<TABLE width=500>
6 A4 l' ?' y; A<TBODY>+ W5 G6 u( b7 C: t5 i& H% [- K) v
<TR>9 i1 F# d# p- O6 k2 m1 q
<TD><PRE>Method 01 " S; w( ]# M @* p
=========
* K/ r6 x) n3 [
4 j+ e' l" Q- m# f/ C9 I: lThis method of detection of SoftICE (as well as the following one) is+ X% b; f3 b: G; l( _/ F& `" x
used by the majority of packers/encryptors found on Internet.
$ ?% L6 Y% U2 q& FIt seeks the signature of BoundsChecker in SoftICE
/ V# q. z/ C( m) L. i) Q2 I% k- M9 q0 r+ Z
mov ebp, 04243484Bh ; 'BCHK'6 K& b; F- t& P( z. f6 y
mov ax, 04h
2 d# m0 ^, @' D; z int 3 7 J O A/ l* K" C+ E7 E) k
cmp al,49 _8 Z- d: j& ?4 x8 P0 ?8 n$ s
jnz SoftICE_Detected
* h$ n8 X. a4 D/ g5 ?4 y; H7 ^2 T+ h& x+ ]
___________________________________________________________________________2 @) e7 o/ u* z. s4 {/ n4 Z) A; G
3 X1 P, n2 @- |
Method 02+ B1 I" ^2 S0 T) a# `! Q
=========, \2 q- J, C& l% ^' Y9 s9 T# ]
. n$ f/ z* Q, a' J7 Y. R, u6 }8 _Still a method very much used (perhaps the most frequent one). It is used2 d$ o6 p8 t4 i) e8 {
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,6 y$ |" H: z0 Q: ]4 `
or execute SoftICE commands...3 v& ~) ^& N$ w/ o
It is also used to crash SoftICE and to force it to execute any commands8 ?4 C3 h7 b+ o* e' B8 {/ r" c- j
(HBOOT...) :-(( . H" C7 b6 h: O% Q, C* f' t
, {2 V3 h/ z/ C" X8 Q) W6 R9 jHere is a quick description:
: c" a( t6 V p2 u' ^-AX = 0910h (Display string in SIce windows)
, j% G% P ]1 y( |, k' x-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)* q" W* b( ], O ?# g7 K( @
-AX = 0912h (Get breakpoint infos)6 I9 e7 H6 L, \: U: ?6 s+ z5 w
-AX = 0913h (Set Sice breakpoints)! r' N* }: O0 s* j; t
-AX = 0914h (Remove SIce breakoints)
9 V0 s& `4 b& O1 X& M) r( s2 V! v+ k; V: T; @
Each time you'll meet this trick, you'll see:( ^; V2 ^3 j+ [. F+ z
-SI = 4647h
3 u3 P% z0 d T3 j-DI = 4A4Dh* \& v4 p( G" X! E
Which are the 'magic values' used by SoftIce.
$ p2 o) e9 q, m& a" {5 qFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
! N3 C" Y {- \$ p M/ B) q% h8 O- C
Here is one example from the file "Haspinst.exe" which is the dongle HASP# n; S5 E7 J# p: Q. B
Envelope utility use to protect DOS applications:2 K; n) M0 ]$ ]3 M) b* R) H5 L
% `- E$ u, t0 [* v7 X/ H2 j) d( x! [" O7 Z. [! ~% |$ e; M
4C19:0095 MOV AX,0911 ; execute command.; z3 E7 l, o8 r: C/ |* B. e
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).7 v( b/ p# R$ m( }( D
4C19:009A MOV SI,4647 ; 1st magic value.
% P1 w p; K- y8 ~4C19:009D MOV DI,4A4D ; 2nd magic value., h6 l# k, x# G# j! k4 N& d4 Y
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
- w$ [1 B S: `4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
- w" k. t4 Y; U& t3 I4C19:00A4 INC CX
5 _8 B. m! b2 ?( g) y2 K4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
0 y$ y3 h( d( K, A# B% x- j4C19:00A8 JB 0095 ; 6 different commands.5 V2 E: T, H8 M1 g. x- d3 |
4C19:00AA JMP 0002 ; Bad_Guy jmp back.3 x' j, c% a) J0 i" J
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)$ ]2 J. f# T! @- m- b
' n9 |& Z) {# \2 HThe program will execute 6 different SIce commands located at ds:dx, which0 d# g1 A0 ?8 p6 h! s- d |( z. e
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
: I) R7 {$ B- q0 l8 A+ x D% o. ]& P( [7 b3 U
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.9 x; I2 U6 w2 l( P* D T9 z
___________________________________________________________________________4 F# y$ l2 X: J$ Z
1 x5 ^6 d$ Y. S: f b/ C% m" H+ t5 t3 y6 E
Method 039 r4 C& ^' ]( o2 K' J) F/ o7 x2 l
=========
* @- z* G1 Y; `, i/ G& I% N$ d' J1 a E: P" G, O
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h7 K$ K! Q) c3 `4 j$ T# V1 _4 p
(API Get entry point)
, M) n V0 s/ m( M1 C
# J1 W" y" x- |: O
2 O5 q( {1 \+ y" ?& ]- r xor di,di {# q% ?0 P1 M. B& z
mov es,di
# g- U8 k4 K# m" h, v# _ mov ax, 1684h * l6 Z$ [! L! z8 v. R
mov bx, 0202h ; VxD ID of winice
1 n- K! q: C% b. Y+ O% I9 \1 o5 k( x4 x int 2Fh
& C& V! b) A* y% z0 Z# Q% W mov ax, es ; ES:DI -> VxD API entry point9 w; A) n$ ^# j9 ] f: Y' u
add ax, di+ M5 v9 h; n) [+ L1 t4 q C
test ax,ax# |- U1 I8 l' V1 B9 R- }
jnz SoftICE_Detected! m; A. I/ p, b' x+ v3 s# K+ s
( }1 m- y: c1 u1 O1 s/ i___________________________________________________________________________0 e" W$ Y/ Q& A8 R
6 f$ U( N# a2 Q. i& f9 U( H
Method 04) |, E8 V8 Y7 `/ g7 p. T
=========. f+ o7 o, d6 z! }! ?
! I) H, b# H; }2 q& G- [$ aMethod identical to the preceding one except that it seeks the ID of SoftICE8 i: X1 @8 ^, w
GFX VxD.
, @! B& }8 \$ t0 `# U; f
3 z+ U. u) ]( \2 { xor di,di
4 N& M# ?+ v0 [4 g) H mov es,di
, @1 M7 m' N( B3 k) [ T/ }! |2 I mov ax, 1684h
0 N- V5 U5 Z+ a0 d0 r: J# I: P mov bx, 7a5Fh ; VxD ID of SIWVID7 |7 F1 D+ K( ?6 ?- a* K# W" p) z/ c
int 2fh
, |; E* m+ F' j. U2 l0 A) L mov ax, es ; ES:DI -> VxD API entry point
' Y9 S- E3 i$ C0 S# A1 d7 ^7 I add ax, di- K4 Q& a+ o1 ~$ S5 G: `
test ax,ax
0 O( z* y6 M, h/ y jnz SoftICE_Detected
5 ?2 L$ D Z4 i; G4 b5 M. K. O
__________________________________________________________________________( k v+ @) e/ F% v6 R& W; V
0 I; Q8 W, _4 C0 w$ _) m2 j; r
0 R! \7 B, f4 Q( R% `- {1 Y7 g* y
Method 05
! |) d: }) ?0 m9 _2 s- ^. |! `=========
) h' F2 J) a/ s' W: `# L& s: L4 e0 ]( Q
Method seeking the 'magic number' 0F386h returned (in ax) by all system! `( U) d" I* s0 o; F6 i
debugger. It calls the int 41h, function 4Fh.& u2 }% t. \ `* u0 s! ?+ [ F
There are several alternatives. ! M, d0 c& c) W( E
7 J, _. ?! K3 U# F% R5 @The following one is the simplest:# n! @+ W) P: }+ [
% U8 ~3 t, d2 a! ^$ V mov ax,4fh
4 g( U* V6 Z" i/ J5 h1 Q5 w int 41h* N4 J) B5 b* X# I4 W& L3 [
cmp ax, 0F386
9 w" B/ P; H1 f jz SoftICE_detected
2 u. M5 h$ k8 a' _: k, s- w2 D) j" s1 Q5 V
2 J9 i6 {/ a9 j2 z; y
Next method as well as the following one are 2 examples from Stone's
( r& y# E2 {0 Y"stn-wid.zip" (www.cracking.net):5 _9 ]* Z; h2 v N7 |; g) [0 }
+ o/ o9 a: Y2 N
mov bx, cs
* r4 [" d) p0 `, R" }( Z0 a lea dx, int41handler2
& g I! _- @2 [# f8 q2 x& s k' \ xchg dx, es:[41h*4]; T( j/ y) G3 g+ A
xchg bx, es:[41h*4+2]) m7 [3 _1 L9 d5 M6 p
mov ax,4fh
7 g9 f7 m r) P" X; V% S) W int 41h
/ c& A7 G$ q% p/ H' j4 M xchg dx, es:[41h*4]
4 @; A7 g$ d9 D: D { xchg bx, es:[41h*4+2]
* X) O, O- ]6 b" m5 W cmp ax, 0f386h2 u* B5 s2 b, j& r4 G
jz SoftICE_detected9 K3 T. n/ v3 E1 ~& p3 \
: L) C5 [: q* C4 R4 y" q9 O9 Fint41handler2 PROC1 D4 S8 R I" l
iret
5 c. M u$ e4 Nint41handler2 ENDP# Q. T; |! P- u. l7 L) [7 c X
( z8 l# N4 D* a; T) ~* \; r
& W2 P+ J: K: s/ Y3 ]+ G# q3 j/ d_________________________________________________________________________
) Z* q2 X; N/ l! M, f5 ^$ s/ P' H+ n! ~) g0 ]% H9 z! r* S
- {" `6 E1 d( f' n8 {. L
Method 06
b% F. T0 m+ C& w s2 X4 A=========
3 S6 }0 f& r5 f3 r5 g: H, v; A3 ~7 \& ~3 k* G
" q! d, Q+ o8 J
2nd method similar to the preceding one but more difficult to detect:: r- u) e+ \/ _2 d& r) Z
- t- | c- q7 }6 K3 r
& N+ }8 A" D P! `
int41handler PROC7 l3 I3 A4 _5 c1 B
mov cl,al
4 j3 X6 i, V& }+ `% S! i iret! U8 H8 X* p+ T0 d
int41handler ENDP
7 _- }+ J# i5 w6 h
+ V) N! h t* F4 l/ i, ?2 \! I
. z( H) ?. `: o" T ?! K8 u xor ax,ax
. b+ y! S! j9 v0 f, X* J$ G mov es,ax. o2 H9 j9 c( [, H0 x" \8 {. l
mov bx, cs
, q+ d, z A8 L" d6 Q( d0 R lea dx, int41handler
( P* E! A9 N* ]3 C# ?" V xchg dx, es:[41h*4]; o8 E u% R$ Z. W2 _2 L9 Z
xchg bx, es:[41h*4+2] |; m- h( d! ^2 n, a0 t
in al, 40h, z; v u5 O5 Z0 q) B
xor cx,cx
1 i8 ~1 X4 e$ O- n% U int 41h1 U3 \0 \9 g7 Q# M; V+ E, z
xchg dx, es:[41h*4]
% b. m# D2 a$ M2 u xchg bx, es:[41h*4+2]% M" ]) k( b* m5 o* k: R
cmp cl,al5 a C9 _" \# A9 J- }3 l7 t
jnz SoftICE_detected0 J5 A2 B8 P( D
2 e2 E. e1 g) q! m0 \" a# d1 q_________________________________________________________________________
% ^* J; l7 T* J! r6 S0 `
2 b) y" u8 j# l. jMethod 07 W' X, r! z7 M$ [7 w. f2 z; x: X# h
=========
5 I' F; O# P6 N1 p" l
4 n! g' x s0 @/ q- _Method of detection of the WinICE handler in the int68h (V86)3 W, x; n+ K Y& y, l
/ C2 @" o3 x0 W' t4 R! ^
mov ah,43h" Z p- W$ W: i2 y) L
int 68h
7 b3 c: x* U1 a+ r. g U# w3 L cmp ax,0F386h$ |* d, D+ `1 I; m( R4 t2 p4 ?
jz SoftICE_Detected
* v" Y, }$ o6 i1 u' ~/ U, S3 J0 u1 P3 N" f3 y" \9 |
, R5 p2 _/ W* L O2 {+ j
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
/ i" X4 k* s' U3 U' B) } app like this:
9 [9 q: ?+ }/ l5 T- r( J/ T; h9 ^) Y$ }' |5 z4 l
BPX exec_int if ax==681 |$ F1 D2 x( Z& Q! T
(function called is located at byte ptr [ebp+1Dh] and client eip is
5 Z/ r4 M. J$ ` located at [ebp+48h] for 32Bit apps)5 N4 I2 j) `9 Q( b) T0 U
__________________________________________________________________________7 B9 l+ y. o: X
" G: u! o$ q# y. `) }4 e3 H- N a3 ~0 n* x' k) Z
Method 08' u0 M+ S9 N- B* ^4 X
=========- N$ x5 g; x; t3 F: H4 a* E9 D
2 Q3 r( p; L7 g" b1 TIt is not a method of detection of SoftICE but a possibility to crash the$ u/ T+ n* K- |$ e( ~
system by intercepting int 01h and int 03h and redirecting them to another
' Z/ A* K+ o+ X( _8 groutine.( {4 t$ }( m( U, n6 Y9 X. r% D& J* Z
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points( P. |7 ~$ @0 F/ Q$ `# @- Z) M3 B
to the new routine to execute (hangs computer...)
0 {0 w% M! y+ F; Z' \- y
/ k5 j) C: g" P; g1 y3 x B mov ah, 25h
( t9 y. R/ A+ D* E! e h/ s mov al, Int_Number (01h or 03h)
/ f$ N% l3 v; K$ u [* ~ mov dx, offset New_Int_Routine Q3 q2 |5 o' X
int 21h
/ A$ M# r. B/ Y( ?% z8 O4 R
4 |' ?, o" r0 B, v' @3 c; S__________________________________________________________________________
# b* {9 F5 z# U% N" F) K4 Q2 z$ `1 y1 J4 S* t
Method 090 w% w9 g4 x1 {) t4 l
=========
: l! R8 X3 F) {; u$ {* t# J, C/ H. F5 m. f* F3 e$ T/ h
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
; I4 }1 S3 W R# ?8 ?. u/ N6 v9 kperformed in ring0 (VxD or a ring3 app using the VxdCall).
4 F9 S& y# b! D) W. Q( Q& A9 aThe Get_DDB service is used to determine whether or not a VxD is installed
) I4 r2 V5 N; F8 Gfor the specified device and returns a Device Description Block (in ecx) for
& u( L: ?; h/ N; L4 ?that device if it is installed.8 f/ o" f! O5 N0 s' v
" ^* O+ s, F% q* Z! ^ mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
8 H6 J2 i7 _4 \8 O. ` mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
3 T- g( [$ n1 w' z5 Y+ F; S5 Y- e VMMCall Get_DDB6 i! l( K J w1 w
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
r9 W. d: _+ t& z* ]7 Y
1 H+ q0 I9 Y/ x D4 J1 L }6 LNote as well that you can easily detect this method with SoftICE:
" ~3 o% m0 I4 i bpx Get_DDB if ax==0202 || ax==7a5fh9 i; Z! z" [ O" r2 T; E
! Y& S6 o' N' f9 x( ~7 V__________________________________________________________________________2 T9 m; h, n# N5 P$ v
; I9 m7 a6 i" @3 l+ ? t9 Z$ ]
Method 104 {2 [8 c- U% `, c$ a
=========" a& u6 }1 M- J- T2 X. R
l* l5 A2 g. J=>Disable or clear breakpoints before using this feature. DO NOT trace with1 {3 G0 e* ~2 R8 C8 r" t8 ~
SoftICE while the option is enable!!
# M% k7 Y: @) H! N8 B1 u& s3 Z1 M, Z! Z( ?* _
This trick is very efficient:0 p, @( P( N' j$ F3 [
by checking the Debug Registers, you can detect if SoftICE is loaded" |$ P- w% [! u
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if. t9 @+ j7 G! S* C# y
there are some memory breakpoints set (dr0 to dr3) simply by reading their
* r8 }' J) v# M2 S: p( S& O' q% Yvalue (in ring0 only). Values can be manipulated and or changed as well: }+ `9 w9 ?0 H! S' v) V& C+ V9 `
(clearing BPMs for instance)) x' M x- H" ^. Z ]+ T
+ ~; B7 Z9 {, |& h5 i; S
__________________________________________________________________________5 _& W8 L6 v, m2 @- A3 V) E) z
- t5 N* I! b4 G6 o H: pMethod 11
8 n% R5 S* t$ ]=========' s+ @3 X& e1 j$ L0 ^+ r) i) o t9 S
; J. z; o! h5 b5 k) O8 {* ]& tThis method is most known as 'MeltICE' because it has been freely distributed6 m5 R' C) P; E# K5 V6 q7 j( s( P
via www.winfiles.com. However it was first used by NuMega people to allow, G6 r& [, E4 c& t0 O/ s0 ?+ K
Symbol Loader to check if SoftICE was active or not (the code is located
: {: ?1 I- T% c# \' Q* R1 Q' E* Vinside nmtrans.dll).+ B! A/ |/ N& q
$ ]6 n3 l" E% {& `; X
The way it works is very simple:
& C' B6 u# z, O# tIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
% G: P! a! `6 T* [WinNT) with the CreateFileA API.
6 @2 }1 _) l8 s- h& P# Z0 k0 m2 [! k
Here is a sample (checking for 'SICE'):
4 E5 e* g; I- z( Z2 b F- k9 q
# a; u* O5 Z/ M$ W9 j/ v! f0 uBOOL IsSoftIce95Loaded()7 h9 t& {: S5 n9 i
{
% Y, \: _4 v$ g, Q+ P# z' ` HANDLE hFile;
9 T+ K+ P# c4 |% }: Z; L hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,# f" H0 ]: @# X3 F- |3 |
FILE_SHARE_READ | FILE_SHARE_WRITE,9 R7 X+ x) p) I+ `! x& S
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);1 T4 V* o4 P; U
if( hFile != INVALID_HANDLE_VALUE )
+ P' L7 b S8 c% t! H t {5 c5 s" s# b) ~. _- k7 |
CloseHandle(hFile);3 Y! S' K! N+ d0 J3 ]
return TRUE;' x! \. z# A: h
}: P$ q' ~5 U' `
return FALSE;
8 |# A5 U$ i0 C) ^}
( I2 a1 H6 N' i, O$ }0 q! H& C. s- E9 `
2 a# h! U) \: s' u' |) M3 xAlthough this trick calls the CreateFileA function, don't even expect to be) i; ^) W. b: r- f8 t) g2 b$ X
able to intercept it by installing a IFS hook: it will not work, no way!
0 X$ B' I+ U7 I" a! vIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
Z G8 G$ t; w: {+ r0 y, q* y# o; Oservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
1 a' i) M, b! K; l% Fand then browse the DDB list until it find the VxD and its DDB_Control_Proc0 ]) H4 ?" M5 E; M& H Z
field.
8 @9 p# s+ w, cIn fact, its purpose is not to load/unload VxDs but only to send a " A8 X# w2 F: u7 J+ T2 [
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)1 b) j5 `( x# d$ \' ^/ t
to the VxD Control_Dispatch proc (how the hell a shareware soft could try+ j+ ]. V( r5 ]5 x2 |, c
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
+ f6 @3 F5 W1 r- ^& j) XIf the VxD is loaded, it will always clear eax and the Carry flag to allow& ~# q5 R: r4 S( |* h, F, C# q* v
its handle to be opened and then, will be detected.$ d: N; q, P5 E! e# ?& K# W. c
You can check that simply by hooking Winice.exe control proc entry point H, D L- P! R/ v- @, c( K
while running MeltICE.
) o9 ]& C8 [5 e# l
- p& R9 J# e/ w4 h) L5 [3 Y3 o; m, F/ l8 s: i B! `" s& l
00401067: push 00402025 ; \\.\SICE
9 w6 |3 R8 a/ z: @" a 0040106C: call CreateFileA w# q \% a8 [0 D
00401071: cmp eax,-001
- ^; Y8 x! W5 z6 u/ a' G% R 00401074: je 00401091
Q( R' ~0 t, u/ }6 T9 X% k
- [: t$ J# U% d9 |' t1 h5 F' Y4 S8 ^- p6 I
There could be hundreds of BPX you could use to detect this trick.) r" a) W o6 v' l% s4 r6 l
-The most classical one is:# u, N+ L4 ]/ K! \0 ` w4 J
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
% _2 d- B' ?9 a# ~ *(esp->4+4)=='NTIC'
1 y1 i( K5 y1 i" e- @- O8 [
4 j) B0 |0 K2 j$ q% ^-The most exotic ones (could be very slooooow :-(
& y3 A9 g; {. R- D, R9 f BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 8 q2 a V* Z% A% m( Z, _6 o/ }
;will break 3 times :-( Q6 }' |% w4 }; C. K( H+ V
! U5 ^4 x5 t3 k: z
-or (a bit) faster:
1 m: E0 O# o$ {; K BPINT 30 if (*edi=='SICE' || *edi=='SIWV')( r& l4 E( \- \) d/ T0 ]/ D
7 t3 d% x4 i4 ? BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 5 N8 N& j) u, S# N
;will break 3 times :-(- P l# A! w0 ?) b" X* B' d
p4 R- a( x. f- Z+ q& q' T% W* E
-Much faster:
7 e$ B. f5 p5 S# E; J BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'/ v/ J, h8 [' ?- L' f L8 f5 f3 i
% C3 T4 l& m+ s% i% ^) yNote also that some programs (like AZPR3.00) use de old 16-bit _lopen# a* p2 g. W7 { f6 B9 ^9 ]
function to do the same job:3 S& W1 s7 Z$ q) X. s- o0 ~7 D4 G: Y
. d' b" _. u6 [1 Z0 ?' @
push 00 ; OF_READ4 D( D |) [5 U/ K# M( a" v
mov eax,[00656634] ; '\\.\SICE',0. c% r9 y0 G6 W: W0 N, w
push eax
0 n5 k, `( T& W3 G call KERNEL32!_lopen
: x/ G% _( }$ |' H/ y inc eax
- D5 |5 a1 C6 y' k: e jnz 00650589 ; detected
6 r$ _; ]/ ~5 o) r) p- K4 P/ \ push 00 ; OF_READ+ }2 a S" s, |' Z4 |2 U2 {
mov eax,[00656638] ; '\\.\SICE'. s# M8 C, Z$ H
push eax6 `( p% X& M& y" @+ }. j. R
call KERNEL32!_lopen
9 {! ]& E# T0 s" ^+ e& @ inc eax# X) c3 F, L- k- l
jz 006505ae ; not detected
% ~2 y2 c4 {# D! V+ v7 t% I8 D0 B
/ p. D. a2 q* m- W' }
__________________________________________________________________________/ I, `/ E4 V2 f D
- H8 L6 D8 Q R/ ?9 U( ^; S
Method 12; ~: t& U4 } F) ]) R! P- A
=========4 Q/ W, a: d1 \' E/ |
' [/ t, g) ]+ S |
This trick is similar to int41h/4fh Debugger installation check (code 05
0 K, i/ L. Q7 Q# B8 L% @$ L* q& 06) but very limited because it's only available for Win95/98 (not NT)0 ?: ^% l) V9 ]! ?
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.7 X4 k0 X+ @2 X, l6 [1 V( z3 c
3 b5 Q& l4 [* z push 0000004fh ; function 4fh
; t! H+ q; f( W% I; P push 002a002ah ; high word specifies which VxD (VWIN32)& ?* h9 g, h+ U! o" U C
; low word specifies which service' h0 L% F8 T( f
(VWIN32_Int41Dispatch)+ d" [$ z4 {) l
call Kernel32!ORD_001 ; VxdCall! \: c1 C* E; O! V7 Y
cmp ax, 0f386h ; magic number returned by system debuggers
+ i- v( n; `5 h+ B$ w, h+ K jz SoftICE_detected
. r' W- n8 ~$ B0 _! U) G% x5 g3 K6 e8 ~
Here again, several ways to detect it:
+ }1 W$ G* V, d8 N9 A
4 c& O t0 G/ T$ t2 p) S4 z" i8 U" \ BPINT 41 if ax==4f- G0 e1 }7 n8 o5 z% f" m
) Y' ]4 A5 j; L0 Y* |
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one1 L: [7 t8 x, T# P( T& F8 q
* U* w- r3 y0 Q7 B2 R& Q
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
8 W( k. E3 W5 C9 j$ l: v$ ]1 S* F+ M7 o. n
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!% h- m" [" e7 H5 L( q. A
/ h- e- @' X4 k: P! c! k__________________________________________________________________________, R7 k- c3 b/ G( L
1 f. Q9 h$ c( r V6 }* r# @+ V1 Y
Method 13# K5 `: |, ?, ?
=========
" O0 }; [: i$ @& z
. [* G$ w9 B* r" cNot a real method of detection, but a good way to know if SoftICE is1 \+ T4 ]' _4 F
installed on a computer and to locate its installation directory.
( `; u5 U1 \! Y4 J5 ^3 N; O2 ~5 [8 gIt is used by few softs which access the following registry keys (usually #2) :
$ L) f+ g* z$ J# H
% T. R4 a* E; N% ~ f/ c-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 M0 h* ]* l" a* Y$ z) L\Uninstall\SoftICE. w/ {# u! ~7 e4 Y9 K0 ~3 Y% O
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
% D ^- \6 I9 s2 e-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
0 [/ ^5 n# ?( e( N" Y C' _\App Paths\Loader32.Exe N" ^/ |1 e9 I+ _
+ P9 h: Q7 K3 D! c9 P+ w( o
* d( ^! G7 g ~# B
Note that some nasty apps could then erase all files from SoftICE directory
6 ^7 w& Z) K4 Q# `% o' I/ C$ i* J(I faced that once :-(# a) l% N+ \3 A# C" g
0 f! z+ A; z8 K% g" mUseful breakpoint to detect it:
% H% K& ~6 X+ h1 C* A) ~: b/ }2 c$ t) {- F4 y- c# S8 h
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'+ g/ g8 R q- b$ X
5 h. c( R4 P' D# q- P8 e4 d7 A__________________________________________________________________________' ?$ D) m* q8 _6 J$ _+ @
* x# X7 L! e& ?/ H
* }' w3 T; G- R
Method 14
2 D% T% d1 G- S) V4 O=========9 @. h5 d+ V/ Y- c: W! p5 X2 Z
. ?1 G' B0 A0 w+ |A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
! h7 r+ A1 }4 J. Vis to determines whether a debugger is running on your system (ring0 only).
& @. j8 B1 [! J7 n0 o- S2 G9 m7 A, `% j" Q8 e' s) a
VMMCall Test_Debug_Installed8 d2 v* n) W0 @% V8 A
je not_installed
& {7 t4 o T! e1 I) {) e1 l y
This service just checks a flag.
! v. @4 `0 l: z1 a9 f</PRE></TD></TR></TBODY></TABLE> |