or maybe just a false positive? Rather strange, because it was only detected yesterday when I was starting DrWeb to download updates. Couldnt have been on my system for longer than an hour though. DrWeb eradicated it as you can tell, and I rebooted after to make sure I got it . I was fully patched from MS, running a firewall, and am not running SQL. I think the worm was found in the memory of one of my active processes for my firewall. It does look like a positive identification from DrWeb though. Any thoughts or anyone with a similar experience, to maybe confirm a false positive? Thanks!