<TABLE width=500>( I3 A1 q+ J$ C
<TBODY>
$ I7 n3 L- k8 j<TR>3 _2 t$ ~6 Z8 Z1 v, e& D" x5 R
<TD><PRE>Method 01 1 f4 R: z2 V H8 `( h) g2 [
=========) a$ m9 a+ A! i# \! d
+ H6 v! P4 |. t9 A+ ]This method of detection of SoftICE (as well as the following one) is
2 y9 h1 p, v0 Y# S I* C9 kused by the majority of packers/encryptors found on Internet.
+ T, b' e/ T( n6 i: X+ `It seeks the signature of BoundsChecker in SoftICE* e6 K/ P" R0 R4 }1 ^# f
m% H! ?' G. J) q mov ebp, 04243484Bh ; 'BCHK'
% h( ?1 a: Y& ]& z) _" X& v mov ax, 04h
: A, T: O- }: [+ |( e( J' L int 3
: c' O8 p9 m6 x8 Y cmp al,40 J" G% w& e7 u' F# P4 O% |
jnz SoftICE_Detected3 c% R2 L. w% p
& X* c1 {7 N. L" g: V% D. d___________________________________________________________________________0 ]. ]+ _) A# ^# q3 P, O9 X
3 a3 B" ]5 h% ^* A3 o/ o
Method 02
! A8 I- h0 i: K$ M0 e4 K=========$ x! @* V6 T' |+ t8 L6 A( m
! M* H0 ^; n6 H4 E
Still a method very much used (perhaps the most frequent one). It is used
6 n* o' r) T( r5 w0 p& K( \, a) n% _to get SoftICE 'Back Door commands' which gives infos on Breakpoints,; [$ d$ m, Z6 c7 j
or execute SoftICE commands...* k/ w: ?% ^1 c5 b* r9 j/ w @
It is also used to crash SoftICE and to force it to execute any commands/ P9 o8 x5 y, i1 j' N
(HBOOT...) :-(( ( k, y0 ~) V7 b" e+ d1 F
' t3 A r( R" F2 \& P
Here is a quick description:
3 q, }- }8 [8 m i+ ~8 [-AX = 0910h (Display string in SIce windows)
7 u* U U* k/ n+ Z3 U! M3 Z-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)! Y+ L, U/ g" O9 U: q3 a
-AX = 0912h (Get breakpoint infos)9 ~! p) \+ B% U' k$ q" f
-AX = 0913h (Set Sice breakpoints)
9 I# }/ l" t( ?0 h/ d-AX = 0914h (Remove SIce breakoints)
' |9 o5 p* ~, l: P3 i' ]6 h! F& @. k7 h5 F+ S* @) j+ c/ ~ m
Each time you'll meet this trick, you'll see:
. t0 V6 i6 I6 K- ?-SI = 4647h
4 T4 K* ~% V8 z* R. I% _-DI = 4A4Dh
5 T8 t& G. H8 b9 DWhich are the 'magic values' used by SoftIce.3 ~" f3 o0 k& ^: ]
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
$ x+ X( _5 Q1 z, F* l. ~
" J7 x7 s/ i) O2 MHere is one example from the file "Haspinst.exe" which is the dongle HASP
/ k, I; G( ~' @ K. C4 z1 LEnvelope utility use to protect DOS applications:
5 h+ h6 L4 y" c* U( [
6 c. K! L' w8 z4 ~$ H; A" T( u
4 q3 G1 F2 y" T: S- B4C19:0095 MOV AX,0911 ; execute command.
0 ?+ n6 ^# c A$ h4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
4 p2 K: q3 P: x( h9 o: ~/ U4C19:009A MOV SI,4647 ; 1st magic value.
2 x0 ~# P& a! C9 v6 ~% U4C19:009D MOV DI,4A4D ; 2nd magic value.
- I9 x5 G: [7 F4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)9 W# h# M; K. E5 Y8 u4 G, ]
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute/ V! m- G9 n" Z4 _6 j% _8 ]
4C19:00A4 INC CX4 p9 g5 q, |" Y
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute7 [5 z2 r/ v) x" p; B: V
4C19:00A8 JB 0095 ; 6 different commands.
# P( Y% v1 ]" b' ~4C19:00AA JMP 0002 ; Bad_Guy jmp back.
+ `5 Z+ q" q% G% M4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
+ `' N5 O) p+ y; B8 F; _1 J6 A' b$ J3 ]8 f3 n( }' F6 O+ c
The program will execute 6 different SIce commands located at ds:dx, which
" j, @# z4 J; F& A. B# O, [% sare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
3 j8 b. }' d7 \' G% ~3 {* U7 E' m1 l$ K, {" l/ ?: }
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
; D1 U. k: x4 A t; U" W' |$ z___________________________________________________________________________
+ R3 @. G2 @* k4 W, @( e7 [6 j. a* Y* m" w+ Q
# g# p a" C, s/ q1 a
Method 03 W) c( D1 U+ n$ [/ P3 ?$ I9 j
=========) w6 i# j% Q$ e4 B" h
8 c& [$ ?. j0 a, T0 c+ ~Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
+ C* u, ?$ i5 C5 E3 q(API Get entry point)9 T& o; i K1 ^
7 F7 G$ w& \7 L
5 T _6 p) Q0 ` xor di,di
# K3 A1 U4 s+ T6 e/ a! x- j" o2 x mov es,di
0 E' r+ v; P( L. l mov ax, 1684h
2 j0 a; N% j' N% s mov bx, 0202h ; VxD ID of winice
`/ G5 T. k$ B d+ p! M1 g) S7 @ int 2Fh4 ]; E& x/ V! f4 b' G0 `
mov ax, es ; ES:DI -> VxD API entry point2 l$ q( n; ^) D" d3 i. P, {$ h5 n
add ax, di; y. K# b) H0 ~6 o: S- p4 h* |
test ax,ax& A0 ]( g: v- d! y4 k' V
jnz SoftICE_Detected& Y0 f( b, _5 U7 h: Q) j* V
" d: k/ E% x4 d- R* q2 {4 x___________________________________________________________________________* g4 U! I* m" o4 ~5 Q$ n _+ b
7 G0 ]5 I, }6 {; k; S& E% J8 L% k$ m
Method 04
0 o) `) H6 }6 j& N=========; [% J4 f3 G4 p6 u
2 V1 K" _. ~! ~$ g8 \
Method identical to the preceding one except that it seeks the ID of SoftICE$ q* S' t- v5 }1 v9 y
GFX VxD.
. E4 |5 T- b5 i
3 G' W& k/ b$ E _% ? xor di,di
- H! t( y# Q, g0 j7 U5 T) F0 Q; o% v mov es,di
- N" f2 V) x3 e/ m8 c, ] ~ mov ax, 1684h 4 s5 d, p' f) u; |# m+ D* J
mov bx, 7a5Fh ; VxD ID of SIWVID' N/ ]: m" V5 m) w# c1 b- [
int 2fh, r3 W) X' o: y" o. C
mov ax, es ; ES:DI -> VxD API entry point
- G+ G) i3 M! l# D& g% H! j. B! @ add ax, di ^+ T8 B8 o$ D
test ax,ax
7 Q; A( X% }* R4 L jnz SoftICE_Detected
, R" x2 x$ }* F# q' G& J3 B8 @% E/ E. ~
__________________________________________________________________________* B% Y" m; k s" O Z5 w" n
' P* ]; a5 v ]0 {: h' I* o5 k0 @
( K7 ~: X% X8 |* I1 y& Y4 v
Method 05. ~+ e$ r5 H1 `/ V9 m2 ~* k
=========
. m K+ K4 T- h$ S- [# ~* [: K. j& p; ]; R4 z4 B
Method seeking the 'magic number' 0F386h returned (in ax) by all system/ y. ^, o" t) A) Z0 X
debugger. It calls the int 41h, function 4Fh.
! b0 o8 g$ ?$ _% uThere are several alternatives. 5 o1 U' T' {2 b& D3 {
D4 A: ?4 y7 @5 a9 t
The following one is the simplest:
" i3 s5 V- z- i' g; k; L4 @* L8 `% s
mov ax,4fh
9 B( U {3 r9 f3 R U2 b6 g int 41h
! g" s) o; c- k0 H2 w3 @ cmp ax, 0F386- j) w, k& n i6 \% J: w
jz SoftICE_detected
8 A5 ^9 W) H* k- Y) {. a% c$ M" `/ s
5 x# o J8 ^! I: k
Next method as well as the following one are 2 examples from Stone's
3 F. T3 b( G! O"stn-wid.zip" (www.cracking.net):
, x0 J) e/ L& F) k, ~5 z8 {4 P9 f% ?( S" d/ D% _1 I, N+ W1 \, i
mov bx, cs
/ a' c& k9 m- N/ j lea dx, int41handler2% i+ e/ H' M5 ^+ r: u) o
xchg dx, es:[41h*4]
3 [' S$ D% C4 q) S) P! h# ^ xchg bx, es:[41h*4+2]2 P; X' T; ] z
mov ax,4fh
5 g% f5 M" ^/ S. `, R0 \/ `. d* E int 41h6 N9 v v7 n' y8 i% ^& S, a! ~
xchg dx, es:[41h*4]
! T& v( |* J; @6 [ I \, }( q xchg bx, es:[41h*4+2]
4 o# F0 t8 O$ | cmp ax, 0f386h" Y# O$ l4 P' W2 {5 a0 G: w
jz SoftICE_detected7 z z3 e6 J9 d8 `/ j3 z" x2 F
3 }3 L" D$ H9 Q9 Lint41handler2 PROC# p. ~' _ v1 u* E. P
iret8 w3 i4 I4 x/ C9 \8 E! o/ d
int41handler2 ENDP
( [* _4 n7 L* y) a* }4 w$ Q/ ]/ j' [9 L0 k
& k9 U6 |, I. Y6 v: O; P3 ]
_________________________________________________________________________- \% H' D6 ^+ @6 h4 p, ~
. H8 c* e: W% [" `- @0 \0 f c; u) c2 {6 I2 }. L
Method 061 I4 R+ I1 w" d
=========
+ D5 ]! U+ T" _) X! I7 Z
7 }! E5 Q% b8 J; ^" T) O
2 f6 b1 w" `3 J* n' B. r. H& L2nd method similar to the preceding one but more difficult to detect:" O5 n) P$ {1 Y7 L9 Y
5 \: P, q! v# [9 m0 z- M) Q0 ?$ A: K" o3 R& t! R* `
int41handler PROC
0 x% G6 I: g: G2 @1 i mov cl,al- F! G$ f+ H/ u# S3 _! I* X
iret6 _; s- J* \; o& a1 A
int41handler ENDP# ^' E/ ]$ B) y( M( w: K
o; b! I+ a3 D v- ~( [' O# h! D# ^; }
xor ax,ax; l/ a: L2 x% W' G B2 K
mov es,ax
! q6 x2 c5 h$ \. Q( W" d mov bx, cs
; D' v! x& i" K. t lea dx, int41handler) ~: Z* T- k% R- ^9 x% p- |
xchg dx, es:[41h*4]
. t q! e& x4 a' F$ X% u xchg bx, es:[41h*4+2]
+ t; K" |; \( Y* ^0 ^ in al, 40h( z+ w" ? J1 \0 b3 n% W3 ~
xor cx,cx+ E0 T' t( T& I$ E- ?( v X
int 41h
P( q/ {4 H l$ C! Y xchg dx, es:[41h*4]- }* z; S* r8 x5 d, T
xchg bx, es:[41h*4+2]: N6 [3 F3 ^' F( R
cmp cl,al- W" l5 p/ [; r5 T6 e2 F$ t+ s( |" i) a
jnz SoftICE_detected. k2 a6 f. N+ e6 m
! G0 H# |3 D! d( f_________________________________________________________________________% L, C. w* U, K/ p
; [& N+ M6 |1 wMethod 07" I! J0 ^/ b7 l) H, u
=========
' u. Q* X9 u" U, ?/ F; O/ ^) n3 T. t/ u
Method of detection of the WinICE handler in the int68h (V86)2 e+ L1 ?+ C4 N# S" Q0 K
' l, }1 N2 ?5 Y2 [" ?. [" R
mov ah,43h& F* D+ E; G2 p9 c) t' i' e8 ^
int 68h3 E' s) \& i' \9 h% L6 d7 \
cmp ax,0F386h
0 R& a" W5 a0 F- Y% g2 z+ f jz SoftICE_Detected
2 `8 y( b+ E( m" t* R; P9 C* {7 i
+ h( O) x# G$ F3 h2 t: U9 a0 |: o$ j/ O. [! w% |
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit5 c. Z+ [$ ]8 H$ Q( ~! H! V4 i
app like this:; i: _% L/ Q+ h/ B' [7 e
( T; r4 l6 Y5 D. U F" S
BPX exec_int if ax==68
" O% B7 I( I: v' V4 o0 C (function called is located at byte ptr [ebp+1Dh] and client eip is D9 F3 t8 Z# s$ G9 [# M" T. v; W0 B
located at [ebp+48h] for 32Bit apps)
" W7 C4 W& W1 Q- Y. y( @7 e__________________________________________________________________________* w& ~ B1 j) L4 A6 H5 h! f" ]. g. w- |
& m9 E6 y7 ]! P6 N6 _7 f$ t6 R
3 J' N, n4 e7 S, PMethod 08
( C0 C6 l5 I v" Z, ?4 E=========# t* _6 U) W7 ?
* w9 S! M0 q5 F. B4 B- _
It is not a method of detection of SoftICE but a possibility to crash the6 l+ Q4 @- h3 O, q$ M5 f
system by intercepting int 01h and int 03h and redirecting them to another% w5 S ~# W- e5 Z- X& c. K/ J
routine.2 m8 N; S4 k5 {2 |5 N; G
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points2 G$ @ ] o# E- S
to the new routine to execute (hangs computer...)
2 k; g0 \; O+ f" G- v9 n% w* p9 A; t) k( k: v' \( Y
mov ah, 25h2 J% x/ V S7 `' v% r
mov al, Int_Number (01h or 03h)
* g' C4 k: N* p7 n% E mov dx, offset New_Int_Routine
7 c7 @! ^) _: V/ ^$ m, f int 21h" l: S; Z! _9 j. O% B' w" M
4 H5 Q( z! D! E3 C* v__________________________________________________________________________& ]8 Q0 G3 P$ P+ ~! L
4 \1 O/ ?2 B. s$ e9 l. v) }0 A6 pMethod 09
2 j' e1 G9 h3 O1 E=========" q- ?" J, j; P4 K3 {5 `; N
9 h' ?3 \6 Y* w& E
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
1 O' ?& c" n& D+ m, tperformed in ring0 (VxD or a ring3 app using the VxdCall).
" f& u2 u$ i0 i' x+ M# m$ HThe Get_DDB service is used to determine whether or not a VxD is installed: t+ i9 ~, I. @" a, L- C
for the specified device and returns a Device Description Block (in ecx) for: l/ M4 C9 L4 m; ^
that device if it is installed., x! f8 a6 I, S# i O2 ~6 {) A
1 ~3 o. Y! B5 N8 t5 g+ a; i mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
+ P# V8 K# ^2 [+ X' F mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
& n3 D6 R- U7 o VMMCall Get_DDB
; \/ `- L7 C) E; a mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed/ e, f! g e# p1 q6 H
' Z5 |. J6 L4 Y8 O
Note as well that you can easily detect this method with SoftICE:
9 X! b7 O, [' N0 b% r! j( H$ u3 H bpx Get_DDB if ax==0202 || ax==7a5fh
* f/ s# ?2 I3 H( a0 j: C, y, `, @% w! I
__________________________________________________________________________$ J5 E6 z1 @1 ?( T- G$ B3 ^
O0 w2 U4 ^! s& S9 R0 `
Method 10
x- S, L! K8 w8 D ?=========& u! y3 ^8 V! y b) v
[2 j/ E2 f; |+ V) h& N* i/ t$ {=>Disable or clear breakpoints before using this feature. DO NOT trace with9 ^6 V6 H2 ~! P# _; t- v: S
SoftICE while the option is enable!!
# u& R2 \2 r9 n
$ T& \3 D8 K6 d0 MThis trick is very efficient:
4 f# ]7 r2 B5 p+ \* \# Mby checking the Debug Registers, you can detect if SoftICE is loaded
; }. P$ K6 ]+ a* X( v; E(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if. A8 P" T7 Q# g2 p/ m: _
there are some memory breakpoints set (dr0 to dr3) simply by reading their4 i- S. V% T- ]0 I2 T5 e
value (in ring0 only). Values can be manipulated and or changed as well
& A8 F4 G$ j1 e d3 l2 B9 G) h(clearing BPMs for instance)6 B) Q r5 E1 E- l! n
: Z: t, F3 ]8 Y+ e8 @__________________________________________________________________________
$ ]9 j; u+ T% ?7 N( R8 D8 A4 A, r4 m! k/ d8 p) `/ ]- t5 c
Method 11! W B: r. X* V8 u b. D
=========
% S$ a1 z& N2 A5 Y! j4 z& R( Y6 r& L# \
This method is most known as 'MeltICE' because it has been freely distributed
" ]- q% M. a! _; W3 G4 W, h, nvia www.winfiles.com. However it was first used by NuMega people to allow) u8 S, M" U- u" \1 k1 w! s
Symbol Loader to check if SoftICE was active or not (the code is located e3 N$ Y) l+ L- k; J
inside nmtrans.dll)., s1 b) y- V( S9 L8 [3 f
) x0 ], X @! M/ D' E- q) X# Q7 U# o
The way it works is very simple:
: C2 K- T! A- |5 d- F1 X/ P+ o0 OIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for! `$ \% o$ k( m, {0 g9 X0 q
WinNT) with the CreateFileA API.7 s m; x5 Y1 \& F* g' f r+ w
. W% \ r; p3 m7 [" y7 L: L& h( a8 VHere is a sample (checking for 'SICE'):$ Q2 j/ k) S# D) R! }, ?
6 }& O6 b5 c& Q3 ABOOL IsSoftIce95Loaded()9 M/ G$ l2 |+ g! G) E
{
; q' k+ P8 E& B HANDLE hFile; # r" f% s! ], q0 R. u
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,8 U, I' u, J9 x. |! e% x
FILE_SHARE_READ | FILE_SHARE_WRITE,' r$ u* q9 }2 D4 G2 U# o$ \
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);! B; i1 \& S$ ^6 K8 c
if( hFile != INVALID_HANDLE_VALUE )
6 h, y7 m9 M! X" Z! Z6 O {! | B1 c. q$ H v. u9 a: S- j/ O
CloseHandle(hFile);
1 M B1 A1 R% O( j5 r8 R# ] return TRUE;3 O8 Q w1 i5 s* n# Q. E
}. {/ N: O: K9 z. Y |4 j9 }3 W1 P" Q
return FALSE;
! F3 q8 O4 u9 m. t}1 u- H( k4 ~2 R- h
V& h* S! p6 w7 {0 u
Although this trick calls the CreateFileA function, don't even expect to be/ Z, ~ f/ ]( F8 l r2 e s
able to intercept it by installing a IFS hook: it will not work, no way!
) c6 f) d5 Q0 M; t+ ?3 S9 r9 V! u2 l) VIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
+ P. f% W# O7 \) P' q9 s: hservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)1 M: u$ S& _/ ~% t7 J1 f0 P
and then browse the DDB list until it find the VxD and its DDB_Control_Proc+ Z' y+ p+ P1 u7 c
field.
& v9 b" _" w X/ f7 b3 TIn fact, its purpose is not to load/unload VxDs but only to send a - z9 m/ j4 L9 h
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)7 X' T. R0 Z1 d6 `3 ~# A, @3 \
to the VxD Control_Dispatch proc (how the hell a shareware soft could try# m! k% c/ B1 ]* n3 e: Z
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
, B5 Y# B. {2 M3 AIf the VxD is loaded, it will always clear eax and the Carry flag to allow
0 E6 y% L! q/ W% jits handle to be opened and then, will be detected.# x7 a8 u% B3 e" ], N$ j
You can check that simply by hooking Winice.exe control proc entry point
, B) ], ~) |: v9 Owhile running MeltICE.+ O, y% V) `2 o# Z, _5 Z& v
: N! L0 Q- n4 p" ~1 P2 {1 p" \2 e" i; W6 Q
00401067: push 00402025 ; \\.\SICE% o) V( q9 p7 S; v6 N" j
0040106C: call CreateFileA1 |# j- Q' p* ^% _2 L
00401071: cmp eax,-001; y! I* a* Y: Z
00401074: je 00401091* S" g3 r- z- \ l1 G! x) Z/ f
( R3 ?+ k. ?/ t* i4 s4 `- n
1 K% \+ M, I; |
There could be hundreds of BPX you could use to detect this trick.
; `7 o0 |$ v, u9 o+ n; p-The most classical one is:
) g6 ]" b) `7 E( _ BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
; F5 u# W1 {# X! j- p# H, s; l *(esp->4+4)=='NTIC'
5 C; ?& f$ z7 N, ?$ f
, M3 j3 D4 R7 W- [2 p T7 D-The most exotic ones (could be very slooooow :-(
$ W6 e D1 [. n+ K BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
3 p; L+ s) Y8 Y. K ;will break 3 times :-(+ g# u* T U2 O, {# l+ U0 K' j
" o5 Q, |5 ~2 E" m/ G& B5 }
-or (a bit) faster: + @( ^ l# F' y
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
5 ~1 e- X- z+ Y8 ]1 o/ O/ Z3 E) A2 |& y% b
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 0 K. f" Y. r/ b4 G% U
;will break 3 times :-(
! R/ `+ g( i$ @+ u% d& B: I- d2 o$ b3 P8 c V, e
-Much faster:
3 u# ~. y4 |% |- R+ o$ C BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV', f8 O0 R0 v7 [3 b) W9 A% O3 I
" ?$ }- [9 ?# D1 D, {) A8 cNote also that some programs (like AZPR3.00) use de old 16-bit _lopen+ i9 x7 W1 }5 U# w: C
function to do the same job:/ s9 ?5 N/ h4 I( z
9 |' i" D4 n0 E; m6 m push 00 ; OF_READ7 k. D; l6 j4 b/ {. T
mov eax,[00656634] ; '\\.\SICE',0! l3 C6 N" L; K' N7 V* y+ d
push eax+ i0 e# X5 O# ]' B0 z+ X
call KERNEL32!_lopen
+ u* |3 ^# }, ^: B inc eax
- O2 [( o' H) B* V% Q& ] jnz 00650589 ; detected
( L: d( P2 b; `" V' U push 00 ; OF_READ6 b- R3 R' k v# M9 R; n/ J' ]
mov eax,[00656638] ; '\\.\SICE': o* F: J9 x; h$ r K
push eax9 }9 Y4 v+ q% ?; [6 ?
call KERNEL32!_lopen* V$ A8 o% V6 g9 a; ^, K# |
inc eax
- v% {' k1 R( f jz 006505ae ; not detected
! L& J5 J* ?" |" w2 W0 o3 L& p" U
+ F$ l; ~- @- S3 U4 `& b% `5 Q5 c__________________________________________________________________________0 I {! x& S% N' x E
5 R4 p3 e9 w8 w8 b* e6 x( X) _Method 12/ ~0 G& J) N3 F+ y
=========
. W! u. T" y) n2 {; y3 O1 w1 u$ @+ M9 \9 W' l9 @7 l9 a
This trick is similar to int41h/4fh Debugger installation check (code 05
' E& f9 w2 d3 @( C& 06) but very limited because it's only available for Win95/98 (not NT)
: u. N) l' O* Yas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
- Y! S6 ~3 J4 }. i3 G! W- o: ?6 {/ V. `4 s5 @
push 0000004fh ; function 4fh( _+ ?( `" p; B6 X% Z8 ~# b& n8 G
push 002a002ah ; high word specifies which VxD (VWIN32)
* s- @6 D2 r& V E- K7 P2 }+ j ; low word specifies which service4 O. v* X% e8 m0 G
(VWIN32_Int41Dispatch)) F' A& _' V( L9 c/ a3 c
call Kernel32!ORD_001 ; VxdCall
) h! o# ^/ U+ y' E& G. @8 {, v cmp ax, 0f386h ; magic number returned by system debuggers# B Q- @. h+ b% H3 w, H! m) E% g
jz SoftICE_detected' e+ @, I0 V! K3 P! r
, U" T& [( \9 H5 m" K3 m0 L) P+ y9 uHere again, several ways to detect it:
! {2 H4 |* H3 B8 t
' G& U) [* r4 x- @ BPINT 41 if ax==4f" f$ U) J" S4 t7 y9 f
7 Z9 T" h" \% ?' o ? BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one$ s, X) ~ B' j' {! T0 c% `
! k& j8 h/ f6 [8 T- D; c- B BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A1 t1 |/ A6 V# J, k4 | O
+ N* \' L: ?3 ?- S4 B7 {4 W
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
+ l4 \: x6 A% W; n3 E1 j2 B. x; D8 |1 {" q& P( O1 U# c
__________________________________________________________________________
: \ X8 w2 ~+ m
, p- R* p; a6 J' h( g& EMethod 13/ O0 J6 v6 D: z7 r" y# Z
=========) S2 B7 b* C* k' E: p
: g2 v* y: g% C+ v+ g' I4 c( x$ c. kNot a real method of detection, but a good way to know if SoftICE is
2 ^: \) m, V' }* }installed on a computer and to locate its installation directory.
- e# }: h2 M0 i' x$ B* F+ i, kIt is used by few softs which access the following registry keys (usually #2) :# n, {5 i* f# \ I, B
$ O; v- Z' J/ C& q-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
% c% v9 g) m7 b2 W% j: P/ o" i\Uninstall\SoftICE
6 R) `) z7 @9 M4 ^7 l1 a, I6 r-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
& c* u% c) A) {6 ?( O-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 U# I) I) ~+ x
\App Paths\Loader32.Exe
& s: `' ~5 {, W7 @& z% a$ F- w8 W; \( p ~
3 U& Y$ }" E* `+ t% {Note that some nasty apps could then erase all files from SoftICE directory0 c: r3 n; c: e5 v1 K( s! D
(I faced that once :-(3 d0 p% n' f4 [' P% O9 l( q
- t; F- b! m$ U& T& @1 h. N
Useful breakpoint to detect it:
4 k/ v1 b9 P/ Y
+ _" R% T! A3 A9 }% Y2 v% n+ m9 k BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
3 D2 j3 B1 P- h' U& `# C6 n! N5 H# j1 q7 ]: m) B$ _* D
__________________________________________________________________________$ O- ^' m8 F6 V/ V' W7 D! j
3 L ]; t4 I7 A2 U
$ B& a; A! b- ?$ V X- z
Method 14 ' b+ B. s u' l1 \, w
=========
7 E+ \9 L; L' q! O1 a# X& D( }% ] f9 V7 C! |9 P* {
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
# L: {4 t9 \6 g$ w7 U" q( E1 nis to determines whether a debugger is running on your system (ring0 only). W0 F Y$ V6 @) Q2 D) g/ M! d
3 c3 `4 F& S I# @
VMMCall Test_Debug_Installed
7 L: |$ o1 e0 L6 s je not_installed
" ?; z( B; d4 |+ ]( t: \
/ r3 q6 |5 W$ ~" ~9 x r6 QThis service just checks a flag.: {! Q& V/ f! ^! N: N- x
</PRE></TD></TR></TBODY></TABLE> |