internat.exe - Dangerous
%windir%\internat.exe
Manual removal instructions:
%windir%\internat.exe | Malware |
%windir%\internat.exe | Dangerous |
%windir%\internat.exe | High Risk |
The worm also has a backdoor component that allows a malicious user remote access to an infected computer via the IRC network.
This worm can also copy itself into the shared folders of several peer-to-peer (P2P) file sharing utilities.
Copy itself into the Windows system folder as INTERNAT.EXE and set the following registry entries so that it is executed automatically upon restart:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ "" = \"%1\" %*
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ Windows Taskbar Manager = C:\
In order to run automatically when Windows starts up the worm may change the following registry entry so that it is executed before any EXE files:
HKCR\exefile\shell\open\command\ "" = C:\
W32/Protoride-H may also set the registry entry: HKLM\Software\BeyonD inDustries\ProtoType[v3]
Use RegRun Startup Optimizer to remove it from your system.
Dmitry Sokolov:
Since that time I work every day to fix the issues that antiviruses cannot.
If your antivirus have not helped you solve the problem, you should try UnHackMe.
We are a small company and you can ask me directly, if you have any questions.