A dark cinematic close-up of a computer screen displaying abstract red warning indicators, with soft out-of-focus server rack lights glowing in the background, moody and tense atmosphere

Step-by-step removal guides for adware, browser hijackers, ransomware, trojans, and more — written for Windows and Mac users.

A wide shot of a laptop keyboard with a subtle red glow emanating from beneath the keys, shallow depth of field, dark and moody cybersecurity theme

Ransomware Removal Guides

Comprehensive ransomware removal instructions covering DJVU/STOP variants and other families. Includes references to decryptor tools from Emsisoft, Kaspersky, and NoMoreRansom, plus file recovery methods using Shadow Explorer.

Read More
A cinematic frame of a glowing padlock icon floating above a motherboard, cool blue tones with subtle amber warning lights, clean and technical atmosphere

Trojan Removal Guides

Step-by-step trojan identification and removal guides covering threats such as VB:Trojan.Agent.EIOB and Backdoor.PHP.WebShell.CT, with both manual and automatic removal methods.

Read More

Recent Stories

Helprestore@pcmalwareexpert.com Ransomware Removal Guide

Trace malware launch points with Windows Event Viewer

When a Windows computer behaves strangely, the visible symptom is rarely the whole story. A pop-up, disabled security tool or sudden browser redirect may have started with a process launched several minutes earlier. Event Viewer can help reconstruct that sequence by showing when services, scheduled tasks, drivers and applications started.

The utility does not automatically identify every malicious file. Instead, it provides timestamps, account names, process information and error messages that can be compared with antivirus alerts, browser history and recent system changes. This makes it useful for investigating trojans, spyware, ransomware loaders and persistent adware.

The process is relevant for Australian home users, small businesses and remote workers who may rely on Windows laptops for banking, online shopping or work across Sydney, Melbourne, Brisbane and regional areas. Treat unfamiliar events carefully, especially on a device connected to home NBN equipment or a workplace network.

Prepare the investigation

Before opening logs, record what happened and when. Note the first pop-up, browser change, crash, unusual sign-in or file-encryption symptom. Approximate times are valuable because Event Viewer records events in local system time, while security products may use a different time zone or timestamp format.

Avoid deleting files or repeatedly restarting the computer before collecting evidence. If ransomware is actively encrypting files, disconnect the device from Wi-Fi or Ethernet and external drives. Do not open suspicious attachments again to reproduce the problem.

Sign in with an account that has administrative rights, then press Win + R, type eventvwr.msc, and press Enter. Event Viewer is built into Windows 10 and Windows 11, although the names and detail available in individual logs can differ between versions.

Navigate the relevant logs

The most useful area is Windows Logs > System. It records service starts, driver activity, unexpected shutdowns and changes involving core components. Windows Logs > Application contains application crashes and installer activity, while Security can show process creation if auditing has been enabled.

For a wider view, open Applications and Services Logs > Microsoft > Windows. Useful channels include TaskScheduler/Operational, PowerShell/Operational, Windows Defender/Operational, WMI-Activity/Operational and BITS-Client/Operational. Malware often abuses scheduled tasks, PowerShell, Windows Management Instrumentation or background transfer services.

Right-click a log and choose Save All Events As to preserve an .evtx copy. Export before clearing anything. Event Viewer files can contain usernames, computer names and other sensitive information, so store them securely and avoid uploading them to public forums.

Filter for suspicious timing

Select Filter Current Log and set a time range around the first known symptom. You can filter by event level, source, user and event ID. The Find option is useful for searching a filename, service name or keyword such as powershell, wscript, rundll32 or schtasks.

Important Windows event IDs include 4688 for a new process when process auditing is active, 7045 for a newly installed service, 4698 for a scheduled task created, and 1102 when the Security audit log is cleared. These IDs are clues rather than automatic proof of infection; administrators and legitimate installers can generate the same records.

Look for activity immediately before the first symptom. A suspicious pattern might show a newly created task, a script interpreter launching from a user-writable folder, followed by a browser crash or security warning. A normal-looking process can still be dangerous if its command line points to AppData, Temp, a downloads folder or an oddly named directory.

Compare common launch indicators

Event details become more useful when several logs support the same timeline. The following indicators are common during malware investigations:

Event or source What it may show Why it matters
Security 4688 New process and, when configured, its command line May reveal the executable or script that started the chain
System 7045 New Windows service Persistent malware sometimes installs a service
Security 4698 Scheduled task creation Helps identify recurring launches after login or at boot
TaskScheduler/Operational Task registration and execution Can expose triggers, paths and run times
Windows Defender/Operational Detection, quarantine or remediation Provides a second timestamp for comparison
PowerShell/Operational Script execution activity May support investigation of fileless or script-based threats

If process command lines are missing, auditing may not have been enabled before the incident. In that case, use the event’s General and Details tabs to capture the provider, event ID, timestamp, account and computer name. Correlate those details with Windows Defender history, installed-program dates and browser download records.

Inspect persistence mechanisms

Malware launch points often survive a reboot through scheduled tasks, services, startup folders or registry run entries. In Event Viewer, review task execution times and service installation events, then inspect the named item through Task Scheduler or the Services console. Do not disable a component solely because its name looks unfamiliar.

Check the file’s digital signature, publisher, location and creation date. Microsoft and hardware vendors commonly place trusted files in C:\Windows\System32, but a familiar filename in a different directory may be an impersonation. Search the exact path using a reputable security scanner rather than opening the executable.

Adware can create repeated browser or notification activity without behaving like a conventional virus. If the investigation points to unwanted system-tray alerts, compare the findings with this pop-up adware guide, which covers a related removal scenario.

Verify findings safely

Event Viewer evidence should be checked against Microsoft Defender scans, installed application lists, startup entries and the file system. A single failed service, unsigned program or PowerShell event does not establish that malware is present. Software updates, remote-support tools, printer utilities and corporate management agents can generate unusual-looking records.

Run an offline or full scan from Windows Security when practical, and use Safe Mode only when normal startup prevents cleanup. If a file is quarantined, preserve the detection name and path. For suspected ransomware, focus first on isolating the device and protecting backups rather than deleting every suspicious log entry.

Australian users can also consult guidance from the Australian Cyber Security Centre or report relevant scams through Scamwatch. Corporate devices may be governed by employer monitoring rules and the Privacy Act 1988, so forensic logs should be shared only with authorised staff. This website’s site disclaimer explains the informational nature of its security content.

Prevent clearer traces next time

Process creation auditing can be enabled through Local Security Policy under Advanced Audit Policy Configuration > Detailed Tracking > Audit Process Creation. Command-line logging for process creation can provide additional context, but it may expose sensitive arguments and increase log volume. On managed computers, an administrator should configure retention and central collection.

Keep Windows, browsers and security software updated, and enable tamper protection where supported. Limit daily work to a standard user account, disable unnecessary macros and treat unsolicited delivery notices, parcel messages and fake support calls with suspicion. These scams are common across Australian email and messaging habits, particularly when attackers imitate banks, Australia Post or government services.

Event Viewer works best as part of a timeline rather than as a standalone malware detector. Matching launch records with file paths, security detections and persistence changes can reveal where an infection began while preserving the evidence needed for a safer cleanup. For broader information about unwanted advertising software, see this adware security guide.

Stydco Scam Email Virus Removal Guide

A scam displayed on the rogue website Stydco.com, typically encountered through redirects from potentially unwanted programs. This guide explains how the scam operates and how to clean affected systems.

Read More