<TABLE width=500>0 ]/ d9 ^1 m2 O0 `
<TBODY>
1 X/ c! a2 t, w- \% `. q8 m4 r( `<TR>8 W# t5 Z6 E1 l
<TD><PRE>Method 01 1 k+ Z/ g1 |: _! X1 g. \
=========7 D7 C# s) q9 N, ?2 j
, m- }; D% |! Y
This method of detection of SoftICE (as well as the following one) is
8 D6 N6 a8 @9 v5 L6 e% aused by the majority of packers/encryptors found on Internet.
8 x6 i" ]8 @9 H: c. CIt seeks the signature of BoundsChecker in SoftICE
6 H7 x5 d0 P, i! }9 }9 y$ ?
( w3 J6 s0 r) `& ?6 m$ X mov ebp, 04243484Bh ; 'BCHK'
/ O% l) B/ b; r: N* Y5 J. { mov ax, 04h) I& \/ R( t9 O5 [2 u+ Y1 j# C
int 3
$ P- S2 |; r0 R e' ~ cmp al,4) ?% L; q$ `) P6 b+ `+ h7 k7 I& w
jnz SoftICE_Detected
' M8 Z5 _& k+ u3 y# F% O6 x
0 U+ w( `8 q v___________________________________________________________________________
& _1 G7 O I6 f$ I" A) t l" Q. a- J* y7 S$ v! i1 L' R# `5 _0 O: d
Method 02
$ z6 D# x( n0 ?6 @: }' E$ w=========
" q/ x, t4 O6 t3 w
4 M$ a) w+ i2 ]7 ~Still a method very much used (perhaps the most frequent one). It is used7 S9 O/ B5 ~' ?$ Y$ h
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
; q0 t! P! h' d* \ g3 N' Dor execute SoftICE commands..., i( |8 C6 V7 ~, D. v0 p4 t
It is also used to crash SoftICE and to force it to execute any commands1 p) N( t5 f1 {) t
(HBOOT...) :-((
0 U/ j# V3 [2 S0 q! G- ^2 ~
1 r: |4 j' t" T, _, T% FHere is a quick description:
9 O2 i% Z8 z& V7 ]$ W-AX = 0910h (Display string in SIce windows)
0 ~/ D7 l1 Z. ~ N: [$ M9 w! w-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)+ Y! N+ @/ Q: A
-AX = 0912h (Get breakpoint infos): Y; F" H9 d5 [( s* x( \6 o
-AX = 0913h (Set Sice breakpoints)
& v3 E4 G, f$ I1 L3 {3 e-AX = 0914h (Remove SIce breakoints)# A) c! ~, q( F4 `, B: b5 ]
# n% ?$ h4 d% P5 ]4 D
Each time you'll meet this trick, you'll see:
- ^+ g/ z, c* K' j4 K" ]-SI = 4647h
8 a/ x% g: g7 l8 B: r$ h' Y& m-DI = 4A4Dh/ Q0 {: h5 q2 b' k
Which are the 'magic values' used by SoftIce.+ a+ a# C, m$ A
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
: C, Z( p9 w. G" N4 p" ~2 G0 y( c5 ^0 r4 b, Z C0 j
Here is one example from the file "Haspinst.exe" which is the dongle HASP
2 s" U/ D6 Z: \8 R* t6 X$ \! _3 ` aEnvelope utility use to protect DOS applications:$ N8 N; q* `2 s) r
* ~# E) x9 \$ i+ J. g" B
8 C5 ?( T9 y# ?1 [& b4C19:0095 MOV AX,0911 ; execute command.. e' J) t. ^2 P5 c
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
8 F* p( u3 T( v7 x7 a* v4C19:009A MOV SI,4647 ; 1st magic value.
. Y( W; @; t# u. \8 F( {( e4C19:009D MOV DI,4A4D ; 2nd magic value.* E; v F# t/ ]4 Z
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
[( O# E0 h6 a5 X& r8 t. z& p4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
. h/ L$ T5 l+ Q* _# F: i4C19:00A4 INC CX
& ]7 ]3 W# x! B+ D4 F2 [+ y. |, X4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
4 E N0 [' y( l7 Q4C19:00A8 JB 0095 ; 6 different commands.7 E# a, t; _; g5 @7 T; g
4C19:00AA JMP 0002 ; Bad_Guy jmp back." O) e+ w4 U2 @' |/ f# \ V) w
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
( ], u8 E# a: H/ N
. p7 x; D6 ?, d3 G5 eThe program will execute 6 different SIce commands located at ds:dx, which
9 V& b1 M0 P9 d9 [/ tare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
@1 q$ O! R% e6 \$ j7 N/ q' ?; A0 C5 u. Z: m& t: O- W- x
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.0 T- m) R: M6 j
___________________________________________________________________________
" @4 ]; }% k9 y. l5 u" R! G+ U& Z3 t+ V' d5 Y$ d) E8 w
3 f1 S/ f( r/ L3 H( m& n, x
Method 03
- Y7 Q; K. A7 \. Y, \) k" g0 Y2 @=========
1 d) h3 o8 ^' d/ O' p X1 U1 @. r" R$ n6 n2 }
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h: ]: y7 A3 ^$ M9 p2 H% U
(API Get entry point)( @: ?3 s! R4 `: x
0 }5 `3 {* i, H4 u7 Q
1 f- T s0 D6 Z8 F0 g
xor di,di
% {/ x: g7 w9 g( ^9 B( `$ ? mov es,di" X" L3 ?2 a, Q8 h) r* z2 }
mov ax, 1684h , m4 O1 M3 n0 J2 p4 @" n
mov bx, 0202h ; VxD ID of winice, G. K& {* E, z2 d6 S' i
int 2Fh
6 x$ M" p7 a6 h mov ax, es ; ES:DI -> VxD API entry point6 T% o1 u' J0 e( H; o9 M
add ax, di
; H! n0 H% x# t7 J* o, p( x test ax,ax
7 g! v M" r d9 l, C. n; M& J: | jnz SoftICE_Detected9 j2 I! U1 X1 \' q; _
. M. V- i- V- {4 X* l8 T$ {* `- y
___________________________________________________________________________
- s9 Z8 P2 K! y8 a5 M8 K, g
1 z; C- T) C3 e/ a5 O" c3 I8 OMethod 041 V' \- K2 V$ x( g
=========5 X; a4 z+ \2 t1 Z5 {# w0 G
& O z9 |( j3 k5 e# H, q% l
Method identical to the preceding one except that it seeks the ID of SoftICE
; s7 {5 g: M% v$ e' X! ]/ W) Q. O, eGFX VxD.* ^! s* Z* L8 k3 L6 E& f
% X9 K7 K# @6 |* [9 [ xor di,di% B$ O* E3 _8 A; ^! F
mov es,di
& C# j6 }; ]3 I2 U- J0 ~ mov ax, 1684h & G( q) Y# B: ]* H
mov bx, 7a5Fh ; VxD ID of SIWVID3 S2 C4 u; s/ e6 y* g' U3 `
int 2fh
8 ^+ j1 b. D& o3 ^8 v& I% m+ ? mov ax, es ; ES:DI -> VxD API entry point" q4 l, ]0 C! t& @4 x
add ax, di3 v- i: t; i& x
test ax,ax
9 C. v F/ y! N5 Z% ] jnz SoftICE_Detected
: w& ^9 O; }+ Z3 e; r. X9 Q& Y1 E/ ?' F. J/ D* J4 k
__________________________________________________________________________
) ?6 H# A5 a# m4 H _$ k$ b# E& k2 p7 t( r3 t* v9 D
# m2 ?* E1 z- I( p- J% p; RMethod 05
" ^0 ]6 p1 V( ?& r5 k, V. U! Y=========' T. _0 G" t0 s; g
+ T. j9 Q( u! s1 K2 z3 M2 Y: W( p) VMethod seeking the 'magic number' 0F386h returned (in ax) by all system) `# j4 g9 _: F. r' Z, R! M% t6 A
debugger. It calls the int 41h, function 4Fh.
( Q0 o Q/ ]! {' I( [; C* MThere are several alternatives.
X' W- A# U0 j* J
$ L5 G! i+ u3 T# [5 _6 aThe following one is the simplest:
6 ]" m5 F+ ~- u. N9 x: ~
" q6 T4 y/ c* J mov ax,4fh
# p$ |' |. G* L+ { int 41h9 C4 i/ f% q8 W1 d1 Z Z
cmp ax, 0F386
; O2 A3 C- H$ |. D8 F% W5 K0 C jz SoftICE_detected) z5 ~5 ^) @$ w9 O3 G6 d. Y2 X
# ^6 x# |# |$ p3 `/ T
9 H. e4 {" w+ K0 r! u/ @Next method as well as the following one are 2 examples from Stone's + H2 Q0 i0 ?1 [ N: x( ^0 N
"stn-wid.zip" (www.cracking.net):
- I+ u8 a, \: [1 I& S" D$ r+ A: K7 e: H1 s' o8 i
mov bx, cs: L4 r" O6 P3 s& v2 h
lea dx, int41handler2- J4 w8 T7 E" m1 E: ]
xchg dx, es:[41h*4]" J: S8 H ]* T4 p
xchg bx, es:[41h*4+2]5 k2 F' T- {7 E
mov ax,4fh! Y9 m: ^! _: n2 `
int 41h* x" p- C$ d% o& R
xchg dx, es:[41h*4]
3 H0 U% j/ G: n; ?; u. h3 J0 x xchg bx, es:[41h*4+2]
' Y1 h% [& x; I* w5 f9 L cmp ax, 0f386h
, U* T$ r- m& W" ]/ ^ jz SoftICE_detected
$ ^& t4 R7 ^9 r3 l# C9 K! b6 b1 `2 \2 m. n5 P
int41handler2 PROC4 T7 O4 y! o' Y3 E+ f$ n
iret g' q' j$ O1 M' ?2 m) j' A- f
int41handler2 ENDP( Y$ I. }, T! p( v
" {% s& R" ^, _7 J4 |5 X! g- E8 w
, X" d, f" y5 `; i5 x& U V! F I_________________________________________________________________________, y N! C* l/ g: m3 S# R
! P. k3 h1 ]$ X4 D6 N& d1 {2 P$ z' R' Y1 D6 |
Method 06# R6 R; `' Y8 Y% n+ r g
=========
- l" W c- @. o& }+ J* I& ^) q! d! ^3 x$ Q
7 L, V+ U+ }6 U& F$ z
2nd method similar to the preceding one but more difficult to detect:( K3 x, g# J. s: A& v! k; [
* B; m o9 l2 M8 ]+ G) D
/ a% }2 Y! h# K7 g- w bint41handler PROC1 ]0 K! `2 H4 h7 O% J$ J% m9 B9 g
mov cl,al
& k+ P) c% n+ w8 p5 K* S$ ^ iret
% {# F) ^# K* d! O5 u/ [3 xint41handler ENDP% j* j5 |4 h- G. A, P" l
- V7 T o* i$ a! w0 P) H R7 m6 D5 X$ h/ W
xor ax,ax
8 H5 Z$ f( s8 i! O" P6 F8 V mov es,ax; j, Y, @$ ], P/ t+ p" `# j$ e# Z
mov bx, cs1 i1 @; M4 r" j$ }, n4 Q
lea dx, int41handler
$ B0 Q% V6 i j7 p$ N0 j: p xchg dx, es:[41h*4]
; J! A, o& m4 z/ o1 ^7 T [ xchg bx, es:[41h*4+2]
/ u% `+ z; X* J" A& j: S in al, 40h
+ G# E4 f3 b# q9 h xor cx,cx! h4 V9 v# b2 D; J8 N( X a( w
int 41h3 q9 {/ C0 x$ j& l& w: t
xchg dx, es:[41h*4]
: ]+ v) K" i: z. E3 M) ] xchg bx, es:[41h*4+2]
& G X2 D( k4 c( K cmp cl,al; i. k, n1 o( o9 C' X, d
jnz SoftICE_detected
4 G; M6 |9 E& I1 K
- \ L o7 A9 R9 Z+ w' [_________________________________________________________________________
# c5 c4 V+ s5 h) x- J
2 Z3 {5 |6 }, fMethod 07" j x. e- p' ]: r5 L
=========
5 C" c( n( e5 |% A8 `' ]5 f) j' n/ @ v* r$ Z) t9 P( q1 k8 k
Method of detection of the WinICE handler in the int68h (V86)1 r1 Z3 r; @' e, x- l* U7 ` K
) E4 O$ z/ D4 L0 C/ e% E& v
mov ah,43h
! ?1 B* z8 f9 @ int 68h
8 q7 f0 U5 K) h+ ? cmp ax,0F386h& v8 K; _3 H& ^7 ]
jz SoftICE_Detected
- C% s0 l/ X4 p0 ]* q( H! J5 i- L
) K, d, E" q. F2 `" R N7 i3 R5 N7 z5 x' @" }+ c7 a1 |
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit5 u6 f/ W8 i9 S7 J0 L N
app like this:, T! f; A$ {2 b( k6 z
+ y3 E! O5 r7 b3 x! J! G5 R; [( K; [ ~ BPX exec_int if ax==68
. y# \) h" u% M! l (function called is located at byte ptr [ebp+1Dh] and client eip is
. Q I) K9 l- D1 ]! J5 A2 P$ W located at [ebp+48h] for 32Bit apps)0 R0 b: e p. P
__________________________________________________________________________
0 I2 c' W: J$ V( P- v' I- C9 I: f: F; e. Z: s* ~$ ?" ^# Y
/ O; L# N7 D5 e+ E* m! IMethod 08
- J+ O7 I. Z0 ^& h=========
; u; n, P4 m" }% q$ L# d3 o* j; l
It is not a method of detection of SoftICE but a possibility to crash the
% D. o8 I, H) Y7 Y, Q) H0 f; Rsystem by intercepting int 01h and int 03h and redirecting them to another; s6 _( V# Z8 P/ P. r8 z. s5 s
routine." ?3 G/ y T( L3 q3 i
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
; e3 l3 W3 L n5 V; ?to the new routine to execute (hangs computer...)! e1 Q r" g* T# Q
- R: [( o2 R) E1 G; D2 Q mov ah, 25h
# n$ Z5 o* h: q* L, w mov al, Int_Number (01h or 03h)
; t; ] F; a0 d x+ L mov dx, offset New_Int_Routine0 ]$ a1 T6 D, n- q8 H* z
int 21h
9 b4 F4 k& X. s; I. o- y+ y& I: l3 _6 u# T* X
__________________________________________________________________________
6 [+ P* n0 X7 q% H& S2 t) N% X2 I
: j" [ R) L- q6 `/ M0 G; vMethod 09
4 k# M- R0 z* C/ [& B# S=========$ T+ f7 C/ h1 I+ A
1 V3 q* r9 n/ |# i! U
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
. ]. `- a/ P ^, y2 k& h. Rperformed in ring0 (VxD or a ring3 app using the VxdCall).) s+ K1 x' u; O% _) j
The Get_DDB service is used to determine whether or not a VxD is installed
' s9 ~5 L" O# M* I* jfor the specified device and returns a Device Description Block (in ecx) for" Z- F2 M8 J9 P% v" c6 L
that device if it is installed.
6 m A. \; {0 I+ C* z" t
2 l8 i' S8 v- d" ^( D mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
8 Y2 A( @; C2 {- _( | mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
8 T4 U; T7 D: u& x2 w& l9 m VMMCall Get_DDB( J1 v' `; A! ?. G
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
' h* Y1 h }* {8 b: q( s' f0 C7 f
( C7 n4 Z# p4 |: yNote as well that you can easily detect this method with SoftICE:
2 O4 i$ A3 C: N( | bpx Get_DDB if ax==0202 || ax==7a5fh
$ r6 @8 k! w$ y
7 x, q8 f, v9 D# h__________________________________________________________________________% X1 x9 n( G+ O3 H( |$ c6 m; Z; d
: Z$ X8 V. M: w/ M% J& E" mMethod 10
9 P* P1 E! O, J% Z2 j+ k( p4 I=========4 W2 G. k( w3 G, b/ s
: u( |' o! a3 p* b=>Disable or clear breakpoints before using this feature. DO NOT trace with
. u7 N( i7 {, [ SoftICE while the option is enable!!
) f! f" b8 c) v. V
% y8 a( | {3 ~5 hThis trick is very efficient:
" a% B4 A* M5 l* Cby checking the Debug Registers, you can detect if SoftICE is loaded. h2 e* \3 h8 i- d0 Y2 F5 V B4 m
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
; H; L* H3 p' l# b* {! S& Athere are some memory breakpoints set (dr0 to dr3) simply by reading their
( z% C' e u5 s& S# ^0 Kvalue (in ring0 only). Values can be manipulated and or changed as well, [6 G$ V0 ^( s
(clearing BPMs for instance)) K- o b; E( y4 ^
& E; K( t* l2 I- h+ o) w__________________________________________________________________________9 n6 x6 U: b' m
. @! V$ H0 V! f! `. Q4 I
Method 11
8 }" M8 m+ v% x% r=========
# J" G7 m; Y' i5 y+ e; N8 \; p1 x1 U- a# F( H- O! [8 \0 H- b
This method is most known as 'MeltICE' because it has been freely distributed
& t2 m2 y( ?; p& U+ ]( H: gvia www.winfiles.com. However it was first used by NuMega people to allow
: W5 H% I, [5 E% Y: wSymbol Loader to check if SoftICE was active or not (the code is located
( ~! Y6 V& X- R( z* K3 a% o6 _0 Minside nmtrans.dll).
) U8 a# T% Y1 d7 g2 j
& Y+ x: [. j9 b* I* QThe way it works is very simple:$ ^, f e0 y; X E8 A& E* A
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for* F; `; s' t* i. |% d
WinNT) with the CreateFileA API.8 a' n4 i! J, j6 G2 b# F
' f: t' T6 A: [7 K
Here is a sample (checking for 'SICE'):
! V( _: `3 n3 q$ \2 W: s0 B+ F
! x% H G" `2 k4 J/ z" E# s- JBOOL IsSoftIce95Loaded(); _9 h4 J9 F8 |0 g! p7 s
{$ X8 L5 ?9 a7 f% l9 n0 z0 r r' V
HANDLE hFile;
! s; p! K; i1 e' @4 q! I hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
; |$ Z# b: O* ? ^) s: n FILE_SHARE_READ | FILE_SHARE_WRITE,
; Q! C8 d& `) Z$ S6 d! p NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
$ I2 I9 ^8 F0 P& y7 W if( hFile != INVALID_HANDLE_VALUE )
0 r% Q" l) u5 c) P! h {
: O1 _( m7 _, ]9 T# x( f- k; r CloseHandle(hFile);2 f) |* \' C: W
return TRUE;
2 d+ e& n3 E5 @3 p' P, U+ K, ` }: w6 ?) j$ p8 a$ J3 E
return FALSE;& H/ A7 W+ ?! y6 k$ z9 `
}2 o: s- @7 h h: |; j2 q
2 Q, ]7 D/ D: |
Although this trick calls the CreateFileA function, don't even expect to be
! o. u+ i: h* R# |* Q, qable to intercept it by installing a IFS hook: it will not work, no way!1 M4 L% u0 }& h6 I
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
! j% S8 ` c! r7 y' uservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)6 W) b: f4 m0 E( c
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
* T& d& \# t$ y- S. Tfield.
; a2 p0 }* K2 c( {5 N6 cIn fact, its purpose is not to load/unload VxDs but only to send a
/ l D7 O2 Y8 \2 p, iW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE) c. M0 V% I+ M8 i# G
to the VxD Control_Dispatch proc (how the hell a shareware soft could try% H2 ~; H6 i/ @# P! j2 U! r# Y1 A# r6 v1 e
to load/unload a non-dynamically loadable driver such as SoftICE ;-).3 F5 I3 W. x7 u* m# G; U$ t
If the VxD is loaded, it will always clear eax and the Carry flag to allow
+ ~- s4 K, _3 x; s" N6 t+ f% ]its handle to be opened and then, will be detected.. A3 o4 Z- F& s/ ]7 Y; T; W" |
You can check that simply by hooking Winice.exe control proc entry point
3 k. S! B( z/ D: ?: ^while running MeltICE.9 ]: o- H2 ^) O2 b# ~" v8 R
9 P6 g' m& o4 X( b' F
1 [% u/ m8 u. g% g 00401067: push 00402025 ; \\.\SICE
" f" l0 U8 p8 C- b/ ? 0040106C: call CreateFileA9 Y2 `, Q* p* A
00401071: cmp eax,-001& L3 k$ A+ F8 \: M+ ]8 _6 w
00401074: je 004010915 g0 U1 y$ ^) O% P
+ ]) t Z, D$ ]6 p% ?
. }1 M8 `2 j: J1 U
There could be hundreds of BPX you could use to detect this trick.7 z+ S* B& k7 F/ J
-The most classical one is:
/ ~' @) B- I' P S3 i% ]4 L BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||7 H+ h. Q( [# \
*(esp->4+4)=='NTIC'
' e$ v6 F' @2 h3 l" r1 T8 {3 T3 b/ C! A9 @
-The most exotic ones (could be very slooooow :-(
" z* S/ p1 [, f; Y5 v BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
+ O$ N; S. l- Q9 r2 Z& i/ k5 h ;will break 3 times :-($ b7 {: s+ U4 {$ }2 G; _- U
# N7 \: v5 v* v; q% ~3 H ^-or (a bit) faster: - M, a& L3 T5 v/ n9 t& A% U
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
4 u: @6 U4 W) Z2 k1 k
+ q/ }' F0 J o! M) a' z BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
# y2 X9 I4 w) V3 B# s7 U+ x ;will break 3 times :-(
" p0 c7 |' d% r; Z
" Z6 a/ x- B ]) e; s8 m( \-Much faster:
9 C; l+ a% L. ]$ ?' I- |. g BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
5 \4 F Z' \9 \3 ? S1 _& E+ J
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen2 Y8 o) s+ L& ]9 k w
function to do the same job:# h& W0 T2 p- q* z6 E9 f
1 o4 k3 U; U; h$ j- f push 00 ; OF_READ
/ B3 R- \# s" Z& V9 Y8 U mov eax,[00656634] ; '\\.\SICE',0
% Q( l* r* @$ d1 C( e) X push eax4 v D# f: r7 W8 n3 s2 _ k( Z
call KERNEL32!_lopen) Z) @7 C- k, J" j1 g
inc eax5 B! V1 M) A6 ~& `
jnz 00650589 ; detected
3 Q/ N& T- r! z. }: e( y- N0 V. v8 F push 00 ; OF_READ
0 l+ \8 S7 q% [/ y7 p2 e* ` mov eax,[00656638] ; '\\.\SICE'' D# T1 a7 H( V+ M% O# R
push eax! i2 N. d! z) h- s, T# Q; J
call KERNEL32!_lopen5 s& X# ]5 x, H2 [( @
inc eax
2 G6 y4 C1 \0 W& x/ V( l jz 006505ae ; not detected) @( p' b8 g! u- h) N; h. V
; I( F0 l) y# ?# L4 t1 e
- ?9 s2 f- h( }__________________________________________________________________________
' p9 x' u, X$ S G& [
) P& ~; u5 e& k4 h7 hMethod 12
$ O; T2 ^, r( H a=========
% c) }9 x9 _- W9 J. g% f
5 [% W, x" u$ O8 uThis trick is similar to int41h/4fh Debugger installation check (code 059 C# k1 Z/ v2 Q, {" B) }! k1 l
& 06) but very limited because it's only available for Win95/98 (not NT); N0 C# |2 [. C6 @- R0 S7 T
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
; Y0 s9 y$ P) _( T" S2 @" y5 e$ [2 X# N: d7 k
push 0000004fh ; function 4fh
, [: P6 p, Z* K/ L6 @ push 002a002ah ; high word specifies which VxD (VWIN32)6 l1 p/ o( l: G* K
; low word specifies which service \% ?5 S- L0 | ]& }5 S5 T
(VWIN32_Int41Dispatch)4 R( _ g! m, K n$ F6 _* m9 y6 _
call Kernel32!ORD_001 ; VxdCall
7 b: }$ q A& F0 a$ u& d5 o. ^* P/ r cmp ax, 0f386h ; magic number returned by system debuggers
, K D9 y' _, c$ V& k jz SoftICE_detected% V: v# a" |+ k
. Z" r2 I+ }) `8 s# Z% k
Here again, several ways to detect it:
4 W. x' N G' J. d) P9 z- \. Y: v+ ?# o6 G. g2 B7 t! `
BPINT 41 if ax==4f
- v, _' b- r, t0 X& `- B: K( Y
* [! b8 B" r1 D" H$ B! b BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one0 \2 b5 d, h$ J6 D8 E9 L+ D# ?! h
3 E: Z4 S- O4 x( E BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
8 N7 p3 H: e, x; t. {* Q
5 k6 b2 l8 D2 Y" o+ ] BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow! X$ m6 o7 w) C2 K) q. i/ S
0 c. i6 S3 ?$ r__________________________________________________________________________: F9 s* r1 F" G3 ], C7 r
& u/ m/ _8 y* _. fMethod 138 U1 n+ v7 f3 q9 M9 x; N8 [5 ^
=========/ p+ \, @1 l% {! E
& v8 C% F. u# i, e! ~- N
Not a real method of detection, but a good way to know if SoftICE is. d6 }/ Q. Y5 A5 O# h
installed on a computer and to locate its installation directory.
$ m- d, K S; ^: H8 J# f) L, d5 YIt is used by few softs which access the following registry keys (usually #2) :( ]/ {1 S& t; a( J
# ?% V( o" Y+ V; v2 y. f3 d; [% P-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion) x9 c2 }0 y- N$ I3 ?/ [
\Uninstall\SoftICE
; k: q- J( T t4 n: T0 ?1 O( r-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
0 Q+ U: [. j4 x" J-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 }! L k; y$ s% Z; K1 b
\App Paths\Loader32.Exe
, j$ n8 o" L1 X! {; j
' u" k. d9 \) G) ]+ ~$ C+ D
, T K1 A, a: X. n( i1 ~7 VNote that some nasty apps could then erase all files from SoftICE directory
5 `1 _3 w' m2 B7 x3 r9 n(I faced that once :-(: t I) E5 W( v( I- t' a; K- o4 M' P& N
6 A" V2 L8 J3 R7 E/ K p
Useful breakpoint to detect it: H' J3 T8 [5 G3 L3 C0 S
7 D* m9 E+ [$ C! g6 E& v4 ?7 s; @ BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'/ c3 [- v) N* g
# u" ~( J# S4 Q7 T9 t1 x( A F8 |4 H. i__________________________________________________________________________
* L& L# {' T! b9 N8 P3 u7 X+ _4 W2 j0 C9 m: i
2 V7 j& l2 K& P. ?
Method 14 " L1 K g; s- o8 A
=========$ M2 A6 ] H9 Y0 I* A- L' b, q
" I" z: j! j: A0 ]& B9 x; T. H4 k
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose3 n; _/ w* j, A) X/ D
is to determines whether a debugger is running on your system (ring0 only).
) k- e. d7 T$ j S# v0 `* W
$ L' ^0 a- N C& N/ F1 c+ }2 u( h VMMCall Test_Debug_Installed
) ?. I# \7 h0 k: @ je not_installed
' j6 _( c9 p$ e9 O3 F+ z9 ^( i; C' y' f/ w$ v
This service just checks a flag.
; V! ?3 K* p; q7 ~</PRE></TD></TR></TBODY></TABLE> |