<TABLE width=500>2 H9 @: ]- w o' [# j( r
<TBODY>
* Z# q4 D, l& n, q' [- ~<TR>- w( ] W8 ?" G5 m8 }8 t
<TD><PRE>Method 01 8 t+ x" C7 E* E& m6 w
=========
o1 S' f0 t+ U+ `" n
- v5 P1 M5 b2 p. Q4 N8 V/ s" [2 dThis method of detection of SoftICE (as well as the following one) is
( Q2 ?# F8 H! sused by the majority of packers/encryptors found on Internet.
4 O% B% b j3 Y, aIt seeks the signature of BoundsChecker in SoftICE
& s0 c' p1 @7 n$ Y* @$ }5 i `8 Q- ~/ n" G# h- l& ]/ U! Q! [
mov ebp, 04243484Bh ; 'BCHK'6 s- z7 p3 v& ]/ c, O9 P- C
mov ax, 04h
) x+ h# `+ p! u/ t; Y* M int 3
* Y4 F; x( q }$ M( y% w, k+ r cmp al,4. D# m* z* ~# P# U, G
jnz SoftICE_Detected
) N: R+ c! z3 \2 s- @( I3 F
2 @! e+ x6 `" N X___________________________________________________________________________
/ S, t: r. e& y, P" X u$ }' t: T/ w. b$ J' c/ w
Method 02 M s. E4 ]) [ J: P2 [
=========9 D* y( r1 b- P- q$ p
. L, @' I+ I: a2 c" a
Still a method very much used (perhaps the most frequent one). It is used
7 m% I, X+ C. C. |8 Vto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
: ~9 }: d( n) ?& Uor execute SoftICE commands...; \( n0 Q# k8 H2 T
It is also used to crash SoftICE and to force it to execute any commands
' S5 J% S$ S( m1 B) P6 F, x @0 G(HBOOT...) :-((
' g# A e7 g7 W0 P) j# H9 ]* B1 a7 Z; w
Here is a quick description:+ V" P+ K9 d( h8 D2 b. }- l
-AX = 0910h (Display string in SIce windows)% b, q# j" N$ H, E# V. T+ r
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
7 Y/ _' @ M. _/ ]" q9 q-AX = 0912h (Get breakpoint infos)0 E0 ~6 ^. v! }3 b: G$ W
-AX = 0913h (Set Sice breakpoints)9 u9 C8 K7 F. p$ I$ i% ]
-AX = 0914h (Remove SIce breakoints)# ?# B0 m) R: @; T6 i4 [
: E$ @* o0 R- Y) r% wEach time you'll meet this trick, you'll see:' l6 I5 }1 Z, D
-SI = 4647h( K- n, W( Z4 Y( {: i' W. W6 n
-DI = 4A4Dh) ^* R2 z1 V# ?1 T
Which are the 'magic values' used by SoftIce.( B& U8 W! e( B% c* E3 P5 T
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
k7 s9 `' @7 _ [" p0 c' r4 J; ^, L; ]) J7 A. }8 X2 k. Y
Here is one example from the file "Haspinst.exe" which is the dongle HASP) e9 Y& G8 o) s! ?! K
Envelope utility use to protect DOS applications:
( v" Q. p: ~* D$ w, X. ?2 u5 O1 `9 q$ S4 Y* ]/ K8 d
" |8 S N) e4 ?, \& s1 O4C19:0095 MOV AX,0911 ; execute command.
: M: T! V; p8 ^ Q1 U8 _4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below). ^+ s3 @; O. V% G9 [% z5 q+ B
4C19:009A MOV SI,4647 ; 1st magic value.
/ r' f) p+ z0 ~7 Y: K4 m4C19:009D MOV DI,4A4D ; 2nd magic value.
7 R! |" w- e4 s7 ?4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)9 @( X3 B) U5 A) \
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
7 i2 w2 Y" ~+ o- P5 |, E' g4C19:00A4 INC CX- w9 o$ e( w) Z) |# H+ l$ I5 _: u% ^
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
: h% x$ N4 I. D0 h! l' u$ C" M4C19:00A8 JB 0095 ; 6 different commands.: M! G1 N9 N! M3 p% v
4C19:00AA JMP 0002 ; Bad_Guy jmp back.; A9 u/ P& g4 w% ]% }9 @0 J6 w& |2 K# \
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)" v& D( j% k! u: n( |3 j' `4 O: E# M4 q
2 v' m) v9 @2 n5 s2 g
The program will execute 6 different SIce commands located at ds:dx, which
7 L( U; K9 a& Sare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
) N. |5 z0 Y' r) v6 {# x8 `9 ?2 x. Z. Y# T$ f
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
' b3 L. B7 ?; G9 b___________________________________________________________________________
/ T+ A; M6 L( B6 o- a& ~$ ?2 S+ j8 g: l( }/ v6 ~
5 x( V- t- f$ ]* m! l. P4 QMethod 03
! x4 b: f% m& U m=========
R. T; L) c- l3 z6 Q* T. X
' j( _4 a9 k+ v( zLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
* J+ b: V1 D3 F0 f/ }(API Get entry point)
, L9 s$ C z# f- ` 9 M: N9 b; m" O0 V$ A5 a3 I% o
% H) x9 z, L) H; {
xor di,di
9 X- m* @* o9 [( L mov es,di
' u# y: _" X9 y+ V+ o; i1 l mov ax, 1684h
' p- |- B5 `6 ]& I ~ mov bx, 0202h ; VxD ID of winice
* _2 i, I$ w, n% P7 t int 2Fh" ^0 a9 G2 Y4 F+ d# r1 c. |
mov ax, es ; ES:DI -> VxD API entry point
1 K6 Q1 G$ x# g& H6 x( h2 ] add ax, di- W9 B6 H* F l( {; K
test ax,ax( M' g, D2 \( L1 {0 g
jnz SoftICE_Detected. K% ^) }$ Q' z* R" p- }
" Z% _6 V5 P: k% k4 }! X) ]___________________________________________________________________________
m' C( O/ [8 x
& |6 Z' W+ a7 l4 d, S" wMethod 047 l4 Q: O2 S3 R" R, A
=========% I* \, T A/ R. S6 d# v
5 k+ D3 p0 `9 y( H9 a! p! lMethod identical to the preceding one except that it seeks the ID of SoftICE
# F0 m& M$ {3 eGFX VxD.
, K& s3 ]* F0 |6 _1 r" ?' h5 _+ o* Q% A9 w1 l7 A
xor di,di, k8 v8 _; v' o$ t# l7 K0 Y, b
mov es,di
: ]( w) E/ e8 C6 `+ I mov ax, 1684h : R) B7 E! l3 W2 Y; P
mov bx, 7a5Fh ; VxD ID of SIWVID
! K/ Q i; G, @- u9 x- I X int 2fh; m9 X9 U; k* M$ b
mov ax, es ; ES:DI -> VxD API entry point
5 Y+ m/ `* D6 ~0 | add ax, di% `" o# v1 R6 q0 _+ e [
test ax,ax
5 E8 Q0 M; r% Y jnz SoftICE_Detected
5 z" C! I4 G! |- |! i; a% {/ e" S9 ?" V9 F
__________________________________________________________________________" f. n( b# h! u, I
, t! t& [; S6 ^$ U; ]! H1 b
1 y' A* @8 a" LMethod 05
9 G0 ^4 v2 q, C# {- A8 |* q=========2 T$ W4 D1 s* V7 t& T7 F7 J
# Q* M# Z* G1 U( f! m6 g8 }3 _
Method seeking the 'magic number' 0F386h returned (in ax) by all system
9 W( ~) N- o' u1 C- Xdebugger. It calls the int 41h, function 4Fh.
' _* J6 A$ ?& a3 RThere are several alternatives.
4 R( v/ W' V' `) ^# L( ~. o. Y' }& x* x- Q
The following one is the simplest: f: q! T2 w* j7 R* k
2 X! k! D0 X8 g; z
mov ax,4fh$ Z: }1 ~' Q X
int 41h" {4 K. v0 _# n+ t3 X
cmp ax, 0F386
, i, D) a2 F, n jz SoftICE_detected
% J- J X: _, {" m, L# G8 R# b% |0 x z
$ K h1 ~5 }- a2 m" r# mNext method as well as the following one are 2 examples from Stone's 5 r2 m* A3 W) n6 S; L, f
"stn-wid.zip" (www.cracking.net):( A+ ~0 d3 U6 S; Z# J7 s4 A; [; t
" `/ z) D: i+ w' j: ` mov bx, cs
2 l' P6 Y5 v9 K( T+ R lea dx, int41handler2
+ P; s; ~9 _- a% h1 \# l xchg dx, es:[41h*4]8 ]0 `; f0 w7 N) n4 K u
xchg bx, es:[41h*4+2]
W; A# A$ j3 W% B. G; Q4 f mov ax,4fh/ g# ^+ y8 X! i: A3 X
int 41h
* J0 }: B( O6 K8 z xchg dx, es:[41h*4], ]8 X4 P$ c+ W$ Z2 S0 o
xchg bx, es:[41h*4+2]* R3 Q& h8 C2 y/ ?3 ^( L, \
cmp ax, 0f386h a$ E7 {3 h7 T5 W4 u0 @$ ^9 c
jz SoftICE_detected
6 R$ @9 n3 X# a8 y1 _& s6 @: n% c! V1 o: R
int41handler2 PROC. X* x' q7 W! ~, n) f% p
iret
* A) ~$ T; A* bint41handler2 ENDP0 j ^8 A/ u3 [! n
. g3 e' v x% E) n( F2 R
y" ^! A, Q5 G. Z2 {- L g
_________________________________________________________________________
* ?9 k+ U+ i( e2 r* E- x$ E( W9 T- D. \8 w
5 f7 X2 S; o, d& Y. gMethod 06) m; a6 E% n) Y( y6 o( ? {
=========1 r, v8 v) y; U
! O* j# F8 [" d% v, Z x1 H* X& d4 |9 e- h0 p- o
2nd method similar to the preceding one but more difficult to detect:
( ^& X! M' k" i, D" p9 S
# G1 |: ~# F4 V& F& P+ ?) m' j# H8 @4 y4 o) Y
int41handler PROC3 ?& _7 u: w4 \1 V! ]7 y! [
mov cl,al
+ N8 @7 a5 Y1 P c3 v6 I iret
9 i8 Z* C$ s! x% ?6 d: jint41handler ENDP
* x* a7 Z* s" ?, E, A: y- m7 V6 |% L+ H* ^! h8 w) P0 {
% @+ b0 p$ U$ E9 Q, K2 i
xor ax,ax8 ]$ I* L' D; q6 k+ |
mov es,ax3 f3 B' w/ e! w$ T0 H# I! {
mov bx, cs: d8 P! l- o y/ k8 j) n( J5 T9 i
lea dx, int41handler1 I3 `& A- X) N9 t! Q
xchg dx, es:[41h*4]$ r" Y( e$ p3 ?; x# M7 g% ]2 B
xchg bx, es:[41h*4+2]
4 y% n$ D6 z* }( Q! n in al, 40h
1 m# J+ ]- ~) C! g3 u xor cx,cx% l" L* \& b5 h+ w2 I4 C# y/ E
int 41h# d: d3 q( E4 M! ^7 k5 v- \
xchg dx, es:[41h*4]2 S" L2 M+ x. L' R" A
xchg bx, es:[41h*4+2]" w/ Y# D# [2 B0 R8 `8 P# S
cmp cl,al
8 N2 l3 F/ B* j8 A2 f2 m" w" A jnz SoftICE_detected: I; j0 _8 b; e5 b% k- ^! N u# c- }
8 }% d& D. A' F_________________________________________________________________________' ]) u8 N" ~" s' U1 k% ]' X
; g C9 e$ v3 q- V/ _
Method 07
- i: L4 O3 d& v: y=========
$ i. z9 `! }4 p) V- B2 P1 J! a/ B3 A" b9 F7 C7 p( Z# u+ c: @) _
Method of detection of the WinICE handler in the int68h (V86)
! Q0 Q- P! |& s# I
) V4 |. B8 `: s mov ah,43h
, \$ ^+ N) _ ^' k$ X1 j. Q/ }, n" w int 68h$ L1 l6 u/ d% ~
cmp ax,0F386h
* r9 r% G- A @) K. O jz SoftICE_Detected, R& r) w' i. ]+ E+ ~+ W. v4 _
- \* i8 i& V( C# w' e& N
: a9 ^) K& G8 w- D5 p- H=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
6 q0 d! n0 v/ E) ]/ P app like this:2 H* F! V8 E% F. _( R( ]
4 ~+ ^; J+ T9 D1 m* M+ `* [3 t
BPX exec_int if ax==68' L# l! G& ^; j! Q2 J1 V
(function called is located at byte ptr [ebp+1Dh] and client eip is
; I( W- O# D+ y& O ~5 b) U+ W. j located at [ebp+48h] for 32Bit apps)
) M) ^/ A9 G7 t__________________________________________________________________________
5 D* ~) Z8 d$ S2 |" y! S# O: C. j, q2 z. J4 W$ W9 U; A
9 A9 w2 r8 Y3 n2 O$ y
Method 08
; i& a4 H. X" d% L=========, H" C1 V" i; _
4 [* \2 W0 r5 i& W1 ?' T
It is not a method of detection of SoftICE but a possibility to crash the
: w% ?* s$ p' u9 J# I7 esystem by intercepting int 01h and int 03h and redirecting them to another1 E4 W C! C/ X+ V( L2 g% w
routine.6 g) I3 _% E, h' {
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points8 J0 h& F+ A1 Q/ }" G
to the new routine to execute (hangs computer...)
6 T! m0 q( K/ K; C+ @$ W' w
) {0 V8 D" q }0 G0 s& y mov ah, 25h
9 z4 X! k: A/ } |" J. C mov al, Int_Number (01h or 03h)1 N1 k2 C4 ?$ j, S& U& G2 [
mov dx, offset New_Int_Routine7 B5 o3 y& X- f1 x2 n! N
int 21h
6 z' |9 q2 s! L3 e' `4 [7 [7 x- J+ M) \& x1 @
__________________________________________________________________________
$ k) D: ~: O6 T
5 F1 O" g9 Q! i2 hMethod 09
! c4 E7 Q+ x( x, G) W& `# q( v( f=========) [/ Y- F5 L, g
/ D% B) F: Q7 v* L- d5 x
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only7 Z1 ^. l3 A: f
performed in ring0 (VxD or a ring3 app using the VxdCall).
7 ?7 X" i/ R+ {( `9 s+ PThe Get_DDB service is used to determine whether or not a VxD is installed
! `5 k6 s/ `) u* N8 T* hfor the specified device and returns a Device Description Block (in ecx) for
! T$ a2 o& B/ ]# x' P g& r5 R0 ithat device if it is installed.
$ M N" U& V$ P$ |7 }0 `0 p% H8 M" [& D. l3 a
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
4 r! A5 O6 ?; H+ { mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)6 X) J% j1 M8 @
VMMCall Get_DDB) P$ y# g' `; ~8 l3 [! a# o
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed( w& B/ D" M3 p4 j9 F' @
' |: |+ p; @7 U6 \Note as well that you can easily detect this method with SoftICE:
% N4 d; I5 p, \2 [9 ] bpx Get_DDB if ax==0202 || ax==7a5fh
& B4 o& V4 k A& U' Z7 W3 a% S
. D- Q: W* ? i) T9 f/ Q2 L# w__________________________________________________________________________
, k( b$ p" G. N6 K1 u+ D, T9 l' t
Method 10- d% j2 P/ {2 P4 C) u) H6 x
=========: ]% ~% J/ v4 Y4 x! u3 z* e
& b' s; F3 ]2 R# `8 _! o=>Disable or clear breakpoints before using this feature. DO NOT trace with
" {2 h* K( v# A+ y* {% { h- ?$ x SoftICE while the option is enable!!
7 V+ s- P2 ]3 f& G( N) b5 R, W/ n" k
This trick is very efficient:/ W N& d& f2 D4 Z" p
by checking the Debug Registers, you can detect if SoftICE is loaded4 [7 S& Q _* c# S3 t0 w. B$ W
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
+ D! a) `9 q" r4 sthere are some memory breakpoints set (dr0 to dr3) simply by reading their* n @. S3 V# J$ `% P4 f
value (in ring0 only). Values can be manipulated and or changed as well1 I: d# x( J- @/ m9 G+ B
(clearing BPMs for instance)
* p1 g& W9 g* n& j
& h, h2 @# D( x& o+ u__________________________________________________________________________8 L @4 m* T8 l @& u
, I7 s# y! g% x2 H' j. X8 [' @
Method 11 I5 V' A H% m1 ?5 m# T
=========
9 c7 J6 d0 S8 s& A: V. r3 ^$ |( }/ Z4 D- d
This method is most known as 'MeltICE' because it has been freely distributed
8 g$ ]/ v( g8 ?. I& M9 R: t& `+ jvia www.winfiles.com. However it was first used by NuMega people to allow
; E) N: a5 f$ y! O+ s" J% x! XSymbol Loader to check if SoftICE was active or not (the code is located
6 n9 W3 Y0 b8 {3 |& Binside nmtrans.dll).1 D h5 i% A! A/ _
( l$ X& B8 @3 J" D5 BThe way it works is very simple:) S0 Q2 E3 `) b% K$ h
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for) t- u' I) N% m1 P6 P0 N9 P1 z5 t
WinNT) with the CreateFileA API.
- n3 F7 g+ y! i6 o4 E8 N2 g0 e, M0 U. n N
Here is a sample (checking for 'SICE'):
4 H0 c7 Z7 R) ?5 v" o
I3 P2 U. M& _$ s8 M2 l( xBOOL IsSoftIce95Loaded()" u `& F2 P' o$ m" j5 ]
{: R( G5 t8 ]% Q
HANDLE hFile;
" l7 d' @. K7 A* A) M1 E) b hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,3 Q* ~4 z& u; o- E8 }( e
FILE_SHARE_READ | FILE_SHARE_WRITE,
$ Q) s% j, C' a; m0 M NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
3 i$ R& d' A% Y: U- k if( hFile != INVALID_HANDLE_VALUE )* _# P1 f6 L* N0 t3 E9 f' Y
{9 j. O0 h, v0 I# b: ^" {
CloseHandle(hFile);: F" y ~0 w1 G7 K6 H
return TRUE;
4 O. Z U# y4 y$ d; H& Q5 Q- \# M }
E2 v4 `& Z7 }4 W return FALSE;
# t- B% l. ~; I- u L}+ l' p7 b+ o! C
" J, r* X8 r( ~8 tAlthough this trick calls the CreateFileA function, don't even expect to be
8 K6 [& c8 f ?& xable to intercept it by installing a IFS hook: it will not work, no way!: L; p- d% { x6 J
In fact, after the call to CreateFileA it will get through VWIN32 0x001F! A" _! N# ^5 S' }6 |* |
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
# h0 A# |; b6 u- M" M+ U, N2 _+ yand then browse the DDB list until it find the VxD and its DDB_Control_Proc; n1 x" [3 }. t/ Q
field.8 H1 b5 L U( Y7 v5 H7 ~" T
In fact, its purpose is not to load/unload VxDs but only to send a
' U8 N1 N$ r3 c5 m) e' \+ n1 qW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)& Q5 F6 Z1 u+ Z* }* g s- u
to the VxD Control_Dispatch proc (how the hell a shareware soft could try+ g) @! o5 t2 S) l3 h
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
$ E2 t- Y) N# S4 S. F( _If the VxD is loaded, it will always clear eax and the Carry flag to allow! {' r. A o. [# ^0 w' a
its handle to be opened and then, will be detected.: Z$ I. e, x; C7 k( D3 v
You can check that simply by hooking Winice.exe control proc entry point& z8 W- f9 L1 V
while running MeltICE.
! S4 f8 o- W G) h) H& p* I8 Y9 _- u+ S6 H& q8 f) g
2 o$ D1 Z8 W D# |8 c5 a
00401067: push 00402025 ; \\.\SICE
1 R/ x" `. o7 n 0040106C: call CreateFileA
* L& a* ^# \" y1 p 00401071: cmp eax,-001
/ c4 C$ F& _1 Z 00401074: je 00401091$ u* O2 u' K, x4 Y
; D$ N4 E& z# h* d3 t/ D
# y$ ]1 }$ \: X* G" ]There could be hundreds of BPX you could use to detect this trick./ w: d9 o& _' G7 |$ O% O
-The most classical one is:* }5 o3 M9 A' p0 C+ u$ }; ~; D
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
- c9 q) |( Q4 h7 Q5 `4 E* F *(esp->4+4)=='NTIC'& S5 K* Y# X7 V+ e4 [5 h( i$ ^' s
1 M/ y1 i" X' v1 T! P8 k1 M1 B. v) f-The most exotic ones (could be very slooooow :-(
% z# p1 o z& P1 j; w+ _; z BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
' K2 D& r+ |0 r0 {, o ;will break 3 times :-(7 Y9 h X: j8 I
0 q0 l# [1 P/ B) `-or (a bit) faster:
+ r0 v/ x; d Z3 ^2 _ BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
* G( R, i0 f& a* R6 z0 R2 z' }9 h1 ^1 A- _+ v9 W1 G& M# l
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
1 u9 z5 j4 G5 {- P- j$ n2 _4 S ;will break 3 times :-(
. ^7 P+ o( a7 z# \+ u! k; T& G
0 O2 s9 [: f9 Q" z-Much faster:) T5 Y5 _1 W+ _2 J
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'7 m( B* B% A# T
1 d* l' f8 H* q# P: ]Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
7 |4 z+ f% [ _function to do the same job:6 h, |$ }7 `4 @. H
$ f) G s+ V8 Y0 Y6 c
push 00 ; OF_READ
/ r* f) f, l0 `; [4 h7 Q mov eax,[00656634] ; '\\.\SICE',0, @0 D! o6 }/ r4 o7 S
push eax
1 w& x# l$ `6 C) [8 u8 A7 f call KERNEL32!_lopen
3 O5 Y# Q" h) f0 E3 O0 F6 \' g x7 m inc eax4 o/ ^& I; g r5 @* G4 D
jnz 00650589 ; detected& r5 ~9 \# z" v& v& M7 w
push 00 ; OF_READ0 [( R* s) X9 B3 p; t7 X5 S) x
mov eax,[00656638] ; '\\.\SICE'5 ]9 P( E/ Q- ~. f& w: F9 l
push eax: ~2 t5 ^ Z+ o- w. h: @
call KERNEL32!_lopen
9 a1 ~9 y: u l2 t, h7 F2 z inc eax2 D7 i7 l' ?8 j
jz 006505ae ; not detected
9 y! N: S5 l1 p# ^& z. |0 T
. h4 i* M0 B) {0 M- X% l# _ d$ v. [* n9 N2 F! W
__________________________________________________________________________
& m0 @; w; t9 q! h* i
/ c" _/ G+ J5 @. D, F& }Method 12: O9 p& f9 k! T4 K) o2 R
=========
* c D: _8 T" n; }5 H3 k3 [- z9 x5 j& _+ \8 [& D3 I$ ]$ T% F" L
This trick is similar to int41h/4fh Debugger installation check (code 05. S9 s4 s' p5 b! c T
& 06) but very limited because it's only available for Win95/98 (not NT). @7 P+ S. h; P; i9 l
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.1 h4 U. d$ W0 Y0 r, }
; ~0 N' R6 s6 t8 n) h
push 0000004fh ; function 4fh
1 d1 ?. g* i' \- _! Z6 E push 002a002ah ; high word specifies which VxD (VWIN32)
! A* a* m8 q8 r9 t/ j" L- X ; low word specifies which service
; G* s2 P0 N ~% k7 ~9 N* ~ (VWIN32_Int41Dispatch)5 |4 L, {: m! C2 n: B( ~
call Kernel32!ORD_001 ; VxdCall3 F# l2 ^9 u3 F* S
cmp ax, 0f386h ; magic number returned by system debuggers
2 a* Y& z+ C! B7 }+ ?: a jz SoftICE_detected# C6 G' Y1 `9 h- V# S
* f3 y6 ^: d" [* I y7 S. FHere again, several ways to detect it:
% ?! P- G, u6 |3 @+ i5 k& [, A3 O* n2 W& K7 H4 F$ g% c) M/ d0 T9 }
BPINT 41 if ax==4f
) e3 e5 W4 E8 p! x& M: o. L: I" s G- u/ K1 a& J
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one& [9 f _3 W. i1 Y. N
9 T% c D" `( H1 Q BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
; m& d$ G4 i1 S4 z+ c, ?' ~3 R; d7 D6 n% F
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
: B V0 o2 M( P/ ?. i7 W
! j/ N2 ` `2 q! S9 t, h2 \__________________________________________________________________________
+ t1 n* N' a5 V% J$ x
* A$ e; S4 Z% b8 w8 CMethod 13
$ L" L( @, E& `& b5 a* Y=========; r# C c4 n# [% W3 T2 z" n% p
$ j7 y% @4 U( G. C/ V
Not a real method of detection, but a good way to know if SoftICE is
: X+ w) y) J$ A4 T3 ~8 tinstalled on a computer and to locate its installation directory.
6 R6 H6 ~+ {( @$ Z8 ]/ T5 I' B# FIt is used by few softs which access the following registry keys (usually #2) :% X, v, I _/ T5 m8 i5 J
% x5 \& i) l: _. z' y
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 O: ?; r: A: w\Uninstall\SoftICE" e [- r$ _! `9 t7 b5 R, K
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
( d% Y5 h0 o2 D8 `" N2 n! ^-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion8 Z' `0 D; o0 b7 O
\App Paths\Loader32.Exe9 }: X* v/ F1 J9 {0 q! `. \! P( _
& |- g: N; j1 z. w
, J* I$ D5 g) n0 a
Note that some nasty apps could then erase all files from SoftICE directory9 z- ^$ m( s9 T" g- y" w$ i7 s8 w
(I faced that once :-(
% @0 G$ j' i5 M3 D+ |8 m6 Q% y2 c! j" |( [
Useful breakpoint to detect it:
) ~- _$ d3 }- G L
6 P$ G2 g/ G7 p1 a BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
1 x v1 h5 j8 d1 A: [5 c. a) S' w0 n0 q, h, H+ S' t5 f
__________________________________________________________________________# D: a C7 {/ q; t' r; o! o7 r
+ }" f; f) J$ G! u- K; W
* K# O* |( B' w# f, U7 g+ h
Method 14 # i( [( i9 D; c% ~1 Z
=========
( \% M4 h% w5 A8 I! T
3 h0 H* z7 [; @, dA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
2 T! e+ F1 }5 w: p, mis to determines whether a debugger is running on your system (ring0 only).! E9 f! R# x: p$ X# x
6 o' [0 p/ ] Z- K5 C: @$ t5 O7 x- b
VMMCall Test_Debug_Installed' s$ W0 N2 ~1 p
je not_installed
6 [4 T5 Y9 r- O* H# {; O8 C
4 j$ M! l& J5 p4 h# KThis service just checks a flag.; D$ N$ K- L; q5 [! A% i
</PRE></TD></TR></TBODY></TABLE> |