A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #25407  by EP_X0FF
 Sat Mar 07, 2015 8:40 am
GLOBALBANFIXED wrote:What version of VBox driver you use?
Where?
 #25413  by GLOBALBANFIXED
 Sat Mar 07, 2015 1:29 pm
EP_X0FF wrote:
GLOBALBANFIXED wrote:What version of VBox driver you use?
Where?
In last dsefix (ultra4.sys) version. Ultra4.sys this is VBoxDrv .sys (ver?) ? Or another selfmade driver?

P.S. Thanks for this app, really make life easier :twisted:
 #25414  by EP_X0FF
 Sat Mar 07, 2015 1:32 pm
SelectHF2 wrote:So i would need to use a Vbox to do this?
No.
GLOBALBANFIXED wrote:In last dsefix (ultra4.sys) version. Ultra4.sys this is VBoxDrv .sys (ver?) ? Or another selfmade driver?
1.6
 #26625  by EP_X0FF
 Mon Aug 31, 2015 5:31 am
aionescu wrote:Why not just use the Windows 8+ unfixed 0 day from my Infiltrate talk? With the technique I presented, you can easily disable DSE :)
Well because it 0day and maybe fixed, while this driver isn't banned and used by malware for 5+ years.