Threat Intelligence Directory
Malware

Rogue Antivirus / Tech Support Pop-Up Scam

Attack Trigger

Alarming on-screen virus warning or browser pop-up claiming your computer is infected

What Attackers Want

$200–$1,000 for fake "virus removal" plus potential credential theft

How This Attack Works

Rogue antivirus scams display fake virus detection pop-ups or browser alerts that mimic legitimate security software. Victims are instructed to call a toll-free number or download a "removal tool" that is actually malware or spyware. Once remote access is granted, attackers steal banking credentials and charge hundreds for fake services.

Red Flags to Watch For

  • Pop-up or email claims multiple viruses were found in a free unsolicited scan
  • You are told to call a phone number displayed in the alert immediately
  • Download prompted is from a site you do not recognize — not Microsoft or your antivirus vendor
  • Technician asks for remote access software to be installed
  • Payment for removal service is demanded via gift cards or prepaid debit cards
  • Alert uses loud sounds or voice narration to create panic

Known Malicious Domains

These domains have been associated with this attack. Never click links going to these addresses.

  • virus-detected-alert.comMALICIOUS
  • pc-security-scan-now.netMALICIOUS
  • windows-error-fix.comMALICIOUS
  • free-virus-removal.netMALICIOUS

Glance automatically blocks emails from domains on this list. Domain list is not exhaustive — attackers register new domains continuously.

How Glance Stops This

  • Domain similarity analysis catches lookalike sender addresses at millisecond speed
  • SPF / DKIM / DMARC validation flags authentication failures before you ever see the email
  • VirusTotal + Google Safe Browsing checks every link in real time
  • Urgency language detection scores the email higher for manual review
  • Known malicious domain blocklist updated continuously from live scan data

Don't wait to get hit.

Glance scans every incoming email against 12 detection layers — including the exact tactics described above — before it reaches your inbox.

Protect My Inbox — Free