<TABLE width=500>
[5 f& \5 Q: S" m<TBODY>7 |/ W" l6 v. X, ]5 k; c
<TR>
5 w4 H9 A& O3 h" |<TD><PRE>Method 01 & D: a/ z: Y! H3 C
=========
9 B t! `& S0 r! I! N8 A, u: B; f1 |( z7 Q
This method of detection of SoftICE (as well as the following one) is0 a, M! s9 i7 t) O7 J H
used by the majority of packers/encryptors found on Internet.
4 P6 @9 z0 a; c+ w: A8 k8 y# vIt seeks the signature of BoundsChecker in SoftICE
# \6 h4 i- S9 W6 W6 v$ c" O, E4 \( s0 H7 t3 x) \3 y8 m/ ~! H) m
mov ebp, 04243484Bh ; 'BCHK'$ P2 M+ V( x$ _* R- ~3 \8 [: c3 C8 \
mov ax, 04h
" o/ K% y$ ]9 Q( ~ int 3
4 @& x" b9 A# q# S; w) e. G w cmp al,4
- s" ]# c+ b4 _7 T0 } jnz SoftICE_Detected
% L- d& T: T3 |) N
' {, q# p* `- z___________________________________________________________________________
2 D2 H0 D& I) z0 C$ F* T! t u% ?) ?& {
Method 027 j* q! q& |: j+ o `
=========$ K; m6 |7 B& h3 E) v8 A; Z3 j
2 Z8 P3 {' d) H5 L4 a1 o* A0 @Still a method very much used (perhaps the most frequent one). It is used9 V9 J* j5 ?# _7 a; ]5 w, M- A
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,0 P( }3 j9 Y$ }' o6 L; c5 }8 K3 ~
or execute SoftICE commands...
9 {; n' Z9 o8 K. t! UIt is also used to crash SoftICE and to force it to execute any commands/ D6 _( f3 V1 A/ s6 u. H
(HBOOT...) :-((
6 T# [2 f8 N1 n. p( T5 Q
0 f* [0 {+ B& [ i$ Y9 J6 mHere is a quick description:, C, V& ~. d/ g) X9 z5 H
-AX = 0910h (Display string in SIce windows)
# v% J$ Z$ I9 P& m3 H/ x! @-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
. w( t- D4 B. o-AX = 0912h (Get breakpoint infos)& J. Y0 x- V' h
-AX = 0913h (Set Sice breakpoints)
* n% n# X& T: k+ |( c8 U0 F( r; R t-AX = 0914h (Remove SIce breakoints)
- d' M5 p0 D, y- y# m6 L
( Q1 G2 j$ a" ]' XEach time you'll meet this trick, you'll see:( `8 ^# {: ]6 w, J% n
-SI = 4647h
2 m2 v/ q/ }4 H8 n$ G, M3 y$ F5 U-DI = 4A4Dh0 V- x$ q ~7 Y
Which are the 'magic values' used by SoftIce.
0 D# E4 j' F7 M+ m- }" F& F# pFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
9 E" q5 H. X4 ?' [( u+ y1 P- U8 v1 Y4 b
Here is one example from the file "Haspinst.exe" which is the dongle HASP
. u" s; n/ ? CEnvelope utility use to protect DOS applications:
9 n" _+ r5 U' @4 X
* q! Q t- {8 G {1 m5 S4 Y3 P1 a
4C19:0095 MOV AX,0911 ; execute command.
$ z1 ?2 n2 h3 D7 p! c, S2 I# F4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).3 w/ F. Y2 v3 y1 x
4C19:009A MOV SI,4647 ; 1st magic value.% l+ B( C$ x& ?/ B
4C19:009D MOV DI,4A4D ; 2nd magic value.' P! Q/ ?# K. W8 Y, X+ }6 p2 F
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
# O# H! R/ v0 m4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
- \0 t' d7 M2 |' O4 v9 c. M4C19:00A4 INC CX
' X& e4 b1 p7 H# K% s8 T4C19:00A5 CMP CX,06 ; Repeat 6 times to execute5 j! V' Y( h, m) ]1 l
4C19:00A8 JB 0095 ; 6 different commands.* n' L6 \* I) M. J0 {4 I* j
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
& r! s% i( V6 V6 d& A- \' m" V4C19:00AD MOV BX,SP ; Good_Guy go ahead :)% b5 C, u( h) [% y- Q1 [9 \' ?
- [/ z/ Y' _' o
The program will execute 6 different SIce commands located at ds:dx, which. d0 A' ]5 [/ d! C1 Z3 V
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
1 S c5 R6 }+ N' }. H# n# O* o" v# F- |' U
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
8 ~& G3 d6 c" `: _; X___________________________________________________________________________
2 ^3 h$ t/ C4 t3 o0 N+ i7 d
, f% {. V! m/ `0 ~0 m3 N; k/ v; Z- c4 j: w. S9 F
Method 03! ^2 q: e2 d4 Z( |! i& j
=========" e8 E7 c0 \" l( l6 M
, s! B3 O) Y) `2 v1 l
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h( q* d; L/ O% }) J: U
(API Get entry point)
# ?( R. x6 i6 A8 v5 I! j. T
& t0 c5 g& _) R6 P/ C1 j8 l) p2 K
xor di,di7 |& p, N6 f; \7 y! r
mov es,di. `; N2 a6 r% @
mov ax, 1684h
! `0 R7 `; p" U! Y mov bx, 0202h ; VxD ID of winice- \4 f4 O4 c# W, ?' x+ Y
int 2Fh) P" \9 R/ L! U. b. k" M/ X
mov ax, es ; ES:DI -> VxD API entry point
5 F, e- k9 p4 N7 @$ _. `/ R9 n8 A add ax, di: r/ x# ?$ U9 @2 S
test ax,ax. ]' R i8 Q6 K. @. H0 Z8 K, @
jnz SoftICE_Detected% \$ b5 i8 P# J" P5 W: E5 s
( x% P% z2 N( Q3 W: ]) p4 u' \ a
___________________________________________________________________________
8 {2 X% B/ d+ ~' `# Q- Q/ K) N* J1 G& l: E
Method 04: |4 D, x2 z6 t" i
=========8 \, D0 e2 P; h! `9 u7 d3 v* O2 m
. U2 i0 w* @/ q6 p c/ d& m3 ?) z
Method identical to the preceding one except that it seeks the ID of SoftICE O7 h3 \# U' z* P. M1 q! k
GFX VxD.- D$ H" ]: W- y2 }
* d A1 M. e1 P4 A: ~/ B
xor di,di
5 W9 ^* ~- y) `8 H o mov es,di5 m3 ?4 g8 N' G v! z% p9 L9 j+ p3 k( Y
mov ax, 1684h a8 ^1 C, x7 o- @# v. _" L* n5 ]0 A
mov bx, 7a5Fh ; VxD ID of SIWVID5 e+ J0 E: ~! h' y( Y' E( @' ~; T
int 2fh" I/ h _1 l5 U# v# [
mov ax, es ; ES:DI -> VxD API entry point
( ?6 y: S% y) R# k add ax, di
6 ?2 ?* F F1 a/ S test ax,ax
: d5 |( s& y8 S# T jnz SoftICE_Detected8 }8 j: A( t) s% {/ `
" ]8 T! H0 p+ \+ ~__________________________________________________________________________1 w; \4 L3 O3 [" F h' w G6 Z
& n: O2 d6 p3 p- I) J
& q! @2 h2 T: x
Method 057 A2 N' ?# S$ e3 x
=========6 P; c/ `/ x, [- T
* ] Y! k4 x; }9 l _! @' qMethod seeking the 'magic number' 0F386h returned (in ax) by all system
! I/ i4 Q: w+ y; c& w+ Xdebugger. It calls the int 41h, function 4Fh.8 d9 C e, o7 W# p
There are several alternatives. . `, g4 W" y5 L/ f
; V. G8 C) Q$ H( u3 @
The following one is the simplest:" [ j' ?4 Y( |( w1 @. g9 c' I
" W4 E7 s+ B* k1 I mov ax,4fh# ?1 _" Z' u" T$ }" H
int 41h6 a% @! j" j) e8 G. H t2 x6 M
cmp ax, 0F386) c5 J6 w2 o' A3 S3 t9 m
jz SoftICE_detected
" r" w# C& `% Q1 _1 u2 b2 ?
7 c% U1 k1 E! [5 n+ N. H9 d6 o8 g" i5 y& k0 c
Next method as well as the following one are 2 examples from Stone's
- Q j& ^. \1 d7 l6 o8 v( ^, U; j; d"stn-wid.zip" (www.cracking.net):+ ^! W; v1 J. T3 L) `5 Z+ w
, D- W8 L5 ]3 f, i/ z
mov bx, cs$ l# ]' k# g: ]
lea dx, int41handler2
2 t6 _( p m1 P. e6 u3 F xchg dx, es:[41h*4]1 |. v% Q; t& R
xchg bx, es:[41h*4+2]/ p9 t* m4 L/ U( Z
mov ax,4fh
) t6 F4 z$ V0 w9 H1 K3 i9 B9 q int 41h
8 q8 f1 Q# l9 f% M* H xchg dx, es:[41h*4]' N% S" S' G3 o2 a8 y
xchg bx, es:[41h*4+2]
9 [$ D3 L- H9 ?/ q; z O cmp ax, 0f386h
, T( B( q' d% a# s7 c5 v# y+ n$ ? jz SoftICE_detected! s0 j! P" d3 |% Y8 W. P- s
7 _ P% k1 H7 {: W1 @int41handler2 PROC
' W; B+ P& ?9 y8 K iret3 O: }$ z( a+ d$ ^' X
int41handler2 ENDP
8 G% X$ e2 ?1 r' Y
0 ]5 P4 k- I- S; x, u" W8 M* T- J: B; T
_________________________________________________________________________
1 t5 D# u0 _. ^1 |+ @7 h% S7 }) E6 B5 p9 R- S! Z d1 v1 D6 {5 H
2 h g- _" T4 O3 ]# E
Method 065 W7 I9 C2 q9 C# V2 p# B- G, ?
=========* a$ b9 P, ~1 B! g' q& B) j
! G- h8 g# O( C5 k, ]6 [$ C, `
* ^: w9 X+ w# M4 {5 m4 H0 V2nd method similar to the preceding one but more difficult to detect:$ U, m+ U1 b$ g
' w! p/ u m& F, _3 a
: O, l1 {3 Z* q8 Xint41handler PROC
, X8 \; y% N1 S" E. T; S( j; O mov cl,al
; V: Z8 D7 b' L! v9 Y iret
0 U# W3 V1 W7 k& {. W" |: Q& wint41handler ENDP
4 Z0 j0 p* I1 H; W( N, s
8 M7 o4 F5 `# u8 t0 n$ J1 _- g" | h! e5 k! b1 u
xor ax,ax
7 X8 d5 t) F4 s3 W' O mov es,ax |+ P, A( r) g
mov bx, cs# d3 E* E: V7 o7 V
lea dx, int41handler; y' `/ ~ T3 q0 w* A
xchg dx, es:[41h*4]
+ S" O; M) N6 y+ S xchg bx, es:[41h*4+2]
2 ~, ^* `! P! t8 _' ` in al, 40h l! Z+ g0 O& G" Y7 n0 m/ N
xor cx,cx- a' u) T6 Y* c" l. K4 F' _
int 41h
6 s6 S2 `' m5 x& b: f1 Y; ] xchg dx, es:[41h*4]1 ? A& m' u2 x, T$ V) p: W$ p
xchg bx, es:[41h*4+2]
. g: A/ I' }6 E) v cmp cl,al2 p2 o. d3 x+ }: E, P& O
jnz SoftICE_detected
. r$ o+ o( G$ U! ^0 b6 N8 n, g# C7 Z
_________________________________________________________________________
$ f+ D" P' ]" l+ w
* l# |& r; T. Z- k* ^$ {Method 07
# y, O: f% E9 [ Y=========
" T/ q S$ Y% |3 `
, c: n# q {( F: J- B, A6 y" ]6 H I8 TMethod of detection of the WinICE handler in the int68h (V86)
7 J" [- N( I% @/ F8 t
7 ]3 h' E! B4 R) k+ h2 c mov ah,43h
, \( s8 ?! L% V int 68h0 B+ K" [' |& R' {9 G+ {$ b
cmp ax,0F386h" n8 r2 S$ ~5 f; E0 y P
jz SoftICE_Detected
( Q, ]7 J( i2 M0 Y, ^: }& M5 ~
7 g6 [; m9 i; B2 m' O
1 S/ Y, _. g5 C& n* `=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
j! K( _5 J$ f% x4 w8 x app like this:7 ~5 s9 i7 b# k2 [! S
* u+ Q3 ^( ], f& b- Y7 ] BPX exec_int if ax==68. ~0 o. v9 l# F
(function called is located at byte ptr [ebp+1Dh] and client eip is, B- o1 P* k7 Y& @9 G/ M+ `
located at [ebp+48h] for 32Bit apps)+ l2 u% e& s& V, ^7 B" S
__________________________________________________________________________+ ?7 a/ w9 G7 f2 y* k ~7 M
2 b7 ~8 L1 f, T( j
6 b+ B x9 ^. o, KMethod 08
& y9 e3 K) q' h=========9 ]: E, _$ ~. ~) e
. B: L. a+ K6 [% c8 z8 Z( T
It is not a method of detection of SoftICE but a possibility to crash the) F: b1 l/ S0 G, }/ t
system by intercepting int 01h and int 03h and redirecting them to another# Y; l1 [9 z0 y- [$ D$ b; f
routine.
' F# q( X' a4 i. T0 B- }It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
; d: e L; B9 x. |/ a2 D9 G5 \/ eto the new routine to execute (hangs computer...): ]1 {/ v2 ~ C3 z' F3 J: M
% {& |9 X3 k8 Y, b, @" g
mov ah, 25h7 }; ^$ `5 H/ d7 o
mov al, Int_Number (01h or 03h)- |$ @" B+ H$ \) e
mov dx, offset New_Int_Routine6 k& F# ^$ j: N: b/ j5 {- W% \, h
int 21h) f5 d7 T$ u, h- E
6 E1 ^- g- O+ s4 Z6 O# i# l$ w
__________________________________________________________________________
9 J' v% o$ |* l# s# F2 k* L4 M# O% E0 M5 y- }* c% h2 J3 L2 N- w) |
Method 09
/ t+ X, t' p5 `& d# k=========9 U E. s9 {# ^$ e
- u% i' w1 R7 R- V- }9 XThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only+ u) e- v$ ? W
performed in ring0 (VxD or a ring3 app using the VxdCall).* w* n% U$ Q* t I0 s5 m
The Get_DDB service is used to determine whether or not a VxD is installed( s- X5 N n1 p( j$ h
for the specified device and returns a Device Description Block (in ecx) for2 [* [# O9 B. k- Q( {5 h, R" r1 ~
that device if it is installed.! i7 q3 t+ i; }* H- ]
8 H! \# t# t2 |" A" K, q4 M mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID9 x2 o( n, P$ a2 n4 y
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-), }% N, V& G' [4 v. T
VMMCall Get_DDB8 _' ]! }9 m% h1 g. K6 p6 f( M. O
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed. ^1 ?* t& U5 o6 F: {3 D7 D
& s: v7 K J3 x: oNote as well that you can easily detect this method with SoftICE:1 k" `& Y" k/ |/ z8 {$ ~# F
bpx Get_DDB if ax==0202 || ax==7a5fh6 E4 A* w L) `+ R: l# \% F
d( M' c, {3 N% ^: `( u
__________________________________________________________________________$ R1 ?5 j1 Y" `, S" c; l% X
; ` t5 d& f6 U. u2 mMethod 10' X8 d* D. S8 L3 \
=========/ L9 J+ b* U( I( o9 E5 x7 \0 \
' D4 Q I6 N% \2 m( e+ K
=>Disable or clear breakpoints before using this feature. DO NOT trace with7 | l: L Z- O7 u. c) K
SoftICE while the option is enable!!' E" w% D6 B1 ?
1 M3 t6 F8 t2 w- ]3 _" m* tThis trick is very efficient:. F: o9 c( i. I! }: K( S8 {- O3 J
by checking the Debug Registers, you can detect if SoftICE is loaded% a1 z% ?' G2 w
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
2 O7 K2 ?4 \7 U4 f" mthere are some memory breakpoints set (dr0 to dr3) simply by reading their; I7 Q7 s5 A$ u6 V q
value (in ring0 only). Values can be manipulated and or changed as well+ o. E) t) N% ]+ j: s7 I. _ E2 a2 B
(clearing BPMs for instance) c/ i, ~5 G9 v! s' l
^4 ~7 T3 l. ]$ J$ w" v* |& `__________________________________________________________________________' z1 Y6 w0 i- ]
) v3 Z4 G7 _7 OMethod 111 b% l. m$ P: q5 R' u. _
=========( E2 c- E6 \; M; Z8 h& x
& P, R9 X: A9 ?# W0 O' _7 e7 Z
This method is most known as 'MeltICE' because it has been freely distributed# ~8 [0 ~8 ]8 `! d# |% k3 @
via www.winfiles.com. However it was first used by NuMega people to allow/ T0 | t1 a- w2 N/ T8 c
Symbol Loader to check if SoftICE was active or not (the code is located+ ~3 M; @: x/ }; ^6 i& O( w ~; L# ]
inside nmtrans.dll).
& A8 ^. s9 I0 f& N% |' O7 j7 ~( w5 I
The way it works is very simple:2 |" ~' B6 y( W0 t
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for# i9 z( F/ `: U! d1 {: b2 s
WinNT) with the CreateFileA API.
) g, d" X" Z; d1 T( w1 ~" ^. u
* ~# y1 V& o9 _; M7 P0 P9 Y/ T9 G( iHere is a sample (checking for 'SICE'):
3 n- V7 X3 O" t' ~. Z
0 _2 N' m1 M- w% [8 P8 T! V- IBOOL IsSoftIce95Loaded()8 W& h+ J0 i* Y; d7 `4 _( k
{' J: F. ?* w9 g+ s* B/ F! N# F: ?) r9 P
HANDLE hFile;
* K5 W$ O9 ?; x- {# u hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
, w! a: M) q+ E2 U$ O% j FILE_SHARE_READ | FILE_SHARE_WRITE, F: t/ z" {% l* s: m) G3 x" I4 m
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
4 I+ P# p' A/ W- l# W" j if( hFile != INVALID_HANDLE_VALUE )) N7 Z4 B: p% Y& X* [! ?
{2 w- P9 y( C) M
CloseHandle(hFile);2 x/ j, a" k/ H" y1 e P4 o
return TRUE;
1 c; l6 Y l! i( t: D$ F }, T3 @0 P7 ?" J) }& G0 R# V; ]
return FALSE;" N* L6 b) o4 n I% I
}
/ s* U" F8 {4 e! a( H
/ S& H% v1 q: ?6 V- GAlthough this trick calls the CreateFileA function, don't even expect to be. S" J0 q8 l; Q- h# E7 u% X
able to intercept it by installing a IFS hook: it will not work, no way!3 R$ g( q8 @1 ]6 a- ^- [
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
6 R6 b0 e b% M* Sservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)& p. ^9 t% k1 Y6 W
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
4 X2 A+ o- H9 ?field.. q9 l |, T$ e* Y @& y5 T/ \
In fact, its purpose is not to load/unload VxDs but only to send a
+ t1 \0 r: X! k; y2 qW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
3 E0 w" U- [! w7 i% E$ q" {to the VxD Control_Dispatch proc (how the hell a shareware soft could try
7 c) \2 L# A2 w& ?, Gto load/unload a non-dynamically loadable driver such as SoftICE ;-).! V5 F; T6 P' t6 |0 ^# O+ T
If the VxD is loaded, it will always clear eax and the Carry flag to allow
- `# p* q0 C! P/ P6 S/ c% Qits handle to be opened and then, will be detected.
2 n* k6 |+ w# R5 ^You can check that simply by hooking Winice.exe control proc entry point
1 \6 j" f: \- p* ^1 z9 e6 _while running MeltICE.9 A* D S2 c! W8 P( O
; |. Y- ?1 _/ O( Y: r. q
2 J% w& Q6 n: P7 _
00401067: push 00402025 ; \\.\SICE
# Q5 j' {* K2 Y 0040106C: call CreateFileA8 a3 s/ l: M" {& ~6 H
00401071: cmp eax,-001
B9 ~4 P8 L8 x 00401074: je 00401091: f! p7 @0 Y [' b2 D
- H6 O, G1 T4 F* `; h# o! ]: I) b2 {# k
There could be hundreds of BPX you could use to detect this trick.
3 r4 `/ O2 P$ z* ^-The most classical one is:( `* c' d/ P2 P% ]* X- R
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||8 d) ~1 U {+ {& C- w
*(esp->4+4)=='NTIC'
1 O; K6 R+ r# y
9 w' L* v' ?1 [* `-The most exotic ones (could be very slooooow :-(
7 \0 {% z( k. i6 i7 o5 D BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
) z: a* I# D; H2 e) A ;will break 3 times :-(! M' c& d+ v5 T" \. |' z
" w5 R, g: f4 U5 M-or (a bit) faster: . p' }, Y- S) L: q
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
) t" a5 ]2 ~) ]5 `3 V$ a+ ^, x. |
$ @" `9 F0 i& R4 y. r BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 7 Z# ]1 G/ h0 _9 @! Z
;will break 3 times :-(& o6 Y- B1 [7 b7 W# V- Z
/ v5 s5 G+ |$ V& L) |1 Z( ?/ F1 L-Much faster:4 Q1 J8 x" w# B0 L: h8 t
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
4 q) ~, o1 ~* S) M! d5 j' P
$ g2 t0 b% j+ J; `7 ^Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
2 @; e$ J& s }7 zfunction to do the same job:
* c w! J( a2 q, R, R" A6 r/ f
8 a H0 j6 N' _$ y* C' g5 R push 00 ; OF_READ4 u) e4 |" _# G" ]
mov eax,[00656634] ; '\\.\SICE',0
4 b% R3 S+ X0 Q7 P push eax
- L! L: K3 e3 Q6 j call KERNEL32!_lopen+ x& I; ]) }6 P0 V
inc eax
( X7 [- p+ A$ Y5 n2 @ jnz 00650589 ; detected- k* Q, z( S6 d; z- ?2 U9 o
push 00 ; OF_READ
6 ?) J; V( ~& \% S. i mov eax,[00656638] ; '\\.\SICE'9 U6 x1 T0 @2 g& n# D/ N4 z
push eax* ?; y0 n r; O& v& D
call KERNEL32!_lopen0 m' R8 e6 y" e" j1 t0 x4 f/ b4 M/ K
inc eax
0 P7 T/ A1 k9 F) Z9 G \& P1 I jz 006505ae ; not detected" y$ r' M* ^/ J* o! Y
. J+ r5 n- x( @& i
9 r7 S* L0 s1 g7 F4 D) K, i__________________________________________________________________________. }+ F1 z4 I/ F& q
* U1 ~! |1 Y. U% ^4 r) v9 eMethod 12% h+ o. W7 m" ~: K0 h) E$ d+ y
=========
! N9 S4 w B2 D7 ?; h1 `7 q2 Q0 j) d, q7 K2 M; g5 J9 S" T; ?
This trick is similar to int41h/4fh Debugger installation check (code 05) A6 s" i# k: u; k
& 06) but very limited because it's only available for Win95/98 (not NT)
4 B' f7 {! C; n: K9 R) _) p3 was it uses the VxDCall backdoor. This detection was found in Bleem Demo.
6 a R& L% P( K1 J. }9 q8 n/ m9 j: A7 U0 G# \
push 0000004fh ; function 4fh/ n) j0 z1 Z- H
push 002a002ah ; high word specifies which VxD (VWIN32)! f2 A4 A+ z! h, f
; low word specifies which service7 ^5 U5 i7 j" E2 m
(VWIN32_Int41Dispatch)
: A( N5 n8 h& M5 v" T$ b3 M0 m call Kernel32!ORD_001 ; VxdCall
' C4 m/ A# ~- t$ h cmp ax, 0f386h ; magic number returned by system debuggers
! b) H+ Y# M' m2 U4 M jz SoftICE_detected$ H) E# w# p. ]9 P' d$ j X9 k+ ]0 t
7 u, C# Q; W q: Z5 c& UHere again, several ways to detect it:
# B* E, E/ B2 X$ p) O* D0 N2 d
8 K' l# ^ x7 ~. }9 b; Q9 o BPINT 41 if ax==4f
( p& J3 s5 T" W8 i2 b& A4 r; J
$ {0 \# F& p8 A" U# q" d BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one! D' }4 I7 `! C8 d' K
7 e b2 w* @( r# { BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A; ]1 l3 @3 ~+ N" ?' s
. [: R# d: F+ T2 O% x) q4 K) d BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!6 @! L9 k! P9 }" A4 _ f
4 v2 n5 r/ O6 g4 {' S__________________________________________________________________________4 ] p6 F7 y0 |, I
0 C1 ]' I1 b: _6 B4 Q- y
Method 13
9 y" |2 p8 A+ r=========
2 A, v, e% _9 ?) f8 ~9 C. F2 S
. t! E0 R9 z* b; e7 R' I# SNot a real method of detection, but a good way to know if SoftICE is* i4 K- W$ l3 V+ v9 ^" q+ C! x9 J& f# [
installed on a computer and to locate its installation directory.4 |5 l Q! P# r7 q$ A; R& h; O
It is used by few softs which access the following registry keys (usually #2) :% f# k, f) q! F: B
' i$ r" ]% L6 Q% D2 o' \
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion; p4 w; ~- H+ z# w' M
\Uninstall\SoftICE2 m l& D7 u [: Z
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- a" L( S$ ^1 @0 w9 P( M- R-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 _: q, u7 i& G2 v; E V\App Paths\Loader32.Exe
& a& Q! w. g; j- e
8 B0 n8 Z! o; P$ i: ?! g s7 P$ O$ T# j
Note that some nasty apps could then erase all files from SoftICE directory6 D- U: i5 y/ U4 S* M. @! j8 U0 s3 o
(I faced that once :-(+ R G+ u% [0 ?: X
0 B3 V2 a2 g2 q
Useful breakpoint to detect it:
9 s! d! i$ U; i( `8 Q
( U5 N$ J/ Y/ L) M. ^ BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
4 x! l/ v6 A3 e, F! M9 J
e- }/ u6 x$ O. n__________________________________________________________________________4 x8 J9 h: S4 }! L
! H6 M: n# i8 X) ?; t# G' |+ Z9 j
+ T7 Z2 I1 L# R/ `5 t; ~Method 14
9 @$ g2 P3 O4 e* `3 H=========
, c1 I7 h" }: C r! r9 F8 x7 }5 w. x) M' [9 m
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose! e* i9 W" i7 K# w+ t; w. B
is to determines whether a debugger is running on your system (ring0 only).
* K# l7 _! m0 j# a& `9 {7 G- X5 K. k: O- t5 x
VMMCall Test_Debug_Installed
9 y4 {* L1 A0 A' I3 \- C je not_installed
: ^9 X# s d0 ?% Q% `8 {& l3 O" q. q5 @0 [; L& w
This service just checks a flag.! N/ J3 L3 Y1 C* g2 i
</PRE></TD></TR></TBODY></TABLE> |