Fake “Windows Security Alert” Popup: What To Do (a Corstorphine Guide)

A full-screen alert screaming that your PC is infected, with an alarm sound and a phone number to call — it looks like Windows, but it isn’t. It’s a webpage designed to scare you into ringing a scammer.

11 August 2026 7 min read Cybersecurity Alex M.
Fake Windows Security Alert Popup — What It Is and How to Deal With It in Corstorphine

Every couple of weeks a laptop comes in from Corstorphine with the same story. Someone was reading the news or clicking a link on Facebook, the browser jumped to full-screen, an alarm started playing, and a red “Windows Security Alert — do not shut down your computer!” page appeared with a phone number claiming to be Microsoft. The person either couldn’t close it, or they rang the number and were talked into installing something.

This is one of the most common cybersecurity calls we take across west Edinburgh — from St John’s Road all the way out towards the Gyle, and up into Murrayfield and Sighthill. If it’s happening to you right now, here’s how to close it, and here’s what to check if you got as far as speaking to them. If you’d rather we just handle it in person, the local Corstorphine virus removal service is the fastest route.

Why It Isn’t Actually a Virus

This is the piece almost every guide leaves out. The scary page you’re looking at is not malware, and Windows Defender didn’t miss anything. It’s an ordinary webpage — HTML, a bit of JavaScript, and an autoplaying audio clip — being served by a random website. The site tells your browser to go full-screen, play the alarm, and block the back button. All of those are things browsers legitimately allow (Netflix uses full-screen, YouTube autoplays audio, banking sites warn before you close the tab), so an antivirus can’t just kill them without breaking real sites too.

That’s why nothing on your PC has caught anything. The moment you close the tab, the “alert” is gone. There is no infection to remove — unless you rang the number, in which case skip down to the section on that.

How to Close It Right Now, Safely

Try these in order. One of them will work:

  1. Press Esc. That drops the browser out of full-screen, so you can see the tab bar again. Then click the tiny X on the offending tab.
  2. If Esc does nothing, press Ctrl + W. That closes the active tab. Some scam pages catch this and pop a “are you sure you want to leave?” box — click Leave, not Stay.
  3. If the browser is fully locked up, press Ctrl + Shift + Esc. That opens Task Manager directly. Find your browser (Chrome, Edge, Firefox) in the list, click it, click End task. The whole browser closes.
  4. When you reopen the browser, do NOT click “Restore pages”. That will bring the scam page straight back. Start a fresh window instead.

Under no circumstance call the number on the screen, and never let the popup make you type anything or press Windows-key combinations it tells you to press. Real Microsoft warnings never contain a phone number.

What NOT To Do

  • Do not ring the number. No legitimate Microsoft, McAfee, Norton or ISP alert asks you to call anyone. The people on the other end are not a support desk — their job is to talk you into installing remote-access software.
  • Do not install anything they ask you to. The tools they favour are AnyDesk, TeamViewer, UltraViewer and Supremo. All are legitimate remote-support tools; the scam is who’s on the other end of them.
  • Do not read them numbers off your bank card or your online banking screen. If you’ve already logged into online banking with them watching, treat that account as compromised (see below).
  • Do not run “PC cleaner” tools they email you afterwards. Those are the payload.

If You Already Called Them or Let Them In

This is where the actual bench work starts, and it’s the bit that matters. If you ran anything they told you to, or you gave them a code that let them view or control your screen, treat the machine as compromised even though your antivirus is showing clean. Here’s what we actually do on the bench in that scenario, in order:

  1. Unplug the network cable and turn Wi-Fi off first. That stops any active session dead. Only then start looking.
  2. Uninstall every remote-access tool present. AnyDesk, TeamViewer, UltraViewer, Supremo, Splashtop, LogMeIn, ConnectWise ScreenConnect, ShowMyPC. Then hunt for their leftover services and scheduled tasks manually, because a plain uninstall leaves the auto-start entries behind in a lot of cases.
  3. Check startup, services and scheduled tasks. Anything set to run at boot that the customer doesn’t recognise gets investigated, not just left alone. Scammers routinely add a Task Scheduler entry so they can reconnect after a reboot.
  4. Rotate the important passwords — from a different device. Email first (because email resets everything else), then online banking, then anything with a payment method saved. Do these from a phone or a family member’s clean laptop, not the one that was accessed.
  5. Ring the bank on the number on the back of your card. Not any number the caller gave you. If they were shown your banking screen at all, the bank needs to know.
  6. Targeted browser reset. A full Windows reinstall is usually overkill; a clean reset of Chrome and Edge profiles — wiping saved passwords, extensions, cookies and autofill — closes the browser-side of the exposure without nuking the OS. We prefer this route because it keeps your files intact.

If the “support agent” had you type your Windows password out loud or into a Notepad window they were watching, change it too. And if they had you log into your Microsoft account, revoke sessions and enable two-factor authentication straight away — our two-factor authentication setup guide walks that step through end to end.

A Recent Job Near Corstorphine High Street

A retired customer near Corstorphine High Street brought in a Lenovo laptop after “Microsoft” had guided them through installing AnyDesk over the phone. Windows Defender was clean; nothing flagged. But AnyDesk was still installed, was set to auto-start, and had a saved unattended-access password the customer hadn’t chosen. There was also a fresh scheduled task called “WindowsUpdateCheck” pointing at a batch file in %AppData%. That was the reconnection hook.

We pulled the network cable, removed AnyDesk and its leftover service, killed the scheduled task, cleaned the batch file out, reset the two browsers, and walked the customer through changing their email and banking passwords from their daughter’s iPad while we worked. Nothing was lost. No Windows reinstall was needed. Total time on the bench: about ninety minutes, once we knew what we were looking for.

How To Stop It Happening Again

  • Turn on browser pop-up and notification blocking. In Chrome and Edge, in Site Settings, set Pop-ups and redirects to Don’t allow, and set Notifications to Ask before sending (or block entirely).
  • Never click “Allow” on a browser notification prompt. A lot of these full-screen scares are delivered by earlier notification abuse from a shady site the person once clicked Allow on. Our post on fake browser update popups covers the same trick from the other angle.
  • Use uBlock Origin (Chrome/Edge/Firefox). It blocks a huge proportion of the ad networks these scam pages piggyback on.
  • Keep Windows Defender on — but understand it won’t stop this class of scam. It stops malware; a scam webpage isn’t malware.
  • If a stranger phones claiming to be from Microsoft, BT, TalkTalk or your bank, hang up. Our companion post on tech support scams in Edinburgh goes through the cold-call variant in detail. And if a virus scare has you double-checking — the real signs a PC has a virus look nothing like these popups.

When It’s Worth Getting Us Out

If you closed the popup without engaging, you’re fine — there’s no clean-up to do. If you called, installed anything, or gave anyone access, please treat it as urgent and get the machine looked at properly. We cover Corstorphine, Murrayfield, Sighthill-Wester-Hailes and the rest of west Edinburgh under virus & malware removal, and any resulting Windows or browser cleanup falls under software troubleshooting. If you’d rather we take a look from your side without you dropping the machine off, remote support lets us do the sweep over a secure session — the difference being, you can hang up whenever you like and we’re not asking you to install anything you can’t remove yourself.

The short version: a scary popup is almost never an infection. But five minutes on the phone with the wrong person can turn it into one, and that’s the version worth spending an hour cleaning up properly rather than hoping an antivirus scan catches it.

Last updated: 11 August 2026

Frequently Asked Questions

Common questions Corstorphine residents ask us about fake Windows security popups.

No. Almost every version of it is a webpage designed to look like a Windows alert — HTML, JavaScript and an autoplaying alarm sound. Your antivirus isn’t missing anything, and Windows itself is unaffected. Close the tab (or force-close the browser via Task Manager) and it’s gone. The one exception is if you actually rang the number and gave the person access; then the compromise is on the human side, not the malware side, and needs a proper sweep.

Treat it as compromised. If the person was on the screen while you logged in, or while a card was on screen, ring your bank on the number printed on the back of your card straight away and tell them. Change your email password first (from a different device), then online banking, then anything else with a payment method saved. And get the PC properly cleaned — the remote-access tool they installed is often set to auto-reconnect on the next reboot.

Because the popup is an ordinary webpage, not malware. It uses features that legitimate sites use every day — full-screen mode, autoplay audio, warning on close. An antivirus that killed those would also break Netflix, YouTube and half of internet banking. A good ad-blocker (uBlock Origin is the one we recommend) is the more effective defence, because it blocks the shady ad networks these pages are usually served through in the first place.

Usually not. If you only saw the popup and closed it, there’s nothing to reinstall. If you did let someone in, a targeted clean-up — removing every remote-access tool, checking scheduled tasks and startup, resetting the browsers, and rotating important passwords from a different device — is almost always enough. A full Windows reinstall wipes your files and settings and is a big enough job that we’d only recommend it if the sweep turns up something that genuinely needs it.

Rang the Number or Let Someone Connect?

Don’t wait it out. A proper sweep now closes the door before the reconnection hook fires.