Passed a potential security risk This scan result only displays when OfficeScan detects "probable virus/malware" during Manual Scan, Scheduled Scan, and Scan Now.

MS TCP Loopback interface 0x2 ...00 1d 60 9a ce 94 ...... Related: What can I do to minimize the risk of a malware attack? R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-10-7 35168] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-4-18 176128] R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-7-18 181616] R2 ConfigFree Service;ConfigFree Unable to clean the file Explanation 1 The infected file may be contained in a compressed file and the "Clean/Delete" infected files within compressed files setting in Agents > Global Agent http://www.techsupportforum.com/forums/f284/threat-found-in-memory-unable-to-clean-649640.html

See below for a list of notifications that you might see from your ESET product and our suggestions about how to follow-up when you see them: Threat found Figure 1-1

Once the scan is complete, you may receive another notice about rootkit activity.Click OK.GMER will produce a log. Check the size of the infected file.

Please copy and paste the contents of that file here.If a reboot is required, the report can also be found in your root directory (usually C:\ folder)

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal

Eset Threats Found But Not Cleaned

This is a copy of your MBR. They may otherwise interfere with our tools Double click on ComboFix.exe & follow the prompts. How To Delete Threats In Eset Nod32 If you don't know how, please see the link below: How to Disable Your Security Applications Your desktop may go blank. Eset How To Clean Infected Files c:\windows\system32\atieclxx.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe c:\windows\system32\TODDSrv.exe c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe c:\program

Solution: See Unable to quarantine the file/Unable to rename the file.

Navigate to your Desktop, right-click Recycle Bin and select Empty Recycle Bin. Solution For infected files on a CD, consider not using the CD as the virus may infect other computers on the network. When the web browser releases the file, OfficeScan will delete the file.

File Check: ======== C:\windows\system32\dhcpcsvc.dll => MD5 is legit C:\windows\system32\Drivers\afd.sys => MD5 is legit C:\windows\system32\Drivers\netbt.sys => MD5 is legit C:\windows\system32\Drivers\tcpip.sys => MD5 is legit C:\windows\system32\Drivers\ipsec.sys => MD5 is legit C:\windows\system32\dnsrslvr.dll => MD5 Newer versions of Zbot are capable of injecting code into the address space of all running processes matching the privilege of the currently logged on user. Checking ImagePath: Attention! How To Prevent Eset From Deleting A File The ServiceDll of sharedaccess service is OK.

I left Combo Fix for over an hour and nothing changed in the dos box past "Attempting to create system restore point".

If the quarantine directory is on a different directory on the OfficeScan agent endpoint (you can only use absolute path for this scenario), check if the quarantine directory folder exists. C:\windows\system32\wininit.exe C:\windows\system32\lsm.exe C:\windows\system32\atiesrxx.exe C:\windows\system32\atieclxx.exe C:\windows\System32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\Program In most cases, your ESETproduct will clean, quarantine or block threats that result in this type of notification. That may cause it to stallNote 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer"information and logs"In