Click on screenshot to zoom
Danger level 5
Type: Worms

MH690.A

MH690.A is classified as a Worm infection, which is also regarded as cloaked malware and a malware downloader.

Therefore MH690.A should not be trusted or taken lightly, and should be removed as soon as its presence has been detected.

MH690.A has been seen to perform the following behavior:

* The Process is packed and/or encrypted using a software packing process
* This process creates other processes on disk
* This Process Deletes Other Processes From Disk
* Executes a Process
* Checks for the use of debuggers
* Can communicate with other computer systems using HTTP protocols
* Registers a Dynamic Link Library File
* Adds a Registry Key (RUN) to auto start Programs on system start up
* Creates system tray popups, messages, errors and security warnings
* Found on infected systems and resists interrogation by security products
* The Process is polymorphic and can change its structure
* Ability to execute files automatically on your PC
* Disables the built in Windows File Protection System
* Terminates Processes
* Uses rootkit techniques to conceal its presence, interrogation or removal
* Disables safe mode on your PC
* Looks at the contents of the autoexec.bat file
* Reads email address and phone book details

MH690.A is quite dangerous if left to its own devices on a computer system. It is therefore recommended to employ the services of a fully functional and up to date antispyware application, in order to rid the system infected of MH690.A and all its affiliated components.

Download Spyware Removal Tool to Remove* MH690.A
  • Quick & tested solution for MH690.A removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove MH690.A

Files associated with MH690.A infection:

service.exe
internat.exe

MH690.A processes to kill:

service.exe
internat.exe

Remove MH690.A registry entries:

HKEY_CURRENT_USERSOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN internat
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN WinNT 32
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ internat
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ WinNT 32
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.