Page 3 of 3

Posted: Tue May 02, 2006 3:10 pm
by josku_x
Last week I nearly couldn't go to the net as I was infected by a virus that pinged other network users, so my operator had to suspend me for one hour and they gave me instructions of what I should do. Here's a part of it:

Code: Select all

... Protecting yourself and others from being attacked by a virus is as easy as the alphabet. Our partner, F-Secure offers a free online scanning tool with which you can get more information about the virus your computer is infected. ...
So, I scanned my PC, the scanner told me I had a Dr. Watson virus. When I got instructions removing the virus, I had to remove the drwtsn32.exe file which was a virus instead of the real Dr. Watson logging software. After I restarted my PC, I was able to access the net, but my XP stopped to work on many behaviors, I couldn't play my Megaman X games! :cry: . I backed up all my files to another harddrive, made a clean install and copied the files back. Now, everything seems to run smoothly, but I am afraid I get the virus again, as my antivirus (NOD32) didn't catch it.

I don't have the virus anymore, but after you get your first stable release of the PureAV done, try to make it better than NOD32, even if the virus databases of NOD32 are more than 50Mb+.

Posted: Tue May 02, 2006 3:15 pm
by Inf0Byt3
To make it better than NOD32.... I think this is 100% impossible... They have extremely well made heuristics... I made a test keylogger and it detected it instantly. Now that's what I call protection. Still, has anybody got any ideas of how to compare a memory location with other 52000 very fast? I simply cannot find a solution and this decepts me... Any idea is welcome.