Home Malware Programs Browser Hijackers Soldierantivirus.com

Soldierantivirus.com

Posted: March 1, 2010

Soldierantivirus.com is a browser hijacker which promotes the rogue anti-spyware Security Tool. Similarly to other hijackers, soldierantivirus.com is known to modify targeted web browsers and divert users to Soldierantivirus.com. Soldierantivirus.com will display fake security notifications to scare users into purchasing the "full version" of Security Tool. In order to avoid Security Tool and its sponsor soldierantivirus.com, users are strongly recommended to keep their anti-virus software updated and frequently scan their systems.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Application Data\[randomnumbers]\[randomnumbers].bat
    2 %UserProfile%\Application Data\[randomnumbers]\[randomnumbers].cfg
    3 %UserProfile%\Application Data\[randomnumbers]\[randomnumbers].exe
    4 %UserProfile%\Desktop\Security Tool.lnk
    5 %UserProfile%\Start Menu\Programs\Security Tool.lnk

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Security ToolHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random numbers].exe"
Loading...