<TABLE width=500>1 B( R# I3 S+ T
<TBODY>" h+ R6 A4 a+ ^7 Y
<TR>8 S! W* s2 a y: m8 l$ u
<TD><PRE>Method 01
1 ~. H d3 ]+ A5 ^- j/ z=========9 Q$ ?' b7 Z" b: @
% j: \( }/ q6 ] aThis method of detection of SoftICE (as well as the following one) is* C+ K4 H" B3 A" S/ u# O* R
used by the majority of packers/encryptors found on Internet.
. c/ w) B4 N' K2 z" e0 g. s1 ?It seeks the signature of BoundsChecker in SoftICE ]; W2 ?+ _3 W/ E4 o. z
. v% i( a( s% q, E& U: _ _
mov ebp, 04243484Bh ; 'BCHK'
& I. h+ r B) H) D! |: C( m mov ax, 04h
" o9 p, b5 {6 }9 ~( F3 z- y int 3 # O1 F8 D9 J$ B8 y, n9 Y
cmp al,41 e* y4 Z1 o# c
jnz SoftICE_Detected0 U2 Z6 W9 C) m1 ~( O
7 `: \- @& `1 P7 z0 S
___________________________________________________________________________
, y! T. d4 u& E: R: }# d* f) ~: v2 g
* R1 T7 B7 d5 QMethod 02
. o: A3 u8 V, t* ]=========4 ]/ `, I5 W9 M5 r( }9 O. S E8 ^
$ D9 c' u: W: z" vStill a method very much used (perhaps the most frequent one). It is used/ Z( w8 o2 e6 I# w. g, f; J& j9 f' Q
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
6 U, q. @- j& `or execute SoftICE commands...% W- ~, U+ F* \
It is also used to crash SoftICE and to force it to execute any commands! W( B( i4 Q" X9 X! f: P
(HBOOT...) :-((
, l( W4 ]. Q. M9 b4 ~3 z5 ?5 Y2 q2 D2 O; |. l4 {0 c) y
Here is a quick description:
; B3 B; x6 x. x' y-AX = 0910h (Display string in SIce windows)
- O% x7 n- |9 d0 v3 X s" v-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)2 g9 O) B1 ^9 \
-AX = 0912h (Get breakpoint infos)/ Q; `1 Q$ L) {. j$ w: J
-AX = 0913h (Set Sice breakpoints)" o- o" s5 d, d ~$ I, s( {5 E" x; y
-AX = 0914h (Remove SIce breakoints)1 B: {7 s8 h4 v, F, ]) k; ]+ X
; z7 F& d- a) Z- K, w/ R# tEach time you'll meet this trick, you'll see:
. W5 e+ x$ e# B+ {-SI = 4647h: {# y& B, i) t% ?+ k
-DI = 4A4Dh `4 X3 Z# ]7 u+ D0 m5 l
Which are the 'magic values' used by SoftIce.5 A0 f: v( i& y! S' V" l
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
$ e9 n( d' x! V& e+ [; s6 t4 Z/ a0 X9 Z- P$ n- T5 |" j9 ^1 l
Here is one example from the file "Haspinst.exe" which is the dongle HASP
- p! h- X% n3 y2 [8 UEnvelope utility use to protect DOS applications:
5 r8 v+ y* g) W: \ u% m7 c2 x o0 \8 M, W% Y
+ J9 l6 X$ e0 Z9 f/ z4C19:0095 MOV AX,0911 ; execute command.
/ Y/ D& `; T7 ~ G; N4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).. A+ x: d: h+ c, q1 d+ J0 S
4C19:009A MOV SI,4647 ; 1st magic value.
2 T# D4 z2 Y$ _4C19:009D MOV DI,4A4D ; 2nd magic value.) T: `2 I1 @; g# j; e4 w8 f3 z
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)5 D( K/ Z/ ]0 X! E* x
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute+ n b1 S1 J" H8 t6 [' p9 {, ]
4C19:00A4 INC CX; G! K/ v( j% X* d! @" S9 }/ `- o) t
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute4 ?9 p( L, N1 t' j. H
4C19:00A8 JB 0095 ; 6 different commands.
9 U" G+ D% S1 X3 G3 J1 I# m/ n4C19:00AA JMP 0002 ; Bad_Guy jmp back.4 c" [6 |- G3 l9 P2 f4 X5 J6 j `
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
, x8 ^* @) o2 C5 A' T" d. q6 ^$ f7 ^$ w# h+ H3 {
The program will execute 6 different SIce commands located at ds:dx, which: E0 r5 Y. c& j4 w. _
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
( M5 H6 y" K, \+ C, N. O1 K5 Y
, K# ~5 J2 `4 G* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.( x) A8 ?' ~& b7 a% q- S9 ]
___________________________________________________________________________9 ` d) _$ Q1 R
( f' h. _+ A+ a" Z
( s2 m' _7 ^8 N# w. n7 PMethod 03# S" x7 o6 y2 {) K/ o8 G
=========7 z4 d9 h# G( {9 g
+ T- Z, |: B6 C% l- I2 Y/ T
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
% H+ b: H! ]4 _, M8 [& P- a% r(API Get entry point)
- [: @9 M6 Z+ d) `" f
! `: R/ M( d9 l. ~7 Z& t. `9 D, U9 K v* I: G( T1 o! y2 `
xor di,di
/ t! q# q5 O3 m$ p) A0 X$ _ mov es,di- r( p$ Z- E6 ?: Q9 E! s$ C; X4 [
mov ax, 1684h
1 j! O4 |$ ?2 D, j B' K6 g mov bx, 0202h ; VxD ID of winice
5 }0 t) p, T4 S int 2Fh" l1 t' m" Y6 l: c2 q
mov ax, es ; ES:DI -> VxD API entry point4 c4 e1 d6 n- W, f. @) [: `7 _) U
add ax, di# M, P/ w# e) ]$ o( v( V0 D
test ax,ax2 M; x9 }2 y" U" {& \
jnz SoftICE_Detected
) u3 g0 k1 x# o( `/ r
! X" P3 S! W3 w; S! t* v8 i, U0 R___________________________________________________________________________
% x3 _, T q8 f8 P
: A v7 B) z3 F7 v; N% r" [* yMethod 04$ ^) O. K7 r" F3 V) L. o* J# |
=========
! r) ]: }6 r5 M; l3 y
& v9 s8 c7 r7 o: tMethod identical to the preceding one except that it seeks the ID of SoftICE( Y! o# _- i6 h& A
GFX VxD.$ J7 Z% d* ?5 w; x* t, ]' S
! \) v* I1 r2 d xor di,di. E; z# h) D# {1 w7 e. E. ?3 m
mov es,di6 S" x# ^4 |- Z# M2 K1 Y* m2 Z# b
mov ax, 1684h
, v9 } u' y" e mov bx, 7a5Fh ; VxD ID of SIWVID
: w; c' s8 v/ T# U( X* y4 V0 J# ] int 2fh
7 _; y, ~: \: r7 P# P) ? mov ax, es ; ES:DI -> VxD API entry point8 R! n4 \0 ~ P8 j. O
add ax, di. s' x. b. Q; Q7 `& Q, V& j
test ax,ax ?& h, }& k% q" J9 q6 S- m
jnz SoftICE_Detected
6 P8 K* K6 G6 _+ P5 b% q
- i% k) x* F- F) R! k8 [__________________________________________________________________________4 y- c" f! r3 d4 ]
0 S! Z% ?( G" p R
" v% w$ f" w8 e+ U8 e7 ?. JMethod 05; p7 D. [0 e) d3 M2 y: }$ v
=========
8 h$ @4 G8 i; A X
3 E' e3 k5 z: wMethod seeking the 'magic number' 0F386h returned (in ax) by all system/ X) e/ `$ t5 v) T9 L7 X
debugger. It calls the int 41h, function 4Fh./ c& ~0 k' Z' ^; f/ Y
There are several alternatives. 7 N/ Q1 I0 z, s$ C& P+ D
& M9 l) n E( n) T5 f
The following one is the simplest:
, N$ ?% G, v Q. u: X* P9 d' Q% }( Y2 V$ Q
mov ax,4fh" P$ G* p: I* D0 d7 o( b
int 41h
' K9 @( z" U1 G) T* h% m/ u cmp ax, 0F386+ S; H6 ^, f# o9 j% v5 D& P+ i, r1 W
jz SoftICE_detected
. w6 T3 c: l+ g8 M" X) e( |6 o& @3 P
8 U+ i4 i/ Y1 M4 y7 _) uNext method as well as the following one are 2 examples from Stone's
% X, ^4 E, x- N" P. Z"stn-wid.zip" (www.cracking.net):' E/ e4 P: T! m1 \' K
$ e# `$ E3 R2 g- c
mov bx, cs
% R- M1 c) ?$ L7 h% ?' {4 B lea dx, int41handler2
! N7 j( M9 [+ k+ X' e% x1 r xchg dx, es:[41h*4]
' s1 G0 u: z& l- A2 W xchg bx, es:[41h*4+2]) C2 \$ |& h4 D$ a
mov ax,4fh
+ S4 E( `& q+ W2 g: M" V int 41h; d( n8 P4 ?* p5 E: H9 F' V" h
xchg dx, es:[41h*4]
4 J' c2 k7 E" c& H xchg bx, es:[41h*4+2]
( j/ r, O- g+ F8 t! A7 q5 { cmp ax, 0f386h
, U$ M6 O, k k: [8 d jz SoftICE_detected
8 U5 q- L# m E: \' z0 I( P* V+ o* S% U# K
int41handler2 PROC5 b2 Z+ T* j; `
iret9 u" s' s$ U! i4 k& V! Y8 u
int41handler2 ENDP
5 ~9 O' ~7 [+ a' ~. |$ Y! L& i; b
0 H) \: V1 y7 a) y' u$ H- b9 w) Q" f2 ^3 T
_________________________________________________________________________
7 d- f/ E8 w) s; v' A3 a
; W# q; J4 V( C w& ]5 K1 [, O8 K
/ h2 u1 ]3 X+ |) {" LMethod 062 ]; b, Y" J+ U& F0 s- G1 K
=========$ }4 }6 Y7 m3 Z; A" h. D m& S
& n4 {$ u! I0 y
6 M8 O' E: ?5 B% _0 N1 x, D7 _$ @! v2nd method similar to the preceding one but more difficult to detect:
8 o+ x' k" ?5 `6 W y
- `0 D( u; M9 Z s. n/ a2 a) c e0 e- q# p; S& y( d
int41handler PROC A8 C( M0 R! ?" z7 t4 M' `! O' q
mov cl,al
; `- C' n7 u1 F4 t iret& i1 j5 U* I* U. x
int41handler ENDP
) s/ L3 `+ Z- u% j2 {/ s+ S! e; G8 [6 @, ]3 A
s' Q) I- O" u xor ax,ax
: }) p3 L1 a$ A" S* q5 O! u6 s+ ~ mov es,ax
9 p, s( n x0 x mov bx, cs
) K$ b* G1 `# I6 s+ n lea dx, int41handler: h2 p/ V7 N, D& B
xchg dx, es:[41h*4]
' ]4 M: w: D! g9 |, \) ]! r0 B xchg bx, es:[41h*4+2]
9 I; D7 K5 T) }! L in al, 40h
' j p! P: A) x, n! E) t) _ xor cx,cx: ^$ N x" ~3 w: Q; H5 K$ S% U4 r
int 41h2 U4 T9 r. ^2 S7 |. T
xchg dx, es:[41h*4]9 Y3 A4 X' _/ c0 D! {4 Z, Z, m: e
xchg bx, es:[41h*4+2]
# P% H- l0 x2 S* Y4 H' C# P" B4 R cmp cl,al, G4 v) A* n* a& z
jnz SoftICE_detected
% T; k$ x) z6 ]! J" E+ ^5 m& D! }* g8 t3 n* u7 G" k: W6 N
_________________________________________________________________________' e$ x5 [' w0 G6 T" R8 k, U
# x T" k8 X, @6 h1 S% C# Y4 A/ Y
Method 07
5 y' v% S' i3 L9 k) K* W=========
" N& M/ q' t# g& T6 L
2 D' W3 O; Q& y) s3 G, E) f! M$ u+ w) U+ CMethod of detection of the WinICE handler in the int68h (V86)5 m4 p) N2 W. x8 ]$ @
5 w; b1 ]! q* G: o5 D+ ?3 V$ k" `
mov ah,43h
; I& p# e1 g, o _! a int 68h7 H) X9 |6 N& ~! B9 O
cmp ax,0F386h% ]( l" U2 \/ Q; b& A
jz SoftICE_Detected! z" ^1 `) U l6 n# a
6 g2 X$ _+ d% q$ v" }# @6 G5 L4 W2 ^3 R! M8 s' {: ]' G, E
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
) |3 O2 P) d" G" i6 k7 P2 S app like this:
" G4 N2 j3 N. k- |; }9 J/ a9 R/ K8 C, w/ l s3 i' ]
BPX exec_int if ax==68# I; `& R5 T5 a, ?0 c* ]( {8 s3 |
(function called is located at byte ptr [ebp+1Dh] and client eip is% X0 t# J# J. |9 T& L/ n ^7 R0 S2 A
located at [ebp+48h] for 32Bit apps)! y3 _( S) s [9 a; Q9 v
__________________________________________________________________________9 m6 {1 J" O6 ^) X6 O+ e* U
9 ~# j' F( T8 y/ |
" f# u0 Q+ i( S9 X
Method 08, @ l: p0 f" c; R8 M3 F! w+ x$ u
=========. r2 Y3 F/ m) z
5 K. J- {: w* E
It is not a method of detection of SoftICE but a possibility to crash the' N) f! x e7 z; }* b
system by intercepting int 01h and int 03h and redirecting them to another
# Y4 z4 |) J j8 Vroutine.9 _$ a7 V9 w! H
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points+ E+ b, b3 W$ v J% F0 ^1 e
to the new routine to execute (hangs computer...)
. h# X5 G' j5 s) S, b- \1 h
l8 K" I: _" {, S7 }! H mov ah, 25h
: c; u7 t& q9 u% I mov al, Int_Number (01h or 03h)$ e& c% I$ [% x! A7 }
mov dx, offset New_Int_Routine
& q, D2 U. e% j! w% w int 21h
! Z/ n% J1 s2 `0 E8 B k( J( s2 p/ R m
__________________________________________________________________________
6 I$ u" P3 m, y
' n K7 V" g9 T0 C8 A* lMethod 09
4 S* E3 @% T. T( ~- J+ c. d3 X4 n=========
7 {9 d: V5 x6 N9 r' c! U4 L) Z5 p2 u( W2 {% e4 ?9 G& B c
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
# @* r/ c) O& D. iperformed in ring0 (VxD or a ring3 app using the VxdCall).0 y7 b3 X1 M; ~( c" C' V4 J' }
The Get_DDB service is used to determine whether or not a VxD is installed2 Z5 f. ^$ B3 D2 y6 R3 [. @
for the specified device and returns a Device Description Block (in ecx) for& {9 g1 ^. Y% l
that device if it is installed.+ @1 _- K8 ]. e# u2 v" J% |. ^
3 O. a; r. c9 B; [1 i( W' w5 b, ]$ k mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
* l# u) n2 V/ L! d2 d. u" Y mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
3 T$ V8 F7 T7 @1 t; h; d VMMCall Get_DDB
9 S: }6 q0 h" B! i1 z+ R5 U mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed' t3 g* L+ r+ r3 y+ R/ s$ E0 G
3 C x X7 Q9 I$ T4 E7 ^% bNote as well that you can easily detect this method with SoftICE:! x6 F7 _5 N9 J/ j! Y( U2 O
bpx Get_DDB if ax==0202 || ax==7a5fh2 @+ y4 Y) t8 \: ~4 g
' e+ K2 G+ Z, S1 {# O- C# c0 l- ?2 Y__________________________________________________________________________
8 k& A4 R/ v! G/ @
% ~3 a( B3 I# j" |. Z& [5 x ^$ w' kMethod 10
+ q/ `" b5 d% F1 d3 s& {6 P=========
3 |1 k/ y* F3 \1 c" }# |8 {( f& z; S* j5 n- ?. g( m
=>Disable or clear breakpoints before using this feature. DO NOT trace with
; x* A) N" S! \4 ~' \ SoftICE while the option is enable!!
' `/ w7 I8 y* m! p+ `1 G( \+ K0 A |2 Q9 N% w( S9 t
This trick is very efficient:
# \: g/ A/ X0 C& b5 ?by checking the Debug Registers, you can detect if SoftICE is loaded
& `( T# l* g. a0 }& S8 `- T) P(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if( W4 x" x- `) r5 {' ]2 Q: q/ c
there are some memory breakpoints set (dr0 to dr3) simply by reading their% s7 J: v2 K1 l& ^' I4 `* \
value (in ring0 only). Values can be manipulated and or changed as well' o) @2 ^* i9 h+ W$ {
(clearing BPMs for instance): w" _# X0 m7 ^7 x" C; P
" k9 t4 G( _; J- [
__________________________________________________________________________
& R5 A0 w6 Q) L- M; m, T0 z j& |8 }
Method 117 d: s0 C8 a! _) s' ?
=========
. s$ V7 j6 q+ U; A. b
: x/ [# H8 L& e; @This method is most known as 'MeltICE' because it has been freely distributed
+ u5 @; v* O7 W1 [; V5 ovia www.winfiles.com. However it was first used by NuMega people to allow
z& u+ x# m" c, L# ySymbol Loader to check if SoftICE was active or not (the code is located
: s2 C+ ` k' J/ W* G) Jinside nmtrans.dll).
1 Z! K9 V) [) K1 K: V! l/ G; [" h
. c1 ^# a( g3 O. @The way it works is very simple:% W. |( k* E. b) d1 E
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for# R, k' K. m3 X
WinNT) with the CreateFileA API.$ v4 d: ^% A/ C& L+ z: t: m
3 C9 k/ t4 n, Y/ W
Here is a sample (checking for 'SICE'):
x! P v& w1 j6 |6 t. E+ }) b$ t8 @+ u+ S" V$ u
BOOL IsSoftIce95Loaded()
' d# y" ]7 F1 w$ L" {{( d; z4 j y/ r: R
HANDLE hFile;
2 S! M3 I2 |" A/ D: L9 _ f hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
x. h0 O- ~, A( h. c% \" B FILE_SHARE_READ | FILE_SHARE_WRITE," H$ U2 c$ u4 n" J- J$ ]7 Z
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);4 |5 O9 t+ L: G1 Z
if( hFile != INVALID_HANDLE_VALUE )
4 G/ w6 L H) [) ? {9 s; l5 `1 A* A+ A) ~$ G
CloseHandle(hFile);! i; K0 a/ t: I- c3 d- r( E
return TRUE; g2 B$ [3 b5 Y
}: D/ o; ~# h# e8 j% n6 n+ @* I% \
return FALSE;
( p% w" {( C9 P}
# Z0 ^/ r T9 Z+ \. N( V9 T5 d& L" w O) c t
Although this trick calls the CreateFileA function, don't even expect to be, q3 L- ~, V, C
able to intercept it by installing a IFS hook: it will not work, no way!
% N6 _: t/ W' o- p* fIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
; o- s* E+ p7 Uservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
* R* z0 j ~7 G: A% e$ j g$ c$ Land then browse the DDB list until it find the VxD and its DDB_Control_Proc: U. M2 C* x3 \1 _- s7 e" g
field.
' j- k: ~' i* w, P7 j {In fact, its purpose is not to load/unload VxDs but only to send a
3 A X$ ^! |! r; w: GW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
' o9 A! ?/ v) k* `5 r3 yto the VxD Control_Dispatch proc (how the hell a shareware soft could try6 r* U+ ?% [8 j; N6 p* Q. U u2 G+ s
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
8 `$ x7 k2 ]0 Z9 NIf the VxD is loaded, it will always clear eax and the Carry flag to allow
. Q; t$ n, s; }. O/ wits handle to be opened and then, will be detected.
( m1 b5 _9 F! x% L* A+ T" m4 {. |You can check that simply by hooking Winice.exe control proc entry point
% T( ~0 q6 v) ^8 s8 q% Lwhile running MeltICE.6 D) L. l7 R$ ]4 t* ^+ }8 }. o
' q3 b9 K3 B9 U
0 }7 ]3 \/ w7 [: d6 A; P 00401067: push 00402025 ; \\.\SICE
4 m J `' i2 N0 B- D 0040106C: call CreateFileA" L5 g) t; K8 v/ H
00401071: cmp eax,-001) o, B9 d! o2 M, M# B+ `" h5 X' ^
00401074: je 00401091
$ p1 n) @2 ^! d, t1 f4 W, E' D3 X7 `
# v* O+ O2 _; [! B0 L
+ Y3 c/ N) u2 A# b8 @There could be hundreds of BPX you could use to detect this trick.6 \4 m, t G( c2 Z
-The most classical one is:
( |) I0 U/ n8 v6 I! u F! @) L& I BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||- }) A) B3 i, r
*(esp->4+4)=='NTIC'
3 e9 R# l7 [# p' Y
, Q9 y6 l8 z, G. Z/ [& `: q- n6 Z-The most exotic ones (could be very slooooow :-(
7 G$ m0 h; n/ J+ q' ]& Q BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') : v9 R8 S4 ~+ k# i/ ?) _2 i1 b
;will break 3 times :-(! ^/ p, [3 o7 G' b
# a& r. L8 `& E, s7 N+ L
-or (a bit) faster:
+ N& B* T4 L5 _2 C: e7 G BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
A$ p0 |3 p( E T. F; V* X! X0 U7 Z4 y' G8 t0 j: B- ]5 I/ Q- J
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
# Z! }" Z# }( m8 q ;will break 3 times :-(; f* T8 K+ u O% x1 W! A: Z t
: _9 X( W3 I- _2 o* g5 p5 |6 ]9 s' W! x-Much faster:- r. o# o7 a3 ]0 o
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'& ?0 K! J) N/ y' S% Q+ p" Q y+ T
6 s$ r1 f9 \4 \& lNote also that some programs (like AZPR3.00) use de old 16-bit _lopen; a% ]+ ^% G- o
function to do the same job:
, d7 `* b1 ~) [9 C+ F( E- z: F8 Q9 ~4 O& c2 G! K+ z9 e! B3 F
push 00 ; OF_READ
. m; x1 }) j0 N! ?1 X& m mov eax,[00656634] ; '\\.\SICE',0
$ V% i, \ x6 t/ U push eax' U! c, L* n2 v1 V: j" D1 n
call KERNEL32!_lopen3 H* t' c' n9 w* ~/ f& L7 P
inc eax* ]) \: ^: r( Y) ~$ G; U0 D* R
jnz 00650589 ; detected
- z. @, x9 u+ S4 h& e- t push 00 ; OF_READ
4 a7 l M. X- n0 B, J, q5 |% L mov eax,[00656638] ; '\\.\SICE'# U. F( N$ g5 I
push eax! c X3 O" a$ G0 ^7 J: e* k# s! y" M
call KERNEL32!_lopen ^1 p8 K, T8 `8 B. i! }5 `
inc eax3 u4 N0 q) z* O4 p% l6 ~& k
jz 006505ae ; not detected6 w7 j& J% L. |3 Y; N
0 F, J! \4 o/ l9 u) ~
3 k: t( X" o/ B1 D__________________________________________________________________________! @9 o. I. j0 y7 Z/ q
- l& W5 v& u* q# u+ P) {
Method 12% h9 L" ` m+ i8 ]! h* n
========= ^8 T/ k; N) R6 J- O) u' J
( B/ Y/ P; _! `. i- a7 [+ [# P
This trick is similar to int41h/4fh Debugger installation check (code 05
6 }1 z" [5 ^) f# `1 k+ t& 06) but very limited because it's only available for Win95/98 (not NT)
3 o' \4 A8 _ k w4 @as it uses the VxDCall backdoor. This detection was found in Bleem Demo.: v- Z) x+ m% d- N! M
' b5 [# l+ D A' ?7 W push 0000004fh ; function 4fh; W: G! H2 H9 p' n7 f% l
push 002a002ah ; high word specifies which VxD (VWIN32)
) C" W1 o' `! |8 S+ I/ H ; low word specifies which service
% H% z1 i7 w) e7 ?) z; v6 P (VWIN32_Int41Dispatch)
# Y5 U$ L$ n+ s' f/ K! A9 w" t: f call Kernel32!ORD_001 ; VxdCall3 x, l" h/ m! W; v! O1 Z; c/ B$ Z
cmp ax, 0f386h ; magic number returned by system debuggers
* L b: Y- M( R, `. {8 v2 Q4 p& U* Z jz SoftICE_detected' _% X5 R* E. K. [& j' I. ~8 m
; B6 n- ]* _1 q1 M/ q3 W+ ]6 e
Here again, several ways to detect it:8 `5 W3 E; t4 P$ ?( J- S# f, S
1 t( {) ], P6 o2 e, u7 f' s BPINT 41 if ax==4f, y5 y; Q2 A9 A7 Y
: v9 t- U' H; F/ z# h& z6 C( ?- z5 H BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
" {, D* }( i) I7 ?2 i
9 Q/ M+ X1 t) S4 j' [$ D2 V% A$ B- Y BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A/ {# k$ g# v4 l0 y6 { }0 C
1 ]3 D% J) U; L% M
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
' e( Q: X- V4 E& J2 T6 T7 G. Z8 |; W$ l+ b
__________________________________________________________________________0 x; g; L. i4 I, d. o4 @
. H) b) u/ w. F+ [# {) A4 o1 V) N
Method 13
4 |% l* y. N1 T+ H=========
# v: M V5 _- g0 n( |; l' q
, ^5 R$ S' R' ~Not a real method of detection, but a good way to know if SoftICE is5 J: L6 T( ^$ k
installed on a computer and to locate its installation directory.
2 v2 b C# j4 {It is used by few softs which access the following registry keys (usually #2) :
|: q* L" H" r
3 a2 K `) I8 d7 f @1 m+ o-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
: q a* M- T1 b# N\Uninstall\SoftICE
2 P' ^, V. C& j) z4 E* V-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
& i, l+ b; p( C6 Q-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
, I! {: f r) Q& q\App Paths\Loader32.Exe. R+ S& P+ U _* H3 i$ ]
" I# N7 F2 i) J3 h0 X; J" u3 N
Note that some nasty apps could then erase all files from SoftICE directory% r% m2 J ?. g) x N% {1 K$ J
(I faced that once :-(& p3 E+ P5 j" t5 d
( ]) D, [' u! H7 Q2 Q! y. K: LUseful breakpoint to detect it:! }! c1 \: z' P3 m
( U! m) H1 Z9 k' V4 i
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'1 r. J, {7 B& Y" B
8 d6 g e3 z% F( z% p# d2 n__________________________________________________________________________6 c2 ~! _* G1 |; ?
& a0 ^, ^; y4 d3 `2 n
$ s4 ^' p( c* \' E; {( t6 qMethod 14 9 |' _8 }1 }2 ^2 ?) V
=========
9 F% l, }" A6 H
' ^6 {% y" J. o" `A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose. ?4 o( _: }3 R" D
is to determines whether a debugger is running on your system (ring0 only).
* T; ^- V# z2 H: V1 S% r! @
. s5 h* J7 K( y# k* M% }3 u VMMCall Test_Debug_Installed
8 Z" c' P2 r# @+ ~' x je not_installed/ C. C! V! S# V. ?1 F& S7 w N+ K
6 D4 T @/ ~' Q/ K) IThis service just checks a flag.
3 u6 M3 t/ L3 `& x" Z/ ~; \$ R1 X</PRE></TD></TR></TBODY></TABLE> |