Skip to main content
FixMyTech

The Fake Virus Warning Scam, Explained

By

Published

8 min read

Share

Short answer

No operating system reports an infection through a web page, a browser pop-up or a countdown timer. The warning is an advert designed to make you ring a number. Close the tab — force-quit the browser if it will not close — and never call the number. The call is where the actual loss happens, not the page.

On this page

A page appears claiming your computer is infected. It may name your operating system correctly, show a countdown, play an alarm, or refuse to close. There is a telephone number for “Microsoft Support” or “Apple Support”, and an instruction not to restart the machine.

Everything on that page is an advertisement. The page cannot see inside your computer, no infection has been detected, and no operating system has ever reported malware through a web browser. The entire purpose is to get you to ring the number, because the page itself cannot take anything from you.

Why it sounds like it knows you

The page names your operating system and browser because every website receives that information as a matter of routine — it is how sites decide whether to send you the Windows or Mac download. Your approximate location comes from your IP address, which is equally standard.

A page that says “Windows 11 detected” has performed no detection at all. It read a line of text your browser sends to every site you visit, and presented it back as a diagnosis. The same template, served to a Mac, says macOS.

The audio alarm, the countdown timer and the flashing red are theatre, and effective theatre, because fear degrades exactly the judgement you need.

What a real warning looks like

Worth knowing the genuine article, because the contrast is total.

Real security warning Fake warning
Appears in Windows Security or System Settings Appears in a browser tab
No telephone number Prominent telephone number
No countdown Countdown or alarm
Quiet notification Audio, flashing, full screen
Does not ask you to install anything Download or call to proceed

Microsoft Defender reports through Windows Security and a system notification. macOS does not notify about infections at all. Neither company puts a support number in a security alert, and neither asks you to act within five minutes.

Closing it

The page may block the close button with a dialog that reappears, or enter full-screen so the browser controls are hidden. The browser is not broken and the machine is not locked. The page is simply reopening a dialog in a loop.

Press Esc first, which exits full-screen.

Then force-quit the browser:

  • Windows: Ctrl+Shift+Esc for Task Manager, select the browser, End task
  • macOS: Cmd+Option+Esc, select the browser, Force Quit
  • iPhone and Android: close the browser from the app switcher

When you reopen, decline to restore the previous session. Chrome offers to reopen your tabs after an unexpected close, which brings the page straight back. If it reopens anyway, clear the browsing history for the last hour.

While you are there: check whether the site was allowed to send notifications, because some of these persist that way and then appear as alerts outside the browser. Stopping websites sending notifications in Chrome covers the cleanup.

What happens if you call

The page is bait. The call is the operation, and it follows a consistent script.

They ask for remote access. Through legitimate remote support software, which is downloadable by anyone and is not itself malicious. You install it, and they are now on your computer with your permission.

They show you something alarming. The Windows Event Viewer is the favourite, because a normal, healthy Windows machine logs hundreds of warnings and errors that mean nothing. Scrolled past quickly by someone describing them as infections, it is persuasive. Other variants use a command prompt filled with output, or a directory of temporary files.

They diagnose and quote. A sum for cleaning, a support plan, sometimes a multi-year contract.

They take payment, and they prefer methods that cannot be reversed — bank transfer, gift cards, cryptocurrency.

They may do real damage on the way out. Setting a password you do not know, installing something persistent, or leaving the remote access software behind so they can return. A variant inverts the whole thing: a “refund” is offered, a fake bank page shows you have been overpaid, and you are talked into transferring the difference back.

The sum involved is often modest enough to feel survivable. The remote access and the card details are the larger loss, and the number is resold to other operations, which is why one call tends to produce many more.

If you already called

Order matters, and the first step is not scanning.

1. Disconnect from the internet. Unplug the ethernet cable or turn off Wi-Fi. This ends the session immediately if they are still connected.

2. Uninstall the remote access software. Settings → Apps → Installed apps on Windows, or drag it to the Bin on macOS, and check login items afterwards.

3. Change your passwords from a different device. Email first, then banking, then anything else you signed into on that machine. Not from the affected computer.

4. Ring your bank if you paid by card or transfer, on the number printed on your card. Card payments can sometimes be reversed. Bank transfers and gift cards usually cannot, which is precisely why they were requested.

5. Scan the machine properly. Use the Defender offline scan, which reboots and scans before Windows loads: scanning for and removing malware on Windows has the full procedure.

6. Expect follow-up calls. Often from someone offering to recover your money for a fee, which is the same operation returning. Nobody legitimate offers this unprompted.

The complete ordered checklist for the aftermath is in what to do after clicking a suspicious link.

The rules that end this permanently

  • No technology company puts a phone number in an error message. None. This single rule defeats the entire category.
  • Nobody legitimate calls you about a virus on your computer. Your internet provider cannot see that, and Microsoft does not telephone individuals.
  • Never allow remote access to someone who contacted you first. Fine when you rang a company you chose. Never when they reached you.
  • Gift cards are not a payment method for support. Any request for them ends the conversation.
  • Never search for a support number and ring the first result. Paid adverts for fake support numbers appear regularly in search results. Use the number on your card, your receipt, or the company’s own site reached by typing the address.

Realistic expectations

If you closed the tab, nothing happened. The page took nothing, left nothing and cannot do anything. That is the overwhelmingly common ending.

If you rang but installed nothing and paid nothing, you are in reasonable shape, and the main consequence is more calls. Where it becomes serious is remote access and payment, and both of those need the ordered response above rather than a scan.

This scam has worked for well over a decade and shows no sign of stopping, because it needs no technical skill and the targeting is indiscriminate. It is worth explaining the “no phone numbers in error messages” rule to anyone in your household who might be on the receiving end of it, because the one-line version is all the defence most people need.

Frequently asked questions

How do I close a pop-up that will not let me close the tab?
Force-quit the browser instead of fighting the dialog. Ctrl+Shift+Esc on Windows to open Task Manager and End task on the browser, or Cmd+Option+Esc on a Mac and Force Quit. Then reopen and decline any offer to restore the previous tabs.
I called the number but hung up before anything happened. Am I at risk?
If you installed nothing and gave no card details, you are almost certainly fine. Expect further calls, because numbers that call in are marked as responsive and resold. Treat any call claiming to follow up as the same scam continuing.
Does the warning mean my computer is actually infected?
No. The page cannot see your computer. It reads your browser and operating system from ordinary information every site receives, which is why it names your system correctly and sounds convincing.
What if I already gave them remote access?
Disconnect from the internet, uninstall the remote access software, and change your passwords from a different device starting with email and banking. Assume anything visible or typed during the session is known to them.
Why does my phone show these warnings too?
Same mechanism. A web page or an aggressive advert on a mobile browser, sometimes delivered through a notification you allowed earlier. Neither iOS nor Android reports infection through a browser.

All Security guides