<TABLE width=500>" E$ [, h3 T2 E5 u0 }; E- F
<TBODY>* b; i' j- n @' X3 g* w
<TR>
+ I( `% p( {* [3 P& N- U. C& S% s<TD><PRE>Method 01 ' S* d$ I( v ?+ i/ X
=========6 v" |! d3 X4 }0 [3 i
7 g' ?$ t! ~& E) u: \9 t6 t* lThis method of detection of SoftICE (as well as the following one) is
, Q! ^2 E9 A( Q' k6 k/ F: M- L9 W; cused by the majority of packers/encryptors found on Internet.; \+ A: y: I ]; h$ I0 o
It seeks the signature of BoundsChecker in SoftICE5 O4 z) i* r j4 x$ \$ M
& M* }- S$ k6 G8 G* F mov ebp, 04243484Bh ; 'BCHK'$ t* `- T3 B7 ]) m( @& C) m
mov ax, 04h$ n G. q! e1 i) C' M
int 3 ) j5 }% J" t( h7 _/ F! ^0 h
cmp al,4) \7 r0 j( c9 ?1 \8 M2 X) a
jnz SoftICE_Detected! g' D6 R5 z- d d7 g
6 I1 C1 H% q: \: [8 o D, B& n___________________________________________________________________________
5 f& i, h& E, x8 ~0 }8 T% x, h2 G/ {; b2 d
Method 022 v6 D" g7 U m% T7 E$ E- }) D' m
=========* @2 ?6 z4 P. j- v4 W! w
9 O& `& \* G) a) a/ c7 {/ ]Still a method very much used (perhaps the most frequent one). It is used8 R* w0 x. E* M+ {" E
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
0 g( a; I% U" H4 B& |or execute SoftICE commands...1 d0 {9 ]0 B$ U' Z
It is also used to crash SoftICE and to force it to execute any commands
7 |- B; @8 S, B3 t(HBOOT...) :-((
6 v; j" O+ f# z. r
; x7 j* J. L" [1 P" iHere is a quick description:7 t( j' a! u4 s& q8 }
-AX = 0910h (Display string in SIce windows)
9 Y4 n/ o- C. b; K1 D G7 I8 i-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
, O6 C8 B8 a _4 R/ t0 @! O-AX = 0912h (Get breakpoint infos)9 x# D4 }' n& v. a. n+ G/ V. Z
-AX = 0913h (Set Sice breakpoints)
6 S! j: u$ M! `$ w# x5 L; [-AX = 0914h (Remove SIce breakoints)+ y0 F4 y+ F% h: ^
5 w @* o2 h# Y% P! }Each time you'll meet this trick, you'll see:
+ g8 k! F1 S5 c% S# x( k8 H* r-SI = 4647h* U) x2 X+ O: ?: Y/ H
-DI = 4A4Dh
6 \1 O! _' C- u* \* ]7 H5 _/ \0 }( D) gWhich are the 'magic values' used by SoftIce.; O# y8 Q n2 f2 h, B8 I
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
. ?6 l3 b L5 i! J4 s
" X. f+ U I; BHere is one example from the file "Haspinst.exe" which is the dongle HASP
4 a1 Z6 T5 _5 i9 GEnvelope utility use to protect DOS applications:
; {" W! g1 ?# D' h% K
0 ?! y4 E3 _6 A1 {/ ]7 y! l1 D0 g# g7 V. z: @6 s7 J7 c
4C19:0095 MOV AX,0911 ; execute command.
. j) j% `" \* O4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).
$ [1 |9 C1 K- K) H8 y6 X! a4C19:009A MOV SI,4647 ; 1st magic value.
( q, S1 z! Z! c* ?4C19:009D MOV DI,4A4D ; 2nd magic value.* c& |- @0 a9 }) M9 T
4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
2 l: _& } Q }% n4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
+ q. ?1 J3 V$ J9 M4C19:00A4 INC CX! {/ f9 I) n% x+ X; E1 o
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute" a( v" l& U8 |- l" B1 Y
4C19:00A8 JB 0095 ; 6 different commands.3 y/ L: w; p2 q- @
4C19:00AA JMP 0002 ; Bad_Guy jmp back.6 s, L* m) X m2 f1 L
4C19:00AD MOV BX,SP ; Good_Guy go ahead :)# v y9 A1 p$ v; R+ I
9 K3 s0 g8 D& O' d. K
The program will execute 6 different SIce commands located at ds:dx, which
# h& j7 p5 e% p) q2 _& Tare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
1 K8 ~' }1 F. t7 a
/ ^/ u! i! \3 l. J. A* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
4 L: Q: R! O3 u% {, t# a% Y3 C& j___________________________________________________________________________1 @( E9 `+ W4 `% T8 I/ O' d" s# J6 @+ O
* t3 N1 R4 _; c7 f) o% {
. U \9 H9 W- P0 z9 L
Method 03
9 K2 s5 p% n8 ~2 A& j" x3 b- C/ _=========
9 M; P6 o5 X9 \, g
7 U8 |1 j; E7 ?) O; S" [* {/ _Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
* N2 r& x1 m5 X6 K o(API Get entry point)% j$ M3 l$ N' u" d
, l. B0 M/ r# r/ W3 n' M
$ g+ k& ~9 j/ ~5 \2 x% a4 X xor di,di
+ u8 A3 e7 F/ { mov es,di5 Y- X V L4 ]
mov ax, 1684h 8 | O/ z" Y2 S2 T3 F) x( A
mov bx, 0202h ; VxD ID of winice
6 y, B' ^2 q |" E) W" \ int 2Fh
% l# R) h7 Z% r) e. Y. _ mov ax, es ; ES:DI -> VxD API entry point
4 a; E( n2 m; w9 ]- J' b add ax, di' F% M8 s& r6 T4 {; V, x
test ax,ax
" n! U: k' E# |. F jnz SoftICE_Detected
7 M q& [$ K2 O. e
6 s4 i2 @* s: o4 P) E [9 b4 J___________________________________________________________________________9 B2 f/ o- I& w# t: g: V$ O; Y$ U3 e
+ @$ J# n8 E, F- [" R# k( O' ?
Method 04) O- M) p$ b0 `$ l1 H* R+ u
=========
! q1 m- F( O& m8 b9 a& U( n$ g7 Q& L
Method identical to the preceding one except that it seeks the ID of SoftICE6 A) v1 p! C, F! ~3 Z, E- a
GFX VxD.; @6 R) r5 K+ M" A
/ k2 h& T1 x' ?0 P' i xor di,di. h2 _. P! E# A# \ G
mov es,di7 J2 M# ^0 r' F2 o& h! T; K" B
mov ax, 1684h
H! J% _0 @0 @' N- R. ?! { mov bx, 7a5Fh ; VxD ID of SIWVID; o6 k5 x) K1 `2 F) q: H7 R5 h, W
int 2fh* U9 l; }' M. ~& Y+ K) H
mov ax, es ; ES:DI -> VxD API entry point/ }4 V: F1 ]) `0 r. a0 s8 N
add ax, di0 _$ O- P+ P5 h! E
test ax,ax
1 _) M$ K7 ]: d/ ~% U jnz SoftICE_Detected6 m) F7 W/ i9 E b4 k% g6 ]
- b' D" ^+ y& _$ ]( W# N__________________________________________________________________________
/ p" A' A3 E9 r* T+ k0 w
, T# ~. M4 ^ h
5 z) N! k4 E& `+ _# l( bMethod 05) v5 _" r( }9 N3 u
=========3 I- \3 z9 J+ A. ^. f0 ?
% ~* a* E( w5 Q$ [" q
Method seeking the 'magic number' 0F386h returned (in ax) by all system
2 _0 D2 f/ y5 X8 ]) edebugger. It calls the int 41h, function 4Fh.
& L+ [# g( n# i/ D9 r: bThere are several alternatives.
" }) R: I+ o) ]; L! a. |0 L
- E1 ~0 b8 _: {. q. DThe following one is the simplest:
+ i- \, L0 |# V$ y
* e7 f7 i+ J5 v; \: x" @+ ~! T( C" K; S mov ax,4fh
. j/ L Z; f: {6 w' m( o" v5 R8 ~ int 41h
! b* B4 q. e! L; o cmp ax, 0F386/ \4 r# m4 s" Y! D9 Y
jz SoftICE_detected
2 Q2 y& V: ^% @: s% Q
9 {8 i3 @3 P0 m- U" W& D. ]+ O3 j) ?3 X$ P. g
Next method as well as the following one are 2 examples from Stone's 4 H4 Q9 R- \& \- r, }3 H
"stn-wid.zip" (www.cracking.net):
0 N$ h. r* w! v) n2 w
: j. n: v# ~) c) m mov bx, cs
" @# l5 n: k' \+ j$ }0 f3 u, n lea dx, int41handler2
2 r; z( h1 i0 [7 a. v( T' T. e# z xchg dx, es:[41h*4]
$ w. |6 g$ e( A, a$ N4 @$ o) } xchg bx, es:[41h*4+2]
: {! R7 b9 j/ w6 p" [1 x- P# [2 V9 L mov ax,4fh" x6 d1 i+ u8 ~9 T; T# ^6 j7 P
int 41h# v4 P# V" s1 l" Y
xchg dx, es:[41h*4]2 F9 i5 A M$ W, f4 I+ d
xchg bx, es:[41h*4+2]2 H _0 i. B' z+ Y" {
cmp ax, 0f386h3 C+ C$ I9 s7 ` |+ V. `6 | W
jz SoftICE_detected
( h$ ]# r; s4 N0 P9 U4 c9 U
6 Z9 N; d9 r0 sint41handler2 PROC& W1 B) f% ^( T
iret
4 M$ }8 }; w. i+ h/ t" L7 {int41handler2 ENDP
$ E" }9 k6 A' O! M) }+ [% O
( E7 i9 G6 {, X! i3 o( V' r" ^9 o. Q' |1 n; O
_________________________________________________________________________6 |( G9 t# F4 K/ c0 J
N% \# @' ^2 U3 `4 q0 S0 t1 g+ M% a+ [) z; B- K8 @( j
Method 06- o, r3 ?4 O& e! b
=========
! b' y" b9 j w- @
0 C, L4 [) ~0 C5 \
6 X) p+ E0 t7 `+ ?2nd method similar to the preceding one but more difficult to detect:
8 S- H; p3 A2 j& S/ g$ g; g
2 E: R% ]4 _# A) a8 x! e2 k
/ _; k2 Z+ E% N: j+ Zint41handler PROC
$ A- T$ g6 G9 T/ N2 ^! K8 L! k mov cl,al; `0 W8 Q- s( g
iret
5 M% b# p/ i( a; n; i/ h$ Rint41handler ENDP
u9 H/ c+ C- E5 R! q* J& h( n& a$ }, l" a1 Y
- m3 \7 m5 O3 m6 q6 h. @% f# u xor ax,ax
. T/ w3 g: B9 H% N8 ]0 O2 {( ~ mov es,ax1 X6 B* ?1 i+ N; \
mov bx, cs" J( B9 A' l- y* N5 Q% d4 w
lea dx, int41handler
2 A5 p( ? f4 `* b/ ?3 w1 b; e. _ xchg dx, es:[41h*4]
# q( N; p/ X* Y' g0 C xchg bx, es:[41h*4+2]
* A0 `1 ~' ~9 |6 b( L! R- T. E: Y5 \ in al, 40h" Y* ~# z% L3 k. p1 p( ^
xor cx,cx* R# `# z3 W ]1 A; S3 F
int 41h2 |! E' w7 s8 o5 O" U( q p: j2 b
xchg dx, es:[41h*4]; D+ u6 @0 t* ~. K3 w0 k$ u
xchg bx, es:[41h*4+2]+ R( @9 {1 j( N7 C# D9 ~
cmp cl,al
0 k e# m+ k% x. t& a- h3 m7 x) k3 V, u jnz SoftICE_detected& \* B' o8 f2 `7 W6 p9 _
f/ N2 b' V6 S" T" e_________________________________________________________________________; Z) A+ [2 l2 z% E
# ]2 d7 h$ m) O
Method 07' ]5 v& Y& u( ~' ~
=========
8 R) K' Q( J4 w# j
8 j0 C/ Z3 p% l! ^8 J/ H2 KMethod of detection of the WinICE handler in the int68h (V86)% K3 M V9 A6 d. K
2 _, m- K' C5 ?4 c5 s6 R' j mov ah,43h* [! E- N# g- X
int 68h
' N8 A+ u L3 Y cmp ax,0F386h
& j/ s% Q9 Z& C& M& J/ X/ L* s jz SoftICE_Detected
k& t4 Z1 {" T- M, B$ p H3 [
$ X* @4 H& Q* J( p7 i. V0 `/ A+ E5 H7 K1 c; k
=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit, ]1 ~- _* j& z% f( K3 }" X0 @5 I
app like this:3 c9 u/ a* @, j7 J! ~; o
& ?' g5 P/ X$ J6 ` C# I; K BPX exec_int if ax==68! v% r! Y1 ]! X7 ?$ W9 j
(function called is located at byte ptr [ebp+1Dh] and client eip is
# j$ \* Q) f0 ~) c6 ]9 ` located at [ebp+48h] for 32Bit apps)7 ]% ^+ w* S$ n1 ^2 t% ?
__________________________________________________________________________( K" [, Q+ U/ K& h
5 ^; n. B3 L( Y- X; D' j6 O
/ A" M9 A) G' v5 w: r8 QMethod 08
$ g' v8 w$ o3 w% V6 _5 \=========6 x9 _& U, h- T' F: Z( H
; g. ]4 D% B+ Q6 q) X5 U5 oIt is not a method of detection of SoftICE but a possibility to crash the
5 f/ z4 V* J8 O1 Osystem by intercepting int 01h and int 03h and redirecting them to another3 D9 d3 c, O1 r, D
routine.
& G) `. c& M$ P6 e: gIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
$ n; }# f# ]- r' v0 B$ Tto the new routine to execute (hangs computer...)( X2 c+ [$ ^# J* e* h- {
. c3 [0 ?& |1 c7 j) m3 f
mov ah, 25h; V( N* _% E$ B; I/ W) K+ t# K
mov al, Int_Number (01h or 03h)2 N, L2 A; O0 L* i6 `( f
mov dx, offset New_Int_Routine( m" v! R; R# ~8 T/ m s
int 21h
* M; t' A) ?0 A, L( V+ `8 a9 J3 H* m( x6 g
__________________________________________________________________________) H# f1 \2 H+ ~1 q- c: r) U$ |' q' k
/ ]" G) _% J" \1 ]( EMethod 09
% c2 r, l' p) @" l" @% v: l8 @=========. O z E2 z1 `7 N1 h2 c" ~, Y
8 ]- e4 \9 g9 h) h0 GThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
; b p b) j A2 `" u, Qperformed in ring0 (VxD or a ring3 app using the VxdCall).
% X( c, k0 T+ N G' N/ X5 lThe Get_DDB service is used to determine whether or not a VxD is installed' k- ^! a ^3 e& j4 i a/ {
for the specified device and returns a Device Description Block (in ecx) for
% P2 f! [# C7 ?+ Wthat device if it is installed.8 D" N$ R) a& \; `
9 X9 `3 u! D1 t p, e9 B mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID; k# r7 B0 N0 o9 ?/ _: e( x
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
( m" k6 l ]9 R B# M+ ? VMMCall Get_DDB
+ d/ [ ]8 S. C$ x* z0 o2 s" h mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
) z7 G7 o, D! n! l& ]# i
- ?' i1 C$ i5 P- H+ V o+ oNote as well that you can easily detect this method with SoftICE:
2 }8 \6 T, v) D8 t' s0 ~" P bpx Get_DDB if ax==0202 || ax==7a5fh
3 ~; r' [$ t1 ~8 l' n: S+ s& ? `
: X& \$ d( a! B: N/ s- a__________________________________________________________________________
( m: @0 u8 t$ w! k1 X- H! {; c
' P" P2 Y s" b" r% c, ^. rMethod 104 M# r) X) K7 L0 `
=========
' F6 h' u; M3 [& Z8 |0 |$ k- N8 C: x2 Q
=>Disable or clear breakpoints before using this feature. DO NOT trace with8 t4 |( l! e; U
SoftICE while the option is enable!!
8 K. _3 C8 I( j2 s7 {. H# a; U& X9 Q" H. n
This trick is very efficient:, ^+ E# `/ Y& b6 }1 d9 \; t! h! M
by checking the Debug Registers, you can detect if SoftICE is loaded
) U. T/ {$ L& j) y& P(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
# h7 ^/ b. z% L* L: lthere are some memory breakpoints set (dr0 to dr3) simply by reading their
: m2 x- F" f9 w |7 S2 b# uvalue (in ring0 only). Values can be manipulated and or changed as well; v6 a- J$ `# M& t" q6 l
(clearing BPMs for instance)
. r% Z. M5 ?6 c5 O, a% \2 p N' g- `$ J- n9 O: I+ S; F% O1 E8 E
__________________________________________________________________________; r1 w6 s! r: y1 @9 _; j: m
0 H2 D6 u8 V6 Z, i1 i9 I
Method 11
: L D0 ~& P, _, r=========
7 [3 _/ p; J! h$ u7 A) |& O" x/ G2 A4 x" g9 p, O4 T
This method is most known as 'MeltICE' because it has been freely distributed2 R7 m' P# z: v1 p! Q
via www.winfiles.com. However it was first used by NuMega people to allow' A% O- a4 ~6 R6 j- j) `
Symbol Loader to check if SoftICE was active or not (the code is located
" f2 D2 r& w" p! }3 oinside nmtrans.dll).
: ?6 t/ |% m' R' @/ k+ |9 u& x" u4 j7 B( y X/ y# B; N( g
The way it works is very simple:7 h: e- M8 d( K# ` u( K0 \8 ?, d6 m
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
7 T& Z( t) Z1 OWinNT) with the CreateFileA API.
3 p4 D* F; M5 P. y5 Z% t% Z
: ~3 ^# `7 B/ m3 {/ P, xHere is a sample (checking for 'SICE'):
9 i/ \: d& ^! ?5 Z
" w6 J8 \. G- {1 l5 ^1 I8 G2 eBOOL IsSoftIce95Loaded()
7 J1 U) O/ Y9 w1 D{) [: r% U! |/ I/ Z! u7 `; I
HANDLE hFile; 2 r7 u" C% w% ?4 l# O1 H* F' u
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
% a- b4 `4 u' a3 W0 E6 C4 p5 f FILE_SHARE_READ | FILE_SHARE_WRITE,
7 R( V% d9 ~) N* O* D. y4 R& O9 c NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);9 T0 ^3 |( }7 k3 ?/ V# [9 M" u
if( hFile != INVALID_HANDLE_VALUE )
# ]7 x3 p3 J2 B# u/ ]; n {9 ]! O! [9 S8 q* G! l2 V
CloseHandle(hFile);
; g* D5 D3 P" `$ V% K return TRUE;* L% [/ b. h: m6 Y; A* V
}
$ h) i: f! L3 ^2 `! T9 a return FALSE;
" Y/ i: d- r4 w/ N) O$ q7 K}
z! S p# B# S6 x/ P. K, w4 A1 a
9 f! d4 A/ v2 @4 m, e/ pAlthough this trick calls the CreateFileA function, don't even expect to be
* S" S; ?7 u: X4 \8 c' u8 oable to intercept it by installing a IFS hook: it will not work, no way!9 u$ P5 L! \7 ^. B, `0 @7 Q
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
/ D3 r% \# o5 X, L0 Lservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
# U! r2 m6 g2 i& u% Iand then browse the DDB list until it find the VxD and its DDB_Control_Proc3 C; F$ Y. x* C: \
field.
b. H6 k( ^; CIn fact, its purpose is not to load/unload VxDs but only to send a 4 l+ K0 ^" P7 D8 w3 Z" s: L
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
# q4 I: u; A1 b( ^! J! X7 a9 E( R+ Sto the VxD Control_Dispatch proc (how the hell a shareware soft could try
, o* c( @* t% z5 v- @to load/unload a non-dynamically loadable driver such as SoftICE ;-).
# h) ^; d' y/ j4 |' _If the VxD is loaded, it will always clear eax and the Carry flag to allow5 r" S9 m! m% `4 _
its handle to be opened and then, will be detected.9 k4 O8 l) O/ w) Z ^/ O5 k
You can check that simply by hooking Winice.exe control proc entry point
; C% f* g$ L* }/ l# iwhile running MeltICE. C# M5 M# r& c9 e
& a* W$ s, N; m: T' V
+ \) n7 w4 `7 o- _: y$ F3 |
00401067: push 00402025 ; \\.\SICE- z: K" Q' `: ]. Q# Y4 s& m
0040106C: call CreateFileA/ S3 \% M; b2 j* ?( C" m
00401071: cmp eax,-0013 u8 k! A3 O- ?- o4 D' F
00401074: je 00401091
( E6 r8 _' U: S, i. V) U& V8 y" g F
2 w S+ M: p( {" Z
There could be hundreds of BPX you could use to detect this trick., ^- N# m) F. O5 \6 R
-The most classical one is:
( }( U, m, Q7 _6 P1 E BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
! m8 j% V' w# H *(esp->4+4)=='NTIC'/ ^2 ~5 F" `. R9 x" l/ F8 m
+ U9 a6 _/ Y- ]! n( l
-The most exotic ones (could be very slooooow :-(5 e: n4 s4 K/ V5 X' R$ X
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
6 E9 N! D* |* t ;will break 3 times :-(, a l" M* w% M/ G. z7 }
5 Q7 \& Q% `9 v1 u3 B- W8 P-or (a bit) faster:
' x; G- l$ ~6 \ L BPINT 30 if (*edi=='SICE' || *edi=='SIWV')+ t& s% Q. G" A" O9 E5 g& b: ^
+ J$ @" U2 c4 Q: n5 z8 e8 p2 B BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
6 M! ]& y3 G1 X- } ;will break 3 times :-(- [& N( l6 O, P0 |% h! ^- U
B/ z! a% `1 F, t! }' t+ k-Much faster:; e7 M+ |" `% G
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
4 Z' \/ m6 \1 d k6 I( i! C5 \% D2 l& F4 h
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
$ i' z; \9 F0 a! j) ^- P' P6 Rfunction to do the same job:
M2 p+ f7 i7 y+ c" Y* O* T) _+ {8 h" h: Q7 C
push 00 ; OF_READ
2 N# @& p |9 g$ i( j+ n mov eax,[00656634] ; '\\.\SICE',0
3 U* x& K- Z; w& n8 |+ t& |9 } push eax& U2 j8 C% O- x' E$ Q) ] T0 R
call KERNEL32!_lopen
3 _6 @' ]& ?+ Z; x/ M1 B5 J( o0 t inc eax
4 J7 R* K4 [! ~5 R3 I: F jnz 00650589 ; detected
9 \+ u2 Q8 w6 e9 D7 t2 v push 00 ; OF_READ
3 F& o0 k: r. p mov eax,[00656638] ; '\\.\SICE'2 g/ ^9 V# M7 b9 |
push eax
9 C' m2 |4 a- b* @' h% Z% z3 v call KERNEL32!_lopen
, f/ d* G0 i7 w J, m7 X inc eax/ C- Q: A" n, O
jz 006505ae ; not detected- a! f& q, s C1 f; T# ]- g5 Q
8 h7 a; n Q% Z4 Z; o! T
% O/ T& F F3 Q4 d__________________________________________________________________________; ]" q% f3 n) P) t- L
3 C, H& @; E! b2 `' ]# }+ Q2 u0 r0 v
Method 12
( `2 W( u- z8 i2 [$ ?=========4 ^0 b$ g% t# \5 M
) v1 Y% F4 U% e$ e2 }* e) V
This trick is similar to int41h/4fh Debugger installation check (code 055 L7 b5 q+ S8 u$ Z x! U
& 06) but very limited because it's only available for Win95/98 (not NT)/ r6 V! X! ]' }1 e5 y- _
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.( n. {$ m Q0 |* D! ]! e1 H
3 r: `$ V0 X4 @; G
push 0000004fh ; function 4fh8 u% D% |* ?! q9 a. j e( @
push 002a002ah ; high word specifies which VxD (VWIN32)/ Y A* F ]) {4 }2 [% d6 _
; low word specifies which service% ?' C8 W0 o) `* L ^& R3 J
(VWIN32_Int41Dispatch). ]( `" h+ @" T0 \* W4 y3 F7 A
call Kernel32!ORD_001 ; VxdCall: m# _4 Y6 u2 Z6 H
cmp ax, 0f386h ; magic number returned by system debuggers
; b9 T7 J% ?6 |9 L E- I jz SoftICE_detected
( `! i! q6 G6 }$ G6 Z+ e; X) z3 a/ F/ T/ V. P0 @
Here again, several ways to detect it:9 q) r( R k) ^' t" I) A
' x% ?+ @. v# D" S* ^- d BPINT 41 if ax==4f1 r4 C% z* E2 F3 Q. a, W$ ]
/ g3 _6 |/ g7 \ M BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
) u- _ @$ C9 j* I' |4 X. i
) Q! |* S' F3 v1 r8 b- G5 B! a BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
$ B4 z; Z* c ^; `9 a5 y; P" N2 s7 @/ D
BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!# p" ]+ g7 w3 J1 f s0 G# z9 @
J" ~, @" T5 j/ [* R$ q! X, B__________________________________________________________________________
& i2 W7 M3 X. K# A! s& G2 b- I) J! S" M$ A F4 P% S; S
Method 13
! }* P( |$ h# r=========7 C0 R/ E2 y* V: y0 O0 A6 W# U
8 Z( T* L- j' _" \! @+ ~Not a real method of detection, but a good way to know if SoftICE is& @. ^* f; r: @! n& L x/ A( \
installed on a computer and to locate its installation directory.- o' x0 T/ `" q; U1 m- I8 o" P" e
It is used by few softs which access the following registry keys (usually #2) :1 _; K0 ?) t# b9 r' l$ Q+ \" {
! Q" F2 O1 I: N9 P-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion: q5 i) T8 C w2 G
\Uninstall\SoftICE- ~% e$ v1 s( \. [9 s; K! l
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
, ^/ z7 E; ?6 k. b0 s-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion1 a0 ?* F! v- c/ u
\App Paths\Loader32.Exe
. M0 r+ Y% B; L2 x! C |; ~4 x
% A {$ s3 r; \% w1 D+ A% M9 @) _
5 A6 y5 m2 p: `1 V; R* iNote that some nasty apps could then erase all files from SoftICE directory( o1 b. [. o, g$ l
(I faced that once :-(: y: m% [0 j9 }
6 j9 @( s) ^, c. {7 E6 @, o
Useful breakpoint to detect it:( B: w9 a' g+ {* U
$ ?, p; o4 g( M } BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'
3 W' P8 p7 j: T% q% \4 \2 J* S
__________________________________________________________________________) N) ~1 p0 a6 y" T3 u+ I
3 A* V8 O! ?* N8 \
5 R q" J K$ ]* ~3 s% F- \% {: E
Method 14
5 b8 d( J* W1 l5 m2 t, Z" I1 U. R6 I=========8 R4 |; j; u1 C0 d) E [
+ ^9 x3 [6 Z' [5 a! R& JA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
; T2 k; k9 y7 W8 r. J, U* k4 lis to determines whether a debugger is running on your system (ring0 only).
5 J6 J/ J- n- D# ~, o! v
$ g8 B) D6 n8 |% A4 H VMMCall Test_Debug_Installed4 f% p3 V% ?" L8 F( C/ t# y
je not_installed
( k- c1 J5 z& _; `- o' _, F; C; E+ E. n5 O5 ?$ L. y$ {+ l. i
This service just checks a flag.
" Z+ S8 z$ x, e1 J</PRE></TD></TR></TBODY></TABLE> |