Skip to content

SecurityNot yet confirmed elsewhere1 publisher3 min readPublished

The refund scam that asks you to uninstall your antivirus, then writes down which one

Eleven look-alike sites run a scan whose score is capped at 30 out of 100, then record which of 28 security products the victim removed. Endpoint tampering by consent, over the phone.

The Watch · Security desk

How we use AISend a correction

Photograph accompanying The refund scam that asks you to uninstall your antivirus, then writes down which one
Photo: malwarebytes.com

What happened

  • Malwarebytes found eleven look-alike sites on one host, branded as Microsoft and calling themselves SysScan, offering to check whether your antivirus works.
  • Each concludes that Windows no longer supports third-party antivirus and that the visitor should uninstall it at once. It does, and they should not.
  • The site logs which of 28 named security products the victim removed, and enterprise products are on that list.
  • Malwarebytes describes the whole sequence as the front end of a refund scam that moves the victim to a phone call.

Why it matters

  • constraint Tamper protection is built for an attacker fighting the agent. Here the licensed user removes it on purpose, so the control most likely to stop it is the one being overridden.
  • exposure Because enterprise products sit on the pick-list, a managed work laptop can lose its agent mid-call, and the removal will read as authorised to whoever reviews it later.
  • capability By the time the phone rings, the caller knows which product is gone and which of 30 remote-access tools to talk the victim through installing.
  • decision Help desks and vendors now have to decide whether to explain Defender's passive state to users unprompted, since that single true detail is what makes the uninstall request sound plausible.

Fifty of the findings these pages display are fixed text, sitting in blocks the developer labelled as fake checks [7]. The genuine browser data the page reads is what makes them land: user agent, screen dimensions, device memory, processor count, permission states, network information and page timings all come back correct [6], so the assertion that your kernel page-table isolation is inactive or that no Trusted Platform Module was found arrives wearing the same clothes [8].

The arithmetic gives it away. The score is constrained in code to between 13 and 30 out of 100 [10], which leaves the whole diagnostic a seventeen-point range [18] on a scale where passing is not an available result [10]. Malwarebytes ran it against a fully updated test browser and got "possibly outdated" [11]. An encrypted connection is reported as a downgrade risk, and cookies produce a warning when enabled and a failure when disabled [12]. Two scans of the same machine minutes apart disagree about how far behind its patches are, because that number is generated at random each time [9].

The instruction to uninstall is the part worth an operator's attention. It clears the path for remote-access software and anything else installed during the session, and it hands the scammers the name of the product that was there [13]. That answer goes into a list of 28 named products plus an Other option, and enterprise security software is among them [14].

Nothing in that sequence is technical. No exploit, no driver abuse, no signed binary killing a service. The licensed user removes the agent themselves, deliberately, while on a call with someone holding an Agent ID [17]. Consent is the hardest condition for tooling to argue with, and it is the whole mechanism here.

The pitch works because it bends something true by one degree. Microsoft Defender Antivirus can move into a passive state when a compatible third-party product is installed [15], so a user who has noticed that in Windows Security has already half-assembled the story the site is selling. Microsoft still supports third-party antivirus, and no legitimate refund requires removing security tools or installing remote access [16].

The form after the scan settles the question of who this is built for. It asks for bank name, cryptocurrency username, refund amount and reason, and the ID and password for a remote-access session, with 30 tools to choose from [1]. It also requires Agent ID, Agent Name and Company [17], which are fields you complete when you are the one placing the call. Eleven near-identical sites on one host [2] is the same fact from the other end: the scan is the intake form, and the call is the product.

What to watch

  • Whether the eleven sites come down, and how fast the same template reappears under new names on a different host.
  • Whether any employer reports a managed endpoint agent being uninstalled during one of these calls, which would confirm the enterprise entries on the product list are being worked.
  • Whether the operator-facing fields turn up in other refund-scam kits, which would point to a shared template rather than one crew.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence74
Adoption24
Hype gap+8
Incentives72
Confidence64
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The form collects name, address, phone numbers, email address, refund amount and reason, bank name, cryptocurrency username, antivirus product, and the ID and password for a remote-access session, with a choice of 30 different remote-access tools.

  2. [2]

    Malwarebytes found eleven sites on a single host offering to check whether your antivirus is working, calling themselves SysScan and carrying Microsoft branding; the names vary but they work in essentially the same way.

    ReportedSupportedSource: Malwarebytes threat intelligenceView cited source
  3. [3]

    The sites claim Windows no longer supports third-party antivirus and tell the visitor to uninstall it immediately, which Malwarebytes says is false.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. malwarebytes.com

    1 article · August 24, 2026

    Fake Microsoft security scans trick victims into uninstalling their antivirus

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories