<TABLE width=500> W: {9 q% E$ V ]" ~7 n {# e
<TBODY># l4 X& x3 y# Q5 A" G7 j3 `! v+ X4 B" z
<TR>
/ V* G" L0 A! M/ E) D<TD><PRE>Method 01 9 Y, d/ _4 b! I0 X
=========
, B& n! c- \ M! H( o2 \( |9 B6 @+ L. n H4 P3 w5 `( I
This method of detection of SoftICE (as well as the following one) is) J9 S& ^) e) v" c1 S2 T# R6 |( F! N
used by the majority of packers/encryptors found on Internet.
2 a( T2 M s7 NIt seeks the signature of BoundsChecker in SoftICE
7 j8 F8 s: P1 B& y/ G
7 N; Y1 ?: A. q& f3 u) g. y+ o! Q mov ebp, 04243484Bh ; 'BCHK'. I3 M7 a" H% C ]
mov ax, 04h: y8 x- l( a% l: ]8 }
int 3
" z0 ]+ k/ K0 } I1 H6 y cmp al,4
8 d C! j0 C; K& W; J) P! C jnz SoftICE_Detected0 I/ h2 |+ z1 d7 [
9 {: T3 E$ [, ]$ ?. v___________________________________________________________________________1 R1 v4 ~6 \3 ~0 y# @$ Q
0 A6 m$ J; H6 a( Q( g
Method 02% r' s U8 P5 P* x' b
=========
) x& ~' p1 {2 B
6 b+ l5 y+ a* ]& V- n h6 u3 zStill a method very much used (perhaps the most frequent one). It is used
/ {0 [! a7 `; E+ A0 x/ {to get SoftICE 'Back Door commands' which gives infos on Breakpoints,* J! X6 ~, N' `) U
or execute SoftICE commands...
2 _4 {" y- N" X* v$ }: t8 H9 W6 h" _It is also used to crash SoftICE and to force it to execute any commands
7 u8 g9 T, k% ~0 D(HBOOT...) :-(( + K) R' P% a# _& ^- {- S; Z. L/ i
- I4 a0 d$ H$ xHere is a quick description:/ y& h2 \$ ~& I6 f7 w0 z1 a3 b
-AX = 0910h (Display string in SIce windows)$ j0 f3 ]$ x' u% W5 q$ T
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
6 }3 v1 i, C; n% p. O-AX = 0912h (Get breakpoint infos)6 z* n/ q: s* y
-AX = 0913h (Set Sice breakpoints)
1 \, J2 b# @, X7 }' u+ T-AX = 0914h (Remove SIce breakoints)7 t, B5 w" N2 B0 j! i; A( T$ P* K" B
# U0 d4 y5 ?- R6 j
Each time you'll meet this trick, you'll see:5 L6 X5 H9 X6 P- u3 `* `8 z9 D
-SI = 4647h5 S7 a |4 n, @" V& Y9 I- f
-DI = 4A4Dh
( I& ~6 G$ Y6 t! j u# q' JWhich are the 'magic values' used by SoftIce.7 w# C4 \8 j3 @
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.( ~. f, `) I: N8 r# ~9 x
+ V' W* s) h: b, H5 DHere is one example from the file "Haspinst.exe" which is the dongle HASP
$ w- g6 F3 q3 oEnvelope utility use to protect DOS applications:- b; A- A& v! e0 M7 `) Q
& m+ v5 W4 j* p; L+ u7 F. {
; t0 |9 h2 B8 j7 m4C19:0095 MOV AX,0911 ; execute command.
* ~7 f& @! p9 }5 F1 Z m( E: }4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
% W6 B& P7 `7 F" P4C19:009A MOV SI,4647 ; 1st magic value.! M9 x) y8 c4 P, c1 @/ Y
4C19:009D MOV DI,4A4D ; 2nd magic value.- O n0 d& h6 Q
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)% C0 t" H- v4 X1 j3 g! n" D
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
5 N/ S$ T# e/ u: I4 q4C19:00A4 INC CX" [$ w8 V6 }7 ]8 K: w6 S' Q
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
9 ^, y& u& e/ C W4 b4C19:00A8 JB 0095 ; 6 different commands.; U" G8 K. L8 F) h3 T
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
; W& l7 x0 u5 w+ y; {/ n4C19:00AD MOV BX,SP ; Good_Guy go ahead :)( h# L" q# q4 w/ p4 {% {# e
" b: n9 d9 T, R e
The program will execute 6 different SIce commands located at ds:dx, which
7 j2 `7 T+ J3 I/ w. n5 pare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
" }$ b8 ]: s( |5 S- y5 V& L9 j: j" y6 @6 D+ j
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.0 y3 B1 g0 u7 d2 d% E
___________________________________________________________________________5 U* K; a$ o# f0 H5 m2 X
9 b0 M) f9 l7 s6 u( C1 b( ^2 O% c6 M- p, g0 k
Method 03
' f. m) w: D3 p, }* r; L=========
3 P7 E# k- N* i+ S& d8 ~" _4 u, U V# X9 G# b( j' B
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
3 t8 W& }% o( e5 c(API Get entry point)& \1 P( q4 v9 b# d
D5 e F) b) R6 v
6 x @; r& h; R3 m2 q9 j
xor di,di3 t/ D I8 b* V" M; j, [0 ]
mov es,di
+ [6 r6 ^ I) p$ u mov ax, 1684h
0 Y1 b, M8 f, w& ?4 Y" {0 Z% v mov bx, 0202h ; VxD ID of winice' k3 M, C0 f& _5 x
int 2Fh
3 Q1 P3 g+ n4 g) P! T mov ax, es ; ES:DI -> VxD API entry point
/ w$ l; J5 U# S# N+ j) M add ax, di
, u% i% h7 n4 Y test ax,ax
* {3 h4 Y, Y' b- C2 n" T: O4 D jnz SoftICE_Detected/ h& y' o& S. T; ]: s! }( S p
, ^, ?* z7 j, q: a! W$ M
___________________________________________________________________________
: U( p" P5 R3 \: c; m$ \* S/ P. N: s1 ]
Method 042 j/ C; i8 b, G6 E! q) I/ F2 Z' k
=========
3 L; }/ m0 W$ f4 v% F4 l7 y# Z9 k' J5 u
Method identical to the preceding one except that it seeks the ID of SoftICE
* P4 X8 |0 @- c0 L- ZGFX VxD.0 m1 A; V( p( M; ]
5 V% C+ c- f3 z- R% ` xor di,di7 T7 B+ D. m9 B5 w: h' ]2 a: ?
mov es,di
& r; B1 o2 z& F& Z% D+ T, ~ mov ax, 1684h $ i' F/ Z1 B0 g1 Y7 \) c
mov bx, 7a5Fh ; VxD ID of SIWVID
9 R2 o- f X* o/ {4 k int 2fh" h" f5 t& [- _2 t
mov ax, es ; ES:DI -> VxD API entry point9 c% m1 l/ T+ h. `4 x8 T
add ax, di$ c1 B' n$ I$ `: L4 \
test ax,ax
# h( a5 h1 x! v0 t- x jnz SoftICE_Detected0 u) \* V4 S% J
" V& P5 o: Y0 N* i; E# z# {2 k7 w__________________________________________________________________________
7 q4 H: O" t: C5 m. j( y! _3 t# z3 N
6 b* ]$ U% A" s8 B- Z
Method 05
/ S% r. H/ X8 B# j! p1 N. t! {=========
! s- a5 L5 [; {+ Z n c( K
+ @: j0 G' \) H9 B4 N" `1 h6 X" IMethod seeking the 'magic number' 0F386h returned (in ax) by all system1 v+ j+ @( |+ T- e
debugger. It calls the int 41h, function 4Fh.
2 P9 U' K+ S0 h3 K- tThere are several alternatives. 9 t1 f$ i7 A8 g
( y* E6 J# X5 O y4 c
The following one is the simplest:
3 V8 f; i' B, n+ o1 y9 E% \/ F+ |, \ k
mov ax,4fh' W# Q% B) G- }# d& f! v7 L
int 41h [) P1 [1 V2 P6 A
cmp ax, 0F386& N3 r; {; w( a( e" d7 c: L. w
jz SoftICE_detected
$ M3 W. \1 K# W# T4 V" j3 z
7 p3 f M$ ]8 K# A5 Y
U, u/ z, q2 H3 r3 H3 dNext method as well as the following one are 2 examples from Stone's 1 N- p2 R8 [* F( [3 d \8 A0 y
"stn-wid.zip" (www.cracking.net):
; G9 }9 C* ~5 P) ^, V# ?0 k. g' u4 Q% L5 E
mov bx, cs7 H( `( l, p3 ]6 l5 b
lea dx, int41handler2
8 z4 m# W3 k% A" W3 w% P xchg dx, es:[41h*4]
6 j: k: c. ~- y" W6 K xchg bx, es:[41h*4+2]
# c9 Y& ?3 I/ e- I% Y& C$ [' D mov ax,4fh( K& J9 |" W6 j5 r$ b% f8 {7 o3 d/ `
int 41h8 I! w% h5 {2 E& S
xchg dx, es:[41h*4]5 T% X7 n+ A. Y9 {0 e
xchg bx, es:[41h*4+2]
1 M5 r( }. M1 H: Z+ z* ? cmp ax, 0f386h7 v% ]. h% l! F, M1 B& O
jz SoftICE_detected8 p7 |9 H4 z, H/ S/ d
& r! g2 q R1 q4 u2 V$ Q/ _' _int41handler2 PROC7 Q3 ^( T! B& y/ ^2 S y2 p
iret
* F2 k# G9 U9 ^8 K$ Nint41handler2 ENDP
0 R/ U3 s- y1 h6 Z3 R! h7 ~
2 i* ?1 [2 ]5 w; ]0 A3 l7 Y) j9 Z6 b9 b
_________________________________________________________________________
- Q3 z, V4 N* ]% I3 s0 Z4 b; v9 J: M- v- S) P$ c2 X! t. d
0 W; K; D3 A# b7 XMethod 068 O: M* s9 d8 q. g9 t
=========
# A7 k3 m4 r7 l9 o# u; r2 P( k0 c* ]. \/ c, o9 @0 p! ?7 u% S
: Y( ]+ o. X& B2nd method similar to the preceding one but more difficult to detect:
( Y2 w/ b3 }& L6 ], S4 E; \$ \. n) I
) i& K: z7 s& G% A3 O; A8 T. V7 K
int41handler PROC, H- _& K3 M4 t3 n2 ~/ w$ w
mov cl,al4 `8 a% I' |& N( U$ g
iret4 U2 a% L) S% n
int41handler ENDP* A1 T J4 B) l& s
/ B# x3 _( f, U; n @
1 `( i. G. c; u( y- @; w
xor ax,ax
+ l& S: e5 r) A+ q- m, b! M mov es,ax
9 Z3 P; ]: k8 }3 [3 U1 }, V5 l6 ~ mov bx, cs$ i* j7 Z6 _) t, j! b0 M/ ]
lea dx, int41handler3 O4 F1 M- T: y
xchg dx, es:[41h*4]% [' q: Y. _ G" |7 W
xchg bx, es:[41h*4+2]
. e9 B& T% l& k/ l% t% {. I in al, 40h; Z3 [2 q2 \6 h3 E
xor cx,cx
, ] h8 p6 c% v& I7 d1 R2 l4 } int 41h
/ A# d2 F- L# f8 g% A xchg dx, es:[41h*4]0 \/ \: Z; G$ S g5 F$ b G
xchg bx, es:[41h*4+2]
3 v6 C2 e- \' e( o( U/ I$ A cmp cl,al. ^7 k: Q9 W3 L$ p4 n" |
jnz SoftICE_detected" C R( r% H( i n6 U2 ^( }3 [% m
9 J! ]9 J% {! Z- F: w_________________________________________________________________________+ J) u4 l% G- g# {- d) n; f
8 t4 A( k/ ^$ m# E. q$ @5 nMethod 07: a: e: L+ S/ R
=========, y; \) \+ \% b2 [* @' O
. W d4 g6 R! tMethod of detection of the WinICE handler in the int68h (V86)
2 V/ _1 V- o" b* ^. F
0 c; z7 A( A) ~9 D8 n2 b1 O mov ah,43h
) U8 C9 W9 f$ A5 f int 68h
, H; A2 t0 p9 `8 [8 ^% p cmp ax,0F386h) s. f! X) O$ U# X* T- @- d/ o
jz SoftICE_Detected
, X- F: D( l" T# w4 E# U
3 L3 A( L: |9 m0 G" m* j. u2 J) d1 | T2 q$ M, l
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
( y8 \& x2 Y: ^0 j6 T- w2 q app like this:
7 q4 f+ C# D! K
0 `& G( `) w" S1 x, ] BPX exec_int if ax==68
- a# ~: l' ^8 v& q5 F: o- u (function called is located at byte ptr [ebp+1Dh] and client eip is9 H" m3 K, I) f' _9 `
located at [ebp+48h] for 32Bit apps)
4 I8 [6 p* @( \__________________________________________________________________________
' ?# q2 P0 a8 J6 K' w: {9 _
0 s" [, ?; d; s4 N' v: ^ g* i! M* b
Method 08
7 }% g9 J; L& w, W1 U=========
" p6 Y( ]' r( x- o0 i1 b! Z0 }1 q/ T) c7 J4 N$ L
It is not a method of detection of SoftICE but a possibility to crash the
6 V* ^+ a. y3 |% A! bsystem by intercepting int 01h and int 03h and redirecting them to another
; g2 }4 q% A3 f$ T: c: C, croutine.! \5 F, D9 Y% f7 G. t3 @
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points: r9 n6 q6 A2 @ q& ]4 }& R6 W, B
to the new routine to execute (hangs computer...). Z/ X& p$ w* K4 M4 t7 C; q( X
; f6 J l3 B& A" x$ G8 E mov ah, 25h: {+ o; n1 M& m. ]5 z
mov al, Int_Number (01h or 03h)% z8 n" b8 Y' N2 r) X, `/ A2 o+ _
mov dx, offset New_Int_Routine: j s' q* l+ Y
int 21h+ Q( a1 M/ l f6 m. q
. L6 H% |/ V% y2 {
__________________________________________________________________________$ t! Q U+ d% y3 N' s
4 E& R7 r- w9 Y4 I" H# z5 \1 j2 A
Method 098 y$ @1 w0 y' K6 n$ y
=========
" s! j7 w* e0 d2 z, ?- B
4 E' Y+ \ U3 W) t# U1 u! hThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only# i9 s! K0 u4 s
performed in ring0 (VxD or a ring3 app using the VxdCall).: H' ]3 T7 Y1 |0 Z) n
The Get_DDB service is used to determine whether or not a VxD is installed
5 w% X0 G3 Z2 @- h# b$ ]' V- @for the specified device and returns a Device Description Block (in ecx) for( p* L; \3 p" }2 S& Q6 t
that device if it is installed.
9 @" q, A% y" _ X' u' p# ]: Q( M' C! u7 ~0 \, }3 B
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID' a$ b; [: D# f1 s# h. i
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
+ z, Q- v8 i: ~9 S W VMMCall Get_DDB
; V# U: C$ @" M3 p* a0 c& O mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
4 l: a3 y- P- X' `4 E6 i5 ~& l
3 g; L( ]# b B1 K3 A3 J$ r F/ w! oNote as well that you can easily detect this method with SoftICE:; u# E! t' ?' R8 `) p3 o& [) @0 g; Z" ^
bpx Get_DDB if ax==0202 || ax==7a5fh
3 N. z% x; _) ^) L i3 j1 J: L4 y# m& R% T. e& }2 K8 J1 l
__________________________________________________________________________$ W4 z+ I% _" y! P" p, a
- I' o% g* S& f# MMethod 10
! u) s$ L$ l" J- b0 e=========
0 d4 i% z# Y4 M* O: F& h5 R
1 [2 K6 W0 u* n J- k=>Disable or clear breakpoints before using this feature. DO NOT trace with
0 u- L( o- m% y& s6 w; A" |% } SoftICE while the option is enable!!; Z( j- O& P9 h8 R
$ y% T2 d' D* I7 i
This trick is very efficient:" D! O' b3 x, b" a
by checking the Debug Registers, you can detect if SoftICE is loaded# w, [% ~2 d( v1 x
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if% k9 H& `0 Q1 L0 z! e' P6 N, e
there are some memory breakpoints set (dr0 to dr3) simply by reading their
. i" {! W& d4 l/ k" {value (in ring0 only). Values can be manipulated and or changed as well6 c C9 \) _6 s+ r( S, y
(clearing BPMs for instance)7 J u! k6 B: x) G8 \: L
! K. k* n5 H3 {" K8 f7 S2 l__________________________________________________________________________
3 z& h. h2 h3 ?0 L# O- Z& N7 Z9 W% V* j
Method 11) n) K0 H" E# k& A
=========4 Y3 @, d! {+ B7 L9 M5 X. w
# H" |# C8 j% x5 Z0 m
This method is most known as 'MeltICE' because it has been freely distributed! f' q/ b$ b% P/ l- }$ d+ _* n& s
via www.winfiles.com. However it was first used by NuMega people to allow
7 K1 Z) P2 c$ Y7 s! G* pSymbol Loader to check if SoftICE was active or not (the code is located3 I9 Q7 I: t( U7 d- [, M& R3 v3 j% @4 k" ?
inside nmtrans.dll).
: P# Z% _& }9 w% D& a# I) N& M4 c
The way it works is very simple:% T1 h" L3 Q# x N" P2 n
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
4 ]0 }7 @5 l, ^" A+ U0 G+ fWinNT) with the CreateFileA API.
/ G4 r% a/ E: E( Q2 x: x8 f" M" O8 ^9 P: F
Here is a sample (checking for 'SICE'):6 L2 w& V# d; N- w
. `; Z& Q' O% {, z; ]7 eBOOL IsSoftIce95Loaded()1 O3 Q% l6 a+ f1 O
{
6 T4 X" _! ^) r e. f HANDLE hFile; $ J0 `4 p. U- P9 @+ v, H) p8 K+ z7 p
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,: @. o$ L1 j Y4 Q
FILE_SHARE_READ | FILE_SHARE_WRITE,
, M" K: e. T$ s/ P0 k; M NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);7 w- k( u, e+ V- Q/ g& l
if( hFile != INVALID_HANDLE_VALUE ). y( I) f* H+ k# x
{3 \8 g2 U8 Y. H, v2 H
CloseHandle(hFile);! k3 N7 L! ?% V" q u* d) { W5 a6 y
return TRUE;
0 H. Z" e( W" f }9 B% H- F. M! h0 q
return FALSE;
3 v! ~6 w. g% G: v$ u" f}
, [+ e1 q0 k9 m( g' U" R1 l; {# {5 w* {
- w$ T6 z) {# a$ ~" ~7 Z: N" fAlthough this trick calls the CreateFileA function, don't even expect to be
- }" d" Y+ L( ?7 I& qable to intercept it by installing a IFS hook: it will not work, no way!
$ z7 T2 x/ x, j/ t4 u1 e* ?In fact, after the call to CreateFileA it will get through VWIN32 0x001F; X5 ^$ t+ V- Y2 @
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)- ~" O) l0 ~% [7 {
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
' q7 ~3 F H( W Pfield./ |! D' o& W# G# C# D
In fact, its purpose is not to load/unload VxDs but only to send a
4 N/ D4 [/ z' G; i+ i& RW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)) k1 P) c: \* s0 u7 X) E
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
) D: ]9 n; v6 w* r8 g4 L! Q6 Sto load/unload a non-dynamically loadable driver such as SoftICE ;-).
. R: J t+ t# W- O; L& Y& ~" h8 Y6 rIf the VxD is loaded, it will always clear eax and the Carry flag to allow: k: `! }0 U- r ?; M/ F
its handle to be opened and then, will be detected.
0 _8 C# n3 |: Q7 |, NYou can check that simply by hooking Winice.exe control proc entry point2 }- F" ?6 r9 \- C L$ ]2 I
while running MeltICE.
# i/ d z! ?1 f/ I
" q6 r% ^$ M% y- {2 ~4 L6 X
+ c* ?: w I, ~8 N0 z, R7 I 00401067: push 00402025 ; \\.\SICE. a3 g& l. m8 j, W6 W. O+ j0 a. `
0040106C: call CreateFileA1 z4 | t' X1 V- B# u* V! v$ t. |1 v
00401071: cmp eax,-001
) ~+ u$ i4 ^6 y3 b 00401074: je 00401091
- P5 l: u9 z; C M* R% N0 q
/ D+ B+ G2 f! B9 g8 [) _) a
8 ^! ^* `* C# j- a* d k3 @% wThere could be hundreds of BPX you could use to detect this trick.. T' l- j8 b8 M; M5 r
-The most classical one is:( {8 I. Z3 e* i" c/ S
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
. Q0 a7 C5 B, C# i *(esp->4+4)=='NTIC'
: q) X1 E# y0 S3 p3 i& n6 N3 ~3 q8 D6 K% h( C" k( {+ p
-The most exotic ones (could be very slooooow :-(
7 ~+ c4 Z B5 F! z BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
, Z2 N) G7 z& c1 s9 r R0 V ;will break 3 times :-( T, b* S, S" t- ~5 E5 h4 A, e" R8 {: f
- s; p/ t* `! q/ H: a-or (a bit) faster:
T: O; b/ i. p# b/ i5 f& _2 f( U BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
0 b5 a1 c0 c. l: [( {+ W+ O* f
/ V4 a6 ]. R7 p. A; S3 @: i" Q. I BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
, P5 A' A! g+ p9 z ;will break 3 times :-( {* n0 z* L) a& }
* j5 \9 j+ _. f5 _6 M0 c+ X& {-Much faster: h3 `/ o3 d5 d( w; m; n) ?, `
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
) h7 r* p: u+ ^, S- t: y& s
' V1 k, h5 S: l- I! dNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
; ]4 H$ }; y5 Y2 l3 ^function to do the same job:0 x' L- W' E; x" u4 W
0 P) m2 o( \- ~, e4 W1 Z: ^ push 00 ; OF_READ
4 f2 a8 ~- Y/ A2 w3 T9 ~: L+ V mov eax,[00656634] ; '\\.\SICE',0
" N0 h, J- b! Z6 Z6 D1 u push eax
5 c9 p% M9 o' ?! Y/ C call KERNEL32!_lopen
) @) J* t8 `$ ]& ^& x inc eax
0 x* B+ _- J$ ^: T" _ jnz 00650589 ; detected- w2 ]1 K6 M/ ~* o* d" L
push 00 ; OF_READ
+ [/ G( W5 }4 c: j+ U* s. F3 V2 q mov eax,[00656638] ; '\\.\SICE'
3 `- N8 W! ?% @8 e6 z& i push eax
! }3 k3 ~9 @9 U' a call KERNEL32!_lopen
* G6 s/ \6 q; Y* g, x! l( U inc eax: ]% Z- @6 P$ D( m* y) B
jz 006505ae ; not detected
) G* h# [2 q( h) Y
1 _8 `9 h6 f5 m0 t' o7 o: A7 `" b, k" x T7 J) K0 p, n
__________________________________________________________________________4 U: A! X- c' N8 `4 r. i) T {
8 h1 J$ R1 ^! PMethod 12
* m+ C* c% q; p0 K=========: z; R/ V" g% V% V
4 L1 q5 b, J, {
This trick is similar to int41h/4fh Debugger installation check (code 05! _* S- i9 n* o& O+ ]
& 06) but very limited because it's only available for Win95/98 (not NT)* {( i4 o3 C0 |$ e
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
1 R) B* B/ v* v8 \: O: t* Q4 k P; w( _7 ]3 H9 t: d K
push 0000004fh ; function 4fh
% t3 Z6 I8 S# K5 h push 002a002ah ; high word specifies which VxD (VWIN32)+ z H: C& r* t l1 @
; low word specifies which service. W( x! x# s. ?" s. O# K
(VWIN32_Int41Dispatch)
! {! Z( b8 M1 |5 U) T; W call Kernel32!ORD_001 ; VxdCall
8 x- i8 S8 `0 x* B cmp ax, 0f386h ; magic number returned by system debuggers( r7 n5 e% V1 A' A; b+ Y
jz SoftICE_detected
# E W$ u% S/ G+ K
$ M" e9 q! M- i% dHere again, several ways to detect it:( K1 w1 P2 S) K; G0 |# j2 X
; s7 G: B h5 b" L BPINT 41 if ax==4f
8 |( Q# t- h5 _' I# w! J& K5 }/ p; d$ y- o6 y
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one' p( _! I" {- Z4 z* g, g
, r& r1 t& T4 l9 S8 [6 A5 p
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
! E$ ]9 m$ M. f$ U! Y0 J
+ M; }. A% ]% e [9 u2 B BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
/ F4 B, l, s# G( U% o
! ]" Y. \4 Y# o; N__________________________________________________________________________9 X/ v4 g+ U3 F( r4 `7 ?( ]9 g; W7 P
! ^( Q h* X( d R
Method 13
' S& l8 G% n& i0 X* S=========
% R" y' o4 ?3 s) V* ~/ W7 F( r6 S( q o Y. o+ k
Not a real method of detection, but a good way to know if SoftICE is
% Q# I6 A1 X) k8 s* o* t! y$ xinstalled on a computer and to locate its installation directory.
8 B% T; n* O9 T+ p: U" }2 p& k9 V; bIt is used by few softs which access the following registry keys (usually #2) :) i4 Z8 t4 [1 S/ h" R* t
$ b, c1 e y" [, c# y* y
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
% T/ G) ?# ~* L4 h" i; w\Uninstall\SoftICE
) B5 @7 ?) V" D$ T+ Y9 z% _! S/ g-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
/ \, z2 h2 V; ~6 W% N7 J-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion' M3 D* w; F: `. V
\App Paths\Loader32.Exe
8 ^5 O% {) r; e, D1 I% m3 H/ R/ Z8 L: L2 `
& a$ u/ U! S* o; m3 `* L$ vNote that some nasty apps could then erase all files from SoftICE directory
4 E* d( s! V( q# ?1 C6 o(I faced that once :-(7 r" @5 Y& G' C
- N- f% `& x. p4 t
Useful breakpoint to detect it:
, W9 D1 T/ t! g" N( l: w
6 B' V: y2 J% G" c& g( A0 \7 Y6 q BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
* Z$ C$ H: `3 @2 J
7 w9 k& L1 _2 S. L5 T__________________________________________________________________________- E% i7 k8 Q& a; N# i7 u- C
# ?* k' j' Z" k2 V, c
W$ C* m c9 j$ J/ PMethod 14 0 c- r4 R; z [7 r' z% U# _
=========
8 Y) E) B* V1 a8 x, t$ x- p) B' C
" h: \: {! k& L2 o# c2 E! bA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose$ Q7 y' }% {- C
is to determines whether a debugger is running on your system (ring0 only).
" @7 S' W) ?: f; h' Z/ N: b# j9 _9 S# b! N B N; Z7 l' ]
VMMCall Test_Debug_Installed
- O$ {5 z8 D; n( Z$ p- C# k& `$ r je not_installed, W- S) v" r& s5 v$ k1 C
# f; M- u3 f( z( ]
This service just checks a flag.
3 Y/ E( {* [/ M1 |$ }2 J5 P' E</PRE></TD></TR></TBODY></TABLE> |