<TABLE width=500>( w5 X2 q2 I' J; X3 \. _9 O2 E1 h
<TBODY>
7 D% n* Q ?& O<TR>$ e7 ?4 a# Q1 t2 Q/ ?( l9 d
<TD><PRE>Method 01 $ h$ E# W5 ]- g. r( l3 A
=========
7 S! @' G q3 k) S5 y7 C4 t7 R: b3 z a
This method of detection of SoftICE (as well as the following one) is& ^' P* m8 H/ ?
used by the majority of packers/encryptors found on Internet.
+ M+ R6 @1 {# }/ q8 {: H. E7 r0 NIt seeks the signature of BoundsChecker in SoftICE; ?- y( b4 P% A2 q1 `' ]
* F0 Z5 ], |2 q' C% Y- F mov ebp, 04243484Bh ; 'BCHK'7 @8 C( a/ ^- m) f
mov ax, 04h( ~) o+ V+ f c7 T0 b( v
int 3 - z; Q" s( W F: c$ C5 T
cmp al,4
* |7 I3 P5 I, C jnz SoftICE_Detected0 Q4 B; A6 s% w5 A0 x
8 |2 ~) Y3 O# ?% @: J$ M___________________________________________________________________________' b: E( c* q. q2 u, X
6 a* I% F& W S" w- fMethod 027 H; H N) G( l$ ^/ x4 N
=========
$ O9 y0 K. y& j0 h: G$ Y, n( n+ M
Still a method very much used (perhaps the most frequent one). It is used2 k4 q1 f5 k3 S+ f/ F4 s$ \" ^
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
1 N$ `; z$ A% w: N9 j4 bor execute SoftICE commands...
" G! J3 W# g4 QIt is also used to crash SoftICE and to force it to execute any commands. `7 _# G7 f6 D4 d7 X. J
(HBOOT...) :-(( , V7 Y U. E' }7 e: Q- t5 f. [& a
) a( U# U, L7 PHere is a quick description:8 K# P9 e$ D* u; G) `
-AX = 0910h (Display string in SIce windows)3 U& `) ]9 \0 C" e. Q0 X8 B
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
7 v3 N2 C' U" @-AX = 0912h (Get breakpoint infos)% Q/ c5 d+ g. L+ ^, b- a
-AX = 0913h (Set Sice breakpoints)
+ v s- p% r# ^2 B-AX = 0914h (Remove SIce breakoints)9 \( D9 }4 t6 k% K0 h) }/ N
3 \% l3 E) v) l) S O( p
Each time you'll meet this trick, you'll see:
5 V& O1 w! V3 Y7 M s-SI = 4647h
3 K3 l; J" V8 b) X-DI = 4A4Dh% F3 e. f% I* b- L, e5 j
Which are the 'magic values' used by SoftIce.
8 f- f9 Q0 f. B" |4 V) NFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
& v6 r! j3 Y. K# J8 E# C/ Y n0 B9 y! f9 T5 d
Here is one example from the file "Haspinst.exe" which is the dongle HASP
, A6 A3 x3 ~( G4 r* wEnvelope utility use to protect DOS applications:% S8 S4 @ a4 A8 L7 [0 y- O/ m
8 h e* O" Z3 O' r( K4 O
2 @! [5 ~ ?$ A3 X
4C19:0095 MOV AX,0911 ; execute command.3 V1 k$ r: y1 i$ i7 X$ z1 Q
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).5 g/ a& |* p! _, c4 j6 h
4C19:009A MOV SI,4647 ; 1st magic value.2 g, Z6 g) E. M( A* J% k% ~
4C19:009D MOV DI,4A4D ; 2nd magic value.
& \1 y/ V# p6 e% N% I$ ~! B( ^4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)$ P+ v8 f( e* ^4 c
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute( M- w |! ^# Y: N/ ^ b" y: V, D
4C19:00A4 INC CX7 J Q# t5 w; }0 i3 l
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
. H4 ~# ?# {* z. J; Z4C19:00A8 JB 0095 ; 6 different commands.
$ z1 W/ T: ~7 g9 s1 P9 F4C19:00AA JMP 0002 ; Bad_Guy jmp back.: R: S- e% F! a
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)5 y/ y& U% D! Q% h; P, D
" L* N/ x5 z/ v+ B. Q3 H0 [, X
The program will execute 6 different SIce commands located at ds:dx, which9 g% A4 z: ?. g& e
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.( I$ h2 j& |1 F I4 t
8 m5 K/ B5 o0 Z$ x1 Q% Z* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.' x- [) ^* ^+ I! R
___________________________________________________________________________' O3 V+ [( D% P' e# z
4 c9 x+ r4 s; A+ b+ I2 [. w
6 r3 J1 q: t1 c f0 w1 I
Method 03
( @( N, p" b+ o/ Z=========+ w# H& I- d8 Z
2 e' ?0 M- p2 M9 P- ^5 M
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
- f2 z1 a$ }' _ V2 e" b5 c( ~1 L(API Get entry point)" E/ _- ?1 x+ ]* l" C M. M6 E
9 ` S8 v/ ^' c. `3 W( P+ {' b8 w" e, d* I. r, f$ Z/ q3 g
xor di,di, L0 o F3 p$ h2 z/ j
mov es,di
% I+ S5 v/ M% X9 F0 q# ]2 z$ g* D mov ax, 1684h
. i+ d$ R6 c% _6 a \7 [9 I3 b mov bx, 0202h ; VxD ID of winice* f5 q& I- b& \; {2 U
int 2Fh
* ]/ ]2 K( \6 y1 t' ?& i( b5 ] mov ax, es ; ES:DI -> VxD API entry point
/ Z' s! e5 u. ? k add ax, di5 l% l+ Z" ~7 _- o) s
test ax,ax* S' E- Q3 O. t! V" R8 f' q
jnz SoftICE_Detected# ?$ T$ q$ ~) I8 P
" Z3 G" P; j3 C
___________________________________________________________________________
9 l& C' q- h1 w" p+ e! k3 S& w1 S$ ^" x2 L+ H
Method 04; `7 H; x& T$ _5 q: X" Q
=========
6 Q, G: Z9 m! m2 T M% a2 A- P
- R. c/ x) K$ PMethod identical to the preceding one except that it seeks the ID of SoftICE; \4 I7 V, K5 ?0 `
GFX VxD.: z- w% u, Q" Q# [6 Z, a* _" w5 z. X% C
2 H: h# H% X: C+ E' X. O5 W1 E
xor di,di' L5 _) }* a* G" p
mov es,di
6 ~( B, Y* D8 {) J! a% ^0 m0 |8 T- e mov ax, 1684h : F5 ?& e: _1 [! n$ `7 s4 |
mov bx, 7a5Fh ; VxD ID of SIWVID
2 p4 g0 {2 g1 w- W int 2fh. `: a% ?# `5 c6 @4 D- ?, v
mov ax, es ; ES:DI -> VxD API entry point: J+ [$ v/ p) q" k; t
add ax, di" ]1 P9 X' }. Q7 A) }' U& Q0 s3 B& z
test ax,ax
% p" e' _" q$ j3 I3 Y5 J) N: O jnz SoftICE_Detected2 l8 G; H9 V% b; \6 V" V
' P O) o$ ~; n. N2 f9 v8 ?, E__________________________________________________________________________" _' g6 G0 A: v
- D/ c9 o* x$ E3 H; V) |+ r
7 R% F3 n# k. T0 [, tMethod 058 P K" m5 M7 d4 ?
=========
: ]" C$ [* {6 E5 u/ [9 m6 r8 w' r7 D! \
Method seeking the 'magic number' 0F386h returned (in ax) by all system
4 d) P+ a# l9 J: V, V- Q7 H& |+ Xdebugger. It calls the int 41h, function 4Fh.
/ a' y6 W: {5 @: u8 d& d' DThere are several alternatives.
% `5 G, b6 l2 Z2 }# G- Y0 r9 K2 l" [! S7 ^
The following one is the simplest:0 y# a8 a! W0 {. y: K6 o
. T* N! q# ~2 a; V7 F5 {# { mov ax,4fh
% w8 A2 k- v s! W; n int 41h: T: C0 \8 X7 J v7 e
cmp ax, 0F386* h4 W' \/ H( R7 Y( _7 G
jz SoftICE_detected: y$ M" b/ `& L
: s( i$ f7 C5 }1 j8 j
' r) }% Q* a$ T: g; r- d: pNext method as well as the following one are 2 examples from Stone's
7 T' J) x+ e6 N6 ]$ s# J"stn-wid.zip" (www.cracking.net):
. Q& U+ U! I& e$ o& I
( ?' I B2 q+ K9 n4 Z! B. [ mov bx, cs
% `+ M# P) u' L+ _* P9 k lea dx, int41handler2$ C3 t, T5 t- C' \/ m. @0 ~
xchg dx, es:[41h*4]
/ J$ T: e D! o xchg bx, es:[41h*4+2]
4 s3 b8 K- D6 a; g k mov ax,4fh& E6 Q# }# g4 G( H# e/ e! D
int 41h
6 _! }$ {- j% C( @7 W7 r xchg dx, es:[41h*4]
) d% c& @8 G0 C' T. r0 p xchg bx, es:[41h*4+2]
9 y) C& k+ e1 F% T* O! D cmp ax, 0f386h/ r% j& `$ O1 I0 t1 e# ^
jz SoftICE_detected, d0 x* n6 P s
. A- ? A% {+ o2 K4 @: _
int41handler2 PROC
1 l6 u1 k% ^7 I/ k iret
& t+ p$ V d) K b. vint41handler2 ENDP
, e) R) n1 u: i, f9 ^9 T; N- Y2 l+ ]# _5 y
4 ^3 m" M' i+ ], [- g, `# O/ Q9 w/ ?_________________________________________________________________________' y( ?$ K( P8 p% Y
+ ~7 _3 I2 h+ w8 R8 H
1 Q8 Q, c& f% [" S% E1 X: @, FMethod 06
( V0 ]0 V% Z, A! d; Z=========
- a' T. r& F r; U: p# b* N7 s* }& v+ T: s" V$ ?$ @& |2 G
* R( ^, J! N. H* l2nd method similar to the preceding one but more difficult to detect:
9 G. Z+ y) D/ r; X* p* n$ }4 o7 d1 E _
+ _. U" w' z" o# `# q2 Qint41handler PROC
" c) q. ~6 x, G7 d6 Z/ q mov cl,al# W, E+ y$ j# G2 L9 Z; K6 \- M
iret
4 U) e8 j3 }0 H' l" oint41handler ENDP
( W; U) F z. x
0 M. A# L" @/ r2 S% @* z! i6 V$ A% Y& k7 ^; U5 C
xor ax,ax* q/ F7 c, j5 |2 K& R( g: ?8 @
mov es,ax
9 u3 t/ b- p. u1 h- n mov bx, cs
! N3 n3 E9 @3 W# o( l- X lea dx, int41handler
F, y9 g- n [9 m& p' j; L xchg dx, es:[41h*4]
: H4 V6 l; S* }/ @9 K* H xchg bx, es:[41h*4+2]
+ p! _# N4 C4 y; p' Y) g0 g$ U in al, 40h
$ u8 S, z8 ^! q* `1 e% G1 _ xor cx,cx6 Y$ K& v4 L* ?9 S0 }# u
int 41h _% I9 D* z G, g! h/ c9 s6 p
xchg dx, es:[41h*4]8 p! z$ w/ V, V8 L
xchg bx, es:[41h*4+2]
+ j! ?" P. A; P cmp cl,al! E9 d- y! H1 L; Y' P
jnz SoftICE_detected0 s! z8 L1 }: K* v% I
# a3 _; F3 X5 Z7 H# u. J+ y_________________________________________________________________________: P1 U" Z* t S9 ^3 J
$ y9 L) v* X- f6 k4 qMethod 07
* `# y* x5 M5 f! m% |; k! Z+ j=========
+ y6 I+ I* s* P) f# o" }# q( u: Y0 X/ i- k W. Y' H
Method of detection of the WinICE handler in the int68h (V86)
J; c4 q4 ^ x3 r2 d2 E }6 ^$ H3 s" X
mov ah,43h! _& A9 s, W7 Q. M% v x
int 68h
( R% l* b$ m) V6 p/ k I) e { cmp ax,0F386h
, ^ S9 u, c: ?) J" p H3 G jz SoftICE_Detected8 \, O( }. ]) M: _4 m7 j3 i; E
9 o+ S, g4 u& {7 q: G; T# e- s$ v5 [# ?. r) N* K, E
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit& z9 i! J* B+ O
app like this:
2 }" G4 o. p9 F' `9 ^1 ?" R$ n
4 t- F; g1 H6 I$ _ BPX exec_int if ax==68
8 b" V: R# X; V# j* u, z, \: B (function called is located at byte ptr [ebp+1Dh] and client eip is
9 }6 s: s( i3 X$ r" g' j located at [ebp+48h] for 32Bit apps)
& k2 j! d* o2 Y' ]# j__________________________________________________________________________
, K8 |$ m" L# i. t: I) P3 ~3 Q) s* E: b0 U! t% r: [5 S
2 b; o: B/ Q7 E2 tMethod 08
1 b* Q: G/ M5 h$ W=========
' E, W. H( {: ~- r4 s( W$ i) O' ~
It is not a method of detection of SoftICE but a possibility to crash the
& Q7 [* {) E9 y1 t7 }system by intercepting int 01h and int 03h and redirecting them to another
7 c5 v$ ?3 x; @9 K' L: H6 ?/ Proutine.
6 w7 M5 L+ J3 b5 \7 m' o- O }7 P) rIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points/ A8 b, ]* V# Q
to the new routine to execute (hangs computer...)
0 m% n; R0 t1 c9 i3 C4 E* _- r* |* X8 E. z; p" ]. g
mov ah, 25h
. m P3 V2 L5 e4 S mov al, Int_Number (01h or 03h)
+ D2 @& q& B5 E; k' m% T mov dx, offset New_Int_Routine
- z( N7 n5 i9 K8 l3 W: f int 21h
# p" ~* j7 y Q3 }2 U* ]( G4 _( V7 e$ X/ N2 l$ Z! I
__________________________________________________________________________
& A, s( M' T ~0 g3 S* \2 D6 O* |* C
Method 09
, @! m* C3 R$ P9 v=========" Y% M. X) u7 o. y
% n+ ]" H( c4 a+ n* v
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only4 K7 N* c" m9 {9 s9 `% }& K
performed in ring0 (VxD or a ring3 app using the VxdCall)., D2 D5 ^* _+ a7 X5 K, U. F
The Get_DDB service is used to determine whether or not a VxD is installed$ e" h+ @! K! h) [+ {: r A
for the specified device and returns a Device Description Block (in ecx) for
, S/ T# l1 D& X3 uthat device if it is installed.
& r% y1 e9 W4 H9 e; c8 M' t4 q
- N/ V( z4 X& t( {5 V. l, T; ]. S mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
4 R+ m4 J( J# H% F7 C) J mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
5 m5 w# `3 x* w VMMCall Get_DDB: _. a5 f1 z3 Q: s
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed. {0 R0 R. h. I$ t% e9 P
, j# e6 c B. J! LNote as well that you can easily detect this method with SoftICE:
: {/ ]6 _) O. a" C bpx Get_DDB if ax==0202 || ax==7a5fh# H8 A! U& M* H# E9 \7 b
1 P0 l$ n2 P$ j' |1 z! ~__________________________________________________________________________
- X8 s) H: O. g5 [6 S7 e5 M
c9 |, ~. C& VMethod 108 P' }1 Q/ R1 Y. I& ]- _8 p
=========% E7 L) o& ` C3 M' q: [# x
4 ]/ @! o- H9 k1 _) f n
=>Disable or clear breakpoints before using this feature. DO NOT trace with3 \- a4 |2 R5 g+ [
SoftICE while the option is enable!!
8 Q! U3 h9 U, c- M6 ]9 q0 j7 j @8 O/ {' l6 g9 W/ R" o
This trick is very efficient:
# l$ r$ r& A7 q) Q/ k7 Y1 |by checking the Debug Registers, you can detect if SoftICE is loaded' {& y( Y: f$ ~6 U1 |5 }9 Y
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
' f0 A7 `. e, y* othere are some memory breakpoints set (dr0 to dr3) simply by reading their
3 E% E4 w, W4 f6 v# evalue (in ring0 only). Values can be manipulated and or changed as well9 H* z0 \. O a7 `
(clearing BPMs for instance) j8 ]2 ~7 x2 z' h- x0 u# y' t' M
$ I* v( ]" d3 e) m9 Y. e8 v__________________________________________________________________________
" q# S6 L% E5 N1 [" A
3 v4 l3 J$ [1 s" H; I$ `$ r2 \1 YMethod 113 O! I* j! X% E; L6 p* @/ z
=========0 ]8 l* b q5 Z) v5 C
v+ `6 q2 E* D9 H& B) f& h8 u# b) \8 m8 {
This method is most known as 'MeltICE' because it has been freely distributed
! T6 r. E; J$ R( evia www.winfiles.com. However it was first used by NuMega people to allow
/ \ ^8 ]% {) WSymbol Loader to check if SoftICE was active or not (the code is located
* w" n$ Q$ V) ]0 X1 Z% Zinside nmtrans.dll).
: @; e4 G9 P. h' z& {4 S" N+ d& |9 t2 [ Z F6 C6 Q$ e
The way it works is very simple:
. s3 `6 [/ w" I6 E6 V2 dIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
( f8 Q1 ^, X( k9 M+ w5 xWinNT) with the CreateFileA API.
1 b h8 o- `% Z
. a! O, _" S5 d4 X- ^Here is a sample (checking for 'SICE'):! o+ N: a9 A( K. r2 U; |8 l
; e9 Y) y3 f4 L4 ABOOL IsSoftIce95Loaded()
* C; a9 M: t5 g2 U5 M3 I1 h{
- y$ e& G5 \( a! ~8 U, \9 w HANDLE hFile;
f' X. s' x9 X {# | hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,, x4 z8 J/ M7 e: x( }
FILE_SHARE_READ | FILE_SHARE_WRITE,- o* h g0 B6 E2 e5 ?2 w
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);: k( h( W9 O& z
if( hFile != INVALID_HANDLE_VALUE )
6 h6 ~3 r1 v+ e9 _) f {+ n0 n$ ^* O6 G+ J
CloseHandle(hFile);0 P, K \: @$ Q2 I n& C& \
return TRUE;0 S* ]5 j( T8 A0 S& T
}
1 E% ]& H2 T! |8 r6 l5 q9 L return FALSE;
0 Z$ i0 x& T8 F; |2 v) X4 K}
2 {$ U! s* c' a( _8 d5 T4 l! V8 r
Although this trick calls the CreateFileA function, don't even expect to be
8 f V# b6 p, h9 ~9 s1 xable to intercept it by installing a IFS hook: it will not work, no way!
1 z& G8 K" K) r* I' PIn fact, after the call to CreateFileA it will get through VWIN32 0x001F' W) l {, e3 U& z- H
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)- H4 {% j1 q0 L( t. e+ ^
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
* g9 l" o+ i- i0 t. w9 Cfield.& K% i7 |, m7 h E* T% I; R
In fact, its purpose is not to load/unload VxDs but only to send a
5 \3 a. C9 k& u/ SW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)( \& u* e7 U d) x# a& @: ?! R0 g
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
( W* [/ f% `) V4 @% Dto load/unload a non-dynamically loadable driver such as SoftICE ;-).
0 h0 u# |: O1 C9 m, jIf the VxD is loaded, it will always clear eax and the Carry flag to allow
5 U9 B! d. Q! j5 [its handle to be opened and then, will be detected.$ e+ H9 ~/ k) A9 Y% O6 D
You can check that simply by hooking Winice.exe control proc entry point
' H5 k2 [4 K( c; C# ~while running MeltICE." W8 S. Y. E; p) i2 d0 U
) V3 Z0 B9 U; Q6 b7 x% I& a7 k
; S* O6 E- s2 ]1 C% ~ 00401067: push 00402025 ; \\.\SICE4 Q. c" H; x: w
0040106C: call CreateFileA- h% j5 n/ f$ ]. M8 P# G% d
00401071: cmp eax,-001
% _( f* K, g" ~, [5 U. L 00401074: je 00401091
% a& r& a4 h6 z9 s) S) [8 r, _& J, H
, ~* W7 i; ]. _$ w7 N
There could be hundreds of BPX you could use to detect this trick.
[7 U U: ]! H, k' _+ a' X-The most classical one is:/ a3 {9 I# Y5 Y! Z( ^6 ^9 T7 I; p
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
1 Q" E) b- l. c+ l2 } *(esp->4+4)=='NTIC'
$ [' n; T8 T# F( l- y- R9 r' m9 f8 S
-The most exotic ones (could be very slooooow :-(
6 X8 z8 O8 E$ A- o BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') ! k: Y( Z! d* z9 k) I3 X
;will break 3 times :-(/ w8 L9 q, L5 G) `! Q8 A
4 K% {9 l) h6 H/ M2 H* t- n-or (a bit) faster:
. V2 c' `( d2 c" U0 V: o8 P8 z) k$ u7 k BPINT 30 if (*edi=='SICE' || *edi=='SIWV')' T: d4 e9 ^7 ^' U. {% I! X" `' K
* L$ n/ R% k3 [4 p BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
. r c/ e: I! J7 E3 U' R+ M ;will break 3 times :-(
/ |4 D$ Y; T/ u1 K: \" B5 G
% d* g8 F" l/ {. _-Much faster: {! S: @% u. ]$ C
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'( w o( @' |8 ?9 Y
/ H' W; c$ A* b% i8 m! a' GNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
' `& V% m3 c/ bfunction to do the same job:* `. U8 V2 _& y8 `0 B; g
( }* u% l/ e7 i% j& ^' @
push 00 ; OF_READ, G- ~; x$ B' _
mov eax,[00656634] ; '\\.\SICE',0( R! o1 ~5 b9 _: U
push eax
* _! I4 L8 M. V3 Y call KERNEL32!_lopen6 Q+ G/ F, A% s: U2 S# d
inc eax
% O4 q$ L% N# J/ X4 T: Z: H; P jnz 00650589 ; detected
. g% Y, Q; K+ z3 I6 O" v8 m push 00 ; OF_READ
6 U3 q. Z, P4 q% R; V mov eax,[00656638] ; '\\.\SICE' X3 Y0 W' Y+ H G" ^6 ]
push eax
% {6 t" {7 _/ j3 n# o call KERNEL32!_lopen
; w+ j! J9 j5 g inc eax: @; q3 a4 `, J6 l: i# l/ f2 u3 M
jz 006505ae ; not detected
9 I/ U" m$ O4 V9 w6 i
, U) V h* y( v; _+ c. F& J& |
. r, j3 r$ T4 Z5 e( G1 q, G5 c__________________________________________________________________________# ~% U Z& l7 ]; K
* H# M7 h0 y8 @8 \: x1 O6 C
Method 12
/ K" z# V. |1 ]1 p7 f=========
6 O9 V' k* E* p1 J3 H1 M2 ]9 H0 C- J% J( V
This trick is similar to int41h/4fh Debugger installation check (code 05
4 O/ D* K6 I+ b. N- c; l( _! u. Z& 06) but very limited because it's only available for Win95/98 (not NT)
' i4 D8 a3 T/ W, F' ^, U/ das it uses the VxDCall backdoor. This detection was found in Bleem Demo./ ?+ Y+ w+ Q K$ E9 U
6 L9 _3 |# I/ x, ^ push 0000004fh ; function 4fh
3 M/ I) v0 ], }3 o- Z push 002a002ah ; high word specifies which VxD (VWIN32)
$ D, O/ S: Z, Z1 M1 [ ; low word specifies which service$ N2 @1 V. Z1 g% W
(VWIN32_Int41Dispatch)% ?7 L' j( ?' x+ U
call Kernel32!ORD_001 ; VxdCall1 q3 c, f2 A' T7 s" k
cmp ax, 0f386h ; magic number returned by system debuggers2 Q& {' y& Z2 Y# e7 s+ Q
jz SoftICE_detected
* v8 _1 T! M0 j' h3 K! ?5 H+ `! P! d. A' X; Y! J0 U" r
Here again, several ways to detect it:
1 M2 U0 O6 F9 ]/ p# v: h- A6 _
. J: \; j, Y, l- { BPINT 41 if ax==4f
% K6 @) J, k! ~9 e' Y {2 u' A, _0 ?# _9 X8 u/ W% m
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one. C/ d* Q6 l2 E5 x! k. l
8 O) }! V: ~) k% D1 R BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
' G: s5 a$ K: M0 v2 Z) N( `9 V* U
7 J* s3 p- }- v BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!$ Z! @ B/ W$ B: Y, J9 \
/ m' b, `! ^- q% g1 k__________________________________________________________________________) Z# ~6 t7 Z! ]: }# A
* C1 I+ S3 P3 S6 MMethod 13
8 a( b1 o. ] s" }9 n$ j4 [=========
M" ]* h( {, @# D0 l" q* J4 I9 k$ O9 D5 A
Not a real method of detection, but a good way to know if SoftICE is' _. Y$ h. Q: l# v
installed on a computer and to locate its installation directory.
% v7 m. p+ i4 ]& Z: zIt is used by few softs which access the following registry keys (usually #2) :% z8 J$ {9 ^- n& L
% |* b: V3 i: G7 c, C t
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion0 f" d6 @* b. p% l4 ~- o
\Uninstall\SoftICE
( n$ w/ u P j# F4 B4 q' p-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE1 n. A; v* A8 Z! a' Z2 M
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 w9 c$ b* X& I$ y- `- H
\App Paths\Loader32.Exe9 T9 c8 y3 O4 [& O2 l/ y
2 o8 g! U/ G9 @* |, ]# k3 n/ j# m1 Y3 L3 k" }1 ~% I) w
Note that some nasty apps could then erase all files from SoftICE directory
2 r" W' n, `; \( k$ P! y) T7 _(I faced that once :-(5 `. T" d! @2 q+ N$ E
( P$ G B, \4 O( P. i. ?0 LUseful breakpoint to detect it:; X8 N, { j! h2 W6 l) u( m
& Z4 V) \! A% y O; \6 a" F BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
$ Q- l( V9 G% h: \# ~( ?4 K5 t+ b/ p$ n" B- `9 d0 B! s% h6 I+ J/ f
__________________________________________________________________________5 o! L0 {6 A0 E! \5 [, s' `' B8 o' m
- O4 P1 B W9 F8 _# j. B
, B" J8 T2 y1 w2 s' f
Method 14 5 `% r' T. X/ @0 L& X% t
=========7 `* ?. M& R* l6 \" \( N
% P8 G: j! T9 W! e/ Z- a! uA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
: I: e. S, T+ N3 u! H: S1 o- [! c' sis to determines whether a debugger is running on your system (ring0 only). X. ?1 f; ?9 ?5 U
4 C u( N9 ]# Y& b" ~' t' r
VMMCall Test_Debug_Installed
$ K; {: H6 k: C K: e3 L je not_installed, f' ^) V' E" r9 i( T
1 J) x4 B7 g5 K- i$ GThis service just checks a flag.
( \, A: y/ ]& E4 f4 {</PRE></TD></TR></TBODY></TABLE> |