<TABLE width=500>: u( f1 v, R: G/ ~2 Y
<TBODY>
+ E3 a% m. W( I- r/ Z<TR>9 o7 \/ @4 a0 [9 q) Y
<TD><PRE>Method 01
$ p( S( g; m! Y, R0 h6 h5 g8 b1 L=========
6 ]# P0 F8 S; m p- y d7 ]
. P. ^. ^# a* c) _5 z: FThis method of detection of SoftICE (as well as the following one) is
; [$ e1 y# {' r2 r/ @- ]! o; {" ~; Aused by the majority of packers/encryptors found on Internet.. e4 f1 o% T$ A. x
It seeks the signature of BoundsChecker in SoftICE
7 o2 L( ]4 ]. _* w9 ^( @5 d9 ^7 A" H/ l; E
mov ebp, 04243484Bh ; 'BCHK': P* Y# p8 r/ @' B2 w$ L8 F
mov ax, 04h/ i& d3 _2 m M, L _' o, _1 {
int 3
2 e5 w. J, t9 V4 i+ W: E cmp al,44 Y) J4 @$ @4 \8 H# L u
jnz SoftICE_Detected
/ o- q; l0 c* E- p
0 f% _0 A3 [, C2 e4 R |___________________________________________________________________________- m: J4 a( t5 p5 X: e# k
% q2 U, \( l3 T! ?& q
Method 02
4 }) \1 d% h9 C. `* U8 c b=========$ k7 p) [# {! C. b& e; D5 D% W
% Q9 G1 W1 j7 [- e% X/ [. dStill a method very much used (perhaps the most frequent one). It is used
, f$ c/ k: n1 Kto get SoftICE 'Back Door commands' which gives infos on Breakpoints,$ F; a& {' }" v7 K' e2 n& [5 V0 Q
or execute SoftICE commands...
. p. _" t! [( m j) D# aIt is also used to crash SoftICE and to force it to execute any commands
( @9 s9 m% V. p' }8 a, Z$ k2 t(HBOOT...) :-((
6 z# r8 a, s0 X. N; c w4 H7 l2 y1 p | b+ q
Here is a quick description:, \" {* o" A* ~: d
-AX = 0910h (Display string in SIce windows)
+ b; a2 T; e8 D3 k( {# E# Y-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
( l5 H% v0 v! V' |7 u: I' @0 W-AX = 0912h (Get breakpoint infos)
9 ~. |. S& e" z \" K-AX = 0913h (Set Sice breakpoints)+ g0 N6 {+ M5 m" i- H9 |) p' F2 D
-AX = 0914h (Remove SIce breakoints)) c* L+ y( D" J: Q' ~
* j6 `: S/ P0 b' _* \
Each time you'll meet this trick, you'll see:
# e3 A# }7 ?' i& ~- `# O: q-SI = 4647h. S# b* B' f! a3 q7 g3 V
-DI = 4A4Dh$ n7 A( n# P: }( L. R4 g2 |# U g
Which are the 'magic values' used by SoftIce.! n; O" g5 k2 D- Q4 b! o: h
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
( W9 i7 h7 E: L% H$ ?1 s
; C" ?: h1 W4 Z1 Q9 A+ hHere is one example from the file "Haspinst.exe" which is the dongle HASP
6 e- j; M& S! v) o- H( O5 pEnvelope utility use to protect DOS applications:
9 E! I9 l% o7 {# J7 b9 t& \9 H" @( _5 U* y9 D; e- a0 F
2 D& ~9 J5 z+ c2 _ w( z0 \$ b
4C19:0095 MOV AX,0911 ; execute command.! ~- ]1 `6 |! B6 m& v: t# ]# ?
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).$ P1 u% `8 x9 z2 i0 z) F6 b
4C19:009A MOV SI,4647 ; 1st magic value. E% U3 |5 Z ^" F( l# l
4C19:009D MOV DI,4A4D ; 2nd magic value. u8 [7 d) Q" f9 t) w1 l
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)# G0 T9 l( W0 {! d
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute& i+ f$ ^% J3 ?7 e
4C19:00A4 INC CX, W& Z, S5 |: w* ?
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute* H" i0 j2 g4 n
4C19:00A8 JB 0095 ; 6 different commands.
; d9 h4 f4 N: C" E y: a: A4 T4C19:00AA JMP 0002 ; Bad_Guy jmp back.& F, k" G% I2 `" r. R
4C19:00AD MOV BX,SP ; Good_Guy go ahead :): u) q3 o& \) F) M2 L% x8 P
* {$ J: M* d8 t$ M9 ?
The program will execute 6 different SIce commands located at ds:dx, which
; i6 T* E* C# q0 r0 Qare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
* {6 R% o* q5 P) L% K7 W- R/ K+ q& S7 U3 c8 e. M
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
7 y1 k) i+ e0 U7 J; A: K: s___________________________________________________________________________9 g- O2 v, Q q! Y$ t# |7 z
: K9 F6 e: y4 ?
" A* C! v8 `% HMethod 034 O# r! k+ N, Y$ L" v
=========3 J6 H( d/ S5 y, l# d* S. c
) U' T% D# u- h5 M: uLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
2 b* x' f& i% b1 ?$ d1 N(API Get entry point)
1 c- v' x7 u& k9 h
1 b: Q8 d) A# |; ~$ K0 s/ Z }/ j3 i; ]* K
xor di,di
N( |8 ` a( Z, c! l( _' D8 V4 H mov es,di) C! u. {+ Q# `" s! @5 E
mov ax, 1684h
+ y, [$ N2 d9 ~: O mov bx, 0202h ; VxD ID of winice ^/ k' e' Z# g' Z
int 2Fh. O: Y9 D$ A2 B: e# p
mov ax, es ; ES:DI -> VxD API entry point# s2 K4 c% h; J! ^: \1 H
add ax, di
' P+ @. u( a: v" v! a test ax,ax
0 K! U, k# x' R jnz SoftICE_Detected
v+ I! l" x( z0 g) Y: S, P$ \' ?1 N( x7 V; T, I
___________________________________________________________________________ x, h( b3 r4 D& n! q1 Z
- \8 `: u3 Q4 h% h0 T
Method 04
- t1 Z. p6 A q6 m! }4 S5 Y=========
, l7 G% v8 k! d/ D6 C, \$ S' \, w: h" `" O/ U0 y
Method identical to the preceding one except that it seeks the ID of SoftICE- s* l' ?1 k2 o: g* o2 R) `
GFX VxD.2 x7 E, U( [, e! N$ |
% N, c+ U' T6 { S4 X6 h xor di,di
1 v- n; t' e# E$ e& `; s* z mov es,di
* T) _/ e4 O/ v$ B; G. u: K mov ax, 1684h
# ~2 l8 C4 t& B3 W+ s0 j& G mov bx, 7a5Fh ; VxD ID of SIWVID( J7 ~, x4 `+ [+ c5 \8 I
int 2fh6 a( W& ~. D: H5 u
mov ax, es ; ES:DI -> VxD API entry point
" b! ?5 {+ @- z7 C) C { add ax, di- P" C$ b) L, a" s; G5 o0 L" z
test ax,ax
' J# l' M" T. p! V& H4 ~ jnz SoftICE_Detected* `4 x5 B) y' V6 S& W, r% E+ r3 m8 A' F1 X
) j( X+ D1 ?& K8 E, g( S7 ___________________________________________________________________________
: I, E* y' \/ m/ Y
8 _4 Z% o" q8 Z' N/ K6 x. x9 w7 O5 j$ [2 a3 @+ j S) w7 w+ } x
Method 05
0 h2 `$ H# W: ]" N7 c=========
4 k3 g9 B' Q( a; f4 ?
- ^/ E& u/ j& \# b+ |; pMethod seeking the 'magic number' 0F386h returned (in ax) by all system6 y4 N$ F: A" ]0 @( R. S
debugger. It calls the int 41h, function 4Fh.
3 N u0 i: ?7 [6 H9 _( ]There are several alternatives. 0 B! h( `1 z# [8 B& x
! x/ W# m* Q- S, Q2 g
The following one is the simplest:( e+ _% d" S1 a9 @& W
+ O+ q- t7 n+ c mov ax,4fh2 C: n# b- w' w$ ?
int 41h
' a7 K) `9 k- p0 S) \& O cmp ax, 0F386
, f, G$ u+ E, z! U/ F jz SoftICE_detected3 u/ G( H; A8 {- {; T. j! e
0 \* s, D* c* v
5 Z) w5 }: B) g8 G% W; cNext method as well as the following one are 2 examples from Stone's $ I' H& z! S5 F; @2 h( k
"stn-wid.zip" (www.cracking.net):
0 U! Y/ {! P! A' h( A/ ], z) i0 \! N3 z2 v+ q" ], R0 j. v
mov bx, cs
: q. n6 y- p0 h) Z lea dx, int41handler2
4 j% J6 _9 D9 D8 p- B3 \ xchg dx, es:[41h*4]
6 O" q; ]# |- m xchg bx, es:[41h*4+2]
D" u1 a: F: n' w5 _$ z( K mov ax,4fh
& x/ r" Y. [3 a% A; f* } int 41h
% \2 f6 B+ h5 T- ` xchg dx, es:[41h*4]
K$ R& r3 M, j* V4 q6 G xchg bx, es:[41h*4+2]
# A( M9 G! j: t, y# r& p cmp ax, 0f386h
/ Y" A4 ~9 p3 f2 R4 ^0 Y jz SoftICE_detected* ]' J3 p, N$ s- r
% y. {4 {# L3 F$ O. m$ z
int41handler2 PROC
. z' {& I7 N5 o+ R& ?+ N iret
w* P1 g+ H+ \4 n/ C1 c6 L/ ~int41handler2 ENDP+ y5 Q! d" X4 ?% N$ O3 o
' M; N% F! Y5 Q C% g6 ~3 N; Q4 y/ @3 b, f4 b' U ~
_________________________________________________________________________% |( R) [& D8 P# I0 D) \
^% b$ |# Q1 T* F# ]% u* f. K
' s6 E) z# \9 n
Method 063 O1 s( ]( d5 d2 K6 E9 f; Z
=========
- H8 }0 u+ p# `8 r: a4 @! | o) C' z1 h$ w* J1 k/ ~9 }
! J! x% |2 t) j n, u2nd method similar to the preceding one but more difficult to detect:8 t [4 g j4 ], S7 f% a
2 @$ _' E& L8 b& o, C7 b# M, ?
# p, @$ T5 h( R2 mint41handler PROC; z5 A2 v7 y6 i( \/ v5 l7 {
mov cl,al
. Q) j9 T/ ~) R0 O' g M iret
; d+ f& Y- m( ?; z' `* @ Iint41handler ENDP/ K4 D: I( x+ }6 n
+ B) \) G1 Y8 T# X7 _- B
+ s+ W+ x9 M+ Q& B1 f# ^ b xor ax,ax2 _* L9 I: s L5 O- R
mov es,ax
0 H: Z* v8 V l! x0 @ E0 b m% i& k mov bx, cs! P7 S' q, u5 G5 x# _4 v
lea dx, int41handler
# `# G, g+ Y) s8 b, I2 F+ l( Z xchg dx, es:[41h*4]
4 a8 s; v* z( \ s6 I: L: P# L xchg bx, es:[41h*4+2]
# f, D3 @) N5 J in al, 40h4 X( |% @4 `1 X& _& q( E
xor cx,cx
$ a5 S% w% y: T* b- n int 41h
V) v- L3 t. n; `, ` xchg dx, es:[41h*4]
2 k) n+ D5 ~, w" K3 O xchg bx, es:[41h*4+2]
: m$ Z8 |, o: z' k/ [6 ? cmp cl,al2 @# i' x* m; N! ^$ v1 y
jnz SoftICE_detected% }3 ?6 X/ c4 L4 D0 \+ l
/ u. Q6 S7 u2 Y, f# X3 G) o$ O_________________________________________________________________________
) l; c0 r# ]1 Z( q; T. G& f; R! R5 j
1 K5 N' _2 Y+ i: I/ [1 WMethod 07, T/ }; V# i& R
=========
: ?+ K% ~2 `+ {/ @( Q0 _) Y4 Y) C
5 a9 x% B* K* f- j$ p3 W+ n1 W) ZMethod of detection of the WinICE handler in the int68h (V86)3 Z7 \2 t: S/ P
& B: l& ?; e7 m: J1 `
mov ah,43h, {* x+ q0 w" D+ Q# _5 \
int 68h
. X' T; c- w7 Q7 Q; F3 K cmp ax,0F386h
" O( j% h9 u" u% @8 c* Z( [ jz SoftICE_Detected# A( p) s& i9 P
' F1 M+ n. G+ _+ W
# a+ q; p$ Z& ]
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit. y% B4 Y/ H+ s6 z, f3 M9 l
app like this:
7 \0 P8 I% z: I# H8 j* @+ z/ O4 ?3 j( F; W9 `
BPX exec_int if ax==68
9 R9 @3 a2 l! Y (function called is located at byte ptr [ebp+1Dh] and client eip is! U/ V Y; F5 |. b) P. g/ D
located at [ebp+48h] for 32Bit apps)+ M4 y' ^: l* t9 |5 F" ?& g6 J( f5 D
__________________________________________________________________________
9 V! L$ }' a, ^5 x# s3 S, t' w2 S- v! l- Y, _
; H( Z' {; S, s/ D: K
Method 08
, z' d& V- u; y4 y2 d7 V5 T=========
' b6 z# y0 M9 g3 n' ?4 @- W8 ?* f8 `8 }/ }, i( E9 Y1 y% G7 x/ o6 \0 o# G
It is not a method of detection of SoftICE but a possibility to crash the
6 }8 l& J, p+ |5 I$ \1 u/ ^$ msystem by intercepting int 01h and int 03h and redirecting them to another
( B- Z4 g+ K$ s* u9 rroutine.9 ?" E0 O" ~! N2 o+ z
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
# Y2 f+ O0 W* \) ?to the new routine to execute (hangs computer...)
* H! e4 q: e( V
4 c* u6 N5 o& o8 F mov ah, 25h3 C; `& \" Q9 g: }+ M
mov al, Int_Number (01h or 03h)* n5 E8 u+ g0 J) c- O; z
mov dx, offset New_Int_Routine
! @# V/ V$ J0 x- X int 21h
. |" E; `( u3 p0 {8 h+ F7 p
6 q5 {* W: N. }8 G$ X__________________________________________________________________________
) z. U/ s& e6 n' k. F$ n0 Q) e+ \3 t2 j) A9 Z
Method 09
/ W0 ]! x6 ^0 o) n9 S0 t$ P=========
7 v# h9 L2 _; }. L; d: S9 n0 s0 s2 X; v& @6 L
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only1 p; p0 @8 ?- F, V( G1 @
performed in ring0 (VxD or a ring3 app using the VxdCall).+ z- Z& g2 t5 y+ x; O
The Get_DDB service is used to determine whether or not a VxD is installed7 a# i i) Y! z4 |' m, }, X
for the specified device and returns a Device Description Block (in ecx) for
% u7 [, y0 g4 Rthat device if it is installed.$ O* Q. W, \! \ y
) D% K8 z) l! b( Y G! M4 I0 W
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID' j4 n- g) f, ^
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
p6 I* e4 ?1 o2 { VMMCall Get_DDB
2 g& f5 D: a" U, I$ _, c y: c mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
& c# s' T/ S4 V1 v. _8 s( F g! s2 I9 A# t3 L
Note as well that you can easily detect this method with SoftICE:% k1 S/ Q" m: Z4 G8 T
bpx Get_DDB if ax==0202 || ax==7a5fh
7 I5 H- ?! E( w! m: G. G- o3 b% \/ G1 u6 u- y; [
__________________________________________________________________________
2 T( I1 E! a1 ]7 z/ V- |% X3 k9 I
7 s/ C* u. r4 G. u+ f% K8 }Method 10
0 O6 a/ Q8 p! T3 t=========
9 \; T! i: ]# G/ Q( {5 X/ o8 ~7 i, T0 d: g
=>Disable or clear breakpoints before using this feature. DO NOT trace with0 @) z" v1 v# M% S, K+ O
SoftICE while the option is enable!!
' x* p. J. a- q
) N" ?: D, }$ D2 R2 |This trick is very efficient:
( a" x. q" _' z8 Q. kby checking the Debug Registers, you can detect if SoftICE is loaded; H* H6 k1 }' ~. V7 g' B+ T; ~' @
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if7 Q! _6 \! x) X% l
there are some memory breakpoints set (dr0 to dr3) simply by reading their
/ t2 m. Y" U! V' Yvalue (in ring0 only). Values can be manipulated and or changed as well
* d+ d! D5 N5 g8 ?2 Q4 s(clearing BPMs for instance)
: r$ Z2 r) X, F
9 Y1 E. F9 y. P. u' ~__________________________________________________________________________) L0 q/ a( }$ V. h5 v
$ T/ D: f& ?" P( [. p4 {" P
Method 11
( {9 c; f6 \6 L: G4 q=========
- K2 ^5 }3 ?1 D! N, {( J# K2 M; i2 I. d1 @' L3 \
This method is most known as 'MeltICE' because it has been freely distributed' Y* n* e0 ?: L+ @8 g2 o, H- U8 F
via www.winfiles.com. However it was first used by NuMega people to allow! n: ~7 w! T% R# g4 i
Symbol Loader to check if SoftICE was active or not (the code is located
9 X! y) b! E- L. g. q6 I% y9 N( Dinside nmtrans.dll).; _! Z. E9 U. l5 ? [
4 h. Z {( e/ M! s
The way it works is very simple:) i) r3 o2 [+ `9 }% I! {6 B9 T
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for9 J9 W$ ~* a1 L! x7 ?8 C% B" r4 Y
WinNT) with the CreateFileA API.' ?2 ~4 ]: M4 w, W/ ~9 Y% P
5 n3 j6 f+ [* q3 GHere is a sample (checking for 'SICE'):
- t _" z. M3 w% J& e
, w: e. m+ R) ~+ y; D; `( IBOOL IsSoftIce95Loaded() Y1 W6 x2 L7 |4 B
{
) j+ A2 ^8 u7 [. R HANDLE hFile; 7 x8 X7 r% I" a# B# p$ k2 g9 D
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,; P6 G4 d' F3 _5 z E6 M# \, S
FILE_SHARE_READ | FILE_SHARE_WRITE,. u ~$ Q% j/ ?9 y* s6 e; H
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);2 g J; t6 Y2 o* L5 N' j. W
if( hFile != INVALID_HANDLE_VALUE )
- V' M4 _8 x- p* p {% y0 U/ X8 c3 i- l
CloseHandle(hFile);
; Y$ u6 s5 m9 v$ U' r0 C" g return TRUE;7 A* Y6 k' E8 b* s
}
( c* ` D3 C9 w! w4 n8 ~6 T" o return FALSE;
6 @* ?+ M- e0 d; F j4 J4 z}
& q' T8 O$ l4 Z# k9 R7 ?3 e/ V& C Z8 d
; [( T7 D5 z7 p. W1 d, QAlthough this trick calls the CreateFileA function, don't even expect to be- n; x+ v, {+ g
able to intercept it by installing a IFS hook: it will not work, no way!
4 s. W, r1 S+ {3 |' Z+ BIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
. q9 h& W7 Z0 Yservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
# {8 h" R# h( _+ A1 i3 Oand then browse the DDB list until it find the VxD and its DDB_Control_Proc
$ p% x. P$ N+ A/ e5 x( Bfield. ^9 v4 e( F* g4 t, a
In fact, its purpose is not to load/unload VxDs but only to send a $ |; C. ?5 F4 i8 f# ^' l& o1 k; _! [
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)7 I" B p& y, W* Y' C. k. u
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
; b4 D1 ]' [9 u9 p# Dto load/unload a non-dynamically loadable driver such as SoftICE ;-).
$ O5 i# M x4 p' T. u' Z9 CIf the VxD is loaded, it will always clear eax and the Carry flag to allow
4 V" D7 A+ K) ^/ S- `% v9 I* Eits handle to be opened and then, will be detected.9 _3 b9 q( G* K; z( y' j) Z
You can check that simply by hooking Winice.exe control proc entry point f4 F. I& { X! h' \0 k
while running MeltICE.6 b2 ^! S4 N( m" C
2 t+ e2 [: I2 j& `' j3 s8 Y! R8 Z
# B5 w \# C4 L$ ?9 R
00401067: push 00402025 ; \\.\SICE
% c! B' o6 Q# i 0040106C: call CreateFileA
% o. W) f! C8 U Z: {5 _ 00401071: cmp eax,-001! b. O& u- B- B
00401074: je 004010912 l4 t+ J; p8 b+ r) v- x2 J% ^9 S' N- B
# C1 l) X- R5 T* Q2 c
+ T0 X: ]+ w( T. gThere could be hundreds of BPX you could use to detect this trick.
! T5 a; S4 b$ P; J6 d: ~" J-The most classical one is:1 }+ ]5 n T+ d8 [6 X
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||+ E8 m) O2 p$ n8 N) ~. D* ?2 ~
*(esp->4+4)=='NTIC'9 G4 V d8 ~& h/ }
% H' u8 y8 C$ H8 a5 U- t
-The most exotic ones (could be very slooooow :-(
1 A2 _- @, n3 Q5 G# U9 R BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
; ^% X3 N& D. i T, ? ;will break 3 times :-(: I9 C# J |4 z" H5 N4 O
7 u5 }4 l* i* e" _4 `7 ^, _-or (a bit) faster: / W" I) I s8 u8 \( Y+ i
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
/ o( Q* Y7 R* o5 i3 g4 n, M) h \( f( y9 b0 h1 H# _9 I: `$ p
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' ; g* ~& E5 |! e" `# M, Z4 j
;will break 3 times :-(2 b2 r+ Z4 w8 z6 Z3 y
3 c( ^; m0 T( j) C2 f6 | f-Much faster:3 J( ]0 M% r& z# s
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'( {! E: I4 @! q/ N
5 [% U/ I+ x* F% R
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
. B6 M, J- E9 j. _8 ]function to do the same job:) e t ]( w4 ~" s, K9 X6 \
0 b! O4 g5 `5 p2 V4 X, c
push 00 ; OF_READ# J0 L5 f8 @. ~9 b4 R
mov eax,[00656634] ; '\\.\SICE',03 w4 @* M8 g' |/ G5 \8 z
push eax% H6 ]6 X6 Q$ A3 S" S& w. m; Q( z7 D- F
call KERNEL32!_lopen4 L. h5 Q" H! T, h7 u" _
inc eax
* P* ]$ V# d, s6 h4 b W' X jnz 00650589 ; detected
M: n/ z3 T7 f9 j- I0 A push 00 ; OF_READ
! P# @1 U6 o; l+ N2 _ mov eax,[00656638] ; '\\.\SICE'
/ U, M) A$ Y. i. i, ~1 n' } push eax
" x7 A* A" c& p4 M; @& k7 S8 ~ call KERNEL32!_lopen0 w A- }9 q. y& D( P
inc eax
$ H4 X2 w2 \ Q4 t7 M& p3 J jz 006505ae ; not detected
; ^6 ^% l9 q+ g0 _. T( @. V
7 ^( S1 l }* U' G4 a( R: J! Y7 j# c2 n) w
__________________________________________________________________________7 p$ ?+ T0 Z% M
; e4 h' e4 ?6 _0 A9 ZMethod 12
. t0 v) f1 k A e=========
1 F8 k. D. j/ a5 h! ], \* D* f8 {
This trick is similar to int41h/4fh Debugger installation check (code 05; O; A0 h/ v H! W& q
& 06) but very limited because it's only available for Win95/98 (not NT)9 c. X( w p0 o, l7 A' o) h
as it uses the VxDCall backdoor. This detection was found in Bleem Demo./ k7 b4 J A7 @* g
4 A( D/ b5 i/ y4 F! q3 Q0 b
push 0000004fh ; function 4fh5 F3 k& j" N9 ]) i- _% K
push 002a002ah ; high word specifies which VxD (VWIN32)6 S0 f$ c7 J1 n3 C' d8 n9 Y
; low word specifies which service8 T H" \+ W! Q g# _' x
(VWIN32_Int41Dispatch)
. C! `7 S6 u, v/ v; t call Kernel32!ORD_001 ; VxdCall
$ `* q. P. ?0 L2 x cmp ax, 0f386h ; magic number returned by system debuggers7 w) c; D/ p% O8 i0 i
jz SoftICE_detected& g5 w9 J& W2 M( [1 R1 R
- a: B) o, ~' `
Here again, several ways to detect it:& d( ]% a5 G8 q( D' {/ l9 D
4 W$ Z, `/ O; K3 O. z C8 j7 E BPINT 41 if ax==4f
$ L2 c9 u7 i8 f
% ?0 _2 o3 i" G6 r3 I' f& [1 ~: J BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one' M' O# ]) g1 A3 ^- {/ Z
* v' V4 r0 _/ s9 F4 l* a BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
* e( a' N0 C W. M- t0 l
# q5 A9 M' D+ a5 Q! Q+ ] BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
6 V" d) z2 Q a8 V x J2 p$ D" K7 Z6 K" ~1 L9 |8 {1 a8 }! ]: y7 H
__________________________________________________________________________
9 N! D$ Q$ X! J" N
% y! @$ Z! e2 `) x6 O7 yMethod 13
2 n" _$ j$ N; y# m=========8 ?! e* L; T' }+ y) {9 ?6 H' ~
& j8 v+ }% P- p L4 I% G9 D
Not a real method of detection, but a good way to know if SoftICE is
: O, q8 t! R+ [9 T/ j" \installed on a computer and to locate its installation directory.' M$ v' H/ s# o) p# y0 o6 d
It is used by few softs which access the following registry keys (usually #2) :8 p6 f1 ~- n9 s% \$ M+ h G
) e) h( Z1 E3 i- ^3 J; s1 M; _& |
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& f5 o+ T8 @6 g0 ~, u( ]0 T1 g
\Uninstall\SoftICE K& O8 O: [; X N0 j1 W0 q
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
9 r* L5 T8 H: K1 R" V7 M; w9 ~-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion, v; H2 y7 v& H
\App Paths\Loader32.Exe
2 n* |9 U# l9 t4 u) F$ ]
1 B2 `5 Q5 ?, _
" N$ _" ?/ F% N5 nNote that some nasty apps could then erase all files from SoftICE directory
2 h. G3 l1 l& n7 U# b3 J(I faced that once :-(
& T; `# Z* ^4 x% n1 g
# p Q8 Z4 Z |4 `0 _9 n$ tUseful breakpoint to detect it:
7 P0 L/ P. t; P: {+ k' Z- J/ b4 Q) f5 o' A0 L6 ?' ]
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
5 U8 y6 `- ~8 p2 K9 }$ L
, G% j2 Y8 O; i8 {__________________________________________________________________________
+ q0 |1 i2 l! Z% T2 J# r3 `! l3 ^3 Q: Z$ L' F9 X; n/ F3 d
1 C0 G. S: J8 Z s& {, `Method 14
2 w' d: n" W2 X; e7 V1 J2 X1 c=========
' o3 a8 m6 Q5 M
- A+ d4 [, @ }. ]: q( i2 a, X& ?# {A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose2 h# w6 D% f) U0 ]" a- O' M
is to determines whether a debugger is running on your system (ring0 only). N9 R6 S, l% c4 I( p' R+ Z; j
0 }/ X8 J& o T3 c& N$ p8 _1 k/ @; t VMMCall Test_Debug_Installed# G& `. s8 x! p
je not_installed
. H" b: L( {+ X( a$ j5 S! Y0 G3 I
This service just checks a flag.
8 G0 |4 e( r, b3 C m/ o/ _</PRE></TD></TR></TBODY></TABLE> |