Vista Antivirus Plus 2013

Vista Antivirus Plus 2013 Description

Type: Adware

ScreenshotVista Antivirus Plus 2013 is another one among numerous rogue security applications that belong to the FakeRean or Braviax family of rogue security applications. This notorious family carries out a misleading tactic that criminals use to take advantage of inexperienced computer users. Basically, Vista Antivirus Plus 2013 and its clones pretend to be real security programs in order to prove to PC users that the purchase of an expensive, fake upgrade in order to keep their computers safe from threats. To do this, Vista Antivirus Plus 2013 displays numerous alarming error messages and deliberately causes performance problems on the infected computer. However, since Vista Antivirus Plus 2013 and its clones are actually threats themselves, PC security researchers strongly advise disregarding all messages displayed by these fake security programs and then using a real anti-malware tool to protect your computer.

Identifying Vista Antivirus Plus 2013 and Its Clones

There are dozens of clones of Vista Antivirus Plus 2013 that use similar names or even different names such as Windows Antivirus 2008, Vista Antivirus 2008, Antivirus Pro 2009, AntiSpy Safeguard, ThinkPoint, Spyware Protection 2010, Internet Antivirus 2011, Palladium Pro, XP Anti-Virus 2011, CleanThis, PC Clean Pro, XP Home Security 2012, Windows Clear Problems, XP Security 2012, Antivirus PRO 2015.

Because of these characteristic naming patterns, which are probably generated automatically, these fake security programs are usually not difficult to recognize. Vista Antivirus Plus 2013 and its clones have names made up of three distinct part:

  1. The first part of the name will indicate the targeted computer's operating system. This first part can be either 'Vista', 'XP', 'Win 7' or 'Win 8', depending on the infected computer. Vista Antivirus Plus 2013 infects computers with the Windows Vista operating system. During installation, a variant corresponding to the infected computer's operating system is installed.
  2. This is usually followed by a term designed to convince the victim that Vista Antivirus Plus 2013 is, in fact, a real security program. These are usually broad, generic terms such as 'security', 'anti-malware', 'Internet protection', or – in this case - 'Antivirus Plus'.
  3. Finally, criminals add the current year to the end of these fake security programs' names. This is done to attempt to convince computer users that these are the latest in an established line of security software. Variants have been released since 2009 and, previously, PC security researchers have encountered Vista Antivirus Plus 2009, 2010, 2011 and 2012. Vista Antivirus Plus 2013 was released in October of 2012 and is part of a large batch of rogue security software claiming to be an update for the coming new year.


Technical Information

File System Details

Vista Antivirus Plus 2013 creates the following file(s):
# File Name Detection Count
1 %AppData%\Local\[RANDOM CHARACTERS].exe N/A
3 %AppData%\Roaming\Microsoft\Windows\Templates\[RANDOM CHARACTERS] N/A
5 %AllUsersProfile%\[RANDOM CHARACTERS] N/A

Registry Details

Vista Antivirus Plus 2013 creates the following registry entry or registry entries:
Registry key
HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'exefile'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = '"%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile "(Default)" = 'Application'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "(Default)"= '"%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%Program Files%\Mozilla Firefox\firefox.exe"'
HKEY_CURRENT_USER\Software\Classes\.exe "Content Type" = 'application/x-msdownload'
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = '"%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile "Content Type" = 'application/x-msdownload'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "IsolatedCommand" – '"%1" %*'
HKEY_CLASSES_ROOT\exefile\shell\open\command “(Default)” = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe' /START "%Program Files%\Mozilla Firefox\firefox.exe" -safe-mode'
HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon "(Default)" = '%1' = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%1" %*"
HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = '"%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%1" %*'
HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon "(Default)" = '%1'
HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "IsolatedCommand" = '"%1" %*'
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\[RANDOM CHARACTERS].exe" /START "%Program Files%\Internet Explorer\iexplore.exe"'

More Details on Vista Antivirus Plus 2013

The following messages associated with Vista Antivirus Plus 2013 were found:
Stealth intrusion!
Infection detected in the background. Your computer is now attacked by spyware and rogue software. Eliminate the infection safely, perform a security scan and deletion now.
Tracking software found!
Your PC activity is being monitored. Possible spyware infection. Your data security may be compromised. Sensitive data can be stolen. Prevent damage now by completing a security scan.
Virus infection!
System security was found to be compromised. Your computer is now infected. Attention, irreversible system changes may occur. Private data may get stolen. Click here now for an instant anti-virus scan.
Vista Antivirus Plus 2013 Alert
Internet Connection alert!
Suspicious network activity detected!
Malware infection is possible!
Vista Antivirus Plus 2013 Alert
System hacked!
Unknown programs is scanning your system registry right now! Identity theft detected!
Vista Antivirus Plus 2013 Firewall Alert
Vista Antivirus Plus 2013 has blocked a program from accessing the internet
Internet Explorer is infected with Trojan-BNK.Win32.Keylogger.gen
Private data can be stolen by third parties, including credit card details and passwords.

Site Disclaimer is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.