<TABLE width=500>
7 V3 R4 S) m. I. z. _4 h<TBODY>
: Y/ t) R3 B0 L y0 F<TR>
+ e6 j5 \3 b i5 F( \1 R4 y<TD><PRE>Method 01
& E/ C" ?4 H- U1 s p3 |=========! o: {" w; B9 s2 Z# h
' x% `$ i d: V! ZThis method of detection of SoftICE (as well as the following one) is7 `9 a0 h$ a0 r
used by the majority of packers/encryptors found on Internet.6 o: {& {1 U$ u
It seeks the signature of BoundsChecker in SoftICE
' f& C' W6 k+ H# Q2 ^& h" Q3 B- Y5 K) m/ C* ]% }1 G
mov ebp, 04243484Bh ; 'BCHK'
) e$ s" T1 r# P2 d mov ax, 04h* k. H9 o1 d9 N6 ?. u' @9 U
int 3
; w: e+ j* Q0 R9 N+ v cmp al,4
! L2 S/ S* O& s$ _2 P$ | jnz SoftICE_Detected- S3 o. j' y* P/ Y
" I5 P; |& C( X7 {1 t3 V" R3 b2 f___________________________________________________________________________
8 u- N+ U# Y5 S; n( W" I) `0 p3 G& e; k# M4 a% ~* |
Method 02
" Y4 l6 }3 {) G1 z=========
( z% e' W4 L/ I1 u) ?7 n. E" E; S! r4 e6 {
Still a method very much used (perhaps the most frequent one). It is used
, T6 P' q( C' N0 E+ C, g6 Rto get SoftICE 'Back Door commands' which gives infos on Breakpoints,. m. w4 m+ C1 i/ H/ \+ j+ [5 S
or execute SoftICE commands...3 @( @. x: L: ]4 a% v3 W/ Q$ v% i
It is also used to crash SoftICE and to force it to execute any commands
% L, q+ x: W! [6 O; l2 H(HBOOT...) :-(( ! m( J5 }) S1 U, `
# o3 t, y+ p1 g( q5 T! O+ l$ R% \
Here is a quick description:( L3 t; W4 O% M5 \2 k; U# w
-AX = 0910h (Display string in SIce windows)
$ h# }( s; F ?2 e/ O-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)" h$ c7 T( d: w9 v" z. |
-AX = 0912h (Get breakpoint infos)
5 ~* s G* X. z7 j6 z2 t, S-AX = 0913h (Set Sice breakpoints)
# s7 ^2 B1 U' d4 I2 ~1 v5 |5 n& [-AX = 0914h (Remove SIce breakoints)
6 S: F$ _+ ~$ D$ C) F7 x0 N( ?+ T
Each time you'll meet this trick, you'll see:
# m% ]. \' U/ M+ q7 s ]1 b! N-SI = 4647h
, v! d+ P: C+ T( ^5 H-DI = 4A4Dh# L* b, s0 M; J
Which are the 'magic values' used by SoftIce.4 z' Y8 U) y7 n: Z, ^/ _
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
) s! H5 f r! j Y: |3 S. L; x0 B! [5 \. D
Here is one example from the file "Haspinst.exe" which is the dongle HASP- Q; M$ K! _$ r& X) J5 W
Envelope utility use to protect DOS applications:
8 `4 A! h1 n, Y/ j# l- A1 u' }4 G8 |
* U, U3 }$ `8 L$ I2 g4C19:0095 MOV AX,0911 ; execute command." L. ~& m/ `4 h! L$ H1 f' b
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
4 M: a* H1 ` q- U6 {4C19:009A MOV SI,4647 ; 1st magic value.
. b$ [+ R2 ?8 L* A7 ?4C19:009D MOV DI,4A4D ; 2nd magic value.' O& d' ^- f& H
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
5 e/ e( S# Z: r4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
6 j g( \1 H" Z7 x6 I4C19:00A4 INC CX/ S W, U9 I+ y
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute: M- R2 F# G( [
4C19:00A8 JB 0095 ; 6 different commands.
% m! a# o0 H& r$ Q& Y& w, c4C19:00AA JMP 0002 ; Bad_Guy jmp back.8 p1 N6 G; ~+ I4 u7 H1 s& M
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
8 N4 y- L6 u& L" D. {
& c1 L3 j; o8 W& QThe program will execute 6 different SIce commands located at ds:dx, which1 o/ S" u' }+ x+ N* ]. p! b$ @
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
! g/ D% k: m& Z: u5 F8 W
4 O; R# u. R2 X2 d2 p! e3 B* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded., j x) z) w% V; l" N0 M. t9 m4 l
___________________________________________________________________________
/ v- ^. o5 w# ?: d
$ b9 W6 P! i5 D' q; z2 c1 G2 ?. E& {9 j1 J# P7 f& N0 \2 N) A
Method 037 Q) y8 o( `$ C4 \! P
=========( [2 L$ B8 N2 j8 O4 q+ O m5 u
5 q' G! n9 u$ [' a
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h9 e0 b+ S, l/ b' |+ I
(API Get entry point): N7 F1 z- b9 z9 L3 [
0 `+ y$ }5 c% B/ h8 G( z+ a( x* V
& l$ {, |# h: z$ b( r* Q7 t9 o xor di,di) ^: E" J# ~( S9 z% Y
mov es,di# E% V! g" f$ e4 ^% Z
mov ax, 1684h
" F7 P& Z& u, d7 H& F+ D% g mov bx, 0202h ; VxD ID of winice) q; ~/ Z9 |! n8 a
int 2Fh
9 H3 Y" s" Q3 |( g" v mov ax, es ; ES:DI -> VxD API entry point: l1 e% q. J( L* |5 y
add ax, di2 W2 e2 U8 J* {( G
test ax,ax' d! D: O6 s( B1 N. @
jnz SoftICE_Detected
/ O, `" ~ ~' C! H2 x' u
$ |+ ^) q; C S7 K( ^___________________________________________________________________________
/ Y# [4 g) H! v# `
$ I- L3 g% S: t o- y- pMethod 04) E; i2 t. s: O2 a; ^8 y
=========
7 R0 S" a8 Q& u3 y7 u" M9 n6 J6 S
Method identical to the preceding one except that it seeks the ID of SoftICE
( I5 Y0 G5 n$ bGFX VxD.0 Y3 i& {% h2 s. m
. R& V7 d! ], b1 J) ]
xor di,di
7 i3 U7 q* c5 y0 x( j mov es,di% H. Y) G$ D) R( \
mov ax, 1684h & j* N$ h s( S+ ~" ^
mov bx, 7a5Fh ; VxD ID of SIWVID4 y0 K" |) o/ i- t
int 2fh
" N! g! i g$ {) {, k2 a3 ^ mov ax, es ; ES:DI -> VxD API entry point1 K# o9 d+ I3 V, `4 G
add ax, di/ u( v5 s- n" u2 }' W" p
test ax,ax) O+ Q* M8 C# \# ^- u: s4 j
jnz SoftICE_Detected. w8 t0 G$ R" M7 B) P6 f! _) I
% e# K$ N* j5 T5 D1 Q& ?__________________________________________________________________________
$ Z" \$ J1 u9 N3 N. h& ^* l7 X
% P5 Z7 n. _- c4 B3 {. k+ j5 z4 z* h% w. p8 }) `- [
Method 054 N% Q9 N3 F* g5 I
=========
8 L& g" X* J8 k2 M: L5 c# v7 R: M' I
Method seeking the 'magic number' 0F386h returned (in ax) by all system, p2 [- t/ x8 z4 ~
debugger. It calls the int 41h, function 4Fh.
0 u- j, o+ F; U) BThere are several alternatives.
0 n+ P2 m5 W6 Y
5 t6 K" B: h8 N8 u5 vThe following one is the simplest:
8 g3 ^- h4 m6 y; g2 `8 m' Y* M4 @) }8 d4 C8 M
mov ax,4fh# A2 u0 v; U4 H+ t& Q- d- _
int 41h
& ^! B3 w [- G, v e/ p* ^( C cmp ax, 0F386) B( q5 s; p3 U- ^1 p4 o
jz SoftICE_detected7 }& ^, L3 a. ^2 Y+ o
9 Z3 v* D+ q6 d3 X
# A: Q/ v$ y, ~( }Next method as well as the following one are 2 examples from Stone's & k! o3 L8 N( C: b
"stn-wid.zip" (www.cracking.net):
6 w2 s* M. |5 Y5 ~+ v9 K# @; f. v/ r* y0 i4 [
mov bx, cs
$ N; c+ P o" J9 \7 W) F2 ~' } lea dx, int41handler2
r( X- D4 T1 Q5 [' J* C P' Y xchg dx, es:[41h*4]$ T8 g" ^5 z: I N
xchg bx, es:[41h*4+2]
; |6 ~# e5 w3 X) y mov ax,4fh
9 f' w) m5 |3 ]2 j- O4 o int 41h) w; R/ u; T, D; Q# i% u* R6 w
xchg dx, es:[41h*4]+ v# a' D b, A7 t+ y
xchg bx, es:[41h*4+2]
: F5 M' I" \' S0 F3 m0 g1 Q; Z" j( U# | cmp ax, 0f386h: B1 [: t$ D4 C% L$ k2 v$ b% f
jz SoftICE_detected
( R1 }7 R2 [) w/ L* l# {4 I8 J; S% ]+ M% W% L# f' P. F& A1 u
int41handler2 PROC8 d. |% R' I/ K1 g" a7 o8 h$ H
iret
7 A, u; b1 a) u5 |# [int41handler2 ENDP
4 j$ V0 l0 Q/ p8 [; w/ B5 J$ J* w$ e5 R& f% Y' v
! x7 X$ M1 j2 r8 O% N0 t_________________________________________________________________________+ C8 |. Z* m! U' z
# V) @5 R0 S8 ]4 n) e4 j; H: `0 ]% S+ b! J4 U( R! L. Q/ f
Method 06# S% K4 r8 i2 ?! y3 f/ B2 g
=========6 F {. h( }7 n2 C$ j- d
2 t: C: J! D( H! Z( \$ l& t3 i& b) L3 L" w- Q& m8 S4 X
2nd method similar to the preceding one but more difficult to detect:
/ S% `8 E5 C) Z c- k% I; Q3 B4 c) |' I2 X
* X. @' m" d8 p9 S; p/ \int41handler PROC6 e/ ^. a5 Y* o
mov cl,al. Y2 W5 S& _5 G& V
iret
, h" {7 O$ L/ V8 A- bint41handler ENDP
( M# B; T, t- b) ?; T- `: b# s
. A y6 X% D( n4 ]: H& Q o7 a! `6 x' i! J6 E: {% U V! z
xor ax,ax3 A% `' H: x! u0 Z: E3 |. ^
mov es,ax
- d; @9 k% ` p% m% N" `4 I mov bx, cs
% }8 k& I4 ]0 V! Q2 _ lea dx, int41handler
( X3 o6 p: f% d/ `8 M8 b xchg dx, es:[41h*4]
! O( n( I4 p' M' } xchg bx, es:[41h*4+2]! v8 Z" ~" J: W# ^2 {
in al, 40h
9 u U/ S; G1 a& \) P xor cx,cx2 q3 i9 W; [* M# C3 ^3 k# [3 C6 q
int 41h4 n! D0 \8 B# n9 R
xchg dx, es:[41h*4]' Q4 j6 z" O2 Z* M9 P
xchg bx, es:[41h*4+2]
- b/ @ |5 ~ z2 F0 H cmp cl,al, s2 r! ^: _2 ?$ w8 V2 {
jnz SoftICE_detected
7 q4 j) Q$ `3 {# k! \
3 O# W! L J0 k_________________________________________________________________________
# u7 X$ v2 N& d0 p) x: }
8 F: e( J) _9 LMethod 07
* a1 K: Q2 x! s) A=========
6 |( U* p* E: m* S% E' q- e4 p4 s
# s4 B- f6 |! d7 F/ B) {Method of detection of the WinICE handler in the int68h (V86)
; ^3 ^7 n) G) c/ q( m; b1 E" @# Z
mov ah,43h
# t# D' M) k# ^1 \9 u int 68h& t! y0 Z7 m/ }; F- }
cmp ax,0F386h
% S- i9 U, x8 I6 Z jz SoftICE_Detected
, [$ t+ j0 Z( ^& Q2 _3 |* e& w/ s/ U$ q" u# z
# u' x" ^ g; z* m n
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
& G6 L, U9 |5 i8 N8 x# [ app like this:
m1 e' |6 D P' v! q# n z$ F1 B4 i9 ]6 y6 K
BPX exec_int if ax==68, h; I/ O& [7 L, q
(function called is located at byte ptr [ebp+1Dh] and client eip is" s. _3 G! _1 b, I* k: e
located at [ebp+48h] for 32Bit apps)
0 n( O. I, O) O; s: M! p% I__________________________________________________________________________# K" \( B) ^; t* d3 k
9 j* K. v: }6 G. S8 o5 k" K' ?( \4 F1 D8 P' @
Method 08) f5 l/ \3 m) K7 s, y
=========
3 _& o7 D, E& s- w; n, w
1 o h! T% c" ~/ K5 mIt is not a method of detection of SoftICE but a possibility to crash the
4 S0 d% E9 B6 b5 R s$ Fsystem by intercepting int 01h and int 03h and redirecting them to another- O% R8 [6 @2 I- D( ?( c" n
routine.
0 c( I( G. e" d7 j5 lIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points3 s% _- n& `2 e
to the new routine to execute (hangs computer...)
) O6 ~# j2 `9 a# G Y1 L Q0 S8 [9 o% q( k0 H1 l& f
mov ah, 25h8 z- Z5 O0 \( N- o
mov al, Int_Number (01h or 03h)& y g& \7 f7 l) [1 W
mov dx, offset New_Int_Routine
; ?; O" L- t, c* q, x int 21h' E& P! P, x. I% t' j9 k
8 `% s3 {: I( I__________________________________________________________________________' o5 g& R/ e" n. q) y
8 ^; o h) v6 uMethod 095 a7 g) Z. N3 v0 n5 O
=========1 a- f0 ^" c. o) b t
2 t" S* h* ]! j1 f3 N; R5 R0 e0 ]% `
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
$ Y; o* C2 ^& ~, a9 _) ~8 f- D# q7 s3 y' Qperformed in ring0 (VxD or a ring3 app using the VxdCall).
4 z/ H. _7 g7 S$ W+ RThe Get_DDB service is used to determine whether or not a VxD is installed
0 ` c5 @& }# L3 j- `for the specified device and returns a Device Description Block (in ecx) for8 v9 H( p/ A3 z: {/ b9 I, C- T
that device if it is installed.5 ?0 l1 Y! ]! J3 }4 Z4 r. Z
7 X! X, p. I4 j9 R% y- y
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
' D' S# M, e* |4 T: p mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
+ ^; d( r9 i4 {; Q( T D VMMCall Get_DDB4 x+ m! u) J: z2 v+ t" M
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed1 Z2 z2 n" `- c, y. w# f, r& R
3 q0 ]3 k( I1 n. `* C4 S9 yNote as well that you can easily detect this method with SoftICE:5 d) I+ o# j% _
bpx Get_DDB if ax==0202 || ax==7a5fh8 Y( q9 D/ r" D$ R
% @: j( G0 S7 L
__________________________________________________________________________" _: e. E \8 O
+ B$ v1 c9 n' m& N
Method 10
8 B+ C: D: V1 Y=========
% h+ v4 Q& J: v
" e; l8 A) ~) q! N" ?9 P, l( |, _=>Disable or clear breakpoints before using this feature. DO NOT trace with
1 a! G a8 ]$ m+ N SoftICE while the option is enable!!8 ^ X( j, f+ @( v4 i. M
* Z8 K, w7 P( y/ A0 b" J: R8 fThis trick is very efficient:% u# P! Y0 r9 K D3 t
by checking the Debug Registers, you can detect if SoftICE is loaded
1 ~: p; E0 U0 S+ {. T" `, ^/ S M(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
6 r! C0 r) p) ?2 e" d7 A- Cthere are some memory breakpoints set (dr0 to dr3) simply by reading their% Y$ `/ S! `9 H2 g$ ~) C
value (in ring0 only). Values can be manipulated and or changed as well" w1 e2 K1 p# R
(clearing BPMs for instance)) s% t% J0 u: g. ]; ?
0 X3 i( n1 d* |+ d* u+ R' Z
__________________________________________________________________________
$ I! Z2 c/ w- \2 p( Q) I$ d) y$ w% `0 |7 R* h( j9 m% k
Method 11
3 k, s! }8 t1 t1 Q. c1 w( i=========0 x0 h2 F3 {' p! M% U! y% `8 p) ?- _
# t7 Q5 Q# j C" z7 gThis method is most known as 'MeltICE' because it has been freely distributed
+ U, t1 g/ U' K# H4 Rvia www.winfiles.com. However it was first used by NuMega people to allow, E' T$ J6 v/ B
Symbol Loader to check if SoftICE was active or not (the code is located! ^5 f9 m9 e( i% o( V
inside nmtrans.dll)., o+ s2 K" C4 R# a5 ^0 U% s7 K A" {
^* w6 l/ H/ d% VThe way it works is very simple:
: I8 N, u4 |& }It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
, }5 m7 D$ T3 ^( s8 q+ o( ~WinNT) with the CreateFileA API.4 [, A) q+ i0 A' _1 X, p
- E& t6 r5 c" XHere is a sample (checking for 'SICE'):* x/ `; y8 k) B) V& @8 C# {
6 X! }; ~/ j. z9 v$ X+ |6 l( QBOOL IsSoftIce95Loaded()2 v) Q; k5 s1 G$ g3 h( R- L
{
m8 T/ I5 ?0 P, e* P- l5 A1 g HANDLE hFile;
7 N! @* s' v, z1 B2 p hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,4 X1 F* ?) x5 ^( A w5 v! ?6 j
FILE_SHARE_READ | FILE_SHARE_WRITE,4 V8 u" ~& C% Y v6 L5 @ R3 q% `
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);! h, a1 q( C+ R( z3 ^
if( hFile != INVALID_HANDLE_VALUE )+ W3 [3 o' z' V7 v1 k0 M% O! t
{
& H3 a6 R( l! {8 o- }8 H; } CloseHandle(hFile);
" a8 {# {( _1 n return TRUE;' R; |& {& e: w G- Y
}2 ^; ^& Q: U- ^3 y6 I# Z0 V
return FALSE;
. p) z! [% @" i; V}3 y ]- J& T. x o% h
2 [# f, y' b6 L- Z: o* N( EAlthough this trick calls the CreateFileA function, don't even expect to be
3 i6 x7 d+ J! e& u/ W2 @4 Table to intercept it by installing a IFS hook: it will not work, no way!
' g) Y- f9 v7 S6 wIn fact, after the call to CreateFileA it will get through VWIN32 0x001F. |3 A5 j X0 U# Y( n
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)7 g" X. A: H Y# M: f8 s
and then browse the DDB list until it find the VxD and its DDB_Control_Proc1 S2 q0 j8 }* ~* e- T/ X% \" k
field.
! K6 ]. [! N9 `. J1 L" IIn fact, its purpose is not to load/unload VxDs but only to send a
|$ j- `' T* ~/ n3 vW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
- U- [, C7 f6 V; s- U/ `& }to the VxD Control_Dispatch proc (how the hell a shareware soft could try! A3 L) ~! V5 f
to load/unload a non-dynamically loadable driver such as SoftICE ;-).6 J- s J3 J2 `) C/ t
If the VxD is loaded, it will always clear eax and the Carry flag to allow L3 E5 ~1 L# ]7 O& I2 |% _
its handle to be opened and then, will be detected.
* {) i' @/ y8 E2 FYou can check that simply by hooking Winice.exe control proc entry point: C4 b2 l: K [# G y1 W0 J
while running MeltICE.
}/ _" }( f4 Y/ J6 _" ~% Q$ R; k9 j; p- {/ q U3 L
" j4 h+ I4 H) d+ m7 ], ]6 F. L 00401067: push 00402025 ; \\.\SICE
) F) d M0 _: i. I5 E 0040106C: call CreateFileA7 Y# o ~0 b# _/ m+ @
00401071: cmp eax,-001- u+ D; [! l3 k; g& T
00401074: je 00401091
4 r9 L% v2 h1 I
/ B% I/ I4 e; k3 R9 e7 R" Y; i: n6 J2 e# \: B0 m% @
There could be hundreds of BPX you could use to detect this trick.
8 i0 O( m2 G b; `-The most classical one is:
' ?) ~: S. z$ |0 \6 U% n BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||8 z" L6 h$ ^- G5 l" S* j
*(esp->4+4)=='NTIC'
! T3 W3 p* m% d: x! Z* j
- {# _0 x) |3 W8 i7 c-The most exotic ones (could be very slooooow :-(
$ p# R9 L! Z3 Y$ ` BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
+ v, Y$ h" B2 ] Q ;will break 3 times :-(
! r5 g2 r. o4 E7 y; Q5 A m: w& m
. t9 x) z/ a/ M$ q6 f-or (a bit) faster:
8 m8 E1 i3 D+ Y* t; y BPINT 30 if (*edi=='SICE' || *edi=='SIWV')' ?" A# l" ^) a8 R. h) r9 j
! f0 d3 F/ ^/ f
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
7 `) {. C3 J! K2 R( f ;will break 3 times :-(* S* a0 y4 m; o, C
: v; Q" t6 q" {7 @) x: r/ V [
-Much faster:
) S) C9 r" {# z8 B! }* S& n BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
2 ?3 ]" v, u# ?. P. N' x
$ E) Q: j$ _1 U$ f+ H1 M0 dNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
) U, Z: }( c& s. l% `# Jfunction to do the same job:
0 i1 H0 D$ k+ N& M" B* | M
! P5 U6 n& A! S5 y. [& T2 W! _ push 00 ; OF_READ: d% ?3 q8 A: l
mov eax,[00656634] ; '\\.\SICE',0! m* _* Q, V3 y* L4 A; i N$ N: s
push eax
/ m* r$ w7 H6 Y; t3 o" p. \ call KERNEL32!_lopen5 a0 ^9 J3 [; ?
inc eax" r* r, b( B' a5 o5 {9 {3 q( U
jnz 00650589 ; detected
9 I: D2 f9 ` D3 O. u push 00 ; OF_READ
# z" f3 G" Z, y9 j, V+ n9 B3 n( w( D mov eax,[00656638] ; '\\.\SICE'
; l. y9 n% Q+ @) @ push eax, z6 C8 N g, q; Y/ ~1 r" M
call KERNEL32!_lopen
8 A" g3 J/ g3 z+ U! x% U: A3 N inc eax
0 X* b ~& _4 O7 ^8 Y6 C jz 006505ae ; not detected
, O' |8 t4 H* Q, `/ U# i" {: t9 Y0 B
$ K6 Y( E, Z5 m+ U8 J! R' b__________________________________________________________________________" l! B9 ~6 ?" ? K0 n/ g
1 R% L0 y- j9 G x3 Y/ ?0 lMethod 12
; p. J% ]1 O3 |7 V, ]8 A; O6 T=========9 F8 b+ \* T$ I5 V
' E- R& f* ~: O6 v) c: K
This trick is similar to int41h/4fh Debugger installation check (code 05
2 m# g' ?0 N( }$ j9 W9 Y U& 06) but very limited because it's only available for Win95/98 (not NT)0 S( P7 x3 ]$ X9 M1 H
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
) Z! v' A3 A. ?; u7 h$ w' A/ B- l. c1 d3 o
push 0000004fh ; function 4fh
7 ^7 |% m. N; ~' {, { push 002a002ah ; high word specifies which VxD (VWIN32)5 q: p9 {, A4 F5 q: J
; low word specifies which service% u; s* o6 e$ V. A4 D
(VWIN32_Int41Dispatch)& q) s- z6 k# C4 O7 q
call Kernel32!ORD_001 ; VxdCall
7 X2 P, }; T( ?/ K- _% n2 A cmp ax, 0f386h ; magic number returned by system debuggers6 O2 q) I$ h% q$ G- w
jz SoftICE_detected" T0 m% |5 Y6 R! A! Y! N) b
9 C& N7 W( ]7 [& Q$ ~) A
Here again, several ways to detect it:
5 S, e' w9 J! v! |
- o6 `9 t$ a; \, M1 ^ BPINT 41 if ax==4f6 e; F% k0 f- c; M: h8 e; x
2 v9 \2 g- ?) M
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
8 K* ^$ w$ x3 `9 k& {$ ]/ Z8 _4 g- w0 W: ^. m9 g
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
- f* c4 {6 k% Y2 o! G! ~- B( p- X' z% E+ h
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
* o# N5 u/ z4 ~- p( G; Q. r6 h0 M X1 z) y* _+ N1 ~
__________________________________________________________________________
/ ]$ t5 X E8 n5 \* T
5 G' M1 k+ t3 ?* P( W/ ~Method 13 Q" D6 f- F9 J9 W: Q L8 ?
=========
/ i9 B* P2 g9 M+ R: y z; V2 j/ _# H
Not a real method of detection, but a good way to know if SoftICE is
- _3 |* {) I# u% f+ D" p8 s& ?installed on a computer and to locate its installation directory.
4 a, H, A: e2 LIt is used by few softs which access the following registry keys (usually #2) :
! i! c) v0 A8 C! t4 k0 s2 |# R3 {' ?. q
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
& Y! J% G: O: q; e5 q\Uninstall\SoftICE
6 z5 x" F% P; ?5 A+ w! p+ a+ p-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
; t+ d b7 C* l2 a: R: C& p }-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 U) J0 y: l6 d @2 z- G
\App Paths\Loader32.Exe
$ N8 V+ ~. m( C3 J- ?4 e5 y; [) G. X1 @6 p
# m1 T" `& F7 ^- J" VNote that some nasty apps could then erase all files from SoftICE directory9 c0 i/ w% J1 \8 C2 \ U
(I faced that once :-(9 _2 y( S6 q: I6 V
, O4 [! P- G/ Q" ~5 l% P$ jUseful breakpoint to detect it:6 v9 W5 m+ ^# @9 S8 n$ \
1 V4 n7 I% \. Z5 t4 X
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
; Y& ~9 Z5 L x: `1 Y2 E2 H! |4 \% E' M! P$ f9 v8 v4 e Q" u
__________________________________________________________________________6 b' X6 K7 X! l' F$ i ]
8 j( X9 u/ _0 T# z" D& b: V. \, D
" W; l3 Z. C4 _& kMethod 14
, X1 A7 M0 r) x0 o=========
: x) K$ w4 ~8 W# }0 z: U F( Q' x% K! Y& h+ M
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose/ f" t" i! K0 R. B% V/ M8 K& R
is to determines whether a debugger is running on your system (ring0 only).
8 w6 ~+ a4 u) E$ L
! I% j1 m2 }- J( z! R. S; s9 R VMMCall Test_Debug_Installed( Q5 |' q3 |% _' \+ {) ]5 P$ _
je not_installed
, V+ w& P+ [" r' m5 ?% A) ^% ^1 n1 u2 A) L+ m
This service just checks a flag.
" S) t; N, g- \2 p$ o# z</PRE></TD></TR></TBODY></TABLE> |