What Is Scareware? The One Fact That Settles Every Fake Virus Alert
Scareware does not break into anything. It persuades you to open the door yourself, by showing you an emergency that is not happening.
The usual advice is a list of warning signs to memorise - misspellings, urgency, odd logos. That advice is fine and it is also more work than the problem needs, because there is a single technical fact that settles the whole category.
The fact that settles it
A web page cannot scan your computer.
This is not a matter of degree or of how good the scam is. A page running in a browser tab is sandboxed: it has no access to your file system, your running processes, your drives or your antivirus. It cannot count your infections because it cannot see that anything exists.
So any alert that appears inside a browser tab and claims to have found viruses on your machine is false by construction. Not suspicious - false. It did not find anything, because it could not look. It is a picture of a scan.
That one fact identifies every variant without your having to recognise which variant it is.
What real alerts look like instead
Genuine warnings come from software you installed, and they behave like software:
- They appear in the antivirus program’s own window or in a system notification, not in a web page.
- They name a file and a path, because they actually found one.
- They offer to quarantine or remove it, from within the product.
- They never ask you to telephone anyone, and they never demand an immediate payment to clean the machine.
A real security product has already been paid for and already has access. It has no reason to put you on the phone.

The three things it is trying to get
Scareware is a delivery method rather than a single scam. The fear is the same; what it is fishing for differs.
Money for software that does nothing. The oldest form: a rogue security product with a convincing name that reports dozens of infections and asks for a licence to remove them. It removes nothing, because it found nothing. Some variants also disable the real antivirus so their own alerts are the only ones you see.
A phone call. The alert freezes your browser, plays an alarm sound and displays a support number. There is no support. The person who answers wants remote access to your machine, and once they have it they will show you routine system logs as evidence of catastrophe, then charge for a fix. This one is the most damaging, because the machine really is compromised at the end of it - by you having granted access.
An installation. The alert offers a free scanner or a required update. What arrives is the actual malware, and the fake alert was only the pretext.
Why the pop-up will not close
Part of the effect comes from a browser trick rather than an infection. A page can open a dialog in a loop, so dismissing it produces another. It can go full screen and draw a fake browser interface, so the close button you are clicking is a picture. It can play audio you cannot find the tab for.
None of that means the machine is infected. It means a tab is misbehaving, and a tab can be ended.
Close the browser at the process level: Task Manager on Windows (Ctrl + Shift + Esc), Force Quit on macOS. Do not click anything in the page first, including its close button. When the browser reopens, decline any offer to restore the previous session, or you will restore the page too.
If you already engaged
The honest answer depends on how far it went, and the difference matters.
You only saw the page and closed it - nothing happened. A page you looked at is not an infection. No scan needed, though running your existing antivirus costs nothing if it settles your mind.
You installed what it offered - that is a real infection now, and it is treated as one: remove the malware from Windows or from Mac, with a scan from a product you chose yourself rather than one the alert suggested.
You called the number and gave remote access - assume everything on that machine was readable while they were connected, and act on that rather than on what they told you they did. Change the passwords that matter, from a different device, starting with email, because email resets everything else. If you were talked into a payment, contact your bank; if remote-access software was installed, remove it.
The short version
Scareware works by making you act before you think, so the defence is one fact you can recall while the alarm is sounding: a web page cannot see your computer. Whatever it claims to have found, it did not find it.
Close the tab at the process level, do not call the number, and treat only what you actually installed or authorised as a real incident. If you are unsure whether something on the machine is genuine, the calmer route is the checklist in how to know if your computer has a virus - which relies on what the system tells you, not on what a page claims.