Fake Microsoft scans tell you to delete your antivirus

A website cannot tell whether your computer has a Trusted Platform Module, or whether your memory is vulnerable to Rowhammer. Eleven websites found by Malwarebytes claim to do exactly that, and every one of them reaches the same verdict: your machine is in trouble, and your antivirus is the reason.

That verdict is the opening move in a refund scam.

A scan that cannot be passed

The sites brand themselves SysScan, carry Microsoft branding, and all run from a single host. The scan does read some genuine values, which is part of why it convinces: user agent, screen dimensions, device memory and processor count are all things a browser hands over willingly. The conclusions have nothing to do with those readings.

Fifty of the findings are fixed text baked into the page, grouped in blocks the developer labelled as fake checks. One of them reports how many days behind your security patches are, using a number generated at random each time the check runs. Run the scan twice and you get two answers. Malwarebytes found the score is clamped in code to between 13 and 30 out of 100, so passing is not a possible outcome. Even the honest readings get bent: an encrypted connection is reported as a downgrade risk, cookies enabled is a warning, cookies disabled is a failure, and a fully patched test browser came back as possibly outdated.

Why they want your antivirus gone

Telling someone to uninstall their security software is the most consequential instruction on the page, and it serves the operators twice. It clears out whatever would object to what gets installed next, and it tells the scammers which product the victim was running: the site records the answer from a list of 28 named products plus an Other option. Enterprise products appear on that list, which suggests the operators expect to reach people on work machines.

The claim is made plausible by distorting something true. Windows does include Microsoft Defender Antivirus, and Defender does move into a passive state when a compatible third party product is installed. That is not the same as Windows dropping support for third party antivirus, which it has not done.

The form looks built for the caller

After the scan comes a customer information form asking for name, address, phone numbers, email, refund amount and reason, bank name, cryptocurrency username, antivirus product, and the ID and password for a remote access session, choosable from 30 different tools. It also asks for an Agent ID, Agent Name and Company. Malwarebytes is careful here: the code cannot prove who types what. But agent fields have little purpose on a form meant only for a customer.

One field asks whether explicit content is involved, which fits a pattern the researchers highlight: embarrassment keeps victims from telling their bank or their family.

On submit, the browser bundles the customer, agent, remote access, antivirus and banking details into one message and posts it straight to Telegram's bot API. There is no backend at all, which makes the sites cheap to stand up and easy to abandon, and it contradicts the page's own claim, stated in several places, that no data is collected or sent. The victim is then parked on a page promising a refund manager will call within three to five minutes, playing a looping synthetic video they cannot pause or exit.

How to spot one before it costs you

A browser cannot inspect firmware settings, antivirus status or your exact patch level, and a diagnostic that can never return a pass is not diagnosing anything. Microsoft still supports third party antivirus. No legitimate refund asks you to uninstall security software, install remote access tools, or hand over banking or cryptocurrency details. If this has already happened, disconnect the machine, remove the remote access tool, reinstall and update your antivirus, and call your bank on a number you look up yourself.

Defanged indicators from the original write-up: the eleven domains share the host 157[.]230[.]180[.]90 and include detectsysscanner[.]com, detsysscanner[.]com, techsysscanner[.]com, techsysscanner[.]lol and tlcscanner[.]com.

The pattern repeats across a whole genre of fake diagnostics. We recently covered bogus wallet safety checkers and a fake pharmacy refund page. The tell is always the same: a free check you did not ask for, and a result you are supposed to panic about.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions