About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>8 `* H. a  n$ X; ]9 {
<TBODY>
0 w. j- y+ O* I5 f% X5 _6 E<TR>. @* p6 r2 H1 H! [9 z' Y
<TD><PRE>Method 01 0 G7 c1 N, f+ Q1 ?
=========
! [# S  q2 r5 P$ J0 G# {9 g( ?
  A# F( o. T, @+ x: `This method of detection of SoftICE (as well as the following one) is1 E- G7 D+ H9 A$ [) x: e
used by the majority of packers/encryptors found on Internet.) L: a) l; J5 t* V8 f3 v
It seeks the signature of BoundsChecker in SoftICE, x: A# L8 {4 @7 \; b

! f: M' T  z, i0 v    mov     ebp, 04243484Bh        ; 'BCHK'
( w7 ]" d' X; w2 g& {    mov     ax, 04h
3 i+ h  b8 T, v0 b( o8 V3 h( |    int     3       2 U" m. B) H2 v
    cmp     al,45 Q" }: X1 ?% V6 [& }8 V
    jnz     SoftICE_Detected
5 p1 B8 L  c" G* l2 m6 n$ y
9 q7 s, P* l2 W' v___________________________________________________________________________
0 J. ~4 ^- u  m. M
% |% Y% W% N+ P& \* c, G) ^  AMethod 02
" R5 q; }3 C4 x8 A( h6 z, z=========
& g! X5 }2 w: A* O5 G" S5 e; T& }" j
Still a method very much used (perhaps the most frequent one).  It is used
$ K  u4 S2 N9 ^9 C6 Uto get SoftICE 'Back Door commands' which gives infos on Breakpoints,+ N) W  f0 [" X6 {; k
or execute SoftICE commands...
+ w$ o$ N" y! tIt is also used to crash SoftICE and to force it to execute any commands2 h9 U7 c$ Z. s
(HBOOT...) :-((  " L  e' l! R2 L% _; D
" b* _+ Y8 `) r+ R) A
Here is a quick description:
( f2 q& P% f8 ~8 x6 K3 a-AX = 0910h   (Display string in SIce windows)
- `3 y8 }, g; U: |& n" @% g-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
  G/ V( Z" Y2 c7 \-AX = 0912h   (Get breakpoint infos)$ u) v% e" D, r% V( @" Q) w9 ?
-AX = 0913h   (Set Sice breakpoints), B* p2 k" Y! `9 J8 B
-AX = 0914h   (Remove SIce breakoints), e8 c+ C, f: f) t1 W
$ d0 M- {- U) {, ?" v
Each time you'll meet this trick, you'll see:
3 {4 G) J* {& v% i0 z-SI = 4647h  x. D# {3 |$ H( u1 {
-DI = 4A4Dh
  ~. y# e7 Y8 Q- N. J* F7 dWhich are the 'magic values' used by SoftIce.
3 G5 [: I: u3 d- ~4 _; ~: m, gFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
5 a7 g( l& a$ g2 k/ A, C: p
& y6 b2 U- U/ D  P: @Here is one example from the file "Haspinst.exe" which is the dongle HASP
3 [& O# H9 \' g/ H" @/ `' b$ k; LEnvelope utility use to protect DOS applications:
" L: w1 v% N- D8 |* Z2 ^' g+ ]( H  R
) u; q# N% {$ X
4C19:0095   MOV    AX,0911  ; execute command.# k; t, f+ Z- L1 P) \- V
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).# W% h5 X7 B1 t( p
4C19:009A   MOV    SI,4647  ; 1st magic value.; D: j9 ?6 a% g0 ?
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.2 ^8 C9 B" A. [; K, Y
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
9 k6 S; f4 u8 r4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
1 I; s) n8 X: K( f  @' D4C19:00A4   INC    CX
  {; O& B) F0 P4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
" A$ X& @  k' {; e: K- j, y4C19:00A8   JB     0095     ; 6 different commands.
: _9 y$ U+ ?3 }  [+ d# x4C19:00AA   JMP    0002     ; Bad_Guy jmp back.. N  x% \6 N7 I' g/ @1 e
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)* n# H0 z  L+ @' [
: N$ H, P& M- b# q
The program will execute 6 different SIce commands located at ds:dx, which
+ `: ]* S; Z' ^: u% Oare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
1 i6 \* j& \) @# b. B( n9 {
& q% W0 [3 ]( j* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded." b1 e$ M3 n0 r; o, \
___________________________________________________________________________
! ?$ l* w0 X2 y& P- M1 X
4 V8 B4 z+ ^( l% O1 \. Q0 i" C$ [& \7 t7 C) T% y% ~, W
Method 030 u( q; `# W" [) S
=========
! G7 J8 b1 a8 L- j. Q" x
1 i# ]) P4 f" E: Z9 u- e# rLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
3 }7 _5 v9 m& I) ~& x) \6 H5 G(API Get entry point)' c7 f( @8 {9 K* _7 X2 y. P
        2 O8 H0 ]- m0 J: T

/ @3 D8 A7 r: J: p" f* }    xor     di,di
0 t$ f2 F, B- g& j" F8 b/ S3 j    mov     es,di
& u$ H. ^# g5 r% k+ w6 E- x. d    mov     ax, 1684h      
. W$ N/ B3 V* y  r& ?3 ?( B    mov     bx, 0202h       ; VxD ID of winice
8 k$ U( f8 j/ U; C2 q7 @% R8 y    int     2Fh1 P( [$ Y0 k( e' P0 u7 v8 n
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
6 l% e) `: x* F% q5 V    add     ax, di
, N" \1 W1 E. H; i3 n1 l    test    ax,ax$ ]0 g+ w* j' i5 t/ S- o2 Z
    jnz     SoftICE_Detected
& @5 |* c% l3 Y4 t5 @+ m
$ E- E1 a( U( F$ ~. C0 u___________________________________________________________________________2 F4 |# C: {# w  @3 u9 v3 E4 ?
' K3 z. n3 Q3 U
Method 043 G* C! d8 ?8 f- ^, u9 }! A: @
=========
9 U8 R. t$ \, `, K( @) ]- G, V* m7 G
: K3 u* \& ^3 C7 E+ a' p/ NMethod identical to the preceding one except that it seeks the ID of SoftICE6 ?5 H5 p4 p$ k( M
GFX VxD.+ U) c& c. ]+ F3 v5 C" P

. ~5 N/ ?3 n% x    xor     di,di7 b& K/ _& ]3 H" S
    mov     es,di' a* R+ i2 \, Z) V
    mov     ax, 1684h      
& f' A" a5 _/ h/ f& g+ D    mov     bx, 7a5Fh       ; VxD ID of SIWVID8 h5 D$ t6 E$ z$ [  L( p
    int     2fh0 q6 X. @" |. R+ Q- J. K, n
    mov     ax, es          ; ES:DI -&gt; VxD API entry point( d; w4 g) a/ [  T# `4 k; H0 a
    add     ax, di. i" R# T' P+ d& \2 ^" ]4 Q! [
    test    ax,ax  F) X# J: u: G) d; V0 S( ~
    jnz     SoftICE_Detected  \# M( f5 b8 T

9 S2 W. l( s, d# F0 m__________________________________________________________________________8 ~/ c0 ~' t  k3 _7 e( K1 r" `
* c1 x: R' |/ d& v! _3 ?* g2 z
7 U" t! t! B7 v2 _0 j
Method 05( ~, d5 |5 @1 c& x3 x5 R7 ?6 R
=========
9 I' p6 W8 M! A* ~* b
$ |, v% o" I( X6 Y. ?2 lMethod seeking the 'magic number' 0F386h returned (in ax) by all system. P" _& x2 c& i5 U+ l- b
debugger. It calls the int 41h, function 4Fh.
: g9 _$ Q" w: xThere are several alternatives.  ) M8 B, r: M" U* |% _" N( T( n9 h

7 u1 L4 G' T6 j* S3 C2 V% t# qThe following one is the simplest:
' c+ Z3 Q& J/ m
( b! \) m: y8 ~    mov     ax,4fh
  t7 v7 X* J* p6 R/ H# \    int     41h
* K# O4 X& k$ F. ?2 t' j" Z    cmp     ax, 0F386
9 M8 F0 }/ V$ O& l8 O2 V    jz      SoftICE_detected
1 T8 S$ a7 L" X" m
6 t# U( {6 f4 h7 ~3 @" r( K  g: {" ~9 o& e) V0 h! j' x0 u( ~
Next method as well as the following one are 2 examples from Stone's & i$ O% G& t7 ?
"stn-wid.zip" (www.cracking.net):' |; B; B5 x+ ?" T0 i' @
+ h* S8 j4 q: a0 S; Q) x9 i% _
    mov     bx, cs0 ^' a6 _- N* P. m
    lea     dx, int41handler2
$ K* M$ @; D  ^% P8 T    xchg    dx, es:[41h*4]
# J; ^; a! R; E) O5 L+ i    xchg    bx, es:[41h*4+2]
. i0 |6 {/ x- }! {6 a% A( R    mov     ax,4fh' O; n6 Y9 R* ?% R
    int     41h2 C7 h/ d9 [/ J/ ^. o+ ?
    xchg    dx, es:[41h*4]
3 \* h* x+ G8 S3 P$ ~( v    xchg    bx, es:[41h*4+2]" N0 M9 {9 d8 ?0 f7 _3 ~% S! r9 f
    cmp     ax, 0f386h. m( t! _5 U/ c! i5 Y5 n
    jz      SoftICE_detected
0 x9 _" E# a8 {$ A8 }; B5 O
: p4 y6 H" A+ N& Y) f/ sint41handler2 PROC% I# r- I; p( ?$ X" O
    iret
, J9 I  ]! u! x5 Y3 P. F0 Bint41handler2 ENDP5 Z$ U; Z: D" M4 q1 R0 D
% q: S2 I. @) p5 F4 W

7 `7 H: e( b6 h" U* G& J6 U! U_________________________________________________________________________
! V) ^/ r" s# i! ]5 \8 S# T4 U  q% l! i0 l- Y, I
% x/ }6 S8 I1 U* E* x+ L
Method 06
" U8 @' o7 c# t3 r$ G5 C, f=========
7 ^+ h+ E' U1 \9 Y  Q& J3 ~- [" k! h8 H' U. q4 [

, Y- e( P  w8 H8 W% l9 H: Z2nd method similar to the preceding one but more difficult to detect:
, A( U7 \  Y! z" {( O1 s& B5 r/ c# {- f& p' t$ u* E% U% J

' W7 h' q6 P0 o" A# Eint41handler PROC
8 e6 U* R3 @1 p4 V- |; v    mov     cl,al) T% Y" V6 M; q, Q# ~) h
    iret8 w: G" {) z# f. O6 E3 L) R% d8 P) I
int41handler ENDP
5 q* c: ?: ^& w8 X8 N7 G! r( J  q& C# N! h" J" |# f2 O) J

" P  v( Z5 x7 U0 G    xor     ax,ax
1 x: b9 ~5 T) d# C# b3 J    mov     es,ax
2 E- Z! r" h# s- t4 N/ A  o8 z    mov     bx, cs
6 R) A+ W. D7 [9 ?' F# a* t- ]1 v    lea     dx, int41handler3 l7 i9 Q1 n# x5 Z
    xchg    dx, es:[41h*4]
3 d, G  \  R# O' a9 G    xchg    bx, es:[41h*4+2]
+ G1 {4 u2 L9 ]! V3 W    in      al, 40h
- i: v- K( O$ S4 P) l5 P( }8 M2 Z! K( _/ K    xor     cx,cx- @& z2 t0 Z$ C: K: q9 S- L
    int     41h' q( Y9 X! n; X. `9 K: m1 J
    xchg    dx, es:[41h*4]
$ {  _' c% C- q1 o& p. f    xchg    bx, es:[41h*4+2]
9 j# j% }% c0 l' C: _    cmp     cl,al
1 T! H- j9 u; q+ l) y4 t5 e* g4 Q# H    jnz     SoftICE_detected1 n5 _& A; C* a% s8 `6 Y

* J2 g) f! M* S6 b3 a: d_________________________________________________________________________( g4 P( {2 Z# P( E; h( o2 w8 T

- z; m/ Q4 v2 c/ d- a+ YMethod 07
! Q9 C4 a" a( P7 j$ b7 R=========6 ~' p" ^) l5 J3 o) ~; s
( {# u5 j( l2 z) l, `2 J/ X
Method of detection of the WinICE handler in the int68h (V86)
: m* O1 h1 v; ^  Z) Z' \+ Z" B+ A" {* @( E2 u; x0 ~
    mov     ah,43h
) {) m. A2 ~1 {2 @    int     68h& z" r% _* J$ v9 `9 C0 E* L
    cmp     ax,0F386h5 O# n7 T% z. y! W# @1 `' T$ \
    jz      SoftICE_Detected
& z( R) V$ r( }, c6 ^0 }+ m* }
0 `: N/ u, M( z2 s5 o9 E/ S6 i2 q0 T7 G8 ]' c3 D
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit: y0 R3 {6 N  g8 \- \
   app like this:4 O% s. i4 Y2 u1 S5 w1 Q: F

: c6 O( d" q! i, {# N6 Y4 _" R& Z   BPX exec_int if ax==68& n- N- ]; r: @& B  M& g& B3 l& ~- ~
   (function called is located at byte ptr [ebp+1Dh] and client eip is2 ~0 F. l- N6 S
   located at [ebp+48h] for 32Bit apps)7 o# W: g; j5 `4 f; @
__________________________________________________________________________
3 d. c3 h- w1 F  `. i5 C: Z) b" }2 z  }
. N' F( H; _, q$ J: d! J7 Q0 n9 h+ k0 K5 `! r& z; T
Method 085 b' N& i1 h0 Q5 f
=========
5 V/ A( P5 D) j, {: C7 o; G% X1 Q( h, f7 I
It is not a method of detection of SoftICE but a possibility to crash the
" c: b6 [+ h# d1 V* Esystem by intercepting int 01h and int 03h and redirecting them to another
0 p3 v  P. w8 a( h" B0 Broutine.
2 s9 w" F7 N# A6 I4 o5 R" r! _It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points  N' }( ~# C# w. _" F3 p. C- O
to the new routine to execute (hangs computer...)2 `" Q+ _/ y7 h7 M( U
6 E" E* h7 Y$ g0 c( Y4 e' U
    mov     ah, 25h: v8 L# [% b/ B# W+ i
    mov     al, Int_Number (01h or 03h)0 M) ]* h8 u& j
    mov     dx, offset New_Int_Routine6 s& h1 O1 @  q! g' E9 N
    int     21h
! \( N. ^8 M) m/ \; N
# U) q2 N; [* ~) ~__________________________________________________________________________
2 ]- |  i: V9 Q! k' @6 T9 R8 m2 r. T* I9 {
Method 09
# j2 b3 q, f# F$ Z8 R7 \=========
- d6 V* W" A/ ?2 E/ B' B
0 \$ ^# \, R+ ^. m) w  R1 [; |/ @This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
9 I6 q3 B+ H; J2 z* y4 ?0 i7 i; j( T2 vperformed in ring0 (VxD or a ring3 app using the VxdCall).; t" L$ w& {: \, C
The Get_DDB service is used to determine whether or not a VxD is installed
' f# V1 G9 u  o' L2 H8 Qfor the specified device and returns a Device Description Block (in ecx) for
' ~# i- G+ a- G$ I9 s! T) d! nthat device if it is installed.6 S# a- s) n0 v7 L0 m
5 ]/ P( E& R0 S' _% _. Y3 [
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID; E* Y0 ]1 Q' A; ]1 [8 h0 x8 p- ?
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
( `) Y; V6 s6 h   VMMCall Get_DDB9 D* y( G1 a6 K5 ]" V* H
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
7 N2 E( l) ^' k: H. i" f$ d6 f4 k. {6 m
1 ~5 z0 P$ ~9 I. XNote as well that you can easily detect this method with SoftICE:) V1 R7 e8 P6 r& v  E
   bpx Get_DDB if ax==0202 || ax==7a5fh! J! t/ _$ ~1 S9 p
$ [: @* B3 D4 R9 N' h; U
__________________________________________________________________________
! M/ ~3 v4 _: S- ^# F& C! }1 L# n/ X# f; r, `7 o$ A
Method 10
( `, ~1 `8 @1 T=========
/ Y% Q) P1 C0 |) f$ ?' k- x8 i# `* ^/ `9 L, x: B; y
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
2 u  G& n2 T" d6 s. F  SoftICE while the option is enable!!( G* g, F8 f. Z" h

, _8 ^) T) e" {9 r# }This trick is very efficient:
: N1 E: E! ]- @  J: X0 }% Lby checking the Debug Registers, you can detect if SoftICE is loaded: x; T6 y1 O% e0 Q
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if: q) |, D/ i3 U* f/ K* h
there are some memory breakpoints set (dr0 to dr3) simply by reading their+ d' h. r$ i( x' [/ ^
value (in ring0 only). Values can be manipulated and or changed as well3 Y, W9 J: D% y5 v
(clearing BPMs for instance)* ?, t! i1 q, O- W+ f

. V; p4 ^/ k8 s__________________________________________________________________________
7 M: _6 R; I; K& G7 E0 s
' z, t, }. ]( b/ D" }, T8 W1 oMethod 11
, v# ?: d9 r+ r( N7 v( a  |/ q=========4 n# C9 J! M" k* D# D: w# o3 f8 i

8 l0 X* a( t( }This method is most known as 'MeltICE' because it has been freely distributed$ @' X- A  X( Z! W" g
via www.winfiles.com. However it was first used by NuMega people to allow
: X/ t+ l+ O% `( O$ ^# d8 k" [7 WSymbol Loader to check if SoftICE was active or not (the code is located7 C9 H+ c% l2 i& \. u4 `* D
inside nmtrans.dll)., i2 B  I. E0 S0 D( j1 E( k( Q
  p& r+ w! y# q( G% M+ Y" y3 `
The way it works is very simple:- `  E! U- y) o  }+ x
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
- @# q9 ?3 L; |& DWinNT) with the CreateFileA API.
+ b! ?& Y7 d' l# F' M" ~3 h2 [% A8 m$ P
Here is a sample (checking for 'SICE'):3 T& q# g- r: n) w  x3 m

% v6 I% v/ _: m) BBOOL IsSoftIce95Loaded()
0 I  u( W2 N0 Q0 q: W+ A) B3 S{# ^& u+ C$ k# E. Y! x. m
   HANDLE hFile;  9 X& y3 r$ S8 `0 o  h
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
: I. {, R/ k' p8 ?& N$ p) ~                      FILE_SHARE_READ | FILE_SHARE_WRITE,
% m: H3 r; h( c- h: V2 C                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);9 @, D7 ?% K% j! ]9 D# z
   if( hFile != INVALID_HANDLE_VALUE )
, H1 K3 e2 _' Z' P   {! R1 y/ d2 _  z+ R
      CloseHandle(hFile);* i' U% O5 F7 o* L' Q
      return TRUE;9 j3 ]  P, a/ h
   }- {9 z8 k: s+ y! C0 P8 ~9 C. p
   return FALSE;3 p! W' e8 y; c( t# Z8 m4 G, E
}
& i9 ]8 L! C2 N- j8 b
$ F& G! g, f0 C6 r- e$ Y6 o9 \Although this trick calls the CreateFileA function, don't even expect to be
% y0 o5 |+ U4 W2 h8 L! B& J" Xable to intercept it by installing a IFS hook: it will not work, no way!, \& m# q' V" I
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
0 s4 F' }9 Y2 x( T% Pservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
$ d- ~! W# J) @+ wand then browse the DDB list until it find the VxD and its DDB_Control_Proc7 h6 u' I* c0 z6 H/ q# r
field.$ D1 S; I5 O6 g, X  G+ \
In fact, its purpose is not to load/unload VxDs but only to send a 1 q1 g. G6 e; G  a- C, z6 F
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)& l3 T$ y& J: p
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
, c8 A& v. b  L2 `4 c, U6 Q% `to load/unload a non-dynamically loadable driver such as SoftICE ;-).9 `1 M' Y# o! z' c& p
If the VxD is loaded, it will always clear eax and the Carry flag to allow) A$ K8 A' |4 C: G) F
its handle to be opened and then, will be detected.
% B* v0 v6 K1 B, W/ D# jYou can check that simply by hooking Winice.exe control proc entry point, q6 O: w0 H8 z5 H) W3 l1 W
while running MeltICE.. e: N( P* f) |4 ^- Z0 y0 n2 x

  [3 T: q3 [0 K; X, _0 o9 ^+ }" J0 f  L% J
  00401067:  push      00402025    ; \\.\SICE
' F0 [1 o8 A- X" h  0040106C:  call      CreateFileA
5 ~5 O8 J8 k3 z! c5 D! }  00401071:  cmp       eax,-001
. y7 v2 ?: V) e. G  00401074:  je        00401091  X7 w& S% \, S/ ^0 e, u
5 A2 p0 E( d: z3 }1 \- t
- |# v5 `! t/ K7 Z
There could be hundreds of BPX you could use to detect this trick.
  Z4 O5 A& `& A9 Z9 `" k/ q-The most classical one is:* m1 O3 q0 K, h
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||0 X/ R3 I/ V  R1 d7 G- V# B
    *(esp-&gt;4+4)=='NTIC'
9 X( F: h: K( O( V, i# e1 b2 Z7 p+ r$ c! D. x1 x+ E- N4 Q( ?. f
-The most exotic ones (could be very slooooow :-(
1 L- ^% h: e7 y" a3 c% O8 q% m- u+ ~   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
. c% g* H( G7 `- b! d. ^! {* T- i, P9 f     ;will break 3 times :-(, m. q: g+ i; b- h/ _, F; k

! b2 h3 i0 K# A& [3 Q' G-or (a bit) faster: * O- Y% Y. y5 ]- Z
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
/ ^/ {6 _8 d5 o* M9 J' P  s# G+ O1 k+ o1 P; {+ b& n$ R+ Z: ^5 k
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  , Z. F/ c8 B" i  d, F1 Z" H3 r8 X
     ;will break 3 times :-(
+ ^2 y: P+ @, C3 G
1 Z8 \9 y, q5 a* x# m6 l; p-Much faster:
" e' N3 G" R3 n   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
0 D" t) Q5 B7 q; L: L9 }6 M" M, q8 y% [( v& t. P/ Q. ?
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen2 K  A: Q& }5 K2 \, `: o# G
function to do the same job:
& S& J8 P5 v" F
7 E; P; L+ O! p; H' f0 T- L   push    00                        ; OF_READ, r; _0 k/ ]2 g+ E& o8 U4 ~) [7 b
   mov     eax,[00656634]            ; '\\.\SICE',0
5 a# I! p* n% Y0 c* u   push    eax7 ~& L6 J9 R) e1 B' N' B. T
   call    KERNEL32!_lopen5 c6 ?! p2 {5 m* [+ }0 z
   inc     eax
$ F: K% y" @; ?* x   jnz     00650589                  ; detected$ U8 n5 x2 ^+ i9 `/ M
   push    00                        ; OF_READ8 z1 N& ~% G4 n
   mov     eax,[00656638]            ; '\\.\SICE'
1 i: ]. |& a8 P   push    eax2 F1 n1 \$ e4 b0 o: @
   call    KERNEL32!_lopen$ Q3 |5 ^5 I* Y$ c0 R' T! `
   inc     eax
3 Z/ B* }+ H$ Y4 W3 B5 x3 `6 P   jz      006505ae                  ; not detected: }! ^* r2 x' b8 ?

: @0 D& ~7 f- \% i1 e" g" E8 R4 Q. E- M' I7 V
__________________________________________________________________________
' w( A3 a. [0 y9 @  M
$ `! m  o- V! d8 V( S9 X# zMethod 122 j/ K- W# z% {/ l9 e2 G
=========  }: ~7 f' p4 J# i

2 }6 I. N: U, J4 J; S; J0 wThis trick is similar to int41h/4fh Debugger installation check (code 05* K% N5 c- l2 g5 R
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
1 @8 T# `& e' H. I* h9 y# v* qas it uses the VxDCall backdoor. This detection was found in Bleem Demo." O8 G% k( n0 ]. m4 }. E
2 W8 t+ B6 H: Q& i& K/ d
   push  0000004fh         ; function 4fh
- ], |' I6 n$ K   push  002a002ah         ; high word specifies which VxD (VWIN32). i( Q1 B4 l" o9 k- d5 N
                           ; low word specifies which service
( W& C/ L% t5 r" J; B3 y  ?$ h                             (VWIN32_Int41Dispatch)
( X$ `9 ?) u0 }& a1 G& V6 E, E   call  Kernel32!ORD_001  ; VxdCall$ o' U( {+ Y. d9 L
   cmp   ax, 0f386h        ; magic number returned by system debuggers" _# g/ R: o0 ~  J8 x/ q: m
   jz    SoftICE_detected
( x& I2 z6 e2 O& H
7 M- W8 v( c; a, w; K1 aHere again, several ways to detect it:
, u: X. @0 X7 r7 G+ P
! j) L7 m" ?  {6 l/ ^) X    BPINT 41 if ax==4f7 r/ i+ P; ?- ~) b7 O

# |/ v* @4 r$ q0 I0 X3 ^    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
: P* R- y$ D& K" T: ~; g, W4 t7 |: y
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
. Z$ i! c* M& C' ?& k/ g
- W0 q5 K6 ~- s) H- M    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
& \" g+ w  t' c8 n) R/ N/ q3 a! x0 F5 L: `" r3 _+ a) ^
__________________________________________________________________________! S3 v/ C+ q1 Z2 F2 d

8 s6 v  x* a+ ?/ l" mMethod 13, B# X) z. G* v8 I) o; Y' H
=========
$ g" C( U4 U- c/ W- W
) C; }& |/ `6 ?" VNot a real method of detection, but a good way to know if SoftICE is
* ]( x4 Z+ ]" z* O% E- Vinstalled on a computer and to locate its installation directory.) t8 t! b2 `4 n, T9 E4 j
It is used by few softs which access the following registry keys (usually #2) :5 t2 \, b5 m* I3 V+ E4 {
4 w' y( f9 E' i7 ]
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion* O2 I" c7 B8 e) S) P
\Uninstall\SoftICE
" {  x* B- E8 x! p-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
0 [5 }7 C4 R2 b/ H) s-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
+ r4 I4 ?# K! x+ I0 E4 a% G\App Paths\Loader32.Exe
8 `/ u% c( c, q  y1 t, e% m5 `$ i. v! ^0 a+ k
3 S0 V" Z3 y& }6 d7 {. i0 j: ?
Note that some nasty apps could then erase all files from SoftICE directory+ n* T2 M. y+ @: i2 E" b
(I faced that once :-(/ H/ u5 N! ^  @. _% j( ^# ^0 a5 ]

0 f; u/ G+ X# f3 Q: jUseful breakpoint to detect it:7 `  k# Y7 \; f
, f; Z% P& M) H% {/ s
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'" q" Y" H0 Y! v& t% s$ E

' k# P- Q* U% c' j: ]" K__________________________________________________________________________
" u: T, y- n; t. r
) o$ R; B# Q9 n
2 Z2 G9 Q4 ~9 DMethod 14 1 d" g& O! _& U- P
=========% w( L0 e# Q. _! V& q7 L0 R) L% v
7 `4 _! M2 a: \6 {. w6 ?
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose" G; s/ x3 N+ p' u+ R+ w- f
is to determines whether a debugger is running on your system (ring0 only).+ i3 _9 q4 v2 s4 U& v9 _( `
$ p8 s. M/ G0 d6 G  `( T5 n
   VMMCall Test_Debug_Installed! m8 n+ k4 M4 i6 E2 E0 N% O
   je      not_installed
4 {. ^2 Q. o2 w9 K8 w  Y3 j6 ^3 Y0 }' S) \$ J3 q& ^
This service just checks a flag.7 T( v# _3 {) t! \* @
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部