<TABLE width=500>( W9 U$ o. b/ \" A/ c
<TBODY>9 i# U* f) s0 d) m
<TR>% U! D' n( A+ H, N* l. t- M/ }
<TD><PRE>Method 01
# Z/ _- Q1 Q2 i=========
+ ^0 x e5 T3 l, U3 _9 |. A6 H5 y
This method of detection of SoftICE (as well as the following one) is
. X: V3 O7 ^# X! cused by the majority of packers/encryptors found on Internet.
" i c9 |. G: \+ Q% PIt seeks the signature of BoundsChecker in SoftICE6 F) d2 O& s8 Z& e6 c3 a
; d3 @/ K( g, n# [" \ mov ebp, 04243484Bh ; 'BCHK'. ^9 T- ]* S* l( s
mov ax, 04h
! ]9 Z" i N J* N F int 3
+ ]! D! f0 F, x/ P# q' z) A; c$ m cmp al,4
7 Q6 A& i/ p* u; u1 G! g. ^ jnz SoftICE_Detected( V7 {' L$ `# @# ]
7 w7 W3 ]# c K/ j2 [___________________________________________________________________________! j" { R, k4 Q2 | t3 n) } S
3 ?& r- O6 z7 R: SMethod 021 X' @) ^1 [, }0 n& T
=========
" |; V8 ]3 u$ [8 b+ G3 A+ D' z: }3 q6 [2 o, s8 ?. d
Still a method very much used (perhaps the most frequent one). It is used K* f4 k- {0 F1 G0 L3 y
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,( o+ e* ]& e) _3 s8 h+ I$ F% h
or execute SoftICE commands...
& q( S' p1 v$ W# hIt is also used to crash SoftICE and to force it to execute any commands9 X& A! P9 W* V4 K1 v' p6 G
(HBOOT...) :-((
) L- N: o2 j8 H6 T& V8 q# m% M) ?# X9 y3 L5 h$ X6 |6 ]
Here is a quick description:, O/ W$ E/ J1 y* z
-AX = 0910h (Display string in SIce windows)
6 N0 x, z Z+ S: v0 e w-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)' H, g: |* z8 Z$ L O+ Q, E
-AX = 0912h (Get breakpoint infos)0 s/ ]2 w4 G2 C5 \0 z; l' q4 \3 a/ U
-AX = 0913h (Set Sice breakpoints)
0 u( D- h7 w, L$ b) p-AX = 0914h (Remove SIce breakoints)& d! y% y8 ^. w8 B9 P3 i
; t6 w- q$ ]/ n" L" D2 F, [Each time you'll meet this trick, you'll see:$ V' b: H) Q6 D0 e) h! K, C( v g
-SI = 4647h
: F* I* w$ A4 L4 k-DI = 4A4Dh
( i- l4 z% X( R/ Z: a3 p! {Which are the 'magic values' used by SoftIce.
: c6 j9 u4 [3 L& v# oFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.5 I1 g/ m9 B4 X+ {" J2 R9 N
+ O8 t2 ~5 A4 k& t: yHere is one example from the file "Haspinst.exe" which is the dongle HASP
- [% o* r$ w: {( R- jEnvelope utility use to protect DOS applications:
2 M1 l7 L( G/ N7 [; X ^
& e; P# ]& g* T: f) I/ z
; K. `* E0 s6 t) L8 {; k$ R3 b4C19:0095 MOV AX,0911 ; execute command.6 S9 N+ K$ z9 i- U$ R9 Q" m
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
* ?2 ^$ F' u9 k( k7 H2 l- Y9 @2 J4C19:009A MOV SI,4647 ; 1st magic value.
% u* ]( M5 M. G( ]- ^% A4C19:009D MOV DI,4A4D ; 2nd magic value.1 o3 y6 l) B8 ?0 h
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)9 A+ X7 p9 r+ B( a: K# \
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
" B; n" {' T% `' b" b4C19:00A4 INC CX1 M: O |* Q$ h1 b6 i" w; y
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute0 O7 w$ a7 Q; R. p. N/ z* d
4C19:00A8 JB 0095 ; 6 different commands.
( C3 }4 k' M& A- R4C19:00AA JMP 0002 ; Bad_Guy jmp back.5 c/ C5 h. E% A+ l: y3 N
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
5 E) x3 Z/ }$ M# R7 s
. A; N4 g; Z& i# }1 E6 N% A3 \8 DThe program will execute 6 different SIce commands located at ds:dx, which' t" M" d7 V# i) g
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
/ V3 A8 B* y( G o A' q" [% Y/ P+ C$ q2 j
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.$ l: z A+ D, f6 {
___________________________________________________________________________
' I# b! a" [0 Q' q/ ]8 K$ A# W( z9 ~( _
# e* L" N$ c: w% g
# G" L+ H5 N8 u/ \Method 03
0 l1 S. _) L# F* s; _! u; h=========
! @4 R; j/ L4 Y4 a3 O/ B4 Q% Y+ `3 `* R9 e4 A
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
% H; _# S# `" E% ] u(API Get entry point)
, m- m: w% w8 I3 ~$ p ; W' w9 t4 M& A6 ~/ m
+ s6 B' A& C2 C4 b xor di,di
+ q5 l4 e6 O1 I4 y s' t mov es,di( k" V0 z" h2 o$ \" I
mov ax, 1684h
) z( T+ F5 b- t1 R mov bx, 0202h ; VxD ID of winice5 N I3 |( \/ h" {# @" m
int 2Fh8 a& T7 I' K5 I/ f, J
mov ax, es ; ES:DI -> VxD API entry point
- ?0 ?" {$ |% N, W add ax, di. f- d5 i* |( I& U' [+ ]
test ax,ax2 _* D$ B2 _1 l- Q% H1 ?9 ?! p
jnz SoftICE_Detected% z+ n7 q, x1 q( w# Z! j4 Q+ _
3 L6 {0 X6 @' G___________________________________________________________________________
& Q; G& c! d+ H! O, n
/ f; p9 P8 o9 m, h+ nMethod 04
6 A8 e: E4 _2 r6 v0 j=========
/ v1 d% q9 w6 u/ v* |) Y2 @. f% f% l% [
Method identical to the preceding one except that it seeks the ID of SoftICE2 z/ ?7 O; i) G! y$ a' ]
GFX VxD., k- \8 [9 m' u2 e$ o
9 u# u0 ~7 ^! C, g! u- E0 E
xor di,di/ g/ V- O. e& n/ S% @
mov es,di" G* ?& q" @2 L$ i3 x A
mov ax, 1684h r; Q% H% t2 h2 m* z
mov bx, 7a5Fh ; VxD ID of SIWVID
$ @$ t) x0 o9 l, |# L int 2fh& d3 @ x2 v( [
mov ax, es ; ES:DI -> VxD API entry point6 o4 k$ K4 H1 \4 z
add ax, di G% p5 K# i+ `, G
test ax,ax
5 |0 q% |; i; d# x0 c jnz SoftICE_Detected! v2 u+ X6 g6 A: C X1 o/ d
- N$ v4 c5 o, c3 }5 [' _8 p& F8 W
__________________________________________________________________________
8 o- c# c5 B1 v/ f! \. s* o8 ?( ~: ^' D
2 Q0 g3 P) Q2 b. P, \8 f1 ~8 _. Y4 m2 w* Q$ ]
Method 05
6 N c+ B" O3 o8 ?) B& ]$ D6 U=========
) L' h* }% Q) w2 w9 R; F
0 h) e! m M: X# ?3 iMethod seeking the 'magic number' 0F386h returned (in ax) by all system
8 k; y6 y* h0 hdebugger. It calls the int 41h, function 4Fh.9 o/ C( t3 k8 x2 r4 m. m6 u
There are several alternatives. ' z" X- [1 h" r
; w, Q" A: M8 `9 t2 H/ y
The following one is the simplest:
6 e) M7 _( ^5 R
7 s o" m. L- x2 u, `/ Z/ d) C mov ax,4fh
% P: z" P) t; v4 T' g$ | l4 O int 41h
$ K, i* \6 s. b cmp ax, 0F386" E! o# d; r6 \5 {1 x( e1 V0 k T5 o
jz SoftICE_detected7 f& V1 ~( e9 o- k9 O
# A9 ?+ y4 ~+ R) U1 t0 C( x% @% Z. B, @
Next method as well as the following one are 2 examples from Stone's 7 Q) r1 x' d' ]# T
"stn-wid.zip" (www.cracking.net):# a0 v6 ^, I1 g4 x7 N6 d. S# q5 O/ j j
( R! W7 {: z, n7 s4 } mov bx, cs
' w+ o, n S) d9 ]- F3 P, L lea dx, int41handler20 c3 Q" |. k0 O
xchg dx, es:[41h*4]
7 I! _, A- N* V+ p3 }5 n& Z3 L" U xchg bx, es:[41h*4+2]
2 ~+ V) N0 e' d1 L mov ax,4fh
. ?( \4 x4 L9 X3 h) } int 41h
9 Z k6 k( {4 @9 ~- Y' Y xchg dx, es:[41h*4]
3 \* a5 S- h0 `" A6 c xchg bx, es:[41h*4+2]" X. C2 G# Z0 b7 D( Z
cmp ax, 0f386h) [8 c6 w+ P1 u( F$ o
jz SoftICE_detected! ?" H: H5 ?4 c1 @
' }- g2 v L: D" w! C+ B9 Y' @+ i: n5 jint41handler2 PROC
3 v! ~8 c, d2 T/ k" U iret
6 u a. X0 `) L: r* [5 t/ U3 aint41handler2 ENDP
( @* j% x1 M- m" \: S X f2 @0 q3 v
; M* b5 B# q1 w7 n" e3 o5 N' G_________________________________________________________________________- O& r3 B' `! b4 w- W; y! `
2 @& O$ c) S$ Y1 X1 `& U$ E7 @3 t4 G) W/ a
Method 06
6 a0 {" n# i* J0 W* Z9 v( A0 t) T" G; E=========1 V$ X4 R/ q6 m( n$ V, S2 i) l
, x& P. [ f# O
4 y1 e A9 p5 V, K8 p2nd method similar to the preceding one but more difficult to detect:. [& N E" P W3 a. ]
8 F+ I8 O# T3 `: c# O2 R% q
( c" p4 u; a. I4 f* ?4 z( U' m9 Uint41handler PROC* D J' @9 V! U7 A" O; M. V
mov cl,al; h4 P: a6 N2 [( E, M4 X
iret& Z( W k/ G9 ]5 k2 H: u
int41handler ENDP! z; m1 y/ S1 I1 v4 {- ?8 [
( S$ z, a/ \1 @* ?# Y) r2 O, H% d1 p$ b/ P
xor ax,ax5 b+ ]0 J; w/ u7 c3 ]
mov es,ax
6 a" u9 M U: t* x( j& i) t+ C r mov bx, cs+ k0 y8 T, y3 _% v! `) l M
lea dx, int41handler( J1 f6 s4 W) g' J( {( }0 j& v, W# f+ p
xchg dx, es:[41h*4]6 i5 U! s0 n% y, a1 y6 k# o/ Q
xchg bx, es:[41h*4+2]
0 |& x; Z/ ? p' m; `7 t. p/ l in al, 40h" x9 P$ N1 a/ c% k9 A/ m8 R
xor cx,cx, e! A" w5 r7 ]
int 41h/ O2 N% D+ J, Q6 Q
xchg dx, es:[41h*4]
* R, k3 s, [& e& h% k, C- l# g xchg bx, es:[41h*4+2]/ N* R4 f) i' }1 r9 d5 H+ l
cmp cl,al
5 I; p! j4 G6 N+ I; N6 I jnz SoftICE_detected
$ m' c, ^+ P* J2 i/ o$ N: R
2 \3 j. L" K2 z5 h: @_________________________________________________________________________
2 ?+ B! \9 h+ M4 _! Z% \' r
. E8 B3 B U0 O" T% x! ]Method 07; I% [$ `" ^/ v% v5 S
=========
/ A1 R( s: F4 @$ `/ I* s
7 k2 E% \1 f7 b( E5 x$ Z4 G' X6 a4 Y: fMethod of detection of the WinICE handler in the int68h (V86)
6 j; s0 a/ m7 J. O _" v+ @& K- [- M5 c9 R! ]& J/ A
mov ah,43h( @ m. B+ h# @: F! t$ X9 r4 J* G
int 68h
) t, v y( W/ [# y cmp ax,0F386h
# j: w3 {1 V8 o. N jz SoftICE_Detected& S; _0 t) I" y, n+ R8 m! q' A1 ^
% P9 n# l, Y1 _* B3 P7 w K" n8 y
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
- |7 N3 m0 N8 {0 Z app like this:2 M0 C* ^: n* i
: l/ m2 y( K2 e6 f8 r BPX exec_int if ax==68
; E; i3 c1 b! X (function called is located at byte ptr [ebp+1Dh] and client eip is; v! @" E5 Y$ G
located at [ebp+48h] for 32Bit apps)
. ?7 l1 d- h: U% }& [__________________________________________________________________________: V; [# P5 e6 O L% @
7 B1 K4 G3 l. N8 n( \& E
& U; [/ U0 ~' |- s
Method 082 z9 J$ P4 ^# c: _7 k: I2 {
=========( a' V, ]3 K7 Z' t$ K, f
$ ~8 F5 R/ E) z% M
It is not a method of detection of SoftICE but a possibility to crash the9 f7 L9 o3 g! ]9 I; ?2 ], A
system by intercepting int 01h and int 03h and redirecting them to another
) P; M: d) B4 Y7 aroutine.1 X, D5 G0 l) Y7 S+ z; e8 j' Y
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points* h/ y6 C' x9 h# v
to the new routine to execute (hangs computer...)
1 j+ i+ ^, h8 h0 |- o; h- ]1 Z/ d. r* G' b- }& N0 L
mov ah, 25h1 C. x0 r# s, U" h" U
mov al, Int_Number (01h or 03h)
6 P/ k0 Z4 S# n( @, I mov dx, offset New_Int_Routine3 z& K* D7 i- N" j G
int 21h
4 w$ h% N) u- r+ q
& S# G. o1 g+ u4 s7 M( g__________________________________________________________________________
* `; [: Q( Y; R- x' L1 H. ?' f6 k1 _+ v4 o9 F7 [
Method 096 S) d% {5 O! V) E1 }" P
=========
# V9 z) c! K" k2 `3 q. C
4 K6 h. m1 [: ^$ |1 sThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only& C- b* b2 A* R8 g) P) A+ G
performed in ring0 (VxD or a ring3 app using the VxdCall).2 q- a* o8 R! g/ a$ Y! M4 Z
The Get_DDB service is used to determine whether or not a VxD is installed W+ u; s1 }0 X% f0 d4 C7 O
for the specified device and returns a Device Description Block (in ecx) for
. U4 M8 \3 }: T: x$ d1 Y" h* P4 zthat device if it is installed.9 e! a4 P0 F" \. M L
$ i& _5 g7 D& C/ f6 A mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID/ Q; Z: T8 _5 F3 ]+ p, C
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)2 I; M6 ]# F- K9 M: u! m- o; k! A+ x8 \" _
VMMCall Get_DDB' s3 H7 E4 N7 y( \8 ]) G4 ?
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed9 O9 z2 W( t6 [) ]
7 t# y! O. [* c+ j# B t
Note as well that you can easily detect this method with SoftICE:
. g7 |9 {0 L6 F9 } bpx Get_DDB if ax==0202 || ax==7a5fh
+ F2 X) U! ]. u' n* I3 I- v# h2 y K% ~1 U, h3 _
__________________________________________________________________________; s1 y- w9 [# X3 w7 [2 Y- @
[! A1 e3 n+ C* Q5 @Method 10, v9 |+ t' D/ [$ b8 ~$ z' a
=========: m; |6 `% n( R* ]3 i, p
/ m+ L/ x1 n7 o9 ?- f; |
=>Disable or clear breakpoints before using this feature. DO NOT trace with% b A6 v0 I1 W6 \+ F U1 Z( y
SoftICE while the option is enable!!' R- Y9 X- r1 X7 n
# H$ `, }$ J6 n1 {9 K: ]3 w5 MThis trick is very efficient:
1 i5 ^2 p6 G! s) yby checking the Debug Registers, you can detect if SoftICE is loaded
# l1 d1 o; m2 U* C( q( d i: T(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
3 J5 m, @+ ^4 ?4 g4 nthere are some memory breakpoints set (dr0 to dr3) simply by reading their
! P2 T6 m, F0 F7 \7 E7 |8 Nvalue (in ring0 only). Values can be manipulated and or changed as well' C* i) v. i' t. i" y- a# Y4 w
(clearing BPMs for instance)
/ E: A& R! u- i; N% j' X
1 a. _6 R, D5 ]0 U9 E4 p% C; G6 m__________________________________________________________________________8 u$ O$ L6 g/ _( O
/ M. v* M3 ]% n% iMethod 11# I6 }1 x% _5 M. m- L {0 b; m/ ^
=========
3 O( f# Y" _, p. e& `, R/ c2 u1 ]2 t7 x) E) J: _' u
This method is most known as 'MeltICE' because it has been freely distributed
! j8 y# k0 l0 G4 R6 kvia www.winfiles.com. However it was first used by NuMega people to allow- z& V5 U6 y( n O0 w
Symbol Loader to check if SoftICE was active or not (the code is located6 ^4 s- n: u" [* d1 m" s$ H0 C
inside nmtrans.dll)." ]6 P7 h8 [4 o; ]# p& F& d
6 k, F8 l8 L* C- `The way it works is very simple:3 _3 T" D3 e. W0 ?& J
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
8 }1 y0 c0 e" h& `* bWinNT) with the CreateFileA API.4 ?6 D$ i+ B2 h7 c) \2 {( \
8 a% }5 b0 t- D6 WHere is a sample (checking for 'SICE'):
' s& D$ T+ P$ _! o% f% y- |6 D5 p4 r" [
BOOL IsSoftIce95Loaded()5 s/ {6 [; G' a6 v' d0 @$ Q8 {
{ X6 p9 h' [# a2 h
HANDLE hFile; & G& P% t2 v8 r- s
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,9 f) ^) o" Y$ j+ U$ C3 M
FILE_SHARE_READ | FILE_SHARE_WRITE,
1 u* c" _% C9 j8 c+ N- H NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);7 k4 r2 }# y: r* }8 J
if( hFile != INVALID_HANDLE_VALUE )
& Z. S* `( @; y' ]' u \0 k' m {
2 N( e: Q" k/ J3 ] CloseHandle(hFile);
^" [' k o. R return TRUE;
5 {. ^% ?* Z b- ^- p! U }
H4 {, d3 V# n; C5 d return FALSE;+ j( ^. K5 z; C& {$ J
}) u1 G$ W" ?4 z, ^- Z% q2 S2 Q9 b% {- `
8 U8 G+ S0 B( K" R, f7 IAlthough this trick calls the CreateFileA function, don't even expect to be
( I$ D' j) M, [2 i) Nable to intercept it by installing a IFS hook: it will not work, no way!# v8 a+ B* _1 u8 F) @0 c8 c) |
In fact, after the call to CreateFileA it will get through VWIN32 0x001F# C. u+ m3 o% `' }' p6 ~
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function); U9 v! U) ^. k* E4 H! e
and then browse the DDB list until it find the VxD and its DDB_Control_Proc0 m# Z& T2 V; E7 O/ k6 R) N' U
field.1 d: b2 f9 j3 K, z7 D
In fact, its purpose is not to load/unload VxDs but only to send a " ^( Z9 ~; ^8 u0 r y
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE). i0 ~' Z- I) N3 k( O' p" A
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
* v7 D) p- t d! r8 ^7 ~to load/unload a non-dynamically loadable driver such as SoftICE ;-).
6 P( h4 P( M; Y6 V/ v$ F5 QIf the VxD is loaded, it will always clear eax and the Carry flag to allow" |, i5 n% O+ g. M7 f& a1 D
its handle to be opened and then, will be detected.. I" f" ~7 e, j9 R% E. f
You can check that simply by hooking Winice.exe control proc entry point
3 D2 s5 h7 d5 R8 \; |. Mwhile running MeltICE.
- q& L( L5 m2 Y- K Z0 g' j" _ d6 ? o/ a9 t
/ G3 `/ I% A: R: `" P- I& T4 r 00401067: push 00402025 ; \\.\SICE
6 N' Q7 |2 X; j' L 0040106C: call CreateFileA- Q/ v2 e1 @) e$ j1 N
00401071: cmp eax,-001& ~ j0 Y. }, l2 v" M; n2 d
00401074: je 00401091
$ c$ g9 H8 A# ~3 f- M8 T8 ]" a3 n: b A* d& \
1 z- s# B `* MThere could be hundreds of BPX you could use to detect this trick.
# R I/ X, n) i9 R* x: t9 u-The most classical one is:
/ F& V4 b5 l" S0 Q0 @8 p BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||) t8 X: |! ?" s' I1 l1 k
*(esp->4+4)=='NTIC'
# l1 ]+ A8 x: ?6 }: s+ e! q+ r) h i* _8 I, x6 |* N( `7 V% a
-The most exotic ones (could be very slooooow :-(7 }5 l" x$ ~* ^, G# h* K
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
) ~3 x8 p- t9 Q7 ]4 ] ;will break 3 times :-(8 e, G( u3 _0 b7 n; H1 g% O$ o9 o9 O9 r
& `3 d( A- [2 D8 T! U6 }
-or (a bit) faster:
+ n5 |. ]( b6 I) H% _ BPINT 30 if (*edi=='SICE' || *edi=='SIWV')5 v/ k7 l$ a7 L# d% N& A+ ~
& u6 J0 `- f0 S# z
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
- L( b9 f0 q+ D7 Y# i+ v: B2 [ ;will break 3 times :-(
; Q- u% z0 N# B4 ]9 w3 B$ d+ i' P* d1 S3 B6 w' h0 Z7 X! c7 e
-Much faster:2 ^7 E0 d8 J- X
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'2 R5 W9 ?/ C; T
. y" K/ F6 z- D4 P
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
" `8 q8 v2 Y5 M" Lfunction to do the same job:
, R4 i/ x+ B1 d8 q. N, u5 m/ o! @( r% r6 Q6 D9 t
push 00 ; OF_READ
, p6 k/ W* B9 r& d2 n mov eax,[00656634] ; '\\.\SICE',0
( O* {4 f; ] ?+ d push eax. j. d0 @; w4 @) y5 b
call KERNEL32!_lopen c( |- |7 P- E2 ]; V6 o% u J
inc eax
) W& b) O2 A( Z' p: z jnz 00650589 ; detected
2 l2 t- E5 i( N9 r5 W push 00 ; OF_READ3 _. r* p5 k7 {& V$ K w2 k
mov eax,[00656638] ; '\\.\SICE'
+ p/ C5 L. v; `1 Z6 V push eax; J5 I3 K6 ?5 q4 [
call KERNEL32!_lopen/ g! N' }$ o- q7 l; k- N4 r+ h J H
inc eax5 t+ s& h% \1 Y5 Q/ o; r
jz 006505ae ; not detected
( @$ _4 K" _& U0 i8 G6 D
9 U0 i' n6 L3 ^4 x/ S5 K [2 C
9 x: i( D$ _% h, T, ^% m4 r__________________________________________________________________________4 |: f; t6 O, ^$ y
' c+ f$ l& ]7 X) F
Method 12/ D9 ?! C; X/ ^$ u+ l& ?
=========' N! y$ a, M' v! Q
, V# L; f, H! X6 x6 e6 ?& dThis trick is similar to int41h/4fh Debugger installation check (code 05
& y, P& `- W% A3 l1 U6 J& 06) but very limited because it's only available for Win95/98 (not NT)6 h/ H5 p7 Q# d" n; I- i* M4 W
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.8 @% v- O* o( _- | x
! F/ P' r- g" j3 u push 0000004fh ; function 4fh
- g% Y5 z8 a6 L( v# u push 002a002ah ; high word specifies which VxD (VWIN32), l: f# W- M5 P( k( A6 G
; low word specifies which service
7 B. ^( q0 Q3 L! p' d9 E8 w: I (VWIN32_Int41Dispatch)9 i- g8 s* x; u+ q/ u- y& @7 [
call Kernel32!ORD_001 ; VxdCall u+ C/ n) _2 {+ `7 z2 S, m
cmp ax, 0f386h ; magic number returned by system debuggers
. g7 x4 D- A% p' Z; D) K( ~ jz SoftICE_detected
- ]' b: S h5 y
# X5 A! g. k* B' l3 ~8 B' _Here again, several ways to detect it:, {5 a2 G) { z) m0 e, \
5 Z* l; ^' O# u0 o8 Q1 e. o
BPINT 41 if ax==4f4 y9 e" t, k* O) E
( R7 Z- M4 L C, E' c3 j BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one$ k2 m0 w8 v, m' N- Z
' F$ N G+ B7 t9 Y1 k/ k U
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
, U) ?7 }, U- p6 R0 C$ @$ D% q: H4 | @7 v! i0 B, W
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!* j! D% W- w m, q' m* z# d6 R
" v; E4 k* \) k7 T
__________________________________________________________________________
g7 O1 Y1 U1 C |4 }
8 K) V8 P5 O, B" c4 j* xMethod 13+ j: G; L. q- \& I; Z* }' J/ u
=========
- b) P# h. L) A+ X% _
( I/ \: {. V" Z( s; j0 b- T" PNot a real method of detection, but a good way to know if SoftICE is
9 d2 d6 E0 I4 l, n' A% n* xinstalled on a computer and to locate its installation directory.
& N& m9 q2 Z M( Y) R+ TIt is used by few softs which access the following registry keys (usually #2) :- h0 a7 m% ^, l' p8 ~
% Z4 l7 N% N8 R' S) `
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 u* ?" L% J* B2 x
\Uninstall\SoftICE8 F8 Z6 \6 W9 ~5 D# p) K2 X
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE/ y% S# c3 u) `
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
# D$ M/ i5 i7 f* r; n$ Y" | \% Y\App Paths\Loader32.Exe
" C4 r9 z' @/ D9 Q9 g% D5 h: _, d# v J4 D
0 T& N; [( u8 m. [* {7 ?% BNote that some nasty apps could then erase all files from SoftICE directory
: ^+ `; F- H) X$ g; s(I faced that once :-(8 J$ E- A4 J& Q( f
' G4 @5 M v2 d$ i* s
Useful breakpoint to detect it:, s4 a5 J b2 ]7 S( \( m5 e4 j
# _5 Q9 b- A, g5 _8 V
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
5 y4 Q& ?1 s. }7 G2 G5 h5 T' u4 v, F7 x; f
__________________________________________________________________________1 Y3 ]/ @4 v8 M' f
* L7 O8 Y7 f4 @% V0 [; W
9 [ g9 M) i" f2 i3 |+ S6 c
Method 14
2 Z7 u/ o" N* W+ c=========' E4 l& E. x6 F) n
3 @# e6 G" k+ h" K( \7 MA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
+ i" Y5 g6 d4 ?4 v* Dis to determines whether a debugger is running on your system (ring0 only).( D/ U: X. O3 I4 J: v; g
( | m; ~ |9 g6 ^: P" @9 x VMMCall Test_Debug_Installed* o9 G9 L: Y) { I3 C9 z# ~
je not_installed
9 P) s- `+ {2 T( i% K7 z6 V
9 Y- k! E- B2 c! V/ DThis service just checks a flag.3 X, `2 p. ]/ j, j, f. ^9 G4 a" {
</PRE></TD></TR></TBODY></TABLE> |