SHABI.EXE - Dangerous
SHABI.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
SHABI.EXE is known as: W32.Virut.CF [Symantec] Virus.Win32.Virut.ce [Kaspersky Lab] W32/Virut.n.gen [McAfee] W32/Scribble-B [Sophos] Virus:Win32/Virut.BN [Microsoft] Trojan-Spy.Win32.VB [Ikarus] Win32/Virut.F [AhnLab].
MD5 of SHABI.EXE = 00368A1D06670BB431275DE616915589
SHABI.EXE size is 56320 bytes.
Full path on a computer: %WINDIR%\TEMP\SHABI.EXE
Related Files:
%COMMONAPPDATA%\COMMON.DATA
%APPDATA%\ADOBE\MSIMSIMSI97\MSFTCORE.DAT
%APPDATA%\ADOBE\MSIMSIMSI97\MSFTCORE.DLL
%WINDIR%\TEMP\MSFTDM.EXE
%WINDIR%\TEMP\MSFTDM32.EXE
%APPDATA%\ADOBE\MSIMSIMSI97\MSFTEML.DLL
%APPDATA%\ADOBE\MSIMSIMSI97\MSFTLDR.DLL
%WINDIR%\TEMP\MSFTMOD.DAT
%APPDATA%\ADOBE\MSIMSIMSI97\MSFTSTP.EXE
%APPDATA%\ADOBE\MSIMSIMSI97\MSFTTCP.DLL
%TEMP%\0T70U3AZY.BAT
%TEMP%\1AVS.LOG
%WINDIR%\TEMP\2QW9.EXE
%TEMP%\D5JD6GNB.BAT
%WINDIR%\TEMP\QTFCYYP.EXE
%WINDIR%\TEMP\SHABI.EXE
%TEMP%\X4KH12PT6.EXE
%PROGRAMS%\STARTUP\WINUPDATE.LNK
C:\PERFECT\CONFIG.BIN
C:\PERFECT\PERFECT.EXE
%SYSTEM%\NWCWKS.DLL
%SYSTEM%\NWSAPAGENTS.DLL
%SYSTEM%\RFNRP1.LOG
%WINDIR%\TEMP\1AVS.LOG
%WINDIR%\TEMP\4FTU184PZ.EXE
%WINDIR%\TEMP\7R2PT6C5.EXE
%WINDIR%\TEMP\JCMTHH88.EXE
%WINDIR%\TEMP\MLOG
%WINDIR%\TEMP\MSFTCORE.DAT
%WINDIR%\TEMP\MSFTCORE.DLL
%WINDIR%\TEMP\MSFTEML.DLL
%WINDIR%\TEMP\MSFTLDR.DLL
%WINDIR%\TEMP\MSFTSTP.EXE
%WINDIR%\TEMP\MSFTTCP.DLL