<TABLE width=500>- i. ~! ~1 v1 j5 v
<TBODY>/ _% ~) H4 M& F( I* k1 S
<TR>% P1 k+ X' y R8 T/ G
<TD><PRE>Method 01
9 D- X/ \. L8 J: m c8 _) V! g=========6 i6 z1 n9 ]6 {" }0 i2 x; b/ A9 m
7 J- D7 ~+ B; H# M7 t
This method of detection of SoftICE (as well as the following one) is
% u9 Y! W4 ~# a+ t: lused by the majority of packers/encryptors found on Internet.* ]7 ]! s. E. H. t# l
It seeks the signature of BoundsChecker in SoftICE: F3 M3 l/ C/ e% Q9 @9 m. i
' [- N+ L2 s/ o4 Y" S/ A mov ebp, 04243484Bh ; 'BCHK'- J/ M0 O3 i H) X8 T" m
mov ax, 04h
: Z/ ]! x% T' K' v2 P4 S1 } int 3 9 O# U+ G0 b! v7 [7 e7 e1 ?
cmp al,4. \8 n0 _: n- q
jnz SoftICE_Detected
/ J f1 m( n% g% Y, E0 `, ]' I. ^5 K& w6 z
___________________________________________________________________________
& C1 {/ {+ l3 v7 g, P
( @+ O3 {, Y+ S( jMethod 02
0 M5 A$ Y$ P& o" J6 \$ `=========: p& M: l* b& p1 C% O' k
) J# l, ~) V4 h/ X, O) I% j, W
Still a method very much used (perhaps the most frequent one). It is used" {5 R2 C+ S/ [! n7 j
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
) S: v7 q6 ]8 d- L: [* J; \or execute SoftICE commands...4 E i1 y, E* t. V
It is also used to crash SoftICE and to force it to execute any commands
% M8 R9 W1 V/ f6 B1 |& _(HBOOT...) :-((
3 m( Z z( h) d$ f: |+ P1 A2 q
! `. i- v$ }' P7 Q' vHere is a quick description:
5 q( @; P6 [/ J1 D3 x-AX = 0910h (Display string in SIce windows)7 q, Q+ j, k5 i8 L7 c$ b1 v$ r: }
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
% j0 P) w( _$ |; R3 e, `-AX = 0912h (Get breakpoint infos)/ ?7 v% t3 n5 f- J
-AX = 0913h (Set Sice breakpoints)
4 q6 r2 Y' Y# ~8 O-AX = 0914h (Remove SIce breakoints)
d6 u* J( r+ v) A5 x7 j6 K5 s. u/ \" A) `8 W/ K
Each time you'll meet this trick, you'll see:( `4 ]! C7 d7 V Y& ]- P2 `% m) e
-SI = 4647h
; y* \- N- R% h-DI = 4A4Dh
+ ~: K- d: g& @2 S( k7 H% |. JWhich are the 'magic values' used by SoftIce.. H) |1 X3 v& ~ o y# G7 G9 X
For more informations, see "Ralf Brown Interrupt list" chapter int 03h. A- E h |4 b6 O' P2 z
3 h( z- o& o* l/ IHere is one example from the file "Haspinst.exe" which is the dongle HASP" R( \- R& E% ^( l7 r$ D
Envelope utility use to protect DOS applications:
$ G! h; s( C7 O) w. p6 W! y. ?/ u4 z9 D2 |5 X
4 N3 w2 Y; E7 ?% N
4C19:0095 MOV AX,0911 ; execute command.; ?0 V( O4 u* C
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).; X/ ~; U9 i, u1 c
4C19:009A MOV SI,4647 ; 1st magic value.! h1 a0 R% X% b! V' z
4C19:009D MOV DI,4A4D ; 2nd magic value./ V8 Q* V2 l9 P# R/ j* D9 U; c, S
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)# n- l7 b# J3 t% ]" P
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute n g0 O1 M1 k% Z
4C19:00A4 INC CX) _ G) i' E- ~
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute: p4 S/ g. @1 i
4C19:00A8 JB 0095 ; 6 different commands.
$ O# @ Z4 o+ U! Q q4 ~0 U; e4 q2 L& ~4C19:00AA JMP 0002 ; Bad_Guy jmp back.( S+ g1 v; ^% t# c" K
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
+ ?6 }4 ?. n: z
& A8 {# i" H) q) s# v- eThe program will execute 6 different SIce commands located at ds:dx, which
p; j4 j$ e, Xare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
, ]; J% @3 V9 k8 E/ W/ J, J
4 p8 m% b$ O Z/ B1 z. m, R* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
; K5 v% Q" E. r% W6 D___________________________________________________________________________
7 ]4 l' ], m: t8 E$ \( V' A: t' I) k- `9 z8 j
$ J6 Z7 B1 c" T9 Z- v
Method 03
) r; g5 G8 m1 v" e' h=========
; Y1 u% i& z" E& o' v( c7 L" H+ Q$ o, E" s$ j( s0 I! I# C9 j6 C- N4 Y
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
& t# y; O+ x3 T; |; K9 X5 n(API Get entry point)
6 C0 W b0 t9 f( p - D- ]" s, W) E& E. A1 J2 S
5 H7 o- v0 v! q3 S* h9 O
xor di,di
7 T& n2 {( _( @, _ mov es,di' T" x* M9 ?/ U4 u
mov ax, 1684h , s7 ]2 _" K3 Z" h4 R
mov bx, 0202h ; VxD ID of winice
( }+ u# b3 ] @# _/ C1 m3 t9 X int 2Fh$ d+ W7 p* q9 f* s. ?7 F1 d. ?
mov ax, es ; ES:DI -> VxD API entry point1 M" q' y3 p7 H6 M/ u
add ax, di9 Y2 N1 v* w6 E, \3 T& W. U7 a
test ax,ax
: O6 d& ~5 o& s& d jnz SoftICE_Detected
; j* j3 Y* u p
/ s6 T+ v5 G0 A K4 I/ E___________________________________________________________________________1 e5 a4 @4 `6 e: h4 r4 V; V3 P, q' r
6 W8 I% q5 \" C6 J9 _
Method 04$ c, Y; T/ b' b! I* g! v
=========
/ f$ _2 v2 r! s" X& y8 e5 `3 f' s6 _ i; Z" }
Method identical to the preceding one except that it seeks the ID of SoftICE+ [! d/ J. P. U! k( r" a: Z: ~
GFX VxD.$ i# s! N1 o0 n( H/ m
1 ]+ [ N0 C' t& @# n0 e xor di,di
0 R: l$ D- ~ U4 L8 d- o: U mov es,di
) \4 S; W) c) C6 I mov ax, 1684h
6 X9 h: \* h& L' @ mov bx, 7a5Fh ; VxD ID of SIWVID
n! h9 p3 ^5 P( E$ u6 t3 Y int 2fh
1 {0 M& ]( d* [' O' s mov ax, es ; ES:DI -> VxD API entry point
) F$ T7 p& I- t- \& y add ax, di
' C1 J! O' G+ p) \' \" } test ax,ax6 L4 S% T, c1 ^. {+ o' m- E
jnz SoftICE_Detected
' ^: X' O7 q/ W) ^. Y1 _ i/ _! e
7 s) c' ?: r3 B* w3 G! y__________________________________________________________________________. I+ i" Q! w& n& B0 e+ @* [# @
6 ~" i0 g+ N- D' P/ }
0 l5 Z/ S$ R+ A( q6 p7 ~
Method 05
& N/ }$ s4 d# C* A! j q! p0 o' K8 O9 ^=========: |" \7 |6 b4 S$ S
6 P* K# v- K& X6 c1 }$ IMethod seeking the 'magic number' 0F386h returned (in ax) by all system9 R& L6 u2 L" U# s
debugger. It calls the int 41h, function 4Fh.
* c" Y3 r% B Y2 k9 R2 i+ CThere are several alternatives.
* B! r3 R. @9 B6 ]4 X* c- x, k F' I& M3 T
The following one is the simplest:
0 ?* K2 l" W6 W2 ?# T$ f# n4 Y$ h! l! |: E8 N; }3 B. x! ]) b7 z
mov ax,4fh
! _2 W0 \% v2 E5 z8 f0 ~ j int 41h
2 p X2 p! W5 D# } cmp ax, 0F386# T* B) p* L' y* J0 i, l
jz SoftICE_detected7 A8 J+ o; R) ?/ e, @" c( A
9 G9 J1 S4 X1 U8 \* z6 j
2 c" H* i" ^* }; E2 b0 i) c& m
Next method as well as the following one are 2 examples from Stone's / s- y) `' h( q
"stn-wid.zip" (www.cracking.net):- V Q% a5 h! z4 v* x8 J
8 B, j& F! V* i, t
mov bx, cs( `( ?6 ^) y* y7 O2 Q
lea dx, int41handler2( y! M( C* i! }: ?1 C3 U/ I- H: E
xchg dx, es:[41h*4]4 A+ \$ o+ S# Z E/ F. B5 X0 t
xchg bx, es:[41h*4+2]0 W+ ~2 l$ m/ e. c
mov ax,4fh
" p/ h; }6 v2 @0 ] int 41h
$ x; p s' j t- C' s6 n xchg dx, es:[41h*4]
W# u" J$ {. [+ q6 n: N m xchg bx, es:[41h*4+2]3 B8 t- f# }* J+ U- F G
cmp ax, 0f386h
J1 V/ @# g9 ~. V# K jz SoftICE_detected
" `( V# D' u: P9 C, O( G
9 j+ g! S6 w: u9 _2 j; Xint41handler2 PROC4 ]* \ l) `/ u; b% o8 V% Z+ c. [. w
iret; b8 H6 T2 t( q
int41handler2 ENDP& m1 K9 r2 i! j* T
. U$ e, p4 n/ s m- a+ [/ E" q
. J4 }2 b3 M9 l! o- o6 w7 G6 E_________________________________________________________________________* z3 P" i- b( t/ m( h$ c4 e
3 L1 A" a2 e: N& ?2 \1 }
. Z7 N1 u1 g! P$ h# O
Method 06
" i9 d9 Q0 y* ?3 ]=========4 g5 [: y! G" A8 i& W6 @. u
& s3 b+ w" W4 |1 w
3 R8 W, A( I) @9 Y1 r+ _; [2nd method similar to the preceding one but more difficult to detect:5 a6 T# [( ^6 w5 y5 z- l
0 Q% D7 d0 ?6 U$ u: P" z& E3 I
" u' u! ~3 R$ ]0 E5 N- Tint41handler PROC
( ?8 e# }' A" D0 V5 v mov cl,al# C7 B9 ]! a1 m( X2 c I
iret! m' J% G0 {) R R ^# n5 g* B
int41handler ENDP
" s# s! J: E/ n1 ~8 Q
6 J9 R0 ]2 |1 e* @
4 I- Q i; J5 {' T! D- h' p) F xor ax,ax
! {+ S }# g" G8 V mov es,ax( f$ M& o& X% p+ M ~! U4 G
mov bx, cs
2 V' B* n4 m/ C' ? lea dx, int41handler! S" o$ N. f+ A/ I6 A! E
xchg dx, es:[41h*4]+ M9 ~; V; C9 D* o, N9 {" C# [
xchg bx, es:[41h*4+2]
: Z4 M) \! |) s' a. c" p2 s9 M in al, 40h
" t% K+ w+ e, b% W xor cx,cx: g# l0 f6 Q7 s' J$ C1 c5 W9 N
int 41h1 h* n. W7 g( R. M
xchg dx, es:[41h*4]
" V# ^, O% S3 ^4 Y9 w' L7 J xchg bx, es:[41h*4+2]/ A6 g, m, @5 ~. o' C4 L4 U
cmp cl,al$ {+ S% X0 w+ z7 T% h' ]3 o* O; M( ^
jnz SoftICE_detected
% Z" }" d( K) ?. ] p# j2 h- }; K1 i; D7 k- ^
_________________________________________________________________________+ p. J) A- W6 D" E0 q
5 y. c! s' i: w/ S
Method 071 e/ Q9 Q: |# R: n
=========" r9 s% ]8 a) Y
, \8 v2 t8 X( `. ]
Method of detection of the WinICE handler in the int68h (V86)
2 M: y! ]& C) t1 [; v u/ W$ _( a* k6 S
mov ah,43h
1 d# {5 J3 C; f4 L3 ?8 ~" M int 68h* C8 D4 o4 x0 Q$ l
cmp ax,0F386h# g, t, Q+ n- a. P7 o% I
jz SoftICE_Detected- ~9 l% [! C9 K( F) Z) ~# L
6 w( A# m# c0 m4 I6 S3 C7 m- d" R0 x* C) w
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit& x* c& g: w. A6 G- [9 w
app like this:9 b# g# v7 b9 G
+ i0 t0 p O0 t* I2 u1 h# y BPX exec_int if ax==68
+ h2 A+ e7 V7 Y& w: u5 E (function called is located at byte ptr [ebp+1Dh] and client eip is" Z# Q* p% Y/ G, m4 V3 Q! o; O
located at [ebp+48h] for 32Bit apps)
) B" _7 U/ Q% C__________________________________________________________________________
/ J0 A# f# P; C1 j0 y+ w! V( S5 n
4 `" p! b( E( l; F
Method 08
# R! P" o5 \/ L5 i/ r. Y z=========0 w: C4 h3 i; w
7 c- G0 P, ^. F* C/ P: Q
It is not a method of detection of SoftICE but a possibility to crash the
8 O- _- T0 |; _9 i# u0 `3 jsystem by intercepting int 01h and int 03h and redirecting them to another8 O1 r; O n# u
routine.
2 w& i. v* \1 |It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points( l: T' k3 L! A% N. e& z
to the new routine to execute (hangs computer...)
- l- }) t1 U* V- c+ F( k7 j, T6 A' x6 o
mov ah, 25h7 t- Q3 w/ Z! W6 a. m8 |
mov al, Int_Number (01h or 03h)# m3 U) b6 I7 z1 d3 K
mov dx, offset New_Int_Routine
4 ~7 y: q! R8 v; E3 e2 u int 21h
/ a+ V4 b# g3 S, H$ B% y8 Z. f1 } ^9 r7 K$ @9 Z
__________________________________________________________________________
" P& Q \0 s$ {9 W- Y3 y) z
! e8 x/ I7 m7 RMethod 09/ g% z* k2 B" k, W0 h- Q+ x0 N7 M
=========
& |, g+ v' o. P: z' |& b+ P- _& \# i" j2 K( H- f. F7 J; i- p
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
& @' _' u5 p8 Y$ R3 z- w9 u3 P+ Rperformed in ring0 (VxD or a ring3 app using the VxdCall).
; C# v9 @/ B+ U2 w% WThe Get_DDB service is used to determine whether or not a VxD is installed
J7 r6 g6 K b# Z, g; \for the specified device and returns a Device Description Block (in ecx) for3 n, S4 [, e @; S6 W
that device if it is installed.
* u# q, t8 `: Z7 g1 h# [
8 M: h7 Y: {0 U, m. T ?) h mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID1 [, ?+ I6 m$ t7 l* I" r
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
, D2 f- @' g8 @4 p/ u% u VMMCall Get_DDB
5 t8 }3 E. m+ f$ ? mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
8 ]( Q. t7 g1 k5 F
( a* z9 `( t' SNote as well that you can easily detect this method with SoftICE:0 k' Y1 h* t4 H" D. T
bpx Get_DDB if ax==0202 || ax==7a5fh# f" l+ v; W: E. Q
- w/ u2 a1 l" [ e9 W
__________________________________________________________________________
. A0 b6 E. k3 v5 q1 `# x4 ?, Q; p( I% U+ ]. A
Method 10- {) D: n. f* @" p `
=========
9 E, R2 `# ~, ?3 @0 B- F8 L0 s% S# I
=>Disable or clear breakpoints before using this feature. DO NOT trace with9 L8 P. N( O& N) z: G7 E
SoftICE while the option is enable!!2 L% W6 b. q# B+ r; {
$ [+ W* \) ?) H! b7 x
This trick is very efficient:
" Z6 P' t9 T9 z; ?1 B+ A$ y3 Hby checking the Debug Registers, you can detect if SoftICE is loaded# }% O5 a7 i8 F |! X
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
, A1 ^5 x$ n% L2 Athere are some memory breakpoints set (dr0 to dr3) simply by reading their
8 R0 y# r9 J8 T% O% G. { mvalue (in ring0 only). Values can be manipulated and or changed as well
4 [' j, x4 N9 V+ v& J s(clearing BPMs for instance)' R& j* i3 t. A/ ~( Q: p8 @& m
; B" ], p4 u9 E" O7 V__________________________________________________________________________3 y/ }" o# V6 ?4 x! O7 S# r
" A9 ~( k& n x$ lMethod 119 Z$ H& m; g% {2 v" h h4 U
=========7 G2 n* O, W+ S0 h' F- o8 o
2 I4 d3 ` _% u' \6 |This method is most known as 'MeltICE' because it has been freely distributed# K: }! T/ y7 t
via www.winfiles.com. However it was first used by NuMega people to allow
+ h& k2 J: D9 Q. t8 ?9 N4 rSymbol Loader to check if SoftICE was active or not (the code is located
" V( {8 ]. ^$ J' f1 X' r7 Winside nmtrans.dll).6 d8 x7 K5 ?5 n- w
+ b3 T6 ?( y* S+ ^- d; hThe way it works is very simple:
% O% S0 l' ]. p/ F- ^9 k0 \It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for; c- R3 b9 d, R+ r8 e% L
WinNT) with the CreateFileA API.
$ j# S9 W3 \2 \, U* F1 W' F. h7 M8 c" `: }
, D7 K' c; [- h5 p- OHere is a sample (checking for 'SICE'):" W# H) E8 O$ f* {& A/ X2 T) O
7 `2 ~+ W# o! w( X. J2 W, @
BOOL IsSoftIce95Loaded()
) }* A7 M- A$ n1 B2 O! o5 F+ M' e( W{
! \0 a$ t( J, t3 C: Z, F9 q HANDLE hFile;
7 d& r% r! N: `# G/ r1 H( x hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
1 P+ r3 n. ~% q FILE_SHARE_READ | FILE_SHARE_WRITE,
! D$ Q! C! F% [+ l' @: ~( p NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
0 q7 [: N+ I# f M6 `2 a. g if( hFile != INVALID_HANDLE_VALUE )3 k7 r* j! b2 ~$ i( q; C
{1 ~* `4 x6 \5 t" p( F& d6 F9 F+ v
CloseHandle(hFile);
9 l1 r. `1 e3 k/ g7 u' C6 H6 @2 o' f T return TRUE;
* w. U/ G! p9 ~0 H7 v+ x" n" H, A" u }
- [: P9 N4 R6 u) M2 ]# p return FALSE;
1 A! h. K. l) O9 d( s}$ H2 @9 |0 H% U) {0 t* R! \
* h7 i! A% B0 Z% y
Although this trick calls the CreateFileA function, don't even expect to be
/ x2 e6 [- f. ?3 z# Bable to intercept it by installing a IFS hook: it will not work, no way!$ [/ i' i; d+ P' [3 U
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
1 U- S; u7 G& y. W4 oservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
- P0 Y& m6 c4 s7 r, m5 C1 s) ?and then browse the DDB list until it find the VxD and its DDB_Control_Proc' ~. q5 {- h5 k8 g1 M! \& g! N$ ~
field.
5 q% Y0 [. U2 Y* e9 EIn fact, its purpose is not to load/unload VxDs but only to send a 9 p1 H' @& H& v
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)+ `, w4 V8 ]! x c& g
to the VxD Control_Dispatch proc (how the hell a shareware soft could try4 y" F6 L& [& c
to load/unload a non-dynamically loadable driver such as SoftICE ;-).8 G/ h- |% _" J" ]! Q$ E- }: N& o
If the VxD is loaded, it will always clear eax and the Carry flag to allow
) a a# D4 O0 j( Lits handle to be opened and then, will be detected.0 V, g/ \) S' q3 j4 \$ \
You can check that simply by hooking Winice.exe control proc entry point
. R" _ s* v- _* C3 Bwhile running MeltICE.
: Z8 x7 x4 X& N4 j. n) ~ q
; a/ o0 ~+ N6 A+ ]7 y8 X/ @- ]+ m3 o* T! ^6 r
00401067: push 00402025 ; \\.\SICE
! P2 [9 [$ a u: w( j 0040106C: call CreateFileA
0 F7 |$ Y; }3 i8 W. a" a" m- N _ 00401071: cmp eax,-001
* ^! }1 I3 A4 B6 h9 g 00401074: je 00401091# C5 c j# a- E0 }
2 J9 a+ R4 k7 i4 _; s6 v+ Y
/ n" b# p9 v$ V \7 X2 MThere could be hundreds of BPX you could use to detect this trick.
% }% u. E# s# V+ i8 f$ R0 t7 z" \-The most classical one is:/ t7 k+ T* b- u
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||; a+ a9 u8 d5 a, {& s* _% |
*(esp->4+4)=='NTIC'
3 @/ F, j4 `+ u/ o1 d* X
( b# n' N; ]/ e-The most exotic ones (could be very slooooow :-(
$ c2 K& ^) z* n9 r% [; O BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 2 ]- i" e8 n% Y
;will break 3 times :-(
* `# C" c0 N: N$ H0 v& Z7 n2 ^; G- C4 e$ [8 H" J
-or (a bit) faster:
* m* H9 ?+ A6 `7 {4 D BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
# S# w8 M j+ ~/ m. O. O
8 G! y d5 N1 }* N2 v2 z' L- W- P BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 0 h. y( C: ` h$ n0 t t
;will break 3 times :-(
3 W% n4 B% v& w; d$ ]' \" A
9 ~2 [ d6 e& W8 w-Much faster:
" S, g, r5 R: g! \0 y BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
& {9 ]+ D3 M: z) Y& q D' T j1 g' {) l
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen1 l1 {9 H% m& m7 u! }& ^3 q
function to do the same job:6 _) h" R1 {! ?
1 _/ f9 f* E7 H( R' o push 00 ; OF_READ$ R3 ]/ c9 ?2 l! j
mov eax,[00656634] ; '\\.\SICE',01 p0 x6 F1 d' {" K2 e8 ~: A9 R9 o
push eax
- `. ]$ D) x+ V: J' B( d call KERNEL32!_lopen
M% k2 L) e1 ^5 u. K# X" @) Z inc eax# ?% h' k# M+ Q/ N. t
jnz 00650589 ; detected
. l% p+ |3 I' M- A, b push 00 ; OF_READ! h- O# s6 U1 q) t, I& ^: J
mov eax,[00656638] ; '\\.\SICE'
3 X& h& a# \; X' m8 P) ~ push eax3 p0 U7 B3 V& N" O8 Y; P
call KERNEL32!_lopen
( l% z: l! O5 k inc eax
7 O. O; t2 _8 I q& U9 l) ~ jz 006505ae ; not detected- @' g7 E% V( O& k0 W
) Z& d. m. X4 z1 ]
" V- o4 P! e, Q; |* P__________________________________________________________________________6 j. [/ D# V- \6 [, O1 K6 e" W
3 I& W9 Y8 Z5 p! g: I) ^
Method 12( i5 b0 N' z) n% Q* A: y; m# J: p
=========
( { Q3 z4 x! ]9 m# T! [: I" g9 m: h8 z* L
This trick is similar to int41h/4fh Debugger installation check (code 05
7 A" L, U# h! ^: B2 z& 06) but very limited because it's only available for Win95/98 (not NT)
( M4 }8 e0 ^) O. q q( @. qas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
. r! d* t2 @4 [) o+ T# q/ R! o- v
# m4 v i) v, z q push 0000004fh ; function 4fh
: }. e) a( z: F) w! o( n4 ^ push 002a002ah ; high word specifies which VxD (VWIN32)
, @1 \) C0 b, [( @: ^. L6 p6 R ; low word specifies which service, ?6 U" y: R7 c6 @3 u% B( z( T
(VWIN32_Int41Dispatch)
: y0 z4 m0 t8 Q. F1 o5 `. m7 F call Kernel32!ORD_001 ; VxdCall' w0 T" n2 W6 q3 t1 n/ J0 |
cmp ax, 0f386h ; magic number returned by system debuggers/ E1 p, J! F! Y, i1 c/ |* R0 c
jz SoftICE_detected6 z- T1 [. e/ r! b8 h+ Z
: ]3 l' O6 l4 U7 M& tHere again, several ways to detect it:: ]; E! ^9 s, D0 C* {
4 d, C1 r0 q/ g, i5 {* B- e
BPINT 41 if ax==4f$ S: [+ W1 W' [! @2 ~
8 D* t4 r0 v2 l BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
1 [9 G+ X) l4 w! g% P- S/ P3 w& Q( G6 s5 |/ S
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
$ e4 T% h! Q! G& G6 U I8 v5 L/ W ~, I% F
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
# l6 V0 h @, y. u( t! w& I' j6 t6 a) o4 K0 s" W' R% h. A3 d4 Q1 m! J
__________________________________________________________________________
. k( e9 G1 m$ d3 @
) L$ N" J/ R/ ]) f o( C" u& @3 uMethod 137 g+ k1 e8 L) s g
=========
2 W1 B7 a9 ~: P; ~" a
t) S7 } i1 e" gNot a real method of detection, but a good way to know if SoftICE is
: u: I+ Z. w* ?, N" f7 Ginstalled on a computer and to locate its installation directory.* r$ ]( a0 m2 V4 w$ q
It is used by few softs which access the following registry keys (usually #2) :/ O5 i0 ]$ r6 g" Z) f; d( z+ a+ A
; K( B7 F. a2 ~9 {
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
3 S+ p* K5 w* f\Uninstall\SoftICE
( k. K+ P8 x; r$ f$ {6 f-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE8 ~# @; ^9 H% {# _5 G9 B
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion" {$ F( i" H- |1 n4 }2 l
\App Paths\Loader32.Exe
& X1 X) y6 {/ u5 d. Y! E1 s3 o
; }* o( o7 i) |% T+ i
0 A5 R4 q9 ?; CNote that some nasty apps could then erase all files from SoftICE directory
9 X- v$ K# f& t/ D0 O2 j9 c4 @(I faced that once :-(
. `# e5 D' P5 y! b( d& `
3 v7 A' x: f% S1 @7 Z2 |0 A& G: kUseful breakpoint to detect it:
2 }8 e5 k, `2 H5 }- J
. p4 v* A' v" I Y* _ BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE' ]9 W9 b0 k7 ~+ v3 B4 S
% I% X9 C( S% U, {5 x__________________________________________________________________________
+ Q6 `. f1 l4 L
; z1 E. W' ^6 g0 z& m& D% C3 D6 L% E! B+ L$ m* ^
Method 14 q! \: D# \ O7 ]
=========4 v( W, t0 f. A0 V2 E7 ?; F7 h
0 M" E) t# \' S. ?
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
, o' M% H U( f% i/ iis to determines whether a debugger is running on your system (ring0 only).
: \7 R) G+ \" D7 A9 ^6 u5 p$ A$ m' B: s' @4 H" K: s
VMMCall Test_Debug_Installed9 a- F6 g5 q# h$ j, [! s
je not_installed
+ h# C, @: J3 y9 l; y
- c( i+ E) _( N, [ L! G0 s1 {3 A @This service just checks a flag.3 i9 s! l/ j5 P5 \5 u
</PRE></TD></TR></TBODY></TABLE> |