<TABLE width=500>2 G, t4 r3 Q; |. D ^7 j5 j, Y
<TBODY>6 J$ v) @8 H6 \4 S' W8 Y
<TR>- I6 R6 x( A, r3 ^" j; l7 k# M
<TD><PRE>Method 01 + d' P `. I5 ], l- p
=========3 |+ T2 t' s& R
- B1 D. F: Z4 KThis method of detection of SoftICE (as well as the following one) is5 v) u# L9 w( J2 R( O
used by the majority of packers/encryptors found on Internet." b/ k! c! [$ H. Q1 o5 h
It seeks the signature of BoundsChecker in SoftICE0 ]1 g: T% ?, g! v! c! A5 \3 T% c+ ?
! u5 X# k8 `/ ]! @5 H
mov ebp, 04243484Bh ; 'BCHK'# T9 I6 f7 f+ O* G0 N& I
mov ax, 04h
# v$ y) N4 L* M+ K% k1 Y8 B- t5 M int 3 2 @* d V& J" z% L
cmp al,4' Y% \% N: c) g8 B
jnz SoftICE_Detected) ]" P R& M2 M2 F( x: e
0 M* ]9 j0 g4 p3 Z1 c# F3 G# M. o+ h6 ____________________________________________________________________________
- ]# N' o* @, M+ @+ ?
8 K2 K8 n) u5 ]Method 024 y2 |1 o9 R2 j! p3 ^' r- X
=========& `! d+ q/ ]( Z& B2 D3 s4 a" g
/ E u% w+ Z. E: [. A7 Z
Still a method very much used (perhaps the most frequent one). It is used
7 D7 U: [ ?) F! M, ^5 a+ xto get SoftICE 'Back Door commands' which gives infos on Breakpoints,* a. C0 C8 c8 z2 n; S
or execute SoftICE commands..." [* g2 k6 L2 L# J9 n+ D1 p
It is also used to crash SoftICE and to force it to execute any commands" r- O4 @% A$ | n' ^, s
(HBOOT...) :-(( 5 y0 B5 i3 Z2 T% V: B/ {
8 U9 Z" g; m1 N
Here is a quick description:
4 A) m8 u- V3 v7 d5 c/ c-AX = 0910h (Display string in SIce windows)
* ~+ w1 A+ g$ I6 U) F* n-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
$ v" B& l/ C2 \# D-AX = 0912h (Get breakpoint infos)/ T' H5 g" U9 z3 |8 `
-AX = 0913h (Set Sice breakpoints)
1 v0 `# b1 q' q1 Y-AX = 0914h (Remove SIce breakoints)
+ q7 ^' _& Q0 H! a. W. x7 ^$ M4 y/ ?. o
Each time you'll meet this trick, you'll see:! U8 v9 E1 x8 b# o% z
-SI = 4647h7 M! `" g5 C9 c% y
-DI = 4A4Dh1 {3 l( K- r% r/ N) ~
Which are the 'magic values' used by SoftIce.. g1 r3 \0 W& E! X% z
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
" {, R7 e1 E o3 o3 O% ?' J. x7 i: q; }8 S$ w: O$ W% L
Here is one example from the file "Haspinst.exe" which is the dongle HASP$ a6 e9 n, W, W7 [# b7 A8 m
Envelope utility use to protect DOS applications:5 x$ `1 i/ X0 G3 c+ \5 w Z
8 T7 P* f' h1 Z' ^3 \- u" z
, ~2 U# }/ m; @4 N1 v2 j0 c
4C19:0095 MOV AX,0911 ; execute command.
7 _! I3 g; i1 Z4 v- j4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).. S5 i* x5 D% x
4C19:009A MOV SI,4647 ; 1st magic value.
" ~/ V& v/ _+ k2 j; f. D6 j4C19:009D MOV DI,4A4D ; 2nd magic value.
* c p+ J! L! i. x4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
6 R- x# K; o: g0 D7 k" }) \4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute$ q1 F F3 P$ D
4C19:00A4 INC CX/ Y/ ? U+ M' b }& V7 ^
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
5 c: b# @- J5 j! v4C19:00A8 JB 0095 ; 6 different commands.
1 K) |; L! z a$ X- k* t5 `4C19:00AA JMP 0002 ; Bad_Guy jmp back.
+ M* ? r" x$ G, Q4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
/ k* x) p( X4 y1 P, ]* Z4 t! |$ r7 l3 `9 ^9 B8 I2 S/ m
The program will execute 6 different SIce commands located at ds:dx, which
/ M3 c }: U& s. V; Vare: LDT, IDT, GDT, TSS, RS, and ...HBOOT./ s- V7 P0 E. r: }4 h* \2 C
- S% e! b" B" Q/ j) x* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded. H% V! K+ ^( ]) ?2 q
___________________________________________________________________________
( F* ~' s6 @0 @
# ]) _& U" l, y' l+ T: x
, }4 N4 }" {# J d3 `% HMethod 03
- J% t. J" a" O! s=========
. j! M4 D; v3 K) a0 t+ E( c" i% Y1 c
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h) g+ |) ~( o4 o# P2 K
(API Get entry point)5 P6 G P: N8 ~
( W& N0 u, U* F+ S* ]2 S" ^1 l: Q2 Y; W) {" C+ d3 R
xor di,di
* ?9 d8 P, |8 i5 J& K( t3 y& z mov es,di
+ |2 t! x. g+ j( z2 h mov ax, 1684h ) i9 i8 r* o4 w' k" i% X6 r
mov bx, 0202h ; VxD ID of winice- q% ~, \/ G0 p6 }! A- M" y
int 2Fh
, {7 ?9 c' q) K. _" X mov ax, es ; ES:DI -> VxD API entry point
8 R* V1 p0 J$ n add ax, di9 x, U2 ~: I- a# ]
test ax,ax
3 d) o8 g( j' q- _ jnz SoftICE_Detected& |" M8 N& f# P9 f
: x( u v3 W# \7 n1 m
___________________________________________________________________________
8 { M8 o a- L, P" B U: E/ t+ _" X* X9 o" v* N
Method 04
3 a# y' [$ s% u& ]=========
5 ^5 ^, F) y& [# n5 A$ m9 E& A! g2 p- u
Method identical to the preceding one except that it seeks the ID of SoftICE
( \! E( m Q, A9 G( @8 {% y; BGFX VxD.
# K0 |# L: D# `; h s# I* [' L- ?3 {5 [7 z$ q5 A( f
xor di,di
7 k$ E, I- e3 u) B mov es,di
% W$ M/ [& J' H! p! M mov ax, 1684h
# v/ M0 y8 }' Z6 B mov bx, 7a5Fh ; VxD ID of SIWVID
$ O: l, ]" m% j9 _/ K; U int 2fh: j& |. E r5 J' Y8 @, N
mov ax, es ; ES:DI -> VxD API entry point0 a7 g5 W* Q" Q- k
add ax, di
6 P4 p' E- a, s9 U6 H test ax,ax! b' M0 T. U/ Y! ?# L u1 B
jnz SoftICE_Detected
5 w: r! V( [9 K" N4 M* x# \
H% `5 s5 v& {, x__________________________________________________________________________! h# F/ I X8 o' [" i O8 G
, W- O4 |2 E8 G6 v* ?' H: ^0 S
/ T; j& Q- F: q
Method 05
1 ?) f; o! {. K |0 M7 `, _=========
0 d6 l9 Q3 s" ]7 y! L( V, a }: r$ O$ R. R. J
Method seeking the 'magic number' 0F386h returned (in ax) by all system
2 c) f+ D+ T o! C! fdebugger. It calls the int 41h, function 4Fh." T8 z9 ~7 ]/ b' s" a! j5 u
There are several alternatives.
6 `5 a& }# s4 d. o! @7 f
* T5 j$ y9 Y0 AThe following one is the simplest:
* _" Z) s( f' S; B) }: w1 t
E7 o8 Y. r7 o- Q( W, s+ i mov ax,4fh
8 N: m. j G% L3 \2 Y5 M6 O1 u int 41h3 o1 n' e* x4 m- A( `
cmp ax, 0F386
* n" Q6 w. ]( V% z0 L jz SoftICE_detected# n# W$ Z/ b/ M1 p5 q2 `
6 r. C/ Y' g/ N4 p
$ d6 @! V) f2 G- e. iNext method as well as the following one are 2 examples from Stone's
! C/ L+ w3 {+ @0 M" |1 t"stn-wid.zip" (www.cracking.net):
1 k8 C' K! P9 u- G/ |3 u; |' I/ }: s% ~2 l9 _' q* n
mov bx, cs" N$ ^, D5 e2 K( v% c' V% k
lea dx, int41handler2' Q# G: G( _2 b- h2 ^7 e3 O: L8 W
xchg dx, es:[41h*4]
) k( S* p4 {& L9 J7 ?- A9 j9 B xchg bx, es:[41h*4+2]
: X' E& N& k; [+ M( P4 Y% Q' r mov ax,4fh/ D \$ N+ r0 f- g' R
int 41h
( E# K- `. C. x$ N' j, @# J' o xchg dx, es:[41h*4]( \8 E! q: Z' W+ U x3 W
xchg bx, es:[41h*4+2]! k0 o; R6 l P5 e( S
cmp ax, 0f386h( K$ N L {+ D
jz SoftICE_detected8 v" @) j4 N G. q- Y' W& w
* P1 o, _0 z3 V$ r
int41handler2 PROC
: K# O; F3 `' C, O4 x5 E iret
' J, i; F- k9 I% D9 k! Qint41handler2 ENDP+ E4 d, j4 t p' r' S9 x( Z4 I. o
: _. f0 D( |# Q; m. }7 D7 p8 G* x
Y) R; F5 V! _8 F+ l/ e3 {- _
_________________________________________________________________________9 _5 V V+ Q* R& ^
# K0 M) ^5 m' U9 m( e1 M. {# S' D9 @& s. I/ o6 X6 S1 l& _
Method 06* O ~ I" q" a7 i# J8 ?
=========* K! U5 A* }- E; Z. B$ k; d
0 O) Q, \& h% X# r( F. | l+ U, F: T( \) q4 a7 M" |- u7 d* F4 {/ G
2nd method similar to the preceding one but more difficult to detect:! m4 o" O8 m' K1 e, ^- Y6 _/ [
, e: q( L) E; s0 o4 O! b8 T& J+ z
Q) f' B$ p' P0 Qint41handler PROC7 e1 z/ ^1 H: v/ z5 ?; ~6 D% S: u6 r+ A
mov cl,al; @: A0 ^, [! x/ t
iret7 p; ^" i5 f% y5 A( W: s
int41handler ENDP
) i4 Y& {7 o9 J0 H D. ~5 V5 M6 t' H! w/ _: T
2 f) f) l/ Z1 K; P% j! n
xor ax,ax
6 `: }. d* }% [/ i' e mov es,ax
. K$ q2 J9 x' D9 m- @+ R mov bx, cs# F9 i8 A) m4 J- S/ m- b
lea dx, int41handler
+ |& c R+ H* Q- l$ X5 v8 n xchg dx, es:[41h*4]
. \9 [# D( e+ q# h5 i xchg bx, es:[41h*4+2]$ N5 U e$ E9 J! U
in al, 40h0 L& D( Z: X3 ^9 T G4 |, s: c. d
xor cx,cx5 V& `; f, M; K( Z+ I2 `9 D. V4 o. l
int 41h
7 r0 \* T8 d' w* i5 S1 r$ a: T xchg dx, es:[41h*4]
& ]: k/ p& Q- C9 a, |& Q xchg bx, es:[41h*4+2]
1 g3 x- k m u0 r, H cmp cl,al
# |- F6 N% w7 _+ a8 F! X jnz SoftICE_detected
$ z: Q# j/ K/ [' m7 N2 i' d/ s+ t, ^4 f( S& x: n9 b
_________________________________________________________________________, B- \$ j2 R: g0 f8 m8 e
: m0 `2 H* `! ^; v) e) X, {Method 07
: l! I6 x: M/ ~=========
# W& f; T {3 i( `- E& K$ E1 X
' J( I$ N4 O2 R4 }Method of detection of the WinICE handler in the int68h (V86)
6 [ ?& T3 _2 I7 t" D
`$ A1 X) r5 Q7 u3 T mov ah,43h2 C( ?/ l9 p; @- ?) w
int 68h$ t2 o1 z3 X8 p: d; u" v/ L
cmp ax,0F386h) R' B/ j* V9 ?6 F
jz SoftICE_Detected
, u) ^% A, R% s" `9 L/ P- m* t/ b% V4 v( z9 p( B9 f
& Q+ C' c2 ]3 R=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit, m5 \. i# i7 C v6 q* P
app like this:
/ m# b# r) I- i. Q) J
3 Q- M8 @, v; R% p# H# s1 ` BPX exec_int if ax==68+ |$ L* A8 \8 r1 H9 Y
(function called is located at byte ptr [ebp+1Dh] and client eip is) V! m0 d# L8 I$ q# x
located at [ebp+48h] for 32Bit apps)
" h; S: I% Q( R& u' I$ r__________________________________________________________________________
0 H0 J) O4 D U0 r# f% m2 _' z0 A
/ @$ \* c9 h" r/ k
# b- x1 g- h' |) x" @Method 08
3 b/ a6 i% H. V9 r=========
" B7 r9 {8 f' o7 b( w; Y$ q' u6 Q [" ?- v! P& N* x2 O$ Z
It is not a method of detection of SoftICE but a possibility to crash the
# d% ]7 V4 _; V+ I7 jsystem by intercepting int 01h and int 03h and redirecting them to another/ v/ B) M T4 I. l. e: a
routine.: E3 Q6 r) G7 m! r u$ d1 e
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
2 v7 }2 p3 F4 T% A* N4 P+ x3 r' cto the new routine to execute (hangs computer...); }" P; o" a5 A- c3 f
5 E9 \. a3 E' |- ]1 `9 t5 ?9 i7 N
mov ah, 25h0 {: P0 o3 W" f
mov al, Int_Number (01h or 03h)$ l2 D9 z! C. }8 r
mov dx, offset New_Int_Routine7 _: O+ \1 H& R: W
int 21h( I8 ^6 w& a4 i
; e6 f* w. z" w) n) J# `
__________________________________________________________________________7 ^* p, D7 S! u1 |
) x2 e6 E: s6 I) k7 R
Method 09
9 Y# Q; v- [; R7 h- F=========1 [3 }* `6 g) F- Z$ A. g( U% x
, e5 F6 g" [% Q& H5 Z1 Z6 R$ TThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only* y2 r [3 N5 d& Z h. e! g$ [4 b
performed in ring0 (VxD or a ring3 app using the VxdCall).( B' S% Q* v; [% B$ O& h
The Get_DDB service is used to determine whether or not a VxD is installed
, C6 u- u. b2 _7 B" T+ i, ffor the specified device and returns a Device Description Block (in ecx) for
4 d( K3 [& F1 M, D! Fthat device if it is installed.
# x" W' Z1 @- }+ p) h0 V2 f, E) _
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
7 d/ `' b' {! |- x# Q9 g mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
1 J7 q6 R8 ^- }/ ~. N VMMCall Get_DDB% i1 q9 z1 w$ \$ D, o
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed9 a* `, }, R4 g2 j
6 S8 E( t& m+ \& b
Note as well that you can easily detect this method with SoftICE:; `+ Y8 M/ ~. ~9 F; R3 P! q' F g
bpx Get_DDB if ax==0202 || ax==7a5fh0 O# u( U' r& O9 N0 n* S' z) }1 h
( P- r; u! v3 ?# D0 {
__________________________________________________________________________! ^! d! L- H( S, u
# r- q' x) W& Y; }8 N3 e) {3 P
Method 104 ]- @& r3 K; b5 H9 Q4 p0 i
=========5 D7 }4 ]0 s6 \- m- U b
% I) `. b9 d6 H
=>Disable or clear breakpoints before using this feature. DO NOT trace with& p- Y' g9 I& U# p5 P1 N
SoftICE while the option is enable!!- z5 {2 u& q1 U1 @' p( x: i
, ~- B% l0 K$ y$ G: ~This trick is very efficient:& M) U( T5 k* Z! X. m3 x7 S0 u3 L3 J
by checking the Debug Registers, you can detect if SoftICE is loaded
" l( L4 ^9 O3 z- e: h(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if. n" t6 u* l j# W- O
there are some memory breakpoints set (dr0 to dr3) simply by reading their
$ z% `* I8 y* b% @ Bvalue (in ring0 only). Values can be manipulated and or changed as well- A8 J/ ~. ^: H; K7 M
(clearing BPMs for instance)0 W$ P) C Q$ S; y3 p! L
8 O! t; n! C/ u) d! Q__________________________________________________________________________
+ v+ i' J/ h9 e, `/ F8 o& ^' Q
% Q; b5 y6 g" B x9 ]/ F" t# hMethod 11
" R8 B, V# G$ N/ A9 r=========5 x. s/ m" C0 X8 i
1 p y, M8 r. Y+ ]; ~4 \
This method is most known as 'MeltICE' because it has been freely distributed- v- q! M- y& P! N; V
via www.winfiles.com. However it was first used by NuMega people to allow8 v4 |7 J- D0 y' e3 Y8 V% @% `
Symbol Loader to check if SoftICE was active or not (the code is located
. `$ b) Q" S& M) `inside nmtrans.dll).2 r% i; b! s. O& n
" A k4 z6 i1 K, F, sThe way it works is very simple:
2 x+ `: h1 @) F3 _It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
3 v/ F. [2 T) r6 W& R" Q7 @WinNT) with the CreateFileA API.% N4 @7 p! q) b8 G8 ]
9 H6 T! p. s+ a: i: P
Here is a sample (checking for 'SICE'):* O( W" ^& R/ i* e" e
5 w5 u0 t# J& x/ ^+ PBOOL IsSoftIce95Loaded()1 R0 P8 ~ t# M7 S% Y. V; h
{
+ p2 k1 l* T; p9 W* F8 V o/ S HANDLE hFile; ) }- Y" I2 g# v; R) G
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
- j8 ?( F( Y- j& o" S* d: h FILE_SHARE_READ | FILE_SHARE_WRITE,- y4 a/ r, V5 _$ s
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
2 l- W; `7 t: T& }: \ if( hFile != INVALID_HANDLE_VALUE )
5 B* r6 n' B; X, P0 v6 v I2 s {
+ N6 \1 p+ \ S! D; J1 o CloseHandle(hFile);
) y. ^% }6 T0 a; L K return TRUE;
% T( {, E1 r5 Q# E6 t& q p# y! ~ }- n# ~& e |9 D
return FALSE;! L- z& ^& a1 r& p [/ e
}
) Q8 o' r3 W4 o, F
# S. R0 Q; j6 X* ?, tAlthough this trick calls the CreateFileA function, don't even expect to be
) r& ]2 q2 @1 c" b% [2 K3 @% Pable to intercept it by installing a IFS hook: it will not work, no way!
* r( H. N& i3 Q* ~' tIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
' i" M# j: c1 f+ u+ X9 pservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
; [3 G" t1 g( B/ F5 o, ~and then browse the DDB list until it find the VxD and its DDB_Control_Proc2 B9 B5 m! q( p4 z+ ^3 |
field.
$ t; q3 T! q* k3 I0 D WIn fact, its purpose is not to load/unload VxDs but only to send a ( H# \9 `- M% k2 ]
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
1 ^* H; |' n6 P8 }+ ?2 g. g6 Lto the VxD Control_Dispatch proc (how the hell a shareware soft could try N* p* u+ F6 D. O% W- _- Z& {
to load/unload a non-dynamically loadable driver such as SoftICE ;-).3 X' t3 q9 K0 b$ F1 [: A R6 O5 N
If the VxD is loaded, it will always clear eax and the Carry flag to allow: A Y& L$ X/ B
its handle to be opened and then, will be detected.% J u% J8 \2 n, m7 s5 ^8 ?
You can check that simply by hooking Winice.exe control proc entry point7 E$ i U d5 s
while running MeltICE.
6 h- D& S8 z: ]: Y5 @8 e- a! G2 a H9 L2 T p1 h
' S) R- q6 S/ N& f% y
00401067: push 00402025 ; \\.\SICE
7 ^% W1 \% p" g1 Z' C 0040106C: call CreateFileA
% g- [6 g; s: f) n: o# L/ ^- l- { 00401071: cmp eax,-001
/ b) D6 W. M/ \7 q u t 00401074: je 004010912 b" |! x0 _+ i% ~/ T
, }8 C8 A) k1 `) I6 l7 Q' o
% v; W& s* _0 z, T& _There could be hundreds of BPX you could use to detect this trick.
0 ]$ J, F! T! n) \% b-The most classical one is:/ C" I1 t+ o% j1 v9 c& k ?
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||: q- g" C" } U9 t. g0 y' `
*(esp->4+4)=='NTIC'5 e# p! V0 N' @7 l1 K7 z, o
/ T$ L" b5 g9 K5 F$ u$ y-The most exotic ones (could be very slooooow :-(
% ~) B: p6 b/ ?! E: a1 @* r! Y$ n, N BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
0 a1 Y" T |1 x' y& ^ ;will break 3 times :-(! a9 D' K6 ^4 b
4 ?4 X E: L* Z0 E: E' @, b-or (a bit) faster: 4 c8 ~" L5 G, u) Q- ^- ^2 N2 R3 G8 d
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')3 P7 v( _# k# w/ `( p, f- y
( h2 v3 }( ?$ w$ m" v( a4 r BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
# a3 X; h& X* `5 M ;will break 3 times :-(
% o a. c& s i' M+ X9 N
. r$ `* I1 w; X8 ^6 E, {- V-Much faster:6 w7 n9 w9 I7 B6 g
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
$ c. K" x2 }8 F2 b7 E$ n8 v9 M' b( h j4 O! s8 ]7 e: V
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen6 N1 k; c) G E2 G
function to do the same job:
3 H& I; Y# n! k+ @: `8 }: M
: ^" Z/ J; n) `2 R6 e f push 00 ; OF_READ
3 D) i3 z7 Z2 E8 [* q6 {6 ] w3 M mov eax,[00656634] ; '\\.\SICE',0
! f \2 e9 b8 }) P push eax% ^& T6 C8 H1 Z/ T
call KERNEL32!_lopen
$ b: F$ ^6 [0 T+ | inc eax# E( N4 K G+ m' l( L
jnz 00650589 ; detected% a" ]" K# d3 P4 ^4 ]9 I4 k1 J% N
push 00 ; OF_READ- t) c( A6 j. W
mov eax,[00656638] ; '\\.\SICE'
( O7 B5 |9 G. R3 P push eax2 T6 T: [% S0 q; N0 n
call KERNEL32!_lopen
# Z$ P( Q) |. R1 v2 s inc eax
# a7 x/ f# h7 ^* o, X7 W* d jz 006505ae ; not detected! d% Q4 K& @" b, s j1 ]; \; ]
. A( U# k; O2 H; u x# e, \4 h: L: C) _' I0 I
__________________________________________________________________________
* L& \: F) n. D* t% F
6 z2 K7 z: x1 E" J3 EMethod 12
6 i# E/ H/ h3 I=========0 V& t! g0 {( V$ @! T
. h$ p( T2 b" p
This trick is similar to int41h/4fh Debugger installation check (code 05
# V2 h& ~0 n; `1 J. X6 q& 06) but very limited because it's only available for Win95/98 (not NT)
' w `- Z8 i0 n4 M- a, C1 }7 `0 yas it uses the VxDCall backdoor. This detection was found in Bleem Demo.2 |) L" u: m# v. N, J3 k) `
" ` s+ t, \0 L4 i push 0000004fh ; function 4fh+ c: ^9 ]7 \/ ^6 J" l Y9 U1 |" f
push 002a002ah ; high word specifies which VxD (VWIN32)9 m1 N& F2 x4 d4 F. ] o! h
; low word specifies which service1 r. @6 b9 A( y( X1 `# c+ L9 Y
(VWIN32_Int41Dispatch)
. e, Q0 g- J" u4 b7 P' E call Kernel32!ORD_001 ; VxdCall* g) m: b; ^/ B9 w) x+ R! {
cmp ax, 0f386h ; magic number returned by system debuggers" @8 H6 s8 ^7 ^6 r# k: p
jz SoftICE_detected" Z7 m9 Q: S9 i' V
+ L$ n; x; q. o5 B; _& J3 v
Here again, several ways to detect it:
. |9 B3 |. A- N& @: y% n% J
- r8 k: v) ~; g5 G( Y BPINT 41 if ax==4f% a9 Y5 A' {' E# O9 y
h6 ?* [# {8 G* A3 X+ x
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one, H" i& P+ R& H z/ W3 H
0 b; ?+ K& H. G, N BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
' Y" Z) f0 y% x1 U; o
2 m. F; D! w) H- M( w/ G* D. C BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
. }0 o2 Z+ h% S; X) i/ ~7 O. G
! v: G2 C; z2 W: I5 n3 Y__________________________________________________________________________) T& R; ~- p5 _" S5 v \1 _; ?
* b+ J/ O; o4 e! H0 o3 q& R
Method 13
" k& C% Q) J R, z/ h=========
" W( F$ R- ^) _0 i& L, l7 c
' l/ a( E' Q" ^8 s0 TNot a real method of detection, but a good way to know if SoftICE is
( p* A8 B: T o+ P0 N; l5 K: U, T8 }) `+ ]installed on a computer and to locate its installation directory.9 U8 a8 H* a6 E* }
It is used by few softs which access the following registry keys (usually #2) :) D1 k2 ~1 ~) l: F4 Y' }
& G$ k) v. [# |# \6 p-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
/ s. ]) d& _3 J8 a\Uninstall\SoftICE5 i2 X9 }9 U- y. X
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE9 j1 b0 A& Q+ A: f
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion, _; x, c A$ e. }4 ?' j$ p
\App Paths\Loader32.Exe3 R$ m: j) F7 r
# ?6 r0 l; H3 W
$ b7 w% L8 h& ^% ~7 O6 O+ F* W
Note that some nasty apps could then erase all files from SoftICE directory
6 k r4 q9 d. [" Q7 p; ]. M(I faced that once :-(8 n3 o; j8 D5 V3 }2 s0 C
. t [ K# \8 ~2 J/ Z4 O7 FUseful breakpoint to detect it:
0 @1 ]3 \7 h( {) b& n6 t9 b0 G# s1 c$ m! i1 r& ~
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
( s" d/ r+ P3 U( A4 F
$ v: v. T6 _) o0 H1 F4 q. g3 J* K__________________________________________________________________________' ^- S9 W9 P6 V$ K! D
/ ^' ^4 l! g: A( X* u
0 g$ ^7 _, Z6 s3 D$ s+ B# |! H. HMethod 14 " F! U2 b. k L* q
=========
* E4 T; e* e3 A2 `
7 Y. ]; t! U7 g# f% z$ i4 O. qA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
/ `& i/ b% ]8 @& Kis to determines whether a debugger is running on your system (ring0 only).2 i( R4 X. ]$ z3 P8 K+ d$ G! _
- w4 }$ H7 u& [7 D8 R4 O! K1 J, y
VMMCall Test_Debug_Installed
o% c6 o0 y S+ \, f je not_installed
2 v" q( n+ i+ P7 ]' u& v9 G+ h0 r9 v6 K
This service just checks a flag.5 c$ B I* T1 x( h, G. c: v
</PRE></TD></TR></TBODY></TABLE> |