Those pop-ups are almost certainly a tech‑support scam in the browser, not a legitimate Microsoft virus alert.
- What to try next
- Close the scam page and browser
- Press Alt + F4 repeatedly to close the browser window, or
- Press Ctrl + Shift + Esc → open Task Manager → select the browser (Edge/Chrome/Firefox) → End task.
- If that fails, hold the power button until the PC turns off, then restart.
- Clear the browser cache and data
- After restart, open the browser, clear cache and site data (cookies/history). This removes any script that keeps reopening the scam page.
- Run built‑in Microsoft malware tools
- Run a full scan again with Microsoft Defender Antivirus from Windows Security.
- Then run the Malicious Software Removal Tool:
- Press Windows key + R.
- Type
%windir%\system32\mrt.exeand select OK. - Approve the prompt and run a full scan.
- If the same threat keeps coming back, run Microsoft Defender Offline:
- Go to Start > Settings > Update & Security > Windows Security > Virus & threat protection.
- Under Current threats, select Scan options.
- Choose Windows Defender Offline scan → Scan now (PC will restart and scan outside Windows).
- If pop‑ups still appear
- Use a modern browser like Microsoft Edge with Microsoft Defender SmartScreen enabled to block malicious sites.
- Avoid sites with illegal downloads or suspicious content, as revisiting the same site can reinfect or re‑trigger the scam.
If after these steps malware is still repeatedly detected, follow the advanced guidance in the malware troubleshooting article and consider professional support.
- What happens to the infected files
Behavior depends on what the security tool chose for each threat:
- Remove – the file is deleted from the PC.
- Quarantine – the file is moved to a safe location and blocked from running.
- Partially removed – some components were cleaned, but not all. In this case Microsoft recommends:
- Run a full scan with the Malicious Software Removal Tool (
mrt.exe). - Restart the PC and install the latest Windows and security updates.
- If needed, use Microsoft Defender Offline to catch hidden components.
- Run a full scan with the Malicious Software Removal Tool (
If a threat is only partially removed, the report will say so; additional scans and offline scan are required to fully clean it.
- Is it safe to email a file from this PC?
Before emailing any file:
- Make sure the system is clean as above (Defender full scan, MSRT, and Defender Offline if needed).
- Scan the specific file:
- Right‑click the file → scan with your Microsoft security software.
- If the file is flagged as malware or unwanted software:
- Do not send it.
- Let the security software remove or quarantine it.
If a file is not detected but is suspicious (for example, came from an untrusted source), it can be submitted to Microsoft for analysis using Submit a file for malware analysis from the malware troubleshooting article. Only send files by email when they are not flagged and are from a trusted source.
Also, never call phone numbers shown in pop‑up “virus alerts” and never follow instructions from those pages; Microsoft does not lock PCs or display phone numbers in that way.
References:
- How to troubleshoot an error when you run the Microsoft Safety Scanner
- Trojans
- Microsoft resources and guidance for removal of malware and viruses
- Antivirus and antimalware software: FAQ
- Troubleshoot problems with detecting and removing malware
- I WAS HACKED - Microsoft Q&A
- possible virus, computer locked - Microsoft Q&A
- I think I'm being scammed, but I want to make sure. (Though I may be in the wrong place.) - Microsoft Q&A
- device missing important security and quality issues - Microsoft Q&A
- My computer was locked by Microsoft defender, I was asked to call 1-844-452-2441 to get it unblocked. Could somebody confirm that this is a legitimated Microsoft number rather than a scammer? - Microsoft Q&A