Home Malware Programs Hijackers Softenza.com

Softenza.com

Posted: February 28, 2011

Yet another shiny poisoned apple offered on the web, Softenza.com looks like a website for security programs, but its true motives are to serve as a portal for fraudulent transactions. Along with snatching up your money and giving only problems back in return, Softenza.com is extremely likely to drop malware onto your computer without your express knowledge or consent. If your browser is redirecting towards Softenza.com and making you visit the site without wanting to, your chances of infection are very high. Delete all Softenza.com-related infections in short order, since these infections will create security problems that can harm your computer indirectly beyond the damage it's already suffered.

Softenza.com's Close Kin to Rogue Program Traitors

Softenza.com is best known for its marketing of the rogue anti-virus application Antimalware Go. The Antimalware Go program looks like a good security scanner for your computer, but causes system instability and offers bad results without even trying to detect or cure infections. Having Antimalware Go on your system means keeping your computer wide open to other attacks, and the rogue scanner may have also come with accompanying Trojans.

The only positive side about Antimalware Go is that you don't have to look hard to see Antimalware Go. Like all rogue anti-virus programs, Antimalware Go will as good as take over your computer to shove itself in your face. Any other infections that came with Antimalware Go are not likely to be so obvious to detect.

Along with the rogue anti-virus product, Softenza.com also uses a browser hijacker to redirect your browser via proxy server abuse. This can block access to legitimate security websites through fake 'unsafe website' error messages and other methods. These heavy-handed may have you thinking that just buying the product to get everything back to normal is the best idea, but do not do this! Softenza.com will only misuse your credit card for criminal purposes.

Finding a Path to a Softenza.com-Free Future

Softenza.com's hijacker uses randomized file names to make itself difficult to find. Softenza.com also creates startup registry entries to run in the background whenever Windows boots! The proper mean of deleting Softenza.com-related infections is, therefore, to prevent the hijacker from running by using Safe Mode.

Once Safe Mode is accessed, you can use all the real security tools at your disposal to remove everything linked to Softenza.com. Don't attempt to get this done on your own unless you're an expert ? the hiding of files and the use of registry changes makes Softenza.com infections hard for novices to peg down.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Temp%\[RANDOM CAHARACTERS]\
    2 %Temp%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = "0"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\InternetHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:33440"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS].exe"HKEY_CURRENT_USER\Software\[RANDOM CHARACTERS]HKEY..\..\..\..{RegistryKeys}Settings "ProxyOverride" = ""
Loading...