Threatremover.net

Threatremover.net is a dangerous hijacker that could redirect users to web pages that promote fake security programs. Threatremover.net is known to advertise and offer the AV Security Suite rogue application. AV Security Suite, like many other rogues, is unable to detect or remove computer parasites despite its claim. Threatremover.net may also lead to other malware infections if a user is not careful. Use of a spyware detection tool is recommended after visiting Threatremover.net.

File System Details

Threatremover.net may create the following file(s):
# File Name Detections
1. %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string]tssd.exe
2. %Documents and Settings%\[UserName]\Local Settings\Application Data\[random string]\[random string].exe

Registry Details

Threatremover.net may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" ="1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "[random string]"
HKEY_LOCAL_MACHINE\Software\AvSuite
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "[random string]"
HKEY_CURRENT_USER\Software\AvSuite
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = ""
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"

Trending

Most Viewed

Loading...