Fake Microsoft Security Scan Tricks Users into Removing Antivirus
Key Takeaways A new web-based scam leverages fake Microsoft-branded security scans to deceive users. Victims are manipulated into uninstalling legitimate antivirus software under false pretenses. The...
Key Takeaways
- A new web-based scam leverages fake Microsoft-branded security scans to deceive users.
- Victims are manipulated into uninstalling legitimate antivirus software under false pretenses.
- The scam employs tailored, but fabricated, scan reports and pushes for a fraudulent refund process.
- The ultimate goal is to gain remote access to victims’ computers and extract sensitive financial information.
- Eleven related scam sites, all using similar SysScan branding, have been identified.
Sophisticated Web Scam Targets Antivirus Software
A deceptive new online scheme is actively tricking users into removing their crucial antivirus protection by presenting fabricated Microsoft security alerts. These fraudulent web pages simulate a device scan, then falsely report severe security vulnerabilities and claim that third-party antivirus products are incompatible with Windows systems. This assertion is entirely untrue, yet the messaging is crafted to evoke urgency and a sense of personalized threat.
Table Of Content
The scam websites gather basic browser information, such as screen resolution and device specifics, to generate a seemingly customized scan report. This personalization enhances the illusion of legitimacy, but the true objective is to steer victims toward a bogus refund process. According to a Malwarebytes report, researchers have identified eleven interconnected sites operating from the same server, all participating in this coordinated attack.
The Anatomy of Deception: Fake Scans and False Claims
Each of these malicious sites employs similar “SysScan” branding and falsely portrays itself as an official Microsoft security check. They systematically inform visitors that their installed antivirus software is the root cause of alleged system issues. The attack does not rely on a direct file download; instead, it uses a meticulously designed website, a misleading security score, a data collection form, and the promise of a follow-up phone call to progressively build trust. By the time scammers request remote access or banking details, victims may already be convinced they are engaged in a legitimate support or refund procedure.
The scam pages display warnings that browsers are incapable of verifying. They falsely claim to detect problems related to browser isolation, memory integrity, firmware security settings, Windows updates, and processor performance. Crucially, a standard website cannot access these deep system components or accurately assess the functionality of a user’s antivirus protection.
To bolster credibility, the scam incorporates genuine, publicly available browser details such as the operating system, CPU core count, screen dimensions, and certain enabled features or permissions. However, these legitimate data points are then interwoven with pre-set, alarming warnings to construct a report that appears both technical and dire.
Researchers discovered that many of the “scan findings” are hard-coded into the web pages, rather than being the result of an actual system analysis. The fabricated security score is consistently low, ranging from 13 to 30 out of 100, ensuring no visitor receives a positive outcome. This fear-mongering tactic mirrors other fake antivirus website campaigns. The most dangerous instruction is the demand for users to uninstall their legitimate antivirus software. While Windows can indeed set Microsoft Defender Antivirus to a passive mode when another compatible security product is installed, this does not imply that Windows has ceased support for third-party solutions. Recent reports on tools capable of disabling Windows Defender protection underscore why attackers prioritize neutralizing endpoint defenses.
The “Refund” Trap: Remote Access and Financial Fraud
Following the deceptive scan, the sites present a form requesting a wide array of personal and financial information. This includes names, home addresses, phone numbers, email addresses, bank details, purported refund amounts, cryptocurrency usernames, antivirus product specifics, and even remote-access session credentials. The form also features fields for an “agent ID,” “agent name,” and “company,” suggesting that a scam operator might guide the victim through the process during a phone call. Victims are then offered a choice of 30 remote-access tools, providing criminals a pathway to seize control of the computer once they have convinced the user that a refund is pending.
Upon submission, the collected data is bundled and transmitted to Telegram via its bot API, as detailed by Malwarebytes. The victim is then redirected to a page promising a call from a “refund manager” within three to five minutes, accompanied by a looping office video designed to lend an air of authenticity to the wait. This handoff is critical, as remote-access software grants criminals a direct view of sensitive accounts and files. Similar refund scams have previously exploited legitimate remote monitoring tools to manipulate banking activities or maintain persistent control over a victim’s device, echoing the patterns observed in remote monitoring software abuse.
What You Should Do
- Be highly suspicious of any web page claiming to perform a comprehensive computer security scan. Legitimate companies will never demand the removal of protective software as a condition for support, a refund, or a security check.
- If a web scan produces only negative results and demands immediate action, close the page immediately.
- If you have already granted remote access to your device, disconnect it from the internet, remove any remote-access tools, reinstall and update your antivirus software, and perform a full system scan.
- If banking information was shared or online banking was accessed during the scam call, contact your bank immediately using a phone number obtained independently (e.g., from their official website or the back of your card).
- Change all email and banking passwords from a separate, trusted device.
- Do not let embarrassment prevent you from reporting such incidents. Prompt action can significantly mitigate potential financial losses or further account compromises.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| IP address | 157.230.180.90 |
Hosting server associated with the scam sites |
| Domain | detectsysscanner[.]at |
Scam site domain |
| Domain | detectsysscanner[.]com |
Scam site domain |
| Domain | detectsysscanner[.]de |
Scam site domain |
| Domain | detectsysscanner[.]in[.]net |
Scam site domain |
| Domain | detectsysscanner[.]xn--q9jyb4c |



No Comment! Be the first one.