PDA

View Full Version : Interesting: Myths about Dr.Web Anti-virus


Miyagi
May 16th, 2006, 02:08 AM
Interesting myths about Dr.Web Anti-virus :-\ :

The quantity of unbelievable myths spread on the Internet about Dr.Web Anti-virus is a constant source of surprise for our company.
We have decided to collect the myths we could find about Dr.Web Anti-virus and ask you too to send us myths about our product! - DrWeb.com

http://support.drweb.com/faq/a15/

Stefan Kurtzhals
May 16th, 2006, 03:24 AM
It seems not a myth that Dr.Web can't tell the difference between a behaviour blocker and heuristic detection by scanning. ::)

Oh and they spread myths aswell:

"In addition, there are certain algorithms in Dr.Web’s heuristic analyzer which help to detect new macro viruses – no other anti-virus has such functionality."

Basically, every other antivirus product on this planet has macro heuristics for years. ::)

RejZoR
May 16th, 2006, 03:34 AM
This is not a myth list but a reversed FAQ and nothing else. ::)

I could make a 30 page list of myths about avast! if i'd want.
It's not about myths at all, but about statements of unknowledgeable people.
I can see same number of such "myths" for any antivirus on the market, so this one from DrWeb doesn't really "surprise" me if we can even talk about surprises...

sergeyko
May 16th, 2006, 03:39 AM
{QUOTE-> It seems not a myth that Dr.Web can't tell the difference between a behaviour blocker and heuristic detection by scanning. ::)
<-QUOTE}

Does it really seem so? There is an option of using heuristic in Dr.Web, but what is a behaviour blocking you are talking about?

sergeyko
May 16th, 2006, 03:40 AM
{QUOTE->
It's not about myths at all, but about statements of unknowledgeable people.
<-QUOTE}

I thought a myth is a statement of unknowledgeable people...

Miyagi
May 16th, 2006, 04:23 AM
I think the myths mentioned by Dr.Web are those that have been questioned to them many times. They are explaining, informing, and clarifying to the audience from their belief. I, highly doubt, that they are mentioning the myths to falsely accuse or dis-credit other av-vendors ;)

As far as the technical information, I'll leave this to the experts and developers. :)

Zveroboy
May 16th, 2006, 04:31 AM
{QUOTE-> ...
Basically, every other antivirus product on this planet has macro heuristics for years. ::) <-QUOTE}
...and what about Avast! ?

RejZoR
May 16th, 2006, 04:37 AM
Macro generics :P

TAP
May 16th, 2006, 04:50 AM
As far as I've seen, avast! also has generic detections/signatures for many type of malware as the following

Win32:Trojan-gen. {UPX!}
Win32:Trojan-gen. {VC}
Win32:Trojan-gen. {Delphi}
Win32:Trojan-gen. {Other}
VBS:Malware [Gen]
VBS:Generic-Direct
VBS:Malware [Encrypted]
VBS:Malware [Script]
Win32:Adware-gen. {Adw}
Win32:Spyware-gen. {Trj}
Win32: Dialer-gen. {Trj}

and for some malware families such as

Win32:Swizzor-gen [Trj]
Win32:Spybot-gen [Trj]

I've seen avast! uses its generic detection method to detect many .html files that infected by VBS:Redlof virus as VBS:Malware [Script].

Zveroboy
May 16th, 2006, 05:00 AM
{QUOTE-> Macro generics :P <-QUOTE}
Realy?
In avast! 4 Professional Edition heuristic only mentioned in e-mail modules - not in macro.

RejZoR
May 16th, 2006, 05:08 AM
You don't exactly need heuristics to detect new stuff. Especially not for macros that can be more predictable than lets say new malware written from scratch in EXE form with it's own crypto and packer algorithm. At least to some degree.
You'll have to ask Alwil team for more details, coz i don't know their in detail engine specs.

Zveroboy
May 16th, 2006, 05:12 AM
{QUOTE-> As far as I've seen, avast! also has generic detections/signatures for many type of malware . <-QUOTE}
Dr.Web can detects unknown vatiants of malware not only in macro, but also in mail worm, network worms.

TAP
May 16th, 2006, 05:13 AM
There're some Macro virus generator available, so this whole macro virus family can be likely detected by generic detections.

Zveroboy
May 16th, 2006, 05:45 AM
{QUOTE-> Interesting myths about Dr.Web Anti-virus :-\ :

The quantity of unbelievable myths spread on the Internet about Dr.Web Anti-virus is a constant source of surprise for our company.
We have decided to collect the myths we could find about Dr.Web Anti-virus and ask you too to send us myths about our product! - DrWeb.com

http://support.drweb.com/faq/a15/ <-QUOTE}
Very intristing ;D