<TABLE width=500>1 f3 _" f! b3 }6 V
<TBODY>
9 w: {- M/ l$ t# l# _5 {! U# \<TR>; a' o/ z0 ^6 b- j, p
<TD><PRE>Method 01 $ f" r" `8 E$ J- T7 q" m2 \ L
=========( l! T) A9 b* q" o
+ p5 Y" D% m7 F/ y0 a
This method of detection of SoftICE (as well as the following one) is- T: _, s$ I8 _: J# w; P% ]
used by the majority of packers/encryptors found on Internet.
) e/ @$ q) [. m3 z6 Z$ W6 d% ?2 QIt seeks the signature of BoundsChecker in SoftICE ~ t/ V% z% ?) R: S
, G0 f W" ? \6 s mov ebp, 04243484Bh ; 'BCHK'0 Y3 Z+ R8 M3 J! r/ J5 H
mov ax, 04h" S5 ?( Z' a+ s
int 3 + _3 H/ I$ `" f! c1 @
cmp al,4
% B# g& ?, ]. g, i7 m" h. D" @; E jnz SoftICE_Detected5 B$ A0 @7 X; {* H* }1 m& @
$ o( x+ V& O8 h# s' \___________________________________________________________________________
; A. {- I( S5 Z k1 p( ~3 ?9 }3 K& }: \$ }2 k6 L: r
Method 021 P% T* y7 Y7 y
=========
! F2 w5 m! ?0 F% y0 A. q% Y. W8 F& c( K4 L
Still a method very much used (perhaps the most frequent one). It is used2 z) K, e8 @1 p
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,# D2 e/ f5 t+ x$ S) L. p D
or execute SoftICE commands...
1 e; Q+ Q" r0 e' L, g8 J$ S3 i4 m8 MIt is also used to crash SoftICE and to force it to execute any commands
9 O& a: O" P. k* `$ S(HBOOT...) :-(( 1 `. S0 C/ \. t/ o* H6 @& P! U; H
5 I' ~7 x- _6 Q% G$ nHere is a quick description:
! O! _& {- Q8 ^! h( k" X3 X4 u-AX = 0910h (Display string in SIce windows)6 y% n9 y+ ~- f4 C
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
) k% e8 [- @. g! ~: K-AX = 0912h (Get breakpoint infos)) _: C( D! Y8 l4 O* X% |
-AX = 0913h (Set Sice breakpoints)
) H; G% `0 T& c-AX = 0914h (Remove SIce breakoints)
1 X& D2 }) [2 @" z, M/ V% ?" r! U' Q$ L% e j; q6 g
Each time you'll meet this trick, you'll see:, v8 s3 c8 v6 h+ H, c* F
-SI = 4647h
, }/ H% ^: {! ?" }, k# U; l-DI = 4A4Dh$ r$ z: y& b6 S# x6 ?, D3 M: w5 c; t
Which are the 'magic values' used by SoftIce.
. s% N6 f# s/ p) oFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.1 O) e% X' W6 n) C
+ H5 J3 M6 ? `! o- i& V0 y' l2 p
Here is one example from the file "Haspinst.exe" which is the dongle HASP! @$ m$ N5 L* I) c E, q" [
Envelope utility use to protect DOS applications:, \2 u) B& P% w1 z
* Z' g ~2 g9 W# L* j3 h1 z$ ]) F4 H
5 D& S: c" _. p2 G, e E; g+ l4C19:0095 MOV AX,0911 ; execute command.
/ ~2 e( y7 @+ q' f0 i1 J4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
, ~# k- S- ^% M4 _# ?+ l" e. @9 m8 m4C19:009A MOV SI,4647 ; 1st magic value.
5 F6 ^+ ^% k0 S% Q1 r- X2 L) g( ?4C19:009D MOV DI,4A4D ; 2nd magic value.7 l% u W4 `/ @( c# n
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
4 ]* i4 {! z) ?4 f! x! g3 u5 T4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute3 O5 O3 [; s2 }; g/ T
4C19:00A4 INC CX
' y, N2 ~/ _+ a) o4C19:00A5 CMP CX,06 ; Repeat 6 times to execute# w0 e1 Q3 m% P X8 o
4C19:00A8 JB 0095 ; 6 different commands.- W9 L d4 S8 F$ f5 ~
4C19:00AA JMP 0002 ; Bad_Guy jmp back.5 {, h: m$ D: e
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
7 `8 Q* r* D1 b' G; c N* U
7 S1 [' ~! I% e) H+ n/ r4 O9 T4 zThe program will execute 6 different SIce commands located at ds:dx, which( G. t3 k# _5 G- M2 n
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
( N* v" Y& u% M$ q1 U0 \
. h' k: D* |3 W7 g" d, ~* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.* D- Y3 O& R; S* Q2 q6 B
___________________________________________________________________________
9 Q& q ~6 Q+ G" i8 n+ c3 J2 ~6 W* \3 g# Z
1 A( k# l# N$ f1 V, E% A/ AMethod 03
' K8 x M2 X! |) [0 `=========6 s0 d/ P. g. h6 S- Z2 Q; k% C
5 q6 D# U3 Z7 {5 f0 l5 a, y' N! n7 ?& zLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h" t/ h# N8 @* x& i. t. x& `5 F
(API Get entry point)
$ S( F5 A/ O2 j( k2 {! P, \, I
4 ^9 D0 K! V- Q i' D4 X; P+ I( C: W3 @5 w. [$ B0 x
xor di,di
/ i4 g8 O" x) {. p6 ?$ Q mov es,di
+ ? I5 L; ~! | mov ax, 1684h # g- u: _% K* \
mov bx, 0202h ; VxD ID of winice2 C2 L4 t& A# U( X: {% D$ ~
int 2Fh9 |2 L6 M% ^8 g7 b; Y8 I
mov ax, es ; ES:DI -> VxD API entry point
' Q+ j! q3 d0 i4 w add ax, di
% r5 Q. G& ^( @' c8 Q5 `' j% _; J test ax,ax0 F( i+ v3 Z2 E7 m; i4 Q! h2 s
jnz SoftICE_Detected
! k/ y7 c* P. L( G% z, d1 ~3 f5 K8 I6 ~
___________________________________________________________________________
3 v; P7 ?- g" O5 V; T% J- S% P1 t K: d; n& g
Method 04
! c( z% ?0 _# }7 _" o2 Y/ g=========5 _3 j/ s2 z# G% ?
4 ?/ Z1 x1 a6 L% g1 g! S" r3 v9 AMethod identical to the preceding one except that it seeks the ID of SoftICE9 I2 K9 j; `- Z, Y' [* V
GFX VxD.
# m: ?3 x0 N3 B$ m8 W$ l- d4 A0 R2 R
xor di,di9 E8 r F$ M- G; Z+ d
mov es,di3 H1 M6 ~+ V& M+ a/ f S
mov ax, 1684h / z( } c5 O( x0 r5 l; \
mov bx, 7a5Fh ; VxD ID of SIWVID1 K5 F b9 E3 L0 g" c: w" i3 r3 X
int 2fh
& f% P5 E$ @- i# f2 z mov ax, es ; ES:DI -> VxD API entry point
: Q. p6 o6 b2 x) ?+ D add ax, di; K/ {7 ?; z0 }7 x* {' a
test ax,ax- [! U" M# D7 n6 i4 ^0 W0 g
jnz SoftICE_Detected
2 q: c$ O. U. U: E, a2 z3 ?- ]+ n
9 L3 p) \% [; c, r, I2 a6 w__________________________________________________________________________
# [3 N) _- a9 M8 U: e" x3 u, P1 n$ l' r" Z4 t! O2 f4 c% R4 z
9 i+ k7 q+ ]1 @& G9 Y. O; C
Method 058 N0 Y! s: |2 L: F9 G
=========$ m( {7 L, D$ X) |
2 h/ f- o S$ y: @Method seeking the 'magic number' 0F386h returned (in ax) by all system
( e: M- {- D1 o+ H% edebugger. It calls the int 41h, function 4Fh.1 \* Z; o8 {% s- _$ G
There are several alternatives. |6 Q% Z2 Y1 B
5 a# m' [: E5 L# }& a
The following one is the simplest:% D, z' H. t. p: Z7 h
0 f2 k+ s- `/ R$ p
mov ax,4fh
$ }1 `* J$ B5 C5 T% ?' x: N int 41h
. {, Q" u$ u% J \4 ^8 N( _ cmp ax, 0F386
0 W; @1 l( U6 z, D( `0 d jz SoftICE_detected
+ p- w. U9 x4 W! s
u, p _) v2 n/ x0 v# G
2 Y* m9 B5 _+ K. U; ?1 C# E" rNext method as well as the following one are 2 examples from Stone's
$ |) O1 X8 r$ v( @& g7 Y"stn-wid.zip" (www.cracking.net):! P( `+ n* e0 m* i- E' O3 F
& Z+ A4 U- Z0 S mov bx, cs
4 L# y" M D, p& c4 g' h2 p lea dx, int41handler2
% E5 r0 d8 D. C xchg dx, es:[41h*4]7 P5 M# b; C" I' M
xchg bx, es:[41h*4+2]/ f# R8 v0 X! ~8 r9 w
mov ax,4fh
# t7 ~! y" t% r8 r) S% } int 41h
/ {2 t. S8 O8 Z7 v: ] xchg dx, es:[41h*4]
1 w% c6 [% f7 x( T/ V! a xchg bx, es:[41h*4+2]
! [, E' r1 X+ k2 e3 ]) ~% a0 S: o cmp ax, 0f386h
p7 \: T, {( }. _, ^3 w1 E jz SoftICE_detected
6 f1 `8 e/ c4 M1 S6 u
$ @# _$ ~- W' n8 [8 O6 Hint41handler2 PROC; {) r: ~% y. A% e" r1 \
iret
; ?) P' h) N# ?# Gint41handler2 ENDP
+ `: r) @( u4 u; ^2 b
% ^7 r; P, M' B0 k% r3 C
# Z" b3 V& m3 t* X! n_________________________________________________________________________
7 `3 u% P( D" N, v, l; i$ E& {% t) @9 d8 f2 o/ F$ Q
! p. v& u; o$ m, VMethod 06
: \ F+ P: Q0 Z; T=========, \) F1 z' C, I* ~& O
! a0 o' h( V( w, S. k, b, o* Q
2 t$ m# @, [' z0 p
2nd method similar to the preceding one but more difficult to detect:
( D; z9 _* P t: g( E7 E4 `8 x8 j4 j0 P' x; R- W6 _+ v4 b
8 L/ A* O4 t8 N+ {" Yint41handler PROC# f( x6 V: {$ Z$ J! b
mov cl,al6 ^- k5 p: r" a
iret! }& S. R% V9 j
int41handler ENDP/ w- P5 ]8 F$ o1 T
' l, [9 r. C; R: m J
1 Q; p% b4 f2 Z/ F xor ax,ax8 a0 H8 c5 e l+ X9 Y
mov es,ax
$ n' g" t5 `5 }( G5 X% x" t mov bx, cs
* W/ O# s, w/ I2 t lea dx, int41handler
6 ?/ n6 F% \( o9 C/ m xchg dx, es:[41h*4]' O! m. Q2 G, ~+ v
xchg bx, es:[41h*4+2]
: U9 c$ h' m0 t4 T4 } in al, 40h% |: y9 j y$ }0 h9 N
xor cx,cx- N3 _5 R# u4 p# d+ v+ [% V& ^4 N
int 41h
, G" M" o* K: |# N, { xchg dx, es:[41h*4]
+ h- X( v' _4 z4 C1 o xchg bx, es:[41h*4+2]
5 l6 f7 E! g) X3 f. K cmp cl,al
+ m) Y6 z" n8 u2 S6 @7 X. i/ r' L% ~4 ? jnz SoftICE_detected% s# y7 O' ^1 K# P
8 {$ d( D! j: F7 g/ f8 F
_________________________________________________________________________
" c2 e9 w" y4 d6 h9 S' _2 z) a! U
Method 077 i( Q( ~8 H! [( |; `2 ~* B( Y
=========
6 ?' ?8 [1 C' G8 ^6 |' e" @# N' K& j$ b) p
Method of detection of the WinICE handler in the int68h (V86)
' G' k) |5 ?: _9 x+ A! i2 k. [! C9 S1 p" n6 N# u0 f# ? {
mov ah,43h9 a$ {- ~3 L- J
int 68h
: f1 A) p6 q4 h( \" i0 }: B9 L cmp ax,0F386h; q) f2 u3 z& i5 V( f) B6 @ u
jz SoftICE_Detected* q1 Z5 d# y, t( Y4 n" [2 m
' n9 c; h: c- T3 ?* B7 H
i* O$ D2 _' a; R7 U; H5 N2 |2 y
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit* L* T$ p# u3 s) h. T8 j
app like this:
: i# m1 V8 t9 d! m# b3 ?2 u: b3 V: a& d5 A! ?$ ]
BPX exec_int if ax==685 U/ B5 z/ F% H/ U- b5 f
(function called is located at byte ptr [ebp+1Dh] and client eip is
, z' k: a0 q$ u! } located at [ebp+48h] for 32Bit apps)+ i4 m1 Q, }, G9 {$ _( {/ {
__________________________________________________________________________! ^. o7 x: U; U5 l" |% H
- I0 y# b x4 A1 d. @5 ?' T4 R D
4 I! u( t: m5 S% v/ cMethod 08: y+ c5 [9 h# ?/ h
=========
. c0 i9 z' h6 i- ^- a, l/ Z9 r4 X [ g1 k K5 X; R
It is not a method of detection of SoftICE but a possibility to crash the
! @2 u, M H" @+ P1 Jsystem by intercepting int 01h and int 03h and redirecting them to another
2 Q- o/ w8 @. [& d% U# d$ J% nroutine. A; @# B) x2 V* n# K K7 @+ L
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points! C! y; n8 \7 C5 L+ s
to the new routine to execute (hangs computer...)7 I$ j8 d) M& e, P) K3 w5 l
+ A4 }! ^) M0 o mov ah, 25h
5 T/ n5 n9 r- F mov al, Int_Number (01h or 03h)4 ~- M: Y# e, v) w
mov dx, offset New_Int_Routine! d. j B+ Q, i l
int 21h
! Y4 Y5 T+ Q: d5 t* N+ n
0 L8 m |- A2 k9 B# N3 }__________________________________________________________________________
) ]8 H O1 ?+ F. R% ~' r$ T9 W$ ?5 X* B$ A' d0 C
Method 09
8 b* Z" \8 i# {) z% U5 l$ l3 a' v=========, q+ y# K" n3 g) K4 O/ ^
- Y- q3 {6 p( o! M3 T7 L0 vThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
6 i, `9 M2 e" `7 ?$ @0 L- Rperformed in ring0 (VxD or a ring3 app using the VxdCall).
& @9 @! O# @4 _7 Q: {$ d1 hThe Get_DDB service is used to determine whether or not a VxD is installed
, H+ d( T. @6 }" cfor the specified device and returns a Device Description Block (in ecx) for
! Y5 |! I0 g4 l, S. sthat device if it is installed.
3 U0 g' B( x: o: {
, D, |: r& F4 ~5 Z1 W mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID7 {* B3 D9 j, d* z
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)* Q( l7 R9 P& D' d" [7 C' ]
VMMCall Get_DDB ]" q2 s# Z7 Y9 G- P W4 c/ ~
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
. E; y( e" H- w
h% t# X+ U7 n, ^Note as well that you can easily detect this method with SoftICE:- @8 I, s. V3 T! F* ~6 e$ u( k
bpx Get_DDB if ax==0202 || ax==7a5fh+ D" k X8 H5 B$ u1 _) N
8 ~5 I: N6 H5 y+ |& m1 y! M" c9 j
__________________________________________________________________________
4 S. s1 H/ i/ a# a8 b( n
) A8 G; V) }/ ?/ E8 h$ lMethod 10& j; p& O+ e: l8 ]
=========
) U) B6 [+ P. R1 o6 s7 K3 S7 g0 z; g$ o( O8 V
=>Disable or clear breakpoints before using this feature. DO NOT trace with. i" ~9 ^7 r9 y' t) ?
SoftICE while the option is enable!!
8 n2 u* G5 x& S% y. r) Q% @2 D+ S; l( f' r2 I% L8 G
This trick is very efficient:' b2 m+ {, G# Q4 u' S% j, n$ }" V
by checking the Debug Registers, you can detect if SoftICE is loaded
9 Y" i8 i6 T# c9 ` c(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
4 S5 `( r* H# ^- @there are some memory breakpoints set (dr0 to dr3) simply by reading their
2 G' u3 `. q9 m3 zvalue (in ring0 only). Values can be manipulated and or changed as well
[# h9 c. e: }; R6 d, J(clearing BPMs for instance): b& d# i _0 S5 z
3 N- @6 W v- b$ M__________________________________________________________________________
( q* f. R/ n$ [- W& n* q
9 f1 J4 J/ s" p' R/ I3 ^Method 11
4 q' g4 R( n) a) S3 r* L1 y=========
1 p( j$ y i6 _6 H9 K
" _# m( v/ h( |( F& R2 m* s$ e4 _9 pThis method is most known as 'MeltICE' because it has been freely distributed
6 u8 l9 i! A4 [! U( \via www.winfiles.com. However it was first used by NuMega people to allow# a a- E7 p; K) Q% w
Symbol Loader to check if SoftICE was active or not (the code is located3 ^2 }% b- `' z i8 G0 a+ P* W; G
inside nmtrans.dll).
0 k7 ~% g/ @1 x6 }7 i: K& U
) J9 g3 B: o7 ]- K# m/ d: kThe way it works is very simple:
0 o+ T4 B) g8 n9 @It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for: y3 t7 P5 O. [
WinNT) with the CreateFileA API.) I( u$ e" y* b `# M- {$ { b* Y
6 l3 g4 p0 d# C O/ w" @
Here is a sample (checking for 'SICE'):
, t5 g& w2 [: i0 e. e; i& {* R: b% q' m7 G j, K& P
BOOL IsSoftIce95Loaded()
9 u7 f9 F0 v/ U1 q4 q2 w! b{
. c7 Q/ g, N2 E0 G+ E- K HANDLE hFile; % E' B1 B8 z) S/ L5 q7 I; e/ Q3 Y
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
n f4 T# O3 c FILE_SHARE_READ | FILE_SHARE_WRITE,5 H X; d. C# J1 W5 V
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
; {* j& X# A/ ?' z if( hFile != INVALID_HANDLE_VALUE )
3 i* `8 J7 P. } {
% X: b2 M: I: g+ [" L5 |: t5 o CloseHandle(hFile);' P# ?) m v, C) T
return TRUE;
5 U( C$ D' I9 E! `. S }
9 f W8 G: y; @! q& N( v& I. N* { return FALSE;
+ B% v% z9 L8 j8 Y8 f0 h}2 \- M# ]0 i. g! {+ H
+ b- ?8 \7 ?' \' b$ gAlthough this trick calls the CreateFileA function, don't even expect to be
0 \& m: f! s3 aable to intercept it by installing a IFS hook: it will not work, no way!
9 g9 ^. _% P" s" \In fact, after the call to CreateFileA it will get through VWIN32 0x001F
n% p6 F, F& ^service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
2 Q- l9 u" l% T1 W9 Q% ]and then browse the DDB list until it find the VxD and its DDB_Control_Proc* Z2 X5 V# w7 U; m
field.8 ?, G. ^$ o D4 {5 R$ S
In fact, its purpose is not to load/unload VxDs but only to send a 1 u% Y# ]$ I7 |/ Z
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)- ^% I0 ]: z$ ~" h/ v# v
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
5 I) [2 C7 x& g" E7 sto load/unload a non-dynamically loadable driver such as SoftICE ;-).
+ ?# z% _) _ C5 M. [/ Y4 ~8 aIf the VxD is loaded, it will always clear eax and the Carry flag to allow
5 ?0 S# R' _3 J# X( Yits handle to be opened and then, will be detected.5 M# h; A7 B! y. g! R4 c
You can check that simply by hooking Winice.exe control proc entry point3 z$ T, ~6 k% P+ ?1 X" \
while running MeltICE./ H- U. }3 H/ s6 {( z
2 Q$ j) E: x5 `) U0 }5 t
% j S4 r2 c5 d 00401067: push 00402025 ; \\.\SICE
9 x: N5 U, a* r5 h }9 | 0040106C: call CreateFileA
% ]. a4 c% r; l) d/ v( V u& g 00401071: cmp eax,-001" r8 @+ l- M4 X8 c" Y1 k$ ~
00401074: je 00401091
$ ^5 L' k& ^! ^$ G: J3 b
" ^- J* w2 B, L6 i3 _ r
, C$ j; [: j) Y( PThere could be hundreds of BPX you could use to detect this trick.
( @: f0 ^* M( a# ~8 Z-The most classical one is:3 F1 C+ v. }( E6 ~, {8 ~
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||6 c* r0 l- v& |& W- J
*(esp->4+4)=='NTIC'( i6 G: s! q& P$ z; n( ~4 ^
$ R* l' r( U& \+ Q
-The most exotic ones (could be very slooooow :-(
: l' @% i1 J( l: `* K0 J% B BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
4 j( e5 w6 G0 D+ B ;will break 3 times :-(
5 ]/ B" h( ~4 u& Y7 k2 ~3 \, I! N. B
-or (a bit) faster: , R: h3 `! T$ D V, n
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
, [* a/ m6 } U8 a/ O6 Z; L7 Y0 X4 | L
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
6 G+ E: \7 f6 \; \% ^3 ` ;will break 3 times :-(
% X; }6 W6 J+ q) P
. G7 e4 f5 U( }" p-Much faster:1 E8 Y7 v+ l% m7 d( y, V6 T$ Y/ m+ z
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
, u0 j3 x& }" J% ~) B9 A( z% F2 V5 W4 h r5 [! O6 W
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
, [' _& U+ ]. u: vfunction to do the same job:
* n( s0 l' p! h3 i6 c5 {* X# v5 ^
9 d2 {4 x/ y; d& w push 00 ; OF_READ p. U; n' K- X! m8 p$ ^
mov eax,[00656634] ; '\\.\SICE',00 _& i9 _' M9 D9 b" X9 \
push eax
1 a; }: Y m6 r call KERNEL32!_lopen
+ c/ I2 G/ G9 i( P! M6 r inc eax# N7 G/ c: w! K; T3 h! a H4 r1 _0 s
jnz 00650589 ; detected
" B, s; `: J) Q9 C0 T7 D. N push 00 ; OF_READ
+ _; e; P0 G! v# x mov eax,[00656638] ; '\\.\SICE'6 P: h, o! f8 n1 T; W5 L
push eax
5 l# K# |, X" @7 j6 c3 t; D: H call KERNEL32!_lopen4 P, r9 n8 _7 |0 }
inc eax- I2 H9 q/ p& V9 |$ X4 Q. W2 A
jz 006505ae ; not detected/ y5 U8 k! x, S; @+ |+ j
' e% F7 s' M+ n' k9 w
) M/ y' |) P# `: g/ |, I
__________________________________________________________________________9 J% O+ z; P4 D
" e6 Q# R( O! z6 S: c
Method 12& K6 ?# u4 N% J* q. ~7 y5 u
=========
: m2 J- J; z4 C
$ }+ G% y+ @2 M4 D. q2 QThis trick is similar to int41h/4fh Debugger installation check (code 052 f, c ^/ k# r7 }9 E
& 06) but very limited because it's only available for Win95/98 (not NT)& Q# f9 v3 e2 B) D
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.1 u, ~& X% A& m
4 L) O+ X+ b. S! e! v) R! v
push 0000004fh ; function 4fh0 H! n* }8 m5 @9 X& i$ {& u
push 002a002ah ; high word specifies which VxD (VWIN32)4 w* C- G. E) F% s0 _ Z
; low word specifies which service7 p+ o% x. i3 b5 a3 q( W
(VWIN32_Int41Dispatch)
+ Q/ U* M3 g+ k2 X" b call Kernel32!ORD_001 ; VxdCall
, P w q# N" Y9 e, m6 X | cmp ax, 0f386h ; magic number returned by system debuggers: {- y" w9 ~1 D0 H+ p
jz SoftICE_detected
% E, x8 w) H0 ?# Q- R; t& Y: K n+ `5 p% H. D) y# H3 m
Here again, several ways to detect it:/ f7 }9 H! E* D" p8 x
8 y& Z; w& { O2 j BPINT 41 if ax==4f
( [4 M/ ?4 s( P/ h, H: _7 O5 g* T$ l" {0 d" W0 ]8 l" X. K) X
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
8 |7 ]4 R3 O2 y9 K# t3 J5 Q6 f% s" s0 `- Z# N Q% W" _, B
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
- y) K3 n/ E6 t: R/ V8 |: t
& U5 B$ y) ]1 Z. Z# Z# s8 w BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!# o# q6 M& M, h. B; Z. s
& k6 r8 O/ r% `__________________________________________________________________________0 t! {9 B# F( E5 k& G, ]
/ i: x0 Z% Y; H0 p1 i# X
Method 13* s" c' \% k3 x H2 f
=========
3 P, T4 n$ ^: a) M
* g! L& x( i+ n$ j, n, CNot a real method of detection, but a good way to know if SoftICE is: o! {" v4 i2 ?" g5 E) e3 i4 b8 Q0 \2 f
installed on a computer and to locate its installation directory.4 h0 Z X' {9 l: e
It is used by few softs which access the following registry keys (usually #2) :: }6 a$ R! j0 |& G2 }) }% |8 ]
- N, T+ v2 [7 R( i-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion" L, @* _5 ] P6 V- w, x6 }
\Uninstall\SoftICE9 B5 R0 g r" `7 t. G- O! |
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
8 S' f, o( M+ c( _. s# T2 u-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
x. K- e" N. \# m\App Paths\Loader32.Exe
3 M/ a4 Q) V0 A5 d: F- X6 _
- J- l5 A" L! R+ M- E7 M! [5 Y& s! X3 }& O1 A
Note that some nasty apps could then erase all files from SoftICE directory2 m: A) J; T6 m/ N
(I faced that once :-(2 N' k* i( g) u
6 L6 r# y' C2 S1 I" O$ [0 _: J
Useful breakpoint to detect it:) V0 Q! B4 ^+ Y. e( f" U
4 `' p. Y8 A3 ], {8 I
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
5 D8 U3 g2 o2 Y6 ~; E: {6 v3 C0 E- e. P. g' E b d
__________________________________________________________________________8 o7 C' I2 p! ^& h
) X& `* ~$ m; R2 I. R
5 `6 [7 c9 k& S' AMethod 14 * }# q% _1 m( B) Z
=========
4 K: K' [; s* G" L5 F/ [1 M& A% Y; I# T$ V6 N, [
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
4 E* o! y1 z0 v, F1 z- J& r; ] Yis to determines whether a debugger is running on your system (ring0 only).
; `% Y) t4 |! U: o9 w* k* c G: I/ u
VMMCall Test_Debug_Installed
: F9 ]( M& x. Y je not_installed
5 r+ [" s3 S3 ?* P) {; c3 x A8 c* L; C. ]; k
This service just checks a flag.% {& m" Y+ f' j& m8 \
</PRE></TD></TR></TBODY></TABLE> |