<TABLE width=500>
@% w& i& q* W! m. H# Z<TBODY>, m- _ z( B O9 J g
<TR>/ ]2 q4 I( A" Q, e" ^% A0 {
<TD><PRE>Method 01
, J$ N0 ?: o/ x- E1 a0 z3 g=========' N% k" i' V! L! f1 ~
* F1 K7 ^4 n6 h/ g4 B! EThis method of detection of SoftICE (as well as the following one) is
8 L2 v' C. t+ p+ u1 |( v3 Eused by the majority of packers/encryptors found on Internet.# j% I6 l0 m1 Y4 v9 ^8 n
It seeks the signature of BoundsChecker in SoftICE
! n: h# w! m4 }* h O( ^6 q
2 X& I8 L+ ]8 r/ j" A4 Y8 L/ I mov ebp, 04243484Bh ; 'BCHK'
; h$ R) @* P, c# | mov ax, 04h
1 ~5 Z- [# m7 x1 c2 y$ i5 c0 d- T o/ h int 3 : d v8 U5 \2 {% q
cmp al,49 A) k! A" m2 u' a) G6 L
jnz SoftICE_Detected
5 u8 c* Y! {: K% j2 Y! o( l- d
! T6 \& `: m: o) y___________________________________________________________________________
) G! |2 ]: T$ x( m
: i2 d# @8 r& D9 W$ ]Method 028 N0 L, s, }$ }/ D' i
=========8 u; k, a, m3 }1 M/ P! P
# B- M6 b1 c$ FStill a method very much used (perhaps the most frequent one). It is used( F- ^5 T e* }% [' c0 H! _
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
9 T8 f6 r3 Y4 V/ Dor execute SoftICE commands...! n3 v. u5 v. Z8 z1 M
It is also used to crash SoftICE and to force it to execute any commands
7 c* p' j7 S/ }$ ~9 j- W% m1 J(HBOOT...) :-((
' r! |2 Y; a) J( I- i9 l% w. l# ^8 x; c8 [( j
Here is a quick description:* v! F6 l f- `$ ^- Y
-AX = 0910h (Display string in SIce windows)
0 o! l' d( V& `9 O% p-AX = 0911h (Execute SIce commands -command is displayed is ds:dx)% t! [3 p2 w: Q( }8 b
-AX = 0912h (Get breakpoint infos)4 t2 M: c; B) D" \) ?$ t: m
-AX = 0913h (Set Sice breakpoints)
3 J3 p( F& Q8 }4 A-AX = 0914h (Remove SIce breakoints)
# Y6 z( O0 Z2 ~8 B
0 C3 Z& k- d) M& b; `Each time you'll meet this trick, you'll see:
2 L7 X3 `. ^1 D4 Z. A-SI = 4647h4 [0 w( U" f. G" U& R
-DI = 4A4Dh# T% t7 }+ M3 |) z" ?
Which are the 'magic values' used by SoftIce.- n) U- D" t+ g1 S& N
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
0 d! S5 c' y* m4 R6 _- m/ u& P7 ~. J$ |" N0 ^- \6 |
Here is one example from the file "Haspinst.exe" which is the dongle HASP
4 X7 q7 c- l2 I4 s. B7 Q2 LEnvelope utility use to protect DOS applications:
# T' ]; i; ]6 W2 ]! I0 } X8 b4 b+ q' v2 P* ?" \
* F/ y2 V, v/ k% a% p
4C19:0095 MOV AX,0911 ; execute command.
- r3 A; | o3 L# Y4C19:0098 MOV DX,[BX] ; ds:dx point to the command (see below).$ t* |/ j" {, E' X
4C19:009A MOV SI,4647 ; 1st magic value.
7 ]5 `7 b$ I. A$ C4C19:009D MOV DI,4A4D ; 2nd magic value.
6 P3 ~+ s9 ^6 O# q# x4C19:00A0 INT 3 ; Int call.(if SIce is not loaded, jmp to 00AD*)
3 T( K, ^, \. I6 X4C19:00A1 ADD BX,02 ; BX+2 to point to next command to execute V1 A( k! T' W# q2 h$ t* u
4C19:00A4 INC CX
2 o. Y( ^! s( f! ^2 ]1 t/ d) v9 i. _4C19:00A5 CMP CX,06 ; Repeat 6 times to execute4 \8 g8 F8 ]) G* I/ B
4C19:00A8 JB 0095 ; 6 different commands.
" X+ M# S, f/ R& C* w: M7 H, y4C19:00AA JMP 0002 ; Bad_Guy jmp back.
+ E# r$ l& Y6 j& S" w7 Z4C19:00AD MOV BX,SP ; Good_Guy go ahead :)
- h6 {: X9 ^( F; K- C2 r& o+ z
, V M# C$ _6 C' {The program will execute 6 different SIce commands located at ds:dx, which& ]9 _3 p- V' ^! f, D
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
5 R* d3 V$ F Z7 b8 h4 M
/ a. V, _' b9 @$ _2 d1 Z8 q9 h" m* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded. I; U/ B; _8 ]$ d' Z
___________________________________________________________________________ `6 y8 v$ B. e0 b, I# q
& g: l! `- i* M f! b+ }2 Q- `+ m+ u/ I
Method 03
! s' S% i' e+ c. t7 Y% u3 i=========+ l: `+ ^( F- i3 V
8 I% }4 P" O6 ~2 ^- {Less used method. It seeks the ID of SoftICE VxD via the int 2Fh/1684h
3 q5 V6 W9 ~4 K) Z) m! U$ u. q(API Get entry point)+ ?1 }4 a) [. q; A# {, J( Y+ }* D
( l6 N+ m1 }1 y# Y7 Z% | G/ T0 Y. l# t7 W; Z/ [* `
xor di,di/ R& m. L0 |* Z
mov es,di; x: p3 @' Q8 ^0 T; m( S4 u
mov ax, 1684h 2 J: z" S b' b% d% k8 i. G t( R
mov bx, 0202h ; VxD ID of winice! ?$ a: }" a7 F. E/ P9 x: f
int 2Fh1 A$ h7 z3 _- o' F" _7 T% x4 X
mov ax, es ; ES:DI -> VxD API entry point1 R T/ b6 P; q3 M
add ax, di, d% e- u7 ~- [2 b5 K' c* v
test ax,ax
' c$ N1 _# J* q. k jnz SoftICE_Detected7 E! Z9 \4 I) ]% `0 `( n
i" f4 x, C6 ]+ `% f& }
___________________________________________________________________________; r4 R" r+ g* H' q: m
8 {( \8 X5 T( X5 f- n
Method 04
0 |( e: t4 K2 I' A1 Y- V. A=========
, m+ p/ d6 H1 c0 A! t E& p! [% r7 s
Method identical to the preceding one except that it seeks the ID of SoftICE# }. K* @- D8 ?# \! ^: Y9 X4 s5 {
GFX VxD." m! P* z2 v1 X
, l7 k; y% Z2 z9 Y0 j xor di,di
9 f9 s5 j1 d# x& q& f7 c mov es,di
- C: U( y- l P {" }- s mov ax, 1684h & [* T) `% W* c( E
mov bx, 7a5Fh ; VxD ID of SIWVID# n4 q0 J) C- Z- e
int 2fh; {+ Y& i- T, u8 h
mov ax, es ; ES:DI -> VxD API entry point1 q+ G- J, ^$ ^" J0 S
add ax, di+ f5 P: z# T6 P, U- @0 z" l
test ax,ax' v$ F5 b+ c i# c
jnz SoftICE_Detected
/ ]' W1 F0 d/ k d
) E) ]# T, i. g$ I ]0 F3 M__________________________________________________________________________5 ~- I! E: w8 E! m5 S$ Q: T
) S, ~7 @3 _+ \: z; a8 a- |% U2 Q
+ y# S- m! v2 g2 u3 h$ nMethod 05
% E2 M2 K. o' H- o. E+ _% K=========
7 s: ?9 B, _# B
3 z- Y Q2 E C _Method seeking the 'magic number' 0F386h returned (in ax) by all system
+ w- f8 ^: `( ^6 d1 _: s. M8 Tdebugger. It calls the int 41h, function 4Fh.# S: c* s1 Q' l& M; i, O9 M+ Y. r
There are several alternatives. ( k( W, Y- S5 R+ N5 j
f" Q/ d. k3 g0 b GThe following one is the simplest:1 U, p6 e& B' B% q$ p8 X$ D2 K8 t
; M* w/ U5 y1 R! w+ y7 x" }' u2 v. N mov ax,4fh/ C; b$ b( Y: k6 c" t; k+ R
int 41h
1 d! {7 \/ {6 c+ W! ?- q/ S: g cmp ax, 0F3860 z8 A j2 @7 M. ~4 X: K
jz SoftICE_detected
7 U5 A( Q* t% S0 h" q% P" g
1 q4 M( j. N# T( c6 ~* r+ ^* W' s. u8 k0 X5 [
Next method as well as the following one are 2 examples from Stone's 6 T1 T0 k# |/ D1 F9 H# i
"stn-wid.zip" (www.cracking.net):9 L) `3 [1 @6 A7 K( M7 b
) q" y1 c7 `% t+ L1 e7 ~1 h mov bx, cs( g6 w3 X9 x% K8 ~& I
lea dx, int41handler2
8 V' ~! R9 i' D* ^/ s xchg dx, es:[41h*4]) W0 ]0 I' m: }7 t
xchg bx, es:[41h*4+2]
N4 Z! `+ i# V+ n. l0 `! ^, ? mov ax,4fh
( c2 f; G' `, k( D- e int 41h
) s; k/ J1 x5 g G% p: f xchg dx, es:[41h*4]/ Z9 S$ S( p3 U' w
xchg bx, es:[41h*4+2]
$ ^- D" a+ U. s% E. \ cmp ax, 0f386h& _ M' e. C" M# R( s/ X+ H3 U) o1 \
jz SoftICE_detected
4 w F1 s2 ~7 M9 @0 @, U) a- T+ Y+ l n. ]: F' w
int41handler2 PROC
# |8 z1 Z1 Q$ D7 x% H( u8 r" x iret
2 Y5 ]" z& I, E C$ R% M( y# o" Hint41handler2 ENDP2 _0 H' `0 U8 Z( J8 r1 p( l7 X
8 M8 Q% |0 s$ [1 Q K/ s; L5 m
( L% y- O- q: K) O S
_________________________________________________________________________
: t$ k( }8 x! r# I5 N# J& a$ j
, _9 T. H$ M# q& O
, o$ v. v8 X/ R0 C! zMethod 06
1 B( q- ]5 I% X2 _" p @9 J=========
: I6 c0 Y K1 i9 o7 b% D+ u0 o5 } _
' d' d; K. r# t% F+ h9 H2 V/ h+ Y6 ~* n2nd method similar to the preceding one but more difficult to detect:
) i7 V8 _- U3 A3 B8 p$ ^# C1 V$ j4 U* f
7 G+ ^# W: d1 v) \, Q0 B# Q
int41handler PROC+ H: B, `6 [8 R
mov cl,al9 m# r3 t% l) Q! |. L! G$ n
iret3 X4 L" q) U5 x4 B* `( o5 a7 D
int41handler ENDP. T' c) h1 x- X
8 }8 [3 g# I( V4 p1 \0 @! ~$ k. t) ^0 D# I2 w0 _: p8 E
xor ax,ax
. Q* N K* x1 V$ O$ ~* \ mov es,ax
% b2 ~7 n7 ^$ X% u) Z mov bx, cs. C8 @+ _# r0 Y- [
lea dx, int41handler7 z1 e! R2 a7 }5 \! F6 L+ [2 B% q. P
xchg dx, es:[41h*4]# b7 j9 D) c2 T: i! b8 F4 U
xchg bx, es:[41h*4+2]+ v7 |8 \1 ?. V; i: ^/ a
in al, 40h' m9 c) K. r1 f5 ^$ H- S
xor cx,cx
6 E. K1 b _# u int 41h
; `) N7 a* E) O' O# J xchg dx, es:[41h*4]
0 x: d+ D/ }+ t s! y- i xchg bx, es:[41h*4+2]
J1 @+ Y8 G% ^8 g+ x9 Z }) i cmp cl,al
0 S/ m! D7 U- x+ b, K: _1 l jnz SoftICE_detected
6 ^9 f! E+ w% P" U& o5 P+ m7 w E4 c2 M/ d9 c: j- L& Q. j* X
_________________________________________________________________________
' Z; v' e6 q! S2 A8 U2 v% ?$ Q( I2 O+ u- X2 h3 F+ {9 i1 \4 D
Method 07
8 K: _3 O' t. G2 X" K=========( E( S$ n: l$ r2 _
& |! [; o! B* g( ^; E3 I% U! A' vMethod of detection of the WinICE handler in the int68h (V86)
3 J0 N4 F+ ^1 g, }
& {3 j5 u! Q8 a8 U' T+ |; a mov ah,43h: {: K. _3 R+ |3 r" {
int 68h3 G: J! n6 {6 `' O& @1 Z, P
cmp ax,0F386h
. |9 `* E( t* o3 }8 ] jz SoftICE_Detected m8 T. Y# k# o: n
; x8 u+ A& B) u' ?6 s, \
- T" b5 V5 ^2 V; {=> it is not possible to set a BPINT 68 with softice but you can hook a 32Bit" b6 a* C# g; o2 [+ l7 ^& L, a
app like this:
" U2 p% H% s7 j& n. I
7 R( V3 F. u0 H# r7 x BPX exec_int if ax==683 Y# [* X2 J. r
(function called is located at byte ptr [ebp+1Dh] and client eip is
4 Y: G+ K1 ^. x. A% a- K7 F2 `: Q located at [ebp+48h] for 32Bit apps)2 s- q, Y6 G8 @- X1 \, Y, x5 j+ y0 a
__________________________________________________________________________
- ]# z V3 m4 r( B! M+ ~0 @$ _2 o. o( t+ A
' e6 ?1 i* x( b N
Method 08& `7 ?, y" [* A, W5 k* O" N
=========
/ G3 P2 c: l( o) q$ U( M G4 ^7 f N. t5 G. Q
It is not a method of detection of SoftICE but a possibility to crash the
$ F& a- ?! I- F$ i$ g- g- X( ]% Q6 fsystem by intercepting int 01h and int 03h and redirecting them to another7 v# w) S c' m7 l
routine.: L! [, {$ {; g% _) l. ~8 S* W) @
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points1 V/ |4 Z% g) f4 n
to the new routine to execute (hangs computer...)5 t4 E! z2 c( v! {/ m" F: y
$ X/ g9 S( J4 E) r
mov ah, 25h
1 `3 E1 `) t: a: M mov al, Int_Number (01h or 03h)
9 p. F; a& O! {7 i! a3 l" B. Q mov dx, offset New_Int_Routine
8 o1 a5 o& U+ g$ `" E! l int 21h% M/ M' L4 a6 q- S# U
' a3 R9 n- d6 F- o! p5 A+ \( l__________________________________________________________________________# B& c$ k: G4 K4 n9 K! F0 y5 o @. E8 [
/ L# x: q1 f, O3 E$ o
Method 09
; w {. B5 H R- ~9 t5 x3 s=========4 Z* j3 `3 w: X8 b+ Q& p
! ?7 Y. }8 N4 ?+ V) ?This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
1 Z- f9 U5 B. Nperformed in ring0 (VxD or a ring3 app using the VxdCall)./ G+ u1 i. Y$ H4 H8 `. v0 h5 d
The Get_DDB service is used to determine whether or not a VxD is installed- [2 L% i( v: C- v
for the specified device and returns a Device Description Block (in ecx) for- L/ F/ I- n- q; Q
that device if it is installed.
/ Y! O0 R9 f. T( [7 h9 c3 W9 g$ W% }' d( Z2 k& b7 C5 s
mov eax, Device_ID ; 202h for SICE or 7a5Fh for SIWVID VxD ID- a t" Q8 F$ M, U) r8 P
mov edi, Device_Name ; only used if no VxD ID (useless in our case ;-)! e4 o1 m5 l: v% \
VMMCall Get_DDB
6 c+ R- |" Z4 m/ D" G+ c mov [DDB], ecx ; ecx=DDB or 0 if the VxD is not installed2 y3 v8 }, d$ p6 j& Q6 ~
$ @4 w2 F5 e2 j- s0 C$ z( D1 m
Note as well that you can easily detect this method with SoftICE:
( ~0 I2 b/ z& k8 }, F& C' J bpx Get_DDB if ax==0202 || ax==7a5fh
# d+ n: m8 Z; y9 l
0 U* R& d% B( ~__________________________________________________________________________' b/ Q$ o' v3 V. [5 P
3 P4 k5 w! d4 ^1 L5 b
Method 108 `1 W5 r0 X- S% q: R4 z
=========+ J* ? O9 a* V0 O5 K; l+ R0 e
+ R5 l& X E+ ~) R
=>Disable or clear breakpoints before using this feature. DO NOT trace with8 g, i6 ?4 ?* J v0 a: ~' W
SoftICE while the option is enable!!0 |, H# P& j: q" z: @
7 r, D6 ~: N- o U0 b% m( h: o
This trick is very efficient:
$ w7 ~3 j& R9 u* g2 E+ zby checking the Debug Registers, you can detect if SoftICE is loaded
. d% Z/ P0 f) H% q& Q(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if. h) e6 C6 Q* O) ]
there are some memory breakpoints set (dr0 to dr3) simply by reading their, c: I) l- H, a1 j$ ?+ ^9 S) d
value (in ring0 only). Values can be manipulated and or changed as well
/ S" o( A8 [7 X! Z4 {4 z f(clearing BPMs for instance)
' ~" T7 w" f# @. u, l+ N2 X4 N7 @; }, l. {6 m$ K5 X5 t
__________________________________________________________________________; c; G) q/ l( s4 e+ e) d
$ Z3 Y+ x' N' y- }/ f1 _' n- b
Method 11
% N/ v6 ^9 W* s9 ^4 M. l=========
7 M y, o2 N9 z2 |
5 m! m" H; J% @3 M6 V8 sThis method is most known as 'MeltICE' because it has been freely distributed' O2 R5 T3 e* T6 p+ h3 A4 b8 t( L
via www.winfiles.com. However it was first used by NuMega people to allow
0 U" N2 q7 _& A1 [5 G+ |+ x( tSymbol Loader to check if SoftICE was active or not (the code is located
" x; w. ]% S% |inside nmtrans.dll).
3 ~# l; \( |1 N8 ?8 h/ n
' \, ~# ~) T9 a; N2 }) zThe way it works is very simple:3 F3 v+ s9 W0 P
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
3 [, w* M. E! u/ T0 I: j6 MWinNT) with the CreateFileA API.0 O" G% A4 O# h. w/ g
9 d4 K& P- }$ Y9 @) B3 F
Here is a sample (checking for 'SICE'):5 s% S6 g3 e# p1 l, I _+ n
, K' J; S- Q+ \8 W/ u* R8 E2 `BOOL IsSoftIce95Loaded()
$ d3 b _6 C9 {% k# |/ M; ~$ w# F' z1 A{
+ c9 u6 K& ^7 H3 W% j HANDLE hFile; 3 D1 K! R5 u. z# q
hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
% {+ N; S! e$ A! p a- } FILE_SHARE_READ | FILE_SHARE_WRITE,8 J: j7 C+ N* z/ g2 C
NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);+ a7 s+ k) @" h! Y0 G
if( hFile != INVALID_HANDLE_VALUE )% u4 Y& S1 Y" F. o3 z( v: E* Q$ Z
{
5 X1 O1 y8 n" E/ |# S CloseHandle(hFile);
) j: \+ a$ ]8 ~ return TRUE;& l3 O" I7 f! q" G3 m# ]/ G% A
}
& S0 |, V( w4 N# | return FALSE;, q) ?- ^+ s) S
}4 F* s( w. r3 R6 ^9 D( D1 E
' S$ o4 a/ d: t) R {1 U& J- P* BAlthough this trick calls the CreateFileA function, don't even expect to be
8 W8 }: V/ }/ r; A p% J& e, Bable to intercept it by installing a IFS hook: it will not work, no way!
8 M1 m/ A+ S' c2 z3 P0 BIn fact, after the call to CreateFileA it will get through VWIN32 0x001F/ I D9 T) G- \5 i" H$ D( m
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)5 C# U3 d8 V9 V, W4 g7 I8 H' b
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
@% S) U- D& e vfield.4 ?. v0 a6 }& q
In fact, its purpose is not to load/unload VxDs but only to send a
* T& O4 f' ~; B% v/ EW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
. p+ W/ H7 o* Y* j9 Bto the VxD Control_Dispatch proc (how the hell a shareware soft could try
( C' s$ z3 ?4 ]# M) xto load/unload a non-dynamically loadable driver such as SoftICE ;-).
! |" l8 I$ E2 G! KIf the VxD is loaded, it will always clear eax and the Carry flag to allow
+ g8 ?: y! Y4 `* j+ a' h! l4 n; Mits handle to be opened and then, will be detected.- Y* s! h$ R$ D7 G6 Z* m! @
You can check that simply by hooking Winice.exe control proc entry point
. X$ o6 K, f( m5 P: [while running MeltICE.0 S; ~& m: y$ l. G8 j
8 M/ t7 j" _" d' L5 H0 i: w
( m" u2 t; y3 H1 `* @/ H 00401067: push 00402025 ; \\.\SICE
& c! |% c6 O- ]8 z 0040106C: call CreateFileA
& {1 g! s+ Y' p- I! Q: D% U 00401071: cmp eax,-001
1 ?/ j' P7 w+ O+ C: A 00401074: je 00401091
8 {" m5 P. K. w* @8 q5 `( o5 B* c
8 o& b% w, e0 A, O. \# \8 M) h. h' X0 O" ?( T/ o7 |5 n
There could be hundreds of BPX you could use to detect this trick.
1 f- P5 y. u' M5 e2 U-The most classical one is:! l7 E/ I. O# E* _+ f; t4 C
BPX CreateFileA if *(esp->4+4)=='SICE' || *(esp->4+4)=='SIWV' ||
; | L+ @' x ]. Z4 B7 q9 C4 A *(esp->4+4)=='NTIC') |% V) h6 z5 i. e. |# \
" N3 r- g v& l* }) T-The most exotic ones (could be very slooooow :-(% I, Y o. d" ]: J3 N% q
BPINT 30 if eax==002A001F && (*edi=='SICE' || *edi=='SIWV')
0 _3 P$ G$ ]8 f/ K9 u( Z& X% |9 V ;will break 3 times :-(
4 q% a5 k8 y* t% u$ j$ |1 g8 i7 E8 w" V5 o0 [
-or (a bit) faster: ( }8 S/ m; }8 ?5 m+ Q
BPINT 30 if (*edi=='SICE' || *edi=='SIWV') b- O4 c& y' ]
/ R. n7 Q5 Z2 U7 h( \" E0 @
BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV' 6 Y7 I* }5 n) R6 l" ?
;will break 3 times :-(# A1 M* ]1 Z. r+ M
& ]; }, \- J" t7 l( Y% B6 `
-Much faster:
8 s, v- ^! l& Q$ i8 U BPX VMM_GetDDBList if eax->3=='SICE' || eax->3=='SIWV'9 ^$ d: n* k) r# c2 x2 s
( L- ]" }5 w2 }" ~
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen) P# J2 U, l% ?' Y
function to do the same job:, d. X! h+ G4 r0 W
; P1 t- t- J& X5 A
push 00 ; OF_READ
8 s: I- U# e5 {/ m; G* |$ m+ k* i/ { mov eax,[00656634] ; '\\.\SICE',0" h5 ^3 p/ v3 a
push eax1 z& [0 _2 @8 g+ r7 ]# e. r
call KERNEL32!_lopen
1 y" M, \5 d- Y inc eax
' Z+ c+ x9 R: s" C* [, @ jnz 00650589 ; detected
% U* r8 M8 b" F9 W* f! s push 00 ; OF_READ1 T! n3 t2 ^* x
mov eax,[00656638] ; '\\.\SICE'
3 P4 f( r3 O7 R" ]" ^* U @ push eax* F( Y) @1 d7 O" m
call KERNEL32!_lopen4 W; {* O+ b; P( ~; w# d
inc eax
) N2 A4 v1 A4 k4 A$ B9 O jz 006505ae ; not detected
+ i" L8 I4 w; W% k& t- I4 j, y7 b4 |2 e" s1 t8 g
$ m2 ^" Z" W- E2 s6 U: g__________________________________________________________________________
' y! Z, X% I7 w' E3 w
2 b" E5 _" Y, gMethod 12
; B; i7 R9 U( a3 s=========
2 T0 Y L& u F+ o) J: ^5 ^3 C% n& _& h8 c6 d1 R0 W6 K! x8 }
This trick is similar to int41h/4fh Debugger installation check (code 05
2 d5 z s$ f, T1 k* K& 06) but very limited because it's only available for Win95/98 (not NT)
8 F! k, p+ F8 S0 U7 Bas it uses the VxDCall backdoor. This detection was found in Bleem Demo." [$ W1 ^' V8 m+ B7 \9 ]. [
6 [* n9 T8 L# K% ~1 U7 h9 s
push 0000004fh ; function 4fh
: E) s# B- N2 F& d push 002a002ah ; high word specifies which VxD (VWIN32); O' s# N1 }8 o$ g* N( v" I; Y
; low word specifies which service) x& {5 I9 L9 L6 i
(VWIN32_Int41Dispatch)
. _0 u: X( t# ]% j3 c call Kernel32!ORD_001 ; VxdCall8 m% x) d5 f+ s, h; g# w
cmp ax, 0f386h ; magic number returned by system debuggers
, o8 E8 r- H9 u# t1 m6 W+ o jz SoftICE_detected
* T$ g0 W% T2 [' `( l; B; N% K1 j8 P: t
Here again, several ways to detect it:$ J3 \* I+ b, l! A# g [
" [+ N: H, [- O# T8 @; T BPINT 41 if ax==4f
9 K( }. r! u+ L" d; g& [ p M# _! ]: s2 @- ^
BPINT 30 if ax==0xF386 ; SoftICE must be loaded for this one
% ]+ `5 Y2 h/ R- l3 G" Z0 D3 i3 }" u* I5 j
BPX Exec_PM_Int if eax==41 && edx->1c==4f && edx->10==002A002A
) u3 h% |% X) m
- `% ?$ {( _! ` BPX Kernel32!ord_0001 if esp->4==002A002A && esp->8==4f ; slooooow!
. j9 U3 Q5 Q0 E9 L3 f! f- b: \4 s: J) A. E$ T5 }7 l* w+ g5 R r4 r
__________________________________________________________________________
7 _1 W$ P1 W+ e$ W0 R
3 u0 j5 m( Y% y# h- c' o- `$ JMethod 13# N3 j0 P f4 ?; Y
=========
( J/ c5 V( h' K/ [7 N5 ~# A8 H6 w, y
0 n+ v- Z3 ? \/ s4 f6 jNot a real method of detection, but a good way to know if SoftICE is; m+ |( a9 E/ T' s& g$ S+ q1 F
installed on a computer and to locate its installation directory.4 T4 r7 r5 @& C% A; x
It is used by few softs which access the following registry keys (usually #2) :
& q, j0 T: Q( ?2 `
% p& s! X" v4 u-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
: N9 x/ n- Q8 j. w. c" R' t$ T\Uninstall\SoftICE
! Z; h, l7 o$ \7 x+ \3 F4 c# I-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- [3 u+ j1 N1 p! U0 u" ~-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
$ L1 G. {$ r. j* j\App Paths\Loader32.Exe8 k$ l! G$ Q: Z; `
6 c' s/ v, W. X& s0 a8 s1 Q4 g2 H+ `- i, o
Note that some nasty apps could then erase all files from SoftICE directory- H9 [1 Y4 e* f: H8 U7 x' d
(I faced that once :-(
0 b! g/ |6 l9 r X1 r$ j8 ~9 e9 C+ E, v% H
Useful breakpoint to detect it:
) W& S! f/ u3 @2 ]" I& }' S
- Z, J* y& k7 Z" ~2 r BPX _regopenkey if *(esp->8+0x13)=='tICE' || *(esp->8+0x37)=='tICE'+ F3 h! }' `+ \) D1 ]! \
# [. h9 C& \0 n) f" v6 x__________________________________________________________________________
) S* M6 h/ j% T; l6 p: c: c( ` x* z% v. g. o( ~
' h" x% y; o1 r% {8 Q. B$ Z, T( mMethod 14
' h. @) W' F% s' a* i1 @8 g3 S. k=========1 d2 A4 s3 ~& A4 l c
" `3 J2 F& I8 IA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
4 |2 R! L* u* x% C1 }is to determines whether a debugger is running on your system (ring0 only).
% x) s/ v' w4 r) g( z0 w4 H2 k: X% l: \% s* n2 H
VMMCall Test_Debug_Installed" [4 D; t3 y. C5 F) E) ^
je not_installed
4 m5 Z- X) T4 a5 Z0 R6 s7 h) f- _0 b: }7 }1 z1 }( L+ T
This service just checks a flag.+ F/ i' p. s! ?2 j
</PRE></TD></TR></TBODY></TABLE> |