<TABLE width=500>
( J/ S# ?7 G" ~* p1 W<TBODY>* I5 l& |0 f; B1 N( z, D Z7 W* f
<TR>; m* w1 c# z2 O! Q0 g
<TD><PRE>Method 01
1 }# J t+ b0 V3 ^; j=========+ Y3 P8 |; V, {
6 G! d0 |: C% `3 e9 FThis method of detection of SoftICE (as well as the following one) is
5 w n- |$ V) f; jused by the majority of packers/encryptors found on Internet." v* l1 G( m. I) X7 n6 C
It seeks the signature of BoundsChecker in SoftICE4 D4 p1 R. y/ u$ u; y( {. h" o
: [/ ~' R$ _( @# y mov ebp, 04243484Bh ; 'BCHK'9 c6 h; r$ i* t! H/ l; E, I
mov ax, 04h
# C; F! V* O: e0 E int 3
v9 ] k5 u/ p6 O) z cmp al,4
' U% h! }2 D/ }1 _, f6 U jnz SoftICE_Detected5 E" |, K% A8 w2 X
) s$ l8 d8 w$ J, J4 R
___________________________________________________________________________# K! N- S3 H" ^ W4 p
) z& {* F2 G* t$ tMethod 02
7 a- ?3 [, h3 P=========
$ k) @$ L( Y; Q( j' U
% ~ A5 n% ]7 W k. E0 YStill a method very much used (perhaps the most frequent one). It is used
4 k, o/ G# }. ~to get SoftICE 'Back Door commands' which gives infos on Breakpoints,4 C6 m- }3 m" a0 p0 z" @
or execute SoftICE commands...- H2 b8 V2 C! ?+ z) Z
It is also used to crash SoftICE and to force it to execute any commands# I) U$ f7 _6 N! M% O: t0 j
(HBOOT...) :-((
! c+ A! h2 ]5 v9 u7 l- f) ~3 S m( ^; |) k* J
Here is a quick description:, B1 X" Q5 W, c0 j M9 c8 w
-AX = 0910h (Display string in SIce windows)/ Z" H, @( c( I8 A3 ?+ C; {6 P1 L
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)' d* f `; P- P; k/ q, S2 y
-AX = 0912h (Get breakpoint infos)% [: B* Q" @2 F9 {5 @. _. P
-AX = 0913h (Set Sice breakpoints)) Q* p4 H2 ~' B# d: V
-AX = 0914h (Remove SIce breakoints)9 N+ y" h5 [5 {
$ w9 w4 {" S9 R6 wEach time you'll meet this trick, you'll see:$ X- u% i' D" M. U
-SI = 4647h6 R" t, c, _& h( C. [* |2 q# {/ Q! r
-DI = 4A4Dh
q( ~) l1 u. c, CWhich are the 'magic values' used by SoftIce.. ]# w8 Z6 Y$ [4 c" ^
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
* U; ?. C/ w$ t! f7 H' e3 e" u) A$ T/ R5 c V9 S
Here is one example from the file "Haspinst.exe" which is the dongle HASP9 Z- _1 w+ L: A- Z$ h1 m9 C
Envelope utility use to protect DOS applications:1 F& z! H$ L9 \4 j3 Q4 K! c
' }- ]) x+ ^* p/ T
9 z% v* |9 G( c/ f! L# M% [' G4C19:0095 MOV AX,0911 ; execute command.
* m: ^3 F4 G1 U. R% ]4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
0 f0 @$ {# O. u3 V0 U4 B4C19:009A MOV SI,4647 ; 1st magic value.: \$ l2 m4 T8 i
4C19:009D MOV DI,4A4D ; 2nd magic value.
* E7 r' v9 {) [7 [6 F4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)6 W& g& W3 r8 f& w7 Y$ G
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
! D$ O0 ~8 G* \9 M" y7 R* k4C19:00A4 INC CX- B2 i# S0 o2 ]) r
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
8 Q. c7 O) Y. ~# I' p4C19:00A8 JB 0095 ; 6 different commands.) w: o3 S3 X' e9 u9 L- l0 K5 X
4C19:00AA JMP 0002 ; Bad_Guy jmp back.: f. F8 o9 F/ F
4C19:00AD MOV BX,SP ; Good_Guy go ahead :): x2 N5 l- C0 |$ B( ]8 D1 m% J' A+ y2 z
9 V( R0 _8 K; N) Z" C
The program will execute 6 different SIce commands located at ds:dx, which
1 ^: e; Q/ m7 K7 q5 S5 \are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.8 S* L, ?( W& ]8 C g& P
% i f8 i2 z& r
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.* G W0 Z4 [5 r" l* i: U; K
___________________________________________________________________________& {% B- \; l5 k/ p1 ~% a! r
1 m& ~+ C+ X% Z- f! n S/ V
7 u% d* y! Y( E8 b4 O3 y& F- `2 G
Method 03/ Y4 ^( _. }, U0 p: n4 C( {
=========/ ~1 R$ K8 f c" A" i
c Q$ n* Z8 g$ R2 LLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h" N2 S) }1 w2 A+ j; _
(API Get entry point)- M8 z$ r, B8 \4 d
9 o5 w2 m h$ A: j2 z1 L A& i. n9 w I' w
xor di,di3 k9 I% }! ?4 t3 Z
mov es,di* O7 x) c$ A4 ]' V$ V$ F- Q
mov ax, 1684h
+ @# [1 p' R/ @* F& O- _; j mov bx, 0202h ; VxD ID of winice
1 c1 j- m4 x4 @% [1 O$ K2 Q& a int 2Fh* y" x b f6 x ?+ ^8 v5 I7 g! A
mov ax, es ; ES:DI -> VxD API entry point
& g9 ~/ A7 `$ p2 q2 f" z, Z6 T' T add ax, di
' I& c* D7 [( Y2 ]# Z/ Z! O4 y test ax,ax$ A3 b9 B' |( ?/ N7 ^
jnz SoftICE_Detected( M: B, \# d9 D* L9 ?
$ H8 ?2 n" H# I3 \* z" d0 u5 |4 n3 G___________________________________________________________________________- v# j- B. y) u4 G3 _
% D, B5 l# X! G3 O1 Z
Method 04
/ {" H6 ?+ d& c9 h( G3 h" u% G3 I) r=========
$ |# h1 w4 z! X1 P5 n) E9 t0 K# H: n& ?/ y
Method identical to the preceding one except that it seeks the ID of SoftICE( J8 a+ F$ S# ]$ v6 X0 ~
GFX VxD.8 i6 S1 s" p; ^- J
9 _5 Q1 a3 C S% B+ O+ Y, S1 h. T xor di,di ?0 e b3 _; Y6 P. g; L! J3 F
mov es,di; a4 r6 E% J$ X7 B, w
mov ax, 1684h 8 p7 O6 D& K( g( a: n% c3 ]" w
mov bx, 7a5Fh ; VxD ID of SIWVID
) f( X9 M& S3 p2 E int 2fh
! q! ~7 H7 W9 \0 g- J) ?0 V( C mov ax, es ; ES:DI -> VxD API entry point! u% }- R# E z! M8 _
add ax, di4 k6 a }' f% g: p; a: {
test ax,ax
. Q8 B8 g& u( |7 ~% d jnz SoftICE_Detected$ l& h- x% B# A# B6 g6 c
1 h C, \) G% y1 C, F__________________________________________________________________________) ]) E8 l) a7 x5 F! I! d
2 a2 y5 y! X8 O" s$ [
: a# K. Y% \+ K8 m0 e/ n( C! @+ m UMethod 05
& x$ p8 p* R% X, D: r9 T4 P=========
9 A/ C. T# R5 X8 p1 i# e! N
3 K# |4 }8 F: v6 z1 oMethod seeking the 'magic number' 0F386h returned (in ax) by all system; n. f. D4 L. @
debugger. It calls the int 41h, function 4Fh.1 V, N& r# x, B* ` H* D8 ~
There are several alternatives. 1 Z; z% z0 [5 A I, Q3 c
7 W9 ]: w% g9 Q& ]) w; m z4 Q' y
The following one is the simplest:5 }. l" e0 S C3 d2 _% P F" K
6 ]0 [( D" ]0 B: W9 X8 {! p mov ax,4fh3 ]4 e) L- k# _; c. p, v
int 41h' p. I. `" |) N7 W/ Y7 _
cmp ax, 0F386
/ Y4 x7 `: N8 K3 M; k jz SoftICE_detected
7 d, n$ S. R! q: E# }
# g, f" ?% p0 L) ]% N2 w, t. |7 w% j" z
Next method as well as the following one are 2 examples from Stone's
; `6 _3 W( [7 w9 r4 t"stn-wid.zip" (www.cracking.net):
; `0 a s0 U! F* a p1 G
; S. m) l' I; v mov bx, cs
% u6 m" [& m2 g3 Z( N( m! U lea dx, int41handler2
! [6 d+ r: X/ j6 b4 L( H2 K xchg dx, es:[41h*4]
6 f5 r# C- A% A, \/ x( y4 e! |$ v- U9 F xchg bx, es:[41h*4+2]
/ J' d& I2 {/ t7 R; [ s2 { mov ax,4fh, |# I3 U3 o2 \1 b5 }4 p9 t
int 41h
4 b) V/ n3 [! I& m( D xchg dx, es:[41h*4]
" f+ Z! P8 ?- k4 [, p, W$ }1 P xchg bx, es:[41h*4+2], U3 v# F- h7 B' x0 i3 x5 E- i5 P
cmp ax, 0f386h1 D/ d* e. L9 l$ E3 Y+ e
jz SoftICE_detected
/ c" y6 p9 s/ T1 r+ L+ [+ g1 \! m( p$ ~. T4 q. t+ g
int41handler2 PROC
) X$ G; h4 P# h4 V1 j" r2 C iret
$ W W! }( ?4 {3 i* i: Fint41handler2 ENDP
- q9 \. ~& q; [6 R
+ [2 X8 |% T" i) g8 ^9 X8 `# ]9 m: B3 A, }; |: E" c
_________________________________________________________________________
" K# s! D/ |. g% B7 n) m2 U, v' }$ _$ b+ A$ K- n- r( y, a
4 ?$ ^8 B/ q9 ]) l) YMethod 06$ v9 _( `- f0 o% q# e& [# d
=========+ T$ o; [7 x, r' d/ q8 r
, V5 k8 ?! {3 U6 `2 a3 }) ?
; y+ j1 r* X0 k: e- W
2nd method similar to the preceding one but more difficult to detect:
/ |! k4 M* S# h3 k; d! l; R
) v- @7 p1 V f9 n: V/ @, o8 Y$ v" d0 v
int41handler PROC5 l, u/ _+ r2 n- C3 I1 ]- y
mov cl,al
3 t- y+ ~& I6 ~' D1 j* z iret) m% |9 D# _3 h3 t- C6 j2 l$ e
int41handler ENDP
Y2 L: T" ?1 }; t
) I' V& o, f K! I6 C8 |- D, r: J6 ]8 x: k& i
xor ax,ax/ v! D' @+ O% C3 R
mov es,ax
5 H. s) F4 O0 R; m mov bx, cs
a* s: u, ?& l* k lea dx, int41handler
( u$ h. p# _/ o2 }; b xchg dx, es:[41h*4]
& h; L# e# B( B, \ xchg bx, es:[41h*4+2]
3 y( h* j* L/ r in al, 40h
0 {( N2 s/ \' \ c xor cx,cx
; ]8 T1 J3 t% U, m; I8 ^ int 41h
* t: t ?$ u0 u7 E& m+ t9 d5 @, R7 _ xchg dx, es:[41h*4]
9 c4 Z; G6 C# }6 s! V7 ] xchg bx, es:[41h*4+2]
9 r7 v# ^9 [( l% g* S$ f/ I7 Y cmp cl,al1 F! h* ]' K- |1 d4 m
jnz SoftICE_detected1 q7 X+ F7 F- I5 \7 u( K5 Y
0 A- ?3 U8 N+ L) _
_________________________________________________________________________/ \* X, t" |( ?, w O! m ]0 `
6 m8 f, p3 g2 \: {$ QMethod 07
- {2 f2 q! i6 f: ]=========
; b1 K# k6 m- b7 }$ U) v! |
; a0 P5 Y: o" Q$ t& a' @Method of detection of the WinICE handler in the int68h (V86)
/ F( ~- Y' [8 {: O( V
$ j+ Y3 M) j* G, y$ [" P* Z* {8 | mov ah,43h
4 P# w9 o9 g- \+ k6 Y5 }1 S int 68h& s" y3 Q! N. R& x4 F* |
cmp ax,0F386h
; N* W$ U& ?' b( ? jz SoftICE_Detected; G9 p' C7 A3 E2 N6 i" J
$ z1 l7 p7 ~% u$ J5 d! G
, A. [6 M& I( {2 D=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
4 _3 a+ r# |/ h2 w2 f app like this:2 t( ]' `- s: p
0 u# x# Q4 d( k$ d) G! z/ z/ Y" l BPX exec_int if ax==68
& g8 U! g7 w2 l- |6 y8 Y2 O, S (function called is located at byte ptr [ebp+1Dh] and client eip is; d: ?+ N7 R1 m) u4 u& A+ a
located at [ebp+48h] for 32Bit apps)
6 W# F9 @& q* i__________________________________________________________________________
2 ]0 M5 c/ y; p8 ?* d3 Z S3 M, C' l& F6 M2 w
& k- `! U$ g" y8 Y6 r, Y Y
Method 08
7 D r. N9 ^% @9 _/ K=========1 |+ u4 N" Z+ e0 J: g8 u
+ ?2 ]# j/ m6 V5 n4 W- d8 `: rIt is not a method of detection of SoftICE but a possibility to crash the' M' ~5 K; { ]% Q3 L! b! y8 ~1 K
system by intercepting int 01h and int 03h and redirecting them to another
4 x% s- m: c) K$ X! xroutine.& H g7 _+ X0 Z0 g) D% }6 L& G2 T. R
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points3 S E' { F- p& k2 y# @% P
to the new routine to execute (hangs computer...). x4 R x% q1 i( r- Q: n, P
$ |5 v3 z% h: \. p mov ah, 25h
) E6 K" A! g; M- M# O& n8 g7 {; U mov al, Int_Number (01h or 03h)& f. J% q5 I2 o4 Y9 S f4 \
mov dx, offset New_Int_Routine- u( ^# S. v4 A# v: p% x
int 21h* U c, s8 z8 @+ N- G
; K/ I2 A" h3 e6 U9 ^! X# b+ t) P
__________________________________________________________________________
* M, f" r; }" P- O# D4 J; L* I: l# b
Method 09
2 I* k: e) r- N0 j" T=========$ ~8 o! S: k* e" L# l5 n- }2 L
: t8 j6 \% S4 t$ p* `4 |
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only: n" P) B- C E8 Z$ W5 X, x, G% |
performed in ring0 (VxD or a ring3 app using the VxdCall).
6 g( V; R+ { u0 h4 rThe Get_DDB service is used to determine whether or not a VxD is installed: Y5 q6 G- d* D" H' [$ T
for the specified device and returns a Device Description Block (in ecx) for
1 g X( R( S! |5 e: W( tthat device if it is installed.! x8 m( G; ?& I y- g6 ]
4 { ?$ L. a9 Y mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID6 J! N" _. h m& r( ^2 f0 y; x
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)' Z* s) m, @6 E( a9 z
VMMCall Get_DDB
+ r) Z& I& ^3 ?# \! K+ b, O5 l' D mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
) p/ l) _, b7 t2 c0 n: [+ C; u: N4 L3 x) R7 i# o
Note as well that you can easily detect this method with SoftICE:: q9 F' ~& D. O8 f: V
bpx Get_DDB if ax==0202 || ax==7a5fh
2 @' w& g' Y( B) ]
/ k' W3 x% [7 V# y' k6 ~( _$ h__________________________________________________________________________' P3 C- s5 Z6 U8 P
8 b* s, {1 z* dMethod 10! K) ~& p2 _& ?5 C9 g6 d
=========
5 _ _! `7 c$ g6 r+ J
* C9 ~) m8 A5 G, @; O=>Disable or clear breakpoints before using this feature. DO NOT trace with
' z$ c8 W; p; y! C4 h SoftICE while the option is enable!!
* Y- o5 F' x! @! T3 N- W, K$ k% ?+ ]' d. B6 G* S" d
This trick is very efficient:2 L* O Q' d# h4 I' q- q# K! y4 M; B+ }. }
by checking the Debug Registers, you can detect if SoftICE is loaded
! M+ k* Y! U! }% k8 }' u(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
4 Z# M, \! j2 m0 r T: { ~there are some memory breakpoints set (dr0 to dr3) simply by reading their1 r) e0 W! c" j& z- Q, U
value (in ring0 only). Values can be manipulated and or changed as well
/ y; r6 ]! f* w! B; o- z(clearing BPMs for instance)
' y) d% J) a. g6 Q1 C5 C# E) i* W: x7 C' d
__________________________________________________________________________' d5 u5 b2 \- [8 M: y; d; v( R
& k7 m% t! I: E; N- g
Method 111 L- I; o8 c' [: P, i
=========
" I$ k% O, `" z. t
K6 L$ s+ C$ e; j9 BThis method is most known as 'MeltICE' because it has been freely distributed9 C$ |( P4 ^! H5 w9 j
via www.winfiles.com. However it was first used by NuMega people to allow
2 w* c6 W. e3 x1 G4 X+ TSymbol Loader to check if SoftICE was active or not (the code is located* z& u! \! {3 L' H5 m% G
inside nmtrans.dll).
3 v+ B& V) Z4 L' J3 F- v
* a" M* @4 m& y3 [, HThe way it works is very simple:
. A( }9 p$ _# |. eIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for9 b$ |+ N" N! ]2 b# }4 ~1 B+ B
WinNT) with the CreateFileA API.. C5 h0 k9 H9 w' F1 \: R) I# ^! H
# B. _, ~/ Q8 l! l
Here is a sample (checking for 'SICE'):* E) v' x: S( r
# b, ]- ^7 M2 G' zBOOL IsSoftIce95Loaded(). Z g* P6 M/ d# q
{+ x+ X# l! J8 E, {* q$ |
HANDLE hFile; 9 g9 _. _5 r0 [5 D+ r
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,$ E2 \) ?2 @( M
FILE_SHARE_READ | FILE_SHARE_WRITE,9 B. m, y- H: G s$ B
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
9 w- n6 v% X9 [4 D- H& X# Q8 b: J- _ if( hFile != INVALID_HANDLE_VALUE )- L7 v, ]6 J; J: W9 D. u) g
{
1 s& y) R! V* g CloseHandle(hFile);
4 }/ b+ l" W- F/ R# q' X return TRUE;
( D% x' M! c, G0 k, p% V& ? }
9 @, ~$ H4 K, ~$ L8 M9 q( u* W7 h return FALSE;
8 a; F+ J6 F ?) C6 h$ v}
T, T, H- z5 P& Y2 _& }
! X) m3 ^/ F, w6 [2 uAlthough this trick calls the CreateFileA function, don't even expect to be
. D# Q. x E2 b. wable to intercept it by installing a IFS hook: it will not work, no way!
# [ n. d4 }# ^9 C* bIn fact, after the call to CreateFileA it will get through VWIN32 0x001F- g+ a L2 k) c" X( _
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)( C+ x& j9 N3 s8 e7 o& m3 n
and then browse the DDB list until it find the VxD and its DDB_Control_Proc! i' `8 X B: Q; x( V' C9 j
field.- ?$ h" H- B& Q6 j$ x" p! k
In fact, its purpose is not to load/unload VxDs but only to send a # [6 D; B0 y" H6 n* N1 I* [
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)( [' G( P8 r- J
to the VxD Control_Dispatch proc (how the hell a shareware soft could try0 m6 `. J$ g I. C" H- n
to load/unload a non-dynamically loadable driver such as SoftICE ;-).5 K E t; r, Z7 h9 I
If the VxD is loaded, it will always clear eax and the Carry flag to allow, b2 X5 \6 j G n& i1 _3 N# F
its handle to be opened and then, will be detected.9 f4 H$ w/ o# @- S
You can check that simply by hooking Winice.exe control proc entry point( \: j) y! r/ ^" r* w+ y) }) {
while running MeltICE." |; P$ [( i9 r0 d% S/ m
7 ?4 ?; P5 n2 a
7 ?" s0 b4 T9 q5 e 00401067: push 00402025 ; \\.\SICE9 {0 M3 g7 w1 f9 X( p& @
0040106C: call CreateFileA& j3 v" Y% q2 |$ b0 m. u1 e
00401071: cmp eax,-001
- @) _; I! R6 k# G 00401074: je 004010915 S8 `6 L) S; k+ W' E. n
3 z% b; {4 r! K# E
9 W2 M# W' |3 b2 X
There could be hundreds of BPX you could use to detect this trick.$ K1 }. r7 O8 ?/ t+ w7 S4 e
-The most classical one is:
" g. j4 n0 a1 E4 Z+ m+ M BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||, I4 F) K& R R9 h6 X. S
*(esp->4+4)=='NTIC'" w3 H! B, T) _+ Q5 g
+ t0 g m; N+ Z% p* `( D( L
-The most exotic ones (could be very slooooow :-(
. i9 u% }" w* a9 S BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 1 e5 q3 b* F' R6 w, x: C
;will break 3 times :-(9 p* ^4 K# Q2 M9 Q( z( X1 \
6 a, h4 m7 C& l: r2 n/ e( n-or (a bit) faster: " w F& A6 p0 M5 ~0 N3 e# k
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
. ?3 K3 X4 Y( t }1 u/ j# E! `6 }5 _* H
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' : c5 r' i3 C! S& ^0 d: N/ b
;will break 3 times :-(
) M2 A. f( i* I# d5 A; X) g5 E/ v. [9 F! V1 d2 ^
-Much faster:% Q* u" o4 x1 J8 ^& ~
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
" m0 V# [3 B! q% X2 m! E" a
0 D# i k' H' W# O, KNote also that some programs (like AZPR3.00) use de old 16-bit _lopen- p2 P5 I0 t. b; z% w& o) j
function to do the same job:4 |2 T2 r. q& V" `4 f: H2 E' C
$ `: q1 ?, }$ p) h# ]
push 00 ; OF_READ
4 Y6 w2 g4 a+ y7 Y mov eax,[00656634] ; '\\.\SICE',00 s6 u! F9 ^* o+ M. C2 l f/ U1 i! v
push eax
' J. R* X8 m* v/ i5 _ call KERNEL32!_lopen7 [. Z; N/ ^. w
inc eax
& l* ^/ v9 L, {% g4 k; k jnz 00650589 ; detected8 }( [% Y9 l+ s, n5 c4 x g
push 00 ; OF_READ
1 F3 w4 v8 }+ p, V0 U, i2 T mov eax,[00656638] ; '\\.\SICE'
: F9 I& Y$ @, u push eax0 O; B2 L( x# ?. F
call KERNEL32!_lopen
& x l- N7 @4 h3 Q5 ~9 k inc eax
1 W8 h I6 d' h6 t; R0 [( w5 Y jz 006505ae ; not detected
: F1 Y2 @$ k1 B: f1 G
" Y4 }. D# N$ ^: J" R" K
U- i1 S5 [: F. C__________________________________________________________________________
# k% V. n+ ^3 ?8 m5 _/ `6 r7 ~; }9 `, O- G# l O
Method 12
9 s- Z! O# w; N. J* y/ L" b, q=========
& ^- x z) L& s! @, ~/ L9 f( @% B9 f& T
This trick is similar to int41h/4fh Debugger installation check (code 05
0 n4 U% E5 `% X# G5 M& 06) but very limited because it's only available for Win95/98 (not NT)$ ]! Q4 U3 F5 ?* o
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
3 Q& T1 t2 g$ U2 H
6 E2 A K1 F' W! Z9 ^ push 0000004fh ; function 4fh
1 L* }: f4 |' i7 G/ k push 002a002ah ; high word specifies which VxD (VWIN32)
1 c: U0 N# d1 G Z; O1 {; `. B. C+ i ; low word specifies which service
! z; o* Z/ J v8 L3 s (VWIN32_Int41Dispatch)
, s* i! I- ]' z call Kernel32!ORD_001 ; VxdCall: L$ O/ k9 n1 \( v8 K
cmp ax, 0f386h ; magic number returned by system debuggers
. L( z& c. C& P' Y' p jz SoftICE_detected
0 K( P, Q: i2 w& ]5 a, }1 Q
1 U, ?5 c% ^" p3 w2 F! C' eHere again, several ways to detect it:
! h6 f1 K P J3 @1 f$ Y: O, x
x% G. ~1 X7 ], P0 p' [' ^5 R BPINT 41 if ax==4f
, U" w: g4 D. }3 m# \5 ^. F
9 y2 j8 q/ i. x9 o1 ]$ W" ? BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
0 j+ d+ z# n$ U+ b1 E# |: D& k
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
6 F. a9 `) Q8 J0 f4 g; p9 ~* @ K1 O- S* D! P( B' X- x$ S0 P
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!2 y* L% `' f$ O6 f3 Y7 b
& a9 Y; I" T- w+ }8 o
__________________________________________________________________________8 r8 W# `% }3 E; U) L
. z$ t- n: t! h3 R; `' P0 LMethod 13; B" u Y' Z. X2 X
=========
- O/ [0 o' B. c# v/ Z( S5 R& z9 l
Not a real method of detection, but a good way to know if SoftICE is
w1 G# ^; m; C1 zinstalled on a computer and to locate its installation directory.: Z5 F0 K; x! h. J5 b
It is used by few softs which access the following registry keys (usually #2) :; d& u3 x) h/ |) Q
$ P9 h- {* {8 v. D
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
# Y- y" Q+ Q- T1 v3 k, M9 _\Uninstall\SoftICE
' B K- D% D. ^- t- q7 w-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE( t! J9 t: Y' T9 c; W; m
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion: |6 R! v9 |6 Z: a
\App Paths\Loader32.Exe
, w' U% h3 u( Q! i! g2 s+ s; g* {! X8 |
: k2 [; B( u* r4 tNote that some nasty apps could then erase all files from SoftICE directory" x: r ?) o ~
(I faced that once :-(
+ |5 i, t+ v; {6 ~% A
! E I! \" e: \. @- S( CUseful breakpoint to detect it:
1 |+ t l! K/ Y# r* l; F9 T. P
1 u! z2 Z- A8 N. L BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
8 M, i3 z: z" ^6 k7 \; n: Y3 Z( j1 r" W7 \. e L, `
__________________________________________________________________________6 }' V: u3 _1 [, U6 g7 q
/ T. H. T. W/ f6 u3 w5 G
; {4 d. q: J4 o" w2 |) tMethod 14 3 h$ r2 c# [' Z; R& g: Q; q
=========$ P7 I2 P$ D( J. D$ m
! Y$ E5 }- I4 E2 ^3 l
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
$ N' y# e5 L: X/ E8 W0 J3 r0 Eis to determines whether a debugger is running on your system (ring0 only).. c8 ?! I$ g. w$ n9 m
- c' l* e3 D: z% [! q& w
VMMCall Test_Debug_Installed
2 S8 d" R% Y# Z je not_installed6 R6 l i, u- O; Y6 C, h0 z
& ?8 p! z* K& n9 ^- C0 e% qThis service just checks a flag.
$ P( F' r4 e% Z, O# u; u6 J' a. k</PRE></TD></TR></TBODY></TABLE> |