Possible Suspicious Activity" virus: what it is and how to remove it
"Possible Suspicious Activity" virus defines a browser-based tech support scam. It is universal as it plagues Chrome, Internet Explorer, Firefox, and Microsoft Edge.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
An automatic scan checks installed programs, startup items and browser extensions for anything that came with Possible Suspicious Activity" virus.
Do it yourself · free Remove Possible Suspicious Activity" virus yourself 4 steps, about 12 minutes, no software needed.
Start the steps
Possible Suspicious Activity" virus: summary
| Detection names | No Microsoft detection name is known |
|---|---|
| Distribution | Not recorded in the old report |
| Damage | Not recorded in the old report |
| Name | Possible Suspicious Activity" virus |
| Type | Adware extension |
| Symptoms | An unknown program in Installed apps |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 4 more facts
| Evidence | 4 write-ups by security sites; details still limited |
|---|---|
| Program | Possible Suspicious Activity" virus |
| First seen | 30 October 2017 |
| Facts checked | 7 October 2026 |
Is Possible Suspicious Activity" virus dangerous?
From our report of Oct 2017 · not reviewed since
"Possible Suspicious Activity" alerts come from tech support scammers
"Possible Suspicious Activity" virus defines a browser-based tech support scam.
It is universal as it plagues Chrome, Internet Explorer, Firefox, and Microsoft Edge. This sample of scam is more elaborate. Unlike the majority of online deceptions which terrify users with Zeus virus and Facebook login as well as email account log-in data theft, this time, the crooks tied in more technical details to make the scam more realistic.
When users get redirected to a scam site, first of all, the message pops up stating that:
A couple of other alerts follow the latter. The next is called "Warning! Hyper-V Manager." The very program, Hyper-V Manager, is a virtualization platform introduced by Microsoft in 2008.
Thus, the racketeers loaded a few definition of real programs to persuade users. Though they crowd the pop-up alert with technical details and definitions, the key thing which reveals the origin of the scam is the phone number.
Despite how realistic the scam might seem, if it includes the phone number or an email address, exit the page and clean the browser. The majority of browser-based tech scams are not destructive.
Claims that your data will be corrupted or lost are just lies. However, some online deceptions may temporarily hijack your browser. Thus, clicking on the button "Prevent this page from creating additional dialogues" may not work.
You will need to force shut-down on the browser. In addition, it is recommended to remove "Possible Suspicious Activity" scripts from the browser. You can do so with the assistance of or .

From our report of Oct 2017 · not reviewed since
Keep your computer safe and learn to identify tech support scams
Browser-based tech support scams scripts might be foisted in a variety of websites.
Observing the tendency, most likely, you could get directed to such scam when you browse illegal movie streaming sites or torrent sharing domains.
Likewise, "Possible Suspicious Activity" hijack might have occurred as a result of such technique. On the other hand, even if you are cautious, a tech support page might appear if you click on a legitimate ad or banner.
Note that you should be wary of corrupted apps and extensions. They might be a harbinger of a PC version of a tech support scam. The latter cause more elimination troubles. Now let us review "Possible Suspicious Activity" scam removal options.

From our report of Oct 2017 · not reviewed since
More from our earlier report on Possible Suspicious Activity" virus
- Customer, your system has detected possible suspicious activity.
- (…)CONTACT MICROSOFT CERTIFIED TECHNICIANS TO RESOLVE THE ISSUE CALLING TOLL FREE 8447756410.
How Possible Suspicious Activity" virus got into your browser
From our report of Oct 2017 · not reviewed since
On October 30th, researchers discovered a brand new scam using "Antivirus Detected Some Suspicious Activity" line to trick unsuspecting users into calling fraudsters via provided "toll-free" number.
This time, scammers suggest dialing +1-844-665-6888 number for help directly from "Microsoft Technicians." Calling the fraudsters won't help to resolve the imaginary issue that the deceptive alert warns you about.
Scammers will simply ask you to follow their commands that can eventually result in data loss or a severe computer infection. The pop-up typically appears on pages that look like Microsoft's Support page or another related site because it is filled with forged company's logos all over.
Do not let these cheap tricks fool you and convince you to call scammers. Otherwise, you might end up giving them remote access logins or credit card details to people who will use such data for illegal purposes.
Remove "Antivirus Detected Some Suspicious Activity" virus as soon as you can and make these fake alerts disappear once and for good. You can detect the malware sending you these pop-ups using anti-malware or anti-spyware programs that we mentioned earlier.
How to remove Possible Suspicious Activity" virus
How to remove the Possible Suspicious Activity" virus extension
Do the browser steps in every browser and profile on the PC, then check Windows for the program that installed the extension.
Step 1: Remove extensions you did not add
In Chrome open
chrome://extensions, in Edgeedge://extensions, and in Firefox the menu > Extensions and themes.Remove every extension you do not remember adding, especially search, new tab, coupon, PDF, weather or video downloader add-ons. Check every browser and every profile, because each keeps its own list.
If an extension has no Remove button or comes back, a browser policy holds it (see "Managed by your organization" in the procedure below). The pages are the same on Windows 11 and Windows 10.

Chrome on Windows 11: More > Extensions > Manage extensions. Full procedure with screenshots: Remove a browser extension
Step 2: Uninstall Possible Suspicious Activity" virus
Possible Suspicious Activity" virus is removed like any other program, from the list of installed apps. In Windows 11 that is Settings > Apps > Installed apps, in Windows 10 Settings > Apps > Apps & features, and in both you can also use Control Panel > Programs and Features.
Select Possible Suspicious Activity" virus, click Uninstall and follow the uninstaller to the end. Then look at the entries just above and below it when the list is sorted by date: bundled programs install at the same minute.
Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix
Step 3: Reset the browser
A reset removes what the steps above could miss:
- changed start pages
- site permissions
- hidden settings
In Chrome open Settings > Reset settings > Restore settings to their original defaults; in Edge Settings > Reset settings; in Firefox Help > More troubleshooting information > Refresh Firefox.
Tip: Bookmarks and saved passwords stay, while extensions are turned off and the search engine and start page return to the defaults.
Reset every browser on the PC, including Edge, which Windows 11 and Windows 10 always have.

Chrome on Windows 11: Settings > Reset settings. Full procedure with screenshots: Reset a browser and fix a hijacked search engine
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of Possible Suspicious Activity" virus that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Instructions for each browser and system
The detailed steps for every browser and system this guide covers. Open the one you use.
Uninstall from Windows
Uninstall from Windows 10/8:
- Type Control Panel into the Windows search box and open the result.
- Under Programs, select Uninstall a program.

Uninstall from Windows 7/XP:
- Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
- In Control Panel, select Programs > Uninstall a program.

Remove the unwanted program:
- In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
- If User Account Control appears, click Yes to confirm, then complete the removal.

Remove from Google Chrome
Delete malicious extensions from Google Chrome:
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.

Clear cache and web data from Chrome:
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.

Change your homepage:
- Click menu and choose Settings.
- Look for a suspicious site in the On startup section.
- Click on Open a specific or set of pages and click on three dots to find the Remove option.
Reset Google Chrome:
If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:
- Click on Menu and select Settings.
- In the Settings, scroll down and click Advanced.
- Scroll down and locate Reset and clean up section.
- Now click Restore settings to their original defaults.
- Confirm with Reset settings.

Remove from Microsoft Edge
Delete unwanted extensions from MS Edge:
- Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
- From the list, pick the extension and click on the Gear icon.
- Click Remove.

Clear cookies and other browser data:
- Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
- Under Clear browsing data, pick Choose what to clear.
- Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.

Restore new tab and homepage settings:
- Click the menu icon and choose Settings.
- Then find On startup section.
- Click Remove next to any suspicious startup page.
Reset MS Edge if the above steps did not work:
- Press on Ctrl + Shift + Esc to open Task Manager.
- Click on More details arrow at the bottom of the window.
- Select Details tab.
- Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.

Delete extensions from MS Edge (Chromium):
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.

Clear cache and site data:
- Click on Menu and go to Settings.
- Select Privacy, search and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.

Reset Chromium-based MS Edge:
- Click on Menu and select Settings.
- On the left side, pick Reset settings.
- Select Restore settings to their default values.
- Confirm with Reset.
- This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.

Remove from Mozilla Firefox (FF)
Remove dangerous extensions:
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- In here, select the unwanted extension and click Remove.

Reset the homepage:
- Click three horizontal lines at the top right corner to open the menu.
- Choose Settings.
- Under Home, set your preferred homepage and new tab settings.
Clear cookies and site data:
- Click Menu and pick Settings.
- Go to Privacy & Security section.
- Scroll down to locate Cookies and Site Data.
- Click on Clear Data...
- Select Cookies and Site Data and Temporary cached files and pages, then click Clear.

Reset Mozilla Firefox
If clearing the browser as explained above did not help, reset Mozilla Firefox:
- Open Mozilla Firefox browser and click the Menu.
- Go to Help and then choose Troubleshooting Information.

- Under Give Firefox a tune up section, click on Refresh Firefox...
- Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.

Delete from Safari
Remove dangerous extensions:
- Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
- Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.

Clear history and website data:
- Click Safari in the menu and pick Clear History.
- Set Clear to all history and confirm with Clear History.

Reset Safari:
- Click Safari in the menu and select Preferences > Advanced.
- Enable Show Develop menu in menu bar.
- From the menu bar, click Develop and select Empty Caches.

Delete from macOS
Mac OS users should be wary of "Possible Suspicious Activity" scam types. Theey might be targeted with the iOS counterparts of this felony.
Remove the unwanted application:
- From the menu bar, select Go > Applications.
- In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).

Delete leftover files and folders:
- Select Go > Go to Folder.
- Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
- Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.

- Finally, empty the Trash to permanently remove the leftovers.
Reset Internet Explorer
Remove dangerous add-ons:
- Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
- Pick Manage Add-ons.
- You will see a Manage Add-ons window. Here, look for suspicious plugins. Click on these entries and select Disable.

Change your homepage if it was altered:
- Open IE and click on the Gear icon.
- Select Internet Options.
- In the General tab, delete the Home page address and replace it by your preferred one (for example, Google.com).
- Click Apply and then select OK.

Delete temporary files:
- Press on the Gear icon and select Internet Options.
- Under Browsing history, click Delete...
- Select relevant fields and press Delete.

Reset Internet Explorer:
- Click on Gear icon > Internet options and select Advanced tab.
- Select Reset.
- In the new window, check Delete personal settings and select Reset.

Stream videos without limitations, no matter where you are
There are multiple parties that could find out almost anything about you by checking your online activity.
While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.
Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.
Data backups are important - recover your lost files
Ransomware is one of the biggest threats to personal data.
Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.
While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.
From our report of Oct 2017 · not reviewed since
Remove Possible Suspicious Activity virus with ease
First of all, you need to exit the tech support scam site.
Click on CTRL+SHIFT+ESC. Find your browser commands in the Task Manager, right-click on them and then choose "End task."
Now restart the browser. Enter the Settings and clear cookies as well browsing data. In case the redirect page still emerges, reset the browser to remove "Possible Suspicious Activity" virus elements.
It is also advised to scan the browser. The tool will complete "Possible Suspicious Activity" removal procedure. This scam might appear not only in English but in French, Hungarian or Estonian sites.
Questions about Possible Suspicious Activity" virus
What is Possible Suspicious Activity" virus and why is it on my PC?
Possible Suspicious Activity" virus is a program that was installed on the PC, most likely together with something else you downloaded. Free software sites and many installers add extra programs on setup pages with pre-ticked boxes, so the extra install looks like your choice even though nobody read the page.
Check the install date in Settings, Apps, Installed apps: the program you installed that day is the probable carrier. If you do not need Possible Suspicious Activity" virus, uninstall it. If it belongs to your hardware or to a program you use, search its exact name and publisher first, because drivers and their tools can have unfamiliar names.
How do I stop programs like Possible Suspicious Activity" virus from being installed again?
Most unwanted programs arrive through installers, so the fix is in how you install software. Download programs from their official sites or the Microsoft Store, not from download portals or ads above search results. During setup, choose Custom or Advanced installation and untick every extra offer, including browsers, toolbars and optimizers.
Decline update prompts that appear inside other programs unless you know them. In Windows Security, turn on reputation-based protection and potentially unwanted app blocking. These steps would most likely have stopped Possible Suspicious Activity" virus before it reached the app list.
Can adware slow down my PC?
Yes. Adware runs in the background, loads ad scripts, opens extra tabs and contacts its servers, all of which use processor time, memory and bandwidth. Ad-heavy extensions also slow down every page, because they inspect and change it before you see it.
The effect is strongest on older PCs and when several adware programs arrived together. After removal, restart the PC and check Task Manager for anything still using a lot of resources that you do not recognise. Speed usually returns to normal once the ads stop.
Does adware steal passwords?
Ordinary adware is built to show ads, not to steal logins, and most of it never touches saved passwords. The line is blurry, though. Extensions that can read every page could capture what you type, and adware ads sometimes lead to phishing pages that ask for passwords directly.
If you entered credentials on a page reached through an ad, change that password from a clean device and turn on two-step verification. Otherwise, removing adware extension and clearing cookies is usually enough.
I clicked on one of the ads. Am I infected?
Probably not. Clicking an ad usually only opens a page, and a page cannot install programs on an up-to-date Windows PC without your help.
You are at risk only if you then downloaded and ran a file, allowed notifications, entered card or login details, or called a phone number shown on the page. Delete any download and run a full and offline scan.
Change passwords you typed, from a clean device. Call your bank if you gave card details. If you called a number or allowed remote access, see the next question.
Why didn't my antivirus catch Possible Suspicious Activity" virus?
Many security products do not block adware or notification sites by default, because users often agreed to them, even through a misleading prompt. Notification spam installs nothing at all, so there is no file to detect.
In Windows 11 you can make Microsoft Defender block potentially unwanted apps: open Windows Security > App & browser control > Reputation-based protection settings and turn on Potentially unwanted app blocking. If notifications caused the pop-ups, no scanner will report them; the fix is in the browser's site settings.
An ad showed a phone number and I called it. What now?
The number belongs to scammers, not to Microsoft or an antivirus company. If you only talked, hang up and do not call back. If you let them connect to the PC, disconnect it from the internet, uninstall the remote access program they used, such as AnyDesk, TeamViewer, ScreenConnect or UltraViewer, and run a full and offline scan.
If you paid or gave bank details, call your bank at once on the number printed on your card. Change any passwords you typed while they were connected, and report the call.
How did Possible Suspicious Activity get on my computer?
Observing the tendency, most likely, you could get directed to such scam when you browse illegal movie streaming sites or torrent sharing domains. Software of this kind often comes bundled with free programs, fake updates or downloads from unofficial sites.
It can also arrive through a browser extension or a notification you allowed on a spam page. Think back to what you installed or allowed just before the first ad or redirect appeared.
Will Fortect remove Possible Suspicious Activity" virus?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Possible Suspicious Activity" virus, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Veeam: What is Hyper-V technology? (read October 7, 2026)
- GrahamCluley: Taboola ads exploited to serve up tech support scams (read October 7, 2026)
- Google Chrome Help: Use notifications to get alerts (no longer online) (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)
- Microsoft Learn: Microsoft Defender Offline (read October 7, 2026)