About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>6 v& V+ u8 D% r) ]
<TBODY>, b+ {- H* z9 N8 h
<TR>6 f3 N/ L. d+ v) s% Y: g8 E
<TD><PRE>Method 01
* m" r* q" Z& |1 J! W! l6 s, m3 _=========* z! P, k/ L) q, |

% j( x) f) \- b# e9 kThis method of detection of SoftICE (as well as the following one) is
  j  S! [4 X% u. Z2 I5 m' J1 @used by the majority of packers/encryptors found on Internet.$ x7 Y* J3 x5 C
It seeks the signature of BoundsChecker in SoftICE
& s% C1 v5 J1 r/ y$ o2 r* a
7 O. b& W4 m$ a$ }    mov     ebp, 04243484Bh        ; 'BCHK'+ O7 e* j$ l+ C4 Q
    mov     ax, 04h3 C5 }" }' ^( B* x5 p# H% V& {. z
    int     3       8 t1 U, |- V0 \  L( z1 H
    cmp     al,4( B. |, `7 r, K9 ?9 T, q
    jnz     SoftICE_Detected
) _3 i3 J+ A* L& e- s, Y, v) F0 n$ q3 q. T: u" w6 i2 V8 y
___________________________________________________________________________6 x( B) U) m8 n. C

' D  f8 e! c6 u2 @2 U3 K0 ?Method 02( M/ L( V( s& Y4 z1 I( s
=========
; i4 c+ X# h: e# u8 j& `6 R/ H2 ]; d1 J4 W) T$ M/ R
Still a method very much used (perhaps the most frequent one).  It is used- M: n! ~/ e0 {. k( r2 h$ \8 |$ g
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,+ V) D+ t+ ~! s9 |
or execute SoftICE commands...
! q* I; E* ?6 f4 O/ Z5 i2 \8 xIt is also used to crash SoftICE and to force it to execute any commands  d, e) M6 m' c
(HBOOT...) :-((  - E" P9 ^. _1 R0 R( B3 v
( L- \$ c# @. g
Here is a quick description:/ Y4 }7 ]& s7 |, G' x4 Q! V
-AX = 0910h   (Display string in SIce windows)4 D- ~/ l* [$ X& H
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)+ c  p, O% l% t9 i
-AX = 0912h   (Get breakpoint infos)1 P0 W$ T+ n: E2 K+ B1 K
-AX = 0913h   (Set Sice breakpoints)
& j0 X! V# K: I+ G5 b+ b1 t-AX = 0914h   (Remove SIce breakoints)3 K7 n. E; @/ A, j

" @+ R% n/ K5 H) f0 X4 h% T$ Y9 \Each time you'll meet this trick, you'll see:
  T( L$ G4 ~0 J# }$ J$ d/ Y- _# j-SI = 4647h
1 C! O1 ?) C) K-DI = 4A4Dh
% z% M) O$ C( b% [Which are the 'magic values' used by SoftIce.' R6 z, }' e% V) K& D
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.& g4 {5 }1 _4 m7 I* ~: w
* S: k0 @% V1 l% G4 W" s1 c
Here is one example from the file "Haspinst.exe" which is the dongle HASP
& V: @% g3 {. I1 ^Envelope utility use to protect DOS applications:1 H8 I1 L. V/ g
1 i$ x$ C: O* p) E0 Q  ~2 e* m

9 p0 h! q5 G) |, H+ I: J! q" c' h" T4C19:0095   MOV    AX,0911  ; execute command.7 i) ], M3 H) K+ G$ C
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).0 C4 u9 C' l5 P/ j
4C19:009A   MOV    SI,4647  ; 1st magic value.5 q( R$ {- n9 J" L9 p
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
2 {, E2 r9 u; c3 Q5 o. y4 R4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
, I) i+ @# r% E; g7 c* p4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
5 w! V' z* I$ ~7 j1 q4C19:00A4   INC    CX
8 a/ M, k# V, `0 K; d; H4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
8 G& d/ d; E! E( I( v6 \4C19:00A8   JB     0095     ; 6 different commands.
( O5 n+ y, r4 x$ B; S3 C4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
; M1 y- L$ t2 J2 G4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)" q& z5 l& R" |/ O# ~0 ^2 S

7 O" R: K% @0 p8 ^- q' cThe program will execute 6 different SIce commands located at ds:dx, which9 r+ N8 [6 X: o. l
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.3 }0 V# D( J: ^

* a! x* a1 Q1 \# Q/ M4 |5 N! h. {, X, x* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.5 l3 ?  [% d. U3 m1 `
___________________________________________________________________________
8 l) d( c" p7 ?# I- D, h
1 w* v$ h% z7 X; h# h
1 t$ F2 F  T/ DMethod 03
) |+ F" x9 s( y6 r+ p=========* C: n5 E% Z  S7 |1 s
' a! x. b2 n5 y5 B
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
7 e) G" U$ J+ y0 k$ m- V(API Get entry point)
0 }6 G2 H' z5 C# n+ s        " X$ t" T. C' s) ?  Q. N- G
$ s  C0 J& b$ S6 R' y
    xor     di,di
" d9 L' ^1 k' k/ f: x0 o    mov     es,di4 m5 z* Y8 h" b
    mov     ax, 1684h       : b' a/ v: Q4 s6 y7 ^9 v# e0 L
    mov     bx, 0202h       ; VxD ID of winice  ?. Q0 D' Q7 q8 B4 j% G
    int     2Fh- i1 f5 H8 i, h2 k$ u/ r
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
' F2 b0 W, _+ M8 r9 a( h5 [    add     ax, di
0 G- Z) t$ E# k    test    ax,ax/ B6 S( u( Y. R2 H2 g
    jnz     SoftICE_Detected. T: f: t: S2 g; }5 H5 m% W( _6 ^, T9 G

! I% s6 C3 K2 h4 K8 S8 {! A- G___________________________________________________________________________
' j1 S" `" L: E1 _3 e; {
+ n9 ~! I4 d2 v1 @) D5 zMethod 04
( M2 |7 U. R: d' o8 m( _) y  }. K=========
, e! o2 X8 P. t: O, T  ~
3 P7 e9 \' l5 ^/ J7 q" M8 e" `Method identical to the preceding one except that it seeks the ID of SoftICE
* a& t3 v! E" ]* E! `" M* t3 `GFX VxD.
; @7 n& O3 ?* B8 @) ?
+ A1 U9 s& b+ _    xor     di,di6 I5 V: H) c9 f: F' k* `4 z* ?- r
    mov     es,di7 {+ M4 {2 H9 g
    mov     ax, 1684h       5 S' k. i  z  Q3 L* F# [2 ~
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
# t6 b7 N/ G3 L9 |7 f; z6 d2 C- Y    int     2fh/ J% g; I- Y/ B! N- v; n
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
  w: k2 {* D+ O. v8 G$ y    add     ax, di
1 ?# |0 ?& m" B8 h. p    test    ax,ax. W% n$ F2 c+ ^8 b7 ?
    jnz     SoftICE_Detected
; @  U1 }# ~4 i4 Z4 t5 F9 t3 L$ z2 Q1 Z* r/ ~+ f, [# N2 l2 h
__________________________________________________________________________
& Y& i+ T# r% i2 O7 R" b8 j- K9 Y" T0 H* `  ]2 }3 {$ K) x6 H
( Z4 ~- j; @+ I  R  \
Method 05+ W$ ]' Z6 T! J& O
=========
3 r3 U% n" j" \3 }
- B) `$ N- D5 F$ \Method seeking the 'magic number' 0F386h returned (in ax) by all system3 N( G, ^! Y, D. j
debugger. It calls the int 41h, function 4Fh.
% d5 F- I; x3 E- F$ x5 Y' K4 ~There are several alternatives.  ! l( C6 u9 h0 Z3 H0 Z" r% V
) h9 f0 H& a: D4 F3 u1 L
The following one is the simplest:0 ^: V, ]) Q' d9 r$ a

- w1 }# _9 f$ M1 v% S. m  a# D& @    mov     ax,4fh4 t2 c" ?) I0 z% Y: @/ t  x+ `" L8 G- d
    int     41h+ i) G. W. E- I( k5 a# C
    cmp     ax, 0F386
6 H2 F/ f4 C( M1 c3 p, D    jz      SoftICE_detected1 s5 k  }# U+ g7 I) v

- d3 z6 f& U' W6 T) O7 G- @- L* Y3 |$ C( P- K+ [& _
Next method as well as the following one are 2 examples from Stone's
3 t. j, [& n7 N. ~7 o"stn-wid.zip" (www.cracking.net):! V- b. D& T4 r* Q. R
; l3 `$ b7 C8 s7 T' @" H9 H+ `
    mov     bx, cs8 A1 |( ?" I$ a5 W% H+ F+ S! w- W
    lea     dx, int41handler2* k* V# a0 z: K0 G4 R. {8 O7 M& i
    xchg    dx, es:[41h*4]$ v+ m' J5 h% u. [/ ^
    xchg    bx, es:[41h*4+2]- |9 K7 a) ^) x& a, x" n! C; p1 v
    mov     ax,4fh; F; j: _) I( W4 ]2 m* n2 K" c
    int     41h
! O' Q: k+ |: e  ]% a/ \  j. n    xchg    dx, es:[41h*4]
  c! v1 ^( T- ]4 V    xchg    bx, es:[41h*4+2]
: a9 \1 g  g2 }1 {    cmp     ax, 0f386h  E; B- K4 z8 O3 f2 o/ I1 T, U5 l6 Z* W  L
    jz      SoftICE_detected) C" i5 E% t" P" M. J

+ ^/ t! j* L8 h5 y; Xint41handler2 PROC' f6 z% ^- I9 o
    iret
: D' H8 u7 s* D- F9 f% i' v% nint41handler2 ENDP
! G2 q( C+ N2 M* U' j3 T- y4 m9 g! o, O; ]! D" {# ^

0 z- }) l* R- j& G$ L( x_________________________________________________________________________
# W! \, v8 W) r7 _; u$ O1 H3 d1 h  ~- D+ G" k6 u8 y5 K/ c9 ?2 L

1 I( Q( j; @6 H3 t1 n# {, E/ PMethod 060 H; _9 E8 ^) ^2 A
=========
- w+ F8 R& C" k/ c5 T, |! e4 I9 d5 |$ l

1 L5 F: d3 @, y# z6 f( W2nd method similar to the preceding one but more difficult to detect:
  {) I6 d1 F* F0 O, S* z
- F. G6 P! h  `* ^# ]9 s4 u; A3 e+ W) s0 r6 ~  x3 B8 Q+ B
int41handler PROC
. `+ P& Y4 \& G2 _% P; [    mov     cl,al% W, ?& a+ f( N( \
    iret# L; K" U1 r8 U) Z6 E) l1 A. t
int41handler ENDP, J  s  b" b7 K8 F7 ]

! ^  B  B3 L! B6 u7 Z3 z8 N& A/ w: c7 e1 s9 W  h
    xor     ax,ax
  X/ g7 k4 k. x1 p0 k) L1 [" h: W    mov     es,ax* g- Y2 k+ Q5 Q. A; N8 a- D# s- I
    mov     bx, cs
5 B" M6 V5 {6 S0 B    lea     dx, int41handler9 L2 a5 i  c" j* H/ W6 o& D8 m/ Z; Y
    xchg    dx, es:[41h*4]
' P1 `0 C4 Q5 p" Z    xchg    bx, es:[41h*4+2]
( Z/ a$ j; s- K% |% _0 h9 A7 l/ F( w    in      al, 40h$ X/ d2 Q+ I) y* a0 i) w. Q: \
    xor     cx,cx
+ M8 U4 k6 {" ^    int     41h1 a) g* r% d# M( M
    xchg    dx, es:[41h*4]$ n$ H* I% K! g. D9 _. S
    xchg    bx, es:[41h*4+2]
4 ^. Z+ i$ X7 ]/ c    cmp     cl,al/ [9 w3 ?: }* |4 q
    jnz     SoftICE_detected4 a5 H  h/ E/ w% y% [8 Q5 E

( ?  M/ t2 b, i" g_________________________________________________________________________
4 d( ]- @% v$ B5 d( r2 i+ `8 O  G) f; J1 j
Method 07" I  ]; J1 v# `0 L0 M
=========& a/ Z' y) d' |: J) B
5 b" r& z9 A8 B1 ]* m5 _% p( p. f" F
Method of detection of the WinICE handler in the int68h (V86)
7 S' K/ b" F1 V' @4 r
2 _: }/ k' e6 d! I6 {1 p! M    mov     ah,43h- @+ W7 Q9 v5 V/ S0 N
    int     68h0 i7 ?$ o8 }4 A$ L' O: {) z  I0 z" a
    cmp     ax,0F386h2 _1 k% D% ^8 h! Y7 B; `4 v8 W& P
    jz      SoftICE_Detected
. z1 e8 b! c6 Z) M% D% V- Q9 z; c: ?5 k- W4 n; [

" a4 x0 M; y% j+ M/ }: T0 x+ M=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
1 l8 y7 D* X' t# p$ c" E7 ^* J. p   app like this:9 ]) C: f2 m7 T

- r2 c, @5 V, O' U- s3 T   BPX exec_int if ax==68
. Q  H) d8 A( z2 S% u* C2 c1 g/ a   (function called is located at byte ptr [ebp+1Dh] and client eip is
& f1 F- Z' h* A% z7 I0 X/ W8 j, G   located at [ebp+48h] for 32Bit apps)& V: s1 v" ?% ~
__________________________________________________________________________
5 Y& p( j, b6 S  ^  g
. _4 r+ L1 u  K' v' e/ x2 \4 }# ~5 \) T
Method 08. |+ T. Z( t0 d6 Y9 j
=========
- w. |4 g1 w% \# B& A. p6 |; c
$ |8 O( n$ i/ {; m8 ^5 zIt is not a method of detection of SoftICE but a possibility to crash the
8 v. a, N6 K1 w8 y3 M! Bsystem by intercepting int 01h and int 03h and redirecting them to another
2 p0 p9 p! t0 k3 l# q  H5 [* p% wroutine.3 v, v7 c$ d7 E, p0 s. m" Q
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points4 b4 I5 R: P8 W+ j0 V# [
to the new routine to execute (hangs computer...)
+ H% d5 J. t8 N0 c7 L
7 Z9 F. k; V7 F3 f0 ~: V    mov     ah, 25h+ H+ o! W8 k0 G) F
    mov     al, Int_Number (01h or 03h)
$ z; V4 o" z% ~, z    mov     dx, offset New_Int_Routine
- v* e/ S+ x. @- n6 t7 U' C    int     21h
2 O% k; \" e5 A/ y% L& \5 g2 f1 D* Q, s/ v! L  S8 p
__________________________________________________________________________
2 N4 U7 O( h3 }# o- }4 j
; m  i( v% v8 ]" sMethod 09
0 `. v# [7 h. @6 N=========
7 J  s! _$ ?' A- W! N! l  t& H% w. H$ g
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
% ~9 o; o- L/ f' X, R, ]+ zperformed in ring0 (VxD or a ring3 app using the VxdCall).
- A5 @: I0 W2 `* mThe Get_DDB service is used to determine whether or not a VxD is installed
5 U/ h+ s+ S5 x: ^. p& }. ~for the specified device and returns a Device Description Block (in ecx) for, E; _# v+ o$ n: p3 M
that device if it is installed.
- d: N. k. R# Q
5 w7 E1 j2 g+ z, E. s3 l% i1 Z   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID9 q$ S/ Q& R( T8 R$ ]2 H6 j& t
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)0 K  ?4 O& T6 b! W9 q$ E; m
   VMMCall Get_DDB2 \: U& {- e5 T# A
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
6 I& \# k$ N  o) N) [) q9 `$ t7 G  j- o2 e0 V  g- ^
Note as well that you can easily detect this method with SoftICE:) y( k' s# x0 o- T0 c) V
   bpx Get_DDB if ax==0202 || ax==7a5fh
7 X, M, H$ R; O/ J( y  L% W
$ ]6 {2 A4 J; \! k# f8 X__________________________________________________________________________* N1 _: X9 {. z3 D; j3 U" l" f
* o3 J& o3 X0 V" K: @4 \
Method 101 Y1 Q8 n/ p, }- @  ?
=========) I  H) J, e, w4 T# p- c3 p/ b
$ p1 A8 n* v: T! Z: p7 @
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
# M: v5 p) }* E% \  SoftICE while the option is enable!!) z$ [- F- c  N$ Q

: f! e8 H3 ]3 ^/ k$ Z: x+ s4 n% L5 rThis trick is very efficient:
" W( C( X2 N- \" r' r3 zby checking the Debug Registers, you can detect if SoftICE is loaded
3 _: q5 A& Z; d; W! M1 K, g7 ~(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if; o/ y, S( _9 b2 v6 z6 y
there are some memory breakpoints set (dr0 to dr3) simply by reading their- V' z9 j2 e. s# T
value (in ring0 only). Values can be manipulated and or changed as well, X. x, J. q5 O9 r0 @8 u; v# D: s
(clearing BPMs for instance)0 v+ u  c9 j9 H- S) U4 t! r

( a8 F0 O: g2 \; G+ `__________________________________________________________________________
3 G( h  A6 U  @6 e. t$ }7 d5 p! r3 o6 I- z3 D  F
Method 11
9 T3 |  \* [# E5 p" f=========
' Y1 y8 V" P! K. g: ~' m. w: y( l  [: E6 `
This method is most known as 'MeltICE' because it has been freely distributed
0 i* i6 v0 ?2 u- cvia www.winfiles.com. However it was first used by NuMega people to allow
% a) |0 w0 I, K! ]  l4 PSymbol Loader to check if SoftICE was active or not (the code is located4 A2 [5 |. `, B: h; u! Y
inside nmtrans.dll).
+ Y6 i) q- C. H, c3 m3 ~1 j# x- d! E; X8 B& V( Q/ ^
The way it works is very simple:
4 n0 W2 c, k9 o0 q) w0 T! qIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for; C. v4 E8 W# a' O
WinNT) with the CreateFileA API.1 X$ J' _% w  j4 l9 P! k
' t5 S6 i- c) B7 n1 S) l
Here is a sample (checking for 'SICE'):
! r$ G( M9 s1 G8 c% m
+ B6 T8 c. D- N8 \4 _$ eBOOL IsSoftIce95Loaded()
: Z  f! K5 I; n1 o0 y{
& H1 f7 g0 Z7 y/ V. N   HANDLE hFile;  
% N% L; W9 n2 ~5 a0 [   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,) C+ h. _# B' f# v( i6 D! ?% f9 o
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
8 n2 e9 n0 v# t' c                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
, V" ]1 u( t$ \: s" O- r8 x9 e   if( hFile != INVALID_HANDLE_VALUE )
% E5 F! m- J7 D% G& ~8 C* Q   {
! H. X6 z- e( w; M1 r& Y6 p! |/ ^      CloseHandle(hFile);/ C0 k% V" Q$ B7 q2 b" v6 g0 A
      return TRUE;2 s2 `  f2 A/ \8 F9 o: p" D/ B
   }" H- E) H. B0 \  X) |
   return FALSE;
$ X2 ]5 q/ [; C. L- ~+ k# J}3 z/ Y2 Z3 S1 |
: c# z7 R1 Y6 a1 g
Although this trick calls the CreateFileA function, don't even expect to be
5 s+ M2 b+ l5 E+ f& Xable to intercept it by installing a IFS hook: it will not work, no way!- h3 z8 U1 q. @* G1 C' b6 u7 ~+ ^
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
5 y* B2 q& j7 z6 Z: y, eservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
, G0 k( ~2 p7 zand then browse the DDB list until it find the VxD and its DDB_Control_Proc
. Q2 }" s& w$ efield.: ~5 L+ {. G1 X( w: ~
In fact, its purpose is not to load/unload VxDs but only to send a & k/ U# z' b, ]; M
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)" ]) c7 S3 P% G
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
6 @! O$ ?- e1 Q& cto load/unload a non-dynamically loadable driver such as SoftICE ;-).
+ j0 y! k% ^& d. GIf the VxD is loaded, it will always clear eax and the Carry flag to allow
. A5 z. z7 q4 b8 y2 \3 lits handle to be opened and then, will be detected.
+ f; d. ~; H# S0 }; Z! ^0 [) {: g" EYou can check that simply by hooking Winice.exe control proc entry point
9 T! D( [2 [6 B  U; Fwhile running MeltICE.1 h# e) @" T8 t1 R  z

/ S) v9 H3 T2 Q2 d/ t/ X
6 K$ J' X1 a$ ^+ Y7 d  00401067:  push      00402025    ; \\.\SICE
, d7 v, \  K  P* g- U$ W  0040106C:  call      CreateFileA# j2 I' k: X# p& e
  00401071:  cmp       eax,-001* I/ e1 n. D: x/ _
  00401074:  je        004010911 k$ F- d- I1 L1 E) N: [

; h0 [8 M; y* b9 o. M3 ~8 X9 h
$ r8 O1 |9 @& ]# l7 c( y: h3 `* eThere could be hundreds of BPX you could use to detect this trick.
* |' W3 s/ e6 u, \8 }- {) p9 C-The most classical one is:
  d$ o1 z0 Q( z  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||+ A. L; [/ l7 b4 ^5 a( M$ s. p
    *(esp-&gt;4+4)=='NTIC'
3 ?+ Y; v& }- b% J+ P8 V
$ o+ a& u+ p# S( F: F: r-The most exotic ones (could be very slooooow :-(
$ ~& a2 s7 }) g2 h, E$ k   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
+ D9 [2 b6 \% m+ D$ `/ ^$ X4 B; r     ;will break 3 times :-(9 o) g9 P* e  S! u$ i
$ w8 r9 A3 `3 B2 ~2 U) b' T9 s  }
-or (a bit) faster:
0 {/ J; i( X$ \  S) }   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
# }9 s* G$ R) f$ U: Q: h1 X3 M( M' _1 `" \2 _- K8 _
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  5 Q4 T7 Q/ i; R4 {* f& K# ^6 e
     ;will break 3 times :-(
% `, E: i7 r6 t: |
& c, E( I8 h. b6 A& i) y-Much faster:
& H5 m# b5 L9 I1 R* {4 y4 l   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
. X. x5 d6 k4 ?0 ~$ X( {  _- O6 J5 D, ^
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
( {6 W3 _/ e& A/ s: W% u& c" D3 afunction to do the same job:* _  O6 F% n, G/ j$ {+ [
/ B6 S; c: }  M7 m: j
   push    00                        ; OF_READ0 R  f0 K* h$ i- s. p8 w
   mov     eax,[00656634]            ; '\\.\SICE',0+ e. x; K( ^" R! ?. A' S
   push    eax
: F. n. q* E  O! A   call    KERNEL32!_lopen6 n  R3 F8 U+ C, C2 q* @; o+ S% O
   inc     eax3 v( h3 t) J/ l9 b' H6 {0 d% T
   jnz     00650589                  ; detected
4 H2 V0 }5 n5 z+ i% B9 D2 r9 u( \   push    00                        ; OF_READ
* q9 |" D! ^: d" A4 c1 \   mov     eax,[00656638]            ; '\\.\SICE'+ y% n- J' p( @  D6 A/ o6 L% `
   push    eax
' |6 `4 b5 F! ]7 q) b- E   call    KERNEL32!_lopen
- b7 X& _( F9 @% z   inc     eax
+ @& W& V4 ~/ j! V& b   jz      006505ae                  ; not detected
) B2 g& A5 S" r1 u! a4 J) @/ P5 }3 J
! e, _4 T& {7 j% G
3 ^5 y  j+ u/ \4 ]; h__________________________________________________________________________
' S) s1 j) v# i7 ^! x8 \$ X& I. n1 A+ q
Method 12
, ~. E7 i$ ~3 e! T! I; K0 k=========+ w1 z) A' m: K1 Q# f8 O1 A

# |7 a% u& I' u# [+ IThis trick is similar to int41h/4fh Debugger installation check (code 05$ A; V0 F9 j% H& f6 Z
&amp; 06) but very limited because it's only available for Win95/98 (not NT)4 P3 e% n% S3 a# V% J8 x
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.+ K/ C! P# K# h) G

. V% l1 L+ o2 a- T/ L; n$ ~- _   push  0000004fh         ; function 4fh
2 X6 ~8 v& z) }* e4 w   push  002a002ah         ; high word specifies which VxD (VWIN32)
5 r- y0 n2 E* W! r                           ; low word specifies which service/ [1 \6 G1 C1 t8 s% p
                             (VWIN32_Int41Dispatch)$ i; v7 N( x$ C+ u" `1 H$ Q  q
   call  Kernel32!ORD_001  ; VxdCall
( O  e/ x! ]0 }: W   cmp   ax, 0f386h        ; magic number returned by system debuggers4 ?2 d( Z7 `7 A) B% J1 i: }
   jz    SoftICE_detected3 V7 [9 ~/ G# ^

8 A, x: M: T: X. l+ x* M5 `* VHere again, several ways to detect it:% E1 w  _# x9 _! V
9 y: X6 P% v0 K, ]- W
    BPINT 41 if ax==4f# [1 O6 @  F+ V7 |, d' b8 L  H

9 B5 k( Y% m6 s, K  [: S    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
# j6 K. u: L( h. d
8 f& d# f- V+ W6 o+ _9 U- v    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A( G" K2 I/ G( w/ h

5 I& P0 t3 |; w" _$ N4 S5 n4 `! ~5 M6 Z    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
. a: I: ?# o+ y+ t, L; p
/ L1 `& n8 G; P' `* P5 e5 T: o__________________________________________________________________________
* W( O- q0 j# f4 d5 ~8 w6 W7 |
) p7 j! a4 {. X' uMethod 139 s0 r' t# E! N  ?, |+ ?6 ]2 W
=========5 k6 \1 B! @+ i0 |0 Y
' h9 ?9 D& @, H% s
Not a real method of detection, but a good way to know if SoftICE is# b% ^1 Q8 w9 Z  w' C
installed on a computer and to locate its installation directory.- z2 N% V# s- K: x7 r
It is used by few softs which access the following registry keys (usually #2) :* M5 i" O4 n6 i% i6 H2 x+ Q
) ?* |$ e& h0 M. L
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
0 B% }1 }) M" Q0 g8 j\Uninstall\SoftICE
* @- c2 w$ g: d8 W, k-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE2 ^, F* c, P* y" _
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
) R/ b/ i: I+ v' `( Z+ Q* i\App Paths\Loader32.Exe5 g: A% j: y! {% v

( @% Y3 b, |* V5 u6 s
4 q. H4 }( l: p  e6 PNote that some nasty apps could then erase all files from SoftICE directory' H( Z+ h* j  q4 f3 m, P
(I faced that once :-(* i7 B  ^" M; M' U1 K8 v  d
5 y6 v( d) _  e$ [$ g0 R' k
Useful breakpoint to detect it:
" v) b/ j1 v0 {
' D  ~8 R8 c" p- ?7 ~" }/ y     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'  U. G8 c1 v( a2 s& p
' D1 u. }3 \2 @, N6 b& k
__________________________________________________________________________
( x. S+ U. O4 ?% z4 [( Y
8 X/ V/ q4 d" d2 C1 W1 A3 [; r+ s) o% n1 U5 O7 u1 |
Method 14
( {( Z. v1 w8 x! k: Y$ S=========
! Z# @: S6 a' {
, b5 m, H, o: @9 s2 Q4 b3 ^$ XA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
# k' a  B$ A6 o/ L2 z/ w" Mis to determines whether a debugger is running on your system (ring0 only).! @* k& U0 |9 f0 P3 m

9 U4 F& [7 f/ O. i4 ^: z4 {   VMMCall Test_Debug_Installed
) T( r4 [9 I4 A. }, y   je      not_installed
; z0 R& l9 m, }  r& f) y6 U, R; O$ [( h- d( W. F1 L
This service just checks a flag.
2 K1 Z/ v) Z  D5 e) ^" Q</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部