<TABLE width=500>
% w% h, J# s8 K% f$ U<TBODY>0 X1 U5 J7 ]8 {7 k9 U6 m! ]+ U( [
<TR>
+ R6 y0 p& T% B& ]: ]<TD><PRE>Method 01 ! S+ J& E g" Q5 p$ F: x$ T; N; C
=========* m7 N* h/ ~9 `- x, q$ \
, _4 k$ q. h& }( k9 b$ F
This method of detection of SoftICE (as well as the following one) is
1 ^6 B3 ~) k& _used by the majority of packers/encryptors found on Internet.( X/ y T% _" L8 d! }- U
It seeks the signature of BoundsChecker in SoftICE
; E) A; V4 R# T7 W9 k* G& r
9 a. K* o5 B# A7 o) V mov ebp, 04243484Bh ; 'BCHK'! A& J$ B! n7 s6 B2 m' N) S% {
mov ax, 04h
0 v- b* Q0 G( K int 3
, X7 h- [5 J4 j M3 |7 N cmp al,4' w4 n0 J, H: E; P2 T7 A& S
jnz SoftICE_Detected
$ t2 \/ B! L: F
4 n, o4 G; [4 u" V___________________________________________________________________________* m; e! i A6 I% W
6 o; y! S8 B) W. \# Z
Method 02
a$ e' n. b8 |5 v, S=========
5 M7 ]1 @+ ?, k G6 l9 V; t$ r/ Z6 ~/ G7 B: O
Still a method very much used (perhaps the most frequent one). It is used( G! j; W* N3 t& @4 t5 A- V
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,- m- R5 }# v+ A- {
or execute SoftICE commands...; B* @9 R1 M5 h; z
It is also used to crash SoftICE and to force it to execute any commands7 B& F! e/ M6 m. X5 s
(HBOOT...) :-(( ' F T+ A6 W2 V+ Y& H3 e
. j+ n$ O& J D1 j9 Z8 {
Here is a quick description:/ ?* o% _1 Q( H4 {" t8 p4 \
-AX = 0910h (Display string in SIce windows)
$ {# @- E% m" Q* @2 U2 Z-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
" C2 K9 O | }7 a- w- I( ?-AX = 0912h (Get breakpoint infos)
. }- c$ X! h- l; D5 i9 G-AX = 0913h (Set Sice breakpoints), T1 G7 c6 M; m8 N
-AX = 0914h (Remove SIce breakoints)
& H/ O* i5 ~, J5 I0 J' a5 A( ?% ?$ }9 K# R3 J& _9 E0 n% G( ]
Each time you'll meet this trick, you'll see:- X \6 ^& F o4 U. O. o
-SI = 4647h
, q) x& ]- \! ~, e0 }$ ]-DI = 4A4Dh8 W' ?: _ E) F' D. A' m/ r
Which are the 'magic values' used by SoftIce.. R* ?8 W/ v6 V4 F2 Q
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.3 Q1 \: A- r0 {/ u: U
; h) _- ~* j! V( T. N0 ~
Here is one example from the file "Haspinst.exe" which is the dongle HASP8 P3 }5 D) f' w
Envelope utility use to protect DOS applications:) i8 \, g$ d0 o- _" `" L1 a: w
- ~( M! E0 Y" F, n7 {6 V0 E
. H$ ^7 d% M g9 x/ J
4C19:0095 MOV AX,0911 ; execute command.
7 [; [- A/ z$ L1 ^4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).1 _$ ]5 W: J4 l9 Z
4C19:009A MOV SI,4647 ; 1st magic value.5 y' q) F+ U* c3 M0 y, U1 ~
4C19:009D MOV DI,4A4D ; 2nd magic value.
; k; r" a' y/ E4 ^' f6 j" k0 p8 @4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
$ ~: f* @- f- t6 H. o8 P6 T4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
9 S% O' V Q" A) P4C19:00A4 INC CX
3 h1 r# \" e' z4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
: T9 z j. d @4C19:00A8 JB 0095 ; 6 different commands.
* X* A3 W3 B) h7 u* m* ^% S4C19:00AA JMP 0002 ; Bad_Guy jmp back.
& }3 [, }' X) U1 b6 ]9 U8 ]1 w4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
1 O: b1 Q$ P) C j8 h: U& I
' F% m! T" ]9 |0 ~0 v3 H$ ~The program will execute 6 different SIce commands located at ds:dx, which
6 p+ w2 j5 g- ?) N7 R8 B E* tare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
& x# j' Z+ [1 U% Z$ O
% x+ n3 b# o) M" b* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
. ~: K* G; i$ z2 g) f; ~___________________________________________________________________________1 E+ v' G6 h f
5 E8 G7 Z8 V+ V- U1 Q0 p
* Z# [8 c4 b/ M# s ]Method 030 w4 |, S3 g1 S( F7 I) {! o
=========6 x2 ~; d) Z/ M: _7 r2 J8 o
: q4 D: \3 x) F3 Q1 r
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
8 O+ Z$ }5 u. K$ G4 |! }# T(API Get entry point)
F4 T& P' W; T; C7 e S2 O # G' Y2 f! O2 w ~+ m
; m& S$ z: d; |0 B# e% A# w
xor di,di" N1 q3 B+ w+ _) R; G+ l+ d, `
mov es,di' C% B5 z8 c% }& Z, ?
mov ax, 1684h * X- h* a; d* f4 O& H
mov bx, 0202h ; VxD ID of winice) f2 f0 t$ G* _6 M9 l7 ?
int 2Fh
5 f6 T: \! [* U8 ^4 D mov ax, es ; ES:DI -> VxD API entry point H, \2 z: k/ H4 W$ ?
add ax, di
; Z: E1 l/ o9 S+ _+ W5 b0 \ test ax,ax. r1 y. M8 W" N7 t
jnz SoftICE_Detected: |! Y; b( n* D: p9 H
/ z7 [; r$ d+ |& P1 }8 G4 Y4 ?8 U___________________________________________________________________________8 X+ D5 v; _1 u/ ?' E
' g2 K6 f7 {9 M. l! O3 Y8 x9 \
Method 04
1 |5 T- C, O1 @# M9 ?6 y% }" D=========( ^6 t2 L8 x: @0 Q
' G9 y! v$ k4 }" u
Method identical to the preceding one except that it seeks the ID of SoftICE5 _8 J: A; o; s( v/ I
GFX VxD.
9 `$ k% o) d4 v- o
: G# c& F" h. S xor di,di
; {9 Z0 u+ l0 L% Z mov es,di
" X: n' I: t4 l mov ax, 1684h
/ F- M7 }' e5 U4 L9 H! u; J: x mov bx, 7a5Fh ; VxD ID of SIWVID- T- ]; Y7 O0 {- K+ ]* J
int 2fh
/ K! l; `! ]( C mov ax, es ; ES:DI -> VxD API entry point
5 H( S8 G3 k: n) [% x: W add ax, di( X4 A- i- t- s! K+ K$ M* m
test ax,ax
% U6 C4 z: G" W) i jnz SoftICE_Detected8 {! V1 G1 B& j
7 X: j* f: R! g7 B) S__________________________________________________________________________. z4 Q; g k. G3 l( K I7 @
) k# n) i0 _. X& D+ g% @( {
# q' B4 Z( W7 k1 L! ?( b4 z* u
Method 05- l% Y' g8 C; z+ I4 ?& h
=========, D5 J, ^ v: x
3 f4 B8 c* ?$ W& G
Method seeking the 'magic number' 0F386h returned (in ax) by all system
( ~+ L1 w1 s9 j2 Z* b0 vdebugger. It calls the int 41h, function 4Fh.
* x# Q9 X5 t7 rThere are several alternatives.
% h+ f) Q. g: p" L4 \/ g6 p
3 e' L' q9 c% N9 O; {( N. oThe following one is the simplest:* u$ t: H n, U( o
- x6 g w2 T& o! y1 V4 \* M
mov ax,4fh- E6 u4 F0 I/ \
int 41h
0 x+ E, I6 k; p9 v) W% J cmp ax, 0F386
3 A- ?: ?$ M: ~6 n/ B jz SoftICE_detected
2 B/ s% w( \1 G* g/ @2 q" @
+ G; W; A, G! M7 A7 S+ i
' k i$ C; A( d, E( U& R4 o) uNext method as well as the following one are 2 examples from Stone's 2 l1 p/ l/ {4 A3 k' b9 J" w6 x' C
"stn-wid.zip" (www.cracking.net):+ w1 \2 c4 c: p4 h( z N
& I; @# t; f: x$ j4 T) R- L7 b
mov bx, cs
0 x1 `8 m1 p. t, [% u7 w, r; b8 ?1 D# A6 C lea dx, int41handler2+ X& |+ f |" v( j3 x) m
xchg dx, es:[41h*4]
3 a. h$ m3 S/ n5 \+ R( e xchg bx, es:[41h*4+2]
+ f' l* r9 R" }4 Z mov ax,4fh7 i/ C" _4 }0 S" _+ h
int 41h4 y# B' s8 Y1 z* r5 D) E
xchg dx, es:[41h*4]
! y% i* i$ r, a' R: G- Q xchg bx, es:[41h*4+2]
4 C8 c* E* ~ \4 T cmp ax, 0f386h6 ^, Z' c( R0 y1 b/ c1 U
jz SoftICE_detected& Y) M& ^+ v( R9 n; F" N
# _" X! A) W+ X2 `+ g4 s$ }5 U
int41handler2 PROC8 ~0 k4 a6 {) r. G0 U
iret; g9 _% J/ T2 p) N7 m& j+ Z: W
int41handler2 ENDP
4 L" ~" c) O ~7 G2 h. f
- D6 u( Z. \4 o- R$ h( d9 O7 \ {8 l/ j! ^
_________________________________________________________________________
, l0 _; B1 c5 A% L% A9 P# A/ D
6 j% Q$ p( X. H7 K' |( H5 b) ^9 a; V- _7 Z/ t. S6 I
Method 063 ~& h7 _7 Y9 N
=========& F# i+ Y5 {3 a$ s1 J* `) q/ B
" C u1 `! a* k9 J5 D/ |
8 Z* k. |7 R8 c* }5 }& I2nd method similar to the preceding one but more difficult to detect:
( O1 h$ v! b2 c) j) m
0 V% F0 z* j2 w
5 S9 o2 V# V/ n! _2 j2 f2 k0 R1 bint41handler PROC6 X& e( H, p& o4 O/ B1 s
mov cl,al! ~9 ]7 {% w" _+ z
iret
8 S% m& v) Z8 k. \int41handler ENDP9 n; a9 t+ S# W8 ^5 @0 s
p. K' T. ^* I6 K# j6 ~4 D
+ D& ?8 g9 i/ X xor ax,ax
@: I' Q/ [9 h4 ~! b% R3 {2 C" @8 M+ T mov es,ax
2 h' v, S' q0 F8 ?+ g mov bx, cs% b3 U2 C+ B o
lea dx, int41handler: @ B5 F6 C% A9 {9 d0 h1 E3 G
xchg dx, es:[41h*4]% E4 k9 ~4 {) D0 ?
xchg bx, es:[41h*4+2]# i9 ]; x- Y: r) Q5 Z5 Y, l) g N
in al, 40h
2 n' u) m. U+ P5 ]5 Q, ~! u xor cx,cx
|4 y! l/ D' H4 s5 j int 41h2 i" I9 _7 H5 Y+ c ]
xchg dx, es:[41h*4]
; I) M- o$ W5 k2 r6 l- Q3 U7 A4 Z xchg bx, es:[41h*4+2]
8 v5 Z. V* N2 H6 t( a cmp cl,al
+ Z1 |, b5 `, H* i9 x- Z4 M' T! D/ V jnz SoftICE_detected
" B9 E+ q. R2 V g. o! m' k% G! _# y! n1 L7 v8 ]' J
_________________________________________________________________________
3 v0 W6 n/ z( a- r. O, ^: I5 l9 L/ R& w8 d7 z) J
Method 07! [ r* d8 m: {; ^2 ~) F- |
=========
8 `; n; ]/ V' Y( e5 r
9 C' i4 i7 ]6 e" Y/ ~+ pMethod of detection of the WinICE handler in the int68h (V86)2 R. K8 C, n, p; e7 r3 l; f
# D- ~; k" [' E6 ]9 @8 F; H U mov ah,43h; k7 E- }- k" a4 f" K
int 68h
7 o1 ~2 U% m" `) E cmp ax,0F386h* K, O2 J! }( x: J
jz SoftICE_Detected, _) X9 z C$ M$ r3 W. c* _
5 k, h& q6 G- b6 S4 d- o U1 ?0 W+ n0 z5 t5 {
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
* [) Z, l7 U d5 e) w( B app like this:
) O% B0 k. D# e8 a
7 y9 M$ y& c7 U5 |- ] BPX exec_int if ax==68
8 j3 h" c4 d7 b' m (function called is located at byte ptr [ebp+1Dh] and client eip is
0 l5 p3 K( j! @1 G located at [ebp+48h] for 32Bit apps)
6 Z( H8 F3 S5 E& d0 ^__________________________________________________________________________; E7 A+ s4 V- g3 C' y0 H0 p3 v' e
4 s }) p) i0 [. p3 X
6 `- Z; l' x* e! ?$ f7 G
Method 08% } t( Q+ f$ W, f* b8 w4 a
=========$ M+ T( n8 C7 m& j
- f T( s, z) G3 i/ r& u& y3 |! DIt is not a method of detection of SoftICE but a possibility to crash the
% G& e, t- ~* J" U3 Ksystem by intercepting int 01h and int 03h and redirecting them to another2 N9 l* M# X4 K$ U( S
routine.
1 k9 ~# |/ w, Q; V ^; K4 NIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
" K- ^) d# r" X1 mto the new routine to execute (hangs computer...)6 D7 x- e6 o% Z$ I Z5 ?
2 d& w! g( H& s6 K& B9 d# ~ mov ah, 25h
5 s' ?7 h) T3 R- Z- L3 K* N mov al, Int_Number (01h or 03h)6 P, n$ T3 D8 Q* r5 R, l3 {
mov dx, offset New_Int_Routine
' [. F& @6 s) t: p int 21h. `* m1 J/ K' v% \
5 r2 d. l( q J- a6 x
__________________________________________________________________________
" G+ D+ B' |! a" F* o2 _ L" \( P- ^' N S5 d- b# i
Method 09& @5 Z, b& Y0 K2 {1 Q: |0 ^
=========
( P6 I! L6 a& B) F& o5 U$ i1 z) T. B4 L, H
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only% Q. J& i7 a( ^5 V" M9 Q
performed in ring0 (VxD or a ring3 app using the VxdCall).
3 r) ]! e* k8 |0 m4 G& x, V: MThe Get_DDB service is used to determine whether or not a VxD is installed
, x1 O5 }* E2 X% a' a! ~; F" l& nfor the specified device and returns a Device Description Block (in ecx) for
! @: |: y6 w( f1 D/ rthat device if it is installed.+ y. G8 v- j6 F4 B# G0 C6 }( F9 ]
4 p' X( K% {3 j mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
7 C/ e+ a2 D$ q8 u, |: K1 _: J mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)2 d! k6 f1 `" ?- W
VMMCall Get_DDB
8 `$ K5 J3 @9 Q2 \/ ]+ Y- X0 `. J mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
% W6 B$ f9 I/ J) @: y e( [( q, l9 R0 Q7 S. @
Note as well that you can easily detect this method with SoftICE: K3 Y4 [, p) U9 q
bpx Get_DDB if ax==0202 || ax==7a5fh2 w/ f0 @/ S' g! v& Z6 y( F
5 B5 M: {7 _# @0 R/ o. f
__________________________________________________________________________
, y% A) l+ {' w x' j: N. k+ \( Y! `! g3 W H4 n ?3 o
Method 10
' e; p* T! c2 b: y; p& g=========0 n) W) H8 K0 Q1 W
* }5 z+ `; K0 q2 S
=>Disable or clear breakpoints before using this feature. DO NOT trace with
8 `6 F8 u3 I% Q* r- F* } SoftICE while the option is enable!!( X2 ^" |6 \% o
& |# p9 z' l3 v5 Q$ bThis trick is very efficient:- h( b4 k4 `2 f1 `
by checking the Debug Registers, you can detect if SoftICE is loaded
: S r! E9 ]& X2 q$ w3 `, X(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
5 \ R' e: p( fthere are some memory breakpoints set (dr0 to dr3) simply by reading their
$ H+ E$ i) ?" k/ o# Hvalue (in ring0 only). Values can be manipulated and or changed as well
3 }$ E6 M2 m) |* ]( \(clearing BPMs for instance)5 N9 ^8 s+ I2 D5 p/ l
; G# i; i5 x7 k3 i9 w2 @+ F__________________________________________________________________________
/ h3 e. P! ~8 U4 r; r2 l
% j# f9 c9 S5 x, GMethod 11/ r( V' I! e y: d: y. E" ~
=========
m- E# F0 E1 y+ x- ^% [. [) v
: Y* r3 l- x% u4 T: ^. VThis method is most known as 'MeltICE' because it has been freely distributed( `* r' k: s) L* F t
via www.winfiles.com. However it was first used by NuMega people to allow
4 Q; \& r0 w5 l. f( iSymbol Loader to check if SoftICE was active or not (the code is located, A- j L! U D( Z
inside nmtrans.dll).. B# W0 `- F+ M; D! \! h
, G. N ~/ w- W, r7 x) }7 qThe way it works is very simple:
) e" u+ W; O8 x* c, }2 Y4 }It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
( f$ }4 `$ E6 i7 NWinNT) with the CreateFileA API.3 P+ F- F0 ]- x& a5 a
3 E4 ]& k+ S$ N. H% e) X0 NHere is a sample (checking for 'SICE'):7 g6 Y% J# T1 U d0 }3 t2 G
, a8 N4 }6 X8 l/ b, F8 eBOOL IsSoftIce95Loaded()
: I& B }2 J7 N7 J$ ~( u{
$ Y% G2 l! H9 {1 D HANDLE hFile; - q2 ]1 H$ D' Q8 E; o [; y) A
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE," O" d- _$ J$ w$ X' j6 o
FILE_SHARE_READ | FILE_SHARE_WRITE,
7 `/ n9 k! x9 u' \ NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);7 D3 f) l7 S. P, s7 U0 B( O
if( hFile != INVALID_HANDLE_VALUE )0 ?" K( t' \* w6 ^0 U
{# W4 X, N& M* V+ ~# H7 X* w
CloseHandle(hFile);
/ j. h0 `" ~$ [$ L+ m8 f) C return TRUE;/ e& s+ f ^( M
}
, m$ T; v0 Y% A return FALSE;
. a Q: a9 e- H}
+ w( P& _# A* d! S% `4 n
3 ?& Y4 |& J% a9 D7 C3 _1 S' KAlthough this trick calls the CreateFileA function, don't even expect to be
: F* K/ d+ F' Z/ t9 `/ Zable to intercept it by installing a IFS hook: it will not work, no way!
+ U. H. R% l0 MIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
0 n0 W8 I0 T/ T, `6 dservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function) M/ L. S! g4 ^2 r
and then browse the DDB list until it find the VxD and its DDB_Control_Proc% U5 n1 A9 P2 c: t/ d
field.: r6 D7 Q; N% U) m/ O4 @, K) X, n2 F
In fact, its purpose is not to load/unload VxDs but only to send a % ~6 T! H! R5 R* D
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
* N5 E6 O+ u/ u" B* j/ }to the VxD Control_Dispatch proc (how the hell a shareware soft could try. Z, P: T1 z7 _. l
to load/unload a non-dynamically loadable driver such as SoftICE ;-).5 J0 G5 E7 B9 f6 U
If the VxD is loaded, it will always clear eax and the Carry flag to allow
( V F7 R+ r3 ]its handle to be opened and then, will be detected.
& a( j* Q1 z) yYou can check that simply by hooking Winice.exe control proc entry point- F2 c# d* o. n- f3 W- L
while running MeltICE.2 Z3 Y- v- w/ S- l f
3 {8 T6 ?& N2 d! J8 @% @( a% b+ o5 `
" \/ ~$ J! u _% M2 e/ p
00401067: push 00402025 ; \\.\SICE
4 i4 O* p/ T! H6 e* X8 } p 0040106C: call CreateFileA: c2 M+ _: G% t/ |3 M, `* O' p% ^% G+ Q
00401071: cmp eax,-001
1 o& Z \1 C7 i# l3 {9 Y+ X 00401074: je 00401091& g8 U& y' k4 K5 Z+ N4 k( |
z8 y- j, H$ i+ r# s( H# u
1 ]9 [9 ]* M" ~- p: r2 NThere could be hundreds of BPX you could use to detect this trick.
! d8 B, n; g6 S8 L$ q& a# j-The most classical one is:2 X% s, ?, u9 m+ b0 H; z! m, M( C
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||2 m' y }" J+ g$ ~
*(esp->4+4)=='NTIC'
. w$ M; e$ t6 ]; Q5 @9 F+ |# E V, H( y* H
-The most exotic ones (could be very slooooow :-(
) {5 W+ o8 `8 N, g% a4 | BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
: x. [# x3 I1 z# O* g Y1 V' ]+ X5 M ;will break 3 times :-(; G9 ] G- ^& t4 s6 I1 D! g; }
% M9 n- s; w7 E! U7 c6 P-or (a bit) faster: ' ^! d' i% g+ R2 d
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
6 X1 U; _2 | M7 T& O
: f: y+ w7 K ] ]0 S BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
4 L4 v* Y a$ \9 d% R ;will break 3 times :-(" n* q' d& b# X; s" C$ t
( i* O- V* d4 x4 a5 F
-Much faster:2 C r& `! y9 }* C6 d+ s4 T
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
+ F& L& X8 E3 n- t, @# I O) K% F
( P4 H( p' W' d3 UNote also that some programs (like AZPR3.00) use de old 16-bit _lopen: w; t: x! c% @) I7 c1 ^) R
function to do the same job: V4 d; C9 x1 X! L+ t- [9 n
: e4 E' }! {) s9 B
push 00 ; OF_READ' Q, `8 B7 O, r) V6 b; e
mov eax,[00656634] ; '\\.\SICE',0
8 Z- E. g: @' q3 f! P; p. A push eax
8 x+ D# s, x$ Q$ ] call KERNEL32!_lopen
5 X( s, x% i3 k8 h6 f# [ inc eax
5 o4 ~4 W$ \9 |/ `9 _* n) X- w+ ?/ W jnz 00650589 ; detected
6 S8 ^. L c* ?5 Q$ [ push 00 ; OF_READ: y; M. l2 Y9 c$ i4 W7 X) i% T
mov eax,[00656638] ; '\\.\SICE': ?3 U! s+ y; u! _' j
push eax
2 B( @9 F2 M; ? call KERNEL32!_lopen4 F5 z X7 {/ i9 z: q
inc eax9 g; f7 @# m2 L$ n: p+ r
jz 006505ae ; not detected% m( B, i$ o+ U4 c1 i
# B( U7 w! o+ c6 n: Q/ A
8 O8 ]. f. g9 j# v3 W
__________________________________________________________________________
& J. O. T O8 h$ c1 l( V7 ~& p
: ]: p, V0 J; d3 OMethod 126 C+ w: q, q9 p3 g8 W& [1 |9 T- S2 U
=========, I- v: K, J. M. ]2 M0 V# I
/ e \# o( U+ `
This trick is similar to int41h/4fh Debugger installation check (code 05 s* Z% K; C; [: l% n# @
& 06) but very limited because it's only available for Win95/98 (not NT)
' ]. K+ V8 o6 b: g0 Kas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
4 I. w& E4 x/ c* a; }+ {# v
- d/ g/ | }) I$ S* }, n0 Z3 S push 0000004fh ; function 4fh
" F6 L: r3 U+ e" o# f) p0 j9 o, _4 @ push 002a002ah ; high word specifies which VxD (VWIN32). t( M6 k( T0 v. j* Z
; low word specifies which service
4 T$ o& p/ L' @% \* u3 p (VWIN32_Int41Dispatch)& F" z, o1 \% `
call Kernel32!ORD_001 ; VxdCall
" M/ Z( ]2 ]9 Z+ W, h L cmp ax, 0f386h ; magic number returned by system debuggers
' F0 M" b9 H- e4 d. h jz SoftICE_detected
! a0 |8 A5 O+ q: f$ M; e+ n
( }" j* r7 _( l8 D! d- qHere again, several ways to detect it:: R M; [9 r% H b' F2 B3 |
% P5 H. i7 H$ v A1 {
BPINT 41 if ax==4f
7 g3 w n! @$ I$ p! h1 d
$ Q' B6 ^. J5 C! q9 [7 b( I BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
: A& T+ I% ^" M }5 K* E J' D# u/ ~. t& |) ?: m J7 b' h0 G. }* ]
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A& N$ B# Y5 ?. t/ }: m9 q# z+ R" z
2 B" D% Q# Y2 Y N0 z/ ^! E BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
( V0 d2 t$ T! ?$ K9 E# X; D7 y6 w8 E3 o& \/ G, d
__________________________________________________________________________: O# d4 F( m$ |8 N2 n
8 e( v0 x7 H% J7 u4 u, E0 w6 `* j
Method 13+ }/ X( K" j; h: e& E
=========
. u# J- g8 Y. v# q8 ~9 C9 h: v' X4 T9 Z; j
Not a real method of detection, but a good way to know if SoftICE is" I' b* S! r' ^3 [. C# k
installed on a computer and to locate its installation directory.$ N) A- ~9 S) g6 [& F1 ?$ y$ D
It is used by few softs which access the following registry keys (usually #2) :8 E8 u n# `( e4 e) K3 K9 W1 ~
2 n' \8 Q8 [% U5 r. x-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
" C$ l' X6 d7 F! P2 |# V/ S\Uninstall\SoftICE9 m! V7 U+ m* ?( Z% l3 Y) Z
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE* {3 X4 e1 A3 H' [" {9 s/ C
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion8 {* ]9 d( F* G4 S& G7 U( U' o
\App Paths\Loader32.Exe
2 v b4 D# y" i$ h
! T+ `: X2 _8 Y/ P
% [: z& X2 g+ V) ^Note that some nasty apps could then erase all files from SoftICE directory
! ~1 \( ]2 J5 _(I faced that once :-(8 x8 M- H& c6 Q# t& F* z+ @* E3 Y3 v
4 z' e; Q3 _5 i& |8 O' X) N
Useful breakpoint to detect it:3 K' W# u5 u3 p" u* U6 T
b; }) e- \" ~& E BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'4 B8 a# p% e) L7 n5 K. I
- t% S( i" A' Q6 I
__________________________________________________________________________+ m ?7 O7 f. Y$ \& q2 U; w6 o
! v4 A b, g( Q* a' P4 h0 l( ^4 ]0 x9 N1 H& ?! y7 u
Method 14
9 M9 j& U. V8 g5 p+ E=========
/ K; Z: v+ ]8 J9 [4 [. w# M2 I8 D1 [2 J, i0 i' ?
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
% N) r% X& P1 Q# P$ \/ r6 v, qis to determines whether a debugger is running on your system (ring0 only).; N1 o. t' P' }) D5 {
" {9 l% C. |8 k' d
VMMCall Test_Debug_Installed' q$ W u' f# L: k* m8 {2 z) l7 i
je not_installed& W0 C# m; d1 c5 j6 Q s y
, p# d+ v; X( M) K% SThis service just checks a flag.- V3 Z5 E) y9 K* n0 Q
</PRE></TD></TR></TBODY></TABLE> |