<TABLE width=500>+ ]( g7 J# q- ]
<TBODY>8 B; W7 U% ]# [2 L+ }- j; o
<TR>1 }" E+ K- P: D7 y1 s, Y
<TD><PRE>Method 01 ! A: P2 B7 E, P: c1 V N1 H
=========
# ? ~+ Q& J( z5 x. X3 I: |+ I/ ]# u
$ c9 J$ D3 m2 M5 FThis method of detection of SoftICE (as well as the following one) is1 f2 X& L$ d! l# H: G
used by the majority of packers/encryptors found on Internet.
/ ]5 a8 E2 Q' |( [4 T& f! JIt seeks the signature of BoundsChecker in SoftICE
0 Y1 W) u7 F- z. [0 T8 b- z, [" q' g( M o/ ]5 e
mov ebp, 04243484Bh ; 'BCHK'
5 T4 s: f0 d, P0 X; A6 m mov ax, 04h
; g6 X. p* I# S9 x int 3 % R+ @. B5 V: T0 y' ?
cmp al,4
! d* w4 x3 A/ y. h% y jnz SoftICE_Detected: q8 ^1 S' O/ G' E1 L
% ?& C8 p3 [" T1 H7 k9 S+ b___________________________________________________________________________# `8 W/ I: {$ [! }8 [* v) h
6 `; |9 r8 C) U3 o6 V1 g: M/ cMethod 02: K; `# D( g1 w- Z2 M3 v$ ?( A6 C
=========! Y* c2 B( D7 }1 A8 {* k& J: H, _
2 Q8 E" w6 O8 l5 Z0 t6 d) R
Still a method very much used (perhaps the most frequent one). It is used
4 X2 q6 m- K+ @8 l0 N7 uto get SoftICE 'Back Door commands' which gives infos on Breakpoints,/ `+ `4 p3 I3 V; m
or execute SoftICE commands...
' [. h0 a5 K. Z S5 {4 u' CIt is also used to crash SoftICE and to force it to execute any commands
7 c" O4 e. R0 H3 L* T* ?0 c4 j1 v(HBOOT...) :-((
0 V3 t6 _2 ]2 ~0 n3 S0 d
& z# \* t7 K* qHere is a quick description:% h. K# }9 N' v( ]/ O. M
-AX = 0910h (Display string in SIce windows)
0 M' k4 N+ Z" L# \' c( m-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)" q6 G2 I% E# k* V
-AX = 0912h (Get breakpoint infos)
, |% o. u- h/ l% s$ l3 P-AX = 0913h (Set Sice breakpoints), @3 ] i; c- H/ D+ R1 u9 f6 W
-AX = 0914h (Remove SIce breakoints)
- n! q7 H( K* v/ q1 q0 p9 _9 h# n
6 Q; [- x; ~( j* k! k; p/ [6 iEach time you'll meet this trick, you'll see:
3 U: D" ]7 m. _2 X% y( z' ]-SI = 4647h o; p; _9 _' R, H$ e E
-DI = 4A4Dh
! S5 F2 V) P4 I9 k2 z: \" h1 |Which are the 'magic values' used by SoftIce.
9 l- \+ ?0 s t. bFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
! e: j/ }/ `/ w# M9 r$ a" f& ?( a6 f) P5 g3 N5 S v! {/ X* d7 e/ @
Here is one example from the file "Haspinst.exe" which is the dongle HASP1 W4 `/ A. m$ H
Envelope utility use to protect DOS applications:1 x. `; ^' W; E# H
9 [+ e; P, H. K7 f7 o- [/ g
* D: V6 L0 {( g9 K1 R4 y7 @4C19:0095 MOV AX,0911 ; execute command.8 Z# S4 ?7 \ O9 Z( {
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
: z$ Z# g7 T% D) B4C19:009A MOV SI,4647 ; 1st magic value.' D7 y/ a$ [2 f' n9 T
4C19:009D MOV DI,4A4D ; 2nd magic value.' [8 L' Q7 y. s5 k" ]' D, R4 _7 z
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
& ]$ A j& O: t% w" g/ l4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute* h' c5 T# g/ r8 _
4C19:00A4 INC CX
' b. h8 w6 M1 g3 r9 Z4C19:00A5 CMP CX,06 ; Repeat 6 times to execute* M. Q( ]- _$ E
4C19:00A8 JB 0095 ; 6 different commands.
4 }- v$ [2 [; r9 x/ A/ v& X4C19:00AA JMP 0002 ; Bad_Guy jmp back./ H, b( s4 L3 g& c4 ]% F4 v6 x( h
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)) b5 E& [2 u7 L9 B1 S( _7 Y
$ r: o/ {, W! J! `0 e2 z7 t; {! |The program will execute 6 different SIce commands located at ds:dx, which
- c6 k) a* L$ W! ^1 eare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.$ w& p) O+ I# i2 } }* V% c
! c3 @( v: v6 i4 c7 Y8 N! M' c
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
+ ^; B2 z2 y( y' g9 T___________________________________________________________________________
% K. i! j% D: Z* R) ?
1 q0 B/ c' t5 `8 _6 Y: _# \ l7 ^8 K( W1 X* x$ w& p, F# s! Y
Method 03
( r; }# I2 d+ [ E; Q=========. ^% @: M7 k1 q$ ^( ~- B6 p
5 X& [* L4 H, k9 m7 wLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h% ]0 w( C0 E! d2 I; U& _
(API Get entry point)8 F9 }. K6 |9 Z+ C
+ U R5 U# |2 S$ t$ Q
4 [" _1 b0 h4 R6 j# E" k
xor di,di" ~ L3 \$ ^" Z; p" [ N4 U1 ^
mov es,di2 k9 j1 b7 g; H# X, f" K' y+ x
mov ax, 1684h
+ E( y- n' _) R& |1 K mov bx, 0202h ; VxD ID of winice/ \9 g( p8 [. x6 i X" n
int 2Fh
- B% h* H2 K4 ~& h( v) g: J mov ax, es ; ES:DI -> VxD API entry point
; C' k" N3 N. s/ ^* p add ax, di! C6 @/ D( F# e, h
test ax,ax
5 }" \- {/ Y$ [( q0 W jnz SoftICE_Detected* e2 ~) }: ]; f/ ]
- K7 U) D6 A: `) \4 C% J___________________________________________________________________________
7 N2 |! u7 y8 |- G1 v0 R4 s, w! u3 q
Method 04
- C) b) G4 {% x" G2 u5 w% d=========, Z* J5 R* Z ~0 |: |! ~% C) e3 i
$ I( i" M) E0 c' L1 kMethod identical to the preceding one except that it seeks the ID of SoftICE& t6 X( p \1 ^9 k8 | F6 s; P
GFX VxD.7 N+ U$ S! G+ l0 T) Q
3 [& L, ]+ n; c# L8 t" @ xor di,di9 a* i& H3 y; b' ~4 z
mov es,di5 S9 `, [: J' S3 {
mov ax, 1684h
, I! N2 C( N0 I# V$ V mov bx, 7a5Fh ; VxD ID of SIWVID
$ Y- K* T: p7 B Y5 v6 _ int 2fh! B5 A* H/ C: ^- k
mov ax, es ; ES:DI -> VxD API entry point
# K5 C1 C, h9 }8 Y1 Y4 t5 W add ax, di3 H2 K1 _6 Z* y3 t4 \
test ax,ax
5 }- l$ h- D2 s0 R+ G jnz SoftICE_Detected8 u* m( M. a1 F. F9 y5 Z5 B
: A T% I+ k$ S+ `% V' ], E
__________________________________________________________________________
7 g) }0 B6 }- x7 q8 `6 z
2 Z- l* {" v- u2 d$ q( ?+ j s, B; I; x/ ^8 `0 A9 l% n- L
Method 05. B7 p! [; Y) A- n" m5 L
=========
5 F4 g3 B( p# B4 w, a0 y& J" P4 `/ ]! y5 z8 C
Method seeking the 'magic number' 0F386h returned (in ax) by all system8 b" p* H' D. e# u- y. ]. E9 t
debugger. It calls the int 41h, function 4Fh.
! f# J7 g$ ?: lThere are several alternatives. 0 M3 i9 H3 Q+ F8 S# X( I* {; D: v
3 g3 X2 K* s% D
The following one is the simplest:
$ Q1 p! H/ p0 |1 [, D1 m* s
6 V& C( {/ E* I* a6 C" Z mov ax,4fh' w1 z4 D& C# O8 i
int 41h1 A9 [* H6 Y3 M# s
cmp ax, 0F386
0 j- ]- U% e+ M0 m jz SoftICE_detected1 q2 ], D$ H! S) N
u& w) P A: m l5 D/ ~, H9 M& C3 Z, ]' z0 q4 A0 Z
Next method as well as the following one are 2 examples from Stone's
0 R$ u+ Y5 p" ?; e6 S, w"stn-wid.zip" (www.cracking.net):) F! q5 T E& y0 N m; ]. S6 N3 k Q
4 d9 @" N+ @) o( O, i
mov bx, cs
$ {: \* k U; J3 b } lea dx, int41handler2
; W, m- }# z3 a& F. Q xchg dx, es:[41h*4]
3 z9 }1 u: G H/ Q! B xchg bx, es:[41h*4+2] V0 J# x$ L" i5 X( u
mov ax,4fh7 |3 M' @! t6 W& o L
int 41h) C. {, @3 Q e5 f) w1 m2 U& ^
xchg dx, es:[41h*4]
( x5 A; {% ]; T9 q9 [ xchg bx, es:[41h*4+2]
; G; P7 V h/ J6 [1 w cmp ax, 0f386h
2 o: C$ K) h/ M3 M- h jz SoftICE_detected
0 x0 U s# [, t( }# E( o6 E0 }* Y X
( O# w1 Q4 D1 ^/ x, jint41handler2 PROC9 F% Z" ]9 ]7 [6 x
iret
. @) o2 h4 u5 T" N1 }1 Jint41handler2 ENDP
) K p; ]" k9 m, F# B- [$ s# e7 {# @
6 p$ L+ H% H& _/ C* u9 B2 q' D3 V_________________________________________________________________________+ F3 H: `9 D. O- M# G. O' q; B
$ P% ?3 |, ]1 {# T- P( Q: L; I, s% y! q3 H3 e. }8 O1 K2 i9 o% X( x- g3 `/ \
Method 06
: \9 B0 y b$ d& }! a, h=========% N+ O5 K2 t1 D6 c: P' ?% m$ P1 c
( w3 K! v) S* D' W
1 n/ x+ c* ^, f0 t) C; s/ h2nd method similar to the preceding one but more difficult to detect:
' p% i/ t( s! `) j+ R9 c# |% i3 {1 W7 s# h: x8 G. s4 a9 X
( A, p+ _/ W1 J# _! d$ g( @' M# x
int41handler PROC) S* s6 i' G+ d( `8 z
mov cl,al* l5 ~- t) Y B+ `* t9 `; x
iret
2 u. v! Q ~$ P9 a4 G" K; N4 | ?int41handler ENDP
}) R4 [$ A' U
0 r9 q4 ^5 S9 P8 Z$ ?& k/ V% o" Q. K6 |$ ~1 K
xor ax,ax
4 ^' T' P4 D& S' J o8 ` mov es,ax
; x) k3 r9 P% P% b1 m9 ^ mov bx, cs
- I0 G$ [6 g; H' P lea dx, int41handler _5 e4 P7 u( S+ H; Y d& n! R
xchg dx, es:[41h*4]% J% o) c$ \7 X/ l0 w; L- x7 l
xchg bx, es:[41h*4+2]
$ Q. V- l% v$ L2 P2 o. a/ @1 ^1 C$ b in al, 40h; ^: Y5 [6 v/ C4 M! w8 E- G
xor cx,cx
' @' _4 f' \* |, T int 41h8 R& V' A6 F8 [
xchg dx, es:[41h*4]
& t% a3 E$ ?& T4 g xchg bx, es:[41h*4+2]
& x+ _* g% W3 h. u4 Q cmp cl,al
6 z5 E( H* v/ B0 e9 g" q/ ]4 {; q jnz SoftICE_detected* Y8 Q; V! O; F6 |1 E, M& L- C* q& B; y' ~
/ y: e; }9 o3 ~% S* \_________________________________________________________________________ t" K! v' y. c9 o
' s7 h+ I: f% d$ H, @8 k- ]
Method 07% B7 J- X, a* u' K3 i: l
=========1 `+ Q# V$ ~0 @( G
; F( B( d' ^: B" _: m2 ~ ?% r y$ l# r; {
Method of detection of the WinICE handler in the int68h (V86)
# T1 Y) R1 [2 P9 g) L2 r) U G0 j& U7 W6 I) C" r. g+ _
mov ah,43h
. @7 m% {6 Q9 I5 j8 w7 s4 l0 X- ~ int 68h) K+ Q8 K4 G/ V, e
cmp ax,0F386h! C0 ^9 G. K+ n3 T8 e( X! b
jz SoftICE_Detected1 J: m) k- V/ a! z- l2 Q+ m
' X0 |4 L! `$ U: l" f7 t1 ^5 W7 @ c6 n! V% k/ f
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
" t! m# u% ]) u' r1 X/ S: Q app like this:
4 g8 C/ s9 p7 d F
* t' H0 B) v# \) f9 v8 w4 L, r6 z: } BPX exec_int if ax==68
, l3 `5 e( _3 a o& r (function called is located at byte ptr [ebp+1Dh] and client eip is9 z* m" F( e! f
located at [ebp+48h] for 32Bit apps)
6 ?* E$ x- [0 }7 c! f__________________________________________________________________________& D# B9 e: @+ s& A
7 L' z7 B* s g( z0 V Z+ Y) a- e9 s4 l. G" C/ ~0 e+ C
Method 08
/ z. a! ^2 v% R2 r7 s=========# W, B; ~0 g3 ~% t' x b
, t! w0 n( b: N: H
It is not a method of detection of SoftICE but a possibility to crash the; ?: x0 v! T9 X3 S
system by intercepting int 01h and int 03h and redirecting them to another
+ P: @9 W* O" j9 Z3 B9 Aroutine.& | `$ |. N) P
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
5 S' O- t1 A6 Z; o! ?1 x/ p1 Jto the new routine to execute (hangs computer...)
1 ^' G. ]1 Y6 b3 E. ~1 k
, B& ?& }! s4 q% | mov ah, 25h" C- l+ V- o: C# h
mov al, Int_Number (01h or 03h)
- f# y3 D2 ]9 N. ?8 \ mov dx, offset New_Int_Routine+ V( O! L- b7 D# H. f5 u/ b
int 21h0 C# H3 k# q/ M2 ]4 d' n
1 o( {0 P$ ~0 N, \( N& [+ u
__________________________________________________________________________
0 C" [; u: c2 |( h( ]. U
3 O& _) Z2 ^! n h }5 h: bMethod 09# z- h# x0 ~5 S# |& J; Z0 f
=========
& L1 s. }0 }: _6 s$ x7 ^
- w$ s- M% c# f3 C2 ^/ u: P. r* A2 UThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only3 i; d9 u% R, p2 _- T- n
performed in ring0 (VxD or a ring3 app using the VxdCall).
& b% O0 K- E( W. O) p8 Z; {The Get_DDB service is used to determine whether or not a VxD is installed& J% s4 u3 Q' b; S8 ?0 `/ c
for the specified device and returns a Device Description Block (in ecx) for4 U6 N3 z! a. z. l+ F3 A8 g) |" T
that device if it is installed.
3 M+ R" E8 a9 k% w& K: J5 Y' w: o# n% u' y: k) Q# p$ h
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID0 r% O( Q& R3 {2 @4 ^( J" x
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)* m; T! c0 M; c7 Y
VMMCall Get_DDB' {( } L' T [# k+ z- k
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed$ k/ p# }& c, h6 t
% o/ [$ p, b+ i9 x) A/ ]6 p
Note as well that you can easily detect this method with SoftICE:
1 m l6 t. S7 o5 ^3 r bpx Get_DDB if ax==0202 || ax==7a5fh
9 a! h; I$ B& R/ k! R w m
S! \1 q- i; Y% C. v# s__________________________________________________________________________3 P9 c4 k9 R- _) L: K5 }! o0 f. C
' C1 d% Q$ e" O' ~& ^0 ?. `9 q
Method 10
/ h( @1 w- s8 d* F=========
, n1 l% b; Q* m, V, C4 J8 p: b: y% T- {1 p
=>Disable or clear breakpoints before using this feature. DO NOT trace with
: S" v; G+ o: d' [1 ^) [ SoftICE while the option is enable!!) ^6 P, q0 m8 d. i5 m* x& `4 f
: K) a% `* A# x# {- Z
This trick is very efficient:; Y/ i5 L# Z! E- v! X+ S2 `# T- @
by checking the Debug Registers, you can detect if SoftICE is loaded
5 X0 V5 y+ `, t(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if- q( B' ?7 B; J+ l
there are some memory breakpoints set (dr0 to dr3) simply by reading their) ~5 \( n8 T& {( C* n( U4 [
value (in ring0 only). Values can be manipulated and or changed as well
_& n: C" O- y. U$ L& S(clearing BPMs for instance)
! N- c! y5 q3 o# {/ e* l* _3 c! V, w3 s* k4 g- Q
__________________________________________________________________________ H3 J' v3 c2 }9 Z4 ?# K6 a7 p
; G! S, h' y1 E( YMethod 116 [2 }2 d& Z; A8 R7 O6 ? {% X# k
=========$ L& w' k; D! T% x8 | E
& P$ ]4 J$ \, V- m3 RThis method is most known as 'MeltICE' because it has been freely distributed
' @9 o) i8 p3 f% ]' L. N" ?via www.winfiles.com. However it was first used by NuMega people to allow
2 y1 X0 L; m% lSymbol Loader to check if SoftICE was active or not (the code is located4 O( o+ P! I, U2 B! l& V# e2 v
inside nmtrans.dll).9 A$ O1 G( y! a/ q+ q( B& R C
' E. B9 ^, l* O( I* { f6 s Y; rThe way it works is very simple:' i1 V! l! a$ {% H7 Q9 a: a( M3 n
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
) y6 R8 d" u f3 uWinNT) with the CreateFileA API. n) f" W+ e" i* _. j" _
1 \; ?4 Z/ t* Q$ T2 j. mHere is a sample (checking for 'SICE'):3 }* g# d: X, _, j! H* X7 }/ ?
/ y& t2 M& {8 D' h" F! FBOOL IsSoftIce95Loaded()+ u, P6 i5 y1 B4 s
{
* C; J6 B6 r' f% B: A l HANDLE hFile; 5 \" I" h0 ^* r6 ?/ {8 X
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,! R% q: H+ r/ ?: W7 n
FILE_SHARE_READ | FILE_SHARE_WRITE,- g+ K& W! f0 y* E2 R! m4 v+ [
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);% I' _+ G6 Z) {/ n% c2 ~
if( hFile != INVALID_HANDLE_VALUE )
2 X S* ?6 v) z4 K) @/ u; O( b% X% @$ Q {
- z4 {. W9 g; S, s4 W2 x* n CloseHandle(hFile);- X+ A7 r7 T# \! q
return TRUE;
4 ?& [2 s$ N# v2 C$ y }% z' N/ q* N" E
return FALSE;5 h7 _& v5 ]8 K7 @" w
}$ b6 Z$ F$ X7 z; F
$ o6 _5 Z) j6 Q, s
Although this trick calls the CreateFileA function, don't even expect to be
1 R$ {; j" F9 m' X6 V! `able to intercept it by installing a IFS hook: it will not work, no way!# v% f0 N9 s8 p I# h
In fact, after the call to CreateFileA it will get through VWIN32 0x001F3 U+ R0 @3 j. @' I3 i" m. B4 J
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function). G8 X3 p3 m& n/ P& |. j
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
% w, y2 ]& l, m8 zfield.
0 k' X+ [* R9 d* z$ h- {* Z' c6 DIn fact, its purpose is not to load/unload VxDs but only to send a
) |+ L& l: C7 T6 r: wW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)" f& m+ U/ N; V# g2 b, I
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
* C0 Q1 K( Z, `* g% r0 y0 M- C$ Tto load/unload a non-dynamically loadable driver such as SoftICE ;-).9 [0 j* v K1 c; |1 y( C) Y
If the VxD is loaded, it will always clear eax and the Carry flag to allow
2 o1 e1 ^5 m6 a$ @, ^its handle to be opened and then, will be detected.
5 X! `4 J; [' [7 CYou can check that simply by hooking Winice.exe control proc entry point
/ H. J. V3 B1 g" @while running MeltICE.- p4 G2 _( `1 k L) N. f {
+ z2 p4 C* d6 q# t2 [# W
3 ~' b E& p$ C+ M, Y; v 00401067: push 00402025 ; \\.\SICE
# F1 B# Z3 e( S" J4 k+ r( G 0040106C: call CreateFileA
' Z; B& }# W# e# X5 H C 00401071: cmp eax,-001
4 Y: P" p/ m: o0 G' E 00401074: je 00401091$ C8 A4 h% Z/ o2 N+ [8 z
& H: X; a. |# S0 @' p4 b2 v9 _/ V! s( d' |; B' B0 y6 u+ H% G
There could be hundreds of BPX you could use to detect this trick.
0 w8 Y& y8 u2 m3 e2 w1 j. x' s' x-The most classical one is:
7 n8 s# R6 y! Q @% \ BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||- s& X0 Q, D" e* W0 v
*(esp->4+4)=='NTIC'
8 u) V( h3 {% r& l3 N; }
9 h: b: ~. |) ^: {7 a3 U, T-The most exotic ones (could be very slooooow :-(
7 r" g, W4 [2 X5 Q) X' | BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
5 C+ i2 f7 A+ {4 k, U ;will break 3 times :-(
/ o2 s: Y, a- R4 w: k: I
$ i k& f2 U0 z8 ?5 k* F4 w-or (a bit) faster:
1 ^* o9 m# o' z9 D0 [+ E& R BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
* Y7 N8 {* D+ f2 b1 \
/ J& T" C, f2 k$ ~4 F3 w BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 5 u4 b# k, U1 s( Q& f
;will break 3 times :-(8 H2 v" S! b+ j) S9 o4 i
$ f" b) h" g$ ?3 E% G4 U' U2 F
-Much faster:% S q* B n. ?. u, K) }; t
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
$ P+ v8 k* d- n& `" g; C" N |/ {+ X' C" _5 C) T
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen( h) z2 N" T- r8 p' p; ?& C
function to do the same job:7 o5 M( k4 S; c# N9 U% B
; a" m7 C; O( Z7 l* s5 O( ? push 00 ; OF_READ7 M9 }2 }0 U- Z/ w: \+ h
mov eax,[00656634] ; '\\.\SICE',0 C& g# n* ?( \1 U! V6 g
push eax; X- {/ b4 P7 v6 s7 E4 K, ~- u
call KERNEL32!_lopen
! e2 c6 f, v$ [/ s' v2 D inc eax
* E- [4 y- X& c* f/ c2 D0 ^, j3 ^ jnz 00650589 ; detected
+ E, n" n% N2 a6 y( J8 Z2 a* ?' b! s push 00 ; OF_READ
1 [# m$ q" t# g3 ]" ?0 L, ^- @ mov eax,[00656638] ; '\\.\SICE'( V" `) |+ L7 r8 n3 t+ H) ~
push eax
- @' O' r7 ]( |- Q+ h call KERNEL32!_lopen* Q" u* Y# E7 k5 e% I
inc eax( P O Z1 a5 K$ F# ]; l
jz 006505ae ; not detected" J* q6 @9 @) |8 [* O7 n
0 f! Q- A9 A/ R' p9 h# B" C) c! ]8 h6 V- A. A; q9 t8 J3 f6 f3 E7 `6 `6 P0 W
__________________________________________________________________________
/ n) a2 i; E9 J- H6 h6 a! r1 O$ @ ?% D
Method 12, @6 W& W5 d/ z
=========$ I/ s: U/ l. ~0 g c! L6 O
& V7 S; ?. c U! h1 `
This trick is similar to int41h/4fh Debugger installation check (code 059 o1 c, z: P6 h
& 06) but very limited because it's only available for Win95/98 (not NT) M- E7 C% p: I+ K) o
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
" N, `7 ` O5 w3 {" g @
& l: D# J1 ]2 t# j% U push 0000004fh ; function 4fh, e# a5 X5 R; {3 r8 Y
push 002a002ah ; high word specifies which VxD (VWIN32)
9 J" P+ G `# L, o; \* E ; low word specifies which service
+ B: p) O5 c. }% a (VWIN32_Int41Dispatch)/ e9 P4 m. E+ I! o* g5 }4 F3 t! m$ ~# W
call Kernel32!ORD_001 ; VxdCall$ J) H" p8 m3 l: `6 E' @0 M7 w. X% H
cmp ax, 0f386h ; magic number returned by system debuggers
4 }" z; g5 M8 i( I! B% f jz SoftICE_detected
# r8 Y: s* Z# B4 e# d. v" d; g& A8 ^. R1 t
Here again, several ways to detect it:' q5 f. G/ J$ U
0 ~1 N5 J+ K9 F6 Y8 @ BPINT 41 if ax==4f. |5 Q* f* K# _3 }& S. T) Q) S
: Q6 j8 g; a6 k% G7 `3 Y BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
. w7 v& S, k2 j& b9 d
- p3 G% N) Y3 i" D$ f+ G- | BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
; J% x6 g9 N% n2 ^- _ d8 h
- p# q5 q3 _1 w- `8 ]' h0 Y BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!( M) O5 n6 v7 N1 [0 m# U- q/ K1 o
5 p, B8 j/ L( D; }
__________________________________________________________________________3 U; E* a+ Y# k c. r+ ^
$ v: k7 [+ P j# m4 r; [
Method 13, H5 I* p U* {! z/ |/ P4 n
=========
' p4 Z4 }. j! l) o! N6 l+ e( Y% I$ ~& `( G" C8 F# p9 {; [; t
Not a real method of detection, but a good way to know if SoftICE is
8 [8 C" v+ U& ^& F7 P4 Ninstalled on a computer and to locate its installation directory.1 c' c0 ?, E4 L6 X
It is used by few softs which access the following registry keys (usually #2) :
. L6 {8 x/ U, h* z' _: `3 M- J' D( U" ~' c
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
9 r S. D* c' ~$ k\Uninstall\SoftICE
7 M X1 X0 N$ R, s$ E3 z-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- {+ _* R$ k( K' L& j. |6 ]5 u2 y-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion/ [2 b3 e5 e( t" Z
\App Paths\Loader32.Exe
" |3 b* S d/ W: R
4 m$ ]3 K* ~# K; z& t$ f4 m8 ^( ]/ Z
' T' |6 ?& t- c1 QNote that some nasty apps could then erase all files from SoftICE directory
, M* s6 C( W+ B8 T(I faced that once :-(
. U$ {$ I, ]$ }5 x) P; a" i2 t( \, h6 j7 ]# }# H
Useful breakpoint to detect it:) _2 W) }2 q" m- K# ?+ [% P' K
0 N1 \; S" P- Q1 @6 d) l9 s+ q
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE' Z3 c& `# p% W8 `0 D0 s# `
/ X( m- K" |' J6 ]5 b, K
__________________________________________________________________________
2 f. m) b% t: F9 n) U1 U3 s: G' g. S4 y) ?% m2 `* [
; O, c/ g$ J% r
Method 14
* t& ]* }1 g2 J; G& u=========* P( E0 E' G7 v
: i- i9 n9 a- P5 k7 g! cA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
& M7 F& n) V jis to determines whether a debugger is running on your system (ring0 only).8 E# ]* @4 W; a
& V1 C' q# ]4 l Z0 K
VMMCall Test_Debug_Installed
! b8 o4 @: a: |, L je not_installed
' ^; g9 g9 E0 f; ?4 D, k' r
2 }* h, c5 B8 ]. T% {. K# rThis service just checks a flag.( \6 \" h6 v1 y; t
</PRE></TD></TR></TBODY></TABLE> |