Vista Antivirus 2012 Removal Process (remove VistaAntiVirus2012)

June 7, 2011

Vista Antivirus 2012 is yet another fake security program deemed to be dangerous to have installed on your Windows PC. Vista Antivirus 2012 is known to mimic the look and feel of Windows Vista in an attempt to gain trust from computer users. Unfortunately that trust is broken the instant that someone falls for Vista Antivirus 2012's tricks and ends up purchasing a full version in hopes that it would somehow remove parasites that it says it detected. Everything about Vista Antivirus 2012 is plagiarized in an effort to get computer users to buy the full version which is just as useless as the free version of Vista Antivirus 2012.

Are you getting popups from Vista Antivirus 2012? Have you identified that you have Vista Antivirus 2012 installed on your computer? Do you wish to remove Vista Antivirus 2012 completely from your computer?

Why should you remove Vista Antivirus 2012?

If Vista Antivirus 2012 resides on your computer, it can potentially damage your personal files or you may end up losing data stored on your system. Research has shown that Vista Antivirus 2012 may have the ability to make your computer vulnerable to remote attacks which could result, initially, in loss of money, possibly identity theft, and, eventually, a painstaking Vista Antivirus 2012 removal process.

How can you manually remove Vista Antivirus 2012

Manual removal of Vista Antivirus 2012 may not be for everyone. Each manual Vista Antivirus 2012 removal step must be followed delicately to completely remove all related files and registry entries from your computer. If you are unsure or have doubts about editing your system registry, then we recommend that you use the automatic Vista Antivirus 2012 removal process.

Vista Antivirus 2012 can be removed manually by following the steps below.

  1. With all programs closed, click the Start Menu and go to the Control Panel.
  2. Locate the Add/Remove Programs icon and double click it.
  3. Locate Vista Antivirus 2012 in the list of programs. If you find it, select it and remove it. If you cannot find Vista Antivirus 2012, you can continue to step 5.
  4. Restart your computer.
  5. Close all open programs and windows on your desktop.
  6. Open your registry editor (regedit) program by going to Start Menu, type in regedit, and click OK.
  7. Find all of the following registry entries and delete them. If you do not know how to do this, then you can read how to edit the registry in Windows.

    HKEY_CLASSES_ROOT\.exe\DefaultIcon "(Default)" = '%1?
    HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\(random 3 letters).exe" /START "%1? %*'
    HKEY_CLASSES_ROOT\.exe\shell\open\command "IsolatedCommand" = '"%1? %*'
    HKEY_CLASSES_ROOT\.exe\shell\runas\command "(Default)" = '"%1? %*'
    HKEY_CLASSES_ROOT\.exe\shell\runas\command "IsolatedCommand" = '"%1? %*'
    HKEY_CLASSES_ROOT\exefile "Content Type" = 'application/x-msdownload'
    HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\(random 3 letters).exe" /START "%1? %*'
    HKEY_CLASSES_ROOT\exefile\shell\open\command "IsolatedCommand" = '"%1? %*'
    HKEY_CLASSES_ROOT\exefile\shell\runas\command "IsolatedCommand" = '"%1? %*'
    HKEY_CURRENT_USER\Software\Classes\.exe "(Default)" = 'exefile'
    HKEY_CURRENT_USER\Software\Classes\.exe "Content Type" = 'application/x-msdownload'
    HKEY_CURRENT_USER\Software\Classes\.exe\DefaultIcon "(Default)" = '%1? = '"%UserProfile%\Local Settings\Application Data\(random 3 letters).exe" /START "%1? %*'
    HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "IsolatedCommand" = '"%1? %*'
    HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "(Default)" = '"%1? %*'
    HKEY_CURRENT_USER\Software\Classes\.exe\shell\runas\command "IsolatedCommand" = '"%1? %*'
    HKEY_CURRENT_USER\Software\Classes\exefile "(Default)" = 'Application'
    HKEY_CURRENT_USER\Software\Classes\exefile "Content Type" = 'application/x-msdownload'
    HKEY_CURRENT_USER\Software\Classes\exefile\DefaultIcon "(Default)" = '%1?
    HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\(random 3 letters).exe" /START "%1? %*'
    HKEY_CURRENT_USER\Software\Classes\exefile\shell\open\command "IsolatedCommand" = '"%1? %*'
    HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "(Default)" = '"%1? %*'
    HKEY_CURRENT_USER\Software\Classes\exefile\shell\runas\command "IsolatedCommand" – '"%1? %*'
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\(random 3 letters).exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"'
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\(random 3 letters).exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode'
    HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command "(Default)" = '"%UserProfile%\Local Settings\Application Data\(random 3 letters).exe" /START "C:\Program Files\Internet Explorer\iexplore.exe
  8. You may need to return to this removal process for removing Vista Antivirus 2012. You can do this easily by bookmarking or adding a favorite to this page by clicking here. If you are using the FireFox web browser you can press the keys Ctrl and D simultaneously to bookmark this page.

    Image 1. Bookmark PCHubs removal process


  9. Delete all of the following files that are associated with Vista Antivirus 2012 from your computer.

    %AllUsersProfile%\9olpq2xnc6yhnjeuwnjIUks1k (or any random)
    %AppData%\9olpq2xnc6yhnjeuwnjIUks1k (or any random)
    %UserProfile%\Local Settings\Application Data\.exe
    %UserProfile%\Templates\9olpq2xnc6yhnjeuwnjIUks1k (or any random)
    %Temp%\9olpq2xnc6yhnjeuwnjIUks1k (or any random)
    %AppData%\Local\9olpq2xnc6yhnjeuwnjIUks1k (or any random)
    %AppData%\Roaming\Microsoft\Windows\Templates\9olpq2xnc6yhnjeuwnjIUks1k (or any random)

    If you need a better understanding on how to search for these files then you can read how to find and search for files and folders here.

    If you have issues deleting any of the previously listed files that are associated with Vista Antivirus 2012, you can try rebooting your computer into safe mode. Booting into safe mode may allow certain malicious files to be deleted. If you are wondering how to boot into safe mode, you can read our process for starting a computer in safe mode here.

    Image 2. Select "Safe Mode with Networking"


  10. After locating and deleting the previous files you must remove all directories associated with Vista Antivirus 2012 by going to the C:\ProgramFiles\Vista Antivirus 2012 folder, select it, and delete it. In some cases you may not be able to find this directory. You can still continue to the next step.

  11. Restart your computer. You do not need to boot into safe mode at this point. You should have removed Vista Antivirus 2012 completely from your computer. If you find that Vista Antivirus 2012 is still on your computer, you can repeat the steps again or go to the automatic Vista Antivirus 2012 removal process.


  • Annabell Scibetta says:

    Do you agree that McAfee anti-spyware is crap now? It doesn’t seem to do the job anymore and the price is going up every year. I merely hate it in any way.

  • Jeremy Preet says:

    The easiest, quickest and safest way to delete any malware is to do a SYSTEM RESTORE on your computer. It is part of Microsoft Operating system software so you know it is not a fake answer that will corrupt your computer. Hit the Start button. In the search cell, write, “system restore” then follow the instructions. Choose a restore time that is the most recent before your computer was infected. System Restore will restore the OS to that time — without the malware. I just did it on my computer to delete malware that took over my internet–Ran System Restore, clicked on internet, no problem — and the program is gone from the system tray.

Leave a Reply

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as is:
What is 2 + 6 ?