<TABLE width=500>. F% h: l' A. P6 l; b- q
<TBODY>
( u, C3 F1 B$ ?' N5 b<TR>& z2 Y$ n' X6 \ y7 k p6 N
<TD><PRE>Method 01 " Z* Z% I2 x( l) ?( ~9 {
=========( l+ Q) w: T" Y( Y% T
b3 s1 g9 A9 A" u$ yThis method of detection of SoftICE (as well as the following one) is
$ H: b' P, e9 q. @% j4 w# e) Rused by the majority of packers/encryptors found on Internet., m6 U; c. f$ b/ t+ U5 u' m
It seeks the signature of BoundsChecker in SoftICE
6 E# i+ i4 f$ ~6 [/ `
! t3 M/ J8 N9 i/ x mov ebp, 04243484Bh ; 'BCHK'
0 U2 D6 E; F8 M mov ax, 04h- b- y( i- M# }
int 3 9 Z: b" ~7 a+ }7 ` ^' k
cmp al,4
7 G9 B9 s+ V* Q8 u jnz SoftICE_Detected
- ^& t1 @# u4 m2 w+ h0 H- I5 R
* A: w6 I; ~6 D3 g% X5 s0 _' |___________________________________________________________________________ ]( |1 T) l; `' t. ~, ]) ]7 y/ U( ~
?/ n: h" ~9 Z* [! gMethod 02 u# [* B1 I+ Q i/ O# l3 d
=========
9 ]. u5 R! [# v- Y; s) z4 `$ [: g! L* R: Y
Still a method very much used (perhaps the most frequent one). It is used; w+ O7 I# T! T* v3 U& p
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,( Z" v/ a% p/ N% u
or execute SoftICE commands...
+ v+ [7 Z/ ]$ V8 ^" k/ M8 zIt is also used to crash SoftICE and to force it to execute any commands
2 l/ l1 d" ?# R(HBOOT...) :-(( 8 I+ T* L* o9 E* r/ ?& l
1 w0 G f1 s% Y) N1 }0 Z* GHere is a quick description:
" N5 N( D; i' z6 S, E-AX = 0910h (Display string in SIce windows)
0 N) `5 @9 j0 [+ e-AX = 0911h (Execute SIce commands -command is displayed is ds:dx); l3 G7 i5 I: B' J
-AX = 0912h (Get breakpoint infos)
# z x! |# z+ p-AX = 0913h (Set Sice breakpoints)
8 w( l+ a8 e8 `4 {# B4 Z( l-AX = 0914h (Remove SIce breakoints)- c0 m. l1 ^/ o& F' `
$ k3 t. p4 ~$ J& w8 j$ Y3 yEach time you'll meet this trick, you'll see:
' M/ \8 S6 a/ `) i* I E' i-SI = 4647h
. {1 E3 g1 ^; t$ r$ H! i% v-DI = 4A4Dh
/ S9 s/ [5 u/ P ^0 V$ SWhich are the 'magic values' used by SoftIce., X$ U* U# M i3 x0 X8 b
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
7 X/ |* i4 j6 j3 S; L& G y% S& m+ H; z1 [! ~: W$ s
Here is one example from the file "Haspinst.exe" which is the dongle HASP
5 P7 e3 q8 x4 ?; U2 Z/ c' vEnvelope utility use to protect DOS applications:
# b' ~! F1 Y! i6 G* n+ x; z4 {' s1 A) x' N" w* w
G7 t" O/ K+ _
4C19:0095 MOV AX,0911 ; execute command.
" a# _# C2 }6 O. E0 W; ^0 l4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).8 m* F y# H( I# V5 e$ \7 T
4C19:009A MOV SI,4647 ; 1st magic value.' T5 V& G; {; f
4C19:009D MOV DI,4A4D ; 2nd magic value., Z B7 ~9 s1 v# ~
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)" g3 z! h& D4 B3 ` T7 C8 d
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute7 [! ?7 z7 y, h
4C19:00A4 INC CX5 v6 R! N' p5 p
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute* i" o' G' @! s2 k- E; B
4C19:00A8 JB 0095 ; 6 different commands./ @( G5 S; F3 V% F
4C19:00AA JMP 0002 ; Bad_Guy jmp back.( M: B' V) x1 e9 r! J1 T
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
6 g ~3 s+ g: {$ a3 d% g" f
5 @" n7 x; l' `4 W" i5 vThe program will execute 6 different SIce commands located at ds:dx, which
; L8 [1 y! z9 |$ K6 ~are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.* k0 i! h$ e8 N5 P4 R: r
% j7 T8 V0 H5 f( {5 q+ e2 P% g
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.( F$ u: a4 }$ P$ \/ D
___________________________________________________________________________
* {4 Q" i- l c# O- y
0 J u: M0 _4 _, D7 s; f; t
) V$ r9 f- b, c- J- E! V! ~Method 03* j. q! h' I) r. u3 \) h
=========
1 y! N: A: y B& x+ h
4 ?6 f9 g$ b/ m% j+ p: \& S9 j+ |Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
' K: z" r# _* _. E I3 b(API Get entry point)" c! D* X* t& }9 b) O7 ~/ q
5 t( Y& @! p* F8 g; S
& v, W X( ?( i. J! B' Z xor di,di
( ^% {2 x! s5 h7 I ~ mov es,di
* U8 ]* P( p7 `9 J: h2 h mov ax, 1684h
" f9 s: ^7 d. q1 V( M9 p% T j2 w+ S mov bx, 0202h ; VxD ID of winice
( h+ u# i* D- _2 k$ J" u+ ^- u$ r int 2Fh" [' @. K; ?8 _6 y: ~% O
mov ax, es ; ES:DI -> VxD API entry point& ]! X5 E' d. o9 ?+ \
add ax, di' @5 B! S$ y! O) Q3 @6 Z/ [3 `
test ax,ax+ k6 ]& Q8 F& X2 U
jnz SoftICE_Detected( U& k9 E4 h5 m$ ]
# K M5 D8 v$ l- q3 Q9 q
___________________________________________________________________________
, {4 x& X- W: F0 X! i# x5 {2 l: F$ e4 R+ D
Method 04) X' C: F( K; t0 v1 W7 e$ ~+ W# @
=========
; z) S! ^ T' b$ f
! T! M9 T0 c5 n8 rMethod identical to the preceding one except that it seeks the ID of SoftICE% J8 R& Y$ ]0 l# `; c" G2 P
GFX VxD.
7 y; e, c9 L# d, d; M) d7 U1 w; U& K( w3 D3 Z, V6 P
xor di,di
! o+ V& P; M V' @ mov es,di8 D: e* U" w& j- G: k
mov ax, 1684h 7 i8 a- ^! ~" Q' }0 v3 ]" n
mov bx, 7a5Fh ; VxD ID of SIWVID
) H9 _7 O2 e: C% F int 2fh L; p8 r6 W- e1 p( n
mov ax, es ; ES:DI -> VxD API entry point
3 p. n- H4 T" v: B: m) y add ax, di+ |) r( _0 w+ I2 n3 |% i
test ax,ax
7 R! U9 R i; B; X0 l" |% Z jnz SoftICE_Detected
& l$ |, l$ m) o9 U8 f O$ A5 F9 W5 ~: M
__________________________________________________________________________
) {9 Y0 G+ W6 ]& j |7 w2 }2 v
# n7 @. w u. r$ B+ A) X; i; P
9 G, a) z) h9 Y2 _: IMethod 050 J6 r5 G( J' E6 ?
=========) ?# t) c( @( |
- s2 T) k5 W. g& ]+ j% lMethod seeking the 'magic number' 0F386h returned (in ax) by all system9 Q, Z, w7 h: w5 X2 @8 R
debugger. It calls the int 41h, function 4Fh.6 _% |* P# K' S( o
There are several alternatives. ( |% ^' `; A3 n; \/ w3 U
7 Z/ u4 f t- {$ V
The following one is the simplest:
) [8 f7 r9 y! N+ i
" | B: Q, f. [/ s$ L) m2 W mov ax,4fh
* r0 W# U& q7 x$ U+ D int 41h
! c9 z! }7 N0 P( J4 K( [& Q, j cmp ax, 0F386: n# R$ P+ X; h" M
jz SoftICE_detected
8 g' Y6 l, s6 ^* G( K- U2 i$ \* b4 t9 [: @2 N4 q
7 }/ r' k8 S, c: r( [# ENext method as well as the following one are 2 examples from Stone's
" c* {% l6 a$ p- o4 a"stn-wid.zip" (www.cracking.net):
* K* o: |: w$ |1 }7 E( Z: F/ m+ T. d* Q
mov bx, cs
6 J1 Y8 e( `9 S: L" ` lea dx, int41handler2
% N3 k, i; q% R. s1 i xchg dx, es:[41h*4]
: v) w- W5 i( }& A xchg bx, es:[41h*4+2]1 h/ E0 _4 \/ O8 ~2 d
mov ax,4fh
0 ~# v* f- k4 ^# e% Y int 41h
2 U( [" ], A) @" R+ ]6 E/ R xchg dx, es:[41h*4]
# r( E# P& E2 r/ ?4 L A xchg bx, es:[41h*4+2]
8 i( c3 U& S7 T! }5 S- Y cmp ax, 0f386h
# s3 s9 @0 F1 J; ~6 W jz SoftICE_detected
- R# G, i+ D& E" r. R2 w9 c, T+ X
int41handler2 PROC
- W1 S- b5 [1 n iret
( \6 D4 M1 f: C$ s! s1 F0 Tint41handler2 ENDP
- |3 X* w0 r$ r9 }1 L9 F8 a2 f+ z
3 z9 t3 Y# b* t% B; q. k
_________________________________________________________________________; ?; I; z! D! c6 {) z: t0 V& Y
4 t! b4 E- w6 @# d7 m
& U0 o2 A. @6 m: J; u; j) k5 }
Method 068 Y* w+ A: g) [8 @4 V% {$ N; S) p
=========
8 s# [, c+ w5 l# v
1 [; e0 \9 S+ m7 V, U$ e* U& }! P
/ [: { N+ `3 O% n5 ?3 H2nd method similar to the preceding one but more difficult to detect:+ |% i$ ?) D) X) t
9 [% f! q2 V: {8 p
$ v7 [9 F, Y8 f7 z
int41handler PROC
+ O0 m* M3 i. {9 S mov cl,al
B6 ~; {9 @8 M! e3 Z+ [* d iret9 I2 @: l6 N& T1 T' R7 t1 c
int41handler ENDP8 ?2 E% `4 f3 }# O
& G3 H: X( T' N9 x# t$ J' Q- F3 c5 d H
" e$ {- x+ k! \0 W: z1 e
xor ax,ax
* @1 v( X/ b. V' [* {7 Z mov es,ax
1 m5 A# i% n/ m+ n5 d/ A+ [ mov bx, cs% X8 W/ M7 c6 P B9 Q+ l
lea dx, int41handler
5 e1 ?, j! W8 e( P; b8 r6 d. ]* E xchg dx, es:[41h*4], `8 A2 g, \1 X" l8 \- k; {
xchg bx, es:[41h*4+2]: R/ a) {2 q/ t: r3 P
in al, 40h
7 E, [1 h2 Z: A8 R. V: I; N xor cx,cx
4 j( u/ z0 \2 t, {. e8 n n$ l int 41h l) ]7 r1 S: K
xchg dx, es:[41h*4]; m+ `9 b) P* {# d3 A6 `8 z
xchg bx, es:[41h*4+2]& ~ S' @7 Y. \2 R) z" P# q
cmp cl,al
+ }, x7 B8 ?/ P. u& x5 {* H& q jnz SoftICE_detected$ K6 X J9 I, r, M+ `$ S
; V* Y" x! v- ]* l/ j+ f
_________________________________________________________________________! ]8 s7 d+ t% n& g& P e u( ~
3 X( K3 P, g& f; |- q9 xMethod 07. _1 O& E' V; ?7 s; K
=========
* W5 c2 k) E7 b/ S1 ?; z( C) Q7 w/ o2 n: n6 j6 C4 l
Method of detection of the WinICE handler in the int68h (V86)+ P: V' n( Q, T6 ?
2 n9 F! R% w* b2 w# S
mov ah,43h2 h2 G/ F' O/ p" P9 ~
int 68h
# C2 ^; H, I: n7 ]3 v2 J) S cmp ax,0F386h
5 `. u+ Z8 T% u! E+ m; q6 h9 H jz SoftICE_Detected0 h% [/ l: V5 X7 }
3 ^% T b( d1 o, ~0 J: I. z; o) \! B# I3 z' C1 b
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit9 W4 Q2 g7 S) ?9 Y. \
app like this:, ^* A0 ^2 f4 T7 m$ |5 h# f
7 p2 H+ N; s) Z" W( l0 ?, X2 a BPX exec_int if ax==68
; q# k9 W- p( o. s- N7 I3 P (function called is located at byte ptr [ebp+1Dh] and client eip is
1 ^5 ~! r" T0 q+ Q" C2 e located at [ebp+48h] for 32Bit apps)' z: `1 o. p! D- P! X
__________________________________________________________________________
+ \: l2 f. T0 k5 D
% ?% ?6 n/ A% H7 r: Y W$ ~3 h' R1 Z+ C* i/ b
Method 08
9 o) f! |! A4 i, y+ Z# Z) }$ ?0 E=========
; a" V$ n$ \1 z7 e. s6 e* i. k1 [7 @2 ?" z1 B4 `; g
It is not a method of detection of SoftICE but a possibility to crash the7 G* J: ?, D5 [
system by intercepting int 01h and int 03h and redirecting them to another& c% d4 s! W3 n% U
routine.
+ I9 @9 O8 g& c+ E; E! H2 s' B& BIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
$ z3 z# |0 P* K1 Sto the new routine to execute (hangs computer...); h; P6 ^' R7 B$ ~" ]
* A+ M3 P0 t c. M
mov ah, 25h7 o0 D! |% Y0 u& E; i5 z: i
mov al, Int_Number (01h or 03h)* W: F8 V% a6 n7 G; ~
mov dx, offset New_Int_Routine
* J" n5 t3 b ~, ^2 L4 R int 21h8 q1 c! \& E- ~/ t% r2 n5 k9 T
$ H2 d& E& X2 `- k9 `__________________________________________________________________________
$ Z' M7 {) ~8 c
~9 j) D) E! A) D' L9 ^Method 09
' V4 H! a8 _# X9 o+ T=========
$ C! e, E3 I& U2 R% O2 t* h; ^/ T; N- i
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
0 n1 g- J* G4 h" G) n) M5 yperformed in ring0 (VxD or a ring3 app using the VxdCall).) e( z+ l! p' f! K7 X
The Get_DDB service is used to determine whether or not a VxD is installed
. f3 P8 W& k3 S2 Ufor the specified device and returns a Device Description Block (in ecx) for
( u* ^! j% x7 F4 h# @" l( Pthat device if it is installed.
" }" r; o% Y" |" v) m: j
9 r7 b: G! O' `2 B8 W mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID9 A) \& d( e2 k9 e
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-). j8 r$ ?6 z1 g! [
VMMCall Get_DDB' h/ b! I$ o1 z* Q5 Q8 ?* N
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
- p7 v! }! S, `9 [3 A. S* @
$ t0 v0 E3 ^! Y$ ANote as well that you can easily detect this method with SoftICE:
/ \/ b% g7 T: _8 ~5 T bpx Get_DDB if ax==0202 || ax==7a5fh1 J- l0 J9 l# P1 ^% w" f. ^+ k! K- I
; Q5 d" _9 r& J3 r8 F
__________________________________________________________________________
@8 @5 |: U4 M" Q" l
( G* f4 X6 O: y6 h" E8 w7 aMethod 103 L; [8 j' b7 j0 Q& T. c; O( G+ p
=========% z+ ]% X1 q, B
+ h; \1 ^3 E( n7 ]=>Disable or clear breakpoints before using this feature. DO NOT trace with- k6 O( F9 I0 ~4 r r/ r) I
SoftICE while the option is enable!!
& f/ C; R% N4 F% L+ ]& P
B7 W5 C5 K G* \9 bThis trick is very efficient:
% p+ q$ g+ g9 f3 b; sby checking the Debug Registers, you can detect if SoftICE is loaded
' H" T0 _9 @! ?6 I9 L5 {(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if/ N, W* b# z# |2 ]4 r! X& [
there are some memory breakpoints set (dr0 to dr3) simply by reading their
0 B. g2 W6 p: v6 Evalue (in ring0 only). Values can be manipulated and or changed as well I- N) Q L& y2 T3 M- g
(clearing BPMs for instance)/ T, y' x1 ^0 R* g7 {
5 G# Y; d& j% R9 f3 @! o8 U6 ~& l4 d8 l__________________________________________________________________________+ A3 b4 I7 w( u" S) ]) ~7 k5 |
9 Z6 m0 l" U6 x' {) v7 ?5 l
Method 112 t. f" k' A, F9 I2 l
=========
" ?7 Y7 \( C, G" {8 H5 b5 _" m
1 [4 k6 e6 h jThis method is most known as 'MeltICE' because it has been freely distributed
# F- W5 `6 I! ^$ [) F6 ^via www.winfiles.com. However it was first used by NuMega people to allow, m# \2 S5 ~3 G2 C! ]& [2 ?" V
Symbol Loader to check if SoftICE was active or not (the code is located% ^% K( |8 b% N7 t- O/ b3 {
inside nmtrans.dll). T# j9 T D: }) G
) b1 R7 Y. o! p3 ]. t! {The way it works is very simple:
& O9 C8 [7 ~- |& R5 V0 W; WIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
3 [6 B) c" D: {: l _WinNT) with the CreateFileA API.
8 i q8 S2 X# O, K/ R( K
# y z% L& T. n9 E% WHere is a sample (checking for 'SICE'):1 X5 A5 T- I! f# X3 C
2 y( [! M5 \* k2 _ H; _! f ]
BOOL IsSoftIce95Loaded()- F+ ~& X6 J' Q7 q
{
/ ^; O8 X& K; d6 _/ R# D HANDLE hFile; 4 X% W8 b0 C- X' A( ~0 j; m: O
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,& P5 U& L1 J' B+ f5 {
FILE_SHARE_READ | FILE_SHARE_WRITE,
( N+ J: {% k7 B$ t% w NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
" G3 w3 ~- D, V if( hFile != INVALID_HANDLE_VALUE )
* U) X0 V. s: B9 J: i$ b2 @ {9 S; I, D/ a8 c9 @
CloseHandle(hFile);+ O# k1 j4 f" a5 }( ~
return TRUE;5 m+ q* ?$ Z8 e; N6 ?/ t
}
- t: _2 I1 Y2 F- r8 W7 Z return FALSE;
4 l3 y5 l1 F8 c& }, M* Z}4 i" o4 l9 T2 B4 [/ A% D
6 c3 j( z. P; u- n3 U, c( |8 {
Although this trick calls the CreateFileA function, don't even expect to be
: a4 Y/ J; j0 K7 Aable to intercept it by installing a IFS hook: it will not work, no way!
$ g( @* }$ s+ u0 lIn fact, after the call to CreateFileA it will get through VWIN32 0x001F& F) f) G9 v7 n" [
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)* R. ]' x. N$ t$ K: a' J
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
; i; O& y4 c! ?6 Rfield.
. F' N3 s1 O% f' l6 IIn fact, its purpose is not to load/unload VxDs but only to send a 1 i5 Y( z: H) f6 _
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)! y: C& d' u! W
to the VxD Control_Dispatch proc (how the hell a shareware soft could try$ \5 v$ _ }# J- D
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
+ _: S" h5 A3 S! qIf the VxD is loaded, it will always clear eax and the Carry flag to allow* D3 N7 g3 F* K* ^" G x; s; J# m
its handle to be opened and then, will be detected.
) c8 H0 x* v( h6 U) Y1 l1 ?You can check that simply by hooking Winice.exe control proc entry point
5 G D' s+ n% ^; t* H0 n: Ewhile running MeltICE.
; h8 b8 U% R/ v$ W. x! k5 ~3 R% I2 a8 ~, s# m3 @5 h g3 i
, L& @4 d3 d% }7 [) J, t
00401067: push 00402025 ; \\.\SICE
7 t8 P# h. {+ e. E7 x1 m6 i) x 0040106C: call CreateFileA6 j" O- a. X2 X1 W: ]& ]: ^: N
00401071: cmp eax,-001
+ |7 }' P2 v6 @7 }. Z4 N. ?! a" s 00401074: je 00401091; ]3 h) E# o. B8 l4 f0 f
' j; f7 p3 t9 y2 J8 B" W4 U) g( N" _9 ~; e' M# | S7 c! u
There could be hundreds of BPX you could use to detect this trick.
: v6 n" P' P/ `6 I6 I-The most classical one is:8 ?/ u8 c$ ~9 s
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||$ d1 }1 W9 H- s) Y' O4 U; a0 B
*(esp->4+4)=='NTIC'% W( L8 b, u1 R6 d" l8 z1 m' X8 `
. H$ K/ ~: l4 ]" K# c. m7 m-The most exotic ones (could be very slooooow :-(% \, E# W5 }+ L- n7 _
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
' v t+ q" }: Z$ ^& n ;will break 3 times :-(
6 `& d( R: e/ x( Z1 j: C
6 @/ \! w6 _6 n7 z4 |! i; J-or (a bit) faster:
1 Z* ?+ Y T% V. x' y7 w BPINT 30 if (*edi=='SICE' || *edi=='SIWV')1 A$ q" Y; z) o( N; K( k7 z+ Y0 s
6 q; ]/ k: n( l7 A2 N BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
4 a( ^- ?4 \" M1 K6 M. T/ x ;will break 3 times :-(
# X: }7 W* N# c9 `& r# ~) v6 j# r& D( X# K& Y) b
-Much faster: m, m w# o' {
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'- L5 x8 I: m4 t- {
- f" Q! g! S4 S C% D7 {8 L
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
8 v1 Z. s3 r! H( `1 Ffunction to do the same job:* q3 e. a" v3 G% m
) K, n9 p. o4 r7 t7 v+ E4 f push 00 ; OF_READ
% R3 G. C- D4 H0 H( ?$ [4 @ mov eax,[00656634] ; '\\.\SICE',0: v5 c! x- u8 t* K; c% z
push eax( ^( |& D1 f. j7 K8 }
call KERNEL32!_lopen
# ^- Z4 |* ~5 ?* I inc eax
0 U% d& ~* H% _* B2 n jnz 00650589 ; detected
0 X0 k9 d; h# x6 B# b% Z' p) p% @ push 00 ; OF_READ
/ A: y4 C" t7 }) x5 J. d mov eax,[00656638] ; '\\.\SICE'
8 e- R0 }* E/ Q* V8 y5 L/ ] push eax$ e7 O4 `8 A" @; w
call KERNEL32!_lopen& G- ]# J( |& `, F* C
inc eax
# Q7 y6 X2 e" x# K: }) F" i jz 006505ae ; not detected
6 F s& ~2 Y N6 W* z$ P# J5 b! p/ E4 t" O& o
6 i) e: }, p- u. `4 n9 Q5 i0 D__________________________________________________________________________; f* M- |: {+ B+ O) r* ^3 X0 ]( S
# \& a2 L; I$ KMethod 121 _1 G* ^( X# e7 s$ l. d/ J
=========9 M* z7 A4 }/ W) D
: m2 w- U# x) D7 i% X& OThis trick is similar to int41h/4fh Debugger installation check (code 05% f$ h6 s% N* L- e- k& A- M
& 06) but very limited because it's only available for Win95/98 (not NT)' q9 T& a8 Z! X
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.( S2 T$ @9 f7 ]" B8 q, C( l
7 _" Z3 J. K$ w' @" C; `% \5 s
push 0000004fh ; function 4fh
: b; t) D& q! o( P. v& U5 l push 002a002ah ; high word specifies which VxD (VWIN32)5 t. r6 n! x2 v5 R( R
; low word specifies which service/ H: R" w. R- Y# z) Y: X
(VWIN32_Int41Dispatch)
- S, C6 v4 c6 L4 A' y call Kernel32!ORD_001 ; VxdCall
# v# F( p/ o z; m cmp ax, 0f386h ; magic number returned by system debuggers; C' h1 d* A! ?$ p
jz SoftICE_detected
* n. Z' ^( D3 f4 K# F- e! U+ X& p# [3 ^
Here again, several ways to detect it:
: U+ J5 g/ K8 {0 R( |1 K# V* C6 }1 W
BPINT 41 if ax==4f2 { o9 I' t$ c, i [" ?
1 [$ i" N! G: w; I1 z5 p+ Q BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
, h1 F! v1 L0 v9 r& l$ G. X& {5 j7 I) [' p- T X, q
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
6 s5 @: A! j3 U7 W5 T
5 x* g: ?8 i0 x' m( ]% Y1 I BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
8 U' `9 r6 K% [5 A v f
6 `6 K; L4 Q9 m( F9 ~__________________________________________________________________________7 j3 d! E; y1 H
! o+ `$ n, t8 D; ` uMethod 13
m+ z" x5 m5 p: [$ _" e3 t2 ~=========
! H" i+ @( w( N& e# U% e s' ?1 Z; b" }# }+ ~. N7 ^
Not a real method of detection, but a good way to know if SoftICE is
. |" K% n7 X. c M" vinstalled on a computer and to locate its installation directory.
7 g0 s2 @& P# @# _+ E3 JIt is used by few softs which access the following registry keys (usually #2) :) D) O c9 x/ J) `: P# O9 W2 R
& T) s9 }* f. r-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
$ U& m& E9 Y4 E% ]\Uninstall\SoftICE; n5 ^9 W, ^ l
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE! L# Z9 I8 a8 q7 @8 D; C5 ?
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion/ c0 K' Z8 b+ s% J D' C" A2 \
\App Paths\Loader32.Exe5 t1 f, j+ B- ~8 }6 t2 m
2 A: O3 `, Q* k' j
: W9 d0 m4 M6 |0 `$ x) H! F4 v
Note that some nasty apps could then erase all files from SoftICE directory
; U: `1 N' r+ G6 S(I faced that once :-(
/ d8 V, b/ M% z4 S) G) u8 T. }2 F' D( s; g% y
Useful breakpoint to detect it:1 C% ?2 w u/ a) l# `+ c
@9 a4 n: Q* P6 n) a/ G& K
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
% j5 O5 A" y1 x- c1 x2 J" M1 x
6 |2 {* o4 g4 d7 {, w__________________________________________________________________________
% l# c5 I7 z- y+ k2 i* r2 G
: _6 m/ D3 }( X1 v/ E6 c7 f
& G5 U1 P! M4 B; a, W8 `Method 14
$ ~7 A" K* q0 ?, G% f=========
( Z) J% {: E1 F8 f) x$ D3 g$ K T3 a1 ]! `% W8 g
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose8 m& n, f- Q$ F+ X1 g
is to determines whether a debugger is running on your system (ring0 only).
0 c8 A1 k( N! v v) S
2 q0 A2 s$ k: j+ e6 q% q VMMCall Test_Debug_Installed
Z" M) a3 h8 B je not_installed2 b c& x3 T. e# E* \ y' B1 q6 b4 q& m
3 K& @' g- Z; `$ [( ]" D7 X PThis service just checks a flag.- u/ Z8 c& C* y7 M
</PRE></TD></TR></TBODY></TABLE> |