<TABLE width=500>
: T; s x* P2 A' k<TBODY>
5 y- m* {( d9 V( f- F) L<TR>+ A, i) \- a- k
<TD><PRE>Method 01
. D6 R+ I+ u& y2 h=========
# p# n4 M$ `2 V5 N0 M u) X; _# t. x5 _+ {
This method of detection of SoftICE (as well as the following one) is- E* u. a5 B! o7 ^. W
used by the majority of packers/encryptors found on Internet.5 \2 p% \2 s9 \6 O
It seeks the signature of BoundsChecker in SoftICE
# e0 z0 x, e# M2 v- S0 b1 H2 \6 ~0 C/ \4 G5 B( A. K" k$ U# b
mov ebp, 04243484Bh ; 'BCHK'- g; }5 w: I* \1 v3 Q) U7 `6 Z4 o
mov ax, 04h
) }) W" X3 e( P! ~* d int 3
9 u. r% ?3 C, E8 _ n cmp al,4- @% Y! X9 c1 s$ m9 f- [* i% \
jnz SoftICE_Detected+ X) {7 t5 ?/ ?+ _
6 `: v. G3 U6 F! o& u___________________________________________________________________________
' h. d6 N$ l# m- B( I+ e
9 m1 h* }4 G) L4 [5 qMethod 02& i3 u/ v+ u* P0 W, n g
=========' R* H5 Y* H" U; {# N# y3 _
( h8 k9 b7 l" i( L( wStill a method very much used (perhaps the most frequent one). It is used
2 m6 k2 J! E# W; Jto get SoftICE 'Back Door commands' which gives infos on Breakpoints,+ Q4 h- q8 ^! r( O
or execute SoftICE commands...& P7 J. u" W( d' b+ X) o8 y
It is also used to crash SoftICE and to force it to execute any commands
, ]3 G5 b: |5 [6 c- r- X+ Y(HBOOT...) :-(( ! q! |9 }# W r0 V9 a, v; s1 y
: B2 k" q' B4 m' N/ Q
Here is a quick description:
5 `. U1 w, R: t3 @9 ~& v: }. p6 T-AX = 0910h (Display string in SIce windows)
% v4 W3 L- e" y2 h; v-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)- p" x' D8 o( ], G6 ]
-AX = 0912h (Get breakpoint infos)
1 H' ~ k! c# X-AX = 0913h (Set Sice breakpoints)
" A' m8 t' c1 {! C& \0 G8 ]: O; \' [-AX = 0914h (Remove SIce breakoints)
; o3 K6 x2 N# ?
+ D. ~1 B, [8 B2 H) Q8 pEach time you'll meet this trick, you'll see:
: i$ {, `0 w8 |- o/ E-SI = 4647h
+ W- l( V: H% X; C' U-DI = 4A4Dh3 l* \5 k* z1 J3 _& ]5 z
Which are the 'magic values' used by SoftIce.6 D( o4 C- ^2 E: }
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
6 x, T% K! H+ t2 ?7 ?
! v; @! F# V7 S/ c; AHere is one example from the file "Haspinst.exe" which is the dongle HASP0 A, G& ~( Z- C, K0 A0 T& _" @
Envelope utility use to protect DOS applications:1 e' T" Y3 I& ]2 M
: R& F( g+ Q1 [; N* g4 S$ c# H8 d+ Z& t) P
4C19:0095 MOV AX,0911 ; execute command.
: a. O* y. j& X+ k$ k# R0 i, S4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
2 y; b9 t e2 b4 k6 S8 Y4C19:009A MOV SI,4647 ; 1st magic value.+ |$ n/ M9 T h
4C19:009D MOV DI,4A4D ; 2nd magic value.
, R2 F$ g& H% n6 t& ~4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)* Q: q4 V$ E; T6 o9 S
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute! v0 d0 g! q0 u' O/ U% G8 ?
4C19:00A4 INC CX
3 P4 l6 m. o G- s+ k5 G n- \4C19:00A5 CMP CX,06 ; Repeat 6 times to execute, t( k" K- x% |- H
4C19:00A8 JB 0095 ; 6 different commands.
% G% c% u1 F. K* |4C19:00AA JMP 0002 ; Bad_Guy jmp back.# A3 J) y' @: K6 \1 W- M
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
' C9 o) h2 {( q/ J" r) d$ z7 U x6 Q9 `$ n) Y
The program will execute 6 different SIce commands located at ds:dx, which
. K O& ?. R, y& e6 D4 K* }are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
# E# u' ?# V1 @3 X; |7 q' C2 ^" ^
8 u; O; @3 \ K7 T S6 O6 f# B( u! S7 g* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.' P( J! z" b3 M$ b/ T4 G, [
___________________________________________________________________________
3 c6 y# D' y, C
' R- ?! C/ s. V! O3 f3 h
& y' h" F. e% ~) `; G EMethod 03. D0 a- M R/ b! q
=========' Z. G3 X2 q; U3 D+ s
1 X" u. r8 l( b% t
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h9 Z: L* B) J m) p5 B0 G
(API Get entry point)
5 c, R: f! D7 R" r G
b$ H" b- c& r# Y: b, H1 f% @( J R
xor di,di
' M$ o) W- S4 ^ v, e mov es,di
& h5 j$ P; ~' c2 Z/ P- u. S mov ax, 1684h
3 G9 D; T1 g3 [% N$ J mov bx, 0202h ; VxD ID of winice2 {+ D( R3 x6 p5 d$ k
int 2Fh
$ v' j, s( ]; u+ D/ m2 f/ t0 G mov ax, es ; ES:DI -> VxD API entry point
* n* _' T) {8 j1 n9 }5 o, l add ax, di
# |+ K8 m7 P9 I" \ test ax,ax
) }6 f" [) i) T+ S* m; [ \0 H+ ] jnz SoftICE_Detected
, h7 q N( _. l( h6 c; J
& w. f/ h/ w' l! R4 B___________________________________________________________________________+ T' m* w6 l* Q1 w$ T' ^$ y; _
% N d$ c) L; u: _( }Method 04; B& t6 \9 f3 U/ B) ?
=========/ r7 |9 r! {( u2 j" w. h9 q0 _
/ a7 @' ]9 `1 R8 x; \
Method identical to the preceding one except that it seeks the ID of SoftICE3 L& a# W) @: ?5 `
GFX VxD.5 q. F' I1 o8 l o( W
5 S4 o3 q! e9 X; Q9 K+ A9 h
xor di,di
9 t" i& b5 }( Z3 y' {% Q1 { mov es,di
% O4 E( z$ k0 \- }/ ]- t mov ax, 1684h 4 Y0 p0 R& k8 X, t1 w. U
mov bx, 7a5Fh ; VxD ID of SIWVID( P3 J# Y/ i# q$ Z2 T
int 2fh8 K, {" m6 n. @ S6 B
mov ax, es ; ES:DI -> VxD API entry point
$ ]" \- ]/ M- P2 Y0 m ]/ N add ax, di$ c/ }8 P; M* v
test ax,ax) I$ U. K6 U2 ]) f( r) @9 E% A
jnz SoftICE_Detected
# F6 r. u3 L2 e% V
; f/ `1 K1 R' ^4 M# b__________________________________________________________________________
- W8 N; [! g; V. e6 a% o6 d4 K4 x" X% w6 c, q6 ^; m+ w7 Q
7 j: D1 K6 c- C6 W: g: j) Q
Method 05
, r( |; ?" ]1 ]. @/ Q========= C6 x4 g6 e' L( r
3 c4 Z C* _2 I6 V! CMethod seeking the 'magic number' 0F386h returned (in ax) by all system
0 J8 F( J4 D# r: B' cdebugger. It calls the int 41h, function 4Fh.
5 k& h( `" S2 b: aThere are several alternatives. " b& Z4 F3 X J# x1 Q6 y7 T
0 }- f: }8 N* e+ [( v6 I! OThe following one is the simplest:
7 ]: L% s& w9 S6 }- M$ y. K* `- M' t
mov ax,4fh
4 o% o* W1 T8 V1 i' `3 @ int 41h6 s. a& g; b0 C$ J2 m% v
cmp ax, 0F386
9 O' u# W7 ^! G# M" e* G$ A& Q: A jz SoftICE_detected
4 i: p4 E( h2 Y# J l
/ g5 Z5 t5 Z8 ]$ [, d* k5 x) d }& S" z& `: f. o
Next method as well as the following one are 2 examples from Stone's 9 T: J& p* Q7 ]1 b# K
"stn-wid.zip" (www.cracking.net):: z" q$ U4 ^) {; z7 v
" c" U1 H, d& m mov bx, cs
8 ~, F* J, J: G1 }0 \ F lea dx, int41handler2
, `: p* P- L. m) |) h. Y9 U4 O xchg dx, es:[41h*4]
( M+ {1 W( q) w' X' V xchg bx, es:[41h*4+2]+ A5 A, m9 P" R
mov ax,4fh/ I5 A8 [7 o- h- k
int 41h- m9 l3 K) }/ U
xchg dx, es:[41h*4]
! O( R: F w; l, \9 N xchg bx, es:[41h*4+2]8 e. G8 p6 r& w g( y7 U
cmp ax, 0f386h
_. n2 V" x/ k' v/ N g& p. {4 @8 { jz SoftICE_detected. m* l% U% o2 b/ t
8 d! B; `0 d4 j* J* e
int41handler2 PROC9 _5 g! `5 z% G0 {7 p. c6 J
iret
, r2 _! H+ L/ @6 O- \" E, _/ Iint41handler2 ENDP
1 R& E5 p. X0 B& o; O, S% {) N
+ b% j2 e: x( R
1 Z* j5 E& g, T# K. h_________________________________________________________________________
+ K* f) X, O4 m9 J4 K; z
1 J" K! y( y" A7 }$ v2 E+ Q( U% C# }$ u) N; Q- k& K& b @8 k
Method 06
4 s Y- p" n4 H=========
, M# ~, x& j8 b* z
$ `) P0 c; r. N- T3 s: o
+ a. H+ v( J1 E2nd method similar to the preceding one but more difficult to detect:
! G% t$ p( _# E. b! q2 w. k
8 l) e' P1 f/ H$ _" _" s" y5 M# R0 ] G$ c- q2 S9 E4 `; t. _
int41handler PROC. r% E6 M' w" F, y8 G9 j5 d B. @
mov cl,al
0 A8 @* r+ c# L, x3 n4 _ iret
0 b W& X' {! n# W( l# e) b9 K! N2 dint41handler ENDP
' Z! {2 @. S% j' {2 h/ m7 }! K0 D: z# }' F' d( e
g! O; t: B; \- I6 X: @ xor ax,ax
" X h0 O5 W' Y+ C3 y: { mov es,ax
. F0 w# ~, Z" g! C D8 C8 | mov bx, cs
) v0 \0 c$ `6 C3 S3 y2 K lea dx, int41handler
9 y$ [1 k: B0 v% Q% @5 e2 Q( r xchg dx, es:[41h*4]
5 u) K+ \2 n7 U) a; r. |. ~* e xchg bx, es:[41h*4+2]
1 T; `, z# }+ ]0 q9 j in al, 40h( x# i [9 ^' \0 C4 h l- b$ i
xor cx,cx" d, i! B9 F$ z8 p# g1 r
int 41h: r- J! T$ Q, S( n1 _" E% G, \
xchg dx, es:[41h*4]- S, k$ m) p/ K+ `7 J1 V8 H% W: f
xchg bx, es:[41h*4+2]
% T7 {+ b6 \7 d& E3 f( ~4 M9 K cmp cl,al! W5 n4 s1 V5 v& U
jnz SoftICE_detected$ f {9 l! {& C. ~4 n9 e. F
/ e3 B9 J4 E3 Y
_________________________________________________________________________" m. i i/ p+ `- e" }
: U6 {' J8 x- m: E* X5 R- G) J2 |
Method 07
8 I" H9 r1 V( q: X4 g1 y- l7 @. T3 Q) n=========- P, C' m. @( ~, P5 B
$ c Y6 }/ z) P, E' g. XMethod of detection of the WinICE handler in the int68h (V86)5 K4 r3 n' G, g# u- Y2 h
. z8 D1 @6 C7 y. C6 n6 P5 T: F' [
mov ah,43h
# z$ s" o" A$ S9 i& U0 P7 T int 68h
: Z1 y9 j+ j: d2 i7 s' g cmp ax,0F386h' T; f, j5 c5 S9 P
jz SoftICE_Detected
9 Y1 S/ V5 E O$ V
" x+ ?) T5 Q* o
5 j" B$ N- M; V$ F* p4 L. C- w=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit( b4 c: y( h7 X2 X' c, p& f
app like this:
7 u/ }+ N( b$ ?) l/ s% `$ Q* x2 q0 G& `: `& P- C2 W4 ]4 \
BPX exec_int if ax==68
# L8 w; z- Z0 S2 o" J1 t8 \3 y (function called is located at byte ptr [ebp+1Dh] and client eip is4 `0 p% Z" j T7 y
located at [ebp+48h] for 32Bit apps)
$ Q2 n, \/ z0 J& B. O__________________________________________________________________________
. [2 {3 W' Y6 |' Z: t7 ?; ~& _1 s
7 t. o! C+ w: J5 j8 J
+ C7 _3 f/ S1 TMethod 085 B4 b$ ^" F, l- M$ p+ Z
=========7 f! A9 `0 m3 j% i0 N
' k# d' w* c- ^4 X% E2 c3 W
It is not a method of detection of SoftICE but a possibility to crash the. b9 ^" p* X2 S
system by intercepting int 01h and int 03h and redirecting them to another
( W0 ^, `* ?1 I) l1 Croutine.
% K7 |" [( ]2 M+ w7 a1 }" oIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
' _2 K/ R3 z/ o# Z# Z @ mto the new routine to execute (hangs computer...)' R8 U1 \7 W3 M9 U
' N) a h3 h3 Z' v: G( C
mov ah, 25h
# q1 s2 o( c! ?8 Q' w mov al, Int_Number (01h or 03h)) d' \/ y: f; r7 }
mov dx, offset New_Int_Routine
3 c& m' s+ l9 v int 21h
) A2 {3 I" e' g1 w5 z: e) V1 K3 E' i# w9 _; D
__________________________________________________________________________
& j8 i3 S) T2 B' }8 u$ } T8 P# s8 e
Method 09' e4 C7 F6 m# W4 o9 N# E# R
=========
9 w6 U8 V% _& n$ S+ n; B) ^# ]2 e3 y+ b
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
) c$ H1 F2 T7 @# t2 r. Tperformed in ring0 (VxD or a ring3 app using the VxdCall).& m" Q- w7 `; {1 _8 \3 F d; e
The Get_DDB service is used to determine whether or not a VxD is installed
0 T0 `, B0 p, i. afor the specified device and returns a Device Description Block (in ecx) for
2 [3 ^1 e3 E# n% }& t& tthat device if it is installed.7 I" ^, [/ O, q
4 c; Z0 ^, q' [, L6 t0 Y' V9 R+ z mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
: h- `+ @: j$ n. O3 p mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
6 c" b0 a4 U& S; g, e VMMCall Get_DDB5 M5 D# C" y# s/ T, `
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed9 K) [1 p, {# N+ y0 V# W: O
, D& v9 n& k9 M2 Y8 y! A
Note as well that you can easily detect this method with SoftICE:# Z& }3 A: O+ v/ S# o
bpx Get_DDB if ax==0202 || ax==7a5fh1 f+ F# |8 U0 } Y/ i' s$ V; p' P
1 F9 A( m) `1 g: j6 u, i# E( O8 T
__________________________________________________________________________3 D' V6 f* c Q% f) g" \3 b
# s: @. \' `# n! p& \, [" V9 c1 ~, SMethod 10( K3 o: o2 M2 Z0 ^; w
=========1 U& ?5 |( B3 J" g
9 W* P& f* A& @% ~8 E=>Disable or clear breakpoints before using this feature. DO NOT trace with
/ |9 E7 `5 ~! i5 W$ G. l SoftICE while the option is enable!!1 o. B9 n: z* D r
+ g# x7 W9 r/ Y4 E
This trick is very efficient:1 }) `: S9 n5 t6 Z
by checking the Debug Registers, you can detect if SoftICE is loaded) e6 \# y0 i+ @* ?# t
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if! g( z& o. w }" V( g2 |* p. q: B% I
there are some memory breakpoints set (dr0 to dr3) simply by reading their2 ^" A! d& Y: R( B- w. d
value (in ring0 only). Values can be manipulated and or changed as well3 o- c1 R. U9 Q2 b) t2 l0 P6 o& I
(clearing BPMs for instance)
2 b. k0 w3 k$ }' Q
3 a- ~, w& G) I& w% Z1 Q2 I__________________________________________________________________________
7 X& L7 ^ i* n; M A; h0 B1 c
+ y2 v/ I$ f3 r: T$ O* s( RMethod 11
$ ^% M8 e( \. v$ Q# j* z s# @" f! f=========7 u7 } f4 ?* `( o+ p# D) S, N; [
' ~8 X3 ]$ B# M% i$ a% _9 v
This method is most known as 'MeltICE' because it has been freely distributed
3 t# ^& v o* Q- i( d4 n9 M/ ]: Bvia www.winfiles.com. However it was first used by NuMega people to allow
: i7 Y5 v; K E: }Symbol Loader to check if SoftICE was active or not (the code is located0 t. R) t4 `, o! k' u" Q4 u' u
inside nmtrans.dll).
- A1 n, y7 c) k* u( i4 e6 F3 j
4 t5 O! ^" G4 A$ j7 \ n; aThe way it works is very simple:- ?) f4 y% |( T) N. n# n
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
6 j5 `) M$ x9 z) W8 b' tWinNT) with the CreateFileA API.0 B+ h3 e5 n/ t" \) v& T
, g# z$ }& C2 P, x; z
Here is a sample (checking for 'SICE'):. m( x) f+ o3 g$ Y
+ w& }1 D5 L/ l6 jBOOL IsSoftIce95Loaded()4 ?! @) m" v m0 Q+ T
{' v; P. x; V' ]1 {5 W( o
HANDLE hFile; / L* D5 D7 U* [: n& Q# [5 ~
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
w& z2 d: j; W1 \& P FILE_SHARE_READ | FILE_SHARE_WRITE,- G( |# w8 C8 O; \% S
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
7 _- M6 V" S+ s ] if( hFile != INVALID_HANDLE_VALUE )
; ^" {! V- Z* k$ o6 G {: b; `; B$ T. J% I
CloseHandle(hFile);
6 L, Y7 G* X7 g1 m1 X0 l* L( x8 C5 i( R return TRUE;9 P7 G( d' {/ B Q: m
}/ p/ r- x+ s% G7 p; w
return FALSE;
L% @4 x- |2 U5 d- G}
" \/ B2 o) p, C8 E( W- \- J9 v( E/ D
- P# l+ p- i. ?Although this trick calls the CreateFileA function, don't even expect to be2 ~- \9 D! M! m$ W% m l( z d
able to intercept it by installing a IFS hook: it will not work, no way!! K( s. d8 s2 Y2 O
In fact, after the call to CreateFileA it will get through VWIN32 0x001F6 b: S/ Y( a/ i7 M8 `1 H/ K
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function): }; c: X; n! l' j. h% D
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
' a/ A2 _4 u! I& M9 \# Nfield.
) V5 l% b A1 M1 WIn fact, its purpose is not to load/unload VxDs but only to send a
, Y3 N& k: C% d3 Q$ [ `W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)+ R3 F3 i* I2 P
to the VxD Control_Dispatch proc (how the hell a shareware soft could try7 U1 e8 y: b- l$ ~! x: W
to load/unload a non-dynamically loadable driver such as SoftICE ;-).4 a7 L$ P( i% h0 M
If the VxD is loaded, it will always clear eax and the Carry flag to allow
7 D4 {' E) y) oits handle to be opened and then, will be detected., t# l9 Z( k- T2 B# i6 ~& U+ {3 K% M
You can check that simply by hooking Winice.exe control proc entry point% q: b q7 ]" {- k
while running MeltICE./ W7 w; \, y+ _: h- x7 j1 D9 A
}7 S. K5 n0 g: V4 M4 p; l( g) I4 e
00401067: push 00402025 ; \\.\SICE5 B+ g- Z) p4 P& ?! s
0040106C: call CreateFileA3 L. @1 _' G* I. _* R7 M
00401071: cmp eax,-001# E5 H* ]' @& ^# b' R
00401074: je 00401091' Z4 \; P+ ~8 L5 x
- f- h1 d B8 t7 A5 V, F
9 H5 s' C- R5 ^6 w \" W9 U0 D
There could be hundreds of BPX you could use to detect this trick.6 k ]. \# w( `6 N5 ^# b5 ?& F
-The most classical one is:* C2 l- a; z6 q9 p- }
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
) R0 {9 n' `% S6 ` *(esp->4+4)=='NTIC'5 ]+ g" ^5 u1 O/ t1 [6 T. S* e
, j2 S, d; u+ O! C1 j-The most exotic ones (could be very slooooow :-(( Q, D7 L1 j' ^0 a* L C0 s) \
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
4 K( Y9 ]- X; }; E( q: u: ^, f ;will break 3 times :-(6 Q B! u& e4 n0 k4 F9 q0 X9 f2 @
& l0 n% b$ ]! F, K$ {
-or (a bit) faster:
8 |& Q& F4 `8 P7 r: u6 l BPINT 30 if (*edi=='SICE' || *edi=='SIWV')) C+ N! F' H' g! k; t% w
- N) h! F8 D2 j! e BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' * t# S4 h4 P4 V
;will break 3 times :-(, U3 k6 I7 D- p) Z0 p# M
( c# G. a5 R3 o1 L4 s' U( p9 e-Much faster:
@7 z) t! Z3 I: M R BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
) _3 ^8 x7 t. p/ r f" O. _2 X) e6 _5 ?
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen* ^6 l$ L5 X# w8 a
function to do the same job:
# a7 L$ |& `. i8 d- G! E
% Y; y& W1 e6 f push 00 ; OF_READ( }( h5 \3 c" F/ f
mov eax,[00656634] ; '\\.\SICE',0
6 p; l# ?; R, X& E. D# s- j push eax- M& Z2 i& B6 o: N
call KERNEL32!_lopen
# n8 k3 u+ Y) Y4 S4 G" L4 _ inc eax
6 u" Q' |9 `7 z2 W. b& B jnz 00650589 ; detected
" v4 R% i! D& N' e push 00 ; OF_READ
' R0 H+ h) {& Z& q/ |- H9 P mov eax,[00656638] ; '\\.\SICE'
* F( P, F: Z: K3 ]4 V/ N1 K push eax
6 ^( n# N7 Z0 r% Z) Z call KERNEL32!_lopen
: e9 `9 W' A! u# K inc eax* c, u9 Z0 g1 a8 `
jz 006505ae ; not detected
* l1 p& Q- d' K1 ~4 K" }! ~
( R' \0 P$ P/ q
. Y: Q5 D8 Q7 O7 ~/ a__________________________________________________________________________
0 c' G7 q; B/ P8 ~$ n" D4 ?# h! ?$ T( `, ~* I
Method 123 [( X* N. F5 @# i! F
=========
! W0 w/ T, k6 I3 _- Q2 s
. c1 ^) u$ k1 J( Y t, gThis trick is similar to int41h/4fh Debugger installation check (code 05
& h& s* I5 {8 `7 H. S& 06) but very limited because it's only available for Win95/98 (not NT)( W/ E: `0 } E' j2 w8 S' n2 r
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
5 ~1 \9 B: n( ` Q8 \% x
, K. H8 V T' K* S) H push 0000004fh ; function 4fh
' I% R' g: i+ h0 m) ^ push 002a002ah ; high word specifies which VxD (VWIN32)& B9 v. t; S& `& n' m
; low word specifies which service$ t* H. }. @( _6 V4 E: R. m: ^
(VWIN32_Int41Dispatch)
& B+ I5 @: a5 `1 s call Kernel32!ORD_001 ; VxdCall* I1 }6 F5 L/ |! q' Y }: D# p
cmp ax, 0f386h ; magic number returned by system debuggers
+ t, {3 m% M2 v% w. R9 B! O" I jz SoftICE_detected
4 O2 A7 b: z9 }1 i3 T A2 W0 t4 [, H8 q0 D' K/ P* J
Here again, several ways to detect it:1 G4 \' F, x4 [! g7 c2 B9 a
' w$ X( D; o/ u" B# F0 z BPINT 41 if ax==4f: V, F3 j$ T+ W a) j1 M
: u( Y% n8 I, A0 x BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one2 y" V0 ]1 l* f) i% X/ U
- i) Z1 ]6 A6 A4 E
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
4 x: Z: K6 z' K8 Q+ ^9 m0 t: M4 k9 K/ s. u( M
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!+ ]; M5 {. q6 m- n: [9 f
3 Y/ C F6 C7 K: x$ I$ t
__________________________________________________________________________0 a5 P* F( u6 a5 B
3 T# z' w/ Q0 S4 l7 CMethod 13
% ^5 V. m2 O0 r/ ^; I& h F=========! M4 M6 }7 q5 h; S& K+ I9 Y
7 a" C+ _5 z/ fNot a real method of detection, but a good way to know if SoftICE is$ \' T% S2 S; x3 r+ `! J$ G$ m
installed on a computer and to locate its installation directory.9 J! P* o2 o% k, q$ I
It is used by few softs which access the following registry keys (usually #2) :
5 a5 e z/ i3 V6 \* T N+ H/ O+ S5 o% _2 X1 p4 X
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
- |* k& [6 p& e\Uninstall\SoftICE
: D9 A; a% s7 w- D4 k* k O; U- e-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
7 f L5 C) v% x-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
( f4 [3 X: R d# F* V: }. y\App Paths\Loader32.Exe9 J4 L, q/ l1 F. s
# {. ^( z5 V* a
* Z6 f& L$ n. M6 c" b( r# `. p) }Note that some nasty apps could then erase all files from SoftICE directory
$ s5 c u; o) p(I faced that once :-($ k- I/ P2 U9 q2 ?+ E
! h5 U7 b8 } J' I2 o5 ~: I
Useful breakpoint to detect it:5 |* f" v* l% x+ w% X
7 G; P8 H0 ^* a
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
6 i9 y- n4 b A- Z( q4 ~$ r, @! {. a+ z& ~# c7 @& d
__________________________________________________________________________
9 a# ]# J: c( H! j# E
+ _, c, U+ |. i/ v1 e: I2 R+ H
, l/ I! u% ?8 s/ z3 p# G7 Y7 HMethod 14
! v: ~3 T" _9 U# M* ^+ w=========
% G6 A* A7 O7 t0 k+ a" u9 e, I
% B5 K% \3 e' T, P8 F0 d1 dA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
. F% [% g9 X9 [/ O |is to determines whether a debugger is running on your system (ring0 only).( j1 a& [, @4 G! P! z8 X0 x9 T
! z: ?3 w2 [2 d6 t VMMCall Test_Debug_Installed1 {1 N7 x) f5 V0 H$ g4 S( J: @) L$ o
je not_installed
4 S2 }2 U& L- f0 x4 x* w* ?7 p3 P2 g) t# L" G& p
This service just checks a flag.
' |. k; n; i5 C0 x7 i3 r y* x</PRE></TD></TR></TBODY></TABLE> |