Thursday, February 19, 2009

ANSAV +E ADVANCED (1.9.3) AND ANSAV 2

What the package ?
1. ansav.exe -> primary executable ANSAV
MD5 : 5B737C1027D2D418D0A613973DE3FA9F
CRC-32 : 79EF973A
2. anPdetector.dll -> ANSAV PE Heuristic compiler & packer detector
MD5 : 3CC220FBC8FEB3DC2C8A9EB86AA82117
CRC-32 : F4C8CB58
3. an32hk.dll -> ANSAV engine
MD5 : 29E4871D5A0805685B66DDC52FF87A60
CRC-32 : 933AD917
4. agd32.sys -> ANSAV’s driver
MD5 : 341615F888FE257FD50207524D34E923
CRC-32 : C493FFE9
5. ste.dll -> component of ANSAV
MD5 : 76936944243492340697334D6A788386
CRC-32 : 4CE20A3C
6. fixer.fx -> component of ANSAV
MD5 : C3FCAB5566BC33E5C35CE9706B5158FE
CRC-32 : DBEC386C
7. ansav.ini -> configuration of ANSAV (maybe changed hashing MD5 or CRC-32)
8. readme.txt -> readme file for ANSAV (maybe changed hashing MD5 or CRC-32)
9. vdb.dat -> external database of ANSAV (maybe changed hashing MD5 or CRC-32)
10. arc.dll -> ANSAV Archive Format Definition
MD5 : 1C7CF30F2D300082EFD82FEEAE431CB5
CRC-32 : 2BF08077

New Files in ANSAV 2.0
1. cconfig.anv-> configuration language for ANSAV
2. changelog.txt ->log file of ANSAV
3. config.anv -> configuration language for ANSAV
4. dbs.anv ->database of viruses
5. ansavd.exe-> ANSAV guard
6. install.ini-> configuration installed of ANSAV
ANSAV +E Advanced has :
Quarantine Zone-> zone for suspected virus
Trust Zone -> zone will be skip from scanner
Scan Method -> has 3 Level (Hardcore, Medium, Low)
Stealth Mode (ring 3) -> class window will be unknown
Ansav Guard -> Service for Ansav
Archive Scan -> Scanner will scan Archive file or not
AutoUpdate ->update database for Ansav




New in ANSAV 2.0 :
Multi lingual
Secure plug-in management & Unlimited plug-in
Online update or offline
ANSAV Guard stable & responsive
New Engine (Rewrite code with C++)
Error handler Active



ANSAV has many plug-in
Fixerion -> fix file for infected viruses. Kespo (W32/Kspoold, W32/Kspoold.C, W32/Kspoold.D), SangPerawan (W32/VB.Worm.IT), Nebula (W32/VB.Worm.CDW) , FluBurung (W32/Fluburung , W32/FluBurung.B , W32/FluBurung.D , W32/FluBurung.E), Repvblik (VBS/Repvblik), Fujack (W32/WhBoy-2), Maxtrox (W32/Windxp.B , W32/Windxp.C , W32/VB.Worm.CSV , W32/Matrox.C, W32/Matrox.D , W32/Matrox.E) , Trafox (W32/Trafox.Inf , W32/Trafox.DE , W32/Trafox/DE.p) , Srigala (W32/Srigala), BluVenTheXi (W32/VB.Worm.ENM)
The Styler -> change theme for ANSAV interface
Simple Office Recovery -> plug-in will recover document
RegistryFX -> fixing your registry (local setting)
Process Image Finder-> find for processes, kill packed processes , and kill VB process
MalTrack -> known suspected malware with sampled by user
Hidden Revealer -> show file if virus hidden file
DocRestore -> fix doc file for infected viruses.
DeepSlayer ->kill process suspected virus by User
XScriptConsole -> command prompt with available commands :

exit -> exit console
quit -> quit console
echo [text] -> output string in console
set [name],[variable] -> set a global variable defined by name
input [request] -> request user input to $input
sleep [miliseconds] -> delay script execution
loadscript [file] -> load a file script in Scripts folder
readln -> same as pause in batch, press enter to continue
exec [program] -> execute a program with WinExec
execwait [program] -> same as above, but its wait until program finished
restart -> restart the computer
shutdown -> shutdown the computer
fileopen [filename] -> open a file/folder or execute a program defined by filename
filedelete [filename] -> delete a file
filedeletetobin [filename] -> delete the file to recycle bin
fileproperties [filename] -> open explorer file properties
filesize [filename] -> return filesize to $output
filegetcrc32 [filename] - > return file crc32 to $output
processkill [process.exe] -> kill a process by name
processkillvb -> kill all running vb processes
processcreate [filename] -> create process
regreadstring [key],[path],[name] -> read a registry item, output to $output
regreaddword [key],[path],[name] -> read a registry item, output to $output
regwritestring [key],[path],[name],[value] -> write a registry item for string
regwritedword [key],[path],[name],[value] -> write a registry item for integer
regdeletevalue [key],[path],[name] -> delete a registry item
servicestop [service] -> stop a service
servicedisable [service] -> disable service startup
servicedelete [service] -> delete a service

Comparative ANSAV +E Advanced and ANSAV 2.0

Parameter ANSAV +E Advanced ANSAV 2.0
Class window HoneyKissMe,but if Ansav#2194 ,not have stealth mode
stealth mode ->UNKNOWN
Database 933 (9.1.2008) 1081 (3/2/2009 avd-075407.57)
Plug-in Supported Supported, but need trusted by ANSAV
Coded Assembly C++
Updater Available ANSAV donatour public
or ANSAV community member
Archive Scan Supported (ZIP & JAR) Not yet supported
Portable YES,ALWAYS yes
Compress AsPack No

ANSAV An’s AntiVirus
Copyright © 2006-2008 by AnLab Software
e-mail :
anvie_2194@yahoo.com
anvie@ansav.com
website:
http://www.ansav.com
forum:
http://www.ansav.com/forum
download
ANSAV ADVANCED
ANSAV 2.0
Reviewed by Rockess Alpha

1 comment: