About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>& H5 b" L9 p3 A. _3 p+ C
<TBODY>! B( z' R$ D: B/ f) H# V
<TR>
9 T5 i2 N; d5 }4 r* m/ i, A! U<TD><PRE>Method 01 " O' L; X# H5 y: ^
=========5 u" X5 Y9 [! [2 d

) O+ Q4 V2 d/ H" d" O( i3 J3 ~7 h# A: gThis method of detection of SoftICE (as well as the following one) is
4 r# j/ U$ z6 e! R  Y5 @: t1 l" qused by the majority of packers/encryptors found on Internet.9 w, _8 R1 {4 _$ K6 t, ]
It seeks the signature of BoundsChecker in SoftICE  W. y* N  D: p

5 C9 ]' U2 C0 U1 {    mov     ebp, 04243484Bh        ; 'BCHK'1 f: y7 |9 n+ x% L. y% u
    mov     ax, 04h5 r* G' }2 K& Y* \5 d; a. C
    int     3      
0 @. ^5 P+ J2 e/ v+ g    cmp     al,4) z+ t$ q9 v2 i8 N$ |
    jnz     SoftICE_Detected) I' }) J" e. t& U- C  U4 U! r0 }
" Q- y; B, l9 }& c7 U: D
___________________________________________________________________________
$ `6 [0 t% U+ }8 `4 \9 Y+ g! E# K0 |5 b; K7 [6 x" ~
Method 02
* \! r0 k6 ?. b, h( S' f% m; ~2 s=========* V3 K& y1 t. J! B& A4 |

" @$ i# Y" e. H' h1 j1 [# J, uStill a method very much used (perhaps the most frequent one).  It is used
" u7 x3 L) ~# [7 Q) Z7 g" q8 C; \to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
! P5 S6 \8 C9 x* [2 N- u5 ]) m1 {or execute SoftICE commands...
9 m8 z6 }9 G, X& yIt is also used to crash SoftICE and to force it to execute any commands3 r9 r1 ^. j! [. ~* h* {1 c: j
(HBOOT...) :-((  1 Z+ \# G! ^6 p/ y3 k, A: D2 }

7 h3 u5 t% O9 x6 d, i* e4 SHere is a quick description:
. S% v5 A; p1 p-AX = 0910h   (Display string in SIce windows)
* Q7 l6 j- s$ m- B/ \# Y. ^) F3 s3 G-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)3 V- f" t3 w' O9 Q* g
-AX = 0912h   (Get breakpoint infos)6 t$ r2 V: W( ]0 r# L
-AX = 0913h   (Set Sice breakpoints)
& I4 P0 `+ F$ c! R-AX = 0914h   (Remove SIce breakoints)8 [: g1 l7 N" h3 t

$ Q$ t+ h& ]6 yEach time you'll meet this trick, you'll see:' \9 R" O9 ]4 q/ ]% C* o; j9 @4 i
-SI = 4647h% y- B& h+ B% L, E4 Q. @
-DI = 4A4Dh( r! E; K- w. t8 t2 j- M
Which are the 'magic values' used by SoftIce.
) ^8 N/ e+ v/ R1 U3 [7 \2 dFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
# z3 H3 O1 \# U: r  T1 L' g- J+ z' }5 F
Here is one example from the file "Haspinst.exe" which is the dongle HASP9 s/ y$ c1 I/ D4 t5 V) N# J5 ?
Envelope utility use to protect DOS applications:
5 }" P6 y7 [  e! p
! [2 Q: |" Y7 t5 G3 P: |0 ]# }4 G6 p
; N4 D; v$ E" G) |6 t3 J" \4C19:0095   MOV    AX,0911  ; execute command.  N8 O' h- g7 Q5 U$ A- C8 O
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).* Y" |* c# N7 F- b2 B
4C19:009A   MOV    SI,4647  ; 1st magic value.
: v9 N0 Z6 @6 y; B6 l4 S4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
0 K% x5 A- U# M; d% H, D/ z" \9 }4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)9 Y+ U! a, ]/ m) p7 M
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute. w# m& H0 ~2 I# P8 c% U! z
4C19:00A4   INC    CX4 \: f. p0 D! f& K8 E. Q8 [
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute0 p! M) s# o6 v
4C19:00A8   JB     0095     ; 6 different commands.
( z* W, _3 o4 e$ [9 C4C19:00AA   JMP    0002     ; Bad_Guy jmp back.  M0 a, J. g1 |
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)) q: a# S) `+ Z' w
  e+ d; A! G, q
The program will execute 6 different SIce commands located at ds:dx, which3 A: A* u2 ]$ \4 M' t
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.: D9 ^; h) O2 {: r0 d" A, X
9 p# k, w- m* q/ E+ W% \! s+ u3 V
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.  e) {, W; O" B  o" c
___________________________________________________________________________# \5 w+ W8 z6 ?; C

7 C4 P! n3 M9 @3 H) Z; `1 M& d
, w8 L! ^) H; R) }Method 037 Z" A3 r5 w, V# Y# _5 w
=========
& {! d; ~8 T3 e8 ]( k
/ k4 |8 d" k1 f4 CLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
5 ?, ^8 l/ L6 i+ V2 C* p(API Get entry point)
' y2 S6 o) @$ {3 R        
8 j0 K8 Z' P+ X2 g5 z" t+ z0 W  ~) o6 }6 a6 w
    xor     di,di
* ^( e5 Z9 q0 A    mov     es,di2 O7 c4 e$ w3 K4 m" X
    mov     ax, 1684h       9 w2 M  s3 z  o0 \
    mov     bx, 0202h       ; VxD ID of winice
) S/ p+ V# j, @% y' \    int     2Fh
) a( b1 }/ W5 V+ H  W% `    mov     ax, es          ; ES:DI -&gt; VxD API entry point, V- f2 X6 P* B0 s
    add     ax, di
% E# ~- v# `6 i/ M5 v    test    ax,ax
7 r$ E' @7 G" D1 Z3 K: X6 g  P% O) p    jnz     SoftICE_Detected$ N" J& h! e# i3 ^5 S( s% j- }
$ I( u+ p) }+ c9 @1 y" I$ Y
___________________________________________________________________________
2 K% X* @5 o: |. M1 q, B$ i- H, C  N
Method 04
: P. F+ y! t6 v2 ?=========, Q$ |6 I# R9 d; G! t& c7 R5 s, t
* G9 m* T9 ~! z8 U0 }! B$ f' L
Method identical to the preceding one except that it seeks the ID of SoftICE" e  z( z0 E7 l  ?+ D, q; h; x
GFX VxD.
) n0 [4 k% Y$ Q  n1 ?  L) w/ b3 x
( f. ]; q& g- {3 k- r+ ^    xor     di,di
$ y7 C# }& ?& k5 `  x  m    mov     es,di1 @9 U+ K; d- ]
    mov     ax, 1684h       # i. H- J5 I/ D, D) q
    mov     bx, 7a5Fh       ; VxD ID of SIWVID$ ]$ I) ^/ R: ^+ S3 E$ D
    int     2fh
' t+ b' t) Q' C$ W0 C    mov     ax, es          ; ES:DI -&gt; VxD API entry point
" x7 v' u7 X2 E* T' h( o    add     ax, di
7 R+ A  }! m& L( F9 m+ d$ x    test    ax,ax+ V3 H+ o7 I1 C, ~$ H9 H1 m# p$ Z
    jnz     SoftICE_Detected
7 i% s% H% s7 P2 W, v0 z/ \" h% T
__________________________________________________________________________
+ _$ S8 X7 E. e) g- x) Q, J0 ]1 T5 N6 t: B/ L% P0 o

; z! s( m2 Y- e3 Z% [Method 058 O! W( Q) L( ]: h; e& v9 t
=========
8 ^' A* {) z5 C' L$ E$ D
  p- J# U# y  S: e! V- j8 P7 |9 _" W. RMethod seeking the 'magic number' 0F386h returned (in ax) by all system, N2 D6 e2 E! D4 m6 N3 `1 y5 Y$ g- R
debugger. It calls the int 41h, function 4Fh.
, d2 P/ s6 D# {& V6 E6 a% r7 ?( IThere are several alternatives.  
( ^, c" `* N5 Q) V2 ^- G- d' T( T
The following one is the simplest:) Y/ V! Q+ \( X

, w/ X5 J/ s% f: T    mov     ax,4fh
  R0 K. p$ }8 ?2 b% f0 f    int     41h
, G3 `) N0 m( ]3 H3 z6 B" i8 t    cmp     ax, 0F386
% _( a# _6 l3 T    jz      SoftICE_detected8 b/ G! u; d# t" e7 j

% E7 h$ {- a1 a  Y, X! ?; H! L) f% `! M& a7 E. a% c
Next method as well as the following one are 2 examples from Stone's
$ m2 f" ^! A* E* _9 a"stn-wid.zip" (www.cracking.net):7 Y5 z9 j' ^  n# F

3 H& `( d- I/ V+ }    mov     bx, cs
6 \; Q4 O8 ]: \  X2 g; M7 M    lea     dx, int41handler2" ~. w2 ]5 w1 z/ x; Q; o( P9 U! _4 j: K
    xchg    dx, es:[41h*4]
" Y7 C, O/ f' a5 u    xchg    bx, es:[41h*4+2]
: Q4 Q) l- n5 T# u9 ?3 R. q( D+ Y    mov     ax,4fh3 |- u0 G2 T8 U! t; B. C; z
    int     41h
  v. |2 F# g0 x# F. c8 L: U( n2 L    xchg    dx, es:[41h*4]
# ~3 j4 h1 T' `9 B    xchg    bx, es:[41h*4+2]$ O+ z6 O( L0 Y2 |% _4 e
    cmp     ax, 0f386h
2 I: q5 o) e3 ?0 n2 N5 U. S    jz      SoftICE_detected, {7 `" b/ p! ~# I
/ |0 W& T/ U) S# ?' P
int41handler2 PROC9 m9 E$ ^( D- p. [4 D. {7 c. Y1 i
    iret% }9 ~6 O0 f( H1 G7 D
int41handler2 ENDP
/ z/ U9 S' ]( v6 D. J
* V; E* N/ B. O3 u2 j2 X$ ]; u2 q
- y1 R2 l5 r$ d6 g  Y* Z_________________________________________________________________________
/ _! ^1 C2 s) e
1 _, R% `  x( w- a% L# c9 y1 v+ J# x6 W* k
Method 06- G$ l& [' I1 E6 A0 s
=========" e$ T. e( ^1 n% n& n
7 i1 E) M/ x& I/ E
! H. w% g/ y4 f0 D1 e
2nd method similar to the preceding one but more difficult to detect:+ l7 [2 I3 @& |1 w* ?" `) m

& K: V' M, w) Q7 e  s! t5 b6 E
# [; T0 @0 @# m8 V2 s, Q4 C: g" @% hint41handler PROC' I" S( {( u4 j9 W: n! e( ~9 b/ Q
    mov     cl,al+ K6 e' b" K6 K0 z* `( G
    iret
' Y. q* g! b6 Q8 d' y& T7 y& @! yint41handler ENDP
* ?! D4 a+ H7 P' G% i' v, T/ ?" p& t0 g
1 e3 h6 L) u( ]) p- d4 w
    xor     ax,ax
+ a2 Z+ F& U% b    mov     es,ax+ Q" c  }! P0 j  M
    mov     bx, cs
; Y: k1 L2 H6 @- M0 b    lea     dx, int41handler
% @) k5 P; b  V% d    xchg    dx, es:[41h*4]
" F! }! T3 u; w    xchg    bx, es:[41h*4+2]( a7 U9 a1 W$ I9 z$ a% \
    in      al, 40h2 k  e3 L; k- C& l2 ]* X, `
    xor     cx,cx: o) n, R3 l; W' m3 J+ m% h3 r+ E) e
    int     41h& R# Y1 {) D1 `8 T) J; B" h7 |: p
    xchg    dx, es:[41h*4]
$ S2 t  Y9 R7 s: _! P; k    xchg    bx, es:[41h*4+2]
, {, Z2 X, U+ X5 `; ?/ B    cmp     cl,al1 s" S1 ~; O% c& K+ G* D  e
    jnz     SoftICE_detected
9 p/ d0 A3 N+ ]& _/ g' Z$ p
, |8 L" n3 M3 l; A% h' e2 g_________________________________________________________________________
' D5 b! t3 J, }; ^
( \& k, n7 P* m. bMethod 07. O3 V2 z& n9 v$ `1 J8 g" A, K: G* z2 |
=========& V6 Y, N! T/ s% {! A/ j

) q0 @! a* R- Q2 P) u' i8 aMethod of detection of the WinICE handler in the int68h (V86)9 b" J' F9 b$ a: u/ _# B2 }

% ^+ S) ?9 s% Y" @7 h0 U7 Q    mov     ah,43h7 h) z9 o2 T  y( ~4 F
    int     68h2 o( m) [4 O0 E6 `% ^2 r' R) |
    cmp     ax,0F386h% Z' u. V$ R5 ~
    jz      SoftICE_Detected9 T1 f+ y8 m" Z4 y. k2 B! O

) C4 K4 k, e' ^2 [8 N+ _! X: ]% ^, t  M8 A- D
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
+ a6 y$ V( |! `& \. S% d7 J   app like this:
7 b  W* W: Z  r0 K0 K$ m' \- {) d. s5 s, D$ B
   BPX exec_int if ax==68, z: k' k2 a4 [
   (function called is located at byte ptr [ebp+1Dh] and client eip is/ d1 ~  U$ f* T8 i8 O9 e& P1 ~+ a
   located at [ebp+48h] for 32Bit apps)
( t: a. N0 n' A/ \; [1 o__________________________________________________________________________8 w# i1 Z+ W- ~% X' _& ]; c" w% u

, N5 v$ F; S/ z! b& L4 |! ]1 Y4 d" G$ y* ?( @/ o+ ^, b$ ~
Method 08
/ y# x: l  R5 H# J, r=========  i' D2 X) ]$ Z! E) H

" E' ~/ [, [7 |- \. K) T# ^' eIt is not a method of detection of SoftICE but a possibility to crash the
" f0 G- t- b: N( I# c' Psystem by intercepting int 01h and int 03h and redirecting them to another# s6 V; y' h/ R* K" w0 F
routine.# w: L% [" N5 r$ }6 {
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points+ e$ ^. Z; ^. N' n* m# Q9 ?7 y
to the new routine to execute (hangs computer...)
* ~* F8 M/ g$ h" j1 Y/ B. _$ O- Q) b5 {; p
    mov     ah, 25h
/ m: @1 n2 P$ z3 @# r6 Z    mov     al, Int_Number (01h or 03h)
* L( B# K* \/ G9 q9 R    mov     dx, offset New_Int_Routine
8 g7 @' G" \* V: w* l9 D    int     21h* ?: F% X  u  ]$ u6 J) U4 i
( x3 h6 z; Y% }& r1 E
__________________________________________________________________________
0 Y8 r) u. g, f, u+ U; l3 u: q) U. ~# S
Method 09
% O! m9 E3 w5 W& p0 O) S9 ]% ~=========" h$ g  R8 L8 x

" s. n8 F! y& CThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only3 z2 d+ V" k* H' `
performed in ring0 (VxD or a ring3 app using the VxdCall).
4 ^9 {) q" B/ d4 K! \4 mThe Get_DDB service is used to determine whether or not a VxD is installed
- O  f0 A  d# b: e- X/ q0 r( Nfor the specified device and returns a Device Description Block (in ecx) for
& t" V4 c4 Z3 T, x6 {that device if it is installed.% z; G+ {  g( B
+ d9 P. A! J7 _
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID- _$ h2 n1 C' l
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)% _4 w; Z+ ?" }2 O, N- t0 R
   VMMCall Get_DDB
- T& r9 F; h. _' }: F# J! i0 R   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed# Z0 t- f" Y) K& q+ x1 B

7 M% ~; M+ B0 b$ E- K$ Z, UNote as well that you can easily detect this method with SoftICE:
0 ?* T; R( }6 X" ~   bpx Get_DDB if ax==0202 || ax==7a5fh
. x: c& `$ i# e  [% k" s: m
( K) X5 x! ~1 W% g__________________________________________________________________________
: _9 z) T. X! t+ F9 K
/ w1 V3 A* l) k3 x# z- V0 ], \Method 10
) o/ o6 A- w3 y, C! J  x  j=========4 O9 t0 `( w) e8 W# k

9 c1 e" ~1 Y4 y/ Z& A# T0 t" }=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with: P" I: Z5 ^9 m6 k
  SoftICE while the option is enable!!
, G( E/ G" m9 p! C0 }1 J. o2 ?" L! Q# ]5 g3 u5 m
This trick is very efficient:$ z8 K" d! B6 C0 T
by checking the Debug Registers, you can detect if SoftICE is loaded! s% u3 l. G- [. f
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if4 X! `! C( W/ G( S9 w3 g
there are some memory breakpoints set (dr0 to dr3) simply by reading their& W# ]6 A, M$ E! X
value (in ring0 only). Values can be manipulated and or changed as well2 `8 S8 E, |; z' m5 Z( S9 m! x
(clearing BPMs for instance)
# [5 Z% D$ ~# ~* m5 D
% ?+ W3 A/ G4 w( W8 S2 Y7 [__________________________________________________________________________
8 y4 k1 n, j3 \/ H# i9 K& A* L1 y! L6 n; s
Method 11( |4 C7 a' q; A. ^
=========) v  K* ^' k+ j; M/ L
: w! b1 o$ x4 X( C
This method is most known as 'MeltICE' because it has been freely distributed
) I6 A5 w" m" o  ^$ ~# J! zvia www.winfiles.com. However it was first used by NuMega people to allow  ]8 P' T& g% r+ W. [
Symbol Loader to check if SoftICE was active or not (the code is located
) P% v$ Q2 T0 l6 n2 l7 ~: zinside nmtrans.dll).3 a& }7 e, a% B+ {( p1 P: \+ n* d
- X. X- X! y7 r/ k; e' c6 ^/ V+ b1 [
The way it works is very simple:" p4 [5 C! ^& @/ p1 }1 d7 U
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for& X4 u$ k' O) \4 [7 X/ w
WinNT) with the CreateFileA API.
' m. }. }- u- s
( Z" A  P' d" L4 P9 s0 IHere is a sample (checking for 'SICE'):
4 n" W, r1 g) Z# a" \! o! P8 d$ C% T# _7 L/ G! F( u
BOOL IsSoftIce95Loaded()5 l9 B% X* \- ]5 z( U
{
' k% m# _2 Q1 E# G   HANDLE hFile;  : w. W/ T0 J7 L9 h3 ^/ ~5 z
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,9 x3 P- l* V- _" P
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
" w+ c$ e' W% i5 l2 D( P3 P) g6 F3 [1 A                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);4 I( s7 Y; K/ g  C! e6 D0 \
   if( hFile != INVALID_HANDLE_VALUE )
9 U+ n- h7 W8 V/ @( [$ W5 W   {
( U) t& c, h" p5 F& N      CloseHandle(hFile);
/ n8 l- K; I9 R1 f# C8 f      return TRUE;
* G9 O$ w' x/ ?7 k6 J' b   }" W& |, J5 `5 n) J6 B( C
   return FALSE;; @, ^: N" X# Y
}
% D. `9 M6 W% Q. u) V; `8 h
9 t# T8 `/ P- e/ O7 ~! xAlthough this trick calls the CreateFileA function, don't even expect to be( Z' ?1 Z1 z2 r# H+ H* }
able to intercept it by installing a IFS hook: it will not work, no way!& k$ L' K7 `$ ?7 f/ m! K/ ~. P9 }
In fact, after the call to CreateFileA it will get through VWIN32 0x001F0 `+ B, s( T6 Z# N
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)) f0 u- P/ J* Z9 s# @
and then browse the DDB list until it find the VxD and its DDB_Control_Proc% ?# e( t1 w& Z) s* g9 F) r( S% [- C
field.7 D' k  O) g+ f  N% }1 D
In fact, its purpose is not to load/unload VxDs but only to send a
: o, P2 B$ r0 d  J5 r! x* O8 dW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)! y) m- R7 W, E( A  X9 o+ o
to the VxD Control_Dispatch proc (how the hell a shareware soft could try' g" f0 x/ `/ w8 z4 Q# z. S; Q
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
/ T2 z2 a$ `. l$ D- Q/ D7 x& J. `" rIf the VxD is loaded, it will always clear eax and the Carry flag to allow3 Y1 f, J6 v  @
its handle to be opened and then, will be detected.
1 P. G$ X, [& F& M' J. wYou can check that simply by hooking Winice.exe control proc entry point, j/ V0 e7 Q" f# m4 n; m* a
while running MeltICE.
5 B5 V" F/ }# h" v4 H1 `+ d% ~1 R  [/ g: e  f

. r8 H2 ~0 c$ `  W! w6 r8 o0 |$ S  00401067:  push      00402025    ; \\.\SICE
* f) L0 e8 O- B  T9 M5 f/ x6 W  0040106C:  call      CreateFileA
1 F/ M- q& X9 @* l( \, a) A% r9 X  00401071:  cmp       eax,-0011 J' ~+ s+ R  f4 _+ [% Q7 `. p: X
  00401074:  je        00401091
( Z$ @4 |# y$ R0 d
1 d0 z/ x- j/ e0 v) O
! c" P! r3 G+ m; n$ KThere could be hundreds of BPX you could use to detect this trick.
/ v! d1 Y- V# v- O0 {2 [-The most classical one is:* F  m" ]! k4 F# z  f' k7 Z. f  p
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
5 h, ]. Y; s. c% w    *(esp-&gt;4+4)=='NTIC'5 u; J/ h5 y2 ~2 u2 V) ?/ g# q
& U: Q5 N6 Q) D* A4 @  \
-The most exotic ones (could be very slooooow :-(
) ^' A7 `* c$ G% y4 G   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
9 ~  \& {9 F+ c1 i     ;will break 3 times :-(( o1 o$ D" X3 ~2 Y: M) I3 T- d

" b) d' t% D3 b-or (a bit) faster: 0 b1 J1 }# r+ i2 f5 q" \
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')9 b  x& E. F9 N& n! E% C0 H  p
6 ^3 n9 B' N9 I. v# W( q( t
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  4 P+ U  n1 T- {+ x3 P( ^) e8 l
     ;will break 3 times :-(6 K" G' m& s  I8 r+ @; u: p7 Y
2 \3 x+ n0 n1 Q4 A9 X4 v' v0 x3 }
-Much faster:6 \- L9 ]: {: ~' ~
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'- q3 M1 d$ r5 I) I5 a8 ?
4 G1 s" u/ u: f
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
% }! y) v; u3 Q% g4 t1 ?! I4 K5 [function to do the same job:+ X/ c- X' k! S9 S6 X. L
  ~) p1 W  g% `& n- a5 L4 O
   push    00                        ; OF_READ4 C, ], R( `' N4 s+ Y- r
   mov     eax,[00656634]            ; '\\.\SICE',0
6 x9 R2 t0 O$ E+ G   push    eax- T1 w4 H2 b, E: w2 z
   call    KERNEL32!_lopen
$ k% Y. `; i0 U& O   inc     eax
2 C; y* w  B' b) P5 X   jnz     00650589                  ; detected
$ K& t3 R2 B0 d% h  K! `! x! T   push    00                        ; OF_READ
. G5 T( g+ i  F0 J9 s; i# a   mov     eax,[00656638]            ; '\\.\SICE'" H* e/ h$ ?) w
   push    eax/ ]. ~  b/ @- w) s) }3 T
   call    KERNEL32!_lopen
8 N0 g8 q4 P, w' g# L   inc     eax
. C& q9 R/ {! U7 n   jz      006505ae                  ; not detected
1 `1 F8 h3 L2 ]9 U/ X8 A3 D7 x) U. S4 z/ D/ G6 j' {  A

0 `( ]. ]# u) P: R5 p__________________________________________________________________________
0 Y7 n9 d& `* t- f7 ^
0 K- F5 [/ g5 s- s% x- lMethod 122 {# o! u( W  e& X8 ~; V, h
=========5 n8 ]: p) Q) K1 v$ z' a7 f# K

5 _1 d5 L' l4 b5 lThis trick is similar to int41h/4fh Debugger installation check (code 05+ A1 W' k5 r1 R/ j( [" C
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
( E% w9 U5 M' ~. r4 @as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
$ F! M" V1 H+ x, ]4 P- b
8 s+ r6 Y& _: D% V6 \( L- N8 p   push  0000004fh         ; function 4fh: ~" d: r% Y# H& t+ s
   push  002a002ah         ; high word specifies which VxD (VWIN32)
: l2 L$ Z( [5 l8 j: j9 l) w                           ; low word specifies which service/ Z: b# M5 m4 e; h
                             (VWIN32_Int41Dispatch)* P; p8 P8 n& G/ ^' u
   call  Kernel32!ORD_001  ; VxdCall; m$ h# |$ h( S: k4 [/ c) L
   cmp   ax, 0f386h        ; magic number returned by system debuggers  }" w' f5 j2 }! e: S" C1 H
   jz    SoftICE_detected
1 v2 L7 n$ v$ d6 s$ M$ C- X7 n/ i8 P8 A& m( N
Here again, several ways to detect it:
( W0 u% Z' z+ r% m  a1 Y! d5 x! `% i0 Z2 T# f6 Q% N+ W
    BPINT 41 if ax==4f
! R1 G2 ^7 a4 l5 p$ [5 l
- D8 y4 N) H4 s% H3 x    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
2 v7 z, w' P0 Q; x; S3 \6 K: ?# R
5 [; x! H2 J+ o8 `- l$ e    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A) w* i5 h+ J7 Y0 t3 B: H2 J
/ r3 r' r' M" W+ S# n4 V
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!. l& J# X( Y+ d8 D. s

' ]7 e2 B3 ~6 u3 a% Q" o8 q__________________________________________________________________________1 V5 y( y' H) u% u4 n$ |: h

* P' ?5 A1 d2 p4 q  d- J2 xMethod 13# d/ {/ U  i7 M9 m3 |! l
=========+ k9 L/ ?2 K7 C$ U# g) \' ^/ ^

% @) Y" S! V; W) I% |$ ANot a real method of detection, but a good way to know if SoftICE is
& J2 M% I- c& D1 m6 h' g9 Hinstalled on a computer and to locate its installation directory.
) o( |: l" \8 u. \# b$ VIt is used by few softs which access the following registry keys (usually #2) :1 Y- e1 C* @8 O# g8 Q

$ ]/ q) G8 ~0 C) f: S3 _3 v" k' ]-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
3 {0 _6 C5 F( m4 D" Z1 n$ O3 W\Uninstall\SoftICE
* p) u3 t2 D' ]; G-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
# a/ b8 p3 `, ~-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion) w7 q, e! I6 S. R& P
\App Paths\Loader32.Exe7 e0 @7 S. e$ s) {% K( i" w; P& E
& Y; Z& M, F9 |4 @( l

1 m5 {. w$ A" x/ uNote that some nasty apps could then erase all files from SoftICE directory. x4 {* d3 U. p. U( V6 L* G0 H  Z1 m
(I faced that once :-(
& [4 u6 D( P3 ?" w7 b2 a) t9 y# T' n. p4 |3 q7 J
Useful breakpoint to detect it:! {7 H/ b! A1 _2 e

* r/ U" D. i1 g     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
# A" V$ S6 {* c! d- u' ?7 S% M9 Q  Y% p
__________________________________________________________________________
- e; V7 z7 ~$ \* D$ h$ a
" r! B$ w$ n+ o2 I! e3 B8 M- M% d) E2 W: S# D& T
Method 14 ' f0 e1 Q- c+ q. E% ]  d
=========
4 }3 K5 k# [& S) o9 p$ r( t: Y$ R
( L+ D4 |8 f/ G) \6 LA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose4 h' d7 g: s2 o# R, l* p
is to determines whether a debugger is running on your system (ring0 only).! O0 c; b$ R9 ]

3 _- F# A. l0 o% W9 u: j   VMMCall Test_Debug_Installed
9 b/ `5 z9 x) a5 Y  S1 u   je      not_installed
8 y' A8 v( q3 x, X9 ~+ \1 c) N) e9 S; i; T: A8 x  T0 J
This service just checks a flag.
0 Y% ?* u# S5 y3 o</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部