<TABLE width=500>/ `: ?+ u2 a. F
<TBODY>! ~* B' J9 e7 q3 P- A, z1 ~ o
<TR>; S' `" @1 x. t7 y1 z0 {) k* {! Y
<TD><PRE>Method 01
3 b( c( Q: @4 {4 x6 o% d8 B=========
/ w6 ]% F% _; }' Q' S, K7 v
. s+ K$ w! K: n/ JThis method of detection of SoftICE (as well as the following one) is8 `5 Y L* W5 d1 {1 t/ C$ l
used by the majority of packers/encryptors found on Internet.
" B; l! r1 n. N6 WIt seeks the signature of BoundsChecker in SoftICE
3 y& n6 A+ T0 c7 u. X. h$ o9 m# u4 c: u: W% q2 w
mov ebp, 04243484Bh ; 'BCHK'4 L' ~0 K0 q7 A. S8 i' t: B
mov ax, 04h. c* T8 X7 U5 B0 K5 N6 @
int 3 5 j) ^! d1 h5 _1 f
cmp al,43 G; y4 ?5 ~) r
jnz SoftICE_Detected1 K6 Y$ D4 T: G# `/ P0 y
- T& ~5 \) }5 ^: v- E
___________________________________________________________________________ w; E5 J3 Q Y4 y
) N* q' f, F' M& f; o! X
Method 02
$ ~2 _& P1 C* S+ A/ O& t! d4 K=========
# d, ?) n6 G2 r+ [& b0 v; L
3 ^) d* n. ]- z3 UStill a method very much used (perhaps the most frequent one). It is used! S; A$ z u1 [2 Z7 X8 r
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
2 V6 L9 n0 {; ?, {or execute SoftICE commands...
9 Q3 B7 ^3 n7 Q. _4 W, GIt is also used to crash SoftICE and to force it to execute any commands c. T t- z, i8 j& s) s
(HBOOT...) :-(( 7 h3 l/ H# ?1 P
' }# c& b% e) E5 S T5 BHere is a quick description:/ O' g& I: A$ U: c" Y) P
-AX = 0910h (Display string in SIce windows)% l5 W0 @8 r/ Q% N
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)0 Q) c' l4 N$ p
-AX = 0912h (Get breakpoint infos)8 t/ }! A' j/ p1 L: ~! S# M6 S$ k
-AX = 0913h (Set Sice breakpoints)
* U( _, a) h* B, C/ Q [-AX = 0914h (Remove SIce breakoints)6 |% s+ e$ ?- W0 a5 p5 G2 o
7 D& Y: Q! K: E: HEach time you'll meet this trick, you'll see:
: i6 @( x3 a4 X5 L5 g-SI = 4647h
S. Y7 i5 G6 |/ \-DI = 4A4Dh
. @8 q+ i! {. Z9 Y6 |4 MWhich are the 'magic values' used by SoftIce.$ y! L! y5 ] G) @; F% ^! R% ?5 [# h, H
For more informations, see "Ralf Brown Interrupt list" chapter int 03h., o& I3 \# I, Y; a! ~. d
3 I* C" e* I) o) i. _. u
Here is one example from the file "Haspinst.exe" which is the dongle HASP6 s8 V& b( v% |8 b0 T l
Envelope utility use to protect DOS applications:
% y, D+ _9 n8 w% y2 R* D* Q
( U, j, I' ?; g# N8 D8 L3 Y
3 y# n2 t7 `! g8 k2 i+ O7 P9 Y4C19:0095 MOV AX,0911 ; execute command.- K; L; Y, I* @; Q
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
8 O( Q. w0 h) S4C19:009A MOV SI,4647 ; 1st magic value.5 s N" f% e; A7 W
4C19:009D MOV DI,4A4D ; 2nd magic value.; S o( C8 {2 N
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
0 F0 r# D0 q: }" p9 T9 ]5 ?4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
: K# `. y N, t8 O4 H& |4 Q4C19:00A4 INC CX, V3 {& h: }! U
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute5 J; d2 g2 ?* f
4C19:00A8 JB 0095 ; 6 different commands.
* K! A! p) w8 F/ r+ j4C19:00AA JMP 0002 ; Bad_Guy jmp back.
6 L- H$ i) \: V! a5 j4 O" y! { x4 M4C19:00AD MOV BX,SP ; Good_Guy go ahead :)) B7 K# r1 T3 S* J+ |
: P S& R. M6 h# K1 ?* r. v
The program will execute 6 different SIce commands located at ds:dx, which; e9 E! O4 Z! j# _- o; Y
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
* ?2 V% C8 m! w7 g+ j, X8 [: O! p h
" ]. f0 W$ v; D. e9 F7 q* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.8 K4 ~' R) n2 j/ r
___________________________________________________________________________
8 _; H: o5 J# D' R4 r/ w# ]# ~: k2 S' i4 |5 [) _! f/ a: W; _" H
0 k! q" J( d9 F' D1 w y- ^' hMethod 031 N% s$ r+ Y% r7 L/ ^8 M( g
=========! u* ?1 o. p5 X
; {# v( m4 J2 {6 gLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
9 {4 ]& @# W* B(API Get entry point)
; y, p# ]! M2 }: p9 P( m- a / v. [2 g- g7 B2 F+ ?( J! D
* S9 X+ b5 e% T, ]$ ?1 c xor di,di
: r. W* h! T: C6 \9 u. j$ N8 l mov es,di
( G' }% s8 e9 \* x! S mov ax, 1684h 1 O4 O3 S2 ?- r. \/ W
mov bx, 0202h ; VxD ID of winice
9 Y' H% E7 X8 l, T1 J int 2Fh
9 i5 x2 C# F) A2 X% }, q, l mov ax, es ; ES:DI -> VxD API entry point
+ j; m) O) G$ D& ? z. k add ax, di
! S8 Q3 R$ d. c M3 G* P0 j test ax,ax }9 ?: F$ D0 i
jnz SoftICE_Detected9 N+ ?0 H7 Y! m. R0 P* e3 l' [+ M
2 D4 P/ J* S) y# X" f \% u
___________________________________________________________________________( ^8 u4 X6 ~8 m* z( a+ B# [
! {3 h0 h; R6 f2 {- WMethod 04
3 Q7 f/ ^3 p5 G, a/ G=========
+ v( }: }9 C# b
9 W) f& l& s" C! Q0 tMethod identical to the preceding one except that it seeks the ID of SoftICE
/ o' ]% |, k! W9 l5 [1 FGFX VxD.
+ n |. e$ M8 H% L& q4 z. p
) n5 b4 O" J9 _/ S5 p5 { xor di,di
0 g5 m/ R6 H8 j! n& Y mov es,di( v, W5 @" F( q" a+ K b5 x& j
mov ax, 1684h V2 C' _: O% u3 q) ?
mov bx, 7a5Fh ; VxD ID of SIWVID
4 `5 t: a9 H4 l6 Z5 i int 2fh
4 h$ X3 }8 ?5 [: G0 v mov ax, es ; ES:DI -> VxD API entry point# K5 N/ i# W _, p9 N Z
add ax, di
6 ^1 S7 L, p4 }9 E test ax,ax' g% V; j, T# c# p; x
jnz SoftICE_Detected+ W8 J, \& z3 q
" A( v% {( y7 m8 q2 y# X. J7 r
__________________________________________________________________________* B; O0 _: p7 Y" j' P( s) o8 `
0 h# ?6 i% \3 z7 v, N5 l" y6 A/ _3 P4 }/ A0 f7 k& G
Method 05
& {0 }, p: H9 {/ X$ _8 P) F* Y+ v1 R=========" S6 l1 L* P, P+ h+ _ n& M
3 ]- u4 C9 Y, \) \3 |8 A
Method seeking the 'magic number' 0F386h returned (in ax) by all system
9 k+ ^% ]7 {/ adebugger. It calls the int 41h, function 4Fh.& V! v0 s$ Y$ K! e. k: C; T
There are several alternatives. ( W$ [3 a% J2 N) \9 w+ I- `
; T7 `" ^' i* [6 F8 Z6 K- fThe following one is the simplest:
; d3 H- B0 l/ @5 e2 j- P d/ G$ C! d5 i1 {) E
mov ax,4fh
6 |0 O5 p( b7 @$ B! J8 W/ t' z int 41h# u1 G) T8 v- \$ o# y
cmp ax, 0F386
& o! {9 q* g0 p" I9 U8 g# j jz SoftICE_detected. Z u. C" W/ o5 }4 k8 d# t7 S
- f2 P$ H2 Q" M1 }- Z
+ V1 |! F- C: ]0 f8 J2 yNext method as well as the following one are 2 examples from Stone's
! z$ x$ h# n# |9 }! d"stn-wid.zip" (www.cracking.net):: C5 n+ t: E' \- P1 Y
! m- d5 G, K) q4 G8 a1 l
mov bx, cs5 a- N6 e2 w8 o/ s. l: C8 Y
lea dx, int41handler2- m3 i; H1 I# J% v! P- ~
xchg dx, es:[41h*4]
' H5 Q2 t ^/ B7 d xchg bx, es:[41h*4+2]9 o1 j4 x6 ?! t
mov ax,4fh! [& i" c! [7 ?
int 41h) o0 O% m: w- R7 M t' \1 d
xchg dx, es:[41h*4]1 S% M7 g& q0 `0 }
xchg bx, es:[41h*4+2]
6 J" H( `8 S* ?& `- e cmp ax, 0f386h
9 u& M1 g& A! H5 }4 a7 w jz SoftICE_detected2 b0 }; @' M* [- E
% C, `) c2 I# I" e! F0 L
int41handler2 PROC) r+ N* Y+ ?& S( E& t) y9 W' Z
iret
- ~6 z' u) x$ N2 H" ~# p6 x0 L' gint41handler2 ENDP
# q. ?9 B# s) Y( q& Y% m8 O8 B0 v+ w% ~ }
: F9 {4 s- Z0 y: [# \; w4 |' x0 W, M* t
_________________________________________________________________________
: X& U9 X3 Q" H7 c$ s
) \- ]: y6 e' M0 v5 q9 K3 c$ G1 E7 \# a. v- L+ F. `0 z6 u
Method 066 H9 y# X! A" G2 B4 d8 r0 x$ U
=========* X3 n' }( |& r+ m# ^' J; j1 j
. n; h, S1 R: y: _* V8 z% U g& F ?* q2 Y& [0 }5 W$ J/ T
2nd method similar to the preceding one but more difficult to detect:# u; g9 v4 O' k
- M: d% V' ?" G/ X7 r+ O" [% s7 }9 C! }4 k' W
int41handler PROC
' z3 L% s- u! k mov cl,al
3 v6 b/ A; b1 W& L2 L iret
& T- q) p8 k( o8 K0 F9 Zint41handler ENDP
" C& ~: W$ `' A1 A
8 K2 ?, E2 J# x/ }2 R% G" K. B# q* h4 F, h+ S( ^
xor ax,ax
e5 `, j: C* s' G- x* u: t mov es,ax
; x& Z- N7 P0 I; H `& `; q, b mov bx, cs
+ X" E9 ^$ C( p9 q9 z0 Y lea dx, int41handler8 N% g7 X0 V! w3 v5 ?! a
xchg dx, es:[41h*4]
) D( I9 _, O7 r% C5 g xchg bx, es:[41h*4+2]
, m" O0 E9 ]3 r. l% Q" }: p in al, 40h. X! r6 Z9 f* n" i8 H& [1 O/ V
xor cx,cx
3 \4 r. D. M2 Y) ?: y) E/ n int 41h
' L) o, k+ G& ^) W4 L8 g% N: U- ~ xchg dx, es:[41h*4]5 C5 g2 `- u7 k- O( q% y4 {
xchg bx, es:[41h*4+2]
9 m/ }8 Y e& B* ]5 r( A6 B7 }* m$ ^ cmp cl,al
, T2 {' S d) p, w jnz SoftICE_detected
) o6 L" p e; w" \& X5 M
7 `# J, W$ K9 W_________________________________________________________________________
1 W" b* x+ z2 A e# r% W
; [; A5 ]; r: ?1 C% [Method 07' [' ] [, D+ y: Q7 X0 S& ~9 y+ ?
=========
9 [5 A* C, D f' H4 n4 G4 [7 r! ~8 u5 w+ D, t7 t5 A9 I1 J5 X% U8 _
Method of detection of the WinICE handler in the int68h (V86)
/ y' T$ L g7 C7 d' c) ^5 x
* J" p% n! Y% V; N5 ]0 {% g- \9 C mov ah,43h
$ z) q* b& g. X2 d: V5 o$ w. P int 68h
1 r3 B% b& Y9 g: h4 B cmp ax,0F386h
9 j) K9 }7 d/ h, Y jz SoftICE_Detected
2 x- ~4 y2 O- y1 }2 i4 Y$ u$ e8 s
! Q) g n7 }2 K
" r4 `8 D# _& E0 z. n=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit9 @! s% B/ c" F- }% d$ W# P
app like this: G3 j; A6 d3 r! G+ B7 D
0 T, C* ~8 T7 k/ d9 `6 i* d0 h
BPX exec_int if ax==681 [3 D" f4 q- m9 h! I* V
(function called is located at byte ptr [ebp+1Dh] and client eip is
( z: ?# Q2 q0 P; o located at [ebp+48h] for 32Bit apps)9 s, l- s, z9 Z3 v" S3 V
__________________________________________________________________________7 f @: N5 z' C" Y: }* z: O3 A$ ?
$ ^& Y9 u$ D; L/ L& V6 z
% O/ F6 n6 Z8 h! p2 u" MMethod 08. u+ Y1 X, f! M! o0 p
=========( O& z2 y" @/ k+ Z$ X
$ V2 Y& f$ N) E+ ~2 M, C
It is not a method of detection of SoftICE but a possibility to crash the9 D8 P. Q O Z; S4 C' V, p! |; U: Y: T
system by intercepting int 01h and int 03h and redirecting them to another9 V( i* K6 x+ R3 R" R8 @- p' t
routine.1 q4 u/ I3 w% I& m( v1 F, q
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points( |8 `% h D9 K( y
to the new routine to execute (hangs computer...), M1 F$ R: I: a# N" y& o0 _
9 |7 O& ~. c/ B% b/ f mov ah, 25h
. E8 N) I4 F8 Y" d7 r7 O mov al, Int_Number (01h or 03h)
6 L- O/ x K' p4 O' k2 ^2 D J mov dx, offset New_Int_Routine
' T# W" R# @0 \# ]* J! g9 w: {; C int 21h$ @; a" I/ R4 s: A- K" p" d
# Z6 w0 \" T$ b; N
__________________________________________________________________________
' `; D7 B' R2 P
4 h+ h$ j( j* z7 P+ tMethod 09
; @; K3 I3 [9 A=========
; z( q- \# c8 G! U5 n
, w" o0 f$ o* QThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only4 B9 k) q5 s b% `2 E$ e: T
performed in ring0 (VxD or a ring3 app using the VxdCall).: Q- P! e. O0 ]. i* z
The Get_DDB service is used to determine whether or not a VxD is installed
) V0 x! o3 D: A+ Q4 x/ f: ]for the specified device and returns a Device Description Block (in ecx) for
) x8 A: U9 r1 K, H( Xthat device if it is installed.1 Y2 C6 N4 M" [0 {# h/ o
8 k& a- s6 K$ Y" S% r+ o mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID+ D- Q) _# T7 y
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)% |# [% \0 G, Z: p6 W) @' q
VMMCall Get_DDB4 M. _. p) O/ @& Y( P, [$ {
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed* ?, P2 r: g# o0 X- r; d
9 g r: r: W3 ~5 Z2 j4 eNote as well that you can easily detect this method with SoftICE:! R4 M& I% q) W6 c8 c
bpx Get_DDB if ax==0202 || ax==7a5fh2 P6 @3 c) U# B
2 P J' {# B/ ~. u
__________________________________________________________________________. c5 Q! w2 Z: c8 O" b3 b0 b
. G+ E' o) {0 u& v/ ?9 ~! @0 hMethod 10& w+ o1 p: |: o- w
=========
A9 Y, d, J3 a% r. V# u2 L8 E
1 p6 e! J6 ]/ O! ^( {=>Disable or clear breakpoints before using this feature. DO NOT trace with
) I( I% ~+ O5 q1 q SoftICE while the option is enable!!3 L3 C6 R6 W9 K. ]
" U- B# {# ?2 WThis trick is very efficient:* l A, c$ x7 k2 b% C
by checking the Debug Registers, you can detect if SoftICE is loaded
/ b) k8 h4 s) Q3 d8 x6 g' k(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if A, d1 J7 X, h9 P7 k% t
there are some memory breakpoints set (dr0 to dr3) simply by reading their% n+ c) \4 f9 e, P# N1 g
value (in ring0 only). Values can be manipulated and or changed as well
! y! m4 y6 ]" @ w(clearing BPMs for instance)) h, Z- {) Z; c
7 h' q. J4 h; }/ y
__________________________________________________________________________
. E! V! W' {0 }; S2 r4 W- H0 ~) W3 B; V: \, @( f/ g- Q% f
Method 11$ {8 f4 p2 u. M0 v! F
=========
( o9 V% O E- Q" ~+ o) m9 \ d# r1 j2 D5 G. b( y4 A, p
This method is most known as 'MeltICE' because it has been freely distributed" [1 Z8 I2 L& C+ h
via www.winfiles.com. However it was first used by NuMega people to allow i2 p+ D; O2 L- T
Symbol Loader to check if SoftICE was active or not (the code is located
# m/ s" W1 V9 F* y+ [/ Xinside nmtrans.dll).
' K) o. z5 a$ r4 J2 O6 ~2 r
+ \4 @& x) P* p* n r( dThe way it works is very simple:7 l& l6 x5 R, j( Z# ]! v* S4 J
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for- L5 N2 H* L" H! x( e* q
WinNT) with the CreateFileA API.4 H% u- t8 W3 R
9 g) I# @" g# A* _
Here is a sample (checking for 'SICE'):% `% z9 n5 \. f$ r" s5 t+ C
# K& X& M( K" c
BOOL IsSoftIce95Loaded(); w' A' V( L( `( g
{+ ` r- h9 [# o) _2 p
HANDLE hFile; * X" @% u+ [3 U" f4 }2 X
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
$ S% |, w' F' K1 c2 D7 q FILE_SHARE_READ | FILE_SHARE_WRITE,
3 V3 K. T. B# }! ~5 E8 N+ ` NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
1 C* D* ?6 i* L3 \5 l6 N if( hFile != INVALID_HANDLE_VALUE )
! Z4 Y4 r4 b, M* s& V% n {+ Q f9 C/ A- ]0 Q$ i5 T- y1 E1 i( M
CloseHandle(hFile);9 \- L; v$ R: y
return TRUE;
% J2 g }/ D: ~6 j; t. B }
) W d) H0 i8 a6 E, F" v5 Z return FALSE;# _5 p% c0 I! O3 t9 [9 n
}# q" s# b1 h& t n( A
( W# \* o7 P1 R( z4 Y4 d
Although this trick calls the CreateFileA function, don't even expect to be9 S( h, W. M5 X1 [% A
able to intercept it by installing a IFS hook: it will not work, no way!
8 U0 v, Y/ p! |0 X- q+ \0 AIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
) L5 j* H2 b4 n" Yservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
a( p+ A0 x: f& k8 Tand then browse the DDB list until it find the VxD and its DDB_Control_Proc6 |8 T+ S5 E b- r
field.
1 _2 P, G' F5 O A' q/ DIn fact, its purpose is not to load/unload VxDs but only to send a
% K; l/ _/ z& X2 [1 ~W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
7 I3 J! t2 s" d( A- `! ~) uto the VxD Control_Dispatch proc (how the hell a shareware soft could try& S6 g4 t- | z& S
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
& o4 `2 t$ K- `+ i0 M/ g8 m, qIf the VxD is loaded, it will always clear eax and the Carry flag to allow4 y. P& d; G3 M7 G
its handle to be opened and then, will be detected.# W- I/ D# ]8 N8 H- H4 v
You can check that simply by hooking Winice.exe control proc entry point4 O% x" X% z: N( m T+ w
while running MeltICE.
- {; v" B" I4 _- h4 T5 o) V( q8 I
) _ v7 g. q8 R3 J
00401067: push 00402025 ; \\.\SICE _# M5 a6 G8 S. _7 w: |8 [
0040106C: call CreateFileA/ y/ X$ u: J: h& v8 Z8 \9 u8 J
00401071: cmp eax,-001' E2 Y! L6 p, a7 v+ H. F
00401074: je 00401091! u8 x$ }# N H* n& i/ ~% w0 G, }
3 m. W: _5 S; X1 \
5 u7 V/ c4 H+ ^7 E, t$ K/ U+ {There could be hundreds of BPX you could use to detect this trick.) U8 p$ W2 ]* a8 Y
-The most classical one is:
- [$ n. }# Z" p8 q) _ BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||* G% V. p$ Z' f- y j
*(esp->4+4)=='NTIC'4 x t0 l; A8 e6 z: g7 V
1 U+ ~) S- D2 {( E' @# I-The most exotic ones (could be very slooooow :-(
4 t0 s0 t+ @5 P7 g- ~; U BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') / U2 ~3 G. f* D2 Y
;will break 3 times :-(
7 w5 B# ]6 H7 C% G% d$ U8 t) U) t. N
-or (a bit) faster:
1 k/ k8 Q0 w3 o BPINT 30 if (*edi=='SICE' || *edi=='SIWV')% Q& c2 q: A! d7 B7 ~- j
, }. j0 z% F( Z/ w7 @' s
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' , o! y( k7 x) w* L0 U
;will break 3 times :-(
8 U& T8 R9 }2 X( t2 m
* T% p7 |8 f8 ~8 n( y2 }+ N, U" K-Much faster:
7 e$ D4 w0 Y0 R! @' r" h+ P BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'2 D x/ X$ z B, P ^/ k
2 a: t1 b6 x; D' w. N, ^$ O1 ~9 hNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
8 i- @" `" P, M! @; Ufunction to do the same job:& P2 c: C$ \' e' [5 T6 g/ c
& j" q" T- `9 H, k& [* \
push 00 ; OF_READ
( U+ L2 W# l& D( T6 W mov eax,[00656634] ; '\\.\SICE',0. U' X1 I, U) y# Y- e
push eax2 o' L, W0 E0 t, F- A2 U$ v
call KERNEL32!_lopen
/ ^5 ?6 t! D7 r( a, y inc eax' Q5 L4 U" a5 z2 H
jnz 00650589 ; detected- t3 C& x V4 o" s
push 00 ; OF_READ
+ B8 K8 A- O" K' ?3 f3 p" \, s! r mov eax,[00656638] ; '\\.\SICE'" R+ x3 k; O G3 u8 \9 [
push eax0 t. v! h) P9 |$ Y/ `) V# k0 r7 Q
call KERNEL32!_lopen
: v$ f: m b {( [0 O3 U inc eax8 h/ D6 }( ~' [- E& a
jz 006505ae ; not detected
: H1 F; j' V/ x! ~" ^( L* S# E, g1 E, u5 C9 _' p
+ B' F7 Q9 z) a# o+ }5 N @__________________________________________________________________________
- }" X ^! C; I v0 p0 n, R+ u$ K; E, i, Y( \7 `( B3 H% D
Method 12
' o' O9 }& G" _9 ~% b& P=========' q6 z4 H* a/ F& H3 ^3 `
8 {/ X" O6 U' T
This trick is similar to int41h/4fh Debugger installation check (code 05
0 P6 ^! f) I, F7 P8 D& 06) but very limited because it's only available for Win95/98 (not NT)5 P$ o* M( n3 {) K0 J+ ~
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.) t, i+ @# Q" X% ~3 b. P
1 ~- {/ D/ J7 C0 p; h A8 I7 Q push 0000004fh ; function 4fh
) ?% f% h% a) ` push 002a002ah ; high word specifies which VxD (VWIN32)
4 l5 {) K { n5 l ; low word specifies which service' ^( d4 G. X. n7 t9 q& q0 _
(VWIN32_Int41Dispatch)
5 g& D8 i# _/ V4 N3 S0 @- n2 X2 A/ t call Kernel32!ORD_001 ; VxdCall7 @/ W) z" e' O1 l6 |
cmp ax, 0f386h ; magic number returned by system debuggers
2 y- e- r8 r) d$ m* B5 n3 h jz SoftICE_detected
" i( z! i- V6 D# v" H$ _9 S
# }$ w: v$ O0 i; `, nHere again, several ways to detect it:
# }8 g8 u+ N/ w9 r' ?
9 {1 G" O8 i8 \7 t% _: A; S+ z BPINT 41 if ax==4f
; d5 z, V2 u$ w2 A3 Q Y% Z- k
/ L+ E! x" L2 v/ T% E; H BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one4 \$ T; a6 Q0 U7 |( x1 Y1 I
, R8 v) V. b; G) v BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A: u! ~3 S5 u$ x5 Y7 G F; F
' j4 n: G) u( ~6 {! s
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!( l. B4 ~4 U% a" j& I7 R
# l/ h0 z% M, y0 x, w# h" `
__________________________________________________________________________+ v. c* W, J, c5 w; V! K1 {
2 {' F3 F- w' y# b1 yMethod 134 v$ i( W d/ X0 @( h4 t" V% }! R
=========
K) y" s% p" l# Q) ^3 i4 m: l& ^ T: ^# l. o2 G" }
Not a real method of detection, but a good way to know if SoftICE is
1 U, {- ?, t0 A5 S9 u; }9 Binstalled on a computer and to locate its installation directory.
$ p# f2 D% q# V9 |: c" p$ sIt is used by few softs which access the following registry keys (usually #2) :2 ~+ D, C% b5 c8 e- {
2 K3 S7 ?! {9 f! i0 |
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
|( f/ _" B2 H- x( C\Uninstall\SoftICE
% n- N# m" K3 T% T- _-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE: o, m% j* [- J
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
^8 n0 W, J( m+ u7 s' N& Z\App Paths\Loader32.Exe
( p* ]# k, E4 W" e! B5 q
. |" Q: A" F W9 P5 E9 L
/ c7 t$ s4 P& B% P( _Note that some nasty apps could then erase all files from SoftICE directory. g. l/ \ m; s. q
(I faced that once :-(
% [* M- L6 ]# o5 q; l
5 p9 O/ @& ~5 T! d+ G+ u/ C4 Y L# CUseful breakpoint to detect it:
' H7 h( o% s6 S7 D7 {. T) Y, c# u8 e" K. ~
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
; F u: ^+ i! M6 o7 r9 S }# O( [6 O! T& Z
__________________________________________________________________________
8 u: o* ], n; Z6 B8 u
9 U# X# X/ U! X, O% o
* j+ w* x% f- R& S& D! E9 NMethod 14
8 |/ ^! @4 x0 R# m$ k% c7 B$ t' J=========
0 \' R# i+ D2 o4 m1 ?! h
0 `0 c9 @1 Y7 Q1 k' uA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose9 c; V+ t7 ?' U1 b+ ^9 w+ n# c3 ?
is to determines whether a debugger is running on your system (ring0 only).
* h( i1 g) [" \; p2 [5 M, C7 ?1 _; Z2 X; H' E: R8 c. P% F! O
VMMCall Test_Debug_Installed
/ K6 P* }. y9 P, n, r je not_installed
' Q/ s) r7 l$ Z& ]: N/ S3 m- F- n, }0 ~9 V F7 w4 S2 ?
This service just checks a flag.' C4 R1 }' V; k0 K5 ~& V- s
</PRE></TD></TR></TBODY></TABLE> |