About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>$ v5 x1 U* T: k6 \) A; V2 I
<TBODY>% P" i8 [2 Z: w0 l
<TR>9 ~# o/ N& y& K
<TD><PRE>Method 01
6 N0 E4 J% e% y# |( V2 U! _7 S=========  [* r/ X; F) B" [) \) D

$ L8 I: ]4 G' a3 Q3 BThis method of detection of SoftICE (as well as the following one) is
- ^+ S9 p. ?. @0 r& q; i$ c; lused by the majority of packers/encryptors found on Internet.. k  T, ?6 F3 e- f2 I$ M
It seeks the signature of BoundsChecker in SoftICE
% [- L: u* [) Q9 Z0 @, t
( F  Z. q7 K1 d    mov     ebp, 04243484Bh        ; 'BCHK'3 {( V$ ]: C. ?+ {4 ~2 j% X
    mov     ax, 04h
/ @( u. _6 N' `    int     3       * l5 f! B2 H! `' f! Z) x
    cmp     al,4
* R- q' @0 H6 g& O4 a    jnz     SoftICE_Detected
4 v6 R# R5 n4 o% }* N7 [5 ^* q! B" j. f
___________________________________________________________________________1 o3 T( e% e, `  x

' Y7 D) u/ U6 N4 p) W/ q! M* _  h* D* \: oMethod 028 s6 L: o& u2 B- ^0 T6 S  u
=========# U1 b, W4 w/ m8 y- N( |- L

9 ?+ l6 ~$ y2 }: GStill a method very much used (perhaps the most frequent one).  It is used
% V- G1 H" I4 |/ ^) E. [+ hto get SoftICE 'Back Door commands' which gives infos on Breakpoints,+ i. y! @1 ~1 \) y& u# N$ B
or execute SoftICE commands...
) N" m. {( ^5 I7 K" Y( ^It is also used to crash SoftICE and to force it to execute any commands) ~% @1 J; z$ H5 O
(HBOOT...) :-((  
" p! h9 U* S! o/ i3 G/ T
/ D! n7 Z; C0 \2 J+ tHere is a quick description:
  c" D7 t9 [. q/ i2 \-AX = 0910h   (Display string in SIce windows)
" M8 {8 B: c8 o$ \- T" s-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
1 }0 r' `$ Y/ {9 e8 J# C$ J5 E-AX = 0912h   (Get breakpoint infos)
7 G/ V: h% D* J7 [-AX = 0913h   (Set Sice breakpoints)
8 I8 F; @9 k7 ?2 B  f  ^-AX = 0914h   (Remove SIce breakoints)  }2 }" @6 c8 @  T* H

3 t& o6 o8 b$ y" c+ [Each time you'll meet this trick, you'll see:
0 x3 M" }7 Y4 ]( i7 u. f-SI = 4647h
( @. w  K$ {% q* x-DI = 4A4Dh+ I' e, s: A3 }5 N+ B# o) e
Which are the 'magic values' used by SoftIce.6 U  l+ u' I) ~7 T5 S
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
3 j  G8 l' M) j5 }  a2 ^4 E; o' u" P2 N3 i4 d
Here is one example from the file "Haspinst.exe" which is the dongle HASP
3 O" L/ M* Y( Y& J3 g+ G" YEnvelope utility use to protect DOS applications:% j0 q" _$ s; ~6 _

3 e. ~& R" F# B2 A7 S/ j+ D' b' G( R$ @% ]( ~* D( W6 B2 y5 z
4C19:0095   MOV    AX,0911  ; execute command.
1 z# E* T0 J9 a6 W4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
3 l# W1 H3 u. o8 g' K) p7 v; U2 X( C4C19:009A   MOV    SI,4647  ; 1st magic value.
. k2 ^! y3 F- R' F5 i# S4C19:009D   MOV    DI,4A4D  ; 2nd magic value.- _6 X0 z+ f1 y0 c
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
' {  F0 |( t& j" x: J  c: e$ ]  r5 T0 L4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
! J' j" m& X) c9 l+ F+ F( h4C19:00A4   INC    CX
! N5 V& W6 L; D3 c4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
. B; a7 z0 [" U' b" V( C8 j4C19:00A8   JB     0095     ; 6 different commands.
: ~  W& T0 O% b0 M; x% m( Z4C19:00AA   JMP    0002     ; Bad_Guy jmp back.& w) I- t: ~: Q
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
3 N+ Y8 }- v7 F" ~. @6 {  e/ J- Q3 G5 ]$ `# ]* q5 z: q
The program will execute 6 different SIce commands located at ds:dx, which
* W8 m8 E6 k2 D; s# [are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
6 A6 S4 D. C' i" `7 E
2 B0 E2 W/ P7 K; l. \9 l* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
. j1 s2 }! k: z9 b# {0 q% U+ ]% C. ~___________________________________________________________________________
/ {5 V* t5 _2 P/ Q5 B( F0 f- r, O+ I/ {9 h
$ c; y6 ~7 w; N; \* M, F
Method 03" M: @3 v0 N) o, m2 h$ m7 s
=========! Q' \# p$ S5 w; R5 b- y$ M

* n5 _; h. L& r1 E7 T) [( Q! ]Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h$ E8 u  D% Y; M- [* v" @, k
(API Get entry point): n( r- N; Q3 C" ^
        
+ `2 Q- R. e+ }: I0 {7 U0 t# H* e' @6 x: m; b) ~& o- f& B
    xor     di,di$ d7 o, A2 ?8 u
    mov     es,di
( \; h& {5 G& N9 E, ?/ R    mov     ax, 1684h      
4 S( I  d) g* K- M; C3 ^    mov     bx, 0202h       ; VxD ID of winice% a) I. y0 N3 H+ ~( L: k9 Y7 q0 B
    int     2Fh* [; Q. m5 s" V9 D' M. X
    mov     ax, es          ; ES:DI -&gt; VxD API entry point9 K3 ?6 G$ x" i. T+ e
    add     ax, di
& q0 O6 ^' F2 O2 j% q# q( c" k: o    test    ax,ax6 t9 M" H  \' |- k! s
    jnz     SoftICE_Detected
% D0 M& q% X& d! X- H1 x0 \% z' n9 \( ^( i3 e4 g, J
___________________________________________________________________________1 z4 ?: g, l+ l
2 z( w8 N  o. K! l0 _
Method 04
" W' Y3 k5 D& A  p7 k=========
7 T$ T4 ^0 ?% ]3 {! ~2 Z+ [& `4 B! e% i6 ?( a) N! G3 C
Method identical to the preceding one except that it seeks the ID of SoftICE
4 ^/ J4 b; q6 G6 JGFX VxD.3 ]4 ]0 t4 z, r
3 m# G1 R( n  o  S; R
    xor     di,di! k3 C+ Y  d; R1 ~1 w2 e
    mov     es,di3 [6 ?2 u7 K& ?; z* V0 W
    mov     ax, 1684h       # _% R2 O- k: \7 G- ]8 u1 z! x
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
. l# C3 ^  P" }0 w' m# _    int     2fh: x4 I  K% Z4 H$ i& G& p
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
( r2 B  M" k. v4 g- [, Y9 B    add     ax, di5 ?+ O. J! N% t) Q# I1 P. Y; x
    test    ax,ax, Y) @' m5 ?  {7 r) r
    jnz     SoftICE_Detected. b1 U& h5 j$ `% Y

7 E$ {" o! Q. Y  V4 b__________________________________________________________________________
' u% q$ h7 z5 m7 B1 `& e) p  [) O5 F; Z& p8 N
* e3 e3 R4 c& E' [7 n
Method 05) Q" ?# I, v& L( u4 _+ q$ ~8 u
=========
; O" s2 _2 v9 `
9 F. L: _; Z! s. F9 D- S" c' c; `6 mMethod seeking the 'magic number' 0F386h returned (in ax) by all system8 l: Z$ r" d* q8 I
debugger. It calls the int 41h, function 4Fh.$ j4 V* {: d; y
There are several alternatives.  5 S8 R" E& {- J* W: E: u" z

7 P/ G  k$ g- e0 MThe following one is the simplest:+ A7 p7 ~* g: J$ v
9 e8 C; s) L8 o; p
    mov     ax,4fh7 {& U0 c4 o3 ?6 G# a
    int     41h
2 _8 y! \; ?8 t' A1 {- W9 F    cmp     ax, 0F386  d% v, o+ m  E  V9 y! S7 ]
    jz      SoftICE_detected- ~/ @8 \+ o+ a3 }2 R. S. M# T
! I9 U+ ~3 b7 O& s  g" a
. i# d' G# R0 q1 S! V( L& Q
Next method as well as the following one are 2 examples from Stone's
0 @2 g2 S9 @3 {% b' \+ }3 s1 I"stn-wid.zip" (www.cracking.net):& a* T7 O* d3 f& ~/ E% B/ W9 D/ E
# ^" E) I7 ^% R2 Q. d% D
    mov     bx, cs% T5 P& ~) X+ U* m
    lea     dx, int41handler2, Y9 {: N6 H/ z: |" P
    xchg    dx, es:[41h*4]
$ P. s: s# `. i" B# p  B    xchg    bx, es:[41h*4+2]/ r7 r* |+ L8 p3 h
    mov     ax,4fh
- B& }' o$ F' u: O7 ~( ?6 x    int     41h
, r" y9 M' P6 c, g! v: V/ c    xchg    dx, es:[41h*4]
5 d* W; o) ]8 ?/ F3 X# V+ a7 p    xchg    bx, es:[41h*4+2]( w; D6 ]$ `- C+ v0 \
    cmp     ax, 0f386h3 J7 t  I5 ?1 N& X9 h: a
    jz      SoftICE_detected. h, s6 v8 p# f) c
. s' v5 _* Q- i$ V+ f' V0 X, @( W$ q2 ]
int41handler2 PROC: x& U: [9 W! G- f7 V" Z- H
    iret
$ g; q1 \& y: z) Y* {% [# ?* Xint41handler2 ENDP4 ], O3 t2 X. r

  D; Y7 x; \" p9 W9 w8 `0 X- G; `7 q4 Y; ]" k/ J; Q
_________________________________________________________________________3 H& ]: D; I  m" A$ U
; |. E$ d5 R2 S0 p8 h& j$ @
* ?& \  A* d, b; |/ \
Method 065 `& Y- r) A9 _& P  p
=========
$ y* y  K* I6 o0 {" C
2 n: t4 Q3 b% Z7 ?& B/ @
, C( U) l0 \  l) J* I  }" \2nd method similar to the preceding one but more difficult to detect:/ w! V9 K% x- G

; b6 ^+ C; e* ~4 T) p3 q
" B% b4 D& U5 H7 D7 b, [int41handler PROC4 u1 e- k/ l3 _  _  d6 Q0 r: o' R
    mov     cl,al; j0 d  z+ c+ V' ^% S, N+ E
    iret
; ]6 P) P4 i/ R; z, gint41handler ENDP
6 H7 s8 @- ^  g4 T8 m, L3 i! V4 t/ }$ ?7 Y5 a( ~1 J* h
" F! i8 g+ k; |& Y3 C
    xor     ax,ax
, j6 q3 s( R0 z5 r' T6 `    mov     es,ax
5 Y. H2 D" w% b+ o8 H    mov     bx, cs- F8 P$ o; N2 y
    lea     dx, int41handler
& j( d/ t. q& |; s    xchg    dx, es:[41h*4]
* T5 B( l$ F4 I    xchg    bx, es:[41h*4+2]/ o4 v. ^4 C5 y9 Q& z
    in      al, 40h
9 J; U4 x, J4 @# R    xor     cx,cx
7 y! l% S. ]: ?0 R9 ?. ^    int     41h" o5 K; K1 a4 c, C( @* P/ X
    xchg    dx, es:[41h*4]
5 \$ Q. E8 W9 j7 I: P% `    xchg    bx, es:[41h*4+2]+ d7 C* q2 l2 h/ e9 f# d
    cmp     cl,al9 v& b4 J5 W* T3 m+ L) }1 L
    jnz     SoftICE_detected
- b2 k  O: J8 q0 t, g1 K& E
7 I& j# p+ w. W6 j8 V: I5 x& v_________________________________________________________________________
. J  M+ R0 ~- O/ Z4 j
9 W% t3 Y1 a1 p& t3 y3 H- f& FMethod 07
$ n; Q' U& H% ]3 M  m! I/ s=========
7 B8 k# v4 \$ K5 k
/ [- [# f. e, i. I1 _0 sMethod of detection of the WinICE handler in the int68h (V86)
1 g2 C0 Y$ v7 a& S) o% d
% m/ O3 i) t3 v' h    mov     ah,43h9 f* \0 b* a/ T2 U! M* {
    int     68h7 f: N0 j( w% A: g( x
    cmp     ax,0F386h! ]; P  U+ A# l8 x
    jz      SoftICE_Detected
6 d, A5 |# u8 e/ y; W6 T: E3 ?- {0 W, r

. Y! ~% F/ j4 |. }, U/ [. ^=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
! J: a$ a$ m8 S- b. q3 }   app like this:) K4 K# ~( C6 Y9 D5 M* X

6 K' n1 L5 p  m8 v   BPX exec_int if ax==68( Z* \+ F! f" @
   (function called is located at byte ptr [ebp+1Dh] and client eip is
: U- D* I" f( G. ?( U   located at [ebp+48h] for 32Bit apps)
  g: g# K$ ]8 q+ G__________________________________________________________________________0 ~, d* K0 B( v! a, m
& \& B! B- _7 K' z1 m5 g, j
3 D" f) [" p& f8 S/ w
Method 08" X: ]7 N+ b& k8 g/ |4 h
=========9 c) p- v( B5 B3 Z6 r

. P' Z6 s' l; I  GIt is not a method of detection of SoftICE but a possibility to crash the0 Z: ~* y4 V- Y1 W8 @/ K
system by intercepting int 01h and int 03h and redirecting them to another! j3 V) z; R: V8 b. k
routine.
7 ^" G# f2 ~) c0 w5 Y. g+ ZIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points$ W' X5 K+ _) Y" N# U1 T2 r* J
to the new routine to execute (hangs computer...)0 e+ Y. O5 `, n4 N% T/ K

# G+ a  B1 C+ z1 n1 d7 b) U    mov     ah, 25h+ I' h" d! i6 g# p
    mov     al, Int_Number (01h or 03h)
6 q2 ~! f: |9 c8 w    mov     dx, offset New_Int_Routine9 l' t" X5 p4 b2 r4 o2 s- v% t
    int     21h
# c5 }( s) O0 X- ]" b& i) b& t2 z9 o: P9 Y- e' k5 T
__________________________________________________________________________1 i8 }  a: m! Z
9 k/ ?" O. M! u/ Z6 o' x
Method 09$ G) Q& C- x) @* x
=========+ L( @; T$ I5 X! d/ D+ f, R9 O
4 Y9 v. T9 X+ |5 Y
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only3 S& c( J" f# \! X# @$ C+ M, P' e
performed in ring0 (VxD or a ring3 app using the VxdCall).8 B9 l6 `) v3 r7 W2 t
The Get_DDB service is used to determine whether or not a VxD is installed
1 r0 N+ q+ j, Y) b/ K6 f/ i. jfor the specified device and returns a Device Description Block (in ecx) for
4 i- E$ I  W: Q8 ]. W) }% ^that device if it is installed.6 \: A0 y- ?( M, i3 }% g+ L8 W
% B/ l* T, |. Q4 I5 F
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID# d9 ~7 G! I# W
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)4 o! B* ^7 u# d. |; C+ t
   VMMCall Get_DDB
6 n, g. ~/ X: h+ U+ l   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed6 X* O1 m  P3 [6 X2 s5 B! J5 l# _) c

2 U. D8 g3 A6 ?$ I; n; |# ENote as well that you can easily detect this method with SoftICE:! L4 ?6 i" }2 r* @: v+ F
   bpx Get_DDB if ax==0202 || ax==7a5fh, j, t' t2 E, f+ @9 D

, R' n  u6 h# M& t__________________________________________________________________________5 T( c7 l0 ~3 s/ B' I

/ x- G6 Z$ \3 D- ^Method 10
& o, S  g7 t% D' @( o3 c6 t4 i4 r=========/ j! i. U7 N. b) L8 ~6 c$ C, ?/ B3 K' U

: Z2 N9 ^1 e- P" F3 z1 I& y5 {=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
+ ~# D) s: b; Z3 I, k  SoftICE while the option is enable!!
2 a  t7 ^( a& a# @& G3 i9 @) j6 D% W1 |7 j+ h# ^
This trick is very efficient:
$ ]( }2 Y# i' t1 H; k1 nby checking the Debug Registers, you can detect if SoftICE is loaded1 C# h/ E9 ?( w+ U7 E( e' S
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if. s5 l, ?) w/ p) K* l. I3 N
there are some memory breakpoints set (dr0 to dr3) simply by reading their
7 ]3 M2 E3 M$ J5 Ivalue (in ring0 only). Values can be manipulated and or changed as well
# p- [0 o1 u. F; @(clearing BPMs for instance)2 `& D# h( _7 d* n9 y) e/ d, _

0 G3 E- k- x. u__________________________________________________________________________
' @2 d# T: M3 D2 w2 I
8 f9 C  F& E6 E$ I: Y3 t, ~Method 112 e/ ?9 u8 ]+ w1 U% X* C/ M
=========
! X2 _/ P. Q# E- C" e$ e. K+ U( O4 }8 F: V( m, b. d
This method is most known as 'MeltICE' because it has been freely distributed! v3 f$ Y0 `$ c' D2 O. j) |+ ^
via www.winfiles.com. However it was first used by NuMega people to allow( v7 ^, g' |- W5 @& ^1 ]
Symbol Loader to check if SoftICE was active or not (the code is located
6 b- N* Q( i3 m$ s* linside nmtrans.dll).1 g" n4 T# a' Q. v2 b; f4 y
, ]' e; Z  a, i  S
The way it works is very simple:
1 n3 A9 G- C9 W, g- h" mIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
/ g) Y( |' r; ?0 I% V' kWinNT) with the CreateFileA API.9 `, v0 t, D- r, A, \+ Y" {

) K/ {3 A+ I: N- A$ zHere is a sample (checking for 'SICE'):
2 Z4 Z, s1 {- `0 {6 W+ M0 ?) G! Q6 Q& x/ j1 }
BOOL IsSoftIce95Loaded()
, P/ L' k% n9 |/ t6 Z/ e7 p" x{
0 E; I2 m( O+ Q+ |' Z; d3 o8 e# Z   HANDLE hFile;  % h3 x9 Y+ v% q
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,$ c# W: i* |! j$ t' x: N% J; O
                      FILE_SHARE_READ | FILE_SHARE_WRITE,5 I) b5 L$ P1 A2 S( j
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);4 r' E" Y0 |3 z" t( `3 z6 w4 J
   if( hFile != INVALID_HANDLE_VALUE )' u* O% ^7 }# u1 |
   {
2 Z4 u. n% w+ f) u0 \$ ]      CloseHandle(hFile);4 Y% o9 J& j* h- C, a1 h: M2 F
      return TRUE;
2 ?; \$ k2 \% ~$ |   }$ w: c' h9 v2 L6 a/ R9 _5 C
   return FALSE;
$ q# ]! L' M" z}
" Z" r$ J& Y- x
- E7 H; G9 Z1 t- \6 R7 u7 ^/ L% o8 KAlthough this trick calls the CreateFileA function, don't even expect to be# h; x# x  M9 I
able to intercept it by installing a IFS hook: it will not work, no way!
" A" w: P# A: bIn fact, after the call to CreateFileA it will get through VWIN32 0x001F5 G' S2 R# W9 m( ^
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
3 C4 x; H1 _2 a1 i7 G$ [and then browse the DDB list until it find the VxD and its DDB_Control_Proc7 A# Z- H* \4 L, u& E1 e& l) Y" X
field.3 h  a# J& j( h; }
In fact, its purpose is not to load/unload VxDs but only to send a , x/ [3 H) c7 N8 t6 m) k0 [  N
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)2 ?& ^+ V, A8 ^
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
; @3 R9 \2 X$ r: a) H4 X; X, cto load/unload a non-dynamically loadable driver such as SoftICE ;-).
& X! g9 y0 g! p2 W; c, |6 a0 n' t  ZIf the VxD is loaded, it will always clear eax and the Carry flag to allow! A4 e- t, G1 z* t8 ~& P4 `
its handle to be opened and then, will be detected.5 V+ k2 k& N$ ^% h! s  L
You can check that simply by hooking Winice.exe control proc entry point
. z: O6 v3 j" ~" pwhile running MeltICE.! E; u! v' R3 ^& R1 q/ Z

1 N7 D& N6 t8 j' Q- E# B' S& H9 }
8 Q1 S0 g; O9 F" y  00401067:  push      00402025    ; \\.\SICE
: t2 Q! N- X0 _& R. K. q1 J  0040106C:  call      CreateFileA
+ b) G5 z2 B$ O! [/ ~& Z$ z$ o  00401071:  cmp       eax,-001* N- e1 ~0 l0 W
  00401074:  je        00401091
, o& L2 C! I$ N# y7 v5 f' b3 F
( q0 J. J  S$ A. Z* t; n. l
9 G1 o$ \2 Y; xThere could be hundreds of BPX you could use to detect this trick.
3 X& K  }& s5 Q' Y8 E& B-The most classical one is:
7 S, g8 S( o9 P3 `8 G  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||5 v" t  y/ r* e: p2 N
    *(esp-&gt;4+4)=='NTIC'
/ m& ?* \8 ~7 }% \. \8 n) {
2 `; \1 F. s' D7 n+ Y& Y4 M/ V-The most exotic ones (could be very slooooow :-(
- l7 \! @8 {. s) L8 U# f0 D5 C   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
  E% L4 Z+ a+ b' _; t0 F     ;will break 3 times :-(6 F% h3 T/ E& a' P$ z* g# a
8 p' C  r5 F- e" n! v: G
-or (a bit) faster: 2 K, V, E/ u/ x. F! j3 V" B7 B: V
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
% t# Y: z( Q# M$ u3 }
* \/ \7 n4 \6 m5 J: o( T1 x" }   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
% ?* H$ @; _" C# p) |1 G1 h$ o     ;will break 3 times :-(
& W# n  X9 F5 s& |% T" m4 }
: j  g: M; A; p1 c/ w-Much faster:
( S  }0 ~& F4 a+ x, Y   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
6 I5 d" C* \$ n4 l% F" q# ]
: h; @9 ~2 y& T& }) Z( p0 XNote also that some programs (like AZPR3.00) use de old 16-bit _lopen0 H( B! b" B  {/ ~1 ^' E9 d
function to do the same job:
4 }# e( @( C/ [" _4 x  _  d4 `* h" Q1 D4 z: R7 O
   push    00                        ; OF_READ4 x3 C" i! |9 [, P9 g3 \' U
   mov     eax,[00656634]            ; '\\.\SICE',0
& Q" m3 ~3 d* v5 p   push    eax8 n2 W' G, W1 P9 K  p* X
   call    KERNEL32!_lopen* v- R  z1 O& b$ f( P0 ]
   inc     eax
  c+ R+ h5 {- \0 }  g6 K  z, D, ?) R   jnz     00650589                  ; detected
6 t4 w; ^  Y: o   push    00                        ; OF_READ
, q1 ]" @& b4 _5 j0 x0 `   mov     eax,[00656638]            ; '\\.\SICE'5 M/ m1 M# }6 Y1 _6 O' ]3 f
   push    eax
' X5 {& _# a" e, r. y3 X   call    KERNEL32!_lopen0 Z- E( ?7 B) v! E# k) t8 Q
   inc     eax
* w  F6 n; _% T, \   jz      006505ae                  ; not detected
8 d! ~: h* a' c
5 Q$ w' \% Y( E1 k9 ~1 S* p
5 Z+ J. |! ~: E- }5 ___________________________________________________________________________
- r& r& O; D& B. s0 Q9 _9 v/ P% t7 t1 c$ o
Method 12
7 r, V! \& ~* T=========
: C  b( g5 N) T' \4 B: V9 a9 e4 A: \5 s0 v2 G8 l
This trick is similar to int41h/4fh Debugger installation check (code 05
7 f/ N" P! g" d&amp; 06) but very limited because it's only available for Win95/98 (not NT)
3 X2 p/ j2 v. jas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
) I3 X+ W, y6 J5 J7 a( {' [$ ^  z% n5 P  K- Q" I/ \, T
   push  0000004fh         ; function 4fh+ }, [/ t  P, i+ L" O" F
   push  002a002ah         ; high word specifies which VxD (VWIN32), [& I: {# ^6 X2 `
                           ; low word specifies which service
2 y& u+ R. v/ y5 h6 o                             (VWIN32_Int41Dispatch)
0 V: @$ [9 ]7 r6 H+ q8 j' o( j   call  Kernel32!ORD_001  ; VxdCall, @& o5 Y- e3 r5 f2 t
   cmp   ax, 0f386h        ; magic number returned by system debuggers9 B4 w- d7 T" m1 C8 e" K
   jz    SoftICE_detected- ^, d6 F0 u" i' a: a/ g2 F

/ g( O, m$ r2 ]$ i# RHere again, several ways to detect it:9 |3 T& |' ~" `+ z1 M
$ t* [7 m7 `6 ]3 G. S
    BPINT 41 if ax==4f
0 A; Z$ U! W: }" S5 o4 d9 x  F, v1 a  P
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
) G/ X/ z3 a/ C0 l1 S  J3 t2 |/ h/ _  t) }
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A9 u. D$ x* A- r. e3 S/ w
) Q2 P' `( j, Q6 }" q3 w6 D
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!" C; W4 H. f- K& [: O. r

" w5 ^  _* P- B6 w__________________________________________________________________________
' W- K5 y8 \, U; U6 O4 R2 W7 F3 ]* ~2 k) y
Method 137 H& N* m, _9 J  ]
=========$ J- L) J) @  G* I1 w; j
; Z% ?: S: x0 k( q5 c
Not a real method of detection, but a good way to know if SoftICE is& w4 N0 }6 w0 l( Q7 d% D5 D% _
installed on a computer and to locate its installation directory.
( @6 o& @: S9 H0 @$ w" f5 l  y2 qIt is used by few softs which access the following registry keys (usually #2) :6 v5 {6 T! E2 r+ \

+ O4 `' e/ O6 ^1 |# @-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion/ `# q' _& P3 _7 L6 X2 x
\Uninstall\SoftICE
' [' p; c9 q( t" r5 i6 l-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- O; {5 E) e( U% W  l' ?$ `-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion! P8 ~/ x9 F# b+ M+ y# ~) Z5 m
\App Paths\Loader32.Exe
; J1 N2 O. U6 j) d- G1 b% ?* L& E0 H7 x; m: b

, C" z0 H4 _+ lNote that some nasty apps could then erase all files from SoftICE directory- Y. S) S: o/ R
(I faced that once :-(
' s) Z+ r! u/ X+ D2 E
1 n! ~  R5 Q7 Q; TUseful breakpoint to detect it:6 ~5 Z" M- P' x6 j9 w" D

7 F" ^- l* O! E     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
: ~2 _. p8 F6 `, M  j0 C* E
! n! T# C8 t8 {__________________________________________________________________________! s0 ]4 ^9 J  ?; S# Z; |

/ g# C0 ^7 }! X" k8 a0 z/ a" `; L' B1 [2 S* S
Method 14 4 X+ ]! ~# t4 s; R+ u6 S- p
=========4 Q: {/ K6 K! j8 L
! I9 k2 ?4 M1 E+ K
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose0 v8 O" p6 p5 N6 k/ A# t$ K
is to determines whether a debugger is running on your system (ring0 only).
( t( z4 \* }9 X5 Z3 E7 \; E& U0 A& G6 ]: d; Y
   VMMCall Test_Debug_Installed
  Y5 A! P; ]& E   je      not_installed" F  j4 e. E" g, R

8 j( q9 N1 }' }# z& W* O+ oThis service just checks a flag.
! z; Q0 C6 m- y( [</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部