Jump to content
Tuts 4 You

Pass Debugger Check in VMprotect 2.x


mojtaba

Recommended Posts

On 3/24/2024 at 4:41 PM, windowbase said:

@X0rby Just showing off?

I didn't change anything, just my usual dbg settings...

Edited by X0rby
  • Like 1
Link to comment
Share on other sites

1 hour ago, windowbase said:

Just showing off?

Regards.

sean.

With simple tricks, everyone can bypass the Anti-Debug of this target without loading the kernel-driver. If no one is willing to share this method, I will make it public. :)

 

  • Like 2
Link to comment
Share on other sites

jackyjask
3 minutes ago, RADIOX said:

Please try that with the 2 targets i shared 

one target silently crashes even without any debugger being  used

steps to run it?

Link to comment
Share on other sites

2 hours ago, jackyjask said:

silently crashes

I'll do a short video the 2 apps running fin without using a debugger 

Link to comment
Share on other sites

Sean Park - Lovejoy
12 minutes ago, Oliver said:

@bootbro did you tried solving titan hide driver's blu screen issue?

Regards.

 

 

Regards.

sean.

Link to comment
Share on other sites

14 hours ago, Oliver said:

Did you tried solving titan hide driver's blu screen issue?

I have tried to add Etw Hook's source code to the source code of TitanHide.sys, but it was not effective and I am not considering it for now. I will release newly compiled plugins and drivers, using methods to bypass signatures. They will not need to disable signatures and can be loaded in normal mode.

  • Like 2
Link to comment
Share on other sites

Wow superb @boot ,what the great jobs you are doing for us bro.

Much  appreciated.

Best of luck.

Thank you very much.

Edited by Oliver
  • Like 1
Link to comment
Share on other sites

4 hours ago, boot said:

Not need to disable signatures and can be loaded in normal mode...

In theory, it is feasible, but it is unknown whether it will be effective in the new version of Windows OS.

  • Like 2
Link to comment
Share on other sites

@bootbro i have a question ,when we start titan hide drivers then we can easily debug the latest vmp protected file like putting breakpoints and stepping but when we attach same file to the debugger and after putting  breakpoint click on the button why  program auto closes?

 

 

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...