Silvia07 | 13.03.2015 17:00 | Fehlermeldung: ungültiges Bild (C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL) Hallo zusammen,
habe seit gestern dasselbe Problem wie so einige hier im Forum. Beim Hochfahren meines Laptops erhielt ich mehrfach folgende Meldung:
C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL ist entweder nicht für die Ausführung unter Windows vorgesehen oder enthält einen Fehler. Installieren Sie das Programm mit den Originalinstallationsmedien erneut, oder wenden Sie sich an den Systemadministrator oder Softwarelieferanten, Um Unterstützung zu erhalten.
Da ich nicht Zeit hatte, mich direkt drum zu kümmern, habe ich den Laptop zunächst zugeklappt und damit in Standby versetzt. Im Anschluss daran ist der Computer nicht mehr hochgefahren, ich erhielt lediglich einen schwarzen Hintergrund mit der obigen Fehlermeldung.
Ich habe danach den Laptop im abgesicherten Modus hochgefahren, Anti-Malware installiert und 2 x laufen lassen.
Herzlichen Dank im Voraus!
Hier die Logs: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 12.03.2015
Scan Time: 22:26:17
Logfile: mbam_20150312.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2014.11.20.06
Rootkit Database: v2014.11.18.01
License: Trial
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: SILVI
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 386520
Time Elapsed: 19 min, 39 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 20
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6C434537-053E-486D-B62A-160059D9D456}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6C434537-053E-486D-B62A-160059D9D456}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\CLASSES\GenericAskToolbar.ToolbarWnd.1, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\CLASSES\GenericAskToolbar.ToolbarWnd, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GenericAskToolbar.ToolbarWnd, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{D4027C7F-154A-4066-A1AD-4243D8127440}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GenericAskToolbar.ToolbarWnd.1, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKU\S-1-5-21-1716138007-1145930210-586402359-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D4027C7F-154A-4066-A1AD-4243D8127440}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKU\S-1-5-21-1716138007-1145930210-586402359-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D4027C7F-154A-4066-A1AD-4243D8127440}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT, Quarantined, [57af033ba9d3979f6878153d7e85c43c],
PUP.Optional.ConduitSearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, Quarantined, [0105f747215b96a022250485ae56956b],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1716138007-1145930210-586402359-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, [7e88b38baad2de580741c1a4c2419a66],
Registry Values: 3
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{D4027C7F-154A-4066-A1AD-4243D8127440}, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.FrostwireTB.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{D4027C7F-154A-4066-A1AD-4243D8127440}, Quarantined, [da2ce856d1abbc7a09549563f80a827e],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT|InstallDir, C:\PROGRA~2\SearchProtect, Quarantined, [57af033ba9d3979f6878153d7e85c43c]
Registry Data: 3
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL , Good: (), Bad: (C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC32LO~1.DLL),Replaced,[6d9975c95e1ee05638fba862b74cc53b]
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC64LO~1.DLL , Good: (), Bad: (C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\VC64LO~1.DLL),Replaced,[6d9975c95e1ee05638fba862b74cc53b]
PUP.Optional.Trovi.A, HKU\S-1-5-21-1716138007-1145930210-586402359-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.trovi.com/?gd=&ctid=CT3315513&octid=EB_ORIGINAL_CTID&ISID=M68FFED19-A269-4062-A268-ADF2B1CBD412&SearchSource=55&CUI=&UM=5&UP=SP76A5A5A3-0718-44AA-9059-9B257659C0D6&SSPV=Banner3D213B_sp_ie, Good: (www.google.com), Bad: (hxxp://www.trovi.com/?gd=&ctid=CT3315513&octid=EB_ORIGINAL_CTID&ISID=M68FFED19-A269-4062-A268-ADF2B1CBD412&SearchSource=55&CUI=&UM=5&UP=SP76A5A5A3-0718-44AA-9059-9B257659C0D6&SSPV=Banner3D213B_sp_ie),Replaced,[60a6ef4f89f3a294363667dd14f1ea16]
Folders: 13
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, Quarantined, [d333b38b047841f52c06bd4dc83bba46],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, Quarantined, [6d9975c95e1ee05638fba862b74cc53b],
PUP.Optional.SearchProtect.A, C:\Users\Gast\AppData\Local\SearchProtect, Quarantined, [43c3dc62f7858caa3bec8a9455ae60a0],
PUP.Optional.SearchProtect.A, C:\Users\Gast\AppData\Local\SearchProtect\SearchProtect, Quarantined, [43c3dc62f7858caa3bec8a9455ae60a0],
PUP.Optional.SearchProtect.A, C:\Users\Gast\AppData\Local\SearchProtect\SearchProtect\rep, Quarantined, [43c3dc62f7858caa3bec8a9455ae60a0],
PUP.Optional.SearchProtect.A, C:\Users\Gast\AppData\Local\SearchProtect\SearchProtect\STG, Quarantined, [43c3dc62f7858caa3bec8a9455ae60a0],
PUP.Optional.SearchProtect.A, C:\Users\Gast\AppData\Local\SearchProtect\UI, Quarantined, [43c3dc62f7858caa3bec8a9455ae60a0],
PUP.Optional.SearchProtect.A, C:\Users\Gast\AppData\Local\SearchProtect\UI\rep, Quarantined, [43c3dc62f7858caa3bec8a9455ae60a0],
PUP.Optional.SearchProtect.A, C:\Users\SILVI\AppData\Local\SearchProtect, Quarantined, [2adccb731d5f1c1af7302ef0659ed729],
PUP.Optional.SearchProtect.A, C:\Users\SILVI\AppData\Local\SearchProtect\SearchProtect, Quarantined, [2adccb731d5f1c1af7302ef0659ed729],
PUP.Optional.SearchProtect.A, C:\Users\SILVI\AppData\Local\SearchProtect\SearchProtect\rep, Quarantined, [2adccb731d5f1c1af7302ef0659ed729],
PUP.Optional.SearchProtect.A, C:\Users\SILVI\AppData\Local\SearchProtect\UI, Quarantined, [2adccb731d5f1c1af7302ef0659ed729],
PUP.Optional.SearchProtect.A, C:\Users\SILVI\AppData\Local\SearchProtect\UI\rep, Quarantined, [2adccb731d5f1c1af7302ef0659ed729],
Files: 40
PUP.Optional.FrostwireTB.A, C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll, Quarantined, [47bf08369fdd9a9cbba2e513c83a7f81],
PUP.Optional.SearchProtect.A, C:\Users\SILVI\AppData\Local\Temp\SPSetup.exe, Quarantined, [6c9aa6985f1daa8c1ed8525452af46ba],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsaB96C.exe, Quarantined, [8c7a5fdf2e4e092dc711702cb34e6997],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsc55F0.exe, Quarantined, [ae581a24b9c3ca6c22b67923758c27d9],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsc7A81.exe, Quarantined, [4fb7e9559be1a88ec0183a6212ef1ee2],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsc959E.exe, Quarantined, [6d99a797ceaed75f77615745bd44a759],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsh42CE.exe, Quarantined, [8f7782bcc1bb0432ffd9d9c3629f22de],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsh5120.exe, Quarantined, [eb1bd866cfad67cfdcfc039903fec13f],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsh6B64.exe, Quarantined, [b74fbb835a2285b13d9b3c60d9287e82],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsr9A3F.exe, Quarantined, [fe08e45a245832045682c3d9e61bf808],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsrB33B.exe, Quarantined, [6d995be38bf13df97068c9d30ff221df],
PUP.Optional.Conduit.A, C:\Windows\Temp\nss257E.exe, Quarantined, [887e9ca2e09c1f173b9d7725d52cdc24],
PUP.Optional.Conduit.A, C:\Windows\Temp\nss41C5.exe, Quarantined, [47bfd46a205cb97d8e4ac4d815ecf010],
PUP.Optional.Conduit.A, C:\Windows\Temp\nssE361.exe, Quarantined, [a6609da1c6b66bcbd206336978892ed2],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsx2724.exe, Quarantined, [32d48cb20e6e86b070681d7f857c34cc],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsx4CAD.exe, Quarantined, [c64045f915672e08dcfca0fc57aa956b],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsxD57C.exe, Quarantined, [35d11628255772c4a632019bc73aff01],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsz318F.exe, Quarantined, [4cba93ab56267eb80dcbcad250b111ef],
PUP.Optional.Conduit.A, C:\Windows\Temp\nshE370.exe, Quarantined, [93732b137408f145d305445858a9c23e],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsi1DE0.exe, Quarantined, [60a6ed51c7b5c2748f498418d62b33cd],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsm2ED0.exe, Quarantined, [46c0102e8cf0c373c90fb8e425dcce32],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsmB982.exe, Quarantined, [3ec81b230b71f04625b33a62ff021ee2],
PUP.Optional.Conduit.A, C:\Windows\Temp\nso4D59.exe, Quarantined, [a264b9851963d66026b22c7019e8c33d],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsq1449.exe, Quarantined, [9d691d21a1dbfd397e5af7a5728f35cb],
PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, Quarantined, [38ce90ae9ae294a2df85654bbd47b050],
PUP.Optional.ConduitSearchProtect, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, Quarantined, [0105f747215b96a022250485ae56956b],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, Quarantined, [d333b38b047841f52c06bd4dc83bba46],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, Quarantined, [6d9975c95e1ee05638fba862b74cc53b],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\RN32.dll, Quarantined, [6d9975c95e1ee05638fba862b74cc53b],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPtool64.exe, Quarantined, [6d9975c95e1ee05638fba862b74cc53b],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32.dll, Quarantined, [6d9975c95e1ee05638fba862b74cc53b],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll, Quarantined, [6d9975c95e1ee05638fba862b74cc53b],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64.dll, Quarantined, [6d9975c95e1ee05638fba862b74cc53b],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll, Quarantined, [6d9975c95e1ee05638fba862b74cc53b],
PUP.Optional.SearchProtect.A, C:\Users\Gast\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, Quarantined, [43c3dc62f7858caa3bec8a9455ae60a0],
PUP.Optional.SearchProtect.A, C:\Users\Gast\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, Quarantined, [43c3dc62f7858caa3bec8a9455ae60a0],
PUP.Optional.SearchProtect.A, C:\Users\Gast\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, Quarantined, [43c3dc62f7858caa3bec8a9455ae60a0],
PUP.Optional.SearchProtect.A, C:\Users\SILVI\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, Quarantined, [2adccb731d5f1c1af7302ef0659ed729],
PUP.Optional.SearchProtect.A, C:\Users\SILVI\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, Quarantined, [2adccb731d5f1c1af7302ef0659ed729],
PUP.Optional.SearchProtect.A, C:\Users\SILVI\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, Quarantined, [2adccb731d5f1c1af7302ef0659ed729],
Physical Sectors: 0
(No malicious items detected)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 12.03.2015
Scan Time: 22:54:44
Logfile: mbam_20150312_scnd run.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.03.12.06
Rootkit Database: v2015.02.25.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: SILVI
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 414979
Time Elapsed: 28 min, 5 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end) |