<TABLE width=500>
* [2 [ n& Q4 N<TBODY>2 {9 z5 }# Z/ i/ c4 I4 W
<TR> ]+ O1 X; U. S) P* P k2 b
<TD><PRE>Method 01
) t2 X' U) I k( `=========/ ~+ j& G* Z" R P/ W
9 }' p S7 e9 h4 H8 XThis method of detection of SoftICE (as well as the following one) is* F8 r- Z( }$ Z; d8 ^. G9 J
used by the majority of packers/encryptors found on Internet.0 S) r. T5 k! U: \' s! r
It seeks the signature of BoundsChecker in SoftICE: A. y! T+ A! m1 I$ i
3 N2 v; V4 \7 p4 C% o
mov ebp, 04243484Bh ; 'BCHK'
! n9 G1 P- H$ ?* t5 Q6 K mov ax, 04h
+ ^$ d6 Y7 G% ]+ V& U1 @+ @ int 3
" l6 R4 } D" V cmp al,4
4 A* T( i7 z' w* y4 S% | jnz SoftICE_Detected9 K& g" E: D* c1 W* ]
; Z% |) O- H. ~- ^( w, n' } {___________________________________________________________________________
1 Z- c* W2 a2 X6 E' k
8 ~0 ~( Y3 h3 f- rMethod 02
% w9 ]6 x* G1 a2 @/ q# F& I=========; U2 h2 e/ W: M' Y: k
* L, u* p6 Y" Y" k$ a1 A1 `Still a method very much used (perhaps the most frequent one). It is used
3 l8 d1 f3 z8 i1 v- Z4 Ito get SoftICE 'Back Door commands' which gives infos on Breakpoints,7 f7 L+ G9 G+ Q" {
or execute SoftICE commands...
# L+ C' }9 J$ A; i& u: s% o kIt is also used to crash SoftICE and to force it to execute any commands+ ^* s& l+ C# V9 {* F
(HBOOT...) :-((
l8 B) z# c5 {3 ?; A, p
' v: [2 \8 k4 T1 R8 C) M' sHere is a quick description:
& v0 y: |8 N5 e1 _1 s. |-AX = 0910h (Display string in SIce windows)2 F! j0 U1 M: {4 b. G8 l
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
G) [3 j* P# G! I-AX = 0912h (Get breakpoint infos)& j$ g" X( R$ \2 |* k& S
-AX = 0913h (Set Sice breakpoints)
3 f$ k" a) O4 _+ }-AX = 0914h (Remove SIce breakoints)
8 w6 ]8 |- i! C3 A, E) I# a6 [( ~! i
Each time you'll meet this trick, you'll see:; s4 s5 s1 f. n- M8 P
-SI = 4647h
4 V& ]3 @. D, M; i* H) p-DI = 4A4Dh& S9 A& T/ W% X5 p! D" A. W0 H
Which are the 'magic values' used by SoftIce.
2 G4 x/ |9 R$ |7 {2 u0 EFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
1 k. }5 G! g7 B/ {/ c) w3 M) w; J( A( J3 l" U
Here is one example from the file "Haspinst.exe" which is the dongle HASP) W: V" t" [- C0 F
Envelope utility use to protect DOS applications:9 A6 \- Y7 c: b0 n6 C/ z
; P9 ]4 E& g g6 e$ }- @8 k7 _2 a% D9 K7 Q+ y+ X
4C19:0095 MOV AX,0911 ; execute command.8 ?) H" Q/ Y5 P" y U& U
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).. M L4 P, `6 y4 ^/ l* s, o
4C19:009A MOV SI,4647 ; 1st magic value.
" q7 W# ~0 {! A0 h4C19:009D MOV DI,4A4D ; 2nd magic value.6 |8 g2 d& ~& a* r+ {- }# a
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)' _# m, r+ c- b/ @, d [/ T
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute, [# B; B: E) y, |3 t2 ^, u0 Q
4C19:00A4 INC CX6 P) v$ P3 M$ o7 g" m
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute) r5 D/ E" p5 P$ N
4C19:00A8 JB 0095 ; 6 different commands.
0 s3 Q# R" k8 C3 S" t6 i$ P9 c! [; N4C19:00AA JMP 0002 ; Bad_Guy jmp back.
+ ~( p* A1 r3 z: Y' B4C19:00AD MOV BX,SP ; Good_Guy go ahead :)( N2 T, v! K5 U9 {
/ ^0 _8 J+ Z' EThe program will execute 6 different SIce commands located at ds:dx, which
" ^; T3 | t, t9 ?, e2 jare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.' e8 j! J7 ^6 r- e6 y
7 @) r3 L- u+ r- r/ y& z2 U) S* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
4 j5 ~* D: q8 c. E' e; [___________________________________________________________________________
% Q3 ?* P. f. P1 R5 g! ^, h- l* \+ r2 Z
# ?( \$ F5 |+ _. a6 J; K- \Method 03' G' O7 a$ ]/ D" s( Q. |. y
=========
! u; @8 j" g4 F$ j; g( ^% }: R0 J, \$ I, m) }
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
& R; }5 _+ o m(API Get entry point)/ }: v- T4 w. G3 a8 J0 P& u( _+ l
: B3 `: n R' H+ x/ K4 s( l4 w: L* m1 s$ s7 g+ t0 y
xor di,di
( x* N1 B- n% F2 Y+ j* { mov es,di" U( I/ J9 q- Y% s1 U
mov ax, 1684h - Z- o* D: I) S
mov bx, 0202h ; VxD ID of winice9 H" \4 l' ~: N$ f2 R6 `
int 2Fh
5 @( ]5 g* _/ h2 Y& S# |- I mov ax, es ; ES:DI -> VxD API entry point2 ~, E. z' Y C, ?
add ax, di
+ h# H! ^4 [' X; s u5 } test ax,ax
- [$ X+ _$ Q: w, ~' o, M jnz SoftICE_Detected
: F; T$ Z2 y4 e; ]! W, H. h) I( X- p! A0 S8 |* }
___________________________________________________________________________1 W; g/ Z* n: D. H) \* G
4 |# t7 }9 c3 W3 o1 K1 F5 a
Method 04
$ S/ v4 _8 F1 F! O6 R* w=========
' S. [. k/ `) n% W- \( |! b# o, z, Z# o
Method identical to the preceding one except that it seeks the ID of SoftICE- A% X/ v+ K) P( ]
GFX VxD.0 \3 v# T+ c, P. _; A3 v
. Y; m; ^0 A# x
xor di,di" ?$ g2 r* [# D
mov es,di
; P5 m/ v m! x& ]! v! ^" c3 B' x mov ax, 1684h - V2 t$ g; s! Q: q4 n
mov bx, 7a5Fh ; VxD ID of SIWVID
" O8 u8 z# Y( Z4 o int 2fh
3 w. t% ? p& O! ` mov ax, es ; ES:DI -> VxD API entry point! e0 ]' k5 o) ~$ \, }; X' Q
add ax, di
' a v+ O) Y. q test ax,ax
$ a: s# `! i2 g0 E5 X' g6 } jnz SoftICE_Detected
4 e3 C# s3 x# M/ W/ ?
& f# M8 h7 w. d8 O__________________________________________________________________________
9 X6 w- F1 w& } H% h
0 `7 `& |. x# @$ A- T5 X- U6 f4 _
/ L+ {8 x" T8 B1 P9 e7 F1 |( ~Method 05* C. A: r. X4 d" A
=========
, d" B9 S7 @- M2 L# o4 F5 L; s/ w& C
Method seeking the 'magic number' 0F386h returned (in ax) by all system B) Z$ j% u' n
debugger. It calls the int 41h, function 4Fh.
8 \- a7 L* I8 u e5 jThere are several alternatives.
' e+ A/ p8 J5 Y; V3 O# m* x" V6 K4 B% M8 A, e& B6 n) ~+ p
The following one is the simplest:
% @+ P& Z) o, h: K( v2 b4 m% c5 B- J
mov ax,4fh( u9 U2 f5 ?/ U( Z
int 41h( [( O/ Z! h" a% Y
cmp ax, 0F3868 A+ j2 K, E7 e( r# a
jz SoftICE_detected
; Q; |" o5 c: [* O$ t: r" Z# U) e" K( q6 T: v$ A$ r2 K, E0 e R) V2 |4 d
2 m5 B t6 B" }0 e0 fNext method as well as the following one are 2 examples from Stone's 7 X% u+ R6 ?3 T& [9 n/ @
"stn-wid.zip" (www.cracking.net):" b6 u. m0 f: c. Z1 R
% X; U5 |1 K; | mov bx, cs$ ~/ h$ h- d0 w. Y7 e; ]
lea dx, int41handler2, c/ [+ Q, b( H6 w- r O& ?7 i( B
xchg dx, es:[41h*4]0 F& j5 ~4 w/ H1 M
xchg bx, es:[41h*4+2]' W% b2 e; `4 \3 ~. i% t
mov ax,4fh
! H/ W: h8 @& j$ Y int 41h
t2 o# M6 c2 S3 d xchg dx, es:[41h*4]+ e1 F, P2 Z$ u1 d8 |0 K* _4 x
xchg bx, es:[41h*4+2]# O9 p1 l, z6 t* k5 @
cmp ax, 0f386h
3 i V; R9 s1 z- p k6 b+ E jz SoftICE_detected" |# `8 O. g( o* Z2 F- O
, e* w. I: P9 t: M7 W- Oint41handler2 PROC% D, n* B* o' Y# z2 {, m$ R
iret7 u1 {0 E9 ^$ d
int41handler2 ENDP
6 q$ ~8 N o2 A7 C/ B% T2 J5 R' K3 |+ f9 x* s Y# y
. L. p. N5 x; l% h- I' q/ F( k
_________________________________________________________________________/ }' K' L8 c2 N: i( \
) u; n9 p2 a3 K! {0 c, \
8 r( K: M4 t9 l$ [+ Z7 C* v
Method 06
/ Z/ b q0 K. F/ x4 G=========
# l$ y: G$ c4 }! [3 C4 P2 K# M- |% r' ?
+ v5 A* u0 _+ \' h" E* l, Y2nd method similar to the preceding one but more difficult to detect:
, i, d1 [; c& m' H6 p0 K
. G$ C1 X) S* H2 f! p, l- q: |1 L1 p! g
& ]6 k+ ]) w# t: vint41handler PROC0 |9 R- z4 ~/ Z' Z. }2 g2 I
mov cl,al
7 v# Z3 `2 |( P* c6 `9 ], }- l( q iret' z* R, R5 y k: U* N# |0 e1 B* V2 G
int41handler ENDP
S, v, g8 Q3 B0 b7 Y: N# e& R) G8 h6 [$ }' p! {/ h
9 v. h6 C' E9 p% @0 s7 L. L2 |- q xor ax,ax
1 \) [ A$ z" e6 b1 y9 [) Y mov es,ax+ d+ ?7 M; u, `# e) L( G/ Z
mov bx, cs2 X: N: W) |0 L J
lea dx, int41handler
6 A8 z O# `* s0 `) k xchg dx, es:[41h*4]
0 k" }9 ~8 i' W, ^7 Y xchg bx, es:[41h*4+2]# }$ |1 Y, R/ t
in al, 40h- Y3 ?5 z% Q4 s. g% s
xor cx,cx
$ v) S ?5 C; K- k int 41h% Z7 Y. N5 a; Z7 e( r% L* @+ l" U
xchg dx, es:[41h*4]
! u& b5 d2 f: P5 M; d xchg bx, es:[41h*4+2]1 f/ ?0 R3 A- J1 D
cmp cl,al
4 d& z; @7 p5 C4 x% Z jnz SoftICE_detected
3 b5 V: [# l/ z: @1 h
7 t1 E+ X9 F1 n_________________________________________________________________________
/ ^, d; b8 Z! Y& v5 n- w; Z6 e2 i) m9 R' g/ A5 p
Method 078 D3 S; H: B C! n/ A% u
=========& o# n h3 i8 O/ G, l! ~
4 g7 N: ?2 T" j t1 Q2 X: Z
Method of detection of the WinICE handler in the int68h (V86)
# i" x- ^9 Q9 Z+ o
6 b* t% l1 c- i3 O; U: k mov ah,43h
* W) N" @8 M2 _5 j int 68h
3 p; y0 S% b; R& \- p9 S( R cmp ax,0F386h2 J n3 D4 ~5 u* k3 c t
jz SoftICE_Detected- t- ^6 o( e" |" \* L
6 Q, \( A3 X6 A9 W1 \8 f+ h- w9 B# s) [8 j
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit: \- O0 g! _( g: ?+ B
app like this:# ]9 S; i }" v2 y; [- T g; V
/ r7 m6 K6 {2 z- t, z BPX exec_int if ax==68* S/ c2 l# A5 _& b2 ?0 e
(function called is located at byte ptr [ebp+1Dh] and client eip is" M( _, f( F1 |8 ]. F" @% V( t
located at [ebp+48h] for 32Bit apps)
+ |2 x. _! t% S2 ]8 I__________________________________________________________________________
5 e3 t! A f K7 Q0 H
) Z$ ]8 F+ x% O
! j& N; L6 Z8 R' ]Method 08
- j7 i, x6 X' w- Y" S/ \=========, m/ E6 H2 A& y) F
7 g" g, D% Q! o/ }, I6 x3 @2 `4 q* n
It is not a method of detection of SoftICE but a possibility to crash the
7 I2 M. A% e; D9 u) tsystem by intercepting int 01h and int 03h and redirecting them to another
( W$ t& ?. q3 proutine.; c) B5 g- H3 R) g' m0 X
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points8 W% U1 q) P7 T+ ]) c7 X
to the new routine to execute (hangs computer...)
. K, a5 L5 E4 |; a# ^
5 n3 M) R6 l9 k( S4 v; h4 z7 ^' i$ b mov ah, 25h
0 {4 y& p; v9 A* q mov al, Int_Number (01h or 03h)
2 `$ u" r r7 F" e mov dx, offset New_Int_Routine2 J4 J \6 Q/ }1 i3 }, y
int 21h# R: n5 J( W3 x
3 \9 U$ S) @6 M: C8 k9 [
__________________________________________________________________________
. I. k3 d* I; J# F5 n8 p5 a! A/ M, n8 `1 V7 k
Method 09
4 A0 f! r5 K/ e4 W; b% {=========9 ~# V5 K9 `, R$ n
+ F+ G1 p: R3 b$ [3 S' X$ GThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only: D: W1 A: \/ M; [/ S
performed in ring0 (VxD or a ring3 app using the VxdCall).6 \( p4 ~& v1 y! |
The Get_DDB service is used to determine whether or not a VxD is installed
5 D' |+ Q* x) u3 V, z; K, tfor the specified device and returns a Device Description Block (in ecx) for7 r7 e+ u, s3 V/ n
that device if it is installed.1 e& f; a0 V' s. `
$ x* _4 K1 f* k8 K! i e' {/ e& w mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID$ T5 [1 S" T* r4 J% w) \
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
9 \; m$ I" y! O# I$ B* Q VMMCall Get_DDB- b* W6 [. [* V' ~+ k- e
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
5 s6 G0 Y) u- K% U
& W- k9 E$ A6 I, PNote as well that you can easily detect this method with SoftICE:+ I" A# m z0 i7 M/ c: L
bpx Get_DDB if ax==0202 || ax==7a5fh
0 o( G* V+ G% {8 |# P' |
& P% A$ n* u" l6 |) @" d__________________________________________________________________________
_ ^7 R8 ]- h% M- z
5 Q# Y" b1 D- T* ~Method 10# @9 `. y3 w' k8 Y. Q# ^/ _
=========$ t+ B5 k* `. w) L U! Z% e
+ k' E4 \+ {. g
=>Disable or clear breakpoints before using this feature. DO NOT trace with
# l5 b @9 \) T3 t- b7 z, M SoftICE while the option is enable!!
9 _- \' @, o* x) o8 r! c+ p. I' f1 F
This trick is very efficient:
6 E7 W* ~# |( t# A6 q7 Uby checking the Debug Registers, you can detect if SoftICE is loaded
, P5 R& c- }& @! c( m3 s(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
$ F( h3 X1 A% s4 }$ jthere are some memory breakpoints set (dr0 to dr3) simply by reading their
" l0 D7 _5 j3 c: }& q h* mvalue (in ring0 only). Values can be manipulated and or changed as well$ @1 s0 f' ?9 b' k9 t e" A: U
(clearing BPMs for instance)
" g' d+ a. n H7 q8 T4 v- s1 ?0 g! q6 } R _
__________________________________________________________________________2 G9 t9 S, [+ v# n& G7 |
6 e: q7 H3 B! s0 B9 W* V7 p
Method 11& d! G1 f/ t; s# F
=========
/ t; [; d% O2 v. m N* F5 B+ A4 L" {% s0 D9 M- W1 f
This method is most known as 'MeltICE' because it has been freely distributed% d4 F$ ~9 _$ ^; l+ O9 ~. @2 q1 K
via www.winfiles.com. However it was first used by NuMega people to allow
; ` c7 g- x' W, ]) kSymbol Loader to check if SoftICE was active or not (the code is located
* o7 Q; N+ a4 K/ j2 p; ainside nmtrans.dll).
% `7 x; _; a9 W1 e: c1 H/ f0 f8 L+ F* X" t0 k" y
The way it works is very simple:
" f7 w1 B" G; h. [* }% i$ `It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for5 E" J5 Q5 D! Q
WinNT) with the CreateFileA API.
+ D, \* v4 D+ G5 s2 T: q+ z
$ h8 k+ n2 c7 C: ~Here is a sample (checking for 'SICE'):
( l* H- h& l; Z, d' z8 w9 ?/ o$ Q4 [& D4 x
BOOL IsSoftIce95Loaded()
D% [* f$ U) c6 B{
) P L `0 ]# O! j HANDLE hFile;
0 P5 ?" {0 C7 W! E# W" Q+ e3 F' G hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,+ o- D9 V: b! C/ m9 _5 {; {- j
FILE_SHARE_READ | FILE_SHARE_WRITE,
# b* {% Q9 a4 R' B1 W NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
7 G, ~7 G' b; d. U: ]" p$ [0 l if( hFile != INVALID_HANDLE_VALUE )
& m* i3 p! j. L% F+ b! Z {
) k4 Q8 Z) u7 n7 [& m+ w% a; N CloseHandle(hFile); e' T [7 z: X
return TRUE;
3 e# O& H" F1 G, N }% _# _; O3 }, Y
return FALSE;: R, m* y5 f0 G! z6 U7 b
}3 z- ]# T& l; _" t' z
( q; x! x S' a* y: G
Although this trick calls the CreateFileA function, don't even expect to be
, w! ^% S6 d4 s, t% Cable to intercept it by installing a IFS hook: it will not work, no way!
4 O1 u" A5 q2 S* j( TIn fact, after the call to CreateFileA it will get through VWIN32 0x001F7 R7 B. J9 i1 e
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)# T0 J! v6 P& F! M5 q O
and then browse the DDB list until it find the VxD and its DDB_Control_Proc9 g$ U5 ]+ F: y- L7 C
field.5 d7 g8 {" T$ |1 @4 @. D
In fact, its purpose is not to load/unload VxDs but only to send a & M, Z" z; w$ R$ \
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
1 u9 s3 `$ T/ eto the VxD Control_Dispatch proc (how the hell a shareware soft could try
# D0 X+ u; L$ d6 N/ O' Xto load/unload a non-dynamically loadable driver such as SoftICE ;-).
U" i6 J& U! M# M" H! b9 J6 `2 GIf the VxD is loaded, it will always clear eax and the Carry flag to allow2 s) d& }2 i c$ S) n6 G7 v
its handle to be opened and then, will be detected.
8 ~7 b- T" H$ E* f% `You can check that simply by hooking Winice.exe control proc entry point2 `) @$ h0 K5 j/ `% a( |
while running MeltICE.
; r. A5 f. l, P" V" b' \! n1 k; e' L$ ~7 m* y
7 X8 g& ]5 @1 U( Y) O9 @2 j 00401067: push 00402025 ; \\.\SICE
/ J! M/ G4 Y# r- }* e: M0 a$ M, M 0040106C: call CreateFileA
7 _, _3 t: J \" R, Q 00401071: cmp eax,-001# J/ F3 f/ k2 q7 h) E6 L
00401074: je 00401091! _; \1 [; [2 B) J. N' ~
; \& R9 W' F' z( h3 G9 y
* n: H( ]& j$ v5 K, K% @2 I' LThere could be hundreds of BPX you could use to detect this trick.
9 Z8 R6 P1 }- A+ }-The most classical one is:
4 C$ |' @8 v$ E l3 h( o BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
I1 u, J# P0 ~3 y$ e" t5 @5 z. f *(esp->4+4)=='NTIC'9 W8 i" L# T% u3 Y8 t3 P- g
6 {0 {6 }: d! x6 ?/ y, _) w' y
-The most exotic ones (could be very slooooow :-(
& ?0 { v0 M/ M" b- f, k BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
3 ?' s% E4 C5 L& S( `2 ^$ w ;will break 3 times :-(
3 [- m: h; v$ N2 s3 b0 ^
+ m' g, J! U8 f# F0 A+ R-or (a bit) faster:
6 e: U6 e& z6 i: X) o% J9 l I BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
. E, U/ o* L8 N; H s% I5 I0 s5 W& N% O
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' * [" V1 W& p- J
;will break 3 times :-(* V6 z! G3 }% m1 A5 W# g
9 B+ e$ ?; m" \2 z- ?' y-Much faster:
2 z; D; B* D+ V: h: G BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
) S' X3 _' D0 s1 l2 }3 X3 a2 G! [" H, q
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
; Y i" N3 d, M" f9 A$ o% ^# @function to do the same job:0 X8 d' ` a# v2 g6 h# z1 [* M
! h D9 N) f' L# g7 o n push 00 ; OF_READ/ {( t6 o: @5 E# |6 t9 M
mov eax,[00656634] ; '\\.\SICE',0! C2 R4 m s6 k8 P+ l/ [: n+ X
push eax7 t2 v/ _( Y6 J$ T! V* a M
call KERNEL32!_lopen9 |1 l* f7 F. j# y8 ?# ?! ]4 r
inc eax
; c" z. `- |: a# N8 I jnz 00650589 ; detected
, c1 h- H6 u+ v push 00 ; OF_READ1 G' b. b9 k+ d; H
mov eax,[00656638] ; '\\.\SICE'
9 t, g: T% ?! u' O: F, _! x- { push eax
. R Y! T: l# T# t# V/ n& N call KERNEL32!_lopen: o9 l0 k8 [1 w
inc eax
' n, V' ]8 @& B jz 006505ae ; not detected
) D9 c T6 N' z& i) A7 z( n' a7 l( o. {7 r
* j5 y b' Z0 a/ V% d__________________________________________________________________________" ^7 x6 p. _& B; S3 b
* k) w. ]* B2 I3 FMethod 12, T d t% D0 C# ]$ e* H( w
=========; R7 Q4 x! Y0 S! i
E' }5 [( q. X" r& E
This trick is similar to int41h/4fh Debugger installation check (code 05
- Z) F, x' I1 H7 A. N% k& 06) but very limited because it's only available for Win95/98 (not NT)
7 Y$ ^8 o% P8 E1 d0 @2 h( Gas it uses the VxDCall backdoor. This detection was found in Bleem Demo.% s. d1 U: w6 n6 s/ E" a1 N5 G6 J1 b# Q6 y
/ h, |5 W$ }6 q* f' P1 ?# A
push 0000004fh ; function 4fh3 `0 R$ O& a+ Z
push 002a002ah ; high word specifies which VxD (VWIN32)9 |- ?7 T/ y; D7 V* y: Y
; low word specifies which service
5 o8 C1 v5 }) B0 J6 j0 T; v (VWIN32_Int41Dispatch)
5 A8 Y5 p2 F2 B L' V/ K9 l7 F+ ~ call Kernel32!ORD_001 ; VxdCall( j- Q1 e: O- J3 q G: ]7 l
cmp ax, 0f386h ; magic number returned by system debuggers
' _1 g; [- t& }% D$ P1 r jz SoftICE_detected/ m- k( `; I+ l2 i: o; m% p
! v/ y* B8 s; _' o/ e; o! e' dHere again, several ways to detect it:
' C, c$ D" w E. b* H' u4 P* M, y
- z# M7 C$ R2 p1 l BPINT 41 if ax==4f; i8 E! T: S0 v) o0 f2 z( J
3 S! r9 m$ v& d1 \ BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one5 K; `; q" i4 e
; v- E: J, x- O* a- l" Y BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A, C" W* i4 t6 x+ N
3 r0 t- L0 K: N: n4 T
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
8 Z _+ |7 ~3 ^1 H: H
" K5 J! Y; U/ p# S* k# A" Q4 w$ w__________________________________________________________________________
4 q4 t' n& ^; o$ ?7 ~
6 H( R3 Y3 F/ y( P- h5 KMethod 13
" _2 t' z" e9 A6 W* z- p* V=========
8 ^% ^+ L- U5 ^9 Z+ V
0 m* w8 t3 s" q6 ZNot a real method of detection, but a good way to know if SoftICE is7 R( Z$ H" w& q1 ?( `2 f
installed on a computer and to locate its installation directory.+ p8 t, a8 n+ k& w
It is used by few softs which access the following registry keys (usually #2) :3 T' h. {9 F1 L! }
: n, _# {- P- B# m) S9 D
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 a% ^: N5 p" m$ ?\Uninstall\SoftICE8 X: m* ?- @$ H* i5 S, i
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE$ o5 r' B+ I2 {( h' p4 p% S
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion$ y+ z0 }1 I- g8 q
\App Paths\Loader32.Exe
% m) d5 U* ?! m. {1 B& ^9 z9 e' w# `
/ e6 {' t( I# R2 S
Note that some nasty apps could then erase all files from SoftICE directory9 [ g: t- c1 d! H4 g, N' R
(I faced that once :-(
8 i% \- m E' f: \
; G- v" n/ _7 r, I9 JUseful breakpoint to detect it:
" T$ ]8 v7 J7 A4 W6 t+ Z5 T; k: }& q
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'0 Z/ O. }2 M" a8 m/ [
4 E4 p6 Z9 j% w- A9 w
__________________________________________________________________________: M% u* T8 [* E1 A5 S3 F; i- q" N4 W
2 E4 Z5 F4 A, h' m
9 t7 n# ?( C1 I: w& {
Method 14
7 S: s, J; y# ?# t* U: K3 u========= ~) s, E- ~' h' H" z# i5 Y
) s; b0 ~2 S8 z# r0 OA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose1 C9 Z7 d) t+ Z" C: r& I
is to determines whether a debugger is running on your system (ring0 only).
" B$ k5 j. |& J2 q" e, i! L! o g. F* e
VMMCall Test_Debug_Installed: Z9 z+ w5 D8 e) O& G
je not_installed8 J9 w5 V- _, [2 c' P
/ C7 @: `$ g& N6 }# \+ R* jThis service just checks a flag.
, | z/ @/ J( [8 B9 S</PRE></TD></TR></TBODY></TABLE> |