Four virus: what it is and how to remove it
Four virus is a scam stating that the user's computer system is heavily damaged. The deceptive message can appear on multiple platforms, including computers, smartphones, and tablets.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If Four virus keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove Four virus yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Four virus: summary
| Detection names | No Microsoft detection name is known |
|---|---|
| Distribution | Not recorded in the old report |
| Damage | Not recorded in the old report |
| Name | Four virus |
| Type | Adware extension |
| Symptoms | An unknown program in Installed apps |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 4 more facts
| Evidence | 4 write-ups by security sites; details still limited |
|---|---|
| Program | Four virus |
| First seen | 4 March 2021 |
| Facts checked | 7 October 2026 |
Is Four virus dangerous?
From our report of Mar 2021 · not reviewed since
Four virus is a fake warning used to scare users to make them download useless software
Four virus is a scam stating that the user's computer system is heavily damaged.
The deceptive message can appear on multiple platforms, including computers, smartphones, and tablets. Similarly to Android virus and iPhone virus, it displays questionable notifications with the help of adware installed on the system without the user's interaction.
Adware, which is also considered the potentially unwanted program, can equally hijack Safari, Chrome, Firefox and or another browser. As a result, the victim is redirected to scam websites shouting out: Your system is heavily damaged by (4) virus.
By using malicious social engineering, the authors of Four virus scam are trying to make users install questionable software on their machines, pay for useless services, or disclose their sensitive information. As you can see, it is a highly dangerous warning that you should not interact with.
Regardless of the motive, the scam changes the frequency of its appearance, the browser it keeps reappearing and similar factors. The fraction of Four virus warning delivered by one of its versions reads the following:
Note that you should never trust the fake virus alert since it might trick you into downloading more potentially unwanted programs or even malware. Victims report being offered to get a "trustworthy" security software to get rid of (4) virus. However, this is the way how criminals promote less than reliable programs or distribute malware.
Additionally, there is a serious risk of being tricked into revealing your personal information, such as:
Finally, you might be redirected to "Your system is heavily damaged by (4) virus" warning by a suspicious website. Therefore, we strongly suggest you to avoid visiting shady pages since this is one of the ways how you might be tricked by hackers into manually infecting your system. Please, ignore this scam and remove Four virus from your system immediately.
If you have encountered the Four virus warning on iPhone or computer, close the tab or window immediately. If you are blocked, cancel the browser's task and you should eliminate this warning. Note that this is only a temporary solution to get rid of the alert, although it will protect you from installing various other potentially unwanted programs or dangerous cyber threats on your system.
Later, you must remove virus by uninstalling the adware program which is the cause why you keep receiving such fake alerts. Unfortunately, ad-supported software often has numerous extra components that are hidden deep inside your system. So, it might be challenging to identify and eliminate them all.
Either employ or another reliable security software to uninstall the adware for good. Additionally, you will find guidelines showing how to reset your browser settings to finish the removal procedure.
- full name
- home address
- social security number
- bank account details


From our report of Mar 2021 · not reviewed since
Your Computer is heavily damaged by (4) virus
This scam appears directly in the browser, with the tab name "VIRUS FOUND!" and Google logo present.
Obviously, the URL is spewing out fakery, but the content of the message might get users confused. It warns that victims' machine is heavily damaged and needs to be repaired using PCKeeper or similar useless program. It also explains that users only have few minutes to do so - otherwise, photos, contacts and other data will get deleted.
That is not how malware works. Legitimate anti-virus software would immediately flag up the threat, but would not require you to download anything. What is more, the message would not randomly appear on your browser. Unfortunately, there quite a significant amount of individuals who are not familiar with virus operation, and might believe scams like this.

From our report of Mar 2021 · not reviewed since
Your system is heavily damaged by (4) virus!
Your system is heavily damaged by (4) virus! fake error message that users can encounter when they get rerouted from a questionable website, as well as adware, could be causing these redirects. The tab name shows "Windows" written on it, as well as displays the fake message. Additionally, users may sometimes encounter a pop-up accompanying the web page, which displays the exact copy of the original message.
Users are then prompted to install suspicious software on their devices (accordingly, victims are urged to download apps from Google Play on their phones). In some cases, the virus picks up the information of the device (for example, Samsung Galaxy S6) to make the scam more believable. As usual, users should ignore this message and remove Your system is heavily damaged by (4) virus! fake alert from their systems.
From our report of Mar 2021 · not reviewed since
Your Windows Computer Is Infected With (4) Viruses
Your Windows Computer Is Infected With (4) Viruses is targeting individuals who use Windows operating systems.
This time, crooks use official Windows and Microsoft logos to convince users about message legitimacy. The questionable URL is displayed on a tab named "Scanner."
The fake alert informs users that "a pre-scan" found traces of malware, as well as phishing and spyware. It is ironic because the message itself is a phishing attack. What is more, victims are more likely to proceed when they see that their passwords and other data might be stolen.
Nevertheless, never believe any warnings that come from a browser, unless it is a legitimate one. To make sure it is real - check the URL of the tab, and it is usually all it takes to realize that the message is bogus. Beware that cybercriminals might create domain names which are very similar to original ones, for example, microsoft- .com.

From our report of Mar 2021 · not reviewed since
You can let PUPs inside your system during the installation of freeware
As we have already mentioned, "Your system is heavily damaged by (4) virus!" ads are delivered by an adware program.
This software is one of the many that are classified as potentially unwanted programs and distributed via popular marketing technique called bundling. In other terms, it is stealthily installed on your computer during the installation procedure of free applications.
Note that such a distribution method is legal, yet unfair. If you pick Quick or Recommended settings during the process the information about adware will be hidden, and you will end up installing it on your system. For this reason, we suggest you protect your system by ALWAYS choosing the Advanced or Custom mode.
Once you proceed with the installation, attentively follow each step and search for any suspicious offers to install unknown programs. If you find any, de-select the checkmarks granting your permission to install them and check your system for PUPs with professional security software.
From our report of Mar 2021 · not reviewed since
More from our earlier report on Four virus
- Installation of bogus software, stolen or uselessly spent money, injection of other PUPs or even malware, personal data disclosure
- Aggressive ads popping out of nowhere, redirects leading to questionable realms, propagation of bogus software installation, etc.
- We have detected that your Windows 7 is 28.1% DAMAGED because of (4) harmful viruses from recent adult sites, If you do not remove the virus now, it will cause permanent damage to your system, corrupt your photos, data, applications, etc.
- Here's what you NEED to do (step by step): Step 1: Tap the button and install PC SmartCIeanup for free now!
- Step 2: Open the app to fix your system now!
- As usual, crooks are trying to scare users into downloading questionable software by adding a timer, as well as using attributes of legitimate (security) companies - Microsoft, Norton, McAfee, etc.
How Four virus got into your browser
From our report of Mar 2021 · not reviewed since
There are three different variants of Four virus.
Each version differs very minimally, including the name, modifications in the message itself, as well as different logos and icons used (crooks are using branding of legitimate companies, such as Microsoft or Google). However, all of them have the same goal - to gain monetary benefit one way or another.
How to remove Four virus
How to remove the Four virus extension
Do the browser steps in every browser and profile on the PC, then check Windows for the program that installed the extension.
Step 1: Remove extensions you did not add
Four virus often works through an extension, so go through the extension list of each browser:
chrome://extensionsedge://extensions- Extensions and themes in Firefox
Switch suspicious extensions off one at a time and reload the page where the problem shows, then remove the one that stops it, and any other you did not add.
Remember the other browsers and profiles on the PC. If Remove is missing or greyed out, a policy forces the extension, which the policy step deals with. Windows 11 and Windows 10 show the same pages.

Chrome on Windows 11: More > Extensions > Manage extensions. Full procedure with screenshots: Remove a browser extension
Step 2: Uninstall Four virus
Open Settings > Apps > Installed apps in Windows 11, or Settings > Apps > Apps & features in Windows 10. Sort the list by install date and find Four virus, then choose Uninstall from the three-dot menu next to it (in Windows 10, click the entry and then Uninstall).
Remove anything else installed on the same day that you do not recognise, because such programs usually arrive together in one installer. If the uninstaller opens a browser page with an offer or a survey, close it: the program is removed either way.
Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix
Step 3: Reset the browser
Finish the browser part with a reset, which puts the search engine, start page, new tab page and site permissions back to their defaults and switches extensions off. Chrome: Settings > Reset settings > Restore settings to their original defaults.
Edge: Settings > Reset settings. Firefox: Help > More troubleshooting information > Refresh Firefox, which also removes its extensions. Your bookmarks and saved passwords are kept, and the menus are the same on Windows 11 and Windows 10.

Chrome on Windows 11: Settings > Reset settings. Full procedure with screenshots: Reset a browser and fix a hijacked search engine
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Uninstall from Windows
If an adware program is present on your windows system, you must remove it together with additional components.
Uninstall from Windows 10/8:
- Type Control Panel into the Windows search box and open the result.
- Under Programs, select Uninstall a program.

Uninstall from Windows 7/XP:
- Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
- In Control Panel, select Programs > Uninstall a program.

Remove the unwanted program:
- In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
- If User Account Control appears, click Yes to confirm, then complete the removal.

Remove from Google Chrome
You can fix Chrome by deleting suspicious plug-ins and extensions which are disrupting your browser's activity.
Delete malicious extensions from Google Chrome:
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.

Clear cache and web data from Chrome:
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.

Change your homepage:
- Click menu and choose Settings.
- Look for a suspicious site in the On startup section.
- Click on Open a specific or set of pages and click on three dots to find the Remove option.
Reset Google Chrome:
If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:
- Click on Menu and select Settings.
- In the Settings, scroll down and click Advanced.
- Scroll down and locate Reset and clean up section.
- Now click Restore settings to their original defaults.
- Confirm with Reset settings.

Remove from Microsoft Edge
Delete unwanted extensions from MS Edge:
- Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
- From the list, pick the extension and click on the Gear icon.
- Click Remove.

Clear cookies and other browser data:
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
- Under Clear browsing data, pick Choose what to clear.
- Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.

Restore new tab and homepage settings:
- Click the menu icon and choose Settings.
- Then find On startup section.
- Click Remove next to any suspicious startup page.
Reset MS Edge if the above steps did not work:
- Press on Ctrl + Shift + Esc to open Task Manager.
- Click on More details arrow at the bottom of the window.
- Select Details tab.
- Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.

Delete extensions from MS Edge (Chromium):
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.

Clear cache and site data:
- Click on Menu and go to Settings.
- Select Privacy, search and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.

Reset Chromium-based MS Edge:
- Click on Menu and select Settings.
- On the left side, pick Reset settings.
- Select Restore settings to their default values.
- Confirm with Reset.
- This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.

Remove from Mozilla Firefox (FF)
Remove dangerous extensions:
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- In here, select the unwanted extension and click Remove.

Reset the homepage:
- Click three horizontal lines at the top right corner to open the menu.
- Choose Settings.
- Under Home, set your preferred homepage and new tab settings.
Clear cookies and site data:
- Click Menu and pick Settings.
- Go to Privacy & Security section.
- Scroll down to locate Cookies and Site Data.
- Click on Clear Data...
- Select Cookies and Site Data and Temporary cached files and pages, then click Clear.

Reset Mozilla Firefox
If clearing the browser as explained above did not help, reset Mozilla Firefox:
- Open Mozilla Firefox browser and click the Menu.
- Go to Help and then choose Troubleshooting Information.

- Under Give Firefox a tune up section, click on Refresh Firefox...
- Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.

Delete from Safari
Remove dangerous extensions:
- Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
- Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.

Clear history and website data:
- Click Safari in the menu and pick Clear History.
- Set Clear to all history and confirm with Clear History.

Reset Safari:
- Click Safari in the menu and select Preferences > Advanced.
- Enable Show Develop menu in menu bar.
- From the menu bar, click Develop and select Empty Caches.

Delete from macOS
In case you encounter Four virus message on Mac, search for and uninstall the adware.
Remove the unwanted application:
- From the menu bar, select Go > Applications.
- In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).

Delete leftover files and folders:
- Select Go > Go to Folder.
- Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
- Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.

- Finally, empty the Trash to permanently remove the leftovers.
Do not let government spy on you
The government has many issues in regards to tracking users' data and spying on citizens, so you should take this into consideration and learn more about shady information gathering practices.
Avoid any unwanted government tracking or spying by going totally anonymous on the internet.
You can choose a different location when you go online and access any material you want without particular content restrictions. You can easily enjoy internet connection without any risks of being hacked by using VPN.
Control the information that can be accessed by government any other unwanted party and surf online without being spied on. Even if you are not involved in illegal activities or trust your selection of services, platforms, be suspicious for your own security and take precautionary measures by using the VPN service.
Backup files for the later use, in case of the malware attack
Computer users can suffer from data losses due to cyber infections or their own faulty doings.
Ransomware can encrypt and hold files hostage, while unforeseen power cuts might cause a loss of important documents. If you have proper up-to-date backups, you can easily recover after such an incident and get back to work. It is also equally important to update backups on a regular basis so that the newest information remains intact - you can set this process to be performed automatically.
When you have the previous version of every important document or project you can avoid frustration and breakdowns. It comes in handy when malware strikes out of nowhere. Use for the data restoration process.
From our report of Mar 2021 · not reviewed since
Four virus removal from iPhone and Android
According to experts, to remove Four virus from Android and iPhone, you should start by canceling the web browser completely.
If the scam does not disappear from your browser, reset the Android device completely by following these guidelines:
iPhone instructions to get rid of the fake pop-up message are provided below:
Do not deal with this scam! We guarantee you that you will either be tricked to download expensive and ineffective antivirus or even lured to infiltrate malware.
- Click the Settings icon on your device. You can find it among other apps;
- Select Privacy (or Personal) and Factory reset (you can also find it as Factory data reset, Backup & reset, etc.);
- Click Reset device to remove Four virus completely.
- Go to Settings;
- Navigate to General;
- Tap on Erase All Contents option.
From our report of Mar 2021 · not reviewed since
Removing Four virus from Windows and Mac
To ensure removal from Windows, download professional and expert-tested software.
You can find our top picks listed down below. Shortly after, you will no longer receive fake alerts during your browsing sessions.
Additionally, there is a way to get rid of Four virus by following the manual elimination guidelines given below. However, this method requires you to be an experienced computer user in order to complete the removal procedure correctly and avoid system damage.
From our report of Mar 2021 · not reviewed since
Four virus termination steps in video format
Our team is always looking for ways how to help users understand important virus elimination steps as clear as possible.
This time, we added a short video to guide you through the entire removal process and help you delete Four virus from the affected operating system and hijacked browsers (Chrome, Firefox, Edge, Explorer, Safari).
Questions about Four virus
What is Four virus and why is it on my PC?
Four virus is a program that was installed on the PC, most likely together with something else you downloaded. Free software sites and many installers add extra programs on setup pages with pre-ticked boxes, so the extra install looks like your choice even though nobody read the page.
Check the install date in Settings, Apps, Installed apps: the program you installed that day is the probable carrier. If you do not need Four virus, uninstall it. If it belongs to your hardware or to a program you use, search its exact name and publisher first, because drivers and their tools can have unfamiliar names.
How do I stop programs like Four virus from being installed again?
Most unwanted programs arrive through installers, so the fix is in how you install software. Download programs from their official sites or the Microsoft Store, not from download portals or ads above search results. During setup, choose Custom or Advanced installation and untick every extra offer, including browsers, toolbars and optimizers.
Decline update prompts that appear inside other programs unless you know them. In Windows Security, turn on reputation-based protection and potentially unwanted app blocking. These steps would most likely have stopped Four virus before it reached the app list.
Did Four virus collect my data?
Adware typically collects what it needs to choose ads:
- the sites you visit
- search terms
- approximate location
- browser and system details
Extensions with permission to read and change data on all websites can technically see everything on those pages, including forms. That is a privacy problem rather than proof of theft.
If you typed card details or passwords while it was active, changing the most important passwords is a reasonable precaution. Clearing cookies after removal ends the tracking sessions it may have started.
Can an adware pop-up infect my PC just by appearing?
No. A pop-up, a notification or a new tab is only a web page or a message. It cannot run programs on Windows by itself, provided the browser and Windows are up to date. Infection needs a step from you:
- running a downloaded file
- installing an extension
- giving a stranger remote access
That is why scam pages work so hard to make you click. Close such pages with the tab's X or by closing the browser, not with buttons inside the page, which may start a download.
I let a "support technician" from an ad connect to my PC. What should I do?
Act quickly but calmly. Disconnect the PC from the internet first, so the connection ends. Uninstall the remote access tool they asked you to install and check Installed apps for anything else added during the call.
Run a Microsoft Defender full scan and offline scan. From another device, change your e-mail and banking passwords and sign out of all sessions.
If you paid by card, bank transfer or gift card, contact your bank or the card issuer immediately, and report the scam to the police. Do not answer if they call back.
Why is my browser so slow since the ads started?
Each page now does extra work. An adware extension reads the page, decides where to put ads, loads them from ad servers and reports your visit, and that happens on every tab. Ad-supported programs add their own background activity.
Removing the extension or program usually makes the browser fast again at once. If it stays slow, open the browser's own task manager with Shift+Esc in Chrome or Edge and look for extensions using a lot of memory or processor time.
My scan found nothing, but the ads continue. Why?
Because the source may not be a file a scanner looks for. Browser notifications are a permission stored in the browser, and many adware extensions are not flagged because they come from an official store.
Some ad-supported programs are only reported if you enable detection of potentially unwanted apps. So a clean scan does not mean the job is done. Check each browser's notification permissions and extension list by hand, and turn on Potentially unwanted app blocking in Windows Security before scanning again.
Do I need to reset my browser after removing Four?
A reset is a good last step, because it undoes settings that the program changed. A reset restores the home page, new tab page and default search engine, and turns off extensions.
It does not delete your bookmarks or saved passwords in the main browsers. Add back only the extensions you trust, one at a time.
Will Fortect remove Four virus?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Four virus, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Wikipedia: Adware (read October 7, 2026)
- Google Chrome Help: Use notifications to get alerts (no longer online) (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 7, 2026)
- Microsoft Learn: How Microsoft names malware (read October 7, 2026)