<TABLE width=500>" m* ^, s! }. d" _1 B8 v
<TBODY>
3 [ I( Q& l* u; `4 q7 }, o3 u' x<TR>
3 W. X: `+ w0 Q. P<TD><PRE>Method 01
: k! V0 i1 R; L. Y2 }5 D=========
( W6 h* U( b; x3 x+ I5 S
0 q, Q v! F0 e* RThis method of detection of SoftICE (as well as the following one) is
8 `% X; _7 m% R- ]used by the majority of packers/encryptors found on Internet.9 s5 H- r4 C! M) A- t+ ]0 |
It seeks the signature of BoundsChecker in SoftICE4 f6 e' @3 k* e9 g7 [ B* e' ^
( T' }% y4 ?7 U) k1 j r+ ^6 Z
mov ebp, 04243484Bh ; 'BCHK' \. m* {8 y! ]1 _+ X
mov ax, 04h
4 O5 G; g( l. u% S# \ int 3
2 _% \* x1 }% \5 X/ K2 d; y8 J cmp al,4
; [4 R S) [; g; _ ~# z jnz SoftICE_Detected ?+ @2 ~& A4 X5 h, @5 K
r3 ?+ L5 H% D___________________________________________________________________________
3 R& b# |. p" `/ F1 [, h! a; k9 @
2 O6 {* a; T# i6 k- }Method 02' u# E, ?5 U4 x4 G6 u0 k8 M9 [- r
=========7 ?& f: }' ]4 U* o% d1 E- n
1 V4 j0 j: a% S1 m
Still a method very much used (perhaps the most frequent one). It is used
+ U$ x7 I, T9 Rto get SoftICE 'Back Door commands' which gives infos on Breakpoints,; `3 R( c7 v: r1 _/ I! d6 P6 h
or execute SoftICE commands...1 k/ }6 [" f) E4 f2 R+ H' C( a' M3 O' J
It is also used to crash SoftICE and to force it to execute any commands
' F0 H. d2 x) h(HBOOT...) :-((
1 q* w @5 W- K4 _# c: x' O7 S( ?& A9 Q9 q6 `( x* o
Here is a quick description:& X5 N2 ?/ E7 o
-AX = 0910h (Display string in SIce windows)2 M/ U0 ^9 \$ H; |7 B5 Z0 ~
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)* _' k, K$ F1 l
-AX = 0912h (Get breakpoint infos)
1 F) j; R- s' E- M: u2 I3 n-AX = 0913h (Set Sice breakpoints)
6 S' t" q4 b' L' u/ |1 @( ~$ E/ E-AX = 0914h (Remove SIce breakoints)# H5 _, A/ @6 T3 p7 q
& I1 z% E9 ^, c4 f# b% uEach time you'll meet this trick, you'll see:
) @6 v1 J: J* q% g% j-SI = 4647h
6 s5 V9 O/ q* i3 U2 D0 l-DI = 4A4Dh5 g5 J- k# g- U; C
Which are the 'magic values' used by SoftIce.3 l( d2 t* c9 `3 o. l( f6 s
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
( e7 Y! L1 _& X5 y- i
* a1 s5 y0 w3 D& tHere is one example from the file "Haspinst.exe" which is the dongle HASP
. j! t: G/ ~9 [6 j- g4 vEnvelope utility use to protect DOS applications:/ {" k1 l+ S% {8 F9 f+ c- o
% s9 C% u9 }" [0 [ z6 w8 Q
5 e( W8 E) T3 W1 I; s
4C19:0095 MOV AX,0911 ; execute command.6 Y c9 o- O- R( a
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
( G) q$ v; c7 M4C19:009A MOV SI,4647 ; 1st magic value.
' A( T" n, {# n6 V( g4C19:009D MOV DI,4A4D ; 2nd magic value./ B+ |& L/ W0 \ t- B0 b' F
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)2 [" K5 v- P% e
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute! V3 W6 A" K4 S; d1 M$ j
4C19:00A4 INC CX
# B7 i4 E' j+ t3 l4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
/ X9 u) G4 x& b9 D4C19:00A8 JB 0095 ; 6 different commands.1 Z3 H) e! ?. [: _3 k9 r
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
$ t8 ?) r! ^9 C6 N5 a6 x4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
% V) y) I" v I7 v Y3 G6 h( }5 ~1 H/ v' M* h7 v% x: z- u1 ]1 p
The program will execute 6 different SIce commands located at ds:dx, which" o3 W9 J. F* k% c* N
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT. P- s- I% Q2 C- ~' O
: M R. y9 G, v/ Q# U6 p* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
$ J7 S* n, n9 d0 V4 E9 B7 {5 L___________________________________________________________________________. B5 S, Z8 g* l8 D$ H2 g1 F
5 R9 ~9 g) A2 ]' M9 ^" h: A! `; e# [ G, C# {7 r
Method 038 c! N! S( K+ N, \
=========
* g/ \) w. D& ]( B4 Q# t0 D. O0 Z
8 @; _; ]1 M9 q; ULess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h# S+ K1 C3 [; j. Q% o% D
(API Get entry point)7 ?& n; @8 R E
5 Z5 Y1 a. C8 z( K+ g! }! j
1 o! E" R# ?. b4 W2 P& m/ ]0 \1 c xor di,di6 _; c: t8 ~8 N( D6 ?) @
mov es,di
: P, h7 p; O5 Y: f! }8 A/ N mov ax, 1684h
Z" S5 F. T- o! ^* _ mov bx, 0202h ; VxD ID of winice$ U8 r( \) i4 Q; L8 ]' [) |. y
int 2Fh
1 y7 f4 e& ~! D& v0 z! p: S mov ax, es ; ES:DI -> VxD API entry point
( q7 r) D1 O- H$ a- S0 w1 a& Q add ax, di
, T! r/ E( G0 n# B7 A% B D: n test ax,ax
' e( z. t2 b/ A, K+ h jnz SoftICE_Detected
Q% f9 A. Y' ~/ u
9 j/ [8 `3 C! k2 _7 d___________________________________________________________________________
0 w1 m, x7 s/ ]2 c% R" M* a& A( m8 S! N& |6 b
Method 04
& M( K! q& `8 j7 P( n: | [% y=========- M. \$ _4 |+ z# h, z1 \) M( Z
" u b% j3 i u8 f, D
Method identical to the preceding one except that it seeks the ID of SoftICE' f' J5 @! M# m7 t! y
GFX VxD.4 \5 ]4 Z0 `4 k2 Q
0 Q' M6 {0 Q# l$ g ]/ A$ s xor di,di
0 s0 @7 ~2 ?6 S1 M0 r4 V mov es,di
: a$ D, k o1 b" Z( G- a mov ax, 1684h 1 ?- i# {2 l: R0 S7 H
mov bx, 7a5Fh ; VxD ID of SIWVID
+ Z6 t/ {2 N# E9 W. y- z" Q int 2fh" U0 h. e2 f6 s/ v; h5 c: m
mov ax, es ; ES:DI -> VxD API entry point
; L* Q O% C* ? add ax, di
; W8 i, v2 p$ Z6 B6 q9 g8 e test ax,ax
5 {4 n6 M5 r9 z& ], L jnz SoftICE_Detected( J& k2 J% O/ p6 f; W
. y6 K! L: s/ [" I0 ?: Y4 ~
__________________________________________________________________________' f- i* d7 v, s: e+ m p+ c$ H
" p0 i/ I) S/ F1 u
9 K2 m! J$ G6 W8 cMethod 05
, L2 c1 u0 d6 a=========$ n5 K, O& B8 d8 O8 k/ |7 U
4 l+ A, {4 R- H( F" sMethod seeking the 'magic number' 0F386h returned (in ax) by all system; e9 }. {# f+ I1 L! j+ Z
debugger. It calls the int 41h, function 4Fh.8 Q7 Y2 Y1 z# `/ v
There are several alternatives. 4 ?( b- @. A; D' v. v5 l4 R
; m# W/ w2 s" p% v# x# BThe following one is the simplest:
7 I; M, a; }; N6 F1 z, ?7 M" P0 ?* o* @% s
mov ax,4fh/ G% l) H# r$ ?1 @
int 41h# t) h1 `0 G1 a' |# a
cmp ax, 0F386
# W' S3 T" l" A9 D3 T jz SoftICE_detected' }, M1 Q0 E4 F# u
5 K8 K( z0 z1 W. l/ I0 i' g$ {# v; k4 s: W( n) u3 g
Next method as well as the following one are 2 examples from Stone's
9 U; B/ h% z4 H/ [& l"stn-wid.zip" (www.cracking.net):
8 I- Y8 j- d" h. E7 F" w# _% H0 k% ]4 \6 k* c8 O: V- h: E4 ?
mov bx, cs/ M3 H2 d' D0 j, U3 P5 _
lea dx, int41handler2
1 S. `* l) q% t xchg dx, es:[41h*4]
$ k- K1 z* _0 R+ C) x! s xchg bx, es:[41h*4+2]1 A( k" [/ C! ^4 ?+ N1 P9 j
mov ax,4fh
7 a: G2 {, \2 q int 41h
1 y- a- o3 P1 x, Q& X xchg dx, es:[41h*4]
2 g& w) v# Q4 q+ d/ \ xchg bx, es:[41h*4+2]
: h, v, h) D* t3 x cmp ax, 0f386h# v5 j9 B. W- N8 W) j/ Q
jz SoftICE_detected
0 f, T* n2 u: e* l/ E4 M7 T4 \8 a/ }
/ A5 ^3 }/ w1 f" d7 l9 a4 yint41handler2 PROC
$ s g1 |6 U/ l" H" v8 @4 k7 L0 C iret
+ y4 e7 _) K' x9 vint41handler2 ENDP
% |* R0 a: W! p
: P' @( r$ v" j! q3 l% o4 h- d \& B# @# K+ P: b0 b. A0 M
_________________________________________________________________________6 q: J. {/ b/ g; `" Z% F1 N2 \
/ V: `$ L( M5 R1 H' ~& O! _5 k$ z/ u" K0 }
Method 06
+ U7 G" i- G5 a+ e* M0 m1 J=========
, d+ U6 t o5 g
% A, v' G& j2 p. a
7 \1 @+ b; h9 P/ V' Z+ D0 |! B2nd method similar to the preceding one but more difficult to detect:
6 J& L: g k8 W* J1 k- H: j8 \ }8 A: L9 r. K @* P
7 f0 \9 k' e1 H$ F6 e1 c. P& y% xint41handler PROC
5 h# [; F( j8 _* e; X" p* j mov cl,al
/ E% t3 N2 {& \9 W* X iret5 p8 @: Q( G: n) v' P& b
int41handler ENDP
, B% t6 O v/ V- q
2 u+ E9 J+ t) M8 q' ?; N Y8 z4 B: l" E& C) s
xor ax,ax
: W" P I6 {. T mov es,ax
# C2 w1 L0 s8 J1 | mov bx, cs
) y' L6 E# O- V' M: X5 q5 P0 n lea dx, int41handler Y# [) E2 n4 V) b7 M, U: a
xchg dx, es:[41h*4]) r4 k% x& M8 b# D# O/ k. c
xchg bx, es:[41h*4+2]0 \2 r$ | f) \/ M
in al, 40h
- \( [' m6 Q' u8 J/ R xor cx,cx
$ S% \& S# G1 i; `, ]* _ int 41h! e4 f- }0 B+ a; r% g! |. x$ M! V; v
xchg dx, es:[41h*4]
. v0 }1 `# V3 m) L xchg bx, es:[41h*4+2]
* w2 K* S$ H) p |% q% D cmp cl,al: N; O% Y) r9 B& o& D U
jnz SoftICE_detected
6 C! ~) q8 h/ Y) H/ I9 n
' Y) C. o+ O/ ]3 i7 X" `/ v_________________________________________________________________________
- G2 q7 a7 c& d' h" P
( T+ H: r! T; ~% [% X6 n1 |- _7 IMethod 07
% n& `8 ~. {5 G2 C* |6 u j$ H' n=========1 K" J+ y7 u0 |
1 M- n {+ [# L3 M( u! E
Method of detection of the WinICE handler in the int68h (V86)
; U) M* V* Y- @7 Q& W( N( s
& n( w* ^7 k3 Q4 d; N+ P& ^# L+ E9 O mov ah,43h% e i9 v- c P/ U
int 68h
# F( u7 s8 L- u cmp ax,0F386h$ B/ m$ i- [+ l+ G: b' {. _% ?
jz SoftICE_Detected
7 [! H: K* A+ X* I6 T& \2 a1 x/ S" a, k8 X! s4 r
. m, b5 `! [6 K8 ^6 j o=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
: Y8 t2 X2 B& A" f6 i @% a5 Y8 E app like this:& T: G5 E2 C% n
1 \! ]' j3 l5 {0 E( R; F/ y% X
BPX exec_int if ax==68- m# f5 n9 v% \7 Z1 }6 Y- f, I) {% Z
(function called is located at byte ptr [ebp+1Dh] and client eip is
/ J% c% e7 s% V) @5 I. }( y# X" z& W located at [ebp+48h] for 32Bit apps)
1 V+ z0 q4 _! F0 |5 F1 U* ], r1 y__________________________________________________________________________! t- e! T5 ^- N. Z( f' Y
8 ~6 T/ z# q2 Y! {$ Y6 E
/ Z% f! k! b5 v$ R- m
Method 08
: B! X5 x9 N; X. z! m=========
Z9 J# f2 d F/ L2 A; {8 O! u# x
It is not a method of detection of SoftICE but a possibility to crash the
^" f7 P, u/ M+ nsystem by intercepting int 01h and int 03h and redirecting them to another
) _4 L( o; @0 K! L# z% M" Z8 Wroutine.
. {& q4 Y( f4 R: q3 zIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
1 X, {" P y: X c# m |to the new routine to execute (hangs computer...)
# A2 y# ^0 d8 j; J0 V1 z
# K' `* |5 B2 y5 q) u mov ah, 25h$ a9 K$ F/ K! @) Q; o
mov al, Int_Number (01h or 03h)9 p% Z& Y/ ?" ?! l, u0 m& R
mov dx, offset New_Int_Routine' m, q# z g8 i3 z5 ~( o b% J
int 21h
o+ |. `2 D2 J% h1 b6 J- t2 T1 Z% i" }: i( U+ |, V8 ?
__________________________________________________________________________
; n; {; a" W e" H
" ^* t: K2 k1 A. L% ?Method 09
4 a: e; R' V* _7 p5 \; {( Z========= G, q3 w, H# U; A8 }. B
% a9 |* k% f+ v/ v! K
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
# Y8 k& x9 I: d) I0 q; w- fperformed in ring0 (VxD or a ring3 app using the VxdCall).) o2 \. b4 g: g( t' T# I6 c
The Get_DDB service is used to determine whether or not a VxD is installed) P+ ]. W- V0 ?8 J2 ]4 R( {
for the specified device and returns a Device Description Block (in ecx) for% c/ c( {' B: F# I2 ^
that device if it is installed.
8 |4 |6 ~. ?7 X- l) v f9 p( i# d
. y& Y- B0 H7 Q6 L+ s mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID x7 ]5 [6 B* o# [4 M
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)$ c7 u! }6 l2 e% O
VMMCall Get_DDB
& [$ @4 k: ~; \5 G8 M mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
( a/ \1 o' k; z2 w* w, }" I6 ]3 {) b0 c, L( V' G: ]/ E% |
Note as well that you can easily detect this method with SoftICE:% w2 @: L7 E/ M2 H9 D( ~/ D
bpx Get_DDB if ax==0202 || ax==7a5fh7 p( T! c0 I9 [# Y) e
3 z7 }# \- j( k4 }3 n0 V__________________________________________________________________________6 {) Q4 z4 p1 Y* X
1 @' \" q- K$ O( v5 u9 [Method 10
6 ^! W z0 L* T4 E5 [=========- y" ]1 Y1 {2 _6 b- [
* O; \/ O9 `8 P! h; ^* Z
=>Disable or clear breakpoints before using this feature. DO NOT trace with
$ o, T% n: P f# I; H9 U! H SoftICE while the option is enable!!
; u K4 ]. e: O. J% `8 {; O* t& E L( { I8 Q; n- [7 D( _
This trick is very efficient:
5 c4 H1 x9 H4 u% e$ T* b1 _by checking the Debug Registers, you can detect if SoftICE is loaded
6 ^: b/ \0 u: G/ u9 x1 A4 F3 A(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if& t1 X3 G5 ~2 ]1 n& O
there are some memory breakpoints set (dr0 to dr3) simply by reading their
) u+ b* }% P0 o4 \9 C5 G bvalue (in ring0 only). Values can be manipulated and or changed as well
Z0 v4 M* r4 r4 d(clearing BPMs for instance)4 C8 l* M r5 l( k, G5 K" |5 g
6 u& A W5 S* @" t' |2 R, |# \__________________________________________________________________________" I4 r" L) [+ p4 G
! C1 N) L& V* G/ f: uMethod 117 t6 ^* O" l8 a. o1 _2 ~& N
=========
4 p, M) r* {2 s* Y3 M- z7 L% U, R
This method is most known as 'MeltICE' because it has been freely distributed+ R! R# j1 Q0 |$ j( r. |+ g3 @& i
via www.winfiles.com. However it was first used by NuMega people to allow
$ [( R: z5 w0 R# Q h5 n/ ISymbol Loader to check if SoftICE was active or not (the code is located
* g1 \( r- R" f [/ D1 [inside nmtrans.dll).
8 d" P9 E. A( i0 g6 L
% ?* |8 {, u+ d9 {. z4 z1 T6 tThe way it works is very simple:
9 R% B; {; G. f6 `It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for" G9 w5 }: H! I1 {- e3 Y* S9 a) z
WinNT) with the CreateFileA API.. b+ s* [" q, N, _# h& S1 L# k
# H8 M0 ]% K: P* m( C6 X. T
Here is a sample (checking for 'SICE'):
& \! Q+ G2 u4 u. D+ n3 F
8 N1 g; F# b( m! t" j: }/ OBOOL IsSoftIce95Loaded()1 D- a' t' c3 a! J$ X( L
{% b! h" I7 F8 U6 p; z: p
HANDLE hFile;
' }9 l3 Q( d5 G hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE, I3 n4 `* {& Y+ W0 R
FILE_SHARE_READ | FILE_SHARE_WRITE,
9 n/ l! p% ~' O; m NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
# m& k1 z+ Q& t( _ if( hFile != INVALID_HANDLE_VALUE ); Q* ?4 [# M, ?) r9 {$ k
{0 ?4 X& k* u) D% I$ w7 b
CloseHandle(hFile);
% s0 W4 I9 _5 F/ O return TRUE;
9 R! R( Y- ]9 {5 M7 Z1 ?# H* i' G }
5 Y4 P! V0 \* p2 R4 e/ M3 x4 l- P return FALSE;, A5 m; ~. F& t
}
( g: M6 ?7 m8 `0 S# H8 g
" d- ?; Y1 @+ o& f7 q4 QAlthough this trick calls the CreateFileA function, don't even expect to be. @7 C2 ^! ^4 y' ^8 B% Q
able to intercept it by installing a IFS hook: it will not work, no way!
, X6 R$ Q. i; z6 n) G$ iIn fact, after the call to CreateFileA it will get through VWIN32 0x001F$ L4 l/ H% D |) B
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function). v4 k2 z e2 a# z9 F
and then browse the DDB list until it find the VxD and its DDB_Control_Proc6 B9 _, S5 ^4 o( B8 w
field.
6 f2 v' Y( T3 V6 ^, z& R1 f: rIn fact, its purpose is not to load/unload VxDs but only to send a
6 U" \9 K+ Z) q/ |. ^$ M: DW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)) T# I% Y9 l) b w n
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
+ c1 N, Q6 U8 S! D3 Q2 W6 Qto load/unload a non-dynamically loadable driver such as SoftICE ;-).
! p! C6 l- N- g& E- C8 B( yIf the VxD is loaded, it will always clear eax and the Carry flag to allow- c) g* ^0 g' U
its handle to be opened and then, will be detected.2 A: w% F3 f# v6 O
You can check that simply by hooking Winice.exe control proc entry point2 a- s- ^% l# [& b6 R. b3 K9 M
while running MeltICE.* ^* o. R, |' A) W \- G7 {* B
' {" e" h+ x# y% Z+ V
; l. h" y- \" M: U4 S 00401067: push 00402025 ; \\.\SICE/ L2 @9 N9 |* |3 I/ S
0040106C: call CreateFileA6 \* s- d! T9 a* [$ b3 Y
00401071: cmp eax,-001& p: B) g+ m% ^6 A& F1 `) ]( Y5 r
00401074: je 00401091
0 h- J7 a# k d& v2 r( r$ V# V& U/ d2 b# C4 Y9 N
1 d+ Y/ L3 O; rThere could be hundreds of BPX you could use to detect this trick.* `- y& V1 Z( l; O! A5 k
-The most classical one is:7 m5 q( Z @7 i2 O1 I
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||% z V9 z1 q% C, Z
*(esp->4+4)=='NTIC'
' g) G4 {( C% j3 Z3 l% e2 p9 o* o/ `
-The most exotic ones (could be very slooooow :-(
: F3 A5 A: j* ~' q7 T BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') ) d( c+ @2 n. L* V
;will break 3 times :-() I+ U* _- W- l
/ Q" q; Y, j: v" d1 h; P" U-or (a bit) faster:
, |/ H) {7 x5 g7 Y9 k( J BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
9 y6 x0 L3 I5 D' o" p1 Y: Y2 o
- a. z4 ~1 p/ U& d' f BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' " X! e# o8 {( q* L
;will break 3 times :-($ i" U# T! A4 V2 S1 [% d- w
0 q) I! }! b5 D-Much faster:; S9 Z t# T$ d4 _( U2 U" d: |
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'- C- f, \% i" c2 j
; I4 R* g; ^( u7 G
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
; q, s: i& K) w0 Yfunction to do the same job:
4 v! v# X/ H2 }0 v6 T- p0 g" k( G9 f! i" S9 g9 m
push 00 ; OF_READ% R' e6 p9 X) U6 s0 l
mov eax,[00656634] ; '\\.\SICE',0
4 q& C4 G1 x1 ^7 o/ c push eax
5 o( e6 R7 t+ C: F. F+ y' r call KERNEL32!_lopen
4 T9 D* r2 Q* a! n: D: K M inc eax
' ]* p1 s+ S7 r- E# G; t7 l7 ] jnz 00650589 ; detected; Z# t6 j3 O, E4 i
push 00 ; OF_READ9 x4 Z7 L* M4 ?+ N% \ P4 C0 `
mov eax,[00656638] ; '\\.\SICE'/ H3 k; y, D- O% Y5 I
push eax, i6 x) u% O* Q/ F9 ~
call KERNEL32!_lopen
) Z0 V; ^9 C3 C9 I0 L, L inc eax: T# X. y9 J( f; T1 W# q
jz 006505ae ; not detected
4 x; {+ Z, \; [3 e& D' I
# W# h# L* p& g+ h, ^
5 B9 E- y( a% ^: W__________________________________________________________________________$ n$ g9 m2 t! E' I
) f! ? ` Q; Z
Method 12
, H6 s) M9 F6 K3 r6 i=========
/ f+ E$ y/ Y2 N# |, V* i, V# _' Y
This trick is similar to int41h/4fh Debugger installation check (code 05
- J9 i& }/ o" x, B1 Q& 06) but very limited because it's only available for Win95/98 (not NT)% ], v6 ^) I/ C2 ] Q
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
# }( g* J3 o- b3 k1 L! x' g3 u' i) n6 l* e6 u9 \9 {2 ~# `+ ?
push 0000004fh ; function 4fh0 t4 `7 H) A9 L/ \6 s, ?
push 002a002ah ; high word specifies which VxD (VWIN32): I) p0 ]( x3 Z$ T! \
; low word specifies which service) C5 k5 w5 g0 ^/ c- H$ d* U
(VWIN32_Int41Dispatch)+ Q; U; L& M/ ]4 U* n8 [4 r b2 X
call Kernel32!ORD_001 ; VxdCall
) W, v/ Y* L, \& g& p+ y+ H cmp ax, 0f386h ; magic number returned by system debuggers) \" l6 c2 z. |6 w/ `
jz SoftICE_detected6 H7 }8 G4 U) G [" E& Z
, G0 W+ c2 r$ k% eHere again, several ways to detect it:, d* S% p8 m U1 _7 i
- z( V) v* m, }7 t BPINT 41 if ax==4f0 I: I" h% R) f/ q5 G! D- i
, x1 P% W& J" x- t3 P" m BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
. x# [& }" w- h
7 v# x; f) W- J' P" [4 p5 t9 R; _. _ BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A3 F! B, P9 w3 Z- _' e
& h& c1 a a5 ~5 V, @3 @
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!# r5 n. ^- a+ V6 l
. [" i) J8 N" }( L
__________________________________________________________________________# M9 C) H; u% {2 d# |" {
( l* G; [7 C/ `" g9 d" ~Method 13; l) [6 z G- }! V6 c6 ]
=========
' K1 ]& x5 |- C. H# P7 H# X/ ]6 u0 _ O
Not a real method of detection, but a good way to know if SoftICE is \- U. q, I( |! |$ b$ M
installed on a computer and to locate its installation directory.! Y: q* J! C# z: n/ D
It is used by few softs which access the following registry keys (usually #2) :8 {2 E. P. H7 o
% _& h. k1 j; }+ o: o( Y1 O( T
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
8 i8 z2 m) q4 c. L' a5 d7 C7 `' x\Uninstall\SoftICE
, ]# a- c* J* ~+ G9 B: S-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE/ J- H [/ t; e0 P9 m
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion x7 L- j9 V4 P6 u6 L; y- X% b5 Y. D
\App Paths\Loader32.Exe% P7 G5 {1 w$ o, V( p ^" ^+ V
- u8 G" Z$ _8 j& ]- a3 ~$ E$ g) x! M" M$ s
Note that some nasty apps could then erase all files from SoftICE directory2 L4 y, @6 o4 O" |9 p
(I faced that once :-(
+ i. ?. r2 k& |; s7 J7 s1 u6 `' B6 M) Z, r6 E( Z$ a7 z
Useful breakpoint to detect it:# y8 r5 r( t9 B- T
% q+ @) l3 f$ G3 v2 Z5 @
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'" F3 ^0 a) R) s: a/ M" Q0 B: j% t M
/ C0 `( \0 \' a$ G/ e( I6 ?__________________________________________________________________________ f5 }# G9 s6 p$ C) X
/ r7 j* I4 W9 ?9 ?% o
" L a$ a' d2 I) D. MMethod 14
$ |- s t4 `/ ~2 L j3 r6 X% ?/ w i0 @=========; D; h9 i/ S" |) I* B- V# F* z
- {! d1 `/ q4 P2 `4 f
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
0 B$ I: c% o7 A( G3 m/ X+ Zis to determines whether a debugger is running on your system (ring0 only).
& d+ Y+ Y2 h1 [7 Q
% G* V8 O9 _* T, Q+ G VMMCall Test_Debug_Installed6 w, D- N! @6 s1 ^
je not_installed8 U1 W/ R" F* I+ _, p5 r
% ^ B8 i: L! ^9 xThis service just checks a flag.- u( i: Q0 h6 i/ ^- E- ^
</PRE></TD></TR></TBODY></TABLE> |