Papcorwye.live e-mail scam: how to spot it and what to do

Papcorwye.live is a bogus website designed by crooks to look like a Chrome giveaway. Supposedly, users are chosen by Chrome as lucky visitors who made the 5-billionth search and are eligible to win a prize.

Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Papcorwye.live e-mail scam yourself 4 steps, about 12 minutes, no software needed.

Start the steps
Screenshot of Papcorwye.live: papcorwye live
Papcorwye.live as our 2022 report showed it.

Papcorwye.live e-mail scam: summary

DistributionThe appearance of this scam page might indicate adware infection; users can also stumble upon such sites accidentally
NAMEPapcorwye.live
TYPEPhishing attempt; scam
SYMPTOMSA page appears claiming that the visitor is a 5-billionth Chrome visitor who can receive a prize
DANGERSPeople can be tricked into providing personal information which could lead to monetary losses or even identity theft
NamePapcorwye.live
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
TypePhishing message
SymptomsA phishing e-mail asking you to sign in
Evidence4 write-ups by security sites; details still limited
Arrives asE-mail
Pretends to beA well-known company
ClaimYour account needs urgent attention
Asks forYour password
First seen13 September 2022
Facts checked7 October 2026

What the Papcorwye.live e-mail scam e-mail looks like

What a phishing e-mail asking you to sign in said

a phishing e-mail asking you to sign in

You've made the 5-billionth search.

Congratulations! You may be our next lucky winner!

Our last winner was Brad Jenkins from London who won Samsung KU6179 Ultra HD TV on 14.05.2019 with his 5-billionth Search.

Every time the 5-billionth search is reached, we proclaim a winner and reset the counter.

You may choose one of three hidden prizes below. In addition, you will be entered in our Hall of Fame and receive a winner's certificate.

Behind every box is a prize. Click on a box to uncover it.

For technical reasons, we are not allowed to keep your invitation open for more than 15 minutes.

Choose one of the prizes below and follow the instructions on your screen.

From our report of Sep 2022 · not reviewed since

Distribution methods

Scam sites, like Papcorwye.live rarely appear in the search results.

Usually, they appear seemingly out of nowhere while browsing the web. That is because most of the time they are hidden behind deceptive ads and sneaky redirects on other shady websites.

Do not click on random links and ads even if they seem to be promoting legitimate products and services. Crooks can use social engineering and impersonate well-known brands.

Papcorwye.live: papcorwye live ads
Papcorwye.live in our 2022 report.

How to tell the Papcorwye.live e-mail scam e-mail is fake

From our report of Sep 2022 · not reviewed since

Papcorwye.live is a page designed by crooks that looks like a Chrome giveaway

Papcorwye.live is a bogus website designed by crooks to look like a Chrome giveaway.

Supposedly, users are chosen by Chrome as lucky visitors who made the 5-billionth search and are eligible to win a prize. The full message reads as follows:

The main goal of such deceptive websites is to extract personal information. After users click on a gift box and supposedly win a phone, TV, or another tech prize, they may be asked to enter their details or pay for shipping costs.

The page might ask to provide a name, address, email, phone number, or credit card details. Falling for this type of scam may result in monetary losses or even identity theft.

When browsing the web, it is important to not lose your head. If it seems too good to be true - it probably is. Big tech companies like Google or Apple do not choose random Internet users and shower them with gifts. It is best not to interact with such sites at all.

Screenshot of Papcorwye.live: papcorwye live
Papcorwye.live in our 2022 report.

From our report of Sep 2022 · not reviewed since

More from our earlier report on Papcorwye.live

  • Check your system for adware with professional security tools

What to do after the Papcorwye.live e-mail

If you only received the message and clicked nothing, step 3 is all you need.

If you clicked the link or typed anything on the page it opened, do every step, starting with the password.

  1. Step 1: Change the password you typed on the fake page

    If you typed a password on the page the Papcorwye.live message opened, assume the sender has it. Go to the real site by typing its address yourself and change the password there, choosing one you have never used.

    Change it anywhere else the same password was used, and sign out all other sessions if the service offers it. Any browser on Windows 11 or Windows 10 will do, as long as you do not follow the e-mail's link.

    Microsoft account Security page with Change password at the top
    Microsoft account, Security page (account.microsoft.com/security): Change password.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

  2. Step 2: Turn on two-step verification

    With two-step verification on, a stolen password alone no longer opens the account, because a sign-in from a new device also needs a code from your phone.

    Switch it on for the e-mail account first, then for banking, shopping and social accounts that use that address.

    Check the recovery phone, the recovery e-mail and any forwarding rules while you are in the settings, since attackers change them to come back. The pages are the same on Windows 11 and Windows 10.

    Microsoft account Manage how I sign in page with the sign-in methods
    Microsoft account: Manage how I sign in, where two-step verification and the sign-in methods are.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

  3. Step 3: Report the e-mail and delete it

    Do not reply and do not click anything else in the message. In Outlook select the e-mail and choose Report > Report phishing; in Gmail open the three-dot menu next to Reply and pick Report phishing.

    That trains the filter for everyone on the service, and the message goes to the junk folder. If the e-mail came to a work address, forward it to your IT team as an attachment first.

    The steps are the same in the web mail and the mail apps on Windows 11 and Windows 10.

    Outlook Report menu with Report phishing selected
    New Outlook for Windows and Outlook on the web: Report > Report phishing.

    Full procedure with screenshots: Report a phishing e-mail

  4. Step 4: Scan the PC if you opened a file from the message

    A fake sign-in page only steals what you type, so most readers can skip this step. If the Papcorwye.live e-mail made you download or open a file, delete it and scan the PC.

    In Windows Security > Virus & threat protection > Scan options, run a Full scan and then Microsoft Defender Antivirus (offline scan) > Scan now. The offline scan restarts Windows 11 or Windows 10 and takes about 15 minutes.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Instructions for each browser and system

The detailed steps for every browser and system this guide covers. Open the one you use.

Remove from Microsoft Edge

Delete unwanted extensions from MS Edge:

  1. Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  2. From the list, pick the extension and click on the Gear icon.
  3. Click Remove.Remove extensions from Edge

Clear cookies and other browser data:

  1. Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
  2. Under Clear browsing data, pick Choose what to clear.
  3. Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.Clear Edge browsing data

Restore new tab and homepage settings:

  1. Click the menu icon and choose Settings.
  2. Then find On startup section.
  3. Click Remove next to any suspicious startup page.

Reset MS Edge if the above steps did not work:

  1. Press on Ctrl + Shift + Esc to open Task Manager.
  2. Click on More details arrow at the bottom of the window.
  3. Select Details tab.
  4. Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.Reset MS Edge
Instructions for Chromium-based Edge

Delete extensions from MS Edge (Chromium):

  1. Open Edge and click select Settings > Extensions.
  2. Delete unwanted extensions by clicking Remove.Remove extensions from Chromium Edge

Clear cache and site data:

  1. Click on Menu and go to Settings.
  2. Select Privacy, search and services.
  3. Under Clear browsing data, pick Choose what to clear.
  4. Under Time range, pick All time.
  5. Select Clear now.Clear browser data from Chroum Edge

Reset Chromium-based MS Edge:

  1. Click on Menu and select Settings.
  2. On the left side, pick Reset settings.
  3. Select Restore settings to their default values.
  4. Confirm with Reset.
  5. This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.Reset Chromium Edge
Remove from Mozilla Firefox (FF)

Remove dangerous extensions:

  1. Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  2. Select Add-ons.
  3. In here, select the unwanted extension and click Remove.Remove extensions from Firefox

Reset the homepage:

  1. Click three horizontal lines at the top right corner to open the menu.
  2. Choose Settings.
  3. Under Home, set your preferred homepage and new tab settings.

Clear cookies and site data:

  1. Click Menu and pick Settings.
  2. Go to Privacy & Security section.
  3. Scroll down to locate Cookies and Site Data.
  4. Click on Clear Data...
  5. Select Cookies and Site Data and Temporary cached files and pages, then click Clear.Clear cookies and site data from Firefox

Reset Mozilla Firefox

If clearing the browser as explained above did not help, reset Mozilla Firefox:

  1. Open Mozilla Firefox browser and click the Menu.
  2. Go to Help and then choose Troubleshooting Information.Reset Firefox 1
  3. Under Give Firefox a tune up section, click on Refresh Firefox...
  4. Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.Reset Firefox 2
Delete from Safari

Remove dangerous extensions:

  1. Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
  2. Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.Remove extensions from Safari

Clear history and website data:

  1. Click Safari in the menu and pick Clear History.
  2. Set Clear to all history and confirm with Clear History.Clear history from Safari

Reset Safari:

  1. Click Safari in the menu and select Preferences > Advanced.
  2. Enable Show Develop menu in menu bar.
  3. From the menu bar, click Develop and select Empty Caches.Reset Safari

Protect your privacy - employ a VPN

There are several ways how to make your online time more private - you can access an incognito tab.

However, there is no secret that even in this mode, you are tracked for advertising purposes. There is a way to add an extra layer of protection and create a completely anonymous web browsing practice with the help of VPN. This software reroutes traffic through different servers, thus leaving your IP address and geolocation in disguise.

Besides, it is based on a strict no-log policy, meaning that no data will be recorded, leaked, and available for both first and third parties. The combination of a secure web browser and VPN will let you browse the Internet without a feeling of being spied or targeted by criminals.

No backups? No problem. Use a data recovery tool

If you wonder how data loss can occur, you should not look any further for answers - human errors, malware attacks, hardware failures, power cuts, natural disasters, or even simple negligence.

In some cases, lost files are extremely important, and many straight out panic when such an unfortunate course of events happen. Due to this, you should always ensure that you prepare proper data backups on a regular basis.

If you were caught by surprise and did not have any backups to restore your files from, not everything is lost. is one of the leading file recovery solutions you can find on the market - it is likely to restore even lost emails or data located on an external device.

From our report of Sep 2022 · not reviewed since

Take these steps if you were tricked by scammers

  • If you have given your passwords to crooks by mistake, you should try to change them as soon as possible before they can get to them first. Scammers can gain login details to social media accounts and use them to spread their scams further.
  • If you think you gave away your banking details to untrustful sources, contact your bank and explain what happened. They may be able to block your card in time to prevent scammers from accessing it and stealing your funds.

From our report of Sep 2022 · not reviewed since

Fix your browser

After an encounter with a site like Papcorwye.live you should take care of your browser.

Follow the guide below:

Delete malicious extensions from Google Chrome:

Cookies are small text files that can track your browsing activity and store information, like your IP address, geolocation, websites you visit, links you click on, and things you purchase. This data is normally used to personalize the user experience but crooks use it to make a profit. They can be sold to advertising networks and other third parties.

They can even be hijacked, and used for malicious purposes, which is why security experts recommend clearing them regularly. This process can be made easy with a maintenance tool like . Besides, this powerful software can fix various system errors, corrupted files, and registry issues which is especially helpful after a virus infection.

Clear cache and web data from Chrome:

Reset Google Chrome:

If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:

  • Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  • In the newly opened window, you will see all the installed extensions. Uninstall all the suspicious plugins that might be related to the unwanted program by clicking Remove.
  • Click on Menu and pick Settings.
  • Under Privacy and security, select Clear browsing data.
  • Select Browsing history, Cookies and other site data, as well as Cached images and files.
  • Click Clear data.
  • Click on Menu and select Settings.
  • Now click Restore settings to their original defaults.
  • Confirm with Reset settings.

From our report of Sep 2022 · not reviewed since

Check your system for adware

If you have performed all the previous steps but you still experience unwanted symptoms, you might have a PUP(potentially unwanted programs) installed in your system that is generating ads in the background without your consent. Such programs are known as adware, and usually, they sneak into the system from freeware distribution platforms.

Security software can also prevent such infections in the future by giving you a warning about suspicious programs. If you want to try it yourself, follow the instructions for Windows and macOS:

To fully remove an unwanted app, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:

  • Enter Control Panel into Windows search box and hit Enter or click on the search result.
  • Under Programs, select Uninstall a program.
  • From the list, find the entry of the suspicious program.
  • Right-click on the application and select Uninstall.
  • If User Account Control shows up, click Yes.
  • Wait till uninstallation process is complete and click OK.
  • Click on Windows Start > Control Panel located on the right pane (if you are Windows XP user, click on Add/Remove Programs).
  • In Control Panel, select Programs > Uninstall a program.
  • Pick the unwanted application by clicking on it once.
  • At the top, click Uninstall/Change.
  • In the confirmation prompt, pick Yes.
  • Click OK once the removal process is finished.
  • From the menu bar, select Go > Applications.
  • In the Applications folder, look for all related entries.
  • Click on the app and drag it to Trash (or right-click and pick Move to Trash)
  • Select Go > Go to Folder.
  • Enter /Library/Application Support and click Go or press Enter.
  • In the Application Support folder, look for any dubious entries and then delete them.
  • Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the related .plist files.

Questions about Papcorwye.live e-mail scam

I opened the "You've made the 5-billionth search." e-mail. Am I hacked?

No. Opening and reading a phishing e-mail does not give anyone access to your account or your PC. Modern mail programs block scripts and remote content by default, so reading the message "You've made the 5-billionth search." only showed you text and pictures.

The danger comes from clicking the button and typing your password on the page it opens, or from opening an attached file. If you did neither, report the message as phishing and delete it.

If you clicked but closed the page without typing anything, there is also nothing to fix. If you did type a password, change it from another device and turn on two-step verification.

I typed my password after "You've made the 5-billionth search.". What now?

Act within the hour. From another device, open the real site of the account the message "You've made the 5-billionth search." imitated and change the password. If the same password is used anywhere else, change it there too.

Sign out of all other sessions, check the recovery e-mail and phone number, and look for mail forwarding rules or filters you did not create. Then turn on two-step verification with an authenticator app or a passkey.

If the fake page also asked for a card number or a bank login, call your bank and ask them to block the card. Finally, report the e-mail so others are warned.

Could Papcorwye.live be a genuine message?

We checked it, and it is not. A well-known company is only the costume. The message exists to get your password, and real companies handle that inside your account, after you sign in normally, not through links, attachments or phone numbers in a message you did not expect.

Scammers copy logos and footers perfectly, so the design proves nothing. The sender address, the link target and the request are the reliable signs, and all three point to a scam here. Delete it, and if you are worried, check your account directly.

Why does Papcorwye.live say that your account needs urgent attention?

Because that story works. A problem that needs fixing, a deadline and a simple solution make people act before they check.

The claim that your account needs urgent attention is the same for everyone who received Papcorwye.live; it was written once and sent in bulk. Nothing about your own situation triggered it.

If you are unsure, look at the real account or service the normal way, without using the message. The claim will not be there, which settles the question. Then report the message.

What does Papcorwye.live want from me?

In the end, your password. Everything else in Papcorwye.live, from the logo to the deadline, is there to get you to that point without stopping to think. Knowing the goal helps you judge your risk.

If you did not give it, you lost nothing and can delete the message. If you did, the steps in this guide are ordered by what you handed over:

  • passwords first
  • then card and bank details
  • then documents and anything you installed
  • ran

Act on the highest item on that list first.

How do I contact the real a well-known company?

Not through anything in Papcorwye.live. Type the official website address into the browser yourself, use the app you already have, or use the phone number printed on your card, contract or a previous genuine invoice. Search results can be risky too, because scammers buy ads for support numbers.

Once you reach the real a well-known company, you can ask whether there is any problem with your account and report the scam message; many companies have a dedicated address for phishing reports on their security page.

I opened the message. Is my computer infected?

Opening and reading a message is safe in modern mail apps and browsers; images and text do not install anything by themselves. Your PC is at risk only if you opened an attachment, ran a downloaded file, or followed instructions to paste a command or install a program.

If you did none of that, delete the message and move on. If you did, disconnect from the internet and run a full scan and the Microsoft Defender offline scan. Do not reply to the sender or click links in the message later either.

Does Papcorwye.live mean my PC is hacked?

Not necessarily. The sign reported, an e-mail with the subject "You've made the 5-billionth search.", is usually caused by a password that leaked or was phished, not by malware on the PC.

Passwords leak in breaches of other websites and are tried on many services. Still, rule out the PC:

  • run a full scan in Windows Security
  • check Installed apps for anything you do not recognise
  • look at the browser's extensions

If all is clean, the problem lies with the account, and changing the password with two-step verification turned on is the fix.

I entered my password on the fake page. What should I do?

Change the password on the real site right away, through its own website or app, and sign out of all sessions.

If you use the same password anywhere else, change it there too. Turn on two-step verification with an authenticator app or a passkey. Check the account for changes:

  • recovery e-mail
  • phone number
  • forwarding rules
  • recently sent messages

If you can no longer sign in, use the provider's account recovery page. Tell your contacts if the account sent messages in your name.

Will Fortect remove Papcorwye.live?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Papcorwye.live, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove Immediate Action Required

Immediate Action Required is a fake notification that might pop-up out of nowhere and prompt users to download useless bogus software Immediate Action Required is a scam that users mightAdwareMedium riskUgnius Kiguolis ·

Remove ReceiverHelper Mac virus

ReceiverHelper virus is a high threat to your personal safety and Mac security ReceiverHelper is a harmful application targeting Mac devices, classified under the Adload malware family. It is notoriousAdwareMedium riskJake Doevan ·

Remove Casalemedia

Casalemedia is a legal advertising service but is sometimes abused by crooks to gain personal income Casalemedia is a legitimate advertising service that provides assistance in monetizing on online contentAdwareMedium riskJake Doevan ·

Remove D1ue3yi0hkdsdl.cloudfront.net ads

D1ue3yi0hkdsdl.cloudfront.net ads is the content related to scam campaigns and fake errors or warnings D1ue3yi0hkdsdl.cloudfront.net is the program that causes notifications and advertisements that may appear unexpectedly, preventing you fromAdwareMedium riskJulie Splinters ·

Questions and experiences: Papcorwye.live e-mail scam

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year