<TABLE width=500>% o) ]4 ]/ L2 Q
<TBODY>
% p- X! u- L7 i; W<TR>/ |" s# t E6 w9 [
<TD><PRE>Method 01 % x8 T4 W- e7 A8 l4 B3 b
=========
, x/ f/ j. q3 E5 k1 W% y
& \! c; ^+ A% [This method of detection of SoftICE (as well as the following one) is0 y+ Y: }2 y# |, T4 N* e' e# s% |) |
used by the majority of packers/encryptors found on Internet.
! t) j4 C0 S* }) m$ A' [+ q5 D) R1 kIt seeks the signature of BoundsChecker in SoftICE
3 b) v9 T* \2 O: H; ^$ k5 H, q0 h( \3 ~! j& K7 G
mov ebp, 04243484Bh ; 'BCHK'
% W+ x1 {( d) i6 u0 F. I mov ax, 04h7 g: B8 E/ @9 _8 m" R& {# v4 M2 R
int 3 ) @ D) i7 b& N f- i, R5 I
cmp al,44 V; [; V5 s/ o* m: S
jnz SoftICE_Detected) \9 T `+ [ F/ o
5 \ h$ r- f7 q+ q___________________________________________________________________________# ^; f. a! j: m! ~# D6 S: N- D
. a4 U2 }: b F" v
Method 02' I d9 V" r6 i1 Y C
=========
' w1 ?9 X7 j: l: `$ c+ `8 B4 U+ W( C8 X
Still a method very much used (perhaps the most frequent one). It is used
6 K1 \' u0 L0 f: Z% P* D/ tto get SoftICE 'Back Door commands' which gives infos on Breakpoints,- M6 h0 x. ?2 m9 @4 @+ o
or execute SoftICE commands...
' N& @+ k5 ^1 \/ L' QIt is also used to crash SoftICE and to force it to execute any commands( Z3 _0 j* Y& \) P$ a' e) o
(HBOOT...) :-((
( o* i n; L. u6 a+ K9 m/ B% \- Y) E0 ~
, A" h% E( x9 U" qHere is a quick description:
. ^9 h* R9 M0 H7 J4 @0 U6 B% V3 D-AX = 0910h (Display string in SIce windows)
. p- r; o9 C7 v-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
- U. p! V T0 f7 v8 t( f6 e& E; Z-AX = 0912h (Get breakpoint infos)
; K! t/ P4 `3 Y+ K4 `3 M2 z! N-AX = 0913h (Set Sice breakpoints)% H( l! z; U2 z% p S
-AX = 0914h (Remove SIce breakoints)
% n6 _ x* ^' O5 {. Y
) X( e' _+ t2 p3 u- UEach time you'll meet this trick, you'll see:" E H2 l: q+ F$ _; ~" O# ^7 q# |7 B
-SI = 4647h& m, E( `3 O z1 ~( X$ X# ]; W
-DI = 4A4Dh+ s- ^+ b/ [' E- h2 X
Which are the 'magic values' used by SoftIce.4 E# `6 q6 L8 A0 s! ?* s6 B1 v, f* W
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.2 c$ E% t' M+ s3 E4 R
l9 Q' u3 ]) A. S: q O
Here is one example from the file "Haspinst.exe" which is the dongle HASP
# w( Q$ g8 N- S. u, T0 CEnvelope utility use to protect DOS applications:
2 N4 t* c% P+ j: r- b% E
- z# t4 K" t9 K$ L9 X" }& S3 C: `+ S0 R6 A1 b7 O- O! b
4C19:0095 MOV AX,0911 ; execute command.
$ C: t+ P! c( h1 Y, V7 M/ a4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).. s. X4 F* B# S
4C19:009A MOV SI,4647 ; 1st magic value.
! d+ V2 q$ g$ J! R+ ?2 t" ]/ j1 |4C19:009D MOV DI,4A4D ; 2nd magic value.
# T7 c, a& w, s4 Y2 z4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
! i6 s: u$ o0 R3 G( |3 a4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute2 B4 }8 `$ V$ q& J, @0 R |/ i
4C19:00A4 INC CX* J+ V ]6 n M/ B" _7 C5 T2 @9 w
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
9 Q b' q3 |$ r0 \4C19:00A8 JB 0095 ; 6 different commands., P) u) Z( r7 b/ j4 a
4C19:00AA JMP 0002 ; Bad_Guy jmp back.2 ]& `* @1 V. _; }2 h! H9 n, Y0 A
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
( n4 F; l, N5 C( U# Z0 x h# V4 G7 G
The program will execute 6 different SIce commands located at ds:dx, which: F1 h' N; a: T% j
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.+ D d$ c# Z$ V/ h7 w1 F4 [
* V$ a, P' X3 }" L
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.% ~2 C `# d" {! ?1 L7 n' B
___________________________________________________________________________$ ]6 }+ a0 s+ d! y- j/ {! }) b
" i2 u! A- s' ~0 f5 ]+ O3 e+ r
0 d! \ w) D$ ?5 P( `5 Y
Method 03
! k. R- G1 Y2 E- _* _" D9 `/ ?3 f=========2 j2 p/ l5 C" t- w2 v. A
) t. \( @2 L ~
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h5 o) p) L5 ?$ x7 j* V: A
(API Get entry point)* u; N: J& A1 R
7 c4 C: W( n- T% B9 ^( }& ^0 _* `4 w0 K/ m% O8 N6 s
xor di,di$ K1 ^( u) l4 c5 a' V& b/ l- H, w
mov es,di8 `7 b3 f' Y# k& ?7 m' p0 P
mov ax, 1684h
% u( P7 y1 ?" `! S mov bx, 0202h ; VxD ID of winice+ J9 x' R6 Q/ x
int 2Fh8 o5 b& ?8 b; D% E+ |
mov ax, es ; ES:DI -> VxD API entry point
% a/ t# {" H6 A+ z) Z add ax, di
% \/ Z3 e1 @4 | test ax,ax# j) K0 P F, t4 m2 C: \' \
jnz SoftICE_Detected
7 [3 o( i* J. D& M, A9 l3 o* F' k/ Q1 o h, O4 t
___________________________________________________________________________8 A o0 Y B- Y- F" f* ?4 L
9 i& j+ ]) t, m# ?
Method 042 c4 `7 n5 S% _+ Q
=========
) q3 h$ T x0 @0 [8 k
7 g6 v) Z- b4 ?+ k6 g/ R5 yMethod identical to the preceding one except that it seeks the ID of SoftICE
: h! F0 D$ _* ~1 N- Q, tGFX VxD.' u4 `: x$ X. t& H. v
" k# O- H# o' H* f xor di,di; z3 }' b+ E) e( ~9 v1 |
mov es,di V4 F- t6 C9 k9 O2 D
mov ax, 1684h 1 S [0 c* R, a7 W5 h4 m
mov bx, 7a5Fh ; VxD ID of SIWVID: ?% @0 u- j4 x& o$ Q8 B
int 2fh. u! C. L7 ?: G& A) f; E, z6 A, c
mov ax, es ; ES:DI -> VxD API entry point0 a0 H' q& l9 x0 q
add ax, di4 R3 z( [1 Y4 U& C8 D* m! p& b
test ax,ax
- [' m8 Y: {% R( c% s$ X, P) ^' N jnz SoftICE_Detected5 |* S( u' y& g) P- j
; n4 ?& I( Z( a' z0 |2 n; `
__________________________________________________________________________
5 Q6 o7 |% ]# |
% ^1 S, e$ }1 u5 ^( p% o" b( f& m! G3 Q# D
Method 05
6 O6 u, i& G3 Z7 y4 G" t( v=========: |' G+ k! m" c: L2 w
7 t0 [) Y, M% j* k
Method seeking the 'magic number' 0F386h returned (in ax) by all system
6 v. C; j* G; N T/ ?2 q2 Q9 hdebugger. It calls the int 41h, function 4Fh.
0 C( D, S0 T, R* D, {) UThere are several alternatives.
* H: z$ O5 q0 R& F0 E/ ]7 n$ h, t( E' h$ h& l" L
The following one is the simplest:, c" V& \# Z0 W
$ E6 U/ q8 c$ S5 R D8 ~# e mov ax,4fh
. w5 l* ]- L3 B) P9 f9 }. L int 41h \" j$ ^, Z4 h; t
cmp ax, 0F3861 {0 p8 \+ n1 k& a! y. \
jz SoftICE_detected. n6 C' {- G* t0 \" \( Z9 A, z
6 ]& v& p% W I6 J- j) {
+ ^: a" F% U4 z+ ^" RNext method as well as the following one are 2 examples from Stone's ) G3 E4 J( ~& F) Z
"stn-wid.zip" (www.cracking.net):
2 h; L; L5 p6 b+ N( ~& M i
' I5 f- g% i4 C mov bx, cs( v1 G7 F* A0 g; X' o: C
lea dx, int41handler2
1 L' K8 @$ `; U8 V xchg dx, es:[41h*4]3 P# X# b! E( v: H5 h+ d8 Z
xchg bx, es:[41h*4+2]
7 _( N0 M2 i6 b! }7 g mov ax,4fh" \; k# J( B/ u9 k8 l
int 41h! O) h0 g; @; Q, B9 e/ }% p
xchg dx, es:[41h*4]" k& m+ X3 n$ p2 n* Q) C" f
xchg bx, es:[41h*4+2]
) K z. g; R7 O cmp ax, 0f386h: I8 Z6 `! v! S7 @3 z; s9 i5 o
jz SoftICE_detected
4 m& J4 ~: F' Z B) o" b% q: }) L- q% S8 {* n
int41handler2 PROC
& s3 P, Z. X. ^ iret
! a" k5 w" T* ] V2 _. Q& [int41handler2 ENDP% k! F \5 \( }" E7 |4 Z$ F1 d
% r) y8 @& r( C& p, B3 m
- O3 I# w/ M! u- G' o_________________________________________________________________________
1 ]- L1 z& B, T6 w8 N$ U7 y' v8 \" u
8 W# O" ~: {) a: l5 uMethod 06
3 s+ _2 ^& q8 B& w' E=========8 p& S' q" E$ m O0 n7 a
4 C1 l# {) T) ] ~+ @! @
& q; q) H( _& I4 v6 J% z2nd method similar to the preceding one but more difficult to detect:1 j, I( _2 L* I1 y( q
& m2 }/ n) A& N n+ S
1 c: r$ B( x% ?5 Oint41handler PROC. i. s3 L4 B# M2 w
mov cl,al
$ }% M/ P. r& ?4 c iret
2 j- J \; O$ H# sint41handler ENDP: A" l1 M" U) J* v
6 R3 _& j, p! p) t4 L; [* n9 d) W
( a, L5 E( y6 N9 ] xor ax,ax; \1 `8 I# _1 i$ @) J
mov es,ax
; K8 B* R. I0 w2 I* _ mov bx, cs
8 q3 ?, t/ K' C" F3 q lea dx, int41handler
' h: n# R' f p$ h7 \# y0 z9 X xchg dx, es:[41h*4]0 E: Z, v. b" u0 s7 j) B- W# Y
xchg bx, es:[41h*4+2]
) s+ \- o. J* Z. B% K9 h' K in al, 40h, A" H; j9 k+ {# j2 j2 P
xor cx,cx
. A$ u4 @8 T2 H& b' S int 41h. d: ~2 _9 u4 L% x. `* z, G, f/ ~
xchg dx, es:[41h*4]& a+ k& c0 d; h. E2 v
xchg bx, es:[41h*4+2] ~* }. ]% ^4 X4 u, q* I
cmp cl,al$ T% e5 Z3 {6 ?+ |8 I
jnz SoftICE_detected
2 {* X1 C" V5 S+ \3 ?* ^
+ i7 }" }+ D# \_________________________________________________________________________- L5 ^/ J! u; J
) D* q0 @; P& ~1 C- dMethod 07: }5 w0 T" g2 K. |# L, x4 N* j
=========, W+ M6 }; ]' ^1 v
- o, N* ~' _2 z$ A0 |3 pMethod of detection of the WinICE handler in the int68h (V86)
' a! M. g) H; c: W$ C) v3 s& s
) Y ?2 J) Q, R' e. W: \3 R( x mov ah,43h3 a1 E6 l4 k3 C7 H
int 68h# s7 c. P m) ]" C. s
cmp ax,0F386h, {% u: D7 Q' V
jz SoftICE_Detected g2 D# \/ a0 q; p9 E; ^
! O! e1 Y5 S% l, E: r( O: Y+ b. }- N% `
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit! N) l. ?6 I0 }/ S
app like this:
& O' b* k5 M. |! ^) }( E0 L: ]$ L- h+ m) l* q) b; P& Z
BPX exec_int if ax==68# ]1 l3 F, x$ ~' D+ f- C# s* O
(function called is located at byte ptr [ebp+1Dh] and client eip is0 F8 h, g7 V2 C3 ^
located at [ebp+48h] for 32Bit apps); J* z, M) a6 @3 P
__________________________________________________________________________) C- }7 J( t! }1 n
8 P1 c8 z! z0 ?: l
1 e% x6 J6 q3 p: H8 B @9 s
Method 08
( n; E9 G/ G$ \' f% { K=========
; ~: _ @4 J: u' V6 U" h% [9 [ j2 y
/ `% c3 o5 \! y" `* C3 E8 n/ UIt is not a method of detection of SoftICE but a possibility to crash the
4 T& u8 I S) F7 h8 B0 Xsystem by intercepting int 01h and int 03h and redirecting them to another
- P! P4 S! U4 j! X! Aroutine.
3 _. {" |0 M1 |4 B0 `$ F! RIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
: {) h; y) ?" w. ato the new routine to execute (hangs computer...)
; ^& f' ^) U7 i4 k5 G' z3 m$ @4 p' t5 N3 ]0 j5 }8 j
mov ah, 25h
! s* H' M2 {& r: I6 d) {$ _) t7 Q. Y mov al, Int_Number (01h or 03h)
" {) J3 b: a! d5 H7 s mov dx, offset New_Int_Routine
# @3 M9 G K* _1 Q int 21h
! `8 i5 Y) D ~5 Z- A) V. i
# g8 q4 X% D( ___________________________________________________________________________
3 Q$ J4 z, f2 C$ Z8 f
+ `% R8 ?+ O( A6 Z vMethod 09. W, x# G- o1 B1 z x4 n3 F0 \
=========2 R+ L- ^: ?0 q
/ l. D; C' B r* h+ KThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only5 O- L" j. n' {5 c, i
performed in ring0 (VxD or a ring3 app using the VxdCall).$ s6 G- h5 n6 {$ K& w) S0 X
The Get_DDB service is used to determine whether or not a VxD is installed4 F6 [$ |! o* k/ s; r$ o# i4 b
for the specified device and returns a Device Description Block (in ecx) for. _% |% O0 X: n+ K, A/ C' A
that device if it is installed.
( _3 x% g& w4 E7 [! o" Z
+ W, N3 c0 V5 T# {& G- B mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
4 Y$ i# |$ A) \1 F3 N mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)6 s% L" P% V3 j, t
VMMCall Get_DDB& K6 U. E4 n0 v9 _+ v& X( ?
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed" j. B% k9 x8 M$ K- c0 V' y
1 Z( y p9 g c8 I2 ^, U
Note as well that you can easily detect this method with SoftICE:5 @. e% i9 e) s1 o# f% L7 L
bpx Get_DDB if ax==0202 || ax==7a5fh
; \, R/ g5 p+ D E2 g2 r( P8 }) ^1 }4 Y1 t- d" o( L
__________________________________________________________________________
( {. Q) F/ }1 T: ~4 L( B9 o' |+ z! C; i+ T
Method 10
" N7 Q* m& B2 r ~, a0 k4 i1 o* y=========) m5 d& K1 N& h
% a% p5 z9 O) c) U ]=>Disable or clear breakpoints before using this feature. DO NOT trace with) j9 Y# C8 Y( l
SoftICE while the option is enable!!
- ?* i! f8 O8 I9 o* H
% d6 w8 [ Y4 j; s" A! a& _This trick is very efficient:
0 [! q( [5 a) Cby checking the Debug Registers, you can detect if SoftICE is loaded
1 O/ |2 k" y1 I' H(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
+ T6 W& f: v. xthere are some memory breakpoints set (dr0 to dr3) simply by reading their
( h! E/ K1 X$ P. x) Mvalue (in ring0 only). Values can be manipulated and or changed as well
. T; [2 ~ b) c( b3 ^0 Q* A(clearing BPMs for instance)
5 H& h! g% e- w
- p4 q; Q0 v2 I% D" u__________________________________________________________________________- p1 c! P0 X# F! c' O. F$ C
. C6 l: h/ y, j4 e! Q" ^Method 116 p/ J; I6 x% Q0 x9 i7 {
=========
! S0 l- S. _( n$ }/ O: w9 H3 ]4 O' A$ r) r1 H% u* ?8 R- H7 _( g* I
This method is most known as 'MeltICE' because it has been freely distributed
, P1 l- e9 T8 p" c) v" Kvia www.winfiles.com. However it was first used by NuMega people to allow d' B) }3 v! X9 _8 t# {& P5 \: H
Symbol Loader to check if SoftICE was active or not (the code is located
/ P4 D8 F# n, s' d- L/ D! oinside nmtrans.dll).! H; u" B6 l X* |6 w
1 U6 R4 e D N: X* b0 T
The way it works is very simple:+ [2 q4 A% j* }8 B
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
! {% U: a9 @# V3 @+ ^6 c& ^ c: ?WinNT) with the CreateFileA API.
- N6 D4 w; M. P& O3 F
# A& u2 i% b9 z: \0 R5 VHere is a sample (checking for 'SICE'):* P/ q1 M: f8 {7 \3 n
4 F% d) v$ @- K
BOOL IsSoftIce95Loaded()
5 i; X8 r6 p) x- u" E& Q v{$ c v D+ L! C o8 U' ]5 [" ^& c! X
HANDLE hFile;
+ M7 T8 h1 k% a- V E! N% } hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,6 r: g& J( l6 e& K* `' e4 H
FILE_SHARE_READ | FILE_SHARE_WRITE,2 P4 C6 ]3 c6 f. R
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
- q& ^9 F6 E- e# ^% P# O; q if( hFile != INVALID_HANDLE_VALUE ); D# i: i1 s# `* n; f$ }! ~' D
{+ L. E/ Y# I) ^$ J: F$ j, l' i4 W
CloseHandle(hFile);
7 V4 i/ F) M% D return TRUE;+ g# G( z0 b) C- O* O0 G
}1 w( ?* B5 y' W+ T! N
return FALSE;
' I: F* G; Z& \. @- C}
0 D+ I! E" u# F9 r; t) K+ K+ t5 R( o9 F
Although this trick calls the CreateFileA function, don't even expect to be9 m; b' l M3 X, [9 k8 P& h
able to intercept it by installing a IFS hook: it will not work, no way!" V) [1 D) V, S& }
In fact, after the call to CreateFileA it will get through VWIN32 0x001F V" F d6 H) b; a) n/ j" H+ I- m
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
( p9 q0 T7 Y6 D1 e. Z' P# ?and then browse the DDB list until it find the VxD and its DDB_Control_Proc3 ~1 |: q: O4 K# f$ Q
field.
% {4 o) h. _4 t8 |In fact, its purpose is not to load/unload VxDs but only to send a 2 z! \( N7 @6 h' L- }
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
! q. _) L; n m% Tto the VxD Control_Dispatch proc (how the hell a shareware soft could try& V1 `" W5 U, m
to load/unload a non-dynamically loadable driver such as SoftICE ;-).4 Q! A& m& o8 O1 D
If the VxD is loaded, it will always clear eax and the Carry flag to allow
" L: B, i; N: cits handle to be opened and then, will be detected.8 P* r1 x% d3 P3 F, i
You can check that simply by hooking Winice.exe control proc entry point
6 K' p% u8 z1 v6 ]( N. Fwhile running MeltICE. l8 W! d# p' e9 E$ g. a
+ c" \6 h, A& y# U$ t9 V$ A0 \: |& K) _
00401067: push 00402025 ; \\.\SICE3 X' R1 M, X# p/ X" n3 u
0040106C: call CreateFileA+ H& v9 q# P* p& O' M4 V. j
00401071: cmp eax,-001
) J& i; H3 ^( z& L2 R 00401074: je 00401091, B; b, x# {6 n5 C
4 a1 ~0 n; ?- q8 K' Z2 s- F* E6 P6 f' E: m ]. R% y* h. T
There could be hundreds of BPX you could use to detect this trick.
2 k" k2 V) c6 m# B) j" j% k7 |8 C-The most classical one is:
/ ?$ N, b- [& \+ o BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||- ~( T c: X# J7 T5 P
*(esp->4+4)=='NTIC'3 V' S; w6 q$ I3 o5 ^) k. a; l5 K
4 d' p1 n' G" X
-The most exotic ones (could be very slooooow :-(
2 @: V( m k* _8 _2 U" m3 _ BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') " D. \8 @7 f' `3 ?/ L/ N/ A' C( T8 C
;will break 3 times :-(
( m0 Z9 `# s7 P( @; f) T# X$ R* G+ A/ q% x+ V
-or (a bit) faster: [+ H3 T) [2 N$ q. ?+ r$ @
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
! I* Y; x( _+ F& u/ e2 L* r( I. T6 ]
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
, f0 |2 V! i% P8 A; x( S ;will break 3 times :-(
/ ^: p1 y$ _" I+ [5 `. m
7 y+ e- {. a' S-Much faster:5 e" l( F, ]) y3 {; m
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
( G+ Y. j F$ O6 ~) d% t
8 M, E- X3 U$ h4 RNote also that some programs (like AZPR3.00) use de old 16-bit _lopen1 I+ b- H1 T- p0 R$ o9 w7 m; P0 `
function to do the same job:; G8 }: p5 R2 X# |
/ Y. e" `& J2 a! `1 h# g5 |# U
push 00 ; OF_READ0 i: a7 k" [+ m- r- l( H3 ]7 _
mov eax,[00656634] ; '\\.\SICE',0% g! [. t7 i4 k+ ~* D; A6 v Z
push eax& t; Y; f8 ?) R. k5 c" p
call KERNEL32!_lopen
# D! k4 g6 P" O- I0 A inc eax* e& u4 v& T& m( n8 ~. ^0 D
jnz 00650589 ; detected
5 O) w2 M4 E- s! m9 ^$ V push 00 ; OF_READ6 S e. U6 ]# c8 Q3 }
mov eax,[00656638] ; '\\.\SICE'' i% T7 g8 [" I. C6 }1 N
push eax, n5 `0 y$ h$ [$ W, Y# f
call KERNEL32!_lopen7 N- S( U' E( O$ h9 Z; z
inc eax
4 z( c* z9 A/ X) Q- D, D jz 006505ae ; not detected
}! U! ?8 |7 c; k# E: a0 H+ ?( m" u6 s! A" J
: D6 }# `" x! g/ U__________________________________________________________________________
" { H# b$ x' I
2 ]. \, k9 F0 I% z) ]* v( pMethod 12
* t2 A+ v$ L5 w) ]=========; D: K- s5 z: s! X
& g) Z6 }4 u! v
This trick is similar to int41h/4fh Debugger installation check (code 05
1 ]. q4 b M/ E7 Z2 V- {' I, B& 06) but very limited because it's only available for Win95/98 (not NT)
% a) V- n3 g+ W1 B5 D8 eas it uses the VxDCall backdoor. This detection was found in Bleem Demo.& g1 z* U& \' i% F
% o) E J- n% [$ [& P( i( i
push 0000004fh ; function 4fh
' o$ c, |0 k% L! b: a% \ push 002a002ah ; high word specifies which VxD (VWIN32)
. A! D6 I9 Z+ D S. S& V ; low word specifies which service! N( F! m( E! v: M# E$ E
(VWIN32_Int41Dispatch)
8 l! C3 P' p7 _! E1 @ call Kernel32!ORD_001 ; VxdCall
6 @( W8 Q6 W6 p; | cmp ax, 0f386h ; magic number returned by system debuggers
% y! a. n' V, U8 H# V4 m4 h jz SoftICE_detected1 q; V- E) t" E5 H8 C% \ W
/ l0 v: {$ @* X' L
Here again, several ways to detect it:
+ V- g5 q9 @" G( u" y" u
$ ~1 _" b1 K' X BPINT 41 if ax==4f- R- G/ b3 a% a4 `: }) J" j7 A7 o
2 Q- p, U5 V/ i% N( @' ?
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one( P9 d3 }9 q% Q$ i
4 B2 ]% {3 d) P3 F, b3 D
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A+ K1 A; ]7 i! g. D. H
' G9 H/ ~, I- i5 ^7 ]2 j- O
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
: k) h2 }" A0 V1 d+ ]$ |) h
3 M+ h. E+ \& W+ }" V( z__________________________________________________________________________; {! s7 H* y+ w+ J( h
4 X* p7 s8 _% p2 X
Method 13
, `; o# U0 h1 Q+ @=========
8 d G8 f8 A) e# `) A
. k7 K' n3 `* U d0 kNot a real method of detection, but a good way to know if SoftICE is+ ^# _5 ?: S' D
installed on a computer and to locate its installation directory.
, N0 O; e1 s) X# d3 z0 `( |8 F2 nIt is used by few softs which access the following registry keys (usually #2) :' J' q9 a+ y% x" B. \
* v/ a" C6 L- \. h% p6 p
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
+ S# m" y0 |* z& z, X" U e3 w\Uninstall\SoftICE- {* f+ s/ @4 L
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE+ M- w' Q, Y0 o2 u: G
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion# m" M x0 \3 K# \ [
\App Paths\Loader32.Exe! @7 f: U2 t& x a. M
- }) x4 |2 H' w7 a3 A0 y' W3 t/ o. ]! Q" `
Note that some nasty apps could then erase all files from SoftICE directory
, G6 Q- @4 i3 ?6 d/ V- D1 L n) Y(I faced that once :-(
' [) `+ d7 Q, m4 b+ f" z) g
- `. I N& l1 s! }# ~) xUseful breakpoint to detect it:
# r0 p8 L! X6 ?: s
8 [. ? `5 l% K" @4 Y2 F BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'% A2 n& m' a: Y/ @) {2 H+ |
- ?9 X$ S1 Q6 i4 \3 E
__________________________________________________________________________8 K0 U/ x) D- I$ _
+ F5 t ?2 N* w0 e$ ?2 S" o1 f; c# r$ w1 b1 h( q* I
Method 14
" D6 ?9 K+ t# J5 }6 X+ }=========
* R8 h1 h1 A) n+ h% g4 |, M P7 N! S
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
3 T7 v @# J( ?0 \% y& W- s' uis to determines whether a debugger is running on your system (ring0 only).
- u; K' a4 B" f& j+ u2 t& x. u" r5 ?! f( K; ~0 w. H
VMMCall Test_Debug_Installed) Z! Y" c% {% W) I
je not_installed! ~8 P3 G5 N( K+ b8 T8 |$ r
7 r' ]+ v& j+ V
This service just checks a flag.
! c- g- q$ M9 D</PRE></TD></TR></TBODY></TABLE> |