Pop-ups Even With Your Browser Closed? It’s Not a Virus (a Craigmillar Guide)

Little ad windows appearing in the bottom corner of the screen when Chrome isn’t even open — and antivirus scans keep coming back clean. Here’s what’s actually going on, and how to shut it off for good.

1 September 2026 8 min read Cybersecurity Alex M.
Browser notification pop-ups appearing on Windows even with the browser closed — a Craigmillar cybersecurity guide

Roughly one Craigmillar laptop a fortnight comes in with the same complaint. Small ad boxes keep sliding in from the bottom-right corner of the screen — sometimes a fake “McAfee subscription has expired”, sometimes a “5 viruses detected” scare, sometimes just an ad for a game. The customer has run a full Windows Defender scan, then Malwarebytes for good measure, and every scan comes back completely clean. Chrome or Edge isn’t even open, and yet the pop-ups keep coming.

It’s not a virus. It’s a browser feature the site tricked the user into switching on months ago, and antivirus can’t catch it because there’s nothing to catch. Below is exactly what’s happening, and how we clear it on the bench — whether you’re round Niddrie Mains Road, up towards The Jewel or over at Peffermill. If you’d rather just have it done for you, virus removal in Craigmillar is the fast route.

What Craigmillar Customers Usually Describe

The pattern is remarkably consistent. Pop-ups appear in the bottom-right (or bottom-left on Edge) with the Windows notification chime. They look real enough that people assume it’s Windows or their antivirus. The pop-ups can appear when the browser is closed, or even a few minutes after the PC boots. Antivirus scans find nothing. Uninstalling and reinstalling Chrome doesn’t help — and often makes things worse because the user restores their bookmarks and settings, which brings the permission back with them.

Almost every single case traces back to a single click, weeks or months ago, on a webpage that said something like “Click Allow to confirm you are not a robot” or “Allow notifications to continue”. There was a small blue box in the top-left of the browser asking whether to allow notifications; the user clicked Allow because the page told them to.

Why Your Antivirus Finds Nothing

Modern browsers include a feature called Web Push Notifications. It’s a genuinely useful bit of the web platform: your webmail can chime when a new email lands, Slack can flash when a colleague messages, Google Calendar can nudge you before a meeting. When you visit a site that uses it, the browser shows a little permission prompt asking whether that site can send you notifications. If you say yes, the site can push notifications to your desktop — and Chrome and Edge deliver them by keeping a tiny background process running even when the main window is closed.

Scam and low-quality ad sites abuse the same feature. They ask you to Allow notifications under a false pretext (“click Allow to prove you’re human”, “click Allow to download”, “click Allow to view the video”). Once you do, they can fire notifications at your desktop for as long as the permission stands. Nothing malicious ever ran on your PC. No file was ever installed. Antivirus has nothing to scan because the whole thing is a legitimate browser feature being used the way it was designed — just by people you’d rather not have doing so.

That’s why every one of the pop-ups can be shut off in a couple of minutes once you know where to look.

The “Verify You’re Human” Trap — and its Dangerous Cousin

There are two very different tricks that share the same “verify you’re human” disguise, and it matters which one you saw.

The notification trick is the one above. It’s annoying and it needs cleaning up, but nothing is actually infected. The fix is a menu setting.

The ClickFix trick looks almost identical — a fake CAPTCHA, sometimes styled to look like Cloudflare’s — but the instructions are different. Instead of asking you to click Allow, it tells you to press Windows key + R, then Ctrl + V, then Enter. What it has quietly copied to your clipboard is a PowerShell command, and pressing those three key combinations runs it. That version is a real infection: it typically fetches an infostealer or a remote-access trojan and quietly installs it. Windows Defender does sometimes catch it, but not always, and the payload changes weekly.

If the “verify” prompt only asked you to click Allow, you’re in the notification-abuse camp — keep reading. If it asked you to press Windows+R and paste something in, treat the PC as compromised and get it looked at properly. That’s a different job.

Clearing It Out of Chrome

This takes about two minutes.

  1. Open Chrome. In the address bar, paste chrome://settings/content/notifications and press Enter.
  2. Under “Allowed to send notifications”, look at the list. Anything you don’t recognise as a site you deliberately signed up for — delete it (click the three dots on the right, then Remove). If you’re not sure, delete it; the site will simply ask again if you ever visit it and genuinely need a notification from it.
  3. While you’re there, change the top toggle to “Use quieter messaging” or set the default to “Don’t allow sites to send notifications”. Both are fine.
  4. Restart Chrome. The pop-ups should stop within a minute or two — there’s no queued message left to deliver once the permission is gone.

If the pop-ups came from a shady site that also snuck in an extension, check chrome://extensions at the same time and remove anything you didn’t install yourself. Extensions labelled “Managed by your organisation” on a home PC are usually a red flag — you shouldn’t see that message on a family laptop at all.

Clearing It Out of Edge

Very similar — Edge is a Chromium browser too.

  1. Open Edge. Paste edge://settings/content/notifications and press Enter.
  2. Under “Allow”, delete anything you don’t recognise. Same rule — if in doubt, delete it.
  3. Toggle “Ask before sending” on if it isn’t already, or turn notifications off entirely.
  4. While in Edge, also check edge://settings/content/popupsAndRedirects. That should be set to “Don’t allow”.
  5. Restart Edge.

Firefox users: same idea — Settings → Privacy & Security → Permissions → Notifications → Settings, then delete every unfamiliar site and tick “Block new requests asking to allow notifications”.

When It Goes Deeper

The permission cleanup fixes the notification-abuse cases we see most weeks in Craigmillar. Occasionally a laptop comes in where more went on than just clicking Allow — usually because the same visit that grabbed the notification permission also tricked the user into installing a “video downloader” or “PDF-to-Word converter” utility that turned out to be adware. If pop-ups persist after the browser settings are clean, we check the following:

  • Installed apps. Settings → Apps → Installed apps, sorted by install date. Anything installed on the same day the pop-ups started is a candidate.
  • Startup programs. Task Manager → Startup apps. Uncommon publishers or blank publisher names get investigated.
  • Scheduled Tasks. Adware often adds a task under Task Scheduler Library that reopens the browser to a specific URL every so many hours. Anything with a random-looking name gets checked.
  • Browser profile reset. If a profile is thoroughly messed up (search hijacked, homepage changed, several rogue extensions), a targeted reset of that specific profile is cleaner than trying to undo everything by hand. It keeps bookmarks and saved logins but wipes the tampered settings.

If any of that sounds like more than a wet afternoon, it’s the sort of job we handle under virus & malware removal or software troubleshooting — and we can usually do it without you leaving the house, over remote support, since none of it involves opening the machine.

A Recent Job Near Niddrie Mains Road

A laptop came in from a household near Niddrie Mains Road last month. The teenager in the house had been getting fake “Windows Defender: 3 viruses found” pop-ups for weeks, always in the bottom-right, always chiming. Three antivirus scans had come back clean. Both parents were convinced the PC was infected and considering wiping it.

The whole cleanup took nine minutes. Chrome’s notifications page had eleven allowed sites, of which the user recognised exactly one (Gmail). The other ten were a mix of misspelt news sites, a fake CAPTCHA host, and two ad networks. Deleting them, restarting Chrome, and checking chrome://extensions (one dodgy extension called “PDF Reader Pro” that the user hadn’t installed) closed it out. No Windows reinstall, no antivirus subscription needed, no reset. The pop-ups stopped that afternoon and haven’t come back. A clean scan is genuinely a clean PC; the pop-ups had just been abusing a feature the browser was designed to allow.

How To Spot the Trick Next Time

  • Any webpage that tells you to click Allow — don’t. A legitimate site does not need notification permission to prove you’re human or to play a video. If the page won’t work without it, close the tab.
  • Any webpage that tells you to press Windows+R and paste something in — close it and step away from the PC. That’s the dangerous cousin. The fake ‘Windows Security Alert’ guide covers the phone-call variant of the same style of scam.
  • Real Windows notifications don’t contain phone numbers. Ever. If there’s a phone number in the pop-up, it’s a webpage, not Windows.
  • Fake “update your browser” boxes are the same family of trick. Our post on fake browser update popups covers that flavour in detail.
  • Install uBlock Origin. It blocks a huge slice of the ad networks that farm these permission requests in the first place.
  • Actual malware behaves differently. The real signs a PC has a virus look almost nothing like a chiming pop-up in the corner.

Nine times out of ten, the pop-ups are a nuisance rather than an infection, and the fix takes less time than a full antivirus scan. It’s worth the two minutes to check the notifications list before anyone reaches for a reinstall.

Last updated: 1 September 2026

Frequently Asked Questions

Common questions Craigmillar residents ask us about desktop pop-ups that appear even when the browser is closed.

Modern Chromium browsers keep a small background service running so that sites you’ve given notification permission to (webmail, calendar, chat apps) can chime even after you close the browser window. Scam and ad sites abuse the same feature: once you accidentally clicked Allow on their notification prompt, they can push desktop pop-ups until you revoke the permission. It isn’t malware and antivirus won’t catch it — the fix is in the browser’s notifications settings.

Because nothing malicious was ever installed. The pop-ups are being delivered by a legitimate browser feature (Web Push Notifications) that a site got permission to use by tricking you into clicking Allow. There is no file for a scanner to flag, no process running that shouldn’t be, and no registry key out of place. The fix is a permission list, not a scan.

Almost never. Removing the site from your browser’s notifications list and restarting the browser stops the pop-ups within minutes. If you reinstall Chrome and let it restore your settings from your Google account, the permission comes right back with them — so reinstalling actually doesn’t help. Clean the permissions list and you’re done.

That’s the ClickFix version, and it’s a genuine infection attempt — not the notification-abuse case above. The paste command runs a hidden PowerShell script that pulls down malware. If you actually pressed Enter after Ctrl+V, treat the PC as compromised: change your important passwords from a different device (email first), and get the machine properly cleaned. A permission cleanup won’t be enough on its own for that one.

Pop-ups That Won’t Stop, Even After Scans?

We’ll clear the permission abuse in minutes — and check nothing sneakier came along for the ride.