<TABLE width=500># h6 z+ U$ o$ E+ M0 f1 K' N
<TBODY>$ V6 W$ N# e8 |& m
<TR>
! b+ p/ v0 O3 f! T9 N<TD><PRE>Method 01 1 H: G- O+ [- {, f7 F8 P0 T" j
=========8 @) l: a9 \2 B3 H4 v- r N( S
+ \1 z8 i3 x& h0 w# @, @This method of detection of SoftICE (as well as the following one) is
+ a8 O* Q; Q: H# m4 i9 U5 Zused by the majority of packers/encryptors found on Internet.
5 r2 m+ a, z4 |- q) {It seeks the signature of BoundsChecker in SoftICE1 b: Q- f& _" }# D+ Z6 R9 c% w m
2 K3 L& A6 W1 n: A) D! d mov ebp, 04243484Bh ; 'BCHK') ?9 ], l; X: I2 q$ J
mov ax, 04h7 K$ `+ j* g- g0 S. E$ C
int 3
5 c) s1 V& l+ w) e, ^9 o, p( d cmp al,4
6 U1 \0 Y6 {. G6 {. i5 d \ jnz SoftICE_Detected0 o/ `% ~* C5 | s2 O+ D
, I9 T# m. d3 ^8 }( q6 Y
___________________________________________________________________________
' Q* u7 ?! P" i: `, ^# ~6 `' i4 G/ G0 q# _, W9 t+ L
Method 02
$ x' {9 u, C8 k t# g$ F=========6 H2 s. F' h- a
" x5 v2 \3 L" hStill a method very much used (perhaps the most frequent one). It is used% H+ J7 S/ r- E# O% ~. f; H
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
( A4 e8 ~& u6 b( f9 cor execute SoftICE commands...' u1 W" Q2 j! _0 A! I
It is also used to crash SoftICE and to force it to execute any commands- \) G( C& n8 t; X( c5 h
(HBOOT...) :-(( 1 a0 P/ e, [7 b2 A" I$ E- Z V/ J
( H7 l8 G, Z m9 q" R& x- P% ]Here is a quick description:
8 Y- Q5 I5 A8 p5 f6 K-AX = 0910h (Display string in SIce windows)
; F# @2 R6 i7 g+ D+ o8 u3 S-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
7 d( z- V( E* |* m+ a( T$ o-AX = 0912h (Get breakpoint infos)
1 X6 S6 v+ m9 j* u) m-AX = 0913h (Set Sice breakpoints)
/ I2 |* N3 |. F9 J- _( x5 c-AX = 0914h (Remove SIce breakoints)
9 B9 I% U3 x9 F! T$ Y
* z" l' L* p1 C7 o7 F, jEach time you'll meet this trick, you'll see:) W3 i( i9 y* ~* h
-SI = 4647h, n5 D# }- e( t( I
-DI = 4A4Dh$ O# i0 A! q7 M
Which are the 'magic values' used by SoftIce., l$ R" d6 D* }3 r" j
For more informations, see "Ralf Brown Interrupt list" chapter int 03h./ X8 ^ o; T9 W, E4 E
4 p; c& i& `# ]: v' O: ?( [Here is one example from the file "Haspinst.exe" which is the dongle HASP$ ]% N0 o* Q+ k! X6 R) u
Envelope utility use to protect DOS applications:9 X- e K# |; P$ } Y4 o
) Y, G& J# b3 P3 [, w
6 S7 L0 @$ n! y4 U- m2 D
4C19:0095 MOV AX,0911 ; execute command. U; n/ k) ]8 N
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).. Y3 R9 M- z. o- i* P" ^
4C19:009A MOV SI,4647 ; 1st magic value.
: ?- x+ D1 c1 _( L4C19:009D MOV DI,4A4D ; 2nd magic value.
; \9 O* n0 Y1 D& r4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
# i2 G( r; ]) V* z: _ R5 {4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute8 o) r" n# p( c" I7 W7 J* `
4C19:00A4 INC CX! N( `; m, n) R2 G5 ~
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
+ H6 N, z) t2 J4 u! C+ O$ {8 e4C19:00A8 JB 0095 ; 6 different commands.
4 B6 {/ _4 y# m0 B4C19:00AA JMP 0002 ; Bad_Guy jmp back.1 r' s& M% R' ~0 E
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)& P8 L# K& F2 U! P' a% i
" j6 y' E8 S& L5 Q$ a- pThe program will execute 6 different SIce commands located at ds:dx, which
" k) ?) c( t& O0 Care: LDT, IDT, GDT, TSS, RS, and ...HBOOT.7 w% {/ `! G! s" e5 c
% D+ p/ }. |+ b( h" Z0 H7 U* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
) }1 ?) p6 Q; l$ x& R' K1 }% ]/ b/ Z5 g___________________________________________________________________________
, C3 X) M# N5 L8 G( x
% e+ g3 n" |- t: L( C w! M
- T b9 ?* C% }Method 03
$ V+ k8 t" [8 o$ t. V; A+ S! r0 ?=========
% V% ^; a- C S. Z+ a0 @
$ B: i! W4 w) ~8 w; s- |Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h+ _; M! m) {7 l8 h
(API Get entry point)
; v8 N/ a& [+ `4 D! }: l , O/ d6 n! V4 N) k7 z9 w! {
0 _" b3 v$ ~) Z3 u0 j% |- l" \, _ xor di,di
6 ]4 h9 P% x* A8 L mov es,di) g* }, k1 Y d0 u( B1 h! L7 r3 _
mov ax, 1684h 4 Q7 R; Q0 B. p# A0 \7 A" {
mov bx, 0202h ; VxD ID of winice! m' o$ e/ H6 i0 A% {. D
int 2Fh
+ W1 `6 ]/ Z$ D! w5 L mov ax, es ; ES:DI -> VxD API entry point
6 l5 d0 `! a5 K7 L1 C8 o _ add ax, di
9 Z* I+ X" x f, r3 A test ax,ax9 s3 K8 H/ N, u' D& |8 G6 g
jnz SoftICE_Detected
5 J# ], ^! {# K. F2 l2 d: a& ^
& N4 L p0 v( C1 ~ i4 i0 B___________________________________________________________________________
7 |: b O- x7 Q& d9 k+ J$ u
) B$ \7 h9 e/ Z2 ]( F' bMethod 045 p# o: b( E. S" W" m' s6 V* C7 J
=========8 u; d* L! C ^. i5 _ h! j( j
+ t$ c; ^4 V) t; L" z, z& R
Method identical to the preceding one except that it seeks the ID of SoftICE
$ V; _, h* S, t5 c6 J4 PGFX VxD.! m( G m: v; f0 ^) _
/ ~+ f1 W& M' k xor di,di
' w+ m$ k3 F+ h1 T4 I mov es,di6 V* x$ n; o3 f
mov ax, 1684h
% |, o# b( V$ U. t mov bx, 7a5Fh ; VxD ID of SIWVID6 {' T4 D6 L$ k, h; ?9 W
int 2fh* R8 P( s% T# ~( {/ c3 ]
mov ax, es ; ES:DI -> VxD API entry point/ i3 A8 L! t8 |( w
add ax, di# c9 t: y6 Q; {' s; e# {$ U
test ax,ax5 {: q; _, v% `- ?; B6 U$ v
jnz SoftICE_Detected3 P' ^3 k! A9 U5 f& n3 _+ ~
5 D- D6 q$ d7 v: c# ~' b! c6 @__________________________________________________________________________
4 C* }! ?& i& \% F( t% Q) n% r
/ W8 x( G$ s; D# T, _" D. Q; u7 ]- ]& G
Method 05
1 J" |5 Z9 Z1 |) a# B8 l0 C, V+ R=========
. d- _9 l8 G) d( \1 _: O, ]3 @% O
% J5 X. h' f% c2 k- g RMethod seeking the 'magic number' 0F386h returned (in ax) by all system
' s/ \: K6 J6 c* q7 |' j+ `debugger. It calls the int 41h, function 4Fh.
" ?# `9 G- J l1 t( ^There are several alternatives.
7 S+ i% \8 m6 v+ k$ N# @5 Z- h1 R
The following one is the simplest: I d- e' W* S. I( i9 `
2 B" G {5 ]2 g5 W% i mov ax,4fh& O$ {2 I. f! i
int 41h
4 B5 K9 j1 L9 p# O* O8 Q% ? cmp ax, 0F386
0 \- M1 [/ ^5 l2 N7 v jz SoftICE_detected
7 q4 \/ l6 G& ~2 e) o. V3 u; A# E4 ?, s9 a, |6 n* q0 _
& u& l; l* X2 t# Y0 e8 V
Next method as well as the following one are 2 examples from Stone's
1 ~9 ]# u7 L! S8 H& J"stn-wid.zip" (www.cracking.net):
' B" n* A k8 r1 @
+ Q( e. C3 U: } E% s% K, ? mov bx, cs
9 C- i5 [7 n$ L4 a8 K lea dx, int41handler2
6 ?% i& \7 U0 J: c$ v4 q# S$ _ xchg dx, es:[41h*4]! _+ Q- G* N7 N6 r9 ^
xchg bx, es:[41h*4+2]- m8 b" N, T9 B" ^" Z
mov ax,4fh) @ c, S; v" W Q
int 41h3 D$ t X- N) k/ b6 x! j
xchg dx, es:[41h*4]8 A/ n) C+ A2 k2 T7 F2 n, Y+ H
xchg bx, es:[41h*4+2]
' G4 c* A' G0 Y! ]( E. V cmp ax, 0f386h1 o# p, q8 ]* j" ?! i- z
jz SoftICE_detected! L( Q& ^" n, Q2 B3 q
; o( r& k b" c; e9 z7 |int41handler2 PROC
1 c7 Q' N. ]; ~- J! y iret
$ S; ?7 u' V! ~+ U" xint41handler2 ENDP
& ?/ M6 {! q3 P: N$ t7 r+ h: o8 d' j4 p
8 e# w8 p, H$ G! G_________________________________________________________________________
/ {) s7 c. @$ R7 l& W. w2 \
$ S2 V; n( Y: n6 X W; w# w7 V+ ]* B5 ]" T1 }6 X V
Method 06
# Y1 c( F! S% O3 l m! h=========
5 f: L# c8 W$ U7 h
1 q3 x* S/ ^. c- z1 v* O
" R; M! A: J: x! ^; |( I! Y) g2nd method similar to the preceding one but more difficult to detect:
$ q5 D+ z8 J( U* z n) f) J/ `% j2 D0 `1 `# ? D
5 E) q& @' w% ~" g r9 E
int41handler PROC
$ t" V0 }' Y) e$ G# x, I mov cl,al
& v" y4 L/ { U* X( m3 Z iret
9 C R% l1 _( U( ~) v4 y, {7 M- xint41handler ENDP+ {) |$ @! O6 @! E0 M: f; I% c9 q5 P
+ H, I# X5 i; c( H" j. ?1 |7 t5 t4 d$ |- _8 _$ u
xor ax,ax
. V# q' p$ T/ T6 o* Q) q mov es,ax; \8 H: u* r' r# V j! u4 B
mov bx, cs# R- K' B# P: z7 l5 ^9 v2 c0 B! {6 y
lea dx, int41handler, R/ t' Q8 k# w: s s3 Y
xchg dx, es:[41h*4]
' ?$ a& S: u5 L6 R- `4 a$ J xchg bx, es:[41h*4+2]
( Q* D! [, \5 n# E: n" W$ f9 A5 Y in al, 40h$ ^8 {7 a4 l9 E! u. m4 ]
xor cx,cx' E! L) ]7 J3 B D4 f/ M
int 41h
0 j5 \$ {, e5 x, ]7 q xchg dx, es:[41h*4]( e- P. N8 B7 D' W9 i
xchg bx, es:[41h*4+2]
% p1 E! T3 }+ a- A p* @8 B# C cmp cl,al
d8 R# `! g( v: @' m jnz SoftICE_detected9 G$ U3 }! ~" S- }' D8 d
" x8 V! |7 S q- X! ]5 {
_________________________________________________________________________
4 m' U f# ?' ?, {' w
; A( h$ ?5 d; A/ QMethod 07
% n& T5 @+ S$ `- O* N$ f& z=========
2 D8 |1 _/ E. W4 g9 E5 V- H/ R/ }4 K5 t7 ?
Method of detection of the WinICE handler in the int68h (V86)
) n, e5 I3 C" S8 q5 P3 c0 f1 O4 [7 O9 D' v
mov ah,43h
0 @' i/ g2 I" O3 S/ w int 68h" C/ h3 A3 r2 `) u8 Z
cmp ax,0F386h
8 R: V* ^) r, J* ]; a% M3 h jz SoftICE_Detected
3 e+ i; `# h, Q1 u" M; W7 ]4 ^8 l! \; e- |" h
9 d$ j7 \ ^; B
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit/ ]; ~* {2 B; { f
app like this:
4 F% Z0 d/ g- y3 \5 |( X
2 o6 f6 ?' }, c/ I: d/ t/ W& O BPX exec_int if ax==683 m7 P% ?7 y. W8 O' t6 q
(function called is located at byte ptr [ebp+1Dh] and client eip is1 @) U) K. b+ j" }- X( {
located at [ebp+48h] for 32Bit apps)
8 u9 f! u4 _& o9 f8 i* _" P__________________________________________________________________________0 i# Z* W- h" `7 i
: G: W& A9 o8 O: v5 Q$ N
A1 B8 t3 \$ [0 z
Method 08# _" k, k- m- B+ e4 C0 d' n
=========
5 N1 ]* \# e3 D, L' G& Y7 Y: a+ R3 @( G- g& j1 u4 B
It is not a method of detection of SoftICE but a possibility to crash the
, K! D2 P, z: Msystem by intercepting int 01h and int 03h and redirecting them to another
0 \+ t( }- Q l. ~routine.4 k* F1 H% }# r6 m7 g
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
& \+ r' @( A% |( Eto the new routine to execute (hangs computer...)5 r+ |7 c, w6 e
" K) y/ w% ~5 j1 U. e mov ah, 25h
: F! k# _- l' O7 h- f mov al, Int_Number (01h or 03h)* f# u4 D% s3 T4 l3 n( b
mov dx, offset New_Int_Routine. \5 m. T) t9 S, |3 h3 o
int 21h- a5 N1 M/ D( p
# A* k& {4 l4 }. |* C__________________________________________________________________________( l& ^0 @, a1 R" `0 _, ]
6 r. H" J# i' T7 }5 vMethod 09
3 @) Q" Q+ O# n, X- b=========
5 r$ X" L$ l7 w! Z$ Y! j2 d! v; F1 [ i6 Y
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
/ \0 _% ~8 [! Q$ mperformed in ring0 (VxD or a ring3 app using the VxdCall).
) [/ z" b7 C% g2 q2 P) K4 D$ WThe Get_DDB service is used to determine whether or not a VxD is installed
7 E( s. i5 @- @' f# ?4 @9 Lfor the specified device and returns a Device Description Block (in ecx) for
) W- K/ n: [" P' nthat device if it is installed.
' y* l0 D; F \4 ^" L' D2 ^7 t+ t
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID0 `3 K1 I: N2 C9 X
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-) \& s) i6 h8 t g# d, F
VMMCall Get_DDB
7 |, N4 _8 ?5 M! x& y& n1 t3 K mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed2 y w- \, h, G$ c
4 \* \& y0 }+ G: H) r" {# ?$ Q
Note as well that you can easily detect this method with SoftICE:3 x- t) X; t' a$ ^3 O; m& }1 I8 K, F
bpx Get_DDB if ax==0202 || ax==7a5fh' N7 V4 v4 D" c' w
8 j% v7 A* k; o2 l: r__________________________________________________________________________
6 l7 B6 Y5 d' [: O- }9 ?( a- d
# y2 {: B9 f0 J9 n$ X( vMethod 10
) @, O! F; G$ J5 e; l1 i=========5 [; m, ^6 j) g" C
4 E; {/ ?, q+ C/ p! \9 k=>Disable or clear breakpoints before using this feature. DO NOT trace with
# ]& ?+ r3 w8 s SoftICE while the option is enable!!' x; K8 ^& H- o
! m% t$ S) [* z4 }, M- y2 D
This trick is very efficient:
g, H% S8 i* ^( C5 @( C; ~& `by checking the Debug Registers, you can detect if SoftICE is loaded
" x5 `$ z- n5 B7 [7 g, ](dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if2 {2 Z. c6 ]: X ^1 _ y
there are some memory breakpoints set (dr0 to dr3) simply by reading their
: O) B; i9 k5 V$ i; |: [8 Hvalue (in ring0 only). Values can be manipulated and or changed as well! c1 L5 t! A7 f! a% X- Q/ Z6 R$ h
(clearing BPMs for instance); n% `! i8 {) N7 r" ^
% g1 c7 L; f$ J8 r+ v( j__________________________________________________________________________
" U) G- |2 v& x+ K7 B
" ^' \; m& M8 Q6 m7 YMethod 11
( L8 n0 a* M3 r* V: P4 g( I1 j3 ]=========0 y+ q: z! ?, u- ]& Q4 U
, I4 x/ J @6 v U, fThis method is most known as 'MeltICE' because it has been freely distributed
6 x' E( R9 A6 H/ \( u2 n! I2 Gvia www.winfiles.com. However it was first used by NuMega people to allow
; `1 J+ n9 j5 P; J$ R% T/ KSymbol Loader to check if SoftICE was active or not (the code is located
- c% Z+ x s8 i4 D5 Qinside nmtrans.dll).
2 T& `- m/ {0 }: s
/ {' x! E1 O& DThe way it works is very simple:, L) V2 F& `2 w* _* s
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for8 X: N* Q1 x- `4 |, ^8 ~7 @& B6 E: P* E
WinNT) with the CreateFileA API." N c/ Q; d$ @5 T, K3 \
; O, Q: v! K8 sHere is a sample (checking for 'SICE'):
; n0 d; q2 @/ M: [: @+ t
: v; i9 x: M: T" A9 }BOOL IsSoftIce95Loaded()
: e: x0 m0 t1 t{8 y9 m" w* [) h8 |0 K8 S9 Z
HANDLE hFile; $ P9 Z8 L& H% c" W) i
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,4 I& E! j C$ P. N' t1 P$ N4 X% B: B& F
FILE_SHARE_READ | FILE_SHARE_WRITE,/ u+ B* ], W1 j. f8 e2 |3 F D* B6 W0 ]
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);: g( S; k x g) {; v
if( hFile != INVALID_HANDLE_VALUE )7 p) ]& t b; `* c5 w( ]# f
{; q' y3 Q0 i. g: t
CloseHandle(hFile);
6 j/ ]5 I1 r& ~4 w0 \ return TRUE;
+ |: I+ D6 H8 E }
3 p" t7 Q( r0 E3 f0 ]. M return FALSE;' F4 f6 K7 W. F
}
) M) N; \9 d8 ~( Z
& R( o# L6 W1 ~* vAlthough this trick calls the CreateFileA function, don't even expect to be0 p- ~3 d4 A5 L$ C; h9 f& a: X. x
able to intercept it by installing a IFS hook: it will not work, no way!
$ H/ O( `. ?+ S8 r2 `3 EIn fact, after the call to CreateFileA it will get through VWIN32 0x001F8 q% v+ f. W0 |# J2 v; X9 M" h0 \- \
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
$ n! ^2 d9 K; Z5 i: x/ Uand then browse the DDB list until it find the VxD and its DDB_Control_Proc3 k) u; ]. |* n
field.) X0 w# D! Q0 l/ ~! T$ b- L8 j# |
In fact, its purpose is not to load/unload VxDs but only to send a 7 E. [- ]: W) X' S5 {! N$ y/ o
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)) N9 D& {' A. D" v, T9 I
to the VxD Control_Dispatch proc (how the hell a shareware soft could try- w% N; Y3 T1 d0 q! @) @! R
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
$ L. F# O- M0 PIf the VxD is loaded, it will always clear eax and the Carry flag to allow
" U+ D% R) s2 Q; J) U" S: Lits handle to be opened and then, will be detected.3 a. E/ T! ?* a
You can check that simply by hooking Winice.exe control proc entry point
( n7 ^& f0 O1 E1 Dwhile running MeltICE.
3 U6 c) k: v5 W' Q1 q5 V2 f8 O: {" I* R+ S
9 m. _# \/ H' G6 P+ O, b
00401067: push 00402025 ; \\.\SICE
8 J" Q8 Q& P5 x: a7 V# b( l& N7 ] 0040106C: call CreateFileA4 |6 g/ E8 Q( N0 t) x/ y& R
00401071: cmp eax,-0016 }* ^$ ?2 j; h, B d
00401074: je 00401091
! o( i. l; W6 P- E+ f* p% a
3 T9 S8 N; q: `; x( c# |, G- @9 s7 T5 a- n4 n* h" g
There could be hundreds of BPX you could use to detect this trick.
6 v4 w+ m* c+ f3 J& ?8 v-The most classical one is:
! z- U6 J( \1 m7 x6 j& } BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
, x/ ^$ p" P% _! |: d$ B; @ *(esp->4+4)=='NTIC'
b! Z7 F8 F3 }6 P, v `' {( A, i
: n$ g& q+ A1 K0 S3 S/ K-The most exotic ones (could be very slooooow :-(
@/ s% u# y% q' J BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
" K: R- m- z! ` ;will break 3 times :-(
" R1 R$ W- P5 E8 ~; |1 n, l! c
7 A! h/ I2 N$ I- Q-or (a bit) faster:
" r0 V4 |0 w a9 M) Y BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
0 |) _' ~1 |$ H/ j* Q3 K- D+ @
' g. v% Y4 Y4 s' _) j/ H$ p7 }* H BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
2 @0 v/ S) Y, [) b& Z) l! i ;will break 3 times :-(
8 h; i8 F, r- T8 j) F( p4 Q( B( p0 p3 d- H {3 s1 w
-Much faster:
" w5 d$ L* h. e( U n- [' r0 B BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'7 J3 D4 G o+ ]
6 E+ z' Z! O$ y3 }5 Q
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen! K( i8 d" r$ R2 h4 o& ?0 _ a3 s4 D
function to do the same job:
& N$ R w% }7 r6 M) V% c- t6 m2 r7 L. h7 B7 Z
push 00 ; OF_READ' d* V" |: @4 T0 D
mov eax,[00656634] ; '\\.\SICE',0
+ R* b# I9 B5 k& z! }0 t push eax+ w6 k0 i3 T- L, L
call KERNEL32!_lopen
) Y6 W( y# [4 S3 D9 x) A9 w inc eax
, U# V; T# S' a' f* e$ l jnz 00650589 ; detected3 y( h# b' I) b* a, Q# g
push 00 ; OF_READ
& g; C' {3 G8 b# k mov eax,[00656638] ; '\\.\SICE'( ?& f3 W |& A4 }3 i
push eax* ]4 O ~! n' B3 H, F
call KERNEL32!_lopen
( r# w( f6 k9 J" b inc eax
# a$ }7 F0 Y/ v0 V' X: R& u jz 006505ae ; not detected x& B8 S9 x H' U* H" A' q
$ r6 s. I# z6 T! G0 U. z9 ^" g3 q. L
/ S4 K% z- ?6 ~) V' N. d
__________________________________________________________________________: G' ^% _, `5 v+ Q; Z
% T8 I' G4 i! l, t2 i
Method 12
4 D/ Y; j( V9 f1 {=========7 U0 s5 E# l0 Z
2 Y4 B" d0 ^, g" zThis trick is similar to int41h/4fh Debugger installation check (code 05
- J+ x, B& k1 f0 |7 m& 06) but very limited because it's only available for Win95/98 (not NT)
. f# C& P/ p5 W# oas it uses the VxDCall backdoor. This detection was found in Bleem Demo.8 v1 W4 v, l, ?/ L
& u4 g! a; m' E, Y& E push 0000004fh ; function 4fh
% q9 J3 r( a: b push 002a002ah ; high word specifies which VxD (VWIN32)
% H$ u0 I% i. S- V/ q' d9 K ; low word specifies which service$ D! t8 n9 K# v8 h6 g. I; ]
(VWIN32_Int41Dispatch)
$ R* Y! T" `1 _- J call Kernel32!ORD_001 ; VxdCall" Z- g* |2 p- ^9 r, [
cmp ax, 0f386h ; magic number returned by system debuggers
" s: l% j5 {6 B$ \5 m$ ~ jz SoftICE_detected4 E0 s. ]+ R2 f9 q
* _5 t, j3 p: C5 L- T
Here again, several ways to detect it:
( v7 J0 b0 \7 J) O. B# o1 W6 m0 v5 ~" f
BPINT 41 if ax==4f& k9 M% h! `# i& v# e, i
$ \8 m5 I9 N1 A8 ~, G
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
% F6 _3 D* f4 _' v. q |# _9 z& A. h8 A9 x/ g$ K. w1 y
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
( a( B* m, o$ E9 Y: t3 F6 i1 V& Y! m3 f
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
- U. k0 }) v' w3 \7 R3 [5 Y8 f, S/ j8 Q0 g5 P1 b9 D
__________________________________________________________________________' i8 x b3 w6 t$ |- ~
/ T& k: z: u, u+ L5 kMethod 136 i* R, {5 R$ T4 @9 \8 B4 d
=========
+ ]; y4 V7 P9 G- J* v" C( p3 U1 m7 i: S1 m2 R
Not a real method of detection, but a good way to know if SoftICE is" Z/ L9 H' Y9 m* O
installed on a computer and to locate its installation directory.
* b. _2 D# e5 o0 `0 p% V0 wIt is used by few softs which access the following registry keys (usually #2) :
7 K& o, l5 l8 q D
+ K& h6 R/ H. z* ~-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
" S0 O6 g0 S7 S\Uninstall\SoftICE
+ R+ {; S) y; B6 l: F J8 N-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
" c( [1 S- p# E/ t8 `1 p& ]-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion, z2 J, `: s `, ^1 n2 I, W* W
\App Paths\Loader32.Exe$ L$ i* v: u* ]" r9 I2 H0 c
: j9 [, i0 v3 D8 e- Q9 F: z
/ ]6 O- V3 Q- c4 _
Note that some nasty apps could then erase all files from SoftICE directory
/ v- Q8 @/ N. D/ y3 H A9 V(I faced that once :-(
( V# @/ V7 ~9 A* L8 x
/ p# b1 T! R9 `" I9 o( [Useful breakpoint to detect it:# A9 T ~, K1 e/ a6 B& e
: Z. X. c$ O; n9 c& Q BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
9 t# K. N& \& f& L& c( T& \1 P/ c A4 s, i8 ]
__________________________________________________________________________
; Y( v4 k w2 \
! @! I0 V4 ?7 W: [4 m3 |; Y- o/ x0 @( z3 N- D! H P) D' J. |
Method 14 # I1 ^: V8 e0 S, _/ {
=========3 G) W8 f* E8 c0 _, v3 S& Q! \# R; ~
+ j c: L& \1 d) r( O Q) a! tA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose2 C8 n' l$ _' f% R* C
is to determines whether a debugger is running on your system (ring0 only).
2 [) \5 V: m0 J4 c, }3 [ X; G4 K4 j
VMMCall Test_Debug_Installed/ ~, i- E4 n; ~4 R1 V# a7 {
je not_installed+ Z7 k. Z+ c" q; c6 G" a0 t" |
1 R$ g) {) Y9 t7 n
This service just checks a flag.
, f* T3 A! K$ j</PRE></TD></TR></TBODY></TABLE> |