<TABLE width=500>
3 Z; }/ J. \- J6 B O4 q<TBODY>
0 D/ ^+ m U/ N; ]- c: W" X# m<TR>
2 d8 c* U$ m8 P! j% x% u9 o3 F9 M<TD><PRE>Method 01
0 c( h& @. Y- x2 X0 R6 Y/ N=========* V. C7 |+ O8 |7 B7 F
, n( C$ q% T7 J3 K
This method of detection of SoftICE (as well as the following one) is
4 y7 d- J& T1 K$ ^4 Tused by the majority of packers/encryptors found on Internet.& S h$ |3 z- @) f* E
It seeks the signature of BoundsChecker in SoftICE
7 z# m2 O t! p, h' n
+ I) m3 f: ]8 ^ mov ebp, 04243484Bh ; 'BCHK'
^/ G3 P: f* i: U mov ax, 04h
5 q2 V: A2 E$ R7 Q# X, e! D int 3 - ^4 _6 ?' q1 l' ^5 Q' v) A
cmp al,4
# D/ _4 j2 n, ]/ H* @9 G jnz SoftICE_Detected+ t" X$ f0 A! h0 b: Y7 g5 ^. M/ n
& Y5 p7 O! C, P3 G ]- N1 \& n___________________________________________________________________________6 \# Y3 J% g; g% H& A
: [* P2 O& ~7 GMethod 02
9 G2 T# {* H$ t: K4 K=========
- M9 X/ w- h7 i) y" d( w7 C9 W3 b7 {5 G6 O2 P) H& ~4 a
Still a method very much used (perhaps the most frequent one). It is used
0 x* {4 Q0 e8 P) ?8 z" vto get SoftICE 'Back Door commands' which gives infos on Breakpoints,7 w( L; w' l; m: R( H( G
or execute SoftICE commands...: j& X2 ^* {% ^6 F+ t# L
It is also used to crash SoftICE and to force it to execute any commands
4 i* ?- T- ^" \/ x, _ r(HBOOT...) :-((
2 X/ Q9 V' h. i+ Z7 X
9 K& f, q I+ [( g, Q3 K9 w! a- D6 ?, FHere is a quick description:
2 r7 ~, o9 H" d+ [# s6 M, g+ L' _-AX = 0910h (Display string in SIce windows)# Z7 Y0 X5 ^0 {# ^( x8 v" y& T
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
" i' E. W. A7 {, C% X- O-AX = 0912h (Get breakpoint infos)
/ `" {7 j5 M# r8 q-AX = 0913h (Set Sice breakpoints)6 O9 R: f( O q1 |
-AX = 0914h (Remove SIce breakoints)
( j& K! `/ R' U8 D: b$ I
+ S4 d# }. A0 Q1 h& T) P0 tEach time you'll meet this trick, you'll see:" P& _# u& S- z/ W% Y
-SI = 4647h' i, V) E( O# i+ O; i
-DI = 4A4Dh, ?* v8 W1 e* r- e% l" f+ A
Which are the 'magic values' used by SoftIce.
0 N, Q H) _" O- wFor more informations, see "Ralf Brown Interrupt list" chapter int 03h., E2 V8 L! J9 u5 M2 ]: u
3 j) P% Z. }) r2 M/ D7 m, p& o$ L
Here is one example from the file "Haspinst.exe" which is the dongle HASP+ u$ Y+ Q+ q9 d, i+ u8 i) B1 o
Envelope utility use to protect DOS applications:% `$ u/ g" D- a. g R" y
) G! ^ m8 n4 F v
3 ]; V& W* D6 ?: _* T/ q4C19:0095 MOV AX,0911 ; execute command./ e( t2 `& b& t4 L/ ]
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).4 H) i4 J* t/ x3 x" D; e
4C19:009A MOV SI,4647 ; 1st magic value.
; z, ?8 h' E* O: b' I* y1 q4C19:009D MOV DI,4A4D ; 2nd magic value.
' d& Z3 ?, X) B. R& l P0 d4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
6 W' e) f0 d4 V& u+ a7 z4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute% j# M! {) M( e* T2 f" L
4C19:00A4 INC CX
8 l5 I' t# }5 u! r4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
& A/ y0 v7 ?! b' O( v7 z' r4 X4C19:00A8 JB 0095 ; 6 different commands.
/ [ M5 ^1 ]9 n6 p3 O' t) ?0 ^4 @4C19:00AA JMP 0002 ; Bad_Guy jmp back.
% B3 F( o' Z# \0 _$ C, r3 {4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
% K* V+ {2 w# c
3 F8 ^2 \# v, q6 Q- I MThe program will execute 6 different SIce commands located at ds:dx, which: f2 A8 V9 y5 B$ s" J
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
" v* \- [: h# s4 ]( t
9 `4 H3 {& ~( {' ?- Z9 m, X& v4 L+ O* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
7 H7 T/ ^0 {* K; C- ~- o9 e5 e. Y6 i___________________________________________________________________________
/ K$ ^6 a7 C) m; _2 s9 [1 E! Q a# h1 U* a) D _) b2 L
1 W% j/ \, ]6 u r4 |9 R& Z0 l' yMethod 030 m5 W# [& H! Z" W
=========5 Q( a7 A m- E
) j, d, b" q) h" x6 m3 T% { c
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
$ {% Q" M# M* M(API Get entry point)- s# q; V4 m' N# Z7 g F4 Y, l
! d5 L& ]' c9 I3 }) ^5 k5 {, {
! i1 Y. b w, Y) v3 S* f4 A- s xor di,di% Z9 {7 Q f, n
mov es,di/ W$ a0 |& B% A* t% q7 q8 b% }
mov ax, 1684h
! P. E& v0 D" q) j! j9 D+ g2 } mov bx, 0202h ; VxD ID of winice5 k0 t4 y3 F ]5 L/ n. m. A
int 2Fh2 V" S' {6 U* k1 B; o2 |
mov ax, es ; ES:DI -> VxD API entry point
( A+ `% Z( l9 I% z# } add ax, di
( H% K: ]9 U) t; N4 ^2 ?6 H( g% U! C test ax,ax
8 \# r1 S% g# n$ Y2 T* k& `6 J jnz SoftICE_Detected
, |4 i" c j/ `( Q3 P( @
0 L" |* x# W# p, m___________________________________________________________________________( V9 ? T- W" N2 r' ]* L# b2 K
# q( e6 ^7 Q1 i$ \2 s( N. H
Method 045 F& R8 f9 I0 H* c3 ]$ E v
=========$ J5 O& J6 V1 g5 X- F- D1 X; n$ f, w3 O
( ^7 g. ]8 `0 ?/ r: I& _Method identical to the preceding one except that it seeks the ID of SoftICE
& q( P; \4 U. \ O: [+ \3 mGFX VxD.; \5 F0 f( P9 |8 D& v
2 p3 k/ d: Z6 f, w! q. j xor di,di
; U5 T: e! [5 N. V6 K8 L( s2 [ mov es,di
9 y: t6 _5 T6 v+ a+ m' T5 J. J3 p mov ax, 1684h 2 a3 _2 h$ M; N; L5 k6 w
mov bx, 7a5Fh ; VxD ID of SIWVID0 [. @! ^4 b6 y4 [) ^0 B& q
int 2fh! g% ]7 X& f2 S: t
mov ax, es ; ES:DI -> VxD API entry point8 y$ H, P. T" G8 E$ y1 p
add ax, di3 p: S- @1 K0 s6 |- q
test ax,ax6 a+ N$ z/ b* z: a1 q! o: M) _" \
jnz SoftICE_Detected. k) ^3 i2 N5 m% r/ b
- { a1 t- a5 `5 a. |
__________________________________________________________________________+ d& {. @) {+ k* g {- w. q+ [
. w$ v4 h i1 @: o4 @
5 o8 _! u2 |1 j0 V" ?+ e0 i% }
Method 05
4 `$ i# x6 _; g# {- ]) b0 ?" s=========
# p, K0 U9 ~8 R. v- F, @, M, o
M; P! Q5 o" M6 j8 xMethod seeking the 'magic number' 0F386h returned (in ax) by all system* \7 v( u- [1 Z: j% K' z7 i
debugger. It calls the int 41h, function 4Fh.$ o1 ~! _: W; S6 d" [
There are several alternatives.
Y- w! T* X4 D" P/ M) k3 g: l4 U0 U0 y# _
The following one is the simplest:) R; S; k( S9 r, T. ~3 p9 C& ]2 Q4 o
# d( i3 s5 w6 {" q2 H3 U mov ax,4fh. R j2 D7 n& l; M2 \% N5 R! z c
int 41h; g" R/ n4 P7 h3 Q5 ?* u8 u( ~
cmp ax, 0F386
5 y" l" H5 d; B0 P, E" h jz SoftICE_detected# I' s4 e+ c- S5 d
! h+ U" [( B2 f3 s. o
% c9 n6 z' ]" ^Next method as well as the following one are 2 examples from Stone's 6 P% f5 _8 } [
"stn-wid.zip" (www.cracking.net):
3 V# n; K$ ^) m2 \' T# R) A$ h5 J; a5 h _9 O# N
mov bx, cs8 p# }- a2 M, e" W7 y1 |
lea dx, int41handler2
' ^2 j# b5 p. Q4 f0 ]$ m* R) q, h xchg dx, es:[41h*4]
- }& R! a& n$ G( L% ]3 l xchg bx, es:[41h*4+2]; ~0 ~% Z5 {/ A; R! k3 L
mov ax,4fh
7 ^, i% J1 W% t+ F6 F1 T int 41h3 a- m& a# M2 F, _1 {
xchg dx, es:[41h*4]
; K" J9 J0 `* j) H3 I# t xchg bx, es:[41h*4+2]
/ Q* e9 d: C9 J4 x" x1 A d0 T cmp ax, 0f386h1 X1 s: d3 p' U# E
jz SoftICE_detected
7 u" F2 F& H% I/ i' p/ O% i
2 x3 t( ~1 R9 j2 [* Cint41handler2 PROC
L. N& k# f) t- A/ i* N iret
$ \' z" L9 S& u k' A, _1 v5 lint41handler2 ENDP
- d& j; g; n* @6 r& P3 o: q
$ F: u0 I2 x8 w* {$ B* D$ ?% Q* s1 C
2 _7 N7 g( ~5 g+ D_________________________________________________________________________
8 h+ L8 W3 c# w1 M7 e+ e* M. j+ ?& W V* g& Y0 {3 z# Z
5 q) n& F' i5 m* [+ R: P
Method 06- U1 N& j. [. R2 B \& ]! b5 Y! l
=========4 v- G2 [& `" T" M
/ T2 ~* Z% t: W* s- H
' U* q2 H$ B4 z5 B1 J7 Z2nd method similar to the preceding one but more difficult to detect:
1 x' C% P# ]$ ]
. z: b+ \& |/ k& O. _1 U3 m
# ?" {) n- S' Gint41handler PROC+ w( z$ n5 p% x2 e- ]& C
mov cl,al
6 I. H2 Q9 G! E6 j/ V/ e) D o iret
- G% V, W& C0 \8 L7 eint41handler ENDP
) I2 ]# `* A3 B( S3 G' a
" ]8 s6 J1 z, d3 t4 q$ e! `, [* I n s+ G% B
xor ax,ax
5 b# ~8 T. i9 D+ V4 k- H+ [. I- g& F mov es,ax( p7 i7 t2 V# t; {4 {
mov bx, cs
" d8 ? F5 e$ X5 Q! N6 i9 @ lea dx, int41handler
) _7 b# z+ }, w% d. m xchg dx, es:[41h*4]' ~) t/ a! q8 U. Y
xchg bx, es:[41h*4+2]$ _; Q7 Q& M% O
in al, 40h @% r. H# W& ?' b/ W* v
xor cx,cx
4 Q4 i" f0 m" T- i0 O0 x. n8 I int 41h
* r5 J8 d1 `7 U2 C- E" ~ xchg dx, es:[41h*4] a& S# ]2 {& y x2 y
xchg bx, es:[41h*4+2]( E+ y$ d- _5 i
cmp cl,al
; }% p w$ A/ m, A% l) m$ J ^, L, _ jnz SoftICE_detected
4 m4 D. m0 W/ d0 f* X8 |: L6 c; |5 t8 N
_________________________________________________________________________' e) U' s0 E- q, o
7 ?7 {( A" N2 ]+ VMethod 07. K- x1 d ?' p6 K' V4 p' ^- o5 V
=========
, K" U+ `2 x% J, ]( `; E
; U- _- X; m5 Y- R4 q6 JMethod of detection of the WinICE handler in the int68h (V86)- M2 A+ y$ U: m' C! Y: e
* I5 }5 X- X* ^/ m1 U9 ]
mov ah,43h
3 N* ]% O1 f! s8 ~/ R7 i h int 68h( p5 v v" A3 }7 c5 e
cmp ax,0F386h7 R' O( G4 Z1 a4 h% `# |- A* F2 \4 h
jz SoftICE_Detected9 G [/ U+ I' L0 Y
) Q/ n/ y/ e% V6 r. Y
9 |/ l$ f$ G/ c. i=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
) v2 Q i2 W1 l# o' ? app like this:
% x5 N! e: C: n, |0 k9 n
( ~( U, H% I0 s' Z! w4 U- a BPX exec_int if ax==688 h, s" E3 N( k- Y
(function called is located at byte ptr [ebp+1Dh] and client eip is; C' C5 e- K: ^" d1 \% Y! _
located at [ebp+48h] for 32Bit apps)
; {: A% }/ K! ~__________________________________________________________________________
# o/ u) m9 D, W/ x8 G t4 u$ w, }: \& P7 @9 ]9 h
' q. p6 I0 X8 {8 v% k( g
Method 08' t8 y/ l: D% G5 |
=========3 J# ?5 F8 I! m5 v% P U \
5 x- M# Q" h. Q5 @. K# ZIt is not a method of detection of SoftICE but a possibility to crash the
T/ `8 A! S0 p6 z7 Lsystem by intercepting int 01h and int 03h and redirecting them to another @6 G# q5 b) X. ~2 u0 O/ ~
routine.
+ f9 S( X: h' OIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
7 [9 n0 O/ q" A2 i3 Wto the new routine to execute (hangs computer...)
- C# w9 L5 E4 Q2 u: a& M' j
! p. `) p# i: K mov ah, 25h1 K" _8 O1 ~0 `( L) Z7 r
mov al, Int_Number (01h or 03h)! y* `$ J& g; U# G% b2 e$ r0 c
mov dx, offset New_Int_Routine
D2 X2 }7 D+ _2 w" t% b5 { int 21h) y) w) q) q# q
$ O, t' d$ X4 k3 O7 a7 c* V$ u* Y__________________________________________________________________________
3 Y! Y& Y4 g4 f! _+ ^! A6 {; P! k c1 ?6 j% \, Z
Method 090 r& g: M+ Q6 b1 [* ^
=========
( [/ D* a7 L% G9 Y% a. R- P! J& A9 g" Q1 J4 g- |6 c
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
" F0 U0 ]% @& _, F& V. X# D( I! zperformed in ring0 (VxD or a ring3 app using the VxdCall).% o' P3 Z8 Z- z- v1 T
The Get_DDB service is used to determine whether or not a VxD is installed
% A: Q5 y) T# p0 T" G! R& Z D2 Q' ~for the specified device and returns a Device Description Block (in ecx) for6 E, e# x& d& @9 R* v, M0 l
that device if it is installed.
( r1 s8 F+ B/ O2 r( m9 [+ T8 p/ G( P
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID; A# P% C& M: F
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)0 j/ [! \+ L2 M1 n% j
VMMCall Get_DDB9 `1 w0 |! S+ G: g) C" @
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed. l- B j) G0 s3 M% W
- Q7 u/ M' g# M( c+ s, {$ J
Note as well that you can easily detect this method with SoftICE:
6 H0 r4 j ^5 n) h bpx Get_DDB if ax==0202 || ax==7a5fh: Z/ t0 o1 M+ @; Z. m
- U) O8 d* C7 g z9 \
__________________________________________________________________________8 N' Y; a0 f3 k- ?# O0 d) x/ g6 [
+ O8 b/ C( G1 `% R
Method 10! a: ~& n1 r! N* v) F$ F
=========& b9 H) i% C9 c* y4 }& u
: y6 i, [0 K/ C7 q" i- f/ K$ A=>Disable or clear breakpoints before using this feature. DO NOT trace with" u( {4 q' y* {( f; ~' C+ ~3 a7 c
SoftICE while the option is enable!!
. @. l9 n5 D6 U7 M$ V" ^/ l8 @; R3 k: I8 I8 s
This trick is very efficient:
$ t: ~3 _+ {& i" d- S2 q' rby checking the Debug Registers, you can detect if SoftICE is loaded+ l7 }1 s0 ~8 l: e* t) x
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
# l- c7 G4 _0 ythere are some memory breakpoints set (dr0 to dr3) simply by reading their
5 x- D! u5 q N0 u6 U Dvalue (in ring0 only). Values can be manipulated and or changed as well/ {0 F8 Y$ }1 F( x! i; E
(clearing BPMs for instance)
; P7 w y5 X. A# [0 K6 j6 ~- C; H9 ?
__________________________________________________________________________& M# J% ^ d: W& C& m3 ^. k0 }
. k2 Y, ~( q) r8 a1 h) X* e
Method 110 `) }# p1 F) L' @4 w7 A4 F
=========
5 z9 I0 L8 }( X0 g) X4 V! Z
2 L) e1 i( A% n$ _: ?This method is most known as 'MeltICE' because it has been freely distributed% \2 E8 k3 ^% ]& Z( d' Z+ {" y" n
via www.winfiles.com. However it was first used by NuMega people to allow
) N3 V, Q0 O4 |6 hSymbol Loader to check if SoftICE was active or not (the code is located* b& ~0 S! {% K3 B- E8 m) M+ y+ V
inside nmtrans.dll).
. R- q2 V+ Q& b, V6 |. n
# |; F- A& Y8 P4 N {5 b& BThe way it works is very simple:" [3 ~2 U9 \" D. Q& e" H/ a8 O
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
) `, N9 R8 }1 r! Q3 q# ~/ u- S( GWinNT) with the CreateFileA API.
, p& L* Z. D, `6 x' Y! S+ ]
% [2 D/ B6 W8 `2 e4 BHere is a sample (checking for 'SICE'):3 T `2 |' p# ]
# ?- V) t d, ]. sBOOL IsSoftIce95Loaded()
: ~0 z! o, Q4 }' m6 e0 O$ S{
; B" ?8 x7 x2 Y9 ` HANDLE hFile; 3 }7 t1 D9 N0 T* m7 y0 b9 V
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
, V' A7 o* p" e FILE_SHARE_READ | FILE_SHARE_WRITE,$ W8 ^, V; W! f& D5 D( S: ^
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);* r/ [& U6 ]; A0 e- y$ t
if( hFile != INVALID_HANDLE_VALUE )
: s4 H; T! Z- g0 O4 e' y {4 W" c8 N! x7 P6 ] J, ?
CloseHandle(hFile);* P/ [ E, \: M% {
return TRUE;/ z: h; G* W% c
}
6 X) u0 T2 l6 l return FALSE;7 u& p/ _* }$ z/ I# ?0 s1 @
}
: N$ {* u( ^) `' |
9 e0 o, W- A0 y: ?& N2 \$ ~; y; oAlthough this trick calls the CreateFileA function, don't even expect to be; i! _# Z4 M7 e% L7 J$ z( W
able to intercept it by installing a IFS hook: it will not work, no way!7 b& B6 ]* P S; q$ Y
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
* |) A& D0 e6 q7 {/ ~service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)3 l8 z0 j- Y% C
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
3 Q, h, Y3 a& c) gfield.7 Z7 i/ e' O7 ^5 I& ^& d
In fact, its purpose is not to load/unload VxDs but only to send a . V6 z" ]8 H. E2 Z& ]& r$ k
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)2 L) x, T v) L$ ?& D- H
to the VxD Control_Dispatch proc (how the hell a shareware soft could try4 K8 e) j7 s% w/ H
to load/unload a non-dynamically loadable driver such as SoftICE ;-). M# e: \3 F* l8 _0 {2 I
If the VxD is loaded, it will always clear eax and the Carry flag to allow
. U) \* a# E: c2 g3 u+ [ Lits handle to be opened and then, will be detected.2 p4 Z4 ?2 t2 K4 N* g: Q
You can check that simply by hooking Winice.exe control proc entry point3 E* g# c5 m( e7 a8 v0 _& t
while running MeltICE.1 `) e7 C f+ S
* P" v1 W0 F- ^5 ~1 d! m4 B: V' ^+ t. r9 s1 S1 j; P
00401067: push 00402025 ; \\.\SICE
8 S4 E8 v7 E; ^ 0040106C: call CreateFileA! E m- g, q K7 n
00401071: cmp eax,-0011 P+ g' l' C2 P
00401074: je 00401091% s0 u C. A- s$ ]( J
$ S0 Z3 t0 a! k- E- g$ k0 z/ Q+ C; |7 h
There could be hundreds of BPX you could use to detect this trick.
" s8 I0 i4 l4 e( f/ h+ @8 ~-The most classical one is:
7 E5 ]* ~/ r7 H BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
. ?) Y1 M& D5 W: y0 A0 p) K$ v3 ~! i6 d *(esp->4+4)=='NTIC'9 y3 a8 y+ W: I4 q1 r1 z
/ j' z: B2 [7 L# {- A" h3 R-The most exotic ones (could be very slooooow :-(
) S' B( ~9 g; P/ l4 ^7 ^ BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
. |+ n4 A( V( p5 q% ?" M @' B6 ~ ;will break 3 times :-(
( w) [- f8 t* r+ }
8 U1 L$ t3 q6 O2 G9 d-or (a bit) faster: $ S) l9 c8 n3 @5 B3 S: w3 Y5 l/ z# k
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
. r6 L& @5 B7 f' S
6 M4 d: b4 _0 Y! d BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' # A6 Z' g1 q; R4 X8 S0 I9 N! a
;will break 3 times :-(
+ n% u) a/ g2 Z1 ~% W8 I, D5 T+ @4 q7 J
-Much faster:
4 P* Q8 |9 R( g* A BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
* T+ ]; B- @" t- F5 M7 g0 y
+ g; k* }( y7 X4 y5 Y0 T6 F3 ?9 |Note also that some programs (like AZPR3.00) use de old 16-bit _lopen/ t) e c `: v# }
function to do the same job:
; ?% ^' Y) ~( v, ], @" ]
* g( ]- I5 k5 `4 _2 w push 00 ; OF_READ) Y; k; C% f' \9 W; X8 D
mov eax,[00656634] ; '\\.\SICE',07 W. h4 a# s3 W9 l8 l7 @# h+ e
push eax% W: I/ }8 Y) l9 S
call KERNEL32!_lopen
u" ?. d/ j# @% |! B inc eax& p& ^4 x# `, l' _* ]5 n% s0 D
jnz 00650589 ; detected
8 d; y& O7 m) \( G) y9 m$ b push 00 ; OF_READ# P+ D. w, Y. j9 X! _3 o
mov eax,[00656638] ; '\\.\SICE'. c8 v" D+ Q( c4 v& t% x' [
push eax
" R# J' U W6 s5 B! R2 [ call KERNEL32!_lopen
! y( d% q0 t& J [& N3 l inc eax
6 y0 k& l$ Z9 l. m jz 006505ae ; not detected
6 s/ G7 D t- l2 u; _( C1 N" {2 y* |9 X% f2 `, K' Y% m. \
; q h! @7 J6 ~0 X
__________________________________________________________________________$ z: l! V& W. z, b2 q2 _3 l& J
/ ~0 R3 E6 X! f7 CMethod 12( c2 E# S$ e) l' h7 L6 r
=========. }6 i+ |2 Q! m3 ?) H1 I
* Y* i: [' V! zThis trick is similar to int41h/4fh Debugger installation check (code 05
; l- ` u4 l' g- o$ @& 06) but very limited because it's only available for Win95/98 (not NT)
" C% k! I: X g8 Y1 j7 mas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
. C& j) y/ E" a3 e
1 h' @- [. g' E8 L& S5 A) R push 0000004fh ; function 4fh
7 f4 V, W& `& r push 002a002ah ; high word specifies which VxD (VWIN32)' p4 q+ n" P2 U3 Z, c
; low word specifies which service2 n" V; ^; o% {
(VWIN32_Int41Dispatch)" h% w) H0 X1 x, }$ d
call Kernel32!ORD_001 ; VxdCall: b% b+ V5 \ k5 Q% H' i9 d9 e
cmp ax, 0f386h ; magic number returned by system debuggers b; c; h5 t0 c0 {# B6 h g
jz SoftICE_detected e E! i1 U% R$ Z5 u* }
9 [# G* ~# h/ A- i+ h! F9 } ]
Here again, several ways to detect it:
* {1 [3 X6 w% W1 h: H5 F9 i, d1 \- i( f2 h
BPINT 41 if ax==4f
$ J3 S& L U2 R# Z I' S
2 w8 y$ ~# w+ A BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one/ {; L. V+ q& T( j% d9 F
. g& P* u/ s' a7 m' R BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
- H w7 t/ _6 _: s" c
2 V+ ` `1 \( H. ~; v BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
' ~+ i8 }- x, m* ]" C% O
5 D" F+ r( D+ H__________________________________________________________________________
8 n! o* C% h1 G3 ?3 N) `$ ~. b
6 |- ~: r5 K0 d: \Method 13
( c {+ @2 @ L=========- |5 e, v7 p4 B* y. S$ J
" f8 m6 ] B* C* e) s
Not a real method of detection, but a good way to know if SoftICE is4 B, G9 P4 B/ f( [7 A( d) z
installed on a computer and to locate its installation directory.
5 A* y n2 `/ n7 vIt is used by few softs which access the following registry keys (usually #2) :! g( q% Z% R! l0 O5 ^2 t
8 z. n$ L7 F: v/ o5 C) |6 ^- C-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
- f# p! H% }6 Q) @, c. P8 V\Uninstall\SoftICE3 d: z/ K+ n3 a% c
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE6 A- ~" S" x, n* b8 E, A7 J
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 ]6 ]; b9 S1 ^* w. n. [0 B
\App Paths\Loader32.Exe& a% W$ w. q0 w
) d2 x# l, i% A( o5 p0 s0 @
9 ?+ s' f+ Q6 D
Note that some nasty apps could then erase all files from SoftICE directory
1 j: L* A6 r+ L& W1 ^(I faced that once :-(
! k: \/ ?' a6 h- _$ @( t4 j9 Y9 k* {: ~- w" V+ y
Useful breakpoint to detect it:
. A! h. w$ T# b
8 v! O+ i+ n" d6 `; z" R# a BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
9 a- P, `# y. N' e b" W7 e
* p. W3 ]$ B* K$ K- v__________________________________________________________________________0 ^4 I& X4 }6 ?
' z P4 Z/ { P9 J. ~/ B
/ C- B- b1 ]4 N3 D, f8 z- YMethod 14 1 f+ ^ ^4 G& v1 j% @
=========* H0 {! s ]+ f! m" b9 [1 n
' n }! s% s+ L4 }5 s" E- @
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose# a/ x; Y+ e8 x
is to determines whether a debugger is running on your system (ring0 only).1 o! ]! v p# m1 B
' g7 v7 @8 m3 ?$ X0 {& t
VMMCall Test_Debug_Installed% G6 I5 Z# T' Y8 e
je not_installed
- m& x" o4 F6 Y0 G, I
3 E5 t# h5 X9 x8 B& `9 w$ VThis service just checks a flag.
/ ?8 R4 |) G$ R</PRE></TD></TR></TBODY></TABLE> |