<TABLE width=500>
; u* I6 Z$ C/ s7 f% K+ C/ P$ G. e4 ?' P<TBODY>
7 ?) g# A# p$ P<TR> A: d- c& a v" x" e8 a
<TD><PRE>Method 01 . k; w7 Y* P) _ c
=========
' u4 d. C% h% O" a: Q
& K/ T1 r! ^* p) x" Z5 PThis method of detection of SoftICE (as well as the following one) is
/ ~- s, H( _ T1 l5 V) Q- Bused by the majority of packers/encryptors found on Internet.
$ [" P& E# G7 m1 z* q @It seeks the signature of BoundsChecker in SoftICE$ j+ e6 c1 H& Z5 R$ G
/ R4 N5 {# y: p1 j" q( f! B0 I mov ebp, 04243484Bh ; 'BCHK'
: l: D- m8 h/ Z4 [) E1 p/ d mov ax, 04h
; ~. b( B7 R X' Z1 k int 3 8 F& I8 O7 J4 u; B" b( ^2 N
cmp al,4% b- ~3 B* l! c) T. T
jnz SoftICE_Detected
0 q7 ?* y0 }% q$ k5 j+ }% E1 C' L7 u0 Y: t* A) ?
___________________________________________________________________________3 F: H, J! w% O7 J, k5 P
% U7 i9 S6 j6 x! z: d" jMethod 02
" e5 ^0 r: J" D# f- J% }2 \7 u4 N" ?=========6 j' @0 W/ N) G6 T
) X+ N0 @8 j" c+ B; FStill a method very much used (perhaps the most frequent one). It is used
7 I, N: k8 t+ |1 q- C+ qto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
8 U/ f \) e5 Z; z* d; }or execute SoftICE commands...
* s9 l X+ z" u( _It is also used to crash SoftICE and to force it to execute any commands
, m. ^ s6 A5 _# P% M2 P' \(HBOOT...) :-((
* j! {2 D5 K: [9 Y p
- n* ~ d+ s" I' E+ |, GHere is a quick description:2 z$ e( F. u5 j P
-AX = 0910h (Display string in SIce windows)) e/ a+ R$ o( P% s2 x
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
+ y3 j; Y* j! j J& }8 c% i-AX = 0912h (Get breakpoint infos)" y3 ]1 p+ F8 |0 Z) {9 l
-AX = 0913h (Set Sice breakpoints)! `) J* k. D0 [8 L- g
-AX = 0914h (Remove SIce breakoints)
7 P8 \9 ?7 c0 W9 S$ L* [6 t% x5 _: Q. h6 t! m# t& H
Each time you'll meet this trick, you'll see:! G& Z* t0 h! a0 G5 \! A
-SI = 4647h1 k0 w- m/ h& L) Y$ D
-DI = 4A4Dh
2 k$ x9 R. H g% k+ ?0 RWhich are the 'magic values' used by SoftIce.# [) l. X$ }# d1 w" @0 T2 H8 ^
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
' ]& c. |, V f2 W( Y+ w0 l" w+ N `
Here is one example from the file "Haspinst.exe" which is the dongle HASP
: d0 w6 D) @! z- m, K3 NEnvelope utility use to protect DOS applications:7 m4 ^' }1 o( B% Y
" a! ?' Q3 W% E. |4 C
; P9 C" ^) a0 F* p& D6 K9 `
4C19:0095 MOV AX,0911 ; execute command.
9 g* F3 c. ?( n/ g4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).. q3 j2 R6 x, ?9 c/ g; n! {
4C19:009A MOV SI,4647 ; 1st magic value.
8 y8 [: v8 O% s6 D0 s4C19:009D MOV DI,4A4D ; 2nd magic value.
1 b& P2 v5 w" C# G! ^) W6 M4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
j: e! k, c) p* L2 Y0 F4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
8 }3 k2 P6 G) ^- N6 [% m4C19:00A4 INC CX
8 j# G- `& e6 k+ T( u! Y4C19:00A5 CMP CX,06 ; Repeat 6 times to execute5 W! W0 j1 z% k8 Z
4C19:00A8 JB 0095 ; 6 different commands.
4 Y5 Z8 }/ }& S1 e5 \! H" j4C19:00AA JMP 0002 ; Bad_Guy jmp back.
7 [- h- b. h4 J; D9 \4C19:00AD MOV BX,SP ; Good_Guy go ahead :)7 z: O" y ~! ^- }! a
$ |% `" c2 w$ j: S- q* wThe program will execute 6 different SIce commands located at ds:dx, which0 C' s9 d E, E* a* J% r8 b
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
8 H+ l; ^5 \2 |; |
% `2 M$ @5 A! ^' P& d* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
* [, c9 l+ W V___________________________________________________________________________
/ o! n( _0 J% }
* K1 |/ a3 {/ P p7 y7 U/ i
( l1 G. x; l+ S5 n8 a1 yMethod 03
( H( [/ F% d8 K( F7 U=========
4 _' R3 x7 g) G. |$ j0 X% H4 u- K- e
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h @5 B4 c' H0 e) ?+ E b
(API Get entry point)+ f% G2 c+ S- s2 z
& X {3 i+ E( r4 P; ]
; O1 v! x4 L. `* q xor di,di
) e2 n( s$ Q' k mov es,di, E e1 f" k7 T: u) o, `
mov ax, 1684h
( K3 y8 I1 \; D% C* i mov bx, 0202h ; VxD ID of winice- {0 x) C3 t7 G+ z
int 2Fh
& G" w7 W* ^: t( [! q# S- J mov ax, es ; ES:DI -> VxD API entry point" d# N5 A: w) M8 c/ ^+ t
add ax, di
2 G8 w' Q D1 e1 H# L: e test ax,ax
0 p2 s8 _% M/ \) U$ ^- ?' d jnz SoftICE_Detected
! C# x/ Z+ f. D5 o
: t4 q E. v, w2 q___________________________________________________________________________9 f5 F! p& g' D- {6 _$ h
! F6 X. \6 f: w; P4 O( R. JMethod 04) d o0 k: t% s! J5 y
=========
F+ h$ W! v" r" C9 Q
9 @* c' H0 Y2 L! P9 ]Method identical to the preceding one except that it seeks the ID of SoftICE1 g8 D3 ~( e) K$ B
GFX VxD.
8 A/ ~* {) T$ ~7 T7 H6 z) J
- Q: R2 O0 l! ^: }0 T& Z( v xor di,di% j2 {% }6 `$ L9 u, P# `5 c2 p1 T
mov es,di
/ }8 v* J6 |( _+ U) | mov ax, 1684h
$ }) C. y8 Z; l5 T! p) [8 ` mov bx, 7a5Fh ; VxD ID of SIWVID& e' v- e+ `/ B, @
int 2fh# H9 M. b" p, x" U; e. g4 w; w+ x
mov ax, es ; ES:DI -> VxD API entry point
, N6 v1 f; u5 O/ f5 b3 y5 H" l add ax, di- `4 V" g2 u9 _8 y
test ax,ax
4 P# G4 o% R j8 s' ` jnz SoftICE_Detected9 [4 c+ r1 J" M; @) }
( n$ \2 [! P* Q1 j( h& j; o__________________________________________________________________________
# _) k. N( @5 e# _ X* t2 s& Q3 |" }, X- S- S4 }0 |4 A2 D
: `# y1 i$ H. wMethod 05
3 A( z* M+ z( z: t- q& p=========
6 m2 T, H+ e& M8 `* ~
/ S1 u6 r( C7 |- q& t2 ?" e& YMethod seeking the 'magic number' 0F386h returned (in ax) by all system
3 |+ V/ Q: G5 J+ w A' t4 t7 Z4 X: Adebugger. It calls the int 41h, function 4Fh./ v2 s2 [2 W; X! b6 h0 D; G
There are several alternatives. * l! j& n+ c1 |+ {( x, N+ x9 M
% w C& n" b4 z) r% j" ]3 nThe following one is the simplest:
0 e1 N; c% a& U T, i0 J6 u4 E0 n% w. u
mov ax,4fh. Q, \6 j! C2 U
int 41h
; E% N3 @0 K, s cmp ax, 0F386
/ ^+ b( h& m$ a" p& ?0 ^ jz SoftICE_detected
' O9 U$ P+ u0 [( Q" ?3 Z
/ r( s/ Q. p w) d. q; y# c, H6 ^) J- O# }) `% R
Next method as well as the following one are 2 examples from Stone's
0 w/ ^* |1 G/ r/ E"stn-wid.zip" (www.cracking.net):
: G0 x) Q% s8 g& A/ B+ M+ Y
( U/ O* i+ u4 s" W- ] mov bx, cs
# O7 r( I8 I9 g lea dx, int41handler2
0 T0 M0 J8 c7 g xchg dx, es:[41h*4]0 d6 X: S1 F2 Y9 w2 ?9 Z" q# z
xchg bx, es:[41h*4+2]
& Q: k% O7 B" K6 X5 ~' ^ mov ax,4fh
/ Z: M8 u" H& ^ int 41h4 B) B# x4 ]( o# D) x9 V
xchg dx, es:[41h*4]
- z* b! z( \; q5 z. g xchg bx, es:[41h*4+2]+ C! m* ?1 H' r. E5 B$ d/ B! I
cmp ax, 0f386h
8 @9 N& g: ~/ D* L jz SoftICE_detected
% P0 Q1 Z% h, j" i6 A! t% D7 {* ~ |3 K8 Z( p: o
int41handler2 PROC
5 T d+ q% \7 o iret# ?8 s& [7 e. L# d f+ ]
int41handler2 ENDP
/ x* n! P3 `* ~% m+ g2 P
! W/ y& k7 x6 j& N# P( o5 W9 ?
& \1 x8 l M; {: l& c_________________________________________________________________________
1 R7 Q% ` w( v N4 z6 [* {, }2 z& C7 e, I9 B
) L5 A) W6 z, l( V$ Z1 O' j& F3 M# M' N
Method 06
6 H: {8 j7 \/ p* ?, B& }7 X=========. T& s: A7 w Z2 y
! k' K& L! J2 N
( v. ^5 ^. x, W {/ b& s2nd method similar to the preceding one but more difficult to detect:" K1 w" u) f3 R% m7 P U
2 Y2 V% b& |0 P1 |+ A. {
) Y9 U+ u2 O; v! n
int41handler PROC9 A- S# F c5 Z
mov cl,al0 R$ W) D8 i" m W' \& n
iret* S! J; M! M" B
int41handler ENDP
5 z- A0 o$ n! v5 h- q \6 X/ h. O
6 j d3 Q7 `# z) \ T$ p7 e. B' u* w! g+ ?* _2 f
xor ax,ax
/ a' I1 F0 Z$ `9 p+ z* w4 w% ^ mov es,ax
* e5 o4 I( ^5 u mov bx, cs
; O. a \' Y+ h' A, H; f lea dx, int41handler
( s8 b% H+ [; G0 L* z xchg dx, es:[41h*4]7 ^3 ^: ^2 i: G. P& [$ M$ c9 N
xchg bx, es:[41h*4+2]( q5 Y4 F0 _7 F. |- E
in al, 40h
9 t# u) M$ P% F& C3 o+ [! N xor cx,cx% v9 W$ l. W0 O8 ]7 R
int 41h9 U6 F0 L6 j3 \2 v. T- B
xchg dx, es:[41h*4]1 ]5 x3 Y% d. V% k5 ~# c
xchg bx, es:[41h*4+2]3 `: g( W Y9 k# _1 S
cmp cl,al5 T1 f- m! J3 L% l8 F( b; j
jnz SoftICE_detected
. p' C7 t/ k' W% V6 ?/ w* h, w- F% K9 F
_________________________________________________________________________3 w9 m/ F6 [# c; W3 F) ~
2 c; E7 V3 C' N7 h1 ^Method 07" x7 e$ N$ B9 N0 ~8 `
=========8 M5 X& F) l9 d6 t! T1 u
/ ]' P( J7 x. U v0 _) i2 vMethod of detection of the WinICE handler in the int68h (V86)/ U* a* G$ r3 Z2 a' s% [$ u4 p! z: s
$ H& Q5 j: j2 f) X mov ah,43h
; b; z6 i7 B+ k% D int 68h( @# N1 m1 h V
cmp ax,0F386h
/ l& V: H Z/ x/ n7 c8 R# y jz SoftICE_Detected. D1 ~) v$ A3 e, r
3 d; w+ s L% y2 g" G( W6 q3 l6 N# e1 h4 P- N& X, K5 G8 L
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit, L1 j$ h% v7 o4 Y# ]
app like this:) h3 n( z6 f' _' _& a
0 c& o( k! C; u. q BPX exec_int if ax==68
' b6 ^. p- a1 c (function called is located at byte ptr [ebp+1Dh] and client eip is2 ~8 Z+ w8 ~% [$ K
located at [ebp+48h] for 32Bit apps)
1 M C7 [ M! _$ b__________________________________________________________________________$ I! r& Z% v5 X* t* v, c! M: E
4 T( s% J/ s4 p) N# V+ G( F
4 B- F/ W( @ y- n0 y
Method 088 _7 Z7 \3 `8 }9 q* _" G
=========) j$ n& l0 E7 M c5 h6 f. @
) N5 S" [0 g4 c% { A
It is not a method of detection of SoftICE but a possibility to crash the
& ]+ ]5 |+ |1 B" q# t3 u! |/ y3 c+ Ksystem by intercepting int 01h and int 03h and redirecting them to another
% p. H3 ^2 N2 _: Broutine.) H1 K& L( X" j
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
3 Y e9 K! v9 Lto the new routine to execute (hangs computer...)
1 \) J0 {. o4 w; G) R" T" ~5 u0 E8 O. t
mov ah, 25h
3 Y6 T8 U/ p9 F6 N/ D+ B7 j mov al, Int_Number (01h or 03h)" Z# O. [% a$ D9 |* `
mov dx, offset New_Int_Routine
3 J0 A: e2 B, J; M int 21h1 e, D( y& T8 ~7 i5 D
& _3 q$ f1 N2 o( m$ {7 K7 T2 ?' J! @! T__________________________________________________________________________
* E9 o- j% ~ |& N
5 D6 h, G# g$ W' X; T# y& dMethod 09, x3 u* c; Q/ k ?$ v! H* t
=========
+ M# R/ a) i% E6 K7 O- ]' x" X3 K3 o J* W2 w' E0 z1 ^
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
; x2 w1 ?* ~ C3 gperformed in ring0 (VxD or a ring3 app using the VxdCall).7 L/ r& _1 d0 N
The Get_DDB service is used to determine whether or not a VxD is installed
4 p7 S5 N4 D$ e0 h" y# s7 jfor the specified device and returns a Device Description Block (in ecx) for
/ G$ K$ M2 e) j, j3 ethat device if it is installed.' E- c; V8 {, u
9 Z2 N2 o1 \/ ^' Z/ X; @ mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID, s/ j3 b5 x D+ W8 z8 h+ G
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)9 C/ k" t, X- b
VMMCall Get_DDB2 f$ v% p& F+ S- i
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
- g# b( ^$ J" ]2 i' Z4 a, U/ G# y6 l9 E* o3 L9 H
Note as well that you can easily detect this method with SoftICE:
5 I3 ]* t, D; W! Z- i6 T bpx Get_DDB if ax==0202 || ax==7a5fh
- u& w, X; s. ^$ l$ }5 J) B8 r' U7 ^1 X% e7 G$ H
__________________________________________________________________________
5 E# G+ e, k% t9 c7 y4 R
7 Z% ?# [0 e% D- {9 |9 lMethod 10
* v$ H$ U- }% _=========% o6 Q* q0 v. @/ c9 N# i
5 G" D3 i) G. U; X$ m
=>Disable or clear breakpoints before using this feature. DO NOT trace with+ D. T9 P+ I* B" K4 j; Y: _
SoftICE while the option is enable!!# z3 B$ E, n. v3 X3 A. g3 u! w; p
/ z9 H4 n/ R1 P+ K, m" U0 _0 qThis trick is very efficient:7 ~2 h0 f) H' @6 Y. W" g4 K7 T
by checking the Debug Registers, you can detect if SoftICE is loaded
" K. e& w# w6 r: C& p: n: U0 z7 S; _(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if( w5 j. A. s% u
there are some memory breakpoints set (dr0 to dr3) simply by reading their) u% `. X" A! a
value (in ring0 only). Values can be manipulated and or changed as well3 l% Z4 v0 G: Y- T
(clearing BPMs for instance)
# @" D! H' C) z
4 T- E5 z( a$ `' o__________________________________________________________________________% ?0 P( V p" u. [9 A3 M: C
( g! F- S0 }3 W% qMethod 118 j, ^! I9 h9 D8 s! i' E
=========
* m8 d# [6 D8 b' p% O9 O* T) ~, C2 @& |/ y6 X) g
This method is most known as 'MeltICE' because it has been freely distributed
" s5 B; T$ \0 F, W4 svia www.winfiles.com. However it was first used by NuMega people to allow
+ A! C, w d1 h; a, E& q& k% K! b) nSymbol Loader to check if SoftICE was active or not (the code is located4 {( S8 s) L" W3 K8 e C* h
inside nmtrans.dll).
, N+ o9 K3 h2 x) N
- A; p& Q' m1 N3 ]* AThe way it works is very simple: ]8 C. d7 p5 o7 i- m
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
2 u2 \+ S' G. F) _1 F, G/ r; LWinNT) with the CreateFileA API.! d; U3 o) O$ D* {# S4 e% q
" n0 K, r" |( h2 m; E
Here is a sample (checking for 'SICE'):
9 I: G8 d: A. r) k; D' V b1 A1 q3 M, ?
BOOL IsSoftIce95Loaded()7 \7 @3 p6 Q2 n5 ^/ X
{6 E2 j; U5 }& `2 a
HANDLE hFile;
6 I; q2 Q) _# Q% j! J, ? hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
8 ~# I! n% Y' e, Q8 V! Q FILE_SHARE_READ | FILE_SHARE_WRITE,
: R, y8 I# R5 s, w+ c6 q7 { NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);3 A% W4 i3 H4 {9 v! M
if( hFile != INVALID_HANDLE_VALUE )( B" k0 }! {+ S7 T. f1 F
{+ m, e$ \: A$ B; ^) l& z, ]! k
CloseHandle(hFile);7 |! ?/ x3 E2 G) N( ?
return TRUE;
" v1 i$ e( n. s/ F2 q }
8 k% @8 l4 n4 `8 ^5 l0 _& t return FALSE;& {7 p* ~7 D, `" E) N) d
}- i! v6 w" a* m+ k# ` W
; E* ~8 z$ ^. p* T( y, u
Although this trick calls the CreateFileA function, don't even expect to be2 S5 Q- ?" S8 G( S2 o. y. X: q
able to intercept it by installing a IFS hook: it will not work, no way!- z: ^& O. c+ W0 ]
In fact, after the call to CreateFileA it will get through VWIN32 0x001F/ X% B' L; C4 v/ w( e% s6 T5 i# [
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
; @! T+ D: a* h7 f6 Jand then browse the DDB list until it find the VxD and its DDB_Control_Proc! w/ p# E; A6 y0 S; A& R" _, C
field.
7 |* t' R1 A# [In fact, its purpose is not to load/unload VxDs but only to send a 3 d: j: I8 O1 Y/ J' J- a
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE): S6 {' J' N$ ^3 `; r. c2 x
to the VxD Control_Dispatch proc (how the hell a shareware soft could try5 Q& Y) U# t# z& _+ r
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
2 s$ r0 r+ V" e% p4 T# q$ wIf the VxD is loaded, it will always clear eax and the Carry flag to allow/ N$ l7 u. l0 X% U; [5 J
its handle to be opened and then, will be detected.1 p8 p! {4 d9 @3 m0 H! }
You can check that simply by hooking Winice.exe control proc entry point4 Z& `+ F8 _$ k8 I
while running MeltICE.
, c8 Z4 C* @, A2 j& L% m: g& [" f" ~
# L3 I3 m7 k4 r5 X
00401067: push 00402025 ; \\.\SICE. B/ W8 ^5 @- C, S
0040106C: call CreateFileA
$ l$ N5 j" z+ B8 T& D0 C' M 00401071: cmp eax,-001
) G( y( a8 ~" Q3 b, E" B# n; D 00401074: je 004010917 K& s7 v$ E4 C
6 ]$ i7 U" `# e% J4 J+ b4 y
* C, A" f8 A& z' `: w/ ]There could be hundreds of BPX you could use to detect this trick.7 Y/ ~5 S3 s- f
-The most classical one is:
0 n2 Q+ l4 R7 b, K BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
! W, e+ @4 Q- T% \ *(esp->4+4)=='NTIC'
+ X8 d* r+ T. w! P1 b$ t( j N7 I1 g* `: Z5 a3 E0 ]
-The most exotic ones (could be very slooooow :-(
$ K9 V* T3 I" t' v5 ?" p: V6 w BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
8 M7 c' c n& l' ]" W; R ;will break 3 times :-(' u4 R; x) v/ K& ^
# N3 s+ c( }6 u-or (a bit) faster:
' Q1 r! D* c* o BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
+ C# M4 U( K* L. M
' y/ S7 `( J$ v6 s& i BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 6 w# b8 ]8 R' b- F, [4 q; C
;will break 3 times :-(( @, N4 N3 ^1 U' N0 h
# D# O( T) ?" J4 D/ U-Much faster:" u V3 j6 ~% j# @, s
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV' M8 X1 l3 S8 h6 i/ v
/ U' J' R, L; _4 R7 N4 _, |( k
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
4 ]# k6 |* v7 d' ~) ffunction to do the same job:; { M; _! Y ^4 r- X- z9 W. c
& c: {8 U7 G; F6 i
push 00 ; OF_READ
; C7 R: T) e) G9 Q mov eax,[00656634] ; '\\.\SICE',0
. q0 N6 O- h* `0 l push eax6 u$ n3 M+ F& d O) ^; f9 r
call KERNEL32!_lopen
" O, n2 |% V |# S+ \ inc eax9 u: `8 I$ }* T8 o
jnz 00650589 ; detected9 y/ [" t/ x3 g: Z4 f! f; W
push 00 ; OF_READ$ m* k- W* z( H) f
mov eax,[00656638] ; '\\.\SICE'
" }) f' C6 ~0 B/ N7 s' n" g, d push eax1 T/ e6 ]& N# F+ ~; L+ {" J) J1 _
call KERNEL32!_lopen( [; v: X; m( ^
inc eax: z1 _4 C" p9 Y+ B4 \
jz 006505ae ; not detected! _8 _8 r4 X @) j5 w
5 O9 Z% [9 d( U8 F8 d, v9 j
: F/ ]% w" Q) J0 Y. Z: y$ |__________________________________________________________________________
* `* K: N: X7 k# _9 a; ?) Y' r# @
0 D8 E6 o7 V' p! f; o' @4 s4 I' f* f) vMethod 129 D( {" ~5 f: p( |1 M
=========, H& B/ r! Y6 i$ W' R" k
! b- p, T! U' C
This trick is similar to int41h/4fh Debugger installation check (code 05 l5 h$ ^) D% [0 l* Y
& 06) but very limited because it's only available for Win95/98 (not NT)
" l) ?. Q9 h- N3 S8 pas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
5 a. ]3 Q1 I1 z# A; V2 h% Z6 E3 o! r" _; X
push 0000004fh ; function 4fh; \7 z, |; t; w7 b) L b- M5 s4 I
push 002a002ah ; high word specifies which VxD (VWIN32)* W5 w5 z i7 {" n) x
; low word specifies which service6 e$ S, _$ m( h. X- h
(VWIN32_Int41Dispatch)
/ C) q3 z1 }" M- J; A2 e2 v0 } call Kernel32!ORD_001 ; VxdCall
; u4 m+ Z$ h' t6 C. s- Z! Z- F cmp ax, 0f386h ; magic number returned by system debuggers$ }, a( G5 r$ T# H- j( m
jz SoftICE_detected0 p# P0 s* |* J: X2 G
) V! G3 |& B8 Q: c+ SHere again, several ways to detect it:
5 `" p( A$ G% U' W" ^( Y- S& y& ~+ U+ `/ }- j7 @! W! _, ~3 U+ m
BPINT 41 if ax==4f
3 P# _3 h9 @8 E) l$ G% i8 q2 ^& E! m% r( f
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
, |* F% x+ D! J4 A7 A; f( X$ b! Y5 s' I& r% ~1 D D1 W
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
5 I: y3 B- t/ m( i# ?
& ^* s' Z" f$ G# i3 t& ^ BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
7 {; L* [% g* _1 r! ]: r
4 ?& b9 n6 {$ Y" f! u__________________________________________________________________________
. {+ J% |: P4 r& o" l5 t! {: `/ p7 T
Method 13
/ U' g B' Q8 v. C" w# K6 j=========
1 S6 ?- l' P$ k& n+ N6 b$ `3 g1 }: f3 O- k, {6 R# b
Not a real method of detection, but a good way to know if SoftICE is" }& j0 ~6 C+ k/ q" E9 l+ o( S! H
installed on a computer and to locate its installation directory.
% {( {2 ], d: [5 ~3 TIt is used by few softs which access the following registry keys (usually #2) :
3 e! y$ S8 [+ L- E6 a A
# f+ Q- ?& V' U5 S- {' M' \-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
% ~4 M. g3 o1 b$ x1 t1 `; M+ l- M\Uninstall\SoftICE0 v7 ^! h- A- g
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE6 d3 s2 X5 g1 M, _
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 n6 o" V( e. ^! M- Z\App Paths\Loader32.Exe
! Y# L0 ~4 R3 H& V/ w$ ?7 {3 o+ P* E+ ^* Y0 C: ?
7 N$ w' v _3 [' lNote that some nasty apps could then erase all files from SoftICE directory
6 Z. R9 W2 U [1 d8 g0 ? d% l# ~(I faced that once :-(
- M# ]$ `+ `+ U7 I/ D: u
! c+ k, }2 m3 P- ~! E2 a( lUseful breakpoint to detect it:. e2 W! ~0 D8 J/ U( n2 |
- G. l; m/ T. ]2 Y' u$ i- { BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'+ o& {7 B" z1 K1 U
: |2 B9 n# w! @: R+ F/ N, N
__________________________________________________________________________
( c1 [; v4 `4 I! ^9 v% R% @8 ^ |& s+ Q
- i8 L1 B( N" RMethod 14 7 u( E2 L9 P- ~+ G. X1 x
=========3 V0 L5 `: x6 Z0 b
2 m4 V" w6 }* }5 {$ j1 ^4 [A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose/ {/ `2 O" j( f+ b; c# B
is to determines whether a debugger is running on your system (ring0 only).
6 Y+ C, g ] m; M: c4 c. p
M, h8 B3 z) y: P/ [7 S1 v% `5 z$ v VMMCall Test_Debug_Installed
) n, |% ^5 H" Z3 t' F- [ je not_installed8 M* U9 x* q/ q5 z% S2 E
) i0 \+ p. t$ @4 q4 i
This service just checks a flag.0 e7 _% Q% t+ P/ ]( M
</PRE></TD></TR></TBODY></TABLE> |