You did fine, azureus.
Please copy this page to
Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
Also be sure to carry out the instructions in the sequence listed below.
***************************************************
Close any open browsers.
--------------------------------------------------------------------
Disable Spybot TeaTimer as it may interfere with the fix below:
- Open Spybot Search & Destroy.
- In the Mode menu click "Advanced mode" if not already selected.
- Choose "Yes" at the Warning prompt.
- Expand the "Tools" menu.
- Click "Resident".
- Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
- In the File menu click "Exit" to exit Spybot Search & Destroy.
--------------------------------------------------------------------
Open HijackThis and click on 'Do a System Scan Only'. 'Check' the following entries:
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: System Process - {C2EEB4FA-B6D6-41b9-9CFA-ABA87F862BCB} - C:\WINDOWS\system32\navshext1.dll
O2 - BHO: C:\WINDOWS\lbbho.dll - {D9E06A41-2A46-4653-9692-BE26EFE2A018} - C:\WINDOWS\lbbho.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/si...nerInstall.cab
Click
'Fix Checked' and close HijackThis.
--------------------------------------------------------------------
Using 'My Computer', navigate to and delete the following
File
C:\WINDOWS\system32\
navshext1.dll
--------------------------------------------------------------------
Reboot your system.
--------------------------------------------------------------------
Please run another online scan at Panda so we can see what remnants remain:
Perform an online scan with Internet Explorer with
Panda ActiveScan- Click on
located at the bottom of the page.
- A "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
- Enter your e-mail address, country, and state & click "Free Online Scan" *The download of the 8 MB Panda's ActiveX control will take place*
Begin the scan by selecting

- If it finds any malware, it will offer you a report.
- Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
- Click on
then click 
* You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
* Turn off the real time scanner of any existing antivirus program while performing the online scan
--------------------------------------------------------------------
Run a new scan with HijackThis and save the log.
--------------------------------------------------------------------
Please include the following in your next reply:
Panda results
New HijackThis log
I'd also like to review the
c:\fixwareout\report.txt. Please include that report as well.
__________________
Member of ASAP since 2005
Member of UNITE since 2006
"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."