internat.exe - Dangerous
%windir%\internat.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
The worm also has a backdoor component that allows a malicious user remote access to an infected computer via the IRC network.
This worm can also copy itself into the shared folders of several peer-to-peer (P2P) file sharing utilities.
Copy itself into the Windows system folder as INTERNAT.EXE and set the following registry entries so that it is executed automatically upon restart:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ "" = \"%1\" %*
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ Windows Taskbar Manager = C:\
In order to run automatically when Windows starts up the worm may change the following registry entry so that it is executed before any EXE files:
HKCR\exefile\shell\open\command\ "" = C:\
W32/Protoride-H may also set the registry entry: HKLM\Software\BeyonD inDustries\ProtoType[v3]
Use RegRun Startup Optimizer to remove it from your system.