internat.exe+aimfix dectecting it=?

Discussion in 'Malware Help (A Specialist Will Reply)' started by the new tech guy, Jan 6, 2006.

  1. Hi i was wondering about somthing i just noticed that was a little suspicious today. I ran aimfix as part of a routine cleanup on my computer and it detects and removes the file called internat.exe which resides in the windows system 32 folder and it says that it is a keyboard interpreter in properties. However, when i scan with the kapersky file checker it says its safe. Could this thing be the signs of a trojan or simply a false positive of a virus remover thinking somthing is a keylogger when it is actually a legit system process? The operating system is windows 2000.
    thanks for any help on this
    -the new tech guy
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's a valid Windows file.

    http://www.liutilities.com/products/wintaskspro/processlibrary/internat/

    You can easily tell this by right clicking on the file and looking at Properties/Version info.

    Sounds like Aimfix has a false positive issue and is deleting a valid file for the OS. Seems like writer needs to stop using just file names to determine if something is bad.
     
  3. Ok phew cause i was going crazy with the computer looking for wether it was safe or not. I did check the file myself and it did say ms but i figured that any scriptor can type that in to confuse the user and make them think somthing is safe when in reality it is a peice of malware. Thanks chas.
    PS: I heard you reviewed my idea for a aim virus removal sticky. Just wondering wether it was useful or not as I have not heard anything.
    thanks again for verifying that with me
    -the new tech guy
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a big enough issue to require a special procedure. We already require some of what you mentioned to be done during the READ ME. Adding AimFix is something we already do as necessary much like many other special cleaning steps (like Look 2 Me for one).

    But as stated AIM virus issues are a not problematic enough to need anything special to removed them outside of whats in the READ ME and we do throw in AimFix as an additional step sometimes.
     
  5. Oh ok I just figured i would mention somthing usefull and if its not usefull right now im sorry if i wasted your time then. I Just thought i would give a little hand in here knowing you guys are so busy all the time. If you ever need the procedure again do not be afraid to ask me and i figured i would send it cause i have seen alot of people infected with these worms and usually when they ask me for help i refer them to here where they can find a removal sticky for the problem they have. Thanks for letting me know.
    -the new tech guy
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's not a problem to suggest possible helpful procedures. But this one is just not needed. It is already covered in the READ ME, the only thing you added was AimFix.
     
  7. Oh I never noticed the virus scanner i mentioned unless it has been edited to include it. lol. OK then thanks for the help.
    -the new tech guy
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it was not added to the READ ME. It is not needed. The ones already mentioned cover things well enough.
     
  9. Oh ok thanks for the help :)
    -the new tech guy
     
  10. Hey good news on this chas! I just ran aimfix for my reg system maintence today in safe mode and it did not detect the internat.exe thing! Also that is an update to the latest version so i guess he fixed it.
    -the new tech guy
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You mean he removed the false positive detection of c:\windows\system32\internat.exe ?
     
  12. Yup cause i do not see it being detected anymore.
    -the new tech guy
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It took him long enough! ;)
     
  14. Its taking longer still to make a do it all wonder program to clean up every baddie there is to know about on the internet! I think a internet antispyware should be made! lol.
    -the new tech guy
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There will never be a do it all tool because malware stuff changes to frequently and new malware arrives too frequently. Antivirus programs have been around way longer than antispyware, and none of them fix all things they should be fixing either. And they never will either.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds