Vista Antivirus Plus 2013

By ESGI Advisor in Rogue Anti-Spyware Program | 348 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (2 votes, average: 4.50 out of 5)
Loading ... Loading ...
More... More

Vista Antivirus Plus 2013 Description

Image Screenshot

[+] Click Image to Enlarge

Vista Antivirus Plus 2013 is a fake anti-virus program created by scammers to convince innocent PC users to purchase its imaginary full version. In truth, the full edition of Vista Antivirus Plus 2013 will not protect the computer from any type of malware because it does not exist. Vista Antivirus Plus 2013 might seem to be a legal and trustworthy security tool because of its name and appearance, but, in reality, Vista Antivirus Plus 2013 will not defend your PC from any type of security threats. Vista Antivirus Plus 2013 proliferates via Trojans that could be downloaded from malicious websites. Trojans take advantage of security holes and other system vulnerabilities to access a corrupted machine. Vista Antivirus Plus 2013 strives to make victims purchasing the commercial version of its rogue program and gain credit card details. Once installed on the infected computer system, Vista Antivirus Plus 2013 launches bogus system scans and returns false scan results in order to intimidate PC users into believing their computers are infected with numerous malware infections. Vista Antivirus Plus 2013 also shows fake warning messages that report certain computer problems and declare that your computer is at risk. Vista Antivirus Plus 2013 does not have the ability to find and uninstall any type of malware threats, so the purchase of this software product is only a waste of money. To uninstall Vista Antivirus Plus 2013 from the affected PC, ESG’s malware research team advises you to use an appropriate anti-malware tool that is able to remove rogue software.

Type: Rogue Anti-Virus Program

How Can You Detect Vista Antivirus Plus 2013?

Vista Antivirus Plus 2013 Technical Report

As new Vista Antivirus Plus 2013 details are reported by our customers and findings from our Threat Research Center, we will update this section.

Fake message for Vista Antivirus Plus 2013:

The following fake error message(s) appears for Vista Antivirus Plus 2013:

Vista Antivirus Plus 2013 Alert
System hacked!
Unknown programs is scanning your system registry right now! Identity theft detected!

Vista Antivirus Plus 2013 Alert
Internet Connection alert!
Suspicious network activity detected!
Malware infection is possible!

Virus infection!
System security was found to be compromised. Your computer is now infected. Attention, irreversible system changes may occur. Private data may get stolen. Click here now for an instant anti-virus scan.

Vista Antivirus Plus 2013 Firewall Alert
Vista Antivirus Plus 2013 has blocked a program from accessing the internet
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
Private data can be stolen by third parties, including credit card details and passwords.

Tracking software found!
Your PC activity is being monitored. Possible spyware infection. Your data security may be compromised. Sensitive data can be stolen. Prevent damage now by completing a security scan.

Stealth intrusion!
Infection detected in the background. Your computer is now attacked by spyware and rogue software. Eliminate the infection safely, perform a security scan and deletion now.

Vista Antivirus Plus 2013 Removal Details

Vista Antivirus Plus 2013 has typically the following processes in memory:

  • %AppData%\Local\[RANDOM CHARACTERS].exe

Vista Antivirus Plus 2013 creates the following files in the system:

  • %AppData%\Local\[RANDOM CHARACTERS]
  • %AppData%\Roaming\Microsoft\Windows\Templates\[RANDOM CHARACTERS]
  • %Temp%\[RANDOM CHARACTERS]
  • %AllUsersProfile%\[RANDOM CHARACTERS]

Vista Antivirus Plus 2013 creates the following registry entries:

  • HKEY_CURRENT_USER\Software\Classes\.exe “(Default)” = ‘exefile’
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “(Default)” = ‘”%1″ %*’
  • HKEY_CURRENT_USER\Software\Classes\exefile “(Default)” = ‘Application’
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “(Default)”= ‘”%1″ %*
  • HKEY_CLASSES_ROOT\.exe\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe” /START “%1″ %*’
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe” /START “%Program Files%\Mozilla Firefox\firefox.exe”‘
  • HKEY_CURRENT_USER\Software\Classes\.exe “Content Type” = ‘application/x-msdownload’
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command “IsolatedCommand” = ‘”%1″ %*’
  • HKEY_CURRENT_USER\Software\Classes\exefile “Content Type” = ‘application/x-msdownload’
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command “IsolatedCommand” – ‘”%1″ %*’
  • HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe” /START “%1″ %*’
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe’ /START “%Program Files%\Mozilla Firefox\firefox.exe” -safe-mode’
  • HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon “(Default)” = ‘%1′ = ‘”%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe” /START “%1″ %*”
  • HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command “IsolatedCommand” = ‘”%1″ %*’
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe” /START “%1″ %*’
  • HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon “(Default)” = ‘%1′
  • HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command “IsolatedCommand” = ‘”%1″ %*’
  • HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command “(Default)” = ‘”%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe” /START “%Program Files%\Internet Explorer\iexplore.exe”‘

Important Article Disclaimer

ESG Support Center

This entry was last updated on 01/15/13 and posted on 12/5/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.