Windows Security has been Compromised ads: what it is and how to remove it

Windows Security has been Compromised is a deceptive notification which appears on the screen during browsing sessions and prevents users from using their browser. The screen-locking feature allows tricking people into believing that their computers are infected, and they must take immediate actions.

Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan checks installed programs, startup items and browser extensions for anything that came with Windows Security has been Compromised.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Windows Security has been Compromised ads yourself 4 steps, about 12 minutes, no software needed.

Start the steps
Windows Security has been Compromised: scam message
Windows Security has been Compromised as our 2018 report showed it.

Windows Security has been Compromised ads: summary

DistributionSpreads via bundling method
NameWindows Security has been Compromised
TypeMalware
Danger levelMedium. Includes a screen-locking feature
SymptomsLocks the screen and displays a fake message saying that Windows security has been compromised
Indicated number+1 888 398 0888
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 6 more facts
Detection namesNo Microsoft detection name is known
DamageNot recorded in the old report
Evidence4 write-ups by security sites; details still limited
ProgramWindows Security has been Compromised
First seen26 September 2018
Facts checked7 October 2026

Is Windows Security has been Compromised ads dangerous?

From our report of Sep 2018 · not reviewed since

Windows Security has been Compromised is a fake message trying to trick people into purchasing useless security tools

Windows Security has been Compromised is a deceptive notification which appears on the screen during browsing sessions and prevents users from using their browser.

The screen-locking feature allows tricking people into believing that their computers are infected, and they must take immediate actions. For that, cybercriminals offer to purchase a new Microsoft License via an inbuilt button on the pop-up window. However, experts note that your system is not infected and you should not click on any content in the message since it is a technical support scam .

Windows Security has been Compromised message indicates that an adware program sneaked into your system. Usually, you might unconsciously install it while installing third-party applications from unreliable developers. As soon as it settles, this ad-supported program modifies browser settings to redirect users to a website showing this fake notification.

Here is the fraction of Windows Security has been Compromised alert:

Furthermore, the criminals behind Windows Security has been Compromised virus claim that users and re-install Windows but that would lead to data loss. They indicate another option — purchase a new license key by clicking on "What to do?" button below the message.

We want to warn you that "Windows Security has been Compromised" message is a scam, and you should never fall for this fake technical support trick. Your computer is not infected, and you do NOT need to pay for a supposedly new Microsoft license key. In fact, you only need to uninstall the adware redirecting you to this message.

Keep in mind that you should NOT call via the indicated +1 888 398 0888 number either. Usually, cybercriminals ask to give remote access to the computer to clean the infections allegedly. In reality, hackers install numerous potentially unwanted programs (PUPs) to force you to keep using their services and paying.

Our experts say that the easiest way to remove Windows Security has been Compromised message is download and install a robust antivirus software.

Additionally, a wise decision is to run a full system scan with after Windows Security has been Compromised removal as it can help you eliminate virus damage and restore any modifications that were previously made.

Windows Security has been Compromised: virus message
The message as our 2018 report captured it.

From our report of Sep 2018 · not reviewed since

More from our earlier report on Windows Security has been Compromised

  • Get a professional malware removal software to get rid of "Windows Security has been Compromised" virus.
  • Windows Security has been Compromised Your Windows Security has been Compromised and Microsoft has detected an unsolvable threat and this threat can result a great loss to your computer and it has been violated the terms of Microsoft.
  • We (microsoft) will not be the responsible for any kinds of security threats.
  • Your PC has been Blocked, so you cannot access your PC right now and it is very much bad for you.
  • We have covered you with 2 options

How Windows Security has been Compromised ads got into your browser

From our report of Sep 2018 · not reviewed since

Most commonly, adware and similar potentially unwanted program (PUPs) come in a bundle with freeware so users might not notice how it was installed on their computers.

Therefore, it is essential to pay close attention during the installation of third-party applications if you want to keep your system safe.

For that, you should reject the Quick/Recommended installation mode once it is offered. Instead, pick Custom/Advanced and attentively follow the steps. Usually, adware appears as a pre-selected checkmark that should be de-selected. Always look for those additional components and reject them.

How to remove Windows Security has been Compromised ads

How to remove the Windows Security has been Compromised extension

Do the browser steps in every browser and profile on the PC, then check Windows for the program that installed the extension.

  1. Step 1: Remove extensions you did not add

    In Chrome open chrome://extensions, in Edge edge://extensions, and in Firefox the menu > Extensions and themes.

    Remove every extension you do not remember adding, especially search, new tab, coupon, PDF, weather or video downloader add-ons. Check every browser and every profile, because each keeps its own list.

    If an extension has no Remove button or comes back, a browser policy holds it (see "Managed by your organization" in the procedure below). The pages are the same on Windows 11 and Windows 10.

    Chrome menu with Extensions and Manage extensions highlighted
    Chrome on Windows 11: More > Extensions > Manage extensions.

    Full procedure with screenshots: Remove a browser extension

  2. Step 2: Uninstall Windows Security has been Compromised

    Windows Security has been Compromised is removed like any other program, from the list of installed apps. In Windows 11 that is Settings > Apps > Installed apps, in Windows 10 Settings > Apps > Apps & features, and in both you can also use Control Panel > Programs and Features.

    Select Windows Security has been Compromised, click Uninstall and follow the uninstaller to the end. Then look at the entries just above and below it when the list is sorted by date: bundled programs install at the same minute.

    Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix

  3. Step 3: Reset the browser

    A reset removes what the steps above could miss:

    • changed start pages
    • site permissions
    • hidden settings

    In Chrome open Settings > Reset settings > Restore settings to their original defaults; in Edge Settings > Reset settings; in Firefox Help > More troubleshooting information > Refresh Firefox.

    Tip: Bookmarks and saved passwords stay, while extensions are turned off and the search engine and start page return to the defaults.

    Reset every browser on the PC, including Edge, which Windows 11 and Windows 10 always have.

    Chrome Settings page with the Reset settings section open
    Chrome on Windows 11: Settings > Reset settings.

    Full procedure with screenshots: Reset a browser and fix a hijacked search engine

  4. Step 4: Scan the PC, then run the offline scan

    A scan finds the parts of Windows Security has been Compromised that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Instructions for each browser and system

The detailed steps for every browser and system this guide covers. Open the one you use.

Uninstall from Windows

Get rid of suspicious programs from Windows OS first:

Uninstall from Windows 10/8:

  1. Type Control Panel into the Windows search box and open the result.
  2. Under Programs, select Uninstall a program.Uninstall from Windows 10/8

Uninstall from Windows 7/XP:

  1. Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
  2. In Control Panel, select Programs > Uninstall a program.Uninstall from Windows 7/XP

Remove the unwanted program:

  1. In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
  2. If User Account Control appears, click Yes to confirm, then complete the removal.Uninstall the unwanted program from Windows
Remove from Google Chrome

Get rid of Windows Security has been Compromised message from Chrome by uninstalling unknown extensions.

Delete malicious extensions from Google Chrome:

  1. Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  2. In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.Remove extensions from Chrome

Clear cache and web data from Chrome:

  1. Click on Menu and pick Settings.
  2. Under Privacy and security, select Clear browsing data.
  3. Select Browsing history, Cookies and other site data, as well as Cached images and files.
  4. Click Clear data.Clear cache and web data from Chrome

Change your homepage:

  1. Click menu and choose Settings.
  2. Look for a suspicious site in the On startup section.
  3. Click on Open a specific or set of pages and click on three dots to find the Remove option.

Reset Google Chrome:

If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:

  1. Click on Menu and select Settings.
  2. In the Settings, scroll down and click Advanced.
  3. Scroll down and locate Reset and clean up section.
  4. Now click Restore settings to their original defaults.
  5. Confirm with Reset settings.Reset Chrome 2
Remove from Microsoft Edge

Delete unwanted extensions from MS Edge:

  1. Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  2. From the list, pick the extension and click on the Gear icon.
  3. Click Remove.Remove extensions from Edge

Clear cookies and other browser data:

  1. Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
  2. Under Clear browsing data, pick Choose what to clear.
  3. Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.Clear Edge browsing data

Restore new tab and homepage settings:

  1. Click the menu icon and choose Settings.
  2. Then find On startup section.
  3. Click Remove next to any suspicious startup page.

Reset MS Edge if the above steps did not work:

  1. Press on Ctrl + Shift + Esc to open Task Manager.
  2. Click on More details arrow at the bottom of the window.
  3. Select Details tab.
  4. Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.Reset MS Edge
Instructions for Chromium-based Edge

Delete extensions from MS Edge (Chromium):

  1. Open Edge and click select Settings > Extensions.
  2. Delete unwanted extensions by clicking Remove.Remove extensions from Chromium Edge

Clear cache and site data:

  1. Click on Menu and go to Settings.
  2. Select Privacy, search and services.
  3. Under Clear browsing data, pick Choose what to clear.
  4. Under Time range, pick All time.
  5. Select Clear now.Clear browser data from Chroum Edge

Reset Chromium-based MS Edge:

  1. Click on Menu and select Settings.
  2. On the left side, pick Reset settings.
  3. Select Restore settings to their default values.
  4. Confirm with Reset.
  5. This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.Reset Chromium Edge
Remove from Mozilla Firefox (FF)

You have to delete unverified entries from Mozilla Firefox and reset your browser.

Remove dangerous extensions:

  1. Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  2. Select Add-ons.
  3. In here, select the unwanted extension and click Remove.Remove extensions from Firefox

Reset the homepage:

  1. Click three horizontal lines at the top right corner to open the menu.
  2. Choose Settings.
  3. Under Home, set your preferred homepage and new tab settings.

Clear cookies and site data:

  1. Click Menu and pick Settings.
  2. Go to Privacy & Security section.
  3. Scroll down to locate Cookies and Site Data.
  4. Click on Clear Data...
  5. Select Cookies and Site Data and Temporary cached files and pages, then click Clear.Clear cookies and site data from Firefox

Reset Mozilla Firefox

If clearing the browser as explained above did not help, reset Mozilla Firefox:

  1. Open Mozilla Firefox browser and click the Menu.
  2. Go to Help and then choose Troubleshooting Information.Reset Firefox 1
  3. Under Give Firefox a tune up section, click on Refresh Firefox...
  4. Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.Reset Firefox 2
Reset Internet Explorer

Remove dangerous add-ons:

  1. Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
  2. Pick Manage Add-ons.
  3. You will see a Manage Add-ons window. Here, look for suspicious plugins. Click on these entries and select Disable.Remove add-ons from Internet Explorer

Change your homepage if it was altered:

  1. Open IE and click on the Gear icon.
  2. Select Internet Options.
  3. In the General tab, delete the Home page address and replace it by your preferred one (for example, Google.com).
  4. Click Apply and then select OK.Reset IE homepage

Delete temporary files:

  1. Press on the Gear icon and select Internet Options.
  2. Under Browsing history, click Delete...
  3. Select relevant fields and press Delete.Clear temporary files from Internet Explorer

Reset Internet Explorer:

  1. Click on Gear icon > Internet options and select Advanced tab.
  2. Select Reset.
  3. In the new window, check Delete personal settings and select Reset.Reset Internet Explorer

Access your website securely from any location

When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. The best solution for creating a tighter network could be a dedicated/fixed IP address.

If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for the server or network manager that needs to monitor connections and activities. VPN software providers like can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world.

Recover files after data-affecting malware attacks

While much of the data can be accidentally deleted due to various reasons, malware is one of the main culprits that can cause loss of pictures, documents, videos, and other important files.

More serious malware infections lead to significant data loss when your documents, system files, and images get encrypted. In particular, ransomware is is a type of malware that focuses on such functions, so your files become useless without an ability to access them.

Even though there is little to no possibility to recover after file-locking threats, some applications have features for data recovery in the system. In some cases, can also help to recover at least some portion of your data after data-locking virus infection or general cyber infection.

From our report of Sep 2018 · not reviewed since

Learn how to get rid of Windows Security has been Compromised message

As we have already mentioned, you should start Windows Security has been Compromised removal by downloading and installing a professional security tool.

Although, feel free to use any reliable antivirus of your choice.

However, you can also remove Windows Security has been Compromised manually. This method requires specific IT knowledge. Thus, experts recommend it only for advanced computer users. Check the guidelines presented at the end of this article.

Questions about Windows Security has been Compromised ads

What is Windows Security has been Compromised and why is it on my PC?

Windows Security has been Compromised is a program that was installed on the PC, most likely together with something else you downloaded. Free software sites and many installers add extra programs on setup pages with pre-ticked boxes, so the extra install looks like your choice even though nobody read the page.

Check the install date in Settings, Apps, Installed apps: the program you installed that day is the probable carrier. If you do not need Windows Security has been Compromised, uninstall it. If it belongs to your hardware or to a program you use, search its exact name and publisher first, because drivers and their tools can have unfamiliar names.

Windows Security has been Compromised will not uninstall. What can I do?

First restart the PC and try again, because the program may have been running and locked its own files. If the uninstaller is missing or fails, start Windows in Safe Mode, where most third-party programs do not start, and remove Windows Security has been Compromised from Installed apps there.

If it still refuses, delete its startup entry and its scheduled task, restart, and try once more. A program that actively prevents removal is behaving like malware, so finish with a Microsoft Defender offline scan. Avoid third-party uninstallers offered on search ads; several of them are unwanted programs themselves.

Can adware slow down my PC?

Yes. Adware runs in the background, loads ad scripts, opens extra tabs and contacts its servers, all of which use processor time, memory and bandwidth. Ad-heavy extensions also slow down every page, because they inspect and change it before you see it.

The effect is strongest on older PCs and when several adware programs arrived together. After removal, restart the PC and check Task Manager for anything still using a lot of resources that you do not recognise. Speed usually returns to normal once the ads stop.

Does adware steal passwords?

Ordinary adware is built to show ads, not to steal logins, and most of it never touches saved passwords. The line is blurry, though. Extensions that can read every page could capture what you type, and adware ads sometimes lead to phishing pages that ask for passwords directly.

If you entered credentials on a page reached through an ad, change that password from a clean device and turn on two-step verification. Otherwise, removing adware extension and clearing cookies is usually enough.

I clicked on one of the ads. Am I infected?

Probably not. Clicking an ad usually only opens a page, and a page cannot install programs on an up-to-date Windows PC without your help.

You are at risk only if you then downloaded and ran a file, allowed notifications, entered card or login details, or called a phone number shown on the page. Delete any download and run a full and offline scan.

Change passwords you typed, from a clean device. Call your bank if you gave card details. If you called a number or allowed remote access, see the next question.

An ad showed a phone number and I called it. What now?

The number belongs to scammers, not to Microsoft or an antivirus company. If you only talked, hang up and do not call back. If you let them connect to the PC, disconnect it from the internet, uninstall the remote access program they used, such as AnyDesk, TeamViewer, ScreenConnect or UltraViewer, and run a full and offline scan.

If you paid or gave bank details, call your bank at once on the number printed on your card. Change any passwords you typed while they were connected, and report the call.

Why didn't my antivirus catch Windows Security has been Compromised?

Many security products do not block adware or notification sites by default, because users often agreed to them, even through a misleading prompt. Notification spam installs nothing at all, so there is no file to detect.

In Windows 11 you can make Microsoft Defender block potentially unwanted apps: open Windows Security > App & browser control > Reputation-based protection settings and turn on Potentially unwanted app blocking. If notifications caused the pop-ups, no scanner will report them; the fix is in the browser's site settings.

Do I need to reset my browser after removing Windows Security has been Compromised?

A reset is a good last step, because it undoes settings that the program changed. A reset restores the home page, new tab page and default search engine, and turns off extensions.

It does not delete your bookmarks or saved passwords in the main browsers. Add back only the extensions you trust, one at a time.

Will Fortect remove Windows Security has been Compromised?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Windows Security has been Compromised, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

  1. TechTarget: Pop-up (read October 7, 2026)
  2. Wikipedia: Technical Support Scam (read October 7, 2026)
  3. Google Chrome Help: Use notifications to get alerts (no longer online) (read October 7, 2026)
  4. FTC: How to recognize, remove and avoid malware (read October 7, 2026)
  5. Microsoft Learn: Microsoft Defender Offline (read October 7, 2026)

More removal guides

Remove Immediate Action Required

Immediate Action Required is a fake notification that might pop-up out of nowhere and prompt users to download useless bogus software Immediate Action Required is a scam that users mightAdwareMedium riskUgnius Kiguolis ·

Remove ReceiverHelper Mac virus

ReceiverHelper virus is a high threat to your personal safety and Mac security ReceiverHelper is a harmful application targeting Mac devices, classified under the Adload malware family. It is notoriousAdwareMedium riskJake Doevan ·

Remove Casalemedia

Casalemedia is a legal advertising service but is sometimes abused by crooks to gain personal income Casalemedia is a legitimate advertising service that provides assistance in monetizing on online contentAdwareMedium riskJake Doevan ·

Remove D1ue3yi0hkdsdl.cloudfront.net ads

D1ue3yi0hkdsdl.cloudfront.net ads is the content related to scam campaigns and fake errors or warnings D1ue3yi0hkdsdl.cloudfront.net is the program that causes notifications and advertisements that may appear unexpectedly, preventing you fromAdwareMedium riskJulie Splinters ·

Questions and experiences: Windows Security has been Compromised ads

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year