Security1 distinct publisher3 min readPublished
Eleven look-alike sites run a scan whose score is capped at 30 out of 100, then record which of 28 security products the victim removed. Endpoint tampering by consent, over the phone.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Fifty of the findings these pages display are fixed text, sitting in blocks the developer labelled as fake checks [6]. The genuine browser data the page reads is what makes them land: user agent, screen dimensions, device memory, processor count, permission states, network information and page timings all come back correct [5], so the assertion that your kernel page-table isolation is inactive or that no Trusted Platform Module was found arrives wearing the same clothes [7].
The arithmetic gives it away. The score is constrained in code to between 13 and 30 out of 100 [9], which leaves the whole diagnostic a seventeen-point range [10] on a scale where passing is not an available result [9]. Malwarebytes ran it against a fully updated test browser and got "possibly outdated" [11]. An encrypted connection is reported as a downgrade risk, and cookies produce a warning when enabled and a failure when disabled [12]. Two scans of the same machine minutes apart disagree about how far behind its patches are, because that number is generated at random each time [8].
The instruction to uninstall is the part worth an operator's attention. It clears the path for remote-access software and anything else installed during the session, and it hands the scammers the name of the product that was there [13]. That answer goes into a list of 28 named products plus an Other option, and enterprise security software is among them [14].
Nothing in that sequence is technical. No exploit, no driver abuse, no signed binary killing a service. The licensed user removes the agent themselves, deliberately, while on a call with someone holding an Agent ID [17]. Consent is the hardest condition for tooling to argue with, and it is the whole mechanism here.
The pitch works because it bends something true by one degree. Microsoft Defender Antivirus can move into a passive state when a compatible third-party product is installed [15], so a user who has noticed that in Windows Security has already half-assembled the story the site is selling. Microsoft still supports third-party antivirus, and no legitimate refund requires removing security tools or installing remote access [16].
The form after the scan settles the question of who this is built for. It asks for bank name, cryptocurrency username, refund amount and reason, and the ID and password for a remote-access session, with 30 tools to choose from [18]. It also requires Agent ID, Agent Name and Company [17], which are fields you complete when you are the one placing the call. Eleven near-identical sites on one host [1] is the same fact from the other end: the scan is the intake form, and the call is the product.
Ranked by verification strength, evidence, and original report placement.
The form collects name, address, phone numbers, email address, refund amount and reason, bank name, cryptocurrency username, antivirus product, and the ID and password for a remote-access session, with a choice of 30 different remote-access tools.
Malwarebytes found eleven sites on a single host offering to check whether your antivirus is working, calling themselves SysScan and carrying Microsoft branding; the names vary but they work in essentially the same way.
The sites claim Windows no longer supports third-party antivirus and tell the visitor to uninstall it immediately, which Malwarebytes says is false.
According to Malwarebytes the fake scan is the first step in a refund scam designed to get victims onto the phone, remove their security software, and hand over personal, banking and remote-access information.
A website cannot run a real security scan; it can only read basic browser data such as operating system, screen size and approximate location, and cannot check for malware, memory issues or missing security patches.
The page reads information a browser legitimately exposes: user agent, screen dimensions, device memory, processor count, permission states, network information, available web features and some page performance timings, which makes the results appear specific to the machine.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party code review, single publisher
The claims rest on direct inspection of the pages' client-side code and a first-party test run: hard-coded finding blocks the developer labelled as fake, a score clamped to 13-30, a randomised patch-lag value, an enumerated 28-product antivirus picker and a 30-option remote-access field. That is specific, checkable and internally consistent. It is capped short of high because a single publisher supplies all of it, no domains, hashes or host identifiers are shared for independent verification, and the operator-fills-the-form conclusion is explicitly labelled inference rather than proof.
Confirmed small footprint, unknown reach
There is a concrete, observed deployment footprint — eleven near-identical sites on one host, an operational Telegram exfiltration channel, and a form pre-built for call-centre workflow with 28 antivirus and 30 remote-access options implying repeated use. But nothing in the material quantifies visitors, completed forms, victims, losses, or whether the sites remain live, and there is no traffic or telemetry disclosure. Scored low to reflect verified existence at small scale rather than demonstrated spread.
Slightly ahead of evidence on intent and targeting
The technical claims are unusually well matched to the artefacts shown, and the headline framing (capped score, recorded product) is literally what the code does — little inflation there. The modest positive gap comes from interpretive reach beyond the code: that enterprise entries in the picker show the scam is 'prepared for people using work computers', and that agent fields mean an operator types during a call, are plausible inferences presented alongside verified findings, while the campaign's actual reach is never measured. The publisher does flag the operator inference as unproven, which keeps the gap small.
Antivirus vendor reporting a scam that removes antivirus
The sole publisher is a consumer antivirus vendor, and the scam's central action is persuading users to uninstall antivirus. The report's core corrective guidance — Microsoft still supports third-party antivirus, do not remove your security software — aligns exactly with the publisher's commercial interest in retained installs, and the enumerated product list includes competitors and enterprise suites. That does not undercut the code findings, which are specific and checkable, but the alignment is strong and the article carries no disclosure of it, and there is no independent publisher to offset it.
Solid on mechanics, thin on scale
Confidence is moderate-high for the mechanics of how these pages work and what the form harvests, because those rest on reproducible code artefacts and a first-party test. It is held down by structural thinness: one publisher, a commercially aligned one, no shared indicators enabling verification, no measurement of reach or liveness, and two load-bearing conclusions (enterprise targeting, operator-completed forms) that are inference by the publisher's own admission.
security
A trailer date is a campaign schedule: fake GTA 6 sites are selling stolen session cookies1 distinct publisher
security
TCG writes down what "quantum-safe TPM" means, and buyers finally get a document to argue with2 distinct publishers
product
Rillet's $100M reads as proof mid-market ERP is rip-and-replace, mostly at the cheap end1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026