![]() |
|
#1
|
|||
|
|||
|
VirusBlokAda Ltd. glads to offer you a new version of Vba32 AntiRootkit and invite you to participate in beta testing of our product.
Links to download: ftp://anti-virus.by/beta/Vba32arkit_beta.rar ftp://anti-virus.by/beta/Vba32arkit_beta.zip ftp://vba.ok.by/vba/beta/Vba32arkit_beta.rar ftp://vba.ok.by/vba/beta/Vba32arkit_beta.zip The following techniques of kernel-mode rootkit detection are implemented in Vba32 AntiRootkit:
Moreover the following additional techniques are implemented:
The following features are designed for neutralizing rootkits:
Vba32 AntiRootkit allows user to collect information, which may help in solving problems at user's computer. Vba32 AntiRootkit has English help (Vba32ArkitEN.chm file). You can send your feedback to beta[at]anti-virus.by or post it here. Last edited by sergey ulasen : September 14th, 2009 at 12:54 PM. |
|
#2
|
||||
|
||||
|
__________________
Fine Art Landscape Photography
|
|
#3
|
||||
|
||||
|
Much more serious ark than from other antivirus houses, trying out now but first impression is good one.
__________________
Who controls the past controls the future Who controls the present controls the past vmworld |
|
#4
|
||||
|
||||
|
Saraceno, your link is only for antivirus, not for antirootkit.
Link for antirootkit - come also from this Post #17 (with VBA forum link - by Sergey Ulasen - for this antirootkit software) from the thread: 'ANTI-ROOTKITS: Good, Safe ...' here: http://www.wilderssecurity.com/showp...6&postcount=17 Very good tool. Thank you Sergey! PROROOTECT
__________________
W.XPSP2,1GBRAM,13proc,17svc;IE8s *** On-DemandPowerTool XueTr NVT Ga S RFS Preventive+FW!! S.Mon. TinyW. JS SettingsX NoDs . = ![]() URL checkZ Q W T U urlQ W IPduh DNS-info Sleuth R W WPT BC WS M BShotSu C $ Rev IP NoAV,Java JRE-Why Why|VOP MalwareTips-Turin Shroud PSus **READs!!! CATS! |
|
#5
|
||||
|
||||
|
__________________
Free Security Software - If you are currently infected - Securing your PC - Ako's list |
|
#6
|
||||
|
||||
|
sergey ulasen
Thanx Your 4th link doesn't work, the f in front of ftp doesn't get resolved ? |
|
#7
|
|||
|
|||
|
Quote:
Thanks for your post there(http://www.wilderssecurity.com/showpost.php?p=1540086&postcount=17). Until now we have discussing only on http://virusinfo.info/showthread.php?t=41137 in Russian. From this time we will get English-speaking audience to testing Vba32 AntiRootkit. Product is constantly evolving. We have had four beta-iterations (3.12.3.0, 3.12.3.1, 3.12.3.2, 3.12.3.3) for 7 monthes. You can see it in readme.en. Now we are working up a low level disk access. |
|
#8
|
|||
|
|||
|
Quote:
Thanks ![]() |
|
#9
|
|||
|
|||
|
No problems on XP Pro SP2.
|
|
#10
|
|||
|
|||
|
Vba32 AntiRootKit 3.12.3.3 beta:
ftp://anti-virus.by/beta/Vba32arkit_beta.rar ftp://anti-virus.by/beta/Vba32arkit_beta.zip ftp://vba.ok.by/vba/beta/Vba32arkit_beta.rar ftp://vba.ok.by/vba/beta/Vba32arkit_beta.zip + Added support of Windows 7 I think it's the last major change in the present branch. In the nearest future (during the month) we are planning to release public-version Vba32 AntiRootkit 3.12.4.0. Thank you.
__________________
Sergey Ulasen |
|
#11
|
|||
|
|||
|
Just tried to run this latest version, but it says - " couldn't install driver"
However, I can still run the earlier version with no problem. See screenshot attached. |
|
#12
|
|||
|
|||
|
can you ad keyboard support? i can not navigate whith tab and can not select the options.
|
|
#13
|
|||
|
|||
|
Quote:
May be problem is connected with DefenseWall. Please, add vba32arkit.exe in "white list" and try again.
__________________
Sergey Ulasen |
|
#14
|
|||
|
|||
|
Quote:
__________________
DefenseWall HIPS developer. www.softsphere.com |
|
#15
|
|||
|
|||
|
Quote:
I tried this, but it didn't work. Quote:
I don't why had so much trouble this time around, but I deleted everything and started over. I extracted the rar file to the unzipped folder as trusted, and this time it worked. See a copy of the Dw_log.txt for informational purposes, showing the unsuccessful attempts. |
|
#16
|
|||
|
|||
|
"module C:\unzipped\vba\Vba32arkit.exe, Loading untrusted/untrusted created module C:\unzipped\vba\Vba32ar.dll. Process is untrusted now". That's the reason of the issue.
Just totally remove "vba" folder and unrar as trusted. Or, another solution- select the "vba" folder and run "change status to trusted".
__________________
DefenseWall HIPS developer. www.softsphere.com |
|
#17
|
|||
|
|||
|
Thanks to Ilya Rabinovich
Quote:
We know about problem. But I can't promise that we'll fix it in the nearest future.
__________________
Sergey Ulasen |
|
#18
|
|||
|
|||
|
Vba32 AntiRootkit 3.12.4.0 release:
http://anti-virus.by/en/vba32arkit.html Vba32 AntiRootkit advantages:
__________________
Sergey Ulasen |
|
#19
|
||||
|
||||
|
Can you give some more informations of how this works:
Quote:
thanks
__________________
Webroot Secure Anywhere - Norton DNS - MalwareBytes - A bit of luck |
|
#20
|
|||
|
|||
|
Quote:
Following operations are available: deleting files, copying files to the quarantine. To do this, select the File - Run Script menu item. Example: Code:
All information about scripts is available in Vba32arkitEn.chm file in Additional Features/Running Scripts chapter.
__________________
Sergey Ulasen |
|
#21
|
||||
|
||||
|
Does it have OnBootClean like AVZ?
__________________
Webroot Secure Anywhere - Norton DNS - MalwareBytes - A bit of luck |
|
#22
|
|||
|
|||
|
Quote:
Yes, it does
__________________
Sergey Ulasen |
|
#23
|
|||
|
|||
|
Vba32 AntiRootKit 3.12.5.0 beta:
ftp://anti-virus.by/beta/Vba32arkit_beta.rar ftp://anti-virus.by/beta/Vba32arkit_beta.zip ftp://vba.ok.by/vba/beta/Vba32arkit_beta.rar ftp://vba.ok.by/vba/beta/Vba32arkit_beta.zip + Added direct disk access mechanism. NTFS and FAT 12/16/32 are supported. Low-level file verification is performed in all existed windows / checks + Added Low-Level Disk Access Tool windows. View, Copy, Delete and Wipe (with purging from windows file cache) operations were implemented at a low level. Hidden, locked and forged files can be optionally highlighted. NTFS Alternate Data Streams and symbolic links are also supported + Vba32 Defender prevents executable file startup and driver loading during the antirootkit operation time + Search hidden drivers was improved, Windows driver stack analysis was added + Search of hidden processes was improved (were added handle search in csrss.exe, PspCidTable parsing and etc.) + Section attributes verification for all kernel-mode modules was added + Search of hidden IRP handlers was added * Possibility to exclude user mode images in kernel modules window was added * Prosess window was improved, EPROCESS address and short name were added to user view * Interaction between GUI and antirootkit driver was improved * Hook detection mechanism was revised. Checking of EAT and code sections of all kernel mode modules was implemented * Help in Russian was improved
__________________
Sergey Ulasen |
|
#24
|
||||
|
||||
|
Thank you
|
|
#25
|
||||
|
||||
|
i am trying this one now
![]()
__________________
Emsisoft Anti-Malware 7.0 |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|