A network of fraudulent websites, branded as SysScan, has been discovered, which falsely claims to evaluate antivirus software effectiveness through deceptive security scans. These sites manipulate users into uninstalling legitimate antivirus products and disclosing sensitive personal and banking information. Eleven distinct domains associated with SysScan have been identified, all hosted on a single server. The fraudulent scans generate misleading results based on static findings rather than actual system assessments, and users are coerced into believing their computers are at risk. The scams misrepresent normal browser behaviors as security threats and instruct victims to uninstall their antivirus software, compromising their defenses. The operation targets both individual and business users, collecting extensive personal information and utilizing remote-access tools. The data submitted is sent to Telegram via its bot API. Users are advised to disconnect from the internet and secure their devices if they suspect they have been compromised. Indicators of compromise include specific IP addresses and domains associated with the scam.