<TABLE width=500>
+ I" S0 ?1 i( W" q% b- ~- M' y<TBODY>
& n: z' H, d! k* `0 {( W<TR>6 V {6 H* a' d3 e( f _* ?) W' X
<TD><PRE>Method 01
: c* E4 Y0 H( Q. K, h1 j=========
; j3 y& ^- i* r8 l; h% v" z$ u; c0 n8 a1 L3 k$ e
This method of detection of SoftICE (as well as the following one) is
& Z5 b: P6 g7 ]1 xused by the majority of packers/encryptors found on Internet.
. {- `# s! \: U. TIt seeks the signature of BoundsChecker in SoftICE
0 Y2 ?* G& V4 s6 O, R) P7 S0 P. g4 `; ^0 p' z+ u" I
mov ebp, 04243484Bh ; 'BCHK'
! ~+ T5 k, `2 i" H1 l mov ax, 04h
4 x& H6 b1 E, F. D int 3 R* x. H. @( b2 C, A
cmp al,4* V. [% N# j' ^: N/ z7 r$ @0 o
jnz SoftICE_Detected6 l* U2 J9 d- [5 r
3 c2 Q1 A6 w) Z6 f* F
___________________________________________________________________________
( B" A9 |+ t* [( H: C+ I5 R2 ^$ j- K- v' V
Method 02. N; n& y! ?7 s+ l
=========
8 p5 z6 F& s. q! z7 m7 R# R/ S0 E
7 {5 K. p9 e; F6 PStill a method very much used (perhaps the most frequent one). It is used1 b# x3 d0 q3 g( f" t* T6 T" e
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,! M- p% ^" \# U2 b: n3 K" o' |
or execute SoftICE commands...
, M, Z2 b3 O6 q& k; l+ l( sIt is also used to crash SoftICE and to force it to execute any commands
$ W$ F' k" u: o" f: ^! h* v(HBOOT...) :-((
# d. e& [0 `. d/ Q. g) P% {3 Q- A9 s' Q. J5 g( |/ p/ h. |
Here is a quick description:5 r: G- A4 @- ]" M
-AX = 0910h (Display string in SIce windows)
- ~5 \6 b9 n( @( f& _-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)+ t4 k% \2 v4 S( f
-AX = 0912h (Get breakpoint infos)# Q7 `8 I+ q' a( n1 Y
-AX = 0913h (Set Sice breakpoints)
# r' \/ ^$ C+ X- X0 w-AX = 0914h (Remove SIce breakoints)
4 y* x& j) N$ [3 B9 D R2 v. {% B. L% t4 [3 h
Each time you'll meet this trick, you'll see:+ p. e% a% \, p& }8 j: h
-SI = 4647h
7 `# c& C x) J( v8 h7 G) U7 ]" U-DI = 4A4Dh' P1 s0 r- m, `; i+ z
Which are the 'magic values' used by SoftIce.7 k! I+ C: B+ M R
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
# A- n2 w; J& E
1 c# i4 b! q7 e/ Y1 l* |# wHere is one example from the file "Haspinst.exe" which is the dongle HASP2 E7 N+ Y7 z, V3 e% ^' i; w
Envelope utility use to protect DOS applications:2 g& b# [. }/ A3 d9 o& k7 w6 y& W" ~
, x9 V- \: R" r- M7 `2 a% e7 A+ u' Y) `& n1 j0 ?# b2 {0 n" ]0 N
4C19:0095 MOV AX,0911 ; execute command. k: v- s" U) X: ^ E
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).2 t- M* m* `, D; B" m8 w
4C19:009A MOV SI,4647 ; 1st magic value.$ \8 S* \5 _; p8 D
4C19:009D MOV DI,4A4D ; 2nd magic value. d9 z2 _/ H% ]% f
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)3 N: c4 U, R# |* K: p
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute* b: l, x0 a) Z$ Y: G0 ?/ q6 X* g
4C19:00A4 INC CX
( l6 x9 n0 e& ?' O4 m5 N A3 A4C19:00A5 CMP CX,06 ; Repeat 6 times to execute3 i$ {1 Y+ C6 @- x
4C19:00A8 JB 0095 ; 6 different commands.2 n3 R- ^# y2 I1 C9 W
4C19:00AA JMP 0002 ; Bad_Guy jmp back.7 Y5 r# X v1 c" I" k3 ]
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)2 _+ N( D( E; ]: R, B
: v5 o! Y* P$ h" e7 WThe program will execute 6 different SIce commands located at ds:dx, which
2 e ]( H8 h2 {6 M- r3 G% O3 f4 Hare: LDT, IDT, GDT, TSS, RS, and ...HBOOT. c9 J9 k U; L" y5 ]: O8 x
$ Q. j0 p$ G4 n% J* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
; }" h( k# X9 M7 B/ q! Z___________________________________________________________________________
1 j/ J- _$ ^$ a, m; e5 d$ O
, r! \- ?& y! S& Q5 V& c6 Y) s$ D. c8 M/ K% H) | N5 m
Method 03
% ?0 g$ n1 c$ ]$ @# u=========" P3 a: R# b6 N, B
, ]! u( ?; E( L! KLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
8 U3 u# A2 m- I4 A(API Get entry point)
9 y3 x0 h7 [1 ?3 u # l& ]" b9 b( x2 v% {; ~
9 b+ M$ e- Y$ i. h8 O xor di,di y% ~0 ^. L, q: b( w9 h9 _. m
mov es,di- E% j% H' T1 D# @
mov ax, 1684h , ?& C! L* x3 z, t8 Q M! k! c* b
mov bx, 0202h ; VxD ID of winice* ?4 }$ K" X: U
int 2Fh
: u. \& i7 M. r1 J. \ mov ax, es ; ES:DI -> VxD API entry point
]; x% Q: h$ |4 G add ax, di% e: X4 b- x/ n3 v
test ax,ax
" r5 c, k: I T# z# V9 Q jnz SoftICE_Detected
( T; M6 H( B! `1 \5 q& z0 S; V2 n' C$ W3 d9 l, d6 ~# T4 e
___________________________________________________________________________* E/ {' y) g* S, q& H
) U7 \+ d0 l4 T6 sMethod 04( a; w* h" b5 P# h6 C2 _
=========" T- ?5 C: p# J0 _, G' o
( S5 ?/ d2 V8 C7 f% k
Method identical to the preceding one except that it seeks the ID of SoftICE
6 x6 ?+ A0 ]2 ^3 i9 NGFX VxD.
' M' W: ~: P) k8 x! |3 ~
4 u F$ d! w' X I: a xor di,di8 S* y5 z- `/ z) l0 }2 M
mov es,di9 y: P* |* |2 v; ^" M
mov ax, 1684h + C, p. W- j1 H, |7 L
mov bx, 7a5Fh ; VxD ID of SIWVID
% o/ P7 E2 R1 p2 P: v; X, Q5 l int 2fh
: i' P/ |! ^8 e9 f8 |# q mov ax, es ; ES:DI -> VxD API entry point
* D# i, P( e/ O! o( Q' u add ax, di; H" w/ W1 W7 R, y
test ax,ax, E5 u: i& [' }/ ]1 `$ C4 [9 Z
jnz SoftICE_Detected
; q s* m! b/ [1 [: o! f* q
& G8 m1 a/ J" D( I__________________________________________________________________________
; _) B D* A" ~) y( ~
. P; f% K, a, C! [. t' H; e3 {% U% J! `/ }$ L
Method 051 v' W- p' R) Y
=========
: l' ]; `5 M0 _6 o* @/ q: V, X9 I8 k+ g' p: b c! G5 j+ p4 B5 b
Method seeking the 'magic number' 0F386h returned (in ax) by all system/ B5 k6 U5 _9 L/ c# ~% g# D6 b
debugger. It calls the int 41h, function 4Fh.8 G" M: }2 ^: A9 o2 T. ^
There are several alternatives. 3 M& x7 C+ s; b1 C5 P8 C
9 t8 H" h) {2 N, m* s+ O& p
The following one is the simplest:
& l- w' C% b/ F3 t
5 y: T/ C0 K3 O3 X mov ax,4fh
" L& {: X4 w! b int 41h, B0 g5 [' V$ V5 U2 [. E n
cmp ax, 0F386
0 V1 Q2 a" u3 p jz SoftICE_detected+ h9 q3 |- i3 `! Z$ g, g
- q$ G' |* O4 H+ A6 A3 z; l
& j/ z: c# u9 u+ N2 [
Next method as well as the following one are 2 examples from Stone's
* N9 ?8 ~$ L7 n+ k! E$ Z, B"stn-wid.zip" (www.cracking.net):
5 P; r- e4 |1 P$ h. w1 O; j4 K# ^2 f& \+ |( B
mov bx, cs5 \5 h' I( W9 B1 U7 y" f; y8 C
lea dx, int41handler2
9 Y) u2 V2 T/ T xchg dx, es:[41h*4]( O. [7 O+ U. X7 O) y' r' F; J
xchg bx, es:[41h*4+2]( J, N j7 T, _" e$ r9 `& y# b
mov ax,4fh
4 J4 ?+ }( d+ M) M2 J: g int 41h
- {2 }7 ?$ t0 A& K( | xchg dx, es:[41h*4]
3 z$ E2 f, F% g: ~/ k* X xchg bx, es:[41h*4+2]
6 J$ X% s- w0 ~" g9 K cmp ax, 0f386h
* x4 Q1 _& G; Y/ `/ [! `7 D7 P jz SoftICE_detected$ N# ~9 r! l0 I0 M1 z( a
" Z- M/ q: A _1 ` [+ b
int41handler2 PROC
6 D, k& y/ l/ Q8 ^/ e @ iret
: |3 l7 K* a- ~7 _: p( U/ kint41handler2 ENDP% f+ g4 C3 G: m7 @; ^& f2 k
! y* z7 ]6 i' p% J# n4 t+ ?) e" I1 ]7 c! h* i
_________________________________________________________________________! l) D: Y5 k, t' y6 D% l
" z5 W- z5 Z3 D9 m6 E" h8 Z$ {$ r5 |6 |8 u
Method 06
' _& g/ v z# w7 r. _/ F4 q, _8 |=========
D4 b# W3 H) t( _: I; v$ @+ k6 I1 T+ {& B8 {3 p/ i
; o( W% N/ k: t# E$ S7 }2nd method similar to the preceding one but more difficult to detect:
/ s) k! Q6 j4 T! L: i3 x! T4 L/ v, N0 n5 ~
4 q! M. {9 P4 k, j7 _; c& g/ {( wint41handler PROC2 i9 e6 ~9 f& v$ b0 q3 S
mov cl,al
! R5 h+ \1 a' w. I3 b iret( m% y( a( P+ F
int41handler ENDP
9 v) c1 v' {9 Y5 {$ e" E. A& D* }: X& H+ h
8 ~4 [7 }; t3 B$ J" [ xor ax,ax! h0 w7 A+ S2 H( w5 V) i, g( t
mov es,ax
! G+ j* g, C, e mov bx, cs
h. Y5 k/ t; Z2 t. M' C! p lea dx, int41handler4 C, a) Z8 v6 Z4 @8 c
xchg dx, es:[41h*4]% f' h7 k3 [. b" |) [
xchg bx, es:[41h*4+2]
$ M5 @9 b9 R: P% p in al, 40h
' ?7 i0 T1 L8 K# O xor cx,cx/ r" J; F/ H# ~6 |, i3 ]% M
int 41h4 @* k) t% B8 w5 Q
xchg dx, es:[41h*4]
5 z- Q1 }5 }. n& Q6 p# m4 r# j9 |4 ? xchg bx, es:[41h*4+2]% }; ~- Q$ ]+ Z9 u: r" C5 k3 a' u
cmp cl,al. \: v5 l3 ?. S; X3 h
jnz SoftICE_detected" O- ~/ j, }- N
3 m4 s5 P; r1 X5 H& T) \, B3 C
_________________________________________________________________________$ C/ z9 `) y/ D' c# f
2 b; P' r* x2 C0 T6 ^9 t; QMethod 079 s( H1 _; i5 g4 x4 `
=========3 {3 V8 V8 [& Y# M6 F- o1 B
8 D) R: | i& ]$ v0 {7 a
Method of detection of the WinICE handler in the int68h (V86)/ A; P$ A' u" i7 ?- s8 U1 J$ [: _
0 y3 j8 L9 E4 r9 B( Q+ p
mov ah,43h5 ~8 q! B( m; o" }2 N4 w) D O
int 68h
7 b* a/ l" T/ T3 c0 s1 P2 z8 x cmp ax,0F386h
* Z( _% a. J; @1 W0 N t, ` jz SoftICE_Detected
" I0 A! z3 i) m9 E1 p& N5 x: \9 M# n ` \2 V( T0 M( ^7 h: b3 c& J" g' Q
4 J6 V H) D+ k3 X) B" ?=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
. }* F$ \# ~7 p7 ] app like this:5 v# p }. m s4 x) y
* X5 g+ c% _5 A: B! y" B" w7 d* l7 U
BPX exec_int if ax==68
4 k$ y3 | u, t+ q6 m (function called is located at byte ptr [ebp+1Dh] and client eip is
r% C# E" o3 E" Z located at [ebp+48h] for 32Bit apps)
" c* j) Y, l! \) X5 [8 b! q5 B__________________________________________________________________________- T$ N* ?9 _, g$ @' [/ e% ~
! I1 W) \0 M) [
9 F$ g9 e& W3 e6 ]/ B6 ?, R; SMethod 08
4 L* ?! C. i+ U8 T# Y=========
" R& Q+ c5 q8 c) q3 D, j" |* [6 @0 J6 A
It is not a method of detection of SoftICE but a possibility to crash the
% O' K& H5 W4 e3 b3 Isystem by intercepting int 01h and int 03h and redirecting them to another# D2 t1 G* X& k$ I1 t
routine.
% ?& l8 K z6 V, NIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points" F( c& p Y' v. [2 i
to the new routine to execute (hangs computer...)
# [& k. }4 Q% `( v! m
E! |/ u! ~% o mov ah, 25h
3 |4 B( X- l6 l7 |. Y. Z mov al, Int_Number (01h or 03h); Y W2 x* G c" L* N% K
mov dx, offset New_Int_Routine
% w3 }% M$ p; ~ int 21h; T% u4 g2 v! M0 W2 v' L
1 D( o* A' D3 B+ w( p__________________________________________________________________________- F9 _3 X. w0 V! n# A
' E% j, E* u- L/ TMethod 09& |+ y2 g0 z- s9 Q# f4 [1 T" M L
=========
5 E$ a% O8 ]7 Q+ A' ~* p# g9 @# X9 ^4 e) E: Q+ |1 e k
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only5 v/ c- a5 w/ |8 r# a* c; h
performed in ring0 (VxD or a ring3 app using the VxdCall).
. \" }: g1 D7 s+ n2 pThe Get_DDB service is used to determine whether or not a VxD is installed
$ ?6 J) }8 g3 @" V1 Bfor the specified device and returns a Device Description Block (in ecx) for
- l2 v" }" O- U" }$ x" ythat device if it is installed.
8 r0 e7 }+ C% K9 X/ P2 s7 p5 j1 T, u- ]9 }
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
' U# h7 Q# }: g' g5 P: O" m mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)7 u* I/ k: \( R6 F n1 r" S& k
VMMCall Get_DDB. A |; W) [9 t& _0 @0 S+ Y
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed% s/ c- |- c1 w; |
& F6 k' o4 V) {3 n* E- Q9 [1 s2 ^Note as well that you can easily detect this method with SoftICE:
! ?7 T; V9 [+ u bpx Get_DDB if ax==0202 || ax==7a5fh" e' W/ N' T; [0 K7 N
4 p5 \ F7 F) U# w. E
__________________________________________________________________________* f" c, F; D9 b+ i/ Y9 R+ ^
, z% `1 O" F4 I& R) v5 HMethod 105 C( u4 v8 Y6 t8 v7 m M6 h
=========
. \( ^! C+ G0 J
" l! z# k- W8 S' m+ Q# T N=>Disable or clear breakpoints before using this feature. DO NOT trace with- t9 p9 A6 ~3 \* y8 y
SoftICE while the option is enable!!* w+ n! _# M6 |% n1 J n8 E6 C
' I" g* v$ k/ S% B* h Z4 x
This trick is very efficient:' X2 F# C z) E9 @) U K: I# `
by checking the Debug Registers, you can detect if SoftICE is loaded
; x' a" I* R. u! K/ P" G, R4 z(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if+ p+ t: M2 r" Z3 u- n0 S
there are some memory breakpoints set (dr0 to dr3) simply by reading their1 [# e. j* Q/ S9 |
value (in ring0 only). Values can be manipulated and or changed as well- D5 E" p- Y6 ^% @4 [3 Z- q
(clearing BPMs for instance)
" Z6 b. @7 l4 v) v* p4 }+ e8 G8 [' Y% ]
__________________________________________________________________________
2 a* W9 Z; X$ V1 t' s$ d ~3 f& _( J9 L1 U5 v3 J
Method 11: O( F- h" b# z$ @* v
=========/ W; K' \" h4 x3 @3 X/ t- Y
: t; V- s; I1 O5 N
This method is most known as 'MeltICE' because it has been freely distributed1 z9 @, d2 U$ u$ Q$ Y$ S. t
via www.winfiles.com. However it was first used by NuMega people to allow
]5 ~8 l7 Y' G0 ?% USymbol Loader to check if SoftICE was active or not (the code is located
+ T8 R$ B; U3 q. Kinside nmtrans.dll).$ v- x. [; y8 n- U
9 U/ X. \' g! A/ m0 v1 O3 Q
The way it works is very simple:+ }4 L8 `* _" l& y
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for! K' Q1 q/ y% a: t9 h
WinNT) with the CreateFileA API.; ?4 E5 `. ?, S8 M6 M
8 R5 z- v1 R# L& l( {# lHere is a sample (checking for 'SICE'):( M; ]' `" A- {" X. s3 o- ~; N& f3 T
1 b# P$ O3 @0 \" `/ M. {0 [
BOOL IsSoftIce95Loaded()
7 ], w1 f, A, f/ X{
5 ? r6 j8 A1 e. N# t# n9 ~ HANDLE hFile; 8 G) o- V" d! c4 U& G6 U1 T
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,/ Q! ^5 \( l# b, k3 f- `
FILE_SHARE_READ | FILE_SHARE_WRITE,
$ t! h( `) Q' ? N8 p& W$ P/ f9 H* \ NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);: y* d& M" d6 C: g
if( hFile != INVALID_HANDLE_VALUE ): ]: E6 M6 p# R+ y* K; s
{! f" p* h1 C/ O
CloseHandle(hFile);
: v- I4 z/ b3 i, B" P' r return TRUE;
; ~( |6 Y1 V7 C; x, b. C }9 U+ d0 e9 v* o6 c( v, x2 F: F* d
return FALSE;
5 a4 H0 T0 n- ^ y}
: ?4 e/ J+ I) w" Z u, u9 \3 l$ l1 `- W* e" T% h, ^& f
Although this trick calls the CreateFileA function, don't even expect to be, Y6 Q$ i4 e1 ~1 H: M, G0 M
able to intercept it by installing a IFS hook: it will not work, no way!
3 [/ _8 p" k$ q$ Q$ Q' SIn fact, after the call to CreateFileA it will get through VWIN32 0x001F) Z! b! z# {& s3 f' [: y
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)( l! N( a& e ~% W; p' l
and then browse the DDB list until it find the VxD and its DDB_Control_Proc e% |- c. |' T1 v" W" e8 U
field.
$ v) X8 \/ u+ T% i" y4 [In fact, its purpose is not to load/unload VxDs but only to send a
* X) P& r1 \$ _" ]( QW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE), r6 [: u- @4 }$ E3 X9 V
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
% V* Y; |$ ~1 P3 E1 Tto load/unload a non-dynamically loadable driver such as SoftICE ;-).
# \5 Q! z! x3 P. { cIf the VxD is loaded, it will always clear eax and the Carry flag to allow
( j8 F, B+ i/ q2 zits handle to be opened and then, will be detected.) z# N3 C% `/ K$ }
You can check that simply by hooking Winice.exe control proc entry point
4 d2 \) f' [0 k9 H* w/ Qwhile running MeltICE.
2 r9 p2 ], G6 f1 U
1 L$ ^8 U6 i+ v) p7 R1 g1 z/ G! J9 N$ R q: [" [7 I$ ]
00401067: push 00402025 ; \\.\SICE
* y3 n4 w F8 _; N& { 0040106C: call CreateFileA G! ^/ g1 q$ M$ J! X& f3 y% [5 f
00401071: cmp eax,-001
; _7 L$ M: d# U' K3 \0 f 00401074: je 00401091
4 E+ w) ~4 _7 S% |( C) G5 ?6 Z
' k0 y1 {# ~) Q! j7 R; [2 N0 b" \9 I+ h2 E% a, Z2 L4 N
There could be hundreds of BPX you could use to detect this trick.2 i- n0 m3 Z/ ?) \
-The most classical one is:. @7 K* Y0 c6 s5 E6 e
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||% D, A; X* V) c5 B7 t
*(esp->4+4)=='NTIC'8 {3 ]9 v) t9 n4 \% d
0 |5 ?4 n. |9 x( m* v-The most exotic ones (could be very slooooow :-(
. z' N0 C+ R6 c* ?" Y- j7 O BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') ! E* I: [9 ~5 T2 v' E- D
;will break 3 times :-(0 u3 J# Q+ k" u+ z4 H5 D
: [3 p1 I" q5 \" J# W8 B-or (a bit) faster:
: _$ W# C3 V$ V( m BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
5 \0 P/ {+ U/ a3 S! {# K
! O$ V$ h3 i; ^! V* ~0 p4 S" |' Y/ h BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' + X3 |! Y' y# r- D' z2 c9 U+ w
;will break 3 times :-($ b" X$ Z+ n) a2 {6 u e1 D
$ v) I. Y7 [: v+ w2 k: s-Much faster:
" s" j4 ?# Y x1 c1 ^ BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'7 _. g7 ^5 k4 M! {" A
0 F' A& s1 v* }: Y2 o. V' B/ v
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen* j P# `) f2 s8 }* X& y S
function to do the same job:
' E- _8 @( `6 d: S- i- L" I* [% e; m0 i8 l0 X6 G; J
push 00 ; OF_READ7 d2 W. _/ w& [
mov eax,[00656634] ; '\\.\SICE',0
6 `3 z) Y. @. t0 J push eax
8 e( T |8 U% d4 @) F call KERNEL32!_lopen7 }- u% i, H( M2 N
inc eax
! {7 I! v' z1 l* |2 U: T0 o jnz 00650589 ; detected3 k; s3 t2 A+ }: m& F
push 00 ; OF_READ9 h* N k+ y& Z8 H) `! g' e: s
mov eax,[00656638] ; '\\.\SICE'
. r7 W; V9 @) `' x5 ?1 H push eax
7 j; P5 F/ c8 t C4 |, J# h call KERNEL32!_lopen5 f/ v. H% R4 x
inc eax
) i6 j* E+ Y/ x) k jz 006505ae ; not detected
$ ?! o2 r6 w7 i0 ?7 ?; T) [
0 t! W) y- A9 m6 |: Y& D' X0 [+ d" m. A* i3 C4 I |
__________________________________________________________________________
3 i+ p6 W7 A$ F/ P
9 E9 J& ~# R0 J2 {6 R% g, b9 T3 pMethod 122 f; {: q) j2 B4 p% M0 `
=========
1 x$ F0 J! n% }5 F
! w8 R9 \5 Z5 w, P3 gThis trick is similar to int41h/4fh Debugger installation check (code 05
+ J2 A0 D! q" B3 ~9 W& 06) but very limited because it's only available for Win95/98 (not NT)
- u8 B1 ]" f* ~' kas it uses the VxDCall backdoor. This detection was found in Bleem Demo.& W! c1 O0 e" @5 E
/ |- E% U2 j0 X
push 0000004fh ; function 4fh
$ w1 E& S9 n7 t push 002a002ah ; high word specifies which VxD (VWIN32)- t' q8 |! Q9 y, S. z
; low word specifies which service
5 \! _. H. d3 Q# a: o (VWIN32_Int41Dispatch)
* {% ?5 R) O3 J+ F7 o$ V call Kernel32!ORD_001 ; VxdCall
D% }, K. i2 R* Z cmp ax, 0f386h ; magic number returned by system debuggers
: i G! C9 M: M8 L! v jz SoftICE_detected3 Q, Z F( ]8 z# y
: m: D$ G) g5 }% jHere again, several ways to detect it:
( Q! s" Z( L" [. b/ H2 T( ~) x# s* Z3 _9 k' q! z6 C
BPINT 41 if ax==4f$ w `# g. Q0 q
$ w% U8 m) I& K# q& \4 g BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
- C1 v7 `9 z% I: u* w( k/ ?
! D. ~" u3 P" E% g' U BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
: Y1 m5 ]! m4 P" F5 ?! T8 y, P# p
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
1 g0 i! ?/ w! v2 J" a; f
! z t$ a2 |2 d0 m__________________________________________________________________________
q5 I T3 z2 I Q
1 w; b; o! |$ e. j, wMethod 13
. s/ V1 c0 j) N4 u5 i S=========
( C( J2 d; \# i9 M# B/ P0 e( F; ^3 d2 B
Not a real method of detection, but a good way to know if SoftICE is% z: b% \- i3 J& N' r3 C
installed on a computer and to locate its installation directory.
4 D4 ]! [3 i7 H; X, \. | H/ aIt is used by few softs which access the following registry keys (usually #2) :
8 ]. y$ M' f# X
: n( D9 ^- c3 m- ^- t# |, ?-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion. T0 I! ~2 q% f+ C# o
\Uninstall\SoftICE5 C1 X# }; b( h
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE9 U, ~8 P6 w% \% K, F7 O3 U5 m
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
/ F& ]: _5 O/ N$ z3 k\App Paths\Loader32.Exe
' Q: }) E: K* }) M. {" u
}% n* l& b/ _+ j5 ^6 K% e
9 L7 t0 y& y" ]/ v# vNote that some nasty apps could then erase all files from SoftICE directory
2 A( H% M, z* _. L g(I faced that once :-(/ ~: f6 v$ t2 z6 l; l" c' I
2 k6 e2 m1 |! y0 @6 i4 b% U- a: n
Useful breakpoint to detect it:
) G$ b# }& W) L" o' ~, U/ l2 U5 Q. G- A/ l) [, }% r* f. D$ ~
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
; f( A4 O- A3 v/ i2 N: q6 E8 i4 \' X* |7 I- e5 Z( P& \, F4 q
__________________________________________________________________________: i0 h2 f2 c) c1 J1 T2 n
/ W7 w5 t/ B+ x5 C5 c4 Y4 i
: R K; W. U8 t! ~' OMethod 14 # p5 j" Z5 E+ H' S
=========( l7 @& [1 n" y9 ]0 [8 @7 s7 ~
i" t# h* w& l
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
/ t; ?+ O9 I1 Q2 ~is to determines whether a debugger is running on your system (ring0 only).: Z. w ~0 @- K% l+ s
3 @: ~1 H' M& e
VMMCall Test_Debug_Installed
8 Q$ n% A2 G7 ]" S je not_installed; z8 M2 @' q0 v8 Y' R0 O, t5 B
0 @7 v, X. |0 R: E/ v
This service just checks a flag.: E; T/ V9 S/ N
</PRE></TD></TR></TBODY></TABLE> |