A forum for reverse engineering, OS internals and malware analysis 

Search found 124 matches: AntiVM

Searched query: antivm

 Go to advanced search

Re: VirtualBox Anti-AntiVM

 by DerW_234 ¦  Mon Apr 01, 2013 8:50 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214169

Try comparing the dlls with the originals in a decent hex editor and you'll see the differences. Easy enough to replicate for the 32 bit versions, since it's all just string changes (great idea nevertheless, saved me a lot of trouble :)).

Re: VirtualBox Anti-AntiVM

 by myodyne ¦  Sun Mar 31, 2013 11:50 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214169

EP_X0FF wrote:
MAXS wrote:Someone has patches for x86 version of VBox...
fc to find difference with original files and hexeditor to do the same for 32 bit dlls.

No plans for patching x86 dlls as we don't use 32 bit VBox.
It would be nice to have these for educational purposes.
It would be piece of cake for you.

Re: VirtualBox Anti-AntiVM

 by myodyne ¦  Sun Mar 31, 2013 11:40 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214169

EP_X0FF wrote:Patched dlls for Win64 VirtualBox-4.2.10-84105. Backup original Vbox files and replace with attached. Due to patch digital signature is broken, however it is not important and do not affect Vbox work.
Thanks a lot...

Re: VirtualBox Anti-AntiVM

 by EP_X0FF ¦  Mon Mar 25, 2013 4:58 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214169

Patched dlls for Win64 VirtualBox-4.2.10-84105. Backup original Vbox files and replace with attached. Due to patch digital signature is broken, however it is not important and do not affect Vbox work.

Re: Backdoor Andromeda (alias Gamarue)

 by aaSSfxxx ¦  Wed Mar 20, 2013 7:00 pm ¦  Forum: Malware ¦  Topic: Backdoor Andromeda (waahoo, alias Gamarue) ¦  Replies: 129 ¦  Views: 198776

... variant "I". In this thread mostly attached "F" variant. Analyze code, not how and where it connects. Usual Andromeda encrypted strings related to AntiVM/SandboxIE. Ќ…ЊюяяPяuґяUр…А…pяяяяuґяUмhdll hdll.hsbie‹ДPяUьѓД…А…© З…|юяя j h.dllhpi32hadva‹ДPяUи‰EАѓД…А„Y hѕ<л‡яuАимъяя‰EФ…А„A hG1ћяuАиФъяя‰EР…А„) ...

Re: Backdoor Andromeda (alias Gamarue)

 by EP_X0FF ¦  Wed Mar 13, 2013 1:15 am ¦  Forum: Malware ¦  Topic: Backdoor Andromeda (waahoo, alias Gamarue) ¦  Replies: 129 ¦  Views: 198776

... variant "I". In this thread mostly attached "F" variant. Analyze code, not how and where it connects. Usual Andromeda encrypted strings related to AntiVM/SandboxIE. Ќ…ЊюяяPяuґяUр…А…pяяяяuґяUмhdll hdll.hsbie‹ДPяUьѓД…А…© З…|юяя j h.dllhpi32hadva‹ДPяUи‰EАѓД…А„Y hѕ<л‡яuАимъяя‰EФ…А„A hG1ћяuАиФъяя‰EР…А„) ...

Re: Conficker under virtual machine

 by Horgh ¦  Wed Feb 27, 2013 11:39 pm ¦  Forum: Malware ¦  Topic: Win32/Conficker ¦  Replies: 27 ¦  Views: 50037

I downloaded 10 samples and none works...
Maybe debug them and patch the antivm stuff ?

Re: Vmware Anti-AntiVM

 by TwinHeadedEagle ¦  Fri Feb 22, 2013 9:06 pm ¦  Forum: Tools/Software ¦  Topic: Vmware Anti-AntiVM ¦  Replies: 4 ¦  Views: 8218

Decide what you want - reversing/researching malware or playing in comfortable homemade/twitter virus analyst. VM (Vbox, Vmware etc) is just a emulation environment, anything else (usb support, additions, d3d support and rest of the crap) is not important. I have no idea what kind of bugs you exper...

Re: VirtualBox Anti-AntiVM

 by TwinHeadedEagle ¦  Fri Feb 22, 2013 9:01 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214169

I solved the problem, now USB in Repair mode is working... :mrgreen:

Only thing that has to be installed is Extension Pack for VirtualBox :lol:

Re: Vmware Anti-AntiVM

 by EP_X0FF ¦  Fri Feb 22, 2013 3:56 pm ¦  Forum: Tools/Software ¦  Topic: Vmware Anti-AntiVM ¦  Replies: 4 ¦  Views: 8218

Decide what you want - reversing/researching malware or playing in comfortable homemade/twitter virus analyst. VM (Vbox, Vmware etc) is just a emulation environment, anything else (usb support, additions, d3d support and rest of the crap) is not important. I have no idea what kind of bugs you experi...

  • 1
  • 4
  • 5
  • 6
  • 7
  • 8
  • 13