SoftBarrier
SoftBarrier Description
SoftBarrier is a rogue security program that comes from the group of hackers that created other rogue anti-spyware programs such as Soft Cop, WiniGuard and other related applications. SoftBarrier or Soft Barrier, is sometimes installed without knowledge to the computer users through a Trojan horse downloaded from a malicious source online.
Once installed, SoftBarrier will display falsified popup alerts and carryout system scans that return fabricated parasite results. These actions performed by SoftBarrier are designed to trick computer users into purchasing the SoftBarrier program. SoftBarrier does not have the capability to detect or remove computer parasites.
Type: Rogue AntiSpyware Programs
Automatic Detection of SoftBarrier
SoftBarrier Technical Report
As new SoftBarrier details are reported by our customers and findings from our Threat Research Center, we will update this section.
The following SoftBarrier files with its MD5s were created in the system:
| File Name | File Size | MD5 |
|---|
| setup[1].exe | 882865 | c1cc6a70f1b76916feb8e07d37d1808c |
| setup[1].exe | 882859 | 0b5952b33b2d413c8cffe5656dbd2ce0 |
| setup[2].exe | 431104 | fd3393651e1db5476c23b1c874117a95 |
| SoftBarrier.exe | 786944 | b92edfa87d8cb599a8f620aa4d3970ff |
SoftBarrier has typically the following processes in memory:
- C:\WINDOWS\system32\16624s5y1z9.dll
- %Temp%\vwc4.tmp.exe
- C:\Program Files\SoftBarrier Software\SoftBarrier\uninstall.exe
- C:\WINDOWS\system32\1649zt5oj447.exe
- C:\Program Files\SoftBarrier Software\SoftBarrier\SoftBarrier.exe
- C:\WINDOWS\111249acztool1ef5.exe
- SoftBarrier.exe
SoftBarrier created the following directories, files, paths:
- %ProgramFiles%\SoftBarrier Software\SoftBarrier
- %AllUsersProfile%\Start Menu\Programs\SoftBarrier
SoftBarrier creates the following registry entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\SoftBarrier
- HKEY_CURRENT_USER\Software\SoftBarrier
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “vwc4.tmp.exe”
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftBarrier
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “SoftBarrier”
Important Article Disclaimer


English 

SoftBarrier 










