# Ever Seen This Malware? I cannot remove it

**URL:** https://boards.straightdope.com/t/ever-seen-this-malware-i-cannot-remove-it/641909
**Category:** Factual Questions
**Created:** [November 23, 2012, 4:48pm UTC](https://boards.straightdope.com/t/ever-seen-this-malware-i-cannot-remove-it/641909 "2012-11-23T16:48:50Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![chargerrich](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chargerrich/32/5399_2.png) [@chargerrich](https://boards.straightdope.com/u/chargerrich)
#### Post date: [November 23, 2012, 4:48pm UTC](https://boards.straightdope.com/t/ever-seen-this-malware-i-cannot-remove-it/641909/1 "2012-11-23T16:48:50Z")

</div>

As a developer, I like to consider myself pretty proficient around a computer and have over the years removed several malware programs, but this latest has me stumped to the point where even my google-fu has failed me.

First let me state I know that I can just reformat and reinstall Windows 7, but I would like to avoid that if possible.

Anyway, the malware basically creates a popup that takes the shape of an iPhone that displays in the bottom right hand corner of my desktop using some keywords I have used to try and sell something. So for example, if I point my browser to a this site, the popup will say something like “click here to save 50% on straight dope items in your area” 😃

The malware also likes to redirect me every so often (1 in 5 or 10) when I type in a URL to a malware/ad engine such as adserver and a few others.

Other than this is seems pretty harmless but it is annoying as hell.

I have done the following:

Ran TDSKILLER looking for a rootkit, none found.  
Ran Malware Bytes several times, nothing.  
I use spyware blaster  
I have no script installed on Firefock  
Have tired other programs such as adware and AVG free but the popup persists.

Anyone seen or defeated this little bastard? 😃

---

<div class="post-metadata">

### Author: ![Sitnam](https://avatars.discourse-cdn.com/v4/letter/s/6a8cbe/32.png) [@Sitnam](https://boards.straightdope.com/u/Sitnam)
#### Post date: [November 23, 2012, 4:57pm UTC](https://boards.straightdope.com/t/ever-seen-this-malware-i-cannot-remove-it/641909/2 "2012-11-23T16:57:31Z")

</div>

[REVO Uninstaller](http://www.revouninstaller.com/revo_uninstaller_free_download.html) has served me well in the past.

---

<div class="post-metadata">

### Author: ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)
#### Post date: [November 23, 2012, 6:26pm UTC](https://boards.straightdope.com/t/ever-seen-this-malware-i-cannot-remove-it/641909/3 "2012-11-23T18:26:22Z")

</div>

For really stubborn stuff I use [Kaspersky Rescue Disk](http://support.kaspersky.com/viruses/rescuedisk). You sometimes need a standalone AV disc. Download and burn on a different computer.

Does this page about [Cloud Protection](http://deletemalware.blogspot.com/2011/10/how-to-remove-cloud-protection.html) look relevant?

---

<div class="post-metadata">

### Author: ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)
#### Post date: [November 23, 2012, 6:37pm UTC](https://boards.straightdope.com/t/ever-seen-this-malware-i-cannot-remove-it/641909/4 "2012-11-23T18:37:14Z")

</div>

> [@chargerrich](#):
>
> As a developer, I like to consider myself pretty proficient around a computer and have over the years removed several malware programs, but this latest has me stumped to the point where even my google-fu has failed me.
> 
> First let me state I know that I can just reformat and reinstall Windows 7, but I would like to avoid that if possible.
> 
> Anyway, the malware basically creates a popup that takes the shape of an iPhone that displays in the bottom right hand corner of my desktop using some keywords I have used to try and sell something. So for example, if I point my browser to a this site, the popup will say something like “click here to save 50% on straight dope items in your area” 😃
> 
> The malware also likes to redirect me every so often (1 in 5 or 10) when I type in a URL to a malware/ad engine such as adserver and a few others.
> 
> Other than this is seems pretty harmless but it is annoying as hell.
> 
> I have done the following:
> 
> Ran TDSKILLER looking for a rootkit, none found.  
> Ran Malware Bytes several times, nothing.  
> I use spyware blaster  
> I have no script installed on Firefock  
> Have tired other programs such as adware and AVG free but the popup persists.
> 
> Anyone seen or defeated this little bastard? 😃

Take a look at your startup tasks and your general task list, look for suspicious entries, especially ones with paths to random file names or paths to temp folders.

Disable them

note those filenames and search your registry for that word, export a copy of the key then delete the original.

Reboot and see if its still there  
\*please note these instructions assume poster is familiar with task lists, startup list and registry editing.

If that does not solve it, post in thread

I will PM you a remote session link and give you a look no charge.

free virus help from [www.pcsearchandrescue.com](http://www.pcsearchandrescue.com) 😃

---

<div class="post-metadata">

### Author: ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)
#### Post date: [November 23, 2012, 6:57pm UTC](https://boards.straightdope.com/t/ever-seen-this-malware-i-cannot-remove-it/641909/5 "2012-11-23T18:57:56Z")

</div>

Did you run Malware Bytes etc in Safe Mode?

---

<div class="post-metadata">

### Author: ![Mdcastle](https://avatars.discourse-cdn.com/v4/letter/m/958977/32.png) [@Mdcastle](https://boards.straightdope.com/u/Mdcastle)
#### Post date: [November 23, 2012, 7:00pm UTC](https://boards.straightdope.com/t/ever-seen-this-malware-i-cannot-remove-it/641909/6 "2012-11-23T19:00:40Z")

</div>

Norton Power Eraser has served me well several times.

---

<div class="post-metadata">

### Author: ![md2000](https://avatars.discourse-cdn.com/v4/letter/m/73ab20/32.png) [@md2000](https://boards.straightdope.com/u/md2000)
#### Post date: [November 23, 2012, 7:25pm UTC](https://boards.straightdope.com/t/ever-seen-this-malware-i-cannot-remove-it/641909/7 "2012-11-23T19:25:53Z")

</div>

I know the fake-AV sometimes used to hook itself into the registry for the “.exe”; every time you ran a program, it instead launched the virus program, which then ran the requested program, provided it was not and AV program.

What are the symptoms - it appears on the desktop, or only when you run IE? DOes browser redirect happen with Firefox or Chrome too, or just IE? What about booting in safe mode and see if the same symptoms happen?
