<TABLE width=500>
0 L2 l, t# y6 N<TBODY>% C3 i5 y- R& W* |
<TR>
1 M1 t1 n7 K% O. D0 d<TD><PRE>Method 01
$ N j& W) S- o. i$ F$ {8 K=========
6 h: N, k/ _) ^$ R% V9 T
6 o; Z! c4 E; R* `- C0 uThis method of detection of SoftICE (as well as the following one) is
3 d$ b- c" P* f! I: K* Zused by the majority of packers/encryptors found on Internet.5 }$ T& H9 H1 X
It seeks the signature of BoundsChecker in SoftICE% v* u. k& ?- |
* C: D7 C" X+ L4 |: H mov ebp, 04243484Bh ; 'BCHK'* U' X2 a& T I& t$ i
mov ax, 04h' T' T) G J; `. H
int 3
" e; N P# n# d7 {# J' Z cmp al,4
: i: @) x$ f$ W+ n5 }5 _ jnz SoftICE_Detected
( S1 ?$ Y* ?# e! v! n) S4 m# t0 d. h: A; Q, L
___________________________________________________________________________- S) o, C. J* P5 M+ I4 j
0 S. c' s- a* m1 }0 x' zMethod 023 Z) j+ A* ^) L. e+ b" m
=========& C% ?1 V! n; I9 J: x
0 T. g/ ]9 D& @) I
Still a method very much used (perhaps the most frequent one). It is used
; @# F* ]5 ^) Lto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
) w: ]2 @6 j# a6 [% Q+ Z2 V% yor execute SoftICE commands.../ b: k0 G2 v- P) V# J
It is also used to crash SoftICE and to force it to execute any commands( h% @0 Q) y$ h( b# X/ B
(HBOOT...) :-(( ( v( B* [0 L3 `3 M+ U
0 T& {! _+ x p: m9 A1 nHere is a quick description:
/ K4 @) T) [6 v1 G' o, ~' U3 a I-AX = 0910h (Display string in SIce windows)
! ^- x& H; C% u-AX = 0911h (Execute SIce commands -command is displayed is ds:dx) Z0 G$ T3 ~3 t0 Z; \2 n+ F
-AX = 0912h (Get breakpoint infos)
6 U0 o% P# }) k: x-AX = 0913h (Set Sice breakpoints)
% E% _# h; _/ ~* U-AX = 0914h (Remove SIce breakoints)
" H: z. y/ Y8 u p/ K
3 t( \( E# z6 q( c! @* ]Each time you'll meet this trick, you'll see:! _- b( l( W) |! e; b* W. k: R# j
-SI = 4647h) o* f! X1 M' Q# d7 k
-DI = 4A4Dh
; h3 L ^( A6 r$ `Which are the 'magic values' used by SoftIce.
3 {. _+ i# U/ P8 D3 ^! a% f+ C5 AFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.; k& l. ^+ l3 f
8 e4 \+ i3 \9 J0 x/ e4 U! E# sHere is one example from the file "Haspinst.exe" which is the dongle HASP3 L2 _& t- N6 k3 f$ g& b
Envelope utility use to protect DOS applications:
3 K: i" v" U0 C4 p& X# L, w5 r2 }9 t# l G- I# \) S9 R/ l
& f- U/ Z2 _+ V- p. u1 q# H
4C19:0095 MOV AX,0911 ; execute command.
' o. x. h: o& K. O4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
" _/ _: f* Q2 H: v* D4 }4C19:009A MOV SI,4647 ; 1st magic value.5 g4 O9 \! E0 S+ w/ K
4C19:009D MOV DI,4A4D ; 2nd magic value.
4 h9 N6 Z$ ?" {4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)8 |1 W, C" U- Z* x8 M
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
1 J; B& D% I( G8 ]4C19:00A4 INC CX
- e G% s. P8 v" x4 @4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
~5 ~9 w% b- ~/ o# s4C19:00A8 JB 0095 ; 6 different commands.( ]( J0 F0 f7 z. W- p2 b
4C19:00AA JMP 0002 ; Bad_Guy jmp back.* H8 A5 q* {, e; _- I
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)/ E- p; X7 V# @) n' Y6 g- A
# O. v$ @7 A5 I5 a
The program will execute 6 different SIce commands located at ds:dx, which
' }+ q0 e( C* E: P2 bare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
1 h, F* f- S$ z0 k/ w6 g7 ^; L! Q, J* _2 B- m0 m+ w& d
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
; ^$ i" ]0 ]8 u- `( T! k3 E0 R/ ?; r___________________________________________________________________________. L& \7 X/ W1 R% c T9 i& f
" E9 `$ O& q! h! l. U" n# \/ A. k7 J- b- \
Method 03* k2 N- [. D4 W7 R" f }5 V
=========
) V e+ S) v: p% u9 m) S/ V2 p5 q" H9 L
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
( s% Y% ?4 E0 x8 a5 p$ x(API Get entry point)
* X# Q* s" m% a: w5 t 7 b+ E# ^9 I5 k/ r! ?; h6 d- o E8 ?/ ?
/ J0 b( b3 y' r+ X* I" _* i xor di,di
% f. I7 U8 G' S( H- x/ R mov es,di
' W5 m7 |& H+ T9 [ mov ax, 1684h ) C3 D! w) O- p6 V5 U p6 S2 C
mov bx, 0202h ; VxD ID of winice+ o+ f4 T. D; t! a0 `3 }9 q
int 2Fh6 h, j9 D# s1 w2 i- `
mov ax, es ; ES:DI -> VxD API entry point7 c8 i, N& Q; N0 `$ s; F& \
add ax, di( I" g% z$ L9 v- B; G
test ax,ax
* i* b8 ]& M6 p% U3 x; { jnz SoftICE_Detected7 J& i& S# V8 w. A/ k. |
% m8 u$ s- F n
___________________________________________________________________________7 S3 @; ~: b: |5 J( j) Q
3 J# k, W0 a p7 W9 G4 R0 t4 K3 FMethod 048 d5 g6 d1 D1 p; e; F7 V4 ?
=========
% y! \' s& X v6 P# T: C5 O$ u/ A+ V1 B
Method identical to the preceding one except that it seeks the ID of SoftICE
% n/ e. \" r5 kGFX VxD.7 ~9 D* [2 U! Z* e
; a4 B4 X5 q6 `" X: A) |7 r xor di,di5 p' P2 ?* ~: v% P2 Q3 Y
mov es,di) `6 c. P& V* n
mov ax, 1684h
5 |' n- S* D& q- u mov bx, 7a5Fh ; VxD ID of SIWVID
/ ]5 E( R5 z6 k: t; i; W- ` int 2fh
, p E/ o. R9 T Q mov ax, es ; ES:DI -> VxD API entry point
2 J! I! ~' S: p add ax, di0 R5 M% |& |3 Z& c
test ax,ax
9 D- y- w: b" ?' ~/ B jnz SoftICE_Detected0 a, e0 n6 V7 t% c0 Z) ?
: d0 E8 A A1 ]$ S2 j# j
__________________________________________________________________________: D g( M$ A, I4 v3 S; V5 |
1 G/ P7 x6 u; C4 }. t$ v0 n& ?( Q
: P* V4 T! X9 N1 BMethod 05
# `8 ^) H6 z ~! P=========' Z# d! S+ a e# H. F
9 r/ ^4 J+ J5 c: }0 M
Method seeking the 'magic number' 0F386h returned (in ax) by all system( p% C- ]0 o" E1 z( k" T1 M2 C" t
debugger. It calls the int 41h, function 4Fh.* U5 S& z8 M/ _% x
There are several alternatives. ! F) J% b) M# i$ F0 @8 f7 Y
- _) S* c* \. l) S/ C* E
The following one is the simplest:
( Z+ o8 V5 \8 s( T( t0 a$ O+ y7 _8 G9 C& ~6 k( D4 E" Z. O! @9 e
mov ax,4fh
' G* N; f: M6 x- l4 p# l( } int 41h( `: ^) Y# o' Q4 p, X# z
cmp ax, 0F386
, W6 g- v& @2 u% [ {! }: @+ E jz SoftICE_detected
! G( q/ }: Q8 P: Q l; V; H& c. i' T8 T' }- K- M
, O7 v9 i9 H7 k* T" t# JNext method as well as the following one are 2 examples from Stone's
' p, i" I2 ~7 {- O"stn-wid.zip" (www.cracking.net):
* [9 M7 q" S7 Z T: R0 [0 o% B
1 t; h8 M$ W8 @! l( J mov bx, cs6 R% g( G! x! c* n
lea dx, int41handler25 w& s. f) a( r+ G9 F
xchg dx, es:[41h*4]
+ e; b7 N! z3 m' Z( t* m$ X1 v+ a" ^ xchg bx, es:[41h*4+2]3 b9 h, a) N. T% B! [2 q9 W; c7 r
mov ax,4fh3 Q5 C4 s5 W( o5 ^! l4 j5 |
int 41h
5 u9 n4 d. H; u/ w; l xchg dx, es:[41h*4]
- X$ m' K2 e$ `3 x# z0 u0 ^ xchg bx, es:[41h*4+2]
0 W7 O' _9 E, x% K: L, S cmp ax, 0f386h3 e+ ^& h+ ^8 _' T6 }2 h1 A
jz SoftICE_detected
K, {) x. `+ R+ @. B$ k, _) [) }' D1 l2 H$ k0 S/ t/ g% }
int41handler2 PROC6 @2 g4 k$ T3 Y
iret
4 V4 p" `- r7 X' l9 E' m3 R- Dint41handler2 ENDP
6 L0 f# ^+ X+ L5 y, n1 X, C
; Y3 p9 T; }3 Q+ n% l9 t" O
+ y8 \# q- @5 b9 m! W_________________________________________________________________________$ O% n0 Y2 r0 z' X" ^
4 i% X8 l" G( g1 ~3 Z/ V# B
" x# w" a& a# ?8 _/ GMethod 06
' N/ q" z& U0 K0 q7 g=========; c, |& f; M% c' S: Y
( l' s" ^# E3 n6 m! X; s
3 F3 _+ u2 s2 G2nd method similar to the preceding one but more difficult to detect:0 `, T' h! p1 c4 c% B
+ g' r7 M4 t) A9 q" d* R4 i4 I7 M, r( D2 ^# }$ Z( B' h( l! W f* }
int41handler PROC5 |: p$ A. i9 _. p% H
mov cl,al
5 X4 s$ H! Y3 x3 T iret
+ g+ U0 @2 {0 R: H) N3 aint41handler ENDP6 _9 P; q7 S4 Z3 y
; t1 Z9 e2 A' F, C& B* g
~, M4 { a8 ^$ g: Q' \/ N5 k( O xor ax,ax
' g2 y2 P+ j+ t$ f mov es,ax7 i2 w0 K8 O# U a2 S- [3 x( k# F+ T' Z
mov bx, cs
c7 Y! p. o! Y. L% v+ g. [ lea dx, int41handler" Z9 S% T0 M( @ `9 m1 Y# b
xchg dx, es:[41h*4]; P8 s* f& e' V% l ]
xchg bx, es:[41h*4+2]" n( o# W E- I' k4 t: R3 ~4 V
in al, 40h
( O" H3 q/ [: {* k xor cx,cx' l' c' I9 D% t' n: [2 y; p
int 41h7 x( g* a8 b/ Z! O# ^+ n
xchg dx, es:[41h*4]
2 w1 {; g- V K9 v- Y/ ~/ H xchg bx, es:[41h*4+2]
4 ~! x$ I/ w8 X1 @! P4 ? cmp cl,al
8 m4 G' O8 D: X8 ^$ f9 D jnz SoftICE_detected9 E7 b1 K1 j2 U% A$ ~7 g
3 q1 m: X. f+ H; {, [7 U
_________________________________________________________________________
8 H; f3 e+ }7 u R% w7 d, Z4 D$ Z9 p$ g3 Y; [
Method 07
- O0 |9 n1 H5 U! z' |, ?* ^7 {% M=========
% K5 D6 B' Y& R" @0 B: w- u# D+ l. {# s. ~, R/ E" a- W: O8 ]
Method of detection of the WinICE handler in the int68h (V86): S$ R2 ^1 ^7 n: W) @8 H( W# x
2 m6 R. |6 Y. L8 W6 w
mov ah,43h
" ~ V2 q Q" x int 68h% L z2 N0 T9 u5 }) `% ]. T9 f
cmp ax,0F386h
7 B! ^6 g! P: O0 E- V$ j; Z6 x" t jz SoftICE_Detected& c* O1 z8 M7 C5 ^
7 n# a+ F! R, v0 n; A3 h$ p0 ~! ~" x8 D
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
$ v* F3 [4 F1 `, T app like this:1 z( C0 A& O- M8 m
+ u: Z! W1 n6 t; I( r
BPX exec_int if ax==68
+ Y! b: V ^- Y! Z9 W" c: b (function called is located at byte ptr [ebp+1Dh] and client eip is
) m! d7 R: I |2 A* l located at [ebp+48h] for 32Bit apps)
; L3 a C9 Z: b__________________________________________________________________________
- I$ p8 X E4 [+ y) a- [1 k4 z! |( X0 [3 r' a( [
9 B7 u$ h' _; x
Method 086 B2 |2 @0 o9 ^% p4 |0 ^
=========8 c' I O$ H8 K6 B
) L% @8 ~ M. a! D
It is not a method of detection of SoftICE but a possibility to crash the+ o: F5 W' o' x, Z7 O
system by intercepting int 01h and int 03h and redirecting them to another9 k8 w) d; E0 p% l+ ]! _
routine.& N( S6 J# \- q1 P
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points7 J U& y0 _1 W( m8 |
to the new routine to execute (hangs computer...)
0 e2 b* T$ n R" b y# P# K
P! z5 i" \+ u8 N3 h3 ?% t h! { mov ah, 25h6 j8 v4 Y8 P' f" B$ @' {
mov al, Int_Number (01h or 03h)
: m; x1 T& j; t9 H# m mov dx, offset New_Int_Routine
$ D9 B* m, j4 e$ L8 s7 _) S1 ? int 21h: |0 {1 N. K+ `2 m
^/ e8 T2 B- W, ]* K9 `
__________________________________________________________________________
" a5 C, e6 s+ G5 U/ f; F9 L
2 W' p5 \3 ^2 U3 }& ^ j9 J8 HMethod 09
. Q2 a4 ~8 i } Z) A8 H; m1 u=========
6 T0 S, q5 N& n+ R7 b5 n6 `) A% p
$ C, A- s* h" ]+ d- ]! ZThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only$ _* J* W/ R0 H! X+ v2 @
performed in ring0 (VxD or a ring3 app using the VxdCall).2 h8 }: y! S* n/ S
The Get_DDB service is used to determine whether or not a VxD is installed
+ E2 l& F7 M, `for the specified device and returns a Device Description Block (in ecx) for
/ q- B" c7 R! _7 @that device if it is installed.0 ]; k' X0 o3 N. G
; h% v! J- s; h) g& F+ p; |5 C$ ~( O mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID* k! ~) h5 u4 ?% f3 Y( H1 e
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)) w+ m' e' {# }0 @+ r, }$ X& s
VMMCall Get_DDB
' L9 F2 K/ V( p* n: A1 C( C) b1 I mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
1 J9 \: G; [# A# s* b4 r0 P( M- F0 q$ ]2 S! Z- s# z
Note as well that you can easily detect this method with SoftICE:
6 i g, \# V! N* ~6 ?2 r$ L/ R bpx Get_DDB if ax==0202 || ax==7a5fh
6 [3 x' K; ?+ E: `" i* F! s' R) H7 _+ o1 F
__________________________________________________________________________
/ L$ N" d7 U- m. F' R0 }4 ?- S1 Q, I& [9 ?2 `* x: U$ O
Method 10
9 m M% F1 n2 g& o" J=========# {8 q% x, G; s: I# [2 ~1 E) u
: ?% v& k' k7 H
=>Disable or clear breakpoints before using this feature. DO NOT trace with$ u. r% c( G' X& P+ l
SoftICE while the option is enable!!4 d% H- V5 `+ |+ O: n
4 e5 e5 Q. A- Q; s# m5 r; k9 q
This trick is very efficient:7 A& F, i( B) U/ R
by checking the Debug Registers, you can detect if SoftICE is loaded# G. Y4 t1 V/ c% }- F7 V( z8 k
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
- ]" U" N+ L9 V! ^0 |1 `! @there are some memory breakpoints set (dr0 to dr3) simply by reading their( h q# ^3 n }; S9 e8 J
value (in ring0 only). Values can be manipulated and or changed as well- k$ I! J- R* L3 \1 u3 [
(clearing BPMs for instance)+ O3 e4 x& `( _( K- j7 i
# S9 N5 \0 l+ a) h0 L+ o
__________________________________________________________________________9 d' [" s# F2 u6 A4 b. b
+ Z; e& Z+ ?1 L0 J
Method 11
. {+ W8 ]( Q9 O2 s j+ H: U1 j7 T% s=========- K2 R. c9 \9 m) ^
: x! {0 R& m& A5 [3 k! |This method is most known as 'MeltICE' because it has been freely distributed2 a0 C3 D% u0 Y: I3 W l9 I
via www.winfiles.com. However it was first used by NuMega people to allow$ f& Q' b' I5 U6 [- A5 D
Symbol Loader to check if SoftICE was active or not (the code is located) i4 i7 s! f. ?
inside nmtrans.dll).
, r u, l b i C) M! P5 h6 P% ^% W* i% G8 B7 u$ Z2 j
The way it works is very simple:8 `2 [1 ^, x: z; d5 _5 P
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for4 c' i4 e0 M; S; A2 d
WinNT) with the CreateFileA API.
+ Z1 o9 m& e* [) Z1 p! \& K6 P4 g8 T
Here is a sample (checking for 'SICE'):
^- F( }* ~! n4 v) i7 f
/ m7 W# {* ~1 Q8 f! t1 wBOOL IsSoftIce95Loaded()
3 Y8 U) d) x% Y% Z& [{) N' B# U# E& C/ Y% Z. x8 ~
HANDLE hFile; 3 ]% D( P6 p8 U4 _) V& z3 g
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,# t P) X" s8 X$ [; }' J
FILE_SHARE_READ | FILE_SHARE_WRITE,
5 R) `2 X$ i- `0 {1 r8 J NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
' _8 _9 U$ k+ A% L4 B if( hFile != INVALID_HANDLE_VALUE )
' E# H! e9 u0 r# M! Q {. S; \9 e U" `; u
CloseHandle(hFile);" P: r+ Q) z8 C' Z' ? J: O* ]6 ?
return TRUE;3 [2 `" V- }& j+ L/ f3 Q2 E
} c1 O3 L3 l" z/ E
return FALSE;' n3 y0 d7 Q7 D1 C% y5 t
}6 B6 W$ s4 R+ h' a/ u% }
' ], v4 g4 J b& RAlthough this trick calls the CreateFileA function, don't even expect to be
6 ~+ `/ G$ f6 H' d0 o+ Mable to intercept it by installing a IFS hook: it will not work, no way!
) N+ G3 G' e+ wIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
, T: [& J3 h" O9 s( E# r6 M% Mservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
- M6 E' N3 d/ O$ s1 B/ V3 xand then browse the DDB list until it find the VxD and its DDB_Control_Proc) x/ G" C, x/ {
field.3 B8 j; ^- R! L/ a9 e% V( L! d
In fact, its purpose is not to load/unload VxDs but only to send a : P- `7 D: K) S$ P
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)( K/ q( ^* X0 K" n
to the VxD Control_Dispatch proc (how the hell a shareware soft could try1 k0 ~3 C( F- W8 P% J/ d0 }
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
7 G! l7 d P& EIf the VxD is loaded, it will always clear eax and the Carry flag to allow1 H6 |6 S( k) y B. R' L
its handle to be opened and then, will be detected." X1 O* Y- L2 H% H6 `2 k+ H
You can check that simply by hooking Winice.exe control proc entry point
7 W* h2 C- {3 t+ i. n. U& nwhile running MeltICE.8 I3 B7 B# E- U% D8 K2 C1 t
! Z! \' M9 [+ g. E) A0 I, E
% ~! G( [' G, I* F% i 00401067: push 00402025 ; \\.\SICE
- E7 P, ^, M8 F% q 0040106C: call CreateFileA
* {7 G+ a7 `7 Q4 w- g7 ^: U$ o/ I1 Z 00401071: cmp eax,-001. B# X* ]2 V* i+ @
00401074: je 00401091
9 t$ u( k3 d; C( y0 B/ R" F' G) A% N9 n' o: |& m Z! Y/ ~3 a7 L2 v
, Q1 Q- p1 p# C2 q6 yThere could be hundreds of BPX you could use to detect this trick.9 d+ ?# B6 V5 }4 \/ i
-The most classical one is:& u4 t9 _* n* Z+ Y% Z& J5 J" A
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||1 _$ h( y2 K! D. G+ m
*(esp->4+4)=='NTIC'
6 b# ]) _# @3 R1 O' x2 O+ z, r9 a0 R) Y( T
-The most exotic ones (could be very slooooow :-(: F6 Q' n' O- x/ k- L( P
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') % n: E. e9 e, \8 ?, D
;will break 3 times :-(
' Y8 r' r: w; y
# p. _& n( f! Y-or (a bit) faster:
( c z7 }% I/ |: h3 X8 _ BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
X' ^; x' B b4 t
@! U; P7 c; G( { j BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 2 I5 _# ?0 M0 v5 V4 j: n8 [* @6 H
;will break 3 times :-(
2 ^7 `8 Q, z z0 F, U: L) w6 U$ u# H- J* d }
-Much faster:
0 e9 t9 X2 l/ a9 S BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
* z3 ]$ A' Q3 _( y/ F/ R, a8 {" g _; ]8 f6 I* p0 r! G
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen7 {# E- L9 r% Z6 f4 M: U
function to do the same job:% r, W! C) S1 }
5 C/ [6 B! ^0 D( `+ P
push 00 ; OF_READ
9 a+ T) H8 _, n8 T& O' f mov eax,[00656634] ; '\\.\SICE',0
- D1 y+ w3 B- K push eax& j5 I, S; {2 \# t* |! J! }
call KERNEL32!_lopen8 J2 n$ v4 _4 R$ j" o9 W% T
inc eax
0 F3 q3 f$ X/ E: ]$ Q jnz 00650589 ; detected
" \0 ?; f0 B8 C' ?2 @+ D! k push 00 ; OF_READ" P% d4 V( d+ a; Y) d
mov eax,[00656638] ; '\\.\SICE'
! G6 ~$ E% u. e# k push eax
* W% E) U" ]5 ?2 g' b. p# K call KERNEL32!_lopen
2 R' p' c6 t/ z) C0 V3 e$ _& t inc eax
( J3 K# c3 J2 f' ]+ ?" T3 }5 w jz 006505ae ; not detected
1 d% S1 g4 Q& b+ O! L7 v4 c% e5 i$ o8 W* D5 I# O; e, c
9 s+ R8 L4 ~3 a' M5 b__________________________________________________________________________8 ^/ d/ M0 @3 Z- Q
9 E- b6 Y u3 Z) Q5 n4 iMethod 12
, x# v" O/ V t3 H, Q' ]/ C" S=========
, w) R/ d$ `0 {+ D8 { u
. X" K, y% D# {0 S& h( PThis trick is similar to int41h/4fh Debugger installation check (code 05# B2 b4 e, }. l9 g O" b
& 06) but very limited because it's only available for Win95/98 (not NT)/ K b1 |+ V3 r) n' H
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.# b& Q2 h5 G3 Z1 ?
4 I$ f5 U8 z2 ]+ s3 j
push 0000004fh ; function 4fh% D0 V. g: L+ A7 y3 T- c
push 002a002ah ; high word specifies which VxD (VWIN32)# a0 V% Q' ~/ C: q6 y
; low word specifies which service1 g( c' }' E! }; m+ m- o
(VWIN32_Int41Dispatch)
) `3 C1 o% l2 I. u6 \1 E call Kernel32!ORD_001 ; VxdCall
9 `) \$ o1 x# @/ p/ N cmp ax, 0f386h ; magic number returned by system debuggers
" Q4 U) E9 p5 \1 x9 J* D4 N! B0 |) d jz SoftICE_detected
- @1 [" t# i; e( t% s s7 ^# S8 V9 S9 p: i% S0 z
Here again, several ways to detect it:
7 L1 S7 N* Y& ?5 |% c) _1 u0 {! g7 u# {3 u
BPINT 41 if ax==4f
( ~9 s5 @9 U2 t, y5 \; q+ c
0 p: T: G! _3 Y6 N* H BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
/ @" f& A/ q: v6 R& {4 K1 r5 Z' Y$ I
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A& ?' M8 I0 \4 i4 m% q
7 f$ ~0 F: R, s0 o1 N/ d* v
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!# l4 [, D: c) l# J4 y
9 q7 [2 E9 G, w$ N( c__________________________________________________________________________3 T4 F7 ?; l: B2 O& V' Q
I; q) a. b- B \8 U- @Method 135 s! k) b" x/ w/ k
=========
9 y( o$ Y' f2 z- A# g& l, s- w/ j$ E' X" s k
Not a real method of detection, but a good way to know if SoftICE is4 q; j- w) U. D' g
installed on a computer and to locate its installation directory.
; y1 ~; y1 o" H' {It is used by few softs which access the following registry keys (usually #2) :
0 q% ?8 L; P9 g( h/ Q- g! d0 p, X$ ?' B5 t
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
p" ?# v- ?% C5 C\Uninstall\SoftICE
. C s( t7 j+ p5 Q$ R; v-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE; q6 q' N4 h4 u! T6 ?& L* \% M% Q
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
$ b8 o$ h9 E- S6 e* n0 w\App Paths\Loader32.Exe
1 [6 r. p/ K6 ~# i' z9 t: u% [$ E! y1 M" z0 ^9 f+ g4 z* S, U5 v
7 O0 @% e U$ p: T( Q( O
Note that some nasty apps could then erase all files from SoftICE directory
9 M4 x3 |9 o+ d" _( |(I faced that once :-(1 N- l) h( J" t$ U
+ x% F, E9 H/ R8 j1 n' U5 S, X6 n9 _
Useful breakpoint to detect it:
' P0 e' N2 b* E& z5 \ w# x( `
" @# L0 U+ K, e/ p BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
5 p0 @. P `, Q( P% T3 Y
0 f1 U6 B9 n3 X. Z' S__________________________________________________________________________
& N6 \+ U' }9 l( G3 T2 ~! k+ h+ O( n. @7 T7 V9 ?2 G6 w3 b1 }$ x+ M
( W, _2 }) g# p* d
Method 14
3 ~# T% f3 K8 \5 L* d5 B=========
6 E/ t# J5 _/ R4 q/ V9 u
, S7 w" v! |2 u4 N/ f. hA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose2 X2 u3 e. X9 {5 g
is to determines whether a debugger is running on your system (ring0 only).
9 H! j2 z, A( }4 z& V3 K. Q1 t# S3 e8 o' W: N4 h
VMMCall Test_Debug_Installed( S* Y9 \6 R8 D
je not_installed0 Q8 }. P- D6 V4 @; F
; S y; ~) X" iThis service just checks a flag.
( F: x' c, Y* a! F& f/ F1 D</PRE></TD></TR></TBODY></TABLE> |