<TABLE width=500>
& S }" g0 `- S9 m2 H+ S9 J<TBODY># P5 o1 q) H$ w5 E. o1 b) A
<TR>
% e5 _0 v$ p3 m7 D/ }0 m* y<TD><PRE>Method 01 0 {* o+ b5 F1 O3 E$ V" M( T
=========
7 F& O$ o0 Z) {$ ?6 m: p# `# T% e/ f7 F) H+ S1 t1 L4 k, L
This method of detection of SoftICE (as well as the following one) is- r, e# l4 s. j* k0 ]+ r. C
used by the majority of packers/encryptors found on Internet.
4 w/ r' O8 r7 yIt seeks the signature of BoundsChecker in SoftICE
/ ~. G5 I2 w: k$ l+ I9 y; g+ e
5 S+ v0 I( w6 @2 d mov ebp, 04243484Bh ; 'BCHK'
1 k; i7 U$ { a5 q mov ax, 04h
2 o, o5 w" b* F4 d4 k# H) i int 3 # q! r1 K1 T: p! D
cmp al,4; B+ G) H4 [; W% `) G+ k
jnz SoftICE_Detected
N8 n0 c# b# A, P/ v" ^' T
9 B3 p! ]2 j9 E9 e8 e( |5 O___________________________________________________________________________' ^$ ?* p8 a7 A# W& Y, R5 J% f
2 [% k. |; j* O/ |5 gMethod 02
- r* u! a; q: O. V=========
( L/ v f E4 p+ D3 B C6 }2 M7 t" a$ F6 p3 p
Still a method very much used (perhaps the most frequent one). It is used. @. H$ r- H4 v' L$ z( E4 q2 `2 ?
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
! P8 D, g# H, r1 e+ a& ]or execute SoftICE commands...
7 u: P% O+ T C T; T1 ^It is also used to crash SoftICE and to force it to execute any commands, S# @& |0 k6 K K" P4 ~1 I0 I( S
(HBOOT...) :-(( 0 T! q1 |7 |4 T- G9 q
1 m2 @$ d% Q* {) BHere is a quick description:/ e) `6 Y! i: A7 O% x: x
-AX = 0910h (Display string in SIce windows)
& }. F+ x: Y0 N3 Q, k8 i4 E-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)1 i% j6 p" \: n: [+ C
-AX = 0912h (Get breakpoint infos)
. m) Y" c) V% b# e8 D) E-AX = 0913h (Set Sice breakpoints)/ L; Z; M: i/ s
-AX = 0914h (Remove SIce breakoints)
$ K* L# R! a6 m( ^8 ^7 X
# T$ P3 o4 `9 gEach time you'll meet this trick, you'll see:
2 h4 N/ w4 O7 W, e0 P4 R-SI = 4647h
+ W" e* L( a- I-DI = 4A4Dh) ?0 O" W6 X$ S; ^; w$ I G
Which are the 'magic values' used by SoftIce.
; g1 Y& _, I# z7 R1 cFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
$ u# r2 A$ H7 H$ }* g" [! a" A( c: Y3 O9 o
Here is one example from the file "Haspinst.exe" which is the dongle HASP2 t! n; ^: V8 K4 s6 x
Envelope utility use to protect DOS applications:1 T; `5 t; p7 k8 N
; g( m$ K& O3 R3 l5 ]: r! H
. j/ _$ o. o0 H3 ?
4C19:0095 MOV AX,0911 ; execute command.
8 M6 q' E+ A; p% B4 M, M& w: k; B0 Z4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).7 I8 B# _% b# b8 r: s; \6 V' [
4C19:009A MOV SI,4647 ; 1st magic value.
1 @2 ^3 F- Y% ]) y7 R1 v% I3 v+ O4C19:009D MOV DI,4A4D ; 2nd magic value.
1 E1 M8 b7 _; \8 _$ \/ k8 G4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
' k+ w8 y* ^0 d2 C& y4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute' J2 ^9 o5 h S, P; m) }3 y# ~- \( ?
4C19:00A4 INC CX
* Q% a1 [1 s' @4C19:00A5 CMP CX,06 ; Repeat 6 times to execute C; Z( q) K l1 W( I L4 Q/ P. D; M
4C19:00A8 JB 0095 ; 6 different commands.
; T1 ^6 k5 K& D( Q( J P4C19:00AA JMP 0002 ; Bad_Guy jmp back.* v" x8 F( ]7 q5 `
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
4 {$ I- a) s4 J8 _
8 G) z8 `6 w$ eThe program will execute 6 different SIce commands located at ds:dx, which
! D8 d0 Z% y& q$ c$ \are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
8 g( h' h% I; r6 n) `5 @
$ w6 F# \% W1 x7 \, w* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.8 c0 \! J" ]: w" g+ X/ n+ ^; A3 R# I
___________________________________________________________________________
* v- Y [& y, q# ]( t# o4 E2 H
- x' m, p" w, |2 v
5 g' H \- E( c2 r& T) PMethod 038 J9 m: o0 o+ S1 U
=========5 z* O7 {: B& m
/ N! ?8 l+ A; M9 k
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h4 t; Y& |' X1 z$ o# V6 P
(API Get entry point)
4 M5 r5 n+ j4 `1 O- o8 D! A
- p2 ~. s6 W! L( x8 z. x/ f f2 ?% d' X: R2 `; f% Z! ?/ z
xor di,di
0 t, b6 J; ?+ n mov es,di& B, e% M c0 X' {7 J
mov ax, 1684h & W" N- c: B9 n- R' k
mov bx, 0202h ; VxD ID of winice
+ E4 J' r" {% U& x+ v& L int 2Fh
) m- E. L! w0 a3 @2 Z9 k mov ax, es ; ES:DI -> VxD API entry point) I+ a. \ K' b# t1 ^" H% Y- p$ n
add ax, di
6 x4 }. c# Q( F) t+ Y. P test ax,ax
4 d4 _! Y. X/ K$ U0 D% g0 E jnz SoftICE_Detected
& c4 Z, t( _, y5 E
' L- }; r$ U! w8 [/ ?___________________________________________________________________________( J7 s7 Y9 ?# _ A3 T
7 Q, h- V0 n4 c% t. a% \# O6 {4 D4 q, lMethod 04
; Y- E; b1 g! A3 m=========# ~) L) z# \6 E" B0 L- D
9 f- u6 Y$ a: G! z3 K, Z u* w
Method identical to the preceding one except that it seeks the ID of SoftICE) s$ w/ A3 m$ T: |( M
GFX VxD.8 L, E4 I7 `$ V
% {+ q7 H7 n2 N7 Y; Z7 W/ L
xor di,di
" N/ \- z/ i9 ~) p mov es,di' j( \0 C0 q* A+ U; l
mov ax, 1684h
" \& j/ Z; [6 ?' T mov bx, 7a5Fh ; VxD ID of SIWVID
) X- M" E' I2 N' t) o int 2fh# x9 \6 `8 j+ x1 a4 H& X$ a1 v
mov ax, es ; ES:DI -> VxD API entry point% ^6 o; {6 ?" R7 s7 R7 L" ~) o* {
add ax, di
, f/ ]& e/ ?, i& H test ax,ax3 B. F# n& `$ v! i5 D- f1 \
jnz SoftICE_Detected
4 f; P: Q% V1 b2 P! ~. Q3 }" G6 s5 }' q- ]
__________________________________________________________________________1 x1 O2 Y6 U$ U9 ]) {0 o* D; V
0 |0 F* B. C7 P; T& O! ]8 w" u" H1 Z! L
Method 05
/ Z' ^8 F/ E: T+ t3 }=========+ A5 a# A( J6 I; z) D
4 _5 S! B1 a& d% a- r3 j
Method seeking the 'magic number' 0F386h returned (in ax) by all system
& ]3 l x6 b* h Q+ ddebugger. It calls the int 41h, function 4Fh.
# y. i+ c4 n1 s0 `- {- ~There are several alternatives. 0 ]: U+ I3 L4 l: R1 p0 q% B; w, q
1 |! s, x4 @7 s5 ZThe following one is the simplest:& S8 W) S. @8 W0 Q' O' P
" P' ^2 ^5 W2 d; N/ ~4 ? mov ax,4fh d9 s3 V; \4 K
int 41h
. S. ]) J& u/ C% P O cmp ax, 0F386& G/ i1 N1 y4 t K [+ t
jz SoftICE_detected
" b$ S% D2 y b$ l% ]+ e" n
f$ W0 j) d& B
7 `- b( H/ `, ?. yNext method as well as the following one are 2 examples from Stone's
4 n$ s& v4 L8 K, Z"stn-wid.zip" (www.cracking.net):
; d' B( U* ~& T9 c* u! C4 z* {( }, W$ m# B. x* R; Y5 P- M
mov bx, cs+ m7 y5 ]4 K$ [" R
lea dx, int41handler2
4 Z# Q+ W* k0 P0 f" l) l- | xchg dx, es:[41h*4]
D1 z! G+ E/ I1 W: z xchg bx, es:[41h*4+2]
9 `6 v% _" Z$ R8 f( a/ R mov ax,4fh! ?; U7 | \# e6 e
int 41h7 N& [. F: u0 p) t. n+ A9 p
xchg dx, es:[41h*4]
* b) t; s/ [7 c7 @' \ xchg bx, es:[41h*4+2]
! p. e, x# @) B/ { cmp ax, 0f386h8 w4 @( Q6 a* Q' X8 q$ M; W
jz SoftICE_detected
" R* p8 T7 h; R4 _4 w' v6 u0 G/ h4 F0 y
int41handler2 PROC
n$ t+ v; ]$ l) u iret
7 I! a; t- z# uint41handler2 ENDP
0 T9 ^6 w" u+ y5 O0 T
. W2 h, I) T! u% \- I/ Q0 L8 @# H, j: ?
_________________________________________________________________________
) y9 K0 n9 S2 n. B% f. h
& N2 G& q( A+ X8 F9 K, B; I+ E
7 J! P( S8 s$ P. }% u) D" AMethod 06# u% y4 C0 x4 n4 h2 P9 |! W7 j
=========# K0 x0 H1 C! S0 r" h; q
9 L* \& f" J ~! Z8 s
4 [3 x; s. [8 H1 Y- \1 @2nd method similar to the preceding one but more difficult to detect:
* I7 Z6 I5 C& d2 J
/ p# V3 L; S: ]) ?) q1 q' b p8 x4 `
int41handler PROC
* u! ^( S) p3 j mov cl,al
9 g8 b) \; P5 @; s+ v1 c# w iret( w' n- j4 F, q# H3 b# g3 K4 b" N2 Q
int41handler ENDP( q7 c0 T; G' d0 h9 r
, Q% F% O: ?6 b' m/ i, B
$ k! ]- y: K! X7 o xor ax,ax# _, @0 I8 O2 y* j
mov es,ax
" L' ~/ V O2 x4 Y6 ]7 U mov bx, cs
; H, G4 c7 R. v* F- A lea dx, int41handler
" y$ S$ R- K/ {# I8 B( t" P" q* | xchg dx, es:[41h*4]! a- q% J5 s7 }( v
xchg bx, es:[41h*4+2]
/ n$ B7 p7 d- ?" { S+ g in al, 40h) _. W5 O1 o! A; K3 G9 G7 o* d
xor cx,cx
& ?! _% R: r& I/ M9 a- A int 41h% R9 M: C$ [4 B7 \, }0 w9 s
xchg dx, es:[41h*4]/ j+ v" K9 x" L0 _8 f
xchg bx, es:[41h*4+2]
: g; G' B$ O- w& w2 t$ X cmp cl,al/ F3 d* O( k* q! j
jnz SoftICE_detected/ Y. b. c- E& ]2 r. H6 f
# v Z$ L5 I4 @, |/ G0 ~0 w
_________________________________________________________________________
0 N( D' [& l% I F# X3 P
6 @8 Z6 B( f J% E: Y+ r5 ^9 yMethod 07; l+ M* v+ U2 d( K" V
=========
) x2 a+ H5 a7 `% `, \
0 B8 v2 N/ w& \5 e$ {% m( `Method of detection of the WinICE handler in the int68h (V86)7 z5 Q/ B2 g! V: |
3 ~9 w4 g `7 l# z1 l9 ^- ~ mov ah,43h/ ^* _: w) a4 M2 P2 \- ]1 l" C
int 68h
/ N& X2 C* _3 d+ j cmp ax,0F386h
9 V' q5 h2 a+ q' t. f' y jz SoftICE_Detected
. l7 R' `; ?* {( }5 j% T& S& x& o/ g( ~
. q) l! `8 U$ M6 R! t, O=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
! X' V: ]& I9 G6 T2 W app like this:
& G) S$ J, k3 \2 w c6 b- O; W8 L% Z1 E* T, K' F
BPX exec_int if ax==68
9 s6 U3 a- i" ~" p7 O! M (function called is located at byte ptr [ebp+1Dh] and client eip is+ W1 V! T& G( v! a7 ^
located at [ebp+48h] for 32Bit apps)
5 [" R* ?, T; B: ~( ?2 C1 f' W, w__________________________________________________________________________
) ?, g' q- Q3 D) U T3 Y& N% s& |4 [- s; A$ N7 Q3 x
5 F" x- j0 ~; g2 |' M6 b
Method 08* R1 `5 [2 C5 F- n; ^3 e3 E2 e$ e: m1 s
=========: h p; l! u! V9 F, d
% f" t" U& S& zIt is not a method of detection of SoftICE but a possibility to crash the
0 p6 `$ m; R; ^& W* ?system by intercepting int 01h and int 03h and redirecting them to another0 d& s- l1 q- X
routine.7 `$ H# H4 a2 }. X" c: x
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points1 O6 B; p" {+ Z0 `4 i: _$ q- ?
to the new routine to execute (hangs computer...)
) l3 R( @2 D- v d+ \" `* |8 m$ f4 s" l
mov ah, 25h1 }. L! h- d2 c3 i: t$ O; }; }
mov al, Int_Number (01h or 03h); P* G$ n6 B$ i3 m/ a! o
mov dx, offset New_Int_Routine" G" t% j8 E% [( P" M
int 21h
9 N) b$ B! D7 n1 G' y0 ]" I8 K- i; s8 |7 J8 F6 a
__________________________________________________________________________
6 C6 z# s5 m* Q% j* R" k( }" K) @) x- ~
Method 094 [) E- I) h" q) w w8 f
=========$ I: Y+ S- f! p; N' V: `
9 k' D! f, S0 W. N6 C% k$ P; j( w
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only0 j4 x. f" |9 j, B- S, `1 i
performed in ring0 (VxD or a ring3 app using the VxdCall).
6 M/ p, g9 t6 e' {# |The Get_DDB service is used to determine whether or not a VxD is installed4 s& i. G; N) A! L3 M( h0 I
for the specified device and returns a Device Description Block (in ecx) for$ Q l/ F0 R% o8 w: {4 T
that device if it is installed.1 |3 y5 m) ~& \3 m$ K" c
) u X! f* ]% K. V" b
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID5 u5 _) S( r8 a+ U$ y+ _0 D/ Q- y
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)4 `5 I \8 A" j% v& N
VMMCall Get_DDB
5 e9 w" H8 D# E mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
5 ]5 ^' g! k* l. h; r& v$ V" m3 W" \; G0 e* z+ u/ C4 K; W
Note as well that you can easily detect this method with SoftICE:2 ]+ e* L" K0 ]8 E+ J0 h
bpx Get_DDB if ax==0202 || ax==7a5fh
8 E9 J/ c( u. C: c8 C
* P) I; f6 h* v l+ x/ W__________________________________________________________________________
+ f( }) l7 V, I' i2 l1 B& b3 s& S; D" O; J# H4 F4 X
Method 10
V* O* I. _8 a( L+ f=========
5 i4 F4 F. G+ z* `
% m, A# Z" l* g+ F0 W% g=>Disable or clear breakpoints before using this feature. DO NOT trace with: H6 C v0 u0 ^/ t" f* H
SoftICE while the option is enable!! H- Q$ x: k5 x8 E( r
/ _' Y* I* {6 xThis trick is very efficient:
6 w) H3 |) F2 s6 iby checking the Debug Registers, you can detect if SoftICE is loaded
3 H& r4 I) P4 |2 `% _! x(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if& {' B0 h# O; m
there are some memory breakpoints set (dr0 to dr3) simply by reading their0 q1 h% J/ b1 C" k. h# r$ S
value (in ring0 only). Values can be manipulated and or changed as well& H) F9 u3 {: O0 f$ @+ a: R# X1 p8 w) @
(clearing BPMs for instance)
$ F4 ~1 w& H' @9 Q3 Q$ x$ F: w1 k) K1 v
__________________________________________________________________________# {0 ?; O* L& B) }
& N7 r% m* G9 B f1 [2 o a
Method 11% h1 N+ G5 |' r; \- T
=========
" y/ r; u+ ]* w9 }* }
0 u. ~- t, Y' yThis method is most known as 'MeltICE' because it has been freely distributed
0 h2 t/ o6 i% C0 ]! U- Cvia www.winfiles.com. However it was first used by NuMega people to allow
/ |5 y) Y+ H7 x6 J5 `( |: iSymbol Loader to check if SoftICE was active or not (the code is located I) p8 b3 x( y
inside nmtrans.dll).8 E# _( r+ Z% [' F3 M0 i8 {( g
5 v' f+ S& \9 K3 HThe way it works is very simple:
9 q) s( E, c6 s0 r8 H1 uIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
; N, P6 s& M: ?# R) kWinNT) with the CreateFileA API.% s8 w& d5 s9 ~4 n5 \7 \9 S0 `$ D
- u9 @% N; O, S& H3 oHere is a sample (checking for 'SICE'):2 ?+ ?' d: F) H2 h* z! @/ }6 y9 o
8 W* l. t, M# X' T* u4 @BOOL IsSoftIce95Loaded()5 h" Z8 `1 t4 C6 H# v4 T! a+ S
{1 M1 J c2 j) l+ m' e
HANDLE hFile; ! ^9 c- T% D# |4 C1 p( ?
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,6 D! [# i. K5 \) ^4 A
FILE_SHARE_READ | FILE_SHARE_WRITE,
3 {" i( m- [" H' T5 Z* |. }; t NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);" i9 n5 W. g6 X# q0 R
if( hFile != INVALID_HANDLE_VALUE )- @8 y; w, s( [
{
; O0 S: N/ H5 |& {: j, o CloseHandle(hFile);
( p$ g* G) E9 G* h, U" G return TRUE;
3 I3 L" Q: g; d X4 D$ \ }4 d) _ |) ~2 Y! E/ I% f
return FALSE;8 O& R6 e Z% E+ R
}$ `3 M! O# I! X
4 Q4 t2 j6 T3 _, s) XAlthough this trick calls the CreateFileA function, don't even expect to be
w* ^! y# d6 Y: lable to intercept it by installing a IFS hook: it will not work, no way!5 d: c ^ a7 d! X( C) e
In fact, after the call to CreateFileA it will get through VWIN32 0x001F* w$ x" r' ~) t4 l
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)/ G+ |7 O: S& @( k% t& F
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
3 t4 y3 g1 D1 Sfield.: [$ X) j7 r- ^5 ^. @
In fact, its purpose is not to load/unload VxDs but only to send a
* v0 ] W. J2 R! u X: s, GW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
( v& R6 D" p# y1 {9 l! vto the VxD Control_Dispatch proc (how the hell a shareware soft could try% L% r$ [- z$ @$ r# I( A. E
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
$ s! j2 T, B, UIf the VxD is loaded, it will always clear eax and the Carry flag to allow) s* a* B1 N; @4 \: p
its handle to be opened and then, will be detected.
: l9 V5 l+ L7 CYou can check that simply by hooking Winice.exe control proc entry point
1 m; w! I' r# Q lwhile running MeltICE.& s* f( v% n/ e; `1 d& O
7 c9 }, G2 V [$ F# X$ d5 c
, l& @3 M2 M7 m
00401067: push 00402025 ; \\.\SICE. B! t- H5 }: a" i8 i2 Y8 i+ i
0040106C: call CreateFileA4 c: }+ o- q. w9 A, N
00401071: cmp eax,-001
# ?+ ^2 Y- b/ o 00401074: je 004010913 \5 w+ T0 U/ x& R
3 C4 ]5 U% t" i2 a/ D1 ~* t
1 S; a! ], B- E% w B9 o
There could be hundreds of BPX you could use to detect this trick.
4 i/ f8 j6 V, Z* i2 y2 s- J-The most classical one is:
" r6 q' j1 X7 _! j7 m8 H$ Q8 F3 c BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
2 v2 S- t# @; g! t0 r; Q *(esp->4+4)=='NTIC'1 w9 V8 r$ p% b
) L8 H* Y- k) c-The most exotic ones (could be very slooooow :-(7 ?2 Z: F, V- W* y& U0 E
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
% d! e3 O# i3 W \7 l& a ;will break 3 times :-(
" b7 W& W$ g' G7 x3 r; i- i, c$ f* R3 H0 k6 @ O! y$ X: t" O: [' r
-or (a bit) faster: * H+ B! o, Z; U# s7 \
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
E: ~) H3 s# ]# N( y
: `( G7 t7 }. B! M( r( e% J; @ BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
$ K, x( k1 s7 D9 k, \ ;will break 3 times :-(
" [& ?$ i) Q5 `# w
/ U; B: k" a1 I" g: u+ ~-Much faster:
" x W6 t- `8 s. |& m1 V3 ] BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
i, X! i( ?" S3 v8 [# L
. t& |/ }% b- cNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
9 _! L* A' @& ?! k9 dfunction to do the same job:
, J, _% }+ e! R: V2 X2 D# Q F
push 00 ; OF_READ: p* F/ |" O4 q, Y
mov eax,[00656634] ; '\\.\SICE',0
, x+ J* p; n, N M1 p push eax* Y1 A' x- F U# p
call KERNEL32!_lopen( `8 E' k1 G2 N9 m
inc eax, m4 M" v9 |0 p* E/ ]/ x
jnz 00650589 ; detected
& h* y7 q$ _4 v6 L5 } push 00 ; OF_READ6 R& k5 g1 o j+ d% Q
mov eax,[00656638] ; '\\.\SICE'7 S7 G- |* ^% ^ B# m) K# J
push eax
4 u8 P: _: l* W2 O9 \ y# k& h$ E, A call KERNEL32!_lopen
5 |4 q' h' a/ }/ c4 Y, ~ inc eax
1 a( n9 q; {1 E6 j, e9 ?, ^ jz 006505ae ; not detected
9 D2 A/ h% ]8 s/ T# f& K! W9 _6 y' ^3 y/ k0 U9 t8 D( ?
! k1 F5 {6 K; z1 }* U0 K j__________________________________________________________________________1 I" H. F; j* n. z5 m: [
/ T, n) b( \5 kMethod 12
7 c* b* ?9 w0 V=========
6 P$ Y/ x; x6 a' M: b x1 P: J7 _. T: b5 F& D# ?) ^% r
This trick is similar to int41h/4fh Debugger installation check (code 051 E, T3 @& b) _$ C. @- g% g* J8 N
& 06) but very limited because it's only available for Win95/98 (not NT)
& i: b- x4 a Das it uses the VxDCall backdoor. This detection was found in Bleem Demo." r# L1 U* L) x: J" `
8 G! j8 \) P$ ^2 w: K- K push 0000004fh ; function 4fh/ p' @- T$ {& v: q! s
push 002a002ah ; high word specifies which VxD (VWIN32)
$ }' s( Z3 d% Z' f ; low word specifies which service' y+ ]$ _/ k L1 S
(VWIN32_Int41Dispatch)( m/ s# R% k" `, A
call Kernel32!ORD_001 ; VxdCall
8 m: z" M- j1 N; a# ]; L* R cmp ax, 0f386h ; magic number returned by system debuggers
0 C. y ~! K( a* w& W H! N jz SoftICE_detected' w2 x a& _, E N
$ v- y* r6 |/ D- w; L' J
Here again, several ways to detect it:. [: f6 p. \% q
. }, M! h( e9 {5 R: N( e( V
BPINT 41 if ax==4f
" ]: G z' ]( `* `: w! X* s5 r: E5 H. e1 W
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
2 s, z+ v9 r7 z# n0 T- a4 I i! ?5 X
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A5 I4 E5 ~* ?7 L+ B) Q
( H# U6 M7 M: ~+ S BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
( r/ L: A& [# C: V4 s* O( {6 p3 H' P( p" _2 B' p9 R5 M
__________________________________________________________________________
) v+ Z6 P% z5 U
+ C0 O3 S, ~) f7 n- RMethod 137 d+ J. e5 o a& h+ M
=========
% h2 ^& @& R5 P; e1 p, P; {" C; w
, `4 v# d2 J1 v: o9 L: S1 D0 @Not a real method of detection, but a good way to know if SoftICE is* f3 g; a" q# E# ?" [) Z
installed on a computer and to locate its installation directory.8 I- B( l) M" H Q4 M e
It is used by few softs which access the following registry keys (usually #2) :: n/ ^ z2 B, c& l# m3 f
- B. l" B4 _* q* r. ?. u
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 r. e* p* v: k4 _5 N! t/ i+ ~4 C
\Uninstall\SoftICE2 V% v' M+ h( G* \; j) U4 R6 n$ _. T( s
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE. U' V! J' j' s
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
$ e" n4 y; e& p) u( A k\App Paths\Loader32.Exe
0 t2 h2 J. a3 r1 n# }) \
- S' f, g" D# |
& l' i g7 i0 D9 F! O5 o! [Note that some nasty apps could then erase all files from SoftICE directory) R/ ]; U3 J* p6 d/ P( H8 W
(I faced that once :-(
. N$ D. p% o. q/ i0 w9 I/ c
) @( Z. c" h6 [$ C: Q0 ?Useful breakpoint to detect it:
- Q4 \' p1 b T; i, v, v+ Y
( q5 ]# J$ n7 H1 u4 D- t& r% y" s BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
: h( x4 p, [( H5 Y5 S+ |& }7 V
4 Y2 w, i& y$ V2 @ x__________________________________________________________________________& _4 W" y* f3 O( R: G$ F, Y
6 @9 u- u5 p- z, M( L* w( a% J; q- m( s1 K- T
Method 14
y* {4 q, }4 p$ Z9 K/ ]=========
V# s9 t2 [. A& f. Z# T0 K; y. {3 W8 B$ l
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose8 \" g/ i# i: z0 B' Y( j
is to determines whether a debugger is running on your system (ring0 only).% X) W4 L1 |: q. R
0 l4 `' Q1 O. L9 F' C& ~; g VMMCall Test_Debug_Installed
8 ^: V( m2 E/ Q je not_installed3 j; ~3 l+ u" Q) ^
. ]5 Y: q% D9 B" R. m: [This service just checks a flag.
6 t/ p6 r5 a1 i( z3 |</PRE></TD></TR></TBODY></TABLE> |