<TABLE width=500>; w$ ^ g( [# ?& h
<TBODY>
( I: Q& w9 o8 q# _* h1 h<TR>" \8 Q5 D L, N" i
<TD><PRE>Method 01
2 e5 C. V0 {6 ?, t! S: u=========$ r: V, s9 d9 H0 o8 J7 Y, F
8 s+ j {5 f5 N7 w
This method of detection of SoftICE (as well as the following one) is' L b: Z" ]4 g
used by the majority of packers/encryptors found on Internet.
7 @6 d2 U7 D: z, R: F) R+ ?* }7 XIt seeks the signature of BoundsChecker in SoftICE3 H; p5 w! h; M R4 L
! l+ s/ _; b4 N* @- N& L
mov ebp, 04243484Bh ; 'BCHK'! i7 R+ [; i0 h& P b6 C
mov ax, 04h
, p- E6 c; ^7 l" t4 a3 ~" W) u int 3
7 a' o5 D! }) L8 v& i- q cmp al,4# {! j k/ X1 x/ D( h( w
jnz SoftICE_Detected
" _ _8 k/ h6 N) Z+ z3 `
# ~ h3 S- g0 ]) j" N6 c___________________________________________________________________________
' H$ Q1 M- ^) [! |$ P4 e/ X7 G; x$ ~$ V6 j
Method 02
& X, |# ?% y- u=========
; Q& H, S5 K+ ]6 o1 o2 k5 w
) \! l+ U. r) wStill a method very much used (perhaps the most frequent one). It is used
1 a. h- A8 Z$ r1 E. W6 r+ i$ p! Oto get SoftICE 'Back Door commands' which gives infos on Breakpoints,- F' M0 @- K4 \4 z
or execute SoftICE commands.../ Y4 u$ v4 y2 v/ U, y; ^; U, b& @
It is also used to crash SoftICE and to force it to execute any commands
# A2 J! g) i1 i0 T5 b8 [(HBOOT...) :-((
F. F/ t& P* b
4 x8 |/ l {% j7 x7 R$ v1 FHere is a quick description:5 B, m0 y# J; z! M) v* P
-AX = 0910h (Display string in SIce windows)
- H L7 ~/ E6 l) x/ v) M% p4 b-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)* g. t* m8 l& r" N3 a9 G
-AX = 0912h (Get breakpoint infos)# K2 ]1 y+ }, z0 N, L- [8 `
-AX = 0913h (Set Sice breakpoints). f5 Q0 K6 C0 |8 |
-AX = 0914h (Remove SIce breakoints)
$ ^9 E) L/ v1 k) w0 H
4 m7 B- g2 c+ e% yEach time you'll meet this trick, you'll see:1 @- |5 k# U. w( R/ r; r
-SI = 4647h9 U6 }" l4 Z( f8 ]4 G1 \. `
-DI = 4A4Dh% a; E; c" W/ p! }8 c5 V- o5 ?
Which are the 'magic values' used by SoftIce.; i) S" U# K' Q( u3 S* `' n
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
* |% v, Q( Y/ j# g
% G4 [2 k2 Y7 UHere is one example from the file "Haspinst.exe" which is the dongle HASP
9 K4 Y% a. j& d; q4 ?Envelope utility use to protect DOS applications:
3 O1 q3 H; @0 O8 R5 A& u+ l4 B G7 { s3 b5 o" O3 x$ D
; m( u8 M: ?" ?8 l9 Y
4C19:0095 MOV AX,0911 ; execute command.
% ~. |( X- F% u' X# a# e1 D5 x4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
) r9 z; b) q; w; z3 {/ u. n# L4C19:009A MOV SI,4647 ; 1st magic value.
8 R5 X% J, S' R" O( S4C19:009D MOV DI,4A4D ; 2nd magic value.$ |9 t; u! n, I( n' x& u& j! g
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)9 t$ A* g! Z2 U( A6 e) t
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute( x( ?+ B( V! m- M6 E% f0 A
4C19:00A4 INC CX( X" Z# t' b9 b3 r7 v: a
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute8 ~: A; I- a. [: C' I
4C19:00A8 JB 0095 ; 6 different commands.
! S; t9 P5 ?) ~4C19:00AA JMP 0002 ; Bad_Guy jmp back.
) Q; i8 N P3 L9 v8 H4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
0 ?. |2 Y! @& V4 W. k
' K# o& @+ G0 E$ k" ^The program will execute 6 different SIce commands located at ds:dx, which
/ g. Y! C% Q5 r* V9 mare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
4 U+ ?4 f) E5 c0 \9 g
6 N. r5 l2 |. R* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
& w6 N0 \! U. J" }7 _; p% } @___________________________________________________________________________
, r" L' b7 q: K* H
3 w2 k- U) r: k( a H
G" D; ?4 t" {" g6 z( [& t6 _Method 032 |( h) \4 Y6 z( I$ i
=========& C$ j+ [1 G h$ \3 U; ^, @
5 a/ Z& S1 b5 }) P2 i; P
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h3 E/ b) c/ U% Z
(API Get entry point)
$ S. B! p4 Q6 |, y' e! A! {1 y# p+ H
& I: @1 y! `) o! I. z, X6 D! E! W5 k- ]! B) W1 t _
xor di,di1 X4 s" P6 e8 x1 v) w/ y& A
mov es,di
2 Z3 v }# `( j5 Q7 D& d mov ax, 1684h ; S1 b4 l3 o$ C! V/ t8 Y/ x
mov bx, 0202h ; VxD ID of winice2 ~, i; x7 E- \6 E; Z6 g$ P- Y- }3 B
int 2Fh- L, Q, A; B* y* U( D, k5 @7 h
mov ax, es ; ES:DI -> VxD API entry point0 c" I7 H6 F4 |% Q' p+ D: r
add ax, di
0 Z9 r0 o$ T* G4 t test ax,ax' }. w- d, I7 k- X$ O7 B' e* R
jnz SoftICE_Detected& ~7 d& K0 N5 {4 V9 c* B3 u
2 m" G- R1 n; a6 [___________________________________________________________________________8 W* r# a( ~; f
: {: B! u9 n& D4 U
Method 04+ b- Q7 x% c- w+ W2 W0 j& ^
=========
+ ~" ~4 U2 C" E% n0 R H9 O6 c& D- q: K' n& G' ~: u2 }! {& F
Method identical to the preceding one except that it seeks the ID of SoftICE
& D4 O# J5 } f. Z# HGFX VxD.' r1 E, ]- n; z# g( O
$ |' w+ Z; a4 y/ R% W( n
xor di,di- L6 K& U6 x& p+ D& Z
mov es,di8 m2 ^- V( D% H% T% R! }: M8 E
mov ax, 1684h
" Z& K/ v; p6 \1 c% K6 ] mov bx, 7a5Fh ; VxD ID of SIWVID
; K! @8 r* B) Z6 S) C int 2fh3 l- k9 L( H5 K5 ]4 K S) U
mov ax, es ; ES:DI -> VxD API entry point8 b, @2 A$ `- V6 q
add ax, di: [+ E+ _ R* @
test ax,ax& {0 q5 D$ ?& T1 J8 M
jnz SoftICE_Detected
7 m' S8 K; T4 ~2 L: |: G" E, q* u
__________________________________________________________________________
/ H# o7 |( u# x7 S& R
/ r3 H( Y7 f5 \) H, n* y7 `+ o6 s# _# `2 m2 U) H- J6 \0 e4 h9 s& V
Method 05* |: ?7 C, {1 g
=========
' ?0 K/ ]1 u* W9 e- X
$ O. }8 y! w- J0 r5 |Method seeking the 'magic number' 0F386h returned (in ax) by all system
* E. ], c* l3 P6 Y( q5 D1 pdebugger. It calls the int 41h, function 4Fh.
1 K; i2 s6 c b3 D$ c" U x& ]There are several alternatives.
2 p. R3 z' P& e' X) z
$ J6 ]9 X" G0 f) S! IThe following one is the simplest:
' ?; L2 \- \0 z2 U8 R- F( |% O2 N. W* x
mov ax,4fh
) J c3 w, x8 F( O& ~# Z0 I/ ]1 R int 41h: {' r( j+ p, ~' _8 U
cmp ax, 0F386: \3 v/ z% U/ M
jz SoftICE_detected
9 S3 V; d; l& w r* u" w2 [
/ a6 L# n: ~) T' m( {/ S9 R
2 X2 _1 _3 O' ?/ G, d* ` UNext method as well as the following one are 2 examples from Stone's ' y+ s3 m% U- p7 D9 g: w
"stn-wid.zip" (www.cracking.net):
2 g3 f6 t0 }" r3 Q$ o% i5 B& t1 }& @. M7 }' |
mov bx, cs! X3 O' E* O( W5 F0 k
lea dx, int41handler20 a2 C q1 _. }3 N
xchg dx, es:[41h*4]
: p: V# r+ M& [ xchg bx, es:[41h*4+2]. V7 u/ }3 r3 Y9 s' |
mov ax,4fh
3 [2 D/ e, z3 t/ l5 l' S int 41h/ ]) D) N! [: X5 a0 ~
xchg dx, es:[41h*4]4 u% I1 ]# J% g* {' X
xchg bx, es:[41h*4+2]
% V- ]4 x$ d; p7 C$ ?9 s cmp ax, 0f386h8 v& p- s( l6 b7 k; E+ \% X
jz SoftICE_detected/ x7 [/ z+ u% M/ r! X
$ @" j( G P; \; \2 Nint41handler2 PROC F- B4 ~+ y/ n* s/ k- ?* ?
iret* j) u3 @9 \7 }/ l6 Y* o2 Y6 \2 i7 V
int41handler2 ENDP
( g2 l/ a% u7 o- L5 G. U; d1 P1 x
& j, P# a% O6 w X) S9 b! A- R' Y6 o1 Y& X& ]5 a4 t% V
_________________________________________________________________________6 g) B- r* ?$ ^" b$ d
; @( L* z( K+ Y, g
/ P- P+ E, F. {% {Method 06
4 O" A* F& Z2 M' A; Y=========8 l9 R0 V7 C( w ?
/ d- s3 E/ Y5 c. O5 {. k
5 |+ ~ c" u! T G* L, g0 N8 O2nd method similar to the preceding one but more difficult to detect:( Y7 t, `, S4 `5 N+ A# @6 {8 ^
* p3 F$ G2 o u; C, o5 M* B; F; M) N( H/ T
int41handler PROC9 s6 d: |' w, A% k i6 i
mov cl,al
( y' v( w5 a+ F ?- o iret
! v; E) U! O$ E# u. cint41handler ENDP
. N/ Z, l1 c* P
$ X% c/ D$ w7 y8 g1 X @( [) d* w% H' q- r* ]1 U
xor ax,ax4 E% v! _0 n7 v4 \+ v( M2 _
mov es,ax
, P% D4 p5 H* L% k% r% E. g mov bx, cs. J, ^8 p- _% W2 ?7 q& B. @- z) f$ a. e
lea dx, int41handler0 L- f/ k& u" y- z$ [. t3 I* y' A. U
xchg dx, es:[41h*4]
" f$ {$ i( E$ M0 c. O6 l) I xchg bx, es:[41h*4+2]
* O, [ K/ u0 T3 S# s9 ] in al, 40h
+ ]% H6 `: G" h! a xor cx,cx
) Y; b0 U9 O C, K2 M int 41h6 Q- B4 m, r( d, @
xchg dx, es:[41h*4]0 K5 o1 D+ @! M$ {
xchg bx, es:[41h*4+2]
" A- b$ G! S( {7 t cmp cl,al4 y9 V6 q: k2 _/ r
jnz SoftICE_detected s9 t6 u1 k, V- ^! @
4 y- X. `- m& ^: F9 F' i
_________________________________________________________________________- q4 ]; I( i; h* s2 f
5 v, n8 }4 r: _# E" h8 M9 hMethod 07/ o3 K; O1 c5 j/ M9 D7 z% m8 @' v1 H" ~
=========0 C+ ]0 @% w2 }) B; J
8 ~0 N& [6 J% O6 O" _Method of detection of the WinICE handler in the int68h (V86). A1 s. u: e& m, Q: A
1 ?' R9 @2 y# e7 G; m7 ~) \! v
mov ah,43h* p! o/ h( F" j" N/ O$ g7 @+ P. }
int 68h
7 D, E8 ]" y7 |, r7 m cmp ax,0F386h2 {4 N5 u7 e1 W0 s1 l$ }
jz SoftICE_Detected+ i" \& m% s; h1 U$ n
6 t- i) Z& I' R f- d( O6 r
( d: O- S) Y* o2 z H
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit/ z, U' G* D' P) Y5 h
app like this:
3 f W% v: q% ^! P9 a0 ?1 C3 [* F6 ?" E& m1 M/ V: h
BPX exec_int if ax==68
# k# l- u1 s* [, G" ] (function called is located at byte ptr [ebp+1Dh] and client eip is
; V, [% D5 k% s# @7 X. e3 o located at [ebp+48h] for 32Bit apps)$ W7 v$ ]3 F, {7 i3 }
__________________________________________________________________________9 l8 h- u) i7 l: U% a
9 r+ o5 L) R* P
; ]7 p8 {, T. H7 d E9 b- WMethod 08+ q* D7 \: h% H% b) p
=========2 ^" a( W4 {8 U7 f6 p8 P5 j
/ }4 k( x7 d/ b' S( `: A/ v
It is not a method of detection of SoftICE but a possibility to crash the
2 {1 J& l- k/ }, }# t! `( asystem by intercepting int 01h and int 03h and redirecting them to another/ `: E& X2 \0 \0 g& V
routine.
1 A* ?6 b( U/ b1 p. Y3 q. YIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
9 E* T( r- E1 F0 `% f7 k1 C3 l; mto the new routine to execute (hangs computer...)
$ \1 ^! X2 _" X9 z. O4 k Q% I5 o+ }) I( y- @ P2 P
mov ah, 25h( J" m* s! v4 H- g" ` O: J
mov al, Int_Number (01h or 03h); T7 d7 {* s c0 G3 G. A, v4 T( w
mov dx, offset New_Int_Routine7 H% | Q; q5 e* U* X, S. \9 i
int 21h( G! z1 r3 L$ N, R" p* j
0 `; x( _7 D/ p2 M( {__________________________________________________________________________
: ?8 e) x/ B& ` v
; M+ e& J2 O$ {0 @/ t0 ?( f% JMethod 09' D! e6 d) x: p/ }. S
=========
0 s+ e, h9 f- H a0 e& K. C( b- w" b6 H- L3 O h
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
" E- |' [* J7 vperformed in ring0 (VxD or a ring3 app using the VxdCall).
5 }4 u- P) ~; c+ s- c4 nThe Get_DDB service is used to determine whether or not a VxD is installed% M6 g' n- |' D; f' ?
for the specified device and returns a Device Description Block (in ecx) for
: `* C+ J0 F2 T8 f/ Uthat device if it is installed.2 N* L. `7 q9 J Q' M8 Q; e
+ a. P% l& N! {7 `9 _+ Z
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID# r5 N8 _' ]4 f! u4 H7 B
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
1 x( h+ J% N2 X3 r1 i' `# w2 L G/ z VMMCall Get_DDB
+ G2 M: R. u1 o+ r mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed( Z" f1 \, \* R% W' F. a0 l0 P# F
4 B. P; M# [+ n! eNote as well that you can easily detect this method with SoftICE:- u$ B" D7 k5 ~* s7 a
bpx Get_DDB if ax==0202 || ax==7a5fh* i0 y6 J2 G8 |* d5 r$ D2 S
5 l: Y: M7 G. B9 ^( k$ \( v__________________________________________________________________________) G5 [/ T6 J" A1 U
/ D+ V3 \: V1 x \& ^
Method 10
+ }$ f+ h, v$ \; G2 o$ n2 V=========
9 Z. S4 s2 c( L) [1 A2 e5 ~. S& K( [4 l o; @" v
=>Disable or clear breakpoints before using this feature. DO NOT trace with; B9 F1 L3 p: W
SoftICE while the option is enable!!
z$ ~& W O7 C% @ l3 K$ ?3 U8 F1 f, w, h3 V! l
This trick is very efficient:
b9 `5 F( S, |7 Mby checking the Debug Registers, you can detect if SoftICE is loaded
2 Y! x: R+ ?! z# l1 V1 I& ^1 k0 f(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
2 `2 S+ {! ^) gthere are some memory breakpoints set (dr0 to dr3) simply by reading their( F) \! c9 j& n6 k" C2 A
value (in ring0 only). Values can be manipulated and or changed as well
# e: D. e6 K# O# t3 ~+ I7 q(clearing BPMs for instance)
, D r0 a6 q' S( q9 P) N% Y+ P7 r4 c9 B7 p
__________________________________________________________________________9 A% t$ X' b& }, Z- W7 P
. G! _ E$ Q, i
Method 11
" ^% {) ] r& B& J" \; H=========
" F/ I+ X. G/ j# M* e" j' K, l$ g2 @& B; U- P1 G
This method is most known as 'MeltICE' because it has been freely distributed
+ p d$ n% u" x3 G" D" q/ rvia www.winfiles.com. However it was first used by NuMega people to allow
5 p0 u f: p6 T1 N+ [. b3 _9 f$ k' eSymbol Loader to check if SoftICE was active or not (the code is located' ]" I! y/ C# k" r: p# [) Y) g
inside nmtrans.dll).. X, y- E3 @' B2 X
' X% h |- m' X4 `# [
The way it works is very simple:
) B0 x, I( K7 g" c2 g0 zIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
4 y0 L7 w# q5 C% o IWinNT) with the CreateFileA API.
. z/ w" b0 O! y; O* k, _! D1 ]$ e0 l
& l) c2 W! n' _7 s% q4 O* p6 K, @2 lHere is a sample (checking for 'SICE'):
& r" I8 c5 I8 ?" h* x
6 M" S: z% i) Z$ H0 @BOOL IsSoftIce95Loaded()& @4 o2 g. k( _. M
{
" V. u1 F. C6 K" z HANDLE hFile;
* \* h+ p( X) o" o5 \ hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
2 u7 H: s6 A- U1 d FILE_SHARE_READ | FILE_SHARE_WRITE,) g5 S& L* g; e
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);6 a# y, S H4 D) o; T. S9 A
if( hFile != INVALID_HANDLE_VALUE ). T5 O+ q1 Y; B. w& [5 o; P
{8 J1 z s) Z: \1 ]
CloseHandle(hFile);- g) M2 h# p0 j$ ]' v, ~& ~3 O+ i
return TRUE;
2 ?/ C& d) k# D4 d1 E9 H }) W: T2 I# p1 V! V/ G& A# U$ q
return FALSE;* x' ^) ~( \6 V& b" I6 w4 D
}
7 ~ m, f+ G# p) Z4 h5 E" E, c7 R7 B, K7 a- y6 _
Although this trick calls the CreateFileA function, don't even expect to be. I- Q- Z1 h# ^ h% V9 d* W
able to intercept it by installing a IFS hook: it will not work, no way!
( b0 a! Y8 E; x, ?3 F4 EIn fact, after the call to CreateFileA it will get through VWIN32 0x001F0 l6 s6 Y; s# L& p N
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)3 j- S6 O" R1 h( K1 L' x/ U& L
and then browse the DDB list until it find the VxD and its DDB_Control_Proc* C+ G4 X# Y( G
field., h) ?' {" {9 Z( e
In fact, its purpose is not to load/unload VxDs but only to send a + S& _8 H0 p, V
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)4 b, r/ q E; J# i' E4 A
to the VxD Control_Dispatch proc (how the hell a shareware soft could try5 |0 z K' k# k2 D
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
3 X! A3 s+ t2 b7 s# a0 l( gIf the VxD is loaded, it will always clear eax and the Carry flag to allow
a" T7 Y+ d% q& g9 L6 n, I4 E$ Qits handle to be opened and then, will be detected.3 g) L* p3 ^) {0 Q5 M. T" \
You can check that simply by hooking Winice.exe control proc entry point
. `2 x4 p# U# \7 zwhile running MeltICE.9 B0 h: w: Z" h
! z1 ?6 p4 R5 d' s/ \" b8 {( b
) b0 E! S$ Y) r* s. I+ M5 u 00401067: push 00402025 ; \\.\SICE
/ C0 V" K4 X) D! @. U 0040106C: call CreateFileA* |& u3 Z# o+ C9 Q
00401071: cmp eax,-001
: }( @; y: P G& P0 [ 00401074: je 00401091+ K6 |1 W5 e. ~- N4 P$ V7 a
2 I2 h. ^ } i
7 I8 T, b7 C5 q; h% z* TThere could be hundreds of BPX you could use to detect this trick.
4 l) D5 T$ G5 Q-The most classical one is:" q/ w% q: L9 R8 q1 N8 i, K
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
C" B4 ]% p/ Q5 m/ J *(esp->4+4)=='NTIC'9 y; @+ X* R! Q8 n7 c( J8 c9 g
: ?' ]! ^) E" u+ d) T5 E-The most exotic ones (could be very slooooow :-(
8 V+ V( Z/ ~% X% T- U BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 1 C5 e) D: K# f, J
;will break 3 times :-(
9 a" c: F- t" J' R9 Z8 R* ~( _9 `% C1 {: @7 v3 w6 s- K
-or (a bit) faster:
% z, E8 A' C: r& }3 h BPINT 30 if (*edi=='SICE' || *edi=='SIWV'), u& U2 b' B" q' [9 q6 M4 G1 E+ Q
, Y! f3 M) @6 A q2 n0 G U6 B* R BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' - z& e1 u u8 o
;will break 3 times :-(
. z7 ]2 ~' k3 N4 Q7 Q A2 q0 D' L2 b, Z5 j: J3 m0 h; l
-Much faster:
# I" G" T: f: Q+ U6 V* L1 f BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
1 [# m4 _% q% A% `
2 e1 V) ~* V: [5 p" C! s& V* E1 c9 kNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
5 r. s; a0 z/ @- P, [! C* pfunction to do the same job:
, T: R& e# i* [6 S- ]9 O: f' m0 d" F( ]' z/ S. [
push 00 ; OF_READ
# x D4 N# }$ E! V; R m mov eax,[00656634] ; '\\.\SICE',0
9 I% b% F% F, t* T8 k- f% Y push eax* k% T8 b* W; m5 }* s& k% m4 l8 _
call KERNEL32!_lopen
& I5 u2 K: A5 C* N! K% h inc eax" m% P. X; S& U6 [
jnz 00650589 ; detected
' T: ^/ M7 k! a( T) M' r8 M% o push 00 ; OF_READ* _* {* q* h1 }# \
mov eax,[00656638] ; '\\.\SICE'
- m+ l. V0 o0 ]3 _: N push eax
( L8 L" ^ d3 e* _ call KERNEL32!_lopen
8 ?! p3 g8 f' U2 q8 \( _ inc eax
0 M, ~5 q9 s G) a7 G# V7 v' d jz 006505ae ; not detected. W) {2 `1 h0 w0 }0 \
r. h/ f! ?" j. B b: c0 J2 P r6 B. ^& E( W
__________________________________________________________________________
0 b) J B0 k( V1 C0 c
+ m" f3 T& Y, V/ eMethod 127 f' F7 y1 H+ d+ ?6 U2 e9 b5 x3 F
=========" m( P, ^, f# r
9 W6 R# D* u. n* Z; q( MThis trick is similar to int41h/4fh Debugger installation check (code 05# s/ `2 ^8 `) u: B% l7 b
& 06) but very limited because it's only available for Win95/98 (not NT)
) ], d, O: G$ l/ D0 {" X- H, |as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
) n9 V( [$ I- |- J7 a( \* k0 ^. g) u0 o& ~* W' Q4 Z% n; `* x
push 0000004fh ; function 4fh7 e: n# F2 g0 l- i! P; y. O' T4 Q
push 002a002ah ; high word specifies which VxD (VWIN32)0 A2 N. M8 X7 U7 R
; low word specifies which service
( Q, U' M2 _+ e6 c5 l (VWIN32_Int41Dispatch)9 A0 C% P' Q9 g7 T5 c7 n3 U
call Kernel32!ORD_001 ; VxdCall$ f* X2 W; d* P: |% n6 l; i. q
cmp ax, 0f386h ; magic number returned by system debuggers
/ r& f2 q, U6 b; @* N) Z jz SoftICE_detected
3 i/ {0 n# A' z" v2 @0 ]; g- @1 B% t6 \1 |/ V+ Y) l
Here again, several ways to detect it:( g( {7 W. v4 g5 E. @8 h
; j, B+ R! O9 x9 L. h) K6 d
BPINT 41 if ax==4f4 z1 C U$ Q; D5 p: b
) i$ d+ \ v$ ]: x4 _" ^ BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one: W- i8 T6 u7 q6 H2 \2 \9 w
! o) W8 t; G. _) S5 _$ }- \ x: I# V. i
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
) ?2 _! e4 @8 K5 ]/ B5 v! w0 o8 P, q) |: ]; f( F- Q- N, l) t, Y
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!) j% R: R$ ?0 ~% H
# ?9 y( S7 c7 I6 K1 F. T( W& @__________________________________________________________________________; @5 s# m3 X: d+ p8 ?5 j0 I$ F" x) |" l
! }& a" L$ f- c/ M$ J
Method 132 I" d, I* @7 { d* j7 ^
=========
9 ]) v, T+ d0 m6 ]4 R, r
5 |9 |: A9 F" ?0 M) A8 B6 m4 ]5 bNot a real method of detection, but a good way to know if SoftICE is
8 |2 t: N9 U1 P- g2 Z5 cinstalled on a computer and to locate its installation directory.
4 x. p' g! E' \6 X( I) U7 n! gIt is used by few softs which access the following registry keys (usually #2) :
) L3 n {0 E' C2 `; e6 [
' h) P" s& U/ @-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
: A \+ b# r6 H# ]" `0 j& L: g\Uninstall\SoftICE' ?$ `* ?. V: ~4 m4 v
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- E2 R% S% ~* d-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
, n3 c5 @/ e8 }! T\App Paths\Loader32.Exe ?. C/ d( ]& G8 `" H. z
% o7 g$ N6 ?8 k( F6 k8 X1 e% s2 O+ G0 c s& T8 @9 f
Note that some nasty apps could then erase all files from SoftICE directory' I6 D, @5 t: b9 O* S- E3 p' G
(I faced that once :-(5 ]. l! b( c: C* j1 p, `! \
P3 |* V R6 _' V# x2 lUseful breakpoint to detect it:
1 R4 r9 z$ i# _- F, T: ~
' q! p. }# e! g; m BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'% X- p' D5 Q+ L0 H% P
; }- V7 C" ^4 f7 c3 d! W) R8 [( z__________________________________________________________________________8 Z0 h; b# e8 ^# m' P
5 F# q+ X- z# Z o
! j. ~" S9 ^* b3 u) c% B% _& T8 ~Method 14 5 n5 e7 f) z7 K/ C/ R
=========
! y: ?" P/ N& @: d4 }! o2 k+ ~6 _9 \* _- h6 m" x5 f
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
9 N) i$ [: T1 i( _* ]7 }is to determines whether a debugger is running on your system (ring0 only).
% |! l3 Q6 i# Y* }9 p$ b1 i8 o, t0 d& s0 m( I0 v" b
VMMCall Test_Debug_Installed7 h' M1 U: {0 _7 ~- ]/ S- N3 U0 K
je not_installed
5 @" W' n' r: w1 n# q/ q4 a: u! N
This service just checks a flag.; t8 g2 {2 V9 P$ d/ T
</PRE></TD></TR></TBODY></TABLE> |