Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 03-29-2010, 09:07
ZeNiX's Avatar
ZeNiX ZeNiX is offline
Administrator
 
Join Date: Feb 2009
Posts: 735
Rept. Given: 177
Rept. Rcvd 772 Times in 259 Posts
Thanks Given: 226
Thanks Rcvd at 910 Times in 247 Posts
ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899
How to hide VirtualBox, Virtual PC and VMware from Detection

I use VirtualBox more often then VMWare.
And some times, I use XP Mod from Win7, which claims to be Microsoft Virtual PC.

However, some protectors detect the Virtual Machines.

So, maybe we can collect some tips or tools that can make our Virtual Machines invisible to those protectors.
Reply With Quote
  #2  
Old 03-29-2010, 18:13
metr0 metr0 is offline
Friend
 
Join Date: Apr 2009
Posts: 65
Rept. Given: 19
Rept. Rcvd 11 Times in 5 Posts
Thanks Given: 2
Thanks Rcvd at 2 Times in 2 Posts
metr0 Reputation: 11
These settings (for VMWare VMs) will disable some useful guest integration features but you can remove them at any time if it's not necessary to evade detection anymore.

Taken from some PDF, don't remember the author though. :/

Quote:
isolation.tools.getPtrLocation.disable ="TRUE"
isolation.tools.setPtrLocation.disable ="TRUE"
isolation.tools.setVersion.disable ="TRUE"
isolation.tools.getVersion.disable ="TRUE"
monitor_control.disable_directexec ="TRUE"
monitor_control.disable_chksimd ="TRUE"
monitor_control.disable_ntreloc ="TRUE"
monitor_control.disable_selfmod ="TRUE"
monitor_control.disable_reloc ="TRUE"
monitor_control.disable_btinout ="TRUE"
monitor_control.disable_btmemspace ="TRUE"
monitor_control.disable_btpriv ="TRUE"
monitor_control.disable_btseg ="TRUE"
Reply With Quote
The Following User Gave Reputation+1 to metr0 For This Useful Post:
  #3  
Old 03-29-2010, 18:58
Silkut Silkut is offline
Friend
 
Join Date: Jun 2006
Posts: 24
Rept. Given: 12
Rept. Rcvd 2 Times in 2 Posts
Thanks Given: 1
Thanks Rcvd at 1 Time in 1 Post
Silkut Reputation: 2
Hi,

metr0, I believe the source of those tips are this blog hXXp://vrt-sourcefire.blogspot.com/2009/10/how-does-malware-know-difference.html

I think defeating VM detection goes through suming up all the detection techniques and finding a workaround for each of them.

EvilCry got a C file on his blog, referencing lots of functions to detect emulation/sandbox/virtualization, maybe some ideas to pick up there.

Ed Skoudis also wrote something about VM detection thwarts, for SANS Institute I believe.
Reply With Quote
  #4  
Old 04-08-2010, 10:13
ZeNiX's Avatar
ZeNiX ZeNiX is offline
Administrator
 
Join Date: Feb 2009
Posts: 735
Rept. Given: 177
Rept. Rcvd 772 Times in 259 Posts
Thanks Given: 226
Thanks Rcvd at 910 Times in 247 Posts
ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899
As VirtualBox is my favorite,
I am still looking for a solution for it.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
safeEngine sandboxie and vmware detection wassim_ General Discussion 4 07-14-2018 19:56
Virtual Machine Detection (Themida/WinLicense) Kingstaa General Discussion 1 03-02-2014 17:11
How to Hide Sice and smartcheck from detection? tekhead General Discussion 2 07-13-2003 20:26


All times are GMT +8. The time now is 19:51.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )