<TABLE width=500>
* n4 m* P8 w0 e/ p<TBODY>; u* Y( _2 Q4 p2 E t8 Y* z4 l
<TR>
0 G' g. M; f4 {! ?$ f<TD><PRE>Method 01
2 ~4 }: v9 @/ c# K. b! V& m=========6 O ~% I+ T' U! p0 [$ A" c
" ^, j$ U0 s, GThis method of detection of SoftICE (as well as the following one) is
, l( k" X/ B& D6 f" A5 Vused by the majority of packers/encryptors found on Internet.+ |8 `; C8 i( P/ T! x+ Z
It seeks the signature of BoundsChecker in SoftICE
+ h2 c" q- h- s) g
( S6 o, m6 Q0 s: G- x! M2 K+ F3 R7 p mov ebp, 04243484Bh ; 'BCHK'. o; ` Z' B; a9 | J" s
mov ax, 04h
% n3 A7 H* F# L- z2 g' a int 3
* O$ J, t6 Y- g; Y6 F cmp al,4: n; p1 a; h8 ]5 Y7 Y
jnz SoftICE_Detected
' J( W2 B- }0 P, |, T6 ?! F' b" {; z
___________________________________________________________________________/ }2 z) l! G7 N4 z9 z
. o; q( s6 V0 F* g" Z9 B
Method 02+ ~1 f9 o; Z2 u4 h" i* k( b- k
=========* {! l2 D$ G2 E4 ~ u
& a" ^6 U/ {& U( ]3 mStill a method very much used (perhaps the most frequent one). It is used- V5 k; a' }/ a3 L/ J5 i
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,6 n4 N8 [4 U! i$ v# c4 I9 e
or execute SoftICE commands...* v1 }/ j+ q7 q* \
It is also used to crash SoftICE and to force it to execute any commands& ~. N* [) p- [* _1 o
(HBOOT...) :-(( 3 H# b+ B' @1 L) f+ Q
# m$ h. {0 m) K; j5 x0 Z- W
Here is a quick description:0 }" @6 o; q- Q. i( u Z
-AX = 0910h (Display string in SIce windows)
4 n" ?8 X- r% o# Z( B-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
7 T. E+ i: X/ Y; |6 z& H* H-AX = 0912h (Get breakpoint infos)& a- b l+ x! s8 `4 [
-AX = 0913h (Set Sice breakpoints)% b% Q/ h9 Z" H3 t% o' S% ~7 t. j
-AX = 0914h (Remove SIce breakoints): ]; e* B$ x5 D
3 _. g# c) |5 V- m Z! V; Z
Each time you'll meet this trick, you'll see:
& ^& s$ ]* y8 m$ ?* b-SI = 4647h2 }, M2 y6 } O& t# X, D: Y9 B% ^
-DI = 4A4Dh
5 n% J5 S# S3 W9 yWhich are the 'magic values' used by SoftIce.
3 R J# l+ s: {9 iFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.6 g6 B2 C3 B5 s' }6 N9 k) t+ d0 q
; t- s# L- l! ]; `5 THere is one example from the file "Haspinst.exe" which is the dongle HASP" ^: z+ A8 a" n9 q
Envelope utility use to protect DOS applications:
$ W0 M! t& }/ z
$ e9 M5 O: \7 `: Y/ S* C) c' g) _$ a! l9 N, m Z! x
4C19:0095 MOV AX,0911 ; execute command.
% |; v- g- Z* M3 @+ y" V6 d" S4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
( e/ Z3 y" H s( T/ E1 X4C19:009A MOV SI,4647 ; 1st magic value.& l. q2 _+ D& N R9 {) o) B: F
4C19:009D MOV DI,4A4D ; 2nd magic value.
0 n& Q+ L; H; }! ?5 y) g* z% b2 Q4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
! s5 C* {" C0 o; w) J8 U( {4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
( E- t& S+ O* |3 M4C19:00A4 INC CX. t. k0 ?; C+ X; o
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute% `8 {7 {. T# _5 U. `
4C19:00A8 JB 0095 ; 6 different commands.
6 u5 t$ O7 O/ c, ^2 ?+ A O' s4 y6 C4C19:00AA JMP 0002 ; Bad_Guy jmp back.3 H" H! T9 L( `* P
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
: R9 t' h7 L# e4 a) t* U, b0 r$ g$ f/ _7 \2 n7 O3 I
The program will execute 6 different SIce commands located at ds:dx, which
5 b0 z9 ?8 k2 p; r% ?: aare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
J% ?! b6 \. l# o2 J9 Y; c/ L/ K+ b7 O- O4 ~
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
" N4 V0 ^5 R. B2 q___________________________________________________________________________) N; G: F9 }4 M2 R! O* k* R1 ^
6 C* D& M3 {3 g; S
) @5 D! u5 {! s' ~7 t7 N" mMethod 03
8 g3 m6 Q' M+ S. p3 W=========
8 W! n, f2 o1 m% @
3 D- P7 p0 r" ILess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
+ K0 X9 s! X( r1 X: S l(API Get entry point)( e8 ~& Y( o5 R0 P" u" x; g7 d
( Y4 T4 S, f! ~
- S; i' X1 N I* W, Z1 I# h xor di,di& N- o9 K6 U N7 i n. A
mov es,di
6 W6 z& N0 u I, ` mov ax, 1684h & n" |& t3 D& w- S8 K4 m
mov bx, 0202h ; VxD ID of winice
' G/ x _ B M0 i4 P L O) U/ ~ int 2Fh+ j+ X, L4 Y* a( L% P
mov ax, es ; ES:DI -> VxD API entry point5 |9 {5 [6 Z* f
add ax, di! D* L: c9 x/ _* s
test ax,ax
7 i& V4 ^- L+ J4 p, \- \ jnz SoftICE_Detected$ x9 d4 I8 p5 }! x# [
' S# g! X3 V$ h# u; K0 A___________________________________________________________________________9 g" }2 o( z& A4 @4 K7 h. C
, @3 z2 l, w% w' i+ m& a7 F, mMethod 04
: _: A: }3 t0 M7 P/ F=========: Z. [+ i8 h) w2 ^
( Q0 l1 W s2 D- N8 ]' cMethod identical to the preceding one except that it seeks the ID of SoftICE6 V+ @+ {! p( J- P" t
GFX VxD." ~! O) v& C! A7 `- }7 i* R2 a5 I
+ _3 ~' i3 S( i9 t p
xor di,di# ^, L2 G9 C' }" `
mov es,di
a+ J7 F5 M2 Y mov ax, 1684h
2 l6 f% T0 O9 l" z% [ mov bx, 7a5Fh ; VxD ID of SIWVID
5 I/ G& A8 q: _* |6 @. u int 2fh1 x- L% S$ t: }! _. z6 x" i; d2 O
mov ax, es ; ES:DI -> VxD API entry point5 v- j, S8 Q* |" |9 F) q
add ax, di
Z+ ~6 `9 }5 y* J; ? _ test ax,ax
/ d6 f0 |) X/ k) ^: i7 H jnz SoftICE_Detected
- k; U8 S% q) f. x% C! C& q
; |1 N; a4 C2 q; v1 w2 S( w__________________________________________________________________________3 f% y$ n) W0 v2 V) d6 `
5 K' E% X: {( r( ^
3 u( F7 I3 @' @5 F" V5 M' U* [Method 05
# w( j1 I; w. U @( O/ `=========
) G; X+ k5 Z; N$ z
0 |& I0 S6 G; a) L; yMethod seeking the 'magic number' 0F386h returned (in ax) by all system w5 F, t3 c( \: Z
debugger. It calls the int 41h, function 4Fh.
- z U6 p* Y* ~$ O* P; GThere are several alternatives. 8 P6 f# `7 b' k1 Y5 N2 _
' t" v: B" Q- s& Y
The following one is the simplest:
. v* Z# f, J9 B1 [( t$ B9 x# ?$ L: ~/ d/ ]. {, X+ T2 `
mov ax,4fh; H7 [+ |: S2 r+ D* B
int 41h
2 q3 \( Q, w) m p. L- e D cmp ax, 0F386
0 [ L8 j j! u7 l: Q jz SoftICE_detected
* K0 _) N6 ~3 T4 J
- P3 H2 z) y/ Z& g8 q* u" ~: q, i! [: y }) S: M
Next method as well as the following one are 2 examples from Stone's " P7 B$ ~* j: l0 `
"stn-wid.zip" (www.cracking.net):
3 S: c) y( C- U; u, V) }+ x% P
+ T% j# f; v8 @ mov bx, cs, x3 S: s! ?7 p( S9 i. o7 e
lea dx, int41handler2: W, G9 U7 c- w# u
xchg dx, es:[41h*4]
) F! N+ p8 c. `5 x1 G xchg bx, es:[41h*4+2]
o4 z, V+ T( O: d& Q" R mov ax,4fh) ~& b; K( L+ `, ?0 X8 j
int 41h# _; u! l! g6 ~
xchg dx, es:[41h*4]
. o9 E- G4 {6 _ xchg bx, es:[41h*4+2]
1 o3 p, F! P1 B* `% {% T7 q cmp ax, 0f386h
' A7 O1 R- \3 N, S: L, \4 Q jz SoftICE_detected
; j( M% E: U3 ~7 |7 p, d$ K9 N' L, H4 }1 n, Z, y
int41handler2 PROC/ h! ]8 P, N9 {3 B8 v' C
iret
- W$ l1 w' ^( ~9 Z' oint41handler2 ENDP
% E, I6 I* M2 c# m
1 D0 ^" `/ S8 j% k3 o7 d) ^) a# U3 }
+ q9 P @! m( g( D/ |: W4 ^_________________________________________________________________________
) Z# U9 M( E7 C7 r9 e, t1 y
- M7 _( U" Z, h. s1 R# c" g7 Y* _6 T1 Q! F& T- U$ K7 z3 o
Method 06
" a/ Q! e$ n) i=========
. y- C7 d: i3 w* d! w8 A r h: r# K6 Y0 d* f4 c- B6 p
. o! }8 v8 A8 i1 v2 A0 z
2nd method similar to the preceding one but more difficult to detect:0 Z7 I& ?+ M; I8 Y7 E6 L+ Q( c! H
; f2 \! H3 W7 X' j2 q8 h4 f3 |
5 ~5 ]1 Q' Y. a+ j" Jint41handler PROC* U9 u1 s) `% N2 w
mov cl,al, O" J7 ^, S% Q5 |1 w
iret
0 ? Q! w) e A( f' J% r% z4 ?' Cint41handler ENDP6 W/ ]' x! Z. r
/ {+ E3 c0 X; `7 ^1 g! z
" R9 S O, p8 u( O3 X5 H xor ax,ax9 }6 X! f; G5 J0 A
mov es,ax
* i) d+ u5 E( g7 m, ~: @% ?+ T n mov bx, cs
* L2 F7 `, g4 x9 @ lea dx, int41handler& E# p( l- t) R, x9 u& Y
xchg dx, es:[41h*4]
: {# n7 S3 ~% _2 k8 o xchg bx, es:[41h*4+2]6 l9 r( l$ m/ |! G/ Y
in al, 40h$ h; k; |% t3 [) C, f, E: {% t
xor cx,cx
0 L- A3 G1 h- G7 J2 s6 X int 41h
, M _) t: L9 Z* S: n9 l0 s xchg dx, es:[41h*4]9 j. o) Q# l) ]7 o/ r
xchg bx, es:[41h*4+2]1 Y% Q* A% u( U8 P9 W" u
cmp cl,al
5 D4 i1 K% N+ b0 \7 I5 G7 E1 x: y jnz SoftICE_detected
/ Q3 K" F6 @ H4 p! h: F$ I9 N u2 T+ b
_________________________________________________________________________! y% S z% B6 X7 e. i
8 [* m* c( r1 q6 Z7 h0 }2 {8 r' [9 }
Method 07- ]( m+ A) k: J$ \+ M
=========
. C* A: I0 X6 H; ^, y2 Q8 V
2 B Z8 ]# I! q# N( LMethod of detection of the WinICE handler in the int68h (V86)
( B/ y( A5 W0 T
( |/ U1 r L, w# f% H0 V mov ah,43h
! y7 l9 c4 S* k int 68h, G: o7 k: j' q: `( U
cmp ax,0F386h
3 [8 ~) c4 Y/ Q: L S" P; c7 q- E jz SoftICE_Detected/ b* @+ L$ u4 F
8 P: Z& b3 Q8 M3 ]5 A l" h1 L1 m/ b- C" ] ]
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit1 x5 w4 |4 `" s& b4 E
app like this:
: H: Z" t9 c5 l! I8 d# g1 ~, m6 [: ]& k" [+ `: Q* I4 V& L( V8 Q
BPX exec_int if ax==68
! d. w& v, p! m$ l (function called is located at byte ptr [ebp+1Dh] and client eip is! J7 U$ a# v! `2 f8 b: Q$ r) U
located at [ebp+48h] for 32Bit apps) _$ h& q _* y$ b6 |7 {
__________________________________________________________________________
% R. c' Z# o% ?/ T, b' M
4 e5 t) b. T# {% \8 E6 _
" X ~8 _$ c; l: U2 d* p8 d+ i4 ]0 kMethod 088 J% ?/ N7 q2 u1 @- T6 X
=========/ D, \6 w8 U- V/ ~
' \4 ^0 ?) e' c5 c$ ~- j1 ]It is not a method of detection of SoftICE but a possibility to crash the
& S: \/ w, v* o: Y3 usystem by intercepting int 01h and int 03h and redirecting them to another
- M+ b& A( H8 f9 E7 x% nroutine.
) J5 D: g6 l8 V8 U/ ?It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points+ V1 f+ F# J& ]7 V
to the new routine to execute (hangs computer...)
' m* m5 H* H k7 V( R7 g# }2 t- r& I7 A
mov ah, 25h
6 {5 O8 m7 H$ \/ h) Y) i mov al, Int_Number (01h or 03h)
$ l# ^! ~9 D4 L. E, u8 \3 Z( K: W mov dx, offset New_Int_Routine
5 a* V8 L# y$ E0 f w' j/ u1 i7 p2 _6 C int 21h
9 {6 x9 r7 F3 |1 j) M4 d+ e" ~
D! h0 ~# t: N( X/ z/ J+ k__________________________________________________________________________
; a. h5 `) V( G% T9 _( v$ a+ F
/ |3 |4 M! I4 x3 NMethod 09
+ _4 U' q2 }0 e0 ^+ R2 {6 j' }=========
1 u4 y% P4 E0 x# i
4 Y8 x+ k9 z% O4 l8 n' {5 M# WThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only) [* K. P( e: k: q2 f
performed in ring0 (VxD or a ring3 app using the VxdCall).
5 w7 a3 ?" ^- D/ J" {The Get_DDB service is used to determine whether or not a VxD is installed
9 N8 D, y7 E, h5 ]( k7 Lfor the specified device and returns a Device Description Block (in ecx) for
) R( M9 M) }3 `& M( B$ w4 v* pthat device if it is installed.
& P" E3 ^0 i/ t* ]2 r# }- K7 O, R* D, @# L" {+ g
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
& i4 d2 m3 n y ` mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-) x+ b! z; D& {$ g4 j
VMMCall Get_DDB
. d. c9 o- s* H% L mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed M9 {$ J5 }1 N% D: r6 U$ j( p% ]: j
! O I. R/ X, h N2 ]Note as well that you can easily detect this method with SoftICE:; I. k& K6 K& B
bpx Get_DDB if ax==0202 || ax==7a5fh
: }; N+ t$ v) V3 k
f# G E8 D1 l( \" C__________________________________________________________________________
4 ?& H [5 z( X( D6 Q9 ~
2 _7 c) l& R# M) U1 S! x+ x# SMethod 101 \& ^4 h1 N- r% i; I1 W, c
=========, R8 M+ x$ B$ ~) V( r0 y. G
- g# {$ |% y: p* t- X/ H! u
=>Disable or clear breakpoints before using this feature. DO NOT trace with
( B: l! j3 H. @- Q SoftICE while the option is enable!!+ K$ R% A& u) R; G- ^& v9 @
2 y |5 J* Z y: w6 z |
This trick is very efficient:# P4 [2 R% N! F6 \" _
by checking the Debug Registers, you can detect if SoftICE is loaded
) b) x7 `9 m* Q" U(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
+ [8 j4 _- C; F5 Mthere are some memory breakpoints set (dr0 to dr3) simply by reading their5 N1 M$ `" R1 h U y8 x
value (in ring0 only). Values can be manipulated and or changed as well! h" e) |& E }1 [
(clearing BPMs for instance)+ t7 e# r& u! E8 m" B5 a5 C
$ O7 v9 g/ N% M5 T7 a6 ?8 c
__________________________________________________________________________
; C( f, u: ~' A5 |; d9 X! y6 B, W$ _: v+ h4 L) s2 @" A
Method 11
, |/ j @2 b$ U! H3 B. i, l# H4 }=========
; ?- g! d1 g4 B) M: o* T, C; [1 J
9 @! N( T/ ]% m1 d3 ^This method is most known as 'MeltICE' because it has been freely distributed
. D" J% X: P' c$ y& I* y" Fvia www.winfiles.com. However it was first used by NuMega people to allow
, `- k9 @ q9 i, Z* j. O5 ySymbol Loader to check if SoftICE was active or not (the code is located
( H3 q/ W. y- Einside nmtrans.dll).
$ y9 G: I) u( a. |
5 U. I: L0 R5 ]! XThe way it works is very simple:. {# d" l5 D. `6 ^9 y- Z
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
6 \3 m* _3 ?& bWinNT) with the CreateFileA API.
) t6 c2 D0 e8 l/ F# p+ ?/ L C" ]- y" d
Here is a sample (checking for 'SICE'):; N0 z" d# B- B$ Q9 e. P
& D* s+ {5 @: ~7 _# ~" F0 Q
BOOL IsSoftIce95Loaded()
3 u1 Z4 ^+ B, E{
1 h3 {5 }6 C+ h8 D4 t HANDLE hFile; 8 I6 a9 P$ N- T0 J3 p
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,' w8 R4 g( R9 f+ R, o3 e E- X
FILE_SHARE_READ | FILE_SHARE_WRITE,
' U- s" r2 i2 A" j0 q NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);* D0 _: d, R6 o2 I7 S- l6 P
if( hFile != INVALID_HANDLE_VALUE )( s! V3 G1 Q" J& w$ s0 J/ u0 S P8 z
{
6 S! j E& e4 z# L- Y CloseHandle(hFile);
* f! J6 @$ I0 i2 i( { return TRUE;2 K. E. W6 x" K% ~9 R) M7 n
}- c% k- D6 u- f h* }6 U2 e
return FALSE;; c' K5 A, W4 g& {8 h* ^
}2 S* f+ T' _9 H8 A
) N0 U0 V6 b. cAlthough this trick calls the CreateFileA function, don't even expect to be* i0 J3 r( [& b; D3 j& ^: f
able to intercept it by installing a IFS hook: it will not work, no way! M/ p% B; m& X
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
0 p# T' J& [1 @' pservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
. r( C6 O4 V3 K9 D& E# w3 t7 w8 u8 B" {and then browse the DDB list until it find the VxD and its DDB_Control_Proc
* l* i( i+ Z9 H3 nfield.& t; U9 G w4 d2 w, t9 u$ t
In fact, its purpose is not to load/unload VxDs but only to send a
% ^) n6 T N4 y0 J3 H+ Y) JW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
* [0 _+ f8 P1 v0 h. {( Vto the VxD Control_Dispatch proc (how the hell a shareware soft could try
8 Y( p0 G$ U- [) ~; ~/ o4 V/ d I$ \to load/unload a non-dynamically loadable driver such as SoftICE ;-)./ [9 U0 h" l5 G5 O
If the VxD is loaded, it will always clear eax and the Carry flag to allow
+ S0 }* a' [; W7 w ?3 I4 `' E# uits handle to be opened and then, will be detected.2 U# V7 R! s% y+ s3 j; m# ?& P
You can check that simply by hooking Winice.exe control proc entry point
+ L# T6 e: L9 F0 twhile running MeltICE.& t6 s/ l8 ~/ B) u5 r! C, y
) g+ r$ T0 G5 ~- W. q! M. @1 P+ Y& t/ L$ }
00401067: push 00402025 ; \\.\SICE& Q) @ [8 k3 l6 Q2 I1 y( [4 Y8 z. [6 k
0040106C: call CreateFileA5 u. T Z2 c; \! E
00401071: cmp eax,-001
1 {4 P* f, M" X2 W7 ` 00401074: je 004010914 ?5 Y9 M" R; c% j! i$ ~6 q/ m
+ I! r# A8 T& r A3 B) @* h- D( w( m$ t0 L3 v+ z
There could be hundreds of BPX you could use to detect this trick.
1 a# L) G" N& \" x" Y5 {1 A& X-The most classical one is:5 k8 z4 `! r2 X8 Y
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||, ~. C& a# V7 a, V* w
*(esp->4+4)=='NTIC'
9 k) N4 B7 t# w% \5 h
" h+ G" T9 M$ Q2 J `" |8 i6 ^1 Y-The most exotic ones (could be very slooooow :-(
% {( g) k- ]! c; b C: Q- X: J BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
2 n1 h$ }8 J" b# O! `- w9 B" l ;will break 3 times :-(3 T+ C/ r2 i' @% j# s( a3 X
" K2 @3 ?4 ^# N; G+ g4 N
-or (a bit) faster:
2 s0 Q% v3 K2 ^8 x& E6 U* k3 g BPINT 30 if (*edi=='SICE' || *edi=='SIWV')! H! j }4 m2 w, I# T; Q
% F+ c. c8 Q; e6 \! k5 b$ F BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
( R, B+ _. m- D2 {! K+ R ;will break 3 times :-(
) W! Z8 h; I2 x% e4 p0 b
, s- k \6 n, P+ b' N% E-Much faster:
{+ X9 x T' T- c: ` BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
$ d' Q/ W, K \- |% t# z( q; }6 _$ W* [! {
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen8 i" \8 o4 @* h
function to do the same job:
, K" f, F r1 A* L1 Q+ T
+ s7 n6 D7 ~& b push 00 ; OF_READ
1 n9 n5 }& X, Z1 \ mov eax,[00656634] ; '\\.\SICE',0
/ T; g6 w8 ~; H0 A8 o8 d push eax
6 k- R* l4 {, `1 R call KERNEL32!_lopen
+ {/ C$ p8 q/ J, V inc eax, X' q# G2 Y( {' `$ }6 \
jnz 00650589 ; detected
6 H' L6 L# }: C) `' Q% ?% v/ r" K push 00 ; OF_READ
$ T: L! M4 X4 g5 v* J9 G; Z$ h mov eax,[00656638] ; '\\.\SICE'$ w9 {) n3 }# O4 _$ _
push eax
( p% m& a2 G' ?+ B$ N call KERNEL32!_lopen
+ s4 ]8 W7 Q$ w7 M& ] inc eax5 v: E5 n0 t5 a9 [7 h% q1 _
jz 006505ae ; not detected
/ U& D" a! A9 f. [9 G1 z* N2 ?8 E/ H' h" U$ B% Y0 \
3 K5 ]- m& y) c- c9 H
__________________________________________________________________________
. S4 H+ t/ U/ f6 L! F$ {8 C* r/ A" H W
Method 12
; b9 k. a9 A6 A# X, [=========; J6 ?/ I( n" z5 ~
. z) [. i0 V9 J' c9 q0 v9 l" |
This trick is similar to int41h/4fh Debugger installation check (code 05
3 y6 ^, @; U! T" [' @9 O& 06) but very limited because it's only available for Win95/98 (not NT)& W9 B. E; q5 c ^
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.- `' D* C/ X& q7 Z1 J! R( S; Y
6 [* o5 z; D" x
push 0000004fh ; function 4fh
: G/ H4 L( O" \( O; Y3 n: r. X push 002a002ah ; high word specifies which VxD (VWIN32)7 S$ U: @, q5 f/ o' z8 i& f0 \% M, S
; low word specifies which service
a+ j( ~( |' F6 M R' q (VWIN32_Int41Dispatch)4 ]; A# |2 u6 Z' |0 F0 ^9 h
call Kernel32!ORD_001 ; VxdCall
6 l9 u, T' k N0 L% D1 v0 m0 w cmp ax, 0f386h ; magic number returned by system debuggers
5 L' u6 {7 ~7 i, _* |, \; R1 V jz SoftICE_detected
- r& \! x7 y( h z
; o- r7 ~! z7 D0 @1 _/ ^- [7 c* THere again, several ways to detect it:! D1 _& }1 M D, T
" g; i2 R+ z, I. p( x8 l BPINT 41 if ax==4f1 j% ^5 K! q: ]6 h7 I
7 ` P0 U2 a* b; q' O. S
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one a2 y& q7 j2 s1 F6 S
6 q3 p9 N7 _4 c4 ^& [ BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A* F% w+ Y+ {- h, D8 X, u4 k O- I7 S' F
, O f1 \7 R9 n2 [, q" d0 ~ BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!4 P- m t3 W+ k# W% e8 W5 _- K; Z' W
9 v: W& f" r: s
__________________________________________________________________________% x4 n& w, h+ _; X& g
! r' x5 Q6 z: D7 z
Method 13: h- ]4 T* v- t2 J
=========" H# r9 \5 S+ H; P7 i, V
. @. A; z1 `$ j0 UNot a real method of detection, but a good way to know if SoftICE is& ?- a9 f# F9 E6 J
installed on a computer and to locate its installation directory.
& h' j$ f9 U$ x# h8 y! X/ yIt is used by few softs which access the following registry keys (usually #2) :
% a6 c3 J$ |( w. A
- {0 a( a# K1 }9 f-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& \& ?6 ^+ e4 S
\Uninstall\SoftICE c/ o, B5 P5 C: v& B+ D w
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
, P% P2 R$ M# @, g-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
+ l. Q9 Y! A4 b- Z* F\App Paths\Loader32.Exe
$ r4 {7 H) K6 m. g8 X1 h
" R& ]- J: p; r/ v# G& i- a; V& ]6 P: F" Z8 @# P3 c
Note that some nasty apps could then erase all files from SoftICE directory
+ R j8 T) z' b) D(I faced that once :-(9 T4 V7 f+ _3 _4 V, x! e% N+ N% V
j% Z: \" a& M! M5 m4 M" b
Useful breakpoint to detect it:
( E5 {+ g$ W5 g( Z( {$ S. J$ Q8 R2 k5 ?; S% |
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
3 T/ [ U, S5 v, `5 M
' A0 w+ K5 @# F__________________________________________________________________________
( u0 O* l! f' I: L( f7 J
! H( [6 G1 F: C2 n% `
" g1 ?: S( J0 p( O% sMethod 14
& ^1 k7 g# L5 G2 [# Y0 H1 L=========
; Q6 N. _8 i- `) R2 J4 }
$ d" N* j( G1 kA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose6 H. e, x. h% T; @% b$ L1 T
is to determines whether a debugger is running on your system (ring0 only).: p7 i% n% f" e! y! F' F' L1 C& J) Q
$ @: m' s1 u8 Z" c% e: Z: _6 a
VMMCall Test_Debug_Installed
) b# D& q% s: t' z& |4 k$ g je not_installed9 k' t; Q x! `5 L1 g
/ [7 r$ x9 u$ N, k0 ^: V5 A, L3 lThis service just checks a flag.' T8 B( [2 e5 L
</PRE></TD></TR></TBODY></TABLE> |