Vba32 AntiRootkit 3.12.* beta

Discussion in 'other anti-malware software' started by sergey ulasen, Sep 14, 2009.

Thread Status:
Not open for further replies.
  1. AF_

    AF_ Registered Member

    Joined:
    May 13, 2010
    Posts:
    23
    You have to download version with AV kernel. Here is direct link:
    ftp://anti-virus.by/pub/beta/vba32arkit_full_beta.zip ( updated daily )


    Sry, I didn't understand what do you mean ?
     
  2. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    Thanks AF,

    I'm sorry, my english is not good enough. ;)

    For ie, I have the vba32 log file. In which forum or website is possible to analyze or to check it ? Where can I submit the log file ?

    Also, I've noticed that the scanning time is longer than previous versions.
     
  3. AF_

    AF_ Registered Member

    Joined:
    May 13, 2010
    Posts:
    23
    You can submit the log file here or send it directly to us : arkit[_at_]anti-virus.by
    Usually analysis is pretty much simple and could be done by yourself.
    Yes, it's possible. We are improving disk access code every build ( mainly we're aiming stability of the tool ), sometimes it causes perfomance degradation. Pls check future versions :rolleyes:
     
  4. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
  5. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    AF,

    Any news, please ?
     
  6. Amin

    Amin Registered Member

    Joined:
    May 16, 2012
    Posts:
    437
    Location:
    UK
    Is this the best Anti rootkit ? o_O
     
  7. groft

    groft Registered Member

    Joined:
    Feb 16, 2012
    Posts:
    6
    Hello!
    1) Your Hosts file ( C:\Windows\System32\drivers\etc\Hosts ) is modified. You changed it?
    2) Second Volume boot record is "Non-standard VBR". Dump and send an arkit[@]anti-virus.by
     
  8. groft

    groft Registered Member

    Joined:
    Feb 16, 2012
    Posts:
    6
    You doubt it? Try it!
     
  9. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    Hi groft,

    1) Maybe my Antivirus or anti-malware program.
    2) Ok, thanks. I will send my log file.

     
  10. groft

    groft Registered Member

    Joined:
    Feb 16, 2012
    Posts:
    6
    Dump is created as:
    1. start arkit
    2. open in main windows "Tools -> Low-Level Disk Access Tool -> Volumes"
    3. Select "Non-standard VBR"
    4. In context menu select "dump"
    5. Save & and send an arkit[@]anti-virus.by
     
  11. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    Hi groft,

    I've just sent the requested file, please check it. :thumb:

     
  12. groft

    groft Registered Member

    Joined:
    Feb 16, 2012
    Posts:
    6
    Thanks, tomorrow answer
     
  13. AF_

    AF_ Registered Member

    Joined:
    May 13, 2010
    Posts:
    23
    I've checked both you log file and dump. You system is most likely clean. Non-standard VBR is our false positive and already fixed ( fix will be available in the next beta version )
    Gray and blown are neutral colors. Usually brown means that object doesn't have any anomaly but also doesn't have a digital signature ( if applicable ). With gray color we mark objects that were unloaded from memory or don't exist on filesystem.
    Hope that helps.
     
  14. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    Big thanks AF_ and groft ! :thumb:

    Great job ! Excellent program, go along with the next version :D
     
  15. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    AF_ and groft

    Check your mailbox, I submit a request, thanks. ;)
     
  16. panz

    panz Registered Member

    Joined:
    Oct 14, 2012
    Posts:
    1
    hi, i'm getting the failed to load driver error also on windows 7 64 bit
    i tried the above 'full installer' and it wont run on x64

    any suggestions on how to get past that 'failed to load driver'
    it seems to run otherwise when you hit start

    not sure what functions are lost w/o the driver can you elaborate
    also is there a download with the virus definitions intact other than this one that will run in x64 systems? thx n regards
     
    Last edited by a moderator: Oct 14, 2012
  17. groft

    groft Registered Member

    Joined:
    Feb 16, 2012
    Posts:
    6
    Look post #109
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.