ACPI key added

This commit is contained in:
Thorsten Sick 2014-02-17 10:15:24 +01:00
parent 2902f5f21f
commit e2ea0340b6
3 changed files with 32 additions and 0 deletions

View File

@ -189,6 +189,16 @@ int main(int argc, char *argv[])
print_not_traced();
}
printf("[*] Reg key (HKLM\\HARDWARE\\ACPI\\DSDT\\VBOX__");
if (vbox_reg_key5() == 0) {
write_log("VirtualBox traced using Reg key HKLM\\HARDWARE\\ACPI\\DSDT\\VBOX__");
print_traced();
write_trace("hi_virtualbox");
}
else {
print_not_traced();
}
if (vbox_sysfile1() == 0) {
}
else {

View File

@ -113,6 +113,26 @@ int vbox_reg_key4() {
}
}
/**
* ACPI Regkey detection
**/
int vbox_reg_key5() {
HKEY regkey;
LONG retu;
char value[1024];
int i;
DWORD size;
size = sizeof(value);
retu = RegOpenKeyEx(HKEY_LOCAL_MACHINE, "HARDWARE\\ACPI\\DSDT\\VBOX__", 0, KEY_READ, &regkey);
if (retu == ERROR_SUCCESS) {
return 0;
}
else {
return 1;
}
}
/**
* VirtualBox Driver files in windows/system32
**/

View File

@ -10,6 +10,8 @@ int vbox_reg_key3();
int vbox_reg_key4();
int vbox_reg_key5();
int vbox_sysfile1();
int vbox_sysfile2();