About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
4 Q' {, H+ m) ?& q9 n5 q8 @/ [<TBODY>' l4 J: i  [  z% y
<TR>" _+ H' I  d( _* p; v" O' x
<TD><PRE>Method 01 4 d9 ?' ]4 c% l2 q  z/ {
=========8 O; R% E9 R0 Y' b4 P) ?5 I5 v
6 j; Y6 P" X' {' X7 t  z/ e
This method of detection of SoftICE (as well as the following one) is2 w- L1 A5 j, Y, ~6 t$ ], u5 y
used by the majority of packers/encryptors found on Internet.
1 W$ k$ k1 }- \4 o" u8 NIt seeks the signature of BoundsChecker in SoftICE$ X* s7 c7 K) F+ Q6 [6 Z* M

3 X) j! n" X' T4 U' F2 _    mov     ebp, 04243484Bh        ; 'BCHK'* C8 f& u, x( T4 ]. w
    mov     ax, 04h
& p% V7 c( w' A, @! Q4 |" t    int     3      
  g, ^: t  M5 ~. O& B( m    cmp     al,4
, b1 N2 @/ k  k4 f0 v" b    jnz     SoftICE_Detected
6 b& i/ w0 @- B" W) e" h0 D; c
) Y3 ~2 U$ O- [* u" J! Q, Y, S* l, w- w___________________________________________________________________________
: M* j3 ^) i0 n& {% B6 a
- o- p0 J& q4 L, n: H# ?, HMethod 02' s( H0 w$ m4 o  K, a7 Q
=========. h+ J+ z. @) G$ V, n4 T* F
2 M& t% ]' K9 t# y9 I% c  a
Still a method very much used (perhaps the most frequent one).  It is used
+ \; B+ L5 R4 r# {! s. W$ zto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
' K" s* B* A; Wor execute SoftICE commands...
9 E" c& h2 c# b# C, sIt is also used to crash SoftICE and to force it to execute any commands
( `- D& {3 J: T8 v# y% q+ u(HBOOT...) :-((  
1 n8 j, g6 i; \0 L9 R
4 F- I# a, D& MHere is a quick description:
- S. x4 T1 J' ?-AX = 0910h   (Display string in SIce windows)
8 H7 S2 Z, g2 n5 g% }-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
3 b% N( i# Z6 J) G" L- i2 X-AX = 0912h   (Get breakpoint infos)
( }! w% H' |6 y. ?. G, [4 S-AX = 0913h   (Set Sice breakpoints)
2 ~6 ^/ I9 O- Z/ y-AX = 0914h   (Remove SIce breakoints): @! Z9 k, L% A. _; V" X
6 C+ a. {- _3 Q1 Y5 p% s; X
Each time you'll meet this trick, you'll see:
5 o+ w+ w2 y9 ~4 m+ A-SI = 4647h1 p0 b/ [3 l5 I- q0 \* c
-DI = 4A4Dh
0 w! y1 s5 W+ v! M: }8 n0 f0 [Which are the 'magic values' used by SoftIce.
. Z* w; r- F# ?9 Q) pFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
$ K6 x+ t/ U0 O0 V2 c% u6 {* _* Y# X( D1 Q" B
Here is one example from the file "Haspinst.exe" which is the dongle HASP. _6 b. F  o8 |& f/ ?
Envelope utility use to protect DOS applications:2 J& X) B; w  E6 J
$ X$ w( T  E+ G5 i
  W/ [1 t; I! C: ~
4C19:0095   MOV    AX,0911  ; execute command.! H" A- k! V1 Q2 X7 b* t  S( H* D
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).: C  q6 g. m/ }+ e/ f4 m+ s
4C19:009A   MOV    SI,4647  ; 1st magic value.
# p2 Y2 A: T1 j! N. p/ N4C19:009D   MOV    DI,4A4D  ; 2nd magic value.2 s( L1 v9 D! r: }
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)& e  r( A2 i/ q; r* w
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
& B# {0 b$ r9 `5 S% w0 N0 l4C19:00A4   INC    CX  l! c5 A9 l7 f4 V
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute: a+ f% c: e9 ]% d7 X, c
4C19:00A8   JB     0095     ; 6 different commands.( V4 [" r2 v2 W! @1 J
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
' |' x( }* M, L  O; x4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
$ D+ [1 y* q$ w% X6 v- H" Q' f7 d" U# e4 ^# O/ m! k9 D# `
The program will execute 6 different SIce commands located at ds:dx, which
) R& F" ^) s% D7 ^! j; Vare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.+ j0 u1 B: h/ P6 o  U. M

) D  }1 m+ Q* e* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
- P+ ]0 N3 @7 F1 j; r) g; H___________________________________________________________________________; A* a: C; ~" d6 }1 B3 ~$ _. s8 A

5 c4 o) @6 P! K$ T8 `% c" H! I% K) V5 L2 E. o) Q+ h' \: q7 j& T% e1 F$ S
Method 03
* `" i$ L. u1 L=========% X% x/ e5 H, _: a- E2 b- X
% @1 W1 \- y1 g) x% T: A* o
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h! I* ?/ r- B# B3 c' B$ n) \! q6 F
(API Get entry point)- s! Y% g0 |  {  O3 ]2 t
        ( T) _0 ?1 R0 z9 U1 F

, ]' ~9 G% `( i" L; M2 H    xor     di,di8 ]! Z; \0 i9 r2 w
    mov     es,di% y  e9 ?3 b9 b" R4 \
    mov     ax, 1684h      
9 ~' t9 l- \1 }. }6 T" ]$ [* F    mov     bx, 0202h       ; VxD ID of winice
$ m" n  b' A5 x/ u& r. ]6 I' v    int     2Fh" Y. H! R: a# N! i' t( l
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
- G; W$ y' e3 b2 g4 _3 |    add     ax, di9 _- _4 D3 D/ M* c; z! [: b7 s* B( P
    test    ax,ax0 U6 R2 j+ N& e& ]9 L6 E
    jnz     SoftICE_Detected& ?* C1 w3 _8 K' N. Y) J3 X1 }

+ I% ?0 T; j; }5 O' [4 K___________________________________________________________________________( D6 q1 I' g% o" D2 M' f: n$ n* h1 G' h

% a, m! v8 ?; U; T% B$ r1 P3 m4 JMethod 048 n! v1 i# v5 A) a" R
=========
. g' Y! w7 A; F( a; }8 ?# g' s9 @! \1 q% ?
Method identical to the preceding one except that it seeks the ID of SoftICE
! N' e& D7 r: z3 I. C' oGFX VxD.
' o/ K% y3 U% C( ~7 \/ d0 U! s7 y: C+ _! f, J
    xor     di,di( q0 x# S4 u# ^( [6 x- t2 ?
    mov     es,di" Q, Z# k& b% J% E
    mov     ax, 1684h       % r( ~! b& B: J) O4 P
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
$ ?- @9 u4 t$ u+ T& S! S6 p$ n) S8 O    int     2fh! y8 x' Q# x- ^( U0 P
    mov     ax, es          ; ES:DI -&gt; VxD API entry point5 t! P0 K" @, X5 }* h) X0 u
    add     ax, di
( z0 G4 h7 W' v/ {    test    ax,ax7 O2 [# }) l4 Y3 z1 f
    jnz     SoftICE_Detected# U5 d! |! O8 D- c- `2 f
. Q: j" V# k9 V
__________________________________________________________________________
0 H8 h$ T. F9 R2 a" P  X# M2 [  V% w9 s3 i, X2 Z" s( P9 b
# @* P. \' |! l" V( ]& B
Method 05  N# M  b$ [6 [6 Y  g, h' f
=========
: H8 L. l  F/ Y7 [- ?# w
, W. s7 m7 G1 v, l7 W4 qMethod seeking the 'magic number' 0F386h returned (in ax) by all system
+ B! w, H  L4 J. t- X3 ?debugger. It calls the int 41h, function 4Fh.
; Q, a& q# r  C# ^There are several alternatives.  
" b! C) Z( z' Z! w5 ]& f
/ l# ]# c; Q  q5 X! wThe following one is the simplest:$ m# _# h1 G; _& J- Q+ P% f1 b

, a3 D# ~- W5 a6 v# E/ R    mov     ax,4fh
) f5 d* u: C8 J9 `& w# B1 e    int     41h; I: U% k+ a$ e) a) R0 u
    cmp     ax, 0F386
6 R, F/ x3 V4 s( F; X! W    jz      SoftICE_detected! u# k" v- Y" C9 A/ t2 A

) D8 U0 f/ O; }. x# E9 r# Y
' n$ d. v  {' G  b3 JNext method as well as the following one are 2 examples from Stone's
8 V5 c' I' F  B) Y) r"stn-wid.zip" (www.cracking.net):
6 r$ B8 |7 h) B3 H
& }; }8 h6 c  j    mov     bx, cs% c" b; T4 T* B) P$ g0 o
    lea     dx, int41handler2
0 `" r  j' ?7 \% v    xchg    dx, es:[41h*4]6 O7 D; n5 H4 `3 Y/ X. C
    xchg    bx, es:[41h*4+2]
% h1 D3 R# J" D5 X* i1 N3 o/ e    mov     ax,4fh2 F8 ?3 R$ t* ~) _1 }
    int     41h) A( W# Z2 d4 {* P* c
    xchg    dx, es:[41h*4]
2 K/ i1 ?# b: d2 F# j; [+ G    xchg    bx, es:[41h*4+2]( c4 ~, K! i4 Q; X  l
    cmp     ax, 0f386h
9 N( U- K3 ^1 M' t, }  v    jz      SoftICE_detected
6 _9 y" \, C5 N5 @1 h2 N  g1 y: O! V0 N) D
int41handler2 PROC# J! d! P, N5 E
    iret
. l. \  J, M( ?int41handler2 ENDP7 }$ ~  b. z, X/ h2 v( ~, D

! o6 V& W' E/ g6 _4 @+ R  z2 _  W* K# x2 n
_________________________________________________________________________
6 b) z5 K2 p/ c! [& N0 Q. p0 O
* g( z/ T# b% T3 w0 B; a
0 x% g: h8 \  ]- s9 ?- A9 \9 r5 C8 [* `Method 06
# ^1 n' W) x! B7 a6 i1 s=========4 g! Z  x- j+ O  N' z
4 f7 ~: ^. S8 A. H& [& l4 Q
, c: `' Z' x' C+ z9 J# G' e
2nd method similar to the preceding one but more difficult to detect:1 e2 P  m/ C% A! _% A0 O
5 l! B6 ?4 u, n* f2 Y$ o
- I7 I& x( E/ r" W! W& W/ [
int41handler PROC
8 R( d! \2 a2 b2 _    mov     cl,al) M& d+ Q, p' [; \
    iret! Z; S+ ?! J! r" I9 @
int41handler ENDP
* p" _- p# x$ u7 ?
8 B" j* P4 d' i8 q3 `) i7 P
& F3 o; b* W& g9 ]7 x8 c    xor     ax,ax
4 l0 [* [) z% ~, U) o    mov     es,ax2 \  L3 }7 w# H! C: a5 T
    mov     bx, cs8 G- A7 Z* [4 v0 O
    lea     dx, int41handler! U: H. s5 D8 ], T: U3 I0 f
    xchg    dx, es:[41h*4]
5 B# C- o+ T8 N, M7 Y    xchg    bx, es:[41h*4+2]
" e3 n2 u' Z& [    in      al, 40h
* `, O  n" U' e; \7 G1 C9 |) o; Y7 A    xor     cx,cx
1 _9 }7 T+ l' }) |    int     41h& ?, p% _: a$ `
    xchg    dx, es:[41h*4]6 T9 W0 f# Z) Q$ t6 Y* w
    xchg    bx, es:[41h*4+2]# N, X4 K, W  U+ k  s; D! t' G
    cmp     cl,al
$ i, a0 u# S0 o  K+ x    jnz     SoftICE_detected
( A8 [& f) u) U: U9 R' U7 y) w2 Q* j0 q8 P' M
_________________________________________________________________________
/ x: W8 a6 Y. c) K
9 g) o  d+ D. N0 h4 p, \1 HMethod 070 D' a9 t, H: [& i
=========
( w: g7 T9 R- U! N$ G/ v: U( x1 Y' N9 f. P% l* f1 i) V
Method of detection of the WinICE handler in the int68h (V86)8 b* W/ T$ I6 ?3 u( M
4 v% ^1 C& R- x6 N- s
    mov     ah,43h
+ ~# [( e9 w1 z5 v% Y% L4 ?    int     68h4 A: P. W/ r6 ?, ~
    cmp     ax,0F386h7 R9 z8 l3 O) h  N0 K6 [. X! u
    jz      SoftICE_Detected
: y( w* y7 d( j6 Y8 n3 ~3 z* h
- g9 m3 F$ I0 B3 I6 J3 `8 G; X: V' h  y
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
- [+ I, ?; c/ m# x* h1 M! e   app like this:+ J' n5 |3 x4 X; D0 B* M) C5 j

- }& Q* b; b9 `2 U8 i   BPX exec_int if ax==68$ g. T% u; P) p  W: c
   (function called is located at byte ptr [ebp+1Dh] and client eip is
3 `& ~7 |( A- o# t2 p   located at [ebp+48h] for 32Bit apps)$ F. A+ T3 f* L, i) i1 X+ j; y, {, s
__________________________________________________________________________
7 X: x6 A4 u4 M4 C5 J
0 y4 _9 n4 o8 _4 c. ^5 U/ K: ?3 b' v1 Y8 U( f" X! L4 l& @3 {
Method 08  |( p2 @" I  I; m6 m
=========% z8 N/ {" Q5 n2 J/ U$ x) K; M( m. H
- V0 R1 d  Y( S/ h% _* o0 K
It is not a method of detection of SoftICE but a possibility to crash the
8 I! Y9 Y6 ^$ w! d* xsystem by intercepting int 01h and int 03h and redirecting them to another$ K5 B7 v& c. S  f5 |
routine.1 U1 F2 U' [9 e1 F, S
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
* ]2 ^0 o3 Q+ j3 \2 Kto the new routine to execute (hangs computer...)
9 S; ^# H1 P9 r. F+ @8 g
+ h7 t: [8 h6 a7 I  c    mov     ah, 25h
. s- j7 B$ ]0 o+ ~" C: r! m    mov     al, Int_Number (01h or 03h)
+ a" X0 A) ^' O  Y6 z    mov     dx, offset New_Int_Routine: n  n1 h  w1 x0 o, d- Z! e
    int     21h- S3 P4 j4 s1 F, C* v$ T6 r; u
5 M) W4 N/ \) M. [  r$ Y5 E
__________________________________________________________________________
- F# T/ O9 W% @* E  Z
  y/ w8 o: m* @$ D+ g* ?Method 09
5 v, R. T7 @7 ], [=========) b/ [/ w0 Y! e, y' |! _9 s) n7 ?
; g  b# f+ \3 p9 `
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only& Q  j. ?$ p2 ~" I1 `; v  y6 I* }
performed in ring0 (VxD or a ring3 app using the VxdCall).
: `: {7 X4 D" s; `' x" F+ X8 Q$ F& AThe Get_DDB service is used to determine whether or not a VxD is installed6 A8 c9 I& k8 ]* U/ ^/ X" f2 W3 t
for the specified device and returns a Device Description Block (in ecx) for0 k6 g" h! A) e; [- O
that device if it is installed.1 Q) _2 P, D) H' C+ ^

( n5 {. a, w- Z4 e6 i6 E   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
: j- L5 I1 J" }7 U3 h   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)7 u" j; z3 t( R, n; l) G% y/ B
   VMMCall Get_DDB
1 D0 L5 x4 T. ^* \$ {6 _   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
# P9 n0 u0 f! w: }7 A
( m9 w6 {+ _" E0 ^) ]Note as well that you can easily detect this method with SoftICE:
% U2 ^- J( \0 Q. T   bpx Get_DDB if ax==0202 || ax==7a5fh4 c: D# X0 M% |6 U) f

; P3 m) W+ @: S3 m: m__________________________________________________________________________
+ P. W- T* y" Q/ k0 p
- Z$ y9 w4 y$ `% f+ S# YMethod 10# ?8 k7 ^$ K# W9 O/ D
=========5 _* Q2 p! x* Q4 \; b, ], ?
. E5 T$ \0 z9 {: f/ |; o' ?2 c
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
% L/ D+ R4 l1 o, c  SoftICE while the option is enable!!
+ k" T# A! |* l9 H
: M$ ^2 y5 p" T+ |8 J; Q  _This trick is very efficient:
. L' g8 W+ b. {: wby checking the Debug Registers, you can detect if SoftICE is loaded
% J# t4 P. F& X$ P(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if5 S& W0 _" O) h" z% B  H' @
there are some memory breakpoints set (dr0 to dr3) simply by reading their
) j3 A* x: \5 R! m( F' i7 jvalue (in ring0 only). Values can be manipulated and or changed as well, O4 d* x$ n. t( ?: \% @0 ~
(clearing BPMs for instance)
' |, R+ ?/ h7 @# M- V0 j* K8 q+ Z& F5 \* @  g
__________________________________________________________________________
+ {3 ?7 D% _' g/ I/ P
+ \2 {+ M, J3 y) J- {& v$ ]( _$ L1 HMethod 11
6 l$ j& j2 D& q5 S+ x0 c=========
0 C) o) k. I  m/ `; `  V  A1 c( x$ O! f6 o/ y3 l* I
This method is most known as 'MeltICE' because it has been freely distributed
+ `6 _3 B1 `5 U/ O8 R/ [8 o0 Lvia www.winfiles.com. However it was first used by NuMega people to allow
) ?3 w/ H' u; a% h5 w3 pSymbol Loader to check if SoftICE was active or not (the code is located
! H& N% ~* A! Uinside nmtrans.dll).
! Q, l5 y/ U- F) p0 p/ X( t4 |7 K
The way it works is very simple:( w  _7 L* k5 J; X( n' U( j- w3 l
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for+ i4 I7 A" {& x: T
WinNT) with the CreateFileA API.
8 N3 U) M) H+ y0 q7 F) n
5 r4 p- i1 D: ?, ?2 yHere is a sample (checking for 'SICE'):
' k) F0 k0 {+ n" I( k# |4 n0 o) F( b; ~7 G3 p
BOOL IsSoftIce95Loaded()
2 v9 S- M6 j8 a4 e: r5 h{0 r7 r$ K: C# K# K, e
   HANDLE hFile;  
" o+ S- _) p$ H+ ~   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
" ^% }2 D9 m) [. X7 g6 \8 D                      FILE_SHARE_READ | FILE_SHARE_WRITE,! X; b" G, p- B; f, v$ Q
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);! p' S1 W8 s) b2 x( h  X) B7 m  {
   if( hFile != INVALID_HANDLE_VALUE )
& c! M9 d0 o9 z: g5 H   {7 C$ q4 _3 E* O8 `5 W
      CloseHandle(hFile);
4 Z# V4 y( n0 X: f1 X; h! {/ f      return TRUE;9 _8 ^/ b% v. G5 {- U9 m
   }3 G, I8 s) J% x; j4 ?3 m2 u  U
   return FALSE;1 }5 v/ z+ W2 F
}7 z+ p: C" ?* r5 m' b9 c
6 ?3 j# P0 i1 U7 v# o
Although this trick calls the CreateFileA function, don't even expect to be9 f$ X% L+ o: B* V( p8 ?" I
able to intercept it by installing a IFS hook: it will not work, no way!
+ X  U/ k+ ]+ |7 v: ~# S, H' `. SIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
) \3 e. s9 Z4 ^! ^9 _! hservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)0 C6 _1 U5 H, V# i+ L$ `$ b0 t8 x  Q
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
( ], ]2 y9 K/ n; _field.
* d2 c; \. f  ~/ ?* e( IIn fact, its purpose is not to load/unload VxDs but only to send a
/ N! S0 [/ S& S' u% Q7 |& sW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
7 l" [, p- g$ d; M0 cto the VxD Control_Dispatch proc (how the hell a shareware soft could try
$ K2 m! @1 _9 w- U7 `+ Uto load/unload a non-dynamically loadable driver such as SoftICE ;-)." m3 C1 d" N5 n6 q% {  h5 n! N4 f2 `
If the VxD is loaded, it will always clear eax and the Carry flag to allow, K& n0 S6 H( y
its handle to be opened and then, will be detected.) I6 E5 f2 Q& g1 t
You can check that simply by hooking Winice.exe control proc entry point) T% b9 y2 z, e3 C" U) w1 o
while running MeltICE.
% H; o- |$ {" {5 @0 J6 a  e3 w1 O
1 B- o5 D/ a- {; v* X" b6 m1 C) a, y# o7 T+ g+ J
  00401067:  push      00402025    ; \\.\SICE
( ?/ ?9 r( a$ r3 E1 J& S  0040106C:  call      CreateFileA
& A7 s! ]0 {. p' @* o/ O4 @# I  00401071:  cmp       eax,-0017 W* B2 r* h, V" P. {
  00401074:  je        00401091% A6 c/ w+ h4 ~/ N

' m& R( ]4 O% ]* ^3 n: G" }
! m1 r0 [8 x& R6 D7 Z1 h2 LThere could be hundreds of BPX you could use to detect this trick.* J. `% S# B3 T
-The most classical one is:
* ~7 t; F$ y6 S5 y  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
. R. R3 `& t1 `  f, L; W    *(esp-&gt;4+4)=='NTIC'
4 V. u2 N, H( ]- g) Y8 x. q. l9 S0 @7 D' V6 |* v
-The most exotic ones (could be very slooooow :-(
! D6 H8 ?- \  F# J   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
% |3 i6 W; D* _1 I     ;will break 3 times :-(/ G+ B& o) C% \7 k1 w
  R; g) t$ ?8 w7 s( J1 t+ \
-or (a bit) faster:
/ L7 A7 p& `# h/ H: o0 R   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
! W" c* i, a* C. z, v5 j
) u0 N1 b# b0 A" `   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  ) i/ f; H9 t+ X; {9 D8 J
     ;will break 3 times :-(% P2 S$ |( x' V+ {/ K8 J0 S; _
% ~$ ^* m- E' u& i8 K5 q% j
-Much faster:
0 k& }0 I! c5 V) }0 h8 n1 s: x7 W   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV': C& O/ c1 O) j5 B
/ E  a+ B4 f; R9 ~+ r/ l( K
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
7 H3 d) q4 C( p+ I1 P( p( v% L# Wfunction to do the same job:
6 J5 S' }/ s* N! W$ ?1 p2 N
* G9 v+ S( E8 b' v   push    00                        ; OF_READ; _& H: F% ?6 _/ n9 f" k6 p* U
   mov     eax,[00656634]            ; '\\.\SICE',0
2 Z3 {0 G& V6 m# O   push    eax
9 u3 A9 I; G- j2 B, U7 |* s   call    KERNEL32!_lopen" r4 D2 W- Y  J+ i
   inc     eax" p5 C* w2 ^7 G# I$ D2 g
   jnz     00650589                  ; detected* E3 p# h3 R; ^% ^
   push    00                        ; OF_READ3 a. d: K$ c# ~( ?, x
   mov     eax,[00656638]            ; '\\.\SICE') S6 P, r- Z% g& }3 F# v
   push    eax
) `/ A# |( t8 I% y; K3 w( @   call    KERNEL32!_lopen! e5 \: C  E1 A) Y- G
   inc     eax# ~6 B- [+ c# G  N5 j/ N) J
   jz      006505ae                  ; not detected
  l: E; p& C* g( s( y
- ^3 T( ]* U! p, w' X. ^
4 S0 p6 d) L! d) L4 h- U__________________________________________________________________________5 O, P  z7 ~3 H1 U8 w  N4 {
" B* w1 }. j3 Z- F  O  o
Method 12
5 O: v0 G. J8 U=========
9 f4 ^( G" N5 N' g5 f* @1 Y0 z6 [+ N" ?& O7 Y5 ~
This trick is similar to int41h/4fh Debugger installation check (code 05
1 D# g8 x: L* U* m- J5 X&amp; 06) but very limited because it's only available for Win95/98 (not NT)9 f: x4 K* S$ ?, l3 M3 t5 Z
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
5 G- Q, g7 K- l" d- N& j/ P$ G7 Q+ J
6 d* A) X$ f, w, M% e3 i6 U   push  0000004fh         ; function 4fh3 t# u( L- g" T! ^5 @$ ~  H
   push  002a002ah         ; high word specifies which VxD (VWIN32)
3 N+ r. [* i4 W* K                           ; low word specifies which service  X! V# Q$ P" P
                             (VWIN32_Int41Dispatch)
& H1 J  a- H5 L4 e4 G& C   call  Kernel32!ORD_001  ; VxdCall# y9 {# O) [* n8 b
   cmp   ax, 0f386h        ; magic number returned by system debuggers
5 |: a& H  H* c& q   jz    SoftICE_detected; s8 w, T! [: y  e9 v% k  p! w
$ z) {; _3 O: S* A( ]% t
Here again, several ways to detect it:
- p  g" ~# i5 @2 g$ Z3 s6 p/ c4 c, A0 ?  e2 [: ?  O1 q
    BPINT 41 if ax==4f
* N, \" Y2 }5 q: Q* X4 T
1 ?% o% _0 u0 M5 _. P    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
# O8 C2 b* N; f  o0 M1 V: M& {- l- b. ~) q
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
# f8 \/ J* l1 C8 ?2 J8 j
5 ^1 ]7 J& K( v# W" L1 y! c    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
) w) n' n0 k- c; r. k0 \& W% l
/ t. ]6 H; x" \% s& j. d/ Z__________________________________________________________________________
3 v& N" B# i% X$ l7 L- r  v8 m/ g) q6 Y0 H
Method 13
: d$ [( ^: t, b5 N/ b1 a* h, X; V=========
& P& M  b2 v" A; W' o; M& E/ J* r2 M( k- G' L6 s! m
Not a real method of detection, but a good way to know if SoftICE is
* _* F4 L/ a, k( O' g( Rinstalled on a computer and to locate its installation directory.
. {3 @7 W5 P: S: l3 f+ K- S# tIt is used by few softs which access the following registry keys (usually #2) :/ B( {3 [5 u# |
. q4 L# X2 T" e0 q; q
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
9 d/ V' y9 I4 |+ C, L+ w\Uninstall\SoftICE
, F$ ?' o0 Y' G; c1 v3 K-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE# k- |, Q! y& ]; P/ {- r
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 B5 f+ ~+ }" @, U" N
\App Paths\Loader32.Exe
( e, F% w- F1 ?. ]+ y! C# Q% Z8 p( [3 X0 p5 J& B$ \# u

( K. Q) p$ L: s6 P4 P; vNote that some nasty apps could then erase all files from SoftICE directory- v& y2 N5 X2 J3 k2 N
(I faced that once :-(
$ m) \, K, w- g1 i' r+ s' E6 x6 q5 |& p6 M
Useful breakpoint to detect it:
2 a  b* g7 d0 T
" k3 ?8 ~/ ~/ w4 H; U     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
  ~; g5 l) d6 j
5 Y8 R9 o4 v* V# G% l) h__________________________________________________________________________
- g& s7 v$ K" z3 F
1 h; `7 v+ w( G% f4 x8 L
* _# ?; b* W3 t  L, KMethod 14 6 h0 F; t( e! w8 y  E+ f$ s% T, v
=========
2 Q, G$ F: B( v2 U3 B: X- \
% M* q. b0 s/ K5 z4 zA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose7 a3 N6 J$ D# V% o
is to determines whether a debugger is running on your system (ring0 only).6 `3 k5 a! s7 F8 H9 A  w8 `7 E7 h8 z7 W
8 [6 P& l9 k) m
   VMMCall Test_Debug_Installed
; Y3 `0 w# w, ?   je      not_installed
2 P0 M* Y( f3 f% V7 {; D( m0 v
2 s$ Z* |1 z4 g9 `: X4 @1 m; r% dThis service just checks a flag.6 O! i% e: ]0 }) u( {* D
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部