Rurik / Noriben

Noriben - Portable, Simple, Malware Analysis Sandbox
Other
1.12k stars 222 forks source link

Procmon needs permisison to "make changes on this computer" #27

Closed malwarehuntingisfun closed 4 years ago

malwarehuntingisfun commented 5 years ago

Screen Shot 2019-03-24 at 5 20 44 PM

After the file is sent to the virtual machine Windows requires the user to accept "yes" for procmon to initiate. I tried going to "User account control settings” and selecting "never" notify, but that does not resolve the issue. Any thoughts?

Rurik commented 5 years ago

Apologies for the delay. This is something that I won't have control over changing, nor something that I've seen locally. Disabling UAC should fix this and I'm not sure why it isn't.

Does your local user have admin privileges?