<TABLE width=500>& t# s5 s9 p' |
<TBODY>. C( \/ Y" Y B7 K# m0 l T
<TR>: [( J; w7 r' j6 g
<TD><PRE>Method 01
+ P6 h+ ^/ C6 d w. L, W; H# J& s7 U=========1 [: I8 l2 [0 S9 b; e5 T
8 t/ n% X8 M$ G) R k
This method of detection of SoftICE (as well as the following one) is
2 K d t# b$ l. _' ^/ Kused by the majority of packers/encryptors found on Internet.3 p4 n" ]! @- ?0 K6 c" l
It seeks the signature of BoundsChecker in SoftICE
/ L7 h2 z! R! F* }7 W/ G
4 I; l. I, _. O+ a0 A) r9 w1 X' V mov ebp, 04243484Bh ; 'BCHK'! P% D+ d; o( o" O
mov ax, 04h
) f f* o, [. F+ Y5 N# Z int 3
1 l! A5 R# L% r; l, ] cmp al,4
" [, {- n J' w# J5 a jnz SoftICE_Detected& Z7 k! v9 n+ {- n8 ~
, z9 F7 o9 c2 O7 I* f0 @1 j
___________________________________________________________________________3 p$ [! p! V6 k( Q+ a/ I. R
U) q% _4 t1 X" F/ T; W# d5 t
Method 029 k5 Y9 n. H$ I4 @* I
=========
4 {! L* E; ~2 P+ Q! v
& T6 Q" c5 F/ W) g+ SStill a method very much used (perhaps the most frequent one). It is used
) A$ r* Y7 V1 k( Jto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
# p7 C( l& i/ E: a+ S8 Vor execute SoftICE commands...* L! k- z# \2 o) @
It is also used to crash SoftICE and to force it to execute any commands1 x+ Z1 u/ E" z# F
(HBOOT...) :-(( / Y n/ w9 _' C" t+ Z
8 p/ k5 o; h! Y! S- FHere is a quick description:
1 ~, a9 f$ S( z. M9 C-AX = 0910h (Display string in SIce windows)- E3 H9 N( l: a8 A
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
# P5 r: L- D/ o-AX = 0912h (Get breakpoint infos)- i$ v4 x$ ? m; b- [
-AX = 0913h (Set Sice breakpoints)( W B; E5 j+ O& N9 H: ?5 g
-AX = 0914h (Remove SIce breakoints)
: C8 v: v6 r/ J2 W/ V0 [! P- s- h' ], m3 d' Z
Each time you'll meet this trick, you'll see:6 Z p: d$ V: B- L, ~
-SI = 4647h
: H1 d" z$ O* }7 _* N-DI = 4A4Dh- f& Z' ]* n; B8 x- E/ s/ r) f: O
Which are the 'magic values' used by SoftIce.
0 B$ e( X( A' {% Z1 i4 R/ IFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.7 m+ P+ P) ]' J6 w
; d! C6 X% B" ^1 p/ v5 s5 X, J3 V8 Z2 vHere is one example from the file "Haspinst.exe" which is the dongle HASP% [- Q& Y. s. s; [" P
Envelope utility use to protect DOS applications:0 n0 N, o3 `! D
^9 C M* F5 T! I& x
; V" x; I* P- b z9 m" n4C19:0095 MOV AX,0911 ; execute command.
0 o4 E: ^7 Z; b/ ^! i4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).7 O$ v# D/ d* B7 V
4C19:009A MOV SI,4647 ; 1st magic value.1 n- o+ b3 }3 H% ] d6 X) K: h
4C19:009D MOV DI,4A4D ; 2nd magic value. Z% d7 f8 f9 I: l' h$ ~/ b
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
* |- ^1 S3 I. P3 P; p s4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute# s( Z# C, o$ x' h) V
4C19:00A4 INC CX
3 ~4 D' f4 D1 {( e- H' v: P4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
7 c7 l! n& n; P) _: V4C19:00A8 JB 0095 ; 6 different commands.
, Q5 C4 f+ b n4 ?3 Q, a" S4C19:00AA JMP 0002 ; Bad_Guy jmp back.
# t |2 N7 y+ e' s( h4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
8 K3 P0 O8 E! v8 n( S4 k
( T* s2 ?; K3 `. W IThe program will execute 6 different SIce commands located at ds:dx, which
$ ?% x+ Z: E1 w) Z, x: M: Sare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
$ T8 p7 L) w( L% R
9 R8 F! Y1 c& ?! e; g* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
& g8 @5 ], Y; F# b! o$ A___________________________________________________________________________
* U6 J2 X. p& E0 C2 c. X4 }" {* n7 }, Y. y& m* S
. W0 `0 Y! B8 z, H+ H7 y6 h
Method 03
$ l/ P8 p2 i: T7 l=========
( h- B' Q& y2 j3 \3 [/ ~( }
. G9 ^- t$ s1 B. h" X8 _Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h3 f/ o* [ [& c
(API Get entry point), c) Z5 K8 H% N, U' r j( A1 g7 ^
% x* h! e* O9 P; p' M& f1 V
! V" y* n5 E- R8 _' V xor di,di
. e9 T1 ?7 o) \3 |" l& E5 B mov es,di
9 H+ r. k) U* i# [2 I# [; @5 P) U mov ax, 1684h
+ h( O% R& `, i mov bx, 0202h ; VxD ID of winice
6 e+ }* I8 n8 y/ {* R) E int 2Fh. W+ |- e( O3 C0 y H6 f
mov ax, es ; ES:DI -> VxD API entry point
9 T7 x1 h; D6 r# R add ax, di
9 B2 K, j! k% a4 j; C test ax,ax
& N, ?8 A. `# n0 U: x2 A9 f jnz SoftICE_Detected( |$ L- N- w- Q( \
, t7 s' }3 ^$ u( Q___________________________________________________________________________% ~: O0 _1 \' F+ _' W: s- ]# ?
8 _$ ?3 W' d+ s" ?9 u; S" ?Method 04
% K' x0 v$ m, Q! m=========
% b9 `$ O6 t, U- R$ [8 h+ J
) j0 ~7 G) m! n7 N' i9 p" jMethod identical to the preceding one except that it seeks the ID of SoftICE+ r1 ~( \( j2 G5 V3 U( N# \
GFX VxD." _3 L1 C0 F9 J8 I) k6 `( N% W( Q6 s
; V6 |/ e9 e1 @. G h5 ?* ^6 P
xor di,di
% Z% b! n3 j. e1 S/ m mov es,di
& `" s( p/ D* O: ?4 o mov ax, 1684h
/ s2 H& E7 \( n8 m7 r; ]. a" q mov bx, 7a5Fh ; VxD ID of SIWVID \/ P2 w5 K0 T# o+ m. B T& j1 n
int 2fh; ~4 k( T& C6 l, j7 ~6 e
mov ax, es ; ES:DI -> VxD API entry point: J# B! d+ E& _! v8 e
add ax, di
8 f: t3 t7 w9 {. J* p test ax,ax
! H' C$ x# S; A/ D% V4 h jnz SoftICE_Detected# I+ ?# j# {# ?# B, a' U* k
; k' D4 o7 D' H6 ___________________________________________________________________________
$ e7 R; {: l( o& U. ` \5 E- k; P$ L6 ~+ t( v; T. e; F/ f3 N: v
6 P; b% s1 f$ X# S1 v1 M7 m' ?Method 05& j$ x' ?- C5 d* g3 A
=========: M4 n: {6 E j+ S( s5 Z! O9 x
7 G& A6 m- n0 S1 w
Method seeking the 'magic number' 0F386h returned (in ax) by all system( F0 ?- i5 c" b" r
debugger. It calls the int 41h, function 4Fh.5 ^9 y3 }* k4 m6 E# o, s1 ^
There are several alternatives.
' o% L$ c9 o; O3 ]. `; D* a& o
7 E$ r0 z D" [9 q( ZThe following one is the simplest:, U8 T, A" F/ M5 \( ~/ l
, g0 o) q( g- p0 y7 a mov ax,4fh
& |$ h L7 A; p5 P int 41h+ J; @* W$ }+ E' x' ]% A
cmp ax, 0F386
" s6 k1 i; N% u# ~3 w jz SoftICE_detected
( S. f8 b) T M/ G* M: \! R, q' J: ^- a# M h
+ m0 ], f8 |. }: U* Q/ b9 LNext method as well as the following one are 2 examples from Stone's
& L6 Y/ q. C: s7 t" U"stn-wid.zip" (www.cracking.net):: B! O, d$ @( P6 |2 X# h- E/ C
1 X% [3 P& L! t& {5 d# U. d
mov bx, cs
! b) V! q$ b' a% T6 B) e lea dx, int41handler21 `4 ^) p, i$ B: i B* c
xchg dx, es:[41h*4] K! J" w: [! _% l9 i. J
xchg bx, es:[41h*4+2]
5 l# v) R3 X% H+ m8 D( J. ?- f mov ax,4fh# Y& [$ H* x v3 `3 X+ c
int 41h& _5 H6 ^, c4 E, E# `( H
xchg dx, es:[41h*4]
3 V; V9 {) I X- Z2 k2 f$ a xchg bx, es:[41h*4+2]) ] e3 d8 w. v9 t1 z
cmp ax, 0f386h+ M: E3 \6 d. o- u, q
jz SoftICE_detected
% R2 C* n8 |' m9 ^( [8 P# M8 ~' |: j. t6 k
int41handler2 PROC4 u2 ]3 B7 e& o; A' z7 C, Z+ q
iret
, e; e+ r9 }5 ?) i* n# Sint41handler2 ENDP0 Y* ?- |( q( w; |8 i" N" f+ |4 j8 k4 H
) ]* X: @/ P( S6 {3 m& s1 Z; z
5 k# b% p& ?; G3 }0 R, `_________________________________________________________________________
3 L M+ b. A t1 d: e8 _2 A$ |: B1 u( W$ [# E0 C
/ Y5 h; a0 y! n0 ^9 I7 lMethod 06
, e) \) `2 I2 k) a, K M=========7 G* G: E X1 n( x' p x, s
: U5 ^! A, S- b: r
6 a% p* e* d2 d2nd method similar to the preceding one but more difficult to detect:
7 U/ G4 w+ U2 J6 m7 a0 a& ~- B2 {* X+ M. m4 l6 `9 I# {1 Z0 I
6 o6 K. ]+ x) P% k$ S/ ~. Lint41handler PROC% s! Z* ^, U) C6 y
mov cl,al! j; R6 F/ Y! P. v! X& U d% j& B
iret; V" T0 m. l6 Q. C1 m
int41handler ENDP+ N" }2 _$ P# G7 p( t/ T
5 \# w, ?5 x U6 d( {
2 w" c& X3 ^" B% N! j3 d! B# R xor ax,ax
5 e4 B% B1 v( d+ N! E# H. O0 a4 J mov es,ax
, `7 S y( f& V! N R; E mov bx, cs
. a5 }3 a7 n- `6 v! ^- b! G lea dx, int41handler0 A& ?) I! F6 G1 ~: V
xchg dx, es:[41h*4]
; `; w& t( ?" z! D) u xchg bx, es:[41h*4+2]/ F8 b# A4 A/ K; @! D+ ^7 J: A, a
in al, 40h- e& \: t" M8 A% W- p* q& _7 F% ]% B0 F
xor cx,cx- i6 j' P) P$ d4 w* g) g. h
int 41h/ D9 @. q$ Q8 R% x3 F
xchg dx, es:[41h*4]
) ~ j! t* w. s xchg bx, es:[41h*4+2]1 d- y6 H( F; ?/ K( w
cmp cl,al
0 \: V/ x; k! s0 {# O: d' ] jnz SoftICE_detected: X: Z! O: s. E& ]( d m; n
6 y. y% j: g! H3 m# f9 s_________________________________________________________________________. j0 N, W3 [2 y% s1 [1 k
1 N$ ]4 `- i: @
Method 075 \6 ]1 S; C# W5 W e' z+ m3 b0 P8 u! \
=========2 n4 W) S5 ]5 F; x* S9 ?) Y
( j+ M. U9 M i7 s' DMethod of detection of the WinICE handler in the int68h (V86)
* Q3 S9 z2 ]- f
6 Q5 P6 _; {$ {1 `7 j8 _ mov ah,43h
; \1 l% r& H. o1 s1 s3 D int 68h
. A$ Y& ~* l4 w- l* |0 j1 b cmp ax,0F386h
- C7 g' p3 f* R& b4 J% y" r jz SoftICE_Detected a6 j R u0 D( V/ w$ ^9 x
% U6 U/ Z6 |& `! U& Z
! g9 @8 X! ?, Z* \9 U3 e# K' ?) J
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit' H& K, ~/ s2 s' j* m; U) k
app like this:
$ S' d" f1 t3 i3 P
, H1 d3 h v. d9 H4 [( N BPX exec_int if ax==68
6 X4 l) @0 {/ b1 b& V& \ (function called is located at byte ptr [ebp+1Dh] and client eip is! o5 ?% B7 @" f! v5 @6 y! G
located at [ebp+48h] for 32Bit apps)& P% a/ W8 c/ R0 q! c% R. W
__________________________________________________________________________ @0 \5 g f2 s% h- @- ?
2 k$ r; G E8 @ ^1 ^, s
# F& `1 o5 x% \% h/ cMethod 08' P2 ~+ ?8 F- }4 N, ]; ~
=========
4 @3 v' U% n" C, p3 n+ c8 i" G% |5 M+ q' |! J3 }7 r+ ~
It is not a method of detection of SoftICE but a possibility to crash the
" h7 x+ h1 r$ K, p4 H1 Jsystem by intercepting int 01h and int 03h and redirecting them to another
% ~2 a6 P! {8 u$ u2 T. wroutine.
% Z: I' D+ N5 F5 l/ n U3 f! y( MIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
$ Z4 _9 H' L" C2 A6 Gto the new routine to execute (hangs computer...)
3 C8 }4 Q' d& S7 |0 }6 H
% A1 T: x$ r7 k0 I mov ah, 25h1 g0 }2 y. A+ h5 J
mov al, Int_Number (01h or 03h)
! Q, I$ F; i! s* ]* N( k/ T mov dx, offset New_Int_Routine% [. f0 I4 ?/ u" i3 {0 B
int 21h
3 P- x! A6 C9 F1 ^5 F# f. L6 n& R& i3 i0 ~* e) k
__________________________________________________________________________
5 m$ v" F9 E: g6 |$ T
# k6 g( S: m0 e' ?4 k4 q2 K* Z+ ZMethod 09
. v6 O) R+ }4 G, a- `. C, Y=========
# E6 I9 r6 [% f6 Z g. _/ m
: U7 W0 u, Y: s/ W7 mThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
! p, h$ q! H2 J1 Lperformed in ring0 (VxD or a ring3 app using the VxdCall).
7 @/ o8 `& h2 h4 }8 P1 d& C) LThe Get_DDB service is used to determine whether or not a VxD is installed- c) E# I) Y7 \+ Y. w- W: l
for the specified device and returns a Device Description Block (in ecx) for1 u/ e8 F8 Y' `0 V
that device if it is installed.
' E: N C% m" A% a6 T- W
+ m* f- n" ^2 J; Q) S5 K, n7 S mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
' v( v2 [ \4 @ mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)' F; a( s0 {7 T* L6 j0 a7 O
VMMCall Get_DDB
# \. E7 h6 x$ |, d) i. O mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed: Y0 w: `: I( U" L4 U, g
; }2 K+ H% F* T h2 L4 B! @Note as well that you can easily detect this method with SoftICE:
( n$ Z" a' H, Z1 s bpx Get_DDB if ax==0202 || ax==7a5fh
! I; {& o- ~; n) e: W
/ |" r& ]0 H$ n- L__________________________________________________________________________$ F3 J( L. e5 S q# q, E
q6 N. o' O ? T5 |2 P
Method 10
% M5 R) Q( w$ N! R=========7 b: M, L7 K$ Y! m
6 N/ ~; @( q% U ^! _$ @+ b! C
=>Disable or clear breakpoints before using this feature. DO NOT trace with
( y- @5 w5 y, G, t* O( i' o) y U SoftICE while the option is enable!!! C% m! @" d, E2 z+ Y
" Q. l" f" i2 EThis trick is very efficient:
1 ]* C( w* u% w3 ?9 s; Aby checking the Debug Registers, you can detect if SoftICE is loaded6 h: ]8 X9 G) M; F
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
% A O- K5 n8 I3 J7 V" Dthere are some memory breakpoints set (dr0 to dr3) simply by reading their
$ k; d* l6 A- f H5 F5 Nvalue (in ring0 only). Values can be manipulated and or changed as well+ o9 j& |' P6 P
(clearing BPMs for instance)
' Q% c( X2 n2 m, S6 q- T, A E7 q7 H4 y: |
__________________________________________________________________________4 `2 [7 C- u2 u% M% {8 t
) f( o. j0 ~9 b
Method 11+ ] t- N7 D- T8 R3 F
=========8 I# O5 W% [' K' h* D, _
/ M. x8 o; E" q9 q2 x$ rThis method is most known as 'MeltICE' because it has been freely distributed2 k; m+ O$ E3 H4 @2 F
via www.winfiles.com. However it was first used by NuMega people to allow
. o/ m5 a. P+ m) p! F- t- F4 WSymbol Loader to check if SoftICE was active or not (the code is located/ a2 `: V+ ?' O
inside nmtrans.dll).
( Q/ K* Y4 t( q7 X) i, p4 j# R, ]; Q: l2 ]+ _# g
The way it works is very simple:0 R* C* V: U, D6 H# ^& g
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
* |, r6 z$ D% `/ F* x7 D3 A, aWinNT) with the CreateFileA API.) L* c5 T$ a: ?/ e
+ K, T" k5 T: iHere is a sample (checking for 'SICE'):
. O5 x- p. t" ~
! e+ w! p" W$ LBOOL IsSoftIce95Loaded()! P* H$ C8 v2 V( L. H
{
' h& E# T: T# j4 d2 a. U' R HANDLE hFile; * C4 ?1 n z* `8 @1 D
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,/ k2 M. w4 q) ^9 a2 g7 I
FILE_SHARE_READ | FILE_SHARE_WRITE,
; ]' y) S# K8 ? NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);) G' c E+ r2 G, z# O5 z' K7 D& I
if( hFile != INVALID_HANDLE_VALUE )2 j- Y3 b' l( [7 u k* n) o
{( e* I, ?4 K7 y% [7 Y+ t
CloseHandle(hFile);
$ a6 K5 }9 V7 g* N! z: W& U; t return TRUE;
, m/ |* ?3 E R$ g7 l! c6 S }' K- I! h1 [+ l+ K' s: } ?
return FALSE;+ [+ w& b u* R' \, d# `
}
1 n' A( n. G/ s( {* w5 q4 c _
' l/ b, O3 @- e! yAlthough this trick calls the CreateFileA function, don't even expect to be/ I9 ?( `- m6 l
able to intercept it by installing a IFS hook: it will not work, no way!% O* l8 r% L7 T- d: c$ O% m
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
6 q) j. d/ @7 [5 Y2 O% kservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
( h8 N8 I/ D+ Tand then browse the DDB list until it find the VxD and its DDB_Control_Proc5 p* w2 \6 ?# `5 }
field.
$ K w8 I4 ^" \5 [5 c2 J) ]1 wIn fact, its purpose is not to load/unload VxDs but only to send a ' K* H9 \, ^' ^2 f: Z
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE), a! r" h e/ `. _% w
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
4 }/ T* M: D. n0 }to load/unload a non-dynamically loadable driver such as SoftICE ;-).% X' P+ O1 Q3 }& T0 o& B" D
If the VxD is loaded, it will always clear eax and the Carry flag to allow; {' s( |# p* r% A
its handle to be opened and then, will be detected.
6 n' ]$ }, G% z/ pYou can check that simply by hooking Winice.exe control proc entry point8 l/ T/ P6 l) w
while running MeltICE.0 J0 v& ^8 E( k7 i5 |( ^& [% s
9 ~( u% N/ ] [& U+ Q2 h/ S! E
6 _, W( e8 R- F$ h( G: L O/ k. ?
00401067: push 00402025 ; \\.\SICE" q1 e- s4 z O0 V _8 Z. j0 o
0040106C: call CreateFileA
% q* }" ~3 Z) e, N2 i 00401071: cmp eax,-001
; Q$ s% F( ~: s' w9 D 00401074: je 00401091
% P; B; a$ l! T3 B+ h( T" ]
* C& ]4 u% L6 O
, M7 G- g: R. P' T1 ZThere could be hundreds of BPX you could use to detect this trick.
- e) Z$ u9 Y9 ]4 i+ ]# n-The most classical one is:4 N. `7 y) w) | `% t
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||7 ?( ]/ |6 {9 n1 A* c, x9 k
*(esp->4+4)=='NTIC'* `' p3 S2 q7 h/ L' O7 J+ e: G
( w3 W! \% e' J; ~6 U3 y4 N& V6 M-The most exotic ones (could be very slooooow :-(4 ]8 p$ {+ ]0 S
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
; k) S9 d3 T* g8 K1 A; j ;will break 3 times :-(: X2 s0 O3 _$ V8 `8 }/ _
+ I, Z1 u0 P: U; M2 O- o
-or (a bit) faster: ( P- M: a; s3 x
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')4 e) c: R. Y* f$ `% X5 u+ g, I
$ {/ P$ y* p/ E5 \. x* `% |+ A m
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
0 z+ p/ E* [& C6 [ ;will break 3 times :-(- y) X+ Q( `; z( o
# @1 p$ q$ ~0 W% Z" W* J9 @# E-Much faster:* x' A) r3 _% A
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
$ [) S$ _/ q1 G+ w- n
9 n8 b# p3 p3 Q* r8 t1 A8 {Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
2 N) Y1 M' |# J( U! ], D' sfunction to do the same job:
3 G: y$ T8 |4 w+ Y! w. y
* I. I$ x% E( v& Z push 00 ; OF_READ
9 \# R9 k' J& S4 ]# ~" u6 W mov eax,[00656634] ; '\\.\SICE',05 `! b+ U! J# g0 W" ?& g$ [$ A) ^
push eax
/ t3 _. q9 }. Y0 t% s call KERNEL32!_lopen0 L4 }7 Q& s0 G) u( m& U; D/ ^- r
inc eax
4 b- m. w- g2 F: Y" i7 W& E jnz 00650589 ; detected
6 c' O% ~. ^6 z push 00 ; OF_READ6 K% y- N& z ^9 s
mov eax,[00656638] ; '\\.\SICE'4 B1 f( p" X: q& p& P. V
push eax Z! N, s3 Y7 C1 c
call KERNEL32!_lopen
. s. }' v# m8 q/ A. ] inc eax
6 f6 W8 O1 a- g& z" e1 c jz 006505ae ; not detected3 K9 K# a3 K' J- E5 x! q
' k" [6 ?1 t2 H
& [# \! Y% |6 O ^$ k. Z
__________________________________________________________________________0 T/ z* C4 i( Y3 Q) R$ ]
. M" E6 R8 G! C& X( j5 mMethod 12+ R) o3 t4 X \0 ]8 C7 q2 B
=========+ D5 t5 |, ?5 M
# ?% E/ w- l, g0 |
This trick is similar to int41h/4fh Debugger installation check (code 05) N: z* f. F8 C7 i! l
& 06) but very limited because it's only available for Win95/98 (not NT)
( a8 Y1 w5 M+ ]: t, Z2 f- Sas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
! I! K, q' ^7 G2 e, i0 I1 y3 x' {: e3 w# K, q: |
push 0000004fh ; function 4fh
# W& h2 `4 G* s! @0 s- A& r push 002a002ah ; high word specifies which VxD (VWIN32)- R6 M" a! E1 n& N& f3 O4 t
; low word specifies which service
" S4 o, G0 ~3 u4 A2 ` (VWIN32_Int41Dispatch)$ p1 i0 l7 J/ \5 m
call Kernel32!ORD_001 ; VxdCall2 t$ S$ X, m! _/ z7 v
cmp ax, 0f386h ; magic number returned by system debuggers
$ x( b- c$ b! }; ?( N, I: V1 A1 s jz SoftICE_detected4 D+ R' E3 `& u. T1 A7 G! w. @
* A( ]' U2 \2 `+ k; K4 q, s! r% CHere again, several ways to detect it:# G: d- {6 R; U; O; \$ k& h2 V
7 i; @, Z5 ?, v+ L; v( @
BPINT 41 if ax==4f" J% c$ x( s5 r u( O7 K) `1 L
: f, H8 G8 M% m6 Q+ t8 f BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one l- U+ T( E# |: {8 Z Y
; m/ z7 v2 \! C5 \$ v6 Z BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
4 q+ ~# j5 S. P) d& ~
3 ~0 F3 ]" _1 O7 w. k. l BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
2 F8 l+ {$ l+ I# d, I' M. _5 C- a1 K4 K" C
__________________________________________________________________________
4 f3 G/ N8 F% Q2 w9 t* D, e
1 @* c5 y/ O% `8 _Method 13
+ c. S1 w, v" `9 O& W* e=========0 C0 g/ U& s& Z. B) h( }( W
j8 h2 D# F+ k7 b2 ?& J# @" w" v* z
Not a real method of detection, but a good way to know if SoftICE is3 k- t6 M7 y* i: Q+ Q$ d( M
installed on a computer and to locate its installation directory.$ t7 |5 ?9 D$ L
It is used by few softs which access the following registry keys (usually #2) :
- L: `2 c, h9 f" w- k h+ F& t, U% i$ |0 c# ?
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
) G# Z" J0 A: Q- n. f" }\Uninstall\SoftICE; d1 B+ L+ X4 r+ Z4 S0 b
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
1 G+ D I& k! {4 M+ C$ _8 y-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion' }; i& F( L( ^7 v
\App Paths\Loader32.Exe( `2 \' t0 g/ ?* ?: ~
+ g/ V( D9 z$ f( k6 @1 W6 R
# d/ Y5 }9 k7 nNote that some nasty apps could then erase all files from SoftICE directory7 U* h, S- ^8 P, c
(I faced that once :-(
" k u4 ?: P$ s. f
! R3 i3 i+ O: [( F- Y7 c# oUseful breakpoint to detect it:
5 q# T, `' K: f" N% P
% k# h4 V8 c% F+ Z, k BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE' b% o5 k0 D+ M6 o- x) Z
9 V; k# n) Y) U6 V__________________________________________________________________________
" w: g/ m$ @# @( `& V0 t9 c- ]4 E( ]$ q% e* t% O
: {# ^* [5 K- F3 W
Method 14
: a$ c9 U3 R( u( H=========
! W: w \' F; t6 r5 [) d
' [) N0 V% @$ o1 p+ V# R" ~7 eA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
3 | V d& ?8 l* q/ v) M$ b. |is to determines whether a debugger is running on your system (ring0 only).
2 ` H, q5 U+ V3 U" i) ~5 S; s3 x$ Z. l4 J' h/ D
VMMCall Test_Debug_Installed
0 Q7 x) n2 Y6 F$ X8 s% `8 y je not_installed
) R7 D( y9 p, J5 s
2 q5 _6 [6 r# Z1 ~This service just checks a flag.
8 A* X2 w; ^( ~6 T</PRE></TD></TR></TBODY></TABLE> |