For quite some time ive been suspecting that ive been bootkitted. Suddenly I couldnt read my SMBIOS table, windows detected a hyper visor even when disabled with bcdedit. I could find traces of vpn connections getting established to MS ip addresses.
-
-
Now I am not saying any of this is done with bad intensions and it is maybe a good idea for some people. I dont think many people are aware of how this works though, I prefer to know what is happening on my pc for security.
-
@threadreaderapp unroll please - Show replies
New conversation -
-
-
I did stumble upon some tools i have not seen before while looking at the files used- like this hex editor https://cdn.discordapp.com/attachments/817218816521797654/881878819290615838/he.exe …pic.twitter.com/diKXlpfXCs
-
I have this file c:\windows\bfsvc.exe that maybe is used to serve the files that a vm boots from?pic.twitter.com/LzuXeiu04b
- Show replies
New conversation -
-
-
This was your posts afew weeks ago with the bcedit trick?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Some other explanations for what is going on ive also consider: 1. This happen when you kill defender 2. Its because i install xbox store and it is intended as an anticheat - by doing the attestion in another vm 3. This is done to make dtrace work somehow....
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
this also happen on my home version of windows, so its not just some feature for sandbox, there is no sandbox on home.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
