Thanks for another nice review MB <3

but noticed that Default settings are for real world which you never download 100 malwares and execute all of them :D
if you want join to a war zone like this, you need to set Dr.Web on Paranoid :D

( by the way Dr.Web KATANA is not realy good as Security Space is, i don't know why, but Behavior Blocker in DrWeb Security Space works better ! )
 
M

MalwareBlockerYT

Thanks for another nice review MB <3

but noticed that Default settings are for real world which you never download 100 malwares and execute all of them :D
if you want join to a war zone like this, you need to set Dr.Web on Paranoid :D

( by the way Dr.Web KATANA is not realy good as Security Space is, i don't know why, but Behavior Blocker in DrWeb Security Space works better ! )
Yeah the BB doesn't seem as good as on Security Space, thanks for watching :D
 

Der.Reisende

Level 42
Verified
Trusted
Content Creator
Malware Hunter
Yeah the BB doesn't seem as good as on Security Space, thanks for watching :D
I wonder why, because here they state it should be the same:
"Attention, Dr.Web Security Space and Dr.Web Anti-virus users!
You won't have to purchase Dr.Web KATANA—its protection technologies have been incorporated into the Dr.Web applications you are using."
Dr.Web KATANA

However, it's good to see so much pressure put on Dr. Web lately by vid reviews here, hope they will take care soon - hope dies last :)

Thank you for all those great productions lately @MalwareBlockerYT :)
 
M

MalwareBlockerYT

I wonder why, because here they state it should be the same:
"Attention, Dr.Web Security Space and Dr.Web Anti-virus users!
You won't have to purchase Dr.Web KATANA—its protection technologies have been incorporated into the Dr.Web applications you are using."
Dr.Web KATANA

However, it's good to see so much pressure put on Dr. Web lately by vid reviews here, hope they will take care soon - hope dies last :)

Thank you for all those great productions lately @MalwareBlockerYT :)
Yeah it's weird but in testing KATANA seems worse :confused: Thanks for the support :) There's a special video coming soon for 500 subs!
 
hope they will take care soon
i'm just a person who tried for almost a year to learn their believes, and as that person, i know they don't care about these Personal tests, they don't believe them, if they had, they will join to Av-Com and Av-Tes ( in Dr.Web Company also there is some opinions about that av-com and av-test just care about money )

anyway, they don't care about these forums, its just increase their Users/Beta Testers works, we need to collect these information from such these good Reviews, and forward for them in Bug Tracker , thats the only way they could listen :D

MalwareBlockerYT, could you please upload that JohnyCrypt and send its link as a PM for me? Spora Ransomware already forwarded for them, its confirmed and Developers are debugging their Prevention Protection.
 
M

MalwareBlockerYT

i'm just a person who tried for almost a year to learn their believes, and as that person, i know they don't care about these Personal tests, they don't believe them, if they had, they will join to Av-Com and Av-Tes ( in Dr.Web Company also there is some opinions about that av-com and av-test just care about money )

anyway, they don't care about these forums, its just increase their Users/Beta Testers works, we need to collect these information from such these good Reviews, and forward for them in Bug Tracker , thats the only way they could listen :D

MalwareBlockerYT, could you please upload that JohnyCrypt and send its link as a PM for me? Spora Ransomware already forwarded for them, its confirmed and Developers are debugging their Prevention Protection.
Please send me a PM to remind me since I'm going to the gym now but will be able to later.
 
W

Wave

I'm going to install Dr. Web Katana in a VM and test it against some custom samples: MBR overwrite, dynamic forking, force BSOD + hijack hosts/browser on reboot, etc... And see if it can block anything lol. No system calls so it should still be able to log behavior fine if it supports that. I'll also take a look at how it's monitoring the programs: e.g. injection + hooks, kernel-mode callbacks, etc.

As for Windows Defender, yeah it does the same on my host -> disable and it auto-enables. It's annoying. And even when it's set to disabled it still cleans malware sometimes, annoying.
 
M

MalwareBlockerYT

I'm going to install Dr. Web Katana in a VM and test it against some custom samples: MBR overwrite, dynamic forking, force BSOD + hijack hosts/browser on reboot, etc... And see if it can block anything lol. No system calls so it should still be able to log behavior fine if it supports that. I'll also take a look at how it's monitoring the programs: e.g. injection + hooks, kernel-mode callbacks, etc.

As for Windows Defender, yeah it does the same on my host -> disable and it auto-enables. It's annoying. And even when it's set to disabled it still cleans malware sometimes, annoying.
Sounds good :) Apart from the Windows Defender thing, I wish there was an easy way to disable it.
 
W

Wave

Well, it seems not an exceptional job but I guess the best place for Dr. Web Katana is alongside a resident AV as a second defense line.
Even that I think would be pointless if you're using a product from a well-established vendor, literally this product failed every single thing I threw at it.. Except user-mode self-protection attacks. Looks like they focus more on self-protection than the actual malware mitigation.

But that's just my personal view and my own results = grain of salt :)
 
M

MalwareBlockerYT

Even that I think would be pointless if you're using a product from a well-established vendor, literally this product failed every single thing I threw at it.. Except user-mode self-protection attacks. Looks like they focus more on self-protection than the actual malware mitigation.

But that's just my personal view and my own results = grain of salt :)
But I mean both me & Leo have tested this & it did equally badly so I would say that it's not really worth using. Zemana or HitmanPro.Alert are both better.
 
Top