sample key for most armadilled targets that use the system time clock implemented with armadillo:
[HKEY_CLASSES_ROOT\CLSID\{B9A1B7AE-0E0F-13D1-B2E4-0060975B8649}]
"0"=hex:70,9c,25,c3,dc,72,48,9d,d1,8b,f9,ef,94,b0,4d,0c,cf,59,c3,d5,96,6e,2f,\
db,78,ba,6c
[HKEY_CLASSES_ROOT\CLSID\{B9A1B7AE-0E0F-13D1-B2E4-0060975B8649}\Version]
@="1.0"
but also i found out that some targets write to:
[HKEY_CURRENT_USER\Software\Classes....
Sample:
[HKEY_CURRENT_USER\Software\Classes\{4B7BEAFF-A184-13D1-B2E4-0060975B8649}]
"0"=hex:9f,11,b0,7a,24,bf,30,6b,e1,e5,47,ae,94,f0,09,bc,9b,80,6b,03,c7,a4,07,\
b1,d9,8a,f1
[HKEY_CURRENT_USER\Software\Classes\{4B7BEAFF-A184-13D1-B2E4-0060975B8649}\Version]
@="1.0"
on "0"=hex....... store the time check with encrypted hex data
i still need to find out how to make regmonitor from system internals to work out... i can't think that the most famous regmonitor don't work with this.. in that case should i called this a bug? umhhhh.. i would like to try an older version ..anyone have an old version to try out?.. i'm still waiting for Viper.. comments about this.. how did you make it?
Results with WinSteal :
CreateKey CURRENT\Software\Microsoft\Windows\CurrentVersion\
Bmp CreateKey
Bmp OpenKey LOCAL\Software\Microsoft\Windows\CurrentVersion SUCCESS hKey: 0xC2A20A90
Bmp QueryValueEx LOCAL\Software\Microsoft\Windows\CurrentVersion\SubVersionNumber SUCCESS
Bmp CloseKey LOCAL\Software\Microsoft\Windows\CurrentVersion SUCCESS
Bmp OpenKey LOCAL\Software\Microsoft\Windows\CurrentVersion SUCCESS hKey: 0xC2A20A90
Bmp QueryValueEx LOCAL\Software\Microsoft\Windows\CurrentVersion\SubVersionNumber SUCCESS
Bmp CloseKey LOCAL\Software\Microsoft\Windows\CurrentVersion SUCCESS
Bmp OpenKey LOCAL\Software\The Silicon Realms Toolworks\Armadillo SUCCESS hKey: 0xC2A20A90
Bmp CloseKey LOCAL\Software\The Silicon Realms Toolworks\Armadillo SUCCESS
Bmp OpenKey LOCAL\Software\The Silicon Realms Toolworks\Armadillo SUCCESS hKey: 0xC2A20A90
Bmp QueryValueEx LOCAL\Software\The Silicon Realms Toolworks\Armadillo\{071BD7C95D8CDD898} SUCCESS
Bmp CloseKey LOCAL\Software\The Silicon Realms Toolworks\Armadillo SUCCESS
Bmp OpenKey ROOT\CLSID\{B9A1B7AE-0E0F-13D1-B2E4-0060975B8649} NOTFOUND
Bmp OpenKey CURRENT\Software\The Silicon Realms Toolworks\Armadillo NOTFOUND
Bmp OpenKey CURRENT\Software\Classes\{4B7BEAFF-A184-13D1-B2E4-0060975B8649} NOTFOUND
Bmp OpenKey LOCAL\Software\The Silicon Realms Toolworks\Armadillo SUCCESS hKey: 0xC2A20A90
Bmp QueryValueEx LOCAL\Software\The Silicon Realms Toolworks\Armadillo\{D8CDD89871BD7C95} NOTFOUND
Bmp CloseKey LOCAL\Software\The Silicon Realms Toolworks\Armadillo SUCCESS
Bmp OpenKey LOCAL\Software\The Silicon Realms Toolworks\Armadillo SUCCESS hKey: 0xC2A20A90
Bmp QueryValueEx LOCAL\Software\The Silicon Realms Toolworks\Armadillo\{71BD7C95D8CDD899} NOTFOUND
Bmp CloseKey LOCAL\Software\The Silicon Realms Toolworks\Armadillo SUCCESS
Bmp OpenKey LOCAL\System\CurrentControlSet\Control\CommAlias NOTFOUND
Bmp QueryValueEx 0xC2A100A0\PORTNAME SUCCESS "COM1"
Bmp QueryValueEx 0xC2A100A0\FRIENDLYNAME SUCCESS "Communications Port (COM1)"
Bmp QueryValueEx 0xC2A20750\PORTNAME SUCCESS "LPT1"
Bmp QueryValueEx 0xC2A20750\FRIENDLYNAME SUCCESS "ECP Printer Port (LPT1)"
Bmp QueryValueEx 0xC29FF130\PORTNAME SUCCESS "COM4"
Bmp QueryValueEx 0xC29FF130\FRIENDLYNAME SUCCESS "HSP56 MR"
Bmp OpenKey LOCAL\System\CurrentControlSet\Control\SessionManager\KnownVxDs NOTFOUND
Bmp OpenKey LOCAL\System\CurrentControlSet\Control\CommAlias NOTFOUND
Bmp QueryValueEx 0xC2A100A0\PORTNAME SUCCESS "COM1"
Bmp QueryValueEx 0xC2A100A0\FRIENDLYNAME SUCCESS "Communications Port (COM1)"
Bmp QueryValueEx 0xC2A20750\PORTNAME SUCCESS "LPT1"
Bmp QueryValueEx 0xC2A20750\FRIENDLYNAME SUCCESS "ECP Printer Port (LPT1)"
Bmp QueryValueEx 0xC29FF130\PORTNAME SUCCESS "COM4"
Bmp QueryValueEx 0xC29FF130\FRIENDLYNAME SUCCESS "HSP56 MR"
Bmp OpenKey LOCAL\System\CurrentControlSet\Control\SessionManager\KnownVxDs NOTFOUND
Bmp QueryValueEx 0xC2A20750\FRIENDLYNAME SUCCESS "ECP Printer Port (LPT1)"
Bmp QueryValueEx 0xC29FF130\PORTNAME SUCCESS "COM4"
Bmp QueryValueEx 0xC29FF130\FRIENDLYNAME SUCCESS "HSP56 MR"
Bmp OpenKey LOCAL\System\CurrentControlSet\Control\SessionManager\KnownVxDs NOTFOUND
Bmp OpenKey LOCAL\Software\Microsoft\Windows\CurrentVersion SUCCESS hKey: 0xC2A20A90
Bmp QueryValueEx LOCAL\Software\Microsoft\Windows\CurrentVersion\SubVersionNumber SUCCESS
Bmp CloseKey LOCAL\Software\Microsoft\Windows\CurrentVersion SUCCESS
Bmp CloseKey LOCAL\Software\The Silicon Realms Toolworks\Armadillo SUCCESS
Bmp OpenKey ROOT\CLSID\{B9A1B7AE-0E0F-13D1-B2E4-0060975B8649} NOTFOUND
Bmp CreateKey ROOT\CLSID\{B9A1B7AE-0E0F-13D1-B2E4-0060975B8649} SUCCESS hKey: 0xC2A20A90
Bmp SetValueEx ROOT\CLSID\{B9A1B7AE-0E0F-13D1-B2E4-0060975B8649}\0 SUCCESS 70 9C 19 C3 DC 72 3C 91 ...
Bmp OpenKey ROOT\CLSID\{B9A1B7AE-0E0F-13D1-B2E4-0060975B8649}\Version NOTFOUND
Bmp CreateKey ROOT\CLSID\{B9A1B7AE-0E0F-13D1-B2E4-0060975B8649}\Version SUCCESS hKey: 0xC2A206F0
Bmp SetValueEx ROOT\CLSID\{B9A1B7AE-0E0F-13D1-B2E4-0060975B8649}\Version SUCCESS
Bmp OpenKey CURRENT\Software\Classes\{4B7BEAFF-A184-13D1-B2E4-0060975B8649} NOTFOUND
Bmp CreateKey CURRENT\Software\Classes\{4B7BEAFF-A184-13D1-B2E4-0060975B8649} SUCCESS hKey: 0xC2A20A90
Bmp SetValueEx CURRENT\Software\Classes\{4B7BEAFF-A184-13D1-B2E4-0060975B8649}\0 SUCCESS 9F 11 8C 7A 24 BF 44 67 ...
Bmp OpenKey CURRENT\Software\Classes\{4B7BEAFF-A184-13D1-B2E4-0060975B8649}\Version NOTFOUND
Bmp CreateKey CURRENT\Software\Classes\{4B7BEAFF-A184-13D1-B2E4-0060975B8649}\Version SUCCESS hKey: 0xC2A206F0
Bmp SetValueEx CURRENT\Software\Classes\{4B7BEAFF-A184-13D1-B2E4-0060975B8649}\Version SUCCESS "1.0"
Bmp CloseKey CURRENT\Software\Classes\{4B7BEAFF-A184-13D1-B2E4-0060975B8649}\Version SUCCESS
Bmp CloseKey CURRENT\Software\Classes\{4B7BEAFF-A184-13D1-B2E4-0060975B8649} SUCCESS
Bmp QueryValueEx 0xC189CD70\MSVBVM60 NOTFOUND
