![]() |
|
#1
|
||||
|
||||
|
How to hide VirtualBox, Virtual PC and VMware from Detection
I use VirtualBox more often then VMWare.
And some times, I use XP Mod from Win7, which claims to be Microsoft Virtual PC. However, some protectors detect the Virtual Machines. So, maybe we can collect some tips or tools that can make our Virtual Machines invisible to those protectors. |
|
#2
|
|||
|
|||
|
These settings (for VMWare VMs) will disable some useful guest integration features but you can remove them at any time if it's not necessary to evade detection anymore.
Taken from some PDF, don't remember the author though. :/ Quote:
|
| The Following User Gave Reputation+1 to metr0 For This Useful Post: | ||
|
#3
|
|||
|
|||
|
Hi,
metr0, I believe the source of those tips are this blog hXXp://vrt-sourcefire.blogspot.com/2009/10/how-does-malware-know-difference.html I think defeating VM detection goes through suming up all the detection techniques and finding a workaround for each of them. EvilCry got a C file on his blog, referencing lots of functions to detect emulation/sandbox/virtualization, maybe some ideas to pick up there. Ed Skoudis also wrote something about VM detection thwarts, for SANS Institute I believe. |
|
#4
|
||||
|
||||
|
As VirtualBox is my favorite,
I am still looking for a solution for it. |
![]() |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| safeEngine sandboxie and vmware detection | wassim_ | General Discussion | 4 | 07-14-2018 19:56 |
| Virtual Machine Detection (Themida/WinLicense) | Kingstaa | General Discussion | 1 | 03-02-2014 17:11 |
| How to Hide Sice and smartcheck from detection? | tekhead | General Discussion | 2 | 07-13-2003 20:26 |