ServiceDesk Simulator
← All articles

Pop-ups, Fake Search Engines, and the Extension That Keeps Coming Back

August 18, 2026 · ServiceDesk Simulator · 4 min read

Ask a help desk which tickets they see most under the malware heading, and it is not ransomware and it is not anything sophisticated. It is ads. Pop-ups appearing over other windows, a search engine nobody chose, a browser that has been getting slower for a fortnight and a user who is certain they changed nothing.

They usually did change something, months ago, by clicking Allow on a prompt they no longer remember. That is the part that makes these tickets interesting, because the standard response, run a scan, frequently comes back clean and fixes nothing.

The ads that are not malware at all

A large share of pop-up tickets are browser notifications. At some point a site asked for permission to send them and the user clicked through the prompt on the way to what they actually wanted. Every one after that is the browser doing exactly what it was told, by the user, in writing.

The tell is that the ads appear whatever the user is doing, including when the browser looks closed but is still running, and closing one seems to summon another. The cure is in the browser’s notification settings, where the permitted sites are listed and can be removed. Nothing needs uninstalling, because nothing was installed.

This is worth understanding rather than memorizing, because an antivirus scan will never fix it. Nothing on that machine is malicious. A setting is being honored. Techs who only know how to run scans will scan, find nothing, tell the user the machine is clean, and get the same ticket again next week under a different subject line.

A web browser open on a remote workstation in ServiceDesk Simulator
Most of this ticket gets solved in browser settings rather than in a security tool, which is the opposite of what the ticket's category suggests.

When the search engine changed itself

The hijack version is different in kind. The new tab page belongs to a search site the user has never heard of, the results are mostly advertising, and the browser has been sluggish since it started. Somewhere behind that is an extension, and behind the extension is usually an application that installed it.

The order matters more than the steps here. The instinctive move is to fix the visible symptom first, reset the search engine, remove the extension, and confirm with the user that the new tab looks normal again. It does, for a while. Then the extension returns, because the installer that put it there is still on the machine and still runs.

So work backwards instead. Find the extension, note it, then look at installed applications sorted by date. Something arrived around the time the user says the trouble started, usually with a name built to sound like a utility. Remove that first, remove the extension second, and only then reset the browser settings that were changed. Reset before removal and you are simply undoing settings that are about to be set again.

Sorting applications by install date is the underrated part of that. Users cannot tell you what they installed, but the machine remembers precisely, and a cluster of unfamiliar entries on the same afternoon is both your answer and the story of how it happened.

Knowing what is meant to be there

All of this depends on being able to tell an unfamiliar name from a bad one, which is where new techs stall. The organization’s own tools look just as strange as the junk when you have been there three weeks.

That is what an approved list is for. A knowledge base that records which extensions and applications are expected turns an anxious judgment call into a lookup. Where no such list exists, building one is a genuinely valuable thing for a junior tech to do, and it is the sort of contribution that gets noticed far more than another closed ticket.

The scan still has a place at the end. It confirms nothing heavier came along for the ride, and it gives the user the reassurance they are actually asking for. It is the verification step, not the fix, which is the same shape as every other troubleshooting method that works.

The conversation at the end

Finish these tickets with the explanation, always. Not a lecture, thirty seconds: this is where the ads were coming from, this is the prompt that grants it, and here is what it looks like next time. Users click Allow because the prompt appears while they are trying to do something else and dismissing it seems like the fast way past. Once someone has seen the connection between that click and a fortnight of pop-ups, they stop, and one ticket has prevented several.

There is a boundary here too. Adware is a cleanup. A machine also showing signs of something worse, disabled security software, unfamiliar services, credentials in play, is not a cleanup, and treating it as one is how a real intrusion gets closed as resolved.

Getting the reps without wrecking a laptop

Nobody wants to learn this on a machine that matters, and infecting your own laptop for practice is a poor career plan. ServiceDesk Simulator runs the whole family as tickets: pop-ups fed by a notification permission, a hijacked search with an extension that comes back if you remove it in the wrong order, and a full screen scare page that is only a web page pretending to be a crisis. The scanner behaves like a real one, which is to say it tells you what it cannot fix, and finding out where the fix actually lives is the entire exercise.

Common questions

Why do pop-up ads appear when the browser is closed or on a clean site?

Usually because a website was granted notification permission at some point. Those pop-ups are browser notifications rather than infections, and an antivirus scan cannot remove them because nothing malicious is installed.

What is browser hijacking?

When something changes the browser's search engine, home page, or new tab to a site the user did not choose, typically to route searches through pages full of ads. It usually arrives with an extension or a bundled application.

Why does a removed extension come back?

Because the extension was the visible half. A bundled application or scheduled task reinstalls it, so removing the extension without removing what installed it buys a few hours at most.

Does antivirus remove adware?

Sometimes, but plenty of adware is technically legitimate software or a browser setting, which scanners deliberately leave alone. The removal work happens in browser settings and installed applications, with the scan as confirmation rather than the cure.

Built by Rena, who broke into IT with no degree. Read her story →