<TABLE width=500>! |1 c8 f. o& z% z
<TBODY>. ?; w: U- `9 N/ o, [+ v' ?
<TR>5 U+ r+ S3 [- P3 j8 {# P7 @$ l) ~
<TD><PRE>Method 01
6 \2 U# C9 o8 ?7 s=========8 w+ Q* e0 ~, Z5 ~
) |/ D! _, N+ EThis method of detection of SoftICE (as well as the following one) is: E) w8 S& T: y5 U
used by the majority of packers/encryptors found on Internet.; ]& u6 q3 |* ^2 `5 h; l7 X+ o- _
It seeks the signature of BoundsChecker in SoftICE: m# K. |/ \9 I
. O* y, x" \) J6 n5 W9 E% K
mov ebp, 04243484Bh ; 'BCHK', I8 |$ `+ R' Y5 z# @ ]
mov ax, 04h4 j0 ^9 t, |% N+ s* c' B
int 3
+ Z3 ]: \7 l3 v8 f. t2 d" W cmp al,4
+ M1 l, b5 A( w5 K0 x3 I% l jnz SoftICE_Detected( {/ H* m# L+ Y) z
. X! a/ k: t/ V0 a6 p M- v___________________________________________________________________________
6 h4 d4 \& k; `" o+ w0 J. V7 T
$ b- {& I7 _4 D1 N S$ qMethod 02) q/ \. _" }, [5 y
=========
/ u; N6 Y3 X6 l
+ e+ n# _% Y1 V7 r8 P1 D5 KStill a method very much used (perhaps the most frequent one). It is used
) q! V7 c0 O- |9 j' f( Vto get SoftICE 'Back Door commands' which gives infos on Breakpoints,3 ~: V: a# n+ W0 z" ^4 W/ L: u
or execute SoftICE commands...
% L" O! t9 O9 | |! ~3 zIt is also used to crash SoftICE and to force it to execute any commands/ o% p; }5 E4 c$ X4 y
(HBOOT...) :-(( % |. q/ M8 ^. e0 ]
9 m6 r0 J/ V1 ~( N2 cHere is a quick description:
- ?4 P7 L; t/ f( z: P-AX = 0910h (Display string in SIce windows)
/ c' W7 E) {, c: o-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
+ m2 B0 \$ Y" w3 s2 P$ m! U-AX = 0912h (Get breakpoint infos)
# Z8 B( ^) {. ]' X-AX = 0913h (Set Sice breakpoints)7 x7 d3 J( H+ j% |8 u
-AX = 0914h (Remove SIce breakoints)3 Y% R( c2 X' W# u
4 ] {, u9 e; ~; k) Y
Each time you'll meet this trick, you'll see:
' M0 e) r, h% D( E- Q5 C-SI = 4647h' H G0 o3 b/ S' n
-DI = 4A4Dh
0 g8 i8 P1 o, R& UWhich are the 'magic values' used by SoftIce.$ {- g1 o2 G8 X
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
* u( p* l! `* `5 Z' x7 Y6 u! _! x$ E/ s1 S
Here is one example from the file "Haspinst.exe" which is the dongle HASP
2 o+ n4 j$ t2 f6 ^0 CEnvelope utility use to protect DOS applications:1 a$ k4 ^8 @3 x$ Y" j
; W5 l+ W7 H8 I' ^
, o. P6 R8 [/ N9 u5 X/ O4C19:0095 MOV AX,0911 ; execute command.
. b \ d p4 @1 I0 c* t/ | O" m4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
) P' d2 J1 P: R* D3 s; E% ]4C19:009A MOV SI,4647 ; 1st magic value.9 l; w9 \* U/ } y
4C19:009D MOV DI,4A4D ; 2nd magic value.
s) @2 X7 l; [4 ^( e5 S4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
; P2 Q6 l+ }/ R/ ^" S. p9 \4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
, |+ y6 c- u$ d4C19:00A4 INC CX
- {' t6 j2 Z) T, v# U1 _, _' X5 a, Z7 Q4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
/ Y' m& [) {* _( l5 @6 s) ?& d4C19:00A8 JB 0095 ; 6 different commands.* b* n: F% b, Z- E0 W& V' C1 ?
4C19:00AA JMP 0002 ; Bad_Guy jmp back.; s# t& M# M# P: Z. k; {
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
6 S$ m" V* i9 ^4 q
% ^% p1 `0 A; V$ c/ SThe program will execute 6 different SIce commands located at ds:dx, which
5 d7 b \% }, y. |$ Hare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.& w4 W: h+ R6 w. ^, Q; _
' |, w+ X9 b: m1 S8 g; F* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.3 K6 \6 f- R- q" ^( W. v' d
___________________________________________________________________________) ~& H5 S+ U7 m/ J
& f8 I/ u- X! u$ G$ A
$ ^+ B. r2 l1 V1 yMethod 03
% a' g2 c) ^" x$ I( ^/ [5 t=========
& e. y! {/ K2 X* J: b
) ~7 P; Y# x* G' fLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h& f# Y" X" f1 o$ ~* j) m* k0 w" c& m
(API Get entry point)
8 Q1 w6 r# ]2 m7 |! u' v+ c 5 G: G' n4 f$ Z* D
" K; k' U5 A- M4 _$ P' v) @ xor di,di
, b! [3 B& R+ K6 T! J mov es,di+ {( @. p$ t' I, \; T1 l0 c
mov ax, 1684h
- n, T2 ~2 a; Y3 ^8 z+ H. [3 P8 F; g5 R mov bx, 0202h ; VxD ID of winice. f" |( S" |* R$ p
int 2Fh/ h3 k: g t" M4 V
mov ax, es ; ES:DI -> VxD API entry point, H8 o; ~8 l2 x6 \6 T g3 b. x5 l4 q1 r
add ax, di
/ G9 l5 I: A' S7 w& U5 d test ax,ax
1 y( C; [ f4 H jnz SoftICE_Detected
: f& V, @5 y' E# P: G" }" n% @) |; n5 R j! Z) z8 J6 l. s
___________________________________________________________________________( ?" {" d, Y0 a& {3 P- M2 L: K
; r: R, }( d+ X
Method 04
) F8 I- ~1 U# ]7 o=========
2 @0 s4 t1 Y6 p2 ]* T
, c. ]$ g. d- H) v" e* \Method identical to the preceding one except that it seeks the ID of SoftICE/ Z" p4 r# H( \1 |# l9 g
GFX VxD.
; Z1 A$ \5 C' q( f( u
% b) l% o& G! ^1 J, U xor di,di+ v( p/ Q: L5 c @; x
mov es,di/ z* }( u5 l; Y; c( o' _
mov ax, 1684h {( O6 B: `! h2 ]3 M4 A
mov bx, 7a5Fh ; VxD ID of SIWVID; w/ b n" [6 Z
int 2fh
: _% z# i/ U- G& y& A mov ax, es ; ES:DI -> VxD API entry point
( B/ @2 {7 i# S$ w add ax, di
: t4 F$ E* Y; D test ax,ax
6 B: t& I' |% t) c$ [! C" @! j jnz SoftICE_Detected
2 I; a: J5 v, d2 C+ E2 k; I Q, l$ S+ o
__________________________________________________________________________
3 R. S- g: I8 C
$ m! R, \3 A3 w& J8 m% N+ h# R$ y( T8 s4 s) |* b1 u
Method 057 D% O" U7 }% r* c5 O
=========
1 y3 w/ f0 k) ^+ u( @% Z5 {6 [, q; l
Method seeking the 'magic number' 0F386h returned (in ax) by all system6 H( P) |! e: C( A) H$ T* D
debugger. It calls the int 41h, function 4Fh.7 c' V+ f k1 B. l& G
There are several alternatives. * q$ D1 J7 m* Z2 e5 M. o6 _
, x% o, N0 F& m
The following one is the simplest:+ T3 `) L0 B( ?' Z# |) \8 Z2 t- v: r
7 V7 C# e; P9 J7 Y" M5 D mov ax,4fh0 }( Q) ?" S" u5 S! v" M* g! T
int 41h
( Z1 @9 I4 t- V( Z4 D) b cmp ax, 0F386
. {- K& C& m. [/ K jz SoftICE_detected
' i2 ?7 o) h. _1 d1 Q
" x6 J) m- j. d" M) H6 l: n! a/ _& J% w$ q( d" V
Next method as well as the following one are 2 examples from Stone's
2 D( C* [ c% r+ N( y2 E' t, q"stn-wid.zip" (www.cracking.net):
. U" l$ |; x: X
! B- d) e7 K' s7 [ mov bx, cs
0 G, n) p& [0 [% d lea dx, int41handler2
! O( s6 H5 R5 c! o! l7 T xchg dx, es:[41h*4]
- g" |- A s) x8 e" w/ r% a xchg bx, es:[41h*4+2]
1 M F+ e% a' @ mov ax,4fh
: s7 ]6 V# J: `+ ?: Z( \ int 41h
2 n( y8 `1 [7 L4 g% h8 Y) F8 K xchg dx, es:[41h*4]- d- i" ~4 L( ?$ j' u+ h" T6 X& y! v1 c4 y" ]
xchg bx, es:[41h*4+2]7 H1 C+ w/ J9 z6 i
cmp ax, 0f386h
" b# ^% q q' J) a jz SoftICE_detected
+ T) C( o' ?! b0 b
# T( w/ Y, V( t: m% Gint41handler2 PROC0 T. m" e! Z8 K O6 H" S! U
iret4 J! p8 D! L) K1 M9 J/ _% w
int41handler2 ENDP6 l" ?6 l0 l. l2 l' q
8 {* D+ I1 `2 n3 Q5 n& H, K3 g& S6 E# z* g. o
_________________________________________________________________________
6 }8 G& Z5 y, N7 Y* w6 {( T
& {6 j0 e# K& P5 V* t' w2 n4 D$ \7 K( S9 ~# M
Method 06" e0 ]1 \) Z: W& q
=========
" K G4 i5 J) b% M0 |- C" N- K( I7 w
/ E! v. \1 i, U, ], F. |
2nd method similar to the preceding one but more difficult to detect:5 `' e: J& e1 q! z0 N
' G+ H4 K1 W+ G) ~% a9 R: j' {, E1 C5 ~2 U- t) d' Y ~! c8 v
int41handler PROC
: {9 y: F& m0 |: U5 n. G Q mov cl,al+ j0 |' p$ u+ j
iret8 k) i8 R) D5 U$ V
int41handler ENDP
7 V2 g" ?7 |! O- z/ m, N
1 Y' s' r( J( ]4 H& k4 u: u
! W2 U/ q$ L1 t xor ax,ax6 X9 M8 v: B0 `! E" z9 ? |
mov es,ax/ T9 h) }' {& i6 U) `+ D$ _+ Q
mov bx, cs
' x+ D& J; g2 [ lea dx, int41handler+ Q$ }4 R- J. a& \& e* k
xchg dx, es:[41h*4]
8 J, ~6 v& R% L3 T- E7 V xchg bx, es:[41h*4+2]
( a5 ^2 Q1 c! R& S0 c5 p0 i5 W3 n in al, 40h
8 V* Y* u& b! K% i3 @ xor cx,cx
% ^( b! E5 @1 n int 41h; j5 Q0 c' @ _: [9 Z
xchg dx, es:[41h*4]
) H! `3 b8 J9 I0 [( {+ m) @: r xchg bx, es:[41h*4+2]
5 l! f9 p+ U8 ]( C D4 \ cmp cl,al8 Y, l i, t- ~3 c3 L: I
jnz SoftICE_detected' ]1 C( }; J% n/ g
! D' s3 O8 l, d% d
_________________________________________________________________________/ s. E7 f+ t" n' Y. C$ I
1 X2 Q) |$ c9 X# B" J7 B9 V* jMethod 07 M" a) @. M, F0 H2 Q0 ^9 T8 `. S
=========
. I$ U1 t9 `+ p$ B5 {
' V; o4 K3 Q" W+ oMethod of detection of the WinICE handler in the int68h (V86)6 m/ T/ g/ a2 u( b. F
1 L, k" V3 J! y/ U mov ah,43h1 }$ L- r t( q) q: i
int 68h6 q3 a, Z: O2 ]$ |' c7 T
cmp ax,0F386h ?7 W- w( }/ w, |; x
jz SoftICE_Detected
) u" |! [! k. R! U0 Y- L% l( P! i! g m' y. j2 Q
7 F; n. p- U3 C=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit h, f2 o- {; i. N8 R# V% n, X
app like this:6 c4 T9 v( L! k# P0 `, E" B
! j6 U7 h ?3 m1 U* u
BPX exec_int if ax==68; a; z7 _3 E# P# l% ^- C
(function called is located at byte ptr [ebp+1Dh] and client eip is1 B7 x, f) y" i3 y- \, u+ ^
located at [ebp+48h] for 32Bit apps)* d8 {/ m7 Y' Z: S
__________________________________________________________________________, N8 e4 I6 L& j3 m7 t
! D: S- p0 j/ e1 `# Y
+ p6 R& p) s, L
Method 08- X- ]) s! W8 a/ y
=========
/ R5 i% k; ?& w% A9 ~ W: f5 S
+ i* N; k/ K+ IIt is not a method of detection of SoftICE but a possibility to crash the, P: Y4 u# P$ A6 v1 c' E+ P- E
system by intercepting int 01h and int 03h and redirecting them to another, @( T+ H. z$ u R: k8 i
routine. }: @: [+ [' \0 ? z7 R T
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points2 o b0 K5 C& Y% l* W$ Z6 D6 l
to the new routine to execute (hangs computer...)
$ `8 Z4 z7 ^7 X9 T' D/ c0 B
0 J4 [0 l. e. {; P6 a& P M mov ah, 25h
8 E! P' D" ^3 k mov al, Int_Number (01h or 03h)' a7 A1 P& R; _1 ^ w& d
mov dx, offset New_Int_Routine( G3 N5 C! N6 ~" B7 ?# [
int 21h7 D6 `/ |% R1 G, b; W
1 M" `! s+ I( o( u# D6 F3 E! z2 Q__________________________________________________________________________
9 P' H1 q# E( J* T. x
! w& [% o: C- C8 J9 b. G* x# }Method 09
! t# w2 S5 g( q4 x$ Y# j, j0 Z=========
- H$ n# V) S$ d
; f! N# A" Z& rThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only+ c+ j* v2 h. X4 Y' A0 g. S( ?
performed in ring0 (VxD or a ring3 app using the VxdCall).
0 v, |# k1 c8 K; tThe Get_DDB service is used to determine whether or not a VxD is installed0 u& g: [+ O& b* _6 ?6 O
for the specified device and returns a Device Description Block (in ecx) for
4 p8 K% P" D* {$ u$ Gthat device if it is installed.
( k$ P8 [: a+ ~) K: I/ L/ S& U j" E; t* Y% z; @+ W5 I
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID5 U) s. ?7 i* A: Q2 D7 T7 T
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
7 Y" Y; n' `7 p7 |6 l; K7 m# b VMMCall Get_DDB! x8 I- D8 D8 a' L$ T o
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed* I. Q" b* Z9 E2 Y$ z
% @, l, Z/ e# M5 {
Note as well that you can easily detect this method with SoftICE:
; F" p* p- K+ q0 H; a" E' S' j bpx Get_DDB if ax==0202 || ax==7a5fh
3 `6 _! x0 A3 ]6 `
( d, @# A' q5 X8 Q! X6 ?__________________________________________________________________________/ m2 }; I# X" g* \
% r0 G! A9 l% S4 U
Method 10- u, t7 P. r9 f+ O( e3 Y! u
=========
- L! d# m' t3 c4 {: o0 @2 N
1 d' T; N+ m$ X; y( s. {=>Disable or clear breakpoints before using this feature. DO NOT trace with1 M, }+ h! I) p
SoftICE while the option is enable!!4 |8 q$ g9 T) s: |" j
; g6 N* T B9 \/ O# ~This trick is very efficient:
% X5 C5 e2 `; C3 ~3 o$ ~. R2 d' `4 Tby checking the Debug Registers, you can detect if SoftICE is loaded K! o4 r- s( T
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if, @4 R$ a& g' o8 {" k( ^
there are some memory breakpoints set (dr0 to dr3) simply by reading their
* b. K: ~6 v( \* o1 L9 kvalue (in ring0 only). Values can be manipulated and or changed as well5 P( M. [" Y1 e( R6 [
(clearing BPMs for instance)6 \; o- t/ M$ |! a
4 m+ X: | X3 M: z
__________________________________________________________________________' U0 o+ ?/ d" R7 G( D5 y/ X
$ C! B7 u6 @8 Y; ^. JMethod 11
! r$ t6 ]- o2 C6 v1 n=========& W8 u* h! p- s
$ I! @6 ]# a9 Q9 @
This method is most known as 'MeltICE' because it has been freely distributed) w. y1 [3 \ f; H+ I
via www.winfiles.com. However it was first used by NuMega people to allow/ j, d$ u3 v8 r7 i* \* E. A
Symbol Loader to check if SoftICE was active or not (the code is located
" {8 v m6 {1 `4 m( f3 l% m. L* Finside nmtrans.dll).
; O0 M) n8 a6 v" z
j5 l4 }& U4 o5 ^) ~The way it works is very simple:
1 k+ W1 K, r( c8 aIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
4 @$ E2 E& H# y- b! F1 O5 t: RWinNT) with the CreateFileA API.
/ L, W9 a3 l8 W4 X/ @6 B* T7 P
0 X/ A+ X8 O& A9 h3 @0 I" hHere is a sample (checking for 'SICE'):3 k; r h f$ P' {- E J; Q2 E
3 i0 K# ~$ z& Z2 b# `
BOOL IsSoftIce95Loaded(), r2 A4 e( `: Q1 V) k# L3 z
{& C, ]( Z+ z9 J. y3 c/ J) H* W
HANDLE hFile;
- D2 O! n) k5 j" h hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
$ U$ p9 o* P& h, x FILE_SHARE_READ | FILE_SHARE_WRITE,
3 v3 ?+ C5 x7 L5 L3 t; O NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
0 S2 N5 S8 N: L0 c if( hFile != INVALID_HANDLE_VALUE )
8 i/ B; R# U, g x. k7 V {
- p/ j% r# r @; A0 z$ \4 o \7 F' h CloseHandle(hFile);& z; Z( Z& C% C' j0 F# D0 Y! F+ G1 ]
return TRUE;
$ e* e4 R& {- c& o) Q# E }7 v( U$ o* ~. k4 U, B
return FALSE;" L, s. h1 J' W
}
' B. P4 ~3 T" Y( z3 @% t8 _( Q6 e$ b l/ O1 B
Although this trick calls the CreateFileA function, don't even expect to be
& T3 O9 @9 }$ ]+ h7 V: yable to intercept it by installing a IFS hook: it will not work, no way!
7 T. b. Z. n/ z W* F& r) `- UIn fact, after the call to CreateFileA it will get through VWIN32 0x001F6 N3 I* ?8 G! e* S4 E. g: Y
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
' M; y: @# Q! x: Fand then browse the DDB list until it find the VxD and its DDB_Control_Proc" O. T( H" d3 @% B0 {( i
field.
% U# g7 J; p) O+ XIn fact, its purpose is not to load/unload VxDs but only to send a
, Y" W/ t4 ^& N1 j: w" EW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)8 X7 X0 }, f3 y& V7 E) F6 U# u% [$ Y
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
2 [8 o" b4 H+ U2 h+ c% Vto load/unload a non-dynamically loadable driver such as SoftICE ;-).
, f) P& u3 v/ U& KIf the VxD is loaded, it will always clear eax and the Carry flag to allow! R1 r! R" Y% w
its handle to be opened and then, will be detected./ E6 g7 d1 X; ^: j3 B* ]9 u( ?
You can check that simply by hooking Winice.exe control proc entry point
$ m1 ]0 Z7 l9 Q$ H+ h. t1 wwhile running MeltICE.# k! m& ~: ^$ f0 }4 H
. N# \# q1 j" T( e3 P
7 p) I4 C! u/ D8 I6 B
00401067: push 00402025 ; \\.\SICE
1 |1 U% s3 n- l: P 0040106C: call CreateFileA
3 w6 Z: h# ]4 ?! A3 f9 h! z. x 00401071: cmp eax,-001
8 d0 f7 E4 v# Q r9 I# r 00401074: je 00401091/ i. W7 X/ j7 K) g9 W1 u
4 Q# f I( k5 E0 X
7 j1 ~3 P( m0 o+ s( r+ N% j# eThere could be hundreds of BPX you could use to detect this trick.( S2 D5 i3 k5 @7 ]
-The most classical one is:% z* v3 T3 F- _1 K
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
, p, J R' ~6 i. o2 g9 s, W *(esp->4+4)=='NTIC'
% T' M' K% {" ]7 |5 D! L% ?3 j }! B j) E; ?, q9 ]
-The most exotic ones (could be very slooooow :-(& U$ A/ Q ], ]& _( G" b( d Q
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 2 [7 l, `* f" y) W9 \6 i/ C
;will break 3 times :-(
- k) x0 u' ~4 K7 F2 I* h |# Z, N. z, P9 o* s
-or (a bit) faster: 3 |$ z$ m, K( e( G0 {& w( X
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
( E" s3 Y2 l4 S! M# a$ e, o
) p- l2 V: Z" u& U& x# d6 v, A BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' * p ^, Z ^1 V. p* Z
;will break 3 times :-(
! `, k7 t! [9 G; w/ A; y _- ~4 ~/ T8 V" y5 c! Q5 `3 J, R1 Y
-Much faster:
+ `, Z. ]& Z3 p( U: a! V6 l0 O9 [ BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV': V. F* H0 |) k d: Y# t) [
* T$ ?/ M7 _7 z9 f& q+ H; aNote also that some programs (like AZPR3.00) use de old 16-bit _lopen& D; u" i& p4 H" J& n2 h
function to do the same job:0 O) B/ ?9 Z0 y; v! P
. I8 c- F) P" f' s/ M
push 00 ; OF_READ3 i( Q; l' a6 t2 s2 Z# N% m
mov eax,[00656634] ; '\\.\SICE',0+ A) R' y/ d" b
push eax
, A& I4 ]! x* F6 P+ y. W call KERNEL32!_lopen
/ E0 C: ]/ e7 |( g1 F2 [/ I; U inc eax, D/ c. U' e) u3 s# w5 w) t- |3 l: Z
jnz 00650589 ; detected
; f9 k2 k' p1 o# m push 00 ; OF_READ1 e% @% E' j% ~$ p7 ~! z) o
mov eax,[00656638] ; '\\.\SICE') @4 v5 ?, S, l& Q& e
push eax
0 P3 R3 v' c$ u' i call KERNEL32!_lopen+ a0 C/ U$ U6 h3 @$ ?
inc eax
3 [! j( ]+ H2 U+ s/ ?4 I4 I jz 006505ae ; not detected6 r! f, Y2 Y$ l3 D# B+ g
' ?& n& \4 }+ x& S$ S5 E7 M2 e
2 y% Z% L5 n/ H6 t: F4 e7 J__________________________________________________________________________0 c( q* L! }, q9 U. c
! U0 I$ y. [* h, `; mMethod 12
/ \( V. A1 K6 O7 k0 P=========
, u" D, M, X9 G2 v3 c7 m D+ F' D8 c$ o, k1 k
This trick is similar to int41h/4fh Debugger installation check (code 05$ Z. g1 p& \) _* z& \% e0 L
& 06) but very limited because it's only available for Win95/98 (not NT)7 I& u B# F$ O, | y5 ?6 n
as it uses the VxDCall backdoor. This detection was found in Bleem Demo./ a' i! t$ C S& o! W+ W `2 e3 G) h
* _9 G: F& y% u
push 0000004fh ; function 4fh8 p9 i4 ]+ ^7 K% `* I' [/ p; J
push 002a002ah ; high word specifies which VxD (VWIN32)
6 o B0 y$ M! V ; low word specifies which service
6 M) R$ l8 T1 _, u* ?: T (VWIN32_Int41Dispatch)
: p C2 u* h$ R) s. @7 Z" a" c- w call Kernel32!ORD_001 ; VxdCall# o" K( D" N. j& t w$ @- O
cmp ax, 0f386h ; magic number returned by system debuggers
M5 b. }0 s R: i7 ` jz SoftICE_detected$ y7 h! T* i6 ~# a2 u
; s- |5 K) @. B$ {9 jHere again, several ways to detect it:
& n4 F2 x; b; A4 l3 `5 b# [4 ?% s# l( N, p' W9 \3 J: B
BPINT 41 if ax==4f2 O/ i. }$ S7 @7 y
( W* o/ W- j) Y; @" V BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
& T# q& G a7 S) V, A% _+ G. s$ A8 a c3 f8 V4 t
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
9 t; ~9 V) w: G2 U, i
9 g( Z& M9 v1 V5 j2 p/ b( n/ v BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!+ x4 e1 K( @% m& ~" i
7 ^7 ?0 p( k: I__________________________________________________________________________3 I T6 N2 G) i- Q) s2 x/ A
5 ]/ k8 D. t' L( [" o$ U
Method 13
, v+ h6 m/ A* R1 y: n3 P& f. j8 W l) y=========
6 _* W2 y! T8 o& m+ H% y1 ~4 B5 L) d( G3 O: W/ b8 d1 ~* Q
Not a real method of detection, but a good way to know if SoftICE is
& j* a* _- ]' E* p- j4 binstalled on a computer and to locate its installation directory.- Z) F5 ^ A+ p4 }! ?4 t3 m
It is used by few softs which access the following registry keys (usually #2) :
: w! k, Y E% t; p9 i; M' Z0 ?" i: |3 c0 g T7 w- D% p" o
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion: v4 I0 v+ f6 o q% O! v" |5 n1 I
\Uninstall\SoftICE
4 ?1 A. L9 S* |3 t2 ~3 V: N-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE9 p0 \6 Z2 M- P) j0 @0 W5 t
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion" Z4 E; S- b3 Z6 a6 W P+ M* L: L
\App Paths\Loader32.Exe2 U- I! r& D! k( T6 O
$ y% n# m7 { q/ |$ i# l
8 @4 R3 X( s8 y Q4 C' ENote that some nasty apps could then erase all files from SoftICE directory
3 W' ~7 ?+ A: c7 s, [(I faced that once :-(
3 o! g! }; T# ?8 ?: [! f) D
9 Z8 P7 v" x; |) p8 V7 SUseful breakpoint to detect it:
- Z# J( M) z1 J$ y% v( |5 A" a! V/ L0 g
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE', m2 b4 q! L, Y
' b* u8 `: g ]0 ]$ d, B r__________________________________________________________________________; N g9 ~: N, k6 k; T/ L* z! T! Q
! }* R+ f2 R) s b( L% R
* X) } x6 Z; ]
Method 14 $ g$ l# v' q9 L, t3 \* C
=========
. A# S, {: x, ?, O6 t; m) J3 ^
% o/ q; `) ?/ E( LA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
. D* e o" i+ M! r% M6 s8 {9 dis to determines whether a debugger is running on your system (ring0 only).) @1 {6 K/ s' N" ^
4 _+ l: ^9 K+ {" X VMMCall Test_Debug_Installed/ F1 A; R: _5 t1 \, Z$ v% H, E0 w
je not_installed7 G, F/ B, g+ h/ E
$ m# R5 y0 g. M2 Z K+ BThis service just checks a flag.8 f2 w, M* J# g0 Z2 Y& S
</PRE></TD></TR></TBODY></TABLE> |