Originally Posted by
VX2
are you about modifying process after launching? I can't see a difference. both must be easy detectable. but in this case you have no reason launch additional program.
if you about archives injection - anyway you couldn't fake 'signaturefile' protection without disabling this check.
I have another idea, but it's greatly difficult to realize (at least for me). it's substitution of 'advapi32.dll'. client get all hashes by this library, and if it would be return always correct for client hashes, you'll never see any errors. but this way may depend base of etalon hashes, or separated folder for original files, what allow to get correct hashes. this method must be greatly elegance, but it may be traced too by a strong desire.
actually, I think any method may be faked, but also any method may be detected. imho main dilemma is how much you are willing to risk and how much this risk is necessary for you.
Based on the above - better is that it is easier.