<TABLE width=500>
: K' `) m' Y8 n6 ~" |: v<TBODY>
4 T% i! r Z% K5 r. e- j<TR>
. @( Z# A- w% W3 c4 Y( T8 A( `<TD><PRE>Method 01
5 r0 B: H% a+ d' D7 W. I6 K4 p=========
% M: Y" H: U9 U5 W0 I; D3 |0 c+ k' Y" J/ B
This method of detection of SoftICE (as well as the following one) is5 v# K7 H) d4 z5 K( w2 t
used by the majority of packers/encryptors found on Internet.
4 \8 j# J7 }# ^* WIt seeks the signature of BoundsChecker in SoftICE
" W2 D+ T7 p" S
% ? T; u' q' [6 M6 `" u mov ebp, 04243484Bh ; 'BCHK'$ Z. c) G- M! h) r" i6 w4 W
mov ax, 04h
; b4 g) v- f1 u* K* w9 l+ c$ p8 s int 3 3 m! ?0 C2 K* W" u+ W; N( U
cmp al,43 Z" [! }/ ?( p Y9 s8 d
jnz SoftICE_Detected* a5 V4 K1 V8 m$ P0 E& c( g; f
4 i; i# p# Y+ G) {0 x/ o
___________________________________________________________________________. [) k% _9 K& a, g
! ]( B2 `: z/ }, ?Method 02
! E2 Y P @. f/ P: ~! w=========
k& y' d) t' I' U& I! v+ n- \+ Z' V) W& m! I3 I6 H+ q: X7 ]( }
Still a method very much used (perhaps the most frequent one). It is used
* b* v3 ?' N: Xto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
, Q. H9 h. t! V4 N' i4 P; R. p) uor execute SoftICE commands...# f( m( T' f' ]& ^2 L% g% O
It is also used to crash SoftICE and to force it to execute any commands/ W3 E' u' _ R# g! r, L
(HBOOT...) :-(( 0 Y' @9 Y( ^1 Z5 e
2 T& _$ y1 C* P0 { @
Here is a quick description:
( I" {2 j% Z( s* M-AX = 0910h (Display string in SIce windows) x q( A( P, ]
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
; D' T% g. g' c" Y3 u, q-AX = 0912h (Get breakpoint infos)
% L5 b# ?2 M) l0 { ]# p: L-AX = 0913h (Set Sice breakpoints)
3 L* Z/ W% F, E! L, I-AX = 0914h (Remove SIce breakoints)9 n! M' e) j6 f( g0 E' c
1 P4 {' u. e& C" K
Each time you'll meet this trick, you'll see:6 J: L( K+ h* h/ j$ C' V. z
-SI = 4647h
l3 n7 d4 W' D$ L8 E-DI = 4A4Dh
( L" ^+ T( R& f% B' X7 I/ L" EWhich are the 'magic values' used by SoftIce.# [% d( a" e0 V8 ]3 C4 L
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
" L* N8 f" s2 g1 Z; u* Q3 b, V6 M0 F6 {: p* A. N
Here is one example from the file "Haspinst.exe" which is the dongle HASP
" \( k; N. @; l* V0 z6 e. @1 qEnvelope utility use to protect DOS applications:
2 [/ ~" L* e0 }7 f6 o: H: `
* J' Y1 X$ m4 c+ Z$ M" J
' y: q+ s/ g1 h' }' b9 s- a4C19:0095 MOV AX,0911 ; execute command.
8 ~* K5 z1 F& g7 e4 V4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
! K& B( n! a! H- b) {4 C) ?4C19:009A MOV SI,4647 ; 1st magic value.. N9 u6 r; |' Q, _2 t7 |) ^
4C19:009D MOV DI,4A4D ; 2nd magic value.* v7 J% U4 w9 E, E2 R
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
8 m( u0 Q+ I- ^% M" \; h( L4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
' a: B7 i! x* R# p! i# _4C19:00A4 INC CX
6 \; Y8 r' O4 V3 c. `4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
- i3 e* }# `% x. h1 h4C19:00A8 JB 0095 ; 6 different commands." I" Q% X5 B* N* t; b
4C19:00AA JMP 0002 ; Bad_Guy jmp back.8 T9 w7 C* m* q t
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
/ Y# P! r6 i8 ~/ L+ \
/ `6 u6 h5 j9 Q: h$ R% hThe program will execute 6 different SIce commands located at ds:dx, which
* J9 ]7 F. c" {8 Jare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.1 |+ m- l( ^' X4 G1 \
9 ~+ C8 l$ o3 A) R
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
8 j+ T" o* O- U) P! Z+ b___________________________________________________________________________
. g& z# H; _) Z5 @' B' P* T! x( R3 u( `; s+ U- X: S
1 v2 g7 h" x+ S" Q$ _Method 03% k& T) A' U- E/ q. }4 h6 c
=========( U9 D' `2 ?+ Y
; f. S5 |/ p0 Y) `
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
5 }1 D+ v9 Y6 \& r9 U" ~4 X, u(API Get entry point)
( [6 ^9 {) n1 O" |; h: O
( O8 _1 ~$ W$ ^- F8 T: d
! b& R$ N/ ^( k xor di,di1 U5 L4 c$ P; [, b6 C5 Z
mov es,di( q0 r/ q: n) d5 \) d
mov ax, 1684h
2 r5 J* l, n8 x+ x1 j2 g mov bx, 0202h ; VxD ID of winice
7 M8 H9 `+ B9 X, X1 P3 ~ int 2Fh1 c0 \$ d) F3 x- l; e6 C6 {
mov ax, es ; ES:DI -> VxD API entry point
! [+ \ x1 ~9 _, y: m: X4 T5 G add ax, di! z M! F6 L: ?$ H2 v
test ax,ax, Y) M) y, L: A4 r! k& q) E' U
jnz SoftICE_Detected
+ z- q" |# G. E2 h7 t1 F* E, \; g+ P, T( G x- f" y& ~7 l- D
___________________________________________________________________________8 d+ A$ |8 L. L' A8 _9 W5 n
1 v1 a6 z5 I2 A2 j6 P! H. D; YMethod 04
3 Q0 r* R7 G# M2 h+ z=========+ I' q/ [3 W3 W
( t8 G* Z$ e( O; r$ |: A
Method identical to the preceding one except that it seeks the ID of SoftICE% m9 [4 Y: Z F9 v
GFX VxD.
! x4 K% L4 p& i
- G! m: Z* E) P7 }8 X$ z xor di,di
: G& Q' o5 v: ~5 @/ h5 ]0 k, E9 n! p1 M mov es,di
+ l" b" V: V. T mov ax, 1684h K$ q0 B s, n& f3 k
mov bx, 7a5Fh ; VxD ID of SIWVID" v+ v5 o7 v' h- t \- o
int 2fh
u5 M. ?; V6 W! d) q5 u mov ax, es ; ES:DI -> VxD API entry point7 C; z4 `# m7 D# k( S% [
add ax, di& q* O/ J; E" Z5 {! G3 Z# d8 `
test ax,ax" O& v! q+ y Y J9 G* z1 K
jnz SoftICE_Detected" k6 B$ `; Y2 c! I) @6 l2 b
2 W6 y' A# J: _) u+ \
__________________________________________________________________________
$ T: Y1 o* h+ i+ E% A+ t
0 E" s9 ^3 |5 i$ G' P( p. a- ^1 Q; O: ^( `+ z5 v4 p& J% d- a6 V
Method 05
) q' h& M* A- H! Q7 s! C8 \=========1 L$ T" F! o: m3 N' \$ Y" h0 R) \# S
( x, c% d F, S( j; v
Method seeking the 'magic number' 0F386h returned (in ax) by all system- _# ]" X ^; J0 m7 T8 v: b
debugger. It calls the int 41h, function 4Fh.
. B* |% U+ l1 qThere are several alternatives.
' N/ f8 ]9 k+ b
, ?6 k2 S1 |9 s1 J0 B9 ~The following one is the simplest:
+ o5 h1 `9 L4 h4 C1 k: @
" N! j. l. q H mov ax,4fh- g& C w3 Q3 w2 t4 ?
int 41h
# G. J, _" x5 _ cmp ax, 0F386
+ D8 w( l9 H4 C- f% e5 ~( v, q( @ jz SoftICE_detected5 |2 `$ O- T5 v
5 m" n6 a6 n; B$ v& o
; s6 g; j% J+ L3 F; h- [$ | ~Next method as well as the following one are 2 examples from Stone's
0 ~2 |: A- J% \% k" \' I! X; |0 g"stn-wid.zip" (www.cracking.net):
( }1 D: p3 `- Z8 Y" j
& Q( c5 ^# Y3 D6 T% u: w mov bx, cs3 N* q( a Y& f; f
lea dx, int41handler2, Q5 l% u0 `( G$ _8 \
xchg dx, es:[41h*4], x' j( D# u& K$ S" w7 X
xchg bx, es:[41h*4+2]7 @* Y/ b/ e, v- `8 R- H9 ~
mov ax,4fh5 B$ b4 o, c, u9 y
int 41h
: m: O' v/ I* L xchg dx, es:[41h*4]
$ N/ ?, C; M( k& d3 v2 n xchg bx, es:[41h*4+2]
# R; x, j* y, `+ q8 Y. {5 H0 `9 ^ cmp ax, 0f386h3 i M) v3 I8 |2 c2 j$ U6 q
jz SoftICE_detected
% \7 M- {) A* W; a* `5 G1 ^
# `1 N( n, V; _4 C% Fint41handler2 PROC0 p' K' o0 h! |3 L0 O0 v) {
iret# K/ z4 n _' v0 _9 @* @/ X
int41handler2 ENDP
5 ^# J) W) [! X. y/ G& a7 U& P, K" ~/ m7 k3 m9 t" @! g5 [
: B! l& w) O3 }! P5 D
_________________________________________________________________________; H2 B) i" ]5 ?/ G
# A9 m2 }! M, s' e; t6 t- x2 Q+ c; P2 z7 s3 O8 E. B# }7 E' E
Method 06" Q2 O: g/ K4 h" p
=========
/ G6 j. m% |! _
" Z+ J+ ], @3 Q; o% l( h7 ?( C7 y
* O# A M" X2 m$ [1 O2nd method similar to the preceding one but more difficult to detect:* R0 ]2 |+ }! r: V+ s
7 s' z1 T* L7 D4 k1 y6 g
& j* a8 p7 u) a% w! L# zint41handler PROC/ Z/ h# Z S$ O+ f$ x& A. ~! ~
mov cl,al; F0 N, |, V8 N9 F% S8 g
iret# t& y% Q" u& h, `
int41handler ENDP
' I: k1 u7 {" W- c3 P# y+ q9 n# D. S1 r8 k0 S
5 l2 u& L$ W. `/ Q
xor ax,ax- k* h- a6 a# v: b8 }1 `5 |# [
mov es,ax8 |- _( B/ x9 t5 y; d
mov bx, cs$ ]# J$ ?: F) L: W9 f' u7 T }
lea dx, int41handler
- ]# B5 `, h. `6 K, g+ h y xchg dx, es:[41h*4]
$ }% [5 J# H9 ^: ` b1 [$ s8 ?' H xchg bx, es:[41h*4+2]* t* [% _ l$ y$ M& t/ S0 m' x/ n
in al, 40h
( J y" l+ W0 G6 c$ |6 r xor cx,cx
$ I4 D5 a( P& _# ~) r int 41h2 J" Q: a: I" Y: } \
xchg dx, es:[41h*4]8 l1 O, _* C" k$ v# _0 i
xchg bx, es:[41h*4+2]
: o- U/ z& s I: v cmp cl,al$ S) O. r. [& e; X: ~* w
jnz SoftICE_detected
+ ^( J% X M# h& b) Y% X0 y4 ?/ k$ N
_________________________________________________________________________$ G* L4 b3 X2 B% w
) s" j0 g5 M8 i6 \" @Method 07- U" l4 d7 r7 ^7 C
=========- R" D. `& Q+ a' |& v& z) R
7 e% t: `, h0 VMethod of detection of the WinICE handler in the int68h (V86)- ?7 H3 e' T* @
* i R% U* h+ E% H& J
mov ah,43h) q3 c) S; j7 F7 u" Z% C4 s
int 68h4 M3 t8 `% _# Y4 Y
cmp ax,0F386h
0 S m/ R# m0 C jz SoftICE_Detected5 d4 N( A( A8 [3 F' O8 d
1 _7 m9 K4 _: G) j* z& {/ e t! ^0 l6 T9 L
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit9 t' W7 Q0 Y7 k
app like this:4 w% S& E, R2 e2 e. f
. ]# Y0 N6 d" W% ? BPX exec_int if ax==68
& S$ i0 u, f' i K: ]2 F (function called is located at byte ptr [ebp+1Dh] and client eip is4 r: \& f8 K1 R) r6 m" S
located at [ebp+48h] for 32Bit apps)
- ^! V% o9 p& A8 U__________________________________________________________________________1 |2 E% M% l+ s2 M* p
8 y+ V6 U) D- u9 Y* t
9 _& }# r% r$ j1 s3 x1 {Method 08
7 a9 D. S- x7 |8 F=========
" n4 v! k( d; S$ f! |; G% u% |& m
It is not a method of detection of SoftICE but a possibility to crash the0 I9 ^5 P8 p( O% l' p( m
system by intercepting int 01h and int 03h and redirecting them to another
. X) ^7 R- o j, Mroutine.
9 r6 F" d2 N8 f' X# M1 B1 J! l( mIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points3 F- u+ D; b4 Q5 J5 n
to the new routine to execute (hangs computer...)
: X( i6 t9 g3 ` e- A" m2 S
3 T+ R. ~$ B$ H2 H mov ah, 25h g, L8 L. I0 M, z* Y6 s' j4 f$ q
mov al, Int_Number (01h or 03h)3 h. L" U7 i. m6 i" @
mov dx, offset New_Int_Routine
" Z. y4 h; T- ~ int 21h& q9 o6 K9 U6 J0 |9 S2 V# q
7 q* l; b) K& _% C) a% S__________________________________________________________________________
: W! |. y& }+ R4 k- S6 _' e. [. Y- N# g
! L2 {! @8 e9 ^) q7 L; R8 ~3 GMethod 09
2 x* {6 r& M) H: c, R1 ^=========
$ q' N3 R* [. {( U! r
7 m" [8 j& X3 s, |; iThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only+ S9 G9 X9 ^- y+ k
performed in ring0 (VxD or a ring3 app using the VxdCall)." g; p$ U! b8 v. A' x
The Get_DDB service is used to determine whether or not a VxD is installed
2 Z* A8 V. s" D) Z: Y& A$ Ofor the specified device and returns a Device Description Block (in ecx) for
+ P% I1 t/ v) _, Ethat device if it is installed.
6 F% B) x/ j0 B- { z: @+ z6 b/ b3 c& {/ ^
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID, O7 u, J. `: d* k0 H9 X2 N0 K1 I
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
) u( u# e! N; b( D8 F& z/ }& o' X VMMCall Get_DDB. Y# A% I+ y$ ^: Q$ w+ \$ A
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
4 g+ H+ h4 n+ D( ?
# u8 u: i% L( A3 n F* t: y0 D6 Z- GNote as well that you can easily detect this method with SoftICE:3 M A1 x: Y5 i" {& Z. d
bpx Get_DDB if ax==0202 || ax==7a5fh( T* j7 W6 J2 A4 t' c" [
; |- _% s, e& X* O; n, L
__________________________________________________________________________
p3 S+ P2 l5 N }- S9 n. B1 t
+ T6 Q4 p4 e: {/ AMethod 10' n# }+ R& b( W' V
=========
$ ]+ S# `; ?0 A
* B3 s9 C: i, O$ N, A; m0 [=>Disable or clear breakpoints before using this feature. DO NOT trace with: U( @5 n) O- w2 m2 n% A
SoftICE while the option is enable!!
" V0 r: K, @7 r' g
' _0 |* Y$ D* d" g1 U- x k: W% j& SThis trick is very efficient:$ S% Y9 {6 S( E! Y0 O. }, D: _/ \
by checking the Debug Registers, you can detect if SoftICE is loaded6 h* O1 H1 m0 c8 H( s M
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
v& y$ J! y. Y) r6 t, e dthere are some memory breakpoints set (dr0 to dr3) simply by reading their" u T2 ^1 i7 V( L+ `
value (in ring0 only). Values can be manipulated and or changed as well$ n3 q2 k- F6 g7 A# m
(clearing BPMs for instance)
9 @) Y& k" G( l( ?- W3 c; r* |* @: A* p1 [
__________________________________________________________________________
- x/ G6 l8 o, g
( I6 Z5 n, ~! u. o. e0 u3 ^- QMethod 11
8 C' b2 D# T3 o% E+ J; X=========
0 V* m# ]; H0 p, r% Y$ _" P! `! A" j' s
This method is most known as 'MeltICE' because it has been freely distributed
' Y- w* n! M2 c) T7 Lvia www.winfiles.com. However it was first used by NuMega people to allow
+ H, i- Q) d- `Symbol Loader to check if SoftICE was active or not (the code is located6 F) q' @5 y# Y( A2 B
inside nmtrans.dll).
6 \2 d) i5 _- M* v. P: v2 X. Q/ I4 i2 j5 f
The way it works is very simple:9 E3 u$ H2 V7 Y U0 n
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
# j/ ^, P P9 a8 n+ _* E6 U# MWinNT) with the CreateFileA API.5 e. U2 W8 @6 _" n: e
, ]+ ^' H- `5 S1 [+ [9 \) |Here is a sample (checking for 'SICE'):' b8 k% F4 u2 y5 `
7 O9 R U3 x0 M, e% Q
BOOL IsSoftIce95Loaded()
" K# X) n. ]# W+ q) l: R* I{
: M* X) Z& e& z. Q HANDLE hFile;
1 K. _% O h- v+ D1 G* E. N hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
& W6 Q; Y1 c$ [. D- w. c3 v FILE_SHARE_READ | FILE_SHARE_WRITE,9 ?& i% y& S$ \# E' `* Z3 j
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);; n |: `- k7 _, g e
if( hFile != INVALID_HANDLE_VALUE )2 h5 \5 P8 h4 U, @
{
+ D9 J C$ [# L* N; J CloseHandle(hFile);. c1 Y3 J* K E5 A3 H& T# k
return TRUE;
$ v: T: q4 y8 u4 z }9 Y- T5 L% z. M- N y7 H
return FALSE;
8 d/ B7 a" U" {) a$ o [$ \}
4 m# n/ P1 b) d# l' o
- i9 e. C- u8 EAlthough this trick calls the CreateFileA function, don't even expect to be2 z0 }- K+ s5 f8 q! \
able to intercept it by installing a IFS hook: it will not work, no way!9 O, O: \7 h2 _' [5 i
In fact, after the call to CreateFileA it will get through VWIN32 0x001F3 J# d$ g" |# @
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
0 }- D: s6 [! L" v8 j& B' Mand then browse the DDB list until it find the VxD and its DDB_Control_Proc% b4 r1 x4 }/ C0 S9 w
field.7 I! D$ @4 ^! k9 p# f3 D
In fact, its purpose is not to load/unload VxDs but only to send a " F4 V8 t4 y3 H
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)7 C; ?. J& V( k q! v& O: e+ b! h
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
5 S( q: h6 W4 [9 }to load/unload a non-dynamically loadable driver such as SoftICE ;-).* K$ ?: b0 J2 h) U1 A2 l1 y
If the VxD is loaded, it will always clear eax and the Carry flag to allow
1 y# K! s4 W6 [! @) P. xits handle to be opened and then, will be detected.
8 K- k3 A: a( R# b0 H% I& ~8 cYou can check that simply by hooking Winice.exe control proc entry point
T' ]' l# u' g, u- s* O3 Ewhile running MeltICE.5 b/ _0 k( x8 O+ v1 N
: v5 d8 G% I9 T' }
i3 t) ?* o. S" ~: G' O: n5 |6 O
00401067: push 00402025 ; \\.\SICE
& @6 i! p1 {, t* c 0040106C: call CreateFileA
5 B A2 X+ W$ w! Y+ d- _ 00401071: cmp eax,-001' f& i2 h8 i1 n, x$ v3 D; v
00401074: je 00401091, T, F- [5 Q( M! p' |( T7 v- Z; @
9 A3 e: O" J" A6 J
3 [* E$ Z# q$ j4 D8 sThere could be hundreds of BPX you could use to detect this trick.( t4 [6 J3 d2 d; n
-The most classical one is:
& ~! y$ H2 F+ t- Y4 \* t BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
/ O3 r" [6 }! T7 p *(esp->4+4)=='NTIC'1 H; l2 \ u4 ^$ h- V$ u) U
/ ~1 y4 x8 @; x- p! s4 C0 X-The most exotic ones (could be very slooooow :-(
6 K3 W; A0 U, S6 B BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') ( R! d, j3 o; ]. j( o6 E
;will break 3 times :-(
& v5 E0 X. X% r7 b. J9 G6 i5 u' _0 D" d" Q8 L
-or (a bit) faster:
$ B3 A0 F4 ~1 ?! s9 ~% ?; u" G BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
+ n( `: {4 H1 \5 R7 Q6 _$ C V* N$ g( ?
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
' Q( Y9 c; R, y0 s ;will break 3 times :-(, m9 \3 I e. ?
6 S# b0 Y3 i# V5 a* {( Q; ~( V-Much faster:) \. e; S5 t" [* ]- y' j5 L
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'' Z4 k& p, ~( I% R7 F/ B7 Q9 Q" G/ p( [
3 t" z7 q: X( T/ FNote also that some programs (like AZPR3.00) use de old 16-bit _lopen" Y" C7 ^# v6 X( x
function to do the same job:
5 s) r5 W; E$ E: M8 k9 p" E3 k) \. Q W0 [* ~
push 00 ; OF_READ
: a+ N/ L: T$ S mov eax,[00656634] ; '\\.\SICE',06 f$ C$ m! }+ t
push eax3 i- j0 f7 R$ n" {3 t/ W
call KERNEL32!_lopen; b) [& Y! t+ e) F; t5 _5 T/ l; X
inc eax S! [2 c$ E3 A6 ?' {8 I d
jnz 00650589 ; detected- D E. l) i, q" P) ]. e
push 00 ; OF_READ
9 j) ~6 X8 Y' U6 Q H) w2 h9 M% { mov eax,[00656638] ; '\\.\SICE'
- E- b2 T* j( J) C push eax$ ^/ a- ?$ w, M N
call KERNEL32!_lopen
2 q- G7 V, g6 Y* q7 E" V& P* K inc eax
' d. v: ^* l& W# O jz 006505ae ; not detected
3 ]) i% I) Z; F! z1 J0 E" ^- Z" ~7 M5 n [; N
: Y$ k* Z- ~1 u) ? ~# m: U+ B
__________________________________________________________________________
8 w$ M% C1 O8 f! O6 x3 E1 ?; z
7 j4 |+ M- @2 Z: I: ~( ?9 \: x/ tMethod 12
( D1 G" T, k9 r/ ~) \$ S% B( W6 k4 N) H=========
# B+ s% ]5 H5 ?3 R- n9 m( R: t! @+ @( |+ O
This trick is similar to int41h/4fh Debugger installation check (code 05
/ U, c( f. C& D V! ~& 06) but very limited because it's only available for Win95/98 (not NT)
5 f v0 L: |& x. G8 L# I4 Was it uses the VxDCall backdoor. This detection was found in Bleem Demo.# ~1 T) U/ \4 n0 t$ |& t
6 r! O. L# b* o! H' v ~- x
push 0000004fh ; function 4fh
( s q2 ?& l5 a# J2 X push 002a002ah ; high word specifies which VxD (VWIN32)
# Z$ d) h( v A# ~0 w1 h5 i N ; low word specifies which service
" m9 b; G" ]$ r; t (VWIN32_Int41Dispatch)
! D/ \2 b0 ^& Z! n; Z call Kernel32!ORD_001 ; VxdCall6 r- G# }, V$ J V8 s$ F- N
cmp ax, 0f386h ; magic number returned by system debuggers ^$ X* W- i3 `, n
jz SoftICE_detected
! C) k6 g, |' g R# F5 H
6 U q% C- t# B; D% e/ KHere again, several ways to detect it:
6 r z3 l+ ?/ M0 q& E% e2 G# M: ^$ V5 y: X. [6 B
BPINT 41 if ax==4f% \* E+ @! J# p+ z$ a B" g& x
2 w! S; t7 j0 L* L3 w BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
0 B) U# v2 p( M P+ @/ n! q5 S3 g5 j l5 O; Y; w
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A7 G/ p9 \# A v* [( K: F( N
7 s( N- B1 b4 ^$ t l BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!$ l* Y V( j9 Q9 h# E( \
) D( ~% |" x9 F: q" }1 Y
__________________________________________________________________________
3 o) O( t& y" m. K" U" t4 n+ X( l$ W* v
Method 13
* J v( p0 ]" _ a% k=========+ j9 B4 W* W5 F3 t3 Q
( a, i5 F6 u( i3 f8 n0 R% s
Not a real method of detection, but a good way to know if SoftICE is
, M" N" N% c) a( ninstalled on a computer and to locate its installation directory.0 u7 q6 d e* B8 d/ X2 _3 u
It is used by few softs which access the following registry keys (usually #2) :* X Y* v* _- O
5 u6 H. T- K7 i& _0 l. E0 r( E @
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
7 E8 L5 G, \7 C u: k3 \" g( ^& F2 B! X3 u\Uninstall\SoftICE' K4 J, j3 ?. J1 @$ K; ^
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
+ v* F4 ?& M1 v, F1 T3 Z) `7 w-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
3 H% _+ T2 Q- _* P) e [; U; V\App Paths\Loader32.Exe3 L% ]! q, e. y7 r
8 P4 W# p0 V+ h, g: T- K7 r8 Y' B* A! q" w
Note that some nasty apps could then erase all files from SoftICE directory
8 p1 y g8 t9 v8 V. |(I faced that once :-(
7 d9 W, {9 Y0 x h! R# d5 U- W: ~: |& [# t; G
Useful breakpoint to detect it:
9 R7 h; X( l. Q, W! t1 { l9 Y
5 V) g3 M* [* C8 l7 G. F4 q BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
. s( R- R: s1 K4 R7 c; k9 n. I( l0 l7 k1 |! u$ h
__________________________________________________________________________
! n4 d1 H4 ~. A& t# G0 C7 M
$ ]/ v( D' a2 C7 |) m7 r F2 N) Y5 s9 i! M4 h8 }' ?
Method 14 & N I: k7 j' _. T. C
=========% ]' R* V1 F$ Y; s [# e
+ W. g6 b( x! DA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
8 q" K3 e, r& B) R4 p( Lis to determines whether a debugger is running on your system (ring0 only).
# u# V' H U9 S) d& J: A. p+ v7 i+ T& {: {- G
VMMCall Test_Debug_Installed
, \2 D$ Q# d) v3 Q je not_installed2 d2 {/ E5 Q( z$ u
: l$ K8 M* |: LThis service just checks a flag.) e" p$ M. m! _$ U: U6 U! _
</PRE></TD></TR></TBODY></TABLE> |