鬼圈 发表于 2020-3-7 16:38

一个病毒样本,VM的壳检测到虚拟机怎么处理?

Sorry, this application cannot run under a virtual machine



一个游戏病毒样本,虚拟机已经设置了,还是跑不起来





isolation.tools.getPtrLocation.disable = "TRUE"
isolation.tools.setPtrLocation.disable = "TRUE"
isolation.tools.setVersion.disable = "TRUE"
isolation.tools.getVersion.disable = "TRUE"
monitor_control.disable_directexec = "TRUE"
monitor_control.disable_chksimd = "TRUE"
monitor_control.disable_ntreloc = "TRUE"
monitor_control.disable_selfmod = "TRUE"
monitor_control.disable_reloc = "TRUE"
monitor_control.disable_btinout = "TRUE"
monitor_control.disable_btmemspace = "TRUE"
monitor_control.disable_btpriv = "TRUE"
monitor_control.disable_btseg = "TRUE"
tools.upgrade.policy = "manual"
monitor_control.restrict_backdoor = "TRUE"
usb_xhci:4.present = "TRUE"
usb_xhci:4.deviceType = "hid"
usb_xhci:4.port = "4"
usb_xhci:4.parent = "-1"


下载地址
链接:https://pan.baidu.com/s/1kj9HN81YO3TQTmAri91Oxg
提取码:eulb

52bug 发表于 2020-3-7 23:52

win7真机开影子模式 OR 云电脑{:301_987:}

JOJOpet0 发表于 2020-3-23 10:47

Bitdefender 阻止下载
Trojan.GenericKD.42825117
页: [1]
查看完整版本: 一个病毒样本,VM的壳检测到虚拟机怎么处理?