Before you begin
Slow performance, browser pop-ups and failed logins can have innocent causes as well as malicious ones. They are warning signs to investigate, not proof that someone has stolen your passwords. Record what you see without following instructions inside the suspicious message.
If a page claims your PC is infected and tells you to call a number, install remote-access software or pay immediately, close it. Do not grant access or enter banking details. If you suspect active remote control, disconnect the PC from the network and use a separate trusted device to seek help and protect your accounts.
Work through the checks
-
Reduce exposure
Stop using the suspect PC for sensitive sign-ins. Disconnect internet access if an unknown person appears to control it or a suspected threat is actively sending data. Keep a note of the app name, download source and time symptoms began. Do not forward a suspicious executable to a friend to “see if it works”, and do not plug valuable backup drives into a machine you believe is compromised.
-
Check Windows Security
Open Windows Security from the Start menu rather than through a pop-up. Review the protection status, security intelligence updates and Protection history. If another reputable antivirus manages protection, use its documented interface. Do not run several competing real-time antivirus products together or disable protection simply because an unknown download says it is required.
-
Run an appropriate scan
When safe to reconnect for updates, update the security tool and run its supported scan. Windows Security provides scan options, including a full scan and Microsoft Defender Offline where available. Save work before an offline scan because it restarts the computer. Review what was detected and the action taken. A completed scan lowers uncertainty but cannot guarantee that every possible compromise has been removed.
-
Check the browser separately
Review installed extensions, notification permissions, homepage and default search provider. Remove unfamiliar extensions through the browser’s own controls. An unwanted website notification can look like a system warning even when it is only a browser permission. Avoid clicking the warning to remove it. Check installed apps for recently added software you do not recognise, and use official uninstall instructions.
-
Secure affected accounts from a trusted device
If credentials may have been exposed, change the affected passwords on a clean device and review active sessions, recovery details and multifactor settings. Prioritise the email account used to recover other accounts. Use different passwords for different services. If payment details were exposed, contact the relevant provider using a known official channel rather than a number shown in the suspicious message.
-
Decide whether a clean installation is needed
Persistent infection, unknown remote access or a compromised administrator account may justify rebuilding Windows from official media. First decide what data can be recovered safely. Do not automatically format every drive or blindly restore all old programs. Keep documents separate from suspicious executables, scan recovered files and reinstall applications from official sources. Ask for help if business or irreplaceable data is involved.
What the results tell you
Only browser notifications appear
Review website notification permissions and extensions. Treat the content as untrusted even when it uses a Windows-style icon.
Security protection will not stay enabled
Record the message and check which security product is managing the PC. Persistent unexplained changes need investigation.
Account activity you do not recognise
Secure the account from a trusted device, revoke suspicious sessions and review recovery methods. A PC scan alone does not revoke stolen sessions.
Common questions
Does one failed login prove spyware?
No. Mistyped credentials, connection issues and service faults are common. Investigate the wider evidence instead of treating a failed first attempt as proof.
Should I wipe the D: drive immediately?
No. Identify the affected data and make a recovery plan. Unnecessary formatting destroys files and may not address compromised online accounts.
Can I use a free “cleaner” advertised in a warning?
Do not install software recommended by the warning itself. Use the operating system’s security tools or software obtained directly from a trusted official publisher.
When to contact ElitePCS
We can help you distinguish suspicious browser behaviour from a system fault and discuss a safe Windows rebuild. Do not send passwords, recovery keys or suspicious programs in an ordinary contact message.
Contact ElitePCS support. Include your order number, the exact symptom and the checks you have completed. Keep passwords, licence keys and recovery keys out of screenshots.
Technical references: Microsoft tech-support scam guidance · Windows Security. Reviewed 27 September 2026.