<TABLE width=500>' j# Z8 B4 f( Z3 U9 d/ _5 h
<TBODY>
, E4 v0 N3 n5 h" r; o) a& i( L# g<TR>
' y& P' g) U* u: E' x4 O, P<TD><PRE>Method 01
/ |( W7 M3 K/ M: z& O5 Q5 x5 I! `=========3 S6 x7 T, R2 R5 G7 b5 U. y! o
7 [+ t# Z) P5 A/ PThis method of detection of SoftICE (as well as the following one) is
% J$ h8 p2 ~- `$ ^used by the majority of packers/encryptors found on Internet.
( m: j- x1 A: O0 W0 k3 t( O/ `* }' \It seeks the signature of BoundsChecker in SoftICE
' C& O4 S( V7 ^0 W) v" N% @
& Q$ Y& o0 C. O' G7 O+ F1 k+ G+ n mov ebp, 04243484Bh ; 'BCHK') h" q: @. r* H6 R# i
mov ax, 04h
$ ^- r {% u* c- [* U$ ?, ?& u int 3 9 C+ u- L% ?2 g- J6 l& q
cmp al,4
& X3 F, N6 P. D: ]6 E$ n9 q jnz SoftICE_Detected( D; v8 a2 L8 l- Q$ L a) m( e
: ]0 l+ Z2 ?: q5 D5 s8 Z
___________________________________________________________________________
( i# E7 @* e" n1 r- U2 s9 T, s; T) B/ M1 F
Method 024 z* d' k. j. i: p4 f% X
=========
# t, E% }' ^/ \3 C9 m8 W$ v- Z/ T' d" f! n$ V7 x" r
Still a method very much used (perhaps the most frequent one). It is used
0 F* V1 H. _1 `to get SoftICE 'Back Door commands' which gives infos on Breakpoints,5 F% H2 \" w* }8 w5 @8 ?/ |
or execute SoftICE commands...
0 ]" i) F7 e+ s9 F& VIt is also used to crash SoftICE and to force it to execute any commands
. A% W/ O- }" P(HBOOT...) :-(( # X' l+ E' l) |1 u5 [, r2 d
4 Z- s0 q. f2 v) u# v& _Here is a quick description:- |+ f- _% ]' e. {7 J1 `7 ~0 W
-AX = 0910h (Display string in SIce windows)( {: d1 k: C4 D: J
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx); ~3 Q+ A& U( k* }0 Z6 Q0 R& U7 M
-AX = 0912h (Get breakpoint infos): L8 u0 p9 X, M3 L# c" e2 R! y( C$ H v
-AX = 0913h (Set Sice breakpoints)* z% o* O0 k! d$ \# s
-AX = 0914h (Remove SIce breakoints)/ m8 { Q8 t# N: _ h$ P
' A2 M. T4 I) M; X; b% d( [1 ZEach time you'll meet this trick, you'll see:4 G$ V4 z R7 B0 s h5 c0 {8 k
-SI = 4647h+ y# l. w7 {, j9 w0 q: R
-DI = 4A4Dh% c9 \ Z7 \2 R. v' e
Which are the 'magic values' used by SoftIce.
+ z6 b g1 y( Z+ J4 @For more informations, see "Ralf Brown Interrupt list" chapter int 03h.* k$ B q) l. W# J/ s% z1 F
$ ^$ P7 m7 \7 b6 O7 \
Here is one example from the file "Haspinst.exe" which is the dongle HASP9 W: d* m, ?" S5 _( F2 y5 M7 C
Envelope utility use to protect DOS applications:! f8 O3 K$ O+ K; ~
5 ?5 P9 i' L) |. U. n7 V$ B& J% L
, C5 w9 V x2 b4C19:0095 MOV AX,0911 ; execute command.
* @8 _& V. _2 ?. M: I4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).- v, b% D+ l8 `
4C19:009A MOV SI,4647 ; 1st magic value.# ?9 c; }; p% m, T
4C19:009D MOV DI,4A4D ; 2nd magic value.
# o6 r: a! k/ w: V4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)6 p0 K$ N2 t. S: W' R' {% D; x
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
. U7 }% G+ Q7 ]: f" m4C19:00A4 INC CX
[& s3 P! c9 D% j- s4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
5 \% g) @" _3 M; X4C19:00A8 JB 0095 ; 6 different commands.
9 j# `2 }$ w* p1 j+ `4C19:00AA JMP 0002 ; Bad_Guy jmp back.0 J9 \7 i) j: F! P5 `2 i8 I
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
9 D& \+ j) Y" j, S3 s, J& l$ d6 T/ i6 o
The program will execute 6 different SIce commands located at ds:dx, which' o; R# r9 c, }# e3 d
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.+ G* d+ ^9 G% Y$ o2 H. {
( y& Z" a& G D: `/ ^" w
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
$ o/ H- k1 M" u) B___________________________________________________________________________' u* V+ g$ P' I! j# g, m
& y4 b4 i! x6 |# c/ |
4 P. U z9 q) jMethod 03- N( k$ U8 Q' S- K/ [
=========6 t" W r+ c9 J) S
* c* f( M( `* G) [! S8 s% Y3 }% jLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h' v" q$ i" ^; q; k
(API Get entry point)
3 b6 e2 E0 y! q5 S/ p
* ]$ E1 f! `7 _: W; z) h% W7 X2 t/ ?1 q2 g+ s1 k
xor di,di
# F4 j0 m* ^( V- k+ m mov es,di" q/ h" l y% _6 R- u
mov ax, 1684h
; k4 V) b( Z; R1 F mov bx, 0202h ; VxD ID of winice% S8 w$ S, J2 C0 P% u3 `' D
int 2Fh
/ F$ V, U/ j0 U! r mov ax, es ; ES:DI -> VxD API entry point6 D# S/ }( ~. ?& R4 G( [2 Z
add ax, di5 U$ r0 I, d) E/ ~7 ]
test ax,ax( U! G" a" t0 P1 z1 V9 P
jnz SoftICE_Detected0 K. L! Z+ Q+ |4 O1 ?1 [, [
; \& F* e* o4 a2 L) v4 w& N: m3 e ]
___________________________________________________________________________" \) ~2 Y9 s' v3 e
& P7 a8 h/ @' q' e" H
Method 04( @0 J5 [, F% J: o
=========
. t, Y0 r" s# M4 J; Q1 H: m) @6 ? |& O$ l6 ^1 g
Method identical to the preceding one except that it seeks the ID of SoftICE
" d9 A# L8 p; ^, }/ ]GFX VxD.
* i$ P0 q0 ~7 Z8 L; V
% [0 z! _2 j2 S( T* C+ ^ xor di,di. u7 ~( t' L# ?' v
mov es,di
% i# @5 \' s" s, Z! k) [- Z0 E: z mov ax, 1684h
, g# t j0 l$ r/ L0 M! T mov bx, 7a5Fh ; VxD ID of SIWVID
. [4 F" _/ u. ^6 K# J int 2fh
9 I G* W$ s& p+ I' K5 ^- G mov ax, es ; ES:DI -> VxD API entry point
1 O; c6 }% I# V. T' ]% h add ax, di
6 N2 M! B) U& p7 V test ax,ax( G# e4 q3 i* a# H E
jnz SoftICE_Detected7 G, _( G5 i8 }) d4 I
; p. l7 g) L" Y3 [
__________________________________________________________________________
, h' S2 x+ j! Q5 f% K$ ~/ ]
) ]" x9 m+ Z. z+ A, u$ `2 J+ w' Q, w2 v* V* H9 ]* L* X
Method 05
( m; I+ {+ |! x" n=========
0 ]0 ?" E2 D2 u. L. Y4 R+ H d: f2 m y7 y
Method seeking the 'magic number' 0F386h returned (in ax) by all system
5 F3 j3 i* B( | qdebugger. It calls the int 41h, function 4Fh.; g8 S5 j$ |) g4 ~
There are several alternatives. ; M0 ~+ g- g0 o- S
# b+ q9 N' J7 i2 F7 c6 j7 \The following one is the simplest:2 x( R t. v5 l6 o9 k6 a6 f
! E- J# \% b1 @
mov ax,4fh4 N# t& ?2 R- H9 a! s3 P4 F
int 41h0 E: d) e8 b8 L% A: x
cmp ax, 0F386
6 e" p! f$ o4 v jz SoftICE_detected1 V4 M2 y4 `5 K! t F
( |/ L6 w6 {- ], X y; p
, D+ k3 \/ W1 x" Z% d
Next method as well as the following one are 2 examples from Stone's : k( b' B& W! K' L9 s
"stn-wid.zip" (www.cracking.net):: ]6 G+ w3 n( i# `' C1 T
& B7 x# z7 h T5 T/ d" F
mov bx, cs
( V1 B& s; H+ M1 X lea dx, int41handler2
: w$ G" ^ q( A xchg dx, es:[41h*4]; {* I7 d# R8 ^, ` j3 L, l4 C. S
xchg bx, es:[41h*4+2]& x5 ]$ x5 U8 a2 Z9 [
mov ax,4fh8 k* p4 c3 i! v7 B, ~$ h
int 41h' Y0 U$ l8 l/ e" c
xchg dx, es:[41h*4]
1 J5 `' s) W& _% A1 V- h7 w xchg bx, es:[41h*4+2]9 `0 w$ m$ f' }; J" |7 y+ K! L
cmp ax, 0f386h4 A# }0 ~' _ [* I. J( e5 } i
jz SoftICE_detected: [; I( L' U/ V4 ?& P+ W
% B" J4 j9 T) }6 O" k8 p% K& G4 S0 J+ Uint41handler2 PROC! K; X# \- |+ t W( p
iret/ @7 }# ~% N8 a: T+ N' X
int41handler2 ENDP
4 k1 K' z+ S+ Y4 d( y" C" P2 ?
1 P/ K3 y z* {( s' u
2 R& z# f% j" Y, p# L! N$ Y_________________________________________________________________________
4 o7 T! |9 Q: H% c+ S. I! V4 {9 s" Z
/ I& D: J% H7 A2 HMethod 06; T W# k3 N6 P4 p( d
=========
% r: k' z5 {' z* O
. ~: `4 h8 e/ g$ {2 L" U' V& n" l$ `3 @2 z
2nd method similar to the preceding one but more difficult to detect:
+ W3 m8 _, S) A: h" Q7 O2 Z7 U) J4 x2 a- x/ y3 d
: i! f$ j5 E+ b$ c
int41handler PROC: H; O( {% C* \2 S2 i# x8 t; E
mov cl,al
6 ?7 j; L7 t7 d- g1 k iret
* L2 J1 `' E: c' B! P; s6 O6 oint41handler ENDP
1 f# X! x. |/ v Q% F1 F2 c- S: S/ Z) X# v" E
$ i9 o5 R; ^& `% `5 R; a
xor ax,ax
8 k; t. _* T8 H: p3 Q8 Q3 T mov es,ax9 d+ _; g/ k0 i3 A0 ~& J
mov bx, cs. w* c: g2 J1 X: T
lea dx, int41handler- N; D9 Z) C. c! J
xchg dx, es:[41h*4]
X% Y2 ]+ V4 H4 a xchg bx, es:[41h*4+2]- ~- r. X" O* O; k0 C/ u) t* G% y7 c
in al, 40h
+ H2 j2 P2 L) A& i4 I- A; K3 m1 f! G xor cx,cx: y" C# M* u9 A
int 41h4 z8 `, Q! ]' o/ ?. A$ Y3 N$ l
xchg dx, es:[41h*4]* D/ Y0 d1 f" a8 I; W: Q
xchg bx, es:[41h*4+2]
8 c$ _) b- N$ ?3 o3 Z cmp cl,al+ U; y; F Z3 B- V2 b
jnz SoftICE_detected2 o/ N5 N: Q( c+ ?! k7 \% J
" |( F0 p0 |; ?) F_________________________________________________________________________
; Y0 A2 @, |$ i6 o# d
4 g" H' f: O6 A. D2 Q9 fMethod 07
5 T' F: z+ z5 A7 @6 I=========. c6 a+ @2 Q5 ^
% @ {: U' h* K
Method of detection of the WinICE handler in the int68h (V86)
; `- P# ?; ^" g' G x# J1 [ X4 D! {1 M7 R$ T
mov ah,43h
3 t* e* m, S/ j, Q int 68h5 O- Y& @: z' [3 l( S5 k( C
cmp ax,0F386h
9 X% q' J6 ]/ L- k2 r. l jz SoftICE_Detected' j) [: {. E. o$ H/ m6 s5 h5 I
4 u# z9 I" b) w! Z, L
0 n' \$ s" {! M. J=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
Z/ h$ j# A5 z1 @0 c- m app like this:
/ q, M% E7 F0 r( z$ i3 i/ M0 L" Q& F6 n% i) @. m7 }
BPX exec_int if ax==68
9 x* K+ e* Z/ j (function called is located at byte ptr [ebp+1Dh] and client eip is
) J) _7 D2 F) @' p6 _/ ]+ m located at [ebp+48h] for 32Bit apps)
1 K( } b" U# e* x+ |! V- v; c1 }__________________________________________________________________________! C! `5 z% f# c' f% Q3 G' G$ Z
1 C7 }0 |/ |: T8 {1 M/ ~ w* D2 ^
/ a; K) a4 v% \7 NMethod 08
/ Y9 e5 E% t5 n ^4 p" Q=========6 L3 [) a7 m: ^% r! l( K8 u
& j% u$ h5 n2 C% g9 C0 Y8 k
It is not a method of detection of SoftICE but a possibility to crash the
! e5 M% i; q+ j; C* }% G* z5 Asystem by intercepting int 01h and int 03h and redirecting them to another
4 o7 Z Y4 X! V# yroutine.
% O9 B7 v5 S* @8 f: wIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points3 Y+ ]2 ^- o- B8 V" O
to the new routine to execute (hangs computer...)+ b3 O0 E! L, D" Q1 Y
2 m) z3 S" u% A: {/ }
mov ah, 25h
/ {4 V+ A% E3 Y4 A3 h: D" Q mov al, Int_Number (01h or 03h)
' W5 ^ v) t& }) e mov dx, offset New_Int_Routine2 w2 @# S6 Y/ p1 B: K
int 21h
8 d" C- x4 h* h9 F$ p2 u/ ?2 I; `, L% _4 U
__________________________________________________________________________2 D! [3 M3 S+ J7 {2 C6 T) r( u% a+ w7 ?! l
/ d( n! m) F( ]! w. O2 A8 u2 O
Method 09
1 [$ R# M6 P" L2 X% O/ G=========
7 Q! V! k8 `: h! y" o0 v* X9 g) M1 X7 C) I5 j3 W
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
+ v! c. ^; m0 e$ B; ~performed in ring0 (VxD or a ring3 app using the VxdCall).
8 w' }/ t' W# t, j* k. z/ s# U9 f' WThe Get_DDB service is used to determine whether or not a VxD is installed: J) o& V% A2 Z1 z1 e3 ~: K
for the specified device and returns a Device Description Block (in ecx) for- J6 S" K" l! {+ ?$ q9 U
that device if it is installed.8 y6 u2 |# C; |2 P3 |% `# R9 Y
& j) w9 }% V3 M8 z
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
2 ~: `2 O' {% v& [5 @ mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-): H g; `2 q v8 U6 k% B
VMMCall Get_DDB% B+ Q9 P# S9 ?, y) F4 Z
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
! V7 O! l9 k' R1 X& ~4 B, m% k+ {+ I/ d3 l6 J$ q5 R+ a7 r+ R4 T5 C
Note as well that you can easily detect this method with SoftICE:
9 V$ p9 f* K& U3 j0 [" Z r5 h9 ^% g bpx Get_DDB if ax==0202 || ax==7a5fh
! B. l, |7 p& _# A
* B0 D- f, e: X# s5 p' w: \__________________________________________________________________________
! P+ F5 p2 l- P8 e6 ^
- H, c% p* ?( A) S H! ^Method 10
: W. L4 A$ U5 a/ @$ i) t=========# A( k# S m* B& r m! i4 ?; z0 j
1 u, c7 O* A* h- b0 p2 I" Q
=>Disable or clear breakpoints before using this feature. DO NOT trace with7 C8 j7 t$ J3 B1 z1 |
SoftICE while the option is enable!! t( l" P8 w$ l/ N
! d C' G+ k" Z3 Z: |This trick is very efficient:. S P# |; E- e% y4 x
by checking the Debug Registers, you can detect if SoftICE is loaded s& l3 G' Y' _8 c6 @( z
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
! G2 E* F3 ]" c1 V8 q- ?: E9 ithere are some memory breakpoints set (dr0 to dr3) simply by reading their
, M. |* ?( \, o- i! a# d; z- ovalue (in ring0 only). Values can be manipulated and or changed as well
5 V: x& J, d' a+ c( d(clearing BPMs for instance)- x0 r" L8 j3 c
! T! Q) K- X; ~% `- C- ]2 `' i
__________________________________________________________________________( E j! m5 ^( M% c9 M$ V
% w- R/ y! u0 G
Method 11
9 K7 _- u M9 I' L=========' B: c, R0 ?2 z; V4 U& U2 s1 X, R# H1 z
- e' ~5 G: ~) q" T5 V, K" _0 K: m9 u
This method is most known as 'MeltICE' because it has been freely distributed
) {9 o8 N: o1 i/ ^+ X% M# _% p) mvia www.winfiles.com. However it was first used by NuMega people to allow
- ^0 b& n8 s9 @, d0 n `Symbol Loader to check if SoftICE was active or not (the code is located
6 }% _5 o4 x- H) v6 z4 P) M$ C- i9 ]& qinside nmtrans.dll).3 U d: x9 B, g9 H" X
( y9 s" x; M3 FThe way it works is very simple:
( ^5 g% Z- t# e& e3 `It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for* u2 E( x' B3 ^! E' C7 h" G
WinNT) with the CreateFileA API.
- s* h u; K* \4 N# S* g; d% a4 l5 S | n+ \8 E7 S- Y& h! G
Here is a sample (checking for 'SICE'):
, b; ~% V8 n0 M) w5 ?/ s$ q3 W$ Q6 P) T/ }, W, E
BOOL IsSoftIce95Loaded()
0 r. w4 B) n5 a; u4 l9 H Q- C! t{
) l! j, {2 V9 {& o3 A HANDLE hFile;
# Z/ {% k7 b: b6 {4 m3 N hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
3 K/ T1 W; h8 w; M+ k FILE_SHARE_READ | FILE_SHARE_WRITE,( d5 U2 j6 ^* J8 N! d* B
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
4 ^/ e1 a1 ]6 |1 i if( hFile != INVALID_HANDLE_VALUE ); m! w2 y/ V$ c G5 Y7 k. _; F
{- W3 Y/ |! T7 `# n# _. O
CloseHandle(hFile);" K+ I/ m0 f: W
return TRUE;
8 h( M3 T2 R) o* d7 t4 N" X, L, f }7 o+ a0 N. [5 P( X' H; e- K1 z! j
return FALSE;
7 W& A- ?0 w- [5 R, P}1 y$ m; e& B1 {: }# R
. S) n0 f: Q3 G' I! U0 j' f
Although this trick calls the CreateFileA function, don't even expect to be) T9 O8 c0 Q5 T; [ H% }. d5 v
able to intercept it by installing a IFS hook: it will not work, no way!9 i# e2 D1 K0 Y
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
0 l( M' B# X5 O! o# l; Tservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
, n( c2 j, y) l6 ~9 iand then browse the DDB list until it find the VxD and its DDB_Control_Proc
: `% D6 A* a& @2 tfield.
( O/ s: g% t% ?: g% cIn fact, its purpose is not to load/unload VxDs but only to send a 7 C9 f- {. ? F) D2 I* W
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE), \; ~/ u- V1 ~9 M7 Q, k
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
/ e/ L/ l. X+ w" v" ?5 vto load/unload a non-dynamically loadable driver such as SoftICE ;-).
/ K+ D2 N3 {" v- U. H Z8 dIf the VxD is loaded, it will always clear eax and the Carry flag to allow
0 o9 p* |- K# j9 G/ t3 u+ H; ^" z) yits handle to be opened and then, will be detected.5 H. a3 n' |" g4 `; V% s7 L0 d
You can check that simply by hooking Winice.exe control proc entry point+ _4 e1 t. _0 A3 f3 F4 L! [
while running MeltICE.
8 b- z+ y. X/ v0 V" b* e1 M2 p7 N5 d
: S) _9 e2 B7 H, Z+ _$ v* P9 `
" @/ a+ `: }. v 00401067: push 00402025 ; \\.\SICE
1 G/ J2 |( r: t- }; B; @0 C 0040106C: call CreateFileA; z p, M# R. ~- j2 \
00401071: cmp eax,-001
3 m3 K3 }5 z9 ~; I1 D/ b. R5 Q2 M 00401074: je 00401091
) c8 ~1 I3 P8 ~+ A8 B; N. I6 c% q8 \
* T$ a' l5 w" p( A
There could be hundreds of BPX you could use to detect this trick.
6 W# p, }" |) v7 {4 v3 @-The most classical one is:" a9 x+ k/ y1 i- c: Z4 \. m8 S
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||8 Q' g: v6 l) j( J$ f- q- Y3 P
*(esp->4+4)=='NTIC'
8 |& |( c; ]; `3 X) i- ~! g, r: W: a; [: p- _# ~+ M
-The most exotic ones (could be very slooooow :-(
/ \6 Z9 i. A8 |5 b7 q) z BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
& f, l; o" d0 p5 B' ]0 G ;will break 3 times :-(: h+ \0 Y, A/ h7 ~* ]% `; H- u
* f4 {' Z) i) C* A: [2 _' ^( M
-or (a bit) faster:
9 T4 r$ ~4 q% t) J9 B8 P0 H BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
( u6 w# z9 i2 {; R( N# \1 ~5 Y
2 [1 K+ q1 O: l* K BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
' P! E; b' E1 s' a$ U, g; ~ ;will break 3 times :-(
9 U! Q5 z- q) U' {3 m. A' o0 v0 U1 n( }, M0 k) s
-Much faster:
7 [* \. m4 y- |. h BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'- W5 o7 _6 Z3 p. O9 @6 C
- ~: t' G; T( X% r8 }# D
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
# K7 M) i# F, Zfunction to do the same job:
" }3 m, C8 s, n7 R, D N
/ k% ]+ o# i/ v7 b- t# ` push 00 ; OF_READ$ u4 @' _8 B3 B! s, c) P
mov eax,[00656634] ; '\\.\SICE',0
' z5 e- g9 J/ j% W push eax$ N' o6 O: E7 M4 @, |& ]
call KERNEL32!_lopen
$ z6 l' \( S1 C5 k inc eax
( G; t/ i" N! |5 O! ^% w" v jnz 00650589 ; detected
?7 v+ T2 H0 ~0 S; w) a0 w push 00 ; OF_READ; L% p1 q8 F' P J; L3 F9 P5 X! X4 g4 p
mov eax,[00656638] ; '\\.\SICE'+ m; A7 ]/ F9 R3 _2 j2 d" R
push eax5 O8 O8 {$ @3 V/ k( q
call KERNEL32!_lopen
+ n) F. z& u0 G8 T/ M9 N inc eax
# \; j3 a: L8 r' K- ` jz 006505ae ; not detected
8 c' t/ |4 l3 [ H
5 j" O$ k/ r4 f) N
# G: Q' k( {& ~+ o* J__________________________________________________________________________
; H& p) x4 S& a, [: N K! l! z% {9 s, p7 K* J" ]
Method 12
. L, w# P* q3 b2 X0 r0 C0 q5 }4 m=========/ g- a4 y& V( ?. A! K
2 G2 ?& u0 z. ]' B |/ jThis trick is similar to int41h/4fh Debugger installation check (code 05: i3 ^6 i3 L$ h# }& h) E: [1 l
& 06) but very limited because it's only available for Win95/98 (not NT)' ], D4 o9 E ~/ X5 R+ `. I4 I7 ~; {3 L' z
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
$ L3 ^/ v2 H; b" w4 W+ @8 ?8 \' ?- f7 k* j' Z) Z# s; \5 k
push 0000004fh ; function 4fh5 `- N a" W& N8 x z; b9 M
push 002a002ah ; high word specifies which VxD (VWIN32)8 H4 `" v9 f* o( S5 H8 e
; low word specifies which service O, t3 U1 j! S8 a t" Y
(VWIN32_Int41Dispatch): u* U( t# a4 l. i: i8 F
call Kernel32!ORD_001 ; VxdCall) T$ c9 N/ k6 X9 Q2 o! M
cmp ax, 0f386h ; magic number returned by system debuggers$ j* ~' ^" T( I! V. f3 {( M
jz SoftICE_detected/ O% j: v. Y, \0 Q
2 N$ s0 L3 H7 m4 o( Y% i4 O
Here again, several ways to detect it:
3 Z8 |. j3 d; O) H! }4 T- A3 N* U4 F* m. |
BPINT 41 if ax==4f4 H; r6 e& O/ x: O7 D4 t, y
2 P; a! B* \9 }% r) b2 S BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one2 n" w- O3 J9 J5 r! G
' \8 g+ ~( ]4 H `9 Y1 W/ E BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A% ^; I! x- ^/ S; b% A
( n- Q0 {+ N: r' J N7 N4 K4 d3 y! O
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
5 z$ w, o" x8 k! r% t
" s- [0 P" F% j6 F$ f__________________________________________________________________________9 Q$ v8 U+ ^) [8 }- Z. q7 G b* K
' i6 R, C! J7 N+ U# T [
Method 13
" e- D# v+ [" d7 G9 W! b=========
' }" `4 R( [: [+ M, r% n. S" l0 D; k1 S
Not a real method of detection, but a good way to know if SoftICE is
. J& v0 a' V; n& V8 Q" X# K( V! ninstalled on a computer and to locate its installation directory.* [$ h' g8 u: F& e) ^0 H* x+ |
It is used by few softs which access the following registry keys (usually #2) :
, }/ r/ u1 c. [# e' ^# F8 Z* X' g0 k
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( e+ [$ H) Y6 q, Y c8 c7 M" ^- s
\Uninstall\SoftICE
2 u0 y0 f0 I6 ]" |1 ]: ~" ^-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE7 i3 n% c1 b% F7 u, I+ b
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
7 G& ]# W5 b# H8 Z4 J' ?\App Paths\Loader32.Exe
3 N0 O7 f8 q! R) `5 Y- Y$ f% U; F+ x5 k0 l
% f" i; t8 F- ]8 n+ Z( ?5 GNote that some nasty apps could then erase all files from SoftICE directory; n; k4 H0 d6 I3 F! z5 p0 A, x
(I faced that once :-(
+ d q7 p, N* B
9 ?; p L x" j' f' dUseful breakpoint to detect it:7 z, _2 o3 y) m; d$ A$ m
( e# B) ?8 l7 P3 l; o- M) C
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
$ U( G) F9 Z: f+ a/ E- R* J: }& M5 b0 X' o6 H2 _3 `8 C
__________________________________________________________________________
4 w" i% j7 Z5 c
8 u5 Z( E1 X; x+ Y
0 y* T. q! S) F/ WMethod 14
. A7 @; A3 u2 c- y* I) G* a" p=========( S9 X x6 a* u! t3 K9 G
9 I; |) F: x# Z j- V
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose, Q* X3 ~* _4 ~) s. e8 t& b
is to determines whether a debugger is running on your system (ring0 only).4 Q" _6 l) Z3 _: w% Z2 E8 X
$ _4 p2 P& ^) S3 g VMMCall Test_Debug_Installed
8 x' Z3 I, V9 [' z$ A/ b je not_installed
3 r" p3 Y& `" `( d/ r8 E9 m1 t+ o6 n# n& _) @' W: l4 s! e
This service just checks a flag.3 }+ ]. M' C I6 E3 g, k2 V" r' f
</PRE></TD></TR></TBODY></TABLE> |