PDA

View Full Version : The Best AV heuristic analyzer poll


Technodrome
February 13th, 2002, 05:09 AM
Well here is the poll for The Best Antivirus heuristic analyzer. Post your comments or whatever you want...

Technodrome

wizard
February 13th, 2002, 07:31 PM
DrWeb32's heuristic produces some false positives and KAV's heuristic is too cautous for me. So I choose NOD32. :)

wizard

Technodrome
February 13th, 2002, 09:41 PM
Did you try the latest version from DrWeb32 ????

False positives from DrWeb were common in 4.xx-4.19 (if memory serves me right). There has been a great improvement over past DrWebs versions...

Technodrome

wizard
February 14th, 2002, 09:09 AM
Last one I tried was 4.27a. At the moment I am a little bit unhappy with the DrWeb/Dials people. They do not answer my emails. :(

wizard

javacool
February 14th, 2002, 05:52 PM
IMHO, NOD32 tops the pack you have select in heuristics scanning.

Just my two cents...

-javacool

UNICRON
February 15th, 2002, 11:41 PM
NOD32 is king.

DrSeltsam
February 21st, 2002, 03:21 PM
Nothing of this above ... .

trojans: F-Prot
macro: F/WIN32
dos: RHBVS
scripts (VBS, CS, ...): RHBVS / f_mirc
windows: PEHead (i don't know if ralph integrated it in RHBVS so far)

Nod32 causes some false postives with dos files and misses many script viruses.

By the way, f_mirc and rhbvs did a complete analysis of the found malware, too :o).

Adieu, Andreas

wizard
February 21st, 2002, 04:04 PM
The heuristic of f-prot for trojans is nice indeed but has a big problem. When the trojan is packed or crypted there is no chance for the heuristic. For (backdoor-)trojans TDS-3 might be the better choice because heuristic rules also apply to process memory scanning.

F/Win32 is outdated. The product is not developed any longer. Last version is from April 2000. It was a good product. For macro viruses heuristic I would vote for NOD32 at the moment.

For script malware Wormguard is my favourite choice.

wizard

DrSeltsam
February 21st, 2002, 04:08 PM
>F/Win32 is outdated. The product is not developed any
>longer. Last version is from April 2000. It was a good
>product. For macro viruses heuristic I would vote for
>NOD32 at the moment.

*lach* - there weren't any big changes in the macro virus developement since 2000 ;o). You may try it. The F/WIN32 heuristic is still the best.

>For script malware Wormguard is my favourite choice.

Do you ever compared f_mirc/RHBVS with wormguard?

Adieu, Andreas

Blacksheep
February 22nd, 2002, 12:38 AM
So, is DrWeb Russian code?

DrSeltsam
February 22nd, 2002, 12:54 AM
Yes - Headquarter is in St. Petersburg as far as i know.

Adieu, Andreas

Blacksheep
February 23rd, 2002, 12:33 AM
{QUOTE-> Yes - Headquarter is in St. Petersburg as far as i know.

Adieu, Andreas <-QUOTE}
Hi Andreas,

Thanks for reply. Did some Googleing - here's some company info:

http://www.dials.ru/english/company/home.htm

Regards,
Blacksheep

wizard
February 23rd, 2002, 10:32 AM
The official homepage for DrWeb seems to be:

St.Petersburg antivirus laboratory by Igor Daniloff
(SalD Ltd.)

http://www.sald.com/

wizard

DrSeltsam
February 23rd, 2002, 11:10 AM
as far as i know its sald.com :o).

Adieu, Andreas

Blacksheep
February 23rd, 2002, 01:51 PM
Thanks for sald link - added to bookmarks.

I must try DrWeb soon...

Regards,
Blacksheep

Technodrome
February 25th, 2002, 08:32 PM
Official site for DrWeb is http://www.dials.ru/english/home.htm

http://www.sald.com is distribution site!!!

Technodrome

wizard
February 26th, 2002, 09:25 AM
{QUOTE-> Official site for DrWeb is http://www.dials.ru/english/home.htm

http://www.sald.com is distribution site!!!

Technodrome
<-QUOTE}

Dials is a very suspicious company. They do not answer any of my emails. So they would not gain a new costumer. :(

wizard

Technodrome
February 26th, 2002, 06:41 PM
They need more English-language speaking people!!!! *:'(

You should try German site (in English) http://drweb.imshop.de/index1.asp?sprache=en

Maybe there is still hope for them *;)