About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>3 ~( Z6 ?; T2 j, S3 D
<TBODY>
  f* }9 g7 F# A6 A5 X' v<TR>
# I2 f( A% Q5 C" y' W<TD><PRE>Method 01 ; y1 K  {4 \% E4 y% A* v
=========
4 M/ F: ]$ W' j3 G; W; c( g9 d3 ~3 F. V  A
This method of detection of SoftICE (as well as the following one) is
  n+ z) C9 V7 v8 }: x; rused by the majority of packers/encryptors found on Internet.
  }6 g& f. D! e* R& I3 ?, @. r% kIt seeks the signature of BoundsChecker in SoftICE
& K& V7 k) t) a- h7 I- I
, R$ Q" _5 A# |' b9 o    mov     ebp, 04243484Bh        ; 'BCHK'
$ N* Q8 a& \% G  f! Z* u& e    mov     ax, 04h
$ s3 L: i5 w1 H! n, A0 m) Q! r5 r7 ?    int     3      
8 O4 n2 p9 e3 I) W5 y; z. ]    cmp     al,49 y" x9 {; Y& i+ N
    jnz     SoftICE_Detected/ N; u/ {0 M! ~1 [

" e( R1 t( h& H! w* A* ^5 |$ J1 I___________________________________________________________________________
# U8 d; M8 D; Q
+ r) ^9 s! q$ w9 i+ \2 h& S+ X  FMethod 02
/ m) E, ]9 D: `, J+ Q=========2 ?( S9 f) V, r. O( ?1 w
6 f' X( J9 y6 v  h8 \. T
Still a method very much used (perhaps the most frequent one).  It is used3 o8 o3 S! W& }2 P. [" @
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,; y2 Q. s1 J" T# k" M- F% O
or execute SoftICE commands...
/ Y$ ~. J5 t' IIt is also used to crash SoftICE and to force it to execute any commands
. o" `! p3 O0 ]2 m(HBOOT...) :-((  
* m; A; l2 o8 r, q) e
. z. j& g3 M# j% tHere is a quick description:
& S$ n2 r) x5 m! G! t1 I  c-AX = 0910h   (Display string in SIce windows)
7 R; e; ^. z! J1 f9 T-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
1 A; P8 u6 x/ |3 U* ^-AX = 0912h   (Get breakpoint infos)
0 n0 g9 m6 N" C& [; E-AX = 0913h   (Set Sice breakpoints)
+ H; u5 o0 t5 C0 C% Q-AX = 0914h   (Remove SIce breakoints)
/ }& v; V# ]& }0 S0 R9 `5 q
6 H+ v# |" S/ g( I  Z0 A+ rEach time you'll meet this trick, you'll see:
$ M' k8 q' F7 ~+ Q  }; s' W. H-SI = 4647h5 m+ U& y& x8 ~' Q( s0 g
-DI = 4A4Dh
6 ]  j3 k4 ~1 [: _  cWhich are the 'magic values' used by SoftIce.  p$ y+ i3 b7 X3 B% ?* D
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
8 u) j% U, s3 z1 c' r7 ]5 @6 z9 p3 f2 o( g( u- {* \
Here is one example from the file "Haspinst.exe" which is the dongle HASP
1 I  i$ U9 Z2 i4 W- E/ z& YEnvelope utility use to protect DOS applications:% k( D) o1 A4 x6 H, F; S
; P" `% {5 `1 K! n) ?
2 ~3 Q/ ^3 c- j) A, o
4C19:0095   MOV    AX,0911  ; execute command.$ @) P) D) h* P5 X- a
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below)." ]0 f/ V& y! {/ \9 N
4C19:009A   MOV    SI,4647  ; 1st magic value.7 f2 @2 F( ~3 D' V- g( r
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
% J5 O$ M: z4 j. g) U4 Y4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)2 C, L) h: E( ]$ ]
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
& n; \! I9 b+ |1 B' A4C19:00A4   INC    CX: }9 Q! w, l- T8 B% d" J, A/ g
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute( t" [4 T* u1 }- E: w
4C19:00A8   JB     0095     ; 6 different commands.$ U' O! S; c+ f, n' k1 V
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
  f+ E1 Y/ q6 r3 ]0 P) n# ^4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
0 s. q% {2 G7 F7 W* [' T9 T3 u9 e; j' }& P# i  R" W4 A$ h
The program will execute 6 different SIce commands located at ds:dx, which. {' S6 I# y1 d/ D& r, p3 f
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
# h- [( Z4 q/ M* C' i" h
  `* N2 H3 x1 y- l9 C! j* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
1 `& S& g% O* G1 r# C; A___________________________________________________________________________. {2 ~6 ^/ q* ?/ R/ V  w0 P

$ o* `# H* j& t1 ?  H" C) m& n- B' V2 {: ^' E7 |8 B# [" C  {! i
Method 03
! N; o- N: Q/ Q3 y+ d=========
- Q- G6 Q. c% K$ M$ U3 N7 g$ D# [6 d" S
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h8 s) J9 N, A6 |5 G: e7 d( [
(API Get entry point)- D' R3 O7 O! B
        
  ~$ G* k2 [+ x% x2 Y  v& n
  M" q1 W2 P/ |: h+ l7 I    xor     di,di
/ `% Q7 ~, Z: W0 {, H    mov     es,di
/ D$ m6 q/ y! X. s" ]    mov     ax, 1684h      
5 I/ m$ T) L6 _) ?    mov     bx, 0202h       ; VxD ID of winice
7 w% n& v3 {, y: D5 {    int     2Fh* [* @. X$ {9 H
    mov     ax, es          ; ES:DI -&gt; VxD API entry point1 `( r+ m5 k$ t5 t% d9 [: ?; ?5 n4 d
    add     ax, di6 W- j) H& Y* x. P; G
    test    ax,ax8 G6 f  ?  a( S/ s
    jnz     SoftICE_Detected+ W; b' E  Z$ _5 I
9 ?$ K) S/ x% ?  E$ A
___________________________________________________________________________
6 v9 ~; s( H& U, u, r: }' ^6 h1 ]. Y
Method 04
! o) F$ B+ Y5 `0 @7 ?  o- m=========
% e/ ^# ?2 E* m. R5 f0 x1 D
- X7 Q9 H6 E$ ?  d0 d. }0 i" }, SMethod identical to the preceding one except that it seeks the ID of SoftICE5 d% Q+ d2 y/ Z! W
GFX VxD.
% k: E! \8 ]5 p; X
5 D2 w' {- L' S3 A6 u1 f+ b. _3 Q    xor     di,di6 L. e& E0 {5 ], W, J& y( t8 L
    mov     es,di% o8 A' M' R8 a' \1 K' q' n0 V2 p
    mov     ax, 1684h      
- t) h6 S: }, y8 F  e    mov     bx, 7a5Fh       ; VxD ID of SIWVID$ ^4 S$ D; Y9 Q* u# `2 V/ r6 v7 T
    int     2fh  h8 M1 H- u, p0 v0 u) y! M/ n
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
; g2 j, p5 _& ?% V1 u    add     ax, di
5 s  L2 C$ d. z' v! Y: D. ?4 v    test    ax,ax
, V* Q( i% D6 H  Q    jnz     SoftICE_Detected% G: o4 D1 W: _5 p9 {( }# p0 M

% F' Z3 F. z* h9 r__________________________________________________________________________; ~& x- m; q% I
6 C8 P: |* W! K- F, p  E
" Z; m; i$ o7 I3 Z2 H
Method 05
% h2 G( y8 I- W=========
+ H  R. t2 {$ ]% u7 O
- v! Z1 c5 V7 n# p: T( V2 W/ a7 D$ pMethod seeking the 'magic number' 0F386h returned (in ax) by all system& t/ w9 s: D$ B- @4 v3 V
debugger. It calls the int 41h, function 4Fh.6 U+ ], a& z! E3 d( u/ {6 ?; n
There are several alternatives.  
6 F+ U. x' r9 Q4 q' K( T4 H( [  G0 s& t! @4 N3 D
The following one is the simplest:
4 Z* L  k, v; A" w: v
  r; q- O' y' m$ ^1 T    mov     ax,4fh' h% j4 N( t+ z% ^! A. D
    int     41h
9 R7 Z1 `/ L- ?7 l& c    cmp     ax, 0F386( Y+ U$ k  _. s
    jz      SoftICE_detected
! f. B9 S6 i# F+ l7 k9 Z3 D$ K3 q+ b# o; F

- e3 D# n/ i( KNext method as well as the following one are 2 examples from Stone's * H7 ?/ z' Z: s, {0 p, Q% l
"stn-wid.zip" (www.cracking.net):
2 b* \  r6 U, R" ]) E  l' e2 R
) r) B% y( N4 L3 z  K$ J( S    mov     bx, cs; _2 Z2 p  j, L3 ?4 K2 z; l+ l
    lea     dx, int41handler24 O7 h$ {; `% ~& Y$ m$ m* N$ k
    xchg    dx, es:[41h*4]
1 t) F: \( I. x. X    xchg    bx, es:[41h*4+2]8 k" B9 |, k) B1 S; U. |
    mov     ax,4fh
  W/ k3 f! _  u; [) a    int     41h2 H/ p( h' K/ ~( e) x( h1 h
    xchg    dx, es:[41h*4]: s8 ^0 `$ \& c* h# g; M
    xchg    bx, es:[41h*4+2], w2 o; S6 y% V, @* p
    cmp     ax, 0f386h) Z5 L% s9 i2 o- j2 _
    jz      SoftICE_detected& M+ ~: A" X/ e8 A. D
% N0 `7 a5 o1 K3 Q0 i/ y$ K6 r
int41handler2 PROC
& X+ Y1 f# P1 C2 _/ C6 {! y    iret
0 o7 t) g" N' `/ d$ E5 Sint41handler2 ENDP
7 T  X2 Y8 h* ?# q2 l4 z
$ O6 b& K: {" o0 \( o$ a' Y- F) J6 v, z; q+ n7 m# H
_________________________________________________________________________9 ?: X3 Q; k1 z% m4 z& U' x
' e9 w! b) a; P# C7 x
8 J% N4 m& s6 F. E- v0 }! w
Method 06# x3 D9 z( C) R5 ~' Y
=========; y) J  R2 s, Z8 g4 T2 N3 p

" s. o1 ?: s$ ~: Z7 C3 ^
2 @8 F" C! f9 S2 H& i) s! q1 H2nd method similar to the preceding one but more difficult to detect:( g" }; ~9 z3 s! _; t: s

1 v1 ?+ S( P1 G- M2 e( s6 b+ b
2 p  b+ ?. Y1 `# Q. Wint41handler PROC  u" O+ i. |) }) {8 v
    mov     cl,al
5 i$ }& b) ?9 D. F: E3 @    iret6 s- u$ M) T. W* n
int41handler ENDP
; P; I( p3 P" P. b6 G0 p% \& m4 J  H) t4 }
8 S" s6 g3 ?+ k! k4 U4 N5 G
    xor     ax,ax
  l9 j) f  W& j' ^( y    mov     es,ax- j) ]# c5 e- E6 Q5 x$ j! @
    mov     bx, cs
7 ~1 c+ j7 N: N" f, Y7 s! ^    lea     dx, int41handler
$ Y7 k- d1 [2 A/ j    xchg    dx, es:[41h*4]% X8 S! f. X0 R% }* q
    xchg    bx, es:[41h*4+2]
/ g4 ^- @$ N' Z7 c8 D1 t) Y3 H! ^5 c    in      al, 40h
6 T/ n5 ]3 O2 R0 Q    xor     cx,cx
! G/ K$ D0 U0 a+ C$ A    int     41h  K1 `# W  _( ?' m0 L* M+ O2 ~0 ^
    xchg    dx, es:[41h*4]9 {+ n* P- t1 V  }1 T. C% k0 X
    xchg    bx, es:[41h*4+2]- m1 e; P- c5 y9 ?) _: m4 v9 D$ K
    cmp     cl,al7 Y7 p' w5 k! n$ `: m
    jnz     SoftICE_detected; N3 I" ^! \: n: W% k

5 N1 M* t; B& Z  V( t_________________________________________________________________________. `8 K) w2 X: m3 w: ?. Z
( u- t+ X  r5 C+ b, `! E8 V
Method 07- e4 i1 ]& j' x! ~6 }' s
=========
/ V1 G4 y4 z3 p0 i) W6 w" n  w* i6 d7 ?' S0 [; y
Method of detection of the WinICE handler in the int68h (V86)
7 c/ V4 u- \! e( R8 }& @' j) X
3 E6 N: f  z- L* l2 ~% H2 Y    mov     ah,43h
' P# e- E: b$ J% N$ g    int     68h: [8 v$ ?6 ~) p* O. }" L4 j% U% ]
    cmp     ax,0F386h) @/ I# \7 ^  O* x; J
    jz      SoftICE_Detected
! o5 x" G) G8 S# m& A& K
' P  K+ r/ J1 ]% J: _# V
$ G: a6 y/ f1 Z! a% g2 W=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit; b; |# E1 h% E% c" G8 a2 H
   app like this:
% o2 c7 N' ^7 ?" n, u7 Y, D% ~
* O2 R: a0 K/ u5 ?) Z   BPX exec_int if ax==68
6 n' x: v" }* L. v9 r   (function called is located at byte ptr [ebp+1Dh] and client eip is- F, {# P2 _: Q+ q, ]
   located at [ebp+48h] for 32Bit apps)) g( v/ L* c$ `( r+ d# J
__________________________________________________________________________: i) O- P9 S- W; T# P! d* c7 b

* h* e- ]# r! W  v' B2 U8 s: Q+ z, S" y5 i! X+ R
Method 083 ]7 V8 ]  `+ Q. @, \# D- J  x9 K
=========
' L2 R$ z2 j. V5 g: [' i6 H
! l; ^& X1 J. S& L7 YIt is not a method of detection of SoftICE but a possibility to crash the, c6 B& P6 J0 |8 L
system by intercepting int 01h and int 03h and redirecting them to another5 q4 a5 N( ~  B! ~
routine.
( O0 G3 [2 h. p- `* I' K4 G- r$ H5 q& o( qIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
8 R# g8 K3 \  s$ n- n. T9 {to the new routine to execute (hangs computer...)# t( p% X3 \# Q% q

' B# {0 R& Z( `  y    mov     ah, 25h
+ i6 L( _5 d0 I) [3 N3 P    mov     al, Int_Number (01h or 03h); a; ]+ v# P* ?) u  q& |4 p
    mov     dx, offset New_Int_Routine
: \' o7 z3 R# F  ~- b- p6 k    int     21h& ?' _' H3 L% q; V. |
9 s) `  b7 c8 a# X& W
__________________________________________________________________________
; f% m. Y! J. M
; I6 x% j" \8 }  g5 n5 z- DMethod 09) f/ [' Y* _6 c% X& L2 L
=========
4 S  o3 q2 d4 t7 \( I4 l+ W. w2 R' o) C- `0 f% u; h+ J/ p8 Z
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
9 y" H- s- T; i# Bperformed in ring0 (VxD or a ring3 app using the VxdCall).
. F1 h( [, A+ l& ^0 f( f9 r8 wThe Get_DDB service is used to determine whether or not a VxD is installed
% Q8 l2 ^# c4 X; ?6 A( x/ K# Sfor the specified device and returns a Device Description Block (in ecx) for
+ [8 c0 |# K; Y4 R- Ithat device if it is installed." ~6 b. B- @, f- a* ]6 V7 z$ b

' q* O1 k) _# W   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
3 K, ^9 @1 \1 |; a9 i1 I# d9 x   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
6 u: k; b" T3 j8 ~   VMMCall Get_DDB
% U1 q: m* N7 J3 L  x' ]0 `   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed; @7 ]% y4 E7 T" Q" n# P0 X

4 i2 Y% M, ]7 v8 s( f* ]7 ^Note as well that you can easily detect this method with SoftICE:9 r& F( O% w. h/ Q
   bpx Get_DDB if ax==0202 || ax==7a5fh
5 B6 {8 o, A. q# f
+ ~5 w( g* R- N( Q/ C: a__________________________________________________________________________
* B7 O# n6 k) l* W6 ^8 r: H0 l) F# B" |" S- V& `! H3 b5 n
Method 10
( B- I( `) K2 r- K4 K5 M, ?=========
- ]3 Y* [& C3 |' L! `0 G2 A, X9 x
% O- j7 N! ?8 q* I& d=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
+ o2 U/ \7 z3 G0 a  SoftICE while the option is enable!!! Y( B4 n! w  e' U* Y2 h

1 S1 P  T. c" LThis trick is very efficient:" F* e6 g! h( e3 I- ?$ j
by checking the Debug Registers, you can detect if SoftICE is loaded
  I$ U: K4 K, n3 N(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
+ b! K7 z2 L: l" B9 U% C0 Qthere are some memory breakpoints set (dr0 to dr3) simply by reading their$ r4 y" X8 ]+ B! p  V) ]
value (in ring0 only). Values can be manipulated and or changed as well
- M/ @; _4 f; G4 B# `" v( t(clearing BPMs for instance)
0 U4 I- c9 \* V* i: i9 {, z) H) ~( z0 a( @* H
__________________________________________________________________________9 r" {$ x; C& h% ~/ B
9 P4 F+ i/ r8 ~' g% j( H, {
Method 11: A# |' f- o- W8 b, c5 ~+ @( w% U
=========1 _0 r, S; Q! ~  y4 k7 T

( G/ _% a+ G& nThis method is most known as 'MeltICE' because it has been freely distributed" O& b; c* f6 s
via www.winfiles.com. However it was first used by NuMega people to allow
' p2 a* w+ j7 D8 eSymbol Loader to check if SoftICE was active or not (the code is located2 a) Q, c# A) u4 T! \3 @# ]. D
inside nmtrans.dll).
2 A" Q* J6 Z) W: [& j; K) e% k
9 I+ z7 L/ x' E5 `$ S: aThe way it works is very simple:
8 y- y5 x0 M. @9 U  IIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for) {6 _4 o+ I! v
WinNT) with the CreateFileA API.
5 z, ?% o" G: O; y& X9 {$ {5 i( m+ T  j2 Q  y
Here is a sample (checking for 'SICE'):+ {6 a4 C  {  v' G

, P& V% ~4 a! A! R0 z2 bBOOL IsSoftIce95Loaded()8 `3 m. c8 V/ `7 O$ a
{
0 }4 m0 ?% r6 w   HANDLE hFile;  2 l0 c* s1 J% m7 D2 k5 q, t
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
0 N6 W- a3 X1 J0 J                      FILE_SHARE_READ | FILE_SHARE_WRITE,0 w# E& ?' U; B* S- t" y+ i
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
0 n# E! |( |$ d; z6 g. F   if( hFile != INVALID_HANDLE_VALUE )
5 U2 Z. p0 ?' M# @+ v   {( g% J2 I$ _7 m  _9 X
      CloseHandle(hFile);% x; M3 e# Q" c' ~8 @( e9 c
      return TRUE;
! v: _( P( C, L$ r. S   }1 P2 V0 n- k9 h, k$ B4 ^: \/ m4 A
   return FALSE;; j3 m6 @9 e) E  I# J
}  C5 c' ]- e) D+ Q/ M1 W- A# n+ Z
1 C0 B$ b% j+ Z0 r
Although this trick calls the CreateFileA function, don't even expect to be* g5 R4 m1 v# Y# Z1 {
able to intercept it by installing a IFS hook: it will not work, no way!
9 R: C/ O" D. V0 @% e3 J) G6 _In fact, after the call to CreateFileA it will get through VWIN32 0x001F
3 n5 Y% c) F( W# \: |6 I, eservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function); ?% F% b3 Q0 N% h4 v
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
+ h! i) r& a. T5 e* ~field.
* C* i8 p4 h  e. V) \" J* ]In fact, its purpose is not to load/unload VxDs but only to send a $ w' a% R6 v* U3 t% y4 s! a! g( ^
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
8 w; K( G  {; [) Zto the VxD Control_Dispatch proc (how the hell a shareware soft could try
7 L1 @1 e/ p- j" c) H7 Z# u$ _; Mto load/unload a non-dynamically loadable driver such as SoftICE ;-).
  B3 f& z% J- K4 A. O+ A7 BIf the VxD is loaded, it will always clear eax and the Carry flag to allow
* n7 m  e, o: f  |4 ]its handle to be opened and then, will be detected.3 N) J; o2 w% Q
You can check that simply by hooking Winice.exe control proc entry point
1 o# d( p/ e5 W; iwhile running MeltICE.
( G" E; o# I* x& y! s6 }; J# ?! T. }" d1 \! S3 w, Y- m

/ f0 H% b) o' p. d5 c  00401067:  push      00402025    ; \\.\SICE
  p/ j9 x# M( {  0040106C:  call      CreateFileA' P/ _3 @" A) `
  00401071:  cmp       eax,-001. Z. D3 @. Y0 R. f6 {9 }
  00401074:  je        00401091) X" h: s- S; j- b' L7 z; F

7 N1 F8 a. v7 C$ a# Z# q! G# i8 R7 w
There could be hundreds of BPX you could use to detect this trick.; m! K* M# _7 K  R* Y4 f' `' i
-The most classical one is:
1 p1 s4 y; ]) c  _( ]3 ]. Q  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
( [4 H" ^/ f) P! Y0 I& i    *(esp-&gt;4+4)=='NTIC'7 v+ @6 A( u$ G8 {8 v3 L
( Q2 T- e, _0 f  R  ]# A
-The most exotic ones (could be very slooooow :-(6 X9 C( }( E2 H6 E# G
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
5 }! {9 D: ~0 E3 k7 Q/ ^- d5 v% H     ;will break 3 times :-(, o6 k; t/ B# s! E0 }- X

% Z, j) s! K  o2 x9 ^-or (a bit) faster:
9 ]0 ]! Z: |; `; }   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')4 ^/ W1 [8 v$ C; j

; ~0 U/ f6 K# p- q* j   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  9 M' T/ H1 f+ ]  J- @( L1 ^
     ;will break 3 times :-($ Q+ }6 o+ `5 u! T

" _1 w  h( r5 \+ W" _6 t-Much faster:: l: u  N$ Q2 {& s
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
. p% e& z/ m, d1 d5 I) c, ]" Y9 _3 O, W& n& k2 m& @  \! I
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen# A8 J! p5 W5 X5 j- e4 g8 b9 A
function to do the same job:6 `. t" O; N# l

. a9 {* G7 a0 x, I   push    00                        ; OF_READ
% T, a0 u  l: g7 m8 y) v( Q   mov     eax,[00656634]            ; '\\.\SICE',0
# p+ p5 @3 _3 r" C7 Q   push    eax% ~" e! I( O6 W- x2 r% o7 a
   call    KERNEL32!_lopen& S0 k! B8 M6 J7 Y4 t1 E2 G
   inc     eax
; ^6 r2 u3 x2 U  F8 k! V0 S   jnz     00650589                  ; detected" q# I# g2 R8 A5 g
   push    00                        ; OF_READ  ^+ F( m' x. c4 X/ X
   mov     eax,[00656638]            ; '\\.\SICE'
) E/ ]4 Y4 W8 H* H$ p# N   push    eax( r( r; y9 R( V  ^
   call    KERNEL32!_lopen
; ^' \; J  I5 X. Z+ |* F   inc     eax
2 U: c: R) Z4 z( N$ A$ L- {  U, g( o- Q$ W   jz      006505ae                  ; not detected% K5 q. a$ I3 q! e5 U. ~- D% I

4 d. f8 i2 A: c; T) H
4 N3 b$ _: |, o__________________________________________________________________________) h9 T/ p5 t& `" p6 _3 @. t

0 y0 d' D, `  \: P. |Method 12
  [, t4 H8 z3 A/ f4 n=========
& ~7 n, J* C0 ~6 n0 |& E. v+ k. f6 ~6 |
This trick is similar to int41h/4fh Debugger installation check (code 05
: _  n6 J( U! H/ s* q&amp; 06) but very limited because it's only available for Win95/98 (not NT)2 ?, f  U6 V! _
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.6 B3 K, Q1 P% K, D' [3 _* g9 O4 \

' K% W) C( \  v$ X7 s* \) @2 }   push  0000004fh         ; function 4fh2 X# f; w' t8 O( G+ P* |. ]$ W
   push  002a002ah         ; high word specifies which VxD (VWIN32)7 D7 t; g/ {4 v) V+ z  S9 O& M
                           ; low word specifies which service6 s7 o2 u4 D) l) B- d8 X5 k. J
                             (VWIN32_Int41Dispatch)
1 |3 W/ n" K# E   call  Kernel32!ORD_001  ; VxdCall
. E9 {' u9 s- g5 s( C. O- h! Z+ x# u   cmp   ax, 0f386h        ; magic number returned by system debuggers
) @2 o. R, e7 o   jz    SoftICE_detected
3 u5 n' `- o* a5 U+ l+ p& J' Z( h
& r3 a7 m7 E  c4 p( Y, Y( g  {" e0 ^, tHere again, several ways to detect it:
3 o! u( b! r6 a5 F, ^
: {/ h; n5 z: ?: N5 y3 T6 t- g    BPINT 41 if ax==4f
1 K1 ~) a: C. {
) Y3 D, @% Z% S3 G. f7 O: g1 a    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
5 G5 X& P) {9 t/ f  y8 D/ |* N: P9 w* L. j. P3 [
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
* G6 T" o! x! t1 y! m6 T
2 M2 D' X; f# k, r  o    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!* O6 A/ o6 b' O" Y6 E: w* w
$ O1 U6 d' ], h: I& W' y) E
__________________________________________________________________________
3 |0 C. I8 |( u+ x. s4 Y7 ^  ]) o- ?6 p9 }
Method 13
* L. O& ~' K2 H  ^* n=========
7 r+ {3 v5 z& w; F5 N( m# Y% ~8 {7 y2 m
Not a real method of detection, but a good way to know if SoftICE is5 V  m, a7 R( p. T8 A
installed on a computer and to locate its installation directory.2 y$ {$ u4 b' K) X7 C0 f! H
It is used by few softs which access the following registry keys (usually #2) :% e1 E# j7 [: X# U
5 \. _  u& `/ W" g2 C
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion0 B  R$ h! ]9 m( @. t2 R" h
\Uninstall\SoftICE; B! K# d4 ], o1 p5 u5 y8 m6 L
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
  J; x  c$ w1 U  r/ `9 t-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion8 Z0 R9 K  a* H) j+ |- T
\App Paths\Loader32.Exe2 H" t) U$ G5 L( c% W: p
% \& S( Z2 K2 r7 J6 }( _

8 m& x+ u2 A  z9 m- a  F; N1 d" M  D: @Note that some nasty apps could then erase all files from SoftICE directory4 _. V+ |/ R1 N- S1 K- [
(I faced that once :-(
2 \2 ^; v! R; a( B$ A, d( v0 \( c+ @# Y% d0 X) ?
Useful breakpoint to detect it:- s4 Q7 L2 d9 U& M
- e, _1 p! ?2 X- ?! K7 i6 h
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'% h) D9 {! x$ Q/ I' p( p

9 k, S) M2 F' t- w& R& N: K+ d__________________________________________________________________________
4 V& d$ s8 J" J- p; ^* A) C
2 J3 y* B+ I8 s! t% ^8 u- G7 C& f6 K( N5 J  u; _1 A9 `% a# s# K
Method 14
" `& F" A8 S3 ], E=========
' x  O3 h. Z: O! ^: \% z3 T
; Y, Y! R+ m, n4 {( g$ ZA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose' i( V4 S# R' D/ A  i; j9 C
is to determines whether a debugger is running on your system (ring0 only).1 h, z. {) t' j  Y% b5 l
! J& K- r/ G0 u4 \" N! p9 F
   VMMCall Test_Debug_Installed
' C5 e1 U  @' [   je      not_installed3 x" B, }9 V- G* V% i/ O; v; b! H

- D4 G; |& u- ~2 D2 \+ M$ gThis service just checks a flag.
1 I; Y- Q1 l- A  E8 n! J( \</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部