Sarthak Srivastava

Results 11 comments of Sarthak Srivastava

As per the instructions given by you in some previous issues created by someone, we have updated the malware trace execution command. The following command has been executed: **sudo ./src/drakvuf...

Sir in order to avoid the mismatch of the version of the json profile and the windows running on VM, we have set up drakvuf recently on another system and...

As per your suggestions: 1.The json file has been verified and it is up to date with recent windows version. No update has been performed on windows. 2. The process...

A gentle reminder for the issue as we have been waiting for your reply since long time. As per your suggestions: 1.The json file has been verified and it is...

@tklengyel The debug output of drakvuf during process injection is as follows: root@cs13-HP-280-G2-MT-Legacy:/home/cs13/drakvuf# ./src/drakvuf -r /root/windows7-sp1.json -d 1 -x socketmon -t 120 -i 1300 -e “C:\Users\Shawn\Desktop\zbot\zbot_1.exe” -v 1 > zbot_1.txt...

Sorry, we tried exploring into the debug information multiple times after your message, but still we are not able to spot the issue. And as per our knowledge, 1. The...

Thanks for your reply. The command has been changed (path is corrected) but still the issue is same. 1.The process injection is again getting failed showing process creation failed ![Screenshot...

I tried it with a different process(task manager PID 2832) the debug output is shown below: ![Screenshot from 2022-05-06 11-44-03](https://user-images.githubusercontent.com/104664415/167077621-b7989dad-8908-4e17-a3b6-bd2c1a96cc2c.png) ![Screenshot from 2022-05-06 11-51-00](https://user-images.githubusercontent.com/104664415/167077907-5226766b-4268-418f-a3b1-39c04d7e0cb1.png) ![Screenshot from 2022-05-06 11-45-57](https://user-images.githubusercontent.com/104664415/167077629-8b789015-991b-4c64-8cd0-2993adc59745.png) @tklengyel

A gentle reminder. Sorry I am still not able to resolve the issue. Please help me out. Thanks @tklengyel

Actually yes, the path of the file given in the command has been verified several times. But still we are not getting why is it showing that the file not...