Defpush ads: what it is and how to remove it
Defpush.com is an advertising network misused by scammers to show notifications on Android. While it can also display its pop-up ads on Windows OS devices, the Android operating system is infected even more frequently.
Facts checked October 6, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Not sure what sends your browser to defpush.com? An automatic scan looks at the usual sources for you.
Do it yourself · free Remove Defpush ads yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Defpush ads: summary
| Distribution | Software bundles, deceptive ads |
|---|---|
| Name | Defpush |
| Type | Adware/PUP |
| Operating system affected | Android, Windows |
| detected as | JS.Defpush.com |
| Symptoms | Delivers intrusive content, causes redirects to unsafe sites, hides from the user to prevent removal |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| main risks | Once you allow push notifications, your browser is filled with dangerous content; you can be redirected to infected sites |
|---|---|
| Detection names | No Microsoft detection name is known |
| Damage | Not recorded in the old report |
| Evidence | 7 write-ups by security sites; details still limited |
| Domains | defpush.com |
| Ads shown as | Redirects through ad pages |
| Browsers | Chrome, Edge and Firefox |
| First seen | 2 January 2021 |
| Facts checked | 6 October 2026 |
Is Defpush ads dangerous?
From our report of Jan 2021 · not reviewed since
Defpush is the Android-based adware that changes settings and preferences on the device
Defpush.com is an advertising network misused by scammers to show notifications on Android.
While it can also display its pop-up ads on Windows OS devices, the Android operating system is infected even more frequently. The real reason why people are interrupted by aggressive notifications is the potentially unwanted program hiding in their system. The unwanted application redirects users to defpush.com and 2-3 other questionable websites.
While it is still unknown what is to blame for causing Defpush notifications on the screen, if you have recently installed some "helper", optimization tool, or a similar program that is supposed to enhance the work of your device, check it with anti-spyware. Use Android virus removal guide to reset your device to its factory settings.
The PUP has been associated with various commercial content delivered to victims while browsing the Internet. It is almost identical to other push notification viruses, such as Directlinkkpush.com, Exerciers.mobi, Worldnaturenet.xyz, and many others hijack systems to reroute victims to sponsored sites.
Unfortunately, you can't block Defpush notifications with the help of popular ad blockers. As soon as the user allows them, the virus modifies the web browser to stay on the system for as long as possible.
Victims infected with this Android virus should be careful when interacting with ads, as clicking on them can result in the installation of malware, useless extensions, or optimization tools.
This guarantees ad income for partners and boosts traffic to their websites, which artificially increases its rank. Nevertheless, if an advertisement redirects to a potentially malicious site, the user might accidentally get his/her computer infected with a Trojan horse, ransomware, or other viruses.
You can find the commercial content displayed by the Defpush virus is very tempting because it has also been sent to spy on its victims to know more about their preferences and browsing habits.
The adware can be set to track users' most visited sites, clicks, their location, IP address, geo-location, and any other information revealed during their searches. While adware threats do not collect personally identifiable information (PII), it can get access to your non-personal data and misuse it for marketing purposes.
If you have already noticed any of the above-mentioned symptoms, remove Defpush virus. Otherwise, you can find additional malware installed on your machine without you noticing. Besides, because of data tracking, the PUP can lead you to an increased amount of spam which has been actively used for spreading such threats as ransomware or trojans.
To proceed with the threat removal from Android and Windows, you need to employ reputable tools like , . They will help you get rid of all related components (browser helper objects, added registry entries, etc.) and will prevent virus reappearance in the future.
A full system scan is required for the elimination of all cyber infections if you want to delete them for good, so make sure you take care of your PC's security by selecting a reputable anti-spyware and keeping it up-to-date.
If you are wondering how to remove Defpush from Android, check our last section for more instructions. In short, you should reset your device to factory settings to get rid of all PUPs causing issues on it.
Note that if you hesitate to perform the elimination, the longer the unwanted app stays on your computer, the worse the browser struggles might get. Due to a huge number of adverts, web browsers might start operating very slowly and even crash.


From our report of Jan 2021 · not reviewed since
Free download sites and deceptive promotional ads lead to PUP infiltration
Since there is an opportunity to get anything online, people tend to use p2p networks or questionable sites as the source of the desired software.
However, security experts advise avoiding services that offer to share and downloading various programs for free. What you should do is always opt for a reputable website or the official App Store when in need of something.
Also, choosing Advanced or Custom options during installations can be crucial for the security of your device since these settings allow you to de-select unwanted additional programs from the list.
This way you make sure that the software you need gets installed on the device and nothing else. Make sure you never perform installations when the Quick/Recommended mode is on, otherwise, PUPs might be able to infiltrate your system unnoticed very easily.
Keep your software, programs, and anti-malware tools up-to-date so no deceptive advertisement can trick you into purchasing anything useless. Various ads promote system optimization tools or display alerts about the poor security of your PC with the purpose of downloading their product onto your system. If you always pay attention to your online activity and be cautious while performing computing work, you can avoid cyber intruders in the future.

From our report of Jan 2021 · not reviewed since
More from our earlier report on Defpush
- Use for system cleaning and fixing the virus damage
Check your browser and PC
- Address:
defpush.com
How to remove Defpush ads
How to remove the Defpush extension
Do the browser steps in every browser and profile on the PC, then check Windows for the program that installed the extension.
Step 1: Remove extensions you did not add
In Chrome open
chrome://extensions, in Edgeedge://extensions, and in Firefox the menu > Extensions and themes.Remove every extension you do not remember adding, especially search, new tab, coupon, PDF, weather or video downloader add-ons. Check every browser and every profile, because each keeps its own list.
If an extension has no Remove button or comes back, a browser policy holds it (see "Managed by your organization" in the procedure below). The pages are the same on Windows 11 and Windows 10.

Chrome on Windows 11: More > Extensions > Manage extensions. Full procedure with screenshots: Remove a browser extension
Step 2: Uninstall programs you did not mean to install
Defpush rarely comes alone: it is usually installed by, or together with, a free program. In Windows 11 open Settings > Apps > Installed apps, in Windows 10 Settings > Apps > Apps & features, and sort by install date.
Uninstall every entry from the day the trouble began that you did not install on purpose, for example a download manager, a converter or a browser you never chose.
Keep drivers and entries from Microsoft, Intel, AMD, NVIDIA or your PC's maker unless you are sure.
Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix
Step 3: Reset the browser
A reset removes what the steps above could miss:
- changed start pages
- site permissions
- hidden settings
In Chrome open Settings > Reset settings > Restore settings to their original defaults; in Edge Settings > Reset settings; in Firefox Help > More troubleshooting information > Refresh Firefox.
Tip: Bookmarks and saved passwords stay, while extensions are turned off and the search engine and start page return to the defaults.
Reset every browser on the PC, including Edge, which Windows 11 and Windows 10 always have.

Chrome on Windows 11: Settings > Reset settings. Full procedure with screenshots: Reset a browser and fix a hijacked search engine
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of Defpush that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Uninstall from Windows
Uninstall from Windows 10/8:
- Type Control Panel into the Windows search box and open the result.
- Under Programs, select Uninstall a program.

Uninstall from Windows 7/XP:
- Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
- In Control Panel, select Programs > Uninstall a program.

Remove the unwanted program:
- In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
- If User Account Control appears, click Yes to confirm, then complete the removal.

Remove from Google Chrome
Delete malicious extensions from Google Chrome:
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.

Clear cache and web data from Chrome:
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.

Change your homepage:
- Click menu and choose Settings.
- Look for a suspicious site in the On startup section.
- Click on Open a specific or set of pages and click on three dots to find the Remove option.
Reset Google Chrome:
If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:
- Click on Menu and select Settings.
- In the Settings, scroll down and click Advanced.
- Scroll down and locate Reset and clean up section.
- Now click Restore settings to their original defaults.
- Confirm with Reset settings.

Remove from Microsoft Edge
Delete unwanted extensions from MS Edge:
- Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
- From the list, pick the extension and click on the Gear icon.
- Click Remove.

Clear cookies and other browser data:
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
- Under Clear browsing data, pick Choose what to clear.
- Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.

Restore new tab and homepage settings:
- Click the menu icon and choose Settings.
- Then find On startup section.
- Click Remove next to any suspicious startup page.
Reset MS Edge if the above steps did not work:
- Press on Ctrl + Shift + Esc to open Task Manager.
- Click on More details arrow at the bottom of the window.
- Select Details tab.
- Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.

Delete extensions from MS Edge (Chromium):
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.

Clear cache and site data:
- Click on Menu and go to Settings.
- Select Privacy, search and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.

Reset Chromium-based MS Edge:
- Click on Menu and select Settings.
- On the left side, pick Reset settings.
- Select Restore settings to their default values.
- Confirm with Reset.
- This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.

Remove from Mozilla Firefox (FF)
Fix Firefox by using the following guide:
Remove dangerous extensions:
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- In here, select the unwanted extension and click Remove.

Reset the homepage:
- Click three horizontal lines at the top right corner to open the menu.
- Choose Settings.
- Under Home, set your preferred homepage and new tab settings.
Clear cookies and site data:
- Click Menu and pick Settings.
- Go to Privacy & Security section.
- Scroll down to locate Cookies and Site Data.
- Click on Clear Data...
- Select Cookies and Site Data and Temporary cached files and pages, then click Clear.

Reset Mozilla Firefox
If clearing the browser as explained above did not help, reset Mozilla Firefox:
- Open Mozilla Firefox browser and click the Menu.
- Go to Help and then choose Troubleshooting Information.

- Under Give Firefox a tune up section, click on Refresh Firefox...
- Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.

Delete from Safari
If Safari got hijacked by the potentially unwanted program, you can reverse all changes by looking thru these steps:
Remove dangerous extensions:
- Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
- Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.

Clear history and website data:
- Click Safari in the menu and pick Clear History.
- Set Clear to all history and confirm with Clear History.

Reset Safari:
- Click Safari in the menu and select Preferences > Advanced.
- Enable Show Develop menu in menu bar.
- From the menu bar, click Develop and select Empty Caches.

Do not let government spy on you
The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices.
Avoid any unwanted government tracking or spying by going totally anonymous on the internet.
You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using VPN.
Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.
Backup files for the later use, in case of the malware attack
Computer users can suffer from data losses due to cyber infections or their own faulty doings.
Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact - you can set this process to be performed automatically.
When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use for the data restoration process.
From our report of Jan 2021 · not reviewed since
Get the proper AV tool for a successful Defpush removal
You should get rid of these notifications immediately after noticing them on your web browser because they are the main sign informing you about the adware's presence on the system.
Unfortunately, closing the pop-up window is not enough because it only closes the possibly malicious page. Adware and any other cyber intruder should be removed during a full system scan which eliminates the threat together with additional pieces of malware.
Automatic Defpush removal is easier to take care of because it takes less time and effort. However, you should not forget to block notifications and reset your web browsers to Default. While it takes some time, you should fix your browser fully to forget about unwanted ads while browsing thru your favorite sites.
Moreover, to block notifications on your web browser, use the following steps:
From our report of Jan 2021 · not reviewed since
Google Chrome
- Open the browser and select Customize and Control Google Chrome from the options after clicking three dots in the top right corner;
- Click Settings -> Advanced and select Content Settings;
- Click three dots and select Block under each of these entries.
From our report of Jan 2021 · not reviewed since
Mozilla Firefox
- Open the browser and click three lines in the top right corner of the browser;
- Select Options -> Privacy and Security;
- Click on Permissions and select Notifications -> Settings;
- Find hxxps://xxps://defpush.com and related entries and click Block;
- Select Save Changes.
From our report of Jan 2021 · not reviewed since
The virus removal from Android
Defpush.com notification elimination from Android requires you to enter Safe Mode and uninstalling all suspicious applications with admin rights.
To enter Safe Mode, follow these steps:
When in Safe mode, go to Settings -> Apps and check for suspicious entries. Eliminate them at once.
After that, open Chrome app and go to Defpush.com. Tap on Menu -> Info. Select Site Settings -> Notifications. Choose block.
- Press and hold the Power button for a couple of seconds;
- Tap and hold on Power off, and a pop-up window will appear, asking if you are willing to enter Safe Mode;
- Press OK;
- After the reboot, you will be in the Safe Mode.
Questions about Defpush ads
How do I stop defpush.com from opening?
Find and remove whatever opens it. Start with the browser's extensions page and remove anything you do not remember adding. Next, open the notification settings and take away permission from sites you do not recognise.
Then check Settings > Apps > Installed apps for programs added around the day the redirects began, and uninstall those. Restart the browser and test a few links after each step.
If defpush.com still appears, reset the browser, which restores the default search engine, start page and permissions without deleting bookmarks or saved passwords. Redirects that survive a reset in every browser point to a program in Windows, and a full scan is the next step.
Is it safe that my browser was redirected to defpush.com?
Landing on defpush.com does not infect the PC by itself. A browser does not run programs from a page without your action. The danger is in the pages that come next:
- some ask you to allow notifications
- some show fake virus warnings
- some offer downloads
- ask for card details
If you only saw those pages and closed them, nothing more is needed than removing whatever caused the redirect. If you allowed notifications, remove that permission.
If you downloaded a file, delete it unopened, or uninstall it if you ran it. If you typed a password or card number on one of the pages, change the password and call your bank.
Why does Defpush show me ads?
Because that is its whole purpose. Defpush is an adware extension, and its operators are paid for every ad it displays and every click it gets. In this case the ads take the form of redirects through ad pages.
They are chosen by ad networks that accept almost any advertiser, which is why so many look like warnings or prizes. The ads are not a sign that your PC is broken or infected with something worse; they are a sign that something on it, or in the browser, has permission to advertise. Removing that permission or program stops them.
Do I have to clean every browser?
Yes, if you use more than one. We saw Defpush in Chrome, Edge and Firefox, and each browser keeps its own extensions, notification permissions and settings. Chrome and Edge share the same extension format, so one installer can add the same adware to both, while Firefox has its own add-ons.
Check every browser on the PC, including ones you rarely open. If you sync a browser with an account, clean it while signed in, so that the removal reaches your other computers rather than the adware returning from them.
How do I know the ads come from Defpush?
Look for redirects to defpush.com. That is the trace Defpush leaves, and it shows up as redirects through ad pages. Ads that appear on every site, including ones that never carried ads before, point to something on your PC or in the browser rather than to the sites themselves.
A quick test is a private window, where extensions are off by default: if the ads disappear there, an extension is responsible. If they appear even with the browser closed, the source is a notification permission or a program in Windows.
Why didn't my antivirus catch Defpush?
Many security products do not block adware or notification sites by default, because users often agreed to them, even through a misleading prompt. Notification spam installs nothing at all, so there is no file to detect.
In Windows 11 you can make Microsoft Defender block potentially unwanted apps: open Windows Security > App & browser control > Reputation-based protection settings and turn on Potentially unwanted app blocking. If notifications caused the pop-ups, no scanner will report them; the fix is in the browser's site settings.
An ad showed a phone number and I called it. What now?
The number belongs to scammers, not to Microsoft or an antivirus company. If you only talked, hang up and do not call back. If you let them connect to the PC, disconnect it from the internet, uninstall the remote access program they used, such as AnyDesk, TeamViewer, ScreenConnect or UltraViewer, and run a full and offline scan.
If you paid or gave bank details, call your bank at once on the number printed on your card. Change any passwords you typed while they were connected, and report the call.
Can adware slow down my PC?
Yes. Adware runs in the background, loads ad scripts, opens extra tabs and contacts its servers, all of which use processor time, memory and bandwidth. Ad-heavy extensions also slow down every page, because they inspect and change it before you see it.
The effect is strongest on older PCs and when several adware programs arrived together. After removal, restart the PC and check Task Manager for anything still using a lot of resources that you do not recognise. Speed usually returns to normal once the ads stop.
I clicked on one of the ads. Am I infected?
Probably not. Clicking an ad usually only opens a page, and a page cannot install programs on an up-to-date Windows PC without your help.
You are at risk only if you then downloaded and ran a file, allowed notifications, entered card or login details, or called a phone number shown on the page. Delete any download and run a full and offline scan.
Change passwords you typed, from a clean device. Call your bank if you gave card details. If you called a number or allowed remote access, see the next question.
Will Fortect remove Defpush?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Defpush, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Search Security: PUP (potentially unwanted program) (read October 6, 2026)
- Wikipedia: Trojan horse (computing) (read October 6, 2026)
- Google Chrome Help: Use notifications to get alerts (no longer online) (read October 6, 2026)
- FTC: How to recognize, remove and avoid malware (read October 6, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 6, 2026)