<TABLE width=500>
$ _" R7 K1 T; U% s& B t, g<TBODY>
4 Y& K! v7 Y3 i1 j0 j8 P<TR>
; ]2 K% M3 v1 ?& a<TD><PRE>Method 01 ( X' A9 e4 ]1 P6 E8 J! o
=========
9 P! E% d" k3 X6 h0 K9 }- m3 m' ^* @
This method of detection of SoftICE (as well as the following one) is
+ l0 C1 Y: P7 V. S- yused by the majority of packers/encryptors found on Internet.
+ q; A# C; b9 V- `) e' v' L* _) AIt seeks the signature of BoundsChecker in SoftICE6 Z$ q, D% b1 F" {; m" |
- N0 F2 C q9 l& B6 i% J2 g mov ebp, 04243484Bh ; 'BCHK'# ^3 E) i5 d4 @; u- j+ U( b# H
mov ax, 04h( |8 |- F* l2 ~( V6 @" K0 D
int 3 / \1 U8 d8 o! {
cmp al,4# Q2 M$ ~% Y' F8 }8 T6 F$ ]# o/ u
jnz SoftICE_Detected
c& Z* I) N0 L% |5 k
# _4 N3 ]. H6 B, C* O! C___________________________________________________________________________
. i) h5 S- ~8 Z8 ~ H
% I. |2 ^4 _" z6 `, MMethod 02
. I% C( U# q, c- Y; t7 p( v6 ]=========
9 p/ w- i, G8 {$ s
, V$ h4 m6 d2 X- H: {Still a method very much used (perhaps the most frequent one). It is used* a' E k( P, W8 ^6 u" H& X1 w
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,0 Z1 W- v: Y. {
or execute SoftICE commands...
& R7 i" C0 K) }6 r IIt is also used to crash SoftICE and to force it to execute any commands! P9 M6 h6 c S# Y. ?, C( ?4 e
(HBOOT...) :-((
3 i9 j! k8 D: M: L# ?
+ `! x/ x0 L8 A' d% G2 X6 {Here is a quick description:
$ `7 X9 E0 t$ n9 X" q! _& i-AX = 0910h (Display string in SIce windows)1 a+ |- c3 C6 `( [7 r( J
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
2 N; w) [% x9 Q-AX = 0912h (Get breakpoint infos)
/ ?9 n6 L! [, W1 @; o! o- I-AX = 0913h (Set Sice breakpoints)
; _6 T* U9 E8 T" q& V/ [, l& S-AX = 0914h (Remove SIce breakoints)
. N/ o, A5 K4 a0 o C% k( i) F0 X( {) o# W2 c
Each time you'll meet this trick, you'll see:+ b' l9 H1 o- k! |* t# P7 r
-SI = 4647h7 D: H0 T' A. R& k3 @( U! I, }
-DI = 4A4Dh$ Y( b2 c& Z& W! B. b
Which are the 'magic values' used by SoftIce.
* _, _* v+ u5 MFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.' s7 u- I) P, Z$ Q: O
: E c% w3 Q# F, N6 eHere is one example from the file "Haspinst.exe" which is the dongle HASP/ q% }) k( ^( j+ q- c( d1 Y0 W
Envelope utility use to protect DOS applications:
$ z4 F F3 k6 @( [. c- B1 W% ]' g) c3 A* O+ E
- U& S, p J: ~1 \: \" S& p4C19:0095 MOV AX,0911 ; execute command.
( I) H+ s' W4 a) z) c4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
/ D; j0 P3 o- N9 E) x$ v' u% s4C19:009A MOV SI,4647 ; 1st magic value.- x5 U' r ^( [+ Y8 j2 ~
4C19:009D MOV DI,4A4D ; 2nd magic value.1 W( A3 ~4 h" d- q
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
8 n u3 m+ y/ a6 T5 D0 C2 a4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute% R+ D! W% K% h8 g
4C19:00A4 INC CX3 P0 v( N: m. ~0 v
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
& D h5 d E" V' @4C19:00A8 JB 0095 ; 6 different commands.
) T1 h- }$ ~3 d5 Z2 ]4C19:00AA JMP 0002 ; Bad_Guy jmp back.
) B/ l4 m7 N/ g- f+ r4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
5 ~! P/ M3 W8 j- y4 D* t. A& W6 m" b" L! K q6 y& i
The program will execute 6 different SIce commands located at ds:dx, which4 @: [" k. }7 M: [$ x! I
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
" @' ?% o4 `, i. H; v6 f4 P; S
; [% F( p5 z* {) v* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
5 m0 P4 t1 o, F# g. d+ E( R' h' D: \0 o$ |___________________________________________________________________________1 K O+ D3 _. H6 A+ [0 b
# P( V! c/ Q! a2 z+ a& E6 l9 ?( u; |1 f( ]8 w
Method 03
5 ], y7 I0 T+ i$ }6 }=========
& }$ k! @/ |* c0 X! l
6 \6 A& B. m; c) z: KLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
4 c: `2 c- [) k(API Get entry point)8 U) t: }9 L' W# p% |# ^& P( q7 y
" o8 i% @' h8 |$ u( f
+ e/ D, }! r' h xor di,di4 X4 Q5 w1 z0 c& M7 O
mov es,di
+ R; C' f& E# J% M3 x. K mov ax, 1684h - {5 D" d# d9 p9 Y7 Z p8 P( u4 Y7 x0 m
mov bx, 0202h ; VxD ID of winice
& Z9 k5 V* [1 o4 Z8 L int 2Fh
: ]# @. e5 x" |9 R; I' R, F5 z mov ax, es ; ES:DI -> VxD API entry point; S A/ u4 A1 G. w
add ax, di+ ^" `0 ?+ C( ?& k( N3 G
test ax,ax
$ n" j) p o9 F& q! _ jnz SoftICE_Detected
1 e& O6 O& O% |; T
} p% q. \+ w* T$ K4 r! W0 ^( u___________________________________________________________________________
; E1 U i" W0 k! ?" `
. W4 M' M( V' g! V4 p6 XMethod 04
" X9 [6 N: X- @3 r9 v; `=========0 J/ r5 z. N4 P1 C4 C" P
) w$ x- j' v# P) Z* o9 {) K; @Method identical to the preceding one except that it seeks the ID of SoftICE$ s) t: X& F9 q/ u4 x
GFX VxD.7 n( ~/ b# W+ S, _- F2 n# x* |
: o" p; L; [/ X* C$ M! K xor di,di
' q& A+ U% F6 Z |6 ]8 I/ ?) V mov es,di
0 Q" G# O( A- |0 A( H) m( f mov ax, 1684h 7 h1 q' t9 U5 p, N% o
mov bx, 7a5Fh ; VxD ID of SIWVID
: I% r+ }5 Q4 \# Q int 2fh! B# v9 p$ T2 \. l% E. [
mov ax, es ; ES:DI -> VxD API entry point, n' q. `& t$ X: \6 V, w* J
add ax, di
8 A6 W% Q: b3 ?/ l- X test ax,ax- v. ]) q* ]) Y# h9 y
jnz SoftICE_Detected
% ~6 m7 ^; x! _0 {9 f% I* q/ F
1 \# O' v( L, N) Y__________________________________________________________________________8 F0 F. b# i6 {$ H" L& o9 }
k& N4 M& J; c; @
# {8 A# x, t: A* XMethod 05 K6 O+ D" R6 M$ s$ w* ^" g: ]
=========# F9 @. R5 R) I4 P, ^
+ K& D6 z u2 ?" }
Method seeking the 'magic number' 0F386h returned (in ax) by all system
2 r4 ?" K& m4 U2 C% udebugger. It calls the int 41h, function 4Fh.; p( ^: u, H' `8 W# W' _7 L
There are several alternatives. , r! q% B/ _6 V
$ w. n) m+ @ L5 P! iThe following one is the simplest:
2 l/ x' F9 h; L
; u" {' }7 R% o- n: o* ?2 X$ k mov ax,4fh
, x0 f, ?2 |8 l+ I int 41h
; X4 Q. q0 O0 e% R1 e, V cmp ax, 0F386
0 L+ A* S# m7 g jz SoftICE_detected8 T$ n U d2 Z+ _: b8 l9 R
{/ B c" }( |: n; n# t* u0 u6 Q. m. c& D
Next method as well as the following one are 2 examples from Stone's
( C5 z- p% ~) ~* }"stn-wid.zip" (www.cracking.net):
7 z( v2 d! j2 G5 R) J- j8 R7 E% d$ y! a! L' O: X
mov bx, cs6 r' y5 E2 Z, p" H6 W
lea dx, int41handler27 `" ]- M; P) m6 C$ ?
xchg dx, es:[41h*4]3 n: {$ }1 F# `9 R
xchg bx, es:[41h*4+2]
+ m4 f7 o, a* M- f/ m" i, i5 j mov ax,4fh
3 B- K* t0 M: ^ I int 41h
4 m6 S1 R+ A* p! E: | xchg dx, es:[41h*4]
p! N3 |& @! p& a7 g xchg bx, es:[41h*4+2]
8 _" D$ ~# Y# R% q. m cmp ax, 0f386h
1 S2 _, y' S% R/ ^9 M, D jz SoftICE_detected1 k: F! k( \' B1 v* f* X0 ?
+ y1 a( s7 Q% Q, P
int41handler2 PROC
- x9 i1 V6 E0 C5 n& h2 X) q iret
: e- B* H1 U8 t* t( Iint41handler2 ENDP
6 Y6 s$ C. Y [, ? J% \0 B. h: [; X2 v( M: I! M I1 [# s
( I& m) y; p( @9 I) e_________________________________________________________________________7 P) ]4 z# [# w8 i2 C Y
/ i4 K0 j4 x/ F1 z& ~( M" s
* I! F$ ]' U7 V3 T) _. tMethod 067 M3 B2 S. ?* R* `$ |4 y
=========
1 X, q) F; q" r: }( ], K+ @$ {4 E7 L1 e# l) F
' E- J0 Q# K T& F2nd method similar to the preceding one but more difficult to detect:5 K) Q4 x' Z" f, O
0 q) q4 ?2 l( o' a; h( V0 t( t# h/ G% C6 S: K) m
int41handler PROC9 A7 _) x. [( ~% f+ G- h
mov cl,al" B" J& X3 b& X+ _7 h0 ]
iret. b0 g+ ]1 ]- l1 z2 L
int41handler ENDP
+ M( I5 E2 Y% [. }* Z" K' Y# z! p3 A0 v: ]
0 L9 d' l5 B- }8 ^3 F; N _; P
xor ax,ax
) t2 K- j. x5 l5 h+ y& V. | mov es,ax8 Y) H4 J# B* s
mov bx, cs& _3 \+ m' D& q" U" x
lea dx, int41handler
3 t8 s1 _ A/ y' ^# W xchg dx, es:[41h*4]
$ `5 G$ X$ K5 N xchg bx, es:[41h*4+2]/ U0 @" G9 }6 S/ p6 @: Y
in al, 40h+ Q& z7 V8 R9 N/ @" N9 W( F' o6 q: P0 O
xor cx,cx
+ d$ I7 w$ s Y) `- P int 41h; w/ H6 f) }' z
xchg dx, es:[41h*4]6 S- n. t6 D! b D+ c, w& }
xchg bx, es:[41h*4+2]
" x3 X1 w5 b! C& r5 t% U6 _ cmp cl,al
1 ~5 w+ R- E! D: p, k jnz SoftICE_detected
+ A% G+ L- k9 U( O/ z: Q. P# Y' v9 e& Q/ | A
_________________________________________________________________________
: R' ?9 m6 J) W
, @8 J9 ?7 v4 N: Q* ?) q8 Q& eMethod 07
: O9 e- U( V& P- _. |0 u8 Q! ~=========
8 e+ ~* x. W* l4 O- {6 N+ m$ r g3 k4 X" J+ g- H e
Method of detection of the WinICE handler in the int68h (V86)8 u+ J6 W* p a: r7 o9 e* t
* r" d7 c7 ?. a: a" h* z; [. J mov ah,43h
* p+ o. K3 r$ U# F. E: H; n4 Q C; x6 C int 68h9 `5 [/ k' Q- _3 v/ c" a! Q5 h
cmp ax,0F386h2 P% p* q! C: L1 O) n& t# r& U
jz SoftICE_Detected
, q4 d: o( c9 d# f1 M/ h
* C8 l- ]0 s4 k0 R$ p2 ^# C+ k$ c; C4 \ v5 N
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit* W; m; }8 `: T' e
app like this:
J/ K9 o5 Z" E% }# ~7 W+ q* h. S1 _. E x$ _- ^! y
BPX exec_int if ax==681 @0 f% |2 H( B: M: G1 O3 |& o& }
(function called is located at byte ptr [ebp+1Dh] and client eip is
/ j# C" q' Q* Q* B4 f located at [ebp+48h] for 32Bit apps)
: J2 t/ X. t; ?. n6 p9 e__________________________________________________________________________
$ Q' g, u. } @: Y! i5 m
4 a1 W! A9 ]5 u1 r0 C
: a3 c8 B; P" q( AMethod 08
& x, I: n+ @; G3 d' T: C @=========
, i0 F! m. z" `
. a6 X2 O; d. K% _8 BIt is not a method of detection of SoftICE but a possibility to crash the
+ i. V$ t3 v6 r8 I8 X0 O+ i* ^; @0 Fsystem by intercepting int 01h and int 03h and redirecting them to another
+ S0 f0 Q6 \8 B% E# [) Iroutine.3 m& |1 {) R8 t0 l) a: `4 E
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points) X# w n+ s4 J2 p+ v9 K
to the new routine to execute (hangs computer...)
X% X/ L+ l/ k. S6 R
, i0 O, y7 d% j) I. I$ B- J% ^+ J mov ah, 25h
. \. A/ [/ |2 V! a mov al, Int_Number (01h or 03h)/ [7 }/ g3 b; \& f# ~
mov dx, offset New_Int_Routine
- R! O2 T6 ~6 r int 21h1 Y% G7 D) v; y% l* S4 h; E
3 c8 L: B7 Y% w5 Q__________________________________________________________________________
- f) Q- l' \8 I* G' J1 c8 x ]# p0 P' o/ [# f, n% m
Method 09- k ?' ]! n* Q6 d
=========
; H; A8 S1 J& N/ ?( Q/ n5 `) |, Z, W" _7 G/ v# {
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
& ^8 C8 j/ ^# fperformed in ring0 (VxD or a ring3 app using the VxdCall).5 _% R5 J5 k" j3 B5 N0 _. ~6 `
The Get_DDB service is used to determine whether or not a VxD is installed
! d/ Q2 Z& d! hfor the specified device and returns a Device Description Block (in ecx) for/ ?9 x6 Y5 O8 g# _7 d0 m
that device if it is installed.
2 e" j* V! S$ n7 {1 o1 G0 Q- K# Y3 a& q0 J3 o0 ] ]0 |; _
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
, R' u1 e+ V3 m mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
5 u7 S) q8 s2 S2 W5 D VMMCall Get_DDB- ]1 L5 ?$ t0 [2 b
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed. v3 M0 @ L& u& }) J, e
) j6 }' r3 K$ c3 G4 n# f* FNote as well that you can easily detect this method with SoftICE:
" F) a3 m M2 B( ^ bpx Get_DDB if ax==0202 || ax==7a5fh9 } P# X* d q! x. F
8 R% ~* n4 |/ D* y: ?6 \, t__________________________________________________________________________" |$ v9 q2 A9 h$ l. Q8 R: U; d$ t0 a
' x$ o1 F6 k$ R+ E. p2 ?
Method 10% d) x4 E* P+ d( [1 S9 U
=========
9 H8 m' U- |7 I* w. R
) f' U1 j0 ~& n- j) u1 d=>Disable or clear breakpoints before using this feature. DO NOT trace with8 }! S9 z& ~/ R- s3 w# @
SoftICE while the option is enable!!' s! e! Q$ T6 d9 Z
' b' u$ ]( `6 ?$ sThis trick is very efficient:
S) ~. m$ n& wby checking the Debug Registers, you can detect if SoftICE is loaded, h6 m/ l( O2 `' x' Y
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if* O) a4 Q- ?+ }, |, e- X
there are some memory breakpoints set (dr0 to dr3) simply by reading their
8 Y) p6 Y% V5 r3 avalue (in ring0 only). Values can be manipulated and or changed as well
6 ]$ d! L5 V% @% g) I(clearing BPMs for instance)
- y$ K! d9 M$ B5 T! F% `
+ d5 M: N; T! ?# Q! A. W7 O__________________________________________________________________________2 N9 K: k( j# @* S3 F4 |5 r
( ^3 N) h- B, A& @2 P; OMethod 11
& |7 V( U7 }* A F=========, M; c1 |1 I. G( c) R2 \. ?
0 d; ~- x) u, F9 B$ SThis method is most known as 'MeltICE' because it has been freely distributed: a) T: @! a' C+ @$ M: m
via www.winfiles.com. However it was first used by NuMega people to allow' x6 F5 e9 u) D0 |
Symbol Loader to check if SoftICE was active or not (the code is located
! \" p# B! c jinside nmtrans.dll)., O& z+ U& c W; M" g2 ?
9 M7 \1 B1 j& S( | @The way it works is very simple:, K! t) g% j6 K
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for- D6 L( b& I9 w" q4 t: I5 F
WinNT) with the CreateFileA API.
4 @; }4 z: [7 O' @+ q9 ^
% P9 a$ W( r, h; E) [! THere is a sample (checking for 'SICE'):
0 P* N! P7 k& W2 V. V
' l7 m6 x) C- CBOOL IsSoftIce95Loaded()- }+ w7 M- s# c3 k( ` Y
{# I& h$ B6 Y+ ~* | a5 `
HANDLE hFile;
, `0 Q# H( J$ K4 F3 A9 g! g* x% r. _ hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
8 q# Z& }* X+ p2 @ FILE_SHARE_READ | FILE_SHARE_WRITE,
% k% k0 }4 U* b( O3 x8 t. r5 N% L NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);5 g8 ^- M# o+ C6 K5 U5 n
if( hFile != INVALID_HANDLE_VALUE )
0 s6 {) _, ]( V {3 o% Z; }- L/ E5 u- u/ L4 U
CloseHandle(hFile);! c% i+ `& _& ~- j2 X' G7 j1 o- V$ X
return TRUE;& y& B0 f1 @) |8 h3 s, Q$ g
}
+ f5 x! N3 T8 b V( u return FALSE;. O' S* y8 Q1 e/ K
}
3 S; t5 J, v4 W, F# c" q8 o* e4 u: ?0 ?
Although this trick calls the CreateFileA function, don't even expect to be& H" q7 y- I: R7 c
able to intercept it by installing a IFS hook: it will not work, no way!
: P' Y, c" v9 U/ G8 O jIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
( p0 B2 M! w9 e* h8 Q9 b6 Gservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
& x0 T! _* E# p4 d& Y( eand then browse the DDB list until it find the VxD and its DDB_Control_Proc/ @8 j3 D! q. T% C1 B9 e# e' u
field.' w6 S+ E2 N, l' p
In fact, its purpose is not to load/unload VxDs but only to send a
' p0 o. e* p, f! W+ D6 VW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)& ~: y+ W# e1 Z% V; q/ F6 O9 H1 E
to the VxD Control_Dispatch proc (how the hell a shareware soft could try. {+ {5 @ b# L0 A/ V3 K! y
to load/unload a non-dynamically loadable driver such as SoftICE ;-).8 V" X& y- L7 O/ C6 \' j
If the VxD is loaded, it will always clear eax and the Carry flag to allow( d; T% w4 W2 I" u, \
its handle to be opened and then, will be detected.
; q( M; p% O4 R8 [+ U% g) N; _You can check that simply by hooking Winice.exe control proc entry point" ^" A( s& Z' i+ t
while running MeltICE.0 d* X. Z9 \2 A$ G
F/ c. `1 o" e! G# d8 W3 B4 `. Y
6 l4 o& d+ h0 v 00401067: push 00402025 ; \\.\SICE2 _. V0 Q$ D. r# E3 L7 \+ y
0040106C: call CreateFileA
& ]1 X% Q7 Z# @ 00401071: cmp eax,-001
' k$ \6 m1 Q/ u# E! r" d% G 00401074: je 00401091# C: b* V" Q, W7 }+ t
. }8 M& @" U1 c3 ~. [8 D: l* y2 {8 g; j
. N- u4 P+ ^ R1 n2 a7 gThere could be hundreds of BPX you could use to detect this trick.
' M3 ?7 C! C4 p+ K" h-The most classical one is:
* ^) n* j5 h8 @8 @2 @/ h: M/ E# } BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
; z9 R: }. S2 k *(esp->4+4)=='NTIC'6 W5 s1 _& F) t6 ^: [3 P2 h7 W
" x' h0 ?/ u: E9 V. x-The most exotic ones (could be very slooooow :-(9 t; n: b0 g4 s. [' D
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 4 k' i: N+ r4 x" G0 S* f
;will break 3 times :-(
/ @$ ^% g W% y8 ?0 s* A- k8 S# e- X9 y5 e
-or (a bit) faster:
0 K! x4 \8 i' Y& Y- ~3 z BPINT 30 if (*edi=='SICE' || *edi=='SIWV')) X2 k5 D3 ^3 i8 k3 w. W, Q% Q
' E7 Q+ K: N' s3 j! w BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 7 I3 @# R/ C* J9 V7 W. J
;will break 3 times :-(# {5 `" O( T. a
8 G2 ] P& m5 S2 T1 K7 T-Much faster:
) f9 D' T) W& g, j& K4 } BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'6 q0 z, c& \! l" n) q0 Y3 [" a
{( N d; }! N; U
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
. C* R( d9 L+ B2 a) M, {- H1 y9 \. bfunction to do the same job:
" \$ g5 u; i6 G* T$ N( D
: F Y: u: q5 u* }( T2 @ push 00 ; OF_READ
/ B9 k4 }: r0 I7 g; f mov eax,[00656634] ; '\\.\SICE',0
: r" O) U' @$ F, O+ G1 \ push eax( N8 X, V9 ?6 [3 r8 x
call KERNEL32!_lopen
4 ]7 E6 V/ A3 ^+ i6 W inc eax
/ i( b2 r5 r$ o. h jnz 00650589 ; detected
. T9 m+ P& ]) h0 }1 N& X7 h push 00 ; OF_READ% A! E/ u ?( S' c6 W( {
mov eax,[00656638] ; '\\.\SICE'
P& B: Y6 p% d; \0 D! c, Z push eax, P C# x2 u! s% q5 e, k+ d7 z0 l
call KERNEL32!_lopen
8 R# E% M/ s+ {$ \/ u$ p inc eax
+ c+ a$ F5 s; r0 Y jz 006505ae ; not detected, G3 R4 i# N' A# D
; V; |2 a/ e1 i$ i9 [+ B# B: P
% i2 e* F2 r$ Y, ?/ @__________________________________________________________________________- D _8 f' m1 Y y: k: }5 _6 ~
! t( R1 W$ S2 ^- o# ~! d5 R" \
Method 12; n. F6 r" U, c& D
========= v, n8 s; N& ^1 R; y" P" n- k G4 `
9 i% P* t- s/ VThis trick is similar to int41h/4fh Debugger installation check (code 05
/ ~' R) o) @7 n& 06) but very limited because it's only available for Win95/98 (not NT)" g7 D+ E3 X8 _1 v
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.9 Q ?9 }+ v$ O) o8 X
7 M7 g+ Z7 f5 v/ o1 p* n push 0000004fh ; function 4fh6 H9 [- k; `) Z0 o
push 002a002ah ; high word specifies which VxD (VWIN32)
# I# s u. V7 F1 I* c8 m ; low word specifies which service
" H# M0 a5 R/ a; S; F+ U4 c3 j2 p4 \ (VWIN32_Int41Dispatch)
& Z, C7 x% {% s5 T! y% a, i call Kernel32!ORD_001 ; VxdCall ]2 S7 s Q; F1 P
cmp ax, 0f386h ; magic number returned by system debuggers
) s0 T: w: K& Z" z' N jz SoftICE_detected4 q! E+ u; f! K4 h; ^$ ^/ u
/ D8 F) A; L+ x' U
Here again, several ways to detect it:9 A* w: S' u5 ~; D3 Y
! |9 @+ L5 }# T; F/ Y
BPINT 41 if ax==4f
8 R2 `" k5 Z: J5 o+ O4 Y7 L: u' E) L; s% |
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one( G7 J S4 l3 U
+ u+ M O' H. f* t; b BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
6 R5 U% b0 ^+ t' b9 g6 G; I
: O/ R3 {& {2 e) @* m' U BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!( G+ H& Z: W: V8 C. r8 Z
! N4 a7 j. i8 L I" G9 ?1 N2 e
__________________________________________________________________________( C2 ?3 C$ i6 m
( e7 P! Y3 R2 [' KMethod 13" Z- R" ~5 Z# H4 |* e
=========" `! ~( s3 @ y/ |9 z* |" S
* E. L9 q- @# FNot a real method of detection, but a good way to know if SoftICE is! ?7 T6 V: }1 a* g _
installed on a computer and to locate its installation directory.& b% `/ Z9 G2 s6 r! f1 E0 x
It is used by few softs which access the following registry keys (usually #2) :3 p% V' Z" L- ]# V% s/ i% J2 R" G6 y
7 a4 v: w! t+ n8 d
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
. c$ C$ I" @8 l3 @9 G\Uninstall\SoftICE/ T' k- c3 f1 i: Z4 U5 V3 @
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE7 A( G$ u4 ?9 n' s9 g: }
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
! W8 U' h$ c, G1 S; u' M\App Paths\Loader32.Exe) F5 o/ j, J+ T+ G7 L4 C7 `6 ^
6 C+ f! h) {4 o7 d3 y, R4 o5 [, _
Note that some nasty apps could then erase all files from SoftICE directory. i7 m9 ]2 o! {# Z; o( w# ]
(I faced that once :-(0 Q5 ~- e& F4 L4 {
* Z# P6 ]. ?; L' n: J; K
Useful breakpoint to detect it:
( W& M7 n0 p( G2 E* i, j5 M* D# W# K% D6 E- l; f
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
R1 c: \+ m% X, C" i+ y( Y0 z2 w7 X& S" j& R. Q* m# Y1 \
__________________________________________________________________________7 P- I. V% z& E
4 [ { W$ ? F9 r! }
! ^1 }2 O2 [5 MMethod 14
3 L, q8 P, P5 v3 M# m l' O=========0 Q$ S$ O9 e- J6 J9 j( H
5 N% o$ ~- O9 w5 Y; w1 L: I! ]! xA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
' O3 b( E' w' Z7 y. G$ s4 Y) [is to determines whether a debugger is running on your system (ring0 only).
9 w( X7 x3 c% M& M7 p4 z" x* \2 B$ q
VMMCall Test_Debug_Installed
6 C' t7 e% J8 @2 ]6 x+ Z6 X$ x je not_installed
; T! \3 k2 D: M M6 x$ E6 Q3 o [# Y1 }
This service just checks a flag.) t4 {0 j/ V4 y+ q( M& k# Z
</PRE></TD></TR></TBODY></TABLE> |