Download the Pocket KillBox
Unzip the file to your desktop.
Run Pocket Killbox and paste the full file path of each of the below files in the box and click on Standard File Kill and End Explorer Shell While Killing File. Click on the button with the red circle and an X in the middle after you enter each file (see the files below).
C:\WINDOWS\System32\svcnet.exe
C:\WINDOWS\dxsetu.exe
c:\windows\winsock.scr
c:\windows\dxsetu.exe
c:\windows\system32\winlog.com
c:\windows\system32\dxwinex.exe
Reboot afterwards if the files are successfully deleted.
If all files are not deleted, do not reboot yet. Run Pocket Killbox again and paste the full file path in the box and click on Delete on Reboot. Next click on the button with the red circle and an X in the middle. You will get a message saying "File with be deleted on next reboot, Process and Reboot now?" Click "Yes" to reboot only after the last file you enter.
Post a new log.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
try this program while waiting for a reply from Crunchie after running it post a fresh log .
,,,,,,,,,,,,,,,,,,,,,,,,,,
Go
Here and Get Trojan-Hunter Fully working trial! and run a full scan
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
Close all browser windows, scan with HJT, and have it fix the following entries:
F2 - REG:system.ini: Shell=Explorer.exe winsock.scr
O4 - HKLM\..\Run: [F:\WINDOWS\System32\ope6A1.exe ] F:\WINDOWS\System32\ope6A1.exe
O4 - HKLM\..\Run: [WinDSNX] F:\WINDOWS\System32\ope6B4.exe
O4 - HKLM\..\Run: [F:\WINDOWS\System32\ope6AA.exe ] F:\WINDOWS\System32\ope6AA.exe
O4 - HKLM\..\Run: [F:\WINDOWS\System32\ope6B3.exe ] F:\WINDOWS\System32\ope6B3.exe
O4 - HKLM\..\Run: [dxset.exe] F:\WINDOWS\dxsetu.exe
Reboot into Safe Mode
Delete the highlighted files in these locations:
F:\WINDOWS\System32\ope6A1.exe
F:\WINDOWS\System32\ope6B4.exe
F:\WINDOWS\System32\ope6AA.exe
F:\WINDOWS\System32\ope6B3.exe
F:\WINDOWS\dxsetu.exe
Open Windows Explorer, go to Tools, and in the Folder Options, select "Show hidden files and folders," and uncheck "Hide protected operating system files."
For every User listed under C:\Documents and Settings, delete the entire contents of these folders (not the folders themselves):
Cookies
History
Local Settings\Temp
Local Settings\Temporary Internet Files\Content.IE5
Delete the entire contents of your C:\Windows\Temp folder.
Delete the entire contents of your C:\Temp folder (if you have one).
Do a search for *.tmp and delete all entries found.
Empty your Recycle Bin.
Reboot normally, close all browser windows, scan with HJT, and post a new log please. (Let us know if you still have the problem too)
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
I'd wait for some advice from crunchie or DMR on the Mirc.exe (unless you've done something with it already?); other than that, your log looks clean to me, are you still having trouble with the backdoor thing?
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214