Papcorwye.live e-mail scam: how to spot it and what to do
Papcorwye.live is a bogus website designed by crooks to look like a Chrome giveaway. Supposedly, users are chosen by Chrome as lucky visitors who made the 5-billionth search and are eligible to win a prize.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Do it yourself · free Remove Papcorwye.live e-mail scam yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Papcorwye.live e-mail scam: summary
| Distribution | The appearance of this scam page might indicate adware infection; users can also stumble upon such sites accidentally |
|---|---|
| NAME | Papcorwye.live |
| TYPE | Phishing attempt; scam |
| SYMPTOMS | A page appears claiming that the visitor is a 5-billionth Chrome visitor who can receive a prize |
| DANGERS | People can be tricked into providing personal information which could lead to monetary losses or even identity theft |
| Name | Papcorwye.live |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Type | Phishing message |
|---|---|
| Symptoms | A phishing e-mail asking you to sign in |
| Evidence | 4 write-ups by security sites; details still limited |
| Arrives as | |
| Pretends to be | A well-known company |
| Claim | Your account needs urgent attention |
| Asks for | Your password |
| First seen | 13 September 2022 |
| Facts checked | 7 October 2026 |
What the Papcorwye.live e-mail scam e-mail looks like
What a phishing e-mail asking you to sign in said
You've made the 5-billionth search.
Congratulations! You may be our next lucky winner!
Our last winner was Brad Jenkins from London who won Samsung KU6179 Ultra HD TV on 14.05.2019 with his 5-billionth Search.
Every time the 5-billionth search is reached, we proclaim a winner and reset the counter.
You may choose one of three hidden prizes below. In addition, you will be entered in our Hall of Fame and receive a winner's certificate.
Behind every box is a prize. Click on a box to uncover it.
For technical reasons, we are not allowed to keep your invitation open for more than 15 minutes.
Choose one of the prizes below and follow the instructions on your screen.
From our report of Sep 2022 · not reviewed since
Distribution methods
Scam sites, like Papcorwye.live rarely appear in the search results.
Usually, they appear seemingly out of nowhere while browsing the web. That is because most of the time they are hidden behind deceptive ads and sneaky redirects on other shady websites.
Do not click on random links and ads even if they seem to be promoting legitimate products and services. Crooks can use social engineering and impersonate well-known brands.

How to tell the Papcorwye.live e-mail scam e-mail is fake
From our report of Sep 2022 · not reviewed since
Papcorwye.live is a page designed by crooks that looks like a Chrome giveaway
Papcorwye.live is a bogus website designed by crooks to look like a Chrome giveaway.
Supposedly, users are chosen by Chrome as lucky visitors who made the 5-billionth search and are eligible to win a prize. The full message reads as follows:
The main goal of such deceptive websites is to extract personal information. After users click on a gift box and supposedly win a phone, TV, or another tech prize, they may be asked to enter their details or pay for shipping costs.
The page might ask to provide a name, address, email, phone number, or credit card details. Falling for this type of scam may result in monetary losses or even identity theft.
When browsing the web, it is important to not lose your head. If it seems too good to be true - it probably is. Big tech companies like Google or Apple do not choose random Internet users and shower them with gifts. It is best not to interact with such sites at all.

From our report of Sep 2022 · not reviewed since
More from our earlier report on Papcorwye.live
- Check your system for adware with professional security tools
What to do after the Papcorwye.live e-mail
If you only received the message and clicked nothing, step 3 is all you need.
If you clicked the link or typed anything on the page it opened, do every step, starting with the password.
Step 1: Change the password you typed on the fake page
If you typed a password on the page the Papcorwye.live message opened, assume the sender has it. Go to the real site by typing its address yourself and change the password there, choosing one you have never used.
Change it anywhere else the same password was used, and sign out all other sessions if the service offers it. Any browser on Windows 11 or Windows 10 will do, as long as you do not follow the e-mail's link.

Microsoft account, Security page (account.microsoft.com/security): Change password. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 2: Turn on two-step verification
With two-step verification on, a stolen password alone no longer opens the account, because a sign-in from a new device also needs a code from your phone.
Switch it on for the e-mail account first, then for banking, shopping and social accounts that use that address.
Check the recovery phone, the recovery e-mail and any forwarding rules while you are in the settings, since attackers change them to come back. The pages are the same on Windows 11 and Windows 10.

Microsoft account: Manage how I sign in, where two-step verification and the sign-in methods are. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 3: Report the e-mail and delete it
Do not reply and do not click anything else in the message. In Outlook select the e-mail and choose Report > Report phishing; in Gmail open the three-dot menu next to Reply and pick Report phishing.
That trains the filter for everyone on the service, and the message goes to the junk folder. If the e-mail came to a work address, forward it to your IT team as an attachment first.
The steps are the same in the web mail and the mail apps on Windows 11 and Windows 10.

New Outlook for Windows and Outlook on the web: Report > Report phishing. Full procedure with screenshots: Report a phishing e-mail
Step 4: Scan the PC if you opened a file from the message
A fake sign-in page only steals what you type, so most readers can skip this step. If the Papcorwye.live e-mail made you download or open a file, delete it and scan the PC.
In Windows Security > Virus & threat protection > Scan options, run a Full scan and then Microsoft Defender Antivirus (offline scan) > Scan now. The offline scan restarts Windows 11 or Windows 10 and takes about 15 minutes.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Remove from Microsoft Edge
Delete unwanted extensions from MS Edge:
- Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
- From the list, pick the extension and click on the Gear icon.
- Click Remove.

Clear cookies and other browser data:
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
- Under Clear browsing data, pick Choose what to clear.
- Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.

Restore new tab and homepage settings:
- Click the menu icon and choose Settings.
- Then find On startup section.
- Click Remove next to any suspicious startup page.
Reset MS Edge if the above steps did not work:
- Press on Ctrl + Shift + Esc to open Task Manager.
- Click on More details arrow at the bottom of the window.
- Select Details tab.
- Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.

Delete extensions from MS Edge (Chromium):
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.

Clear cache and site data:
- Click on Menu and go to Settings.
- Select Privacy, search and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.

Reset Chromium-based MS Edge:
- Click on Menu and select Settings.
- On the left side, pick Reset settings.
- Select Restore settings to their default values.
- Confirm with Reset.
- This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.

Remove from Mozilla Firefox (FF)
Remove dangerous extensions:
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- In here, select the unwanted extension and click Remove.

Reset the homepage:
- Click three horizontal lines at the top right corner to open the menu.
- Choose Settings.
- Under Home, set your preferred homepage and new tab settings.
Clear cookies and site data:
- Click Menu and pick Settings.
- Go to Privacy & Security section.
- Scroll down to locate Cookies and Site Data.
- Click on Clear Data...
- Select Cookies and Site Data and Temporary cached files and pages, then click Clear.

Reset Mozilla Firefox
If clearing the browser as explained above did not help, reset Mozilla Firefox:
- Open Mozilla Firefox browser and click the Menu.
- Go to Help and then choose Troubleshooting Information.

- Under Give Firefox a tune up section, click on Refresh Firefox...
- Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.

Delete from Safari
Remove dangerous extensions:
- Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
- Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.

Clear history and website data:
- Click Safari in the menu and pick Clear History.
- Set Clear to all history and confirm with Clear History.

Reset Safari:
- Click Safari in the menu and select Preferences > Advanced.
- Enable Show Develop menu in menu bar.
- From the menu bar, click Develop and select Empty Caches.

Protect your privacy - employ a VPN
There are several ways how to make your online time more private - you can access an incognito tab.
However, there is no secret that even in this mode, you are tracked for advertising purposes. There is a way to add an extra layer of protection and create a completely anonymous web browsing practice with the help of VPN. This software reroutes traffic through different servers, thus leaving your IP address and geolocation in disguise.
Besides, it is based on a strict no-log policy, meaning that no data will be recorded, leaked, and available for both first and third parties. The combination of a secure web browser and VPN will let you browse the Internet without a feeling of being spied or targeted by criminals.
No backups? No problem. Use a data recovery tool
If you wonder how data loss can occur, you should not look any further for answers - human errors, malware attacks, hardware failures, power cuts, natural disasters, or even simple negligence.
In some cases, lost files are extremely important, and many straight out panic when such an unfortunate course of events happen. Due to this, you should always ensure that you prepare proper data backups on a regular basis.
If you were caught by surprise and did not have any backups to restore your files from, not everything is lost. is one of the leading file recovery solutions you can find on the market - it is likely to restore even lost emails or data located on an external device.
From our report of Sep 2022 · not reviewed since
Take these steps if you were tricked by scammers
- If you have given your passwords to crooks by mistake, you should try to change them as soon as possible before they can get to them first. Scammers can gain login details to social media accounts and use them to spread their scams further.
- If you think you gave away your banking details to untrustful sources, contact your bank and explain what happened. They may be able to block your card in time to prevent scammers from accessing it and stealing your funds.
From our report of Sep 2022 · not reviewed since
Fix your browser
After an encounter with a site like Papcorwye.live you should take care of your browser.
Follow the guide below:
Delete malicious extensions from Google Chrome:
Cookies are small text files that can track your browsing activity and store information, like your IP address, geolocation, websites you visit, links you click on, and things you purchase. This data is normally used to personalize the user experience but crooks use it to make a profit. They can be sold to advertising networks and other third parties.
They can even be hijacked, and used for malicious purposes, which is why security experts recommend clearing them regularly. This process can be made easy with a maintenance tool like . Besides, this powerful software can fix various system errors, corrupted files, and registry issues which is especially helpful after a virus infection.
Clear cache and web data from Chrome:
Reset Google Chrome:
If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all the suspicious plugins that might be related to the unwanted program by clicking Remove.
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.
- Click on Menu and select Settings.
- Now click Restore settings to their original defaults.
- Confirm with Reset settings.
From our report of Sep 2022 · not reviewed since
Check your system for adware
If you have performed all the previous steps but you still experience unwanted symptoms, you might have a PUP(potentially unwanted programs) installed in your system that is generating ads in the background without your consent. Such programs are known as adware, and usually, they sneak into the system from freeware distribution platforms.
Security software can also prevent such infections in the future by giving you a warning about suspicious programs. If you want to try it yourself, follow the instructions for Windows and macOS:
To fully remove an unwanted app, you need to access Application Support, LaunchAgents, and LaunchDaemons folders and delete relevant files:
- Enter Control Panel into Windows search box and hit Enter or click on the search result.
- Under Programs, select Uninstall a program.
- From the list, find the entry of the suspicious program.
- Right-click on the application and select Uninstall.
- If User Account Control shows up, click Yes.
- Wait till uninstallation process is complete and click OK.
- Click on Windows Start > Control Panel located on the right pane (if you are Windows XP user, click on Add/Remove Programs).
- In Control Panel, select Programs > Uninstall a program.
- Pick the unwanted application by clicking on it once.
- At the top, click Uninstall/Change.
- In the confirmation prompt, pick Yes.
- Click OK once the removal process is finished.
- From the menu bar, select Go > Applications.
- In the Applications folder, look for all related entries.
- Click on the app and drag it to Trash (or right-click and pick Move to Trash)
- Select Go > Go to Folder.
- Enter /Library/Application Support and click Go or press Enter.
- In the Application Support folder, look for any dubious entries and then delete them.
- Now enter /Library/LaunchAgents and /Library/LaunchDaemons folders the same way and terminate all the related .plist files.
Questions about Papcorwye.live e-mail scam
I opened the "You've made the 5-billionth search." e-mail. Am I hacked?
No. Opening and reading a phishing e-mail does not give anyone access to your account or your PC. Modern mail programs block scripts and remote content by default, so reading the message "You've made the 5-billionth search." only showed you text and pictures.
The danger comes from clicking the button and typing your password on the page it opens, or from opening an attached file. If you did neither, report the message as phishing and delete it.
If you clicked but closed the page without typing anything, there is also nothing to fix. If you did type a password, change it from another device and turn on two-step verification.
I typed my password after "You've made the 5-billionth search.". What now?
Act within the hour. From another device, open the real site of the account the message "You've made the 5-billionth search." imitated and change the password. If the same password is used anywhere else, change it there too.
Sign out of all other sessions, check the recovery e-mail and phone number, and look for mail forwarding rules or filters you did not create. Then turn on two-step verification with an authenticator app or a passkey.
If the fake page also asked for a card number or a bank login, call your bank and ask them to block the card. Finally, report the e-mail so others are warned.
Could Papcorwye.live be a genuine message?
We checked it, and it is not. A well-known company is only the costume. The message exists to get your password, and real companies handle that inside your account, after you sign in normally, not through links, attachments or phone numbers in a message you did not expect.
Scammers copy logos and footers perfectly, so the design proves nothing. The sender address, the link target and the request are the reliable signs, and all three point to a scam here. Delete it, and if you are worried, check your account directly.
Why does Papcorwye.live say that your account needs urgent attention?
Because that story works. A problem that needs fixing, a deadline and a simple solution make people act before they check.
The claim that your account needs urgent attention is the same for everyone who received Papcorwye.live; it was written once and sent in bulk. Nothing about your own situation triggered it.
If you are unsure, look at the real account or service the normal way, without using the message. The claim will not be there, which settles the question. Then report the message.
What does Papcorwye.live want from me?
In the end, your password. Everything else in Papcorwye.live, from the logo to the deadline, is there to get you to that point without stopping to think. Knowing the goal helps you judge your risk.
If you did not give it, you lost nothing and can delete the message. If you did, the steps in this guide are ordered by what you handed over:
- passwords first
- then card and bank details
- then documents and anything you installed
- ran
Act on the highest item on that list first.
How do I contact the real a well-known company?
Not through anything in Papcorwye.live. Type the official website address into the browser yourself, use the app you already have, or use the phone number printed on your card, contract or a previous genuine invoice. Search results can be risky too, because scammers buy ads for support numbers.
Once you reach the real a well-known company, you can ask whether there is any problem with your account and report the scam message; many companies have a dedicated address for phishing reports on their security page.
I opened the message. Is my computer infected?
Opening and reading a message is safe in modern mail apps and browsers; images and text do not install anything by themselves. Your PC is at risk only if you opened an attachment, ran a downloaded file, or followed instructions to paste a command or install a program.
If you did none of that, delete the message and move on. If you did, disconnect from the internet and run a full scan and the Microsoft Defender offline scan. Do not reply to the sender or click links in the message later either.
Does Papcorwye.live mean my PC is hacked?
Not necessarily. The sign reported, an e-mail with the subject "You've made the 5-billionth search.", is usually caused by a password that leaked or was phished, not by malware on the PC.
Passwords leak in breaches of other websites and are tried on many services. Still, rule out the PC:
- run a full scan in Windows Security
- check Installed apps for anything you do not recognise
- look at the browser's extensions
If all is clean, the problem lies with the account, and changing the password with two-step verification turned on is the fix.
I entered my password on the fake page. What should I do?
Change the password on the real site right away, through its own website or app, and sign out of all sessions.
If you use the same password anywhere else, change it there too. Turn on two-step verification with an authenticator app or a passkey. Check the account for changes:
- recovery e-mail
- phone number
- forwarding rules
- recently sent messages
If you can no longer sign in, use the provider's account recovery page. Tell your contacts if the account sent messages in your name.
Will Fortect remove Papcorwye.live?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Papcorwye.live, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Dataprot: What Are Cookies? The Good and the Bad of Browser Cookies (read October 7, 2026)
- Wikipedia, the free encyclopedia: Potentially unwanted program (read October 7, 2026)
- Malwarebytes: Adware (read October 7, 2026)
- FTC: How to recognize and avoid phishing scams (read October 7, 2026)
- CISA: Recognize and report phishing (read October 7, 2026)