From Collaborative RCE Tool Library

Jump to: navigation, search

Antisptd

Tool name: Antisptd
Rating: 0.0 (0 votes)
Author: smoke                        
Website: http://www.woodmann.com/forum/showthread.php?t=11870
Current version:
Last updated: July 1, 2008
Direct D/L link: Locally archived copy
License type: Free / Open Source
Description: Antisptd is a driver that makes it possible for SoftICE to load when sptd.sys is present. It uses the method described by Kayaker (see related URLs below) and that is, by removing the notifyroutine sptd sets to prevent ntice.sys to load. After ntice.sys gets loaded, it restores the notifyroutine and the keyboard hooks in i8042prt.sys that have been screwed by the sptd.sys


How to use it:

Just put the startsi.exe in a directory with antisptd.sys and execute startsi.exe.


Compatibility issues

The driver should work on XP SP2/SP3 with the latest SoftICE installed. I have no idea if it'll work on XP SP1 (cause I have used hard-coded values to locate the patches). If it doesn't work, feel free to modify the sources and recompile the driver yourself. ;)
Related URLs:
Forum thread discussing anti-debug features of sptd / Daemon Tools:
http://www.woodmann.com/forum/showthread.php?t=9201
Another forum thread with some (possibly) additional information:
http://www.woodmann.com/forum/showthread.php?p=64335


RSS feed Feed containing all updates for this tool.

You are welcome to add your own useful notes about this tool, for others to see!



If you find that any information for the tool above is missing, outdated or incorrect, please edit it!
(please also edit it if you think it fits well in some additional category, since this can also be controlled)


Views
Category Navigation Tree
   Code Coverage Tools  (13)
   Code Ripping Tools  (2)
   Helper Tools  (3)
   Hex Editors  (13)
   Memory Patchers  (7)
   Packers  (20)
   Profiler Tools  (11)
   String Finders  (10)
   Tool Hiding Tools  (7)
   Tracers  (22)
   Needs New Category  (3)