{"id":22616,"date":"2024-06-07T16:43:55","date_gmt":"2024-06-07T16:43:55","guid":{"rendered":"https:\/\/gridinsoft.com\/blogs\/?p=22616"},"modified":"2025-07-09T01:20:33","modified_gmt":"2025-07-09T01:20:33","slug":"windows-defender-security-warning","status":"publish","type":"post","link":"https:\/\/gridinsoft.com\/blogs\/windows-defender-security-warning\/","title":{"rendered":"Windows Defender Security Warning"},"content":{"rendered":"<p>&#8220;Windows Defender Security Warning&#8221; is a scam website that falsely claims your PC is infected and urges you to contact Microsoft tech support. This scam is part of a larger scheme aimed at deploying unwanted software on users&#8217; devices and extracting money for resolving nonexistent issues. It has been around for some time and targets users worldwide.<\/p>\n<p><a href=\"https:\/\/gridinsoft.com\/blogs\/microsoft-tech-support-scam-affiliate-program\/\">Tech support scams<\/a> represent a particularly notorious type of online fraud, utilizing various tactics to coerce people into making a phone call to a fake support service. The Windows Defender Security Warning scam is one of the most enduring and widespread methods used in these schemes. In this article, I will describe what this scam is, how it operates, and how you can avoid falling victim to it in the future.<\/p>\n<h2>What is Windows Defender Security Warning?<\/h2>\n<p>As mentioned earlier, the Windows Defender Security Warning typically appears as a browser window after clicking a link on a certain website. It displays numerous smaller windows, which are actually non-interactive images. These fake alerts inform the user that their PC is blocked &#8220;for security reasons&#8221;. In the background, a robotic voice claims the following:<\/p>\n<div class=\"su-quote su-quote-style-default\"><div class=\"su-quote-inner su-u-clearfix su-u-trim\">\u201cImportant security message! Your computer has been locked up. Your IP address was used without your knowledge or consent to visit websites that contain identity theft virus. To unlock the computer please call the support immediately. Please do not attempt to shut down or restart your computer. That will lead to data loss and identity theft.\u201d<\/div><\/div>\n<p>Clicking on any of the site elements \u2013 which in fairness may happen randomly \u2013 results in the website switching to a full screen, with no obvious way out. Escape button won\u2019t work, and roaming the mouse around the screen won\u2019t help out either. If the victim is not aware of combinations like Ctrl+F4, Alt+Tab or Ctrl+Shift+Esc, it may look like a trap. That, along with the sound alert, is what should push the user towards following the scam\u2019s guidance and call the support.<\/p>\n<figure id=\"attachment_22628\" aria-describedby=\"caption-attachment-22628\" style=\"width: 1918px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/windows-defender-security-warning-scam.webp\" alt=\"Windows Defender Security Warning scam page\" width=\"1918\" height=\"922\" class=\"size-full wp-image-22628\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/windows-defender-security-warning-scam.webp 1918w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/windows-defender-security-warning-scam-300x144.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/windows-defender-security-warning-scam-1024x492.webp 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/windows-defender-security-warning-scam-768x369.webp 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/windows-defender-security-warning-scam-1536x738.webp 1536w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/windows-defender-security-warning-scam-1568x754.webp 1568w\" sizes=\"auto, (max-width: 1918px) 100vw, 1918px\" \/><figcaption id=\"caption-attachment-22628\" class=\"wp-caption-text\">Typical example of a Windows Defender Security Warning page<\/figcaption><\/figure>\n<p>As you can see, this is just a scam designed to capitalize on the fear of individuals who may have less knowledge about computer security or computers in general. However, let&#8217;s take a closer look at how this scam operates\u2014there are quite a few interesting tactics involved.<\/p>\n<h2>Windows Defender Security Warning Mechanism Explained<\/h2>\n<p>The scam begins by luring users to the Windows Defender Security Warning page. To achieve this, scammers often purchase link placements on dubious websites, such as those hosting pirated movies. A user clicking on a play button or attempting to skip an ad in the video player may be redirected to the scam site.<\/p>\n<p>The domains hosting this scam can vary widely, but they typically include some mention of Microsoft in the URL. In some egregious instances, fraudsters have even managed to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-tech-support-scams-invade-azure-cloud-services\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">secure hosting from Microsoft themselves<\/a>. Below, you can find a list of sites used in this scam campaign:<\/p>\n<div class=\"su-table su-table-alternate\">\n<table>\n<tr>\n<td>digitalcompletes[.]online<\/td>\n<td>spicyhotrecipes[.]site<\/td>\n<td>rickyhousing[.]xyz<\/td>\n<\/tr>\n<tr>\n<td>gardenhub[.]site<\/td>\n<td>morningh[.]shop<\/td>\n<td>robortcleaning[.]site<\/td>\n<\/tr>\n<tr>\n<td>jadeneal[.]autos<\/td>\n<td>programmaticcrooks[.]online<\/td>\n<td>elhiuwf[.]cf<\/td>\n<\/tr>\n<tr>\n<td>hitorikawag[.]top<\/td>\n<td>adultfriend[.]store<\/td>\n<td>yeddt[.]jet<\/td>\n<\/tr>\n<tr>\n<td>jonwirch[.]com<\/td>\n<td>aweqaw12d[.]tk<\/td>\n<td>helpadvance[.]ga<\/td>\n<\/tr>\n<tr>\n<td>333waxonet[.]ml<\/td>\n<td>noblevox[.]com<\/td>\n<td>risingsolutions[.]online<\/td>\n<\/tr>\n<tr>\n<td>pixua[.]com<\/td>\n<td>adultfriend[.]site<\/td>\n<td>giveserendipity[.]website<\/td>\n<\/tr>\n<tr>\n<td>connectflash[.]ml<\/td>\n<td>ondigitalocean[.]app<\/td>\n<td>dothrakiz[.]com<\/td>\n<\/tr>\n<tr>\n<td>jbvhjcbjzvhxvhzcjgzvgcczgh29[.]ml<\/td>\n<td>digitalflawless[.]ga<\/td>\n<td>todogallina[.]es<\/td>\n<\/tr>\n<tr>\n<td>markmoisturise[.]online<\/td>\n<td>enterthecode[.]org<\/td>\n<td>ebonygirlslive[.]com<\/td>\n<\/tr>\n<\/table>\n<\/div>\n<p>Once the user lands on the scam site, it typically goes fullscreen and starts playing the previously mentioned audio message. The main goal of this message is to coerce the victim into contacting &#8220;tech support&#8221; using the phone number displayed on the site, which is mentioned multiple times. The phone call marks the final phase of the scam.<\/p>\n<p>The so-called support manager begins by instructing the user to download sketchy software purported to resolve the issue\u2014without explaining how the software addresses identity compromise. Throughout the life of this scam, various fraudulent programs have been offered, including SystemKeeper, Driver Updater, and Wise System Mechanic. As expected, all these are <a href=\"https:\/\/gridinsoft.com\/unwanted-program\">pseudo-effective unwanted programs<\/a> that further prompt users to pay for fixing a myriad of non-existent problems.<\/p>\n<p>What is the purpose of all this, you might ask? Money is the short and universal answer. The fraudsters posing as tech support managers receive commissions for each user they persuade to download the software. Meanwhile, the developers of this software profit from users purchasing licenses. Considering how long this scam has been active, the monetary turnover is quite substantial.<\/p>\n<h2>How to Protect Against Windows Defender Security Warning Scam?<\/h2>\n<p>The primary advice for protecting against the Windows Defender Security Warning scam and similar schemes is to avoid websites that initiate these scams. As mentioned, the majority of redirects to scam websites originate from pages hosting pirated content. This should be another reason to steer clear of such sites, beyond the fact that content piracy is illegal. Additionally, pirated software or games pose a significant security risk.<\/p>\n<p>Learn how genuine notifications from security software should look, and how they should not. Neither Microsoft Defender nor other antivirus\/antimalware programs issue security notifications through web browsers. None of them will prompt you to call support while appearing to block your computer. And, importantly, no legitimate tech support from any security vendor will ever advise you to install questionable third-party software.<\/p>\n<p>Use reliable antivirus software with network protection. To prevent scam pages from opening and to ensure your system remains secure regardless of any fake alerts, a robust antivirus solution is essential. GridinSoft Anti-Malware offers excellent malware removal capabilities and network protection, backed by a multi-component detection system and regular updates.<\/p>\n<img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-main.webp\" alt=\"GridinSoft Anti-Malware main screen\" width=\"886\" height=\"689\" class=\"aligncenter size-full wp-image-22665\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-main.webp 886w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-main-300x233.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-main-768x597.webp 768w\" sizes=\"auto, (max-width: 886px) 100vw, 886px\" \/>\n<p>Download and install Anti-Malware by clicking the button below. After the installation, run a Full scan: this will check all the volumes present in the system, including hidden folders and system files. Scanning will take around 15 minutes.<\/p>\n<div style=\"text-align:center\"><a href=\"\/download\/antimalware\" class=\"btn border-black\" rel=\"nofollow\">Download Anti-Malware<\/a><\/div>\n<p>After the scan, you will see the list of detected malicious and unwanted elements. It is possible to adjust the actions that the antimalware program does to each element: click \"Advanced mode\" and see the options in the drop-down menus. You can also see extended information about each detection - malware type, effects and potential source of infection.<\/p>\n<img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-result.webp\" alt=\"Scan results screen\" width=\"886\" height=\"689\" class=\"aligncenter size-full wp-image-22666\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-result.webp 886w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-result-300x233.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-result-768x597.webp 768w\" sizes=\"auto, (max-width: 886px) 100vw, 886px\" \/>\n<p>Click \"Clean Now\" to start the removal process. Important: removal process may take several minutes when there are a lot of detections. Do not interrupt this process, and you will get your system as clean as new.<\/p>\n<img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-clean.webp\" alt=\"Removal finished\" width=\"886\" height=\"689\" class=\"aligncenter size-full wp-image-22667\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-clean.webp 886w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-clean-300x233.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/antimalware-clean-768x597.webp 768w\" sizes=\"auto, (max-width: 886px) 100vw, 886px\" \/>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;Windows Defender Security Warning&#8221; is a scam website that falsely claims your PC is infected and urges you to contact Microsoft tech support. This scam is part of a larger scheme aimed at deploying unwanted software on users&#8217; devices and extracting money for resolving nonexistent issues. It has been around for some time and targets [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":22631,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[4,1549],"tags":[94,348,40,826],"class_list":{"0":"post-22616","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tips-tricks","8":"category-troubleshooting","9":"tag-microsoft","10":"tag-online-fraud","11":"tag-online-security","12":"tag-scam"},"featured_image_src":"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/06\/windows-defender-security-warning-scam-featured.webp","author_info":{"display_name":"Stephanie Adlam","author_link":"https:\/\/gridinsoft.com\/blogs\/author\/adlam\/"},"_links":{"self":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/22616","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/comments?post=22616"}],"version-history":[{"count":14,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/22616\/revisions"}],"predecessor-version":[{"id":25527,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/22616\/revisions\/25527"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media\/22631"}],"wp:attachment":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media?parent=22616"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/categories?post=22616"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/tags?post=22616"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}