<TABLE width=500>) ]" q; }6 c d* M" z5 j: [
<TBODY>
6 u0 n* j0 r9 _( g+ O" F<TR>1 _- B" l, `' ] J7 a- |
<TD><PRE>Method 01 & Y# A' t! K/ s3 U
=========/ }# r) ^8 R5 z: J# W! z# b& R
' f A" G) P% Y+ [- H( c5 b
This method of detection of SoftICE (as well as the following one) is& t+ D6 m3 N2 W- {6 ^ b0 g3 s9 M
used by the majority of packers/encryptors found on Internet.+ O- c. M" u* L8 d6 w- g, \
It seeks the signature of BoundsChecker in SoftICE! s& D" @9 v7 W" r
E8 C! }0 u& P! |3 ^ mov ebp, 04243484Bh ; 'BCHK'' s! p/ P4 {5 p f9 `
mov ax, 04h
2 `' ]6 U& C% r* G int 3 ' _5 d; Q$ t# ]' `8 ~
cmp al,45 s/ U: `/ ~8 B
jnz SoftICE_Detected
( D. X ~" n. x) J' \
, C0 ^7 ~7 d2 f3 W5 B0 v___________________________________________________________________________
% r) z" i6 X% z, B! [5 k
2 `* N: T9 N6 y/ v, qMethod 02
! S, p6 n4 L/ A5 d2 P=========6 ~ n4 L% a, T
% B* S4 i3 S) L, O0 IStill a method very much used (perhaps the most frequent one). It is used: }+ }, ? P( c
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,( H# E( y: N& n/ a
or execute SoftICE commands..." t" E2 t f2 }) M" I7 z
It is also used to crash SoftICE and to force it to execute any commands
' H( t( |& Q2 C(HBOOT...) :-(( + A; I A# t# }5 p
) i9 S+ J+ J, _( K2 \, ^8 HHere is a quick description:3 ]* n$ L& Z5 q
-AX = 0910h (Display string in SIce windows)2 N; N# m* c% V. `+ b; q* m
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)$ X' T4 q, ^* O" h- M
-AX = 0912h (Get breakpoint infos)" b/ ?7 S v* q- k1 y9 ?
-AX = 0913h (Set Sice breakpoints)/ f+ t# C2 I' j t( D/ C: V& Z
-AX = 0914h (Remove SIce breakoints)
5 S5 w$ Z, |' S" Z9 |# o' Z
9 m f; D9 ?- QEach time you'll meet this trick, you'll see:
6 v5 f2 \( i1 v1 i# X' |1 A- o-SI = 4647h% P& H- k j5 R5 V& t
-DI = 4A4Dh
7 z8 D/ m4 H' Z% G. d1 D: Z: }3 Z8 OWhich are the 'magic values' used by SoftIce.
" I$ f$ @1 ^7 r7 P. {; [6 ^# vFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
, m& B' R* V+ S) ^. r2 S
, ~. b( y' F. }' u* M( a% vHere is one example from the file "Haspinst.exe" which is the dongle HASP
/ _! L0 E( \" g7 a0 m2 CEnvelope utility use to protect DOS applications:6 R9 y3 u; {5 D8 e4 J7 A; i4 {
' H. Y- a+ k) }! l. A( o
+ L5 T, K1 f; S4C19:0095 MOV AX,0911 ; execute command.
" }/ C* ]: s* W6 Q* h- V! ?5 b4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
4 c2 [1 W: J5 D; Z) @4C19:009A MOV SI,4647 ; 1st magic value.
H' c8 g+ B/ e# b2 W# N( |" \4C19:009D MOV DI,4A4D ; 2nd magic value.
! K$ [+ \8 ~+ w4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
# m* r1 f' o4 K" R$ j7 X8 v7 h% B4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute3 v. o% z! R* S+ W. N# S
4C19:00A4 INC CX# p5 u$ o, `* \+ B3 A; h3 b
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute' Q: ~9 ^' f/ A0 n2 [; @, j
4C19:00A8 JB 0095 ; 6 different commands.
! P8 \2 L0 ]9 t" [4 K4C19:00AA JMP 0002 ; Bad_Guy jmp back.
! F: h5 i2 q4 P9 G. X4C19:00AD MOV BX,SP ; Good_Guy go ahead :)5 K$ s" J- [% n2 f( s! s4 ~
, C x! u# {; M- ?0 t( ZThe program will execute 6 different SIce commands located at ds:dx, which
3 R7 \$ K- t# J9 Zare: LDT, IDT, GDT, TSS, RS, and ...HBOOT. p( S" q m9 B% n w6 N, k- W6 b! `
, O/ {* s3 C8 d' x: F; _3 Z
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.* P2 ~3 y7 X: i0 @# K8 J! M) U
___________________________________________________________________________3 Y; h6 G! m+ K
0 j$ V* _: M9 f; ~7 z
) j1 q$ A& G/ [7 h3 GMethod 034 r7 c4 c0 m+ o$ n# y$ T6 U
=========1 Q$ ?1 J9 D+ A+ z% A+ {: i
9 ? F* D/ g; `* r8 H2 r7 s, j
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
- c# E/ h7 ^. s8 W6 T(API Get entry point)$ C$ t- \0 x7 `; X% R
* x- q- c! t p
; _" d) |4 k* D' @ xor di,di+ V, H( T4 H T, j2 G6 a6 o
mov es,di
2 E6 ^: m3 z0 _2 T7 X mov ax, 1684h
9 n: O! s( s& ]6 m mov bx, 0202h ; VxD ID of winice
& i% v6 ^: a4 b' m/ I+ v int 2Fh
, }8 \: A; s8 e: K3 L% u0 T mov ax, es ; ES:DI -> VxD API entry point
; G. ^6 a2 Q* F- T% C* q' f add ax, di
- x2 Z4 j) P9 C, o' c* y test ax,ax
6 e* ^4 s% ^) _# B jnz SoftICE_Detected& ]! a% z7 q" S
% f# w; V% L' ?___________________________________________________________________________& s; C5 R! p8 u6 V5 q8 l
. E1 n4 G8 x* V" k; P
Method 04( ?" q1 V7 u9 d) @% @9 v
=========% x# a) ^% q* H; w9 U" D
# \, ?6 r8 ]0 }4 ~+ UMethod identical to the preceding one except that it seeks the ID of SoftICE5 d& v6 p, z* L4 k3 z
GFX VxD.
0 e" @7 ^ z1 O1 k; z- ^' V% f5 d# u& K" U
xor di,di$ H5 Y6 s' Q! \2 G/ U% s
mov es,di
1 N* u# [# Q- O mov ax, 1684h
) {& D, a+ u8 L/ _ mov bx, 7a5Fh ; VxD ID of SIWVID
$ ^ j- I) S- ?& R+ z& W! T int 2fh/ o* I% G2 L1 C
mov ax, es ; ES:DI -> VxD API entry point9 K1 i v4 @3 ~2 [
add ax, di F, m- ^: F) Q3 \1 G! S
test ax,ax9 K: U2 w; Y) `, [0 o) M M+ E
jnz SoftICE_Detected! o& K1 R' L: p. s, w
% g" @8 s$ Y) B$ T* X__________________________________________________________________________) y( r+ D, a/ d. ~# Z; }8 \
. w* k6 T, g, w1 n- d, S3 _
' M/ N7 V5 H ?! A- N& ~
Method 05
# k9 |) o( m" s B2 m=========8 p) a4 L' }: w; E) V5 w3 Q" i
9 ^4 X, F: m' e6 L" gMethod seeking the 'magic number' 0F386h returned (in ax) by all system/ ~$ F4 S/ c; Q: _2 E" \& C
debugger. It calls the int 41h, function 4Fh.
3 H6 I) C8 S' z! b& }There are several alternatives.
6 q/ z$ W% s( n& p' L
& n. n m, i( a# W$ O+ a3 PThe following one is the simplest:
8 ^6 u# Z g. V. ~
+ ?( S) c8 B- t+ g ^ mov ax,4fh
" ?3 _) `2 ^! c, d; `. B+ J6 P9 m int 41h7 ^7 a9 R6 U l- m" l& _ m3 ~7 b
cmp ax, 0F386. Y4 J! o$ f* @7 j3 a8 B! \
jz SoftICE_detected
d; t- J8 @2 w7 Y" U
6 F! ?0 ^; ^1 L( v" R" j$ o/ p# A7 ]5 ?1 t
Next method as well as the following one are 2 examples from Stone's
1 P7 Z/ r7 ?. |1 q; y. U; Q) o"stn-wid.zip" (www.cracking.net):
" G7 R, k3 ?; |7 s5 T7 y5 m W9 g
* \+ P/ L' v! E; {- k* M mov bx, cs
# r$ i, k) M* r) u: u/ _2 i; o lea dx, int41handler2
) W/ K0 n# h% ^* e8 } xchg dx, es:[41h*4]7 o7 D+ c2 R: X* x; [% r0 O
xchg bx, es:[41h*4+2]
" `1 r4 z" p- J C mov ax,4fh
6 v. U% m& u3 H int 41h' N# j% a3 r# I, c
xchg dx, es:[41h*4]
" Z* S: F, _: z+ B xchg bx, es:[41h*4+2]
6 g |. Q! Y8 m( z0 o" B+ m cmp ax, 0f386h
" R$ W: A7 e/ O. \ jz SoftICE_detected8 c, M U! ?7 h! F
9 B% c/ Q* p7 d' v/ @/ Aint41handler2 PROC
* a. G- O* }9 F$ P/ I iret( u3 H' ]+ E: ~. L; e) n; ~7 |
int41handler2 ENDP
! v# C% R4 G W% ^$ ^: R7 @) x6 M" P1 D6 T1 S
+ c# `9 y* @1 Z5 g8 s_________________________________________________________________________' T6 z; E* n3 X& R% c2 q# u( k
0 v" b% u* V ]9 E, i- q
# E! F- b/ O. N) S; K! `2 I I
Method 06/ p9 A" D7 N5 H, H
=========
( @ C3 `) h+ V6 y+ y' Q6 `2 W
{ v' e2 n: F. ?9 z, U
5 ?3 c' G5 {7 [# j2nd method similar to the preceding one but more difficult to detect:
. q& ^1 y6 ~& A( f7 R& j. {" w5 |9 |0 u! \9 G$ \
2 [0 d( L1 D7 Uint41handler PROC
+ f8 s- Q# H, S9 g mov cl,al5 k% e( h; {' k: a6 ~+ i$ _% y# k
iret5 X* p* W) q: R1 ?
int41handler ENDP% @: a. w) E/ b1 O( h
+ T4 P% n7 [! Y1 E) B0 ~
+ G8 c$ |, p |, {$ g& O
xor ax,ax' ]/ G+ d, e1 e* ^: F: i
mov es,ax
4 S/ g0 I, N6 p4 Z, A( v$ @" T* P mov bx, cs& q1 m. ]5 C/ G/ M& J# Z' V" m, E
lea dx, int41handler* ]2 S3 u2 n h
xchg dx, es:[41h*4], R7 n$ ?( z0 e% z& W2 S3 N# N
xchg bx, es:[41h*4+2]
0 v9 H2 ~1 ]4 f+ f, z1 |; Y* [/ T* Q in al, 40h4 l+ f t" t- R0 N: l! C3 @
xor cx,cx: X/ g! r. x0 b Z4 N
int 41h1 \. y. h6 d* q C6 q' b. A
xchg dx, es:[41h*4] ]3 q0 D E0 A/ X+ f, ?
xchg bx, es:[41h*4+2]
3 W& N/ Z. W& |1 D) v cmp cl,al. M$ N! \0 ~9 n& e
jnz SoftICE_detected9 P* \: E W: T1 S
/ h: J# u2 Z" K_________________________________________________________________________
0 h; e0 u9 e9 A6 c: J' o4 O
0 y, X. \3 Y; [& U4 P' K/ RMethod 07
3 u; }$ b6 _; e. }=========
& }8 X" U. s/ w( z3 h* l" y3 f) Q
" H9 a6 H4 p! |3 \$ LMethod of detection of the WinICE handler in the int68h (V86)
4 Y9 T( d1 j1 K) p" B2 k
- H# m) E$ V! K1 }7 E- {5 x mov ah,43h9 ?/ o! j# W" }! \ t# L1 f7 S
int 68h
5 t0 e" x2 e% ^! J2 i8 c. t% T cmp ax,0F386h
/ ]7 u$ A7 ^4 C7 t) l; e jz SoftICE_Detected
4 ~1 v' h9 V% Q u3 m% v. t! U0 c! K' I# _) U; ^ U7 J/ E$ c6 x
+ P( M2 E! W; Y$ o
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
1 S5 s; \6 a0 K9 z app like this:
' \! u5 q6 g/ j2 m
* K1 G- q; R0 W( Y BPX exec_int if ax==68+ T) o5 u/ h7 y* D7 C1 L
(function called is located at byte ptr [ebp+1Dh] and client eip is5 w- ]/ g/ A. N* z3 ]1 p. o! u
located at [ebp+48h] for 32Bit apps), w# X/ y' C H& N; v
__________________________________________________________________________
% Y+ b, G1 A C9 m5 K
+ V& a8 j- Y" H+ `; y$ S7 u6 e) @1 e7 v8 o4 x4 |
Method 08$ r* C% `( C& K; u% T# \# {5 F
=========
0 |2 S2 h& a: T( T) G" a A5 y
3 h$ \6 z1 w2 w( w% nIt is not a method of detection of SoftICE but a possibility to crash the/ D. ~: s0 `; h
system by intercepting int 01h and int 03h and redirecting them to another+ u% l/ e8 \: b- k3 x' i
routine.& T3 V1 P! f( l. c4 S' M
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
7 D9 i' y' A' |0 Bto the new routine to execute (hangs computer...)
7 @, f9 ^' ?" q# _( S
' w% W) g% k% N+ X9 c, Y' n mov ah, 25h
* J3 K" k) y/ s2 ^8 L" o1 F mov al, Int_Number (01h or 03h)
# G% r4 a0 M k mov dx, offset New_Int_Routine" P- {* Z2 Q8 c. o
int 21h
; x8 R3 v5 L. `$ S; z4 \; x! W$ J' Q4 P7 G
__________________________________________________________________________
' r# B/ ]; ]5 w0 N* [. g3 k+ U- h$ _# V) r
Method 09" E( x$ Q/ w' g( q( H0 a( h
=========/ a2 t: b* h# z0 _5 U
1 b, A; `( S1 m# AThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only5 N$ I, F% j6 u+ u! D" z
performed in ring0 (VxD or a ring3 app using the VxdCall). L# M- n( z! s, Y# M
The Get_DDB service is used to determine whether or not a VxD is installed
; J$ u* G$ H! v2 L* ^ F; O5 Afor the specified device and returns a Device Description Block (in ecx) for
9 o' l Y+ o- @- J9 Tthat device if it is installed./ `( z. ?( ?* @3 I, s
5 y& m( u% y& F" k1 c
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID9 P0 l3 b$ G5 v& X3 C
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
- Y8 s# s, |( T1 ]( w0 J VMMCall Get_DDB4 b/ D7 B+ o$ `0 v7 }, ^# F% S
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed& R- r5 K# A8 M$ Q% L, ^7 U
' Q7 T5 S* c! u h1 `
Note as well that you can easily detect this method with SoftICE:
+ Z# Y" l( j+ L/ Q' o$ |. v: t% ~ bpx Get_DDB if ax==0202 || ax==7a5fh( } u% e2 ?7 j6 W: y
# {6 D. B1 Q6 r/ F( D: X ?__________________________________________________________________________& F8 c0 T7 K5 p5 W; @# S8 ~, u; t
- {) Y( o3 O4 a# ?Method 100 u4 d6 O' ?5 f4 n( D r) r& y5 S
=========" S3 U/ w. H& Y7 a: F
5 T. T# k( j- \
=>Disable or clear breakpoints before using this feature. DO NOT trace with
! C( a k* n! M c! m SoftICE while the option is enable!!
U1 m/ ?4 `$ c3 o4 L$ A Z
( X* B( s/ d9 k+ ZThis trick is very efficient:6 d* ^0 W0 O$ a5 a% B: Y* \
by checking the Debug Registers, you can detect if SoftICE is loaded
% w9 I9 p+ B: H* y' `+ V1 f(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
5 _3 R3 |7 I" vthere are some memory breakpoints set (dr0 to dr3) simply by reading their
6 n4 J( g2 W0 f3 p5 avalue (in ring0 only). Values can be manipulated and or changed as well: e) ^- D" W6 I( b7 B$ H* P! z
(clearing BPMs for instance)$ J! M; r+ ~- ^- X' |3 P( J2 ]/ Q8 d
! z6 `5 R2 n* c1 V* [* s u__________________________________________________________________________
+ L3 w( q( x% K/ Q/ k }8 o7 ~* w) l) h$ A1 Y
Method 11
* i' {: w! i6 G1 S=========
& i0 @4 o2 {8 k" V d0 l" s) u
: ^# }! Z, p- G' d; B- [This method is most known as 'MeltICE' because it has been freely distributed0 t% @% F4 E ?8 b
via www.winfiles.com. However it was first used by NuMega people to allow
( L' N5 U$ D' H7 QSymbol Loader to check if SoftICE was active or not (the code is located
! Q, `1 r: t9 n3 T% M! Q rinside nmtrans.dll)., W- s2 F G+ `% Y
& {; ~ E; E2 A. HThe way it works is very simple:
2 Y) N+ D4 s8 E% PIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for& E+ j, W/ J# \4 z( b+ R
WinNT) with the CreateFileA API.
/ ?& d. R* G' h! h9 X( F0 C/ F8 o: k4 s2 C
Here is a sample (checking for 'SICE'):! R4 [2 c2 U5 q0 b
. O# L n p/ s* aBOOL IsSoftIce95Loaded()5 V4 y- C5 t9 c& ? d3 V% I3 ~
{/ U2 I! V& K; Z3 f! B" T
HANDLE hFile; " A# z, @" W. P+ q; @$ E/ S
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,2 b/ G: a5 t" w0 m% g4 v! J+ ?
FILE_SHARE_READ | FILE_SHARE_WRITE,! z& ^% Y K) r/ D
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
1 B, E1 ?/ W2 w. u if( hFile != INVALID_HANDLE_VALUE )
& p/ \7 f6 v, R! {6 J V t# E {0 A, a9 G- V" R U* f) Y8 R; ~1 |
CloseHandle(hFile);$ y2 ]) @' q" U4 Y: \
return TRUE;
% i. v+ o: B* `1 z }, ^" \5 h0 H* W
return FALSE;
) |$ Q Q# g) t' t}
% e7 s; K+ K9 B, D; G4 M/ N e% O
2 i/ R8 o8 D" x( \) aAlthough this trick calls the CreateFileA function, don't even expect to be: M) w2 p1 O2 }. S5 ^8 P
able to intercept it by installing a IFS hook: it will not work, no way!+ e! @ P' q# ?1 z) ?; F1 A( Y
In fact, after the call to CreateFileA it will get through VWIN32 0x001F( R7 b4 D1 J: E" w3 i2 v1 B r( h A6 ~
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)& j" H4 ]5 z$ F* I" r
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
! I; ^) n! i. c) p* M; ?; yfield.
4 v) m. E0 B! @% MIn fact, its purpose is not to load/unload VxDs but only to send a
; K, K( f/ n3 F ]1 MW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)! b9 j( z3 f" R6 E
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
+ h+ l. x6 Y) B4 Gto load/unload a non-dynamically loadable driver such as SoftICE ;-).
8 W& C p' u. ]- L/ C, SIf the VxD is loaded, it will always clear eax and the Carry flag to allow
- _( G& e- f2 U4 f! e Xits handle to be opened and then, will be detected.
! s' ~6 Y+ s& @7 f6 SYou can check that simply by hooking Winice.exe control proc entry point8 a7 g; V6 D# Y O
while running MeltICE.- J! M7 H6 v: H* h
6 u& [4 n' q" q% L: k' |1 u, ?: u5 B q9 n" k
00401067: push 00402025 ; \\.\SICE" m A, C7 E6 q5 x# N# U9 Q9 G
0040106C: call CreateFileA
6 B; n, B6 V- |2 T 00401071: cmp eax,-001) w* E: n( @* S' U; k
00401074: je 00401091
4 @: g+ b2 T9 f( f; w! A7 }
/ A2 g% d% A# D- \. n1 _! @6 w3 R8 v& n1 _6 n
There could be hundreds of BPX you could use to detect this trick.
& N1 E; K# `1 Z; `8 r( x; V-The most classical one is:
_. d# Y2 s+ Q BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
; d6 y( H+ T/ n! i5 K *(esp->4+4)=='NTIC'
( e. J. R- S! s- b" x$ b
% g8 p0 e1 q1 P8 s0 }-The most exotic ones (could be very slooooow :-(
+ l. M. @7 I b n BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
" j: r8 Q$ R) @1 |& L6 v: { ;will break 3 times :-(
1 G. c" O9 o' ~; e
' J3 ^5 |# \/ Q$ T8 X-or (a bit) faster:
' x3 }9 T) c' G BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
0 S+ `, M7 [# T B' \
( ?9 O7 p( M2 ], x) q9 s5 k BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
" {7 j7 w* w. H7 ]3 ?6 C3 x% W- N8 P6 } ;will break 3 times :-(, W) o- d3 G4 V5 t8 Q. n
8 l9 [" W/ M7 b0 s' t ?
-Much faster:
8 D: `3 _5 Q" v BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
+ ~( }; w% G6 h! d' ~+ Z3 p3 d- h1 U. f
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
7 s, X: ^( |3 Y) afunction to do the same job:
# U+ |7 x0 j5 E. K* K' D3 M! c0 c' T; S$ H0 w# y- h
push 00 ; OF_READ. n H, o9 J3 @8 n: U2 `7 s
mov eax,[00656634] ; '\\.\SICE',0) n' |7 F% t5 M8 v
push eax' M! E2 E8 u$ b
call KERNEL32!_lopen
+ [! J E2 k. ^% X H, W, Y7 A+ V inc eax
2 c, T! Z C% R3 d( ]' N" r jnz 00650589 ; detected
) w. X) Y; Q; S push 00 ; OF_READ, l0 D, ]( B+ _& t+ d; c! f
mov eax,[00656638] ; '\\.\SICE'* p* O* z0 u0 Q( n! N8 z
push eax& |5 {+ w0 S2 ]' z
call KERNEL32!_lopen
; `5 h' j3 D \ inc eax
( w, s" o# q: A }' l" x jz 006505ae ; not detected5 i# n% g9 ^/ U4 y
9 U& y' m% B0 K/ S+ D; Q, G* ]. V4 T
$ n6 u( ~9 u! Y5 z) c% l$ G, T8 s5 q, P
__________________________________________________________________________2 ?: B) T' K0 i( T/ x
4 f. T" T7 w: V0 J8 t
Method 12
5 u0 ~) P! o0 W9 b \=========4 h4 u5 U+ N, K! T+ g1 [/ \
( B- {- U3 h3 q- g# p& _1 `* G; N. g
This trick is similar to int41h/4fh Debugger installation check (code 054 c* A6 `1 k; A5 B9 {$ w
& 06) but very limited because it's only available for Win95/98 (not NT)
# z# Y8 \6 I) J' z+ L" l, d% nas it uses the VxDCall backdoor. This detection was found in Bleem Demo.9 k/ s, M7 w1 }! j
- ~/ [) G; ~1 @9 \. i5 z push 0000004fh ; function 4fh3 x+ }% D+ E$ _6 g
push 002a002ah ; high word specifies which VxD (VWIN32)& T% ~- B. i4 L) U5 |
; low word specifies which service
0 c' v: K9 X7 o) w4 d7 M (VWIN32_Int41Dispatch)7 V2 x, h$ B( f p' F; h) s' h
call Kernel32!ORD_001 ; VxdCall
' U" Y- q0 ?0 m: \: j; Q cmp ax, 0f386h ; magic number returned by system debuggers* y5 B0 }- a" a
jz SoftICE_detected5 m d' E q6 Z7 v ~+ Y+ i
0 a7 {9 p, @6 T5 C) a* h
Here again, several ways to detect it:
( T* U) a' `/ {* K$ U( T7 R6 w. I5 \7 e Y# W9 c) t( ]
BPINT 41 if ax==4f' r' U. T: o Y& o
. j1 V- T8 N* `- Y% l; F0 D5 x
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one. K7 E5 l$ L( [
# L! h- b; N4 X/ [. V" B6 x; W6 P6 F$ _% P
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A$ \" R; |% k6 s5 D" L% I! u( ~
9 N+ [5 Z& @, z1 l! k( V BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
/ D2 o- l, V1 `" N9 g: ?3 t1 b
; I7 r: X# i% V9 A4 P F__________________________________________________________________________
( s- ` K+ }) h6 j- z( G
4 w8 G% ]+ d$ [* D) }Method 13
, i9 V! e, g( n) P1 s$ E=========
" E; x, }2 F3 L& c( {
6 g7 N+ B9 J5 }& F8 f3 E' [5 `Not a real method of detection, but a good way to know if SoftICE is
) ~9 a, M9 K- h4 h% H+ xinstalled on a computer and to locate its installation directory.* u! Y! E6 V; Q" N" ?- s
It is used by few softs which access the following registry keys (usually #2) :
8 Y" s& Q- U5 m$ @" s, w7 i! ^# l w, n+ g- x7 X( E
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
- o: X' w, [5 x- }2 `7 @\Uninstall\SoftICE
N' a5 Y0 _2 Z K( q3 n-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
0 Z3 K! r; ?2 z' u-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
6 Z# |* v2 N' G' D% ~& \\App Paths\Loader32.Exe
' y# X& p! `0 L% ?: ~8 v8 h6 J0 E; g' {# R
2 w% \! Y! f, ?, {( JNote that some nasty apps could then erase all files from SoftICE directory3 O7 k/ \, |& H% H4 D% K0 k
(I faced that once :-(0 R% D: m/ h) n( ? D0 o
; ^- L, k* o+ b0 w! D) e9 B" OUseful breakpoint to detect it: W# ]' g2 n4 J" l) n& w
) _; M/ J- I8 p: ]% Q" X- a
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE' f3 [( ?; E9 T
/ v2 R2 {6 } o" R% w
__________________________________________________________________________
% s8 t3 R+ p7 E+ N y( Z* x- m# Q
2 e- G: J" E* }; f/ M9 ?Method 14
" ]% {7 a- {# K0 V6 j=========
( l5 F* |: x3 @( I: [( y8 r& w3 ^4 y% V3 I
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
6 q {$ p3 }# H5 m! Jis to determines whether a debugger is running on your system (ring0 only).
# x! V& E# a6 T8 o: j% _: r) m% D2 c9 I
VMMCall Test_Debug_Installed: {6 ^ `9 Y4 j
je not_installed- P2 H) f. \/ B$ k! L3 z
( u6 u3 Y$ V4 q' w* q zThis service just checks a flag.$ w5 l6 ?: l0 Y
</PRE></TD></TR></TBODY></TABLE> |