<TABLE width=500>, {. V) x0 j4 o F$ v& C
<TBODY>) u! d6 ~1 ^; p6 a
<TR>
$ b. F$ Y" B8 I9 V, h0 C<TD><PRE>Method 01 + [, V% c Y! w9 o+ A( B J
=========
# g. Y$ Q" O0 s# D8 k
; S6 ]( F3 _# p5 \This method of detection of SoftICE (as well as the following one) is
) W4 }7 e5 i ^* Rused by the majority of packers/encryptors found on Internet.8 h6 g) r# Y8 b+ E
It seeks the signature of BoundsChecker in SoftICE/ T# r1 d7 h0 _% m& K/ v8 F. G% F
# N9 }' L/ ~: f
mov ebp, 04243484Bh ; 'BCHK'! @; m& N5 Y: X5 [; ]7 i
mov ax, 04h0 B. S' v/ @' j
int 3 & n+ F' T8 `$ ~ L2 a2 r; v
cmp al,4( y$ H+ d6 s! q% n& Q0 \7 t
jnz SoftICE_Detected
+ g* P4 B' }7 r. Y0 z% g7 D; A( ?
5 G- ?* k5 l2 Y' r8 ^___________________________________________________________________________* Z0 A% ?3 o% U$ H: \
. s1 C" m* i4 f, j
Method 02
3 x7 c1 u/ J! v5 h=========
/ r0 o" \/ t1 o
1 J0 n: f1 R3 F, n5 j/ YStill a method very much used (perhaps the most frequent one). It is used
( {* V: ? t1 a ?% J/ cto get SoftICE 'Back Door commands' which gives infos on Breakpoints,+ M* b L) T, ~, W+ A3 f* }
or execute SoftICE commands...6 [* R8 ]+ ~9 K% s9 [4 U' L
It is also used to crash SoftICE and to force it to execute any commands
0 g7 O: R( E0 \$ B9 T(HBOOT...) :-(( 7 ^' \2 C6 O8 i- U+ J# V
4 E, g1 T& c) A# {) @$ e
Here is a quick description:
0 B& y0 J9 r v1 l* }7 A8 I-AX = 0910h (Display string in SIce windows)( r+ S8 R" ?! m; J% n6 Z5 ~
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
0 R/ B% a. J5 ?) N/ P8 S' K-AX = 0912h (Get breakpoint infos)
9 K+ s" K5 C% n# ?) H) W3 ^-AX = 0913h (Set Sice breakpoints)
4 l, c! Q$ r: k2 E-AX = 0914h (Remove SIce breakoints)
/ `3 d7 V; o: h6 S) o+ W/ i1 m4 n( I' @
Each time you'll meet this trick, you'll see:
' X9 B5 p4 N3 m-SI = 4647h5 k7 w- d e; O$ _1 y
-DI = 4A4Dh
J% z: x4 d' d& J! l5 L" z. M2 ZWhich are the 'magic values' used by SoftIce.6 ]' u3 g9 [) O( ]! |+ Y
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.3 v8 _% I% g: p( f
( e% p8 q7 j6 U3 b! E
Here is one example from the file "Haspinst.exe" which is the dongle HASP& ]' j5 c* |0 C. C, c3 _
Envelope utility use to protect DOS applications:
0 A# @) R& {& I- r! c& f) @( o g" _& v5 D: s
* ]! Q; o% @7 Q7 P3 D3 \4C19:0095 MOV AX,0911 ; execute command.' g4 i8 s$ s' F7 \1 J& H6 b
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
0 x9 V* Q7 C v0 c0 W4C19:009A MOV SI,4647 ; 1st magic value.- \$ Z( {# ]' d3 E" e
4C19:009D MOV DI,4A4D ; 2nd magic value.7 E- H: ^# I) S# U- k5 u. E/ U8 s/ Q
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
& R6 Z5 y7 E# o+ F8 A; e4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
/ I4 d+ s' W- F4C19:00A4 INC CX, i% V5 i& L( B+ D
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute( j; [* d6 b- {0 _# D
4C19:00A8 JB 0095 ; 6 different commands.
. t' [ o' U& ~3 s: f. d$ d4C19:00AA JMP 0002 ; Bad_Guy jmp back.
) x1 K; `+ ^, k4C19:00AD MOV BX,SP ; Good_Guy go ahead :)4 c D& l& I0 h h# e
# C0 w4 c5 x4 Z& c" A2 I
The program will execute 6 different SIce commands located at ds:dx, which0 x) L4 P6 ^: w5 z
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.# `$ T$ }! H6 l' Q: b$ c
' o8 @4 P4 U! W- a
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.! n* g7 z; w/ b: J$ |
___________________________________________________________________________7 t: t7 p& P0 c4 g+ l0 h6 k
, T) p7 p- b* P$ ?! o
( g0 P, Q; ^. Q6 B/ J# GMethod 03/ [6 ?9 O& Y, O2 ?: ]( P5 C: t7 ]
=========
% g3 ]3 E8 t! r( ^" ~0 T8 \: Q- m9 e/ l5 Y( F+ v2 [) e/ D
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h% Y! s7 W0 }+ Q
(API Get entry point)/ x: i5 @2 q3 G) G; W! h- h/ ~
, d- z) Y9 R& q& i- B9 m9 \9 g# X1 m( B, n- T4 f
xor di,di# _% _1 i) b) D4 S# P
mov es,di( v* _( b4 {3 ^( m
mov ax, 1684h
2 A) x1 p4 {0 K5 ~% }, ^ mov bx, 0202h ; VxD ID of winice/ P0 V( O) N% G9 j4 l) v3 H
int 2Fh+ Y6 ~) x" @: }
mov ax, es ; ES:DI -> VxD API entry point
1 |, ^2 R3 `; [+ P" _1 Q# B% h9 ~ add ax, di M3 u; j# p1 M: {# i ^3 g* E5 A
test ax,ax
$ z) i1 h- u! z$ _( X* D jnz SoftICE_Detected7 O, }/ j/ ]8 W" I
. b8 \% C+ g' }$ W7 Z6 g
___________________________________________________________________________+ i; t. H- t5 z& H) [1 y- S
4 U% C- B+ A t/ N
Method 042 {) d, ~, Z, B8 b8 i5 }# p* o
=========
5 O, g$ S/ l# K: a' g) @. W# p
1 h. q$ K5 b. y* tMethod identical to the preceding one except that it seeks the ID of SoftICE
) H) n% _* y% V! iGFX VxD.0 u6 x& x# q$ s+ v5 j( R8 D6 {
& m. N& z+ ] ^, P$ ~+ S6 n! T) l: F, B/ H xor di,di
" Q( B3 |( q. f) c mov es,di
5 k- ?7 }3 _9 o+ R S3 |6 W Y mov ax, 1684h
; P. n( |' a# M8 @0 G mov bx, 7a5Fh ; VxD ID of SIWVID1 q/ l% | X/ z6 H) j/ x! \# P# m
int 2fh4 O3 H8 c$ ^" ]
mov ax, es ; ES:DI -> VxD API entry point
" B- j T" u$ g" p5 P$ C( V add ax, di
( i) S u, R8 b' A# I; M' R9 S test ax,ax. p% k: [3 J, b9 p
jnz SoftICE_Detected% |. x4 \& @8 u7 @& ]! Z
' k. c+ A6 r; }* _: s! \__________________________________________________________________________4 U% ]0 ^7 n8 I5 @3 [0 e1 {/ F
; J/ Z4 _6 p$ O' K( |( |) Q3 ~6 Y6 N) R1 A4 B
Method 05
; i0 W6 j# U# Q2 s# [=========
- S" J9 j6 M$ K
6 {/ _7 E3 ~7 v8 P3 M0 u u9 TMethod seeking the 'magic number' 0F386h returned (in ax) by all system+ B! v4 t, y4 Q2 _9 ^. b
debugger. It calls the int 41h, function 4Fh.7 q* R/ y/ |! N( u. m# \
There are several alternatives.
& q: b! N9 k, \. F" `+ ]9 n
& y! L% N( r7 g; u; N1 N) D% K8 U- \The following one is the simplest:
" f, a) h8 g* C( _5 N
- _; G- s; ~3 J2 U* g* l" ]% S& Z8 m mov ax,4fh; y! a5 z( W5 t$ o0 s/ L1 g
int 41h
: W- E; W- o" R cmp ax, 0F386
" a( |8 _3 m' q( s' y1 T8 Q jz SoftICE_detected
& u8 T( Q1 A+ X! T) a: z% B$ w
1 `3 K& ~3 g4 ?0 n- b ]$ `+ @' u) A. n' H! V2 o0 j% S. }6 r
Next method as well as the following one are 2 examples from Stone's
2 m9 [+ x) C7 Y* Y3 N6 O"stn-wid.zip" (www.cracking.net):% o8 I* a5 Y5 l3 a" Q% W
, `( o0 L$ I* V# [- F1 b! g# S8 V mov bx, cs' n x9 a9 D# \* f4 R8 s. B
lea dx, int41handler2
* G7 j% d h! @4 N7 q/ C' T xchg dx, es:[41h*4]
4 }) m# Y! |+ c; c$ V+ p, B xchg bx, es:[41h*4+2]
7 l% E/ z. c6 |7 e4 i# o mov ax,4fh
2 _9 z5 D0 o# k+ [" U( U int 41h. ~5 A7 T/ V$ O; N3 h
xchg dx, es:[41h*4]
9 Y' j- t6 p! f9 n7 `4 x2 r" e xchg bx, es:[41h*4+2]) _( C+ \5 f, u8 `
cmp ax, 0f386h; S) j% U- _& y) m9 m$ m4 W
jz SoftICE_detected# S, e6 D: a! S& Y5 X4 ^/ i3 q1 i1 A
6 b2 h- C/ f2 e+ x* D2 @
int41handler2 PROC4 e& \" J# A+ W8 Q$ f) B G
iret. c. `6 H! y* }0 e
int41handler2 ENDP
- X. g3 P# `* L) p' r/ A9 a1 J
* F8 e6 j. b4 G7 d# u+ S
8 J/ r8 X( r0 _& I( T. g+ p5 m: T_________________________________________________________________________. a5 z! }5 E6 m* a) \
+ s3 W0 i! ?2 f1 y- x! u
+ L" [! F2 T! F7 f
Method 06# {3 h: X: D0 g
=========' v1 U. D6 A2 M% {
4 p5 ?* q$ P1 r3 x7 |
) m) Z7 b4 y: a9 O2nd method similar to the preceding one but more difficult to detect:
* M0 v# v* Y7 B* s/ N3 O
( z; ]6 [$ U' a. q* ~! c9 u. M6 X* n2 ]
int41handler PROC
, F) S) t* a ? A/ b mov cl,al
# V3 z4 i1 P9 m5 l+ [ iret* @% R8 w$ {: Q0 x3 A
int41handler ENDP
% B' P8 m1 v! H& d
, D% S6 z5 g& E2 k5 `2 A6 w7 S8 p$ Z( |* W7 J4 }; @" l7 ~
xor ax,ax
6 |! n) F/ D/ ] y) G mov es,ax& d, I7 l9 Z7 v# K( m+ @1 ~! y
mov bx, cs
1 u+ ]5 } Q& H6 Q6 G lea dx, int41handler
5 T% s- s/ w5 d; U. L& ?7 }7 T2 P xchg dx, es:[41h*4]
% s3 o% P" H. P9 ^6 l4 I% Q5 D xchg bx, es:[41h*4+2], [1 n( T, ^1 t2 |3 K- r
in al, 40h# v8 P, F9 b+ T n+ R
xor cx,cx
$ f7 u# n+ b# J int 41h2 F, J% `. C6 P) G3 W! k
xchg dx, es:[41h*4]
! t4 n# A7 _( A xchg bx, es:[41h*4+2]
! y+ S, E2 g0 z1 } cmp cl,al6 l# w# j/ ~2 I: C
jnz SoftICE_detected
: o' c7 a) t+ A/ e' q% U
& \ F- f2 L9 u8 F_________________________________________________________________________& O- {; a0 p: M8 J) q A. H' R
4 y, \/ {$ ^) r$ G: M3 ` ]9 H4 y
Method 07
+ D( |' |& k& u) ]! g=========
; H- v, B3 ?% P2 s
; c( D5 q8 R6 }3 }Method of detection of the WinICE handler in the int68h (V86)9 u+ C% v; D8 m% l8 Z" H2 K4 ?
6 k+ o8 j5 U. D( ~
mov ah,43h! ~0 S3 y. W4 W4 J. Z' `$ _; ~
int 68h) [2 x2 P- x, R2 M
cmp ax,0F386h( z; ~. F7 ]; o5 u. B1 ]$ }1 _
jz SoftICE_Detected
* R: t/ [# d" {+ s: C; q, [% k/ f" ?* r, J
2 u$ d4 V H8 N
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit3 N6 h4 `: |5 W3 H
app like this:
1 {" R( L) i% H f2 c5 Z- z6 c( E5 Q' o0 @4 Y3 d! B+ L: b4 j
BPX exec_int if ax==68
) ?& n) D' P8 d (function called is located at byte ptr [ebp+1Dh] and client eip is D8 [( m6 [ A% r) o+ ?
located at [ebp+48h] for 32Bit apps)
+ T6 c) J$ }. l( a, Y0 {1 `5 ~; Y+ o2 M__________________________________________________________________________
0 w/ |3 M8 M( v$ J T5 x. I0 c& f6 t; I9 }( y
4 j3 y. b% i4 Q7 u" R% EMethod 08
p q2 F2 @& j7 ~=========0 S7 E; ~; x1 _7 z
% o1 j( h# l) I9 f2 x6 T2 Z9 z
It is not a method of detection of SoftICE but a possibility to crash the
- w* V0 G/ d7 a0 I7 i7 ssystem by intercepting int 01h and int 03h and redirecting them to another* W3 k g3 `2 p' e, O! [0 F3 u0 R
routine.6 ^$ j; \( D$ R% ]0 O# T9 A: N
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
9 _1 V! u! |" o) i% Hto the new routine to execute (hangs computer...)5 d% s7 y" U, x0 G& A& v% n
/ s6 }/ k# ?2 Y5 h, J% ] mov ah, 25h, r, B2 |1 n' W/ i
mov al, Int_Number (01h or 03h)
% [* K0 U! b& b% h0 U mov dx, offset New_Int_Routine- u) d( D. h6 b4 c+ z
int 21h* n ~) B" A0 \& H
- K3 I/ V4 P' c7 }+ C& o
__________________________________________________________________________" u' M) h4 C0 A% F4 b' y
; z4 W, \2 _$ c. j5 t% N7 E
Method 09
9 P# S1 }, C/ O7 {=========; |5 l3 Y6 A4 A7 ?
$ I5 t/ {: N: ]1 l, ?* \5 KThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only2 O w. s6 s. {* j9 g$ q, L* W1 K
performed in ring0 (VxD or a ring3 app using the VxdCall). f( P8 b$ f0 c$ J4 D* C
The Get_DDB service is used to determine whether or not a VxD is installed4 S6 u$ R& Q+ V
for the specified device and returns a Device Description Block (in ecx) for
3 U* f( m- x1 {( f9 I* J) j* gthat device if it is installed.0 z. J% v5 A8 p4 o/ F
6 z% I1 j' }! h4 n) _6 ^ mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
9 i+ ^. B4 k* @+ F mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
# U+ D3 Z5 J/ L/ w VMMCall Get_DDB
9 _( `1 \% q- Q3 r5 k mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
$ A6 D% c! `) l/ N: q% F
+ [. e4 k. x& Y3 V yNote as well that you can easily detect this method with SoftICE:5 [$ ?( n* A: t7 b. l$ `
bpx Get_DDB if ax==0202 || ax==7a5fh6 t2 G& ?6 g D+ x2 M2 R
# x6 ^/ J! [+ G__________________________________________________________________________% l% _6 ^- a) D; Z
# l! k9 U, h- [/ W: B1 x$ Y& RMethod 10
3 c4 C% N6 t4 _- e& [* i8 }=========
& l+ |. X9 |; ~/ c# t1 y S; ~" P3 K% O1 X# e- n
=>Disable or clear breakpoints before using this feature. DO NOT trace with4 z5 S; M! E# B& [2 R
SoftICE while the option is enable!!
* X. G/ O, N# h) p7 D: h* u9 m8 h0 N* t( l, `, _; c
This trick is very efficient:6 u) i; a; i+ W0 ^+ l( l
by checking the Debug Registers, you can detect if SoftICE is loaded( V$ d3 y, o$ w" j& G% w7 v2 u, P
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if5 S* ^ A u9 m8 a) f
there are some memory breakpoints set (dr0 to dr3) simply by reading their
- Q; P. L: v8 u/ bvalue (in ring0 only). Values can be manipulated and or changed as well
+ T1 d, M7 e) ?6 X' N$ e2 Z(clearing BPMs for instance)& w Y, [ j: Y
# L; n) r' _% b$ y6 t# r# C__________________________________________________________________________0 Q5 G# B5 M4 z
- B/ c; d9 Z$ ?& tMethod 11
" H4 B ^5 X0 p3 a7 x, s=========+ d# Z: h. S4 p8 O! W
" q& K: M- _9 R: a" p/ E7 u$ v
This method is most known as 'MeltICE' because it has been freely distributed
) P: ~# r% o" Svia www.winfiles.com. However it was first used by NuMega people to allow2 h9 ^- x; ]7 P! T# P$ ^2 h
Symbol Loader to check if SoftICE was active or not (the code is located
I% E9 v" A: a( `inside nmtrans.dll). W; M, `9 ?- d7 s4 c5 Z
: [; p: d w k6 q# c `- x9 W
The way it works is very simple:
3 D2 M7 g: Y5 ?: D9 z3 JIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
6 R: |) k# d9 {0 LWinNT) with the CreateFileA API.
/ g1 ]# `- y: s, `) ] f) U1 E: V* g7 g5 J0 r
Here is a sample (checking for 'SICE'):& D2 @' V3 z2 Y+ n7 B: e
2 }1 ]( F# ]5 a" c- @! i6 ?; n) J" g
BOOL IsSoftIce95Loaded()2 P2 o9 c* s; F! t/ o$ s) H, U/ V
{0 Z# j% M5 _( F8 A* L0 [
HANDLE hFile; 0 X) ]. x/ t7 F
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,2 o3 a. J) `! ~: Q8 G: D
FILE_SHARE_READ | FILE_SHARE_WRITE,
6 f1 u$ O; u5 _ NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);+ x8 G2 y" Z0 Q' {8 k
if( hFile != INVALID_HANDLE_VALUE )# R6 m2 H- Y8 e% ^
{
) Q1 ^9 _2 J+ x( P, j* {: v CloseHandle(hFile);& P9 G Y; M3 G; ]
return TRUE;5 d% ^9 O7 o1 r6 U" [- C/ \% ~
}1 a/ U. z' |! {: S0 O
return FALSE;3 x( q* A7 [( ^6 D
}
) A* U( ]2 w6 F3 n% D9 ^& ]( ~2 ]& \! k) c k: v5 ]* Q) Q+ ] E& c, @- w
Although this trick calls the CreateFileA function, don't even expect to be
; ?+ W4 ~: c3 b$ B+ Fable to intercept it by installing a IFS hook: it will not work, no way!
1 e) d& K. k% z- T! ^In fact, after the call to CreateFileA it will get through VWIN32 0x001F: e3 V C( X3 m( c/ e% Q
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)# V& n) x8 X6 J% @3 U6 Z
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
+ m1 V; s$ Q: i; pfield. @! S9 Z7 _9 g! V/ [1 ~
In fact, its purpose is not to load/unload VxDs but only to send a
6 r6 V9 l x O4 s" SW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
. D+ k" ~ o# g8 q- a" r8 Z% Qto the VxD Control_Dispatch proc (how the hell a shareware soft could try
. r( {( f0 x& ?' u7 b x4 pto load/unload a non-dynamically loadable driver such as SoftICE ;-).
h0 ?" E5 u9 M7 WIf the VxD is loaded, it will always clear eax and the Carry flag to allow' _+ j7 Y; Z6 P4 X1 O, [
its handle to be opened and then, will be detected.
1 E9 J( u* b2 |0 g- i' H- qYou can check that simply by hooking Winice.exe control proc entry point3 B9 p2 ?) W% n+ U
while running MeltICE.6 r9 L, D1 e `
8 R/ M" Y0 ^0 s1 `
. N' @4 B$ {. _' B
00401067: push 00402025 ; \\.\SICE+ n0 o5 n; C* C3 B" l4 T
0040106C: call CreateFileA2 ^2 p, s6 @' n G. M
00401071: cmp eax,-001' g/ U+ f5 s# m1 x' ?6 A
00401074: je 00401091" E+ U7 B5 c; B
9 \; M0 z+ \5 {% I
2 k) w! f2 C8 ]2 W
There could be hundreds of BPX you could use to detect this trick.
. w1 K$ ]1 X+ _; @" a o-The most classical one is:$ a5 N& H& @( }0 ~2 J/ l. Z
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
# ? |& u3 ~1 R8 O' p# c2 r *(esp->4+4)=='NTIC'% C' I; R# E, K, U
: Q% s E4 R! m' ? w-The most exotic ones (could be very slooooow :-(
2 E7 W( R8 G' O# L- w- J* B BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 9 z3 u* k/ J6 Z& X" O8 N
;will break 3 times :-(
, W. ~6 v' P8 p8 D- W; K, l/ A
: T3 u0 {2 K9 v% L8 N1 ?-or (a bit) faster:
4 c( z! G" o, {. p4 w: [6 e BPINT 30 if (*edi=='SICE' || *edi=='SIWV'), J& B. U3 K& M8 Y4 r E& {% o% v0 h
, o3 H' a+ Y3 b$ [7 l! _$ E BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' , R5 f9 T9 A& p& c6 G6 U" Q; u2 H
;will break 3 times :-(! K' E/ `, q6 |8 r3 h7 Q
. v. p0 e+ ?! m# s$ a) M! m& M-Much faster:+ F. @7 j! n4 s1 c& u: L: o
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'6 d( X2 m* t: {) V
7 I1 g6 j" h& i" C; T" r3 p2 u
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen/ E; q( d0 P% _9 K# d4 E- E: A9 D
function to do the same job:
U2 X& a, q6 z( P+ B+ {
$ n! R1 B5 z( V9 C2 R push 00 ; OF_READ
& W. A2 K+ t& { mov eax,[00656634] ; '\\.\SICE',0
( U1 C0 m, S" j! A" ~) f push eax
/ z+ }- w' X) p call KERNEL32!_lopen
& u0 V9 D0 X! g3 c' V inc eax+ w6 b# J8 i1 G' B. D( g
jnz 00650589 ; detected
) q ?0 v4 ~, t- D3 u push 00 ; OF_READ
! W( v; V# w3 ^ E$ ?; @- V0 }0 e5 H mov eax,[00656638] ; '\\.\SICE'
2 B6 }8 j+ y f. v) f2 {# o! o: T push eax
9 ?5 N: |( R9 ?5 P6 A call KERNEL32!_lopen' v" U' t/ z) e7 S3 C
inc eax
* M9 W8 \. j; S( J5 V- c3 O jz 006505ae ; not detected
' H3 C2 ~9 ]9 g1 D! k$ g. F# [. W+ B6 R/ G
) x: y( \ t0 I
__________________________________________________________________________+ m" \& A2 X/ c( q+ r4 I
* L" |' q; b+ M/ E# j9 X$ f2 F
Method 12
- J) X- L, t9 x) b9 L3 T=========
' M) K* p' z6 `/ U4 ?3 |( _' ~# F2 x! O+ j1 G
This trick is similar to int41h/4fh Debugger installation check (code 05, q' ^; C( r4 t/ z% @% q
& 06) but very limited because it's only available for Win95/98 (not NT)
0 k1 b5 {4 o& R: V. ias it uses the VxDCall backdoor. This detection was found in Bleem Demo.6 l# M& `" y: { ^7 u
# c* `( s' J( F6 W. E8 z push 0000004fh ; function 4fh
Q- j. r# a& i& ] push 002a002ah ; high word specifies which VxD (VWIN32)" |4 t5 z# ~3 c' x- {
; low word specifies which service
5 L: o2 w* f9 |( }+ R8 J4 I1 l (VWIN32_Int41Dispatch), {3 \/ D* J& Y
call Kernel32!ORD_001 ; VxdCall
" B2 M3 x+ b' M1 N2 e, N/ O cmp ax, 0f386h ; magic number returned by system debuggers
1 I- N) D( ]6 f/ D' V6 _+ Y+ o jz SoftICE_detected, F+ H4 ^9 }1 ]- R' E
8 P+ l7 Y# q: W( [% n- DHere again, several ways to detect it:
$ B% h9 |) Q+ Y" y9 c& ?; f# M$ j" c1 d& L
BPINT 41 if ax==4f
" E9 _! Q% \% X) ^3 \) h- I9 I/ L5 ^( J1 q" N7 N s! N: x
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
# E" g+ x6 M k
/ b2 @9 ?( v6 U$ Q' r BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
( y2 Q+ M6 J' F. I# n; [; }
# x7 w& m2 W8 N4 h BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
' ^# t5 o4 m* t4 j$ X- f0 \5 M {/ k3 D, V& n) Y
__________________________________________________________________________% v @9 S" n- n Q& e! _! e
/ `: A' t: ~ T3 V8 b9 |$ |
Method 13
4 U1 q8 o8 V+ Q& k0 q0 c9 U0 L=========4 q/ r' v J0 l' X8 U% Z
" w& T, \0 a, h* ?3 N4 eNot a real method of detection, but a good way to know if SoftICE is
6 t) F( E/ R6 C3 _2 z4 sinstalled on a computer and to locate its installation directory.
+ k- T- W2 I' @ _4 @% D; cIt is used by few softs which access the following registry keys (usually #2) :# a5 F" ]- T; \: Q9 K
, h! \6 o- F7 L, B
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
$ E7 f! s; i' _! q( m2 j# Y( P\Uninstall\SoftICE
( W* M, W, n8 V, o0 a! }' q-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
* l; e5 _+ q( I( W, O( m-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
/ P+ o$ F! l3 M8 V2 k( e+ ^) r" f\App Paths\Loader32.Exe
! Y8 s$ I& q, k; V
0 s! X9 q! `6 S- w$ |( Q+ H3 R$ O5 I
9 W+ v. d$ {" K/ _Note that some nasty apps could then erase all files from SoftICE directory
: c' a! h" P3 D& E+ {(I faced that once :-(
$ x# p; K* d3 `5 y& k) j$ P& {$ k7 L7 h9 {0 x! b$ g
Useful breakpoint to detect it:9 x9 a" W/ Y" `) A3 z
2 T) D# p* e7 q# F# I( Q BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE', Y: v t) p( t9 C; M
$ m/ W/ o7 j+ U M# b4 Y" a1 x5 p; y
__________________________________________________________________________& Y$ F" }+ B- T/ e( V( ~
9 H) D, s: M' K2 I% k
- G2 }# C: n9 {7 m% uMethod 14 % B2 B3 z, r) H* o0 P2 W
=========$ I6 i( ]5 M0 d( @2 S
" X4 v+ N, h' R# Z( W0 vA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
& F B. ~/ K9 j8 sis to determines whether a debugger is running on your system (ring0 only).
. a6 R$ g. q' J& V% b; Z" v0 M9 \( u: s( |5 a, S
VMMCall Test_Debug_Installed3 H4 R9 l \% Y5 q+ y h6 U4 Q
je not_installed
! \$ ~$ t: B6 d5 D$ i, v1 k, [1 x9 ]6 y( r) A$ }) g) m1 M
This service just checks a flag.
" A/ r8 L2 B1 n$ I+ O</PRE></TD></TR></TBODY></TABLE> |