Fixing a Fake Security Alert at the Windows Login Screen
A Windows login screen that displays a warning about viruses, account suspension, or urgent technical support may be a scam rather than a genuine system message. Attackers often imitate Microsoft branding, use alarming colours, and demand a phone call, payment, or password before allowing access to the desktop.
The alert may be caused by scareware, a malicious startup program, a compromised account, or a browser window made to look like Windows. The safest response is to avoid interacting with the message, disconnect the computer from the internet, and use trusted recovery tools to identify and remove the unwanted software.
| What you see |
Likely explanation |
Safe response |
| A normal Windows password or PIN field |
Genuine sign-in screen |
Sign in only if the surrounding interface looks normal |
| A warning with a phone number or payment demand |
Tech-support scam or scareware |
Do not call, pay, or provide details |
| A full-screen alert before the desktop loads |
Startup malware or altered login component |
Disconnect the network and enter Windows Recovery |
| A warning that appears after opening a browser |
Malicious advertisement or fake support page |
Close the browser safely and scan the device |
Check Whether the Warning Is Genuine
Microsoft does not normally display a support phone number on the Windows sign-in screen, and legitimate security alerts do not ask users to purchase gift cards or transfer money. A message claiming that a computer is locked because of illegal activity is also a common scare tactic.
Look for unusual spelling, a countdown timer, a toll-free number, cryptocurrency instructions, or a request to install remote-access software. Avoid entering a Microsoft password, banking details, or an authentication code. If the screen has a physical power button, hold it down to shut the computer off rather than clicking buttons inside the alert.
Disconnect the Computer Safely
Unplug an Ethernet cable and switch off Wi-Fi from another device if possible. If the warning appeared after connecting a USB drive, remove that drive once the computer has powered down. This limits communication with a remote operator and can prevent malware from downloading additional components.
Australian households commonly use NBN connections and shared home Wi-Fi, so check other computers, phones, and smart devices for suspicious pop-ups or unfamiliar sign-in notifications. Do not reconnect the affected PC until an initial scan has been completed.
Use Windows Recovery Options
Turn the computer on and interrupt the boot process two or three times by holding the power button when the Windows logo appears. Windows should open the Automatic Repair environment. Select Advanced options, then use Startup Settings to try Safe Mode, or choose Uninstall Updates and System Restore if the problem began after a recent change.
Some threats block Safe Mode or replace the recovery screen with a fake blue-screen message. In that situation, follow this Safe Mode guidance and use a clean Windows installation USB or Microsoft Defender Offline media from an unaffected computer.
Scan for Startup Malware
After reaching Safe Mode, open Settings > Apps and remove software installed shortly before the warning appeared, especially remote-support tools, unknown cleaners, and suspicious browser extensions. Then inspect Task Manager > Startup apps and disable entries with unfamiliar publishers or random-looking names.
Run a full scan with Windows Security and then use Microsoft Defender Offline, which scans before normal Windows processes load. A second reputable on-demand scanner can help identify adware, trojans, or ransomware loaders that evade a first scan. Research unfamiliar detections carefully; deleting legitimate system files can make recovery harder.
Check Accounts and Browser Settings
Once the computer is clean, review local user accounts under Settings > Accounts > Family & other users. Remove unknown accounts and change passwords from a separate, trusted device. Prioritise email, banking, cloud storage, and social media accounts, then enable multifactor authentication wherever it is available.
Inspect browser extensions, notification permissions, proxy settings, and the default search engine. If the alert returned after launching Chrome or Edge, reset the browser and remove recently installed add-ons. Malware that spreads through shared folders or removable media may also behave like a worm, so consult this worm research when several devices show similar symptoms.
Report the Scam and Restore Confidence
Keep a photograph or screenshot of the alert, the phone number shown, payment receipts, and any email addresses involved. Australian users can report online scams to Scamwatch and cybercrime through ReportCyber. If money or card details were shared, contact the bank immediately; Australian banks may be able to stop or monitor suspicious transactions.
If a technician was given remote access, uninstall the remote-control program, change passwords, and ask the bank whether accounts need additional protection. For wider background on ransomware, spyware, hijackers, and recovery methods, use the site’s malware removal guides rather than downloading tools advertised by the pop-up. If Windows remains unstable, back up personal files after scanning and perform a clean reinstall using official Microsoft media.