A web page that says FIVE VIRUSES DETECTED has already accomplished one thing.
It made the browser look like a security product.
Microsoft documents tech-support scam pages that display fake error messages, switch the browser into full-screen mode, trap users in repeated pop-ups, and present a phone number for supposed technical help.
The important clue is that the warning is coming from the page, not from the security product it claims to represent.
See Microsoft’s guidance on tech-support scams.
A claim of a scan is not evidence of a scan
A deceptive page can put almost anything on the screen: a progress bar, a list of infected files, a familiar antivirus logo, flashing red borders, siren sounds, or a percentage counter labeled Scanning....
Those graphics prove that the webpage can draw graphics.
They do not prove that the named antivirus company inspected the computer and found the threats listed on the page.
Microsoft makes one particularly useful distinction: genuine Microsoft error and warning messages do not include phone numbers telling users to call support.
That simple rule breaks a large family of scare pages.
Leave the page before diagnosing the machine
If a browser page suddenly announces a severe infection, do not use the page itself as the route to diagnosis.
Close the tab or browser. If the page has trapped the browser in full screen or repeated dialogs, use the operating system to close the browser rather than clicking buttons inside the warning. Then open the security software already installed on the machine and run its normal scan or update process.
Microsoft also recommends downloading software only from official vendor sites or trusted application stores rather than from links supplied by the warning.
See Microsoft’s Defender guidance on support-scam pages.
A real security alert can certainly be urgent.
The difference is authority.
Your installed antivirus, operating system and browser have defined ways to report danger. A random page that suddenly claims to represent one of them is merely a page until independently verified.
The scareware trick is to collapse those two things into one.
It wants the message about your security software to be mistaken for a message from your security software.
