PanicStation.org
uk Technology & digital loss

What to do if…
your antivirus or security app is suddenly disabled and you did not change it

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Treat the device as possibly compromised for now: disconnect it from the internet and stop using it for banking, email, password managers, work logins, or account recovery until you have checked from a different trusted device.

Do not do these things

  • Don’t keep using the device for banking, email, password managers, work systems, or identity checks.
  • Don’t download “fix tools” from pop-ups, adverts, messages, or random search results.
  • Don’t keep turning the antivirus back on while the device is still online if it immediately switches off again.
  • Don’t plug in external drives, backup disks, or USB sticks to “scan them” while the device may be infected.
  • Don’t wipe or factory-reset a work, school, or managed device unless the IT or security team tells you to.
  • Don’t click around to investigate. If you need a record, take a photo of what is already visible with another device.

What to do now

  1. Disconnect the device from networks.
    Turn off Wi-Fi and Bluetooth, unplug ethernet, and on a phone or tablet turn on airplane mode and check Wi-Fi and Bluetooth are also off. If you cannot reliably disconnect it, or you see ransomware, extortion, files being renamed, or files becoming unreadable, power the device down.

  2. Make a short record without digging further.
    Write down the date and time, the security product name, the exact message shown, and what changed, such as “real-time protection off”, “tamper protection off”, “security app missing”, or “unknown profile installed”. Photograph the screen if the message is already visible.

  3. Use a different trusted device to secure key accounts.
    Start with your email account, Apple, Google or Microsoft account, banking, password manager, and work accounts. Change passwords from the trusted device, especially any reused passwords, and turn on 2-step verification where available. Secure the email account used for password resets before less important accounts.

  4. Check for simple explanations only if you can do it safely offline.
    Look for a newly installed antivirus or security suite you did not choose, an expired subscription message, a recent operating-system update, or an unfamiliar work, school, mobile-device-management, or configuration profile. If something is unfamiliar, note it rather than removing it blindly.

  5. Run an offline or boot-time scan before normal use if available.
    On Windows, Microsoft Defender Offline scan can restart the device and scan without loading Windows in the usual way; follow the prompts in Windows Security. If you use another security product, use only that provider’s official offline, rescue, or boot scan option if it offers one.

  6. Reconnect only for a limited update-and-scan step.
    If you need internet access to update the operating system or security tool, reconnect only on a known network, update the operating system and security definitions, run a full scan, then disconnect again if protection switches off or warnings return.

  7. Escalate if protection will not stay enabled.
    For a personal device, keep it isolated and consider help from the device maker, the security software provider, or a reputable repair professional. For a work, school, healthcare, finance, or managed device, stop and contact the IT, helpdesk, or security team before trying a reinstall or reset.

  8. Report fraud, cyber crime, or exposed financial details where relevant.
    If you are in England, Wales, or Northern Ireland and you think this involved fraud, cyber crime, stolen money, or stolen account access, report it through Report Fraud using a different device. If you are in Scotland, report cyber crime to Police Scotland using 101 for non-emergencies or 999 for emergencies. If bank details may be exposed, contact your bank using the number in your banking app or on your card, not a number from an email or text.

What can wait

  • You do not need to decide now whether to reinstall or replace the device.
  • You do not need to identify the exact malware name before isolating the device and securing accounts.
  • You do not need to respond to threatening messages or decide about payment now; keep the device offline and use official reporting or support routes.
  • You do not need to connect backups or external drives today unless a trusted IT or security professional tells you it is safe.

Important reassurance

A security app switching off can sometimes be caused by updates, expired licences, settings changes, or conflicts between security products. Starting with isolation and account protection is still sensible because it prevents the most serious harm while you work out what happened.

Scope note

These are first steps to stabilise the situation and reduce harm. Later decisions, such as reinstalling the device, restoring backups, investigating logs, or handling a work incident, may need specialist IT or cyber-security help.

Important note

This is general information, not professional cyber-security, legal, financial, or technical advice. If the device is used for work, healthcare, finances, or sensitive personal data, involve the relevant IT or security support early and avoid changes that could remove useful records of what happened.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us