When adware opens a command window at login and disappears
A black Command Prompt or PowerShell window that flashes up when Windows starts can be unsettling, particularly when it closes before you can read it. This behaviour is often linked to an unwanted startup command, browser adware, a scheduled task, or a bundled program that runs briefly in the background.
The disappearing window does not prove that the computer is infected, since some legitimate drivers, cloud clients and update tools use short scripts during sign-in. However, repeated pop-ups, browser redirects, new extensions, sluggish performance or unfamiliar adverts make adware and a potentially unwanted program more likely.
Avoid typing commands into the window or downloading a “fix” from a pop-up. On a Windows computer in Sydney, Melbourne or anywhere else in Australia, start by disconnecting from the internet if the activity appears aggressive, then save important documents to a trusted backup before changing startup settings.
A login command can also be a symptom of a broader threat. Trojans may use similar persistence methods, so review the guidance on trojan activity if you notice password theft warnings, unknown remote-access software or unusual banking activity.
Check what happens at sign-in
First, record the timing and visible details. Use your phone to capture the window if it stays open long enough, noting whether the title mentions cmd.exe, PowerShell, a script file, an unfamiliar company or a path under AppData. Do not open the displayed path manually.
Open Task Manager with Ctrl, Shift and Esc, then select Startup apps. Disable entries you do not recognise, but leave Microsoft, graphics, audio, security and hardware components alone until you have verified them. Check the publisher and startup impact rather than relying only on an unusual name.
You can also inspect Settings > Apps > Startup and the Startup folder by entering shell:startup in the Run dialog. A blank or meaningless publisher is a reason to investigate, not automatic proof of malware.
Find the hidden persistence method
If the window appears only at login and vanishes, the trigger may be a scheduled task. Search for Task Scheduler, open Task Scheduler Library, and review tasks that run at logon or startup. Examine the Actions tab for scripts, PowerShell parameters, temporary folders, random filenames or commands that launch a browser.
Also inspect the Windows Run keys through trusted security software or a reputable utility such as Microsoft Autoruns. Avoid editing the Registry directly unless you have a restore point and know exactly which entry is involved. Removing the wrong key can prevent a legitimate driver or accessibility tool from loading.
Common warning signs include:
- A script launches from
%AppData%, %Temp% or a randomly named folder.
- The task has no clear publisher, description or installed program.
- A browser opens with unwanted search pages after the command window closes.
- The entry returns after you disable it.
Scan before deleting files
Run a full scan with Windows Security, including Microsoft Defender Offline if available. The offline scan restarts the PC and checks before the normal Windows environment loads, which can help when adware protects its files during a regular session.
Add a second-opinion scan from a well-known security vendor if the first result is clean but the behaviour continues. Keep only one real-time antivirus product active, and download tools from their official websites rather than from advertisements or search results.
Safe checks during cleanup
- Disconnect Wi-Fi or Ethernet if redirects or suspicious downloads continue.
- Boot into Windows Safe Mode when normal startup blocks removal.
- Quarantine detected items instead of manually deleting system files.
- Restart twice and check whether the command window returns.
Do not trust a sudden full-screen warning claiming that your PC is locked or that you must call a support number. Guidance about fake blue-screen scams explains why these messages are commonly used to pressure people into installing remote-access tools.
Remove related browser changes
Adware often leaves more than a startup entry. In Chrome, Edge or Firefox, review extensions, notification permissions, the default search engine and the list of pages that open at launch. Remove items you did not install and reset the browser if redirects persist.
Uninstall unfamiliar applications from Settings > Apps > Installed apps, sorting by installation date. Check whether the program appeared shortly before the command window began. Some free download bundles use vague names such as “Search”, “Assistant” or “Update”, while legitimate Australian banking and government software should still be obtained from official sources.
Clear suspicious notification permissions rather than allowing every website to send alerts. If the browser keeps returning to the same unwanted page, create a fresh browser profile after scanning the computer.
| Symptom |
Likely area to inspect |
Safer response |
| Window flashes once at login |
Startup app or Run key |
Verify the publisher and disable the unknown entry |
| PowerShell appears repeatedly |
Scheduled task or script |
Review task actions and scan the script location |
| Ads appear in every browser |
Extension or notification permission |
Remove unfamiliar extensions and reset permissions |
| Entry returns after removal |
Active malware or policy setting |
Use Safe Mode and an offline security scan |
Protect accounts and personal files
If the command window ran unknown scripts, assume that passwords entered during the affected period may be exposed, especially if browsers stored them. From a clean device, change email, banking, shopping and social-media passwords, then enable multifactor authentication. Contact your bank promptly if transactions or login alerts look unfamiliar.
Keep backups disconnected when they are not being used. Ransomware and destructive malware can reach external drives and synced folders, so a USB backup should not remain plugged in all the time. This is particularly important for family photos, tax records and small-business files.
If files become renamed, encrypted or replaced by ransom notes, stop experimenting with random decryptors. Preserve a copy of the affected files and seek guidance from a reliable security source, including the resources at Pc Malware Expert.
Confirm the computer is clean
After removing the suspicious entry, restart normally and observe the next few sign-ins. Check Task Manager, scheduled tasks and browser behaviour again. A clean result should include no unexplained command window, no recurring redirects and no new extensions or applications.
Install Windows updates, update browsers and enable reputation-based protection in Windows Security. Be cautious with “free” video converters, cracked software and unofficial streaming add-ons, as these are common delivery routes for adware in the Australian market.
Keep User Account Control enabled and download programs from their original vendors. If the command window returns after scans and startup cleanup, preserve scan logs and consider professional incident response rather than repeatedly deleting files at random.