A new web-based scam has emerged, leveraging counterfeit Microsoft-branded security scans to instill fear in users, prompting them to uninstall their antivirus software. These deceptive pages purport to conduct a thorough inspection of devices, reporting alarming security failures and falsely asserting that third-party antivirus products are unsupported by Windows. Although the claims are entirely fabricated, they are crafted to evoke a sense of urgency and personal concern.
The scam websites gather basic browser information, such as screen size and device specifications, to fabricate a scan report that appears customized for each visitor’s computer. The ultimate aim is to mislead victims into engaging with a fraudulent refund process.
According to a report from Malwarebytes shared with Cyber Security News, investigators identified 11 related sites hosted on the same server. Each of these sites employs similar branding under the name SysScan, misleadingly presenting themselves as legitimate Microsoft security checks while insisting that users’ antivirus programs are the root cause of purported system issues.
Interestingly, the operation does not initiate with a file download. Instead, it relies on a convincing website, a fabricated security score, a customer information form, and a promised follow-up phone call to gradually build trust with unsuspecting visitors. By the time scammers request remote access or banking details, victims may already be convinced they are navigating a legitimate support or refund process.
Fake Microsoft Security Scan Tells You to Remove Antivirus
The scam sites display alarming warnings that cannot be genuinely verified by a browser. They claim to uncover issues related to browser isolation, memory vulnerabilities, firmware security settings, Windows updates, and processor performance. However, it is important to note that a website cannot delve into these intricate aspects of a computer or accurately assess whether antivirus protection is functioning properly.
Some of the information presented on these pages is legitimate, which enhances the deception. Browsers can reveal details such as the operating system, processor count, screen dimensions, available features, and certain permissions. Scammers cleverly combine these ordinary details with pre-written warnings to generate a report that appears both technical and alarming.
Researchers have discovered that many of the scan results are hard-coded into the web pages rather than derived from any genuine assessment. The security score is intentionally limited to a range between 13 and 30 out of 100, ensuring that no one receives a favorable result. This pressure tactic mirrors other fraudulent antivirus campaigns that exploit fear to drive users toward unsafe decisions.
The most detrimental instruction issued by these scams is the directive to uninstall antivirus software. While Windows can place Microsoft Defender Antivirus into a passive state when a compatible third-party security product is installed, this does not imply that Windows has ceased support for other antivirus solutions. Recent reports highlighting tools capable of disabling Windows Defender protection underscore the attackers’ motive to weaken or eliminate endpoint defenses.
Individuals should approach any webpage claiming to conduct a comprehensive computer security scan with skepticism. A reputable company will never require users to remove protective software as a prerequisite for support, refunds, or security checks. The safest course of action when confronted with a scan yielding only negative results and demanding immediate action is to close the page.
Refund Call Sets Remote Access Trap
Following the fake scan, the sites present a form requesting extensive personal information. This form solicits names, home addresses, phone numbers, email addresses, bank names, claimed refund amounts, cryptocurrency usernames, antivirus details, and even remote-access session credentials. It also includes fields for an agent ID, agent name, and company, implying that an operator may assist the victim during a subsequent phone call.
Victims are given the option to select from 30 remote-access tools, providing scammers with a pathway to take control of the computer after convincing the individual that a refund must be processed. Once submitted, the gathered information is sent to Telegram via its bot API, as reported by Malwarebytes.
After this step, victims are redirected to a page claiming that a refund manager will call within three to five minutes, while a looping office video attempts to lend an air of legitimacy to the wait. This transition is crucial, as remote-access software can grant criminals direct visibility into sensitive accounts and files.
Similar refund fraud schemes have exploited legitimate remote monitoring tools, which attackers misuse to manipulate banking activities or maintain control over a victim’s device. For those who have already granted access, it is advisable to disconnect the device from the internet, remove the remote-access tool, reinstall the antivirus software, update it, and conduct a full scan. If any banking information was shared or online banking was accessed during the call, it is imperative to contact the bank immediately using a phone number sourced independently, followed by changing email and banking passwords from a separate trusted device.
Fake support pages often rely on familiar logos and alarming warnings rather than authentic proof. Previous instances of fraudulent Windows Defender alerts have similarly utilized trusted branding to mislead users toward illegitimate support channels. Victims should not allow embarrassment to hinder timely reporting, as prompt action can significantly mitigate the risk of financial loss or further account compromise.
Indicators of compromise (IoCs):
| Type | Indicator | Description |
|---|---|---|
| IP address | 157.230.180.90 |
Hosting server associated with the scam sites |
| Domain | detectsysscanner[.]at |
Scam site domain |
| Domain | detectsysscanner[.]com |
Scam site domain |
| Domain | detectsysscanner[.]de |
Scam site domain |
| Domain | detectsysscanner[.]in[.]net |
Scam site domain |
| Domain | detectsysscanner[.]xn--q9jyb4c |
Scam site domain |
| Domain | detsysscanner[.]com |
Scam site domain |
| Domain | detsysscanner[.]de |
Scam site domain |
| Domain | detsysscanner[.]xn--q9jyb4c |
Scam site domain |
| Domain | techsysscanner[.]com |
Scam site domain |
| Domain | techsysscanner[.]lol |
Scam site domain |
| Domain | tlcscanner[.]com |
Scam site domain |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC.