Basic Anti-Virus Components

Component

Description

Dr.Web Virus-Finding Engine

Anti-virus engine. Implements algorithms to detect viruses and other malware (by using signature and heuristic analyses).

Managed by the Dr.Web Scanning Engine component


Library file: drweb32.dll.

Logged internal name: CoreEngine

Scanning engine. This component loads Dr.Web Virus-Finding Engine and virus databases.

Passes the contents of files and boot records to the anti-virus engine for scanning.

Manages a queue of the files to be scanned.

Cures threats to which this action is applicable.

Operates under the control of the Dr.Web ConfigD daemon or in standalone mode.

Used by the Dr.Web File Checker and Dr.Web Network Checker components. Also can be used by the Dr.Web MeshD component (in particular modes) and by external (in relation to Dr.Web Server Security Suite) applications using directly the Dr.Web Scanning Engine API


Executable file: drweb-se.

Logged internal name: ScanEngine

Virus databases

Automatically updated database of signatures of viruses and other threats, as well as of malware detection and neutralization algorithms.

Used by Dr.Web Virus-Finding Engine and is supplied with it

Component for scanning file system objects and a quarantine manager.

Receives tasks from the threat scanning component on scanning files in the local (relative to Dr.Web Scanning Engine) file system.

Surfs the file system directories according to the task, sends files for scanning to Dr.Web Scanning Engine and notifies the client components about the scanning progress.

Deletes infected files, puts them in and restores them from quarantine, manages quarantine directories.

Builds the cache and keeps it up-to-date. The cache contains information about previously scanned files to reduce the frequency of rescanning files.

Used by components that scan file system objects, such as SpIDer Guard, SpIDer Guard for SMB, SpIDer Guard for NSS


Executable file: drweb-filecheck.

Logged internal name: FileCheck

Network data scanning agent.

Used to send data to the scanning engine for actual scanning. The data is sent by components of the product via the network (such components as Dr.Web ClamD).

Allows Dr.Web Server Security Suite to manage distributed file scanning: to receive/transmit files for scanning from/to remote hosts. For that purpose, remote hosts must feature an installed and running Dr.Web for Unix operating systems. In the distributed scanning mode, it allows automatic distribution of scanning load among available hosts by reducing load on hosts with a large number of scanning tasks (for example, on mail servers and internet gateways).

If the network contains partner hosts that can receive data for scanning, the components that use Dr.Web Network Checker for scanning may operate without local Dr.Web Scanning Engine. Thus, local Dr.Web Scanning Engine, Dr.Web Virus-Finding Engine and virus databases may be absent.

For security reasons, files are transmitted over the network using SSL


Executable file: drweb-netcheck.

Logged internal name: NetCheck

Component that connects Dr.Web Server Security Suite to a local cloud, which allows Dr.Web for Unix products to exchange updates, results of file scanning, transmit files to each other for scanning, as well as to provide scanning engine services directly.

If this component is included in the product and the local cloud to which it is connected contains hosts providing scanning engine services, local Dr.Web Scanning Engine, Dr.Web Virus-Finding Engine and virus databases may be absent


Executable file: drweb-meshd.

Logged internal name: MeshD