Impossible de trouver le fichier script SysinfYhX.db

protohamza Messages postés 3 Statut Membre -  
protohamza Messages postés 3 Statut Membre -
Bonjour,
Depuis quelques jours j'ai ce message qui s'affiche à chaque démarrage du PC
Impossible de trouver le fichier script
"C:\Users\users\AppData\Local\Temp\SysinfYhX.db"
J'ai téléchargé FRST qui a effectué une analyse et j'ai eu ces 3 rapports :

FRST : https://pjjoint.malekal.com/files.php?id=FRST_20160707_u11i14m11t6t5
Shortcut : https://pjjoint.malekal.com/files.php?id=20160707_y10c12l12o13l13
Addition : https://pjjoint.malekal.com/files.php?id=20160707_f8w13j6c10f10

Merci d'avance pour votre aide.

2 réponses

  1. Malekal_morte- Messages postés 178136 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   24 712
     
    Salut,

    y a des adwares aussi,

    Pour te protéger des infections amovibles type Wscript (Windows Script Host)
    Télécharger et installer Marmiton
    (le mot de passe est malekal)
    Clic sur Désactiver au niveau de Windows Script Host.
    Marmiton va bloquer les scripts malicieux (VBS, VBE, JavaScript etc).

    Voici la correction à effectuer avec FRST. Tu peux t'aider de cette note explicative avec des captures d'écran.

    Ouvre le bloc-notes : Touche Windows + R,
    Dans le champs "Exécuter", saisir notepad et OK.
    Copie/Colle dedans ce qui suit :

    CreateRestorePoint:
    CloseProcesses:
    Task: {1D352031-4086-4D63-8687-9D561861299C} - System32\Tasks\{DC13A3DC-77C3-4312-BE1A-EE5F0744547F} => pcalua.exe -a C:\Users\Hamza\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=adks <==== ATTENTION
    Task: {7B9F2F33-E362-463F-B9B7-0F622C086531} - System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-3 => C:\Program Files (x86)\CinePlus-1.2V15.10\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-3.exe <==== ATTENTION
    Task: {68EB23AD-B0F3-484C-8471-403BD0E2E44C} - System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-6 => C:\Program Files (x86)\CinePlus-1.2V15.10\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-6.exe <==== ATTENTION
    Task: {9234154C-674C-44CE-BE60-FEE1B8DBE166} - System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-11 => C:\Program Files (x86)\CinePlus-1.2V15.10\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-11.exe <==== ATTENTION
    Task: {9BF3E652-0A0A-4408-AD15-8A70DD395391} - System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-7 => C:\Program Files (x86)\CinePlus-1.2V15.10\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-7.exe <==== ATTENTION
    ShortcutWithArgument: C:\Users\Hamza\Desktop\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.bahaty.com/red/e.php
    ShortcutWithArgument: C:\Users\Hamza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.LNK -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.bahaty.com/red/f.php
    ShortcutWithArgument: C:\Users\Hamza\Desktop\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.bahaty.com/red/e.php
    ShortcutWithArgument: C:\Users\Hamza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.LNK -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.bahaty.com/red/f.php
    EmptyTemp:


    Une fois, le texte collé dans le Bloc-notes,
    Menu "Fichier" puis "Enregistrer sous",
    A gauche, place toi sur le Bureau,

    Dans le champs en bas, nom du fichier mets : fixlist.txt
    Clique sur "Enregistrer", cela va créer fixlist.txt sur le Bureau.

    Relance FRST et clique sur le bouton "Corriger / Fix"
    Un redémarrage sera peut-être nécessaire ( pas obligatoire )
    Un fichier texte apparait, copie/colle le contenu ici dans un nouveau message.

    Redémarre l'ordinateur.

    2°)
    Réinitialise manuellement tes navigateurs :

    0
    1. protohamza Messages postés 3 Statut Membre
       
      Malekal_morte merci pour la réponse, j'ai suivi vos instructions mais le même message s'affiche au démarrage, j'ai essayé 2 fois mais le problème persiste, voici le contenu du notepad qui c'est créé sur le bureau au redémarrage :

      Résultats de correction de Farbar Recovery Scan Tool (x64) Version: 02-07-2016
      Exécuté par Hamza (2016-07-07 21:19:19) Run:3
      Exécuté depuis C:\Users\Hamza\Desktop
      Profils chargés: Hamza (Profils disponibles: Hamza)
      Mode d'amorçage: Normal
      ==============================================

      fixlist contenu:

      CreateRestorePoint:
      CloseProcesses:
      Task: {1D352031-4086-4D63-8687-9D561861299C} - System32\Tasks\{DC13A3DC-77C3-4312-BE1A-EE5F0744547F} => pcalua.exe -a C:\Users\Hamza\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=adks <==== ATTENTION
      Task: {7B9F2F33-E362-463F-B9B7-0F622C086531} - System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-3 => C:\Program Files (x86)\CinePlus-1.2V15.10\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-3.exe <==== ATTENTION
      Task: {68EB23AD-B0F3-484C-8471-403BD0E2E44C} - System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-6 => C:\Program Files (x86)\CinePlus-1.2V15.10\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-6.exe <==== ATTENTION
      Task: {9234154C-674C-44CE-BE60-FEE1B8DBE166} - System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-11 => C:\Program Files (x86)\CinePlus-1.2V15.10\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-11.exe <==== ATTENTION
      Task: {9BF3E652-0A0A-4408-AD15-8A70DD395391} - System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-7 => C:\Program Files (x86)\CinePlus-1.2V15.10\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-7.exe <==== ATTENTION
      ShortcutWithArgument: C:\Users\Hamza\Desktop\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.bahaty.com/red/e.php
      ShortcutWithArgument: C:\Users\Hamza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.LNK -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.bahaty.com/red/f.php
      ShortcutWithArgument: C:\Users\Hamza\Desktop\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.bahaty.com/red/e.php
      ShortcutWithArgument: C:\Users\Hamza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.LNK -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://www.bahaty.com/red/f.php
      EmptyTemp:


      Le Point de restauration a été créé avec succès.
      Processus fermé avec succès.
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1D352031-4086-4D63-8687-9D561861299C} => clé non trouvé(e).
      C:\Windows\System32\Tasks\{DC13A3DC-77C3-4312-BE1A-EE5F0744547F} => non trouvé(e).
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DC13A3DC-77C3-4312-BE1A-EE5F0744547F} => clé non trouvé(e).
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B9F2F33-E362-463F-B9B7-0F622C086531} => clé non trouvé(e).
      C:\Windows\System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-3 => non trouvé(e).
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-3 => clé non trouvé(e).
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68EB23AD-B0F3-484C-8471-403BD0E2E44C} => clé non trouvé(e).
      C:\Windows\System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-6 => non trouvé(e).
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-6 => clé non trouvé(e).
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9234154C-674C-44CE-BE60-FEE1B8DBE166} => clé non trouvé(e).
      C:\Windows\System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-11 => non trouvé(e).
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-11 => clé non trouvé(e).
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BF3E652-0A0A-4408-AD15-8A70DD395391} => clé non trouvé(e).
      C:\Windows\System32\Tasks\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-7 => non trouvé(e).
      HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\b3f4423f-2277-4d1d-9ad6-b6fcd141036e-7 => clé non trouvé(e).
      C:\Users\Hamza\Desktop\Internet Explorer.lnk => Raccourci argument supprimé(es) avec succès.
      C:\Users\Hamza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.LNK => Raccourci argument supprimé(es) avec succès.
      C:\Users\Hamza\Desktop\Internet Explorer.lnk => Raccourci argument supprimé(es) avec succès.
      C:\Users\Hamza\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.LNK => Raccourci argument supprimé(es) avec succès.

      =========== EmptyTemp: ==========

      BITS transfer queue => 32768 B
      DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10707352 B
      Java, Flash, Steam htmlcache => 0 B
      Windows/system/drivers => 6628 B
      Edge => 0 B
      Chrome => 0 B
      Firefox => 5555784 B
      Opera => 0 B

      Temp, IE cache, history, cookies, recent:
      Default => 0 B
      ProgramData => 0 B
      Public => 0 B
      systemprofile => 0 B
      systemprofile32 => 0 B
      LocalService => 830 B
      NetworkService => 0 B
      Hamza => 61001 B

      RecycleBin => 0 B
      EmptyTemp: => 15.6 MB données temporaires supprimées.

      ================================


      Le système a dû redémarrer.

      Fin de Fixlog 21:19:33

      0