Howgrewchi.live e-mail scam: how to spot it and what to do
You might come across Howgrewchi.live by accident while using Google Chrome, Mozilla Firefox, Microsoft Edge, or another internet browser. It has been linked to a variety of frauds, although it generally focuses on phony surveys, gift cards, and fake giveaways.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Do it yourself · free Remove Howgrewchi.live e-mail scam yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Howgrewchi.live e-mail scam: summary
| Distribution | Adware, redirects from other websites, malicious links |
|---|---|
| Name | Howgrewchi.live |
| Type | Scam, phishing, adware |
| Operation | Claims that the user has been selected for a free gift; those who proceed to reclaim the alleged gift are asked to provide personal details |
| Dangers | The objective of gift scams is typically to steal personal user information, but scammers might also lead users to harmful or inaccurate websites. This can result in privacy risks, virus infections, and financial losses |
| Symptoms | A phishing e-mail asking you to sign in |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 7 more facts
| Evidence | 4 write-ups by security sites; details still limited |
|---|---|
| Arrives as | |
| Pretends to be | A well-known company |
| Claim | Your account needs urgent attention |
| Asks for | Your password |
| First seen | 8 September 2022 |
| Facts checked | 7 October 2026 |
What the Howgrewchi.live e-mail scam e-mail looks like
You've made the 9.68-billionth search!
Congratulations! You are the lucky winner!
Every 10 millionth search is reached worldwide, we will proclaim a winner to send out a thank-you gift.
Please select your lucky prize below and claim it by following the instruction.
Is Howgrewchi.live e-mail scam dangerous? What the senders want
From our report of Sep 2022 · not reviewed since
Howgrewchi.live is a survey scam that seeks to gather user data for malicious purposes
You might come across Howgrewchi.live by accident while using Google Chrome, Mozilla Firefox, Microsoft Edge, or another internet browser.
It has been linked to a variety of frauds, although it generally focuses on phony surveys, gift cards, and fake giveaways. In other words, users are told that they can win a genuinely valuable gift by merely answering a few questions or by "selecting the box" from the three choices.
In reality, Howgrewchi.live does not have anything to win, as it is a scam. The main goal of the scammers is to convince people that they are the lucky ones, but when the time comes to retrieve the allegedly won prize, they would be asked to provide their personal details, which cybercriminals could later misuse.
Likewise, it is important to check the system for adware, as it may be the reason why you get redirected to phishing websites in the first place.


From our report of Sep 2022 · not reviewed since
How manipulation earns illegal money
Technical support scams succeed by taking advantage of people's fears.
They try to scam people by showing fave virus infection alerts or imitating official scan results of security software, only to offer the "solution" of calling the fake technical support number, where they are then convinced that they need to pay for the services provided.
Another common type of online fraud is the fake giveaway or gift card scam, which manipulates people's emotions and tries to get them to install phony security software or call the claimed tech support.
Happiness is another powerful human feeling that can cause excitement, and individuals may lose their heads when they are in this condition. The use of fake giveaways and gift cards to defraud people is one of the most widespread kinds of cybercrime out there.
Howgrewchi.live is a perfect example of such scamming attempts - it preys on gullible or vulnerable users who easily believe in actually being lucky. One of the best examples is the extremely popular "You've made the 9.68-billionth search!" scam (or its variations), which is hosted on numerous websites to this day - Spreadhugemultiply.xyz or Jsweepus.buzz are just a few examples.
As is common in social engineering attacks, users are shown logos of familiar companies - in this case, Google - and are told that they were lucky and they have already won:
They are then promised one of the expensive gifts, such as the newest iPhone, a smart TV, a gift card, or another valuable item. When users are convinced that they are lucky and about to receive a prize, they tend to forget what is actually happening and may even provide the information they are asked for.

From our report of Sep 2022 · not reviewed since
Stop redirects to Howgrewchi.live and similar sites
Adware is one of the main reasons for malicious ads and redirects, so it's important to be thorough in your checks.
Note that automatic removal with security software guarantees that your system is safe, so there's no need to use the manual steps listed below.
To thoroughly remove an unwanted app, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:
Adware might also get installed as a browser extension. Even though this software can't have high permissions on the system and is much less impactful as a result, there are plenty of malicious extensions that could be tied to a program installed on the system. So, it's crucial to remove all potentially malicious browser extensions.
It is easy to get rid of add-ons: all you have to do is click on the "Extensions" button next to the settings menu to the right of the URL bar. Then, select More Actions and click Uninstall/Remove.
Another crucial step toward recovery is to make sure that adware or other unknown parties do not collect information about you automatically. Trackers such as cookies may be utilized when you visit a website or download adware-type software to follow your online activities every time. To prevent this, we suggest cleaning your browser caches right away using . You can also take the manual actions below:
MS Edge (Chromium)
MS Edge (legacy)
- Enter Control Panel into the Windows search box and hit Enter or click on the search result.
- Under Programs, select Uninstall a program.
- From the list, find the entry of the suspicious program.
- Right-click on the application and select Uninstall.
- If User Account Control shows up, click Yes.
- Wait till the uninstallation process is complete and click OK.
- From the menu bar, select Go > Applications.
- In the Applications folder, look for all related entries.
- Click on the app and drag it to Trash (or right-click and pick Move to Trash)
- Select Go > Go to Folder.
- Enter /Library/Application Support and click Go or press Enter.
- In the Application Support folder, look for any dubious entries and then delete them.
- Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the related .plist files.
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.
- Click Menu and pick Options.
- Go to Privacy & Security section.
- Click on Clear Data...
- Select Cookies and Site Data, as well as Cached Web Content and press Clear.
- Click on Menu and go to Settings.
- Select Privacy and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Privacy & security.
- Under Clear browsing data, pick Choose what to clear.
- Select everything (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.
- Click Safari > Clear History...
- From the drop-down menu under Clear, pick all history.
- Confirm with Clear History.
- Press on the Gear icon and select Internet Options.
- Under Browsing history, click Delete...
- Select relevant fields and press Delete.
From our report of Sep 2022 · not reviewed since
Dangers of survey scams
Once users are hooked, they are ready to receive their prize, although it is not as simple as it may seem initially.
At this point, scammers come up with reasons for users to provide a lot of details they shouldn't need - at least they aren't needed to receive the item.
One of the most common details asked in survey scams is contact information (email, phone number). This information is later commonly used to push further scams, such as fraudulent calls. Additionally, email can be used to deliver all sorts of malware or direct people to spoofing websites to steal their credentials.
In other cases, Howgrewchi.live or any other website of this kind may ask for credit card details, usually with the pretense of "verification" or the charge for the alleged delivery fees. The main goal here is to make people provide these deals so they could be stolen and sold to cybercriminals, so please be wary of that.
What to do after the Howgrewchi.live e-mail
If you only received the message and clicked nothing, step 3 is all you need.
If you clicked the link or typed anything on the page it opened, do every step, starting with the password.
Step 1: Change the password you typed on the fake page
If you entered a password after clicking the link in the Howgrewchi.live message, treat that account as known to the sender.
Open the provider's real site by typing its address yourself, not through any link in the e-mail, and change the password there. Choose a new one you have never used before, and change it on every other account that shared the old one.
Then use the option to sign out of all other sessions or devices, if the provider has one. This works the same in any browser on Windows 11 and Windows 10.

Microsoft account, Security page (account.microsoft.com/security): Change password. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 2: Turn on two-step verification
Two-step verification asks for a code from your phone or an authenticator app whenever someone signs in from a new device. A stolen password alone is then not enough to open the mailbox.
Turn it on in the security settings of the e-mail account first, then for the bank, shop and social accounts that send their reset links to that address.
While you are there, check the recovery e-mail and phone number and the forwarding rules, which attackers sometimes change to keep access. The settings pages look the same on Windows 11 and Windows 10.

Microsoft account: Manage how I sign in, where two-step verification and the sign-in methods are. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 3: Report the e-mail and delete it
Report the message instead of only deleting it. In Outlook choose Report > Report phishing, in Gmail the three-dot menu > Report phishing; the provider then blocks the same message for other people.
Do not reply and do not click anything else in it. On a work account, forward it to your IT team as an attachment first. Web mail and the mail apps on Windows 11 and Windows 10 offer the same options.

New Outlook for Windows and Outlook on the web: Report > Report phishing. Full procedure with screenshots: Report a phishing e-mail
Step 4: Scan the PC if you opened a file from the message
A page that only asked for a password installs nothing, so most readers can skip this step.
If the Howgrewchi.live e-mail or the page it opened made you download or open a file, delete it and run a full scan, then a Microsoft Defender Offline scan.
In Windows 11 and Windows 10 open Windows Security > Virus & threat protection > Scan options, select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts and the scan takes about 15 minutes, so save your work first.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Access your website securely from any location
When you work on the domain, site, blog, or different project that requires constant management, content creation, or coding, you may need to connect to the server and content management service more often. The best solution for creating a tighter network could be a dedicated/fixed IP address.
If you make your IP address static and set to your device, you can connect to the CMS from any location and do not create any additional issues for the server or network manager that needs to monitor connections and activities. VPN software providers like can help you with such settings and offer the option to control the online reputation and manage projects easily from any part of the world.
Recover files after data-affecting malware attacks
While much of the data can be accidentally deleted due to various reasons, malware is one of the main culprits that can cause loss of pictures, documents, videos, and other important files.
More serious malware infections lead to significant data loss when your documents, system files, and images get encrypted. In particular, ransomware is is a type of malware that focuses on such functions, so your files become useless without an ability to access them.
Even though there is little to no possibility to recover after file-locking threats, some applications have features for data recovery in the system. In some cases, can also help to recover at least some portion of your data after data-locking virus infection or general cyber infection.
Questions about Howgrewchi.live e-mail scam
Can reading "You've made the 9.68-billionth search!" infect my computer?
Reading it cannot. An e-mail is text and pictures, and current versions of Outlook, Gmail and other web mail services do not run code from a message just because you opened it. What can cause harm is an action:
- signing in on the page the link opens
- opening an attachment
- enabling macros in a document
The message "You've made the 9.68-billionth search!" was built to lead you to one of those steps. If you stopped at reading, delete it and use the report button so the provider can block the same wave for others. Nothing needs to be removed from Windows.
I typed my password after "You've made the 9.68-billionth search!". What now?
Act within the hour. From another device, open the real site of the account the message "You've made the 9.68-billionth search!" imitated and change the password. If the same password is used anywhere else, change it there too.
Sign out of all other sessions, check the recovery e-mail and phone number, and look for mail forwarding rules or filters you did not create. Then turn on two-step verification with an authenticator app or a passkey.
If the fake page also asked for a card number or a bank login, call your bank and ask them to block the card. Finally, report the e-mail so others are warned.
Is Howgrewchi.live really from a well-known company?
No. It is sent by scammers who copy the name and look of a well-known company. The sender address and the links do not belong to it, and the message asks for your password, which a real company does not request through an unexpected message.
If you want to be sure about your account, open the website or app of a well-known company the way you normally do, not through the message, and look for notices there. Then delete the message and report it as phishing. If you already followed its instructions, use the steps in this guide for your case.
Is it true that your account needs urgent attention?
No. The claim that your account needs urgent attention is the hook of Howgrewchi.live, invented to give you a reason to act quickly. Scammers pick a story that could plausibly apply to many people, so it may feel relevant to you, but nothing in the message is based on your real accounts or devices.
If the claim concerns a service you use, check it there directly, by opening the website or app yourself. You will find no such problem. Then delete the message and report it as phishing.
What happens if I do what Howgrewchi.live asks?
The scammers get your password, and they use it quickly. Passwords are tried on the real service within minutes, cards are charged or added to phone wallets, remote access is used to open your bank, and crypto is moved on at once.
Documents surface later as accounts in your name. If you already did what the message asked, do not wait to see what happens; follow the steps in this guide for your case today. Speed matters more than anything else here.
Will a well-known company refund me if I fell for Howgrewchi.live?
A well-known company did not send the message and is not responsible for it, so a refund usually comes from your bank or card issuer, not from the brand. Call the bank first if you paid.
It still helps to tell the real company: they can secure your account, add notes for their fraud team and take down pages that use their name. Contact them through their official website or app only, never through the message or a search ad. Keep the message as evidence.
How can I spot messages like Howgrewchi.live in future?
Check the sender's actual address, not only the name. Hover over links before clicking and compare the domain with the real one. Be suspicious of urgency, threats, prizes, unexpected invoices and requests for passwords, codes, card data or crypto.
Do not call phone numbers from unexpected messages; use the number on the official site or your card. When in doubt, go to the service directly through its app or a bookmark. Phishing protection and two-step verification limit the damage when a scam gets through.
How quickly do scammers use a phished password?
Often within minutes. Phishing kits send each password to the operators as soon as it is typed, and many test it automatically on the real service. Some kits also pass the two-step code through in real time.
That is why the first hour matters: change the password, end all sessions and check that the recovery details are still yours. If nothing has changed by then, you were probably fast enough, but keep watching for login alerts and password-reset e-mails for a few weeks.
How do I report Howgrewchi.live to my mail provider?
Use the built-in button. In Outlook, select the message and choose Report > Report phishing. In Gmail, open the message, click the three-dot menu and choose Report phishing.
Scam text messages can be forwarded to your carrier's spam number, which is 7726 in the US and the UK.
On social networks, use the report option on the message or the profile. Reporting trains the filters that protect you and other users, and it takes a few seconds. Then delete the message.
Will Fortect remove Howgrewchi.live?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Howgrewchi.live, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Imperva: Phishing attacks (read October 7, 2026)
- Wikipedia: Technical support scam (read October 7, 2026)
- Imperva: Social Engineering (read October 7, 2026)
- FTC: How to recognize and avoid phishing scams (read October 7, 2026)
- CISA: Recognize and report phishing (read October 7, 2026)