<TABLE width=500>
1 E2 V$ b0 a! z! C7 L: M6 H<TBODY>7 o, e( s0 e5 Y4 n, M4 ]0 c: |2 D
<TR>
4 T0 a; J9 Y" T* x4 {<TD><PRE>Method 01 5 z' ]1 B. h4 n
=========$ c. W! L5 f3 @) L3 m, F" j2 b
9 g+ Q1 D* O }3 G; j$ |2 QThis method of detection of SoftICE (as well as the following one) is; U a2 y% w. |. q& E! S H3 v+ p
used by the majority of packers/encryptors found on Internet." h- ^& n! Z# a# i1 I* E
It seeks the signature of BoundsChecker in SoftICE" Y, {" j2 f) ^3 @8 F/ W0 [- M0 M
8 g: t3 a: \# r1 w+ r mov ebp, 04243484Bh ; 'BCHK'0 m) `3 w) I- }- W, X: V1 d
mov ax, 04h
8 C& d) ?6 b, o3 ]7 R( d5 |# E int 3 6 B: j* a5 `5 w2 Y
cmp al,41 e$ m" D$ a6 f, S% R P
jnz SoftICE_Detected
3 @* [6 G9 b5 p; }5 n4 w4 s
- g" L! n$ O$ E___________________________________________________________________________/ g1 i0 X `) R7 N
7 h: F q6 H, }8 ?& o1 U8 M
Method 02
% I. {9 }4 ]9 C- q5 G6 X* Z=========' U K7 g1 {, Z$ J1 _
, s7 S5 `2 u+ V/ _3 P# z& YStill a method very much used (perhaps the most frequent one). It is used
! U; e0 i% l4 A$ H% Mto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
5 l5 L) J$ u. s7 L% }3 j9 ]- @7 yor execute SoftICE commands...
4 J5 J& v1 N7 P2 ~0 }It is also used to crash SoftICE and to force it to execute any commands/ s* Z0 u) i, ^8 d: p, m- t
(HBOOT...) :-(( 9 r# I4 z, j& N7 d" t* y
& n) z' x% p0 n, e$ ^9 nHere is a quick description:/ g' `0 A7 G% B
-AX = 0910h (Display string in SIce windows)
* [9 z. ^! \. B2 Z! ^( L6 v8 P-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)" w, X9 e( L- [
-AX = 0912h (Get breakpoint infos)" X4 E2 T& H5 O0 |; I
-AX = 0913h (Set Sice breakpoints)
6 M- J) o) s' u, }. F. I-AX = 0914h (Remove SIce breakoints) Q! `' e+ w2 b! _
) Q* y, o) y8 ^/ `% I" y1 i
Each time you'll meet this trick, you'll see:' \0 e" \6 Y3 ]8 T$ q Y
-SI = 4647h4 k9 {; f& k- K/ F: K4 S
-DI = 4A4Dh% |( C* {6 S) [: Q, S
Which are the 'magic values' used by SoftIce., ^* ?! U* i$ K C
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
( R9 L! I% V/ \. |1 ]/ q4 I$ L& F- d' t: c
Here is one example from the file "Haspinst.exe" which is the dongle HASP/ @+ U* H6 H' a- g) P
Envelope utility use to protect DOS applications:
r9 A# E7 G& ?
( Z& r' {' L4 @2 ~. m
# Y! O) d# l0 L+ |9 Y( t4C19:0095 MOV AX,0911 ; execute command.9 ]# e* |" O# ~7 Q% _% E3 c: `5 ^
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
7 t! b2 U% C3 I2 h' M' X7 o" i4C19:009A MOV SI,4647 ; 1st magic value.$ c/ ~8 C& B0 b4 [9 T) K# l
4C19:009D MOV DI,4A4D ; 2nd magic value.# {6 G5 E7 k# U
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
8 C5 q) v; e* W; J: ]7 |4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
$ L, ?4 S* i4 b8 K, K% p4C19:00A4 INC CX' q9 T5 A* g% x
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute: {. L7 l5 D# K Z
4C19:00A8 JB 0095 ; 6 different commands.
7 f4 h9 k7 a8 h) d; r; f4C19:00AA JMP 0002 ; Bad_Guy jmp back.4 K7 n. t O3 L
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
6 A1 T* x* V! F. B+ ]: M5 z9 W: m0 Y- M* E' u
The program will execute 6 different SIce commands located at ds:dx, which8 p, Y4 d# L8 a7 [. p1 x2 W
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.! Y) a- L% B& q0 ] O/ s! s, N4 J1 M; ^ o
C* b, |3 Y" d' D9 a* i; b3 l& K, m* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.* T8 P% H8 g, _& Y
___________________________________________________________________________
, Z- M p, b' ]. b. |1 [' |7 W1 `
! G( x. J) {" E% D% S
( t: X8 B7 C- ~9 ^' [- \: R! |3 dMethod 03
* s) N+ j/ C: @8 y=========
/ D; }; J8 f) D* E6 h2 [6 C6 J$ |4 p9 C" ^% M6 f8 O
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h3 m% T) o$ }4 j# T
(API Get entry point)9 U; ~1 g: I6 |
4 K0 P; j: v* e; H5 @% L1 n
( w" c$ u4 g, e! \& k# T+ } xor di,di
2 i9 Z1 W5 t( D' n! V* [3 C5 ? mov es,di% b$ w; |$ s3 p$ F, Q% N
mov ax, 1684h 2 w5 v. G5 m# M' S" S
mov bx, 0202h ; VxD ID of winice+ G! D1 i. U9 ]. K4 _
int 2Fh
Y# l4 K$ ?0 D3 I) D mov ax, es ; ES:DI -> VxD API entry point6 e- h/ ?' d6 h! w: A n
add ax, di# e) Z+ ?' @+ j# K5 @% o+ k
test ax,ax- W7 c3 L$ f" ?& F# a# \# c
jnz SoftICE_Detected g) P! L7 {4 c I) T" i/ v% C
4 s$ e: v! V" m: @
___________________________________________________________________________
. w- c) K9 @; m# _9 I+ ]- O4 |8 ?7 K$ ^% e+ ~, v2 \
Method 04
1 \7 Q5 M8 v' q8 k: D=========3 O) Z9 D0 }% K6 t
0 B2 v" q; y/ L4 L9 VMethod identical to the preceding one except that it seeks the ID of SoftICE! _* B8 e$ `0 v J: V5 b
GFX VxD.
4 T/ F: G( ?) D+ x$ X( c- q
4 M0 L# a6 e# \) A xor di,di1 K6 ^3 F) q& p& a
mov es,di
1 E/ P7 j" B' g& D3 \* q$ H mov ax, 1684h $ \2 Y. ]0 n; O& f/ a) l2 s
mov bx, 7a5Fh ; VxD ID of SIWVID
( F( A, G2 y6 o: H8 F4 x; s" ~0 c% F" l int 2fh
& b! Z$ W4 e! I- v$ p- ` mov ax, es ; ES:DI -> VxD API entry point& U' c" L, d" U
add ax, di
' u7 A; w# q& t" O- I! X! @5 w test ax,ax
% s/ b- ~% K i% b! ]$ @: q jnz SoftICE_Detected/ u1 q( F+ c, z4 b
: W7 z f" Z( \( y2 P: Q. s
__________________________________________________________________________
/ }7 z+ l# i9 q5 K& q$ X' u* i r9 j
3 Z. C j% h X1 ?2 m$ }Method 055 \! ?) O3 k1 c9 z, h; y5 [: N
=========) z& e" S* G1 S% m4 \4 D+ C
. s& A8 b% V# U `
Method seeking the 'magic number' 0F386h returned (in ax) by all system
, |5 s( a/ u1 Z- u& P1 l! x) Odebugger. It calls the int 41h, function 4Fh.
( w9 J4 p# n7 m6 ?2 \8 I; PThere are several alternatives.
' M: u6 ~1 t- ~% u0 O! i7 o, M6 H% q' a+ d/ k- n5 @! b
The following one is the simplest:. _7 A9 K6 o9 O: _# a5 R s- p
3 p9 Q+ F6 R# d! d6 P
mov ax,4fh
) b2 ]7 p% q, l: b, o int 41h) F& P1 b: \! j
cmp ax, 0F3865 N o+ v2 t& D2 K4 @4 O \8 x0 U
jz SoftICE_detected0 w- a" P% r W" y5 ?
# w* o/ z- m2 x
5 m) Q- W% Q$ y- x( H" ?& vNext method as well as the following one are 2 examples from Stone's
3 p3 Z/ G( f* A"stn-wid.zip" (www.cracking.net):
3 }# ~4 O4 K9 {* P& S- u9 o
. x" q) v4 ]5 v) C9 ] mov bx, cs
8 h# ^: d! F" H4 U5 R$ B lea dx, int41handler2
; C( |# R6 B$ \5 G' `# ^: Z7 @ xchg dx, es:[41h*4]" M% P* \1 y& Y9 s3 Q
xchg bx, es:[41h*4+2]3 T, q7 v4 R+ t5 V% ? w
mov ax,4fh
; Z0 J- s- Y# ^ int 41h
4 K4 x+ |6 z- N7 G' y+ h xchg dx, es:[41h*4]+ }1 I9 B' }' u6 r. _
xchg bx, es:[41h*4+2]
. J8 c7 B4 e' b% o- X/ } cmp ax, 0f386h
# K4 G2 D2 W; ]$ i) R jz SoftICE_detected/ R3 B3 J) }" ]) g) g n
$ J' w8 _# ~+ t9 Q% t8 Qint41handler2 PROC
/ i/ V- S6 \% S iret
# `2 u5 F t) n U' u# Aint41handler2 ENDP
$ @: P. [* \ N. @3 _4 h" @+ g8 ^
7 w6 v, k1 m; w f5 C
_________________________________________________________________________3 O7 ]: n2 }! t+ ^; j" W6 G
% R& [' T4 ~5 U* @
# { \* n2 t p% m; ?! xMethod 06; ^% |3 ~& b' l/ f- Q# h
========= X) U# H9 J; [ Q- ^
% [% e, p* M) J1 W H, @
5 l) D1 M8 ]5 i& e- [0 w v( b% I& L2nd method similar to the preceding one but more difficult to detect:
' S7 C0 V: W: D# q( v: c# r" p2 A) W
7 w4 C" J4 t0 ^
int41handler PROC( L0 ?8 h+ `/ P3 t2 ~$ R9 m" g
mov cl,al
* ~+ r6 M( b X! n iret
! E" ^; \% e5 v& ]0 X" ~int41handler ENDP
# A( |6 i; J! p/ o7 V
4 M0 U6 c6 Z- G1 j" e* ?9 b$ V9 ]; \9 p" \& |* g; S
xor ax,ax% K$ k8 p& A- Y# b, r
mov es,ax7 [/ V F) l9 I$ i
mov bx, cs
- q' a2 K4 [ [: ]; s lea dx, int41handler; L- F* Z: g1 w* A6 e8 }
xchg dx, es:[41h*4]
5 X4 P$ p; R# U' Y9 n xchg bx, es:[41h*4+2]- Q4 ]" { F* E* X0 B8 H* d
in al, 40h( Z2 u& Q1 m( X
xor cx,cx# B8 n! W& h1 }) R, }" X
int 41h
! C! T, @6 [7 L+ k) B6 l K xchg dx, es:[41h*4]% r% T6 ]5 }0 s- b/ M% `/ l
xchg bx, es:[41h*4+2]4 g3 c, k8 q) C2 \5 c! L; @
cmp cl,al; D. l' Q& f1 N! i8 }0 P
jnz SoftICE_detected, ?1 ]: Z! @5 h" s8 m
- G; R" D( _) ~9 }7 f
_________________________________________________________________________ _4 s9 d+ g6 E# @, k; r- k$ H
; ^: t, @8 p) Q4 R' N# Y0 G
Method 07
: `- `4 a: T* ]=========% ?* B2 H. `1 W: O1 J9 d
$ _( G! X. [0 O2 GMethod of detection of the WinICE handler in the int68h (V86)
8 V J7 E3 ?! t( w$ y3 }; Q) _: ^6 i; K6 X% k2 w8 M! W9 ^# P- ]3 H2 D- R
mov ah,43h
8 z: w3 H$ U C+ I! c$ q, | int 68h1 l* T2 K* k# I: e! e/ o
cmp ax,0F386h7 M$ ]0 z, f- V2 H
jz SoftICE_Detected/ v9 ?# @/ v2 [( T( [/ O x4 h
8 \" @ b7 \9 l) h$ b
' V m, o" P( ~' D* D( s# L=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
, |; y) v& _: X/ m5 O+ [7 e) x- ]- { app like this:' [( R, l5 S6 L _( o7 w
- q& K4 h5 z9 x( D K8 ?. ^
BPX exec_int if ax==68
1 ~. q" ^' T# l1 z6 o. g (function called is located at byte ptr [ebp+1Dh] and client eip is
$ Z, i+ H; u, F7 x! N/ ?1 w located at [ebp+48h] for 32Bit apps)
% r/ `' k4 V4 h" Z% g2 a__________________________________________________________________________: X1 D7 S, q6 k. Y3 j& S, n' N
! _. Y3 D2 I, P Q4 P
2 G! f3 r" m+ T/ r5 o. B3 t& \2 d VMethod 081 M: N$ B; y: j1 I4 q# L$ ^
=========
+ e0 f4 ^, w6 ]! ^/ _" j$ }
% D6 U0 ?5 u% S1 X2 k' `It is not a method of detection of SoftICE but a possibility to crash the `1 l# w& ?( e8 k, i" H/ e
system by intercepting int 01h and int 03h and redirecting them to another* ^! \: q8 l9 Y3 z( A2 ?6 ?) x1 K4 p
routine./ M# H y: f" Q; }
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points9 X7 V$ c! i/ ^0 ?4 h
to the new routine to execute (hangs computer...), u& y5 n+ `& ?2 h% Q1 Y
# I' T5 W" ] F8 U: Q2 \% } mov ah, 25h
$ y2 j% c7 \# I% C$ D4 p; D mov al, Int_Number (01h or 03h)
& U: E' g: e4 R$ p4 B mov dx, offset New_Int_Routine
! N, Y* Q- H" |. X( z int 21h
/ d: T" {! I$ v" @( O' M2 ~
; z1 E: X4 T# W; }__________________________________________________________________________/ D( B3 I1 J' C8 d
% Z( r+ y0 G2 J/ D) HMethod 090 e m# w' @) Y: u6 w
=========; u2 _6 Y. o6 e4 r* c- T
- l, L" }! N* S) q0 I0 h5 w$ s
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
& }: ]' C5 z6 l7 G" t, C0 yperformed in ring0 (VxD or a ring3 app using the VxdCall).! Y! }# _& p7 h" v
The Get_DDB service is used to determine whether or not a VxD is installed- e* l( y+ F% R& |! q
for the specified device and returns a Device Description Block (in ecx) for* o5 n; _$ J' V" [7 J# g
that device if it is installed.: v I/ F2 }/ a* @: [! c4 ?
) G9 `' o& d1 [9 V/ s3 R# Q* w3 Q
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID% D, I# u, f; X& M6 H" s
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
8 c# r( t! }9 L& e" X VMMCall Get_DDB
* p j8 F1 F4 ?7 M8 D H mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed7 R7 {7 _5 h; |/ B: e
" |7 j5 M7 ^! Q
Note as well that you can easily detect this method with SoftICE:* \4 y i I% E3 g& a' y4 G
bpx Get_DDB if ax==0202 || ax==7a5fh8 l. a+ ~3 h) y' `
4 p- s1 G N; V: Q& c$ Z9 }
__________________________________________________________________________/ S/ _" s+ Z( Y9 G, o; R
" V- s! W- Q9 e1 J# c1 r4 XMethod 10* i1 P) J5 I/ d j& y9 N* Q9 X4 K
=========
' \9 U) C/ K7 n; m- g$ l% A) t# J. A% I' u( N
=>Disable or clear breakpoints before using this feature. DO NOT trace with
. t5 c; n- A: ] W7 M+ B. W SoftICE while the option is enable!! X+ Z: A h7 P$ |5 I
6 z. G- Z# v! }5 \, J1 vThis trick is very efficient:
" L1 |$ M" j' B* d, W" u( cby checking the Debug Registers, you can detect if SoftICE is loaded8 L. f" C! q6 w2 s; f* n. G
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
! C- f* p) {7 lthere are some memory breakpoints set (dr0 to dr3) simply by reading their! Y0 j3 ] ~( c$ h' T3 \1 n
value (in ring0 only). Values can be manipulated and or changed as well
" u( V9 }* J7 P, J. y" a& [7 z(clearing BPMs for instance)" L$ H- A; \0 V1 I. M# u! [- H
0 b. O) X8 Q5 U' P) S& N__________________________________________________________________________* R0 y: z- F9 P
! W" p, ]# j3 p
Method 11
0 H# ?) H0 I& `6 K3 N=========6 c5 I- S2 M' s9 u, u8 O
: T; X0 W$ D( g
This method is most known as 'MeltICE' because it has been freely distributed
8 Z' w0 g: W, {' r. \! b O3 p9 Uvia www.winfiles.com. However it was first used by NuMega people to allow N" @/ d3 _+ d) X7 [) e
Symbol Loader to check if SoftICE was active or not (the code is located
* S# i0 Q1 `3 P/ X3 A8 Dinside nmtrans.dll).
0 {/ |: m o0 l' k; F- @5 C B9 c) r9 R- X. V
The way it works is very simple:7 n7 u/ s* B+ l8 \$ D; F
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for# X4 b" }! W9 M
WinNT) with the CreateFileA API.6 y: p/ p! F! l- Q: Q1 t. b; V6 [
; N. E9 F: S+ w( Q7 k1 c+ _4 R. s
Here is a sample (checking for 'SICE'):
3 u+ R1 ?# p3 D: J G
8 }/ t* u* O1 S4 O" ABOOL IsSoftIce95Loaded(): g. L, u0 X$ E3 N; L
{
: `; D* |! _) i5 E% ? T6 Z5 e HANDLE hFile; : ^$ B0 s6 c* f3 p' w' o
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
! S: w p9 H7 V% i, C8 | FILE_SHARE_READ | FILE_SHARE_WRITE,/ a; x0 P% u! U7 p- M8 a2 ]( H, H6 d
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);. f$ F' ^" K1 |
if( hFile != INVALID_HANDLE_VALUE )
, A% o Y; j! E {
# H1 }- N) a% T5 j( f% A) F CloseHandle(hFile);& _' j# m$ E$ l1 j6 V: e( M% t
return TRUE;: y- A# i& G' g) x8 g# C$ g9 A
}0 U5 M. I8 f) _5 y& c3 w+ `
return FALSE;
$ h4 j5 [1 N% O4 |}
- T2 ?. b. T. F6 a( @' ~' g D- J1 t" A3 N. P8 }6 n9 ~+ s& A5 Z
Although this trick calls the CreateFileA function, don't even expect to be
" ]4 T' D& S4 N, Gable to intercept it by installing a IFS hook: it will not work, no way!
. W& r( M8 u! O8 SIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
7 F0 l- E' o8 F& m. bservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function); G. j' \. g8 {' K% |+ L
and then browse the DDB list until it find the VxD and its DDB_Control_Proc; F9 d+ D+ A' P
field.2 T8 c- w R3 a
In fact, its purpose is not to load/unload VxDs but only to send a 4 L c# t0 Y6 ^) \' h$ e
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
' B5 `- R* u6 W' s9 Sto the VxD Control_Dispatch proc (how the hell a shareware soft could try
5 U! j% P) v6 r: r- x( hto load/unload a non-dynamically loadable driver such as SoftICE ;-).
, ^. V( s5 V4 `, J0 GIf the VxD is loaded, it will always clear eax and the Carry flag to allow$ U! V+ N# X- K/ @
its handle to be opened and then, will be detected.
- w5 c' L* @3 A* \6 C3 MYou can check that simply by hooking Winice.exe control proc entry point
* `- [9 I0 ~% s9 S! P% Rwhile running MeltICE.
1 H4 F$ X/ M5 e6 \0 u7 U& l/ w6 c1 h& t8 j4 r" M( P
! H. G4 H- h4 ~. l# \' U3 B. j
00401067: push 00402025 ; \\.\SICE" w2 z- R# P$ I6 }/ I! n
0040106C: call CreateFileA
" {$ k* O* u, X3 h 00401071: cmp eax,-0015 i3 D' C/ G* {; e( t
00401074: je 00401091
) L( w1 n( ?! q
: G) [; K: i+ W7 }8 d" ^4 J# Y% A# Z
; L; e$ e/ b R' mThere could be hundreds of BPX you could use to detect this trick.$ ?) W2 B# x$ Z, o, Y6 e }3 l
-The most classical one is:
- y1 T9 |; |! y8 p BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
' h: ~: k0 S. ~+ k( k# s3 N6 | *(esp->4+4)=='NTIC'
& e, Q. s3 |! \6 a) U1 S( P; Z; R4 W/ Z) Q+ k' p
-The most exotic ones (could be very slooooow :-(4 K8 e% w$ _9 o4 K; j5 ^
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') ! |7 k5 |' h' y' Z5 B6 f
;will break 3 times :-(- t- u) p( |% v) X$ h& }% Y% U
, D- ^, X `+ n/ ]; n1 r' v
-or (a bit) faster: $ S" L( ^: Z, J5 W
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')' L3 N! t/ I6 D. L$ p6 a/ N* m6 y4 X
" T9 Z% }5 A0 J# a BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' / X$ h* M# F0 n+ P4 B, @& s( \& Z" i8 x
;will break 3 times :-(% a4 ?- g: Y) l O
. w' Z2 L+ u8 B6 k% D# [9 J
-Much faster:, N! w+ H! D" ^' U, @
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'$ Q. e( L8 D& ^
# c1 O) Q, O' b1 d
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen+ h- N$ j0 e1 v. R' `8 ^
function to do the same job:
) _" k$ X+ }" r3 [4 A) _; E$ P
push 00 ; OF_READ0 i. B5 X4 E: n. o* N s+ m0 u
mov eax,[00656634] ; '\\.\SICE',0: Y0 ^$ T& B* E$ k, v
push eax+ B: S) P# I( H3 X5 Q X
call KERNEL32!_lopen3 J4 t. R$ z& T5 ]9 z9 G
inc eax/ |5 ~. N. K+ Q F0 p; g$ z. s
jnz 00650589 ; detected
" ~3 } c0 f0 ?6 D$ X2 y. p7 d push 00 ; OF_READ6 L( }( n* G+ B* W7 |8 S
mov eax,[00656638] ; '\\.\SICE'8 U" G/ s3 C7 d* {" }4 _ s; z
push eax
5 Z1 r: K2 ` l7 ~7 d7 m call KERNEL32!_lopen
; r: H y8 u& a8 a inc eax, z& } k+ B3 O& d, A" C
jz 006505ae ; not detected
; b* T* e2 S8 D& a% D7 h
$ R! Q) _& W& b
* l) r: x& R; p' p2 \__________________________________________________________________________
+ i/ S$ v( o9 Y# B9 {8 a. E+ `3 Z/ f8 g
Method 12
4 M& ^9 T( A' ^& p; G% P6 r& g p=========' z9 N0 |7 L3 t1 R0 g# g7 G
* u: ]1 ~3 i( H
This trick is similar to int41h/4fh Debugger installation check (code 05
) Q" Z0 i0 p$ d' V& 06) but very limited because it's only available for Win95/98 (not NT)( q3 K) d6 u E
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.8 n/ S; g1 G$ J7 f4 b
* ] }. m/ ?3 F+ x' E
push 0000004fh ; function 4fh
. Q7 ?3 d) |# ~0 T6 [% C push 002a002ah ; high word specifies which VxD (VWIN32)
+ q/ M0 t% e5 Q# S0 f. ]9 @' o ; low word specifies which service
2 j# M; L. |( D( f" z (VWIN32_Int41Dispatch)0 |& m4 p* E7 }$ n. p. g3 ^5 C
call Kernel32!ORD_001 ; VxdCall9 b" @% @/ Z: M
cmp ax, 0f386h ; magic number returned by system debuggers
, {- l1 y3 L: U2 c+ v G( N8 v jz SoftICE_detected
, T, M; b3 ^" l" a: l+ P
+ X8 M# x- L' T$ hHere again, several ways to detect it:
/ _* D+ j s' z5 O: o, W* W5 n4 T" g- q$ ]$ X: ?& V
BPINT 41 if ax==4f) w5 [% a2 K. @. z1 P2 ?8 x; {
" u2 t8 D8 X) [$ C& c
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one* i/ l e a* _' X5 @ e2 m+ X
) k: C" S, O# I, Q BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A2 F) N1 d. |) G$ ]! G' k; f* _0 T" \
* o9 w5 a0 t% }! `2 q7 t5 i; q; u* j BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!! G$ b+ x" M# `% A# O! G% V
2 r4 t% _5 `6 t4 ~( T/ L0 v# R
__________________________________________________________________________" f4 ^* F$ |4 f$ c7 {/ U
* \% c! T$ T" } VMethod 13
. n# w9 y9 C; c) F1 x=========
- Z6 k0 M" t2 l B& |
' z" i, Z' u( U6 ^Not a real method of detection, but a good way to know if SoftICE is- h+ {, P* V; V, b% R( A) V
installed on a computer and to locate its installation directory.: Q/ S6 Y/ Y1 |3 U+ H
It is used by few softs which access the following registry keys (usually #2) : ~, r$ y1 y3 I7 D& t$ q/ x7 T
/ E. K- m" ?3 v, A-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
! ^* H+ P2 @; D4 y4 G! O: ]\Uninstall\SoftICE; i, @8 O/ F; M% H" k6 z5 ?6 _5 y; K1 h
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
9 r( {8 o+ f4 H" t. h4 f% X-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
5 l" g& ?9 W3 b$ \6 D3 w5 `- n\App Paths\Loader32.Exe
% f9 u+ I+ j+ `: ^7 @( Y/ E6 S T* Q% K# t
8 m9 X: ?- w. ^3 |$ ]
Note that some nasty apps could then erase all files from SoftICE directory% A6 [1 B5 t* @0 K2 _6 M5 @* i1 } h
(I faced that once :-(
+ ~. N, i6 n" ^' i c3 D5 l
' K8 y) u/ Y4 h8 `; C. C5 s3 MUseful breakpoint to detect it:
* V. | W3 K, h' T, @- d3 Q3 m
: _( \) u$ c0 U( C U6 G8 c BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE') l3 B, E' ^8 d/ Z
1 S0 ~% d+ d3 x' P6 A( T7 h
__________________________________________________________________________" T0 S4 N ^# y. ]) z8 `3 ?1 q* ]/ O
% H, n/ K6 y `- t+ |5 Q6 I6 U0 ]2 \& R# d) C% l! M7 t
Method 14
, J! ]5 Q# v$ O! n=========5 H% K, y. r1 Q6 A* t8 z ?
; ^. p% X. ~9 {3 ]
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose: Y- I/ ]" R* j2 _
is to determines whether a debugger is running on your system (ring0 only).- z+ T( l Q$ |" G! C& {- b8 F
6 l2 a9 S: ]* a VMMCall Test_Debug_Installed# W) a3 T, ^" |! }2 o4 Q. b
je not_installed
, M- q5 A$ J6 W' ~ H
3 h" J% W8 E" {4 C; Z: d: `& lThis service just checks a flag.
4 {/ t7 i# K: l/ u& D3 }- i( z</PRE></TD></TR></TBODY></TABLE> |