<TABLE width=500>( E2 s6 |" \9 V1 { R% C) m' B/ ~
<TBODY>8 \+ y3 G% A( E% L2 \1 f
<TR>
. q* P* P& X7 M9 z" a# @* s<TD><PRE>Method 01 2 Q- U c( f& w( K; Q
=========+ t# V# S# u6 v$ C0 X
5 f1 {' n4 p* C3 ^) @5 F# C/ b& `This method of detection of SoftICE (as well as the following one) is! ~! j2 U9 b# [/ C$ l/ |
used by the majority of packers/encryptors found on Internet.
% M& ?0 d2 L, I! w+ i, }" ]9 }* pIt seeks the signature of BoundsChecker in SoftICE
' g. m3 t( E1 I. n8 Q8 C! ]6 j" d" B
mov ebp, 04243484Bh ; 'BCHK'9 G( s' l, J7 ]) ^
mov ax, 04h+ X% k5 K0 A p; k N; `
int 3
: _4 K0 \/ @+ _& W( F+ g cmp al,4
( Y9 \, b/ `3 q1 m; e- c jnz SoftICE_Detected
9 x+ s4 H6 k2 m/ }2 ]
6 G! r4 S4 ? W___________________________________________________________________________
4 K$ e4 Y( I5 i- J6 k
$ f2 F( z5 v0 ]+ gMethod 02
, K7 N6 y/ ~- y9 z; D=========
' L3 E1 Z e% P) ^) n& w8 s3 {
' t0 K% e Q' c7 _$ M j' ?5 q1 G) t( BStill a method very much used (perhaps the most frequent one). It is used
0 u! h. S/ ~2 rto get SoftICE 'Back Door commands' which gives infos on Breakpoints,7 m5 h) n; o7 I) M+ k7 r
or execute SoftICE commands...
* a+ N4 e1 W' g3 X# ~It is also used to crash SoftICE and to force it to execute any commands1 H; L/ H" I! f) D3 H5 f
(HBOOT...) :-(( - B3 n. L8 N! r& q; A
; A! k: x" U; A. }' R& P: d8 q+ }
Here is a quick description:
6 |& ^+ z- g& f4 I1 [-AX = 0910h (Display string in SIce windows)- B3 [6 R# q- r) |* U7 c) ~' @
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)3 U9 C* p% a/ I" X
-AX = 0912h (Get breakpoint infos)
& |7 \5 c3 s* z9 i! ~4 C-AX = 0913h (Set Sice breakpoints)! F9 l* \) r0 F8 P9 ]' F
-AX = 0914h (Remove SIce breakoints)% P: E% J9 C9 y7 x e9 v9 X
2 h! ~1 Z' ]3 P8 nEach time you'll meet this trick, you'll see:. O3 [9 T6 A- }' x4 H1 i
-SI = 4647h! T6 h1 y: a" c+ z4 g4 S: R
-DI = 4A4Dh
) `" x+ X$ j+ g bWhich are the 'magic values' used by SoftIce.
- G* s0 d' o6 E( n9 |$ Y# W. s" dFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.( u' ]2 n6 W( x0 A. {% g0 `
- t3 q3 N. x1 m; {Here is one example from the file "Haspinst.exe" which is the dongle HASP
3 U8 }+ ~& k4 s0 kEnvelope utility use to protect DOS applications:- m, \: l g8 w; ~- \7 N( z
( v& @8 u! P' `: I9 i0 o8 c1 S$ k) }/ s+ d
4C19:0095 MOV AX,0911 ; execute command.
2 P- s0 ~( Z/ o3 f+ J4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).% d/ h) Q3 n" b. {$ i. G
4C19:009A MOV SI,4647 ; 1st magic value.2 t2 Z4 d, x S" w/ A, U
4C19:009D MOV DI,4A4D ; 2nd magic value.
) F5 X/ O1 G: @3 Z+ J' x" v4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
* ~1 Y' L) Z$ ~' G7 d7 ^4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
/ \& u8 A# J* x$ R6 {4C19:00A4 INC CX
) A y! F/ I( D( i# N4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
. }0 M8 t# a# {, F; [4C19:00A8 JB 0095 ; 6 different commands.
7 z+ {6 J: n+ E4C19:00AA JMP 0002 ; Bad_Guy jmp back.; v6 L& V( R: j" M3 O
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)! ?3 F4 x3 g( L
5 d) b; i' H c* ?The program will execute 6 different SIce commands located at ds:dx, which" i8 t5 V/ |5 I7 e; M" E
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
' g( f. W, P$ I. X2 E% H7 [
. c3 K) ~6 f" x0 Z: b* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded." g v# d# r- g3 }$ e7 E+ M( ^
___________________________________________________________________________
1 H9 M4 X4 U9 p6 I7 E2 Y& \' j
$ f/ }- ]/ q+ ^ R) F2 H5 J2 [0 O/ {1 `( e0 y4 C- M# ]; i; ?
Method 03
7 H, ~2 [- [4 c& a9 M3 y' i/ r6 _=========
( ?8 o5 C: q3 t6 Z( `4 _
1 ~/ z' V( B6 M' s1 n0 N9 L- B- u5 kLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h. y! O. }" J+ \( M
(API Get entry point)
, N( K% _: Z$ [! b1 y& |" e " h3 X/ ~$ n: }5 k2 h* _6 q9 p
Y9 M: U* U8 M$ s3 d
xor di,di
4 \0 u5 l" `4 ^ mov es,di
6 ~3 h, t+ P! k# K; \4 ?. F( Z mov ax, 1684h
1 W7 x/ t; O. l, S4 D2 [ mov bx, 0202h ; VxD ID of winice
7 K0 Q2 }0 o. s0 W$ _ ]5 [8 f/ W int 2Fh
0 e1 q' V* q) B/ x0 u mov ax, es ; ES:DI -> VxD API entry point
( Y w7 l0 i* ^( w+ h add ax, di( O( Z- K a& Z7 h3 |2 s: ?& T
test ax,ax
' ?' T. m8 E/ ?0 P jnz SoftICE_Detected
& ^. k. A+ i; G; E
0 Y$ s1 Q9 o0 B) u. ____________________________________________________________________________
3 @+ E. p7 B `3 j
- m4 }' `; e5 t( R9 } T) BMethod 04; I ?0 T! G/ _ u" S" j$ `
=========
, p. S& i, C$ H: ~4 f3 y4 R8 p8 ~/ M
Method identical to the preceding one except that it seeks the ID of SoftICE
7 V# q; p/ b9 [9 T. O- |GFX VxD.2 p6 B Z) b0 s- W2 w
) i. T9 u4 ~ {. t
xor di,di
! [. O8 L) `9 F2 @8 {$ b1 I mov es,di( \& ?# k& Z0 J! j+ ], u
mov ax, 1684h - J. b- \2 M2 q
mov bx, 7a5Fh ; VxD ID of SIWVID
( n% O. }6 |6 y int 2fh8 f2 g# ^' h- O2 \9 T( }
mov ax, es ; ES:DI -> VxD API entry point
B$ r1 s$ v0 |, |$ e: e add ax, di9 ^0 J3 Z: O3 t+ Y
test ax,ax
5 v4 A4 @$ B+ V: O, V jnz SoftICE_Detected
# o& R1 @; P% V+ g$ O5 K
/ y1 h V: M. y6 G, ~__________________________________________________________________________! s7 x) A8 v1 j o4 `; `
8 S; A% ^' b) G
& |% b7 X( v" z9 n" xMethod 05. ` i7 T8 J# c
=========
' Z" _( o! i9 D4 \" Q( W) Y! X
) Q7 @( T/ A+ d' O5 }1 bMethod seeking the 'magic number' 0F386h returned (in ax) by all system
9 N7 k) B' q+ F, m4 edebugger. It calls the int 41h, function 4Fh. O, M' W7 r) j3 K1 Z# ^
There are several alternatives.
" \% Q/ ~9 P2 ]& s j# {: q2 U9 K) n
The following one is the simplest:
5 z4 Q }. }9 \4 j" c# Z+ U2 M- T" x( o
mov ax,4fh+ e# ]/ u4 v' B+ m* n7 S
int 41h
1 z0 }. V2 E, |6 A cmp ax, 0F386
. y# t% g# I# A, u jz SoftICE_detected3 a- @6 G& O/ w# h/ _! Y; Z
) l- R0 m7 f0 a
* v" @* d5 r3 x( l/ |Next method as well as the following one are 2 examples from Stone's ! p, C9 i$ c1 h4 @. _
"stn-wid.zip" (www.cracking.net):
! V$ S" V: u K$ a, k8 c% K2 V5 e, Q$ l9 e3 s: X
mov bx, cs
" `8 W5 Z# r7 D, R& X lea dx, int41handler2
; S2 ?2 t* R0 P xchg dx, es:[41h*4]6 c! k1 Z4 |5 R+ J: u$ Y
xchg bx, es:[41h*4+2]
7 L. p8 I9 E) C1 U' ?, y+ \4 b: C mov ax,4fh
4 C' Q7 W- ?8 s6 D3 l0 p int 41h# T! t% d5 e8 U0 T) X( @
xchg dx, es:[41h*4]
6 A: A7 b6 }& A5 L! w- y xchg bx, es:[41h*4+2]* K; C4 J' m2 o2 n: H
cmp ax, 0f386h
; N# Y- @0 u. I# W* Q: C' ^7 } jz SoftICE_detected ?0 x7 N7 U7 ]( t1 ]0 {3 z1 o* M
4 P1 F" C: F- H3 y$ J: m: x
int41handler2 PROC
# q: u" k# @- D, _% ] iret A4 H0 K! [2 Z7 _
int41handler2 ENDP: I# N7 I! S% t/ I% u% t
8 A( }2 D, o# x5 v: Z- p+ V
f9 j7 R& n( Z' w; X_________________________________________________________________________; L5 U( X+ A9 s, G' r" Z0 F
' E8 s* G; } x0 A0 C- ?4 x' t' k* R# q
Method 06
. a! j) f; e0 g' l4 ?/ a& h=========1 V0 @$ d. h1 W, e1 c8 r
' L+ D& E' p) J6 ]9 Y
k( {) I8 M0 L- c' ?: U1 ~2nd method similar to the preceding one but more difficult to detect:- a+ t: x7 ^7 p0 I, l' Q& D
4 t @2 w" d% Y, ?
4 R c+ X, R; {* r7 Lint41handler PROC! r- b( C4 @) Q. d& x- z' u- T
mov cl,al
+ {+ G {# Q/ O iret3 K0 c4 X. B) L& D* J1 E1 X. z
int41handler ENDP6 r9 S- t- { x0 d* D% C2 U
Y& z' Y; c! c: e! C$ i, H
# \, y5 N) F7 @/ X xor ax,ax7 i' {& J; Z% t; b* r6 b+ {
mov es,ax
/ t/ w' a" N7 N% T$ g: H6 P mov bx, cs
, h" Z7 u, H+ i6 E$ l. I: | lea dx, int41handler* Q, }+ y1 f+ B" h0 p
xchg dx, es:[41h*4]
2 C; P' r; Q7 `% ?, O* ` xchg bx, es:[41h*4+2]0 h) r9 z8 `0 R: U& B& o" x/ N4 P
in al, 40h
, s# J7 U+ \$ H8 e xor cx,cx
$ J G; f. w) R+ |* T [0 X int 41h
% z/ u* w% }( s5 X xchg dx, es:[41h*4]
, m3 f. A+ T v: ? xchg bx, es:[41h*4+2]
l3 j% T4 h% l( R/ W( D0 U cmp cl,al
3 Y* L |' I/ G* ?! N jnz SoftICE_detected
u/ i6 t8 e7 ], A7 b! f( k9 `3 ~# {# n2 B6 b) R
_________________________________________________________________________; X0 M7 l% C3 K, g+ s. B& f
6 R( _0 x% z0 V3 E& G
Method 07
# k j0 N* v% y( ^& }. U6 {=========8 q; y. X$ M$ v( V0 Z: [# N
) ^' {/ B6 `, k5 ]& [0 k) M
Method of detection of the WinICE handler in the int68h (V86)
5 I! Y7 _. H) g7 I
% o9 i1 ?! a5 F. _0 I# ]6 L mov ah,43h
% X7 a; s( H* S8 k. x int 68h
' V4 w! w t$ F, k3 K cmp ax,0F386h
0 k4 F3 ?9 E8 Q& K0 ` jz SoftICE_Detected
( t. o2 f% |* D3 {6 f. F( W- m" H- y& A& D$ |, n) v/ {1 D
9 _. j" T! g: Q, K=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit4 t- X/ O2 K# {/ t
app like this:
% K) n. \6 h% {" G
! M j- o: C% t5 w2 S( _ BPX exec_int if ax==68
9 C8 U2 S, X( E9 L7 e7 M u: Q (function called is located at byte ptr [ebp+1Dh] and client eip is9 f, E: h" e5 k2 O6 q) j$ |6 n
located at [ebp+48h] for 32Bit apps)' s- b6 ~9 h3 [
__________________________________________________________________________& @6 ~8 u+ v- R3 }: Q% {
, k$ z4 O; q0 J0 Z
' S/ X/ ?! u% n& aMethod 089 n3 _. q. k, H6 ^4 w' B" G
=========2 T; _; N; H5 e# w9 g+ Y
# X8 H. a3 e- U9 R2 R! b3 WIt is not a method of detection of SoftICE but a possibility to crash the
! I- ]& K9 F7 s0 Y" psystem by intercepting int 01h and int 03h and redirecting them to another; C+ o/ o$ v4 C0 W. m& i
routine.7 N, ]3 i. M# z
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points y- M+ H3 b; ^, |0 B u& X- |9 }( M
to the new routine to execute (hangs computer...)
; u( Z* \. R4 w$ o" {7 u0 R
; t( G3 N7 X. q$ o$ U( P" @1 z( P mov ah, 25h
, C. \$ r7 C' u8 C1 R mov al, Int_Number (01h or 03h)
1 f" k+ ~7 t, U6 r mov dx, offset New_Int_Routine
: k& u& V6 A/ a G* { int 21h
: f7 `8 Y) J, ?
* a2 B4 F* S' {* g* ?5 }; k0 r% _" W__________________________________________________________________________6 i- Y# S- ~: U' ?. P9 h
4 C% S( C) Z! h- w# H" A3 H* F
Method 09
j: y& t9 |4 D=========
0 _6 i8 R( B6 [ v) F% G- z
. n3 f# _* \ D1 ^This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only% ~' M- z R3 |' X# X$ ^$ e
performed in ring0 (VxD or a ring3 app using the VxdCall).
1 U# b4 T B. `The Get_DDB service is used to determine whether or not a VxD is installed
6 }' k; c/ T0 jfor the specified device and returns a Device Description Block (in ecx) for( d2 m. |3 I) q& D
that device if it is installed.
( d* S& h- Z; h( E7 j4 I
7 P; G0 Y J! `! F mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
1 t" p6 B0 ?& o. ^7 |2 J2 W- \9 ? mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)3 I6 t, C: _/ ]0 p$ J
VMMCall Get_DDB4 ^" y: B( a0 m# u, T, x3 W
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
6 i1 ?7 n0 ^4 g& ?5 u% ~ f0 O; o: K( g; p; e3 z
Note as well that you can easily detect this method with SoftICE:
* }3 }3 ~6 h" ^) |1 y bpx Get_DDB if ax==0202 || ax==7a5fh
5 @- i) _& _" N8 g1 }
h9 m7 p9 ]! i/ ?__________________________________________________________________________$ L* i1 p+ O* C* O3 @4 g! [1 \
4 Q/ t9 a7 j. z5 W! Z6 a- H/ D1 `
Method 10; n1 W1 x |4 L6 {* x
=========# b' _! m6 _; s7 o, i7 [6 i$ {
( u. B! m- j- k. l' X
=>Disable or clear breakpoints before using this feature. DO NOT trace with: t' K5 B6 H1 U5 l
SoftICE while the option is enable!!; \3 Z3 q: A5 V
: X2 K3 m% Y2 H) s' y4 pThis trick is very efficient:
* K( E4 e7 g/ a6 O; A6 z# Bby checking the Debug Registers, you can detect if SoftICE is loaded0 J$ u5 N! e; ?* m
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if+ B, R; H/ e# h. y, {. F! q% y3 p
there are some memory breakpoints set (dr0 to dr3) simply by reading their' o ?. Q# e' n6 g) d
value (in ring0 only). Values can be manipulated and or changed as well
( X# q- O- N( O6 `4 C(clearing BPMs for instance)5 ]7 Q% g. @$ y% d2 _
$ Z: f# j4 H- X: q) D g- w3 m
__________________________________________________________________________
( n. i- q+ ^* x8 H7 }4 L1 ~
2 B, s" S3 g z1 IMethod 111 {0 d4 B$ R O: ~
========= O) K& ]' p6 b5 ?3 x E+ W# w
a" e" P6 T& ^ nThis method is most known as 'MeltICE' because it has been freely distributed+ C4 S3 }0 i: J( v* ]9 e3 y* |
via www.winfiles.com. However it was first used by NuMega people to allow
7 o5 }2 x8 T/ ~Symbol Loader to check if SoftICE was active or not (the code is located
, B" u+ U8 C8 g8 ^# [- hinside nmtrans.dll).
( L$ v2 x! T8 a9 W+ S, c. i
$ E) L2 g- r1 X, n# Y) k. c. gThe way it works is very simple:
) h- k$ ]* Z* r3 mIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for, G; s/ \. Y/ C( t+ q) o
WinNT) with the CreateFileA API.
9 H$ V, f7 w9 s- W, k; i) F% W. _. D" S% [
Here is a sample (checking for 'SICE'):
" X9 n+ g" f% K- \
$ C( r7 y/ X0 O7 s* \/ J: \BOOL IsSoftIce95Loaded()
8 n+ Y/ t+ Y) k5 y* d{1 u: d: r4 Y z
HANDLE hFile;
( T7 m# u) P# i hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,5 T, K3 E9 t; x4 O# M. }
FILE_SHARE_READ | FILE_SHARE_WRITE,
' ~7 J# l" I$ N8 b NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);/ M% x& D$ a# g; H4 X' E0 @# D
if( hFile != INVALID_HANDLE_VALUE )
3 ]# n F+ o2 {/ ]6 F3 d {, f. L% y* a( E7 t* j# V
CloseHandle(hFile);
& I( b5 p/ K1 e return TRUE;
$ S" Q$ I- A/ ^& [* n& N: q* n5 a }
1 A+ V1 e# ?% t, x return FALSE;
' ~! L: m% ]5 }* o5 E* h: p}
3 o! X7 |) {8 w: J0 w% z% Q4 o- c& H) U+ U, ~$ y
Although this trick calls the CreateFileA function, don't even expect to be. h5 o3 a% y" _5 f R
able to intercept it by installing a IFS hook: it will not work, no way!
& H: L, w1 c+ \+ ^In fact, after the call to CreateFileA it will get through VWIN32 0x001F: a; i1 [( r7 B. [
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)6 `" \ [0 Y8 ~9 h
and then browse the DDB list until it find the VxD and its DDB_Control_Proc, o6 z) _% _+ R
field.
7 v; M% E% m# ?4 m& k, f! f- SIn fact, its purpose is not to load/unload VxDs but only to send a 9 [4 U; q+ T( k
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)1 N. i C# w1 b( Z8 c% P
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
( e2 q7 `4 i5 F6 T- \" Xto load/unload a non-dynamically loadable driver such as SoftICE ;-).# ]" k3 @, B1 Z8 B
If the VxD is loaded, it will always clear eax and the Carry flag to allow
# @* }& |# z+ n9 E5 jits handle to be opened and then, will be detected.7 @. ~, f2 n. `, d8 y/ k
You can check that simply by hooking Winice.exe control proc entry point2 ?' g( x1 r" b0 S: {4 _# w
while running MeltICE.
9 P, a4 |2 @0 D/ e s1 k
- w" h5 y- {4 J7 ], T a
8 G& \! V' N9 w. q$ C 00401067: push 00402025 ; \\.\SICE0 J$ f& a/ ~+ l( p
0040106C: call CreateFileA
3 ?" @) L3 ^ P @, C 00401071: cmp eax,-001$ d6 X/ s/ H! b7 F& a7 Z
00401074: je 00401091
, [/ c' k+ @+ s2 r' m5 a/ w# l7 Y U, W. F, R
' W6 W* s) \1 H7 a8 g( m6 ~
There could be hundreds of BPX you could use to detect this trick.
9 R: l+ V- \; d2 n" ]-The most classical one is:
1 A* T+ `4 u( q" ]8 m BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||! \" D7 _- U. w& U7 O+ Z: p2 `3 t8 n
*(esp->4+4)=='NTIC'
* a5 L# w4 v: p9 }% L. E
% h; }5 F* \3 K3 c-The most exotic ones (could be very slooooow :-(
' a9 r, c5 ]4 _4 q0 r; H+ V- ^ BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
5 d) H$ w; g% s ;will break 3 times :-(
; C- V: C3 D. y1 M9 T* Q; D# k- ?+ d1 p# c9 x H
-or (a bit) faster: " m% s. L2 w" r+ x$ }
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
' D( L! ~, I2 K/ A: B! f( }, c- F! H/ U$ G2 e6 f
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
* x2 k) W/ p1 t; P6 _ ;will break 3 times :-(
0 ^& t+ q" F& Q7 I7 t0 D& h5 i6 T; ]4 i E( }1 q7 e& ?% f& \
-Much faster:/ E/ H9 V# ~( l q
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'- C6 E% R' n" p
: Y2 V' i3 P+ N: Y8 x
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
6 Q, |) i, v, \, tfunction to do the same job:
s$ _) s$ d p' B9 P
; c7 ?3 g* q2 B$ @& V; I push 00 ; OF_READ
) m j# h5 b* i. n" w) z$ r mov eax,[00656634] ; '\\.\SICE',0" B: o: O ~4 A/ |) t4 I& H1 e, f
push eax
, P' x1 i- R! K call KERNEL32!_lopen/ Z# I' `; s2 o/ }0 {- d
inc eax
. m# e1 `/ M2 M6 }; Q& D6 a3 z2 f jnz 00650589 ; detected
9 B+ F; D9 V$ j' s push 00 ; OF_READ3 w# Q( P% I- p r/ }
mov eax,[00656638] ; '\\.\SICE'
' b4 ^; \. p6 x0 T* ^, q+ A1 X push eax, o. k2 N$ S: x, N% J. R4 n6 c
call KERNEL32!_lopen
% n; ^. }9 I# J; t/ H" o5 i inc eax' H; m& m' q2 C8 a3 S* s4 |
jz 006505ae ; not detected5 ` A! Z6 v2 i6 ~
4 Z8 I# a* J; U7 L3 t' _2 B) k ^0 R0 a* I
__________________________________________________________________________
, M6 j& H- ~3 c6 \) o1 s4 B2 F' d1 y
Method 12
/ a2 j' V4 [8 E* Z=========
( W$ v! O& Q7 o% X; h! K9 c$ `* d$ _3 H% l! n- U& p6 @
This trick is similar to int41h/4fh Debugger installation check (code 05% B9 d0 C* U9 o6 I; T/ {
& 06) but very limited because it's only available for Win95/98 (not NT)
g8 x& i. O9 kas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
: s# N8 J8 e4 [1 R0 S! D/ h
, u# a/ Q! a H push 0000004fh ; function 4fh
% `& L, z* b. u& S& F9 j, e push 002a002ah ; high word specifies which VxD (VWIN32)
# o' I5 c' ?0 i9 z# M: K ; low word specifies which service6 F9 D- P4 l8 z( E% S$ B0 z
(VWIN32_Int41Dispatch)
) j/ O* h# z% y+ i x. G call Kernel32!ORD_001 ; VxdCall) ?( D; A k/ w4 P- E- @8 x! Z0 o4 ^
cmp ax, 0f386h ; magic number returned by system debuggers
9 y6 V4 ^3 Z$ E. r) O1 K& Y jz SoftICE_detected
$ ?* D/ c2 l% h. v& J; W( R8 u) k( r$ }" }+ Y1 H
Here again, several ways to detect it:
1 ]- z) Y) w' j' U- M+ E: h# ?5 U6 n8 c5 |! i& W& `
BPINT 41 if ax==4f, b2 {/ Q2 S! ^
" q$ l( M' T* Q8 B8 Z( q
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
, |8 \! a1 N5 @) O
1 K {5 `# s2 p; X+ W1 m1 s BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A* a7 p$ H8 S' L: [+ e
6 k4 x" J/ Q6 b$ r BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!8 V% W3 x& E: B, f' @/ i% _
( P: a( F) j. ]" @__________________________________________________________________________
b! n- ^" P8 U. l" a) @- x! v$ X8 Z
Method 134 N; B6 e% s, t; Q
=========
. a" ~! s9 h' E. J
3 k7 u1 J6 j4 X& g x; WNot a real method of detection, but a good way to know if SoftICE is
' B8 V4 E7 e" oinstalled on a computer and to locate its installation directory.7 C [: E; R; f# Q: i" j6 i
It is used by few softs which access the following registry keys (usually #2) :
+ N7 p2 Z9 h( n+ q% |7 w3 E+ H
0 x; L& ~' o5 q# E: a0 _* `-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion1 I- _* C0 q" G; @
\Uninstall\SoftICE
z5 F& l& V! y O% z o0 O0 Y-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
, h+ t' h3 W/ v* L-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 W3 v; r5 h, ]7 R0 v
\App Paths\Loader32.Exe; @, ^( g4 D+ ?' K% I! q
7 n% H# \! N9 K" W. n4 `. ^
3 g, U$ S: L3 Q# D; mNote that some nasty apps could then erase all files from SoftICE directory: z% w1 x; { O1 i. I
(I faced that once :-(- @. s- r6 ? G* k
2 p: i" m" v4 M1 ^7 o6 M! _
Useful breakpoint to detect it:
% o! X: s( j1 ^: I: X% B& L- F* P, r9 X$ m
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
6 j; }1 w0 p2 G, z: a8 D( Y3 z/ b3 r) T( D# v$ W' G4 P( j
__________________________________________________________________________
) O! a/ E7 Q0 h2 N; g5 T
& A7 \6 \' y- H7 W" e! |6 F' H7 B- F7 d+ S* X" d
Method 14 2 N& g$ v$ Z$ Q: g2 t5 @8 Y: L
========= x6 D4 C4 v( z' q7 N7 A0 R2 q4 w/ E
0 I, O4 \0 c' v, DA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose3 } d H4 g! R" m3 c5 \
is to determines whether a debugger is running on your system (ring0 only).
" s& a; \) r% q- F. ~4 @1 U- ~( H- m3 x2 B* ]. \
VMMCall Test_Debug_Installed0 t3 J, L: O" U9 l' w! ~' @: ]
je not_installed4 D9 S# l$ h8 W5 n5 @ ~; h
' o; E# A* S# P$ i9 X4 j
This service just checks a flag.
9 T4 B4 E" T7 h</PRE></TD></TR></TBODY></TABLE> |