This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Annoying Pop-up

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, 1st time here, hope you might be able to help. I've recently been getting asnnoying popups (twice per day?) advertising games and casino's in an Explorer window even when I don't have explorer open. Have tried using spybot and adaware but they don't seem to detect it. Is the following log able to highlight anything that someone could suggest trying? Logfile of HijackThis v1.99.0 Scan saved at 11:45:21 PM, on 16/12/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Microsoft Hardware\Keyboard\type32.exe C:\WINDOWS\LTMSG.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\cgghgjsy.exe C:\Program Files\ISTsvc\istsvc.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Eset\nod32krn.exe C:\Program Files\SETI@home\[removed] C:\Program Files\Azureus\Azureus.exe C:\Program Files\Java\jre1.5.0\bin\javaw.exe C:\Program Files\Mozilla Firefox\firefox.exe D:\Downloads\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUp.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7 O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [ZhHaf] C:\WINDOWS\cgghgjsy.exe O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: NOD32 Kernel Service - Unknown - C:\Program Files\Eset\nod32krn.exe O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Thanks for any help in advance. David
Hi David, Welcome to TomCoyote forum. While we are only going to remove bad stuff, there is always a slight chance of an error, and HijackThis creates backups in the event this happens and store logfiles also. I am not comfortable with the location you have chosen: D:\Downloads\HijackThis.exe
Before we proceed, please go to your C drive, double click on MyComputer, choose the C drive, then right click on a blank spot, create a new folder, call it HJT, then copy and paste the HJT.exe to that folder. Delete the old one. Thanks.
The new one will look like this: C:\HJT\HijackThis.exe You may also create a shortcut to your desktop if you wish.

Is this your antivirus programs? C:\Program Files\Eset\nod32kui.exe
I am not familiar with it, if it is, make sure you are keeping it updated and run often, this is why:

(Please review the link information so you will know what we are removing, some items may no longer be there after you run the Symantec tool, do that first, then the HJT fix second. I will include all in the HJT removal to be safe.

C:\WINDOWS\cgghgjsy.exe
This item does not identify, as such is a trojan of some kind and will be removed.

C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
(Review This link) http://www.liutilities.com/products/wintas…library/istsvc/

Symantec has recentlly released a tool for removing this item, lets try it out here:
http://sarc.com/avcenter/venc/data/adware.istbar.html Download and follow the instruction for running this removal tool. The other trojan could be conected and might go also. If not we will kill it below.

Once the SYMANTEC tool as been run:

Open your Task Manager (Ctrl, Alt, Delete) at the same time) choose the Processes tab, and if they are there end process on these items:

cgghgjsy
ISTsvc

To be sure, please enable hidden files:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Scan with HijackThis, put a check in front of each of these line items (if there)

O2 - BHO: IeCatch2 Class - {} - C:\PROGRA~1\FlashGet\jccatch.dll
http://computercops.biz/clsid-470.html
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
http://computercops.biz/clsid-927.html
(Same as above)
O4 - HKLM\..\Run: [ZhHaf] C:\WINDOWS\cgghgjsy.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe

Close all programs but HJT and all browser windows, then Click on "Fix Checked"

RIGHT click on Start, then click on Explore, in the tree that opens look for and delete these files or folders, if there:

C:\Program Files\ISTsvc\ >>> folder

C:\PROGRAM FILES~1\FlashGet\>>> folder

C:\WINDOWS\cgghgjsy.exe >>> file


Clean like this: Start, Run then type "cleanmgr" without the quotes then ok. Allow windows to remove anything it locates. Using Add Reply to stay in this same thread, post a new log, please include any feedback you think we should have.

This program is often suggested as a better cleaner than cleanmgr. I am including a link for you: http://www.igorshpak.net/

Thanks…pskelley
TomCoyote forum
Classroom Advanced
Thank you for your response. I am amazed at such a thorough service and think it's even more incredible that it is free. I have followed the steps you have provided and will see if it's fixed the problem. C:\Program Files\Eset\nod32kui.exe is my anti-virus program. It's called NOD32 from Eset After running Symantec's removal tool it indicated that it didn't locate any problems. I still followed through with each of the other steps though. Thank you again for such an amazing response & I will re-post in the unfortunate event that it didn't fix my problem. Guess I will not be using Flashget to manage my downloads anymore!
Hi David,That is strange about the istsvc.exe. It stongly identified as a security risk at Wintasks Process Library, see what WinPatrol has to say: http://www.winpatrol.com/db/freesample/istsvc.html
http://www.liutilities.com/products/wintas…library/istsvc/
Here is an example where at CastleCops they had to use KillBox to get rid of it.
http://computercops.biz/postt91760.html
I would sure appreciate another log to look at so I can be assured your computer is clean. The Symantec removal tool is one of three just released by the software giant, and this is the first time I have used the tool. This will help me judge if I can depend on it for other infections. I also have some information about how to stay clean by three experts I will give you at that point, your call.

Thanks…pskelley
TomCoyote forum
Classroom Advanced
If you get help here consider a donation:
http://tomcoyote.com/donate.php
After such a brilliant help I'm more than happy to post another log. Logfile of HijackThis v1.99.0 Scan saved at 6:19:10 PM, on 21/12/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Microsoft Hardware\Keyboard\type32.exe C:\WINDOWS\LTMSG.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Eset\nod32krn.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Hijack This\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUp.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7 O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: NOD32 Kernel Service - Unknown - C:\Program Files\Eset\nod32krn.exe O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe If there is anything else there you think shouldn't be I'd be happy to hear it. I've been using my computer for a few days now without any annoying pop ups so it seems like what you suggested worked even if the Symantec tool didn't find anything. I just ran it again for the heck of it and it didn't find anything. Just keep in mind I have a bit of a habbit of messing with things on my computer so maybe I did something to stop it working? Anyhow, thanks again.
Hello David, Thank you for your kind comments, and for your help in the clean up proceedure. I must say we were lucky as a lot of stuff that is making the rounds right now is difficult if not almost impossible to remove. I am going to include links to websites where you can check what is running and check software you are considering prior to installing it on your computer. Your hijackThis log is an excellant tool for keeping track of what is going on. I keep a shortcut on my desktop and look at the log often, to the point that I can spot a change in an instant.

Your log is clean, and here are some information from Tony Klein, Texruss and ChrisRLG to help you stay that way:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://www.cjwd.demon.co.uk/compsafetyonline.html

While some products suggested might not run well with your configuration, I personally run:
An AV and a firewall…plus a router
Ad-aware and Spybot
SpywareBlaster, SpywareGuard and IE-Spyad

Here is a link to keep and eye on rouge products:
http://www.spywarewarrior.com/rogue_anti-s…re.htm#products And links to investigate your running software if you are so inclined:
http://www.answersthatwork.com/Tasklist_pages/tasklist.htm
http://www.pacs-portal.co.uk/startup_index.htm
http://computercops.biz/StartupList.html
http://www.sysinfo.org/startuplist.php

Have a great holiday and safe surfing
Thanks…pskelley
TomCoyote forum
Classroom Advanced
If you get help here consider a donation:
http://tomcoyote.com/donate.php
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.


To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI