A surge of websites purporting to verify the functionality of antivirus software has emerged, branding themselves as SysScan and leveraging Microsoft’s name. These sites uniformly assert that users’ computers are plagued with serious issues, attributing the blame to the antivirus software installed on their systems.
These claims are misleading, as they suggest that Windows no longer supports third-party antivirus solutions, urging users to uninstall them immediately. This assertion is categorically false and marks the initial step in a refund scam designed to lure victims into a trap where they may unwittingly disclose personal, banking, and remote-access information.
Our investigation uncovered eleven such websites hosted on a single server. While the names differ, their operational methods are strikingly similar: they execute a convincing yet fraudulent security scan, inform the victim that their antivirus is the source of their computer’s problems, gather personal information, and set the stage for a purported refund call.
What to know if you see one of these scans
It’s crucial to understand that a website cannot conduct a genuine security scan. It can only access basic browser data, such as your operating system, screen size, and approximate location—far from the capability to detect malware, memory issues, or missing security patches.
Microsoft continues to support third-party antivirus software, and any legitimate refund process will never require the uninstallation of security tools or the installation of remote-access software. If a site instructs you to do so, it is best to exit immediately.
Technical analysis
The scan reads real data and draws invented conclusions
The deceptive nature of these scams is partly rooted in their ability to measure real data. They can access information that a browser legitimately exposes, including user agent details, screen dimensions, device memory, processor count, and network information. This allows the results to appear tailored to the user’s machine.
However, the security conclusions drawn from these measurements are entirely fabricated. For instance, fifty of the findings are static text embedded within the page, categorized as fake checks. These include alarming claims such as compromised browser sandboxes, inactive kernel page-table isolation, and vulnerabilities related to memory and processor performance.
One particularly dubious finding even claims to report how many days behind security patches a user is, relying on a randomly generated number that changes with each scan. Even genuine checks are manipulated into warnings, with encrypted connections labeled as risks and standard browser features flagged as privacy concerns. Notably, the scoring system is rigged to yield results between 13 and 30 out of 100, ensuring that a passing score is impossible.
Why the scam tells you to uninstall your antivirus
Instructing users to remove their antivirus software is a critical tactic in this scam, serving two primary purposes. First, it eliminates any software that could obstruct subsequent actions, including the installation of remote-access tools. Second, it reveals which antivirus product the victim is using, as the site logs the specific software removed from a list of 28 recognized products.
This claim gains credibility through a distortion of truth. While Windows does include its own antivirus solution, Microsoft Defender Antivirus, it can enter a passive state when a compatible third-party product is installed. This, however, does not imply that Windows has ceased support for third-party antivirus solutions.
Following the scan, users are presented with a customer information form that collects extensive personal data, including name, address, phone numbers, email, refund amount, bank details, and even remote-access session credentials. The form is structured in a way that suggests it is meant to be filled out by an operator during a call, allowing them to view the victim’s screen.
Notably, one field even inquires whether explicit content is involved, preying on potential embarrassment to discourage victims from seeking help. Upon submission, the collected information is sent directly to a Telegram bot API, bypassing any formal application backend, which makes these sites inexpensive to operate and easy to dismantle when they attract scrutiny.
Then comes the supposed refund call
After submitting the form, victims are redirected to a page indicating that a refund manager will call within three to five minutes. This page features a looping video of a man in an office, designed to keep the victim engaged while they await contact.
The intent here is to reassure the victim that an official process is underway, creating a seamless transition to the next phase of the scam. By the time the caller begins to inquire about banking details, the victim has already been led through a series of manipulative steps, including the removal of their antivirus software and the submission of sensitive information.
The site shows signs of AI-generated code
Interestingly, the waiting page video appears to be synthetic, and the underlying code exhibits characteristics typical of AI-generated content. The comments within the code are heavily explanatory, often reflecting a self-narrating style common in AI programming tools, revealing the deliberate pacing of the scan and the tone of the spoken lines.
Some comments even acknowledge the deception directly, labeling blocks of invented findings as fake while describing exaggerated checks that utilize genuine values. Such elements suggest that the scam has been intricately woven into a broader template, tailored specifically for fraudulent purposes.
How to spot a fake computer security scan
Several warning signs can help identify scams like these:
- A website claims to find deep problems with your computer. A legitimate web page cannot inspect firmware settings, antivirus status, or memory vulnerabilities.
- Every result is bad. A diagnostic that cannot yield a passing result is not a true diagnostic.
- You’re told to uninstall your antivirus. Microsoft supports third-party security software on Windows.
- You’re asked to install remote-access software. Legitimate refunds do not require remote access to your computer.
- You’re asked for banking or cryptocurrency information. A reputable company should not need such details for a refund.
- The page relies on a familiar logo. A Microsoft or Apple logo does not guarantee the site’s legitimacy, as these sites can switch branding based on detected operating systems.
If this has already happened
If you have installed remote-access software or allowed someone to control your computer, disconnect from the internet and remove the remote-access tool. Reinstall your antivirus software, update it, and conduct a full scan.
If you provided banking information or granted access to your online banking, contact your bank immediately using a verified phone number. Inform them of the potential scam. Change your email and banking passwords from a trusted device.
Should any funds have been taken, report the incident to the Federal Trade Commission (FTC) at reportfraud.ftc.gov and the FBI’s Internet Crime Complaint Center (IC3) at ic3.gov. Do not let embarrassment deter you from seeking assistance; scammers often exploit this shame to silence victims. Acting swiftly is crucial to limiting any potential losses.
Indicators of compromise (IOCs)
Hosting: 157.230.180.90
Domains:
detectsysscanner[.]at
detectsysscanner[.]com
detectsysscanner[.]de
detectsysscanner[.]in[.]net
detectsysscanner[.]xn--q9jyb4c
detsysscanner[.]com
detsysscanner[.]de
detsysscanner[.]xn--q9jyb4c
techsysscanner[.]com
techsysscanner[.]lol
tlcscanner[.]com
Fake Microsoft security scans trick victims into uninstalling their antivirus
A surge of websites purporting to verify the functionality of antivirus software has emerged, branding themselves as SysScan and leveraging Microsoft’s name. These sites uniformly assert that users’ computers are plagued with serious issues, attributing the blame to the antivirus software installed on their systems.
These claims are misleading, as they suggest that Windows no longer supports third-party antivirus solutions, urging users to uninstall them immediately. This assertion is categorically false and marks the initial step in a refund scam designed to lure victims into a trap where they may unwittingly disclose personal, banking, and remote-access information.
Our investigation uncovered eleven such websites hosted on a single server. While the names differ, their operational methods are strikingly similar: they execute a convincing yet fraudulent security scan, inform the victim that their antivirus is the source of their computer’s problems, gather personal information, and set the stage for a purported refund call.
What to know if you see one of these scans
It’s crucial to understand that a website cannot conduct a genuine security scan. It can only access basic browser data, such as your operating system, screen size, and approximate location—far from the capability to detect malware, memory issues, or missing security patches.
Microsoft continues to support third-party antivirus software, and any legitimate refund process will never require the uninstallation of security tools or the installation of remote-access software. If a site instructs you to do so, it is best to exit immediately.
Technical analysis
The scan reads real data and draws invented conclusions
The deceptive nature of these scams is partly rooted in their ability to measure real data. They can access information that a browser legitimately exposes, including user agent details, screen dimensions, device memory, processor count, and network information. This allows the results to appear tailored to the user’s machine.
However, the security conclusions drawn from these measurements are entirely fabricated. For instance, fifty of the findings are static text embedded within the page, categorized as fake checks. These include alarming claims such as compromised browser sandboxes, inactive kernel page-table isolation, and vulnerabilities related to memory and processor performance.
One particularly dubious finding even claims to report how many days behind security patches a user is, relying on a randomly generated number that changes with each scan. Even genuine checks are manipulated into warnings, with encrypted connections labeled as risks and standard browser features flagged as privacy concerns. Notably, the scoring system is rigged to yield results between 13 and 30 out of 100, ensuring that a passing score is impossible.
Why the scam tells you to uninstall your antivirus
Instructing users to remove their antivirus software is a critical tactic in this scam, serving two primary purposes. First, it eliminates any software that could obstruct subsequent actions, including the installation of remote-access tools. Second, it reveals which antivirus product the victim is using, as the site logs the specific software removed from a list of 28 recognized products.
This claim gains credibility through a distortion of truth. While Windows does include its own antivirus solution, Microsoft Defender Antivirus, it can enter a passive state when a compatible third-party product is installed. This, however, does not imply that Windows has ceased support for third-party antivirus solutions.
The form appears built for the scammer, not the victim
Following the scan, users are presented with a customer information form that collects extensive personal data, including name, address, phone numbers, email, refund amount, bank details, and even remote-access session credentials. The form is structured in a way that suggests it is meant to be filled out by an operator during a call, allowing them to view the victim’s screen.
Notably, one field even inquires whether explicit content is involved, preying on potential embarrassment to discourage victims from seeking help. Upon submission, the collected information is sent directly to a Telegram bot API, bypassing any formal application backend, which makes these sites inexpensive to operate and easy to dismantle when they attract scrutiny.
Then comes the supposed refund call
After submitting the form, victims are redirected to a page indicating that a refund manager will call within three to five minutes. This page features a looping video of a man in an office, designed to keep the victim engaged while they await contact.
The intent here is to reassure the victim that an official process is underway, creating a seamless transition to the next phase of the scam. By the time the caller begins to inquire about banking details, the victim has already been led through a series of manipulative steps, including the removal of their antivirus software and the submission of sensitive information.
The site shows signs of AI-generated code
Interestingly, the waiting page video appears to be synthetic, and the underlying code exhibits characteristics typical of AI-generated content. The comments within the code are heavily explanatory, often reflecting a self-narrating style common in AI programming tools, revealing the deliberate pacing of the scan and the tone of the spoken lines.
Some comments even acknowledge the deception directly, labeling blocks of invented findings as fake while describing exaggerated checks that utilize genuine values. Such elements suggest that the scam has been intricately woven into a broader template, tailored specifically for fraudulent purposes.
How to spot a fake computer security scan
Several warning signs can help identify scams like these:
If this has already happened
If you have installed remote-access software or allowed someone to control your computer, disconnect from the internet and remove the remote-access tool. Reinstall your antivirus software, update it, and conduct a full scan.
If you provided banking information or granted access to your online banking, contact your bank immediately using a verified phone number. Inform them of the potential scam. Change your email and banking passwords from a trusted device.
Should any funds have been taken, report the incident to the Federal Trade Commission (FTC) at reportfraud.ftc.gov and the FBI’s Internet Crime Complaint Center (IC3) at ic3.gov. Do not let embarrassment deter you from seeking assistance; scammers often exploit this shame to silence victims. Acting swiftly is crucial to limiting any potential losses.
Indicators of compromise (IOCs)
Hosting:
157.230.180.90Domains:
detectsysscanner[.]atdetectsysscanner[.]comdetectsysscanner[.]dedetectsysscanner[.]in[.]netdetectsysscanner[.]xn--q9jyb4cdetsysscanner[.]comdetsysscanner[.]dedetsysscanner[.]xn--q9jyb4ctechsysscanner[.]comtechsysscanner[.]loltlcscanner[.]com