<TABLE width=500>
8 h9 i0 _( L$ ?<TBODY>8 m7 X7 M% s5 d% L
<TR>3 a8 t2 f4 h( o& [$ ]3 x) w
<TD><PRE>Method 01
7 K, t, A, G1 r7 m7 i+ o=========5 i y, C: ^7 T, j6 n
0 X1 ]' O2 }3 Y7 B7 U4 \/ pThis method of detection of SoftICE (as well as the following one) is
' q3 @* _9 m, W1 W" Vused by the majority of packers/encryptors found on Internet.
( ?3 T# f$ V2 \- ^9 bIt seeks the signature of BoundsChecker in SoftICE( C8 {4 l8 S6 n) r
2 `, s; ?+ v* P5 m6 K, g5 g mov ebp, 04243484Bh ; 'BCHK'; U4 G5 \% Z8 g! Y4 u1 x
mov ax, 04h7 u) \+ R- c% [$ {) S. K
int 3 % I- R% r- a. d ]* K C* p+ h1 {" N
cmp al,4
1 R8 a9 n! n* x- U/ J9 {$ W M jnz SoftICE_Detected
; D$ V t* H) G. W* i5 d6 t
; r5 X# f: y9 A: [3 J___________________________________________________________________________
# V& Z' V' V0 H$ l. }8 d2 _) C, l3 g7 M5 K4 @" p) M
Method 02# M, C3 G! J" o. a% O
=========
: k# q0 B, K; b! o s8 S$ y* x2 j# U; q/ ~4 p; T
Still a method very much used (perhaps the most frequent one). It is used) K; r: P, q* V+ c- Y+ R. D5 B# f$ s/ }
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,, s) g) N/ d+ e7 c2 `8 O! ?: R
or execute SoftICE commands...
) k9 ^5 D* \. Q2 C( PIt is also used to crash SoftICE and to force it to execute any commands
$ V: l/ b9 @+ F) r# v(HBOOT...) :-(( ' m, e8 m4 G- F; t% F
. F/ ~$ N+ W5 v, Y4 ^5 N8 k
Here is a quick description:/ M- A! C5 n. n8 f
-AX = 0910h (Display string in SIce windows)0 _) d& q0 l6 q
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)$ }1 {1 X. B# I1 O, p. H
-AX = 0912h (Get breakpoint infos)# |9 Y9 U2 s( [9 h& {3 T
-AX = 0913h (Set Sice breakpoints)( j$ n5 A# I1 }2 l9 f# k
-AX = 0914h (Remove SIce breakoints)7 @0 [) ?4 E: C" |
& ~; j" w- Q. j# u. B4 V [
Each time you'll meet this trick, you'll see:6 y" F3 _8 i4 q2 S' Q* J
-SI = 4647h
" V, H# g! h- h5 G" V-DI = 4A4Dh* |- v/ C3 s; U; m
Which are the 'magic values' used by SoftIce.
/ H/ w& p7 ^; Y" LFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
$ C: N0 O( Y ?. z2 M8 J8 X2 Y
3 r$ w) D# v! Q1 X3 d" ^Here is one example from the file "Haspinst.exe" which is the dongle HASP
% ^6 @2 j1 T( w: `Envelope utility use to protect DOS applications:
+ O. k. L% o' H
; q+ x& s) m+ T' f1 u1 T
9 i0 |. Q' [5 m0 X/ x4C19:0095 MOV AX,0911 ; execute command.
3 I1 ^' P4 _/ O/ c7 g& |$ U4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).. A- S, N G- k5 L
4C19:009A MOV SI,4647 ; 1st magic value.4 D. f& Z' u! l2 g+ n4 V
4C19:009D MOV DI,4A4D ; 2nd magic value.
Z1 o3 k- A, t+ y+ Y4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*) ]! F( m2 U B h. ?' {
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
3 S; @& _7 H3 W2 s1 |3 [4C19:00A4 INC CX
4 I3 ^0 B$ Z& |4C19:00A5 CMP CX,06 ; Repeat 6 times to execute/ s% s R! y9 V) ?/ _
4C19:00A8 JB 0095 ; 6 different commands.
! s1 V& H: l) C' K( Q; Z4C19:00AA JMP 0002 ; Bad_Guy jmp back.
% m f; W9 l8 F3 Q4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
. u* H$ |0 B' N' b" ~
) g+ w1 T% }. PThe program will execute 6 different SIce commands located at ds:dx, which
5 j, F& [1 r1 i; y0 hare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
( F" A3 `) T9 Y) }
+ ~- H G% S- E0 d" C% e* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded., s$ P, [9 L2 I3 U& I9 b8 z f
___________________________________________________________________________
2 Y" P( Z: K1 o. Q. E( j# l/ \. }
( [1 E* z3 B% O# @& `# V0 }, z4 k ~$ T
Method 039 X7 G8 s" p, V
=========2 u I3 s; o; U5 {$ M4 j( N2 D
5 O- H; ~2 l: p* E) o7 k) r1 @
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h% |2 o. s% t0 Y) e. j
(API Get entry point)
, h Y: B9 y/ ^+ _4 A9 }. m7 y
# h4 e3 `4 A# {" a# o& o7 b' ~9 r7 [8 S9 L! w z
xor di,di: |" S: N( U' q% C% `- Z p/ y
mov es,di& z- T" u3 v3 |! u7 N
mov ax, 1684h
& z8 v5 c$ ?( V8 j# n mov bx, 0202h ; VxD ID of winice/ k6 s- H8 v$ u) O" X' a: s
int 2Fh7 q5 |! I8 e7 N
mov ax, es ; ES:DI -> VxD API entry point
5 s+ e" |3 a+ d4 g, m add ax, di
0 N) b! Y7 {! g# F6 v test ax,ax
]+ d+ `9 s' M5 ?/ E, P8 |$ {" i n jnz SoftICE_Detected
9 ?* Y2 c; [! J9 V/ ?6 H) X1 D! A
) g2 D: A5 U: ^* h4 u) l___________________________________________________________________________
+ Z2 H! }# d' V# i- @! }5 ~0 A/ X' ?# u, T. P: S
Method 04& k* ]1 Z- e& D) ^/ x) ^. K, O
=========, Y: @% h4 Z& y$ Q$ I
' g. K9 C: w, ]/ iMethod identical to the preceding one except that it seeks the ID of SoftICE
+ @+ u! o2 s* _3 K4 NGFX VxD. n0 @8 G) K7 Z0 O8 X
' _) ?3 ^! T% a. v5 v
xor di,di/ `' d3 b" B$ \4 }8 x( E9 t
mov es,di0 T' B/ K5 D! a+ s; y! O1 G
mov ax, 1684h
: l! M R L4 l9 s# F$ G/ E3 u3 ] mov bx, 7a5Fh ; VxD ID of SIWVID
6 B+ e# D8 P7 [6 a8 m7 j+ X: F int 2fh" j ]7 P. D3 t: Z
mov ax, es ; ES:DI -> VxD API entry point
7 n V& N7 R* o: p" |! j0 a add ax, di- ^$ ?7 H0 Y( o& X+ y0 l
test ax,ax
/ t/ e& e3 H5 j, Z jnz SoftICE_Detected
1 R' I! \6 Q% m' f% l2 g
/ w: ~ b* _$ E1 x i( G__________________________________________________________________________
$ m& l( Z. {: A' G
0 X n% G2 s2 ^2 E) F/ z. {! F0 w' U( o; ~
Method 05
* D9 o' _% l- t i3 v/ ^=========8 i( G: C4 n7 X9 J5 ~3 R5 A
/ }' R0 h$ b! R) J+ H
Method seeking the 'magic number' 0F386h returned (in ax) by all system8 T3 |, p2 y; G5 l& S; w
debugger. It calls the int 41h, function 4Fh.+ ?1 C' t& F3 E9 y6 O% i
There are several alternatives. 5 v ]# N' I# y0 g( F
- M) z0 K) f H' y+ D3 ^2 r% F
The following one is the simplest:( h$ `4 p% b! E5 f. b1 z
9 n. T7 p. F8 P3 G
mov ax,4fh7 Z1 b- I" N @. Q4 G
int 41h
- W7 i* E3 H; y$ h: x# P$ t cmp ax, 0F386
+ R$ G) |0 ?8 _ jz SoftICE_detected* [+ V% m& L9 U1 W
4 ]% T/ t1 a0 Z9 @
) E' m! `2 Y0 e" J( ~8 b; M) z0 ] TNext method as well as the following one are 2 examples from Stone's
?6 x: d2 J6 Q }) X2 |8 F"stn-wid.zip" (www.cracking.net):
/ V$ o' e; R5 U2 Y0 R) H
( `) U6 ?: b8 h6 g# [6 f' s- H mov bx, cs- z7 c+ v8 {6 Y4 e" M
lea dx, int41handler21 ~; S# A6 q$ M
xchg dx, es:[41h*4]
8 e7 I6 E6 u, Z ? }; o. J9 s xchg bx, es:[41h*4+2]2 A0 p6 y+ Q! B% S' E$ R" k: W
mov ax,4fh& w& a/ S5 y E' `
int 41h$ W1 T" R0 @( W/ a3 R8 ?
xchg dx, es:[41h*4]% r3 F& {. P' i& z2 V- P! H
xchg bx, es:[41h*4+2]+ f! D* s# v/ F2 l7 J: U1 i( u" s
cmp ax, 0f386h
8 H1 V% Q; {- U jz SoftICE_detected
- i( ^8 s( e6 D/ u O: r, A# g- Q& \1 V7 v7 Q
int41handler2 PROC8 y5 M9 ~3 t) N8 w! p' {
iret
% T9 N2 q( g* w! @, `, z0 p4 q: f9 hint41handler2 ENDP* \; @7 F0 m) [- l9 P8 s
2 C" G$ L$ _0 _2 w8 O M
2 ~& P) Y7 m7 m5 P9 s3 d3 @_________________________________________________________________________
2 U- v7 a( @3 \3 F8 Q- w
" Y* P% F2 X/ D( \8 R- E
5 `. x6 A/ [1 A/ R7 O& hMethod 06* _1 j& [" F" v; l& f; E* b
=========
) j+ K; R* M% A0 C5 b0 }/ r+ b; l$ W
0 A* M) w* T6 Z6 H0 C0 Y! L0 a, u1 g( _8 E2 Q+ D
2nd method similar to the preceding one but more difficult to detect:
, Q& [9 S$ C5 a4 t
* d# R8 R, a- _# F( q$ [) }* D) t
, B9 }% z0 t# d, n+ x% Xint41handler PROC
, a2 e6 j a9 @2 M8 w+ d7 d5 V" s9 W' F" u mov cl,al* S8 C' v0 P& z( R; a: a
iret) _: ?, n n) t& m/ v( P5 Y G
int41handler ENDP# B, H: m" e. r8 E
1 B% _: E! j# S. O2 i K( S" q: w- j- R) V+ L# ^/ \
xor ax,ax
: D! v& I* R: x* b6 Z- c mov es,ax
8 Y+ Q1 M! m; e. N/ S3 t+ K& T mov bx, cs+ Y$ h+ [0 e1 S# X, E6 a/ M
lea dx, int41handler: s6 m5 ]: [% C" C1 t n
xchg dx, es:[41h*4]
, r, E, B2 L" m' H xchg bx, es:[41h*4+2]( r: ?! L Z" X }4 i% r
in al, 40h( ]# p* u$ n( B! m/ w! v( h/ ^
xor cx,cx
% f2 d- J3 m1 H) ` int 41h$ k" g- Q1 H4 ]* C3 w$ o7 b# z
xchg dx, es:[41h*4]( w- |3 S4 M# M4 T1 ]
xchg bx, es:[41h*4+2]
$ g. y; T/ ?; e. r1 D! C0 S cmp cl,al+ M# ]& K* Z4 h) Z6 c
jnz SoftICE_detected. I* ]+ o% P6 _. I
4 J. }: g8 Z }( a" k7 @! |0 h: e_________________________________________________________________________
8 p# X7 D% k2 h( D2 P! k7 @7 [+ O! i) U
Method 07. J0 e' n8 {* O, I0 s" q; L
=========
4 f8 p0 u7 u; T2 z. Z: E. ^
- j: q* L* d1 B) q# ^Method of detection of the WinICE handler in the int68h (V86), p# z+ @8 c5 Z$ B- P
9 j7 C2 z, _- d: V& w0 `" R' F) ]
mov ah,43h
2 _1 i% C# i" H H4 i+ m$ T int 68h) n% M) I0 V! ^6 w/ o/ H; p
cmp ax,0F386h
1 a3 h$ h( z# M+ d4 y jz SoftICE_Detected2 U- {: X Q! w& i
9 C: P/ X0 }6 c; r
4 W! Y' p9 U- x: w' l' ]" g' X4 t$ H=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit9 ], @6 b" \! }( L2 @
app like this:
4 Y3 O& Y8 I+ e0 f7 T8 S( f3 _1 k5 [0 b
BPX exec_int if ax==689 g& X7 q7 c5 _% a' V/ {
(function called is located at byte ptr [ebp+1Dh] and client eip is1 K" W+ Q% F/ Q# t u
located at [ebp+48h] for 32Bit apps); A& [, h( _; e. M+ l
__________________________________________________________________________& F) H9 I. P# w7 _0 \
% e( ]/ l$ N4 Q1 ]& x. s
0 l2 w1 P, _$ R- C, xMethod 08: f1 Y8 I6 \/ }+ o
========= H" q, I. g' Y
$ d( P) _8 G3 G9 Z! y' F7 F" MIt is not a method of detection of SoftICE but a possibility to crash the
5 p4 ~/ M# J0 h2 v1 K3 s" v+ usystem by intercepting int 01h and int 03h and redirecting them to another( T. F: m1 R6 q: f
routine.
# N- `, D) H# Q. K2 M% XIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
. L b$ V4 r! O4 y, D& fto the new routine to execute (hangs computer...). v9 \9 y# W+ K% E
5 R. Z0 n: S7 _9 P" I9 X mov ah, 25h5 J0 q* ]; Y5 T2 I7 U3 a4 ?- s
mov al, Int_Number (01h or 03h)
0 E7 x/ ~5 h; ]6 A) L4 ]% O mov dx, offset New_Int_Routine! \# ~/ L$ m4 ?
int 21h
$ p z( s1 D" Z6 O3 x) F6 d5 l3 P# b2 u# R
__________________________________________________________________________
8 `/ D8 G( S2 c# a. I2 h/ [& M. w* G0 o& H& H: {
Method 09
/ N; p6 `6 K0 ?- [" |* v7 E=========- @' [9 t- i# M: r& t+ f
* {' G, a% g0 H3 Z, M5 z6 iThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
: b2 }# I2 C1 fperformed in ring0 (VxD or a ring3 app using the VxdCall).& M1 t1 a- ]; D
The Get_DDB service is used to determine whether or not a VxD is installed% P) T6 Q$ [5 M5 m/ z
for the specified device and returns a Device Description Block (in ecx) for
- @* ~+ Y% u; C( @$ |that device if it is installed.% s: K8 L5 b5 F3 {9 k& E* Y1 E( {, b
! K9 q( ?. Y" c& O; U3 a6 K- w
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID& K, ^; ]. x, @1 P/ o
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)1 E- C: ~1 [; {0 }' T
VMMCall Get_DDB) }& c& u: v$ e# ` |
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed6 {# `! {' c7 u
: ]4 k3 i" F5 qNote as well that you can easily detect this method with SoftICE:8 d7 W/ C, h" H) V9 s+ U
bpx Get_DDB if ax==0202 || ax==7a5fh
8 Q0 k; P' E1 R& H
1 ^8 J% a" R, `/ O! ?__________________________________________________________________________+ x1 L$ G0 ?& v6 @0 j1 o, t
5 o2 I: ?) i) @
Method 102 p1 e& T9 l; N# z7 K5 N
=========; l8 W) j8 @! X% ?
- k" w% \2 d' v, T+ b- I' a! {0 t
=>Disable or clear breakpoints before using this feature. DO NOT trace with
: T) V* q: T- I9 O$ x: D- U SoftICE while the option is enable!!! p [* Q" U5 d u; x* o
1 G) m3 W: x. D! R; V7 ^$ ZThis trick is very efficient:2 N9 _7 Z) k. G- t
by checking the Debug Registers, you can detect if SoftICE is loaded
) H3 V; O+ W- @& u; p* \(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
$ D9 i1 {1 ^6 y; A ythere are some memory breakpoints set (dr0 to dr3) simply by reading their
, K9 m4 S+ y# ~ f. Yvalue (in ring0 only). Values can be manipulated and or changed as well5 K( K; C& I4 [: h e
(clearing BPMs for instance)& x$ p1 X9 z( E* m' Y7 Q
7 @! r: r' G% s* [9 ^. |__________________________________________________________________________2 @' F, W% d/ U+ i
" M3 q, {7 O- xMethod 11
4 T c1 |" [$ N& E& g: Q' v8 x=========
# [7 B# I' E( e. s) _ x$ V8 ~
- o3 i: |0 P* c: }. ~& D7 UThis method is most known as 'MeltICE' because it has been freely distributed
, |& f- I( i, l: C1 m4 z- pvia www.winfiles.com. However it was first used by NuMega people to allow+ p. i% n0 D+ s3 `* \5 w5 l+ \
Symbol Loader to check if SoftICE was active or not (the code is located
% C# P, f$ s$ _* k# Pinside nmtrans.dll).
3 G0 D# a# E8 l9 Z1 L2 X, M* q
* W6 ]# ?- w+ J* T# r4 ^ PThe way it works is very simple:* Z( c- L* U0 G( ^6 M
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for9 y# F4 E$ g6 C9 V$ F
WinNT) with the CreateFileA API.# n- t$ j) i/ ~4 g$ V2 z; J
' o" s* @9 F8 A' S6 s$ ZHere is a sample (checking for 'SICE'):/ X1 b& q( r! Y; U
( t3 N0 K( Z' E+ ^/ a
BOOL IsSoftIce95Loaded()
X1 f0 T, h& e0 e{
0 P0 K+ |. i' [( n5 S; U; R HANDLE hFile;
, v6 X" I% s: G: ]3 u8 A( b hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
" `6 S- F# W S. _$ N FILE_SHARE_READ | FILE_SHARE_WRITE,
* ~2 @) p8 \, { A( P NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
+ x2 t: _+ @$ \ if( hFile != INVALID_HANDLE_VALUE ). Q4 ^. z( h# p: R2 b9 T
{: @2 g1 m& Z m
CloseHandle(hFile);9 R- P$ G% ]1 B+ A
return TRUE;
6 W8 G2 A& Q. b" g }
" G) G9 B! \% n8 l2 i4 V return FALSE;- C, ?) p, w' q
}- H+ y( A% P5 F$ Z$ q5 a
2 g/ C) H# |- n8 i( [Although this trick calls the CreateFileA function, don't even expect to be* V- ?: u6 w( v+ s, Y% w! C# l
able to intercept it by installing a IFS hook: it will not work, no way!
& r) b( N. U. F- `" pIn fact, after the call to CreateFileA it will get through VWIN32 0x001F. R# m: o% M9 K( F2 Q
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)' t# J4 D/ a. B$ q) q B/ f5 u( m) h
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
( b* w9 p- ^7 \2 _# N" `7 kfield.; q) Q/ G$ w/ A) t
In fact, its purpose is not to load/unload VxDs but only to send a 4 l' [5 {4 V9 ~0 s* Q$ Z
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
- C1 A- G; H0 ato the VxD Control_Dispatch proc (how the hell a shareware soft could try6 X6 h2 t- g* t# ]) ^
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
# g% [. G' z8 A! G3 E, V* bIf the VxD is loaded, it will always clear eax and the Carry flag to allow# b" N8 |! B1 f* H- K, f
its handle to be opened and then, will be detected.
4 [: B6 p$ g9 m/ q4 w. u# y( }2 \7 EYou can check that simply by hooking Winice.exe control proc entry point8 w0 D4 j* b7 Q7 [
while running MeltICE.6 e% Y$ w, p7 [$ `6 S7 \# x
1 U+ o! G& N/ O& g+ e
! B, _. E! Z7 r: I; b5 ]
00401067: push 00402025 ; \\.\SICE1 ~0 k# g O: |2 {( K3 e" E! P
0040106C: call CreateFileA
0 U" D, h2 x, C 00401071: cmp eax,-001
( B; ~+ {" y# B' G/ g- ~ 00401074: je 004010919 ?% F5 P7 e& s3 l+ Z& r( |
2 c W H) P7 v+ ~5 R* T9 s" S
( c5 c. \$ ?7 _% N
There could be hundreds of BPX you could use to detect this trick.5 O( k7 y% D* x0 R% Q' b3 X
-The most classical one is:
/ X# T% @0 Q: K& v BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
% h) T0 l4 a- N+ Y *(esp->4+4)=='NTIC'
- K! v4 u! E) E# t6 g9 g, j
6 g2 k5 o" G( I# h. e-The most exotic ones (could be very slooooow :-(
& e, h, z1 u2 m* Q% K BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
, ^1 f0 m* b2 I ;will break 3 times :-(
1 @" b: p, u# E. [3 a* I' D2 Z7 e, K9 I' O
-or (a bit) faster: - t0 R9 b) J$ s# L: D2 B' e' J6 F
BPINT 30 if (*edi=='SICE' || *edi=='SIWV') M' R; s2 U' M) o: S, P
4 w8 B5 ~" B% R
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' - [4 l* _, S' \) g/ R Z( }* T0 T
;will break 3 times :-(
; v; I+ d8 u5 D% t( I7 I: V; R3 o
. u* r4 ^8 r$ C* G-Much faster:+ t# j i9 G$ _4 b' y
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'- r/ b9 c9 V4 A! J/ q+ c' M7 Y
3 N5 o0 l5 a- P8 f( RNote also that some programs (like AZPR3.00) use de old 16-bit _lopen1 k' i4 D1 J3 u4 L0 ]% a% d! O) j
function to do the same job:# J, m$ W4 W' H! S7 F' b0 L
# I* O* ^, a2 }' ~" p. z: H9 E! D push 00 ; OF_READ) `, F k9 u7 j; ]7 d7 S
mov eax,[00656634] ; '\\.\SICE',0
0 V* F8 A4 F6 e2 x5 a# E push eax( ?: a. p+ i, ?9 e0 v
call KERNEL32!_lopen1 Q6 B) d$ t8 ~
inc eax7 q# ~- Z: @) B2 q4 l
jnz 00650589 ; detected
/ P$ u4 g/ D5 u9 U9 c% G push 00 ; OF_READ
) G0 E' h' Y; K- |* E mov eax,[00656638] ; '\\.\SICE'
2 C: V# M- \& y9 N push eax8 t$ V8 m9 t/ _# C0 S" Q: a
call KERNEL32!_lopen9 ~ m! E: i' B6 ?5 _* j x2 Y/ C
inc eax# B& @7 I0 F" b r4 j1 i/ P2 {( n: A
jz 006505ae ; not detected
% A/ H5 X/ I5 R6 W, \) ?/ `& Z. x: Y
# T) m) b- X2 d: _. F S2 H8 ~" k3 E
__________________________________________________________________________9 p- ~5 c* c6 z4 J/ r( l
7 z8 E/ ]! x. T5 m! s3 @7 n' oMethod 12
" }# b& J% V$ ]9 z=========
; A: @0 o5 `* |3 [( d' V; `4 X/ e, [" ?5 k5 P) m3 V# U
This trick is similar to int41h/4fh Debugger installation check (code 05. E0 u$ _+ ^0 x) G
& 06) but very limited because it's only available for Win95/98 (not NT)
4 E2 A8 I: Q2 d1 i1 q1 o" B9 a# `& j% J' Fas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
j7 [7 A8 @" q/ S3 ~! }. c
4 A) F: c+ t, P2 `) X' F5 ^2 l push 0000004fh ; function 4fh0 u! r" m5 L/ A8 H! g2 H0 V' {
push 002a002ah ; high word specifies which VxD (VWIN32) D0 j4 B s& ]6 s
; low word specifies which service- M- x; y; u2 f1 @
(VWIN32_Int41Dispatch)
5 o2 ^# _: p" j: | call Kernel32!ORD_001 ; VxdCall
{4 o! z1 k% Z6 c1 u1 t. y. M cmp ax, 0f386h ; magic number returned by system debuggers* A0 i* Q: l) ^! U0 K x
jz SoftICE_detected
n+ Z& r2 x- V1 L+ A! R b a- F
0 l; w& T7 d* v5 zHere again, several ways to detect it:( ?0 @& z; T, [6 _0 G8 ]6 R2 ]
3 E% Z7 Q* n. x, t* z3 |
BPINT 41 if ax==4f
6 M5 U/ b! z- q
( S9 x1 h: K, o! k$ i2 W BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
2 J% m. v3 J+ N5 L. \+ P; R8 T1 L
! B r! q; s" }+ ~0 B& n6 \. T. e BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
. d/ Y& }. T# ^/ Y% p* O
% U: w. _6 V9 x BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
) {5 `. m: a* ]% i+ O0 a: O `8 Z* H5 b* b4 x0 R
__________________________________________________________________________
3 i; e& Z6 H5 U7 w3 a3 T9 a% _- L6 D; F! W6 ~
Method 132 J1 Z: E" y& `" z w0 M9 j7 R+ {! y
=========
$ q i; W, o6 }" N
2 \* E9 G- n T& TNot a real method of detection, but a good way to know if SoftICE is* F6 j1 V9 g z2 u8 \
installed on a computer and to locate its installation directory.
% J$ @$ t' L n) o. x1 _It is used by few softs which access the following registry keys (usually #2) :& ` U- a" r3 i
# M5 q+ ^0 T$ p: I: w-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 U4 a% g6 M' y3 a) Z2 n
\Uninstall\SoftICE0 e/ j$ Z R& b2 O
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE; W! l5 C+ E- E/ Z6 T# w. h
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 Q3 B G. F2 t. J
\App Paths\Loader32.Exe
5 _8 n% F2 ~% o$ ?
1 E# C# @/ r6 j, ?2 P c) W2 ]7 \3 s
/ C% X+ k9 ^; ?6 s9 {Note that some nasty apps could then erase all files from SoftICE directory
& @' W4 x' B: c. Q2 w(I faced that once :-(9 f Z, z: L# u! k& S: L( S
: z7 R/ H/ @0 s7 N# K5 x- sUseful breakpoint to detect it:
0 B* |4 d$ S- M2 H! e0 K* k
1 [- L# u# N1 ` BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
j4 e' ]7 B0 g3 J7 k r1 _2 U# ^9 @% {6 {; a& j/ X/ h7 L& l
__________________________________________________________________________0 i2 E+ A6 `6 X- p, l2 t
' j. G Z: r0 u" a! v& ]& e
( N, R( G) x( I& Q0 x1 L0 r- {9 C: w
Method 14
9 D1 ^2 D6 y7 I! ~8 D=========# J$ v% u8 @4 T2 a( F
$ o& x G& ~: y3 c6 {- r6 }, [' n. R- r
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose/ T, ?- l2 M5 e# ?4 b7 E' C5 o
is to determines whether a debugger is running on your system (ring0 only).
0 ?1 j( K) s5 I# V- R f1 D0 w) y
VMMCall Test_Debug_Installed+ [0 T- E2 F# H
je not_installed$ o, G$ ?; [! p% v
0 F: q3 T0 n9 s) s! Y: u/ v6 GThis service just checks a flag.
# G- \' ^: E" f% A& q</PRE></TD></TR></TBODY></TABLE> |