Antivirus Security Pro 2013 is a rogue security application that masquerades as legitimate antivirus software while actually serving as a sophisticated scareware tool designed to extort money from victims. This fake antivirus program infiltrates Windows systems through deceptive distribution methods and immediately launches an aggressive campaign of fraudulent system scans and fabricated security alerts. Once installed, it attempts to convince users their computer is severely infected with dozens or even hundreds of threats, pressuring them to purchase a full version of the worthless software to remove these nonexistent dangers.
Despite presenting a polished, professional interface that mimics legitimate security software, Antivirus Security Pro 2013 provides no actual protection and may itself compromise system security by disabling real antivirus programs, blocking access to security websites, and creating system instability. This rogue application belongs to the extensive FakeVimes/FakeRean malware family, which has produced hundreds of variants over the years with slightly different names and interfaces but identical malicious behavior.
Threat Profile
| Threat Type | Rogue antivirus / Scareware / Potentially Unwanted Program (PUP) |
| Family | FakeVimes (also known as FakeRean, BraviaxFamily) |
| Platform | Windows XP, Vista, 7, 8 (primarily targets older systems) |
| Aliases | Win32/FakeVimes, Trojan.FakeAV, Rogue:Win32/FakePAV, various vendor-specific detections |
| First Observed | Late 2012 / Early 2013 |
| Distribution | Trojan downloaders, malicious advertising, fake codec updates, social engineering |
| Persistence Mechanisms | Registry Run keys, browser helper objects (BHOs), system service modifications |
| Primary Capabilities | Fake system scanning, fraudulent security alerts, payment processing for worthless software, real AV blocking, system modification |
| Typical Installation Path | %ProgramFiles%\Antivirus Security Pro 2013\ or variations in user profile directories |
| Registry Artifacts | HKCU\Software\Microsoft\Windows\CurrentVersion\Run entries, HKLM\SOFTWARE entries for the fake program |
| Network Behavior | Contacts command-and-control servers for updates, may download additional malware, processes credit card information |
| Removal Difficulty | Moderate — blocks legitimate security tools and safe mode in some variants, but established removal procedures exist |
How It Spreads
Antivirus Security Pro 2013 typically infiltrates systems through deceptive distribution channels that exploit user trust and technical unfamiliarity. The most common infection vector involves trojan downloaders that arrive bundled with seemingly legitimate software downloads from unvetted websites, particularly those offering "free" versions of commercial software, pirated content, or codec packs. Users inadvertently authorize the installation when they rush through installation wizards without carefully reading the fine print or declining optional offers.
Another prevalent distribution method exploits malicious advertising networks that display fake system scan results within web browsers. These fabricated warnings claim your computer is infected and prompt you to download a "free scanner" to fix the problems. When users click these convincing pop-ups in a moment of concern, they're actually downloading the rogue application itself. Some variants of this scareware also spread through compromised websites that serve drive-by download attacks, particularly targeting systems with outdated browser plugins or security vulnerabilities.
Common distribution vectors include:
- Trojan downloaders bundled with freeware, shareware, or pirated software from unofficial download sites
- Fake codec updates that claim you need special software to view video content on websites
- Malicious advertising (malvertising) on legitimate websites that display fake system warnings
- Spam email attachments disguised as invoices, shipping notifications, or security updates
- Social engineering tactics on social media and messaging platforms with links to "security scans"
- Exploit kits targeting vulnerabilities in Java, Flash, Adobe Reader, and other browser plugins
- Fake download buttons on file-sharing and streaming websites that lead to the installer instead of actual content
What It Does On Your Machine
Upon installation, Antivirus Security Pro 2013 immediately configures itself to launch automatically at Windows startup and begins its deceptive campaign. The program displays an interface remarkably similar to legitimate antivirus software, complete with progress bars, technical-sounding threat names, and severity ratings. It performs a fake system scan that inevitably "discovers" numerous critical infections, Trojans, rootkits, and other malware threats — none of which actually exist. These fabricated scan results create a sense of urgency and fear, prompting users to purchase the "full version" to remove the supposed threats.
Beyond the fraudulent security theater, this rogue application actively interferes with legitimate system operations. It commonly blocks access to security-related websites and prevents users from downloading or running real antivirus software that could expose the fraud. The program may disable Windows Defender, turn off automatic updates, or terminate legitimate security processes. Some variants display persistent pop-up warnings even when you're not actively using the program, claiming your system is under attack or that critical files are corrupted. These interruptions can make normal computer use extremely frustrating and may cause users to panic into making a payment just to regain system functionality.
In addition to its primary scareware function, Antivirus Security Pro 2013 may serve as a gateway for additional malware. Some variants download and install other unwanted programs, including browser hijackers, adware, or actual information-stealing trojans. The program creates multiple persistence mechanisms to ensure it survives between restarts, modifying system registries and potentially creating scheduled tasks. While its primary goal is financial fraud through fake software sales, the system modifications it makes can destabilize your computer, cause performance degradation, and create legitimate security vulnerabilities even after the rogue program itself is removed.
Manual Removal — Step by Step
Disconnect from the Network
Immediately unplug your ethernet cable or disable Wi-Fi to prevent the rogue software from communicating with its command servers, downloading updates, or transmitting any information. This also prevents additional malware from being installed during the removal process.
Boot Into Safe Mode with Networking
Restart your computer and repeatedly press F8 during boot (before the Windows logo appears) to access the Advanced Boot Options menu. Select "Safe Mode with Networking" from the list. This loads Windows with minimal drivers and prevents most malware from loading automatically, though some FakeVimes variants have developed safe mode blocking capabilities.
Terminate Malicious Processes
Open Task Manager (Ctrl+Shift+Esc) and look for processes named "AVSecurityPro2013.exe" or similar variations. If the rogue program has disabled Task Manager, you may need to use a third-party process manager or registry edit to re-enable it first. End any suspicious processes related to Antivirus Security Pro 2013 before proceeding with file removal.
Remove Startup Persistence
Press Windows Key + R, type "msconfig" and press Enter. Navigate to the Startup tab and uncheck any entries related to Antivirus Security Pro 2013. Additionally, open Registry Editor (regedit) and navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to delete any suspicious entries pointing to the rogue program's executable.
Delete Program Files and Folders
Navigate to C:\Program Files\ or C:\Program Files (x86)\ and delete the "Antivirus Security Pro 2013" folder if present. Also check C:\Users\[YourUsername]\AppData\Local\ and C:\Users\[YourUsername]\AppData\Roaming\ for folders with random names or those containing the rogue program's files. Delete these folders entirely after verifying they're related to the infection.
Clean Additional Registry Entries
In Registry Editor, search for "Antivirus Security Pro 2013" and delete any keys or values you find. Also navigate to HKEY_CURRENT_USER\Software\ and HKEY_LOCAL_MACHINE\SOFTWARE\ to manually remove any folders named "Antivirus Security Pro 2013" or variations. Be extremely careful when editing the registry — incorrect deletions can cause system problems.
Scan with Legitimate Security Software
Reconnect to the internet (still in Safe Mode) and download Malwarebytes Anti-Malware or another reputable security scanner. Run a full system scan to detect any remaining components of the rogue program or additional malware that may have been installed alongside it. Quarantine and remove all detected threats before proceeding.
Reset Browser Settings
If the rogue program modified your browser settings, open each installed browser and reset it to defaults. In Chrome, Firefox, Edge, or Internet Explorer, look for the reset/refresh option in settings. This removes unwanted extensions, restores the default homepage and search engine, and clears any malicious modifications that might persist after removing the main program.
Restore System Policies
If Antivirus Security Pro 2013 disabled Task Manager, Registry Editor, or other system tools, you'll need to re-enable them. In Registry Editor, navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System and delete values named "DisableTaskMgr" or "DisableRegistryTools" if present. This restores normal system functionality.
Reboot and Verify Removal
Restart your computer normally (not in Safe Mode) and verify that no warnings or pop-ups from Antivirus Security Pro 2013 appear. Check Task Manager to confirm no related processes are running. Run another full scan with your legitimate antivirus software to ensure complete removal. Monitor system behavior over the next few days for any signs of persistent infection or reinfection.
Prevention
- Maintain legitimate antivirus protection from reputable vendors like Bitdefender, Kaspersky, ESET, or built-in Windows Defender. Keep it updated and running at all times. Real security software won't suddenly appear demanding immediate payment for threats — that's always a red flag.
- Download software only from official sources — the developer's website, Microsoft Store, or Apple App Store. Avoid third-party download sites, torrent platforms, and file-sharing networks that commonly bundle legitimate installers with unwanted programs. Always choose custom installation and decline optional offers.
- Keep your operating system and all software updated with the latest security patches. Enable automatic updates for Windows, and regularly update browser plugins like Adobe Flash (now discontinued), Java, and Adobe Reader, or better yet, uninstall unnecessary plugins entirely to reduce your attack surface.
- Exercise caution with email attachments and links, even from seemingly known senders. Verify unexpected attachments by contacting the sender through a different method before opening. Never enable macros in documents from untrusted sources, and be particularly suspicious of invoices, shipping notifications, or urgent security warnings that arrive unsolicited.
- Use a standard user account for daily activities rather than an administrator account. This limits the damage malware can do since it won't have elevated privileges to modify system-level settings or install itself deeply into Windows. Only switch to administrator access when specifically installing legitimate software.
- Install a reputable ad-blocker like uBlock Origin to reduce exposure to malicious advertising networks. Many infections begin with deceptive ads on otherwise legitimate websites, so blocking these entirely eliminates a significant infection vector without compromising normal web browsing.
- Educate yourself and household members about common social engineering tactics. Legitimate security companies don't cold-call about infections, real antivirus software doesn't suddenly appear demanding payment, and your browser can't actually scan your computer for viruses. Skepticism is your best defense.
- Regularly back up important files to an external drive or cloud service. While Antivirus Security Pro 2013 isn't ransomware, having backups ensures you can recover if any malware causes data loss or system corruption. Keep backup drives disconnected when not actively backing up to prevent infection spread.
When Computer Repair Roswell removes rogue security software from your machine, we guarantee it stays gone. If the same threat returns within 90 days and you haven't installed new software or visited risky websites, we'll fix it again at no additional charge. We take the time to remove every trace and secure your system properly the first time.
Bring It In
If you're dealing with Antivirus Security Pro 2013 or suspect your computer has been compromised by scareware, don't risk incomplete removal or paying for worthless fake software. Our technicians at Computer Repair Roswell have extensive experience identifying and removing rogue security programs, along with any additional malware they may have installed. We'll thoroughly clean your system, verify that your actual security software is functioning properly, and make sure you haven't suffered data theft or other compromise during the infection.
We're located in Roswell, Georgia, and we service both PCs and Macs with same-day appointments usually available. Call us at (770) 667-9696 to describe what you're experiencing, or just bring your machine to our shop — we'll run diagnostics and give you an honest assessment of what's needed. Unlike the fake warnings from rogue software, when we tell you there's a problem, you can trust it's real, and when we tell you it's fixed, it actually is. Let us restore your peace of mind and your computer's security.