PanicStation.org
us Technology & digital loss

What to do if…
your antivirus or security app is suddenly disabled and you did not change it

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Treat the device as possibly unsafe for now. Disconnect it from the internet and use a different trusted device to protect your most important accounts.

Do not do these things

  • Don’t use the affected device for email, banking, shopping, password managers, tax accounts, or work logins.
  • Don’t click pop-ups that say your security is disabled or that you must install a fix.
  • Don’t download random cleanup tools, antivirus tools, or remote-support apps from search results.
  • Don’t reconnect the device just to see what happens if the security app keeps turning itself off.
  • Don’t factory-reset a work, school, healthcare, or managed device unless your IT or security contact tells you to.
  • Don’t spend time investigating every setting. If you need a record, take a photo of what is already visible.

What to do now

  1. Disconnect the affected device.
    Turn off Wi-Fi, Bluetooth, mobile data, and hotspot sharing. Unplug ethernet if it is connected. If this is a personal device and you see ransomware, extortion messages, or files being rapidly changed, power it down after disconnecting if you can.

  2. Make a minimal record.
    Write down the time, the device name, the security app name, what message you saw, and what changed. Take a photo of visible warnings with another device. Do not click deeper just to gather more details.

  3. Use a different trusted device for accounts.
    On a phone or computer you trust, start with your main email account, then your Apple, Google, or Microsoft account, then banking, credit cards, and work accounts. Change passwords that may have been used on the affected device, turn on multi-factor authentication where available, review recovery email and phone details, and sign out of other sessions if the account offers that option.

  4. Check for obvious non-malicious causes without deep troubleshooting.
    Look only for simple explanations: a new security product you installed, a work or school management profile, a family safety tool, or an administrator account you recognize. If you see an unknown administrator, unknown management profile, or unknown security app, stop and document it rather than removing things at random.

  5. For a personal Windows device, consider Microsoft Defender Offline scan.
    If you can safely use the device and Microsoft Defender is available, run Microsoft Defender Offline scan from Windows Security. It restarts the device and scans outside the normal Windows environment. If BitLocker is enabled and you do not have the recovery key, pause and get help first.

  6. For a phone or tablet, check profiles and security apps carefully.
    Look for unknown device management profiles, unknown VPN apps, unknown accessibility permissions, and unknown security or cleaner apps. Do not remove a work or school management profile unless the organisation tells you to.

  7. If protection will not stay on, stop using the device.
    Keep it offline. For a personal device, plan for help from the device maker, your security software provider, a reputable repair service, or a clean reinstall after your accounts are protected. For a work or school device, contact IT or security and do not try to fix it yourself unless they instruct you.

  8. Report crime, fraud, or extortion from a trusted device.
    If there is ransomware, extortion, account takeover, identity theft, or financial loss, report through the FBI Internet Crime Complaint Center. If identity theft may be involved, use IdentityTheft.gov. If a bank or card may be exposed, contact the bank or card issuer using the number on the card or in the official app.

What can wait

  • You do not have to decide right now whether to wipe or replace the device.
  • You do not have to identify the exact malware today.
  • You do not have to answer threats or pay anyone now.
  • You do not have to fix every account at once; start with the email account that controls password resets, then financial and work accounts.

Important reassurance

A disabled security app does not always mean malware. Updates, expired subscriptions, conflicting security tools, and device management settings can also cause this. Disconnecting first is still a sensible way to stop the situation getting worse while you check from a safer device.

Scope note

These are first steps only. Later decisions, such as reinstalling the operating system, restoring backups, investigating data exposure, or reporting a workplace incident, may need specialist technical, legal, or organisational help.

Important note

This is general information, not professional cybersecurity, legal, financial, law-enforcement, or technical support advice. If the device belongs to work, school, healthcare, government, or another organisation, follow that organisation’s incident process.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us