<TABLE width=500>* V- `# R( s! j; v6 i# g8 w
<TBODY>
* i! \8 E( F8 H& Q- }<TR>
: @, T9 a T( A$ M7 i% ]0 G<TD><PRE>Method 01
, T& [: j* h+ _- X=========; k4 E7 X9 q) `5 Q; k( M2 U9 }
G7 \4 K4 X# r. F3 J% b# FThis method of detection of SoftICE (as well as the following one) is
" T- ~+ y$ s: a2 r' [5 i5 U4 Mused by the majority of packers/encryptors found on Internet.
5 P: c2 `) E2 B3 x. xIt seeks the signature of BoundsChecker in SoftICE
+ O ~$ T: L$ E5 B# @& i4 m" l$ v, f4 n
mov ebp, 04243484Bh ; 'BCHK'. z. J" E2 I4 U3 g. R' Q2 D4 ?
mov ax, 04h. y$ ?; f: r/ b0 O. B
int 3
# F. o% C6 z$ _ cmp al,49 z: F' w5 q9 Z% x# }' L3 c
jnz SoftICE_Detected
6 O5 P2 Y6 a; e8 @4 Y& C# o
+ J. N- q% U7 z0 \___________________________________________________________________________
3 e4 ~5 ?/ \/ {, n- k5 x; G/ s( V' u6 i' p6 e. t8 t! j P- X
Method 02
" {8 o0 l. c/ v6 e$ E=========
. c: T$ q0 H" G. G$ k7 d
% _, h/ M2 [9 P. @7 ^0 vStill a method very much used (perhaps the most frequent one). It is used @! W) `- f8 }5 V6 E& l, U6 _
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,$ g# @8 |' y( o% c
or execute SoftICE commands...1 j4 Q3 R9 ~/ {7 V k" s
It is also used to crash SoftICE and to force it to execute any commands7 g3 T4 `+ T& [7 Y1 s) w
(HBOOT...) :-(( 6 z; Z b! p3 ^% X/ y) O4 X: k
( H- r8 l1 Y B7 F% ?Here is a quick description:
4 B1 t! ^+ e. o& u* l w/ q* {9 y-AX = 0910h (Display string in SIce windows)
t9 X) M4 k' G7 a5 f5 t: ]-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)
2 d3 v8 [0 z1 h8 I. d( I-AX = 0912h (Get breakpoint infos)4 a2 q1 M9 ?3 } m" m; V* l+ m) k9 ]: z
-AX = 0913h (Set Sice breakpoints)! N5 T# ]; |) Y8 E1 e
-AX = 0914h (Remove SIce breakoints)
a% M+ r) |8 k" \0 ~: e
# C" ], V9 F3 b0 SEach time you'll meet this trick, you'll see:
# F* `, N* \! }-SI = 4647h
* s8 [) l/ |. b* n2 p( ^1 m-DI = 4A4Dh
1 @6 d8 p9 {% \: l. b( B W* iWhich are the 'magic values' used by SoftIce.
1 H- _) _2 r# @5 v( lFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
2 R( v. {! O# ~' P0 y9 `! a
. D* D. W, f# x6 U3 H Z; a6 w0 nHere is one example from the file "Haspinst.exe" which is the dongle HASP
$ N8 u2 K# |8 I. J8 l, d8 B+ k! _Envelope utility use to protect DOS applications:
9 f6 F5 N0 s3 y9 w: \. [8 [9 ^8 T. p$ T2 h; J# o6 O$ a
6 k) M, G, w5 y( \/ h, a8 y3 i/ u
4C19:0095 MOV AX,0911 ; execute command.! {6 I( {- S0 T6 q4 _3 C
4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).# e/ x, u7 a2 j! \5 c% I3 H% e/ F5 j
4C19:009A MOV SI,4647 ; 1st magic value.
2 {& n8 p" ?9 k- Y, s# z4C19:009D MOV DI,4A4D ; 2nd magic value.
3 r$ t6 r& p0 I+ d0 Z8 \2 C4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
; y( V, N" ~; V+ N* `4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute
2 Y1 K7 P' V$ L$ ?2 l6 R4C19:00A4 INC CX) C6 K: f) b5 F9 R
4C19:00A5 CMP CX,06 ; Repeat 6 times to execute
& W% F+ c6 T( ~" B- N8 W" @7 R5 Z4 _4C19:00A8 JB 0095 ; 6 different commands.! n+ @1 P2 e! a7 z
4C19:00AA JMP 0002 ; Bad_Guy jmp back.
4 h5 p" e/ @" o! f" `4C19:00AD MOV BX,SP ; Good_Guy go ahead :)7 u, l. V6 o/ @' l$ Z1 `6 S
( U$ l4 v6 v$ o" m& S9 P
The program will execute 6 different SIce commands located at ds:dx, which# l1 g% ~& q: T; u+ C( K
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT., m. d' b, m0 q! R
7 k2 Y' \$ Q! v, J m6 }( N' v# j: R
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
8 c' [# r6 Z2 w. j___________________________________________________________________________
8 y" G3 @8 P( n/ A
" q. z: T# q9 L' N" @" W/ p# b0 m
Method 03
- Q0 y# F& ]. t; U7 T5 l, L: b=========
, {- u* x( \8 Q& X1 g6 x9 C- x$ s3 k8 T
Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h; L: H8 T8 W! `. W. _* Q, J
(API Get entry point)
8 S$ W* ^ P9 y
3 e' X) {. ~8 |* m. Z7 e0 O8 R
% A. P2 a2 ~3 T+ A1 ^0 ] xor di,di& \! h9 p3 A7 z
mov es,di
% h& h6 J% | r1 L+ K" T, _2 P mov ax, 1684h
7 `0 s: |7 v% [" h7 Y5 [ mov bx, 0202h ; VxD ID of winice
8 n& @2 H& ^- H9 b% T- x- E int 2Fh
/ b8 |) X1 q1 h( E2 S mov ax, es ; ES:DI -> VxD API entry point
! c& ^. t0 k, w& O3 a add ax, di
8 c; k5 x. a! U c test ax,ax* f/ ^( ~, o$ O7 z H( y* `* z$ q
jnz SoftICE_Detected% \' k K4 \. n4 r3 o* {+ h
- x3 D. v0 d2 I' s___________________________________________________________________________
& \, G8 r5 l n$ p. W4 w
; h& n5 ~$ ?* \( rMethod 04
8 U$ o& x7 ?& x- f4 q, I% {=========
+ m/ z/ O) `& a) q2 n& o; P$ \- g4 Z+ S3 n, b( e
Method identical to the preceding one except that it seeks the ID of SoftICE
5 }% v# f/ v% l% o; tGFX VxD.
7 U+ M! j! x8 B4 D) j3 V" \
* _4 t4 M8 v& C/ u, p" x xor di,di
0 I) J. s* @! \3 b) A f mov es,di
% u$ d. }( n( N1 h1 H" d mov ax, 1684h + ]# z) _( z+ j- |
mov bx, 7a5Fh ; VxD ID of SIWVID$ k+ v7 O' R" @
int 2fh* ]8 v$ E: x. {3 x {2 E5 A: Y @
mov ax, es ; ES:DI -> VxD API entry point' S7 P$ l4 I5 z9 T/ O9 H& K1 {; R5 f- w
add ax, di1 z% P# Q" n4 T9 ~7 A3 M! e
test ax,ax
% p: F+ z% S' `9 N: Q+ h& X jnz SoftICE_Detected \4 C) J1 u! x) m4 t- t3 q! T' X
& W. E4 B( x7 |3 w, s9 K5 B, a
__________________________________________________________________________
: J( \3 c4 J5 Q! A: C( B% }; ^ d" n. M/ M) d9 Q
8 { m( \% o6 C3 H# e6 ?, aMethod 05
0 p3 E: N9 [0 M/ ~- c: b=========4 z9 y% d6 e6 F7 m) s6 G
$ M' ]- i# A1 [# @/ T1 OMethod seeking the 'magic number' 0F386h returned (in ax) by all system
' r7 a+ x8 W, o0 i& n+ ]6 S f0 D6 Ldebugger. It calls the int 41h, function 4Fh.
0 O, x% V2 n) e; a( Q& T/ p3 o: T2 eThere are several alternatives.
( @; U" h: n. \7 `7 u3 L( ^( y
* a5 b; D! O+ `' K! f$ F* aThe following one is the simplest:: P& c" O L6 X
. [5 t! D: U, d" _9 P mov ax,4fh
) F" E: J2 s+ H" ~9 [3 w/ u int 41h. b4 _4 j$ \! i
cmp ax, 0F386
2 K3 ~. X1 ?1 ] jz SoftICE_detected3 ^% r) z" u& g9 |6 I) D
6 h- [$ }/ }: S/ p0 V& Z1 V2 u
4 O4 I1 z8 f& T2 s/ a0 VNext method as well as the following one are 2 examples from Stone's
7 x2 h5 a0 F; R"stn-wid.zip" (www.cracking.net):
9 ?3 m. G0 j. H0 ~
8 T- d3 `% I/ h mov bx, cs
. E( u% R! w! T0 Y5 A- ? lea dx, int41handler2
+ ?: h: j4 T4 x6 G" @7 p1 U5 T/ _ xchg dx, es:[41h*4]
* X! W, L' W" Y5 [ xchg bx, es:[41h*4+2]
# a4 w8 t G2 p& x1 h mov ax,4fh$ I# }+ Z) R3 A+ w9 b
int 41h
6 r: D2 K6 w$ a7 ^ xchg dx, es:[41h*4]' Z" P; P- j4 U% o" K
xchg bx, es:[41h*4+2]
# r2 h+ `8 x/ G1 t( V; O cmp ax, 0f386h+ c6 m5 O. ~: x, }0 B' o% t n
jz SoftICE_detected) I8 v% k: ?) k0 Z
" |/ e1 W( X' B, J$ A) Xint41handler2 PROC
& x" U6 U: e1 @ iret
$ J) f8 s& Z0 ]2 D9 I) Vint41handler2 ENDP
( {$ i, |9 m+ ]# d' c. I* p
4 p' b" ?9 a9 [4 G) ` t/ z
( U% ^* Z* l. e a3 F_________________________________________________________________________4 \5 Q6 ^ S2 k+ o
* d5 S" j) ^, q: w0 E( w
# ~ a. Q% J) I( G* s, v& iMethod 06
5 I9 z. Y z" g; t- \! T=========4 P' \, J/ n F+ T
0 P5 ?/ K N; W# H9 l" K& u
! a0 @8 k, [) a6 O# A& f; x2nd method similar to the preceding one but more difficult to detect:$ ^, ]4 T5 }$ j+ W% M$ T6 I+ i
* W; h; r% H/ S. g0 i) W [4 B+ G
1 G: B$ }6 y8 @3 c' m2 v. x) oint41handler PROC
5 A# b1 P( O" M( y4 T- G# O1 K2 q mov cl,al& v' z4 `' u" ~" A6 J. v0 J; T
iret
4 z: q2 |9 E8 Iint41handler ENDP
1 W- C( ?$ a, v! A# s6 E: \3 ^" f9 q& x
y6 S$ w' K x) Y
xor ax,ax1 L' b0 @* E9 `& S, Y- U
mov es,ax
( ~( J8 ]4 Q6 }# w mov bx, cs
1 K# J# K& R; K* l4 x9 S, b9 k lea dx, int41handler
0 w2 U% l" n v. f5 h/ ?) ?* [* w xchg dx, es:[41h*4]
1 S+ G: h" X; ]9 s xchg bx, es:[41h*4+2]
3 M/ @/ |* _, H; j2 ]' J: G in al, 40h, x3 M- ]% N/ s, a' h- u% r
xor cx,cx
# T5 Q% A3 \$ \0 U) z int 41h3 k# k# s6 P- e: l' }6 r8 h5 J
xchg dx, es:[41h*4], r# X/ R4 t* Y# M
xchg bx, es:[41h*4+2]
5 A) W" Q% W) `& z cmp cl,al
2 V: q! w0 G0 \ x5 h7 f T jnz SoftICE_detected z7 G: C. ~' j) a8 v
" n% ?! l0 f; [- ?7 A
_________________________________________________________________________
, q$ w$ M5 H3 }' m/ j8 ~2 e3 a) Y& C
2 H* W% Y: G$ Q( d% N: Z- l* [Method 077 l j+ X/ A& |3 P
=========
8 c9 k, { e9 Y4 D+ r2 _
' J1 x- |0 s0 p0 R0 j% | d" P0 OMethod of detection of the WinICE handler in the int68h (V86)
& G' {( F$ Y- m) P1 \" x5 X1 U( C" b; b! x# @( h. a) c
mov ah,43h" i+ Y7 n2 P" [% h
int 68h0 K- F# {) s0 b8 q# ~
cmp ax,0F386h- V$ ~% t. L/ A8 @! G' V' R1 j
jz SoftICE_Detected4 y4 Q0 O! Y* S Z4 s/ o
& O# }6 o! w* I" y' K4 b$ ?
9 V& J5 h4 G- D( w) O, Z6 R=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit- w5 t) S5 v; I7 }7 b4 v& k5 F
app like this:
* v: v8 ~6 b( e1 J- j3 X! |4 T4 U# \* }9 V n7 I
BPX exec_int if ax==680 Q5 l/ a' F1 ^$ e8 {9 H
(function called is located at byte ptr [ebp+1Dh] and client eip is3 F& N" {1 t, M% z# ]. h
located at [ebp+48h] for 32Bit apps)% A1 U# }- g% k ^3 x
__________________________________________________________________________
: B% v. J1 f2 r3 Z4 t5 |
3 C( m' E: w% s" u0 O# P9 g/ v% h$ i2 l2 Z+ F0 t1 M% @
Method 08( t! G1 u+ M! v0 ?# L5 m
=========$ Q7 m" S* ?6 K0 D3 j$ m
& X* @% U/ K# o l5 \
It is not a method of detection of SoftICE but a possibility to crash the
6 H+ p7 _7 w' _7 Z; i5 X1 Rsystem by intercepting int 01h and int 03h and redirecting them to another+ U& h* l3 N" e$ ?. p3 C
routine.
/ E% B8 g5 a3 H \2 V/ |It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
( {) \; O% n9 Q0 _5 Q- Y# J+ i9 I6 ato the new routine to execute (hangs computer...)
* ?+ W# s% s" O( U
9 N3 b2 [( a( k3 U; C+ p: D( `9 P mov ah, 25h
% U" l% @# P' I- v mov al, Int_Number (01h or 03h)
# [9 U- y: C. V, \! g mov dx, offset New_Int_Routine
2 m, m) B( H0 x3 \- J, t5 [ int 21h
0 ^' u3 t' Y i2 Y2 K% }! L! D' I, A& J {5 Y
__________________________________________________________________________2 s' g6 c- e: a
! R" L) K4 _2 ~+ b3 a6 {- p
Method 09; _% y0 D3 U- [ M6 S5 z" O; u
=========
0 P1 r( {+ h- b) o |7 [9 ]3 v
# A$ @' V2 r, S. w fThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
- o6 i: T+ G5 H" I# k' C Uperformed in ring0 (VxD or a ring3 app using the VxdCall).3 _& q9 m: H; e6 Z1 e
The Get_DDB service is used to determine whether or not a VxD is installed; K; f% J( Z9 O+ F
for the specified device and returns a Device Description Block (in ecx) for4 A, T+ ^* p/ ` D
that device if it is installed.- M: l3 N" C. v
3 z9 p( c' O; ^) a
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID1 U2 v8 V/ |! x, h) |
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
5 [4 g# w! F1 F: d' K7 I VMMCall Get_DDB! q: F8 C& i0 D
mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed
2 P, _4 i7 T9 t5 p [2 D
: r0 C8 g+ x+ S5 \1 x8 p+ @Note as well that you can easily detect this method with SoftICE:9 o- O7 h. C% t
bpx Get_DDB if ax==0202 || ax==7a5fh
5 E6 w% V5 ~: s. H; I3 E8 w- W8 o+ X2 U A+ {
__________________________________________________________________________% `0 d' O8 [1 ~! J% k" S# Z
0 H, l. l6 i' o' `! z
Method 10
- w* ?! G" c* p8 P1 H) y=========- |! A+ o' x4 G: G( y
% N% N9 Q6 G* w* q9 ~5 w r# p
=>Disable or clear breakpoints before using this feature. DO NOT trace with
+ E! r' Q& e2 Y3 Q1 g6 Y SoftICE while the option is enable!!, T( o: [) U$ Q$ l
S9 [! k2 _$ l' l% I) E6 MThis trick is very efficient:4 I: J& x/ u. ^- K5 R+ y7 f
by checking the Debug Registers, you can detect if SoftICE is loaded9 W) n- F9 {0 y
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if4 h7 S/ p& k0 e
there are some memory breakpoints set (dr0 to dr3) simply by reading their+ B! D1 }+ D. Q: U
value (in ring0 only). Values can be manipulated and or changed as well
n0 `* A. |1 H/ R0 f% n9 a(clearing BPMs for instance)$ J: Z; S$ ?' W& j
' Y% M, W' K4 @
__________________________________________________________________________
) a/ o) N1 \" g1 y+ i9 _0 }! F: M) E4 E* a, D
Method 11; B' s( t0 {4 C! S; @4 D5 U; S
=========. ~$ s( q, @& s7 u: U
8 N; t3 J, P0 k& d4 U
This method is most known as 'MeltICE' because it has been freely distributed& |5 R* J0 \7 ~- G: d- L
via www.winfiles.com. However it was first used by NuMega people to allow
) L% P" ~* n1 x5 vSymbol Loader to check if SoftICE was active or not (the code is located z: }7 p- G3 L
inside nmtrans.dll)., x* ~, m8 f, P) ]
: U; S3 u% G+ X( {% d" `
The way it works is very simple:0 e4 A- \' s5 K# N' z O" n0 e8 T1 n
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
" X$ q( E' D" b2 U U' f( q5 pWinNT) with the CreateFileA API.; o4 m' P2 j( `8 d; m
# L4 s( q, A+ t) Z# l
Here is a sample (checking for 'SICE'):
' o. V* r1 f6 ^
& a8 G: J0 v6 D8 E Y V2 zBOOL IsSoftIce95Loaded(), B9 R5 Y. {" S' C/ {
{$ x( n5 W) c1 K( ~8 h' g* B1 H
HANDLE hFile;
# G. u6 {5 n4 W" Z# V" |0 T hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
3 _6 M2 i( [. y FILE_SHARE_READ | FILE_SHARE_WRITE,* Y$ X6 J* f$ R3 M( p
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
$ Y, K! Y/ ~4 ?2 n& N. e2 @) o+ D if( hFile != INVALID_HANDLE_VALUE )
; F* W7 S6 A' _ {
: j7 Z6 D1 |: Z" b. g: v CloseHandle(hFile);
4 ?: g ~3 W& `. `$ {6 d. r+ p Y return TRUE;3 l9 f& T2 W9 e! i. Z
}8 A: Q1 H3 N$ T7 ~# Y H4 k' Z1 S
return FALSE;
" o0 y( c! H9 J. Y1 k}
; L }, U) Y: x! M; g0 T- t! \( m! x' I6 d! k
Although this trick calls the CreateFileA function, don't even expect to be" x/ f+ l- S, l8 o1 h& M( d/ X7 L
able to intercept it by installing a IFS hook: it will not work, no way!
5 ?6 z/ s- z2 H" Z5 bIn fact, after the call to CreateFileA it will get through VWIN32 0x001F- v4 _! P' A ~9 s6 M
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)& s: O, V# l! \- r
and then browse the DDB list until it find the VxD and its DDB_Control_Proc6 p9 `$ K/ \9 g* b( H9 p: ]/ I
field.
) J& M$ w8 E9 e* EIn fact, its purpose is not to load/unload VxDs but only to send a
" b2 J5 W" }7 |! [; @+ @W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)' G+ Q( Z% |6 p% F# W* ^$ V
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
3 }1 P- G8 O) k( r3 g( Bto load/unload a non-dynamically loadable driver such as SoftICE ;-).$ u0 A6 h1 t$ ] {. H
If the VxD is loaded, it will always clear eax and the Carry flag to allow
3 D! ]$ l5 g" w4 r$ {& @$ s# a1 Yits handle to be opened and then, will be detected.9 o2 l; O V3 s! ?1 q/ ?6 u
You can check that simply by hooking Winice.exe control proc entry point& u _' }9 A4 N' W
while running MeltICE.6 g( e& M& N$ n& O, D" M' \
2 T" @, E- Z( R8 B R: P; x% d1 Y+ P, b* M2 A4 c5 K* c$ q
00401067: push 00402025 ; \\.\SICE( b+ R4 G# |% L/ _
0040106C: call CreateFileA2 w3 v" D5 m1 O
00401071: cmp eax,-001
6 {5 Y0 G4 Y& |( q2 y; ] 00401074: je 00401091
- s3 C# s8 h! R
* O5 ?1 P1 U5 I8 ^* E% l' j- X w4 B0 H0 P) F' m% U1 |
There could be hundreds of BPX you could use to detect this trick.
1 {9 o. j- I( k6 S( a-The most classical one is:: V0 C% p' z/ H7 Q: H! I. C% N# b
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
( G9 d; Z' r6 d# _& M; a *(esp->4+4)=='NTIC'
6 [' n" ]% b3 ]5 h" ]/ g
4 {7 A' f' \+ l- J6 E% Z-The most exotic ones (could be very slooooow :-(2 m4 t/ e$ P7 r, E1 `
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV') 1 w/ R$ R2 Y" P N& u) k( u
;will break 3 times :-(
7 t0 S7 W% E' F
. r0 X' H6 o5 w( r" ^+ s-or (a bit) faster:
. \1 n5 U# v8 F9 L/ i- y3 K# G BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
( H* V) t/ c6 z0 G/ m7 V: \
8 T6 e }5 l" _& q8 b: `4 r BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'
9 G/ a% B# R+ \5 c2 M3 U: G ;will break 3 times :-(
" h5 u0 F9 p% {' n5 T7 H
* \% r" D4 a/ Q-Much faster:* p6 D/ E3 g' D8 _, m$ a1 ?: C5 r
BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'
) X6 d+ f# S# m, A
$ H# q# w* F: j0 N' j. pNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
+ h* e# n3 }- i9 ofunction to do the same job:& [. a& `, g X( \* T
" K9 S; R0 F J6 l- S) W3 z
push 00 ; OF_READ' \3 S2 h$ D2 l+ o0 h6 B7 G
mov eax,[00656634] ; '\\.\SICE',0
! {3 F+ Y3 k( T) ~$ h1 Q push eax4 `5 h% d- L. O
call KERNEL32!_lopen
9 y) h$ S n- d% c+ Y inc eax4 b* x- X% @) r* b) U6 @- [" g
jnz 00650589 ; detected
, `7 }* V& P/ v9 s: a8 l; S% Q& P push 00 ; OF_READ( O3 d! X; E8 o: Z+ i- d Z
mov eax,[00656638] ; '\\.\SICE'" @/ ^4 m6 [- j1 `6 T
push eax8 ]: D1 B+ L# H3 D0 h
call KERNEL32!_lopen6 c1 M3 D7 V5 c# _! |
inc eax% x7 S$ o( j- E, m# X* x# x
jz 006505ae ; not detected
. d9 G; X: q. @0 M# {9 x* O8 I9 l+ F5 m1 B9 k6 ]3 I7 B
! v! v" A9 v0 z4 E. ^0 Q/ i__________________________________________________________________________9 ~, l4 m8 i4 _9 r! H
( Q6 h& `5 C6 X" I. F1 j1 M$ ~6 k# dMethod 12
% |. r! P8 c0 y' o# J% X=========
/ p4 S' @) \' a3 i* Y4 I# ~2 b0 q3 o4 S+ p4 i
This trick is similar to int41h/4fh Debugger installation check (code 05# l: D; @* M/ P( c/ [7 O8 N
& 06) but very limited because it's only available for Win95/98 (not NT)
" v/ D9 q( ]" ?2 J2 B7 \3 _as it uses the VxDCall backdoor. This detection was found in Bleem Demo.4 E/ C5 w, d" N) [* O, w$ r
5 h2 }$ ?: _9 P push 0000004fh ; function 4fh7 R8 S* ~. K. i3 R0 I
push 002a002ah ; high word specifies which VxD (VWIN32)
! n P2 r' K) g2 F/ y ; low word specifies which service
6 Q9 y. ^. K& H+ ~ (VWIN32_Int41Dispatch)# r' V% W$ s0 k7 i. F; B
call Kernel32!ORD_001 ; VxdCall; O* m: ?/ F6 Q0 U
cmp ax, 0f386h ; magic number returned by system debuggers4 J. {3 _/ ^0 [1 t& ]& R% F( |; S
jz SoftICE_detected
* c9 Z9 j% m) h. I% r5 P" _, c* B
0 {2 T! `9 q d" h1 V9 Y: ]Here again, several ways to detect it:
3 q; C& Q$ n- a/ \2 T1 H+ z6 c9 z/ @" J
8 N* l. N; m) U& f% f/ ?' X% B$ { BPINT 41 if ax==4f
' \( y' F# f( e9 m3 Y# l- @1 t* z/ [0 C. I
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
3 ]* y; I4 _$ x
& B. o4 J+ ] L) E* B BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
3 S* B3 V4 Y; Y- J1 F
" ^1 Y, ]. H/ |3 J8 j7 r, p# H! A+ A0 G; v: \ BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
+ {0 _, X' s; }- p7 `" U+ J
7 l# u9 `0 G n4 N__________________________________________________________________________
9 S2 |3 u$ H" s: D9 x) e! C! ^+ M% K; i0 q, n
Method 137 ^0 ^, t. i5 r3 O. i, x+ C
=========0 M2 V" A" ]4 e2 J. P7 N
6 A- M- W7 m. |& v4 f C) s
Not a real method of detection, but a good way to know if SoftICE is
/ x* a/ U+ E* ]1 |' F! y( c" tinstalled on a computer and to locate its installation directory.
0 H% H" [ N' q9 X7 B0 u- q! `It is used by few softs which access the following registry keys (usually #2) :- X: @# `# Q% s7 ]4 P# H
: \% @3 |2 q9 y. s3 `
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion B- A9 G1 u8 v# P
\Uninstall\SoftICE
: t; O" o4 E# t, B7 m, {% y* J-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
) [% s. y. ?4 z. X* b0 o-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion1 P1 j2 i# a6 s) q u2 S
\App Paths\Loader32.Exe
" m7 W- x* F* c; x( b9 ~, j4 H% Q9 }4 s9 `' ^" ?
9 S) j; p4 s4 `Note that some nasty apps could then erase all files from SoftICE directory$ y' Z% k! k5 S/ }( Y' v
(I faced that once :-(8 k% e% W; W1 n! n( z+ l: M3 k
: b+ |5 h) Z% T. ~( k: G. j eUseful breakpoint to detect it:
Q" A$ \: c* w/ M2 ^3 t, Z/ p% v) r3 E0 r
BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'- O+ t* k- r9 |8 e7 ]: y
|; A4 s+ u9 \/ e' o: G
__________________________________________________________________________! x2 k0 W# H' Z8 k7 |
( ^3 ]7 a9 ?2 M- p- {
l/ [: N% N, W+ L9 r' v# N
Method 14
: l' W" p- _% t9 u# p; A% A=========
, q4 c E2 J* K! C
- G9 J; |( l9 R2 r! Y* Y+ wA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
6 W- d8 Z, w& i+ wis to determines whether a debugger is running on your system (ring0 only). X: L9 ]. g% f$ A1 a) w# a
+ J% {$ h" S u2 }" F VMMCall Test_Debug_Installed
# l5 t( {- ]5 |' z, X je not_installed$ O, y0 e6 v) f2 ^2 r: W
1 }9 S3 Z# l9 |0 u
This service just checks a flag.; d7 W: f f6 N. c2 V
</PRE></TD></TR></TBODY></TABLE> |