Team: Huntress Managed Endpoint Detection and Response (EDR)
Product: Web Browsers (Google Chrome, Microsoft Edge, Mozilla Firefox)
Environment: Windows, macOS
Summary: Learn how to identify and remediate browser scareware pop-ups, audit browser notification settings, and understand why Huntress does not generate incident reports for non-malicious browser alerts.
In this Article
Overview
Scareware pop-ups are social engineering tactics that display fake virus warnings, full-screen browser locks, or fake Blue Screen of Death screens. Their goal is to frighten end users into calling fraudulent support phone numbers or downloading unwanted software.
Because most scareware runs entirely inside the web browser without installing malicious software or establishing system persistence, standard remediation requires clearing browser state rather than running system-level active remediation.
https://www.huntress.com/cybersecurity-101/topic/what-is-scareware
Common Examples of Scareware
Recognizing scareware is the first step to stopping it. The following list describes the most common forms scareware takes:
Fake Antivirus Alerts: Pop-ups warning that your device is infected, designed to imitate legitimate security software. Common impersonations include Microsoft Defender and Windows Security, complete with fake scan results and urgent warnings.
Tech Support Scams: Messages claiming your device has been compromised and will be locked unless you call a support phone number immediately. The number connects to scammers who pressure victims into paying for fake repairs or handing over remote access.
Hacked Account Warnings: Emails or text messages claiming your email, bank, or social media account has been breached, with a link to secure it immediately. The link leads to a phishing page designed to steal your credentials.
Browser Lock Pop-Ups: Scareware that freezes your web browser entirely, making it appear that your system is locked. The goal is to panic the user into calling a number or downloading software to unlock the endpoint.
Mobile Scareware: Delivered through malicious apps or advertisements on mobile devices, these target smartphone users with fake infection alerts or phishing lures designed to harvest personal information or install malware.
Examples:
Why Huntress Does Not Report on Scareware
The Huntress Agent analyzes endpoint telemetry, including running processes, persistence mechanisms, and system artifacts, to detect and remediate active threats.
Scareware pop-ups generally do not generate Huntress Incident Reports for the following reasons:
No System Persistence or Execution: Web page pop-ups and malicious advertisement redirects run within the browser sandbox. They do not write malicious binaries to disk or create persistent footholds on the host operating system.
No Active Malware to Contain: Because no executable malware is present on the endpoint, the Huntress SOC has no active threat to isolate or remediate.
Telemetry Context: If a user clicks a scareware link and subsequently downloads an executable file that attempts to run, the Huntress Agent immediately captures the activity and the Huntress SOC begins an investigation.
How To Remediate Scareware Pop-Ups
If an end user encounters a scareware pop-up or a locked browser window, complete the following steps to clear the browser session and restore normal operation.
Step 1: Force Close the Affected Web Browser
Do not click any buttons, links, or phone numbers inside the scareware prompt.
Open Task Manager on Windows (press Ctrl + Shift + Esc) or Activity Monitor on macOS (press Command + Space and type Activity Monitor).
Locate the web browser process (such as chrome.exe, msedge.exe, or firefox.exe).
Select the process and click End Task (Windows) or Force Quit (macOS).
Step 2: Clear Browser Cache and Site Permissions
Reopening the browser without clearing session data may restore the scareware tab.
Open the web browser.
If prompted to restore your previous session or reopen tabs, select No or close the restore prompt.
Open browser settings and clear browsing data, including cached images, files, and cookies.
Go to site permissions settings and reset notification permissions for any unknown or suspicious websites.
Step 3: Remove Unwanted Extensions and Notifications
In the browser menu, go to Extensions or Add-ons.
Review all installed browser extensions.
Remove any unrecognized, unexpected, or recently added extensions.
Browser-Specific Remediation Steps
Follow the tailored instructions below for your specific web browser to clear persistent settings, remove unwanted extensions, and reset default browser behavior.
Google Chrome
Press Ctrl + Shift + Esc to open Task Manager and force close Google Chrome.
Reopen Google Chrome. Do not select the option to restore your previous session.
Go to Settings > Extensions and remove any suspicious extensions.
Go to Settings > Reset settings and select Restore settings to their original defaults.
Go to Settings > Privacy and security > Clear browsing data.
Set the time range to All time and click Clear data.
Microsoft Edge
Press Ctrl + Shift + Esc to open Task Manager and force close Microsoft Edge.
Reopen Microsoft Edge. Do not select the option to restore your previous session.
Go to Settings > Extensions and remove any suspicious extensions.
Go to Settings > Reset settings and select Restore settings to their default values.
Go to Settings > Privacy, search, and services > Clear browsing data.
Set the time range to All time and click Clear now.
Mozilla Firefox
Press Ctrl + Shift + Esc to open Task Manager and force close Mozilla Firefox.
Reopen Mozilla Firefox. Do not select the option to restore your previous session.
Go to Menu > Add-ons and themes and remove any suspicious add-ons or extensions.
Go to Menu > Help > More troubleshooting information and select Refresh Firefox.
Go to Settings > Privacy & Security and select Clear Data.
Safari Remediation Steps
- Force close Safari via Activity Monitor (Mac equivalent of Task Manager)
- Reopen, don't restore previous session
- Go to Safari menu > Settings > Extensions > remove anything suspicious
- Go to Safari menu > Settings > Privacy > Manage Website Data > Remove All
- Go to Safari menu > Settings > Websites > Notifications > remove suspicious sites
- Go to Safari menu > Clear History > All History > Clear History
Auditing and Removing Browser Notifications
If resetting browser settings to defaults is not desired, audit notification permissions manually to remove unexpected sites from sending pop-ups.
Google Chrome Notification Audit
Open Google Chrome and go to Settings > Privacy and security > Site settings > Notifications.
Review the list of websites under the allowed section.
Locate any suspicious or unexpected sites, select the options icon next to each site, and select Remove.
Microsoft Edge Notification Audit
Open Microsoft Edge and go to Settings > Cookies and site permissions > Notifications.
Review the list of websites allowed to send notifications.
Locate any suspicious or unexpected sites, select the options icon next to each site, and select Remove.
Mozilla Firefox Notification Audit
Open Mozilla Firefox and go to Settings > Privacy & Security.
Scroll to the Permissions section, locate Notifications, and select Settings.
Review the list of websites, select any unexpected or suspicious sites, and select Remove Website.
Safari Notification Audit
- Open Safari > click Safari in the menu bar > Settings
- Click the Websites tab
- Click Notifications in the left sidebar
- Review the list of sites and their permissions
- Select any suspicious site and change the permission to Deny or click Remove
Resetting User Profiles as a Last Resort
If standard remediation and settings resets fail to stop recurring scareware behavior, you can reset the browser user profile folder.
Warning: Deleting or renaming user data profile folders completely removes all saved browser settings, extensions, bookmarks, passwords, and browsing history. Perform this step only as a last resort.
Resetting Google Chrome User Data
Close all instances of Google Chrome.
-
Open File Explorer and navigate to the following directory:
C:\Users\<username>\AppData\Local\Google\Chrome\User Data Rename the
User Datafolder toUser Data.oldor delete the folder.Reopen Google Chrome to generate a fresh user profile.
Resetting Microsoft Edge User Data
Close all instances of Microsoft Edge.
-
Open File Explorer and navigate to the following directory:
C:\Users\<username>\AppData\Local\Microsoft\Edge\User Data Rename the
User Datafolder toUser Data.oldor delete the folder.Reopen Microsoft Edge to generate a fresh user profile.
Resetting Mozilla Firefox Profiles
Close all instances of Mozilla Firefox.
-
Open File Explorer and navigate to the following directory:
C:\Users\<username>\AppData\Roaming\Mozilla\Firefox\Profiles Rename or delete the target profile folder within the directory.
Reopen Mozilla Firefox to generate a fresh user profile.
Resetting Safari Profiles
If the steps above don't fully resolve the issue, deleting Safari's user profile will completely wipe all settings, extensions, history, saved passwords, and cached data, essentially returning the browser to a fresh install state. Only use this if other steps have failed.
Close Safari completely before deleting or renaming the folders. When reopened Safari will generate a fresh profile automatically.
-
Safari:
/Users/USERNAME/Library/Safari/
Also clear these additional locations for a clean slate:
/Users/USERNAME/Library/Caches/com.apple.Safari//Users/USERNAME/Library/WebKit//Users/USERNAME/Library/Cookies/Cookies.binarycookies
To access the Library folder:
Open Finder > click Go in the menu bar > hold Option key > Library
When To Contact Huntress Support
If scareware pop-ups persist across system reboots without opening a web browser, or if an end user downloaded and ran a file from the scareware page, open a ticket with Huntress Support.