<TABLE width=500>
7 g9 |1 [4 {0 V/ S* M& }<TBODY>
; Z; {$ }7 O* `8 u5 t: R$ @) z/ P<TR>+ J$ @ O+ I2 r+ M- ~) N
<TD><PRE>Method 01 4 |4 K: h5 z' d8 m, d* b
=========
8 s3 n2 E0 B5 V+ F a3 X0 C' {; d |( E: d* `# f; Z
This method of detection of SoftICE (as well as the following one) is
! o3 j5 T# u& B" N; ~6 G: v+ K- Dused by the majority of packers/encryptors found on Internet." u* B" B2 A. u$ @* Z5 f
It seeks the signature of BoundsChecker in SoftICE
' v& J; f3 f& [) R8 [9 I$ l5 r3 q& @1 G: l" A
mov ebp, 04243484Bh ; 'BCHK'- ~$ d8 _& N: ?" K4 ~1 a
mov ax, 04h
; \* b' P) _( D* w int 3
0 H6 U$ K, u. u0 G cmp al,4
$ ~! k# c# e/ i- s7 w1 f5 s6 a jnz SoftICE_Detected
6 v1 @9 [7 S' x4 l0 J2 Z9 p
! w4 p$ u& K6 n% v0 H, n' b+ d5 T& ~___________________________________________________________________________
, `, F" J3 ~5 U* v3 _; F
+ J/ K- n0 X, x$ ?3 l3 y& YMethod 028 P6 u! r: [7 b* `6 e
=========, V6 w$ O( f9 E6 H
; i0 l7 N# n9 s2 {: T
Still a method very much used (perhaps the most frequent one). It is used$ w z. i9 a% z% B, M [, |
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
/ s; o+ ^8 |( J# nor execute SoftICE commands..." v/ w: G4 w Z6 C
It is also used to crash SoftICE and to force it to execute any commands
. F7 q: k& Y& ?(HBOOT...) :-((
# i8 {. h# T# V" o8 l) _9 p9 S0 `
$ R: s g# S6 g; tHere is a quick description:
- g& @* h! s1 R( g5 p-AX = 0910h (Display string in SIce windows)% D# s, [, w# t i
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)8 F0 `5 Z$ c# Y, Q, ~% Z
-AX = 0912h (Get breakpoint infos)
: U( i0 n+ p* d/ m: U: K2 Z-AX = 0913h (Set Sice breakpoints)
# d% i+ s, d, c; W. } t# N-AX = 0914h (Remove SIce breakoints)
8 b& h5 z. e1 R# }3 `- B9 [- G( m' S0 v, d
Each time you'll meet this trick, you'll see:
+ m9 r$ X I% M& B" w-SI = 4647h8 t( C" [ a/ N5 Y% j8 i% V
-DI = 4A4Dh
! N/ ?/ y0 O6 p* HWhich are the 'magic values' used by SoftIce./ ?' l& ^5 z9 ?5 v9 {8 u
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
* K3 ~4 I+ }5 u4 F; S; D; v+ \9 c. S6 F* j" \/ o) O* x9 u& U
Here is one example from the file "Haspinst.exe" which is the dongle HASP
, h9 m6 r5 p; o) K# HEnvelope utility use to protect DOS applications:8 o7 r( D- h1 n0 Y I/ Q
5 n; x7 _' j4 p: Z; u Q) n b: m. j
. E0 V. t/ D: n- b9 k3 a
4C19:0095 MOV AX,0911 ; execute command.
: p. h1 q$ l9 `# @" Z! Z& l4 v! I4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below)./ R8 r9 T6 J( x2 C) F
4C19:009A MOV SI,4647 ; 1st magic value.
; r9 |% z* C: l1 B4 W' I' I3 ~) m4 K4C19:009D MOV DI,4A4D ; 2nd magic value.# j0 ^4 M5 U5 L! x8 T& L
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
0 d) ^* j( p7 D5 I4 Z9 e% M6 [8 B" O4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute1 y f5 j& `1 q& e/ q
4C19:00A4 INC CX
5 @( N Z$ l" a* k# g C4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
* A+ L1 i) ]. k4 x3 ]4C19:00A8 JB 0095 ; 6 different commands.- [& E) t5 @( |. ~1 @5 P
4C19:00AA JMP 0002 ; Bad_Guy jmp back.2 i$ d5 i' s$ f8 W) o+ d, s5 y
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
* c) L3 I6 D: r" J2 p6 ?- ^( H) M/ I2 g0 e
The program will execute 6 different SIce commands located at ds:dx, which
9 x+ b8 j3 P% k, k. v1 I6 |are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
' f& H; |* r( B7 k1 ~- T
: a/ s1 E( d2 L( j! y& Q6 \/ Q1 Q* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded. A" Z i- M( O4 U) _& S
___________________________________________________________________________' ]) U. S3 f9 ]0 Y2 s9 l
4 e: I5 q+ u, L9 C7 L' S+ ~% T4 @3 [ u4 d2 W) R- W7 b
Method 033 B' C" a, `. x3 N
=========
, P. l: A& {3 p, w" K/ ]) A
7 M$ `$ a6 B8 @# O! \) ~, R6 cLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
$ I0 J2 ^* W4 s(API Get entry point)
7 N: C" `; b: J c9 X4 H
+ Z8 @' G; |! R, Q! U
. k c# w B) z2 ^7 ^7 I xor di,di
! r# m$ Z! H9 {2 p* K6 M mov es,di
0 X$ b' [! e1 _5 r; ~3 G1 t$ O- q mov ax, 1684h " N' @6 V6 q8 O* f- k
mov bx, 0202h ; VxD ID of winice
8 y8 p5 Y, Q& w int 2Fh a! _% C& I5 [+ ]7 U( r, n; Q+ w
mov ax, es ; ES:DI -> VxD API entry point( Q5 }2 b) | @' J& r) E7 G
add ax, di6 {& P0 r5 o* ^+ [
test ax,ax
$ Q# s/ T8 U6 q" S4 u, a# D& { jnz SoftICE_Detected" J: F8 G; _/ @3 j; H; V5 P6 ?
% O0 x- v5 k& `* ^2 s5 U ____________________________________________________________________________1 C+ B$ O7 ]0 S# {
7 h) M6 Z; a' b# \' I7 m6 u+ A
Method 04" Y& ^# |8 ]6 C- F
=========. j7 Q+ |/ b- A) L! x
2 v$ v- H' I6 NMethod identical to the preceding one except that it seeks the ID of SoftICE; i. P! S3 q# W2 e
GFX VxD.. \7 ^$ {- v( {6 E
- G; G6 K3 q! S/ q* x' O
xor di,di
3 m r2 Z( A0 y% z! T3 j mov es,di& ]7 Z+ w5 i. @0 B' D$ Z* D5 _0 n
mov ax, 1684h 6 T2 ^2 q5 f/ W
mov bx, 7a5Fh ; VxD ID of SIWVID
) U+ y: n) u! q: R: l D7 }6 j int 2fh/ |9 U* O; m- d& U) G0 e
mov ax, es ; ES:DI -> VxD API entry point
! n$ S! }8 ]; O add ax, di! [$ s& I: K1 G9 y
test ax,ax
! |" E/ ~' f3 f$ f- C jnz SoftICE_Detected
1 v8 N& e- o) R0 [/ A/ x- s( }7 Y' B6 X/ V7 p- b
__________________________________________________________________________
% Y1 V4 e- k4 {2 f* C
% Y" ]% D) z6 d: R6 [# a$ X
6 v: |7 g4 k9 Y; n" V- iMethod 05
! }9 \+ p- F1 {. g( |6 R: ]- X=========
1 a; O3 ~8 [* F. O0 p) `
+ u: a! A, Y2 ]0 S1 q# B" cMethod seeking the 'magic number' 0F386h returned (in ax) by all system9 t4 j/ p* }8 t& ]
debugger. It calls the int 41h, function 4Fh.
- |, \! @" J$ b+ m1 kThere are several alternatives. 6 @# \) u& V0 \- a: j/ o" g
8 s/ e% O1 i. |
The following one is the simplest:0 X6 K( _% K/ U$ b3 Y: ]( B* n
- \) H" Z/ Z6 P* Z7 T. G$ D
mov ax,4fh
" X1 f) o6 [) V, ~ int 41h9 M1 C! p j' u7 z. Z
cmp ax, 0F386
1 ~$ \( ~6 r% p7 E2 u7 ] jz SoftICE_detected8 ]" C4 U! D) a; n! O3 z
. _+ v- ]% M1 ]# k2 A, P, n' O3 H9 C* m# q
Next method as well as the following one are 2 examples from Stone's
: z4 [6 m/ f Y"stn-wid.zip" (www.cracking.net):
* a8 p n4 Z D/ i; a) `( B3 O
3 d" r$ b! {* `$ t1 g6 Q mov bx, cs
r. [% n# n" O. q8 a6 r lea dx, int41handler2' {6 P' X! h- |6 @6 T$ E+ B
xchg dx, es:[41h*4]
/ t, i+ `8 |) p9 G. x& D& s xchg bx, es:[41h*4+2]
& u# F# p: k: j# e mov ax,4fh
" r6 J# i. p K4 U% T% H int 41h7 V8 B' K( ~. [' V+ G
xchg dx, es:[41h*4]
T& ^ o; Z% w+ n* b- l5 y/ d2 ? xchg bx, es:[41h*4+2]# P- h1 x" U8 b+ L7 \# u! s
cmp ax, 0f386h
/ n0 d v5 F6 @8 Y* _( p7 I jz SoftICE_detected9 `$ ?" _' d0 ^1 r, ~0 o' |! ?9 L) Y
R# u8 L: b/ q! @: A3 bint41handler2 PROC& [; {7 c3 E' h5 E
iret' D) b! I+ E% c% s0 h! a0 w
int41handler2 ENDP
# J2 v& N/ Q( y u m9 ]$ _6 H$ i- d, Y; f* W8 R' ]0 }
( U! E0 {$ {7 Y; @& d2 V/ A; I_________________________________________________________________________
' T9 C; ]8 M8 Y1 u9 I5 u; d s5 N) R+ N! \* l
l; s' b! ~; E6 l" V. U
Method 06& T- w- q* Z7 n/ O8 z$ [' E
=========
6 _0 F% `' k8 N0 h+ @
* }) F0 o9 D' D' U- ?- X ^! z
2 G' Z& t* y% E( j2nd method similar to the preceding one but more difficult to detect:! E1 k+ {2 Y8 h
( {+ ]. A8 U- B
5 O7 ?8 w: u* s0 }1 r8 Iint41handler PROC" J8 D- ?( @5 U6 ^
mov cl,al" r7 }% P7 f. J, l
iret5 B9 _) R$ g' p6 d: ]: D
int41handler ENDP
# o/ f" C9 ^- t. b2 j* ^; k, d$ B \ l
; W8 H/ H3 \1 l t$ f3 s' c6 O5 A
xor ax,ax9 V4 v( i4 K. A& u/ n8 \ J
mov es,ax" F# K2 X& X! b# X& `" Q
mov bx, cs
4 c- H+ y* e a" W- W lea dx, int41handler6 V8 P1 [0 ?3 @* j# g2 |+ a& K
xchg dx, es:[41h*4]
1 h! V" l4 E( \5 E3 s+ t* y xchg bx, es:[41h*4+2]
( U7 f; P3 [, S in al, 40h& ^$ K8 a- L+ k: p3 o v
xor cx,cx' s2 e* H2 `& A- n# M& N% [
int 41h
s& ~& ]2 p6 ?. X' T8 F xchg dx, es:[41h*4], V2 R. e4 g& ^6 q" S, V* I
xchg bx, es:[41h*4+2]1 M% l. f4 A& [& H" O/ O
cmp cl,al3 d a. L" k9 r; _
jnz SoftICE_detected( g6 G. Y( E( c
, |. D% ?+ e- K V5 v/ [0 p* H. M8 c3 u
_________________________________________________________________________ [8 p) _3 t4 _
7 \: ?1 G1 t6 n) k3 V* @- w$ ~
Method 07
* e6 W/ c9 u% G/ p" `=========
+ u) @& r8 o+ |/ J* v6 o2 n* Z9 |# ]$ }4 G# K. A9 p# q; ]
Method of detection of the WinICE handler in the int68h (V86)
) o) ]) M( M. `, l/ O1 y+ o! D
$ x9 ?. l: L1 h: E( Y. K$ j mov ah,43h& L! p4 t" H/ L* @# R4 J5 C
int 68h. b* r: z8 R/ _( f
cmp ax,0F386h
3 z, Q: l5 J) G) `5 L jz SoftICE_Detected( l* s3 |4 Y1 m+ f) Y
! K! T) y: Z: C; ~# M' e
5 j! u- x2 u8 a7 y! N- I0 t# H=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit' K$ i, c% b% D! c7 u
app like this:
" W5 M- D7 @! y1 [4 @, f/ }3 M
BPX exec_int if ax==68- D2 U2 E- U# ?5 _* g# l" q6 Q
(function called is located at byte ptr [ebp+1Dh] and client eip is
! l2 j" x5 q% s! }, Y& N located at [ebp+48h] for 32Bit apps)
* e, R% B5 S! d" Q! o__________________________________________________________________________
. S% k/ ~* S! Y0 e' e9 j8 Y: l9 z0 p4 U5 c
% n8 d P: n& _& {; D% w) C
Method 08' d- b2 [' B- f3 Q+ c2 j
=========
* x- l4 f5 W0 b( X. l" A3 m$ F+ T4 X$ s9 ^: ^9 h
It is not a method of detection of SoftICE but a possibility to crash the
( Z$ O4 u" m' c6 vsystem by intercepting int 01h and int 03h and redirecting them to another
/ X+ g Z- ?1 R) H5 Yroutine.. m( S& b; D( Y% l9 h& q1 U0 k5 v
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points& e) L2 O2 ], f i0 d
to the new routine to execute (hangs computer...)
& p' {2 F K9 Z: _6 f3 h, Q8 v: d6 u: C* ?# U, W+ [
mov ah, 25h
- g1 Q, H3 B5 L# v' s mov al, Int_Number (01h or 03h)- c& H) l/ {4 A! X, K* m$ b! O9 q" K
mov dx, offset New_Int_Routine
7 E- r% D; {+ h1 j! p int 21h0 q+ K/ |: t4 Y7 @9 R# o
# [3 X$ Q7 }/ e' u- b; p# [' K: g
__________________________________________________________________________; z5 N2 \1 ` @' Y
. `" o/ J7 P$ S7 A/ V+ IMethod 090 f1 |; ~. O( f2 H- C# P; i) J: |1 ^
=========" W6 a$ ]8 W4 f- P+ Z/ v
6 T" t. t4 {0 v& B% |+ cThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only0 i9 P; d, ^( e5 w. Q
performed in ring0 (VxD or a ring3 app using the VxdCall).0 W4 f5 Z+ l7 X( a- c
The Get_DDB service is used to determine whether or not a VxD is installed
0 } d( E2 e" k5 @for the specified device and returns a Device Description Block (in ecx) for& Y0 k: q+ X5 f, m0 M( q) Q, a
that device if it is installed.& q3 d2 h0 \" }$ l
( [5 ?5 G: \, [$ i4 @1 l; k' N" V" i mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID; p8 b: U% u; |
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
5 m, R7 [4 p8 L VMMCall Get_DDB
7 k% z5 _8 O2 j% m L g6 e mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed" ^" w$ x( I2 _% H8 Z" p, e* q
/ o2 r/ F) L8 [
Note as well that you can easily detect this method with SoftICE:
. B+ K& Z/ D" [ bpx Get_DDB if ax==0202 || ax==7a5fh" k) J4 {; I; |' W2 ~
7 k3 g* Q4 Z# y3 T. j6 Y__________________________________________________________________________
+ i% U' z9 y! k6 n7 J: c; D
7 f: ]: w( G! X B; J$ IMethod 108 b2 o2 V/ s% q p4 d4 m
=========
- @% B* ~* ? y$ I+ F' S
, U. \, g, v1 W8 F=>Disable or clear breakpoints before using this feature. DO NOT trace with+ b* `; }( h& e: F9 ~2 z- q
SoftICE while the option is enable!!& Y5 u; p6 r4 b/ k
I# I5 X( ?# V) q' [. s n
This trick is very efficient:
4 i1 \: T! q/ f1 ?by checking the Debug Registers, you can detect if SoftICE is loaded. n. [9 Z4 ~0 W7 I" x8 Y$ h
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if% M2 ]: x" H) h3 Q
there are some memory breakpoints set (dr0 to dr3) simply by reading their2 t3 M5 W+ j- G/ W: Y
value (in ring0 only). Values can be manipulated and or changed as well- s9 X# m# T9 H" t3 F' \8 `+ e2 r( P5 c
(clearing BPMs for instance)
: x6 R5 j% h) Q7 o* E. d0 H5 }
1 d: P( r% `$ O* F# l__________________________________________________________________________) }% P4 d2 g1 b4 N* C7 S4 j" e
! G4 Q% l( S1 D" y, I' VMethod 118 Q" z8 I) n: u, Z+ o; t
=========
' E9 \ w/ F z8 _. C# p- K; l
2 s8 r6 A% B8 S$ ~This method is most known as 'MeltICE' because it has been freely distributed7 l+ K2 L! b# Q6 s+ N+ ]
via www.winfiles.com. However it was first used by NuMega people to allow
6 E) ` J' M# H2 z, I. ISymbol Loader to check if SoftICE was active or not (the code is located! s! |- v. a0 n) B& h) r- }6 O! ]
inside nmtrans.dll)./ t0 b0 W/ J! \0 S- C' R$ D6 }
* @7 b9 P8 G- b- ~, q- _/ Q
The way it works is very simple:
/ `9 h0 B7 b# y9 WIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for- L9 e! X9 ?/ x2 S" ~! n8 x
WinNT) with the CreateFileA API.
1 G5 c2 x! _" s' f! ^& M. v1 N
; |2 a6 B, `, {5 OHere is a sample (checking for 'SICE'):
6 C5 b D* @9 ^2 L
l4 z2 T6 @+ }, _3 fBOOL IsSoftIce95Loaded()
+ e7 f$ U7 ~, u{8 v1 W6 H% X: K9 H
HANDLE hFile; 0 \. a' x2 B9 v- e2 I0 k" L
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,: ]; V$ B/ H$ T& K) D
FILE_SHARE_READ | FILE_SHARE_WRITE,* k# H. I% b* d3 k0 h4 Y
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
4 Z1 a4 T0 `9 X& Z if( hFile != INVALID_HANDLE_VALUE ); p; ~" |+ E G7 M) x
{
. r; w* e7 J( T) U, q8 B CloseHandle(hFile);! C% G3 b0 E3 X, @+ h* o
return TRUE;" ^4 ^. G8 E, I1 l% U+ x0 L
}
/ d8 B* H% X( e3 b, }9 w; L* e return FALSE;
+ k+ u5 T( {/ i( ^* U}- w% K$ [6 F, T1 o0 B1 Z
0 u+ u0 O, v' y4 X B$ j! b+ I7 RAlthough this trick calls the CreateFileA function, don't even expect to be
5 y+ \' Q; |1 h, Yable to intercept it by installing a IFS hook: it will not work, no way!5 Y s/ V6 X8 | [3 f) X L1 s- {
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
8 a9 P( I9 K# \8 |6 i i- tservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
J1 i+ c9 G6 t9 Zand then browse the DDB list until it find the VxD and its DDB_Control_Proc
. R: _9 Y) o5 t4 g9 Efield.
0 Z$ p6 E0 b+ \8 RIn fact, its purpose is not to load/unload VxDs but only to send a
" Y* B4 E3 M: _W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE). R' ^+ b3 J1 Z; h
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
4 H$ Z. ]! S8 ~- ato load/unload a non-dynamically loadable driver such as SoftICE ;-)./ o. H9 U' {+ X4 n* f
If the VxD is loaded, it will always clear eax and the Carry flag to allow' d" N# \0 }7 k9 ?5 v
its handle to be opened and then, will be detected.
% r% E( T6 j8 H* ^You can check that simply by hooking Winice.exe control proc entry point# a Q9 }# J3 s7 P
while running MeltICE.0 U$ p/ v( s _' p/ h( }" ~7 K
6 D- ^$ e3 r2 J7 x/ M' i0 s1 O2 \
+ T$ K7 L( F) M1 f& w 00401067: push 00402025 ; \\.\SICE
5 M% k6 L# {$ z8 s$ s 0040106C: call CreateFileA
) t5 s; x1 g. ]& A: C2 H 00401071: cmp eax,-001
& W2 ~7 j1 `8 y6 q1 K8 [$ F+ m% n9 C 00401074: je 00401091
# C% `' i' j% n
$ z4 z5 U% c0 x+ T( A$ o+ V
7 }+ k; z Z. J% dThere could be hundreds of BPX you could use to detect this trick.
3 c/ h" g3 L" W7 V( G6 K3 I+ m-The most classical one is:
5 f7 {1 U& ~* z# j- }: q% p( j$ g. L BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||+ M2 _( I; ?, T A
*(esp->4+4)=='NTIC'8 F6 e3 o4 y6 ]; r
! G) D; ?$ }! W0 X7 m; P" Y3 J6 i-The most exotic ones (could be very slooooow :-(; A/ O l U5 X9 h& x
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
" ?2 B: N& {. G7 e3 \/ j ;will break 3 times :-(
1 }7 B% N$ c$ G/ y
6 e3 f* Q" i: A0 M3 h-or (a bit) faster:
, \0 N3 ^/ C. C! m! I- D& D2 k1 N BPINT 30 if (*edi=='SICE' || *edi=='SIWV'): X7 o7 R2 e) V
% K' Q4 R/ d% Z% M8 U- G' O" b3 X4 } BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
( X6 q/ W4 J8 i1 a% R ;will break 3 times :-($ o d( j; W& F, [- ?" t" _) i
O* w8 t- Y; ^' a' d-Much faster:
9 [: v, ^3 @ {4 }2 C- r" l2 U5 p9 B BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'( g- @- I$ l3 u1 o
8 v; V1 l% e K6 ~+ k
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen8 {3 I' e/ X% {; i# E3 S
function to do the same job:
& R* L- I$ B! Q5 j7 B; K
' Q1 w& x& x4 ?4 k/ f push 00 ; OF_READ; I' T- o9 J7 o2 Y a" y* n
mov eax,[00656634] ; '\\.\SICE',0
8 Q/ J1 T2 H6 o4 \ push eax
8 X- n9 a: M" K call KERNEL32!_lopen$ D- [1 x* B4 U" ?; ?0 L: [! ^& P* b
inc eax
9 _5 `! t. g' o3 x jnz 00650589 ; detected( Z Q7 ~8 z; {) g5 I4 L
push 00 ; OF_READ. G% Q) R+ r0 v5 O( \
mov eax,[00656638] ; '\\.\SICE'
; \& C1 g4 y+ K M6 L6 S push eax
& K" K7 D: h, O! j call KERNEL32!_lopen" @* O7 y2 w/ i( x( }6 ~1 j
inc eax4 t, U) V5 z7 z( ]6 E6 J% I
jz 006505ae ; not detected9 l& a. |) h5 z+ z7 t5 y
7 z0 B8 u8 u6 ~/ K
' X# G" m9 X g& i, z; l
__________________________________________________________________________9 n2 b6 @8 s3 p; F9 }: b; \
# C7 T5 O, J: L5 h9 D& z" J: hMethod 12# \# e" J* x/ m- J$ @1 _0 K! o
=========+ P" `7 z" D5 R7 X! h* C' ~8 P" [
; w6 p: d7 {! X
This trick is similar to int41h/4fh Debugger installation check (code 05) N7 k* O5 |" ~
& 06) but very limited because it's only available for Win95/98 (not NT)
/ T. H2 N5 o5 Y( l" Q/ J# r3 Was it uses the VxDCall backdoor. This detection was found in Bleem Demo.
, ]' r: D; g' h
' Z0 ^2 r9 T! ]( m push 0000004fh ; function 4fh, H. Y# {$ `! ~% k
push 002a002ah ; high word specifies which VxD (VWIN32)* A+ T0 M4 N/ L/ m1 s+ A
; low word specifies which service8 X2 q! E% f+ r
(VWIN32_Int41Dispatch)+ i5 @; d6 R. C, G2 M7 l
call Kernel32!ORD_001 ; VxdCall
4 s/ g7 y. ^& K, U cmp ax, 0f386h ; magic number returned by system debuggers+ B( q& |/ F# B* v! b) X
jz SoftICE_detected
: y) G" j$ L! T" p2 e$ ~/ Q
9 P. Y+ u) Y: v+ I+ b6 iHere again, several ways to detect it:
' N! h& _' l3 j2 c4 Z7 [
$ a. U. Y) D1 t( _ BPINT 41 if ax==4f
8 C* J2 j3 P: U, o
% @5 r6 \8 a. t) W! O# z6 J' m" u BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
" D/ _& a( i1 n6 `% S8 n. a! {9 W, [, n+ I
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A- ?- w$ s7 q/ e9 X
' I9 [4 b! a' G; V
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!& F: k5 k, j) E
: n# N$ i) m( Q) Q9 `3 E9 ]__________________________________________________________________________
9 L* e; a* z0 [$ K9 D; c0 k) e$ ~7 J0 q9 i5 |& N
Method 13 @. h5 `! u2 a+ I
=========
( Z2 _- x" W1 n1 p- X
/ m) |6 l1 l- c: X6 f7 U8 Q) hNot a real method of detection, but a good way to know if SoftICE is
: j" C7 Z8 j( Tinstalled on a computer and to locate its installation directory.
2 G* R; l& z2 h7 q8 G6 WIt is used by few softs which access the following registry keys (usually #2) :
7 [3 C! A3 v% j( y4 ^& w7 Q6 J& O; n# q8 l1 \' F. W
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
/ l# u! j$ p$ \3 M\Uninstall\SoftICE
0 L" q! r7 F6 ^! T* R-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
6 J! a4 D9 r6 H, b* x: o O8 J-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
: E! Z0 E2 U* G. ^3 I F\App Paths\Loader32.Exe
: _) c1 f0 m/ F, l" O
* E+ g/ F* v) e" e7 {0 R" a4 w0 q3 b3 Q) u
Note that some nasty apps could then erase all files from SoftICE directory
" r: B0 U. l4 l9 [" i! Y(I faced that once :-(7 h7 @% X& ?+ W7 u
% G, ]9 [3 _/ B+ A! tUseful breakpoint to detect it:
9 O; r+ Y/ b' G5 H$ p! I2 Q) W* a% f" x% q# I7 u4 M/ D; T( t
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
2 O9 `( W- I5 u4 p+ F
2 Y6 M' |! o! S__________________________________________________________________________
: b5 X0 w9 C) X5 w1 ~" f8 Z7 a1 m% X4 t# w4 A
+ W4 y2 A* |, J# B5 XMethod 14
* p7 g+ a' m$ N* f, }- L=========
- M4 y: R6 _( S+ P9 J4 R: @) N
7 |- B3 P' O0 NA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose9 J# n5 {$ x" v! y
is to determines whether a debugger is running on your system (ring0 only).) I# ]3 ?. Z' T+ V. j* G4 C
. u; _3 H$ m9 Q8 i# u: I VMMCall Test_Debug_Installed
8 I9 n m1 }. X je not_installed7 R* N" y# C/ O9 T
' L0 |6 L; I. a. }. ~, JThis service just checks a flag.
& k2 u/ N# l5 K% d/ ]5 c</PRE></TD></TR></TBODY></TABLE> |