<TABLE width=500>
. j& V& ~" k8 [! M1 m q# e<TBODY>, \ t3 f' |' o3 v
<TR>4 d: [+ o/ v: p* w) J7 [
<TD><PRE>Method 01 , s. h- }" w+ f& P
=========
; q! Z8 T5 _5 y3 A# _1 }8 _4 l8 t2 x- `5 W- ]
This method of detection of SoftICE (as well as the following one) is) [' P. i* O; ~( K% v0 c: L2 [
used by the majority of packers/encryptors found on Internet.
1 b2 U; k2 v% _( M( R- nIt seeks the signature of BoundsChecker in SoftICE8 t" o$ |+ [" ~
0 g0 K& M W* a3 \6 W
mov ebp, 04243484Bh ; 'BCHK'1 G/ E3 n' K: u& H
mov ax, 04h
7 X$ g0 z, u, _8 }* G0 R3 {/ s int 3
; g; U N* y5 y cmp al,4
5 q0 t1 l5 p2 J7 M jnz SoftICE_Detected- k2 B+ j4 K, O9 b7 E, ?! T
; ^9 Y; L N( U___________________________________________________________________________
0 s0 W" \& N9 w7 ^! _. {
; e+ k- q, E2 \% D; AMethod 02& |+ E0 h I: j! B6 o: Z
=========* E% M s, P1 }7 h2 C2 M' B/ [
! b8 ]) |" C/ P) ?
Still a method very much used (perhaps the most frequent one). It is used
1 F- |& X6 _7 Z# \to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
" ]* T& D4 _+ F: a4 u: C$ H. Uor execute SoftICE commands...
) |$ G. Z! P3 l4 S- hIt is also used to crash SoftICE and to force it to execute any commands0 A7 \! Y' F! G5 O
(HBOOT...) :-(( - I, a1 f% t9 C' V
/ A9 j# N: h! y1 R" A) FHere is a quick description:
- \2 I n% @+ w8 I8 |" x-AX = 0910h (Display string in SIce windows)
! r$ ^7 A% r3 }8 C+ B3 Z5 b3 p# ~$ Q; z, L) d-AX = 0911h (Execute SIce commands -command is displayed is ds:dx); ]' [+ h9 T" h* V7 X2 Y
-AX = 0912h (Get breakpoint infos)
7 ?2 e$ q o$ l3 I7 x-AX = 0913h (Set Sice breakpoints): c, b+ V" v% b( m- y- F, M
-AX = 0914h (Remove SIce breakoints)) X9 f, _) h/ e7 _2 t6 L4 a
! \$ ?! s; \ X* d9 ]
Each time you'll meet this trick, you'll see:9 b! e/ t9 Z' E* y8 f1 v" `
-SI = 4647h
2 a) @- y7 e( y; k& `$ [-DI = 4A4Dh
z, }0 M- w: G! K6 x- I2 }Which are the 'magic values' used by SoftIce.
1 O# N k) E0 X1 mFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
3 P7 u6 M1 ]3 w+ l$ K( f: Y6 |' G1 u( H$ S% |: y$ b$ L
Here is one example from the file "Haspinst.exe" which is the dongle HASP3 T! t5 [6 I5 e# o$ w$ w5 [
Envelope utility use to protect DOS applications:
. v* w1 h4 x% K0 W. |! o. b( i
- d. ?. s- y; \" z
y1 |% w& H; v4C19:0095 MOV AX,0911 ; execute command.
3 Z- [, F3 I1 y+ f0 V; G: N' ~4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
/ A7 E; K) ]. ?4C19:009A MOV SI,4647 ; 1st magic value.
0 M9 N" l! F& y+ W; A6 _4C19:009D MOV DI,4A4D ; 2nd magic value.
! S9 I# ^% e7 j4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)" {& n9 C$ E( c
4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute, D- w/ G! {- j' I& W8 _
4C19:00A4 INC CX
/ F, u$ r, I7 r5 r j$ X/ P, ]- x4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
. O7 U" ^" F, I+ J' F2 u4C19:00A8 JB 0095 ; 6 different commands.; N( ?- [ s. c+ h5 E% n2 x
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
) g) r3 U' E* W' c4C19:00AD MOV BX,SP ; Good_Guy go ahead :)& ?9 M- [$ x* y; {" j
; j2 B: c8 G: q5 I9 `
The program will execute 6 different SIce commands located at ds:dx, which
( ]: i, u! a6 ] P+ Uare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.5 |+ F- l: v/ ~* |5 E
1 z) e* L' o u' g E$ E
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.( F8 `3 n: L4 ]3 }
___________________________________________________________________________
) T* ~. A1 I( A" b# k' r( X5 G* i
* T r! v2 |$ d- t- ~: x, A
Method 03
% h, g# f7 S" Z* M3 R1 Z9 H+ N=========: T) i0 y% ^! j: Y1 ?* g
9 j! o- c. _/ l* q! \6 o6 D
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h- y3 g1 o% L$ t
(API Get entry point)
& M5 | c7 ^0 q9 k 7 n3 V: o9 c3 |- s: ~- j4 S9 _
' j) f @- Y1 L% ?9 S" f
xor di,di& R: ~8 J7 t5 l7 A& v: h- b. ?
mov es,di6 m8 W3 v' P7 H c
mov ax, 1684h
0 P/ T% Z8 y) Z9 a- O+ k mov bx, 0202h ; VxD ID of winice; t$ J" L2 y* g) j# F
int 2Fh. z$ F6 i" D* m, q8 M$ `# d
mov ax, es ; ES:DI -> VxD API entry point0 Z, V% c! F* @. K$ b& |
add ax, di/ l" {0 }6 p. y( r0 f
test ax,ax
- s% U/ g; y7 \* U% W% r jnz SoftICE_Detected
5 H, h0 I/ s, V2 I0 [
( S+ [9 f7 y s8 t9 ]___________________________________________________________________________
) y+ x. ]- u; K6 h! E
! m& e2 v, V, |: G0 j# XMethod 04
! J- j$ D/ Y( H( k+ }! u! R) R=========
9 i' c& T" u0 k& L! P
. U) X) I3 I) Z0 u/ xMethod identical to the preceding one except that it seeks the ID of SoftICE
8 o0 b# ^) S1 X" P( UGFX VxD.
* F. W6 S/ n& w& p3 e3 x6 M5 m( r, v+ |' B+ j7 ]
xor di,di' O' x6 R/ ~4 Y: V
mov es,di8 \4 e6 F1 B( \* v: Y. r( n
mov ax, 1684h 9 ^; p0 q- n8 s+ v6 ]" w
mov bx, 7a5Fh ; VxD ID of SIWVID
' y0 v/ r" d# J: a int 2fh! e# r P$ u/ V* L& o' r
mov ax, es ; ES:DI -> VxD API entry point
9 n5 n# n1 X/ f/ ^2 Z- p, U add ax, di4 Q2 K H' [4 w
test ax,ax
- a7 n, A9 ~; p( F jnz SoftICE_Detected+ ?0 Q4 s. L+ O" r7 [$ u
6 i' N& g8 J/ H* g6 S__________________________________________________________________________
9 D+ ~. A; ?! D0 \! j8 ^
/ Z6 P% Z! r/ Y' k5 M4 d- R( @0 w& w) M8 k; @
Method 05
! f9 H8 F$ f6 P4 O' j5 y) `=========* X, F% W0 z( ^* E. G; T1 ]. C
7 }" N# `4 Z& B, @! W+ R3 E
Method seeking the 'magic number' 0F386h returned (in ax) by all system. j6 W/ \( p3 s2 i* x$ G1 E
debugger. It calls the int 41h, function 4Fh.' J2 w% P& }* k+ ?) t
There are several alternatives.
! p& E! N+ @9 T+ k3 g/ `
8 i4 i" X5 h# RThe following one is the simplest:3 D) }! Z# {5 l# j z9 J' p
( S) z8 s: \7 B9 l& j# X mov ax,4fh
" {, N0 c, T& n. l) p int 41h
: E7 U. W0 q9 ~* e0 _ N cmp ax, 0F386
5 a( b5 g. n" j9 w9 ^ jz SoftICE_detected* `' h6 z/ \; Q
9 u, z$ Y# H: q+ G' G8 K9 q4 l5 ]" _$ k" Y3 `5 c
Next method as well as the following one are 2 examples from Stone's
h# f( h/ a% v3 S' k"stn-wid.zip" (www.cracking.net):. i/ k7 F# T) T2 ^
6 R! a3 T; l" b+ Q mov bx, cs
( y/ ?0 y9 G0 p4 O+ V- {9 a lea dx, int41handler2
9 k, \/ t, h2 |, J5 i( D xchg dx, es:[41h*4]
1 i1 c! e. F: `* Y+ u# z xchg bx, es:[41h*4+2]
9 Y' [5 x7 n1 r" i. M5 o8 G mov ax,4fh
0 w) W3 m/ p( e+ b4 h" p int 41h
9 {/ V* ]' x$ Y* q xchg dx, es:[41h*4]9 e1 {! G$ X6 k. q
xchg bx, es:[41h*4+2]
8 N' h$ T L) s) z) m( u, ?9 ^7 J cmp ax, 0f386h
1 u0 |5 v* W/ \6 k6 S5 e2 p jz SoftICE_detected+ P _4 S8 _ j: D1 n- q/ A
* t4 \5 ^" @6 u# a) V* Mint41handler2 PROC/ t& x) d# n8 n, T0 |9 ?
iret
2 I9 t/ l8 Z" J" r" D" Cint41handler2 ENDP+ M. R: ^* Z' i. H- l! o
; u# Q( g8 C* Z/ v" h8 b% @( k% y& Z2 p' w% C! U$ d3 W4 h! e4 f. F: F
_________________________________________________________________________) ~9 V7 k& D8 P& \
: H% C: C( {; R
$ K& H- c s ]2 b) hMethod 068 ]$ ?( g5 f2 ^! e- A8 ?. j2 J" b' C) \1 @
=========1 a: t8 X! x1 j& s( i/ Y
5 Z; Q6 D+ A( a3 i+ g) M7 X4 ]* e
5 c* h$ W# v' t8 r. u2nd method similar to the preceding one but more difficult to detect:
9 W6 V& i& y6 a. ]) Q e
5 v. |; V& V, \- Y( i3 E/ A* f
2 ?3 F* x; J4 h! B% L3 K1 y; v6 [int41handler PROC+ |- J* J. s6 c8 @ G4 {
mov cl,al- }7 {9 s# K$ ^; _5 F" W$ ^, l' p& e# [
iret# g" }! w# I2 |; G
int41handler ENDP
" a9 ?. W, W4 f ^/ f' }4 K
/ U5 o: ^' e) N# b
! z* K8 w6 G8 m& F' H xor ax,ax
& x$ v* Z |% A5 {. C mov es,ax: n2 P4 o1 Z: y/ F; r
mov bx, cs
8 L& Z2 s g( {/ e6 @; q6 }0 [+ | lea dx, int41handler
, h. D, R* }8 n, [ ^% D( r. M xchg dx, es:[41h*4]" E- r6 r6 _8 m) u5 P
xchg bx, es:[41h*4+2]
9 c' {/ m1 L- K in al, 40h
! a0 b& O3 v" n; z. Y5 r xor cx,cx" `: p0 y! @# F
int 41h
, L! m+ F. ~: s) ^! n xchg dx, es:[41h*4]
0 u; B) J% H0 s( e9 j xchg bx, es:[41h*4+2]6 z! d/ b# ^$ x& V* D; ^ d" c& t
cmp cl,al1 X& B( O5 q9 c" N! J- z$ r1 K: k
jnz SoftICE_detected
6 V6 x: w+ S$ ~5 z% O( O
* }; [' H) n8 f; H/ [: x# L_________________________________________________________________________
L+ {2 Y: E. z' v" _
2 }2 } R z/ f* O2 T4 y4 [3 eMethod 07
5 T9 c. _; B3 X. f* ^/ t4 Y=========
( F/ I' E" \0 z9 F' V4 {+ @4 \
, z* w( T* G8 xMethod of detection of the WinICE handler in the int68h (V86)) A( H# k1 S3 C; c" r7 u
0 t- j7 v6 m7 X7 H/ j mov ah,43h; h& f8 Z" Z8 U: c. B! p- A
int 68h5 @" N! \% V1 w( E* X
cmp ax,0F386h2 Z: Q5 u$ a$ P" J3 ]1 s$ z `
jz SoftICE_Detected
/ F+ Q6 B! g( ~2 y6 ]' b0 [' Z+ c; D& W4 j- w) K# V/ q6 \" `
$ }1 U' ~" G4 ~1 Q9 K' y: c
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit6 k% \ ^2 m4 ?2 M5 J. e
app like this:
e3 \, l1 Q7 D4 W/ d3 d) X
0 \3 V+ F H5 Y+ Z BPX exec_int if ax==68; l9 F. K5 `9 J4 k( S7 ?
(function called is located at byte ptr [ebp+1Dh] and client eip is
F+ y# x2 u& F+ f+ J% K5 Q' Q- M located at [ebp+48h] for 32Bit apps)% R* z; @' o- k7 E, y2 B+ w
__________________________________________________________________________
) c/ {7 E% f+ l9 Q0 V0 p4 r
/ ?& c5 K& t0 w% e, K1 ~& q# E7 c$ y! c4 Z( H: g
Method 080 H/ c/ @$ D3 @8 B4 p8 g- J* v
=========4 u# a# e9 S( X( H) o0 ^& @
B8 R* p* C% `, H
It is not a method of detection of SoftICE but a possibility to crash the. w1 v# K- z; f8 c4 e4 V' D& y
system by intercepting int 01h and int 03h and redirecting them to another
) v/ ]' ]. |' K+ z( M! l8 w6 i' [1 Croutine.) _/ I7 R& _9 s
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
1 r% }: O) D7 i( q# L. O+ Ito the new routine to execute (hangs computer...)# x# H1 }. D9 v$ d$ D R% P8 N2 {
( p& z( `( e/ K0 Q6 M# ]& y' O2 u mov ah, 25h# I/ G. w0 }7 O) C: D
mov al, Int_Number (01h or 03h)
( o" b- F& k7 b$ L. ?$ H mov dx, offset New_Int_Routine
# R! G# F/ W' w: w int 21h5 n; z! k- n& u5 Z( S7 K: J x2 W
8 z) v% b. A6 c$ J. H' z
__________________________________________________________________________
; r" k* L1 }4 I7 i3 x' ^2 o- m6 p7 O
Method 09- T! Y. k1 X: V0 x7 D' F
=========4 @. p7 b) ?( i% [! h
9 O$ u. r/ |/ f0 u! R$ PThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only2 p8 [+ b4 A% N! q; u6 ^/ t
performed in ring0 (VxD or a ring3 app using the VxdCall).& |# Q+ g! |3 T( d
The Get_DDB service is used to determine whether or not a VxD is installed" V2 ^/ d1 [6 Z
for the specified device and returns a Device Description Block (in ecx) for
( x. f N5 }! j; O% y5 ~that device if it is installed.
, g+ Q* W9 _2 [- [- K6 v: ]# U& C% C) Y
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
/ z& n/ x8 v% S+ ?7 @# Z mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-); M4 [/ d- y0 ], d8 I
VMMCall Get_DDB
8 P3 k3 _2 R2 e5 T% J" Q mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed6 V# P& z1 v- I& z
0 D* B* t* i0 g p5 [& y# A/ r
Note as well that you can easily detect this method with SoftICE:
2 [$ K0 U4 D0 |" ~0 y' C bpx Get_DDB if ax==0202 || ax==7a5fh
B1 R4 p/ A" v" ?; v6 D
5 b# Y- A& _$ m" l( S" W3 T__________________________________________________________________________
1 f7 C+ e% C% ^. o, g& p" x9 Q8 x& ~% N: q+ s/ r' j; R
Method 10 V. e S) \0 o. o* S$ A
=========4 p. y: j! Y0 [4 i. f, n8 \
; @" m) c/ j& i=>Disable or clear breakpoints before using this feature. DO NOT trace with
( r# [: \. E/ V! ^% ] _9 P SoftICE while the option is enable!!; ^) \( p) W: L7 t7 D3 b6 C
' O6 C- n9 F% ]- Y$ X# B d
This trick is very efficient:( P# B7 P) s# r" g' F1 s2 K& M
by checking the Debug Registers, you can detect if SoftICE is loaded
$ y- x5 l- ^; {(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
! v3 w3 [/ l; E8 \9 ?% dthere are some memory breakpoints set (dr0 to dr3) simply by reading their
' P2 S' f' C: Hvalue (in ring0 only). Values can be manipulated and or changed as well
! c! ^) [; U% X) D- p t(clearing BPMs for instance)
& R/ z/ p9 |3 ]) P% N8 Y7 w! y8 F" w0 C6 ^$ |$ |+ C; z
__________________________________________________________________________
8 J# M1 @( H& ]1 o& o( q6 D4 d" ^) _' v5 a8 [
Method 11
; }+ a% M6 P2 N) u$ I5 F=========$ T) U+ p" A- `2 ^& [
0 |. L8 F5 f, o! i/ O4 kThis method is most known as 'MeltICE' because it has been freely distributed. f$ M8 r2 h' Z& @) x2 t7 i
via www.winfiles.com. However it was first used by NuMega people to allow. _$ g2 e0 z3 c
Symbol Loader to check if SoftICE was active or not (the code is located
0 Q" j: `2 W6 D% Y7 Q# m4 Ninside nmtrans.dll).4 ]/ z0 a1 y' D/ q) O
, A9 p, D) @; c% U3 c" T
The way it works is very simple:
' c* D1 b" P) G s4 ]It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for Y* L3 x; w9 ?8 b7 k( r& v' r
WinNT) with the CreateFileA API.; \$ w4 v _: T. D
! k6 \$ H& }0 Z' Z$ @4 G
Here is a sample (checking for 'SICE'):
1 S, [: { P3 g: H& i$ D# m; [& g( D: t' O3 D2 S
BOOL IsSoftIce95Loaded()
, B7 \$ N" X* {5 j: ~- p{
. j. R, p6 g' s$ z2 e* S HANDLE hFile;
% ~, n5 y/ t- U, D hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,. J# q b) B$ D5 l+ }
FILE_SHARE_READ | FILE_SHARE_WRITE,
% ^" z% f- t+ A8 L/ z1 e. N# G Z NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);! z3 C) |; Z( H. i- B) N
if( hFile != INVALID_HANDLE_VALUE )& s- ~' u7 j- m0 @! d- A
{
2 Z# c4 O% d0 Y, y, ]7 O5 D) C CloseHandle(hFile);
! F; o. W0 e2 S. g return TRUE;
' o' \" m! V" A3 P" }% I6 P& u }+ P Z! P) A3 k& Y7 y
return FALSE;
5 B1 b/ D# _+ P! A/ f" W# b}
% `1 T$ L* w# F. X% H5 m% S
2 N/ k7 w# q0 Z" D- G* MAlthough this trick calls the CreateFileA function, don't even expect to be
% q5 A2 J( C4 W7 f% mable to intercept it by installing a IFS hook: it will not work, no way!
& D% d& w2 ^) HIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
- U; Z5 t5 ^; `9 Lservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function): h, X4 V* T) @* B: p. P1 e; Q
and then browse the DDB list until it find the VxD and its DDB_Control_Proc _9 v; P3 H3 L9 Y" V( j1 `+ S; C
field.8 s8 M+ h3 F0 F1 A9 D) v
In fact, its purpose is not to load/unload VxDs but only to send a ) {) @2 B+ F2 d' V) N/ J
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)& c( r, l4 `& e; _ C
to the VxD Control_Dispatch proc (how the hell a shareware soft could try. z" s3 h9 r P$ |( Q, ~8 E5 Z& R
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
& M" L M# V; ]& A1 DIf the VxD is loaded, it will always clear eax and the Carry flag to allow
" R5 |3 v6 u, Q; hits handle to be opened and then, will be detected.. ]# T2 F! o' {; k! I4 }
You can check that simply by hooking Winice.exe control proc entry point* C0 O. S& `: D# r
while running MeltICE.
; ^6 l1 {/ k- A* N1 M. u, e; P- Y
7 ~- W& ^0 s) o8 k/ K# W3 s. d0 C3 S; y+ p7 K& ^
00401067: push 00402025 ; \\.\SICE! W( W$ S6 m. {" |0 T- ~. I; J
0040106C: call CreateFileA8 P& {. u" \/ S, {; ]
00401071: cmp eax,-0017 T' X+ c" U$ n' |
00401074: je 00401091: I' c3 l3 H5 O* H) c
( D0 m3 ` h! ~* U4 E# P9 f- l! Q
4 V! l, ]0 B" d; v* d0 @There could be hundreds of BPX you could use to detect this trick.4 U& Q) D! M; }* D/ {1 p
-The most classical one is:
* f7 s* t, ^' F" W; `' W a BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||6 Q/ N X" q w0 [4 E
*(esp->4+4)=='NTIC'' j7 g' y6 X+ p: ]# g+ g( L7 v
( F1 C+ @9 e, m/ e1 n-The most exotic ones (could be very slooooow :-(0 H) t# H+ ^* A6 p8 k1 R; T' m
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
C; `" e y) U7 P$ a0 u9 r' N ;will break 3 times :-(
9 n' E; l' u0 u3 ]& C1 s9 R
4 ~0 z; _7 [" ?% x" V6 [4 Q9 u-or (a bit) faster: i& G, V! }: @" V# d: A0 l. _
BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
: T* X4 X, Y7 r, V( N9 i; s4 A7 P# Q4 p: V4 s
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
+ H* H7 V* Y( I8 i$ r! j8 {; P5 } ;will break 3 times :-(
4 o; [$ C* |2 ^1 k, z) J8 y/ d! ]2 Q9 f6 a
-Much faster:
Z" d" |4 W9 j7 A" n! C. v# b' d5 k! S BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'6 s/ h' [( w$ w: w
9 J& o1 z$ [7 Y% tNote also that some programs (like AZPR3.00) use de old 16-bit _lopen( P% j3 i5 G( Z8 D2 Z
function to do the same job:2 F2 ?/ K {% k: Z' L1 i
0 _% j, E0 f+ g. T9 H; Q2 ^ J push 00 ; OF_READ. h' a: _( M" L( @
mov eax,[00656634] ; '\\.\SICE',0" A$ k! l" e( i( g
push eax! G0 _$ ?& q/ q6 i0 m' _
call KERNEL32!_lopen$ a- [3 ~+ b9 `3 M& }
inc eax+ g. ?+ t7 H4 ^& @: J7 N
jnz 00650589 ; detected# m c( \. a4 t2 V
push 00 ; OF_READ
+ f' n1 X. e" Q. h5 u mov eax,[00656638] ; '\\.\SICE'1 Y3 W9 R( ]; h! V# x1 f
push eax. I3 m# q A/ u0 u8 g: n
call KERNEL32!_lopen
/ L, e6 R8 H# X, L9 B3 G( n8 @" v: Q inc eax, I: [7 J* ?6 U: S6 I6 S" E* d
jz 006505ae ; not detected
1 R! `6 [4 @8 X( `9 Y% s7 j, h, s8 C/ o
% g# ?( v+ ?# ]; c/ O5 C" Q6 L__________________________________________________________________________- m/ U% H% j; Q6 C1 `3 L
6 g* p! o' c, J' H4 `6 q3 n
Method 12
& @8 V6 i: m! W=========
3 k/ e9 H8 z( A
5 F! d% C* t, f* qThis trick is similar to int41h/4fh Debugger installation check (code 05
- l) F$ R* r: U: q8 ]9 k6 x& 06) but very limited because it's only available for Win95/98 (not NT)
O6 o1 e: o, k+ P0 ]0 Has it uses the VxDCall backdoor. This detection was found in Bleem Demo.
: l; O1 H5 N) H1 S7 [) d- K) x! s5 q& p. n1 K* |- }; Y
push 0000004fh ; function 4fh2 [ a, L" k& Q% t" w& T
push 002a002ah ; high word specifies which VxD (VWIN32), X! ^* Z7 ]+ d9 e
; low word specifies which service: Q* ]. @5 x% g5 K/ B
(VWIN32_Int41Dispatch)8 m. g2 _& s' H i
call Kernel32!ORD_001 ; VxdCall& G9 I4 n) y) W7 {& Q1 \$ J
cmp ax, 0f386h ; magic number returned by system debuggers1 C' d8 C2 ]/ G5 Z5 K$ q& G2 e
jz SoftICE_detected0 L+ s" i! {9 }# s
; @. \ @- b% d$ K7 k3 [Here again, several ways to detect it:
! t; q! N- W# v! T" ~% F( f8 k" C) ?, o2 | _4 X; Q: v
BPINT 41 if ax==4f8 ]$ a3 O! J. y$ }- F
( e `* n% @! i/ D BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one; n. ?' O: Q5 ]
) i7 m& |# t9 n5 K& s; z* J
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A/ w' o$ F+ Z( {! E0 u8 f
+ C% W9 v) i" v BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
9 |- f7 c/ S8 e0 z, X$ ]; N8 y' }) ?/ Y
) V& e/ T/ K4 v2 G% l9 G9 `# ^2 w__________________________________________________________________________4 L: {1 G' ?" D/ R3 E1 M
& f {' j* w6 sMethod 13( M1 r! I7 {( ?# }! v3 ~6 \
=========- O9 w2 [: `# [+ T5 ?$ N
; G# Z! M/ b" hNot a real method of detection, but a good way to know if SoftICE is
9 W: _; F1 P" H5 x8 oinstalled on a computer and to locate its installation directory.4 k" `2 O0 S0 {8 k9 p: |6 S
It is used by few softs which access the following registry keys (usually #2) :
! _/ y9 C& `. g' G8 `
$ T: p$ s+ n, q% {-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion5 x% e: K' T0 x! j! t6 z
\Uninstall\SoftICE5 i( C/ q P, ~* [' e
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
( z" b( l8 e5 @" j' n, a( Y8 T-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion% a! g+ J- @2 p
\App Paths\Loader32.Exe) l) E0 I( q2 M8 d: B+ q
/ H& e( X- B' a. ^; k3 p( X( ?
& G8 M/ e) l0 b1 K1 mNote that some nasty apps could then erase all files from SoftICE directory
; V/ K; u2 Y! _, s) K(I faced that once :-(% I. J; r9 d, e+ {" n+ k* z
; p: z2 M9 Y9 R' L! i7 Q% i5 R' L
Useful breakpoint to detect it:: v* r+ y1 O0 O* k9 v3 W( u& k
* i: O' l$ M3 m0 M2 ?6 u
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'- y @$ X9 m; h; ]
. C' }; C. N" z: h0 Q__________________________________________________________________________
- }( G) ]/ u% y& u" B! l6 ?3 i0 z) [/ [9 B
$ I$ l& p r" q+ u( }3 G
Method 14
! d8 @% y0 S5 f=========
A5 o% d# `7 K {4 N5 E4 v4 U3 D2 H* }2 z; F6 }& w
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
6 q' O7 B3 K, `$ a1 F3 [! S U; Pis to determines whether a debugger is running on your system (ring0 only).
2 y$ l$ j& M: F, a9 }+ z1 P3 W4 Z" q2 j! C& a7 g
VMMCall Test_Debug_Installed
; x" C7 g) \& ~2 v je not_installed; o( R+ e$ V' v" ~; b' o
5 r7 q: T0 I. |& C5 ~8 g5 [This service just checks a flag.
+ Y8 l! h7 R: \( v- Q4 {/ X</PRE></TD></TR></TBODY></TABLE> |