<TABLE width=500>8 s; V$ g" Y( h2 S! U" Y3 z
<TBODY>
7 Q5 K- l% V) t/ ], W+ H<TR>
M: C0 l* [7 j; O' j<TD><PRE>Method 01 2 E- Z; s, A" b8 c; _/ i( W3 x
=========
' O4 k* ]2 h7 |2 G, U3 _
2 N# \$ B" W6 f3 z" vThis method of detection of SoftICE (as well as the following one) is" t( r0 H) L! j5 j- [
used by the majority of packers/encryptors found on Internet.
/ o' u4 T, K# t) R# u- Q- ^3 ^It seeks the signature of BoundsChecker in SoftICE
% a. z& h, k5 b8 n% [: K, a
* |0 @% ^! C( }9 W' [% U; t mov ebp, 04243484Bh ; 'BCHK'
3 U0 u/ B$ | V5 a mov ax, 04h
, o, o5 o8 Y8 t' u int 3 # i5 o7 o8 j( g- O) k
cmp al,4
& I* n/ F/ N( ?. W; r jnz SoftICE_Detected
0 V4 `3 G, R5 P! B; G; [% i& r; g, |9 I2 k3 f/ p& ~: Y% ^
___________________________________________________________________________) B0 a& l% A+ D& c' f
, c) R3 `# W* PMethod 02
5 x E* Y4 I/ ~, T=========
( A3 D" D3 y$ N+ S2 p' T8 R+ y$ e! D3 J1 [. Q s
Still a method very much used (perhaps the most frequent one). It is used) d1 Q2 ~" B9 p# N( j. S
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
0 B6 u! H. W8 V5 h' `or execute SoftICE commands...8 \; N! V) L7 X) A5 i! w
It is also used to crash SoftICE and to force it to execute any commands/ u$ P7 j3 } ]; I, }$ S
(HBOOT...) :-(( ; c& V# M4 d& ~. ?& B! f5 M
5 y3 B( d' |: K/ ?Here is a quick description:# P: L* v! E/ R7 O: Z
-AX = 0910h (Display string in SIce windows)8 y3 D7 H0 ?9 P. `' {
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
! |2 z/ _4 l8 |9 ^# k! N: E9 V4 I-AX = 0912h (Get breakpoint infos)9 P/ q1 x# C8 b7 @& ?
-AX = 0913h (Set Sice breakpoints)2 L3 B, S( K5 G! K, a; f
-AX = 0914h (Remove SIce breakoints)
, s, \7 _: k" z! ~, c; P- c. ~% o/ a0 ~6 Q$ f( V* ]1 {
Each time you'll meet this trick, you'll see:
" }) F6 ?2 L2 w" |+ e2 g-SI = 4647h
" D9 D; J7 Q" T! W f-DI = 4A4Dh
2 N3 O8 M: H1 ^2 [' q) f: z# LWhich are the 'magic values' used by SoftIce.
& f! C8 M# w, ?; Q* v- Z H9 m6 P, FFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
, H' E- b: E- r( `3 ^
. v5 \1 j% U9 | A E) ZHere is one example from the file "Haspinst.exe" which is the dongle HASP
. e/ v4 z; p, bEnvelope utility use to protect DOS applications:
5 R% ]. [1 ?1 C7 |7 H5 q4 Q \$ e7 @1 ~1 [
1 k$ x5 p7 H; |) P. x, R4C19:0095 MOV AX,0911 ; execute command.
8 A3 \( F8 M7 D/ w4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).$ Z- \" Y- T: Z( j
4C19:009A MOV SI,4647 ; 1st magic value.
; v6 g* ^" K' m( k4C19:009D MOV DI,4A4D ; 2nd magic value.5 q! _4 i, f: c
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
% N8 v' F% O; P( `, ^& ]) e- _4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
* }# X3 Q* R L" E1 h$ ~1 Y4C19:00A4 INC CX
8 K9 V; x# r. g, V; d O9 g$ c4C19:00A5 CMP CX,06 ; Repeat 6 times to execute' w7 F: Q% [. i+ G
4C19:00A8 JB 0095 ; 6 different commands.; J- y) ]( N* p% s5 r" p/ k% l
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
% h5 f# G" m% ~& p0 R; ?) f4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
0 b) X$ u1 E) r R2 V# t& m1 z% o: _/ z
The program will execute 6 different SIce commands located at ds:dx, which/ j \7 b4 p9 i
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT. e8 Z. J. T i! z+ E) B
f4 W$ q0 J$ ?% C4 g$ v8 m6 v* I
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.4 Y# q0 r& t" M. X$ l7 @
___________________________________________________________________________
, E; e) G9 e& a+ D/ r5 t o! U$ I; F! D6 l: a2 y: k }2 w
: k! I+ Y+ h# {- {0 ^, iMethod 03
3 k+ l8 `2 N4 S% d=========
2 |9 ]8 y( n: }0 [& K) i7 s% J: l: H# `* f, J
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h+ ]1 _$ [) \ ^9 q
(API Get entry point)! @" Y/ i2 {2 I% Q* j
8 L+ c$ f- Z/ Q5 N
. x( o2 j0 B( a) V xor di,di. @; @) \9 ?: E' x! Q
mov es,di
. E$ s. D, T4 N9 I mov ax, 1684h
& K$ g2 B, M3 N: h9 y mov bx, 0202h ; VxD ID of winice4 p3 W @- E& }# Q, \6 A0 U; [
int 2Fh3 G# _5 h4 j( _6 Y# p3 t
mov ax, es ; ES:DI -> VxD API entry point( p* d! C, n( ]- ~$ Q- E
add ax, di3 P0 ~# e+ ^: R' S
test ax,ax
; w% l* q3 G3 o* ?' y) E S: ~2 E jnz SoftICE_Detected. V3 w. s5 s7 @3 S. t9 D
' K: `# [& L6 B- f+ P5 U
___________________________________________________________________________0 ]. W" U, [+ R3 G- V5 t( g
4 y, ]2 x, s! H [( I
Method 04
, o1 k% w1 y6 k5 t/ r& _=========9 [% d |" u! z
4 {" A: m7 x! Z& r
Method identical to the preceding one except that it seeks the ID of SoftICE
+ O6 S3 I& h, r9 b6 z- r/ LGFX VxD.* u, H8 {2 A3 g! i
0 X8 A" H/ ]4 k& j xor di,di
- c# D! \0 O) @5 b6 L! Z' r5 b. T8 i mov es,di
! G/ H6 |$ h! D1 ~% \4 s mov ax, 1684h , T+ M$ w7 l& D' r T/ h0 ^. `. o
mov bx, 7a5Fh ; VxD ID of SIWVID
) ]5 r! v n6 Y3 L; f$ K, V$ E int 2fh
0 S) z) x$ H0 n1 B* g7 E' S mov ax, es ; ES:DI -> VxD API entry point2 m9 @% j4 I' Q% V
add ax, di
* j1 o u1 F1 S1 O test ax,ax( _% L* c3 y) Q1 R; w1 ^
jnz SoftICE_Detected G8 {( E: l2 f0 O: f3 z$ _' m
2 A, c( }8 m- v( Y% P* @4 C__________________________________________________________________________6 l+ |1 i1 U0 M& g
5 J1 {5 ^7 ^" G1 u4 ?
+ X* ?3 @" {% v6 L8 D; v3 r5 gMethod 05
! `7 q# d, ~& w=========, d$ y8 ]9 U0 k5 [4 g9 U8 L! \
, m5 O3 u4 u7 z# I& g- I! ~: ^& C0 IMethod seeking the 'magic number' 0F386h returned (in ax) by all system
# \1 t! |* s& \3 \debugger. It calls the int 41h, function 4Fh.
' h6 H7 C, T6 k# N9 r. xThere are several alternatives.
; J4 _; C0 }9 r/ O, @) l- R. a3 J1 _+ \. Q F
The following one is the simplest:
3 R1 j; K6 u- \2 o$ B: H( E5 s1 k, a6 E1 B- @7 n
mov ax,4fh
. M( Y* U3 {: N7 n& c. A int 41h0 A! ?; G8 r+ I" \# I
cmp ax, 0F386- m d# Y, ?3 [- ^$ Y
jz SoftICE_detected
4 G: \: z, Q1 X5 L0 E' q4 r2 S% Z
+ X6 e/ e, O# Z: W: @ m w7 R
8 H* i& v( B# r. K9 n- x3 uNext method as well as the following one are 2 examples from Stone's 4 B7 }. Y) d& v
"stn-wid.zip" (www.cracking.net):
. h: A) {6 {1 Q. m# j6 y4 @( @. t4 \; ^6 d8 R$ t
mov bx, cs
5 p* P, v/ @; y, U! @ lea dx, int41handler2$ g. I+ n; p$ Z. k! c
xchg dx, es:[41h*4]5 k3 Q. V% c7 q q0 ^$ v, _ r
xchg bx, es:[41h*4+2]
9 i# \# }; h K! R m% D mov ax,4fh1 \2 ~2 M& e$ x2 `. V8 g4 D7 ^+ v9 ^
int 41h# L9 w) @) j7 }/ i: l
xchg dx, es:[41h*4]9 e8 n7 R+ E$ {
xchg bx, es:[41h*4+2]
+ R2 c) q& \& p0 J9 h cmp ax, 0f386h
. [' N; j- v! W$ c6 K( J! u jz SoftICE_detected" @! n. D Y* a" n$ ]& W5 ^
# v& @4 T o& D
int41handler2 PROC
) G+ z0 R2 L+ t, n4 p, _: m; v iret
. k$ w& c+ y- I$ }int41handler2 ENDP
# k* y0 F( P) K2 `3 m- y, _; e
& v$ t( r( E8 _6 A
+ g$ f& q+ Y! ~! x1 b4 X_________________________________________________________________________
2 E% E/ s' j7 ~& O- B: F- i5 H4 q& ?! o% p; P9 \: S
9 L2 ]( h. \, `0 D4 YMethod 064 }" h2 Y. r+ z& \- N
=========
4 F# c2 v" c3 H, p
$ _; e n9 e# Z u) t w. E3 T8 k# c9 ^" l) v4 Q ^4 V
2nd method similar to the preceding one but more difficult to detect:4 ]3 m& y7 K$ @4 ~1 f/ M( Y# A, l. ^
) @( a* q- a1 P' [
3 [+ ^+ `+ B1 M# N& p% {$ Bint41handler PROC
3 X* x) V1 c$ A! w: Q mov cl,al
* t9 K( k8 h: u8 o% Q# \" ?8 A iret; J X9 I* k, |7 U! Y( {
int41handler ENDP0 p0 k, q j; k6 ]. i2 k2 L
$ R9 j* y/ i* | {
8 i, d% M4 o- t5 e4 z' O0 d
xor ax,ax
; W6 P1 g" w: k mov es,ax
6 B9 j" x0 d6 ?7 F7 L mov bx, cs5 I% K) ~$ I2 A/ z. Q }
lea dx, int41handler
1 a1 h+ s2 q/ G# z7 S6 J xchg dx, es:[41h*4]5 k8 x, K; v) G% I9 }1 d' A2 U- {* Q
xchg bx, es:[41h*4+2]4 `+ n S4 a( {! H+ q
in al, 40h' z) z# U) U# |1 g
xor cx,cx
' c% Y# o- w. j$ } int 41h
6 d; K1 P7 X9 A) v; U6 ] xchg dx, es:[41h*4]
4 y* u+ W) {! ^* j# ? e xchg bx, es:[41h*4+2]! Y4 J' p, y* S" Z- b
cmp cl,al0 K3 d5 u! B1 g# }. T8 \+ D
jnz SoftICE_detected
& ?% ?. j) }6 Z9 Z& f) f1 R8 y! j# ~! ~2 a! z9 V) n" C
_________________________________________________________________________& y9 g- a2 \+ h/ O! A7 D
6 L1 s3 G$ m5 x1 Q# z: zMethod 07! ?4 |; k q+ v* N2 c
=========
+ ^! o+ q1 m1 ^9 S8 w
) q$ g) k1 g2 o. J& j2 P4 n- \Method of detection of the WinICE handler in the int68h (V86). O7 ?- G) p7 L* ]* y
% g! L4 W& V% F# s: ^9 D; h; y mov ah,43h
W0 C0 v# @; h" X int 68h; N8 u- Z' X6 {. [
cmp ax,0F386h
9 o" ^4 K9 T* U" C& f' a jz SoftICE_Detected
0 v) ? M% ~: w/ c5 _
7 }, {$ O4 E' v8 Z5 E% r3 ^
! Y. U, L+ Y2 Y& d* Q=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
0 D$ B/ x3 g' T# M+ u9 u& @. e app like this:$ [2 U1 C: A E6 W6 y9 R t
! C! G- G( j$ b7 g* B
BPX exec_int if ax==68& r2 _6 p x$ `$ y
(function called is located at byte ptr [ebp+1Dh] and client eip is
! W7 t ?, G8 n6 W$ W located at [ebp+48h] for 32Bit apps)
; s& L3 A& z$ j, @+ X: C/ l__________________________________________________________________________. S# _- s5 u. b2 K4 m
/ i2 h6 i: O8 S0 n1 Z S, m4 }8 c" W. j2 T' U; c
Method 08
7 n$ c) s, ?! F% T=========
3 |( i/ f* x0 Q; ^. C' |0 V/ d p0 q5 b! S3 p( ]
It is not a method of detection of SoftICE but a possibility to crash the& l O5 V w% i- C: N
system by intercepting int 01h and int 03h and redirecting them to another
' f) Z9 v# U. Y; I2 _7 wroutine.
9 O4 m6 E6 Z8 m0 f& k& gIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points( z3 e% B; i S O7 O' L
to the new routine to execute (hangs computer...)" D) {+ u# S2 J$ H; b
: H* @# y# }% _7 Q, }4 e6 @
mov ah, 25h
/ ?/ p0 J1 ?9 D/ Y8 s0 C5 W mov al, Int_Number (01h or 03h)
; I1 j; Q+ |2 c" w8 Q' \7 K mov dx, offset New_Int_Routine2 T( u- F. W4 `8 Q( E( i
int 21h
, h6 `. [+ z* Q2 x0 F0 e# s: `% ], Y
2 D; p9 t5 j$ R$ L2 t__________________________________________________________________________2 Q9 [6 S/ T* k: Z5 n
6 g. O! \5 p& |' {* Z) K! Y: xMethod 09
6 {4 L6 ?* f, V9 C=========
4 u0 N8 a1 }' u# l5 ^7 d, u: i$ d4 Y# t9 c
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
) a# i/ B1 h! j3 u) f- S) O* Gperformed in ring0 (VxD or a ring3 app using the VxdCall).
5 }/ H, K9 {+ F3 E% w& H% jThe Get_DDB service is used to determine whether or not a VxD is installed% x) h" Q. b* z
for the specified device and returns a Device Description Block (in ecx) for( k1 o% q- E/ ]( S$ [ @
that device if it is installed.* d0 V6 c/ ?4 s p5 B& z ]7 D! N( G
: V+ f2 D$ j8 R' k2 F; O mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID( t T F7 Y. q0 c
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
6 v: s5 x' D4 I/ \6 j* I VMMCall Get_DDB$ n" Q, [" k# O. P
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed& _2 V4 R! l" y$ C
' Q. d6 |* q" r2 X4 g/ a$ K
Note as well that you can easily detect this method with SoftICE:& ?, h2 z, w( u6 K4 {3 A
bpx Get_DDB if ax==0202 || ax==7a5fh
2 q, m- X0 B! k; ]
" V1 T/ L4 ]- `9 l% W! c' F__________________________________________________________________________
! \) J, f% f. H( c! K, }: \1 T3 x4 Q3 Y, ?# [" k1 a
Method 108 ]* B0 N2 f) r. s6 ^& q4 a' Q$ y
=========
) }9 c( [9 p( x' n7 j
9 A; F P. e. {0 [! _% Z1 z=>Disable or clear breakpoints before using this feature. DO NOT trace with9 ^2 u {+ ?' b0 R, U2 d
SoftICE while the option is enable!!
2 U: }! N5 T0 J1 {" G, v8 V% L! y! A6 K
This trick is very efficient:
B( R! \$ p) q9 Wby checking the Debug Registers, you can detect if SoftICE is loaded3 o8 t. E5 {* ^( M) u
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
' j7 ^. Q% U" L- D/ zthere are some memory breakpoints set (dr0 to dr3) simply by reading their: M5 B9 o* Q) s( l7 ~4 A
value (in ring0 only). Values can be manipulated and or changed as well
% {, c- x+ H6 Z: F4 x& q' }/ ](clearing BPMs for instance): M# G) Q/ {' G! P1 c2 y1 j6 b1 P4 L
% \$ m+ o: {; y" Y" {4 v" K__________________________________________________________________________' h0 \3 S- D; c
# d0 s4 P! @! j0 [7 g
Method 11
- Q: O2 x+ j* G) I- O u=========
6 Y; i1 [8 w4 a* l' b1 z$ p/ S6 G: w4 w* {; a4 `' |7 m
This method is most known as 'MeltICE' because it has been freely distributed3 U9 C2 B# [+ i \: j
via www.winfiles.com. However it was first used by NuMega people to allow1 V- S- o, a! l9 T4 S e, J
Symbol Loader to check if SoftICE was active or not (the code is located
4 f' S. w- M7 S4 Z, D4 N) H9 g# C# S; einside nmtrans.dll).0 }$ o2 n2 u# W8 {
7 A! u1 W0 H! g
The way it works is very simple:
4 p" y8 P4 V* ^0 r" h iIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
$ h/ O. n' C' s6 @WinNT) with the CreateFileA API.
8 y: }5 ]1 ` t% V k; `9 m0 i s' k( E0 Z3 ]
Here is a sample (checking for 'SICE'):$ ^$ d2 F6 X% `
; i- K" G# z1 G; i5 D+ kBOOL IsSoftIce95Loaded()
7 A1 V/ f$ M* Y{
, s* {: C6 T. k" d- u+ b$ w& f3 [+ G8 f$ K HANDLE hFile; ' F% u5 q5 s4 V! q1 O( D
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,% |# V5 n' {! o& w1 o
FILE_SHARE_READ | FILE_SHARE_WRITE,6 B+ j% k- a) J- p ^4 G4 B4 i
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);( f; Y& O. p6 C* U% g* ]. P
if( hFile != INVALID_HANDLE_VALUE ). r; i8 D: @& l J
{0 E( @; W3 X7 _/ B; N' N
CloseHandle(hFile);
) j9 u5 Z# q2 r, e. x return TRUE;! o+ p% g& l* y2 J! E7 c
}
4 v$ J5 L7 h7 E% {0 d return FALSE;
0 A+ M V X( A% s/ r}
. z- R. ]8 e' s7 C+ A# X7 `, B8 i' n9 ]- ^/ X# L4 C# r" l0 B1 J
Although this trick calls the CreateFileA function, don't even expect to be- X, J* k& \' E1 k/ d5 t
able to intercept it by installing a IFS hook: it will not work, no way!8 [) a8 |& U/ U6 E& W
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
- G+ d7 e4 h, M( Y& Kservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)% W+ V; L1 L3 ^4 `9 Q7 v5 L
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
8 K6 g+ @# S3 }* A- X- G% ? h6 xfield.
7 O; P* S7 s4 z2 V m/ u4 I: GIn fact, its purpose is not to load/unload VxDs but only to send a
" g1 v5 h! q3 f5 B/ J3 hW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)# Q D6 x2 A9 F) U; t6 h- F' e8 i
to the VxD Control_Dispatch proc (how the hell a shareware soft could try, D% Z1 ~# _: A2 f G$ r6 S+ }4 d
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
; a) k( s; A. W. f5 r5 GIf the VxD is loaded, it will always clear eax and the Carry flag to allow
- P4 S. A/ n9 y! K, c5 J. h8 cits handle to be opened and then, will be detected.
* Y3 Z3 H; v9 u$ MYou can check that simply by hooking Winice.exe control proc entry point, I) H# d( U" b+ e. f6 n( x/ R0 C7 T3 e% B
while running MeltICE.
* z. U: z# @) q" e1 l1 f/ _2 ^9 \2 r6 x. J! R5 g& e7 W* i
2 x& l. C- W+ o% N6 H4 ] 00401067: push 00402025 ; \\.\SICE
9 ^* H9 P! P1 m" _$ R 0040106C: call CreateFileA
! M) }& g* j" k! a( J0 ] 00401071: cmp eax,-0011 \! x( f! P4 m' l* w
00401074: je 00401091
) Z1 z; B2 U. I0 i$ T' s9 U* F# O+ X! D/ D2 ~
; `$ |( ]5 S! K) N) iThere could be hundreds of BPX you could use to detect this trick.
" k: X( r3 r! A4 Z-The most classical one is:
$ ^! j: f9 w/ p/ t% x BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
( P8 q& B7 Z" H- { *(esp->4+4)=='NTIC'
+ Z7 \3 ?" Z) f# V$ b* n( y, ^) T$ m+ d' r! I
-The most exotic ones (could be very slooooow :-(
% z% f: c' }' Z R8 C. |; X; y BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 7 S _4 a! J" L
;will break 3 times :-(4 P4 u) D" H/ M( \: n4 }6 r
& L' F. j; d$ `4 i-or (a bit) faster: % U. q6 _- \# Q, \( x+ D0 J
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
7 C# J" {' g( y1 p. L u( D' `' P. `. k5 {! _7 B. w+ K
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
+ Y$ X. q% q. F6 j; u5 R ;will break 3 times :-(1 v" f% U0 @1 g( i4 P( ]
7 \0 G6 k* ~. @8 M5 F* c8 h; T
-Much faster:
2 C& k0 o+ s* I0 L; ^- j: D BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
/ c3 y% v6 q$ x8 O& } Z5 [
. ` U) P' g7 |! xNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
# G' J+ ^% Z3 ffunction to do the same job:
+ N/ ^- m3 a7 r! K; q9 F K( z! R. R" g
push 00 ; OF_READ$ Z- T5 R8 j: F1 f2 {0 D
mov eax,[00656634] ; '\\.\SICE',0
& C1 g. F/ A6 d# [# E4 r' ` push eax
6 i4 v2 _6 }& p! w* t3 R) Y call KERNEL32!_lopen
- ~8 Y; b1 `9 p- P inc eax& C, b; b, P4 F# {. Y8 l
jnz 00650589 ; detected' \" V. a7 X; Y+ o3 i) R
push 00 ; OF_READ# L7 [& u6 X3 }" W. {
mov eax,[00656638] ; '\\.\SICE'* `$ e9 A7 f" V: t1 K
push eax% G( o5 D* B' i) _, h+ p
call KERNEL32!_lopen
+ Z, ?5 H8 F* L, `+ N8 s' Y inc eax! I7 t* Y Z# J
jz 006505ae ; not detected
" Q% R p/ k. ?; @3 S) x, A5 @% A: w0 ~
- Z8 p1 e% @% S5 p/ ~4 \
__________________________________________________________________________
* [8 q3 Z5 I% e- ? P5 G1 E. ]8 E \+ | Z- k
Method 12
1 [" L( L0 b7 N. u# o=========) h# x7 ~! F4 O( B+ j
9 s! t! e( d$ \
This trick is similar to int41h/4fh Debugger installation check (code 05/ k* N0 G) |6 `* o, v7 m
& 06) but very limited because it's only available for Win95/98 (not NT); z( ^7 {5 [( ]: U! F
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
R1 @' Q6 D6 n+ h: _* d: D
4 d6 @4 a. p4 w) e push 0000004fh ; function 4fh
3 r! I, J4 j* Z0 N/ U push 002a002ah ; high word specifies which VxD (VWIN32)
1 P# D. [1 K! p ; low word specifies which service* w" d9 Z7 @% R! W2 a! `
(VWIN32_Int41Dispatch)
% `' J9 V' D$ c% P7 y- o( o call Kernel32!ORD_001 ; VxdCall
+ J( E1 F$ a ` x: }, A cmp ax, 0f386h ; magic number returned by system debuggers' W* \, E5 s- Z: Y, j
jz SoftICE_detected
) h$ A! h$ q1 g4 G v: v" i4 o1 W3 d1 x e$ X- {9 ^
Here again, several ways to detect it:
5 d# r, p, A$ S" f1 U7 T8 F& k! f$ i0 W( v+ E& a7 C) y
BPINT 41 if ax==4f: Y: D' E: g4 k* T
0 y7 C. E& x2 t$ x# ^ BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
* H! X4 S" p2 u, J6 m# T2 i9 t
+ C% a, }" C' B BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
* G! p3 E3 z" o# C8 }
/ n1 A6 @6 a/ ]5 G0 Z r. \+ n+ _ BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!; G J4 K! F+ e4 U8 Y
7 o& t/ V5 g( d, m__________________________________________________________________________
& c# S0 [6 ^3 b$ r1 {% e3 g1 g- O# L" [2 w2 S' a, t; G. M- R) B$ q6 {8 l
Method 13
! M% y6 ^* J. `- T=========3 |- }* c& }, Q9 O# i
' d5 \3 T1 R# K1 e- t
Not a real method of detection, but a good way to know if SoftICE is, M! y5 @& r1 N* ^# h
installed on a computer and to locate its installation directory.
. C4 K5 N+ S" V' E: {+ eIt is used by few softs which access the following registry keys (usually #2) :# m+ X/ X, }- O1 Y2 z% h) b7 ^8 L5 a
+ G) B: n- x( e- \-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion9 T. _& k! p# Q( W1 S
\Uninstall\SoftICE
# r2 T) r+ \7 Y' J v-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
* d7 ~3 q% I; |6 W& t-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
% F- h7 ^5 S/ k) q! E# _+ ^\App Paths\Loader32.Exe, C- t* j6 b( S' }* V4 e. q
; A, t3 S" e( ^+ Y5 Y) w/ R( e0 ?& z2 c1 ]8 {8 ~ H/ c
Note that some nasty apps could then erase all files from SoftICE directory
$ s1 O% {8 r* G' P" b5 S& f8 s(I faced that once :-(
$ |# z* E0 l: P n- Q
" n5 x+ t2 b3 }7 V9 G' jUseful breakpoint to detect it:
R* R( x. y6 L4 @/ o
( g6 e5 u* g, F BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
: m0 b# R9 p# R7 B3 U6 ^- x1 T) W7 m" T5 t8 U
__________________________________________________________________________3 E5 o# F8 j6 N* }) B
: {: l: [7 Y. V1 b z! |) Q
5 a! J9 M! a9 d+ H5 R+ V; CMethod 14
9 i6 ]& V$ M7 I% p=========3 S; k3 ~$ l. Q! l0 l! a
" V2 G# Y- A. W' WA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
; g$ B5 v# X% g+ p* mis to determines whether a debugger is running on your system (ring0 only).
! z, P2 S( K: b+ S( U: t: I7 n. K$ |
VMMCall Test_Debug_Installed
% x: f& j+ B8 o- z! A: b8 z Q: O je not_installed7 T# i" S# H, `9 j
# I" I# N1 r+ g. O. yThis service just checks a flag.$ A# K" ^9 @$ _, }
</PRE></TD></TR></TBODY></TABLE> |