<TABLE width=500>/ Y2 g7 b0 V3 t
<TBODY>
0 f+ E' u2 x. i<TR>8 K4 T/ s9 f/ k$ e3 o: K
<TD><PRE>Method 01
5 z, F% o8 f* l% E( p& \=========
# M3 X# Y o: {) e9 F
* B- t7 `- x8 }; i! NThis method of detection of SoftICE (as well as the following one) is
- q% P5 s$ f) s3 Oused by the majority of packers/encryptors found on Internet.7 m* c& I" A8 a5 Y; U$ ]
It seeks the signature of BoundsChecker in SoftICE% H/ }, V4 T) ?2 I
3 b( h4 }. ^* ^* L1 r7 q) _
mov ebp, 04243484Bh ; 'BCHK'
) s+ g* o0 {5 P6 Z ^5 o mov ax, 04h
: b ]- a% N1 h+ u1 h" [* _ int 3 $ N1 N4 h3 T6 q! x' S. j' ~2 r
cmp al,4* a8 [4 a( [" L
jnz SoftICE_Detected
& f2 y5 |5 b) Z' S' e* M) X! d+ v5 G. H, T
___________________________________________________________________________
) p2 z7 r* C# p2 j) m5 b
1 Y1 e% t+ c; D( [& f0 TMethod 020 Q) [* K3 l+ D' C- l4 M9 w* w+ ~
=========( C0 D/ y: ^! v1 p; N+ i2 ]
% V) e Q$ `, w( C& E( K" uStill a method very much used (perhaps the most frequent one). It is used; Z+ S- ^7 S. W/ ^# q
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
% o/ Z4 e7 }, u; Xor execute SoftICE commands...( a5 c; P+ X e( k/ H1 b% F
It is also used to crash SoftICE and to force it to execute any commands% V3 ?+ o* L4 P. Y
(HBOOT...) :-(( * P7 E z( C; B) i' m/ r
+ J$ d) U& B4 t6 x% HHere is a quick description:& s( F; K% E0 M' c- o k
-AX = 0910h (Display string in SIce windows)
9 v! ]3 u' Z* u2 @-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)5 ~( a( R2 ^# w" G) l
-AX = 0912h (Get breakpoint infos)
0 A* h! r, \7 _7 ^8 i-AX = 0913h (Set Sice breakpoints)% h& V" W& T7 p4 P
-AX = 0914h (Remove SIce breakoints)
3 w, N! {+ v2 z; ^( \1 v" B9 M# N/ K* s
Each time you'll meet this trick, you'll see: q4 f) Y, Z) _& N# @; }4 O: Q
-SI = 4647h. J& o/ Y& j6 m7 L- O
-DI = 4A4Dh
- L. T( ^9 [) [0 e# }- jWhich are the 'magic values' used by SoftIce.
$ e% M9 d. o; U5 [% j7 }For more informations, see "Ralf Brown Interrupt list" chapter int 03h.2 p' J9 P. h# b2 {
. V) q. Z" i+ H" }& ]( ?# THere is one example from the file "Haspinst.exe" which is the dongle HASP
, g2 e* j" k jEnvelope utility use to protect DOS applications:% R/ W: }$ ^) \2 m
5 ^0 P* f A4 d, L9 C3 I& W
7 p) E, t3 m4 A, B* A9 H9 Z. ^
4C19:0095 MOV AX,0911 ; execute command.+ d: S- p7 i9 _3 J4 E5 X3 J
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
1 y% j" @) U! b+ m; W/ Z$ j4C19:009A MOV SI,4647 ; 1st magic value.
' ^& {% Y! U2 F& Z4 [) B0 }4C19:009D MOV DI,4A4D ; 2nd magic value.
4 A+ u. w9 T( V" R4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
4 ~* V& ~6 v3 R& m; T4 R- _4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute) l ]; e# }# q0 [0 J
4C19:00A4 INC CX
, U6 D) P6 ?7 A4 r4C19:00A5 CMP CX,06 ; Repeat 6 times to execute2 f$ P: R( Y5 n& k
4C19:00A8 JB 0095 ; 6 different commands./ ?% k7 _% I) C1 b- X. \
4C19:00AA JMP 0002 ; Bad_Guy jmp back.* T, }$ N: u4 g( u5 K
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
# X% t7 \: I) U2 N; E: [3 B F2 t% r8 d3 ]' |6 g* ^
The program will execute 6 different SIce commands located at ds:dx, which
- \3 l! U6 H1 J: `are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.; @, B* O# _7 ~# M
& t) U/ [$ U* T) }) P+ H9 h8 o* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
; O! k! Y; r4 c6 U' b5 e___________________________________________________________________________0 Z, @* C T7 p) x
8 R' Z) z4 S9 k; M1 [
) ~4 z/ I! x8 q8 @# w' K- C
Method 031 r; c" S' n5 y5 i: T
=========
0 d4 \+ i0 i0 B- e/ U: ?" m" Y8 m, }8 O3 u
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
; T0 q4 n# ]1 [# R1 r(API Get entry point)2 l: I; C6 b ~; E. e3 a0 k
& }8 D2 \" d1 }- i. ?& t
3 ~& z* X- A: U xor di,di
8 E5 ^; R/ J: z- T/ Z mov es,di
5 r5 _' S5 q% V' F3 [: ~$ U! L$ [/ m mov ax, 1684h
' V$ `$ b" F6 S mov bx, 0202h ; VxD ID of winice2 c9 D3 [ d* t* F. }6 l
int 2Fh6 M4 G5 d; ?. z; w+ U
mov ax, es ; ES:DI -> VxD API entry point
& s5 y( ]1 C7 {; O0 z/ Z' X3 i/ s add ax, di4 \9 E# n! H" W7 I X$ K
test ax,ax. v8 y P2 `* ]7 [
jnz SoftICE_Detected4 q* v8 j) b/ |# A; b. a
0 p$ J! M) q2 ?5 j___________________________________________________________________________) U {5 r+ `; B! H% u
# C3 v& C# `/ @% T+ DMethod 04. y4 d0 V, l7 |# I7 u
=========
& H/ `( }! N0 F* G
1 K9 o' i/ g4 ^% c1 tMethod identical to the preceding one except that it seeks the ID of SoftICE$ ?! M4 ]9 t: y9 \6 e9 F+ V
GFX VxD.
C' A: ]' j1 ?, f0 q" u+ s2 e) t2 Z) T( ^& S' r
xor di,di
% w, x! a$ P% ?) [3 x, v D; i- f { mov es,di. {' I+ e1 L Z2 H
mov ax, 1684h 1 n/ Q; N% T6 k4 X5 f+ ]7 W/ d: X9 \
mov bx, 7a5Fh ; VxD ID of SIWVID
+ z: k6 l4 w! v int 2fh1 i7 F' f& l$ H' ?3 g( w2 l
mov ax, es ; ES:DI -> VxD API entry point
& m, {/ ?4 H% y* |" Q1 N4 g add ax, di; T+ g( h' h" e+ d
test ax,ax
+ M. A9 k, N$ A" H3 v+ n! I jnz SoftICE_Detected
6 Q+ v1 M3 L# b! q
) l, X1 R# \# o8 }, k* o8 @9 M__________________________________________________________________________# B: a: z/ E/ F8 N, J
* b3 B: `! a+ |3 A
1 C7 q9 x. F, g- N0 y' M* n" T6 }1 bMethod 05
/ w- P; K/ ~5 Y6 B# G=========
( C: l- a4 s" W1 R* h5 I3 U+ P7 f$ V& x6 F" k
Method seeking the 'magic number' 0F386h returned (in ax) by all system
: x+ L r+ B* }8 v5 xdebugger. It calls the int 41h, function 4Fh.
$ o; y! d0 y" G' t" g4 B0 ]* |1 MThere are several alternatives.
! M# f) @+ }3 a4 {, f$ v9 D; T
1 r4 Z) q$ A, lThe following one is the simplest: p2 g6 Q! D. q0 `+ W# g( \
1 ~ m x$ a: T, ?$ U% X
mov ax,4fh
6 T3 |$ r3 Z+ D" Z. Y6 v int 41h0 K4 Q9 Q0 |' `& ~" {
cmp ax, 0F386
2 Z: H7 S4 d1 ~" c+ j% c jz SoftICE_detected5 W x6 l7 D" K) [( I; i
$ D2 F$ @3 F8 I7 M
8 s$ s, E% X; b: F/ e$ B [' I5 }4 nNext method as well as the following one are 2 examples from Stone's
$ Y+ \2 X* d( b8 f& [6 I"stn-wid.zip" (www.cracking.net):. j1 R6 b3 J6 i! m7 h
2 J3 A1 R% H5 A! I mov bx, cs
# _' a/ }' g; g8 K lea dx, int41handler2 L/ @' x X/ W& N' A7 K# I
xchg dx, es:[41h*4]3 Q# ^' s$ b& Q4 n, P
xchg bx, es:[41h*4+2]
7 M4 N& N; A% C7 W mov ax,4fh
, t. K0 d9 i l int 41h
# H# k" j @! E xchg dx, es:[41h*4]& f, Z0 b& b; \9 [/ A( T
xchg bx, es:[41h*4+2]9 ]. b. r& l+ `" A
cmp ax, 0f386h/ Q- i! ^" g4 B- g( s
jz SoftICE_detected
5 m+ g( M+ s' \2 f: C
1 }4 F! b1 B2 w7 b9 J0 rint41handler2 PROC
; {/ G4 m8 P# D; A iret
$ L/ Q8 y: P5 U- _) f- Bint41handler2 ENDP
' h5 q+ D3 d! d' ^4 d8 Q- E* M4 L9 y" O8 A4 H+ g7 r1 W
6 X) V- ~, N* R1 l$ V/ S& Z* [, __________________________________________________________________________6 a9 m$ H5 w: @7 j1 } `' v% S
$ X" p5 }0 Z9 m" L# |5 X
; n- v- b) e7 iMethod 066 |5 r; U' {2 |$ ?/ b
=========
' G) f2 I' ^. W) S. u- _6 ?' m* \9 `8 r& C
# U3 k0 |) X) S- r( B, z2nd method similar to the preceding one but more difficult to detect:# }& {+ {8 ] p( y3 {8 V
$ k3 t% N& A) K
8 g- s7 [' p/ a: D" `8 f% r& Tint41handler PROC
2 I/ B% Q( U( q% b8 n/ j mov cl,al2 K! `3 d& M4 b/ ~1 b
iret. I" ]! K: u/ I" d2 h5 T
int41handler ENDP
: B8 {, u5 ^ R) R& G! H4 x J$ o* c& M. f1 { ^: R
% Y7 b4 A% G) K$ d: k1 R xor ax,ax
0 ^2 r2 d1 ]3 t# E6 }! P mov es,ax
$ n6 e. i: B% j! c mov bx, cs9 A* ~0 w/ }, G
lea dx, int41handler
, P8 O# ]" O- q t xchg dx, es:[41h*4]/ v. O3 ^. p; Q- j" o* a6 k1 Y& X5 H
xchg bx, es:[41h*4+2]
: P- ]# h' A8 x! b in al, 40h
, I) T/ X: S' l- V& j xor cx,cx6 ?& a" X) A& x+ |0 r" X/ y' r2 h
int 41h2 Q$ b. ^$ J) i0 w/ B) m
xchg dx, es:[41h*4], ?% Z6 U S6 `; t. y
xchg bx, es:[41h*4+2]1 y4 J* U/ q8 l5 T* v. m
cmp cl,al
! Z+ G. g3 A& q; b$ `8 A jnz SoftICE_detected
; g3 R$ |: K/ u5 L% i/ W/ b" o+ P7 V8 A7 c' |. ]
_________________________________________________________________________
/ r+ v$ [7 o1 Z; [ D! g7 q# Z3 x5 O5 k
Method 07
, c1 u8 V, g$ W$ b: A* W, B) s=========
4 N5 t/ Y( D. X3 g& g; \ l7 x0 M( C3 r( @. e9 I9 L. g
Method of detection of the WinICE handler in the int68h (V86)
1 _6 @" w: s7 d: K0 E* L$ ~/ m0 z
1 f4 G! a1 m8 T" `0 o- B; l mov ah,43h. W; i' t8 U& [
int 68h# z4 E; N* x/ w$ V7 R8 z' d
cmp ax,0F386h* z: g* R& A" \
jz SoftICE_Detected4 F; y& m! F8 X2 }4 j
$ r/ j, G( |4 p. ^, P. {2 ]% o0 {4 P. C
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit* b, I! O% S y. A
app like this:
( j0 b1 u# x9 Q8 r9 d% Y) _- n% @ V5 }) f% C, `/ N
BPX exec_int if ax==681 ^) C! a# d0 D$ N$ F# i8 c
(function called is located at byte ptr [ebp+1Dh] and client eip is: i8 X! X. s2 C8 i9 j
located at [ebp+48h] for 32Bit apps)
) Z9 ]% n. }( U8 @4 ]__________________________________________________________________________
* ^, p* e" g8 ~" E7 Y( k; x) z
* b" t& d+ |4 r$ i& `0 Z
; }) r p5 A/ ~2 z2 k) t6 O+ Z) GMethod 08
, |) Q, j3 w# M; s+ G) V1 s=========/ X; M9 n" \3 F5 o- j7 v6 I
5 a9 a2 P! S! h) z' a) `* w% @6 k" V
It is not a method of detection of SoftICE but a possibility to crash the9 |0 K) x' y6 N8 j% n; z
system by intercepting int 01h and int 03h and redirecting them to another
4 F0 T% W) t, R+ n4 k0 ?" Troutine.
; c! a7 \! A @+ CIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
: D; l! _- h/ h6 xto the new routine to execute (hangs computer...)0 g" C1 A$ ^5 Q# d
# v- y4 s5 M2 W+ c
mov ah, 25h
( ~5 R3 o4 O! P& l) r+ O+ R mov al, Int_Number (01h or 03h)
) {; A5 X- \* L5 {/ _4 x$ p. X mov dx, offset New_Int_Routine" S9 _6 W4 w/ |( C0 F- M" B' h3 h
int 21h8 i4 ]% c5 P( {4 B' ^( t6 P
" w, S4 f$ m9 h T5 B7 f__________________________________________________________________________0 d N. M1 p3 e, T9 d& s4 p2 t
3 W8 e% N, X, j3 M
Method 09
# e, _+ Q* i+ y) q$ |=========
% y- f9 M8 U4 x9 Z2 j6 q
$ o# \: z' F- w; |2 gThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only& A! d* ~3 A' K s8 k
performed in ring0 (VxD or a ring3 app using the VxdCall).3 g: g" M& e* R: y
The Get_DDB service is used to determine whether or not a VxD is installed% j& e0 a# D" J* Z
for the specified device and returns a Device Description Block (in ecx) for
V ~" z9 ]8 hthat device if it is installed.1 S. t# Y! X$ {3 j- l% D6 J
4 n. c, i0 B6 \; D mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID6 c9 s# w5 Z+ w( P. z4 s' y
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
' K# h1 ?5 X9 d' M# A5 }+ r VMMCall Get_DDB
* d! h$ Q x+ {" x% W# f& R mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed. S6 t2 ^& U- F2 g
" ~0 T; c+ H: p6 i4 l* }Note as well that you can easily detect this method with SoftICE:- b* k( D) }: m3 H/ w; y
bpx Get_DDB if ax==0202 || ax==7a5fh
( Q! b8 f ?4 @4 ?" y! Q
6 X- ^, @. h! v__________________________________________________________________________
9 O# h9 R* I7 q/ |- ]5 A7 z% m, ~0 X$ o8 m, J
Method 10
+ o7 K6 {+ Q" J4 ]8 x0 d; }: I=========9 R3 }9 u0 A9 F
# M8 O4 p: ^! Y0 [2 f8 W0 G8 _
=>Disable or clear breakpoints before using this feature. DO NOT trace with
2 c: e) f# l5 `' z- R, k! v9 b SoftICE while the option is enable!!2 l; S. D+ |$ f; ^
( \( P" e, d) ? l
This trick is very efficient:
9 ^8 C4 B+ v" g$ L" s/ Y0 X5 ^by checking the Debug Registers, you can detect if SoftICE is loaded
$ ?# H9 O" S9 `* v: Q" P6 F(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
( G4 H2 S# O' o: T( lthere are some memory breakpoints set (dr0 to dr3) simply by reading their0 b5 a5 p% M6 v- M. k. O I
value (in ring0 only). Values can be manipulated and or changed as well
- G6 o8 @& h+ K+ g1 r* A3 w(clearing BPMs for instance)
) `/ A! n8 {: a6 V% p, V3 p+ p! l1 z3 C
__________________________________________________________________________
9 \: }0 P. l9 G) k/ Q
- K1 X( M& f8 h7 Y z: RMethod 11
8 ]+ R0 B, ^5 b=========
, T( j3 g' }' v- d0 x5 L3 Z) ]3 j: r! n$ ~' G2 t
This method is most known as 'MeltICE' because it has been freely distributed
% j; i: {( f6 ~" M0 h+ jvia www.winfiles.com. However it was first used by NuMega people to allow
9 d# c; [, Q) M, W0 G3 ZSymbol Loader to check if SoftICE was active or not (the code is located6 S6 ^2 ?2 G$ r- i; W, j& u
inside nmtrans.dll).
3 ]! Z1 Y8 S/ t, G+ n4 f8 O
; W1 v( p1 U1 |+ ?! k9 RThe way it works is very simple:
; V, j+ q# y" d+ h1 |0 b2 `It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
; X- N: d- f, [( i7 q: t7 P+ u- OWinNT) with the CreateFileA API.# ^: a. W* B7 P- R6 P1 e; m
- G# L# N T+ Z' f/ n( c( VHere is a sample (checking for 'SICE'):0 s. v: O; \, |+ H( p& |) e
v/ o! t8 [! O9 s, H' ABOOL IsSoftIce95Loaded(), x/ l& L5 n7 f! ~- \
{# N3 I' W5 R( M+ m1 Q) L, c
HANDLE hFile; , V% v, y& C5 g0 \4 p; [
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,. _9 I( T$ V1 c7 ?
FILE_SHARE_READ | FILE_SHARE_WRITE,& Y. z2 b5 x5 D6 h2 \) \+ O
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
0 ^" c9 u$ [( ?0 M, i8 a- j1 w if( hFile != INVALID_HANDLE_VALUE )
0 r3 A, ?3 I& R: Q {3 g) `- ]" u0 T& c
CloseHandle(hFile);
) `% Z/ G* e( e6 r* L. t: a return TRUE;3 T2 M( k! M- d# W q8 A+ h5 h
}
9 u* a" O8 M& a, C" h* E$ n5 b) y return FALSE;
2 l: X8 h I. U}7 v1 k, G9 T' B+ x5 Z# l& w) w
. q# \+ z4 j: b: ]Although this trick calls the CreateFileA function, don't even expect to be- b4 H/ m# v, s2 h
able to intercept it by installing a IFS hook: it will not work, no way!
: O" `7 Y+ }6 p# v5 e E) q8 K1 Z# ]In fact, after the call to CreateFileA it will get through VWIN32 0x001F F; _. Q# p& I0 l8 H( }
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)! e+ }) L: U. g: O" c0 f
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
$ U% e# Y" W" v, `5 M3 F5 efield.
) S- p8 b: c% [5 ]In fact, its purpose is not to load/unload VxDs but only to send a . G# R! } Z: L; ?! z5 W. |4 f
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)/ j/ y- ]; P) V9 E
to the VxD Control_Dispatch proc (how the hell a shareware soft could try: r8 i: [5 O# Y. ~+ M
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
2 X; j8 B: D% n# P' fIf the VxD is loaded, it will always clear eax and the Carry flag to allow
" F0 o ~/ ^: m. N& M$ Hits handle to be opened and then, will be detected.
$ J3 I+ K% P/ f/ p+ X, e i: z, bYou can check that simply by hooking Winice.exe control proc entry point
+ G/ g! ^0 ~4 v$ Z8 O0 Dwhile running MeltICE.
6 Y8 l& x* m- _1 \5 l$ t: x: S" B" m' L4 c8 P0 `0 S
% R) |4 Y7 v" O; y# R) K: [ 00401067: push 00402025 ; \\.\SICE8 [: `( D& p# p& K* L
0040106C: call CreateFileA
. D* V: M: n1 Z* r 00401071: cmp eax,-001# f9 J9 P6 d" q% |9 v; G) x1 P |
00401074: je 00401091
2 @; T" j% { @: D- o+ o) R. ~8 N* t n1 i6 d3 x
$ Z! M ~( @' e. e6 zThere could be hundreds of BPX you could use to detect this trick.
0 u' I3 E" v: N-The most classical one is:- _7 f3 z6 w2 A9 `% C
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
$ J' m" Z/ k/ W, j* l4 q' _" t *(esp->4+4)=='NTIC'/ k: U& R( t0 f
& u# E* j/ n" z# D; t* s! o( p5 [-The most exotic ones (could be very slooooow :-(( F/ l2 E2 A3 _, B$ w
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 2 p' Z8 D5 N% \. a
;will break 3 times :-(
% [# N$ Z5 o! k7 ?! J; Y
, b Z$ K0 ^- ?) I x. p" |-or (a bit) faster:
/ d, W8 y" R# p* J9 N2 H; h BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
& V8 H. L- s) ]* ^/ m" p6 Q
" U& I' W' h; N& d; f j) Q BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' , {$ Q" I, _5 P6 W) T( V$ w0 S
;will break 3 times :-(
8 h$ t0 g8 c$ N( ^0 X- T2 x
7 q/ r5 E: V# f& p) P-Much faster:
3 g% X2 f& O$ `, v3 y BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
5 U* t: S' c; A! h( e N0 Y9 e$ A: q, ]& z, ?& s% O |- b
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
6 j! o, y. s, o* @function to do the same job:, V& }9 V9 t* U# t# U2 b
6 T* w* a x" ]4 y" G
push 00 ; OF_READ
- V5 v3 ?8 _2 \ mov eax,[00656634] ; '\\.\SICE',0
; t: {* v: M3 u# e2 W push eax# @/ b" D& U; ~+ M' Y) j4 Z& {. ^' F2 S
call KERNEL32!_lopen* [$ }6 O$ S1 a8 ?& i/ ~0 u* U, C& b
inc eax4 z! Q _6 I- k9 ]9 F" f" e* h
jnz 00650589 ; detected4 ?" K3 Z) x( a4 I4 }0 T i6 d' [
push 00 ; OF_READ# j, \7 }% a& U# i( t9 D; N
mov eax,[00656638] ; '\\.\SICE'
4 r6 v; ^/ ~* V* g push eax
9 ` E1 p4 K9 w, U# p call KERNEL32!_lopen' J6 g4 f. ]; a
inc eax& _: T9 r; J5 }1 V
jz 006505ae ; not detected1 J3 v7 y! \& G6 L
4 `% n! Y. n! @' e3 P0 y) O
5 u* g3 n( N% K4 w0 A__________________________________________________________________________4 k) m P! j+ l U) _: K
. c$ z; }% b) S
Method 12
( H9 J! {. g; e( l=========
2 B, i% `- o4 q! ]& P9 d
) u5 d& x' L( s9 U8 T9 X* M3 F) G+ rThis trick is similar to int41h/4fh Debugger installation check (code 05
& ^5 F' ]& z8 u& y6 p& 06) but very limited because it's only available for Win95/98 (not NT)
n$ u2 Z& J0 k3 @) q" A: ~as it uses the VxDCall backdoor. This detection was found in Bleem Demo.5 u9 a+ O+ _% |$ A6 k* O
' f% ^- G- Y% `1 g" N& B/ z
push 0000004fh ; function 4fh$ G% L1 j- P$ X( l
push 002a002ah ; high word specifies which VxD (VWIN32): p% s; A. a6 {4 W5 @
; low word specifies which service
; P! f0 X0 {9 B/ j C$ _7 O (VWIN32_Int41Dispatch)
. e3 m# R; g; {+ {- | d call Kernel32!ORD_001 ; VxdCall/ _" o' x. N1 B1 {, M( e6 ~0 I2 M' P
cmp ax, 0f386h ; magic number returned by system debuggers
) ~# Z" x! J7 h' K L1 W: l! {7 O8 L1 s jz SoftICE_detected: B5 V* B: O( ?
8 V2 {$ L; [4 B- w8 o3 x; [+ b. q+ BHere again, several ways to detect it:9 F( P8 z, r- F u5 y+ h. p: n
, ]8 X F$ z# y9 e' b% u BPINT 41 if ax==4f1 E; a+ u6 y) K5 @ i8 Z, N* v
0 i) x( Q1 Z& L& @
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
; l$ ]* d! K/ ]. l1 d& s) _) W
* P& }! u% ^' ] f- K9 U# ^ BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A. q2 m" G3 D- f" _1 S
& ]7 D; x; D K0 e# i
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
/ j( j7 ]5 v! D6 B" ]6 D
# V2 B- K; @% E. h N__________________________________________________________________________1 J- E& z2 @8 v) Z0 G
7 s% z8 I# V ~' ?Method 13
6 @7 f% x: f+ Q# l) o! l! [=========# ?5 P4 c5 T3 R: O6 ]
; b% \% B7 x9 \. [. f5 z
Not a real method of detection, but a good way to know if SoftICE is
( X) _# B' U$ R5 xinstalled on a computer and to locate its installation directory.' T4 X0 T' E' {! p( l
It is used by few softs which access the following registry keys (usually #2) :' Z& S, G! f" j& E
: }9 `" p. ^: |. e/ S. B-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
6 k+ [! b+ l( t) u( n& f\Uninstall\SoftICE
9 n5 P" T4 B; G! D: {-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE& B4 a: t0 V6 g/ N! P" k
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion c2 |. `$ b& s' `
\App Paths\Loader32.Exe
i! v# a* U: a# `
_3 q# u' ?' m, }+ f; p) X: j
Note that some nasty apps could then erase all files from SoftICE directory
4 X$ D; z1 c6 m1 [ {8 }# J# o8 \(I faced that once :-() ^6 r$ M- p) u3 Z% h4 e- j
/ m- U* u8 u; [. w# EUseful breakpoint to detect it:. }5 E4 P, _" r6 s3 L( V& D+ U
1 Z) m g$ x6 P; k5 b BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
* \* l N% i: s. `+ _$ c0 a b7 B1 M0 e7 i3 J7 X' k
__________________________________________________________________________# w0 R7 g$ ` O; l' x
, R+ i" `" N$ T
6 n, n( W; }1 M* E' jMethod 14
& G& j7 p/ j$ |7 r3 D=========
; e F5 r8 V2 d$ E) Z: v; q6 T: p+ O" a. m
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose% z D$ @% C5 V6 ~3 u
is to determines whether a debugger is running on your system (ring0 only).
( C7 U& e/ U$ S2 h
5 S+ S9 r# G2 n, H0 _ VMMCall Test_Debug_Installed6 N/ ~# Q, f( g- i6 b9 O
je not_installed I, T0 r' _" f1 C
- f( s& `; E. zThis service just checks a flag./ Q1 E" H; }0 x; O s1 T
</PRE></TD></TR></TBODY></TABLE> |