<TABLE width=500>
/ y B/ W0 W0 `0 Q) o<TBODY>
* n$ I' h' o+ |$ k<TR>
G0 F$ t6 P3 `' R<TD><PRE>Method 01 ! o( G8 D: V1 Z. t
=========7 C6 c0 q$ a2 b3 w* k% c8 U. s
' l7 c3 Z" S7 K+ T
This method of detection of SoftICE (as well as the following one) is
! D3 Q" P- F; j5 ]6 r9 H1 {used by the majority of packers/encryptors found on Internet.$ {. k. e3 k" P! o/ y" |: _! \( Q( [
It seeks the signature of BoundsChecker in SoftICE
' F! ^, w$ X! I" W4 G3 W# L' ^: q2 M. U
mov ebp, 04243484Bh ; 'BCHK'5 T" Z( ?) ^4 i O2 T' \8 [
mov ax, 04h
3 L2 @7 P' Q3 U) Q7 i' p int 3 : k7 a4 X8 I2 ?% l1 a. S
cmp al,4/ t1 x9 t& s( J h- N- \
jnz SoftICE_Detected- z7 E$ R& b4 l3 L6 T0 P
0 }; D/ \2 q, a+ D___________________________________________________________________________. q) j. W) z. F3 A' @
5 b' P0 U$ N4 t5 y% n8 A
Method 023 R$ u* I6 v# Q/ z6 k4 f$ @
=========
. S3 B& p* `5 I/ J
/ {9 w5 Q) v. FStill a method very much used (perhaps the most frequent one). It is used
: P+ O0 g, x' _2 `* Dto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
I+ [/ G9 T. |, a6 B; Z; Q, \or execute SoftICE commands...4 S7 H8 ` J$ ^ r: ~
It is also used to crash SoftICE and to force it to execute any commands% E d" P9 _9 V
(HBOOT...) :-(( . D) H8 b7 c2 I ]/ |% @
5 T; d0 [# n- r1 p9 j, `Here is a quick description:
: u! Q+ h# d; r: g; a7 F N-AX = 0910h (Display string in SIce windows)
" u; I$ C3 q' h: a0 n" L) {% c-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
1 r+ V" [" S x: t( O-AX = 0912h (Get breakpoint infos)
% S# U! b: J7 Z( T-AX = 0913h (Set Sice breakpoints)7 }! f" N; X, F5 l' E: M$ R
-AX = 0914h (Remove SIce breakoints)% _' _( a5 ~2 m# O( k/ `
) K& W/ s. R3 u
Each time you'll meet this trick, you'll see:
( Z+ L5 S7 ?* ]2 r-SI = 4647h
' b& ^7 y1 C6 u; H/ k2 X-DI = 4A4Dh
4 Y0 E- l+ f- _/ n0 ?- D8 b- T2 \6 eWhich are the 'magic values' used by SoftIce.7 ^3 [4 j; j# P
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
2 e, p, f% ]+ G) \% q1 u/ C+ \: F6 X& ?/ X1 l
Here is one example from the file "Haspinst.exe" which is the dongle HASP- t+ E! Y! @3 }8 v) N; S1 c+ t
Envelope utility use to protect DOS applications:
, a7 b) g1 w: z9 u* ?, W$ w6 `" }# X! `/ H J. E
+ U! z. B) M2 z- y) d2 v4C19:0095 MOV AX,0911 ; execute command.
f/ B1 T, [6 a2 g! S4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).! L/ E) v3 r& \* _0 @; ~
4C19:009A MOV SI,4647 ; 1st magic value.# e+ [8 l2 t( h: Z& G- O! {8 y
4C19:009D MOV DI,4A4D ; 2nd magic value.
+ m R5 V4 Z- y2 e, e; [1 d3 H4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)' Q3 m: @* _& b
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
0 Q8 Z. a* y, [1 _+ e4C19:00A4 INC CX
+ D* Z! F9 p. |4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
) w9 q( O$ @ C3 |$ k1 T& j; W4C19:00A8 JB 0095 ; 6 different commands.+ B: V, |) b: K+ ]! b
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
" ~4 T3 f2 y- C; c* m2 e, c7 I! n4C19:00AD MOV BX,SP ; Good_Guy go ahead :)# } p6 @, N3 `" y0 q% @
" s' u3 A$ i% M/ ?
The program will execute 6 different SIce commands located at ds:dx, which
0 g2 H9 D! H1 U) k% ^! `, H8 r: [are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
" w1 F4 F" Y& F2 ~0 w- X4 L& T5 e1 ]1 I7 \8 q
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.0 ]6 d, m$ _$ j1 W* D
___________________________________________________________________________
9 q& j7 ]5 }8 F4 m, | C
3 h8 r. |" q% Q8 n1 |! v8 @
2 p% O) N: A8 z2 M( H9 J2 NMethod 039 \) b# y% C( \- e4 X8 ]: c2 l
=========& u3 C* N( t5 ]0 t( Y2 j! F
5 n9 ^; N9 [+ c3 a0 r- j
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
# G$ S% _, t2 H6 L7 {0 |(API Get entry point)9 R6 G' @; y1 }# t
" Q m7 Q Q# s3 P p/ I
1 |' i W8 J3 t/ I, \1 l5 r
xor di,di
E* q) F; H; |: D* Z$ w mov es,di+ L; r8 w/ `' F- F( j, q
mov ax, 1684h
# ` P' j- I1 |! _0 c mov bx, 0202h ; VxD ID of winice- v9 B6 m7 L& {( H- d" Z- I
int 2Fh
7 Y" W7 b. {( U* X mov ax, es ; ES:DI -> VxD API entry point8 ?; G1 ~& y% f: Y5 G& f. k5 p
add ax, di
* _/ U% f9 O n7 F1 { test ax,ax l* C: M, L* M* i$ A4 k C
jnz SoftICE_Detected
: n# C% i- l! m! U2 m( @
% M3 n1 C, n; E# q: B6 G___________________________________________________________________________) K, y, \: r1 F3 U
, [. K0 d% x( j/ T% Q0 G
Method 04
$ M, z" N8 r( o. e* S- o5 k: J=========
- d) }4 X6 r- p" Q
; i4 t- Z+ B4 m) W, Y9 E7 gMethod identical to the preceding one except that it seeks the ID of SoftICE
* ^4 j4 `% O. ~, u+ O6 S+ o+ IGFX VxD.& H' [9 q$ y# C# @" ~
' v7 ~2 S) N2 \0 M3 h+ @
xor di,di8 B0 K$ ?* L" g( |& e
mov es,di
1 a6 n) ?- k" D mov ax, 1684h 6 O" \8 ]+ q8 M: H+ u% b3 z
mov bx, 7a5Fh ; VxD ID of SIWVID& e+ z6 J/ V8 [$ D9 y
int 2fh! |0 q/ D" Y5 t' }+ u8 N
mov ax, es ; ES:DI -> VxD API entry point1 y2 Z, W1 u ~' C7 U( z1 L1 Z
add ax, di" V8 c; [% ]: d, d
test ax,ax
- `" J) O* z% E6 _0 \7 y/ ] jnz SoftICE_Detected. L0 i: C4 h. l3 ~2 \* |: `8 T
- M9 `) C1 U( z9 m6 R0 D% b' [
__________________________________________________________________________! m! ^2 Z, S7 v, G6 {" \
, O; T1 V6 m# N
s6 P8 G; E9 c3 O0 N( d: qMethod 05' ?- ]4 X2 g8 L) Z. C4 H
=========
T1 h- Y* }% N* X* B e+ T9 s2 c, ]1 ~ n# r' a& I4 u
Method seeking the 'magic number' 0F386h returned (in ax) by all system0 D2 `. H# y4 w6 M: n) T A
debugger. It calls the int 41h, function 4Fh.1 M' y: i2 ^1 t' O* ?1 _
There are several alternatives.
9 }1 \) J, C, G+ U* f: Z3 A
7 h' l; m! c" pThe following one is the simplest:0 z/ G/ I2 S3 a. Z
1 g" _" i- G8 N; W6 V0 o4 [ mov ax,4fh/ [: m5 e7 c. P# K f$ m
int 41h
# U9 H6 R8 m. v, F cmp ax, 0F386
5 U( Y6 d! `8 ~: C jz SoftICE_detected+ l- Q5 \, A; g3 N5 W3 G
& ~( w R [+ y9 Y! a! q+ a
& r: e9 C. ~. `! Q5 f8 `" j
Next method as well as the following one are 2 examples from Stone's
5 E: g! G2 p6 R"stn-wid.zip" (www.cracking.net):2 [0 B! B4 e$ a) M) `/ @( ~8 p
& S4 C7 E" z& D9 G) u mov bx, cs* ~: Q+ U8 c6 g7 m4 t
lea dx, int41handler2' w; |# n/ S* J; r3 n
xchg dx, es:[41h*4], F& I9 ^0 w5 d5 r
xchg bx, es:[41h*4+2]
" h3 f; }2 }" N0 _* [ mov ax,4fh
4 n8 c( V) Y D6 b int 41h2 u3 f8 n' z$ N3 M0 _) E6 l8 |2 f% U
xchg dx, es:[41h*4]% [6 ]8 P+ E9 r- ?
xchg bx, es:[41h*4+2]! T4 I1 S, z3 }5 l" T
cmp ax, 0f386h
" o$ a( {* [3 `- O; c9 E jz SoftICE_detected
" A- L, u% U. E$ t& {& F2 b
% {7 d- Y" a7 [6 Eint41handler2 PROC5 B, q3 d c* N/ o
iret h3 X& X5 U7 f% x% c* j! ?
int41handler2 ENDP+ b6 y% p9 E4 K! l
& P* t! G( c" {: ] U' s6 q2 r' T1 J# {5 O3 H8 d2 m& i$ s
_________________________________________________________________________
6 j4 O M8 T1 C. j6 Z& {/ T9 h& y$ A) Z0 I) J0 d3 g( o- H
$ P# h; E% {$ d q# ]( r& RMethod 06: t# M8 k5 H8 G5 g+ \
========= c2 C T: ?$ f1 {% _& Y8 K+ }
0 W( q! m- \1 N3 A4 m3 f! p% T3 [3 Q+ C
2nd method similar to the preceding one but more difficult to detect:5 Y) Q! x% }: F0 h; d
( d+ a% |" @) r) ` V e y8 m; v# j i B
int41handler PROC+ \7 O( y" U4 X5 g @1 B
mov cl,al
1 r3 J; Y7 s- l$ Q P* s0 i iret
& B8 W- ?- u# [, q# m8 aint41handler ENDP0 l9 d8 l; F9 g S2 ?) O. b( i0 I
; B- s" t3 s" X5 P
7 @; z2 {7 E) [3 W9 r6 A( d- G xor ax,ax1 y& Q# l( K' J# x& U c8 M1 P
mov es,ax
. b* m1 |; f( C/ ]! t7 e, W mov bx, cs
8 M+ |! I! o+ n0 s6 V lea dx, int41handler" B8 w1 w. v% P. q6 H
xchg dx, es:[41h*4]
" f6 @; m3 h8 P- t" l6 Y xchg bx, es:[41h*4+2]
7 |! x! A- a( J! u% ~ in al, 40h9 S1 f; |9 I: L" p9 `
xor cx,cx
# ], J5 L( O; h$ b int 41h3 k4 E9 h8 ~) {- n% v
xchg dx, es:[41h*4]
* k2 I7 p4 I" u: i xchg bx, es:[41h*4+2]+ [) Z4 u- e3 Q: \
cmp cl,al
7 @8 E; A q4 v/ j8 p. k jnz SoftICE_detected
% Z6 N! F& n/ z6 x8 e; l4 @; Q4 S
0 A* o- B, m u* Z_________________________________________________________________________
, Z9 ?2 @2 o% e1 v9 l1 C |: L$ C! q! f' G
Method 07
' ^$ a G- R5 D- i2 l=========% k8 @" U1 S% m- `$ D+ d
: Z3 P( l% n* }2 u4 G: P5 F7 u9 W
Method of detection of the WinICE handler in the int68h (V86)" ]3 {! E9 r4 K* `* F
$ T: }, w$ m y$ T mov ah,43h
, ^5 m4 {7 B9 b8 M, [- a int 68h
* Q! ]# ~4 I1 ~& B/ o- s9 e$ O cmp ax,0F386h/ y) m/ A* v9 a8 K& w( m
jz SoftICE_Detected& @, i& t3 c" y9 v, n; H; k
, E1 \; u' I! D4 o; A/ l$ Y1 C$ \" Q. [6 r w" c3 u9 ?! ~4 m- x
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit0 F# }2 f( M* Z) B
app like this:1 d! _) z7 O1 `8 F1 I
4 H4 I( G5 z l C3 H+ Y9 I
BPX exec_int if ax==68
8 g# D7 b& [6 Z0 h: X (function called is located at byte ptr [ebp+1Dh] and client eip is
, U8 l* F" C- k- @3 \% [8 Z located at [ebp+48h] for 32Bit apps)
( }5 P0 y, |/ _$ J1 [5 r__________________________________________________________________________
9 y! P: l* C) E" D+ w* Y6 t7 q4 v" o5 c8 H" V9 A1 s
2 F, p: n5 Y5 ?, c$ U( G D
Method 08: f% L- j) @; ~% B; A
=========
7 C8 { X7 S- |4 |* Z3 |; q
7 I5 Z4 `, y3 |It is not a method of detection of SoftICE but a possibility to crash the
0 }: Z O0 h, z! bsystem by intercepting int 01h and int 03h and redirecting them to another
! g3 h# e7 ]& j3 p7 froutine.
8 D2 W9 e; b" j; n7 l, ^It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points# _% ~; k( R6 U/ e2 v) x
to the new routine to execute (hangs computer...)
; {$ t7 V! h o4 n: B7 H" ~% ^& Q4 s' b# u+ I
mov ah, 25h9 L1 h4 A5 E: i; g
mov al, Int_Number (01h or 03h)0 r. p5 E& g% g6 w1 I# r
mov dx, offset New_Int_Routine, J ~8 a; k, D# @
int 21h
& l2 M3 e+ M. J; T) F
4 W5 v) s# g P__________________________________________________________________________5 W7 @6 e& M( g6 i. P4 `- M
! y" O, @. m2 I: X' p
Method 09
' p3 D& q$ l& P, {# ?5 d, {=========- V4 b9 P+ s _2 Y& O5 l
) f* L- b0 T4 d. ^4 [
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only8 _ k/ `# g+ }% k- m' x0 r
performed in ring0 (VxD or a ring3 app using the VxdCall).
1 B1 G1 t: P2 r6 FThe Get_DDB service is used to determine whether or not a VxD is installed
7 `$ e3 @+ b# g \) I& n3 K5 Efor the specified device and returns a Device Description Block (in ecx) for$ q' d! K& i- n) m/ H- ]+ z
that device if it is installed.
* H! |) u# b/ ?0 w7 B/ W8 {+ H, {2 W/ c
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID6 ^7 O2 R- N: ^2 g+ V
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)( k5 _" U# U3 O1 @' ]6 _! f
VMMCall Get_DDB
/ K; C( g, u& @8 S: {3 H mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed- K3 V5 B( p% z- ]8 \7 _' ?
9 F+ x9 A2 r6 _& d( B* Z1 W4 j. Q
Note as well that you can easily detect this method with SoftICE:
; y1 h1 w" }% T) a' @3 d bpx Get_DDB if ax==0202 || ax==7a5fh% l$ j7 d1 ?2 ]6 ]" R1 T- z2 W
6 q1 {; f5 u. a1 D: B__________________________________________________________________________5 Q1 c* n- T5 l) `* _ i0 b9 L
" ~: F# i; }3 r: d
Method 10
! ~# D [; u7 K1 [8 Y=========
5 L5 |; F6 w% y) _ R Z
1 ^, O: ?; G; N! L+ z! v' u=>Disable or clear breakpoints before using this feature. DO NOT trace with
- [2 u+ v6 ~8 D3 P9 [! d SoftICE while the option is enable!!; m3 t/ u: p3 t) o4 D5 H" l
$ q* ~" D/ |! S' d
This trick is very efficient: {0 }7 W5 P1 L5 @6 y
by checking the Debug Registers, you can detect if SoftICE is loaded2 z. k6 j4 W8 f1 H# _
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if6 G' J" _$ S6 ?) P- N3 C, v
there are some memory breakpoints set (dr0 to dr3) simply by reading their
' j" e6 |+ {1 q( a0 k$ J+ K Yvalue (in ring0 only). Values can be manipulated and or changed as well
% \8 m/ f9 U) u2 \(clearing BPMs for instance); N3 K W) J9 E5 Z
" L; \% I! A& @$ {3 Z+ Z__________________________________________________________________________
: |1 K. i0 |: c* u7 e- `6 W) J& n: P0 Y1 t( Z/ ~2 I4 t
Method 11
* J, |( D0 I) U=========
$ \( Q0 h' n: d* N! P, g' x' X, ]8 Q) ?9 J
This method is most known as 'MeltICE' because it has been freely distributed/ r$ p0 w: A( b1 R$ x4 b
via www.winfiles.com. However it was first used by NuMega people to allow3 O8 ^' T \2 n9 G% A$ C
Symbol Loader to check if SoftICE was active or not (the code is located
' k _1 m; G- J# }) Hinside nmtrans.dll).
8 G4 J2 c5 ]) Y2 [3 i$ f: N7 D& p0 K8 d1 N
The way it works is very simple:
2 H8 g* b2 O% }It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for R, }6 r/ K) K5 T7 L% j
WinNT) with the CreateFileA API.
, h: l, U7 A: A. U; g& M
. o# m3 z' m$ _0 jHere is a sample (checking for 'SICE'):6 ^2 r' o# G5 ~( T# K
: Q5 {9 t! [) q# v
BOOL IsSoftIce95Loaded()
9 e1 y$ a, g7 {) z( W8 p{
Q. i2 z- u" O. y HANDLE hFile;
3 C& K, S- D i: r/ b) R hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,$ R* p- X# ~& b0 z5 w% O2 B
FILE_SHARE_READ | FILE_SHARE_WRITE, S5 O9 W! V+ T# s$ R
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
; p! m5 N+ Z! g+ a if( hFile != INVALID_HANDLE_VALUE )0 u5 F3 H% J2 y9 n9 @* c l" B
{, j/ H a$ R4 \3 }" y% K6 W0 t
CloseHandle(hFile);4 r0 b+ w" [- ^& A8 w; M" S
return TRUE;' v5 {1 y2 `* ~: ~( J! G7 T
}) ?# \1 m# J7 f3 T6 w# }
return FALSE;
: s6 M. ?% {: P4 j+ {}* w! {: f, b O& Y9 n4 Z9 T
, ~0 |8 Z+ [/ H1 T8 A2 ?9 Z% s+ m
Although this trick calls the CreateFileA function, don't even expect to be
4 `% V+ J+ V3 H3 F' table to intercept it by installing a IFS hook: it will not work, no way!
# X& ~) G% |% Y7 |2 [In fact, after the call to CreateFileA it will get through VWIN32 0x001F
0 s1 Q: j) S0 K6 m0 [% gservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function); G8 r1 |7 G3 d! E
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
: I- y# u# G' Y/ b5 D! yfield.
1 v4 k1 w) w: z d2 RIn fact, its purpose is not to load/unload VxDs but only to send a
" b& _& Y& V8 ^; k& Y7 v& ^W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
- U# |/ k4 u% V; U0 ^2 Cto the VxD Control_Dispatch proc (how the hell a shareware soft could try
7 x9 a& G8 u+ t3 s) v) qto load/unload a non-dynamically loadable driver such as SoftICE ;-).
! _. b6 a! k/ k! mIf the VxD is loaded, it will always clear eax and the Carry flag to allow
5 ^% ~: S$ ~/ X5 q- a8 \+ Aits handle to be opened and then, will be detected.1 n, ?: z8 _* T4 l$ q
You can check that simply by hooking Winice.exe control proc entry point
4 i# S4 D! D+ W+ cwhile running MeltICE.% a$ f; w, a! W! e6 z% Z: ~
* c8 f2 D9 s( T. [# C$ A B5 V
9 ?! K1 E/ ]1 r3 c* F) ^7 w" ]8 h 00401067: push 00402025 ; \\.\SICE
# x/ K7 k! V9 w. y' g 0040106C: call CreateFileA
+ B# K. c5 g/ V( v 00401071: cmp eax,-001
& y8 o* F8 x5 x+ q# d2 ^; c- K 00401074: je 00401091) x7 \6 [! W; F5 U- b& J: W
4 ?- d2 F, \* [5 f: n. V; h' h$ }3 t3 [; F, ~2 c
There could be hundreds of BPX you could use to detect this trick.
6 p2 z7 F0 y: M, D5 A-The most classical one is:
, }5 m2 K! o) F$ \* L0 x BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||$ D: t) C j( K M
*(esp->4+4)=='NTIC'
1 B1 }. z4 S% H7 `6 n
9 m0 g) @' _' s4 h; l-The most exotic ones (could be very slooooow :-(& L* l0 Q' L) ` J
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 7 Z1 n' i9 ^* \" @. b( l: j
;will break 3 times :-(# C! R( z- L9 T2 o
4 k0 t' @$ @( c* v; @ A. X- d& l
-or (a bit) faster: 0 m" U7 ?6 A9 n% c) n
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
v/ J" y) R, n( A- C* s F( H
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
+ o/ h5 z) T' ~0 h ;will break 3 times :-(8 V; ^- U2 S: S8 K
0 G- u3 o8 S& S-Much faster:# F0 Y3 D" S8 |% V) I1 z
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'5 Q4 U0 M' [3 s/ s, J& d
' h+ {( H2 U) F5 T+ U+ ZNote also that some programs (like AZPR3.00) use de old 16-bit _lopen5 X# ]2 g9 ~0 ~7 }. R4 {
function to do the same job:$ N: }* n- r, p( U% Q7 J
' [. }- C5 E; N0 E" u
push 00 ; OF_READ4 s* D% |1 Y, S/ r$ L7 T! y* i+ I
mov eax,[00656634] ; '\\.\SICE',0
* `- E4 y5 f7 w! c2 M" q+ K1 q; W push eax
4 Z; z' g$ h! B1 Z7 l F' P# w call KERNEL32!_lopen( R. J. A: }# ~( C" B/ Q1 d
inc eax0 M) h4 l0 g& i) J
jnz 00650589 ; detected
$ j4 l/ s$ H7 ?% n push 00 ; OF_READ7 c8 O' k# k' y! v% F0 E3 c7 M
mov eax,[00656638] ; '\\.\SICE'& J6 Y/ T }( g+ @2 H
push eax
* {6 F {, D, |2 ^' Q$ J' L/ c* P call KERNEL32!_lopen( i. m0 N5 A) x! |: @1 g) p1 ^
inc eax
W! X' E J! m& x2 r jz 006505ae ; not detected8 p( e. j: k' @! b% p1 S: D
: D& x( Z" _1 N# }
! x- m4 {" K" J" s1 b__________________________________________________________________________
( `$ l6 z* R& c: L! L, }( y0 \& W* T3 x0 g' W
Method 12' L# l& K2 r9 S) L2 _
=========
6 F5 r! q; J* E1 B! r& G* Z
" d+ u* A" S5 v! s9 t3 W% g6 }; DThis trick is similar to int41h/4fh Debugger installation check (code 05$ n# m% J: [/ D7 L N# k2 p3 f
& 06) but very limited because it's only available for Win95/98 (not NT)7 m4 t6 m* u; k' t+ z9 n- ?8 g" f5 y
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
* h6 d' \5 z( E- V6 f: @/ L" L. M* |/ _
push 0000004fh ; function 4fh9 f% t$ G/ T9 l/ F3 `. ?
push 002a002ah ; high word specifies which VxD (VWIN32)* `$ v0 b0 i8 P) B! @
; low word specifies which service
" W# e3 O$ Z% v7 i (VWIN32_Int41Dispatch)9 O x( N; A* K! V- F/ |/ W- e
call Kernel32!ORD_001 ; VxdCall
6 m/ Y* b7 R- P7 J9 Z cmp ax, 0f386h ; magic number returned by system debuggers
( m3 S9 X& r- F: m5 z- p' v) f jz SoftICE_detected$ F `6 w7 K# e2 Y4 T3 {5 s& B% G6 @
& g) g3 N0 m& j0 R3 a0 a
Here again, several ways to detect it:
, B4 {+ L+ i5 u7 P3 U
* p) Y6 d1 b5 ?# I BPINT 41 if ax==4f/ K/ v3 y2 i; F( ^
2 [+ m% K: u" o3 X! K' C
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one( W( I& F7 N) C* h: ~- w- F0 f
: P9 M* B( ?+ N; I+ W7 C. K4 [ BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A6 J8 I( f4 K6 }( v6 [
% c2 W! ]! U9 d- N, {0 k BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
- n: M' P$ K) X9 @4 W" [/ f4 g! M A) }
__________________________________________________________________________: I1 I; n6 x( ^0 K9 P8 H0 h( N, h
I+ {) v6 @7 G: eMethod 13! n/ L" B8 ?) D, U7 R
=========/ n. L$ |. O0 R- l
9 j& C) U5 v. w
Not a real method of detection, but a good way to know if SoftICE is
$ n# P- x9 S( B" kinstalled on a computer and to locate its installation directory.
4 [6 a( \! D+ o2 Z& i0 f; GIt is used by few softs which access the following registry keys (usually #2) :$ T+ q- L6 y7 _) p0 m& o8 m
! Z/ n) T; ~% H, D4 B* y. K" n% a' ?-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion* t4 ^4 @+ [; y4 x% Y
\Uninstall\SoftICE
+ ?& c' i' [" |( A6 X-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE e. w0 ]: h/ U9 s& U* { t; r B3 \
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion! Y( Q' m7 Z. e4 O3 \
\App Paths\Loader32.Exe5 M$ u' B& E+ i- j8 Z& `
8 @2 u% ^9 c' D( b( m- m8 W( H, d; r: O
Note that some nasty apps could then erase all files from SoftICE directory
' F9 z p; F7 c3 M7 G(I faced that once :-(, H P0 B/ ?6 M/ v
; |0 H, q$ j/ q; d2 v2 ZUseful breakpoint to detect it:
+ E5 I4 S' \; M9 a0 K9 v9 i2 C2 M4 H& V4 z% _. E* |8 `
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'/ m) h3 m8 m) k; d
) ?' ~- g% O' {6 ^__________________________________________________________________________2 R/ l. Q( g! k, }- l- P# S3 ?
: _4 P" J I6 h/ ?
[8 C3 q; D9 ^$ ZMethod 14
3 _: b) N1 t3 L4 h=========
y; j' M' O9 I; I6 d% e) m1 @& `$ F3 `, R. v' ^! r0 [8 W D
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
! r6 Q6 E& v3 Ris to determines whether a debugger is running on your system (ring0 only).
1 s$ B) Z9 N! R/ u: D4 _( L1 b6 m/ t+ P! e y% c) J
VMMCall Test_Debug_Installed+ V' X) a; [- k! s8 K
je not_installed
8 [- r0 _" E% w# z" n
' W/ }8 X% K6 H$ F) KThis service just checks a flag.
4 K: p* m: H, r' D, C3 S</PRE></TD></TR></TBODY></TABLE> |