If the popups return after every restart even after full scans, MRT, Safe Mode, and Microsoft Defender Offline, that matches the documented pattern where a hidden component is reinstalling malware or unwanted software at startup.
Recommended next steps:
- Run Microsoft Defender Offline again if not already done from Windows Security
- Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection.
- Select Scan options.
- Select Windows Defender Offline scan > Scan now.
- Save work first, because the PC restarts before the scan.
- Make sure Microsoft Defender protection features are enabled before scanning again
- Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection.
- Under Virus & threat protection settings, select Manage settings.
- Turn Cloud-delivered protection and Automatic sample submission On.
- Then under Virus & threat protection updates, select Check for updates and update threat definitions.
- Remove suspicious software and browser add-ons
- Go to Start > Settings > Apps > Apps & features.
- Sort by install date and uninstall anything unknown or recently added around the time of infection.
- Remove suspicious browser add-ons as well.
- This is especially relevant because unwanted software can persist through installed apps or browser modifiers.
- Avoid the original download source and similar sites
- Malware can return if the same site, download, or email attachment is used again.
- Use official download sources or the Microsoft Store.
- Use Microsoft Edge with SmartScreen protection when browsing.
- If the system still shows popups or suspicious behavior, reset the PC
- Back up files first.
- Restore only from backups created before the infection if possible, because backups present during infection may already be modified.
- After reset or reinstall, update Windows and installed software immediately.
Given the account compromise already occurred, the practical cutoff is:
- If startup popups continue after Offline scan, updated definitions, and uninstalling suspicious apps/add-ons, treat the system as not trustworthy and reset or reinstall Windows.
- After cleanup or reset, continue using only clean backups and updated software.
References: