Posted: June 16, 2010

Threatremover.net is a hijacker that uses fake online marketing scams to trick computer users out of their money. Threatremover.net is not what it appears to be at first glance. Threatremover.net does not offer any legitimate type of parasite removal other than the AV Security Suite application which is nothing more than a rogue anti-spyware program that is not able to detect or remove any type of computer parasite. Threatremover.net may lead users to unwanted web sites and change settings within the web browser program. It is suggested that all traces of Threatremover.net be detected and removed with a good spyware removal tool.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string].exe
    2 %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]tssd.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\AvSuiteHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" ="1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http="HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"HKEY_LOCAL_MACHINE\Software\AvSuiteHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"