<TABLE width=500>: Q0 n" L8 c' k( x% T
<TBODY>
# S+ T X$ g& r1 l( U<TR>4 w3 F+ O& i5 `5 J
<TD><PRE>Method 01 " I _- I- }5 Y+ X0 w- Z
=========/ ~* C0 M `6 |% e J$ V6 y
" O( [" f2 ]9 @$ o. i" nThis method of detection of SoftICE (as well as the following one) is: W& }) U# a2 W# Z6 F( s" T C# `
used by the majority of packers/encryptors found on Internet.
" [- r9 T: M. |: E! V; {4 G/ D# PIt seeks the signature of BoundsChecker in SoftICE
# J" Y, f8 G6 x) R
' B. H/ s! y* A& Q% h5 Y mov ebp, 04243484Bh ; 'BCHK'
+ \. ]6 O. {( ~3 q' V mov ax, 04h
) h3 H, G C' e: t+ T int 3
+ }3 ~4 e' r8 ]1 e cmp al,4
4 K# Q% \& Y. M) _' ^( r jnz SoftICE_Detected
q2 Q1 d) P8 c3 y( S0 c# U& J$ I+ d1 m8 n2 F
___________________________________________________________________________1 y z! _1 h, d7 Y
- }3 z" k, U; p' x2 dMethod 02
! \5 X3 O% T4 O=========
% z8 D% h3 Y2 N8 m* [/ _# P( n i$ D% s+ |5 T V7 N
Still a method very much used (perhaps the most frequent one). It is used
$ e2 E1 H% t: ~' Y, j* Y, U7 V* |to get SoftICE 'Back Door commands' which gives infos on Breakpoints,5 }9 v, n0 n* U) F* U
or execute SoftICE commands...
# `1 H; _, F) S" N' ]5 wIt is also used to crash SoftICE and to force it to execute any commands
" U. \3 U/ J6 n(HBOOT...) :-((
, C; k, e% M1 \4 @% {4 p; p
6 S; i' o; a0 B5 dHere is a quick description:
- C, a7 P) X/ f( f$ ]+ h" B; K-AX = 0910h (Display string in SIce windows)& }- I, s! g3 c! r+ ?4 j
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
, u' G. _$ f$ H8 O$ B-AX = 0912h (Get breakpoint infos)! M0 G1 ~/ _& g
-AX = 0913h (Set Sice breakpoints)
3 F& A2 }- Q7 @, f7 q" |-AX = 0914h (Remove SIce breakoints)
/ }, V6 M8 S3 t* v: L, S" s0 _" q9 c! { [4 V* v) q
Each time you'll meet this trick, you'll see:1 t2 e! m4 a ~' _+ G# L Y1 Y8 H
-SI = 4647h: y& l. E, ?9 V9 C/ J4 g% v8 Z) y
-DI = 4A4Dh- w2 A/ |4 ]: Y" `' w: l
Which are the 'magic values' used by SoftIce.- B! Y9 R5 `: b8 S% n& v
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
) d( } Y4 B2 z0 Y6 F3 i% ]! x$ M$ h5 {9 y+ |3 v. S" e N! F; r
Here is one example from the file "Haspinst.exe" which is the dongle HASP
: A8 H0 n# u8 X1 A4 ]4 NEnvelope utility use to protect DOS applications:$ D+ ~. {/ s! b, H
8 f- u- R, ]- A; y
! |( a3 o) e* g9 e# N4C19:0095 MOV AX,0911 ; execute command.* h, ?1 J! s1 f5 K
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).+ F0 Z9 Q( M* ^2 b
4C19:009A MOV SI,4647 ; 1st magic value.
v! C7 @9 @/ h/ x% V3 c4C19:009D MOV DI,4A4D ; 2nd magic value.
; C* M& s L% l7 ]9 C4 }: s4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)+ c+ @) B" f2 R
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
% [8 g% C* k1 Y* ]: E& a B; B+ b" m4C19:00A4 INC CX+ K0 j. W f4 I: Y7 `
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute0 Y3 m; A; O" t5 k; N
4C19:00A8 JB 0095 ; 6 different commands.
3 B+ c- b" [) P4C19:00AA JMP 0002 ; Bad_Guy jmp back.
# T Z9 B4 N0 M$ X6 a* x4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
! P& c& _! W3 u& }( B6 [1 |- x$ y+ L: N c6 b
The program will execute 6 different SIce commands located at ds:dx, which& }( o+ M9 Q; z! l/ V$ n
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
7 m' V8 i% i1 ]/ P. T2 P- ?" a$ y' N, g$ m
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.& P4 T* ^. y" F
___________________________________________________________________________7 p, k( ^" k. ]2 s
) Q( T6 N3 A2 n
1 U# ?. ?1 X- O' cMethod 03
{2 o% l4 k& q3 {=========
1 y* y" O& A( J- s! v" t
& u" [3 Q& I7 ?) R2 y' p0 T% i c; @Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h6 b, B- _/ L/ w8 R( F
(API Get entry point)
# m* l' U% `' F4 L! R0 [ 7 u- n3 [8 @2 H% p% c& B5 L6 ]
; E' c% w6 N' j0 a- ~+ y6 f( S
xor di,di
/ A% l/ R1 H$ t- {$ X mov es,di
& S. o9 e4 e- Q2 d; u0 ] M! j mov ax, 1684h
( X) \; o2 x9 ^, b- E mov bx, 0202h ; VxD ID of winice$ U3 z# [% f2 W. Q2 I- t
int 2Fh# _* w B2 t9 j
mov ax, es ; ES:DI -> VxD API entry point
( k4 g( B- P/ F6 c add ax, di% k6 l0 ]0 t! L' H4 _
test ax,ax+ w2 m* T' T* i9 a
jnz SoftICE_Detected5 r$ j- }$ o+ [
: w' y2 O* [! `7 g! G3 s6 \9 v___________________________________________________________________________8 m( E0 a9 X( q g7 G7 j
$ F9 }- a3 c$ q. K5 q2 f# i' N7 j
Method 04
4 t& |' N" ?2 o( S) k, R/ e=========
/ g9 a2 `7 ?, G6 I, j1 v$ ^ g
; h$ V( U9 X6 s6 h: K2 y) ^Method identical to the preceding one except that it seeks the ID of SoftICE4 x! \/ t& f) @! s& n) t
GFX VxD.
; i; A+ z1 l1 Z8 u) c. a' w8 x$ s' g, J1 Y) e
xor di,di7 H, k Q1 L. w% r4 h) s
mov es,di& _6 Z. J' z* [) O% u& N" o2 u% E
mov ax, 1684h , `. c! |, J4 o! H; q C3 {9 t) }
mov bx, 7a5Fh ; VxD ID of SIWVID9 e* z% z& c/ S% \
int 2fh
; r0 Q0 `( q @2 ^! ?/ g- x mov ax, es ; ES:DI -> VxD API entry point
! D+ D- K' J# G8 H3 y add ax, di% x* R: V8 V6 b
test ax,ax
5 o( g" O4 U; m/ Y jnz SoftICE_Detected9 E( G: B7 a( D7 I" j$ p" x; F
, D; e! l/ f9 A
__________________________________________________________________________
0 H4 B! d7 a+ Q) _( U- o# P" J: d6 b! S6 l: P# E( g$ Y! }
; F# O4 {# D' o' m" B2 uMethod 05
% a$ @, U. {( A) k3 S8 `& u=========
1 ^* _/ t9 ~' ^0 b6 J! `: ^+ h1 x) e D9 D, ~( E5 n8 q% m4 O, p+ z
Method seeking the 'magic number' 0F386h returned (in ax) by all system
# j% J" Q0 m5 \( H; y2 Cdebugger. It calls the int 41h, function 4Fh.
, J" P$ x6 G. a! ?' b( T( }4 }: lThere are several alternatives. : I& `2 h8 j7 V& F& A
2 c7 ?& q) n: {8 _' b! dThe following one is the simplest:$ Y$ l% `1 t6 J; c) {) v9 M
" x6 w7 B8 h# s$ }4 S; ^: a
mov ax,4fh
' A% B/ N0 b# D int 41h6 G( J* T2 O7 T0 s1 H- o1 n1 }, q
cmp ax, 0F386
7 T# i! m! h/ @; w6 Q! m) p1 a8 v jz SoftICE_detected
; p! o" H' \ b; q; R0 U( s/ E' P2 g: J C
7 I+ \! }( ^8 h; N6 Z! S/ f8 r
Next method as well as the following one are 2 examples from Stone's
O. }# O8 z2 X3 Z3 B- s"stn-wid.zip" (www.cracking.net):
# V% e2 C+ }/ `
; P9 [- b; t5 c% h: v5 ^+ U W9 Z mov bx, cs
0 }) g9 R( @9 T/ B+ ~7 H+ o lea dx, int41handler2
/ c; a- j* M& n1 t5 G& P3 N! E0 y xchg dx, es:[41h*4]
2 D9 @5 Q* N" q1 G xchg bx, es:[41h*4+2]) J' Z+ ]7 t' A; ]4 L: j+ g
mov ax,4fh% L, d0 U# a, n0 Q' O% C1 {- e+ z
int 41h% |4 C7 h. L4 B, g1 W: z
xchg dx, es:[41h*4], r# M: K+ F3 e- s. K% _
xchg bx, es:[41h*4+2], u9 D0 g% c9 T) k2 b
cmp ax, 0f386h
! K8 l4 {4 V$ g6 N4 k, S3 s) |3 ~ jz SoftICE_detected
/ q& w1 o1 l1 v. U0 ^+ M) _( m1 K9 `/ J5 f4 [& L% }! S, P, P3 G8 D. y5 _
int41handler2 PROC
1 }( V, M. v3 Q, U2 Q, K9 E$ A iret4 y J% t; [ ?1 K5 N- d% D4 r4 [# L
int41handler2 ENDP# E' D# i: c3 S2 e) ]
9 x8 U: A6 y" x" D# f8 ~& R, k: `6 h# p7 x. V. X2 I2 E
_________________________________________________________________________( M) R* a2 U( L$ m- j% `6 m
/ O! Y+ A$ _% j1 Q" V9 }) U: x
4 I$ s! ]3 z* v) W6 rMethod 06
8 o1 L' w% o5 Q' R4 [=========; g' o& B% n r5 m
# a1 s5 H D" A/ j5 e! x
$ q9 ^% P1 r+ q1 l/ k, K
2nd method similar to the preceding one but more difficult to detect:( I: E6 n1 H, ?. ^: J' ^
6 @* v7 S9 f5 U5 G! {
O" b4 }1 W F2 Q5 Mint41handler PROC- M, [& s2 {4 ?) }( c
mov cl,al, N/ o9 U# D9 N2 s l
iret
) A* K8 x i Oint41handler ENDP A3 H/ X( v) f% O6 z
" R% _, R' s6 @# c2 F/ |0 C
; {& _$ P* Y* @ xor ax,ax
! ?) Z8 Q1 i9 ^4 O mov es,ax
4 }8 [$ e0 Q9 M ^5 {! J, X6 S5 a# U mov bx, cs- t$ n/ u% o& Z+ ]4 g
lea dx, int41handler$ o5 C0 a/ L4 G# m# ?
xchg dx, es:[41h*4]
) G- W- Y0 a3 h0 |3 i4 |0 i z xchg bx, es:[41h*4+2]* Q" B9 r7 V: v8 r% [4 v
in al, 40h
2 u( v* T! Q) M9 l xor cx,cx, E" C5 G$ }$ T# ]% T9 G( y* @
int 41h
, M3 o5 x2 l! I, M xchg dx, es:[41h*4]7 E% v t. n3 H' g
xchg bx, es:[41h*4+2]0 n: Y8 M/ A, ^: T2 \
cmp cl,al' {( M" ^4 E) L& Z
jnz SoftICE_detected, Y) ?: u. T1 c, s3 j" D3 L6 b
8 `- K. `7 D* U6 H6 c1 |. b1 Q
_________________________________________________________________________- G7 }, Q& P1 R0 V$ n8 |" \
4 Q3 F/ Z7 E; B4 x! MMethod 07
5 c' b" a1 j- L& v0 G=========4 o T( Q2 ~8 f" m" a0 ?( r
; H9 G5 f0 v9 CMethod of detection of the WinICE handler in the int68h (V86)
$ z% t9 @) W& Q+ C4 J1 @. |2 }: K1 u9 d
mov ah,43h! @" R" ?& e$ ?- d7 h
int 68h
/ n# p# w9 @( i2 z cmp ax,0F386h
2 C" g5 C5 M6 Z7 `' D jz SoftICE_Detected$ y( w; j' {% b' r
! Z) g. z; c! k$ ?
& w. e( J6 W- ~( T, h9 ?0 P=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit$ y/ y9 ?* C ]+ D9 R; R- q
app like this:$ R$ x2 A9 @# |" J
1 m+ i! O: _) @# K' y. ~& D
BPX exec_int if ax==68
5 a. R, i6 ]3 I (function called is located at byte ptr [ebp+1Dh] and client eip is4 E! a& S3 `/ |/ [: f# L
located at [ebp+48h] for 32Bit apps)9 ^; ?; p) M5 J- j% t, i3 N; T" C
__________________________________________________________________________
, L2 z' l4 u( n& V
9 i9 _) G/ M& B; J
5 Y; W# a: Y2 \+ rMethod 08
1 v u6 L' C' b0 k! z) H=========' R% n# ^- z! Z
! M9 A4 C2 [/ D: `3 w7 l8 i+ R
It is not a method of detection of SoftICE but a possibility to crash the w% s' O' a0 `1 [" W
system by intercepting int 01h and int 03h and redirecting them to another! L5 U' z9 B+ N$ h9 W4 m" U
routine.6 J5 a- J; R0 l
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
+ B; w3 [6 `, a# I5 @4 Vto the new routine to execute (hangs computer...)% u$ [; j. ]& u1 [
" I& \# U) Q$ Y' g, I- i, J
mov ah, 25h
9 M* s# g# U+ ]- m! R' y& r mov al, Int_Number (01h or 03h)/ j% d4 Y+ R" Q- e
mov dx, offset New_Int_Routine
# }" U* k9 T, p6 b& O: \ m' I int 21h
! |- O7 r. Z9 J* j& I
: i! {, }: `' U6 ]8 G# H( m5 r__________________________________________________________________________
1 q# s4 y, L. `
% Q$ i" k2 V% y2 TMethod 09
; p! A0 J; j4 ?1 j0 e=========6 Q& s0 t K) F% K
, h% {) S; ?0 J8 f" G
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
1 L5 [' a) K% ?: g, Zperformed in ring0 (VxD or a ring3 app using the VxdCall).
% ?( R2 s1 t' ]5 vThe Get_DDB service is used to determine whether or not a VxD is installed
: s4 R9 u0 J# E# }2 m+ I; \. Gfor the specified device and returns a Device Description Block (in ecx) for
0 ?& G5 S+ e- I' y sthat device if it is installed.' n' k; y# L0 ?
) I7 }6 ^2 I @: I3 s7 q @
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID# K8 f/ Q+ t) b, [) ~) l
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)8 n! g- q" t P3 ^! D6 h+ ]7 ~
VMMCall Get_DDB5 i7 v: R) g4 Y- U1 f* K: C0 d
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed$ T7 ]4 w4 q. X0 l- p" C
. q: {6 P7 g" B5 n6 F O! ~4 ^/ ?Note as well that you can easily detect this method with SoftICE:# q- v) W! y! O6 ^
bpx Get_DDB if ax==0202 || ax==7a5fh u' I9 i7 }0 L/ y
; d1 l( \% k( M+ {! {: e__________________________________________________________________________
. @; J* S# Y! i; \ N: W
) R+ F1 I: R- C) ?1 [3 }1 iMethod 100 `+ B6 ]1 v- `* ^! z2 A, K
=========) W8 g, Y$ b' }5 ~ Z
" k2 ?5 d; R# V6 F9 |) n; O7 n
=>Disable or clear breakpoints before using this feature. DO NOT trace with# ~4 m4 G) h4 I
SoftICE while the option is enable!!: \' u0 |' e4 k$ C3 ?, g
5 I1 a" ] V9 T" i, W
This trick is very efficient:
+ H* K# m9 i& H) qby checking the Debug Registers, you can detect if SoftICE is loaded
+ ?& n/ L D: ]. B$ N(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
: Z# s8 v* K1 C( Zthere are some memory breakpoints set (dr0 to dr3) simply by reading their: }1 L" X& y4 P
value (in ring0 only). Values can be manipulated and or changed as well
- |) A, d6 u1 W; Z1 _+ H(clearing BPMs for instance)
6 v$ @9 p; \# f1 o9 w! f) e7 Y% s6 y w) B
__________________________________________________________________________
} l: _) w! w* C6 m: t4 C W* L1 g3 l0 K4 z: x
Method 11& i+ m) u6 K! I2 b
=========
' ~) q h0 @+ V# w4 Z; k. Q1 @- M& X: K
This method is most known as 'MeltICE' because it has been freely distributed( W* K: y# f% U( e; T
via www.winfiles.com. However it was first used by NuMega people to allow
* A* u( G: I# z" gSymbol Loader to check if SoftICE was active or not (the code is located; R" T" t5 y6 J4 p; c
inside nmtrans.dll)., o; D2 l' I X* j1 H0 a
; \- T0 m9 f3 A! @" d. MThe way it works is very simple: q* O8 D& Q3 P, @
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for# P% g' p8 V$ d' K! @; k
WinNT) with the CreateFileA API.
( c U0 B& W; f) m: j' O* v) M) E) J( m: d8 m, j3 b
Here is a sample (checking for 'SICE'):: J3 r1 `1 }( `2 O+ N# }
, D1 S1 _( R, t: S) ]
BOOL IsSoftIce95Loaded()
7 d" e# @. ]6 y/ E9 n' }. B{
% _& t ^. V/ O/ H0 [- ]- k5 {1 O HANDLE hFile;
# o6 u; h. u. c' F hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
$ [* L# I/ P3 {: y' p FILE_SHARE_READ | FILE_SHARE_WRITE,
- \2 A1 E+ J4 j2 I$ y NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
% g; Z/ t& ~9 V- b9 [ if( hFile != INVALID_HANDLE_VALUE )% z, T* X q1 G% x/ t
{; ^" b; T L1 Y T7 X4 |. r4 C) M
CloseHandle(hFile);
1 c1 Q3 h0 e. {. R4 Q# r! _ return TRUE;
4 |; S4 t% U' v1 ]+ A }
1 W3 Y' y; K6 J0 }* }1 d6 o return FALSE;* X; b, R4 F# b. R; \* K \* i
}2 P: ? [. O' F" ~! C# T
5 y" X3 D. {& F' c) o: WAlthough this trick calls the CreateFileA function, don't even expect to be0 U0 v: g$ f. Z# J& r
able to intercept it by installing a IFS hook: it will not work, no way!2 B3 y C; O" X$ I) F/ r
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
+ z" l" K6 ?/ dservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
# }8 k$ H4 h @8 ]4 O2 K. yand then browse the DDB list until it find the VxD and its DDB_Control_Proc6 Z/ n- H8 s3 b! u0 D1 v( h& w6 b( f
field.# F$ u8 G4 O L
In fact, its purpose is not to load/unload VxDs but only to send a
i( {$ \# r- Q0 L8 M) E# N% wW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
; y+ B D0 y- P% k/ d8 h) k$ s1 Zto the VxD Control_Dispatch proc (how the hell a shareware soft could try9 @# V$ z" b* d' z4 l; |* [( g
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
/ O+ U h1 f4 k! i* D+ RIf the VxD is loaded, it will always clear eax and the Carry flag to allow
6 O: r1 c4 ]5 f# s5 B2 aits handle to be opened and then, will be detected./ g* I$ [8 R- M- t% ^4 M2 E2 {
You can check that simply by hooking Winice.exe control proc entry point
% U* k! u" H) m# E$ Swhile running MeltICE.' B! @9 i1 `% ~1 I. t% f1 y* y
0 j( A9 h& H' h# s- j, |
4 Z/ y1 Q% `3 m/ X% N+ C 00401067: push 00402025 ; \\.\SICE
% G; @9 b! v. w! @ 0040106C: call CreateFileA' U; l9 X. P" ^% ^5 i! D9 I7 J' ~
00401071: cmp eax,-001$ U3 q( F8 k( c) |* s
00401074: je 00401091
7 x) x0 T8 _" v2 `1 c: f7 D9 x$ g" Z
7 `6 ^( {- r+ A; B; _, ~7 |
There could be hundreds of BPX you could use to detect this trick.
9 ~+ {, P4 y# X& X-The most classical one is:
8 G0 @- o( e' h1 J' q, Y; N BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||; T! y! m$ _ o9 ?8 a) R# d. D0 L4 O
*(esp->4+4)=='NTIC'# T4 B6 ^* @9 f) K, O5 S2 k, b
3 b1 _" @) ~. B z( o-The most exotic ones (could be very slooooow :-(
# C! |! W4 j2 c- m& W BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') ) V* x+ o+ W/ R
;will break 3 times :-(. g# s* V8 {! ]; C/ Y0 {1 M. ]
8 p' d/ o& G0 E: }: p; C1 D
-or (a bit) faster:
6 U7 n* N8 X* m) h BPINT 30 if (*edi=='SICE' || *edi=='SIWV')* z+ I% p- T5 q# b8 p! D
% E1 ?4 O Y/ ?" P: k
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
8 Z6 M! h6 ] Y ;will break 3 times :-(
4 a5 w4 a3 D! [2 n" |
/ N; Y2 m/ C: h" h; M7 u-Much faster:
3 O' M: B6 D L BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV', O5 R0 i" x) Y3 P& U/ N
# ] p& }0 D- l1 Y$ b. NNote also that some programs (like AZPR3.00) use de old 16-bit _lopen, w" x; D) Y& _" R
function to do the same job:
4 w& \9 w- o& E2 P+ f _, o
6 _. x2 ?* l5 l: ^( V# t: P push 00 ; OF_READ& ^$ \ @7 w1 a6 @2 a2 T: g
mov eax,[00656634] ; '\\.\SICE',0
) Y" a4 w( c9 i' S push eax
- a; S/ T0 e6 _, ~0 g9 M* m$ d call KERNEL32!_lopen
' Q, f6 I+ j" Q; V( U inc eax
4 ^- c. H+ a+ e* v/ s jnz 00650589 ; detected
, \0 S- N. x5 I push 00 ; OF_READ
! e2 _8 H9 a, s! ~2 E' T6 X" U# K mov eax,[00656638] ; '\\.\SICE'! X; V& t* C9 ?9 j0 u9 b1 T+ W. O
push eax$ c+ j- N3 ?, _/ C
call KERNEL32!_lopen4 q m0 a2 G3 n& z4 R7 D
inc eax
8 I2 K3 A/ r8 C/ q( | jz 006505ae ; not detected: k) f b) w$ s+ c
( I# R1 y! l9 H- U/ f \* C7 X( {8 m0 N h) j5 N7 l' @$ n
__________________________________________________________________________
8 P" N# i7 J, L" C
4 R1 x9 V- c! A/ B* oMethod 12
- M8 w$ R1 U4 _4 J4 n5 `=========& o! C3 a+ B. H. Q* y; @$ X \
/ ^4 D4 N( H! u$ KThis trick is similar to int41h/4fh Debugger installation check (code 05
0 A, [% A/ O1 v& 06) but very limited because it's only available for Win95/98 (not NT)8 T& h3 T& {. e W9 x1 L. T
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.3 s6 U: N( h0 T9 X6 h1 \
( C+ a/ P1 o, X9 t" O. j0 v
push 0000004fh ; function 4fh8 a3 K) c: j( W; ]& d8 x y$ _
push 002a002ah ; high word specifies which VxD (VWIN32)' v6 }, N g! J0 ~% W
; low word specifies which service& c: Y* h) G/ O1 x8 Z8 L0 {; h
(VWIN32_Int41Dispatch)$ C8 q/ |( J' z
call Kernel32!ORD_001 ; VxdCall% T4 b% x- h, B! M
cmp ax, 0f386h ; magic number returned by system debuggers( `6 U# r- Y+ V( N" a# A% a [6 `
jz SoftICE_detected
1 r* k) {6 j3 ~2 M
2 u2 n" O/ C3 _$ D) e/ H2 |Here again, several ways to detect it:
. b: j# d0 w4 P$ j# S( e% S* O
, W. q$ Q! U1 T. E; P' I7 P8 r4 v BPINT 41 if ax==4f
# R6 D: _1 K; M( S8 {
0 \2 n0 e6 L! z5 n4 Y* `1 }9 b BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
3 o8 K9 N9 g0 U3 ~9 C, X' M
6 n1 L$ j; Z! W) w d3 l BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
) Y @4 Q' P; I- m" e
3 w! o% n8 h, G8 m BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!" F' l" p/ h" m7 M$ j+ c5 _
7 w1 ^) M/ u) X__________________________________________________________________________
) w% i$ A& ?+ k. u2 }3 h- x) J' n# L: |: V: E- W
Method 13* X2 S( c& p- _& g. r7 g
=========" c3 [4 v, n* q: b9 E# f5 [9 {
# j6 Y" P" j7 C- A( Q6 B. F7 U1 z5 f
Not a real method of detection, but a good way to know if SoftICE is3 H: N* [! Z- ^ m9 d, P5 n# @
installed on a computer and to locate its installation directory.. E1 U* D) E8 e7 ] M2 u$ Q
It is used by few softs which access the following registry keys (usually #2) :
/ O7 A$ D, U0 S0 L5 m# o) s* N3 N; \( F! m! v, l
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
+ {% _- I3 G" b" ~9 K, X; ?8 t\Uninstall\SoftICE2 l9 y8 | y, ]2 Y- F
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE4 S2 [$ e5 u* J+ i. @2 o
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion; a) y2 I2 }9 A, M
\App Paths\Loader32.Exe$ I0 x7 y' q/ ]: y' ?0 ?6 s4 a
( X# _8 |2 ^$ K
4 G0 ?$ x% n: q3 Q( p: w
Note that some nasty apps could then erase all files from SoftICE directory
+ l. W- ]2 h1 T! N6 [; i(I faced that once :-(6 o, Y: q9 r r' Y# q$ a9 c* B! K
. s. W' @2 J9 X" P0 KUseful breakpoint to detect it:
% o3 N+ |% k+ l" A1 G" J4 Q& F) h) {# n% ^# @9 d8 T* m
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'" W8 V' e8 Y) W$ U* ~; Z- U( H
9 `3 I+ _% e) J8 @/ o6 M2 F
__________________________________________________________________________
5 U, B5 D6 Y/ t
" l/ j/ s. j. z: E9 t, B: w" \* g7 M& c$ {% N
Method 14
|# @# L) ]" q2 x" q, U2 C=========
) z1 E# C4 L" q* u$ g, S
9 [2 q( h% i4 l, [A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
: j- r) [6 y- His to determines whether a debugger is running on your system (ring0 only).0 V; k' @4 N' ^3 F" W
& F6 l7 R% R1 y0 n7 {; m4 y4 O) Q
VMMCall Test_Debug_Installed; I/ }( K6 y, E8 f) R
je not_installed: V* E' a! n" l8 J/ M
" Q/ {' m5 t8 `# F& O5 S0 J
This service just checks a flag.' c0 {" a- h e9 T
</PRE></TD></TR></TBODY></TABLE> |