![]() |
|
|
|
#1
|
|||
|
|||
|
Shit ! It use a technology called embed NULL character in registry key, first introduced by RegHide of SysInternals, and used in some rootkit, malware, software.... We can't use RegEdit.exe, RegEdt32.exe to open, view it.
|
|
#2
|
|||
|
|||
|
Quote:
I looked at reghide src and see they use native API for access. So... Can use ZwCreateKey (enumerating subkeys) and then ZwDeleteKey to remove bad keys? Don't have time to test this morning but perhaps will code something later this morning to see if success. Google ZwCreateKey & ZwDeleteKey for MSDN reference. Systernals Reghide as TQN mentioned, Source code at: h**p://www.sysinternals.com/Information/TipsAndTrivia.html#HiddenKeys -bg |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| CRC problem... Alien Registry Viewer | Maltese | General Discussion | 4 | 04-12-2007 13:52 |
| Registry Monitoring, what's best? | Barry | General Discussion | 13 | 08-08-2004 00:55 |