<TABLE width=500>& H5 b" L9 p3 A. _3 p+ C
<TBODY>! B( z' R$ D: B/ f) H# V
<TR>
9 T5 i2 N; d5 }4 r* m/ i, A! U<TD><PRE>Method 01 " O' L; X# H5 y: ^
=========5 u" X5 Y9 [! [2 d
) O+ Q4 V2 d/ H" d" O( i3 J3 ~7 h# A: gThis method of detection of SoftICE (as well as the following one) is
4 r# j/ U$ z6 e! R Y5 @: t1 l" qused by the majority of packers/encryptors found on Internet.9 w, _8 R1 {4 _$ K6 t, ]
It seeks the signature of BoundsChecker in SoftICE W. y* N D: p
5 C9 ]' U2 C0 U1 { mov ebp, 04243484Bh ; 'BCHK'1 f: y7 |9 n+ x% L. y% u
mov ax, 04h5 r* G' }2 K& Y* \5 d; a. C
int 3
0 @. ^5 P+ J2 e/ v+ g cmp al,4) z+ t$ q9 v2 i8 N$ |
jnz SoftICE_Detected) I' }) J" e. t& U- C U4 U! r0 }
" Q- y; B, l9 }& c7 U: D
___________________________________________________________________________
$ `6 [0 t% U+ }8 `4 \9 Y+ g! E# K0 |5 b; K7 [6 x" ~
Method 02
* \! r0 k6 ?. b, h( S' f% m; ~2 s=========* V3 K& y1 t. J! B& A4 |
" @$ i# Y" e. H' h1 j1 [# J, uStill a method very much used (perhaps the most frequent one). It is used
" u7 x3 L) ~# [7 Q) Z7 g" q8 C; \to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
! P5 S6 \8 C9 x* [2 N- u5 ]) m1 {or execute SoftICE commands...
9 m8 z6 }9 G, X& yIt is also used to crash SoftICE and to force it to execute any commands3 r9 r1 ^. j! [. ~* h* {1 c: j
(HBOOT...) :-(( 1 Z+ \# G! ^6 p/ y3 k, A: D2 }
7 h3 u5 t% O9 x6 d, i* e4 SHere is a quick description:
. S% v5 A; p1 p-AX = 0910h (Display string in SIce windows)
* Q7 l6 j- s$ m- B/ \# Y. ^) F3 s3 G-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)3 V- f" t3 w' O9 Q* g
-AX = 0912h (Get breakpoint infos)6 t$ r2 V: W( ]0 r# L
-AX = 0913h (Set Sice breakpoints)
& I4 P0 `+ F$ c! R-AX = 0914h (Remove SIce breakoints)8 [: g1 l7 N" h3 t
$ Q$ t+ h& ]6 yEach time you'll meet this trick, you'll see:' \9 R" O9 ]4 q/ ]% C* o; j9 @4 i
-SI = 4647h% y- B& h+ B% L, E4 Q. @
-DI = 4A4Dh( r! E; K- w. t8 t2 j- M
Which are the 'magic values' used by SoftIce.
) ^8 N/ e+ v/ R1 U3 [7 \2 dFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
# z3 H3 O1 \# U: r T1 L' g- J+ z' }5 F
Here is one example from the file "Haspinst.exe" which is the dongle HASP9 s/ y$ c1 I/ D4 t5 V) N# J5 ?
Envelope utility use to protect DOS applications:
5 }" P6 y7 [ e! p
! [2 Q: |" Y7 t5 G3 P: |0 ]# }4 G6 p
; N4 D; v$ E" G) |6 t3 J" \4C19:0095 MOV AX,0911 ; execute command. N8 O' h- g7 Q5 U$ A- C8 O
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).* Y" |* c# N7 F- b2 B
4C19:009A MOV SI,4647 ; 1st magic value.
: v9 N0 Z6 @6 y; B6 l4 S4C19:009D MOV DI,4A4D ; 2nd magic value.
0 K% x5 A- U# M; d% H, D/ z" \9 }4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)9 Y+ U! a, ]/ m) p7 M
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute. w# m& H0 ~2 I# P8 c% U! z
4C19:00A4 INC CX4 \: f. p0 D! f& K8 E. Q8 [
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute0 p! M) s# o6 v
4C19:00A8 JB 0095 ; 6 different commands.
( z* W, _3 o4 e$ [9 C4C19:00AA JMP 0002 ; Bad_Guy jmp back. M0 a, J. g1 |
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)) q: a# S) `+ Z' w
e+ d; A! G, q
The program will execute 6 different SIce commands located at ds:dx, which3 A: A* u2 ]$ \4 M' t
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.: D9 ^; h) O2 {: r0 d" A, X
9 p# k, w- m* q/ E+ W% \! s+ u3 V
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded. e) {, W; O" B o" c
___________________________________________________________________________# \5 w+ W8 z6 ?; C
7 C4 P! n3 M9 @3 H) Z; `1 M& d
, w8 L! ^) H; R) }Method 037 Z" A3 r5 w, V# Y# _5 w
=========
& {! d; ~8 T3 e8 ]( k
/ k4 |8 d" k1 f4 CLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
5 ?, ^8 l/ L6 i+ V2 C* p(API Get entry point)
' y2 S6 o) @$ {3 R
8 j0 K8 Z' P+ X2 g5 z" t+ z0 W ~) o6 }6 a6 w
xor di,di
* ^( e5 Z9 q0 A mov es,di2 O7 c4 e$ w3 K4 m" X
mov ax, 1684h 9 w2 M s3 z o0 \
mov bx, 0202h ; VxD ID of winice
) S/ p+ V# j, @% y' \ int 2Fh
) a( b1 }/ W5 V+ H W% ` mov ax, es ; ES:DI -> VxD API entry point, V- f2 X6 P* B0 s
add ax, di
% E# ~- v# `6 i/ M5 v test ax,ax
7 r$ E' @7 G" D1 Z3 K: X6 g P% O) p jnz SoftICE_Detected$ N" J& h! e# i3 ^5 S( s% j- }
$ I( u+ p) }+ c9 @1 y" I$ Y
___________________________________________________________________________
2 K% X* @5 o: |. M1 q, B$ i- H, C N
Method 04
: P. F+ y! t6 v2 ?=========, Q$ |6 I# R9 d; G! t& c7 R5 s, t
* G9 m* T9 ~! z8 U0 }! B$ f' L
Method identical to the preceding one except that it seeks the ID of SoftICE" e z( z0 E7 l ?+ D, q; h; x
GFX VxD.
) n0 [4 k% Y$ Q n1 ? L) w/ b3 x
( f. ]; q& g- {3 k- r+ ^ xor di,di
$ y7 C# }& ?& k5 ` x m mov es,di1 @9 U+ K; d- ]
mov ax, 1684h # i. H- J5 I/ D, D) q
mov bx, 7a5Fh ; VxD ID of SIWVID$ ]$ I) ^/ R: ^+ S3 E$ D
int 2fh
' t+ b' t) Q' C$ W0 C mov ax, es ; ES:DI -> VxD API entry point
" x7 v' u7 X2 E* T' h( o add ax, di
7 R+ A }! m& L( F9 m+ d$ x test ax,ax+ V3 H+ o7 I1 C, ~$ H9 H1 m# p$ Z
jnz SoftICE_Detected
7 i% s% H% s7 P2 W, v0 z/ \" h% T
__________________________________________________________________________
+ _$ S8 X7 E. e) g- x) Q, J0 ]1 T5 N6 t: B/ L% P0 o
; z! s( m2 Y- e3 Z% [Method 058 O! W( Q) L( ]: h; e& v9 t
=========
8 ^' A* {) z5 C' L$ E$ D
p- J# U# y S: e! V- j8 P7 |9 _" W. RMethod seeking the 'magic number' 0F386h returned (in ax) by all system, N2 D6 e2 E! D4 m6 N3 `1 y5 Y$ g- R
debugger. It calls the int 41h, function 4Fh.
, d2 P/ s6 D# {& V6 E6 a% r7 ?( IThere are several alternatives.
( ^, c" `* N5 Q) V2 ^- G- d' T( T
The following one is the simplest:) Y/ V! Q+ \( X
, w/ X5 J/ s% f: T mov ax,4fh
R0 K. p$ }8 ?2 b% f0 f int 41h
, G3 `) N0 m( ]3 H3 z6 B" i8 t cmp ax, 0F386
% _( a# _6 l3 T jz SoftICE_detected8 b/ G! u; d# t" e7 j
% E7 h$ {- a1 a Y, X! ?; H! L) f% `! M& a7 E. a% c
Next method as well as the following one are 2 examples from Stone's
$ m2 f" ^! A* E* _9 a"stn-wid.zip" (www.cracking.net):7 Y5 z9 j' ^ n# F
3 H& `( d- I/ V+ } mov bx, cs
6 \; Q4 O8 ]: \ X2 g; M7 M lea dx, int41handler2" ~. w2 ]5 w1 z/ x; Q; o( P9 U! _4 j: K
xchg dx, es:[41h*4]
" Y7 C, O/ f' a5 u xchg bx, es:[41h*4+2]
: Q4 Q) l- n5 T# u9 ?3 R. q( D+ Y mov ax,4fh3 |- u0 G2 T8 U! t; B. C; z
int 41h
v. |2 F# g0 x# F. c8 L: U( n2 L xchg dx, es:[41h*4]
# ~3 j4 h1 T' `9 B xchg bx, es:[41h*4+2]$ O+ z6 O( L0 Y2 |% _4 e
cmp ax, 0f386h
2 I: q5 o) e3 ?0 n2 N5 U. S jz SoftICE_detected, {7 `" b/ p! ~# I
/ |0 W& T/ U) S# ?' P
int41handler2 PROC9 m9 E$ ^( D- p. [4 D. {7 c. Y1 i
iret% }9 ~6 O0 f( H1 G7 D
int41handler2 ENDP
/ z/ U9 S' ]( v6 D. J
* V; E* N/ B. O3 u2 j2 X$ ]; u2 q
- y1 R2 l5 r$ d6 g Y* Z_________________________________________________________________________
/ _! ^1 C2 s) e
1 _, R% ` x( w- a% L# c9 y1 v+ J# x6 W* k
Method 06- G$ l& [' I1 E6 A0 s
=========" e$ T. e( ^1 n% n& n
7 i1 E) M/ x& I/ E
! H. w% g/ y4 f0 D1 e
2nd method similar to the preceding one but more difficult to detect:+ l7 [2 I3 @& |1 w* ?" `) m
& K: V' M, w) Q7 e s! t5 b6 E
# [; T0 @0 @# m8 V2 s, Q4 C: g" @% hint41handler PROC' I" S( {( u4 j9 W: n! e( ~9 b/ Q
mov cl,al+ K6 e' b" K6 K0 z* `( G
iret
' Y. q* g! b6 Q8 d' y& T7 y& @! yint41handler ENDP
* ?! D4 a+ H7 P' G% i' v, T/ ?" p& t0 g
1 e3 h6 L) u( ]) p- d4 w
xor ax,ax
+ a2 Z+ F& U% b mov es,ax+ Q" c }! P0 j M
mov bx, cs
; Y: k1 L2 H6 @- M0 b lea dx, int41handler
% @) k5 P; b V% d xchg dx, es:[41h*4]
" F! }! T3 u; w xchg bx, es:[41h*4+2]( a7 U9 a1 W$ I9 z$ a% \
in al, 40h2 k e3 L; k- C& l2 ]* X, `
xor cx,cx: o) n, R3 l; W' m3 J+ m% h3 r+ E) e
int 41h& R# Y1 {) D1 `8 T) J; B" h7 |: p
xchg dx, es:[41h*4]
$ S2 t Y9 R7 s: _! P; k xchg bx, es:[41h*4+2]
, {, Z2 X, U+ X5 `; ?/ B cmp cl,al1 s" S1 ~; O% c& K+ G* D e
jnz SoftICE_detected
9 p/ d0 A3 N+ ]& _/ g' Z$ p
, |8 L" n3 M3 l; A% h' e2 g_________________________________________________________________________
' D5 b! t3 J, }; ^
( \& k, n7 P* m. bMethod 07. O3 V2 z& n9 v$ `1 J8 g" A, K: G* z2 |
=========& V6 Y, N! T/ s% {! A/ j
) q0 @! a* R- Q2 P) u' i8 aMethod of detection of the WinICE handler in the int68h (V86)9 b" J' F9 b$ a: u/ _# B2 }
% ^+ S) ?9 s% Y" @7 h0 U7 Q mov ah,43h7 h) z9 o2 T y( ~4 F
int 68h2 o( m) [4 O0 E6 `% ^2 r' R) |
cmp ax,0F386h% Z' u. V$ R5 ~
jz SoftICE_Detected9 T1 f+ y8 m" Z4 y. k2 B! O
) C4 K4 k, e' ^2 [8 N+ _! X: ]% ^, t M8 A- D
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
+ a6 y$ V( |! `& \. S% d7 J app like this:
7 b W* W: Z r0 K0 K$ m' \- {) d. s5 s, D$ B
BPX exec_int if ax==68, z: k' k2 a4 [
(function called is located at byte ptr [ebp+1Dh] and client eip is/ d1 ~ U$ f* T8 i8 O9 e& P1 ~+ a
located at [ebp+48h] for 32Bit apps)
( t: a. N0 n' A/ \; [1 o__________________________________________________________________________8 w# i1 Z+ W- ~% X' _& ]; c" w% u
, N5 v$ F; S/ z! b& L4 |! ]1 Y4 d" G$ y* ?( @/ o+ ^, b$ ~
Method 08
/ y# x: l R5 H# J, r========= i' D2 X) ]$ Z! E) H
" E' ~/ [, [7 |- \. K) T# ^' eIt is not a method of detection of SoftICE but a possibility to crash the
" f0 G- t- b: N( I# c' Psystem by intercepting int 01h and int 03h and redirecting them to another# s6 V; y' h/ R* K" w0 F
routine.# w: L% [" N5 r$ }6 {
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points+ e$ ^. Z; ^. N' n* m# Q9 ?7 y
to the new routine to execute (hangs computer...)
* ~* F8 M/ g$ h" j1 Y/ B. _$ O- Q) b5 {; p
mov ah, 25h
/ m: @1 n2 P$ z3 @# r6 Z mov al, Int_Number (01h or 03h)
* L( B# K* \/ G9 q9 R mov dx, offset New_Int_Routine
8 g7 @' G" \* V: w* l9 D int 21h* ?: F% X u ]$ u6 J) U4 i
( x3 h6 z; Y% }& r1 E
__________________________________________________________________________
0 Y8 r) u. g, f, u+ U; l3 u: q) U. ~# S
Method 09
% O! m9 E3 w5 W& p0 O) S9 ]% ~=========" h$ g R8 L8 x
" s. n8 F! y& CThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only3 z2 d+ V" k* H' `
performed in ring0 (VxD or a ring3 app using the VxdCall).
4 ^9 {) q" B/ d4 K! \4 mThe Get_DDB service is used to determine whether or not a VxD is installed
- O f0 A d# b: e- X/ q0 r( Nfor the specified device and returns a Device Description Block (in ecx) for
& t" V4 c4 Z3 T, x6 {that device if it is installed.% z; G+ { g( B
+ d9 P. A! J7 _
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID- _$ h2 n1 C' l
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)% _4 w; Z+ ?" }2 O, N- t0 R
VMMCall Get_DDB
- T& r9 F; h. _' }: F# J! i0 R mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed# Z0 t- f" Y) K& q+ x1 B
7 M% ~; M+ B0 b$ E- K$ Z, UNote as well that you can easily detect this method with SoftICE:
0 ?* T; R( }6 X" ~ bpx Get_DDB if ax==0202 || ax==7a5fh
. x: c& `$ i# e [% k" s: m
( K) X5 x! ~1 W% g__________________________________________________________________________
: _9 z) T. X! t+ F9 K
/ w1 V3 A* l) k3 x# z- V0 ], \Method 10
) o/ o6 A- w3 y, C! J x j=========4 O9 t0 `( w) e8 W# k
9 c1 e" ~1 Y4 y/ Z& A# T0 t" }=>Disable or clear breakpoints before using this feature. DO NOT trace with: P" I: Z5 ^9 m6 k
SoftICE while the option is enable!!
, G( E/ G" m9 p! C0 }1 J. o2 ?" L! Q# ]5 g3 u5 m
This trick is very efficient:$ z8 K" d! B6 C0 T
by checking the Debug Registers, you can detect if SoftICE is loaded! s% u3 l. G- [. f
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if4 X! `! C( W/ G( S9 w3 g
there are some memory breakpoints set (dr0 to dr3) simply by reading their& W# ]6 A, M$ E! X
value (in ring0 only). Values can be manipulated and or changed as well2 `8 S8 E, |; z' m5 Z( S9 m! x
(clearing BPMs for instance)
# [5 Z% D$ ~# ~* m5 D
% ?+ W3 A/ G4 w( W8 S2 Y7 [__________________________________________________________________________
8 y4 k1 n, j3 \/ H# i9 K& A* L1 y! L6 n; s
Method 11( |4 C7 a' q; A. ^
=========) v K* ^' k+ j; M/ L
: w! b1 o$ x4 X( C
This method is most known as 'MeltICE' because it has been freely distributed
) I6 A5 w" m" o ^$ ~# J! zvia www.winfiles.com. However it was first used by NuMega people to allow ]8 P' T& g% r+ W. [
Symbol Loader to check if SoftICE was active or not (the code is located
) P% v$ Q2 T0 l6 n2 l7 ~: zinside nmtrans.dll).3 a& }7 e, a% B+ {( p1 P: \+ n* d
- X. X- X! y7 r/ k; e' c6 ^/ V+ b1 [
The way it works is very simple:" p4 [5 C! ^& @/ p1 }1 d7 U
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for& X4 u$ k' O) \4 [7 X/ w
WinNT) with the CreateFileA API.
' m. }. }- u- s
( Z" A P' d" L4 P9 s0 IHere is a sample (checking for 'SICE'):
4 n" W, r1 g) Z# a" \! o! P8 d$ C% T# _7 L/ G! F( u
BOOL IsSoftIce95Loaded()5 l9 B% X* \- ]5 z( U
{
' k% m# _2 Q1 E# G HANDLE hFile; : w. W/ T0 J7 L9 h3 ^/ ~5 z
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,9 x3 P- l* V- _" P
FILE_SHARE_READ | FILE_SHARE_WRITE,
" w+ c$ e' W% i5 l2 D( P3 P) g6 F3 [1 A NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);4 I( s7 Y; K/ g C! e6 D0 \
if( hFile != INVALID_HANDLE_VALUE )
9 U+ n- h7 W8 V/ @( [$ W5 W {
( U) t& c, h" p5 F& N CloseHandle(hFile);
/ n8 l- K; I9 R1 f# C8 f return TRUE;
* G9 O$ w' x/ ?7 k6 J' b }" W& |, J5 `5 n) J6 B( C
return FALSE;; @, ^: N" X# Y
}
% D. `9 M6 W% Q. u) V; `8 h
9 t# T8 `/ P- e/ O7 ~! xAlthough this trick calls the CreateFileA function, don't even expect to be( Z' ?1 Z1 z2 r# H+ H* }
able to intercept it by installing a IFS hook: it will not work, no way!& k$ L' K7 `$ ?7 f/ m! K/ ~. P9 }
In fact, after the call to CreateFileA it will get through VWIN32 0x001F0 `+ B, s( T6 Z# N
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)) f0 u- P/ J* Z9 s# @
and then browse the DDB list until it find the VxD and its DDB_Control_Proc% ?# e( t1 w& Z) s* g9 F) r( S% [- C
field.7 D' k O) g+ f N% }1 D
In fact, its purpose is not to load/unload VxDs but only to send a
: o, P2 B$ r0 d J5 r! x* O8 dW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)! y) m- R7 W, E( A X9 o+ o
to the VxD Control_Dispatch proc (how the hell a shareware soft could try' g" f0 x/ `/ w8 z4 Q# z. S; Q
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
/ T2 z2 a$ `. l$ D- Q/ D7 x& J. `" rIf the VxD is loaded, it will always clear eax and the Carry flag to allow3 Y1 f, J6 v @
its handle to be opened and then, will be detected.
1 P. G$ X, [& F& M' J. wYou can check that simply by hooking Winice.exe control proc entry point, j/ V0 e7 Q" f# m4 n; m* a
while running MeltICE.
5 B5 V" F/ }# h" v4 H1 `+ d% ~1 R [/ g: e f
. r8 H2 ~0 c$ ` W! w6 r8 o0 |$ S 00401067: push 00402025 ; \\.\SICE
* f) L0 e8 O- B T9 M5 f/ x6 W 0040106C: call CreateFileA
1 F/ M- q& X9 @* l( \, a) A% r9 X 00401071: cmp eax,-0011 J' ~+ s+ R f4 _+ [% Q7 `. p: X
00401074: je 00401091
( Z$ @4 |# y$ R0 d
1 d0 z/ x- j/ e0 v) O
! c" P! r3 G+ m; n$ KThere could be hundreds of BPX you could use to detect this trick.
/ v! d1 Y- V# v- O0 {2 [-The most classical one is:* F m" ]! k4 F# z f' k7 Z. f p
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
5 h, ]. Y; s. c% w *(esp->4+4)=='NTIC'5 u; J/ h5 y2 ~2 u2 V) ?/ g# q
& U: Q5 N6 Q) D* A4 @ \
-The most exotic ones (could be very slooooow :-(
) ^' A7 `* c$ G% y4 G BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
9 ~ \& {9 F+ c1 i ;will break 3 times :-(( o1 o$ D" X3 ~2 Y: M) I3 T- d
" b) d' t% D3 b-or (a bit) faster: 0 b1 J1 }# r+ i2 f5 q" \
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')9 b x& E. F9 N& n! E% C0 H p
6 ^3 n9 B' N9 I. v# W( q( t
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 4 P+ U n1 T- {+ x3 P( ^) e8 l
;will break 3 times :-(6 K" G' m& s I8 r+ @; u: p7 Y
2 \3 x+ n0 n1 Q4 A9 X4 v' v0 x3 }
-Much faster:6 \- L9 ]: {: ~' ~
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'- q3 M1 d$ r5 I) I5 a8 ?
4 G1 s" u/ u: f
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
% }! y) v; u3 Q% g4 t1 ?! I4 K5 [function to do the same job:+ X/ c- X' k! S9 S6 X. L
~) p1 W g% `& n- a5 L4 O
push 00 ; OF_READ4 C, ], R( `' N4 s+ Y- r
mov eax,[00656634] ; '\\.\SICE',0
6 x9 R2 t0 O$ E+ G push eax- T1 w4 H2 b, E: w2 z
call KERNEL32!_lopen
$ k% Y. `; i0 U& O inc eax
2 C; y* w B' b) P5 X jnz 00650589 ; detected
$ K& t3 R2 B0 d% h K! `! x! T push 00 ; OF_READ
. G5 T( g+ i F0 J9 s; i# a mov eax,[00656638] ; '\\.\SICE'" H* e/ h$ ?) w
push eax/ ]. ~ b/ @- w) s) }3 T
call KERNEL32!_lopen
8 N0 g8 q4 P, w' g# L inc eax
. C& q9 R/ {! U7 n jz 006505ae ; not detected
1 `1 F8 h3 L2 ]9 U/ X8 A3 D7 x) U. S4 z/ D/ G6 j' { A
0 `( ]. ]# u) P: R5 p__________________________________________________________________________
0 Y7 n9 d& `* t- f7 ^
0 K- F5 [/ g5 s- s% x- lMethod 122 {# o! u( W e& X8 ~; V, h
=========5 n8 ]: p) Q) K1 v$ z' a7 f# K
5 _1 d5 L' l4 b5 lThis trick is similar to int41h/4fh Debugger installation check (code 05+ A1 W' k5 r1 R/ j( [" C
& 06) but very limited because it's only available for Win95/98 (not NT)
( E% w9 U5 M' ~. r4 @as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
$ F! M" V1 H+ x, ]4 P- b
8 s+ r6 Y& _: D% V6 \( L- N8 p push 0000004fh ; function 4fh: ~" d: r% Y# H& t+ s
push 002a002ah ; high word specifies which VxD (VWIN32)
: l2 L$ Z( [5 l8 j: j9 l) w ; low word specifies which service/ Z: b# M5 m4 e; h
(VWIN32_Int41Dispatch)* P; p8 P8 n& G/ ^' u
call Kernel32!ORD_001 ; VxdCall; m$ h# |$ h( S: k4 [/ c) L
cmp ax, 0f386h ; magic number returned by system debuggers }" w' f5 j2 }! e: S" C1 H
jz SoftICE_detected
1 v2 L7 n$ v$ d6 s$ M$ C- X7 n/ i8 P8 A& m( N
Here again, several ways to detect it:
( W0 u% Z' z+ r% m a1 Y! d5 x! `% i0 Z2 T# f6 Q% N+ W
BPINT 41 if ax==4f
! R1 G2 ^7 a4 l5 p$ [5 l
- D8 y4 N) H4 s% H3 x BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
2 v7 z, w' P0 Q; x; S3 \6 K: ?# R
5 [; x! H2 J+ o8 `- l$ e BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A) w* i5 h+ J7 Y0 t3 B: H2 J
/ r3 r' r' M" W+ S# n4 V
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!. l& J# X( Y+ d8 D. s
' ]7 e2 B3 ~6 u3 a% Q" o8 q__________________________________________________________________________1 V5 y( y' H) u% u4 n$ |: h
* P' ?5 A1 d2 p4 q d- J2 xMethod 13# d/ {/ U i7 M9 m3 |! l
=========+ k9 L/ ?2 K7 C$ U# g) \' ^/ ^
% @) Y" S! V; W) I% |$ ANot a real method of detection, but a good way to know if SoftICE is
& J2 M% I- c& D1 m6 h' g9 Hinstalled on a computer and to locate its installation directory.
) o( |: l" \8 u. \# b$ VIt is used by few softs which access the following registry keys (usually #2) :1 Y- e1 C* @8 O# g8 Q
$ ]/ q) G8 ~0 C) f: S3 _3 v" k' ]-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
3 {0 _6 C5 F( m4 D" Z1 n$ O3 W\Uninstall\SoftICE
* p) u3 t2 D' ]; G-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
# a/ b8 p3 `, ~-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion) w7 q, e! I6 S. R& P
\App Paths\Loader32.Exe7 e0 @7 S. e$ s) {% K( i" w; P& E
& Y; Z& M, F9 |4 @( l
1 m5 {. w$ A" x/ uNote that some nasty apps could then erase all files from SoftICE directory. x4 {* d3 U. p. U( V6 L* G0 H Z1 m
(I faced that once :-(
& [4 u6 D( P3 ?" w7 b2 a) t9 y# T' n. p4 |3 q7 J
Useful breakpoint to detect it:! {7 H/ b! A1 _2 e
* r/ U" D. i1 g BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
# A" V$ S6 {* c! d- u' ?7 S% M9 Q Y% p
__________________________________________________________________________
- e; V7 z7 ~$ \* D$ h$ a
" r! B$ w$ n+ o2 I! e3 B8 M- M% d) E2 W: S# D& T
Method 14 ' f0 e1 Q- c+ q. E% ] d
=========
4 }3 K5 k# [& S) o9 p$ r( t: Y$ R
( L+ D4 |8 f/ G) \6 LA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose4 h' d7 g: s2 o# R, l* p
is to determines whether a debugger is running on your system (ring0 only).! O0 c; b$ R9 ]
3 _- F# A. l0 o% W9 u: j VMMCall Test_Debug_Installed
9 b/ `5 z9 x) a5 Y S1 u je not_installed
8 y' A8 v( q3 x, X9 ~+ \1 c) N) e9 S; i; T: A8 x T0 J
This service just checks a flag.
0 Y% ?* u# S5 y3 o</PRE></TD></TR></TBODY></TABLE> |