<TABLE width=500>% w. S* `1 }$ @! k8 x
<TBODY>! p K+ y( V. Z6 M% Y8 F; {
<TR>: \- ?% x4 u9 v8 m2 d1 _9 v1 s5 b
<TD><PRE>Method 01 4 z) L: X% ~. O$ E! w
========= D6 \9 ?4 u6 v. N" M3 J
1 N. _6 _6 i7 U* K9 J
This method of detection of SoftICE (as well as the following one) is
5 \% A* I, `% W9 f+ iused by the majority of packers/encryptors found on Internet.5 x1 c i- Y4 H0 o6 e- \. j
It seeks the signature of BoundsChecker in SoftICE( ]; T$ \3 G$ Z( b
) ~5 u( h) `" j
mov ebp, 04243484Bh ; 'BCHK'
, ]9 ?( W( d7 y4 o1 `5 O mov ax, 04h+ R) I7 U8 P3 d1 i
int 3
4 n. S _, o- c6 ?5 h cmp al,45 R1 l9 H1 V7 E0 V4 `% T
jnz SoftICE_Detected
% R( X+ \3 x6 t3 x- O6 U
/ s: X0 v" ]. M___________________________________________________________________________
& j& p+ H9 z- ~. J' ^7 p; w+ n) n7 i
Method 02" L. T: L* \! V2 N. J. p! v8 w- B
=========
+ d; {$ A2 H) z6 A! {$ }) t% o) U) |
Still a method very much used (perhaps the most frequent one). It is used% W8 ~$ [( i3 W. j3 l
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
8 K, Z) Y7 c1 @: j: a( W# A4 hor execute SoftICE commands...
2 L3 v0 x" W/ f- h2 bIt is also used to crash SoftICE and to force it to execute any commands, A5 m+ U! W( c
(HBOOT...) :-(( - P/ I: E; M) ?3 a- D9 n0 w
" s, V+ T; D% _Here is a quick description:1 r# N+ O& Y5 d- G. I, s6 ^
-AX = 0910h (Display string in SIce windows)0 X. `" Q" M: }! p
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)) ~9 r$ w' {8 g
-AX = 0912h (Get breakpoint infos)5 A, [# Q4 V0 B- u2 l4 k r+ T
-AX = 0913h (Set Sice breakpoints)* [( q ^( x) l5 _+ l8 L
-AX = 0914h (Remove SIce breakoints)3 X; S! I4 F7 {' G" @
: A2 d( S: _2 m# `9 f3 @3 wEach time you'll meet this trick, you'll see:. c7 c; S# m" f* z. ]
-SI = 4647h
! U& {2 t) w6 J/ Q7 U4 S( G7 f-DI = 4A4Dh
$ y( y7 R6 S4 ]) JWhich are the 'magic values' used by SoftIce.
/ ~, }4 X- d4 M5 y/ n2 u& IFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
5 F8 n7 U% O( A8 u% ^3 A9 f% m# p2 B' O' R" C; \& z$ }, v
Here is one example from the file "Haspinst.exe" which is the dongle HASP' c" d5 J) F3 \6 O
Envelope utility use to protect DOS applications:
8 G' s7 p4 V! }2 X/ q
n6 p- j; X$ r, {
2 Q* E- L( y) Q" q8 Z& H3 ?4C19:0095 MOV AX,0911 ; execute command.$ y! V& ?& D+ J: i+ m( ~) j
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
) i4 C$ ?& p8 N0 m0 G) [5 t4C19:009A MOV SI,4647 ; 1st magic value.7 B/ \+ x( \/ h, j3 w& r1 W
4C19:009D MOV DI,4A4D ; 2nd magic value.
* `: U0 @. o: ]0 k8 B" V9 ]' z4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)5 m" V; r& S$ B# P( ?0 M, s
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
" K/ C, `) {5 ?2 W0 @4C19:00A4 INC CX
4 H8 H. M! m5 u, u4C19:00A5 CMP CX,06 ; Repeat 6 times to execute' Y, V8 F; S2 q2 g
4C19:00A8 JB 0095 ; 6 different commands.* v N- F: ^, }9 r0 e
4C19:00AA JMP 0002 ; Bad_Guy jmp back.$ ?: ~7 s/ ^ `+ @4 b7 ]
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)7 A/ x7 F9 I7 _' s5 ^
" S! o* v( _0 M0 r) oThe program will execute 6 different SIce commands located at ds:dx, which
6 ~" @2 @& t1 A C* `+ G. oare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
& K- m7 ~! [1 e* Q- Y5 z
& _3 o* K8 B, i. _- K5 e# ` `+ s; r9 U* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.1 N8 S! b, @3 d# v8 K# O% {2 n
___________________________________________________________________________
% J4 u: ~: X) b* y; X3 [4 T% L/ g# J
6 D, H$ P; D3 Q, Y* k8 d9 N& V' k4 l
Method 038 I, }! y' y) R# B
=========2 R! c/ V l2 R4 B o/ Z1 X4 ~
% J @9 y x& g
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h) R& X: P0 v! g5 \
(API Get entry point)
4 p9 y: A* G* J3 F
+ A- ]# t$ }3 }3 O7 K/ g* S# o) U! l; T, k/ c+ ?4 H5 H% U
xor di,di
$ h9 [2 E5 J3 i8 ]. z mov es,di
0 y J5 b' N% B mov ax, 1684h
0 u$ a3 E, @( m2 b' ?+ P6 A0 H$ B mov bx, 0202h ; VxD ID of winice# ]' [3 J/ o& A ]4 r% I
int 2Fh
8 ^6 R, ^ b! S- m V, } s) @8 \" V mov ax, es ; ES:DI -> VxD API entry point
7 ~: ]% G* @0 e: I% i add ax, di
8 ]5 _$ K# N# e3 j+ k1 X test ax,ax* \& C9 ^$ b$ {# D# Y# H
jnz SoftICE_Detected* G; X/ O, D6 k6 h
# `( u7 |& G7 M' h% Z# j+ o___________________________________________________________________________5 j8 p% B& S. r9 w) `0 a- u
( E$ l$ f! p4 Q' Q3 e
Method 04, O' ~# J$ S9 l: @& d1 C
=========
" a/ r4 ?2 b9 \9 r
5 I3 D4 K; n0 CMethod identical to the preceding one except that it seeks the ID of SoftICE
1 Z& q3 S0 d; n' T8 _% I2 A0 G, dGFX VxD.
2 j& N8 P) M0 Z( H& P
8 O" H0 M) O; Y0 D! z7 a xor di,di( J4 \. r0 X( n9 G S* U
mov es,di: \. R. }+ W) z% y$ Y/ M
mov ax, 1684h / Q- r8 j, _0 b, r7 ?+ q. q
mov bx, 7a5Fh ; VxD ID of SIWVID. r# D! p- _" R* e: ~" w0 [- N
int 2fh
' x" e5 F7 @. Y1 Z A& A* L mov ax, es ; ES:DI -> VxD API entry point# ^& s- @! Y8 d- [3 w
add ax, di4 A3 E7 H6 h$ \4 S1 H% {& `
test ax,ax9 n# S; s9 D# m' Z5 n) S: y
jnz SoftICE_Detected
% p0 Y. @; h; t9 r1 E8 u9 u$ U3 S" c( G4 Y0 o L3 w/ t& B8 r5 e
__________________________________________________________________________
& n5 d) {3 Z! w1 E0 C% l9 W% b3 K' m/ `) L
$ _+ ?8 u! y g$ b! h: T
Method 05+ M* l, N/ ^ g& A$ }
=========2 p3 R- l9 {6 p1 B
, n8 A2 n2 h5 z, @" h9 r7 D; f
Method seeking the 'magic number' 0F386h returned (in ax) by all system
' H' _' p9 M4 D8 Z. N/ ^debugger. It calls the int 41h, function 4Fh.
; ^7 _; N5 _$ D& }+ d& E1 gThere are several alternatives.
$ [& n" S% [8 c. O' W4 t \
4 T; R& G- f# Y P: n- _The following one is the simplest:! R& M5 T, k1 x) W
! K5 J( e7 i7 C" _+ L/ M
mov ax,4fh. D; \* ^* y; V2 h+ u
int 41h3 v3 i" x' } Y& [
cmp ax, 0F386! Q! f' c- j2 G: p4 s1 K
jz SoftICE_detected, D& w8 c3 B/ v8 m! z5 z
1 V( U# p( |6 }) l
& J9 z& @3 k+ z! Z; `1 h1 _Next method as well as the following one are 2 examples from Stone's
2 @ W# F# P7 o"stn-wid.zip" (www.cracking.net):
' L0 i5 z2 v8 M X) v4 r. N. s1 ^+ I- v8 a
mov bx, cs
/ d2 E6 u$ s+ c0 _( e( m# z lea dx, int41handler2" o9 S- F/ x2 `. d
xchg dx, es:[41h*4]( E- Y I0 n; Y
xchg bx, es:[41h*4+2]
4 Y& ` a, F Q4 L, \ mov ax,4fh
" ~6 Q7 e6 w7 k# B9 ?* _0 t& L" o" X int 41h2 }; S7 z% d* A! C
xchg dx, es:[41h*4]
& |0 y) n! E8 S% S3 x4 K xchg bx, es:[41h*4+2]* |" F4 T4 e0 ^3 f& j
cmp ax, 0f386h1 [+ |+ ?1 I" K" e
jz SoftICE_detected& @" Q6 M, t$ s0 h2 r
# C$ i2 I% T+ A: R9 t7 y- G0 X
int41handler2 PROC) h& v$ k! K" x3 U7 o
iret- Z- v' H3 ^, s! r7 P9 [
int41handler2 ENDP) H4 ~0 ?& g6 O1 n+ L: y
6 ]$ ~+ h. g }* G+ }" S5 [8 h. o0 c. [( g; G/ k- U0 k
_________________________________________________________________________0 \; W4 T+ U) T; p; B4 d* h1 _. c) x
' i) l6 ^/ ]+ x1 c' w
( @4 z ~5 ?2 n M3 LMethod 06
& F1 |" y2 f+ V! G1 a: u# i0 [=========
- H7 E; M$ V# n: \' H8 |
* K# e" A/ t" _) f" x& U6 i3 s8 d) O [3 U7 i; |9 k4 ~
2nd method similar to the preceding one but more difficult to detect:+ d4 g$ d9 O9 ?/ T, ~ c) W
0 R6 ?, P3 D& Z, u# r
9 O" O0 P! ?' H. u
int41handler PROC! e* d3 n5 f1 k8 c* Z
mov cl,al5 Z" A: P- L5 ]
iret+ R3 K8 U- _# a, i: h! s& q
int41handler ENDP
: |, e& Q+ w! ~7 X0 e1 W/ G \) g
0 W( D8 H; {" C6 C+ U* p6 ]+ K" U2 B& M+ H+ n$ ]6 U
xor ax,ax3 J. t K5 V! ?' K
mov es,ax- e* y# ?$ U& W& Z
mov bx, cs
% }) d& K: U. V1 g |4 `- J lea dx, int41handler0 n. X; x# D- p7 K
xchg dx, es:[41h*4]
% _ R8 P- r4 Q5 N xchg bx, es:[41h*4+2]
- s, ^$ k' E9 `. I/ @( X in al, 40h
- I! M* S3 D4 n xor cx,cx7 Z. s1 S4 l/ B) A& y0 Y
int 41h
) Z( N1 g6 e) J% [* L xchg dx, es:[41h*4]
4 r9 t) ?' R0 ]9 \, G5 U. c xchg bx, es:[41h*4+2]
6 x x% R& z2 Z cmp cl,al! l. r7 x4 y* \5 Q0 P- k
jnz SoftICE_detected
, _# g! F+ @; b8 ?" P n2 r1 X# i% R" e6 l5 P1 ~- ~
_________________________________________________________________________+ k. Q' L8 g4 K; V' Q
; t y( s2 _8 u" l2 r+ s
Method 070 ] ~& k7 L( N" Q1 y* A1 T! x
=========
( t4 @ g) _/ h; c$ K7 L& D6 ~
: F/ l8 ?1 a8 A" p: _. pMethod of detection of the WinICE handler in the int68h (V86)$ P3 y& v* P9 a0 ?, N
/ w2 w# i2 J# [. T! L8 V
mov ah,43h
% _ w$ u3 [2 M- {( V- U int 68h
2 U# a( N2 L( b0 F1 N2 V8 i/ | cmp ax,0F386h
& Q+ K3 i% d' s k$ P3 ?: j jz SoftICE_Detected
- E e) S; M9 `. g# ] P3 d6 c* x% k4 C2 J
' Y' {5 [. {3 n3 G0 @6 {2 M- D
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
" g3 R4 ~" _, d4 _ f0 L app like this:
+ c. X5 S, X: n: \, U' \0 |6 t/ {+ g2 J; O1 C1 D4 U& {) d4 e# S! S
BPX exec_int if ax==689 A8 ^" b' ]" ?; ^. @# ^& h
(function called is located at byte ptr [ebp+1Dh] and client eip is; e) i4 C+ k1 H* E1 ~1 k% d
located at [ebp+48h] for 32Bit apps)
/ @ O' Q. V9 h5 q2 M__________________________________________________________________________
1 _) R: Q1 s3 l2 d) K8 \1 I0 M7 U% e8 Y% X+ r- g. m) O
' G! t9 f. h6 K) oMethod 08
# ? K: j+ i- ^' o=========; w+ N' y/ o9 B4 B
! s. q3 L7 j) @& x
It is not a method of detection of SoftICE but a possibility to crash the+ ~$ w* r- t* ?# I9 J
system by intercepting int 01h and int 03h and redirecting them to another
5 g* g8 X% N7 C3 B' eroutine.
+ c7 P* @4 h4 o' z" Q) UIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points* Y% [+ l! a3 E5 p
to the new routine to execute (hangs computer...)
% m0 B$ O% t6 D% q# u/ K
% J: d8 {) Z+ p mov ah, 25h3 B; g2 K z9 D; {0 |0 Q
mov al, Int_Number (01h or 03h) E) o& I! E( ]" _* a$ s' O) V
mov dx, offset New_Int_Routine
_, `1 g9 n0 i0 s' V. Z int 21h
- Y$ f t) J, i# K# g6 E4 H3 Q% x* O9 ^( n, |/ M# L c
__________________________________________________________________________6 P1 I8 M/ I* B/ R
* w' _& u% p/ ^- A! eMethod 09
) v: o$ S1 V8 @+ j7 z1 I=========& P$ w) S: I9 i1 u& l
4 p4 h* b4 {, E U6 m4 R
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
+ Q2 Q7 M& [& \) J8 S9 u( eperformed in ring0 (VxD or a ring3 app using the VxdCall).
* P0 a' H# n! r _( IThe Get_DDB service is used to determine whether or not a VxD is installed3 l* G4 m2 B- j9 Y u8 ?: v9 U' T
for the specified device and returns a Device Description Block (in ecx) for
d- W( @8 e% ~; ?& D! O9 \; Vthat device if it is installed.
2 m2 o: H- S; R8 P8 i/ E, d
6 v8 d |2 \" s! } T% i( h mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID! b/ d. \7 F; @ `
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
+ T3 }1 U7 J5 q J! D1 W VMMCall Get_DDB
) y: A1 l) {) a mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed' q: A: \0 O" d% z
% ~" n D' w, o+ w, I" F# ^# e' k3 t
Note as well that you can easily detect this method with SoftICE:) M1 r- c. a+ s0 H# D
bpx Get_DDB if ax==0202 || ax==7a5fh
+ Y8 d* q6 W" l( s; i" c1 J2 `1 ]- Q% y+ [' i% _4 I
__________________________________________________________________________2 x- {: S- L U# r9 F
9 X6 O8 l% N. Q; _( K1 L0 D8 `- f1 MMethod 10
" n r: M8 \/ ~4 N0 C( I( D! [=========1 V+ d1 Q( z) Z- n
% O1 _% h$ h7 ]6 u2 L
=>Disable or clear breakpoints before using this feature. DO NOT trace with
, E5 A, {' Y1 o, x. ?8 E4 P SoftICE while the option is enable!!
: ^9 ?0 Q" V+ p% r0 u# Y
, b9 m0 G1 p0 ~$ zThis trick is very efficient:# h- L' b4 J% w/ T+ W
by checking the Debug Registers, you can detect if SoftICE is loaded6 `' ]: {% p; x9 I: o: z+ `2 }
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
% h3 b% F# F. u+ Z D; gthere are some memory breakpoints set (dr0 to dr3) simply by reading their
9 Q, _/ D5 U9 G& S; Jvalue (in ring0 only). Values can be manipulated and or changed as well
) c1 Z) x2 m# m9 g/ J(clearing BPMs for instance)
( B, k/ Z w$ G6 h C
# G; y4 ^# r$ r1 o9 E, O, o& T2 P- L__________________________________________________________________________! X$ u! F6 i2 h4 R. ?( |- ?# O
8 C; ~$ R4 ~! y( J/ w! }- B
Method 11
7 P: J, h4 g. u=========7 w; `3 e. S. T1 \4 Q" {( z- Q2 r
$ y: G7 E/ @) R" N) R& i, g# M
This method is most known as 'MeltICE' because it has been freely distributed3 G5 f! @: j( D h
via www.winfiles.com. However it was first used by NuMega people to allow
3 q! m P* P1 R1 a1 `# Y: zSymbol Loader to check if SoftICE was active or not (the code is located
5 o3 ^- t W, Hinside nmtrans.dll).1 B" F; P3 a7 b2 M2 c
' a& ]' d1 g: Y! c
The way it works is very simple:
& b, A' t. |5 n" |It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for0 _& \, _7 S' q
WinNT) with the CreateFileA API.' j/ V; f e8 b: J) ~+ L
R, T- V. W; V( N! J9 z
Here is a sample (checking for 'SICE'):5 y% H; D4 w4 l0 U9 v' [
- u4 n+ }2 @0 n. ]' l- ABOOL IsSoftIce95Loaded(): h3 O7 }- C2 _$ M
{$ n% C! _% c6 T# d% e6 n* ^5 Z" Y- ?
HANDLE hFile; - n) Q9 f/ _) G- l8 O
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,* r8 I9 X. x$ b% j4 n" R. r, L
FILE_SHARE_READ | FILE_SHARE_WRITE,
6 Q+ U) K/ u6 @/ y4 F8 w4 |0 B/ Q NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);) i+ t, M/ F3 X- ]6 Y
if( hFile != INVALID_HANDLE_VALUE )
+ z# r/ |0 W$ I( A/ e% I$ ^( o {* i. W7 @8 B/ N: J# _* w+ @. p7 o) W5 w
CloseHandle(hFile);
' F/ V% m; h& {" ]4 ^- c0 }7 c return TRUE;8 O8 c* m) _; u$ i) F T* O! B
}
: S( f$ ?1 h7 z6 z return FALSE;
! \6 W* m- l; w}
0 z8 \% Q( q5 [" o. H' c
/ R: y7 V9 Q* v0 H6 E# mAlthough this trick calls the CreateFileA function, don't even expect to be4 |3 \( x, W4 Y( z" [
able to intercept it by installing a IFS hook: it will not work, no way!/ D( D* |" L+ t
In fact, after the call to CreateFileA it will get through VWIN32 0x001F2 Z! y' ^* R& T; }. j
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
4 n' A. d- p" w2 n% @ l vand then browse the DDB list until it find the VxD and its DDB_Control_Proc/ v6 E- I+ C( C
field.
6 u, e/ y( H$ @0 b. I) p) aIn fact, its purpose is not to load/unload VxDs but only to send a 7 M, ]' B0 E& A
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE). A9 p. v% r A4 I
to the VxD Control_Dispatch proc (how the hell a shareware soft could try. W. F6 b$ z" G6 k1 _/ f: L
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
* t5 ?8 V9 @4 K4 S% h9 pIf the VxD is loaded, it will always clear eax and the Carry flag to allow
8 q; g, ?7 a1 ]/ e5 G5 `, N8 j3 |its handle to be opened and then, will be detected.
* z! q1 P: D) ?3 _% gYou can check that simply by hooking Winice.exe control proc entry point- R/ b3 H9 ^" h. I v1 b
while running MeltICE.% \* d% S: I- u
; Q P3 ]2 E" ^8 N! }9 {9 q' u( m# p- H, [4 \) B7 o9 |6 A+ g+ [
00401067: push 00402025 ; \\.\SICE" ^5 P0 R" F0 w/ q6 {% G: a6 I
0040106C: call CreateFileA; a- O+ ^2 P" C6 y
00401071: cmp eax,-001
' h5 {5 \' ?! Q. ? 00401074: je 00401091
# t! z8 j7 n5 q" R% x1 W$ @
$ m+ T/ Z0 u, w$ r7 L, I6 I; {5 U+ `4 h% S6 N7 J p! l
There could be hundreds of BPX you could use to detect this trick., J- d% S, N3 F+ H6 d
-The most classical one is:
# C! o7 U' p( B! O BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
: U1 t; f' G- X5 z *(esp->4+4)=='NTIC'
& H3 O2 F r2 B0 t, `3 [+ D* K I) ~+ q
-The most exotic ones (could be very slooooow :-(
; U/ n7 B2 F2 M0 H G BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 3 g6 S3 K, S. U" D$ H
;will break 3 times :-(% l' Y- g' l0 L- j4 \7 k+ N, J1 J
$ H3 c: a6 e; w+ G0 o2 G. p
-or (a bit) faster:
$ t' f H o! j; P9 B0 c BPINT 30 if (*edi=='SICE' || *edi=='SIWV')8 P+ i) Y2 h) f. Z% Z! ?; U$ D2 {+ i
. y# W F' ]" A$ u& u+ `
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' C0 ?; l0 \/ B
;will break 3 times :-(* J8 X0 K8 f9 R8 E1 }/ z1 {; |% q( w
' }, L4 ]7 j# e: W5 y$ ~, V8 |& g-Much faster:
P+ C5 J" g' U/ ?9 B: f& a/ p: E( N BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV': O( e" ^. V' V. n! @
- C; j. Y0 Q* lNote also that some programs (like AZPR3.00) use de old 16-bit _lopen' q7 \* q! d% }- z8 Y8 O& v# B; T6 M6 f
function to do the same job:
e, f1 A+ I9 y9 S0 F& z" `) X" `5 l& h& Q3 H3 P. k
push 00 ; OF_READ
9 @- F7 q4 k3 u1 d' r( @ mov eax,[00656634] ; '\\.\SICE',02 R/ @6 `# v4 X7 w7 |- E
push eax# h3 f$ W% H" t8 s$ b w: X, w
call KERNEL32!_lopen
$ G: z# }& {% w5 I4 p inc eax
! Y7 p3 C+ F% K x5 z jnz 00650589 ; detected3 f p5 @. T' R1 u. F: f
push 00 ; OF_READ1 O0 x* ~0 s* x k
mov eax,[00656638] ; '\\.\SICE'
9 C1 ~- e T0 L( q push eax |' y$ k B/ ]- t
call KERNEL32!_lopen
! K8 B) b. x! W& f+ O) `/ f: J inc eax
+ w ~ O9 C: ^ Z jz 006505ae ; not detected, F* _; Z! L, d7 U
* I. F. u2 }/ @% d' R% d
3 N' h6 Y) ~0 r0 L* j' q__________________________________________________________________________
! E2 Z; ^) C( Q0 s" g. O. S2 q, a4 ?; q7 s* E9 Y' Z8 _. ?& t
Method 12' k( m3 f: u9 e. q
=========/ d0 h4 T2 n" z9 q; ^
0 {" w. Y& l4 j% b/ o$ U! l2 [2 n
This trick is similar to int41h/4fh Debugger installation check (code 05
) C7 }9 r1 g! C+ K3 f# x& 06) but very limited because it's only available for Win95/98 (not NT)
: k7 @1 d+ a: L! was it uses the VxDCall backdoor. This detection was found in Bleem Demo.
! w' r* x# P# g: ?# m! d8 D! q( h
4 U s! u* h2 t; E! G push 0000004fh ; function 4fh
/ l3 v+ g$ C `" d1 T4 L push 002a002ah ; high word specifies which VxD (VWIN32)
, \. O0 o) X T+ ~: W ; low word specifies which service
; Y8 F& Y# Q+ b. [0 R J4 z (VWIN32_Int41Dispatch)
+ _) A1 [) a u) N3 w# S( i1 Y0 d call Kernel32!ORD_001 ; VxdCall$ [$ l5 M' b- Y3 h& J
cmp ax, 0f386h ; magic number returned by system debuggers
! Z; q+ z: T4 j2 C jz SoftICE_detected* r/ m# i/ O ^/ n$ n: r3 A. `8 l
7 n' H7 y9 X! s i& e2 ~. @ |Here again, several ways to detect it:& y+ @) i; E. b5 {9 P
6 k) v- x/ d) L( Q! Q' o, M BPINT 41 if ax==4f% X1 O4 u0 L4 B: N P5 b$ R8 w
& d4 v3 N; \' w5 \) _ BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
5 H3 k5 }4 q+ x4 D8 k8 u4 J7 p! R. `' G3 C6 X
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A) h: A I; j. ?
& H( z( g8 E! ?0 O; u$ t* X
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!+ W, [" z* V; I- [, y! c
! k% N+ i0 G/ M8 [* m7 Q$ J4 z__________________________________________________________________________
6 J) s# D/ V7 S& V4 Y2 j: J" `1 A# I7 x) D' ?
Method 13
2 |! E: z* J1 [1 ]. K- N- K! a========= G' b4 @ i! c5 Y, H
& v6 `- R( d5 w( ]Not a real method of detection, but a good way to know if SoftICE is- }5 K" m' C8 ?. a* w3 B
installed on a computer and to locate its installation directory.2 H( s2 b5 v# n9 O6 i- q% @
It is used by few softs which access the following registry keys (usually #2) :
1 |1 [9 M8 m+ o
' K' o9 `" L# h( w-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 v( E5 u7 E+ D0 N, _
\Uninstall\SoftICE9 A8 h. c& d m
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- S! u6 [0 z8 w) T-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
& O$ E5 l1 q1 c; m3 m) ~! S; {5 v\App Paths\Loader32.Exe: U- S- E) g( X# i: n! E1 r5 D' B4 V
8 I! i. q0 G) A1 b% O- n* [9 c/ h* Q" _0 Z
Note that some nasty apps could then erase all files from SoftICE directory
4 D( w3 p$ E) v4 M5 S& ](I faced that once :-(
5 A$ @; t) B! s+ h2 i# D- x: d4 Z2 R" L
0 \8 ? e& O# Q* J m+ G x7 DUseful breakpoint to detect it:) l1 {) h% h( W3 d% H+ M# s4 k$ {
+ B& _' w& G7 q4 \* A- |
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'2 F' B A7 U% q* Z! ?# p! i ]
4 o/ [* j2 q8 b A__________________________________________________________________________3 Z$ E) j3 e) n/ f o
' B5 ], ?! D% R* g" m) B9 R8 q
) |8 G) m, T4 e! S2 R2 yMethod 14
v+ v% u b% F* k=========
* V" f" v) t) E0 Z. H# H! w' |% E: s$ J. l
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose1 [4 F8 g+ i, ^8 I
is to determines whether a debugger is running on your system (ring0 only).5 F9 X) U9 d8 p8 F" T) U/ F
4 R5 |# ~2 j6 e
VMMCall Test_Debug_Installed- s H! _9 t" {: h9 h, M; c9 m
je not_installed
; x3 l* c4 _3 X: U/ E4 s+ ]+ O2 b
This service just checks a flag.0 f, w6 `9 o1 b5 T& t/ y
</PRE></TD></TR></TBODY></TABLE> |