ElitePCS support · Getting started

Suspected malware, pop-ups and account security

Respond to suspicious behaviour, use trusted security tools and protect accounts from a separate trusted device.

Step-by-step guideReviewed 27 September 2026
1. Stop interacting with the warning. Use a trusted device if you need help. 2. Run trusted security checks. Use official tools, not pop-up downloads. 3. Secure affected accounts. Change passwords on a trusted device.
1. Stop interacting with the warning. Use a trusted device if you need help. 2. Run trusted security checks. Use official tools, not pop-up downloads. 3. Secure affected accounts. Change passwords on a trusted device. Open full-size diagram (opens in a new tab).

Before you begin

Slow performance, browser pop-ups and failed logins can have innocent causes as well as malicious ones. They are warning signs to investigate, not proof that someone has stolen your passwords. Record what you see without following instructions inside the suspicious message.

If a page claims your PC is infected and tells you to call a number, install remote-access software or pay immediately, close it. Do not grant access or enter banking details. If you suspect active remote control, disconnect the PC from the network and use a separate trusted device to seek help and protect your accounts.

Work through the checks

  1. Reduce exposure

    Stop using the suspect PC for sensitive sign-ins. Disconnect internet access if an unknown person appears to control it or a suspected threat is actively sending data. Keep a note of the app name, download source and time symptoms began. Do not forward a suspicious executable to a friend to “see if it works”, and do not plug valuable backup drives into a machine you believe is compromised.

  2. Check Windows Security

    Open Windows Security from the Start menu rather than through a pop-up. Review the protection status, security intelligence updates and Protection history. If another reputable antivirus manages protection, use its documented interface. Do not run several competing real-time antivirus products together or disable protection simply because an unknown download says it is required.

  3. Run an appropriate scan

    When safe to reconnect for updates, update the security tool and run its supported scan. Windows Security provides scan options, including a full scan and Microsoft Defender Offline where available. Save work before an offline scan because it restarts the computer. Review what was detected and the action taken. A completed scan lowers uncertainty but cannot guarantee that every possible compromise has been removed.

  4. Check the browser separately

    Review installed extensions, notification permissions, homepage and default search provider. Remove unfamiliar extensions through the browser’s own controls. An unwanted website notification can look like a system warning even when it is only a browser permission. Avoid clicking the warning to remove it. Check installed apps for recently added software you do not recognise, and use official uninstall instructions.

  5. Secure affected accounts from a trusted device

    If credentials may have been exposed, change the affected passwords on a clean device and review active sessions, recovery details and multifactor settings. Prioritise the email account used to recover other accounts. Use different passwords for different services. If payment details were exposed, contact the relevant provider using a known official channel rather than a number shown in the suspicious message.

  6. Decide whether a clean installation is needed

    Persistent infection, unknown remote access or a compromised administrator account may justify rebuilding Windows from official media. First decide what data can be recovered safely. Do not automatically format every drive or blindly restore all old programs. Keep documents separate from suspicious executables, scan recovered files and reinstall applications from official sources. Ask for help if business or irreplaceable data is involved.

What the results tell you

Only browser notifications appear

Review website notification permissions and extensions. Treat the content as untrusted even when it uses a Windows-style icon.

Security protection will not stay enabled

Record the message and check which security product is managing the PC. Persistent unexplained changes need investigation.

Account activity you do not recognise

Secure the account from a trusted device, revoke suspicious sessions and review recovery methods. A PC scan alone does not revoke stolen sessions.

Common questions

Does one failed login prove spyware?

No. Mistyped credentials, connection issues and service faults are common. Investigate the wider evidence instead of treating a failed first attempt as proof.

Should I wipe the D: drive immediately?

No. Identify the affected data and make a recovery plan. Unnecessary formatting destroys files and may not address compromised online accounts.

Can I use a free “cleaner” advertised in a warning?

Do not install software recommended by the warning itself. Use the operating system’s security tools or software obtained directly from a trusted official publisher.

When to contact ElitePCS

We can help you distinguish suspicious browser behaviour from a system fault and discuss a safe Windows rebuild. Do not send passwords, recovery keys or suspicious programs in an ordinary contact message.

Contact ElitePCS support. Include your order number, the exact symptom and the checks you have completed. Keep passwords, licence keys and recovery keys out of screenshots.

Technical references: Microsoft tech-support scam guidance · Windows Security. Reviewed 27 September 2026.