<TABLE width=500>& B: e- Q4 _* P8 \: _" d( j# G. M4 H
<TBODY>' t3 e# } Z+ Y
<TR>+ v/ R7 q9 N5 x* I, z
<TD><PRE>Method 01
( y' D0 L! c7 ]=========% P8 G2 k) x2 M! [0 n
9 s& V: J+ @3 @3 U: u$ X
This method of detection of SoftICE (as well as the following one) is
, t3 ]6 Y5 \. ^1 sused by the majority of packers/encryptors found on Internet.: S) N4 g( M: E7 d5 |, M
It seeks the signature of BoundsChecker in SoftICE
4 z/ F4 }9 g/ a( o3 x
7 T1 O6 w% L( K3 z mov ebp, 04243484Bh ; 'BCHK'
1 a3 a6 U8 [- m; M F. n mov ax, 04h
+ o1 x7 @& a* v0 D3 f- ]/ i o9 t int 3
, C0 f4 M% h2 |* q* c g cmp al,4" ]/ \( ^9 T+ Y. D
jnz SoftICE_Detected! Y1 H; h7 O* i2 ]+ n0 ^- M
" _4 L/ ]0 K# a8 }( `5 ]. w___________________________________________________________________________
8 u! E7 v( f. y2 n6 e. y
`! V- H5 f& XMethod 02) _* h9 `, n" m4 [, }
=========3 i; F' R6 k$ t9 Z
, n- T0 Q' `: H: f
Still a method very much used (perhaps the most frequent one). It is used, J- T% V* l6 P+ K2 K
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
/ X, @% h$ \" j# u1 a3 V8 |9 w4 d* _or execute SoftICE commands...
3 _! C1 ^& |5 p+ H }It is also used to crash SoftICE and to force it to execute any commands
# [2 L1 Q: ?. V! N(HBOOT...) :-(( 0 Y- g% Y+ J8 Y5 H& \% C' x0 e
% v2 a; O& ]/ [$ r9 X! L- gHere is a quick description:* W0 C+ m8 N9 }
-AX = 0910h (Display string in SIce windows)
1 _& L ]- R! _* R-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
5 o8 s! K+ G: J) t8 G-AX = 0912h (Get breakpoint infos)- f9 x# R$ l4 b5 [ @' a
-AX = 0913h (Set Sice breakpoints)9 W, W. ^ ?6 ^' i9 t4 @& A
-AX = 0914h (Remove SIce breakoints): k' c" R) }) q. j" u
( X6 W; J" S, @7 l9 m5 S6 hEach time you'll meet this trick, you'll see:
! }5 t( r# D: M% @7 t-SI = 4647h% X! K% d( ~9 [! G; U
-DI = 4A4Dh
) l) r$ D/ [& cWhich are the 'magic values' used by SoftIce.' I/ z* r0 k, @7 p# m* Y
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
: n4 A2 f" E) ]3 H5 ^% ^" V5 g8 i' g# T$ Y- A' P! D
Here is one example from the file "Haspinst.exe" which is the dongle HASP3 J6 @9 E b6 b5 {& u$ ?9 _
Envelope utility use to protect DOS applications:
2 l& E/ {8 j0 x/ q" V" F: v0 d
& i) |$ `- R0 c V7 n; R) ~; ^+ b) d0 I3 d
4C19:0095 MOV AX,0911 ; execute command.
# X% ]$ I0 T- k4 ]8 O8 }4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
( S) w/ V! E9 n" O! h4C19:009A MOV SI,4647 ; 1st magic value.
?0 K/ g6 }6 D) ]0 n2 {4C19:009D MOV DI,4A4D ; 2nd magic value.0 Y r. D% D! t# M/ G3 p
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)( M# Q$ ^6 ?* T6 m* M% ^
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
3 ^/ s8 W; M# u5 s8 \4C19:00A4 INC CX& w N& Z! f7 r3 @' ~- }. z( K& S; \1 R
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute- \, a7 x& ^6 `
4C19:00A8 JB 0095 ; 6 different commands.6 b* {( L7 ?& @3 @4 O: M( o/ X+ o
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
/ A) w# N+ A# `+ _: l! J4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
6 d2 c6 B l6 t' o
2 l: x3 Q5 z9 q: TThe program will execute 6 different SIce commands located at ds:dx, which5 c' n- D+ ]3 X Z( V$ @
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
8 m9 Z/ U3 ~, P7 Y+ X' Y2 N* h5 x+ k7 l$ u, z- }+ ]: ]/ D6 j4 Z
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
) m% L+ _/ q" I, Q6 r, u. C* p9 W___________________________________________________________________________
; l' t* `5 O O! T; Z0 v* O- q I5 g- e$ _) I2 Q
: t$ G# I/ T5 ^! I# H
Method 03# I, f% s( b, t1 r5 U% s& { j* B
=========- F) k1 [0 P% y/ k* b" |* c
1 z! ^# _$ l) ^Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
8 r. m( q5 [( b$ I- ]3 F' I9 I) Z(API Get entry point)8 W% A; Z: K7 \( m. y9 T$ c3 N. K' d2 d& |3 w
& ~" W* Q+ {& u! o, a
4 U, ] d" P1 | xor di,di1 e7 `" Z8 Q1 R/ p* Q0 c+ X6 E
mov es,di% V4 v" T& n3 _) Z, [6 i/ \7 \
mov ax, 1684h ) y! T. @: H: }/ h
mov bx, 0202h ; VxD ID of winice
" h) K6 C2 J# U- Y int 2Fh
7 |' E+ U4 @5 Q& P mov ax, es ; ES:DI -> VxD API entry point" o% f- \ K% S* @
add ax, di
% R# c n$ v+ {8 Z& t8 R% h( O test ax,ax
/ Y) C6 q; W8 { jnz SoftICE_Detected W4 @6 B! d- v
, A+ k- i6 C- W8 ^/ ^6 I- A7 X___________________________________________________________________________
# c/ g$ O8 \1 w! R0 [# b( g% F, @7 G3 ]7 K3 r6 k
Method 047 g, |' Q( s, |) M# S
=========
5 s4 d& G1 |; t& I% }" H5 d( \+ O/ H. C' [# G! c( [
Method identical to the preceding one except that it seeks the ID of SoftICE
" a% @: C# O/ d, X4 w8 kGFX VxD.- G2 ^0 r) ]; R; S$ W& u: h/ N" s
4 C! e2 f: \- o p9 b xor di,di
" C5 N2 [5 ~( j8 g$ z mov es,di. f& Z$ |; N% r/ R
mov ax, 1684h ) U1 E0 z3 x% n0 U0 W
mov bx, 7a5Fh ; VxD ID of SIWVID
# q* r4 Q2 m# `. ~ int 2fh: _" M5 e Q# K8 {5 h
mov ax, es ; ES:DI -> VxD API entry point
, y$ O" @5 O; N' e4 j& ` add ax, di
4 t2 w. ^/ C$ t9 P$ ^9 c v7 F3 ?, { test ax,ax& H4 `& j1 }! U
jnz SoftICE_Detected( `5 O; @; `! ~2 ]" z/ d7 k7 Z1 P7 O$ o
' F. J% g8 V4 @/ H5 x1 @0 D; ~3 n# U__________________________________________________________________________* n: T- m$ {# F2 ^7 A* q) A
0 W) b0 S( e6 I- s( g
, E4 q; S& V0 R$ j2 V) [& m' ]8 e
Method 05
/ e4 l8 T7 J. G5 }' n) [) e=========
, S+ f) X! n6 B* i! t& j$ J. x; q% U
Method seeking the 'magic number' 0F386h returned (in ax) by all system
+ B- C9 W" z. U. Pdebugger. It calls the int 41h, function 4Fh.3 ~. E& Z0 G& M' k- k7 N, @0 {& Y
There are several alternatives.
7 q2 M* o) T: c8 `/ y: o
1 U- ~/ X6 Q& ^0 C; h/ jThe following one is the simplest:
8 b+ U% h( [4 s" V8 H, Y0 h# w9 C/ u% V7 ]- Y8 s
mov ax,4fh
7 X( z$ o, d' U4 q int 41h3 }* @( W" A7 c e! H
cmp ax, 0F386+ K- X8 W+ [( W$ h5 [8 } R Z
jz SoftICE_detected, x; j9 b0 n6 c
9 v' z; v) M. `1 e- l0 B( ?
2 }5 |9 F( _5 E* R* m. o, wNext method as well as the following one are 2 examples from Stone's 9 g' o; B5 o9 j
"stn-wid.zip" (www.cracking.net):& Q6 ^* x. P7 @; B& P, H2 x! E" K. |% U
! r# l4 D2 z0 X
mov bx, cs
6 G. v4 e; u/ ~0 K" X& x lea dx, int41handler2
: N- J# T" Q3 h! `- |% I( |$ ] xchg dx, es:[41h*4]
5 H1 E8 h4 \) j) F4 ~+ Z" X# \0 m7 ] xchg bx, es:[41h*4+2]
1 c* a+ r& b- \1 W9 Z- m mov ax,4fh/ z: J0 }, d1 N; L5 d) w t4 T! S
int 41h
5 T M' {& E5 J4 E# v } xchg dx, es:[41h*4]
* u7 S9 X! \; T" i1 U7 s xchg bx, es:[41h*4+2]
. S$ u! K& f2 j1 N cmp ax, 0f386h
- L3 v' O" Q0 n) E, `! S jz SoftICE_detected
; I' _2 [3 E K9 g
, j7 Q. H6 G8 r# t# w/ H/ ^0 Gint41handler2 PROC
9 m# ^7 e$ o) X iret5 v0 @, y: M" o" D- G0 M
int41handler2 ENDP- J) P, e2 x5 {& ]! @- S4 l
1 w4 `& ~3 P6 b1 F' m8 n/ j& } u5 \
. ^" A. d( [- K. Y
_________________________________________________________________________
0 C' i/ J4 U% U$ v& k( k3 T' U7 @7 B# Z9 M" f. Y* L' g! W9 G, r) L* y! t
/ P$ |8 [( c/ H$ G" v& ?6 ?1 Y
Method 06% n6 X5 k0 o9 A0 R( D' j7 M3 @
=========
) m, ]3 F7 h0 {" h; n ]: b$ n& T5 ^1 L" J9 K) n
! m B. e' z; r- w8 _0 n1 i! H2nd method similar to the preceding one but more difficult to detect:
. h+ P. b( m8 d& ?( p9 h, X' W4 \
7 G$ B5 z% G) }# b* x% r* e. _/ \8 N# K! y0 F' M
int41handler PROC
* N$ x5 Q+ `" b# @4 G mov cl,al
+ C' b! ^9 N4 w+ I iret, t" I: l1 f0 \ v7 w
int41handler ENDP* H3 @, m3 N+ P H+ U
4 n+ Z! c) c8 m0 D% g
1 }( F8 z _, l5 j# { xor ax,ax$ \3 n- ^" B' j! A
mov es,ax
7 V) y2 k. x* H9 Q6 ^) E% r. S8 G mov bx, cs( F. P# @7 D7 c% O
lea dx, int41handler3 L- |# E7 ~" ~# G
xchg dx, es:[41h*4]1 z7 Q2 E7 @' B1 s0 E/ }
xchg bx, es:[41h*4+2]
4 B# j# |! c3 a) e in al, 40h
+ c' J# F" y' k2 K- |1 N xor cx,cx& a) C! h! Z r: w3 s
int 41h4 P \# E, }& p) ?# k4 w
xchg dx, es:[41h*4]
1 B: c# d$ r2 N7 J/ ]- \% B xchg bx, es:[41h*4+2]) W6 Z( L+ n" f
cmp cl,al4 m1 I8 ~4 D" r" J
jnz SoftICE_detected! s* J, B: o3 X/ `) F. M+ t
j& z% @- ]# I9 U, v
_________________________________________________________________________6 k4 F1 ?5 S1 {3 l& d ~( ~
, i! Q3 D8 w d. U; N* f. B" d+ {Method 07, ^9 ?9 p2 ]7 J) l, F# f
=========
- b4 R8 C2 S2 M: s
( d- B; a8 z" D& E* u2 oMethod of detection of the WinICE handler in the int68h (V86)# X, {! Q3 i/ m4 ` [$ U
5 c8 o& S; e. F: u) t) W6 ~+ U
mov ah,43h; C( p( I% H# W4 h5 Z
int 68h& L( i% N" E, n" _( G, Z
cmp ax,0F386h) j1 j/ k5 Q- S% _: U+ ~
jz SoftICE_Detected
5 |( Y1 Y) q8 W: K0 p1 E/ F/ ^+ H6 {( C
: q0 ~* ~' P E$ `=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
. W" x1 j4 V+ t0 ^' I7 K app like this:
$ J- i: ~. Y$ i$ Q/ s7 M1 r( i. Q E+ i: y4 [* z) t; e R
BPX exec_int if ax==68' n/ ]# |; H9 P2 b3 @9 a" `. g' a
(function called is located at byte ptr [ebp+1Dh] and client eip is: C6 W H3 X/ I1 ^4 x' s* ]/ W! v5 s
located at [ebp+48h] for 32Bit apps)$ d+ q+ A _6 ?4 e, |/ \1 t6 L
__________________________________________________________________________
1 t2 i4 ~$ k3 Z$ ?- F+ h# r6 o9 }! ]! a: G
, l% F# W2 p7 @4 ?$ k* [. V3 DMethod 08
) `9 e% W ^; r4 h1 U2 I=========5 O1 Q" \8 I" E; V. w* o
' \+ c( t/ P1 w1 }+ T- z# Z& iIt is not a method of detection of SoftICE but a possibility to crash the
o3 f3 x& g6 z7 Usystem by intercepting int 01h and int 03h and redirecting them to another" v$ \1 e& X: V N
routine.
4 k# ?/ ?0 [* }, T/ A- oIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
. l9 r; c3 \7 Fto the new routine to execute (hangs computer...)1 h4 }2 Q5 I, m" E( V9 G
0 ^) r$ _2 j r: s* k7 w
mov ah, 25h6 B, i9 C" I% o L6 ?
mov al, Int_Number (01h or 03h)& q- i. n- ?+ ~, s9 n# a F$ M/ K+ K4 U
mov dx, offset New_Int_Routine
8 q8 s; A# I% s int 21h
% V9 T% H' m! a2 O2 ^+ m6 A9 @& l! }* [- C
__________________________________________________________________________8 h$ i _- M4 n2 G; q7 E
! L9 e) E/ K/ ]5 v& EMethod 093 f9 F$ F0 S4 \, Z i/ X) G
=========
' q/ v! n& d* b+ y4 W* q; h5 O) a8 w9 I8 k) d( j
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
7 ~% M7 M! l. G7 N3 B# S0 R* x0 L$ uperformed in ring0 (VxD or a ring3 app using the VxdCall).
( F. i2 v8 A( }& i8 z% X' rThe Get_DDB service is used to determine whether or not a VxD is installed
, G# i F" M& k7 F4 Y& r) }for the specified device and returns a Device Description Block (in ecx) for9 {+ b4 [: w& B9 i1 ^9 X8 Y
that device if it is installed.0 k7 u' D4 M8 n8 I6 i
! P+ y: j7 \0 {$ r1 G0 w mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID' T5 a" W9 p1 B( ~8 }' C* C" l; C
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
6 }# M; e& K! Y1 |" n( g5 C e7 ? VMMCall Get_DDB/ m$ u; `% e7 p- X' d
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
8 G2 g7 L N0 n; R/ i m9 L7 A3 v2 c1 M) Q4 `2 ^8 k0 c
Note as well that you can easily detect this method with SoftICE:
$ }5 A' ]0 ^ R1 y) d. p0 o bpx Get_DDB if ax==0202 || ax==7a5fh& E% y7 a- X8 K [' F2 p) a5 c
7 x" i4 {- M) L! G7 Z0 J+ [
__________________________________________________________________________
5 ~& R3 s- J$ T0 L6 l$ \- _- n v1 P3 O! h0 t/ T: L: I
Method 10
; b4 o8 U$ L* [, I; }# g- M$ |=========
; c- j }5 a8 y! O& Y: y
5 M. X& @8 @2 P/ L=>Disable or clear breakpoints before using this feature. DO NOT trace with- q; b5 j* ^, O, D7 ]0 A
SoftICE while the option is enable!!9 T8 F/ W/ u+ h: c" ? e! C' q
" V7 u! {+ z3 hThis trick is very efficient:
% N$ r% b8 W' q Fby checking the Debug Registers, you can detect if SoftICE is loaded. ~$ [5 t+ t) t5 c3 @
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if& I, P; x7 S S2 |* @' i" d: `
there are some memory breakpoints set (dr0 to dr3) simply by reading their
: @/ X9 w7 Q6 H. fvalue (in ring0 only). Values can be manipulated and or changed as well
( R: O" L6 \2 L3 W1 f9 W(clearing BPMs for instance)* I3 f/ s8 A9 V3 z8 s) j
4 {) S1 j% B$ W__________________________________________________________________________
' k/ [" l0 Q. \. X5 n$ x7 y6 }1 t5 b) d4 s8 v, E, D- g9 z
Method 11& t' ?% E! n1 s2 [8 j, C
=========3 I4 s8 Q# r9 s8 Y$ {! p% ^
3 |; F) u1 i& r% ?' @1 E2 r1 L
This method is most known as 'MeltICE' because it has been freely distributed+ v9 z) W1 B! e4 x
via www.winfiles.com. However it was first used by NuMega people to allow
& S$ f& f4 o7 O' RSymbol Loader to check if SoftICE was active or not (the code is located1 x8 k$ c5 z. k/ s c. @
inside nmtrans.dll).; `3 h/ E# T; W4 a# u" u
+ |4 H3 r' c* T( `) R2 t2 xThe way it works is very simple:+ c/ L0 I. z4 e5 V! o* ]3 j0 m" E9 V
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for: ?/ ]+ o& p' W9 Z2 K) l
WinNT) with the CreateFileA API.
( S$ b$ h3 t* M& }! X3 N8 ^9 |# n2 T/ Z- N" ^& d8 k6 |
Here is a sample (checking for 'SICE'):
& x; k* U# j. D: u' X! L& o$ D0 E" a& U/ w0 Y1 p+ F
BOOL IsSoftIce95Loaded()3 J+ {, D6 J4 Z
{
0 C. N! Q) J; }& u6 k, m. Q HANDLE hFile;
, N, J6 @ V% J* e hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
/ \# d' y* Y: e* y3 L FILE_SHARE_READ | FILE_SHARE_WRITE,
: j# z4 H; l* O0 F k NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
; O4 \0 y+ ^ T8 D- ]: x. X( Y if( hFile != INVALID_HANDLE_VALUE )/ }, [( o e# j+ u
{
5 r& V- N) Q6 D CloseHandle(hFile);$ V+ _! C! H8 L2 f9 K
return TRUE;5 F! e; `0 f. u$ s( k5 R: s
}
" r: X$ k, p7 j4 p! y2 U% W return FALSE;3 X4 d- X9 i$ d
}( P9 M( T, @* V8 I' b& b7 E
! X$ V; Y9 _# k% C7 b% a: a+ o
Although this trick calls the CreateFileA function, don't even expect to be
1 t+ M% c, F, y; k+ w$ Lable to intercept it by installing a IFS hook: it will not work, no way!
, E* E8 A* j. ]$ pIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
' M* X# b. W7 R' `2 L5 h) Tservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
# u$ r' W* F1 z% F- Y9 v5 q' P' ?, k5 Pand then browse the DDB list until it find the VxD and its DDB_Control_Proc9 C5 b, C/ @# e8 z5 T& i. H$ C
field.1 U6 G; h) J' z$ O
In fact, its purpose is not to load/unload VxDs but only to send a 6 ?1 J9 y. R* G4 U9 E1 d
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
4 W, Y# q p4 i/ yto the VxD Control_Dispatch proc (how the hell a shareware soft could try/ G/ x, j/ [6 c$ J0 v2 P+ h% v- y# L
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
2 L2 U1 [6 }! pIf the VxD is loaded, it will always clear eax and the Carry flag to allow& ~2 g$ f3 m5 ^9 l. T7 M8 {
its handle to be opened and then, will be detected.
" i) r/ {) ?$ J# {* b: ]" q0 xYou can check that simply by hooking Winice.exe control proc entry point, i5 e/ b6 Z; }# J) \( g# ]
while running MeltICE.
" ~) E8 s) k V; V
- ~, j( Z+ m4 H6 b t! q0 X% N7 N4 v9 ~: ^$ o4 y
00401067: push 00402025 ; \\.\SICE
0 a9 {. w% @: I3 h6 \6 l$ T 0040106C: call CreateFileA
8 O4 B" \) y1 b1 B 00401071: cmp eax,-001
D8 r$ y" u3 i" l# d$ E' A 00401074: je 00401091
: `8 A- W S8 t( G$ z4 T, K6 [. n8 L/ R
3 d$ t3 q! r O# h# z* u4 M' i
There could be hundreds of BPX you could use to detect this trick.
3 I& `* ]# D4 K) w, ? i-The most classical one is:& b4 c/ m1 L2 D q* Z ]
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
5 ^+ K+ I$ P3 f9 f. r9 C9 t, i *(esp->4+4)=='NTIC' Z5 `# q- [$ X2 T+ M0 d- D5 q
T: O7 E! J# }+ c4 p
-The most exotic ones (could be very slooooow :-(. u- I$ l% r1 [2 g( F) R
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
& Y3 P) s, T% S/ W ;will break 3 times :-(; h0 E1 z. C8 f3 q& \
4 Z2 D# v. W# Y6 u2 H3 k$ Z' F+ j-or (a bit) faster: 5 D& H( L: F7 e, X
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')& `5 W3 ^$ v& w% y+ i4 r' n
! V" F1 \3 |5 [% N4 H BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
. e k6 u- F$ r' P$ ]0 L ;will break 3 times :-(( f, ^/ Z# _8 B5 }2 J
b7 ^- O$ Q4 p J0 K- |-Much faster:
2 C# S+ `/ {1 d* ` BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'+ R+ C. f4 M, ?2 s6 b
. Z9 B6 g+ b& e
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen: ~. C5 b) z: s1 w7 F* W
function to do the same job:
m3 x6 @; } o3 v: C+ I0 ?: L! U1 W2 c% N% X3 v7 l* M: D
push 00 ; OF_READ
( W; F! t* F) u& ? mov eax,[00656634] ; '\\.\SICE',0
6 }2 Y6 _* b3 @4 k; ], z+ W# x push eax& V& l4 q. b& a
call KERNEL32!_lopen
( J5 s- S. q$ S- i1 @/ v7 u inc eax5 l, L2 h- j7 ]& k$ o# r
jnz 00650589 ; detected
; `4 x# M7 b/ y' e( w% m7 Y push 00 ; OF_READ) P: E" ~5 m7 R+ O
mov eax,[00656638] ; '\\.\SICE', @" F; x0 }4 h8 ]
push eax
2 S3 N; P2 ?% O s& {6 ? call KERNEL32!_lopen
/ w; `" F2 g0 W/ Q' l inc eax0 ~/ @! A- t! `/ _0 q
jz 006505ae ; not detected
. n- J5 X# E( c/ k4 G3 Q/ J- V
5 g6 w4 i8 S3 I7 S
! _: v5 W# ]) {__________________________________________________________________________ B; G; e7 Q' f. u
3 ]+ J2 ]0 ~2 u( RMethod 12
& }. i# ?9 c8 X6 {) t0 W=========
' j+ K: Z ^/ L/ J) B7 D
! o8 D, x( ^' ]This trick is similar to int41h/4fh Debugger installation check (code 05
& a+ [0 s, H$ M0 y) V& 06) but very limited because it's only available for Win95/98 (not NT)
; Y7 J. C# {; c0 Das it uses the VxDCall backdoor. This detection was found in Bleem Demo.# @# }6 A9 N; x. d5 i# S, K
3 \3 b& Z& i( Q. L5 R+ d push 0000004fh ; function 4fh3 v9 d& G+ `0 k# [5 v! Y
push 002a002ah ; high word specifies which VxD (VWIN32)/ @7 H) x$ Z+ Z* Y- O
; low word specifies which service
" @, l4 R& S4 r- n, _& i w& B, ^( l% n (VWIN32_Int41Dispatch)
. L& D+ U7 x- B3 q2 b% S call Kernel32!ORD_001 ; VxdCall: z8 @2 C$ ?& d, ^/ n3 f
cmp ax, 0f386h ; magic number returned by system debuggers
7 ^9 Z) K4 o) [ jz SoftICE_detected" E$ Y' M& ~% c( c" n
& N- U0 {2 B4 _Here again, several ways to detect it:
5 p' W7 n; `4 Y! @; J
, @. e) N! T1 G BPINT 41 if ax==4f
* `* j" _5 d+ _, {; B$ {; D, B' Q* z" r3 {# z
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
! x3 X, I: |% V( h. O5 Q2 l. @. }% j& R
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
6 k$ Q8 k; A: J3 T1 o. D
* d3 V2 O# K* T BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!# Z1 y" F8 q1 q1 u; U0 M/ O" S& F
k+ _; d. J- T7 ]+ k9 ^; F `
__________________________________________________________________________
' S5 ]3 r, {& Z6 p6 Y6 K% n8 U, u/ j3 j( R m8 I
Method 13, {, m: }* S' G5 M
=========4 P" u* z/ e w0 [( U: g/ H
1 C$ i4 T& M X6 X0 ]Not a real method of detection, but a good way to know if SoftICE is
9 Z( ?, b' y0 R/ o# O o6 Ginstalled on a computer and to locate its installation directory.
) X( N/ ^5 Y% M% VIt is used by few softs which access the following registry keys (usually #2) :
- k7 `! N+ d6 N1 `" P
, `8 ]/ }3 z! j5 y& e. k-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( Q/ [. G) y- I4 _" J g& y
\Uninstall\SoftICE
# R M& m2 `8 G; s4 {. ^$ J-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE' V& }- J. U8 c2 T* W+ ^4 ? R
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
, r' O- H. t5 u! c- {\App Paths\Loader32.Exe, M/ Y6 s5 ?5 u ^* J7 ~ }8 V4 @
+ `# W9 y4 {& A+ `
* n/ Z2 s- L& Z& k: c' b& _6 ]) H
Note that some nasty apps could then erase all files from SoftICE directory1 G: }8 t9 b& |/ h% k# u9 w* C
(I faced that once :-(
" Y3 q% b& w2 D: w1 M4 R% r' y/ B2 X, B" @# a. `$ P& M
Useful breakpoint to detect it:& r) P: ]' D# c, P, h
- H3 m2 a" S6 E- J5 U
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'( D9 q, W6 ]* G" u9 v. N/ H8 b
I9 J0 e$ }, I/ S/ a$ C; n__________________________________________________________________________
% ]* }7 ?; t/ D0 K8 K* w9 l4 A
1 ]. ?- K. z: _' A2 c: x" j; B) o% Q2 i/ t0 _ R
Method 14 + b4 ]% `- U! a8 Q
=========; T. ~! I8 r' c" u9 Z, \; Y& L. ^
4 i5 _ w2 I3 ?4 }5 Y5 @& [- O8 pA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose; B) [( K6 ^$ f4 T
is to determines whether a debugger is running on your system (ring0 only).
7 H' `( H' h/ [ Q' _5 w- O. d' Q' a8 F
VMMCall Test_Debug_Installed; ?" R" }7 G Q* e! T" k8 c* }
je not_installed
' s+ ?5 z' U" a/ b# A0 }& \ u5 B7 q& [! I9 @) |9 r7 Z; a
This service just checks a flag.3 C7 k: y( ?! o5 L6 V
</PRE></TD></TR></TBODY></TABLE> |