I'd still argue... If the malicious code is a known variant and recides in the computer exploiting the stated flaw, here are ppl. argueing the AV will catch it during execution anyways. BUT there are many scenerios when ADVANCE HERCULES SCAN, suspecious activity scans etc are only (mostly) enabled for testing DURING MANUAL SCANS as having those enabled during auto protect would cause significant preformance problems. (think of this scenerio again) & lastly... NOD32 has an option to scan inside ADS too. guys..... could anyone suggest any AV that isn't buggy to this trick? ----- on vacation, -bipin