View Single Post
  #20  
Old 08-13-2003, 03:13
Squidge's Avatar
Squidge Squidge is offline
Drunken Squirrel
 
Join Date: Oct 2002
Posts: 412
Rept. Given: 4
Rept. Rcvd 9 Times in 4 Posts
Thanks Given: 0
Thanks Rcvd at 6 Times in 6 Posts
Squidge Reputation: 9
You can use the ZW functions (eg. zwOpenKey) to set back the date of a Armadillo'd application as long as the IRQL is currently at PASSIVE_LEVEL. You may be able to do it with other functions, but these are the ones I've tried, tested, and succeeded with

Deleting keys at random is just not going to work (even if you have a Regsnap/watch/whatever log before and afterwards)

EDIT: This is, of course, assuming a Win2K/XP system (the functions above don't exist on Win98 as far as I'm aware)

Last edited by Squidge; 08-13-2003 at 03:15.
Reply With Quote