<TABLE width=500>% ?: F4 \& M- ^2 q3 {
<TBODY>- R9 R1 ]' T/ T% o: \
<TR>
& t& b7 t1 `; k* g' C<TD><PRE>Method 01 + _2 K' `3 u0 N6 z; n
=========) e, y X: V6 X
5 a: v( e% N: ] ^
This method of detection of SoftICE (as well as the following one) is7 h) E2 {, {/ k! Y8 Q: B( a
used by the majority of packers/encryptors found on Internet.; b- P& W# l9 G
It seeks the signature of BoundsChecker in SoftICE
5 J1 K9 E/ H- o, |, i
2 |+ l+ [8 ?: L+ B mov ebp, 04243484Bh ; 'BCHK') d/ v6 b# M6 e- s9 G0 Y
mov ax, 04h
' R4 Q* y6 A$ v' Q3 T3 U! S int 3
# E4 ^2 P8 B' F cmp al,4
3 ~6 A6 M# t! |5 V5 q jnz SoftICE_Detected7 @+ N2 b' q8 f* Q$ X
2 |* E, ?) P" ]- W) f. B___________________________________________________________________________
( j' G: l& f7 k3 I2 U8 I2 L, t3 N- U6 M5 D0 v7 ?& S6 C% _
Method 02' t* a6 |: z4 z% S% N. s) H+ c
=========
9 c- Z3 F0 W8 g4 i/ D M H: o# U: S
( |* I4 ~" U( [, k8 MStill a method very much used (perhaps the most frequent one). It is used2 c4 T5 X( ~: W9 c
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,; Y* ]5 L) i% j/ r- m9 R$ R) Z* v8 b
or execute SoftICE commands..." Y9 s# O, N: y2 A5 K0 C. {) b% C/ T2 j
It is also used to crash SoftICE and to force it to execute any commands
- a9 u6 ]) ?3 Y a7 Q& ](HBOOT...) :-(( ( y0 \# f8 [9 i6 ]
! B) t( X' f- }; ]; a FHere is a quick description:
8 K" N! B8 X) q' Q( _# Y0 N' W- t-AX = 0910h (Display string in SIce windows)7 ?2 u" k% n* J- l* B
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
1 B5 U* }! L) {) q$ w: f-AX = 0912h (Get breakpoint infos)( y7 M4 x) H" b* `, K+ w( e7 |
-AX = 0913h (Set Sice breakpoints)8 I" q5 g% F) l; u+ d$ K9 j8 [
-AX = 0914h (Remove SIce breakoints)
4 X/ ^- N8 I9 n# _
4 h, g3 P/ N1 {, T: i* f* U& N6 FEach time you'll meet this trick, you'll see:
. c* j% S/ f! q- @7 M-SI = 4647h
* y7 d, c5 T' [9 B' Z1 j2 T. }-DI = 4A4Dh, m. g, |; s; W7 P! Y1 k
Which are the 'magic values' used by SoftIce.5 [- `* a% U' f r. x& f6 o% V
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
5 Q- H n) {( b; o8 ^" K# M7 Y4 d
/ e& Z# b* W0 ^% r0 U- cHere is one example from the file "Haspinst.exe" which is the dongle HASP3 N5 r/ F$ E, j! n! d% _
Envelope utility use to protect DOS applications:
/ V& n5 \6 J& J, S8 O
- O3 E. M) n3 A8 k
# n" L Q1 k( c- H" g9 J9 g4C19:0095 MOV AX,0911 ; execute command.& C1 \8 y, X4 b0 g4 X
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
% b: t0 I* w. |( a$ ~0 b7 N4C19:009A MOV SI,4647 ; 1st magic value.
. x/ c6 q& _+ b. q4C19:009D MOV DI,4A4D ; 2nd magic value.0 p! M: ^7 Q: m( T& }2 s1 O
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
) B% p" X! C" g5 C C9 R4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
: H5 Z/ b( l5 q E4C19:00A4 INC CX
3 c: o. S0 m9 [4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
! A v P1 E3 X# ^4 B4C19:00A8 JB 0095 ; 6 different commands.4 A$ a. Y9 N7 M6 p% s
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
3 _' m7 L: l& C# ^3 o/ u3 [4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
9 g, i& l" b* s0 @9 @& x3 L9 y- O' g ^3 T, w" {
The program will execute 6 different SIce commands located at ds:dx, which
8 J6 m5 a& I4 P: q* {% {" Care: LDT, IDT, GDT, TSS, RS, and ...HBOOT.5 E7 X' J6 T( o
1 X" ~- T8 h* e* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
- A z: F7 z+ Q5 i___________________________________________________________________________
. r# X5 u. U" N) D# u
- W; ?! [/ _" N6 F# F" T8 D( N% G: R. R5 V
Method 03 ~5 ?/ Q2 ?+ H _7 _# z: L, ~
=========
1 k3 t$ v& o% i2 S& D& |
3 S {" W; a4 w2 l# H6 C0 T/ v% K0 wLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
2 _. b% Q$ \7 D2 [* }( `! A' ^(API Get entry point)
* O- c* z! {3 e9 x
. B. Q+ ~$ h: g' K
: z7 L7 n- k) d, @( S# A" w$ j! r xor di,di
$ U' R- s7 P9 s/ h/ F- u4 K mov es,di% j7 p4 V. x! h1 \9 o
mov ax, 1684h ) K1 s) \& N7 R0 z9 l
mov bx, 0202h ; VxD ID of winice8 S$ F( w: u; s$ ?9 W
int 2Fh
, ]" ]( @5 n% R$ ` mov ax, es ; ES:DI -> VxD API entry point$ x1 J' _, q: |
add ax, di% ]# v" t4 A1 Q$ a" L
test ax,ax9 s6 m, D/ c0 f2 l( R: z
jnz SoftICE_Detected
( C/ Z* w4 @) j/ \# z" [! ^* B! n
- p! Y, C, @0 t, k! g___________________________________________________________________________
6 v& B) B' ]- I% E, t
, e# y* D0 Y% i3 kMethod 04. ?, }3 G3 q1 t2 W
=========) g. g9 s" z. f
5 t5 o5 G3 ], V& X
Method identical to the preceding one except that it seeks the ID of SoftICE
, n9 M' D x' _9 LGFX VxD.
O: x; s! f1 S1 T& a$ f6 d9 G- }# n7 h/ l
xor di,di
* z I. s, w9 t+ O mov es,di
( d. z9 @5 Z! P0 X# v4 Y mov ax, 1684h
~, F+ J4 J$ C5 j mov bx, 7a5Fh ; VxD ID of SIWVID$ L; K) d k7 G8 g% F7 I0 u1 w; e- Q
int 2fh) F* x: j% I& I; h
mov ax, es ; ES:DI -> VxD API entry point
. Z4 E: \- E) d% E add ax, di
2 ]. B0 M$ Y& J g6 s# Y' K4 k& v0 x test ax,ax5 e, |8 k* ^; q+ Y
jnz SoftICE_Detected: V5 N$ ^* Y+ b$ i
7 x& ?6 r9 o, y: M
__________________________________________________________________________! Z; L" F$ F$ Y, _3 D+ ?
( w- i5 \2 |8 d ]
$ i! _8 d" B4 Z$ m6 ^- B& j/ nMethod 056 A6 B/ s: ~/ [3 B# _3 y: H1 T' e
=========
5 K% ]4 a6 }, D% M
+ ~+ _4 w- T! O# t, g! sMethod seeking the 'magic number' 0F386h returned (in ax) by all system
- I( |9 \/ Q4 d G9 Ndebugger. It calls the int 41h, function 4Fh.- H3 V+ y% l8 c5 u U& |: r% K
There are several alternatives. ) U5 r% ?5 F& a2 v
, H8 R: C/ X& u$ }" |* H$ G- N
The following one is the simplest:# [$ r5 x: K6 w! e
$ v, c8 e+ U% Y5 |
mov ax,4fh" [5 _# [9 c$ ^$ A& w
int 41h8 _3 V# y+ @6 B
cmp ax, 0F386
9 k8 M/ u. o. E$ }6 z8 J$ j6 G jz SoftICE_detected
% K; Q4 P5 ^: Y L. j1 q% C0 ~- w. d
! h5 {0 i; r* G% A. Z7 eNext method as well as the following one are 2 examples from Stone's 8 g, F V- M; m/ @
"stn-wid.zip" (www.cracking.net):
; L5 {- r& `2 r* b" A" K. S& J& r8 X, p! l. _* j! i
mov bx, cs
5 p; J0 g$ z) u6 j' O3 I lea dx, int41handler2
" y" [! ~& u4 g& H2 e) w xchg dx, es:[41h*4]
0 M+ @: m0 K5 G; E7 x xchg bx, es:[41h*4+2]
- a6 x w" T5 U- Q4 z0 J8 ` mov ax,4fh7 r% K+ @2 O, @7 b8 X& ]
int 41h: P% ^0 h$ f8 h& D/ g
xchg dx, es:[41h*4]
) k5 V: |( z' O1 H xchg bx, es:[41h*4+2]
% i; `& R+ d* ]& j0 R, N7 C cmp ax, 0f386h- t& K8 U# ?6 _. e, [) f
jz SoftICE_detected
: O1 X0 R7 V7 N4 {* d0 J& }) n( T# Q( L% c
int41handler2 PROC j# r9 @" n" `" T/ b# r
iret2 Q: Z( `, q1 C5 ]1 z
int41handler2 ENDP+ p1 }7 w$ z+ W% i- b
" h) _$ W. a- P/ ?
, b7 {6 r/ J# n6 ]8 x: x( |9 m_________________________________________________________________________$ E# V; ~3 a5 T( ~( `1 K6 O$ N
" s7 F6 a" u+ m
; j( w6 `$ N* b- B, y T0 }5 rMethod 06
$ C+ N/ n; ?7 z F=========
" g0 A; ?: u! Z! L, z3 E: f* z" B' G) t
7 p6 Y( M5 c. R* n2 t7 w2nd method similar to the preceding one but more difficult to detect:, [2 y. ]+ D6 y1 u. } I H; J
/ t8 T5 `/ p* \) n# D# I
+ {* ~ O X! ?& o
int41handler PROC
9 v. M* z( O& I" X# [3 d mov cl,al
6 X# N# y) ` L7 Z+ M0 @ iret
5 C1 W/ a+ ^# O7 b& c( N2 a9 qint41handler ENDP
" Y0 O7 s4 V' @* Z) E7 f
( s6 b$ \0 u7 V+ g; b7 p( C$ F0 n3 r* L' T% A; m6 f3 d
xor ax,ax6 B0 N5 q( E: |8 m X2 \
mov es,ax9 K* G6 u8 z* W A* W2 Z4 V# L3 `
mov bx, cs' {6 V' ?- M' j3 d
lea dx, int41handler5 x) V/ ?+ m0 o8 {
xchg dx, es:[41h*4]
; C6 ^$ C3 S. [ xchg bx, es:[41h*4+2]
. _2 B$ l% c& X in al, 40h$ z7 I8 ?% p2 z3 q. _ \- c
xor cx,cx$ V0 D- m3 S' V2 K
int 41h
- Y% L) O4 z- m; }; ]& j5 k xchg dx, es:[41h*4]
3 l! k: s1 {0 j- \ xchg bx, es:[41h*4+2]
# t% t+ n8 @; |0 p cmp cl,al! F P3 a" }" v1 S8 S/ r" C
jnz SoftICE_detected
- p2 f4 r( X6 W" U( W1 F
3 l* D9 c/ C8 P0 j+ w6 P, A8 |+ q1 w_________________________________________________________________________: Y' |1 h8 U) W! m
' W6 e2 F* j8 u$ ~$ x1 _5 @, N Y. |
Method 07+ L6 m% Y% S) x) L# D5 |) t
=========
$ M8 t8 Z& U* y5 s8 ?- M
7 F Z0 K( ]7 ]& s7 RMethod of detection of the WinICE handler in the int68h (V86)
8 e4 }$ e7 j" D. }* x$ C
% I: A# S E' \9 [+ v/ z8 [ mov ah,43h: _7 j+ G9 P, A9 L
int 68h
5 t. s# g: m; P- ^& k cmp ax,0F386h0 q7 b% B* {$ M& i* c
jz SoftICE_Detected' J F; D( ^; B0 v2 X. o( W& J
, d8 W6 ^8 F( C, g7 ]
& x4 W, r! ~+ Q9 l! X: O5 ~
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
2 Y+ p, Y+ ^- C app like this:
8 n1 l$ I( m' U4 E" F) f4 f/ h
BPX exec_int if ax==68
& k8 X# ?$ \: M/ e- @7 M (function called is located at byte ptr [ebp+1Dh] and client eip is9 e3 k" N) w. i
located at [ebp+48h] for 32Bit apps)- F: {9 Z( ^3 h
__________________________________________________________________________
7 ~' A; @! H+ @ ?3 B0 F9 p. n3 r1 ? j2 ]
% \- l! Z. Q4 I$ DMethod 088 R- c) d9 n3 {6 h
=========9 X$ a8 B/ Z* X% F: d0 \) A7 k
8 {; ^9 {+ ~4 |% F F2 C6 Z1 D/ C* H6 DIt is not a method of detection of SoftICE but a possibility to crash the
) j& l9 [2 ^; ^7 `) ?5 K# i4 dsystem by intercepting int 01h and int 03h and redirecting them to another
# \: }/ o a' d4 P4 ]( j* Jroutine.% b* d9 d+ _) j
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
, C5 J1 W7 X# _- w Y! f9 gto the new routine to execute (hangs computer...)
; }1 G- @6 w0 v `9 D/ W" v" g" i# D- L, ], x* Q0 H" S! T: }
mov ah, 25h% I' }3 c, E$ x7 Y
mov al, Int_Number (01h or 03h)( W/ g2 J0 D# G6 [* o4 ~- r6 J
mov dx, offset New_Int_Routine
+ \" z8 [! R% p/ \: d int 21h& G% k" g* J& b. M9 {/ K: d
9 B- B4 H7 C6 ^% s+ i- |% d__________________________________________________________________________
, U: U' A6 L# i4 }2 J# t! N4 D1 L O5 ]
Method 09- \4 B# |$ p6 ]2 f9 U6 V% U
=========$ n! m; ]" c7 A v n9 f
+ E/ j& x0 x; A) |' ?2 J% }$ B. y& j3 J
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only U$ W6 b' m) K% E- l# b
performed in ring0 (VxD or a ring3 app using the VxdCall).% l" m8 C% m. z
The Get_DDB service is used to determine whether or not a VxD is installed
7 }) e, a: R" F" r7 g& d2 `for the specified device and returns a Device Description Block (in ecx) for
0 u1 `* O- `7 ]$ vthat device if it is installed.6 }! Z4 d6 F' h+ {% O1 V2 @5 B1 X
. S& ~0 g4 P0 i* } I$ Y$ q mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
1 {( B9 x* U1 q2 i" E; F mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)# `7 s( u3 S' W
VMMCall Get_DDB
- k) S; D& U: H/ t3 G! [ mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed% z6 `6 s( V5 E" K) p- w
- x4 `3 V. N$ r# B! W* E8 S# RNote as well that you can easily detect this method with SoftICE:' o' w0 e e! d# V
bpx Get_DDB if ax==0202 || ax==7a5fh
8 z4 u5 w' ~" n7 r4 ?6 f6 ^( B0 ?+ ^9 O4 B- E
__________________________________________________________________________
! I' U8 y+ I A& P$ V( e, c% X
8 n- q, d7 u- `4 h* rMethod 10
5 v( w7 |! G& ^7 ]7 u% R1 ]=========
; p! J* V6 U5 `# j: \
) {) o9 M2 H C, b l2 V- b=>Disable or clear breakpoints before using this feature. DO NOT trace with
, f/ d$ q9 m [* m: w* x9 F* _ SoftICE while the option is enable!!9 S6 _1 @- \( |7 [8 B0 b9 P& l0 L
0 q$ [4 o4 i1 ?& r" L+ r' j0 ?" r4 C
This trick is very efficient:3 K @0 @" Y3 g4 A" \ z' L0 L) T
by checking the Debug Registers, you can detect if SoftICE is loaded( O1 P: B( ~2 m N
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if5 I+ U4 q8 l1 a- m8 l& m
there are some memory breakpoints set (dr0 to dr3) simply by reading their( X5 w" d3 ]9 Z# X+ a- y1 O6 j
value (in ring0 only). Values can be manipulated and or changed as well
3 U: i9 |4 b6 h+ S3 Q u3 R(clearing BPMs for instance)5 o1 U; D* A% |$ B+ I1 F# D
3 A+ B; }/ t, s, B
__________________________________________________________________________
, l! Z; }2 X, m* [: {9 x+ F) ~' J+ f
, N9 |' U! p: C2 q6 Y1 p/ EMethod 11% y: @8 v& y! K9 | Z0 X3 {- y9 u
=========
0 t) j! r3 R- s: {: ?% u Y6 C9 L3 @$ w/ z5 {2 ?) j6 I7 N. B
This method is most known as 'MeltICE' because it has been freely distributed
2 t0 v( F" e! tvia www.winfiles.com. However it was first used by NuMega people to allow# i) j {' P3 J" X- n# b9 L6 ~
Symbol Loader to check if SoftICE was active or not (the code is located9 ?3 v( f+ H7 E7 P2 R, Y1 i! M
inside nmtrans.dll).' w4 z- w2 n+ }7 I8 e0 X$ Z" t6 l
* R+ Y! f3 B% j0 x
The way it works is very simple:
: _$ I; W. a" }% GIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for4 B( k' Q7 X, I: k# q+ B
WinNT) with the CreateFileA API.
1 r( D7 i' D X6 m2 ?7 [9 ?
! f/ k8 `* x0 i8 WHere is a sample (checking for 'SICE'):
3 I q2 V( A, [# b. T% r! y
, ]: t% `- L+ hBOOL IsSoftIce95Loaded()
; z/ S$ S( T6 W! U5 }' z{
1 c5 w9 ~& ]; ]7 S5 I HANDLE hFile; $ {2 Z* _, x1 q5 [5 b7 b. [( H: u9 x- x
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
2 n. E: H! \; N7 [) T9 Y! B FILE_SHARE_READ | FILE_SHARE_WRITE,
( n- l9 w0 j( `0 G1 A; M6 W NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);5 |* W" @# m! ~ | K- Z% R6 y5 Q
if( hFile != INVALID_HANDLE_VALUE )! }$ a* I+ `0 e+ P6 q9 Z
{
4 N2 E) R4 T; p3 A5 o+ k CloseHandle(hFile);
' j7 _. s7 K5 }) y- S! D5 N return TRUE;$ ~; A. p3 t" m' S: a* i
}0 m" ]7 x% l! N" Q3 d) W
return FALSE;2 P& W$ \$ {1 ^$ d; B( q+ f' h( I
}
1 G' r: o8 E, t8 D+ v3 W. f
5 G+ U: B2 c C* u6 a% e6 KAlthough this trick calls the CreateFileA function, don't even expect to be
; u, h% H! Y+ N. B( Q O7 H7 Qable to intercept it by installing a IFS hook: it will not work, no way!
" ?+ ~9 A2 ?' h4 w- B5 pIn fact, after the call to CreateFileA it will get through VWIN32 0x001F3 H2 M7 u& `& U
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
+ C) Q* \1 d% I$ d' Qand then browse the DDB list until it find the VxD and its DDB_Control_Proc
; s. U6 f9 S- w afield.3 U- q6 N0 p: D5 ]7 g
In fact, its purpose is not to load/unload VxDs but only to send a
7 M) `# C4 h. t! A- \3 TW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
" v [3 A l6 m( e ^2 sto the VxD Control_Dispatch proc (how the hell a shareware soft could try
1 m1 p" l8 |6 x* D% r9 x4 l7 a% Q6 B5 Nto load/unload a non-dynamically loadable driver such as SoftICE ;-).
{; N8 E' @* e' g7 K) EIf the VxD is loaded, it will always clear eax and the Carry flag to allow
' W' p! G K* v. s" s5 Lits handle to be opened and then, will be detected.
" t) H; D5 V' {) G0 @You can check that simply by hooking Winice.exe control proc entry point, z5 v- L- e& G+ p2 K% J/ O
while running MeltICE.
: p6 i6 |# e& d
) j& d7 D% m, U! _$ x/ \4 A- r+ ?- m: c+ f* G4 S- p
00401067: push 00402025 ; \\.\SICE; ^6 t( i7 u0 O2 W. ~ _+ r
0040106C: call CreateFileA. k) ^! p8 T# j$ z
00401071: cmp eax,-001
- a# L N. v6 a 00401074: je 004010913 s( o; M. ~/ s2 H; U* S, F
. f# P- n- @5 E$ u. U
6 F* }3 w1 c3 @# c( B }& c! e; XThere could be hundreds of BPX you could use to detect this trick.3 _$ y0 S; a* q) {4 b' j
-The most classical one is:) h" ^/ e+ r& Z* X' d
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||6 r9 \% k, A% r0 C" P6 q- v4 S
*(esp->4+4)=='NTIC'; x# J$ s% h2 i) o( u
# x$ v1 B; o2 j f# A
-The most exotic ones (could be very slooooow :-(/ {0 J) \5 ~0 S5 I
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 1 p6 |! }( i% d- k6 S
;will break 3 times :-( g& \, \3 o( I; {, `
; U& G$ T( B- {# g$ Z
-or (a bit) faster:
5 X6 N# W" n9 W' I* J BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
1 i% s5 t9 q- s! e j5 N/ @, F, _8 G) l- g0 S
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
) R+ g% }7 J) x4 d. n* K1 S ;will break 3 times :-(8 ?. r2 B$ X& H: H8 z+ W
: s1 [/ y: P1 u+ [" n; h-Much faster:1 o( }# t* f/ x2 t* R+ N+ c8 d6 {
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'6 l- |. h- p: A( w& P7 U" J9 s/ D
% t A% z/ l2 [8 A# }" |
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen# a( }3 R+ ^$ }. B
function to do the same job:4 j8 Y. h7 r3 [" m- Q p, }# n" I
Z x1 Z+ z. E9 c4 w9 T/ M$ |* D
push 00 ; OF_READ
# m6 d% j- Q- X; |3 M6 ` mov eax,[00656634] ; '\\.\SICE',0
# e. y' H8 j: R$ M push eax* h/ ~! q* T, ?! d! `
call KERNEL32!_lopen
6 [$ L4 r/ |' A3 f& M inc eax
; f0 O4 R& V( w/ u jnz 00650589 ; detected
! Q" ]- e* b3 t push 00 ; OF_READ
3 c; T; w' F7 @ mov eax,[00656638] ; '\\.\SICE'
/ X" m0 Z' B& F& S push eax! O$ t9 k) g4 e; L" H4 x& n
call KERNEL32!_lopen
3 l( j8 D8 a- Z2 ~5 d# `1 \3 b inc eax- G; @9 P" O4 M* e3 x$ ~" w, ~6 L3 J8 h
jz 006505ae ; not detected
8 I. E- t% s F8 O! F
~: P6 T$ ]; ~8 j8 N; G
1 e- A8 p% N' H- j- {__________________________________________________________________________
: \ d* v- P6 K2 ?
( l# b. D8 S3 IMethod 12
6 {- h& w( L! q: H- N========= \. `8 e) e& Y7 I8 f
2 p( N ]( \9 L3 Y4 o4 p5 Z+ R8 ~This trick is similar to int41h/4fh Debugger installation check (code 05. K! G0 E# k- |1 A( [( u. W
& 06) but very limited because it's only available for Win95/98 (not NT)
! U8 w% N, |% |6 Zas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
& m* S6 X0 d- W) i3 G: O1 |: s
8 O4 D1 m. |7 {1 ~, v push 0000004fh ; function 4fh
; e4 i5 P3 ]# K/ E* e push 002a002ah ; high word specifies which VxD (VWIN32)
8 U7 \+ y i4 f; w* H ; low word specifies which service
( S9 R x! Z) |8 x (VWIN32_Int41Dispatch)1 ~( Q' F# F, w6 S) h0 M
call Kernel32!ORD_001 ; VxdCall ~( Y4 F$ O) z8 s$ Q, L0 j+ W. v
cmp ax, 0f386h ; magic number returned by system debuggers
" h: k& l0 j0 a" F" P$ B jz SoftICE_detected
! N5 q( z' |: K" l6 `4 Q$ N5 @5 L
+ r7 ?8 v, D3 u% M* }9 MHere again, several ways to detect it:
, Y f9 }- K" e6 ^! N7 E% }3 h1 ?8 O. Y
BPINT 41 if ax==4f- X% ?. i0 i9 E# \5 G" M
1 u3 W+ I) D0 h! J3 _& e
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one- |+ F( Z' R5 o# O
; X+ J" n ?! @0 e BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
! T' k1 E$ ~: Q' }8 c6 ~+ ~7 K9 w7 ^; |
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!, Z8 C1 M8 K. ^" ^1 d: e e& Z0 ]( Q
/ }! G+ b7 M1 X__________________________________________________________________________
) k2 o. A, C$ ?# k7 B5 W+ \
$ j, Y2 ]+ O# M# rMethod 135 h. F5 R/ g+ C+ Z1 ~( D V
=========& j; f( y! e( M+ k5 H& b9 R" ?
( I7 I+ c6 h! _. bNot a real method of detection, but a good way to know if SoftICE is1 e% a( s/ Z& X! |) Q6 f! q! E
installed on a computer and to locate its installation directory.$ _5 T+ d2 r* |
It is used by few softs which access the following registry keys (usually #2) :2 y6 n$ O Y/ o+ }0 }2 a
+ p, e, G7 [" J: w-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& `/ ^5 I9 c' s: o+ g% A8 o* p: t
\Uninstall\SoftICE. J2 x. I3 G' L- E0 n$ Q1 D
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE+ r% ]% ?/ J# L' }- R6 m( K
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion, {; ?1 x6 ]3 e6 m+ `& ~
\App Paths\Loader32.Exe
. d& r) y7 I3 S+ h2 ~' [; W. ]2 s$ ]: m' C6 R: A; e
) b3 C+ A8 u, |Note that some nasty apps could then erase all files from SoftICE directory( P. S: A" w8 g4 T% R( S8 X9 ^
(I faced that once :-(* t6 }0 |0 F2 m5 m a
4 s1 i7 S0 w3 a/ hUseful breakpoint to detect it:4 N+ z- h( u" m9 g$ ]
3 m$ c* s9 m! r3 C1 m. ^4 H& w
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
6 P% W6 O8 _( N$ n% g) D/ M( Q' X1 n( l2 [; P3 G7 J+ p
__________________________________________________________________________% C( _0 H' X+ C: ]' g' p
0 g/ z s* C* ?4 I
6 y( e/ e1 P) h' G5 |Method 14 " n# b' N! O6 I9 D1 @
=========9 l" E1 M& z' J/ N, l/ V0 k4 h* N
% c8 W1 _0 [2 p4 J/ ~
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose- M( ]. t0 r5 i4 B/ W+ t! p+ q
is to determines whether a debugger is running on your system (ring0 only).8 ^7 z1 T- J6 H0 {# b
1 Y0 `4 i5 u9 w" c, I VMMCall Test_Debug_Installed8 C, P6 L- B9 b' }* D/ N
je not_installed
+ J$ q: G; k9 p' }7 b
& B$ S* t w( SThis service just checks a flag.- N; v% q3 C, f" C7 j \6 R0 C
</PRE></TD></TR></TBODY></TABLE> |