A forum for reverse engineering, OS internals and malware analysis 

Search found 124 matches: AntiVM

Searched query: antivm

 Go to advanced search

Re: Rogue Antimalware (FakeAV, 2013 year)

 by Xylitol ¦  Tue Oct 08, 2013 8:39 am ¦  Forum: Malware ¦  Topic: Rogue Antimalware (FakeAV, 2013 year) ¦  Replies: 142 ¦  Views: 223040

... GET /info.php?idd=1760 Host: antivm.com --- GET /check?pgid=10 Host: www.antivm.com --- GET /percer.php?login=MTc2MA== HTTP/1.1 Host: www.antivm.com --- GET http://www.antivm.com/shop?abc=cGdpZD0xMCZyPTE3NjA=

Re: VirtualBox Anti-AntiVM

 by DerW_234 ¦  Sat Sep 14, 2013 7:39 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

The update worked for me, so I patched the files. Hope I didn't forget anything (basically it's just string replacements of VBOX, VirtualBox and Oracle). However as stated earlier this will only work for some very basic string detection, so don't relay on just this.

Re: VirtualBox Anti-AntiVM

 by TwinHeadedEagle ¦  Sat Sep 07, 2013 1:56 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Don't know, I updated it succesfully...

Re: VirtualBox Anti-AntiVM

 by EP_X0FF ¦  Sat Sep 07, 2013 11:56 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

MAXS wrote:@EP_XOFF

Are you going to patch latest 4.2.18 release?

The following http://download.virtualbox.org/virtualb ... 80-Win.exe link points to a corrupted file.

Re: VirtualBox Anti-AntiVM

 by TwinHeadedEagle ¦  Fri Sep 06, 2013 9:25 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

@EP_XOFF

Are you going to patch latest 4.2.18 release?

Re: VirtualBox Anti-AntiVM

 by EP_X0FF ¦  Sun Jun 23, 2013 4:00 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Patched dlls for Win64 VirtualBox-4.2.14-86644. Backup original Vbox files and replace with attached. Due to patch digital signature is broken, however it is not important and do not affect Vbox work.

Image

Re: ZeroAccess (alias MaxPlus, Sirefef)

 by EP_X0FF ¦  Mon Jun 10, 2013 3:05 pm ¦  Forum: Malware ¦  Topic: Rootkit ZeroAccess (alias MaxPlus, Sirefef) ¦  Replies: 374 ¦  Views: 333311

... drpC . Before decryption Sirefef performs checking if it running inside virtual environment. If we are using public VM's we need to disable antiVM to continue. VMWare antiVM. .00402DE9: 6A0C push 00C .00402DEB: 6800F04200 push 00042F000 --↓1 .00402DF0: E843000000 call .000402E38 --↓2 .00402DF5: ...

Re: Rogue Antimalware (FakeAV, 2013 year)

 by EP_X0FF ¦  Sun Jun 02, 2013 11:06 am ¦  Forum: Malware ¦  Topic: Rogue Antimalware (FakeAV, 2013 year) ¦  Replies: 142 ¦  Views: 223040

... Win32/Daurso JS/Redirector.XX Win32/Dorkbot.A Win32/Ramnit.X Win32/Zwangi Win32/Ifnapod.X In attach original dropper and unpacked patched (removed AntiVM) version.

Re: VirtualBox Anti-AntiVM

 by EP_X0FF ¦  Sun Apr 14, 2013 3:58 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Thanks for update. It is all very cool but only good for primitive malware. VirtualBox (anyhow moded) can be detected in a few lines of primitive code. This information is not zeroday, it is used in some top class commercial protection software and it is up to Oracle to patch this. 1. Register top l...

Re: VirtualBox Anti-AntiVM

 by DerW_234 ¦  Sat Apr 13, 2013 1:05 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214167

Patched DLLs for v4.2.12 (x64) in attach.
I tried to stick to the changes EP_X0FF did, so the signature is broken once again, but the files are working.

  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 13