About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>$ S" R% O. e' o- [2 [. C
<TBODY>' _  j2 E1 j/ W3 w+ G$ ~
<TR>
1 ?. B* J& [) B' g. a% i<TD><PRE>Method 01
+ C' i1 F) f% U5 X- |=========+ y* D* j& U  p! Y# T' y' Q" l

& {7 v. n0 a! e6 q2 U2 o" O; KThis method of detection of SoftICE (as well as the following one) is
* t: `  ~* G9 b: z& H% _3 P% eused by the majority of packers/encryptors found on Internet.
; v5 \- g. t) n* G: MIt seeks the signature of BoundsChecker in SoftICE
6 s5 U6 I" T0 f+ U( F$ G' a. `3 d& O: c+ P
    mov     ebp, 04243484Bh        ; 'BCHK'
8 E/ o/ Z6 |9 W- F( Z1 ?1 n; X    mov     ax, 04h  w4 m/ w2 k& A# Z1 C
    int     3       & ?/ c3 ^, x; l$ x1 J
    cmp     al,4  n7 D9 M) q5 I
    jnz     SoftICE_Detected
& [* m' C; U! |/ X9 Y- U8 M+ o4 W+ \5 p& e3 t* {+ t
___________________________________________________________________________
8 a% y/ p0 f) b. J, u# ?: _8 k( Z5 i9 j$ y
Method 02& |9 ^- J/ y+ k+ D, `! K
=========2 q) _! a' g# ]% Y. Z# [
8 @2 C9 Y8 k! T# @* H. d
Still a method very much used (perhaps the most frequent one).  It is used
' s' \( [, I$ w- N2 C- M+ w% {, nto get SoftICE 'Back Door commands' which gives infos on Breakpoints,- D! E. q9 L4 r2 v" a; I! @! |" Z5 s
or execute SoftICE commands...
8 \# n3 `' D! |% M. rIt is also used to crash SoftICE and to force it to execute any commands
, e7 O" q4 i" f) o2 J9 d1 ?(HBOOT...) :-((  
# H" c' L3 N1 V$ T0 K, n7 O2 _' M/ ^4 m8 L) w
Here is a quick description:
3 ]6 j+ P' u; q5 k4 U-AX = 0910h   (Display string in SIce windows)
- i$ W4 N  h: n: @. ]1 G-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)+ t; h) H# |- u9 b  X: p: K
-AX = 0912h   (Get breakpoint infos)9 n3 u1 G0 w% s5 N9 f6 }
-AX = 0913h   (Set Sice breakpoints)' l" L8 E* \7 O: l
-AX = 0914h   (Remove SIce breakoints)
9 Y1 _( @; z$ @( {
! |. h' G7 K/ J6 |  KEach time you'll meet this trick, you'll see:6 [! u. J* V5 q- l! N
-SI = 4647h
  e- q0 C! G4 c' o2 `9 o* U, x7 ]-DI = 4A4Dh
9 C. |- Z- M' F: L2 eWhich are the 'magic values' used by SoftIce.
! ~& R& ~( @3 |- q4 cFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.( l/ g& `) l. L! F+ t% n
( P! @0 s0 P/ u
Here is one example from the file "Haspinst.exe" which is the dongle HASP
8 X' W( J" b$ G$ x8 u- x" }Envelope utility use to protect DOS applications:4 K4 s  {* x( G

  R" ^$ N4 F+ ?0 [: L  D% x% a6 Q
1 t: A5 Y/ G% E1 b4C19:0095   MOV    AX,0911  ; execute command.
+ d/ ^0 F6 m" E8 p( D4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).0 @# K' w8 B# S% ^
4C19:009A   MOV    SI,4647  ; 1st magic value.
# g: }: x# [, Y; W4C19:009D   MOV    DI,4A4D  ; 2nd magic value., X2 |/ b" R, ]+ _0 w% |6 I1 G4 ]) ^
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)# u  _' W3 i, k+ r2 D
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
! ?; o1 U9 ?/ T- Q9 `' t( u, x2 W  G4C19:00A4   INC    CX
; z2 I8 I/ T- N4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute7 [$ Z$ j) o( Z# U, L9 Y
4C19:00A8   JB     0095     ; 6 different commands.6 J$ G4 D  s+ T8 ?9 s5 q
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
2 ?& \- C& n* F- G2 F( p; ~8 A4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
' `5 ]# j( A3 u2 M) y- V" q- [; k  i( ]3 ^3 O$ H6 ?* y
The program will execute 6 different SIce commands located at ds:dx, which
  ]/ b' }6 v* a4 N0 Eare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
* i/ H( y3 j7 P/ t! ^1 h: T  _; ~  u7 P& z
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
% E0 O! \7 b0 \, |+ O$ s7 v8 u; p___________________________________________________________________________: f! W9 f( ]+ [; s2 D' g6 u$ P' n
2 U  C0 y, _. z4 ?. \9 ?
1 w, y- j1 [0 `" k; M9 B
Method 03) F' ?- g- Z0 H
=========8 x$ X" e2 A/ ?! Y3 v5 N2 N+ [

" M  x  v0 @# G& N% Z% s9 XLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
5 A- ^* q9 @6 [: D, }, d(API Get entry point)
) B6 P8 r* q; ]9 _$ i5 K        ' h$ k# \9 ]! y

& M& u) E8 [5 W) E& r/ ~* J! T6 ]    xor     di,di" `5 U5 ^0 q+ T6 b
    mov     es,di' s. z5 D! D) A4 I
    mov     ax, 1684h       + d" j; m7 g8 ~0 B& K+ K
    mov     bx, 0202h       ; VxD ID of winice4 f2 s1 l0 @4 }. ^, X1 R
    int     2Fh& @$ B& J- R0 q6 V  S
    mov     ax, es          ; ES:DI -&gt; VxD API entry point0 e' k! W0 @9 ~1 A  h
    add     ax, di1 ~  t9 z& r, H& U! E2 C5 w& r
    test    ax,ax
! O& w. W7 S' n. @" |- z3 B    jnz     SoftICE_Detected
/ x1 ^/ v, \6 Y# Y! ?
/ q7 r( h* y. p# v8 p___________________________________________________________________________
$ B- m2 ?( J" M/ J+ f3 Z& U7 S3 y, F6 c5 L1 C2 n
Method 04
6 P1 K5 E. o5 b2 L, e=========
9 z& P2 p2 f& F- P0 U  g# r1 x2 Q5 q- O  h8 q- a7 f) `
Method identical to the preceding one except that it seeks the ID of SoftICE
4 H: t# Q4 V, ~  CGFX VxD.
0 U+ ^: ^: _( b) a+ s) h  V# ?2 w9 B, L
    xor     di,di+ G# i1 d0 {1 O1 x) `8 i; D
    mov     es,di! z! H  _: ]- U/ H2 ?, ~
    mov     ax, 1684h      
& E' p$ G& n% s$ j5 i    mov     bx, 7a5Fh       ; VxD ID of SIWVID
! g1 m* o- h% n9 Q; n    int     2fh
( H5 _  Y% {9 k" z/ `" ^    mov     ax, es          ; ES:DI -&gt; VxD API entry point
0 L$ I/ f8 M( Q: F0 g9 ?: [    add     ax, di
+ R4 G7 N4 N! n; \# L# V    test    ax,ax2 T) Z- K0 A( }' A: |+ l. T
    jnz     SoftICE_Detected
# H6 M9 N- g4 e9 ]' i- v  A" m, r' F' s# q( q& E3 {
__________________________________________________________________________
( i3 E7 ?* d, l' [, Z5 i+ I# p% ^" Q
" i+ G4 W: h$ p- v# A* i
Method 05& V& Z; M9 N1 P+ `/ t$ W  E
=========  G9 L: \6 V/ Y+ W+ `

& j1 a: T0 [+ Q+ ~& TMethod seeking the 'magic number' 0F386h returned (in ax) by all system
/ b' r1 x, t2 D: ldebugger. It calls the int 41h, function 4Fh.$ P) L8 J* p& ^' w9 z' p
There are several alternatives.  
. f5 s$ u( R. w) P/ b0 k' z8 I
/ I( ?0 W& s, cThe following one is the simplest:
1 w+ T7 Y2 G% r" \# J8 a: o9 N8 {# c5 R% z
    mov     ax,4fh' r3 H. w: g4 d( o: ]) I" A5 L
    int     41h
7 ^1 g; i* T3 B7 j! a% V! v    cmp     ax, 0F386- {$ Q- q+ ]* L6 G/ ~+ s# F5 Z
    jz      SoftICE_detected0 E% W5 H! ^+ ~
8 E$ t+ t7 q7 t) n! e4 Z( G

$ h5 E9 d% e% c! B% {3 I* qNext method as well as the following one are 2 examples from Stone's
+ |/ C' o, `7 a8 B  W% d"stn-wid.zip" (www.cracking.net):7 ~0 t9 s. n5 I6 Y  d2 V
0 \. ]. x2 C& v" G9 R  x* Y4 D' L
    mov     bx, cs$ c8 B1 o) z3 b
    lea     dx, int41handler2
; }& t- e8 v. W5 w" B9 t    xchg    dx, es:[41h*4]! T' r4 S8 `& z
    xchg    bx, es:[41h*4+2]6 a& _2 b5 n0 L* S; K) u! a
    mov     ax,4fh3 [. ]2 w) s* t0 l% ^5 w
    int     41h
$ }) |8 u; H" W5 C2 Z; q    xchg    dx, es:[41h*4]; @' f5 v1 b, ~/ B9 x) S
    xchg    bx, es:[41h*4+2]
7 z1 ^* U* J/ p2 d& _    cmp     ax, 0f386h* A) S) g9 k0 f2 D* E5 |. @' n
    jz      SoftICE_detected
6 K8 g+ E. @7 t1 O0 r/ k. L: B9 F% E5 d
int41handler2 PROC1 h- P; @: t0 M3 k
    iret2 q( S* E6 d- y8 ]2 |$ u4 }" \
int41handler2 ENDP
: N  r& Y8 C& G/ d4 \6 b: @$ c. D; W6 M2 y; H% B  W! ]: }, a  z2 B# h
7 G, M+ I5 ^0 I6 U% F5 z
_________________________________________________________________________  W# C7 @5 U% t9 E: L" J& z+ s

( \7 a3 M5 Z8 w: x0 r6 o- A% O9 K, O3 x: `( @" `$ }  P
Method 065 l  M+ e. N% K4 B+ G: ~
=========
' d, Q8 D% Z: T, J  `* K2 Y5 `+ N0 l) b, l/ r+ U& u
  z. `7 V7 d8 T: M
2nd method similar to the preceding one but more difficult to detect:
6 J9 _/ e% A0 m3 Y8 M
# {  K+ }& M* q" K
4 c# u* |+ j$ _5 \& O- Z/ Cint41handler PROC
8 p3 f3 E; r  R+ X    mov     cl,al
6 l# v0 F7 R; W, `    iret
$ V: s! H+ F0 a4 r& p7 I5 Hint41handler ENDP
. ]3 x: d: q9 |9 }! j4 p
9 ]* Q  |9 E* A. ^
/ o3 {; u7 `( W6 q: M! }2 o5 J    xor     ax,ax4 K- w0 g# ]4 e, g# R+ i; ]
    mov     es,ax
& O2 _0 ^: a. X' E8 a# f" r    mov     bx, cs
9 c9 y( r0 M1 ^$ e1 C0 w! Y% d0 L    lea     dx, int41handler
; E6 }  m! z1 o- @    xchg    dx, es:[41h*4]
4 D( F% D& h! Z! x" U+ Y    xchg    bx, es:[41h*4+2]5 Y. F& h8 k0 K# e3 x: {: r1 D
    in      al, 40h! R! f2 O8 M9 D/ ~, q4 A6 w; y
    xor     cx,cx
- A, b3 f; I4 y$ F* I; E! X  Q    int     41h
6 Y0 A1 v. W9 Q$ `0 u    xchg    dx, es:[41h*4]
1 v$ j5 o9 U' f' E& B    xchg    bx, es:[41h*4+2]/ @5 a( I; r5 x
    cmp     cl,al, @# J  C7 }# V1 G' g* v. X
    jnz     SoftICE_detected; g, \) T. L3 O& M" M+ B

1 }: N, R, _* U+ b8 k_________________________________________________________________________
& z3 L/ X( b5 c5 b2 O1 a$ ]. v
Method 07
7 Z, o2 E: r0 k" F=========
! h6 U8 G5 v. L& M1 S7 ~2 _: k+ r4 O. r8 Q( l1 Q
Method of detection of the WinICE handler in the int68h (V86)& x! D, _5 u  n
, D6 S/ E1 u$ h
    mov     ah,43h
9 A5 Z& S( {& I8 R5 ?    int     68h
& x6 ?1 h: F6 g$ B    cmp     ax,0F386h
, \: Y" W  M3 v8 A) s    jz      SoftICE_Detected
. y% w1 p7 @% a+ ~/ `; `
' l8 r' Y( r1 M2 F0 |0 Q4 M2 _
; w7 d+ |- V1 C  p3 w=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
4 g3 L* n7 r! E. U   app like this:0 e* m) U/ U' ]  S" p. \

. t# W9 b( i  \2 ^2 j   BPX exec_int if ax==68  k2 n7 {& p9 S0 V$ k) b5 Y
   (function called is located at byte ptr [ebp+1Dh] and client eip is5 H/ B. B) M5 q/ E+ j% A
   located at [ebp+48h] for 32Bit apps)! q3 [7 o  B5 v- B
__________________________________________________________________________
# c" o, f; S+ j" n* k9 L0 n# ~1 V; `: X) M/ z

; E& _3 ?2 p* s2 u' A) pMethod 08
' `5 h; g. y7 I( {4 ]$ q0 x=========5 r2 b, g: z& b! ]$ Q

  C% }* Y' \! Z  EIt is not a method of detection of SoftICE but a possibility to crash the' [8 x$ y# p9 q# n) d& R
system by intercepting int 01h and int 03h and redirecting them to another. c# d# P; u- S) c$ q
routine.
/ j+ \# _5 @( |It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points- g) y2 Q. l7 C
to the new routine to execute (hangs computer...)1 G' ^/ h, v4 q: `
% o4 ]) g- x% K2 t: h
    mov     ah, 25h
3 o# e; K: L8 g( O    mov     al, Int_Number (01h or 03h)) l1 J9 ]) J+ l) Y2 ?  @* ?4 p0 i
    mov     dx, offset New_Int_Routine1 e2 [) R( }+ W# y
    int     21h
2 M6 k8 c; j. ~2 y' b1 g8 P# v4 W8 y+ {/ ~; H
__________________________________________________________________________& ~" Y8 B  C' g8 o/ _
# Q. Y% H0 x% ]# p
Method 09
. g/ ~, A1 t" {=========0 x+ _! G6 b7 @, L

3 ]) i+ T" a# n' ^! ^; _! D8 a7 {This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
- [5 j1 c4 g; Y0 S7 y" y! z& G' ^performed in ring0 (VxD or a ring3 app using the VxdCall).
# Z0 z& j# t$ v5 |$ {The Get_DDB service is used to determine whether or not a VxD is installed
% e% y; s5 A( M3 U; p5 ^for the specified device and returns a Device Description Block (in ecx) for
% k+ F9 }: t% x" Sthat device if it is installed.
3 c+ S# a$ e6 p( `. N4 i8 R. C( K& K) J9 E9 C; }1 I" l% e( A: O
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
4 {- c9 q' a1 n+ ^1 @+ I& e   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)' A( f8 p; O3 |1 o
   VMMCall Get_DDB
2 F  L" K/ \, a& |, R5 A  h   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed1 E' h1 ~. j0 f/ E# I+ O9 G

0 Z  `! ~) ?+ ~2 m+ `  y+ pNote as well that you can easily detect this method with SoftICE:
3 |$ b& x- A# M* M2 k   bpx Get_DDB if ax==0202 || ax==7a5fh7 {0 n$ _6 r# Y; c

4 v6 z, b) F: Q. o5 `. r__________________________________________________________________________1 y9 x7 b; T7 G9 z8 e  r4 e% h

- j7 r( X) \; h4 N; aMethod 10
' _3 f: u! B' ?( v' v=========
7 {! \1 a7 K& z( D' N/ R" Z. v" ~1 v- k9 I, g/ ], f5 [0 p  G& z
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with/ N3 l- x: B+ w9 |/ m) b+ f/ r
  SoftICE while the option is enable!!; Y# I  A1 e9 T3 X" D6 P+ o

2 Y' c) C1 a9 T/ m# q6 jThis trick is very efficient:
6 n3 W2 K" {" R0 I6 kby checking the Debug Registers, you can detect if SoftICE is loaded. P2 ~! K$ d. t# ^" B% _7 e2 e
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if0 k! A0 r% @% N' c: I9 j- {
there are some memory breakpoints set (dr0 to dr3) simply by reading their5 |' [) }( k  d1 `2 y% C6 t2 `. M
value (in ring0 only). Values can be manipulated and or changed as well
& K% R/ e& h2 z(clearing BPMs for instance)% L6 v  M$ u6 [4 l1 N& J3 r5 {
* p3 L$ k0 R9 X" `  a: M5 }- C  S
__________________________________________________________________________6 w5 A( Q" M8 E. \: G

5 E, m" J( j0 ^1 o* n, g* \Method 11
" N. k/ {# y% Q6 ^=========
3 D+ @, I$ l3 |2 P2 P9 Q; _0 o0 b0 i* e+ W" q) V
This method is most known as 'MeltICE' because it has been freely distributed
6 m# B) @5 x/ i' B' o& Lvia www.winfiles.com. However it was first used by NuMega people to allow
# r/ m  T! K) s$ T2 X+ {0 ySymbol Loader to check if SoftICE was active or not (the code is located
( Q' E# N. t: T' b" T# Pinside nmtrans.dll).
2 L9 t3 u) H7 x9 ?2 ]- w1 \. `& O- q  r. t8 H8 w7 r/ z3 A
The way it works is very simple:
3 L5 B% T7 H" f& X  AIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for) L8 y5 P' e3 G. @0 q
WinNT) with the CreateFileA API.
: F' h& O' {4 f5 r% D
5 J7 o6 x1 c7 a3 R8 b$ `Here is a sample (checking for 'SICE'):/ ?/ }6 g- {" {- k' d* G; i6 h! S

) {. t# @1 x+ Q$ x+ a7 SBOOL IsSoftIce95Loaded()
  D0 w- \" |& c8 p! a% u8 g{% S7 _5 {3 q/ O; B5 S& ^0 l
   HANDLE hFile;  
2 v. o! H* @4 Y4 s- C   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,1 F; D$ K9 F# Z) b9 i  i! e
                      FILE_SHARE_READ | FILE_SHARE_WRITE,7 W+ s1 e" j* C) u4 W
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);9 g, N) W) F) V4 P/ v
   if( hFile != INVALID_HANDLE_VALUE ), N8 U7 d1 a! Q* b1 h
   {
' u- t3 h9 Y3 r0 W      CloseHandle(hFile);3 O3 @1 b6 d; \7 H/ x6 P8 \
      return TRUE;
" \. V' `: z8 M% X' D1 _; l   }
2 N- {1 ?- B! ?  [   return FALSE;9 A  U6 n8 ?. n5 \* J' [7 s& T
}
: M4 E1 {) c* @' g, T% R7 `* Q
8 x- X( E  j% mAlthough this trick calls the CreateFileA function, don't even expect to be1 H+ x7 ~: i1 L$ g# F
able to intercept it by installing a IFS hook: it will not work, no way!1 w( q* Q5 {" Q  B6 v. Y
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
# p! s9 A( D9 q  pservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
( \) P* ]+ M: {and then browse the DDB list until it find the VxD and its DDB_Control_Proc7 \- D: j  k6 f0 E0 {: |! r* O1 j) f$ i
field.7 {' A6 i: P0 b( R7 T/ r5 V9 [
In fact, its purpose is not to load/unload VxDs but only to send a ' v9 M1 u1 g0 f' M. g
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
3 d# d5 K. ^6 B, kto the VxD Control_Dispatch proc (how the hell a shareware soft could try, o6 o* W0 k7 ?9 o
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
- G+ O! T1 T9 _( r9 b8 N$ `If the VxD is loaded, it will always clear eax and the Carry flag to allow( k$ U7 {  Z/ n' A" @
its handle to be opened and then, will be detected.
+ c0 M5 ^  |9 k& V: C. FYou can check that simply by hooking Winice.exe control proc entry point
- g& P) i0 j3 i- h! {* d, }. Rwhile running MeltICE.
/ W3 K: K+ ?; A1 z4 K1 P+ k
' m9 A8 E' R' C! P* O% s8 A* ^) h1 ^2 Y; }2 d5 |* h
  00401067:  push      00402025    ; \\.\SICE
5 i5 t0 F; U. O& M) b  0040106C:  call      CreateFileA3 Q+ v9 p9 l( K$ Z& H  p
  00401071:  cmp       eax,-001' q: g- D5 v0 u: |! D
  00401074:  je        00401091
5 }2 l+ B# z! M" E& b. x1 H
4 C- \6 O" b3 u6 A0 C
' U$ i8 Q& h' C; _There could be hundreds of BPX you could use to detect this trick.% F$ R  ~2 o  N! Z
-The most classical one is:
0 N( p/ `/ Z+ x  G& c( J( R. v  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||7 A0 i1 g6 n' k; Z
    *(esp-&gt;4+4)=='NTIC'
% L. L$ ^& w0 Z: [, K* N+ C' ~# K2 G7 E2 j: p, `7 A
-The most exotic ones (could be very slooooow :-(
* ~9 _( T: ^( `8 E   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
& o% ~4 o6 X$ l8 R2 S. j, z8 e2 b, F, R( T     ;will break 3 times :-(7 @: }+ m0 s* j3 N! N
$ Z: Q! N( @3 ^# j
-or (a bit) faster: / {- A' O' ?1 S4 c* x, I1 b- d- v# }
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')) j1 p6 U' A, w# F
* B0 A% G' B. T* m. ^) a7 L9 o
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  7 O! t) e; V# U: s% W  D* _! o
     ;will break 3 times :-(# m' w) _* [6 P6 r0 g# O; k
9 i7 h, N$ y' l3 X1 e2 i' {
-Much faster:
$ {. }3 p- N# y9 B$ P+ E   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'6 o; }6 Y4 d# }1 P# H/ M$ M
, }2 p0 O. f/ }7 p8 v$ c
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen6 ]  s1 V# v$ n( y
function to do the same job:
7 {% X7 B6 ?* K& N) N0 l$ _2 J$ E$ H* ]3 D+ s/ N
   push    00                        ; OF_READ3 s+ _, g7 q3 _, ]  r
   mov     eax,[00656634]            ; '\\.\SICE',0( o# |7 f: s5 u2 Q
   push    eax
- h) v( ^6 }1 {1 h5 B! C2 N' Z' U   call    KERNEL32!_lopen
# r) I: _$ L! C   inc     eax
3 g( Y% }8 F9 S. r, ?6 ^  L   jnz     00650589                  ; detected& \. Y9 M, }& U( |3 d& Q2 L
   push    00                        ; OF_READ- r* s  ~8 x0 O4 v2 B, A
   mov     eax,[00656638]            ; '\\.\SICE'! s+ J/ c5 C+ z4 g% ?* Y# j
   push    eax
2 J4 e8 ~1 s: p   call    KERNEL32!_lopen
0 H! T; e' F$ _* o3 s& c6 `0 T   inc     eax. z1 X6 Z' g% I2 h' D+ t/ N
   jz      006505ae                  ; not detected  w2 G) }  q% k
1 ?5 X" o/ F' M

' s) \+ m6 Y+ I+ f2 m__________________________________________________________________________5 Z* ~: E, h5 L: \: `  Z+ o

+ c3 i& d6 {9 d* H) ?' q: HMethod 121 T9 U# i( n4 x. ^
=========; S% R0 u* `. Z# n
) Z& R; @+ U  G. A* W5 |( v0 q
This trick is similar to int41h/4fh Debugger installation check (code 05: U! J3 q7 O. S8 ]1 j$ L; m
&amp; 06) but very limited because it's only available for Win95/98 (not NT)- j( _& M) u/ e3 t' ?* Y1 H
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.9 Z! O/ N- q' h0 r9 |* E
6 e( P8 H) u+ e( I$ F2 k
   push  0000004fh         ; function 4fh/ t+ m- E/ t2 Y4 e. S
   push  002a002ah         ; high word specifies which VxD (VWIN32)" l. G1 Q$ b2 V8 D, c
                           ; low word specifies which service5 I+ T% k- d( j; F
                             (VWIN32_Int41Dispatch)
3 ]; N5 Y" o8 J1 P- W+ [$ u   call  Kernel32!ORD_001  ; VxdCall6 k# A8 S1 h9 }+ Y6 H4 K
   cmp   ax, 0f386h        ; magic number returned by system debuggers/ O% U6 X5 ~' y; Y$ P
   jz    SoftICE_detected
- v. o4 J' K- T* F. ^2 U' H$ s9 @" R4 T' w3 o' C
Here again, several ways to detect it:- ^7 ~% E' U; M' ~1 Q& y7 n
; [1 e! K1 }# L# U" j9 D" B
    BPINT 41 if ax==4f
% s2 p; Y  r9 T. O& y% R9 r; ^& {, F9 _
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
% l. r6 v# g9 _7 W" x3 E. O/ _$ {- r. J. C
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
9 K4 G2 Q4 O% j) a
) v9 s9 h# s8 e) Q! Q    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!0 V+ W1 |5 h# Z6 O

; B2 e- X# L4 G7 @2 t9 e__________________________________________________________________________( R4 u3 v  l; b
1 V( W8 E1 T9 j
Method 13
( _  S+ T: h' `$ K1 m6 f=========
! E+ V3 e6 S4 l( B* [- \. u# T
8 h' Y+ V7 Y( ?7 @Not a real method of detection, but a good way to know if SoftICE is
. F% h: J* A: X: y6 r. S( q: Xinstalled on a computer and to locate its installation directory.
/ ?3 B0 k- A' f+ ]7 DIt is used by few softs which access the following registry keys (usually #2) :$ S) o( n7 m4 N# E

+ ?0 j3 H% y5 E+ Z! a9 P-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion8 l2 Q/ _% N. a0 K- ], U6 X0 O
\Uninstall\SoftICE
, h0 k$ m; P3 F7 ?" M# O) C; G0 D6 K/ \-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
8 X  n* u# V0 z1 t7 l# `$ V7 j" W-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion+ A$ p& z/ ?  u7 _$ W. y
\App Paths\Loader32.Exe
( o0 P* n1 C2 k
, b% k, Y7 n& i* Y: h
$ ^* Q& N0 N) N3 d8 }% XNote that some nasty apps could then erase all files from SoftICE directory
* z' n/ K, w8 X9 J1 F(I faced that once :-(: ~  M% {1 ]1 @5 p( [
; E: G7 O+ P: Y; x+ A5 u* m
Useful breakpoint to detect it:
1 b9 y) a/ p+ _" |) n
2 j% t2 d3 P/ V3 k* R/ H2 e2 p     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'5 l9 C3 w, ?+ w6 }* H1 S: ~8 T

9 w4 ?% x1 I  y3 x__________________________________________________________________________
6 `6 n, [& U. Q% i% U& C! z7 N& ~0 v1 n1 F" [: U" Q' p  Q3 J
5 U# R" c2 U* A* j1 ?: d
Method 14 2 G+ i5 G% R0 V/ Q' V
=========' ?5 {" }) Y6 k" g5 D; x
4 R1 y" ~2 O; U5 V% C5 q6 }- S: w  V
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose$ f( H4 I* i% C" Q3 C( _* c- x
is to determines whether a debugger is running on your system (ring0 only).
9 L- S7 j# D% @: l: S( ^* a
4 s: s. Y2 b, U2 u4 N9 u   VMMCall Test_Debug_Installed  J8 ?! u, s8 g+ C) d5 _# X% N: c
   je      not_installed
" [. l7 W% f6 v9 d; k1 }+ K: g7 \+ i$ p$ @* M' k- a$ D2 R
This service just checks a flag.
3 l  p1 y8 F2 k7 @7 t* N7 ^( ~</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部