I have been running hmpalert.exe and run the entire test. I wonder why this tests below not being stopped, all the other tests was stopped. Do 4 and 5 only check for VMware or can it also check for other VM’s, if not that’s why this is not working.
- Unpivot Stack (Executes ROP-chain on both pivoted and native stack)
- ROP – system() in msvcrt (Runs calculator via Return-oriented programming)
- Anti-VM – VMware (Checks if this process is running in a virtual machine )
- Anti-VM - Virtual PC (Checks if this process is running in a virtual machine )
- Keyboard logger (not an exploit) (Captures keystroke from other applications )
This thread was automatically locked due to age.