A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #13457  by wacked2
 Sun May 27, 2012 9:26 pm
I didn't really look because it is VB BUT
It queries the WMI "SELECT * FROM Win32_VideoController"
and aborts on:
Code: Select all
VM Additions S3 Trio32/64
S3 Trio32/64
VirtualBox Graphics Adapter
VMware SVGA II
"\x00"
 #13458  by Buster_BSA
 Sun May 27, 2012 10:36 pm
I know it has VirtualBox and VMWare detections too, but I am interested in Sandboxie detection method.

Thanks anyway.