All news

BadRabbit fears Dr.Web-protected computers: Our research on the infamous Trojan

The encryption Trojan Trojan.BadRabbit, which in recent days has been widely discussed by numerous media outlets, websites, and anti-virus software developers, started spreading on October 24 and soon (according to the same mass media sources) infected scores of computers not only in Russia but also in other countries. Doctor Web is publishing the preliminary results of its research on this malicious program. Of particular note, “bad rabbit” verifies whether Dr.Web products are operating on a computer. If it detects processes connected with them, it skips the encryption stage in an effort to avoid detection. The Trojan also checks for the presence of McAfee products.
About viruses  |  Dr.Web products  |  Real-time threat watch
Read

How to recover a Dr.Web Security Space for Android version 12 password

In Dr.Web Security Space for Android version 12, the application’s account information has been password-protected. This ensures that the URL filter, Call and SMS Filter, and Anti-theft are now reliably protected from having their settings tampered with—provided Parental Control is enabled and configured on a device.
Dr.Web products
Read

Dr.Web will tell whether Android devices have been exposed to the BlueBorne vulnerability in the Bluetooth protocol

Bluetooth is one of the most widespread communication protocols and a popular data-transfer channel used by mobile phones, computers, household appliances, electronics, children’s toys, medical devices, and cars. It provides a secure connection; however, sometimes flaws are discovered in it.
Dr.Web products  |  Real-time threat watch
Read

Dr.Web-protected systems stave off "bad rabbit"

Trojan.BadRabbit, a.k.a. BadRabbit, poses no threat to users whose machines are protected by up-to-date Dr.Web versions that have the preventive protection component enabled. Dr.Web detects the malware as DPH:Trojan.Encoder.32 and thus prevents it from encrypting files. It also prevents the malware from modifying the MBR. The Trojan's payload is similar to that of Trojan.Encoder.12544, also known as Petya, Petya.A, ExPetya and WannaCry-2, and uses the same routine. The program has been examined by Doctor Web's researchers.
About viruses  |  Dr.Web products
Read

Dr.Web solutions 11.0.4 for Unix updated

Russian anti-virus company Doctor Web has updated the following products to version 11.0.4: Dr.Web Anti-virus for Linux, Dr.Web Anti-virus for Unix Mail Servers, Dr.Web Anti-virus for Unix Server and Dr.Web Anti-virus for Internet Gateways Unix.
Dr.Web products  |  Dr.Web software updates
Read

Doctor Web examines backdoor written in Python

Backdoors are malicious programs that can execute the commands of cybercriminals, allowing them to illegally control an infected device. Doctor Web’s analysts have examined a new backdoor whose key feature is that it is written in Python.
About viruses  |  Dr.Web products  |  Real-time threat watch
Read

Amulet coins, beard serum, and other “miraculous” Internet goods

Doctor Web has already published material on the various amusing artefacts being sold in Russian online shops—everything from evil-eye-thwarting thread to devices that employ magnets and black magic to help car owners save on gas. We continue to research this captivating topic. Today we will tell you about curious novelties from online shops offering questionable goods.
Dr.Web products  |  Real-time threat watch
Read

Dr.Web for IBM Lotus Domino updated to version 11.0.3

Russian anti-virus company Doctor Web has updated the plugin Dr.Web for IBM Lotus Domino for Windows to version 11.0.3.
Dr.Web products  |  Dr.Web software updates
Read

Dangerous vulnerabilities in Bluetooth and a banking Trojan on Google Play: September 2017 mobile virus activity review

Doctor Web presents its September 2017 overview of malware for mobile devices. In the past month, vulnerabilities were discovered in the implementation of the Bluetooth protocol, and cybercriminals are exploiting them to gain full control over attacked devices and perform numerous malicious actions. In addition, yet another banking Trojan was detected on Google Play.
Dr.Web products
Read

Doctor Web’s overview of malware detected on mobile devices in September 2017

About viruses  |  Mobile threats  |  Dr.Web products  |  Virus reviews  |  Dr.Web software updates
Read

Mining with JavaScript, IoT-facilitated spam mailings, and other events of September 2017

Doctor Web presents its September 2017 virus activity review. During the first month of autumn, security specialists detected several websites using JavaScript to mine cryptocurrency. In addition, Doctor Web virus analysts discovered that cybercriminals are using the Internet of things (IoT) to distribute spam. Also in September, a significant number of dangerous vulnerabilities in the Bluetooth protocol stack were detected. They particularly threaten Android users.
Dr.Web products
Read

Doctor Web’s September 2017 virus activity review

About viruses  |  Dr.Web products  |  Virus reviews
Read

Components updated in Dr.Web 11.0 for Windows, Dr.Web CureNet!, Dr.Web KATANA 1.0, Dr.Web Enterprise Security Suite 10.0 and 10.1, Dr.Web 11.0 for MS Exchange, Dr.Web 11.0 for Microsoft ISA Server and Forefront TMG, Dr.Web 11.0 for IBM Lotus Domino and Dr.Web AV-Desk 10.0

Russian anti-virus company Doctor Web has updated Dr.Web File System Monitor (11.01.05.09130), Dr.Web Net Filter for Windows driver (11.1.5.09140), Dr.Web Control Service (11.0.24.09210 and 11.0.23.09210), Dr.Web Net filtering Service (11.1.13.09140) and Dr.Web Anti-rootkit API (11.1.13.201709250) in a number of Dr.Web products. In addition, Dr.Web Scanning Engine (11.1.12.201709200) was updated in Dr.Web CureNet! 11.0.
Dr.Web products  |  Dr.Web software updates
Read

Dr.Web Scanning Engine updated in a number of Dr.Web products.

Russian anti-virus company Doctor Web has updated Dr.Web Scanning Engine (11.1.12.201709200) in Dr.Web Security Space 11.0, Dr.Web Anti-virus 11.0, Dr.Web Enterprise Security Suite 10.0 and 10.1, Dr.Web 11.0 for MS Exchange, Dr.Web 11.0 for Microsoft ISA Server и Forefront TMG, Dr.Web 11.0 for IBM Lotus Domino and Dr.Web AV-Desk 10.0.
Dr.Web products  |  Dr.Web software updates
Read

Dr.Web Light 11.0.0 for macOS released

Russian anti-virus company Doctor Web is pleased to announce the release of Dr.Web Light 11.0.0 for macOS. The product has been revamped and improved.
Dr.Web products  |  Dr.Web software updates
Read

Dr.Web Scanner SE updated in a number of Dr.Web products.

Russian anti-virus company Doctor Web has updated Dr.Web Scanner SE (11.0.10.09010) in Dr.Web Security Space 11.0, Dr.Web Anti-virus 11.0, Dr.Web Anti-virus 11.0 for Windows Servers, Dr.Web Enterprise Security Suite 10.0 and 10.1, as well as in the Internet-service Dr.Web AV-Desk 10.0.
Dr.Web products  |  Dr.Web software updates
Read

Cybercriminals using Internet of things to send spam messages

The number of malicious programs capable of infecting “smart” Linux devices is constantly increasing. A major portion of them is designed to mount DDoS attacks and ensure online anonymity. Research conducted by Doctor Web’s specialists has revealed that cybercriminals are using such Linux Trojans for mass mailings.
About viruses  |  Dr.Web products  |  Real-time threat watch
Read

SpIDer Gate updated in Dr.Web 11.0.3 for UNIX

Russian anti-virus company Doctor Web has updated the HTTP monitor SpIDer Gate in Dr.Web Anti-virus 11.0.3 for Linux, Dr.Web Anti-virus 11.0.3 for Unix Server and Dr.Web Anti-virus 11.0.3 for Internet gateways Unix. The update delivers a fix for an identified problem.
Dr.Web products  |  Dr.Web software updates
Read

Components updated in Dr.Web 11.0 for Windows, Dr.Web KATANA 1.0, Dr.Web Enterprise Security Suite 10.0 and 10.1, Dr.Web 11.0 for MS Exchange, Dr.Web 11.0 for Microsoft ISA Server and Forefront TMG, Dr.Web 11.0 for IBM Lotus Domino and Dr.Web AV-Desk 10.0

Russian anti-virus company Doctor Web has updated SpIDer Agent for Windows (11.0.20.08290), the Dr.Web Updater component (11.0.28.08160), Dr.Web Control Service (11.0.20.08310 and 11.0.19.08310) and Lua scripts for dws-parental-control (11.0.6.08220) in a number of Dr.Web products.
Dr.Web products  |  Dr.Web software updates
Read

Android Trojans attacking websites, a dangerous banker, and other events: August 2017 mobile virus activity review

Doctor Web presents its August 2017 overview of malware for mobile devices. In the past month, Google Play was found to contain Trojans that mounted DDoS attacks on websites. Furthermore, malicious programs that covertly loaded web pages and automatically tapped on the advertising banners located on them were detected. Also in August the Dr.Web virus database was updated with the signature of a dangerous Android banker that stole confidential information. In addition, Google Play was infiltrated by a dropper Trojan designed to install other malicious applications.
Dr.Web products
Read

Doctor Web’s overview of malware detected on mobile devices in August 2017

About viruses  |  Mobile threats  |  Dr.Web products  |  Virus reviews  |  Dr.Web software updates
Read

Components updated in Dr.Web 11.0 for Windows, Dr.Web CureNet!, Dr.Web KATANA 1.0, Dr.Web Enterprise Security Suite 10.0 and 10.1, Dr.Web 11.0 for MS Exchange, Dr.Web 11.0 for Microsoft ISA Server and Forefront TMG, Dr.Web 11.0 for IBM Lotus Domino and Dr.Web AV-Desk 10.0

Russian anti-virus company Doctor Web has updated Dr.Web Net filtering Service (11.1.12.08100), Dr.Web Anti-rootkit API (11.1.12.201708242), Dr.Web SelfPROtect (11.01.11.06270), Dr.Web Firewall for Windows (11.1.7.08211) and Dr.Web Firewall Driver (11.01.07.08230) in a number of Dr.Web products. The update delivers new features and resolves known issues.
Dr.Web products  |  Dr.Web software updates
Read

Malicious mass mailings, a new Trojan miner, and other events of August 2017

Doctor Web presents its August 2017 virus activity review. In early August, Doctor Web detected mailings being used by cybercriminals to try to compromise websites by deceiving their administrators. Also in August, the company detected a Trojan-Miner for Linux whose loader code included the address of Brian Krebs’ website, and Linux.Hajime Trojan loader versions for devices possessing the MIPS and MIPSEL architecture were added to the Dr.Web virus databases.
Dr.Web products
Read

Doctor Web’s August 2017 virus activity review

About viruses  |  Dr.Web products  |  Virus reviews
Read

Dr.Web was the first to detect Trojan loader for smart Linux devices with MIPS/MIPSEL architectures

The assortment of modern malicious programs for devices that run on Linux is extremely wide. One of the most widespread Trojans for this OS is Linux.Hajime, several loaders of which are detected only by the Dr.Web Anti-virus.
About viruses  |  Dr.Web products  |  Real-time threat watch
Read