Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 06-30-2005, 19:11
TQN TQN is offline
VIP
 
Join Date: Apr 2003
Location: Vietnam
Posts: 358
Rept. Given: 143
Rept. Rcvd 24 Times in 13 Posts
Thanks Given: 196
Thanks Rcvd at 168 Times in 51 Posts
TQN Reputation: 24
Shit ! It use a technology called embed NULL character in registry key, first introduced by RegHide of SysInternals, and used in some rootkit, malware, software.... We can't use RegEdit.exe, RegEdt32.exe to open, view it.
Reply With Quote
  #2  
Old 06-30-2005, 20:20
bgrimm bgrimm is offline
Friend
 
Join Date: Jan 2004
Location: South of The North Pole
Posts: 66
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 3 Times in 3 Posts
bgrimm Reputation: 0
Quote:
Originally Posted by TQN
It use a technology called embed NULL character in registry key, first introduced by RegHide of SysInternals
I never had seen this before! interesting!
I looked at reghide src and see they use native API for access.

So...
Can use ZwCreateKey (enumerating subkeys) and then ZwDeleteKey to remove bad keys?
Don't have time to test this morning but perhaps will code something later this morning to see if success.

Google ZwCreateKey & ZwDeleteKey for MSDN reference.

Systernals Reghide as TQN mentioned, Source code at:
h**p://www.sysinternals.com/Information/TipsAndTrivia.html#HiddenKeys


-bg
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
CRC problem... Alien Registry Viewer Maltese General Discussion 4 04-12-2007 13:52
Registry Monitoring, what's best? Barry General Discussion 13 08-08-2004 00:55


All times are GMT +8. The time now is 09:38.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )