<TABLE width=500>
9 K J- H1 H; _<TBODY>' r2 l; Q9 |, s8 C5 P' H
<TR>
$ v- R7 z, p* u0 o<TD><PRE>Method 01 / N; C5 R+ h0 c
=========8 O! n) [- ~7 }
. R; k( \# B: K5 P0 @
This method of detection of SoftICE (as well as the following one) is
; q: T5 c& e, h3 u: ?used by the majority of packers/encryptors found on Internet.
( L; J( P, l7 s( p* LIt seeks the signature of BoundsChecker in SoftICE
' t. T- }( G q- P- e( F# T
8 y+ h" t ^; e" q2 B mov ebp, 04243484Bh ; 'BCHK'0 B7 r/ P9 x& M. ]7 r4 ?- i' \
mov ax, 04h
3 q" {& S/ `- M* z int 3 $ o4 o4 \) w# ~4 x! c O1 ]. n
cmp al,4( D+ d6 a; r' Z# \
jnz SoftICE_Detected; ] M6 I6 K \/ z
5 }8 y; t# d ^& |___________________________________________________________________________
* H6 H$ Z0 z! L! n5 |1 t- Q% |/ f) J1 J3 n. ?# h, l8 _* Z
Method 025 _( O* `# u" H/ E- F
=========
$ q/ T2 N0 f$ q! V
z" y2 B6 B m2 @Still a method very much used (perhaps the most frequent one). It is used0 |( @3 J+ {! [4 A( Z: p2 G6 b; W
to get SoftICE 'Back Door commands' which gives infos on Breakpoints," \+ e; S2 G' E
or execute SoftICE commands...2 z& s+ L. m0 y5 y
It is also used to crash SoftICE and to force it to execute any commands
3 m' M3 W& r! f1 l7 ]8 z(HBOOT...) :-((
; |* i6 _) q$ m6 @+ k* S; Z" t [# @! R+ G
Here is a quick description:1 m. ]- C$ O9 q% b& U, l1 r
-AX = 0910h (Display string in SIce windows)
& P, A; G- P' B4 V$ S& l1 K-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
. y9 b- P: Z; A+ m# \9 h-AX = 0912h (Get breakpoint infos)
. I8 Z2 | y, E+ E% L& F-AX = 0913h (Set Sice breakpoints)) ]2 i/ [; r$ X
-AX = 0914h (Remove SIce breakoints)+ ?" \- N- X- C
( A1 z( n* E7 j, y! V3 Y' h) q1 T* y
Each time you'll meet this trick, you'll see:) V$ x& U% I2 J! i0 \6 ~4 Q1 {5 l
-SI = 4647h2 i7 x+ E/ P* e' j& @
-DI = 4A4Dh$ e% L9 O$ I3 F) ?& `
Which are the 'magic values' used by SoftIce.* _' i* w O" j) ]) {8 q0 ]
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.5 Y5 I; k# v$ P" g2 l. |: j! S+ o
7 _( `- a+ ^$ f# W& v, o
Here is one example from the file "Haspinst.exe" which is the dongle HASP4 H* V+ _( y. z) ]7 |0 g1 T8 e
Envelope utility use to protect DOS applications:
; V3 y2 U& |- ^1 u9 i2 ?" p7 [, D5 n& u v& z$ q" c7 i8 z
/ s; f% h) v7 E9 H4C19:0095 MOV AX,0911 ; execute command.
# n. W* L) u% x' J. D: m9 H4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
5 v+ C8 O% I) ?, Q2 N& F. P3 [4C19:009A MOV SI,4647 ; 1st magic value.' R4 ^+ a& D! u, x3 q0 r j3 K* z1 i
4C19:009D MOV DI,4A4D ; 2nd magic value.0 i" [' l8 Q6 n
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)7 m' p* W9 j6 K# S& J( ^& g [* p
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute1 @9 C5 c1 b9 A; v" N
4C19:00A4 INC CX4 ~# n* e& w5 Y: [7 U. }
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute' C6 ~9 V8 ~. e
4C19:00A8 JB 0095 ; 6 different commands.. m5 e) t y7 C; K8 j' p# @% W
4C19:00AA JMP 0002 ; Bad_Guy jmp back. Q# {1 B8 J o: X0 v
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)! u! {4 i3 W- }9 A: B; v; _) q# \
, j0 m' t" l8 q9 x) V- C
The program will execute 6 different SIce commands located at ds:dx, which8 D" \$ E4 s4 @5 N. u" e X
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
6 h" v5 C" ? \8 E( A A5 |6 u% J4 f( k! t& i
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
2 n0 I: c3 i5 R, O1 K' ?- V___________________________________________________________________________# o# Y1 T6 ?- ^; ?4 M, K
1 c7 w% V+ f: P& Z% l- n2 E5 M- L- ]7 i) f
Method 03& K* d4 A5 Q) N' E, o
=========
' O4 u, x: ]6 d, U
7 Z6 m5 Z: E+ ILess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
+ W) u' s( O: y, X8 R(API Get entry point)
9 ^. P9 g( @9 T# f3 h / u+ J. o' X# Q6 X! O d. u3 {
s4 N0 L" `- n$ G8 n- _, `# D& q6 }
xor di,di
3 ]' O2 Q& O) ]/ f) Z mov es,di, r4 V4 T* M6 Z2 K" M; ^; d
mov ax, 1684h . c" I+ n& @) _2 X$ J' L, V% R
mov bx, 0202h ; VxD ID of winice
! s1 e7 A" l" f: p! R9 P$ N int 2Fh' m! J; w& }$ B2 R* h
mov ax, es ; ES:DI -> VxD API entry point
( J% q. P a2 _+ X. h) M add ax, di0 Y; m8 b* T2 D' `3 m% ?
test ax,ax! S; i" y$ }. y C
jnz SoftICE_Detected
+ e" c# {2 l* t5 C$ Y% ]1 _
6 y4 H+ Q8 T! E p2 M___________________________________________________________________________
# T; a' b# b! W
6 Q& j4 \: f' U8 k/ B# n4 oMethod 04
' n1 G- I$ b7 B" _' T=========
; ?9 U- M5 l7 E& f7 ~
5 n2 W. N& e g6 j6 `, @7 fMethod identical to the preceding one except that it seeks the ID of SoftICE
# ^- f/ p1 c! g4 t4 g; n- Y o4 RGFX VxD.2 o: a$ C) G' L4 e% w2 A
+ |( X* X2 K; v
xor di,di; V6 d. i& V N/ X
mov es,di
4 y# w5 _$ _1 U mov ax, 1684h 4 r" g1 c+ i1 ]- @
mov bx, 7a5Fh ; VxD ID of SIWVID
# m9 g2 b; t# I5 P) } int 2fh1 d. J# s6 ~ a; K# W4 f7 u
mov ax, es ; ES:DI -> VxD API entry point
, P$ `! f' Y, W( e/ u8 H add ax, di
! j; e' |( j* K% N test ax,ax+ {) n1 C7 D8 H0 `7 X
jnz SoftICE_Detected
' T* V2 ?6 F& N- b" w; _9 h' f3 c7 h D: b5 V
__________________________________________________________________________7 Z: P, s' K* Q2 ]( k& e. u
% ]; p8 | z3 E L3 O; S: B
5 g# x, I+ ?0 ?5 @" g; O
Method 05# x. N: U T7 p q+ t, j; M; l" E* Y
=========6 q m0 v% o8 H! E: A9 Y
7 v0 r2 V- O% S! R3 o1 d$ [. m
Method seeking the 'magic number' 0F386h returned (in ax) by all system
; f/ F. a; n3 odebugger. It calls the int 41h, function 4Fh.( ~" D2 c0 }* L7 N$ ?3 }
There are several alternatives.
+ M4 v b6 }9 J% _8 y5 H- Y5 b( \, P
The following one is the simplest:+ u8 G9 v7 m6 F' O* G1 p
( u/ f8 q1 t$ `1 c- _2 k; A& \
mov ax,4fh6 [. N4 q3 Q# y/ |* j) L: A x
int 41h) N3 ?; G2 j9 W, `" E7 e9 O/ d* Y
cmp ax, 0F3867 Q- e' k; b: N6 k- [3 i7 z! j0 W
jz SoftICE_detected
I2 B7 H! i3 l* Y7 L$ T1 b1 m; a/ B9 g; V8 ?
1 S& l1 f7 `2 Z) D M+ o
Next method as well as the following one are 2 examples from Stone's & ^) A) t) p* W
"stn-wid.zip" (www.cracking.net):
) [- N# Z. @# {2 e
5 k0 h' t; `6 ^9 } mov bx, cs; M9 w2 ]& P4 j
lea dx, int41handler2( ~! j3 j% [6 i
xchg dx, es:[41h*4]
( v6 J' z. g# W) N- R) l* A; A9 [! y xchg bx, es:[41h*4+2]2 R/ r' v1 g! l; G' ~/ ^4 r
mov ax,4fh
& Y. B1 t' L( J4 j8 r: D int 41h
! C2 F! B' {2 v& ^0 b" s) a5 i xchg dx, es:[41h*4]
' Q$ K! R: M( J( B! B7 f3 y xchg bx, es:[41h*4+2]
; ~$ o5 W* ^/ L/ M+ V: a cmp ax, 0f386h6 D3 q! w0 J7 N w$ R
jz SoftICE_detected
/ B! ^ x7 f8 h& S
3 i# E* u, s6 } lint41handler2 PROC
' C6 K" M- W$ r iret
7 ^$ o7 S5 Q0 `# Nint41handler2 ENDP
/ |' \# F6 G+ o- ?% e2 j+ T3 I$ {' l5 j
; f! H& j* k$ R5 T% {3 ?
_________________________________________________________________________
y2 Z% v ~$ n4 F9 L x& u
2 @# q. X( g9 X3 ?. R6 U4 ?) @1 \: L: I
Method 06: y: V; S% p4 a% {6 |
=========, n" U! h4 D2 V' S5 h+ l
: C, G% a% C% J$ G; A
* k+ z- E, H1 s9 x- Z
2nd method similar to the preceding one but more difficult to detect:
- v3 ~ X7 l/ I' m4 K- D+ L5 q, n/ p) A7 e* x/ p" o1 f0 I
/ C4 x/ Q: b8 Z/ U# `
int41handler PROC5 T* ^# q) k% B* w/ o' B
mov cl,al
2 B/ F* E% L& R3 u: u @ iret4 y3 J- Q( |( K! @) {5 I
int41handler ENDP
* U0 W7 J' G( m2 Z) D# i# Z
, Q7 U7 R* S0 u( t7 j
' T7 J' v1 V' Q; v- K4 @$ T xor ax,ax: L6 i r. J* T
mov es,ax$ P8 ]7 G6 D7 O j& w$ ?
mov bx, cs. h7 {+ p! h$ R2 v
lea dx, int41handler
( @- {, s" Y2 \( f( L4 [ xchg dx, es:[41h*4]" Q* U& [4 U2 q1 v& o. `. q3 U6 Z
xchg bx, es:[41h*4+2]
, y- Z5 u# c4 k0 o in al, 40h- m( P y1 J; N5 g- h" Y( ~' _
xor cx,cx
. \$ n- b/ d, I4 e/ l int 41h
% h; |$ p2 i0 Q1 k' S xchg dx, es:[41h*4]3 m8 _4 ~* q& X9 w" n
xchg bx, es:[41h*4+2]
: l# m; G& t( A% _0 I. Z8 Z% v cmp cl,al
v8 q! |* w, ^ jnz SoftICE_detected0 l- r& ]% {, L% J* r6 }
) V, l) N' }0 ^9 M d
_________________________________________________________________________3 G7 G7 e- n; u. o4 K ^
6 w4 d4 Q) h, L5 X& J/ i3 @; N
Method 07- r) k4 F( i* d; \2 V8 r
=========- y, d$ F u2 n; W! B5 a8 M
! J j0 ] k t4 n3 v3 CMethod of detection of the WinICE handler in the int68h (V86)
8 N; T* ~$ `! P0 U5 t7 R! q
% U% c% D; g* c/ y$ h) s mov ah,43h
& z) U8 t# a1 u9 b% @1 M int 68h
, U1 \5 d- r8 a3 |: N cmp ax,0F386h
: ` o. D" c9 H jz SoftICE_Detected9 H# O/ E" X6 l
& M. D4 V( w0 w: M' H( E2 b3 i' u- B+ B) a
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
2 {* g" G- I& z0 [; ~( Q! X app like this:* H* i. z. m. t8 t: y
6 U. F, n: A+ l O" o- H
BPX exec_int if ax==68
, w/ y B2 s# i6 f, ^7 y% b: B8 {% [ (function called is located at byte ptr [ebp+1Dh] and client eip is
$ x$ ^6 ^& L% g: V located at [ebp+48h] for 32Bit apps)9 X* q9 v8 D; w5 j8 M8 ?" L3 e
__________________________________________________________________________# \9 g( o! O0 d. p1 ]
, Q3 x# N! j' O% f0 |( C( R
% q# ~( y2 |! f/ UMethod 08
; T9 R3 \/ p/ l=========/ W/ _0 x9 @+ H2 H
9 Y+ g. I3 e; ~& P# w
It is not a method of detection of SoftICE but a possibility to crash the8 t5 r! A0 q# B, r
system by intercepting int 01h and int 03h and redirecting them to another
7 T) Z n3 s; f8 G; Iroutine.
7 d+ u% R5 u( t% r# HIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points% W0 e! A* r6 [2 t2 _
to the new routine to execute (hangs computer...): C9 w8 O, L: I
% c7 z: M5 o4 b8 A( ~$ @2 z! @: t mov ah, 25h V0 ?# J* j4 r' U
mov al, Int_Number (01h or 03h)
! O# N1 S3 K ?/ K mov dx, offset New_Int_Routine
\/ j% Y( N* H0 r int 21h
; p' G5 j0 }* ~6 h& V# C. v8 V `4 K" w
__________________________________________________________________________0 g! b3 t. V" c7 r
: y# ?9 ?1 M- KMethod 09
$ z! W% t: m( o=========
5 U8 d x* ]2 z4 {
/ {. t% N: }1 s. BThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
9 S3 `: v9 t6 Q8 L" ^4 zperformed in ring0 (VxD or a ring3 app using the VxdCall).
' g1 I8 V0 j' g2 i x3 E- vThe Get_DDB service is used to determine whether or not a VxD is installed
2 N8 e) X' E1 Ffor the specified device and returns a Device Description Block (in ecx) for
4 ?8 K" b9 I) d5 k( H6 T5 \5 |* }9 [that device if it is installed.
. d, h2 Z5 U0 p! m3 b7 i- c' X: u$ ^/ _
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
5 _3 ?; V% `: u; x& x mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-) L7 P0 f9 u* z0 M5 s- x
VMMCall Get_DDB" x8 D( p2 Q" `) ^' ]8 F' ~
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed$ r" j( Z- r- |
: g7 X+ T- L0 r) W0 j& P& {8 b/ YNote as well that you can easily detect this method with SoftICE:
5 y& p! N7 w7 Z. ~9 L/ u. U4 k bpx Get_DDB if ax==0202 || ax==7a5fh
7 R& J8 T; K6 a1 B: `' m/ \
9 F6 _7 h! o4 D9 m# w7 y__________________________________________________________________________1 ^) {" B4 p% ?
6 k: y3 ?$ P" t) E. j" o. H9 }! t
Method 102 X. L" ]3 k. g+ z+ k
=========2 x* a) j$ T9 Y2 }6 i3 v* }' ]4 J
. e2 I1 c/ E8 ]" f/ z+ a+ k0 H=>Disable or clear breakpoints before using this feature. DO NOT trace with
( ]0 b/ u1 C$ ?) I+ M! i; v9 e( w SoftICE while the option is enable!!
; B& H% ~; A: p
9 a3 o- W# T; AThis trick is very efficient:0 F2 r1 m% O8 r, U/ |. z9 T
by checking the Debug Registers, you can detect if SoftICE is loaded
# h. Z: M, W1 p6 A( l# b" v(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if8 O) K: B2 |! ^5 U0 Y
there are some memory breakpoints set (dr0 to dr3) simply by reading their. ] z' K. {9 o$ q C# i4 d
value (in ring0 only). Values can be manipulated and or changed as well
# N4 }+ R3 Q1 V* G1 i(clearing BPMs for instance)
+ O- t5 q1 c9 ~' {
* L$ r- Q4 `7 U__________________________________________________________________________
' i5 O" ~/ f9 s5 m/ Q! o7 j; M
" P, J0 K0 ~5 r, c8 q' }6 q0 U3 GMethod 11( Z7 t2 d' [# D# t1 @7 |+ c* p4 u, ?
=========
6 Q& `- ]( K+ `8 G* X- ^, t& a5 ^2 x6 X6 u0 F
This method is most known as 'MeltICE' because it has been freely distributed
3 P$ l6 w3 ?8 Vvia www.winfiles.com. However it was first used by NuMega people to allow
' J1 ]9 H( m+ o+ k1 v4 M/ sSymbol Loader to check if SoftICE was active or not (the code is located& |% y' d/ r9 d/ X
inside nmtrans.dll).
, ^" Z/ m. ^/ K1 d' g
& B$ k$ I, @' r' j- s; \7 SThe way it works is very simple:
& R1 @4 K6 o: f2 ]% o& b9 `It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
: Z0 O( N7 A$ ^ t# v! e4 k4 H/ hWinNT) with the CreateFileA API.6 y* a% L& G* A6 |3 n0 \" h s7 N; o
5 z& u, ~ T; h: D( p
Here is a sample (checking for 'SICE'):) ^, f- c. D; `* r7 A9 g
& S$ m9 e, C. zBOOL IsSoftIce95Loaded()1 I& O6 y* U+ \# l9 S
{: h( [$ g( V. P7 r2 N
HANDLE hFile;
& u! E- Q% M' b5 N hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE, n$ [+ V$ `9 R+ s R" }# X+ d$ ?
FILE_SHARE_READ | FILE_SHARE_WRITE,1 m0 a" O( F1 O R/ X. ?4 K
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);$ t o2 H. [) Y- F' w8 y7 Z
if( hFile != INVALID_HANDLE_VALUE )1 d* L& G" |0 Y8 A
{
/ Z A- w5 g" z CloseHandle(hFile);7 R+ L s$ `: B0 a
return TRUE;
3 l" e1 p I) c e5 f }
2 P% z1 ~. u% J: o c2 d; ~ return FALSE;; Q0 S! \ k& {8 l6 V: _
}
* w1 _+ Q% G. }+ d) w3 J0 z( i4 k3 _% Y0 G% @* r4 s! h8 U
Although this trick calls the CreateFileA function, don't even expect to be
- x0 P! o% \& U0 H8 R3 Cable to intercept it by installing a IFS hook: it will not work, no way!
, X, m# i& [' ^In fact, after the call to CreateFileA it will get through VWIN32 0x001F$ E0 h& M# v* w- b! s3 J, ?
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
1 Q: b+ v( z) D2 }- w0 Tand then browse the DDB list until it find the VxD and its DDB_Control_Proc
; \( E, c0 y! k; Vfield.
- @; j1 }" Z7 x6 A. RIn fact, its purpose is not to load/unload VxDs but only to send a
/ D+ R0 ?' y6 X7 X4 A2 WW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)9 p$ t6 i1 x `# ^! I2 b1 ]
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
5 R3 T; |4 U9 s7 P o; S- g! ]* B8 mto load/unload a non-dynamically loadable driver such as SoftICE ;-).
1 M% [' ~4 t! ZIf the VxD is loaded, it will always clear eax and the Carry flag to allow3 T" l$ U9 o5 K w
its handle to be opened and then, will be detected.
@0 ]* f- D L1 X( H$ u" U y8 \You can check that simply by hooking Winice.exe control proc entry point
2 r' P8 C) h8 p6 u+ dwhile running MeltICE.
. ]# x" ]+ Y+ M; x, {2 a. _- ^5 Y/ }, Z6 z: v: ]
) g/ W1 o7 A) j7 h7 P, k! f 00401067: push 00402025 ; \\.\SICE9 @8 f. O: m4 c8 E8 _* g1 c
0040106C: call CreateFileA! b5 \* t- \/ ]
00401071: cmp eax,-001
# l/ u, A. A" f- w. L 00401074: je 00401091
i) F$ Y* P$ V Q4 N& @1 f% m M X2 Y7 U
* I* A, f0 v" P% q! UThere could be hundreds of BPX you could use to detect this trick.
4 {) w! W \+ T- c9 ^( F$ b# a( j-The most classical one is:
. x. w" O4 X! { Q BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
/ P2 }* w( v5 B* V/ C, z g4 m$ ?9 R *(esp->4+4)=='NTIC'
0 }8 ? y+ A# c; K5 y! A- r7 ?, [# {. q
-The most exotic ones (could be very slooooow :-(! m3 ?6 B- ]6 f' |. e
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
: _2 m2 `# R. c. @7 D1 c3 g ;will break 3 times :-(
, Z4 p, o! i+ f; ^, V3 h8 M0 K2 @) @" x( N
-or (a bit) faster: 3 k+ i2 v# [, m8 ?/ \# l% O
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
1 y- R0 e9 C7 x9 `2 C1 S ^9 Q
( _3 V) V/ ]3 j# r8 b BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' ) m4 I( B- V& b, k
;will break 3 times :-() F) }" {; `- S3 P8 f( G% x
) Y) Y& c3 O5 N; f3 h `$ ~9 u
-Much faster:
6 d2 j/ y6 s- T) { BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'& r6 `4 x4 S) Z
( q, w! o; S1 S' j7 W& T
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen+ j, @5 I$ F/ s. g# d, v" w
function to do the same job:: [4 x( [' `+ G0 @
' g$ D# u/ \7 y; J. e. Q5 x push 00 ; OF_READ
+ h G: V0 V1 H+ j2 j3 l mov eax,[00656634] ; '\\.\SICE',0
% N$ i( t! G+ Y+ W( E: ? push eax" x6 Q. b1 D3 a; S' i" g
call KERNEL32!_lopen
1 g* p4 E; q+ `" R7 G inc eax
/ r( g3 G9 c) j+ u% | jnz 00650589 ; detected
( G2 }& U% p/ {. |: n4 i push 00 ; OF_READ& S3 r' X8 b) ^9 \# ~8 F
mov eax,[00656638] ; '\\.\SICE'
) b0 r1 N4 _: V2 b3 X0 @( S2 x push eax& b! a9 p" B F. e
call KERNEL32!_lopen9 x& h% h. R9 d- @, x. m
inc eax. g2 K( u2 R( D' H; E
jz 006505ae ; not detected) [/ t* b6 [" w7 z! e
% K+ {, o: c% R/ n2 a- B1 d: R! ~1 l- o$ j" S! e6 C5 Q5 Z
__________________________________________________________________________3 |, v" U- s; X) {& Q
( D; ?) Z. y. Y6 k' P) LMethod 127 ~2 v4 f( _: G' N, Y) ]4 g# z* e
=========& h+ r. \- r% d/ m- n8 ?+ d
6 l' @- J8 z- o+ H o( a
This trick is similar to int41h/4fh Debugger installation check (code 054 C$ W; s5 L0 N+ w, N) L; N
& 06) but very limited because it's only available for Win95/98 (not NT)
4 p! Y! w+ x6 D2 j( V) i6 H2 q0 Qas it uses the VxDCall backdoor. This detection was found in Bleem Demo." N7 V' C$ r0 y! W
m( n$ k8 H. k# I8 t! V push 0000004fh ; function 4fh- B3 U( X$ [% C' A* M3 w1 s
push 002a002ah ; high word specifies which VxD (VWIN32)
( w& I' D. b' c6 C% A/ f ; low word specifies which service
1 l% e* l+ A- \4 k- T (VWIN32_Int41Dispatch)
/ u1 A! _" J4 S( W( ]; {5 Y$ t call Kernel32!ORD_001 ; VxdCall1 ?2 d0 h2 Y0 _: |6 B/ b7 @
cmp ax, 0f386h ; magic number returned by system debuggers M& Q2 F# t! k( q! }* d
jz SoftICE_detected
4 Q* u' D* d! u* a7 V5 |' l6 e5 D1 _4 I3 n
Here again, several ways to detect it:# ]1 X0 A& P. @! `8 S* K/ Y
7 W) h6 @) |& k! i2 F# w
BPINT 41 if ax==4f
9 h' N3 @1 B2 h- T! @# k4 e7 `4 U. E ]5 e7 ~! @& ?& C& M
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one% U5 V" S( h7 N% W1 I8 `
# T: R `. d7 I
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
# O; h \+ M, S0 D& a7 }+ e3 \" n) @
. d& d' }9 f2 ^0 X# v8 j, {6 _ BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
' D1 u1 N* ]% @$ Z- l, F# T- N8 }7 L: g6 ^
__________________________________________________________________________6 ]9 o, Z; y0 h+ ^% m' ?- n
( [; |3 B6 C9 W0 o
Method 13" M* B7 e# v" @7 x4 [7 ?
=========( F) h4 L; I2 h; P( R3 j- w9 C
- z. F u1 C0 fNot a real method of detection, but a good way to know if SoftICE is
5 v& A$ I7 }9 Vinstalled on a computer and to locate its installation directory.
# ?8 t. J! w& \0 Y5 m m7 wIt is used by few softs which access the following registry keys (usually #2) :- _5 h% I; E6 Q. }9 n2 V
7 m/ E: |; C! h4 ~6 T! T
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion" ]; K8 U, h$ V
\Uninstall\SoftICE8 W; \4 Z/ q* y+ D: {$ x/ G
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE! I- [: r* o, O' P! A+ c& L
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
8 l& _' E( g1 p5 L, y3 I! G" Z\App Paths\Loader32.Exe
- P" _7 h8 j0 J6 F! @7 ~ N
! Y, N# V: a( o6 u9 _! @) h, V5 a. l$ i; d b. Y( E/ P4 R
Note that some nasty apps could then erase all files from SoftICE directory( V' t/ p- B z9 X; O: z
(I faced that once :-(
9 i( m6 n$ @. d3 Q4 I
" y/ n k F2 R* O6 j5 lUseful breakpoint to detect it:
8 S J: }& T# r+ D n! h, r% H- V( w; x
- q6 R& g4 ]# J, |; n BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
- L2 J% Y$ D4 D& d4 E1 X! v! x
# T* k! c# U- M; c__________________________________________________________________________1 [! y* y9 q2 L8 J. n9 W
9 T+ r% @ s c6 U
, q! d, T |3 i1 ^7 Z8 uMethod 14
A+ G T, }6 A% B' y; t========= v0 C ]4 k( ~. ~3 N. w2 P5 O1 g
$ l# [6 D+ q( m$ ]& pA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose' m% G; |" Y+ k3 n2 {. ]6 `7 w- T
is to determines whether a debugger is running on your system (ring0 only)." M$ H. _. v# n! [# T8 ^
9 w7 T% {1 w! P' b. U! ?* L5 c/ J VMMCall Test_Debug_Installed
3 t6 t, \* \' _8 a je not_installed
8 l# o v( A f$ e$ n) f
8 C0 q- e% C! EThis service just checks a flag.9 x4 v2 u6 u" D' o B6 K, y
</PRE></TD></TR></TBODY></TABLE> |