About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>" D2 L. C6 n! p5 \2 K8 _
<TBODY>: s0 B4 l5 y; _# s5 P* T' U# t
<TR>1 K' Q% g( _( T7 T/ K- a  ]$ l
<TD><PRE>Method 01 & R# Y! _  q, r2 s
=========
& S3 T) u$ V, a, D, C5 z" f- N2 y  X5 ^) m4 D' Q) ^* v6 X6 h
This method of detection of SoftICE (as well as the following one) is
& C, |: d, p  e8 |8 p, Bused by the majority of packers/encryptors found on Internet.
7 A/ m5 _% A" s$ T  w" oIt seeks the signature of BoundsChecker in SoftICE# R3 m! f- C% a
) V! N. p9 {! _9 f# Q
    mov     ebp, 04243484Bh        ; 'BCHK'( t: w' p  _1 ?3 [
    mov     ax, 04h
) b6 l- B1 T+ A, ]1 [; H    int     3      
0 l2 ^3 q& d" V+ p' `    cmp     al,4) x' C  V: M% B2 o. R/ T+ d
    jnz     SoftICE_Detected& J- D& M/ b; z/ B; z
0 G$ l6 Z0 ]8 F1 J9 A8 W
___________________________________________________________________________. g3 j* |$ B0 F' Y' s

. o5 r/ w# J1 ~6 D5 YMethod 02
* E/ g. b  H  \2 G6 {4 B( p=========% j: U( l; Y+ t4 _, V( F- D% A

% ]3 f2 |9 f. f6 r$ `( aStill a method very much used (perhaps the most frequent one).  It is used7 S+ G5 q4 G1 g
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,+ _) N2 C( X7 X$ O: O/ r
or execute SoftICE commands...& j  m6 J0 G: ?4 C. T: y
It is also used to crash SoftICE and to force it to execute any commands
) k+ E2 K5 Z3 n(HBOOT...) :-((  0 N$ K1 l! y. P  b

! S& W/ S7 V5 E' m1 e5 CHere is a quick description:
: p' N: K% m6 y) A+ J6 H: ]-AX = 0910h   (Display string in SIce windows)" x; u% B* f9 Z7 o
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)8 Y5 R  d0 ], F+ p0 ~# ~: G
-AX = 0912h   (Get breakpoint infos)% w/ e. o" T5 w  r- M1 Z
-AX = 0913h   (Set Sice breakpoints). P- r9 ?# x% z2 }  e' \! ^6 [/ x2 j
-AX = 0914h   (Remove SIce breakoints)
% Y$ g* h: ?# S/ c' h7 N) z+ |- Z. R, t
Each time you'll meet this trick, you'll see:5 k; F0 q- i. c' r
-SI = 4647h% _2 M1 n( H- d! Q2 v8 N  q6 C- k. g
-DI = 4A4Dh) M1 R6 V& z4 u5 i9 T( k4 O
Which are the 'magic values' used by SoftIce.2 Y$ r9 r9 ]# _$ @) F7 }, F* p& w# Q
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
7 B  f# G5 c3 c5 Q# P4 h9 h& S% c2 s- v3 \
Here is one example from the file "Haspinst.exe" which is the dongle HASP+ Q) I/ d2 k$ r7 K
Envelope utility use to protect DOS applications:
, f: [$ Q7 |; R0 f# q6 `* S/ e; X7 d) f# z) t  o
% t) X! N' h8 I5 v0 u# j$ c
4C19:0095   MOV    AX,0911  ; execute command.
9 T1 p  S9 \) u% t; E  {4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).! z% a1 t' \6 }- ?0 N8 M/ V
4C19:009A   MOV    SI,4647  ; 1st magic value.
5 R; H& @2 W0 O: K6 u+ s2 R4C19:009D   MOV    DI,4A4D  ; 2nd magic value.# Y4 v2 Z; Z5 |/ \3 K4 M: i+ `& |
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)% }! x5 F, c- k0 o$ O
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute/ r- I& W8 o2 I5 i8 k
4C19:00A4   INC    CX
" z5 u+ e: x: \: P4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
. P/ @+ P$ g) R( [/ l2 ?4 h5 @4C19:00A8   JB     0095     ; 6 different commands.
/ b" l; e2 J( B+ W# u8 _1 X9 X4C19:00AA   JMP    0002     ; Bad_Guy jmp back.% v# j" D8 H1 G5 B. H8 u5 g
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)' u6 w$ {& B7 V
' c3 q2 W8 z# y0 P8 n. ^9 m" K# f* _
The program will execute 6 different SIce commands located at ds:dx, which( {( S& Y2 e9 a- S# Z+ p4 T$ \
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
" b, I+ v) }% W+ \" c; r6 f9 G+ S1 a$ M* F1 E6 o2 f% i
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.: ~6 G7 {! }4 I1 m6 m" g
___________________________________________________________________________
3 R  H4 ?; a/ c$ Z3 O, l7 g2 v; v. R1 e  {1 C. @8 M
% G; y4 o2 O. z3 q3 l
Method 03
$ c2 L+ i5 @) O7 o6 `& `% [=========  i/ X. U3 G/ d

% Q1 _1 ?1 P5 @Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h  ~3 e# U* Y+ R, v
(API Get entry point)
' i' o- S+ k, @/ H, r$ E- Z5 ?0 y        4 H8 I) O& @$ O- P- c/ \% z" |- L9 y
0 v* T' ?! o5 t; d
    xor     di,di
3 m- {7 D% s8 R+ Z  g9 s# p    mov     es,di
. F$ v- w  o6 \) h1 o    mov     ax, 1684h      
8 o: X5 G/ z- P* y( Y3 v+ E5 \    mov     bx, 0202h       ; VxD ID of winice
  O' F! n. S8 _/ u    int     2Fh" n6 x2 b& D. d! o/ Q! S1 \
    mov     ax, es          ; ES:DI -&gt; VxD API entry point7 n, D  E/ M5 i) U4 g7 M9 @/ U" d
    add     ax, di* F6 ]4 ?) z( G6 A/ X- A! I4 r
    test    ax,ax
3 F! L1 O* C# z: D8 w5 E) T  W' h    jnz     SoftICE_Detected
9 B( |% K+ K) M. |, Z. G, t
, N# k3 M- Q; ]) R___________________________________________________________________________
6 I9 h: e1 O- x/ i8 m" X2 I6 c9 q
Method 04; l  {2 H6 N3 M( s# p" X. N# ?
=========
) O+ T3 S) P. S0 s
, U' c. H8 U( M$ PMethod identical to the preceding one except that it seeks the ID of SoftICE1 W+ ]5 J4 h8 L( }, J- [3 s6 P
GFX VxD.
4 j) J& e) g9 x8 A( |2 C# K4 d9 W% K5 E2 z2 W
    xor     di,di& [" k9 o* N  D: o# A5 O
    mov     es,di
  r5 P  `# s# J% C7 M4 Q" y# c    mov     ax, 1684h      
1 {, Z5 R8 {0 |$ t% N    mov     bx, 7a5Fh       ; VxD ID of SIWVID
# G9 }8 t- S( P5 ~2 R    int     2fh
8 ?! W# `5 W& b6 L# _8 Y" [6 m    mov     ax, es          ; ES:DI -&gt; VxD API entry point$ A0 [& A' u* I7 {0 H
    add     ax, di
3 W1 N0 j' {( M8 _    test    ax,ax4 W2 Y8 }5 P& _0 i% ?* |7 @6 Y1 d
    jnz     SoftICE_Detected
2 W4 ~4 b" _) I6 _8 \  Y; i6 F
& e" M! d5 {! b8 U" ___________________________________________________________________________
9 I9 W1 ], i3 h0 B3 [, m9 s  o5 H3 F9 Q* |

! x$ S) J8 {7 D# p, K8 XMethod 05- x; s/ e# L* |3 ~) _, `
=========
& R0 y& Y! B$ f8 D7 x/ t3 V
3 ]* Z: o4 B4 q3 L) c) WMethod seeking the 'magic number' 0F386h returned (in ax) by all system
: O1 I. N8 H  q2 ldebugger. It calls the int 41h, function 4Fh.+ M( p2 o6 Q6 ~& O/ H& x7 i
There are several alternatives.  
6 w# ]( u4 I1 u' S) G7 K5 t: X
The following one is the simplest:
+ X! L% l+ ?% Y/ A8 \! Y4 }7 f8 @" s* L- ^$ a+ J
    mov     ax,4fh
' n0 B5 x( u7 Q: W, d/ v5 h1 D    int     41h) L* Q1 o0 u  w2 M8 r
    cmp     ax, 0F386
9 c' S0 p  T( B+ m& z& D) w    jz      SoftICE_detected
. A* m, U. u* }5 w; h# v' s7 ]0 b
, r# l* j3 W2 i/ |7 U0 h5 t
8 }1 Y' C/ e7 o* o% J' sNext method as well as the following one are 2 examples from Stone's 4 Q3 H% w# G3 W' I/ L7 l7 b+ a
"stn-wid.zip" (www.cracking.net):
! g- F4 Z6 i0 v0 H! q! n3 r* e) O2 p. D6 ~3 Q/ J+ H3 W+ }# Y
    mov     bx, cs' {3 j8 H: {1 t2 I4 Q2 Y2 q( B+ E
    lea     dx, int41handler2
7 `1 c8 [( B! k& f+ Z    xchg    dx, es:[41h*4]. V$ M$ D! `+ E5 Q2 B1 z' Q
    xchg    bx, es:[41h*4+2]" R6 X" F% o5 g' x' v! \+ E
    mov     ax,4fh
! _* @8 R# f. e4 o% O# h    int     41h
1 S% J* o2 B' E8 w    xchg    dx, es:[41h*4]
$ h& C; k2 R; }, c    xchg    bx, es:[41h*4+2]0 V* f# Y; W! a
    cmp     ax, 0f386h
$ O0 y; |$ f0 s" W2 y* j    jz      SoftICE_detected: g6 z- A* y; x
' B8 r; Z: Z5 j' q& _0 {# d. P
int41handler2 PROC
) z( [( W3 x- Q( C3 G    iret3 k. M# \& Z8 A$ N# x3 ]% F$ P
int41handler2 ENDP
5 a: [  r$ Y7 \, ^/ x2 \
  q5 S1 t. v. n7 D/ X! G( e/ q1 d6 F, N1 |
_________________________________________________________________________. K" g( r3 Y4 M1 C8 A# }

" Y5 ~5 M( S' B: h2 R5 @$ K  h+ E7 k/ y- q3 e. o% T" u
Method 06/ D1 u! t4 }" c% j
=========; F+ z3 }" k* H$ w3 G. j  r
& w1 I5 z% @" y& V6 l

3 K4 F3 _6 P% o1 C  n9 i2nd method similar to the preceding one but more difficult to detect:% q! f9 C2 ]1 R, U; b. P  ]: Z

" c: ]7 n( v9 F6 D8 R
' _2 c2 X" L* p5 r0 c/ i' Eint41handler PROC. D+ g3 y: S( P
    mov     cl,al
- Q9 U  P* ~, y$ N    iret( G3 J$ a2 ], y  o
int41handler ENDP" l; \8 L% m3 a7 h# u
3 @2 S0 ^0 U* A! n$ S$ Q. V+ ~

$ x% d7 D7 g( [3 u0 q    xor     ax,ax% b, v2 z, C; M  l/ y
    mov     es,ax# B: e* O; M- ]7 z( O+ j
    mov     bx, cs# ]5 A3 _& z% B: C/ J% F
    lea     dx, int41handler' l9 ^' n5 w) p+ O) P( F% ^
    xchg    dx, es:[41h*4]
# u1 Q* Z3 ^# [    xchg    bx, es:[41h*4+2]
0 g. s! X* x8 [3 s# B3 k0 l2 v    in      al, 40h% O! Z# ?7 b- [
    xor     cx,cx( N' d5 I1 C7 ]/ D
    int     41h
/ a4 b) Z) q, ~    xchg    dx, es:[41h*4]7 _4 k, D% c0 N- H2 j0 Q, j3 e
    xchg    bx, es:[41h*4+2]
; P5 B. A- g4 J    cmp     cl,al
# ?) x/ `" j# Z- O' y    jnz     SoftICE_detected0 e- I' l. `8 Z+ X" }6 y4 ?
- C) T1 g1 [2 t  |
_________________________________________________________________________
, y5 r/ v+ C# [. [3 f: U
/ k: Q* ^- L6 g" WMethod 07
, l' F2 S/ |6 \; q+ T7 g=========
7 J7 V$ p+ f5 @# E$ o) e! o$ n# q, m5 X8 I3 @' U9 f$ r+ _
Method of detection of the WinICE handler in the int68h (V86)
7 @" }( ^) k+ K2 d# r+ c" |$ ?! t% I
# E" H4 g8 |) ^3 P# @    mov     ah,43h5 f, `& O* Z3 \; o
    int     68h2 Y( d3 F; k  w8 }% b
    cmp     ax,0F386h
8 h! C6 u. l4 X    jz      SoftICE_Detected6 X5 {0 s2 R* V. X( ?

8 P6 {/ T3 w* }) {* d6 v
, [8 ?* a" w5 S1 a5 E% m) e=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
" O1 {( W8 t; V6 h+ G   app like this:
$ |& ~5 n8 @/ d, T2 _! j  k" _6 D& ]6 h. e4 `& m
   BPX exec_int if ax==68( ?1 @  f, }  p: c" W% `* \
   (function called is located at byte ptr [ebp+1Dh] and client eip is9 v. @9 S) c" R
   located at [ebp+48h] for 32Bit apps)
/ Y0 I1 t+ Z) ^__________________________________________________________________________. P4 m& h2 V! J2 B1 x$ v/ D
+ R3 D, s' |1 d0 ~. G4 P8 l

9 {, J$ w3 e+ ~/ @2 h1 G# VMethod 08
) i8 M2 }4 H" p5 M# w=========9 p, ?4 h4 f! J

; A" I! l2 C6 O& B# IIt is not a method of detection of SoftICE but a possibility to crash the
# N  G) Z2 J* p9 n; q: T8 Jsystem by intercepting int 01h and int 03h and redirecting them to another1 M/ V, b0 p' x6 [! k
routine.: q0 u% X% x: k3 r# W
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points( a$ p' L8 E9 D. b. Y2 E% _% I
to the new routine to execute (hangs computer...)( x& ]' c. \+ g* u' D
4 d" j- y/ {% r
    mov     ah, 25h+ g- x) ]6 N: e) b% W" ~* P
    mov     al, Int_Number (01h or 03h)& P1 ?1 L3 r+ x+ g  z
    mov     dx, offset New_Int_Routine
% Y2 ~8 q5 ^6 F" J2 n  o    int     21h2 x6 E6 _* U8 U/ Z2 E9 x3 a9 j

  f! s; X$ m4 a8 X3 e" d9 k! k__________________________________________________________________________
  K6 w0 d' }3 C! ?) ~8 n- [- f& N* K& }6 b  ~& y
Method 09- b- U/ u# n0 P4 W2 H# f+ x1 S
=========. v! y3 L, ]+ c2 X- y6 E+ ?
: O6 `/ m$ v8 n' z$ H& x; m) ]
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only8 Y* D' P6 \% b; [. P3 W
performed in ring0 (VxD or a ring3 app using the VxdCall).0 {; [6 e  A' [. L
The Get_DDB service is used to determine whether or not a VxD is installed8 Q+ c! w+ O2 r5 S/ G: |
for the specified device and returns a Device Description Block (in ecx) for, W- J# g$ w: d
that device if it is installed.
5 D! |  M, {( i* j6 F
* ?' o: {8 }0 d: g6 s+ C   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID1 h$ m! ^5 G; @" B
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)& W8 F) P) [& C; M- V& E
   VMMCall Get_DDB4 J, i! ~: u, b: W! U- i
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed. B! C5 `  W0 M

- ]2 _. T+ q0 {/ iNote as well that you can easily detect this method with SoftICE:6 o% t0 p( c" d% n
   bpx Get_DDB if ax==0202 || ax==7a5fh7 Z+ g2 t; J7 ~( T5 @5 F% d% ?0 I
% a" ^  P, u$ c8 A1 L& b' S7 |8 d
__________________________________________________________________________
9 Q( s6 Z/ X4 Y9 _, F
2 z1 T3 K3 u! Y  O$ D+ v: y0 z9 QMethod 103 B5 C' X* M5 D9 K  w. L
=========
, G- X8 _8 t+ t( |5 @4 i: P
, G6 X  J: L6 I=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
4 |  k* @4 F2 K3 Y$ }& |1 x9 q8 ^  SoftICE while the option is enable!!
2 ], K& g* G3 `$ w) S6 k- h, S1 D, z( Y3 Z7 r  t. S/ ]3 E
This trick is very efficient:
2 }) F0 F( |1 ^by checking the Debug Registers, you can detect if SoftICE is loaded9 {6 D, @2 n3 u( [
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
1 K! {+ y3 _& e2 Tthere are some memory breakpoints set (dr0 to dr3) simply by reading their
3 X! u2 }5 _* avalue (in ring0 only). Values can be manipulated and or changed as well
& N1 s8 @) {/ P4 R3 j# ^" B3 v(clearing BPMs for instance)
0 k; |; H6 S( t1 S" P/ w  Z9 a: E7 Q$ X2 s
__________________________________________________________________________& v" y+ ~9 z# |! o$ ^* Y

% }5 w7 @5 C( CMethod 113 }7 L- C$ s% e8 K$ }9 N
=========
* f+ }3 E1 W1 U/ ]
. a9 v4 q/ O" n+ W$ MThis method is most known as 'MeltICE' because it has been freely distributed
, H9 o* ~; N3 P! w. ^8 Evia www.winfiles.com. However it was first used by NuMega people to allow7 }& U4 x" O& k" \% E
Symbol Loader to check if SoftICE was active or not (the code is located
. ]. _* C" x' m/ x* E/ T) xinside nmtrans.dll).9 r' ~0 W6 ~1 k. {, ?

4 H; A9 [6 H! a& X) k! uThe way it works is very simple:
* Q6 U4 d8 ]% f1 g+ p0 y& p7 ^It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
" A; N" I' L- v: [WinNT) with the CreateFileA API.
, \, S& ?" x: D8 Z/ [( V" x) H& w& D6 {/ o
Here is a sample (checking for 'SICE'):9 g) ~0 E4 s- F% h( L2 ^  y) r$ ^
! }$ R+ c/ Z! O1 ]. t
BOOL IsSoftIce95Loaded()& {2 Z- M  V; E: s# |, L
{6 P+ O  ^% j1 ?6 s
   HANDLE hFile;  
9 v6 v# W0 [. U, F   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,. B0 C! m3 q" \5 K2 _' y+ c
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
- @# W3 o7 Q5 n' X  x3 ~* s                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);7 m$ P7 k. C8 T# Z
   if( hFile != INVALID_HANDLE_VALUE )
7 k9 y- r% R! `   {8 I( ~4 X$ k; S- j
      CloseHandle(hFile);/ t% J) o0 D  J6 c7 Q
      return TRUE;
$ D8 ?/ Q) ]8 G# Q: X   }( D. w2 u  Z. C$ h5 u: B
   return FALSE;! p' I# N6 _6 m. p2 S
}) s9 R( q% M) f! g' V4 t0 l
1 R  t5 e, g4 p4 m7 j3 C, Z
Although this trick calls the CreateFileA function, don't even expect to be8 Y# q* y( J; x. d: |' l9 o
able to intercept it by installing a IFS hook: it will not work, no way!, f8 {5 H% G- U7 m6 y9 B
In fact, after the call to CreateFileA it will get through VWIN32 0x001F8 V) l' Z7 f. C" T3 x
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)* J2 w3 {1 O# o. f2 T( d
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
2 F' U* _: `( W7 G* e0 d$ jfield.
5 T' D' u4 X0 KIn fact, its purpose is not to load/unload VxDs but only to send a
8 B: n* ^* }- l- b% U" ~, W$ z. O6 tW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE); u2 `2 C* J- H
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
& f4 |8 ]$ M# H0 b  J2 d, t1 cto load/unload a non-dynamically loadable driver such as SoftICE ;-).) h: b" M7 z% ^9 n! R% j: S
If the VxD is loaded, it will always clear eax and the Carry flag to allow+ Y9 Z$ x- @. v2 B8 M
its handle to be opened and then, will be detected.1 m, x/ j% ?- f( e6 D- H
You can check that simply by hooking Winice.exe control proc entry point0 X: V8 T$ Z, Y
while running MeltICE.  e! u% f4 P+ f/ Q) m( E
. u. G6 {8 k4 v. ?

( F  U# ]/ ?, U9 l9 Y1 k  00401067:  push      00402025    ; \\.\SICE/ I# W# ?% R! H4 B
  0040106C:  call      CreateFileA) s3 J0 y. q. ?5 t5 R0 J$ C
  00401071:  cmp       eax,-001, z8 t4 M7 F; T# L% k$ {
  00401074:  je        00401091
! Q$ r1 h8 b" q& H5 t/ M/ E7 |/ Z7 C! o7 A

5 v3 Q1 x7 }. s% IThere could be hundreds of BPX you could use to detect this trick.
/ o3 d: |3 x1 m3 y! [, n$ ^-The most classical one is:+ [6 w0 Q  P% w
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||  H4 w( K! A1 H2 C. h0 i: B- `
    *(esp-&gt;4+4)=='NTIC'
# O( u! r( C$ z8 P4 U2 I2 w' S
0 F& \! v1 ]; U4 z-The most exotic ones (could be very slooooow :-(
( ~. |8 _; D$ m; m/ n/ p   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
+ p7 ?+ W3 i7 e& A1 k! _- x     ;will break 3 times :-(
3 b: T7 \8 N0 b/ `
9 u, u4 a" h2 ?2 j$ w# P* K, x-or (a bit) faster:
; Q& |/ a# Y: Z" H- K* z* j, d   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
- |9 o6 w. Y* J  _
; z6 b( z" w; c0 P8 G   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  ' @* P9 t/ j& b3 X- m1 e. s4 H% ~
     ;will break 3 times :-(
$ o' M/ }& a8 s1 @, o
+ ]# Z8 l2 z* d( i9 b/ p0 ?-Much faster:
8 b# f* A6 H9 B7 @   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'! i; W2 d/ b; b1 R" Q0 J1 [# A# Z4 ^
" }3 F( n$ T/ u0 Y
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen  `6 J1 w; ^& b5 W9 B, c
function to do the same job:
4 u  |. y6 Y' T8 h
0 X4 I  A5 z, {0 j, K   push    00                        ; OF_READ
- k* N$ D" t5 r- [3 G2 {   mov     eax,[00656634]            ; '\\.\SICE',0
' {0 G" |, m& t" K4 F: }; ]   push    eax
8 v  E2 e& h8 [% D& z   call    KERNEL32!_lopen
# |7 n! Q0 x+ h8 y   inc     eax+ @# Z' j( o0 r; t+ ^
   jnz     00650589                  ; detected
# ^' ]3 }$ Q" _: V; g4 K# I2 x6 e+ U   push    00                        ; OF_READ8 d( G3 m  _. t7 v
   mov     eax,[00656638]            ; '\\.\SICE'
: V5 _$ c; h* l. f$ E% I$ h   push    eax
' `# D$ {' N- J7 {/ }- ^   call    KERNEL32!_lopen
$ P4 q) F4 e  d6 P! R5 F  f9 x   inc     eax
$ ^% h5 A9 U$ }; i7 ^0 f   jz      006505ae                  ; not detected2 r( p) h( \5 C; C5 C

6 j1 o1 \: l: ~/ `3 `1 z  K6 D9 y' K+ a% t8 C4 ]' @
__________________________________________________________________________
; j! ~6 |0 E$ K, C4 K. z. R/ ]1 _: f9 s2 d9 `* N
Method 121 @# O; R4 j7 M. S* H: ]9 Y3 q
=========" F8 f1 H7 k! L, x" c

4 U5 x" |: Y1 lThis trick is similar to int41h/4fh Debugger installation check (code 05
" e  _, S, P2 _+ \7 g. a&amp; 06) but very limited because it's only available for Win95/98 (not NT)7 k" h2 R3 P0 I4 h. d8 v- z. `: q
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
; z7 c* Y8 j% c: y+ v/ Z
* T9 c; B+ M* ^" _4 q   push  0000004fh         ; function 4fh
0 A* |, K2 Y1 u! `4 w" u1 i+ F; ?   push  002a002ah         ; high word specifies which VxD (VWIN32)' k) [: K) l/ l+ g, p7 B& O- C
                           ; low word specifies which service
$ o1 [- L& _4 r7 f/ m8 n1 d                             (VWIN32_Int41Dispatch)
: z  U9 V4 d6 M7 _* K' N2 R; Q   call  Kernel32!ORD_001  ; VxdCall. X- L/ p  v7 q7 C! d
   cmp   ax, 0f386h        ; magic number returned by system debuggers
( c# K, l: N8 Z) W   jz    SoftICE_detected
! o3 t0 T( t; H* Q9 u( Y% x+ ^$ I( a, w8 ^6 _# K/ l2 F  Y
Here again, several ways to detect it:
7 Z! c  d  i- P' v2 l% ?. d; b
9 Z" M, x8 b; t    BPINT 41 if ax==4f
- h- H* ?6 E! \; _( N7 H
5 S8 R* H& W7 L% w- }3 s9 `2 i    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one& u* k8 q- B! e
0 X' t6 ^  x  C1 e% Y
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A3 I- d3 Z  s# q( [5 b( v+ O: U: t! c
5 m: T: a& M3 u$ i* J4 m- F, V5 `
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!9 {  T8 p8 d9 k

, ~+ f& W% J. k__________________________________________________________________________
' H0 W) Z2 v. N0 L& |' U, c" ~1 s* c" h/ s# U% ]  F
Method 130 P& E6 [+ i" ]8 ^: n3 F. G
=========: E3 a: Z; ]& j  j. ?

/ X! S1 \& ?* y; o- ~) GNot a real method of detection, but a good way to know if SoftICE is
/ x# [- t( R2 w7 ]2 `installed on a computer and to locate its installation directory.
0 g  C  k/ O; b& u* D( ^It is used by few softs which access the following registry keys (usually #2) :& v; v' I$ u% _2 d+ `
! |1 i# A3 s+ I; {
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
2 a- m% f3 Y5 P. P% M: E. c\Uninstall\SoftICE) q# H8 B/ p, R0 B
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
; m% w. h- v, x1 I& d0 A2 r-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion4 v) b6 f4 P  |  G# H- L. _0 _3 _
\App Paths\Loader32.Exe
9 d4 I. Y- p0 {" ?; |- W. }; c5 \" q. F6 P
- d  G  F, X2 D0 T6 A: P. D
' U0 F# s" w3 nNote that some nasty apps could then erase all files from SoftICE directory% D$ A4 _: X5 L. z& {! x8 S9 I& _
(I faced that once :-(/ r: }/ Y& X, k6 q8 L7 U) O
& z( b1 |$ X- l* P) V. b
Useful breakpoint to detect it:
: E( p1 C6 ~: B( H9 r# U2 Y8 @% [. Z6 i: d: T) L( j' f9 M
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
  B0 |/ u3 y, U5 g$ Y  q+ [1 r) V1 o* l. Z  i3 ]
__________________________________________________________________________* a. Y% J. q4 g  f; n5 A" O  b

4 A4 c" \2 L- B- |. t
% l  W6 @, g5 HMethod 14
/ f1 k1 O9 o8 p=========( w3 ~/ C8 O; D* U$ A

" M" ?2 c) T# s) z% B, FA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose' Y2 ~' J0 `. j! Z  y9 X. ~
is to determines whether a debugger is running on your system (ring0 only).$ D/ o' U5 X3 c
: [' Q1 h3 ^7 u. ]& ?: K7 \& e
   VMMCall Test_Debug_Installed3 F" k7 f; }8 v8 R3 F! R
   je      not_installed
: m$ M) W! c5 d  b/ S/ ^" d' y' Y
This service just checks a flag.
0 L# V8 l: ~- l% W$ b0 r5 j</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部