Home Malware Programs Browser Hijackers Softbard.net

Softbard.net

Posted: March 18, 2011

Softbard.net is one of many malicious websites linked to the rogue security application Antivirus Monitor. Trojans pass this rogue security product along to your computer, and Antivirus Monitor then proceeds to cause a variety of problems, including exhibiting fake infection alerts and hijacking your web browser. Even minor contact with Softbard.net puts you at risk for malware infection through browser exploits that don't require you to download anything intentionally. Personal information such as credit card numbers should never be given to Softbard.net – no matter how legitimate Softbard.net looks on the outside!

Why Even a Taking a Look at Softbard.net Can Hurt Your PC

Softbard.net may appear the same as a real security application website on the outside, but internally Softbard.net hosts a bundle of dangerous code that can attack your computer straight through your browser. JavaScript and Flash-based vulnerabilities allow Softbard.net to force you to download something without your consent. This forced download will usually be the rogue security program Antivirus Monitor or a Trojan that downloads the rogue security program.

Like the Softbard.net website, it hails from Antivirus Monitor puts on a show of being helpful and professional but 'under the hood' it attacks your PC in many different ways:

  • Fake scan results and equally fake infection warning pop-ups will be displayed prominently and incessantly, all to work you up into a state of terror. This usually coincides with links to the Softbard.net website, in case you've been softened up enough to give away your personal information by 'registering' the rogue security product.
  • Browser URL redirection attacks or 'hijackings.' There are two purposes behind this kind of attack – one, to make you go to Softbard.net (again!), and two, to prevent you from accessing threats that could identify Softbard.net and its products as PC threats. Accordingly, with Softbard.net-related malware on your machine, you'll have trouble getting to any website that could provide advice or fixes for Softbard.net malware.
  • Applications that are prevented from running. Antivirus Monitor may use error messages to cover its tracks when crashing a program, but the rogue security product is always the guilty part, not whatever imaginary infection it points a finger at in accusation. This behavior is likely to target security-related applications like anti-virus scanners.

Don't Be Too Soft on Softbard.net

Allowing malware linked to Softbard.net to stay on your computer can result in real and potentially permanent harm over time. If you want to be rid of those annoying error messages and have all your security software working again, you need to remove Softbard.net malware and avoid further contact with the website.

Although Softbard.net's malware takes steps to protect itself, there are ways around Softbard.net's interfering tactics. Using Safe Mode with Networking will let users download any updates or other required files to delete Antivirus Monitor and the Trojan that spawned it. This mode also lets you scan without most forms of malware starting up in Windows, so you can be certain your scan actually worked.

Removing Softbard.net malware might be challenging, but the consequences of not removing Softbard.net are far more stressful. Whether you prefer to delete Softbard.net's threats to your PC manually or with the aid of an anti-malware application, you've everything to gain by doing so as soon as you can!

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\[RANDOM CHARACTERS]
    2 %Temp%\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ''HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = '127.0.0.1:33554'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
Loading...