<TABLE width=500>8 `* H. a n$ X; ]9 {
<TBODY>
0 w. j- y+ O* I5 f% X5 _6 E<TR>. @* p6 r2 H1 H! [9 z' Y
<TD><PRE>Method 01 0 G7 c1 N, f+ Q1 ?
=========
! [# S q2 r5 P$ J0 G# {9 g( ?
A# F( o. T, @+ x: `This method of detection of SoftICE (as well as the following one) is1 E- G7 D+ H9 A$ [) x: e
used by the majority of packers/encryptors found on Internet.) L: a) l; J5 t* V8 f3 v
It seeks the signature of BoundsChecker in SoftICE, x: A# L8 {4 @7 \; b
! f: M' T z, i0 v mov ebp, 04243484Bh ; 'BCHK'
( w7 ]" d' X; w2 g& { mov ax, 04h
3 i+ h b8 T, v0 b( o8 V3 h( | int 3 2 U" m. B) H2 v
cmp al,45 Q" }: X1 ?% V6 [& }8 V
jnz SoftICE_Detected
5 p1 B8 L c" G* l2 m6 n$ y
9 q7 s, P* l2 W' v___________________________________________________________________________
0 J. ~4 ^- u m. M
% |% Y% W% N+ P& \* c, G) ^ AMethod 02
" R5 q; }3 C4 x8 A( h6 z, z=========
& g! X5 }2 w: A* O5 G" S5 e; T& }" j
Still a method very much used (perhaps the most frequent one). It is used
$ K u4 S2 N9 ^9 C6 Uto get SoftICE 'Back Door commands' which gives infos on Breakpoints,+ N) W f0 [" X6 {; k
or execute SoftICE commands...
+ w$ o$ N" y! tIt is also used to crash SoftICE and to force it to execute any commands2 h9 U7 c$ Z. s
(HBOOT...) :-(( " L e' l! R2 L% _; D
" b* _+ Y8 `) r+ R) A
Here is a quick description:
( f2 q& P% f8 ~8 x6 K3 a-AX = 0910h (Display string in SIce windows)
- `3 y8 }, g; U: |& n" @% g-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
G/ V( Z" Y2 c7 \-AX = 0912h (Get breakpoint infos)$ u) v% e" D, r% V( @" Q) w9 ?
-AX = 0913h (Set Sice breakpoints), B* p2 k" Y! `9 J8 B
-AX = 0914h (Remove SIce breakoints), e8 c+ C, f: f) t1 W
$ d0 M- {- U) {, ?" v
Each time you'll meet this trick, you'll see:
3 {4 G) J* {& v% i0 z-SI = 4647h x. D# {3 |$ H( u1 {
-DI = 4A4Dh
~. y# e7 Y8 Q- N. J* F7 dWhich are the 'magic values' used by SoftIce.
3 G5 [: I: u3 d- ~4 _; ~: m, gFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
5 a7 g( l& a$ g2 k/ A, C: p
& y6 b2 U- U/ D P: @Here is one example from the file "Haspinst.exe" which is the dongle HASP
3 [& O# H9 \' g/ H" @/ `' b$ k; LEnvelope utility use to protect DOS applications:
" L: w1 v% N- D8 |* Z2 ^' g+ ]( H R
) u; q# N% {$ X
4C19:0095 MOV AX,0911 ; execute command.# k; t, f+ Z- L1 P) \- V
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).# W% h5 X7 B1 t( p
4C19:009A MOV SI,4647 ; 1st magic value.; D: j9 ?6 a% g0 ?
4C19:009D MOV DI,4A4D ; 2nd magic value.2 ^8 C9 B" A. [; K, Y
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
9 k6 S; f4 u8 r4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
1 I; s) n8 X: K( f @' D4C19:00A4 INC CX
{; O& B) F0 P4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
" A$ X& @ k' {; e: K- j, y4C19:00A8 JB 0095 ; 6 different commands.
: _9 y$ U+ ?3 } [+ d# x4C19:00AA JMP 0002 ; Bad_Guy jmp back.. N x% \6 N7 I' g/ @1 e
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)* n# H0 z L+ @' [
: N$ H, P& M- b# q
The program will execute 6 different SIce commands located at ds:dx, which
+ `: ]* S; Z' ^: u% Oare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
1 i6 \* j& \) @# b. B( n9 {
& q% W0 [3 ]( j* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded." b1 e$ M3 n0 r; o, \
___________________________________________________________________________
! ?$ l* w0 X2 y& P- M1 X
4 V8 B4 z+ ^( l% O1 \. Q0 i" C$ [& \7 t7 C) T% y% ~, W
Method 030 u( q; `# W" [) S
=========
! G7 J8 b1 a8 L- j. Q" x
1 i# ]) P4 f" E: Z9 u- e# rLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
3 }7 _5 v9 m& I) ~& x) \6 H5 G(API Get entry point)' c7 f( @8 {9 K* _7 X2 y. P
2 O8 H0 ]- m0 J: T
/ @3 D8 A7 r: J: p" f* } xor di,di
0 t$ f2 F, B- g& j" F8 b/ S3 j mov es,di
& u$ H. ^# g5 r% k+ w6 E- x. d mov ax, 1684h
. W$ N/ B3 V* y r& ?3 ?( B mov bx, 0202h ; VxD ID of winice
8 k$ U( f8 j/ U; C2 q7 @% R8 y int 2Fh1 P( [$ Y0 k( e' P0 u7 v8 n
mov ax, es ; ES:DI -> VxD API entry point
6 l% e) `: x* F% q5 V add ax, di
, N" \1 W1 E. H; i3 n1 l test ax,ax$ ]0 g+ w* j' i5 t/ S- o2 Z
jnz SoftICE_Detected
& @5 |* c% l3 Y4 t5 @+ m
$ E- E1 a( U( F$ ~. C0 u___________________________________________________________________________2 F4 |# C: {# w @3 u9 v3 E4 ?
' K3 z. n3 Q3 U
Method 043 G* C! d8 ?8 f- ^, u9 }! A: @
=========
9 U8 R. t$ \, `, K( @) ]- G, V* m7 G
: K3 u* \& ^3 C7 E+ a' p/ NMethod identical to the preceding one except that it seeks the ID of SoftICE6 ?5 H5 p4 p$ k( M
GFX VxD.+ U) c& c. ]+ F3 v5 C" P
. ~5 N/ ?3 n% x xor di,di7 b& K/ _& ]3 H" S
mov es,di' a* R+ i2 \, Z) V
mov ax, 1684h
& f' A" a5 _/ h/ f& g+ D mov bx, 7a5Fh ; VxD ID of SIWVID8 h5 D$ t6 E$ z$ [ L( p
int 2fh0 q6 X. @" |. R+ Q- J. K, n
mov ax, es ; ES:DI -> VxD API entry point( d; w4 g) a/ [ T# `4 k; H0 a
add ax, di. i" R# T' P+ d& \2 ^" ]4 Q! [
test ax,ax F) X# J: u: G) d; V0 S( ~
jnz SoftICE_Detected \# M( f5 b8 T
9 S2 W. l( s, d# F0 m__________________________________________________________________________8 ~/ c0 ~' t k3 _7 e( K1 r" `
* c1 x: R' |/ d& v! _3 ?* g2 z
7 U" t! t! B7 v2 _0 j
Method 05( ~, d5 |5 @1 c& x3 x5 R7 ?6 R
=========
9 I' p6 W8 M! A* ~* b
$ |, v% o" I( X6 Y. ?2 lMethod seeking the 'magic number' 0F386h returned (in ax) by all system. P" _& x2 c& i5 U+ l- b
debugger. It calls the int 41h, function 4Fh.
: g9 _$ Q" w: xThere are several alternatives. ) M8 B, r: M" U* |% _" N( T( n9 h
7 u1 L4 G' T6 j* S3 C2 V% t# qThe following one is the simplest:
' c+ Z3 Q& J/ m
( b! \) m: y8 ~ mov ax,4fh
t7 v7 X* J* p6 R/ H# \ int 41h
* K# O4 X& k$ F. ?2 t' j" Z cmp ax, 0F386
9 M8 F0 }/ V$ O& l8 O2 V jz SoftICE_detected
1 T8 S$ a7 L" X" m
6 t# U( {6 f4 h7 ~3 @" r( K g: {" ~9 o& e) V0 h! j' x0 u( ~
Next method as well as the following one are 2 examples from Stone's & i$ O% G& t7 ?
"stn-wid.zip" (www.cracking.net):' |; B; B5 x+ ?" T0 i' @
+ h* S8 j4 q: a0 S; Q) x9 i% _
mov bx, cs0 ^' a6 _- N* P. m
lea dx, int41handler2
$ K* M$ @; D ^% P8 T xchg dx, es:[41h*4]
# J; ^; a! R; E) O5 L+ i xchg bx, es:[41h*4+2]
. i0 |6 {/ x- }! {6 a% A( R mov ax,4fh' O; n6 Y9 R* ?% R
int 41h2 C7 h/ d9 [/ J/ ^. o+ ?
xchg dx, es:[41h*4]
3 \* h* x+ G8 S3 P$ ~( v xchg bx, es:[41h*4+2]" N0 M9 {9 d8 ?0 f7 _3 ~% S! r9 f
cmp ax, 0f386h. m( t! _5 U/ c! i5 Y5 n
jz SoftICE_detected
0 x9 _" E# a8 {$ A8 }; B5 O
: p4 y6 H" A+ N& Y) f/ sint41handler2 PROC% I# r- I; p( ?$ X" O
iret
, J9 I ]! u! x5 Y3 P. F0 Bint41handler2 ENDP5 Z$ U; Z: D" M4 q1 R0 D
% q: S2 I. @) p5 F4 W
7 `7 H: e( b6 h" U* G& J6 U! U_________________________________________________________________________
! V) ^/ r" s# i! ]5 \8 S# T4 U q% l! i0 l- Y, I
% x/ }6 S8 I1 U* E* x+ L
Method 06
" U8 @' o7 c# t3 r$ G5 C, f=========
7 ^+ h+ E' U1 \9 Y Q& J3 ~- [" k! h8 H' U. q4 [
, Y- e( P w8 H8 W% l9 H: Z2nd method similar to the preceding one but more difficult to detect:
, A( U7 \ Y! z" {( O1 s& B5 r/ c# {- f& p' t$ u* E% U% J
' W7 h' q6 P0 o" A# Eint41handler PROC
8 e6 U* R3 @1 p4 V- |; v mov cl,al) T% Y" V6 M; q, Q# ~) h
iret8 w: G" {) z# f. O6 E3 L) R% d8 P) I
int41handler ENDP
5 q* c: ?: ^& w8 X8 N7 G! r( J q& C# N! h" J" |# f2 O) J
" P v( Z5 x7 U0 G xor ax,ax
1 x: b9 ~5 T) d# C# b3 J mov es,ax
2 E- Z! r" h# s- t4 N/ A o8 z mov bx, cs
6 R) A+ W. D7 [9 ?' F# a* t- ]1 v lea dx, int41handler3 l7 i9 Q1 n# x5 Z
xchg dx, es:[41h*4]
3 d, G \ R# O' a9 G xchg bx, es:[41h*4+2]
+ G1 {4 u2 L9 ]! V3 W in al, 40h
- i: v- K( O$ S4 P) l5 P( }8 M2 Z! K( _/ K xor cx,cx- @& z2 t0 Z$ C: K: q9 S- L
int 41h' q( Y9 X! n; X. `9 K: m1 J
xchg dx, es:[41h*4]
$ { _' c% C- q1 o& p. f xchg bx, es:[41h*4+2]
9 j# j% }% c0 l' C: _ cmp cl,al
1 T! H- j9 u; q+ l) y4 t5 e* g4 Q# H jnz SoftICE_detected1 n5 _& A; C* a% s8 `6 Y
* J2 g) f! M* S6 b3 a: d_________________________________________________________________________( g4 P( {2 Z# P( E; h( o2 w8 T
- z; m/ Q4 v2 c/ d- a+ YMethod 07
! Q9 C4 a" a( P7 j$ b7 R=========6 ~' p" ^) l5 J3 o) ~; s
( {# u5 j( l2 z) l, `2 J/ X
Method of detection of the WinICE handler in the int68h (V86)
: m* O1 h1 v; ^ Z) Z' \+ Z" B+ A" {* @( E2 u; x0 ~
mov ah,43h
) {) m. A2 ~1 {2 @ int 68h& z" r% _* J$ v9 `9 C0 E* L
cmp ax,0F386h5 O# n7 T% z. y! W# @1 `' T$ \
jz SoftICE_Detected
& z( R) V$ r( }, c6 ^0 }+ m* }
0 `: N/ u, M( z2 s5 o9 E/ S6 i2 q0 T7 G8 ]' c3 D
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit: y0 R3 {6 N g8 \- \
app like this:4 O% s. i4 Y2 u1 S5 w1 Q: F
: c6 O( d" q! i, {# N6 Y4 _" R& Z BPX exec_int if ax==68& n- N- ]; r: @& B M& g& B3 l& ~- ~
(function called is located at byte ptr [ebp+1Dh] and client eip is2 ~0 F. l- N6 S
located at [ebp+48h] for 32Bit apps)7 o# W: g; j5 `4 f; @
__________________________________________________________________________
3 d. c3 h- w1 F `. i5 C: Z) b" }2 z }
. N' F( H; _, q$ J: d! J7 Q0 n9 h+ k0 K5 `! r& z; T
Method 085 b' N& i1 h0 Q5 f
=========
5 V/ A( P5 D) j, {: C7 o; G% X1 Q( h, f7 I
It is not a method of detection of SoftICE but a possibility to crash the
" c: b6 [+ h# d1 V* Esystem by intercepting int 01h and int 03h and redirecting them to another
0 p3 v P. w8 a( h" B0 Broutine.
2 s9 w" F7 N# A6 I4 o5 R" r! _It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points N' }( ~# C# w. _" F3 p. C- O
to the new routine to execute (hangs computer...)2 `" Q+ _/ y7 h7 M( U
6 E" E* h7 Y$ g0 c( Y4 e' U
mov ah, 25h: v8 L# [% b/ B# W+ i
mov al, Int_Number (01h or 03h)0 M) ]* h8 u& j
mov dx, offset New_Int_Routine6 s& h1 O1 @ q! g' E9 N
int 21h
! \( N. ^8 M) m/ \; N
# U) q2 N; [* ~) ~__________________________________________________________________________
2 ]- | i: V9 Q! k' @6 T9 R8 m2 r. T* I9 {
Method 09
# j2 b3 q, f# F$ Z8 R7 \=========
- d6 V* W" A/ ?2 E/ B' B
0 \$ ^# \, R+ ^. m) w R1 [; |/ @This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
9 I6 q3 B+ H; J2 z* y4 ?0 i7 i; j( T2 vperformed in ring0 (VxD or a ring3 app using the VxdCall).; t" L$ w& {: \, C
The Get_DDB service is used to determine whether or not a VxD is installed
' f# V1 G9 u o' L2 H8 Qfor the specified device and returns a Device Description Block (in ecx) for
' ~# i- G+ a- G$ I9 s! T) d! nthat device if it is installed.6 S# a- s) n0 v7 L0 m
5 ]/ P( E& R0 S' _% _. Y3 [
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID; E* Y0 ]1 Q' A; ]1 [8 h0 x8 p- ?
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
( `) Y; V6 s6 h VMMCall Get_DDB9 D* y( G1 a6 K5 ]" V* H
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
7 N2 E( l) ^' k: H. i" f$ d6 f4 k. {6 m
1 ~5 z0 P$ ~9 I. XNote as well that you can easily detect this method with SoftICE:) V1 R7 e8 P6 r& v E
bpx Get_DDB if ax==0202 || ax==7a5fh! J! t/ _$ ~1 S9 p
$ [: @* B3 D4 R9 N' h; U
__________________________________________________________________________
! M/ ~3 v4 _: S- ^# F& C! }1 L# n/ X# f; r, `7 o$ A
Method 10
( `, ~1 `8 @1 T=========
/ Y% Q) P1 C0 |) f$ ?' k- x8 i# `* ^/ `9 L, x: B; y
=>Disable or clear breakpoints before using this feature. DO NOT trace with
2 u G& n2 T" d6 s. F SoftICE while the option is enable!!( G* g, F8 f. Z" h
, _8 ^) T) e" {9 r# }This trick is very efficient:
: N1 E: E! ]- @ J: X0 }% Lby checking the Debug Registers, you can detect if SoftICE is loaded: x; T6 y1 O% e0 Q
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if: q) |, D/ i3 U* f/ K* h
there are some memory breakpoints set (dr0 to dr3) simply by reading their+ d' h. r$ i( x' [/ ^
value (in ring0 only). Values can be manipulated and or changed as well3 Y, W9 J: D% y5 v
(clearing BPMs for instance)* ?, t! i1 q, O- W+ f
. V; p4 ^/ k8 s__________________________________________________________________________
7 M: _6 R; I; K& G7 E0 s
' z, t, }. ]( b/ D" }, T8 W1 oMethod 11
, v# ?: d9 r+ r( N7 v( a |/ q=========4 n# C9 J! M" k* D# D: w# o3 f8 i
8 l0 X* a( t( }This method is most known as 'MeltICE' because it has been freely distributed$ @' X- A X( Z! W" g
via www.winfiles.com. However it was first used by NuMega people to allow
: X/ t+ l+ O% `( O$ ^# d8 k" [7 WSymbol Loader to check if SoftICE was active or not (the code is located7 C9 H+ c% l2 i& \. u4 `* D
inside nmtrans.dll)., i2 B I. E0 S0 D( j1 E( k( Q
p& r+ w! y# q( G% M+ Y" y3 `
The way it works is very simple:- ` E! U- y) o }+ x
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
- @# q9 ?3 L; |& DWinNT) with the CreateFileA API.
+ b! ?& Y7 d' l# F' M" ~3 h2 [% A8 m$ P
Here is a sample (checking for 'SICE'):3 T& q# g- r: n) w x3 m
% v6 I% v/ _: m) BBOOL IsSoftIce95Loaded()
0 I u( W2 N0 Q0 q: W+ A) B3 S{# ^& u+ C$ k# E. Y! x. m
HANDLE hFile; 9 X& y3 r$ S8 `0 o h
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
: I. {, R/ k' p8 ?& N$ p) ~ FILE_SHARE_READ | FILE_SHARE_WRITE,
% m: H3 r; h( c- h: V2 C NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);9 @, D7 ?% K% j! ]9 D# z
if( hFile != INVALID_HANDLE_VALUE )
, H1 K3 e2 _' Z' P {! R1 y/ d2 _ z+ R
CloseHandle(hFile);* i' U% O5 F7 o* L' Q
return TRUE;9 j3 ] P, a/ h
}- {9 z8 k: s+ y! C0 P8 ~9 C. p
return FALSE;3 p! W' e8 y; c( t# Z8 m4 G, E
}
& i9 ]8 L! C2 N- j8 b
$ F& G! g, f0 C6 r- e$ Y6 o9 \Although this trick calls the CreateFileA function, don't even expect to be
% y0 o5 |+ U4 W2 h8 L! B& J" Xable to intercept it by installing a IFS hook: it will not work, no way!, \& m# q' V" I
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
0 s4 F' }9 Y2 x( T% Pservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
$ d- ~! W# J) @+ wand then browse the DDB list until it find the VxD and its DDB_Control_Proc7 h6 u' I* c0 z6 H/ q# r
field.$ D1 S; I5 O6 g, X G+ \
In fact, its purpose is not to load/unload VxDs but only to send a 1 q1 g. G6 e; G a- C, z6 F
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)& l3 T$ y& J: p
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
, c8 A& v. b L2 `4 c, U6 Q% `to load/unload a non-dynamically loadable driver such as SoftICE ;-).9 `1 M' Y# o! z' c& p
If the VxD is loaded, it will always clear eax and the Carry flag to allow) A$ K8 A' |4 C: G) F
its handle to be opened and then, will be detected.
% B* v0 v6 K1 B, W/ D# jYou can check that simply by hooking Winice.exe control proc entry point, q6 O: w0 H8 z5 H) W3 l1 W
while running MeltICE.. e: N( P* f) |4 ^- Z0 y0 n2 x
[3 T: q3 [0 K; X, _0 o9 ^+ }" J0 f L% J
00401067: push 00402025 ; \\.\SICE
' F0 [1 o8 A- X" h 0040106C: call CreateFileA
5 ~5 O8 J8 k3 z! c5 D! } 00401071: cmp eax,-001
. y7 v2 ?: V) e. G 00401074: je 00401091 X7 w& S% \, S/ ^0 e, u
5 A2 p0 E( d: z3 }1 \- t
- |# v5 `! t/ K7 Z
There could be hundreds of BPX you could use to detect this trick.
Z4 O5 A& `& A9 Z9 `" k/ q-The most classical one is:* m1 O3 q0 K, h
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||0 X/ R3 I/ V R1 d7 G- V# B
*(esp->4+4)=='NTIC'
9 X( F: h: K( O( V, i# e1 b2 Z7 p+ r$ c! D. x1 x+ E- N4 Q( ?. f
-The most exotic ones (could be very slooooow :-(
1 L- ^% h: e7 y" a3 c% O8 q% m- u+ ~ BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
. c% g* H( G7 `- b! d. ^! {* T- i, P9 f ;will break 3 times :-(, m. q: g+ i; b- h/ _, F; k
! b2 h3 i0 K# A& [3 Q' G-or (a bit) faster: * O- Y% Y. y5 ]- Z
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
/ ^/ {6 _8 d5 o* M9 J' P s# G+ O1 k+ o1 P; {+ b& n$ R+ Z: ^5 k
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' , Z. F/ c8 B" i d, F1 Z" H3 r8 X
;will break 3 times :-(
+ ^2 y: P+ @, C3 G
1 Z8 \9 y, q5 a* x# m6 l; p-Much faster:
" e' N3 G" R3 n BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
0 D" t) Q5 B7 q; L: L9 }6 M" M, q8 y% [( v& t. P/ Q. ?
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen2 K A: Q& }5 K2 \, `: o# G
function to do the same job:
& S& J8 P5 v" F
7 E; P; L+ O! p; H' f0 T- L push 00 ; OF_READ, r; _0 k/ ]2 g+ E& o8 U4 ~) [7 b
mov eax,[00656634] ; '\\.\SICE',0
5 a# I! p* n% Y0 c* u push eax7 ~& L6 J9 R) e1 B' N' B. T
call KERNEL32!_lopen5 c6 ?! p2 {5 m* [+ }0 z
inc eax
$ F: K% y" @; ?* x jnz 00650589 ; detected$ U8 n5 x2 ^+ i9 `/ M
push 00 ; OF_READ8 z1 N& ~% G4 n
mov eax,[00656638] ; '\\.\SICE'
1 i: ]. |& a8 P push eax2 F1 n1 \$ e4 b0 o: @
call KERNEL32!_lopen$ Q3 |5 ^5 I* Y$ c0 R' T! `
inc eax
3 Z/ B* }+ H$ Y4 W3 B5 x3 `6 P jz 006505ae ; not detected: }! ^* r2 x' b8 ?
: @0 D& ~7 f- \% i1 e" g" E8 R4 Q. E- M' I7 V
__________________________________________________________________________
' w( A3 a. [0 y9 @ M
$ `! m o- V! d8 V( S9 X# zMethod 122 j/ K- W# z% {/ l9 e2 G
========= }: ~7 f' p4 J# i
2 }6 I. N: U, J4 J; S; J0 wThis trick is similar to int41h/4fh Debugger installation check (code 05* K% N5 c- l2 g5 R
& 06) but very limited because it's only available for Win95/98 (not NT)
1 @8 T# `& e' H. I* h9 y# v* qas it uses the VxDCall backdoor. This detection was found in Bleem Demo." O8 G% k( n0 ]. m4 }. E
2 W8 t+ B6 H: Q& i& K/ d
push 0000004fh ; function 4fh
- ], |' I6 n$ K push 002a002ah ; high word specifies which VxD (VWIN32). i( Q1 B4 l" o9 k- d5 N
; low word specifies which service
( W& C/ L% t5 r" J; B3 y ?$ h (VWIN32_Int41Dispatch)
( X$ `9 ?) u0 }& a1 G& V6 E, E call Kernel32!ORD_001 ; VxdCall$ o' U( {+ Y. d9 L
cmp ax, 0f386h ; magic number returned by system debuggers" _# g/ R: o0 ~ J8 x/ q: m
jz SoftICE_detected
( x& I2 z6 e2 O& H
7 M- W8 v( c; a, w; K1 aHere again, several ways to detect it:
, u: X. @0 X7 r7 G+ P
! j) L7 m" ? {6 l/ ^) X BPINT 41 if ax==4f7 r/ i+ P; ?- ~) b7 O
# |/ v* @4 r$ q0 I0 X3 ^ BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
: P* R- y$ D& K" T: ~; g, W4 t7 |: y
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
. Z$ i! c* M& C' ?& k/ g
- W0 q5 K6 ~- s) H- M BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
& \" g+ w t' c8 n) R/ N/ q3 a! x0 F5 L: `" r3 _+ a) ^
__________________________________________________________________________! S3 v/ C+ q1 Z2 F2 d
8 s6 v x* a+ ?/ l" mMethod 13, B# X) z. G* v8 I) o; Y' H
=========
$ g" C( U4 U- c/ W- W
) C; }& |/ `6 ?" VNot a real method of detection, but a good way to know if SoftICE is
* ]( x4 Z+ ]" z* O% E- Vinstalled on a computer and to locate its installation directory.) t8 t! b2 `4 n, T9 E4 j
It is used by few softs which access the following registry keys (usually #2) :5 t2 \, b5 m* I3 V+ E4 {
4 w' y( f9 E' i7 ]
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion* O2 I" c7 B8 e) S) P
\Uninstall\SoftICE
" { x* B- E8 x! p-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
0 [5 }7 C4 R2 b/ H) s-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
+ r4 I4 ?# K! x+ I0 E4 a% G\App Paths\Loader32.Exe
8 `/ u% c( c, q y1 t, e% m5 `$ i. v! ^0 a+ k
3 S0 V" Z3 y& }6 d7 {. i0 j: ?
Note that some nasty apps could then erase all files from SoftICE directory+ n* T2 M. y+ @: i2 E" b
(I faced that once :-(/ H/ u5 N! ^ @. _% j( ^# ^0 a5 ]
0 f; u/ G+ X# f3 Q: jUseful breakpoint to detect it:7 ` k# Y7 \; f
, f; Z% P& M) H% {/ s
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'" q" Y" H0 Y! v& t% s$ E
' k# P- Q* U% c' j: ]" K__________________________________________________________________________
" u: T, y- n; t. r
) o$ R; B# Q9 n
2 Z2 G9 Q4 ~9 DMethod 14 1 d" g& O! _& U- P
=========% w( L0 e# Q. _! V& q7 L0 R) L% v
7 `4 _! M2 a: \6 {. w6 ?
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose" G; s/ x3 N+ p' u+ R+ w- f
is to determines whether a debugger is running on your system (ring0 only).+ i3 _9 q4 v2 s4 U& v9 _( `
$ p8 s. M/ G0 d6 G `( T5 n
VMMCall Test_Debug_Installed! m8 n+ k4 M4 i6 E2 E0 N% O
je not_installed
4 {. ^2 Q. o2 w9 K8 w Y3 j6 ^3 Y0 }' S) \$ J3 q& ^
This service just checks a flag.7 T( v# _3 {) t! \* @
</PRE></TD></TR></TBODY></TABLE> |