PDA

View Full Version : win32.Fujack.a worm! Please help, greatly appreciated!



Matthew Lim
2007-12-15, 09:11
Hi there. Been lurking around for some time, but i guess now it's my turn to post sadly. First of all just wanna thank the great effort and help from the team, u guys are great!

So yesterday some friends came over, surfed some net and transferred some psp games, and now my pc is infected with a virus called Worm.Win32.Fujack.a i think.

Some 'damages' i've noticed already.
-I can't open Mozilla firefox, which is my main browser. Am using IE at the moment.
-At windows explorer, when I double click the local drives icon (C and E), they don't open, but give a message saying "Please go to the control panel to install and configure system components". I can, however, right click and explore to open.
-My net seems abit weird too, like problems connecting, but that happened twice only.


I did everything in the "Before u post" thread, as well as scanning with avast, AVG and bitdefender. About 5k infected files are moved into quarantine but none of them can heal/disinfect. Also used Ad-aware/Cleanup!/Spybot to clear everything.

Thanks guys in advance, looking forward to replies.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:03:18 PM, on 12/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
E:\iTunes\iTunesHelper.exe
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 7022 bytes

Matthew Lim
2007-12-15, 09:12
There wasn't enough space above so i'm posting the Kapersky log here, sorry for inconvenience caused.



-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, December 15, 2007 3:30:13 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/12/2007
Kaspersky Anti-Virus database records: 483173
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 100109
Number of viruses found: 3
Number of infected objects: 83
Number of suspicious objects: 0
Duration of the scan process: 01:16:32

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\User\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\ApplicationHistory\cli.exe.c88dbd71.ini.inuse Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Messenger\theaveragekid@hotmail.com\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Messenger\theaveragekid@hotmail.com\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Messenger\theaveragekid@hotmail.com\SharingMetadata\Working\database_728C_822D_8C81_EBC3\dfsr.db Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Messenger\theaveragekid@hotmail.com\SharingMetadata\Working\database_728C_822D_8C81_EBC3\fsr.log Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Messenger\theaveragekid@hotmail.com\SharingMetadata\Working\database_728C_822D_8C81_EBC3\fsrtmp.log Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Messenger\theaveragekid@hotmail.com\SharingMetadata\Working\database_728C_822D_8C81_EBC3\tmp.edb Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows Live Contacts\theaveragekid@hotmail.com\real\members.stg Object is locked skipped
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows Live Contacts\theaveragekid@hotmail.com\shadow\members.stg Object is locked skipped
C:\Documents and Settings\User\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\History\History.IE5\MSHist012007121520071216\index.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temp\Perflib_Perfdata_48c.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temp\Perflib_Perfdata_b54.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temp\Perflib_Perfdata_b5c.dat Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temp\~DF11D3.tmp Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temp\~DFB473.tmp Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temp\~DFB50A.tmp Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temp\~DFD684.tmp Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temp\~DFD697.tmp Object is locked skipped
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\User\My Documents\My Music\iTunes\iTunes Library.itl Object is locked skipped
C:\Documents and Settings\User\ntuser.dat Object is locked skipped
C:\Documents and Settings\User\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\ATI Technologies\ATI.ACE\sv\Help\wwhelp\wwhimpl\java\html\explore6.htm Infected: Worm.Win32.Fujack.a skipped
C:\Program Files\ATI Technologies\ATI.ACE\th\Help\DisplayOptions_DisplayOptions_1_0_0001.html Infected: Worm.Win32.Fujack.a skipped
C:\Program Files\ATI Technologies\ATI.ACE\th\Help\wwhelp\wwhimpl\java\html\explore6.htm Infected: Worm.Win32.Fujack.a skipped
C:\Program Files\ATI Technologies\ATI.ACE\tr\Help\MMVideo_VIDEOVISION_1_0_0001.html Infected: Worm.Win32.Fujack.a skipped
C:\Program Files\ATI Technologies\ATI.ACE\tr\Help\MultiVPU_MultiVPU_1_0_0001.html Infected: Worm.Win32.Fujack.a skipped
C:\Program Files\ATI Technologies\ATI.ACE\tr\Help\wwhelp\wwhimpl\java\html\explore6.htm Infected: Worm.Win32.Fujack.a skipped
C:\Program Files\ATI Technologies\ATI.ACE\zh-CHS\Help\wwhelp\wwhimpl\java\html\explore6.htm Infected: Worm.Win32.Fujack.a skipped
C:\Program Files\ATI Technologies\ATI.ACE\zh-CHT\Help\wwhelp\wwhimpl\java\html\explore6.htm Infected: Worm.Win32.Fujack.a skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{182B7C2C-BE99-42FC-9A84-E34DC2D556F8}\RP171\A0011231.dll Infected: Trojan-PSW.Win32.QQPass.ajx skipped
C:\System Volume Information\_restore{182B7C2C-BE99-42FC-9A84-E34DC2D556F8}\RP171\A0011239.exe Infected: Worm.Win32.Small.n skipped
C:\System Volume Information\_restore{182B7C2C-BE99-42FC-9A84-E34DC2D556F8}\RP171\A0011240.exe Infected: Worm.Win32.Small.n skipped
C:\System Volume Information\_restore{182B7C2C-BE99-42FC-9A84-E34DC2D556F8}\RP172\A0011423.exe Infected: Worm.Win32.Small.n skipped
C:\System Volume Information\_restore{182B7C2C-BE99-42FC-9A84-E34DC2D556F8}\RP172\A0011427.dll Infected: Trojan-PSW.Win32.QQPass.ajx skipped
C:\System Volume Information\_restore{182B7C2C-BE99-42FC-9A84-E34DC2D556F8}\RP175\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\bdss.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_634.dat Object is locked skipped
C:\WINDOWS\Temp\tmp000068af\tmp00000000 Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\Games\World of Warcraft\Burning Crusade Install Log.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\connection-help.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Credits.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Credits_BC.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Layout\BSpacer.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Layout\CSpacer.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Layout\Greeting.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Layout\Index.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Layout\LBorder.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Layout\Nav.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Layout\RBorder.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Layout\Requirements.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Layout\Splash.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Layout\TBorder.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(Mac)Foreword.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(Mac)Installation.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(Mac)Patching.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(Mac)ReadMeMenu.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(Mac)SystemRequirements.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(Mac)Uninstall.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(PC)Foreword.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(PC)Installation.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(PC)Patching.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(PC)ReadMeMenu.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(PC)SystemRequirements.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\(PC)Uninstall.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\BasicCommands.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\CharacterNaming.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\EULA.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\GettingStarted.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\ManualErrata.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\ReadMe\RealmSelection.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Support\(Mac)SupportMenu.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Support\(Mac)TechnicalSupport.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Support\(PC)SupportMenu.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Support\(PC)TechnicalSupport.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Support\AccountAdministration.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Support\BlizzardInsider.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Support\Employment.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Support\GameSuggestions.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Support\GameSupport.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Support\Password.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(Mac)AudioProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(Mac)BlizzardDownloaderProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(Mac)ConnectionLoginProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(Mac)GameplayProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(Mac)Install.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(Mac)PreventiveMaintenance.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(Mac)StartupProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(Mac)TroubleshootingMenu.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(Mac)VideoProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(PC)AudioProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(PC)BlizzardDownloaderProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(PC)ConnectionLoginProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(PC)GameplayProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(PC)Install.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(PC)PreventiveMaintenance.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(PC)StartupProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(PC)TroubleshootingMenu.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\Documentation\Troubleshooting\(PC)VideoProblems.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\eula.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Data\enUS\tos.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Interface\AddOns\Quartz\Quartz ReadMe.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\Patch.html Infected: Worm.Win32.Fujack.a skipped
E:\Games\World of Warcraft\World of Warcraft Install Log.html Infected: Worm.Win32.Fujack.a skipped
E:\Internet Downloads\939923471.htm Infected: Worm.Win32.Fujack.a skipped
E:\Internet Downloads\photekui-x8-1-photekui-x8-1-normal\PhotekUIX81 Normal\Interface\AddOns\Quartz\Quartz ReadMe.html Infected: Worm.Win32.Fujack.a skipped
E:\Internet Downloads\profilehistory.php Infected: Worm.Win32.Fujack.a skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{182B7C2C-BE99-42FC-9A84-E34DC2D556F8}\RP171\A0011241.exe Infected: Worm.Win32.Small.n skipped
E:\System Volume Information\_restore{182B7C2C-BE99-42FC-9A84-E34DC2D556F8}\RP172\A0011424.exe Infected: Worm.Win32.Small.n skipped
E:\System Volume Information\_restore{182B7C2C-BE99-42FC-9A84-E34DC2D556F8}\RP175\change.log Object is locked skipped

Scan process completed.