<TABLE width=500>1 ?5 }6 w" f. n8 I
<TBODY>
" f2 {7 @+ ]4 f3 Q* c' j<TR>% U& A. x0 q+ _4 F4 _3 k' t, d
<TD><PRE>Method 01
9 W+ r$ f- @ D/ n' k* p" L/ W7 |=========/ j Z5 B T j& i$ A: W% ?& c
' Q4 B9 q' f9 oThis method of detection of SoftICE (as well as the following one) is
9 R" a9 W, J. e/ pused by the majority of packers/encryptors found on Internet.3 [0 O7 }/ W) T. l+ L. X- V
It seeks the signature of BoundsChecker in SoftICE
) N* e/ X: M6 L# B5 b# n, O% N: a$ W. t6 f/ A5 l9 ^0 ^6 A
mov ebp, 04243484Bh ; 'BCHK'8 j0 M8 l" |; ?5 c8 }- u
mov ax, 04h- D8 e- P5 o1 Q0 V) R
int 3
1 u2 `+ @' d$ q6 F% o cmp al,4
2 ]2 W0 x) i+ i3 L jnz SoftICE_Detected
' `7 B, a6 }" `% G8 J7 |, g2 A. W- G4 I5 Q9 H4 Y o
___________________________________________________________________________+ Y# ]. C4 u* Y
/ o& d% }# z* O& U; }Method 026 c" o& Y6 P5 Z% n3 v f
=========
+ F: I( a1 W# e; W g0 Z- t. y
7 `8 B& j2 |3 Y. d3 F* W1 L0 [9 cStill a method very much used (perhaps the most frequent one). It is used+ Z& t7 k2 v1 g
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
* |' b) Y, ~1 ~or execute SoftICE commands...* y$ E$ u( n- n2 v9 |2 u
It is also used to crash SoftICE and to force it to execute any commands
/ V: G( @: |! e: |(HBOOT...) :-((
- k( d2 Z7 B& ?' r( g4 ^
* ]; F% Z/ n7 w6 ?' D! O% t/ GHere is a quick description:
* _3 ]; m0 y$ W-AX = 0910h (Display string in SIce windows)
2 D. L# \5 ?! m3 H J-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
+ W2 V' c/ N3 @" N2 @. ~8 a-AX = 0912h (Get breakpoint infos)- A/ t, k1 J; q
-AX = 0913h (Set Sice breakpoints)% s5 A3 z) n6 P* X$ B
-AX = 0914h (Remove SIce breakoints)- C5 |9 s) I6 e% k, \. o @
0 D! v/ g1 R2 p6 U- \Each time you'll meet this trick, you'll see:; g& I( V3 r0 B1 A4 ?4 K, o
-SI = 4647h
$ ^+ x- R( j7 h1 N-DI = 4A4Dh: s# C7 @" q- e, r% m
Which are the 'magic values' used by SoftIce.
1 v" d" `* ?7 R1 q5 m( ?( tFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
3 q+ K) p/ p* ]$ D3 `7 i4 a& b/ w$ s6 U2 \& A
Here is one example from the file "Haspinst.exe" which is the dongle HASP& Y0 e& H d0 `% L% [! Y% Y
Envelope utility use to protect DOS applications:
* E, p: A5 `9 W2 Q+ y' g8 ^: J. l6 J0 p8 v' M* O
+ r& k: L h, y3 V3 k8 n% i) J* v
4C19:0095 MOV AX,0911 ; execute command.6 M" X" H4 V* Z$ [7 e
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).! [6 @% E) Y% v5 o% Z6 Q9 m
4C19:009A MOV SI,4647 ; 1st magic value.
& D1 ^) H+ _* u4C19:009D MOV DI,4A4D ; 2nd magic value.
5 f' W& r6 p7 S7 g$ E/ Y* P- e; E2 i) H4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
Y) T6 ~9 D8 J0 O: o/ Z4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute6 W$ t; x0 Z* [
4C19:00A4 INC CX
7 ~* U7 ^3 `' F8 e4 `) s# Z4C19:00A5 CMP CX,06 ; Repeat 6 times to execute1 E* z" a) ]. Y
4C19:00A8 JB 0095 ; 6 different commands.* r* e5 {3 L# N$ ` ]
4C19:00AA JMP 0002 ; Bad_Guy jmp back.2 c1 |4 I: d% _! K+ u+ D; O0 f
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
. B( X! h* ^9 B$ g9 M/ Y m/ J9 {* I% r
The program will execute 6 different SIce commands located at ds:dx, which" n6 B$ T) H' m X8 Q; w, r4 _
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
" d0 A. E: b0 m# a1 y
" ^7 c& I" w; Z ?* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded., M( [ ~( }( c/ H# k0 p
___________________________________________________________________________$ I: \+ P. v7 P0 }- Q
* p2 ]2 h! k t8 v$ g, `3 ^" @+ m8 y( O( Y, R4 I- g
Method 03
3 z, _/ g* z1 {2 w=========7 K2 h2 j! r# Q
4 R" W: \9 T% @) Z# c- @# O! ^ rLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h8 O8 `. ?& u; U; S/ Y1 s# E6 k
(API Get entry point)
5 b: W) P% n' n7 L
Z1 f: D/ D4 l+ B, y- j$ }- `: G+ v9 _) T
xor di,di
1 ]( w( ]6 {- Z( l+ y/ S mov es,di( X% N f! }, ^/ w2 s1 C
mov ax, 1684h
5 b) w) X' _: W- q) L1 r1 O) c& H mov bx, 0202h ; VxD ID of winice/ L( l6 d2 s2 {* o; C* s
int 2Fh- W" g: F$ ~- S& o; ~5 B: L% l! K
mov ax, es ; ES:DI -> VxD API entry point/ |: t% Z. i8 k9 p) o! {% y7 }
add ax, di" z1 c5 J: w7 U& v! r
test ax,ax3 y! M2 p) E: U. M- {2 t
jnz SoftICE_Detected( u- \3 \- X4 v
& |# Z0 ^8 H4 q2 ?3 C- O% a, c2 b___________________________________________________________________________- F/ \- y, k0 _: }$ r6 }1 q
. A1 ^* E6 B# t- ?; @' q
Method 04
2 @2 O$ e0 A9 i; X+ E=========
w! N# z% W- v4 D' L0 c, o2 I) @) O/ o" g
Method identical to the preceding one except that it seeks the ID of SoftICE0 r/ B2 g. |. ^; j6 W0 \- T
GFX VxD.9 m/ D' u% g5 K3 j5 s! _) o* {4 d
, Q/ v# B7 D4 x- Z
xor di,di
' r8 T8 A- B& n9 t: f5 p/ t mov es,di7 p! S& A" |$ @2 G
mov ax, 1684h 2 b: _3 o6 D1 |( q) n1 i
mov bx, 7a5Fh ; VxD ID of SIWVID
. d; v* k9 M* n: C- y int 2fh
/ M" M, e$ f B7 t& A, j mov ax, es ; ES:DI -> VxD API entry point R( y5 V) \6 ^5 Y6 f6 k s
add ax, di
# m d1 J, F$ F8 }! J7 q% o% Y test ax,ax8 B% S4 z5 o+ F/ i
jnz SoftICE_Detected
) W! C- _# I. y1 ]$ u- V, C" U) B0 J6 n6 b3 x1 u' P& {0 Y: k2 a
__________________________________________________________________________6 b, y4 r: w7 S+ T5 O0 A2 f' y
" ^% o+ w* P; w1 v' q5 Q& T* [+ E/ k5 h3 ?) X! g9 e8 R
Method 05
/ m1 N) J0 Y+ E! b4 i=========+ f& G7 [% q. |0 E0 Y6 d. {
+ D6 d- i# T) O3 }0 d1 e$ aMethod seeking the 'magic number' 0F386h returned (in ax) by all system
9 L* e0 ?6 G) U' D4 R! [7 Hdebugger. It calls the int 41h, function 4Fh.
3 ~& B+ J# i& ?) @ YThere are several alternatives. / H4 S4 i6 o0 s' L- o
& \6 \! X: K* ] E& x
The following one is the simplest:
' l0 `! V1 S, B& L% U# i% G
+ F8 J6 B' b8 w D- s8 }& j mov ax,4fh
, `$ S" e4 m4 `1 R8 i, x int 41h+ o, G8 X5 {; \
cmp ax, 0F386
8 i. G: W5 W, c6 k- U; W jz SoftICE_detected
) d, ]- H" v/ U& \( ~5 E% b/ P
6 P9 ]7 `, f9 R- r/ s ?6 b _' A9 a$ ?" a- J$ D8 V
Next method as well as the following one are 2 examples from Stone's 6 p2 Q1 l8 ^" B. |
"stn-wid.zip" (www.cracking.net):
) r5 \2 d( j' `3 D9 F$ g0 j" v4 r$ g9 x8 N) J6 Q9 Q
mov bx, cs9 a& N6 E K6 }
lea dx, int41handler2
) `5 Z8 j2 M- H2 v# E+ n( M% C7 [ xchg dx, es:[41h*4]
# p8 s" ?( k% O& Y- G/ P xchg bx, es:[41h*4+2]$ |/ F4 N0 U* Q6 w2 {) _; m6 W
mov ax,4fh
* ~* k, L5 t+ a2 r" m# _" y' y int 41h5 X! x- @& w: \6 d: t
xchg dx, es:[41h*4]
( G4 R/ q. b6 F! V! i3 ?- S0 \: i xchg bx, es:[41h*4+2]
' B- P; l d, H G cmp ax, 0f386h
~( ^+ v& [* \( \8 n e jz SoftICE_detected
/ b" i8 R- W# U' }" {) t
3 N# x1 J# `) Z* S# iint41handler2 PROC
7 v! O# k. f! _- J: k5 |* n4 ] iret
# k3 h1 n/ @+ w- H% H4 \- Rint41handler2 ENDP
* ]; s& `) K1 U7 D
, j( M- ]+ P; Z0 P. {* q, t! x8 G8 A A: `& a" x1 k
_________________________________________________________________________: c, [4 j0 D0 G8 i
1 ~9 B5 B, S: W8 S# q4 V4 S# v5 L2 ]$ p$ M
Method 060 M4 X- V6 X) M2 {4 [1 n# E
=========, t9 d p& u2 V1 t3 i
; _) C S7 T4 q4 c
, k& |! M& l3 v$ V, z2nd method similar to the preceding one but more difficult to detect:
|9 n1 F0 Y l( j
1 u W0 O9 D, q8 x" R b+ F) e( \& t" K0 S% D
int41handler PROC
/ s) C, x" d- Q& z mov cl,al
, ^! r D. k/ Y( ~ iret
) ]& I/ M% C2 V& j/ Z8 v& {0 @0 aint41handler ENDP8 |9 H; h% M4 I/ r
# |/ j$ {0 c: q4 Q
" [6 h& W3 _$ W* s) K8 b' T
xor ax,ax
9 R/ L3 u3 D" a \ mov es,ax
, x2 J% S, w3 ^0 h0 j- R: o mov bx, cs" w. E* L* j$ C5 e
lea dx, int41handler: c* P+ e3 O8 a, Z: _( r4 b
xchg dx, es:[41h*4]# `4 t9 u" O' k1 k
xchg bx, es:[41h*4+2]
7 U; G$ W: n3 p8 k- c in al, 40h8 }: W0 u+ m! }( W% _
xor cx,cx1 O8 P- I" N" S2 O4 U; I5 F8 T
int 41h
0 r: I0 Q/ Q, S# e xchg dx, es:[41h*4]
% s$ \; |# o; W: n) p5 \" J xchg bx, es:[41h*4+2]2 B/ J7 y) \& x: U7 M5 B( l0 r! y& _
cmp cl,al- h* U w8 w5 [
jnz SoftICE_detected- B1 z% W3 }5 V) N
g! \" h. ~$ h% ]- s1 z+ q3 ]_________________________________________________________________________
0 ^5 h# `7 z6 z' ]( a Y* P$ ?6 H, l/ i/ I* _* u, l- l% x# n& T3 A
Method 07
' `; i( G! Q* A! H=========9 l* Q8 {) W ]! P" g W3 Z3 x# l
- f/ x6 z: g! t7 I
Method of detection of the WinICE handler in the int68h (V86)5 I6 r7 A7 e; N0 z- e$ t
7 h$ y1 ^3 Y8 u3 @) v8 Z4 Q5 C* f mov ah,43h
; Q. ~- {' ? ?2 E ] p1 K# K) I int 68h" i$ Y2 H, \; [, A, J/ }
cmp ax,0F386h
8 p1 v8 B% _1 B: ]7 u2 {+ a& u+ D jz SoftICE_Detected
8 m* N: b/ x( j4 q
% r' ?9 X5 `1 g! g2 H
9 X) O. b1 V9 A5 B' y1 }6 W8 T n=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit* A) w1 |# |9 ]7 V1 a, M: ]
app like this:
1 o) a% X; w) V- h- G, a; `1 Z7 b: A5 f# P$ A
BPX exec_int if ax==68
4 C: W' Y8 z" r (function called is located at byte ptr [ebp+1Dh] and client eip is
% w2 W" [% N: I' K9 N: X: a located at [ebp+48h] for 32Bit apps)
3 r5 F# y# n+ Q1 G$ u$ S" N( t8 u7 e! I__________________________________________________________________________
2 O; c" x! h/ N
/ [2 I0 l! ~3 ?7 I# F. m; G
. o, K% }/ \$ H @Method 08 P2 B# k4 ^2 h( m( h& B: e. ~
=========% \- C& u: P/ n0 q B0 x
5 `; F$ r' {) N) C4 }It is not a method of detection of SoftICE but a possibility to crash the( }% _, {, y5 M4 ?: E. ?
system by intercepting int 01h and int 03h and redirecting them to another7 l9 q: A% _1 v& W! Y5 \
routine.6 k, e; t8 R4 B8 f' }$ }
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
" |2 g5 A" p, {7 M0 fto the new routine to execute (hangs computer...)' Y! |# l' n( b
* v! _ F9 k. n mov ah, 25h
7 C% P. e4 R/ m( H mov al, Int_Number (01h or 03h) c6 D: N* a, F: L2 ~' T Z/ L) |) I( [' e
mov dx, offset New_Int_Routine
! e% g4 d/ P& ^ p t! Z* w int 21h- [9 `, I. }) U
& }: \3 @( P) `' y: V3 i: c__________________________________________________________________________, \- f: y9 F9 H# i5 j/ m
8 Z6 c& N8 v' `; _
Method 09
( \' v' ]& `0 a4 \! T- L4 M4 G0 U=========5 [$ x1 q m* j- }% e4 e+ m% a
0 P% }# f$ o3 aThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
8 `% n% m% o9 Kperformed in ring0 (VxD or a ring3 app using the VxdCall).+ u& a0 N; g+ ?& F4 d) t3 R
The Get_DDB service is used to determine whether or not a VxD is installed6 a+ r. W8 z7 m! e2 Q
for the specified device and returns a Device Description Block (in ecx) for. N( Q0 k( @( F/ |% E3 V1 u& V. l
that device if it is installed.5 \0 ^, d1 l& P+ y
4 M4 G( M* Q, v0 r6 D+ K
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID5 ? @) B2 @% D, v( k r# a' s
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
. Y* M, o" o* Z! o* r7 t* X5 | VMMCall Get_DDB
, x; _2 n6 l7 k8 T9 g8 c mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
$ H, p8 C7 Y, H
+ r$ I' ?5 ? L/ E `+ N2 }Note as well that you can easily detect this method with SoftICE:! t# X _# t) q5 y# O! s, C' ]
bpx Get_DDB if ax==0202 || ax==7a5fh4 k+ u; w# f6 y1 h, ? T1 [# k" p" r
: {% S" \) O: p# Q__________________________________________________________________________
: k* o3 j) O; m) F/ y. ^
% |# F7 G. Y: t0 Y5 q5 |Method 10
6 `6 l- l. b7 C& U3 X; F; B3 L=========9 e5 }* ?2 B) T! {* E0 B+ Z, _
7 C6 [( i; E1 V* F5 ~ U
=>Disable or clear breakpoints before using this feature. DO NOT trace with
/ q4 @% `2 @2 w' O SoftICE while the option is enable!!
- t; }6 N8 |1 X/ ^6 L6 o' \2 J N. v4 P" I3 ?
This trick is very efficient:" ~! p) b$ F, b
by checking the Debug Registers, you can detect if SoftICE is loaded
3 b w: D- E+ Q1 t$ R. I(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
: ?+ k/ f0 H' Othere are some memory breakpoints set (dr0 to dr3) simply by reading their s* o3 f0 X; x3 S* a0 \
value (in ring0 only). Values can be manipulated and or changed as well
8 `5 a+ ^% b, l7 v ~3 ~) C(clearing BPMs for instance), T& Y' w/ z4 l4 _) r9 U
6 b% _% i5 {* q5 v) g/ o+ O% K
__________________________________________________________________________
6 ^4 a( m0 ]1 i5 Y
9 I: K/ s0 Q6 X. @Method 11# c0 e9 A& N1 m% e o
=========
. s8 p3 b# U0 |; m0 n# Z
: g5 j; W8 b. [. j+ n8 B' v/ {" RThis method is most known as 'MeltICE' because it has been freely distributed; n ]6 Q" d* v5 _1 D
via www.winfiles.com. However it was first used by NuMega people to allow
/ x+ j2 W; F6 t# R5 t5 `$ sSymbol Loader to check if SoftICE was active or not (the code is located% ?. U5 Q- k$ F: b
inside nmtrans.dll).
( [9 y7 V9 f1 A4 w/ e" n
3 Z9 r" ^: O& q! O- g% G7 p1 X/ ]5 bThe way it works is very simple:
) M0 U. K' w% }5 C; BIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
) z3 D6 w$ L8 G7 P+ k& VWinNT) with the CreateFileA API.
& q' q8 G, Y6 A1 F5 j
; b( s8 v. D: L7 Q5 F. hHere is a sample (checking for 'SICE'):* \: c0 Q+ F8 L* A' T! G
9 }& }! {8 q; }3 H2 \BOOL IsSoftIce95Loaded()
# [) n+ D, S9 ?- s4 P{
: ]0 n+ k) h: N: s: _ HANDLE hFile; 7 y. y1 |: ^/ R/ U" z
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
9 c7 n* P% z6 B7 D! L) w FILE_SHARE_READ | FILE_SHARE_WRITE,' k9 |5 }* V4 \9 K
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);$ V$ K; c: ^8 R/ @! z3 Z s
if( hFile != INVALID_HANDLE_VALUE )
6 J/ o0 ~6 |9 f7 q9 v {5 o5 \, D/ V9 S7 T% s) q5 l
CloseHandle(hFile);# v" h- L' V$ z) Z* g! ^
return TRUE;. @$ x" f# z+ f9 k# `1 |
}# k t% U) a7 R' G. ~% r2 d
return FALSE;
9 @/ L% |2 ]7 d! A8 m6 f}
/ Q4 r8 _- v9 h+ z" @7 A
( c0 E& U! J( ^! y4 AAlthough this trick calls the CreateFileA function, don't even expect to be
1 T# \$ w" v% ]; y, f+ d+ Wable to intercept it by installing a IFS hook: it will not work, no way!
1 _! j( M" R2 K9 ^' m7 `In fact, after the call to CreateFileA it will get through VWIN32 0x001F% r# U5 x0 g) k; T- i
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)4 a% q* l/ m. n5 S7 m# i- L
and then browse the DDB list until it find the VxD and its DDB_Control_Proc$ ^. t& L) n7 |' H- A/ @2 m- X
field.
* X! k+ p5 t+ B! N' kIn fact, its purpose is not to load/unload VxDs but only to send a # D9 e2 {( j% l: n( ?
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
( T, `7 w% g5 D3 ?: ?1 ]to the VxD Control_Dispatch proc (how the hell a shareware soft could try
5 |% [ n* d0 J" ~to load/unload a non-dynamically loadable driver such as SoftICE ;-).! ]( M% b7 ]' ?$ e) @
If the VxD is loaded, it will always clear eax and the Carry flag to allow
' F/ f+ ?% }! H8 ~, rits handle to be opened and then, will be detected.
2 D+ A1 `1 _/ g" K1 }0 |5 LYou can check that simply by hooking Winice.exe control proc entry point& q- a& z4 \. B' Z' v: v3 q' b
while running MeltICE.
4 w+ v/ U+ U( y7 b; S* `" U5 g' ?# x- n, a. c y# G# n
3 l. Z9 x. R& T0 B; f; v: q. u 00401067: push 00402025 ; \\.\SICE
. S1 \9 C6 Z4 n7 y8 W 0040106C: call CreateFileA0 p( M0 K* i1 l& a+ z" P
00401071: cmp eax,-001* K1 E+ f+ k* `" h
00401074: je 00401091
4 ^" E* ?+ L7 ], }4 |: \# j- e9 X# c- i( \7 o& z- u h
. F4 E$ Q+ [) U1 GThere could be hundreds of BPX you could use to detect this trick." c' ^# o D& [
-The most classical one is:
! y: d7 }" W# E; V# c- v BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||2 M# v- e1 s; n8 p
*(esp->4+4)=='NTIC'
3 k% m- A" T4 y. O' E) L
3 a7 M: m: F" ` e' ]9 K% t8 y-The most exotic ones (could be very slooooow :-(1 [' q. b: \0 o, L4 v% C
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
* _9 s" ~7 X& N, ?. v; ^ ;will break 3 times :-(/ {8 h; w/ ]3 z( e p! y M
* j9 v# X3 V3 O& j3 c7 y, V-or (a bit) faster:
* Y! l2 r6 H" M3 z$ t6 o% g BPINT 30 if (*edi=='SICE' || *edi=='SIWV')% W8 R- r6 N7 B7 C
( ]7 V/ T3 `1 v- E. b! Z
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 4 m* c5 W( \& k" O/ U4 E
;will break 3 times :-(
5 i2 K" p' A2 ~- L6 }1 @. ?5 A& ~/ J6 {, i% y. p) j& }8 A% `1 e- |
-Much faster:2 f# Q, v( w- H
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
9 u: R/ \) h _1 `! o: N: M, }5 Q4 P8 X* a# z& y# M% s
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
1 C: }* [: F- p3 S+ O0 ^function to do the same job:6 v3 r$ E+ C! s/ a
1 [: z5 I. ~, R; _6 F, ^. ?& X& h push 00 ; OF_READ
4 q# i1 o4 W$ u6 A2 z0 ]2 Q mov eax,[00656634] ; '\\.\SICE',0/ X, S) { _$ E8 M; r5 O: |+ @0 x; |# g
push eax
2 P" V+ d' N5 k* }, E2 ~$ j call KERNEL32!_lopen
$ |/ M% l! s' q; u) M5 X inc eax" C: M( |2 d; N- p
jnz 00650589 ; detected
- p3 e1 J. E: \& ]2 L+ a push 00 ; OF_READ5 \1 S* B' L, a" _) }9 ]
mov eax,[00656638] ; '\\.\SICE'
' x* r# o; I/ g% A* Q) U push eax- L( S6 }* J# [) F+ [8 @- ?
call KERNEL32!_lopen
* K7 H+ \3 Q( Q/ Z7 e" e inc eax- L9 B1 N: Q$ @/ F
jz 006505ae ; not detected
4 I7 o1 B" D5 h$ V7 |" d
; f; J- O4 L2 l6 e' ^* Q1 u0 h' `3 n8 n8 m- V
__________________________________________________________________________9 |0 L+ j& ?+ u: D9 Q2 N1 j
2 A; I. Q6 d9 A4 r0 M9 r. jMethod 12
' A& t! i w, z! g=========
V2 O+ g. p/ D+ @
) e g3 z6 @2 A" x& x$ \& XThis trick is similar to int41h/4fh Debugger installation check (code 05
a* ], d9 M! T% G1 y! ^/ s6 V& 06) but very limited because it's only available for Win95/98 (not NT)
2 P; M3 y& D) L$ Oas it uses the VxDCall backdoor. This detection was found in Bleem Demo.1 X* j; E% [5 T. l/ S6 x/ \6 Z3 a! _
7 @% h8 R/ I) L( l0 y4 v# ^
push 0000004fh ; function 4fh ~9 Y( U: j; g" ?) n6 W$ s4 T
push 002a002ah ; high word specifies which VxD (VWIN32)& w, l4 E$ Q5 u2 H3 s
; low word specifies which service+ u' k* V; ?- @
(VWIN32_Int41Dispatch)9 X+ l; k4 n2 w) a+ X! h4 D
call Kernel32!ORD_001 ; VxdCall q/ H4 H& }5 X$ F
cmp ax, 0f386h ; magic number returned by system debuggers
: ]! M. @- v# n jz SoftICE_detected2 X+ K8 J. {8 q2 z: t5 u
2 c: b6 U( _& F' V2 Y% OHere again, several ways to detect it:. T {. ^* A+ ?/ V- S7 b0 l# U8 J
$ n* o# m, T2 q5 n) ~' w) v
BPINT 41 if ax==4f
" j4 o6 F5 R* Z" [- H
4 H8 J9 U: p; x% D9 M BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
. Y) X3 t8 t, M
" Q1 N/ i- N7 {8 [& S) G BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
0 x, m2 t* p& F% r
6 a; I& k( Z$ E, @ R0 K8 |# G BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!/ x" |& M/ M3 A4 k
& V) D" b, M/ b3 A& a__________________________________________________________________________4 N( h* j l) B% h1 Q" Y
# S0 {1 i- M( g% G# C( ~ p
Method 13; o( J% z. x# l3 g
=========
# ^: Y9 W- J" }# H* a9 R5 t4 a: M" `) d8 z/ q& C# `
Not a real method of detection, but a good way to know if SoftICE is
" Z/ C! I1 f8 w# t" Tinstalled on a computer and to locate its installation directory.' s+ x; |$ p9 e: R7 B q
It is used by few softs which access the following registry keys (usually #2) :: L4 `5 R, ?. P* V# i# S' D
! \, D3 p* ]- R( _-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
, s+ a% `8 s ]7 R- X\Uninstall\SoftICE
1 n* l0 R. A9 B ]; n5 K1 ^-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
Z$ f6 G& f' q* {& @; @-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
2 D4 f" q8 z n, s' Y7 U) W\App Paths\Loader32.Exe
- I1 U6 q: K* x7 i3 R( k- [6 [$ }0 l0 R1 L6 D4 k8 z
% P( ?+ B* P! Y& K& fNote that some nasty apps could then erase all files from SoftICE directory( _0 |) `" J5 g# n0 W9 s
(I faced that once :-(
E, y1 t. b$ f9 u% T1 R2 ?
% `* ^; M) x, y: [& v6 UUseful breakpoint to detect it:
) P+ d% N$ l) X& R# B( z O- `: X# _ f( x' p
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
% ?: r% D, Z+ L- L. P+ O
" ?7 _7 g2 q/ ?# { I3 A, b__________________________________________________________________________8 I$ |/ X! C/ I% q* [; @8 i
" w2 \6 k0 V, k, M7 W
" |0 [! A& r, Q( XMethod 14
) B7 q5 R w; A; [=========: R1 o* W9 W% V( g! m
0 u8 h0 n5 c8 B: w$ T1 r. t2 RA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose3 N1 D, r& l& M S
is to determines whether a debugger is running on your system (ring0 only).
' F- V5 |5 h# D2 ], k
" H4 u# P, ~ ` VMMCall Test_Debug_Installed
! o4 d. T; x0 b je not_installed! R7 o7 J0 b `# @5 y4 v
o4 |% |: ]: D% _% [This service just checks a flag.
# R# g* M! m# `1 a7 x</PRE></TD></TR></TBODY></TABLE> |