WFBI.EXE - Dangerous
WFBI.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
WFBI.EXE is known as: Malware.Sality [PCTools] W32.Sality.AE [Symantec] Virus.Win32.Sality.bh [Kaspersky Lab] W32/Sality.gen.e [McAfee] Mal/Sality-D [Sophos] Worm:Win32/Sality.AU [Microsoft] Virus.Win32.Virut [Ikarus] Win32/Kashu.E [AhnLab].
MD5 of WFBI.EXE = 73004F90E56D86C7B87810BCC7415220
WFBI.EXE size is 123619 bytes.
Full path on a computer: C:\WFBI.EXE
Related Files:
C:\AUTORUN.INF
%WINDIR%\TEMP\HS5JWSL7D.EXE
C:\E
%PROGRAMFILES%\STARTNOW TOOLBAR\RESOURCES\PROTECT\NOTIE6.CSS
%PROGRAMFILES%\STARTNOW TOOLBAR\RESOURCES\PROTECT\ONLYIE6.CSS
%PROGRAMFILES%\STARTNOW TOOLBAR\RESOURCES\PROTECT\WINDOW.CSS
%PROGRAMFILES%\STARTNOW TOOLBAR\RESOURCES\PROTECT\WINDOW.JS
%PROGRAMFILES%\STARTNOW TOOLBAR\RESOURCES\REACTIVATE\NOTIE6.CSS
%PROGRAMFILES%\STARTNOW TOOLBAR\RESOURCES\REACTIVATE\ONLYIE6.CSS
%PROGRAMFILES%\STARTNOW TOOLBAR\RESOURCES\REACTIVATE\WINDOW.CSS
%PROGRAMFILES%\STARTNOW TOOLBAR\RESOURCES\REACTIVATE\WINDOW.JS
%PROGRAMFILES%\STARTNOW TOOLBAR\STARTNOWTOOLBARUNINSTALL.EXE
%PROGRAMFILES%\STARTNOW TOOLBAR\TOOLBAR32.DLL
%PROGRAMFILES%\STARTNOW TOOLBAR\TOOLBARUPDATERSERVICE.EXE
%PROGRAMFILES%\STARTNOW TOOLBAR\UNINSTALL.DAT
C:\WFBI.EXE
%WINDIR%\NT.EXE
%SYSTEM%\31RVUK6.LOG
%SYSTEM%\CM22.LOG
%SYSTEM%\MSQS.EXE
%SYSTEM%\MSSF32.DLL
%SYSTEM%\MSXF.EXE
%SYSTEM%\NWCWKS.DLL
%SYSTEM%\USER.INI
%WINDIR%\TASKMANAGER.BAT
%WINDIR%\TASKMANAGER.EXE
%WINDIR%\TEMP\1AVS.LOG
%WINDIR%\TEMP\7CHTBBMF.EXE
%WINDIR%\TEMP\8NRN.EXE
%WINDIR%\TEMP\9FO7L6NZ.EXE
%WINDIR%\TEMP\BXUUTWMR.EXE
%WINDIR%\TEMP\CONIMA
%WINDIR%\TEMP\DETOURED.DLL
%WINDIR%\TEMP\ETUJ4WJEBE.EXE
%WINDIR%\TEMP\GICU4ZOB.EXE
%WINDIR%\TEMP\INPUT MANAGER.BAT
%WINDIR%\TEMP\MLOG
%WINDIR%\TEMP\MOUSEDRIVER.BAT
%WINDIR%\TEMP\NEW5.TMP
%WINDIR%\TEMP\NSO10.TMP\REGISTRY.DLL
%WINDIR%\TEMP\NSW1E.TMP\BRANDINGURL.DLL
%WINDIR%\TEMP\NSO10.TMP\IMINSTALLER.EXE
%WINDIR%\TEMP\RTYIKW5HQ4JH.INI
%WINDIR%\TEMP\PLUG.BAT
%WINDIR%\TEMP\QTFCYYP.EXE
%WINDIR%\TEMP\VZCIBXTUS.EXE