<TABLE width=500>5 F. Y0 \0 r5 X5 ~& y3 g
<TBODY>
# _2 n; Q _' L* ]<TR>. L$ ~% i3 O8 w: J: b9 R& z% ], L; e
<TD><PRE>Method 01
2 V) h$ j" M6 b5 }=========3 ?5 y# l+ W: l" O+ D
+ U$ z3 g3 m6 x/ e1 Q) z' c
This method of detection of SoftICE (as well as the following one) is$ f5 @" L8 h; {* k. d
used by the majority of packers/encryptors found on Internet.1 |0 E7 D, \6 o+ U4 W
It seeks the signature of BoundsChecker in SoftICE
n) }6 q/ d6 M0 s7 m @; Y( u" s% c% e* e
mov ebp, 04243484Bh ; 'BCHK'
2 C$ o p( c1 z* b3 C) F/ w* Y+ E mov ax, 04h
/ v! a4 _4 l5 K! O+ a: ] int 3
8 L+ b h8 b! b8 N; ? cmp al,4 B5 H6 N. n% w- Y& o
jnz SoftICE_Detected- L1 A' U8 q: a- O9 d4 p
( y3 J% p. r; U$ _% d1 v$ V
___________________________________________________________________________8 |/ b1 S) ~$ E) J5 `
- J9 z. }5 ^, K1 ^Method 02# O" N$ q) ?; E2 P6 x* m) Z
=========5 e8 y* M+ R3 @
! A/ z3 p* I8 Q$ QStill a method very much used (perhaps the most frequent one). It is used
* |) z: g) v6 }! [/ t$ mto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
I, t; P" t6 B2 Dor execute SoftICE commands...
* v1 Y8 f/ `2 S" h; F2 YIt is also used to crash SoftICE and to force it to execute any commands
, g3 i, r" {; i, A(HBOOT...) :-((
1 M* S0 H' u7 L3 F' [" R! e4 n+ _; i/ I
Here is a quick description:+ L7 X6 ~7 Z( k0 x8 f d( y/ @3 H
-AX = 0910h (Display string in SIce windows)7 b6 z, h, ?; y0 ~3 g* Z1 _6 q1 ]3 B
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
% D, O! u- y6 C/ Q( I-AX = 0912h (Get breakpoint infos)
( J: q# v [8 C; e8 F- N-AX = 0913h (Set Sice breakpoints)
# v4 }. K) r+ f) |6 _-AX = 0914h (Remove SIce breakoints)" y+ ?' \& q, B7 g8 n4 z k9 Y* x
% x- R3 l* g1 c$ n# V* BEach time you'll meet this trick, you'll see:( r. e' W" O" ^1 ]6 `) z
-SI = 4647h0 b* R6 G4 p# v. K# H4 e
-DI = 4A4Dh
' E2 }2 `4 b: N8 a- yWhich are the 'magic values' used by SoftIce.
3 B' g, Z! I3 l3 ~/ rFor more informations, see "Ralf Brown Interrupt list" chapter int 03h./ h5 o) Z U8 s; @# g$ P' D
% B7 l4 s, z) ^7 KHere is one example from the file "Haspinst.exe" which is the dongle HASP0 Q/ {, v) H3 |1 z
Envelope utility use to protect DOS applications:
, b I/ e+ _( G' @* F% v9 E: ~
5 U5 A9 S+ R1 K) j! Z4C19:0095 MOV AX,0911 ; execute command.' q$ t$ Q% @9 h0 k+ v# f
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
6 i3 B( Y' k4 A9 ^3 |4C19:009A MOV SI,4647 ; 1st magic value.
; w- M" I1 P2 C' w. l4C19:009D MOV DI,4A4D ; 2nd magic value.
4 K9 q3 C1 B1 P) W& Q2 A1 x6 Z: i- C4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
o& S: Q3 c, P4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute" B1 V9 Y9 W( p$ {* U$ x- N$ Q
4C19:00A4 INC CX
6 H. n1 V& H9 u/ ~- o+ \4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
' b: m, ?. `* z% Z$ T9 B% I& b4C19:00A8 JB 0095 ; 6 different commands.
/ ~# Z2 E7 o; p8 {" T4C19:00AA JMP 0002 ; Bad_Guy jmp back.; J$ T; Z3 m, H6 b
4C19:00AD MOV BX,SP ; Good_Guy go ahead :); B7 t* z& u, j# T
; j8 _' G/ s* H4 C
The program will execute 6 different SIce commands located at ds:dx, which( u6 {3 Z% _- F* \# ?
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
. B. X! k A) D" B9 @! ?1 H. A6 }3 @! C4 ^" h& q, B
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.! ]' c9 j0 z8 w- N: X4 f3 H
___________________________________________________________________________
" V, t/ G+ ~8 E
' w3 s* S, l1 @/ B
" S% h6 W0 a7 RMethod 03, S; ^! n& N9 o5 z
=========
8 j# D' ]$ q, p z, f. }* p
7 U* J7 h3 S( ?! M gLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h& x0 V3 i! E! _4 E
(API Get entry point)+ e0 b7 _7 [/ o3 f$ N
* g- h1 d4 k4 F0 d3 l5 x- p( @7 U% y' z
xor di,di
/ u# @/ ?- d) r4 Q2 M* |5 o* a! j mov es,di
: A) n. D3 Q$ ? mov ax, 1684h
, c u! D; N1 Y( ~ mov bx, 0202h ; VxD ID of winice
7 J* }. L1 g* E; f( O- l' f3 g1 d& P+ |+ L int 2Fh# P o+ R. t- q7 N
mov ax, es ; ES:DI -> VxD API entry point
3 I5 F2 k9 e5 i/ o add ax, di) X2 Y6 v1 X/ W" u# i
test ax,ax
9 C1 i( M% c! m; E. w' C+ V; p jnz SoftICE_Detected `3 K4 X- H" H: M' X
' N- A/ G; j/ a/ m8 N___________________________________________________________________________9 k5 Q' h4 b( k U% H. f' e
1 ^+ N- }! d& r, q$ ]$ t2 e, _Method 04
1 ]4 o; [2 D# h- a! Y- c=========5 l8 M. E/ l+ e) C6 Q
; j& E2 |* P+ q3 k" w3 i
Method identical to the preceding one except that it seeks the ID of SoftICE
% F1 L* A: E) |1 TGFX VxD.; M; k6 C& J1 [. R
7 T: e# Y9 Q3 ^- N% R Y5 z' ~
xor di,di
# w) v. b: m. e! s4 I mov es,di
7 S. i$ Y, D7 D mov ax, 1684h
- U. O7 ]/ [: H mov bx, 7a5Fh ; VxD ID of SIWVID9 o6 v* `! g9 |- F
int 2fh
0 j% f& K9 K4 a+ F mov ax, es ; ES:DI -> VxD API entry point
5 h L/ V( l/ s2 Q6 M X add ax, di& O/ h O4 O$ T$ j/ b! D
test ax,ax
2 t5 N/ A R, C+ B, o5 c0 o- l jnz SoftICE_Detected
, a# \% |8 n) P: }
( E' [$ Q( P- v q__________________________________________________________________________8 {1 t* a! p t! _
9 R- t) p3 K2 k; P: f
2 i' G( ]! @7 r/ H! m! eMethod 05: {) V2 p' q& Y5 n( r$ Y
=========
/ L4 B ^/ @0 d* \ P% I
4 s" f' v( O3 c: pMethod seeking the 'magic number' 0F386h returned (in ax) by all system
' o- E6 }9 Z7 }4 E) }6 Zdebugger. It calls the int 41h, function 4Fh.5 f; b$ o0 f! x' }6 F: r
There are several alternatives. & q+ H( W% v( K/ X q2 O
2 z7 F( e, Y: e8 U1 \1 i6 aThe following one is the simplest:
' U: v8 F9 T3 }- }$ L/ [' c0 F' l& Q& @7 d- s2 V) u% ]# w
mov ax,4fh
& }9 P- Z% S. h; X' {' s3 E" D int 41h
- U/ A% ]6 D( I( A cmp ax, 0F386( Q4 z2 S6 S3 ~+ B& I3 u" d% d
jz SoftICE_detected/ U- D3 e K! {" y8 r
1 N% w' r/ u. L- O( S- Z0 p, b. X# U- _& Y' |, f) J7 F
Next method as well as the following one are 2 examples from Stone's 4 ~3 o' i; f1 `/ i5 F+ ?
"stn-wid.zip" (www.cracking.net):2 @( X3 Q: l) ^( q! r& q
0 K! X" r; v' W2 ]. _$ ? mov bx, cs
( B5 ]$ [( H, t7 { lea dx, int41handler29 Y6 E. R: o' f9 n+ s# P+ c
xchg dx, es:[41h*4]9 k* m5 m% C3 i1 H, y
xchg bx, es:[41h*4+2]; x; k% Y4 Q; h3 h/ |! e# l
mov ax,4fh4 l: k& _- K o. z0 d4 F
int 41h2 e7 g. o, [- E7 h- A
xchg dx, es:[41h*4]7 z5 z- d3 \. ~
xchg bx, es:[41h*4+2]
* W ?( X( j& v4 w H cmp ax, 0f386h# }# [! a6 U+ N+ s5 q! V
jz SoftICE_detected" Q) _# R6 G- P$ F6 `6 v4 Z0 N. y
- T. Q' t+ I, G* [. c
int41handler2 PROC! w3 N: x" t8 E, h1 X' k
iret
& Q) X- ]$ U+ tint41handler2 ENDP
' A3 u" Y6 Y9 }8 M4 R4 L1 c M- K9 ^% v7 a& \
6 S# Q* a5 `, t7 N, _. E
_________________________________________________________________________
: S$ }0 N8 {9 a& }% w7 B
: v1 N# D4 p" `! M) C6 A" k9 C z4 g. u* U+ V v, ?. L& W
Method 06
/ e( V1 K* y0 F6 P8 ~: }) Q5 a* k& X6 h=========- h6 Y' Q: a/ C! O0 m
$ q k e1 K; V
" Z8 s& p5 c" s+ i9 E& D, h) [. o
2nd method similar to the preceding one but more difficult to detect:9 Q c+ s i2 w! y; u$ l
# Z ^3 r; C0 ]$ ^* s3 V
( Q4 \2 y7 E. S; {+ y0 Lint41handler PROC7 h; \5 \3 `& R. T+ J/ J, [
mov cl,al9 m. I2 u9 d" o; j( P% \
iret
9 b& q9 G0 B8 a) X, K& Uint41handler ENDP, R7 K1 ?) _6 R9 v/ n8 {$ x4 }
& G, b, A0 T9 o" n* h- W
5 J# I! u- e5 a: s: i- {- k xor ax,ax
0 J3 r9 P, i3 B; ` mov es,ax
$ h+ R# `, @* P& [" T# b mov bx, cs
( D J1 X. F5 ^0 K1 i" k lea dx, int41handler/ p E; ~4 W& [* j0 `
xchg dx, es:[41h*4]- z& l. U2 p. e! u( R! W
xchg bx, es:[41h*4+2]
# H# |2 p7 Z F' |* h- N in al, 40h
3 q1 T/ Z u2 `4 X: b8 ^/ X xor cx,cx; j, E2 J. ^/ ~% `
int 41h
+ `5 f" m# a G u% k( i xchg dx, es:[41h*4]( a" E+ t' h& z% \$ n
xchg bx, es:[41h*4+2]8 u& |& I# U% j( Z
cmp cl,al
1 _! Y# X) k# X; A jnz SoftICE_detected
3 B4 J! v3 V0 f/ ]- y# c* K
8 I5 L: j% j2 ]4 P% a_________________________________________________________________________/ D' U2 o) A+ k: ]' x" J/ E6 Z
* z% o0 n6 s- p1 l
Method 07% j# x! e* S; i/ w# }
=========
. X$ X9 Z; v; H0 Q' ~( W4 O+ J' J! b" \) Q" p8 F
Method of detection of the WinICE handler in the int68h (V86)
2 g8 K, E$ E% `! M+ K1 d( _- a& Y4 D
mov ah,43h
/ y! \: E1 Q+ g1 H9 ?4 c/ } g int 68h- E/ U8 L( b E" X
cmp ax,0F386h
. i6 C, x& G" z7 J; c+ c jz SoftICE_Detected/ ^5 p) ~% E7 `8 ?
7 f6 F( c+ o5 M
' u# |2 s6 c8 }& V2 m% H2 G=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit$ m U$ A7 A w0 z
app like this:% K( v3 H3 L& C% V: @7 }
6 e I' B2 _1 M# `. a: \
BPX exec_int if ax==68
0 g* v( x: V3 b% i: K (function called is located at byte ptr [ebp+1Dh] and client eip is! [" }% ^6 ^( ]( D
located at [ebp+48h] for 32Bit apps)7 o% `# c6 O. V$ \
__________________________________________________________________________
, L" x% u( N8 L+ a& w; B. R' C* @; r/ E X
& y5 H: h- H0 W& {, t" ^4 ]; RMethod 086 ` f$ C1 R# U6 a% E8 m
=========/ X, y6 e8 T. b
/ j- D5 q7 ?# D' ?
It is not a method of detection of SoftICE but a possibility to crash the
( v3 G* b" V y+ Psystem by intercepting int 01h and int 03h and redirecting them to another: n: Q# q- Y% |0 n
routine.
& p+ p8 g6 W! a' ?It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points Q% J0 m6 I' {3 w' I& p
to the new routine to execute (hangs computer...). O/ ]! {4 ?2 f' h, {
4 V+ ^) t' i, L6 n' z1 ?7 a/ d
mov ah, 25h% A) {: L( X+ B) n( V
mov al, Int_Number (01h or 03h); C. Z3 f! j: _. ~
mov dx, offset New_Int_Routine
; V5 A) X4 |- C/ y- G( P1 N% j int 21h
3 O$ q2 i5 m; m L% s2 T+ U# g& a4 u$ d9 o
__________________________________________________________________________& d$ B9 N/ A4 h. R
! D3 {' M1 l. R `Method 098 [7 ] `9 U7 t" I* b9 t3 L
=========
! O% k0 a: W: N& X& U$ P# ?# l: [' D) V3 w: _
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only3 R, y$ w3 C& H' X) @. r4 @
performed in ring0 (VxD or a ring3 app using the VxdCall).+ F2 a6 W) l; x) R, a
The Get_DDB service is used to determine whether or not a VxD is installed2 R6 }3 U, E$ Z% N E( E
for the specified device and returns a Device Description Block (in ecx) for
: h% F4 J1 K2 H8 ] ~% L2 Ythat device if it is installed.
R/ \' B6 T" n. R% N0 m" b4 n/ W# H" N( f) r) V
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
3 \) k8 e0 _0 P8 \ mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)6 r& z- E l# q, g* R7 g
VMMCall Get_DDB
3 n( |/ B( O. f; F+ {# q8 q* Q0 U mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
: M: h2 T" {8 i5 {
9 q. k B* D, cNote as well that you can easily detect this method with SoftICE:/ u+ G: F' w6 ?; q% w7 F+ ~- E( k
bpx Get_DDB if ax==0202 || ax==7a5fh
4 ^" S, v( e, o& e/ c0 B, T' E
# m" M5 @6 X7 ]. ~5 o m3 b__________________________________________________________________________) @% d& H; R8 u' C+ f j( Q
7 i% R+ C- x& a" n* }% u5 z! Q
Method 10
7 E: Y7 Q' [* V* ^( a4 ^ E" v, {* B% ~=========
F# t Z, P8 {# Q+ O# M9 D& E7 N6 p
2 T- F8 N t% u=>Disable or clear breakpoints before using this feature. DO NOT trace with
4 l/ h4 F# D5 \7 i; V! v. a SoftICE while the option is enable!!5 y' h5 M) w! u* `' i& ^6 V% L
, A$ B8 c/ ~. @7 u* ^
This trick is very efficient:7 o. R4 |" s7 C4 R A
by checking the Debug Registers, you can detect if SoftICE is loaded# {# d/ q$ r2 ~. P2 j
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if& R9 s0 x& y) @# b
there are some memory breakpoints set (dr0 to dr3) simply by reading their
* ]4 G% l9 G V/ ]/ N9 rvalue (in ring0 only). Values can be manipulated and or changed as well0 U: Q$ _# ]/ v( n: b
(clearing BPMs for instance)
! S0 g% l0 ]0 l% V! t
/ c6 K& c& ^9 n* w) @: G__________________________________________________________________________0 V! M3 [4 x* {' `* e
f) _" m, B7 ~7 @
Method 11. p9 [: P8 I) X8 \' j+ y
=========$ ]9 _& Z g# {) K" y1 ]) w
% J9 |9 S4 \; a' I! g' A0 _This method is most known as 'MeltICE' because it has been freely distributed
: p1 [. @# q# I- @( i5 Qvia www.winfiles.com. However it was first used by NuMega people to allow; i- l6 G: G+ S; f" l
Symbol Loader to check if SoftICE was active or not (the code is located
2 x5 [ o! s* s8 R% w6 x( linside nmtrans.dll).
' W( \% C3 F* H2 I9 W7 s9 F& T' y0 F+ R: O' F8 q& {$ w' m/ a
The way it works is very simple:$ y( G7 s! B5 _4 a' M
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for. ?/ ?# N2 ?( J) J: l
WinNT) with the CreateFileA API.0 s( `+ o6 l# P$ d$ ]6 Q
0 ?. M; A v6 A9 {+ J8 f, m
Here is a sample (checking for 'SICE'):
% I& S, b9 V3 b. \7 _: x" x4 y$ V1 H/ Z/ Q; F$ T
BOOL IsSoftIce95Loaded()* | e7 c# [ G+ n
{3 p# s; H! c- g; h# S" j
HANDLE hFile; p" O9 X! h2 `
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,& e; `4 k: N' j W6 J- f' `1 Q$ _2 h
FILE_SHARE_READ | FILE_SHARE_WRITE,
4 ~$ L3 H; b2 N NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);) F. Y5 l, X+ b' \$ w: G0 y- t3 _
if( hFile != INVALID_HANDLE_VALUE ); m, t! {3 O7 G
{ c, A0 Y8 H4 w o9 {! q
CloseHandle(hFile);7 ~/ Y% e7 X3 r" _
return TRUE;
3 l) s' t' l+ f8 P0 T1 N3 c; X1 t% j }* y$ F, K7 q& C* C6 |: r
return FALSE;& G6 Z, f8 e. h0 h' U
} G* B, r# Q# C# f8 M, E
1 e3 ~- h" p" F! F- ~) ]7 o
Although this trick calls the CreateFileA function, don't even expect to be- b9 D8 L8 y& E4 |" z! ]) i
able to intercept it by installing a IFS hook: it will not work, no way!1 P1 k, e/ A) C" t0 s* t
In fact, after the call to CreateFileA it will get through VWIN32 0x001F! R9 h# {8 H7 c$ K; @' N: @1 k
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)% K) W f" {* E8 P
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
5 q* `* Z k% _field.
; A' Q* _0 E! F6 j( FIn fact, its purpose is not to load/unload VxDs but only to send a : G/ o% P& g# `- c, P% z f
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)! K# ^ G$ f' \: J4 C
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
- h1 s+ u) B/ vto load/unload a non-dynamically loadable driver such as SoftICE ;-).
7 S3 V3 y4 ]! fIf the VxD is loaded, it will always clear eax and the Carry flag to allow4 K6 t" l0 r8 N W4 N: A, f
its handle to be opened and then, will be detected.4 A4 C, p$ u1 K- o
You can check that simply by hooking Winice.exe control proc entry point, w* j- z; o) c4 b+ i+ W
while running MeltICE., M8 b( v3 f; ?8 ]8 t9 V
6 u6 {3 v5 k- C) r
: b7 H3 C U; m8 v, `" o% W3 [0 { 00401067: push 00402025 ; \\.\SICE% S1 H Y" X$ a, H' g' t1 b* @
0040106C: call CreateFileA9 d/ I* N1 b: b" q4 t4 R* F
00401071: cmp eax,-001. `/ e" ~# B7 _, W
00401074: je 00401091
& O2 H( |. l9 R& p- O, @ h
. ]' Q9 }/ Q& C9 u1 \7 f/ U' w; V5 k$ q
There could be hundreds of BPX you could use to detect this trick. n. z+ u' R" V- w9 F( T. B# Z1 n
-The most classical one is:
7 |5 W% s( J! x+ P BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||: k/ }+ j& F" @$ V u
*(esp->4+4)=='NTIC'
8 t k9 q; f5 A/ M) ]- G
: K: |: g$ n/ L1 t-The most exotic ones (could be very slooooow :-(- L& G4 k4 F+ B0 v, q) r
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 0 Q8 N. j3 x, O+ q
;will break 3 times :-(
" `6 `5 X/ W( v0 ]: D5 y8 M; `3 T
-or (a bit) faster: , w/ R6 n* u* P+ e+ {" M$ X1 F4 D" t5 n2 F
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
" [: o9 F4 }4 R, Y% ^5 r
( i* Q/ Y9 j+ R; v6 D3 d( P: x; g BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
0 J: v4 q7 I' R" ?: a6 O ;will break 3 times :-(
3 \5 B$ ?/ B) K$ Q; Q
1 V2 C1 L- T b* {-Much faster:
' i% @' S l& U/ N: A: N" W+ i. t BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
4 O; I0 v! ~. b9 s0 P1 B9 Y
! P* U5 f6 _3 R. N' k- {, TNote also that some programs (like AZPR3.00) use de old 16-bit _lopen7 } k Q5 ]4 b1 d: t }
function to do the same job:6 Q+ O \! e6 G# y: n
. [' ?, Y- t) D9 D5 i4 w) k( v) @ push 00 ; OF_READ
3 b3 ], {2 z9 N9 `! O; ]. c mov eax,[00656634] ; '\\.\SICE',0" |# w* Z& V- w$ ~
push eax- X; L" }! j. D7 F, d
call KERNEL32!_lopen
5 }! _3 z# J/ b1 M inc eax
7 i" p- H* L! z7 l3 q9 ]/ G jnz 00650589 ; detected
& I, m5 i: A$ \- h8 }7 k2 v push 00 ; OF_READ
7 @7 g; e2 d# _ mov eax,[00656638] ; '\\.\SICE'2 g# B/ Q4 y$ q6 `
push eax
" Q$ z; f3 G: |/ p! X" m1 o o call KERNEL32!_lopen+ s9 L& Q8 ?6 y* C
inc eax
" P' K' v z' l$ ?& ?6 t% N6 ^ jz 006505ae ; not detected+ j+ z, X$ u# f+ ?4 t* k5 S
# F. A; I5 { ?6 t6 s1 F f
. U2 d4 O3 \* y1 E$ Q__________________________________________________________________________/ d) L) P9 Q1 U8 ^0 I4 a
5 Y) \$ Z0 `9 {- F$ b, K0 |
Method 12
+ V3 {* J9 q5 ?8 ^" b% z=========0 n; ], w% V( G" m) b4 o9 t
7 L! j0 U( p/ |9 ^) mThis trick is similar to int41h/4fh Debugger installation check (code 05
7 b+ b8 q+ g B+ N& 06) but very limited because it's only available for Win95/98 (not NT)
3 s% v! }2 y, _, C+ Was it uses the VxDCall backdoor. This detection was found in Bleem Demo.& d/ b. F. d8 A$ E2 P6 M
* B: i6 R! w6 C push 0000004fh ; function 4fh
: D8 c `) j+ O push 002a002ah ; high word specifies which VxD (VWIN32)
6 ^( Y! K. d0 Q ; low word specifies which service
" e8 P2 U' y, Y4 T8 }1 c5 i9 Z: p0 l$ p6 A (VWIN32_Int41Dispatch)
0 v0 a/ O* U( m call Kernel32!ORD_001 ; VxdCall
* f+ H, R S: } cmp ax, 0f386h ; magic number returned by system debuggers
7 E' c& [+ y! D jz SoftICE_detected- H5 w* E) X6 _0 @5 G% ?, P, k5 _& K
( e6 N+ q8 h! z) k+ o& R, nHere again, several ways to detect it:
/ Z) U. r+ s7 w8 A5 ~. A
0 B; C( V% [/ B BPINT 41 if ax==4f
" R' }' H. y; H" q5 k% V- x9 X
5 G% c) u: `2 ~+ K5 f" e9 I BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
( R* U8 e9 I; O5 S$ D% R! _3 a. T
; I; W Q2 ~: {6 B. X BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
- l- E% S" n# a8 D6 W6 S/ r% T1 [5 d! v% [, a
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
( L" n# N* ]+ h8 \4 S3 j1 d
8 a* M E, l3 r3 o, @5 F& I__________________________________________________________________________0 n7 D# I/ }: E+ O, @) I: ]6 e
/ M$ k6 b* ~: g) R; ^$ ?' f
Method 135 {) L5 n4 Q; X. n8 C M
=========2 x6 a9 |6 m5 V: Z, {
+ y/ m7 R" i8 a* C5 U: E
Not a real method of detection, but a good way to know if SoftICE is& R8 n6 P6 I0 J+ r* Q
installed on a computer and to locate its installation directory.& S8 C" P% m# s" j
It is used by few softs which access the following registry keys (usually #2) :. w5 e. S1 Z/ i" \; y% L& ^
5 c" @, R% p# B* q0 h: c; Y, u
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion, Z6 X4 j' e/ U1 F- d: N
\Uninstall\SoftICE3 L2 Y* C/ ?' B7 M% k: q- v
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
* v8 U8 Q% @; P! s4 h-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
- S {! j' b8 S- A$ Q5 B7 N: A\App Paths\Loader32.Exe
4 D: p8 i& @& f9 y( v) g6 q5 T" n/ k' X' n% I# H+ e/ s
. h! I9 V% f+ |' P7 S% ]1 H$ q
Note that some nasty apps could then erase all files from SoftICE directory3 {0 ]) }5 E8 m9 X" D
(I faced that once :-(
+ n$ q+ k, h" c/ F- q H+ @7 S
! |/ i: p* a7 b9 v+ I. @0 B- cUseful breakpoint to detect it:
U- ] k1 C% u3 P [/ Q( Y
" v: a! P, @! o: @9 X4 H5 n1 k BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
7 G$ o% d. J! S
) j7 P) c0 ~+ h: |' f__________________________________________________________________________6 o; e/ _9 o. M" q+ `/ F
/ h. K7 D( X7 w& f! @
5 Y; {' {' d2 i% f# x( x5 ?/ eMethod 14 . v( o" K" E# P' K
=========
4 V& ~) d- Q P4 d/ N. _1 K
; ^9 b: O+ o% IA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
8 m' f9 w v. P/ L Eis to determines whether a debugger is running on your system (ring0 only).
# `& T# A& E& P
, c6 H, I) \5 H! Y0 _3 J- ~% M VMMCall Test_Debug_Installed
6 m: B% p1 f# x8 k je not_installed. q( v- {6 j( e# m* [
* O; P# b" ^# o3 \( tThis service just checks a flag.9 P. G( h5 P5 y ^- S* v# Y8 n* O
</PRE></TD></TR></TBODY></TABLE> |