Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   Hide SoftIce under XP (https://forum.exetools.com/showthread.php?t=2110)

Lindwurm 04-25-2003 05:36

Hide SoftIce under XP
 
Hi there,
is there anyone who can help me with a tool which hides SoftIce from being detected by an anti-debugging routine.
Important: I'm using WinXP with NuMega Driver Studio 2.6 and SoftIce, so FrogsIce is not working and I have no luck with IceExt.
I tried OllyDbg 1.09b instead as a different Debugger but this tools is identified by the exe as well.
Maybe there are other hints to work around this anti-debug. I'm working on web2date 2.0 (Data Becker).

Thanx
Lindwurm

asterix 04-25-2003 06:39

Look this: hxxp://stenri.pisem.net/IceExt025.zip :D
Probably you need to update the DS2.6 on DS2.7.
Or to use win98+icedump 6.026. :)

JMI 04-25-2003 14:43

You will find good information at the RCE messageboard. There have been several patches offered for hidding Softice and for making Softice work with WinXP.

We are having some issues with our backup at the moment so the search function is not working very well at the moment (counters have not been updated) but hope to have these issues resolved shortly.

Most of the patches are for D.S. 2.7. These threads deal with the issue: [remember to change "hxxp" to "http" in your browser.

hxxp://www.woodmann.com/upload/showthread.php?threadid=4679

hxxp://www.woodmann.com/upload/showthread.php?threadid=4636

and

hxxp://www.woodmann.com/upload/showthread.php?threadid=4031

would be a good start.

Also there is a patch for attempting to get D.S. 2.6 to break, found at

hxxp://www.woodmann.com/upload/showthread.php?threadid=4701

Generally reading through the Tools of the Trade there would lead you to many useful threads until the search function is straightened out.

Regards.

banshee 04-26-2003 02:08

:D JMI, you didn't notice the above CLICKABLE link :D

JMI 04-26-2003 03:10

No excuse SIR. :D Omission corrected, SIR. :D

Regards.


All times are GMT +8. The time now is 11:43.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX