<TABLE width=500>
* \% w7 H4 K+ Y; w+ N<TBODY>
0 [4 ~1 O% d6 k; T' t<TR>
( R2 s1 s. K) m [( c% H8 l6 q* H; [<TD><PRE>Method 01 # ^7 D; x* X- P! m) P
=========6 Z' U# F" V2 { F* j5 i* X
9 p6 y7 ?7 O! }3 x# l
This method of detection of SoftICE (as well as the following one) is$ F$ K9 T; s' r* f" D$ Q, O
used by the majority of packers/encryptors found on Internet.
3 y" o7 H! b- t0 J3 r/ DIt seeks the signature of BoundsChecker in SoftICE; K. T w! Q+ }: m4 k
+ H, S" h2 ?' y8 g8 t1 K4 X mov ebp, 04243484Bh ; 'BCHK'
5 u; h5 P5 W3 P( r5 f- c mov ax, 04h
9 I5 {" J& U7 O int 3 4 Y3 b% O. r" d/ U, B: r+ @2 q
cmp al,44 M6 F& {4 ^1 g2 [
jnz SoftICE_Detected Q5 `1 C5 B4 z. f" _! L/ m4 [; w
1 I9 J1 U! c5 c, w' `
___________________________________________________________________________( `1 l, }4 j C
; Q% e+ X7 r0 \7 B; k+ w4 C8 G
Method 02
3 }$ a2 T1 x' K/ x- K=========0 k4 |! g' S ^6 i' D% q1 x; Q
3 F1 ]1 w2 C" S1 z F) H/ Q$ s0 I0 h: c
Still a method very much used (perhaps the most frequent one). It is used
# e2 y" u* n5 n" G4 Z' Qto get SoftICE 'Back Door commands' which gives infos on Breakpoints,4 ]* z; }" m; L2 g+ C2 [
or execute SoftICE commands...7 L% U# ~1 |0 r- E' P3 ~1 D
It is also used to crash SoftICE and to force it to execute any commands
6 Y* W* A5 [% c8 \! U(HBOOT...) :-((
5 u6 X/ ]3 H, X4 _1 q, D) \! w) e: k, D) K
Here is a quick description:$ j a( A8 I9 B3 c5 Q1 B7 `
-AX = 0910h (Display string in SIce windows)+ p7 n( u. G$ ^: _* o; q: L1 S
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
@3 y+ @6 R6 n/ g9 f) S0 s-AX = 0912h (Get breakpoint infos)) q. z. e! C0 k6 ~- R
-AX = 0913h (Set Sice breakpoints)
" ~3 h2 g" S2 Q0 {' K-AX = 0914h (Remove SIce breakoints)
9 V6 c5 e! S' |2 c- l6 n' O1 t y& L$ j7 D+ g2 @/ J
Each time you'll meet this trick, you'll see:
; b; n) S3 O& N' a7 }8 M+ y-SI = 4647h* N; e6 I1 K# q, @4 D
-DI = 4A4Dh
' T9 P0 l) y y, L2 tWhich are the 'magic values' used by SoftIce.
2 P$ \- r0 L0 N4 X7 ?1 VFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
. E0 l; a3 P" K( s
' \" ~6 w& |( _6 wHere is one example from the file "Haspinst.exe" which is the dongle HASP, l) X: K6 Q; v# H2 o4 C
Envelope utility use to protect DOS applications:5 K% @0 p, r- b# z8 H" ?9 u
1 s# N V# L$ W6 g. Y- x& u
$ H5 [9 y* D/ V" m
4C19:0095 MOV AX,0911 ; execute command.5 X, d: |. r- m" x. t; z
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).! D5 _5 w* J4 f6 B
4C19:009A MOV SI,4647 ; 1st magic value.
0 U+ n( w6 ^; A6 J* }4C19:009D MOV DI,4A4D ; 2nd magic value./ a; A4 ?5 D" f( u+ D; Q4 a
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
0 g2 a) C) B7 d/ Z4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute" |; F8 r: n4 S& K P4 J. h1 C
4C19:00A4 INC CX1 j y6 `+ _+ Q8 \- Z M# P
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute+ e* L" ^( \$ z: t
4C19:00A8 JB 0095 ; 6 different commands.8 d5 x7 i5 }8 U
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
( M, p/ O* l5 v! s; y4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
4 M8 l7 u! e, b' p/ n2 |- R+ h/ a2 E* \ C
The program will execute 6 different SIce commands located at ds:dx, which
- \. P6 X& t( d) F% Y$ _# ~are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
2 K% e: q9 l0 A+ q& ~+ J" ]" b6 g* K. G t3 H; g1 r4 \( H
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
3 c: X" p( F7 w8 i- M+ \___________________________________________________________________________
3 F/ G+ g& r+ T( K0 @
v; K o/ z. m! P1 D5 y8 z$ [ V- m& I( I' a
Method 03
$ O5 q, [0 e, z1 V* T8 m=========+ W- X! v2 G9 {6 D( I i2 O
' P- _: ^2 M! N0 [2 Q9 c
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h9 {4 b% a8 i; B6 S. l
(API Get entry point)4 n8 U/ N! e% F. I; _
6 ~9 p. [# j, j% m+ e
; u' E7 y4 F( t% T6 F- O xor di,di& a8 G7 d. l: \
mov es,di8 @* i& [! _) h! v) W
mov ax, 1684h h" k& G1 k6 X+ R* L0 r8 i' C0 g
mov bx, 0202h ; VxD ID of winice' U2 J% r+ K" Q: ]' D* m
int 2Fh& z. q' k3 s' M. H5 B0 V7 n
mov ax, es ; ES:DI -> VxD API entry point u% D" ]1 B' _$ O3 | y0 v1 U
add ax, di0 Y$ B& o: X9 ]2 e& Q
test ax,ax
7 E1 u. I: v x( `9 n" n jnz SoftICE_Detected, Q4 z3 E6 |1 i5 P- C
" ?" T$ _5 D& Y/ k+ }# i! W5 H5 _
___________________________________________________________________________5 h5 d7 K9 v% A, w! w0 [
& O" W$ t" {& k: d6 T
Method 04+ M, _, |5 h1 q
=========
+ D3 G- Z; S* ~ u, F( v+ I" a
7 U9 ^3 f b5 y6 ?) P0 _3 Y: m+ fMethod identical to the preceding one except that it seeks the ID of SoftICE
' c* y/ Q$ q- FGFX VxD.& M" N7 Z2 i" \ J! e* m1 y
! g4 D% \1 W+ k- f7 B
xor di,di
- W0 A- f" K8 E+ {) b% i) s mov es,di
$ o* q) b" z4 \$ p5 U/ w; e mov ax, 1684h 8 r7 R& I l' \7 k
mov bx, 7a5Fh ; VxD ID of SIWVID
( n/ w6 s; H" _! V int 2fh6 q% K) Y! Y6 ?2 M8 Y$ ~
mov ax, es ; ES:DI -> VxD API entry point, D: R. q% E# j
add ax, di$ w1 q. O( n) k; |. J2 M0 D$ O( A9 f
test ax,ax
8 j3 q; H+ l2 r9 R1 q% t! s& c jnz SoftICE_Detected3 z( K6 V9 @8 z1 x. H. a
1 u7 J! W7 b5 D) `, @) f8 Z
__________________________________________________________________________- S2 N, p# i4 s( K, M$ ?
3 f5 x! j/ V8 \) K% R! G, ?
- ^1 i' F- ^8 }9 ^2 W9 j9 dMethod 053 @( `% u# B- e0 Z4 k" i+ f+ W7 u
=========
% ]+ S2 k9 w( F* b i Z6 v- J) E! Z- Z
Method seeking the 'magic number' 0F386h returned (in ax) by all system
) E& }8 s2 z9 p8 p, Y9 mdebugger. It calls the int 41h, function 4Fh.# z) {. z& I ]- [/ k% v
There are several alternatives. 0 s6 f6 S9 q% h, {* v" h
; r, p2 L# ]# r
The following one is the simplest:2 r% O1 w- A: I$ w) X/ t
( R: I: w3 T' e7 Y% ]
mov ax,4fh4 V# I4 L9 { m# L- [% d* n+ e" r( I
int 41h
; u* K8 |( _1 g( ^ cmp ax, 0F386
5 O$ X7 ^( q- U, @- m jz SoftICE_detected4 Y/ p& i( b: \
; s) @5 Q5 h6 q6 r/ I
# f$ {3 f5 c" X3 ^; `) J
Next method as well as the following one are 2 examples from Stone's
# c! |+ v+ [8 m# H [9 ^' T"stn-wid.zip" (www.cracking.net):( E" l9 X' X3 }$ g* C' y4 Z$ v
7 |$ W/ ?# T7 u0 S1 F7 q mov bx, cs( S8 a5 y2 Q$ `& f+ m: \
lea dx, int41handler2
( @% M! l# z4 g. o% `- w1 W( X xchg dx, es:[41h*4]
0 Z/ a' ?1 W! N xchg bx, es:[41h*4+2]0 D1 M2 N; \/ ?. S+ X9 j
mov ax,4fh
# e- x, [! Q# _! T1 M2 u6 ` int 41h
6 l; ? ]2 j% ^- F xchg dx, es:[41h*4]8 n! o: ^# d: N$ i+ `- ]
xchg bx, es:[41h*4+2]% B: C$ L; x* t1 P* M% ~
cmp ax, 0f386h
) b8 P2 P5 E7 ]; K jz SoftICE_detected
6 O8 p5 N, Y* \: u' i0 C1 N7 A& H
int41handler2 PROC; V- D0 k/ d$ L1 N2 p
iret' Q" \2 a9 N) U
int41handler2 ENDP/ N: ]; Q7 |- k) S6 B/ S
1 V N* T/ y# {/ L/ F7 z
0 W Z' x" ^& _' r A) {, K_________________________________________________________________________
9 @; ?: U5 ^% x8 C. @ y5 c9 d2 |; D
5 [3 t* h7 D2 L6 FMethod 06
0 P3 {4 ~* ?7 e+ C! M( F=========
) E* p P5 ^% v- Z y+ {
3 A3 A% A% `6 L* ^7 N& u$ {) I- _8 x' T) j
2nd method similar to the preceding one but more difficult to detect:
- q7 L8 q7 r; _6 d4 ^6 W/ I$ H1 |: r! T- [( Y
]" _ S6 {! W2 E6 o; Z* u0 I
int41handler PROC
" b0 p% F# {! h# H' z1 a) n mov cl,al4 M7 u. C& @/ u3 Z X- q4 K6 @% K
iret) M5 M7 S& T. K. H( [& Y; x
int41handler ENDP/ g9 X% e3 ? y. t& n
( d/ w: M/ P X. |7 q9 `* J: W
; d) g! q# B- S6 C+ n3 S: w& M' O xor ax,ax. m) |9 H. U( p' Y. |, |# g+ v4 p
mov es,ax
1 n& n, m0 C6 s& I* o mov bx, cs% K0 U7 W- r& b' V
lea dx, int41handler- ~1 V( ~9 ^6 f5 J& U3 N
xchg dx, es:[41h*4]( P$ [. Y2 |% S
xchg bx, es:[41h*4+2]
: g; X5 q, Y1 }) `6 O6 M in al, 40h4 _# B8 }: R; X8 y' x# w
xor cx,cx3 c; {( Y$ v* F: z N. f9 h
int 41h- c# F3 t; v% O" C
xchg dx, es:[41h*4]$ i: n7 L, Q$ \. a' b1 a
xchg bx, es:[41h*4+2]
$ h6 q. a9 j- E6 c c! _ cmp cl,al
k+ `, n4 U4 N8 L/ X9 l6 C4 E' [ jnz SoftICE_detected
. k" z, f' }1 l/ h0 D/ K" G0 O# t8 A6 B
_________________________________________________________________________8 g: @# ]) {- G6 H, D) s# a
% e( b" F8 t" U7 ?) b
Method 07
3 T4 e8 j0 Q2 @/ v: [" Z7 f/ w=========
. d% s: t# ~# G: K5 r! v7 V. ~ t: H5 r; r% V$ `' q2 F* L. c
Method of detection of the WinICE handler in the int68h (V86)% X/ }( L, K% J5 G, |
+ i" J8 D1 [% @" |: a' H
mov ah,43h" f: _! m) j0 i$ E8 D$ f2 c n
int 68h
& L- d# r8 `7 g5 i$ D cmp ax,0F386h" e; Q& ^( d/ [" E, S
jz SoftICE_Detected
' x, e5 V# }' R& r4 E$ n
& M0 q" I2 _2 E. u$ n: }. ~4 S" B% Y, d2 A% _4 ^& C- O/ }
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit- ?. j/ `! ]! @4 V. A
app like this:) l+ g# d& V' |. J. `* I1 \
7 [$ b, m8 @9 ~7 l7 I BPX exec_int if ax==68
! t: T6 g; T9 `1 x3 X) o5 O3 { (function called is located at byte ptr [ebp+1Dh] and client eip is2 k7 l2 f7 G/ y1 w, t$ u) X6 X; R" o
located at [ebp+48h] for 32Bit apps)9 @- \4 b& N7 j( k* X2 v& c; ]4 f
__________________________________________________________________________1 T" b9 \: ]$ s7 w3 k0 \4 s7 u
% B* A. h) @. I, s1 e& f
" ~ l" J' G7 IMethod 08' X; s \5 H/ j& S; ]
=========
9 }" M/ r% H4 k2 |) _9 o5 U
6 @* F: v" e* Z8 p& C; I4 cIt is not a method of detection of SoftICE but a possibility to crash the. a$ C; M" { b; A0 W' F- e h, f
system by intercepting int 01h and int 03h and redirecting them to another
+ {) F, Y L* Z, froutine.
- j5 {4 B, s, [5 e7 EIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points& X4 U+ Q1 q' m! ]4 B5 P' W. N9 e
to the new routine to execute (hangs computer...)! f% \' C5 q1 |8 W; _( `8 m; M9 B
+ C0 \* o7 \; K/ Z7 V mov ah, 25h
$ Q$ N2 y G! Q# K mov al, Int_Number (01h or 03h)
& _2 O, l3 |, N. t mov dx, offset New_Int_Routine+ J# P7 t* v8 @1 i; Q+ w6 }
int 21h% n. t7 G, @( k0 a, O' b
% d* U" g" m* k: \6 p3 K' v
__________________________________________________________________________2 }3 u4 ?# J, T* Q$ u% Z
5 D" L' ~0 N I% I' S8 ~
Method 09% ]9 m$ u$ \2 w" x/ j0 f- B* ~, ?
=========
2 l8 s, \6 E7 a
* A' P5 Z) B" ^! G2 j3 z Y4 v& ~This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
$ a$ t' }1 i( h" s& W* d% mperformed in ring0 (VxD or a ring3 app using the VxdCall).& P* l" D5 h: H+ a
The Get_DDB service is used to determine whether or not a VxD is installed
: y. H6 n3 H0 q2 k5 B8 s6 ^for the specified device and returns a Device Description Block (in ecx) for u1 g# N4 V+ d& C. H- z, F
that device if it is installed.3 A& _ r0 j6 _
: m2 S2 u' q; i
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
& K- {6 O3 B2 u2 n3 P mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)' @# }% `9 f7 F
VMMCall Get_DDB( B( h8 c+ G9 t1 y, x( p2 q
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
% P2 Z. E* a( y2 Y
1 \5 c" H3 T! A, y) x) u( O* mNote as well that you can easily detect this method with SoftICE:
! `1 ?- `' I2 V, C* W bpx Get_DDB if ax==0202 || ax==7a5fh2 O2 Q& \% Q. i- J
+ a ^3 Q# h; l* `0 \6 r7 a__________________________________________________________________________
( N( R0 i$ X& o7 t0 {9 T( X- m6 R
$ Q% K' g! P' a# _9 H: c# yMethod 106 t7 |% ?; s$ S* R
=========8 u- g2 g% o) ~; E; ^0 q' Y
8 u0 D; h( ?2 M7 z+ m0 `( u# I, @! N
=>Disable or clear breakpoints before using this feature. DO NOT trace with9 G; G; b5 N" j: b8 H3 k$ l
SoftICE while the option is enable!!# x7 O& e& N$ v/ A8 X
2 X/ P& u, m- }& d" S
This trick is very efficient:8 A- K' F7 V. E! H s; ?( u
by checking the Debug Registers, you can detect if SoftICE is loaded, w$ T6 @( m4 g5 N
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if) X1 J; b( A/ |7 [7 }
there are some memory breakpoints set (dr0 to dr3) simply by reading their
, A) d$ f3 R a6 k. T k2 svalue (in ring0 only). Values can be manipulated and or changed as well
: D3 b! [! t. s. y# n7 u2 F* K# k# u(clearing BPMs for instance)
' X1 M9 J$ Z4 A$ M: S, W; d7 x) K- D
__________________________________________________________________________
7 H/ y9 s# R% d4 F" y4 p) c2 P* c) t$ I K$ x
Method 11, s( ? D% R! w* a5 F3 t2 e
=========
! e: Q0 k% @& z1 @3 p4 ]/ X( U8 @: u& }: L% \9 O) @
This method is most known as 'MeltICE' because it has been freely distributed
a* J; x _- ^! E0 M6 `3 Y. nvia www.winfiles.com. However it was first used by NuMega people to allow# f) g+ g% m& W6 Y: p' U0 D9 U
Symbol Loader to check if SoftICE was active or not (the code is located
" ?$ p" ?( y7 j$ {5 m; S! Yinside nmtrans.dll).) f* }& ?. K9 d1 o& E5 s
# _% j7 Q* G/ P5 q0 a; ]The way it works is very simple:
! W) m/ j+ s3 n A* a- |& l5 w5 sIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
* T+ t A' f0 u6 y i% tWinNT) with the CreateFileA API.
V; E1 g1 I$ T7 h
/ F9 p" X; C2 }5 y' O" ZHere is a sample (checking for 'SICE'):
% ^* \ }8 l3 h6 l0 D: U( G
! O3 @: B) v" J2 @* IBOOL IsSoftIce95Loaded()
! S# D) `8 k+ V6 [{
^. d, F! c+ L5 _ HANDLE hFile;
4 `, h) A( U5 t" j* I hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
( v# H7 U" o: v FILE_SHARE_READ | FILE_SHARE_WRITE,
* S! S: p& E, u NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
: ^+ }7 L3 p7 x8 L, X& g. _ if( hFile != INVALID_HANDLE_VALUE )
# g4 G3 T) c, Y { {
E! x3 L- t: K( k CloseHandle(hFile);
/ b; F% A' T) L7 E9 q" N& K return TRUE;0 \& h! e F6 H# S1 D1 ~& P
}
9 l0 i" B1 T' `. r1 t, w6 z! P0 R return FALSE;/ L$ w& U$ I! c! D5 N+ j1 Q
}
2 q8 |" f: v ]1 m& k+ a* R7 l
- n. {' [& {! X% R6 r9 dAlthough this trick calls the CreateFileA function, don't even expect to be. x7 d+ ~8 ~+ d
able to intercept it by installing a IFS hook: it will not work, no way!
/ K" i' ~) p9 s5 PIn fact, after the call to CreateFileA it will get through VWIN32 0x001F9 Q" G U2 n7 {0 I, K) {
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
) D, ]# C. d, I( fand then browse the DDB list until it find the VxD and its DDB_Control_Proc$ R9 p. q$ m) T
field.
8 ^' K! d/ D" p6 SIn fact, its purpose is not to load/unload VxDs but only to send a
8 L+ Q3 a4 W( H5 c% r0 f, JW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)' ?+ R8 }( T0 ^ i, W
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
4 B5 t6 E' E9 G1 b* jto load/unload a non-dynamically loadable driver such as SoftICE ;-).0 F( W$ t) r3 o. d; \* x
If the VxD is loaded, it will always clear eax and the Carry flag to allow M9 i( ?+ f! N) H* a7 p
its handle to be opened and then, will be detected.' s- H% ?: R' ^
You can check that simply by hooking Winice.exe control proc entry point
9 L B, H+ y. v8 g* t; U8 Zwhile running MeltICE.
( c) `" U. A+ o& ]3 L6 ` f
5 t4 ]* x9 \8 o- [0 c1 R5 p( Q3 F, M) B, Z ?
00401067: push 00402025 ; \\.\SICE
j2 w4 B: G' E3 Y 0040106C: call CreateFileA
7 h% S- _+ H2 m7 u+ t i* b* [ 00401071: cmp eax,-001
' A2 F( K" ]& u. e1 A; j 00401074: je 004010911 S8 s5 \& \/ a# J/ D a; T# Z/ b( ~
1 i; u" j7 P4 ^( F2 \( t
: C/ o# d# ]; y2 {* }There could be hundreds of BPX you could use to detect this trick.
: [9 e5 ~( m) g6 s6 J-The most classical one is:
; F8 B6 q- G+ J! r& j BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||/ \( ?6 W8 W5 P" k' |' h
*(esp->4+4)=='NTIC'
1 \: D4 y$ R" X+ v8 ?8 n \# Z8 _) }9 `$ k5 { ^& @+ C
-The most exotic ones (could be very slooooow :-(
$ A( p. A! t- Q' H$ B- s& o7 I BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') ' H+ Z- F5 @& a# W a
;will break 3 times :-(
5 W5 {! B( W5 }* Q+ r5 J9 ]
( C* F* k+ Y) r* u-or (a bit) faster: * w1 r: F8 `: d2 N' K+ P, }& A9 D
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
, }, f% G/ C: m- S) u# o9 F$ M6 p5 C
. B3 e4 A6 K+ X6 J- @3 M BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
; ?, }& X* I( h# J. s* o4 M ;will break 3 times :-(0 x" ^/ s% H! C* q7 {6 n
6 ^% y; l0 h q# U
-Much faster:3 n: g1 ?3 o; \2 S% H
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'0 p, J% K0 Y3 k4 x) {- ^
4 |; F& o: b1 A0 k3 {) u
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
$ w( ^( c1 G- Pfunction to do the same job:
! w5 G* w8 r. E- n6 O8 X. G' k. S$ T8 D( s6 i
push 00 ; OF_READ P/ |9 `' E% x) w9 O# O! c
mov eax,[00656634] ; '\\.\SICE',0
, V. `$ }2 z6 T' y0 h% d push eax
7 r* |' U8 t- O$ u' s3 D call KERNEL32!_lopen5 p9 K/ U' o( C# T2 p
inc eax
* } c5 o; w# \( J jnz 00650589 ; detected
$ d: \% y2 H2 c' m9 U1 R! f push 00 ; OF_READ
/ }' z @: E* j) }( y mov eax,[00656638] ; '\\.\SICE'
! _- g6 ]$ [, ~; S* U2 q ? push eax
) s6 y8 L' U+ {- ~$ G, q, z/ } call KERNEL32!_lopen
6 D% S. D7 V. F; W$ n% Z8 p inc eax
0 _4 [+ X! k. u9 q7 | jz 006505ae ; not detected5 B3 @5 ] u$ f/ H) F: P$ A) {- K( G
$ O4 b1 F- N/ a) E# c" Q7 G# E0 Y' z% w9 S9 |
__________________________________________________________________________ e% {& T4 J& g h6 a
; T/ H; i" s. A0 IMethod 12% h( b+ o0 D. D# W9 j+ a- d
=========0 K' p& e+ r. }, ~2 r2 ?8 m
4 }$ W6 {; q& I1 J, @, _7 c9 y
This trick is similar to int41h/4fh Debugger installation check (code 05; ~+ g0 H- V) Q7 ]- f5 m. S5 d
& 06) but very limited because it's only available for Win95/98 (not NT). [9 o( w( ?' Z( K
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
! ^, P z5 _- v9 K2 G& @9 {# O3 c0 L' q. B5 X; o1 l
push 0000004fh ; function 4fh" W( ^2 ]* W' ^/ ?
push 002a002ah ; high word specifies which VxD (VWIN32) U; N' ^) L5 V+ K+ c. @$ C
; low word specifies which service* m$ |8 @2 G9 x! L B
(VWIN32_Int41Dispatch)' R; d; F6 Z6 w& Q- J! b, L0 E
call Kernel32!ORD_001 ; VxdCall( `" U; b1 d8 Z% q4 y" ~2 e
cmp ax, 0f386h ; magic number returned by system debuggers
) z2 N% y$ R- ]' {$ Y- T% l jz SoftICE_detected! S* k G! I, r' Q2 J8 C4 g3 q
1 H; u4 M) O( q0 H3 m1 m8 j" ]; v
Here again, several ways to detect it:
& w5 G# ^1 s1 g0 O/ M
6 A. ?6 L2 M4 K F& z) O BPINT 41 if ax==4f
0 F. B9 p N: B, s. ~
* Q, a. a3 l$ p- P3 D BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
, _3 P/ B: z$ W( z. P
& `, P! S, V- n) h& \2 q# A# E BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A8 i. P, b6 O- V. J8 L/ ~. ]! i
& B& ?5 m; _& P$ y BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!2 Y/ E( |: \4 d" g7 V
! Y0 y) } y% U% z& Z; V
__________________________________________________________________________! `1 y- ?* h) K* H3 L
5 u5 d7 ]6 k" m# q5 [( @
Method 13" {4 m: U$ g' K" T
=========
( e" h4 b- p& T/ W1 ?& ]) B
6 _5 N( A( [; V1 n2 d. WNot a real method of detection, but a good way to know if SoftICE is2 E1 }. T% R9 T* i! Q; z( R
installed on a computer and to locate its installation directory.
9 f o: M3 t- D' XIt is used by few softs which access the following registry keys (usually #2) :+ {- _) m/ U: l, M
3 n- }. t' J2 r% h! ~- w
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( }$ T1 T( b1 V8 C: K' B, |1 _
\Uninstall\SoftICE5 q: {7 \# N) K# X2 `) v2 X* U
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE; Y$ Y' D- \# K2 ^
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion3 a ?( d- ?8 x
\App Paths\Loader32.Exe
1 c4 v% C4 U; i' K: t
/ l: W- T& x1 W8 [' ?$ x. B) g! ?( g' s% X
Note that some nasty apps could then erase all files from SoftICE directory! ]/ {" N% }# j" I6 y M& R% [8 u
(I faced that once :-(3 x* Q5 J4 G+ ~ W
0 _2 n6 K* I5 ]* T+ g# D. a# C
Useful breakpoint to detect it:/ Q* ]. V3 _% C+ R/ G G% W7 z4 g2 G
/ G s/ C+ i' ~9 |) j" I5 g# l BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
) C$ `* p: A; M: a3 z7 r1 `) O( S. m- Y1 k
__________________________________________________________________________
" A' ~0 w( v4 Q9 d ~9 u
. c: O/ Y' f* R d+ s" w6 j' Z! ?) _6 C
Method 14 2 t$ b" c, |8 e* o- ?% K* O
=========' Y4 s: `3 k$ {0 ]/ |
5 M% n2 }6 A4 t5 d
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose6 p4 t k& N8 B3 {4 c
is to determines whether a debugger is running on your system (ring0 only). D5 _: B% q& R# a' W. P
9 f7 d( v3 i8 P
VMMCall Test_Debug_Installed
( k P. ~2 h+ M2 t1 s6 ? je not_installed- H" `: h% B) K) x
/ ~& ~5 v, W/ d, V. Y7 U0 `5 ~This service just checks a flag., D5 t0 `% z3 a0 M. L
</PRE></TD></TR></TBODY></TABLE> |