I NEED HELP ishost.exe & ismon.exe

Status
Not open for further replies.
So my brother was retarded and somehow downloaded these startup files and now my internet explorer won't go to my homepage and norton + spysweeper are constantly telling me that i have some crazy trojan. please help.
 
Hello and welcome to Techspot.

Download and run these three tools. Follow the instructions for each tool carefully.

Tool1. Tool2. Tool3.

Then, go and read this thread HERE.

Post a fresh HJT log as a .txt attchment into this thread, only after doing the above.

Regards Howard :wave: :wave:

This thread is for the use of BryanPark only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Hey Howard, thanks for the speedy response so I did everything you told me and heres the HJT log file. one more thing I noticed is that my computer is abnormally slow now is that because of the virus or is this going to be like this forever? I hope you can help me out thanks
 

Attachments

  • hijackthis.txt
    9.4 KB · Views: 6
You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

Boot into safe mode, under your normal user name. See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html

Go to add remove programme in your control panel and uninstall anything to do with(if there).

viewpoint
viewpoint toolbar v35
viewpoint manager

Close control panel.

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

ALCXMNTR.EXE
FotomatDeviceConnect.exe
Remind_XP.exe
ViewMgr.exe

Close task manager.

Run HJT with no other programmes open(except notepad).Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"

O4 - HKLM\..\Run: [ViewMgr] "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe"

O4 - HKLM\..\Run: [ViewpointPhotosDeviceConnect] "C:\Program Files\Viewpoint\Viewpoint Toolbar V35\FotomatDeviceConnect.exe"

Click on the fix checked button.

Close HJT.

Locate and delete the following bold files and/or directories(if there).

C:\Program Files\Viewpoint
C:\Windows\Creator\Remind_XP.exe

Reboot into normal mode and turn system restore back on.

Post a fresh HJT log and let us know how your system is running.


Regards Howard :)

This thread is for the use of BryanPark only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Hey howard I did everything that you told me to do and my computer is still running really slow but my homepage returned and I no longer have those .exe files. I was wondering if you could help me out further so that I can get my computer back up to speed. attached is an updated HJT log. thanks again

Bryan
 

Attachments

  • hijackthis2.txt
    9.2 KB · Views: 6
first you try changing you av programme. norton will slow your pc vastly. i also think that your ie needs updating and maybe get sp2. after some searching i have found that hpdtlk02.dll may also be classified as ad-ware. please don't alter anything until Howard gets back to you.
 
hpdtlk02.dll is a bho(browser helper object). Whether it is spyware is open to some debate. However, it would not cause any noticable problems. It belongs to the pc manufacturers and can be uninstalled if desired.

Regards Howard :)
 
thanx again howard. how fast are you i've only just posted that!! and by the way good morning.:wave:
 
Status
Not open for further replies.
Back