Log in

View Full Version : Hiding SI NT2K :)


+SplAj
July 8th, 2001, 08:23
Hi fellows

I saw a few posts re the topic of anti-debugger cloaking for our beloved tool SI. We all know about Icedump team excellent work
and Frogs+ as well....but I saw a few Q about Win2K. I always point ppl in the way of Nticedump and Pntice from EliCZ who coded a nice patcher for us with an *.ini file for us to update.
This covered 3.24 very well. I made one for 4.01 but not 4.05 as I patched directly myself as well as the latest ntice.sys.

Well I failed miserably at the w/e to make pntice.ini for the latest 4.2.1 Build 57 (or 58) of NTice.sys for everyone. So i attach my patched files for you to play with. I think you know this is for Win2K only

Rename your original files before copying mine to the relevant system / Si directory's. Don't blame me for any PSOD !

happy reversing in peace.

+SplAj }>

drak0
July 8th, 2001, 12:54
Hey Splaj...

I tried your files... and SI wouldn't even start. But I'm not sure if that means anything because with the version of ntice from numega, SI would lock up my system before... With your version, it just says that ntice.sys can't be loaded (0xc0000221)

I have SP2 btw... do you have that? I wish I could revert back to SP1 cuz i can't get SI to work w/ sp2...

-drak0

DGR
July 11th, 2001, 04:20
There is a quite old tool called NTall which does a pretty good job. However, it didn't work with the latest driverstudio 2.5 beta2. Then again, the symbol loader couldn't be used either coz it thought sice wasn't active (symbol loader from ds2.5b2 that is) so it's more a beta-related thing I'd think...

But give ntall a shot... it's quite fine. Altho once u activated all the protections/detections u can't disable them nemore (causes things to lock up heh). Can be annoying, but still... it's a nice tool.