Fake Virus Warning Popups: How Tech Support Scams Really Work
A full-screen "Microsoft security alert" with a siren and a phone number is not a virus detection. Learn what the popup actually is and how to close it safely.
10 minute read
Written by ScamAlert Editorial Team
Fraud research and consumer protection reporting
Checked against primary sources
FTC, FBI IC3 and CFPB — how we verify
- Published:
- Updated:
The short answer
The popup is just a web page — it has not scanned your computer and found nothing, because a website cannot scan your computer. It is designed to look unclosable so you call the number. Close the browser with Task Manager or Force Quit, and never call the number or let anyone connect to your machine.
- No website can detect a virus on your computer. The "scan results" are a pre-written animation.
- Microsoft, Apple and Google never put a phone number in a security warning.
- The popup cannot lock your computer — it fakes fullscreen so the close button seems missing.
- The real damage begins if you grant remote access, not from seeing the page.
It arrives without warning, usually after a mistyped address or a click on an ad. The screen fills. There is a siren, or a robotic voice repeating that your computer has been locked. Red text warns that your banking credentials are being transmitted, that Windows Defender has detected a trojan, that you must not restart your computer. A phone number is displayed prominently, described as Microsoft Support, and the page will not close.
Almost everything on that screen is false, and one thing in particular is worth internalizing before anything else: a website cannot scan your computer. The security model of every modern browser exists specifically to prevent a page from reading your files, enumerating your processes, or inspecting your system. The scan you are watching is an animation written in advance. It shows the same "infections" to every visitor, and it plays identically on a brand-new machine that has never been online.
The alarming design has a single purpose, and it is not to inform you. It is to move you off the screen and onto the telephone, where a person can talk you into granting access to your machine. Everything harmful in this scam happens on that call.
Why the popup seems impossible to close
People often conclude their computer really is locked, because the page genuinely does resist closing. That impression comes from a handful of ordinary web techniques, none of which involve any access to your system.
- Fullscreen mode is requested by the page, which hides the browser toolbar and the close button so the window looks like a system-level takeover.
- A dialog loop repeatedly triggers alert boxes, so dismissing one immediately spawns another and the page appears frozen.
- A navigation guard fires a "Are you sure you want to leave?" prompt on every attempt to close.
- The cursor is hidden or replaced, or the page captures the pointer so clicks do not land where you expect.
- Audio autoplays a siren or a synthesized voice, which is the single most effective element for producing panic.
- The page is styled as a pixel-accurate copy of a Windows or macOS system dialog, including the correct fonts and iconography.
What happens if you call the number
The person who answers is a call centre operator following a script refined across thousands of calls. They will sound calm, technically fluent and genuinely helpful, and they will spend the first minutes building credibility rather than asking for anything. Then they will ask to connect to your computer to "run diagnostics" — using legitimate remote access software such as AnyDesk, TeamViewer or LogMeIn, which is exactly why the download looks safe and passes antivirus.
Once connected, a standard sequence follows. They open Windows Event Viewer and present routine warning entries — present on every healthy computer — as evidence of infection. They may run netstat and describe normal network connections as intruders, or open a command prompt and type alarming text directly into it. The performance is designed to convert your uncertainty into their authority.
The payment request follows, typically several hundred dollars for a multi-year "support plan". But the more serious exposure is the access itself: while connected, they can install persistent remote tools, harvest saved browser passwords, read your email, and open your online banking with your own logged-in session.
| Signal | Real security software | Scam popup |
|---|---|---|
| Where it appears | In its own application window or system notification | Inside a browser tab or fullscreen web page |
| Phone number | Never included in an alert | Large, prominent, urgent |
| Detection claim | Names a specific file path it quarantined | Vague counts of "infections" and stolen credentials |
| Tone | Neutral and factual | Sirens, countdowns, warnings not to restart |
| Requested action | Quarantine or remove, inside the app | Call, then install remote access software |
| Payment | Handled through your account or an app store | Card over the phone, gift cards, wire, or crypto |
Where these popups come from
They rarely mean your computer is compromised. The common delivery routes are mundane: a malicious advertisement served through a legitimate ad network, a typo in a domain name, a redirect from a free streaming or download site, an aggressive browser notification you accidentally allowed, or a browser extension gone bad.
That last one is worth checking if the popups keep returning. Site notification permissions, once granted, can push alerts that appear even when the browser is closed. Reviewing the notification permissions in your browser settings and revoking anything unfamiliar resolves most recurring cases.
Signs the alert is fake
Any single one of these is conclusive.
- It appears in a browser window rather than in a security application.
- It displays a phone number to call.
- It claims to have scanned your computer from a web page.
- It plays a siren, a voice recording, or shows a countdown.
- It tells you not to restart or shut down your computer.
- It uses a Microsoft, Apple, Google or Norton logo alongside a support number.
- It asks you to install remote access software to fix the problem.
- The requested payment is in gift cards, cryptocurrency, or a wire transfer.
If you already gave someone access
Tech support scam recovery timeline
Assume everything on the machine was readable while they were connected.
- 1
Immediately
Disconnect the computer from the internet
Turn off Wi-Fi or unplug the cable. This ends the remote session at once. Do not let a caller talk you out of it — they will say disconnecting will damage your system, which is untrue.
- 2
Minutes 5–20
Remove the remote access software
Uninstall AnyDesk, TeamViewer, LogMeIn, UltraViewer or anything else installed during the call. Also check for unfamiliar programs added the same day and any newly created user accounts.
- 3
Minutes 20–60
Change passwords from a different device
Use your phone or another computer, not the affected one. Start with your email, then banking, then anything sharing that password. Sign out all active sessions where the service offers it.
- 4
Hour 1
Call your bank if you paid or if banking was opened
Report the card as compromised and request reissue. If your online banking was opened during the session, ask them to review activity, force a password reset, and remove unrecognized devices and payees.
- 5
Day 1
Have the machine inspected, or reinstall
Run a full scan with reputable security software. If sensitive accounts were accessed, a clean operating system reinstall is the only way to be confident nothing persistent remains.
- 6
Days 1–7
Report and protect your identity
File at ReportFraud.ftc.gov and with IC3. If personal documents were on the machine, place a fraud alert or credit freeze with all three bureaus.
Report a tech support scam
Include the phone number displayed, the website address if you have it, and any software you were asked to install.
These are official government resources. ScamAlert is not affiliated with any government agency and receives no compensation for these links.
One reframing helps more than any checklist. Every genuine security tool on your computer is already running with the access it needs to protect you — it does not require your cooperation, and it certainly does not need you to phone anyone. So the moment an alert needs you to take an action outside the software itself, especially a phone call, you are not looking at a security product. You are looking at an advertisement that has been designed to frighten you, and the correct response is to close the window.
How to close a fake virus warning popup safely
Steps to dismiss a scam security popup without calling the number, and recovery steps if remote access was granted.
- 1
Do not call the number displayed
No legitimate security warning from Microsoft, Apple or Google includes a phone number. The number is the entire objective of the page.
- 2
Force the browser to close
Windows: Ctrl + Shift + Esc, select the browser, End Task. Mac: Cmd + Option + Esc, select the browser, Force Quit. Phone: close it from the app switcher.
- 3
Decline to restore tabs
Reopen the browser and refuse any offer to restore the previous session, which would reload the same page.
- 4
Revoke rogue notification permissions
Check your browser’s site notification settings and remove anything unfamiliar, which stops recurring popups.
- 5
Disconnect from the internet if you granted access
Turn off Wi-Fi or unplug the cable immediately. This ends the remote session regardless of what the caller claims.
- 6
Uninstall the remote access software
Remove AnyDesk, TeamViewer, LogMeIn or similar, and check for unfamiliar programs and new user accounts created that day.
- 7
Change passwords from a clean device and call your bank
Start with email, then banking. Report any card used as compromised and request reissue.
Frequently asked questions
Can a website really detect a virus on my computer?
No. Browsers deliberately isolate web pages from your file system and running processes — that isolation is one of the core security guarantees of the modern web. A page cannot enumerate your files, read your antivirus status, or identify malware. Any "scan" animation you see is pre-written and shows identical results to every visitor, including on a brand-new machine.
The popup says my computer is locked and I should not restart. Is that true?
It is false, and it is one of the most reliable indicators of a scam. The instruction exists because restarting closes the browser and destroys the illusion instantly. A web page cannot lock your computer; it can only make its own window difficult to close using fullscreen mode and repeated dialogs. Restarting is safe and nothing is being deleted while you decide.
I called the number but hung up before installing anything. Am I at risk?
Very little. If nothing was installed and you disclosed no card details or passwords, the main consequence is that your number is now on a list of people who respond, so expect follow-up calls claiming to be from Microsoft, your bank, or a refund department. Do not engage with them. If you gave your name and address only, stay alert for tailored follow-up attempts.
Does getting this popup mean I already have a virus?
Usually not. These pages are delivered through malicious advertising on otherwise legitimate sites, mistyped domains, redirects from streaming and download sites, or browser notification permissions you granted at some point. If they recur frequently, review your browser’s site notification settings and installed extensions, and run a scan with reputable security software.
They offered me a refund and now want money back. What is happening?
This is the refund reversal scam and it is the most costly variant. They connect remotely, open your banking, and manipulate what is displayed so it appears they refunded far too much. Nothing was sent — you are viewing an edited display of your own account. They then ask you to return the difference in gift cards or a wire. Disconnect immediately, do not send anything, and call your bank on the number printed on your card.
Does Microsoft ever call about problems with my computer?
Microsoft does not make unsolicited calls about malware on personal computers, and neither do Apple, Google or your internet provider. They have no mechanism to detect an infection on your machine from the outside and no reason to phone you about it. Any inbound call claiming otherwise is fraudulent, regardless of what the caller ID displays.
Sources & further reading
Every guide on ScamAlert is checked against primary sources from US consumer protection and law enforcement agencies.
- [1]How to Spot, Avoid, and Report Tech Support Scams — Federal Trade Commission
- [2]Internet Crime Complaint Center (IC3) — Federal Bureau of Investigation
- [3]Identity theft recovery plans — Federal Trade Commission
Topics covered
- microsoft security warning scam
- fake virus warning popup
- tech support scam
- computer locked popup scam
- fake windows defender alert
- how to close a scam popup
Editorial note: This guide is general consumer education, not legal or financial advice. Dispute deadlines, liability limits and reimbursement policies vary by institution and change over time. Confirm your specific rights with your bank or a qualified professional. See our editorial policy for how we research and review this content.
Sponsored content
Related guides
AI & Cyber
AI Voice Cloning Scams
A few seconds of public audio is enough to clone a relative’s voice. Learn how AI voice cloning emergency scams are built, why they defeat instinct, and the one habit that stops them.
Banking & Wire
Bank Fraud Alert Text Scam
A fake bank fraud alert text is the opening move in a bank impersonation scam. Learn how smishing works, the three requests that are always fraud, and the recovery steps that still work.
Cards & Payments
Gift Card Scams & Draining
Nobody legitimate is ever paid in gift cards. Learn why fraudsters insist on them, how in-store card draining works, and what to do in the first hour after paying.