Dr.Web is an excellent antivirus

Abstract on the topic:

Dr.Web



Plan:

    Introduction
  • 1 Characteristics
  • 2 Functions
    • 2.1 Basic protection
    • 2.2 Threat Prevention
    • 2.3 System and data recovery
    • 2.4 Ease of use
  • 3 History of creation
  • 4 Awards
  • 5 Doctor Web Company
    • 5.1 CureIT!
    • 5.2 CureNet!
    • 5.3 Antivirus is a service (AV-Desk)
    • 5.4 Dr.Web Mobile Security Suite
  • Notes

Introduction

Dr. Web is a family of antiviruses designed to protect against email and network worms, rootkits, file viruses, Trojans, stealth viruses, polymorphic viruses, disembodied viruses, macro viruses, viruses that attack MS Office documents, script viruses, spyware, password stealers, keyloggers, paid dialing programs, adware, potentially dangerous software, hacker utilities, trapdoor programs, joke programs, malicious scripts and other malicious objects, as well as spam, scamming, pharming, phishing messages and technical spam.


1. Features

  • A characteristic feature of the Dr. antivirus. Web is the ability to install on an infected machine. During the installation process, the memory and startup files are scanned, and the virus database is updated before scanning. At the same time, virus database updates are released at intervals of several hours or less.
  • Origins Tracing is an algorithm for non-signature detection of malicious objects, which complements traditional signature search and heuristic analyzer, making it possible to significantly increase the level of detection of previously unknown malware.
  • Dr. Web Shield - a mechanism for combating rootkits, implemented as a component driver antivirus scanner, provides access to virus objects hiding in the depths of the operating system.
  • Fly-code is a new generation emulator with dynamic code translation that implements a mechanism for universal unpacking of viruses protected from analysis and detection by one or a chain of new and/or unknown packers, cryptors and droppers. This allows you to unpack files protected, for example, by ASPROTECT, EXECRYPTOR, VMPROTECT and thousands of other packers and protectors, including those unknown to the antivirus.
  • majority support existing formats packed files and archives, including multi-volume and self-extracting archives. On this moment There is support for about 4000 types of various archives and packers.
  • Virus databases are updated immediately as new viruses are identified, up to several times per hour. The developers of the anti-virus product refused to release virus database updates on any schedule, since virus epidemics do not follow such schedules.
  • compact virus database and small update size. One entry in the virus database allows you to identify dozens, in some cases thousands, of similar viruses.
  • cross-platform - a single virus database and a single anti-virus scanner core are used.
  • opportunity full-fledged work scanner without installation, which allows you to use the antivirus to treat infected systems using media in read-only mode.
  • detection and treatment of complex polymorphic, encrypted viruses and rootkits

2. Functions

2.1. Basic protection

  • Protection against viruses, Trojans and worms
  • Protection against spyware and adware
  • Checking files in automatic mode and upon request
  • Examination mail messages(POP3/SMTP/IMAP interception)
  • Checking Internet traffic (intercepting connections)
  • Heuristic protection against new and unknown malware

2.2. Threat Prevention

  • Blocking links to infected sites
  • Recognition of viruses packaged with a new and/or unknown packer, dropper and/or cryptor

2.3. System and data recovery

  • Possibility of installing a program on an infected computer
  • Program self-protection function from shutdown or stop

2.4. Ease of use

  • Automatic program configuration during installation
  • Visual display of program results
  • Informative dialog boxes for the user to make informed decisions
  • Possibility to choose between simple auto-treatment/removal and interactive operating modes
  • 24/7 technical support
  • Automatic database updates

3. History of creation

The history of the development of Igor Danilov's antivirus begins in 1991, and under the Dr. Web antiviruses developed and distributed since 1994.

  • 1992 - creation of the first version of the Spider’s Web antivirus program (Dr. Web prototype). It was the first to implement the idea of ​​executing program code in a processor emulator to search for unknown viruses.
  • 1993 - participation of the Spider’s Web program on international exhibition CeBIT.
  • 1994 - start of antivirus sales Doctor Web. Author - Igor Danilov. Mutant viruses appeared, later called polymorphic viruses, which the Aidstest program could not detect.
  • 1995 - demonstration of the DSAV 2.0 Anti-Virus Kit. Includes Antivirus Doctor Web.
  • 1996 - debut of the Dr. program. Web (version 3.06b) on comparative testing of polyphages, conducted by the Virus Bulletin magazine, is more than impressive - both in terms of the level of knowledge of polymorphic viruses and in the quality of the heuristic analyzer. In an article in the Virus Bulletin magazine about the Doctor Web program (version 3.08), the heuristic antivirus analyzer was especially noted, which in “paranoid” mode identified 100% of polymorphic viruses. Alpha version of Dr. presented. Web for Novell NetWare.
  • 1997 - for the first time Russian antivirus program(Dr. Web) entered the top three best antiviruses world according to testing results from Virus Bulletin magazine. Beta version of Dr. is released. Web for Novell NetWare.
  • 1998 - release of Dr. Web 4.0. The architecture and algorithm of the program have been changed. Public testing of Dr. Web for Windows 95/98/NT.
  • 1999 - appearance of the resident module SpIDer Guard for Windows 95/98. Dr. Web for Windows 95/98/NT wins first VB100 award in Virus Bulletin's tests. Release of the commercial version of Dr. Web for Windows 95/98/NT. In Dr. Web memory check implemented for the first time virtual machines V Windows environment N.T.
  • 2000 - Dr. Web received a certificate of conformity from the Russian Ministry of Defense. The frequency of virus database updates has been sharply increased - up to several times per hour.
  • 2001 - an agreement was concluded with Yandex. From now on, all letters passing through postal system Yandex, checked using Dr. solutions. Web.
  • 2002 - creation of Dr. anti-virus filters. Web for mail servers CommuniGate Pro. Release of the first beta version of Dr. Web for Unix with a unique feature at that time - on-the-fly file disinfection. Release of the SpIDer Mail program - a unique program for checking incoming mail at that time.
  • 2007 - creation of the Origins.Tracing technology for non-signature detection of malware.
  • 2007 - public testing of the Dr.Web AV-Desk service was opened, on the basis of which Internet providers provide their subscribers with the “Dr. Antivirus” service. Web" (the first SaaS model in the Russian Internet business sector).
  • 2008 - the appearance of the Dr. antivirus package. Web Security Space. First implemented new component to check HTTP traffic - Dr. Web SpIDer Gate.
  • 2009 - Beginning of beta testing of the antivirus product Dr. Web Security Space Pro. Different from Dr. Web Security Space with a firewall.
  • 2010 - release of the first antivirus in Russia for Android OS - Dr.Web for Android.

4. Awards

  • Based on the results of the treatment test active infection(October 2008), conducted by the site anti-malware.ru, Dr. Web was the only one of all participants who scored the maximum possible number of points (15) and received the Platinum Malware Treatment Award.
  • According to the results of a self-defense test of antivirus products (January 2009), conducted by the website anti-malware.ru, Dr. Web was the only one of all participants who scored the maximum possible number of points (38) and received the Platinum Self-Protection Award.
  • According to the results of a proactive defense test (March 2009) conducted by the website anti-malware.ru, Dr. Web came in second place and received the Silver Proactive Protection Award.
  • Platinum Self-Protection Award (September 2010) from Anti-Malware.ru.

5. Doctor Web Company

Doctor Web Company - Russian company, which is a manufacturer and supplier of antivirus products under the Dr. brand. Web. The company offers antivirus solutions to a wide range of clients using various operating systems.

The main products developed and supplied by Doctor Web:

  • to protect workstations and file servers under Windows control;
  • for guard corporate network and national networks with centralized management antivirus protection;
  • AV-desk service for ISP;
  • to protect mail and file servers under UNIX systems;
  • to protect Internet gateways under UNIX systems;
  • to protect file servers running Novell NetWare;
  • to protect Lotus Domino servers on Microsoft platform Windows;
  • to protect Microsoft Exchange servers;
  • to protect PDAs running Windows Mobile;
  • to protect Mac OS X workstations.

5.1. CureIT!

The company also produces free version CureIT scanner! , which does not require installation. To update antivirus database must be downloaded from the site current version programs (not possible automatic update). The number of times this program can be launched is not limited. At startup, the user is prompted to check running processes and libraries, upon completion of the check, you can check any path specified by the user, while the heuristic analysis option is activated in the check processes.

Since the fall of 2009, the licensing conditions for the scanner have been changed - now only home users can use it for free; use for organizations and commercial purposes has become paid. In commercial CureIT versions There is a database update utility.


5.2. CureNet!

Dr.Web CureNet! - network utility with centralized management for remote scanning and treatment of infected Windows workstations and servers, even those completely isolated from the Internet.

Dr.Web CureNet! allows you to use 2 antiviruses simultaneously on workstations and file servers Windows: Dr.Web and antivirus from another manufacturer.

This does not require either a server or installation of the Dr.Web anti-virus - the distribution of healing scanners can be carried out from any PC. Dr.Web scanners are not installed, but are launched for execution and, after a scanning session, immediately remove themselves from the computer.

Dr.Web CureNet! is not a web service, therefore, the distribution of healing scanners to the stations being checked is not carried out via the Internet, so the check can be carried out even in networks completely isolated from the Internet.


5.3. Antivirus is a service (AV-Desk)

Dr. Web AV-Desk is the first Internet service of Doctor Web, which allows providers to provide their subscribers with services for information protection of PCs from viruses and spam using Dr. Web for Windows.

Dr. Web AV-Desk is a SAAS business model with which a provider can attract new customers and increase revenue.

Dr. Web AV-Desk is software, which allows you to centrally manage the process of providing the Dr. Antivirus service. Web".

5.4. Dr.Web Mobile Security Suite

This is software designed for comprehensive protection mobile devices. Dr.Web Mobile Security Suite combines protection tools for mobile devices running Windows Mobile, Symbian OS and Android. The company's developers have implemented technology for filtering incoming phone calls and SMS messages based on black and white lists. Even before beta testing began, the program was downloaded by more than 350,000 users. [ source not specified 177 days]


Notes

  1. Dr.Web® - innovative technologies information security. Comprehensive protection from Internet threats - news.drweb.com/show/?i=643&c=5&p=0
  2. Results of an antivirus test for treating active infections (October 2008) - Tests and comparisons of antiviruses - Anti-Malware.ru - anti-malware.ru/malware_treatment_test_2008
  3. Antivirus self-protection test results (January 2009) - Tests and comparisons of antiviruses - Anti-Malware.ru - www.anti-malware.ru/self_protection_2009
  4. Proactive test results antivirus protection(March 2009) - Tests and comparisons of antiviruses - Anti-Malware.ru - antimalware.ru/proactive_test_2009
  5. Self-protection test of antiviruses, comparison of antiviruses (September 2010) - Tests and comparisons of antiviruses - Anti-Malware.ru - www.anti-malware.ru/antivirus_self_protection_test_2010
  6. Dr.Web® AV-Desk - wiki.drweb.com - wiki.drweb.com/index.php/Dr.Web®_AV-Desk
  7. Dr.Web CureIt! - download antivirus for free! Virus treatment, Best free antivirus! - www.freedrweb.com/cureit/
  8. Dr.Web CureNet! - drweb-shop.ru/drweb_cure_net

This abstract is based on

1990–1991

  • First experiments in treating viruses (using Aidstest and other antiviruses, as well as debuggers).
  • Igor Danilov creates his first antivirus - the resident guard Tadpole.

1991

  • Tadpole has been completely rewritten, making it more flexible and versatile.
  • created by Igor Danilov antivirus doctor(scanner) Tornado. Thanks to working with file system hard drive at a low level (BIOS), Tornado coped with the new Ghost-1963 virus and was distinguished by high speed.

1992

  • Released antivirus system Spider's Web, which connected the guard Spider (successor to Tadpole) and Doctor Web(successor to Tornado). It is from this moment that the history of Dr.Web development begins.
  • Participation in the pan-European competition "1&1", which that year was held for countries of Eastern Europe in order to find interesting software products and technology. Igor Danilov’s Spider’s Web anti-virus system won a grant for a free stand at the international computer exhibition CeBIT’93.

1993

  • Participation of Dr.Web in CeBIT’93 (Germany, Hannover).
  • An inspector (auditor) of the Scorpion disk has been created. Like Tornado, Scorpion worked with file hard system disk at the BIOS level, which made it possible to detect the appearance of stealth viruses.
  • The first polymorphic virus has been discovered. The fact of its appearance became a watershed between real antiviruses, capable of not only detecting, but also treating systems from “polymorphics,” and other antivirus-like programs. Dr.Web became the first program in the history of the anti-virus industry that could recognize and cure computers from the most complex polymorphic viruses. It was this technological property of the Dr.Web anti-virus that brought it its first international fame among professionals.
  • Participation in the All-Russian school-seminar (Abrau-Durso) and Igor Danilov’s acquaintance with Dmitry Lozinsky and other virologists.

1994

  • Implemented a heuristic analyzer to detect previously unknown viruses.
  • Implemented a processor emulator for promoting and detecting polymorphic viruses, thanks to which the Dr.Web antivirus turned out to be one of the few in the world that successfully fought the polymorphic virus Phantom-1, which became widespread worldwide.
  • Version 1.00 of the Doctor Web antivirus scanner has been released.
  • Started commercial distribution Dr.Web antivirus.

1995

  • Dr.Web anti-virus was presented at the computer exhibition CeBIT’95 (Hannover, Germany).
  • Delivery of add-on files to the main Dr.Web virus database has been implemented without changing the code of the program itself.
  • Dr.Web anti-virus for WinWord has been released.
  • Dr.Web was one of the first to create an antivirus for Novell NetWare.
  • Igor Danilov made a presentation for the first time in Zurich at the EICAR’95 conference (European Institute for Computer Anti-Virus Research). These conferences bring together computer virologists from all over the world.

1996

  • The January issue of Virus Bulletin magazine published the results of comparative testing of antivirus scanners, in which Dr.Web antivirus took part for the first time.
  • The Virus Bulletin magazine published for the first time a large analytical article dedicated to the Dr.Web antivirus. The Dr.Web heuristic analyzer received the highest marks.
  • An online virus checking service using Dr.Web has been implemented.

1998

  • Version 4.0 of the Dr.Web antivirus was released, which included innovations that fundamentally changed the architecture and algorithms of the antivirus.

1999

  • First developed complex system virus prevention for Windows 95/98.
  • The Dr.Web family has been expanded with the resident guard SpIDer Guard for Windows 95/98.
  • For the first time in the world, the Dr.Web anti-virus program implements memory checking of virtual machines in the Windows NT environment.

year 2000

  • Dr.Web anti-virus received a certificate of conformity from the Ministry of Defense Russian Federation.
  • The frequency of release of Dr.Web virus database additions has been increased many times over. They are now updated daily and hourly.

2002

2003

  • Igor Danilov founded the Doctor Web company - from that moment on he has been its permanent leader Technical Director.

2004

  • A product has been released to protect corporate computer networks Dr.Web Enterprise Suite.
  • The Dr.Web anti-virus engine is licensed by the South Korean developer antivirus Virus Chaser.

2005 year

  • A free healing utility, Dr.Web CureIt!, was released, which soon became the most popular and authoritative means of emergency computer virus treatment for users of other antiviruses.
  • A representative office in Ukraine “Center” was opened technical support"Doctor Web"".

2006

  • A representative office in Kazakhstan “Doctor Web - Central Asia” has been opened.
  • Doctor Web Deutschland GmbH has opened a representative office in Germany.

2007

  • The first version of Dr.Web AV-Desk has been released. From this moment the SaaS era begins in the history of the Russian antivirus industry. Now service providers have begun to supply Dr.Web antivirus to home users via progressive model monthly subscription. Public testing of the Dr.Web AV-Desk service took place on the servers of the provider Corbina Telecom (now Beeline). Doctor Web became the first company to offer Russian market an innovative model for using antivirus as a service for service providers, and is still the undisputed leader in this segment of the antivirus market.
  • The first Dr.Web anti-virus for mobile devices has been released.

Due to the fact that the number of threats to mobile platforms was small at that time, the company makes an unprecedented decision to distribute this product exclusively free of charge. Doctor Web declares the principle: “Protection against non-existent threats should be free! " Doctor Web adhered to this policy of distributing Dr.Web antiviruses for all antiviruses for mobile devices produced by the company until 2012, when the number of threats to mobile operating systems began to grow exponentially.

2008

  • Doctor Web France has opened a representative office in France.
  • Doctor Web announces that it is ceasing to participate in comparative testing by the British magazine Virus Bulletin, since it “has little to do with assessing the capabilities that are truly in demand in the face of modern virus threats.”
  • The Dr.Web Office Shield software and hardware complex has been released. It, like many Doctor Web developments, was many years ahead of its time. Four years after its release in 2012, Dr.Web Office Shield was recognized as one of the most innovative software systems for SMB according to PC Magazine (Russia).
  • Dr.Web AV-Desk is recognized as one of best products 2007 in the “Security” section according to PC Magazine (Russia).

year 2009

  • Doctor Web has released the first domestic antivirus for OS X. Realizing that there are negligible numbers of viruses for OS X only due to the fact that the number of users of this operating system has not yet reached the critical mass when writing viruses for it becomes a profitable business for criminal structures, Doctor Web has invested in the development of this product and is rightfully proud of its quality. Only in April 2012, after the Doctor Web company discovered a botnet of many thousands of Mac computers, the developer of this rapidly growing platform released a utility that removes the Backdoor.Flashback.39 Trojan, thereby recognizing the existence of viruses for OS X.

2010

  • A version of Dr.Web AV-Desk has been released, which allows you to provide the Dr.Web Anti-virus service for business users.
  • Firewall own development included in Dr.Web products for home users.
  • Doctor Web Pacific has opened a representative office in Japan.
  • Doctor Web was the first anti-virus vendor to offer universal licenses to protect both computers and laptops, as well as mobile devices on Android based,BlackBerry.
  • A Doctor Web technical division was opened in Akademgorodok, Novosibirsk.

2011

  • Dr.Web Enterprise Security Suite products are certified for supply to Gazprom.
  • Doctor Web Software Company (Tianjin), Ltd. opened a representative office in China.

year 2012

  • Doctor Web celebrates the 20th anniversary of the development of Dr.Web anti-virus technologies.
  • Certified FSTEC of Russia Dr.Web and ALT Linux products are fully compatible.
  • Dr.Web products version 8.0 have been released.

year 2013

  • Dr.Web products version 9.0 have been released.
  • The first took place banking implementation Internet service Dr.Web AV-Desk.
  • Dr.Web for Android and Dr.Web for Mac OS X are certified by the Russian FSB.
  • Doctor Web is launching an educational project to combat banking Trojans.

year 2014

  • A proprietary firewall is included in Dr.Web for Android.
  • Doctor Web specialists have discovered the first bootkit for Android; it infected more than 350,000 mobile devices.
  • Dr.Web products version 10.0 have been released.
  • After adding to virus databases Trojan for ATMs Trojan.Skimer.18 and publishing information about it, the company was subject to attacks on offices and threats of physical violence.

2015

  • The first ransomware for Linux was discovered and neutralized.
  • The Dr.Web Anti-virus service comes to Spain, South Asia, Belarus, and Lithuania.
  • Released New Product Dr.Web for BlackBerry.
  • A new product, Dr.Web KATANA, has been released.
  • Dr.Web products version 11.0 have been released.
  • Dr.Web for Android has become the most popular mobile antivirus in Russia.
  • The Doctor Web company received a perpetual license from the FSB of Russia for the development and production of means for protecting confidential information.

2016

  • Doctor Web specialists have discovered the first ransomware “in Russian” in the built-in 1C language.
  • Dr.Web products are included in the Unified Register of Domestic Software.
  • Dr.Web KATANA Business Edition has been released.
  • Dr.Web Enterprise Security Suite version 10.0 is certified by FSTEC of Russia.
  • 100 million downloads of Dr.Web for Android from Google Play.
  • Doctor Web specialists have discovered the first ransomware in the Go language.

Main characteristics and advantages of the Dr.Web anti-virus program. Differences from others popular antiviruses. Requirements for installing Dr.Web.

Many Internet users have already appreciated the benefits of the domestic anti-virus program Dr.Web. One of them is the abundance of settings and functions, which allows each computer owner to set the optimal level of protection for themselves. The program implements new technology work in real time, which constantly checks all calls to external and internal devices.

Dr.Web is capable of not only detecting most of the malware known today, but also can restore files that have already been damaged. After all, it is not always enough for a user to simply delete infected files. It was the ability to recover that was one of the key features when creating this antivirus program.

Another undoubted advantage of Dr.Web. is that you can install it even on a computer already infected with a virus. This application is considered one of the most resistant to malicious software due to the use of unique technologies. In most cases, the antivirus can be launched on an infected computer even from removable media.

One of the elements of Dr.Web is a component called SelfPROTECT, which provides the program with a high degree of self-defense, thanks to which even the most dangerous viruses. Since this module is system driver, the likelihood that the antivirus will unload and stop is reduced to a minimum. Thanks to this module, the risk of viruses entering files and the network being used, as well as their intrusion into the registry, is eliminated.

Many modern antiviruses use regular means Windows. The Dr.Web program comes with its own driver, which operates independently. Behind a short time this antivirus is able to scan your computer and check it for viruses. The requirements for its operation and installation are minimal, so Dr.Web can be used even on low-performance machines.

Incoming mail is scanned by the antivirus even before malicious code, if present, goes to your inbox. Thanks to this, the user is protected not only from fraudulent messages and spam, but also from Trojans, which are often sent by mail.

In order to provide this antivirus with the ability normal functioning, you must have:

Internet access to update databases;

40 MB hard disk space;

Installed on a computer 32 or 64-bit Windows Vista/7/XP/2000.

On the official antivirus website, the user can download trial version product after passing simple procedure registration.

Antivirus companies usually name their products after their founders or simply repeat the company name. CHIP will tell you how the Dr.Web product appeared, who was at its origins, and how the global brand was formed.

The founder and owner of the Doctor Web company is the famous Russian programmer Igor Danilov. Back in 1990, he began developing anti-virus protection, and his first protective product became a resident watchman called Tadpole.

As Igor Danilov himself recalls, at that time the choice of his current profession was greatly influenced by the book “Computer Virology” by Nikolai Bezrukov, published in 1991. It was after reading it that the young programmer realized that it was urgently necessary to develop an antivirus.

In the same year, the Tornado anti-virus scanner was created, which compared to its competitors was very important advantage - high speed work. This product won a grant for a free stand at the CeBIT’93 exhibition in Hannover in the pan-European competition “1&1”. Already in 1992, an improved version of the antivirus called Spider’s Web was released. It was she who became the prototype modern antivirus Dr.Web. This package included three programs: Spider, Dr.Web and Scorpion disk examiner. It was then that Igor Danilov realized that at a high technological level such a project could not be carried out alone, and therefore one component was chosen as the main element - Dr.Web, for the development of which every effort was made. However, Igor did not forget how important other components are and that sooner or later they will have to be finalized and included in the anti-virus package. Already in the mid-90s, Dr.Web antivirus was a fully established product and protected the vast majority of personal computers on the territory of the former USSR.

Dr.Web brand



Igor Danilov, technical director, founder and owner of the antivirus company Doctor Web

The brand name predetermined the market success of the Dr.Web antivirus and even the direction of its technological development for many years. A clear and clear understanding of the future by the author of Dr.Web World Wide Web as a unified universal communication infrastructure made it possible to very accurately reflect in the name the main purpose of anti-virus products - to treat networks from viruses.

The choice of a spider as the graphic embodiment of the brand is also not accidental. The spider is one of the most important links in the ecological chain of nature. The thread of the web is a real technological miracle, from which the spider, like a professional architect, builds a strong network (web). Nature has endowed the spider with the unique ability to create web fibers and weave webs from them that can withstand enormous loads.

The spider as an image of Dr.Web is the creator of an unbreakable web that entwines users’ PCs with a strong network information security. Like a spider, Dr.Web antiviruses are organically woven into the complex structure of the computer “cosmos”, they are an integral part of its health, one of its most important elements.

“The first prototype of Dr.Web was presented at the CeBIT’93 exhibition. There, after talking with specialists and customers, I realized that everything needs to be done completely differently.”

Development of Dr.Web antiviruses

1990

Igor Danilov’s first experiments in treating viruses using Aidstest. The first antivirus was created - the resident guard Tadpole.

1991

Tadpole has been completely rewritten, making it more flexible and versatile. The antivirus doctor (scanner) Tornado has been created.


1992

The Spider's Web anti-virus system was released, combining the resident guard Spider (successor to Tadpole) and Dr.Web (successor to Tornado). From this moment on, the history of Dr.Web development begins.

1993

An inspector (auditor) of the Scorpion disk has been created. Like Tornado, Scorpion worked with the hard drive file system at the BIOS level, which made it possible to detect the appearance of stealth viruses.

1994

A heuristic analyzer has been implemented to detect previously unknown viruses. Version 1.00 of the Doctor Web antivirus scanner has been released. Commercial distribution of Dr.Web antivirus has begun.

1995

Delivery of add-on files to the main Dr.Web virus database has been implemented without changing the code of the program itself. Dr.Web anti-virus for WinWord has been released. Dr.Web was one of the first to create an antivirus for Novell NetWare.

1996

An online virus checking service using Dr.Web has been implemented.

1998

Version 4.0 of the Dr.Web antivirus was released, which included innovations that fundamentally changed the architecture and operating algorithms of antivirus 4.0.

1999

The first comprehensive virus prevention system for Windows 95/98 has been developed. The Dr.Web family has been expanded with the resident guard SpIDer Guard for Windows 95/98. For the first time in the world, the Dr.Web anti-virus program implements memory checking of virtual machines in the Windows NT environment.


year 2000

Dr.Web anti-virus received a certificate of conformity from the Ministry of Defense of the Russian Federation. The frequency of release of Dr.Web virus database additions has been increased many times over. They are now updated daily and hourly.

2002

The Dr.Web anti-virus engine is licensed by the Chinese anti-virus developer KingSoft.

2003

Igor Danilov founded the Doctor Web company - from that moment on he is its permanent technical director.

2004

A product for protecting corporate computer networks, Dr.Web Enterprise Suite, has been released.

2005 year

The free healing utility Dr.Web CureIt! was released, which immediately became the most popular and authoritative means of emergency computer virus treatment for users of other antiviruses.


2007

The first version of Dr.Web AV-Desk was released, ushering in the era of SaaS projects. Dr.Web anti-virus for Windows Mobile has been released free of charge.

2008

The Dr.Web Office Shield software and hardware complex has been released.

year 2009

Doctor Web has released the first domestic antivirus for Mac OS X.


2010

A version of Dr.Web AV-Desk has been released, which allows you to provide the Dr.Web Anti-virus service for business users. A proprietary firewall is included in Dr.Web products for home users.

2011

Dr.Web Enterprise Security Suite products are certified for supply to Gazprom.

year 2012

Doctor Web celebrated the 20th anniversary of the development of Dr.Web anti-virus technologies.

year 2013

Doctor Web celebrated the tenth anniversary of the company's founding.

State

In active development

License

Shareware

Website

drweb.com

The main products developed and supplied by Doctor Web:

For Windows OS

Dr.Web Security Space

A full-fledged anti-virus suite that includes all the latest technologies for signature and non-signature detection and removal of all types of malware. Includes antivirus, firewall, web antivirus, antispam, parental control, data backup.

Version development history:

Version date of release Status Improvements and changes
7.0 October 11, 2011 Support stopped

(updating virus databases)

  • Implemented single service, which manages the entire antivirus ("DrWeb Control Service"): settings, statistics, self-defense, etc.
  • Implemented new service(Net Filter) traffic checks (http and mail) instead of SpiderGate and SpiderMail, the modules of which are no longer needed.
  • A secure repository has been implemented to update antivirus components and restore damaged components;
  • Appeared new opportunity - remote control and setting up an antivirus within visibility of the network;
  • Introduction of a new Dr.Web Anti-rootkit API subsystem that uses universal threat neutralization algorithms.
8.0 November 14, 2012 Support stopped

(updating virus databases)

Main list (link to official news):
  • Implemented our own installer that counters active threats;
  • The "Preventive Protection" component has been implemented, allowing flexible management of blocking/protection of the system from the penetration of threats;
  • Implemented background scanning and neutralization subsystem active threats("Background Rootkit Scan"), using ArkAPI.
  • A cloud-based centralized system for sending statistics, firewall rules, behavior and other information about the operation of the product to the company's servers - "Dr.Web Cloud" - has been introduced.
9.0/9.1 September 17, 2013 Support stopped

(auto-update version)

Main list (link to official news):
  • Real-time heuristic technology has been implemented to detect threats of the type "Trojan.Inject" and "Trojan.Encoder" - DPH (Dr.Web Process Heuristic);
  • Real-time technology has been implemented to detect threats known to the Dr.Web virus database, but hidden under new packers - DPD (Dr.Web Process Dumper);
  • Implemented protection against file loss through regular Reserve copy data to a secure storage.
10.0 October 28, 2014 Support stopped

(auto-update version)

  • The antivirus control center ("SpIDer Agent") has been completely redesigned, the functions are divided into 2 modes: user mode and administrative mode;
  • A new component "DrWeb DevGuard" has been added, which allows you to configure access to various devices.
11.0 October 20, 2015 Full support Main list (link to official review):
  • A full-fledged centralized event log has been implemented;
  • A system of advice to users has been created (“Dr.Web Tips”);
  • A new technology "Dr.Web ShellGuard" has been introduced, protecting the system from attacks through exploits in the system and third-party software;
  • A new component "Dr.Web HyperVisor" has been added, designed to improve the threat detection and treatment system, as well as strengthen the self-defense of Dr.Web by using the capabilities of modern processors.
  • Implemented protection against BadUSB attacks.

CureIt!

CureNet!

Unique technologies

  • Fly-code- an emulator with dynamic code translation that implements a mechanism for universal unpacking of viruses protected from analysis and detection by one or a chain of new and/or unknown packers, cryptors and droppers. This allows you to unpack files protected, for example, by ASProtect, EXECryptor, VMProtect and thousands of other packers and protectors, including those unknown to the antivirus.
  • Origins Tracing- an algorithm for non-signature detection of malicious objects, which complements traditional signature search and heuristic analyzer, making it possible to significantly increase the level of detection of previously unknown malware. Also used in Dr.Web for Android
  • Anti-rootkit API (ArkAPI)- a subsystem that uses universal threat neutralization algorithms. Through this system, threats are neutralized by all antivirus components. It is also used in the treatment utility Dr.Web CureIt!
  • Dr.Web Shield- a mechanism for combating rootkits, implemented as a driver. Provides low-level access to virus objects hiding in the depths of the operating system.
  • SelfPROtect - a self-defense module that protects antivirus components (files, registry keys, processes, etc.) from modification and removal by malware.
  • Background Rootkit Scan- subsystem for background scanning and neutralization of active threats. This subsystem is located in memory in a resident state and scans the system for active threats and neutralizes them in various areas, for example: startup objects, running processes and modules, system objects, RAM, WMI, MBR / VBR disks, computer system BIOS.
  • Dr.Web Cloud- a cloud service for checking links and files on Doctor Web servers in real time, allowing the antivirus to use the latest information about unsafe resources and files.
  • Dr.Web Process Heuristic (DPH)- real-time technology that protects against new, most current malware, designed to be undetected by traditional signature and heuristic mechanisms, which have not yet been submitted for analysis to the anti-virus laboratory, and therefore are unknown to the Dr.Web virus database at the time of penetration into the system .
  • Dr.Web Process Dumper (DPD)- real-time technology, significantly increases the level of detection of “new threats” - known to the Dr.Web virus database, but hidden under new packers.
  • Dr.Web HyperVisor- a component that starts and operates below the operating system level, which ensures control of all programs, processes and the operation of the OS itself, as well as the impossibility of malicious programs intercepting control of the system protected by Dr.Web.
  • Dr.Web ShellGuard- a technology that closes the way into a computer for exploits - malicious objects trying to exploit vulnerabilities, including those not yet known to anyone except virus writers (so-called “zero-day” vulnerabilities), in order to gain control of the attacked applications or operating system generally.

History of creation

The history of the development of Igor Danilov's antivirus begins in 1991, and antiviruses have been developed and distributed under the Dr.Web brand since 1994.

  • 1992 - creation of the first version of the Spider’s Web antivirus program (Dr.Web prototype). It implemented the idea of ​​executing program code in a processor emulator to search for unknown viruses.
  • 1993 - participation of the Spider’s Web program at the international exhibition CeBIT.
  • 1994 - the start of sales of the Doctor Web antivirus, designed to replace the Aidstest antivirus program, popular at that time in Russia, which could not fight the emerging polymorphic viruses that completely change their code with each infection.
  • 1995 - demonstration of the DSAV 2.0 Anti-Virus Kit. The kit includes Doctor Web antivirus.
  • 1996 - the debut of the Dr.Web program (version 3.06b) at the comparative testing of polyphages conducted by the Virus Bulletin magazine, more than impressive - both in terms of the level of knowledge of polymorphic viruses and in the quality of the heuristic analyzer. In an article in the Virus Bulletin magazine about the Doctor Web program (version 3.08), the heuristic antivirus analyzer was especially noted, which in “paranoid” mode identified 100% of polymorphic viruses. The alpha version of Dr.Web for Novell NetWare has been presented.
  • 1997 - for the first time, the Russian anti-virus program (Dr.Web) entered the top three best anti-viruses in the world according to testing results from Virus Bulletin magazine. A beta version of Dr.Web for Novell NetWare is released.
  • 1998 - release of Dr.Web 4.0. The architecture and algorithm of the program have been changed. Public testing of Dr.Web for Windows 95 // .
  • 1999 - the appearance of the resident module SpIDer Guard for Windows 95/98. Dr.Web for Windows 95/98/NT receives the first VB100 award in Virus Bulletin magazine tests. Release of the commercial version of Dr.Web for Windows 95/98/NT. Dr.Web is the first to implement memory checking of virtual machines in the Windows NT environment.
  • 2000 - Dr.Web received a certificate of conformity from the Ministry of Defense of the Russian Federation. The frequency of virus database updates has been sharply increased - up to several times per hour.
  • 2001 - an agreement was concluded with Yandex. From now on, all letters passing through the Yandex mail system are scanned using Dr.Web solutions.
  • 2002 - creation of Dr.Web anti-virus filters for CommuniGate Pro mail servers. Release of the first beta version of Dr.Web for Unix with a unique feature at that time - on-the-fly file disinfection. Release of the SpIDer Mail program - a unique program for checking incoming mail at that time.
  • 2007 - creation of the Origins.Tracing technology for non-signature detection of malware.
  • 2007 - public testing of the Dr.Web AV-Desk service was opened, on the basis of which Internet providers provide their subscribers with the Dr.Web Anti-virus service (the first SaaS model in the Russian Internet business).
  • 2008 - the appearance of the Dr.Web Security Space anti-virus package. For the first time, a new component for checking HTTP traffic has been implemented - Dr.Web SpIDer Gate.
  • 2009 - start of beta testing of the anti-virus product Dr.Web Security Space Pro. It differs from Dr.Web Security Space by the presence of a firewall.
  • 2010 - release of the first antivirus in Russia for Android OS - Dr.Web for Android.
  • 2013 - release of the new product Dr.Web Security Space 9. New functions of Dr.Web Cloud, preventive protection, behavioral analyzer Dr.Web Process Heuristic, protection of user data from damage, comprehensive analyzer of packaged threats, traffic scanning for all protocols, function " Safe search", protection of communication in popular services instant messages and other functions.
  • 2014 - release of version 10 of the antivirus.
  • In September 2015, in Ukraine, the company's products were subject to a ban on government procurement of goods and services. Some media outlets erroneously reported that “the sanctions provide for the blocking of assets and the suspension of the fulfillment of economic and financial obligations on the part of Ukraine.”
  • 2015 - Dr.Web Security Space 11 was released in November, the main innovations of which were the strengthening of self-defense and preventive protection, in particular, the new Dr.Web ShellGuard technology made it possible to provide protection against exploits using the so-called. zero-day vulnerabilities.
  • 2015 - release of the Dr.Web Katana product (the technology of which is part of Dr.Web Security Space), a protection solution that is combined with already installed antivirus from another manufacturer.

Awards

WARNING!!!

On behalf of the Syndicate, congratulations on the successful disassembly of the NCR ATM skimmer software. The authors' source is attached below.

Good job, but no prospects. The profit from Dr.Web_ATM_shield is pitiful since bankers never give money voluntarily. However, the development of Dr.Web_ATM_shield undermines the activities of the Syndicate with multi-million dollar profits. Hundreds of criminal families around the world could be left without income.

You have a WEEK to remove all mentions of ATM.Skimmer from your web resource. Otherwise, the syndicate will stop cashing operations and send all the criminals after the heads of your programmers. The ending of DrWeb LLC will be tragic.

After the demand was ignored, on March 9, 2014, there were attempts to arson the office of the St. Petersburg Antivirus Laboratory of I. Danilov (SALD), for which the aforementioned “syndicate” took responsibility. March 31, 2014, after two arson attacks on the St. Petersburg office Antivirus Laboratory Danilova, Doctor Web received a second threat:

Dear Dr.Web, the international syndicate of carders warned you about the inadmissibility of your interference in the ATM sphere. Due to the fact that you ignored the demands of the syndicate, sanctions were applied against you. To emphasize the syndicate’s determination - your office is on the street. Blagodatnaya was burned twice.

If within 10 days you do not remove from your products all references to atmskimmer class viruses and all products for ATM, the international syndicate of carders will destroy all your offices around the world. The syndicate will also lobby for a law banning the use of Russian antiviruses in all countries with representative offices of the syndicate , under the pretext of protection from the Russian special services, which are not friendly to the whole world.

Incoming letters on this e-mail are checked, reasonable arguments in the dispute will be taken into account.

After the third attack on the SALD office, law enforcement detained a suspect, who was subsequently released due to insufficient witness testimony. At the same time, three attempts to physically penetrate the Moscow office of Doctor Web were prevented. According to general director company B. A. Sharov, the reason for such activity of cybercriminals is that Doctor Web specialists discovered and added an entry about Trojan.Skimer.18 to the virus databases at a very unfortunate moment for distributors, when the development of this Trojan for ATMs had already been completed, but sales on the black market have not yet begun.

In response to the threats and attacks, the company released an official statement stating that Doctor Web is committed to ensuring maximum protection users from attacks by cybercriminals, accordingly, work aimed at identifying and studying threats to ATMs will continue, as well as further improvement of the Dr.Web ATM Shield product.

Scandal over the confiscation of an unofficial fan group

In the summer of 2015, the company found itself at the center of a scandal related to the hostile takeover by the company management of an unofficial fan group in social network VKontakte, and forced deletion creator of a community of administrators. The initiator of the scandal demanded monetary compensation or the return of the community. According to a company representative, the creator of the group withdrew from participation in its development, and for several years the group was developed and supported only by Doctor Web staff members. Back in early 2013, in connection with the precedents emerging on the social network VKontakte for users to create groups for clients of well-known companies, the development of these groups by the companies themselves and the subsequent appearance of the original creators of the group, accompanied by demands for monetary compensation and threats to delete the group, the company turned to the social the VKontakte network with a request to transfer group administration rights to an account belonging to Doctor Web, and the request was granted.