|
Mar
19
|
Threat Description:
Vista Defender Pro is a counterpart of the previously described XP Defender Pro (please follow the link to read more about this clone of the malware being analyzed). Like a random rogue antivirus application, Vista Defender Pro looks for installation methods other than the regular ones. This means it discovers a secret pathway into your system thus avoiding the authentication obstacles. Once Vista Defender Pro trialware gets into your OS, it implements some preliminary manipulations changing the Registry and playing havoc with the system files. Such impudent activity enables Vista Defender Pro to ensure its processes are being run. This rogue anti-spyware uses the Ave.exe file and that’s the one that determines the further behavior of your computer. Vista Defender Pro will start shooting out its popup ads that mimic the alert function warning you about some security problems and malicious activity on your workstation. Vista Defender Pro will also show you some of its scanners that return fabricated results listing many more infections that are not in fact on your PC. After that, Vista Defender Pro suggests the victim to get the computer disinfected using its own licensed version which is claimed to be a multifunctional tool for system protection. Buying Vista Defender Pro means giving in to cyber crime deployed by hackers. So instead of deleting non-existent malware with the help of a pseudo antivirus program, you should remove Vista Defender Pro from your system without delay.
Determine if your system is infected with Vista Defender Pro and related threats:
Download Vista Defender Pro Free Scanner with Remover
How to remove this threat manually:
Vista Defender Pro manual uninstall procedure:
Get rid of the related corrupt files:
- %AppData%\ave.exe
Delete the associated registry entries:
- HKEY_CURRENT_USER\Software\Classes\.exe
- HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon
- HKEY_CURRENT_USER\Software\Classes\.exe\shell
- HKEY_CURRENT_USER\Software\Classes\.exe\shell\open
- HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command
- HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas
- HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command
- HKEY_CURRENT_USER\Software\Classes\.exe\shell\start
- HKEY_CURRENT_USER\Software\Classes\.exe\shell\start\command
- HKEY_CURRENT_USER\Software\Classes\secfile
- HKEY_CURRENT_USER\Software\Classes\secfile\DefaultIcon
- HKEY_CURRENT_USER\Software\Classes\secfile\shell
- HKEY_CURRENT_USER\Software\Classes\secfile\shell\open
- HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command
- HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas
- HKEY_CURRENT_USER\Software\Classes\secfile\shell\runas\command
- HKEY_CURRENT_USER\Software\Classes\secfile\shell\start
- HKEY_CURRENT_USER\Software\Classes\secfile\shell\start\command
- HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | @ = “%AppData%\ave.exe” /START “%1″ %*
- HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command | IsolatedCommand = “%1″ %*
- HKEY_CURRENT_USER\Software\Classes\.exe | @ = “secfile”
- HKEY_CURRENT_USER\Software\Classes\.exe | Content Type = “application/x-msdownload”
- HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command | @ = “%AppData%\ave.exe” /START “%1″ %*
- HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\command | IsolatedCommand = “%1″ %*
Please note that Vista Defender Pro manual removal is a procedure of high complexity and should be performed with extreme caution. Lack of the required skills and even the slightest deviation from the instructions may cause irreparable system damage. To ensure trouble-free deletion, it is recommended to use the automatic removal tool below:
![]() |
Download Vista Defender Pro Removal Tool |
