC-B430-C45A03C7E78C}" = dir=in | name=onenote | 
"{194B80B4-B578-4B65-BFFC-37329E6FF132}" = dir=out | name=@{microsoft.windows.shellexperiencehost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.shellexperiencehost/resources/pkgdisplayname} | 
"{1D60A15E-2381-4289-9DFB-784A7B71A140}" = dir=in | name=@{microsoft.windows.photos_2019.18114.17710.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} | 
"{1E08EE6A-3408-4BB9-90E4-AFC283025E72}" = dir=out | name=xbox game bar | 
"{1FC2EF96-B96D-419F-B296-8B44EC842A44}" = dir=out | name=@{microsoft.lockapp_10.0.17763.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.lockapp/resources/appdisplayname} | 
"{214A75BA-C185-4052-956C-FB36BA6CE75B}" = dir=in | name=@{microsoft.windows.cortana_1.11.5.17763_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} | 
"{22C4A797-6520-458B-A7DD-F05F7206C53C}" = dir=out | name=@{microsoft.bingsports_4.28.3242.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/applicationtitlewithbranding} | 
"{26F5BC1D-5117-4A72-8B62-E41AE5B39D90}" = dir=in | name=@{microsoft.xboxgamingoverlay_2.26.28001.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.xboxgamingoverlay/resources/gamebar} | 
"{36AFE774-165A-49DD-AB11-1878CAB426DF}" = dir=in | name=@{microsoft.aad.brokerplugin_1000.17763.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | 
"{394F0584-C2E2-4E6E-8AE9-D775D4358DE0}" = dir=out | name=windows_ie_ac_001 | 
"{3E0FC964-BB81-48C5-B623-96AFD4D504A2}" = dir=out | name=@{microsoft.windowscamera_2018.825.120.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowscamera/resources/appstorename} | 
"{4114AC8A-EE4F-4FFF-9000-B8D23FD1F808}" = dir=in | name=@{microsoft.windowscommunicationsapps_16005.11231.20192.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/appmanifest_outlookdesktop_displayname} | 
"{42F1F3D1-3F1F-45C9-BC2F-72A2440907DF}" = dir=out | name=@{microsoft.desktopappinstaller_1.0.30311.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.desktopappinstaller/resources/appdisplayname} | 
"{42FE6514-4E46-4EFD-92BC-FDCDAC43A09A}" = dir=in | name=@{microsoft.win32webviewhost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.win32webviewhost/resources/displayname} | 
"{45EC2C87-D837-4734-A7B2-3B9D872BF6DD}" = dir=in | name=microsoft sticky notes | 
"{47CBE536-2B8D-43E5-A651-7EF6A7D97F37}" = dir=out | name=@{microsoft.bingfinance_4.28.3242.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/applicationtitlewithbranding} | 
"{5077105D-5FF7-43DD-A656-407ED0451EDC}" = dir=out | name=@{microsoft.messaging_4.1901.10241.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.messaging/resources/appstorename} | 
"{510F4EF8-37FE-4B62-85D9-93EB8D64943F}" = dir=out | name=@{microsoft.yourphone_1.0.20453.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.yourphone/resources/appname} | 
"{583C46D0-665C-4579-923F-E7D0FFE0DBD6}" = dir=out | name=@{microsoft.aad.brokerplugin_1000.17763.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.aad.brokerplugin/resources/packagedisplayname} | 
"{5F726B36-1400-4017-9D17-85DA19E1050C}" = dir=in | name=@{microsoft.yourphone_1.0.20453.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.yourphone/resources/appname} | 
"{5FE67EC3-FE30-40EF-8810-61484AFA959F}" = dir=out | name=@{microsoft.windowsstore_11811.1001.18.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} | 
"{658A7882-FB25-4C8E-BE86-8158477810CD}" = dir=out | name=@{microsoft.storepurchaseapp_11811.1001.18.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.storepurchaseapp/resources/displaytitle} | 
"{66C4F343-9045-4F00-A422-51D611FD4AEC}" = protocol=6 | dir=in | app=c:\program files\microsoft\skype for desktop\skype.exe | 
"{67D77465-CE4C-4EFE-910B-D70AD7CD4AE5}" = dir=in | name=@{microsoft.windowsstore_11811.1001.18.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowsstore/resources/storetitle} | 
"{67E5DCED-37A2-4762-A3F5-F12140C8769C}" = dir=out | name=@{microsoft.xboxgamingoverlay_2.26.28001.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.xboxgamingoverlay/resources/gamebar} | 
"{6C167E34-B2FB-4EA9-9DB5-4EA7F8BA53C6}" = dir=in | name=kodi | 
"{6D238767-A530-426B-BDF3-14B87802E849}" = dir=out | name=@{microsoft.windows.cortana_1.11.5.17763_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cortana/resources/packagedisplayname} | 
"{70067D1F-5019-43AD-A0BD-CA1A35265337}" = dir=out | name=@{microsoft.windows.contentdeliverymanager_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.contentdeliverymanager/resources/appdisplayname} | 
"{712F56F1-835B-45E8-8301-B1F217EE056F}" = dir=in | name=@{microsoft.windows.cloudexperiencehost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | 
"{71CFC24F-ECDB-4FF4-B891-DC2DBE4B5FEF}" = dir=in | name=@{microsoft.microsoftedge_44.17763.1.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | 
"{75CC3503-226B-4261-A393-C6C81D4548F2}" = dir=out | name=@{microsoft.windows.secureassessmentbrowser_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.secureassessmentbrowser/resources/packagedisplayname} | 
"{7615E757-E1B2-4E37-AAEE-93385EB76B57}" = dir=in | name=skype | 
"{7AA165F7-242D-4C0F-8194-2E55EC285657}" = dir=out | name=microsoft sticky notes | 
"{887D27F8-0202-48C5-83CC-999A8A6595F5}" = dir=in | name=@{microsoft.zunemusic_10.19011.11311.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | 
"{8885494F-6B9D-4400-911C-45B15022CB76}" = dir=in | app=c:\program files\itunes\itunes.exe | 
"{96977796-1AD9-40B0-8AAE-565E180D469F}" = dir=out | name=@{microsoft.windows.peopleexperiencehost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.peopleexperiencehost/resources/pkgdisplayname} | 
"{971478B0-6BC6-44DB-B5F4-55E1B6441CF7}" = dir=out | name=@{microsoft.gethelp_10.1706.13371.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.gethelp/resources/appdisplayname} | 
"{98C80423-3953-4AA4-89AA-FD587CABA260}" = protocol=17 | dir=in | app=c:\program files\microsoft\skype for desktop\skype.exe | 
"{9D17B289-2BAC-4B2A-BD9C-8E1290784352}" = dir=out | name=@{microsoft.oneconnect_5.1902.361.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.oneconnect/oneconnectstrings/oneconnect/appstorename} | 
"{9F7486A3-B473-4141-9C7C-6CB125F490CC}" = dir=out | name=@{microsoft.zunemusic_10.19011.11311.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | 
"{A4022D16-92CF-4CC9-91C7-7013158E2F9B}" = dir=out | name=@{microsoft.windowsmaps_5.1812.10071.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowsmaps/resources/appstorename} | 
"{AA240FE6-F8B0-4BA7-9BE0-B3ED7A4C585E}" = dir=out | name=@{microsoft.windows.photos_2019.18114.17710.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windows.photos/resources/appstorename} | 
"{AEB4618B-6455-4BB4-8767-ABAE8A5B6C20}" = dir=out | name=kodi | 
"{B0D72956-7753-4558-9A7E-16C1D76A6ABE}" = dir=out | name=@{microsoft.microsoftedge_44.17763.1.0_neutral__8wekyb3d8bbwe?ms-resource://microsoft.microsoftedge/resources/appname} | 
"{B3868436-87BC-4A34-8F1B-91AC6CA80291}" = dir=out | name=@{microsoft.windows.apprep.chxapp_1000.17763.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.apprep.chxapp/resources/displayname} | 
"{B5EE667D-F603-46F1-86E0-A16B6C2DEDDD}" = dir=out | name=@{microsoft.windows.sechealthui_10.0.17763.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.windows.sechealthui/resources/packagedisplayname} | 
"{B6B11E6B-7695-4B44-9B80-C027CE908CC0}" = dir=out | name=microsoft solitaire collection | 
"{BA832173-F728-4DED-A4F8-878AEDDB7817}" = dir=out | name=@{microsoft.ppiprojection_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} | 
"{BB91ECCD-7B3C-460A-8421-88F61F3AFACE}" = dir=in | name=@{microsoft.ppiprojection_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.ppiprojection/resources/productname} | 
"{BCD023B7-87AC-4936-9F99-0F3585801667}" = dir=out | name=@{microsoft.windowscalculator_10.1812.10048.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowscalculator/resources/appstorename} | 
"{BF575D3F-9140-4750-81AD-A7F950B50AFA}" = dir=out | name=@{microsoft.accountscontrol_10.0.17763.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.accountscontrol/resources/displayname} | 
"{C06667CE-D489-406D-8852-E9D58D44FBE1}" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe | 
"{C0A58834-24EE-4D48-BE41-4479616CFBB6}" = dir=out | name=@{microsoft.bingnews_4.28.3242.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/applicationtitlewithtagline} | 
"{C1E2B8A0-584E-4767-8A95-4164325E92F5}" = dir=out | name=xbox tcui | 
"{C247DED7-81EA-4507-BBAD-ADE0AF985E15}" = dir=out | name=@{microsoft.xboxgamecallableui_1000.17763.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.xboxgamecallableui/resources/pkgdisplayname} | 
"{C29E2BF1-92FA-4E70-97AD-0753B5FA7F8C}" = dir=out | name=@{microsoft.zunevideo_10.19021.10411.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | 
"{C2A75908-2E45-40B6-A195-7C077B0D7B83}" = dir=out | name=@{microsoft.win32webviewhost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://windows.win32webviewhost/resources/displayname} | 
"{C4A57CE5-E922-4CF4-80B3-A57C38197C70}" = dir=out | name=skype | 
"{C94F8DBD-DD82-40C3-87E0-70EE6C20CBFE}" = dir=in | name=@{microsoft.oneconnect_5.1902.361.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.oneconnect/oneconnectstrings/oneconnect/appstorename} | 
"{C9D953D8-2C9F-4709-9590-0A943F13A618}" = dir=out | name=@{microsoft.bingweather_4.28.10351.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/applicationtitlewithbranding} | 
"{CAFB65EB-C746-43A8-BA76-381B01B28B7D}" = dir=out | name=@{microsoft.windowscommunicationsapps_16005.11231.20192.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/hxoutlookintl/appmanifest_outlookdesktop_displayname} | 
"{CD0C587F-DD0E-4C26-95ED-4EB8D2B2B6C9}" = dir=out | name=@{microsoft.windows.oobenetworkcaptiveportal_10.0.17763.1_neutral__cw5n1h2txyewy?ms-resource://microsoft.windows.oobenetworkcaptiveportal/resources/appdisplayname} | 
"{CDE7CFF6-2F18-42CF-B9C1-269EB4C8D760}" = dir=in | app=c:\program files\common files\apple\apple application support\apsdaemon.exe | 
"{D1B1A0FF-D592-48D5-BF4A-5084ECCBF59A}" = dir=in | name=@{microsoft.messaging_4.1901.10241.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.messaging/resources/appstorename} | 
"{D874FB33-8140-4DD1-ACB0-F900E0EE7F86}" = dir=in | name=@{microsoft.desktopappinstaller_1.0.30311.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.desktopappinstaller/resources/appdisplayname} | 
"{DA6B463A-C5CB-43BB-AA50-2B3D271B8B94}" = dir=in | name=microsoft solitaire collection | 
"{DC8111BC-ECDD-4C9D-8F22-51284694D5A8}" = dir=out | name=@{microsoft.windows.cloudexperiencehost_10.0.17763.1_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.cloudexperiencehost/resources/appdescription} | 
"{DF5122CC-4BA9-4741-A534-7B4F7974D5D2}" = dir=out | name=@{microsoft.windows.narratorquickstart_10.0.17763.1_neutral_neutral_8wekyb3d8bbwe?ms-resource://microsoft.windows.narratorquickstart/resources/appdisplayname} | 
"{E8A88052-87E9-4B6E-8D05-60C185BE18A7}" = dir=out | name=@{microsoft.windows.parentalcontrols_1000.17763.1.0_neutral_neutral_cw5n1h2txyewy?ms-resource://microsoft.windows.parentalcontrols/resources/displayname} | 
"{E9CA8A56-F048-4FAA-A3DB-05014767CDA8}" = dir=out | name=@{microsoft.people_10.1812.10232.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.people/resources/appstorename} | 
"{EED6B05C-CD05-4DB0-A1A7-9A9138920963}" = dir=out | name=@{microsoft.getstarted_7.3.20251.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.getstarted/resources/appstorename} | 
"{F7573100-213F-4385-BE15-C51068831FCD}" = dir=out | name=shell input application | 
"{F84C678E-50CA-46B5-8940-71CA8F3629C1}" = dir=in | name=@{microsoft.zunevideo_10.19021.10411.0_x86__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07502F61-F772-48D9-BF95-5A2DA1B756AC}" = PLEOMAX Web Camera
"{08208143-777D-4A06-BB54-71BF0AD1BB70}" = IPTInstaller
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.13
"{097A0B4C-1568-4735-8C3D-4CB265A115C8}" = Viber
"{09E218A5-2C33-4E05-905E-F622440C1F83}_is1" = NetClientOCX Version 6.4.1.0
"{1052502B-4C91-43F9-B160-AE39ED57C9F0}" = Elevated Installer
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{179324FF-7B16-4BA8-9836-055CAAEE4F08}" = SDFormatter
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F32180102F0}" = Java 8 Update 102
"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
"{29BAAF65-09E5-4F52-8D15-2FAF2E23A8DC}" = WinUSB Drivers ext
"{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}" = LG United Mobile Driver
"{2EDEB67C-6C6C-4767-9E90-B57BFEFD606F}" = Windows Device Recovery Tool 3.11.34101
"{30E6FC43-C31F-4968-9A06-AA38E3C3CF73}" = TomTom HOME
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{38057B80-AA2C-3359-A048-FC6A5F972997}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU
"{387843EE-375D-4E28-8436-F73E3E3D02D7}" = Maui META 3G ver 6.1316.1
"{3F0F5AB4-C9CE-4226-8393-E9CFF8369D9D}" = Emergency Download Driver
"{3FC90BF7-B316-40DF-819C-A06D70E5ED2E}" = Xperia Companion
"{4412F224-3849-4461-A3E9-DEEF8D252790}" = Visual Studio C++ 10.0 Runtime
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CEEE5D0-F905-4688-B9F9-ECC710507796}" = HTC Driver Installer
"{4DC59BF3-0D72-3CE8-BFEF-1E8FAF689EB0}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"{4fd02573-5f12-4ae4-8027-c63f8e1115af}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{5199DC5B-D596-4FAA-B464-51E57BCB7872}" = Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{537575D6-3B96-474C-BD8F-DFF667363DBD}" = Naviextras Toolbox Prerequesities
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{5A659BE5-849B-484E-A83B-DCB78407F3A4}" = Apple Application Support (32-Bit)
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{69BCE4AC-9572-3271-A2FB-9423BDA36A43}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{6E83C075-0805-4D11-B403-8BAC84374B81}" = Avira
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7209d085-ed88-4a08-beb2-c49db2b9e838}" = FFU Loader Driver 1.0.0
"{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}" = Smart Switch
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{7E5D2C4B-E9B9-46AA-B5A2-448B29007DDD}" = iTunes
"{80FA650C-6157-4959-9E2B-977CADCBFC3C}" = FFU Loader Driver 1.0.0
"{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}" = Skype Click to Call
"{88547073-C566-4895-9005-EBE98EA3F7C7}" = Samsung Kies3
"{8BE893D4-107C-4867-9B71-A3CF2C917C0E}" = Windows 10 Update and Privacy Settings
"{90160000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2016
"{90160000-0015-0407-0000-0000000FF1CE}" = Microsoft Access MUI (German) 2016
"{90160000-0016-0407-0000-0000000FF1CE}" = Microsoft Excel MUI (German) 2016
"{90160000-0018-0407-0000-0000000FF1CE}" = Microsoft PowerPoint MUI (German) 2016
"{90160000-0019-0407-0000-0000000FF1CE}" = Microsoft Publisher MUI (German) 2016
"{90160000-001A-0407-0000-0000000FF1CE}" = Microsoft Outlook MUI (German) 2016
"{90160000-001B-0407-0000-0000000FF1CE}" = Microsoft Word MUI (German) 2016
"{90160000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Korrekturhilfen 2016 – Deutsch
"{90160000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proofing Tools 2016 - English
"{90160000-001F-040C-0000-0000000FF1CE}" = Outils de vérification linguistique 2016 de Microsoft Office*- Français
"{90160000-001F-0410-0000-0000000FF1CE}" = Strumenti di correzione di Microsoft Office 2016 - Italiano
"{90160000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2016
"{90160000-0044-0407-0000-0000000FF1CE}" = Microsoft InfoPath MUI (German) 2016
"{90160000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2016
"{90160000-0090-0407-0000-0000000FF1CE}" = Microsoft DCF MUI (German) 2016
"{90160000-00A1-0407-0000-0000000FF1CE}" = Microsoft OneNote MUI (German) 2016
"{90160000-00BA-0407-0000-0000000FF1CE}" = Microsoft Groove MUI (German) 2016
"{90160000-00E1-0407-0000-0000000FF1CE}" = Microsoft Office OSM MUI (German) 2016
"{90160000-00E2-0407-0000-0000000FF1CE}" = Microsoft Office OSM UX MUI (German) 2016
"{90160000-012B-0407-0000-0000000FF1CE}" = Microsoft Skype for Business MUI (German) 2016
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile-Gerätecenter
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{9755918A-CDF8-4F1E-8453-6359CF1A330A}" = WinUsb CoInstallers
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D2A75FE-8CE1-4297-AEC1-A097D47BACE9}" = Lumia UEFI Blue Driver
"{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1" = Revo Uninstaller 2.0.5
"{A30EA700-5515-48F0-88B0-9E99DC356B88}" = Apple Software Update
"{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}" = 
"{A4A0B236-6046-4CAB-8177-1EAF61112C75}" = WinUSB Compatible ID Drivers
"{ABDE67C4-5876-4CDB-82A9-0CBACECC1C4A}" = Apple Mobile Device Support
"{AC76BA86-0804-1033-1959-001824311644}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1031-7B44-AC0F074E4100}" = Adobe Acrobat Reader DC - Deutsch
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B4FDB1F4-F79D-4A6A-8CBF-CF638CF6BB63}" = QPST 2.7
"{B69D41C7-8878-4FD4-B0A1-C3F588C0F39B}" = TVCenter
"{BBF2AC74-720C-3CB3-8291-5E34039232FA}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215
"{BCC7CA85-E57F-452D-BB44-15A1CE018BD0}" = Garmin Express
"{bd8bd200-9a60-4969-b267-6b565f36e3da}" = Garmin Express
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{C0E08D8D-6076-4117-B644-2AF34F35B757}" = Universal Adb Driver
"{c4570e47-39e0-450b-a02c-d64965cbf0f0}" = Windows Device Recovery Tool 3.11.34101
"{C6457771-434B-4955-9944-A9BB1452772C}" = Quamotion iMobileDevice for Windows
"{C9A7E6A6-110D-4DBC-A8E2-F634613B5A8C}_is1" = Mobile Upgrade S Gotu2v5.2.1
"{CCF298AF-9CE1-4B26-B251-486E98A34789}" = Windows 7 USB/DVD Download Tool
"{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
"{D045DF86-7FF9-4CF2-919A-7BD172A43AAC}" = Xperia Companion Service
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = Samsung USB Driver for Mobile Phones
"{D168AAD0-6686-47C1-B599-CDD4888B9D1A}" = Bonjour
"{DA9C865D-6762-4931-8588-0B13B7A0796B}" = Garmin Express Tray
"{DE042823-C359-4B87-B66B-308057E8B6AF}" = Camtasia Studio 7
"{e2803110-78b3-4664-a479-3611a381656a}" = Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215
"{E64275CF-27C4-4BC9-8690-2BC2D1C2CF31}" = iCloud
"{E64F69D8-38FE-48B8-95AB-CC676FA636F1}" = ANT Drivers Installer x86
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile-Gerätecenter: Treiberupdate
"{efee6944-1231-492a-a157-93409130a098}" = Xperia Companion
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony PC Companion 2.10.303
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{fd422d82-916c-4aca-bc42-67b7eb9925c4}" = Avira
"{FE83F463-7E61-4B18-9FA0-B94B90A0B6B9}" = Nero Burning ROM 10
"{FF0EA481-42DB-A8AE-8356-48C09F7D953D}" = Windows IP Over USB
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"01D4AA89568B59E5941907D403E3B682EE413AB7" = Windows-Treiberpaket - Microsoft USBDevice  (02/19/2016 1.0.0.0)
"0FC9CED990518C1E946B3B95FD59B3B0785AD9B1" = Windows-Treiberpaket - Gionee Communication Equipment Co.,Ltd. (winusb) AndroidUsbDeviceClass  (04/21/2012 1.0.0000.00000)
"17511B846BE9E9EFA71436DFC880EAD7E4CA1A3A" = Windows-Treiberpaket - Gionee (gnusbnet) Net  (04/21/2012 1.0.0000.00000)
"1A5F38038762A5BC1BE1542877A474DFFDBF4A49" = Windows-Treiberpaket - Gionee Communication Equipment Co.,Ltd. (WinUSB) AndroidUsbDeviceClass  (04/21/2012 1.0.0000.00000)
"3E13462B4D2FE32916015DDA53F5A1DC2BAC9B11" = Windows Driver Package - SpreadTrum (sprd_enum) USB  (02/11/2012 2.4.0.27)
"450B7CBC371CAEC6A328083977AA7A09E7AE5D29" = Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass  (08/27/2012 7.0.0000.00001)
"4D6A4FCE2980678F71AC013D7A3BB39D141EAA26" = Windows-Treiberpaket - libusb-win32 (libusb0) libusb-win32 devices  (03/01/2015 1.2.6.0)
"5C5E744460BC89BBF2EB89161A4F60936B22A1B5" = Windows-Treiberpaket - Qualcomm Incorporated (qcusbser) Ports  (01/30/2012 2.0.9.1)
"625B1BC24FDCB32BB62A4A7EF2EB2A31E4A0DCC7" = Windows-Treiberpaket - Gionee Communication Equipment Co.,Ltd. (gnusbser) Modem  (04/21/2012 1.0.0000.00000)
"6C89719A41410334FF3B6B56B79EC975B9153A07" = Windows-Treiberpaket - libusb-win32 WorldCup_Device (01/18/2012 1.2.6.0)
"78FCD4595A8B18BF01F3375593207912EA704A85" = Windows-Treiberpaket - DriverCoding (DCCOMBUS) USB  (01/11/2012 1.0.1.0)
"7-Zip" = 7-Zip 15.12
"9EAF5C6317C122BCD76E5372013631B6C91D06FC" = Windows-Treiberpaket - Gionee Communication Equipment Co.,Ltd. (gnusbser) Ports  (04/21/2012 1.0.0000.00000)
"A4A3BF1EC3B48586178C2C6285019B2D9B0670C4" = Windows-Treiberpaket - Qualcomm Incorporated (qcusbser) Modem  (01/30/2012 2.0.9.1)
"Adobe Flash Player NPAPI" = Adobe Flash Player 32 NPAPI
"Adobe Flash Player PPAPI" = Adobe Flash Player 32 PPAPI
"Avira Antivirus" = Avira Antivirus
"CCleaner" = CCleaner
"Content Manager" = Content Manager
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.38
"D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2" = Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1)
"D89B66FA53594B71ACB68093FD8CE3B2E8959162" = Windows-Treiberpaket - Qualcomm (qcusbnet) Net  (01/30/2012 1.0.7.2)
"dreamboxEDIT" = dreamboxEDIT -- The one and only settings editor for your Dreambox
"ESET Online Scanner" = ESET Online Scanner v3
"F9D2A789F9CFF8CEC36B544F53877C80F1F73C46" = Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201)
"Flashtool" = Flashtool
"Google Chrome" = Google Chrome
"HaaliMkx" = Haali Media Splitter
"HashTab" = HashTab 5.0.0.19
"InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}" = Smart Switch
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}" = Samsung Kies3
"Made4U_is1" = Katalog/MadeForYou v1.6.118
"Microsoft Visual Studio 2010 Tools for Office Runtime (x86)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x86)
"Microsoft Visual Studio 2010 Tools for Office Runtime (x86) Language Pack - DEU" = Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x86) Language Pack - DEU
"Mozilla Firefox 65.0.2 (x86 de)" = Mozilla Firefox 65.0.2 (x86 de)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MyDriveConnect" = TomTom MyDrive Connect 4.1.5.3181
"NetSurveillance" = NetSurveillance
"Notepad++" = Notepad++
"Office16.PROPLUS" = Microsoft Office Professional Plus 2016
"Opera 58.0.3135.79" = Opera Stable 58.0.3135.79
"plist Editor Pro" = plist Editor Pro 2.1.0
"PotPlayer" = Daum PotPlayer 1.6.54915
"Realterm" = Realterm 2.0.0.70_SignedWrapper
"Skype_is1" = Skype Version 8.40
"SLABCOMM&10C4&EA60" = Silicon Laboratories CP210x USB to UART Bridge (Driver Removal)
"Update Engine" = Sony Mobile Update Engine
"VLC media player" = VLC media player
"Winamp" = Winamp
"WinRAR archiver" = WinRAR 5.30 Beta 3 (32-Bit)
"WorldUnlock Codes Calculator" = WorldUnlock Codes Calculator
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-3889012066-4205385009-3576731210-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{7de2db6a-6f4b-4b45-82b9-57d5d7f1c952}" = Viber
"58d94f3ce2c27db0" = Dell System Detect
"BitTorrent" = BitTorrent
"OneDriveSetup.exe" = Microsoft OneDrive
"uTorrent" = µTorrent
"WhatsApp" = WhatsApp
"Winamp Detect" = Winamp Erkennungs-Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 02.03.2019 05:37:34 | Computer Name = user-PC | Source = SideBySide | ID = 16842785
Description = Fehler beim Generieren des Aktivierungskontextes für "C:\Flashtool\FlashTool64.exe".
Die
 abhängige Assemblierung "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0""
 konnte nicht gefunden werden.  Verwenden Sie für eine detaillierte Diagnose das Programm
 "sxstrace.exe".
 
Error - 02.03.2019 05:40:20 | Computer Name = user-PC | Source = SecurityCenter | ID = 17
Description = 
 
Error - 02.03.2019 06:16:33 | Computer Name = user-PC | Source = SecurityCenter | ID = 17
Description = 
 
Error - 02.03.2019 09:37:37 | Computer Name = user-PC | Source = SecurityCenter | ID = 17
Description = 
 
Error - 02.03.2019 13:39:45 | Computer Name = user-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: Avira.ServiceHost.exe, Version: 1.2.129.13789,
 Zeitstempel: 0x5c63f40d  Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0,
 Zeitstempel: 0x00000000  Ausnahmecode: 0xc0000005  Fehleroffset: 0x0115e6be  ID des fehlerhaften
 Prozesses: 0x16c  Startzeit der fehlerhaften Anwendung: 0x01d4cdf073d28324  Pfad der
 fehlerhaften Anwendung: C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe  Pfad
 des fehlerhaften Moduls: unknown  Berichtskennung: 3d14626e-1713-42a5-a8ce-a73099b8e982
Vollständiger
 Name des fehlerhaften Pakets: ?  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist: ?
 
Error - 03.03.2019 14:37:56 | Computer Name = user-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: Explorer.EXE, Version: 10.0.17763.107,
 Zeitstempel: 0x0d9046f5  Name des fehlerhaften Moduls: combase.dll, Version: 10.0.17763.253,
 Zeitstempel: 0xa3f81b2d  Ausnahmecode: 0xc0000005  Fehleroffset: 0x000859ea  ID des fehlerhaften
 Prozesses: 0x1f58  Startzeit der fehlerhaften Anwendung: 0x01d4d198b31759e9  Pfad der
 fehlerhaften Anwendung: C:\WINDOWS\Explorer.EXE  Pfad des fehlerhaften Moduls: C:\WINDOWS\System32\combase.dll
Berichtskennung:
 5543eb54-e426-46e4-ae3a-86a2382fe04f  Vollständiger Name des fehlerhaften Pakets:
 ?  Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ?
 
Error - 04.03.2019 16:40:00 | Computer Name = user-PC | Source = Application Hang | ID = 1002
Description = Das Programm LockApp.exe Version 10.0.17763.134 hat die Interaktion
 mit Windows beendet und wurde geschlossen. Überprüfen Sie den Problemverlauf in
 der Systemsteuerung "Sicherheit und Wartung", um nach weiteren Informationen zum
 Problem zu suchen.    Prozess-ID: fa8    Startzeit: 01d4d2614b0d6452    Beendigungszeit: 4294967295

Anwendungspfad:
 C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe    Bericht-ID: 2998b643-c426-4113-a3f9-387c8873a0ab

Vollständiger
 Name des fehlerhaften Pakets: Microsoft.LockApp_10.0.17763.1_neutral__cw5n1h2txyewy

Relative
 Anwendungs-ID des fehlerhaften Pakets: WindowsDefaultLockScreen    Absturztyp: Quiesce

 
Error - 06.03.2019 15:25:12 | Computer Name = user-PC | Source = Application Error | ID = 1000
Description = Name der fehlerhaften Anwendung: CCleaner.exe, Version: 5.50.0.6911,
 Zeitstempel: 0x5bfebb34  Name des fehlerhaften Moduls: CCleaner.exe, Version: 5.50.0.6911,
 Zeitstempel: 0x5bfebb34  Ausnahmecode: 0xc0000005  Fehleroffset: 0x004ad57d  ID des fehlerhaften
 Prozesses: 0xa5c  Startzeit der fehlerhaften Anwendung: 0x01d4d45206ec9147  Pfad der
 fehlerhaften Anwendung: C:\Program Files\CCleaner\CCleaner.exe  Pfad des fehlerhaften
 Moduls: C:\Program Files\CCleaner\CCleaner.exe  Berichtskennung: 0afd84eb-ead7-4cca-bd1c-dfa2fde0ed25
Vollständiger
 Name des fehlerhaften Pakets: ?  Anwendungs-ID, die relativ zum fehlerhaften Paket
 ist: ?
 
Error - 07.03.2019 09:03:50 | Computer Name = user-PC | Source = Application Hang | ID = 1002
Description = Das Programm OTL.exe Version 3.2.69.0 hat die Interaktion mit Windows
 beendet und wurde geschlossen. Überprüfen Sie den Problemverlauf in der Systemsteuerung
 "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID:
 2074    Startzeit: 01d4d4e569145746    Beendigungszeit: 4294967295    Anwendungspfad: C:\Users\bersem\Desktop\OTL.exe

Bericht-ID:
 ddc0ee02-e73f-4308-b8e5-bb77762ab538    Vollständiger Name des fehlerhaften Pakets:
 ?    Relative Anwendungs-ID des fehlerhaften Pakets: ?    Absturztyp: Top level window 
is idle  
 
Error - 07.03.2019 09:10:30 | Computer Name = user-PC | Source = Application Hang | ID = 1002
Description = Das Programm OTL.exe Version 3.2.69.0 hat die Interaktion mit Windows
 beendet und wurde geschlossen. Überprüfen Sie den Problemverlauf in der Systemsteuerung
 "Sicherheit und Wartung", um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID:
 1fa0    Startzeit: 01d4d4e673d928ca    Beendigungszeit: 4294967295    Anwendungspfad: C:\Users\bersem\Desktop\OTL.exe

Bericht-ID:
 e1f3f14b-9705-457e-9d1b-3d67c7839a73    Vollständiger Name des fehlerhaften Pakets:
 ?    Relative Anwendungs-ID des fehlerhaften Pakets: ?    Absturztyp: Top level window 
is idle  
 
[ Parameters Events ]
OTL encountered an error while reading this event log. It may be corrupt.
[ State Events ]
OTL encountered an error while reading this event log. It may be corrupt.
Error - 06.03.2019 10:03:29 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 10:03:42 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 12:19:14 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 12:19:29 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 13:49:09 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 13:49:26 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 14:15:07 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 06.03.2019 14:15:20 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 07.03.2019 04:37:28 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
Error - 07.03.2019 04:37:39 | Computer Name = user-PC | Source = DCOM | ID = 10016
Description = 
 
 
< End of report >
         

 

Themen zu trojaner eingefangen?
absturz, adobe, antivirus, browser, error, excel, explorer, fehler, firefox, firewall, flash player, format, google, lockapp.exe, logfile, mozilla, opera, registry, revo uninstaller, rundll, security, sicherheit, software, temp, trojaner, usb, windows




Ähnliche Themen: trojaner eingefangen?


  1. Trojaner: Win32/Trojan Downloader.Nymaim.BA Trojaner eingefangen; mit der Bitte um Hilfe:
    Log-Analyse und Auswertung - 24.01.2017 (55)
  2. Trojaner eingefangen?
    Plagegeister aller Art und deren Bekämpfung - 28.02.2016 (76)
  3. Trojaner eingefangen?
    Log-Analyse und Auswertung - 03.03.2014 (9)
  4. GVU-Trojaner eingefangen ...
    Log-Analyse und Auswertung - 20.06.2013 (16)
  5. GVU Trojaner eingefangen
    Plagegeister aller Art und deren Bekämpfung - 14.06.2013 (9)
  6. GVU Trojaner eingefangen was nun tun.
    Plagegeister aller Art und deren Bekämpfung - 08.06.2013 (21)
  7. Viren eingefangen (JAVA/dldr.lamar.TP), auch Trojaner (Polizei.Trojaner) gefunden
    Log-Analyse und Auswertung - 07.05.2013 (15)
  8. GVU-Trojaner eingefangen
    Log-Analyse und Auswertung - 11.03.2013 (23)
  9. Trojaner eingefangen
    Plagegeister aller Art und deren Bekämpfung - 23.10.2012 (19)
  10. GVU - Trojaner eingefangen
    Plagegeister aller Art und deren Bekämpfung - 21.07.2012 (14)
  11. GVU-Trojaner eingefangen
    Plagegeister aller Art und deren Bekämpfung - 12.07.2012 (19)
  12. Trojaner (u.A. msa.exe) eingefangen :(
    Log-Analyse und Auswertung - 22.02.2010 (7)
  13. 20 Tan Trojaner eingefangen
    Log-Analyse und Auswertung - 04.09.2009 (8)
  14. Trojaner eingefangen?
    Log-Analyse und Auswertung - 03.03.2009 (0)
  15. Trojaner eingefangen
    Plagegeister aller Art und deren Bekämpfung - 22.04.2008 (34)
  16. Trojaner eingefangen
    Antiviren-, Firewall- und andere Schutzprogramme - 14.01.2006 (1)
  17. trojaner eingefangen
    Log-Analyse und Auswertung - 12.02.2005 (4)

Zum Thema trojaner eingefangen? - Hallo allerseits, bin neu hier. Habe das mulmige Gefühl dass jemand sich Zugriff auf mein PC verschafft hat. Hab vor kurzem ein OTL-Scan als Benutzer gemacht den ich hier poste - trojaner eingefangen?...
Archiv
Du betrachtest: trojaner eingefangen? auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.