<TABLE width=500>
+ d1 t9 E- X! d5 ^ p" i<TBODY>
0 g ]# B* ]8 A! c; n- H' H<TR># ^# q/ `9 Z, [ n4 C
<TD><PRE>Method 01
5 [- ~- I+ C. K+ `9 ]0 e3 r8 I/ ]=========
/ P' O+ k8 ]/ L4 u# n) b
8 C( ^) I, S9 D0 h3 z# M) V4 ^This method of detection of SoftICE (as well as the following one) is- G: u4 b+ z# F4 b1 g+ t
used by the majority of packers/encryptors found on Internet.. L( Z; P0 R" x& r3 a
It seeks the signature of BoundsChecker in SoftICE; L/ V8 S7 R3 P! Z8 H
* [; i- j" Q8 Y# p7 i mov ebp, 04243484Bh ; 'BCHK'
8 H* j$ F) J0 Y& j C. z& c3 d mov ax, 04h
7 h5 R- B0 R% Y& N0 ^3 F' b6 \" r int 3 / m) _5 b4 |0 a5 m: I* U
cmp al,4
' T/ |6 j& m, _" Y( T5 B" S: T jnz SoftICE_Detected, w6 N% ]7 t+ }7 L. P
& Y; Z6 e; d9 Y9 o___________________________________________________________________________
9 [9 w( `- U' u6 e) E' @+ S) a8 M" }, L5 A, }/ R. ^
Method 023 Y( i- H0 T! a1 `; }# l7 e+ w% R; K
========= r+ z d! `& h; R
7 G, u$ {0 o' R { \
Still a method very much used (perhaps the most frequent one). It is used
z+ I8 M0 ?, y- Z- Z: i. @; rto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
7 b8 @2 m4 y2 O% Nor execute SoftICE commands...
& B9 Z' U- W( _: r4 G! x3 xIt is also used to crash SoftICE and to force it to execute any commands+ w/ j% J" ?. o+ S+ e
(HBOOT...) :-(( , x/ ~. X8 Z/ C2 ]: w8 d: o
' {& x* g6 ]9 X6 c- P/ ?Here is a quick description:
" G5 x4 L3 D& S. t2 X. N0 i1 x6 B-AX = 0910h (Display string in SIce windows)
; U/ F8 C5 e8 N2 W& _! F" N7 \1 K-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)+ w5 k D' E3 y, c
-AX = 0912h (Get breakpoint infos)2 i# e: ~6 u5 N8 o4 S+ D
-AX = 0913h (Set Sice breakpoints)8 l g p0 S; q
-AX = 0914h (Remove SIce breakoints)
8 P6 z% p/ u! W/ o6 c5 k9 G1 G. J8 B1 N
Each time you'll meet this trick, you'll see:
2 q" x( O% i" F, z, f-SI = 4647h$ g8 v4 N- I b
-DI = 4A4Dh
( S, j1 P! {5 u, t+ y; F( uWhich are the 'magic values' used by SoftIce.$ D3 j' h% ]" @9 j3 ^
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
) Q* [/ N2 k9 o4 ^2 M! ~4 ~& T$ R5 q& j
Here is one example from the file "Haspinst.exe" which is the dongle HASP
- W4 R2 k% I8 h* F6 UEnvelope utility use to protect DOS applications:3 N% _& q6 e3 m
- E) r; @) w% X% f6 ]
7 ~. C. L4 ], \0 s6 t9 J4C19:0095 MOV AX,0911 ; execute command.# `) Z# w& o/ e
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
' O ?8 ], Y0 h' @: Y) H0 O4C19:009A MOV SI,4647 ; 1st magic value.& f% c9 k# d; F" W) n
4C19:009D MOV DI,4A4D ; 2nd magic value.
: D+ S9 [% a( ~2 ]" }4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)5 z9 \5 J- {/ A3 w2 r0 G
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute/ X0 {* ^6 v8 W" w# s, z* C
4C19:00A4 INC CX
/ _2 T0 Q. [' r, m4 D1 q- U; l0 D4C19:00A5 CMP CX,06 ; Repeat 6 times to execute5 j5 h2 G( }/ _, R* H( t, y& X; ^
4C19:00A8 JB 0095 ; 6 different commands.
) c! m# O9 G2 C( E4C19:00AA JMP 0002 ; Bad_Guy jmp back.
3 F" C8 F% y2 X( e4C19:00AD MOV BX,SP ; Good_Guy go ahead :)6 r9 i8 R. Y' p ^) J
* `5 N7 V+ X7 g" r( x1 C5 d& @
The program will execute 6 different SIce commands located at ds:dx, which
( R2 c" t' {6 g9 f& }! L1 B O1 A g" {are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.! y' U S# N' q s8 ~0 V A/ U4 x
! \ U1 A n! W4 ~+ S% z; R. E: U
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
- f. z, B+ \# ]; |- c___________________________________________________________________________
# S" Y$ z% ~* z9 a& T
5 J% S' k7 f. t. e' v
}& O1 Q! G9 d6 m; mMethod 035 O7 i* n* n! y, c' w+ S
=========6 g1 D; U- N6 [& _3 ^& ^+ \
5 `% X: T, X& w2 X8 f! XLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h, Y8 H5 q4 o& H! Z5 @$ E2 N: o
(API Get entry point)! z. Q9 N4 p" h+ b5 T7 o
; Q, `+ \6 {0 t/ \: g. d7 o: N: B3 P
xor di,di1 p. D" c/ W0 J6 |; r
mov es,di! S: r3 P- @# Z3 Z
mov ax, 1684h 5 v) Z& s$ {& f
mov bx, 0202h ; VxD ID of winice
) d w0 g$ \7 s0 a int 2Fh* i% L5 x1 f! ^& v
mov ax, es ; ES:DI -> VxD API entry point
0 m* N$ s4 @1 b# r4 B) M2 j y add ax, di
+ B$ Y6 ?( Q. u2 V3 D! ], a' O test ax,ax
, x- {+ z8 X z$ M3 j jnz SoftICE_Detected- l4 Q: S( C% P3 X1 `
' T8 J# t; Z7 a$ g: `- T( B1 x___________________________________________________________________________1 g8 z8 E9 X! K9 [. {% K. I. P7 d3 d
, h& m/ W0 t7 e- ?Method 04# x) ^0 U" D, o3 r. l7 C( T' g
=========
! l: [1 I3 j5 T2 r
: n: ?+ A6 P6 x5 g) ?/ [: ^Method identical to the preceding one except that it seeks the ID of SoftICE9 x7 h8 h( S, O4 f! C
GFX VxD.
6 t |; j3 D$ ~4 X
& c. Z% y. U* @% t2 O* L xor di,di
7 G/ m9 z" Y7 ~! L/ ` mov es,di! ]3 a9 y) ~, s) B" n+ m' |
mov ax, 1684h # s1 U4 ^ x" _$ v+ y
mov bx, 7a5Fh ; VxD ID of SIWVID& I" b, t; j* K
int 2fh. P6 n4 d! d9 l
mov ax, es ; ES:DI -> VxD API entry point% u' m5 E; ? C% g) U
add ax, di
+ \( S* W2 w8 e8 X test ax,ax" [' D6 l' e4 |7 y) k5 a3 f2 X" s
jnz SoftICE_Detected2 ]$ U* J. i. O; P6 p! J
( Q2 J& }' l( m4 H( l/ n M__________________________________________________________________________1 d( [; U# Y- y+ R) u7 g& F" d
. [1 g' \, `: f2 K5 E2 `, e/ J1 `: u. A4 Y8 [
Method 05
# C% M+ A; Z6 Z" j5 @' y=========
) [7 Q+ \9 x# |& R
7 i7 h& ?0 I' Q# G& g9 SMethod seeking the 'magic number' 0F386h returned (in ax) by all system6 b' A+ c# Q" C5 V' {$ D, \
debugger. It calls the int 41h, function 4Fh.3 A" R5 d5 `% x j
There are several alternatives. 6 x! p/ A O1 N$ c" j3 Y
# o8 t7 S; a8 F$ NThe following one is the simplest:
9 Y; _) B) P, R4 U& s( h6 q/ H" A& Z( r
mov ax,4fh
* r6 b- z% j6 j- y: s int 41h
# G6 E. {. W! j9 K. C cmp ax, 0F386" \0 B8 A6 j" F4 i k3 G
jz SoftICE_detected. W3 M* J* A, }! Z
2 p/ z( r& n6 D4 J. |4 o! ?, m" J- s* @2 y
Next method as well as the following one are 2 examples from Stone's
% J& t" _' p& k( k" k5 B" d"stn-wid.zip" (www.cracking.net):4 E+ F5 x* y; m) S' c2 b1 E5 d
9 _# s0 {2 k! `; M& [7 _0 t& X
mov bx, cs
) C& H8 l9 b. y/ a! s& `0 D& z lea dx, int41handler26 ?* `* j- M; x5 O, ?: R G+ W
xchg dx, es:[41h*4]; u* n/ G. ~6 w! g8 |2 O5 @
xchg bx, es:[41h*4+2]2 j& Y& a. D! W4 C: X3 q
mov ax,4fh
( N5 P8 Y# E/ f3 ~3 _( ? int 41h5 [: g3 t O" T" W* n/ y
xchg dx, es:[41h*4]
- S( [, y* e% W8 i: K% a4 r xchg bx, es:[41h*4+2]1 k6 F7 `. q+ J% H) q7 w& @4 h
cmp ax, 0f386h
- d. y5 y% r- j6 G; e jz SoftICE_detected# i: v! i- r7 S1 O1 G& H
5 L9 o* O. F! m# f; |$ k3 R
int41handler2 PROC4 h1 M8 w8 G& P/ a
iret
|. ]# h- N, s2 B' Dint41handler2 ENDP+ h: w; G4 d% m* l9 p
' o- p8 S2 W5 E
. A5 j# u: w* F_________________________________________________________________________
& \3 @4 M; X5 e1 N1 }
' l! u# [( t( \+ M5 Z: u
4 B$ r4 u. R! r$ F& a% EMethod 06' x! d& @9 G/ ]6 s# N7 q
=========. X7 q+ q4 V, M7 n' Z0 K
- ~" J2 _; y& V
2 R* A" N/ ~3 r9 R% s! ~2nd method similar to the preceding one but more difficult to detect:
5 t: X( B- z% C( r' I# y$ D3 w* t9 D% }! K, O4 [
. i: ], o% I" O& h9 J2 A- N! c( u
int41handler PROC# W7 g. |* G& d/ f
mov cl,al
+ S' M( z) ^* g0 T o1 J/ y iret
" u7 `* a& @/ k1 k$ j$ d# Kint41handler ENDP
8 V# m* k) I9 {$ L: Y% e r8 ?* D+ O2 V3 b7 D
- l, M7 Q0 i9 R% m
xor ax,ax& O/ S/ f6 \# s, h, _8 \
mov es,ax
& U) Q% `! r3 _& Z mov bx, cs8 V" N; @$ Q) H6 Q% W; _6 T
lea dx, int41handler# M* U6 t$ D: M
xchg dx, es:[41h*4]
6 X. p5 D/ K# W$ ? xchg bx, es:[41h*4+2]
& R: b/ ?: Y2 b/ U9 J7 ^: ~: ?; Q in al, 40h) ^2 b6 a% K: L1 p
xor cx,cx) s8 y$ G( `$ B- v/ ~
int 41h
; _2 _* V( u6 ^. G xchg dx, es:[41h*4]
- `) H- F2 ]% {0 e xchg bx, es:[41h*4+2]
1 Y" q1 m" ?0 B ~& S$ I cmp cl,al/ v. _6 @' Q( J, Q. I
jnz SoftICE_detected3 I9 c1 n/ v K0 A6 a4 j
# H$ j! X V: R/ }8 _
_________________________________________________________________________+ {9 p! O4 H" z: {7 v. d
& F0 H9 b u4 ]* J% R( JMethod 071 B# f+ w/ F* q. y# i
=========
2 \, h& r( W, G M, n9 S0 s% h- S! E4 Y9 { p* o% X
Method of detection of the WinICE handler in the int68h (V86)8 H: h9 I2 P: O
7 ^1 w, O( I; p6 J) k1 T mov ah,43h/ b) m* X+ D- B" c2 I
int 68h
$ f- O/ x( Q5 j cmp ax,0F386h
# q8 M6 ~% B3 c) K) Q4 M* W jz SoftICE_Detected
: F8 U# d4 E! G6 g6 p" t4 e5 Z2 k8 H
2 N' V' i' [- _4 h, p4 _: O# O( Y4 b9 y
% t" {/ K* } n7 |0 k=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit5 H1 P7 \* V, k0 _
app like this:
3 a- O" C0 W; ]( @! }6 n) w: ~ Z. l+ }8 W$ [/ n
BPX exec_int if ax==68
9 X& d3 s' E; m t- l8 J: m* g; O (function called is located at byte ptr [ebp+1Dh] and client eip is
2 Y1 a0 W0 s, q5 m* r located at [ebp+48h] for 32Bit apps)6 x+ R5 F( R9 B5 Z
__________________________________________________________________________
; N. _8 J K& b: o
4 b2 s* T8 O' ^ `, r/ j7 r5 D0 x9 H2 T; w
Method 08
4 G& l0 ~6 w: Z4 S) Z=========
( u- D! S9 R7 O) K1 s7 ~/ v5 D6 ]" G# W: f1 e
It is not a method of detection of SoftICE but a possibility to crash the
, h% Y/ C0 m7 L E7 v5 ysystem by intercepting int 01h and int 03h and redirecting them to another
4 M. H& L; x4 u6 E+ nroutine.
G4 ?" \$ _, B9 [It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points! k, W; B Z9 |6 F
to the new routine to execute (hangs computer...)
9 i7 i5 p( @. \+ v8 i% e$ w0 T, l) Z: l, i \- I4 ~7 n
mov ah, 25h- B! i8 n+ C7 g3 P! M
mov al, Int_Number (01h or 03h)
. R: \* S1 d2 X5 \6 a4 I, x mov dx, offset New_Int_Routine
+ W7 R$ P- y7 v int 21h
3 V$ q# a# g- S$ Z; s1 \
; O( W% X i! P3 P__________________________________________________________________________
. T9 W# Y0 ~* c! Y _2 L p( X9 B- }' W
Method 09' e* f% \: V' @! ?' B* y
=========
+ S0 @3 L8 P: T0 y. P5 L) q. M0 Y
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only9 y/ \. h2 J% W9 Z) Z: M
performed in ring0 (VxD or a ring3 app using the VxdCall).- j- C& m1 P* m" I/ @* c! a
The Get_DDB service is used to determine whether or not a VxD is installed
0 T% f# W0 w: h' `for the specified device and returns a Device Description Block (in ecx) for
$ ~ K; h8 k2 F7 ~& Cthat device if it is installed.
+ z9 |, t, w3 s8 {1 [( K. N# \* J9 p) E0 E) w, r
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
% s7 `6 \0 x6 F7 M K mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
- k- f. k% R$ u6 d/ y+ n9 ~ VMMCall Get_DDB6 y6 x) C( _+ X& w" T
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed! [' w) w8 T! n* Q3 z6 `
4 U7 C4 O7 f% L+ e8 hNote as well that you can easily detect this method with SoftICE:
& ~! j7 o0 r- { bpx Get_DDB if ax==0202 || ax==7a5fh9 v% b4 B+ Z4 P* I. S6 A% o
/ m3 a+ |- S; ?. w# j
__________________________________________________________________________
1 S7 l: j5 T; Y6 T9 p) g5 R+ Y. P" o
Method 10
4 N# y% `' t" t I=========
0 ^. e' v, Y3 W3 q( G0 i6 M. `: a1 T( e: m; B) }
=>Disable or clear breakpoints before using this feature. DO NOT trace with
! \* T/ v& X4 G3 i SoftICE while the option is enable!!8 H+ S5 j2 }$ v8 J
3 Z0 s, Q# Z& b1 K) O% j
This trick is very efficient:
% p: Q. _% }0 k. Hby checking the Debug Registers, you can detect if SoftICE is loaded7 G% m! ~4 p( K2 ^+ ]# e! m6 i% W
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
7 k' G8 }1 y: p f/ Y; ~there are some memory breakpoints set (dr0 to dr3) simply by reading their4 m/ N7 e+ v1 v) q
value (in ring0 only). Values can be manipulated and or changed as well
6 L3 w! L8 S) F(clearing BPMs for instance)
4 L6 a2 Z0 B' e& `2 `: F& L0 W$ `, [& x, j. d: v" `' {6 {
__________________________________________________________________________6 Z" D1 E/ N, f; Q+ z
2 m7 | ^5 w# R& N f$ c
Method 110 R( k/ R* I' t7 j& L5 {9 q
=========
9 \4 [' D# p- d' m' j4 Y+ i
( o4 q1 _* n' v6 K, }2 eThis method is most known as 'MeltICE' because it has been freely distributed# D; k! O0 _( H) C" J6 P5 D$ V
via www.winfiles.com. However it was first used by NuMega people to allow/ u; e7 e5 G, [9 B3 Z; L
Symbol Loader to check if SoftICE was active or not (the code is located
, r {& U( j- a( b9 a- sinside nmtrans.dll).4 t/ m+ }0 C8 ^" z2 \& q
$ L G; @2 m" b( E! f
The way it works is very simple:9 W: f0 p3 _) }8 }
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
, h' h- R7 }' t+ B" Z5 u9 |0 WWinNT) with the CreateFileA API.* m3 D8 k" {$ A* j$ V* w2 l" S; Q4 |% Q
7 f6 K6 S( q( @+ D" f# j) W K
Here is a sample (checking for 'SICE'):: F" l' E0 D" z+ ~- o
. C1 M& W4 T: RBOOL IsSoftIce95Loaded()- j. D& _1 y0 ~. |
{8 f' o& j5 H1 P3 X+ ~
HANDLE hFile; 0 N' s6 _. e2 u! l( h6 r+ X; ~
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
5 ?, y7 \0 }3 ^- `- E- R FILE_SHARE_READ | FILE_SHARE_WRITE,& ~0 ?! Y6 ]4 U+ _
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
8 z' i6 s! O. u3 O if( hFile != INVALID_HANDLE_VALUE )
1 f1 H9 h/ ^" l6 `$ y5 g {4 f: p; R& `3 S& u$ |8 H) [
CloseHandle(hFile);7 U) v8 J8 ^: f$ L. F I% y& U
return TRUE;6 Y Y8 |9 E7 a0 U8 b; ^) [5 Z
}
, k- D3 y- H& I+ @; }- a return FALSE;
# Z2 _0 w3 g# o7 n}
6 c5 @ `9 M8 }! Y' S& r2 s3 `7 T' Q9 ^$ k! k' K0 o1 b
Although this trick calls the CreateFileA function, don't even expect to be! p, a6 W7 r( c
able to intercept it by installing a IFS hook: it will not work, no way!
' M$ _" U; l8 `8 U0 Y6 BIn fact, after the call to CreateFileA it will get through VWIN32 0x001F2 O# M I) q7 p4 V6 E/ b
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function) i( f! x% a4 d3 c
and then browse the DDB list until it find the VxD and its DDB_Control_Proc! a( j0 ]' W1 l. K7 x2 b
field.$ E$ M1 m' G, h
In fact, its purpose is not to load/unload VxDs but only to send a : H: ~# X) j; S8 Y% ?
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
" d% r1 K& P1 j+ z$ rto the VxD Control_Dispatch proc (how the hell a shareware soft could try
1 S4 b7 j* |% k0 o; G% vto load/unload a non-dynamically loadable driver such as SoftICE ;-).
4 [! v0 r2 A3 c3 z& j7 e: tIf the VxD is loaded, it will always clear eax and the Carry flag to allow
3 ?! o# g# v5 p4 x0 d6 _' s8 ^its handle to be opened and then, will be detected.
7 G# Y; l& M/ N% Q: SYou can check that simply by hooking Winice.exe control proc entry point
; ]0 v1 C6 r# X4 j0 y0 Lwhile running MeltICE.7 @! G2 x( s8 N8 y5 g4 n; s0 z
: U! |. {3 [ I6 U8 Y* h* a# x( S5 b, x& o" R
00401067: push 00402025 ; \\.\SICE! w& b4 q4 g# x
0040106C: call CreateFileA* w# a4 |- s7 l |. l
00401071: cmp eax,-001
3 n/ U$ b' W- d% q 00401074: je 004010918 z( J. o8 V; S" H5 E0 [% j) C
: E, n4 Q0 [' \$ `
' Y" x/ J9 m% Z& F& x$ aThere could be hundreds of BPX you could use to detect this trick.8 f* e: y2 ]( ]9 q, Y9 B% n: J
-The most classical one is:
* y! w( p! x& R# C/ r* A+ A* l BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||% f5 F( [9 u. f9 u' S) \
*(esp->4+4)=='NTIC'
4 Q9 l+ X* q0 s0 t1 K( P
6 O( X: [$ R+ }2 v. M* j-The most exotic ones (could be very slooooow :-(" C$ r0 u& R) ?6 G' G3 F* W
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 1 `4 o) X/ H/ t& o T
;will break 3 times :-(
) o8 Z7 k0 ?: H# W, p
2 h0 b5 j# t3 c. T# I+ u2 j4 s-or (a bit) faster:
. H" R. _( L2 d- w1 B' a$ x BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
4 P# i a5 l/ y; N7 Z- X) W* t7 C- K5 l* o2 H1 U7 z
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
# m l- t) p) {! w ;will break 3 times :-(
4 }/ w- S! a& c( A9 ^: t% L& P& Z0 V# h. U; {
-Much faster:1 t" R' v% I, I6 w
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
7 H3 [8 J4 P$ ?$ X$ _: }
) _" i" D; p. W k# xNote also that some programs (like AZPR3.00) use de old 16-bit _lopen$ k, N0 v8 C. _5 E
function to do the same job:) _$ J. }6 S7 `# k1 S
9 S" l" }; ^* c+ o* X: l
push 00 ; OF_READ1 K# ?! Z* E/ R# D& c U3 g5 S( F
mov eax,[00656634] ; '\\.\SICE',0
/ H! f' z8 q. v2 e push eax
; ~; A( P1 T6 X$ _# J6 I call KERNEL32!_lopen
9 z1 O/ T R& t& X# ?% ] inc eax
0 D8 L$ a( @2 z+ z1 h jnz 00650589 ; detected
. v% k2 c( P* x# N push 00 ; OF_READ
+ f; J8 D! [" f' j2 D mov eax,[00656638] ; '\\.\SICE'7 _! p. K; H5 E- {2 l( H: [
push eax
# S+ j8 B) G3 l/ J- U call KERNEL32!_lopen
. Q f2 Y. c9 k) F8 B3 J inc eax
2 d: D. E7 t1 i" X6 R2 N/ M8 ? jz 006505ae ; not detected
3 x- H& L; p9 Z
3 f' W' S6 t/ V' k% I) y; o9 L: z* B% Z7 E
__________________________________________________________________________
i8 |1 g" g$ S0 ?8 k3 o6 O: E+ B
Method 12
0 ?8 E! A6 w+ n9 a7 P=========
; v) C* g8 a7 D
3 g- R' C9 m' Z8 N9 q; nThis trick is similar to int41h/4fh Debugger installation check (code 058 x ~ r. T1 |! r3 H
& 06) but very limited because it's only available for Win95/98 (not NT)) G- p* C" P8 @6 E
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.! X# @& \- A; r% Q K7 a+ ~
6 v5 ?1 g3 e5 S% m push 0000004fh ; function 4fh/ L" d1 _9 h' [4 e% U: _
push 002a002ah ; high word specifies which VxD (VWIN32)
. b; H) V$ [( ~) y ; low word specifies which service
M2 e, r: O7 O, Y (VWIN32_Int41Dispatch)
) ~" ], r2 I5 R3 i4 I call Kernel32!ORD_001 ; VxdCall
! @. V: o( s0 p cmp ax, 0f386h ; magic number returned by system debuggers
" K/ w `: P8 H9 | jz SoftICE_detected
" Y% o# B# x- P- E- L2 C1 Y6 e, v# i- L. W) Q! a, M5 `8 U
Here again, several ways to detect it:# k: c; G& v J0 H
5 r9 l6 c/ m2 q; a BPINT 41 if ax==4f
[9 ^) I2 m/ W- i! }' I& `1 P8 q4 y, W1 [! p
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one5 }$ x, m7 Q# h) W
, f. {1 C9 S% t# S* e, z& r* x# _
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
; [8 P H3 B5 F- j
; k( Y2 l3 n1 e BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!; E; }+ a; H$ m) N9 y
* l9 H+ G/ N, U. B$ Y0 h__________________________________________________________________________
' w `% H4 K! A% n8 I- I
; C- X& Y9 B" |Method 13
' S2 ]4 E, [& c( |) ]9 _=========
5 f+ G9 n! k2 R( ^& |7 u
3 n& W' Y8 m0 u, g0 iNot a real method of detection, but a good way to know if SoftICE is
- D& ^. M' N3 R: g+ t. c, G1 U Uinstalled on a computer and to locate its installation directory.
. f9 ~& W3 m$ s3 U: X( P7 NIt is used by few softs which access the following registry keys (usually #2) :
' f2 p" g9 B2 }/ w
0 X6 \7 |' ? g' ` K-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
( d4 r; L2 l6 @\Uninstall\SoftICE
8 ^4 u( h+ y6 z( y! S, Y; w G-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
5 ?0 Z( n& O: H# B7 {% V% L& H4 ]# ^" g-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 C% p% W9 a$ P
\App Paths\Loader32.Exe
" R. h3 s2 |# v; g4 K
3 P, ^( Z$ A z# y! @% D8 n- X
. f& n6 U& L' A' e: o! {( ], ENote that some nasty apps could then erase all files from SoftICE directory
9 y) u% T( p A$ @( F& @5 i' c(I faced that once :-(2 ^4 V4 g! A$ ?7 u0 X7 A; I
# R! N: a; r8 ?Useful breakpoint to detect it:9 {7 V! L. ~# k4 P
" ] q ?( L% i- ?! y) q
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'# a4 a# ^/ Z, |" G, C
* [, _/ _ u! y; o) N9 T
__________________________________________________________________________
2 o- [ Y& w9 }: ?, j. l4 o, d$ I- k, l
7 q8 T W; w: P1 c: m$ B9 SMethod 14 . ` J1 Z7 b0 m8 k9 S6 S7 o
=========" \" I9 D$ D/ z4 A" ^4 x8 L
) d& v0 B6 R0 w! D
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
1 T+ ?0 |7 a1 n, _, ~! s0 ^is to determines whether a debugger is running on your system (ring0 only).( g/ H2 L! L* R
- y+ f% h4 G# `$ K VMMCall Test_Debug_Installed# n3 C/ V& x1 N4 M4 m
je not_installed6 D4 } `$ V# @" o4 G1 q2 _
: a0 @% ^3 i" d3 ~, m% s2 r
This service just checks a flag.) g) _/ M0 `3 _
</PRE></TD></TR></TBODY></TABLE> |