A dark cinematic close-up of a computer screen displaying abstract red warning indicators, with soft out-of-focus server rack lights glowing in the background, moody and tense atmosphere

Step-by-step removal guides for adware, browser hijackers, ransomware, trojans, and more — written for Windows and Mac users.

A wide shot of a laptop keyboard with a subtle red glow emanating from beneath the keys, shallow depth of field, dark and moody cybersecurity theme

Ransomware Removal Guides

Comprehensive ransomware removal instructions covering DJVU/STOP variants and other families. Includes references to decryptor tools from Emsisoft, Kaspersky, and NoMoreRansom, plus file recovery methods using Shadow Explorer.

Read More
A cinematic frame of a glowing padlock icon floating above a motherboard, cool blue tones with subtle amber warning lights, clean and technical atmosphere

Trojan Removal Guides

Step-by-step trojan identification and removal guides covering threats such as VB:Trojan.Agent.EIOB and Backdoor.PHP.WebShell.CT, with both manual and automatic removal methods.

Read More

Recent Stories

Helprestore@pcmalwareexpert.com Ransomware Removal Guide

Removing full-screen video login adware from your computer

Nothing derails a morning quite like an uninvited video playing the moment you reach the desktop. Across Sydney, Melbourne and Brisbane, support desks have fielded a steady stream of calls about a stubborn adware strain that hijacks the Windows logon screen and forces a looping promotional clip to run in full view. The behaviour is disruptive, but it sits firmly inside routine removal rather than genuine ransomware.

The adware piggybacks on bundled installers, fake "media player" updates and cracked software downloads. Once it lands, it registers as a startup component tied to the user logon phase, which is why it survives reboots and refuses to close. You will usually see no obvious process in Task Manager, because the video is driven by a scheduled task or service that fires before the desktop fully loads.

Australia's Cyber Security Centre has repeatedly flagged bundled adware as a leading consumer-level threat, and local providers such as Telstra and Optus publish advisories whenever a new wave starts circulating. Cleanup is similar to any persistent adware, though the login-screen angle requires extra steps before normal removal tools can do their job.

This walkthrough focuses on Windows, since that is where the logon hijack occurs, and notes where Mac users should pivot to a separate procedure. You will need about thirty minutes, a clean backup, and a willingness to boot into Safe Mode first.

How to recognise this type of infection

The classic symptom is a full-screen advertisement, often for a dating service, "system cleaner" or cryptocurrency miner, that starts immediately after you enter your Windows password. Unlike a browser pop-up, it covers the entire display, blocks input, and continues running even if you launch Task Manager from another account.

A second tell is that the volume is set to maximum, the mouse cursor is hidden, and closing the window either does nothing or spawns a second advertisement. If your computer was fine yesterday but started behaving this way after installing a free PDF converter or video codec, the cause is almost certainly bundled adware.

Booting into Safe Mode to regain control

Safe Mode loads only the drivers and services Windows needs, which prevents the adware's startup hook from firing. On Windows 10 or 11, hold Shift while clicking Restart from the Start menu, choose Troubleshoot, then Advanced options, then Startup Settings, and press the number key for Safe Mode with Networking.

Mac users who picked up the same payload through Safari should consult a macOS recovery mode guide instead, because the logon hijack does not occur on macOS but the browser-side infection is just as stubborn. Working from Safe Mode means the next steps will actually take effect.

Removing the startup hooks that trigger the video

Once you are back in a usable desktop, open Task Manager and switch to the Startup tab. Anything you do not recognise, especially entries without a publisher name, should be disabled. Repeat the process in System Configuration under the Services tab, ticking "Hide all Microsoft services" first.

These are the four persistence points this adware family typically abuses, and where to disable each one.

Persistence point Where to find it How to disable it
Startup folder shortcut %AppData%\Microsoft\Windows\Start Menu\Programs\Startup Delete the .lnk file
Registry Run value HKCU\Software\Microsoft\Windows\CurrentVersion\Run Delete the suspicious value
Scheduled task Task Scheduler → Task Scheduler Library Right-click and Disable
Windows service services.msc Set Startup type to Disabled

After clearing these, restart normally and confirm the full-screen advertisement no longer appears. If it returns, repeat the Safe Mode boot and look for a second layer, often a WMI event consumer or Winlogon notification package, both of which require manual removal.

Cleaning the browser layer

Even after the logon video is gone, the same installer usually drops a browser hijacker that rewrites your homepage, injects sponsored search results and pushes pop-under tabs. Open your browser's extension list and remove anything you did not install yourself, then reset the homepage, default search engine and new tab page to the values you actually want.

Reset settings rather than reinstalling the browser, because the hijacker often writes policies into the Registry that survive a clean install. Check HKCU\Software\Policies and HKLM\Software\Policies for any browser-related keys that look non-standard, then clear cookies and site data so injected redirect rules are flushed.

Running a dedicated anti-malware scan

With the obvious hooks removed, run a full system scan with a reputable on-demand scanner. Tools such as Malwarebytes, ESET Online Scanner or the Microsoft Malicious Software Removal Tool will catch remnants that manual cleanup misses, particularly DLL side-loading and the installer dropper itself.

Allow the scan to quarantine everything it flags, then restart once more. A second scan after the reboot is a useful sanity check, since some variants lay dormant for several minutes before re-establishing themselves.

Checking deeper persistence points

Sophisticated variants borrow techniques from more dangerous malware families. They create services with innocuous names such as "WindowsAudioService" or "SystemPerformanceCheck", and hide payloads inside scheduled tasks that only trigger at midnight AEST. Open services.msc, sort by Description, and investigate anything that points to %ProgramData% or %AppData% rather than C:\Windows.

The same diligence applies to anything resembling a database-backed payload. Readers who maintain local SQL servers for point-of-sale or clinic management should review our SQL server ransomware removal guide, because the persistence techniques overlap even though the threat actors differ.

Hardening the system against reinfection

Once the system is clean, a few habits will keep it that way. Download software only from official vendor sites or the Microsoft Store, decline bundled "optional offers" during installation, and keep User Account Control enabled. Enable Microsoft Defender's reputation-based protection and the Potentially Unwanted Application blocking feature.

Finally, treat any unfamiliar executable with suspicion, especially if it arrived through a social media advert or a sponsored search result. A clean install of Windows is faster than a long cleanup, so keep a recent image backup ready and you will never feel pressured to tolerate stubborn adware.

Stydco Scam Email Virus Removal Guide

A scam displayed on the rogue website Stydco.com, typically encountered through redirects from potentially unwanted programs. This guide explains how the scam operates and how to clean affected systems.

Read More