<TABLE width=500>3 ~( Z6 ?; T2 j, S3 D
<TBODY>
f* }9 g7 F# A6 A5 X' v<TR>
# I2 f( A% Q5 C" y' W<TD><PRE>Method 01 ; y1 K {4 \% E4 y% A* v
=========
4 M/ F: ]$ W' j3 G; W; c( g9 d3 ~3 F. V A
This method of detection of SoftICE (as well as the following one) is
n+ z) C9 V7 v8 }: x; rused by the majority of packers/encryptors found on Internet.
}6 g& f. D! e* R& I3 ?, @. r% kIt seeks the signature of BoundsChecker in SoftICE
& K& V7 k) t) a- h7 I- I
, R$ Q" _5 A# |' b9 o mov ebp, 04243484Bh ; 'BCHK'
$ N* Q8 a& \% G f! Z* u& e mov ax, 04h
$ s3 L: i5 w1 H! n, A0 m) Q! r5 r7 ? int 3
8 O4 n2 p9 e3 I) W5 y; z. ] cmp al,49 y" x9 {; Y& i+ N
jnz SoftICE_Detected/ N; u/ {0 M! ~1 [
" e( R1 t( h& H! w* A* ^5 |$ J1 I___________________________________________________________________________
# U8 d; M8 D; Q
+ r) ^9 s! q$ w9 i+ \2 h& S+ X FMethod 02
/ m) E, ]9 D: `, J+ Q=========2 ?( S9 f) V, r. O( ?1 w
6 f' X( J9 y6 v h8 \. T
Still a method very much used (perhaps the most frequent one). It is used3 o8 o3 S! W& }2 P. [" @
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,; y2 Q. s1 J" T# k" M- F% O
or execute SoftICE commands...
/ Y$ ~. J5 t' IIt is also used to crash SoftICE and to force it to execute any commands
. o" `! p3 O0 ]2 m(HBOOT...) :-((
* m; A; l2 o8 r, q) e
. z. j& g3 M# j% tHere is a quick description:
& S$ n2 r) x5 m! G! t1 I c-AX = 0910h (Display string in SIce windows)
7 R; e; ^. z! J1 f9 T-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
1 A; P8 u6 x/ |3 U* ^-AX = 0912h (Get breakpoint infos)
0 n0 g9 m6 N" C& [; E-AX = 0913h (Set Sice breakpoints)
+ H; u5 o0 t5 C0 C% Q-AX = 0914h (Remove SIce breakoints)
/ }& v; V# ]& }0 S0 R9 `5 q
6 H+ v# |" S/ g( I Z0 A+ rEach time you'll meet this trick, you'll see:
$ M' k8 q' F7 ~+ Q }; s' W. H-SI = 4647h5 m+ U& y& x8 ~' Q( s0 g
-DI = 4A4Dh
6 ] j3 k4 ~1 [: _ cWhich are the 'magic values' used by SoftIce. p$ y+ i3 b7 X3 B% ?* D
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
8 u) j% U, s3 z1 c' r7 ]5 @6 z9 p3 f2 o( g( u- {* \
Here is one example from the file "Haspinst.exe" which is the dongle HASP
1 I i$ U9 Z2 i4 W- E/ z& YEnvelope utility use to protect DOS applications:% k( D) o1 A4 x6 H, F; S
; P" `% {5 `1 K! n) ?
2 ~3 Q/ ^3 c- j) A, o
4C19:0095 MOV AX,0911 ; execute command.$ @) P) D) h* P5 X- a
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below)." ]0 f/ V& y! {/ \9 N
4C19:009A MOV SI,4647 ; 1st magic value.7 f2 @2 F( ~3 D' V- g( r
4C19:009D MOV DI,4A4D ; 2nd magic value.
% J5 O$ M: z4 j. g) U4 Y4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)2 C, L) h: E( ]$ ]
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
& n; \! I9 b+ |1 B' A4C19:00A4 INC CX: }9 Q! w, l- T8 B% d" J, A/ g
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute( t" [4 T* u1 }- E: w
4C19:00A8 JB 0095 ; 6 different commands.$ U' O! S; c+ f, n' k1 V
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
f+ E1 Y/ q6 r3 ]0 P) n# ^4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
0 s. q% {2 G7 F7 W* [' T9 T3 u9 e; j' }& P# i R" W4 A$ h
The program will execute 6 different SIce commands located at ds:dx, which. {' S6 I# y1 d/ D& r, p3 f
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
# h- [( Z4 q/ M* C' i" h
`* N2 H3 x1 y- l9 C! j* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
1 `& S& g% O* G1 r# C; A___________________________________________________________________________. {2 ~6 ^/ q* ?/ R/ V w0 P
$ o* `# H* j& t1 ? H" C) m& n- B' V2 {: ^' E7 |8 B# [" C {! i
Method 03
! N; o- N: Q/ Q3 y+ d=========
- Q- G6 Q. c% K$ M$ U3 N7 g$ D# [6 d" S
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h8 s) J9 N, A6 |5 G: e7 d( [
(API Get entry point)- D' R3 O7 O! B
~$ G* k2 [+ x% x2 Y v& n
M" q1 W2 P/ |: h+ l7 I xor di,di
/ `% Q7 ~, Z: W0 {, H mov es,di
/ D$ m6 q/ y! X. s" ] mov ax, 1684h
5 I/ m$ T) L6 _) ? mov bx, 0202h ; VxD ID of winice
7 w% n& v3 {, y: D5 { int 2Fh* [* @. X$ {9 H
mov ax, es ; ES:DI -> VxD API entry point1 `( r+ m5 k$ t5 t% d9 [: ?; ?5 n4 d
add ax, di6 W- j) H& Y* x. P; G
test ax,ax8 G6 f ? a( S/ s
jnz SoftICE_Detected+ W; b' E Z$ _5 I
9 ?$ K) S/ x% ? E$ A
___________________________________________________________________________
6 v9 ~; s( H& U, u, r: }' ^6 h1 ]. Y
Method 04
! o) F$ B+ Y5 `0 @7 ? o- m=========
% e/ ^# ?2 E* m. R5 f0 x1 D
- X7 Q9 H6 E$ ? d0 d. }0 i" }, SMethod identical to the preceding one except that it seeks the ID of SoftICE5 d% Q+ d2 y/ Z! W
GFX VxD.
% k: E! \8 ]5 p; X
5 D2 w' {- L' S3 A6 u1 f+ b. _3 Q xor di,di6 L. e& E0 {5 ], W, J& y( t8 L
mov es,di% o8 A' M' R8 a' \1 K' q' n0 V2 p
mov ax, 1684h
- t) h6 S: }, y8 F e mov bx, 7a5Fh ; VxD ID of SIWVID$ ^4 S$ D; Y9 Q* u# `2 V/ r6 v7 T
int 2fh h8 M1 H- u, p0 v0 u) y! M/ n
mov ax, es ; ES:DI -> VxD API entry point
; g2 j, p5 _& ?% V1 u add ax, di
5 s L2 C$ d. z' v! Y: D. ?4 v test ax,ax
, V* Q( i% D6 H Q jnz SoftICE_Detected% G: o4 D1 W: _5 p9 {( }# p0 M
% F' Z3 F. z* h9 r__________________________________________________________________________; ~& x- m; q% I
6 C8 P: |* W! K- F, p E
" Z; m; i$ o7 I3 Z2 H
Method 05
% h2 G( y8 I- W=========
+ H R. t2 {$ ]% u7 O
- v! Z1 c5 V7 n# p: T( V2 W/ a7 D$ pMethod seeking the 'magic number' 0F386h returned (in ax) by all system& t/ w9 s: D$ B- @4 v3 V
debugger. It calls the int 41h, function 4Fh.6 U+ ], a& z! E3 d( u/ {6 ?; n
There are several alternatives.
6 F+ U. x' r9 Q4 q' K( T4 H( [ G0 s& t! @4 N3 D
The following one is the simplest:
4 Z* L k, v; A" w: v
r; q- O' y' m$ ^1 T mov ax,4fh' h% j4 N( t+ z% ^! A. D
int 41h
9 R7 Z1 `/ L- ?7 l& c cmp ax, 0F386( Y+ U$ k _. s
jz SoftICE_detected
! f. B9 S6 i# F+ l7 k9 Z3 D$ K3 q+ b# o; F
- e3 D# n/ i( KNext method as well as the following one are 2 examples from Stone's * H7 ?/ z' Z: s, {0 p, Q% l
"stn-wid.zip" (www.cracking.net):
2 b* \ r6 U, R" ]) E l' e2 R
) r) B% y( N4 L3 z K$ J( S mov bx, cs; _2 Z2 p j, L3 ?4 K2 z; l+ l
lea dx, int41handler24 O7 h$ {; `% ~& Y$ m$ m* N$ k
xchg dx, es:[41h*4]
1 t) F: \( I. x. X xchg bx, es:[41h*4+2]8 k" B9 |, k) B1 S; U. |
mov ax,4fh
W/ k3 f! _ u; [) a int 41h2 H/ p( h' K/ ~( e) x( h1 h
xchg dx, es:[41h*4]: s8 ^0 `$ \& c* h# g; M
xchg bx, es:[41h*4+2], w2 o; S6 y% V, @* p
cmp ax, 0f386h) Z5 L% s9 i2 o- j2 _
jz SoftICE_detected& M+ ~: A" X/ e8 A. D
% N0 `7 a5 o1 K3 Q0 i/ y$ K6 r
int41handler2 PROC
& X+ Y1 f# P1 C2 _/ C6 {! y iret
0 o7 t) g" N' `/ d$ E5 Sint41handler2 ENDP
7 T X2 Y8 h* ?# q2 l4 z
$ O6 b& K: {" o0 \( o$ a' Y- F) J6 v, z; q+ n7 m# H
_________________________________________________________________________9 ?: X3 Q; k1 z% m4 z& U' x
' e9 w! b) a; P# C7 x
8 J% N4 m& s6 F. E- v0 }! w
Method 06# x3 D9 z( C) R5 ~' Y
=========; y) J R2 s, Z8 g4 T2 N3 p
" s. o1 ?: s$ ~: Z7 C3 ^
2 @8 F" C! f9 S2 H& i) s! q1 H2nd method similar to the preceding one but more difficult to detect:( g" }; ~9 z3 s! _; t: s
1 v1 ?+ S( P1 G- M2 e( s6 b+ b
2 p b+ ?. Y1 `# Q. Wint41handler PROC u" O+ i. |) }) {8 v
mov cl,al
5 i$ }& b) ?9 D. F: E3 @ iret6 s- u$ M) T. W* n
int41handler ENDP
; P; I( p3 P" P. b6 G0 p% \& m4 J H) t4 }
8 S" s6 g3 ?+ k! k4 U4 N5 G
xor ax,ax
l9 j) f W& j' ^( y mov es,ax- j) ]# c5 e- E6 Q5 x$ j! @
mov bx, cs
7 ~1 c+ j7 N: N" f, Y7 s! ^ lea dx, int41handler
$ Y7 k- d1 [2 A/ j xchg dx, es:[41h*4]% X8 S! f. X0 R% }* q
xchg bx, es:[41h*4+2]
/ g4 ^- @$ N' Z7 c8 D1 t) Y3 H! ^5 c in al, 40h
6 T/ n5 ]3 O2 R0 Q xor cx,cx
! G/ K$ D0 U0 a+ C$ A int 41h K1 `# W _( ?' m0 L* M+ O2 ~0 ^
xchg dx, es:[41h*4]9 {+ n* P- t1 V }1 T. C% k0 X
xchg bx, es:[41h*4+2]- m1 e; P- c5 y9 ?) _: m4 v9 D$ K
cmp cl,al7 Y7 p' w5 k! n$ `: m
jnz SoftICE_detected; N3 I" ^! \: n: W% k
5 N1 M* t; B& Z V( t_________________________________________________________________________. `8 K) w2 X: m3 w: ?. Z
( u- t+ X r5 C+ b, `! E8 V
Method 07- e4 i1 ]& j' x! ~6 }' s
=========
/ V1 G4 y4 z3 p0 i) W6 w" n w* i6 d7 ?' S0 [; y
Method of detection of the WinICE handler in the int68h (V86)
7 c/ V4 u- \! e( R8 }& @' j) X
3 E6 N: f z- L* l2 ~% H2 Y mov ah,43h
' P# e- E: b$ J% N$ g int 68h: [8 v$ ?6 ~) p* O. }" L4 j% U% ]
cmp ax,0F386h) @/ I# \7 ^ O* x; J
jz SoftICE_Detected
! o5 x" G) G8 S# m& A& K
' P K+ r/ J1 ]% J: _# V
$ G: a6 y/ f1 Z! a% g2 W=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit; b; |# E1 h% E% c" G8 a2 H
app like this:
% o2 c7 N' ^7 ?" n, u7 Y, D% ~
* O2 R: a0 K/ u5 ?) Z BPX exec_int if ax==68
6 n' x: v" }* L. v9 r (function called is located at byte ptr [ebp+1Dh] and client eip is- F, {# P2 _: Q+ q, ]
located at [ebp+48h] for 32Bit apps)) g( v/ L* c$ `( r+ d# J
__________________________________________________________________________: i) O- P9 S- W; T# P! d* c7 b
* h* e- ]# r! W v' B2 U8 s: Q+ z, S" y5 i! X+ R
Method 083 ]7 V8 ] `+ Q. @, \# D- J x9 K
=========
' L2 R$ z2 j. V5 g: [' i6 H
! l; ^& X1 J. S& L7 YIt is not a method of detection of SoftICE but a possibility to crash the, c6 B& P6 J0 |8 L
system by intercepting int 01h and int 03h and redirecting them to another5 q4 a5 N( ~ B! ~
routine.
( O0 G3 [2 h. p- `* I' K4 G- r$ H5 q& o( qIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
8 R# g8 K3 \ s$ n- n. T9 {to the new routine to execute (hangs computer...)# t( p% X3 \# Q% q
' B# {0 R& Z( ` y mov ah, 25h
+ i6 L( _5 d0 I) [3 N3 P mov al, Int_Number (01h or 03h); a; ]+ v# P* ?) u q& |4 p
mov dx, offset New_Int_Routine
: \' o7 z3 R# F ~- b- p6 k int 21h& ?' _' H3 L% q; V. |
9 s) ` b7 c8 a# X& W
__________________________________________________________________________
; f% m. Y! J. M
; I6 x% j" \8 } g5 n5 z- DMethod 09) f/ [' Y* _6 c% X& L2 L
=========
4 S o3 q2 d4 t7 \( I4 l+ W. w2 R' o) C- `0 f% u; h+ J/ p8 Z
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
9 y" H- s- T; i# Bperformed in ring0 (VxD or a ring3 app using the VxdCall).
. F1 h( [, A+ l& ^0 f( f9 r8 wThe Get_DDB service is used to determine whether or not a VxD is installed
% Q8 l2 ^# c4 X; ?6 A( x/ K# Sfor the specified device and returns a Device Description Block (in ecx) for
+ [8 c0 |# K; Y4 R- Ithat device if it is installed." ~6 b. B- @, f- a* ]6 V7 z$ b
' q* O1 k) _# W mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
3 K, ^9 @1 \1 |; a9 i1 I# d9 x mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
6 u: k; b" T3 j8 ~ VMMCall Get_DDB
% U1 q: m* N7 J3 L x' ]0 ` mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed; @7 ]% y4 E7 T" Q" n# P0 X
4 i2 Y% M, ]7 v8 s( f* ]7 ^Note as well that you can easily detect this method with SoftICE:9 r& F( O% w. h/ Q
bpx Get_DDB if ax==0202 || ax==7a5fh
5 B6 {8 o, A. q# f
+ ~5 w( g* R- N( Q/ C: a__________________________________________________________________________
* B7 O# n6 k) l* W6 ^8 r: H0 l) F# B" |" S- V& `! H3 b5 n
Method 10
( B- I( `) K2 r- K4 K5 M, ?=========
- ]3 Y* [& C3 |' L! `0 G2 A, X9 x
% O- j7 N! ?8 q* I& d=>Disable or clear breakpoints before using this feature. DO NOT trace with
+ o2 U/ \7 z3 G0 a SoftICE while the option is enable!!! Y( B4 n! w e' U* Y2 h
1 S1 P T. c" LThis trick is very efficient:" F* e6 g! h( e3 I- ?$ j
by checking the Debug Registers, you can detect if SoftICE is loaded
I$ U: K4 K, n3 N(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
+ b! K7 z2 L: l" B9 U% C0 Qthere are some memory breakpoints set (dr0 to dr3) simply by reading their$ r4 y" X8 ]+ B! p V) ]
value (in ring0 only). Values can be manipulated and or changed as well
- M/ @; _4 f; G4 B# `" v( t(clearing BPMs for instance)
0 U4 I- c9 \* V* i: i9 {, z) H) ~( z0 a( @* H
__________________________________________________________________________9 r" {$ x; C& h% ~/ B
9 P4 F+ i/ r8 ~' g% j( H, {
Method 11: A# |' f- o- W8 b, c5 ~+ @( w% U
=========1 _0 r, S; Q! ~ y4 k7 T
( G/ _% a+ G& nThis method is most known as 'MeltICE' because it has been freely distributed" O& b; c* f6 s
via www.winfiles.com. However it was first used by NuMega people to allow
' p2 a* w+ j7 D8 eSymbol Loader to check if SoftICE was active or not (the code is located2 a) Q, c# A) u4 T! \3 @# ]. D
inside nmtrans.dll).
2 A" Q* J6 Z) W: [& j; K) e% k
9 I+ z7 L/ x' E5 `$ S: aThe way it works is very simple:
8 y- y5 x0 M. @9 U IIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for) {6 _4 o+ I! v
WinNT) with the CreateFileA API.
5 z, ?% o" G: O; y& X9 {$ {5 i( m+ T j2 Q y
Here is a sample (checking for 'SICE'):+ {6 a4 C { v' G
, P& V% ~4 a! A! R0 z2 bBOOL IsSoftIce95Loaded()8 `3 m. c8 V/ `7 O$ a
{
0 }4 m0 ?% r6 w HANDLE hFile; 2 l0 c* s1 J% m7 D2 k5 q, t
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
0 N6 W- a3 X1 J0 J FILE_SHARE_READ | FILE_SHARE_WRITE,0 w# E& ?' U; B* S- t" y+ i
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
0 n# E! |( |$ d; z6 g. F if( hFile != INVALID_HANDLE_VALUE )
5 U2 Z. p0 ?' M# @+ v {( g% J2 I$ _7 m _9 X
CloseHandle(hFile);% x; M3 e# Q" c' ~8 @( e9 c
return TRUE;
! v: _( P( C, L$ r. S }1 P2 V0 n- k9 h, k$ B4 ^: \/ m4 A
return FALSE;; j3 m6 @9 e) E I# J
} C5 c' ]- e) D+ Q/ M1 W- A# n+ Z
1 C0 B$ b% j+ Z0 r
Although this trick calls the CreateFileA function, don't even expect to be* g5 R4 m1 v# Y# Z1 {
able to intercept it by installing a IFS hook: it will not work, no way!
9 R: C/ O" D. V0 @% e3 J) G6 _In fact, after the call to CreateFileA it will get through VWIN32 0x001F
3 n5 Y% c) F( W# \: |6 I, eservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function); ?% F% b3 Q0 N% h4 v
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
+ h! i) r& a. T5 e* ~field.
* C* i8 p4 h e. V) \" J* ]In fact, its purpose is not to load/unload VxDs but only to send a $ w' a% R6 v* U3 t% y4 s! a! g( ^
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
8 w; K( G {; [) Zto the VxD Control_Dispatch proc (how the hell a shareware soft could try
7 L1 @1 e/ p- j" c) H7 Z# u$ _; Mto load/unload a non-dynamically loadable driver such as SoftICE ;-).
B3 f& z% J- K4 A. O+ A7 BIf the VxD is loaded, it will always clear eax and the Carry flag to allow
* n7 m e, o: f |4 ]its handle to be opened and then, will be detected.3 N) J; o2 w% Q
You can check that simply by hooking Winice.exe control proc entry point
1 o# d( p/ e5 W; iwhile running MeltICE.
( G" E; o# I* x& y! s6 }; J# ?! T. }" d1 \! S3 w, Y- m
/ f0 H% b) o' p. d5 c 00401067: push 00402025 ; \\.\SICE
p/ j9 x# M( { 0040106C: call CreateFileA' P/ _3 @" A) `
00401071: cmp eax,-001. Z. D3 @. Y0 R. f6 {9 }
00401074: je 00401091) X" h: s- S; j- b' L7 z; F
7 N1 F8 a. v7 C$ a# Z# q! G# i8 R7 w
There could be hundreds of BPX you could use to detect this trick.; m! K* M# _7 K R* Y4 f' `' i
-The most classical one is:
1 p1 s4 y; ]) c _( ]3 ]. Q BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
( [4 H" ^/ f) P! Y0 I& i *(esp->4+4)=='NTIC'7 v+ @6 A( u$ G8 {8 v3 L
( Q2 T- e, _0 f R ]# A
-The most exotic ones (could be very slooooow :-(6 X9 C( }( E2 H6 E# G
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
5 }! {9 D: ~0 E3 k7 Q/ ^- d5 v% H ;will break 3 times :-(, o6 k; t/ B# s! E0 }- X
% Z, j) s! K o2 x9 ^-or (a bit) faster:
9 ]0 ]! Z: |; `; } BPINT 30 if (*edi=='SICE' || *edi=='SIWV')4 ^/ W1 [8 v$ C; j
; ~0 U/ f6 K# p- q* j BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 9 M' T/ H1 f+ ] J- @( L1 ^
;will break 3 times :-($ Q+ }6 o+ `5 u! T
" _1 w h( r5 \+ W" _6 t-Much faster:: l: u N$ Q2 {& s
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
. p% e& z/ m, d1 d5 I) c, ]" Y9 _3 O, W& n& k2 m& @ \! I
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen# A8 J! p5 W5 X5 j- e4 g8 b9 A
function to do the same job:6 `. t" O; N# l
. a9 {* G7 a0 x, I push 00 ; OF_READ
% T, a0 u l: g7 m8 y) v( Q mov eax,[00656634] ; '\\.\SICE',0
# p+ p5 @3 _3 r" C7 Q push eax% ~" e! I( O6 W- x2 r% o7 a
call KERNEL32!_lopen& S0 k! B8 M6 J7 Y4 t1 E2 G
inc eax
; ^6 r2 u3 x2 U F8 k! V0 S jnz 00650589 ; detected" q# I# g2 R8 A5 g
push 00 ; OF_READ ^+ F( m' x. c4 X/ X
mov eax,[00656638] ; '\\.\SICE'
) E/ ]4 Y4 W8 H* H$ p# N push eax( r( r; y9 R( V ^
call KERNEL32!_lopen
; ^' \; J I5 X. Z+ |* F inc eax
2 U: c: R) Z4 z( N$ A$ L- { U, g( o- Q$ W jz 006505ae ; not detected% K5 q. a$ I3 q! e5 U. ~- D% I
4 d. f8 i2 A: c; T) H
4 N3 b$ _: |, o__________________________________________________________________________) h9 T/ p5 t& `" p6 _3 @. t
0 y0 d' D, ` \: P. |Method 12
[, t4 H8 z3 A/ f4 n=========
& ~7 n, J* C0 ~6 n0 |& E. v+ k. f6 ~6 |
This trick is similar to int41h/4fh Debugger installation check (code 05
: _ n6 J( U! H/ s* q& 06) but very limited because it's only available for Win95/98 (not NT)2 ?, f U6 V! _
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.6 B3 K, Q1 P% K, D' [3 _* g9 O4 \
' K% W) C( \ v$ X7 s* \) @2 } push 0000004fh ; function 4fh2 X# f; w' t8 O( G+ P* |. ]$ W
push 002a002ah ; high word specifies which VxD (VWIN32)7 D7 t; g/ {4 v) V+ z S9 O& M
; low word specifies which service6 s7 o2 u4 D) l) B- d8 X5 k. J
(VWIN32_Int41Dispatch)
1 |3 W/ n" K# E call Kernel32!ORD_001 ; VxdCall
. E9 {' u9 s- g5 s( C. O- h! Z+ x# u cmp ax, 0f386h ; magic number returned by system debuggers
) @2 o. R, e7 o jz SoftICE_detected
3 u5 n' `- o* a5 U+ l+ p& J' Z( h
& r3 a7 m7 E c4 p( Y, Y( g {" e0 ^, tHere again, several ways to detect it:
3 o! u( b! r6 a5 F, ^
: {/ h; n5 z: ?: N5 y3 T6 t- g BPINT 41 if ax==4f
1 K1 ~) a: C. {
) Y3 D, @% Z% S3 G. f7 O: g1 a BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
5 G5 X& P) {9 t/ f y8 D/ |* N: P9 w* L. j. P3 [
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
* G6 T" o! x! t1 y! m6 T
2 M2 D' X; f# k, r o BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!* O6 A/ o6 b' O" Y6 E: w* w
$ O1 U6 d' ], h: I& W' y) E
__________________________________________________________________________
3 |0 C. I8 |( u+ x. s4 Y7 ^ ]) o- ?6 p9 }
Method 13
* L. O& ~' K2 H ^* n=========
7 r+ {3 v5 z& w; F5 N( m# Y% ~8 {7 y2 m
Not a real method of detection, but a good way to know if SoftICE is5 V m, a7 R( p. T8 A
installed on a computer and to locate its installation directory.2 y$ {$ u4 b' K) X7 C0 f! H
It is used by few softs which access the following registry keys (usually #2) :% e1 E# j7 [: X# U
5 \. _ u& `/ W" g2 C
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion0 B R$ h! ]9 m( @. t2 R" h
\Uninstall\SoftICE; B! K# d4 ], o1 p5 u5 y8 m6 L
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
J; x c$ w1 U r/ `9 t-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion8 Z0 R9 K a* H) j+ |- T
\App Paths\Loader32.Exe2 H" t) U$ G5 L( c% W: p
% \& S( Z2 K2 r7 J6 }( _
8 m& x+ u2 A z9 m- a F; N1 d" M D: @Note that some nasty apps could then erase all files from SoftICE directory4 _. V+ |/ R1 N- S1 K- [
(I faced that once :-(
2 \2 ^; v! R; a( B$ A, d( v0 \( c+ @# Y% d0 X) ?
Useful breakpoint to detect it:- s4 Q7 L2 d9 U& M
- e, _1 p! ?2 X- ?! K7 i6 h
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'% h) D9 {! x$ Q/ I' p( p
9 k, S) M2 F' t- w& R& N: K+ d__________________________________________________________________________
4 V& d$ s8 J" J- p; ^* A) C
2 J3 y* B+ I8 s! t% ^8 u- G7 C& f6 K( N5 J u; _1 A9 `% a# s# K
Method 14
" `& F" A8 S3 ], E=========
' x O3 h. Z: O! ^: \% z3 T
; Y, Y! R+ m, n4 {( g$ ZA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose' i( V4 S# R' D/ A i; j9 C
is to determines whether a debugger is running on your system (ring0 only).1 h, z. {) t' j Y% b5 l
! J& K- r/ G0 u4 \" N! p9 F
VMMCall Test_Debug_Installed
' C5 e1 U @' [ je not_installed3 x" B, }9 V- G* V% i/ O; v; b! H
- D4 G; |& u- ~2 D2 \+ M$ gThis service just checks a flag.
1 I; Y- Q1 l- A E8 n! J( \</PRE></TD></TR></TBODY></TABLE> |