Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 14th, 2009, 05:30 AM
sergey ulasen sergey ulasen is offline
AV Expert
 
Join Date: Sep 2009
Posts: 50
Default Vba32 AntiRootkit 3.12.* beta

VirusBlokAda Ltd. glads to offer you a new version of Vba32 AntiRootkit and invite you to participate in beta testing of our product.
Links to download:

ftp://anti-virus.by/beta/Vba32arkit_beta.rar

ftp://anti-virus.by/beta/Vba32arkit_beta.zip

ftp://vba.ok.by/vba/beta/Vba32arkit_beta.rar

ftp://vba.ok.by/vba/beta/Vba32arkit_beta.zip

The following techniques of kernel-mode rootkit detection are implemented in Vba32 AntiRootkit:
  • searching for SYSENTER hooks;
  • searching for hooks by replacing addresses in SSDT table;
  • searching for hooks by replacing addresses in Shadow SSDT table;
  • searching for hooks by modifying IDT table;
  • searching for export table modifications of main kernel modules (ndis.sys, hal.dll, ntoskrnl.exe);
  • searching for hooks by modifiying machine code (splicing);
  • searching for hooks by replacing addresses of IRP packet handlers;
  • searching for hooks by replacing addresses of FastIO request handlers;
  • searching for kernel modules hidden in the memory. If an object is considered as hidden, it'll be marked as Hidden in memory;
  • searching for processes hidden in memory. If an object is considered as hidden, it'll be marked as Hidden in memory;
  • searching for kernel modules which image on the hard drive doesn't correspond to the image in the memory. Such objects will be marked as Modified image;
  • searching for installed kernel mode notificators.

Moreover the following additional techniques are implemented:
  • scanning autoruns;
  • scanning drivers and services specified in the registry;
  • scanning all obtained objects (process files, autoruns, loaded drivers/services and kernel modules);
  • checking digital signature of all obtained objects (process files, autoruns, loaded drivers/services and kernel modules);
  • displaying additional information retrievied from file resources.

The following features are designed for neutralizing rootkits:
  • restoring hooks in SSDT table;
  • restoring hooks in Shadow SSDT table;
  • restoring hooks in IDT table;
  • restoring hooks in main kernel modules (ndis.sys, hal.dll, ntoskrnl.exe);
  • restoring hooks made by machine code modifications;
  • restoring SYSENTER hooks;
  • removing specified objects from autoruns;
  • enabling/disabling drivers/services specified in the registry;
  • copying specified files to the quarantine early in the system boot;
  • deleting specified files early in the system boot;
  • scanning and deleting autorun.inf files;
  • removing installed kernel mode notificators.

Vba32 AntiRootkit allows user to collect information, which may help in solving problems at user's computer.

Vba32 AntiRootkit has English help (Vba32ArkitEN.chm file).

You can send your feedback to beta[at]anti-virus.by or post it here.

Last edited by sergey ulasen : September 14th, 2009 at 12:54 PM.
  #2  
Old September 14th, 2009, 07:03 AM
Saraceno's Avatar
Saraceno Saraceno is offline
Very Frequent Poster
 
Join Date: Mar 2008
Posts: 2,395
Default Re: Vba32 AntiRootkit 3.12.3 beta

This is the english site for the company, for those interested:

http://www.anti-virus.by/en/
__________________
Fine Art Landscape Photography
  #3  
Old September 14th, 2009, 08:23 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Vba32 AntiRootkit 3.12.3 beta

Much more serious ark than from other antivirus houses, trying out now but first impression is good one.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #4  
Old September 14th, 2009, 09:04 AM
PROROOTECT's Avatar
PROROOTECT PROROOTECT is offline
Very Frequent Poster
 
Join Date: May 2008
Location: HERE ...Fort Lee, NJ
Posts: 1,102
Default Re: Vba32 AntiRootkit 3.12.3 beta

Saraceno, your link is only for antivirus, not for antirootkit.

Link for antirootkit - come also from this Post #17 (with VBA forum link - by Sergey Ulasen - for this antirootkit software) from the thread: 'ANTI-ROOTKITS: Good, Safe ...' here: http://www.wilderssecurity.com/showp...6&postcount=17

Very good tool.

Thank you Sergey!


PROROOTECT
__________________
W.XPSP2,1GBRAM,13proc,17svc;IE8s ***
On-Demand
PowerTool XueTr NVT Ga S RFS
Preventive+
FW!! S.Mon. TinyW. JS SettingsX NoDs . =
URL checkZ Q W T U urlQ W IPduh DNS-info Sleuth
R W WPT BC WS M BShotSu C $ Rev IP
NoAV,Java JRE-Why Why|VOP MalwareTips-Turin Shroud PSus **READs!!! CATS!
  #5  
Old September 14th, 2009, 09:26 AM
Keyboard_Commando's Avatar
Keyboard_Commando Keyboard_Commando is offline
Frequent Poster
 
Join Date: Mar 2009
Posts: 682
Default Re: Vba32 AntiRootkit 3.12.3 beta

Worked fine XP SP3. Haven't tried installing driver at boot yet.

Click image for larger version

Name:	ark1.JPG
Views:	26
Size:	86.9 KB
ID:	212225

Click image for larger version

Name:	ark2.JPG
Views:	20
Size:	131.1 KB
ID:	212226
  #6  
Old September 14th, 2009, 12:00 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: Vba32 AntiRootkit 3.12.3 beta

sergey ulasen

Thanx

Your 4th link doesn't work, the f in front of ftp doesn't get resolved ?
  #7  
Old September 14th, 2009, 12:53 PM
sergey ulasen sergey ulasen is offline
AV Expert
 
Join Date: Sep 2009
Posts: 50
Default Re: Vba32 AntiRootkit 3.12.3 beta

Quote:
Originally Posted by PROROOTECT
Link for antirootkit - come also from this Post #17 (with VBA forum link - by Sergey Ulasen - for this antirootkit software) from the thread: 'ANTI-ROOTKITS: Good, Safe ...' here: http://www.wilderssecurity.com/showp...6&postcount=17

Very good tool.

Thank you Sergey!

Thanks for your post there(http://www.wilderssecurity.com/showpost.php?p=1540086&postcount=17).

Until now we have discussing only on http://virusinfo.info/showthread.php?t=41137 in Russian. From this time we will get English-speaking audience to testing Vba32 AntiRootkit.

Product is constantly evolving. We have had four beta-iterations (3.12.3.0, 3.12.3.1, 3.12.3.2, 3.12.3.3) for 7 monthes. You can see it in readme.en.

Now we are working up a low level disk access.
  #8  
Old September 14th, 2009, 12:56 PM
sergey ulasen sergey ulasen is offline
AV Expert
 
Join Date: Sep 2009
Posts: 50
Default Re: Vba32 AntiRootkit 3.12.3 beta

Quote:
Originally Posted by StevieO
Your 4th link doesn't work, the f in front of ftp doesn't get resolved ?

Thanks
  #9  
Old September 14th, 2009, 08:22 PM
Tarnak Tarnak is offline
Very Frequent Poster
 
Join Date: Feb 2007
Posts: 1,945
Default Re: Vba32 AntiRootkit 3.12.3 beta

No problems on XP Pro SP2.
Attached Thumbnails
Click image for larger version

Name:	ScreenShot_RootKit_13.gif
Views:	43
Size:	33.6 KB
ID:	212244  

  #10  
Old October 7th, 2009, 09:46 AM
sergey ulasen sergey ulasen is offline
AV Expert
 
Join Date: Sep 2009
Posts: 50
Default Re: Vba32 AntiRootkit 3.12.3 beta

Vba32 AntiRootKit 3.12.3.3 beta:

ftp://anti-virus.by/beta/Vba32arkit_beta.rar

ftp://anti-virus.by/beta/Vba32arkit_beta.zip

ftp://vba.ok.by/vba/beta/Vba32arkit_beta.rar

ftp://vba.ok.by/vba/beta/Vba32arkit_beta.zip

+ Added support of Windows 7

I think it's the last major change in the present branch. In the nearest future (during the month) we are planning to release public-version Vba32 AntiRootkit 3.12.4.0.

Thank you.
__________________
Sergey Ulasen
  #11  
Old October 7th, 2009, 11:08 AM
Tarnak Tarnak is offline
Very Frequent Poster
 
Join Date: Feb 2007
Posts: 1,945
Default Re: Vba32 AntiRootkit 3.12.3 beta

Just tried to run this latest version, but it says - " couldn't install driver"
However, I can still run the earlier version with no problem.
See screenshot attached.
Attached Thumbnails
Click image for larger version

Name:	ScreenShot_RootKit_17.gif
Views:	23
Size:	18.0 KB
ID:	212816  

  #12  
Old October 7th, 2009, 12:44 PM
markusg markusg is offline
Frequent Poster
 
Join Date: Jun 2009
Posts: 223
Default Re: Vba32 AntiRootkit 3.12.3 beta

can you ad keyboard support? i can not navigate whith tab and can not select the options.
  #13  
Old October 7th, 2009, 12:50 PM
sergey ulasen sergey ulasen is offline
AV Expert
 
Join Date: Sep 2009
Posts: 50
Default Re: Vba32 AntiRootkit 3.12.3 beta

Quote:
Originally Posted by Tarnak
Just tried to run this latest version, but it says - " couldn't install driver"
However, I can still run the earlier version with no problem.
See screenshot attached.

May be problem is connected with DefenseWall. Please, add vba32arkit.exe in "white list" and try again.
__________________
Sergey Ulasen
  #14  
Old October 7th, 2009, 04:44 PM
Ilya Rabinovich Ilya Rabinovich is offline
Developer
 
Join Date: Sep 2005
Posts: 1,516
Default Re: Vba32 AntiRootkit 3.12.3 beta

Quote:
Originally Posted by Tarnak
Just tried to run this latest version, but it says - " couldn't install driver"
Because you tried to install as untrusted. Run installation file as trusted.
__________________
DefenseWall HIPS developer. www.softsphere.com
  #15  
Old October 7th, 2009, 07:20 PM
Tarnak Tarnak is offline
Very Frequent Poster
 
Join Date: Feb 2007
Posts: 1,945
Default Re: Vba32 AntiRootkit 3.12.3 beta

Quote:
Originally Posted by sergey ulasen
May be problem is connected with DefenseWall. Please, add vba32arkit.exe in "white list" and try again.

I tried this, but it didn't work.

Quote:
Originally Posted by Ilya Rabinovich
Because you tried to install as untrusted. Run installation file as trusted.

I don't why had so much trouble this time around, but I deleted everything and started over.

I extracted the rar file to the unzipped folder as trusted, and this time it worked.

See a copy of the Dw_log.txt for informational purposes, showing the unsuccessful attempts.
Attached Files
File Type: txt DW_log.txt (16.9 KB, 39 views)
  #16  
Old October 8th, 2009, 05:46 AM
Ilya Rabinovich Ilya Rabinovich is offline
Developer
 
Join Date: Sep 2005
Posts: 1,516
Default Re: Vba32 AntiRootkit 3.12.3 beta

"module C:\unzipped\vba\Vba32arkit.exe, Loading untrusted/untrusted created module C:\unzipped\vba\Vba32ar.dll. Process is untrusted now". That's the reason of the issue.

Just totally remove "vba" folder and unrar as trusted. Or, another solution- select the "vba" folder and run "change status to trusted".
__________________
DefenseWall HIPS developer. www.softsphere.com
  #17  
Old October 8th, 2009, 08:54 AM
sergey ulasen sergey ulasen is offline
AV Expert
 
Join Date: Sep 2009
Posts: 50
Default Re: Vba32 AntiRootkit 3.12.3 beta

Thanks to Ilya Rabinovich

Quote:
Originally Posted by markusg
can you ad keyboard support? i can not navigate whith tab and can not select the options.

We know about problem. But I can't promise that we'll fix it in the nearest future.
__________________
Sergey Ulasen
  #18  
Old November 17th, 2009, 04:23 AM
sergey ulasen sergey ulasen is offline
AV Expert
 
Join Date: Sep 2009
Posts: 50
Default Re: Vba32 AntiRootkit 3.12.3 beta

Vba32 AntiRootkit 3.12.4.0 release:

http://anti-virus.by/en/vba32arkit.html

Vba32 AntiRootkit advantages:
  • Does not require installation
  • Can be used with any antivirus software installed on your computer
  • Uses a unique feature of the detection of "clean" files
  • Can be used in several modes
  • Supports the maintenance of a system status report in html format
  • Treatment of the system may be done using a scripting language
  • Supports Windows 7
  • Help files in Russian and English languages
__________________
Sergey Ulasen
  #19  
Old November 18th, 2009, 11:59 AM
Durad's Avatar
Durad Durad is offline
Frequent Poster
 
Join Date: Aug 2005
Location: Canada
Posts: 524
Default Re: Vba32 AntiRootkit 3.12.3 beta

Can you give some more informations of how this works:

Quote:
Treatment of the system may be done using a scripting language


thanks
__________________
Webroot Secure Anywhere - Norton DNS - MalwareBytes - A bit of luck
  #20  
Old November 18th, 2009, 01:29 PM
sergey ulasen sergey ulasen is offline
AV Expert
 
Join Date: Sep 2009
Posts: 50
Default Re: Vba32 AntiRootkit 3.12.3 beta

Quote:
Originally Posted by Durad
Can you give some more informations of how this works:

Following operations are available: deleting files, copying files to the quarantine. To do this, select the File - Run Script menu item.

Example:

Code:
Brs_Start(); Brs_QtnFile("c:\x.exe"); Brs_DelFile("c:\x.exe"); RebootSystem();

All information about scripts is available in Vba32arkitEn.chm file in Additional Features/Running Scripts chapter.
__________________
Sergey Ulasen
  #21  
Old November 19th, 2009, 08:49 PM
Durad's Avatar
Durad Durad is offline
Frequent Poster
 
Join Date: Aug 2005
Location: Canada
Posts: 524
Default Re: Vba32 AntiRootkit 3.12.3 beta

Does it have OnBootClean like AVZ?
__________________
Webroot Secure Anywhere - Norton DNS - MalwareBytes - A bit of luck
  #22  
Old November 20th, 2009, 12:49 PM
sergey ulasen sergey ulasen is offline
AV Expert
 
Join Date: Sep 2009
Posts: 50
Default Re: Vba32 AntiRootkit 3.12.3 beta

Quote:
Originally Posted by Durad
Does it have OnBootClean like AVZ?

Yes, it does
__________________
Sergey Ulasen
  #23  
Old February 23rd, 2010, 03:51 AM
sergey ulasen sergey ulasen is offline
AV Expert
 
Join Date: Sep 2009
Posts: 50
Default Vba32 AntiRootkit 3.12.5.0 beta

Vba32 AntiRootKit 3.12.5.0 beta:

ftp://anti-virus.by/beta/Vba32arkit_beta.rar

ftp://anti-virus.by/beta/Vba32arkit_beta.zip

ftp://vba.ok.by/vba/beta/Vba32arkit_beta.rar

ftp://vba.ok.by/vba/beta/Vba32arkit_beta.zip

+ Added direct disk access mechanism. NTFS and FAT 12/16/32 are supported. Low-level file verification is performed in all existed windows / checks

+ Added Low-Level Disk Access Tool windows. View, Copy, Delete and Wipe (with purging from windows file cache) operations were implemented at a low level. Hidden, locked and forged files can be optionally highlighted. NTFS Alternate Data Streams and symbolic links are also supported

+ Vba32 Defender prevents executable file startup and driver loading during the antirootkit operation time

+ Search hidden drivers was improved, Windows driver stack analysis was added

+ Search of hidden processes was improved (were added handle search in csrss.exe, PspCidTable parsing and etc.)

+ Section attributes verification for all kernel-mode modules was added

+ Search of hidden IRP handlers was added

* Possibility to exclude user mode images in kernel modules window was added

* Prosess window was improved, EPROCESS address and short name were added to user view

* Interaction between GUI and antirootkit driver was improved

* Hook detection mechanism was revised. Checking of EAT and code sections of all kernel mode modules was implemented

* Help in Russian was improved
__________________
Sergey Ulasen
  #24  
Old February 23rd, 2010, 07:18 AM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,855
Thumbs up Re: Vba32 AntiRootkit 3.12.3 beta

Thank you
  #25  
Old February 23rd, 2010, 07:54 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,770
Default Re: Vba32 AntiRootkit 3.12.3 beta

i am trying this one now
__________________
Emsisoft Anti-Malware 7.0
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:37 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums