What kind of pop-up scam is "Scan Computer To See If Antivirus Is Working"

Phishing/Scam

Also Known As: Scan Computer To See If Antivirus Is Working tech support scam

Damage level:

Get free scan and check if your device is infected.

Remove it now

To use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

What is "Scan Computer To See If Antivirus Is Working" pop-up scam?

We analyzed this website and determined it is a fake Microsoft security scanner. According to research published by Malwarebytes, it is designed to trick visitors into removing their real antivirus software, then harvest sensitive personal and financial information. This page should not be trusted in any way.

Scan Computer To See If Antivirus Is Working POP-UP Scam

"Scan Computer To See If Antivirus Is Working" scam in detail

The page mimics a Microsoft product called "Microsoft SysScan," using the company's recognizable four-colored square logo and branding. On loading, it fills two sidebars with the visitor's real browser data, IP address, city, and device specifications - a tactic meant to suggest the site already has meaningful access to the computer.

The central warning claims that upgraded Windows no longer requires or supports third-party antivirus software, and demands the visitor "uninstall immediately." This is entirely false. Microsoft Corporation has no connection to this page, and no genuine Windows security feature delivers alerts like this through a browser.

Removing working antivirus software because a webpage instructed it would leave the computer significantly more exposed to real threats. That is precisely the outcome the scam is built to produce.

Visitors who click "Start Scan" are shown a fake diagnostic sequence. A progress meter fills while an event stream scrolls through hardware and software checks in real time. When it finishes, the page reports 30 problems and 52 warnings across 8 categories, giving the device a health score of 13 out of 100.

All of those results are invented. No website can genuinely assess a computer's security state - that requires software installed directly on the device. The scanning animation is a performance designed to create alarm, not to produce real information.

Once the fake results appear, the scam moves into its data-collection phase. Visitors are directed to a "Customer Information" form requesting their full name, billing address, phone number, and email. The form also asks for the remote software being used, a remote session ID, and a remote session password.

Those remote access fields are the most dangerous part of the form. A scammer who obtains a session ID and password can connect directly to the victim's device via remote access software, without the victim having to take any further action.

The form collects still more. It asks for bank name and cryptocurrency account details, and includes fields labeled "Agent ID" and "Agent Name." These are internal tracking records used by the fraud network to log which scammer handled which victim and what financial accounts were in scope.

After submission, the page displays a waiting screen bearing a fake Microsoft logo. It reads: "Please wait 3-5 minutes. A refund manager will call you shortly." An AI-generated image of a professional-looking man in a suit is shown to project the appearance of a legitimate support business.

The caller is a scammer. Using the data already collected, they pose as a Microsoft support representative and attempt to extract payment for fabricated repair services, push the victim into granting remote access, or instruct them to transfer money through their bank or cryptocurrency account.

Granting remote access carries serious consequences. Connected scammers can steal stored passwords, install trojans, ransomware, or keyloggers, and access banking or email accounts during the session. The damage can persist long after the call ends.

The correct response to this page is to close the browser immediately. Do not uninstall antivirus software based on anything a webpage claims, and never provide personal, financial, or remote access credentials to a site reached through an unexpected redirect or pop-up.

Threat Summary:
Name Scan Computer To See If Antivirus Is Working tech support scam
Threat Type Phishing, Scam, Social Engineering, Fraud
Fake Claim The visitor's antivirus software is incompatible with modern Windows and must be removed; the computer contains numerous security problems
Disguise Legitimate Microsoft security scanning tool ("Microsoft SysScan")
Related Domains detectsysscanner[.]at, detectsysscanner[.]com, detectsysscanner[.]de, detectsysscanner[.]in[.]net, detectsysscanner[.]xn--q9jyb4c, detsysscanner[.]com, detsysscanner[.]de, detsysscanner[.]xn--q9jyb4c, techsysscanner[.]com, techsysscanner[.]lol, tlcscanner[.]com
Threat Status (detsysscanner[.]com) PCrisk Website Scanner Results
Symptoms Fake error messages, fake system warnings, pop-up errors, hoax computer scan.
Distribution methods Compromised websites, rogue online pop-up ads, potentially unwanted applications.
Damage Loss of sensitive private information, monetary loss, identity theft, possible malware infections.
Malware Removal (Windows)

To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.

Download Combo Cleaner

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Online scams in general

Fake security scanner scams blend the visual authority of a trusted brand with personalized data - showing the visitor's own IP address and hardware specs - to manufacture a sense of immediate crisis. The goal is always to prevent the victim from thinking critically long enough to hand over something of value.

Some examples of similar scams are "Windows Security Certificate Expired/Invalid", "Critical Security Alert", and "McAfee - Threats Detected. Action Required!".

How did I open a scam website?

Scam websites like this one are rarely visited on purpose. Most users arrive after clicking a deceptive advertisement or pop-up on an unrelated site. Rogue advertising networks, commonly found on torrent sites, illegal streaming platforms, and adult content pages, frequently redirect visitors to pages like this without any warning.

Browser notifications from rogue sites the user previously allowed are another frequent source of these redirects. Adware already running on the device can also trigger automatic redirects at any time. Phishing emails and misleading links shared on social media are additional delivery routes worth being aware of.

How to avoid visiting scam pages?

Do not allow unfamiliar or suspicious websites to send browser notifications - this is one of the most common ways rogue pages continue reaching users over time. Avoid clicking pop-up ads, deceptive buttons, or links on low-quality sites, and download software only from official websites and verified app stores.

Exercise caution with links received by email, especially from unexpected or unfamiliar senders. Keep the operating system and all installed applications up to date. If unwanted software is already generating these redirects, we recommend scanning the computer with Combo Cleaner Antivirus for Windows to remove it automatically.

Text presented within the "Scan Computer To See If Antivirus Is Working" pop-up scam page:

Scan your computer to see if your antivirus is working.

Upgraded version of Windows does not require and support third-party antivirus software. Uninstall immediately.

This issue commonly arises when legacy applications from a previous Windows installation conflict with the upgraded security stack. Windows includes built-in compatibility features — run affected software in compatibility mode to restore functionality.

Left unresolved, this may indicate operating system instability.

A fast, private diagnostic dashboard that runs 40+ checks on your browser, operating system, network, and privacy settings — right now, in this tab.

Full appearance of the "Scan Computer To See If Antivirus Is Working" scam page (GIF):

Scan Computer To See If Antivirus Is Working POP-UP Scam (GIF)

Instant automatic malware removal:

Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:

DOWNLOAD Combo Cleaner

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Quick menu:

How to identify a pop-up scam?

Pop-up windows with various fake messages are a common type of lures cybercriminals use. They collect sensitive personal data, trick Internet users into calling fake tech support numbers, subscribe to useless online services, invest in shady cryptocurrency schemes, etc.

While in the majority of cases these pop-ups don't infect users' devices with malware, they can cause direct monetary loss or could result in identity theft.

Cybercriminals strive to create their rogue pop-up windows to look trustworthy, however, scams typically have the following characteristics:

  • Spelling mistakes and non-professional images - Closely inspect the information displayed in a pop-up. Spelling mistakes and unprofessional images could be a sign of a scam.
  • Sense of urgency - Countdown timer with a couple of minutes on it, asking you to enter your personal information or subscribe to some online service.
  • Statements that you won something - If you haven't participated in a lottery, online competition, etc., and you see a pop-up window stating that you won.
  • Computer or mobile device scan - A pop-up window that scans your device and informs of detected issues - is undoubtedly a scam; webpages cannot perform such actions.
  • Exclusivity - Pop-up windows stating that only you are given secret access to a financial scheme that can quickly make you rich.

Example of a pop-up scam:

Example of a pop-up scam

How do pop-up scams work?

Cybercriminals and deceptive marketers usually use various advertising networks, search engine poisoning techniques, and shady websites to generate traffic to their pop-ups. Users land on their online lures after clicking on fake download buttons, using a torrent website, or simply clicking on an Internet search engine result.

Based on users' location and device information, they are presented with a scam pop-up. Lures presented in such pop-ups range from get-rich-quick schemes to fake virus scans.

How to remove fake pop-ups?

In most cases, pop-up scams do not infect users' devices with malware. If you encountered a scam pop-up, simply closing it should be enough. In some cases scam, pop-ups may be hard to close; in such cases - close your Internet browser and restart it.

In extremely rare cases, you might need to reset your Internet browser. For this, use our instructions explaining how to reset Internet browser settings.

How to prevent fake pop-ups?

To prevent seeing pop-up scams, you should visit only reputable websites. Torrent, Crack, free online movie streaming, YouTube video download, and other websites of similar reputation commonly redirect Internet users to pop-up scams.

To minimize the risk of encountering pop-up scams, you should keep your Internet browsers up-to-date and use reputable anti-malware application. For this purpose, we recommend Combo Cleaner Antivirus for Windows.

What to do if you fell for a pop-up scam?

This depends on the type of scam that you fell for. Most commonly, pop-up scams try to trick users into sending money, giving away personal information, or giving access to one's device.

  • If you sent money to scammers: You should contact your financial institution and explain that you were scammed. If informed promptly, there's a chance to get your money back.
  • If you gave away your personal information: You should change your passwords and enable two-factor authentication in all online services that you use. Visit Federal Trade Commission to report identity theft and get personalized recovery steps.
  • If you let scammers connect to your device: You should scan your computer with reputable anti-malware (we recommend Combo Cleaner Antivirus for Windows) - cyber criminals could have planted trojans, keyloggers, and other malware, don't use your computer until removing possible threats.
  • Help other Internet users: report Internet scams to Federal Trade Commission.

Frequently Asked Questions (FAQ)

What is a pop-up scam?

Pop-up scams are deceptive pages that appear while browsing and manipulate visitors through urgency, fear, or fake authority. They are designed to push people into calling fraudulent support lines, handing over personal information, sending money, or downloading dangerous software.

What is the purpose of a pop-up scam?

The goal is financial gain for the scammers. This particular scheme aims to collect personal and financial data, obtain remote access credentials, and ultimately defraud victims through calls in which scammers pose as Microsoft support representatives.

Why do I encounter fake pop-ups?

These pages are promoted through rogue advertising networks on low-quality or adult sites, deceptive browser notifications, misleading social media links, and adware that may already be installed on the device. Most visitors who encounter them did not deliberately seek them out.

Will Combo Cleaner protect me from pop-up scams?

Combo Cleaner scans websites as they load and flags malicious pages, including fake security scanner scams like this one. When such a page is detected, Combo Cleaner warns the user before any content loads and blocks access, preventing the scam from running in the browser.

Share:

facebook
X (Twitter)
linkedin
copy link
Tomas Meskauskas

Tomas Meskauskas

Expert security researcher, professional malware analyst

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate