<TABLE width=500>. D* _. `" C) |0 ~9 K# e- ^! M. T- a
<TBODY>
3 K! c3 k: d; n% h7 k<TR>
+ @, |2 B8 L" r. n<TD><PRE>Method 01 & h5 Y. Z5 Y' c
=========
C( Q! k2 w% E& ?% P# t0 O9 E9 q1 f+ e& ]- Z/ D$ d/ j
This method of detection of SoftICE (as well as the following one) is
! a7 v5 v& x8 G, O- D5 gused by the majority of packers/encryptors found on Internet.
/ }1 ^9 _) _, l3 M, c+ C0 DIt seeks the signature of BoundsChecker in SoftICE
" R. u5 H4 Y+ c5 s) E m* J# g V5 S' i& |
mov ebp, 04243484Bh ; 'BCHK'1 m; i5 I% [+ j; i
mov ax, 04h
" f: n4 d9 a% ] int 3
4 J# t7 H$ y# ^* J& ? cmp al,4
2 j' M. F# F- B* { jnz SoftICE_Detected
0 a3 A6 N8 P! k L1 t% f
$ q H. _! o. C% {( x( o1 i___________________________________________________________________________ ?* a) ]& z8 W) D; T) q3 r- S
5 D b5 F& C& ^
Method 02- p- `5 t% O% C0 e1 |3 Q% x
=========$ B7 l; H; y* X6 T) x: x
3 L1 r, u6 }0 a) {* C
Still a method very much used (perhaps the most frequent one). It is used; q8 e( p; v/ a( I3 A
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,+ ~# ?3 H, L: @# b2 {3 A% J
or execute SoftICE commands...
) p! x1 Z& i& e9 E# _4 s! KIt is also used to crash SoftICE and to force it to execute any commands. l# x: D1 h) k# Z- c% b1 [7 `0 R% d
(HBOOT...) :-(( 4 J$ ~8 ], B& P7 U
8 g) {! h" [! } @4 @. ~0 Y+ z. Y
Here is a quick description:
4 K7 G4 u! r+ j# W/ d% O) Z$ Z-AX = 0910h (Display string in SIce windows)6 f2 f' h' q# ?. B! s. O
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
2 b0 ~1 f) X; X) F-AX = 0912h (Get breakpoint infos)
( ]0 i4 T1 R* n- V4 J, Y+ J-AX = 0913h (Set Sice breakpoints)
+ d$ b( V' E6 F-AX = 0914h (Remove SIce breakoints)
& Q; V9 T* n0 s% q- i) L- D+ ~& Z7 ~1 @4 [
Each time you'll meet this trick, you'll see:( g/ T4 W+ X3 R z) [$ b/ }
-SI = 4647h
' C/ g2 @2 E& j7 J4 q) ]-DI = 4A4Dh
! Y1 h9 w E( P$ F9 K: B3 bWhich are the 'magic values' used by SoftIce.3 s$ O" c* [/ {# q8 E# A9 |" |
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
( T& k) k/ u0 F r/ N4 [6 V
- u% @, l0 ~1 F7 N7 RHere is one example from the file "Haspinst.exe" which is the dongle HASP6 \6 u' O# r8 |+ H
Envelope utility use to protect DOS applications:
- S! U }8 f9 F% Z- D4 l* R+ p, g" s [# l9 Q3 J( J& t
* M2 F; [5 R6 i& {+ X- h4 p
4C19:0095 MOV AX,0911 ; execute command.
# B) _# _2 ~: j7 d/ r8 v4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).* u; @- ~1 _$ W( n) D$ C) W! ?5 D
4C19:009A MOV SI,4647 ; 1st magic value. d7 a8 h% J2 f" q* l' E) Z
4C19:009D MOV DI,4A4D ; 2nd magic value.) b! c* f/ U5 h$ K
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
' l. v% [$ m8 Y* i- t4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
* [2 e' g" M8 c- B0 A ]4C19:00A4 INC CX
: x6 n. ~) C/ N- e/ } F) D4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
; E+ n+ e% ]5 S G! E4C19:00A8 JB 0095 ; 6 different commands.% G ~% q6 Y! J/ T' _) ^
4C19:00AA JMP 0002 ; Bad_Guy jmp back.. F* l, l. J' `; t/ x6 l$ `+ v
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
1 h3 t0 e- d4 J' c s5 {, v
" C6 E% R* h+ G0 aThe program will execute 6 different SIce commands located at ds:dx, which( {0 s/ W9 W: M/ _7 O: f$ l7 M" c
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.' L, Y" I( \3 P
# v" [! Z% X8 c* U3 n2 l+ Y# J7 U
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
8 K. x+ [' d5 s___________________________________________________________________________
# q+ n; p* E4 R) f$ l
. L4 S! o3 T- s+ u3 }$ _
/ R5 \* v" I% C. _! b- XMethod 03
. _ ~1 U& B+ e3 w) o2 S2 C=========
1 P! i& L% v1 P! W5 h
& A" J6 N9 E4 a! N' OLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
' H; ~9 T5 k( v# x0 b: X0 A(API Get entry point)
4 U# M9 M% b- H' }* n0 k% s$ r * \# r; o5 k* b. x2 X6 E2 y5 ?1 @. J
7 b; {+ v" D) U, _2 n
xor di,di
, o# m% \: e- B2 } b mov es,di
; O+ G7 l/ u6 Z$ k0 l mov ax, 1684h # r9 X# O$ u8 h% Q4 X3 P+ A
mov bx, 0202h ; VxD ID of winice; I" {, l% O) q6 U0 ]4 X
int 2Fh* X' m1 k3 _8 _, q
mov ax, es ; ES:DI -> VxD API entry point7 j4 ~ G5 M$ Q% \
add ax, di
2 M: \9 u$ Q, ~ test ax,ax
5 E6 [9 u/ ]9 l5 b! U jnz SoftICE_Detected
+ m8 O9 V1 u' z/ I, d: m4 z- b% j9 y' l# A! v: g* P+ D
___________________________________________________________________________; j. C% S% Q$ y) {) x0 u
3 }2 C! |" B7 b+ P$ sMethod 04
* u+ p- E# Z( q, w) z8 j Q=========. X1 E& X/ v3 t; n2 o
8 \/ `0 g. N3 Q+ J
Method identical to the preceding one except that it seeks the ID of SoftICE
9 o g7 u4 v) u& Y L$ P0 _9 nGFX VxD.
, U0 o2 T% \4 M5 C* J- W) ~3 ?( k
xor di,di6 m3 u1 ?1 s5 q) H2 G6 G) i
mov es,di
9 F2 P/ x$ m2 P. B- N1 P# B mov ax, 1684h
( j/ H4 M' k! o6 m% e0 l# k mov bx, 7a5Fh ; VxD ID of SIWVID
0 D; \( l) K. z" s$ p3 D/ c0 z int 2fh* ^' ^* _2 g. a* h: \
mov ax, es ; ES:DI -> VxD API entry point0 t5 p1 M4 c$ e* }+ J
add ax, di, `4 E. w$ u4 O! d% X
test ax,ax- N' Z9 l/ W% U* M6 t8 r6 v. j0 s% h
jnz SoftICE_Detected
% H- D) v9 ^) P# N% L
7 Y/ ^' a, f7 R* h9 ~7 D__________________________________________________________________________" e7 |* N" ^0 K8 _1 c) a
! X$ ^) w" g0 M
6 P0 t, ~3 j3 u* Q5 G2 wMethod 055 n' S; Y- h( ^8 n* W2 q+ S
=========
: C9 x7 l! `# o; d
. l; ^, I# n' x! rMethod seeking the 'magic number' 0F386h returned (in ax) by all system- G" X# I7 q8 o3 R L. R
debugger. It calls the int 41h, function 4Fh.- s! B5 z+ @( g3 `# D
There are several alternatives. # m8 _6 M; `* E
) ]; W- p5 ~5 L$ T$ `The following one is the simplest:/ v3 q& `0 i/ s! y. H" `' j6 T
; `! x B j4 l: z- U/ g8 w. `6 ^# v
mov ax,4fh
; u( R$ ?+ d. I, f v) m: T8 P2 c& B int 41h: ?" j6 c2 J( v
cmp ax, 0F386
% @4 o0 x# H9 @% P9 I/ B2 h jz SoftICE_detected
/ b6 k M4 a1 D5 d$ d& U, t) Q! B5 m
* p {$ P" w) G- l, o. eNext method as well as the following one are 2 examples from Stone's
7 g+ V6 M% j: c5 V0 k2 Y"stn-wid.zip" (www.cracking.net):9 b# A8 P: O2 y; ~
7 T/ l. Y4 q2 B0 j" | mov bx, cs
6 |/ O. a! [- b lea dx, int41handler22 Z- u* [) ^4 Y8 a' a: Z7 p$ V& K% F
xchg dx, es:[41h*4]
. j" l1 l) {5 Q8 t1 S xchg bx, es:[41h*4+2]* C' Z9 ~ [( O- _
mov ax,4fh+ c: Y/ v7 R& u
int 41h
% p) S2 m* Z: t& ?( l xchg dx, es:[41h*4]# O- M7 z2 k- i) K/ Q# i
xchg bx, es:[41h*4+2]! u. E' @3 ?( }9 D, m
cmp ax, 0f386h
3 p- N" y* H8 c8 }! z/ | jz SoftICE_detected$ t3 `8 V- L4 d# B
. y, q0 B, `& ?8 ]! T$ @! M
int41handler2 PROC
6 U9 F- ]( w0 B7 e0 _7 v) @ iret
5 C( S) z" D' `4 ^int41handler2 ENDP( h4 i, @+ W, t# R5 y8 _, s! P
4 w Q4 `+ E7 E% i
0 S. f8 m1 a1 V. ^+ o6 [6 j_________________________________________________________________________
i, `" n4 _$ Z4 U% P$ D( U% @% D& Q4 H, O* u+ ?
% t" O2 _8 `7 K& s) u; WMethod 06* y8 n5 R u$ X5 i { _, Y
=========0 i6 V5 {- h0 s5 Q1 }# ]
7 S) i! A7 W; Y$ ` \
+ \- {; ^. L2 r3 t
2nd method similar to the preceding one but more difficult to detect:) q: ]. `' G" x: F1 K, G! ~/ H
- v. q' u* F6 y; W) z+ L0 b* d) V
$ a7 ~5 v. X" W3 Yint41handler PROC [* [, W5 f3 I8 Y
mov cl,al4 {1 b% V( O( n$ P8 F, N4 K
iret% g4 [' k5 h/ F% G
int41handler ENDP
8 [3 B: s8 x# x. V9 R$ s
]1 i4 j+ O) y, y" i) k. S: p
! r8 Y- c6 v) S/ w( h: `9 B xor ax,ax
! g& Q8 O' D3 R% U3 A mov es,ax
/ h/ {+ ^( n2 A% W" U9 z mov bx, cs6 I: D$ u9 N' J# ~1 {2 P8 y# D
lea dx, int41handler
7 n+ `( _) a- D; E# L! R; O xchg dx, es:[41h*4]
7 y6 t( M. f" \ xchg bx, es:[41h*4+2]& \, }# Q) r5 n7 D* R+ r
in al, 40h' @3 ?! u) x( ]0 d9 f' M3 M$ d, I& q
xor cx,cx
- Z/ _1 T& E* M9 u! H0 ? int 41h9 T8 L' | E- z
xchg dx, es:[41h*4]$ N9 X9 }' p, k/ o& t7 B
xchg bx, es:[41h*4+2]! U4 Q" o, m/ U0 G! `
cmp cl,al1 \4 d7 t- H6 k5 f8 T/ v. Z$ E
jnz SoftICE_detected
# d% T& q7 c' p: D) S" n* W- t1 k1 [* U
_________________________________________________________________________( O5 r2 c3 c5 @6 n
( M" U! F) m' D7 {& i# r! f
Method 07
% L! B2 f6 B3 Y6 C+ C=========
q* X) k9 x9 C5 o9 t$ n% h0 c% h+ b/ F
6 @8 I0 U9 R9 h9 ^, tMethod of detection of the WinICE handler in the int68h (V86)
4 J; X4 j5 ?- F4 x" ?* V
- H! r4 K$ L% q# N+ r% v mov ah,43h) P, c1 p. L" `; i4 A
int 68h
6 q) @# |! v" M1 p9 {* _ cmp ax,0F386h
& z( w) d4 b+ b. }$ X jz SoftICE_Detected0 F2 {/ n+ m1 n& _$ \
0 p: P: |& d. \: Q a" V6 v
8 o. V; g0 h2 L' w, W# m7 w& t=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit+ O" q3 h' Z9 @0 Z, Y
app like this:1 E7 ]) D" E+ [/ l
! Z- ^ b" i, z% P: R I3 Y% J; ?" _ BPX exec_int if ax==68
: u* w$ O: q3 _+ @4 B1 E3 _ (function called is located at byte ptr [ebp+1Dh] and client eip is7 r" |' q" H* v5 C
located at [ebp+48h] for 32Bit apps)
4 e! T' F0 F9 i0 N* I* }__________________________________________________________________________, g9 U, C$ q& @3 t4 }3 i2 d
* Z5 P; v% k0 t9 C2 |
) i& w0 @0 d2 T, m% N, U D4 ZMethod 08$ H, I( t; f/ P
=========
& S6 _' u, V7 v2 D
4 u3 G+ V' p. NIt is not a method of detection of SoftICE but a possibility to crash the1 g! n8 X7 k' b7 B2 Y+ O9 R
system by intercepting int 01h and int 03h and redirecting them to another3 S: P! ]: `( ^4 x: W& _
routine.
; H! Q! y d* D; ?It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points. k0 `; w# W& I( R2 Q/ P
to the new routine to execute (hangs computer...)6 R e. E& |7 |
w- c% V: ^5 t" R9 v
mov ah, 25h
6 Q2 @) v& y" d8 Z9 F1 c mov al, Int_Number (01h or 03h)
) b; z' M& C* A; k( ? mov dx, offset New_Int_Routine: ~ y& g2 F2 ` B
int 21h+ ~ E5 W' B. U6 s$ t
, n3 \, t2 T7 f+ t; z. Q5 I__________________________________________________________________________
6 e9 J/ o& f) G$ Y6 {7 x" j7 i% i% ^% g3 g% B1 N& q4 ?# O) a7 t0 g
Method 09/ {" H) \9 p7 n$ b/ m* }! S+ W& q
=========& q! b1 p6 q2 u" L& q
3 p( h1 G# a7 q) TThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
8 Q6 b! \# p9 j' B nperformed in ring0 (VxD or a ring3 app using the VxdCall). i1 d5 [. t* N* A6 _4 S; `
The Get_DDB service is used to determine whether or not a VxD is installed( I/ S) T4 L" y+ o, U
for the specified device and returns a Device Description Block (in ecx) for
; F4 S: ~' r( K/ Pthat device if it is installed.
, Q& i2 h/ _8 V* `7 H
$ V1 w5 G! c2 s0 \3 u mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
1 S9 p+ Q% q1 O: K6 p mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
# {, ?. k+ f, { VMMCall Get_DDB
* G {8 ~: p) Q, v0 W mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed* S, x/ f6 Q2 p. E5 ^5 D* K
* b8 j5 J. }5 ^/ ~) ? H4 QNote as well that you can easily detect this method with SoftICE:
7 x" Z1 L6 C/ ^( }2 @3 H bpx Get_DDB if ax==0202 || ax==7a5fh9 i" s* k e3 o8 o( J
- B' Z. Q& w( K__________________________________________________________________________
% \) h% s7 p& y( U& T$ N, y( E, T" f" }) \* D( l
Method 10
! c5 ~$ Z. A( ~9 x=========
1 K/ c2 @; C) M8 z4 @, i' q& s/ q% _
=>Disable or clear breakpoints before using this feature. DO NOT trace with+ c+ K" f2 @, y
SoftICE while the option is enable!!( k ^5 r! U9 ]# g7 x" U5 }
! i) |, I& I7 f/ i
This trick is very efficient:4 [3 k6 r4 p! O! `# A
by checking the Debug Registers, you can detect if SoftICE is loaded
! O, d; r) N- x B; \ i(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
6 z! T* r; a7 |2 i4 B, Ethere are some memory breakpoints set (dr0 to dr3) simply by reading their( z' z# B; C" I% L! @' }7 n7 k
value (in ring0 only). Values can be manipulated and or changed as well6 w3 U' L6 V+ h) G
(clearing BPMs for instance)6 [# }' H- ]- K3 b+ M
& n: @' B& I3 a# |! Y__________________________________________________________________________
. [2 y* J8 H& O5 E% p+ r7 z; q+ \+ }% a3 P7 ~" i
Method 113 U. x$ d0 a1 w5 k- a! d
=========% v6 ~. x6 k3 J: z: T) `
8 ]0 K" T+ v {
This method is most known as 'MeltICE' because it has been freely distributed( K7 O- S) Z. }+ e
via www.winfiles.com. However it was first used by NuMega people to allow
: H( [7 T% M+ F/ b1 mSymbol Loader to check if SoftICE was active or not (the code is located9 c9 H& V. J) B+ R0 K- E7 `7 B* v
inside nmtrans.dll).
}) b+ q& h$ j) h/ a5 `1 H. S% E! \6 [
The way it works is very simple:# s/ ^7 z0 w9 Q( d* @. y
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for# f" Z' @& Q5 E
WinNT) with the CreateFileA API.
) z/ @$ {- z: p* v8 O. t; X1 S6 a* D! Z. y
Here is a sample (checking for 'SICE'):& i @. u3 q8 }8 M% N( y
E/ F/ v5 t' ~* t; w
BOOL IsSoftIce95Loaded()7 C, M* [7 ] v1 w
{5 C8 [2 f6 c9 T7 r3 q
HANDLE hFile; : h- P0 h& ?( q
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,+ R9 ~2 I0 k# T+ ~$ u0 z
FILE_SHARE_READ | FILE_SHARE_WRITE,
7 \+ a! M2 ~5 T3 Z3 V6 G: u NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);1 g2 ?, {& Z3 v1 w/ a! O7 c
if( hFile != INVALID_HANDLE_VALUE )
! d. H- X* B' X( `0 e8 s/ V3 s {
! e7 T# j9 N1 e$ D* ?6 o CloseHandle(hFile);% @5 C+ j1 U, |' ]0 `1 _
return TRUE;$ c, w; e; t$ {+ J+ H
}
$ F r5 s' u0 |5 } return FALSE;. ~3 n4 b) R" v3 O
}
9 M, h- Q( d' N s/ S9 z
1 ]; i. }! d( I& TAlthough this trick calls the CreateFileA function, don't even expect to be
) P# [" a4 F, u+ n2 y/ t0 N- ?able to intercept it by installing a IFS hook: it will not work, no way!; Q. T8 z2 Q* G9 ?0 f8 d
In fact, after the call to CreateFileA it will get through VWIN32 0x001F$ x3 n4 l; A }( o+ @8 S
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
: |: ]! _7 Q$ C( X! C: Y6 f! {, oand then browse the DDB list until it find the VxD and its DDB_Control_Proc
; M1 R1 D; P7 r' Wfield.
( @8 G& z3 d' a9 Z! a) b1 \4 MIn fact, its purpose is not to load/unload VxDs but only to send a & z& Z; E0 g4 f
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)! y7 j& q9 x) ~! x# t/ a
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
4 G* l% m1 [6 t# W2 S* zto load/unload a non-dynamically loadable driver such as SoftICE ;-).! \5 i. u+ K$ j! a z1 j; C
If the VxD is loaded, it will always clear eax and the Carry flag to allow. B0 u' w5 g* F$ h+ B
its handle to be opened and then, will be detected.
% N/ i7 j$ A* x" i: ]You can check that simply by hooking Winice.exe control proc entry point
' I& }1 d9 X7 l4 lwhile running MeltICE.1 t0 V$ R: ]1 x0 ~5 L$ [, Z1 @
( Q, ~- h1 k/ L, r( ^/ P' y) k/ h- M+ T0 k$ A8 l
00401067: push 00402025 ; \\.\SICE
- U% Z2 B; Z0 g7 J4 \ 0040106C: call CreateFileA8 g- g, L( M4 m# F4 Q+ E
00401071: cmp eax,-001
0 L1 d; Q& E7 y- C$ U6 B 00401074: je 00401091( A' C3 D4 k' F& T' P5 ]8 T
G/ B$ {) O7 g# H
+ ^4 y2 E% a( ^
There could be hundreds of BPX you could use to detect this trick.
+ \9 T' a/ t* C1 |0 f, N2 s-The most classical one is:
: Z+ a1 C6 {9 o: O$ C6 E BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
8 O1 x& C% T( U r6 H *(esp->4+4)=='NTIC'
( v2 ~8 W6 n& t! q- i
: e8 W, Z1 j2 t$ d-The most exotic ones (could be very slooooow :-(" E! D* }, h; m6 _/ L, V- U
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') : n) y7 A5 g+ t8 B+ a
;will break 3 times :-(5 z! G0 j) T- D, I( r& h$ q
9 {) S6 _3 m. Y) J5 @5 x) c4 Z! ^9 p-or (a bit) faster: 9 C. i; i: p- F& o0 C
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
8 k* l( k9 B8 u% o% b9 d" u0 W. n a& w- ? s9 s- d
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
7 i5 q% l0 ^5 U% b( [ P ;will break 3 times :-(
6 b* W# t+ Q" A$ P
/ E( g- {4 {) r3 k7 Y-Much faster:9 z8 h# Y, ^- u1 K
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'. x( l! m4 ?$ ]" o# q0 h
7 L3 P2 J2 t! s* S4 }5 nNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
" g% ] w# R4 i! J/ Yfunction to do the same job:3 D5 I7 I8 k' |- e* \3 O
Q% Q* G4 ?' D# X push 00 ; OF_READ7 T7 A8 [' q$ W% e& z9 l
mov eax,[00656634] ; '\\.\SICE',0
% i/ q/ B. P0 b5 o( I2 B; x3 i push eax! [7 I0 O. K2 [# t/ b! t0 {5 p1 t
call KERNEL32!_lopen
2 e/ E- {8 Z! S* o1 c inc eax0 ?* U4 P+ v0 \, Q, l1 A. Y
jnz 00650589 ; detected
: Y7 N' Y H7 W! k) [4 w) Z y push 00 ; OF_READ
/ t- Z# N: m6 S mov eax,[00656638] ; '\\.\SICE'1 Y. a. V. C" [/ J. i
push eax
5 j4 ~) E/ K; @* g" y. R call KERNEL32!_lopen
& q4 J6 i( x7 J inc eax
. I) U J6 @/ \4 B/ W jz 006505ae ; not detected. M# l- ^) e- K7 p% S
7 c5 o+ |) f+ Q. J9 H5 W7 `! c/ i. j' s4 B- T/ c
__________________________________________________________________________
+ {) U6 _, z# Y5 |8 Z- w& q! N8 j' q5 q$ e: W7 @
Method 12
; A$ ?1 R( S8 A/ a: ~=========" @% m9 P' G5 x: M' F) }
|9 |( f& F8 n9 [3 T
This trick is similar to int41h/4fh Debugger installation check (code 05" E8 }/ t, Z, R+ E0 k; x
& 06) but very limited because it's only available for Win95/98 (not NT)
; k" R- h4 j [5 g" Fas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
1 h$ d2 X6 p* k0 O/ R# M( l; k$ w3 o T/ G$ L% z
push 0000004fh ; function 4fh: ]0 _- w8 D6 i% W
push 002a002ah ; high word specifies which VxD (VWIN32): o7 y& C- Q$ W& T
; low word specifies which service
* x7 [4 P" _/ D (VWIN32_Int41Dispatch). P, x1 ?! s [2 c
call Kernel32!ORD_001 ; VxdCall
& [* o8 T" R, s) x0 u& i cmp ax, 0f386h ; magic number returned by system debuggers% q7 w' G' m" G! C& K& M2 k
jz SoftICE_detected+ x; B0 H) h( I2 t+ ]
6 ?; H8 @5 B5 v* ~! d# ?Here again, several ways to detect it:
5 n6 S& Z( J2 t% X2 r G3 q; Y' w9 ^5 I0 l- X. O9 ^
BPINT 41 if ax==4f# s5 Z+ j/ R! S1 z/ ]1 r: I8 ]
9 z3 B% z3 m) L! B2 f3 S
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one% p) _! V$ W# R3 k7 I
0 w7 Z- R1 o3 P' X8 Q3 G, w( T BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A4 T1 j. p; d2 l$ J+ I6 c2 G' W
- c3 l2 x! @# c5 ^* a7 j; A8 }! h BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
/ k8 X; ]. |0 u- n1 }0 Z% O* w3 S+ z$ D
__________________________________________________________________________! @9 w, P0 {' F& X: t/ x# U
3 K# z. W7 r, r% Y9 y- l8 Y' S/ KMethod 135 ~' N; ?8 a4 ?0 \# x5 l4 K1 c% _" |
=========! E! ]/ r) ^) U0 S5 A
+ ^! V) W$ |: ~$ e. g0 ~
Not a real method of detection, but a good way to know if SoftICE is
' P2 k2 x! p" l! sinstalled on a computer and to locate its installation directory." |/ U3 s4 r/ L/ Z- _9 ]4 d( h" v
It is used by few softs which access the following registry keys (usually #2) :' y4 T4 s8 G0 K% @ P
" s( _2 x# o/ G( `
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 t* L1 i; @$ i( @! G: K
\Uninstall\SoftICE
: Q! B3 K$ y* I, N2 h# j-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- f0 M: B- A2 }6 X$ x( G-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 N% t% E' {: S% h\App Paths\Loader32.Exe: F, M9 N: _$ @4 e& e/ r
) G( O. M7 q% \" ]$ `
7 P& H1 w U8 [1 `
Note that some nasty apps could then erase all files from SoftICE directory; \+ f/ D3 D7 e0 Q$ s: O
(I faced that once :-(
0 y2 l& J0 @3 E0 C6 a* o2 k: P, ?1 v* q3 t( l9 d5 ?, g+ F
Useful breakpoint to detect it:$ d% m+ {8 F E1 A
0 t# N8 w" U4 A" X BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
' G' q9 C3 D; v/ M6 g$ V* @4 p. L- U- `( F* k
__________________________________________________________________________
! v+ {& R8 H3 v# k6 m8 {% k
$ J6 S0 X1 @) y) E0 m6 P$ v4 j! b; o" z& A- x
Method 14 & Q! I) }& O! u. j2 |
=========8 D f9 u. e* r
' u* c- E' b6 E2 }* C7 |( K
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose. [" w4 Z) H% N0 G9 z! x7 {
is to determines whether a debugger is running on your system (ring0 only).% r" Y& V& w: {( @
8 s+ L7 x4 N& L
VMMCall Test_Debug_Installed
M: |$ F( m( U# u$ j# H& W1 E je not_installed3 f- L8 f* z* q2 y. @- x+ f
+ y! m) n; ^# b6 ^7 r7 X+ k" xThis service just checks a flag.
: C1 Q& g( E* y) s) ~</PRE></TD></TR></TBODY></TABLE> |