<TABLE width=500>
. B" J* s. a2 p$ D<TBODY>
' Y+ Z, C: K8 w' P! F<TR>& R" @- v% c' i5 y" y
<TD><PRE>Method 01 " I! A, |) p% Z1 @- k
=========
g7 c4 f5 o# M" t0 `8 Y# U: z- \5 M0 ?3 [) b2 K5 q, B. F& O
This method of detection of SoftICE (as well as the following one) is$ X; m! e1 [, [; \) n
used by the majority of packers/encryptors found on Internet.
4 e) s5 x3 i+ L* f4 ~5 XIt seeks the signature of BoundsChecker in SoftICE, a0 V' t; ]. _: n/ u! T
( N3 e3 j2 L5 D# T6 K- o
mov ebp, 04243484Bh ; 'BCHK'. v& a9 _! u0 `
mov ax, 04h
1 j g$ y9 n; F int 3
5 m- L4 A$ z6 ~: n% V cmp al,4
0 B/ \3 d: g( q# F9 }- f- N jnz SoftICE_Detected
/ R1 b. k9 E$ F3 B. G
# g* }9 q n* I8 o+ f. X___________________________________________________________________________9 T2 T$ J4 c6 F9 j5 @. p
5 d3 u* E2 n0 H& xMethod 02
% D& y2 z6 P- c% d=========
8 v0 U5 j9 I! f, d8 B- I
6 q" `- H0 h' K0 Q% E! q4 M9 f' NStill a method very much used (perhaps the most frequent one). It is used) r# ~! t7 `( y
to get SoftICE 'Back Door commands' which gives infos on Breakpoints," w: z0 C9 D- X5 N, J6 s
or execute SoftICE commands...3 H. K9 V4 p% N0 J5 T
It is also used to crash SoftICE and to force it to execute any commands
* C4 \5 l) ~+ @9 c: E(HBOOT...) :-(( 3 i- K3 U! R+ l6 _4 Z7 M1 A
9 J1 z% I8 o) @0 I1 \& B. E% j- b
Here is a quick description:
0 J- ]5 R0 u; S; a9 k6 u- R# e4 ^3 Z: U-AX = 0910h (Display string in SIce windows): W! Q. ]( [4 h+ l2 b2 G
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)1 V" T% j% T1 t0 F& s S# `" j
-AX = 0912h (Get breakpoint infos)9 {7 n- g9 h" n6 f) \ @4 e! P
-AX = 0913h (Set Sice breakpoints)
' f* Y l* m3 W" \; H, Y7 s-AX = 0914h (Remove SIce breakoints)% k! L# u/ X7 s& \ D
# `/ H6 w: s6 |' wEach time you'll meet this trick, you'll see:
: N0 r' A1 z8 E' Q-SI = 4647h
' D4 b9 A: Y6 X-DI = 4A4Dh
7 K* l6 o9 H; @2 L5 r$ J/ ]Which are the 'magic values' used by SoftIce.
9 U& u9 p! B" [1 I8 aFor more informations, see "Ralf Brown Interrupt list" chapter int 03h., i- W4 F% u( J$ I1 z0 p
8 |* v0 w: J) U: E
Here is one example from the file "Haspinst.exe" which is the dongle HASP% H1 t5 v% i( Z& l
Envelope utility use to protect DOS applications:
3 _& n5 d; I- L, }) [* c1 E9 }5 t+ P3 m( Q Z8 l' r
! z# ]0 V& ]# B4 i9 P
4C19:0095 MOV AX,0911 ; execute command.% D( ^/ r4 S5 z6 j; o( z" V
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).' v# j! w( W* Z2 d
4C19:009A MOV SI,4647 ; 1st magic value.' _* Y- l# W4 l9 ~' Y/ U: w
4C19:009D MOV DI,4A4D ; 2nd magic value.
3 l3 B' b9 d. X4 z4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)0 a9 q. N0 m+ n3 M/ U4 H! E
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
- G" I1 ^ F0 X& r8 |4 ]4C19:00A4 INC CX
4 y5 E0 H2 \+ I4C19:00A5 CMP CX,06 ; Repeat 6 times to execute( ^* ]! f, w) x2 I Z3 _
4C19:00A8 JB 0095 ; 6 different commands.
) q: P6 J: U' W0 g3 j0 V4C19:00AA JMP 0002 ; Bad_Guy jmp back.
: M& A# I' O% S! {. E4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
3 \+ f& K/ R- P! p: b3 y* P2 B9 |7 o& L* l; A9 o# B5 f
The program will execute 6 different SIce commands located at ds:dx, which0 t C+ U# V: s( I3 o( g. @2 I
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
. x/ T4 O: Z( p2 k3 B+ m+ E4 J- `# T$ f4 K; Z$ T8 Z# \+ c3 f/ x
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
4 K: X" L$ G0 C2 b3 E. \, z W___________________________________________________________________________# A: f9 _0 h6 o; V( k2 ?6 i
+ R( V/ b, y) m8 k" b: x
9 E& K I- }0 T& Y) BMethod 03
8 d( E0 x* c* a& T8 o; ~/ C7 l=========
6 M/ a' f7 r# W7 r$ z8 ^) J* J p* x e& P
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
) _: G: V& M1 J9 l* S- N& m(API Get entry point)
3 w. ]7 U, \# |" A: R / M4 g1 C; F9 N) d4 {' O- P" ?
" h7 T1 x8 E w4 F xor di,di
9 ]( I5 Q: V6 a& H# K mov es,di8 y) z, W! c4 X3 F
mov ax, 1684h
! S; b$ N# s2 _( X' M: x mov bx, 0202h ; VxD ID of winice
8 N! R4 D, z& y( p$ p2 F' Q int 2Fh
+ w# n0 X7 ?5 b1 A, l% t& A mov ax, es ; ES:DI -> VxD API entry point
- y# T X8 C# r, a$ v0 y add ax, di
: B7 Z: k2 S- U; `% \ test ax,ax
2 u+ U; C0 M1 C. c; W7 a jnz SoftICE_Detected
9 ?) G, Z- f; l- z2 ]" H% k, |2 J, @$ B. f
___________________________________________________________________________
# ^6 {5 P! e9 z, v+ ] C% w2 c' ~6 J- C2 l5 H
Method 04
( Y; ?) l$ D# h2 a( r=========# {- N7 _% t& R- w9 G5 X! y
! z0 ~2 ~/ ^9 b+ b8 M- C8 @% oMethod identical to the preceding one except that it seeks the ID of SoftICE6 p% U* D# [6 J; z$ Z
GFX VxD.) g2 j5 f$ i6 N, b) U+ }6 W
& `2 V; L2 q7 v+ A; D4 L d
xor di,di! M! g2 r# a+ u9 F& J8 M
mov es,di
5 \. {. q4 B5 V8 L$ b( O, w; y mov ax, 1684h ( o: ^$ J8 F4 I6 U) U
mov bx, 7a5Fh ; VxD ID of SIWVID3 Q- L5 W3 n; y0 h
int 2fh5 F/ b; j/ a( y
mov ax, es ; ES:DI -> VxD API entry point
/ ]& f; \/ E2 v# n: F; m6 e add ax, di: H& M+ R- R1 H7 N$ K; q
test ax,ax3 U% T; b% p4 L1 Z0 P9 ?; }0 ~
jnz SoftICE_Detected& P1 L' [2 v$ I
$ a+ [2 R* O7 l5 m__________________________________________________________________________ y8 n5 G4 }. H/ } X) n9 @
1 m) L; A# k) h, X$ w6 x5 F d; h+ {
Method 05
6 E0 x6 |/ s+ y, a+ H5 D; o=========. G) v4 `+ [( Q0 J- t( {
$ U; |8 S9 |" z! u8 R* h+ dMethod seeking the 'magic number' 0F386h returned (in ax) by all system
8 |8 |5 V' _& rdebugger. It calls the int 41h, function 4Fh.
8 q# J9 u/ f4 ~There are several alternatives.
/ ^1 W. `+ W# ?* h6 l7 L1 T8 P
- M' |) i2 n& Y/ K7 @. T( |The following one is the simplest:
5 n) p: c/ f1 X) I4 I2 S; a+ m5 U. O- Y# c7 R. Z& R! u0 e
mov ax,4fh
5 Y# w' c1 a+ M int 41h
& {, v" @- Z+ U cmp ax, 0F386
( D2 q1 F! h1 J& \+ z/ v8 W jz SoftICE_detected
! c, P+ |, f P, a/ h% o( g4 @' S& E. A& J; F7 ~
7 D! |, m$ L$ L
Next method as well as the following one are 2 examples from Stone's
" M% x6 h: e6 Q"stn-wid.zip" (www.cracking.net):
; V. W% G: C4 y& r8 O8 ^2 u' E# M' P6 f( L( C
mov bx, cs9 @, \, j3 X* ]3 ^
lea dx, int41handler2 @. K% D0 V4 z: S4 D) z: I
xchg dx, es:[41h*4]
! B" l9 y! g0 o8 N+ o xchg bx, es:[41h*4+2]4 u" D' H, G/ r. y
mov ax,4fh
" a: Z5 Q- p1 p- E! }+ w# y int 41h3 g0 ^4 k/ d- h0 Y
xchg dx, es:[41h*4]( M7 W7 @, L" A9 h
xchg bx, es:[41h*4+2]% \& w* U1 i: _9 G
cmp ax, 0f386h
5 D! K+ f8 `& ]: o jz SoftICE_detected
: k: g1 d4 G5 U$ @( p) H
; h$ N. k9 Q3 [3 s( w2 Pint41handler2 PROC4 a! r$ T/ ~7 q/ P" s0 J
iret
" S3 U9 z5 E1 F7 D) |. Mint41handler2 ENDP
3 ^. b, U( i+ ~3 h5 t9 I9 G/ X2 b( F, }% {, I
& o r9 \* ?9 o8 y4 S" w, f: N
_________________________________________________________________________! P- q( d9 b/ B' |( ]0 V
- s" _+ P. O$ `1 N
( @* u6 p, \9 P. E5 bMethod 06% M3 q& f1 `& d& d/ L
=========- \8 d, V: | |; c
7 m) _4 G8 ]" \
6 {( {- b6 G+ G2nd method similar to the preceding one but more difficult to detect:3 V: U2 N1 c5 \) [- F
6 r; k t; F4 n$ Y9 v3 Y2 ~4 `4 H: ]5 o- G) w) N; ]
int41handler PROC) c- p2 d. O2 x5 R
mov cl,al
1 r' ]6 l1 @; w3 F/ }9 z5 X0 ?, o iret; X- D& \# u; D& @2 S" |! n
int41handler ENDP
+ |6 a2 [1 [. O8 o! s1 t) ?+ N; I6 N/ ], x
8 d9 T4 b- t; k4 q$ _
xor ax,ax1 X: {' h, ]# E4 R
mov es,ax h/ \, k( B/ X/ L
mov bx, cs* I( D7 a3 s9 f0 ~; p5 A5 d! n
lea dx, int41handler" I" d6 X8 i, P% O
xchg dx, es:[41h*4]
/ G h. l# e+ g" L7 p* L: q7 M xchg bx, es:[41h*4+2]
. p5 f5 x+ p) \: _ h1 p in al, 40h$ ~9 G4 f) R( n& g$ @
xor cx,cx
/ T+ H0 H4 K8 m5 w int 41h$ T7 z2 A& b+ U U( C
xchg dx, es:[41h*4]
) B& T0 F/ z7 J7 B xchg bx, es:[41h*4+2]
, z5 K* ^4 Y p$ y! C) p cmp cl,al8 e2 l) O! i( U: X+ d2 [! I
jnz SoftICE_detected
0 Z( ?6 y( L( R5 ~" b3 d2 M6 ~' R9 g( C/ z5 e) l
_________________________________________________________________________
8 j3 k# k3 V, @( Y1 m g4 q/ D0 @
# Z; ?: @: D" c$ c% M. j7 s- hMethod 07
+ B4 k: i. `) @0 G1 F8 H+ @% e========= J& Q5 V1 W7 B9 f% l- g. ~& n
/ x7 h( f+ M! Y7 s1 _Method of detection of the WinICE handler in the int68h (V86)+ m1 ~, a+ @( R6 N( Q& w
2 E+ p4 k7 e) S; s1 e5 `6 W L mov ah,43h
! K9 O) e# n) F0 E. g9 t int 68h
2 l2 r* w' v l; U1 O cmp ax,0F386h
. e! n* @6 r$ j jz SoftICE_Detected8 i, F7 ~9 s3 [4 m5 |- y
. Y5 A, V/ z1 y. `5 a
- ~4 y* i/ `# _# d- _0 j9 }& |=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
2 R/ k; Y7 D% m2 Y0 c) D9 t app like this:
5 m0 [ _7 R; z+ F! r* W* J& a9 Z2 J D& w
BPX exec_int if ax==683 j& X. s+ ?# w$ h$ ^
(function called is located at byte ptr [ebp+1Dh] and client eip is
0 j$ F/ b2 W/ O& }1 c located at [ebp+48h] for 32Bit apps)3 N D/ ^" W# Y; O6 W) X' y
__________________________________________________________________________
8 m5 o; n2 \2 ?/ B: g' q Z$ C) M2 e7 I& m' R
6 l# u& A7 D* V8 R
Method 08
7 F+ b* U; i$ t" z9 q; N1 M=========0 L' T% b: B# c; F8 ?9 }# Q
0 f& H9 R9 s) t4 ?! ~- mIt is not a method of detection of SoftICE but a possibility to crash the
v! }) D) {7 C: m# Nsystem by intercepting int 01h and int 03h and redirecting them to another: ~0 b! a3 c G+ t5 P
routine.
. F% W5 R( g& x% V* n: C1 w2 c2 m3 AIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
" Y) q* y/ N( q4 [ w Kto the new routine to execute (hangs computer...)3 @3 u1 l9 z' a% N9 C
* I1 W, P6 O8 Y3 {
mov ah, 25h
[$ x$ |* U2 ^0 ~" s0 j) i2 | mov al, Int_Number (01h or 03h)8 s" m4 _& w9 H( n
mov dx, offset New_Int_Routine
/ G8 O$ r$ R% \) h int 21h) R3 G- h2 ^, C/ d8 C, h
* w. M! ^( d6 q: Y' i__________________________________________________________________________
8 F2 {$ w) q) J" ?( N9 _" t/ f! F& H' \+ i. d5 {& ]
Method 09+ g/ t* u0 _1 r( i9 w B" @
=========
0 ]; Y5 h, a* ^2 X: _4 m) u; j
' X7 |* I& } U: y+ XThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
6 d0 o" ~0 Z0 G7 T5 Gperformed in ring0 (VxD or a ring3 app using the VxdCall).
, p/ j5 `1 O* v% M5 rThe Get_DDB service is used to determine whether or not a VxD is installed
- |8 W! p# J8 a8 o; Mfor the specified device and returns a Device Description Block (in ecx) for
: @% J; S+ J4 y B8 p% Xthat device if it is installed.) ?4 D, I& ~6 T* Y, S
& m7 I' y5 G* B# Z
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID1 U8 o" z, c, l: W
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
/ m( _. M: s( ]9 p( ^2 d! B VMMCall Get_DDB! Q- g8 n6 L; q& J
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed Z9 {2 @5 d5 y7 v5 |
4 m; ?6 F c, M i3 V# g5 o5 t
Note as well that you can easily detect this method with SoftICE:
. u+ f, Z7 g9 ^2 g bpx Get_DDB if ax==0202 || ax==7a5fh
( Z$ i( |& t/ L1 |; O* y; I
; ^/ T' c$ e' ?9 I/ L6 X__________________________________________________________________________
$ k' p. ?( e. q- u% h
! q$ ]/ I) k0 @0 U1 Y8 Z% SMethod 10
1 {5 @0 t( c/ }& w2 t4 k2 y=========
$ \9 I0 y" C, Y) e& f' l8 w4 l$ y1 n/ w* Z! K
=>Disable or clear breakpoints before using this feature. DO NOT trace with- ^7 d8 @. ?, ?3 P( O7 q' e
SoftICE while the option is enable!!
, _: A9 }1 K$ u* q3 O+ W i$ x$ N
+ i0 |* s2 ^# {1 E# L" n6 q% |This trick is very efficient:2 ]4 e3 M4 Z; e
by checking the Debug Registers, you can detect if SoftICE is loaded. B( i: t% o0 b: D& b7 d
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
: |/ {$ [, {# x6 [9 `there are some memory breakpoints set (dr0 to dr3) simply by reading their
) ?$ G) }3 W( d6 l9 ~$ j5 bvalue (in ring0 only). Values can be manipulated and or changed as well
, @4 v" u9 Z* {# g" k) W(clearing BPMs for instance)
5 S+ q( H0 U; ]5 S& V' L y/ ~2 X9 l+ P
__________________________________________________________________________
( x+ P# h) c5 s$ k. f, E* B' V$ k
Method 118 a" e# s* |2 |$ G
=========5 u9 u8 x3 {* Q; k
& j! F. ~# i8 A q( |This method is most known as 'MeltICE' because it has been freely distributed
1 G% n6 z+ {+ Z: Vvia www.winfiles.com. However it was first used by NuMega people to allow! l. z2 V: L0 V) F) B1 X$ n
Symbol Loader to check if SoftICE was active or not (the code is located5 P& h# ?# C% n$ l* N
inside nmtrans.dll).) F& J- M9 M" }+ b: E
# l/ j0 x4 S6 z t3 I- i" a- l) _; w/ p: IThe way it works is very simple:
- s- B: Y8 { e* RIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for6 `- D: {0 ~6 c2 [, [
WinNT) with the CreateFileA API.
% t0 e/ }5 `- R: S) I) @" G1 ^$ E$ I4 A1 g' c! F! }
Here is a sample (checking for 'SICE'):
! U4 m; ^) a3 J) S) e# O- J1 U" g5 ^1 `; M. H4 x2 P
BOOL IsSoftIce95Loaded()
4 V( n2 E- \( @* g) @7 B. G{# K7 ?5 j+ y- n0 I9 R
HANDLE hFile; " @; R2 r5 P' g5 G8 @- M# T
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,# n* i* S2 n. f
FILE_SHARE_READ | FILE_SHARE_WRITE,
8 ^) Z& k) p0 b7 ~" L- c+ N NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
6 Z. L0 ^" T9 [2 c. f# Q2 n5 P1 i if( hFile != INVALID_HANDLE_VALUE )
* g* x% d( J& u7 S. ]- H: n7 C {$ z* J2 _, f+ M+ J* B* L
CloseHandle(hFile);
# ^$ `( B4 B( u! J4 V return TRUE;& V( m+ R) Q/ x% T# W! B, e6 b
}! y& e: V. S4 u8 ~2 U8 x. E3 c0 {6 N
return FALSE;% b* j# U1 o( A3 l; {) b8 S
}
2 _+ P9 V; f$ q* [1 e8 ]
( K' O, K( _: U. l+ |4 B, H+ C; hAlthough this trick calls the CreateFileA function, don't even expect to be
" o2 O9 J" J' c2 U5 b* K* cable to intercept it by installing a IFS hook: it will not work, no way!1 f3 n, `' D% k& F! ]
In fact, after the call to CreateFileA it will get through VWIN32 0x001F# l. {: ?5 t$ g: Q' F+ J
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
5 A) y( I0 H9 ?5 D" S! A! Fand then browse the DDB list until it find the VxD and its DDB_Control_Proc
: f( o; S1 T5 m" rfield.
) a2 r. A/ L* U; p* [( g* qIn fact, its purpose is not to load/unload VxDs but only to send a & h- f! {# f9 M" G! c
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
1 J& T) ]5 p1 ~4 D0 J# gto the VxD Control_Dispatch proc (how the hell a shareware soft could try
' ~; O: q$ V+ K( Ato load/unload a non-dynamically loadable driver such as SoftICE ;-).! y# j' i) A7 F) e; K
If the VxD is loaded, it will always clear eax and the Carry flag to allow& G- b* _% N6 ^9 `, V! l6 ]& I
its handle to be opened and then, will be detected.
" l4 I# \* w7 V! ^1 m2 Q& C/ y3 dYou can check that simply by hooking Winice.exe control proc entry point; t6 V3 H; T" P& y
while running MeltICE.' l' U; M9 H6 ~/ n+ J1 Q/ o3 ^
9 d% ]7 X: }- G/ D* O3 V2 _5 N; M p5 S, H3 s( B$ K; u+ B2 D
00401067: push 00402025 ; \\.\SICE
7 R7 b1 `5 T: Z' ~- s* l5 [ 0040106C: call CreateFileA N2 q8 R' o, F$ a1 C) ]) f# u
00401071: cmp eax,-0014 m! p1 T8 q0 @5 G5 V+ l5 k5 u
00401074: je 004010911 _$ t0 v6 F/ V. u
# {3 U9 m& h! j- X$ j7 f! S
. z. R0 p0 f. E, j; cThere could be hundreds of BPX you could use to detect this trick.6 F2 i, N/ k1 d5 ^
-The most classical one is:& G7 W' @0 u5 q+ t- D
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
9 {( X) r6 x |0 S *(esp->4+4)=='NTIC'
9 _; b5 M+ y: J& U1 a0 l/ ^: E6 i4 n
, q8 A$ w* N8 {: k- a-The most exotic ones (could be very slooooow :-(: L' M4 `$ b; B, `
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
B% k2 f) `# X1 C9 F9 c ;will break 3 times :-(2 ?$ ^5 V8 k2 T
. B2 e l+ R) [7 `, o( r
-or (a bit) faster: 8 N/ x+ i. K( M; [' }5 W* j
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')1 ^: p, j7 ?3 D' y( o' D6 \( Z
- E" u7 O& U! U5 t" j
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 9 t! T& O' p% V6 B4 k
;will break 3 times :-() C6 G" D( w( A) [2 b; ~& ~
. P& V4 d" \- g7 P6 o
-Much faster:
* X/ |- e" w% U7 L! s BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'0 O, |6 C' ^* {
7 k1 K( A% ~1 u
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
# F% J7 s" d7 o6 U+ \# j+ Afunction to do the same job:
+ Z7 z9 o( M( i( J
$ d* L- |$ q5 I# E0 h/ y& y push 00 ; OF_READ
" }# \% z# Z3 Q! n9 B0 N4 [ mov eax,[00656634] ; '\\.\SICE',0$ H4 f2 g. g% ]8 T, X9 r3 Y/ S
push eax
1 ?1 I+ C1 @, G5 Q5 I call KERNEL32!_lopen9 H& A5 v: L2 Z0 a. j3 K' x( d0 U
inc eax0 x* f' j' P. X+ i4 Q$ p0 f
jnz 00650589 ; detected
) _1 W7 I w7 Q8 b push 00 ; OF_READ4 n% z% e; v5 P* R, ^
mov eax,[00656638] ; '\\.\SICE'$ u/ u( c4 e" D( o
push eax
( q7 w0 p% ?; v call KERNEL32!_lopen
l5 V0 [+ l3 n3 n0 L& L inc eax7 v( Y- f- i# S" k+ D
jz 006505ae ; not detected
+ r! a/ d- F* f6 R
]5 O. i/ c, y' ?# k
1 h8 z. v3 i) e6 R: K2 |3 i__________________________________________________________________________' Z/ m5 Y7 ~' [8 G0 s
8 d! o6 n, o. S
Method 12
+ z6 _6 a1 ]5 W g5 K# K=========
/ h7 Y+ a7 C) o4 N; |( u1 @
4 U! f, n/ t5 e! K7 jThis trick is similar to int41h/4fh Debugger installation check (code 05
& C7 z' v2 ]% Q2 X3 D4 ?/ Z& 06) but very limited because it's only available for Win95/98 (not NT)
- n6 C, v* |/ i" c1 pas it uses the VxDCall backdoor. This detection was found in Bleem Demo.4 N# U! E! V4 E) k% y" [
E4 j$ P8 { R5 B' c* U0 h4 q) M* y6 Q
push 0000004fh ; function 4fh) Q5 |& |) S2 v: {& k5 d, M0 G
push 002a002ah ; high word specifies which VxD (VWIN32), Z. g) e- W% M" f6 d1 ^9 G1 g0 K
; low word specifies which service
3 ]3 u @/ {. l* b4 f (VWIN32_Int41Dispatch)
2 N& |' F- H- y) |% G# A4 M/ z call Kernel32!ORD_001 ; VxdCall+ ? z4 F6 o9 E
cmp ax, 0f386h ; magic number returned by system debuggers
, s: K3 f% b' Z8 n: [+ p jz SoftICE_detected
0 a8 E+ s6 Y& h; n" ~0 E+ W- r. p0 f" h5 C; O: f
Here again, several ways to detect it: w. E% k |3 r' K, F, R
, D: I& Y& R2 D! f. G, F0 g ]5 r BPINT 41 if ax==4f
: ` [5 S, J4 |9 @6 c& ]0 U7 O6 E- z* c8 F2 M' }( m6 f0 H
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one2 w5 _! Q' _% \3 I
: D Z9 j/ J3 e' h
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
4 ^+ i: C2 p5 ^+ o7 X( E& X
9 V+ @* u. M( B8 M# \ BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!; @* ~+ G* P5 r5 t' S) U$ u
$ e8 a; z& @" ^& i$ q
__________________________________________________________________________
1 \+ u% q3 Y5 e% ^+ j: m) G, M4 ^ q7 v9 b7 W+ w- s
Method 13
% S" s# L3 Y+ x: I2 u=========- o0 z0 R: C: C2 r( p4 G
8 M: C$ B0 Z4 r8 W# U: A0 a4 O! D9 x6 M; dNot a real method of detection, but a good way to know if SoftICE is! P/ e& b; d3 C5 p
installed on a computer and to locate its installation directory. O. K% Q9 h' P" O2 Z
It is used by few softs which access the following registry keys (usually #2) :
+ t6 t# s) }1 E" P4 i l6 t$ H* {" p2 f% s
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
( w2 m4 D6 U) Q8 M e2 p\Uninstall\SoftICE
9 Q, x7 B/ \ C) S; d/ u-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
1 w& G9 o3 {/ v" C5 {& q" R-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
! w( Q+ C5 H7 U- R\App Paths\Loader32.Exe8 M& L( ~& j0 _2 _6 d
3 a9 Y9 p3 @( X- W9 h, W# N B& o+ L( m3 ]$ r
Note that some nasty apps could then erase all files from SoftICE directory
) Q. y3 p6 M5 v' s(I faced that once :-(
7 L+ I" ]* Y" ?; b' \4 d/ b3 T, m6 ^, i' h
Useful breakpoint to detect it:
3 H( J; U" D3 Y: A2 z, R0 h6 S/ R0 L8 x$ f
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'1 K# b- f9 w5 z2 o
: U G* R( n( W8 u W3 Q$ e5 J2 r
__________________________________________________________________________
1 x i: r5 P3 L% y# a- Z7 |" L. D; A
. ?; G6 ~" \0 f2 ^
Method 14
$ a' }6 J) h( X. I=========, t2 e0 J: G! D# U6 T1 Q
$ @" l+ g: |, e5 tA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose9 j% n& M- i, x8 l1 w& ^
is to determines whether a debugger is running on your system (ring0 only).9 r1 {5 m, l! m
: p( y+ ^( N U% E VMMCall Test_Debug_Installed
! e" U* n; T4 T. u& D) h je not_installed2 B8 E6 X& u! a6 ^6 Z* V- E5 E
) q3 o$ L% W& d6 N0 b; F, lThis service just checks a flag.1 T/ t/ Z) W) C, Z$ c2 I# K& _3 q# T
</PRE></TD></TR></TBODY></TABLE> |