A new refund scam is leveraging fake Microsoft-branded security scans to trick users into uninstalling their legitimate antivirus software, ultimately aiming to steal personal, banking, and remote-access information. Multiple websites, operating under names like SysScan, present convincing but fraudulent security scans that invariably conclude the user's computer has severe issues, falsely attributing these problems to their installed antivirus.
These scam sites claim that Windows no longer supports third-party antivirus products and instruct victims to uninstall them immediately. This assertion is false; Microsoft continues to support third-party antivirus solutions, and its own Microsoft Defender Antivirus can enter a passive state when another compatible product is installed, but this does not signify a lack of support.
The fake scans are designed to appear legitimate by reading some real browser data, such as operating system, screen size, and approximate location. However, the security conclusions drawn are entirely fabricated. For instance, the sites report issues like compromised browser sandboxes, inactive kernel page-table isolation, Rowhammer vulnerabilities, missing Trusted Platform Modules, WebRTC IP leaks, and thermally throttled processors—none of which a website can genuinely detect. One "security patch" check even generates a random number of days behind, producing different results with each scan.
Even genuine browser features are misrepresented as security risks. An encrypted connection might be flagged as a downgrade risk, and both enabled and disabled cookies are presented as warnings or failures. The "security score" is hardcoded to always fall between 13 and 30 out of 100, ensuring no computer ever "passes" the scan.
The instruction to uninstall antivirus software serves two critical purposes for the scammers: it removes security measures that could interfere with subsequent malicious activities, such as the installation of remote-access software, and it reveals which specific security product the victim was using from a list of 28 common antivirus solutions, including enterprise security software.
Following the fake scan, victims are prompted to fill out a customer information form. This form collects extensive personal details, including name, address, phone numbers, email, bank name, cryptocurrency username, and even the ID and password for a remote-access session, with a choice of 30 different remote-access tools. Intriguingly, the form also includes fields for "Agent ID," "Agent Name," and "Company," suggesting it is designed to be completed by an operator during a call, potentially while viewing the victim's screen. A field even asks if "explicit content" is involved, potentially to leverage embarrassment against victims.
Despite claims on the site that no data is sent or collected, the information entered into the form, along with agent and remote-access details, is bundled and sent directly to Telegram's bot API. This method makes the scam sites inexpensive to host and easy to abandon.
After submitting the form, victims are directed to a waiting page that plays a looping video of a man in an office, informing them that a "refund manager" will call within three to five minutes. This page is designed to keep the victim engaged and reassured that an official process is underway, setting the stage for the subsequent phone call where further financial and personal information is likely extracted.
Analysis of the website code reveals signs of AI generation, including extensive, self-narrating comments that explain the deliberate pacing of the scan and the terse tone of spoken lines. Some comments explicitly describe the deceptive elements, labeling blocks of invented findings as "fake" and genuine value checks as "exaggerated." One comment even falsely states that no data leaves the device, despite the function sending data to Telegram being present just a few hundred lines later. The fraud-specific elements, such as the US bank list and agent identifiers, appear to be integrated into a broader scanner template.
Users should be aware that legitimate websites cannot perform deep security scans of a computer, nor can they detect malware or memory issues. Microsoft continues to support third-party antivirus, and genuine refund processes never require uninstalling security software or installing remote-access tools. Any website making such claims should be immediately closed.






