<TABLE width=500>
# ^' Z8 r# s U$ W<TBODY>
+ c. S0 O' w( @, Q<TR>
: o! N- z4 C( \2 A K) m& ?<TD><PRE>Method 01
( E4 ^; V& d8 v {6 E=========' _5 K8 i) a' l4 }% i( o5 K
% U$ S9 V3 ]1 A/ PThis method of detection of SoftICE (as well as the following one) is8 b5 k& _2 Z0 j7 a8 H2 t; c
used by the majority of packers/encryptors found on Internet.! _8 R( R. L: M7 ]
It seeks the signature of BoundsChecker in SoftICE
' `; d, ]. M% ?" b
$ d4 \, B( E/ B" q1 J6 G' a' U mov ebp, 04243484Bh ; 'BCHK'8 }. K1 ^2 [$ }2 U
mov ax, 04h2 [+ E. V6 J* @/ q! Z+ A4 ?
int 3 - s! c k! T* P! L8 g* ]4 c
cmp al,4" `- u5 ~% |6 h
jnz SoftICE_Detected
' C$ z4 k/ f, y- a+ J' B. f- O( k) Z& n
___________________________________________________________________________3 K/ |% _% n' U: k" `
! X' t4 t9 N) L7 o8 Q z- e3 L
Method 02- m4 w! u, O+ M# x w' h
=========( t( K8 U) u) _1 H! E3 Z
# g( F9 C8 S" C2 a' {Still a method very much used (perhaps the most frequent one). It is used
8 J" k! l+ x$ d/ |5 q: [to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
6 u! k% i) j6 }or execute SoftICE commands...
" A) X# S% I/ m1 s. B- ?It is also used to crash SoftICE and to force it to execute any commands6 {; H3 f" K! ^' ~$ m6 w* d
(HBOOT...) :-((
4 p$ }# D2 A5 t7 j/ q6 U! t" A0 V2 ~' g
Here is a quick description:/ N8 a1 M5 G3 C5 b p
-AX = 0910h (Display string in SIce windows)
9 A' C, h0 w: W' K; c' w0 ]-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)3 A( }1 q7 D; A2 E5 A8 U
-AX = 0912h (Get breakpoint infos)
1 X' X" K1 e" N$ l-AX = 0913h (Set Sice breakpoints)
. X+ n) ?( ^1 v2 X5 b, @-AX = 0914h (Remove SIce breakoints)
$ q: C/ E4 O: p( `3 \3 l7 y$ J5 g! l
Each time you'll meet this trick, you'll see:0 \8 @! `+ a$ Q! H
-SI = 4647h
$ D; ^' i' ^- i* W' X-DI = 4A4Dh3 z# D, F" w& H/ H |3 `
Which are the 'magic values' used by SoftIce.0 I! x8 K- Q' z
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
* Q& I, P! g+ K. u! m& [% o0 c; [, p& T
Here is one example from the file "Haspinst.exe" which is the dongle HASP U* n- O& E" I8 b5 E
Envelope utility use to protect DOS applications:
5 R: h2 `5 `3 v( U/ h
9 p- ]! t$ T- K2 p% h/ U1 x
8 f- Y( ^' X) @6 H9 ]# ~4C19:0095 MOV AX,0911 ; execute command.
2 B/ {9 M' T- U3 D0 g9 |4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
b- _* r" e3 @4C19:009A MOV SI,4647 ; 1st magic value.
9 m/ l5 i5 @2 Z# F5 M4C19:009D MOV DI,4A4D ; 2nd magic value.
7 _1 S- n! W3 t4 K8 P7 k, z4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
% f |- }% R$ s$ @3 p6 H4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute- w4 v/ Y% c9 `/ d% F
4C19:00A4 INC CX
9 z5 D' t1 G) W0 |6 c+ f j- U4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
. X/ `* _" K) L/ \5 B) k; q4C19:00A8 JB 0095 ; 6 different commands.
1 Y5 i' J5 N. e4C19:00AA JMP 0002 ; Bad_Guy jmp back.. c9 ]5 `4 x7 y( h4 c9 }# i" Z# L
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
' n7 d- y2 j1 _ t( o6 D5 w
; e8 h4 Q& o1 ^5 f& ~6 GThe program will execute 6 different SIce commands located at ds:dx, which
4 V8 h7 D! j& \0 I1 g5 V6 W: L% care: LDT, IDT, GDT, TSS, RS, and ...HBOOT.$ g$ e- [. D6 @9 ?3 Z
: R+ O9 m/ Q; U" S% z
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.- Y" a; F6 s: l' x' b: m: ^2 [
___________________________________________________________________________
. [0 |- J |& F( e6 e, i4 P: \5 y+ u' F
F) k: G) {4 t* d* g+ _5 L0 r
Method 03: G% B1 r/ z4 r) ?/ u
=========
@' b8 V) K' G! i+ o0 w4 B2 |- ~, G1 j
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h% Z- L4 \' p0 s6 N/ g! E6 [
(API Get entry point). _5 ?3 Q3 U9 ~4 V( T) B
$ c& ]# F+ }' B! p7 J( l7 B5 d" t1 ~' ?2 u9 k3 h& `% ]. ?6 g: y
xor di,di3 X5 e- r7 @; [) [- x
mov es,di
% {- k' s' Z: u, W mov ax, 1684h ; _9 j( ^, j( v9 J1 X: {
mov bx, 0202h ; VxD ID of winice
2 f' h5 m/ f: N, C" E int 2Fh
) O" c( M: h T mov ax, es ; ES:DI -> VxD API entry point
) n$ ]; b" s" s: L9 l8 {! _" ? add ax, di
& n: |2 G3 U: n/ L- y7 ^0 F& g test ax,ax
& k1 [. l, `6 J/ Z: b0 `& A' u- ^8 v jnz SoftICE_Detected9 o; F% T7 r3 T- B& J3 C3 W" P
( l, f* x: }6 S4 c2 a
___________________________________________________________________________- @ C- s4 P) z! R: N$ Z
" {3 t U8 M# O6 A, }$ fMethod 042 d( D/ z3 X5 n
=========1 Y. X& {5 j1 d/ H5 q& X
1 V+ ?. J' n) H6 cMethod identical to the preceding one except that it seeks the ID of SoftICE1 D- z; [0 c5 ^
GFX VxD.
" w7 Z; R! N$ ]) c: t+ b% j" o: O) ~) m$ c5 T1 B) S; Z
xor di,di( l- e( ~$ c8 m! [. b# T- t
mov es,di
$ S# L( y# Y0 [8 S3 ] q2 q mov ax, 1684h
! U8 _/ N& L' L# E$ M mov bx, 7a5Fh ; VxD ID of SIWVID
. D1 F4 v0 X9 v. w int 2fh- R- f l6 A' r2 c
mov ax, es ; ES:DI -> VxD API entry point
7 A- K2 O+ Q* ? @- T/ r0 P add ax, di
C' k2 P+ U( l test ax,ax) |+ L) M6 H9 v: e/ w( E
jnz SoftICE_Detected( b. w, a& R' t) N
- a* p2 O, H) @' B/ J e- e
__________________________________________________________________________
! p% o% G' x7 `
1 {& c4 W& w) ^$ |3 l" J/ Q* ?
+ v! H5 U2 _# T; ZMethod 05
. C" Y1 H2 m% s3 T=========! G, o0 i" G) E: L
0 i+ L( }, G9 r) F+ V( Z8 q& S
Method seeking the 'magic number' 0F386h returned (in ax) by all system, U/ I4 G7 l9 r& q) T( S
debugger. It calls the int 41h, function 4Fh.
( b' ~: z0 ^+ Z8 ?3 wThere are several alternatives. # X4 e5 K O$ M
1 ]1 X: t3 D1 q6 E: v$ k( a! h
The following one is the simplest:
- r( Z' _) E9 p" r' V
! s9 F' j- ~5 j# h% s3 {( [2 |& q mov ax,4fh5 L4 |9 ?5 v% }* l' i1 q. K
int 41h$ O0 h3 n7 I* [" I! Y
cmp ax, 0F386) z' D" d9 |/ R
jz SoftICE_detected( ~; O+ t0 n p3 W6 f, Y7 a
6 w1 _1 Q- r1 S( s& g
8 b! A5 \- L% |' A
Next method as well as the following one are 2 examples from Stone's 3 P* F0 w) V E4 e8 r7 @! d& K
"stn-wid.zip" (www.cracking.net):. @* ~8 j. ]2 J1 s+ z* i) x) q& P
7 a+ C- D+ u- J% C! h/ A mov bx, cs
; M5 v2 g% ]: r lea dx, int41handler2. g" f' @1 h) m* A2 J. b
xchg dx, es:[41h*4]
' d6 @ l+ B5 W7 S xchg bx, es:[41h*4+2]0 P! w( C$ O( @1 z- J' H i
mov ax,4fh
1 k3 Z: W1 H' U1 X int 41h
- L: p6 T' @! a. w6 D+ r xchg dx, es:[41h*4]2 a; F! ]( ^' f' p% b
xchg bx, es:[41h*4+2]7 K, g* d" `6 C. r J* t, v
cmp ax, 0f386h' [) e- b& l+ ?* a2 p
jz SoftICE_detected4 T; H+ q; i* v" S& G" O( o; K* \
6 F( }7 C+ W O- `$ e$ I
int41handler2 PROC6 J4 P$ n: T* t
iret
( G5 ^+ N% ~: R& H W% D' m* Lint41handler2 ENDP; v/ }! f4 I/ C5 E) q
/ T* Q* E* S9 s6 t1 n9 v+ ^7 H
( Q% c5 B1 S# f/ b, x n' p_________________________________________________________________________2 q$ i5 p* }1 g$ H6 A$ I' `. y
+ n; h* y. \5 P* }
( Q/ R& J+ r$ J
Method 06
( m" ]$ h; J" G' u+ d=========
5 Z7 n4 e. m1 G( C i& O# K1 W
% B( V# C- d( \- C% M, `0 C' F C. ?4 m- l; X
2nd method similar to the preceding one but more difficult to detect:
, x. x, U3 [+ Q3 U8 _- o+ f
' ~1 L- I e3 ~% g5 Q! D, Q) a A9 q J0 t' }
int41handler PROC
+ m9 m. W6 |, N0 ~: I3 R/ w mov cl,al
& k/ i5 s5 m; `' J; ?. ?9 R8 x iret. G V4 g) O( \1 Y# `5 o
int41handler ENDP/ f U5 w0 e' N& d/ w. c9 S0 q
8 l* G1 |" v" e6 s, i
1 V9 ~) B; A( L. B/ o6 O
xor ax,ax
8 r. x& N7 z9 h2 v mov es,ax5 Y$ X7 ?6 a' Y1 U- M
mov bx, cs
& l5 M0 T1 @& y) P lea dx, int41handler6 |% D+ w6 r% |7 x( P
xchg dx, es:[41h*4]" `/ s+ d1 T7 ?. v7 J
xchg bx, es:[41h*4+2]
! d0 q- \0 j3 @: S$ U in al, 40h
$ E \' o( {, L& G xor cx,cx
H% f$ Y% I2 k: Z. o int 41h: Q6 G+ N. o. V4 @
xchg dx, es:[41h*4]
y$ O; s, L2 g2 F xchg bx, es:[41h*4+2]
" L0 h0 b% a8 c8 ]5 x6 _ cmp cl,al$ O2 G7 d- M( R( x
jnz SoftICE_detected1 z" N/ U7 U) U' j2 e
* [) s7 ~3 M( w. \
_________________________________________________________________________9 e: j- V. K% e5 X
# ?* r9 Q( e$ }8 V) x
Method 07
( q) G9 J" F: {9 }=========8 M' ^1 n; d% {
# k D/ p. s0 ]
Method of detection of the WinICE handler in the int68h (V86)
3 t W: |5 U4 L' G- z
c( o u4 s3 @' i; R mov ah,43h
) ^1 m6 y" l2 l& s! w. p/ W9 h int 68h
n, M& U$ \2 g; c. N cmp ax,0F386h/ }1 k; t. d5 u1 x3 C
jz SoftICE_Detected s8 {3 v0 I) s+ I( q
5 q. x$ B9 Z2 I" y9 y7 f
: f2 _1 N$ w. e! P5 ^=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit$ Z4 w' \- J9 L- w4 a E% v
app like this:
5 W! k& P/ o( E& |) T6 n3 K* Q! c7 S$ }6 B" r/ ` `4 P& n7 J- `& K+ z
BPX exec_int if ax==68* X7 D# n* Q# p( W1 A3 x6 F
(function called is located at byte ptr [ebp+1Dh] and client eip is
4 v: S/ V& w) h1 t$ ?9 B: r located at [ebp+48h] for 32Bit apps)" V7 H/ T' A7 t' U- x6 G3 i; Y( h3 U
__________________________________________________________________________6 c) _" u! ], s1 E; P" V& }5 G3 ]
" r# t' d3 w: {2 q+ E0 O* H3 ]- r: p# R
; m3 Q0 D }$ A9 C
Method 086 ^) C# w' V" o: T: A- K* D
=========
1 x5 S/ L* {4 |( ^3 ^" B3 A/ z* ^& F3 V
It is not a method of detection of SoftICE but a possibility to crash the& m8 L& d2 ^( F+ y8 `
system by intercepting int 01h and int 03h and redirecting them to another
+ X6 j7 S" \# d: jroutine.+ w, k* w# M i9 s* A, `0 c
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points7 @( \8 b7 A! q+ ]' \& [# d% }7 P
to the new routine to execute (hangs computer...)& k `+ G# Q' V9 C, j
# {% V" k( t3 p9 ~' |4 m, g
mov ah, 25h
0 j8 `' o# Y" i' M* C' n' j# ^ mov al, Int_Number (01h or 03h)
, P+ O1 n5 n$ A. i% Z mov dx, offset New_Int_Routine) l0 s/ y5 O$ W @/ n# ^8 E5 H
int 21h
# C; B) X, W/ Q- b4 n9 k9 @2 w$ K/ m+ p* U! g2 g6 @' I. v6 \
__________________________________________________________________________
$ w( v, b0 q8 O. v }% E4 s3 ]6 ^" ~9 \+ V
Method 09
( ~8 H+ O$ W f, f6 M! N& t$ F=========
/ y. }( x: M9 E9 h9 r! x: {" @' L- }' d: D$ F4 h c
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only7 y2 u8 E4 n( v- C( j; Q' A6 x
performed in ring0 (VxD or a ring3 app using the VxdCall).
% j4 @# I& [0 ?7 o3 tThe Get_DDB service is used to determine whether or not a VxD is installed
" ^; ~ V( J8 I! wfor the specified device and returns a Device Description Block (in ecx) for
! R: j2 f9 }! @! d2 A9 c9 Fthat device if it is installed.) o3 [- U0 `( V" L5 T5 m. ]
9 g% a7 c$ ?( p, a, ?. c8 f; ? mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
7 Y% {& z3 Q+ r# _" Q7 v mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)7 X- P4 l- T) M# m& B$ Y
VMMCall Get_DDB2 }3 b8 ^" u0 A: {$ [
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
; S- j2 }) |7 ^( Z
& Z1 U6 Q" J M- E7 TNote as well that you can easily detect this method with SoftICE:3 W3 C7 `! D0 c; D& ]) o7 l
bpx Get_DDB if ax==0202 || ax==7a5fh
" X5 w) n y4 d; l0 u% Y: ]" z0 J2 S1 F3 ^; U1 b
__________________________________________________________________________ [4 i. \0 N4 a5 t; i: N( |
' }! J0 V9 }% P
Method 10/ F# w6 g' D& H6 u; x) ^
=========
% W4 v4 f0 \( f5 m: M% G! F6 g. P" y) E# G( H
=>Disable or clear breakpoints before using this feature. DO NOT trace with
# W5 K/ B% t C" I SoftICE while the option is enable!!6 Q1 l: t4 |; s' X5 Z/ G/ Q
% h6 z ~ F) i4 f. L- W- G5 M1 HThis trick is very efficient:; r* z L1 l- ^3 s
by checking the Debug Registers, you can detect if SoftICE is loaded2 g' v# }+ J R/ F- {
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if4 O4 g' J2 ]4 d8 n7 c
there are some memory breakpoints set (dr0 to dr3) simply by reading their. i# \* r: u5 H$ [
value (in ring0 only). Values can be manipulated and or changed as well) @4 W3 o( A7 O7 O; B }2 f8 d2 u
(clearing BPMs for instance)
0 R8 Z3 \& W$ f+ f/ ~5 d5 b* V- V" D
__________________________________________________________________________
3 o& p2 Y& h4 `- W4 L9 V R8 B0 i; s6 Y: P2 a* U$ u2 c. k
Method 11
# B& l2 \$ Q3 ?0 L' q, w=========# c* ~' o) Z! b! B* Q w9 ~
9 D2 \; [& e7 z; J! h
This method is most known as 'MeltICE' because it has been freely distributed
. X" t* `9 [5 Yvia www.winfiles.com. However it was first used by NuMega people to allow
( O$ U2 ~" e+ a: ?& ^Symbol Loader to check if SoftICE was active or not (the code is located: \+ ^1 w& W+ J( h5 s4 k/ f
inside nmtrans.dll).
3 j) F( e) i0 t' ?5 _; M& Z6 m- w) Y6 f# L& X' M$ m' B, l
The way it works is very simple:6 r0 x; ?4 m. O/ p3 x& E& [2 k
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for2 T' F4 e; S, q3 d
WinNT) with the CreateFileA API.. P+ P- y' E9 N! ~
! C% R! y; Q4 q' P/ k5 V( w, q
Here is a sample (checking for 'SICE'):+ V8 y) y, F- z1 W
& F, R9 {8 ^" \( u" ~ T
BOOL IsSoftIce95Loaded()6 \ v0 @* ^% v3 f; w1 b' v
{
2 `. x, r0 C" X9 K) t; s& A4 F HANDLE hFile; ) o, h" [! b9 T1 w5 B$ e7 M: a, e& d0 Y
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,# [$ l6 a, N5 u* x n
FILE_SHARE_READ | FILE_SHARE_WRITE,
, [* {$ j) }% _ NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
y, [3 _- |+ ~7 L7 _; U0 y1 V/ h if( hFile != INVALID_HANDLE_VALUE )
' z2 V0 t, M/ X3 ?6 ]& C2 ^( i {
* s: f, ^# Z0 X- [ CloseHandle(hFile);
* N! G+ w- X3 t' s+ C4 o9 V& h! @6 i6 H return TRUE;
9 b' N3 U% h# b6 V* I4 g" W' b }! M* F# i9 I/ b* Q1 X
return FALSE; N- `& L4 l' X2 M/ ?+ f
}
9 F3 T# ^% v( r# }3 }7 R- Z6 V5 S
% I( p m: e* {, qAlthough this trick calls the CreateFileA function, don't even expect to be* L& _5 g9 \: ~9 Q; X p6 u
able to intercept it by installing a IFS hook: it will not work, no way!9 K7 \. c" a7 C( [: b* V7 d# M
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
W( d4 r+ ^/ ^; H" ~, Vservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
3 A% i; C, U2 K& [( m: band then browse the DDB list until it find the VxD and its DDB_Control_Proc
7 J+ \8 m, K# s) tfield.
' y% }# q3 |2 u" z; n& dIn fact, its purpose is not to load/unload VxDs but only to send a
0 g+ z& Z1 [& Q9 ?$ u9 N+ gW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)# K1 k \; t9 B$ f3 _
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
- B" b" A1 z% R# `% \ c( F" hto load/unload a non-dynamically loadable driver such as SoftICE ;-).
, K4 c0 F7 m& D! T, JIf the VxD is loaded, it will always clear eax and the Carry flag to allow% A5 F" j: U! M
its handle to be opened and then, will be detected.
& O2 \. Z( ?* e: r' C5 GYou can check that simply by hooking Winice.exe control proc entry point7 n- _! F, s! h, y2 m3 o0 C8 Y
while running MeltICE.
+ L( W. d1 V! t
7 _1 A' r$ n; ?4 h0 V0 O) |" w& S
7 ^, W1 ~5 @# h5 h 00401067: push 00402025 ; \\.\SICE/ ]- L# f, g! {: i: O+ y9 O9 l( [) s
0040106C: call CreateFileA6 N/ c( _1 v4 X$ q n( H
00401071: cmp eax,-001
& \+ g }1 F. @! a 00401074: je 004010919 |" H0 r. `5 s, B; B8 V1 `8 H
: [) e0 ^% l: g6 Q$ n: R
0 v' a+ @; ~; t. f; _There could be hundreds of BPX you could use to detect this trick.$ h- @+ i: ]6 ^6 e
-The most classical one is:
+ {" C" m- e8 u( c9 h- |, w( g3 T BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||; [- N* f, H r5 j7 n% i
*(esp->4+4)=='NTIC'0 x- R7 k& h+ F; L, P K6 d/ s
. ~% ?# W2 P1 d/ J% X1 `# y
-The most exotic ones (could be very slooooow :-(
2 ]8 s1 A$ l& }5 o1 w ? BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') : ]& {0 G' j: ~/ f) S
;will break 3 times :-(
f1 P( H& T% f0 [+ V) e4 y
) c2 T1 l# U( Z z* K- e-or (a bit) faster: 5 n/ }1 k5 B+ _/ B+ Y; z0 h8 L
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
3 f) P3 l/ a" `. V9 a) w: F
/ O# Q w9 X7 ]; l3 I+ [; }, e BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' + K% p( t; O6 b( Z" U: b- C4 G
;will break 3 times :-( _1 j+ T+ a" [% P( X, G
- R6 L5 z% A7 R4 w% o0 t
-Much faster:
- b x( q% [' O$ I: q! O BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
- s3 x5 |' R' {, o
( N3 E6 g8 ~! ?* U% E. o, p4 y w. O; `Note also that some programs (like AZPR3.00) use de old 16-bit _lopen8 P) f5 i' a& M- U; W$ o
function to do the same job:
9 c7 B/ t# C' e9 ^' m4 }" j+ H% r ^" w8 ^6 @; ^9 Q6 H3 e- l" N3 F
push 00 ; OF_READ
, C. i) p& Y. b& f% t( k mov eax,[00656634] ; '\\.\SICE',0
7 [% r0 V& u; q. R( r; T! v push eax; A5 _/ Z" q/ }) R# h7 v5 G
call KERNEL32!_lopen
# w% j& C' ^! W inc eax& ^- [! e. z$ z% V
jnz 00650589 ; detected
% Z1 ^& _# S3 r$ @) h push 00 ; OF_READ
4 @7 B/ F5 Z) _. S6 [4 r) G mov eax,[00656638] ; '\\.\SICE'8 |* G/ g, }7 u e' I& R0 Q
push eax( r- y* a& `) c5 M- `
call KERNEL32!_lopen* ^! j+ c. j. \$ ]! F
inc eax
; Y, o5 _; q# G% ` jz 006505ae ; not detected8 j) w2 J( a1 Q; [
! l4 f, w- W& h
# {4 U5 ?, k9 f5 N9 q# u. S__________________________________________________________________________
7 ~' X4 W, M; O6 x! i& ]' K; \* N3 k9 x0 Q
Method 121 Z. Q) S) j1 v) R1 n0 u
=========
. d; M X! i6 r3 |: k
W0 V# H: T; e) _& Y7 pThis trick is similar to int41h/4fh Debugger installation check (code 05
n9 B; I! E9 B' n, s" K5 X& 06) but very limited because it's only available for Win95/98 (not NT)$ N: ]+ |1 Y0 |
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.& i8 _$ v6 b4 \) `6 y
! F$ J" \6 ~, A& k7 q( ^+ K3 ^' ~$ O
push 0000004fh ; function 4fh
! O1 F* _; x5 i, S5 U& g* h3 V push 002a002ah ; high word specifies which VxD (VWIN32)4 T1 z( p" I* x0 d* @
; low word specifies which service3 J7 s- l6 U2 O: j% [+ F1 g! ?0 x
(VWIN32_Int41Dispatch)0 Q( N2 c/ C( C* _) Y
call Kernel32!ORD_001 ; VxdCall# s1 T( t, g$ q, t- [7 C0 H
cmp ax, 0f386h ; magic number returned by system debuggers
) r5 \' ?, X. P% Z jz SoftICE_detected
; P7 j% H% d$ ]+ h9 G7 \; K- Q8 U% R6 O+ o5 z2 ~" b6 A8 e
Here again, several ways to detect it:: y5 n$ k' m* r
+ H# { J$ \( u7 s! D BPINT 41 if ax==4f
( L2 E; W- U L/ p- o
8 |" E; B! C* _3 {) ~$ k5 i W BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one: O* ?; [( {! `+ O% Y+ ^
& R2 n5 W( H4 P
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
" U: S2 W" {9 S# J
4 c* t- V: s' \ BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
6 Y& _+ J2 W9 N- m. F, f. j; Y2 Q, S1 S: @0 S! @% ^0 m9 s2 t# g' F
__________________________________________________________________________
9 v/ _1 L' H3 V- P
; |% ?$ A" K( H% q+ oMethod 130 r7 e1 b" a+ |- K8 c9 Q8 B; s
=========9 x1 l& \0 v6 B' N# d
) ?% I# z+ w) ]( q
Not a real method of detection, but a good way to know if SoftICE is
4 Y; v" e, f% L! Q; u% _2 Ainstalled on a computer and to locate its installation directory.
8 P/ z6 Y8 t: BIt is used by few softs which access the following registry keys (usually #2) :3 a4 Z# v- ~5 y. z# `7 r, _( J @
5 e( m O, ]; n) |( {: c( c4 Q, ]-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
# d' ?1 r" e# Q; h. U/ _\Uninstall\SoftICE
' D" d; ]. F* G% p0 |5 I-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
& N. T2 W2 W8 d q4 M- y: z-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( P8 ?: ^( d. ]5 Y! z; B
\App Paths\Loader32.Exe
! n% V7 W5 o4 N; d6 }0 E$ x, Q3 u) r: t c, Z
/ j2 V2 u p. u3 ~$ q; YNote that some nasty apps could then erase all files from SoftICE directory
* `' f) D6 r- z+ |+ N, O" q(I faced that once :-(
9 K4 X4 l% A: `* [- ]0 d( a" R; m8 o4 k6 E# o+ O, \' [: z1 p3 d* u
Useful breakpoint to detect it:
5 C2 T1 U9 P1 `0 z/ S8 K0 x4 m+ j8 f/ s% E! G
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'* v" n) g# V4 P- g+ m
% L, B7 E: j8 U' \__________________________________________________________________________7 P/ ?# V7 J/ D* X
, i* Y: L7 ]* c0 K; o8 ?3 @7 ~' j4 N3 Z* Z' h) F# v. z( Z7 t1 Y
Method 14 7 p3 C/ `+ @/ i" N. W0 l
=========' }9 U8 j6 \) \$ k
- ~ A' Z+ x; P0 X2 TA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
# A! ]2 j h: e4 Y4 h% Qis to determines whether a debugger is running on your system (ring0 only).
/ |* j) \8 ~% w% t B) l" c k" |$ {7 I* N2 z+ [! s% |/ ^* s
VMMCall Test_Debug_Installed d$ m1 [% w8 J; y- H" G
je not_installed
) V7 Q' n; S) X9 Q
* B; r& U8 V" d1 k6 l2 `This service just checks a flag.! ^; P; Q$ `1 W) |* s3 e/ v n
</PRE></TD></TR></TBODY></TABLE> |