About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>4 w5 u5 P% {' b* {; A5 ]5 s
<TBODY>% G) X! s4 t% L, _- ^+ y: |
<TR>
5 u0 C  r" C% m% J1 h<TD><PRE>Method 01 2 c7 B0 W# t0 f, ^
=========; b! `) S; V/ p3 {/ Y  X

& x) Q$ h1 i2 ]3 JThis method of detection of SoftICE (as well as the following one) is' n- u8 |0 j3 ^" w& X( S4 M/ O
used by the majority of packers/encryptors found on Internet.- E6 s$ Z5 U6 _0 V9 P/ N3 Q: @3 @
It seeks the signature of BoundsChecker in SoftICE/ u8 H2 h- ^9 m* u

/ _6 J- n- Y- ^6 Q# k5 B# Y    mov     ebp, 04243484Bh        ; 'BCHK'
' D* N% S) ?- N/ g9 y    mov     ax, 04h
# D. W0 j4 X$ |! `( x8 m, B; J3 h    int     3       $ E5 z8 Z8 G4 ^- V0 Q
    cmp     al,4
$ J. h/ @3 t7 c7 ]( L* Z* J' Y    jnz     SoftICE_Detected
8 Z! S: Z$ p) E/ D' J1 M: h' o; o8 l! |" Q) F9 O2 ^2 K
___________________________________________________________________________
' S' G, A2 S5 ]: I! y. K+ t4 E2 e2 v
Method 02
6 y8 F/ i& b( Y6 Z- ]  ?# m# d/ X9 k+ e9 I=========& e7 a7 Q+ \2 B; a
2 p4 R6 X" f1 P6 X+ Z. ]' ]
Still a method very much used (perhaps the most frequent one).  It is used
( V5 j2 V# c' xto get SoftICE 'Back Door commands' which gives infos on Breakpoints,( p* ?: I. U9 w5 r* t/ f
or execute SoftICE commands...
3 k! Z  G+ t/ e+ n7 O) e& BIt is also used to crash SoftICE and to force it to execute any commands
. ]+ V- ~/ |" L4 A4 V(HBOOT...) :-((  
# x; D5 c- W0 [; z& @/ ]! ?/ k1 H/ ^& q% [. m
Here is a quick description:
- d* e# H  n2 c1 S( e-AX = 0910h   (Display string in SIce windows)
& I& r+ g8 P% a8 V& \# }5 }-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)$ g9 j. B9 v( E. M  f9 O+ g9 g
-AX = 0912h   (Get breakpoint infos)
: I, C( x5 }( \7 ?# r0 I) u-AX = 0913h   (Set Sice breakpoints)& W8 m, b$ U2 N0 X) z7 w
-AX = 0914h   (Remove SIce breakoints)
% ^& r$ a/ ?1 \! J; a
) q+ b. u* I! Z0 x/ wEach time you'll meet this trick, you'll see:- G( ]$ Q8 z6 |: ]/ ]
-SI = 4647h
3 `7 s  U& F) }* P" |-DI = 4A4Dh5 g# H8 l6 x8 P/ ?0 l
Which are the 'magic values' used by SoftIce.0 d3 T# K; E( @7 L
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
& ?% l* a8 I' Y# U! |  z: d0 R/ v: l, S  h5 a1 f" @
Here is one example from the file "Haspinst.exe" which is the dongle HASP& B, C* x# T5 n3 F! f# j' M
Envelope utility use to protect DOS applications:; X# W& V+ p4 @+ `
" a0 H3 R; ^& c4 Q: V) y' F

$ _/ Y* ^4 \: F# A' J4C19:0095   MOV    AX,0911  ; execute command.1 [1 N3 l  l4 }, M% t
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
2 w' B# I  b! S+ B4 ]* A4 K7 i4C19:009A   MOV    SI,4647  ; 1st magic value.
. [; h4 a* T' M0 H- v& t+ O4C19:009D   MOV    DI,4A4D  ; 2nd magic value.# {$ P7 v6 ^7 N5 c1 k8 u2 q- x% y; w
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
. w* f/ }5 G( t" X1 A4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
3 ?/ s9 `2 c& q) p& ?7 S1 Y4C19:00A4   INC    CX* ~0 F, q) G7 [) D1 ?& Y
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
0 F& e4 h1 ?. g; e/ `5 ?4C19:00A8   JB     0095     ; 6 different commands.
' j7 }2 J) r% j  m7 J8 n* S4C19:00AA   JMP    0002     ; Bad_Guy jmp back.: t- v8 {4 x  ]
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
2 r' X' Q/ p% T  C4 N& x5 i0 I9 M# g  S3 c6 ]$ l- G
The program will execute 6 different SIce commands located at ds:dx, which
: z3 J' [  j% X8 s  `6 t: {1 E) M, bare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
9 i- L' V  n- d( H/ Y6 h' ]# j2 M) U0 M& |0 Z+ G
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
) V2 i+ _, E+ j3 k' }' k5 @- R___________________________________________________________________________
1 {8 m5 v6 N  z8 W, N0 a$ C, }. P: O; ?' \6 K: s/ F* }
* }0 w6 u, e1 y. r
Method 03* I/ }' \# G1 [- G+ n/ y, x4 A
=========8 Q7 y7 T) z* `

5 l% H6 l& D* p0 K# O7 O4 ALess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
4 x- k: N. S  O- e(API Get entry point), o' N/ G1 z7 e% R( r; C
        : R: a1 X8 J! A$ C$ w' e  }, N+ s

6 N; J1 l# j; j+ L7 J; N+ A$ v    xor     di,di
9 _, M: T7 C6 k% x( t4 j& L    mov     es,di% D5 n! b* n1 C- r( t6 t/ s* k
    mov     ax, 1684h      
. O- h) a% Z2 o: ~" d    mov     bx, 0202h       ; VxD ID of winice
2 ~) c# ~3 w4 i5 j6 W" z* n    int     2Fh
9 o- ]9 J0 r7 Z7 p2 j    mov     ax, es          ; ES:DI -&gt; VxD API entry point+ R% t4 ]- C% S. J
    add     ax, di, j- i5 f3 i5 G
    test    ax,ax; I, M, b1 `) w8 M( ~+ \8 N$ ~
    jnz     SoftICE_Detected
5 Q. s4 \& _5 m9 o5 J$ i
' v, G' ^: \1 u___________________________________________________________________________1 h) ~( D7 Z& \4 Y7 E5 r2 W) ?
& y) J' ]; n- i, ?: F, M* O! ]
Method 04
) L4 h& F* t8 C1 ^# M3 o=========
6 A0 u1 g. L, s8 I7 I+ a
7 T: F, R0 s! ]" F# A+ GMethod identical to the preceding one except that it seeks the ID of SoftICE% t- q& L  [; _" _4 J/ f
GFX VxD.
# ?9 q- u- W7 n& j" I* r3 u$ h% G" S4 s
    xor     di,di! H% U1 D' A' H9 ?' y& C. }; g1 w
    mov     es,di, F! n4 t$ _9 v8 ~6 L
    mov     ax, 1684h      
6 C0 l' {* o% Q" u2 M! g    mov     bx, 7a5Fh       ; VxD ID of SIWVID" i4 ^* L  H6 p4 q9 l
    int     2fh
( A9 {+ b0 j6 h    mov     ax, es          ; ES:DI -&gt; VxD API entry point" O' w2 z: o: y; S! ?# f/ k, Q
    add     ax, di& O3 \  A, j2 e- }% q* S
    test    ax,ax* N3 U( r  s2 s, n$ D
    jnz     SoftICE_Detected
  r% o: U. {5 j% [; Z/ a. z: b. ?& I# G+ X5 ~7 S, r9 q
__________________________________________________________________________" D, M* H4 U% o( C  A! [8 \% B3 [6 x

. M: X$ r2 [  C4 m  ^% t' z! l9 x6 c
Method 05, ]# k/ m: R% Q8 c" n+ ^* v* u3 ?
=========/ M  {( S1 o( I& [+ C% F
. Y8 N4 _* @9 _+ y- J% p
Method seeking the 'magic number' 0F386h returned (in ax) by all system+ i: Q# Y! k/ ?/ r' R7 v' P* v
debugger. It calls the int 41h, function 4Fh.
/ u3 o: h0 w9 S# x0 e1 vThere are several alternatives.  0 p% S" j1 ~; L, U6 B( B/ K2 }! X% v
) B4 B1 \8 l! G- V, E- R
The following one is the simplest:
% n/ f, x; W. m8 q9 w) ~( Y4 s
; a/ X3 _6 z: z  ~/ m    mov     ax,4fh0 ?4 x3 R* @9 ]9 Y" V7 }4 A* M1 A
    int     41h$ ?# z% Z! k+ F" r8 E9 ?: k8 N0 [
    cmp     ax, 0F386
+ G% E; D9 h, l; h, e4 ~. p    jz      SoftICE_detected6 r5 [2 J2 Z' {. j7 `: T
& j* z+ B0 h/ t: ]7 C
* q' e7 ^" _7 n) ^
Next method as well as the following one are 2 examples from Stone's & ?+ K$ b8 M* t$ v9 n4 h- f
"stn-wid.zip" (www.cracking.net):
) b1 d8 _0 S) A
% k- e* W. f$ v/ ?    mov     bx, cs
( c+ z1 [/ i# b: R# T/ q    lea     dx, int41handler28 ?, A6 J. @1 k9 t6 M/ B
    xchg    dx, es:[41h*4]+ w; J$ {* s3 {. w. W1 A0 h- q
    xchg    bx, es:[41h*4+2]
% p& k3 s2 p6 n* r( `- `! h: s( e    mov     ax,4fh# C* I2 @  Y/ q2 c+ j' R
    int     41h
3 [- y( X8 `, S3 D    xchg    dx, es:[41h*4]# h) X7 Q! Z7 i( `- U: H5 [2 V$ `7 V
    xchg    bx, es:[41h*4+2]9 r9 G, |  f& {  R- q
    cmp     ax, 0f386h4 [2 H2 v% o  n' D: s
    jz      SoftICE_detected* I3 ]4 p% P1 y+ v1 H, H

; W6 y8 Q; ~" ^int41handler2 PROC/ e" v" m& P" y$ J; H1 ~3 w; R
    iret
6 `# ~* L) z: x9 K5 Q/ |int41handler2 ENDP4 M' _0 a& C, C9 o! Q5 z/ j6 K' t* p

1 f6 W6 a9 u0 `: a; Q, N: K6 N  ^) k. L' V6 c# c
_________________________________________________________________________- B0 \8 A  P' o0 M$ L  N

# x8 J- W0 z2 O" `) y' E! w( L4 D0 r8 M0 b6 B1 S- q: ]+ B
Method 06# z! T4 N% {# Q' z* e
=========
) y' A  @3 \5 v6 _& n0 j9 K+ Z2 M; L7 f8 e

) _6 b, j8 P" h. s' e* n: }! q' Q2nd method similar to the preceding one but more difficult to detect:7 u- E0 }1 d/ T
+ ?* k& }$ f' r0 k# T
2 b8 b9 J* R( T  ^; s
int41handler PROC
( ~3 P# |% r2 @; `: i    mov     cl,al
; U! p, h2 H0 s( s    iret2 U1 M8 w6 M, v. f
int41handler ENDP- G9 @9 |5 L: o5 n6 d' N- A( ]
8 i9 |0 L2 D' N' n# N; h' r% y, d: S

! A/ O9 K7 B8 s9 ]9 m1 n    xor     ax,ax0 n- [2 d; s/ P/ `8 D7 s8 t
    mov     es,ax0 N3 f3 z0 H5 R; S9 E6 F
    mov     bx, cs
' B. a9 A0 F% P    lea     dx, int41handler4 R- b- U1 g  @
    xchg    dx, es:[41h*4]3 L% n7 Y1 P4 |" Z! R0 T2 i- \
    xchg    bx, es:[41h*4+2]5 X' T5 ?& t* |
    in      al, 40h
/ e1 d. T$ W- J0 F    xor     cx,cx
  x% I6 g# l; j6 a& |5 [    int     41h, R% |- X: R$ C% S% J7 x
    xchg    dx, es:[41h*4]$ ?/ V9 `4 k8 [4 u( I
    xchg    bx, es:[41h*4+2]& q- }4 L/ z" K* K
    cmp     cl,al0 }) K4 _$ V! a% d: x/ o
    jnz     SoftICE_detected* ]8 [6 I& N& ?& R6 u+ Z0 j$ W

5 T: W; t9 J0 {( }' F_________________________________________________________________________
1 P- r" b1 y; d: g2 J6 A( C* V2 |4 \. X5 W
Method 07% t! |0 R4 A$ k, [" I2 o# ]- m3 c
=========
6 c9 s5 u9 ]7 W7 M3 J) g1 e, c! s# A4 J3 r5 R: c
Method of detection of the WinICE handler in the int68h (V86)
( n9 J) P/ Z$ u
& S, u$ g# B2 a7 c    mov     ah,43h1 L- j- ~* l5 Y' @7 D: L8 Q
    int     68h# [0 s, y& r, X4 r2 \+ y; z
    cmp     ax,0F386h
( H9 j0 N' b7 o& z' e+ Y; W    jz      SoftICE_Detected' m8 R& e3 D+ X7 ^4 q3 _8 k
; m" \- g; k& G* D
' w0 X& _6 A2 D3 |8 x  T# P2 Z
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
; K  ~% S2 I/ G1 |   app like this:, j- a  J) o" p) H8 Z0 c" _# d& A
- z7 I$ Z. N4 @1 d( D
   BPX exec_int if ax==688 L  {  Z4 a( I6 _0 j
   (function called is located at byte ptr [ebp+1Dh] and client eip is
9 X  u8 v+ J" l   located at [ebp+48h] for 32Bit apps)
1 A6 ?/ p; a0 L$ ^* I# S) F6 `) O__________________________________________________________________________8 r$ a% V- W- R

. `9 d$ f# U* b; b. W8 M2 p& G0 o/ l; r7 p. F! ?
Method 083 s. {' W* k7 [9 d+ g( A2 h& U
=========
0 W( M- I  |( L8 e( Y
# A& O4 c) x9 h4 HIt is not a method of detection of SoftICE but a possibility to crash the
1 B4 A; l; X$ msystem by intercepting int 01h and int 03h and redirecting them to another
0 h. t; f" D1 [/ U2 x6 U6 `routine.
6 M: F* m+ \% S7 ~% m2 RIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points+ J( J1 n$ U0 `/ Q7 |1 r: i( A
to the new routine to execute (hangs computer...)
9 [/ `3 [) A. W+ x9 |- G
+ J3 m" J8 q# x3 b    mov     ah, 25h
, [) |: Y( _4 V  _! X    mov     al, Int_Number (01h or 03h)
- g- w4 a7 m3 |) w    mov     dx, offset New_Int_Routine7 T5 m- j# H& n1 s6 z/ N  O9 v
    int     21h
" ]  X) X7 U9 R% C+ m* R/ P: _
2 t0 w& e2 _, E8 X6 D3 N- h9 o1 j__________________________________________________________________________/ e6 O; ]8 k4 E. z
5 Y. B( r$ G: N: l6 l  v5 c
Method 09# l. G/ T) B: `" ^: o
=========
1 I6 D6 t' c; M1 d
6 X4 R; i& _( q1 h4 b0 [This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only* ^9 S0 |+ |* C8 M9 |3 h
performed in ring0 (VxD or a ring3 app using the VxdCall).  q! _) o# r# P, {
The Get_DDB service is used to determine whether or not a VxD is installed7 |% f9 |1 ?- p: `# @
for the specified device and returns a Device Description Block (in ecx) for
+ N' J+ H5 O8 qthat device if it is installed.
% C& M: S; E' L. r5 W" P& N/ H! I5 H7 c8 A$ ]
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID$ |4 T$ `2 I. \: r6 ~- n2 O6 f% W4 y
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)4 ?# G# n( t9 b0 o) i4 r. J
   VMMCall Get_DDB
- ]: K: }- G3 S: W  A& r! Z   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed+ X- }0 M$ Z0 g/ K9 y/ j0 v
1 [% Y3 F3 i, k6 B! \9 u- n8 o
Note as well that you can easily detect this method with SoftICE:
* s0 M  _9 }' K* A0 K3 Z   bpx Get_DDB if ax==0202 || ax==7a5fh
& S0 f1 j6 ~: P. b, C/ r6 |+ J+ w- L
__________________________________________________________________________
/ f! y4 C& O6 S  y6 ^. f: k8 l' s2 ^' H2 k6 z' [- ^  Q' L3 B
Method 10
* ^( q! W. F0 i=========3 j$ W/ D& w/ `

6 B) q3 S5 }; [+ y( ^8 M+ O=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
# \4 w! e# \2 i) ]4 O' u  SoftICE while the option is enable!!
, b) n4 Q! G" u1 V2 G, R2 y$ C  v( Z- }, `; f
This trick is very efficient:
1 m( B% |' \) x( @% lby checking the Debug Registers, you can detect if SoftICE is loaded3 Y4 L  d0 ?  ?
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
! c! ]9 V. [; B0 s: O& F& zthere are some memory breakpoints set (dr0 to dr3) simply by reading their
: v( x. z3 b: ^: qvalue (in ring0 only). Values can be manipulated and or changed as well' M) O$ R9 D3 @- u
(clearing BPMs for instance)8 l  X; l: C" [
9 o5 @' ^4 _) }- S
__________________________________________________________________________+ w9 s, k( [+ I
( O4 W5 L% I' p! d# p4 m
Method 110 i4 Z) |2 ]  T% M# o& F3 n) V
=========3 j, b4 ?3 K$ f7 |

2 F' J! w$ [) V7 g$ C9 nThis method is most known as 'MeltICE' because it has been freely distributed; Q, g) A" o! D( i( B3 E6 l
via www.winfiles.com. However it was first used by NuMega people to allow
- i+ y. E" P3 ~3 M' E% ^0 fSymbol Loader to check if SoftICE was active or not (the code is located/ C( }) ]. I4 I  b2 `* m' s# F8 H3 Y
inside nmtrans.dll).
0 e7 @% Z: r, y& r# ~2 x
+ n4 e/ e/ X$ s- [( LThe way it works is very simple:7 l. \: u! ?/ J8 v8 J6 y
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
$ u9 C- s% @, B5 K8 v; I, x; zWinNT) with the CreateFileA API.
3 n# Q* b' k( s. d. V! i& N1 u) j$ N) B- B' f5 ]
Here is a sample (checking for 'SICE'):* \* f7 F+ o" r4 R' o7 ]+ ]

* c6 E1 j' Q" `1 d3 }8 H  xBOOL IsSoftIce95Loaded()
# G% J% A% }9 S. [& b: m8 j" Z{
' O% A5 M& R- q! |0 k* Q   HANDLE hFile;  0 ]' M, e2 u9 C
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,+ b6 h$ \: Z7 G4 y- i" t: J
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
; B# O; B6 A7 d0 h# q% r                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);: M% o& A9 L0 g1 f8 n. v
   if( hFile != INVALID_HANDLE_VALUE )
3 c  P9 b, x( g  b, J   {$ |  u, A" k8 |
      CloseHandle(hFile);
: q6 V) A3 m8 S  X3 `, s. W& J      return TRUE;, ^' `; }# V5 [, D. G+ b
   }
- r# n2 \1 X1 M   return FALSE;9 s7 }4 H$ c- g. G% v5 q9 Y
}
$ L3 X7 }. m0 E" t, ^* e# `* x( b
Although this trick calls the CreateFileA function, don't even expect to be
$ }# k. g7 \$ v$ @  Hable to intercept it by installing a IFS hook: it will not work, no way!% z/ m  E9 k+ L% t1 ^7 j- `
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
& E% d' A7 O+ x" Y, C1 }service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
4 \, p. V4 o% I8 land then browse the DDB list until it find the VxD and its DDB_Control_Proc+ G$ ?: Y: z$ {# p4 J3 m. q6 ?
field.
# Q; c1 v& {7 O6 sIn fact, its purpose is not to load/unload VxDs but only to send a
* M; m( }5 {/ t, K7 [W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)4 s3 G7 O9 \1 d+ G. r3 j( Z8 q
to the VxD Control_Dispatch proc (how the hell a shareware soft could try! ~7 s0 |- ?4 F6 P
to load/unload a non-dynamically loadable driver such as SoftICE ;-).. T) r8 H& f* C" w
If the VxD is loaded, it will always clear eax and the Carry flag to allow
5 l! a" l& N7 q; G+ A. k, @% aits handle to be opened and then, will be detected.
5 i; Y: m- N7 \, m9 DYou can check that simply by hooking Winice.exe control proc entry point
+ M" ]3 w) |0 X1 |, R1 @while running MeltICE.1 N) _8 @7 L  c# \2 E
/ S3 R: \- L! V$ g4 y$ G8 L, I
( r7 Y1 H6 D/ y; ^( U8 z: [
  00401067:  push      00402025    ; \\.\SICE' h$ a$ Y/ N5 `) B5 e) t& X. A# E6 e
  0040106C:  call      CreateFileA
  M2 R& Z, |% u  k+ e  00401071:  cmp       eax,-001
- q$ q; `; J) `, h" ~  }) w  00401074:  je        00401091
, J# V% n- r2 _' n: g, }/ h
$ [1 A, m# V* @$ u6 _
; e* I1 O/ J& I" Z+ J- V) QThere could be hundreds of BPX you could use to detect this trick.: t! Z; J( N2 ], d  m
-The most classical one is:
1 J# I9 B, _6 V. x4 y$ x  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
7 m8 d5 S. r+ X+ c$ K$ P    *(esp-&gt;4+4)=='NTIC'
+ H. M% g- P, g$ h5 t; b0 a" ]; h( T# O/ g, q: g
-The most exotic ones (could be very slooooow :-(
) w- }7 O9 P/ D* U   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  , @3 z  |6 O8 ^7 F6 A+ ^0 P( K6 ~% Z
     ;will break 3 times :-() ~, _' s# W/ d- o
9 o) H% D3 b+ X' R9 L4 z& w
-or (a bit) faster: 6 c$ m/ |- c! r
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')% A# t* n) ~1 Q' q

/ z  o. z/ `$ G3 t+ F   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  ; y. {) Q+ i8 S
     ;will break 3 times :-(! Y  j+ M/ r- q, U& b  U+ b! Z5 X
' M& q5 {9 W8 i7 c( w: H' S# B# r
-Much faster:
/ z0 |2 p0 a0 [$ k/ k& a6 `' Y1 \   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
0 M1 S  O4 R) M4 w2 d, W2 D" F$ z, U1 w& D9 T  Q# p
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
- Q7 D% u' Y! _9 g. Ufunction to do the same job:' F# `9 P% V/ E; g  D* `

4 v/ G' L/ O! z0 N% k. p   push    00                        ; OF_READ7 l7 r) O" S$ m4 f- D9 h; q
   mov     eax,[00656634]            ; '\\.\SICE',0! v, C# d5 |7 Q) s
   push    eax
% H8 ]5 h- Y% L7 G8 |+ s! ?. r# R' B   call    KERNEL32!_lopen, a1 J2 V8 E4 {: O9 I
   inc     eax" v4 `- R! {4 c7 N. v
   jnz     00650589                  ; detected* t- L- E1 t/ E2 r  k/ U9 h
   push    00                        ; OF_READ! l  g# R# P" m& O
   mov     eax,[00656638]            ; '\\.\SICE'% V" e! m% ~' p+ [$ L* U
   push    eax
( U+ k% X- f7 Y   call    KERNEL32!_lopen
. G: U7 N6 s, [' H   inc     eax
) E$ A5 F( _* W) G9 q9 P" ?; m   jz      006505ae                  ; not detected. N3 j" \$ @  Z4 B7 d: x+ x
3 Z  J6 A3 i. o# c

; Y7 E4 Z2 o) w+ W5 _# Y8 w( E' ___________________________________________________________________________
6 n* N5 P; ^* C+ ]
! n+ R# l! R, A" WMethod 12
8 f5 c" T4 J: j! ]& p3 P4 w=========- m) l6 u. P. [9 B
" v0 m) k; \# y  D/ ^1 _. D0 m
This trick is similar to int41h/4fh Debugger installation check (code 05$ o1 b% g2 a0 a7 R
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
9 n* \! C+ `. u& Pas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
7 P1 G& Q' v2 a) s4 x/ X& j  ?$ u/ p6 y  _( [( Y
   push  0000004fh         ; function 4fh% n" J6 Z' {( Y& L1 f7 s
   push  002a002ah         ; high word specifies which VxD (VWIN32)0 P6 t1 q: Y4 o
                           ; low word specifies which service9 @( F3 x% a5 l8 g
                             (VWIN32_Int41Dispatch)
2 m6 c7 b: v+ H+ M* w9 t   call  Kernel32!ORD_001  ; VxdCall
8 s; V# {2 j. E* ~0 q   cmp   ax, 0f386h        ; magic number returned by system debuggers
: K% U% m4 c2 D; }0 L9 B   jz    SoftICE_detected3 ]! q7 U9 [+ F- G
, A8 |4 N% q( ?, `( T1 F
Here again, several ways to detect it:1 R4 F1 V' {0 h; ^, W5 r

5 L3 W, Y3 i# k/ U) I' }2 y6 w3 l  D    BPINT 41 if ax==4f$ C! A4 \1 n  D! H6 J
# R4 w$ e! k( O5 O; s( n: A
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
7 t) o  e+ t# _
& d0 P- S$ K$ q9 o. G( W) E/ ]# {    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
" v; P  }9 `3 [5 M, S( m
; ?. Q! {" Q4 D% X: \    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
/ R. V, h( ~9 ?" J( C4 ^
! i3 v# A6 y  {- f& ^; V- z__________________________________________________________________________
5 r8 S% h0 e, R
8 z& [- y4 I' k) eMethod 13
( E' [! z% j0 E5 ^, W8 _) n=========( s; Z3 n0 Y% Y9 P2 _9 Q$ @

9 D- [$ N2 r/ L* H3 HNot a real method of detection, but a good way to know if SoftICE is. U3 ~! R9 W3 D
installed on a computer and to locate its installation directory.
+ x! T0 Y0 \! K4 A* A: i! dIt is used by few softs which access the following registry keys (usually #2) :& A' [( {5 e, b9 D* O

* G( h- O3 i5 _-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion$ a+ X6 Z0 T6 V2 P4 l7 X
\Uninstall\SoftICE* y- C' E7 }% m) s) Z
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE; D4 v) j% V9 x# z% S
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
4 h9 q( a7 q2 O7 W) {& h7 Y\App Paths\Loader32.Exe
' R+ |: Z3 c0 b+ z4 J8 e  Q3 }6 w1 V$ ]" A, N# Q) u7 S" C

  L+ ]6 T. c7 A. J5 @. MNote that some nasty apps could then erase all files from SoftICE directory
4 H5 c6 ]; _$ U1 K* w(I faced that once :-(. I( N' y; q! c/ S, v; M
& M) \7 v2 Y8 d3 m- @
Useful breakpoint to detect it:+ U& c' C6 j$ C' A6 N7 y
( ?; A, q  J& x( L; Y
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'+ r( Q1 _# U3 F* h: w6 S

" V% ]+ b2 {" B8 h$ r; a__________________________________________________________________________# @+ |, T; ?  s' @' r% p9 V. e
! ^+ A- g2 x6 r1 A6 D" g& m6 i

3 k9 R: w% i6 h( P( I) {. nMethod 14 8 y2 F% T6 {- p$ `2 k# X4 C7 n/ u
=========# t3 W8 |' k( g/ ?' A4 \

  D1 c$ h5 I* ]2 x2 vA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose* d0 n2 c4 W7 W' l* @
is to determines whether a debugger is running on your system (ring0 only).
- a  ~3 n* Z6 ]3 U! T# [& j& Y3 D- I% l
   VMMCall Test_Debug_Installed+ k- x/ g+ ?! G, K$ Z% M% ?
   je      not_installed# u& q- l3 y% L. p) s

; Z  Z4 A( H! l; j) KThis service just checks a flag.
0 H. v1 e- O+ p+ }3 s1 {6 A) X2 _4 g</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部