PDA

View Full Version : Errors and limitations of viruscanners


Pachomius2000
09-05-2004, 05:09 AM
Do you people here experience limitations and errors among various viruscanners?

For example, over some two years back, I had some very bad virus infecting the master boot records of FDDs and HDDs, which McAfee and others of prominence, if I remember rightly, could not remove, telling me instead to reformat the disks.

But the short program AVPlite from a low profile Russian -- can't recall his name now, in DOS version and freely available in the net at that time, could easily and quickly remove without any so much as a hint of any reformatting.

Now, earlier today I was wondering why I couldn't access Google (and up to now still cannot), and my ISP told me it could be a virus. So I did a free online viruscan by Bitdefender.

You know what Bitdefender detected and could not clean? Read these lines from Bitdefender:


C:\program files\network associates\mcafee viruscan\bootscan.exe. Infected with the virus one_half.3570. Unable to clean virus.

C:\program files\network associates\mcafee viruscan\scan86.exe Infected with the virus one_half.3570. Unable to clean virus.


So I looked up the net for this virus and found it described in McAfee website. I thought I should gave them this finding of Bitdfender, which I did; and I asked them also how this virus got into files coming from them, with the request to reply.*

Afterwards I did a viruscan with AVG, the free version which I got from its website, and which I use occasionally.

You know what AVG found out: No viruses found in the concerned directory; but Bitdefender found it everytime I tried it again and again, for the purpose of double checking.

What do you guys say about that?

And what is that darn virus that is stopping me from accessing Google. Up to now, the notice returned is that his page or whatever cannot be downloaded, etc., to check your modem, or your isp, whatever.

Pachomius2000

*Is Bitdefender playing a joke on McAfee?

david eaton
09-05-2004, 09:17 AM
That sounds like a false positive. All A/Vs have a tendency to this sort of thing, particularly if they use heuristic scanning.
If AVG doesn not detect it, then a false positive is almost certain.

As regards your Google problem, please download http://tools.zerosrealm.com/hjt.zip
Copy it into its own folder, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, do Ctrl-A to Select All, and copy its contents here. Most of what it lists will be harmless or even essential, don't fix anything yet.