<TABLE width=500>
6 r0 f4 a Q/ Z) z/ {/ L5 ?- n<TBODY>) O. w+ g$ `! ]+ t U
<TR>" R# ^# q1 ]6 ~' q* g2 s+ I
<TD><PRE>Method 01 % i q# g* G! L- @2 b. P+ \
=========
/ Y w9 M: W' s3 M0 [1 C7 g* `- h- U# q+ @( B0 r" P: z+ z' X7 ]- {
This method of detection of SoftICE (as well as the following one) is1 E$ t, u4 ^, S$ f) y
used by the majority of packers/encryptors found on Internet.
& c1 m6 S' A! Y% [- C- yIt seeks the signature of BoundsChecker in SoftICE
( Q6 H: d+ k6 E$ |
8 g/ ~: i. s Y* B j. f/ z, x! X% W mov ebp, 04243484Bh ; 'BCHK'+ |' F, {! B+ L$ ~2 m7 m
mov ax, 04h
7 B; B" D- M& c! A3 O int 3 5 p# w& R$ m4 ^! L* {+ c
cmp al,43 J+ j' k' ?. o
jnz SoftICE_Detected
& X5 e5 W" N" g- ]2 E0 ~3 f3 h/ j5 G% W j; Q% z
___________________________________________________________________________
; }( J( U! [& B4 p
3 e q' {' L5 S/ C* }4 XMethod 024 p0 R% _% p1 k+ b, I2 P) l5 D
=========
7 c) H7 c! _ K) s
* \+ g" L6 i: V2 W% B% UStill a method very much used (perhaps the most frequent one). It is used0 y! n% d* g5 J5 g
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
. J& x" [4 `8 @& yor execute SoftICE commands...
$ p0 u1 z- `. d$ [6 PIt is also used to crash SoftICE and to force it to execute any commands1 y5 c" M1 X+ P$ P
(HBOOT...) :-(( . c' D3 M8 w; d3 G$ q5 Q
9 g# A+ k( X, s2 c. p% R; y4 p/ w
Here is a quick description:
1 a: e" ]: q5 K. T7 t! x9 P-AX = 0910h (Display string in SIce windows)
( k/ T! {$ [! C6 j4 u-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
. e: x3 I7 B9 I( i-AX = 0912h (Get breakpoint infos)
/ A7 k$ f4 ?* a# Z) u-AX = 0913h (Set Sice breakpoints)/ ]4 u }+ Q: L1 m p
-AX = 0914h (Remove SIce breakoints)
7 B! C' S& {& j l# k$ z* y [. x" [( d9 d
Each time you'll meet this trick, you'll see:" G4 D) P @5 f n9 ]7 M2 g, S
-SI = 4647h
q) N5 K/ y3 z/ e- V( M-DI = 4A4Dh3 O( K0 ]5 }3 f& A7 W: G
Which are the 'magic values' used by SoftIce.1 s& [+ [# R5 F8 j6 i& N/ {
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.1 s$ U1 c: w- |, y: S
3 ]: O- f) p1 o$ R- f) p" P( IHere is one example from the file "Haspinst.exe" which is the dongle HASP
& q8 b* k+ @' `! AEnvelope utility use to protect DOS applications:0 ] Q3 |4 h& |7 K9 N1 {
- m+ p0 {2 C* Z1 H# X
7 h, A) p( \4 K" x: Y% i# T4C19:0095 MOV AX,0911 ; execute command. H9 [/ D$ j8 s% j* \! d! ^& q
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below)." u, g; }6 l* { Y E4 s) }2 S
4C19:009A MOV SI,4647 ; 1st magic value.4 F ^& N/ Y* W8 @! \
4C19:009D MOV DI,4A4D ; 2nd magic value.; _4 L. f" G5 X2 Q
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
8 @3 y1 E, i: I' N4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
: y [ F7 D ?) Q4 r& j, M- G8 g! m4C19:00A4 INC CX' @5 d9 F8 q* h/ k5 d: J
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute: a: i3 [# |0 e( ?+ A. o @
4C19:00A8 JB 0095 ; 6 different commands.8 i' X5 R! j0 {5 \* n8 e
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
1 E: g! J" I3 ~! |7 C& f4C19:00AD MOV BX,SP ; Good_Guy go ahead :)( C( F/ d( B+ l3 |0 t3 R" M) g
' l; A* P/ {, S% p9 L
The program will execute 6 different SIce commands located at ds:dx, which
9 H: ~- _& L' V6 y% E5 lare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
4 F$ n* L3 l. t+ m# Z/ y$ b2 H q/ R2 L4 n5 q% B4 n
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.8 \3 T9 k7 d; S8 t% S. F
___________________________________________________________________________
8 u$ J" T% r/ U6 ^ \. \( m! k6 F5 v+ B1 r
) N: j' A, {$ m0 \
Method 036 g$ O0 P5 v. O, Y
=========4 M8 _; Q B$ Y0 F
, B4 O) e1 E# d. ]' Z) p; i
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h% x. D' x/ s1 a: j, l: Y
(API Get entry point)
4 ~6 G) y2 @: ?4 o0 i 5 f2 W' O) W" B' Y
9 R9 D$ m9 Z" P( E9 O6 M( e xor di,di
$ N( @6 c) C! u mov es,di
0 n3 K6 ~0 o( r' F- ?! e. b$ c mov ax, 1684h 3 i7 L0 U" L" t
mov bx, 0202h ; VxD ID of winice
; e7 E: K: l8 ~: v3 o8 w int 2Fh) y( \- z4 [2 t: s! ]7 R
mov ax, es ; ES:DI -> VxD API entry point; q( `( _$ L4 Z8 L
add ax, di! ~) x" F' j% y0 E/ _/ }
test ax,ax
1 V. ], M E9 Z6 h; x/ _) I5 z7 \ jnz SoftICE_Detected' W/ w- n" }) N+ W- ^
$ ]2 b0 K( P; n y
___________________________________________________________________________
2 P: R L- R- I2 x9 I$ d
$ r3 E, y7 W/ f4 H7 O& eMethod 049 y- ^2 ~% b6 ^1 x: C7 ]) S) J
=========
, e- @$ f% `+ E3 z3 T. R$ m: J I' X
Method identical to the preceding one except that it seeks the ID of SoftICE
: F: b" _. D" X, XGFX VxD. y& F1 I s& v) L1 \# p
5 A1 b2 V+ S# q4 `5 n xor di,di
- n& h& j5 L+ J0 v! [ mov es,di
" q3 W+ i4 h' z% `3 t- E) x mov ax, 1684h 1 u+ E$ N% L5 w" ^; \) L! c
mov bx, 7a5Fh ; VxD ID of SIWVID
`( |3 ^* q4 V- o% \: @( [/ O int 2fh8 \4 \! ?1 [0 I/ L9 C ?
mov ax, es ; ES:DI -> VxD API entry point+ x0 _/ Y$ n. I( X t, p
add ax, di
1 Q3 M t* O. R1 N test ax,ax
% ^8 E, p8 x0 ~# {; ~ jnz SoftICE_Detected
. I+ T) l/ N% }" U7 ^- w/ w& H( l5 g8 U8 z1 i- q$ J
__________________________________________________________________________3 ~8 c% i* X( H( Z
* l! d- b4 Z8 l4 d
- ?) J4 ^! E7 N; W% GMethod 05- A! V$ s2 v5 {* F; A( V7 [
=========4 M2 a2 G+ F- N) V/ w& U1 x
y, U$ ~# b( x0 @
Method seeking the 'magic number' 0F386h returned (in ax) by all system. Y& _2 Z9 Z% L! A9 z' J* |
debugger. It calls the int 41h, function 4Fh.( F$ B3 L( v" ^# ]: D" F
There are several alternatives. 4 f e) o/ A: N- a" |
6 [7 t1 f- ]4 d W* }The following one is the simplest:
' m. k- P: I5 n6 k' V3 X: G: h' y6 K
& Z8 c+ y2 {, H6 u mov ax,4fh) b. Z& l* [$ A @5 L; X
int 41h1 ^% K. I# y- @8 X& n7 C4 \
cmp ax, 0F386- A, F5 m9 k1 w. `( b- x
jz SoftICE_detected9 M I4 n5 J' ]# p" \0 l
* Z* [+ P* ]: ~* @$ ^5 m: x9 Q
( C. m/ U# e* hNext method as well as the following one are 2 examples from Stone's - U/ a3 n4 Y* F7 R4 n& r
"stn-wid.zip" (www.cracking.net):! w; R7 |% l1 ]4 @5 ~4 g
( {" _& w2 d: i! c- R" ?+ H
mov bx, cs
v Z. M! U* k" Q$ D* b lea dx, int41handler24 h8 z2 B8 z4 b, P& {
xchg dx, es:[41h*4]+ @7 u+ f" m" R; [( k3 M/ J
xchg bx, es:[41h*4+2]
9 W/ V! Z* k2 i9 ?0 G; [: M mov ax,4fh
: u5 N. O- U$ b6 q* f6 S3 Z int 41h0 T1 C5 ]1 p6 U" Y0 {
xchg dx, es:[41h*4]8 v- T7 ^$ G6 L9 g1 Y! ?; L
xchg bx, es:[41h*4+2]0 N; H3 v9 `" C4 F0 a
cmp ax, 0f386h
: s- ]) i- M! ~, m D9 Z9 j3 Q+ f jz SoftICE_detected* f. I# a& C K" J' @6 Q' v6 b
3 z L" l: X N$ }; x! V, b
int41handler2 PROC. f( e% B7 [+ ^( Z" t/ f
iret
) Y. d& J0 @, s5 r, G: r& _int41handler2 ENDP! G# e- y+ D% C+ N3 E) \ k0 t& j
0 J$ h6 R# ~1 d
& W K* W# P1 b$ k: y( M
_________________________________________________________________________" ]1 O" G. v, u. L; ^
' h" Q. Q+ U G5 s7 O; B9 I& T
6 y+ t; d& x0 N D# IMethod 06: L' v2 }) S" [! l
=========
! _# ~+ H$ G) f# t% S
1 h3 u- `. j# v9 i+ [; [, S ^
7 p, \" ]2 b) e1 q5 [3 {2nd method similar to the preceding one but more difficult to detect:
$ S3 p9 Q# ]$ y. f" G
, D% g7 D0 X8 u4 c- l5 }4 g2 r- X+ y+ n
?% X! I5 `, Q$ z" aint41handler PROC, d- B4 x+ ^" m7 N) Z
mov cl,al
1 P% C8 z6 H8 |0 n5 } iret
1 ^3 e* C0 B7 ?8 {+ a# X2 C# sint41handler ENDP. }: f& @) c9 \1 i
# t0 Z2 G3 ?) s% U2 m
2 V' o- N- z* }0 s* X xor ax,ax9 H! a5 B' t0 x
mov es,ax
( J+ U9 ?1 C% Q* U0 `& \ mov bx, cs3 \1 o5 c/ Q! k) D5 W! ^6 h
lea dx, int41handler* j5 e# n0 [. x8 x8 p, P
xchg dx, es:[41h*4]7 ^6 ^# y, X# ^, u
xchg bx, es:[41h*4+2]% l$ N# j: g/ A5 {% S+ N$ x- q; _
in al, 40h4 O4 h( t" i K' `. B
xor cx,cx
! M8 _; p+ Q: |# ^5 w3 g& j int 41h
( \& O1 Z# v6 @/ d. r. l0 c xchg dx, es:[41h*4]
n+ B$ E# l; C* D xchg bx, es:[41h*4+2]
+ G& m- y3 a& s cmp cl,al7 H8 M! i# ~% Q6 B4 [! f
jnz SoftICE_detected
1 e% M9 F6 D' [7 Z0 Y+ n F" D
. U, u! \$ y& p0 {) L& I7 O# z2 @_________________________________________________________________________0 ]. C1 U& W8 p% ^ b8 [; c( L
# {4 m, s. I0 Z6 QMethod 07
# b) f* Q, n& l1 ~: ?, y! l=========! Y+ ?7 ]* d d$ Q" J! Q
, u; ?+ `3 e V# w; b' W' m0 _Method of detection of the WinICE handler in the int68h (V86)7 C; r; j W( t
2 A9 a; r J+ A1 m8 N mov ah,43h7 b3 z+ w7 P. L5 v6 |
int 68h: A0 r, B, o/ b( P. l
cmp ax,0F386h
: X- h9 ~' y( S, Y$ M jz SoftICE_Detected
# X. E, y2 q& c/ X. N! g5 J+ ` U* V0 V6 v& d I
! d+ W& x4 m, i% U2 {- y* @- i=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
; [4 k) E, u: ?. F; \3 h app like this:
! V$ D, Z8 v' h# f) ]5 _! g+ C7 x/ H% v" Z& f6 e1 ]: q* u
BPX exec_int if ax==683 I2 y% R3 T& k8 U' w4 T6 g
(function called is located at byte ptr [ebp+1Dh] and client eip is
/ f1 Z1 o. ]" P# N. K/ ^+ f located at [ebp+48h] for 32Bit apps)0 y: f' E9 f2 M; q
__________________________________________________________________________! O# X3 `5 m2 k; u
6 z! r8 v2 x7 p6 n- q2 }* b4 \' H5 ~0 p( z, R( s- P
Method 08
& w5 p7 U8 G$ Q. |1 R=========& _8 ^- B! ` i# b* x
: b6 Z* S: [' S6 `: @1 R
It is not a method of detection of SoftICE but a possibility to crash the
4 p: L" U! C3 d2 k+ L+ Esystem by intercepting int 01h and int 03h and redirecting them to another
/ d/ `; }7 I* l) }9 j$ w0 \routine.
6 i6 [2 m% V: T4 IIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points6 U9 H; M- F" j2 a8 k! Y! [+ P
to the new routine to execute (hangs computer...)/ a4 ]; K+ O/ Y5 a1 K! H7 ~
9 [, E4 Y# ~- q% E mov ah, 25h' ?; s1 h; A" `$ _4 }. n/ h; m
mov al, Int_Number (01h or 03h)) ]1 e, F* W! B
mov dx, offset New_Int_Routine
& F1 T8 B5 Y; M8 }7 z int 21h3 U4 ?; w5 r% [; U6 s. Z( U5 ^
) Z1 \ H/ L' S5 Q) b
__________________________________________________________________________
& ~2 f0 C. k5 i7 }& w: ]8 Q! c5 V* q$ D
Method 09
$ K5 O L0 n& [=========2 i: x( |. Z9 {9 m
0 i5 Q) z3 A$ E0 y$ s' e+ \
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only; p G( N& o4 q* L: w
performed in ring0 (VxD or a ring3 app using the VxdCall).# I3 T7 y: l6 D9 |$ s- L! ] R
The Get_DDB service is used to determine whether or not a VxD is installed
( `5 _: x3 g& D4 N' ^, Dfor the specified device and returns a Device Description Block (in ecx) for
* ?' g i8 v) i& D! ^that device if it is installed.* y$ h( U7 k/ B
+ Z" E% O4 L% k* f, K* V1 @ Z
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID+ E# V. n/ T8 U$ a) w% |
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
; ]1 y% E3 j$ t6 J- F: f3 h VMMCall Get_DDB
* s, N* A8 y- ~) y% k3 Q* ]: M. m mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
0 I' c, h. f0 S9 `# h
/ k0 S2 G( p' J8 S) w: sNote as well that you can easily detect this method with SoftICE:- o' K9 a. Z5 Y8 R$ _
bpx Get_DDB if ax==0202 || ax==7a5fh
1 O' k! O6 A' H" Y/ Q& ?; L* d& R6 U' F1 R/ }
__________________________________________________________________________
; H0 A+ j( k3 s5 S
+ B, B. \2 [8 W) }9 P% iMethod 10
" f) p2 ?2 Y5 W" j( {=========
3 {0 P# G/ R" t3 O$ q: y& Q
& |& |; E: l" V) ?=>Disable or clear breakpoints before using this feature. DO NOT trace with5 a. b$ l2 o% I1 j2 W f$ ^4 P8 y
SoftICE while the option is enable!!: S3 y0 h5 D8 L7 u) b; Q
' V" X$ P6 I" M9 s& t
This trick is very efficient:
1 J1 t) `6 d* M0 nby checking the Debug Registers, you can detect if SoftICE is loaded- a* z+ P$ m9 a/ U6 R) V# g. z
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if% R- M s9 e" d8 C, P0 f
there are some memory breakpoints set (dr0 to dr3) simply by reading their- g; L" H/ e/ G0 T! U& |/ G6 ~+ a
value (in ring0 only). Values can be manipulated and or changed as well
/ t) X; b1 F# ~0 B(clearing BPMs for instance)
1 k- n2 O& F d# D
4 A# D5 ?% b$ z7 y__________________________________________________________________________) ^' S- D" [3 J% |
" y. y: e! U# E+ b' z8 rMethod 11# Z) N1 Z2 R( o6 t
=========( N- W' N* G. D4 A2 J
9 z$ \1 O+ ^7 f; _7 `' q$ k
This method is most known as 'MeltICE' because it has been freely distributed* ^+ s/ Q5 H7 G9 X
via www.winfiles.com. However it was first used by NuMega people to allow% N) a& B( [: R# {9 q5 W) v x
Symbol Loader to check if SoftICE was active or not (the code is located
: r. r& `9 n( ninside nmtrans.dll).* y: E+ S$ m; w" n6 P- V
2 ^! v5 ~7 m, U4 f; B& a3 NThe way it works is very simple:: c: H# ?5 D% u3 ?$ H
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for5 q @! k# k$ ~# x, F* \+ X' y
WinNT) with the CreateFileA API.
/ g' s9 X! x3 `7 t% T6 m
7 q/ o: j+ }9 b4 e' k% GHere is a sample (checking for 'SICE'):
4 T) A i6 q. O& s. g! x5 H/ G& A9 e4 G: i6 U8 e% z" }' T1 X7 E
BOOL IsSoftIce95Loaded()8 H3 M( r5 f4 Y( x' b* e" d9 z
{- b* s$ i" q+ b8 M5 {
HANDLE hFile; G4 `/ b# d j$ @! ~0 q
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,! L2 m; w. [/ Z3 V; ]' s5 j
FILE_SHARE_READ | FILE_SHARE_WRITE,, i1 S; Y, e1 ]' _3 J
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
, {' x4 ^0 H' f6 b4 ] if( hFile != INVALID_HANDLE_VALUE )9 `: @7 V% O/ S( j0 D5 k
{
; I1 [3 ]- R" `7 w2 N- {. I8 A# D CloseHandle(hFile);. y! Q$ }( C! I6 p
return TRUE;0 Z) n4 u1 b3 J/ Q! Q
}. I/ I7 X- Y7 Q u+ e: Z
return FALSE;
- H" m7 y5 p& N}$ V- @( s& l7 G
' q$ X6 i, W' r+ p) M' h6 DAlthough this trick calls the CreateFileA function, don't even expect to be# Q6 {' V% i H) @: M5 H+ G f
able to intercept it by installing a IFS hook: it will not work, no way!, @+ q- F- g2 `, q ]
In fact, after the call to CreateFileA it will get through VWIN32 0x001F! ]6 o+ ?5 V' s" k5 b3 `
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)+ k4 \. s& ~6 J4 }1 ]$ H
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
4 |1 z! o# ^. a: kfield.# k6 Q+ |: d7 s& G3 C* F B
In fact, its purpose is not to load/unload VxDs but only to send a 9 T" u. e& j3 H" I6 A6 R& R
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)' l, c1 X0 e3 B, y0 K# P
to the VxD Control_Dispatch proc (how the hell a shareware soft could try( L1 v2 Y( h/ e N; f8 a% \* a
to load/unload a non-dynamically loadable driver such as SoftICE ;-).0 C1 |" z: Q- E4 D0 }
If the VxD is loaded, it will always clear eax and the Carry flag to allow
6 B4 T8 V: p' D- e0 z1 fits handle to be opened and then, will be detected.
+ }& f' Q% k: _ j2 ?" |You can check that simply by hooking Winice.exe control proc entry point5 M, z0 _5 u* e2 g
while running MeltICE.
5 P$ b ~! O' f8 l1 P3 ^( G
. X8 {# [# G }6 D& Q9 G$ a" f7 j
$ u, C+ S- ]! e4 H 00401067: push 00402025 ; \\.\SICE
' d" V7 V$ a; a$ L 0040106C: call CreateFileA H* C- R3 `5 ]9 p1 P. e( o% ~
00401071: cmp eax,-001. j% K6 S, j$ C f/ T$ W' R; x
00401074: je 00401091
% O/ j' F" R: Z9 {8 S
1 q/ H T# u$ r& S2 {" t
# |' e9 F4 P9 u! UThere could be hundreds of BPX you could use to detect this trick.
* H' l. U8 R$ R: O- h-The most classical one is: \9 A" O Y$ H0 `5 d
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||3 H$ K- h0 V* e. H5 d' a+ |6 k8 |
*(esp->4+4)=='NTIC'
' |9 Y3 k0 a6 j$ i5 K
: M0 P! s- B6 [8 s! o-The most exotic ones (could be very slooooow :-(
% {% H6 @% w" f* Z; m BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') e0 R3 ^0 E# L
;will break 3 times :-(7 q4 w& E0 ?; R, }+ n0 F0 e% S
) c, l O: x: c/ r% ^8 ^8 J+ C-or (a bit) faster: ' V4 L. [7 P( I' V0 ~( g
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
2 Q6 Z2 f% ]* A; J+ G9 [6 h% o7 F# V9 g) M* y7 v+ }# @. a
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
: v' @- C' b7 ?7 y$ C. E ;will break 3 times :-(
$ Q( W1 ^+ M d3 i [/ S3 O- T/ J h
" s% u; l# ?1 Q% s7 }* T- t-Much faster:. v% C7 a, x3 V
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
+ z$ i( B, E4 ^& _
3 T1 Q# I8 ~! a7 H& _! L9 F. o8 UNote also that some programs (like AZPR3.00) use de old 16-bit _lopen- V2 w. }+ Q" B/ \. N
function to do the same job:+ Q: k& `$ o$ H* w
+ q' b$ R8 u9 t$ P# K' {
push 00 ; OF_READ0 l; C5 [. c2 h
mov eax,[00656634] ; '\\.\SICE',0( q# T- e9 x( Z5 \ e/ l
push eax
* ~0 d1 k5 t2 @0 | call KERNEL32!_lopen
! I5 V# G8 P6 _ inc eax8 A }; j' }5 [: y" o0 r. i; H
jnz 00650589 ; detected2 `2 V9 p! O" S$ Q) p4 j' L
push 00 ; OF_READ
4 \0 h: u5 E) }& o$ k+ U mov eax,[00656638] ; '\\.\SICE'& j {2 ?+ K2 n* z$ j( V
push eax
$ ]0 }" X8 j+ x! l; i/ _$ i call KERNEL32!_lopen
$ q6 Z/ m3 v5 v( `8 Y inc eax
/ C" K! _7 G/ [5 U+ l( v4 a jz 006505ae ; not detected
$ f8 a: U* }' g, @: l* O. z8 ?3 U
- |+ w# H% e% ?# \% Y& `
# v1 k2 b: X p& d__________________________________________________________________________
8 |- g6 \) u3 v: m/ Y$ B$ u, j+ O
" o& U9 S# b5 c9 f4 y VMethod 12+ R2 H2 J- E* y K% k
=========
H8 d! c" v! \' Q' E/ Z% w0 ~# O1 f J3 h0 \7 z
This trick is similar to int41h/4fh Debugger installation check (code 05# b5 H5 T& J% q
& 06) but very limited because it's only available for Win95/98 (not NT)
' r' F8 g4 U: O9 N, h4 ]2 Qas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
# O9 g1 q3 V+ m' `6 i* d
4 y% e( g& X8 L6 o! t! Z" V7 e% N push 0000004fh ; function 4fh9 T( t" o& x- c: U! o, w# }
push 002a002ah ; high word specifies which VxD (VWIN32)
5 r+ F! M; A9 K3 X+ W! F# m- I3 h# N8 ^ ; low word specifies which service( P3 m( e. A. m& u' f! l9 A
(VWIN32_Int41Dispatch)
' p9 B3 A. z% [, k* S call Kernel32!ORD_001 ; VxdCall
6 C( I6 t( Y, G* r& |% ~2 W cmp ax, 0f386h ; magic number returned by system debuggers" {& a( Q% N. i. ]- u6 V
jz SoftICE_detected( x0 E4 q5 z% T2 ]$ Z
1 ^4 a2 ~' T9 j4 y. f$ }8 IHere again, several ways to detect it:
; D( `' t) w' U+ m0 d: T# ]0 c* y3 B4 H4 Z7 @/ b, s* O3 I/ }
BPINT 41 if ax==4f
# d4 A1 s* d/ d; T" k( E9 @0 ~1 K9 T$ I2 U4 m
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one1 f3 [# h, x* q8 r( a
" {2 `7 C8 ?' G" Z/ N: a
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
; ^. T2 P' t% |' _/ f7 j
+ \6 f# f4 R1 L3 [ BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!6 B w2 P5 s- [; ^6 l7 L
, z* o1 T5 F. H4 C' F
__________________________________________________________________________
/ P% p; ^( `( l1 t- _1 i' E! d U; G, _3 G1 w
Method 13# v5 d. W, Z) o7 o: H2 K" T+ c
=========/ x# e/ H' |+ U( \
& w# l- t( @8 ~9 Y6 a4 S
Not a real method of detection, but a good way to know if SoftICE is
3 J( T# Y: ^( s6 ~: O; M3 w! {- E; [4 Xinstalled on a computer and to locate its installation directory." }) t0 j6 d2 I' {! E( I
It is used by few softs which access the following registry keys (usually #2) :
2 u4 {4 h* S! t+ ]! ^
" K {: ~* t7 V1 A( `$ \-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
( M1 C9 [$ Z; e\Uninstall\SoftICE
0 ?5 |& i: w# _/ ^5 M k3 g-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
6 j" ]5 ~) f! I9 i-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 D# E8 H2 I' `2 S' Z/ q
\App Paths\Loader32.Exe
( s. h! B* r4 o+ O7 }: x/ Y
: q, \) i! S! U& r' }! |3 e2 G* m4 V
Note that some nasty apps could then erase all files from SoftICE directory
K* @7 R' w8 V, o! ~* M8 D8 I+ `- A(I faced that once :-(, ^2 N) d( b; Z( r w: T4 u+ I
* L5 T% a5 ]% v
Useful breakpoint to detect it:: c/ k7 ?- Z$ i2 e1 C9 j; [
$ `7 A& X. w0 p, S! t% G% U9 j" Q BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'5 r" {' Y- `5 V( s( r
, D* ^( h% _: e__________________________________________________________________________
! \) k+ u* S0 C; D3 _1 y' }
# R& G/ C- r% h7 y& i; ?
) C/ B8 [; n! ]Method 14
( v8 ?/ x; u5 J$ H7 J$ w=========
* U$ R+ J, G( Q+ d( v }. C6 Y. \
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
8 D$ E% c! V4 V& q/ wis to determines whether a debugger is running on your system (ring0 only).
$ _4 b" v! Z$ S6 j; W- e1 e3 e# K9 G8 @* m- G
VMMCall Test_Debug_Installed
3 R, F3 w, c0 D- u je not_installed
6 h. h$ b, @) W3 j; m$ ]9 |7 A4 s! A; L$ d, u
This service just checks a flag.3 f n$ _1 R$ Q! }0 A8 S9 J$ [
</PRE></TD></TR></TBODY></TABLE> |