SecurityNot yet confirmed elsewhere1 publisher3 min readPublished
The refund scam that asks you to uninstall your antivirus, then writes down which one
Eleven look-alike sites run a scan whose score is capped at 30 out of 100, then record which of 28 security products the victim removed. Endpoint tampering by consent, over the phone.
The Watch · Security desk

What happened
- Malwarebytes found eleven look-alike sites on one host, branded as Microsoft and calling themselves SysScan, offering to check whether your antivirus works.
- Each concludes that Windows no longer supports third-party antivirus and that the visitor should uninstall it at once. It does, and they should not.
- The site logs which of 28 named security products the victim removed, and enterprise products are on that list.
- Malwarebytes describes the whole sequence as the front end of a refund scam that moves the victim to a phone call.
Why it matters
- constraint Tamper protection is built for an attacker fighting the agent. Here the licensed user removes it on purpose, so the control most likely to stop it is the one being overridden.
- exposure Because enterprise products sit on the pick-list, a managed work laptop can lose its agent mid-call, and the removal will read as authorised to whoever reviews it later.
- capability By the time the phone rings, the caller knows which product is gone and which of 30 remote-access tools to talk the victim through installing.
- decision Help desks and vendors now have to decide whether to explain Defender's passive state to users unprompted, since that single true detail is what makes the uninstall request sound plausible.
Fifty of the findings these pages display are fixed text, sitting in blocks the developer labelled as fake checks [7]. The genuine browser data the page reads is what makes them land: user agent, screen dimensions, device memory, processor count, permission states, network information and page timings all come back correct [6], so the assertion that your kernel page-table isolation is inactive or that no Trusted Platform Module was found arrives wearing the same clothes [8].
The arithmetic gives it away. The score is constrained in code to between 13 and 30 out of 100 [10], which leaves the whole diagnostic a seventeen-point range [18] on a scale where passing is not an available result [10]. Malwarebytes ran it against a fully updated test browser and got "possibly outdated" [11]. An encrypted connection is reported as a downgrade risk, and cookies produce a warning when enabled and a failure when disabled [12]. Two scans of the same machine minutes apart disagree about how far behind its patches are, because that number is generated at random each time [9].
The instruction to uninstall is the part worth an operator's attention. It clears the path for remote-access software and anything else installed during the session, and it hands the scammers the name of the product that was there [13]. That answer goes into a list of 28 named products plus an Other option, and enterprise security software is among them [14].
Nothing in that sequence is technical. No exploit, no driver abuse, no signed binary killing a service. The licensed user removes the agent themselves, deliberately, while on a call with someone holding an Agent ID [17]. Consent is the hardest condition for tooling to argue with, and it is the whole mechanism here.
The pitch works because it bends something true by one degree. Microsoft Defender Antivirus can move into a passive state when a compatible third-party product is installed [15], so a user who has noticed that in Windows Security has already half-assembled the story the site is selling. Microsoft still supports third-party antivirus, and no legitimate refund requires removing security tools or installing remote access [16].
The form after the scan settles the question of who this is built for. It asks for bank name, cryptocurrency username, refund amount and reason, and the ID and password for a remote-access session, with 30 tools to choose from [1]. It also requires Agent ID, Agent Name and Company [17], which are fields you complete when you are the one placing the call. Eleven near-identical sites on one host [2] is the same fact from the other end: the scan is the intake form, and the call is the product.
What to watch
- Whether the eleven sites come down, and how fast the same template reappears under new names on a different host.
- Whether any employer reports a managed endpoint agent being uninstalled during one of these calls, which would confirm the enterprise entries on the product list are being worked.
- Whether the operator-facing fields turn up in other refund-scam kits, which would point to a shared template rather than one crew.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence74
- Adoption24
- Hype gap+8
- Incentives72
- Confidence64
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The form collects name, address, phone numbers, email address, refund amount and reason, bank name, cryptocurrency username, antivirus product, and the ID and password for a remote-access session, with a choice of 30 different remote-access tools.
- [2]
Malwarebytes found eleven sites on a single host offering to check whether your antivirus is working, calling themselves SysScan and carrying Microsoft branding; the names vary but they work in essentially the same way.
- [3]
The sites claim Windows no longer supports third-party antivirus and tell the visitor to uninstall it immediately, which Malwarebytes says is false.
- [4]
According to Malwarebytes the fake scan is the first step in a refund scam designed to get victims onto the phone, remove their security software, and hand over personal, banking and remote-access information.
- [5]
A website cannot run a real security scan; it can only read basic browser data such as operating system, screen size and approximate location, and cannot check for malware, memory issues or missing security patches.
- [6]
The page reads information a browser legitimately exposes: user agent, screen dimensions, device memory, processor count, permission states, network information, available web features and some page performance timings, which makes the results appear specific to the machine.
- [7]
Fifty of the findings are fixed text written into the page, grouped in blocks that the developer labelled as fake checks.
- [8]
Hard-coded findings include claims that the browser sandbox is compromised, kernel page-table isolation is inactive, memory is vulnerable to Rowhammer, no Trusted Platform Module was found, WebRTC is leaking the local IP address and the processor is thermally throttled; a web page cannot determine those things.
- [9]
One finding reports how many days behind the security patches are using a random number generated whenever that check runs, so running the scan again returns a different answer.
- [10]
The score is constrained in the code to between 13 and 30 out of 100 and cannot report anything above 30 regardless of the computer being tested; passing is not a possible outcome.
- [11]
Malwarebytes' fully updated test browser was reported by the scan as possibly outdated.
- [12]
Checks using genuine information are twisted into warnings: an encrypted connection becomes a downgrade risk, cookies enabled is a warning and cookies disabled is a failure.
- [13]
Telling the victim to remove their antivirus serves the scammers twice: it removes software that could interfere with what comes next, including remote-access software and anything installed during the session, and it tells them which security product the victim uses.
- [14]
The site records which antivirus was removed from a list of 28 named products plus an Other option, and enterprise security software also appears on the list, suggesting the scam is prepared for people using work computers.
- [15]
Windows includes Microsoft Defender Antivirus, which can move into a passive state when a compatible third-party antivirus product is installed because the other product is providing protection.
- [16]
Microsoft still supports third-party antivirus software, and legitimate refunds never require uninstalling security tools or installing remote-access software.
- [17]
The post-scan form requires an Agent ID, Agent Name and Company, fields which strongly suggest it is designed to be filled in by an operator during a call.
- [18]
The full spread of possible scores is seventeen points out of 100.
Sources
1 independent publisher whose own reporting we read for this story.
- malwarebytes.comFake Microsoft security scans trick victims into uninstalling their antivirus
1 article · August 24, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Brand ImpersonationFollow
- Social Engineering and Voice PhishingFollow
- Fake Security ScannersFollow
- Browser FingerprintingFollow
- Tech Support and Refund ScamsFollow
- Remote Access Tool AbuseFollow
- Endpoint Security TamperingFollow
Entities
- MalwarebytesFollow
- SysScan (fake scan sites)Follow
- MicrosoftFollow
- Microsoft Defender AntivirusFollow
- Telegram Bot APIFollow
- RowhammerFollow
- Kernel Page-Table IsolationFollow
- Trusted Platform ModuleFollow
- WebRTCFollow