A fake virus pop-up on Windows 11 can look frighteningly real. It may use a Microsoft Defender, McAfee, Norton, Chrome, or Edge logo; claim that several viruses were found; play an alarm; or tell you to call a toll-free number immediately. The warning may even appear in the Windows notification area after you close the browser.



In many cases, the PC is not infected. The alert is a deceptive webpage or a website notification that was allowed—often after a page asked the visitor to click Allow to prove they were human, watch a video, or download a file. In other cases, persistent redirects, unknown extensions, or recently installed software can indicate adware or malware that deserves a proper scan.

This guide explains how to tell the difference and remove the source safely in Google Chrome and Microsoft Edge. It also covers what U.S. users should do if they called the number, paid the scammer, shared personal information, or allowed remote access. Instructions and official sources were checked on August 15, 2026.

Quick Answer

Do not click the warning or call the number. Close the tab with Alt + F4; if the browser will not close, open Task Manager with Ctrl + Shift + Esc and end the browser task. Reopen Chrome or Edge without restoring the suspicious tab, remove unknown websites from the browser's notification permissions, review extensions and installed apps, then run an updated Windows Security scan. If anyone had remote access or received your payment or personal data, secure your accounts and contact your bank immediately.

Key Takeaways

  • A warning with a phone number is a major scam signal. Microsoft says its genuine error and warning messages do not include phone numbers.
  • A notification in the lower-right corner can come from a website even when the browser window is closed.
  • Blocking all Windows notifications only hides the symptom; removing the site's permission in Chrome or Edge fixes the source.
  • One fake alert does not prove that malware is installed, but repeated redirects, changed browser settings, and unknown apps justify a deeper scan.
  • Use Windows Security and official browser settings before downloading any third-party “cleanup” tool.
  • If a scammer obtained remote access, money, a password, or a Social Security number, treat it as an account and identity-security incident—not only a browser problem.
If the warning is open right now: do not press Scan, Remove, Renew, Allow, Download, or any close button drawn inside the webpage. Do not call its number. Use the keyboard steps below to close the browser safely.

Is the Virus Warning Real or Fake?

A real security alert should be verifiable inside the security product that generated it. For Microsoft Defender, open Start → Windows Security → Virus & threat protection → Protection history. If the alarming browser message has no matching event there, that is evidence that the webpage or notification—not Windows Security—created the warning.

Fake alerts rely on urgency. They may claim your files, subscription, banking information, or IP address is at risk. Some place the browser in full-screen mode, repeat dialog boxes, or play speech that tells you not to turn off the computer. These effects can make a webpage resemble a system screen, but a website cannot diagnose every file on your PC simply because you opened a page.

What you see Most likely source Best first action
Small alert in the lower-right corner showing a strange website address Browser website notification Block the site in Chrome or Edge notification settings
Full-screen page, loud alarm, countdown, or phone number Tech-support scam webpage Force-close the tab or browser; do not interact with the page
New tabs, redirects, changed homepage, or extensions that return Unwanted extension, adware, or altered browser settings Remove extensions/apps, reset the browser, and scan Windows
Alert recorded in Windows Security Protection history Potentially genuine Microsoft Defender detection Follow the action shown in Windows Security and update definitions
A caller requests remote access, gift cards, crypto, or bank transfers Tech-support or impersonation scam End contact, disconnect remote access, and secure financial accounts
Brand-name warning: a pop-up can copy the logo of a legitimate security company. That does not mean the company sent it. If you actually subscribe to that product, open the installed app from the Start menu and check its status there—never through the pop-up.

Step 1: Close a Fake Virus Pop-Up Safely

Start with the least disruptive option. Avoid clicking anywhere inside the suspicious page because even a button labeled “Cancel” or an X can be part of the scam.

Leave full-screen mode

Press Esc or F11. This may reveal the normal browser controls, but do not interact with the suspicious tab itself.

Close the active window

Press Alt + F4. Save other work first when possible because this closes the active browser window and its tabs.

End the browser task

If the window stays locked, press Ctrl + Shift + Esc, select Chrome or Microsoft Edge in Task Manager, and choose End task. This can close every window for that browser.

Use the Windows security screen

If Task Manager will not appear, press Ctrl + Alt + Delete and choose Task Manager, Sign out, or Restart. A normal restart is safer than holding the physical power button.

When the browser opens again, decline any prompt to restore the previous session if it would reopen the suspicious page. If the bad tab returns automatically, disconnect the internet temporarily, open the browser settings, and continue with the permission and reset steps below.

Step 2: Remove Fake Virus Notifications From Google Chrome

Chrome website notifications can appear through the Windows notification system, which makes them look like operating-system alerts. Removing the site's permission stops the source instead of merely muting Chrome in Windows.

  1. Open Chrome and select the three-dot menu.
  2. Open Settings → Privacy and security → Site Settings → Notifications.
  3. Review the sites under the list allowed to send notifications.
  4. For every domain you do not recognize or trust, open its menu and select Block or Remove.
  5. Consider enabling Chrome's quieter notification prompts so unfamiliar sites cannot interrupt you with aggressive requests.
  6. Restart Chrome and watch whether the false warnings return.

You can also manage a site's permission from the address bar while visiting a trusted page: select the site-information icon, find Notifications, and choose Block. Do not revisit a known scam page merely to change this setting; use the full settings list instead.

Fast diagnosis: if the warning contains a random domain name and disappears immediately after that domain is blocked, it was probably notification spam—not proof of a Windows virus.

Step 3: Remove Fake Virus Notifications From Microsoft Edge

Microsoft explains that website notifications can continue to appear in the lower-right corner and Notification Center even when Edge is closed. Use Edge's site permissions to revoke access.

  1. Open Microsoft Edge and select Settings and more (the three-dot menu).
  2. Choose Settings → Privacy, search, and services → Site permissions → All sites.
  3. Select an unfamiliar site that has been sending warnings.
  4. Find Notifications and change the permission to Block.
  5. Repeat the process for every suspicious domain.
  6. Close and reopen Edge.

If you are already on a site you trust, the site-information icon to the left of the address bar also provides a notification permission. Again, do not reopen a scam site just to access that shortcut.

Pop-ups and notifications are different: a pop-up opens inside a browser window or tab. A website notification appears through the Windows notification area. You may need to block both, but notification permission is the most common reason alerts continue after the original tab is closed.

Step 4: Block Browser Pop-Ups and Redirects

After removing notification permissions, verify that pop-up and redirect protection is active.

In Google Chrome

  1. Open Settings → Privacy and security → Site Settings.
  2. Select Pop-ups and redirects.
  3. Use the option that does not allow sites to send pop-ups or use redirects.
  4. Remove unfamiliar domains from any allowed list.

In Microsoft Edge

  1. Open Settings → Cookies and site permissions or the current Site permissions section.
  2. Select Pop-ups and redirects.
  3. Make sure blocking is enabled.
  4. Remove suspicious sites from the Allow list.

Pop-up blocking reduces interruptions but is not an antivirus scan. If the browser continues to redirect on many unrelated websites, inspect extensions, applications, and Windows Security next.

Step 5: Remove Suspicious Browser Extensions

An unwanted extension can inject ads, change search results, replace the homepage, read browsing activity, or restore permissions after you remove them.

Chrome

  1. Select the three-dot menu → Extensions → Manage extensions.
  2. Review every extension, especially anything installed near the time the problem began.
  3. Remove extensions you did not intentionally install or no longer need.
  4. Disable uncertain extensions one at a time and test the browser.

Microsoft Edge

  1. Select the three-dot menu → Extensions → Manage extensions.
  2. Turn off or remove unknown add-ons.
  3. Restart Edge and check whether redirects or warnings continue.
Work and school PCs: an extension marked “managed by your organization” may be required by an administrator. Do not edit policies or the Registry to remove it. Contact the IT administrator if you do not recognize the extension.

Step 6: Check Recently Installed Windows Apps

Browser notification spam does not normally install an app by itself. However, if you downloaded a “cleaner,” “driver updater,” browser helper, remote-support tool, or security program after seeing the warning, review installed software.

  1. Open Settings → Apps → Installed apps.
  2. Sort by installation date if that option is available.
  3. Look for software installed when the warnings began.
  4. Research the exact publisher and product name using the developer's official website.
  5. Uninstall software you know came from the scam or that the scammer asked you to install.
  6. Restart Windows.

Do not remove an unfamiliar Microsoft, Intel, AMD, NVIDIA, Realtek, Dell, HP, Lenovo, or other hardware component merely because its name is technical. If you are unsure, leave it in place until you verify what it does.

Step 7: Run Windows Security Scans

Even when the original alert was fake, a scan is sensible if you clicked a download, installed a program, enabled an extension, or allowed remote access. Windows 11 includes Microsoft Defender Antivirus through the Windows Security app.

  1. Open Start → Windows Security → Virus & threat protection.
  2. Under protection updates, check for the latest security intelligence.
  3. Run a Quick scan first.
  4. Open Scan options and select Full scan if you downloaded or installed anything suspicious.
  5. Review Protection history after the scan and follow Windows Security's recommended actions.

A full scan can take a long time and use considerable disk and processor resources. Let it finish. Do not install several real-time antivirus products at once, because they can conflict and reduce performance.

When to use Microsoft Defender Offline

Use the offline scan when malware keeps returning, Windows Security recommends it, or you have strong reason to suspect a persistent infection. Save open work first because the computer will restart.

  1. Open Windows Security → Virus & threat protection → Scan options.
  2. Select Microsoft Defender Antivirus (offline scan).
  3. Choose Scan now.
  4. Allow the PC to restart and complete the scan in the recovery environment.
  5. After Windows starts again, open Protection history to review the result.
Do not pay for a mystery cleanup app: fake-alert pages often advertise the very software they want you to install. Start with Windows Security and the official browser controls. If you choose another security product, obtain it directly from a vendor you independently trust.

Step 8: Reset Chrome or Edge if the Problem Continues

A browser reset is useful when the homepage, search engine, startup tabs, content permissions, or extensions keep changing. It should come after you record any settings you need.

Reset Chrome

  1. Open Chrome Settings → Reset settings.
  2. Select Restore settings to their original defaults.
  3. Confirm Reset settings.

Google says this does not delete saved bookmarks or passwords. It resets items such as the default search engine, startup behavior, content settings, cookies, themes, and extensions. You may need to sign in to websites again and re-enable only the extensions you trust.

Reset Microsoft Edge

  1. Open Edge Settings → Reset settings.
  2. Select Restore settings to their default values.
  3. Read the confirmation carefully and select Reset.

If the browser is managed by an employer or school, contact the administrator before resetting it. If resets do not hold and unknown settings return after every restart, run the offline scan and seek trusted technical help.

What to Do if You Called the Number or Allowed Remote Access

Do not feel embarrassed. Tech-support scams are designed to create fear and rush reasonable people into acting. Focus on limiting access and protecting accounts.

Disconnect the session

If the scammer is still connected, disconnect Wi-Fi or unplug Ethernet. Close the remote-support program and shut down the PC if you cannot end the session safely.

Remove remote-access tools

From Installed apps, uninstall software the caller asked you to install. Common legitimate remote-support programs can be abused by scammers, so the issue is who received access—not only the program's brand.

Scan and update

Update Windows Security, run a Full scan, and use Microsoft Defender Offline if access was extensive or suspicious software persists.

Secure accounts from a clean device

Change the password for your primary email first, then banking, shopping, social, and Microsoft or Google accounts. Replace reused passwords and enable two-factor authentication.

Check email forwarding rules, recent sign-ins, recovery addresses, and bank transactions. If the scammer saw sensitive documents or obtained a Social Security number, visit IdentityTheft.gov for a personalized U.S. recovery plan.

Do not log in to banking or email from a PC you still believe is compromised. Use a different trusted device to change passwords and contact financial institutions first.

What to Do if You Paid the Scammer

Act quickly. Recovery is not guaranteed, but the U.S. Federal Trade Commission says it is always worth asking the company used to send the money whether the transaction can be reversed.

  • Credit or debit card: call the issuer using the number on the back of the card, report a fraudulent charge, and ask about reversal and card replacement.
  • Bank transfer: contact the bank's fraud department and report an unauthorized or fraudulent transfer.
  • Payment app: report the transaction to the app and to the linked bank or card issuer.
  • Gift card: contact the issuer immediately, keep the card and receipt, and ask whether funds can be frozen or refunded.
  • Wire transfer: contact the wire service or bank immediately and request a reversal.
  • Cryptocurrency: transactions are usually difficult or impossible to reverse, but notify the exchange or service used and report the fraud.

Report the incident at ReportFraud.ftc.gov. If the scam involved identity information, also use IdentityTheft.gov. Keep screenshots, receipts, phone numbers, email messages, transaction IDs, and the names of remote-access applications, but do not continue communicating with the scammer to collect more evidence.

How to Prevent Fake Virus Alerts

  • Never click Allow because a site says it is required to prove you are human, remove a virus, start a download, or watch a video.
  • Never call a phone number displayed in a virus pop-up.
  • Download browsers, updates, and security tools from their official websites—not from sponsored ads or pop-up pages.
  • Keep Chrome, Edge, Windows, and security intelligence updated.
  • Review website notification permissions and browser extensions periodically.
  • Use unique passwords and enable two-factor authentication on email and financial accounts.
  • Keep an offline or protected backup of important personal files.
  • Teach family members that legitimate companies do not demand gift cards, cryptocurrency, secrecy, or unexpected remote access.

Keeping Windows current also closes security weaknesses used by real malware. If updates fail or remain frozen, follow our safety-first guide to fix a Windows 11 update stuck at 0%, 99%, or 100% using built-in Microsoft tools.

What Not to Do

  • Do not call the number in the warning.
  • Do not grant remote access to an unsolicited caller.
  • Do not pay with gift cards, cryptocurrency, or a bank transfer to “unlock” the PC.
  • Do not install a cleaner, driver updater, browser extension, or antivirus promoted by the pop-up.
  • Do not disable Windows Security because a webpage tells you to.
  • Do not edit the Registry or run random PowerShell, BAT, or cleanup scripts from forums.
  • Do not assume a clean scan alone makes exposed passwords or financial details safe; secure the accounts separately.

When to Get Professional Help

Contact the PC manufacturer, a trusted local technician, or your organization's IT department if the browser remains hijacked after a reset, Windows Security cannot complete a scan, security settings turn themselves off, unknown administrator accounts appear, files become encrypted, or the same malware returns after an offline scan.

For a work or school PC, report the incident before uninstalling managed tools or resetting Windows. If you decide that Windows must be reset after confirmed remote compromise, back up personal documents carefully and use Microsoft's built-in Recovery options. Do not preserve suspicious installers, scripts, or executable files in that backup.

Explore more tested troubleshooting articles in the ACSNETWORLD Windows guides.

Frequently Asked Questions

Why do virus alerts appear when I do not have that antivirus installed?

A website can copy a security company's name or logo and send browser notifications after permission was granted. The branding does not prove that the company's software is installed. Check the notification's website address and verify real detections inside Windows Security or your legitimately installed security app.

Are fake virus pop-ups always caused by malware?

No. A single alert is often a deceptive webpage or an allowed website notification. Malware or adware becomes more likely when redirects occur across many sites, browser settings keep changing, unknown extensions return, or Windows shows other unusual behavior.

Why do alerts continue after I close Chrome or Edge?

Websites with notification permission can deliver alerts through the Windows notification system, and Microsoft says Edge notifications may appear even when Edge is closed. Remove or block the suspicious website inside the browser's notification permissions.

Will resetting Chrome delete my bookmarks and passwords?

Google states that restoring Chrome settings does not delete saved bookmarks or passwords. It resets items such as the search engine, startup pages, content settings, cookies, themes, and extensions, so you may need to sign in again and re-enable trusted extensions.

Should I install another antivirus after seeing a fake warning?

Not automatically. Windows 11 includes Microsoft Defender Antivirus. Update it and run the appropriate scan first. Avoid running multiple real-time antivirus products together, and never install software promoted by the suspicious pop-up.

What should I do if I gave the scammer my Social Security number?

Visit the official IdentityTheft.gov website from a trusted device to report the exposure and receive a personalized recovery plan, including appropriate credit-monitoring or fraud-protection steps. Also review financial accounts and change any passwords or verification details the scammer received.

Can a browser pop-up lock my Windows 11 computer?

A malicious page can use full-screen mode, repeated dialogs, and audio to make the browser appear locked. Try Esc or F11, then Alt + F4. If necessary, use Ctrl + Shift + Esc to end the browser task. A persistent lock outside the browser needs deeper security troubleshooting.

Article Changelog

Published with current Chrome and Microsoft Edge notification steps, Windows Security scanning guidance, scam-recovery actions for U.S. readers, official sources, and a safety-first troubleshooting order.
Advertisement