Cyber Security News

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing the antivirus software protecting their computers.

The pages claim to inspect a device, report serious security failures, and insist that third-party antivirus products are no longer supported by Windows. The message is false, but it is designed to feel urgent and personal.

The scam sites collect basic browser information, such as screen size and device details, then use it to make a made-up scan report look tailored to the visitor’s computer. The real goal is to push victims toward a fake refund process.

Malwarebytes said in a report shared with Cyber Security News that it found 11 related sites hosted on the same server.

Each site uses similar SysScan branding, falsely presents itself as a Microsoft-linked security check, and tells visitors that their antivirus is the source of supposed system problems.

The operation does not rely on a file download at the start. Instead, it uses a convincing website, a false security score, a customer-information form, and a promised phone call to gradually gain trust.

By the time scammers request remote access or banking details, victims may already believe they are working through a legitimate support or refund process.

Fake Microsoft Security Scan Tells You to Remove Antivirus

The sites display warnings that a browser cannot genuinely verify. They claim to find problems involving browser isolation, memory weaknesses, firmware security settings, Windows patches, and processor performance.

Yet a website cannot inspect those deep parts of a computer or accurately determine whether antivirus protection is functioning.

Some information on the page is real, which helps the deception. A browser can reveal details such as operating system, processor count, screen dimensions, available features, and certain permissions.

Fake scan (Source – Malwarebytes)

However, the scammers combine those ordinary details with fixed warnings to create a report that appears technical and alarming.

Researchers found that many scan findings are hard-coded into the pages rather than produced by a real assessment.

The score is also deliberately restricted to between 13 and 30 out of 100, ensuring that nobody receives a healthy result. This type of pressure tactic resembles other fake antivirus website campaigns that use fear to drive unsafe decisions.

The most damaging instruction is the demand to uninstall antivirus software. Windows can place Microsoft Defender Antivirus into a passive state when a compatible third-party security product is installed, but that does not mean Windows has stopped supporting other antivirus products.

Recent reporting on tools that can disable Windows Defender protection also shows why attackers value removing or weakening endpoint defenses.

People should treat any web page that claims to complete a full computer security scan with caution. A legitimate company will not require someone to remove protective software as a condition for support, a refund, or a security check.

Closing the page is the safest response when the scan produces only bad results and demands immediate action.

Refund Call Sets Remote Access Trap

After the fake scan, the sites present a form that asks for extensive personal information. It requests names, home addresses, phone numbers, email addresses, bank names, claimed refund amounts, cryptocurrency usernames, antivirus details, and remote-access session credentials.

The form also contains fields for an agent ID, agent name, and company, suggesting that an operator may guide the victim through it during a phone call.

Victims can select from 30 remote-access tools, giving scammers a way to take control of the computer after persuading them that a refund must be processed.

Once submitted, the information is bundled and sent to Telegram through its bot API, according to Malwarebytes.

The victim is then redirected to a page claiming that a refund manager will call within three to five minutes, while a looping office video attempts to make the wait feel official.

This handoff is important because remote-access software can give criminals a direct view of sensitive accounts and files.

Similar refund fraud has involved legitimate remote monitoring tools, which attackers misuse to manipulate bank activity or maintain control of a victim’s device, as explained in coverage of remote monitoring software abuse.

Fake page (Source – Malwarebytes)

Anyone who has already granted access should disconnect the device from the internet, remove the remote-access tool, reinstall the removed antivirus product, update it, and run a full scan.

If banking information was shared or online banking was accessed during the call, contact the bank immediately through a phone number found independently, then change email and banking passwords from a separate trusted device.

Fake support pages often depend on familiar logos and frightening warnings rather than genuine proof. Previous fake Windows Defender alerts have likewise used trusted branding to steer users toward fraudulent support channels.

Victims should not let embarrassment delay reporting, since swift action can reduce the chance of financial loss or further account compromise.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IP address157.230.180.90Hosting server associated with the scam sites
Domaindetectsysscanner[.]atScam site domain
Domaindetectsysscanner[.]comScam site domain
Domaindetectsysscanner[.]deScam site domain
Domaindetectsysscanner[.]in[.]netScam site domain
Domaindetectsysscanner[.]xn--q9jyb4cScam site domain
Domaindetsysscanner[.]comScam site domain
Domaindetsysscanner[.]deScam site domain
Domaindetsysscanner[.]xn--q9jyb4cScam site domain
Domaintechsysscanner[.]comScam site domain
Domaintechsysscanner[.]lolScam site domain
Domaintlcscanner[.]comScam site domain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records

A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85…

2 minutes ago

AliExpress Uses WebAudio API and Zero-Gain Audio Graphs for Silent Device Fingerprinting

AliExpress's homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears…

6 minutes ago

Tata’s B2B Platform Flaw Enables Account Takeover Just by Knowing Victim’s Phone Number

A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium…

12 minutes ago

ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer

ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is…

1 hour ago

Microsoft August 2026 Update Breaks When Generating PDF/XPS Content

Microsoft has confirmed that its August 2026 .NET Framework cumulative updates are causing printing failures…

1 hour ago

Multiple Zscaler Client Connector Vulnerabilities Enable RCE Attacks

Multiple vulnerabilities affecting Zscaler Client Connector have been disclosed, potentially allowing remote code execution on…

1 hour ago