<TABLE width=500>
4 n+ R! }6 ]0 Z* Z8 D<TBODY>: W) ]7 V) E. \8 }, e
<TR>5 a7 e& A2 Y7 ?
<TD><PRE>Method 01
$ s' n: W' P' u4 f. J=========5 J+ ? I- z6 x) n8 B4 e1 l
- @. ^6 `# J0 K& O' w
This method of detection of SoftICE (as well as the following one) is$ p1 K) j: Y; [& Z0 k+ E: Q
used by the majority of packers/encryptors found on Internet.
! \) G( q' |! _2 M6 [1 M3 ~5 k8 M8 P) HIt seeks the signature of BoundsChecker in SoftICE
7 B6 Z' [6 J$ f4 U' K* ^+ o) f G p9 q9 Q& m- M$ R4 p5 N2 I
mov ebp, 04243484Bh ; 'BCHK'
" O& _% \8 Z# A/ ? mov ax, 04h a' `& i2 W" A/ H9 f h4 Y
int 3 . l/ s' c! I$ y' I8 g
cmp al,4# D5 t: w6 ?" o7 p6 j8 K3 X+ e |5 r
jnz SoftICE_Detected3 I: K& \5 Q h6 I
" M$ k) g3 k3 y- A. N- ?0 D& e6 Q
___________________________________________________________________________
: E6 z" T g$ d7 G' P- U# F. `) a. e9 W, L( G/ q
Method 02
7 ]& r( o+ V2 C* W. \=========& Z/ k) }8 _" M1 Y9 N* p& b2 f8 d
8 v2 G2 j, C- [; LStill a method very much used (perhaps the most frequent one). It is used
6 _0 u) ]+ G5 ]to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
5 I2 G. u+ x" ~2 Tor execute SoftICE commands...6 y# I, A9 ~$ C8 Q6 ~6 I
It is also used to crash SoftICE and to force it to execute any commands
. U0 h' U9 W) @+ ?, {+ i1 t(HBOOT...) :-((
$ r, {5 Y+ V+ \4 ]' R; B+ u; q
$ T. W7 b! R! B* t$ mHere is a quick description:4 `5 h+ v' o6 T' ^
-AX = 0910h (Display string in SIce windows)* V( v6 w: e% K; Y* _) b
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)9 I5 k$ P, d& t( w
-AX = 0912h (Get breakpoint infos)
0 w; Z/ B9 Y) X-AX = 0913h (Set Sice breakpoints)% @: a. F* n9 B6 f' y% Q$ ]+ r
-AX = 0914h (Remove SIce breakoints)
4 ~+ o& k( w# E: X3 ~/ C. \
* N9 X0 [( y! ^1 [Each time you'll meet this trick, you'll see:
9 a$ s$ P, _: I" n-SI = 4647h
) V$ @2 q' V' e-DI = 4A4Dh
6 u1 v; {+ p4 y( A, z2 f1 ~Which are the 'magic values' used by SoftIce.
, k8 A+ |' P r3 `/ V j) fFor more informations, see "Ralf Brown Interrupt list" chapter int 03h./ L/ |# W* h/ }! I
4 J2 Q# b3 P6 J& J" H1 p! eHere is one example from the file "Haspinst.exe" which is the dongle HASP
; d' l. G; X% c! AEnvelope utility use to protect DOS applications:
: O0 F$ X: C/ X" [# k; D' n k" |* ]6 n I! A; x
, U* Q$ g, w9 F; j( h. B: v* P4C19:0095 MOV AX,0911 ; execute command.4 x* b$ r8 h4 `
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).% |6 Y/ t. v0 c& g
4C19:009A MOV SI,4647 ; 1st magic value.
: [4 J& Q- t8 b& o( K2 r8 W% v$ ]) }4C19:009D MOV DI,4A4D ; 2nd magic value.0 S- m. T( x4 {1 A/ Y5 ~& Z
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*). V& ?& V+ S. ?# x0 x
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
1 V: h" D7 C' T) L4C19:00A4 INC CX4 V5 b2 j' Z& X0 z0 Z
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute) N' l$ x( J) [5 h7 s4 _4 [
4C19:00A8 JB 0095 ; 6 different commands.% U0 p8 M" b$ {: u$ K
4C19:00AA JMP 0002 ; Bad_Guy jmp back.9 K. B6 X. P! |6 x/ g# m6 f
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
7 a8 l" Q ~4 I6 l, g$ S7 a2 @0 d3 _# N/ \' ^1 y7 @1 h
The program will execute 6 different SIce commands located at ds:dx, which
( N% [7 x8 U8 l/ ]2 H5 g1 qare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.$ |. \2 t6 Y+ M s9 R0 X$ z
1 E3 u$ `% {: {0 y$ n ?
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
, q9 Y+ |# a# T___________________________________________________________________________
( K9 p) x5 }( F; B0 G/ t/ i3 i
i3 V+ w# D& C8 e: Q a$ I
+ {* r- ]2 e# W3 XMethod 03
0 \) ~. v1 D& E# h- n) r* C( G( a=========
9 v4 L) i- a9 X3 J+ F! K$ b' }9 s8 y& d. I9 T; p# T& v
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
. s3 q1 R! U% z+ X9 C% E7 V2 `(API Get entry point)
4 \8 i. d- J$ }& j- w5 j# | # D2 ]) ?6 _ D# V1 r* K
/ L- z$ @" A Y! Z( h xor di,di# M9 k7 v# K# u3 J
mov es,di
$ L3 w9 R! e9 N8 [ mov ax, 1684h
. _$ p A. e- `5 L- K mov bx, 0202h ; VxD ID of winice
# n- g Q' b" ?. N+ b int 2Fh
; m V# C& d0 K7 [- X2 a mov ax, es ; ES:DI -> VxD API entry point
# D( K/ W, o' \# P. T+ b* f add ax, di
2 u' ~1 m7 P" v4 o/ A test ax,ax
9 y- o4 u" F* x! N+ ?' a jnz SoftICE_Detected) t; e2 A" L6 Y5 W! ]; f- W7 z
8 k" E+ I) R* g. |" A! j; W
___________________________________________________________________________, }9 t, [- D; H( U* v! e
8 G" P) r: Y4 B2 G6 F% sMethod 04
3 |6 p3 k; y5 d$ ] A=========8 w1 F, B# W* Q3 y c& i0 p
% I A) @ G' i6 p0 sMethod identical to the preceding one except that it seeks the ID of SoftICE) Y: v8 G" o6 L) C; I/ E
GFX VxD.
9 L$ A: v) W l: @
, f7 t0 e2 e% U4 J5 s8 a" h xor di,di6 c& V, \5 g% O
mov es,di
m" f2 U4 H- z+ d) v mov ax, 1684h
1 I c& |7 R [) B2 y mov bx, 7a5Fh ; VxD ID of SIWVID
, J( p8 h5 a0 U+ v3 \* c int 2fh
5 R) ^& T% j( |; p% D3 ~2 } mov ax, es ; ES:DI -> VxD API entry point; ~, Q" Q0 o0 } d$ R/ e
add ax, di
. i( f4 i) {* I5 O test ax,ax
' \* ^, c H& e jnz SoftICE_Detected$ G( a. A& h4 _. H
3 O# |) \/ A% H__________________________________________________________________________
6 y- P+ [9 f/ k Q6 M8 z8 A, }, H; I7 H; H: I0 F
# j5 q, I1 q9 j N: LMethod 05- P9 `& t( t$ K" N S
=========9 J1 H6 N$ V9 i% g" V
0 J* h0 Z0 t# a8 {) r
Method seeking the 'magic number' 0F386h returned (in ax) by all system
2 b# x& y. G# |! p! D9 Rdebugger. It calls the int 41h, function 4Fh. q z# p. c) A: j4 y$ Z
There are several alternatives. 8 m3 U( P4 O; Y9 ?7 O" r% x# O& c
5 x6 U8 \: _- V6 q, {
The following one is the simplest:
) J4 I1 }/ Q5 |: M2 |9 V8 B+ r& a: a# Q% M8 R
mov ax,4fh) G" W* A3 R: f% J2 G p) g+ ~
int 41h
u' f n) R3 @9 B% Q/ Q cmp ax, 0F386
" q& }- Z" J. [9 Q$ ]3 U- C2 ` jz SoftICE_detected n6 f# {3 g. Y$ [1 y& o! j6 \
; s! K0 S- ]3 O- m; G- F
( W& z- z D( O' H0 TNext method as well as the following one are 2 examples from Stone's
0 X9 I4 D, p) f$ `, |"stn-wid.zip" (www.cracking.net):
, G; s9 g0 Y* O1 \$ ~
; E) v) H* d# B5 Z3 a; n mov bx, cs
) K# X1 m# d# D1 F lea dx, int41handler2
2 }( X% X$ B4 o0 o1 E" ~ xchg dx, es:[41h*4]) I( p5 y1 s0 w# S0 A( M
xchg bx, es:[41h*4+2]$ r/ o j. M' j2 ~3 H( K6 I
mov ax,4fh
- k c+ X: e! ^; s int 41h* Q: J' k; F8 V- c" k0 I
xchg dx, es:[41h*4]/ t! i R! B3 s
xchg bx, es:[41h*4+2]
; i- l3 Z, s* C6 J: m cmp ax, 0f386h1 T: G2 y% Q) t* B6 Y
jz SoftICE_detected$ \# |$ x v. l5 j- m
3 r# I% c7 `5 |7 a5 q
int41handler2 PROC
. t# G. O% k) P" V iret
: d/ [, Z" H9 A Xint41handler2 ENDP
7 U6 }) Q5 k8 z* y
7 l! u* X% B# v+ P$ [: R: M! \! O+ ~
_________________________________________________________________________
2 M& Y+ u- s/ N
! k. k# Q, ^( K, W% V {( V; H: b) l0 ]% [$ V
Method 06
; x% s% J7 m: ?$ Y: }: Z6 P=========0 X& o1 e% ?: r
& e* @4 u; L; m& O. J
" a5 G/ B& M' C( o- z
2nd method similar to the preceding one but more difficult to detect:
' c& H3 P/ b1 }" y' g M( u8 j+ b
* f/ f7 Q5 N; E# b" N
% Y7 i5 ]9 K& Z, ?( v0 Cint41handler PROC
4 M! R7 |& E# k, ? mov cl,al6 z: U# t8 P, D; t* u- L
iret& H% ?; |+ Y8 p1 w' l: r
int41handler ENDP
* v' n6 X$ ]3 d
! m5 Q ~, S- B. b0 c* [' w
& a* M5 @$ w( i! r) z1 A/ j! U xor ax,ax7 L( E9 P. G1 y* h- v( X$ l
mov es,ax
K+ n/ V G/ r" H mov bx, cs* G2 K2 S. X( |9 X
lea dx, int41handler
4 H' A& ?4 P! A$ h; m xchg dx, es:[41h*4]; ^7 ]. A* z0 v
xchg bx, es:[41h*4+2]9 }$ o$ \8 a# _ t1 q3 f
in al, 40h3 L* N4 H, p9 L& ?
xor cx,cx
, |5 n% Q+ H5 _* x& ^ int 41h& [( r! ~# v6 ~6 m/ O& C) A8 a/ L! t
xchg dx, es:[41h*4]
+ \/ b% }! |1 w5 c' v xchg bx, es:[41h*4+2]6 s# B9 B# ^0 x% I/ H' e
cmp cl,al
; t& j) t( |- Z, F+ G u3 G4 W jnz SoftICE_detected5 L" c" x; \& k
$ q/ I- |" l: `1 w_________________________________________________________________________
3 Y4 N. A( Y4 y5 E5 D: |& f! m$ g H
Method 07
2 A' n( U$ ^4 [$ r# Z7 `$ L=========
+ c9 N0 n. [+ J" ?6 E# W! y7 @. E5 h- I' `5 X6 i& V
Method of detection of the WinICE handler in the int68h (V86)
+ O$ T/ e! `3 C/ Q
2 E+ u& u0 Y; y8 W8 u; M mov ah,43h
0 R+ t n" G5 y | V, F' S int 68h4 P8 [- X/ Z1 W7 p' q
cmp ax,0F386h
0 Z4 u6 j c/ s3 _$ C jz SoftICE_Detected
0 w3 q( W8 [- h; N# k/ [8 `$ k8 k% j" E% P
( g# F$ j7 [: k! y0 Y5 Y4 A
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
: S% X' y, c9 Z2 L Q8 y app like this:
* a* o8 a# E- ?$ A
- S* Y/ R* P( D2 n7 J- _ BPX exec_int if ax==68
1 Q& M) H. X+ W (function called is located at byte ptr [ebp+1Dh] and client eip is3 J( z, ?( x4 ^* h# e' }; b j' ?
located at [ebp+48h] for 32Bit apps)9 H5 A8 T2 k1 s0 a% V! P& |
__________________________________________________________________________: I. ]6 R/ u4 W7 ^$ S
9 U6 A9 r( l) f7 E2 I# Q: H7 Z- i' _
Method 08& L6 P# T8 q' [$ P+ h* S% d
=========: O3 J- b) G2 ~/ Z1 y
" h' Z5 w; _+ c0 k) s
It is not a method of detection of SoftICE but a possibility to crash the& ?2 }9 A1 {' D0 v! }6 L
system by intercepting int 01h and int 03h and redirecting them to another
8 \$ v3 T. c! U7 _routine.2 J4 A2 e+ s& R) ^" H6 I
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points0 C( ?+ d+ Q# C, i+ U7 B0 b
to the new routine to execute (hangs computer...)
; m7 z2 r, ?, I3 L- v
* `5 l! y/ M5 _8 S+ J mov ah, 25h2 j- \% k+ z/ x3 Y* |4 y* [" i
mov al, Int_Number (01h or 03h) P5 H- Z3 q9 V
mov dx, offset New_Int_Routine
& c8 J# B* G5 C/ A5 U ]* H7 t" V int 21h
/ |( c+ D d0 I5 W. _
+ a. H8 `- F& v3 R5 p, Q__________________________________________________________________________7 m$ }( C/ X3 F |* |# \# v; D) y
- u7 p& }, ]& t) P. V4 [Method 09. H" x8 f' [1 W$ _
=========
3 E/ J M: l E/ b: j: a% B ]$ u: `# v$ D% Y1 T7 j& L
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
# y$ \: w3 @$ Fperformed in ring0 (VxD or a ring3 app using the VxdCall).! x. U( f2 _! R8 W# \% M
The Get_DDB service is used to determine whether or not a VxD is installed/ F% p& S0 F/ s6 V; \. |
for the specified device and returns a Device Description Block (in ecx) for
H5 B- U B7 r! @$ a' e9 `that device if it is installed./ R" h4 g- t# x: k
; q9 v. p" C! H) t8 P4 _6 y/ Y3 K
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID! R2 E3 N+ g) b8 W& S
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
+ f. o! ^4 m( B VMMCall Get_DDB
% O% N! F' r3 b' R& M mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed' C$ j4 f( T9 F& D2 u2 ^' [ h' l
. {6 L3 t2 t+ _Note as well that you can easily detect this method with SoftICE:
; j& c7 i: T9 J. R bpx Get_DDB if ax==0202 || ax==7a5fh
% i- p. s! s/ K" K6 G) {
0 T& _# B; u7 ~3 ]6 `__________________________________________________________________________; w2 V R0 z; G, r
% b4 R- f+ M) J6 P! {) \0 E/ u0 b/ ^
Method 10
R- r6 ?# a- `6 k( ^: n6 t4 P/ n; j=========
: q- t4 Q' G$ Y6 E2 \: l
9 L6 O# ?& k9 ?) m=>Disable or clear breakpoints before using this feature. DO NOT trace with
* D a- M* P3 X5 A+ N. L SoftICE while the option is enable!!
8 l+ P* i+ I% }+ {
1 `( |/ A) i- [2 x' T7 pThis trick is very efficient:& y" G( v. Z6 e7 M' ?3 x
by checking the Debug Registers, you can detect if SoftICE is loaded
. M+ X; X: Z$ H, S! |2 t(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if6 W! {5 ~4 c. o
there are some memory breakpoints set (dr0 to dr3) simply by reading their$ Y; E4 Q& ]( e; L
value (in ring0 only). Values can be manipulated and or changed as well
" N" @1 q$ n! Z5 X(clearing BPMs for instance)/ r: E: ]" T w7 }+ C, ^
/ v( |+ m" o* z4 A0 F; l__________________________________________________________________________( y: y/ o, M- X8 b
% `8 m. f" O0 [. i+ y
Method 116 I6 O1 ]! x0 Q: g) `* M* o9 G
=========
8 G9 U L# m6 `# x# v7 F/ ?/ O U' k. {1 }! g, P
This method is most known as 'MeltICE' because it has been freely distributed0 q$ u* j9 i C
via www.winfiles.com. However it was first used by NuMega people to allow: I% Q5 B9 B1 B' H
Symbol Loader to check if SoftICE was active or not (the code is located" v. X8 A# }4 q' J9 l3 h/ ?
inside nmtrans.dll).
8 X5 b3 E4 W9 N. B1 l: p* q- q5 s1 C9 O/ f5 a
The way it works is very simple:
& g9 V! a B- J, @It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
2 K2 U1 r: K" zWinNT) with the CreateFileA API.% K& k7 V g/ V' ]- Z
* j4 ?$ T9 {- n( U% o1 p$ j0 zHere is a sample (checking for 'SICE'):" D4 C: y2 @4 w/ e o- X7 a
d( Z+ ~% m5 D6 f* t6 M% z6 Y3 W' ABOOL IsSoftIce95Loaded()
- }7 H6 ~# u1 Q* l( i6 ` g1 R{
4 i. d; G6 b) I3 V HANDLE hFile;
) i' O8 V3 o* l hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,/ K1 J( ?2 V9 j' L' e
FILE_SHARE_READ | FILE_SHARE_WRITE,
/ u& L! `; B/ |$ ?" A% P NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);& N( f" f* a. ^! e* f' ~! c! a
if( hFile != INVALID_HANDLE_VALUE ); @% V" f0 Y \2 d& V/ e( |8 J# {
{' d: l0 ?9 O4 O1 f" r
CloseHandle(hFile);4 O+ A' c+ ]/ G- e9 Q
return TRUE;- s; k. }/ Z" w( K! @4 n
}
) D! {5 l$ g2 T8 V5 Y return FALSE;, B* U( _; A; L2 i; S) F
}
/ T7 {+ ]! u1 ?2 |- U# e$ w4 M0 F! u2 s9 g' j( A" R( |/ b' E
Although this trick calls the CreateFileA function, don't even expect to be& S/ {& k5 D& q" s
able to intercept it by installing a IFS hook: it will not work, no way!
! z3 u" x3 g! {In fact, after the call to CreateFileA it will get through VWIN32 0x001F" K. F. ]* g3 q# h8 p' l. a
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)* N8 f0 K& p% N# E" Z
and then browse the DDB list until it find the VxD and its DDB_Control_Proc2 b8 R; A; n. K5 o
field.
' {% B7 d& @$ n ~* ^In fact, its purpose is not to load/unload VxDs but only to send a
' ]8 l% Q7 E/ U+ @, s' hW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
6 H2 C. k% i. ato the VxD Control_Dispatch proc (how the hell a shareware soft could try! `5 {. S- _( e6 \( G; j
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
7 y- ^8 s0 Z- Y2 z8 x( p4 pIf the VxD is loaded, it will always clear eax and the Carry flag to allow
5 T F0 [" R0 X+ x3 ?9 c4 Kits handle to be opened and then, will be detected.% V- _, q ^* j" o. v' _* d
You can check that simply by hooking Winice.exe control proc entry point
% u% o/ W8 H1 \; s) uwhile running MeltICE.
4 S f+ B! Q) U& m
; g, v8 ]5 ~; G3 ]- w5 |3 L/ [9 P b# A4 ]
00401067: push 00402025 ; \\.\SICE1 L# |, q; k9 O" ~% H
0040106C: call CreateFileA
. l; d6 @- ]- g0 L; m5 F2 x 00401071: cmp eax,-001% }- S0 G, ?0 N6 n
00401074: je 004010915 s1 y% H8 a# h7 v- B4 g7 m% j/ H
6 n% }/ |- [) K) Z: G; S* ]8 v
3 F: f( D# z/ J" R4 X. \) eThere could be hundreds of BPX you could use to detect this trick.
# G+ [9 ^ d3 y" X% a6 H-The most classical one is:
$ M2 A. f' l$ a# c# D J3 o BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
! s, h) n# l! E! a2 R( U2 _ *(esp->4+4)=='NTIC'/ x3 K# A# t( g( F
/ Y) j$ e9 `9 D ^, A# s! U$ Z P
-The most exotic ones (could be very slooooow :-() }: G5 g, F" ^( j
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
x S% X1 u8 h2 I; b1 ~ ;will break 3 times :-(9 M/ m6 T7 ^$ d6 E% c4 d3 A3 y
# m% G; L% K K2 [. `2 h, }, ~-or (a bit) faster: 9 y1 w7 ~9 i* ]! @$ b1 E
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')$ |6 n/ U/ T# ~1 X
& \8 I8 }: W+ @* s
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
) [' X! w1 F7 f2 t1 B ;will break 3 times :-(
# K9 |1 a4 Z+ M/ @; G% A2 b9 X( w9 g) S/ L& F& r( b+ B
-Much faster:
) F2 t6 p6 d' b) m8 O4 T BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
# K! T$ a" O4 U- ^
+ s: T; T' {7 v& r( {# {Note also that some programs (like AZPR3.00) use de old 16-bit _lopen: V/ B J" L8 K# a3 c/ z- ?
function to do the same job:( [; P! |# Q/ c& q. ~9 D
k" A @6 O5 L7 r+ c push 00 ; OF_READ! L0 o0 \# h1 Y( E
mov eax,[00656634] ; '\\.\SICE',0: N1 i" f1 R' q
push eax
/ Z e( t; U* |$ a call KERNEL32!_lopen! T+ P9 D+ `) y; U4 J$ l% q6 W
inc eax
! _4 n, e" T |4 L2 Z& ] jnz 00650589 ; detected
7 O4 j/ @$ ~/ Y+ h push 00 ; OF_READ$ l# x9 u$ J( G) n% A- e
mov eax,[00656638] ; '\\.\SICE'3 Z1 Y0 z0 a6 @
push eax6 _# g f% s' C, T, H3 t/ n
call KERNEL32!_lopen# p$ `& m# ?, m- N
inc eax d& |) d D; s# S$ ]# A" |
jz 006505ae ; not detected
! L' E9 {/ T0 d$ B$ f& f$ _$ o) Y3 y( E) `
, m: M9 b& a1 N# O9 D5 s; Q__________________________________________________________________________
* x* i* w k B x
5 r+ X! {+ c! xMethod 123 O3 o V/ i4 m; e$ L
=========9 ^) R. o9 G1 Z+ [+ o; I& O) Y
+ a9 G+ E8 x1 B9 {+ S" A
This trick is similar to int41h/4fh Debugger installation check (code 05
8 c8 Z, Z( j3 Z0 ~, ^3 a$ c0 a& 06) but very limited because it's only available for Win95/98 (not NT)
' X; u0 n4 x4 Das it uses the VxDCall backdoor. This detection was found in Bleem Demo. L" x5 ^( A% I+ e
, E! n; ^3 G6 w5 \9 l G push 0000004fh ; function 4fh
4 T/ l* Z5 `) m+ _3 ]0 X push 002a002ah ; high word specifies which VxD (VWIN32)
: g5 A0 T6 p k+ v ; low word specifies which service
, w% y1 [* {+ X* s3 x8 V (VWIN32_Int41Dispatch)
# X! v, t ?0 x call Kernel32!ORD_001 ; VxdCall+ O3 R2 _! O8 @- ?. g0 a
cmp ax, 0f386h ; magic number returned by system debuggers8 U3 K0 P0 s% Q. x* i
jz SoftICE_detected
- s8 R v8 w. d% n+ E
" ?8 ^: O& U9 U! c' nHere again, several ways to detect it:% i* v" _& ?. K# A9 O- L
" Z" J: ^$ l9 Y& _. \
BPINT 41 if ax==4f1 c- ?* \% z2 b6 j$ q, v
. `: y/ E. ~* p- k0 R) e BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one0 a2 l* @. ]( \
# r% l+ I7 F% a. s
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
6 A2 ^" V6 F' A3 q2 k0 J4 N5 V* j- _2 z6 o7 R! D" ~
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
7 q- N6 P/ l. Q4 [) Q
$ P5 d3 A' Z1 d* Z__________________________________________________________________________
; m4 q) n! n! r
& Q0 Q# r2 y8 z9 e0 AMethod 13
& d8 l9 |, z6 i- L8 {4 R=========# Y( |& d- _" g5 O) N7 U* [
9 C( O8 Z' t7 V3 z9 @! hNot a real method of detection, but a good way to know if SoftICE is
9 ?9 F% O2 b, T: R2 @ g4 Ninstalled on a computer and to locate its installation directory.3 N: x/ Y$ Q3 x6 m; z A# ]- s- k/ d
It is used by few softs which access the following registry keys (usually #2) :! M( `; D5 T- V
8 ~' b" R8 W& W
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
6 j5 }. z% t A9 L% Q# K3 W7 }\Uninstall\SoftICE
; Q+ r- m2 p! F2 V9 b2 }& |-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE/ U6 ], d6 R1 Y. ~! O3 v( Z
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion0 K. y0 Q/ c9 I/ i7 d+ @" E7 f
\App Paths\Loader32.Exe
+ b$ u3 g/ q0 y! L& L3 t4 C* K2 I, V3 j6 U, P/ ?
F1 k; c1 \$ e
Note that some nasty apps could then erase all files from SoftICE directory
+ V$ J7 u- S% d(I faced that once :-(. [# q- e) ?' d' k7 ]$ a
9 Q- d9 \+ ]$ @! i% u- J6 j
Useful breakpoint to detect it:
' A- R7 C- a9 P' A; w [/ M) B
" W2 E6 g! }2 d7 Y$ d! v9 @% d BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'4 o+ n1 V+ G) p6 L& ?, X1 z
) a2 l) m- |2 H, m
__________________________________________________________________________
( p. K1 ^/ C* U2 [$ s: F
" O) m- e& Y- \$ \3 ]
( i) v+ G6 O5 W5 v: X$ QMethod 14 % E4 y$ n- A5 Q$ b) [8 Z5 d3 }
=========
, @' a$ L Y8 j2 R
, [) l# b0 k$ NA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose. l& P8 I( P4 }* H! n' \4 W. p
is to determines whether a debugger is running on your system (ring0 only).7 N7 s8 e2 I1 R& N+ K
7 q$ _" v/ ?0 k4 {$ K3 X
VMMCall Test_Debug_Installed
4 {3 B% P( {* @- G je not_installed
2 x( F+ t; f2 C9 m5 K, C) W, ~; a" A2 J3 m! }4 Q+ w& m
This service just checks a flag.
/ X& k! _9 V: D1 i) g</PRE></TD></TR></TBODY></TABLE> |