A frightening message does not always mean your computer has a virus. A web page can imitate a security alert, a desktop notification can come from a website, and a genuine protection tool can report a detected file. Slowness can also have many causes. Start by recording what you actually observed rather than naming the problem too soon. This guide is for one working personal Windows or Mac computer. It is not a ransomware recovery plan, a failed-drive procedure or a substitute for urgent help.
Start here
Start with the kind of problem you saw
Use the closest description below, then move to the matching next step.
Check where the warning appearedUse the browser or desktop context to distinguish a web-page message from a notification or an installed protection alert.Read this part
Inspect only with a trusted sourceIf the computer is still working, open the protection already installed on it independently rather than following a warning's link, phone number or download prompt.Read this part
Record the next safe stepWrite down what changed, when it happened and what protection reported. Keep the note private and use it when deciding whether to seek help.Read this part
Identify the observation
First ask where the message appeared. A page inside a browser that demands a phone call, payment or an urgent download is a browser warning, not proof that the computer was scanned. A notification from a website may appear on the desktop even after the browser is closed. A real installed protection alert normally appears within the protection application or the operating system's security area.
General slowness is different again. It may be worth investigating, but it does not identify malware by itself. Note the exact wording if safe, which application was open, whether the message returned after closing the browser, and whether you saw a named detection in protection software. Do not click a phone number, pay, install a tool or hand over remote access from the warning.
Choose a bounded check
If the computer is working normally enough to use, keep the next check platform-specific. On Windows, independently open Windows Security from the Start menu and review its current report. On a Mac, install current macOS updates, review Applications and Safari extensions using Apple’s guidance, or independently open only a known third-party security product already installed. Do not use a link supplied by the warning.
For a Windows computer, the next guide explains what a Windows Security scan result means: understand Windows Security scan results. For a fake browser warning, use fake virus pop-ups. Keep the check limited to understanding the trusted source's current report. Do not casually delete files, reinstall the system or change security settings because of an alarming message.
For Apple’s official adware guidance, see Apple Support’s guidance on deceptive software and pop-ups.
Review Mac software and extensions without guessing
On a Mac that is still working, review the Applications folder and Safari extensions as separate observations. Note the name of software or an extension you do not recognise, when you first noticed it and whether the problem returns after the browser is closed. Do not delete an application, extension or system item simply because its name is unfamiliar.
Use Apple’s current guidance for deceptive software and pop-ups, keep macOS and trusted applications updated, and seek help if the software cannot be removed safely or the Mac appears managed by someone else. A list of an unfamiliar item is not a diagnosis, and removing one extension does not prove that the computer is clean.
This is a bounded observation for one working personal Mac. It does not cover forensic investigation, malware-remediation guarantees or recovery of inaccessible files.
Record and escalate safely
Write down the time, visible message, application or website involved, and whether the computer remains usable. A short private note can help a specialist distinguish an observation from a conclusion. Do not include passwords, full payment details or unnecessary personal information.
If files are being encrypted or a ransom note is visible, stop routine checks. Stop using the device and disconnect it from the network as an immediate step, but do not treat that alone as complete containment. From another trusted device, use official Australian Cyber Security Centre guidance or contact a suitable specialist. Do not pay a ransom or plug a backup into the affected device.
If files merely fail to open, that may indicate storage or file-system trouble rather than ransomware. Stop unnecessary writes, avoid deletion or reinstallation, and seek a suitable storage or data-recovery assessment without diagnosing ransomware. If money may be exposed, contact your bank immediately using official details and read suspected scam: first steps. For other persistent or unclear problems, seek an assessment rather than guessing at a fix.
Source: Australian Cyber Security Centre ransomware guidance.
If a warning is on a Mac, see Apple’s guidance on deceptive software and pop-ups. If files appear locked or ransomware is suspected, follow Australian Cyber Security Centre ransomware guidance rather than experimenting with the affected files.
What to read next
If you’d rather have local help, see our virus and malware diagnosis help.