A dark cinematic close-up of a computer screen displaying abstract red warning indicators, with soft out-of-focus server rack lights glowing in the background, moody and tense atmosphere

Step-by-step removal guides for adware, browser hijackers, ransomware, trojans, and more — written for Windows and Mac users.

A wide shot of a laptop keyboard with a subtle red glow emanating from beneath the keys, shallow depth of field, dark and moody cybersecurity theme

Ransomware Removal Guides

Comprehensive ransomware removal instructions covering DJVU/STOP variants and other families. Includes references to decryptor tools from Emsisoft, Kaspersky, and NoMoreRansom, plus file recovery methods using Shadow Explorer.

Read More
A cinematic frame of a glowing padlock icon floating above a motherboard, cool blue tones with subtle amber warning lights, clean and technical atmosphere

Trojan Removal Guides

Step-by-step trojan identification and removal guides covering threats such as VB:Trojan.Agent.EIOB and Backdoor.PHP.WebShell.CT, with both manual and automatic removal methods.

Read More

Recent Stories

Helprestore@pcmalwareexpert.com Ransomware Removal Guide

Removing a Rootkit That Survives a Windows Reinstall

A rootkit that appears to return after a clean Windows installation may be hiding outside the normal Windows partition. The cause can be a UEFI bootkit, a compromised recovery environment, an infected second drive, a malicious device driver, or a false detection caused by security software. Treat the result as a possible boot-chain compromise until each persistence layer has been checked.

This process is intended for Windows users who need a careful, educational response rather than a remote removal service. Businesses in Sydney, Melbourne, Brisbane and elsewhere in Australia should involve their IT provider early, especially when the computer stores customer records, health information or payment data.

Map the persistence layer

A Windows reinstall removes files from the selected system partition, but it may leave other storage areas untouched. The following comparison helps identify what a reinstall can and cannot normally clean:

Persistence location Can a standard reinstall remove it? Appropriate response
Windows system partition Usually Delete all partitions and install to unallocated space
EFI System Partition Sometimes Remove it during a full disk wipe
Second internal or USB drive No, if left connected Disconnect, scan, or securely erase it
UEFI or device firmware No Update firmware and load verified defaults
Router, NAS or recovery media No Reset, patch and recreate from trusted sources
Cloud-synchronised files No Review synced installers and credentials

Before wiping anything, photograph warning messages and record detection names, file paths, timestamps and security-tool logs. A suspected rootkit can be confused with a damaged bootloader, an OEM utility, or a persistent unwanted application. If evidence may be needed for an employer or insurer, preserve it before making changes.

Isolate the computer safely

Disconnect Ethernet and disable Wi-Fi from a clean device or the router. Unplug external hard drives, USB sticks, docks and phone storage. Do not sign in to banking, email, cryptocurrency or business accounts from the suspect installation. In Australia, contact your bank immediately if payment credentials may have been exposed, and report relevant scams through Scamwatch where appropriate.

Prepare a trusted computer for downloading tools and creating installation media. Obtain Windows installation media and firmware updates directly from Microsoft and the computer or motherboard manufacturer. Avoid “free driver updater” sites and unofficial activators, which frequently bundle trojans or tampered boot files.

Check firmware and boot security

Enter UEFI setup using the manufacturer’s documented key, commonly Delete, F2 or Esc. Record the current boot order, then load UEFI defaults. Enable Secure Boot, TPM or firmware security where supported, and disable booting from external media after the repair is complete. A Secure Boot warning, unfamiliar boot entry or unexpected administrator password deserves careful attention.

Download the latest BIOS or UEFI firmware using the model and revision printed on the device. Verify the vendor’s instructions and, where available, the published checksum. Apply the update from a trusted USB drive, keep mains power connected, and never interrupt the process. For a laptop, charge the battery as well. Firmware flashing varies by manufacturer, so a business device should be handled by its authorised technician.

Wipe every internal drive

Boot from the trusted Windows installer, select the custom installation option, and identify every internal drive by capacity and model. If there is any uncertainty, stop and verify the hardware rather than deleting the wrong disk. Disconnecting secondary drives before starting is safer than relying on drive numbers.

On the intended system disk, remove every partition, including recovery and EFI partitions, until the installer shows unallocated space. For a suspected rootkit, use the manufacturer’s secure-erase or sanitize function for an SSD where available; repeated overwriting is generally unsuitable for modern solid-state storage. If a second disk was connected during the suspected infection, erase or replace it before reconnecting. A Locky removal guide also illustrates why examining the delivery mechanism matters, rather than focusing on the visible payload alone.

Reinstall from a verified source

Create fresh installation media on the clean computer and boot it in UEFI mode. Install Windows to the wiped disk, allow Windows Update to install current security fixes, and obtain drivers from the manufacturer. Avoid restoring an old system image, cloned disk or unknown recovery partition until it has been scanned and its origin is confirmed.

Create a separate standard user account for everyday work and keep the administrator account for maintenance. Turn on Microsoft Defender, tamper protection, firewall protection and reputation-based security. If a business uses endpoint detection and response, install its agent from the organisation’s approved portal instead of copying an installer from the compromised machine.

Rebuild the surrounding environment

Change passwords from the clean installation or another trusted device, beginning with email, Microsoft accounts, banking, password managers and remote-access services. Revoke active sessions, rotate recovery codes and enable multifactor authentication. If the same password was reused across services, treat every account using it as exposed.

Reset the home or office router, update its firmware and set a new administration password. Review DNS, port forwarding, remote management and connected clients. NBN connections in Australia commonly use consumer routers supplied by an internet provider, so check both the router’s local settings and the provider’s customer portal. A second device can reintroduce malware through shared folders, USB media or synchronised installers; this is also why a proxy hijacker guide is useful when unexplained browser traffic continues after reinstalling Windows.

Validate before restoring data

Run an offline scan from trusted security media, then perform a full scan after Windows is updated. Inspect UEFI boot entries, Device Manager, scheduled tasks, services, startup locations and browser extensions. Check that Secure Boot remains enabled and that the system clock, DNS settings and proxy configuration have not changed unexpectedly.

Restore personal documents selectively, starting with files that have been scanned on a separate system. Do not restore executable files, scripts, cracked software, unknown macros or old browser extensions. Monitor network connections and security alerts for several days. If suspicious command-and-control activity involves a chat application, review the Discord malware guide before reinstalling that application.

Escalate serious compromises

A rootkit that remains after firmware updating, full disk sanitisation and a verified reinstall may indicate an infected peripheral, malicious firmware, a compromised network device or a mistaken detection. Replace suspect storage or peripherals and have the device examined by the manufacturer or a qualified incident-response professional. Do not repeatedly reinstall Windows while leaving the same unverified devices attached.

Australian organisations should document the incident, preserve logs and assess notification duties under the Privacy Act 1988 and the Notifiable Data Breaches scheme. Follow the Australian Cyber Security Centre’s Essential Eight guidance for supported systems, application control, patching, multifactor authentication and regular backups. Keep at least one backup offline or otherwise protected from the computer’s everyday credentials.

Stydco Scam Email Virus Removal Guide

A scam displayed on the rogue website Stydco.com, typically encountered through redirects from potentially unwanted programs. This guide explains how the scam operates and how to clean affected systems.

Read More