<TABLE width=500>! p' L0 X6 v. `4 B& O* d
<TBODY>
8 k3 ]( ~$ K3 F$ m" ?<TR>! w2 p+ l) x' Q: g8 R& h
<TD><PRE>Method 01 $ {: Y! m- j' A6 M! H; p
=========
& ~6 W1 Z8 Y5 s z$ y
m1 z4 Z: A1 M# yThis method of detection of SoftICE (as well as the following one) is
, @/ m/ m- c0 n- vused by the majority of packers/encryptors found on Internet.9 y1 @' k& x7 e2 H! W2 i+ o, g
It seeks the signature of BoundsChecker in SoftICE
5 V l$ J, H8 ?# b- _. Y
' e( ~, v* ]" p6 @, l$ d0 W mov ebp, 04243484Bh ; 'BCHK'
9 ^2 o( L6 x& I3 { mov ax, 04h* u9 \+ N6 F1 Z# Q. z' f
int 3
: B. @( Y) o7 F5 Q% Z8 K8 i7 v' E cmp al,4: a7 i- C: Y: o- X5 J+ [
jnz SoftICE_Detected! k- l7 H4 x% ]: X: x; O+ q, c A
, Z3 V; b6 _+ q( \* T" j* q___________________________________________________________________________; l$ |+ }+ R( b1 [, |+ f4 ]- R
3 {, A5 R" Q6 o HMethod 028 [3 r1 Q5 x6 I3 l4 p
=========
8 u- ~! Y% @3 E3 i) j/ b2 L0 W: r& X( `. ^! R
Still a method very much used (perhaps the most frequent one). It is used
; P3 e" q$ r) f9 o9 {to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
2 r2 H0 A! r- c) @" U# D: Vor execute SoftICE commands...
0 o& S- E" A! S) rIt is also used to crash SoftICE and to force it to execute any commands/ V5 f! } C2 k1 _: e
(HBOOT...) :-(( 2 t6 Z. \9 T; z
7 S! {1 f8 {, {) K9 L9 RHere is a quick description:7 L. P; |' n. A4 C! v8 d; z& w) ^
-AX = 0910h (Display string in SIce windows)' U/ |: u1 o! \6 a- W0 |% c$ f0 s
-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)8 D: c0 u3 Y8 u; h( d: ~
-AX = 0912h (Get breakpoint infos)
6 N! R" {0 s0 y3 j-AX = 0913h (Set Sice breakpoints)
; I+ J7 T9 P2 J5 X) k; t, }; S-AX = 0914h (Remove SIce breakoints) X/ \8 j0 y; G# e6 o
0 g) ?6 V. s: J4 n# A0 W# UEach time you'll meet this trick, you'll see:, q' C% B. e+ s$ a, z; j3 E
-SI = 4647h' ~$ Q7 M3 E0 L. B9 u
-DI = 4A4Dh
4 u# M2 M: P `& G) hWhich are the 'magic values' used by SoftIce.8 |8 g; _ x+ J. D4 f- S9 Z o$ U4 I
For more informations, see "Ralf Brown Interrupt list" chapter int 03h. U) d2 g2 G7 a" d
: K! H- ?, k) fHere is one example from the file "Haspinst.exe" which is the dongle HASP! B- X& ]$ M. l, n4 F. `
Envelope utility use to protect DOS applications:$ m6 [ M! v1 W! u, X, x
0 W& ]3 a: l1 f( |/ e; n+ y1 ?9 c% Y7 B Z1 n: Q
4C19:0095 MOV AX,0911 ; execute command.
5 Q: [5 o# z. @) J4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
3 F7 |& H' F" P6 u+ { m4C19:009A MOV SI,4647 ; 1st magic value.
7 m4 p# h5 l9 U: J4C19:009D MOV DI,4A4D ; 2nd magic value.
! N- w: I7 g6 X8 S# M; w4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
* [4 N' E+ ~& [. ^, ?( Z3 J& M4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
, q- W4 K* S k; g4C19:00A4 INC CX
) j$ z( G7 K% X& Z6 i$ ^9 Q H: x! M4C19:00A5 CMP CX,06 ; Repeat 6 times to execute% l+ w) T2 ~+ f0 I; w; h
4C19:00A8 JB 0095 ; 6 different commands.
' x d t- p9 I) ^7 ?4C19:00AA JMP 0002 ; Bad_Guy jmp back.9 R3 u8 h$ C1 J
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
) M' ?1 s* v% ]- \9 X4 w
" q+ K; z0 m8 N6 f7 H2 r6 l5 s& hThe program will execute 6 different SIce commands located at ds:dx, which
! e# h% e% v: P( Rare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
/ _0 I, o7 C$ Z! D+ A3 x% w) E# o" b
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
# |/ x" { `0 L$ `0 U7 l; u7 [: A. y___________________________________________________________________________
5 y7 u5 s; v* Z) ]! h r0 S* ~9 U. ?
" l8 _8 ^! \# _/ `: Q/ i6 S8 F0 d' _
Method 03* ]$ m, _8 m/ `& ^3 j& B) P! M0 X
=========; R" E! w% V) m, U: B4 R
: H, k0 [0 x O9 a4 v7 _6 F
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
( r+ E% T5 @/ y0 V6 p# n b(API Get entry point)2 h) g1 [2 _" g p6 |5 U- x
3 S0 Q5 x0 {0 M! |
+ o- i4 \4 r }/ B$ {7 { xor di,di
/ g6 v% _# X5 }& y- H& J mov es,di
]) B/ c8 Y* q' ]- K2 k mov ax, 1684h
9 Z7 q3 x5 \6 K* j4 a* ^ mov bx, 0202h ; VxD ID of winice( y0 B- u2 x. Y( c
int 2Fh/ U3 c# j: e4 a
mov ax, es ; ES:DI -> VxD API entry point. a. X* q* r. Q7 d: K* ^- P
add ax, di/ p! N7 X# b( w" Z* O. |
test ax,ax
~; Q" y! K: L2 B: ` jnz SoftICE_Detected& B: {# ?8 u& R3 s Y) e P: t# e
" l# {8 h! Q) W, M, u3 n% O
___________________________________________________________________________
" u8 o3 `3 R4 T7 t* Q/ v1 \! z# x
$ d2 ]# f( `' Q& S3 V ZMethod 045 z- a# @# H5 G* u4 s* |+ u( x
=========6 T0 M# e/ H8 H& W* j
4 K- ^7 ^2 v) YMethod identical to the preceding one except that it seeks the ID of SoftICE
. j+ h; ]' Z6 D s8 UGFX VxD.) \9 ]1 L9 b# \; e5 @4 V: V4 c
$ {% X) n9 v) E
xor di,di3 q, y) F) M& y5 `/ k
mov es,di9 l+ l! n, T* f
mov ax, 1684h
4 I4 [) I' t4 K: f. { mov bx, 7a5Fh ; VxD ID of SIWVID
/ c. ^9 k! h6 F- d* D int 2fh
; X4 o% \4 z" V4 y7 w ^ mov ax, es ; ES:DI -> VxD API entry point- }: q# H0 p6 r& Q3 j3 ]
add ax, di1 `& \; X( a; A& `
test ax,ax- m, x2 I) k4 ? h4 j- {5 y$ B
jnz SoftICE_Detected
/ S( C1 T) P# c7 M F/ ^1 t$ U8 P9 D
__________________________________________________________________________7 F' N# \/ r1 X- l. B
* ` O2 a" X! p1 p# V1 k
: z8 K' |: m7 L2 I
Method 057 G5 Q5 N0 H% z" T1 Z) B
=========
4 c% m8 {+ _7 s7 Z
# x5 }. ^$ D* z: f7 ^* p! l) \Method seeking the 'magic number' 0F386h returned (in ax) by all system
, x8 W) S8 U0 `4 u* m: t' e2 u+ ldebugger. It calls the int 41h, function 4Fh.& Y& U$ [6 V3 {% E( X
There are several alternatives.
% p$ v0 o8 M- u# W! Y/ Y: z
* ~3 _+ v& J) X$ eThe following one is the simplest:
4 D8 V' n. V9 t4 ?7 n- {) }4 t
/ c7 s$ @ T5 I" u0 T mov ax,4fh3 `0 \, Q) @- w' a* P
int 41h3 c; |; j0 g2 w$ k9 X$ X# u
cmp ax, 0F386
& c$ x7 B2 n, z: n jz SoftICE_detected1 T1 r0 U H; B/ n ~5 f
) S9 ~3 J! w4 {7 ~8 @ y+ F
' _5 }7 p: c7 z9 ENext method as well as the following one are 2 examples from Stone's
$ ]! s8 [2 u- |"stn-wid.zip" (www.cracking.net):1 {) X& |# W( P& e, F+ d. g; V
8 I9 y; |3 z' Y: {0 G8 s9 ~
mov bx, cs- P; a4 ]2 V4 p5 D! _( l* p2 n& Q
lea dx, int41handler2- T2 L9 C1 R \: u2 m
xchg dx, es:[41h*4]% e5 r+ e2 p( E2 R$ p5 z& n
xchg bx, es:[41h*4+2]7 h- {0 n5 a6 @% r1 }* @/ b
mov ax,4fh
2 w, Q# W; q) B. F int 41h
) O5 L8 [" B0 r' s% U% v xchg dx, es:[41h*4]- r( i0 ~" l% R/ C! O g
xchg bx, es:[41h*4+2]
9 P; ^$ e+ A. G" Q7 G( t2 j cmp ax, 0f386h
9 f( s- d. t8 l jz SoftICE_detected4 @% g3 r) j" a; S+ z# K1 y# Z; X3 J
2 F' C" S) R( C# Z; ?4 R1 Vint41handler2 PROC
+ T0 q0 z: a8 a; V1 S: f: e! T iret$ Z6 m& n4 {8 V, B; j% t
int41handler2 ENDP
9 d, k/ s5 R( v2 h) J; i# F! ^( ~& v1 b
: _/ `) N/ {6 X, O
_________________________________________________________________________
' [9 a5 F g% c6 L" V! s
9 Z: V) _0 ]- p
) u( `1 }0 ]( m- x9 gMethod 06; [5 N9 e. } v
=========
) W* u+ Y3 d! K+ Z# R6 }) d
( Q {. r% V* Y F& b5 Z, B l
2nd method similar to the preceding one but more difficult to detect:
! c# d# d, {* s: O8 Q& k+ V. c* l8 d- f
7 p" X. _' Z. f" A2 ~( B u& M9 aint41handler PROC
( W" p6 `4 [6 Q1 V6 j! {9 g$ `" H$ i mov cl,al
, ]& b, y; B; {6 [8 L iret1 @) ]; V& i- s
int41handler ENDP
. `: F! S/ l+ P3 R9 B$ q# ]6 X; f! `
6 O2 u( ?. j0 O' E6 [
xor ax,ax* w: K" g- o `
mov es,ax
& M& c7 {: r v9 a: }2 Q& _* Q+ m% s3 ^7 x mov bx, cs
. ?- U8 ^5 j5 I0 Y1 u1 o/ b lea dx, int41handler2 }8 D$ y8 N: l( X8 R
xchg dx, es:[41h*4]
8 J' }4 ?& p" o( f+ \! ^& P) F; f xchg bx, es:[41h*4+2]: J7 [" v/ z, ^$ ?
in al, 40h
9 L5 Z9 v4 ^ w1 H' k, ~ xor cx,cx! a0 e& y: R: v3 X5 a0 l5 X
int 41h
. ^% X4 K X! B& \3 g) x- k9 [ xchg dx, es:[41h*4]! i% Z, a j; i, O, t
xchg bx, es:[41h*4+2]
+ @3 D5 w, Z- S/ d. @) c cmp cl,al u# I- F! I3 U: Q9 M
jnz SoftICE_detected" `2 D5 V( ~1 C7 F
3 K- W: r0 l7 q: I/ Z( B# }7 x t* g_________________________________________________________________________
3 D! a+ r( q" V8 d) B& e W: ]0 i0 H2 b P8 `
Method 07
' W5 a# L3 j+ h=========
5 q, X+ I" _2 d0 y1 w; s+ g" B. j v# l% ?
Method of detection of the WinICE handler in the int68h (V86)( J+ G( K9 `0 a8 a! H
6 H" T5 M {2 P2 q
mov ah,43h
1 |7 t5 [6 g+ j7 ^; F; ` int 68h/ I4 F$ z6 }* x* S. L3 X( p9 f) H
cmp ax,0F386h5 _% U' T( |# [4 U' C
jz SoftICE_Detected
) s8 ~+ ` C' c U4 H
: b+ h) Z5 J0 A/ f
3 J8 Z3 ^9 P1 { D3 Q! I=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit% r N2 m0 Q3 v% _) F5 y7 H2 m# y2 i
app like this:
) y {8 }: R0 m+ [7 F- H% N' O2 u2 g- y% e# G# j: t/ |
BPX exec_int if ax==68/ Y: m2 k# ?0 p4 u. K4 B
(function called is located at byte ptr [ebp+1Dh] and client eip is
1 j* E% e1 I! {* M located at [ebp+48h] for 32Bit apps)
" f; C# W0 }' a9 `3 P1 h__________________________________________________________________________
4 ~1 X( x- R. F% Z( h) B5 E
( I: n6 [) s9 ~- [1 {+ \4 @* m9 l0 e
Method 08" t8 V& K! `0 w5 b O0 V |6 J5 E) L
=========& H" d$ l, K# W3 M, T1 w
9 n, m) U4 W, r# u: }; v- EIt is not a method of detection of SoftICE but a possibility to crash the
) l$ i6 z4 ]# s# Q3 T9 K% dsystem by intercepting int 01h and int 03h and redirecting them to another
8 \4 R6 V% Z' [+ Q$ Q( Y+ Wroutine.
# x6 v! Z) G/ L5 _* aIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
, o& G* R' X" Z2 I. k6 \# D' ]to the new routine to execute (hangs computer...) n/ `9 ]- T% G# Y7 v
: L2 X" N% J$ I2 a C mov ah, 25h
7 |" i" x; g0 X mov al, Int_Number (01h or 03h)+ T% V5 ?+ w3 T8 o, ^
mov dx, offset New_Int_Routine5 a) X$ \9 ^& V! @) [
int 21h& G0 m S+ e" h5 X2 A
: B4 ~- ]% Z# N; W, N; s4 J" Y9 f5 {3 k
__________________________________________________________________________) A% {$ v" v, Q0 v% f
3 Q }$ {2 e3 j: [$ e- TMethod 09
3 ], l4 L) Z% ^8 m, S=========
* S( v0 e4 E) j" Y. M3 X# Y# b9 ?3 A; J6 K2 m$ p8 n
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only4 p- r: r6 K& n( L* F4 m
performed in ring0 (VxD or a ring3 app using the VxdCall).
" M: O; Z) ?: L' ^' y+ kThe Get_DDB service is used to determine whether or not a VxD is installed' S- Z# E$ _% {+ t6 A& K
for the specified device and returns a Device Description Block (in ecx) for* M" q S/ k+ R$ \: }- P1 }9 T
that device if it is installed.; t5 ^7 s @7 m# A' C
3 ~+ K1 m# _: }3 e& g mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID
( P% ?1 k( N; Q, `' b. B3 J mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
; L: c+ q( M. Z% l1 ? VMMCall Get_DDB. r) ^3 p( \8 t9 [; z/ D( y) E
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed D5 e6 S( U2 ~- m
7 H8 e1 S% l7 d% |Note as well that you can easily detect this method with SoftICE:
: {, e2 T9 A% F! t! C* O% n; N: C9 G bpx Get_DDB if ax==0202 || ax==7a5fh
# j2 m+ b0 c: g: z1 f' S* a" e8 r& }4 `/ R& U1 S
__________________________________________________________________________
3 i) |+ ~' N7 E) }! y* N8 E& }- a$ j
6 v: L7 H' F( }! D+ AMethod 10
7 ~) W# L& L$ d6 V7 T( Y* M=========: D$ g0 ` T8 h( y0 b& {$ Y; t% b
P- o2 G5 i5 E' n _# E=>Disable or clear breakpoints before using this feature. DO NOT trace with
! R% W- n7 {6 \9 E3 H/ ~/ h SoftICE while the option is enable!!
2 p1 X1 H1 G% `- U! E5 M% R% l$ C5 N( H
This trick is very efficient:
! I/ M8 W8 B; ^6 T' D- P1 {' Mby checking the Debug Registers, you can detect if SoftICE is loaded
; Z% p4 R; G7 ]# l9 D! k2 {# L(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
* q" I! w$ R1 {3 }" a v& Gthere are some memory breakpoints set (dr0 to dr3) simply by reading their
# d2 S) f( S* W# I; @0 g& b) ?7 Mvalue (in ring0 only). Values can be manipulated and or changed as well
5 P' C7 K" V2 }. D+ m(clearing BPMs for instance), B$ N: i3 O8 l( M# ]4 h
! [8 b; ^0 V1 P__________________________________________________________________________
( ~0 E: }: g) W E$ P4 ]; O$ P5 W$ f! W6 D7 j0 j' ^
Method 11& g6 t( }# b* X9 q1 l7 [0 w
=========
, `$ m$ C7 {0 J0 U) P. |% ?- P1 `5 s& u7 }; x& p: ?
This method is most known as 'MeltICE' because it has been freely distributed
2 V. X* d. r( T N7 ` d3 D B/ rvia www.winfiles.com. However it was first used by NuMega people to allow1 f' K4 _# F9 C
Symbol Loader to check if SoftICE was active or not (the code is located8 l4 X G8 \* ^5 j1 Q6 g
inside nmtrans.dll).
1 g7 t) ~; Z$ H" |1 Z( E1 N# V- F, j) [
The way it works is very simple:6 {7 p4 H$ M5 ` H `) h& t0 j5 O
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for" ^- r0 r" W Z5 d
WinNT) with the CreateFileA API.; o+ S% _7 q, b2 k5 G
7 i# m0 t, L2 Q, bHere is a sample (checking for 'SICE'):* Y4 a+ z0 V+ Z$ m+ D
?) d* o+ s `
BOOL IsSoftIce95Loaded(): X/ ]0 x( H3 b! q T: K. [' }
{
+ d; `+ S5 I0 C# c6 k; e- V7 Y% j HANDLE hFile;
; H2 [: w, Y2 c' t) q1 X# _ P hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,; p! U( `& s. H. ^1 W7 {
FILE_SHARE_READ | FILE_SHARE_WRITE,
" X! k: u$ m# J6 B% Q NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);/ V- J: j. {7 k- z, [ Z
if( hFile != INVALID_HANDLE_VALUE ); _: F+ F V' n0 m* q
{+ {/ K2 ^2 B5 _5 I. t; Z6 k' b
CloseHandle(hFile);/ C8 ~) k0 j Y' i: v
return TRUE;* f" T4 [5 C9 A/ X
}+ |, _* Y W5 c( J
return FALSE;
8 f* D) k6 d# _% r, d' P}9 L! ~, I0 j7 q. A- ^7 p
& n# S# H( r" C. J9 }Although this trick calls the CreateFileA function, don't even expect to be
9 ^4 o6 ? _% g/ Fable to intercept it by installing a IFS hook: it will not work, no way!
2 q8 U: w9 x4 F+ t$ ?In fact, after the call to CreateFileA it will get through VWIN32 0x001F8 R; G- ^! ^7 W, R& m: i
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)' x2 r z/ U/ d1 p& F, U f
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
! j. i) f7 k& n6 F# F$ x j _field.
, E( A9 E" u0 J- C$ C4 GIn fact, its purpose is not to load/unload VxDs but only to send a - K/ D. d- U0 }' n/ W8 w6 \! o. c
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)1 f4 g) c) X0 @. ^) g) j% W
to the VxD Control_Dispatch proc (how the hell a shareware soft could try- t; P0 R6 o& t2 _
to load/unload a non-dynamically loadable driver such as SoftICE ;-).! p" G+ u) W* o# l2 Y4 |, i
If the VxD is loaded, it will always clear eax and the Carry flag to allow
8 v5 p E s/ Vits handle to be opened and then, will be detected.
! f$ m' u+ ?8 v& Q0 [' ]; r) p8 VYou can check that simply by hooking Winice.exe control proc entry point
$ o0 B; B* o: u; mwhile running MeltICE.
2 G% H, D& R* _" D1 h1 M( ]+ c" Q) W" W# `- m3 Y8 \ J
1 H( m P. D; T5 O( `1 p$ S
00401067: push 00402025 ; \\.\SICE
$ I! v8 `8 l% u! O 0040106C: call CreateFileA* n0 L5 ]! W0 [
00401071: cmp eax,-001( X" S: k B6 A1 p
00401074: je 00401091
6 F& F* o7 M9 w8 d e
; w: Q. C0 h% F+ u2 T% D% y
6 J5 Y, G! S6 Q: AThere could be hundreds of BPX you could use to detect this trick.
6 N9 W' y) s R* c$ C$ f3 z-The most classical one is:
% n' X0 F3 k; g: O' i$ }8 h BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
& S7 z) l2 q4 f3 w& O *(esp->4+4)=='NTIC'8 p; v; [$ f, L+ A, J+ ?5 v3 F2 R
7 C" d, L1 J$ O6 @1 s-The most exotic ones (could be very slooooow :-(
& I2 q2 z0 y5 x4 v4 S BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') " y: q- |; t4 g7 s
;will break 3 times :-(5 q. o- A0 k0 _- n' q' K
: e3 _0 x; {9 a( [
-or (a bit) faster: 9 z" Y2 Y: m' U2 e
BPINT 30 if (*edi=='SICE' || *edi=='SIWV'). |; w4 j7 Z+ @3 Z. f' x/ ~
. j$ S9 M6 T6 N3 E/ p! ^5 {
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' % i. s/ a) p* }" B6 G* Y
;will break 3 times :-(
: D" V. p' j# C! M8 q8 }
4 }' H4 g* ?; b a: k6 P-Much faster:! j6 \/ C9 L) W5 [+ M$ w7 g
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'- {- J1 ~: {* T7 \, D
* Y, i; A: b1 `8 ] R) s1 i
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
; G& G/ m; q8 x. f1 b2 Xfunction to do the same job:& \1 K& ~, m- i9 Y
- l5 _$ B# C6 X7 Z; T% e push 00 ; OF_READ( N- @, ~+ C& ~& d
mov eax,[00656634] ; '\\.\SICE',0
* y, i6 _7 L [5 _1 @. t- p! k push eax j1 L! H# B& y7 {9 X: w7 K8 s
call KERNEL32!_lopen
* S$ I# B1 \3 \: t- ^ inc eax9 o. z' ~9 {3 Z ]7 q, e2 k* [
jnz 00650589 ; detected
. I2 i# G1 v. T) T push 00 ; OF_READ
. S6 r0 H# T. N ^; a3 e5 d& E mov eax,[00656638] ; '\\.\SICE'& \4 |$ ?5 C! V9 w, f, G& T
push eax) I8 S @. N* x7 G; s6 X* T! u1 L
call KERNEL32!_lopen6 d% C! K$ q4 ?
inc eax$ T- r3 _2 P1 m9 A& C
jz 006505ae ; not detected
+ J( J' y; w* ?. i9 R( l8 C1 A) G- ~! ~0 F1 }
2 ^ E) }% T; D* ~. Q__________________________________________________________________________
1 D7 x- P+ D! U3 z1 O, x
: f5 A; K. Y' B" u4 O1 rMethod 12' N e" y" k/ P; t
=========
% _& e/ f- V; L k$ L) l7 x! _' v. v( b9 M5 E. B% E; h: K! D$ |) v
This trick is similar to int41h/4fh Debugger installation check (code 05* ?- D3 _1 R* c! v
& 06) but very limited because it's only available for Win95/98 (not NT)
. J# p# q$ z8 j) j/ pas it uses the VxDCall backdoor. This detection was found in Bleem Demo.9 `8 j3 M6 i4 W+ w! l
( C. Q( b D6 p( g
push 0000004fh ; function 4fh# ^. ^- c9 x) Z6 [" C' Z6 Q4 G0 S k
push 002a002ah ; high word specifies which VxD (VWIN32)/ A) x L$ i: @- I( w5 a: z
; low word specifies which service# g0 q2 Q% ?: i9 @- F
(VWIN32_Int41Dispatch)
o6 ?) G: P. i3 J+ v call Kernel32!ORD_001 ; VxdCall
+ C3 [8 t2 m6 w# J; O cmp ax, 0f386h ; magic number returned by system debuggers: `% a1 K3 b; ^2 Q H- i0 j
jz SoftICE_detected
. O9 Y) s" l1 y8 w C5 c& e8 y+ J
. C; c& s0 ^1 l& UHere again, several ways to detect it:1 e% Q* N7 v) ?/ g( k X
* _* @' @4 i' G& V' @) X) V* X, P4 q BPINT 41 if ax==4f
3 m/ B- M% j( r U# W( E2 E$ [" J/ B9 O* j- p$ e0 [) Q- _
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
1 I, k. }9 w3 u4 ]: I' n0 E7 p0 H! E n0 Q: [
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A6 K5 Q- Q! _& P4 |$ l0 }8 L1 r; B
2 B; P5 Y+ N* C4 z& X" t/ d9 ~$ K
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!7 d0 m# G( x4 [+ p+ c" j, `) l1 Q
+ Q, t2 w' Y+ k W! J__________________________________________________________________________$ \. M' V" q, l$ Q! s) v
! o0 ?3 `# y" ~9 m. F0 `6 @7 u1 o, k5 J
Method 13$ O8 J" i# P+ T5 o! e! }
=========
/ ^) h% T0 g! g, U7 B- f8 l3 t7 Y5 W( G4 c9 R8 s0 @
Not a real method of detection, but a good way to know if SoftICE is3 P- R% c3 U* }! W; g9 z1 V
installed on a computer and to locate its installation directory.4 O- m j" H) U4 h
It is used by few softs which access the following registry keys (usually #2) :7 ?3 T2 m$ S4 E* a9 e
" L9 Y; b) q+ t8 N+ C2 ^9 Z-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion8 a1 ^% j+ v |
\Uninstall\SoftICE
; i8 q% r! V2 Y-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE' `# j3 {: R9 H4 |+ V M
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion5 ^. k: R2 l: [" s
\App Paths\Loader32.Exe- }+ J6 s& Y* ]% D% H: @. ~ ^( g7 `
F# x! A. ^8 o5 j- E8 \0 R& S
3 W9 B8 Z! P) K# Y
Note that some nasty apps could then erase all files from SoftICE directory
6 a, S6 z+ K) {(I faced that once :-(
6 v C4 T7 M, F4 [3 e( p$ ^- f. X2 j: c- E
Useful breakpoint to detect it:
" g8 T" u" R- N- _5 r6 v/ `
2 B; A$ O% F7 N7 ~ BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
2 }# _1 c7 _* @2 \* I, O# K
. a4 S! Z; B$ c5 b! |- J__________________________________________________________________________ \5 r i) g$ f% c: Y5 z# @) C& }
9 f" J' A4 ^: C
+ c( }+ ]4 _$ m. T# |: q, b. O1 \' ]Method 14
( z+ p! l; F7 N! s) ~9 S- b9 M% e=========
) V+ c' f7 f2 h# `: O+ X% ]( [3 j( u5 h' e- }+ @2 H7 g" h
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose: O) G: ]4 M9 v+ f+ k
is to determines whether a debugger is running on your system (ring0 only).
+ Z1 d/ S3 m; ~; {" Z$ [
2 a) C, G* F6 J& J9 M0 L2 M5 P' ^ VMMCall Test_Debug_Installed
E: k5 |& t) G* Z! o( `3 T/ ] je not_installed
, y: m4 O" g) ]+ k! I' v% Y
* ^. P- f* l6 f5 x* Q0 ~This service just checks a flag.
2 j2 N- Z3 g- p0 v</PRE></TD></TR></TBODY></TABLE> |