MS Antivirus 2008: what it is and how to remove it

MS Antivirus 2008 is a new corrupt anti-spyware product coming from the rogue malware creators, which, as usual, tries to convince PC users that it can find malware parasites in your computer. Of course, no other remover can do that.

Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Programs like MS Antivirus 2008 usually arrive in groups; a free scan lists the companions that are easy to miss.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove MS Antivirus 2008 yourself 5 steps, about 15 minutes, no software needed.

Start the steps
MS Antivirus 2008: screenshot
MS Antivirus 2008 as our 2021 report showed it.

MS Antivirus 2008: summary

Detection namesNo Microsoft detection name is known
DistributionNot recorded in the old report
DamageNot recorded in the old report
NameMS Antivirus 2008
TypeRogue antivirus
SymptomsAn unknown program in Installed apps
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 4 more facts
EvidenceOne write-up by a security site; details still limited
ProgramMS Antivirus 2008
First seen26 April 2021
Facts checked7 October 2026

From our report of Apr 2021 · not reviewed since

What MS Antivirus 2008 is

MS Antivirus 2008 is a new corrupt anti-spyware product coming from the rogue malware creators, which, as usual, tries to convince PC users that it can find malware parasites in your computer. Of course, no other remover can do that.

The main website that sells MS Anti-virus is Msantivirus-xp.com; block it using your HOSTS file. The story gets better as it goes - MS Antivirus 2008 also finds spyware pests that do not exist at all. Worst of all, it demands you to pay money to remove these non-existent threats.

Which means, you should remove MS Antivirus 2008 as soon as possible from your system if you have been infected. It doesn't matter if it presents itself as MSAntivirus2008 or simply as MS Anti- virus, this application is malicious and it shouldn't be trusted.

How to remove MS Antivirus 2008

Nothing it reports is real.

These steps remove it and undo a payment if you made one.

  1. Step 1: Do not pay, and undo a payment if you made one

    Nothing that MS Antivirus 2008 says it found needs fixing by MS Antivirus 2008. Close its windows and do not enter card details.

    If you bought it, contact your bank or card issuer about a dispute and cancel any renewal, keeping the receipt e-mail as evidence. Uninstalling it from Windows 11 or Windows 10 removes the program but leaves the subscription running.

    Full procedure with screenshots: What to do after paying a scammer

  2. Step 2: Uninstall MS Antivirus 2008

    MS Antivirus 2008 is removed like any other program, from the list of installed apps. In Windows 11 that is Settings > Apps > Installed apps, in Windows 10 Settings > Apps > Apps & features, and in both you can also use Control Panel > Programs and Features.

    Select MS Antivirus 2008, click Uninstall and follow the uninstaller to the end. Then look at the entries just above and below it when the list is sorted by date: bundled programs install at the same minute.

    Full procedure with screenshots: Uninstall a program or app in Windows On uGetFix

  3. Step 3: Remove it from startup

    Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.

    Right-click an entry and choose Open file location to see where it runs from: programs in %AppData% or %Temp% deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  4. Step 4: Delete the folders left behind

    Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.

    Press Windows + R, type %LocalAppData% and press Enter, then do the same for %AppData% and %ProgramData%, and look for folders named after MS Antivirus 2008, its publisher or created on the day the problem started.

    Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.

    If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  5. Step 5: Scan the PC, then run the offline scan

    A scan finds the parts of MS Antivirus 2008 that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.

    Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.

    It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

Stream videos without limitations, no matter where you are

There are multiple parties that could find out almost anything about you by checking your online activity.

While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.

Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.

Data backups are important - recover your lost files

Ransomware is one of the biggest threats to personal data.

Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.

While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.

Questions about MS Antivirus 2008

What is MS Antivirus 2008 and why is it on my PC?

MS Antivirus 2008 is a program that was installed on the PC, most likely together with something else you downloaded. Free software sites and many installers add extra programs on setup pages with pre-ticked boxes, so the extra install looks like your choice even though nobody read the page.

Check the install date in Settings, Apps, Installed apps: the program you installed that day is the probable carrier. If you do not need MS Antivirus 2008, uninstall it. If it belongs to your hardware or to a program you use, search its exact name and publisher first, because drivers and their tools can have unfamiliar names.

MS Antivirus 2008 will not uninstall. What can I do?

First restart the PC and try again, because the program may have been running and locked its own files. If the uninstaller is missing or fails, start Windows in Safe Mode, where most third-party programs do not start, and remove MS Antivirus 2008 from Installed apps there.

If it still refuses, delete its startup entry and its scheduled task, restart, and try once more. A program that actively prevents removal is behaving like malware, so finish with a Microsoft Defender offline scan. Avoid third-party uninstallers offered on search ads; several of them are unwanted programs themselves.

Someone called offering a refund for MS Antivirus 2008. Is it genuine?

Almost certainly not. Refund calls are a well-known second stage of scareware and tech support scams. The caller says you are owed money, asks you to install a remote access program to "process" it, then opens your online banking, makes it look as if too much was refunded and asks you to send the difference back.

Hang up. Real refunds go back to the card or PayPal account you paid with, through your bank or the payment provider, and never need remote access or a gift card.

MS Antivirus 2008 will not uninstall. What can I do?

Close it in Task Manager first, then uninstall it from Settings > Apps > Installed apps (in Windows 10, Apps & features). If it blocks this or restarts itself, start Windows in Safe Mode, where third-party programs do not start automatically, and uninstall from there.

Afterwards run a Microsoft Defender offline scan and delete any leftover folder named after MS Antivirus 2008 in C:\Program Files or %AppData%. If nothing works, Windows can be reset while keeping your personal files, which removes the program together with any settings it changed.

Is Windows Security enough to protect me from programs like MS Antivirus 2008?

For most home users, yes, especially with Potentially unwanted app blocking turned on in Windows Security > App & browser control > Reputation-based protection settings. That setting blocks many scareware installers before they run.

No security tool stops every scam, though, because programs like MS Antivirus 2008 are usually installed by the user after a frightening message. The habit that helps most is simple: ignore any website or pop-up that claims to have scanned your PC, and never call a number shown in a warning.

How do I know MS Antivirus 2008 is fake?

Three things give it away. It appears as MS Antivirus 2008 in the list of installed apps, a window from a program rather than from Windows Security. It pushes you to act quickly by calling, paying or downloading.

And the threats it reports never show up when you run a scan in the real Windows Security app. Microsoft does not put phone numbers in warnings or charge for removing threats through pop-ups. Close the window, do not call, and follow the steps to find and uninstall the program behind it.

Do I need to reinstall Windows to get rid of MS Antivirus 2008?

Usually not. A thorough clean-up is enough when the offline scan finds nothing afterwards and you do not see MS Antivirus 2008 in the list of installed apps again. A reset is the safer choice if an attacker had remote control, if security tools were switched off, or if detections come back after every clean-up.

Windows 11 can reset itself without a USB stick under Settings > System > Recovery > Reset this PC. Copy documents and photos out first and scan the copies. A reset does not change passwords or undo stolen data, so the account steps still apply.

Is my card safe after buying MS Antivirus 2008?

Treat it as exposed. The order page belongs to the seller of MS Antivirus 2008, and you cannot know how the number is stored or shared. Ask your bank for a replacement card, which is usually free, and dispute the original charge as a misrepresented product.

Until the new card arrives, check your account daily for small or foreign transactions. If the bank offers alerts for every card payment, turn them on. Keep the receipt and screenshots, because they support the dispute.

What could the caller do while connected to my PC?

Anything you could do. Callers working with fake alerts like MS Antivirus 2008 typically show you Windows logs as "proof", install their own remote tool for later, and steer you to online banking or a gift card purchase. Some add a password to Windows or lock the PC if you refuse to pay.

Remove every remote access program you did not install yourself, check Settings > Accounts > Other users for new accounts, and change important passwords from a clean device. If you cannot be sure what was changed, a reset of Windows is the safe choice.

Will Fortect remove MS Antivirus 2008?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For MS Antivirus 2008, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove maple30.com: a Mac malware host tagged Amos and ClickFix, and what to do if you ran a command from it

maple30.com is a website that URLhaus lists for Mac malware downloads tagged Amos and ClickFix, and it shares an identical file address with another listed host, quillchant14.com. If you pasted a command from it into...TRHigh riskUgnius Kiguolis ·

Remove nordertextil.de: a ClickFix loader site for Windows, and what to do if you pasted its PowerShell command

nordertextil.de is a German web address that URLhaus lists for four malware downloads tagged ClickFix, Loader, exe and powershell, and our browser could not find the domain when we tested it. If you pasted a command...TRHigh riskUgnius Kiguolis ·

Remove Android Charging Boost

Android Charging Boost blue lock screen is an intrusive problem for Android users triggered by PUPs and malware Android Charging Boost is an unwanted lock screen that emerges on AndroidMalwareHigh riskLinas Kiguolis ·

Remove Ghost Push virus

Ghost Push virus - a dangerous cyber attack that gains root access of Android devices Ghost Push virus is malware designed to infiltrate Android OS tablets and phones exclusively. ItMalwareHigh riskAlice Woods ·

Questions and experiences: MS Antivirus 2008

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,449 members already hereReading, writing, commenting and voting. 0 verified · 174 joined this year