<TABLE width=500>
% X7 G0 N2 y" ~<TBODY>
* U! Z! f2 N& H) ~; l% Q<TR>0 x! w. q. ^! F* t
<TD><PRE>Method 01
; X/ `0 q! \1 p6 m) f4 [0 B=========
2 D( H9 r5 Y% @9 J7 d: u5 d- u% ?% |8 B8 f% S1 m
This method of detection of SoftICE (as well as the following one) is7 d; Y# ~+ G+ x; u3 ]! Q
used by the majority of packers/encryptors found on Internet.+ A; K* u3 c9 K; _% L, z! B8 P4 `
It seeks the signature of BoundsChecker in SoftICE
- F$ X# H" ?* V$ z* u
+ D. X# n1 c" { mov ebp, 04243484Bh ; 'BCHK'
2 m- b+ [' @; {# N6 c$ L; t9 b mov ax, 04h
) w' T9 g; A+ Y5 N4 | int 3 8 I8 r L' P3 G8 W9 h- P- `: e
cmp al,4; W7 ?% W9 f& m# U7 y$ w& h. W
jnz SoftICE_Detected: [/ S8 b% x* w( e% s! a6 i
" z. V" e! G3 S B2 c; U
___________________________________________________________________________
$ a0 T2 @ e7 _3 \( b2 S) x- q1 }- L7 @. O' w* \9 ~( s2 |4 E) l1 R
Method 02
! @8 S* a$ n3 F) m/ j$ O4 {=========
, ?1 V& k4 z* q0 N
: C- b" O# q' q% MStill a method very much used (perhaps the most frequent one). It is used
# }* S% C6 j: p; z% Y6 ^% qto get SoftICE 'Back Door commands' which gives infos on Breakpoints,1 R2 _* B5 q+ C1 _0 u1 u
or execute SoftICE commands...& Z6 }; N( M' o Q& z4 K2 V
It is also used to crash SoftICE and to force it to execute any commands0 y, ]+ a7 ~1 \; M
(HBOOT...) :-(( ! Y) b( U2 w8 X! e' \) c0 ~
, U7 j( C# r# T9 E
Here is a quick description:
/ L$ z3 q$ Z Y2 K2 A% l$ I-AX = 0910h (Display string in SIce windows)
4 m/ }8 s: r a( p8 I, g+ R' M-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)3 N8 i8 e0 z. H& V. i: v5 T2 e
-AX = 0912h (Get breakpoint infos)3 c, V8 C9 n/ u1 e; V
-AX = 0913h (Set Sice breakpoints)& O2 L) X( B- a% D1 M0 [; J& J+ u
-AX = 0914h (Remove SIce breakoints)5 ^ }/ }# E! B0 R- Q/ \
I5 l/ i7 f& r( tEach time you'll meet this trick, you'll see:
# h2 G1 w& ]7 k- L Q-SI = 4647h) t. B0 a3 s4 F0 j% u
-DI = 4A4Dh
4 O- U; t6 @) R% UWhich are the 'magic values' used by SoftIce.
4 @; }/ x( ]* b! M& D2 V' `For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
$ x! C/ a- |, }, h; ^2 W( a. P' a Z& c! v2 f* z K
Here is one example from the file "Haspinst.exe" which is the dongle HASP
# Z: z6 _# ]. |1 uEnvelope utility use to protect DOS applications:, {! U$ U9 O7 |% h. |0 L3 a
( E; U' [: ~8 c; b8 ?$ N! q$ a8 G7 r
4C19:0095 MOV AX,0911 ; execute command.& o& M: S0 z4 o4 B" [
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).2 [ x+ i( P; M1 d4 e
4C19:009A MOV SI,4647 ; 1st magic value." F* k5 ]; X3 c+ Y" C, W. m
4C19:009D MOV DI,4A4D ; 2nd magic value.& j* \( \7 g9 q! [8 L( z1 X$ t
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)$ z1 ~* P$ o; U6 ]
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
2 `( D8 ^; X! \4 f) [; D4C19:00A4 INC CX7 _$ j4 `4 Y1 t) O7 t
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute: L) m* [4 n0 B" M+ O% b: T
4C19:00A8 JB 0095 ; 6 different commands.
5 R, @% G. `9 O0 Z# C x4 K0 t4C19:00AA JMP 0002 ; Bad_Guy jmp back.8 T- Y+ |* \- c$ Q* Y/ f+ ?
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)8 h& @/ c, m: K P' ~4 |& w
% Y4 ]# t0 q$ P2 ~
The program will execute 6 different SIce commands located at ds:dx, which
' U: Q [/ ]4 c1 @3 b7 i& \# Pare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.+ q) O3 {: A/ N) l4 Q
* x A& A S; h" {
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.2 B/ q% ]6 K# j% j
___________________________________________________________________________
) s. E8 S& x3 F0 S( N( j
) x# L( c6 \) j! S& h' `$ X* u; v% P* G$ X8 H$ Z
Method 03
0 h! v- U- K; u/ h0 i7 R+ L=========# a1 Y9 l: r6 R% |: t' v
+ @' W: w" u2 b3 v" H0 v& m4 d1 L$ zLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
9 ^! ]2 n3 A- q(API Get entry point)8 N: r$ C" c z4 s4 b
* P* X# _0 U9 @
) H6 [3 Y" k2 W2 |( y M xor di,di
4 l, u% q* P [& H mov es,di: I4 V9 |+ \* k% l
mov ax, 1684h * Q7 i9 G* u# q) [$ y9 s7 Q6 u1 w
mov bx, 0202h ; VxD ID of winice
. H* R, b, C- R5 B7 ?7 R, }7 F int 2Fh) V, P+ x+ p9 |9 }
mov ax, es ; ES:DI -> VxD API entry point
9 q) m& X2 n+ e9 n) N add ax, di
" o) {+ c. [( n0 y test ax,ax
+ E: t# Y( I# D0 l jnz SoftICE_Detected" C; {+ K0 \, m- Q3 ~5 U
! f: @( C7 y0 M1 _' x' b- Q1 H; }
___________________________________________________________________________5 k+ S, {9 w% e" t5 U* [
0 K5 }/ g% M- P% p2 ^' X: q
Method 046 h% ?$ r5 n! u6 f
=========/ Q* S2 |/ V! J7 s$ t
3 ~4 Z. ^; A1 c2 |, Z5 AMethod identical to the preceding one except that it seeks the ID of SoftICE6 d3 |4 v5 [2 h6 H) c& e8 J4 N
GFX VxD.5 r0 J) I8 b- ~% w' l6 N- i4 Y. I: K+ d7 q
5 P8 Y3 A. G) |8 q7 i# s8 M xor di,di3 r/ ?9 R' a8 \3 U* {
mov es,di
7 i" p, w) ~* W8 _8 \ mov ax, 1684h
9 |: U$ B) q, R2 x; I mov bx, 7a5Fh ; VxD ID of SIWVID
1 Q: B9 K4 J/ @8 _( {: v4 r' | int 2fh
4 c9 Q! c3 ?( n% ?7 P! G mov ax, es ; ES:DI -> VxD API entry point
/ d1 z( t7 r6 y& x5 `( N2 F add ax, di3 m/ h7 K/ L/ I0 `( L f) y
test ax,ax
, |2 f# P4 Y' N3 J jnz SoftICE_Detected, b. ~) F3 b6 a6 Z
7 l3 B7 j. s: p5 A
__________________________________________________________________________
& g% V: E8 d( n7 T* A7 ~
( W5 E Y6 c! y G- g9 ~
C" e7 F/ C$ X# t6 F( i/ nMethod 05
( a4 N: W( }( o+ J$ \! u=========1 L- k' M! {$ E
U) @5 t( X* a' PMethod seeking the 'magic number' 0F386h returned (in ax) by all system
# |% ]" q5 H! W% }3 j8 Mdebugger. It calls the int 41h, function 4Fh.
6 p/ \1 L8 o( l6 L3 _There are several alternatives. 7 D& N% ~: b L0 R: c! F
' @. W5 t) P' D- p3 `
The following one is the simplest:9 i! L7 V d: J* \6 l' c0 O) C1 J) V
T* Z/ b9 y0 d+ X mov ax,4fh3 C4 E$ h) y A! W S5 S
int 41h
1 F* Q5 [! Z/ Y2 _$ ]3 @" r) {8 c cmp ax, 0F386, m+ |0 V1 C7 t1 A' o
jz SoftICE_detected
5 U( N, b" a' ?3 k1 |7 W9 M0 `( s$ c. E5 m2 x. U# {) w7 V! W
0 O. a+ V' F6 S, p+ @& B1 h0 ^
Next method as well as the following one are 2 examples from Stone's
8 y: @+ M3 H7 v% j: y" `/ W"stn-wid.zip" (www.cracking.net):
2 q& Z& n3 L' u% C5 C1 c, \- Z9 \/ s6 z5 q9 h# x
mov bx, cs1 n5 W) O$ l' W) K- K5 g0 x) v/ Y5 S
lea dx, int41handler2
' o- Q. w3 l2 b xchg dx, es:[41h*4]
: h, I2 d6 U+ U% E1 {: q xchg bx, es:[41h*4+2]* h, r% {+ ^& w$ L* j2 g1 \; M
mov ax,4fh
5 U* r8 @$ d- `4 P# w" l, [ int 41h
1 H4 e8 j) y+ H; x7 t xchg dx, es:[41h*4]
8 e( Y( C" h- x/ }# Y xchg bx, es:[41h*4+2]
# D& U9 X! t" d, a9 t+ e cmp ax, 0f386h
; v6 [1 O3 d# M+ A; Z" s: O jz SoftICE_detected4 p; r4 o5 n" v% t+ x+ s
9 Z, N3 Z. y2 l& m% p
int41handler2 PROC
& n. X7 L& H( O1 o; n' g& e iret6 B3 u6 b" z, f2 S3 [
int41handler2 ENDP! \8 U0 f' g/ u, L# X+ U* X
& x! {8 _- f2 ^3 ?
/ V S& q B4 O; |9 V( c: e6 r
_________________________________________________________________________$ A& N6 m8 H- g, X; U& y: F
' A6 e# }+ J. V4 _8 f+ Z% R9 B) r+ ] V* q$ w* I! _$ A3 B
Method 064 B& _& k% R, o# c3 t! ?" m
=========
, G1 e8 E+ {( m" s( z* X
?1 t+ H7 x. c$ D# x3 a8 K* t% {% ~1 ~- T
2nd method similar to the preceding one but more difficult to detect:4 I; G. ]" f5 I3 {# ?: F
* Z: I" o1 ?" ^4 |$ F
7 B* P: c+ c5 ?1 B2 l# rint41handler PROC
D1 i: t! Q! m6 D! i }; H mov cl,al
: o: u% O( E6 q0 {' V# ]8 D iret
' ^# D3 E2 w- m% ^int41handler ENDP
* h7 U& D! M: ^9 ^* M* t- {2 F! j% s8 `( `/ K3 L1 [7 C ]
# @/ h1 g8 W8 q0 k8 _6 c5 L1 X xor ax,ax
0 s8 e+ {, a) ]; q( J mov es,ax( g) ^& D! a' q7 E( r- j+ ?' \! B
mov bx, cs
6 j3 N# N: f4 @: W) D lea dx, int41handler" E' a; k" r+ q! Z- Z
xchg dx, es:[41h*4]" O4 B$ c9 e0 u
xchg bx, es:[41h*4+2]3 e" X5 [+ Q7 y7 Z, M
in al, 40h0 M0 z( X' e2 j7 v7 A9 O( X$ t9 ?2 `
xor cx,cx
) u4 r. n& i2 T; O7 |. d7 p" z) l int 41h; C6 s0 e: O% T
xchg dx, es:[41h*4]6 H" w8 U& H& h" D7 W7 f3 C8 X/ ]8 r
xchg bx, es:[41h*4+2]1 A& x, P \8 Y8 m! m8 X
cmp cl,al
' f! ]1 c1 X1 b5 n L' B jnz SoftICE_detected# ~, Z* E7 k6 r o- ?+ |* N, ?
2 H6 B0 t1 w3 V( J_________________________________________________________________________- r% B0 c& x4 N7 \3 k2 m
V/ j/ _+ O! h% `, n0 D1 a7 m) d
Method 07: b* S `2 ?) J( \
=========
! y! t" M! e: l0 V: M6 k7 m- F( |4 }1 t+ o! q, Q
Method of detection of the WinICE handler in the int68h (V86); r& }' d! o$ E7 {7 c
- |* B# @+ o. s, a3 ^ mov ah,43h
9 P2 K! X& }; F3 J1 N int 68h. s* H; k3 r& q% y/ l# `' T
cmp ax,0F386h
: Q6 g2 j9 S2 c" k8 ~* D jz SoftICE_Detected: }/ K# l0 \$ o4 m- [
: A" R1 P( g; ?; j6 F! s$ H n
) o8 n5 |4 k9 N1 x- t1 U3 {=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
. n) d* b0 Z" s" v; h# k9 \; H' m, z app like this:) J& E& Q" F: G8 b( L
6 {, w8 D4 S+ |( ~1 n+ `
BPX exec_int if ax==68
, l" v, L U0 G5 P8 G$ S9 o; l (function called is located at byte ptr [ebp+1Dh] and client eip is# W* X9 b7 E9 T) }, Z' L7 A
located at [ebp+48h] for 32Bit apps)
( B# Y: u5 W& ?0 \0 ]+ ?' }! q__________________________________________________________________________
( X+ h x9 o- \4 D3 L" N9 S6 h* L0 Z' E. n( C8 V+ t# _5 a1 g
- P# V: Z- A6 J4 |8 ~8 H$ P) MMethod 08# ~, O* V R: L& T, e v
=========
6 @2 a8 {' y7 h/ S. W7 j; a5 X( w5 s" R& P1 w
It is not a method of detection of SoftICE but a possibility to crash the
$ u3 k9 p! q. ^) l& ?8 G- K5 M6 esystem by intercepting int 01h and int 03h and redirecting them to another$ ~0 L) X( D( N8 L* H- q" b
routine.: J4 F4 n. \& ^+ N9 o
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
: l2 \1 t5 m; @ R. j9 m1 zto the new routine to execute (hangs computer...)) ]- w" {2 E3 p! l* T/ c( h1 P
1 t+ R! b! H) D8 B. S; B mov ah, 25h4 n: I$ V9 T$ B% s) L& ?
mov al, Int_Number (01h or 03h)- t4 M9 k% b7 m4 x
mov dx, offset New_Int_Routine
% z- T' `* P2 P" C1 d int 21h
0 s/ A! n1 I7 q& y
/ b- K8 D7 e0 w+ K" h7 W__________________________________________________________________________, i( U: B) X; r- e* i+ f- ?
5 I+ S2 k& V! [4 N- v8 H4 n
Method 09
- U4 N) f4 J1 \6 ^5 _) a) [=========$ x5 G$ N3 u! L: j
* ^1 C% V* |9 D% t6 K L& h) r
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
- I1 g& W4 p8 R" N/ Tperformed in ring0 (VxD or a ring3 app using the VxdCall).5 E+ T# W0 |* R* }; U8 }
The Get_DDB service is used to determine whether or not a VxD is installed6 P' p4 O0 a: d& d0 l$ ~
for the specified device and returns a Device Description Block (in ecx) for
; d# m! u8 z7 \% W" P# D6 nthat device if it is installed., I" M$ Y/ g. `
9 k; M, i8 c4 ~" Z5 ]' V mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID. B) F- y% H1 e4 {# G' J: d) l
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)# C5 F( @9 `5 ~- m$ g" V
VMMCall Get_DDB0 r& F7 k4 n0 S' P" H
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
- N) ?5 b, b; [; S) M. r! D4 s& I5 l3 ~% x8 r
Note as well that you can easily detect this method with SoftICE:8 V5 s h J# I/ H, D
bpx Get_DDB if ax==0202 || ax==7a5fh
/ {( `0 X$ K* H: ?
) O5 ]! ^4 s& d6 V& W% A+ V__________________________________________________________________________. p+ \. K. J8 c
3 k+ V, s/ U$ P6 U0 C. H+ h6 MMethod 10
, |9 y7 ]5 r, n2 L; i R: D2 ?=========
0 T" Z" r- P3 {, o; ^; ~+ d
+ F8 H; o) M) |: I, c. Y=>Disable or clear breakpoints before using this feature. DO NOT trace with# k8 ] b" j+ t5 @6 e3 C6 J5 U% h
SoftICE while the option is enable!!1 R! d* a. z- l* f3 q3 [+ @
; @+ K% s; D- u. S, a+ IThis trick is very efficient:# T" N. i: d X2 C1 p
by checking the Debug Registers, you can detect if SoftICE is loaded
# y: Z; _. r6 m! G, F(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
& u) `/ ] c6 B4 X- wthere are some memory breakpoints set (dr0 to dr3) simply by reading their& j* O+ D7 D* o$ X( e3 X% o) Y
value (in ring0 only). Values can be manipulated and or changed as well
3 Z: B3 b/ u. x( `/ M4 R(clearing BPMs for instance)
3 Y$ Y- L: P% Q% q5 i, _/ u: I* V" v9 V: k3 J) {( X+ f
__________________________________________________________________________2 H7 p2 _* h O% |1 X
$ T2 [+ K1 Y% i4 h! R$ N0 BMethod 11
3 S. Z: O( b) z: [. ?; K Z e=========
# c6 Y/ m, P# L6 C* r" k+ ^+ K2 R6 W9 ~% }4 y+ M: @4 U- b2 u" H' f
This method is most known as 'MeltICE' because it has been freely distributed
- x1 s% k) B( {% n/ U3 P- z, i8 bvia www.winfiles.com. However it was first used by NuMega people to allow' j: `9 C" Y+ @% r7 ?+ n6 G" h
Symbol Loader to check if SoftICE was active or not (the code is located
+ P' l( `& U7 _, l$ binside nmtrans.dll).
7 ~5 T( I* N0 L" H( O y: q2 Z; b/ ^2 p6 k/ g6 b# D: a, e3 g
The way it works is very simple:
$ Y* J$ I: G# g$ \0 j3 C- bIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for7 m' R0 R4 d& Q! \( y" j
WinNT) with the CreateFileA API.
2 ~1 @) B+ _4 o1 D' e, X
+ e4 ~/ `6 P* ]7 J3 PHere is a sample (checking for 'SICE'):
# k* k9 T# v/ o% k1 G K* e2 E/ b1 ^. y: I: ]" {( a
BOOL IsSoftIce95Loaded()
X, V9 i, ^. D' P" w{
9 c! i( ]; O; f' v6 g HANDLE hFile;
5 i c5 W5 I6 Y6 i Q hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
( w7 L& Z# U- X4 |1 Y8 X FILE_SHARE_READ | FILE_SHARE_WRITE,/ A7 u0 q* e( S0 D; J! G2 g' F* a
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);) L" C# K# o3 p+ `( C1 x) l
if( hFile != INVALID_HANDLE_VALUE )1 K) t- ]4 d4 C# x0 J
{& X# n L4 u7 ?3 b1 w
CloseHandle(hFile);
% N/ M7 y% d! S r3 g6 T return TRUE;2 J0 ^: B( W2 Q
}2 v0 c: k# @# ]" O' N
return FALSE;
: S4 c0 Q% R& x. o+ u& n: w, Q/ a- I}
8 w' y7 d2 y) n6 j7 I) z- [7 E- A( s1 r2 z5 a+ i+ k
Although this trick calls the CreateFileA function, don't even expect to be/ E( n2 `& r$ ^6 z# m
able to intercept it by installing a IFS hook: it will not work, no way!
# i8 a! L! V7 ?In fact, after the call to CreateFileA it will get through VWIN32 0x001F6 J0 b6 d$ j F+ v% }& z
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)* k! v+ ?. Y- U; y# [: k2 n
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
; F4 V; Q, N8 W2 Wfield.7 q( z. P/ k7 d2 o3 u
In fact, its purpose is not to load/unload VxDs but only to send a
9 n. m$ t1 X* t. kW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)& ^) F& u$ u8 L+ r! q
to the VxD Control_Dispatch proc (how the hell a shareware soft could try8 w: i5 a1 P4 v) e4 ^8 o
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
+ h& F T% \3 P+ L8 DIf the VxD is loaded, it will always clear eax and the Carry flag to allow/ ^8 f1 D1 o# J! X# K
its handle to be opened and then, will be detected.
7 w0 R0 p' v3 s$ U$ |+ d W0 lYou can check that simply by hooking Winice.exe control proc entry point2 W# r) X9 l# t
while running MeltICE.; M, i6 ]! A: O- W. \& w7 F% w
; k6 W7 e: ?) i& _
. t# |# c; O* s/ x 00401067: push 00402025 ; \\.\SICE& h$ M, e' @4 S/ [) t9 _
0040106C: call CreateFileA
4 n5 P5 {. I9 R 00401071: cmp eax,-0012 \4 Y4 `! N' D, p8 d' K
00401074: je 00401091% {: q, j1 S7 S! @2 d0 f
$ N5 t x% v) v9 ], L2 V8 w- U6 G/ C$ |
: v$ B8 y1 Q- WThere could be hundreds of BPX you could use to detect this trick.4 C: G0 M3 i2 r: `
-The most classical one is:3 o w1 \# J5 A4 O9 [) q& F* X1 y0 @' ]
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
! f, S8 A- j: q* d' s *(esp->4+4)=='NTIC'5 y6 O, `- c. a8 B4 _6 J
: k$ f# W8 R/ o9 F% T- ?9 F
-The most exotic ones (could be very slooooow :-(* \- C! s+ K" a5 ]
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
" p( D) b$ U2 J5 K P ;will break 3 times :-(
3 v( p& u/ r: U6 v- |8 D1 f( c0 j5 `- I |% |' O. ~
-or (a bit) faster:
. W! v) z4 _5 r" E k: n BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
9 g; K- j$ V- [; Q8 [! s Y7 A" t, ~7 D* s. Z: L
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
$ {9 ~) k3 U1 b$ N& C ;will break 3 times :-(+ C$ [: J) B, Z
6 ]) f0 D d( Y$ V, Q' z
-Much faster:6 j8 Q! B! \& s/ l* N
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
" m; a0 H6 e! B; c2 \: T+ G0 }- V3 P) _) I
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
/ `+ D/ k& M7 m5 s9 B1 T$ C$ Ifunction to do the same job:
N5 z- d+ }4 H; Q. @" s" t4 o* C L
push 00 ; OF_READ
7 S% Q1 y: S; |" h- M mov eax,[00656634] ; '\\.\SICE',0
. N% r$ n' ]& a5 m1 \/ s push eax4 |8 C; }- Q5 y
call KERNEL32!_lopen
! U. Z4 z, B/ b! { inc eax
% ]3 N. M: K) [ jnz 00650589 ; detected
" z j4 C! O3 d% J$ [9 H push 00 ; OF_READ! g: O0 N$ i( k% n3 L
mov eax,[00656638] ; '\\.\SICE'8 _% h+ Y2 S: v
push eax
/ b( n- D' b9 Z/ S6 z* ~7 W call KERNEL32!_lopen
; ?7 G( U1 g+ [2 ~ inc eax5 q1 T, ~8 G- E& Y: s3 \7 r6 m! w
jz 006505ae ; not detected5 y; J1 i( h) r; @: u) F9 C# W9 A! M- y- x
$ |: v0 b# u! W
+ @# a6 e( V$ F
__________________________________________________________________________" E- g' j- d0 P
2 N! y: u3 V) z" P. U" |Method 12
6 j' t8 `% o' u$ _! A=========& I S0 D: M2 Q M5 e
8 k1 R" X+ K5 L$ p+ |6 _
This trick is similar to int41h/4fh Debugger installation check (code 055 D% Y# F7 K, e4 b
& 06) but very limited because it's only available for Win95/98 (not NT)
8 i: n9 Q. S4 g; o' zas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
4 l3 K2 q# i: v5 D" t' s6 y, t: q# I
& u: g: j) A$ E6 i/ k/ h* w+ c push 0000004fh ; function 4fh, [7 V. o9 ^( G7 Y- B
push 002a002ah ; high word specifies which VxD (VWIN32)2 m/ }5 r, f7 K# l8 z
; low word specifies which service" z$ K# k- w9 ]9 ?2 c# C
(VWIN32_Int41Dispatch)4 W2 [- }/ S" `
call Kernel32!ORD_001 ; VxdCall
9 K! K5 ?: T5 f1 W) [. { cmp ax, 0f386h ; magic number returned by system debuggers5 b1 [( M9 U; _. U7 j4 U. ^4 n
jz SoftICE_detected6 L+ r1 K. U0 B8 \7 k
5 m5 N& K1 ]( t) D8 F e
Here again, several ways to detect it:
. ]3 M4 c0 w) ?/ E7 P+ H
5 a7 Z' n `3 f, ]4 J& G2 J BPINT 41 if ax==4f0 ?$ l6 T' t5 D* o, C
' l' y% i) D4 d
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
/ R+ _. C% I, T- q) e, \
0 f$ W$ ]5 N; a( E i0 ^ BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
6 b' h( w6 O: k$ U$ l }
# }6 p+ i4 m v0 ]# O3 T) [ BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!% k* z; P' ~/ e
- p- _# ~9 C$ b: F+ O
__________________________________________________________________________$ R' q& X* E8 X' h9 |, |0 g& ^
* p% R: K) y3 w/ _Method 13
3 n5 g- l5 `/ D$ g1 j# t' C! N=========7 f) t; d9 t6 z
1 }, C* h9 E3 `- y
Not a real method of detection, but a good way to know if SoftICE is/ L3 z' Z" {/ H! t; S7 p+ I9 G
installed on a computer and to locate its installation directory.
# K' D9 [7 A# o2 [1 g8 u, t" t( sIt is used by few softs which access the following registry keys (usually #2) :
' d6 K& c: N6 m+ V( y
& m, d: w. ~, R-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
Z! M' j, B# p% H& \\Uninstall\SoftICE
5 S+ N2 U1 f) E-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
" g7 z' _1 [; k6 n-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion# k D' b y" Z' c
\App Paths\Loader32.Exe
- c, D- K% X0 u0 w+ F* S E% f' Q k
+ o8 D3 H" K5 P% v* Y" }2 \6 B, x8 l& `" V& y, o# ^
Note that some nasty apps could then erase all files from SoftICE directory
) u- h3 e8 ~2 r+ S& [(I faced that once :-(; x. A4 K g6 T. _+ `
+ W# ]$ D& ^- S' v- }. q5 JUseful breakpoint to detect it:
' j& f1 W$ A* H2 n& a" @7 ^3 ^, k( u# n. h2 Q7 l# O
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
& U+ R# M* E8 ?4 D0 \
* l; d K' F' Y4 c__________________________________________________________________________
3 P+ M* P; E+ c7 t6 k* Q" j$ i1 {! J; Y5 f
, V7 e$ c# }, E- W# ]Method 14
3 a% m" n' `1 n6 S) S8 ~% C=========
' C/ s7 c9 D- P* J% h9 G5 M% G+ [
m6 y3 j9 \$ T8 @% \* PA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose1 j5 y. e. |% N' |9 E5 u
is to determines whether a debugger is running on your system (ring0 only).2 H5 o" B1 A/ R" a& P. m7 ?4 j
8 I. \$ ?# N7 j9 x
VMMCall Test_Debug_Installed
1 U! W P: e& ^7 m6 r) R je not_installed9 q) H% e z% h6 S+ a
# U$ h1 g, b4 f6 k( R" o
This service just checks a flag.( n `/ D1 Z$ H, k- O8 I% Y7 K
</PRE></TD></TR></TBODY></TABLE> |