Boas...cá estou eu de novo.
Depois de mais umas horitas de volta disto e analisando e fazendo o que vem no segundo link
(
http://josecandido.galeon.com/enlaces/smitfraudfix.html) que o amigo PauloJorge postou anteriormente, infelizmente, quando faço outra analise no SpyBot, o meu "adorado" SMITFRAUD.C-toolbar888 ai cá está...
Parece que é dos persistentes o teimoso do BUG!!!Dassss!
De qualquer forma aqui fica o ralatorio gerado pelo "SmitFraudFix v2.195"
_____________________________________________________________
SmitFraudFix v2.195
Scan done at 22:26:55,21, 15-06-2007
Run from C:\Documents and Settings\"User"\Ambiente de trabalho\SmitfraudFix
OS: Microsoft Windows XP [VersÆo 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{7498A94A-7891-4013-9269-E4282C2B8E12}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{BF705A5B-B9B0-434F-B670-568F5F0401EC}: NameServer=195.23.129.126,194.79.69.222
HKLM\SYSTEM\CS1\Services\Tcpip\..\{7498A94A-7891-4013-9269-E4282C2B8E12}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{BF705A5B-B9B0-434F-B670-568F5F0401EC}: NameServer=195.23.129.126,194.79.69.222
HKLM\SYSTEM\CS3\Services\Tcpip\..\{7498A94A-7891-4013-9269-E4282C2B8E12}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{BF705A5B-B9B0-434F-B670-568F5F0401EC}: NameServer=195.23.129.126,194.79.69.222
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
_____________________________________________________________
Relativamente ao primeiro link (
http://www.forospyware.com/t93052.html), reporta sobre uma situação também de um SmitFraud mas centrada num relatorio do programa Hijackthis que é obviamente diferente. Já me registei naquele forum tambem e vou postar lá um tópico parecido com aquele expondo o meu relatorio do Hijackthis para ver se tenho sorte e consigo algo...
cumps