<TABLE width=500>
% A' A2 n* {( G<TBODY>
2 z! \5 r+ t8 V V1 b, q<TR>
7 J! L. G7 U2 x% M<TD><PRE>Method 01 / p9 W$ y1 o. K$ Y9 j0 b3 A
=========5 |5 p( a. q- f- Y
1 m+ d r$ P! m. u/ `) }1 c e- TThis method of detection of SoftICE (as well as the following one) is
- ]9 u& I& t3 R! Tused by the majority of packers/encryptors found on Internet.3 K5 @7 i" s; t0 D+ o; P- T* R1 s
It seeks the signature of BoundsChecker in SoftICE
( d; ^+ T) N P+ e+ u1 R
1 p. g1 c, R/ W( |' V: m9 _ mov ebp, 04243484Bh ; 'BCHK') g1 r- B6 d/ `) F& t( @
mov ax, 04h) n8 F/ B/ M7 M, v/ \3 i% G5 F
int 3 7 F* [5 d" }$ F0 g8 u
cmp al,4
+ ` a7 W% g' Y6 S4 |. B$ j' E( ^ jnz SoftICE_Detected
% N6 J+ p2 P9 T+ \% ?
4 k6 E7 H# P9 A/ {- ~___________________________________________________________________________
& M. y& d( P& V8 U @; h8 ~* c4 G, \7 m# @4 a$ }3 I7 d% `
Method 02$ \6 t6 Z2 A7 k0 a) A
=========
9 l& \! O* b4 [' B
. k. J Y+ C4 k8 K2 {; mStill a method very much used (perhaps the most frequent one). It is used
- C& P4 X0 m5 ?8 X7 o: B4 @to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
4 r6 f- v1 o( O! V* L- I& dor execute SoftICE commands...+ V. x, i6 G! X8 m; p. f
It is also used to crash SoftICE and to force it to execute any commands
7 n g3 b$ w$ C(HBOOT...) :-(( $ z) ~! G. I9 u5 n2 C8 t8 @! H
# e; R- f" {& z8 F
Here is a quick description:6 l9 x! |. S7 o' M+ P
-AX = 0910h (Display string in SIce windows)
; j) J3 c+ Y0 z$ e7 z1 q6 ^-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)8 F( G Q6 t6 f) |8 b
-AX = 0912h (Get breakpoint infos); y2 D V3 n& J: ^5 d* ~
-AX = 0913h (Set Sice breakpoints)
4 {4 w8 E5 _" I' W% `. }-AX = 0914h (Remove SIce breakoints)% U& [; K# |0 S) ]. t; {# [# ^, O
/ C2 ~7 G, l6 n2 MEach time you'll meet this trick, you'll see:
# m7 [0 k0 _5 Y, i! f-SI = 4647h( o$ {. s6 `1 ~# X A
-DI = 4A4Dh2 R5 ?: ^; x- h( }* G. r! J+ @
Which are the 'magic values' used by SoftIce.
' }) n: M5 c" G1 c# e$ O( mFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
% e% _! v# M" K9 l0 V% x3 @ T
2 `: ]* s. A7 XHere is one example from the file "Haspinst.exe" which is the dongle HASP5 n: r Q3 V7 }1 f. |$ n' f' `
Envelope utility use to protect DOS applications:
* @' L9 d1 t5 R) z4 i2 L2 @* w- u' c& a6 D$ m3 |) z+ \
, v Z, ? Y, n! x/ Q1 ~
4C19:0095 MOV AX,0911 ; execute command. L1 ?( J( ]* \* X' H; J& i
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
) t# e: }( b( Q1 w4C19:009A MOV SI,4647 ; 1st magic value.0 }1 m1 ]8 m# J5 R" g6 K
4C19:009D MOV DI,4A4D ; 2nd magic value.
+ o' A! m+ W5 U% l. c$ F4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
* }! c& G a* y e8 v( v4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
* Q' N% L! | |. S3 g! Y9 n0 R& m4C19:00A4 INC CX, H! | n- R# ~7 }4 i: q
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
6 {& e8 S! {$ i) o1 D) ]+ A4C19:00A8 JB 0095 ; 6 different commands.
H/ M2 N! I+ ]" c4C19:00AA JMP 0002 ; Bad_Guy jmp back.
; _0 |+ M7 V/ W& A" T2 _0 \( O2 J1 E' M4C19:00AD MOV BX,SP ; Good_Guy go ahead :): _: b# \0 w4 h0 y
3 m5 e4 A$ _, Q/ d
The program will execute 6 different SIce commands located at ds:dx, which/ |( P$ Z1 K, A5 Z P
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
# A, l5 r* T3 q: V2 J9 d7 _' w. O! X% r
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
, Q3 n0 J/ h% L8 s t+ Y___________________________________________________________________________) S/ n- L, R) O7 W+ L
: E% ^4 N, Z" N$ @: m, E$ a/ X4 m7 h) ]/ E' `
Method 03
: D/ \ [/ K0 j& Y4 U=========0 p L4 g2 X) ?& t
# s: H6 P U7 z* {
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h* U; R1 K" ?& S. _; O
(API Get entry point)
5 @5 o$ l, D/ `; V W$ W; s : m9 X) U& E4 P# S6 b; N# V
" @% ~+ [( U8 e4 o7 N/ K xor di,di
7 l8 o' H. B) p$ Z1 Y mov es,di
" D6 k, s- i3 _: S/ F8 r1 y mov ax, 1684h ; Z0 g( ?' i+ s& k+ \% O
mov bx, 0202h ; VxD ID of winice0 ~' [4 S* z3 [( ~ D
int 2Fh
8 X$ g4 _1 _6 n# {- N( ~ mov ax, es ; ES:DI -> VxD API entry point2 N8 y/ T7 c& B; G1 B. k1 d
add ax, di
5 {+ i- ^" [& a7 B \. i5 f% G7 M test ax,ax5 z( D& x! w5 p/ a# c a* @
jnz SoftICE_Detected
0 Y* @, H! T) o! V, X7 ^
$ ~& K' F8 G5 A5 R6 z' \1 M0 O___________________________________________________________________________' `, N5 d6 n$ C5 r2 p6 `
' w. L$ ]) B( J7 {( b: d
Method 04- a# Z9 P" e7 z3 e8 P9 F/ {9 o
=========
) T/ Y& a F8 j3 e6 j5 v" a' A
2 I* Y: K& a b* UMethod identical to the preceding one except that it seeks the ID of SoftICE; B% A- [1 D9 F. ]( j, c' F; [
GFX VxD.
# `1 j) l7 W/ ]1 w! C" v- H: f" R
: }, q6 U) [* o9 t xor di,di" e" N8 d p' b1 |7 G- k6 x
mov es,di
5 x4 ]2 G5 a& `( {" D mov ax, 1684h
$ Y. [/ m! x( T7 L) e mov bx, 7a5Fh ; VxD ID of SIWVID4 U9 n1 o. {7 w% ~; q
int 2fh
. j% Y0 R1 ?/ ?9 k# E mov ax, es ; ES:DI -> VxD API entry point% n7 L" }8 x+ E1 j5 x" g
add ax, di9 v" d( R8 b5 T0 X- r7 R$ h+ a- p
test ax,ax
7 {1 Y$ h, w: C+ a9 A jnz SoftICE_Detected
& _6 c6 ~; O5 f
2 Y" L. ?, l2 e% m& f5 n3 ]__________________________________________________________________________( b. m7 Z5 a" Y4 R! q" _0 t6 `
" g* K( k& S6 k
3 E. W o( ?/ ?, h- l4 d+ NMethod 05 \7 M/ z2 ^6 q* J) H
=========) `2 y" }! C* P2 o( F: g4 P% p
+ v" _' l4 A) |' G* }Method seeking the 'magic number' 0F386h returned (in ax) by all system' t' m* E3 p5 D
debugger. It calls the int 41h, function 4Fh.
$ ?, G2 _: U! ]: ?3 kThere are several alternatives.
; F5 f! b* c* p0 b
2 W. s- w0 D) H! k6 zThe following one is the simplest:- N/ k3 D* ?, L, U( O9 S# c
$ E+ X$ }! b1 t2 Q
mov ax,4fh# G7 `" ~2 ^" E$ T' }6 |
int 41h [ \3 _ h3 G* V7 \6 T
cmp ax, 0F386
0 c0 \$ G+ u6 W2 @- _& X jz SoftICE_detected! G# A s& r( O: @/ c
1 E7 a% J: _, `* q, q U- `; I$ n# c
2 Y7 t4 j6 g" B
Next method as well as the following one are 2 examples from Stone's & o/ {9 i. c6 Z J1 A' a: v
"stn-wid.zip" (www.cracking.net):" [+ U C0 e7 d
' a( Z2 G+ w1 t+ ^
mov bx, cs2 ?2 l$ N+ a$ @
lea dx, int41handler2, _) Z5 B: l( c0 J) s; H+ v" x
xchg dx, es:[41h*4]% ~# u9 `9 o, D) x2 e& \
xchg bx, es:[41h*4+2]
: Q1 t: _5 w: h& \ mov ax,4fh
" m+ {# u9 W: v int 41h- E0 P& I& U4 j5 F" `9 I
xchg dx, es:[41h*4]9 [' A: x+ h; L S/ `' F
xchg bx, es:[41h*4+2]
& r: @6 G# r- T. O: P! l cmp ax, 0f386h
j+ I( R- h) U, B6 ] jz SoftICE_detected
% I( k; O9 @) s. I
* V, X. m# J- vint41handler2 PROC
7 b h' u. n4 s0 p" x6 k5 S5 P iret
. Z: r; C- s0 y6 f$ V+ ]int41handler2 ENDP! n% k) r1 s$ J; z. F
. J! [4 S* X# k- L8 V' C
6 W2 ~+ o0 D* U4 W8 U' O_________________________________________________________________________
4 W( |8 m4 w$ x
4 [2 s$ I% y+ ^# }" x! i# r0 U5 Y# \: X2 k, k$ y5 s
Method 06" d% p* i% I" U+ s' r8 g
=========
3 i5 u, z6 E8 G- a
5 b1 Y( X! s" m* K" ?) a9 ~1 C" ?- J3 @9 T6 T9 d! P+ A2 ^
2nd method similar to the preceding one but more difficult to detect:
' F; B" { S# d$ ^9 J) o7 [: m+ a
* ]+ r& O! \( y1 T) a! G$ C* Z, b: W `0 [
int41handler PROC- a( m' W. O9 ~
mov cl,al/ N2 r; \! C8 N( y6 T* C3 q0 j- |3 `
iret
2 S7 s9 A6 x6 B& O# }int41handler ENDP7 a6 [4 H0 e3 s7 t
1 [+ Y0 k. a9 X% ]& z8 k
5 `& U/ o, N& N2 B9 L xor ax,ax
: O0 n* X# X5 q3 q6 T! h mov es,ax+ z% N+ f3 P7 r6 [
mov bx, cs
# ]; [, ~% [/ J0 X lea dx, int41handler
" N5 S8 v' U5 L xchg dx, es:[41h*4]% Z1 P* }5 f) w3 Z) M3 L9 ~! b. Q
xchg bx, es:[41h*4+2]
* U; i$ T2 W0 [) d& u in al, 40h5 z4 `2 p1 Y# b4 r. Z& |# h$ }
xor cx,cx
' V+ Z+ U# c8 M5 Y# F int 41h
( ?$ k3 z: {+ h xchg dx, es:[41h*4]0 C* y/ `: ?% J3 b2 G( i+ @7 X
xchg bx, es:[41h*4+2]
5 K" `3 O- J2 q( ~$ z# q4 u cmp cl,al* U) r, I( w/ Y( S" u, B
jnz SoftICE_detected- @) Y: ~5 r3 d" f! \
+ ^; H, p& p% N' h: j/ c4 D8 T! }_________________________________________________________________________
3 ]. J. l( @, u" ?
/ B1 C. a& L7 E+ dMethod 07
4 f1 t1 F( i7 \ p+ b) X _=========
7 G- ?! v$ j9 M' y( z
: U b0 B/ A$ @, L3 u7 t' lMethod of detection of the WinICE handler in the int68h (V86)
) [$ b! I/ W1 [, F3 A
: q1 p& ?: Z/ p5 J& Y- |0 d mov ah,43h& o, }. Y# m3 {' h
int 68h
7 e7 B6 R5 j* m; q cmp ax,0F386h% d& V$ r9 Y" ~
jz SoftICE_Detected* H/ H% E: q" ]) {* z
6 N& V" g0 }" H# f) y% o2 p; s
4 y2 E6 }( S1 K# [. [=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
4 T( s5 O, [4 c app like this:
/ s1 f$ A. [7 ` A3 e/ A+ D; ?
7 N# Y" N' G! Y" j BPX exec_int if ax==68$ f3 }$ w( n) V. p' @) W
(function called is located at byte ptr [ebp+1Dh] and client eip is
@6 Z/ q/ p: R& }8 g1 ^2 x% E located at [ebp+48h] for 32Bit apps)# }- h& D, b; f6 U
__________________________________________________________________________
! g" a1 i8 ?0 F' ?8 H% [6 T- |% l( h; Z! z
. `1 L( G) {" K, c$ FMethod 08
( D6 t& t" E6 s$ T=========
3 D2 o, E B3 h8 K/ s# `- F3 o$ [
It is not a method of detection of SoftICE but a possibility to crash the( K9 `& [" L* Z0 r7 T% `
system by intercepting int 01h and int 03h and redirecting them to another) @9 E: D H/ [0 v
routine.! N K2 e/ d/ g; i
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points' C1 g" b- B5 O) | p& @, b
to the new routine to execute (hangs computer...)
& ?3 U) m }$ N2 B$ U1 f
0 W. l3 e& c! N; n! c mov ah, 25h3 t' n) B8 ^" a( q/ A
mov al, Int_Number (01h or 03h)6 C6 k* R: E/ N
mov dx, offset New_Int_Routine( z" H0 A( x9 ?/ Y( u4 Z0 u* T
int 21h; i! l; C$ }- `$ ?- O
- q; B" \) R5 j+ Y! S* C__________________________________________________________________________( f- e- _, p4 Q l# g+ ?, Y
5 Y5 P3 ~% Q+ SMethod 095 X0 X" j; {- m# ]0 ?: z
=========
6 n$ R; `/ Q/ P) L
# B# I2 L4 W x3 _$ S) sThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
% A( |$ v# d& H9 U, P1 K7 rperformed in ring0 (VxD or a ring3 app using the VxdCall).. Y. q% y9 H `' Z- g
The Get_DDB service is used to determine whether or not a VxD is installed
- d8 W7 p0 ]. |8 \# |for the specified device and returns a Device Description Block (in ecx) for
, R2 u8 d: i3 u$ mthat device if it is installed.( N$ K6 u" s5 V! J! |' A
/ j- O% S- f7 N- g s
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
4 @. e" o! _9 p7 E0 y1 S* Q mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
, {$ @. F/ }8 ~2 @; x' E VMMCall Get_DDB
+ R" z( I3 N9 s mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
2 i* g8 A! @* K' W8 d$ m
$ E8 Z6 s |, k7 ZNote as well that you can easily detect this method with SoftICE:
8 T s2 e% P1 I0 E6 p5 U8 G3 H bpx Get_DDB if ax==0202 || ax==7a5fh
1 d& I9 H; d; ? G X: A
9 Q3 W2 ?! r4 R1 j7 u. [. G2 I__________________________________________________________________________
6 P! }! |7 E% h& s" V- F
& ?! m2 v) L9 h5 L, w- dMethod 10
$ C( x0 W" e5 z4 g+ u=========- g% E5 z5 v* l, n+ y f' i3 Y
) C& w5 x8 Z; c. Z( U1 Z1 z=>Disable or clear breakpoints before using this feature. DO NOT trace with
+ q; k5 _! B. H SoftICE while the option is enable!!
, z3 M8 c7 J7 E. n8 m+ ^3 S0 D# s
+ n4 a$ [5 |/ T' U0 }8 l6 [This trick is very efficient:
0 B$ Y* N/ A, R3 `7 [by checking the Debug Registers, you can detect if SoftICE is loaded
l W6 _/ J8 {* C(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if' C# d. x1 D- t* T9 v% ?
there are some memory breakpoints set (dr0 to dr3) simply by reading their
! D# L% Q, b _ N/ G6 N. _value (in ring0 only). Values can be manipulated and or changed as well
' j! [! D- p8 G" I2 B- q. o0 k7 A(clearing BPMs for instance): I Q. H4 `2 Y* I. s
$ E: z- S9 [3 S7 `# c) f
__________________________________________________________________________
- Y! p' c. O) o
) A/ \# s! i3 o: [9 h" a' MMethod 11
' W E4 S6 T8 n8 L3 Q3 A0 }=========
7 {( u5 ^# I3 s+ \* Y" g; h7 G' o- R9 t$ x( z6 K. Q/ }( F
This method is most known as 'MeltICE' because it has been freely distributed A O- c h# y9 ?
via www.winfiles.com. However it was first used by NuMega people to allow
$ L$ ]! I6 o0 Y8 z2 f5 g# wSymbol Loader to check if SoftICE was active or not (the code is located
- B" w# O* H5 M$ Q! Cinside nmtrans.dll).
$ e1 r/ O4 K$ P0 K6 h
9 J1 j; y/ v! }6 ZThe way it works is very simple:8 }! f, [. C' G0 `/ Z! G
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
9 Y |& _$ i. eWinNT) with the CreateFileA API.& g& W0 b% J9 E1 f1 M
W# X- J0 g% Z2 h$ K7 m$ ZHere is a sample (checking for 'SICE'):: N+ I J+ z. F
- }5 o: h6 y& X% U* RBOOL IsSoftIce95Loaded()4 H0 r% F) p' X- ~& v( F2 Q
{/ I) L% }( ^) P7 w7 U; e7 ?7 f
HANDLE hFile; 2 m. g( M' w( ?3 g
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
& a* p) Z' @0 i& k, ?% ~% m FILE_SHARE_READ | FILE_SHARE_WRITE,
6 N2 q- Z, ] Z+ I8 _0 Q# h3 v- H9 g NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
/ o" u$ S2 a4 D, U5 l if( hFile != INVALID_HANDLE_VALUE )
( t) {- g7 v+ d# L! D6 x {
- _7 ]' U# B0 @$ c, y6 T5 t1 q CloseHandle(hFile);
3 e% F h9 V* I' q; J return TRUE;- _& \6 k/ f8 _# g6 A5 n* g, k
}# d6 N2 S/ Q$ ]) J
return FALSE;
. f% M+ g8 M; X6 S1 e}
0 M& _, k0 { Z% g$ k1 ^4 }$ B+ ?3 \1 ^# J+ C ~
Although this trick calls the CreateFileA function, don't even expect to be- n$ f' L1 B1 N8 Q, A; T
able to intercept it by installing a IFS hook: it will not work, no way!
- ~ _7 b' p# _In fact, after the call to CreateFileA it will get through VWIN32 0x001F8 l' i$ ~, {5 }; b+ C
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)8 K1 L- L4 h, p J8 t
and then browse the DDB list until it find the VxD and its DDB_Control_Proc/ T* k+ O- Y8 B' A
field.
% e I# {6 \! [- k) gIn fact, its purpose is not to load/unload VxDs but only to send a ) ~6 g8 P4 ]" |6 V! U
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
* f- d6 x2 h: K3 H% A& J# ito the VxD Control_Dispatch proc (how the hell a shareware soft could try+ u3 E, E2 D( |1 S2 V$ ^* q, k
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
& V, L# w E7 a: r k* ?If the VxD is loaded, it will always clear eax and the Carry flag to allow
! [& D! T- c+ o2 Dits handle to be opened and then, will be detected.3 z6 u7 ^5 |: f$ h
You can check that simply by hooking Winice.exe control proc entry point6 y1 |7 G1 d' Y1 J
while running MeltICE.* l$ I2 t# Y3 t# F3 J
: _3 }" L# F( ~, O, z2 R% S
. L+ l4 T F# S# U
00401067: push 00402025 ; \\.\SICE
& ? G8 w0 g4 L: e 0040106C: call CreateFileA7 W2 |5 i; R6 T
00401071: cmp eax,-001/ b" d$ w* r! } w7 Y) C( k
00401074: je 00401091
; J9 Y' X7 N* z: G
; W4 [/ M) ^' [- y, v& y$ o$ U5 {9 \1 y* Q2 A
There could be hundreds of BPX you could use to detect this trick.
9 ~5 m8 d3 f! b) x-The most classical one is:5 D$ g1 p" G$ ]: c
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||: \1 Y* \' d) ~7 v( v1 N7 X
*(esp->4+4)=='NTIC'
2 W) J* G/ l4 M1 W! E2 G
- o! K" y, v" U X: ~-The most exotic ones (could be very slooooow :-(4 ]% ^) Y6 n- Q5 D: V& e1 J' f
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
( |- B" ]$ E$ A* { ;will break 3 times :-(# E9 o* X. Z$ c. f+ F2 B; ~0 J
* _6 }* f2 j/ E) p- `+ x-or (a bit) faster:
d, q5 K( ?- ^7 z- F BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
% g& `/ Y( }7 H; ^+ P. w: L) J1 L8 ]0 f r/ A
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
! Y8 w. G& t2 x0 Y, F9 x! ?9 a ;will break 3 times :-(
; R, H' Z. |5 B8 X0 ]& C* [ u7 }, r2 @' J2 e3 T: ^2 G4 p: m
-Much faster:+ J5 T8 F( d- M. D' ~+ u
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'$ N. C5 i' g8 E6 _& ]+ z# u
4 K- R9 D* O2 S! v; UNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
! U* ^( O8 N( F& N5 J1 Z6 Ofunction to do the same job:) {) v& J% Q! `1 ?' A) t1 C
# ^1 b! l4 w8 V2 k4 ^7 K
push 00 ; OF_READ
- [: R* ]$ Y7 i. e% H mov eax,[00656634] ; '\\.\SICE',0; g5 ~; F5 S, y2 h: ]3 ?2 e* K( J) v
push eax
/ j+ R. U2 `% Q+ T! \. B call KERNEL32!_lopen& L% j- s2 {' x! A& W
inc eax" [ r+ M3 u8 S6 F
jnz 00650589 ; detected, U& \$ }# I1 L* D$ [( \8 @/ u
push 00 ; OF_READ$ `7 X4 a% @. E9 k
mov eax,[00656638] ; '\\.\SICE'% l1 \/ Y7 p- z9 k4 U
push eax
0 {" B1 P4 R8 Y" E+ O7 p call KERNEL32!_lopen
% F6 ]; h! L I# j$ z inc eax
! ~4 H) C1 q/ i9 x2 b5 L jz 006505ae ; not detected- Y- w N2 t! A& s M
/ b5 L1 w3 O* O. @. o3 e$ r+ z1 E* h
3 P% K7 W, [7 T& b. ]2 y5 j
__________________________________________________________________________7 x1 w( C4 m/ o4 f$ Q! ~
" K; p' e' I7 p+ Y5 x# v' @Method 12
; B6 n: H" K% b0 z/ f=========! j1 N3 e+ x: e/ d% I
# u" r( v8 S( p) M" p; x8 F lThis trick is similar to int41h/4fh Debugger installation check (code 05% n! N" O& M" @6 u; l7 R: s
& 06) but very limited because it's only available for Win95/98 (not NT)7 T( E! `2 o8 q; S
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.3 r$ ]2 d8 S+ X+ f, @
% `/ X( F) c1 W q/ m' Z
push 0000004fh ; function 4fh
3 o; a" z" S9 d push 002a002ah ; high word specifies which VxD (VWIN32)
9 N _& U# W+ |1 j& ]0 M ; low word specifies which service
4 c& w" n5 s9 n7 Y" Q7 h& V( R& M (VWIN32_Int41Dispatch)0 q# ?6 s- N3 ~" d0 g/ Z# m
call Kernel32!ORD_001 ; VxdCall
1 p$ x) w/ v& k- ?; U% a8 b9 a cmp ax, 0f386h ; magic number returned by system debuggers
6 s0 L+ M# s5 I) f8 a1 z* c3 M$ y jz SoftICE_detected+ K) E7 j, \! z2 j- } ^9 L
: Q/ r. K1 I# s& B! G9 y
Here again, several ways to detect it:5 @" R! Y+ j% \/ K
4 R3 M; ^& V& |) |" V# N* O' P1 g' r
BPINT 41 if ax==4f8 Q/ B! X4 o" E1 Z' Z1 Z
- U6 H) @: A$ @% d" X, z/ _
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one( x9 D* E9 F$ j" y/ e8 c! o; f
" q9 h& Z; J/ H BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
4 H/ T6 B6 B; @+ D' i" c
/ L- j, t$ C$ G( T8 l BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!) W) H6 c2 Q* l% F: k
, B7 l4 e7 s4 e+ ^
__________________________________________________________________________
' e7 I% I+ x7 L# j; g
* P5 q1 c% p$ G1 U) vMethod 13
7 `* U% Q. }! _ W5 ^. _=========
5 H- h; |8 g2 p$ @7 P8 a4 h& d. i1 A. t5 {+ Z) {0 P/ u
Not a real method of detection, but a good way to know if SoftICE is' U# e4 I1 ^3 d3 |% p0 _: ]
installed on a computer and to locate its installation directory.1 I7 U! v2 { J n+ @9 A1 }0 l/ ]
It is used by few softs which access the following registry keys (usually #2) :
6 r7 G' k2 p' q( X3 @. x
, F/ f6 ]# S, k7 n-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 I' o/ T7 f+ n L
\Uninstall\SoftICE! N, O8 @8 N" O6 m9 z
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE! }/ b$ e0 {, b" G5 L
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion0 k- A; ^5 e$ s, Q# g. k
\App Paths\Loader32.Exe
: s! K7 c3 b% r3 i- q C
% U" h5 E* I; ^( C/ ~+ E- s
6 ~# n/ x! l1 g' W( S: qNote that some nasty apps could then erase all files from SoftICE directory
5 [+ j+ H! L$ g" g0 d8 C. g0 M(I faced that once :-(/ \1 k1 }. T! ?; \
0 l+ {' ?( ^" |5 p4 ^7 Y4 ~. ~Useful breakpoint to detect it:5 y7 |- u- i+ |2 {+ m4 b/ h
5 q* j2 A8 x' Y9 M BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
# s3 Y o, ? |; q# d( U8 h+ }1 i n' }/ x, T
__________________________________________________________________________' u2 v3 Q0 H t/ `1 }
2 c. B5 b' B/ d8 o
/ i# y& r9 c. z& f9 z* u, U7 g4 gMethod 14 4 [8 j' D% @- `* h6 A9 y
=========
3 c% P( m. [4 Q8 T4 w- B8 B/ E
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
" ~, q* T6 \4 o* T) Fis to determines whether a debugger is running on your system (ring0 only).5 Z( V% {& r( y7 C' ?) o
; K( v. w4 r) W5 k
VMMCall Test_Debug_Installed2 X4 \$ d3 h4 w* ~4 l* p# x
je not_installed0 V: k, V; {( W
9 T, l& P9 M) O4 J6 @
This service just checks a flag.
# ~) `1 i+ X: N</PRE></TD></TR></TBODY></TABLE> |