A forum for reverse engineering, OS internals and malware analysis 

Search found 124 matches: AntiVM

Searched query: antivm

 Go to advanced search

Re: VirtualBox Anti-AntiVM

 by DerW_234 ¦  Sun Dec 29, 2013 12:05 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Happy new year everyone :).

I attached the patched DLLs for the latest VirtualBox version (4.3.6-91406).

PS: Does anybody know of a good hex editor that supports regular expression search? Would make the process a little faster.

Re: VirtualBox Anti-AntiVM

 by feryno ¦  Mon Dec 09, 2013 12:09 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Wrong instruction after single-step exception with 'rdtsc' and 'cpuid' It seems there is (at least) one lazy programmer in the VirtualBox team - just forgot to generate #DB after emulating these instructions in VBox hypervisor vm exit handler. I would say it is more laziness than a bug. I just wond...

Re: VirtualBox Anti-AntiVM

 by EP_X0FF ¦  Sat Dec 07, 2013 3:41 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Hello. Important fix for everyone who use VBox for malware research. Bug described here http://www.kernelmode.info/forum/viewtopic.php?p=18930#p18930 Wrong instruction after single-step exception with 'rdtsc' and 'cpuid' https://www.virtualbox.org/ticket/10947 Assume vmprotect author should do anot...

Re: VirtualBox Anti-AntiVM

 by DerW_234 ¦  Sun Dec 01, 2013 11:39 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Hello rin,

thanks for the heads up :).
I've attached the new patched DLLs for this version.

Re: VirtualBox Anti-AntiVM

 by rinn ¦  Sun Dec 01, 2013 9:26 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Hello. Important fix for everyone who use VBox for malware research. Bug described here http://www.kernelmode.info/forum/viewtopic.php?p=18930#p18930 Wrong instruction after single-step exception with 'rdtsc' and 'cpuid' https://www.virtualbox.org/ticket/10947 Assume vmprotect author should do anoth...

Re: VirtualBox Anti-AntiVM

 by bitstechs ¦  Mon Nov 18, 2013 7:03 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

I just wanted to thank you guys so much for this information. Upon creating a new virtual box vm I realized that I was unable to open some malware/viruses, more specifically Antivirus Security Pro. Then, I ran across this thread and after doing some research and applying these settings and dll's I s...

Re: VirtualBox Anti-AntiVM

 by DerW_234 ¦  Sun Nov 10, 2013 9:44 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Update for the new 4.3.2 version.

Re: Rogue Antimalware (FakeAV, 2013 year)

 by grum ¦  Mon Oct 28, 2013 1:32 pm ¦  Forum: Malware ¦  Topic: Rogue Antimalware (FakeAV, 2013 year) ¦  Replies: 142 ¦  Views: 223040

... GET /info.php?idd=1760 Host: antivm.com --- GET /check?pgid=10 Host: www.antivm.com --- GET /percer.php?login=MTc2MA== HTTP/1.1 Host: www.antivm.com --- GET http://www.antivm.com/shop?abc=cGdpZD0xMCZyPTE3NjA= ...

Re: VirtualBox Anti-AntiVM

 by DerW_234 ¦  Sun Oct 20, 2013 10:16 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Here you go :) I noticed that in one of my VMs old values were still saved from before I applied this: http://www.kernelmode.info/forum/viewtopic.php?p=16102#p16102, so if you want to make sure it worked, search your registry for VBox, VirtualBox etc. the keys might need to be deleted from user SYST...

Re: VirtualBox Anti-AntiVM

 by Tigzy ¦  Fri Oct 18, 2013 6:26 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Hey, there's the new version 4.3
Someone for patching the DLLs ? :)

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 13