Air14 / HyperHide

Hypervisor based anti anti debug plugin for x64dbg
MIT License
1.28k stars 296 forks source link

vmp3.5 "Virtual Machine" #16

Closed nblog closed 3 years ago

nblog commented 3 years ago

image

vmprotect v3.5.0, any program will prompt as long as virtual machine detection is enabled. HyperHide->(√)Hypervisor not visible

Air14 commented 3 years ago

vmprotect uses rdtsc time attacks which my hv is vulnerable to. And "Hypervisor not visible" option just tells hv to don't expose itself via cpuid

nblog commented 3 years ago

uses "eflags exception" + "seh" check

image

Test Examples.zip