A dark cinematic close-up of a computer screen displaying abstract red warning indicators, with soft out-of-focus server rack lights glowing in the background, moody and tense atmosphere

Step-by-step removal guides for adware, browser hijackers, ransomware, trojans, and more — written for Windows and Mac users.

A wide shot of a laptop keyboard with a subtle red glow emanating from beneath the keys, shallow depth of field, dark and moody cybersecurity theme

Ransomware Removal Guides

Comprehensive ransomware removal instructions covering DJVU/STOP variants and other families. Includes references to decryptor tools from Emsisoft, Kaspersky, and NoMoreRansom, plus file recovery methods using Shadow Explorer.

Read More
A cinematic frame of a glowing padlock icon floating above a motherboard, cool blue tones with subtle amber warning lights, clean and technical atmosphere

Trojan Removal Guides

Step-by-step trojan identification and removal guides covering threats such as VB:Trojan.Agent.EIOB and Backdoor.PHP.WebShell.CT, with both manual and automatic removal methods.

Read More

Recent Stories

Helprestore@pcmalwareexpert.com Ransomware Removal Guide

Escaping a Browser Hijacker Locked in Kiosk Mode

A browser suddenly snaps to full screen, the address bar vanishes, and the only thing on display is a fraudulent "security warning" or a support-scam phone number. There is no obvious way to close the tab or taskbar, and Alt+F4 does nothing. Hijackers push Chrome or Edge into kiosk-style presentation mode, and this lockout has been hitting everyday users in Sydney, Melbourne, Brisbane and smaller towns from Wagga to Cairns.

The ACSC has logged multiple waves of these campaigns, with Scamwatch data from the ACCC showing that remote-access and tech-support scams remain among the costliest categories for local victims. The chain usually starts with a dodgy streaming ad, a cracked download, or a malicious extension. Once installed, the payload flips the browser into a forced full-screen state and re-opens the page every time the user tries to escape.

The good news is that these hijacks are removable without reinstalling Windows. The process involves regaining control of the window, tracking down the underlying process or extension, scrubbing leftover entries, and closing the gaps that let the infection slip in.

What Kiosk Mode Lockouts Actually Mean

Modern browsers ship with a legitimate kiosk feature meant for unattended displays and digital signage. The Fullscreen API, often invoked through a script, can lock a tab edge-to-edge and suppress most keyboard shortcuts. Hijackers abuse that same plumbing to trap victims on a fake alert, phishing form, or "call this number" page.

In Australia, these lockouts frequently impersonate the ATO, myGov, or an ISP such as Telstra or Optus. The page might show a fake ATO tax-debt notice, a fraudulent myGov login, or a Telstra-branded "your NBN line has been compromised" warning. The branding is convincing, but the browser is simply stuck in full-screen with the navigation chrome hidden.

The user can usually still see the desktop behind a thin sliver if they alt-tab quickly, so the lockout is not a system-wide takeover. It is a browser-level trick. Recognising this matters, because cleanup steps differ from a true ransomware or boot-sector compromise where the operating system itself is hijacked. For more aggressive payloads, the boot-sector cleanup walkthrough covers a different threat family.

Breaking Free from the Locked Window

The first priority is regaining the mouse and keyboard without paying any fee or calling any number shown. On Windows, hold Ctrl+Alt+Delete to summon the security screen and choose Task Manager, then end the Chrome, Edge, or Firefox process. On a Mac, hit Cmd+Option+Esc for Force Quit, or open Activity Monitor through Spotlight.

If the keyboard is also being captured, try the Windows key alone, or Cmd+Tab on macOS, to flip away from the browser. Some hijacks only listen for specific shortcuts, so a quick Cmd+Tab from a mate's laptop in the next room can be the fastest way out. Once closed, do not reopen the browser until the cause is removed, or the script will simply relaunch.

If even Task Manager is blocked, boot into Safe Mode with Networking. From the recovery environment, the offending startup entries can be disabled before the browser launches, removing the re-launch trap. This is the same general approach used against persistent threats that survive a normal reboot.

Hunting Down the Underlying Process

After escaping the lockout, the next step is figuring out what installed the hijack. Open the browser's extension list and look for anything unfamiliar, especially PDF converters, "video downloader" tools, or "coupon finder" add-ons installed around the time the problem started. These extensions carry permissions allowing them to run scripts on every page, enabling the forced full-screen behaviour.

Outside the browser, check the Startup tab in Task Manager, the Run keys in the Registry, and Login Items on macOS. Hijackers commonly drop a small helper executable into AppData\Roaming or Library/Application Support that re-opens the malicious URL on each login. Sorting startup items by publisher is a good way to spot it: legitimate programs are signed and named, while suspicious entries are missing a publisher.

Some advanced strains go further and use DLL injection techniques, which makes them harder to isolate. If the lockout returns after every cleanup, or if random desktop applications start behaving strangely, the infection has probably moved beyond the browser into a broader system compromise.

Cleaning the Browser and Operating System

With the source identified, the browser itself should be reset. In Chrome, open Settings, expand the Advanced section, and choose "Restore settings to their original defaults." In Edge, navigate to Reset Settings, and in Firefox use the Refresh option under Troubleshooting information. Resetting clears the homepage, default search engine, pinned tabs, and any extensions that survived removal.

Run a full scan with a reputable on-demand scanner such as Malwarebytes, Sophos Home, or the built-in Microsoft Defender offline scan. Boot-sector threats and rootkits will not show up in a normal scan, so reading the guide on fake notifications can help users recognise when a hijack has escalated. After the scan, clear the browser cache, remove all cookies, and uninstall any unknown program.

Hardening Against the Next Full-Screen Takeover

Once the system is clean, a few habits will keep the next forced full-screen hijack from gaining a foothold. Disable Fullscreen API prompts from unrecognised sites and consider running the browser with a separate, low-privilege user account on shared family PCs. Avoid "free" PDF tools, video grabbers, and cracked games from file-hosting sites, which remain the most common delivery vehicles in Australia.

Keeping Chrome, Edge, or Firefox up to date closes many of the script-escape bugs hijackers rely on, and turning on automatic operating system updates protects against secondary payloads. For households on NBN connections, the eSafety Commissioner publishes practical advice on recognising and reporting tech-support scams, worth bookmarking on a phone before it is needed.

If a full-screen scam page ever reappears, remember the sequence: Task Manager first, browser reset second, and only then a full system scan. The lockout is intimidating but rarely permanent, and the cleanup is well within the reach of any patient user.

Stydco Scam Email Virus Removal Guide

A scam displayed on the rogue website Stydco.com, typically encountered through redirects from potentially unwanted programs. This guide explains how the scam operates and how to clean affected systems.

Read More