About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
, d2 P) L) n6 p$ @" i. \<TBODY>
/ v! {  a- W* I+ b1 W<TR>: b: O* W, O+ l% j
<TD><PRE>Method 01
; n4 {; u4 l: e* W8 @=========
- P9 L  b5 t" E: f+ L! H4 A& Y; Q1 c0 C3 I# ^5 b5 b+ y
This method of detection of SoftICE (as well as the following one) is
4 f4 U; }/ C0 I% p1 O: Qused by the majority of packers/encryptors found on Internet.
( {) w* S$ Q1 g9 i( o9 ~It seeks the signature of BoundsChecker in SoftICE
6 j8 V1 A6 v( u& X6 y  w& _$ J7 x/ h4 u. T) l3 u0 H
    mov     ebp, 04243484Bh        ; 'BCHK') F$ F2 q6 f: t" q$ Y
    mov     ax, 04h
. U* B  }6 L5 z5 d    int     3       6 r) s+ {$ O  @) ?7 J$ X5 L
    cmp     al,4
& z4 v+ N+ i" G4 O& [    jnz     SoftICE_Detected
0 F2 W9 R: I5 k
# m& D+ ]! a. ^% d: X( ~___________________________________________________________________________7 b8 f. Q* F. a# i. e
) j) F3 k* w' }+ X! U
Method 025 S. F6 d! j/ x* l3 @( s2 X
=========& ?# n/ Z  V2 `: N( \

( P' }, N  W, G3 U4 |; F) vStill a method very much used (perhaps the most frequent one).  It is used- T+ m, C7 ^$ O" W* }. Z4 |" G% s
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
7 C% _! C& W0 D. c* d3 N3 ^! mor execute SoftICE commands...4 K0 f  d' c+ N* b+ ~1 G, m/ r$ g
It is also used to crash SoftICE and to force it to execute any commands
" D1 n) q+ p' u6 h# M! @(HBOOT...) :-((  
3 @6 _% p8 g' L, K+ U# r9 ?2 q
, h/ o3 \% k# c& MHere is a quick description:
3 i" i7 s5 B& z5 W* e% m-AX = 0910h   (Display string in SIce windows)- m9 b  I% X& @# [+ K0 G
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
% C  f% M1 s3 R. ^$ A$ R; b2 {1 X) N-AX = 0912h   (Get breakpoint infos)
$ b! r$ M5 \; Q-AX = 0913h   (Set Sice breakpoints)& Z  _# I* ^8 m# e
-AX = 0914h   (Remove SIce breakoints)' `/ o) k' U# T. S% J) n/ ~4 M

' |( S. u/ n" m& B% P4 FEach time you'll meet this trick, you'll see:
% {6 L7 u1 E6 J-SI = 4647h
9 d, `3 H, s5 Q  w# x/ @-DI = 4A4Dh
& G" g) [! Z1 ?) U7 E$ ]' hWhich are the 'magic values' used by SoftIce.
9 d' E; k1 |/ v, ?, b% k& S. CFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
! m1 W% l1 R8 u1 Y' d2 R/ A- x' F9 Q
Here is one example from the file "Haspinst.exe" which is the dongle HASP, ~  t# `1 _- g2 v
Envelope utility use to protect DOS applications:
9 T( X6 r- x4 h5 T' T2 V) _; @; W/ F9 q/ v

2 A3 `; I1 A. m/ e9 \6 ?' w% j4C19:0095   MOV    AX,0911  ; execute command.3 d: Q# x2 O. ?. |/ h) t
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).; X1 ~8 d0 j5 {5 M6 E, C
4C19:009A   MOV    SI,4647  ; 1st magic value.
1 a* J8 ]. U5 _9 b1 s' a7 r4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
4 ^' Y+ ?( i, R/ R4 v. X6 Y4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
1 A, e. }4 @$ g# \4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
1 N0 [( i# {9 n! g; ]4C19:00A4   INC    CX3 @1 ~  A: L" L0 N* O2 I) l
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
/ G  x+ W: |  h$ i4C19:00A8   JB     0095     ; 6 different commands.
: r6 D5 U( H( N4C19:00AA   JMP    0002     ; Bad_Guy jmp back.& G5 z! ]7 f" y8 M
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)- r2 C. K) g+ a4 J  U  ]+ E3 c
1 d6 A$ b+ F9 L, I1 r  |
The program will execute 6 different SIce commands located at ds:dx, which" Z4 a- [) ~) I* R& Y
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
' g" ]$ j# G6 A0 y8 ^# l" M* Y; s6 M7 U' O( Q  [& H% K! C; ~
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
3 w3 j/ o6 `; c8 z___________________________________________________________________________
" Y( R# `% F- r% b' |: D! ^% K6 w  H0 _6 r; w
) M1 V7 ]" q# A9 S1 z7 g, T
Method 03. }: E$ B/ t" l- ?+ L5 b7 N
=========9 o6 l1 j  ~  a! h/ U0 p

# E) k- @. Z% X: H* W6 iLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
! k( v, K/ Z) r0 {% m* r7 d(API Get entry point)" f: N; e, |' L7 U& D* k
        2 E: _$ {/ g* t0 x: e3 ]
/ t* I' l! U, c3 y' \% h
    xor     di,di# R% |1 d* `  G0 H! V: M0 R
    mov     es,di
+ l/ S4 O( u/ _# X  E8 x/ `    mov     ax, 1684h      
! r' I) k3 D; i6 ~0 _    mov     bx, 0202h       ; VxD ID of winice
# y: u, `& {8 B/ h+ q# G6 S& v, ^    int     2Fh
/ }8 a, `; V, v4 O; s    mov     ax, es          ; ES:DI -&gt; VxD API entry point* n4 G: }5 ^# S# O
    add     ax, di
" E3 n, E- {: J3 _. V    test    ax,ax
. R# @+ K) S; }    jnz     SoftICE_Detected) y  \7 u8 f6 n0 F8 f% J4 m/ ^

0 N) e1 R: n9 ~6 u___________________________________________________________________________4 B/ ~) u# C0 M0 X6 ~
1 i& n* w" T! `7 S( J5 x+ J% `& }
Method 04
5 e: h2 @! n! V=========; g5 V: s; V7 q0 x- {, }. s8 G5 ]

" t& ]) C% `  w/ [8 v3 V/ f) XMethod identical to the preceding one except that it seeks the ID of SoftICE6 {+ Q0 k  S# @- N4 O
GFX VxD.! W& h: F$ D  W( c+ ^6 E
, [6 H6 q% \& T) \+ U
    xor     di,di
! k5 [; y. s) D9 S# P4 x6 Y1 N    mov     es,di
# q2 [0 U+ s6 G( D    mov     ax, 1684h       " i! c, \4 l( L! A3 }5 \( h; u
    mov     bx, 7a5Fh       ; VxD ID of SIWVID3 z- y" t- I6 p( x' k
    int     2fh! T3 E6 D" W' Y9 E5 ^4 o; Q
    mov     ax, es          ; ES:DI -&gt; VxD API entry point4 g' `( c" B; T+ ?$ v/ J) I1 C
    add     ax, di
1 O( y- s+ C* ^& B  Z    test    ax,ax
. A, r9 p$ p2 x5 \2 ]5 h    jnz     SoftICE_Detected* O% b9 n3 l5 y6 Y6 W
" _. A4 F# v0 A4 A) N
__________________________________________________________________________2 o  s0 W+ B1 d; S6 k2 M

( ]4 g' @2 f9 F! Y0 O% m' C2 U$ o. ?' h) C6 ^5 M4 c0 `: V
Method 05
6 h; z7 T  C$ }! X' }. L5 g=========' O# J3 a) i4 l! u+ N7 i$ d7 U
! |  a+ h3 U, [
Method seeking the 'magic number' 0F386h returned (in ax) by all system! ], I. M8 z3 n8 {, [
debugger. It calls the int 41h, function 4Fh.  a& C' o1 ~& G% N, a
There are several alternatives.  4 H7 n, C2 o! B) z9 B8 k

" h- `5 h' j; Z) X# Q: cThe following one is the simplest:6 l0 `5 E3 J: ?' b# M
$ e3 Y. h/ m" m0 H0 ^
    mov     ax,4fh# K% W  D6 \2 i# Q
    int     41h
6 T. b$ i; {4 ?/ ~/ X    cmp     ax, 0F386
) {! ^- }# j: H; ]    jz      SoftICE_detected4 `4 x9 T, @. K

0 C; t9 ]7 i6 h' `9 q6 y3 z+ u4 j4 [. \
Next method as well as the following one are 2 examples from Stone's
' S2 u& ^# `& T* u"stn-wid.zip" (www.cracking.net):+ `; X# r4 l; c( W
/ b% [5 Q1 a! ~1 F/ E3 n
    mov     bx, cs( {1 s: C$ z2 z3 E+ D! N* U3 @
    lea     dx, int41handler2" x5 C5 x; g) \. e' Q1 \5 Z
    xchg    dx, es:[41h*4]/ `  i8 C6 M' v( F# l5 U
    xchg    bx, es:[41h*4+2]8 o$ |2 B/ H" [2 G+ y8 l" _
    mov     ax,4fh- i& j5 o/ d1 K  U% t
    int     41h( N& f9 A, O, [- E0 }, K
    xchg    dx, es:[41h*4]
. [0 F; s- A+ n* ^    xchg    bx, es:[41h*4+2]. D" o% M+ F) h! }2 T
    cmp     ax, 0f386h6 U; H  u9 k: o% \5 z3 t! i# ?
    jz      SoftICE_detected: I  \" J; _3 R7 H- @
; B" J2 Z" o6 e! W& E) Z) A
int41handler2 PROC
# M$ Z" @0 D2 b$ r6 c0 g    iret
$ Q! V/ w& b! N/ v6 P- s9 f* I; h- Dint41handler2 ENDP/ M7 Z/ C! C5 ?: v- A- r# y3 x

  g2 S9 V5 W  |* D% W: D
% A+ s2 ]1 T1 h% _/ _! h" U_________________________________________________________________________" x1 C6 {: E# L* ?7 @9 n

6 C% J$ l) s7 m; i3 Z& Q$ P) J, m9 w3 d
Method 06
/ \+ ]' o% F! c  Y# p=========
3 R, Q* P7 ?1 `/ v/ n( f' z# g$ f& {# c3 V$ u  v

7 t0 |$ y7 x3 L% D9 f: L6 L' q2nd method similar to the preceding one but more difficult to detect:
3 h+ I8 @7 l- j0 {/ G0 o& I6 `7 t0 h. O
4 A8 a7 L2 n) V. X! Y& p" u" X/ }
int41handler PROC1 R8 @# m) q/ t# p5 V
    mov     cl,al
# x) f! ~" }, r7 }7 n4 u3 [4 |7 g    iret9 N8 w3 q4 @1 G  F0 v
int41handler ENDP
, d/ R$ s  {# L6 ?* x
3 I9 C# d7 I8 }4 I& ~' G) M4 y7 O0 H( r$ L  u& s
    xor     ax,ax
3 P: y$ l! u2 t& `6 G! B4 R    mov     es,ax. S7 v+ J2 [; K
    mov     bx, cs. o* ~7 s/ A4 I' _9 D! l. E* ]
    lea     dx, int41handler
# b2 @3 u0 j, g* f% w4 _    xchg    dx, es:[41h*4]% g8 k; ^% z/ ^, Z) S) w1 d- ~/ }1 x
    xchg    bx, es:[41h*4+2]: m6 ~' P. ?. N
    in      al, 40h
) O, Y$ H9 {! Z" l1 o; Z    xor     cx,cx! e/ m5 ~( s, w# @; Q
    int     41h- u. z* z( N; A1 I. d6 w; h9 T
    xchg    dx, es:[41h*4]$ R" Q; g& ~" y  R* @* L
    xchg    bx, es:[41h*4+2]1 p# B5 W8 D9 F5 C9 B; i2 [5 H1 ]
    cmp     cl,al( {( B* W. T6 u# b$ I$ E* P$ v9 B
    jnz     SoftICE_detected3 `, @" D$ ~/ A
) R7 m2 k/ ?2 D! [
_________________________________________________________________________
0 r! w% S' b1 l+ c0 w
7 P$ A( O- K0 C6 p# f+ @! m7 VMethod 07
8 e" E5 c( ?% M=========
; D1 c) ?& A5 s/ ~/ K& v1 A, J! h( i1 T$ x2 W7 C
Method of detection of the WinICE handler in the int68h (V86)! j2 G$ N7 w9 ?
5 o1 u; i& ]8 W: H; A5 x5 d; b
    mov     ah,43h
. Z2 N8 G: a& F4 a    int     68h( K+ c; O5 v+ e2 s; Y$ J! i3 q3 [
    cmp     ax,0F386h& Z2 y2 f# e  }7 l& h' n/ g
    jz      SoftICE_Detected
  ?3 X) f( ]2 H% [9 |  L/ P4 }# O3 j- p8 b4 N7 I& @/ T( U3 _
1 X$ W. ]7 |) \0 Y, w& A: L
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
3 U7 Y( w, @+ n; _) x9 o   app like this:
' p2 J4 a+ E% }8 h3 h6 W" K1 v' i) S) t7 v) `' N2 v
   BPX exec_int if ax==68" [8 ^5 o+ T3 R
   (function called is located at byte ptr [ebp+1Dh] and client eip is
% c( b1 s5 B3 A! c; l3 n: y2 h   located at [ebp+48h] for 32Bit apps)# a0 p0 _) T/ K& t. e8 }) J
__________________________________________________________________________
0 R5 O& U- E: i  m" i6 O, z
3 j3 B& _9 Q0 E- h' y" [4 {& D1 G6 Q0 e" n, F, X7 N
Method 08
( H* k& a. [, ^9 C3 l! P5 t=========
$ x7 a' M- Z1 e6 m5 K" [2 R* C6 f6 ?  O/ i1 Y# U# T4 I
It is not a method of detection of SoftICE but a possibility to crash the
. d5 _7 [& g5 Q  Q0 a, ]' Psystem by intercepting int 01h and int 03h and redirecting them to another! B: c3 H4 r- v. J+ P: E9 P
routine.
  [3 p4 ?2 b& Q4 c/ OIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points/ x8 J9 z+ e- R3 V
to the new routine to execute (hangs computer...)1 P& O9 J$ }) s

/ f  _% l) ~) a* B$ Z% G    mov     ah, 25h
5 K8 z8 D" {: Q0 o7 v: r' S1 S5 M    mov     al, Int_Number (01h or 03h)% q2 [, j5 G* U, H7 [0 h
    mov     dx, offset New_Int_Routine, k5 F4 w2 M/ t0 T5 v' Q
    int     21h
# S- z5 T# K8 |. t0 q7 e
( S" v) s% q+ r__________________________________________________________________________
! B/ R* n( R! g' ]8 C9 P4 a, W# l/ i  ?% J7 d
Method 09
" K' x' d8 \4 u  ]* x, r+ D+ m$ K=========
4 e: w, B+ D6 M+ c- I& C7 w- ^2 a( M5 N7 F
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
7 M2 g3 u$ m5 j+ Aperformed in ring0 (VxD or a ring3 app using the VxdCall).
% y% ~" @; Q/ b) T# y& X9 {$ _The Get_DDB service is used to determine whether or not a VxD is installed
) O/ }2 w* r: {4 k0 Efor the specified device and returns a Device Description Block (in ecx) for
0 p5 Y- {1 X7 I0 I* pthat device if it is installed.8 W( x+ l+ r8 Z+ E. {0 s
( E4 l2 e) O* ]/ F( r) Q
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
9 T% v# J0 \: ^6 D8 i5 f$ L   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)$ ^( M1 X4 K2 a* L5 C
   VMMCall Get_DDB$ g+ r9 I. l$ K% p- {- g6 Z7 o; c  i
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed; O( U" Q. u" d  ^9 t9 N
7 g  n* h' Z" ~2 j: w# q# s! I
Note as well that you can easily detect this method with SoftICE:
) t( b: i4 \* S+ E0 i   bpx Get_DDB if ax==0202 || ax==7a5fh
- n! \% C6 J: \  w
# D# g8 ?9 O& c# I$ X# k__________________________________________________________________________* P) T8 \: I4 k* u, e. J
/ o( \$ Y' l/ e0 ]- I6 N, @& V
Method 10
- g- J6 Q% \0 U, ~, c=========
0 `% v0 J1 L3 c, A& ~- z, {. v3 x3 b) J7 {
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
/ o& F0 H7 c8 l% @1 i7 V* C3 Z  SoftICE while the option is enable!!
# b$ n" m+ N! \8 b: f7 G- l8 |* N% D# m: |9 k- @; d
This trick is very efficient:
  i! l9 ~4 {1 v0 y: n0 Xby checking the Debug Registers, you can detect if SoftICE is loaded
7 f6 u6 g9 |1 {5 ](dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if5 g+ l9 {: P' w) j$ B+ p6 y
there are some memory breakpoints set (dr0 to dr3) simply by reading their  Y+ |9 J; y" e" f7 g  f
value (in ring0 only). Values can be manipulated and or changed as well
9 h- g$ S7 u5 m# L7 p( }  Q6 o(clearing BPMs for instance). B5 B* A4 R6 I$ v

9 ?. h9 O( h; f! p& B( Z# M__________________________________________________________________________
2 b/ b- ]. G$ M3 j5 w" E: K3 |0 c" A) Y$ ?2 ]* I0 e
Method 11' g' m# b, {! a) T$ l3 ~
=========5 a* h& \1 _$ T9 c: S1 y

: V6 x# y0 _% S+ q, eThis method is most known as 'MeltICE' because it has been freely distributed
7 ?; y/ w( h- ]1 `0 R5 s0 avia www.winfiles.com. However it was first used by NuMega people to allow
/ B( A6 y' ^8 M; V' `0 KSymbol Loader to check if SoftICE was active or not (the code is located0 V$ j# A  o5 _0 j' u; {* c, X
inside nmtrans.dll).) ]4 I* a/ ~% e$ k

$ w  m  l; u: QThe way it works is very simple:3 |- X- ~1 N# S: k7 N0 c
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
# U1 b5 p! h( d7 v# {/ ZWinNT) with the CreateFileA API.
: L6 ?6 K$ l6 R: G2 `
- y* N5 r) ^8 s7 ?" `5 S8 q+ `  a7 U' mHere is a sample (checking for 'SICE'):+ K" e6 u. w# D8 ?" y1 W# v

$ Z: A# ]! m2 R' {* HBOOL IsSoftIce95Loaded()% p3 M+ m9 J7 |6 F( u; Q# \$ y
{
4 q! [1 O" H" y2 w   HANDLE hFile;  & ~! S, I/ J" v/ A8 {
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
4 p% v2 r& f% m+ I                      FILE_SHARE_READ | FILE_SHARE_WRITE,
& D0 q1 C: \+ N                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
" u2 Y6 p7 Y8 E# m1 W, s* n   if( hFile != INVALID_HANDLE_VALUE ), Q  U/ N( x% w- K" q: g
   {: w* X: k1 H1 f% o8 s1 U0 ?
      CloseHandle(hFile);! O# X0 i: E! V. r
      return TRUE;# }5 ?3 e% |& j' d% F5 N1 Z$ }4 |9 j" w
   }
, a7 q' E# l( y0 A3 s3 }, U   return FALSE;9 u/ e2 J: ]2 u; b% t5 ]7 M
}
" ^: T9 S8 Q: ?( R5 c2 l3 Q5 b4 z: d$ x. Q4 d) {( v) w3 m
Although this trick calls the CreateFileA function, don't even expect to be7 x  o6 M. ]' z. R5 H! J
able to intercept it by installing a IFS hook: it will not work, no way!1 s2 K8 s, X* R# z( v
In fact, after the call to CreateFileA it will get through VWIN32 0x001F" Z# Y4 \# Y2 Z0 u
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)- }7 n# P* ^, b, W' @
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
: _5 y4 H8 }# Y4 `, H6 V" r* cfield.8 D! ^: H& X/ u3 g( _1 {
In fact, its purpose is not to load/unload VxDs but only to send a
* ~* g; z- T+ B( v3 B: W6 N3 m. tW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
# k" z- k6 h4 A8 G2 I4 H- fto the VxD Control_Dispatch proc (how the hell a shareware soft could try
4 d( n& \  Y7 Q: t. i0 ]; bto load/unload a non-dynamically loadable driver such as SoftICE ;-).# ]: a6 t/ j  ~) H# T" _3 M5 t
If the VxD is loaded, it will always clear eax and the Carry flag to allow3 n0 u4 |& \7 J) s& R
its handle to be opened and then, will be detected.
, ~$ Z, \1 T/ L1 U- H6 rYou can check that simply by hooking Winice.exe control proc entry point# T( }; E/ F0 Q# T) B4 |
while running MeltICE.
# {+ x8 N6 p0 k1 X8 [
( D! X2 K3 N/ |; @" |
( E, w& b7 s& Q1 f8 M  00401067:  push      00402025    ; \\.\SICE; O  a' g% ^" h& m) M
  0040106C:  call      CreateFileA  p! e3 R1 M+ D0 g, K
  00401071:  cmp       eax,-001( `* j8 N9 [# h
  00401074:  je        00401091
  j7 b- R% t' W& c
* x% b6 U- w6 D: O
0 y& ~$ D- }; z+ W/ j; m! vThere could be hundreds of BPX you could use to detect this trick.
5 [% T) E* Q5 _-The most classical one is:
" ]/ K# e" |7 o- p* Z8 P# Q  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||3 D) u6 v/ ~) t4 p. V6 U( ?" Q- O% ]
    *(esp-&gt;4+4)=='NTIC'1 `8 O! y  v" N$ p

0 c2 A1 L+ l. H3 k) n-The most exotic ones (could be very slooooow :-(
+ x# d7 u; O, {& o0 W   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  / m6 T4 ~3 ^2 v# H% z
     ;will break 3 times :-(5 v( _& l7 v$ L$ @
5 L) }$ |3 Y0 K* `/ _5 Z4 k$ n
-or (a bit) faster: ( x1 h: d1 _0 B8 C( {, f! `
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')& X* M: @% c6 [+ C7 ]

! z. X; X  v  a7 H& |: j1 a. ]. T8 W   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  - z) x, p" p) E1 X- s' R+ _
     ;will break 3 times :-(
, x% }1 y2 V/ f  m' @) x& s2 A9 y9 @# H8 j+ @, W& j
-Much faster:
- p& f: z- N7 s/ y; H8 \   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
7 Z& F$ V& `' Q0 R
$ D3 S' H& Y% b4 I' g1 ~2 ONote also that some programs (like AZPR3.00) use de old 16-bit _lopen/ n% b8 R. [7 \# U/ K
function to do the same job:! ^; F( E4 G( f' h, N

& W- b2 [6 g' w" H- n" M7 h   push    00                        ; OF_READ1 m, n5 G: u/ P; R+ l# h" O
   mov     eax,[00656634]            ; '\\.\SICE',04 C9 W( }% }/ O, X. q! q
   push    eax
- y" W( k- e: B$ P' V' p3 Y( H   call    KERNEL32!_lopen1 j: ?' C* G2 C! W. }* k5 S* E
   inc     eax
7 @$ M! r, {$ @5 b0 T# T) |   jnz     00650589                  ; detected: j  i- l- j5 Y
   push    00                        ; OF_READ. |% {. ?! a2 R5 v: \! O# q
   mov     eax,[00656638]            ; '\\.\SICE'
, N: d+ m0 ~  n: N' }; w   push    eax9 M" k' f( l) L  }" J: k' B; {* d
   call    KERNEL32!_lopen  `* X  F  [+ z  ^! ]
   inc     eax
' K; F. l0 j7 p" D% m  b6 J0 u/ q   jz      006505ae                  ; not detected
' _& _& P; _: E
; o! ~+ m3 U5 X" V- E5 R& E6 R1 d: x5 R% z
__________________________________________________________________________
' H# ~! C" s1 h8 Y+ n8 D) H( d: |
Method 12+ n2 Y5 w5 X7 H* f7 F: w6 p# o
=========
3 Y6 y4 B! \9 {; L$ _, C+ E" `
( ^. ?! a) w. |5 I- T2 i3 r5 sThis trick is similar to int41h/4fh Debugger installation check (code 05
. }: k3 [' t" e& [6 E5 `5 a0 h&amp; 06) but very limited because it's only available for Win95/98 (not NT)
8 ]4 ~- Z" V, cas it uses the VxDCall backdoor. This detection was found in Bleem Demo." ~9 v7 _% n' M- b3 Q$ U- t

9 H. z' @0 V1 J! @# i   push  0000004fh         ; function 4fh
- N1 S* k# t( O   push  002a002ah         ; high word specifies which VxD (VWIN32)
8 _# A2 }' \4 X; u/ D& z                           ; low word specifies which service0 N( |. Q6 D/ [+ k
                             (VWIN32_Int41Dispatch)
9 ^/ B' W. R: J3 u   call  Kernel32!ORD_001  ; VxdCall
8 a- J, s5 `7 }8 o   cmp   ax, 0f386h        ; magic number returned by system debuggers
/ `0 m7 D1 h3 S7 ]; T   jz    SoftICE_detected
% F2 }8 [( `$ |! S0 s- x  Z5 h- s: ^! u
Here again, several ways to detect it:
+ F% `/ l$ l5 y
6 f' Z7 b0 M. Y    BPINT 41 if ax==4f9 X0 u. J% B8 r  l- g) K
. l  T  t$ Y  z: _
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
4 Q) b4 |9 x, _! d) W; l) W; Y: K; \) N/ K% N2 {
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
- T8 ]* S! Y" `8 a" ~% c, E# W. d4 V" i5 D  c4 ^5 _" N
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
! ?# w: Q" {6 N! p/ D$ n( j: `, K9 A2 E/ y
__________________________________________________________________________
4 [: b9 G6 s. z0 o0 m- A' C; R6 x
Method 13# t% e! K# A" E/ i
=========3 P/ m$ i9 U' E0 t

+ N4 _* Z6 s2 ~. UNot a real method of detection, but a good way to know if SoftICE is" `' l' n3 O( }! U) s6 g3 n# r$ b
installed on a computer and to locate its installation directory.5 D4 H/ m8 P: ~$ X; _9 _( q
It is used by few softs which access the following registry keys (usually #2) :
0 F4 A* C* x0 `5 {
/ F) i/ y/ a9 ^( k1 _0 f-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion0 O# _2 J5 @9 w) W6 M) b# f
\Uninstall\SoftICE
! R% D+ U4 T' [7 n-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
/ m( r8 v: y4 v( O' M- L-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion; R7 K7 G2 M4 h' F: y
\App Paths\Loader32.Exe
* o6 `0 E1 Z  o( l* I
. q1 f% T, `& _. b
# n! I% F8 Q/ l3 HNote that some nasty apps could then erase all files from SoftICE directory, g. u% e7 t+ P
(I faced that once :-(( h( B! l& e9 O* {  b; h7 R4 ~

, g$ |! b& v( w$ I' _# j/ U9 i' }Useful breakpoint to detect it:0 J1 [8 f7 u1 J& f% }* t
: H* J! t, K5 Q1 A
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'7 J2 p1 p: b; K! ^
$ Q, b/ ^& x( R3 f/ V; S
__________________________________________________________________________1 y1 ?( y! X# u) q& Q. |" Y
' y/ s4 ?- d. D# o2 Y! _
- H+ b$ w" x2 a
Method 14 % M) k0 O3 _6 N
=========
% n8 D" V8 a+ I8 |/ _" x% X* ]* z7 ^) ], G" O9 C/ r
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose6 A8 u2 n, @1 B4 F7 d
is to determines whether a debugger is running on your system (ring0 only).
- G- D' U7 W# e5 Q. w) S
- Z" \8 _- I3 w) z+ H% I   VMMCall Test_Debug_Installed( f$ C  C8 C7 {1 Z+ X  H& r
   je      not_installed* |4 Q4 e+ z! p+ _* Y- v% t" E5 I
# B7 |  v$ f, L5 |( h$ v
This service just checks a flag.
' l0 }$ r* P4 s9 y6 c</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部