Study on Circumvention of Virtual Machine Anti-Virus

JIANG Xiao-feng,SHI Yong,XUE Zhi
DOI: https://doi.org/10.3969/j.issn.1009-8054.2011.02.025
2011-01-01
Abstract:Nowadays anti-viruses softwares use virtual machine to execute programme and determine whether it would do harm to the system,thus decides to let the program go or alarm.Aiming at virtual machine anti-viruses features,how to detect virtual environment of anti-viruses software is studied.According to the difference between virtual machine environment and actual user environment and virtual machine properties of specific anti-viruses software,how to circumvent virtual machine anti-virus is explored,thus to avoid the programme not being executed by virtual machine of anti-viruses software and meet the specific requirements.
What problem does this paper attempt to address?