free scan trap

The Free scan Antivirus trap

“Your computer is infected. Click here for a free scan.” It pops up out of nowhere — while you’re browsing, sometimes even when you’re not actively online — and it’s built to make you panic first and think second. That’s not an accident. It’s one of the most common online scams around, and it works precisely because it feels urgent. And AI is making impersonation of authentic products much more common. They’ll look like they’re from Microsoft/Apple/Google.

How the trap works

The pop-up mimics a real security warning, often copying the name, logo, and colour scheme of a well-known antivirus brand or even your operating system. It runs a “scan” that takes seconds and somehow finds dozens of infections. Then it pushes you toward one of two outcomes: pay immediately for “removal” software (handing over your card details to a scammer), or download the “scanner” itself — which is, ironically, the actual malware.

The Australian Competition and Consumer Commission’s Scamwatch has a standing warning about exactly this scam, and its advice is blunt: the software offered in these pop-ups often doesn’t work, or actively infects your computer with what it claims to remove.

Signs it’s fake, not a real alert

  • It doesn’t match antivirus you actually have installed, or it’s from software you never installed at all.
  • Extreme urgency — countdown timers, alarm sounds, “ACT NOW or lose all your files.”
  • A suspiciously fast, suspiciously thorough scan — dozens of “threats found” in a matter of seconds.
  • A phone number demanding you call immediately.
  • Small tells that don’t quite add up — odd phrasing, spelling mistakes, a logo that’s almost right but not quite.

One thing worth knowing going into 2026: these scams are getting harder to eyeball. Scammers are increasingly using AI to generate alerts that closely mimic the real styling of Microsoft, Apple, or Google, tailored to match your actual device. “It looked legitimate” isn’t a reliable test anymore — the behaviour (urgency, an unprompted pop-up, a demand to click or call) is a better tell than the appearance.

What to actually do if you see one

  • Don’t click anything on the pop-up — including the X to close it. Scamwatch specifically warns against this, since closing it the “normal” way can trigger more pop-ups or trigger a download.
  • Close the browser via your taskbar, or restart the device, rather than interacting with the alert at all.
  • Don’t call any number shown on the alert.
  • If you want to check, run a scan using antivirus software you already know and trust — not the one being offered to you.

A couple of names worth trusting

If you don’t already have something in place: Microsoft Defender is built into Windows and free, so most PCs already have a legitimate baseline without downloading anything extra. Malwarebytes is a well-regarded option many IT professionals use for on-demand scans and second opinions. Whatever you choose, go directly to the vendor’s official website by typing the address yourself — not through a link in a pop-up, email, or ad.

When the free tools aren’t enough

Where the free tools hit a ceiling is with anything that’s built to survive a standard scan. Some infections bury themselves in startup processes or reinstall on their own, and a straightforward scan-and-delete won’t catch that. A “0 threats found” result also isn’t proof the device is genuinely clean — it just means nothing matched what that particular tool was looking for.

The other gap is collateral damage. A scan can remove the infection itself without fixing what it changed along the way — corrupted system files, altered browser or network settings, or in a ransomware case, files that are still encrypted after the malware’s gone. Clearing the infection and restoring the device to how it actually should work are two different jobs.

So the practical version: run a scan with a tool you trust first. If it comes back clean but the same symptoms keep coming back, bite the bullet and get it looked at properly. Another scan will not help.

If you’ve already been caught out

  • If you entered card details, contact your bank straight away — they can watch for or block fraudulent charges.
  • If you downloaded and ran the “scanner,” stop using the device and disconnect it from the internet. Don’t try to fix it yourself from that point — get it looked at.
  • Change your passwords from a different, clean device if you’re not sure what the software may have captured.
  • You can also report the scam to Scamwatch, which helps track these patterns more broadly.

If you’ve clicked something you shouldn’t have, or your computer’s acting up after a pop-up like this, get it checked properly — assessments are generally $85.

Related Posts

Scroll to Top