Softnate.com

By ESGI Advisor in Browser Hijackers

No, Softnate.com is not a site devoted to a guy with exceptionally soft skin, or a tendency to be easily swayed by emotion. There is no Nate in Softnate.com. The site is just another example of a malicious site that supports a rogue anti-virus program scam, and these sites do often use domain names that are slightly off the mark. The inclusion of the word "soft" is almost certainly the reason why the name Softnate.com was used, since a lot of the sites for these fake security programs will use the word "soft" as a reference to software. In addition to being a malicious site, Softnate.com has an associated browser hijacker.

To be clear, when people talk about Softnate.com, they may be referring to either of two things: a browser hijacker, or a website. The hijacker is typically called Softnate.com because that's the site it directs the web browser to on an infected computer. If you are unable to view any site other than Softnate.com, and every time you try to view another website your browser takes you to Softnate.com instead, then your computer is infected with the hijacker.

The Hijacker Softnate.com

The hijacker Softnate.com is installed by a Trojan hidden in an ordinary-looking file that you download, or it may be installed as a drive-by-download when you view an infected or malicious website. After Softnate.com is downloaded to your PC, the hijacker Softnate.com changes your Internet settings and directs all of your Internet traffic through a proxy server, which is how Softnate.com controls which sites you are able to view. Furthermore, the hijacker Softnate.com targets Internet Explorer's security settings and makes changes in the Registry to turn Internet Explorer's Phishing and download protection off. So, if you use a browser other than Internet Explorer, you will still be redirected to Softnate.com, but the browser's security features may remain active.

The Website Softnate.com

As a website, Softnate.com promotes the fake anti-virus program Antivirus Protection. The site's content is entirely fluff and lies. There are three phony customer testimonials and some lame basic definitions of malware terminology, which are repeated in various places throughout the site in order to take up space. Softnate.com includes tabs that claim to offer information on customer support and on the company that offers Antivirus Protection, but the "support" is nonexistent, and the company information is bogus. The only portion of the site Softnate.com that really matters to Softnate.com's creators is Softnate.com's payment page, where the site says you can purchase a licensed copy of Antivirus Protection by entering your credit card information. Softnate.com never delivers on these license purchases, because there aren't any licenses to be had. Softnate.com is out to commit fraud, not to sell software.

The website Softnate.com was registered on April 11, 2011, using a fake name with a stolen phone number and address in Portland, Oregon. As of this writing, there is no site at the exact address of Softnate.com, but it is entirely possible that the Antivirus Protection payment page uses a variation on the address for Softnate.com, such as a sub-page. The domain Softnate.net is also registered, and Softnate.com has the same status – that of existing but not having any content. That's not to say that the people who run the site couldn't change things tomorrow, or that they aren't using the site somehow. So if you are not being redirected to Softnate.com, please, do not attempt to visit the site.

File System Details

Softnate.com may create the following file(s):
# File Name Detections
1. %Temp%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
2. %Temp%\[RANDOM CHARACTERS]\

Registry Details

Softnate.com may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = '127.0.0.1:33554'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[RANDOM CHARACTERS]"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = '.exe'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter "Enabled" = '0'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ''
HKEY_CURRENT_USER\Software\[RANDOM CHARACTERS]

Trending

Most Viewed

Loading...