A forum for reverse engineering, OS internals and malware analysis 

Forum for discussion about kernel-mode development.
 #1947  by Cr4sh
 Fri Aug 13, 2010 7:18 pm
Changing address of the nt!KeUpdateSystemTime in HAL.DLL IAT for the same purposes is a more simple and stable way: only 4-byte patcing without any disassemblers, signatures, unexported functions, etc.