Most of this page uses content from Wikipedia. The original article was at MS Antivirus. The page may have contained some inaccurate or outdated information, so please edit it so it contains better information.
The list of authors can be seen in the page history. As with Malware Wiki, the text of Wikipedia is available under the Creative Common Attribution-ShareAlike 3.0 License.
Remove this template when most of the Wikipedia content has been removed or the Wikipedia information is outnumbered by non-Wikipedia information.

MS Antivirus, also known as XP Antivirus[1]; Vitae Antivirus; Windows Antivirus; Win Antivirus; Antivirus Pro; Antivirus Pro 2009 ,2010, 2017[2]; Antivirus 2007, 2008[3], 2009[4], 2010[5], and 360[6]; System Antivirus; Vista Antivirus; AntiSpywareMaster[7]; and XP AntiSpyware 2009, or Microsoft Antivirus, is a scareware rogue anti-virus which claims to remove nonexistent virus infections found on a computer running Microsoft Windows if a user purchases the full version of the software.

Method of Infection/Variants

MS Antivirus is known to infect users using the Microsoft Windows operating system, and is browser independent. One infection method involves the Zlob trojan. Another involves the use of fake codec scams, such as Video ActiveX Enhancement 2.07.

Symptoms of infection


Screenshot of Antivirus 2009 "scanner" on an infected computer

Each variant has its own way of downloading and installing itself onto a computer. MS Antivirus is made to look professional and functional to fool a computer user into thinking that it is a real anti-virus system in order to convince the user to "purchase" it. In a typical installation, MS Antivirus runs a scan on the computer and gives a false report claiming that the computer is infected with spyware. Once the scan is completed, a warning message appears that lists the spyware ‘found’ and the user has to either click on a link or a button to remove it. Regardless of which button is clicked -- "Next" or "Cancel" -- a download box will still pop up. This deceptive tactic is an attempt to scare the Internet user into clicking on the link or button to purchase MS Antivirus. If the user decides not to purchase the program, then they will constantly receive pop-ups stating that the program has found infections and that they should register it in order to fix them. This type of behavior can cause a computer to operate slower than normal. It affects the Windows Registry.

MS Antivirus will also occasionally display fake pop-up alerts on an infected computer. These alerts pretend to be a detection of an attack on that computer and the alert prompts the user to activate, or purchase, the software in order to stop the attack. The Windows registry is also modified so the software runs at system startup. The following files may be downloaded to an infected computer:[8]

  • MSASetup.exe
  • MSA.exe
    MS Antivirus

    MS Antivirus

  • MSA.cpl
  • MSx.exe

Depending on the variant, the files will have different names and therefore can appear or be labeled differently. For example, Antivirus 2009 will have the .exe file name a2009.exe.

Malicious actions

Most variants of this malware will not be overtly harmful, as they usually will not steal a user's information (as spyware) nor critically harm a system. However, the software will act to inconvenience the user by frequently displaying popups that prompt the user to pay to register the software in order to remove non-existant viruses. Some variants are more harmful; they display popups whenever the user tries to start an application or even tries to navigate their hard drive, especially after they restart their computer. It does this by modifying the Windows registry. It can also disable real antivirus programs to protect itself from removal. Whichever variant infects a computer, MS Antivirus always uses system resources when running, potentially making an infected computer run slower than before.

The malware can also block access to known spyware removal sites and in some instances, searching for "antivirus 2009" (or similar search terms) on a search engine will result in a blank page or an error page. Some variants will also redirect the user from the actual Google search page to a false Google search page that states that the user has a virus and should get Antivirus 2009 with a hotlink to the virus’s page.

AntiVirus2009 can also disable a user’s antimalware programs and prevent the user from opening or re-enabling them. Antimalware applications disabled by AntiVirus2009 include McAfee, Spybot - Search & Destroy, AVG and Superantispyware.

MS Antivirus is constantly updated and re-released to prevent detection by common anti-virus scanners.


In November 2008, it was reported that a Hacker known as NeoN hacked the Bakasoftware's database, and posted the earnings of the company received from XP Antivirus. The data revealed the most successful affiliate earned $158,000 USD in a week.

Court Actions

On December 2, 2008 the U.S. District Court for the District of Maryland issued temporary restraining against Innovative Marketing, Inc. and ByteHosting Internet Services, LLC after receiving a request from the Federal Trade Commission (FTC). According to the FTC, the combined malware of WinFixer, WinAntivirus, DriveCleaner, ErrorSafe, and XP Antivirus has fooled over one million people into purchasing the software marketed as security products. The court also froze the assets of the companies in an effort to provide some monetary reimbursement to affected victims. The FTC established claims that the companies established an elaborate ruse that duped Internet advertising networks and popular web sites into carrying their advertisements.

According to the FTC complaint, the companies charged in the case operated using a variety of aliases and maintained offices in the countries of Belize and Ukraine. ByteHosting Internet Services is based in Cincinnati, Ohio. The complaint also names defendants Daniel Sundin, Sam Jain, Marc D’Souza, Kristy Ross, and James Reno in its filing, along with Maurice D’Souza, who is named relief defendant, for receiving proceeds from the scheme.

See also