SteadyScope Questions and fixes, explained calmly

Pop-ups, warnings and unexpected calls

Six questions about messages that arrive uninvited, on screen or by telephone. Answers reviewed 8 October 2026.

The short version

A web page has no way of examining your computer, so any page that describes a fault on your machine is describing an invention. Genuine system and security messages appear in the operating system's own interface, never ask you to telephone a call centre, and never charge for a repair over the phone. Closing the tab is almost always the entire fix.

A page says my device has a problem. Is that true?

Short answer: no. Pages of that kind are advertising, and they are written to look like something the operating system produced.

Why the page cannot know

Web pages run in a deliberately restricted environment. A page can see roughly what kind of browser you are using and what language your device is set to, because that information is sent so pages can be displayed correctly. It cannot read your files, list your installed programs, or examine anything about the health of the machine. A page that reports a specific number of problems found, or names your operating system in alarming terms, is working from the handful of general details every page receives, and filling in the rest.

The visual design is the whole trick. The page borrows the colours, icons and layout of a familiar system window and places it inside an ordinary browser tab. Once you notice that the window has no real title bar of its own and that everything sits inside the browser's own frame, the illusion is hard to see again.

What to try first, at no cost

  • Close the tab. Do not use any button inside the page, including one marked as a close or cancel control.
  • If the tab reopens the same page, close the whole browser window and reopen it without restoring tabs.
  • Check whether the page was reached through an advertisement on another site, and avoid that route in future.
  • Review your browser's notification permissions, since these pages often ask for them.

When to ask for official help

No help is usually needed for the page itself. If the same page keeps appearing without any action from you, see the question about notifications below. Pages of this kind can be reported to Scamwatch, and the Australian Cyber Security Centre publishes plain-language guidance on recognising this pattern.

Where a paid product may or may not help

Nothing on your machine needs to be bought because of a page like this, and buying something in direct response to one is the outcome the page was built to produce. A security product with a web-filtering component may block some of these addresses, but the behaviour that protects you is recognising the pattern.

The warning fills the screen and will not close

Short answer: the page has asked the browser to go full screen and may be blocking the ordinary close control. The keyboard and the task manager both still work.

Likely causes

Two browser features are being used together. Full-screen mode hides the browser's own frame, which removes the visual clues that would give the page away. A dialog loop repeatedly opens a message box so that dismissing one immediately produces another. Neither feature has control over your computer; both are confined to the browser.

What to try first, at no cost

  1. Press the escape key to leave full-screen mode and bring back the browser frame.
  2. If a message box keeps returning, look for a tick box offering to prevent the page creating further dialogs, and use it.
  3. If that fails, close the browser from the task manager on Windows, or force it to quit on macOS.
  4. Reopen the browser and decline any offer to restore the previous session, which would reload the same page.
  5. Clear the browser's cached data for that site if it keeps returning.

When to ask for official help

If the display remains locked after the browser is closed and the machine restarted, the problem is no longer a web page and a repairer should look at it.

Where a paid product may or may not help

A security product does not close browser windows for you. This is a browser problem with a browser solution, and the steps above cost nothing.

Someone rang claiming to be from a technology company

Short answer: large technology and telecommunications companies do not telephone individuals to report a fault on their computer. There is no mechanism by which they would know.

How the call is structured

The caller establishes authority by naming a company you recognise, then creates a shared task — "let us look at it together" — and asks you to open a part of the operating system that shows ordinary system messages. Every computer has entries there that look alarming to someone unfamiliar with them, and the caller uses those entries as proof. The request that follows is either to install remote access software or to pay for a repair. Some calls arrive after a pop-up has supplied the number; others arrive cold.

What to watch out for

  • Any caller who asks you to install software so they can see your screen.
  • A request to stay on the line while you log in to internet banking for a refund.
  • Payment requested by gift card, voucher, bank transfer or cryptocurrency.
  • Pressure to remain on the call and not to consult anyone else.
  • A number that appears to be local. Displayed numbers can be set to almost anything.

What to try first, at no cost

Hang up. There is no obligation to be polite to an unsolicited caller, and ending the call is the complete response. If you want to verify whether a company genuinely tried to contact you, find its number yourself from your bill or its official site and ring back, using a different telephone if one is available.

When to ask for official help

Report the call to Scamwatch, which tracks these campaigns in Australia. If money was paid, contact your bank at once; some transfers can be stopped if reported quickly.

Where a paid product may or may not help

No software prevents a telephone call. If the caller persuaded you to install something, a security product is useful in finding and removing it — see the next question — but prevention here is entirely a matter of recognising the pattern.

I let a caller connect to my computer. What now?

Short answer: disconnect the machine from the internet, then work through accounts and software in that order. This is recoverable, and panic is not required.

What the access allowed

Remote access software shows the caller your screen and lets them use your mouse and keyboard. Anything visible to you while connected was visible to them, including any account you signed in to during the call. They may have installed additional software, changed settings, or copied files. They may equally have done very little beyond putting on a performance. Assume the former and act accordingly.

What to try first, at no cost

  1. Disconnect from Wi-Fi or unplug the network cable, which ends any live session immediately.
  2. From a different device you trust, change the passwords on your email and banking accounts, and sign out all other sessions.
  3. Telephone your bank on the number printed on your card, particularly if banking was opened during the call.
  4. Uninstall any remote access program that was added, noting its name first.
  5. Run a full scan with the protection in your operating system, then review the installed programs list by install date.

When to ask for official help

Report the incident through ReportCyber at cyber.gov.au and to Scamwatch. If you are not confident the machine is clean afterwards, a reputable local repairer rebuilding the operating system is the thorough option, and is often cheaper than it sounds.

Where a paid product may or may not help

A second scanning engine with vendor support attached is a defensible purchase after an incident of this kind, particularly if you would rather have someone to telephone while you work through it. Norton AntiVirus Plus is one such paid subscription; what it includes and what it costs are matters for the vendor's own pages rather than this one. Visit the Norton AntiVirus Plus websitePaid affiliate link. If you subscribe after following it, the affiliate network that operates the link pays SteadyScope a commission; what you pay is unaffected.

Why does a website keep sending me notifications?

Short answer: because at some point a permission prompt was accepted, probably without being read, and the site is now allowed to push messages to your desktop.

Likely causes

Browser notifications were designed for messaging and calendar services. They are also used to deliver advertising that appears outside the browser, where it looks far more like a system message than it would on a page. The prompt asking for permission is small, appears at the moment you are trying to read something, and is easy to accept by reflex. Some sites make accepting it a condition of continuing, which is itself a reason to leave.

What to try first, at no cost

Every browser keeps a list of sites allowed to send notifications, in its settings under site permissions or notifications. Open that list, remove everything you do not actively want, and set the default to ask rather than allow. On Windows and macOS there is a second list at the operating system level controlling which applications may display notifications at all, which is a useful backstop.

Telling the two apart

A browser notification always identifies the browser somewhere in the notification itself, usually in small text naming the site and the browser. A message from the operating system does not reference a website. If a notification about your computer's health names a site, it came from that site.

When to ask for official help

No external help is needed for notification permissions. If notifications are being used to deliver content that is seriously harmful rather than merely unwanted, the eSafety Commissioner is the Australian body that handles complaints about illegal and restricted online content.

Where a paid product may or may not help

Some security suites offer to tidy browser permissions. The browser's own settings do the same thing in under a minute, and knowing where that list lives is worth more than a subscription.

How do I tell a real system message from an imitation?

Short answer: by where it appears and what it asks for. Real messages live in the operating system's interface and never ask for a telephone call or a payment.

Characteristics that separate genuine messages from imitations
CharacteristicGenuine system or security messageImitation in a browser
Where it appearsIn the notification area or the security application itselfInside a browser tab or window
What it asksTo scan, quarantine, update or restartTo telephone a number, pay, or download something
ToneFactual and specificUrgent, counting down, or alarming
BrandingMatches the software you installedBorrows a well-known name loosely
Behaviour when ignoredStays until dealt with, quietlyReappears, blocks the page, or plays sound
Survives closing the browserYes, it is not part of the browserNo

What to try first, at no cost

Close the browser entirely. If the message is still there afterwards, it came from your computer and is worth reading properly. If it disappeared with the browser, it was a page. This single test resolves most cases without any technical knowledge at all.

When to ask for official help

If a genuine security application reports something and you are unsure what it means, open the application directly from the start menu or applications folder and read the report there, rather than acting on the notification. Vendor support, where you have it, is the right place for product-specific questions.

Where a paid product may or may not help

Having one named security product that you recognise does make this easier, because an unfamiliar brand appearing in a message is then an obvious signal. That applies equally to the protection included with your operating system, which is free and which you can learn to recognise just as well.