Possible Suspicious Activity" virus: what it is and how to remove it

"Possible Suspicious Activity" virus defines a browser-based tech support scam. It is universal as it plagues Chrome, Internet Explorer, Firefox, and Microsoft Edge.

Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

An automatic scan checks installed programs, startup items and browser extensions for anything that came with Possible Suspicious Activity" virus.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Possible Suspicious Activity" virus yourself 4 steps, about 12 minutes, no software needed.

Start the steps
Possible Suspicious Activity" virus: possible suspicious activity scam
Possible Suspicious Activity" virus as our 2017 report showed it.

Possible Suspicious Activity" virus: summary

Detection namesNo Microsoft detection name is known
DistributionNot recorded in the old report
DamageNot recorded in the old report
NamePossible Suspicious Activity" virus
TypeAdware extension
SymptomsAn unknown program in Installed apps
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 4 more facts
Evidence4 write-ups by security sites; details still limited
ProgramPossible Suspicious Activity" virus
First seen30 October 2017
Facts checked7 October 2026

Is Possible Suspicious Activity" virus dangerous?

From our report of Oct 2017 · not reviewed since

"Possible Suspicious Activity" alerts come from tech support scammers

"Possible Suspicious Activity" virus defines a browser-based tech support scam.

It is universal as it plagues Chrome, Internet Explorer, Firefox, and Microsoft Edge. This sample of scam is more elaborate. Unlike the majority of online deceptions which terrify users with Zeus virus and Facebook login as well as email account log-in data theft, this time, the crooks tied in more technical details to make the scam more realistic.

When users get redirected to a scam site, first of all, the message pops up stating that:

A couple of other alerts follow the latter. The next is called "Warning! Hyper-V Manager." The very program, Hyper-V Manager, is a virtualization platform introduced by Microsoft in 2008.

Thus, the racketeers loaded a few definition of real programs to persuade users. Though they crowd the pop-up alert with technical details and definitions, the key thing which reveals the origin of the scam is the phone number.

Despite how realistic the scam might seem, if it includes the phone number or an email address, exit the page and clean the browser. The majority of browser-based tech scams are not destructive.

Claims that your data will be corrupted or lost are just lies. However, some online deceptions may temporarily hijack your browser. Thus, clicking on the button "Prevent this page from creating additional dialogues" may not work.

You will need to force shut-down on the browser. In addition, it is recommended to remove "Possible Suspicious Activity" scripts from the browser. You can do so with the assistance of or .

Possible Suspicious Activity" virus: possible suspicious activity scam
Possible Suspicious Activity" virus in our 2017 report.

From our report of Oct 2017 · not reviewed since

Keep your computer safe and learn to identify tech support scams

Browser-based tech support scams scripts might be foisted in a variety of websites.

Observing the tendency, most likely, you could get directed to such scam when you browse illegal movie streaming sites or torrent sharing domains.

Likewise, "Possible Suspicious Activity" hijack might have occurred as a result of such technique. On the other hand, even if you are cautious, a tech support page might appear if you click on a legitimate ad or banner.

Note that you should be wary of corrupted apps and extensions. They might be a harbinger of a PC version of a tech support scam. The latter cause more elimination troubles. Now let us review "Possible Suspicious Activity" scam removal options.

Possible Suspicious Activity" virus: posssible suspicious activity
Possible Suspicious Activity" virus in our 2017 report.

From our report of Oct 2017 · not reviewed since

More from our earlier report on Possible Suspicious Activity" virus

  • Customer, your system has detected possible suspicious activity.
  • (…)CONTACT MICROSOFT CERTIFIED TECHNICIANS TO RESOLVE THE ISSUE CALLING TOLL FREE 8447756410.

How Possible Suspicious Activity" virus got into your browser

From our report of Oct 2017 · not reviewed since

On October 30th, researchers discovered a brand new scam using "Antivirus Detected Some Suspicious Activity" line to trick unsuspecting users into calling fraudsters via provided "toll-free" number.

This time, scammers suggest dialing +1-844-665-6888 number for help directly from "Microsoft Technicians." Calling the fraudsters won't help to resolve the imaginary issue that the deceptive alert warns you about.

Scammers will simply ask you to follow their commands that can eventually result in data loss or a severe computer infection. The pop-up typically appears on pages that look like Microsoft's Support page or another related site because it is filled with forged company's logos all over.

Do not let these cheap tricks fool you and convince you to call scammers. Otherwise, you might end up giving them remote access logins or credit card details to people who will use such data for illegal purposes.

Remove "Antivirus Detected Some Suspicious Activity" virus as soon as you can and make these fake alerts disappear once and for good. You can detect the malware sending you these pop-ups using anti-malware or anti-spyware programs that we mentioned earlier.

How to remove Possible Suspicious Activity" virus

How to remove the Possible Suspicious Activity" virus extension

Do the browser steps in every browser and profile on the PC, then check Windows for the program that installed the extension.

  1. Step 1: Remove extensions you did not add

    In Chrome open chrome://extensions, in Edge edge://extensions, and in Firefox the menu > Extensions and themes.

    Remove every extension you do not remember adding, especially search, new tab, coupon, PDF, weather or video downloader add-ons. Check every browser and every profile, because each keeps its own list.

    If an extension has no Remove button or comes back, a browser policy holds it (see "Managed by your organization" in the procedure below). The pages are the same on Windows 11 and Windows 10.

    Chrome menu with Extensions and Manage extensions highlighted
    Chrome on Windows 11: More > Extensions > Manage extensions.

    Full procedure with screenshots: Remove a browser extension

  2. Step 2: Uninstall Possible Suspicious Activity" virus

    Possible Suspicious Activity" virus is removed like any other program, from the list of installed apps. In Windows 11 that is Settings > Apps > Installed apps, in Windows 10 Settings > Apps > Apps & features, and in both you can also use Control Panel > Programs and Features.

    Select Possible Suspicious Activity" virus, click Uninstall and follow the uninstaller to the end. Then look at the entries just above and below it when the list is sorted by date: bundled programs install at the same minute.

    Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix

  3. Step 3: Reset the browser

    A reset removes what the steps above could miss:

    • changed start pages
    • site permissions
    • hidden settings

    In Chrome open Settings > Reset settings > Restore settings to their original defaults; in Edge Settings > Reset settings; in Firefox Help > More troubleshooting information > Refresh Firefox.

    Tip: Bookmarks and saved passwords stay, while extensions are turned off and the search engine and start page return to the defaults.

    Reset every browser on the PC, including Edge, which Windows 11 and Windows 10 always have.

    Chrome Settings page with the Reset settings section open
    Chrome on Windows 11: Settings > Reset settings.

    Full procedure with screenshots: Reset a browser and fix a hijacked search engine

  4. Step 4: Scan the PC, then run the offline scan

    A scan finds the parts of Possible Suspicious Activity" virus that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Instructions for each browser and system

The detailed steps for every browser and system this guide covers. Open the one you use.

Uninstall from Windows

Uninstall from Windows 10/8:

  1. Type Control Panel into the Windows search box and open the result.
  2. Under Programs, select Uninstall a program.Uninstall from Windows 10/8

Uninstall from Windows 7/XP:

  1. Click on Windows Start > Control Panel (Windows XP users should click on Add/Remove Programs).
  2. In Control Panel, select Programs > Uninstall a program.Uninstall from Windows 7/XP

Remove the unwanted program:

  1. In the Programs and Features window, look for any recently installed suspicious entries, select them, and click Uninstall.
  2. If User Account Control appears, click Yes to confirm, then complete the removal.Uninstall the unwanted program from Windows
Remove from Google Chrome

Delete malicious extensions from Google Chrome:

  1. Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
  2. In the newly opened window, you will see all the installed extensions. Uninstall all suspicious extensions related to the unwanted program by clicking Remove.Remove extensions from Chrome

Clear cache and web data from Chrome:

  1. Click on Menu and pick Settings.
  2. Under Privacy and security, select Clear browsing data.
  3. Select Browsing history, Cookies and other site data, as well as Cached images and files.
  4. Click Clear data.Clear cache and web data from Chrome

Change your homepage:

  1. Click menu and choose Settings.
  2. Look for a suspicious site in the On startup section.
  3. Click on Open a specific or set of pages and click on three dots to find the Remove option.

Reset Google Chrome:

If the previous methods did not help you, reset Google Chrome to eliminate all the unwanted components:

  1. Click on Menu and select Settings.
  2. In the Settings, scroll down and click Advanced.
  3. Scroll down and locate Reset and clean up section.
  4. Now click Restore settings to their original defaults.
  5. Confirm with Reset settings.Reset Chrome 2
Remove from Microsoft Edge

Delete unwanted extensions from MS Edge:

  1. Select Menu (three horizontal dots at the top-right of the browser window) and pick Extensions.
  2. From the list, pick the extension and click on the Gear icon.
  3. Click Remove.Remove extensions from Edge

Clear cookies and other browser data:

  1. Click on the Menu (three horizontal dots at the top-right of the browser window) and select Settings > Privacy, search, and services..
  2. Under Clear browsing data, pick Choose what to clear.
  3. Select Cookies and other site data and Cached images and files. (apart from passwords, although you might want to include Media licenses as well, if applicable) and click on Clear.Clear Edge browsing data

Restore new tab and homepage settings:

  1. Click the menu icon and choose Settings.
  2. Then find On startup section.
  3. Click Remove next to any suspicious startup page.

Reset MS Edge if the above steps did not work:

  1. Press on Ctrl + Shift + Esc to open Task Manager.
  2. Click on More details arrow at the bottom of the window.
  3. Select Details tab.
  4. Now scroll down and locate every entry with Microsoft Edge name in it. Right-click on each of them and select End Task to stop MS Edge from running.Reset MS Edge
Instructions for Chromium-based Edge

Delete extensions from MS Edge (Chromium):

  1. Open Edge and click select Settings > Extensions.
  2. Delete unwanted extensions by clicking Remove.Remove extensions from Chromium Edge

Clear cache and site data:

  1. Click on Menu and go to Settings.
  2. Select Privacy, search and services.
  3. Under Clear browsing data, pick Choose what to clear.
  4. Under Time range, pick All time.
  5. Select Clear now.Clear browser data from Chroum Edge

Reset Chromium-based MS Edge:

  1. Click on Menu and select Settings.
  2. On the left side, pick Reset settings.
  3. Select Restore settings to their default values.
  4. Confirm with Reset.
  5. This will disable extensions and reset startup pages but will not delete bookmarks, saved passwords, or browsing history.Reset Chromium Edge
Remove from Mozilla Firefox (FF)

Remove dangerous extensions:

  1. Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
  2. Select Add-ons.
  3. In here, select the unwanted extension and click Remove.Remove extensions from Firefox

Reset the homepage:

  1. Click three horizontal lines at the top right corner to open the menu.
  2. Choose Settings.
  3. Under Home, set your preferred homepage and new tab settings.

Clear cookies and site data:

  1. Click Menu and pick Settings.
  2. Go to Privacy & Security section.
  3. Scroll down to locate Cookies and Site Data.
  4. Click on Clear Data...
  5. Select Cookies and Site Data and Temporary cached files and pages, then click Clear.Clear cookies and site data from Firefox

Reset Mozilla Firefox

If clearing the browser as explained above did not help, reset Mozilla Firefox:

  1. Open Mozilla Firefox browser and click the Menu.
  2. Go to Help and then choose Troubleshooting Information.Reset Firefox 1
  3. Under Give Firefox a tune up section, click on Refresh Firefox...
  4. Once the pop-up shows up, confirm the action by pressing on Refresh Firefox.Reset Firefox 2
Delete from Safari

Remove dangerous extensions:

  1. Open Safari, click Safari in the menu at the top-left of the screen, and select Preferences.
  2. Go to the Extensions tab, look for any suspicious entries, and click Uninstall to remove them.Remove extensions from Safari

Clear history and website data:

  1. Click Safari in the menu and pick Clear History.
  2. Set Clear to all history and confirm with Clear History.Clear history from Safari

Reset Safari:

  1. Click Safari in the menu and select Preferences > Advanced.
  2. Enable Show Develop menu in menu bar.
  3. From the menu bar, click Develop and select Empty Caches.Reset Safari
Delete from macOS

Mac OS users should be wary of "Possible Suspicious Activity" scam types. Theey might be targeted with the iOS counterparts of this felony.

Remove the unwanted application:

  1. From the menu bar, select Go > Applications.
  2. In the Applications folder, look for any suspicious entries, then drag them to Trash (or right-click and pick Move to Trash).Uninstall from Mac

Delete leftover files and folders:

  1. Select Go > Go to Folder.
  2. Enter /Library/Application Support and remove any suspicious folders related to the unwanted program.
  3. Repeat the same check in the /Library/LaunchAgents and /Library/LaunchDaemons folders, deleting any suspicious entries.Delete leftover files from Mac
  4. Finally, empty the Trash to permanently remove the leftovers.
Reset Internet Explorer

Remove dangerous add-ons:

  1. Open Internet Explorer, click on the Gear icon (IE menu) on the top-right corner of the browser
  2. Pick Manage Add-ons.
  3. You will see a Manage Add-ons window. Here, look for suspicious plugins. Click on these entries and select Disable.Remove add-ons from Internet Explorer

Change your homepage if it was altered:

  1. Open IE and click on the Gear icon.
  2. Select Internet Options.
  3. In the General tab, delete the Home page address and replace it by your preferred one (for example, Google.com).
  4. Click Apply and then select OK.Reset IE homepage

Delete temporary files:

  1. Press on the Gear icon and select Internet Options.
  2. Under Browsing history, click Delete...
  3. Select relevant fields and press Delete.Clear temporary files from Internet Explorer

Reset Internet Explorer:

  1. Click on Gear icon > Internet options and select Advanced tab.
  2. Select Reset.
  3. In the new window, check Delete personal settings and select Reset.Reset Internet Explorer

Stream videos without limitations, no matter where you are

There are multiple parties that could find out almost anything about you by checking your online activity.

While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.

Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.

Data backups are important - recover your lost files

Ransomware is one of the biggest threats to personal data.

Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.

While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.

From our report of Oct 2017 · not reviewed since

Remove Possible Suspicious Activity virus with ease

First of all, you need to exit the tech support scam site.

Click on CTRL+SHIFT+ESC. Find your browser commands in the Task Manager, right-click on them and then choose "End task."

Now restart the browser. Enter the Settings and clear cookies as well browsing data. In case the redirect page still emerges, reset the browser to remove "Possible Suspicious Activity" virus elements.

It is also advised to scan the browser. The tool will complete "Possible Suspicious Activity" removal procedure. This scam might appear not only in English but in French, Hungarian or Estonian sites.

Questions about Possible Suspicious Activity" virus

What is Possible Suspicious Activity" virus and why is it on my PC?

Possible Suspicious Activity" virus is a program that was installed on the PC, most likely together with something else you downloaded. Free software sites and many installers add extra programs on setup pages with pre-ticked boxes, so the extra install looks like your choice even though nobody read the page.

Check the install date in Settings, Apps, Installed apps: the program you installed that day is the probable carrier. If you do not need Possible Suspicious Activity" virus, uninstall it. If it belongs to your hardware or to a program you use, search its exact name and publisher first, because drivers and their tools can have unfamiliar names.

How do I stop programs like Possible Suspicious Activity" virus from being installed again?

Most unwanted programs arrive through installers, so the fix is in how you install software. Download programs from their official sites or the Microsoft Store, not from download portals or ads above search results. During setup, choose Custom or Advanced installation and untick every extra offer, including browsers, toolbars and optimizers.

Decline update prompts that appear inside other programs unless you know them. In Windows Security, turn on reputation-based protection and potentially unwanted app blocking. These steps would most likely have stopped Possible Suspicious Activity" virus before it reached the app list.

Can adware slow down my PC?

Yes. Adware runs in the background, loads ad scripts, opens extra tabs and contacts its servers, all of which use processor time, memory and bandwidth. Ad-heavy extensions also slow down every page, because they inspect and change it before you see it.

The effect is strongest on older PCs and when several adware programs arrived together. After removal, restart the PC and check Task Manager for anything still using a lot of resources that you do not recognise. Speed usually returns to normal once the ads stop.

Does adware steal passwords?

Ordinary adware is built to show ads, not to steal logins, and most of it never touches saved passwords. The line is blurry, though. Extensions that can read every page could capture what you type, and adware ads sometimes lead to phishing pages that ask for passwords directly.

If you entered credentials on a page reached through an ad, change that password from a clean device and turn on two-step verification. Otherwise, removing adware extension and clearing cookies is usually enough.

I clicked on one of the ads. Am I infected?

Probably not. Clicking an ad usually only opens a page, and a page cannot install programs on an up-to-date Windows PC without your help.

You are at risk only if you then downloaded and ran a file, allowed notifications, entered card or login details, or called a phone number shown on the page. Delete any download and run a full and offline scan.

Change passwords you typed, from a clean device. Call your bank if you gave card details. If you called a number or allowed remote access, see the next question.

Why didn't my antivirus catch Possible Suspicious Activity" virus?

Many security products do not block adware or notification sites by default, because users often agreed to them, even through a misleading prompt. Notification spam installs nothing at all, so there is no file to detect.

In Windows 11 you can make Microsoft Defender block potentially unwanted apps: open Windows Security > App & browser control > Reputation-based protection settings and turn on Potentially unwanted app blocking. If notifications caused the pop-ups, no scanner will report them; the fix is in the browser's site settings.

An ad showed a phone number and I called it. What now?

The number belongs to scammers, not to Microsoft or an antivirus company. If you only talked, hang up and do not call back. If you let them connect to the PC, disconnect it from the internet, uninstall the remote access program they used, such as AnyDesk, TeamViewer, ScreenConnect or UltraViewer, and run a full and offline scan.

If you paid or gave bank details, call your bank at once on the number printed on your card. Change any passwords you typed while they were connected, and report the call.

How did Possible Suspicious Activity get on my computer?

Observing the tendency, most likely, you could get directed to such scam when you browse illegal movie streaming sites or torrent sharing domains. Software of this kind often comes bundled with free programs, fake updates or downloads from unofficial sites.

It can also arrive through a browser extension or a notification you allowed on a spam page. Think back to what you installed or allowed just before the first ad or redirect appeared.

Will Fortect remove Possible Suspicious Activity" virus?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Possible Suspicious Activity" virus, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

  1. Veeam: What is Hyper-V technology? (read October 7, 2026)
  2. GrahamCluley: Taboola ads exploited to serve up tech support scams (read October 7, 2026)
  3. Google Chrome Help: Use notifications to get alerts (no longer online) (read October 7, 2026)
  4. FTC: How to recognize, remove and avoid malware (read October 7, 2026)
  5. Microsoft Learn: Microsoft Defender Offline (read October 7, 2026)

More removal guides

Remove Immediate Action Required

Immediate Action Required is a fake notification that might pop-up out of nowhere and prompt users to download useless bogus software Immediate Action Required is a scam that users mightAdwareMedium riskUgnius Kiguolis ·

Remove ReceiverHelper Mac virus

ReceiverHelper virus is a high threat to your personal safety and Mac security ReceiverHelper is a harmful application targeting Mac devices, classified under the Adload malware family. It is notoriousAdwareMedium riskJake Doevan ·

Remove Casalemedia

Casalemedia is a legal advertising service but is sometimes abused by crooks to gain personal income Casalemedia is a legitimate advertising service that provides assistance in monetizing on online contentAdwareMedium riskJake Doevan ·

Remove D1ue3yi0hkdsdl.cloudfront.net ads

D1ue3yi0hkdsdl.cloudfront.net ads is the content related to scam campaigns and fake errors or warnings D1ue3yi0hkdsdl.cloudfront.net is the program that causes notifications and advertisements that may appear unexpectedly, preventing you fromAdwareMedium riskJulie Splinters ·

Questions and experiences: Possible Suspicious Activity" virus

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,442 members already hereReading, writing, commenting and voting. 0 verified · 167 joined this year