Manko
April 9th, 2003, 01:40
Hi, all!
I guess this is nothing new to most of you, but...
Someone once posted a small sicedetecter that using ntquerysysteminformation got a basepointer to something that contained, among other things, the names of all (?) services and just scanned through them and found NTice, even though I had hidden it with Nicolatesla20s patch...
Also now Soldat told me that armadillo uses openservice to find out if we have NTice service running. (I have not done armadillo ever yet. Believe it or not.)
Someone once, when i was even more of a newbie, said you have to deal with these things on a case by case basis. While that is very true, many times for many reasons, I never liked that answer... So I thought about this simple idea, but only just now actually tried it.
Anyway, I just tested yesterday to rename the service, rename all important occurances in the registry and rename all affected textstrings in the 3 important sice-files... (Those usually patched. Not actually all three though... One didn't contain the strings... I think...)
It worked ofcourse. Now sice is superhidden!
Just remember that if you have patched it before, you ofcourse need to find ZTice aswell as NTice. Don't forget, search BOTH unicase and c-style textstrings!
(And use same length on names...)
/Manko
I guess this is nothing new to most of you, but...
Someone once posted a small sicedetecter that using ntquerysysteminformation got a basepointer to something that contained, among other things, the names of all (?) services and just scanned through them and found NTice, even though I had hidden it with Nicolatesla20s patch...
Also now Soldat told me that armadillo uses openservice to find out if we have NTice service running. (I have not done armadillo ever yet. Believe it or not.)
Someone once, when i was even more of a newbie, said you have to deal with these things on a case by case basis. While that is very true, many times for many reasons, I never liked that answer... So I thought about this simple idea, but only just now actually tried it.
Anyway, I just tested yesterday to rename the service, rename all important occurances in the registry and rename all affected textstrings in the 3 important sice-files... (Those usually patched. Not actually all three though... One didn't contain the strings... I think...)
It worked ofcourse. Now sice is superhidden!

Just remember that if you have patched it before, you ofcourse need to find ZTice aswell as NTice. Don't forget, search BOTH unicase and c-style textstrings!

(And use same length on names...)
/Manko