Dr. Web

Dr. Web
Initial release 1992 (1992)
Stable release 11.0
Development status Active
Operating system Linux
Mac OS X
Microsoft Windows
DOS
OS/2
Windows Mobile
Android
BlackBerry
Available in Russian, English, French, German, Japanese, Korean
Type Antivirus
Website www.drweb.com

Dr.Web is a Russian anti-malware company, and the name of its flagship software suite. First released in 1992, it became the first anti-virus service in Russia.[1] Doctor Web is one of a few anti-virus vendors in the world that owns its technologies for detecting and curing malware.

The software also offers anti-spam solutions and is used by Yandex, Russia's biggest search provider, to scan e-mail attachments. There is also an add-on for all major browsers which checks links with the online version of Dr Web.[2]

Dr.Web has withdrawn from AV tests such as Virus Bulletin VB100% around 2008 stating that they no longer represent the ability to counteract contemporary malware threats.[3]

Main features

Home user products and feature comparison

Dr.Web products for home users come in three variants: Dr.Web Anti-virus, Dr.Web Security Space and Dr.Web Katana. Dr.Web Security Space is the complex antivirus solution that uses all the technologies developed by Dr.Web, Dr.Web Anti-virus is a basic antivirus and Dr.Web Katana is a non-signature anti-virus offering preventive protection against the latest active threats, targeted attacks, and attempts by Trojans and exploits to use vulnerabilities, including zero-day ones, to penetrate systems. It can be used with antivirus software of other vendors in order to apply Dr.Web preemprive protection such products lack.

Dr.Web Security Space Dr.Web Anti-virus Dr.Web Katana
Anti-virus + + -
Preventive protection + + +
Anti-spam + - -
HTTP monitor + + -
Parental Control + - -
Firewall + + -
Anti-virus network + - -
Protection against data loss (backup) + - -
Dr.Web Cloud + - +
Block access to removable devices + - -

Main products

Doctor Web offers products for:

Dr.Web Security Space

Dr.Web Security Space includes applications that provide comprehensive protection for Windows and Android and anti-virus security for Mac OS X, Linux, Symbian OS and Windows Mobile.

CureIt!

Dr.Web CureIt! Is an anti-virus scanner based on Dr.Web Scanning Engine, the standard virus scanning engine of Dr.Web products. Although Dr.Web CureIt! Has limited performance capabilities in comparison with Dr.Web Anti-virus for Windows (no resident monitor, no command line scanner, no updating utility, etc.), it is nevertheless able to effectively scan the system and perform necessary actions for detected threats. You can use Dr.Web CureIt! free of charge to scan your personal computer. For any commercial use of Dr.Web CureIt!, however, a license is required.

CureNet!

A solution for remote centralised curing onWindows PCs and servers, including those running different anti-virus software, regardless of local network size.

Dr.Web Security Space for Android

This anti-virus solution offers a reliable protection of the mobile devices working under the Android™ operating system as well as TV sets, media players and game consoles working under Android TV™ platform from various virus threats designed specifically for these devices.

The application employs the most advanced developments and technologies of Doctor Web aimed at detection and neutralization of malicious objects which may represent a threat to the device operation and information security. Dr.Web uses Origins Tracing™ for Android — the unique algorithm to detect malware designed specially for Android. This algorithm allows detecting the new virus families using the knowledge database on previous threats. Origins Tracing for Android can identify the recompiled viruses, e.g. Android.SMSSend, Android.MobileSpy, as well as the applications infected by Android.ADRD, Android.Geinimi, Android.DreamExploid. The names of the threats detected using Origins Tracing for Android are Android.VirusName.origin.

Users ofDr.Web Security Space or Dr.Web Anti-virus are entitled to use Dr.Web Security Space for Android free of charge.

Dr.Web Katana

A non-signature anti-virus offering preventive protection against the latest active threats, targeted attacks, and attempts by Trojans and exploits to use vulnerabilities, including zero-day ones, to penetrate systems.

Please note that Dr.Web Katana is not a replacement for a signature-based anti-virus; it operates efficiently in conjunction with other anti-viruses besides Dr.Web.

The technologies used in Dr.Web Katana are included in Dr.Web Security Space and Dr.Web Anti-virus 11.0, so users of these products do not need Dr.Web Katana.

Notable discoveries

Flashback Trojan

Dr.Web discovered the Trojan BackDoor.Flashback variant that affected more than 600,000 Macs.[4]

Trojan.Skimer.18

Dr.Web discovered the Trojan.Skimer.18, a Trojan that works like an ATM software skimmer.[5] The Trojan can intercept and transmit bank card information processed by ATMs as well as data stored on the card and its PIN code.

Linux.Encoder.1

Main article: Linux.Encoder.1

Dr.Web discovered the ransomware Linux.Encoder.1 that affected more than 2,000 Linux users.[6] Linux.Encoder.2 which was discovered later turned out to be an earlier version of this ransomware.

Trojan.Skimer discovery and attacks on Doctor Web offices

The day that Doctor Web published a news item about Trojan.Skimer.18 getting recorded in the company’s virus database (December 18, 2013), Doctor Web received a threat supposedly from the Trojan writers or criminal organization sponsoring this malware’s development and promotion:[7]

WARNING!!!
On behalf of Syndicate we congratulate you with successful disassembly of NCR ATM software skimmer. The source code of writers is attached.
Good job but it’s prospectless. Profit from Dr.Web_ATM_shield is dirt-cheap because bankers never give money willingly. However the development of Dr.Web_ATM_shield threatens activity of Syndicate with multi-million dollar profit. Hundreds of criminal organizations throughout the world can lose their earnings.
You have a WEEK to delete all references about ATM.Skimmer from your web resource. Otherwise syndicate will stop cash-out transactions and send criminal for your programmers’ heads. The final of Doctor Web will be tragic.

On March 31, after two arson attacks were carried out on Igor Daniloff’s anti-virus laboratory in St. Petersburg,[8] company received a second threat.

Dear Dr.Web, the International carder syndicate has warned you about avoidance of interference (unacceptable interference) in the ATM sphere. Taking into account the fact that you’ve ignored syndicate’s demands, we employed sanctions. To emphasis the syndicate’s purpose your office at Blagodatnaya st. was burnt twice.
If you don’t delete all references about atmskimmer viruses from your products and all products for ATM, the International carder syndicate will destroy Doctor Web’s offices throughout the world, In addition, syndicate will lobby the Prohibition of usage of Russian anti-viruses Law in countries that have representation offices of the syndicate under the pretext of protection against Russian intelligence service.
Incoming letters of this e-mai are being monitoring, arguments of this dispute will be specified.

Doctor Web released a statement that the company considers it its duty to provide users with the ultimate protection against the encroachments of cybercriminals and consequently, efforts aimed at identifying and studying ATM threats are in progress as is work to improve Dr.Web ATM Shield.[9]

History

1990–1991

1991

1992

1993

1994

1995

1996

1998

1999

2000

2002

2003

2004

2005

2006

2007

2008

2009

2010

2011

2012

2013

2015

See also

References

External links

This article is issued from Wikipedia - version of the Monday, January 04, 2016. The text is available under the Creative Commons Attribution/Share Alike but additional terms may apply for the media files.