<TABLE width=500>
8 j8 X$ A8 l8 P7 p6 S1 c$ _; f<TBODY>* a3 ]- L0 L7 Z# [" O( R
<TR>' }$ E' i/ f" @7 \
<TD><PRE>Method 01
7 U; D3 l, t& [& x=========
1 A8 e: b7 J' L5 I9 H4 z @ r# F0 |& W1 X
This method of detection of SoftICE (as well as the following one) is
0 I$ O; q3 O) g rused by the majority of packers/encryptors found on Internet.
1 Z: E6 X, J/ S0 B0 \, jIt seeks the signature of BoundsChecker in SoftICE9 g# B' @. |( x r3 E6 S+ P5 V
# {3 T! E9 a% q1 A7 T4 J0 q6 q4 t
mov ebp, 04243484Bh ; 'BCHK'
, o* W9 n1 i9 Q: [: j- h6 ^6 Z9 E$ { mov ax, 04h! U; C. Q% j( c4 ~
int 3 1 a2 w% T! E" H+ c: L5 K
cmp al,4
5 m+ T. h, n2 s F' v jnz SoftICE_Detected# ^0 D$ f6 I# S
! q8 G9 G: W. T3 {___________________________________________________________________________
; G2 [% x" U+ Z0 M# u- R* Y# U3 U6 M0 j$ x. a0 ?; ^8 b
Method 02' x! J7 ?& U7 H
=========: `2 u1 G/ ?4 }; E7 Z1 B/ y
e( o5 J# l: `7 Y0 n# h
Still a method very much used (perhaps the most frequent one). It is used
9 A( C' K! n/ ]/ [1 J- d2 Ato get SoftICE 'Back Door commands' which gives infos on Breakpoints,0 {9 ]+ H: S o, d: b
or execute SoftICE commands...$ b3 `$ g- m; }3 H- |8 q, U
It is also used to crash SoftICE and to force it to execute any commands
3 x9 e& X. u8 ^0 u; v(HBOOT...) :-(( ! Y: a& J7 [; g# W/ ^( V
2 {0 C1 _3 R# i' v3 r9 g
Here is a quick description:' c6 f8 U& ^, |! G" Y
-AX = 0910h (Display string in SIce windows)' q9 W0 h) W1 Z8 b# ~
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
+ J: h5 w5 q* C2 x-AX = 0912h (Get breakpoint infos)
& b( ~; g9 d. J5 i: p-AX = 0913h (Set Sice breakpoints)4 w6 j- U$ s. \* R5 l* e
-AX = 0914h (Remove SIce breakoints)7 s. w/ R* W" Y3 L% P4 E' j7 z
1 T$ G- W- t: l6 XEach time you'll meet this trick, you'll see:+ C. p% f$ f3 v% Q R0 Q6 M
-SI = 4647h
. a% s: W+ T# m& ]-DI = 4A4Dh7 `$ w4 c+ b" v# `
Which are the 'magic values' used by SoftIce.+ ^1 y2 k9 x# ?) N3 ?
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
% J" ~. ^0 K2 {7 F( i
% t/ Y: U/ B1 Y9 b" K8 h7 zHere is one example from the file "Haspinst.exe" which is the dongle HASP) q( ^' c2 i) f6 _
Envelope utility use to protect DOS applications:) l/ |8 O0 p( o( Y# @- x6 \
1 L* m) M0 w1 p2 u
: Q3 o7 {% I; X' D" y
4C19:0095 MOV AX,0911 ; execute command.* U$ D3 Y, P' G+ p/ y2 |4 t
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
+ I" A7 L4 I) A- p4C19:009A MOV SI,4647 ; 1st magic value.
w+ v; \/ ?/ H$ d( _3 V4C19:009D MOV DI,4A4D ; 2nd magic value.8 Q, x& C e! R
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)* \5 S: r4 Q) `
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
/ S% H; C: m$ q9 I* A4C19:00A4 INC CX( J/ @5 o3 |8 ^2 N* O) z7 b9 Z
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
0 v! d* p) l/ n, W& g' ^; U4C19:00A8 JB 0095 ; 6 different commands.
5 ~" q+ r) V4 ^! R3 ~& U, A! S0 N4C19:00AA JMP 0002 ; Bad_Guy jmp back.
0 @0 e" G+ e5 @ d4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
- |0 j6 i; K. [5 ?. Y7 K
( e) ^/ s2 s3 F3 d' ?The program will execute 6 different SIce commands located at ds:dx, which
/ g6 A8 a( B/ U' b9 Xare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
) R9 V8 I9 f4 o" \) d
) w9 i, m9 a+ x1 r- O5 S" g* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
. b g q# z5 D. I: X___________________________________________________________________________ m, I: g6 v e2 S
1 o" S# F7 B8 Y1 l' x
: _, t! O+ q, ?' n9 [
Method 03
8 F4 ^5 k5 W. d" G6 c! k=========
5 P5 }# D x/ n$ ~. j3 w
E \* j5 p* O o0 dLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h" j9 |+ x7 Z6 c' d! ]' U) g
(API Get entry point)* w8 ~$ Z# [/ \
8 X2 N- W) ~5 A6 P
5 g; P( M" D5 Y) y5 L xor di,di
! e4 z& P* i7 N$ k8 z1 R. D* W mov es,di" v$ ]5 l9 q3 L' }) Z& J
mov ax, 1684h
/ e3 T* U+ _, i mov bx, 0202h ; VxD ID of winice
0 E0 e9 ^2 ^5 j- Q/ d' @ int 2Fh" X& i; P" f( k$ b5 I
mov ax, es ; ES:DI -> VxD API entry point
Q) j& M1 ]7 w, { H add ax, di' C/ v2 ]# v4 x7 s% r& Y% u
test ax,ax- d, x$ S, `0 u" y6 e- X2 f: {& L
jnz SoftICE_Detected7 [) a7 @3 o( y) K* C( f$ a( _: q
2 N; T+ r* r: B/ G___________________________________________________________________________3 S! F1 v- d0 ^% a- D% K. [
- J( U1 P, t5 B& g9 }
Method 04
& w# Y$ P' P: A* j- D2 ?+ `=========
9 \# t5 w6 ~. f! ]# e$ T. p9 ^* d( F/ F5 b9 L7 Y
Method identical to the preceding one except that it seeks the ID of SoftICE
, R0 O! h' z$ XGFX VxD.) n. h) w% O- ?8 u
) }* D7 A' S. a! a# `) Y xor di,di
; H6 t8 y- k0 S, h mov es,di
/ U4 I9 G( Y( O! i' M* x+ m mov ax, 1684h 1 g7 X" U. t" \ t+ z! _1 W
mov bx, 7a5Fh ; VxD ID of SIWVID
; A9 E" B- Q& f0 y5 I" S$ k5 X0 b int 2fh
) g) _+ b3 A l mov ax, es ; ES:DI -> VxD API entry point
% V* K* `7 ~! e4 F. e add ax, di
9 M I9 O( w( v3 r. o; g test ax,ax1 t- }1 Z$ [3 C! l8 `+ v7 T
jnz SoftICE_Detected: E0 C7 L0 v" i2 H
/ h/ Q* s* q' l2 s+ n& o( O
__________________________________________________________________________
2 ~5 N' M* f8 j( }
6 U$ I q7 U. ?% d' A* ^6 O8 z: R
Method 05$ r4 e8 r( d0 w7 ]: s, A
=========
5 }' T+ {& H' a! q+ b
8 M. O# @) {! A2 {/ PMethod seeking the 'magic number' 0F386h returned (in ax) by all system
3 e% @4 X: x" a# Z9 ?debugger. It calls the int 41h, function 4Fh.7 g5 e, C( p; l4 m" O1 C
There are several alternatives.
2 s6 |& A1 R7 i7 T- ?$ g) Y: F1 b) ~
The following one is the simplest:9 {8 z) N0 |; c1 {. G
3 X& v1 i4 P$ W2 d3 x
mov ax,4fh, ^: G! Y9 t% E6 B) m1 P& |! V
int 41h" A2 i% g! \2 F0 S8 ^
cmp ax, 0F3863 m4 a t' V5 k( B* {1 @8 G+ Z
jz SoftICE_detected( ?4 |$ l- C( A9 O5 h3 S
S- I9 f9 v" P( j- f/ M1 @* W4 q
/ U9 ?+ \: X: H) A3 a: r; TNext method as well as the following one are 2 examples from Stone's
) D6 T8 M) {. U% c6 j"stn-wid.zip" (www.cracking.net):
: M6 R/ Z: Y! `; ]6 |" h: W/ i+ `! X7 l* @. I/ g" I+ o
mov bx, cs
/ y9 F( f6 \& j2 x+ \$ A6 } lea dx, int41handler2
b$ n) ]; C' M& N0 N D xchg dx, es:[41h*4]- S2 N. w- }0 P; l! u, L1 z( _
xchg bx, es:[41h*4+2]
) Z( V, h! Y: Y0 L mov ax,4fh
$ n! A: k" q. M% y int 41h5 K- ]# G( N9 h2 a
xchg dx, es:[41h*4]
* V' u" z" }$ e$ p+ |8 Q9 r, C xchg bx, es:[41h*4+2]
% a# p B* V# @! I( H cmp ax, 0f386h& y8 @7 V0 V! h$ u% m
jz SoftICE_detected
2 E3 t: T+ v2 \/ H, J2 P2 B
. j2 W0 o4 V! Y. f% S6 _3 rint41handler2 PROC
& i7 }% x% O0 d/ o7 a8 t3 V- v) e iret' O! A r, H, Q' a: d+ Y; E
int41handler2 ENDP8 q8 V% V, F& [* j9 P
( h7 y7 d6 Q l3 ~6 H1 ]4 H9 d0 d8 C. P1 K5 P
_________________________________________________________________________
* d; r! k9 A" `* o
3 b i7 l$ S1 l
' q2 p. W9 \& O8 u, zMethod 06( L2 O* H0 E2 U6 x( V
=========
9 p) Q8 }) D' X5 Z! {7 @" O
u1 S" E. e, i8 ?2 A( _
; w' [6 p8 Z. k2nd method similar to the preceding one but more difficult to detect:: r. i% ? _% r S/ u
' n( y, ]; |* Z5 X) Q: }$ h2 a/ y& a( w6 g2 p8 ~
int41handler PROC* Y7 b' ^. u3 Y
mov cl,al; `5 P) \5 `# C* z( O0 ~( {% \
iret! `- H4 \4 O0 i0 R# ]( u
int41handler ENDP
+ z2 C# L& |1 p) Z# R
i! g5 B9 k+ c( z
! Z+ Z( C8 D2 T) f, s7 \ xor ax,ax
j* N @+ |& T ?. r, _! O mov es,ax
) h& d0 J6 ]- _8 p5 z4 ^ mov bx, cs! a8 f' ?7 l: ^# \0 P
lea dx, int41handler
' g F B, f7 ^: e xchg dx, es:[41h*4]9 ]7 j: r0 J; q3 {& I- T
xchg bx, es:[41h*4+2]
; X0 r+ z0 r# B. C; d in al, 40h3 E$ y$ }5 s/ j. r/ @; B! B' |
xor cx,cx/ b/ ^; F2 ^$ `; o& v; P" V/ f
int 41h
/ }" v, |9 ?2 C @: l$ [ xchg dx, es:[41h*4]" p! \* ^- v/ B. H* y
xchg bx, es:[41h*4+2]. m6 T% ]9 D/ s" M9 O
cmp cl,al
/ D8 O8 i6 S+ N6 i, T: D jnz SoftICE_detected) M! o: }8 l$ @% ]4 x
2 e2 H3 ^" n3 V+ F* u8 F2 k X+ }_________________________________________________________________________1 q8 E5 r' k8 H9 h! i7 T$ k' l! J* r
; q' a* s1 L' j0 n* B. t. JMethod 07
+ o/ P X) {8 o! t$ N9 I=========$ p& o& N, a- g" f9 R7 a
~! l- o- f; b9 ?Method of detection of the WinICE handler in the int68h (V86)
( _4 G0 n7 `# B4 q
& K2 h9 G. I; A8 a3 X mov ah,43h
! Q2 x$ j5 B m5 s' R# k2 d int 68h4 ^( ^1 v7 R$ A
cmp ax,0F386h' z. K! b% M- W2 h% _5 V
jz SoftICE_Detected2 }* Q, ?! w e1 g, q
+ p8 N; z; Q3 e' h @9 e8 y2 Y3 Z6 Y! \, a# I/ c
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
/ f# ^! c. ^$ ?: V2 J4 x9 V app like this:2 Y4 E# C5 p& E$ D
G0 ^3 T$ [8 f3 |! w" A, S% J BPX exec_int if ax==68
) d# z) n; k+ S0 _) q+ F$ T- G (function called is located at byte ptr [ebp+1Dh] and client eip is8 e1 F3 ]; k4 p
located at [ebp+48h] for 32Bit apps)
- [+ M& L& t; i' N: |% F) V5 L__________________________________________________________________________
& I8 H5 ^2 O0 q- M4 F5 d+ _( z/ A1 L) N5 g; S/ S0 ^4 ^" w; |
3 @2 D% Q, \/ ]Method 083 R/ ?- A9 G- Z6 _
=========4 u+ i3 b6 g. q. A# K
" N! W* \ d5 k9 [1 K+ \
It is not a method of detection of SoftICE but a possibility to crash the+ S- y8 B) ]" W" }/ a
system by intercepting int 01h and int 03h and redirecting them to another
* J* O+ ?3 x) ~5 [" c* r( i' ^routine.4 k4 m$ O8 r. }9 U* H0 ?
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
. l' ^+ V4 D8 o$ G6 l! hto the new routine to execute (hangs computer...)
" K: t$ T3 x8 h* A" N7 p) Z& W' N! n4 g7 S, a1 W
mov ah, 25h+ `: B! I7 o8 t0 J
mov al, Int_Number (01h or 03h)# n ~* e8 G! S! J
mov dx, offset New_Int_Routine
/ _, @* {( b+ @! ]% f int 21h; h+ ?8 M/ I' x3 ?; P5 d6 F B
8 \$ L2 i1 b6 i( ~- P. ~. c__________________________________________________________________________
1 B0 w: U, B6 Z7 @
/ f* m( _/ H) [( P7 M( HMethod 09
) S& S5 N0 \4 l: N. n9 G/ a+ x1 r+ G=========. _6 {" }; [# z( N+ X, z
; o+ d' I( i% z# z7 b1 x7 o) B
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only7 L' a/ L+ n: E" J9 g
performed in ring0 (VxD or a ring3 app using the VxdCall).
; [+ Q& I7 h% M$ y; N$ tThe Get_DDB service is used to determine whether or not a VxD is installed8 b+ P- S* a4 i2 V) ^0 j( Y
for the specified device and returns a Device Description Block (in ecx) for
6 }. H( x: N2 j* C/ O0 L( l" d, nthat device if it is installed./ p e% p! Y+ H
- Q0 U7 W5 {0 o. g E& L( d; q mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID: a' q& ?0 N/ @9 q. e1 P
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
$ w- H: s8 p0 G VMMCall Get_DDB
" R9 d6 k5 c" a J( |( }5 \- w& ~ mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed; \1 e# o2 N4 b8 t' e
. o; `; B+ D5 X1 ~: ^Note as well that you can easily detect this method with SoftICE:" \- B4 e8 \1 t8 l ^
bpx Get_DDB if ax==0202 || ax==7a5fh
; B* n! m' p3 s9 {; k. `
( F4 _8 F* K$ j4 e: {8 a! L* _, t__________________________________________________________________________
1 Z6 R3 I. J4 _5 [
8 h9 w" H" L0 r0 D( L! l9 \Method 10
3 c( u5 A% h+ y=========
Y2 O) A- f/ p. a: n- x
l" ]5 m/ I9 v" |6 @; K=>Disable or clear breakpoints before using this feature. DO NOT trace with
1 z/ a8 `; k1 l SoftICE while the option is enable!!
4 @3 l' Q- u' e0 W2 {9 Z( U1 T. \3 p
This trick is very efficient:
" t; C) z7 Z8 E1 [by checking the Debug Registers, you can detect if SoftICE is loaded1 m+ a2 q- v4 K3 `2 m5 F6 ^6 f
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if8 f1 A, b! I7 |
there are some memory breakpoints set (dr0 to dr3) simply by reading their; b6 h. O0 F3 I4 M. {. ?9 x- S {$ y& P
value (in ring0 only). Values can be manipulated and or changed as well
# p- p/ S% g f' f% L5 n4 X* `5 I(clearing BPMs for instance)
/ s0 j' U; S8 h) d+ O) H S$ i- f( E5 K- L4 j9 j
__________________________________________________________________________( x$ N6 P) J' Q$ I4 H
; M. R X/ S- c/ Z! x( C7 f4 B% f4 AMethod 11/ T: i8 `6 u. c/ \" Q- @
=========
( R" {2 P5 G$ x! T# ?% o
7 I7 O) T% `8 E! BThis method is most known as 'MeltICE' because it has been freely distributed
/ L0 Y% J% C6 H$ {2 e1 bvia www.winfiles.com. However it was first used by NuMega people to allow
/ U g# g; ^( T! i; pSymbol Loader to check if SoftICE was active or not (the code is located4 p' u! w9 J: l5 J3 L& L& b. E- I
inside nmtrans.dll).) Z% D( P) Y* N; c% i5 X
0 U$ l8 c- t7 B& c; p6 c- ?The way it works is very simple:3 }3 j1 O" a0 d# t5 L6 I* @
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for! M3 R% V, x( B& g' i
WinNT) with the CreateFileA API.
& E9 f: u* f/ k4 M4 p8 l$ `9 X$ h e" X7 x$ Q3 ~8 K- T
Here is a sample (checking for 'SICE'):
* S$ o% l6 G) c7 K9 R/ z5 ~2 D# b' ~6 l0 D& E/ q& W$ a7 N7 M6 }# F
BOOL IsSoftIce95Loaded()3 |9 ?! W/ [1 F9 w* w- F7 }* r
{% S8 V- A5 l3 T, m
HANDLE hFile;
; M4 F1 _( C4 V1 p; \1 G hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
6 B; Z# h4 O ], S$ ] FILE_SHARE_READ | FILE_SHARE_WRITE,) t, o/ x6 ?+ n& K
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
R7 D( i: E' c R4 R7 D9 g% [ if( hFile != INVALID_HANDLE_VALUE ) e* L6 y, P" f) }8 w7 s1 T
{; A! n$ J2 W9 o3 w$ I7 x
CloseHandle(hFile);
" Q) j6 o0 @7 n" x; z3 ~; M/ F9 ?0 T return TRUE;
+ f# a; w, I& ^/ b1 @' W }, e* E; D1 k v- y) J# b8 V
return FALSE;( p* U! ?9 H+ `: p3 j: `
}
# m) W% K5 ]2 H. q7 O" u
7 w7 R! ]8 P O0 t, b0 k+ w& D# EAlthough this trick calls the CreateFileA function, don't even expect to be. H4 \* V9 g0 L# T X/ `
able to intercept it by installing a IFS hook: it will not work, no way!
) T& k' ?& @( E+ o% _In fact, after the call to CreateFileA it will get through VWIN32 0x001F3 G8 R+ G4 f- g; `* T
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)$ @, C" L9 U1 V2 q" Q8 o6 A
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
) {7 X# B0 J9 ?; E7 Rfield.$ t6 M1 D' t$ k
In fact, its purpose is not to load/unload VxDs but only to send a / V5 }: m4 }6 v
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
- J0 H; s. N- U8 |/ a" p, O) T: f0 sto the VxD Control_Dispatch proc (how the hell a shareware soft could try; K9 Y, n, D2 `
to load/unload a non-dynamically loadable driver such as SoftICE ;-).! Z9 r$ u2 Z2 |. Q
If the VxD is loaded, it will always clear eax and the Carry flag to allow* Z# D1 ~! I, I2 N2 w3 S1 ]
its handle to be opened and then, will be detected.9 N) S+ v( a5 f5 Q) a. a' O$ G U
You can check that simply by hooking Winice.exe control proc entry point
/ h, K+ F) N, u, t5 ]1 Hwhile running MeltICE.
7 _( l6 T$ v& L: _
& @# x a+ b: Z' z. v' m l2 G, c
00401067: push 00402025 ; \\.\SICE: h) P+ E' Q' K! q- y4 F
0040106C: call CreateFileA N! H' r7 ?) f$ ]/ P+ Y# T
00401071: cmp eax,-001: ]2 l5 E, Z4 J4 `+ t6 W& F
00401074: je 00401091
" J0 y, I: B$ c) P# |! Y8 ~- l
8 c) H: z. `2 o1 E6 T7 }6 Z, v% R! y+ ~/ S n
There could be hundreds of BPX you could use to detect this trick.+ \! u) X4 y3 K/ n `
-The most classical one is:
# I4 a' s$ ~3 ^$ \3 u3 D7 R BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
9 G/ C3 m" r) [( m# @, ~9 [/ }$ [" Z *(esp->4+4)=='NTIC'3 Q) {( P! M+ e7 v5 b6 S
" s" T) j; \: p
-The most exotic ones (could be very slooooow :-(
6 K( i& d& i$ J+ O BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 7 O" [4 | t) m) |5 B7 w5 G
;will break 3 times :-(
0 H( |5 W+ b. V4 R6 I
, F" p1 w- N, k1 p a, |4 x7 t% Q! {5 ^* S-or (a bit) faster:
. I2 ]4 W: y: s7 W$ ] BPINT 30 if (*edi=='SICE' || *edi=='SIWV')# @& t* U; L* O6 g
% P/ c) d% G6 w/ [& q1 L: B, m BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
* Q* e( U) X2 W& u+ g ;will break 3 times :-(
, l3 M. o- z' o. A4 Z" ~
! I- ~- K& n) l* C-Much faster:
0 q/ d% K! W9 ~ BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
0 O3 F2 M, K% u4 L( _! m- k: f J; `
+ ^( h6 f7 j; k8 C* v" ~1 lNote also that some programs (like AZPR3.00) use de old 16-bit _lopen7 l, ~& {" n, Z! {
function to do the same job:4 _7 v/ P% k" B) T( i$ Q( f
1 |: l8 B5 q6 F H
push 00 ; OF_READ# w8 \. S( [; S+ m8 I+ B
mov eax,[00656634] ; '\\.\SICE',0
3 V7 j, N) C/ l$ r push eax$ s4 g$ \4 ]2 J: b2 I+ l) a& v
call KERNEL32!_lopen
0 p3 M0 O9 R8 v0 m0 O: t+ E- I inc eax
% g1 T/ n# @! i$ s5 \. X jnz 00650589 ; detected
: L% ~1 T) Y$ {( b push 00 ; OF_READ
- p5 ^0 v. `& U& K% s1 I mov eax,[00656638] ; '\\.\SICE'
& F* d8 {0 ?/ I& U push eax; N% }2 l1 Z+ S: e% ?& s5 A1 n! `
call KERNEL32!_lopen( R, k% X; @2 ~; E; ]! H2 r1 A
inc eax; O8 q- |& \) ]' m4 \
jz 006505ae ; not detected
9 D# z) o" ^( T$ P: h6 q8 K7 R- w. P" j$ A5 O! B1 e6 R7 j
# [. J; U. H* Y1 C4 W8 G- g. Z, N__________________________________________________________________________7 ~$ ?0 k$ Z; X9 z6 f, l
' I) X1 _% b. y/ IMethod 12
1 Y0 W9 R, O$ X& ^! z=========
1 k: j, i0 J* b- X: _6 Y: k, l1 c; D& U# _/ T) D
This trick is similar to int41h/4fh Debugger installation check (code 05
9 N: @; A5 V; ~" l& `) w. L& 06) but very limited because it's only available for Win95/98 (not NT)
0 f; a; _4 A. F( s/ Pas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
. Z$ y: F' d8 n2 u( _3 c: T/ d. K/ W% W
push 0000004fh ; function 4fh
3 v, u) y2 g0 Q* y# J push 002a002ah ; high word specifies which VxD (VWIN32)
% ~) M' b$ b6 _! N; h$ f1 { ; low word specifies which service
4 F) o# b+ Q6 \4 Q' t$ D (VWIN32_Int41Dispatch)
l( b+ h" u9 e2 M' [; Q) z6 w call Kernel32!ORD_001 ; VxdCall
8 ` n' ?% O* i$ P" {% j* c( ^+ n cmp ax, 0f386h ; magic number returned by system debuggers
3 N: k& [% ^: y/ S/ a2 n4 O jz SoftICE_detected$ i0 t1 V( s, D0 q( t
# R# c9 e* _/ O+ ] x
Here again, several ways to detect it:
6 ~% ^4 y; K6 B$ E" B" u% _7 d
j/ U7 `% A& v, K7 w3 q' P BPINT 41 if ax==4f
! h/ L: N3 S+ d' Y& ?
2 u/ |7 J b5 {4 D BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
6 ?7 {) t6 V& m! Y5 I2 B
: H6 l) g2 u% N2 U( ]8 T \ BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
: i) u# q5 o7 z* @
! ]" U; r/ n& ] BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!" |8 ]/ G6 r1 H3 \9 F$ E/ o
3 v+ ]% e# J" |: f# _/ i( W
__________________________________________________________________________1 X( [) n. z" N7 ~
8 Y: \" ]- M, h& [" O
Method 13
7 P! S) ^: R L# U1 }. c$ }- Y=========
' f3 a u/ Z& ]8 q/ R
- M z1 ~9 L) l- G. ONot a real method of detection, but a good way to know if SoftICE is+ v- @2 h5 _6 M
installed on a computer and to locate its installation directory.
% V$ z( a! `+ M' B4 MIt is used by few softs which access the following registry keys (usually #2) :
/ |* _- U1 \; O& [7 x: N5 v5 Y2 N- J/ p, }
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
, O- N5 d: u7 @6 X4 y# `- Y\Uninstall\SoftICE
+ c" D! w2 O- u! S; l( J8 X6 c-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE1 y+ l" g; O; H$ A( B; J; y; N' V
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion! b8 T+ \0 e4 M3 t/ y% M( d3 j
\App Paths\Loader32.Exe! n" a+ C# Q' Q" P$ [
Y* y7 p$ H" B0 g0 O, z) q) c" j" }- {: _2 V% [- P
Note that some nasty apps could then erase all files from SoftICE directory* y, O; U+ p$ u$ Y2 o4 H
(I faced that once :-(
# L" F. e8 b3 j& r0 C; i- E7 s$ }4 u. q- ?$ C5 E
Useful breakpoint to detect it:# W+ s6 F; j9 a/ j0 r
9 T7 F- g3 Q! f7 s" B BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'1 k6 U. I1 H, \5 U- r
( {$ p. _0 r/ A
__________________________________________________________________________
( @$ E! k6 l S6 P% P3 Y
3 T8 `4 I7 p7 @* x
1 P/ E( I, b5 o# n, fMethod 14
6 p( e. L' ^/ M; O=========
& ^2 P5 [8 X" r [; h$ [
* [2 i. i. v4 N6 P1 a) wA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose, t/ P' M4 ?$ A
is to determines whether a debugger is running on your system (ring0 only).
9 p2 B. c$ Y* m1 f
% n$ Q" t* ?0 S' r& ?0 l( [ VMMCall Test_Debug_Installed; [) `2 T9 _( F& Q
je not_installed3 {$ `2 v- q" X: u1 f
x, \. \4 ~1 E% p8 pThis service just checks a flag.
$ c8 |1 ^/ w; ?, q8 |6 f</PRE></TD></TR></TBODY></TABLE> |