Blog · September 13, 2026

How to Spot a Tech Support Scam: Fake Microsoft Calls and Pop-Ups Explained

These scams are convincing, they target everyone, and we see the aftermath of them regularly. Here is exactly what to watch for and what to do.

← Back to Blog

It usually starts with a pop-up. A loud alarm sound. Text filling the screen saying your computer has been infected, your files are at risk, and you must call a number immediately. Or it starts with a phone call from someone claiming to be from Microsoft, saying that their servers have detected errors coming from your computer.

Both are scams, and both are designed to look and sound completely legitimate.

We see the aftermath of these scams regularly here in Rhode Island, particularly among seniors and people who are not used to questioning a call that seems official. This guide explains exactly how these scams work, the warning signs to look for, and what to do if you or someone you know has fallen for one.

The single most important thing to know: Technology companies like Microsoft or Apple do not call you unprompted. Your internet provider will not call you to tell you your computer has a virus. If you receive a call or pop-up like this, it is a scam every single time.

How the pop-up scam works

While browsing the internet a pop-up box suddenly fills your screen with an alarming message. It may say "Windows Defender Alert," "Your computer has been blocked," or "Critical virus detected." There is often a loud alarm sound or a robotic voice reading the warning out loud. The message tells you to call a toll-free number right away.

This is not a real warning from Windows. It is a webpage designed to look like one. The alarming language is meant to create panic so you pick up the phone without stopping to think.

When you call the number, a person answers and claims to be from Microsoft, Windows, or a company hired by Microsoft. They may ask you to download a program so they can "fix" your computer remotely. Common tools they request include TeamViewer, AnyDesk, UltraViewer, or other similar software. Once you install it, they have full control of your computer, which could include access to your passwords.

At this point, they will pretend to run scans, show you alarming but fake results, and tell you the repairs will cost several hundred dollars. Payment is almost always requested by gift card, wire transfer, or sometimes cryptocurrency, because those methods are very difficult to reverse.

How the phone call scam works

In this version, you receive an unsolicited call. The caller says they are from Microsoft, Windows Technical Support, or sometimes your internet provider. They say their systems have detected that your computer is infected, sending out errors, or about to be shut down for your protection.

The caller may know your name, your general location, or even the name of your internet provider, which makes them seem more credible. This information is often obtained from data brokers or previous data breaches and costs almost nothing to buy in bulk.

They follow the same script as the pop-up version: ask you to get on your computer, walk you through installing remote access software, then show you "evidence" of the infection and demand payment to fix it.

What to do when it happens

If you get the pop-up

Do not call the number. The pop-up is just a webpage. Close the browser tab. If the pop-up fills the screen and will not let you close it, press Ctrl + Shift + Esc to open Task Manager, find your browser in the list, click it, and select End Task. Then restart your browser without restoring your previous tabs.

Your computer is almost certainly fine. The pop-up did not infect anything; it was just a scare tactic. If you are not sure, a quick scan with your antivirus software will confirm there are no viruses. If you do not know how to do this or are unsure whether you have antivirus software, give us a call.

If you get the phone call

Hang up. You do not owe them a polite explanation. If they call back, do not answer or hang up again and block the number. Real companies do not call you unsolicited about your computer.

If you already gave them access

This is where it gets more serious, but it is recoverable. Here is what to do:

  1. Disconnect from the internet right now. Unplug the network cable or turn off Wi-Fi. This cuts off any active remote connection immediately.
  2. Contact your bank if you paid anything or shared any account information. Call the number on the back of your card and explain what happened. They can often reverse recent gift card or wire transactions if you act quickly.
  3. Change your passwords from a different device (your phone or a different computer) for your email, banking, and any other accounts you use on that computer. If you use the same password for multiple accounts, read our article on why every password should be unique, or call us and we can help.
  4. Do not use that computer for anything until a technician has checked it. The scammers may have installed remote access tools designed to run quietly in the background so they can get back in later.
  5. Have the computer checked and cleaned by someone you trust. We do this regularly at Comp-u-Doc and can come to your home anywhere in Rhode Island.

Why are seniors targeted more often?

Scammers target seniors because they are more likely to be home during the day, are more likely to trust an authoritative voice on the phone, and are less likely to have encountered these specific scam formats before.

The best protection is awareness. If you or someone you know is less familiar with computers, share this article or pass along this simple rule: technology companies never call you unless you called them first.

What Comp-u-Doc can do if it already happened

We check for remote access software and malware, remove anything that should not be there, and assist you in changing passwords and securing your accounts.

We serve all of Rhode Island, including Warwick, Cranston, East Greenwich, West Warwick, Coventry, North Kingstown, and the surrounding area. If you or someone you know thinks they may have been scammed, text or call us at (401) 884-4432 and we will walk you through what to do.

You can also learn more about our virus removal service or our senior tech help.

Red flags to watch for

  • A pop-up or website plays an alarm sound and urges you to call a phone number
  • Someone calls you claiming to be from Microsoft, Apple, or Windows support
  • The caller says your computer has been sending errors or has been infected
  • You are asked to download software like TeamViewer, AnyDesk, or AnySupport
  • The caller asks you to open Event Viewer or Command Prompt to "prove" you have errors (these tools always show some warnings on any computer)
  • Payment is requested by gift card, wire transfer, Zelle, or cryptocurrency
  • The caller creates urgency, saying you must act now or your computer will be locked or your bank account drained
  • The person becomes aggressive or threatening when you question them or try to hang up

Think a scammer got into your computer?

We come to your home anywhere in Rhode Island. We’ll check it, clean it, and help you secure your accounts.

Text or Call (401) 884-4432

More from the blog:

Think Before You Click: Be a Human Firewall →

Disclaimer: The information on this blog is provided for general educational purposes and reflects the opinions and experience of Comp-u-Doc, Inc. It is not a substitute for professional diagnosis or service. If you believe you have been the victim of fraud, contact your bank and local law enforcement in addition to having your computer checked. Comp-u-Doc, Inc. is not responsible for actions taken based on this content.