DEVELOPMENT BUILD · EVERY FEATURE STATES ITS LIMITS

Antivirus software that tells you exactly what it's checking — and what it isn't.

Malzox scans with real ClamAV and YARA engines through an authenticated native Windows service. No inflated detection claims, no silent background monitoring you weren't told about.

2
real scan engines
6
protection modules
0
inflated claims
Real enginesClamAV 1.5.4 + YARA-X
Encrypted vaultWindows DPAPI, machine scope
Authenticated IPCHMAC-signed, replay-protected
Built in the openevery claim is a tested claim
Product

Four core tools, all run by the service

No roadmap slides. Every card below runs against the real native service, the same one that ships in this build.

Scan

On-demand file and folder scans through ClamAV and YARA, run by the service — not the app window, so results outlive a closed UI.

StartScan / GetJobDetail

Quarantine

Malware moves into a DPAPI-sealed vault — automatically for real-time and USB detections. Restore never overwrites an existing file.

QuarantineItem / RestoreItem

Schedule

Daily, weekly or monthly scans fire from the service's own scheduler thread — they still run even if Malzox isn't open.

SetSchedule

Activity

A durable, bounded audit log of every scan and quarantine action — exportable, and kept by the service, not a UI-side guess.

ListEvents / ExportEvents
The app

One calm window. Every answer with its evidence.

Each status in Malzox comes from a fresh report by the service. If something is off, the app says so — it never shows a green tick it can't back up.

  • Protection states that show their evidence and their age
  • Alerts explain what was seen, where, and what was done
  • Threats go to an encrypted vault, one click to restore
  • Light and dark themes, simple and advanced modes
Malzox
HomeScanProtectionFirewallQuarantineActivity
CURRENT PROTECTION STATE Protected Service connected · report 4 s old
Real-timeWatching
RansomwareWatching
SignaturesToday
Quarantined automaticallyDownloads\invoice_final.exe · Win.Trojan.Agent
Restore
Protection

Six protection modules, each labelled with what it won't do

Every module says what it covers and what happens when it trips. Each one is switched on or off in Settings, with no restart.

Enforced

Firewall

Block or allow an app's network access, or whole IP addresses and ranges, through the Windows Filtering Platform.

Covers
Apps and IP addresses
Action
Blocks the connections
Not yet
Port and protocol rules
Auto-quarantine

Real-time file scanning

New or changed files in your Downloads folder are scanned with ClamAV and YARA about two seconds after they land.

Covers
Downloads folder, top level
Action
Moves malware to quarantine
Not yet
Blocking a file before it opens
Alert only

Ransomware alerts

Watches for a burst of file changes: 40 files rewritten, or 10 extensions renamed, within 10 seconds.

Covers
Documents, Desktop, Pictures
Action
Logs an alert; nothing is stopped
Not yet
Naming or stopping the process
Auto-quarantine

USB drive scanning

A flash drive, SD card or USB hard disk is scanned with ClamAV as soon as it's plugged in.

Covers
Flash drives, SD cards, USB disks
Action
Moves malware to quarantine
Not yet
Blocking or ejecting the drive
On demand

Link checker

Paste a link before you open it. Malzox checks it against your own blocklist and flags raw IP addresses and international lookalike names.

Covers
Links you paste in
Action
Shows a verdict; blocks nothing
Not yet
Protection while you browse
Alert only

Behavior alerts

Reads every process start from Windows' kernel events and checks four patterns: Office opening a shell, encoded PowerShell, shadow-copy deletion and download tools fetching files.

Covers
Every new process
Action
Logs an alert; nothing is stopped
Not yet
Ending or suspending a process
Enforced acts on its own Alert only tells you, takes no action On demand runs when you ask
How it works

A privileged service, not a privileged app window

The interface you click around in never touches your files directly. It asks a separate, native Windows service to do it — over a connection that has to prove who's asking.

  1. 01

    The app asks

    The window you see only displays results and sends requests. It holds no special rights and never opens your files itself.

  2. 02

    The request proves itself

    Every command that changes something is HMAC-SHA256 signed with a per-install secret, timestamped against replay, and checked against the caller's identity.

  3. 03

    The service acts

    A Rust service owns the engines, the vault and every monitor, keeps running when the window closes, and stores its data where only SYSTEM and administrators can write.

Plans

One price, every year.

No cheap first year that doubles at renewal. Every paid plan includes all protection modules, and every install starts with 30 days of the full product to try.

Spark
€0forever

The essentials, for checking files yourself.

  • On-demand scans with ClamAV + YARA
  • Encrypted quarantine and restore
  • Scheduled scans and activity log
  • Automatic signature updates
  • Link checker
Get notified
Solo
€19.99/ year

Full protection for 1 PC.

  • Everything in Spark
  • Real-time scanning with auto-quarantine
  • USB scanning, incl. USB hard disks
  • Ransomware and behavior alerts
  • Firewall rules for apps and IPs
Get notified
Best value
Household
€34.99/ year

Everything in Solo on up to 5 PCs — €7 per PC.

  • All protection modules on every PC
  • One license key for the whole home
  • Move a license between PCs yourself
  • Security page and Windows notifications
Get notified
Studio
€119/ year

For freelancers and small offices, up to 10 PCs.

  • Everything in Household
  • Up to 10 PCs on one license
  • Invoice with VAT for your business
  • Priority email support
Get notified
Fleet
Customon request

For companies with more than 10 PCs.

  • Volume pricing per PC
  • Help rolling Malzox out to your PCs
  • Pay by invoice or bank transfer
  • A named contact for your team
Ask for a quote

Prices include VAT. Planned prices for the first signed release; the waitlist hears first.

Development status

What's real, what isn't — plainly

Antivirus marketing tends to round up. Ours doesn't. This is the same status the app itself reports.

On-demand scanning — ClamAV + YARA
Real engines, real signature verification
Shipping
Encrypted quarantine & scheduling
DPAPI machine-scope vault, service-owned scheduler
Shipping
Automatic signature updates
Every 6 hours, verified and test-loaded before use
Shipping
Firewall
Block or allow an app's traffic, or IP addresses and ranges
Shipping
Real-time file scanning
Downloads folder; malware is quarantined automatically right after it lands
Auto-quarantine
Ransomware alerts
Burst detection in Documents, Desktop and Pictures
Alert only
USB drive scanning
Flash drives, SD cards and USB hard disks; malware is quarantined automatically
Auto-quarantine
Link checker
Your own blocklist plus address checks, for links you paste in
On demand
Behavior alerts
Four rules on kernel process-start events
Alert only
Stopping threats before they run
Blocking files and processes needs a signed kernel driver; website blocking isn't built either
Not built yet
Independent security review
An internal review's findings are fixed; a third-party audit comes before general release
Not started
Early access

Get Malzox when it's ready

Malzox isn't packaged for general download yet — there's no signed installer to hand out safely. Leave your email and we'll tell you the moment there is one.

We use your address only to tell you when a signed build is ready, and delete it on request. Privacy policy

Almost done: check your inbox and click the confirmation link. Nothing is sent until you confirm.