What kind of scam is "Your antivirus protection has expired"?
We have discovered this pop-up scam while testing various websites that use rogue advertising networks (display shady ads and redirect visitors to untrustworthy pages). We concluded that the purpose of this pop-up scam is to trick visitors into believing that their computers are infected with malware.
"Your antivirus protection has expired" in detail
At first, this deceptive page displays a fake safety warning claiming that you may have recently visited compromised websites and your computer might be under attack. To remove potential viruses, you must run an antivirus scan immediately.
This site is also designed to run a fake system scan and display a list of detected malware (such as "Win32/Rbot", "Win32/Sirefed.A", "Win32/Spatet.A", "HTML/frame.B.Gen"). It claims that a computer is not protected and urges to purchase the McAfee Total Protection subscription with a 55% discount available only for a specified amount of time.
McAfee Total Protection is legitimate antivirus software. Its developers do not use pop-up scams or similar methods to advertise it. Most likely, scammers behind this particular participate in an affiliate program and promote McAfee Total Protection to collect illegitimate commissions.
|Name||Your antivirus protection has expired scam|
|Threat Type||Phishing, Scam, Social Engineering, Fraud|
|Fake Claim||A computer is infected with malware|
|Disguise||Legitimate security warning from McAfee|
|Related Domai||web-scanning[.]com, privacy-optimize[.]com|
|Detection Names (web-scanning[.]com)||N/A (VirusTotal)|
|Symptoms||Fake error messages, fake system warnings, pop-up errors, hoax computer scan.|
|Distribution methods||Compromised websites, rogue online pop-up ads, potentially unwanted applications.|
|Damage||Loss of sensitive private information, monetary loss, identity theft, possible malware infections.|
|Malware Removal (Windows)||
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.
Similar scams in general
Scam websites that use scare tactics to trick visitors into purchasing antivirus subscriptions are disguised as legitimate pages. They display fake safety warnings or similar notifications claiming that a computer is infected, damaged, etc. These websites must be ignored.
More examples of similar scams are "McAfee Total Protection - Your PC Might Be Infected With Viruses!", "Kaspersky - Your PC Is infected With 5 viruses!", "TROJAN Zeus2021 Spyware Adware Detected".
How did I open a scam website
Websites that deliver pop-up scams usually get opened through shady advertisements and other untrustworthy websites. Also, scammers promote these pages using questionable applications, search engine poisoning techniques, website notifications. Either way, users do not visit scam websites of this type on purpose.
How to avoid visiting scam pages?
Do not allow untrustworthy websites to show notifications or click advertisements appearing on them. Download apps and files from legitimate sources (official pages and direct download links). Do not trust downloads from P2P networks, shady pages, third-party downloaders, etc.
Deselect unwanted apps before downloading or installing software bundled with them. Typically, downloaders/installers used to distribute shady apps have "Custom", "Advanced", or similar settings in them. If your computer is already infected with unwanted apps, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate them.
The appearance of "Your antivirus protection has expired" pop-up scam (GIF):
Text in the initial pop-up window:
You might recently browsed to comprimised websites that are most likely infected with viruses.
You might recently browsed to comprimised websites with streaming and/or adult content.
Therefore, your computer might currently be under attack.
To delete potential viruses, you must run an antivirus scan immediately.
[Start Quick Scan Now]
Text in the second pop-up window:
Quick Scan Results
Your Computer might be infected with potentially critical viruses!
Warning! Action required!
Your Computer is infected with (5) viruses, damaging your system.
Your personal data, banking information and other sensitive information is at risk!
Please start your McAfee Total Protection to eliminate all threats.
[Start McAfee Total Protection]
Text in the final page:
McAfee Total Protection
Warning! Your computer is not protected!
The following viruses and problems were found:
Identity Protection: Disabled
McAfee WebAdvisor: Disabled
Your Antivirus Protection has expired on Mar 9, 2022
Renew Now To Eliminate Viruses and Malwares From Your COmputer
Warning: If your computer is unprotected, it is at a high risk for viruses and other malware.
Is Available For: 3 minutes 59 seconds
Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
- What is Your antivirus protection has expired scam?
- How to identify a pop-up scam?
- How do pop-up scams work?
- How to remove fake pop-ups?
- How to prevent fake pop-ups?
- What to do if you fell for a pop-up scam?
How to identify a pop-up scam?
Pop-up windows with various fake messages are a common type of lures cybercriminals use. They collect sensitive personal data, trick Internet users into calling fake tech support numbers, subscribe to useless online services, invest in shady cryptocurrency schemes, etc.
While in the majority of cases these pop-ups don't infect users' devices with malware, they can cause direct monetary loss or could result in identity theft.
Cybercriminals strive to create their rogue pop-up windows to look trustworthy, however, scams typically have the following characteristics:
- Spelling mistakes and non-professional images - Closely inspect the information displayed in a pop-up. Spelling mistakes and unprofessional images could be a sign of a scam.
- Sense of urgency - Countdown timer with a couple of minutes on it, asking you to enter your personal information or subscribe to some online service.
- Statements that you won something - If you haven't participated in a lottery, online competition, etc., and you see a pop-up window stating that you won.
- Computer or mobile device scan - A pop-up window that scans your device and informs of detected issues - is undoubtedly a scam; webpages cannot perform such actions.
- Exclusivity - Pop-up windows stating that only you are given secret access to a financial scheme that can quickly make you rich.
Example of a pop-up scam:
How do pop-up scams work?
Cybercriminals and deceptive marketers usually use various advertising networks, search engine poisoning techniques, and shady websites to generate traffic to their pop-ups. Users land on their online lures after clicking on fake download buttons, using a torrent website, or simply clicking on an Internet search engine result.
Based on users' location and device information, they are presented with a scam pop-up. Lures presented in such pop-ups range from get-rich-quick schemes to fake virus scans.
How to remove fake pop-ups?
In most cases, pop-up scams do not infect users' devices with malware. If you encountered a scam pop-up, simply closing it should be enough. In some cases scam, pop-ups may be hard to close; in such cases - close your Internet browser and restart it.
In extremely rare cases, you might need to reset your Internet browser. For this, use our instructions explaining how to reset Internet browser settings.
How to prevent fake pop-ups?
To prevent seeing pop-up scams, you should visit only reputable websites. Torrent, Crack, free online movie streaming, YouTube video download, and other websites of similar reputation commonly redirect Internet users to pop-up scams.
To minimize the risk of encountering pop-up scams, you should keep your Internet browsers up-to-date and use reputable anti-malware application. For this purpose, we recommend Combo Cleaner Antivirus for Windows.
What to do if you fell for a pop-up scam?
This depends on the type of scam that you fell for. Most commonly, pop-up scams try to trick users into sending money, giving away personal information, or giving access to one's device.
- If you sent money to scammers: You should contact your financial institution and explain that you were scammed. If informed promptly, there's a chance to get your money back.
- If you gave away your personal information: You should change your passwords and enable two-factor authentication in all online services that you use. Visit Federal Trade Commission to report identity theft and get personalized recovery steps.
- If you let scammers connect to your device: You should scan your computer with reputable anti-malware (we recommend Combo Cleaner Antivirus for Windows) - cyber criminals could have planted trojans, keyloggers, and other malware, don't use your computer until removing possible threats.
- Help other Internet users: report Internet scams to Federal Trade Commission.
Frequently Asked Questions (FAQ)
What is a pop-up scam?
It is a fake system warning or other deceptive message displayed by a shady website claiming that a computer is infected, compromised, etc. Usually, it urges to fix the "occurred" problem as soon as possible.
What is the purpose of a pop-up scam?
There are different types of pop-up scams. Scammers use them to trick unsuspecting users into calling the provided number, purchasing fake or unnecessary software, infecting computers with malware, providing sensitive information.
Why do I encounter fake pop-ups?
In most cases, websites that display fake/deceptive pop-ups get opened after a shady ad is clicked or an untrustworthy page is visited. Sometimes, these sites can appear in search results (when promoted using search engine poisoning techniques). Also, scam websites can be promoted through dubious apps that most users install inadvertently.
Will Combo Cleaner protect me from pop-up scams?
Combo Cleaner will scan visited websites, detect untrustworthy ones and restrict access to them (including websites designed to display deceptive pop-ups).