Windows 10 May Be In Danger e-mail scam: how to spot it and what to do

"Windows 10 May Be In Danger" is a web scam that uses various scare tactics to make users install antivirus software. The page promotes a legitimate antivirus tool called Total AV.

Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Windows 10 May Be In Danger e-mail scam yourself 4 steps, about 12 minutes, no software needed.

Start the steps
Windows 10 May Be In Danger: scam
Windows 10 May Be In Danger as our 2021 report showed it.

Windows 10 May Be In Danger e-mail scam: summary

DistributionCompromised websites, deceptive ads, software bundling
NAMEWindows 10 May Be In Danger
TYPEOnline scam; adware
SYMPTOMSA page pop-ups up claiming that Windows 10 could be infected with viruses
DANGERSInstallation of PUPs or malware, sensitive information disclosure, monetary losses
NameWindows 10 May Be In Danger
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
TypePhishing message
SymptomsA phishing e-mail asking you to sign in
Evidence5 write-ups by security sites; details still limited
Arrives asE-mail
Pretends to beA well-known company
ClaimYour account needs urgent attention
Asks forYour password
First seen22 December 2021
Facts checked7 October 2026

What the Windows 10 May Be In Danger e-mail scam e-mail looks like

a phishing e-mail asking you to sign in

Check Windows for hidden malicious codes!

Windows 10 may be in danger. The system could be infected.System potencial damage: 28.1%

REMOVE SYSTEM JUNK AND POSSIBLE VIRUSES!

It is recommended to remove possible viruses to prevent system damage, loss of files, and other

sensitive data.

Chrome 96 0 4664 can work with errors IP 172.58 236 177.

Step 1: Click on the "Proceed" button to check your computer for viruses.

1 minutes and 56 seconds remaining...

Proceed >>

How to tell the Windows 10 May Be In Danger e-mail scam e-mail is fake

From our report of Dec 2021 · not reviewed since

  • In order to avoid viewing malicious ads, you should install a reliable ad-blocking app.
  • You should also check your system for adware – you can either do it manually or perform a full system scan with antivirus for a quicker solution

Is Windows 10 May Be In Danger e-mail scam dangerous? What the senders want

From our report of Dec 2021 · not reviewed since

Scammers use social engineering techniques

Social engineering is a manipulation tactic that exploits human error.

In this case, scammers want to frighten users into taking an action. First, they do this by designing the website to look like a legitimate Microsoft page. They even put Microsoft's support email address in the corner to gain trust.

The page also shows the user's IP address and browser version. This is also meant to make users believe the message shown. This tactic is also used in another scam that we previously wrote about called "IP address & personal information might be exposed."

The truth is that almost every website you visit can see your IP address, browser version, and approximate location if you have that turned on because they use cookies. So do not be fooled if you see your "personal information" flashing on the screen. Scammers want you to act quickly before you have a chance to think.

Second, fraudsters use words that may raise concerns for average users who are less IT-savvy. The message that people first see says:

They also use a time limit to introduce a sense of urgency and leave no time for people to think. Once users proceed, the page shows a "SCAN IN PROGRESS" message.

Of course, after the scan is complete, the page shows a bunch of viruses that have apparently infected the device. The website says that in order to remove them, people need to download special software, and this is the part where users get redirected to the Total AV website.

Windows 10 May Be In Danger: scare tactics
Windows 10 May Be In Danger in our 2021 report.

From our report of Dec 2021 · not reviewed since

"Windows 10 May Be In Danger" scam uses scare tactics to promote a legitimate antivirus tool

"Windows 10 May Be In Danger" is a web scam that uses various scare tactics to make users install antivirus software.

The page promotes a legitimate antivirus tool called Total AV. However, the developers of the program have nothing to do with this fraudulent campaign. Users can sign up for an affiliate program via the Total AV official website, so the crooks probably receive revenue for every installation with their link.

Schemes like this are usually promoted on shady websites that engage in illegal activities because they are unregulated. Untrusted advertising networks can place their ads in them and lure users in with deceptive messages. Another reason why you could have ended up on this page is that you have adware hiding in your system that generates unwanted commercial content like pop-ups, banners, and redirects in your machine.

Windows 10 May Be In Danger: scam
Windows 10 May Be In Danger in our 2021 report.

What to do after the Windows 10 May Be In Danger e-mail

If you only received the message and clicked nothing, step 3 is all you need.

If you clicked the link or typed anything on the page it opened, do every step, starting with the password.

  1. Step 1: Change the password you typed on the fake page

    If you typed a password on the page the Windows 10 May Be In Danger message opened, assume the sender has it. Go to the real site by typing its address yourself and change the password there, choosing one you have never used.

    Change it anywhere else the same password was used, and sign out all other sessions if the service offers it. Any browser on Windows 11 or Windows 10 will do, as long as you do not follow the e-mail's link.

    Microsoft account Security page with Change password at the top
    Microsoft account, Security page (account.microsoft.com/security): Change password.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

  2. Step 2: Turn on two-step verification

    With two-step verification on, a stolen password alone no longer opens the account, because a sign-in from a new device also needs a code from your phone.

    Switch it on for the e-mail account first, then for banking, shopping and social accounts that use that address.

    Check the recovery phone, the recovery e-mail and any forwarding rules while you are in the settings, since attackers change them to come back. The pages are the same on Windows 11 and Windows 10.

    Microsoft account Manage how I sign in page with the sign-in methods
    Microsoft account: Manage how I sign in, where two-step verification and the sign-in methods are.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

  3. Step 3: Report the e-mail and delete it

    Do not reply and do not click anything else in the message. In Outlook select the e-mail and choose Report > Report phishing; in Gmail open the three-dot menu next to Reply and pick Report phishing.

    That trains the filter for everyone on the service, and the message goes to the junk folder. If the e-mail came to a work address, forward it to your IT team as an attachment first.

    The steps are the same in the web mail and the mail apps on Windows 11 and Windows 10.

    Outlook Report menu with Report phishing selected
    New Outlook for Windows and Outlook on the web: Report > Report phishing.

    Full procedure with screenshots: Report a phishing e-mail

  4. Step 4: Scan the PC if you opened a file from the message

    A fake sign-in page only steals what you type, so most readers can skip this step. If the Windows 10 May Be In Danger e-mail made you download or open a file, delete it and scan the PC.

    In Windows Security > Virus & threat protection > Scan options, run a Full scan and then Microsoft Defender Antivirus (offline scan) > Scan now. The offline scan restarts Windows 11 or Windows 10 and takes about 15 minutes.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Choose a proper web browser and improve your safety with a VPN tool

Online spying has got momentum in recent years and people are getting more and more interested in how to protect their privacy online.

One of the basic means to add a layer of security - choose the most private and secure web browser. Although web browsers can't grant full privacy protection and security, some of them are much better at sandboxing, HTTPS upgrading, active content blocking, tracking blocking, phishing protection, and similar privacy-oriented features.

However, if you want true anonymity, we suggest you employ a powerful VPN - it can encrypt all the traffic that comes and goes out of your computer, preventing tracking completely.

Lost your files? Use data recovery software

While some files located on any computer are replaceable or useless, others can be extremely valuable.

Family photos, work documents, school projects - these are types of files that we don't want to lose. Unfortunately, there are many ways how unexpected data loss can occur:

  • power cuts
  • Blue Screen of Death errors
  • hardware failures
  • crypto-malware attack
  • even accidental deletion

To ensure that all the files remain intact, you should prepare regular data backups. You can choose cloud-based or physical copies you could restore from later in case of a disaster. If your backups were lost as well or you never bothered to prepare any, can be your only hope to retrieve your invaluable files.

From our report of Dec 2021 · not reviewed since

Start the removal process

You might be seeing the "Windows 10 May Be In Danger" scam page because you have a malicious extension added to your browser which is causing pop-ups, banners, redirects, and an overall increase of commercial content in your device. Even if you do not notice these symptoms we suggest investigating your browser.

The first thing you should do is go to your browser settings and check if you see any suspicious add-ons in the list. The best way to do this is by removing the extensions one by one and seeing if you notice any difference. You can follow our guide if you need help:

MS Edge (Chromium)

One more thing you should do is clean cookies and cache from your browser. Many websites use these tracking technologies to see the links you click on, things you purchase online, and other data like your IP address, which we mentioned before. Generally, these technologies help websites to personalize the user experience.

But we see that more often, cookies are used to generate revenue. They can be sold to advertising networks or other third parties and used for malicious purposes so security experts recommend clearing them regularly. You can use a maintenance tool like which will do this automatically.

  • Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  • In the newly opened window, you will see all the installed extensions. Uninstall all the suspicious plugins that might be related to the unwanted program by clicking Remove.
  • Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  • From the list, pick the extension and click on the Gear icon.
  • Click on Uninstall at the bottom.
  • Open Edge and click select Settings > Extensions.
  • Delete unwanted extensions by clicking Remove.
  • Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  • Select Add-ons.
  • In here, select unwanted plugin and click Remove.
  • Click Safari > Preferences...
  • In the new window, pick Extensions.
  • Select the unwanted extension and select Uninstall.
  • Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
  • Pick Manage Add-ons.
  • You will see a Manage Add-ons window. Here, look for suspicious plugins. Click on these entries and select Disable.

From our report of Dec 2021 · not reviewed since

Remove PUPs hiding in your system

Manual removal of a PUP can be tricky if you do not have experience.

Even if you uninstall the program itself, it can leave some traces behind (like files, registry entries, etc) which can result in a renewal of the infection.

PUAs are also often disguised as handy tools that you would never suspect. Professional security tools will scan your machine, eliminate intruders, and prevent such infections in the future by giving you a warning before a suspicious program can make any changes.

Adware is mostly spread on freeware distribution sites. The owners include additional programs in the installers without clearly disclosing this on their platforms. Most people skip through the installation process and do not notice bundled software. That is why it is so important to have a tool that can detect these processes for you.

You can use the guide below to remove Total AV if you have installed it or to try to identify any suspicious programs that should not be on your computer.

  • Enter Control Panel into Windows search box and hit Enter or click on the search result.
  • Under Programs, select Uninstall a program.
  • From the list, find the entry of the suspicious program.
  • Right-click on the application and select Uninstall.
  • If User Account Control shows up, click Yes.
  • Wait till uninstallation process is complete and click OK.
  • Click on Windows Start > Control Panel located on the right pane (if you are Windows XP user, click on Add/Remove Programs).
  • In Control Panel, select Programs > Uninstall a program.
  • Pick the unwanted application by clicking on it once.
  • At the top, click Uninstall/Change.
  • In the confirmation prompt, pick Yes.
  • Click OK once the removal process is finished.

Questions about Windows 10 May Be In Danger e-mail scam

I opened the "Check Windows for hidden malicious codes!" e-mail. Am I hacked?

No. Opening and reading a phishing e-mail does not give anyone access to your account or your PC. Modern mail programs block scripts and remote content by default, so reading the message "Check Windows for hidden malicious codes!" only showed you text and pictures.

The danger comes from clicking the button and typing your password on the page it opens, or from opening an attached file. If you did neither, report the message as phishing and delete it.

If you clicked but closed the page without typing anything, there is also nothing to fix. If you did type a password, change it from another device and turn on two-step verification.

How fast do I need to react after signing in on the "Check Windows for hidden malicious codes!" page?

As fast as you can. Stolen passwords are often tried within minutes, and the first thing an attacker usually changes is the recovery e-mail or phone, which locks you out. Change the password from a clean device first, then sign out everywhere and review the recovery settings.

If you are already locked out, use the provider's account recovery form straight away and mention that the page behind "Check Windows for hidden malicious codes!" took your password. Warn your contacts, since a taken-over mailbox is often used to send the same phishing to them.

Could Windows 10 May Be In Danger be a genuine message?

We checked it, and it is not. A well-known company is only the costume. The message exists to get your password, and real companies handle that inside your account, after you sign in normally, not through links, attachments or phone numbers in a message you did not expect.

Scammers copy logos and footers perfectly, so the design proves nothing. The sender address, the link target and the request are the reliable signs, and all three point to a scam here. Delete it, and if you are worried, check your account directly.

Why does Windows 10 May Be In Danger say that your account needs urgent attention?

Because that story works. A problem that needs fixing, a deadline and a simple solution make people act before they check.

The claim that your account needs urgent attention is the same for everyone who received Windows 10 May Be In Danger; it was written once and sent in bulk. Nothing about your own situation triggered it.

If you are unsure, look at the real account or service the normal way, without using the message. The claim will not be there, which settles the question. Then report the message.

What does Windows 10 May Be In Danger want from me?

In the end, your password. Everything else in Windows 10 May Be In Danger, from the logo to the deadline, is there to get you to that point without stopping to think.

Knowing the goal helps you judge your risk. If you did not give it, you lost nothing and can delete the message. If you did, the steps in this guide are ordered by what you handed over:

  • passwords first
  • then card and bank details
  • then documents and anything you installed
  • ran

Act on the highest item on that list first.

How do I contact the real a well-known company?

Not through anything in Windows 10 May Be In Danger. Type the official website address into the browser yourself, use the app you already have, or use the phone number printed on your card, contract or a previous genuine invoice.

Search results can be risky too, because scammers buy ads for support numbers. Once you reach the real a well-known company, you can ask whether there is any problem with your account and report the scam message; many companies have a dedicated address for phishing reports on their security page.

Who should I contact about Windows 10 May Be In Danger?

Start with the company whose account is involved, through its official website or app, never through links or numbers in messages. If money moved, call your bank or card issuer using the number on the card.

Then report the incident: in the US to the FTC at ReportFraud.ftc.gov, in the UK to Action Fraud, in Canada to the Canadian Anti-Fraud Centre and in Australia to ReportCyber. Keep notes of an e-mail with the subject "Check Windows for hidden malicious codes!", with dates and amounts; banks and police will ask for them.

Is it worth reporting a scam if I lost nothing?

Yes. Reports from people who did not fall for Windows 10 May Be In Danger are how blocklists, mail filters and hosting companies find new scam pages quickly, often before most recipients open the message. Reporting the message as phishing in your mail app is enough for most people.

If the message impersonates a company, its security or abuse team usually accepts forwarded copies too. Police reports matter mainly when money or documents were lost, but national fraud centres also collect reports without losses to spot campaigns.

Does Windows 10 May Be In Danger mean my PC is hacked?

Not necessarily. The sign reported, an e-mail with the subject "Check Windows for hidden malicious codes!", is usually caused by a password that leaked or was phished, not by malware on the PC.

Passwords leak in breaches of other websites and are tried on many services. Still, rule out the PC:

  • run a full scan in Windows Security
  • check Installed apps for anything you do not recognise
  • look at the browser's extensions

If all is clean, the problem lies with the account, and changing the password with two-step verification turned on is the fix.

Will Fortect remove Windows 10 May Be In Danger?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Windows 10 May Be In Danger, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove Immediate Action Required

Immediate Action Required is a fake notification that might pop-up out of nowhere and prompt users to download useless bogus software Immediate Action Required is a scam that users mightAdwareMedium riskUgnius Kiguolis ·

Remove ReceiverHelper Mac virus

ReceiverHelper virus is a high threat to your personal safety and Mac security ReceiverHelper is a harmful application targeting Mac devices, classified under the Adload malware family. It is notoriousAdwareMedium riskJake Doevan ·

Remove Casalemedia

Casalemedia is a legal advertising service but is sometimes abused by crooks to gain personal income Casalemedia is a legitimate advertising service that provides assistance in monetizing on online contentAdwareMedium riskJake Doevan ·

Remove D1ue3yi0hkdsdl.cloudfront.net ads

D1ue3yi0hkdsdl.cloudfront.net ads is the content related to scam campaigns and fake errors or warnings D1ue3yi0hkdsdl.cloudfront.net is the program that causes notifications and advertisements that may appear unexpectedly, preventing you fromAdwareMedium riskJulie Splinters ·

Questions and experiences: Windows 10 May Be In Danger e-mail scam

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year