<TABLE width=500>
o# c- ~/ Z" z2 ?, r2 X e9 o<TBODY>
/ |* b& N. J" h4 M7 y<TR>
$ Q$ \6 P/ O. h% n8 p( |8 c: ~2 {<TD><PRE>Method 01
( F( }& C' [- q% d" \=========3 h9 _5 `# M/ F, d0 B
, w- K7 b+ }# \, L
This method of detection of SoftICE (as well as the following one) is
A7 H0 g- X1 bused by the majority of packers/encryptors found on Internet.. Y; m5 c+ Y7 h) q6 L9 n/ q
It seeks the signature of BoundsChecker in SoftICE
7 }2 i+ ~" S/ R; N3 L- m& J0 k" l. o5 a& u
mov ebp, 04243484Bh ; 'BCHK'
$ N d7 }, ~3 V! V4 M mov ax, 04h% `" A% h) `+ d7 z
int 3 1 p3 _9 d3 U& v9 V3 c [
cmp al,4
; ]" X% S" ?" y; k jnz SoftICE_Detected9 ?, U9 C% U4 v! U, N
) @& B3 A! f9 F6 x8 e
___________________________________________________________________________' T7 U- | Z b! l: u4 Q$ U
- k- ]0 l* }8 D- [; w& |Method 02
0 X$ t" E% v- X=========
0 q9 n& X3 z( r$ p3 B( f1 \/ k) R4 u. O5 d5 q: p' w
Still a method very much used (perhaps the most frequent one). It is used
& U5 r) L J; m; V$ k5 X jto get SoftICE 'Back Door commands' which gives infos on Breakpoints,8 y* F* H1 H _' a8 f
or execute SoftICE commands...
8 a0 @! v; o. \& k# w/ OIt is also used to crash SoftICE and to force it to execute any commands
* e; N, k, d/ }- t$ d1 g" Y(HBOOT...) :-((
" S V% A& J7 C% d3 u
! v) j+ G7 v" X r/ q: ~( i- QHere is a quick description:8 l4 I! ?7 W- {4 p1 i' V
-AX = 0910h (Display string in SIce windows)
) ^5 Q: {) Q! k- x N& [-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
4 ~* F- u( W2 }5 K-AX = 0912h (Get breakpoint infos)( g4 D. |) o, b5 g/ D7 V7 p
-AX = 0913h (Set Sice breakpoints)
( Z6 x" g3 p U& h$ @7 k-AX = 0914h (Remove SIce breakoints). p2 }, s* f/ m1 M$ w7 m
# R. m# c1 ]$ B: M: P; G }% t1 W# ~
Each time you'll meet this trick, you'll see:* ]8 N' V1 }* e6 U: m6 f
-SI = 4647h
' J! O0 Z4 P A. o8 j) {5 s% J-DI = 4A4Dh4 B- T5 r! ?( x% b9 q; ]
Which are the 'magic values' used by SoftIce. {- q) J0 E8 Q7 z
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.; P9 S3 l, C$ n/ \. Z3 h
5 v C, J1 ~! R8 @7 [ c) ~; @) h
Here is one example from the file "Haspinst.exe" which is the dongle HASP& Q" P. C w. w- _* u
Envelope utility use to protect DOS applications:: q9 {; R# y9 j3 ]
1 Y6 O9 v( c9 Q t- U. e
2 d p9 q8 r: B( T8 j3 ? o" D$ d4C19:0095 MOV AX,0911 ; execute command.
( O. ~' `: k& \/ Q& f7 ~' _4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
' T' U& T" c, e4C19:009A MOV SI,4647 ; 1st magic value.
/ R3 W3 B' \, K: r5 I- i4 q4C19:009D MOV DI,4A4D ; 2nd magic value.
1 e8 e7 j% K( A' L5 D3 o9 n/ Q4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
1 V0 ]& K: S+ L' h6 E" B) m% A1 ]7 P4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute `- F1 x. P) V
4C19:00A4 INC CX
0 d2 h3 P8 Q" `5 |% c. d4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
/ f& N, i& Z% d4 q: g( j8 T4C19:00A8 JB 0095 ; 6 different commands.; a: a' h4 A% f) z
4C19:00AA JMP 0002 ; Bad_Guy jmp back. ?, @# S5 ^( L1 j P/ L* o e
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
T' T5 s6 S+ a5 x- b" U
' }) M$ d$ C1 T9 e0 h6 rThe program will execute 6 different SIce commands located at ds:dx, which* B I8 f) W4 s0 b- I+ s O
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.) Z6 M( L* `) [$ l% a# S; s( U$ ^- k
' d7 O% |- @4 O% e) k( y* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.! g4 o) o8 T7 O& n, b
___________________________________________________________________________3 c3 b2 ~2 A. F# t
$ X' F) g8 i* \: h6 w9 U" H; s. v7 ` g! z
Method 03. n) R" e: C- l5 b/ G: B5 @3 ]' r
=========
! K7 y0 ^( Z* E2 o2 Q, q. |, z
; B. \" }* o, k8 z7 t1 ~# eLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h/ z, A* E/ O6 N. v- f
(API Get entry point)% p* c7 M! e" x7 I0 b
- p$ L+ v# F5 a8 V: C& g* c, S* s4 Z
xor di,di3 ]# g5 g# |" S6 s/ l) T( C ?
mov es,di
& c2 S3 ~3 [9 D, H# s mov ax, 1684h 3 |! q" h' I; w, v
mov bx, 0202h ; VxD ID of winice
; p; _, L R- | int 2Fh& I/ c6 m- T& k8 k# o& I8 i
mov ax, es ; ES:DI -> VxD API entry point8 F) n% d, ]6 U3 h
add ax, di( ]" X' o& g o4 p7 K
test ax,ax
' w- Z7 O# q0 j; C5 V) K, S jnz SoftICE_Detected1 l& _) D' ?' A8 i+ Q) I* f
# p2 J! f8 c8 ?8 \5 S1 I8 ^% h9 F___________________________________________________________________________4 Z* _0 T2 o" S* H- e/ a
7 q% m, ~& H% c2 S: D
Method 04
8 w8 ^ \' r5 o+ c=========
# t; i/ Q1 ?0 i( o9 P$ U8 F: V' M: @* Q1 B2 q5 y
Method identical to the preceding one except that it seeks the ID of SoftICE
* i3 [5 [& q( XGFX VxD.+ @7 |5 [, d5 l+ O
4 E5 D' g7 f5 H/ t9 `6 J
xor di,di
9 N' ?& M' `/ q1 ` mov es,di) v' ~4 O, S( s, F, p# D
mov ax, 1684h
' ?9 t2 x8 k+ e' ` mov bx, 7a5Fh ; VxD ID of SIWVID8 c- y( y% q/ K8 H$ z$ [6 e
int 2fh0 P: e& P% n# ~* @# X; G
mov ax, es ; ES:DI -> VxD API entry point
3 v3 @+ u* K! {( y add ax, di4 ?, F1 C8 M* @) U9 b3 L2 A
test ax,ax
/ }' p) T) M- L. V5 W6 r jnz SoftICE_Detected
! ~& Q# o. c* \) B$ m2 ]
7 J2 \3 Y) I& ~__________________________________________________________________________# a: v2 {! W- O1 O& W$ y
2 y6 r$ z) e) d# `& @ M6 L2 Q& J
& }, b2 v' a _5 O5 H
Method 05
/ n7 |# ^7 e9 d: W+ g=========" p R+ w* M1 G( P3 X
, J; k! j {; u2 n7 a i
Method seeking the 'magic number' 0F386h returned (in ax) by all system2 D6 e, o+ r/ _
debugger. It calls the int 41h, function 4Fh.
5 a3 n; r: q5 [ mThere are several alternatives.
y$ U# p( a( j. q' N6 Z* x) W& ?- s; S
The following one is the simplest:
# M5 M6 g# t( @2 B5 ]' I% o: @2 F" {+ p W& r
mov ax,4fh
4 w! g; I& L! }: H* v int 41h
3 Y/ ?1 | o: p# J# P' g cmp ax, 0F386
1 M* v$ F1 I# E5 l+ u) N/ e% F jz SoftICE_detected
& H6 g$ y( F; q* k% x4 [2 ?& K
$ N; e; f* d* P9 b8 G' J# X/ B9 c# ~/ M! {0 n* }
Next method as well as the following one are 2 examples from Stone's
# O4 Z# s6 `% r+ x' R"stn-wid.zip" (www.cracking.net):
* X, I: v% ?2 s( V! p3 \/ O
3 s: R" n: c/ e; c* }- H/ b mov bx, cs
1 t! x8 D, U* v f4 ^ x2 c lea dx, int41handler2/ M2 V" a1 R1 i9 A# p
xchg dx, es:[41h*4]
( V# `9 _* J' o" s: Q0 K. I: k4 o xchg bx, es:[41h*4+2]
( Q, Q+ u. n' s0 E. Y$ I mov ax,4fh
$ U5 B ]& d3 g# f! }/ i- ` int 41h
& b% M$ }! z0 }1 m xchg dx, es:[41h*4]; K; J2 V$ E7 }% t
xchg bx, es:[41h*4+2]
( y" l# T9 M/ G9 v" b cmp ax, 0f386h# W" S7 z" T1 K: `& i
jz SoftICE_detected% H4 F9 m% D- Z# p. E8 P. L7 q3 _
+ U! e4 B% g# A$ T2 k# ?int41handler2 PROC ?0 _ \% [- p$ v- {
iret
) V- m9 ^, }1 U+ U c, c7 u6 |int41handler2 ENDP: n3 p1 y# l2 N: i
2 I& a; P4 m. e" P2 a
% I: L. {6 x" T5 r$ B_________________________________________________________________________
: w. {! d5 M. D' F/ B/ N/ d# h3 D4 B+ w/ ] p) y
9 v/ ?' F: P7 e! {) c' [
Method 06% N) [4 P+ J7 K8 ?4 M" ]. O) v4 \( ?' v
=========
/ Q# l4 z( s2 P5 d0 y
$ e* Y- ]% P! M3 N3 l% `2 N- f: z% p- D1 j+ o% S* Z8 Y
2nd method similar to the preceding one but more difficult to detect:
! W F9 G! S' [1 f
5 R6 f) x. y0 v) D2 L, x& l
& B& X; r; y' h5 q+ g2 Fint41handler PROC' T- L# A4 d7 P* s8 Q4 q8 C
mov cl,al
; X' d' ^; n9 R- P: R4 C0 H iret
& D5 w2 d9 z+ A4 l. Mint41handler ENDP7 I* \0 Q" g$ X8 N
( O# r0 d" [. y1 w! i
1 i% A q: y" r) y) i+ ?$ Q% b xor ax,ax9 h$ B- y6 z8 M U. F5 [
mov es,ax' T$ c3 N$ b0 G0 ~7 k. s$ J0 y# ]
mov bx, cs9 f" a$ k/ U6 ?) o- R4 e, v$ j
lea dx, int41handler4 @! o8 U2 M/ C x& | v
xchg dx, es:[41h*4]2 n; p3 Z1 A" [* E) V; G
xchg bx, es:[41h*4+2]. L0 g, M0 U0 h
in al, 40h5 u/ @: Z- j; r1 P7 g$ M! ?; i( `$ i
xor cx,cx
6 ^9 u7 ?! ]: q int 41h
5 l2 I0 O/ `( L xchg dx, es:[41h*4]
4 K" B, v# d* [* ? xchg bx, es:[41h*4+2]
- E3 L1 n1 M: p* y cmp cl,al0 n2 J( J6 A9 C: Q8 U
jnz SoftICE_detected
" w4 }' O# ~/ C6 R' Z0 n" V& e0 m1 E% r
_________________________________________________________________________
1 Q2 i( q$ Q% G3 _
/ u- }, v* G3 oMethod 076 e5 z) r1 ]" \: @, U4 M5 V9 z
=========
6 X7 ?+ ^0 F- `) S: T7 @4 ] e ~, d' [' N( D
Method of detection of the WinICE handler in the int68h (V86)
8 ? a Y. a7 L- Y
9 T f! m( `7 H% s0 \ mov ah,43h4 V+ ?: k' y$ p' v
int 68h
8 G: B/ N$ |2 f7 N1 w$ b, G' g cmp ax,0F386h
4 w& D, ~, Z6 w, L q jz SoftICE_Detected
, f5 i `& U1 R
# Z+ }# D$ u4 C/ Q$ G- Y
6 _* g4 j* p% |: P, q! T7 Y: R; e+ j=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
$ { d7 M4 S2 o% W) h7 s app like this:
: I4 A7 S7 n' X4 v/ m
% `- W' B( K4 S% r( { BPX exec_int if ax==68
: @! i7 o6 o- l& w' M (function called is located at byte ptr [ebp+1Dh] and client eip is v# K& g. i7 L1 I5 O# @! h$ A
located at [ebp+48h] for 32Bit apps)
0 r; N% v0 S+ {' P/ n* t__________________________________________________________________________4 W; _. g, w5 {1 z3 M$ f% L- }& y
, N# P3 R9 b: [" v; B$ [: |2 M
F- J% `. ?" ]& j4 Y* H2 u
Method 08) D) w3 t3 |6 A ?) L
=========+ _: K2 C0 g) Q' c! J/ ~
+ W* E4 q* X+ s! I ?It is not a method of detection of SoftICE but a possibility to crash the
) U' i$ Z Z, C; y4 I6 e! p$ @system by intercepting int 01h and int 03h and redirecting them to another
8 d x6 J A1 Mroutine.1 K- L+ w# j% @1 X! l
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points* ?! y. C: y1 B& J d% C
to the new routine to execute (hangs computer...)
9 b2 s H6 s; H
t$ \# ?% w6 V$ k. s' D/ S0 { mov ah, 25h3 \" }" y P; f' {* E" G$ ^
mov al, Int_Number (01h or 03h)& v9 ^6 C- Y, Z5 Q! O, T) P# X: t
mov dx, offset New_Int_Routine
2 K, d+ l3 M3 a" G: k4 f. I int 21h
) R. }! C. M0 N6 n- Q3 f: I7 m( Y# m
__________________________________________________________________________
; e& c A7 [8 M4 t# j( E- r# F0 U
Method 09
. v3 l8 y4 R1 V/ S, @: F=========
& ?' Y: Z7 k2 x) F- W$ ]" ]! \# s c# G* i- }) L) ]
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
7 ]% w; N/ c1 k3 d. f) X0 eperformed in ring0 (VxD or a ring3 app using the VxdCall).
. \, P5 z+ L- c5 _7 Z0 cThe Get_DDB service is used to determine whether or not a VxD is installed, j1 M- D3 B& p- s) S# y/ x1 b
for the specified device and returns a Device Description Block (in ecx) for1 d5 p5 z9 g- R# D- i2 v
that device if it is installed./ f3 s! g) m- F
$ E5 s+ o- m# B7 y+ M2 L6 F
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
, |" L( s* h) m0 c$ ^& i mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)4 _" W* k8 h, j( D
VMMCall Get_DDB
! F" K- V7 ~7 X5 ]6 Z E mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
0 r3 b1 ?; n |, Q2 w2 T# W5 n. `( H
Note as well that you can easily detect this method with SoftICE:
+ r/ \ |. b$ D$ x/ r5 d bpx Get_DDB if ax==0202 || ax==7a5fh
3 k: y+ r9 C. t( n9 y2 Z B& `9 W( P& {% D( Y: |
__________________________________________________________________________
+ C$ h" r1 f7 E i A$ C+ b U7 t% T' b; r! g; _
Method 101 _9 L* H. T0 _+ W
=========
# C+ j/ G1 x4 t1 \* ~/ p' l8 {* @9 D4 ~& q
=>Disable or clear breakpoints before using this feature. DO NOT trace with* g1 ~; F0 `) l! _ T- R% k
SoftICE while the option is enable!!/ ~' u) a) A) z& p# k( V2 J
& p$ M8 u: m) }; ]. a" AThis trick is very efficient:
' w' D% q$ S+ \, q$ @' U0 }by checking the Debug Registers, you can detect if SoftICE is loaded5 z% i" D. {. D `3 X B& W" `7 M
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
* a# M" [ O, O6 ^" j' Kthere are some memory breakpoints set (dr0 to dr3) simply by reading their- T8 t* A+ U7 L D
value (in ring0 only). Values can be manipulated and or changed as well
9 v& V9 } n# q. k(clearing BPMs for instance)
# V" X8 S2 S L7 R
! b) j& L( P! i# W# B5 v! V__________________________________________________________________________
4 c+ [$ f% ?+ q6 n* M9 S B4 |- k% S0 \ n% S6 f' n; c
Method 111 z( ~; o3 ~$ c
=========$ _/ m$ m' h/ q: B+ U+ ?" F
G7 F9 @4 Z+ u- C0 S3 w" C
This method is most known as 'MeltICE' because it has been freely distributed
- R( Y, r0 A5 D9 a: ]& U+ A8 @9 `via www.winfiles.com. However it was first used by NuMega people to allow$ t! n1 C% i( F. X" Y
Symbol Loader to check if SoftICE was active or not (the code is located$ \- S( `. R5 ^: O2 h q9 v- S
inside nmtrans.dll).4 E6 s, @$ _# `6 a+ B; F
' ?$ P+ |& |. W$ L& V
The way it works is very simple:
9 `& v1 [- Z, i% v2 X zIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
- k4 @/ o4 Q) u! G6 _7 Z A# LWinNT) with the CreateFileA API.; E' _' e% N% b# i/ y$ t6 ^
" N6 R2 a( X I, x/ j0 QHere is a sample (checking for 'SICE'):3 h& l y6 H4 ]7 M t
; ]$ I' J0 k! GBOOL IsSoftIce95Loaded()2 D' U, \8 z0 r6 G; f
{
2 [' _; S" K3 f6 q+ z HANDLE hFile; 4 R1 @) F3 _0 T3 f
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
, F2 ]2 R7 q8 N) L FILE_SHARE_READ | FILE_SHARE_WRITE,8 d a1 N9 O. u# _ Z7 _
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);4 L7 @' F, S0 C9 n* R! A- ~7 c
if( hFile != INVALID_HANDLE_VALUE )6 \2 Z! `. \% @7 L+ j0 v
{
& T, `( n) F- E7 S1 H1 f) N" @ CloseHandle(hFile);8 s! D3 `8 s( a; B' G5 @" k3 z
return TRUE;
; I9 m- j" j2 f8 [+ k }
X- Z9 g8 ~2 ^3 f$ T3 s return FALSE;
9 x3 N; ?; h0 v: }9 y}: Z3 \6 [- R9 e, P: |7 x
: l: u4 `2 [. X Q" z
Although this trick calls the CreateFileA function, don't even expect to be
" f5 U4 |2 x1 \3 ~2 dable to intercept it by installing a IFS hook: it will not work, no way!
5 q" B% B9 j$ ?: X3 }6 _In fact, after the call to CreateFileA it will get through VWIN32 0x001F4 F- I5 S' x4 R8 ^
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
& o8 O) b; f9 P4 |and then browse the DDB list until it find the VxD and its DDB_Control_Proc- w- @4 t P9 P1 z, M' h3 B" m
field." ^& D& y1 z' [4 H6 p& I
In fact, its purpose is not to load/unload VxDs but only to send a : t1 w S" A! C3 d3 h" ]: N
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
, y$ Q* @4 Z$ p6 u8 tto the VxD Control_Dispatch proc (how the hell a shareware soft could try2 j+ p V4 D8 O, Z6 f
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
/ c# K% s7 O4 z1 }6 ZIf the VxD is loaded, it will always clear eax and the Carry flag to allow% h+ t) y* V' j" E
its handle to be opened and then, will be detected.7 y. y$ Z" x" S* Y; P, j2 |
You can check that simply by hooking Winice.exe control proc entry point
; q$ Q& @4 K# I, w( B9 n3 rwhile running MeltICE.
3 H$ w8 l8 k" X' p$ Q, T# `" N0 P" Y' `: B3 y
" M6 z5 K* M$ \7 R- o' H$ y 00401067: push 00402025 ; \\.\SICE
' N' z7 H4 i. S 0040106C: call CreateFileA
; T$ |3 v5 r" H5 t 00401071: cmp eax,-001
- ~4 ^- H, s$ A$ }; f% }( \! B 00401074: je 00401091+ l9 `. O; N' ~7 @0 W
% B2 G- `/ j1 e' m1 |0 o8 e V/ D
There could be hundreds of BPX you could use to detect this trick.
+ I: ~+ n d* `$ O0 t& d-The most classical one is:+ L; d2 e+ m5 a! N; J* i: k8 d
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
* `" l" n# Z$ U- w5 p *(esp->4+4)=='NTIC'
5 V1 ~: O/ z- u, j8 T
( n1 t1 x; @, R0 g-The most exotic ones (could be very slooooow :-(' I1 `9 V+ a6 C5 a- Y
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') , n% s, _9 E, T0 M. j1 B+ K: [
;will break 3 times :-(6 ?4 |4 I7 Y5 l
3 `8 I3 V0 }8 g" m& F7 p% m1 f
-or (a bit) faster: ( {4 `7 w; H2 b9 ]% V0 i
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')$ f6 k4 B* ^% C
X4 F8 K( l, {5 |& D% s" ] BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' . y$ C3 |7 e; P4 E* ~$ G% \& N
;will break 3 times :-(- X( T/ \( e' \6 R
) X/ Z, G- `. W
-Much faster:, Y ^. l1 l% ]" u! Y
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
N" N& A4 p- r3 B8 U* c
( T4 V8 G" q! @' X3 nNote also that some programs (like AZPR3.00) use de old 16-bit _lopen4 }. B0 I* W/ L: n" J+ b
function to do the same job:' M4 ]& K a& f4 P/ k7 z
, M1 e" M- x Z2 n9 ?3 _ push 00 ; OF_READ
4 s! _% v; K! u mov eax,[00656634] ; '\\.\SICE',0
$ C# u6 f8 a: {$ X$ k push eax3 _2 ^ P% S, n: v& S) N* I
call KERNEL32!_lopen) [ W- a& `' L6 u9 R$ @5 C
inc eax
' S4 I% s1 y: [% N+ J% ^" L( ? jnz 00650589 ; detected% M6 B" _* n. F" k0 b
push 00 ; OF_READ h( b. f* b( u, i
mov eax,[00656638] ; '\\.\SICE'
& Z6 }; a$ P& k( @& d% h. ] push eax
& c1 p. C( S! ~- a1 a3 e' G: V call KERNEL32!_lopen
& c1 s% S' @" j7 o3 \0 H inc eax
% J: T$ d9 C0 \9 m$ V4 a jz 006505ae ; not detected T1 H: [- N6 f! t/ i
5 v; S+ N. ^0 ?% j$ z! F! H% @$ v. H$ ^* O
__________________________________________________________________________. S; C& I* L9 y3 a1 F0 N
6 |* B1 J# x4 x4 U* l! GMethod 12% v l! {/ ^, m
=========- C0 H5 V+ a* n& ?" D" c6 z
, ^' [% Y2 k- D; L3 w, N' PThis trick is similar to int41h/4fh Debugger installation check (code 05$ E8 |, ~' K# R2 n' U( L# m7 ~
& 06) but very limited because it's only available for Win95/98 (not NT)$ X% b$ u4 P& i3 \$ k1 L8 a* F
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
( t' v `4 q7 S+ m# A. G( x p" Y+ y; O+ }7 t9 E! c$ N
push 0000004fh ; function 4fh
6 r. f( ~4 _: H% Z3 h push 002a002ah ; high word specifies which VxD (VWIN32)
1 n: I& [6 E2 l5 E# Z6 o9 v) V ; low word specifies which service
- x0 P8 v2 r9 X1 P6 [5 _0 n4 F' a5 f2 t (VWIN32_Int41Dispatch)
" H1 M+ E0 |1 W8 N call Kernel32!ORD_001 ; VxdCall
% y5 A- W6 \* O: q" y' q cmp ax, 0f386h ; magic number returned by system debuggers. V; V: I! z) L8 o u4 R9 z1 d' e
jz SoftICE_detected% v5 @/ h" T" I& K( ?7 w. K" S) I
9 i0 p; ]$ U6 E Q
Here again, several ways to detect it:
3 N. t: h: i3 m4 w4 b+ _$ Q+ {% I( Q4 x6 X* U3 V; i
BPINT 41 if ax==4f. M! m6 z" \, h3 C
; x' j7 e3 u) `2 A) E BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one% @) q- ~ E* o& G9 G4 n
: q6 s; B' p6 S: k% n l' g7 e
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
* \9 G# R4 _+ S2 S3 F. E. V2 Q9 ?' p6 Q W5 B: d& |, V/ T! a8 {
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
# A# r5 H( @3 I+ Z1 @0 k/ n) h. S- b7 D- }
__________________________________________________________________________# q; u8 b u. L
. u" `" {6 M& t, {5 JMethod 13
. c, o9 j t- U1 ]- @: s0 J=========
! i, f. J. c4 P( C- h" Z
\# ^! ?1 e5 b0 E, l6 ?Not a real method of detection, but a good way to know if SoftICE is
$ h4 C) m# m0 m; \/ e: Tinstalled on a computer and to locate its installation directory.; L9 H5 I0 C" p# ~! R
It is used by few softs which access the following registry keys (usually #2) :4 M: u' g2 I+ i( x. q0 r. k6 U% @
( y, l p9 t. U! k0 z-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion3 Z/ n1 l" Q4 @* C j3 l
\Uninstall\SoftICE# t' {4 y; g7 }" ^1 ^# m
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
9 }( O4 {2 U6 p+ z% v E-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& C+ e3 z% u+ ^: N( v# M
\App Paths\Loader32.Exe
! o3 W" @8 f2 A9 C: i, ?8 M/ R: a- i( V
6 t5 d9 P% i2 p+ `# V; KNote that some nasty apps could then erase all files from SoftICE directory
' F% }9 l- q# J5 |( h1 X/ ?: P(I faced that once :-(
8 a1 U9 F* Z/ c4 | B' E/ p
$ Q3 R K# ?! x) |* T/ NUseful breakpoint to detect it:) y' q; p' l6 }: w" k1 e
, ~- u3 y& d' S* k- B BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
5 q$ Y! r" \* Z
, J2 j* E$ P2 g7 t: C7 Y9 m, r__________________________________________________________________________ @7 s0 @7 M- B& f+ Y' L
/ r6 @$ o9 t3 P( l* @1 [: P" h
1 D; u5 k; u9 l. Q2 M$ s" @' \
Method 14 $ A$ B3 E5 J$ ^' B
=========
8 m4 Q! T& F: z2 \! m6 U6 `9 n) D
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose+ m& X9 q! v3 y" D
is to determines whether a debugger is running on your system (ring0 only)./ U$ j, g6 t* s+ |
% K; O4 W2 S9 z5 N) d; k, A
VMMCall Test_Debug_Installed- I$ A2 T/ }" l1 \6 j' v. N
je not_installed
. [$ P5 b4 P* v+ u+ K
( D$ V- m" h D5 @This service just checks a flag.
0 z+ v% J! V! _3 U, [0 \/ a</PRE></TD></TR></TBODY></TABLE> |