<TABLE width=500>
4 J4 ^5 j& F1 s& w2 x<TBODY>1 X" p( l) r; w& [& o
<TR>
" m7 W) c2 R3 X% P0 W2 \& s<TD><PRE>Method 01
' K9 c k- D( W=========2 x2 J2 ]% c% k; \$ }
, L# Z* w8 l" [4 CThis method of detection of SoftICE (as well as the following one) is
' m& Q8 i' w8 Vused by the majority of packers/encryptors found on Internet." H1 s# Z# b/ `6 X) a* y. d3 V& l4 l
It seeks the signature of BoundsChecker in SoftICE
- E& c; }) U6 W+ C
: h8 R6 H+ G; c q) M0 T mov ebp, 04243484Bh ; 'BCHK'; T4 n5 y2 [1 T, W4 T
mov ax, 04h
/ Y# h/ x6 T. h/ \/ i int 3 z2 t' ]. d# z; c
cmp al,4
: h) J* F' k! z h/ }! t( G jnz SoftICE_Detected- C. x: f) C2 N5 `% m2 T! m
) E; _! @6 v4 }+ A/ X* X# }___________________________________________________________________________
. P; i8 U. N1 X# _' H8 k( W4 G8 h) c! l; G! J
Method 02
: {% `8 A" a; r2 H7 g0 H6 g=========
' U1 Y9 I: Y, h5 H& c: [$ z0 b" R. i+ M3 F. e2 b4 v7 {7 l
Still a method very much used (perhaps the most frequent one). It is used
6 M- W9 |! m; L5 wto get SoftICE 'Back Door commands' which gives infos on Breakpoints,$ @; t. `/ V+ ~# s. N6 `; H
or execute SoftICE commands...
: @8 e L# U" J% _ xIt is also used to crash SoftICE and to force it to execute any commands( |& z+ x; C4 |% `9 c. s" `" ?( ]
(HBOOT...) :-(( : h; _3 O8 U5 a
6 w( R$ Y" ^& B* N: nHere is a quick description:
' @+ H+ c. {* ?1 N-AX = 0910h (Display string in SIce windows)" K6 u. u y8 ? ?* @
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)" V c/ i: ~0 v0 L3 |1 ~
-AX = 0912h (Get breakpoint infos)% a9 Z1 U) s5 c
-AX = 0913h (Set Sice breakpoints)2 E! a6 c8 l" N" V- d
-AX = 0914h (Remove SIce breakoints)3 G f! o I+ N2 w
- D3 X% }1 {' J: l
Each time you'll meet this trick, you'll see:) K9 _$ j2 K( s8 E
-SI = 4647h# d3 B6 z8 R+ E4 o
-DI = 4A4Dh
2 A+ T4 ?$ H w- X) {; q# D. W3 `Which are the 'magic values' used by SoftIce.
% T, ~ Q1 R4 B8 {% Y; kFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
2 M0 H+ U! i$ }9 l; E/ M5 l" ^3 x) {1 l3 i# ?
Here is one example from the file "Haspinst.exe" which is the dongle HASP
( U* d9 ^3 E9 s+ bEnvelope utility use to protect DOS applications: u# n) n: c2 R" u7 L2 _8 r
; o8 Y" N4 c) M
h$ J- B' e* y8 [4C19:0095 MOV AX,0911 ; execute command.
4 S4 V/ e# ^8 G( \4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
& {9 n$ J+ |4 V# A* V- ~! I# q4C19:009A MOV SI,4647 ; 1st magic value.
2 ] T E9 `; m; W5 N; I) K3 i0 W4C19:009D MOV DI,4A4D ; 2nd magic value.
- x3 C/ _$ y2 v% U0 v& A* y4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)7 |* G2 a% m2 o" ~6 i
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute( Q; V# a. s, ~0 H. S. _4 N
4C19:00A4 INC CX0 g6 j8 a4 t- U
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
) }, r0 T. F& J. N/ x% g% ~4C19:00A8 JB 0095 ; 6 different commands.
! J' B' d( ?9 Z2 W2 i& e4C19:00AA JMP 0002 ; Bad_Guy jmp back.
5 }3 l0 v- g' |7 y* S5 `. ]4C19:00AD MOV BX,SP ; Good_Guy go ahead :)2 x( P% x6 ^1 F. ]& Q! ~. ^
* t& w' ~, s! c$ F% H% r* }& S; z6 dThe program will execute 6 different SIce commands located at ds:dx, which
3 |+ j, u+ \1 X! t# U+ Gare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.1 j& g. p2 A- o( F! u
2 x+ f, P$ J {. I: d# I( q* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
4 }# O* I, t# S1 X( N2 L___________________________________________________________________________
/ V/ ?$ k* y9 G0 h+ L4 S! C, f1 T1 } o! }/ }/ \
: C0 `+ D, A3 q7 o; {Method 03
' z, ]* ?5 _6 V2 i/ @8 i9 e( c========= {# y' ~5 f5 R7 t" }
* G! o2 j; K3 ~% U. {Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
2 c' }6 [' e, z7 Q& P+ u* { U(API Get entry point)
2 }$ r% a4 g+ n - u0 Z8 Z% R2 x- ^+ V2 e3 x
* }2 k# z+ @) }9 }4 ^0 \5 k, \
xor di,di
# S+ f/ N1 n# b; r$ ]0 A mov es,di
% ^% B4 d) N, D7 b% y! h mov ax, 1684h
' Y* I5 i M# G: e mov bx, 0202h ; VxD ID of winice2 h: [- g7 m# N ?; m7 ~
int 2Fh6 }; \# `, \/ Z
mov ax, es ; ES:DI -> VxD API entry point3 ]! e1 O/ L8 }3 b8 @: w# I
add ax, di
$ Q4 o! w+ l8 j6 j& y, w7 G test ax,ax6 L1 I& R+ v4 \) V* y, H
jnz SoftICE_Detected
/ Y% ]! u% m$ z1 H6 i5 \' p" m: N$ q' z1 x
___________________________________________________________________________
+ ^9 L7 g( q. H7 n1 F
7 q8 R) O4 B, J# x6 s% X6 xMethod 04
5 S6 y) I9 p+ w) [0 Q4 T# I1 L=========; p" |6 w9 o0 O. z& X/ s
, C0 i# S5 C7 K4 \1 I2 QMethod identical to the preceding one except that it seeks the ID of SoftICE
& B) b# n7 u2 c2 a% ~8 p, N+ Q) o& d- vGFX VxD.
2 `- Q- Q! t: E1 ^, X4 j x/ t' s0 o7 q4 l- Z" Q0 R# b
xor di,di8 R0 W# @/ Q- M: c* |: A& H
mov es,di1 `' l4 _2 O( L1 P9 X
mov ax, 1684h
- q U2 w; {/ n% r" L% Q mov bx, 7a5Fh ; VxD ID of SIWVID; \. B% }/ X: l( e/ [" [
int 2fh
0 V1 B7 V- W2 ~+ X5 n$ ? mov ax, es ; ES:DI -> VxD API entry point( t( E" T& f+ G8 ]( |/ m- Z0 X* n
add ax, di: q1 L9 C+ J. R7 c8 J Y% M
test ax,ax* v( A8 V8 Y1 O
jnz SoftICE_Detected
2 [- i( v+ u: A& Q z! e( R
* }3 @1 Q. F2 e! p2 T) y__________________________________________________________________________
) z% x0 @% j! b2 z7 Z& p1 W& w+ i% H" ?/ ^
. S/ O& r: w' M$ L
Method 05
4 X8 M) q H+ x _; o4 X5 b- T9 B=========
# B, L. Y) j! H- T- {# B P; U
4 [) Y5 t+ @0 t& c* ?/ N6 k1 YMethod seeking the 'magic number' 0F386h returned (in ax) by all system
9 w' G; p& J, U+ Z/ [3 Xdebugger. It calls the int 41h, function 4Fh.9 b( V% Y7 X- ~2 n9 j! u5 y; j+ R
There are several alternatives. % v& B0 K+ Q5 U9 m' S* ]+ h0 q% h8 @
# I1 h! |' n5 z R; s, U6 a
The following one is the simplest:
& o) a" M$ ]6 V; }! ^7 T
, h4 K4 a5 i2 N o! K mov ax,4fh
7 v; [4 [! f/ X2 F4 i+ S int 41h
* X3 I9 D! T) I$ M, x+ w$ `" y/ \ cmp ax, 0F386
( j. o# v* Q, }: W jz SoftICE_detected! C7 r! N% b9 k" ?- ?- H! h
7 S& N6 f6 W( F! I
) d6 v I2 {8 R3 mNext method as well as the following one are 2 examples from Stone's ' k$ P$ O% L2 C* U; D3 d5 N4 K- W
"stn-wid.zip" (www.cracking.net):
7 |7 m/ k, Y- u* _$ ?9 l- {+ h4 P- _- u
mov bx, cs6 C( F! H. y% a8 T3 w; Z3 A% G: Z; M
lea dx, int41handler2) O0 ~" L; M) _& L% I
xchg dx, es:[41h*4]% Y$ l; T' f/ o$ c1 E
xchg bx, es:[41h*4+2]
3 }# n! w* h: o h+ f mov ax,4fh6 X1 N$ w( a8 a5 p" ?3 L
int 41h
4 y; o7 }2 y1 [0 @ xchg dx, es:[41h*4]' ?0 b+ Z$ N k7 A, U
xchg bx, es:[41h*4+2]* n" v4 T7 h( P0 L( |
cmp ax, 0f386h' a6 o6 n. Y/ ^! M
jz SoftICE_detected
5 m5 h% ~0 [: o! u
7 @! P) ]+ a3 @; R2 R9 r, Tint41handler2 PROC
% `+ l3 C" |8 b2 h& L; \3 z6 W: F iret
; e: _/ Q& Z1 o' _1 c* |int41handler2 ENDP
+ Z# T7 }: c9 s4 M
0 W* e n1 J" |9 E# B! E5 y) K' P/ p m
( ]5 d) U$ R% A' }/ {_________________________________________________________________________
- H! o$ `# d& Z- K+ T6 J5 B/ G& y$ G; ^: q4 w- X( S, @+ W
9 j) O; P7 y6 U, d# H! c. \
Method 06 u& U) R5 Z0 W5 q/ f
=========
1 e6 l, p0 M2 ?) P9 F* i/ y
% F; Y! R5 x0 F. Z: C0 s9 \1 _7 \( H5 E, G% S$ e; F
2nd method similar to the preceding one but more difficult to detect:
' u1 Q3 p' X' F0 f7 \
; d- M# H9 o/ w3 f
^5 C, E- o1 L6 }1 c: Xint41handler PROC9 u5 D5 W9 c5 b3 f+ c* ~* O8 {
mov cl,al
" c2 h- c" X( f8 L0 Y iret( { o3 h( W& Z( T2 i0 \
int41handler ENDP' {7 g5 y7 v% N' ^! ~7 e1 y
7 ^% z1 p h a8 G0 t. W7 X9 F4 U& e& S0 w
3 [! f# J$ G( T+ d7 v3 _ xor ax,ax- V, w# A9 {* Y4 X o a
mov es,ax
+ n5 r9 ~# |% }2 [ mov bx, cs
9 P8 y) Y1 X6 C. v lea dx, int41handler
) S- p8 Q6 n) j( Z% i( f. N xchg dx, es:[41h*4]
) i. O2 K* G- m2 E' ?7 L2 v xchg bx, es:[41h*4+2]
/ L" j3 |2 E8 u! g, D m$ z in al, 40h
* i8 o$ o/ k6 T. I; C! s. d xor cx,cx8 R# {6 q& I6 c) E
int 41h3 P; E4 S/ _, s; k3 h% V
xchg dx, es:[41h*4]
# r! A L" Y9 k/ X xchg bx, es:[41h*4+2]0 F1 _' }' Q, ], @
cmp cl,al
6 M6 |+ Z0 x' n3 @1 v jnz SoftICE_detected% u. P/ H1 ~2 |: W: L
6 }- l# Z$ Z! J4 e; }0 C
_________________________________________________________________________
6 I2 f7 W0 \& }. i5 o% u5 R' r( ^& Z' Z4 h# u# o& d
Method 07$ F! y* e. ~) f& `( q% O$ g- ?
=========* ?3 b2 N* L1 L6 ^' ^0 [1 Y. G
1 B3 C9 O. ]- o. I+ Z) h( a
Method of detection of the WinICE handler in the int68h (V86)
, [3 t# ~" K e, q, T }4 i$ u1 z
mov ah,43h
0 S/ n, L% U4 ?: B8 n int 68h, O3 U- Q: K7 \- T8 G! G
cmp ax,0F386h
, ~5 t9 k6 M0 J+ w( }& q# B7 ~ jz SoftICE_Detected
1 u# G- }5 O# p: [3 d, l5 \5 H+ ^0 y- r- }' V4 W
! O0 a# `! w# e! i! o3 C
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit' ~: [' S+ H7 v' j) ^
app like this:" \( r& [* d& N5 _# I1 F$ l, }+ A
! p! @5 P1 Q- l" G- r; b4 | BPX exec_int if ax==68/ ~5 S4 a% Z. m
(function called is located at byte ptr [ebp+1Dh] and client eip is5 ?( U# S5 U/ b1 s9 q5 }8 u3 l
located at [ebp+48h] for 32Bit apps)
5 z/ E* G$ @& s" u+ Q7 t0 q__________________________________________________________________________
) o8 N- W* [$ D; x6 e: r3 D; T% P! ~7 U/ _( I1 k! k
+ Y* y" x* B, D6 p, }Method 083 i5 S$ p: t7 {# `- ]+ T
=========
0 h+ a, S: P. n* g+ P+ V7 ^
2 G" G5 t8 z" h+ cIt is not a method of detection of SoftICE but a possibility to crash the9 M# e& q- M1 p- N+ s
system by intercepting int 01h and int 03h and redirecting them to another
& \8 t" K$ z1 D8 @9 T" a9 eroutine.
, m. J; O# W8 O$ b) `$ W6 BIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points x1 p' ~7 h6 b: v a1 u
to the new routine to execute (hangs computer...)
2 C3 T( B- l" k
1 [6 J/ W: z, C3 _ mov ah, 25h
0 V; p2 b w8 l& [7 b- A1 C mov al, Int_Number (01h or 03h)2 i* @2 w& a$ \3 X2 @) k" F4 Q' b- W
mov dx, offset New_Int_Routine
2 e5 x1 I! f5 E" U8 O/ G int 21h6 k6 x) `$ D7 w/ n+ b! i" u. F0 [
, t' U0 H2 Z9 q1 u7 C
__________________________________________________________________________) o9 l) v% ~6 z4 X
3 \' H$ r u) s3 {5 C
Method 09& t* K/ K/ Z" \
=========3 L' K8 X/ Q1 m# z& ]( `5 \
+ ~+ B! C5 ~$ Q) j& x KThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
/ e. Z5 h: v! |0 sperformed in ring0 (VxD or a ring3 app using the VxdCall).
2 I% q! e2 q3 ]The Get_DDB service is used to determine whether or not a VxD is installed/ w m8 |- H3 O0 D0 n( ]) M& u* b
for the specified device and returns a Device Description Block (in ecx) for
/ W2 V- K) C5 x* j/ `/ ` ythat device if it is installed.
7 W* a% I, B: E- V# O+ _
7 C G9 Z7 H" `7 H mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID* H3 e( c1 y& h/ Q; ~2 M9 T# {$ p
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
4 h9 h [, j" q. r* f4 u VMMCall Get_DDB( x" @* Z! L J" i& P
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
) x3 } o) y1 W0 K& P# ~+ i7 u; ]" W. \4 a. v: {3 L# p# t7 T
Note as well that you can easily detect this method with SoftICE:, e* ^3 P" n! h" X4 s3 P
bpx Get_DDB if ax==0202 || ax==7a5fh8 g" H8 J( ?! t, o% K [
0 ^0 i3 O) {: C/ {; i7 c__________________________________________________________________________
- K( [! X) _1 S7 E+ g+ h* w6 L6 {# a( |$ a0 y- q. S* m: {
Method 107 P7 I& d9 E1 o% n# k2 ?
=========& l9 E& Y& N( R
4 i- T8 c0 p5 i# p=>Disable or clear breakpoints before using this feature. DO NOT trace with: p, b6 ~: [: @- p2 d
SoftICE while the option is enable!!
( I1 B1 J! N* q# @
6 W* t& E8 x9 i. d* g, @This trick is very efficient:; K! h$ b* d6 o( T
by checking the Debug Registers, you can detect if SoftICE is loaded+ F1 h& q9 M1 x Q" n: N
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if0 I( S* M9 _& {' u) h m& e
there are some memory breakpoints set (dr0 to dr3) simply by reading their
6 O* J; W6 z4 I% X) Q9 svalue (in ring0 only). Values can be manipulated and or changed as well
/ d5 X6 S3 m, q) f9 S7 Y(clearing BPMs for instance)3 n5 o6 @ T( e" _
$ x5 v7 d! P3 c2 L8 x
__________________________________________________________________________
- x+ A2 ]4 F0 d: W y! Q6 M" O' ]
2 X3 x8 G' c0 ~Method 11
# [& |" j4 o3 F: a+ Z+ F=========% l) A. B9 P+ W( d% o6 `! o
# @8 h! G% c4 S( ]& s) F- [This method is most known as 'MeltICE' because it has been freely distributed
8 H6 X3 o; D8 M2 Gvia www.winfiles.com. However it was first used by NuMega people to allow4 f& [5 P M+ o1 q
Symbol Loader to check if SoftICE was active or not (the code is located
& P. I5 O& R( z' v/ Binside nmtrans.dll).: P0 S3 f7 i' g0 g/ ^5 I( j' Q
! Y6 u2 V. [1 v- ? a
The way it works is very simple:
$ y7 b! n( C) d; l; C* E7 u/ |It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for0 N4 q; c) l4 B3 {
WinNT) with the CreateFileA API.
9 P; `: h: o3 l8 \
7 z" }1 B8 Q) VHere is a sample (checking for 'SICE'):9 Z( f5 g6 d; M( m
R# [ \. }. _ a$ s1 g$ dBOOL IsSoftIce95Loaded() B3 \! g2 Q/ S
{
: Q! J. O* N( i HANDLE hFile;
& ?9 o# Z! M' D/ P" R L1 @- A hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
7 h( H% n/ e9 I# b* T+ t FILE_SHARE_READ | FILE_SHARE_WRITE,
7 V% J. x! F+ ?% y" q1 R- t* k NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);3 _% C: O1 B( ]) Q. w- b
if( hFile != INVALID_HANDLE_VALUE )
# |; P* i7 p% ?) P {: W$ s% Z& \* e5 `
CloseHandle(hFile);
8 W3 o+ z+ j0 k return TRUE;
) L, w- }* c+ }4 t6 ? }9 t0 A( p# ~+ C1 X
return FALSE;
3 W) ?7 R. p/ d3 t}
3 c5 y, R; f6 m7 B0 W7 @1 V/ E& o7 g! u+ @# L2 i
Although this trick calls the CreateFileA function, don't even expect to be
) F5 @* P5 X9 j$ i; N8 @3 J! n# wable to intercept it by installing a IFS hook: it will not work, no way!
* M( q1 z& @# ]: S3 {$ k% s oIn fact, after the call to CreateFileA it will get through VWIN32 0x001F! q1 L! u* T; Y, d8 ]$ v
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)3 L4 M2 Y, t, w! J% R+ M$ t) w# N) n
and then browse the DDB list until it find the VxD and its DDB_Control_Proc& k( y6 _8 I, D$ @0 f ]) u! [
field.% R# l) n/ m6 L Z+ L
In fact, its purpose is not to load/unload VxDs but only to send a 4 V1 D. U$ v: @) |0 J
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)) m" y4 H& r, u9 \5 H1 _1 D
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
% k: B- H: o+ z5 N/ Dto load/unload a non-dynamically loadable driver such as SoftICE ;-).9 J' P* G; F9 H3 a5 B
If the VxD is loaded, it will always clear eax and the Carry flag to allow+ m7 o- y" X! v8 f8 C
its handle to be opened and then, will be detected.2 |& {2 q# ~$ t" B5 P7 k
You can check that simply by hooking Winice.exe control proc entry point
! `* y$ I- W" |5 G" K+ |0 H; ewhile running MeltICE.
: @) R& M8 \* n: J+ |7 x9 ^5 d% c: S, v5 m" w/ |
& K' d4 }+ ], Y' o
00401067: push 00402025 ; \\.\SICE
, b6 N+ `/ t2 z N0 `7 U 0040106C: call CreateFileA
$ @) G# |: T* f5 B, W. m/ C7 Q) q' s2 { 00401071: cmp eax,-0018 d. K1 m( d$ b1 W0 q! U
00401074: je 004010916 O6 U0 [- z. C4 v' j
8 b1 O2 w1 y+ s m% V# x9 `. m, e- P/ E7 V: Z6 U6 Z
There could be hundreds of BPX you could use to detect this trick.
& q0 V3 U; o+ g" J-The most classical one is:
: A/ y; {. O! i, K' B BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||5 ^2 y# D) U( ^+ ~- h. A# N3 i/ m- \
*(esp->4+4)=='NTIC'
% F, f8 Q/ `4 d; X+ {# b; s
( J" s3 ~- J8 r0 j- e5 M-The most exotic ones (could be very slooooow :-(
( c* {; O- F- s. |6 f BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 0 B. h: Z% T$ E4 X, Q! d0 \
;will break 3 times :-(
. ^8 q0 {" [* g: O, r0 \+ j. {
" K+ e! Q" [7 @3 }-or (a bit) faster: 6 }; \ F! _ u- r. u
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
7 N- D# j% s% }1 Y6 C( R8 |3 O# J+ |4 y/ o' r+ m5 q
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' ) ?$ i/ b& d' Q+ x) R0 g B: o. W+ d
;will break 3 times :-(
5 h" k. M& C- E1 L& R4 a7 x" X$ b D
-Much faster: `, d' X1 j n$ \. |
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'- @/ G. p; L, g
9 D1 A6 v0 o2 J) }Note also that some programs (like AZPR3.00) use de old 16-bit _lopen; [* O, f1 k, B' f* W1 x+ m
function to do the same job:
: s" P9 b" c0 L& D0 N, s, y
$ Z, n m Q" ]5 n1 O push 00 ; OF_READ
1 o, K @3 ^+ _ mov eax,[00656634] ; '\\.\SICE',0 k$ [9 V; W7 B5 g4 Q% A1 x
push eax7 h+ Q4 Q9 {7 j, ^! {/ @" a
call KERNEL32!_lopen
3 v. F( B5 M# m! g7 N: L) k inc eax: p6 n" @- @+ n# `
jnz 00650589 ; detected+ V' F7 y0 c- Z' X
push 00 ; OF_READ
3 J- G0 g/ [2 Y( k$ x! d v mov eax,[00656638] ; '\\.\SICE'
0 d2 w. s# E7 t+ s) m5 g push eax# h8 e+ Z. ^7 y- g# \
call KERNEL32!_lopen4 f* @% D0 p+ B4 j& p* `% \ r7 U
inc eax
9 q& x: K. m8 x& v& O9 W jz 006505ae ; not detected
* @9 x+ ~' i' Y2 N% H% k/ O3 \3 n# K' u4 M
! g0 t, I: `/ k& z
__________________________________________________________________________# x1 d& N) B) K: ]7 `
/ {5 g" F9 ]4 ~: X" U9 y1 p9 WMethod 12
+ c$ v2 R# |/ i! m=========1 ^6 s3 ~% e/ v$ [ o* E0 T, q E
9 @& Q! L" A |/ J1 B: T' O1 Y2 sThis trick is similar to int41h/4fh Debugger installation check (code 05
( A# ]8 Q2 D8 E) {5 n) n. B; @& 06) but very limited because it's only available for Win95/98 (not NT); [0 N3 x5 G4 Z7 R5 D" q
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
# f% E I2 `8 J2 d( ?: w
- L" m2 }7 L" k2 C push 0000004fh ; function 4fh
4 C/ h V" X3 J+ P: }% r/ X push 002a002ah ; high word specifies which VxD (VWIN32)
/ I/ e& j. U% |% y ; low word specifies which service0 \) P( ^7 B U/ l5 l' p- a3 \' A( I
(VWIN32_Int41Dispatch)1 y' K, t) Q* u$ v2 {8 V
call Kernel32!ORD_001 ; VxdCall
0 X) t5 s1 I9 n7 p cmp ax, 0f386h ; magic number returned by system debuggers
. W: ~3 f L2 H R0 A; O9 S/ I jz SoftICE_detected4 ]9 b, N* f k) U4 J. f
' g/ h0 e6 r2 l, ^' k! U# Z/ QHere again, several ways to detect it:3 W* X& Y* e: C; r) W# V
! s; E d1 H2 P BPINT 41 if ax==4f5 T& ~! e$ }+ z& ?, w
7 w4 f* V. X9 D BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
" ]* v1 Y& o$ ~) \6 R
3 f9 x9 C" w! a% G% L BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A6 }4 p( S9 d8 c: g y
5 ]6 V( ^9 ]" k' `( m6 X BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
: Y+ M9 C, m) K2 E6 J# x* C6 T5 n# _6 y- @( F6 n# k
__________________________________________________________________________
1 S7 W7 F, D: H3 g2 a+ q" u; v c/ |: N9 | f/ @' l9 t
Method 13
' J/ g- g5 |7 ^' _=========& E7 u$ o' L$ X/ c* W
% x- d( C/ ~2 I+ |1 y% k, UNot a real method of detection, but a good way to know if SoftICE is
! w! s, h" G: _installed on a computer and to locate its installation directory.; s" K/ K5 u& O9 K* {( T6 W1 ~9 |+ F" Z
It is used by few softs which access the following registry keys (usually #2) :3 I, Q3 [1 x5 g6 w
3 _7 A/ L, E% s: G0 A3 L$ ]
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion. u$ M4 x+ R' ^& b
\Uninstall\SoftICE
9 C" z& P- h D5 b1 {1 Q: N, ?-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- G' y7 e* n) n2 U-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
" [! m. ^- d8 z! T/ U% a2 s4 g\App Paths\Loader32.Exe
M, L2 Z/ A1 j' _ M+ [7 F; J: b1 W, R7 [1 V8 C
$ U6 {7 L6 ]" e0 W, a( R% M. w7 N5 nNote that some nasty apps could then erase all files from SoftICE directory
6 R% I8 c8 Q1 S+ h4 U4 o9 J(I faced that once :-(. v& {% v) \# `/ {# r- s
& u/ J# j- B0 Q: u- X: g5 ]; r
Useful breakpoint to detect it:4 ~0 p- a; D/ U! `! w8 G
, }: Q& j' C9 ~3 ]! h
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
6 Z3 H- f' m# e+ u2 j! Z7 Q/ U) ] n2 t( U. F
__________________________________________________________________________
# k9 y1 E+ V1 J. i' J, j
$ v8 }% ]' R5 a$ l4 I. M4 d/ d) }* }) m' B* o+ r0 w
Method 14 5 A$ }- x+ ]5 `: _
=========" o$ @$ e `, x' {% G6 g& h
- |6 N/ `3 ]. H
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose- Q/ W: H* ^# n4 n, x! R
is to determines whether a debugger is running on your system (ring0 only).+ t8 n {% n) X; Y
7 O- v- h. N" ~5 L# w1 d VMMCall Test_Debug_Installed2 f1 `! b7 h7 ?) }
je not_installed
! M: m2 F }" n, o/ D) ~# U/ T5 c$ B X# p0 C( r
This service just checks a flag.+ P; m8 g" V$ d5 D; d8 u7 R4 w* U
</PRE></TD></TR></TBODY></TABLE> |