A new web-based scam is using counterfeit Microsoft-branded security scans to deceive users into uninstalling their antivirus software. The scam sites falsely claim to conduct thorough inspections of devices, reporting alarming security failures and asserting that third-party antivirus products are unsupported by Windows. They gather basic browser information to create customized-looking scan reports. Researchers identified 11 related scam sites hosted on a single server, branded as SysScan. The sites do not initiate file downloads but rely on convincing web pages and fabricated security scores to build trust with victims. They present fake warnings about various system issues that a website cannot genuinely verify. The scam includes a form requesting extensive personal information and offers a follow-up call, during which scammers may request remote access to the victim's computer. The information collected is sent to Telegram via its bot API. Victims are advised to disconnect from the internet and take immediate action if they have granted access. The scam sites are associated with specific IP addresses and domains, which are listed as indicators of compromise.