<TABLE width=500>' s( V6 Z# T; ~' C+ m% h
<TBODY>% X7 R8 `9 \, N5 H0 U$ h/ F K/ V
<TR>
! l( ]/ l3 z5 c* t3 b<TD><PRE>Method 01 ( @1 f+ y3 s3 _- o
=========
+ f; o6 w1 C4 r! X6 ~( b! B/ _1 y' a8 y
This method of detection of SoftICE (as well as the following one) is
- j4 c; H! h$ x6 hused by the majority of packers/encryptors found on Internet.
1 l3 G1 ?: s# m$ LIt seeks the signature of BoundsChecker in SoftICE
' m* z( P4 L$ @! ?. p3 Y, X7 M6 ?0 {
mov ebp, 04243484Bh ; 'BCHK': H$ ~! ?( K: X& j W8 P
mov ax, 04h& W: b* I& w& v0 d, v) n4 c
int 3 9 t, o+ t" e( X( ~, Q
cmp al,4
( U9 ^( a4 p/ J; B5 e jnz SoftICE_Detected* K1 @% {2 e! J9 N8 b
& D E/ I0 o. l$ E5 A6 ~___________________________________________________________________________
4 @2 Q: n8 e& o- |& Q6 H" H) ?6 Z8 V* k! b1 H2 D3 R
Method 02& k% j9 q7 X# ~, m9 t# Z+ Y+ A
=========& i5 t0 M" Q8 c
& J" N+ }1 S: T% O' g
Still a method very much used (perhaps the most frequent one). It is used
( P: L3 |! @& Q' ~to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
4 [! V3 o) F/ z" B, `or execute SoftICE commands...+ n* ?' k3 Q" U8 \( V+ U6 k7 n
It is also used to crash SoftICE and to force it to execute any commands
. d* n& B6 G8 F0 H7 Z(HBOOT...) :-((
# f# w1 L8 y9 V4 _ I: n
' \# J) z9 @7 s5 SHere is a quick description:0 L2 X$ A9 B' \ F; ?2 h1 Z
-AX = 0910h (Display string in SIce windows)
7 {) D, r2 P/ p-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
% ~0 X& \8 [: p) h. q* G-AX = 0912h (Get breakpoint infos)
& i9 o$ Y9 A a8 L* ~- ^7 B-AX = 0913h (Set Sice breakpoints)
1 r5 W: a1 V& r* z% B' [2 r-AX = 0914h (Remove SIce breakoints) e2 H0 h4 Y" a/ {' Y3 k- }
% n- y" b; x9 A8 y$ X6 z' xEach time you'll meet this trick, you'll see:* z3 h6 D+ u0 g: G, ^* C* B
-SI = 4647h
9 \ M0 m2 R$ l. U# l- u-DI = 4A4Dh
% L) a4 w# F AWhich are the 'magic values' used by SoftIce.
& H! V% C( f5 YFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
. N* e# b; ~$ z' k2 D+ V1 C7 a6 u7 s
* g; {$ M" I/ ]Here is one example from the file "Haspinst.exe" which is the dongle HASP7 e ?( ?5 p8 ?% o$ {8 w
Envelope utility use to protect DOS applications:
0 K: H- e8 R) J I$ J4 S% K( _! w/ B
8 | S' ]+ @+ G( Z" w J
4C19:0095 MOV AX,0911 ; execute command.
" V, r0 l+ B6 Y( H& F0 L1 j' Y4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
3 U6 J8 ~3 T* o# E- ]3 ]$ B, L3 y1 w4C19:009A MOV SI,4647 ; 1st magic value.+ `+ [$ V+ e- [. j5 T4 y7 e0 O8 c
4C19:009D MOV DI,4A4D ; 2nd magic value.
" _3 R( @' i& J i: V4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*), B. h7 K# K8 C) V: R+ [7 S# q
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
; z2 M8 z5 o- a4C19:00A4 INC CX6 f4 U" r/ ?% d9 K' P6 M* R
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute6 T, ~& U) W( j/ G/ R
4C19:00A8 JB 0095 ; 6 different commands.
+ D9 Y9 I8 r$ O7 G# W# E* m4C19:00AA JMP 0002 ; Bad_Guy jmp back.5 O' _ Z' t1 A6 ~( s4 Q
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
7 D5 b' h! d# |
4 } T; z( f, Y7 QThe program will execute 6 different SIce commands located at ds:dx, which
$ }" f) G2 E; c5 P! Nare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.- Q5 Y9 K5 E- ~ N
S/ w) j2 q9 M! Z9 Z
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.# f9 o# Q/ d% j; {$ P* E
___________________________________________________________________________
6 i6 p F% u% p- U9 _' o2 @ _& r' P: t* z2 L) ~: p% w: } t
. Z/ K! r8 M" XMethod 03
# J% Y8 b( \$ {# d% B! q=========/ }8 b; f3 B! ^3 I4 W: g/ _
C( i1 r/ ?2 O, m2 W" j, ~) t
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
9 ~6 Z- L$ Q7 |+ _(API Get entry point)
( L; `8 l# ^8 p- t
( w+ v" I/ F- @1 B8 M
' r! g6 K4 h+ V. @ xor di,di
" l) r% L( w* l* m5 [; q* {$ R mov es,di/ B; \: W# n' ^( P
mov ax, 1684h 1 j- [1 @- ?, k* L
mov bx, 0202h ; VxD ID of winice# S6 I; Q# j+ C; d0 K2 s
int 2Fh
+ Z; z/ t# [2 ~! F mov ax, es ; ES:DI -> VxD API entry point/ k$ c; v! g F9 X8 Z
add ax, di- q" k5 q% A; ~& ]) p1 _- L
test ax,ax
5 W! t U& n% y2 r8 x jnz SoftICE_Detected( ~0 r V3 U5 P" P1 g
4 h* J7 c4 x$ C" ^
___________________________________________________________________________
8 i" `- Z6 N1 U; _ k1 Y
' N# {2 ~# v9 j8 Z; g+ g$ m) k; |Method 04! |* v( {" C3 P `7 ^1 U
=========4 V. j3 A% ~/ q, ~$ s7 ?' I" _2 L
) x% m3 n5 y! |, z4 cMethod identical to the preceding one except that it seeks the ID of SoftICE
, X* x- O( H, V, H, t7 S% v, uGFX VxD.# K Y* {0 S6 v- y
6 `! E7 F" j/ V8 V/ V/ U xor di,di2 l* S( E, g3 `9 z4 o
mov es,di, _# b' t+ o% I# T ]
mov ax, 1684h % P! @. g2 s7 g
mov bx, 7a5Fh ; VxD ID of SIWVID
3 S! }3 C% l* t- `- A* K int 2fh
# h5 m' h7 k0 N1 c( t* q mov ax, es ; ES:DI -> VxD API entry point2 I, C1 r+ ^0 V! f
add ax, di$ G7 X: S! g' J
test ax,ax
7 M* e: Y6 b9 a2 T/ z jnz SoftICE_Detected0 o& @4 B: f* C/ f) L% O
2 p. g% m# i5 y1 \' X4 w1 k
__________________________________________________________________________
6 i/ y. ]4 _' _; d/ O% ?- P! z+ |6 }* w5 ?! e* Y. y2 q' a* D1 O
7 Z' \. }# Q; l7 oMethod 059 X5 M6 H* ~. I, S! |5 y; m7 i7 `# Y
=========
8 u% }3 Q( |# U X
$ n4 Z) @; @/ v& F' Z) o. [ dMethod seeking the 'magic number' 0F386h returned (in ax) by all system0 U* J/ u- |% E [0 f* p; n3 J
debugger. It calls the int 41h, function 4Fh.
7 `% i0 Y0 V. e* I- ]There are several alternatives.
! B$ h: I: m0 t4 W: ?% Z# H4 m& Y8 W
The following one is the simplest:9 M4 C9 }9 k7 n$ p) q5 I+ ?
0 U r$ c+ W) r* U/ M
mov ax,4fh% K1 x1 u7 j/ L# \4 {
int 41h
! S F: i n* b9 X6 N. p cmp ax, 0F386; k7 L k/ n" F: o% [( c7 D
jz SoftICE_detected& n$ P6 u7 n% I% k
1 J' ]3 I5 }4 U8 Y1 Y
6 A( A0 `2 k* s9 c H4 ~# NNext method as well as the following one are 2 examples from Stone's ) {' e; x7 y; r
"stn-wid.zip" (www.cracking.net):
# F/ o$ A5 ~4 ], c; h6 p9 j
. [1 ]- I5 G: Y mov bx, cs
' }* H" a: u8 ]4 X lea dx, int41handler2" b8 B! R. _; Q, `- Y
xchg dx, es:[41h*4] ^/ c+ h" V& C% J A9 O9 Y
xchg bx, es:[41h*4+2]
6 n$ w% t. E# W+ p9 } mov ax,4fh
' e6 u# M2 V; j3 `; @' k6 Z: V int 41h3 z6 ^: i2 a) C$ d3 K
xchg dx, es:[41h*4]
& Q$ I4 z' K9 N3 A xchg bx, es:[41h*4+2]3 ] S5 S a& d% j5 {
cmp ax, 0f386h3 q3 N- Z6 s) m$ G3 `9 F" Z: ^& U( V
jz SoftICE_detected' T: _: S. x O: n( \
- I; P) z8 W9 v- L; e$ Aint41handler2 PROC
, |4 F8 U4 A6 j8 s4 k iret
% _! P2 M! p4 mint41handler2 ENDP4 ]! t* J6 P/ H# h) V: E* g3 q
3 Q6 d' c1 M3 _+ u. z4 d/ t7 ^$ ]; U" a
_________________________________________________________________________. Y9 @$ e# E# _
/ n( d6 b1 k3 y2 {, H
3 V4 v( a. Q$ T. z. n! lMethod 068 O9 V, O( o g0 R
=========& D, ~" Q% O! o4 M/ E0 T! P/ m
- |; I% B3 G: f
8 N, H# |/ l! u- Z
2nd method similar to the preceding one but more difficult to detect:% b& T3 ~* w' }: l! Q
- O+ p# g8 x9 R! b5 @* P
! U% d9 a3 {2 m
int41handler PROC- }2 B4 s X# K* S, d P. M9 N; X$ Q7 j
mov cl,al" y6 M+ B1 o$ C( H
iret
/ T) C8 I' x6 Q7 l" e( p+ Sint41handler ENDP o& s$ V, b! T6 T
# q* Z6 r7 N5 o
' t. j- V+ f+ Q xor ax,ax
' \$ m# D8 n- w% ~0 [, Q8 F mov es,ax
3 c, J. M$ J. d( k/ S mov bx, cs$ C" }; h8 [3 _8 R( G- h2 F" O
lea dx, int41handler* `+ v! H" C) W: S7 n
xchg dx, es:[41h*4]$ m$ q4 \ o* `; p
xchg bx, es:[41h*4+2]8 G( P9 B) I$ N! W
in al, 40h
/ I& ]7 I) z8 |8 B: ~# q xor cx,cx% ^. ?$ Y$ e c2 ~3 E' t
int 41h
% h! L$ D3 Z, X xchg dx, es:[41h*4]
4 \; M/ j! R/ S2 D xchg bx, es:[41h*4+2]
6 i% P- P4 I7 z$ L/ s cmp cl,al2 n# c- w- \. L( U6 d
jnz SoftICE_detected2 g# \' A) f; O2 t- l; T: a
4 U8 B8 e9 }+ _
_________________________________________________________________________- u/ }' {8 K, w: ~
[* t" Q1 B" ]; hMethod 07. i8 x5 {( h. c. B
=========- ]" G, `, @; O- l o9 ^& J" y
0 ^( }0 V' }( tMethod of detection of the WinICE handler in the int68h (V86)
5 w" O# ]6 ^% C/ c
# ?4 D) l. J8 J# y/ q; d$ N mov ah,43h) I* I4 ]/ W) q1 w# @" S
int 68h" A* P" _! C( `9 C
cmp ax,0F386h
9 L. J% b& F- O0 G0 \+ _$ x jz SoftICE_Detected7 A$ g# p) P" R4 z$ o( c
' x5 ]; r* s3 \* {# S, L; c0 c) J& `* g
' `6 d1 K! |* q( p% P=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
- I) z9 }! v7 g app like this:
* m8 S( v7 G: P. k. r! }
) O- {7 i* C- w, U- P& g+ [ BPX exec_int if ax==68
, m9 L" a$ G# z/ { (function called is located at byte ptr [ebp+1Dh] and client eip is8 `; @. S$ H7 z; b- D) l0 p
located at [ebp+48h] for 32Bit apps)
& h& s1 ^- E2 y! z S/ c__________________________________________________________________________. T' n( k3 ]& O4 z; u3 n/ t" {
2 Q6 u/ P% c9 ^! s) V
8 ? C; |) A" y, g: C& H
Method 08, r# E6 _; t) @* P
=========/ L8 _' }' @6 @% q( u/ a9 q
/ V9 y. U r& L/ K' Z' VIt is not a method of detection of SoftICE but a possibility to crash the; E: P* c# e& U9 g5 a O* J
system by intercepting int 01h and int 03h and redirecting them to another+ p# C6 n- E. k8 G: T s" p
routine.' d- e( h" O; _7 H. Q$ V" v
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points7 Q% T- X& Q8 e
to the new routine to execute (hangs computer...)8 m2 B( s% X) B% j9 Z% S
* N3 B: K% e; S$ g, d6 b" I
mov ah, 25h
$ l; H! c9 {, B* W. a mov al, Int_Number (01h or 03h)+ W8 s4 I2 V' P2 ?
mov dx, offset New_Int_Routine3 ~" p) H3 ]2 f* V! y G
int 21h* ?3 y8 G1 \1 M0 }7 h& \' K+ m
% A' c& u0 e# X/ j__________________________________________________________________________
3 ?- s! Y0 c* ?: `! W7 ^) C3 m" b5 ]8 G1 X6 \) O$ M! i
Method 094 y+ C- _, j5 g0 r0 J" U
=========! n! _( D, ~% Y0 ]5 e; d
' A0 y4 T0 O/ @$ z: x0 B
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only* X* z) {7 L% n) {, u
performed in ring0 (VxD or a ring3 app using the VxdCall).: |& Y6 R# _( `: J
The Get_DDB service is used to determine whether or not a VxD is installed0 s% H" U. e; P' D7 E" L
for the specified device and returns a Device Description Block (in ecx) for% C. q4 U4 ~. t' d$ _3 Y) T
that device if it is installed.+ R' j9 {$ z% N9 |* H" j
, {; M, c. u, |. H( ~2 \ mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
) D3 `7 z, M$ D! v7 _ mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
0 K- n) k8 z" Y6 K# N VMMCall Get_DDB
$ f6 J& j; H* t7 o" p3 q( e6 @' y mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed# I# i7 y. c& k/ ~# m, X
& h \5 U' S2 I
Note as well that you can easily detect this method with SoftICE:; _8 K' S: h4 w2 n, J
bpx Get_DDB if ax==0202 || ax==7a5fh
0 ^" E0 g, b% V/ h6 o0 M2 d0 ^( B% p1 S0 n) Y; \1 X) F- _- P1 o
__________________________________________________________________________
4 \$ x0 J# Y- [
+ k) G! ~( O6 [Method 10* W2 D+ G- }" V
=========" `$ N4 E. @/ I- b h0 N7 z' [1 f
! b0 l t$ |; P- K( ]) R9 T5 a. i+ I=>Disable or clear breakpoints before using this feature. DO NOT trace with
3 E+ u8 a1 P: R SoftICE while the option is enable!!
2 J7 y1 c# e2 ^% C6 X& t1 ~
6 F7 q8 l8 p+ i; j4 F+ y5 mThis trick is very efficient:" G$ I, l( \3 M3 G0 [- \7 h
by checking the Debug Registers, you can detect if SoftICE is loaded
+ m/ U% M9 ^5 ?, p0 t# O/ R(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
0 @ |8 h3 l7 K8 E; q5 lthere are some memory breakpoints set (dr0 to dr3) simply by reading their
* X' u8 B3 ^7 U: f$ z9 v }value (in ring0 only). Values can be manipulated and or changed as well
7 I( K" G& x7 H: m(clearing BPMs for instance)
$ U' [* a1 a( C/ _& l. P1 p% Q' a; [ d( ^# v
__________________________________________________________________________
6 }! @. ?9 C. H% O: c- S) H2 U
% p' l# L; P- v# TMethod 111 ?% V: _ f4 o* K) r4 l
=========9 v y9 d- u4 ?
5 |/ ]* J7 l- X: ]
This method is most known as 'MeltICE' because it has been freely distributed
3 W* u& L" K2 M; |via www.winfiles.com. However it was first used by NuMega people to allow
# e; n z* j% ySymbol Loader to check if SoftICE was active or not (the code is located; g% U) [& y) n/ I9 |; W" Y
inside nmtrans.dll).: g8 q0 L5 n( {3 l- e
0 r1 {# E$ r5 ?8 m9 I q# r$ A
The way it works is very simple:
/ R% T* f2 E- }6 u( rIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
7 W7 B5 P7 |# \; sWinNT) with the CreateFileA API.
0 W, G, X/ Q5 [) Y# _9 S0 r- r
Here is a sample (checking for 'SICE'):3 u: w1 G; s3 |/ Z
1 o* ], b; }( o) w# J8 ?8 n
BOOL IsSoftIce95Loaded()
8 `/ O7 o/ f% V" n{
+ h/ G; F4 d! l5 a HANDLE hFile;
5 p0 H9 z! B, L$ a/ J* e5 y hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,3 y+ l U9 E/ \2 q' o
FILE_SHARE_READ | FILE_SHARE_WRITE,
0 Q O. U$ X0 T' [ NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
+ c$ ?: W! g* o% F# s if( hFile != INVALID_HANDLE_VALUE )
; j/ _0 K" ^0 G- t! J {& L: x- K3 v9 O, o- Y
CloseHandle(hFile);/ i$ c# U1 a$ c; M0 u% b2 o3 Z
return TRUE;6 \- c" e2 x% r; ~$ B4 T% p# _
}
) P, ]3 a0 L7 r) C+ X return FALSE;
0 Q! |4 o. ~* Q: e& n}
" h' Z' d3 u% u: D( i+ M9 C0 J4 |5 o
Although this trick calls the CreateFileA function, don't even expect to be' @* M" M/ A: `- M$ l1 z
able to intercept it by installing a IFS hook: it will not work, no way!. S% w# ]. H# y+ S
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
) h- \/ F: A# E3 k4 X3 |! F9 Qservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function). E& ^$ G3 c/ b- H7 f9 P2 e
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
/ R$ m7 E4 g9 J+ g5 r; p9 mfield.
: Y) m% r4 Y2 x% f. P( E+ eIn fact, its purpose is not to load/unload VxDs but only to send a
- i* H. k. V0 |W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
2 S2 i! e6 F4 [8 \) [: i1 lto the VxD Control_Dispatch proc (how the hell a shareware soft could try
0 N; @5 @* w# k, jto load/unload a non-dynamically loadable driver such as SoftICE ;-)." C6 n2 L5 X8 k: T5 g
If the VxD is loaded, it will always clear eax and the Carry flag to allow: u* r4 ?/ Q/ B2 h. ~( r
its handle to be opened and then, will be detected.
C! Q$ p' v+ g+ w) Z# v3 m" HYou can check that simply by hooking Winice.exe control proc entry point
* d2 U+ q4 l3 P5 hwhile running MeltICE.% ^! I5 e- x$ L2 q5 |5 F
7 ~3 W" a' s) u6 V8 q6 N
/ _) @2 t8 s4 ~2 M7 D0 _
00401067: push 00402025 ; \\.\SICE
% h( K# S# d! K9 n7 c" Z8 f 0040106C: call CreateFileA
. Y# c3 [* |( R1 }8 [! g! O6 J* {: K$ Q; @ 00401071: cmp eax,-001
! A, F: @/ D. N, V" ~) Y* I3 @ 00401074: je 00401091
& j# e) a' _$ k# ]5 @) _
- N3 n7 x0 e# `. `$ p7 n9 a" I3 ?! k- c3 e( J
There could be hundreds of BPX you could use to detect this trick.+ W3 e. z9 d/ g5 b
-The most classical one is:
& n) r4 F5 f( K3 v8 G BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||/ q+ X, e( g5 M, L
*(esp->4+4)=='NTIC'4 f! a5 Z" {/ d. V, x* B: h D
5 Z% O0 r+ R) B( G/ S
-The most exotic ones (could be very slooooow :-(1 p, [- Q( @9 K- y9 y
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
1 h ?- k$ _2 O1 l; h: y1 ]7 a ;will break 3 times :-(9 d4 y3 `4 ~% @; M k0 U
+ U: J: D* ]; Z* o' q
-or (a bit) faster: , {- M" f5 x7 u
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
8 b6 U0 a+ ]" L/ M8 h3 ?0 u
) h/ t8 c4 R8 ^: q9 d. | BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 5 c. [3 B4 a T. E
;will break 3 times :-(
- P$ A9 |4 H- `- d
, K5 { o1 y" q, N; B1 g-Much faster:
0 Y+ ?$ B$ n) U% h( O, n BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'3 e, ?: e d! y/ D1 S% m
; l5 w5 |; ]% j# `1 j$ g0 QNote also that some programs (like AZPR3.00) use de old 16-bit _lopen& u9 r/ I' ?5 d0 d( G- G$ u
function to do the same job:
6 b- a/ \0 o# C/ ?
% y5 ?3 W+ g' E9 h m push 00 ; OF_READ" {# g4 U4 a c) \
mov eax,[00656634] ; '\\.\SICE',0
& T2 e( D$ J4 K- m, J+ E7 c push eax3 E+ z1 f7 A9 T+ \
call KERNEL32!_lopen
3 m% U {/ d, F7 ?! t inc eax/ o2 K( j9 [: F. w4 b, n5 X
jnz 00650589 ; detected0 {0 B( _* X8 ^
push 00 ; OF_READ
7 I, U3 Y( y& [! w* `& w M mov eax,[00656638] ; '\\.\SICE'* [4 A! K0 f, i. Y
push eax* J8 V8 [4 h$ y( N& N
call KERNEL32!_lopen
! {5 Y8 i( M0 [+ z inc eax
- Q$ X% ]7 n6 g4 n$ \ jz 006505ae ; not detected4 G' r! h) H- {
3 A+ Y( l7 f: T" [" n3 I/ W: h% r" p8 x Q
__________________________________________________________________________
3 W3 k& D1 y1 h6 ^5 C
+ @; s7 A6 Z8 [' Q$ dMethod 12) T3 T" w; P& r% [
=========
: N6 O+ f' @. t: l7 Z+ h5 Q1 |; \
This trick is similar to int41h/4fh Debugger installation check (code 05
7 K) e) Q) G9 m1 \( B7 U; h& 06) but very limited because it's only available for Win95/98 (not NT)
2 L6 @# F+ c! P) ]2 N3 Zas it uses the VxDCall backdoor. This detection was found in Bleem Demo.7 E7 U/ a. X8 h# c
! U1 L# c8 n) u& W8 V+ _ push 0000004fh ; function 4fh- D5 T0 n) ?& [6 E; i1 l$ h
push 002a002ah ; high word specifies which VxD (VWIN32)
( e7 L. L3 P/ r ; low word specifies which service/ E4 {; \& j S# `1 H: |1 ^/ K# P# J( j
(VWIN32_Int41Dispatch)
4 @6 M) p8 _% I5 Z call Kernel32!ORD_001 ; VxdCall% C0 W+ {' X9 Q$ Z; m5 M8 g3 ^7 u4 @' j
cmp ax, 0f386h ; magic number returned by system debuggers
$ S5 ~% o9 N4 I jz SoftICE_detected0 H$ ^ Q4 s; ~" _% N$ R4 T
4 b) n9 ?: F0 B: O8 p! [$ V& v
Here again, several ways to detect it:( g6 s3 p/ w Y( i: p# G' H9 d
' R) Q' C5 A u O# J. r+ D9 N
BPINT 41 if ax==4f1 i% {1 G/ X" l! i* L% z
4 K3 g) T! X5 y) I% {7 ~3 \
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
; ~. ?1 M6 Q5 l; A3 T7 ]) p
5 o: \ x# ?* y& m BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A) W4 r, b4 w& h
- i% {: z, r. T6 f/ C8 R BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!" l5 K2 F7 C( O6 m9 D, m n0 S
" h) a' B$ t6 O' j; H
__________________________________________________________________________
: t4 M; v L! T$ |8 m& k5 Y; ]% q- l T3 g& D* f& L
Method 131 p" `7 S! y3 w. X. ~) r7 }* q
=========) D% ^& q% a! v# Q$ ]0 {
; \! e" O1 J* _Not a real method of detection, but a good way to know if SoftICE is* y: }, c o# b; Q4 d6 `4 e
installed on a computer and to locate its installation directory.
, x# G V+ ^3 nIt is used by few softs which access the following registry keys (usually #2) :
* F S9 ~1 d. h/ B0 P3 n
9 h# Y: b& X. X-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
* o# h" W4 f8 {* X4 H$ y\Uninstall\SoftICE
# k; B; i& Z7 C/ ^6 M& F-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- D2 [5 E' e* @. ~. ]* q0 h, Q; l-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 G1 l0 D' I5 o- L! [\App Paths\Loader32.Exe* n8 i( y" c' [# a
! [, _/ J' J. n- d8 V+ l+ H$ G
. U4 D& S" V- r( g& u k; j
Note that some nasty apps could then erase all files from SoftICE directory
* I+ t2 f* U; G0 K/ G(I faced that once :-(
0 J) Y2 C6 D' u9 g) h: h' U* Q, p. G' Z
Useful breakpoint to detect it:+ f- W f+ }& t1 s
: X( Y! m) t: Y8 C BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'8 n; I+ ~) G; L/ X. U
" L3 q* ] V% G: h% W4 l__________________________________________________________________________9 |. }+ T+ K6 u2 N4 K
: g: g1 u) u0 O5 j
8 _- q0 P, e; ~1 V. GMethod 14
" k0 T# @2 V! J, d=========! x. W3 s: u# L: ?6 m- u6 o6 v
- w, i& m$ }2 {' r4 RA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose5 S, o$ s G! n* s- u! d. W
is to determines whether a debugger is running on your system (ring0 only).
/ z, o, r) R( a5 a* X3 Z# D* m$ y7 G* V o6 {+ [0 F/ F
VMMCall Test_Debug_Installed" U% g( y! X9 Z
je not_installed$ A" z8 @* O# Z3 I
% G: V" f3 x! V& w
This service just checks a flag.
1 @7 O: u0 B$ y! _9 z3 F0 S</PRE></TD></TR></TBODY></TABLE> |