Online scams have become increasingly sophisticated, often disguising themselves as legitimate messages to lure unsuspecting users into installing malicious software or revealing sensitive personal information. One such scam is the “AVG – Your Subscription Has Expired” pop-up, which exploits users’ trust in the well-known antivirus software AVG to trick them into downloading potentially harmful software.
Scam Overview
The “AVG – Your Subscription Has Expired” scam presents itself as an urgent notification from AVG, claiming that the user’s antivirus subscription has expired. The message warns the user that their computer is no longer protected and is at risk of malware infections, identity theft, and other security threats. In an attempt to scare the user, the scam offers a discount on AVG Total Security to prompt the download of malicious software.
The scam is not associated with AVG or any legitimate antivirus service. It is simply an attempt to scare users into installing fake security software or visiting malicious websites designed to compromise their device and personal information.
Text Presented in the Scam Pop-Up
The “AVG – Your Subscription Has Expired” pop-up contains alarming and misleading messages to create a sense of urgency:
AVG
Your AVG Security subscription has expired
Your subscription of AVG Total Protection for Windows has expired on March 31, 2025.
After the expiry date has passed, a virus may infect your PC, malicious malware might be installed, or your online identity may be stolen.
Your PC is unprotected, it is exposed to viruses and other malware.
Discount (April 02, 2025):
You are eligible for UP TO 50% OFF
AVG Total Security
20.9.139 (10 DEVICES)
Serial Number:
8A5B4-RV6N-Q8TL-OFG3
Renew Subscription
The pop-up includes a call to action urging the user to renew their subscription, which is a direct attempt to sell the victim fake security software.
Summary of the Scam Details
| Detail | Information |
|---|---|
| Threat Type | Phishing, Scam, Social Engineering, Fraud |
| Fake Claim | User’s AVG antivirus subscription has expired, and their computer is at risk of malware. |
| Disguise | AVG AntiVirus |
| Related Domains | webmeetwin[.]site |
| Detection Names | N/A (VirusTotal) |
| Symptoms | Fake error messages, fake system warnings, hoax computer scan, pop-up errors |
| Distribution Methods | Compromised websites, rogue online ads, PUAs |
| Damage | Loss of sensitive private information, monetary loss, identity theft, possible malware infections |
| Danger Level | High (due to the potential for malware infections, financial loss, and identity theft) |
Associated Scams
This particular scam is part of a larger category of online frauds involving fake antivirus subscriptions. Other scams, such as “VirtualShield – Your PC Is Infected With 18 Viruses” and “McAfee – Computer Infected With Potentially Critical Viruses,” employ similar scare tactics to convince users that their devices are at risk, prompting them to download malicious software or pay for fake security programs.
Manual Adware Removal (Windows & Mac)
Step 1: Identify Suspicious Applications
For Windows Users
- Press
Ctrl + Shift + Escto open the Task Manager. - Check the “Processes” tab for unfamiliar or suspicious programs consuming excessive CPU or memory.
- If you find any, note their names and close them.
- Open
Control Panel>Programs>Programs and Features. - Locate the suspicious application, right-click it, and select “Uninstall.”
For Mac Users
- Open
Finderand navigate toApplications. - Look for any suspicious or unknown applications.
- Drag them to the
Trash, then right-click on theTrashand selectEmpty Trash. - Open
System Preferences>Users & Groups>Login Itemsand remove any unrecognized startup programs.
Step 2: Remove Adware-Related Browser Extensions
Google Chrome
- Open Chrome and go to
Menu(three dots in the top-right corner) >Extensions. - Locate suspicious extensions and click “Remove.”
- Reset Chrome: Go to
Settings>Reset settings> “Restore settings to their original defaults.”
Mozilla Firefox
- Open Firefox and go to
Menu(three lines in the top-right corner) >Add-ons and themes. - Locate and remove suspicious extensions.
- Reset Firefox: Go to
Help>More troubleshooting information> “Refresh Firefox.”
Safari (Mac)
- Open Safari and go to
Preferences>Extensions. - Locate and remove any unknown extensions.
- Reset Safari: Go to
History> “Clear History.”
Microsoft Edge
- Open Edge and go to
Menu(three dots in the top-right corner) >Extensions. - Remove suspicious extensions.
- Reset Edge: Go to
Settings>Reset settings> “Restore settings to their default values.”
Step 3: Delete Adware-Related Files and Folders
For Windows Users
- Press
Win + R, type%AppData%, and press Enter. - Look for suspicious folders and delete them.
- Repeat for
%LocalAppData%,%ProgramData%, and%Temp%.
For Mac Users
- Open Finder, press
Shift + Command + G, and enter~/Library/Application Support/. - Locate and delete suspicious folders.
- Repeat for
~/Library/LaunchAgents/,~/Library/LaunchDaemons/, and~/Library/Preferences/.
Step 4: Flush DNS Cache (Recommended)
For Windows Users
- Open
Command Promptas Administrator. - Type
ipconfig /flushdnsand press Enter.
For Mac Users
- Open
Terminal. - Type
sudo killall -HUP mDNSResponderand press Enter.
Step 5: Restart Your Computer
Restart your device to complete the manual removal process.
Automatic Adware Removal Using SpyHunter (Windows & Mac)
For a hassle-free and effective removal, use SpyHunter, a robust anti-malware tool designed to detect and remove adware efficiently.
Step 1: Download SpyHunter
Download SpyHunter from the official website: Click here to download SpyHunter.
Step 2: Install SpyHunter
Follow the installation instructions based on your operating system:
For Windows Users:
- Open the downloaded
.exefile. - Follow the on-screen installation instructions.
- Launch SpyHunter and allow it to update its malware definitions.
For Mac Users:
- Open the downloaded
.dmgfile. - Drag and drop SpyHunter into the Applications folder.
- Launch SpyHunter and allow it to update its malware definitions.
Step 3: Perform a System Scan
- Open SpyHunter.
- Click on
Start Scan. - Wait for the scan to complete.
- Review the detected threats and click
Fix Threatsto remove adware.
Step 4: Restart Your Device
After SpyHunter removes the threats, restart your computer to finalize the process.
For the most secure and effective removal, we recommend downloading and using SpyHunter: Download SpyHunter Here.
Stay safe and keep your system clean!
Conclusion
This scam can have serious consequences for users, potentially leading to identity theft, financial losses, and malware infections. Always exercise caution when faced with alarming pop-ups or offers, and make sure to verify the legitimacy of such messages before taking any action. Stay safe and always opt for trusted sources when renewing software or making online purchases.
