nikolatesla20
February 7th, 2003, 14:14
This is my first loader program and I must say I am very proud of it so far, it works pretty well I think. I finally figured out how to do the "loading" 
OKee, the whole point of this program is for those of you with Win2K/ XP on their systems, and SoftICE. SoftICE likes to put a INT3 on UnhandledExceptionFilter , and some programs check for this. Also, SoftICE hoses int1 up in the IDT.
You ask: WHY DO I NEED THIS?
Well, no one really "needs" it, but if you have hidden softICE as best you can under win2k / XP and a program still detects a debugger, chances are it's using either int3 or int1 detection. And this program will fix both. (well, not int1 just yet, but soon). So you could give it a shot at least...
Rather than having to try and BPM on UnhandledExceptionFilter, and then step thru code, or not begin able to BPM at all anyway, because of SEH's, you can use this little utility I made up, and it should work. It heals UnhandledExceptionFilter for you.
By the way, you also will not need to have SuperBPM with this either.
ALSO I have a driver that I've written to patch INT1 as well and it works great, but I am still integrating it into this program yet, going thru all the service API's takes a while! So be patient I will have it working soon.
hxxp:\\webpages.charter.net\nikolatesla20\PatchUnhandledKernel.zip
-nt20

OKee, the whole point of this program is for those of you with Win2K/ XP on their systems, and SoftICE. SoftICE likes to put a INT3 on UnhandledExceptionFilter , and some programs check for this. Also, SoftICE hoses int1 up in the IDT.
You ask: WHY DO I NEED THIS?
Well, no one really "needs" it, but if you have hidden softICE as best you can under win2k / XP and a program still detects a debugger, chances are it's using either int3 or int1 detection. And this program will fix both. (well, not int1 just yet, but soon). So you could give it a shot at least...
Rather than having to try and BPM on UnhandledExceptionFilter, and then step thru code, or not begin able to BPM at all anyway, because of SEH's, you can use this little utility I made up, and it should work. It heals UnhandledExceptionFilter for you.
By the way, you also will not need to have SuperBPM with this either.
ALSO I have a driver that I've written to patch INT1 as well and it works great, but I am still integrating it into this program yet, going thru all the service API's takes a while! So be patient I will have it working soon.
hxxp:\\webpages.charter.net\nikolatesla20\PatchUnhandledKernel.zip
-nt20

 . So even my loader can simply ask for GetProcAddress and the returned address would be correct for any process. This is the address I use to patch UnhandledExceptionFilter in the loaded program.
. So even my loader can simply ask for GetProcAddress and the returned address would be correct for any process. This is the address I use to patch UnhandledExceptionFilter in the loaded program.