About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
3 Z; }/ J. \- J6 B  O4 q<TBODY>
0 D/ ^+ m  U/ N; ]- c: W" X# m<TR>
2 d8 c* U$ m8 P! j% x% u9 o3 F9 M<TD><PRE>Method 01
0 c( h& @. Y- x2 X0 R6 Y/ N=========* V. C7 |+ O8 |7 B7 F
, n( C$ q% T7 J3 K
This method of detection of SoftICE (as well as the following one) is
4 y7 d- J& T1 K$ ^4 Tused by the majority of packers/encryptors found on Internet.& S  h$ |3 z- @) f* E
It seeks the signature of BoundsChecker in SoftICE
7 z# m2 O  t! p, h' n
+ I) m3 f: ]8 ^    mov     ebp, 04243484Bh        ; 'BCHK'
  ^/ G3 P: f* i: U    mov     ax, 04h
5 q2 V: A2 E$ R7 Q# X, e! D    int     3       - ^4 _6 ?' q1 l' ^5 Q' v) A
    cmp     al,4
# D/ _4 j2 n, ]/ H* @9 G    jnz     SoftICE_Detected+ t" X$ f0 A! h0 b: Y7 g5 ^. M/ n

& Y5 p7 O! C, P3 G  ]- N1 \& n___________________________________________________________________________6 \# Y3 J% g; g% H& A

: [* P2 O& ~7 GMethod 02
9 G2 T# {* H$ t: K4 K=========
- M9 X/ w- h7 i) y" d( w7 C9 W3 b7 {5 G6 O2 P) H& ~4 a
Still a method very much used (perhaps the most frequent one).  It is used
0 x* {4 Q0 e8 P) ?8 z" vto get SoftICE 'Back Door commands' which gives infos on Breakpoints,7 w( L; w' l; m: R( H( G
or execute SoftICE commands...: j& X2 ^* {% ^6 F+ t# L
It is also used to crash SoftICE and to force it to execute any commands
4 i* ?- T- ^" \/ x, _  r(HBOOT...) :-((  
2 X/ Q9 V' h. i+ Z7 X
9 K& f, q  I+ [( g, Q3 K9 w! a- D6 ?, FHere is a quick description:
2 r7 ~, o9 H" d+ [# s6 M, g+ L' _-AX = 0910h   (Display string in SIce windows)# Z7 Y0 X5 ^0 {# ^( x8 v" y& T
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
" i' E. W. A7 {, C% X- O-AX = 0912h   (Get breakpoint infos)
/ `" {7 j5 M# r8 q-AX = 0913h   (Set Sice breakpoints)6 O9 R: f( O  q1 |
-AX = 0914h   (Remove SIce breakoints)
( j& K! `/ R' U8 D: b$ I
+ S4 d# }. A0 Q1 h& T) P0 tEach time you'll meet this trick, you'll see:" P& _# u& S- z/ W% Y
-SI = 4647h' i, V) E( O# i+ O; i
-DI = 4A4Dh, ?* v8 W1 e* r- e% l" f+ A
Which are the 'magic values' used by SoftIce.
0 N, Q  H) _" O- wFor more informations, see "Ralf Brown Interrupt list" chapter int 03h., E2 V8 L! J9 u5 M2 ]: u
3 j) P% Z. }) r2 M/ D7 m, p& o$ L
Here is one example from the file "Haspinst.exe" which is the dongle HASP+ u$ Y+ Q+ q9 d, i+ u8 i) B1 o
Envelope utility use to protect DOS applications:% `$ u/ g" D- a. g  R" y
) G! ^  m8 n4 F  v

3 ]; V& W* D6 ?: _* T/ q4C19:0095   MOV    AX,0911  ; execute command./ e( t2 `& b& t4 L/ ]
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).4 H) i4 J* t/ x3 x" D; e
4C19:009A   MOV    SI,4647  ; 1st magic value.
; z, ?8 h' E* O: b' I* y1 q4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
' d& Z3 ?, X) B. R& l  P0 d4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
6 W' e) f0 d4 V& u+ a7 z4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute% j# M! {) M( e* T2 f" L
4C19:00A4   INC    CX
8 l5 I' t# }5 u! r4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
& A/ y0 v7 ?! b' O( v7 z' r4 X4C19:00A8   JB     0095     ; 6 different commands.
/ [  M5 ^1 ]9 n6 p3 O' t) ?0 ^4 @4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
% B3 F( o' Z# \0 _$ C, r3 {4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
% K* V+ {2 w# c
3 F8 ^2 \# v, q6 Q- I  MThe program will execute 6 different SIce commands located at ds:dx, which: f2 A8 V9 y5 B$ s" J
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
" v* \- [: h# s4 ]( t
9 `4 H3 {& ~( {' ?- Z9 m, X& v4 L+ O* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
7 H7 T/ ^0 {* K; C- ~- o9 e5 e. Y6 i___________________________________________________________________________
/ K$ ^6 a7 C) m; _2 s9 [1 E! Q  a# h1 U* a) D  _) b2 L

1 W% j/ \, ]6 u  r4 |9 R& Z0 l' yMethod 030 m5 W# [& H! Z" W
=========5 Q( a7 A  m- E
) j, d, b" q) h" x6 m3 T% {  c
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
$ {% Q" M# M* M(API Get entry point)- s# q; V4 m' N# Z7 g  F4 Y, l
        ! d5 L& ]' c9 I3 }) ^5 k5 {, {

! i1 Y. b  w, Y) v3 S* f4 A- s    xor     di,di% Z9 {7 Q  f, n
    mov     es,di/ W$ a0 |& B% A* t% q7 q8 b% }
    mov     ax, 1684h      
! P. E& v0 D" q) j! j9 D+ g2 }    mov     bx, 0202h       ; VxD ID of winice5 k0 t4 y3 F  ]5 L/ n. m. A
    int     2Fh2 V" S' {6 U* k1 B; o2 |
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
( A+ `% Z( l9 I% z# }    add     ax, di
( H% K: ]9 U) t; N4 ^2 ?6 H( g% U! C    test    ax,ax
8 \# r1 S% g# n$ Y2 T* k& `6 J    jnz     SoftICE_Detected
, |4 i" c  j/ `( Q3 P( @
0 L" |* x# W# p, m___________________________________________________________________________( V9 ?  T- W" N2 r' ]* L# b2 K
# q( e6 ^7 Q1 i$ \2 s( N. H
Method 045 F& R8 f9 I0 H* c3 ]$ E  v
=========$ J5 O& J6 V1 g5 X- F- D1 X; n$ f, w3 O

( ^7 g. ]8 `0 ?/ r: I& _Method identical to the preceding one except that it seeks the ID of SoftICE
& q( P; \4 U. \  O: [+ \3 mGFX VxD.; \5 F0 f( P9 |8 D& v

2 p3 k/ d: Z6 f, w! q. j    xor     di,di
; U5 T: e! [5 N. V6 K8 L( s2 [    mov     es,di
9 y: t6 _5 T6 v+ a+ m' T5 J. J3 p    mov     ax, 1684h       2 a3 _2 h$ M; N; L5 k6 w
    mov     bx, 7a5Fh       ; VxD ID of SIWVID0 [. @! ^4 b6 y4 [) ^0 B& q
    int     2fh! g% ]7 X& f2 S: t
    mov     ax, es          ; ES:DI -&gt; VxD API entry point8 y$ H, P. T" G8 E$ y1 p
    add     ax, di3 p: S- @1 K0 s6 |- q
    test    ax,ax6 a+ N$ z/ b* z: a1 q! o: M) _" \
    jnz     SoftICE_Detected. k) ^3 i2 N5 m% r/ b
- {  a1 t- a5 `5 a. |
__________________________________________________________________________+ d& {. @) {+ k* g  {- w. q+ [
. w$ v4 h  i1 @: o4 @
5 o8 _! u2 |1 j0 V" ?+ e0 i% }
Method 05
4 `$ i# x6 _; g# {- ]) b0 ?" s=========
# p, K0 U9 ~8 R. v- F, @, M, o
  M; P! Q5 o" M6 j8 xMethod seeking the 'magic number' 0F386h returned (in ax) by all system* \7 v( u- [1 Z: j% K' z7 i
debugger. It calls the int 41h, function 4Fh.$ o1 ~! _: W; S6 d" [
There are several alternatives.  
  Y- w! T* X4 D" P/ M) k3 g: l4 U0 U0 y# _
The following one is the simplest:) R; S; k( S9 r, T. ~3 p9 C& ]2 Q4 o

# d( i3 s5 w6 {" q2 H3 U    mov     ax,4fh. R  j2 D7 n& l; M2 \% N5 R! z  c
    int     41h; g" R/ n4 P7 h3 Q5 ?* u8 u( ~
    cmp     ax, 0F386
5 y" l" H5 d; B0 P, E" h    jz      SoftICE_detected# I' s4 e+ c- S5 d
! h+ U" [( B2 f3 s. o

% c9 n6 z' ]" ^Next method as well as the following one are 2 examples from Stone's 6 P% f5 _8 }  [
"stn-wid.zip" (www.cracking.net):
3 V# n; K$ ^) m2 \' T# R) A$ h5 J; a5 h  _9 O# N
    mov     bx, cs8 p# }- a2 M, e" W7 y1 |
    lea     dx, int41handler2
' ^2 j# b5 p. Q4 f0 ]$ m* R) q, h    xchg    dx, es:[41h*4]
- }& R! a& n$ G( L% ]3 l    xchg    bx, es:[41h*4+2]; ~0 ~% Z5 {/ A; R! k3 L
    mov     ax,4fh
7 ^, i% J1 W% t+ F6 F1 T    int     41h3 a- m& a# M2 F, _1 {
    xchg    dx, es:[41h*4]
; K" J9 J0 `* j) H3 I# t    xchg    bx, es:[41h*4+2]
/ Q* e9 d: C9 J4 x" x1 A  d0 T    cmp     ax, 0f386h1 X1 s: d3 p' U# E
    jz      SoftICE_detected
7 u" F2 F& H% I/ i' p/ O% i
2 x3 t( ~1 R9 j2 [* Cint41handler2 PROC
  L. N& k# f) t- A/ i* N    iret
$ \' z" L9 S& u  k' A, _1 v5 lint41handler2 ENDP
- d& j; g; n* @6 r& P3 o: q
$ F: u0 I2 x8 w* {$ B* D$ ?% Q* s1 C
2 _7 N7 g( ~5 g+ D_________________________________________________________________________
8 h+ L8 W3 c# w1 M7 e+ e* M. j+ ?& W  V* g& Y0 {3 z# Z
5 q) n& F' i5 m* [+ R: P
Method 06- U1 N& j. [. R2 B  \& ]! b5 Y! l
=========4 v- G2 [& `" T" M
/ T2 ~* Z% t: W* s- H

' U* q2 H$ B4 z5 B1 J7 Z2nd method similar to the preceding one but more difficult to detect:
1 x' C% P# ]$ ]
. z: b+ \& |/ k& O. _1 U3 m
# ?" {) n- S' Gint41handler PROC+ w( z$ n5 p% x2 e- ]& C
    mov     cl,al
6 I. H2 Q9 G! E6 j/ V/ e) D  o    iret
- G% V, W& C0 \8 L7 eint41handler ENDP
) I2 ]# `* A3 B( S3 G' a
" ]8 s6 J1 z, d3 t4 q$ e! `, [* I  n  s+ G% B
    xor     ax,ax
5 b# ~8 T. i9 D+ V4 k- H+ [. I- g& F    mov     es,ax( p7 i7 t2 V# t; {4 {
    mov     bx, cs
" d8 ?  F5 e$ X5 Q! N6 i9 @    lea     dx, int41handler
) _7 b# z+ }, w% d. m    xchg    dx, es:[41h*4]' ~) t/ a! q8 U. Y
    xchg    bx, es:[41h*4+2]$ _; Q7 Q& M% O
    in      al, 40h  @% r. H# W& ?' b/ W* v
    xor     cx,cx
4 Q4 i" f0 m" T- i0 O0 x. n8 I    int     41h
* r5 J8 d1 `7 U2 C- E" ~    xchg    dx, es:[41h*4]  a& S# ]2 {& y  x2 y
    xchg    bx, es:[41h*4+2]( E+ y$ d- _5 i
    cmp     cl,al
; }% p  w$ A/ m, A% l) m$ J  ^, L, _    jnz     SoftICE_detected
4 m4 D. m0 W/ d0 f* X8 |: L6 c; |5 t8 N
_________________________________________________________________________' e) U' s0 E- q, o

7 ?7 {( A" N2 ]+ VMethod 07. K- x1 d  ?' p6 K' V4 p' ^- o5 V
=========
, K" U+ `2 x% J, ]( `; E
; U- _- X; m5 Y- R4 q6 JMethod of detection of the WinICE handler in the int68h (V86)- M2 A+ y$ U: m' C! Y: e
* I5 }5 X- X* ^/ m1 U9 ]
    mov     ah,43h
3 N* ]% O1 f! s8 ~/ R7 i  h    int     68h( p5 v  v" A3 }7 c5 e
    cmp     ax,0F386h7 R' O( G4 Z1 a4 h% `# |- A* F2 \4 h
    jz      SoftICE_Detected9 G  [/ U+ I' L0 Y
) Q/ n/ y/ e% V6 r. Y

9 |/ l$ f$ G/ c. i=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
) v2 Q  i2 W1 l# o' ?   app like this:
% x5 N! e: C: n, |0 k9 n
( ~( U, H% I0 s' Z! w4 U- a   BPX exec_int if ax==688 h, s" E3 N( k- Y
   (function called is located at byte ptr [ebp+1Dh] and client eip is; C' C5 e- K: ^" d1 \% Y! _
   located at [ebp+48h] for 32Bit apps)
; {: A% }/ K! ~__________________________________________________________________________
# o/ u) m9 D, W/ x8 G  t4 u$ w, }: \& P7 @9 ]9 h
' q. p6 I0 X8 {8 v% k( g
Method 08' t8 y/ l: D% G5 |
=========3 J# ?5 F8 I! m5 v% P  U  \

5 x- M# Q" h. Q5 @. K# ZIt is not a method of detection of SoftICE but a possibility to crash the
  T/ `8 A! S0 p6 z7 Lsystem by intercepting int 01h and int 03h and redirecting them to another  @6 G# q5 b) X. ~2 u0 O/ ~
routine.
+ f9 S( X: h' OIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
7 [9 n0 O/ q" A2 i3 Wto the new routine to execute (hangs computer...)
- C# w9 L5 E4 Q2 u: a& M' j
! p. `) p# i: K    mov     ah, 25h1 K" _8 O1 ~0 `( L) Z7 r
    mov     al, Int_Number (01h or 03h)! y* `$ J& g; U# G% b2 e$ r0 c
    mov     dx, offset New_Int_Routine
  D2 X2 }7 D+ _2 w" t% b5 {    int     21h) y) w) q) q# q

$ O, t' d$ X4 k3 O7 a7 c* V$ u* Y__________________________________________________________________________
3 Y! Y& Y4 g4 f! _+ ^! A6 {; P! k  c1 ?6 j% \, Z
Method 090 r& g: M+ Q6 b1 [* ^
=========
( [/ D* a7 L% G9 Y% a. R- P! J& A9 g" Q1 J4 g- |6 c
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
" F0 U0 ]% @& _, F& V. X# D( I! zperformed in ring0 (VxD or a ring3 app using the VxdCall).% o' P3 Z8 Z- z- v1 T
The Get_DDB service is used to determine whether or not a VxD is installed
% A: Q5 y) T# p0 T" G! R& Z  D2 Q' ~for the specified device and returns a Device Description Block (in ecx) for6 E, e# x& d& @9 R* v, M0 l
that device if it is installed.
( r1 s8 F+ B/ O2 r( m9 [+ T8 p/ G( P
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID; A# P% C& M: F
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)0 j/ [! \+ L2 M1 n% j
   VMMCall Get_DDB9 `1 w0 |! S+ G: g) C" @
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed. l- B  j) G0 s3 M% W
- Q7 u/ M' g# M( c+ s, {$ J
Note as well that you can easily detect this method with SoftICE:
6 H0 r4 j  ^5 n) h   bpx Get_DDB if ax==0202 || ax==7a5fh: Z/ t0 o1 M+ @; Z. m
- U) O8 d* C7 g  z9 \
__________________________________________________________________________8 N' Y; a0 f3 k- ?# O0 d) x/ g6 [
+ O8 b/ C( G1 `% R
Method 10! a: ~& n1 r! N* v) F$ F
=========& b9 H) i% C9 c* y4 }& u

: y6 i, [0 K/ C7 q" i- f/ K$ A=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with" u( {4 q' y* {( f; ~' C+ ~3 a7 c
  SoftICE while the option is enable!!
. @. l9 n5 D6 U7 M$ V" ^/ l8 @; R3 k: I8 I8 s
This trick is very efficient:
$ t: ~3 _+ {& i" d- S2 q' rby checking the Debug Registers, you can detect if SoftICE is loaded+ l7 }1 s0 ~8 l: e* t) x
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
# l- c7 G4 _0 ythere are some memory breakpoints set (dr0 to dr3) simply by reading their
5 x- D! u5 q  N0 u6 U  Dvalue (in ring0 only). Values can be manipulated and or changed as well/ {0 F8 Y$ }1 F( x! i; E
(clearing BPMs for instance)
; P7 w  y5 X. A# [0 K6 j6 ~- C; H9 ?
__________________________________________________________________________& M# J% ^  d: W& C& m3 ^. k0 }
. k2 Y, ~( q) r8 a1 h) X* e
Method 110 `) }# p1 F) L' @4 w7 A4 F
=========
5 z9 I0 L8 }( X0 g) X4 V! Z
2 L) e1 i( A% n$ _: ?This method is most known as 'MeltICE' because it has been freely distributed% \2 E8 k3 ^% ]& Z( d' Z+ {" y" n
via www.winfiles.com. However it was first used by NuMega people to allow
) N3 V, Q0 O4 |6 hSymbol Loader to check if SoftICE was active or not (the code is located* b& ~0 S! {% K3 B- E8 m) M+ y+ V
inside nmtrans.dll).
. R- q2 V+ Q& b, V6 |. n
# |; F- A& Y8 P4 N  {5 b& BThe way it works is very simple:" [3 ~2 U9 \" D. Q& e" H/ a8 O
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
) `, N9 R8 }1 r! Q3 q# ~/ u- S( GWinNT) with the CreateFileA API.
, p& L* Z. D, `6 x' Y! S+ ]
% [2 D/ B6 W8 `2 e4 BHere is a sample (checking for 'SICE'):3 T  `2 |' p# ]

# ?- V) t  d, ]. sBOOL IsSoftIce95Loaded()
: ~0 z! o, Q4 }' m6 e0 O$ S{
; B" ?8 x7 x2 Y9 `   HANDLE hFile;  3 }7 t1 D9 N0 T* m7 y0 b9 V
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
, V' A7 o* p" e                      FILE_SHARE_READ | FILE_SHARE_WRITE,$ W8 ^, V; W! f& D5 D( S: ^
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);* r/ [& U6 ]; A0 e- y$ t
   if( hFile != INVALID_HANDLE_VALUE )
: s4 H; T! Z- g0 O4 e' y   {4 W" c8 N! x7 P6 ]  J, ?
      CloseHandle(hFile);* P/ [  E, \: M% {
      return TRUE;/ z: h; G* W% c
   }
6 X) u0 T2 l6 l   return FALSE;7 u& p/ _* }$ z/ I# ?0 s1 @
}
: N$ {* u( ^) `' |
9 e0 o, W- A0 y: ?& N2 \$ ~; y; oAlthough this trick calls the CreateFileA function, don't even expect to be; i! _# Z4 M7 e% L7 J$ z( W
able to intercept it by installing a IFS hook: it will not work, no way!7 b& B6 ]* P  S; q$ Y
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
* |) A& D0 e6 q7 {/ ~service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)3 l8 z0 j- Y% C
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
3 Q, h, Y3 a& c) gfield.7 Z7 i/ e' O7 ^5 I& ^& d
In fact, its purpose is not to load/unload VxDs but only to send a . V6 z" ]8 H. E2 Z& ]& r$ k
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)2 L) x, T  v) L$ ?& D- H
to the VxD Control_Dispatch proc (how the hell a shareware soft could try4 K8 e) j7 s% w/ H
to load/unload a non-dynamically loadable driver such as SoftICE ;-).  M# e: \3 F* l8 _0 {2 I
If the VxD is loaded, it will always clear eax and the Carry flag to allow
. U) \* a# E: c2 g3 u+ [  Lits handle to be opened and then, will be detected.2 p4 Z4 ?2 t2 K4 N* g: Q
You can check that simply by hooking Winice.exe control proc entry point3 E* g# c5 m( e7 a8 v0 _& t
while running MeltICE.1 `) e7 C  f+ S

* P" v1 W0 F- ^5 ~1 d! m4 B: V' ^+ t. r9 s1 S1 j; P
  00401067:  push      00402025    ; \\.\SICE
8 S4 E8 v7 E; ^  0040106C:  call      CreateFileA! E  m- g, q  K7 n
  00401071:  cmp       eax,-0011 P+ g' l' C2 P
  00401074:  je        00401091% s0 u  C. A- s$ ]( J

$ S0 Z3 t0 a! k- E- g$ k0 z/ Q+ C; |7 h
There could be hundreds of BPX you could use to detect this trick.
" s8 I0 i4 l4 e( f/ h+ @8 ~-The most classical one is:
7 E5 ]* ~/ r7 H  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
. ?) Y1 M& D5 W: y0 A0 p) K$ v3 ~! i6 d    *(esp-&gt;4+4)=='NTIC'9 y3 a8 y+ W: I4 q1 r1 z

/ j' z: B2 [7 L# {- A" h3 R-The most exotic ones (could be very slooooow :-(
) S' B( ~9 g; P/ l4 ^7 ^   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
. |+ n4 A( V( p5 q% ?" M  @' B6 ~     ;will break 3 times :-(
( w) [- f8 t* r+ }
8 U1 L$ t3 q6 O2 G9 d-or (a bit) faster: $ S) l9 c8 n3 @5 B3 S: w3 Y5 l/ z# k
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
. r6 L& @5 B7 f' S
6 M4 d: b4 _0 Y! d   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  # A6 Z' g1 q; R4 X8 S0 I9 N! a
     ;will break 3 times :-(
+ n% u) a/ g2 Z1 ~% W8 I, D5 T+ @4 q7 J
-Much faster:
4 P* Q8 |9 R( g* A   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
* T+ ]; B- @" t- F5 M7 g0 y
+ g; k* }( y7 X4 y5 Y0 T6 F3 ?9 |Note also that some programs (like AZPR3.00) use de old 16-bit _lopen/ t) e  c  `: v# }
function to do the same job:
; ?% ^' Y) ~( v, ], @" ]
* g( ]- I5 k5 `4 _2 w   push    00                        ; OF_READ) Y; k; C% f' \9 W; X8 D
   mov     eax,[00656634]            ; '\\.\SICE',07 W. h4 a# s3 W9 l8 l7 @# h+ e
   push    eax% W: I/ }8 Y) l9 S
   call    KERNEL32!_lopen
  u" ?. d/ j# @% |! B   inc     eax& p& ^4 x# `, l' _* ]5 n% s0 D
   jnz     00650589                  ; detected
8 d; y& O7 m) \( G) y9 m$ b   push    00                        ; OF_READ# P+ D. w, Y. j9 X! _3 o
   mov     eax,[00656638]            ; '\\.\SICE'. c8 v" D+ Q( c4 v& t% x' [
   push    eax
" R# J' U  W6 s5 B! R2 [   call    KERNEL32!_lopen
! y( d% q0 t& J  [& N3 l   inc     eax
6 y0 k& l$ Z9 l. m   jz      006505ae                  ; not detected
6 s/ G7 D  t- l2 u; _( C1 N" {2 y* |9 X% f2 `, K' Y% m. \
; q  h! @7 J6 ~0 X
__________________________________________________________________________$ z: l! V& W. z, b2 q2 _3 l& J

/ ~0 R3 E6 X! f7 CMethod 12( c2 E# S$ e) l' h7 L6 r
=========. }6 i+ |2 Q! m3 ?) H1 I

* Y* i: [' V! zThis trick is similar to int41h/4fh Debugger installation check (code 05
; l- `  u4 l' g- o$ @&amp; 06) but very limited because it's only available for Win95/98 (not NT)
" C% k! I: X  g8 Y1 j7 mas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
. C& j) y/ E" a3 e
1 h' @- [. g' E8 L& S5 A) R   push  0000004fh         ; function 4fh
7 f4 V, W& `& r   push  002a002ah         ; high word specifies which VxD (VWIN32)' p4 q+ n" P2 U3 Z, c
                           ; low word specifies which service2 n" V; ^; o% {
                             (VWIN32_Int41Dispatch)" h% w) H0 X1 x, }$ d
   call  Kernel32!ORD_001  ; VxdCall: b% b+ V5 \  k5 Q% H' i9 d9 e
   cmp   ax, 0f386h        ; magic number returned by system debuggers  b; c; h5 t0 c0 {# B6 h  g
   jz    SoftICE_detected  e  E! i1 U% R$ Z5 u* }
9 [# G* ~# h/ A- i+ h! F9 }  ]
Here again, several ways to detect it:
* {1 [3 X6 w% W1 h: H5 F9 i, d1 \- i( f2 h
    BPINT 41 if ax==4f
$ J3 S& L  U2 R# Z  I' S
2 w8 y$ ~# w+ A    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one/ {; L. V+ q& T( j% d9 F

. g& P* u/ s' a7 m' R    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
- H  w7 t/ _6 _: s" c
2 V+ `  `1 \( H. ~; v    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
' ~+ i8 }- x, m* ]" C% O
5 D" F+ r( D+ H__________________________________________________________________________
8 n! o* C% h1 G3 ?3 N) `$ ~. b
6 |- ~: r5 K0 d: \Method 13
( c  {+ @2 @  L=========- |5 e, v7 p4 B* y. S$ J
" f8 m6 ]  B* C* e) s
Not a real method of detection, but a good way to know if SoftICE is4 B, G9 P4 B/ f( [7 A( d) z
installed on a computer and to locate its installation directory.
5 A* y  n2 `/ n7 vIt is used by few softs which access the following registry keys (usually #2) :! g( q% Z% R! l0 O5 ^2 t

8 z. n$ L7 F: v/ o5 C) |6 ^- C-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
- f# p! H% }6 Q) @, c. P8 V\Uninstall\SoftICE3 d: z/ K+ n3 a% c
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE6 A- ~" S" x, n* b8 E, A7 J
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 ]6 ]; b9 S1 ^* w. n. [0 B
\App Paths\Loader32.Exe& a% W$ w. q0 w
) d2 x# l, i% A( o5 p0 s0 @
9 ?+ s' f+ Q6 D
Note that some nasty apps could then erase all files from SoftICE directory
1 j: L* A6 r+ L& W1 ^(I faced that once :-(
! k: \/ ?' a6 h- _$ @( t4 j9 Y9 k* {: ~- w" V+ y
Useful breakpoint to detect it:
. A! h. w$ T# b
8 v! O+ i+ n" d6 `; z" R# a     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
9 a- P, `# y. N' e  b" W7 e
* p. W3 ]$ B* K$ K- v__________________________________________________________________________0 ^4 I& X4 }6 ?
' z  P4 Z/ {  P9 J. ~/ B

/ C- B- b1 ]4 N3 D, f8 z- YMethod 14 1 f+ ^  ^4 G& v1 j% @
=========* H0 {! s  ]+ f! m" b9 [1 n
' n  }! s% s+ L4 }5 s" E- @
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose# a/ x; Y+ e8 x
is to determines whether a debugger is running on your system (ring0 only).1 o! ]! v  p# m1 B
' g7 v7 @8 m3 ?$ X0 {& t
   VMMCall Test_Debug_Installed% G6 I5 Z# T' Y8 e
   je      not_installed
- m& x" o4 F6 Y0 G, I
3 E5 t# h5 X9 x8 B& `9 w$ VThis service just checks a flag.
/ ?8 R4 |) G$ R</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部