Dr.Web

Last updated
Dr.Web
Developer(s) Doctor Web
Initial release1992 (1992)
Stable release
12.0
Operating system Linux
macOS
Microsoft Windows
DOS
OS/2
Windows Mobile
Android
BlackBerry
Available in6 languages
List of languages
Type Antivirus
Website www.drweb.com
Dr.Web shield icon Drweb logo.png
Dr.Web shield icon

Dr.Web is a software suite developed by Russian anti-malware company Doctor Web. First released in 1992, it became the first anti-virus service in Russia. [1]

Contents

The company also offers anti-spam solutions and is used by Yandex to scan e-mail attachments. It also features an add-on for all major browsers which checks links with the online version of Dr Web. [2]

Dr.Web has withdrawn from AV tests such as Virus Bulletin VB100% around 2008 stating that they believe that virus scans on viruses are different subject from that of real world malware attacks. [3]

Critics, reviews and reliability

Staunch anti-adware policy led to software developers complaining that Dr.Web treated their virus free applications as a "virus". When developers tried contacting Dr.Web to resolve the issue, developers received no response. [4] [5]

Notable discoveries

Flashback Trojan

Dr.Web discovered the Trojan BackDoor.Flashback variant that affected more than 600,000 Macs. [6]

Trojan.Skimer.18

Dr.Web discovered the Trojan.Skimer.18, a Trojan that works like an ATM software skimmer. [7] The Trojan can intercept and transmit bank card information processed by ATMs as well as data stored on the card and its PIN code.

Linux.Encoder.1

Dr.Web discovered the ransomware Linux.Encoder.1 that affected more than 2,000 Linux users. [8] Linux.Encoder.2 which was discovered later turned out to be an earlier version of this ransomware.

Trojan.Skimer discovery and attacks on Doctor Web offices

Doctor Web received a threat supposedly from the Trojan writers or criminal organization sponsoring this malware's development and promotion: [9] On March 31, 2014, after two arson attacks were carried out on Igor Daniloff's anti-virus laboratory in St. Petersburg, [10] company received a second threat. Doctor Web released a statement that the company considers it its duty to provide users with the ultimate protection against the encroachments of cybercriminals and consequently, efforts aimed at identifying and studying ATM threats with their ATM Shield. [11]

See also

Related Research Articles

Malware is any software intentionally designed to cause disruption to a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, deprive access to information, or which unknowingly interferes with the user's computer security and privacy. Researchers tend to classify malware into one or more sub-types.

<span class="mw-page-title-main">Timeline of computer viruses and worms</span> Computer malware timeline

This timeline of computer viruses and worms presents a chronological timeline of noteworthy computer viruses, computer worms, Trojan horses, similar malware, related research and events.

<span class="mw-page-title-main">Antivirus software</span> Computer software to defend against malicious computer viruses

Antivirus software, also known as anti-malware, is a computer program used to prevent, detect, and remove malware.

Linux malware includes viruses, Trojans, worms and other types of malware that affect the Linux family of operating systems. Linux, Unix and other Unix-like computer operating systems are generally regarded as very well-protected against, but not immune to, computer viruses.

<span class="mw-page-title-main">ClamAV</span> Open-source antivirus software

ClamAV (antivirus) is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses. It was developed for Unix and has third party versions available for AIX, BSD, HP-UX, Linux, macOS, OpenVMS, OSF (Tru64), Solaris and Haiku. As of version 0.97.5, ClamAV builds and runs on Microsoft Windows. Both ClamAV and its updates are made available free of charge. One of its main uses is on mail servers as a server-side email virus scanner.

Scareware is a form of malware which uses social engineering to cause shock, anxiety, or the perception of a threat in order to manipulate users into buying unwanted software. Scareware is part of a class of malicious software that includes rogue security software, ransomware and other scam software that tricks users into believing their computer is infected with a virus, then suggests that they download and pay for fake antivirus software to remove it. Usually the virus is fictional and the software is non-functional or malware itself. According to the Anti-Phishing Working Group, the number of scareware packages in circulation rose from 2,850 to 9,287 in the second half of 2008. In the first half of 2009, the APWG identified a 585% increase in scareware programs.

<span class="mw-page-title-main">ESET NOD32</span> Computer protection software

ESET NOD32 Antivirus, commonly known as NOD32, is an antivirus software package made by the Slovak company ESET. ESET NOD32 Antivirus is sold in two editions, Home Edition and Business Edition. The Business Edition packages add ESET Remote Administrator allowing for server deployment and management, mirroring of threat signature database updates and the ability to install on Microsoft Windows Server operating systems.

<span class="mw-page-title-main">ClamWin Free Antivirus</span>

ClamWin Free Antivirus is a free and open-source antivirus tool for Windows. It provides a graphical user interface to the Clam AntiVirus engine.

<span class="mw-page-title-main">WinFixer</span> Rogue security software

WinFixer was a family of scareware rogue security programs developed by Winsoftware which claimed to repair computer system problems on Microsoft Windows computers if a user purchased the full version of the software. The software was mainly installed without the user's consent. McAfee claimed that "the primary function of the free version appears to be to alarm the user into paying for registration, at least partially based on false or erroneous detections." The program prompted the user to purchase a paid copy of the program.

<span class="mw-page-title-main">McAfee VirusScan</span> Antivirus software

McAfee VirusScan is an antivirus software created and maintained by McAfee. Originally marketed as a standalone product, it has been bundled with McAfee LiveSafe, McAfee AntiVirus Plus, McAfee Total Protection and McAfee Gamer Security since 2010. McAfee LiveSafe is antivirus protection that defends against viruses, online threats, and ransomware with online and offline protection integrates antivirus, firewall and anti-spyware/anti-ransomware capabilities.
In 2006, British telecom company BSkyB started offering Sky Broadband customers a branded version of VirusScan for free upon broadband modem installation.

Rogue security software is a form of malicious software and internet fraud that misleads users into believing there is a virus on their computer and aims to convince them to pay for a fake malware removal tool that actually installs malware on their computer. It is a form of scareware that manipulates users through fear, and a form of ransomware. Rogue security software has been a serious security threat in desktop computing since 2008. An early example that gained infamy was SpySheriff and its clones, such as Nava Shield.

<span class="mw-page-title-main">Kaspersky Anti-Virus</span> Antivirus solution

Kaspersky Anti-Virus is a proprietary antivirus program developed by Kaspersky Lab. It is designed to protect users from malware and is primarily designed for computers running Microsoft Windows and macOS, although a version for Linux is available for business consumers.

<span class="mw-page-title-main">PC Tools (company)</span> Australian software company

PC Tools, formerly known as WinGuides.com, was a software company acquired by Symantec in 2008; the new owner eventually discontinued the PC Tools name. Company headquarters were in Australia, with offices in Luxembourg, the United States, United Kingdom, Ireland and Ukraine. The company had previously developed and distributed security and optimization software for the Mac OS X and Microsoft Windows platforms.

<span class="mw-page-title-main">VirusTotal</span> Cybersecurity website owned by Chronicle

VirusTotal is a website created by the Spanish security company Hispasec Sistemas. Launched in June 2004, it was acquired by Google in September 2012. The company's ownership switched in January 2018 to Chronicle, a subsidiary of Google.

<span class="mw-page-title-main">Computer virus</span> Computer program that modifies other programs to replicate itself and spread

A computer virus is a type of malware that, when executed, replicates itself by modifying other computer programs and inserting its own code into those programs. If this replication succeeds, the affected areas are then said to be "infected" with a computer virus, a metaphor derived from biological viruses.

<span class="mw-page-title-main">Malwarebytes</span> Internet security company

Malwarebytes Inc. is an American Internet security company that specializes in protecting home computers, smartphones, and companies from malware and other threats. It has offices in Santa Clara, California; Clearwater, Florida; Tallinn, Estonia; Bastia Umbra, Italy; and Cork, Ireland.

Avira Operations GmbH & Co. KG is a German multinational computer security software company mainly known for its Avira Free Security antivirus software. Although founded in 2006, the Avira antivirus application has been under active development since 1986 through its predecessor company H+BEDV Datentechnik GmbH. Since 2021, Avira has been owned by American software company NortonLifeLock, which also operates Norton, Avast and AVG. It was previously owned by investment firm Investcorp.

OSX.FlashBack, also known as the Flashback Trojan, Fakeflash, or Trojan BackDoor.Flashback, is a Trojan horse affecting personal computer systems running Mac OS X. The first variant of Flashback was discovered by antivirus company Intego in September 2011.

Linux.Encoder is considered to be the first ransomware Trojan targeting computers running Linux. There are additional variants of this Trojan that target other Unix and Unix-like systems. Discovered on November 5, 2015, by Dr. Web, this malware affected at least tens of Linux users.

macOS malware includes viruses, trojan horses, worms and other types of malware that affect macOS, Apple's current operating system for Macintosh computers. macOS is said to rarely suffer malware or virus attacks, and has been considered less vulnerable than Windows. There is a frequent release of system software updates to resolve vulnerabilities. Utilities are also available to find and remove malware.

References

  1. "Dr. Web LTD Doctor Web / Dr. Web Reviews, Best AntiVirus Software Reviews, Review Centre". Reviewcentre.com. Retrieved 2014-02-17.
  2. Web, Doctor (2013-10-07). "Dr. Web LinkChecker :: Add-ons for Firefox". Addons.mozilla.org. Retrieved 2014-02-17.
  3. "Doctor Web: statement on Virus Bulletin comparative reviews". news.drweb.com. Retrieved 2015-11-03.
  4. "Drweb and false positive". Malwarebytes Forums. 20 December 2014.
  5. "PDFsam Basic issue report". PDFsam Basic issue tracker.
  6. Greenberg, Andy (April 9, 2012). "Apple Snubs Firm That Discovered Mac Botnet, Tries To Cut Off Its Server Monitoring Infections". Forbes. Retrieved April 10, 2012.
  7. "Trojan.Skimer.18 infects ATMs". news.drweb.com. Retrieved 2015-11-27.
  8. Dr.Web (November 6, 2015). "Encryption Ransomware Threatens Linux Users". Forbes. Retrieved November 16, 2015.
  9. "Dr.Web - ATM Trojans – Doctor Web and ATM Trojans". antifraud.drweb.com. Retrieved 2015-12-09.
  10. "ATM Skimmer Gang Firebombed Antivirus Firm — Krebs on Security". krebsonsecurity.com. 29 September 2015. Retrieved 2015-12-09.
  11. ""На карте – ваши деньги"! Банкоматные троянцы угрожают вам, а их распространители – поджогами и физической расправой сотрудникам компании "Доктор Веб"". news.drweb.ru. Retrieved 2015-12-09.