Looks like there is still one left :(.
- Double click on OTMoveIt3 to run it.
- Please copy and paste the text in the Code box below, into OTMoveIt3;
:reg [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ade9f68-2b65-4f0d-9b33-e070d1b5e128}] :files d:\WINDOWS\system32\arwehdx.dll :commands [EmptyTemp] [Reboot]
- Check the box "Unregister Dll's and OCX's ... if not checked.
- Click on MoveIt!
- The end results of the processing will be in 2 places:
- The Results window on the right side of the OTMoveIt screen.
- A log (text) file created in "C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log"
- Copy all the text from the Results window...
- Click Exit (3) when done.
- Please paste the results from the OTMoveIt window or the log file, in your next reply.
====
Post a new hijackthis log too please.