A full-screen warning claiming your PC has "247 viruses," a fake blue error screen with a phone number to call, or a browser tab that won't close and keeps blaring an alarm sound β€” scareware is designed purely to panic you into calling a fake support line or paying for fake "repair" software. This guide explains how to shut it down safely, whether your PC is actually infected, and how to remove anything genuinely malicious left behind.

First: Is This a Real Infection or a Browser Scare Page?

This distinction changes what you need to do next, so work it out before panicking.

  • Browser-based scareware (by far the most common) is just a webpage designed to look like a Windows warning or antivirus alert, often triggered by an ad network or a dodgy site. It cannot actually scan your PC β€” closing the browser tab or process removes it entirely, no infection occurred.
  • A genuine fake antivirus program (rogueware) is actual software that got installed on your PC, which continues to show fake warnings even after you close your browser and restart, and which typically pushes you to "purchase" a fake licence to "remove" invented threats.

Safety warning: A real Microsoft or antivirus alert will never ask you to call a phone number, and Microsoft never proactively contacts customers about virus detections this way. Any pop-up with a phone number to call is a scam, full stop β€” do not call it, and if you already have, do not give the caller remote access to your PC or any payment details.

Step 1: Close the Pop-Up Safely

Scareware pages often try to prevent normal closing, trap you in a fullscreen loop, or spawn a "leave site?" dialog designed to make you click something that triggers a download instead.

  1. Do not click any button inside the pop-up itself β€” including "Cancel," "Close," or an X that appears inside the page content, since these are sometimes fake and trigger a download regardless of which you click.
  2. Press Alt + F4 to close the entire browser window, or Ctrl + Shift + Esc to open Task Manager directly and end the browser process from there.
  3. If it's in fullscreen/kiosk mode and won't respond to Alt+F4, press Ctrl + Alt + Delete and choose Task Manager, then find your browser under Processes and click End task.
  4. When you reopen your browser, do not restore the previous session/tabs if prompted β€” this would simply reopen the same scareware page. Open a fresh window instead.

Step 2: Clear Browser Notifications and Permissions

Some scareware sites trick you into allowing browser notifications, which then let them keep sending fake "virus detected" alerts even after you've closed the tab, disguised as normal desktop notifications.

Chrome / Edge

  1. Go to Settings > Privacy and security > Site settings > Notifications.
  2. Look through the list of sites allowed to send notifications.
  3. Remove anything unfamiliar or related to the scareware incident by clicking the three dots next to it and choosing Remove.

Firefox

  1. Go to Settings > Privacy & Security > Permissions > Notifications > Settings.
  2. Remove any unfamiliar sites from the list.

Step 3: Check for an Actual Installed Rogue Program

If fake warnings persist after closing and reopening your browser cleanly, or appear even with the browser fully closed, treat it as a genuine infection.

  1. Open Settings > Apps > Installed apps and sort by install date.
  2. Look for unfamiliar "antivirus," "cleaner," "optimizer," or "PC repair" tools you didn't intentionally install β€” these names are deliberately chosen to sound legitimate and helpful.
  3. Uninstall anything suspicious.
  4. Check Task Manager > Startup apps and disable any unfamiliar entries.

Step 4: Run a Full Scan

  1. Open Windows Security > Virus & threat protection and run a Full scan.
  2. Follow up with a Malwarebytes scan (downloaded fresh from the official malwarebytes.com site β€” not from any link the scareware itself provided, which could be another fake download).
  3. Quarantine and remove anything detected, then restart.

Pro tip: If you've already downloaded and run something the scareware pop-up told you to install, treat that as a likely genuine infection even if no further warnings appear β€” some rogueware installs quietly in the background after the initial loud "scan" theatre finishes, specifically to seem less suspicious. Run the full scan process above regardless of whether symptoms persist.

Step 5: If You Called the Number or Gave Remote Access

This is the scenario that needs the most careful follow-up, since it moves beyond software and into direct manipulation by a scammer.

  1. If you gave someone remote access to your PC (via TeamViewer, AnyDesk, or similar, at their instruction): disconnect immediately, then uninstall that remote access software. Assume the PC's security is compromised and run the full malware removal process in this guide, ideally followed by the fuller trojan/worm removal steps in our dedicated guide.
  2. If you paid for anything over the phone or through a scareware "purchase" page: contact your bank or card provider immediately to report the transaction as fraudulent and consider the card compromised β€” request a replacement.
  3. If you provided personal details (name, address, or especially banking details): monitor your bank statements closely for the following weeks and consider a fraud alert with your bank.
  4. Report the scam to Action Fraud (actionfraud.police.uk), the UK's national reporting centre for fraud and cybercrime.

Step 6: Prevent It Happening Again

  • Keep your browser's built-in phishing/malware protection enabled (Safe Browsing in Chrome/Edge, or equivalent in Firefox) under Privacy and Security settings.
  • Be cautious with ad-heavy or pirated content sites, torrenting portals, and "free movie streaming" sites, which are disproportionately common sources of malicious ad redirects that trigger scareware.
  • Consider a browser extension-based ad blocker from a reputable source (uBlock Origin is widely trusted) to reduce exposure to the malicious ad networks that serve scareware in the first place.
  • Remember the golden rule: a real security alert never asks you to call a number, and never demands immediate payment to "fix" something found during a scan you didn't run yourself.

Quick Reference: What to Do Right Now

  • [ ] Close the pop-up via Task Manager, not by clicking anything inside it
  • [ ] Don't restore the previous browser session when reopening
  • [ ] Check and clear browser notification permissions
  • [ ] Check installed apps for anything unfamiliar and uninstall it
  • [ ] Run Windows Defender full scan, then Malwarebytes
  • [ ] If you called the number, gave remote access, or paid β€” contact your bank and report to Action Fraud

Scareware relies entirely on panic to work β€” once you know it's just a webpage (in the vast majority of cases) rather than a genuine scan of your PC, the fear it's designed to create loses most of its power.


Was this guide helpful? Explore more Malware Removal guides, or browse all Security & Performance articles.