If the quarantine directory is on a different directory on the OfficeScan agent endpoint (you can only use absolute path for this scenario), check if the quarantine directory folder exists. Spyware/Grayware scan result unidentified. As soon as you close the browser, Trend is supposed to take care of the issue for you, no action should be required.

From: Les Connor [SBS Community Member - SBS MVP] Re: Why is this virus being detected? Explanation 2: The infected file may be locked by another application, is executing, or is in a CD. Check if the UNC path is correct. First action is Clean but cleaning was unsuccessful.

Solution: Archive the spyware/grayware files and send them to your Support provider. The default Internet Explorer temporary folder in Windows 2000/XP/Server 2003 is C:\Documents and Settings\{Your user name}\Local Settings\Temporary Internet Files. Write-protected infected files Solution: Remove the write-protection to allow OfficeScan to clean the file.

Unable to quarantine the file. Also check if the quarantine directory folder exists and if the UNC path is correct. If you use URL as the quarantine directory format: Ensure that the computer name you specify after "http://" is correct.

For computers running Windows 2000/XP/Server 2003 with NTFS File System: Log on to the computer with Administrator privilege. Unable to clean the file Explanation 1 The infected file may be contained in a compressed file and the "Clean/Delete" infected files within compressed files setting in Agents > Global Agent Solution: Run a Manual Scan and wait for the scan to finish. Refer to the following page on the Trend Micro online Virus Encyclopedia for information about probable virus/malware and how to submit suspicious files to Trend Micro for analysis.

Since the computer downloads files while you are browsing the Web, the Web browser may have locked the infected file. I think there are some possible solutions: 1.(my favorite) delete all virus infected mail rather than clean or quarantine. 2. Second action is "Rename" and the infected file was renamed. Nick "Les Connor [SBS Community Member - SBS MVP]" wrote in message news:[email protected] Hi Nick, It looks like it's being scanned on backup while the volume shadow copy is being

OfficeScan did not perform any action on the infected file. Unable to quarantine the file/Unable to rename the file Explanation 1 The infected file may be locked by another application, is executing, or is on a CD. Since the endpoint downloads files while you are browsing, the web browser may have locked the infected file. In the Manual Scan Result tab on the OfficeScan client, detected virus/malware cannot be cleaned, deleted or renamed.

Second action is Rename and the infected file was renamed. For details and solutions, see Uncleanable Files. Also check if the quarantine directory folder exists and if the UNC path is correct. The second level results are as follows: Cleaned: OfficeScan terminated processes or deleted registries, files, cookies and shortcuts.

Solution: Run Manual Scan so OfficeScan can clean or quarantine the file. Close all running applications to prevent applications from locking the file, which would make Windows unable to delete it. Solution: Stop the processes that use the temporary file.

Ran it a second time, and showed everything clear. Connect with top rated Experts 21 Experts available now in Live! Because the file is locked, Trend can't do anything with it until you close IE.

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=POSSIBLE_VIRUS&VSect=Sn B.

Scan action was successful when the following scan results display: Scan Result Explanation The first level result is "Successful, no action required". The OfficeScan client may display that cleaning, deleting or renaming is successful but no action is actually performed on the infected file. When the web browser releases the file, OfficeScan will delete the file.

Check the size of the infected file. Trend Micro Discovered Virus: Troj_agent.ahqy Infected files in the Recycle Bin: OfficeScan may not remove infected files in the Recycle Bin because the system is running.

