Home Malware Programs Browser Hijackers Softnate.com

Softnate.com

Posted: April 15, 2011

Softnate.com is a dangerous website known for marketing fake security software, in particular, the rogue Antivirus Protection. Softnate.com's Antivirus Protection product is fraudulently sold to unsuspecting PC users under a variety of names, to keep you from learning Antivirus Protection's true nature – a threat that exudes fake infection-riddled errors and system scans, blocks programs from running and steals control over your web browser. Even brief contact with Softnate.com isn't recommended, since Softnate.com may attack your system through browser security holes and force you to download its malware.

Softnate.com is a Dealer of Many PC-Endangering Cards

Softnate.com is actually just one of many different and identical websites selling the same identically rogue security applications. The Antivirus Protection application sold by Softnate.com is extremely similar to threats like Antivirus Monitor, which in turn is marketed by a similar site such as Softbard.com. The profusion of malicious websites and rogue-related threats linked to Softnate.com is simply a way of catching you off-guard by using a multitude of different names on the same fraudulent scam.

This is also relevant because Softnate.com and infections and sites related to Softnate.com have built up a reputation for hijacking your web browser – forcing your browser to visit a particular site, or preventing it from visiting other sites. Even your search results and homepage can be changed by hijacker infections, and most Softnate.com-related hijackers will redirect you, if not to Softnate.com itself, then at least to one of the affiliated criminal sites.

The soothing blue color scheme and semi-professional interface, including supportive product testimonials, may lure you into thinking that Softnate.com sells useful products. As you can see from the below list of Antivirus Protection's characteristics, though, nothing could be further from the truth.

Not the Protection Antivirus Protection Pretends to Be

Softnate.com's Antivirus Protection is known for:

  • Altering your desktop background without your permission.
  • Adding startup entries into your Registry, so that Antivirus Protection will launch whenever Windows does the same.
  • Creating fake scans and desktop errors that show the presence of high quantities of nonexistent infections. Most infections will be labeled as highly threatening types, such as keyloggers, backdoor Trojans and password thieves.
  • Falsely announcing that applications and then crashing them - this is partly done simply to cause panic, and partly done to stop you from using anti-malware software.

The prolonged survival of this rogue security program may also mean additional exposure to Softnate.com, since Antivirus Monitor will link to Softnate.com or a similar hostile website whenever possible. Although Softnate.com and its software will claim that the best way for you have your PC clean again is to purchase Antivirus Monitor, the real solution is to delete all evidence of Softnate.com's attacks by running a complete and fully-updated scan of your PC with a real anti-malware program.

Be warned that the slightest contact with Softnate.com may re-infect your PC, and so you should try to avoid using a hijacked web browser while trying to delete Softnate.com malware. If Softnate.com malware is stopping you from using the application, you can switch to a Safe Mode environment, which is available in all Windows systems. This will let Windows start without 'extra' malware processes like Softnate.com inserting themselves into the startup routine.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\[RANDOM CHARACTERS]\
    2 %Temp%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ''HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = '127.0.0.1:33554'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"HKEY_CURRENT_USER\Software\[RANDOM CHARACTERS]
Loading...