<TABLE width=500>3 J+ |8 r$ U& Q: t
<TBODY>; \+ ^/ C- u: R3 d1 j9 {
<TR>, h' s5 l G/ \0 e7 ?5 D- X/ J
<TD><PRE>Method 01
, h9 ]9 w' t- g4 j. L4 A=========6 ?7 t1 O$ r3 H7 L* v- S% v+ W
3 q0 }0 j* R- R; G+ J; W, wThis method of detection of SoftICE (as well as the following one) is
- [8 D3 j6 N+ S+ rused by the majority of packers/encryptors found on Internet.$ |5 T+ d- L; t7 }. d
It seeks the signature of BoundsChecker in SoftICE, d8 `* n% O2 y
1 [0 W e; i3 O( t5 s1 G7 x
mov ebp, 04243484Bh ; 'BCHK'
2 L! J. X2 E& F x mov ax, 04h0 @- [. |" r# f8 `- a8 ^
int 3
+ a# `0 t4 }2 B1 `1 e% [* w% r0 x# u cmp al,4& L, t. p! C/ v3 f8 l: F; J6 _
jnz SoftICE_Detected4 h3 }5 Z5 `; Y
, i9 g1 {6 c: T$ W; ]1 G7 U+ i___________________________________________________________________________9 w2 q; P( D) s" n
& L9 Z# Y6 c2 Z/ kMethod 02
/ t5 ~: d2 x8 v; V& F=========7 ^8 {5 y* i) H2 l4 j
! v/ a9 D! Q2 lStill a method very much used (perhaps the most frequent one). It is used0 |2 U- ~; Q- J+ @& G2 H. }* l- C
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,* z5 O! J4 v; B1 p5 ]1 o$ H
or execute SoftICE commands..." Q9 m: v b! ~5 o( K. R+ N" U
It is also used to crash SoftICE and to force it to execute any commands
' V9 p7 Y" ~7 p c(HBOOT...) :-((
" ~; J7 d; Q- U; |# M
9 s% [6 Q8 I6 k6 D k1 ^Here is a quick description:
6 l4 \) k( H& m-AX = 0910h (Display string in SIce windows)
: f, J5 \; e. P% f" c' R! K-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
" | ~* y" g7 P' `: ?-AX = 0912h (Get breakpoint infos)$ ^' x& i, M5 e& q
-AX = 0913h (Set Sice breakpoints)
+ A d7 g& D1 B1 G) h; S7 v/ W) Z) s-AX = 0914h (Remove SIce breakoints)
- ~1 u1 l; E/ @! u+ J
/ r; N. r: U3 g. K4 bEach time you'll meet this trick, you'll see:
; _" k8 ^% G7 B2 k' U7 s-SI = 4647h
: f, k7 X6 u+ f9 ~6 c4 v# v-DI = 4A4Dh- W7 k3 m! v6 Q& {
Which are the 'magic values' used by SoftIce.: y, m4 w) ]8 [$ R6 E: a3 e, o6 Y3 s
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
9 }4 u3 X6 X. E, }5 X& O1 i5 n: V
5 X' U2 x2 Z6 F' SHere is one example from the file "Haspinst.exe" which is the dongle HASP1 X$ t, G, S- Z3 r
Envelope utility use to protect DOS applications:+ m1 n4 j" S6 U) B7 T/ _, V/ M
8 E- P9 t, D) t _6 Q5 C) Y5 L0 `
& @: y; W; a/ H
4C19:0095 MOV AX,0911 ; execute command.9 i J7 X( x6 W9 G: \4 X+ R
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
) F' ^5 T* I! i4C19:009A MOV SI,4647 ; 1st magic value.
+ G; i1 ^5 G3 h4C19:009D MOV DI,4A4D ; 2nd magic value.
& d9 l9 N& k: K# o8 f& N4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
3 ~- r- [9 e! {. R" A2 h4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute0 O- C7 K6 T1 ^3 D& d+ G: ]* I
4C19:00A4 INC CX
- c. v& @& @+ t$ K4 K* b4C19:00A5 CMP CX,06 ; Repeat 6 times to execute5 I& }& z' k$ r5 A9 ?# _
4C19:00A8 JB 0095 ; 6 different commands.
7 K; }' C8 j& B# a% i' O3 \4C19:00AA JMP 0002 ; Bad_Guy jmp back.
: J1 Y& Z: l1 b7 P g6 O4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
3 u% ~6 G7 x Q" [' A$ |/ J( y& {) u `& ]. u7 H n
The program will execute 6 different SIce commands located at ds:dx, which
5 p+ ^, [$ w2 v- M0 d4 ]are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.1 A, ], c1 J8 A+ q2 Q
) ^$ h5 O* z% z; Y* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.5 e3 I: z! e9 w E9 U
___________________________________________________________________________; r# n+ z# @( q# s* C
2 M* E* M: W4 `# m: x. a. S, _% S& V% P7 V1 i' J: d# W
Method 03; }& [% Y& o6 f0 W4 _
=========0 [- ?+ {1 t/ x& q9 ]
3 t4 g) W/ I8 h" M2 V
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h7 L; p. z [% `% n2 `' |, O0 d
(API Get entry point): _" g: |) z0 } a- N
3 i) a( f8 Y5 p& l2 }' }% r* ?4 O" e, ?0 X. c( q
xor di,di
l- T! q0 f( v' X2 B mov es,di
+ _* F8 Z0 \0 r: \0 e | mov ax, 1684h
" Z0 s, z2 z$ K4 z# r6 F mov bx, 0202h ; VxD ID of winice
' k- i5 A) m' ~& y% w! J int 2Fh2 b% d$ E Q6 s1 S! H$ L0 c: C
mov ax, es ; ES:DI -> VxD API entry point
0 `3 e" V4 |. M0 e, \ add ax, di
- A {2 Q1 I( d test ax,ax
. S, c: N5 w8 x$ q jnz SoftICE_Detected% B% G$ t) b9 ~' }- H' s$ O6 o
: Z7 a$ [2 N% d( L; \) y___________________________________________________________________________1 O3 }' F% A; M. @; z4 c- F. |
, g! I% P9 P" J
Method 04* ~0 b; H; z1 n7 s# o8 Y; |
=========+ d/ x: h5 l: w
* g+ j: R3 Q8 }% w1 r& }" v4 RMethod identical to the preceding one except that it seeks the ID of SoftICE& O# ]" G" x( @4 Z' s
GFX VxD.
8 P7 f6 Q3 ]1 m- v, r; O. M
( w- v* d( ?5 Q: i: u; P xor di,di8 B$ x- o) X/ m/ m
mov es,di
2 C/ _2 @" O% s+ Y, ] mov ax, 1684h
# u& V% [4 B* M/ }$ v mov bx, 7a5Fh ; VxD ID of SIWVID6 k+ \5 E/ g0 t7 J x3 A
int 2fh$ g) a$ Y6 I6 @1 r2 A3 l9 e1 M
mov ax, es ; ES:DI -> VxD API entry point' w: U L# X" k
add ax, di
! Y3 g1 i6 s# @+ ` test ax,ax7 r F h) [7 ^
jnz SoftICE_Detected0 B8 F* |! {( T( f! ^* l4 L$ _
" k* ?2 n, o8 v/ E/ k3 Z
__________________________________________________________________________
1 S4 r( r- o* E& O/ S% X( |9 N# u/ t3 C0 L5 x! ?
) f5 A4 K v: t% D8 C+ t' R
Method 05
( m4 V0 P# B' z2 I2 l, M=========
, D( J) s ^$ g' C7 T: m( s# {, E/ @$ E2 ~, W, P7 I2 M# j
Method seeking the 'magic number' 0F386h returned (in ax) by all system
( @3 N/ f# f5 x& Y" G ]debugger. It calls the int 41h, function 4Fh.9 ?" e2 M+ X7 [1 ^, l
There are several alternatives.
1 ^5 I/ t6 N6 i2 ^9 G
. [4 O8 h2 I4 _: ]1 n" N9 M$ P! P. OThe following one is the simplest:
- p h5 {% U4 X, i) u" B) L! Q" V: o! ?/ O c
mov ax,4fh
* Q: N* h4 v# x- F9 i) q int 41h
+ b: N$ ^" G+ n. F; ~ cmp ax, 0F386+ ?0 R1 `, c8 j, b, M
jz SoftICE_detected# e! u$ ~7 Y" A8 |3 r9 R9 b
& A# B0 q- h4 T+ D8 v/ _
8 J2 B" I' R1 K5 Y( w1 T% Z
Next method as well as the following one are 2 examples from Stone's
! F0 k2 ]- o1 ^& e1 w6 K"stn-wid.zip" (www.cracking.net):
- K- E# d/ B# K! T ]/ | ]2 D4 |: c9 t# r
mov bx, cs
1 e5 d( Z# U1 V% t lea dx, int41handler20 }8 }4 Y9 D' L( G0 X3 ^" O
xchg dx, es:[41h*4]
( I4 U' h N E xchg bx, es:[41h*4+2]
0 n w/ {) R. ?2 X- w& D mov ax,4fh
! e$ u' s! f' a9 O& h( i int 41h
2 B5 l7 D* M' a! F; \" m: j xchg dx, es:[41h*4]
E% l+ C; M: v m# p xchg bx, es:[41h*4+2]4 e- W" s, ^& I% h
cmp ax, 0f386h
2 @$ g! c3 D/ d6 v, W, q0 ~ jz SoftICE_detected
. B4 `6 t; n* O
" E8 q p1 f/ W* Hint41handler2 PROC
' b% T& R* O, J" v9 G- j iret
2 b1 v0 Z. w( ]) o6 t8 l- m# r- q& lint41handler2 ENDP
2 N& V4 A; k( L7 x3 l% h: ]3 N; m) z3 [ |; K0 z4 b y
0 R; Z3 x$ `' M$ y
_________________________________________________________________________
7 ^7 ]( z- k; o0 Q7 P" `% ]0 a) Y, i# t2 \# z
: J& K4 h, _4 m" M( a, R/ K; H1 }
Method 067 `. M, m1 ~ x$ d0 P- W2 _, O
=========7 k: G; m t4 Q/ R7 e) I$ w/ I0 _
4 L0 T# J4 U6 L2 W9 z8 ^( |
6 Z& B; U! ^* \5 K, L, Z) s2nd method similar to the preceding one but more difficult to detect:8 E/ b: i% {: g0 {" l
; _4 Y" L3 Y8 K' |6 y0 d4 _
1 U) N6 f8 u9 K) U! o; e# U! m1 Gint41handler PROC
- }! G l! P8 @ M6 r% P mov cl,al- x2 Q4 J' @# v: M+ p b7 U
iret. \/ y0 V4 L8 E7 [8 f5 K/ t6 _
int41handler ENDP
# \, q1 P* r9 E D/ i) n/ n% Z O1 M' h6 R4 Y3 E4 _6 `
: ~- q7 j+ W! {* O* d2 h xor ax,ax, i+ B P0 M0 H1 F7 C
mov es,ax
$ o; e: w1 j5 N& [; Y mov bx, cs
7 C' |9 _% g$ U lea dx, int41handler
" M M' m: B( p# F- T xchg dx, es:[41h*4]4 b! E' [# ]: S+ N
xchg bx, es:[41h*4+2]1 w9 d. u c; S5 m
in al, 40h
E& X5 B6 d& c xor cx,cx0 B0 @3 \/ V9 ^3 y: h
int 41h; p7 W1 u$ N- w& C
xchg dx, es:[41h*4]
$ v1 W: U0 W( x! @6 f xchg bx, es:[41h*4+2]
. d6 E. S8 n. d/ d' x cmp cl,al
f: ^; B6 N0 H8 A jnz SoftICE_detected3 Q" H6 g& b" \1 S& F- Q( Q
: d( F! I2 _/ Y( d, z- `
_________________________________________________________________________
# D2 C7 g! E& g$ t1 L8 s/ _/ }# \1 m
Method 07: y0 P, a, B: m: V3 f. E5 g
=========
! Q& `9 o2 W+ c; D2 c; A m5 z; C% H% H2 o( q) p
Method of detection of the WinICE handler in the int68h (V86)
0 [. o# y; }: Y) d6 f- ]* m' l. y" |1 g, N, ^+ S8 }* M) H
mov ah,43h
4 S; ]1 P% X7 H5 J int 68h
2 H# j8 ?: J- D/ q( W' T cmp ax,0F386h1 x* N% C7 N- ?4 W) K5 z: T
jz SoftICE_Detected. u2 x3 j/ |7 a' `4 _& j+ ]! }
: C8 }& E9 b& d
* ]' T$ y0 t' n* A8 I! o/ F. B=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit/ g% y* k% d3 o1 D
app like this:
& p; }# L8 z& |" J J& G/ F9 Y2 H* ?, B: j& r6 ?9 F% w$ c
BPX exec_int if ax==687 c* y+ D7 R7 I$ l% ^" I3 E
(function called is located at byte ptr [ebp+1Dh] and client eip is
9 H6 y! k1 P1 [7 L4 @$ X located at [ebp+48h] for 32Bit apps)
, Y6 w9 O( W V__________________________________________________________________________6 Z# o- l9 U5 N- a
3 D2 D* i0 K5 Q( k/ L% O8 U4 B( i* T0 b( B, r, H
Method 08
4 o8 X) @* D- v9 ]4 h- c=========3 f7 R/ H2 E4 H8 b. `
9 P( C4 ~9 p _1 h" h+ SIt is not a method of detection of SoftICE but a possibility to crash the3 q7 L/ A& ?, g- o/ W; n
system by intercepting int 01h and int 03h and redirecting them to another
/ B0 }( x% d: t: N4 troutine.
; @1 Q7 I$ T& S' x0 n' HIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
: O# M9 H- [: `7 O7 qto the new routine to execute (hangs computer...)
+ |" G5 j: m( j. ?
+ E. A9 z8 `7 {. p' m. Z mov ah, 25h9 O7 ]9 x4 G; T0 g+ A9 L
mov al, Int_Number (01h or 03h)
' u( U: H- o8 ^7 O7 N mov dx, offset New_Int_Routine' w& ]: M* C+ D8 J1 t( m( O& g
int 21h) K2 W) J! s( Z! @
3 \& v# g* ~% G4 ]__________________________________________________________________________% l- I* a/ Q2 z+ J! o
/ _! _! Q3 s7 C, g: N3 D
Method 09: J; g, ` G- ^- P0 {" u& n" _
=========
. i' O5 r0 m2 U% s% M
" ^' H1 @" ]( d1 |, T; C6 A0 R! ?This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
1 [4 H& \3 a' W3 _performed in ring0 (VxD or a ring3 app using the VxdCall).
! O3 z$ A$ D% E( P$ G% k& FThe Get_DDB service is used to determine whether or not a VxD is installed k3 ]* B; X* M5 O& ^0 H
for the specified device and returns a Device Description Block (in ecx) for
, v! o& z$ U- lthat device if it is installed.: U5 ^( W" |$ V+ u, r# \# r
) d9 L8 C; G8 Z( K9 ~2 L mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
8 A/ E2 c( E+ R. m* J N S" f( ~ mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
5 Q: w) q9 P' f2 f- y VMMCall Get_DDB0 n$ c7 K- F ^7 N$ ~, S
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
1 G+ s2 c% V6 S3 ^ I/ b7 z8 n* g! ]9 M
, {& G0 w) P/ ?9 U; X! KNote as well that you can easily detect this method with SoftICE:
* ]+ K/ `+ _; l4 _ bpx Get_DDB if ax==0202 || ax==7a5fh
4 c. {6 V1 I1 A0 | u! G5 h
1 q t& q& v. x; v1 L__________________________________________________________________________5 b, `6 c" q- F) d& R6 I4 r( q
+ V: n* u5 G6 p) j2 yMethod 10( W" `0 K6 C0 n4 @
=========
$ v) _: q& S4 S; ~1 W' ~. A" V$ @6 t; g) j2 P- }* J4 U( R& H
=>Disable or clear breakpoints before using this feature. DO NOT trace with) Z4 U# m7 Z+ y9 K/ w
SoftICE while the option is enable!!& W1 Q S; L2 G4 B6 }; A6 x% N
8 M% q+ E+ }$ U% h9 Z7 H6 B
This trick is very efficient:$ e+ L" I# J7 u, G. v4 E8 B
by checking the Debug Registers, you can detect if SoftICE is loaded4 S# v% u* g* f
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if0 z" l9 U/ K) j1 i
there are some memory breakpoints set (dr0 to dr3) simply by reading their1 n" H& [% z; e- |
value (in ring0 only). Values can be manipulated and or changed as well
! p% [- X2 {3 W, G, {$ O; |(clearing BPMs for instance)
4 D8 e& I1 @* @& Y8 S5 E5 u% B; N+ }2 [; O+ _7 E E
__________________________________________________________________________$ B- r: C- g$ K! u
u4 S$ d5 {7 z5 y* l7 FMethod 11
" C5 u4 h' m6 ]6 h! ]" G=========" Y- C( k! z% e, Y
: ~! s' ~- S* x% `1 u4 iThis method is most known as 'MeltICE' because it has been freely distributed0 E, w, J B# B+ _8 H# b# B4 `
via www.winfiles.com. However it was first used by NuMega people to allow7 h( T; Z- `; _3 H/ h
Symbol Loader to check if SoftICE was active or not (the code is located" [8 P, n) W6 U( \, _
inside nmtrans.dll). Y- E$ T: ?* t6 m) I
& b; k/ Z! x5 I7 l4 ]( f5 wThe way it works is very simple:
, X! E/ I8 f8 h+ j$ F' ?( }2 G0 ^6 YIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
' P* _% T$ O4 YWinNT) with the CreateFileA API., V. A3 |" T/ l; m
# o7 k2 m) @4 O, M9 k# `- a- C4 I
Here is a sample (checking for 'SICE'):
: p0 Y* X2 d6 x G$ O# ?: T( `) v
; H7 @' J: k& N) X+ f3 ABOOL IsSoftIce95Loaded()7 t8 \% O5 r+ m; s7 ~1 R) k
{
! ^4 p% ~& c, z* d% V HANDLE hFile;
" S7 V" M7 A) w: ]! H. y/ A: e" O) t hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
; n l. |% V- O5 O. {- X3 Y% H FILE_SHARE_READ | FILE_SHARE_WRITE,
# y- F' c8 W+ y/ v7 [9 E1 k, x NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
5 u* j2 v8 W- \. V6 _! {; w- Y if( hFile != INVALID_HANDLE_VALUE )
0 x, I! n# F6 |7 L+ W9 m- K% ? {
4 }" t* [ X) F' b7 x$ c: F3 ]# U CloseHandle(hFile);
& z }6 p( N' M; ?- B5 a. d- l return TRUE;: A7 K) }/ ^/ T, [
}/ o V! S, O# C1 l% L* @3 y0 K) c! J
return FALSE;8 f) t' o6 g, p. j$ b# V
}! ?1 B8 _% N+ C8 `
4 p9 Y3 h6 W/ z/ r- ?& w" Q3 ~ Y
Although this trick calls the CreateFileA function, don't even expect to be. {& z1 T- o- q9 N2 {' q8 r
able to intercept it by installing a IFS hook: it will not work, no way!3 m$ r! d0 p1 u
In fact, after the call to CreateFileA it will get through VWIN32 0x001F& n" j+ o8 Q' S, e* s* {
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
& T0 \* j) R6 K Z/ Z% Kand then browse the DDB list until it find the VxD and its DDB_Control_Proc
- h1 a/ H) H- jfield.
1 y! y/ m- H/ I1 X# NIn fact, its purpose is not to load/unload VxDs but only to send a
$ d4 Q! ]% U4 Q! E' { E* OW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)5 E& g; |4 Y. s6 B" ^
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
$ k" ]/ _) Y. k0 a9 yto load/unload a non-dynamically loadable driver such as SoftICE ;-).# g/ O V2 T' q
If the VxD is loaded, it will always clear eax and the Carry flag to allow# f" P, i/ D5 u! W
its handle to be opened and then, will be detected.
! ]" l9 L; t( F# U7 CYou can check that simply by hooking Winice.exe control proc entry point
( X' r7 x- E6 g. \* g Pwhile running MeltICE.
5 n* g& f9 X- i1 F) A! B. ?9 r' D2 D" m0 {# n
) i+ Z/ {# l5 ?) X7 u8 g
00401067: push 00402025 ; \\.\SICE
# k) H9 O. w& D; P 0040106C: call CreateFileA
6 `. N' k0 q2 b1 M) |1 u$ C, ^ 00401071: cmp eax,-001
/ C( i! D. O, d" ^' l- O8 J W6 Y 00401074: je 00401091/ F2 [. R* c' t7 D Y
! {- {; Y _- M* H. E' n+ v9 x& p5 v. |+ S0 r' r' w8 W
There could be hundreds of BPX you could use to detect this trick./ P3 i+ n( E, E* ]
-The most classical one is:
5 h# s2 V' n) U5 c; |$ f/ p+ H BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
" z7 V9 x, n" w' z *(esp->4+4)=='NTIC'1 ?- U9 l6 [6 _
& i6 f5 j3 }: C6 o* s; V" [2 i-The most exotic ones (could be very slooooow :-(4 S" ^4 {' H1 U
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') . u8 J0 t6 v% |/ G. x& W2 J. t/ E" U
;will break 3 times :-(
+ {& o3 w- l; |' w7 B, Q- V
' u3 S8 V4 p: g# G t* _$ Z-or (a bit) faster:
2 F- s" E' t/ O% B% J BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
* n- b9 R/ P/ J9 J; c) u
y1 K# ^' W! W& G* v* B; F BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
7 G9 o4 G/ w5 S1 K! _ ;will break 3 times :-(8 E' s$ r; Q3 s4 J3 h( S2 v
0 A' Y# P+ {- {6 e; U7 Y5 V8 U
-Much faster:
) L, H" ?1 h4 m BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
" `2 P" Z, K- } N( J, d1 ]( O- H) Q3 p0 j
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
* b# U8 i% ~8 Z0 _% ofunction to do the same job:$ w& ^+ B- u& X
+ B( u* `; Y, G push 00 ; OF_READ
. T2 O C t8 v mov eax,[00656634] ; '\\.\SICE',0
: k3 ^- X3 g9 y8 q; R push eax
" a. b1 X6 S0 T3 `3 D0 N call KERNEL32!_lopen
" H* E) r1 o# @9 }! q- \% x inc eax" j" m4 ^" Q/ } r) M1 d2 O. U
jnz 00650589 ; detected6 Z, _+ l$ T3 h5 p& x; h: ^7 @
push 00 ; OF_READ# R8 V, I+ C. x
mov eax,[00656638] ; '\\.\SICE'; f, V* v0 H6 {
push eax( n+ `- O! Q# ?$ g3 w, q1 l5 J
call KERNEL32!_lopen
/ ~- X) w: S5 R. m5 L inc eax
# u5 W% z5 d! s+ _ jz 006505ae ; not detected! G6 T. t" b! T3 g: X+ y; c
) y) p3 E0 X8 U6 W- T. i" S" k( l7 ^! |
& |; g' M: T% l+ Z) U2 U T__________________________________________________________________________
H" C/ ~4 y( l2 W0 U, \- M9 N* u. W- F$ Q# P' t+ a* |
Method 12, s# a r2 [6 F7 c$ w9 w5 L
=========" F- S6 \- z8 a0 @
' z( y# R, C3 _" R' g% R: vThis trick is similar to int41h/4fh Debugger installation check (code 05: C9 w0 n0 g4 Q6 s
& 06) but very limited because it's only available for Win95/98 (not NT)
- f- `& ]7 m: _+ @as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
* }5 t* u5 S3 x4 R/ Z* `' _2 E+ G) F' [; z9 C' }2 C; W9 g
push 0000004fh ; function 4fh1 X( N2 [& j: v% F
push 002a002ah ; high word specifies which VxD (VWIN32)
: |( I! x# G, z1 z+ z ; low word specifies which service9 c2 y g) ~: F; y
(VWIN32_Int41Dispatch)3 G5 {7 c6 `! ^+ `" n/ d
call Kernel32!ORD_001 ; VxdCall9 T1 x6 c2 @2 D+ r) ^
cmp ax, 0f386h ; magic number returned by system debuggers
; d$ X3 l7 e' n k4 L T# v$ l jz SoftICE_detected. K+ ?- u4 w; D* d
2 r6 X3 }3 c* q/ s, cHere again, several ways to detect it:4 c: L* `& B1 r9 w
# x/ N* y$ A. h+ I* v0 m BPINT 41 if ax==4f6 n4 J& [' Q( s/ w- z; I& X
$ U7 q6 d' x6 b+ V! p
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one5 U4 `3 `: O" V2 O# N N2 T
6 h4 b5 y, T# U9 c5 k
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
5 V) F# s0 l) p
" F! S. P% Y( w" M# C) Y @ BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
# S9 C7 l$ l; r- f6 i. D* [* m$ X% ^$ ^3 B
__________________________________________________________________________' q; k2 a9 N1 J2 p4 L# X
& ^4 Y0 |: H# y# ]1 d4 D/ ^
Method 13
6 G% u# @- n5 i' E3 T=========
) d, S2 u* `9 P4 I5 f
. t; |( `$ t) _. D9 K( [8 h3 sNot a real method of detection, but a good way to know if SoftICE is2 q. q7 p5 C/ S+ D7 O& }
installed on a computer and to locate its installation directory.
! S7 c- Q c0 R& O4 j/ f5 _( h+ r3 [It is used by few softs which access the following registry keys (usually #2) :
5 x! |9 `6 R7 f* |( q$ w) ~" r+ E4 ~
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 [! E4 A e; B0 d" F\Uninstall\SoftICE! _+ ~, @9 N* u$ y c
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
8 W7 w- e( }- L: |, E-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( J- ~* o, D6 B' g" @' C
\App Paths\Loader32.Exe' s, l2 e7 r7 R p$ ^9 b
4 O6 i0 o6 F5 \& v" q' `6 s) K; b
, N) i- A& U# \ U' f5 O
Note that some nasty apps could then erase all files from SoftICE directory
+ {# X* z5 W9 K(I faced that once :-(
3 {; H# F3 S6 @/ D: h: ?& a" Q) c- \$ f3 t8 B
Useful breakpoint to detect it:
; D O9 @) b* U- A2 N, S! `5 ~7 X0 C+ F+ n& k
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
! K3 ~) L5 m* \- ]! W+ w8 I1 z5 r
. d% _6 D4 f0 M0 {( p: P3 V__________________________________________________________________________8 W9 x- T% R1 |8 v6 G2 E; f0 t4 |
" Q: ]8 j! z y) a' \
3 [% b6 v0 N% m* w" A) F* U0 e
Method 14
4 A6 O- Z& T' ]! I* q=========
% e; j. w7 e8 @+ t3 d
3 F5 s& i) Q9 {* J/ A. @$ BA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
8 Q; f. c2 u3 _# F1 Bis to determines whether a debugger is running on your system (ring0 only).
) C; d$ y* R& [# v" v0 A- I! Z/ J
& {( x" D. R0 D& |. l VMMCall Test_Debug_Installed
( c7 m4 ^& F. L+ o9 q H je not_installed
5 T$ \; i/ T# y' H2 `3 _+ M! W7 m2 g$ J7 g, B7 N3 @& R1 p' K
This service just checks a flag.
# Y3 ]4 r+ {5 ^' e; h: |</PRE></TD></TR></TBODY></TABLE> |