Grrr... this DXSETU.EXE/WINSOCK.SCR thing seems to be the "Nasty of the Week", but unfortunately there doesn't seem to be a heck of a lot of info about it on the Net yet.
I was advised to check the dxsetu and winsock on hijackthis but it keeps coming back.
Did you manually delete those two files after having HJT remove their entries? HJT can remove the "04" entries from your registry, but itwill not physically delete the actual files referenced in those entries; you need to do that yourself.
Have HJT fix:
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.isearch.com/index.php?ap...ODQ6NTo5&Terms=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.isearch.com/index.php?ap...ODQ6NTo5&Terms=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.isearch.com/index.php?ap...ODQ6NTo5&Terms=
R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe winsock.scr
O4 - HKLM\..\Run: [dxset.exe] C:\WINDOWS\dxsetu.exe
O16 - DPF: {99802379-7362-40E2-9D28-8A3B9AF880B7} - http://hotsearchbar.com/toolbar2/winhot32.cab
After HJT has finished with the fixes:
- Reboot into safe mode
- Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files".
- Locate and delete dxsetu.exe and winsock.scr
- For every user account listed under C:\Documents and Settings, delete the entire contents of these folders:
1. Local Settings\Temp
2. Cookies
3. History
4. Local Settings\Temporary Internet Files\Content.IE5
- Delete the entire content of your C:\Windows\Temp folder.
(If you get any messages concerning the deletion of system files such as desktop.ini or index.dat, just choose to delete those files; they'll be automatically regenerated by Windows if needed.)
- Empty your Recycle Bin.
- Reboot normally.
Post a fresh HJT log after that.