Windows on ARM vs Malware ("Copilot+")

Поділитися
Вставка
  • Опубліковано 16 січ 2025

КОМЕНТАРІ • 194

  • @FluffyAngelUwU
    @FluffyAngelUwU 6 місяців тому +555

    The best antivirus is running an environment where the virus doesn't know what to do or how to do!

    • @uooooooooh
      @uooooooooh 6 місяців тому +71

      seems like Windows on ARM isn''t that, though

    • @stonebubbleprivat
      @stonebubbleprivat 6 місяців тому +107

      Security through obscurity isn't a solution.

    • @olnnn
      @olnnn 6 місяців тому

      @@uooooooooh Maybe it could be to an extent (until windows ARM becomes more widespread) if one disabled PRISM x86 emulation - though I suspect there is still a bunch of critical windows bits and/or laptop vendor/driver bits relying on it still so that may not be possible.

    • @Frn1
      @Frn1 6 місяців тому +1

      Run them on wine!

    • @thmUNIX
      @thmUNIX 6 місяців тому +61

      @@stonebubbleprivatI guess, they tried to say that it is better to run GNU/Linux or Mac OS X which indeed would protect you from the majority of malware, but I would say ‘the best antivirus is your head on your shoulders’

  • @GlossySquare3
    @GlossySquare3 6 місяців тому +113

    A few days ago I simply typed "potato" Into copilot, It then gave me an essay about something called a "Sea Apple"
    Yeah, AI Is really smart let me tell ya.

    • @epicpe1
      @epicpe1 6 місяців тому

      Hello AidoBoy. Long time no see.
      We know what you have done to headquarters.

    • @nicholasneyhart396
      @nicholasneyhart396 3 місяці тому

      Sea apples are a type of sea cucumber. People like keeping them in marine aquariums, my uncle tried and found out the hard way they are poisonous and will nuke everything if they get bullied to death.

  • @lunakittyyy
    @lunakittyyy 6 місяців тому +70

    That skull malware was interesting. I can't think of any recent malware that is actually infectious. Not exactly sure what it was trying to accomplish though...

    • @Guy-be2px
      @Guy-be2px 6 місяців тому +3

      Simulating your brain (computer) on drugs

  • @yesdotwmv
    @yesdotwmv 6 місяців тому +178

    Actually there is no such thing as malware on windows because microsoft says in their terms of use to not make malicious software so its impossible

    • @eDoc2020
      @eDoc2020 6 місяців тому +4

      Clearly you haven't heard of cross-compilation.

    • @Dhendo7
      @Dhendo7 6 місяців тому +6

      You’ve got a point.

    • @Juzevs
      @Juzevs 6 місяців тому +13

      what if the bad guys decline the terms of use?

    • @qvsws
      @qvsws 5 місяців тому

      @@Juzevs it SAYS

    • @AraiDigital
      @AraiDigital 4 місяці тому +5

      damn, you're right! malware rates drop to 0%

  • @rainbain5474
    @rainbain5474 6 місяців тому +99

    Its crazy to think malware for windows will run on ARM in the first place. AARCH64 is probably my favorite ISA, and its crazy to see how far its come. For a while 64 bit ARM was unheard of and I never anticipated Windows running on it and was used to most software not being built to support ARM.

    • @rockpie.iso.tar.bz2
      @rockpie.iso.tar.bz2 6 місяців тому +3

      How was it unheard of if most smartphones had it?

    • @Kwpolska
      @Kwpolska 6 місяців тому +7

      Windows 11 on ARM emulates x86-64 software. The emulation is apparently good enough to allow malware to work.

    • @soundspark
      @soundspark 6 місяців тому +1

      @@Kwpolska It's designed to be fully backwards compatible with usermode x86 software.

    • @kipchickensout
      @kipchickensout 6 місяців тому +4

      "I use AARCH64 btw"

    • @the-answer-is-42
      @the-answer-is-42 6 місяців тому

      ​@@Kwpolska Wonder if it's possible to turn it off until you need it as a security measure (as in you have to tell Windows to run an executable with the emulator, rather than doing it automatically, which it seems to do in the video).

  • @ErdrickHero
    @ErdrickHero 6 місяців тому +38

    Windows malware in WINE on Linux on ARM next?

  • @obviouslyaxo
    @obviouslyaxo 6 місяців тому +119

    Bro’s UA-cam (subs) is expanding rapidly

    • @remzdev
      @remzdev 6 місяців тому +15

      ive been watching him since he has had 10k/5k, it's crazy on how much he has grown in not much time.

    • @zombie__
      @zombie__ 6 місяців тому +3

      ⁠@Arasiscooli started at 8k

    • @baribari1000
      @baribari1000 6 місяців тому +1

      wow almost at 50k

    • @inconsistenttutorialuploader
      @inconsistenttutorialuploader 6 місяців тому +2

      I started late at 30k

    • @kavylavx
      @kavylavx 6 місяців тому

      i started at 2k lmao​@@zombie__

  • @tanookimariorocks
    @tanookimariorocks 6 місяців тому +5

    I wanna see more of an investigation of the skull malware and what its end goal is

  • @pathfinderproject9381
    @pathfinderproject9381 6 місяців тому +6

    lain? is that a serial experiments reference?

  • @Klusio19
    @Klusio19 6 місяців тому +5

    ✨"rybody my name is Eric" ✨

  • @Pusheen7092
    @Pusheen7092 6 місяців тому +7

    Almost 50k subscribers congratulations

    • @jeffzkiller3590
      @jeffzkiller3590 6 місяців тому

      id rather this guy doesnt go mainstream, never goes well

  • @chickfila7nugget
    @chickfila7nugget 6 місяців тому +32

    being so used to win11 aesthetics, seeing sharp corners put me off

    • @kaiduwu
      @kaiduwu 6 місяців тому +12

      Ew 11

    • @gagekillingsworth8212
      @gagekillingsworth8212 6 місяців тому +11

      Windows 11 will use the sharp edges if there aren’t any display drivers

    • @another-niko-pfp-holder
      @another-niko-pfp-holder 6 місяців тому +4

      as a hyprland user, same

    • @kaiduwu
      @kaiduwu 6 місяців тому +3

      @@another-niko-pfp-holder W hypr, wayland is fire

  • @KaidenMikami
    @KaidenMikami 6 місяців тому +125

    at the end of the day, windows is still windows and vulnerable as fuck

    • @magicalnoodles
      @magicalnoodles 6 місяців тому +35

      Anything can become vulnerable though. The system doesn't really matter if the user gives the malware/virus admin access. Although linux makes it more difficult to get infected, it's still very possible if you allow the wrong package to get into your system

    • @crackny4n
      @crackny4n 6 місяців тому +16

      linux and macos, the way most people use them aren't secure either

    • @minecrafter9099
      @minecrafter9099 6 місяців тому +3

      @@magicalnoodles sudo destroy_my_computer

    • @PinkAgaricus
      @PinkAgaricus 6 місяців тому +2

      ​@@magicalnoodlesI remember this. The vulnerability that was in a fedora release that actually required you to not update until they patched the issue.

    • @FayyZ_Dox
      @FayyZ_Dox 6 місяців тому +4

      @@minecrafter9099 sudo rm -rf --no-preserve-root / (don't execute that in your bash tho, it's gonna nuke your whole drive)

  • @fusionconcepts
    @fusionconcepts 6 місяців тому +6

    I ran the malware through Recorded Future's Triage and it appears to be an XMRig miner and Lumma stealer

  • @league1809
    @league1809 6 місяців тому

    All your videos are extremely entertaining, thanks :)

  • @patricklechner190
    @patricklechner190 6 місяців тому +12

    Hey Eric, what security do you use on your main system? Just insanely curious...

    • @JJFX-
      @JJFX- 6 місяців тому +9

      CommonSense

    • @wrathofainz
      @wrathofainz 6 місяців тому +6

      Probably just a basic firewall and caution. Maybe defender just because it's there and does a decent job of catching malware if you fucked up hard enough to get infected.

    • @patricklechner190
      @patricklechner190 6 місяців тому +2

      @@wrathofainz configure correctly Defender can be insane tbh

    • @EricParker
      @EricParker  6 місяців тому +10

      I don't use Windows other than for VMs.
      I use Mac & Linux both with defaults (no 3rd party), Apple does have a version of Windows defender, but they keep it hidden.

    • @patricklechner190
      @patricklechner190 6 місяців тому +4

      @@EricParker thank you very much for the answer!

  • @factswithlouis
    @factswithlouis 6 місяців тому +1

    ur subs are growing so fast been here for 3yrs!

  • @baribari1000
    @baribari1000 6 місяців тому +8

    will you do a 50k celebration video or similar Eric?

  • @pixelthrived
    @pixelthrived 6 місяців тому +3

    great video as always!

  • @Coral_pepe
    @Coral_pepe 6 місяців тому +3

    This happened to me when I downloaded a tool from Killnet and even folders from my external drive became shortcuts and excute cmds while opening, they were in system32 I think, I carelessly deleted and it's not opening now 😂. I don't know why I didn't scan the files

  • @NimaSakibo
    @NimaSakibo 6 місяців тому +6

    Nah - there is no malware, what are you talking about? That gibberish was just Windows trying to talk to you in a new language it invented - totally normal!

  • @SkizzieSpeedruns
    @SkizzieSpeedruns 6 місяців тому +5

    Are there any possible workarounds for vmware on how to get around the RDTSC forcing vm exit detection?

    • @EricParker
      @EricParker  6 місяців тому +2

      vmware hardened loader passes it (I believe by fooling the guest with a rootkit), you can kinda hack KVM / qemu with a kernel edit to be less obvious. The vm exit is extremely uncommon for malware.

    • @SkizzieSpeedruns
      @SkizzieSpeedruns 6 місяців тому

      @@EricParker Yeah i am pretty sure i used the "VmwareHardenedLoader" from github, and I did some additional tweaks, although this is still the only thing that's getting detected, but as you said, the vm exit is not really common for malware.

  • @WindowsDestroyer
    @WindowsDestroyer 6 місяців тому +1

    1:35 Hang on how did we find the same malware

  • @redoktopus3047
    @redoktopus3047 6 місяців тому

    you should definitely do a deepin or uos demonstration

  • @RedJStudios
    @RedJStudios 6 місяців тому +2

    You should try to see how many viruses you can get in windows s mode

    • @EricParker
      @EricParker  6 місяців тому

      Exactly 0, but trying that might be fun.

  • @TheBenSanders
    @TheBenSanders 6 місяців тому +2

    Surprised you used a vm connected to the internet to run this. 😅
    Or is it on a different vlan?

    • @EricParker
      @EricParker  6 місяців тому +2

      Of course if I want to see net behavior.

  • @ayden8901
    @ayden8901 6 місяців тому +1

    Can you do a video on IDPS like Surciata that’s bundled with UniFi hardware? Is use that in conjunction with Bitdefender but am curious on what it can actually stop. Especially the DoS and Botnet filters

  • @AlexanderSteinerRacing
    @AlexanderSteinerRacing 6 місяців тому +7

    what if every company you accepted the EULA from, owns your soul. Wouldn't that be great :)

    • @kirill9064
      @kirill9064 6 місяців тому +1

      Do they own parts of it?
      What would they do with it? Inject into an AI to make it alive?

    • @AlexanderSteinerRacing
      @AlexanderSteinerRacing 6 місяців тому +1

      @@kirill9064 maybe who knows :)

    • @undefinedCat
      @undefinedCat 6 місяців тому

      My soul slot has a half-eaten pack of bacon lays

    • @AlexanderSteinerRacing
      @AlexanderSteinerRacing 6 місяців тому +1

      Mine is an Borken Soundbar

  • @jolly_exe
    @jolly_exe 6 місяців тому +2

    do you have the paid version of binary ninja?

  • @dovacon7409
    @dovacon7409 2 місяці тому

    What exactly is ARM? I heard that many times but what is it?

  • @fgf8
    @fgf8 5 місяців тому

    What arm emulator are you using?

  • @mansiselyn
    @mansiselyn 6 місяців тому

    so we can say that it is unarmed?

  • @MrRorosao
    @MrRorosao 6 місяців тому

    Well, expected, windows emulation layers doesn't discriminate against viruses! Be safe kids!

  • @cursqdlol
    @cursqdlol 6 місяців тому +2

    ngl i dont know anything he is saying but its making me wanna know

  • @00evaunit
    @00evaunit 5 місяців тому

    i do not know how youtubers who test viruses don't wee themselves everytime they download it, i know it is a VM but i would be too paranoid

  • @webs_exploits
    @webs_exploits 6 місяців тому

    11:11 how is the tool called for editing code or what it is it looks kinda good

    • @redlionstudio2750
      @redlionstudio2750 6 місяців тому

      I think it's dnSpy, and it's not a code editor

    • @sawyaaa
      @sawyaaa 6 місяців тому

      @@redlionstudio2750Code Editor is called a IDE

    • @EricParker
      @EricParker  6 місяців тому

      Binary ninja. Not a code editor, it's a reverse engineering tool.

  • @WickedNinja48
    @WickedNinja48 6 місяців тому

    What do you think if you were to turn off windows antimalware executable? like derp the registry and use tools to disable it?

  • @luqmaanmohideen8422
    @luqmaanmohideen8422 6 місяців тому +1

    how did u build a scrapper

    • @EricParker
      @EricParker  6 місяців тому +1

      More on that soon.

  • @not-rv1li
    @not-rv1li 6 місяців тому

    It does effect my home systems...seems like no removing it and ive hired programers that just walked away from it

  • @mu11668B
    @mu11668B 6 місяців тому +1

    I wonder if any of those PE/shellcode packers for x86/x64 would work on this ARM64 device. Maybe give xloader/formbook a try. If they do work, I'd say Microsoft did a really good job on compatibility. Lol.

  • @Kajtgg223
    @Kajtgg223 6 місяців тому +2

    Hey :D, also you start to get so much subs recently :D

  • @luheartswarm4573
    @luheartswarm4573 6 місяців тому

    I thought windows itself was the malware nowadays

  • @edelzocker8169
    @edelzocker8169 6 місяців тому +2

    There is malware made to avoid the MS Defender and thats also the reason why I always recommend to instal an AV...

    • @zombi1034
      @zombi1034 6 місяців тому

      Or simply avoid downloading dubious software or mail attachments and you will probably be fine.

    • @edelzocker8169
      @edelzocker8169 6 місяців тому

      @@zombi1034 you know it's possible to get malware from trusted websites like Steam?

    • @baseddoggie
      @baseddoggie 5 місяців тому

      Malware is made to avoid all AV software, its not like they just target Defender and call it a day, especially when the most profitable victims to infect are often the ones using 3rd party AV instead of Common Sense.

  • @CanoTheVolcano
    @CanoTheVolcano 6 місяців тому

    Microsoft provides the OS to you with spyware, so that's nice of them for this challenge

  • @undefinedCat
    @undefinedCat 6 місяців тому

    What's the network drive on the VM?

    • @EricParker
      @EricParker  6 місяців тому +1

      connects to the host.

  • @sawyaaa
    @sawyaaa 6 місяців тому

    Great video!

  • @mnageh-bo1mm
    @mnageh-bo1mm 6 місяців тому

    can you share the yt scraper ?

  • @SamirElabed
    @SamirElabed 6 місяців тому

    running a quick scan will not scan all file in Defender you need to run a full scan

    • @EricParker
      @EricParker  6 місяців тому +1

      I am using an M1 mac and UTM.

    • @SamirElabed
      @SamirElabed 6 місяців тому

      @@EricParker you still need to do full scan Defender will only scan common known path with quick scan while full scan it scan every file on the system

  • @stingfiretube
    @stingfiretube 6 місяців тому +3

    Step 1: Uninstall Windows

  • @hawktuah1991
    @hawktuah1991 6 місяців тому

    can you do a video on bloxstrap? its a like client on roblox

  • @moose7527
    @moose7527 6 місяців тому +2

    I

  • @giridharpavan1592
    @giridharpavan1592 2 місяці тому

    losing an arm and a leg

  • @idkiwatchvideos
    @idkiwatchvideos 6 місяців тому

    what vm do you use

    • @nitterwilly
      @nitterwilly 6 місяців тому

      windows sandbox you need windows 11 pro

    • @EricParker
      @EricParker  6 місяців тому +3

      vmware most videos, qemu a few. This is UTM under an M1 mac for ARM.

  • @fakename2123
    @fakename2123 6 місяців тому

    how would you pass the rdtsc check on a x86 installation?

    • @EricParker
      @EricParker  6 місяців тому +1

      either using a kernel driver to fool the application you're trying to run, or if you're using linux & KVM you can edit the kernel so that the timing is about right. You can also patch the check out of the binary.

    • @fakename2123
      @fakename2123 6 місяців тому

      @@EricParker using a kvm setup, unfortunately all the patches for vmx.c(Intel) are for kernel version 6.0sum and unfortunately vmx.c has changed in my kernel version so those patches are moot, trying my best here but pre clueless when it comes to kernel dev

  • @vinfi8526
    @vinfi8526 6 місяців тому

    you sir just gain a sub

  • @BsktImp
    @BsktImp 6 місяців тому +1

    As I understand it, malware can still detect it's in a VM environment and/or evade the hypervisor, so how do you protect against malware escaping your VM and potentially disarming your modem or infecting host machine?

    • @EricParker
      @EricParker  6 місяців тому +3

      > malware can still detect it's in a VM environment
      Yes, there are ways of making this more difficult, IE the vmware hardened loader rootkit I use.
      > protect against malware escaping your VM and potentially disarming your modem or infecting host machine
      Might be worth a video. As far as I know it has never ever happened in the real world to anybody (although there are VM escape demos).
      It's possible with bad configuration (IE bad ssh settings on host) in theory. If you enable vmware tools, there have been a few exploits based on vulnerabilites in the guest editions driver, not any actual hypervisor escapes. Using Linux /mac on the hos tinstead of windows also helps.

    • @BsktImp
      @BsktImp 6 місяців тому

      @@EricParker Cheers.

  • @not-rv1li
    @not-rv1li 6 місяців тому

    I'm having huge issues on my phone I'd let anyone curious about it to take a look at my system

  • @Coral_pepe
    @Coral_pepe 6 місяців тому +1

    My pc is still stuck, win def did nothing 😂,I trusted a Russian tg channel

    • @undefinedCat
      @undefinedCat 6 місяців тому

      I remember playing bedwars on some russian server and someone was sending a link to a telegram channel with supposed "cheats". Decided to download it and it turns out it was some random Python stealer made with pyinstaller

    • @undefinedCat
      @undefinedCat 6 місяців тому

      Also, I forgot to say that this was done in Triage vm

  • @asbfabfoaijfo8
    @asbfabfoaijfo8 6 місяців тому

    how did u run that. did u actualy bought it or maybe qemu catched up somehow?

  • @DavidBakhash
    @DavidBakhash 6 місяців тому

    Your accent is so cool what is it

  • @mrj4264
    @mrj4264 6 місяців тому

    UA-cam scraper?

  • @rawpie2
    @rawpie2 6 місяців тому

    people finding you bro! keep making videos your on the up

  • @SqualidsargeStudios
    @SqualidsargeStudios 6 місяців тому +1

    What is an alm?

  • @cooltwittertag
    @cooltwittertag 5 місяців тому

    I use typewriters and punch cards so them damn viruses cant come for me!

  • @Real-Rin
    @Real-Rin 6 місяців тому

    Step 1 get recall

  • @ReidAstrea
    @ReidAstrea 6 місяців тому +1

    username is lain🔥🗣️

  • @duzaliteraf7373
    @duzaliteraf7373 6 місяців тому

    1 second ago
    No views
    No comments
    No likes
    I'm first

  • @narpwa
    @narpwa 6 місяців тому

    malware is fun

  • @憂鬱な冒険家
    @憂鬱な冒険家 6 місяців тому +3

    I enjoy your videos so much more when I imagine Tristan Tate with a fat cigar in his mouth talking about malware to me. Your voice sounds too similar !

  • @Scy1hee
    @Scy1hee 6 місяців тому +1

    w video

  • @corsola222
    @corsola222 6 місяців тому

    virus for the love of the game

  • @Mininukefromfallout
    @Mininukefromfallout 6 місяців тому

    7000th view

  • @TechnoMinded-qp5in
    @TechnoMinded-qp5in 6 місяців тому +1

    Windows 10 master race I plan on emulating my games after End of Life if Valve deprecates Windows 10 I am still set for life modern Windows will still be more secure than you think after End of Life and it might be more different than we think don't push the panic button yet get a security software and you will see why. If you have a security software Valve should ALLOW YOU to continue Windows after end of life since it's basically protecting your system I wish Valve would make Windows 10 a chance to use it at your own risk only if you have a security software. Sorry not joining Linux just yet I keep coming back to Windows I've been a Windows kid all my life and REFUSE to allow Microsoft to mandate a TPM2.0 if they want me to stay then remove it already people just want to upgrade Microsoft can still fix this it's not too late to fix it in Windows 12 by opting out TPM2.0 requirements.

    • @KSPAtlas
      @KSPAtlas 6 місяців тому

      There's something called a full stop, use it

  • @L-mm6bk
    @L-mm6bk 6 місяців тому +1

    Hi

  • @blank573p
    @blank573p 6 місяців тому +1

    2nd

    • @Mamikokh0
      @Mamikokh0 6 місяців тому +11

      shut up bro

    • @NatetheNintendofan
      @NatetheNintendofan 6 місяців тому +1

      How about you leave uttp

    • @blank573p
      @blank573p 6 місяців тому +1

      @@Mamikokh0 sorry i didnt know its bad 😔

    • @blank573p
      @blank573p 6 місяців тому +1

      didnt mean for everyone to hate me

    • @blank573p
      @blank573p 6 місяців тому +1

      @@NatetheNintendofan i left 🫡

  • @Daniel636-j7l
    @Daniel636-j7l 6 місяців тому

    27th

  • @RandomytchannelGD
    @RandomytchannelGD 6 місяців тому

    Hi