<TABLE width=500>
( v* z! K \% \! Q# f% Q% e<TBODY>5 H# X/ d1 }. A8 q* ]7 J* j' s
<TR>' _+ u& D. L+ ^: U
<TD><PRE>Method 01 # {7 m1 F' Z: n/ O/ Q5 c
=========2 |% h( j+ q6 z$ c
4 }/ v: U( [/ e$ H) w$ S* ]
This method of detection of SoftICE (as well as the following one) is
) d* r% I* B/ k! eused by the majority of packers/encryptors found on Internet.
6 d! o8 J y: {It seeks the signature of BoundsChecker in SoftICE. U6 ]9 x! \- A2 q6 @
8 u* t _( ^3 V( k
mov ebp, 04243484Bh ; 'BCHK'
4 ?. O4 o4 H3 C3 Y mov ax, 04h; i) X L4 U8 i; d5 x( [; N
int 3 1 f/ T k$ e# v: [( m, l' _& M0 i- W
cmp al,4: }- W0 o1 x' ]
jnz SoftICE_Detected% ^& J8 a& s8 `* X: \ X
+ `$ d, C3 J; T" g- l! D
___________________________________________________________________________& S% x* t/ v1 x1 w; G; o8 B
% j/ o* |# O" C; e% x. B
Method 02& N- j5 ~/ C6 ^
=========& P2 r3 S4 a- X$ k$ p. |9 E% D
5 E7 A9 q* y" H+ Q7 XStill a method very much used (perhaps the most frequent one). It is used
. ^9 [0 Q# k& b4 h! Oto get SoftICE 'Back Door commands' which gives infos on Breakpoints,& N0 ^2 Q6 [/ c% B
or execute SoftICE commands...) F# @ A' g; Q! `6 K9 }5 ^
It is also used to crash SoftICE and to force it to execute any commands
7 s' w( U3 G7 r$ l; z(HBOOT...) :-((
% j: v% |; d8 z
$ A+ M1 h8 v! tHere is a quick description:
, c8 q- @ E B) M) q' d+ K9 I' u-AX = 0910h (Display string in SIce windows)
7 f& `& H7 R1 s: M4 l+ T5 g& I-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
' c* n9 r6 ^- m7 f4 W: L W6 r-AX = 0912h (Get breakpoint infos)5 z- \- j& A. i, i# k
-AX = 0913h (Set Sice breakpoints)
$ |4 ~! M, C! d% w' |-AX = 0914h (Remove SIce breakoints)) U/ \) b- P( J
; \9 x, T4 @* @$ f: T3 _. v( d
Each time you'll meet this trick, you'll see:
. T, r/ K* K. a3 X-SI = 4647h
$ j( i% M- f# T; ?6 l5 l7 k-DI = 4A4Dh5 s+ h( W' f" t& S# `' m1 m5 x* `0 w
Which are the 'magic values' used by SoftIce.
" c% J6 d$ {! U. y5 u _For more informations, see "Ralf Brown Interrupt list" chapter int 03h.7 O$ m& e2 @8 @# G# i7 n
6 I4 }- V% p1 g9 d: v
Here is one example from the file "Haspinst.exe" which is the dongle HASP# n R( [: W6 E p# b
Envelope utility use to protect DOS applications:
' ~& j0 l1 }% H; m2 L; ?9 Q& J$ A& s3 D+ y0 M; u1 H" F
! f- V, f d5 K2 j* \9 x
4C19:0095 MOV AX,0911 ; execute command.2 ^/ [0 j# J2 t- X
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
1 w2 D/ z% y6 Q4C19:009A MOV SI,4647 ; 1st magic value.; g- u3 `7 Y. ~3 b2 R
4C19:009D MOV DI,4A4D ; 2nd magic value.
5 N0 Y* | k" j. I2 Y- Y4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
0 G. p; ?. R4 U5 L4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
9 t8 W+ D* @/ R4C19:00A4 INC CX. m# O" N4 x3 X' I
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute3 p0 a4 b% y2 v5 s6 N" w9 w
4C19:00A8 JB 0095 ; 6 different commands.
8 ?' }% I1 R4 M" M6 e4C19:00AA JMP 0002 ; Bad_Guy jmp back.
- B3 }) h8 Z: Q( t4C19:00AD MOV BX,SP ; Good_Guy go ahead :)1 u! I2 H! f, y- w
/ m, L5 Y( l3 y1 D8 ]& J
The program will execute 6 different SIce commands located at ds:dx, which
7 H0 w/ L$ q5 F8 Qare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
& G% l: g% R9 C/ H1 M4 L9 e- ?9 K" ?( Y- w
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
$ U! ]0 J- H, G5 B___________________________________________________________________________( _8 s' k" ]6 g" T$ V/ ^
7 R+ ~& d, b$ K6 Y8 \% q
, `2 {+ W3 \5 c8 [% i! [3 UMethod 03% G% f1 L6 q6 M8 w6 u. m
=========
! e2 O+ P+ M2 e) I( y4 a) Y) C: t; d( k# l. X- c; B! d
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
; U0 M9 d9 [* @2 ?' R(API Get entry point)+ T% O! R$ w+ ]8 O; b' }
( F& t- K6 ?4 {# ^2 |) L' a6 ]% D, N3 R f- I# b* m% ?
xor di,di! n: N/ T3 j9 ?7 G& j* ]
mov es,di
2 X$ ]0 r; c+ e9 p. ~) V; M4 E2 M3 x mov ax, 1684h 0 Y8 D* h6 d3 ?# K
mov bx, 0202h ; VxD ID of winice
( s- O, f7 R, s" K* s! H: p int 2Fh' w, K, o: y: W' d) H% W
mov ax, es ; ES:DI -> VxD API entry point
6 g5 B" y) |" x$ t1 e! @& M add ax, di
2 k7 H/ u3 I# I6 C, Q4 F. w test ax,ax* X# d6 p# {6 U$ l+ q8 w g! u$ `- ?3 S
jnz SoftICE_Detected
' r$ H9 F Q7 E; t. l" z4 F
: |( _' k2 o( H. V& B9 z___________________________________________________________________________
Y8 P4 G( N4 j& M$ l2 e7 c5 B. q( o; p J; d" M
Method 04: O+ }+ N; R8 `4 P
=========
: s3 Z1 Z# r) H+ ?! I K7 N7 A- g& ~; ~/ \
Method identical to the preceding one except that it seeks the ID of SoftICE
" {; m: D' I; [2 AGFX VxD.
7 r$ f4 B: c) V5 |( I; X' w3 {# v7 z- L% l# m- n) D/ a
xor di,di% r1 Z/ h0 { o* ^' f; m& ^0 F0 S5 @
mov es,di
/ ~+ ]: v5 j! D& Q1 u' x7 E mov ax, 1684h
3 G0 M; d+ E2 ~; c* U( a mov bx, 7a5Fh ; VxD ID of SIWVID; I0 ?/ @! V! E! u! b6 g2 {8 V
int 2fh
* Z K6 d& f' C; r, n# n: e mov ax, es ; ES:DI -> VxD API entry point1 F8 H4 Q5 L, U7 B ]* W
add ax, di l; |' Q# [6 I0 M8 [5 Y" q. ?
test ax,ax
, J7 ~! {4 G0 W% C2 A* g jnz SoftICE_Detected8 u; L; Q( u6 m& }
2 A0 p9 w2 ` E, X
__________________________________________________________________________
, | t, \) o* {" T& k7 t- S2 p+ Z( ~9 ^3 H6 i% r' R
' d. j& G* D0 E, fMethod 050 F Z' o. O$ g6 _ J; `+ v
=========
1 S/ K2 | G5 C, f2 T0 b( x* R' ^- S) w( q# n4 u ^ \' V
Method seeking the 'magic number' 0F386h returned (in ax) by all system
6 m/ k" u8 i. e. jdebugger. It calls the int 41h, function 4Fh.0 O0 p, l, j* B! @% K
There are several alternatives.
9 S4 Q0 P& Y5 Z O0 p& g1 i3 \# l2 S9 l, U+ I4 H. C8 U" E8 P
The following one is the simplest:
6 V, F d" l: E" \' u9 F( X- F) y$ e5 _6 u! R& x k8 |
mov ax,4fh
3 i% ?9 l( e9 Z# J. ]+ ` int 41h
1 @0 C; m+ [% G+ F7 o6 t$ o cmp ax, 0F3867 u( p \6 n2 w/ s# m; B6 O
jz SoftICE_detected
8 U* t( Q5 a4 u9 K6 r% R6 B; E/ r; |; p
$ P D% T+ T+ f, P* \/ fNext method as well as the following one are 2 examples from Stone's ; u1 m$ v* \# a* Q6 l" m- z$ m$ q9 E9 f8 h
"stn-wid.zip" (www.cracking.net):* \0 J6 R6 w H H( M; j
3 G( H8 h2 T2 e+ y' U$ O; s, x mov bx, cs
- i* n1 H( j- N% f( f( c6 n) d L lea dx, int41handler2
' a; L1 P. `7 F9 Y( d+ ?0 J4 A xchg dx, es:[41h*4]
! O0 K6 B" U2 z3 D xchg bx, es:[41h*4+2]3 R4 o& a6 |. y
mov ax,4fh
" @! W8 f5 w6 ]$ d! s! b; Q int 41h
9 n: @5 N; b9 g3 X' t5 d0 P, ] xchg dx, es:[41h*4]
/ t/ i5 C1 w/ ` xchg bx, es:[41h*4+2]
1 w4 s% T# t' h3 h# r0 i cmp ax, 0f386h
! p' ~7 R7 {" O3 ^( g jz SoftICE_detected
3 x3 B6 v/ |; G8 o4 i# C B: P# D6 m: q7 i* W$ t3 N( G
int41handler2 PROC2 w* f) H, k- X( b+ b9 ?
iret
" n: S W' Y" p* f+ U; d) ?int41handler2 ENDP3 y( d3 N/ Y; ^9 E
% P4 Z# q9 h* K+ ~, Y- C0 ^
8 x- U( n" j% D9 w! z. }_________________________________________________________________________8 K, d! I+ i4 O* r
- j+ `1 A# h7 F1 Z5 M; l
^3 U0 L- h' q# A" U- _9 \Method 06
& g- g3 V3 c; T8 H6 L=========5 D# F9 o5 r( q1 w4 O+ ?
2 l* z8 C4 J/ B) V
- l7 P( q+ I8 l; Z
2nd method similar to the preceding one but more difficult to detect:
0 f9 R3 d, U& G& `: z- m4 [2 T. a3 q r, L2 y$ D. v4 ?
0 u! V9 c1 O/ E/ U" B8 K
int41handler PROC
6 [( j2 v4 }- c& t0 I9 r, u mov cl,al
% ~' ~% W& P; R3 V, F! _! \ iret
5 s& m; J O5 }) Z0 {6 A$ Tint41handler ENDP) X- C! T% W% e1 P2 l6 k& b$ O" Z
/ W- ~( U$ F E5 }+ Q) ]# _; Z0 Y1 u2 W, X( q8 D5 |& G! ~+ m# {
xor ax,ax, V1 W2 B) P' E. \
mov es,ax
_9 X8 g: Q' Q( ?- k mov bx, cs" g- E( b q0 m- w( T
lea dx, int41handler
) J* H0 M" y- F xchg dx, es:[41h*4]/ x: E3 s" f" Z& \+ o# Y$ B( x
xchg bx, es:[41h*4+2]
0 i8 N: V* T; O1 K in al, 40h7 p. i; R g; p$ ]" Y$ ~
xor cx,cx1 Q4 x- [9 {/ s* A: B
int 41h
1 u) s' {4 O6 n xchg dx, es:[41h*4]
" x% ?9 ~5 \0 m& x4 _- ? xchg bx, es:[41h*4+2]3 g9 S* x$ O6 z; r
cmp cl,al
1 P: q% b0 H! Q+ }5 h jnz SoftICE_detected
4 k# h" |2 q) g' l3 w3 N
5 M7 f9 s) }& x `5 `_________________________________________________________________________
. V& V7 k; s/ ?9 N
+ q( l) S) t3 i/ R6 aMethod 07/ S1 }0 u: `, R2 N8 m0 a2 d& s' m( b
=========' v: w( m4 X) J# f; k5 |
, g4 G1 }5 n; G! h
Method of detection of the WinICE handler in the int68h (V86)
2 [+ o. d3 @ Q( Q' |( B% ]/ a, L- D
mov ah,43h
- C3 [% o5 j: I- L+ D5 S int 68h/ L' ~, I0 M# s) {9 R) b
cmp ax,0F386h
3 v' L# g2 D& p, Z" {) h/ r jz SoftICE_Detected
( W9 C4 }8 [! t; B. ]
0 {( q$ T9 F/ w! z2 A$ [: j# g9 j5 ?; `& B
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit8 L% q5 {7 ?8 T& v6 |" ?" Z3 N
app like this:: A9 j5 N' j* Y
7 Q1 ]8 c# p9 v2 H& u BPX exec_int if ax==68
# L8 ]. n% L) f. i+ P3 [ (function called is located at byte ptr [ebp+1Dh] and client eip is
- T S" r( o3 r }) N located at [ebp+48h] for 32Bit apps)7 e5 X3 K4 K8 N5 ~
__________________________________________________________________________ r5 V+ d: a( T, S
( n# b0 f5 A2 ^6 W z4 `; n
8 `( E7 p: I F/ g3 v* sMethod 08* R; A0 z; W) G [8 v: t
=========
) D2 o+ g5 ~( o" P5 K% R
) ~: n$ S5 `$ zIt is not a method of detection of SoftICE but a possibility to crash the* _7 v3 _4 } j q) G# k! } Z
system by intercepting int 01h and int 03h and redirecting them to another
/ u7 J! Y' c V4 p7 J5 mroutine.
/ A- X; \5 K2 l; `# hIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points/ r1 i. f) M5 ~: ?( q g
to the new routine to execute (hangs computer...)
8 { J) V( y& }) r f3 |
" y$ K6 @& C5 {/ T mov ah, 25h
3 [& u- x* r- V8 m7 P5 z6 v mov al, Int_Number (01h or 03h)
4 B% r4 m2 E) @# u2 X' S0 G mov dx, offset New_Int_Routine$ U. o! N' w2 c5 W ~4 y s1 s
int 21h
' N0 {" ^4 \' I' @# o% ?* k+ C5 i
__________________________________________________________________________+ s" [9 }9 |' {3 O9 Y8 b/ A& Y
& @' a! s1 w6 g* i1 gMethod 095 l5 F) i% y/ m8 m, O& E
=========6 j! i! D# @6 u
9 ]" O+ y5 M% A" g0 C2 @, dThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only: W8 e9 [( l* j4 ]! u5 h
performed in ring0 (VxD or a ring3 app using the VxdCall).
8 t( j& c( G2 P# {$ DThe Get_DDB service is used to determine whether or not a VxD is installed8 S* n8 u/ @+ \2 y# G! p: B7 w) d
for the specified device and returns a Device Description Block (in ecx) for
+ [' c# q4 Q5 N6 f6 gthat device if it is installed.
$ q7 L1 M; I$ E3 F) _
, ?/ d8 ?( Y. b2 d8 T5 k6 {: X mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
+ {- C3 V1 l, |" d, }- I4 E mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
; {# R _, B) p4 T; }7 k/ B) Y$ R8 C# |: k6 | VMMCall Get_DDB }# M; b2 u' [) `
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed; Y, l4 q$ P0 h) S& j6 [- F
8 } B/ g, b, q% S7 f; i8 f! F( cNote as well that you can easily detect this method with SoftICE:
/ J, l) \. U& D bpx Get_DDB if ax==0202 || ax==7a5fh
: G# w r+ B/ L. C! V' ^" T6 O" @
7 s& v, x+ n }. L+ C {__________________________________________________________________________1 T2 n: f K* Z7 n6 F2 I: }6 P- d
- v/ }: v6 X/ A
Method 10+ N& J% ^# q w& l
=========
% L8 H5 b# S; `' z% w* o
5 B' [# W, O* ?3 p) D=>Disable or clear breakpoints before using this feature. DO NOT trace with; L3 I' k/ J2 k6 D
SoftICE while the option is enable!!/ z- S, Y# C! x/ p9 ^
- P0 l; p" z" d7 X1 P, VThis trick is very efficient:
8 P2 z# L3 a: l, ^$ E3 J$ Sby checking the Debug Registers, you can detect if SoftICE is loaded
# Z' ~& Z7 }/ }6 N& v& A9 d" S3 q(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
3 c; d! C; _4 J f( \7 Othere are some memory breakpoints set (dr0 to dr3) simply by reading their e5 F+ j0 }2 b0 \; a) ?+ b5 _ q
value (in ring0 only). Values can be manipulated and or changed as well
. \' L/ D4 w+ J7 o1 C! v(clearing BPMs for instance). f3 D! H2 E- {! z/ T! ]9 J
0 f5 l9 w; J" ?5 W
__________________________________________________________________________* M) A# F8 s4 u m; m* O
2 {# v) j- `: r
Method 11# w" X7 @5 k" t! Z2 u
=========
! ]/ ?( X0 s7 o, C( p. Q/ O; `1 {) i8 l3 Q# T* x: F
This method is most known as 'MeltICE' because it has been freely distributed
4 r) l/ B/ n# t6 ]+ Cvia www.winfiles.com. However it was first used by NuMega people to allow
" ^3 D9 A+ \2 k4 k( W- _Symbol Loader to check if SoftICE was active or not (the code is located% N% O) e! |7 X+ I7 [6 @" Y1 C+ s
inside nmtrans.dll).1 K8 J6 F) s' ]% Q& B
+ b! g) m8 S) |# V% c$ e
The way it works is very simple:
# t, Y# O4 ^- S. k4 L5 V: pIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for$ V3 O/ ?& m9 a# L2 y% C7 m
WinNT) with the CreateFileA API.
" j& S$ K( h1 K; n
, `: m- V* k! |5 K0 A" O0 F; dHere is a sample (checking for 'SICE'):
7 C# m- H/ ]7 O, }7 ]) q) w& w
BOOL IsSoftIce95Loaded()% p8 K j$ }$ V; t
{
, D/ B$ G# f4 y* E% H E$ u V HANDLE hFile; ) M' N( C n, e( u; F5 E
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
) X3 ]0 m* E; d& u9 A8 f: a. B FILE_SHARE_READ | FILE_SHARE_WRITE,
% l4 _2 T& i2 @9 \& [ NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);) X' U( r+ K1 y* ^
if( hFile != INVALID_HANDLE_VALUE )# {' B) l: v5 M3 y% ~! e
{! [' b1 \6 I; C% ~# ]
CloseHandle(hFile);
* M. m2 K! X9 Y( d return TRUE;
/ F& G& w4 [% |; _1 O2 | }7 e c4 t, w B% _
return FALSE;
/ O! _7 t, }4 V& l/ U} f* c9 u) {% p/ P$ a& [
7 N3 r, d3 u! J2 o5 E, e# L
Although this trick calls the CreateFileA function, don't even expect to be6 w4 M, Z' b) D* k0 G( K3 ?
able to intercept it by installing a IFS hook: it will not work, no way!
8 j% \) Z8 X2 I2 [' hIn fact, after the call to CreateFileA it will get through VWIN32 0x001F! ^5 u7 O8 z( p% N5 A& `
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
+ V: M% M' j7 n, K; x- e; Q" f, aand then browse the DDB list until it find the VxD and its DDB_Control_Proc
. C; Y9 o ?8 a! V+ l3 V( |field.
+ k- U# U- d3 [5 YIn fact, its purpose is not to load/unload VxDs but only to send a 1 p* g/ p$ `; H( R$ g, T
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
/ m7 s( Q5 a5 |$ Wto the VxD Control_Dispatch proc (how the hell a shareware soft could try; l8 \* C& r+ T% Z. ?
to load/unload a non-dynamically loadable driver such as SoftICE ;-).8 ?. ]6 Q! D( d# j1 \# S' ~
If the VxD is loaded, it will always clear eax and the Carry flag to allow6 @! \2 P K+ W4 m
its handle to be opened and then, will be detected.
+ V2 ^) A$ w d: W* iYou can check that simply by hooking Winice.exe control proc entry point
/ ?% t; n; N$ q/ e/ [3 Owhile running MeltICE.
9 w' y$ h* Z1 D- s/ G3 _6 V* m: Z
1 w T2 K- ?/ o; z) p; Q) d [& {2 k; s" P Y3 u& q2 ~$ ~
00401067: push 00402025 ; \\.\SICE
, Q: _& @) h1 R8 V; L `; Q. i 0040106C: call CreateFileA% ?( F# R2 ~+ y- G. {2 Y. W5 _+ ?) `
00401071: cmp eax,-001, p& D9 N5 o4 f
00401074: je 00401091$ ~8 @( S3 D/ ~: F. `- J9 ~! R
+ w: o8 }" g0 o$ `' D8 \3 ~
0 Z( @+ L. U( L3 c8 k+ _; \There could be hundreds of BPX you could use to detect this trick.. F6 b1 Y0 V' G' B
-The most classical one is:) b1 \$ b) B1 H
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||& W( V* n* t& `. T, e
*(esp->4+4)=='NTIC'$ c2 L( T. S" |* @; Q6 J8 r
0 w, {- k+ u8 Y$ [; d! |) S% D-The most exotic ones (could be very slooooow :-(1 x: R' o2 `5 [% r
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') ( l4 o8 f- o8 u8 z
;will break 3 times :-(
& ~7 P$ ~' p; [. y; C( A
2 G5 U0 P. Q3 T3 o' Q7 m; N8 G D' s: ?-or (a bit) faster: + G+ U" J7 T h
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
+ Y O7 \" s8 M; q8 j
+ \; y: B) k& k/ W1 N BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' : F' b9 @5 E- l$ o2 C7 l9 {
;will break 3 times :-(2 l6 C5 h3 [; B" U1 w
& E" k+ R7 D' P5 C, w2 O9 u: D-Much faster:
. P- `( \) K3 E; ` BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'5 k9 e( M7 q P% I
$ f% {% b5 @) W6 b5 e
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
7 }7 n; `! M. z* p8 Gfunction to do the same job:
% i: y' `, F/ b: n% Q P% P! m- y e" k: h
push 00 ; OF_READ
' i, L: ]+ X& @9 H1 o, j* Q. H mov eax,[00656634] ; '\\.\SICE',0
6 D v c' h% o# Q( r" I push eax
2 u+ y! G4 u& |) O7 | call KERNEL32!_lopen
( u. v; L& B( z+ c# Q inc eax
8 `: i% F: E, A) w8 T3 j4 P7 Y jnz 00650589 ; detected
" j; M, g8 _ Z x) z push 00 ; OF_READ
; w5 Z4 d; U$ p0 o ^5 S* K/ R0 P mov eax,[00656638] ; '\\.\SICE'
2 g4 b n4 j0 u push eax
1 {2 |9 y, D& {1 \2 ~& ^. q- ^% g1 S2 M" W call KERNEL32!_lopen
0 a4 M. c( `5 B" M0 k7 z/ x inc eax% t; q6 }3 e* w" R; N0 v
jz 006505ae ; not detected( i4 a# [4 d H/ V
3 H4 n' |' s, G% p5 d
- I# k/ V. C( h4 H$ E
__________________________________________________________________________
6 q( s8 F9 r3 z* ^! F, a% p- p& e9 m
Method 12
% _& F% y+ |6 E; K" U=========! @ e6 S, T: I; \
% h$ D$ l3 a; b2 c+ CThis trick is similar to int41h/4fh Debugger installation check (code 05) e- `6 F3 c4 N/ X' |2 w" v
& 06) but very limited because it's only available for Win95/98 (not NT)0 C, p% C+ `: D) `: ?
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
/ P7 p! D. a; N7 @. y* m" O" k- c5 E2 o" F F; g, O
push 0000004fh ; function 4fh
' w/ G. R6 x- ^! j7 x$ h push 002a002ah ; high word specifies which VxD (VWIN32)5 ]$ }# r0 a5 B. r% T- j+ W
; low word specifies which service% W0 y8 t6 R7 ]2 Z+ \4 H
(VWIN32_Int41Dispatch)
3 ?$ x% E* a4 ]1 n call Kernel32!ORD_001 ; VxdCall
, l( L; W( @2 }$ V# m- } cmp ax, 0f386h ; magic number returned by system debuggers1 L* |) @' g5 n) }' G4 |
jz SoftICE_detected8 S S" C% t- J' A0 ~, `& A
! W( b9 B9 G _8 }Here again, several ways to detect it:
, z8 d$ [. }8 W& I. q
( {6 m$ Q. I# ]! Q BPINT 41 if ax==4f
. g1 o6 v; k) ^: Z6 }1 S, h$ _. ]5 `8 u' [5 _, B( @. `
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one% V" v9 |( M# Y) S; c
/ W! v5 c, _2 n2 P
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A5 H4 _/ u3 u9 `6 ]5 S/ E
! C4 u5 v5 j3 g# i* }# z
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!$ p+ H8 w' c! e
" a( m% s; ^3 L4 A6 l" b" `. s__________________________________________________________________________
, H: e' Y9 ]/ n: o- r$ Z/ o, X2 Z4 Q# N; i* V
Method 13
$ ^$ l* A. n1 A. a) x: D0 k1 [9 J=========7 Y3 o& t' k3 ^2 P) N5 k2 l
k4 F3 u2 v; H" \$ C; r6 I1 x! y+ z1 oNot a real method of detection, but a good way to know if SoftICE is( Y( R9 M- b/ e# b* a5 t
installed on a computer and to locate its installation directory.* B i# l* y" |$ S0 p. a! b
It is used by few softs which access the following registry keys (usually #2) :) K+ r/ u$ m2 {- F
: y- q4 G* d2 z+ J. a' U" U
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
# d. P3 H2 I( \/ O2 Q* Z\Uninstall\SoftICE
7 V: {, s# a+ M6 L* _1 w* e-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE, r) @% S! l2 U) ]- J4 w: e
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
' Y- N/ [! _% L0 q! d& l% d: g\App Paths\Loader32.Exe
" F" A% l, b9 ]% ~: ^- M. {" A' ~+ f5 h# E
) a% w7 |" R- f0 `! n0 cNote that some nasty apps could then erase all files from SoftICE directory
0 o' [/ p# h1 E: L8 t(I faced that once :-(
) q% ^/ {, I @( b& [
2 x! [8 U7 a4 {; A3 M/ [' xUseful breakpoint to detect it:
$ M: v4 ~1 S8 d- a& I" s
) c3 z/ Y2 k' R( k' s$ p8 e BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'6 d4 q* |3 h+ a# p) R. x
5 v0 U _) D* |2 W
__________________________________________________________________________% O2 h9 U: \1 I' I+ b5 A* @
8 W( _. {" _1 J" Q6 N$ f1 p* d
. v: z+ }3 `: |& X6 u( GMethod 14 6 {/ q P9 T+ E8 v1 m
=========
/ T* l' [. i2 P/ I2 x6 [) i8 r! ]; D P) l1 i' k
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose3 K" u- C l8 ]) s* Z2 L0 v
is to determines whether a debugger is running on your system (ring0 only)./ r% \& n7 F. \5 O5 {
( a+ l7 I, |$ Q5 j7 H! r VMMCall Test_Debug_Installed$ M, ]: M( B% W; s
je not_installed
7 ?, Q: B9 A0 E
( |3 {6 H7 o" lThis service just checks a flag.
: I$ Y2 ~, {3 A) D</PRE></TD></TR></TBODY></TABLE> |