View Full Version : The Best AV heuristic analyzer poll
Technodrome
February 13th, 2002, 05:09 AM
Well here is the poll for The Best Antivirus heuristic analyzer. Post your comments or whatever you want...
Technodrome
wizard
February 13th, 2002, 07:31 PM
DrWeb32's heuristic produces some false positives and KAV's heuristic is too cautous for me. So I choose NOD32. :)
wizard
Technodrome
February 13th, 2002, 09:41 PM
Did you try the latest version from DrWeb32 ????
False positives from DrWeb were common in 4.xx-4.19 (if memory serves me right). There has been a great improvement over past DrWebs versions...
Technodrome
wizard
February 14th, 2002, 09:09 AM
Last one I tried was 4.27a. At the moment I am a little bit unhappy with the DrWeb/Dials people. They do not answer my emails. :(
wizard
javacool
February 14th, 2002, 05:52 PM
IMHO, NOD32 tops the pack you have select in heuristics scanning.
Just my two cents...
-javacool
UNICRON
February 15th, 2002, 11:41 PM
NOD32 is king.
DrSeltsam
February 21st, 2002, 03:21 PM
Nothing of this above ... .
trojans: F-Prot
macro: F/WIN32
dos: RHBVS
scripts (VBS, CS, ...): RHBVS / f_mirc
windows: PEHead (i don't know if ralph integrated it in RHBVS so far)
Nod32 causes some false postives with dos files and misses many script viruses.
By the way, f_mirc and rhbvs did a complete analysis of the found malware, too :o).
Adieu, Andreas
wizard
February 21st, 2002, 04:04 PM
The heuristic of f-prot for trojans is nice indeed but has a big problem. When the trojan is packed or crypted there is no chance for the heuristic. For (backdoor-)trojans TDS-3 might be the better choice because heuristic rules also apply to process memory scanning.
F/Win32 is outdated. The product is not developed any longer. Last version is from April 2000. It was a good product. For macro viruses heuristic I would vote for NOD32 at the moment.
For script malware Wormguard is my favourite choice.
wizard
DrSeltsam
February 21st, 2002, 04:08 PM
>F/Win32 is outdated. The product is not developed any
>longer. Last version is from April 2000. It was a good
>product. For macro viruses heuristic I would vote for
>NOD32 at the moment.
*lach* - there weren't any big changes in the macro virus developement since 2000 ;o). You may try it. The F/WIN32 heuristic is still the best.
>For script malware Wormguard is my favourite choice.
Do you ever compared f_mirc/RHBVS with wormguard?
Adieu, Andreas
Blacksheep
February 22nd, 2002, 12:38 AM
So, is DrWeb Russian code?
DrSeltsam
February 22nd, 2002, 12:54 AM
Yes - Headquarter is in St. Petersburg as far as i know.
Adieu, Andreas
Blacksheep
February 23rd, 2002, 12:33 AM
{QUOTE-> Yes - Headquarter is in St. Petersburg as far as i know.
Adieu, Andreas <-QUOTE}
Hi Andreas,
Thanks for reply. Did some Googleing - here's some company info:
http://www.dials.ru/english/company/home.htm
Regards,
Blacksheep
wizard
February 23rd, 2002, 10:32 AM
The official homepage for DrWeb seems to be:
St.Petersburg antivirus laboratory by Igor Daniloff
(SalD Ltd.)
http://www.sald.com/
wizard
DrSeltsam
February 23rd, 2002, 11:10 AM
as far as i know its sald.com :o).
Adieu, Andreas
Blacksheep
February 23rd, 2002, 01:51 PM
Thanks for sald link - added to bookmarks.
I must try DrWeb soon...
Regards,
Blacksheep
Technodrome
February 25th, 2002, 08:32 PM
Official site for DrWeb is http://www.dials.ru/english/home.htm
http://www.sald.com is distribution site!!!
Technodrome
wizard
February 26th, 2002, 09:25 AM
{QUOTE-> Official site for DrWeb is http://www.dials.ru/english/home.htm
http://www.sald.com is distribution site!!!
Technodrome
<-QUOTE}
Dials is a very suspicious company. They do not answer any of my emails. So they would not gain a new costumer. :(
wizard
Technodrome
February 26th, 2002, 06:41 PM
They need more English-language speaking people!!!! *:'(
You should try German site (in English) http://drweb.imshop.de/index1.asp?sprache=en
Maybe there is still hope for them *;)
vBulletin® Copyright ©2000-2008, Jelsoft Enterprises Ltd.