System32 win jpg.jpg

yas66 -  
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   -
Bonjour,
pourriez vous m'aider à resoudre ce probléme de démarrge de ma machine!
a chaque démarrage j'ai un message d'érreur sur system32 win jpg.jpg!
et j'ai des difficulté à exploiter mon word!
Merci d"avance
Yas
Configuration: Windows XP / Internet Explorer 8.0

20 réponses

  1. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Bonjour,

    --> Télécharge UsbFix (par El Desaparecido & C_XX) sur ton Bureau.

    --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.

    --> Double-clique sur le programme UsbFix situé sur ton Bureau.

    --> Choisis l'option 1 (Recherche).

    --> Laisse travailler l'outil.

    --> Poste le rapport UsbFix.txt.

    Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).

    "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
    1
  2. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.

    --> Double-clique sur UsbFix présent sur ton Bureau.

    --> Choisis l'option 2 (Suppression).

    --> Ton Bureau disparaîtra et le PC redémarrera.

    --> Au redémarrage, UsbFix scannera ton PC, laisse travailler l'outil.

    --> Ensuite, poste le rapport UsbFix.txt qui apparaîtra avec le Bureau.

    Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
    1
  3. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    "Mais je n'ai plus de bureau et le windows ne semble plus exploitable???"

    --> Comment ça ?
    1
  4. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Même si tu n'as plus de barre des tâches ni d'icône, tu peux installer un programme et le lancer ?
    1
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. yas-- Messages postés 12 Date d'inscription   Statut Membre Dernière intervention  
     
    salut Destrio5
    Voila j'ai fait comme tu m"as conseillé ( merci pour ta precieuse aide!!! :)) )
    et voila la rapport txt

    C:\DOCUME~1\client\APPLIC~1\Bifrost
    C:\Program Files XP\Bifrost
    C:\autorun.inf
    C:\winfile.jpg
    D:\autorun.inf
    D:\winfile.jpg
    F:\autorun.inf -> fichier appelé : "F:\.\Recycler\svchost.exe" ( Présent ! )
    F:\autorun.inf
    F:\.\Recycler\svchost.exe
    F:\RECYCLER\svchost.exe
    G:\autorun.inf -> fichier appelé : "G:\explorer.exe" ( Présent ! )
    G:\autorun.inf
    G:\39lpji.com
    G:\explorer.exe
    G:\winfile.jpg
    G:\explorer.exe
    G:\Documents.exe

    ################## | Registre |

    [HKCU\SOFTWARE\Bifrost]
    [HKLM\SOFTWARE\Bifrost]
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON"
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "regdiit"
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwtsn32.exe]
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwwinxp.exe]
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe]
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe]
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe]
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe]
    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
    [HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] "DisableSR"

    ################## | Mountpoints2 |

    HKCU\..\..\Explorer\MountPoints2\{2f68f2c6-ae7a-11de-b69d-001a73a8ac23}
    Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL explorer.exe
    Shell\Explore\command =G:\explorer.exe
    Shell\Open\command =G:\explorer.exe

    HKCU\..\..\Explorer\MountPoints2\{acf85722-9d3b-11de-b699-001a73a8ac23}
    shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\Recycler\svchost.exe
    shell\open\command =F:\.\Recycler\svchost.exe

    ################## | Vaccin |

    ################## | ! Fin du rapport # UsbFix V6.099 ! |

    Que cela veut il dire
    Yas 66 :((( !!!????
    0
  7. yas-- Messages postés 12 Date d'inscription   Statut Membre Dernière intervention  
     
    Mais je n'ai plus de bureau et le windows ne semble plus exploitable???
    Que faire
    merci de m'aider plutot inquiete?
    ############################## | UsbFix V6.099 |

    User : client (Administrateurs) # CLIENT-693380C0
    Update on 11/03/2010 by El Desaparecido , C_XX & Chimay8
    Start at: 14:07:16 | 12/03/2010
    Website : http://pagesperso-orange.fr/NosTools/index.html
    Contact : FindyKill.Contact@gmail.com

    Intel(R) Core(TM)2 Duo CPU T5470 @ 1.60GHz
    Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
    Internet Explorer 8.0.6001.18702
    Windows Firewall Status : Disabled

    C:\ -> Disque fixe local # 65,03 Go (27,65 Go free) # NTFS
    D:\ -> Disque fixe local # 7,94 Go (6,21 Go free) [HP_RECOVERY] # NTFS
    E:\ -> Disque CD-ROM
    F:\ -> Disque amovible # 55,89 Go (42,51 Go free) [PRESTIGIO] # NTFS
    G:\ -> Disque amovible # 1,81 Go (1,33 Go free) [YASMUSB] # FAT32

    ################## | Elements infectieux |

    Supprimé ! C:\WINDOWS\BackUp\autorun.inf
    Supprimé ! C:\WINDOWS\BackUp\explorer.exe
    Supprimé ! C:\WINDOWS\System32\winjpg.jpg
    Supprimé ! C:\WINDOWS\System32\winxp.exe
    Supprimé ! C:\DOCUME~1\client\APPLIC~1\addons.dat
    Supprimé ! C:\DOCUME~1\client\APPLIC~1\Bifrost\logg.dat
    Supprimé ! C:\DOCUME~1\client\APPLIC~1\Bifrost\Server.exe
    Supprimé ! C:\DOCUME~1\client\APPLIC~1\Bifrost
    Supprimé ! C:\Program Files XP\Bifrost
    Supprimé ! C:\autorun.inf
    Supprimé ! C:\explorer.exe
    Supprimé ! C:\winfile.jpg
    Supprimé ! C:\Recycler\S-1-5-21-1757981266-854245398-1417001333-1003
    Supprimé ! D:\autorun.inf
    Supprimé ! D:\winfile.jpg
    Supprimé ! D:\Recycler\S-1-5-21-1757981266-854245398-1417001333-1003
    F:\autorun.inf -> fichier appelé : "F:\explorer.exe" ( Présent ! )
    Supprimé ! F:\explorer.exe
    Supprimé ! F:\autorun.inf
    Supprimé ! F:\.\Recycler\svchost.exe
    G:\autorun.inf -> fichier appelé : "G:\explorer.exe" ( Présent ! )
    Supprimé ! G:\explorer.exe
    Supprimé ! G:\autorun.inf
    Supprimé ! G:\39lpji.com
    Supprimé ! G:\winfile.jpg
    Supprimé ! F:\100CASIO.exe
    Supprimé ! G:\Documents.exe

    ################## | Registre |

    Supprimé ! [HKCU\SOFTWARE\Bifrost]
    Supprimé ! [HKLM\SOFTWARE\Bifrost]
    Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON"
    Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "Explorer"
    Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "regdiit"
    Supprimé ! [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwtsn32.exe]
    Supprimé ! [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwwinxp.exe]
    Supprimé ! [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe]
    Supprimé ! [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe]
    Supprimé ! [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe]
    Supprimé ! [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe]
    Supprimé ! [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
    Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
    Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"
    Supprimé ! [HKLM\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] "DisableSR"

    ################## | Mountpoints2 |

    ################## | Listing des fichiers présent |

    [05/09/2009 08:39|--a------|0] C:\AUTOEXEC.BAT
    [05/09/2009 08:35|---hs----|212] C:\boot.ini
    [14/04/2008 12:00|-rahs----|4952] C:\Bootfont.bin
    [05/09/2009 08:39|--a------|0] C:\CONFIG.SYS
    [05/09/2009 08:39|-rahs----|0] C:\IO.SYS
    [26/03/2008 11:31|--a------|52422251] C:\Metal[1].Fatigue.in.Engineering.2nd.Ed-0471510599.zip.002
    [05/09/2009 08:39|-rahs----|0] C:\MSDOS.SYS
    [14/04/2008 12:00|-rahs----|47564] C:\NTDETECT.COM
    [14/04/2008 12:00|-rahs----|252240] C:\ntldr
    [?|?|?] C:\pagefile.sys
    [12/03/2010 14:18|--a------|3935] C:\UsbFix.txt
    [30/08/2006 01:38|--a------|435752] D:\boo.mgr
    [30/08/2006 10:38|--ah-----|435752] D:\BOOTMGR
    [29/05/2006 10:30|--ah-----|778] D:\CSP.DAT
    [22/11/2004 18:28|--ah-----|8130] D:\Folder.htt
    [15/01/2008 22:29|--ah-----|32] D:\HPCD.sys
    [15/01/2008 22:29|--ah-----|1280] D:\MASTER.LOG
    [15/01/2008 22:28|--ah-----|14] D:\NTFS
    ################## | Vaccination |

    # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
    # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
    # F:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
    # G:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

    ################## | Upload |

    Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_CLIENT-693380C0.zip : https://www.ionos.fr/?affiliate_id=77097
    Merci pour votre contribution .
    0
  8. yas-- Messages postés 12 Date d'inscription   Statut Membre Dernière intervention  
     
    J'ai mon bureau deseperement vide ( à part l'image théme) de mes racourcis et pas de barre d' outils Windows !
    Pas du tout famiarilisé avec ces trucs!!
    Merci
    0
  9. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Si tu appuies sur Ctrl+Alt+Suppr, le gestionnaire des tâches s'ouvre ?
    0
  10. yas-- Messages postés 12 Date d'inscription   Statut Membre Dernière intervention  
     
    oui il s'ouvre !
    0
  11. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Ok alors ouvre-le, va dans Fichier > Nouvelle tâche > Tape explorer et valide.
    0
  12. yas-- Messages postés 12 Date d'inscription   Statut Membre Dernière intervention  
     
    L'exploiteur me répond qu'il ne trouve pas explorer.... ou de le chercher grâce à démarrer ? mais il n'y a plus de démarrer!!
    Merci Destrio5 pour ton aide!!!
    0
  13. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Tu as le CD de Windows pour éventuellement réparer ?
    0
  14. yas-- Messages postés 12 Date d'inscription   Statut Membre Dernière intervention  
     
    Aurais je perdu certaines routines du windows ??? :!
    0
  15. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Apparemment, le fichier explorer.exe n'est plus à sa place.
    0
  16. yas-- Messages postés 12 Date d'inscription   Statut Membre Dernière intervention  
     
    Je vais chercher
    j'ai ce truc Win XP Sp2 uE V6!!???
    0
  17. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Où ?
    0
  18. yas-- Messages postés 12 Date d'inscription   Statut Membre Dernière intervention  
     
    Là avec mes CDs Home utilities à porté de main!!
    0
  19. yas-- Messages postés 12 Date d'inscription   Statut Membre Dernière intervention  
     
    pourrais je reparer avec ça!
    0
  20. yas-- Messages postés 12 Date d'inscription   Statut Membre Dernière intervention  
     
    Merci encore à toi Desterio5 et tous!!
    0