|
"how the hell do they detect vmware"
They don't detect it. It is XProtector bug.
By the way: what for the protection should detect VMWare or VirtualPC? For reverser it gives nothing. If you mean no page access (like XProtector feature) for dumping the memory then it still gives you nothing. Why? Because if you are not able to make a dump of non readable protected memory then virtual like environments will not help you to perform further reversing operations needed to rebuild / analyse the protection.
Regards.
|