Mi ha trovato 3 virus che gli hanno negato l'accesso e che non è riuscito a spostare in quarantena.
Uno di questi è sicuramente monrdfxa.exe perché già con AVAST l'avevo beccato ma non sono mai riuscito ad eliminarlo nemmeno con DELETE DOCTOR o UNLOKER (più o meno si scrive così).
Se qualcuno di Voi mi saprebbe indicare una nuova strada per eliminarli definitivamente senza formattare gliene sarei grato.
AntiVir PersonalEdition Classic
Report file date: martedì 30 ottobre 2007 21:00
Scanning for 910788 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 1) [5.1.2600]
Username: SYSTEM
Computer name: ROBERTA280864
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/07 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 30/10/07 19:51:34
AVSCAN.DLL : 7.0.6.0 49192 Bytes 30/10/07 19:51:34
LUKE.DLL : 7.0.5.3 147496 Bytes 30/10/07 19:51:34
LUKERES.DLL : 7.0.6.1 10280 Bytes 30/10/07 19:51:35
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/07 19:51:40
ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/07 19:51:40
ANTIVIR2.VDF : 7.0.0.140 940544 Bytes 26/10/07 19:51:40
ANTIVIR3.VDF : 7.0.0.155 93696 Bytes 30/10/07 19:51:40
AVEWIN32.DLL : 7.6.0.30 3056128 Bytes 30/10/07 19:51:42
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/07 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 30/10/07 19:51:34
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/07 13:16:24
AVPACK32.DLL : 7.3.0.15 360488 Bytes 30/10/07 19:51:42
AVREG.DLL : 7.0.1.6 30760 Bytes 30/10/07 19:51:34
AVARKT.DLL : 1.0.0.20 278568 Bytes 30/10/07 19:51:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 30/10/07 19:51:34
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/07 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 30/10/07 19:51:21
RCTEXT.DLL : 7.0.62.0 86056 Bytes 30/10/07 19:51:21
SQLITE3.DLL : 3.3.17.1 339968 Bytes 30/10/07 19:51:35
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\programmi\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: martedì 30 ottobre 2007 21:00
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'mioSync.exe' - '1' Module(s) have been scanned
Scan process 'ashWebSv.exe' - '1' Module(s) have been scanned
Scan process 'ashMaiSv.exe' - '1' Module(s) have been scanned
Scan process 'vsmon.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'SAgent2.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'EPSON CardMonitor1.0.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'SUPERAntiSpyware.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'zlclient.exe' - '0' Module(s) have been scanned
Scan process 'qttask.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'ashDisp.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'ashServ.exe' - '1' Module(s) have been scanned
Scan process 'aswUpdSv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'InCDsrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
38 processes with 38 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '44' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\msipsr.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinAD.D
[INFO] The file was moved to '47908dd3.qua'!
C:\msupdate.exe
[DETECTION] Contains detection pattern of the worm WORM/Rbot.159554
[INFO] The file was moved to '479c8dd5.qua'!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Roberta Mavero\Dati applicazioni\Sun\Java\Deployment\cache\javapi\v1.0\jar\eRT.jar-4d53972-2891fa66.zip
[0] Archive type: ZIP

[DETECTION] Is the Trojan horse TR/Java.Downloader.Gen
[INFO] The file was moved to '477b9226.qua'!
C:\Documents and Settings\Roberta Mavero\Dati applicazioni\Sun\Java\Deployment\cache\javapi\v1.0\jar\itrRT.jar-567de1b6-1e3da05a.zip
[0] Archive type: ZIP

[DETECTION] Is the Trojan horse TR/Java.Downloader.Gen
[INFO] The file was moved to '4799924e.qua'!
C:\Documents and Settings\Roberta Mavero\Desktop\[PC GAME NO CD]FIFA 2008 crack.zip
[0] Archive type: ZIP

[DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
[1] Archive type: ZIP SFX (self extracting)
[INFO] The file was moved to '476a92af.qua'!
C:\Documents and Settings\Roberta Mavero\Desktop\ANDRE\altro\install.exe
[DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
[INFO] The file was moved to '479a932a.qua'!
C:\Documents and Settings\Roberta Mavero\Desktop\GIOCHI\FIFA06\FIFA06-NODVD.rar
[0] Archive type: RAR

[DETECTION] Is the Trojan horse TR/Dldr.Small.bws.20
[INFO] The file was moved to '476d996c.qua'!
C:\System Volume Information\_restore{60B4AD22-0E09-46BA-82D5-96B0CDC7E57E}\RP1\A0000036.cmd
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/KillAV.BJ Backdoor server programs
[INFO] The file was moved to '4757aa6f.qua'!
C:\System Volume Information\_restore{60B4AD22-0E09-46BA-82D5-96B0CDC7E57E}\RP1\A0000037.exe
[0] Archive type: RAR SFX (self extracting)

[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/KillAV.BJ Backdoor server programs
[INFO] The file was moved to '4757aa75.qua'!
C:\System Volume Information\_restore{60B4AD22-0E09-46BA-82D5-96B0CDC7E57E}\RP1\A0000059.exe
[0] Archive type: RAR SFX (self extracting)

[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/KillAV.BJ Backdoor server programs
[INFO] The file was moved to '4757aa7b.qua'!
C:\System Volume Information\_restore{60B4AD22-0E09-46BA-82D5-96B0CDC7E57E}\RP1\A0000063.cmd
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/KillAV.BJ Backdoor server programs
[INFO] The file was moved to '4757aa7d.qua'!
C:\System Volume Information\_restore{60B4AD22-0E09-46BA-82D5-96B0CDC7E57E}\RP2\A0002118.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinAD.D
[INFO] The file was moved to '4757aa81.qua'!
C:\System Volume Information\_restore{60B4AD22-0E09-46BA-82D5-96B0CDC7E57E}\RP3\A0002186.exe
[0] Archive type: RAR SFX (self extracting)

[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/KillAV.BJ Backdoor server programs
[INFO] The file was moved to '4757aa85.qua'!
C:\System Volume Information\_restore{772D45A0-3BD3-4DBE-AAC3-6A34C5671DE4}\RP12\A0035816.exe
[DETECTION] Is the Trojan horse TR/Agent.afy.7
[INFO] The file was moved to '4757aaa3.qua'!
C:\System Volume Information\_restore{772D45A0-3BD3-4DBE-AAC3-6A34C5671DE4}\RP12\A0036846.exe
[DETECTION] Is the Trojan horse TR/Agent.afy.7
[INFO] The file was moved to '4757aaa9.qua'!
C:\System Volume Information\_restore{772D45A0-3BD3-4DBE-AAC3-6A34C5671DE4}\RP12\A0036888.exe
[DETECTION] Is the Trojan horse TR/Agent.afy.7
[INFO] The file was moved to '4757aaac.qua'!
C:\System Volume Information\_restore{772D45A0-3BD3-4DBE-AAC3-6A34C5671DE4}\RP12\A0036919.exe
[DETECTION] Is the Trojan horse TR/Agent.afy.7
[INFO] The file was moved to '4757aaaf.qua'!
C:\System Volume Information\_restore{772D45A0-3BD3-4DBE-AAC3-6A34C5671DE4}\RP13\A0038026.exe
[DETECTION] Is the Trojan horse TR/LinkOptimiz.10.A
[INFO] The file was moved to '4757aab8.qua'!
C:\System Volume Information\_restore{772D45A0-3BD3-4DBE-AAC3-6A34C5671DE4}\RP13\A0038027.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinAD.D
[INFO] The file was moved to '4757aaba.qua'!
C:\System Volume Information\_restore{772D45A0-3BD3-4DBE-AAC3-6A34C5671DE4}\RP13\A0038028.exe
[DETECTION] Contains detection pattern of the worm WORM/Rbot.159554
[INFO] The file was moved to '4757aabb.qua'!
C:\System Volume Information\_restore{772D45A0-3BD3-4DBE-AAC3-6A34C5671DE4}\RP13\A0038034.exe
[DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
[INFO] The file was moved to '4757aabd.qua'!
C:\WINDOWS\system32\monrdfxa.exe
[WARNING] The file could not be opened!
End of the scan: martedì 30 ottobre 2007 23:21
Used time: 2:21:14 min
The scan has been done completely.
5156 Scanning directories
248647 Files were scanned
19 viruses and/or unwanted programs were found
2 Files were classified as suspicious:
0 files were deleted
0 files were repaired
21 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
248628 Files not concerned
1426 Archives were scanned
2 Warnings
7 Notes
Grazie per l'aiuto.
Ciao