<TABLE width=500>; s, `. H% N( f* d1 d& t+ ]
<TBODY>1 e9 o7 x# D: U7 Q( Q' E- h' ?: g$ D
<TR>* N% w ^$ e2 s2 d
<TD><PRE>Method 01
1 ?: ?& [- M2 |0 m- r, B, n=========
4 E+ ?& i+ n r' w
3 ?- R# W, G& O. Z+ E! S& z ]This method of detection of SoftICE (as well as the following one) is: M& N$ l0 _6 B8 T
used by the majority of packers/encryptors found on Internet. X* ~* `, ?# t8 O% C
It seeks the signature of BoundsChecker in SoftICE q2 v( k, s& T- T+ }$ R* n$ ]
" x* n4 `' w E8 v2 T* ?4 Q mov ebp, 04243484Bh ; 'BCHK'4 l4 C, n2 O L+ X# Y/ d
mov ax, 04h2 Z+ W- Y4 f7 N
int 3 ' c: [" i3 k7 f0 r/ i% b( Q
cmp al,4
; e1 H# \, t, ^! m jnz SoftICE_Detected
1 w' o, V) N8 }- A8 j4 W2 D
) B& R2 d M1 O$ _ H___________________________________________________________________________8 G' Q1 b) U$ M, C. Q2 p, q
p( \# J4 N4 d; ?7 \8 T! G, ~! K
Method 027 ~0 s; q9 K! Y) C9 m& m3 C, @
=========
W- c; O8 c7 I+ g# t0 g
5 a- n& Z9 Q. w9 yStill a method very much used (perhaps the most frequent one). It is used
7 N s x3 v: t5 wto get SoftICE 'Back Door commands' which gives infos on Breakpoints,1 p% S, H" A z5 g, f
or execute SoftICE commands...
4 S" u5 M9 e0 D8 jIt is also used to crash SoftICE and to force it to execute any commands7 x/ B2 c' t _0 k' h* u Y
(HBOOT...) :-((
; Z: n( Q/ h7 g$ \; @- e0 i5 I# _" ~7 @
Here is a quick description:' t6 A6 ]# T- {) N! e- r7 D9 y* H$ K
-AX = 0910h (Display string in SIce windows); o/ N9 P# X; g D# C8 V
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx): z6 f6 n& V, E6 w
-AX = 0912h (Get breakpoint infos)
' X2 ?$ S( H( C6 |0 V) D-AX = 0913h (Set Sice breakpoints)
$ `1 a7 Y3 R+ l3 }' Q) X-AX = 0914h (Remove SIce breakoints)
+ \3 R8 v7 Y9 q/ r2 y# k3 i+ F) J; s6 m7 v4 Q( X, T
Each time you'll meet this trick, you'll see:" V1 ~0 E, P, @! Q
-SI = 4647h
I+ F, Q& w. M" H" Z-DI = 4A4Dh0 a; Z9 g' }+ U+ c$ i4 r. v
Which are the 'magic values' used by SoftIce.
3 ~" @8 h6 _* T& h( J0 VFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
; z1 B2 y! _- c6 d; {
1 f. J4 }, Y. R0 sHere is one example from the file "Haspinst.exe" which is the dongle HASP
$ L0 t6 d% @* R- O5 W/ [Envelope utility use to protect DOS applications:7 i1 G; P) E% P( k# S" \$ d( |
0 ~2 A0 s2 \2 F) G0 I
3 Y* A* C9 d5 w l* a4C19:0095 MOV AX,0911 ; execute command.7 Q; r! t) j& q8 ?* `( V) u) z
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
$ V( l0 d- A3 w- R4 o/ ], y4C19:009A MOV SI,4647 ; 1st magic value.
3 J* z3 V1 O# D) @' Z' X- i4C19:009D MOV DI,4A4D ; 2nd magic value.
: ~0 ]' S! @9 I2 J/ O7 c( W" N4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)& \# @( E1 ?! k5 J
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
% ]8 P2 J z( w4C19:00A4 INC CX* x5 D. G, V7 I" b' K
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
- l D1 e1 I3 [ K0 h4C19:00A8 JB 0095 ; 6 different commands.! E" ?. u. i7 ^ Q
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
# B, w n+ D, k4 X+ |% i7 r& @/ w4C19:00AD MOV BX,SP ; Good_Guy go ahead :)# x5 m6 @0 a! y1 A
9 L+ A. Z3 d$ X$ Z# m7 Y+ b; i5 QThe program will execute 6 different SIce commands located at ds:dx, which
. e# L! @% E6 Q3 J, A/ T/ care: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
# z( p7 m' h# l$ b
9 _5 U: G4 F! V- t5 L3 R9 D* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
/ V* r. J4 U5 Y___________________________________________________________________________7 O& F9 |2 X% S `8 _: ^
1 M2 m5 E% I: l6 g0 ~! g( H6 ]7 A. h! j+ ? S( K
Method 03
6 b! e, W, B: i# @, C+ T=========
; s- `, @, W9 J" K, h2 k% y; ?) M s- p% |# M. q" r1 v( t0 |
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
( C" `( S* B3 w/ [8 \5 D2 ]2 P2 p(API Get entry point), F3 d0 }* @8 ?2 D# x- E1 \
4 e5 \; I" v4 {( v2 z! I
6 l5 @2 y6 t- W I xor di,di
( c" S8 r' `0 F0 w mov es,di F' ]5 |3 F, X
mov ax, 1684h
$ z1 r, @; F3 ^# d2 U8 c mov bx, 0202h ; VxD ID of winice5 P5 Y' @6 k/ _* \$ [0 A: B
int 2Fh8 n5 ~8 B# Y8 n) ^: w& G: F
mov ax, es ; ES:DI -> VxD API entry point8 X$ y6 P; H! P; G% w+ J! c0 w+ k
add ax, di% A& M9 q- m$ E* J2 I
test ax,ax
5 u/ x- C9 p n3 a jnz SoftICE_Detected
, G# s0 @3 S& u0 p
5 m5 D* p. ]' X5 q___________________________________________________________________________
8 s; t2 O3 O, @2 |$ J% _+ S/ f; R+ D8 T' q) p* f% k
Method 04- t" l) [2 f {" P" r3 T7 l) O
=========$ g" @1 M+ ?9 C# i
) j2 h F7 a. L( h# V
Method identical to the preceding one except that it seeks the ID of SoftICE
) W6 W" c/ m/ _0 sGFX VxD.) e3 p6 r6 m: {
6 H3 k4 c0 L! ?( S xor di,di
2 x4 i! {. | }/ b; O# H8 v- o- t7 e mov es,di
3 z% K0 m9 c9 {, g+ o! u, E mov ax, 1684h 8 E4 ~$ Q i7 t
mov bx, 7a5Fh ; VxD ID of SIWVID
. B" F! ^1 h6 j$ R. x* g int 2fh
- C& M! N) \8 p# _6 K9 n9 Q mov ax, es ; ES:DI -> VxD API entry point
% e6 f' J# T" H3 f0 E U add ax, di$ \+ Z9 O& i2 k, p
test ax,ax) z& [) P* e3 |# S8 _
jnz SoftICE_Detected4 j' Z, ?4 ]5 q; ]9 e* Q
- N/ y& ]; [$ k2 I t
__________________________________________________________________________
7 p( t* }4 L# d' Z: T5 H1 { B, W; Y, g$ e
% R' X D6 Z: p5 h; k% ~Method 05$ X4 X! I) o5 f1 n
=========1 W" h8 ~, K9 }& V3 ?, j2 W
: ` N) i$ e; z! HMethod seeking the 'magic number' 0F386h returned (in ax) by all system
3 q1 y) g; r3 {4 ^( I% f1 idebugger. It calls the int 41h, function 4Fh." { m' ]* {' b4 s% S2 s3 s1 k
There are several alternatives. * w+ S5 T( M% |
* S( O6 G. e3 O1 i n& _2 v- a n
The following one is the simplest:# K* V" ^1 g4 l- i s
; a3 m+ j4 w- I9 i$ g2 R2 x mov ax,4fh
* z7 C$ m8 V# ` int 41h
8 C7 {; t/ n& D6 P, m6 ~0 }9 \ cmp ax, 0F386) U$ P! Z% h3 I) p
jz SoftICE_detected8 k8 E, R9 L/ F
( Z+ \0 v# c- m, Y2 n5 w
7 j* Y1 Z; w4 U
Next method as well as the following one are 2 examples from Stone's
1 | C( R$ h' N& f' _9 N6 E& [; A"stn-wid.zip" (www.cracking.net):! z/ M. Y( y+ T! \0 }$ T2 r2 C
/ G, \& M$ _( G0 f2 Z# V
mov bx, cs; T) ~ L% x4 c- e$ D
lea dx, int41handler27 l5 V( `2 Y+ a; ?4 @6 K( q3 v
xchg dx, es:[41h*4]9 b+ E) b9 I, u4 _7 W" ^
xchg bx, es:[41h*4+2]* l5 O4 g4 _. I& v* O9 C1 w
mov ax,4fh
$ s, c% K6 z, D% A9 O% w0 a int 41h
' O' ]9 O5 y* O' B" m& X xchg dx, es:[41h*4]
9 R+ {! M% W% F( `/ M xchg bx, es:[41h*4+2]
* c$ g& G% Z; K8 t O0 M* y cmp ax, 0f386h
5 O- u+ ^- \7 D" J |$ X# D5 Y jz SoftICE_detected
0 F) u) g$ O# Z( M4 H* c: T5 Q0 h2 E @4 Z$ b
int41handler2 PROC
8 i8 G. l/ |2 U+ y2 m- Q iret6 |7 z; r( L, C( \7 N9 m7 z
int41handler2 ENDP3 l+ I. z& V/ U( T' T$ m2 L3 A
5 n4 N5 U9 ^$ n9 T8 T2 g8 S
: E0 n# V8 R! q! T$ s: \_________________________________________________________________________0 Z' {; u; N0 B8 g( K- e
+ x; c: P" N q
+ y! S# k4 G& _ V; I' X& QMethod 06
" {" |9 X8 g7 T6 F=========; z5 _; y- |8 T& Y$ I/ U" H$ I$ }) W
# [# i- u2 p8 r; r- y
9 ~$ a3 |; u) \2nd method similar to the preceding one but more difficult to detect:
: R) H" H: q/ J+ H) w: \ K0 A4 D4 f/ c( @$ u' r( D
0 s, d+ }' r+ w% M" l
int41handler PROC, L | C( X% P& r( g; {) N% _) a% \0 u
mov cl,al
+ R& ]- W, M/ a$ m7 d: ^3 r! u iret+ m o1 I# d. b! {% R- w
int41handler ENDP# l$ C* m* {/ Y9 L
- d5 V8 u4 S! v# j* Y
g! b; s! r$ ]9 |3 M+ J
xor ax,ax" R& w) Q& m0 K6 \( ~' z& W
mov es,ax
4 H) U. @4 ^" L$ V3 c# r mov bx, cs' G' i: K! r" y$ l% e2 c' w6 T
lea dx, int41handler
: m5 N8 r' c) r: W xchg dx, es:[41h*4]
/ Y# ~6 y) e/ ?' z. }: h0 j xchg bx, es:[41h*4+2]' H8 A+ H" r# v( V3 V0 d
in al, 40h
9 R5 M) G" M& o# l4 `8 J4 G6 a& ]8 h xor cx,cx
* ?& r6 J1 Q& G int 41h0 Q+ z5 q* D# s
xchg dx, es:[41h*4]6 [8 h- M7 r3 _, j5 q/ w% ]! k
xchg bx, es:[41h*4+2]
; K& _. ?6 \" ?( |. x cmp cl,al( ]& t ^9 T$ o+ w$ U( _! H
jnz SoftICE_detected
* P. j! n, y) P2 L+ n" u: o9 n: r$ r) _+ j
_________________________________________________________________________5 x0 G- v/ U& P- I; r
2 _* \# r }7 K7 P3 z! y
Method 07
# h, Q& f% z: H# w6 h! @=========
/ b7 y9 | l8 P0 r
0 ]% m& e c. [0 QMethod of detection of the WinICE handler in the int68h (V86)1 i$ Z* X: G+ D8 g. a# l0 H+ B
, h" M8 K- c4 t! O mov ah,43h
6 D+ t5 q1 \" k3 x int 68h) l) P* n$ B. d, W9 a8 T
cmp ax,0F386h
3 V+ P4 V; L W jz SoftICE_Detected3 i |, Z, Z4 {, |6 i, H
6 T6 K( }( O: R4 L; m# j3 J8 ^7 @6 S) u( A
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit7 u' k. f2 }8 n. n- N* w; L7 ]
app like this:# d' n; R. D j: ^" H, J
; j8 v5 P3 { _1 N+ c
BPX exec_int if ax==68! k5 I8 q2 w( G- B" W y
(function called is located at byte ptr [ebp+1Dh] and client eip is
! R; P$ g5 Q& C7 A located at [ebp+48h] for 32Bit apps)
0 ?* {5 S7 A* A/ R__________________________________________________________________________
) ^, N% T) N M6 J! F. ~
/ P& W6 @) U$ R" n' v/ N' [' }( `6 ^4 E+ z3 M2 W1 k
Method 085 E2 b# J! g( l8 g: n0 W0 ?* J
========= z% i" H+ E) P. E2 {- r
5 ~/ s% e% p1 O! A/ U2 u3 i/ S
It is not a method of detection of SoftICE but a possibility to crash the
% Y7 A% [, T0 ]% ]system by intercepting int 01h and int 03h and redirecting them to another
. T: W6 T+ O+ k* y3 q4 v$ aroutine.
; O/ ?2 r1 G5 i5 Q$ qIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points, E! J/ ?8 R8 ?% Z$ Q& W$ o
to the new routine to execute (hangs computer...)& }0 U! N& y" D
7 O* V9 q6 j- [8 g( o mov ah, 25h
; }% j: k5 L# N9 O mov al, Int_Number (01h or 03h)
; j: b3 L1 V( s; ?2 o mov dx, offset New_Int_Routine
5 }2 P' u O3 {, z2 l; X int 21h# F& T& o; m5 o) w. R# |
" u2 W5 |, h4 Z+ ]
__________________________________________________________________________ t& q/ f+ h' V1 i; v
}1 d6 |9 H: R, q- W+ `- E# |
Method 090 {7 P! @- g1 g# G: V
=========
0 W4 k7 i. v/ x3 e9 O% w: R/ N
) d, H/ ~; v5 h' n, NThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only# i4 }* J! w' {
performed in ring0 (VxD or a ring3 app using the VxdCall).; A6 L3 D% U. N
The Get_DDB service is used to determine whether or not a VxD is installed
' S7 g1 [/ ~! @1 yfor the specified device and returns a Device Description Block (in ecx) for4 ~9 ]: r# h3 o- T/ e9 ^4 t
that device if it is installed.
1 u7 f$ Z/ V2 @( k$ l& Q1 e0 r
3 t5 {" B+ ~/ }9 o3 Y mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
7 @ g; q4 t$ W r j p mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)8 _9 o( n( ?' B0 \+ A8 z3 A
VMMCall Get_DDB
* {% _* g7 _2 J% @$ ~ mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
5 y2 A0 Z0 L% [0 h; B0 Y# c/ g3 m6 d% S
Note as well that you can easily detect this method with SoftICE:' u6 }4 |7 y9 S" s; Y/ P
bpx Get_DDB if ax==0202 || ax==7a5fh3 G# V' u8 A2 R' E4 D; Z9 ~
5 K7 x' m( f3 ]' j6 V. N! @__________________________________________________________________________
% [- u3 k. ]. L. `% g2 y4 Z, g7 A
Method 10# ^4 j* C/ n$ v8 n, u% c" d
=========
! ^+ J# S. w, _
; n. @, o, `5 p$ o H=>Disable or clear breakpoints before using this feature. DO NOT trace with
: }" b. M, q- l& Q7 p1 q+ C2 a SoftICE while the option is enable!!9 l9 r) D- t" Q) @+ G) j
% w' Z }7 J6 k I0 { B% U7 G9 J* EThis trick is very efficient:
! M& |( ^1 {" L! d6 ~$ pby checking the Debug Registers, you can detect if SoftICE is loaded! { N2 j9 \; E3 t6 i ^0 o) E0 Z6 ^
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if! \3 e8 g* d( T# V$ |; q& i- I
there are some memory breakpoints set (dr0 to dr3) simply by reading their
2 S% C9 ?! w4 L" w! ]value (in ring0 only). Values can be manipulated and or changed as well% ~1 U$ s% }! K/ B4 K- @: C! x8 Z
(clearing BPMs for instance) z6 U& K. q( I. P6 _. J8 z
+ g. c' W- J* O" _4 O8 J__________________________________________________________________________& l/ K, |$ S4 c
: t9 `* D, w" Q) uMethod 119 ` N6 r# n3 |5 b
=========
* Z& Q& z' Q5 [! F6 V3 p# v( ]" ]+ a
This method is most known as 'MeltICE' because it has been freely distributed
" T# o/ V, C8 b# ~/ J- wvia www.winfiles.com. However it was first used by NuMega people to allow
0 C& Y* t4 P4 _! \Symbol Loader to check if SoftICE was active or not (the code is located6 P0 b1 e4 J [8 d4 J" G% z
inside nmtrans.dll).
0 Z% {7 ?1 O+ e9 P0 ]3 S: Y9 [. f
) {0 T# L2 a5 @! H) F( {$ \" AThe way it works is very simple:4 W" a+ E9 j5 g% a( b3 i3 B# R
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
% u& V9 \) w4 UWinNT) with the CreateFileA API.1 H* |7 {5 T0 U9 P- a9 W
- R8 O, }7 h# X6 K5 i% ^7 y
Here is a sample (checking for 'SICE'):
4 K5 Q7 V) s% f3 w* y- G
1 ?, k3 R; z" }' w0 `: RBOOL IsSoftIce95Loaded()
, f/ D O) ^+ I- I7 C4 W{
5 A: k% B# l' U E3 W HANDLE hFile;
2 x# X* X: F9 B1 K1 i1 z* Y4 k* ` hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
! {$ W6 W; X, \/ e: T( ~ FILE_SHARE_READ | FILE_SHARE_WRITE,
' j |; ^! {; c% h3 d: `1 P# }" ` NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
' s/ r: ]% p4 t# J! x/ s/ c% G. e if( hFile != INVALID_HANDLE_VALUE )
7 H8 P7 \0 i" s$ b. J6 g+ [ {
2 q5 A2 V/ J3 X5 ?5 k' X CloseHandle(hFile);% z; Y5 I* W1 j5 u* z1 u
return TRUE;: i1 D: O T. s, C
}0 {# l. J4 D. E. U8 T9 F
return FALSE;) w O2 E5 q+ S0 f
}
. B6 L, |1 o% F: v! e3 D
8 b. Q% u1 y1 I- z9 l7 Z' u- G" DAlthough this trick calls the CreateFileA function, don't even expect to be4 `8 J" U, o* ^- F
able to intercept it by installing a IFS hook: it will not work, no way!
/ c) G/ \0 F2 [! jIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
. K$ q9 {2 N; Y/ Aservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
5 g, w3 M# G9 L4 d$ nand then browse the DDB list until it find the VxD and its DDB_Control_Proc
" ~& r5 e% T, C- a3 sfield.
9 \% G6 i; D7 W9 {) w: ?9 qIn fact, its purpose is not to load/unload VxDs but only to send a
9 m! F- t' X( I' sW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)% ]. C1 o+ r' ?! h4 m. m6 G% Y t
to the VxD Control_Dispatch proc (how the hell a shareware soft could try; u4 I* ]+ p4 m4 `- A2 z" I1 E& K! K
to load/unload a non-dynamically loadable driver such as SoftICE ;-).8 l2 c5 ?2 M6 L \8 E% U3 c: }
If the VxD is loaded, it will always clear eax and the Carry flag to allow0 t( [% y5 A/ C( z5 i/ w
its handle to be opened and then, will be detected.
6 U" G8 h5 k: x$ U* ?0 _; D3 wYou can check that simply by hooking Winice.exe control proc entry point+ C7 p4 S# o k1 v4 G9 W# H
while running MeltICE.4 A) ?* t3 i. f
7 E, X0 I5 l0 K
: t q& s! e: i3 t1 Z3 S 00401067: push 00402025 ; \\.\SICE
& w8 V9 _' x% g2 S- r, i* K" [ 0040106C: call CreateFileA
U/ `( Z6 T d! h8 v- X 00401071: cmp eax,-001
- Z5 W6 g, M- Q/ Q+ L5 A$ O 00401074: je 00401091, ?6 @3 l- D+ S9 E& w5 q& m
5 E( l/ f0 E" @3 }8 o/ W" u% X3 e0 C5 T3 A
There could be hundreds of BPX you could use to detect this trick.
. ~0 |8 D# L) j# `$ K3 ~/ |-The most classical one is:8 V' x4 s' h" t1 X* F9 A% n% p
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
8 N# U+ S8 j( V( D: n$ P7 P *(esp->4+4)=='NTIC'
1 O" e6 ~. |6 W
) g" _! H: A+ b4 @2 M-The most exotic ones (could be very slooooow :-(
$ o; L9 b7 D0 o: k" L) j6 A BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
: s. x' R& T) b: P ;will break 3 times :-(# P7 J! B8 I; _ {
/ Y. y: }- {) D9 u
-or (a bit) faster:
4 m2 {0 N% {; d BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
9 {( x' M1 |7 W* D; {2 m5 f+ W" j+ q& K, B3 ~8 G" F, {5 q
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
0 G( i( a5 B% _2 g7 u' v7 b8 X ;will break 3 times :-(, @9 o" a5 c; \6 R! z- W
# {- v! _( R$ I; ~-Much faster:
; A" v" _( x7 s" R3 k+ C7 ^0 u BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'; B$ h8 k& W2 u9 z' {7 r3 W
; m9 z0 D1 @( e# Y( A5 \$ @
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
( o+ p8 t1 z3 D+ \) m4 _function to do the same job:
0 A K. ^ J% L. k! r6 m7 W% ~+ T
, o+ }3 N% [3 G( [8 Q" c3 D7 K push 00 ; OF_READ
6 ^& m9 E1 G3 ^5 i( r" N' U" @ mov eax,[00656634] ; '\\.\SICE',0
" B- c, R( \* `9 F5 H! X- h push eax
6 J7 t1 l \* A4 b call KERNEL32!_lopen
; c9 e: |+ _ H& @3 I inc eax
8 U3 U0 A# V2 w( z) C# a* p jnz 00650589 ; detected
& n# J, k! ]7 E% ] push 00 ; OF_READ
& J8 a6 ?0 O9 k# n/ b/ N. ]! B mov eax,[00656638] ; '\\.\SICE'
" }, [& a. ~* W0 f0 S7 T! c push eax
' a% R! W! t& P$ A call KERNEL32!_lopen
4 w% [( B# ^2 h inc eax
3 M3 n8 O0 X( L; V# e6 b8 ] y jz 006505ae ; not detected
; o4 R( O& W. e) C" D) g& |0 E9 ]1 b4 Y
6 F5 u- S+ T+ C f/ ^% z) f1 R__________________________________________________________________________" ~6 y, T8 N Z2 o; T
- P# b% K5 H( B7 ^: z5 |5 H1 h
Method 12/ I3 p! |8 b+ q+ a0 T- { g3 B
=========
}) }1 x: W$ I; U; q% `7 y. V% V* f. l; r5 n* M& |
This trick is similar to int41h/4fh Debugger installation check (code 05+ L. D1 B2 r8 v/ D2 Z
& 06) but very limited because it's only available for Win95/98 (not NT)8 t2 m" k! l% N$ e/ R
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
4 G% ^% O* f6 |; c' O/ _7 [$ l$ w+ A p6 T% w9 u; S7 r( E/ A+ ^
push 0000004fh ; function 4fh3 S& {1 w L: f, I& j5 `# {
push 002a002ah ; high word specifies which VxD (VWIN32)9 l$ C, q+ b1 T2 g3 V3 w
; low word specifies which service
( {6 j' N& I( `6 Z) x (VWIN32_Int41Dispatch)6 o4 I0 C/ B( b, W8 X
call Kernel32!ORD_001 ; VxdCall
9 u$ ~6 Y" S7 u. X# E" s cmp ax, 0f386h ; magic number returned by system debuggers
" `& t2 j& Q3 W- _9 t jz SoftICE_detected
0 j. V$ T5 B' `# `0 F0 W- k
# v8 B9 E4 k9 E* H+ \5 H% jHere again, several ways to detect it:3 g7 R, u# \+ D
3 K; T; K0 |& p, V$ U
BPINT 41 if ax==4f$ v, v! o9 I z' P/ W0 G/ G
' { `9 E2 l& Z BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one" q) H! H: ^& R$ H* D
/ W1 s" R1 E; U* l6 F. O2 ~3 X& D
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A4 x$ @* O* x8 b Z' Q1 m! o
! C l2 @' S% b BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
* h2 a S6 T9 j6 e- B+ E& _- R$ |) Z) a, w: Y* `9 s: I
__________________________________________________________________________8 t6 |, v) x; i6 s
0 I; d* K; D% h' CMethod 138 t; g) A4 ^2 Q+ B( G
=========
1 O/ o* y, Y3 j5 u/ A( n/ g6 E0 I( H* s1 u* u3 j
Not a real method of detection, but a good way to know if SoftICE is
& Y3 F& @, g9 ^! m% E; W" Dinstalled on a computer and to locate its installation directory.
0 A( _5 i, M' Y6 Y- ]It is used by few softs which access the following registry keys (usually #2) :9 b2 |' `" l) L( c7 Z
& a, G# r+ e& j9 ?8 @+ M$ U- V. o" {-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
# i* g+ E! R: V4 g' Q. K' H) {# \\Uninstall\SoftICE
/ j- Q& j" X$ w! F1 @7 ^-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE( G. B+ j: c. X2 @, a) q
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 }& }* z% s6 U' Z. g6 p% N) F4 Z
\App Paths\Loader32.Exe
: c4 S3 u, ^$ K+ D( S2 t" R# i, X, n7 k" Z" b# k0 A, ~
+ T) c$ z. T1 U2 eNote that some nasty apps could then erase all files from SoftICE directory
! B, Y3 v' j5 h/ e7 b8 S(I faced that once :-(4 I% Y6 p5 y# c+ G' ]5 j4 R8 t: a
' H+ L1 J( {% s, e% A2 H" aUseful breakpoint to detect it:
+ { P( P. b. T# T4 H& J
: E: L' I' Z! Z BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
. ], O1 z/ L" v" O: p6 A8 N) J) C: }# I, ]
__________________________________________________________________________
2 V+ ?2 Z7 m1 a* T! W; ^0 I: q; P X7 e! \6 X6 [+ u
7 ]9 u/ q. D$ e( c9 X; G3 U/ i9 vMethod 14
; |4 R/ N! X7 |8 ]8 W=========1 i% y; j( P- F0 ]7 K; E; d9 ^+ r9 Y
, z4 I+ t1 o0 V# r/ `A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose1 r1 p/ Y) z' M' L, g
is to determines whether a debugger is running on your system (ring0 only).$ i$ q5 j; F, Q/ n" I" s/ {( ?
$ V% i, Q$ J, |8 G, N' B
VMMCall Test_Debug_Installed
: l! d) [3 ? X O; h( } je not_installed* Z9 l, ]4 ~8 f; U9 E, C9 ~
`! I$ [: A0 M% N3 ^! Q! E! `, u2 C+ ~
This service just checks a flag.8 O/ D6 l' N8 r! t A9 l* R
</PRE></TD></TR></TBODY></TABLE> |