<TABLE width=500>
* J( e& {+ |7 i6 e- Z. p. Z<TBODY>7 l, ?- d- e) j- v a9 H6 ~% x
<TR>
7 H, g) U1 \! S: s+ _: f S( x K+ G<TD><PRE>Method 01 1 A9 z+ m T, v6 _" Z
=========; Z! ?2 R* \4 V6 E0 Z; e) L
3 e* L: ]- K% O% x" }( j& BThis method of detection of SoftICE (as well as the following one) is4 _2 _" H; ]' \/ j3 K. H
used by the majority of packers/encryptors found on Internet.
/ q/ W, M: {) _It seeks the signature of BoundsChecker in SoftICE0 ?# r5 ` h E# g' H
' x% l) a$ a; Q4 F
mov ebp, 04243484Bh ; 'BCHK'* Q( F3 t4 C- }, K
mov ax, 04h
u1 R7 w" G4 n+ ]1 f- t int 3 ! O" h Z' Y# R5 P
cmp al,4
( z# |2 S6 J( k( l$ A! I jnz SoftICE_Detected
8 `; `. p% D3 w5 n0 s$ n/ R3 E! f' B! c
___________________________________________________________________________' v0 |9 P; E+ _2 m8 d ^
3 m8 P) X9 W3 Q O& ^1 P# v5 t
Method 02
+ X& G( p! N/ g; L9 l=========# P! a+ X4 a# N7 f& d8 S
+ E# R6 a0 [' S; v' |$ ^4 JStill a method very much used (perhaps the most frequent one). It is used$ v) H" ^+ G# e; H& I
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,2 }) o+ O* H* o8 [3 z9 Z
or execute SoftICE commands...3 j6 Q1 Q4 v% v; P
It is also used to crash SoftICE and to force it to execute any commands
( x, D0 T1 G" l4 x. @(HBOOT...) :-((
8 Y d2 b( D: P" K- J/ X* O6 h3 `$ ^ ^( h
Here is a quick description:, r9 _, n) E% z8 L9 C2 d+ Z
-AX = 0910h (Display string in SIce windows)5 A: M( T9 w- T
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)7 e* [6 F- z* l
-AX = 0912h (Get breakpoint infos)
- Q3 {+ U( U- y& o! }9 d2 f-AX = 0913h (Set Sice breakpoints)1 n0 a( S* D$ t# I' c* u
-AX = 0914h (Remove SIce breakoints)0 q# a. G/ Z+ V j3 G
r4 F% M1 B6 v! B
Each time you'll meet this trick, you'll see:
; j$ [, }: _: @$ J-SI = 4647h
# N+ i, S# V' B2 `7 Y* J2 G5 T& I. o-DI = 4A4Dh
# j! q* {9 t( a* f" \3 FWhich are the 'magic values' used by SoftIce.
, c& m5 `( k" WFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
: Z0 G" ?4 }. j2 G. T
7 w7 P# K: u" Z# {9 ^Here is one example from the file "Haspinst.exe" which is the dongle HASP
5 h& M( E$ |2 c3 [Envelope utility use to protect DOS applications:3 @& a5 }% @# z W
1 ~! \3 ?$ K5 H, a: M
" Z1 i) \" U1 k( Z6 Z6 _4 y% w; d) f3 s9 I4C19:0095 MOV AX,0911 ; execute command.- u7 l8 v+ m$ I' ^4 r0 x
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
' C2 Q! A9 m; ^3 I) T/ j4C19:009A MOV SI,4647 ; 1st magic value.
9 V8 P) w# v% N2 k4C19:009D MOV DI,4A4D ; 2nd magic value.
) X" ?/ H2 B& W4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)' y2 m8 F. M% h; c1 ]
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
5 k0 u( M1 y1 N' S4C19:00A4 INC CX0 n9 N# H# e e
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute2 h# y9 m1 \0 E( h: {" T4 u
4C19:00A8 JB 0095 ; 6 different commands.
( F7 b: `: I) q* s4C19:00AA JMP 0002 ; Bad_Guy jmp back.
0 C& k; N% {" i8 h4C19:00AD MOV BX,SP ; Good_Guy go ahead :); S* i: S @8 k# I9 |" D) ?
4 @( y! D* e$ ~5 U; ^% g& k* L
The program will execute 6 different SIce commands located at ds:dx, which) m; z! X6 w" d
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.' q8 ^3 |8 N2 S, |
2 I7 |7 S/ Q1 [" G
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.* G1 B% [9 C( M8 [; u4 i
___________________________________________________________________________4 M3 O' K+ W. I" c4 w5 b
& d* D( g e& Z. X& X6 y
/ N4 s( v# O( p+ `( LMethod 03
0 L( Z0 J) \+ q! E: e* n, J& P) S=========
5 X: Y8 [* ^6 j2 a9 S* l9 B3 y* q2 Z! T5 J5 e- B1 x
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
9 S9 d. {4 \! C9 `(API Get entry point)
% Q+ l2 D0 ^. v3 l. q0 |9 t7 |2 d 2 Q k* q0 }0 @- K a. v
; |8 T! E5 I5 N9 f% k8 I4 t xor di,di
9 t, J: O7 c4 F8 S* q6 C mov es,di) P4 l. T4 y9 T' I2 K. }
mov ax, 1684h 0 Y! f& A3 E. c) I, ^$ Y6 c0 J
mov bx, 0202h ; VxD ID of winice( h! `' m9 q( [/ J( b& d0 }" h
int 2Fh
7 x/ \4 y; v. ?' q( P* P0 P6 @ mov ax, es ; ES:DI -> VxD API entry point
- ?7 a j8 B; }$ a. u add ax, di
, d S. d3 ?7 f1 L7 C test ax,ax
) s1 }% F5 G* B; ?& N: v jnz SoftICE_Detected0 Y9 I" M: n8 Z8 l L8 F/ n+ f
0 ?9 E5 @8 Q8 H9 S+ M$ C
___________________________________________________________________________
. K a5 V8 ]5 V3 t
/ ~% L# a& L# _8 k6 RMethod 045 G. R. A8 Z: k5 q: |
=========. V! u; r% W" F
' X+ I: p+ b/ w8 n, B G* p
Method identical to the preceding one except that it seeks the ID of SoftICE& J! U/ _& X: R, c) @
GFX VxD.) R: P- w9 o7 U0 y5 O) D% g3 W
! ]6 [1 q2 Q5 i( E xor di,di! G: _% w/ `/ F) x+ n _4 E/ N
mov es,di
, A( k9 F$ e! B# s7 m mov ax, 1684h
7 l, L/ W0 b# a' t) m1 f2 t mov bx, 7a5Fh ; VxD ID of SIWVID
0 N+ E3 E; a; T+ N% W4 X int 2fh# w7 c, N" r7 D" e, i) X
mov ax, es ; ES:DI -> VxD API entry point
* B. x8 k( K8 Z3 R5 P/ n* P add ax, di" M ~% Z4 s1 k' i* S
test ax,ax/ t: E) }; o& k! ~* L4 e
jnz SoftICE_Detected
4 f- C. E4 r) P' V9 ], x, }# ~& O4 ~: G9 |
__________________________________________________________________________: A6 e2 A4 U; ]+ Q& v3 P
0 W, Y" d9 R K; @1 j% H. o6 D3 X" M1 | z$ _( {0 Z( v
Method 05
4 ]+ R( X- ?: F- f: y; U* w=========
5 t) C4 p% V% }* `
% k2 v4 @8 `( F; SMethod seeking the 'magic number' 0F386h returned (in ax) by all system
! N# t1 ~9 e3 n3 ` Bdebugger. It calls the int 41h, function 4Fh.
; J1 z+ P7 o* mThere are several alternatives. : r7 k. Z0 o4 F
: f0 f$ g7 h2 RThe following one is the simplest:4 S" i! F7 l' I* H
: \- N( V$ c6 z0 o0 }% e mov ax,4fh
" j. ~! x h1 Z1 e int 41h: o( x m9 B* M
cmp ax, 0F386+ B! g2 j4 [0 k$ m/ [0 i0 @; L
jz SoftICE_detected
0 U) m3 {& p f( C3 t$ o
t# q( h z, L. o+ F: w( o3 N6 q
- v) s+ ?$ \! J, v6 L3 ^* Q% q: G4 P4 bNext method as well as the following one are 2 examples from Stone's
( G6 M) f2 y0 P"stn-wid.zip" (www.cracking.net):
# `5 w) u+ I- [! u6 ^) }; e i
t- b ?! o5 k. Z" f5 v mov bx, cs
2 g* I% |% [1 M; E- A( e6 m lea dx, int41handler2# j0 `. `( O$ k0 R% m' k; S
xchg dx, es:[41h*4]( c2 q! \# g5 f' l
xchg bx, es:[41h*4+2]8 ]# X# n* T0 G( x9 o9 G0 }
mov ax,4fh- k t2 H2 K/ s+ C" A- [+ E
int 41h6 U B! ]- L0 e% l$ t) M
xchg dx, es:[41h*4]7 J) w! `8 L6 q, y1 L
xchg bx, es:[41h*4+2]
/ }" F6 H$ O+ t" K! R* { cmp ax, 0f386h
0 g" C J1 |. r$ ]- q; l% y jz SoftICE_detected- q( N! T a7 l+ G6 e
. A$ S& W0 P: N; [; d
int41handler2 PROC
& J6 a. X4 F) u2 ^+ T- b iret
& G2 Q5 c9 [1 `4 Z6 A8 ]int41handler2 ENDP
( |/ P1 v0 w& _/ z' l6 }, U% X" }! i9 {7 j" q ^6 H2 {* s
$ e" ]8 I* M1 K+ y; V
_________________________________________________________________________' w6 }& { v O. Q, ^
/ g5 P Q* m* s. O) ~. p9 ^7 e* y( H5 N5 F6 B; E
Method 06
6 P @0 c y- w$ }. D3 F=========
+ Z; W( V' H/ X; v- w! F3 _4 x _4 U, G: J2 q0 l
$ v7 b2 U+ g* b2nd method similar to the preceding one but more difficult to detect:; h, ]4 G9 O) V* p0 x
5 a' p. q4 ^# s% m( p/ i2 ~/ |
0 Z0 K6 ^2 R% f2 Bint41handler PROC
% b: l3 }. ? [+ H2 d mov cl,al
3 H* ~6 ~& ?: z& K& ]) g iret
( j1 z9 R, K( i8 K o3 P- hint41handler ENDP
5 H7 ^5 Q7 U8 n) o
$ ]/ l2 v, S( H( e
4 u$ ~* t, h1 l- E( } xor ax,ax
& a8 \0 i9 i% z4 A. G* K mov es,ax
* r8 t/ [% [ i# B: d6 b$ D mov bx, cs2 f) t* n4 [1 O, J, ^
lea dx, int41handler7 F7 X0 }. _7 E4 U1 H
xchg dx, es:[41h*4]% |2 `4 e6 K/ b/ o3 Q" C
xchg bx, es:[41h*4+2]8 x. r( K4 {3 d9 c
in al, 40h0 g2 G& c- S* ?# S
xor cx,cx
2 |& \0 w: Q9 A int 41h
1 S& u" _ J! P6 m7 B& `' D xchg dx, es:[41h*4]
- w: R$ t2 C3 ]; `' n xchg bx, es:[41h*4+2]
: a8 Y7 _. T. O' ?, v9 z; m cmp cl,al
1 z# H, W+ X3 R% u/ u6 { jnz SoftICE_detected
: \1 `7 v: j0 w' O9 u9 M1 V8 t9 X( s9 ~0 a* N% P
_________________________________________________________________________
+ B6 M; X# c7 E
0 K$ U, `6 D, E0 \( a! Z$ N* c! jMethod 079 J- L1 h$ R2 i2 Y4 r' X' b
=========
! J7 Z# I# ^8 m. [4 m' \. Z# x' t' f0 D: q. c# i' l4 P
Method of detection of the WinICE handler in the int68h (V86)+ G) P# S: Y9 f3 i8 V$ Y8 b
8 O/ @1 x# F2 c6 U. W" G
mov ah,43h
; t( \' \/ U& I8 Y/ m, E; ~ int 68h
. U. X: x' H* J3 K- d8 t' E# T; I cmp ax,0F386h
9 o2 q. C6 D6 ~" _9 A jz SoftICE_Detected
+ e6 i8 ]! }4 Z3 g7 A4 W* I
0 E7 T0 g. d% A! b: W! l, O* P- F
8 v7 V( K3 j! C! a, a8 \" h4 U1 Q: Q=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
* |8 `& ]: m! i2 f* Q" m/ a app like this:
8 _( E0 |+ F" M9 Y J4 P% B8 e/ t. Q- V0 V1 O3 ~. K; S* I
BPX exec_int if ax==68 J" f9 h; s" [ Y- w
(function called is located at byte ptr [ebp+1Dh] and client eip is
$ U# }( ]0 d6 p located at [ebp+48h] for 32Bit apps); k4 _* z# G- [7 ? C, h$ n7 v
__________________________________________________________________________) i/ @+ ^ e- D3 s H
; c3 P8 g* ~% L2 b; F
/ E) w- U8 W3 ]+ F, h jMethod 08
7 r8 |. `, k6 N; n; ^- U4 \- Z0 c B7 j=========
0 C6 K0 O8 D7 u. E5 E. @
5 t5 X, H0 q% z; U& u- g$ m: wIt is not a method of detection of SoftICE but a possibility to crash the
& x! @5 ]) B+ Bsystem by intercepting int 01h and int 03h and redirecting them to another
: g5 c# C. K$ x8 Mroutine.
% e% L3 h4 b8 K% X. HIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
9 b( C. q0 q# a+ Lto the new routine to execute (hangs computer...)
' i. v' v5 O( Y# N: d6 W/ V1 ]& o5 i
mov ah, 25h
9 J$ t# m' y2 `1 s/ v mov al, Int_Number (01h or 03h)) I- t$ W1 \7 V6 L
mov dx, offset New_Int_Routine
* c. r- V/ h- l int 21h6 d( g6 F) I$ z5 c K" X; F2 Q
2 o& ]. q- |/ [& l5 `9 l7 R% L__________________________________________________________________________3 b: `1 Y- C) g7 }2 u1 ^/ x" H
+ r* b9 r9 D. y$ ~1 A, @7 QMethod 093 a% i' e6 \# {
=========
% n% p K& Y2 E, R, `% g( @% ~% ]. D
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
; u2 e1 D9 |' u6 zperformed in ring0 (VxD or a ring3 app using the VxdCall).( u0 j2 S4 K/ F+ ?+ i
The Get_DDB service is used to determine whether or not a VxD is installed
# R& x4 ?0 [8 e, d7 U; Kfor the specified device and returns a Device Description Block (in ecx) for& R- M+ i; k9 l* P8 ]) B& i8 `
that device if it is installed.- q7 ~3 l$ e2 y. g5 P
: W& d9 W& x& x* O( J& A# G
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID( G, `( E4 A+ c2 d) X$ ^- X3 J a
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)4 s" `4 n% s& [$ [
VMMCall Get_DDB
! X6 D. X# C: S( |1 I7 F mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
! y6 M- d6 J2 M2 E2 x/ Q, m# k6 s3 V% d& I! s, F4 d- u7 z
Note as well that you can easily detect this method with SoftICE:& t% R f: O) |4 S# q/ Y
bpx Get_DDB if ax==0202 || ax==7a5fh$ Y/ r/ X8 a+ }, Y& F
) A0 T6 V* v- s__________________________________________________________________________! J5 M7 U- s) S b, ~
7 F( e. M% G7 `8 R: K
Method 10
7 {- J& l! F! Q+ f+ A=========' ~4 I( v! U& D7 F0 s J" l
8 Y) S- z3 _/ `=>Disable or clear breakpoints before using this feature. DO NOT trace with9 E7 Q! |/ G' L! g5 n; Z0 Q# X& n3 s4 z
SoftICE while the option is enable!!4 J9 f9 l! L$ [; `1 i
4 }) W3 u. j* f2 O4 K
This trick is very efficient:
0 _$ L$ {- B* |8 \by checking the Debug Registers, you can detect if SoftICE is loaded
# F& {4 Q J1 }9 R7 p1 r. n(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
5 n1 A! O x+ k1 Xthere are some memory breakpoints set (dr0 to dr3) simply by reading their
& b1 f8 g- i) p, Q2 O9 k- L. Vvalue (in ring0 only). Values can be manipulated and or changed as well/ b8 I4 `# F/ ]) p/ {% e. M, ]
(clearing BPMs for instance)
3 C) y( `0 r+ f) _# d5 H" M" V) O# A. {' m4 K/ h
__________________________________________________________________________: Y4 H A# e7 A5 g% R/ y$ s2 `
" z/ U l1 `4 p! q( {Method 11
) Y3 y$ I4 F5 f$ t) H+ a=========
) ]5 c0 d. d# ^- S8 w0 i* l- k0 s d+ e* s: D, O
This method is most known as 'MeltICE' because it has been freely distributed+ N4 T" N. s. \5 V/ ]
via www.winfiles.com. However it was first used by NuMega people to allow
# b- `7 H" Y7 P3 _3 y" Z/ n* w" U0 YSymbol Loader to check if SoftICE was active or not (the code is located) h* b+ _: t, S0 f) U
inside nmtrans.dll).
' B8 ]1 m/ j$ q+ ~& d2 s% D6 U# o2 b# s3 ^" M4 f
The way it works is very simple:
* P' v# q% v: y* `- FIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
9 ?' {$ X2 Y) LWinNT) with the CreateFileA API.$ R* I0 ]' h1 a: N7 h
3 a. A* B* j5 CHere is a sample (checking for 'SICE'):
1 n4 {+ l( }" {9 c9 O: K$ U2 j, a
BOOL IsSoftIce95Loaded()$ I( |, T4 E9 g; J' L
{4 L1 t. J! A% \) _5 h
HANDLE hFile;
5 a; Q8 k! A6 T: [ U$ |3 `" e; O, e hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,+ N v G& y2 O- V8 C: b
FILE_SHARE_READ | FILE_SHARE_WRITE,
$ s1 o. N5 ]1 }0 ~* B! V& X NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);0 f$ R* v ?. b5 Y0 o/ A8 L6 c0 O
if( hFile != INVALID_HANDLE_VALUE )
/ {* Q; }1 ^, F& B$ c1 R {
% \! W, ]& J, r" u. D$ A* _, f CloseHandle(hFile);
; G/ x# C* k( U3 w2 E return TRUE;
2 D) z3 x' } a3 g! U6 T8 c }% b4 R& K$ D# l: z' z4 s
return FALSE;
" \$ S9 S3 Y2 P- m) c( ?}' _, j: {2 T+ @7 H; [' t
4 w" M5 c; l2 d( c$ K5 B# p8 U1 g
Although this trick calls the CreateFileA function, don't even expect to be
! }. c3 X8 B+ N& w* F" ^$ p! Gable to intercept it by installing a IFS hook: it will not work, no way!- `& v, u- l) Y" L$ }
In fact, after the call to CreateFileA it will get through VWIN32 0x001F6 u6 p7 }- i0 P- P: O5 I( \# T
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)" R3 K; N" x! c; ^4 }
and then browse the DDB list until it find the VxD and its DDB_Control_Proc4 }% D3 x( [9 d
field.
) b% Z! x z* i; S; d3 v% |6 ^, kIn fact, its purpose is not to load/unload VxDs but only to send a
/ n! E! Y. ~+ u) aW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)7 v1 @+ L2 K3 @# O. ] I
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
' k: N1 i# y2 d! Q( Q1 o! K6 U/ jto load/unload a non-dynamically loadable driver such as SoftICE ;-).
! e! T* Q7 i" M, ]+ BIf the VxD is loaded, it will always clear eax and the Carry flag to allow
- D1 j* D% E. }9 b0 Tits handle to be opened and then, will be detected.& M6 s& ^' Z/ s; O; F! C
You can check that simply by hooking Winice.exe control proc entry point
K5 v4 e) D- S! ?& Lwhile running MeltICE.9 y7 Y# E' I" `2 ~8 P* k- Z
- O. {6 [! G3 W7 z3 T( g; h
_5 Q1 {9 J" z. j# X
00401067: push 00402025 ; \\.\SICE* g* W5 M! e; {& |2 R
0040106C: call CreateFileA4 H5 W# y. z& i. n2 }
00401071: cmp eax,-001
4 k+ ]2 j" X x 00401074: je 00401091, d4 q. _* U/ z
# {/ V4 W* J* |# @7 W9 e* r
9 L2 h, F& ?1 Z+ Q) N/ T* {& ?; cThere could be hundreds of BPX you could use to detect this trick.
3 }3 B) i" t4 T-The most classical one is:/ T" l+ P( \9 o# Q( Z; w( |/ w V6 J- ?; X
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||8 w% C/ O1 ?/ X$ _! V Z
*(esp->4+4)=='NTIC'
2 ^0 E. R* }: E, S- a1 W4 @; i/ |% D) A$ v+ J
-The most exotic ones (could be very slooooow :-(
8 a0 F5 k8 B. n, `0 |! ]6 ?9 k% } BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
5 j4 c$ u$ R: M; U, w% E ;will break 3 times :-(8 Q' \( \& t; g. `9 F0 H$ B! {7 ^
, b* {; j+ _/ }& P& f) o" V-or (a bit) faster:
8 S+ ]" x! Q+ s [0 X BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
6 A1 v; j3 L0 p1 s0 a3 k5 u$ k( q {- _- }! S
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' - A. f. t6 q" Y! }3 X5 ^6 d7 k
;will break 3 times :-($ i: y' E s6 f) s$ A& e0 Z
% o" X) o! D; P; E. M7 e8 w
-Much faster:
$ X8 f4 h% F2 j. }" G# x- b' A+ o BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
' a. v( Y* l" ]- d
: t. c. {( t) C) O8 nNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
( t9 P7 s/ S$ a; p2 B9 Y3 cfunction to do the same job:
$ {* L$ J6 r$ O) M0 U3 @. z5 m( A2 s' K- j
push 00 ; OF_READ
& F. x( y% ]( \: l mov eax,[00656634] ; '\\.\SICE',0$ a2 ?/ d4 G0 M7 o0 _/ B
push eax1 y' y8 A, c2 w0 u+ i
call KERNEL32!_lopen, Q! u( K5 K, ]" q2 S. ]* M/ W4 Z9 L
inc eax
% c3 y, U! A+ m% l, o: } jnz 00650589 ; detected( |' T0 G# w' U* I. w" C! z: P
push 00 ; OF_READ7 ?; R: c2 C; ^: R# \9 m7 v/ m
mov eax,[00656638] ; '\\.\SICE'$ r% k) i& L7 `
push eax
" Y( g) j0 U: | call KERNEL32!_lopen
4 J% J4 W7 T( c# R8 H5 ~( t+ z inc eax7 O( D" ? D9 h2 ?; p9 Z
jz 006505ae ; not detected
3 B( l/ g3 o$ S" Z' N0 R
. n h# L: }& G% t$ R% h) V8 i8 h( i" j, K- M5 ?
__________________________________________________________________________
, J4 O* V6 v, |; R) ~8 h$ l
7 Y4 T* S) Z7 s4 R0 yMethod 12
1 A( Q1 N+ ^/ }% H9 w, d=========
, i* }6 M& e# ?' y/ _1 U- ^, x7 Y
This trick is similar to int41h/4fh Debugger installation check (code 05
9 J' _" O9 a& F2 Y4 ~0 C' H) G& 06) but very limited because it's only available for Win95/98 (not NT). b$ B2 Z9 ?) k& i, Z
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.+ D; W( H! D1 i7 @% R1 v$ x
) K$ Q6 m% I1 [' f) ]" S1 @
push 0000004fh ; function 4fh4 _* \, Y( t0 H! D
push 002a002ah ; high word specifies which VxD (VWIN32)
5 T; m' l. {9 a+ M$ x ; low word specifies which service5 t* m+ m/ s" S7 g0 U/ m+ T
(VWIN32_Int41Dispatch); }- e$ o/ h7 J$ e0 ]; k/ m
call Kernel32!ORD_001 ; VxdCall5 J( m* s) a- h( z( ?/ y
cmp ax, 0f386h ; magic number returned by system debuggers
, B7 c! e5 H. F$ i# [0 x+ K jz SoftICE_detected; q" |0 B1 y9 c2 ~8 H& Z
% s- F8 d0 ~. `8 j' K! q3 z7 wHere again, several ways to detect it:$ C6 ^' F: n: X6 H
$ [0 F- Q' Q8 Y# K; A! ^+ \ w' w BPINT 41 if ax==4f
# }: j5 F4 O" l5 p, j V# m! ]' U \& ~3 t" Y
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one z& b) M* _) G# P
Z9 z) q3 D3 c7 g7 J/ Y BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A% O- o+ b8 p9 U- y7 J$ n9 l
% R( l1 g- A i* M, s7 ~2 [4 i2 q \
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!. `3 ` X2 f: V0 o
( d: a5 k* o) e' Y% Z- p! S" A__________________________________________________________________________* }, D1 p7 E( S+ k6 n4 E" l
9 \. [5 F4 x+ K# b2 s
Method 13
]! s9 z0 U9 I4 n( X* ?=========
. j8 Q, U/ t F% L4 w9 T x3 l8 S* `( Y& f3 y c
Not a real method of detection, but a good way to know if SoftICE is1 G, Y, N9 V1 \+ S! n ?) R
installed on a computer and to locate its installation directory.
6 y( K7 @, n: ]9 BIt is used by few softs which access the following registry keys (usually #2) :
3 X( E; F; R0 K% q* L$ s* W. b' Q# E; \. b& G. w, @
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
$ U- e$ ~& f9 D* v\Uninstall\SoftICE7 _: J* [" `2 I6 N, ], T% c
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
2 g" ?# H3 i% k6 e3 q/ n-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion, g6 L6 e7 G7 ~5 i
\App Paths\Loader32.Exe
% t. d( D! l* c6 L3 z. D4 \6 a. }' Z5 k
# X5 f0 G: Y0 q @
Note that some nasty apps could then erase all files from SoftICE directory6 G* A5 h4 C8 @* X
(I faced that once :-(
2 V2 t& v# g2 J6 D9 G
& d5 p9 |. x0 w) b d6 i, nUseful breakpoint to detect it:
2 z6 M- L# r+ z5 L
4 \* j1 M7 G" x, a5 z' `- e BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'; G' D6 g& W7 ]0 I, C+ z
2 h* V$ M: p! m% { w! h+ A( `
__________________________________________________________________________: m$ N" R4 h9 u$ J
7 l- Z# i C; w+ D
. f- S! X* t8 |# \% g; h6 P( YMethod 14 ' P( n3 D+ g+ p, l# m" k# {( p3 [
=========
/ C$ H% J# p& \8 u& ^+ h5 d) g, ~" w8 X% c. t, ?4 [1 D+ ]9 P
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
, i6 C# e8 l' t z4 ais to determines whether a debugger is running on your system (ring0 only).
3 x$ r" Q. H' r2 J' l7 q& S4 m% y4 }4 X8 c) \# v$ [, |
VMMCall Test_Debug_Installed% r. H0 {: ]4 T9 x9 D% D5 y b- p, {
je not_installed, w. I+ V' \/ ~: ]8 h
) i% J: t) j( M& Y4 fThis service just checks a flag. c3 U6 d- Q5 j) t: ~1 o9 [
</PRE></TD></TR></TBODY></TABLE> |