<TABLE width=500>& `2 \* \4 P/ ]/ o5 k
<TBODY>
5 S+ A- z& R3 |<TR>
% p) N/ S; R7 e/ T' M7 x$ \3 I# T* O<TD><PRE>Method 01
) Y. w1 X1 E, {0 h+ F4 F4 `=========
; M0 k) |. Z* }! P- r! X v
5 c. {' h" @6 ]This method of detection of SoftICE (as well as the following one) is
2 Y' B4 ^& Z8 L6 d" r, S" yused by the majority of packers/encryptors found on Internet.
( t# }" \, h& U f7 }5 dIt seeks the signature of BoundsChecker in SoftICE
2 N8 }6 A' I# s% D
8 q' T6 G( t- Q, S4 N mov ebp, 04243484Bh ; 'BCHK'
% g! e' ]* o" h% e mov ax, 04h
7 u; @0 T1 L" P8 k: p9 ~ int 3
- [% R1 d' w) s3 Y( u+ k cmp al,4
9 Z% T. K# T7 R7 V, q3 {, v jnz SoftICE_Detected
" ]! k, D) K8 c+ W7 y/ n" R8 A* t& O- I( B% `
___________________________________________________________________________
% p6 P8 n* |& C5 Q7 y i# ~6 a$ m c1 ^8 u1 }4 J/ k; O; r2 u
Method 02
. x7 n& Y3 y" x' ^=========% b+ }1 J) }6 ^& r' `2 U1 }0 @- N) U9 R
% V% w. u O- M6 J/ L
Still a method very much used (perhaps the most frequent one). It is used1 {% r* |! [( W6 j k/ y7 f" B
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,$ Q C/ ?/ \, Y" `
or execute SoftICE commands...
3 M2 `1 O: I4 J# E! zIt is also used to crash SoftICE and to force it to execute any commands
# k0 ]0 @0 E( ~(HBOOT...) :-((
2 r$ O6 T- ? R2 p, Q1 r
3 O- \7 y( j; t1 e. xHere is a quick description:
) c9 f4 r$ Z- w3 o# S! m7 t- K' [) H-AX = 0910h (Display string in SIce windows), U" |% I8 E" j& _" Y1 l5 J
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
# j" F* f! X+ @7 w8 |4 g9 a$ r% z& T-AX = 0912h (Get breakpoint infos)* \- K# j, G4 ^$ e
-AX = 0913h (Set Sice breakpoints): [$ f( [, f$ B( e9 z. O
-AX = 0914h (Remove SIce breakoints)- @- M, s% \+ J7 Z2 L
/ q* y2 h/ {; H' ]8 f R
Each time you'll meet this trick, you'll see:" l" g; s: k* `: o' Q2 n& s+ e7 U
-SI = 4647h
. X; V$ j4 W; h2 R-DI = 4A4Dh! y5 ~& x4 A& E, B$ y$ o0 f V
Which are the 'magic values' used by SoftIce.
4 S& t1 Z# e/ b5 Q6 j zFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
\6 A- P4 b& H( W% T/ S% w( H' r9 ^) }
Here is one example from the file "Haspinst.exe" which is the dongle HASP
; M6 J. Q! s5 z) l7 sEnvelope utility use to protect DOS applications:4 M* ?$ a% p# m" q: t% F
' P1 k$ U+ o6 v
5 y' u" G0 J0 g/ z$ s; |3 x4C19:0095 MOV AX,0911 ; execute command.
4 \) Z8 x; W; b6 E: e5 d6 S4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
! w1 G/ P" w4 t, }0 q' t2 ]4C19:009A MOV SI,4647 ; 1st magic value.# t1 [$ ?( v% W9 X- ]3 ^4 W
4C19:009D MOV DI,4A4D ; 2nd magic value.% r- l' O% e0 v4 H+ ^$ \
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
. k, K# z9 e+ ^8 e4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
9 U7 g/ {! Q! [3 b! Q" y4C19:00A4 INC CX
@* @1 o! Q4 B& F4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
2 O$ J% v" T' J4C19:00A8 JB 0095 ; 6 different commands.
, n* @+ f0 z: c' o4C19:00AA JMP 0002 ; Bad_Guy jmp back.8 B( q9 E8 b6 m G& u8 p- _
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
. Q1 k( i* l M/ [
8 U$ i* h' |4 C1 ?" @& ]6 wThe program will execute 6 different SIce commands located at ds:dx, which9 ?! c2 E0 o% A! I
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
7 o# o+ u1 o# F
* d& N% V* C3 x+ d* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.0 n+ U. m( n& I
___________________________________________________________________________
" w. c* |" `3 T5 Y6 ^: k- T& ^8 y0 W: Y) H
) \: ~0 Q3 t' I1 v" O
Method 03
( K; X3 s* R8 f/ c=========) L- {9 m5 X9 b6 X L/ W5 w
& _2 h) P+ n+ g. g& hLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
A- {' B* z, m( t& H9 D$ K2 {0 W(API Get entry point)
1 d8 @# z ^" ~* y, B4 Y! ]+ a' q x2 _) y0 z$ o9 T1 j8 ~3 k
8 F' ]: Q2 v% _1 ^1 l, G xor di,di7 P- d2 O, M( a
mov es,di
7 z, w4 `$ p# L* r# L6 o; }2 ~ mov ax, 1684h
5 h. q; J/ R9 a9 y$ W R mov bx, 0202h ; VxD ID of winice8 [- ]( G, o6 Q2 U
int 2Fh6 [9 v+ ]6 c7 ^1 j. U ^
mov ax, es ; ES:DI -> VxD API entry point
! P# B9 w7 I4 A add ax, di
2 W1 ? Y x2 K6 l: P. j test ax,ax
% A+ b. I% K" m$ e jnz SoftICE_Detected8 P! a0 S6 E( x% c" W
! L$ p* H3 r: M" u___________________________________________________________________________
" x5 j8 m/ b" m3 g* v; K0 s
& J+ G; d4 X, HMethod 04
/ x& {9 |5 q3 H0 f0 P=========
8 i" ?/ f2 d( O# {+ _
# O4 {: g' \$ V. y+ D" _Method identical to the preceding one except that it seeks the ID of SoftICE3 N/ U# n! ]. `, n/ e9 @' |
GFX VxD.
" L7 e. ]" B w N0 X
& w. r& k0 @7 R% W6 @, R8 } xor di,di2 d9 a C1 t9 _$ l4 H
mov es,di+ K, l3 k/ |+ W1 E
mov ax, 1684h
. p- r3 T3 d6 g$ {3 r- E9 ` mov bx, 7a5Fh ; VxD ID of SIWVID
' A V* c( l6 H: C2 z int 2fh
( v3 |: q+ d6 k6 I$ L' d; s mov ax, es ; ES:DI -> VxD API entry point
# {3 i# a! t u5 { add ax, di4 ]( {2 x6 N+ K0 [: m Q1 d8 T) E
test ax,ax
5 C% J, r, _6 f! w jnz SoftICE_Detected
8 l+ V8 [' v# E: p, q! W1 B- `; t" D% D# Z
__________________________________________________________________________$ A% ^3 q* ^/ t* D7 Z
1 `+ s, S& L4 V- d' G
: h/ c- E: e9 [$ BMethod 057 F* e% i# R; z" E) W
=========
7 d2 L" y3 C) T+ s3 ]3 |4 m
2 A0 l7 `* d" M0 o1 K6 U" G! ~Method seeking the 'magic number' 0F386h returned (in ax) by all system5 I' c6 R/ w6 G) c
debugger. It calls the int 41h, function 4Fh.
_% f+ h- y1 l8 ~+ v( \2 P- Q# H' xThere are several alternatives.
. E$ L O$ g+ g; @$ Y- j
4 q; Z6 w7 ^/ f- YThe following one is the simplest:
9 d$ A# q; @* S/ ]5 T7 @
3 K }0 M5 d/ i/ I mov ax,4fh+ P+ A/ K& g* A4 m, y! p& D% s' H
int 41h( t( E% M! a9 S+ D3 b0 F: ]
cmp ax, 0F386! q+ T; S( |/ S; |! O s8 U* c
jz SoftICE_detected1 s3 N: [0 ` h6 l
5 b# f9 V; o' I- w: p
/ G( [8 K: K; M3 k# F# O( y! T+ sNext method as well as the following one are 2 examples from Stone's
* o" j6 F, _; m3 L. p! q: D& n- H z"stn-wid.zip" (www.cracking.net):
7 L' ?( W0 X- n" s& {7 C
6 j* W. ?" }$ Z; W n. \ mov bx, cs
; `, j' T' g+ q$ L lea dx, int41handler2
, B7 t3 B8 ~- w1 v xchg dx, es:[41h*4]
" B/ I1 a% a; e2 H$ Q xchg bx, es:[41h*4+2]
: @+ N4 }% l) e$ H9 J$ P$ n8 f: p& q2 m mov ax,4fh% W. S& ]5 T: W" o1 T
int 41h0 V2 O) G$ G6 i& [+ J, P
xchg dx, es:[41h*4]! R/ ^% p5 R( p* S2 P- y6 Z+ V. d
xchg bx, es:[41h*4+2]
/ x- ]$ {* u4 M cmp ax, 0f386h% z7 s) _ V1 r( |8 {: S7 T d: f
jz SoftICE_detected p2 E/ P) ~. e. e2 E
, N/ Z" d, M& h" L. \# f( s6 ~; @5 Y
int41handler2 PROC
C4 F- x% o, D+ M% m iret7 X" I9 E$ _" P; x1 M
int41handler2 ENDP
7 ?% E! \" f8 E$ z% z
1 f" K( |/ q7 e( p+ O: I3 R5 k2 z: P1 T1 a$ o
_________________________________________________________________________
; n3 p2 e% z' ?# g- a) c' Z3 r1 l1 x8 L" M$ @
/ }* B/ ]( G$ ]
Method 06
9 a) d0 S8 b! O0 I5 L=========% Y) k- D& p: g, |8 L" V
- D# x* N/ X) L/ \ X* b {/ R$ V
2nd method similar to the preceding one but more difficult to detect:
1 O Q4 Q, ~+ r( r/ P* S9 A) a* i5 n. U4 o8 M! e. q, n& W+ B) g
: w& u$ a- x0 s+ `
int41handler PROC
0 N7 F- d B6 [) o mov cl,al
: t5 o7 a+ h @9 l# H& Q3 K iret
0 l8 i- ]. P4 d4 q- B Jint41handler ENDP
: D0 L) _( ]- a& m5 E# D( W8 f6 r
: V( ^2 @4 A# N6 X7 k
# m6 ^8 M0 ]. X2 D xor ax,ax: d9 q8 s, D4 X! Q. p" _
mov es,ax3 j+ }* K: z; G5 q. m- g, \
mov bx, cs
/ s/ V/ }0 g2 X) ~) U; G' @' W: c lea dx, int41handler
: O/ C4 b& N# n, s2 p1 d+ X6 ^ s xchg dx, es:[41h*4]: j- T" O+ h2 o- `# O
xchg bx, es:[41h*4+2]2 Z) P) X) Z" j5 {
in al, 40h
7 A/ J9 P& {% N( F( c xor cx,cx9 d: `5 g% _# d
int 41h& r. X4 G7 a8 @) n6 W
xchg dx, es:[41h*4]
$ e, S# x' t& X( x& A5 i xchg bx, es:[41h*4+2]" m) c/ e, {4 J
cmp cl,al
6 j* S/ F% s& u7 ?* @8 l4 y jnz SoftICE_detected2 @( _7 S8 x, f/ U- X; j+ R! {9 H
7 R/ H$ @1 J% b! `/ }
_________________________________________________________________________
6 r6 U; y9 O* a3 P4 E0 V) ]2 c( X0 j: h1 L+ P% p
Method 07# b8 |) d. H5 m( [
=========+ V9 k6 _# s, }+ A$ U
: G. b1 m3 H4 E2 o/ x
Method of detection of the WinICE handler in the int68h (V86)2 O. _1 o! U2 ~2 T
/ u+ X1 B$ Z; ~+ u. H mov ah,43h
& G6 t) F5 D3 G, L int 68h! e! X1 C& ^, e4 z
cmp ax,0F386h
& t- ^6 g, r+ I! l jz SoftICE_Detected8 _5 S3 B$ J4 p& @& H! |5 c. I, C
" O$ ?5 A1 L& d
$ @* C8 R6 U- A) G+ R=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit$ {: N. w' w' W; \
app like this:
: _4 Q: H3 E S* q) c, U$ a
3 x1 [8 O0 I: y' ^$ m9 l BPX exec_int if ax==68% V% j, H$ e$ \4 r( P
(function called is located at byte ptr [ebp+1Dh] and client eip is5 q! F0 [# l+ G9 k8 S; R( e3 x
located at [ebp+48h] for 32Bit apps)
/ j7 W+ b2 v+ j; l__________________________________________________________________________
9 x) G6 W, ?6 X4 I6 P; ~9 o% `3 b q8 @) d! j, s
# j: S$ r( q! V! q" X) A
Method 085 u3 K, o+ g0 G$ v' p+ \6 I
=========
6 b6 `5 ]5 q- D: k! M1 D+ E s; ?
1 J. s4 y# a* e# i& o: N7 XIt is not a method of detection of SoftICE but a possibility to crash the2 Y* E6 ~& r. k2 i; ^
system by intercepting int 01h and int 03h and redirecting them to another
7 b8 z$ A; g; V1 S9 Hroutine.
, @% M/ y0 D$ S2 h3 }# k/ `It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
; u5 G$ }% H- J' w# Yto the new routine to execute (hangs computer...)' H3 Y' g- F2 e% u# _) s* O3 `% t
# w; G3 ]" [+ o# [) p) W7 f& A mov ah, 25h
5 g4 i" Q* ^* M( L% o: l) R mov al, Int_Number (01h or 03h)$ Z ~. X# J. c" H7 n( Y
mov dx, offset New_Int_Routine$ ^5 N1 o4 v$ t) p) V9 h
int 21h
" \- _4 `9 V) U; X1 Y
% }3 ]9 y- y1 R @9 V__________________________________________________________________________
2 u7 x& w( U' D6 E5 i7 K8 F7 N
Method 09
" T+ h% }* r) X2 R=========
( K: g! T. u7 M! I$ R8 o
! [# Z2 s4 ~/ Y8 pThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only9 i, B6 b! p1 y" Z, o) K3 G; {, i
performed in ring0 (VxD or a ring3 app using the VxdCall).% y& Q% u2 Z$ h, f; w- P
The Get_DDB service is used to determine whether or not a VxD is installed
/ j) S& v" D; k0 H* k( p; u4 Qfor the specified device and returns a Device Description Block (in ecx) for
3 V6 P2 J. X" w0 t& `# gthat device if it is installed.( Z* a& T9 U3 [# F- I, A
# \4 |9 H# w% r# N4 ?. Y h
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
" z3 T7 N$ a# e0 B N" ? mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-); H, n- M; [4 K8 b5 {6 i, R
VMMCall Get_DDB
0 v) p: O' O$ n1 a7 b mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
/ f4 W! _# S! q2 L. n7 i9 X$ m4 _# N
Note as well that you can easily detect this method with SoftICE: i9 V/ X* u+ N5 o# a& K
bpx Get_DDB if ax==0202 || ax==7a5fh( {& a( n* S! J( g5 N) f' h' _
/ U+ |' K3 r3 I9 Z__________________________________________________________________________3 b z/ a: l, p, q
; R% \/ n/ a/ Q4 e6 v8 T* N; `9 h
Method 100 e b3 g: n# j7 m
=========+ P3 i$ d% M+ w6 L
% m; N1 A1 I* V=>Disable or clear breakpoints before using this feature. DO NOT trace with l; M9 Q8 y1 Q& r; ~/ a$ R
SoftICE while the option is enable!!
/ m$ K3 r% g5 {7 r, G, C) \" H: l/ p0 |: u' u* g9 h( Q
This trick is very efficient:
( U$ v! O, u; `7 s) v! xby checking the Debug Registers, you can detect if SoftICE is loaded3 ^0 V' h+ J0 [
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if4 N- k& ^! @$ U2 {# a( y/ F
there are some memory breakpoints set (dr0 to dr3) simply by reading their
% G9 X* W- ? g8 q: Wvalue (in ring0 only). Values can be manipulated and or changed as well1 E) ~3 S" Q- A0 y
(clearing BPMs for instance)
' n7 r- r% W K) p2 I7 w l0 d8 }+ V
. f% ]3 M# U9 k a__________________________________________________________________________
* [2 n! ^+ p$ j- d% H. ^ h0 h0 t& U
Method 111 |: ^! }+ E0 m* K% }% R7 T7 B
=========
2 K$ L0 V' C: F( c) V
' |9 m( ~! o Y+ PThis method is most known as 'MeltICE' because it has been freely distributed4 g* t& C! X& W) E! W1 V
via www.winfiles.com. However it was first used by NuMega people to allow
6 A; L" D2 I9 |; t- b0 nSymbol Loader to check if SoftICE was active or not (the code is located
7 y: I8 i% [: o* M" p4 v$ ?inside nmtrans.dll).
/ ~7 J, c3 x0 r8 b
1 s% F; H+ l* \1 D# _The way it works is very simple: e) K* n$ Q( q) a+ \+ l
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for- T% P5 h* Q: X3 d6 L9 I* W
WinNT) with the CreateFileA API.
# v% _: a- z- G' R
) H$ d5 L# k, i/ `Here is a sample (checking for 'SICE'):* C) Q: U7 U2 Z: M2 Z$ U$ X
8 G. U' O4 B" D/ UBOOL IsSoftIce95Loaded()' a: ~9 n4 k$ c) M4 ~/ Q3 b
{6 K3 @5 a; i9 G2 k
HANDLE hFile; 6 d) F' o/ Y$ K( s9 S
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,- P' [1 \6 ?9 J
FILE_SHARE_READ | FILE_SHARE_WRITE,
7 l' |3 _- g! A1 ?% h9 s; q! S0 _ NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);' S$ \0 c4 f: @$ M0 m' d
if( hFile != INVALID_HANDLE_VALUE )* D* e8 Q: s8 z" z# p& A9 n: e4 I
{" n3 `( w! M: e0 @* v
CloseHandle(hFile);
/ D* R; T/ u- d2 P return TRUE;! X. A/ T1 s/ e
}& A/ h% f! P0 b% n
return FALSE;) M/ o1 L3 P% ?7 c9 d6 M6 {3 e a9 H
}
7 W0 ]/ O: C# C
/ F' w) `" ~. K4 GAlthough this trick calls the CreateFileA function, don't even expect to be6 C$ q# _; V% p
able to intercept it by installing a IFS hook: it will not work, no way!
5 ^+ k, o: d1 @' GIn fact, after the call to CreateFileA it will get through VWIN32 0x001F' d8 ]8 e( o/ C2 G+ `9 D
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)+ ]* Z; E4 k5 H% Q4 ]4 g, [
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
3 k) K3 }" B' m' U0 ifield.- x! Y$ B, F! |/ l0 X1 e
In fact, its purpose is not to load/unload VxDs but only to send a 2 \! c' j9 ]- M$ n& N
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE): \2 N1 o) v; C, E
to the VxD Control_Dispatch proc (how the hell a shareware soft could try9 g F; I- o" x/ W7 J9 o: b& B' L
to load/unload a non-dynamically loadable driver such as SoftICE ;-)., L0 c7 O/ Z5 \* v* z, e6 ~
If the VxD is loaded, it will always clear eax and the Carry flag to allow# R" Y. A N5 X$ o7 t6 M- i ~
its handle to be opened and then, will be detected.( n1 q. c8 O; X/ K
You can check that simply by hooking Winice.exe control proc entry point
. I8 T* p( t% J ]* K7 y. P3 owhile running MeltICE.% L+ u3 S3 h4 w7 Q( T) `2 I
, \$ P# Y7 {! q% K/ H
: E) ?1 j6 u6 y' e5 A ?
00401067: push 00402025 ; \\.\SICE2 U8 u9 O+ ^! H9 \( A# t
0040106C: call CreateFileA
1 D% S# r* w: r& J7 C 00401071: cmp eax,-001' o, q. X$ x* v; U; H1 D X6 |
00401074: je 00401091
: q$ ^9 V/ M, d% i- W: @+ K! M
. [, \9 W. ?2 W" \, {( I
5 l0 X8 |) d2 r5 A3 z' g2 |There could be hundreds of BPX you could use to detect this trick.8 [9 |, f/ y# w9 m6 e
-The most classical one is:$ X4 l: z" P/ h* z
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||+ e! Y+ a% C3 I# @! o
*(esp->4+4)=='NTIC'* _9 Y% @ H- B9 A( h6 Q. H
6 `6 z+ P& d( ^4 N" J
-The most exotic ones (could be very slooooow :-(8 i/ S9 s* @! `' |+ W4 g( R
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
. D1 y) N: e; _ ;will break 3 times :-(* A/ c+ z( F. ~* r
; F9 a1 C% t5 Z. g0 C-or (a bit) faster: 2 k. ^2 X8 E0 W3 g" @) L/ n- c$ z% `% ~5 b
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')8 G0 T: [$ u% k. z/ R# d0 P
, N- M% ~; C: A7 v4 |3 W
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' ! @' X) G" p7 Y( i1 }
;will break 3 times :-(" M- l- ]: U. a3 K
6 n" S9 x% h0 E$ q-Much faster:1 F0 _+ v( W" D3 \
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'1 p4 J4 z5 A$ S6 o
1 `" Q& e/ h4 H4 u7 |- m( \9 L9 x* b
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen% a! N2 K! j7 z0 y% D
function to do the same job:2 l5 c6 m6 a% w' r$ B1 z6 x) Z+ v
9 @$ `) i% Y# c
push 00 ; OF_READ
6 X$ y4 T1 x$ g1 \6 [. N mov eax,[00656634] ; '\\.\SICE',0$ |: L+ D" n3 q2 c0 I
push eax; |( ^& B l9 g( A3 i8 I1 T- G
call KERNEL32!_lopen( e6 t; U. D/ L0 {
inc eax
" n3 ]# {/ s" f$ u jnz 00650589 ; detected
! a& u% i, z# v2 T P+ M push 00 ; OF_READ& @0 F4 h5 x2 V, X9 N
mov eax,[00656638] ; '\\.\SICE'
' n: b$ v2 O4 z3 p5 ~ push eax$ D ^* B; X2 R: n, N: K/ T1 T
call KERNEL32!_lopen
% S& P; T4 m( k1 F inc eax- Q: v- \2 p- n& D& A
jz 006505ae ; not detected5 W# j9 R$ P! I9 V2 N# T0 B' s
' {6 L7 c- Z" e
u0 l8 Y( t0 [% ?__________________________________________________________________________
7 f1 E; k5 g" Y# j# {$ j# n$ [3 g1 p M( p- W
Method 12
( j5 M& M1 [! Y4 I! [=========
! }1 y8 \" _- v/ a: \, P# o0 H8 `0 f* g6 C
This trick is similar to int41h/4fh Debugger installation check (code 05" P) L9 V( D# h3 }3 j/ m
& 06) but very limited because it's only available for Win95/98 (not NT)
1 P" @: s# `, U0 eas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
0 h* o8 x2 F4 v& w! x+ G
- b6 D- o+ w; J1 {* `8 B push 0000004fh ; function 4fh4 i3 m2 B2 e9 j7 Q2 K; W
push 002a002ah ; high word specifies which VxD (VWIN32)
8 i5 B6 C7 `. ` ; low word specifies which service# [$ J$ ?" f) k) N1 N/ R4 |; L
(VWIN32_Int41Dispatch)8 M6 P, s0 y6 q6 @3 ~
call Kernel32!ORD_001 ; VxdCall' c3 N5 \+ }- ~% n4 e8 A+ R2 {
cmp ax, 0f386h ; magic number returned by system debuggers+ L, m# F9 E! I( U/ k; }
jz SoftICE_detected
6 M- o2 m8 e9 K6 p5 S( G- @3 z8 i' ]: a6 |1 S3 J3 q
Here again, several ways to detect it:
; }) h& O% r1 R% i# B+ O0 {! _5 U6 o9 f: i% k' X: E9 Z3 ]
BPINT 41 if ax==4f B) X% P1 l" |, f: j7 `
8 d! U" T6 n) B$ ~3 i: \4 I BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
5 M7 J7 S1 \9 \7 g( V) k3 X. z" e, g$ H. e' C
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
/ {( Z8 ~( @2 X0 m4 O
. g! j# ^; Y9 W# J BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!- |6 U4 |- }: c4 P
+ m I+ Y5 i6 a5 a- \__________________________________________________________________________
4 `+ o( F# _: s$ v
; ]0 O9 C+ D3 N: Z A( PMethod 13( L: k+ r' V6 |% k
=========
. k" T. @( ?$ a6 k, d0 e" J g* y2 I/ H4 {9 w
Not a real method of detection, but a good way to know if SoftICE is2 \4 z& d+ N2 X1 r
installed on a computer and to locate its installation directory.$ ~- T; y% S/ ~- l: J" [' H2 A; b% ^
It is used by few softs which access the following registry keys (usually #2) :6 ?% V; j8 ^& f' Q! C6 h2 T
1 `# |6 w1 A! H-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
. g9 A* {7 N/ ^$ z" E' n\Uninstall\SoftICE
S3 [! F S* h. g% }-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE& f: ]9 ~6 a1 _" q' w4 V5 T* u8 ^/ S0 n
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
4 x7 G. R, u% f ^( p! N* M\App Paths\Loader32.Exe' o6 Y) ]/ c& U8 E& p T. v
5 u2 y: q+ D: }$ v, I" g
# C, T5 ~1 r: sNote that some nasty apps could then erase all files from SoftICE directory. e/ t5 {8 B+ K4 r+ Q4 Y4 i2 o5 s) g
(I faced that once :-(. |- b9 n- z$ s3 S
6 |3 g, }0 L/ ~1 YUseful breakpoint to detect it:8 n. x8 z K* ]7 r) A* P8 |
0 {0 V( T0 A( ^# g5 y1 Y6 m
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
5 b( u' @8 k7 G+ j, R5 J. g
8 @" s' U/ W; M+ S3 b: L__________________________________________________________________________+ A) @. l% o* M$ n" \& T; t
% L5 l& o! j$ j S. ^
# Y' x$ I3 @ B4 O
Method 14
% h" I$ [0 b7 J+ a( J) Z2 o=========3 t. q* C6 A( F( r7 f% b* O" b/ N
2 ?( n+ _0 \+ _% H4 c% h
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose5 t9 y$ N1 k$ m$ g8 x
is to determines whether a debugger is running on your system (ring0 only)., ?# d0 k; j8 e. r5 o5 v6 _
8 [2 w _& U( w2 ?# {- a
VMMCall Test_Debug_Installed
( ]: T; d! w) v je not_installed. f. Z! Y- s Z( W" g) p6 d) d
8 H2 _+ K6 {& i/ I4 }This service just checks a flag.% n/ @5 w; m9 y$ G+ x' r4 L
</PRE></TD></TR></TBODY></TABLE> |