<TABLE width=500># P! B1 e$ G# s# I' j
<TBODY>6 m+ A& t4 }+ g. Q Q4 g& _
<TR>
9 z' y( t2 X/ ]) U<TD><PRE>Method 01
; ~! ]1 F/ B( [=========" P) w/ [% D- ^ f& c" w
9 e0 |/ n. B3 T/ S1 s- jThis method of detection of SoftICE (as well as the following one) is% l, t) c( o) T, D0 _
used by the majority of packers/encryptors found on Internet.+ g) f% s. K8 y0 Z
It seeks the signature of BoundsChecker in SoftICE. h8 o" {1 |; u% H: y1 l0 S
3 U8 N3 U/ n$ q" g2 X3 l8 m3 N. F& ^
mov ebp, 04243484Bh ; 'BCHK'# w8 t2 u: A. ^
mov ax, 04h
* J2 i; d: K. X: G# K' u3 M9 u int 3 5 N3 A5 @( G; U; I+ B
cmp al,4& m- h$ L( w) u0 {
jnz SoftICE_Detected9 A9 s, N6 j2 `1 N/ S/ t# F; C
8 K+ L1 F: C& t1 k
___________________________________________________________________________
) T, Q% |/ ]/ D, P5 q5 T
+ `) E( l% v q: rMethod 023 K+ I# m2 _6 j! O3 x; A* r8 t7 u9 z) C
=========
/ g+ ?5 I3 S% r, k+ y# k: b* x
9 r' i" {, _ A, d. zStill a method very much used (perhaps the most frequent one). It is used' `' n" r6 `( F; l1 k$ o/ U
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
. y+ v+ Q5 z T H7 ]$ ]or execute SoftICE commands...
; Q- _( P4 [- b: t/ \( hIt is also used to crash SoftICE and to force it to execute any commands* X8 A: x5 [6 q/ B
(HBOOT...) :-(( ) M' l+ m+ U% C% G* ~
9 _" s( O( H) N0 n! i; K% wHere is a quick description:- A3 _+ g6 s. V1 I# A4 @# U7 E, x
-AX = 0910h (Display string in SIce windows)
5 \5 g6 n& f, ?+ \- e' D5 c7 p" G-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
9 H; y+ e) i, q1 k. H/ J: x-AX = 0912h (Get breakpoint infos)
$ ?( L Y: }& Q$ _4 P* A-AX = 0913h (Set Sice breakpoints)
* ~4 q8 f9 D* t4 G3 F-AX = 0914h (Remove SIce breakoints)
& e* P* x) | `& E( a
$ R7 w; q, `1 \4 G7 v5 P& @5 ^% CEach time you'll meet this trick, you'll see: O) N! q5 u* o. `& I, p0 B
-SI = 4647h
+ d$ O4 O2 c! T! k6 P2 E( X-DI = 4A4Dh* F4 a/ D2 h) E
Which are the 'magic values' used by SoftIce.
4 _1 ?: O8 e: I' G; y3 S% {For more informations, see "Ralf Brown Interrupt list" chapter int 03h.+ L+ I/ O" y( v# o D5 A
+ f; \& ^9 h7 A" a4 N- K, HHere is one example from the file "Haspinst.exe" which is the dongle HASP
. [- g- l+ n4 l: c3 }Envelope utility use to protect DOS applications:0 w; `3 q/ o+ B9 P. l
1 B9 {% v8 n/ S6 h$ H. Z6 ^. X6 F, y- M2 }4 d5 p$ W% u
4C19:0095 MOV AX,0911 ; execute command.
7 M' E& A. p; z4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
W( h; z. q; F: e5 [1 `& V4C19:009A MOV SI,4647 ; 1st magic value.
, @( h# n8 R3 N( q0 w4C19:009D MOV DI,4A4D ; 2nd magic value.- I) i- t @, N% R, |( F
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
/ Z/ l, ] b. ~& Q4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
- G, j R7 {3 R) O4C19:00A4 INC CX
5 [0 b0 Z& D, z9 Z N" g% Q4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
' g1 e2 ]9 w$ a3 Q1 G* X4C19:00A8 JB 0095 ; 6 different commands.
6 I8 L" c- x/ w9 e( x' |4C19:00AA JMP 0002 ; Bad_Guy jmp back.
/ ~3 C: I3 ?* {4 L1 S [% M2 J5 D4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
" D5 S3 |$ [. c0 u! d( R" [2 @3 ~5 D* m
7 v# R6 \' x+ y; s+ tThe program will execute 6 different SIce commands located at ds:dx, which
& J8 t1 Y9 S4 c* R Q3 Pare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
4 b) C+ T$ s. H! t+ k; q& A; u" L C- M
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
" E# l2 R: K- @ R___________________________________________________________________________
0 B% M$ H1 W8 ^; x) d, k j+ ^, x- F
) P5 b- \7 G% `6 j' u# J
Method 03
( m$ g8 u. L4 z6 W$ f=========
' ~( R/ O0 B8 j3 _9 {! D2 u( H" \% D1 n# b
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
( |, ?! W' r& d y; T7 Q& x(API Get entry point)
3 c* G" e3 o2 F, D' D: x# P
! u u- L4 X! h, B1 s; Q" Y8 {! W( w' X
xor di,di
* `1 X r) i) S$ n7 ^8 v) j: z mov es,di# y5 z+ r7 H- l
mov ax, 1684h
, n2 H4 D0 \/ z, M( `" m! S mov bx, 0202h ; VxD ID of winice( M' S( c9 H* n' U& P
int 2Fh
6 P( _# u$ D& o# F2 G% H mov ax, es ; ES:DI -> VxD API entry point
! ]$ Y' @$ X" E/ d( h$ y% Q" c9 @ add ax, di3 x2 M G& R; `
test ax,ax, l, e% U- H# f- X' q
jnz SoftICE_Detected
. G' A7 J9 w4 t3 C; w9 S# p3 e; f" Q( J {/ S
___________________________________________________________________________+ d- m1 f7 }# W( d# h
+ Z! m' X6 V. P3 J3 uMethod 04
# b* I3 W( _( N: C) `- M=========
$ w$ \! ?+ e7 _$ e- A5 d0 ?& }, Z F. O3 F0 Z h
Method identical to the preceding one except that it seeks the ID of SoftICE
3 Q7 ?7 {/ `- f c7 L; G2 g" W& YGFX VxD.
, H0 V3 P* X u: a3 d
- ^0 y2 k* _ g* W3 z: |" @- y xor di,di
0 _6 p. E. @$ X: S) g' S mov es,di5 y) G; p$ y: u( |* O: N# {+ U, Q
mov ax, 1684h
, s4 ~; I% d+ o$ O mov bx, 7a5Fh ; VxD ID of SIWVID" |0 n3 J8 l; K" n: H O
int 2fh
) S, K$ Q6 Q0 T; X5 c mov ax, es ; ES:DI -> VxD API entry point0 T; W3 F9 T) k3 X( g2 j3 F
add ax, di" @" W& a" j+ q+ u
test ax,ax
: Q4 X h" k, i8 R8 ?6 t jnz SoftICE_Detected! E1 c0 }2 ^8 [% O7 k
7 E* b1 _+ k% m+ C1 h1 e" W
__________________________________________________________________________
# D- t g$ c9 d% R7 e% p$ A3 [( w, q5 O
# M+ Q3 _6 K' {& e4 G) U: a/ x' f$ V
Method 055 J! L0 E' @7 f( V
=========: f! r% Y2 y) b+ t/ a2 f1 m
3 \ e ~: T7 x
Method seeking the 'magic number' 0F386h returned (in ax) by all system0 N( J4 n9 z1 T; U* b
debugger. It calls the int 41h, function 4Fh.
5 Z: D. H: Q; ]3 vThere are several alternatives.
7 ~( K$ P* u; }+ n2 p) @* b) f
/ P7 A c; a5 E. VThe following one is the simplest:. B7 T t2 d- E) [" @7 |
% J- s, m" I- w/ L/ F. Y mov ax,4fh
. f Q- t+ F2 h7 S+ H1 j int 41h+ L5 d, U- i& w$ X
cmp ax, 0F386* r6 A1 _/ {8 M$ [; S
jz SoftICE_detected
. V3 O# x" x9 C f$ b Y. d) }) S6 Z0 `
7 j9 Z+ y* r. Z. |/ p MNext method as well as the following one are 2 examples from Stone's ! A# [6 p" S1 O- ^0 l
"stn-wid.zip" (www.cracking.net):
) s0 R1 c# x+ c1 ]: Q: R* E; M1 X7 l& M+ K$ Y5 {
mov bx, cs
# h& |% }7 |' L4 d9 w lea dx, int41handler2
7 X- K! Y; A9 G% S xchg dx, es:[41h*4]6 ~ w5 X1 K+ X/ f8 v
xchg bx, es:[41h*4+2]
8 u0 m. ]* i" O. f; z. J7 Z mov ax,4fh
5 r1 ~: @+ `! ^5 L int 41h
6 o+ A6 K6 r* H [: o7 C xchg dx, es:[41h*4]
' L1 I/ r9 C3 T. g6 K) @' Y: f xchg bx, es:[41h*4+2] ^4 h% D) ~" \4 o* W
cmp ax, 0f386h, J7 D. t+ R( m) e6 `1 q
jz SoftICE_detected# O* @! _* V' n* n
# y6 {& y5 Q; j' q0 ]. s" ?. hint41handler2 PROC
% C' i" y0 L, ^ {- n iret
7 K; ^" X- v+ u+ M9 [int41handler2 ENDP
: f4 ^. r" X- K8 J/ v) n% a, V. r* \; [
- ~0 _: M b8 o5 Q) w
_________________________________________________________________________9 N% N# P% t# t( J% g4 {) N
- t9 e7 g4 L" P* R; Y" `1 W; m$ X( ^7 ~3 I2 d# N2 A X
Method 06
+ E* }# l2 u# c=========5 B1 v- W N* R4 k2 W
* a* z) T7 b4 k6 K- H
+ M2 y7 S* k! Y
2nd method similar to the preceding one but more difficult to detect:& A0 o/ n; ` N/ B5 L; X
. P4 y" K% P. _& Z5 [2 K0 l
- d* y/ f) w% m
int41handler PROC0 U2 z# D( m. @6 w: A9 l
mov cl,al$ W5 t( {3 F$ ?$ h, O( {5 P. h' b
iret
. p* H6 Z3 @) s4 b8 _* Lint41handler ENDP R/ @7 F1 |" _* }8 f: s: R
* ]$ ~3 q: H* t2 I9 F [
4 a+ O1 N: W0 v# m! b* _
xor ax,ax
! w2 g8 V+ S! R6 M mov es,ax
' d! @/ x( T- r4 }* b mov bx, cs
* w6 l- ?+ Y+ O, [7 P+ Q lea dx, int41handler) O- S- B4 g) x
xchg dx, es:[41h*4]# E' P& ^7 k5 ]- x* Y& l
xchg bx, es:[41h*4+2]
: G( r8 d, \: p in al, 40h8 t. Y$ @% V# Q# _8 R
xor cx,cx
7 j3 j& q2 n2 {2 Z Q. s5 A int 41h# H" D; v/ {- P) x; J4 |
xchg dx, es:[41h*4]* z+ c! q1 t$ W1 \, A' a) Z
xchg bx, es:[41h*4+2]
. f+ e; j$ k5 Q4 ~ cmp cl,al$ Z( ^$ E( p9 Y; L7 f5 o
jnz SoftICE_detected
" B# I6 X0 s0 Z7 U9 N8 x* w& b' K a: F5 p+ c' S, D3 X
_________________________________________________________________________* m5 |9 `0 L" I' g+ ^/ z
5 [- C( J3 @( a& K' {+ x! v" e
Method 07( K: t6 v# C0 l8 J/ o1 j! r
=========
7 d: Q$ X( g2 J) U' W) g4 d; U. ]6 f
Method of detection of the WinICE handler in the int68h (V86)" ], h( L5 C- \/ ?/ \, v7 A0 `
: R# c. S8 T% z+ B o
mov ah,43h2 F v0 l9 }! L6 `& F w
int 68h
( W: f' d9 G0 r2 [( Z0 }* A& Y cmp ax,0F386h
. d# e" g: M o) r- w$ l$ Y. c jz SoftICE_Detected
& D5 W2 Q! e9 `4 Y4 Y1 m1 E5 a
, d6 G! K# n0 b1 e
& \9 N8 S) Y" m=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit0 B1 X+ {: `# {! ^( C" T" {
app like this:
" L8 C; z! B9 I; P+ O+ h0 e( Z* Z/ b+ _" g5 l- C6 K- I- G
BPX exec_int if ax==689 R* O) f$ u$ f; {! m
(function called is located at byte ptr [ebp+1Dh] and client eip is
, o/ H) y& D9 k5 M! m- ` located at [ebp+48h] for 32Bit apps)
7 T) X3 h3 [5 t5 k) f__________________________________________________________________________9 B- n& ^ K0 r! m9 T
* T5 x; {9 x5 C
3 g5 c! I3 n# c$ Z
Method 088 e/ ^3 c: i. }' m
=========! l3 n/ Z& G( K0 e
: s5 j% I; u% V5 K" QIt is not a method of detection of SoftICE but a possibility to crash the- N+ n8 V0 L4 Q4 u p, i
system by intercepting int 01h and int 03h and redirecting them to another% x$ O( x& F0 N
routine.5 Y# j4 y4 A, g9 A( J# K
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
8 c/ I* h! u" mto the new routine to execute (hangs computer...)
8 v" A% X/ {6 L9 N& @
/ }" O: t$ c3 B! U/ r ` mov ah, 25h
' K8 J% U* a3 |2 g' W- [* k& o mov al, Int_Number (01h or 03h)
# k" Z: Z: x1 b1 j mov dx, offset New_Int_Routine
' s, I- O# @. }1 q int 21h0 p5 j3 f3 r' h; t# @
" j$ S$ \3 f/ l
__________________________________________________________________________# g7 ?0 n O& G3 r) b6 e
$ z! G7 k0 l7 F/ K3 T8 v7 o2 p- QMethod 09+ b# z/ f% y; Z- c; p4 d; X
=========
4 u* O0 m1 v! e1 i) B% F$ W8 @2 ]. B( l$ i F
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only A, ?% b8 r( L6 ]7 S' b4 b+ m
performed in ring0 (VxD or a ring3 app using the VxdCall).
( k d2 z, i0 l1 L5 T9 ZThe Get_DDB service is used to determine whether or not a VxD is installed
0 ? f$ N; z8 J; tfor the specified device and returns a Device Description Block (in ecx) for
( @' T5 l8 F2 |" ~+ s1 \that device if it is installed. f% Z$ Q( N: M T. J' x5 E" j
# C- b) u0 D, w2 S# K mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
4 Q! D6 m, i. p0 p' ^2 Y! R4 y mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
+ h/ v; J% i+ T1 O2 L, a VMMCall Get_DDB; N2 A# ?% m) \: ?% f4 B! C2 _2 ]
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
8 n/ O# l# \2 k, s3 C5 t
* K# I% J7 }+ h+ Z1 |) eNote as well that you can easily detect this method with SoftICE:0 k+ u' V: o! C$ O% E& s
bpx Get_DDB if ax==0202 || ax==7a5fh
R* U% F) u+ e- F" p0 w
+ w% k7 v- ?3 @5 L& u__________________________________________________________________________" P' U! @3 Q' _; d8 [
$ T1 _% Y# y4 c
Method 104 V. ^* A' X; S' a, b7 C4 d
=========; n0 h3 z+ @3 l) W k+ z$ i
( P* J# R0 ? P) x/ `9 b3 a
=>Disable or clear breakpoints before using this feature. DO NOT trace with1 V3 e2 m. y3 f; X
SoftICE while the option is enable!!4 Q$ ^2 X2 B4 ?/ z
4 h- u. I- c: ?7 CThis trick is very efficient:
$ G1 n$ `6 s$ r0 M8 u7 ?by checking the Debug Registers, you can detect if SoftICE is loaded
. j/ x) r* i( Y& w(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if, v8 ]* R, Y' Z7 c& D E3 q
there are some memory breakpoints set (dr0 to dr3) simply by reading their8 N8 g! X6 y& x+ t/ M
value (in ring0 only). Values can be manipulated and or changed as well& Q' \$ H! u" z3 A# E
(clearing BPMs for instance)2 u! \2 q8 n4 h, \ ]" c# V
) T5 ]7 x& M9 T3 e/ d
__________________________________________________________________________. N! v) {3 b5 `
5 V i# J( [, A) J
Method 11
+ P3 ]2 J9 |; F& @0 e G1 W# o=========( z- h* s2 M3 u8 r
* P( D$ |" _6 C4 SThis method is most known as 'MeltICE' because it has been freely distributed
3 K b! S8 e- \. |4 h- U* }via www.winfiles.com. However it was first used by NuMega people to allow
, U( I- d; K2 @# w+ ~- qSymbol Loader to check if SoftICE was active or not (the code is located, S ^+ D+ d W3 j* Z4 c+ B2 h
inside nmtrans.dll).
7 m9 K" c4 {: I: k; K* ]
# o2 A5 F8 Y; n! C' q6 p8 ]The way it works is very simple:, G8 R0 f6 P7 N7 s* R
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
( [4 y% r& S0 |" k. P& c* [# IWinNT) with the CreateFileA API.
0 H4 ?- F5 o: O$ n! Y- n. M, o+ c2 m7 P9 T0 r& X8 q0 F( H7 ?
Here is a sample (checking for 'SICE'):5 }4 f8 l& B7 e2 g. w
9 M; Z" t5 x# ^9 JBOOL IsSoftIce95Loaded()1 K. u% u/ [1 O2 D7 s, O
{/ R3 W8 C2 j- a4 ^( m) g' w
HANDLE hFile; 4 L) v4 |- ~$ R: J
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
( H9 k1 e; G( B& R. E% c6 s4 W FILE_SHARE_READ | FILE_SHARE_WRITE, ~8 G+ d4 Q5 ?/ C5 `
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
$ k6 R( ?/ Q! N8 T- Z9 L4 Y* w if( hFile != INVALID_HANDLE_VALUE )
+ q: s% {5 X9 {! f {+ ?8 E2 u$ ]' ]% C0 Y6 ^, @
CloseHandle(hFile);1 M# f7 N6 Z6 L) T( [
return TRUE;! F3 F+ g. ~" L8 C+ F
}; R/ r1 W" t J G7 X1 k
return FALSE;
) ^, B2 U7 l: S& }/ o}
( Z/ W# [3 A& a% s
- I6 H3 S8 {6 B6 t6 T# h2 LAlthough this trick calls the CreateFileA function, don't even expect to be% Y# V6 B1 E0 W
able to intercept it by installing a IFS hook: it will not work, no way!% L( _1 `- \) T, _& V, Z5 A
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
q, @0 p/ Q mservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)+ f( x* E. Y- g6 ^ }
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
) C6 I. `& g9 w/ ?field.
5 T5 K7 Y% v8 _In fact, its purpose is not to load/unload VxDs but only to send a 8 A& N6 B$ O( s0 _; K. N
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
& ?8 g8 B; g( d' hto the VxD Control_Dispatch proc (how the hell a shareware soft could try
# Y( ?8 x' X. c- B1 D- Cto load/unload a non-dynamically loadable driver such as SoftICE ;-).2 p6 _+ S+ \3 \& [; j# @4 C
If the VxD is loaded, it will always clear eax and the Carry flag to allow
$ Y: X2 p# M3 L$ Hits handle to be opened and then, will be detected.
8 s6 J0 Q* s5 T/ h) fYou can check that simply by hooking Winice.exe control proc entry point" X |. l$ S- n2 d
while running MeltICE.7 V# }0 p' d3 f3 p2 @
+ } C" T$ ~ B [ V _( h
$ J3 T# b$ V- |- q1 A. r/ N 00401067: push 00402025 ; \\.\SICE# J: n5 X8 H) D$ S$ m
0040106C: call CreateFileA
8 s# G1 `9 K% {8 S8 r. P, l 00401071: cmp eax,-001 r" i! g' z! D: _$ L1 o
00401074: je 00401091
+ o) G% B! V$ O- h' [$ w$ W B, S8 V! h# X& t
- h6 H+ F# r. ^There could be hundreds of BPX you could use to detect this trick. ?9 M0 `& `, e* y f
-The most classical one is:% z r/ w6 A' f1 g% Z
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||# L) f' ]7 `, F
*(esp->4+4)=='NTIC'+ m% b7 e* ^( d
% X: h" i2 m/ O" i: `2 i( I
-The most exotic ones (could be very slooooow :-(2 j: G+ J1 z4 s( ~
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
! k2 c: I6 ?) S( x. ]- x ;will break 3 times :-(' n% P" g) ~4 F; \$ y# U, _
" a8 _( h6 s! b* v-or (a bit) faster:
. J6 g' z9 j ~% m) t& ] BPINT 30 if (*edi=='SICE' || *edi=='SIWV'); j* y P) ~! z! x1 n, w
7 _5 H3 z& N8 g, b7 d% p9 @( ^: m# P6 I0 p
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' ) G1 }5 i' `$ ~5 b
;will break 3 times :-(; [7 i# Q! r. Y! V& K9 D# E& H) Z
# v" K- D o" S-Much faster:& Q) M% P& [$ _- Q5 @" O
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
7 l# s8 R/ Y6 I) t+ b' ~( g9 K* h7 @$ j9 P( x/ n
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
+ X4 I1 M1 { S# q. v+ w) Ifunction to do the same job:
* Z. ]; x$ }# u
. g0 J2 I1 u& S; R push 00 ; OF_READ& S' j2 j! x+ {3 }0 D1 H
mov eax,[00656634] ; '\\.\SICE',03 S2 H" I E- X9 J
push eax
! s- B+ m5 Z. j% b, C call KERNEL32!_lopen+ v. z, j3 W6 h" R
inc eax
& }) `9 N7 }3 W) f% @ jnz 00650589 ; detected
( q" K" Y5 Q. R p7 x$ X- E4 R push 00 ; OF_READ, c6 |. j0 U r! w
mov eax,[00656638] ; '\\.\SICE'
1 u+ a& L! ^- r. F1 y S& p) Z push eax: q( i2 Q' u1 V% ]6 {
call KERNEL32!_lopen, b! I$ _1 i7 \4 ^
inc eax* `! w8 _% M' e4 e
jz 006505ae ; not detected9 N6 g0 V; S/ k# o' o
' k% c3 [* T+ e) t' k( c }
% O+ m% ]% G5 H* n9 y& k7 Y" b8 Q1 r__________________________________________________________________________
h) h9 O( M. C$ m* p L% [. o% ~& U
Method 12
$ q0 {5 s' L" Q) `=========
6 w( E- a) d9 I l
* Z. t* ]3 ~* ^+ g6 IThis trick is similar to int41h/4fh Debugger installation check (code 05
) Z+ L1 ^0 l, Q2 h. s; g& 06) but very limited because it's only available for Win95/98 (not NT). m1 O( J% ?: Q- q, l) o4 _
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
# }( a! p3 R2 U' D& c8 \8 K5 k+ `7 s: M( c" C
push 0000004fh ; function 4fh5 j! o+ K3 p7 q2 D$ m: |$ j
push 002a002ah ; high word specifies which VxD (VWIN32)
( e4 O) g. K& O ; low word specifies which service
) c7 K6 H+ h9 q) R% @, p (VWIN32_Int41Dispatch)
0 g, N/ e5 d: D( `% e call Kernel32!ORD_001 ; VxdCall
& q; v5 q- G2 F: C8 ~$ q' i0 X8 i! F/ J$ c cmp ax, 0f386h ; magic number returned by system debuggers
$ d. f4 e) n( h3 @ jz SoftICE_detected* d8 Z! \$ w0 i% u' k$ |' b
/ [+ V( ~9 g; N ~# w% }" b& }9 U
Here again, several ways to detect it:# A8 w k! ?4 f: A, K2 I( Q! {% i
* a9 s. V# U4 g BPINT 41 if ax==4f9 w; w9 @. ~/ ?0 m3 `
$ j" E. a; F# ?4 a* _" }9 a
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one9 ]" }& K% P& p% x* K# C# H ~7 y" x6 l
K0 X" ]+ Z+ i$ H! y1 _# m BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
! a4 n0 b/ I t% L$ a3 W8 w" ~3 X. ^/ y; m/ q
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
5 H! E. c) u g! [% ^3 D( y! n5 \+ ?6 q; K& W
__________________________________________________________________________
4 G- Y, c0 P: h; T" {* A$ C2 _9 ^' V$ W7 E7 a Y
Method 137 N" \" w; ?7 A7 Y' @
=========
* }! X5 v6 P' I# \* \- Y$ _0 T% b9 t- ]
Not a real method of detection, but a good way to know if SoftICE is
8 r: V7 K6 i0 L8 \/ I# Cinstalled on a computer and to locate its installation directory.
1 ^5 c0 {% g' lIt is used by few softs which access the following registry keys (usually #2) :7 s5 i: O- d2 I
: N: x; r5 d/ l-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion; X3 T* w( k/ {& X1 L" @
\Uninstall\SoftICE
$ H3 z$ W1 \ w9 z, y. P5 ` h* x-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE5 E7 X6 J) t3 L: g
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& v" T# K% R. V9 i5 ~" J5 P% i# [
\App Paths\Loader32.Exe: s* C" G/ Z) D' w: {+ p
8 g; H0 A# f/ a3 K+ g4 a# b
4 s5 d# u w, W' JNote that some nasty apps could then erase all files from SoftICE directory# z# @" P, b- V: h/ {6 g
(I faced that once :-(7 Q; _' X5 t- I
2 q5 o1 @# P9 H1 H, z
Useful breakpoint to detect it:
% u, l5 f- m" o- T, g
4 _, q8 u+ J6 ^5 J' `6 k BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
4 ^) k1 e" W$ q5 I. _8 G
' M: ~: q1 _* `# {# e! x6 q# A__________________________________________________________________________
0 n: t/ u5 a& J$ P, ~$ ~ ]' d' h$ R' M; q- h
d' f' r$ X% B5 Z' J
Method 14
; O: [1 ^ `8 b* m# z! i=========
' v% J, Z* x' w6 ]& e) g4 q7 c; p/ v
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose2 F6 d7 o5 u; a6 b9 e+ [& _
is to determines whether a debugger is running on your system (ring0 only).
* z, t- V w( J, }7 e6 x6 r# K$ w! m, K: q- O6 L5 z1 h
VMMCall Test_Debug_Installed7 M4 y! A5 s5 |% b
je not_installed8 Z# I3 p3 d( Q& k( Y0 t# e
. j; w2 c* {* \This service just checks a flag.
% j! {+ Z3 Y( W3 B# R$ N( C d1 H; |</PRE></TD></TR></TBODY></TABLE> |