The “Norton – Scan Your Windows PC For Viruses In Seconds” pop-up scam is a deceptive browser-based attack designed to mimic legitimate Norton Antivirus alerts. This scam’s objective is to trick users into thinking their systems are infected, leading them to click links that may install malware or redirect to phishing websites. This kind of social engineering attack preys on fear and urgency to compromise user safety and data.
Threat Overview
This threat uses fraudulent pop-ups to imitate a Norton virus scan alert. It often appears unexpectedly in web browsers and urges immediate action to remove nonexistent threats. The end goal is to lure users into interacting with malicious sites or downloading potentially unwanted applications (PUAs) under the false pretense of system protection.
Threat Summary
Attribute | Details |
---|---|
Threat Type | Phishing, Scam, Social Engineering, Fraud |
Associated Domains | spostufeaseme[.]com |
Detection Names | Combo Cleaner (Malware), CRDF (Malicious), ESET (Malware), Fortinet (Malware), G-Data (Malware) |
Symptoms of Infection | Fake antivirus alerts, pop-up warnings, deceptive system scan messages |
Damage | Potential malware infection, identity theft, financial loss, data compromise |
Distribution Methods | Compromised websites, malicious ads, deceptive downloads bundled with freeware |
Danger Level | High |
Removal Tool | SpyHunter |
Detailed Analysis
How Did I Get Infected?
Infections typically occur through deceptive websites, malicious advertisements, or software bundles that carry adware or browser hijackers. These infections alter browser settings and inject scripts that trigger scam pop-ups like the fake Norton alert.
What Does It Do?
Once triggered, the scam presents users with a realistic-looking pop-up pretending to be from Norton. It warns of multiple system threats and pressures users to perform a “scan.” Clicking on any links or buttons often leads to rogue software installs or phishing pages that attempt to steal personal data or convince the victim to pay for bogus tech support.
Should You Be Worried About Your System?
Yes, especially if you clicked on the pop-up or downloaded anything it recommended. Even if no malicious software was installed, the presence of this scam indicates vulnerabilities or active adware on your system. These types of scams can evolve into more serious malware infections or financial scams if not addressed promptly.
Scam Message Example
Norton – Scan Your Windows PC For Viruses In Seconds
Your PC is infected with multiple viruses!
Immediate action is required to prevent data loss.
Click ‘Start Scan Now’ to remove threats.
Option 1: Manual Browser Hijacker Removal
Step 1: Uninstall Suspicious Software
For Windows:
- Press
Windows + R
, typeappwiz.cpl
, and press Enter. - Look for recently installed or unknown software.
- Select the suspicious program and click Uninstall.
- Follow the uninstaller’s prompts.
For Mac:
- Open Finder > Applications.
- Locate any unfamiliar apps you didn’t intentionally install.
- Drag them to the Trash.
- Right-click the Trash and select Empty Trash.
Step 2: Reset Each Web Browser Affected
Google Chrome:
- Go to chrome://settings/reset.
- Click Restore settings to their original defaults > Reset settings.
- Then, visit chrome://extensions and remove any suspicious add-ons.
- Change your search engine:
Settings > Search Engine > Manage search engines — remove unwanted entries and set a trusted one like Google.
Mozilla Firefox:
- Click the menu icon (three lines) > Help > More Troubleshooting Information.
- Click Refresh Firefox.
- After reset, check Add-ons and Themes and remove unwanted extensions.
- Navigate to Settings > Home/Search and revert changes to your preferred provider.
Microsoft Edge:
- Click menu (three dots) > Settings > Reset Settings > Restore settings to their default values.
- Open edge://extensions and remove any unfamiliar plugins.
- Reconfigure your homepage and search engine if needed.
Safari (Mac Only):
- Open Safari > Click Safari in the top menu > Clear History (select All History).
- Go to Preferences > Extensions, remove unknown entries.
- Under General, set your homepage.
- Under Search, revert to your preferred search provider.
Step 3: Check and Clean Your Hosts File
On Windows:
- Open Notepad as Administrator.
- Go to:
C:\Windows\System32\drivers\etc\hosts
- Look for unknown IPs or domains — remove them.
- Save changes and reboot.
On Mac:
- Open Terminal.
- Run:
sudo nano /etc/hosts
- Identify and remove hijacker entries.
- Press
Control + O
to save andControl + X
to exit.
Option 2: Automatic Removal Using SpyHunter
If you want a faster and safer solution — especially if the hijacker reinstalls after manual removal — use SpyHunter, a trusted anti-malware tool.
Step 1: Download SpyHunter
Visit the official download page: Download SpyHunter
Need help with the installation? Follow this page: SpyHunter Download Instructions
Step 2: Install and Launch the Program
- Run the installer and follow the steps for your OS.
- Open SpyHunter after installation.
Step 3: Perform a Full System Scan
- Click Start Scan Now.
- Wait while SpyHunter analyzes your computer for browser hijackers, malware, and other PUPs.
- Once the scan completes, click Fix Threats to eliminate them.
Step 4: Reboot and Recheck Your Browser
After cleaning, restart your device. Open your browser and check if your homepage and search settings are restored. If not, perform a quick browser reset using the manual steps above.
How to Prevent Future Infections
- Avoid downloading freeware from third-party sites.
- Use custom/advanced installation and deselect optional offers.
- Keep your browser and OS updated.
- Regularly scan your system with SpyHunter for proactive defense.
- Don’t click strange pop-ups or redirect links from unknown sources.
Conclusion
The "Norton - Scan Your Windows PC For Viruses In Seconds" scam is a high-risk threat that manipulates user fear through fake virus alerts. It's a classic example of phishing combined with scareware tactics, designed to exploit user trust in well-known antivirus brands. If you see such pop-ups, close the browser tab immediately and scan your system using a trusted tool like SpyHunter to ensure full removal of any associated threats.