<TABLE width=500>% G x1 F6 _$ j; T, G6 p0 Z+ R
<TBODY>& V9 a5 p) d$ ~$ x% L" s: Z" I
<TR>
( P7 S. i' Z2 u" }; I<TD><PRE>Method 01 [$ K4 n+ W' S1 \* \& R8 k
=========
( F, h% p' c$ k. A- m5 ? Y' w
This method of detection of SoftICE (as well as the following one) is0 N% E) n9 R; A! [' Y+ A
used by the majority of packers/encryptors found on Internet.# ~4 f4 C2 ~' _. e" d, t6 B
It seeks the signature of BoundsChecker in SoftICE9 S, n: K3 j3 ]! v
' m y0 v: Y. H( H6 P% W4 Q9 J0 C mov ebp, 04243484Bh ; 'BCHK'; s$ N2 |8 Q, M7 w4 A. }
mov ax, 04h
: x2 W4 z) L! Q n* o5 C, K int 3 0 V0 Y2 W; C- {. R* K0 S, U
cmp al,4
2 i, m) i J- j1 \& m jnz SoftICE_Detected# [( b) c0 a t( K
; _/ B& s' _: H5 C) n; E7 G. b___________________________________________________________________________
/ D( g; @- p9 g8 O8 Q- P" u) g
/ u5 d+ @- m2 o+ k& _7 UMethod 02
/ [6 r8 l/ ^/ b* I1 m=========
) I- n$ O5 @3 y1 C* f }9 S0 w, I7 [. N2 u5 ?3 y
Still a method very much used (perhaps the most frequent one). It is used
/ U+ v R5 C$ J$ D, Nto get SoftICE 'Back Door commands' which gives infos on Breakpoints,8 R; q$ I1 z5 |# ^3 U% n1 ?1 x* j
or execute SoftICE commands...
2 S' x: e/ E6 e( }$ z/ EIt is also used to crash SoftICE and to force it to execute any commands2 p/ V" t( U: Z( o. s
(HBOOT...) :-(( # L- ?9 M5 r: ?8 M& e9 Z
3 Y. V' h( F9 }) c$ I: j. eHere is a quick description:
1 f& _. V( v0 V- j* }9 G/ J7 C- e# q-AX = 0910h (Display string in SIce windows)
# m# O4 O6 B$ }5 \: I-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
# P7 V" |4 P8 G4 i' ]-AX = 0912h (Get breakpoint infos)
$ K# U% l/ w$ Q-AX = 0913h (Set Sice breakpoints)
' A% }4 b% w- d' ^9 T2 m-AX = 0914h (Remove SIce breakoints)
1 I7 g# C& q0 k, Q0 U! O H* ]3 J$ d
6 c6 h0 S1 C7 B5 T* U) w' dEach time you'll meet this trick, you'll see:
' w, ?5 m0 Q+ c- d( r-SI = 4647h# ?/ {: U+ q- w
-DI = 4A4Dh5 ^1 ]) d* q- D, c3 _- m7 |
Which are the 'magic values' used by SoftIce.
7 j4 W r5 s- d+ A5 J6 j) k: R; zFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.2 ~* J7 e, E% \" x; O
2 Q7 z& |$ s: p& a) }. \$ q1 [Here is one example from the file "Haspinst.exe" which is the dongle HASP( |4 F6 {" o( R3 o3 N0 R N6 U
Envelope utility use to protect DOS applications:5 O( Z8 u8 V- b! Y
& Y% X- w! Y) w' j; N
7 z' H( p, y; P/ S# C6 R4C19:0095 MOV AX,0911 ; execute command.
4 e- s0 g4 i% Y: m" @$ K% v" E, }" x4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).6 r5 H# Z/ C8 }: S1 t3 v. c& R" G
4C19:009A MOV SI,4647 ; 1st magic value.) \. C! A3 |2 J% D
4C19:009D MOV DI,4A4D ; 2nd magic value.3 T6 \. `5 r; `6 x; k7 S- N+ B
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)# L6 G' D5 [& g. ]5 V( C
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute7 M4 T, ]1 _- |' R) B
4C19:00A4 INC CX2 `, s' |- X; K' R) y2 L
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
/ O) q$ |5 j( H8 {! k) D3 t( E4C19:00A8 JB 0095 ; 6 different commands. n4 V+ N+ a: k0 l% K. |% a
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
; E& z3 i( D4 K. m" [4C19:00AD MOV BX,SP ; Good_Guy go ahead :)" a4 U b: G9 i4 y- x: s+ X
4 \* m, @2 P6 O/ U0 c2 A3 [0 x! E0 o8 OThe program will execute 6 different SIce commands located at ds:dx, which5 M2 D: R0 ?8 Y: p7 E8 j3 T( y
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.; u: |. Y! e. X3 Y" W
4 E4 d. k% k$ p* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.! O( Y- D! B* F u' c
___________________________________________________________________________
" N# x) j) s% {1 u( {8 X" V4 q6 e$ l$ ] n+ g* ^3 {: c
3 g: M; R: F* U6 wMethod 03+ ~4 [( j9 A. x6 T' p( b" l' Y
=========
' A& I" e$ P0 L) ^$ t" q/ U1 Q
! }& l' L1 w# h; iLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h% p/ p* t+ U B9 a
(API Get entry point)+ q% ?" ~3 d. O5 Y, `4 x
# T$ {6 Y" [% ~. i# _
! ~8 J2 {4 p" N/ n2 n xor di,di+ T$ P$ b3 n* i0 ?. `3 A
mov es,di: e4 ?. o" C$ H, e- @
mov ax, 1684h
- g, h) J) g0 ~" H0 a mov bx, 0202h ; VxD ID of winice
& `- ~! V& A3 t/ s/ e' y int 2Fh; R/ R2 A1 _. V, p" L
mov ax, es ; ES:DI -> VxD API entry point
0 S/ P& N! p6 |: F2 L1 z3 t& e add ax, di5 d0 d8 L F9 [. F
test ax,ax
/ M4 x7 d* k" o( Q# \ jnz SoftICE_Detected. X0 ^1 Y% n, x+ k
+ C2 s( _9 f; [2 T, L( S___________________________________________________________________________3 Z3 [' m5 h% J8 d( p
+ y- u0 U- B4 v9 L6 u' B* H0 zMethod 04, H$ Z& l# d% d+ H+ E
=========
# S% M, v' f( h% i2 K! L
4 X0 t. }% {3 o8 Y( J3 q+ ~* e( _" b7 kMethod identical to the preceding one except that it seeks the ID of SoftICE
3 |2 _% C0 T2 x9 gGFX VxD.
9 q P+ G1 G& e/ `/ L3 [) t4 W4 s3 W/ s$ _5 E* k! S
xor di,di
5 C" Q. Q1 R3 Y mov es,di# u8 ]+ {4 O0 \5 I3 j
mov ax, 1684h ! l/ G% ^2 h' {" D2 o- B, }
mov bx, 7a5Fh ; VxD ID of SIWVID e9 p9 c z; i) m
int 2fh) q- P! N; S! q4 D/ n& x
mov ax, es ; ES:DI -> VxD API entry point- U! t9 T; D$ A o' v7 L
add ax, di2 L, q+ @2 E9 D% G+ f2 i$ n
test ax,ax
3 n' K4 K( L& B ~( T, _6 m jnz SoftICE_Detected0 h" X, k8 l+ z) q2 ?$ \
5 Y, r4 l) j1 d% z0 C; U6 e__________________________________________________________________________- y& L4 W; c& m% \* Z0 N( J) K
- `$ C9 M- F6 x. A3 F$ p; ?
. ]* j- C( [/ L/ L8 D' C: M. B
Method 052 V* h( R1 N& [1 U }
=========
; I/ I$ g2 j4 ~) {' V5 X9 a$ {) Z/ t: H+ Y8 f' x
Method seeking the 'magic number' 0F386h returned (in ax) by all system6 T2 [+ c( N, u/ u* _5 P
debugger. It calls the int 41h, function 4Fh.
1 g `. P8 A p, d2 D2 [0 rThere are several alternatives.
; w; W0 d7 u$ r( `( a8 e. C5 t6 Z0 n' L. p
The following one is the simplest:
: ^# L) `8 O2 S3 q, }* _
, V; `. _3 Q( y1 H/ N* F# `0 L& | mov ax,4fh
, [; G4 B: G# }/ r9 E int 41h
0 I$ I$ \ @& N9 a0 h& e cmp ax, 0F386
& Q- O8 |* O7 H' X }& q* k jz SoftICE_detected
7 N) m+ u( g2 Y- y* R
$ `4 u5 b4 [% @+ y0 B' {& F
7 Q6 Q* I) {3 I/ d/ A! |Next method as well as the following one are 2 examples from Stone's 0 C+ P2 P8 p( X7 W& A7 f
"stn-wid.zip" (www.cracking.net):
0 ^( D t! X- k5 ?* n' j4 ?& Q4 q/ h! [
2 f7 g( R' x. M9 K mov bx, cs
- l- u( O6 d9 s# y0 Z. G lea dx, int41handler25 f1 j# t- l- m, z# k: S) G
xchg dx, es:[41h*4]
& o# @( o- `% I! \6 ^3 a# u8 y xchg bx, es:[41h*4+2]- I, H& @/ h# u! }, X4 e& W7 I; C
mov ax,4fh# h& c3 x1 E# c: f/ G* m1 _6 K' M5 s
int 41h! t- c! V# x( P* h7 _
xchg dx, es:[41h*4]+ m& ~& Z9 q/ O6 l8 E
xchg bx, es:[41h*4+2]
4 T- B" I0 v. L% P2 ^0 r: p8 V cmp ax, 0f386h/ E. `: M; F2 b8 a# f' v: A
jz SoftICE_detected. b8 z" L8 p" K j3 h7 o
% P0 w0 L/ [" fint41handler2 PROC6 _6 m: F& @3 t Z$ w
iret
$ r* Q. G+ N& |6 _* i$ gint41handler2 ENDP
+ I/ i4 Y7 w7 {2 O( r
) H6 G2 e! S3 o: z: J/ I2 F7 M" e! l) [ C% S: y1 J) H8 a! ?
_________________________________________________________________________
' o! f1 ]! M: p2 m- Z m2 g/ Z) p% z) P2 }5 V5 Z
' K, _5 i" a; p: j( {
Method 06
( y! i, \1 ~4 `/ y! B, W0 {0 X, c=========
5 c) I7 c+ N' G" y
' V) Q' T3 n4 K$ n8 Z' Q6 C8 M; U4 u, m( d1 Q* p+ i
2nd method similar to the preceding one but more difficult to detect:
) v) T5 e2 Z! X0 g1 b; o' H; Y4 Z5 t: g2 q# H
2 p, c5 L- M& X
int41handler PROC! K; o( ?! V. ]) \$ r- u' u7 M
mov cl,al6 P2 Q2 M, x3 K% B( M
iret. c! X( f( v2 C5 O$ v0 A2 ?. @
int41handler ENDP9 j+ [, i0 K6 F& {
( x, l7 U8 |$ x2 z5 |: o
- n& I* u8 C& {9 m xor ax,ax
; i# I( y, u1 ?. I2 `' @ mov es,ax! J# w5 ~9 Z2 E1 K' S& F
mov bx, cs3 k% d8 a m- y+ g/ @- F
lea dx, int41handler$ B) s/ O. s5 a5 v
xchg dx, es:[41h*4]
+ e% {& i9 U6 u' [. E0 B xchg bx, es:[41h*4+2]4 I. e3 Z: r$ o/ V$ E! ?
in al, 40h; h6 r8 N1 M0 e1 N: d) p0 |
xor cx,cx) e: s( q. Y* B9 ^" Y
int 41h% v F9 W5 P% G+ Z
xchg dx, es:[41h*4]- O" u$ b1 D) U0 p# S6 ]* |$ g
xchg bx, es:[41h*4+2]
/ L) S: c( n0 E6 R, K cmp cl,al
& U" o- e* {) n: e3 F jnz SoftICE_detected
1 i3 T9 w7 N1 r$ x* i! J4 n( ~$ k9 n+ Y; K+ @
_________________________________________________________________________- O+ \4 C/ q! y( M, Y2 I% z
* u* V8 i0 B4 O0 iMethod 07, f. ~- H+ J/ P
=========. }3 V- E( J: B j# P1 a" g
% N& q% ]8 Z8 c% R! O" n: ~! Q
Method of detection of the WinICE handler in the int68h (V86)
7 A1 O0 W7 G3 I; \6 z3 r& U+ D% e) E- J8 H9 u5 W
mov ah,43h
* w( O1 T+ W: l int 68h
1 Q7 t" j8 h* N0 U7 w! O& I cmp ax,0F386h$ Y! S1 g2 g: x
jz SoftICE_Detected& U2 c9 W3 m: G
% b& V( K! z n( o ?
: l" V$ m0 f. @5 H6 \, v, w
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
% u( ^1 W: D" E4 `0 C" E$ n3 B4 G app like this:5 _3 ~: ^/ q" m* j- Y& M, M! C
2 c b5 ]* \! n' ^7 Z BPX exec_int if ax==68
, G4 }- B1 X2 ~- z- V$ ?# |7 b (function called is located at byte ptr [ebp+1Dh] and client eip is
- w7 Q) |5 J- }2 M9 f located at [ebp+48h] for 32Bit apps)
0 u2 D7 f' m/ ?) ^ q" @__________________________________________________________________________! |7 D5 B8 ?% k: l, P4 V
, P7 Y# L/ `: u; A
6 P2 W, e" q9 |Method 08
: E$ o" n2 @+ m, O( h! w0 _=========7 Z" L0 i* G' D6 ~) R
* U3 A8 ~. i Z- U6 t
It is not a method of detection of SoftICE but a possibility to crash the
5 U9 @# e9 Z5 B) q; G' x$ @' Wsystem by intercepting int 01h and int 03h and redirecting them to another7 X) d, B6 P) J9 _7 A, _
routine.: H5 R3 g S, q; r
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points: _( i" j0 d; @& }, c0 l5 h
to the new routine to execute (hangs computer...)
0 g' Q1 U5 L) j1 L$ L( b2 m. d' v1 }9 U" H. ?; y% K/ T
mov ah, 25h
& x" Z0 l3 c5 `+ r mov al, Int_Number (01h or 03h)
. L& a1 M' r0 I0 T R mov dx, offset New_Int_Routine4 U3 I4 R$ \& n9 X2 |! r
int 21h1 M0 e4 ]: A( H7 E
' ^6 c- u! }+ V- z& z9 L. C__________________________________________________________________________
! R( H) L0 c* N, b5 i E4 v, g3 g ], L4 _6 s; {6 }! i6 ?* w8 H
Method 09
# F- W5 E9 y% _% U# s( X s=========
6 T" @$ M1 B; ^' x$ n
, v' q% L9 ~8 G# z- A* fThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only& B. Z. `3 Y! Y2 R, H. y2 ?
performed in ring0 (VxD or a ring3 app using the VxdCall).
) L$ c, R0 z( G6 j4 J$ P( U3 iThe Get_DDB service is used to determine whether or not a VxD is installed/ B% B: d$ i, i) y8 `
for the specified device and returns a Device Description Block (in ecx) for
|+ W8 @1 ?6 x8 Q# Sthat device if it is installed.
, ?; b- ]/ E1 g" l5 r; `7 w2 Q+ h- d4 r) j r) m- U; `
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID0 J4 J+ f$ e8 S
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)- X: D+ q. y( U' m/ D; R* E5 D
VMMCall Get_DDB4 G; X: ]+ ?4 O1 \1 Q8 u
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed- D( W6 k5 O5 C, Q* Z" _
6 G& U% I1 \0 }9 s7 BNote as well that you can easily detect this method with SoftICE:/ K, Y6 h" Y5 {2 i
bpx Get_DDB if ax==0202 || ax==7a5fh
" n/ g1 j4 f; N; r* u3 W. }; F4 t. _. x
__________________________________________________________________________; c9 F9 v: ?% l2 M W& W
; k4 z( Q1 l# k( @9 ]Method 10
& v" U7 r" C5 ^) P0 ?! j=========
7 n4 K8 V% [, ^# a4 J& r( f: a' \
=>Disable or clear breakpoints before using this feature. DO NOT trace with# c8 l0 b2 ?) z' Y4 b# ]
SoftICE while the option is enable!!& C* S: }, ^: Y, ]1 y b
n5 q( i) u) LThis trick is very efficient:
% e$ |# J1 ^) A O$ y: qby checking the Debug Registers, you can detect if SoftICE is loaded# p: S, }) M4 x0 v" v5 x t X+ ~
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if' \9 p( v/ b) C7 x. f9 V2 m" H
there are some memory breakpoints set (dr0 to dr3) simply by reading their
\: m/ _' P8 M5 i$ @value (in ring0 only). Values can be manipulated and or changed as well
) B# r X, Z. o3 }/ s9 p9 o9 S# c(clearing BPMs for instance)
1 |. S8 ?* ~! l) G1 U& I" }
( l/ s" H! I% h- g& o/ Y__________________________________________________________________________7 c, }+ p* G9 \/ L+ F! ^
. @( T- w/ A' ?$ L% D5 _, dMethod 11( b$ ~. B5 _+ W7 |
=========
: K- e/ n7 ^) s! L+ i2 V# h- q7 I/ D0 p
This method is most known as 'MeltICE' because it has been freely distributed
- _5 F8 i9 ]$ Pvia www.winfiles.com. However it was first used by NuMega people to allow
; e% ^6 F6 @! q! R6 s4 CSymbol Loader to check if SoftICE was active or not (the code is located. X4 T- x$ c( R X, g
inside nmtrans.dll).# X. _. U# ^+ ^" B5 O; ?
# T5 x1 x c& X; s0 XThe way it works is very simple:
; u6 c" @( B4 [: P3 a4 O. [7 ]% MIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
1 `8 B4 T- V2 Z* F; vWinNT) with the CreateFileA API.- i! q, @; @/ |! f
, u- E, P0 w5 @7 xHere is a sample (checking for 'SICE'):
5 z7 m/ |0 z: }# o6 E
& U; W$ F- |& n2 P) D4 g+ J- fBOOL IsSoftIce95Loaded()5 c+ M0 }# n k5 p
{$ b: B/ D; J- M. K& u( J- \
HANDLE hFile;
+ e% b9 S4 m9 f' X hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
8 q1 R3 t! U0 G4 V FILE_SHARE_READ | FILE_SHARE_WRITE,
9 M/ F/ i) f' z7 }5 B NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
! h0 k( g+ {# P) [5 `- p if( hFile != INVALID_HANDLE_VALUE )% j! R0 }+ q, w7 f
{' @) [0 c- x$ G: t) [9 U
CloseHandle(hFile);' D9 v" {' K( f7 r- D3 x
return TRUE;7 g. Q0 Q( o$ A9 C, i( K# D
}
! Y7 e% X7 e. J% R9 a9 m+ } return FALSE;3 x: {. b; r$ ]$ ^6 h
}
+ f* b1 r: E8 c3 | [$ l# k9 L& ?+ E1 x# e/ K
Although this trick calls the CreateFileA function, don't even expect to be) {/ f4 ?9 k E `7 r S
able to intercept it by installing a IFS hook: it will not work, no way!3 d+ G2 d! Q7 M4 E- l: c
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
2 W1 d8 O' i h* j7 w& ]+ Uservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
: o7 O! v% b5 B" Wand then browse the DDB list until it find the VxD and its DDB_Control_Proc
9 Y* n6 _7 @% `0 c1 a( wfield.
9 N0 { D. _+ \8 z9 \, I- T$ v# ^In fact, its purpose is not to load/unload VxDs but only to send a
& d3 i3 o+ u( B9 W3 a) vW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)* h- {/ ~1 x1 Z/ j+ a, T( R, N
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
& @, D5 H/ y Q* v7 \to load/unload a non-dynamically loadable driver such as SoftICE ;-).
) a: m% Y( M# ~- tIf the VxD is loaded, it will always clear eax and the Carry flag to allow
1 P- k$ J8 A% s q# h" _its handle to be opened and then, will be detected.; D# x( P7 X2 t3 r% }) l7 N
You can check that simply by hooking Winice.exe control proc entry point
- c% b5 {$ O" R& }# _+ {8 C! hwhile running MeltICE.. ?; ^$ ^. ~9 ]) u, M- H+ B
) G1 Y% s! b& w. q- D
4 w. N: O) X" F+ [; r, ^" y
00401067: push 00402025 ; \\.\SICE8 N( `, W: N( j2 ~
0040106C: call CreateFileA- a' q/ n: Y8 t
00401071: cmp eax,-001* {% n* `$ H% u) \) o
00401074: je 00401091( h; E; R; w" o9 S$ L7 _; C
1 P0 v9 }. Z1 [/ k2 W
, L- P2 m. B) y2 q$ Q `4 hThere could be hundreds of BPX you could use to detect this trick.
+ x/ I/ O9 X/ l. {; T7 D9 V-The most classical one is:
, C6 @" q# R2 n0 |, v! `# ? BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||! l/ Z& V6 O4 j' X8 ^7 b2 B8 \" z
*(esp->4+4)=='NTIC'
5 f- m! g3 }( P5 }7 D3 g! V9 H4 |: v) h @
-The most exotic ones (could be very slooooow :-(
9 B) K, N1 v5 o( d! a | BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
2 V1 p8 ~9 o$ U x( Z4 w- K9 Q ;will break 3 times :-( N0 ~% [. s* m$ h* n5 G* c
# G1 `" `. a4 F! g$ a- d; o-or (a bit) faster:
( B# w. Z% \1 J6 A: S8 `. s BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
3 K/ @$ u6 F8 ~7 G8 T% B9 P$ S+ \" ^+ S
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' ; Q9 [* ]& x# r" A; ?
;will break 3 times :-(
e8 o0 i, i; X- `8 p4 Q% j$ W4 [6 _) N* j0 r( v. V2 Y% H
-Much faster: X$ t# d9 Q' [" ]2 d$ g: X
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
% q% E i9 g0 r
% P, U# K2 Y* j( N" @; aNote also that some programs (like AZPR3.00) use de old 16-bit _lopen* D& ~' S9 }- u( k
function to do the same job:
' X. t- y3 p& y* N) P
/ d- `0 I: T) c, T$ r. S) x7 B push 00 ; OF_READ
5 ^. E' E: ^0 z& m9 S7 e+ | mov eax,[00656634] ; '\\.\SICE',0' x/ D8 p4 Z$ k; ]
push eax
) ]0 B% t' H# y) S call KERNEL32!_lopen
* ^+ A6 t+ S9 `! n" c: n7 z inc eax6 g0 x1 J/ B0 j3 N- w( V" q* K% o3 ?
jnz 00650589 ; detected. _- K; n5 E. Y. G9 U/ [
push 00 ; OF_READ
0 r( `% t) _' E% X! G5 D" q+ u. t/ ^5 C mov eax,[00656638] ; '\\.\SICE'$ }5 |* f# F) ?% r- G
push eax
+ {7 p( w/ }- a0 y( a: c call KERNEL32!_lopen. K9 W7 l7 ^! M) U3 y7 h @ U
inc eax8 u3 \1 x3 K+ u; _
jz 006505ae ; not detected
, r8 [5 R) v7 H' v5 |+ @
5 x: e! b% a, A1 }# d: n+ v: D4 O& H9 Z( S% V) m2 B
__________________________________________________________________________
: [! E2 |/ b2 Y# ^2 H
# w8 l& ]' e+ J! ~) M V* ]) YMethod 12
, \( E$ \+ l: o4 K4 d. T9 |=========8 M; ~. J4 Q9 c% A5 c: g
: L7 K2 m' r1 {: |# j
This trick is similar to int41h/4fh Debugger installation check (code 05
: l5 N/ s9 a& S6 _& 06) but very limited because it's only available for Win95/98 (not NT)
3 s6 Q. x% L( g% mas it uses the VxDCall backdoor. This detection was found in Bleem Demo., \9 T" M& _! F+ j# U
6 @) r2 m9 v* T$ @" x# S
push 0000004fh ; function 4fh
; F. q6 e9 @/ v6 H ]% h" J push 002a002ah ; high word specifies which VxD (VWIN32)
' u9 m$ P6 d# z; n" { Q# g! I2 V ; low word specifies which service+ O3 R" z& B5 X; _
(VWIN32_Int41Dispatch)' `4 A0 ?' J1 t& G
call Kernel32!ORD_001 ; VxdCall
- N5 _' @2 C$ W5 W cmp ax, 0f386h ; magic number returned by system debuggers
! @/ D8 A& S: b: a' Y jz SoftICE_detected. j1 k# h# f; Q( l
3 m' V. ~( m5 }5 J9 I; E/ C oHere again, several ways to detect it:. `8 ~% f3 r2 ?# a& D: ]
( V& k$ |2 B. r4 ^( r2 S: V, j) D
BPINT 41 if ax==4f
4 l; ^3 E& t6 B0 m+ M+ M* E- w4 S2 g9 O* T; H
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
) A7 ]# R) L/ J- j- w, k& c8 I. Y, V, b% ~, ^/ k5 m
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A, n4 \1 E$ _% |/ }" u6 Y% w
: e6 d1 ]$ \8 `% V. P% X
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
0 Z8 O# i- b( P8 m
; o' u+ i$ {( W) m) ?8 G4 n__________________________________________________________________________# q U3 G7 Q# q) f3 Z. a3 Y
8 }3 f" x% t0 d: h1 X: r3 [! N: ]8 t
Method 130 Z$ S. q3 [& k' k1 |! d% Z
=========. B% k6 m6 d" Z4 [
2 Q$ v6 R+ } n INot a real method of detection, but a good way to know if SoftICE is- n. J, J2 S. x# o! @9 J0 h
installed on a computer and to locate its installation directory.
) N! X* [; K- K' d8 T' a, SIt is used by few softs which access the following registry keys (usually #2) :3 z$ Y9 h( T+ L! n
6 [. @# |) ?3 `! a" u-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion Y9 W; O, \- i9 u" D
\Uninstall\SoftICE# E; c) H, \% w" c1 S, `
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
) D$ w/ r' q' E0 }: n A-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 u' N3 |2 I! e9 J
\App Paths\Loader32.Exe
& ?+ a; E1 K. }' t( B0 i
4 V# ]9 n, G% N5 H n0 g8 M9 T" f* ]9 F, F8 x% Y4 K! y
Note that some nasty apps could then erase all files from SoftICE directory
8 F3 V* n5 A- z9 |. _( A(I faced that once :-(
" Q9 `/ ^( o# S' }) G% }' ?; \+ U+ y4 k) s g
Useful breakpoint to detect it:
. a2 V9 c _$ d" |# P% c9 B6 ^/ T. I2 ]: g" l0 C* T3 P
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'& j" a5 p6 q* s* Z$ z
7 B- A* a4 A8 O9 I9 g1 Z+ K__________________________________________________________________________
% m V. U( j2 W) r
: K/ H/ A# B( v+ m
; T5 ] H3 L$ V3 CMethod 14 ( B, u7 g" s# ~8 e
=========& A- Z$ M$ X4 U, r+ u6 i
9 l! o+ j! ^) ]( r% }( H) z: W
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose: P$ K# O) q3 n/ X1 M7 n
is to determines whether a debugger is running on your system (ring0 only).% M' m4 ^- |' V; D
. _4 \- A6 t& K' Q4 n+ E7 u VMMCall Test_Debug_Installed
9 W( F7 C; v3 Q je not_installed+ a4 @" N/ r" W1 T
: \& g: a+ q: X9 x4 X% o/ e, f
This service just checks a flag.
; f0 N* ^/ q8 j& v9 N- F5 a</PRE></TD></TR></TBODY></TABLE> |