exitthematrix wrote:Citadel 1.3.5.1 Rain Edition sample. It have some anti-VM
Not found. Except lame trick with GetKeyboardLayoutList (patch two bytes @00418FC6 with nops) and another lame trick with
Code: Select allROOT\SECURITYCENTERROOT\SECURITYCENTER2 SELECT * FROM%sWQL
Antivirus Product company Name display Name version Number Unknown Company:%s
Product:%s
Version:%s
Firewall Product
Software\Microsoft\Windows\CurrentVersion\Uninstall
Publisher Display Name Display Version%u:%s|%s|%s
Code: Select allSafenSoft SysWatch McAfee McAfee Security Center McAfee SecurityCenter Symantec Client Symantec Protection Symantec Shared Symantec Security Norton Protection Kaspersky Security Kaspersky Anti-Virus avast! Antivirus AntiVir Desktop AVG Monitor AVG Service AVG Security ESET Security ESET Antivirus Microsoft Inspection Microsoft Malware Microsoft Security
+
http://www.kernelmode.info/forum/viewto ... 553#p17553
Patched Zeus result (full disclosure).
http://camas.comodo.com/cgi-bin/submit? ... f9856e4263
No matter how it named - zeus, ice-ix, citadel it all the same slavik shit.