Closed chenbowen9706 closed 1 year ago
used al-hasker to got this dectected info: [] Checking Local Descriptor Table location [ BAD ] [] Checking power capabilities [ BAD ] [] Checking CPU fan using WMI [ BAD ] [] Checking Win32_CacheMemory with WMI [ BAD ] [] Checking Win32_MemoryDevice with WMI [ BAD ] [] Checking Win32_VoltageProbe with WMI [ BAD ] [] Checking Win32_PortConnector with WMI [ BAD ] [] Checking ThermalZoneInfo performance counters with WMI [ BAD ] [] Checking CIM_Memory with WMI [ BAD ] [] Checking CIM_Sensor with WMI [ BAD ] [] Checking CIM_NumericSensor with WMI [ BAD ] [] Checking CIM_TemperatureSensor with WMI [ BAD ] [] Checking CIM_VoltageSensor with WMI [ BAD ] [] Checking CIM_PhysicalConnector with WMI [ BAD ] [] Checking CIM_Slot with WMI [ BAD ] [] Checking for Hyper-V global objects [ BAD ]
exclude wmi check still got this:
[] Checking Local Descriptor Table location [ BAD ]
[] Checking power capabilities [ BAD ]
[*] Checking for Hyper-V global objects [ BAD ]
can you give a simple exe(VMP exe)
works fine here, please check your vm config:
<domain xmlns:qemu="http://libvirt.org/schemas/domain/qemu/1.0" type="kvm">
...
<qemu:commandline>
<qemu:arg value="-smbios"/>
<qemu:arg value="type=0,version=UX305UA.201"/>
<qemu:arg value="-smbios"/>
<qemu:arg value="type=1,manufacturer=ASUS,product=UX305UA,version=2021.1"/>
<qemu:arg value="-smbios"/>
<qemu:arg value="type=2,manufacturer=Intel,version=2021.5,product=Intel i9-12900K"/>
<qemu:arg value="-smbios"/>
<qemu:arg value="type=3,manufacturer=XBZJ"/>
<qemu:arg value="-smbios"/>
<qemu:arg value="type=17,manufacturer=KINGSTON,loc_pfx=DDR5,speed=4800,serial=000000,part=0000"/>
<qemu:arg value="-smbios"/>
<qemu:arg value="type=4,manufacturer=Intel,max-speed=4800,current-speed=4800"/>
<qemu:arg value="-cpu"/>
<qemu:arg value="host,family=6,model=158,stepping=2,model_id=Intel(R) Core(TM) i9-12900K CPU @ 2.60GHz,vmware-cpuid-freq=false,enforce=false,host-phys-bits=true,hypervisor=off"/>
<qemu:arg value="-machine"/>
<qemu:arg value="q35,kernel_irqchip=on"/>
</qemu:commandline>
</domain>
i think we use the same exe file packed with vmp protect
`
can I check your qemu xml fie?
i had upload before
i had upload before
I didn't see your xml config file ,are you using the command to start qemu?
add follows to your qemu args:
-cpu host,-hypervisor,kvm=off,hv_vendor_id='MiHoYo',vmware-cpuid-freq=false,enforce=false,host-phys-bits=true -smbios type=0,version=UX305UA.201 -smbios type=2,manufacturer=Intel,version=2021.5,product='MiHoYoSuperX' -smbios type=3,manufacturer=MiHoYo -smbios type=17,manufacturer=MiHoYo,loc_pfx=DDR5,speed=4800,serial=114514,part=1145 -smbios type=4,manufacturer=Intel,max-speed=4800,current-speed=4800 -acpitable oem_id=mhy,oem_table_id=mihoyo,asl_compiler_id=ASUS,asl_compiler_rev=114514,oem_rev=191981
actually im just copy your xml into my libvirt and just add some dev
actually im just copy your xml into my libvirt and just add some dev
run the command:
ps -ax | grep qemu
I want to see your process 's args
please click "Attach files by dragging & dropping, selecting or pasting them." to upload file
take a screenshot this
the network and disk is passthrou with pci
I think my "al-khaser.exe" is different to you ,can you upload here?
al-khaser.zip or you test it and report
KHASER.zip THIS IS MINE
pafish64 log:
“ [] Delay value is set to 10 minutes ... [] Performing a sleep using NtDelayExecution ... ” i think u should change 10 minute wait to 1 haha.. and this is my log which used your [al-khaser.zip] k-haser-log.txt
run the
ps -ax | grep qemu
on your host machine, and report
ok, then , upload /usr/bin/qemu-system-x86_64
here
i had used 8.0.2 and 7.0.0 they are both dectected with vmp3.x
can you remove your rdtsc ? I know vmp didn't detect it.
yea i will reboot and do it wait me a few minute
did you enable hyper-v on your windows? if it is yes ,please close it
disable hyper-v
okay it works now when i dont patch rdtsc clock ,i will close the issu soon, can u send me your qq or wechat? i want to do more communication with you
q1619180854
after patch qemu7.0.0 and complie it and fix some rdtsc attacks my guest windows still got dectected with vmp3.2+ version