Welcome, Guest
Please Login or Register.    Lost Password?
Go to bottomPage: 12345
TOPIC: Бан.
#51963
Бан. 7 Years, 9 Months ago Karma: 0
Со старыми виртуалками можно распрощаться и готовить новые? Кто что посоветует?
catah4uk
Fresh Boarder
Posts: 24
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#51981
Бан. 7 Years, 9 Months ago Karma: 2
catah4uk писал(а):
Со старыми виртуалками можно распрощаться и готовить новые? Кто что посоветует?
Советую не испытывать судьбу и всё делать с чистого листа.
redhat
Fresh Boarder
Posts: 27
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#51989
Бан. 7 Years, 9 Months ago Karma: 8
заинтриговала тема, решил проверить свою вм, получил такой результат)) буду пробывать латать

Code:

Start 
CPU: GenuineIntel (HV: VMwareVMware) Intel(R) Core(TM) i5-4670 CPU @ 3.40GHz
CPU VM traced by checking the difference between CPU timestamp counters (rdtsc) forcing VM exit
CPU VM traced by checking hypervisor bit in cpuid feature bits
CPU VM traced by checking cpuid hypervisor vendor for known VM vendors
Sandbox traced using mouse activity
Sandbox traced by checking disk size <= 60GB via DeviceIoControl()
Sandbox traced by checking disk size <= 60GB via GetDiskFreeSpaceExA()
Sandbox traced by checking if NumberOfProcessors is less than 2 via raw access
Sandbox traced by checking if NumberOfProcessors is less than 2 via GetSystemInfo()
VMWare traced using Reg key HKLM\HARDWARE\DEVICEMAP\Scsi\Scsi Port 0,1,2\Scsi Bus 0\Target Id 0\Logical Unit Id 0 "Identifier"
VMware traced using Reg key HKLM\SOFTWARE\VMware, Inc.\VMware Tools
VMware traced using file C:\WINDOWS\system32\drivers\vmmouse.sys
VMware traced using file C:\WINDOWS\system32\drivers\vmhgfs.sys
VMWare traced using device \\.\HGFS
VMWare traced using device \\.\vmci
VMware serial number traced using WMI
End

cardon
Expert Boarder
Posts: 372
graphgraph
User Offline Click here to see the profile of this user
Gender: Male
The administrator has disabled public write access.
sheit#3179
 
#51990
Бан. 7 Years, 9 Months ago Karma: 28
Если интересно могу скинуть отчеты со своего совта с ветками реестра куда лезет ева ( или пыталась влезть).
zloiset
Gold Boarder
Posts: 782
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#52000
Бан. 7 Years, 9 Months ago Karma: 28
Хех вчера аки только сделал, сегодня на пару уже баны прилетели)
zloiset
Gold Boarder
Posts: 782
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
#52003
Бан. 7 Years, 9 Months ago Karma: 12
Под виндой 7кой бот сможет подменить родительский процесс лаунчера и должны быть видны папки explorer вместо папок бота, как будто запускается ярлыком с рабочего стола. В 8-ке и 10-тке такой возможности нету и бот просто запускает лаунчер.

На 7 и тестировал, папка бота светится а не IE. + Еще сегодня одна строчка смутила, при запуске лаунчер еще и процессы запущенные смотрит, а там пилот висит, после переименования в настройках в запущенных приложениях пилот название меняет, а во вкладке процессы так же как пилот светится, в теории могут еще оттуда срисовать его.
Leokrs
Senior Boarder
Posts: 199
graphgraph
User Offline Click here to see the profile of this user
The administrator has disabled public write access.
 
Go to topPage: 12345
Moderators: Slav2
© Macro Laboratory 2026
All rights reserved!
Design by Ivan Kozyrin