A forum for reverse engineering, OS internals and malware analysis 

Search found 124 matches: AntiVM

Searched query: antivm

 Go to advanced search

Best Malware Protection My Effort to make him work

 by FakeAVHunter ¦  Sun Sep 23, 2018 4:11 pm ¦  Forum: Malware ¦  Topic: Best Malware Protection My Effort to make him work ¦  Replies: 0 ¦  Views: 2062

... IN BACKGROUND PROCESS https://i.imgur.com/Lks8wKI.png I Learned a lesson about this fakevimes threat.He refuse to be runned on virtual machine antivm So he like to be runned on my host pc and i dont care i can remove this with MBAM OR Remove manually https://i.imgur.com/67mxyTb.png I Dont like ...

About me : FakeAVHunter

 by FakeAVHunter ¦  Sun Feb 04, 2018 10:55 am ¦  Forum: General Discussion ¦  Topic: About me : FakeAVHunter ¦  Replies: 1 ¦  Views: 4166

... archives.The Rogue Antimalware 2018 year comming soon. Any Broken/Crashed fakeav that i find will be unpacked / dumped / or fixed vm vmware vbox antivm First i readed the rules from this site so this forum is very nice :)

Re: FF Userkit .net malware

 by EP_X0FF ¦  Wed Apr 06, 2016 6:55 am ¦  Forum: Malware ¦  Topic: MSIL/SantaClaus (CoinStealer) ¦  Replies: 6 ¦  Views: 7563

It is BTC Stealer from idiot with username "Santa Claus" dropper -> dotnet RunPE with primitive antiVM -> fake messagebox -> 2nd stage dotnet dropper -> dotnet Payload (https://www.virustotal.com/en/file/22e6f18ee2c807c2585a4d53b94a96bd2a202d59e78d0ba2ee91132529c1ef59/analysis/) ...

Re: Win32/Kasidet (Alias Neutrino bot)

 by EP_X0FF ¦  Mon Jul 20, 2015 6:39 pm ¦  Forum: Malware ¦  Topic: Win32/Kasidet (Alias Neutrino bot) ¦  Replies: 6 ¦  Views: 16917

... установленного АВ ( на всех ОС Windows кроме серверных ) * Обновление * Работа через прокладки - Дополнительные функции * Антиотладка * AntiVM * Детект песочниц * Детект всех онлайн сервисов автоматического анализа * BotKiller * Защита бота ( защита процесса\файла\веток реестра ) * Неограниченное ...

Re: Update 01 Apr 2015, EFI video driver patched.

 by JonnyDee ¦  Sun Apr 26, 2015 9:58 pm ¦  Forum: Tools/Software ¦  Topic: VBoxAntiVMDetectHardened mitigation X64 only ¦  Replies: 249 ¦  Views: 1757811

VirtualBox EFI video driver patched. Now you can install UEFI compatible OS'es using AntiVM detection patch without problems with video (e.g. black screen during install, or when already installed VM accessible only via RDP). If you plan to use EFI based VM's: 1) ...

Update 01 Apr 2015, EFI video driver patched.

 by EP_X0FF ¦  Wed Apr 01, 2015 4:16 pm ¦  Forum: Tools/Software ¦  Topic: VBoxAntiVMDetectHardened mitigation X64 only ¦  Replies: 249 ¦  Views: 1757811

VirtualBox EFI video driver patched. Now you can install UEFI compatible OS'es using AntiVM detection patch without problems with video (e.g. black screen during install, or when already installed VM accessible only via RDP). If you plan to use EFI based VM's: 1) ...

WinNT/Pitou (MBR bootkit, alias Backboot)

 by EP_X0FF ¦  Fri Jan 02, 2015 12:52 pm ¦  Forum: Malware ¦  Topic: WinNT/Pitou (MBR bootkit, alias Backboot) ¦  Replies: 6 ¦  Views: 14749

... Hooks IRP_MJ_DEVICE_CONTROL and IRP_MJ_INTERNAL_DEVICE_CONTROL for the disk port driver and several routines in NDIS driver by splicing. Contain antiVM similar to Win32/Avatar lolkit -> MmMapIoSpace and lookup for known VM vendors/products names. http://i57.tinypic.com/34spf6h.jpg Source: 31.184.236.83/crypted.ff.exe ...

Re: Automated Malware Environments

 by frank_boldewin ¦  Sat Dec 13, 2014 4:42 pm ¦  Forum: Malware ¦  Topic: Automated Malware Environments ¦  Replies: 12 ¦  Views: 10678

... which will integrate in the master branch in the near future. Another plugin is zer0m0n from conix-security which supports kernel hooks and some antivm stuff. And yes, you need to buy your own windows licenses.

Re: WinNT/Phase - fileless trojan

 by EP_X0FF ¦  Wed Dec 10, 2014 5:09 am ¦  Forum: Malware ¦  Topic: WinNT/Phase - fileless trojan ¦  Replies: 28 ¦  Views: 28706

Just curious, but how does it detect QEMU? They did nothing new. AntiVM similar to that Andromeda has. There are 4 antivm methods found inside, maybe missed something (anyway none of them worked and will not work with properly configured vm): 1) SYSTEM\ControlSet001\Services\Disk\Enum ...

Re: Unknown to me

 by EP_X0FF ¦  Mon Sep 15, 2014 4:58 am ¦  Forum: Malware ¦  Topic: Win32/Kuluoz ¦  Replies: 37 ¦  Views: 59767

... PW = infected Trojan downloader Kuluoz with antivm, in attach unpacked. https://www.virustotal.com/en/file/efa7ebe7a9541663a876a643fcb123fbfb56f617dba9431bd6f36c564dff4c56/analysis/1410756972/ ...

  • 1
  • 2
  • 3
  • 4
  • 5
  • 13