Tracereg example in detours does not work in Win7. RRS feed

  • Question

  •  Not all cases of Kernel32!RegOpenKeyExw (or any other registry calls) are detoured as expected. It used to work fine in WinXP  where the hook was on Advapi32!RegOpenKeyExw

    I have screen shot of 1 working and non working stack from Procmon. My case was a 2 line vbs script as below..

    Set WshShell = WScript.CreateObject("WScript.Shell")
    WScript.Echo WshShell.RegRead("HKCR\._sln\v1")

    Displaying image.png

    Not working case:

    Displaying image.png

    Thanks Babraham

    • Moved by Jamles Hez Tuesday, September 8, 2015 1:46 AM
    Thursday, September 3, 2015 7:03 AM


All replies