<TABLE width=500>8 r3 d! c" _- _
<TBODY>5 |: b1 X1 ]$ Q8 Q
<TR>* E3 f- C/ N! r% m% s
<TD><PRE>Method 01 6 T& i {: @$ E
=========
5 r; @: d& F9 D p5 I2 g! {1 f' u+ D. j1 S, S! t1 ?+ w: ?3 r5 w3 A
This method of detection of SoftICE (as well as the following one) is
: h( K2 [! W# m* n: z2 B( xused by the majority of packers/encryptors found on Internet.+ b, ~% O3 H) m3 P. i- H
It seeks the signature of BoundsChecker in SoftICE
- r) f0 G$ k: X& J
3 Q4 r2 T2 S6 z7 C; w) `9 L mov ebp, 04243484Bh ; 'BCHK'. V7 `8 g6 [1 ]: ^! W6 x
mov ax, 04h; R( P: f$ R" b& ^0 n4 p
int 3 5 @' r {& z8 w# v1 r% D
cmp al,4
. U6 B7 }& m" \) f7 G: E m jnz SoftICE_Detected" a6 F9 B0 f- W1 }( b! V/ u
8 _" Z+ r5 ?. X' A* ^___________________________________________________________________________( l8 ]7 b$ ~& I) `
) \, h$ E* X ^3 l) HMethod 02. t2 Q7 V, |) L8 c! F2 M! R' L, x
=========
# d: @- l% p/ |' s6 V2 U' b
9 j. v3 F9 Y4 n* i# N( iStill a method very much used (perhaps the most frequent one). It is used
" p% K! r8 F$ }6 eto get SoftICE 'Back Door commands' which gives infos on Breakpoints,* H5 v. \& M! u4 U' O& J
or execute SoftICE commands...
U) w$ m0 ~( j; ~! FIt is also used to crash SoftICE and to force it to execute any commands
1 B7 N6 P* E$ h1 N. X(HBOOT...) :-((
5 J3 f9 Q8 K$ J( @
" r8 I* w4 R% ~' [7 E" {4 o& l- HHere is a quick description:
! D2 E$ f2 O: j( k6 _ _: r9 `-AX = 0910h (Display string in SIce windows)
" h1 y7 i& ]5 q) q8 l! C2 K-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
# k h+ G- s) @( l-AX = 0912h (Get breakpoint infos)
% s3 Q" `) H( O# J-AX = 0913h (Set Sice breakpoints)
' q' a* t. k; _$ R- k+ V. c# S-AX = 0914h (Remove SIce breakoints)
* J) |. a! c4 F6 g) O# t! Q
( D/ E! e- s+ E2 ]. MEach time you'll meet this trick, you'll see:* b( s2 A- W; X
-SI = 4647h
, ? m1 |2 L' h2 S( j/ j; I5 K-DI = 4A4Dh2 M* _# l' `5 }2 l' R* q h
Which are the 'magic values' used by SoftIce.' x% j \" P h* r( [* L" A
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
2 s D3 {# b8 C! u9 ?1 [8 x% F5 K, ^ P7 {1 A
Here is one example from the file "Haspinst.exe" which is the dongle HASP
: s/ P6 V5 h- E9 \* b- SEnvelope utility use to protect DOS applications:+ R4 v- M* F. s& ]9 e
/ M% _, Z7 E! g( c# e2 L+ T
- c& [- { z8 d ~4 _% d6 k( v
4C19:0095 MOV AX,0911 ; execute command.
5 X# {1 `/ I! F$ l- Y6 L4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).3 Y/ N, P/ o, R% `3 u" F+ i) o% _! d
4C19:009A MOV SI,4647 ; 1st magic value.
( y5 Q( o2 j: j. }. z4C19:009D MOV DI,4A4D ; 2nd magic value.3 U3 d/ z7 {% E5 {
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
2 `! U9 V+ ~2 r$ D- D0 E4 X4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
# K4 }4 @" L3 O- I4C19:00A4 INC CX
) O$ W; J4 h( u& L/ l0 m; A& K3 }2 m4C19:00A5 CMP CX,06 ; Repeat 6 times to execute+ E& }3 q" g7 C. J, r: ?
4C19:00A8 JB 0095 ; 6 different commands.
" o! b( _/ c" k4C19:00AA JMP 0002 ; Bad_Guy jmp back.% Y# Y- I2 X( |( Z: ?' X
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
! t5 q7 c' Q: k/ N0 j* ^: j3 E( P. [/ B& [# i7 e
The program will execute 6 different SIce commands located at ds:dx, which1 j: s! ~' x* m6 t& h/ J0 y7 |5 E
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
9 Z7 H- n+ A! ^9 }. ^1 n1 X( s4 R! w/ b. u$ m
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
2 S/ V0 {8 z; B/ d6 H! t# }___________________________________________________________________________8 e3 K5 b2 ^" d+ f6 q+ ^
" b' P' u% j+ X9 ]8 y" P5 f: Q5 p0 |, J" a, L4 \6 O3 }
Method 03' j$ o/ w* I8 G/ c+ U8 d; Y
=========
8 G7 A4 N) T7 F1 \( L* N4 S2 t0 S4 a% A6 |; y
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
) ~! b+ S; t ~! D(API Get entry point) r9 O' t, X) \* S/ ` B! m
: A, O7 c4 `* `' [# d
9 c% ]6 Q# q. ^/ J) ` xor di,di
: g" h8 ]5 d2 ]4 F9 r. c X& ?' W: C mov es,di7 C4 g, H. F1 P) b5 u* ]
mov ax, 1684h : W( d5 U& b$ h0 D, ]( f) K8 z' Q
mov bx, 0202h ; VxD ID of winice
3 r/ B/ e: R0 n8 g! J7 ^; ~ int 2Fh* ]$ x# w' Q6 x. u6 D$ j" X
mov ax, es ; ES:DI -> VxD API entry point
' b# M4 h/ z, ^; F$ z add ax, di
& e0 x1 u9 a: i8 E! L test ax,ax
! G* N/ B# O) n+ T jnz SoftICE_Detected
: P: Y& Q4 ^7 J( _* X
6 Q) T; B* l/ {( R___________________________________________________________________________; s2 w* @" b2 O4 B8 b3 z
* [: [( C9 l- H" JMethod 04+ m4 t5 {0 t, h- [0 U% `
=========# a, h7 X4 W+ w$ v
0 [& Z; Z/ o0 D7 P9 [
Method identical to the preceding one except that it seeks the ID of SoftICE
/ H8 V8 x3 s4 \# _" p/ {GFX VxD.
7 P1 _! {! T. P# ^7 K% j& J' v: _
5 ^: v5 n( a2 B xor di,di5 j9 S/ n- M/ n/ F
mov es,di, D0 \3 Q- i; Q
mov ax, 1684h ' q O" f5 X- c7 P- I) W) q
mov bx, 7a5Fh ; VxD ID of SIWVID
% ?1 }# Z: M" A1 g$ d9 l4 C8 x int 2fh
. f$ f5 w/ I9 f% I mov ax, es ; ES:DI -> VxD API entry point
- V) s# |- e; l9 O7 Q' G add ax, di
: {4 Y( B# j: w# R8 j test ax,ax, I6 c% e" M5 [6 R2 {6 U
jnz SoftICE_Detected
& d! H- F- c' ^. A) L8 q% d C; y5 a) _6 }
__________________________________________________________________________
" a7 H8 \, ^& L: N& @8 s. G' Y3 a1 K3 U3 Q2 h) y+ [) `: I
2 X; j8 Z4 e% T6 f; rMethod 05
, h V( i. i2 V3 F* G6 ^ Z. O4 d=========( D7 X3 c4 B. e( }* u6 ?
; F( N4 k9 h$ c5 |# u6 c2 FMethod seeking the 'magic number' 0F386h returned (in ax) by all system
# _7 ^9 w" B! z2 }3 fdebugger. It calls the int 41h, function 4Fh.3 ?: w& A/ k5 k' X6 I6 x s7 w
There are several alternatives. 0 V" i3 y7 w* i1 }/ L
" Z3 S o" z7 P# x4 k! I3 B' \9 q
The following one is the simplest:
" k( Q2 v- L2 T1 r% v, X1 b8 Q. e% q+ |* }; X. R' n* b
mov ax,4fh
! a( U6 t, v1 N5 l* `) v int 41h- l9 M5 [% r. p( h" y* ?
cmp ax, 0F386
% _; o M5 C7 Y jz SoftICE_detected
6 ^% }1 ]6 a$ w0 @- w
# C; @/ k0 l& f
/ K3 e; }/ q9 z) n6 K m2 CNext method as well as the following one are 2 examples from Stone's ' ]7 G/ ?# F+ f+ B2 ?* R9 S& c# o
"stn-wid.zip" (www.cracking.net):+ O1 r; I8 @7 W1 k( |5 o( a
1 |/ g. o& }" t* x0 Z) t
mov bx, cs& y1 z2 v! P3 Z" U, L0 b; w
lea dx, int41handler20 |+ O& o9 B% c/ r
xchg dx, es:[41h*4]$ Q: C0 @( b3 Y' b! G8 l! |4 i
xchg bx, es:[41h*4+2]
) _ P0 A2 b4 O! Q x4 x( y mov ax,4fh
1 n' Q! \1 s# ~9 I% X int 41h
; _) a, V# }( u+ x! m xchg dx, es:[41h*4]
, i8 \. @0 c, P7 @- C xchg bx, es:[41h*4+2]- f. ~; T6 e( K4 [! o
cmp ax, 0f386h4 s/ y0 a4 N# u5 x2 W; m) A
jz SoftICE_detected: c1 Y2 i+ O! M4 J8 [( l, v
' Y; x% K4 h0 zint41handler2 PROC
- g% ^- O \7 b! n iret, @5 x7 U6 U" f( B: `$ Z
int41handler2 ENDP- t/ } W; t7 Z/ P( i7 K! m
4 x" m' z" P g. r2 k( c- V5 G, E* ~) D q; d
_________________________________________________________________________0 n k; S% s& O V/ I# ^
- B% }; T6 T1 v( Q5 U* G
' g, @. @8 b3 u. eMethod 06
: t/ M; ]( c3 m* k: W=========/ \2 e# ^5 w" p! l
- C9 v. t8 V/ f$ `: t% ^- A( |8 c7 s- _$ r8 s, v- T
2nd method similar to the preceding one but more difficult to detect:
! R1 ?- o" M6 J# Y; K0 f$ [$ B, V
" Q% \' |" o1 H& ^- i8 Jint41handler PROC
5 m3 ?3 Y+ G7 f# m2 A3 _ mov cl,al
5 E% \7 L0 f: I iret0 K8 i& v) J, g
int41handler ENDP
1 v. W$ ^) G; w5 R" }. ]
" } v/ V; y/ r4 e$ w5 _# K7 l" b% l. \/ i$ W& [
xor ax,ax
9 s+ c" I f9 T9 u) e mov es,ax! b& L, K: B2 a
mov bx, cs3 w g0 ^7 ^5 ?( Z( U
lea dx, int41handler0 }4 q5 K0 |. c k3 A2 v
xchg dx, es:[41h*4]$ n1 P2 r/ i/ F& `! z* b
xchg bx, es:[41h*4+2]
: ^+ l% x. Z" [9 |9 E# {) n( l1 i in al, 40h
: }6 s& w: y* [ T5 w xor cx,cx5 ~& O" A* V$ S% Q5 B
int 41h( W# K. Z0 B/ V7 j
xchg dx, es:[41h*4]3 C) I- \! X- j
xchg bx, es:[41h*4+2]; f/ |0 O) p: O3 u( L4 {
cmp cl,al R' r7 G# E6 }. Q) a+ ^
jnz SoftICE_detected
( S% }) V8 t2 q( j5 H
& i3 s7 J' ^- [! T/ x5 ]" A_________________________________________________________________________
5 b: V3 l0 R, G, w+ e0 _5 n+ O' O0 ^9 V7 n/ _
Method 07
* A9 b0 m, s& L, \ m% p) p1 K4 T=========1 p9 z* n( T+ N& ?
. Y; ]7 f9 a6 W' ]Method of detection of the WinICE handler in the int68h (V86)
6 D: ~% V$ ~; X- { q8 \, \1 S, V, E% H+ r9 R( W
mov ah,43h
) w) Y+ ?1 z. [, d' L+ U) m% q4 t int 68h
& S+ k' @4 c4 d$ P4 h# K% v: G cmp ax,0F386h. W% [8 J2 m3 u! W) @# q: A5 E
jz SoftICE_Detected+ `1 x2 _! q0 M
1 s5 p- h; R- x+ v9 D
2 ^8 v+ ]8 q% \% u5 A2 k=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit! m7 g+ X0 z3 j5 p
app like this:
\6 U* L, l# T# m9 G" I4 N; r2 i0 _
BPX exec_int if ax==68
9 D# b2 N0 E. w0 p( Q- k5 ?( ~ (function called is located at byte ptr [ebp+1Dh] and client eip is* a! B+ W1 ?, ~0 @$ x# @3 G
located at [ebp+48h] for 32Bit apps): i& M! v7 x- r, G* l6 q
__________________________________________________________________________7 n( p) }6 B1 v4 n' a' w9 \
( }0 ]% c* A6 o
% m3 U, h7 |* ^& H& u* y
Method 08
. z ?0 [- ~0 U9 g- M. G" l=========
) m0 \% c6 c5 l4 Q& T- R( F7 ^( m% }) I0 Y9 w2 ^( n( t" @) D; \
It is not a method of detection of SoftICE but a possibility to crash the
2 }4 H( _. g# w8 s5 ^ Bsystem by intercepting int 01h and int 03h and redirecting them to another
- N" ?3 }; q) I: ^) {' `3 N: {! ]routine.
. N5 G( }0 K2 z; Q7 [! dIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points# ^/ i0 n0 s' ^5 e
to the new routine to execute (hangs computer...)
[7 v, S4 }/ y' S$ Q# p
* ~" N# a' j. m8 n mov ah, 25h. |- _4 w# I3 I- f
mov al, Int_Number (01h or 03h)
" A, v" \9 B; |# N3 Y mov dx, offset New_Int_Routine
; I; @; T# I G0 ?4 C9 ?% L, N int 21h; J' a8 Y6 M$ T' F3 L0 b& d/ T
- C w; s! _4 I: P: q__________________________________________________________________________
/ l" k7 {1 b5 C6 @5 A8 ?. U# y$ \1 f+ C5 t. C) Z1 Q. [
Method 095 `! O; u1 H7 M
=========
% S+ i- J& _2 K* z
( N4 i7 w' z v2 M* o4 Q; G9 j# zThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
: T, ]5 \. D- k6 `' ]5 q) uperformed in ring0 (VxD or a ring3 app using the VxdCall).
0 y* B( X f1 _- {* NThe Get_DDB service is used to determine whether or not a VxD is installed
- `1 u& t8 {( Zfor the specified device and returns a Device Description Block (in ecx) for
' V& ~) k P7 I& S- Z8 T/ b5 rthat device if it is installed.+ @& M9 ~! U) ~0 @& {
: n- g% V& S% ]) R! O$ H m
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID4 g8 H3 ? ^; U
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)% @/ J5 w( c' ~- P( G8 ~
VMMCall Get_DDB1 E0 z$ \; y- ?9 ~# e
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed3 a' c. N, a/ ]
9 G L5 Q+ r/ X% U4 T
Note as well that you can easily detect this method with SoftICE:) F: J7 |$ L5 B& y8 S3 H$ X' O
bpx Get_DDB if ax==0202 || ax==7a5fh) t+ Z' A! t3 R2 f$ W/ P
. p% i. Y; s! e2 j9 k2 F/ {
__________________________________________________________________________! j" L5 L, [2 W( y: L4 F) f
, Y9 K$ O4 ?) Q; B7 ]Method 10
* z. `4 K" `& r1 y' I=========3 B2 Z+ i! y) I. f
4 }: q8 X+ h* W& ~+ z9 Y
=>Disable or clear breakpoints before using this feature. DO NOT trace with9 k; H' m2 C% k' n8 l1 u
SoftICE while the option is enable!!
: P f+ F& c, [& K0 p( ~: F8 w" L: ? C" I4 G1 N
This trick is very efficient:
5 j, n* h+ O! O9 n. Q, O8 I4 V! b* N; cby checking the Debug Registers, you can detect if SoftICE is loaded
: v8 \0 X% ^! O$ k# Z(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if% {% z) c+ M8 f" P$ o8 l! x0 C
there are some memory breakpoints set (dr0 to dr3) simply by reading their$ j. D, A) b$ C5 e+ c
value (in ring0 only). Values can be manipulated and or changed as well! h, o- t/ q' I1 z/ g2 ~+ D4 w
(clearing BPMs for instance)
- r, w) C1 O# H( u
" [ H# p3 V( |4 b% ~9 u__________________________________________________________________________
* j c, ^1 P/ N3 ?/ }; h# W" M
* D& c: ]3 f- C2 [' y6 dMethod 11
7 Y+ u* A5 p) I i& u: b1 {=========8 p# {! i) i* y. |
# q2 N# L5 {* R, Q; o! J3 {
This method is most known as 'MeltICE' because it has been freely distributed, w& G' n h! a6 _' }
via www.winfiles.com. However it was first used by NuMega people to allow
2 ]) O0 N; t M _. u9 |. C2 ASymbol Loader to check if SoftICE was active or not (the code is located
* w& B1 e+ S7 X* h+ Hinside nmtrans.dll).& v& j* x1 c+ T* a8 t" U+ q
+ H4 ^( T# F7 I+ y& yThe way it works is very simple:
. \2 ^6 Y6 v1 c" K& ]It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
) w6 ?' I- J8 r1 V8 V* @WinNT) with the CreateFileA API.
: ~) O. a( g4 {! L& A3 S" I* G* b& B: ^0 ]- O
Here is a sample (checking for 'SICE'):
9 n- ~7 M' J; a/ i* H3 ?
: b; R) e/ p9 B6 p3 h- O ] ]BOOL IsSoftIce95Loaded(); a2 I' d5 e- C# L& E8 S! v
{, k% S, ^2 h4 j9 k3 M
HANDLE hFile;
1 z0 j( g7 \1 a, x hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,1 D9 f3 b* k) X
FILE_SHARE_READ | FILE_SHARE_WRITE,
& E% \/ z$ ~3 _# W9 C NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
$ O1 q) t. s5 ~ g b& S if( hFile != INVALID_HANDLE_VALUE )- H: s* O% N* t4 F7 v& h
{, t8 D7 ~& X% M9 \8 \, B5 e
CloseHandle(hFile);& W: o' b2 g* O* L1 Z, O0 a9 M
return TRUE;& n5 ]' u: U7 V2 _$ j
}
; n1 k: v. h8 T& ~0 U9 G return FALSE;
. ^: L: |9 v: i# {1 t/ x) a}) _ v7 ` q% w
1 |' B( j* [% H/ U, f7 \3 B
Although this trick calls the CreateFileA function, don't even expect to be( g F6 j% x, b: H
able to intercept it by installing a IFS hook: it will not work, no way!7 O& L; a: m( N6 b/ c
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
& i) L) V4 }, R* i! a0 H# [service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
7 B, V6 c% B) P( _and then browse the DDB list until it find the VxD and its DDB_Control_Proc% O) ?, J, D I' e8 b
field.
3 K; U) t+ b: WIn fact, its purpose is not to load/unload VxDs but only to send a
; G( p4 y" ^; P7 s7 u; Z, y- `W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)/ R" L6 v! m( U( b0 _2 V" i
to the VxD Control_Dispatch proc (how the hell a shareware soft could try+ I9 v# ^2 }4 P
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
2 Y+ c2 |8 H4 [: C( rIf the VxD is loaded, it will always clear eax and the Carry flag to allow3 |- r/ U+ E1 m4 w. f0 q+ g: |
its handle to be opened and then, will be detected.6 I1 d/ D- d0 i8 k" I# B! b
You can check that simply by hooking Winice.exe control proc entry point
+ ]7 s, T1 T+ f2 p: }while running MeltICE.8 F6 t& A9 ]8 x" ]
" P( T+ i0 e" {6 d) R0 n
9 X0 p5 B) i# H) h. y( b, W2 }) Q 00401067: push 00402025 ; \\.\SICE
R1 ^: J" D" X7 | 0040106C: call CreateFileA" T. z4 W t& n3 c5 I% T+ G
00401071: cmp eax,-001$ K4 K; P7 \/ w
00401074: je 00401091% p! A0 ?$ I6 p9 ]- j+ X! l$ f1 J
' u9 g8 H6 x7 n( j: c
" u" S+ _' }7 n+ V& B& FThere could be hundreds of BPX you could use to detect this trick.% g2 s& @6 L9 R( {+ T+ M- T
-The most classical one is:( @. U/ C8 U( T- i0 ]9 ?9 h
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||) R" L1 u7 i9 [# Q
*(esp->4+4)=='NTIC'
5 {: D6 f- X8 @. C+ j4 b% k+ A) R8 X. F' }2 t1 D4 \) U, p8 ^7 O
-The most exotic ones (could be very slooooow :-(
" \8 u& s) m" x( j BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 4 l6 U7 H) S/ O; O J" p2 k) L7 q; F
;will break 3 times :-(- K* H7 w3 y! d! f9 T
- y) Y* q! s; z) Z: ^" O6 m
-or (a bit) faster:
" k$ _* L. g, E- k4 l; A: p& x; W. `. _ BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
2 ^+ Z: l3 b. J9 w% b( M7 ~( f) s3 K' L' f7 N* ?; V$ S' f
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' " C, g) M5 b9 l7 y1 c
;will break 3 times :-(
- d# t- e" [ q% o- U" z* h8 u
5 W3 L7 y7 W: C! M: q9 Z-Much faster:; K) ?% e8 V- e: J/ d, M" C! a. A
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
2 b" y, X7 P& ^: Q7 [6 o/ B- f- {9 d# R x% ?. A. h: w
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
2 ^7 ^. T6 u7 a1 \, s6 W8 Sfunction to do the same job:
+ j6 i$ e9 `7 L5 Z7 D7 g+ Q& W) S
push 00 ; OF_READ+ o9 K% G* d8 x" p$ H1 n
mov eax,[00656634] ; '\\.\SICE',0' m4 [( Y2 w, p( h4 E
push eax
# P5 q; Z- h& A) Z; x" F O& N; g call KERNEL32!_lopen- w/ Z L. T8 T6 o- v1 ~: I
inc eax
) N7 d$ ?" \1 U. O) s- `4 y jnz 00650589 ; detected
, d# I2 H4 v* a push 00 ; OF_READ s0 b" e) _7 B6 T0 ] G7 {
mov eax,[00656638] ; '\\.\SICE'! ^ X! n: S$ }2 O
push eax) }' l9 M' I) n4 e
call KERNEL32!_lopen V/ O% a `, A6 Q
inc eax
M& D! D1 a- z% @( F; n- G" N6 M jz 006505ae ; not detected1 g9 e- U" `# S% T
! O- ~) m$ o J- k" J, J* n" K8 n; l
- ?$ `2 e' M7 m U, a7 z__________________________________________________________________________' u" W# j% b& z; p
3 {" ^. Z; s P2 Z
Method 12
; ]! w) g: z6 A/ g/ _=========
1 q: D" O `* U: `/ b! t4 X
! v; G. G/ a' v' OThis trick is similar to int41h/4fh Debugger installation check (code 05
1 Y( m# Z9 @0 {: ]' S& 06) but very limited because it's only available for Win95/98 (not NT)
* ]/ ^( ]6 U* k% [( vas it uses the VxDCall backdoor. This detection was found in Bleem Demo.% t# Q0 L8 P; q2 T: L
' _, ]- {$ r) ]/ o) s4 E: I
push 0000004fh ; function 4fh
1 k1 p. {( ?: b% C5 K$ O& V2 E push 002a002ah ; high word specifies which VxD (VWIN32)
! @7 y/ g) {0 _ ; low word specifies which service1 P q) _1 t2 p- B* [* z
(VWIN32_Int41Dispatch)
# Q/ \! _2 C! b! j call Kernel32!ORD_001 ; VxdCall
7 f' f5 X* W Q: A G cmp ax, 0f386h ; magic number returned by system debuggers* t" i; s' Y) v/ i
jz SoftICE_detected
6 F: f1 u* O; B9 g7 J- k
- P! G/ m8 U: H7 X; WHere again, several ways to detect it:
# T+ ` T' @3 X0 D0 ]3 `2 a
3 R- D5 k' W! ^3 R8 }9 W. P BPINT 41 if ax==4f
* {! J! ] l( f# [' W% p) s1 n3 G y. P" T( P: y0 [
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
! ^2 C3 v. L* ]3 H- e s# q3 ]& S
" I: a- K. t& ^1 c8 P; T0 @ BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A2 d% I& s& O5 v f
3 v/ t& G1 u; ^. x+ w8 B, E* Q" b BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!2 h: ~6 z- f5 d: y: R1 ]" }- [
+ y" Z W( X- j9 u
__________________________________________________________________________3 f+ K2 @3 J9 r: s" x4 {
! M% [1 A. ^6 ]6 D; QMethod 13, Q& \3 B# B3 B7 V7 e6 W5 W! Y C
=========
& ^& {7 A" k2 y, f; Q/ A
8 @+ w& U4 m- l) l6 D/ D/ V0 lNot a real method of detection, but a good way to know if SoftICE is
4 P0 X: ?* q* m9 {. [7 k+ f3 vinstalled on a computer and to locate its installation directory.. f: s, j5 f% J! y/ Q. {( s, e
It is used by few softs which access the following registry keys (usually #2) :5 N" S) V! Y2 X* ?
2 G+ a! I4 u. N1 Q. x3 K
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion- y5 W/ z; ?4 H) r( t$ v! A4 M
\Uninstall\SoftICE9 `7 j! D8 e8 |* R' t/ z
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
! p& \; A- G4 V) a-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
7 W- Y t( F5 Q9 }\App Paths\Loader32.Exe& O! Q' O$ D' q, H& O, E# A
5 L2 T2 m' v5 z3 J0 y
9 H! f. R! Z& Z/ T h2 xNote that some nasty apps could then erase all files from SoftICE directory
( d; e" e! q {7 \+ { M(I faced that once :-(
; i( p1 b! L& ^1 \
V2 g+ G& E' y; Z3 x8 eUseful breakpoint to detect it:0 h4 W- c0 p* {* i8 b
% E. ^; `. ?& Y( H. h: B BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
7 Q# C# q& T" q3 F
3 i! Q4 {% W$ R/ D$ }( l4 K__________________________________________________________________________4 L2 m+ q1 f4 ^9 i! \# {5 d) h3 r
& h; K7 S' k& g% L2 @
, l1 d( y( S3 ^0 X6 c, nMethod 14 3 ^ ~- p5 g: V2 p4 s7 c
=========* Z9 ?6 U) ~! v. q. {" A( _
5 s+ I+ Z8 S2 Y( O! k- Y' j: L& ~! R- s
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
4 h* j* g5 j4 y7 a. z# V/ ]is to determines whether a debugger is running on your system (ring0 only).5 ?% A9 W+ e: q8 z7 S( H( O
4 R" T w: d- Q+ k+ u0 A3 T
VMMCall Test_Debug_Installed
3 B( k2 `3 m8 Y je not_installed9 p. A- v1 k" [" [- @: H
" d b9 b9 k# g. KThis service just checks a flag.3 x2 F3 `: q; d* u1 E
</PRE></TD></TR></TBODY></TABLE> |