<TABLE width=500>8 e' }7 D- O9 \0 K
<TBODY>
6 D9 P2 U# ` \$ J% P+ i<TR> g0 @- l6 C' V
<TD><PRE>Method 01 , ~4 q; y" b9 y- T7 O6 V I
=========) A7 p: o8 o q+ ?5 b5 f
# `6 v! N5 j* J* z' s5 x
This method of detection of SoftICE (as well as the following one) is
4 Y3 p b e. Dused by the majority of packers/encryptors found on Internet.% y" B' F g0 b
It seeks the signature of BoundsChecker in SoftICE; w/ H3 A0 b' k
" W) f" Q4 \0 k mov ebp, 04243484Bh ; 'BCHK'
4 w" d/ c( G( q( ~ mov ax, 04h/ d* d+ a) z$ B
int 3
/ k3 Y7 R9 I$ `8 K/ L cmp al,4
( r& n" p s* p! q7 Q. ] jnz SoftICE_Detected% J6 G2 m) L. ^0 V
4 d8 s. [2 x5 @* I' T8 _; } h: l" Z___________________________________________________________________________ M: ]; h: o, k, x$ l8 `/ P
$ F2 p2 T; ^2 E6 I
Method 02
! N' a. E# f y2 T- b: Z=========
0 G9 f) J' W0 J. y1 E. z# Y6 J# [1 y& |, R9 B8 B
Still a method very much used (perhaps the most frequent one). It is used: X5 a' [" g: ] j. m" M& q$ V* B
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
+ F# K9 q/ l7 yor execute SoftICE commands...
3 y8 t8 h- f0 G+ d* DIt is also used to crash SoftICE and to force it to execute any commands* Q- H5 @" n6 Y+ X+ d/ f' N
(HBOOT...) :-(( # h2 F4 l. M! @" W
4 ^$ e( y) l& g( i1 p
Here is a quick description: |9 U. x6 J- h$ V
-AX = 0910h (Display string in SIce windows)
1 c# }" ]7 Q3 t' A" o9 ~/ X' l4 z-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
+ ] e) z; W# R% ^ W4 e-AX = 0912h (Get breakpoint infos)6 f1 @1 M0 Z$ q9 X' K! E% s
-AX = 0913h (Set Sice breakpoints)* h3 T% ?& g( P) @2 `6 b
-AX = 0914h (Remove SIce breakoints)
; j" A& c- s( m+ O8 h1 q2 ~* d/ \. m4 }3 Y g( d
Each time you'll meet this trick, you'll see:4 [% X0 T/ H% [$ @2 e2 R& @* _- ]
-SI = 4647h: ?7 `. i% D4 i8 g' G6 I
-DI = 4A4Dh2 K% U; L1 D' r! x; U
Which are the 'magic values' used by SoftIce.
" a/ H/ \# ?4 z; z9 eFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.4 e* [) S5 i# m' r/ d* h# C V! K
0 c4 w: x7 Z9 F# A, E
Here is one example from the file "Haspinst.exe" which is the dongle HASP8 I+ U) A3 n1 [" t0 w; D- O
Envelope utility use to protect DOS applications:+ |! [ @5 i6 R+ u/ b0 I5 \( h8 k
7 L/ X/ K6 u2 Y: U/ Z; ]
; g$ S( M" u4 h- t/ W; k. M4C19:0095 MOV AX,0911 ; execute command.) y/ b! u) _$ r8 Y2 v
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below)., n( _! N }8 h/ U! _2 }
4C19:009A MOV SI,4647 ; 1st magic value.
; b7 X0 a# m3 m, U4C19:009D MOV DI,4A4D ; 2nd magic value.8 Q/ [! x8 B5 j: i7 s
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)* _ v& J+ _! s% p9 r# d
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute( B, _9 f9 q$ N9 a' V8 b) a
4C19:00A4 INC CX
4 f7 @5 J0 C) u' [4C19:00A5 CMP CX,06 ; Repeat 6 times to execute7 r) i# m3 x: G- ?5 h
4C19:00A8 JB 0095 ; 6 different commands.
& G. a, B- Q: @$ k/ Q8 F; l' x- E6 R4C19:00AA JMP 0002 ; Bad_Guy jmp back.
7 S u+ ?7 {3 S5 ?) n4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
& p& e2 z* J) p7 Y4 @& ~- F* [8 [
% {8 l, K, j6 XThe program will execute 6 different SIce commands located at ds:dx, which+ p7 Q8 ^! b) a8 N |/ n/ X
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
8 P& ^0 U+ t9 n( V( _, Y- D
/ N: d) P, W6 x$ H3 N1 ^. @* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded., P# r+ f4 ^% {5 d
___________________________________________________________________________6 ?* { u3 I( g2 ?6 @' t
- z! ]: W" r- |
2 R8 M) y, J" F$ P+ qMethod 03
: B$ F% ~3 j1 i=========. _8 X+ m" E7 q$ w
+ q2 V V6 Z5 p1 S( J' m( v
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h+ [2 ]3 o6 }9 X4 y
(API Get entry point)
2 h5 D; y7 b" Y! y! [' X5 l/ o 1 b0 ~* P$ ^" C$ n1 o8 e
0 X; M; g9 C2 E5 E1 C9 m# F* l
xor di,di
; E6 J& F8 L) Y7 q# t mov es,di
( w' p* a- C+ P6 |6 O6 k; W mov ax, 1684h 0 y$ V) R9 T F2 O
mov bx, 0202h ; VxD ID of winice; d1 {/ N( ^. V4 V, Q0 ]
int 2Fh
2 z' n: y ]" V/ V0 h7 U mov ax, es ; ES:DI -> VxD API entry point
; \: X3 W7 G& A5 i( O/ \8 W add ax, di5 F3 y9 L- T: Q# n
test ax,ax* V# J# ~2 g6 P' g
jnz SoftICE_Detected, Q5 n1 T& |' h' p, c
( Z! X' u7 }- |! [9 T8 W8 [
___________________________________________________________________________
. {$ b# A6 V" c! v# ]0 i4 u1 C) q; }/ l( e7 z: {( s9 `. A
Method 04, @! ~ i6 F5 n5 b! N( j; Q0 v! `
=========
- d; H& e* i" I4 \
6 X3 u& _; N, _6 {. k, a. {5 a% FMethod identical to the preceding one except that it seeks the ID of SoftICE
# u% i H4 {2 F6 j3 d% ^GFX VxD.
7 R3 R2 _* u" s$ f3 o8 i) [8 p& c7 g1 u
xor di,di
# a% q$ X8 Z9 g5 g% G& q0 e mov es,di- B, V, h% p! N2 E% j
mov ax, 1684h * F5 [" c6 e E& x& N# Q
mov bx, 7a5Fh ; VxD ID of SIWVID
* a1 Y9 |3 \3 E int 2fh
: H2 R' S. e, N/ ?4 c3 f mov ax, es ; ES:DI -> VxD API entry point
2 G& G8 C* P9 g4 C add ax, di" V) ~, r0 b! R& Q/ b
test ax,ax
! s. C7 U. s, m) O# I jnz SoftICE_Detected* e' f+ S, W$ l4 l+ I
2 E8 |% ?* N7 b& n: u
__________________________________________________________________________" A/ H' _) }: ]. P Y5 P7 f
, ^8 [9 G7 `; R3 K0 r
j. P- z9 j: R3 NMethod 05
( S8 x o- M9 x: \ M1 c=========
1 ]! R. U% |. d2 `# ~+ I j
) v: w- k2 J+ D$ o7 gMethod seeking the 'magic number' 0F386h returned (in ax) by all system
+ @. N/ T, y/ @+ u$ d6 \# mdebugger. It calls the int 41h, function 4Fh.4 n+ m+ {6 ?# A$ q. \
There are several alternatives.
" Y: X# \3 Q% F. f$ \
9 l" g3 [4 `0 c+ C! oThe following one is the simplest:
) ]& Q) E t# F! G! m
! m) w9 W/ _8 r( Y. B mov ax,4fh; J5 O" @5 ?0 q0 }5 g6 h% ^. T
int 41h
0 W% Z# y- o, l* S cmp ax, 0F386+ Z* i: P$ C) C4 c1 O8 D
jz SoftICE_detected
; y; j. a" _7 c" [# N
( `, z3 m/ b) ]9 }' N4 m4 N0 [# h( |4 p! p
Next method as well as the following one are 2 examples from Stone's
5 P- N8 W% I1 C \4 R"stn-wid.zip" (www.cracking.net):) w1 r+ x" ~9 V9 |# o
+ E" C+ T. y$ q' Y8 H) S
mov bx, cs$ ?& Q' r: @6 m6 r
lea dx, int41handler2
# s& {/ [: g- L9 T# O8 r( p xchg dx, es:[41h*4]
5 s o- y: g! p) E \4 R) p5 b xchg bx, es:[41h*4+2]
3 f l8 B7 L- ?+ M mov ax,4fh
& V+ y. r& `, F* X l: D/ {' x int 41h
! c) d4 k2 m+ w: Q! K& Z& r- H, F xchg dx, es:[41h*4]
- F$ P: |: j: F- a; Z xchg bx, es:[41h*4+2]
v' X) V" s& H8 ]5 G cmp ax, 0f386h
& N0 v. I. R+ x" V7 l w jz SoftICE_detected
9 g/ N) D7 P9 K& b. x" G" \9 i' g% l" R2 l8 a' B
int41handler2 PROC
. ]& f# ^3 S" Q iret
1 H2 J1 s/ l0 [& C+ iint41handler2 ENDP
& q1 W: e3 C+ N+ ]' \2 ~9 T* ?9 F9 u; l: Y& T. t: _
- I. j0 ]1 h. i$ D* t1 G# T_________________________________________________________________________
4 d' z2 m# V8 ]) S( u0 |" g+ s6 M; p7 d" o9 K$ {! U6 n* o% J
6 M+ U2 h9 E9 z& w1 J# W5 NMethod 063 S: V, T: |; x5 Q
=========( _& G, y5 c& r% L* `2 c- ~
5 A6 a! M: v8 G
0 c/ O1 h- L# V6 Y) L0 V% u& ]# P- m% K2nd method similar to the preceding one but more difficult to detect:
0 c5 B+ j g' x5 V( S1 d. W! B; k8 B+ b3 q" w
& C( v3 L4 k# I4 Q \# p% g1 C X: |int41handler PROC9 l" a% T% B: N M
mov cl,al( X# |1 R; W( ]
iret
& ~: W; H o9 f. C7 r: D( V7 eint41handler ENDP
9 b7 i- H! ~1 Y- k- J6 I
3 K* E/ X$ d6 o& g4 _2 h1 r; u0 Y$ b
" J7 L0 C) g4 J6 \% k xor ax,ax
4 |% [9 t2 k- k& g2 \ mov es,ax3 d1 D& @' r; g8 D1 f8 ~
mov bx, cs4 n2 b; _* U3 m+ _7 |7 G# q
lea dx, int41handler
. B, l* T+ B& n8 X; P; _1 ^- q6 t xchg dx, es:[41h*4]
2 `4 s$ ]+ S2 k. x' H xchg bx, es:[41h*4+2]6 x) S/ U% l9 P! w3 A& A, Q% p# U
in al, 40h
. @% ]3 i4 [0 o8 H5 y: d; W6 P4 p$ O xor cx,cx
8 J# {& M% b9 x% m; r, f/ ]' [: U int 41h: E: l4 u( z9 a
xchg dx, es:[41h*4]
! ]. {, O) l$ c% S; ` xchg bx, es:[41h*4+2]
% S* ~" q1 o; Y/ ?2 _ cmp cl,al
, I `9 j# [/ V( ?3 V+ g6 o jnz SoftICE_detected
0 ^3 p* d+ T T1 h3 X* G8 l. V0 Z& W. R
_________________________________________________________________________, g# K6 z; d9 `
; [3 z* B4 x2 ?* e/ i' h! ^
Method 07
6 g* l [0 p; l6 F" Z I0 Y=========
, p0 e t: F, j1 L( W5 Y& t+ G4 L; b1 b" h x
Method of detection of the WinICE handler in the int68h (V86)% x T/ Z6 i4 y \6 X G
6 U1 f( E3 u8 q2 U mov ah,43h
' {) q2 `* g3 p+ b v int 68h
: `' i# Q0 [; x# G6 ^) S$ H; g cmp ax,0F386h
8 `! C' U- f ]" W jz SoftICE_Detected
( ]% u" u ]4 i C A$ @; v
) L" [7 G; R7 P1 j9 _8 `, t* s" b; F: k. F* z0 q9 S/ h+ b" O$ f
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
8 Z2 g" Q- W* X+ { app like this:3 _6 Z& X( U5 V
* A! z. C% n8 A7 g BPX exec_int if ax==68/ [! g" `! C; J" Z; M/ [ Z; V6 }
(function called is located at byte ptr [ebp+1Dh] and client eip is
$ K5 T7 n3 P' Y3 h, u/ u8 F located at [ebp+48h] for 32Bit apps)9 w1 P2 e7 l7 m' I. ~" k
__________________________________________________________________________ P' P l7 m3 x' c9 p I
& Z, k7 \5 E, ]+ a3 n# \% ] U& f' d1 ]
Method 08
' c& W& q+ Y7 M# o=========, H/ X7 I* c; ^# v
2 b! G! T, N& i3 [# @' h
It is not a method of detection of SoftICE but a possibility to crash the
& W# ?- X8 x, ?# b( a: z1 D2 `system by intercepting int 01h and int 03h and redirecting them to another
6 r* S2 r b, d3 Vroutine.3 `' M9 n6 q) D
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
' ~2 z7 k, U2 I" Wto the new routine to execute (hangs computer...)1 T0 F: v' F) D/ o
: z. _8 O( `/ p! ^
mov ah, 25h; ^! F' M$ Z+ a$ w
mov al, Int_Number (01h or 03h)
U! f H, N" [ mov dx, offset New_Int_Routine$ N: ~ k/ U/ h
int 21h
3 M$ N) |# Q: l1 h+ g5 f; g9 l
9 l, w: ?/ f( p( S__________________________________________________________________________% y% x) E+ C3 k
" C* {$ N2 F# o- u, eMethod 09
3 G9 R8 I. R! P=========9 o" Z, I) q1 D3 q. a/ L$ i3 D
4 V7 u8 R7 {/ X5 V" `
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only8 e2 D* @8 q3 \# P7 p
performed in ring0 (VxD or a ring3 app using the VxdCall).5 ]( `0 Q( T9 R* a. m C- P
The Get_DDB service is used to determine whether or not a VxD is installed
- R& j3 G" k$ j' J5 R# ^for the specified device and returns a Device Description Block (in ecx) for+ M& F' @7 c% n8 N) W
that device if it is installed.
: H+ U9 s$ z7 W0 S8 h. B3 o2 X% c5 f8 w. K0 b! v
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID! q9 k: T5 [9 _3 Y! p y4 R
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
, f; w5 S& F4 i2 ` VMMCall Get_DDB
7 Z2 v" M" O5 r6 m8 R$ X& U7 W mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed4 U9 ~: s& y' {2 @, p* [
8 j. R, W% d6 t7 `5 sNote as well that you can easily detect this method with SoftICE:
1 m* e5 t' A# J1 P/ _ bpx Get_DDB if ax==0202 || ax==7a5fh
' |) K' K$ L9 c9 [5 o& g* V
1 k5 [+ x$ Q# s6 c; k; L__________________________________________________________________________$ o3 ?+ s0 o4 t `# i
8 D. H i5 j5 u' t
Method 10( T% `; g$ | r$ \$ {
=========
8 P8 L0 ^* P+ V
& T" @1 k8 p2 E: R0 b- e- z=>Disable or clear breakpoints before using this feature. DO NOT trace with
1 S# H) p/ w0 ?* _9 n SoftICE while the option is enable!!
, U6 [# y# P: Q& N& N- F/ \2 y3 j6 W3 L6 p- u1 G/ s' C
This trick is very efficient:
& {0 ]% T; ^: tby checking the Debug Registers, you can detect if SoftICE is loaded
5 n1 w6 ?' L$ o/ u" ^' h(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
6 U; K( P* b- k1 T! G" Gthere are some memory breakpoints set (dr0 to dr3) simply by reading their% n* k9 r" u2 R2 X) Z( @
value (in ring0 only). Values can be manipulated and or changed as well
, o c) ? a! l: B6 E0 [, g: B2 Q3 S: ](clearing BPMs for instance)
/ A$ x! Z! H- n4 }2 y6 l7 o
2 A. K, H! w; ^6 F6 I__________________________________________________________________________) I/ s: X) @6 v6 m
$ R- y5 `$ c/ c8 v T3 N
Method 11
$ i% S6 r, U! x! W; ?. j=========
, q3 H n9 r6 j y8 t1 ~" V1 C2 K+ D9 }
This method is most known as 'MeltICE' because it has been freely distributed0 ~% I8 [, ~, q0 Z/ F
via www.winfiles.com. However it was first used by NuMega people to allow+ e2 A4 ]* M1 E& w
Symbol Loader to check if SoftICE was active or not (the code is located
/ ]5 z ^6 U! T* Tinside nmtrans.dll).
6 N) L7 @6 p! L- M) J$ ?3 P: z* x& m. k+ m) l! P2 M
The way it works is very simple:& X6 q8 y$ K' k1 Q9 M$ i
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for* X. s/ ]7 \& p7 p3 _
WinNT) with the CreateFileA API.
' j9 r. n& x- S r3 Z$ [) |5 G
0 U, t) [, k d! _$ ]Here is a sample (checking for 'SICE'):
) w" O: X! [7 c, t M" D) z. T: } [ e' n$ e
BOOL IsSoftIce95Loaded()
3 { Z6 \5 L) n: ]{7 ~! b/ D3 L2 t) {7 q6 C# O+ y
HANDLE hFile;
# ]: A7 d# D- f* ]# b! Q6 U t' ? hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,% g8 w! l/ \0 M2 c, } l2 h4 w
FILE_SHARE_READ | FILE_SHARE_WRITE,
7 c. z l% y/ V+ X- `: } NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);/ R8 [ j2 {# d$ d( f* o7 P
if( hFile != INVALID_HANDLE_VALUE )
/ A2 t2 I4 \- \) p {4 W. K1 ]. r3 X
CloseHandle(hFile);4 @+ h* R5 A) H
return TRUE;1 o6 L3 n" A# j C" c
}
6 c1 \3 w. K5 A; \$ V return FALSE;, y) r0 C5 s- s
}
. X3 f0 ^1 o0 q: Y, @5 `) F" f1 W/ a( y; A
Although this trick calls the CreateFileA function, don't even expect to be
/ x0 z1 ]. V1 B6 s5 x6 X [7 [able to intercept it by installing a IFS hook: it will not work, no way!
% l C! ]% C/ YIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
5 A' m* f8 d/ i- [service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)% W$ `2 _) l/ S/ W& `
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
, D# Y. s2 Z) N) _4 Mfield.
! f' v" D6 d* y/ Z: FIn fact, its purpose is not to load/unload VxDs but only to send a
$ B% c. f [7 b4 C& r! }- DW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)* |# P1 L1 J& r4 D3 T+ O: d9 s
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
* q* Y5 j: S0 Tto load/unload a non-dynamically loadable driver such as SoftICE ;-).3 Y8 T, t0 ^8 d0 Q7 @6 ^0 q
If the VxD is loaded, it will always clear eax and the Carry flag to allow
6 v+ p" l: k9 V k+ D% Jits handle to be opened and then, will be detected.; X( _/ L. B7 Q7 F- J( y
You can check that simply by hooking Winice.exe control proc entry point: X4 S- B4 u9 f, [( x7 x1 @
while running MeltICE.
& A' a# ?0 n+ [1 c8 k S
A" D/ O- }' ]$ T
7 H0 d0 D: I* ] 00401067: push 00402025 ; \\.\SICE& }1 p1 E3 Z+ o, E- F
0040106C: call CreateFileA# i9 H7 ^$ z- C1 I, M
00401071: cmp eax,-001
. ^5 \/ I0 r5 |% F6 ^& {4 N0 g( U 00401074: je 00401091 E# g6 z% @8 {; j0 g
: U( ?# x" J/ _0 x3 I: r
; u! Q9 a1 K2 y: fThere could be hundreds of BPX you could use to detect this trick.
' d5 l' [) L" A0 ^6 L" z2 J-The most classical one is:
& c9 X7 {* H2 } @4 k" I. D& s BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
# q( _4 I* a+ V4 Z( [( a *(esp->4+4)=='NTIC'
, o( o. q6 z1 S' R) r2 v$ P* K1 A c+ Y) C6 c: R8 z4 V8 }# e
-The most exotic ones (could be very slooooow :-(" N6 N1 F- A: \2 O
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') ; a, l+ M& S+ L- R) ~
;will break 3 times :-(
7 V7 o# q- v! H6 e
$ P" s6 l* q2 u* h8 L _& u$ j-or (a bit) faster: $ I7 B+ H9 o! I" A
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
5 p) b, M& I& P& u' V, ^6 u' U, s3 {# D6 v2 [3 }
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 3 |$ I5 u! e; f9 q
;will break 3 times :-(
q; @: k+ i, K( Y: c
- w6 }$ a* L2 N; D! P-Much faster:
& o( I3 `' i2 `# w! i BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'2 a6 ^" }2 ]# e1 _6 `# Y! f
6 k- w w' p* i8 w% W4 ]* b- n7 iNote also that some programs (like AZPR3.00) use de old 16-bit _lopen: Q, h) W+ M: b: y
function to do the same job:
! f/ X) P9 ?5 F- F2 O8 f( d# l) y! ^+ i7 l3 w/ S
push 00 ; OF_READ
9 P- @0 ]- m3 I mov eax,[00656634] ; '\\.\SICE',0/ U# D2 g/ p* H" \2 o/ {
push eax
; S `& _. u3 T2 k7 F4 v* | call KERNEL32!_lopen
2 R+ ~9 u0 n4 v( J( h. j# I, ? inc eax: @5 @ I" d& ^% I# Y* E
jnz 00650589 ; detected, O" {6 d6 f$ }! o2 j+ A
push 00 ; OF_READ8 N$ r7 i: M( b" P8 w2 _
mov eax,[00656638] ; '\\.\SICE'
( W5 U3 h1 _# D$ |8 U; j push eax
5 F4 _$ B0 |7 y, V* B0 t% K$ |! J5 B call KERNEL32!_lopen8 m: G( d8 {9 ^2 N2 l5 Z* |
inc eax
8 j, j- x7 I' C- N& v; y jz 006505ae ; not detected
6 N1 Q. ~0 z/ Z" z. g$ H7 Q3 _/ i4 d% R* G) R' x+ [2 z
1 [! Q2 p- [ @0 H# ~; J% }9 x
__________________________________________________________________________
4 H) N. B8 w' k `
- }; e9 g1 U4 ~- d, {Method 128 b! `1 ^) N% q/ X
=========6 z# ?' h1 Y9 i% O7 C! P
) I& p, L. Z( }6 a- x x
This trick is similar to int41h/4fh Debugger installation check (code 05
1 e/ H; d0 ]; d- s& 06) but very limited because it's only available for Win95/98 (not NT)( s7 j L E8 j6 u' t e
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
5 @9 ?/ x" l; p) W. l( d' Q; `* l
push 0000004fh ; function 4fh
! | e! u4 p5 u9 X push 002a002ah ; high word specifies which VxD (VWIN32)
4 [' P8 c! g; f ; low word specifies which service' }5 b4 r4 l5 Z0 ~$ ?7 ?8 a9 V
(VWIN32_Int41Dispatch)' i+ h, [: u9 V2 r3 r$ C9 n5 q8 U
call Kernel32!ORD_001 ; VxdCall
8 v4 i4 p: x' j9 J9 Z* ]9 v cmp ax, 0f386h ; magic number returned by system debuggers- w. Z- I+ {$ W4 W* W1 P! r+ G
jz SoftICE_detected U3 n3 y+ _& ~9 [% r! g
* E+ W4 b$ C6 I, l4 v2 l
Here again, several ways to detect it:, p/ j4 d# F6 m7 A7 {/ {0 K& C
5 F0 j3 G$ I% ?. E BPINT 41 if ax==4f, R* v- X# E9 |0 O O d: X, r
/ `2 C/ z! n; W9 I' m) F( j3 J: Y" r
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
3 f8 {7 g# D4 o
! j! J) v7 a8 x" j BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A, W& \1 v6 u% W9 D# r0 T
6 H* T( ~( {; Y& D BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!- f/ g/ N& \, H1 Z# P% Y; j, R
( C5 N8 f% ?% D
__________________________________________________________________________ Y0 P' Y( @1 q
+ E( N- y6 L0 x( g" q( A6 X6 SMethod 13
. O4 F( @' W8 \ [- g=========: ~# n0 [; b- Z: K7 q' M* k
E7 O: g+ Z# e& K1 B% R1 K8 b
Not a real method of detection, but a good way to know if SoftICE is
" H4 K! z* d2 v) {9 \installed on a computer and to locate its installation directory.
; z- z$ V+ H: L8 i8 P4 ^It is used by few softs which access the following registry keys (usually #2) :
! N( a4 ?2 b( W# z5 z5 r1 R' e
3 b A& T! I3 d# \) w- L-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
6 {3 z7 H5 ~4 ]6 E9 R\Uninstall\SoftICE
+ L# {3 I3 t4 G Y-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE) [, S- a7 M0 X7 i8 d: n$ H3 _6 C4 ^; k
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
" t3 g2 y* N6 Q6 E\App Paths\Loader32.Exe7 N. N/ s2 C7 x
3 `7 p' V( ]$ e& z/ i3 i: W$ p( {9 J# U; ]* A: y/ d! L3 g- ~$ c
Note that some nasty apps could then erase all files from SoftICE directory$ ?3 t! J o. Z# ^
(I faced that once :-(
3 o) E3 i7 F o- f5 Q2 B1 _8 a0 q9 A) n$ K: U
Useful breakpoint to detect it:
1 u! [7 e5 A1 ~
, l/ g3 R7 ~2 m! S# o" Y* K$ P BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
/ |+ u# S5 T$ d% J/ L: t, H; C: R s) R5 D
__________________________________________________________________________& r! _3 g/ D, [' ^2 k" m
7 F- A' a {2 j0 {! X+ G9 W+ N- v9 [0 k" A
, `7 V7 c8 M& k* g/ L( @
Method 14
& y( z/ I4 I2 e2 B; S1 A# \=========; V3 ^' p4 H4 u
, M- o9 m( P( H5 E r3 b/ Z7 u6 R6 J4 }A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
0 _, g# I- W8 Vis to determines whether a debugger is running on your system (ring0 only).
9 M( k1 D) z: V5 g' ~; Y% X8 W W8 p% `8 z7 ^' V9 H# s- G
VMMCall Test_Debug_Installed
# b1 L2 J2 F' c$ _8 p7 S" D je not_installed
2 v, r7 S; T. ~% Z
3 i" I+ T R( o8 z: |9 l# x7 xThis service just checks a flag.
/ D/ W" U$ H4 q. C3 B" o$ Q</PRE></TD></TR></TBODY></TABLE> |