⚠️ The “Admin Login: Windows locked due to unusual activity” pop-up is a scam that pretends to be from Microsoft to trick you into thinking that your computer has crashed or that a serious security issue has occurred. This deceptive pop-up imitates the look of Windows OS graphics and color palette to appear more authentic to unsuspecting users.
The scam involves multiple pop-ups claiming that your system has been locked due to unusual activity and that you need to log in again using your Microsoft ID and password. Additionally, the pop-up prompts you to contact “Microsoft Support” for assistance. These tactics are designed to create a sense of urgency and pressure you into calling the fake helpline provided on the scam page.
If you fall victim to this scam and enter your login credentials, they will be captured by the scammers for malicious purposes. It’s crucial to recognize the signs of such deceptive schemes and avoid providing any personal information or accessing unknown support services.
💡 Remember, legitimate companies like Microsoft will never ask you to call a random support number through a pop-up message. If you encounter such a message, do not call the number or provide any sensitive information. Close the browser tab immediately and consider running a security scan on your computer to ensure that it hasn’t been compromised by the scam.
Table of Contents
How the Scam Works 🚫🔍
The “Windows locked due to unusual activity” pop-up is a scam that preys on users’ fears of malware infections and illegal activities. Scammers employ various tactics to redirect users to their fraudulent websites, often through malicious ads, compromised websites, or email phishing campaigns. Once you land on one of these deceptive pages, a pop-up message appears, claiming to be from a reputable company like Microsoft.
Highlighted below is the text that appears in the ‘Windows locked due to unusual activity’ topmost pop-up:
Admin login
Windows locked due to unusual activity. Please log in again using your Microsoft ID and password. For assistance, contact Microsoft Support
The “Official” Warning 🚨
This fraudulent message pretends to be from “Microsoft Defender”, warning that your computer has been compromised by viruses. It’s designed to alarm you and prompt immediate action without careful thought.
The Call to Action ☎️
The scam plays on your fears, suggesting that your sensitive and financial information is at risk. It pressures you to call a fake “Windows Support” number right away for assistance.
The Endgame 💸
If you call, the scammers might try various tactics:
- Remote Access: They’ll ask to remotely access your computer, supposedly to “fix” the issue, but in reality, they might steal your data or install real malware.
- Phony Fees: They could claim you need to pay a fee to remove the nonexistent “Trojan”, exploiting you financially.
- Sell Useless Software: They might persuade you to purchase unnecessary and often fake software to “protect” your device.
Your Real Risk 🛑
While the pop-up’s threats are bogus, the real danger is in engaging with the scammers, which can lead to loss of money or personal data.
Remember, always be skeptical of unsolicited warnings or calls to action, especially when they provoke panic. Instead, arm yourself with knowledge and stay one step ahead.
Examples of such scams
Scammers are continually coming up with new tactics to deceive unsuspecting individuals, and the “Windows locked due to unusual activity” scam is just one example of their deceptive techniques. However, it is important to note that this is not an isolated case. There are numerous scams out there that exploit similar strategies, aiming to trick people into falling for their fraudulent schemes.
Virus Found (3) Pop-Up Scam
This particular scam involves a pop-up alert claiming that three viruses have been detected on the user’s device. It’s designed to mimic the look and feel of legitimate antivirus software alerts to convince users of its authenticity. The pop-up often includes a timer, adding a sense of urgency to the warning. Users are prompted to click on a button to remove the viruses, which either leads to the download of actual malware or redirects to a site asking for personal information or payment to ‘clean’ the computer.
Your Card Payment Has Failed – Renew Subscription Scam
This scam targets users with a false notification that their credit card payment for a subscription service (like antivirus or streaming) has failed. The message prompts immediate action, urging the user to click on a link to ‘renew’ or ‘update’ their payment information. Once clicked, it leads to a fake website where personal and financial details are requested, putting the user at risk of identity theft and financial fraud.
Hard Drive Damage Pop-Up Scam
In this scam, users receive a pop-up warning claiming that their hard drive is damaged or corrupted due to a virus or malware. It often includes technical jargon and error codes to appear authentic. The pop-up typically advises the user to download a ‘repair tool’ or contact a ‘support number’. However, the tool is usually malware, and the support number connects to scammers who try to gain remote access to the user’s computer or sell unnecessary services.
What to Do If You’re Targeted
If you find yourself targeted by a scam similar to the “Windows locked due to unusual activity” alert, it’s important to take immediate and appropriate action to safeguard your information and computer. Here’s a guide on what to do:
🚫 Do Not Interact
Avoid clicking on any part of the scam pop-up. Use task manager or restart your device to close it safely.
🔍 Run a Security Scan
Conduct a full system scan using legitimate antivirus software to detect and remove any threats.
🔐 Change Passwords
Immediately change your passwords, especially for important accounts, if you suspect any data compromise.
🏦 Monitor Financial Transactions
Keep a close watch on your bank statements for unauthorized activity if you’ve shared financial information.
⚙️ Update Your Software
Ensure all your software, particularly security applications, are up-to-date to combat new threats.
💼 Seek Professional Help
If in doubt about your system’s security, consult with a cybersecurity expert.
📢 Report the Scam
Inform relevant authorities or cybersecurity forums about the scam to help prevent its spread.
🎓 Educate Yourself
Stay informed about the latest online scams and security best practices to enhance your defense against such threats.
How to Identify Scams That Imitate Legitimate Antivirus Notifications
As cybercriminals become more adept at crafting scams, distinguishing between genuine antivirus notifications and fraudulent ones is increasingly challenging. Below, we will discuss key indicators to help identify scams that imitate legitimate antivirus alerts.
🖥️ Unexpected Pop-Ups
Genuine software or operating system messages will never just pop up from a web browser. If you see sudden warnings or alerts while browsing, especially on streaming, downloading, or redirected sites, be wary.
⏳ Urgent Language
Scammers use phrases like “immediate action required” or “your data is at major risk” to pressure you into acting quickly without thinking.
🤳 Request for Personal Info
Official support teams, especially those from big names like Microsoft, won’t ask for personal or financial details through a browser pop-up.
📞 Suspicious Phone Numbers
The pop-up urges you to call a specific number, such as “+1-866-993-8594”. Always double-check any helpline numbers on the company’s official website before calling.
🛡️ Generic Titles and Logos
Scams often use generic terms like “PC Support” or display blurry or stretched logos. Authentic messages will have clear, high-quality branding and specific company names.
💰 Offers to “Fix” for a Fee
If the alert quickly leads to demands for payment, especially for services or software you’ve never heard of, it’s likely a scam.
📝 Poor Grammar and Spelling
Many scams have errors in their messages. If the wording seems off, or there are blatant spelling mistakes, be suspicious.
Threat Summary
Name | “Windows locked due to unusual activity” Scam |
Type | Tech Support Scam |
Fake claims | Claims device is infected with spyware, malware, virus |
Fake err | Windows locked due to unusual activity |
Scammers websites | d1z8pmvijkfxln.cloudfront.net, pleasuretubes.com, jakarotaji.pages.dev, islandka.pages.dev, icy-pebble-0b7320410.5.azurestaticapps.net, mango-plant-03fef0e10.5.azurestaticapps.net |
Scammers phone numabers | +1-877-200-1312, +1-866-993-8594, +1-866-464-0099, +1 (810) 471-4347, (050)-5479-6220, +1-866-464-0099 |
Distribution | Adware, malicious websites, push notifications, social engineering |
Damage | Financial loss, data compromise, installation of malicious software |
Indicators of the Scam | Alarming pop-up messages with urgent warnings; Fake security warning with error codes; Claims of illegal activities leading to device blockage; Urgent call to action to contact the provided phone number; Poorly designed websites with spelling errors and unprofessional elements |
Prevention Tips | Be cautious of unsolicited pop-ups and calls; Do not provide remote access to your device to unknown individuals; Use reliable security software and keep it updated; Educate yourself about common scams and their indicators |
How to remove “Windows locked due to unusual activity” pop-ups
If you have encountered “Windows locked due to unusual activity” pop-ups, you should not trust the message and refrain from clicking any buttons or links that appear on the page. Instead, follow the steps below to remove the pop-up and any potential malware from your computer:
To remove “Windows locked due to unusual activity” pop ups, complete the steps below:
- Close the pop-up
- Clear your browsing history
- Disable push notifications
- Scan your computer for malware
- Reset your browser settings
Close the pop-up
Closing the pop-up is the first step you should take when dealing with the “Windows locked due to unusual activity” scam. Although it may seem like a simple task, some users may find it challenging, especially if the pop-up is designed to be persistent and difficult to close. This step is crucial because it prevents the user from falling into the trap set by the scammers and clicking on any of the buttons or links that can lead to further harm. In this section, we will provide a detailed guide on how to close the “Virus-Warning Windows locked due to unusual activity” pop-up safely and effectively.
- Don’t click on anything within the pop-up as it could lead to further harm.
- Look for a small “X” or “Close” button within the pop-up window. Click on it to close the window.
- If there is no “X” or “Close” button, try pressing the “Esc” key on your keyboard to close the pop-up.
- If the pop-up still won’t close, try opening your computer’s Task Manager by pressing “Ctrl + Shift + Esc” on your keyboard (or “Ctrl + Alt + Delete” and then select “Task Manager”). Find the browser window that the pop-up is in, right-click on it, and select “End Task” to force close the window.
Clear your browsing history
Clearing your browsing history is an important step in removing “Windows locked due to unusual activity” pop-ups. These pop-ups often come from malicious websites that can be stored in your browsing history.
By clearing your browsing history, you can get rid of any traces of these websites and prevent the pop-ups from reappearing. In this step, we will walk you through how to clear your browsing history on different browsers.
- Open your browser’s settings or options menu. This can usually be accessed by clicking on the three dots or lines in the top right or left corner of the browser window.
- Scroll down to the “Privacy & Security” or “History” section of the settings menu.
- Click on “Clear Browsing Data” or “Clear History” (the wording may vary depending on the browser you are using).
- In the pop-up window that appears, choose the time range for which you want to clear your browsing history (e.g. “Last hour”, “Last 24 hours”, “All time”, etc.).
- Make sure that “Browsing history” or “History” is selected as one of the types of data to be cleared.
- Click on the “Clear Data” or “Clear History” button (the wording may vary depending on the browser you are using).
- Wait for the browser to finish clearing your browsing history. This may take a few moments, especially if you have a lot of browsing data stored on your computer.
- Close and restart your browser to ensure that the changes take effect.
Disable push notifications
If you’re experiencing persistent push notifications from websites that are showing “Windows locked due to unusual activity” scams, the best course of action is to disable push notifications altogether. Disabling push notifications prevents malicious websites from showing you unwanted pop-ups and alerts, which can help protect your computer from further harm. In this step, we’ll walk you through the process of disabling push notifications in your web browser.
Google Chrome:
- Click on ‘three dots menu’ button at the top-right corner of the Google Chrome window.
- Select ‘Settings’, scroll down to the bottom and click ‘Advanced’.
- At the ‘Privacy and Security’ section click ‘Site settings’.
- Click on ‘Notifications’.
- Locate a malicious site and click the three vertical dots button next to it, then click on ‘Remove’.
Android:
- Open Chrome.
- Tap on the Menu button (three dots) on the top right corner of the screen.
- In the menu tap ‘Settings’, scroll down to ‘Advanced’.
- In the ‘Site Settings’, tap on ‘Notifications’, locate a phishing URL and tap on it.
- Tap the ‘Clean & Reset’ button and confirm.
Mozilla Firefox:
- In the top right corner, click the Firefox menu (three bars).
- In the drop-down menu select ‘Options’. In the left side select ‘Privacy & Security’.
- Scroll down to ‘Permissions’ section and click ‘Settings…’ button next to ‘Notifications’.
- Find a suspicious URL, click the drop-down menu and select ‘Block’.
- Click ‘Save Changes’ button.
Edge:
- Click the More button (three dots) in the top-right corner of the window.
- Scroll down, locate and click ‘Settings’. In the left side select ‘Advanced’.
- In the ‘Website permissions’ section click ‘Manage permissions’.
- Disable the on switch for a malicious domain.
Internet Explorer:
- Click the Gear button on the top-right corner of the browser.
- Select ‘Internet options’.
- Click on the ‘Privacy’ tab and select ‘Settings’ in the pop-up blockers section.
- Locate a scam site and click the ‘Remove’ button to delete the site.
Safari:
- Go to ‘Preferences’ in the Safari menu.
- Select the ‘Websites’ tab and then select ‘Notifications’ section on the left panel.
- Find a phishing site and select it, click the ‘Deny’ button.
Scan computer for malware
If you have encountered the “Windows locked due to unusual activity” scam, it is possible that your computer has been infected with malware. In order to ensure that your system is completely clean, it is important to perform a thorough scan for malware. This will help to identify any malicious files or programs that may be hiding on your computer and remove them to prevent further damage. In this step, we will guide you through the process of scanning your computer for malware using trusted antivirus software.
Malwarebytes is a reputable anti-malware program that can effectively detect and remove adware, potentially unwanted programs and malware. It has a user-friendly interface and offers both free and paid versions, with the paid version offering real-time protection and other advanced features. To use Malwarebytes to remove malicious software, you can download and install the program, perform a scan of your system, and follow the prompts to remove any detected threats.
Visit the following link and download the latest version of Malwarebytes. Once the download is complete, run the installer and follow the instructions to install the program on your computer.
326379 downloads
Author: Malwarebytes
Category: Security tools
Update: April 15, 2020
Open Malwarebytes and click on the “Scan” button. The program will start scanning your computer for any malware or potentially unwanted programs. Depending on the size of your hard drive, this may take a few minutes to complete.
Once the scan is complete, Malwarebytes will display a list of any threats it has found. Review the list carefully and make sure that all the items are checked for removal. Then, click on the “Quarantine” button to remove the threats from your computer. After the removal process is complete, you may be prompted to restart your computer to complete the process.
Please follow this step-by-step video tutorial to learn how to use Malwarebytes to scan and remove any potential threats from your computer. The video will guide you through the entire process, from downloading and installing Malwarebytes to running a scan and removing any identified threats.
Reset your browser settings
If the “Windows locked due to unusual activity” pop-ups persist even after clearing your browsing history, disabling push notifications, and scanning your computer for malware, resetting your browser settings might be the next step to take. Resetting your browser settings can remove any unwanted extensions or changes made to your browser that may be causing the pop-ups to appear. In this step, we will guide you through the process of resetting your browser settings in different popular browsers.
To reset your browser settings in Google Chrome:
- Open Chrome and click on the three-dot icon in the top-right corner.
- Select “Settings” from the drop-down menu.
- Scroll down to the bottom of the page and click on “Advanced”.
- Scroll down to the “Reset and cleanup” section and click on “Restore settings to their original defaults”.
- Click “Reset settings” to confirm.
To reset your browser settings in Mozilla Firefox:
- Open Firefox and click on the three-line icon in the top-right corner.
- Select “Help” from the drop-down menu and then click on “Troubleshooting Information”.
- Click on the “Refresh Firefox” button in the top-right corner.
- Click “Refresh Firefox” again to confirm.
To reset your browser settings in Microsoft Edge:
- Open Edge and click on the three-dot icon in the top-right corner.
- Select “Settings” from the drop-down menu.
- Scroll down and click on “Reset settings”.
- Click “Restore settings to their default values”.
- Click “Reset” to confirm.
After resetting your browser settings, be sure to check for any remaining suspicious extensions and remove them if necessary.
Conclusion
In conclusion, the “Windows locked due to unusual activity” scam and similar deceptive schemes continue to pose a threat to unsuspecting individuals. By understanding the tactics employed by scammers, recognizing the red flags, and taking preventive measures, you can protect yourself from falling victim to these fraudulent schemes.
Remember to be cautious of suspicious pop-ups, unsolicited contact, and requests for personal or financial information. Legitimate companies will not display alarming messages or demand immediate action through aggressive pop-ups. Stay informed about common scams, rely on official support channels, and use reputable security software to safeguard your devices.