Scan
On-demand file and folder scans through ClamAV and YARA, run by the service — not the app window, so results outlive a closed UI.
StartScan / GetJobDetailMalzox scans with real ClamAV and YARA engines through an authenticated native Windows service. No inflated detection claims, no silent background monitoring you weren't told about.
No roadmap slides. Every card below runs against the real native service, the same one that ships in this build.
On-demand file and folder scans through ClamAV and YARA, run by the service — not the app window, so results outlive a closed UI.
StartScan / GetJobDetailMalware moves into a DPAPI-sealed vault — automatically for real-time and USB detections. Restore never overwrites an existing file.
QuarantineItem / RestoreItemDaily, weekly or monthly scans fire from the service's own scheduler thread — they still run even if Malzox isn't open.
SetScheduleA durable, bounded audit log of every scan and quarantine action — exportable, and kept by the service, not a UI-side guess.
ListEvents / ExportEventsEach status in Malzox comes from a fresh report by the service. If something is off, the app says so — it never shows a green tick it can't back up.
HomeScanProtectionFirewallQuarantineActivity
Every module says what it covers and what happens when it trips. Each one is switched on or off in Settings, with no restart.
Block or allow an app's network access, or whole IP addresses and ranges, through the Windows Filtering Platform.
New or changed files in your Downloads folder are scanned with ClamAV and YARA about two seconds after they land.
Watches for a burst of file changes: 40 files rewritten, or 10 extensions renamed, within 10 seconds.
A flash drive, SD card or USB hard disk is scanned with ClamAV as soon as it's plugged in.
Paste a link before you open it. Malzox checks it against your own blocklist and flags raw IP addresses and international lookalike names.
Reads every process start from Windows' kernel events and checks four patterns: Office opening a shell, encoded PowerShell, shadow-copy deletion and download tools fetching files.
The interface you click around in never touches your files directly. It asks a separate, native Windows service to do it — over a connection that has to prove who's asking.
The window you see only displays results and sends requests. It holds no special rights and never opens your files itself.
Every command that changes something is HMAC-SHA256 signed with a per-install secret, timestamped against replay, and checked against the caller's identity.
A Rust service owns the engines, the vault and every monitor, keeps running when the window closes, and stores its data where only SYSTEM and administrators can write.
No cheap first year that doubles at renewal. Every paid plan includes all protection modules, and every install starts with 30 days of the full product to try.
The essentials, for checking files yourself.
Full protection for 1 PC.
Everything in Solo on up to 5 PCs — €7 per PC.
For freelancers and small offices, up to 10 PCs.
For companies with more than 10 PCs.
Prices include VAT. Planned prices for the first signed release; the waitlist hears first.
Antivirus marketing tends to round up. Ours doesn't. This is the same status the app itself reports.
Malzox isn't packaged for general download yet — there's no signed installer to hand out safely. Leave your email and we'll tell you the moment there is one.
We use your address only to tell you when a signed build is ready, and delete it on request. Privacy policy