a0rtega / pafish

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware families do

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Pafish setup changes after snapshot VBox

ThisIsNotMalware opened this issue · comments

Hi there, this issue is not 100% related to Pafish but I guess is something worth mentioning to see if more people have the same issue.

Scenario: Im running a W7 x64 VM in VBox, every update is disabled and reg keys have been changed, I have a 51/53 in Pafish (the rtsc ones are quite difficult for VBox, rest is fine).

So, when creating a snapshot of said machine, and coming back to check the snapshot in a week or so, and re running pafish again, I can see that the WMI has been activated again, plus the 3 reg keys regarding SystemBiosDate, VideoBiosVersion and ACPI\DSDT\VBOX___

If anyone has any idea Id be more than happy to hear, also, if this does not belong to here just feel free to close it:)

Thanks.
Diego.

EDIT** Update.
Found that this issue might be related to Win7 not being an original version, updated and by now it has not changed in a couple weeks.