Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 05-13-2015, 00:02
te$ter te$ter is offline
Friend
 
Join Date: Feb 2013
Posts: 63
Rept. Given: 23
Rept. Rcvd 6 Times in 5 Posts
Thanks Given: 20
Thanks Rcvd at 25 Times in 12 Posts
te$ter Reputation: 6
Question How to disable VM detection?

Is there any way to disable (pass) Virtual Machine detection?
Code:
This application cannot run in Virtual Machine
Reply With Quote
  #2  
Old 05-13-2015, 00:15
Storm Shadow's Avatar
Storm Shadow Storm Shadow is offline
Family
 
Join Date: Jun 2014
Posts: 281
Rept. Given: 186
Rept. Rcvd 191 Times in 78 Posts
Thanks Given: 138
Thanks Rcvd at 245 Times in 97 Posts
Storm Shadow Reputation: 100-199 Storm Shadow Reputation: 100-199
you can try using x64dbg and using yara plugin, to see if the file contains some of the rules for vm detection.
https://github.com/Yara-Rules/rules/blob/master/antidebug.yar#L400

but there proberly are, more easyer and faster boring ways
__________________
The devil whispered in my ear, "you're not strong enough to withstand the storm."

Today I whispered in the devils ear, "I am the storm."
Reply With Quote
  #3  
Old 05-13-2015, 00:54
Conquest Conquest is offline
Friend
 
Join Date: Jan 2013
Location: 0x484F4D45
Posts: 125
Rept. Given: 46
Rept. Rcvd 29 Times in 17 Posts
Thanks Given: 31
Thanks Rcvd at 60 Times in 29 Posts
Conquest Reputation: 29
you didnt mention the protector name or type. usually the vmware backdoor restriction along with a few registry edits should work.A fast google search result yields
hxxp://www.unibia.com/unibianet/systems-networking/bypassing-virtual-machine-detection-vmware-workstation

there is a great thread about it for vbox linked in our forum.
http://forum.exetools.com/showthread.php?t=16681
unfortunately i am not aware of any detection method in type1 hypervisors.
Reply With Quote
The Following User Says Thank You to Conquest For This Useful Post:
te$ter (05-16-2015)
  #4  
Old 05-16-2015, 17:06
te$ter te$ter is offline
Friend
 
Join Date: Feb 2013
Posts: 63
Rept. Given: 23
Rept. Rcvd 6 Times in 5 Posts
Thanks Given: 20
Thanks Rcvd at 25 Times in 12 Posts
te$ter Reputation: 6
The solution for VMWare is OK for testing software even without changing HDD name in register.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows Update Disable and Enable mdj General Discussion 0 03-05-2018 23:45
CTRL + ALT + DEL Disable TmC General Discussion 20 09-06-2013 19:52
Why?the kb is disable 3boy General Discussion 1 09-03-2003 20:22


All times are GMT +8. The time now is 07:35.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )