<TABLE width=500>8 _0 j# b9 N- n
<TBODY>
^- @+ `, o. c( Q- ~<TR>8 H8 I2 V! t7 o6 s9 O
<TD><PRE>Method 01 1 f: i8 A) F6 S/ g v1 r! e. a
=========" r0 y& x5 b" f9 `1 D& D* Y g
- P# }4 E2 |, T; ]! LThis method of detection of SoftICE (as well as the following one) is: A' W# T. r; m v, P
used by the majority of packers/encryptors found on Internet.
% a2 w) s! W) a4 }It seeks the signature of BoundsChecker in SoftICE
. y2 w' h% J* a- `% P' E/ U j
3 S1 P, G7 Q8 G3 U( y9 u7 @ mov ebp, 04243484Bh ; 'BCHK'
% K! C8 u# x2 E1 P8 M$ j mov ax, 04h
) l! A1 j% k) l9 M/ ~ int 3 / y1 z6 @! m8 ?' H
cmp al,4
* p5 B% v9 y9 g7 q0 r0 V) q jnz SoftICE_Detected
6 R: \9 R' S9 S. b' \0 _, R: R6 k$ R& H7 K$ ~& q/ L
___________________________________________________________________________
. b( Z1 z/ [% ?. U8 ^1 v8 s2 \; Q3 s- w
Method 022 x/ Z! @; W4 M, @
=========! F c, z' |: \. M* t2 u$ Q
6 m' p+ P4 M: U" I6 c% m
Still a method very much used (perhaps the most frequent one). It is used) G: q; Z- k8 R7 [- [: Y
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,( n& p* K/ a4 T. A1 O$ B4 @. l
or execute SoftICE commands...
6 ~' c+ f M2 L$ a) b' PIt is also used to crash SoftICE and to force it to execute any commands k+ L( ?! S" v9 j& ]( L
(HBOOT...) :-((
A! c4 p$ c$ ~, ?
! a+ [) Y5 U# Q" s' L3 _: V# `# ]: rHere is a quick description:$ q# ^' A% I$ G9 \; m
-AX = 0910h (Display string in SIce windows)
# {3 r7 @* w2 ^2 }& r2 ~9 [-AX = 0911h (Execute SIce commands -command is displayed is ds:dx) O2 \( ?1 d6 H f/ L* }
-AX = 0912h (Get breakpoint infos)
0 v0 N3 g5 V# c-AX = 0913h (Set Sice breakpoints)
: K! j) j7 Q! a; r-AX = 0914h (Remove SIce breakoints)6 d6 z8 |% e/ g9 L/ C+ N
2 ~: y: Y1 m6 ]
Each time you'll meet this trick, you'll see:# J9 q, d( e9 D( X0 ~
-SI = 4647h" }4 Q' K4 G( w4 q! x4 s% y
-DI = 4A4Dh& V; w6 ?+ Y& M
Which are the 'magic values' used by SoftIce.; y6 ~. g; K) p5 c0 {, K1 ?
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
6 p4 p9 d: }" b" ^6 Y: v% ]
5 X6 ^5 w0 k, E- w r, BHere is one example from the file "Haspinst.exe" which is the dongle HASP/ j: z3 w" w' i' o4 L
Envelope utility use to protect DOS applications:
# T/ O/ I H; v# R1 L% `0 @
u' n6 V. {8 T4 m2 R* g2 f5 s
/ x+ G3 z. ~ y0 \: G7 h8 @- j1 {2 A4C19:0095 MOV AX,0911 ; execute command.1 b) n7 s, m7 S% c" ?
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
3 m& n# z- C5 o. M9 X3 k: w2 Y2 O4C19:009A MOV SI,4647 ; 1st magic value.9 B% k& s3 h4 a2 G+ d
4C19:009D MOV DI,4A4D ; 2nd magic value.3 O( e3 k8 Q9 Y6 W% Y. l
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)4 V4 c0 K2 ~6 ^8 C8 n
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
- ~# @7 C; y% ~. a4C19:00A4 INC CX
8 E3 A* q3 j+ e+ H4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
7 H Q, D% j. m+ I4C19:00A8 JB 0095 ; 6 different commands.* f. {% C- w4 v ^6 O
4C19:00AA JMP 0002 ; Bad_Guy jmp back.2 V: D& [1 A/ l7 ]% h1 }
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)' t7 J W- `2 ?! F4 D
. o1 ?" V$ s0 G/ [4 p1 Q2 SThe program will execute 6 different SIce commands located at ds:dx, which
" A. T8 P) H4 U; a$ ]are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
& ^9 n* [) b' {, n- |1 |3 e6 T* e7 T& g
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
4 ~' {. n% _% y- |9 G___________________________________________________________________________1 \7 w. Z" j. X. n: s( J8 Y
/ h/ P- X, ^& E. X: k- O7 V0 P7 o& O8 ^6 W( s I: ~
Method 031 c0 {: M" {2 E( F/ i" ]: ?. c
=========4 U( q1 s; k' y9 U& m% C* @9 r) @
1 _$ |/ K+ \7 H% v _Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
$ w' y' a/ D7 g. Z# i& F& N3 x$ Q) X(API Get entry point)
6 n$ a4 x# M8 U( E. m! u
( x6 ~) U7 D1 u" j0 E) k) \9 ~2 E* _7 E% z0 m6 x U
xor di,di
: U. G2 \+ w) [4 c0 ? mov es,di! U$ ?9 h8 N* S5 a, C9 i" e) E
mov ax, 1684h + j) H8 r- M9 n3 B0 u
mov bx, 0202h ; VxD ID of winice
: o5 j: S5 E6 {% F; h4 Y4 d int 2Fh7 l& K* Z+ R/ {3 y
mov ax, es ; ES:DI -> VxD API entry point- w/ F7 C8 c3 v
add ax, di! A$ C6 e5 A- W+ S
test ax,ax" s) ?" C& W! n
jnz SoftICE_Detected
. T4 O2 {( v+ Y) M# n7 ~6 B2 Y. U; G: p! f' L3 J5 z
___________________________________________________________________________! }4 o5 y0 d9 U9 Q. h
8 V C8 r8 A; { `Method 04: |$ ?: F# ]' \9 F4 n+ W c
========= v6 r$ n) ?; h1 O7 a
1 u; t% c9 J/ B A* D& ^
Method identical to the preceding one except that it seeks the ID of SoftICE- l/ ]" \0 B' D5 o& |
GFX VxD.
( x9 k* }/ s8 w3 g& ?( U- x4 M H6 T. @. i
xor di,di
4 E( H5 p l' R. P* W0 e mov es,di
$ }3 ]9 u; G# i$ ]0 Q& Z2 f. A mov ax, 1684h ; i$ M" v7 X% K9 X8 ]% D
mov bx, 7a5Fh ; VxD ID of SIWVID
9 I6 @2 I! \6 u# I5 V& C: q/ b int 2fh
6 |' ]. k* s' L# S7 T" D: B* [ mov ax, es ; ES:DI -> VxD API entry point
4 U6 ?* p0 C+ ^3 b6 ^ add ax, di T/ P8 @ e/ \5 `1 u
test ax,ax9 m! t0 L3 w v, R1 C* e9 ^
jnz SoftICE_Detected
4 L$ P8 d+ x6 i: y( w" |% f1 z4 {- O3 {0 A* R
__________________________________________________________________________
0 s' V' ~2 Q! Z1 @. C9 K% O$ \1 U( O
l# P. t( A* F5 }Method 05
8 i Y: ~( D! L7 p/ J: L2 ~# M0 t=========2 U- w$ S/ T; j( `3 T" s" U9 l; T
: [( ]4 j: Y; S4 a/ x# r6 Z$ J
Method seeking the 'magic number' 0F386h returned (in ax) by all system1 ]/ a, |1 M% E
debugger. It calls the int 41h, function 4Fh.. Y6 j1 U, Z2 T& `9 O
There are several alternatives.
# O* ]6 f: g$ m1 Z
$ W& e/ V$ E# E& |& Q* f& xThe following one is the simplest:' }8 I1 w& c& R
, ~* a+ I. |+ E4 j
mov ax,4fh
) i: x# s' w" O int 41h* V8 ?2 y: Y; h3 h7 Q/ U0 Z
cmp ax, 0F386% I5 |3 T- ?# z/ h, f- j
jz SoftICE_detected
/ W* k* V* h/ O' N
2 x- B% j( \2 Z' c) m; z
# V% ]0 b4 J9 i. R! x* gNext method as well as the following one are 2 examples from Stone's
! }4 d8 h' w( V"stn-wid.zip" (www.cracking.net):
1 V7 @) e+ w7 R6 C# |+ t+ M' I% l/ O7 v/ L: K' c* i9 c i
mov bx, cs* [) z' N0 u2 [( X1 |, t3 s
lea dx, int41handler2
$ ~9 {! x; x* _9 Y U xchg dx, es:[41h*4]8 c: e& c4 g% ?# s# v8 k
xchg bx, es:[41h*4+2]; Y4 ?7 e* _( ?9 M3 Z
mov ax,4fh5 A: H5 W( W5 n1 {% a7 y
int 41h) g9 x( V8 l6 |
xchg dx, es:[41h*4]
, O" D9 M6 h% ], S xchg bx, es:[41h*4+2]
' N- @! X2 _& p5 q/ c' E cmp ax, 0f386h: x0 x# c4 p5 o- |' k; z9 \
jz SoftICE_detected7 v$ |! k/ Z2 R; F0 O
- O5 C, p2 ^. N8 b8 ~ t; Y
int41handler2 PROC8 p0 ~: v' j/ I3 Z- {$ D8 s& _
iret# Q" ]1 q7 y8 x. A2 V! z
int41handler2 ENDP
, B( M9 O7 K$ f' a1 y2 v, e2 V! `7 K+ p7 e
+ v9 {1 J1 f! G/ Y" b
_________________________________________________________________________
0 c8 R7 V; m( C1 K5 ]$ U& g# s) v/ h) s) L
c5 k) f' q9 s; h% |
Method 067 ?3 L/ {( C0 g
=========
6 I! F% T* ]3 i. X
/ b. r; S% D6 | _& b8 y @3 Z# ]4 Y1 t2 G( ?; z) I
2nd method similar to the preceding one but more difficult to detect:2 ]3 F) Q+ J8 s( W* y
F' C0 [3 y8 X, m
) ]/ C% q/ S5 V6 Aint41handler PROC" T' k0 u, o0 g
mov cl,al& W9 P l; h2 b& t' i( b7 t
iret
0 s! Q4 g- r" O- B. Yint41handler ENDP8 @/ u3 |( _" w) n
! Y9 ^: F7 b4 ?
$ f1 c- `- m) K% {9 F* t! g' n xor ax,ax' x) u/ Z1 j. ?+ ~
mov es,ax! n6 L8 R, `( Z
mov bx, cs, a( S# R4 w; c' [9 }/ m7 r
lea dx, int41handler y2 `5 m6 e: B, }% X
xchg dx, es:[41h*4]
" n& Q% [* Z0 t% z" L! M6 n( Z8 g xchg bx, es:[41h*4+2]9 e9 h9 M' X7 F# M) q& X
in al, 40h& q1 D1 w$ n; n p
xor cx,cx5 a) P/ ~. F; B6 c
int 41h: }( d: A9 _' t. u' I: p; a
xchg dx, es:[41h*4]
, \5 O& l/ B4 Y3 \! |; V9 ^ xchg bx, es:[41h*4+2]" w: Y8 }- J( z
cmp cl,al
# q. ?1 ~, @# ]8 h; \; I2 f jnz SoftICE_detected
' m+ Q9 T# O$ Y- v! ^ W3 e% q X5 Y+ t: q9 f5 b3 T) y9 U
_________________________________________________________________________
9 V9 b( m2 I+ z+ J7 g) t1 _$ |1 Z; f' W" F& X: i. [6 y8 H: o5 ^$ p. D
Method 07
b T& C1 L. X4 w& w$ R5 K% ^=========, H3 b; g% G T9 U
+ s$ i* ~' z- HMethod of detection of the WinICE handler in the int68h (V86)( m9 i( f- S0 |
: ]0 h$ Q& @1 b) y9 y mov ah,43h
4 e* s: U- v( M9 v' Y; Y2 H int 68h
8 {/ } v1 R2 h9 t cmp ax,0F386h
8 }9 A' A4 E. `- C jz SoftICE_Detected
9 K' ?. {" ]4 C* ]. }5 X0 U2 ?* N' G4 j2 E, q
5 Z$ I; C* k+ c7 G7 Z
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit0 o8 R7 s- ^+ M, f3 \
app like this:* u* ?& u0 j f5 N3 L0 ?
# V, P* C' [8 z! [0 ^' a; v: k
BPX exec_int if ax==68
# o0 ^+ p, d2 {$ k (function called is located at byte ptr [ebp+1Dh] and client eip is6 Y+ T# J" V1 e
located at [ebp+48h] for 32Bit apps)6 \! V- R; {# H. z0 I: N: o
__________________________________________________________________________
& t& J) Z' |- ~3 e" _- U* n& j% o& b% G, L* H
3 V. _$ G1 j: ]6 v2 x
Method 08 G2 e* r8 \- A; q, H
=========
v1 {- {' l) Q+ k/ i7 K5 C5 o3 [
- M; e: p7 E) D+ @It is not a method of detection of SoftICE but a possibility to crash the1 r; ^7 }) t0 m6 E0 l b3 X% y) C
system by intercepting int 01h and int 03h and redirecting them to another
7 g# ~% C/ r% z( {routine.
; Z+ h3 c! U' Q2 QIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points" a& I' g7 a7 s* ?0 X
to the new routine to execute (hangs computer...)$ y; L5 J6 Y& V6 X, b
. F0 y2 I# i' @: T3 h4 D
mov ah, 25h
0 [$ W0 F$ u4 v1 e3 S J) G mov al, Int_Number (01h or 03h)! H3 ~/ }0 A. y- ~! Z% ~
mov dx, offset New_Int_Routine
7 ?3 W, {0 e8 @0 M. P int 21h! G+ c) I- Q4 v: y" A6 A
! n( z" \' c* a {$ b: T__________________________________________________________________________
( n! \" U: e9 b' Q. \- p8 q0 J/ M* z- I% J3 i8 E
Method 099 ~. R. l) I' [
=========/ B8 M/ H- B, Z5 s2 v
. X. _# `2 B5 G9 ~4 D1 @* C6 X/ J6 f
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
5 N! r3 b h5 |! k* }. bperformed in ring0 (VxD or a ring3 app using the VxdCall).* _; z; s* }3 M7 s/ o
The Get_DDB service is used to determine whether or not a VxD is installed
# r% A# b, g3 Q/ \: O$ [1 d. `for the specified device and returns a Device Description Block (in ecx) for
) M+ [2 o8 e2 Wthat device if it is installed.: r3 v4 a% |7 ~+ W2 n* Y8 K
. i: E8 q2 T' F. ]" b. p
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
9 \* k5 r. o/ U/ h/ t' c7 j5 o mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
; G$ j C2 N7 C VMMCall Get_DDB# r0 X9 W- J1 R/ Z1 `% b: B& d
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
# c, u- d+ g. i9 F
! n( o4 z0 X+ P* q. Y# _" Y6 \Note as well that you can easily detect this method with SoftICE:
+ V* |& q. Z. X- | bpx Get_DDB if ax==0202 || ax==7a5fh
* q; C& U" B+ ]6 n+ N4 X' O1 y+ D% N' l
__________________________________________________________________________
, Q/ Y( b f$ d8 n% \
. K9 ~7 `2 o1 S; T" kMethod 10" {5 E8 c8 e" v; U8 @; Z- n+ R
=========
2 Y+ Z4 r* u |4 _( O4 D' T9 c, _ E" S
=>Disable or clear breakpoints before using this feature. DO NOT trace with# j( E4 A) {: c1 ]) e0 u
SoftICE while the option is enable!!
3 _% e! p2 j5 h6 V
# D' d1 d/ e( T& ?: qThis trick is very efficient:
! z7 Q: J" J& G# Aby checking the Debug Registers, you can detect if SoftICE is loaded
+ ]8 a; B0 B, E+ L% h(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if. ?; M8 h0 v* P
there are some memory breakpoints set (dr0 to dr3) simply by reading their
4 I1 N, b' M: O# Q& s* A$ dvalue (in ring0 only). Values can be manipulated and or changed as well3 P# N( c/ S4 }0 U9 l0 `0 |
(clearing BPMs for instance): q, Y- d4 G: [3 [' n- Y$ M4 @
$ V( n# _1 Z6 g, V8 X4 t8 E__________________________________________________________________________) Y, ?' u% N2 a2 B: s5 J
' K: q) K# `) J: R
Method 11& T$ o* F9 Y2 d7 P( r0 V3 `; s1 c
========= F) g( W! G0 h2 [" l
% ?' s$ R0 o6 g' ]+ }: k
This method is most known as 'MeltICE' because it has been freely distributed1 L9 e. _0 f2 r e: L% d
via www.winfiles.com. However it was first used by NuMega people to allow0 N" `/ u1 X l: B
Symbol Loader to check if SoftICE was active or not (the code is located: n8 ]7 [( Z! Q0 o6 q! Y r
inside nmtrans.dll).
* u. ?# R8 P! N6 \9 b' j" C% p! _+ Z2 E" A
The way it works is very simple:5 B$ h- N0 Z, c, {' }8 c
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for: |& H- W* Z- t) e
WinNT) with the CreateFileA API.* u1 M3 A) r+ z: A2 T2 a0 Y
% ?0 ], I1 `0 a5 f; q* u7 o
Here is a sample (checking for 'SICE'):
7 X4 `2 S2 n9 f
& t0 o. j) v3 j! C. zBOOL IsSoftIce95Loaded()
* X- D) e' A7 n* l, W, w{) b* N* ]" ]6 ^1 C8 K
HANDLE hFile;
+ M/ p: n# i8 U hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,3 y" Q4 u5 E, R- `6 \1 D) Y @
FILE_SHARE_READ | FILE_SHARE_WRITE,
' S+ r3 s! U& ~+ Y) A& e; @3 n NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
F- [$ w6 T9 v& B0 a if( hFile != INVALID_HANDLE_VALUE )
2 c7 A) o: A; \: d: D8 y {! \5 F( j5 Z* X
CloseHandle(hFile);
4 Q1 Z5 b- F+ t! S9 n8 l7 b return TRUE;
1 n$ z4 m1 S; w+ p+ o, r }
# }; I3 C" A% V9 Q return FALSE;
! e1 \* A4 q0 F/ H. D}$ S6 h; C; B% u" b# v4 A8 [1 k& q0 l
# |" {1 _" w0 ?" J* @
Although this trick calls the CreateFileA function, don't even expect to be
D! q, V$ R) y" e" U9 s9 z" i' K0 w, Bable to intercept it by installing a IFS hook: it will not work, no way!
{0 P5 `# g& G; B2 g& T' AIn fact, after the call to CreateFileA it will get through VWIN32 0x001F/ z! ]1 x, |: j. }! @9 a# W2 i
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)% X; x; G) z% ?; A8 E) H, P
and then browse the DDB list until it find the VxD and its DDB_Control_Proc/ ~9 |" p- T( C# _
field.
! [, u* t( _, w! gIn fact, its purpose is not to load/unload VxDs but only to send a
$ @1 K2 T2 F5 _3 H9 kW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
/ W& @; p) ~/ Y/ ?to the VxD Control_Dispatch proc (how the hell a shareware soft could try2 X3 y3 r6 P9 _
to load/unload a non-dynamically loadable driver such as SoftICE ;-).( L% C+ e- R a) `6 C4 D
If the VxD is loaded, it will always clear eax and the Carry flag to allow
# @1 _ }; b. [% _its handle to be opened and then, will be detected.
6 ?4 \" t9 u! J* H4 k$ c: zYou can check that simply by hooking Winice.exe control proc entry point
1 X$ S" [$ p( _+ @- u( F: r3 Jwhile running MeltICE.: A; T. c( |( Y8 R; t1 ?2 T. M5 D) b
$ {! C2 E4 O8 Q' x5 {8 p6 t& ~5 g5 H& M1 {7 L6 ~- d6 h1 |
00401067: push 00402025 ; \\.\SICE
4 c/ q9 x8 j7 N! p: S" ]8 n 0040106C: call CreateFileA- H1 F$ |3 \0 L" t7 Z3 Y
00401071: cmp eax,-001+ {9 S0 S" |4 x( W" d( ]* W
00401074: je 00401091
/ ]7 o( v8 [) u- |9 Y. f5 A0 O
5 R- R+ [; K4 }$ X5 K2 C( |0 a) E* E1 M9 P
There could be hundreds of BPX you could use to detect this trick.2 l' h7 ^, L9 T) @# M) d
-The most classical one is:
, ~; j2 l* Z6 a* k" u BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||7 R. T9 A, @5 h& v9 ~- j( Z8 d
*(esp->4+4)=='NTIC'
1 ~0 ^7 \& T N# n7 }5 Z2 W
7 U. c, b- V% J( i3 N-The most exotic ones (could be very slooooow :-(
4 Y4 h1 a& D7 M3 E0 F BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') y: {$ m9 t2 L) `
;will break 3 times :-(
1 g) O/ z: w% F
5 F1 [+ A' f; V \! p-or (a bit) faster:
p, y+ l2 g/ |6 m BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
2 O. x+ C# R/ O% `5 B
5 r3 B' x9 {5 O2 O& Z BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 9 b$ K2 Z, W( U
;will break 3 times :-(
& h* G. N6 S* G1 ?
9 ]% A/ @2 U! r1 C8 P$ K0 F5 m4 T-Much faster:
* Z4 G& f( R) G9 _# o6 D9 h BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
|' p1 P0 L1 Q- M( T3 C# Y% Z8 Z+ |& v3 L& H9 W
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
# {% l* V( b: F; Afunction to do the same job:
, d8 m+ }/ m7 ]% b1 \
+ O% T x4 A0 e* f, b push 00 ; OF_READ
! M" e( p$ X) W5 e0 i mov eax,[00656634] ; '\\.\SICE',0
, m) _( J$ W; K" q% Z3 Y5 y push eax1 V$ h' }$ ~! Y; Q# K3 ] s
call KERNEL32!_lopen! R% d" }6 z8 b/ j3 c
inc eax
# H( k2 L0 L* W1 e" W' e1 L jnz 00650589 ; detected i) ?1 V/ a0 N( B* S& [9 g* a& M
push 00 ; OF_READ
/ L% A9 {3 a$ C0 p8 j; Y& ~% U) L* s mov eax,[00656638] ; '\\.\SICE'& [# k7 Y/ D, H5 {
push eax
" b' T5 C! W3 s: W4 n0 J call KERNEL32!_lopen
9 L, a c; Y3 `9 t# o" Q* [' X inc eax6 h6 z4 b2 X" @ F
jz 006505ae ; not detected
( d7 `* c2 {* d6 k& `
; C) t( _6 ~1 f) \" @, }; x0 m0 K; ]0 H
__________________________________________________________________________2 p; H0 T0 K* j
9 t- }* H! a& v1 @1 Y' Q+ I
Method 12
& Z* K7 p) U3 }: M1 |: A8 J=========* @4 J/ X6 e |" ^& F
# G5 I! V: N) D% o6 H& f9 {% S5 XThis trick is similar to int41h/4fh Debugger installation check (code 05
4 \3 F0 c# b5 ?8 w& 06) but very limited because it's only available for Win95/98 (not NT)1 ~: u' F/ w7 G; p. Q) G2 H2 s0 Q
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
! @! v7 o6 z V6 y4 g0 S& M2 B- {3 ]
push 0000004fh ; function 4fh
% N9 l" B D' A i0 F" a push 002a002ah ; high word specifies which VxD (VWIN32)
8 h- W. ~0 e7 y1 a; Z2 L0 S ; low word specifies which service
6 T' ]5 U4 @$ f) Q4 } (VWIN32_Int41Dispatch)5 W" b! A9 R( h* b; I
call Kernel32!ORD_001 ; VxdCall( M: L4 }, c. R Z. j( O
cmp ax, 0f386h ; magic number returned by system debuggers
0 d5 G9 v7 c" z6 V& l jz SoftICE_detected1 _! U6 m! O. u, {) k6 p
+ z0 n9 ~0 {4 G- n$ Q
Here again, several ways to detect it:8 ]0 j3 S, y6 G- B% w5 w1 G+ z L
' K$ D( q1 u- }$ A) a$ t
BPINT 41 if ax==4f
/ \* w% y& _, L% {
7 ]/ L4 Q! Y9 a& I7 r# N BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
, p! V/ B A q' {% e/ N( f- A8 ]5 o1 H* U. n% h) H/ D
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
' m3 y9 Z+ d, c$ D! c0 L ~9 D0 Y: z G! ^- b
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
; |3 ^2 ?" C4 j# I( k, @4 u& }$ V7 c0 j! r9 j0 ]$ B- w
__________________________________________________________________________8 G3 C3 C" a6 ]& e# M
7 x8 f- e! T$ ?4 f
Method 13
3 D" a4 U0 P5 o* |+ e) c=========( q; C" P- ]* v# ]: s2 ^# i
5 }- a% k6 y5 V- f+ zNot a real method of detection, but a good way to know if SoftICE is0 {9 Z0 n! |, H7 k( Y5 ^( X. K4 l
installed on a computer and to locate its installation directory.6 s, T, |; Z6 e) W3 |" m3 |
It is used by few softs which access the following registry keys (usually #2) :6 ]7 h- A7 o% u$ F! J
9 q9 r1 |( l" D: y7 [, g' U3 W
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
+ H; ^# |3 ?1 {- b\Uninstall\SoftICE
6 n1 B" K! r/ v! h& u1 V/ o-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
# r9 U8 z# D6 i-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 B/ H3 O' [! c7 g5 N% |) U
\App Paths\Loader32.Exe* W" h; t2 [2 }0 T
h6 P. `0 l. u) ?- B
9 x" Z1 o; ^. J6 H; x+ L3 R; R
Note that some nasty apps could then erase all files from SoftICE directory
4 F( z, L9 ^4 G* L0 \(I faced that once :-(
5 [' T3 T) j1 j' r& J2 w ^% C4 `- c3 e' P2 |7 g
Useful breakpoint to detect it:
7 `. R# s) O9 |9 X
" y+ R" D% Q) @ BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
A0 _' _; D+ C% h$ R6 m t
2 V5 D4 S+ ~2 ?! K; ___________________________________________________________________________
( T8 _. n+ v+ i' d, g9 v& k% d4 y3 c, E- K3 J& k. U
2 A' ]/ L2 o0 o! u* M+ E9 {
Method 14
( S) Z, j1 N9 U$ n=========
9 n$ F# b' g" h7 `
1 B5 X3 K3 J; k( I9 FA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose6 b( M( ~5 f- T( Q* d- l
is to determines whether a debugger is running on your system (ring0 only).; g. l( g( f3 x5 }9 [$ p7 v8 {
/ D+ P5 s6 J w o9 ~2 f7 t) i VMMCall Test_Debug_Installed
0 ]% @- w, C/ y, r% P6 k je not_installed( u- ?7 ]& n& [0 c4 d- M
1 J6 Y5 k: K* C# rThis service just checks a flag./ w& i8 Q4 {% G+ o' G4 x/ Y2 u
</PRE></TD></TR></TBODY></TABLE> |