<TABLE width=500>1 a9 e. E0 K) _: U$ r" G6 j( d. {% P
<TBODY>2 S. U. }; \7 S
<TR>4 ]2 b% e1 N4 n: a% v1 b
<TD><PRE>Method 01 ' a( W9 ~% e) i& }. L
=========9 B9 b. ^4 [2 V+ l) t
: _" e# q6 j* f- V" WThis method of detection of SoftICE (as well as the following one) is, X+ {* {+ u9 @! N: \
used by the majority of packers/encryptors found on Internet.3 m! B: T9 J& X8 \! r
It seeks the signature of BoundsChecker in SoftICE
Y; d. Q+ u& C* k5 f. Q! ?$ I% w* t n& @3 y' a$ V3 e8 K# y
mov ebp, 04243484Bh ; 'BCHK'6 s$ |2 F" c$ K2 f1 ?
mov ax, 04h$ e* a4 `* x+ T' \* V
int 3 ) c3 Y4 C+ \* | t1 t+ }
cmp al,4& p, J0 d6 w& K, D* T) I
jnz SoftICE_Detected/ K- b+ Z6 F* l
. l- d- o% l# ?$ y+ @___________________________________________________________________________
: F' F2 H$ B8 h, c8 }, H' I, G+ P y& Y& x6 ^
Method 020 M6 W. C6 `/ j9 c) F
=========
; U7 Z0 |1 u" P U6 |9 H% u# V8 U% |
7 v' k- W3 d% NStill a method very much used (perhaps the most frequent one). It is used
I* H" z0 c( f7 ?2 r- Wto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
, v# C! Y3 A& D# [0 ror execute SoftICE commands...
5 T" i; H/ ]6 ?* WIt is also used to crash SoftICE and to force it to execute any commands2 m; I+ m: k6 r
(HBOOT...) :-((
# m- M$ X G6 F. h$ `# M$ R" A* M$ l. e. W) z- N4 X
Here is a quick description:
1 n2 z" C0 H' ?$ e) W0 N9 q-AX = 0910h (Display string in SIce windows)1 {* h& C/ o9 L; ]8 q" f
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
- a, F! [4 l& y& o' x4 D3 w-AX = 0912h (Get breakpoint infos)! o" F: j7 f$ X1 ]8 U3 {" e
-AX = 0913h (Set Sice breakpoints)) V% {7 R+ o5 n5 T
-AX = 0914h (Remove SIce breakoints)
a' `% o: v: {- w" h m1 R8 b _. ]2 v }. N
Each time you'll meet this trick, you'll see:
3 T6 c7 k3 C B/ |+ v @-SI = 4647h+ t+ \. s: ]7 u3 G
-DI = 4A4Dh
& I2 ~. s5 h) ]5 WWhich are the 'magic values' used by SoftIce.- a6 {) D2 S: |4 M X2 i) g2 G
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
4 t4 h ^4 G) k; F
5 s. q' L* Z- i- QHere is one example from the file "Haspinst.exe" which is the dongle HASP
" y* {7 s0 q* t S Z& [* v( E1 }Envelope utility use to protect DOS applications:
0 i; o6 z, C0 p/ P) _% ^
8 F. I, a; Q- u# i. ?6 n* P+ @6 ~7 X% J- W$ m$ U& s
4C19:0095 MOV AX,0911 ; execute command.$ _! s* N4 f u5 F
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
$ E2 m3 O4 \! i$ [* h4 J9 ^( }# D4C19:009A MOV SI,4647 ; 1st magic value.
. F+ S5 p2 c" S4C19:009D MOV DI,4A4D ; 2nd magic value.
. x/ p3 c; b8 z4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)! {' t! i9 ?5 [5 ^1 E* _3 D
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute' B. l4 ?% g) y( l* f4 f, X- _
4C19:00A4 INC CX$ K6 r& l. U' p0 G$ o
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
5 }0 u: k+ y. ]1 c4C19:00A8 JB 0095 ; 6 different commands.6 D5 z! t* Y1 K* J7 E/ L
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
$ m* Y. F1 N7 ]8 ~+ y4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
1 l, V+ F; E& t; i
0 H- m5 D+ Q' V* m& XThe program will execute 6 different SIce commands located at ds:dx, which3 |' N5 n3 e* h% D
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
5 w% s5 F. F- @+ M8 b8 J9 U- w) r" h- N' U' [
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
) I4 Z3 y4 p o___________________________________________________________________________
' x4 l( g+ R/ {( \
$ s1 h' Q0 E8 _2 r* M# R
! ]9 i2 s. p3 T, S$ G8 e9 ?Method 03
- K* j% t3 I" ~2 F: P- ? ~=========
g1 ?$ q) g: v ?4 W
. H2 x9 O3 g& ?# e; rLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
/ z' W+ D) q: Q* d(API Get entry point)
: q: s- R4 Q* n* T( ~2 F$ ~ 5 C$ Y3 s! n- A! p- t. D
; H( S1 R% _9 t3 M0 |4 ^ xor di,di
6 r1 c+ F/ N2 o- _. G3 h6 x mov es,di
9 e/ E# f$ F" F8 z mov ax, 1684h
" {6 Q0 I; k' y" | mov bx, 0202h ; VxD ID of winice9 d) [7 h, f7 Q
int 2Fh, F* S8 \0 V( s+ I! s* M1 ?" m
mov ax, es ; ES:DI -> VxD API entry point# t! D- Z9 R7 k, h
add ax, di: E: j- U( E$ x& q7 a
test ax,ax
6 ?8 |+ f; P2 x8 @& x3 a5 U jnz SoftICE_Detected
* p+ O# P. c# s5 O8 E* x
$ z% I8 h& c$ s___________________________________________________________________________
$ u, I M/ Q/ ?3 G- U3 \2 }* s+ l7 K! Y- x3 d+ b# ]
Method 040 t: p4 ]5 E" a6 _' R# |
=========
~0 D. O- ]9 K8 Z# X# i6 Q/ Z1 s1 i3 a" {9 t
Method identical to the preceding one except that it seeks the ID of SoftICE, k+ t) U. p5 r4 w( H0 r9 c
GFX VxD.# U+ ^! ]/ w* e
g: \, ?6 p+ q6 [6 t7 F7 `/ b xor di,di
+ n" Q, ?; U4 h, q+ d) g; I mov es,di$ j L/ Q) c" V& n. ~7 Q J
mov ax, 1684h 8 b0 q9 I" A: U1 b& F
mov bx, 7a5Fh ; VxD ID of SIWVID
8 E1 g2 l. C; w5 o$ G int 2fh
# O5 Z& j/ q8 N! f6 W7 @& b mov ax, es ; ES:DI -> VxD API entry point
( ~: l+ o C8 @; k# i. I, Y add ax, di
$ _9 e. Y# b3 P# j0 X3 B test ax,ax& P/ ^$ V7 T9 R% A. R3 z6 U9 |
jnz SoftICE_Detected
. i( ^' @8 Y. Y! U8 L- m( @' ^
+ A* i6 y4 V9 E: N9 Y2 ___________________________________________________________________________* ?8 R+ H+ D* {' b
5 i( @4 V; N4 ` o; i D) R' Z+ d8 y. d" X, \- `
Method 05
0 N6 [8 l3 g" o+ U9 o! y1 R& V=========
8 T; G1 `* k- @- P
; x, `( Z: H; b2 LMethod seeking the 'magic number' 0F386h returned (in ax) by all system
! B3 x' M2 \& O p& \debugger. It calls the int 41h, function 4Fh.
" x# ^) I- S5 xThere are several alternatives.
* Y& y& ?( f/ {7 H5 Z0 I- W/ {" }( ^, o
The following one is the simplest:
3 b# Q5 s* `8 [9 a7 r3 a% X1 w2 z! D
9 ], A4 a8 _4 b. @ mov ax,4fh' e- w/ G: ]$ r+ h1 v& y9 k: u
int 41h! M8 W% y6 L$ b9 L. C/ ~
cmp ax, 0F386, o5 Y" X! k! g3 W+ I2 R
jz SoftICE_detected8 k8 D, j& U' P) T) M' t3 r' Y
& N+ {, q0 p0 v! J, y) Y% A4 P6 J
. G( \' j' O* X8 HNext method as well as the following one are 2 examples from Stone's 3 x0 U) I9 e0 h8 C+ H# x: f
"stn-wid.zip" (www.cracking.net):% p6 V+ Y+ ?, ]& ^( i* ^0 v
U! r" _& l# \6 ?" I) M/ s5 v; v mov bx, cs2 c J6 n6 U- j T3 r* a0 U( d3 O' S1 [& o
lea dx, int41handler2
2 {: o9 k/ c) Y8 f6 n$ @1 B3 \2 `8 Z xchg dx, es:[41h*4]% g0 V2 o, O" V
xchg bx, es:[41h*4+2]
% ~$ X2 K2 U X3 I mov ax,4fh
) s! U1 Y+ D" m+ y int 41h
4 o( E" s# f# H8 \( `9 U8 [ xchg dx, es:[41h*4]
. L [; _6 V3 i7 t xchg bx, es:[41h*4+2]( H; `* t. F( b* i% S
cmp ax, 0f386h: O+ H+ P( y( x0 h/ y
jz SoftICE_detected
# J7 e5 d# g5 d. T6 ~& R* l: n. `' I/ B$ D z! t1 n. X( M9 {
int41handler2 PROC0 U% W% b/ @0 v: s
iret
* E: S/ R6 ^6 U8 q3 Oint41handler2 ENDP
# A8 h" ?/ S7 S9 p, J# ^, f5 T+ y/ F
* i+ v! ^$ X# _% ?2 i_________________________________________________________________________
: n! C2 Z# Q) I8 J" ]3 N5 l, T l( x0 a4 A( l0 Y0 A a0 m- I
6 r7 n& A5 T3 U6 p+ o
Method 06
- z# m+ U$ G- p. z! N=========. A9 `" _. n' y$ I9 ~, D
7 M! C- ?, K! T# S$ q1 c
/ y4 N0 p- D/ U0 D$ e2nd method similar to the preceding one but more difficult to detect:
4 p r4 Q/ s+ k9 G$ {5 _4 b [, e
3 T" B/ x- G& |
int41handler PROC
3 M" T" k, s/ j( @ l8 Z" r mov cl,al
- V' F5 O, d' a' c7 G+ R/ z' T- }1 W. m iret
& Z( _" t2 h0 h8 Zint41handler ENDP. l A- O+ A: P7 c) T& |
* w# A& x/ Y! ]0 Y2 s
& z' b& X" z z. g& ~ xor ax,ax0 [2 ^* E y5 f
mov es,ax
0 f% B; E. E6 m( {: [ mov bx, cs" f1 [% N3 C9 T7 k. O+ [/ Y+ t
lea dx, int41handler3 L$ C l! S7 Q: W' o! Y3 z& g
xchg dx, es:[41h*4]6 H5 G7 j" F8 G3 j3 t
xchg bx, es:[41h*4+2]0 {; c8 ]/ A S9 M( X9 l- v8 m
in al, 40h
) S$ q8 P3 Y! |, ^7 o xor cx,cx
0 W" @1 t% r, _1 c- { int 41h- \6 X' _% _: {2 x
xchg dx, es:[41h*4]
$ ~5 Z# q5 U4 s! f xchg bx, es:[41h*4+2]& z8 Y3 d+ Z/ L$ r$ w
cmp cl,al. t9 C: K) ]& l- ^
jnz SoftICE_detected
$ U1 U) [, I7 U6 E/ \3 ]9 o4 h" E4 b( J) M; N" u! i
_________________________________________________________________________1 s* g. z; c0 u1 n3 A
' @- H# b& |3 V+ c1 t6 v$ a
Method 07$ c. Y: o$ |/ F) v' B! ~/ q
=========
y- @& C4 \9 s- C. o$ z" K9 A2 i
0 k: {, N j+ j* ]( O8 j& MMethod of detection of the WinICE handler in the int68h (V86)
8 Z* _( n5 _& U2 q
% o/ o3 m! @1 g& e$ x: B' \ mov ah,43h
- V. n X6 y+ |" t# A int 68h S( c) x9 s' e, O9 V
cmp ax,0F386h4 S7 T( C; z$ \& Q) R; I) C
jz SoftICE_Detected
" e7 V/ c* \% e9 w' _$ D
' _& ?3 F: E1 r% s9 o" q* Y# d0 a% J) p* ^, ~% \! J
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
3 J. X/ m. c/ J- Y0 D8 V app like this:
U% D! y$ B7 V& _* K( _3 O) O0 o8 @0 S3 @6 l! ^, @. S- B$ p
BPX exec_int if ax==68
8 a v* H! C, b) C0 Z: n (function called is located at byte ptr [ebp+1Dh] and client eip is z$ C7 G' U# @+ M( |6 R K
located at [ebp+48h] for 32Bit apps)% f. h2 w$ N$ J- x! ?% }' x4 J
__________________________________________________________________________9 ?& d4 b8 m9 M/ L8 G
7 @" C$ e" |/ Y1 J: i
# M5 Y8 V) ]4 h, H1 aMethod 08% y/ r# t" |7 j" g) D# t A2 _
=========. U- {. Z2 n+ B# p8 }. W! o
, M" r: q& ]. @9 h
It is not a method of detection of SoftICE but a possibility to crash the9 N, h/ |. ?0 r- j& ]6 q
system by intercepting int 01h and int 03h and redirecting them to another
; I- L, \# |! i2 O# x8 N8 f* Nroutine.
1 F' B# _, ?7 o- s1 u5 c- yIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points; {# Q5 B+ ]! ]( c* ?- I
to the new routine to execute (hangs computer...)6 r5 v, }) N; Y
$ |) G& Y4 J* }# H# J+ h% w9 D mov ah, 25h# \. w/ _& k# k$ h, Z5 h% Y
mov al, Int_Number (01h or 03h)
; r2 o c5 D" g1 f mov dx, offset New_Int_Routine' j$ Z: d7 k' l) l( b
int 21h# N! D2 | T6 q# h
7 I0 t* l. [) M7 J e3 Z
__________________________________________________________________________
5 f8 O, W. o8 @$ W' I) O
+ i& h _9 w( n5 |- FMethod 099 [& X3 F( N! m+ p( ~& w
=========
) q% z; p: Y) y3 c" u) j5 f" @7 C0 ]: C0 _" {* Y' m X1 q
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
0 H; s" m: x7 Lperformed in ring0 (VxD or a ring3 app using the VxdCall)." i* R. e, o/ L/ A0 S4 x0 v7 S, ]" q
The Get_DDB service is used to determine whether or not a VxD is installed
% G9 L, @5 w) E# w5 J+ |for the specified device and returns a Device Description Block (in ecx) for
4 i9 V$ } L# T9 w4 @ jthat device if it is installed.0 y) M' r2 i5 y/ R" ^. q3 C9 d
' s, x' Q' q. Z5 R
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID" X. q3 C$ T' D( o( P
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
: r* N2 ]0 i4 {4 T/ E7 F* T VMMCall Get_DDB; G5 @ j0 K# u2 O( ?0 B
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed& \, i7 W. J6 i
5 O& F8 L) `5 ^' xNote as well that you can easily detect this method with SoftICE:
3 W6 F2 u/ q' Z. x& s bpx Get_DDB if ax==0202 || ax==7a5fh6 b/ @; q r2 R d) M9 o' j
' s4 T5 `+ q# h5 B( S
__________________________________________________________________________4 p$ G o9 I- j7 s
5 g% _: x2 \5 T6 e0 \Method 10
9 a' I- i" w- m9 r8 a=========
4 s3 P# f# i' H9 |/ }
b5 x0 [9 y- l/ b: t K) S=>Disable or clear breakpoints before using this feature. DO NOT trace with' M) D# T7 X& d
SoftICE while the option is enable!!+ [. q2 G& T8 v' L
* l4 U( J K8 T: j0 {
This trick is very efficient:
; V4 u. } e' K" J; E' G4 M3 C6 nby checking the Debug Registers, you can detect if SoftICE is loaded2 i H/ z7 ^: h3 n( F
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if+ ~8 \1 T( z4 i" l9 z
there are some memory breakpoints set (dr0 to dr3) simply by reading their
4 ^# a5 O$ X$ b! mvalue (in ring0 only). Values can be manipulated and or changed as well% q, ]9 U: k0 H c! e* B
(clearing BPMs for instance)
* u) G; V/ z2 c5 S' C
( h4 E$ l, e9 L' v__________________________________________________________________________
6 c* R+ r4 U9 o& {7 i- D% E/ [$ C4 h1 S8 Z1 |# V- V; \8 ^ \
Method 11
4 C' W$ E9 f4 |! S=========3 J- ?0 U) L/ |+ i1 c
. N& I8 j2 x) j m9 s
This method is most known as 'MeltICE' because it has been freely distributed8 x+ _! y, o5 f" X) A( c! P
via www.winfiles.com. However it was first used by NuMega people to allow
, D0 d( k2 X4 \' L* n4 \; OSymbol Loader to check if SoftICE was active or not (the code is located; | C$ K: [, O# [# \) h+ w
inside nmtrans.dll).0 h% q4 g1 o9 J8 I* y" x2 R
; k/ H) b* v) {" P9 W* g
The way it works is very simple:& c0 t1 |0 Q# H: `; C1 o; ^
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for$ K: }; s( p9 D Y% h
WinNT) with the CreateFileA API.3 _3 B6 Y' q) M& }2 v! k# ]+ R
, S- t' A0 _, o8 n
Here is a sample (checking for 'SICE'):5 w" Q& e* @2 e" Q+ F; `! s
* S6 q& i n5 T
BOOL IsSoftIce95Loaded()
: [1 L$ L! n8 p1 l6 e) _: i{
5 @2 K" Z0 a5 v HANDLE hFile; ! Z) c* h; q. d2 f+ v+ s& p
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,- ?5 z% P& g: ~
FILE_SHARE_READ | FILE_SHARE_WRITE,
+ _) ^* Z/ k8 [. J NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);; Q( k' a- ^+ F. {( _; X. k
if( hFile != INVALID_HANDLE_VALUE )4 A0 }* l- ]7 k( R2 s. I, v8 V! G
{) N( m: R, k& O3 |) ?2 f% P. \* C7 Z4 ?, m
CloseHandle(hFile);3 a8 Y5 Q8 E7 m" a* F
return TRUE;
. ~) a# |* l6 g+ ] }. [& I4 e3 D6 B: O
return FALSE;
8 b+ }) m0 R% Y) v* ^2 W}
4 D$ D/ J( N. @: w+ t7 C) ?8 h7 V" e8 y4 z: z% H. T7 b5 \
Although this trick calls the CreateFileA function, don't even expect to be
; L+ J2 g8 i3 I$ d) n: Eable to intercept it by installing a IFS hook: it will not work, no way!8 z; q/ W0 x$ h0 ~8 l
In fact, after the call to CreateFileA it will get through VWIN32 0x001F4 E( E" p0 {; ^
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function). j; [6 F! G. R& `5 b. I
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
$ s# g U- a# k7 _/ B3 X( @field.
S: F$ q# k# K6 A: fIn fact, its purpose is not to load/unload VxDs but only to send a ' ?+ D$ V- m( s4 T2 X: y
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE) L: Z9 s1 }6 n! M
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
/ Z7 g) H+ G" \$ M0 Xto load/unload a non-dynamically loadable driver such as SoftICE ;-)." z1 _9 `3 i7 O1 n
If the VxD is loaded, it will always clear eax and the Carry flag to allow( N( m9 K1 l$ Q/ u/ m
its handle to be opened and then, will be detected.
' ]4 W) u: O( I6 FYou can check that simply by hooking Winice.exe control proc entry point
& {2 x) |. S; @8 s* ~* j8 I# {while running MeltICE.' ^9 Z+ U, h5 {5 l6 r% X9 a
9 r g; Z. L @$ K7 J" `+ e- X) q( e9 |
. M0 l0 Q# _+ m" m6 p
00401067: push 00402025 ; \\.\SICE' M2 s9 h5 b5 z$ }* v
0040106C: call CreateFileA; c0 Z4 q8 V1 E0 } {
00401071: cmp eax,-0017 x* f, J% }! X& ^# r: m9 A
00401074: je 00401091
. c% v7 q# x; W) l* i4 q8 {
. }$ }$ z5 t- r' A6 Q% Y- @
3 s0 r" V& \3 [$ U2 w( jThere could be hundreds of BPX you could use to detect this trick.
7 D* P* Q! |- C- s w$ Q5 V# T& |-The most classical one is:
) Q2 I: T6 u$ [8 M6 u BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
! U1 o+ O7 L* _; Y! Z6 [0 [ *(esp->4+4)=='NTIC'9 w# T: H; S3 y8 g
% u) \# _7 ^* b3 |-The most exotic ones (could be very slooooow :-(2 D' l6 i9 h- S: V# i; f
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') & T, k. X& l/ t# B0 }
;will break 3 times :-(' J* y3 Z) v3 Z2 @9 U" Z3 `5 m
' f/ Y' t3 G) N- f
-or (a bit) faster:
- y% L- k, v6 e BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
' I0 E, x; t) j
2 A8 g' T# b6 ]# x/ {8 q2 C BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
3 O1 L% H4 b* j ;will break 3 times :-(
7 W# P" Y( p9 ~; d3 F$ ]; R- A
* Y7 d, o. K/ x* y-Much faster:1 [7 U+ T2 x- i% N: \ D9 \
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
; {7 x* U$ X. H7 a' q
+ G3 \& _) x1 k' ~$ j; mNote also that some programs (like AZPR3.00) use de old 16-bit _lopen! n0 M: @3 h4 D" V& K0 X4 J
function to do the same job:# t" T7 A/ J9 Q- {
/ k1 X5 F% `2 n$ o D
push 00 ; OF_READ' N" P7 q' B1 L( [
mov eax,[00656634] ; '\\.\SICE',0$ v# p/ B! I& k( h9 o
push eax& N/ D& O# Q7 w2 C
call KERNEL32!_lopen
! t& V! e3 g% v% l( ~5 ?6 }. ] inc eax. \" ], p% [3 ^6 E+ q
jnz 00650589 ; detected
( V4 f. p8 b) a$ S# e push 00 ; OF_READ. G0 ]! f; D+ M! A4 Z
mov eax,[00656638] ; '\\.\SICE'# X. @' n+ j' ~% o0 j A
push eax( Z" X# i4 \# E. p
call KERNEL32!_lopen7 {2 _4 Z5 j. V0 G k
inc eax+ \/ O# n; @5 X' I; s* G& h- x& t+ w
jz 006505ae ; not detected3 X* S8 u3 S Y9 ~
- S/ r; G0 o% d. s. E
; b& c9 ]0 w# ^( M__________________________________________________________________________& P+ d5 n- D. j. Z. e, y+ L
/ e/ R5 |4 f( j' [0 j
Method 12
( K& o# \' I; F# R# d* U, P7 V6 l=========
6 L* I$ B+ P0 j6 b
$ ?' t, U8 I* D4 XThis trick is similar to int41h/4fh Debugger installation check (code 050 k0 y+ Y& G# B: }1 q$ w
& 06) but very limited because it's only available for Win95/98 (not NT)8 o, u5 M% |7 j" f5 S6 J. l) I
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
8 j6 h# T" m) k+ B9 ~, f% {5 ^! E9 |8 ]( V6 m) A
push 0000004fh ; function 4fh0 V) ^/ k6 S8 w- H) Z' j
push 002a002ah ; high word specifies which VxD (VWIN32)' S& Y. S. \+ r9 ^4 ]
; low word specifies which service
/ K3 i: O7 | k# {& i. B2 R (VWIN32_Int41Dispatch)
; j' @0 I C7 q' Y6 n call Kernel32!ORD_001 ; VxdCall
0 e% H9 t8 N2 v1 y0 [ cmp ax, 0f386h ; magic number returned by system debuggers
% }9 Y1 Q1 Y& y1 t2 S- y jz SoftICE_detected% Y6 Y5 |9 }# x- Q6 S3 r
6 ?; \' z/ S0 f& AHere again, several ways to detect it:
0 c$ p* Q/ S/ t. H6 ?& a, |! j2 a8 N* J& L: ^5 b7 V& B
BPINT 41 if ax==4f* B i) a/ t+ o7 F1 g* M
' N# C0 u3 `6 N) |, d BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one7 k. \: o3 T% `& B( a8 j& ~2 ]6 D/ P1 a
$ }+ a7 i6 ?+ u6 `) X+ Z& [
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A2 ?% v1 Q! j0 J8 s* p8 v2 i
& w A: w' r' ~7 {
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!0 s1 l o5 c4 G$ E2 L
9 W! H8 H! i& ^$ {, D! q& N0 {% t O
__________________________________________________________________________
0 v) T, V5 {+ }- i
- b3 b0 U' C7 Q; i2 wMethod 13
% W5 V. d: U, u# V=========1 a F: Y# P8 c4 u! _
: V! ~ L% \) T! U% O1 WNot a real method of detection, but a good way to know if SoftICE is
1 f6 }+ Q5 c- Uinstalled on a computer and to locate its installation directory.: m3 ^0 N; F1 T
It is used by few softs which access the following registry keys (usually #2) :3 a& @1 l& ]* e: ?
+ O+ f0 ^7 |5 @" c- s# @-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
* L9 t- x& w' Y8 B) _\Uninstall\SoftICE, v# q+ [& m7 r+ J
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE5 e0 t$ B/ J) Y8 V( O) _
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 R' C& j8 D7 j0 R: L9 W
\App Paths\Loader32.Exe- \7 n4 P& L9 V0 B; X7 J8 C6 M
6 `$ J! Z9 |8 t2 j4 p
/ E- S. q* D4 M! t- u) E+ D+ Q8 i( ENote that some nasty apps could then erase all files from SoftICE directory8 ` T# \, F8 j0 j$ K* \
(I faced that once :-(
. Y6 e7 ^( D& I# Y
! }+ `5 B! B8 L6 i% QUseful breakpoint to detect it:, x7 _7 A1 J# k* ~+ H
5 E1 s, ^/ o. b. A+ K: C
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
* b) j1 X$ X& v5 k4 ^) {( @3 S& S3 \2 T1 b J' d" `
__________________________________________________________________________4 I4 \0 w/ z+ g* B# [; q% C
% Q1 T5 u$ d8 N) {/ Q; l* g# q6 i7 C% z5 I; B2 S5 B& z$ J
Method 14
( q; _' m8 J9 J$ E0 x=========1 q* U0 u3 w; t5 e% }9 T
# B8 C* M* m3 c& [& h& N, `
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
5 R2 d6 f* }% f# wis to determines whether a debugger is running on your system (ring0 only).3 _# Q' A, h& D- B& x. W5 H
9 y5 q+ [" E" S" C" ?
VMMCall Test_Debug_Installed% s6 l5 g- l4 x m' m
je not_installed
. Z6 J, H6 D' C2 E
! k2 F* |( @ o6 Y. qThis service just checks a flag.5 e3 A% {: V4 f, C. f. v
</PRE></TD></TR></TBODY></TABLE> |