The Fake Virus Warning Scam, Explained
Short answer
No operating system reports an infection through a web page, a browser pop-up or a countdown timer. The warning is an advert designed to make you ring a number. Close the tab — force-quit the browser if it will not close — and never call the number. The call is where the actual loss happens, not the page.
On this page
A page appears claiming your computer is infected. It may name your operating system correctly, show a countdown, play an alarm, or refuse to close. There is a telephone number for “Microsoft Support” or “Apple Support”, and an instruction not to restart the machine.
Everything on that page is an advertisement. The page cannot see inside your computer, no infection has been detected, and no operating system has ever reported malware through a web browser. The entire purpose is to get you to ring the number, because the page itself cannot take anything from you.
Why it sounds like it knows you
The page names your operating system and browser because every website receives that information as a matter of routine — it is how sites decide whether to send you the Windows or Mac download. Your approximate location comes from your IP address, which is equally standard.
A page that says “Windows 11 detected” has performed no detection at all. It read a line of text your browser sends to every site you visit, and presented it back as a diagnosis. The same template, served to a Mac, says macOS.
The audio alarm, the countdown timer and the flashing red are theatre, and effective theatre, because fear degrades exactly the judgement you need.
What a real warning looks like
Worth knowing the genuine article, because the contrast is total.
| Real security warning | Fake warning |
|---|---|
| Appears in Windows Security or System Settings | Appears in a browser tab |
| No telephone number | Prominent telephone number |
| No countdown | Countdown or alarm |
| Quiet notification | Audio, flashing, full screen |
| Does not ask you to install anything | Download or call to proceed |
Microsoft Defender reports through Windows Security and a system notification. macOS does not notify about infections at all. Neither company puts a support number in a security alert, and neither asks you to act within five minutes.
Closing it
The page may block the close button with a dialog that reappears, or enter full-screen so the browser controls are hidden. The browser is not broken and the machine is not locked. The page is simply reopening a dialog in a loop.
Press Esc first, which exits full-screen.
Then force-quit the browser:
- Windows: Ctrl+Shift+Esc for Task Manager, select the browser, End task
- macOS: Cmd+Option+Esc, select the browser, Force Quit
- iPhone and Android: close the browser from the app switcher
When you reopen, decline to restore the previous session. Chrome offers to reopen your tabs after an unexpected close, which brings the page straight back. If it reopens anyway, clear the browsing history for the last hour.
While you are there: check whether the site was allowed to send notifications, because some of these persist that way and then appear as alerts outside the browser. Stopping websites sending notifications in Chrome covers the cleanup.
What happens if you call
The page is bait. The call is the operation, and it follows a consistent script.
They ask for remote access. Through legitimate remote support software, which is downloadable by anyone and is not itself malicious. You install it, and they are now on your computer with your permission.
They show you something alarming. The Windows Event Viewer is the favourite, because a normal, healthy Windows machine logs hundreds of warnings and errors that mean nothing. Scrolled past quickly by someone describing them as infections, it is persuasive. Other variants use a command prompt filled with output, or a directory of temporary files.
They diagnose and quote. A sum for cleaning, a support plan, sometimes a multi-year contract.
They take payment, and they prefer methods that cannot be reversed — bank transfer, gift cards, cryptocurrency.
They may do real damage on the way out. Setting a password you do not know, installing something persistent, or leaving the remote access software behind so they can return. A variant inverts the whole thing: a “refund” is offered, a fake bank page shows you have been overpaid, and you are talked into transferring the difference back.
The sum involved is often modest enough to feel survivable. The remote access and the card details are the larger loss, and the number is resold to other operations, which is why one call tends to produce many more.
If you already called
Order matters, and the first step is not scanning.
1. Disconnect from the internet. Unplug the ethernet cable or turn off Wi-Fi. This ends the session immediately if they are still connected.
2. Uninstall the remote access software. Settings → Apps → Installed apps on Windows, or drag it to the Bin on macOS, and check login items afterwards.
3. Change your passwords from a different device. Email first, then banking, then anything else you signed into on that machine. Not from the affected computer.
4. Ring your bank if you paid by card or transfer, on the number printed on your card. Card payments can sometimes be reversed. Bank transfers and gift cards usually cannot, which is precisely why they were requested.
5. Scan the machine properly. Use the Defender offline scan, which reboots and scans before Windows loads: scanning for and removing malware on Windows has the full procedure.
6. Expect follow-up calls. Often from someone offering to recover your money for a fee, which is the same operation returning. Nobody legitimate offers this unprompted.
The complete ordered checklist for the aftermath is in what to do after clicking a suspicious link.
The rules that end this permanently
- No technology company puts a phone number in an error message. None. This single rule defeats the entire category.
- Nobody legitimate calls you about a virus on your computer. Your internet provider cannot see that, and Microsoft does not telephone individuals.
- Never allow remote access to someone who contacted you first. Fine when you rang a company you chose. Never when they reached you.
- Gift cards are not a payment method for support. Any request for them ends the conversation.
- Never search for a support number and ring the first result. Paid adverts for fake support numbers appear regularly in search results. Use the number on your card, your receipt, or the company’s own site reached by typing the address.
Realistic expectations
If you closed the tab, nothing happened. The page took nothing, left nothing and cannot do anything. That is the overwhelmingly common ending.
If you rang but installed nothing and paid nothing, you are in reasonable shape, and the main consequence is more calls. Where it becomes serious is remote access and payment, and both of those need the ordered response above rather than a scan.
This scam has worked for well over a decade and shows no sign of stopping, because it needs no technical skill and the targeting is indiscriminate. It is worth explaining the “no phone numbers in error messages” rule to anyone in your household who might be on the receiving end of it, because the one-line version is all the defence most people need.