<TABLE width=500>
Y. `# P" r0 M8 R% H/ w<TBODY>) ^( w7 Q9 @ C& s3 }- q
<TR>
* o& E0 {$ T# i, ^6 P& K# V<TD><PRE>Method 01
1 s9 U. V9 M& X$ r q" ^=========' U0 [2 w1 m- T4 t) q0 k) s4 ~% A
% z0 |, {5 o- g2 w6 p7 \This method of detection of SoftICE (as well as the following one) is" ]5 D1 G; Q, g. [) ? M
used by the majority of packers/encryptors found on Internet.7 E9 C" s" d# z/ U e* N) D- e7 D
It seeks the signature of BoundsChecker in SoftICE
5 O, s& B) u0 p2 S
' j( d y8 v# U$ d D* r mov ebp, 04243484Bh ; 'BCHK'
, V+ d3 R$ w5 [, {! b# c2 M' S mov ax, 04h9 K, Q/ o( a1 y [" t
int 3
; W( q3 ^8 G0 u* \ cmp al,4
8 ]2 _& C4 n. d jnz SoftICE_Detected
{1 Z/ `: ?: i" @ e8 o
1 {" z; j4 t+ g/ j+ K___________________________________________________________________________
! X3 r7 I0 t' [' k! S4 R8 `. P @, F0 u
; o0 z7 y3 P* h% ]; r5 YMethod 02! K& {9 [6 F7 D7 E0 o
=========
8 R6 L* F& O& Z; Y' O8 s' H, K+ F, H1 a5 N
Still a method very much used (perhaps the most frequent one). It is used/ ~- w' y8 P. x* L: h7 A# r2 [4 {
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,- ]! z3 ~, x/ C/ V
or execute SoftICE commands...9 Z% X! `5 F( _ `) i, l# ^
It is also used to crash SoftICE and to force it to execute any commands! L' c# g$ G% _0 O* [) m
(HBOOT...) :-(( ! J- A0 |8 q+ z4 u7 U2 O$ E
7 z. B. C7 f! C- V7 O. L1 k5 z2 oHere is a quick description:! e% E* h# X: h& A5 o) B, S
-AX = 0910h (Display string in SIce windows)1 M7 v/ b& l g3 W$ j
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
4 ^! h; g# n3 S-AX = 0912h (Get breakpoint infos), U4 Y' g w& D! T
-AX = 0913h (Set Sice breakpoints)
/ n% H0 C ]: I! g-AX = 0914h (Remove SIce breakoints)% G8 {" B f3 b$ Q# J! t1 i$ ?6 ^( r
1 z! t7 T- M7 U% [! `
Each time you'll meet this trick, you'll see:
1 a7 J! g# q0 o9 U: e9 G0 Q+ u-SI = 4647h( {8 q: R7 F" E3 f9 S
-DI = 4A4Dh
5 E8 O6 e1 X6 N' l2 mWhich are the 'magic values' used by SoftIce.
8 v5 ]6 G" K7 _) J8 w W. s9 tFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.; G" H5 N, o5 g- m
% @! B; @1 @: w, a/ B5 vHere is one example from the file "Haspinst.exe" which is the dongle HASP
; S( i- U3 l$ W+ @# ^, E9 AEnvelope utility use to protect DOS applications:
, n, I: r- W! ^+ S- W3 b
+ f9 w0 n% N3 [8 K# _( t7 p8 E; [; h% ^; ^6 L
4C19:0095 MOV AX,0911 ; execute command.1 q# a0 U7 U! l: [9 h& u, H
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).5 e9 s! d# p* f% g: f8 ]
4C19:009A MOV SI,4647 ; 1st magic value.+ ?4 c2 z0 c& o+ H% E! ^# v
4C19:009D MOV DI,4A4D ; 2nd magic value.
! Y# `% C& `- g7 r4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
0 s4 J- U7 ~! \7 u& _+ c4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute; e8 j% Y g% B5 N* V
4C19:00A4 INC CX: E6 r [: f+ k7 }- z% o( s& H
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute; a; w# e- m3 g: m U
4C19:00A8 JB 0095 ; 6 different commands.. J7 m# a$ T; i/ x4 x- @0 N/ A
4C19:00AA JMP 0002 ; Bad_Guy jmp back.7 I2 s# M0 d5 O \& p" O
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
6 z7 |; w) v/ d' ~# h. n- v) r6 n3 A2 O
The program will execute 6 different SIce commands located at ds:dx, which! M% x( S) ~& j7 I8 M, O" d
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.& z) |+ a) w4 j! {3 k
0 |0 e! D7 G5 P1 @# C) k
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.( V6 w6 B* h2 s5 L) C% I
___________________________________________________________________________; `" n! @) h& T
$ |: W2 J! ^' p6 t2 N
5 H' @! ^) v7 r* R( l! ^; U
Method 03
2 Z# z/ [: H& c- e=========1 d! z0 b; m& Z7 l: h+ P. @
9 j8 |* k2 t4 z# N! t( OLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
- I K% n( Z4 g: \: o- K) D(API Get entry point)5 W$ J) }( m/ P5 L0 u
- r$ C1 v. t3 W. `% f1 P2 ~8 y. [+ b7 K7 W; h" h
xor di,di# [# N" L+ O. P0 Z( h2 ^4 [( h8 m
mov es,di& l, d: R) H) R( M4 K2 K" z
mov ax, 1684h 9 Y# j; S- u4 [1 A( ^0 |6 V
mov bx, 0202h ; VxD ID of winice7 P6 k( c5 |4 Y# j# z
int 2Fh
* j! x& P! N/ U8 A& Z* F/ ?$ t mov ax, es ; ES:DI -> VxD API entry point
3 C% U1 |! g( k5 k# o add ax, di9 N2 H& I% j' |# c- x
test ax,ax2 k2 Y4 G% S- h! m1 [& O. i
jnz SoftICE_Detected
; F' T5 C. c0 `! o6 D4 k) s& `! C5 K: q8 a
___________________________________________________________________________8 L0 ^8 _5 S O
- |2 `! x3 K! o7 MMethod 04
0 `" I& \# n& W- Z/ r' T5 Y; j' s- ]+ J=========) B# g3 i, o+ B& Y0 v& G' z
* ^. F6 f+ u; |3 Z* y0 b9 ^Method identical to the preceding one except that it seeks the ID of SoftICE8 |2 G4 M! O4 |4 V7 d. v
GFX VxD.5 H( H4 D5 r$ z) b
% }, H. W$ c6 n2 p+ L% w
xor di,di
: u0 V& x1 F6 P/ T* V4 z mov es,di
z5 l4 u! `1 H& e, ~, ]$ l4 Y0 w mov ax, 1684h
2 t: ^$ B: \ _ J9 q: z mov bx, 7a5Fh ; VxD ID of SIWVID- F" Y+ F) F$ h5 m' r
int 2fh' |% \3 l, }6 ?; A
mov ax, es ; ES:DI -> VxD API entry point
' {+ B+ O: v' i% y add ax, di
; a4 {" ~2 e# J( x% a$ \: i test ax,ax/ t; x( n T" w U; [) H0 t
jnz SoftICE_Detected
& F) R; z8 U* S$ F0 L& C2 Y
' @6 z0 J) a8 b: B% X: D__________________________________________________________________________8 a8 s9 P. R4 Q
* k1 p5 X+ m1 ]2 N4 q- B( T2 T, }1 M: [
Method 05
( g* ~( f% I4 B* H7 G=========
' C- B3 u/ m2 {4 J. q3 t( t( L. V$ D' F) P8 y+ N
Method seeking the 'magic number' 0F386h returned (in ax) by all system% J# M0 o5 X" ~' P. b6 q
debugger. It calls the int 41h, function 4Fh.
7 L. b" H1 t) VThere are several alternatives.
) k" y4 S9 x, i& |& c1 n' }2 a1 Y/ f1 L1 q; `+ U, n& [
The following one is the simplest:# X2 d! a9 o4 A- g' ]; j9 E
* t* `' T2 {9 Y& Q( ^+ Y3 c3 S9 U mov ax,4fh
- Q3 L. K; B N% q- Z" W int 41h
. q; h3 W1 R: r+ D0 |, g6 ` cmp ax, 0F386( ?8 P7 S( b9 k" R/ n8 q
jz SoftICE_detected/ \9 s8 R/ l4 W- M0 D9 L
- b0 y$ ]' M7 q" H8 U- \" [4 A9 L6 c
Next method as well as the following one are 2 examples from Stone's z2 ~/ Z* w! [; v
"stn-wid.zip" (www.cracking.net):
7 j9 ?6 i# e' ~+ W" L f# z# g- w) T c
mov bx, cs4 h# \5 \8 h6 L5 ^: Y9 s
lea dx, int41handler2
/ V$ s) y& Q: E4 p4 x xchg dx, es:[41h*4]
7 q! e2 B! E2 i' u6 z xchg bx, es:[41h*4+2]7 d8 j$ }1 r7 k9 I: s2 e
mov ax,4fh: s! b( F: w* O& @% r+ `
int 41h! f" r T: @5 @# y2 }; @
xchg dx, es:[41h*4]! B* C5 A9 H4 V% U) a6 S
xchg bx, es:[41h*4+2], e) w. a0 R) i ], H+ B5 w. n
cmp ax, 0f386h- a1 l# B" l& Y
jz SoftICE_detected
3 p! h$ X7 L% n* _9 w; X. p* P& G
int41handler2 PROC i; V3 s: K3 H; ^$ {
iret; z7 F5 a3 Q, ?# ?9 `9 [
int41handler2 ENDP
( Q, R- C/ o& B, t, R: _5 I& O K# e0 K9 B6 D
; l u: L3 h5 @: j6 u! h5 W0 }$ k% {_________________________________________________________________________9 M3 b& @2 I4 J) n
' s- c$ U K0 n, K3 I" \
6 s, ]: [: T8 [
Method 06
* F t/ ?+ g9 h* p6 X& B0 y=========
: A% A, W' p+ c: B. p, }6 G8 e9 N7 ^+ \5 l* c1 v
9 A1 e2 V( A2 ?# J4 p) \. m7 T6 w4 x2nd method similar to the preceding one but more difficult to detect:
; \6 W, e: Q, @% _/ {9 s l6 u5 g2 I2 S6 g a0 \1 v! Q
& _# J5 b, j- R- F3 A
int41handler PROC( g" s* { i% [& k' z6 ~4 g0 f
mov cl,al
$ i0 [9 N- K f' K7 I iret. T! K8 ]! M1 R
int41handler ENDP
% n+ v* s0 c% T; u6 q# K) h3 w2 S. x6 y# h# L9 C |
- i8 D# S$ S g; E xor ax,ax% j6 T6 p) o; q. D! s- \, ?
mov es,ax" [. r% R* [- g2 ~- g# l$ W% q% w2 k" l
mov bx, cs
3 g$ Z" l1 S7 C/ I( Y lea dx, int41handler
5 j+ B$ j) q! u4 _: S4 W xchg dx, es:[41h*4]
% g5 }9 D3 h/ l$ b xchg bx, es:[41h*4+2] w l/ v" m: n+ X4 s5 J& E6 R- k
in al, 40h
( q0 w( j# k2 q* L3 A# H) X' \/ _ xor cx,cx
) \! e \( M8 F7 T: s, J int 41h( y7 |6 J0 S5 r. X; ^( g
xchg dx, es:[41h*4]
; ]: e. f. ]1 B9 Z+ O% } xchg bx, es:[41h*4+2]
- X/ {2 n+ {; e9 ~# ~1 s( k cmp cl,al* B, H4 q: z: f4 N" g* ?: H( x% s
jnz SoftICE_detected2 E$ H2 ?, C1 B
9 E/ ~5 y0 r. O( L_________________________________________________________________________
: P+ d3 }! l# A1 F2 q( z* O
$ D; P% g" Y5 Q! F4 PMethod 07* O3 U" E! t" Z2 T0 c6 T1 E4 N
=========
( E, Z& M, J3 q% a* r
/ ~- N% n9 L0 OMethod of detection of the WinICE handler in the int68h (V86)9 ?' t7 U# E2 E' ~5 T
+ G+ T4 g! G# v! D/ t
mov ah,43h, N6 |$ b8 M- o s0 H
int 68h
8 E9 o4 R; H9 f5 K7 O, b cmp ax,0F386h
0 d6 M2 m' Y! x jz SoftICE_Detected5 w7 H7 e2 f$ s0 g, \; a
2 g2 C$ F$ Y1 P1 ^: K1 ?# Z- p* U
X+ r" X- x- }- P=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
) }" v% a2 t6 r6 [5 U$ T app like this:
- T8 C; m3 H8 z3 ^" R1 ^4 e! s2 s9 Z' h3 P) e' u# }, q% }7 |
BPX exec_int if ax==68& y) J3 ~5 l* \1 Z' P2 g5 {
(function called is located at byte ptr [ebp+1Dh] and client eip is
9 P2 `( `% s( S6 \( W" I located at [ebp+48h] for 32Bit apps)
6 [- ]$ N; z: e- r4 s4 ~__________________________________________________________________________
% B1 v, v. N3 V
8 B1 n% j7 \3 G4 x( D, H
- {* G) Z! L# ~8 G0 d, @ [% yMethod 08
, e1 x2 f' E/ W: A. _6 l0 n% R) ~========= W0 S1 H) I: X7 u
* A3 l1 L. ]0 d+ dIt is not a method of detection of SoftICE but a possibility to crash the
" d! p2 Y$ o. {2 U- Psystem by intercepting int 01h and int 03h and redirecting them to another
2 u; s) B% b/ w7 Rroutine.
. r) c5 F$ C/ Z' c3 o* WIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points3 n; u9 J: Z# \4 |% @( P- ~
to the new routine to execute (hangs computer...)! m& R/ E1 k1 i T$ L/ j
6 s0 M' \3 ?2 I0 Z& j
mov ah, 25h
5 {0 O! h' l3 G, d4 t, H, i mov al, Int_Number (01h or 03h)
- y' L0 X: e5 `( K+ n+ c1 K4 v* K- |4 ^ mov dx, offset New_Int_Routine
! N! g& f6 ]% Z& \' f int 21h
/ W9 E8 F3 a3 ?' a% [, L9 D) |5 g
* h8 W: c: L% h1 _2 b__________________________________________________________________________% I# i: j1 K2 m/ H- N$ D
4 l; u! o+ r @. g# vMethod 09
) t& }0 A/ X6 y/ Q1 G4 y=========
1 j* J9 s6 T9 Y! H# U2 `4 E% D- J! s2 G2 x3 h
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only) i3 V( d7 y( B; J( D, X
performed in ring0 (VxD or a ring3 app using the VxdCall).
% v. c2 ?; w$ Z, p# J$ PThe Get_DDB service is used to determine whether or not a VxD is installed
6 F; c* s- a! P5 Z$ jfor the specified device and returns a Device Description Block (in ecx) for) t& @. i7 F- L( u$ v* e% @( I
that device if it is installed.9 s' E) f* t- R( l
. ?7 s8 V. a Q( V mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID' ]: k+ ^7 z1 G F2 G4 q& a5 q
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)8 p J3 z9 c+ t
VMMCall Get_DDB3 P% @& ?" z0 R
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed7 f% o" ?( i' G& e
9 }( ~9 P& B1 P% Z! XNote as well that you can easily detect this method with SoftICE:: e7 J( v0 O/ c3 h9 d/ v$ ]9 K
bpx Get_DDB if ax==0202 || ax==7a5fh
4 l @/ z; O5 |* _( G u) a6 I$ P
. x1 l5 |; ]7 V* n, x U7 ?6 B8 \ b* u__________________________________________________________________________
# y2 F* w h6 [% j" O) Y. \
: {# S/ ^' J9 N N2 wMethod 10
2 A" t- R0 \# U) T* e4 Y=========
w9 b) V7 }/ c! k0 {& F
* }3 ]: n: t7 b' Y' _+ m" a4 \=>Disable or clear breakpoints before using this feature. DO NOT trace with
8 B' c4 o9 r' \* B! _5 ^0 z SoftICE while the option is enable!!
5 [' w5 A5 t7 {- a8 U: ~8 C: e) \
This trick is very efficient:7 g5 a! |; B! ^
by checking the Debug Registers, you can detect if SoftICE is loaded e4 C) b) P' T+ q
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if3 Z' ^: h* A+ u: D! ]8 X R
there are some memory breakpoints set (dr0 to dr3) simply by reading their
" J; `9 S3 u. D0 \6 [value (in ring0 only). Values can be manipulated and or changed as well
m8 W7 J2 H) ?" |& J1 f(clearing BPMs for instance)
0 S$ D2 h+ z- {6 _
9 [3 t, g7 b, p- D% c8 Z4 V# a__________________________________________________________________________
( [4 I/ b1 D4 u s. k& o/ i" U# Q( f5 i) I. W+ H$ ]
Method 11
9 @: o; g7 x5 F3 e+ K=========
% g0 c8 e0 a& q/ X* G% }% b! S1 N) I+ ?; M3 T
This method is most known as 'MeltICE' because it has been freely distributed
) y0 e& H: G" I: h' E K; D: ^via www.winfiles.com. However it was first used by NuMega people to allow
# v5 d. @" E0 USymbol Loader to check if SoftICE was active or not (the code is located
* H2 w! \, @6 _2 F4 @; I4 M% d$ Qinside nmtrans.dll).5 S3 r- y7 P' N6 t. E
' z: ~6 |! ?; J' q" w& W0 h* k* {% R
The way it works is very simple:
* Y @. t: e x9 L' L9 f! M& sIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
6 ]+ f5 |' K( W0 fWinNT) with the CreateFileA API.
% z( V8 Z( \. n8 B) \9 h0 V& r0 X
Here is a sample (checking for 'SICE'):( M0 G4 a, U/ ]* H' h/ ?) V& D& z' D
7 e ~' O( P# B9 O% SBOOL IsSoftIce95Loaded()/ S3 F v$ `) @* p$ [$ _6 c" @5 M
{. f0 w; l0 y" }; I3 ~
HANDLE hFile; % E0 X' g P3 h0 i4 I) z: f
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
N! }( r8 p/ I* x# d$ e FILE_SHARE_READ | FILE_SHARE_WRITE,$ b& a: m Q0 z% L+ U X
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);0 o3 d0 x# T6 w# Z
if( hFile != INVALID_HANDLE_VALUE )) j2 d( }$ \( T2 r
{
: [; {. v4 G. N o- c' X CloseHandle(hFile);
6 ~, O7 m* _) w4 g return TRUE;' W. g0 i% k9 U4 O. i
}9 i+ h2 Y$ n& D. _+ j' r
return FALSE;
' @/ e8 d. G5 _/ q& h}+ ~+ t; h- L3 }
! `$ M. `% k8 E5 gAlthough this trick calls the CreateFileA function, don't even expect to be
/ u0 c5 t& E8 ?; P1 K- jable to intercept it by installing a IFS hook: it will not work, no way!
& ^: o; T* O& Q/ y: J7 e9 E- K' eIn fact, after the call to CreateFileA it will get through VWIN32 0x001F% e; G0 Y% C9 ^4 F+ ~8 }/ ~
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
2 U8 `' i x6 o/ ?/ S- eand then browse the DDB list until it find the VxD and its DDB_Control_Proc1 d5 t% X& e3 n! U0 _
field.6 ~/ v3 T' b5 `9 ]3 L9 ^ K/ [ x
In fact, its purpose is not to load/unload VxDs but only to send a + s# o0 T v+ T5 c4 K* B$ _3 [" j
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
0 F0 \2 ?- M; Pto the VxD Control_Dispatch proc (how the hell a shareware soft could try
0 L' G& Q- l7 n" i. M: z; R. d7 H7 wto load/unload a non-dynamically loadable driver such as SoftICE ;-).
% I8 U1 ~2 a. P: [1 lIf the VxD is loaded, it will always clear eax and the Carry flag to allow ]- @' v8 ^' x3 z2 X
its handle to be opened and then, will be detected.
, L2 U3 G1 k& b* X+ I9 d8 RYou can check that simply by hooking Winice.exe control proc entry point2 ]# K# X" u9 K. E
while running MeltICE.
% X$ u' h i; j7 @9 }1 J" d
' G4 c2 Y3 _* z/ Y0 [$ |9 k
9 J1 }- E* a; [- ]- |- a1 d) J" e 00401067: push 00402025 ; \\.\SICE
/ I# o: q, ^# n" r4 B 0040106C: call CreateFileA. S: R8 B& j, F. y& E
00401071: cmp eax,-001
0 [% {# }1 |* H! p) P 00401074: je 00401091
- j3 X; k* \0 U* x [ g/ k, F! c( S, T4 y* K3 T
4 V% y+ Y, ^6 i9 N4 }There could be hundreds of BPX you could use to detect this trick.! n& `9 v5 B5 X9 P: ^
-The most classical one is:& |4 U' r/ T4 q( @
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||) i5 c9 U6 _( w+ G
*(esp->4+4)=='NTIC'+ B4 |2 c' Z1 F! m4 Z
" E4 F6 p1 V6 L n6 I
-The most exotic ones (could be very slooooow :-(3 a/ N7 v- m$ k! U, w* q" X
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') # q, H6 w) H4 q# i$ F5 `! R) W
;will break 3 times :-(4 J+ B* h' v+ Z, q" J% t" e
) _, v" y: f) ?4 Y1 B-or (a bit) faster: ( ]3 W; L% H% ?' S& f ~) b
BPINT 30 if (*edi=='SICE' || *edi=='SIWV'); S& e5 y1 c- \
, s9 r, B$ \' r6 _4 o' c2 `9 t
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
: P1 O; f: f* [* A. X5 A5 d) i ;will break 3 times :-() d( j3 y7 z1 F6 [5 s
. B5 r/ `; A8 Q9 I" p
-Much faster:
3 J. e% q, P7 o( [9 }' @! w BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'! t% ?5 a4 T5 S0 M9 p: S
4 t# @( E5 n# H' C8 g# n2 `* e
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
+ \" i" Q4 V' L; pfunction to do the same job:3 K2 q! r9 V- ?- b' V4 { e
' ? p% t- P6 U. ~% H7 N- j
push 00 ; OF_READ2 L5 I) f4 @( l& s$ `2 l6 b* k! @
mov eax,[00656634] ; '\\.\SICE',0+ a! ]( x8 |+ f4 i& [, d8 B2 ^
push eax4 O2 R) o1 c; f* M1 m) t5 |
call KERNEL32!_lopen- n% a/ H0 {+ C
inc eax
, K7 R+ v/ G! ~ jnz 00650589 ; detected
) K: L# v2 D2 H4 t/ p push 00 ; OF_READ& b7 U, A& o& k; s4 Y' F: [
mov eax,[00656638] ; '\\.\SICE'
2 n2 ^! |, h0 c* Q- V5 }/ I& ]6 r, } push eax
, D, K! W5 q b* n" c8 k call KERNEL32!_lopen+ v' {" E, a, S# @
inc eax# c* z) p: Q- x
jz 006505ae ; not detected# T7 i/ w' x! ?4 j5 K# _( T
( S, }% q/ K7 e$ G) K7 o4 N6 I
- `$ u# o E( i$ S [7 @__________________________________________________________________________
, B* `- l& y l$ O
0 q: C1 c/ \3 G2 \% Q/ O4 M0 bMethod 12 {8 w5 O: g1 F+ q- V5 m) z( c8 G
=========! d3 p5 n/ |1 G" g( \ U
3 ^" \, k4 `/ C9 [$ ^9 D" LThis trick is similar to int41h/4fh Debugger installation check (code 05- Y& M$ q; G! o- T' [! L6 M& M
& 06) but very limited because it's only available for Win95/98 (not NT)
+ }6 l; R+ {. B7 ~, Jas it uses the VxDCall backdoor. This detection was found in Bleem Demo.' B) j0 x) P" n$ w, C% Y
3 x/ H% n- G6 P9 G9 V# G
push 0000004fh ; function 4fh- ~" C/ s [+ e" v
push 002a002ah ; high word specifies which VxD (VWIN32)- k# A9 l( d9 V7 J$ P' z
; low word specifies which service4 ?% t4 \$ K# B1 o& {
(VWIN32_Int41Dispatch)
f" z/ X0 h( E4 Y/ `, ?: Q call Kernel32!ORD_001 ; VxdCall) e# P. n5 `; l2 m
cmp ax, 0f386h ; magic number returned by system debuggers4 q' c$ w' R g$ K+ X/ Q1 ]
jz SoftICE_detected) M5 ~0 g0 @) {4 P$ T+ n
5 \8 x1 K: V7 x5 m1 k" lHere again, several ways to detect it:
+ J; p3 W8 b W' }6 ~; {
! x- w0 C/ @$ M$ x% i BPINT 41 if ax==4f
, q9 R: P0 T% L! A2 t5 X4 F. O9 J, e( e+ y% S0 }3 d
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one" r/ s: |3 @* Y# _$ i- J
( }. T6 ?" V% O* j BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A" H! | X: _% Z5 ~
. C* Z* N7 w: J7 U' Y- l0 A2 _ BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
: D$ y# o: m, Q) R
. J/ f' h8 D. M! {- ~3 I6 F__________________________________________________________________________# d0 Q6 d: D" a! j( }9 A) o, U. M
" ~3 `1 ?: w6 _% f+ K
Method 13
9 e" {/ c) f [1 |=========
. d6 r6 M |5 p4 D: u6 F( `; N6 f2 p- J7 H$ H7 j* T' E2 n, R
Not a real method of detection, but a good way to know if SoftICE is3 P: N J; x. l# c
installed on a computer and to locate its installation directory.5 W, {9 ^8 {" w$ E7 d& e6 I
It is used by few softs which access the following registry keys (usually #2) :/ {+ V+ v6 U5 s0 G" V
4 G4 Y7 s [7 X) O3 U
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion; [4 C) U# Q7 Y9 A& r7 Q$ P- X
\Uninstall\SoftICE
/ _5 ~4 M& e4 u) H4 s2 Z7 _) S-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE3 t9 G$ t/ s( ^4 R/ i* X. ]: [" D
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& M& s% F: H. P2 N
\App Paths\Loader32.Exe( i0 i0 r+ M8 e; L
6 i i* Z( J! H8 q
4 o1 I2 s. S. F6 v/ O4 h# mNote that some nasty apps could then erase all files from SoftICE directory
7 A; g! k# ^; R(I faced that once :-(
$ F. A" O2 C% A4 ?6 `' j1 Q `' T, y6 A
Useful breakpoint to detect it:
% ~! z) V: s9 L* _
]% Z4 x! l6 e1 e6 G BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
, ^- s4 z% h. t$ O/ n( I; S# ^6 U; R& O
__________________________________________________________________________$ o! \# f' v3 |( V1 o
/ B# ?8 W. \9 A' _) `, G w/ i" Y e! k
Method 14 ; S6 ~" i/ M) P3 _
=========) m8 p1 g, l8 ]- P1 s" c
: r4 S2 G: W/ Z- g
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose. O, `9 w6 o V# C" d! q8 W
is to determines whether a debugger is running on your system (ring0 only).4 j3 b+ V. W& D% [1 |2 }7 [
9 K5 o- v+ `+ @8 V" w
VMMCall Test_Debug_Installed
0 \% m! k+ ?: t8 w6 q je not_installed
6 T" }1 d; t: b2 P% S9 y* x$ J5 G2 W! ^; ~
This service just checks a flag.
; f( h3 c( ]/ h5 c% `& j& e9 s</PRE></TD></TR></TBODY></TABLE> |