<TABLE width=500>
1 i, j, E. h0 r<TBODY>! O9 ?0 G b$ W* Q) X* d
<TR>
) d6 s$ P7 m. R& O<TD><PRE>Method 01 / ]+ {: ?- v2 S! t4 T7 t, Y3 D
=========
3 \9 Z' U& V0 h4 \- Z5 f! L" K5 |$ T, [
This method of detection of SoftICE (as well as the following one) is
- W& d/ C2 @7 T. {used by the majority of packers/encryptors found on Internet.
' d: o9 S/ t7 ?It seeks the signature of BoundsChecker in SoftICE
! t, j# l9 S8 J1 a( k* A7 H) s7 P% |% L1 ~
mov ebp, 04243484Bh ; 'BCHK'
0 U$ _) g2 I o1 S mov ax, 04h2 y6 q+ l6 m- r5 }) P
int 3
1 H, z, E* P7 ]8 {; u cmp al,4
: Q& x% L7 f# F( L- H T, L' | jnz SoftICE_Detected/ v. | @7 i/ x
* F/ z- }' [3 K _( O1 G) _5 D___________________________________________________________________________; [; p. c/ I" j
2 z. [5 `5 ` Z5 Y" F5 o/ L9 aMethod 02, ~1 H* I- e% ~
=========$ V+ r& W: b5 j2 X: M8 w
5 k9 W$ m& w3 M5 s6 J
Still a method very much used (perhaps the most frequent one). It is used7 _$ ]% _7 [: C9 F
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
+ }% R6 }# v N/ j0 S! `3 cor execute SoftICE commands...
7 e' r! k2 V# ]It is also used to crash SoftICE and to force it to execute any commands5 Y+ W l+ U$ S8 x+ f' _, ?+ Q+ q3 y+ K
(HBOOT...) :-((
& b- U2 A) [7 \6 A" X( N
6 x+ t4 X3 T3 L- c, ]Here is a quick description:
, J$ ?7 p2 V) V8 z7 H-AX = 0910h (Display string in SIce windows)
7 {: X% E K7 ?9 C# _$ A-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
7 r$ d. t2 k1 O3 j/ t( f0 p, ^-AX = 0912h (Get breakpoint infos)
5 r% C' t( E; c-AX = 0913h (Set Sice breakpoints)
7 f4 p! B/ R: |& I-AX = 0914h (Remove SIce breakoints)" o+ f$ m% Z6 L( g
* T' y) ^! R, y3 nEach time you'll meet this trick, you'll see:$ }# C7 w+ ~3 G) e- i* |
-SI = 4647h
, p# }, n5 M5 _6 `- g* K( H6 ]" C-DI = 4A4Dh
6 }" E& }' D1 S9 PWhich are the 'magic values' used by SoftIce.+ }4 w0 m9 j+ ^9 X9 K6 j& g
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
0 Q* m( {5 z) m7 D3 o; u% F2 i4 }' W m# O$ m2 ~) E6 l
Here is one example from the file "Haspinst.exe" which is the dongle HASP
% p. { j8 k( x0 K1 h& _Envelope utility use to protect DOS applications:
, I5 o3 C, h1 a3 n: a
1 P. z% s- r/ m7 Y
1 n* _9 A/ Y9 U- |6 l$ z4C19:0095 MOV AX,0911 ; execute command.! r* p8 l0 s0 Q5 {- d
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below)., N0 F/ F4 n' c: n E+ p
4C19:009A MOV SI,4647 ; 1st magic value.
% @8 G$ |6 O! O' E/ P5 D4C19:009D MOV DI,4A4D ; 2nd magic value.
% C$ h2 B* ^3 S" |; k4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
) N( C; m5 c1 E8 Z; Y' Q+ i: K# K4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
: b! g+ g! v _0 x4C19:00A4 INC CX
: b. O- E: a) p1 L0 _4C19:00A5 CMP CX,06 ; Repeat 6 times to execute/ ~, t+ c7 K& f; T( V/ E
4C19:00A8 JB 0095 ; 6 different commands.4 Y! l: t. K( ]; |% K9 J
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
: n) `! T- U: M4C19:00AD MOV BX,SP ; Good_Guy go ahead :)& r/ F% u, M- U/ P9 A
( m1 ^; O, S; ^+ |! G S$ N
The program will execute 6 different SIce commands located at ds:dx, which
0 }6 n/ ~ M6 |4 dare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.' f; q6 J8 g8 Q% I
8 w, D% R# T& f# k% y$ ~
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.1 f. J, z4 x5 j& G
___________________________________________________________________________# W% F* Y, ?0 b$ Z U6 q
9 ]: ?/ _' e" M8 [) H$ d9 }
3 ?9 c) ~3 ^( W; \- ~- mMethod 035 C( R$ u- P7 I; b( Q0 X
=========
3 C! _' {( [* K- M
3 Y) L% T* h- L [: U, N7 aLess used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h$ _* x) s/ @% N' r
(API Get entry point); w4 r7 K5 a! t5 }: w
5 A l' b7 y' C6 N! n* p9 {) `; _0 G* C( J! ?3 b% G) z
xor di,di: s/ Z- q7 ?7 ~+ N& Z6 g/ e9 a, r
mov es,di
) s" G, |+ @. W, L _3 P mov ax, 1684h * Z( F: a5 g+ w' J
mov bx, 0202h ; VxD ID of winice }/ V4 p+ {) n4 p+ |/ l
int 2Fh
7 X* w3 R+ S/ b; M( p mov ax, es ; ES:DI -> VxD API entry point- I5 M' Q/ E0 o' y' E
add ax, di: C6 v& \+ o$ P+ d% L. ~
test ax,ax' K6 L5 q% ?( u1 I6 V6 n) j
jnz SoftICE_Detected
1 r) a/ [7 b/ F6 {
" e. t$ r4 s, }. c0 p& Z9 V# C+ `___________________________________________________________________________$ s: A. }5 c- S& ^5 _" K/ D
3 M" N {) m1 e5 |
Method 046 _) C' q1 w4 L! @1 T) v* z' M
=========
( S7 S1 F- t& e
" d. `+ E' P( r* I4 m( ~5 FMethod identical to the preceding one except that it seeks the ID of SoftICE& j. T( C9 b; q7 X* @; D
GFX VxD.
6 U7 w. ]2 B$ q5 ?9 i# R& G/ [+ Q' z- z- @2 R1 {- w0 H
xor di,di
5 K6 K% m- w' k1 z1 | mov es,di. A4 k' S$ m9 c: |# n0 ]8 f9 l+ @ d( ~
mov ax, 1684h - o5 V) b; }) }9 }8 F! p9 }
mov bx, 7a5Fh ; VxD ID of SIWVID; K5 L+ b/ x7 \
int 2fh
. S/ f; D3 L0 M' i4 P6 U mov ax, es ; ES:DI -> VxD API entry point" k) e/ K9 v; f% g
add ax, di
; j4 G2 n' f7 g2 d s# R' B test ax,ax4 L5 M* y. S% h! d, z% ^
jnz SoftICE_Detected/ a) i5 \, v' G2 E: O# E1 O
_& @/ C* b+ q6 U; H: ?8 |8 V
__________________________________________________________________________) i, s0 o _1 s4 ~ j$ q4 Y& z
+ q8 D/ C' X8 |
( ]; l0 {% {9 ^4 S5 e8 s
Method 05( v1 ?7 ]$ Z U6 G* \* M* M
=========9 c% K6 G3 T( \
: W ]4 B' u. p$ xMethod seeking the 'magic number' 0F386h returned (in ax) by all system
+ _; W+ ~% b- Y6 B+ W* S4 odebugger. It calls the int 41h, function 4Fh.
) n' ~. j1 B" V. [+ V+ b3 V* u. g/ ~; y+ fThere are several alternatives.
) ~& F. D& \7 k% K; \6 ~
/ v7 H* i# ^; oThe following one is the simplest:
2 w' x- Z4 Q# v, [1 A( D8 P, ~9 ^& S. ^# Y8 w* }. y+ H0 n
mov ax,4fh3 S1 o0 ], V2 }0 Z+ e8 b
int 41h, w, Y7 _4 ~$ _. _2 h7 X' M# x( ^
cmp ax, 0F386
$ J6 `1 `! q9 Q" a) f2 A& W9 \* e7 \0 K' e jz SoftICE_detected. e1 I; S% @0 j- n1 q, b. x& G
0 }/ @2 Y: j* s, U m, h! ^( ~. ] u, q6 `$ k1 \5 n" R
Next method as well as the following one are 2 examples from Stone's
9 @ A; T1 s$ s2 y"stn-wid.zip" (www.cracking.net):/ K. ~; E1 }( w8 p+ b% Z
8 ~( }- e) _# J- b3 z
mov bx, cs
m8 e2 S6 O q. U lea dx, int41handler2. S3 y- K6 J) t1 ]+ G! o, N
xchg dx, es:[41h*4]8 Q6 s/ P# W p
xchg bx, es:[41h*4+2]% R; t9 \; s. E4 K& S0 j6 Z
mov ax,4fh
' M% i; R( E/ |) C& Q int 41h$ d/ ^, B; m- [& C
xchg dx, es:[41h*4]
% R9 e' {% V8 X- T xchg bx, es:[41h*4+2]6 Z$ B0 U$ V! V
cmp ax, 0f386h
" p/ I% }$ ~+ i# o) f4 m' N9 L jz SoftICE_detected+ T0 m. \9 L3 m1 e4 x
, s1 N* \7 z2 a2 C. E) o+ _
int41handler2 PROC
4 S& ~- S+ S, j) C5 i1 `$ g" v iret
) _/ B8 U! N$ M, tint41handler2 ENDP
* }! E2 M0 B/ z- F8 I8 f& a# o+ Y# Y3 a0 s' k( h" k
% _' y2 A+ u. N& z! j' I5 P' {* [_________________________________________________________________________+ I- G/ I& m* I2 F0 i' N- B; W
* Q0 x# g) V I7 [2 J9 }8 @- w) r& B k, D
Method 06
- Y |) j& m$ q, ~, H8 e: a=========
1 E6 ]! f: m# p0 p: U; }- J% _
( ~7 J3 l9 j4 C0 y4 |$ h
K- Y! {* t, q3 J( \2nd method similar to the preceding one but more difficult to detect:# B6 @5 Y% R2 Z4 I; ?9 e* R9 v
0 Q+ Q3 m: h: Q
$ e( o+ C% }! P& T# ]: M0 p( {
int41handler PROC
2 g" |) U U4 R2 Z' b( L3 W2 p. `, w mov cl,al0 x& J+ n! Y0 o( f, s' E* m4 o
iret0 r/ T# n8 g* _* G1 [- z; G' m$ E
int41handler ENDP5 L; q o/ a, a/ D
; x' f9 u3 }& L A C
/ I- X( ?- F7 r4 v* w
xor ax,ax2 a+ U1 G5 p& I: ?
mov es,ax
2 Y3 e4 ]4 d' {( | mov bx, cs! v3 W7 ]0 ^- X* ?+ s/ I( g! O
lea dx, int41handler4 j: k9 x4 S7 s4 @! `. Z# i; Z
xchg dx, es:[41h*4]
5 [! [* ?( ^, H' k" _: ?; ` xchg bx, es:[41h*4+2]( N* r* e3 e8 t P3 x: b
in al, 40h
" Y& M/ S, J2 F; i0 { xor cx,cx
( v; P9 T) c" K7 m# j* b E int 41h
- ]0 |7 b5 K1 I# q; L) e$ ` xchg dx, es:[41h*4]
% d! W, z4 {5 ] m$ e xchg bx, es:[41h*4+2]
1 S/ r; N- w* k, f$ c: \ cmp cl,al5 V3 @1 B+ E4 {
jnz SoftICE_detected
1 ^ t! {# k% Y! Y7 y$ I0 W" ], A6 b& H; x: k5 z
_________________________________________________________________________6 [% B# S" L, K9 _5 Y/ D7 P6 T! L
2 N) B9 F- k$ F. R& L, p/ {
Method 076 J" a! x2 K9 \+ t! r8 W/ |: T
=========' A1 i! J$ q+ \0 X
0 c' _. b- Y7 ~# r5 OMethod of detection of the WinICE handler in the int68h (V86). r2 l; }! B* Z
* @4 h2 h5 O3 D* [$ z mov ah,43h0 ?% E, a( z2 U. e3 E! m' a8 d
int 68h2 ^; H8 {" O% D! N
cmp ax,0F386h c' a2 |( p+ ~: n8 W9 p
jz SoftICE_Detected6 W# L' t. @2 Z$ F/ p6 k; Y
/ r9 p# b: N3 B8 Q* J3 i* H
& C8 m5 N8 Z2 @8 E$ Q! W+ b=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit$ f1 g3 g) ]. ]0 D( }
app like this:
W. }+ H! [9 M5 b0 ?; t: G! Z* h( }* p5 O
BPX exec_int if ax==68/ J9 t* {9 s, t; p) S3 H$ ]
(function called is located at byte ptr [ebp+1Dh] and client eip is
" J N; V: k+ n# K& c# l located at [ebp+48h] for 32Bit apps)- }( F4 y8 @3 C
__________________________________________________________________________& z1 D2 p0 x3 ]
# C' B! ?# C* U! ?
/ G3 k+ f( ?/ F3 N" U5 F* j, }
Method 08
% u g# Y7 x2 v$ b7 K=========% l4 t- C2 Y: I/ _5 e* O" a
# [( n6 u3 z( \% B$ D: ~3 YIt is not a method of detection of SoftICE but a possibility to crash the% D# ^% Q) \+ C# B8 q% Q
system by intercepting int 01h and int 03h and redirecting them to another) B8 o+ z; Q+ t+ r
routine.
9 h. ~' t$ U: _$ KIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points7 r h" |; m9 W( C
to the new routine to execute (hangs computer...)6 \ n/ s8 m7 _# b- `3 V6 b
8 K# P6 E6 M9 e) ?/ b$ a mov ah, 25h/ J2 ~2 r# G7 y+ ]- Z$ r
mov al, Int_Number (01h or 03h)8 T L% e2 J5 w& m: D6 l e0 w
mov dx, offset New_Int_Routine
/ X2 B0 |: c, M6 C2 h6 J int 21h2 k; o' G" k+ t! a5 ]
6 H2 B8 E! X3 A* Q1 @7 L
__________________________________________________________________________5 L- b2 p8 v3 g W( W/ {
% j! z$ g8 B/ M& A) z+ Z* YMethod 097 D/ y' }) e3 `! [- O( t. c
=========7 J4 J3 n+ \# O
$ _+ F+ u5 ^, N7 Q! rThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only. ]7 l' V* X" l! _( W; B
performed in ring0 (VxD or a ring3 app using the VxdCall).; j0 p2 F* E# E: {" y0 A
The Get_DDB service is used to determine whether or not a VxD is installed
/ G/ B5 y/ [# }. B4 M _# ?! r6 \for the specified device and returns a Device Description Block (in ecx) for
: c1 w x' H2 l5 wthat device if it is installed.
' P8 `0 T: j9 ]* f t! r/ Q( k: E: \) S2 l; ^9 x
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
: l2 f( y( j. M t* Q mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
7 o& \; F( T2 B8 m' u VMMCall Get_DDB
" q! |/ H6 n8 p! ~4 X) T3 c mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed. Q; q2 _7 Z9 [+ t; c6 Z9 A1 @* W
# W4 e! k; ^! P! ~' c% t0 G, ]) X7 }Note as well that you can easily detect this method with SoftICE:. |0 \1 V' z3 }
bpx Get_DDB if ax==0202 || ax==7a5fh7 g3 w+ m5 G0 x( Q
6 M2 L L4 p5 `# T% m" F, v: Z2 a__________________________________________________________________________
/ v% F+ s; Z# h/ i7 q5 w7 O* y8 e! z" r; y' \
Method 10) N( o4 A4 w. v7 E0 k
=========
d4 k' s; W9 T: B D
0 }" ] c; @2 i/ i=>Disable or clear breakpoints before using this feature. DO NOT trace with
5 [8 v, W" i, v) } k4 N SoftICE while the option is enable!!
1 e! ]( F9 p+ x7 @: V7 `# {) X: n5 O6 w/ s# j
This trick is very efficient:
: m# t* R8 d8 ?3 R0 n) V" T! Oby checking the Debug Registers, you can detect if SoftICE is loaded
) ]/ w* t- y0 {1 K1 ]+ y3 x3 w(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if6 Y {- q$ y5 l4 B& g" J
there are some memory breakpoints set (dr0 to dr3) simply by reading their
/ W& j6 r" U' ?2 Dvalue (in ring0 only). Values can be manipulated and or changed as well- x/ N. B9 k- W8 S d9 A
(clearing BPMs for instance)9 k- `7 G( }; C% n0 Y/ G3 D
. g$ V3 {7 t" L# ?& ~
__________________________________________________________________________
& @6 w9 i5 G+ k. X9 r! _: h& k. X0 N5 I8 d( j
Method 11: {! b. p( @6 a A6 Q9 k
=========; e$ ]6 |4 R: u0 t
" w% R6 n& r8 x, s ~This method is most known as 'MeltICE' because it has been freely distributed( L5 s6 d L& G* U' N
via www.winfiles.com. However it was first used by NuMega people to allow+ N$ E& V$ P" k) E. ?$ c
Symbol Loader to check if SoftICE was active or not (the code is located
2 M; [' K$ S9 A! winside nmtrans.dll).
$ o; n- A7 B' u j( v
3 o, m5 \' v% L& R, P2 `The way it works is very simple:
7 K' G# h7 G5 L1 OIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for9 N# i6 L( _! h- H' x+ I- @# u0 z* S1 g
WinNT) with the CreateFileA API.+ e& \6 i! Q L8 H; g
7 R" u, D% L% ^0 y4 ?+ yHere is a sample (checking for 'SICE'):+ H J7 p3 ?5 v9 L6 B
1 R$ `- ?7 n% Y+ x @! Q& TBOOL IsSoftIce95Loaded()2 m( ?: p# E# @2 ? S! x
{. `* P0 u2 n) f8 J+ N. B' ?5 T
HANDLE hFile;
4 u4 s/ k( l: ~0 R3 Q" d hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,1 u/ m4 v0 F0 ^. ]
FILE_SHARE_READ | FILE_SHARE_WRITE,! O) p" @4 `) r7 i9 W. D# Z) {
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);' u9 U- P: b/ I4 |" x
if( hFile != INVALID_HANDLE_VALUE ): l+ ?+ c$ _) T' t
{; M. m- U$ n5 _$ V
CloseHandle(hFile);
7 X+ w9 l2 Z' e0 M/ f9 x return TRUE;7 d- \4 A0 m# q$ t6 |/ E, |) r
}
/ d% ~1 t" Q0 S return FALSE;
" y. D3 \0 {2 r* U8 |}$ Y3 }; J# a; m" ^
, i6 m; y0 ^( c; e$ S) V$ xAlthough this trick calls the CreateFileA function, don't even expect to be4 w$ C% @6 k, ]
able to intercept it by installing a IFS hook: it will not work, no way!1 l( a$ Q5 ~. p: G% |$ w& R9 b3 m
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
: x3 z- B0 Y2 c- m' f; |service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
, F! [1 r" [$ \, B5 wand then browse the DDB list until it find the VxD and its DDB_Control_Proc
2 v5 X! l6 g' N; I- E9 M$ m4 O1 O0 b( {field.
6 n) O( T+ @( S' e# `& L7 FIn fact, its purpose is not to load/unload VxDs but only to send a
0 }$ x9 K) D4 D3 r hW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)% j) Y+ u4 y, f( x2 Y' l
to the VxD Control_Dispatch proc (how the hell a shareware soft could try& J" c/ R+ `$ N& u. w# W# G
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
7 G- v$ z% O0 \8 t$ v/ P/ f! s. o( mIf the VxD is loaded, it will always clear eax and the Carry flag to allow1 \2 C8 B) P3 m' J
its handle to be opened and then, will be detected.& L6 m1 n# A4 S9 R: o% q% b9 Q4 m
You can check that simply by hooking Winice.exe control proc entry point" f! o8 X n% y5 O
while running MeltICE.: H8 d: @) o, x+ q1 j! I
( z) P- m, I) ?6 C3 y j" o" ^8 e0 Z1 }# G y0 d$ n
00401067: push 00402025 ; \\.\SICE
# u4 t! ]6 \/ L1 k5 A 0040106C: call CreateFileA; M* `2 i# {& q$ l2 L! G
00401071: cmp eax,-001& D) v; \4 F3 g% M K. y' J, t0 I8 ~
00401074: je 00401091
3 _: X" \: l/ C0 I" @: j" j0 \$ J/ Y$ A
+ n: B3 I1 U" Y% m, yThere could be hundreds of BPX you could use to detect this trick.8 c) H4 a$ E9 K+ M; N
-The most classical one is:
; `! b, M; g( a; a6 t' r% C- c' g, z BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||2 U1 S. \: Y+ S0 a, Z1 X1 O8 v
*(esp->4+4)=='NTIC'% y+ s2 Y' b* U3 F
7 z, I+ _0 w# {/ f. ]3 G# S
-The most exotic ones (could be very slooooow :-(
. H& B2 x; F ^; I BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') % E. T' B H3 }
;will break 3 times :-(
/ u/ u7 u ~( H; V
( _! t3 `/ {7 ?' e5 D$ r-or (a bit) faster:
3 [; c- h9 ?( ~1 Y1 R' G BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
: [$ ? }6 O5 O9 `5 k' P# `
0 u: D: S* z4 a" F/ N$ C) ? BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
5 S7 U- |5 z& n1 _ ;will break 3 times :-(
, W! Q w3 m7 Y! b) h* W, e" X" i/ A9 ?% Z% o, }! I
-Much faster:) y# z1 X* U9 n3 P8 @( ~0 j0 d
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'$ z8 o2 e Q9 ^6 j) Y. C$ O% |1 [# p) E
% `& E7 \( a( {. i8 |
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen$ q. i% S! N: V, _ t& M1 n2 m0 \
function to do the same job:
: A/ A w! M# @" a k
/ e/ h, u1 C9 B& Z push 00 ; OF_READ- h r( K3 C9 q( A
mov eax,[00656634] ; '\\.\SICE',0
& K. c4 l! s O0 \( J ^% d& `6 i% n push eax
' U0 }0 ~- V; p; [ call KERNEL32!_lopen% c$ ~) E7 v5 E) r. f
inc eax' T5 @2 V" T9 ?' m! y) k2 a+ Z/ F
jnz 00650589 ; detected! H2 g% S' m; x! ?$ S L
push 00 ; OF_READ
; b; X% d( [! A. K: Q mov eax,[00656638] ; '\\.\SICE' [- A2 h: a7 u2 T2 F" ]7 i- L. e# @% q
push eax
% _- g6 h z7 K( m: d call KERNEL32!_lopen
0 l! c! z* g* _6 Y F inc eax
, p- \; u7 J, }/ t m jz 006505ae ; not detected! W6 ?& h" K5 N& v/ M H
$ R/ Y v* G% G, o" D* A' O
) D. ?9 M, ^# z5 I) {9 z5 Y
__________________________________________________________________________
/ r0 D; t2 N8 Q9 L# u4 R; Z: F; a
Method 12
+ z8 {, O5 b4 S; w9 a=========" j7 |8 s3 l' X: P
! W k8 F- Y% ~. K9 I4 _This trick is similar to int41h/4fh Debugger installation check (code 05
6 u0 X' O0 G+ y0 \' C+ i4 ?& 06) but very limited because it's only available for Win95/98 (not NT)
0 o! w, s8 a k+ [( {& L, |7 }3 Fas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
4 p; J |) R. [& Z. O
" \+ h9 V+ C7 S, C' V push 0000004fh ; function 4fh( R! R# b" c) s; N! S+ c
push 002a002ah ; high word specifies which VxD (VWIN32)% \4 u- s8 U+ c4 j
; low word specifies which service
: S4 I. x" V3 y" }, y; D (VWIN32_Int41Dispatch)
- ]* D% i' j8 ?( |. {7 n/ Q) ^& ~' c call Kernel32!ORD_001 ; VxdCall
3 m4 r3 {& P+ r# n cmp ax, 0f386h ; magic number returned by system debuggers
, `0 ^0 W5 `7 U% c" z2 ? jz SoftICE_detected
0 ]/ A. T% q5 Q) Q1 V- O7 }/ t* ?9 a( i9 |- ]! j/ B4 h! {
Here again, several ways to detect it:8 i, S0 k7 W9 R1 n& w4 {4 y4 A) n4 p
8 l! c9 P/ a6 A+ Q2 d/ L
BPINT 41 if ax==4f
1 G# u7 o% R# r
9 B5 ?& |$ @& { d5 D4 `* M BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one: c/ x5 `. b+ P' Y/ j+ H
' |# W2 V7 x/ Z% U. x6 q6 t: S
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A- l! F1 X$ W- K6 S
# r6 h% Z2 C, F, g! E BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
1 H3 {' O( u# V! l7 r; X! B3 B6 V# @3 v. q1 C+ F
__________________________________________________________________________: E" |( D: A4 N4 c/ l
7 C+ c& |& }5 [/ z4 XMethod 13
$ j7 }0 E p0 |; |=========; ?) C" k( [ z. {2 y. o$ W
8 D+ \4 s. z5 T( Z2 d$ K* x
Not a real method of detection, but a good way to know if SoftICE is. K0 t5 k/ W9 x d
installed on a computer and to locate its installation directory.
. G( U6 Q$ S5 vIt is used by few softs which access the following registry keys (usually #2) :8 r/ h. u' Q+ k2 F8 X
% r* x4 j6 z6 a8 b5 {
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
5 o3 x; R7 ~5 O8 f\Uninstall\SoftICE
$ B4 d+ j) {$ H8 l; V" b-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
0 u; J% |3 e1 @/ }-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 E3 @+ a: D/ p# Q& ~
\App Paths\Loader32.Exe% @0 [" r. X& w) V, ]
3 c+ T, `4 Z4 Y# }: {# i) H, ^
/ {8 Z3 B/ A2 C$ \0 JNote that some nasty apps could then erase all files from SoftICE directory
! W* w1 k: D6 G& j( ]1 \- W(I faced that once :-(% }5 p2 |0 Q1 a- P
- K5 |( Z" |! n/ EUseful breakpoint to detect it:. z# X* r* r1 Z7 o! z
& n7 ]7 j* i5 `9 ?2 x BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE' Y+ j; \, r9 O7 N$ x
& j: ?! R2 a% z) ` n; j; e__________________________________________________________________________( L9 H9 k/ ^9 q- D; ^2 [3 A- s- ~
$ s1 m% B& M: o, d) b8 `% u0 D4 z
2 L1 u; A" _0 j5 ZMethod 14 : t0 d+ v" o* R' d
=========$ M0 N! ?4 R, @: n0 Z& a; Y: d
! b' W# t( G& m0 p2 W4 j) a
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
+ @9 D$ K0 m& @+ V$ j: Iis to determines whether a debugger is running on your system (ring0 only).
, `. h) d2 h. q5 y' {; u z& N9 c' x; s, j! \" `# Y3 r0 o+ ~! ?3 \
VMMCall Test_Debug_Installed: Q3 ^$ u0 U& o7 e
je not_installed" x9 B* x; W2 w
) R2 v% n! z8 ~3 C
This service just checks a flag.
- \ V( p4 h+ T4 m; F; E</PRE></TD></TR></TBODY></TABLE> |