<TABLE width=500>
/ f- Y1 T {6 P8 G4 |& [<TBODY>& i. M' j, M, U5 g3 }
<TR>
" n# k, Q3 r( a" z2 ~<TD><PRE>Method 01
7 _. J4 t& Q% @=========) ~. V) W, g( E0 J! B2 }/ m
6 f5 `- K9 B2 hThis method of detection of SoftICE (as well as the following one) is
4 e" z2 ]( O6 O/ oused by the majority of packers/encryptors found on Internet.. h! S0 [( D8 j" _
It seeks the signature of BoundsChecker in SoftICE
0 I# m% I- Z1 z! |5 q, c2 S, Z5 A+ L7 i0 w$ X
mov ebp, 04243484Bh ; 'BCHK'3 h ` j" e6 ~) E. G1 [
mov ax, 04h2 z# G% _; |" o2 f0 G& z, i1 E
int 3 , g" {8 ~& }7 ~4 K1 n7 A% }
cmp al,4
' C, a; c6 x( ~( W jnz SoftICE_Detected
7 j( t& |, M4 `# j; `( T
7 d8 a# @- b9 W1 K% K___________________________________________________________________________
2 g/ o' r" x, z; Y, M' F
- w8 E2 \: D! m _: E4 eMethod 027 T6 K0 v9 b0 `2 O- g
=========
6 E1 `( B1 l0 T! n4 z2 t3 h! N
7 C4 a4 l( P! ^- M# A+ YStill a method very much used (perhaps the most frequent one). It is used" w8 P! r8 Y6 S7 Q6 k
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,/ d0 D8 e- C2 g6 H, q
or execute SoftICE commands...
$ n7 j/ _/ ]- N2 [It is also used to crash SoftICE and to force it to execute any commands7 Y6 e1 Q6 H# K
(HBOOT...) :-(( # O8 h6 ^9 R- S
" {- h) L) M8 _3 n
Here is a quick description:
: B6 [) Z5 O1 i* R' d-AX = 0910h (Display string in SIce windows)
2 E* U( W" e2 X7 W# w. Y! v-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
) S5 j7 P: t, Z) g-AX = 0912h (Get breakpoint infos)
) K' d- }, E2 }7 g8 ]& o# B7 R-AX = 0913h (Set Sice breakpoints)
7 \3 k' ?. t8 k4 M-AX = 0914h (Remove SIce breakoints)4 m, i" J( _9 W' d4 a% A5 K
0 V! V' M- H' N f. ?9 M) t1 U
Each time you'll meet this trick, you'll see:
+ h6 p/ ~6 N2 G. l-SI = 4647h/ f& ?. Q! U- T' w+ ?/ A
-DI = 4A4Dh$ j6 y% s8 p3 d. H- ~7 Q
Which are the 'magic values' used by SoftIce.$ ?1 y6 T @ A2 P
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
+ w# P6 @) v" h; u6 X0 L' @4 k; t' D4 L V
Here is one example from the file "Haspinst.exe" which is the dongle HASP& W6 ?, D, ] K! |
Envelope utility use to protect DOS applications:& P: |8 Q" E1 |! x
; a0 y [+ u: I' K$ l
, d5 \" I* Q- t. p5 v1 b, z4C19:0095 MOV AX,0911 ; execute command.
- D `4 d) h4 J* C. P4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below)., k6 R; m- |& P/ I
4C19:009A MOV SI,4647 ; 1st magic value.
, Z* {' ]7 b; L9 t2 I3 B4 T4C19:009D MOV DI,4A4D ; 2nd magic value.( y4 c3 \6 c" U5 h$ ^) T. x" g
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
. k2 d! i7 {- d! I4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute9 _5 L% y2 k2 s, p* h0 I
4C19:00A4 INC CX
6 N; w9 {, a0 \4C19:00A5 CMP CX,06 ; Repeat 6 times to execute! Y+ f$ N! v0 _/ y- y0 F
4C19:00A8 JB 0095 ; 6 different commands.
. Z* E8 W) M7 i- e4C19:00AA JMP 0002 ; Bad_Guy jmp back.# O" b0 G b7 I* x/ p W
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)% n4 ~2 s8 U6 p+ S' ^: B7 Z
' q; a- L U5 y0 w9 V: QThe program will execute 6 different SIce commands located at ds:dx, which. t# s) O, T+ Y6 |) v
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.7 P% A, f. G& ]; |1 d
0 v9 Y: h6 f, C( L6 H4 v( p; S+ X0 p
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.1 c& t4 D3 L8 n' _0 J
___________________________________________________________________________
8 c8 e5 J- V8 b7 O6 u2 v4 `" ~3 k. x6 [. `8 U0 C
1 ?! Y. e8 m; p. @! ]
Method 03# }/ ~+ T5 ?5 {/ _& R9 p
=========% x- V3 ~% h6 }( H7 ~/ J6 X3 W5 I
& d; ^& C4 R C& {* m4 U; _& [
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
6 P2 K. S5 U. j. O(API Get entry point)5 s6 G2 V0 v9 T: M6 O# |$ T
% K5 S' y% k1 p# d0 h2 z$ D
, f; C% ]; ^; u xor di,di6 S, t3 V) t' x" a2 ]" P3 f: c
mov es,di9 {: ~% C' q5 L3 q* @
mov ax, 1684h - v4 j; ]5 ~( o! c- `% z4 `7 W
mov bx, 0202h ; VxD ID of winice
# Q$ i6 J' B5 D3 o+ s int 2Fh: @ T* |* _; u6 g( m. ^
mov ax, es ; ES:DI -> VxD API entry point
; a# k& G/ h! h3 f add ax, di
' t! F' D6 l$ W: \7 y test ax,ax; ~6 b. g/ U, m
jnz SoftICE_Detected# S$ ]- |) R( t* I7 \3 b9 q
- V4 y$ p0 ]2 t2 V, s9 C4 R___________________________________________________________________________
$ f$ d; W; A( a5 H. e( _& \% {1 m
: c+ p- J( S, G0 a% mMethod 042 I* F) I& ~& B+ r
=========" h5 ^7 q2 t W l/ P! V
! V2 a/ A1 m7 p6 Z8 n" ?5 Q
Method identical to the preceding one except that it seeks the ID of SoftICE; k3 Z! @/ Q, C8 I
GFX VxD.& ?7 p- Z9 }6 \7 d( m
5 i( v0 s% c! W. l6 j V
xor di,di0 q: S8 J! J' n7 ~: o( s9 i a& [# S
mov es,di2 k x: y+ J8 R
mov ax, 1684h / B( e' D8 _% V+ l- h
mov bx, 7a5Fh ; VxD ID of SIWVID! h. y6 j# w r/ ^8 M8 ~
int 2fh
O1 j: S! k! I T$ ~$ ?! b; L$ F mov ax, es ; ES:DI -> VxD API entry point
5 ?* V/ X; G/ D; \+ J. ], P add ax, di
8 t. V% g! ^, G% K, P, E. \) \ test ax,ax# g- t8 u2 T- a& ?: O1 @& V7 |# S0 A( ~
jnz SoftICE_Detected+ I) u! W/ d1 a
! n U+ R% U5 k4 r3 P- D: K- L
__________________________________________________________________________& h* }3 j6 V, P2 w& z" a
3 M2 r8 {* _ ]5 s# J
1 n. H% n, W* C5 l5 Y* fMethod 055 o' B: C: X2 P$ R+ d0 w, N* `
=========) |9 n/ B! ?# _7 E
: K% Z7 Q) W" G2 [7 Q* y7 i! zMethod seeking the 'magic number' 0F386h returned (in ax) by all system g. ?5 l* i4 U* l+ F
debugger. It calls the int 41h, function 4Fh. l2 W! n, r) T* n! ?
There are several alternatives. 3 x3 S4 Z7 z/ t) }
& ^- c: z, A9 i8 n/ KThe following one is the simplest:
1 Z# y. U4 K0 }9 n& b, V; ^5 K Y( x
mov ax,4fh/ B% `& W6 N! N4 Q9 u, ~
int 41h
) v: _5 t! m: b" N4 @ cmp ax, 0F386
: L l, F. }& Q. {! o: D8 S jz SoftICE_detected
1 C6 v9 Y" ]2 g$ O5 b7 v# h, ^" ~# ~) Y% e
, G- Z8 o* m" u5 J ~7 f
Next method as well as the following one are 2 examples from Stone's 4 h! x1 J' r. v# [- p' Z
"stn-wid.zip" (www.cracking.net):
% ]) Z1 v( W2 Z) N/ {) c3 Y
& L' Y! ~/ G% a Z7 U c9 [( U: F$ X mov bx, cs8 l5 [; u7 ?$ `- ?5 y8 f8 E
lea dx, int41handler2" {- t' G: s6 p$ R1 f. N ]
xchg dx, es:[41h*4]0 p3 l7 J7 o: @9 E" M% D
xchg bx, es:[41h*4+2]1 i+ R, {6 }3 a2 E8 i* n
mov ax,4fh
+ ?; J" g/ v6 R) [* s: }8 O9 n int 41h* H. U, j1 `- ]* W# I
xchg dx, es:[41h*4]
1 h* W1 s( M4 e* ?+ o xchg bx, es:[41h*4+2]
+ Q9 s0 g. X4 v' T8 C cmp ax, 0f386h
$ q1 V# D6 ~+ ? jz SoftICE_detected
9 U( Q! I$ s) B3 Y/ N* a, V
3 k2 t" X' j- ^4 H3 f1 {9 Oint41handler2 PROC, t- _ Z \' r: R! i- {
iret) U3 X& M! C% T( F* a0 B# s
int41handler2 ENDP
3 [4 D; H3 k. j S7 }9 r- u g3 t" v; c2 O* z* f
7 Y6 H* M6 j8 p6 h_________________________________________________________________________1 t2 l: u0 D3 Q
! V/ Z. ~& d! m9 `* @4 p% n- Z" ^0 X9 u6 k) V# g
Method 067 D' v2 k, h2 o+ ~" ^. u! Q1 j0 J
=========
9 U- c+ U) \2 ?1 n9 h
# c" k8 _ t. H) f. J4 i
, T3 A* M2 n' l$ D2nd method similar to the preceding one but more difficult to detect:
: v) X' T! n9 H* |5 ?+ n
5 _' m! q7 ?1 x7 C) Y7 D# g# R$ A; v, n
int41handler PROC
+ `& Z @; H5 n* p M mov cl,al
9 f5 R: u+ V- A+ ` iret* Z( O1 v% _* r2 e
int41handler ENDP/ \8 l' U5 y, Y' }% v
5 @" s8 X1 C1 u9 b3 C
) j) `5 N# T' I J) n3 z8 R1 I, k
xor ax,ax# }8 O9 S6 D8 o2 m: ^
mov es,ax
/ a. H+ h! C; a7 y0 v mov bx, cs5 `7 {1 J4 A( ~& ~
lea dx, int41handler
w/ D5 u y4 s# M3 M xchg dx, es:[41h*4]
9 o a- o+ M6 R xchg bx, es:[41h*4+2]* b1 a+ v7 s9 D. z! b1 Y
in al, 40h) B# c6 R. e) T$ \0 |0 @9 @
xor cx,cx
' m; G6 e3 \% r p int 41h. J! _; ]% y3 g8 H7 v
xchg dx, es:[41h*4]
6 J6 K/ f) y1 t! z O xchg bx, es:[41h*4+2]
# b* h6 t/ T F3 f) Y cmp cl,al% V& @" L* V" n" e! a [: O) e
jnz SoftICE_detected, V# k+ ]! w8 \/ l8 ~
$ h' k3 J. }2 I' p
_________________________________________________________________________) `8 v+ Q$ e' w9 d$ Q0 F6 ~, ?9 g
- H# }) _) J) MMethod 07& e$ f: R" a6 e% s
=========
, x; d0 }. a+ \5 K
1 T, ~% e; ^% V# vMethod of detection of the WinICE handler in the int68h (V86)
2 y2 T; ?8 r9 T! A$ u a
4 Y+ P+ ~8 Q5 @ mov ah,43h% K* C2 Y- ^8 R4 `6 A1 \
int 68h
. m! Z, \3 a, a cmp ax,0F386h6 k! i0 C0 W2 S+ V
jz SoftICE_Detected
q5 N6 h" Q% _- p8 Q$ A# G6 R* S }. t) x" e* N9 x! M
; y/ G R1 a3 h
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit, ^ `1 S1 D3 Z+ c6 t. b& H; ]/ M
app like this:0 x+ ]* o+ |2 y( X/ T) u m9 y
. a) g% i8 K9 x) L# q# f BPX exec_int if ax==68
5 E$ a% R- p4 K3 r8 b9 J- \ (function called is located at byte ptr [ebp+1Dh] and client eip is& @5 U# H( S- o# E8 J/ h- r' i5 O
located at [ebp+48h] for 32Bit apps)
1 K$ N4 k8 U* V8 X* P' u P% E__________________________________________________________________________
. v9 q. x/ z7 l+ G; X5 ] X" |. K2 N
$ g% z$ k- y' r9 S& kMethod 08- R5 N) V/ t4 m" u3 a G
=========" w- X$ J( h. w4 ]2 U. R p! `
3 S: X; e& U4 `7 M2 p
It is not a method of detection of SoftICE but a possibility to crash the5 \& J7 Y- c. g1 j5 G
system by intercepting int 01h and int 03h and redirecting them to another
1 X% W. ]/ ^8 Kroutine.
' p$ G# d0 W' L, E" Y& M. MIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points( C5 r# e1 [9 S8 x
to the new routine to execute (hangs computer...)
5 v" Y9 V" _6 Q$ n' `( J2 H
! O! }/ j6 \6 L6 U3 {9 T' r mov ah, 25h- m# x* S; _; b: }" k* V
mov al, Int_Number (01h or 03h); m- J4 `0 c4 C: W" ~' w- o
mov dx, offset New_Int_Routine
% S* P& H+ ?- J. B- Q& K int 21h2 V5 |" P2 o% Q2 p2 g. ]8 W
3 ~# T1 g6 ~2 b) f__________________________________________________________________________
. U6 x1 w5 R, o1 p8 n
2 ~- X3 Z3 V5 \, P3 UMethod 09
8 ~8 d9 N4 V+ o=========4 E8 ]8 [3 E* Q/ b* D. F
0 G( y# c5 {7 j+ ?2 q5 U8 `This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
# v7 ~; d1 H1 r4 M1 eperformed in ring0 (VxD or a ring3 app using the VxdCall).
0 p& b( W1 o9 j; G8 e" X7 FThe Get_DDB service is used to determine whether or not a VxD is installed
3 U6 A) I3 c/ M+ [for the specified device and returns a Device Description Block (in ecx) for
- H% W6 |3 W7 i+ u; K. h+ xthat device if it is installed.* \' B8 b2 U, s
2 Y" b; r7 y+ e1 v9 G# `2 M mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID, j3 T$ v7 @! R. P R) H/ |
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
! A! `" j" t9 @& f5 T& v% y3 U @ VMMCall Get_DDB, D" @' ^0 \! A
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed+ E6 y) T* R. ?" v }
/ b+ F' E& c% [1 ~5 q# Y1 s
Note as well that you can easily detect this method with SoftICE:; I4 Y7 J+ Z" Z+ A: N2 W& l. V
bpx Get_DDB if ax==0202 || ax==7a5fh5 x% [: b4 {1 z. `2 A3 I% `
- \3 u) A5 G+ n$ B1 K2 D0 L
__________________________________________________________________________1 u0 ?; M) W: j, d* T- h
8 e* h/ O9 Y: D
Method 10
, Q4 J& Q2 o1 f& [/ ~5 l, n" ?( E. p=========8 `$ G$ |5 z' R+ m, A9 O# x: J
' ~7 O' P$ I4 v
=>Disable or clear breakpoints before using this feature. DO NOT trace with: F8 r% ~8 y& b7 b3 @6 l
SoftICE while the option is enable!!
+ A, w% _4 V1 ^/ D8 I: I* s
, n# ?1 w0 U' [$ t* u' uThis trick is very efficient:
, z0 u6 S W& Uby checking the Debug Registers, you can detect if SoftICE is loaded
* B- ~9 a) ~% h' E$ }(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
! }: D9 _/ q8 v1 H7 W1 I+ jthere are some memory breakpoints set (dr0 to dr3) simply by reading their
0 o$ H! @8 G: v* G+ `) v6 Tvalue (in ring0 only). Values can be manipulated and or changed as well
5 U5 W( e- A1 ^- Q2 O9 `9 G, N(clearing BPMs for instance)8 b8 T, h, d9 L% E5 z: a S! p' U
6 S# k$ M5 ^0 }. P__________________________________________________________________________
* Q# V: c5 @2 H: Y8 a$ W1 u1 J7 D0 q% z2 H2 }4 d7 S2 ]
Method 11$ m6 g9 x. m2 `: d: N" ^8 t
=========# k; ]& e1 R! v' \2 J
2 h4 m0 y: b1 n2 z
This method is most known as 'MeltICE' because it has been freely distributed- R9 c1 l& `0 @+ g x) M+ s8 c
via www.winfiles.com. However it was first used by NuMega people to allow
! W- @; R' a2 @- @( NSymbol Loader to check if SoftICE was active or not (the code is located
9 V4 c; X1 ~/ I& I' t1 G% r Zinside nmtrans.dll).& M r l# ^- B/ m
" U: y6 f/ I; oThe way it works is very simple:
& s7 o( a/ A0 t. ], [/ N6 oIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
; G4 z6 H! @: l( WWinNT) with the CreateFileA API.
* p, S/ Y& R* b% ^) h' Z( P: U. E. a' c: ~) I: S' [ | z2 g! U; F
Here is a sample (checking for 'SICE'):4 T6 R- a8 s l7 Q& Z, c; x% Q5 K
' X1 W, R% y2 N, p }' HBOOL IsSoftIce95Loaded()
: o6 }. i- J3 f{+ ~4 {# g8 q% c; L: m
HANDLE hFile; # P" C% S: q; x5 ?
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,+ s4 p) v; t" T/ z: c
FILE_SHARE_READ | FILE_SHARE_WRITE," h- {+ D6 J, [; }, m
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);4 |3 O5 Q' h2 k) j% Z) i
if( hFile != INVALID_HANDLE_VALUE )1 C% o0 S7 C! \! n! {$ a2 z
{8 t$ {: g1 f5 i. j
CloseHandle(hFile);
# q, U/ \2 y5 [+ R% a' B/ W: P return TRUE;& D5 |+ Y* K) ]4 ?4 X
}
. v! z$ g" Y# k$ N8 E2 V" ` return FALSE; \6 @5 Z% U: v i2 ?
}' e4 d, ~0 V* j \- M, C
! w0 V5 m+ o5 T0 A
Although this trick calls the CreateFileA function, don't even expect to be
: a% o5 B6 D& c5 n" oable to intercept it by installing a IFS hook: it will not work, no way!! C& @6 r) l! v$ J- G+ H2 }3 z
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
8 R4 y* u+ L9 Z# Aservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)- p8 q% b9 k5 D4 N) H& r; B
and then browse the DDB list until it find the VxD and its DDB_Control_Proc4 e6 R7 {% X1 Y, x$ ^) ?
field.
4 L0 K: g( E8 H! n1 ]. L+ ^In fact, its purpose is not to load/unload VxDs but only to send a
+ Q- L. H2 t3 z5 ]W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
4 f ?9 F% u5 E! `+ l; zto the VxD Control_Dispatch proc (how the hell a shareware soft could try: c' C# H# v. `) N W. I
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
: R# y- W0 ]) p6 V/ r' LIf the VxD is loaded, it will always clear eax and the Carry flag to allow
; X% Z1 [4 _5 ]! P* m* _ Iits handle to be opened and then, will be detected.4 d( @9 |5 R2 B+ Y- Q
You can check that simply by hooking Winice.exe control proc entry point
! S5 L h: Q7 p6 X$ D/ c5 iwhile running MeltICE.
5 j8 W z t4 G6 z& ]+ X3 V& x( O: }6 X- N- o4 A
1 a+ ^, P# j3 N+ `
00401067: push 00402025 ; \\.\SICE) e0 e+ f. Q2 K/ d# L
0040106C: call CreateFileA
" b1 G3 ?% m. r4 t. v0 I# K 00401071: cmp eax,-001! }9 `8 _2 u9 U9 w2 Z4 e/ a
00401074: je 00401091
" V, I0 S" q8 l# E# }! X; c/ `, e# f* X
) Y" c7 o1 K4 h
7 y+ A) T, R& ^There could be hundreds of BPX you could use to detect this trick.
, A5 Q8 m: f6 a- M0 {$ f, u5 y1 i% `-The most classical one is:: q7 P( Z U8 Q7 L0 l5 ]
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||9 }* Z9 E( w5 R$ j8 k B
*(esp->4+4)=='NTIC': Q' z$ c, |5 X! C# O( r0 p
$ U: p! _2 T: ]
-The most exotic ones (could be very slooooow :-(* {' J0 q; a5 w6 d b
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') % b* G' a8 D0 Z4 Q+ i- ~' Q
;will break 3 times :-(2 ]4 H9 {9 [7 b! @3 C
# |0 {/ V8 `% i
-or (a bit) faster:
3 }' z6 ^8 c$ ^8 W BPINT 30 if (*edi=='SICE' || *edi=='SIWV')4 g' |% d& E2 E' `& V
# r. Z% R9 Q" X0 u/ ]% o
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
P9 U7 n! J" w$ n ;will break 3 times :-(+ C4 _0 B# U9 `4 p% \
, P T# [* F8 i; h-Much faster:
# l, n; I3 a* J! A8 V7 U- [ BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'* H; B: M2 U7 u, O+ Z# s
X( z0 g- ~4 d5 a8 g$ b
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
) o c1 C% ?8 c7 ~/ N3 b; Cfunction to do the same job:& \; p) p& q6 C' Z+ d7 R; l
# Q0 D% ]: o6 H6 ^: Q
push 00 ; OF_READ
3 X- M$ ?% N. v7 m) U% o9 u mov eax,[00656634] ; '\\.\SICE',05 Y/ N( J* V! y% w
push eax
7 ?' f& `3 q9 N9 B call KERNEL32!_lopen4 m2 d# `/ f$ E# e9 y
inc eax
0 {: \- Q( v+ y( O6 K jnz 00650589 ; detected4 O1 A( e c7 v2 ~( B/ x! K1 |
push 00 ; OF_READ! T: a6 N$ Z- e: C" \
mov eax,[00656638] ; '\\.\SICE'
+ I% r& x2 h3 I3 \$ ^5 D/ [ push eax
O% M' ^" ?7 Y call KERNEL32!_lopen' B, D, J4 ^4 p- ~( _% x( v0 u
inc eax2 m5 A7 ]4 n5 j- [! T& v! O
jz 006505ae ; not detected
! a6 p, ?" R1 y3 p2 o" l* ]: y7 w
- D: z; X0 t4 W$ A
/ H9 K# w: b) s__________________________________________________________________________; y4 R# Z! b- f# M3 @: ]2 z
+ N* F( y' V7 ]4 @) l9 T t
Method 12% @, Z( [8 t3 F
=========
3 Q2 b) `9 [8 k& X3 N# r5 ?# [/ Q; ?5 [( q
This trick is similar to int41h/4fh Debugger installation check (code 051 D% G$ g9 d( u7 I8 U" \2 q: m
& 06) but very limited because it's only available for Win95/98 (not NT)3 k) N) m6 G8 R6 ^2 v! c# D6 D
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.7 c$ C1 {& ?5 r
* p; g/ H1 w- k- r
push 0000004fh ; function 4fh
M) c @1 H) D# w! l H$ E. L6 I" ` push 002a002ah ; high word specifies which VxD (VWIN32)) d5 }1 H( i* U% T
; low word specifies which service/ S% @' j' x3 \& U, `* Q* Q6 K7 }
(VWIN32_Int41Dispatch)
/ F3 A0 _0 [8 m! [6 I call Kernel32!ORD_001 ; VxdCall |* F' ~: B0 X3 G
cmp ax, 0f386h ; magic number returned by system debuggers( m0 T5 [* ]! B1 C
jz SoftICE_detected
* W6 M! W3 u! Y' Q8 u$ ?6 V% Q/ ?, Q1 V3 n; f e6 t- \
Here again, several ways to detect it:
8 f" _0 i8 Q' f) K& R% j
* {* s* s9 m* r BPINT 41 if ax==4f
0 f. p; W$ O! _* _( K* ]. m$ b8 M% ?2 r$ [
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one- W; k2 d( j; F0 Q3 v' r7 i- _
F. }# V7 Q( K. I6 E e- W
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
5 W; I; x! V: R4 ]5 L9 o- ^. l* m( O# @' Z7 v
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!' y% B& @- t* _4 P
; r& M) m7 @% D3 c6 m5 `
__________________________________________________________________________
: W! D2 H" ^# d- d+ c/ y% |
) O' e- D& c; T( A2 rMethod 13
1 w+ H: z: O/ o=========; G* E. o+ |6 c {
9 D6 o9 {$ A F& x) s7 y
Not a real method of detection, but a good way to know if SoftICE is. w2 U$ {# Z9 z/ N2 M) R
installed on a computer and to locate its installation directory.
" }5 H) v9 q0 g. ~$ {It is used by few softs which access the following registry keys (usually #2) :0 x( e) t. z& @
& @7 I# R2 d# Z9 W; W3 L2 y
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
4 q8 R! ]2 {! G: l9 D0 t; N\Uninstall\SoftICE. _' {0 B# T5 I* A5 X& u
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
$ H; S7 s! P8 m7 C. X8 ], z: N/ C-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion: D& h- m. B" h% N
\App Paths\Loader32.Exe! o! u& x4 }. {6 J, Z. j* Q
9 }! p8 o: E6 N l* N4 |- i* O
0 c* ~. o* @% b3 z! bNote that some nasty apps could then erase all files from SoftICE directory5 d8 L+ r7 A0 d( e f D5 p
(I faced that once :-(
8 V, O3 d7 U$ ^; o3 D; c
3 Z3 k8 \; Z- n$ G: V- mUseful breakpoint to detect it:$ M' m" w; }5 w- i2 v! \
6 ^' ]4 x2 p2 \7 l X3 g BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
# g( P9 K8 [/ V9 u* p* z* K: R
5 ?6 W, M" _, d9 c0 k! ~' t- R__________________________________________________________________________
7 P$ i1 z5 S$ f! N9 `! |+ X
- q$ w# ` Q+ C6 D% U7 U/ I+ A
0 p2 N- ~5 z- L; k4 P( N( qMethod 14
3 I$ `' {, u6 F/ O; z4 r$ U8 e=========! l" n# y, Z8 g
2 Z* p0 l1 g- |6 ^8 w6 u; v# d) gA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose8 h# y% Z2 D/ q- X
is to determines whether a debugger is running on your system (ring0 only).
7 J* `# B- v; ?3 d- l& z
+ w1 `+ {5 B9 u4 U# ~! Q2 h VMMCall Test_Debug_Installed0 I3 q- g/ I, s1 f, a+ o
je not_installed
{% ^3 k( P* m4 x3 S, z; `7 e
3 t( _" G: O, n, Z; W3 i6 Y0 `This service just checks a flag.4 `6 b7 r* r) r1 k; l I3 x. ]
</PRE></TD></TR></TBODY></TABLE> |