About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
& K  m! J& M. p- |+ m6 V# }7 P9 \! M<TBODY>
  x% p& @9 v" U& @3 A<TR>, h: w* [' z# f8 K: u# Z+ S/ l* z
<TD><PRE>Method 01
6 a- O$ K3 G+ g/ [! H2 }. y% A% V8 e=========3 I8 V# q% X: w# z  `* v

2 A' {9 d5 m* a+ O9 MThis method of detection of SoftICE (as well as the following one) is/ d8 s% P" K* q! d
used by the majority of packers/encryptors found on Internet.' U9 m6 x) Q6 `" s& Q; H) N" m
It seeks the signature of BoundsChecker in SoftICE2 B* z6 W" ~7 [

' J. S) b, u+ e    mov     ebp, 04243484Bh        ; 'BCHK'
8 H9 o) ?2 @) v+ l: |0 ?    mov     ax, 04h
( q! f8 a! z0 ?: M* ]4 m, A    int     3      
+ t: a! K" x2 s    cmp     al,4
# ^5 `: d' }' q' b" _$ o6 w    jnz     SoftICE_Detected
5 ~- W; n* S( b
9 y( p  }. u$ ^9 `___________________________________________________________________________$ ?/ p8 J2 z+ P& k

  U; ~/ A$ u6 Y" U0 w; o6 BMethod 02. X4 U5 u& s- W: ?9 ?0 K. f
=========) I7 U0 }) L- J; Q) c

0 |6 e4 P1 V/ ?3 V0 FStill a method very much used (perhaps the most frequent one).  It is used1 b; B: y1 n2 @8 k
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,# e3 V$ G4 m8 @* x! w
or execute SoftICE commands.... Z* K) A1 N7 |% [1 H/ A
It is also used to crash SoftICE and to force it to execute any commands" }9 W% j5 T" C3 F* K! I, @" u* ?) S  I
(HBOOT...) :-((  
; t9 }  l" B6 @; C' z" Z( M! O' j1 Y6 r  {" t& Q
Here is a quick description:
1 K) q" W) b( w' q& z2 v- \-AX = 0910h   (Display string in SIce windows). x1 R& D! G1 d9 @- U8 X
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx), s1 x$ R( Z2 z% W: {- }: v" q0 V- A8 Z
-AX = 0912h   (Get breakpoint infos)
& U" {* i* T, E; f" F! m% `4 G-AX = 0913h   (Set Sice breakpoints)
) I$ N6 y+ D/ m  ]" W- T-AX = 0914h   (Remove SIce breakoints). h! e3 j2 T3 s

" c3 Y: k  c( z" eEach time you'll meet this trick, you'll see:
7 a6 e. W0 r8 f; E-SI = 4647h3 b; A" e6 x# I$ x9 a
-DI = 4A4Dh7 Y' B% q+ L7 L! o$ ?# O. n+ z& ^5 U
Which are the 'magic values' used by SoftIce.
( ~1 U+ z1 V& U5 n+ e. z. kFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
* P" W. _% n  `. v. E
0 \1 m5 W( p' t" j1 }) f4 M$ \Here is one example from the file "Haspinst.exe" which is the dongle HASP" F. _# ~$ P/ P3 l' Y2 c
Envelope utility use to protect DOS applications:
0 J! e. c( m3 ?" w& i$ |7 s. q3 K- T- L# `
: |! c3 G0 L5 W( T5 k
4C19:0095   MOV    AX,0911  ; execute command.  j" F. y6 [2 u, E
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).& n$ ]2 D6 k" x) z, A2 r
4C19:009A   MOV    SI,4647  ; 1st magic value.
: T! I2 F, s7 _& y, P9 C6 J& S3 N4C19:009D   MOV    DI,4A4D  ; 2nd magic value." v$ m. D# w) i5 d
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)5 Y9 }5 J+ K, t0 P) C; G
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute5 p  ?# g7 C% x% w  t  p, G
4C19:00A4   INC    CX
- B) P, h0 ]9 M, Y" i4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute% D8 i. Z8 ?* K) Q" O$ F
4C19:00A8   JB     0095     ; 6 different commands.: k* x, k* h& u) h& @: d
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
2 {7 Z( A" V  h4 W2 o4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
+ M& ~! ]5 Q3 |; Y
6 i8 S& a7 c9 ^2 I3 s6 P( [- i/ Z2 dThe program will execute 6 different SIce commands located at ds:dx, which& D+ B" V8 t$ c6 T) u8 ~
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
0 n* e: R1 o/ h8 s" T, e
9 }* {* o. z$ p; X9 m5 _3 _* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.: {* S. K" @& J
___________________________________________________________________________
- H  |7 l$ `5 M9 A2 M
5 `- B5 h4 f) J! k9 A
' O& [& J$ `# m$ Z) H. ]( \Method 03
% ~+ w& x# y* s$ C+ x  V=========. w& ~- r6 [8 e! P  T* H, `
( s6 |9 q5 ^3 w/ `: t7 `
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
- L4 [: x+ U! O: ^$ _6 V( j( _(API Get entry point)6 j: L$ s# A9 \, x
        
0 y# @5 Q2 j/ s$ y2 F0 D! S
9 c2 y: J' u) C; r8 N$ n    xor     di,di/ m& J/ w- ^( y' y- g" W: l/ P
    mov     es,di
7 g2 \* `, X& z2 f6 ~& S7 ]    mov     ax, 1684h      
# G! ^4 A& U& `* ?$ [$ J0 b    mov     bx, 0202h       ; VxD ID of winice8 u7 [/ E9 ^+ R/ p; h, J
    int     2Fh4 O* c. E- S. y* W) F# b
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
9 z% [/ `, }! h, r    add     ax, di
" f. R/ o! \2 ]/ i( U8 R' X) r7 j; x    test    ax,ax  L- ^4 V- ]+ E4 e* D" g' K
    jnz     SoftICE_Detected
: v# A$ b2 e) P  |. A* j! b! i
2 ^# w- d% U8 e6 t___________________________________________________________________________
# w$ x% Z1 ]! F9 k
8 g- ^  O2 L, h9 FMethod 04
7 R+ [) n1 M/ ], _! \8 S, M=========
5 m+ g$ }6 D3 o* Q3 B  _# O6 z4 I7 I* L: I: X. O9 ~
Method identical to the preceding one except that it seeks the ID of SoftICE2 Y$ f% D$ V2 m* H7 w1 [8 G! u
GFX VxD.8 e+ M3 }( s, z: o& G

6 Y! j; t# S- k+ s4 C3 q1 U    xor     di,di
5 ]5 Y% s  e4 t    mov     es,di) w% m7 H/ ]1 H( e7 w
    mov     ax, 1684h       ; P9 F/ ]8 `3 s3 {' J
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
, N! y( H0 d+ e- m- `0 s    int     2fh
, a0 v2 j* `7 l, ^: Y6 Z  Z9 h& }    mov     ax, es          ; ES:DI -&gt; VxD API entry point
/ |9 @+ u8 X; G: U) C& P( j2 Q' d: }    add     ax, di
5 n! Q% n3 P1 E1 @( e2 y. n- w& x$ S# y    test    ax,ax
! F& L) Q+ \$ m3 p7 j. @    jnz     SoftICE_Detected
+ t* Q. I" ]: O+ G- ~  Y" |6 F! ~- @5 Y( T& z
__________________________________________________________________________+ Q2 e! Z# @" }, c
: r0 Z+ g3 J  |' D( d- f5 Q9 }: S( s; o

# h- Z5 j, a2 S/ ?. x) xMethod 059 c- V# b+ o1 q- @  \0 H( T
=========
! S. g& g' }& J, {
1 R6 ~, x' U+ y- G4 N' NMethod seeking the 'magic number' 0F386h returned (in ax) by all system
3 J2 E& C: E% C4 Ydebugger. It calls the int 41h, function 4Fh.' v5 C8 x2 A! A) {) x
There are several alternatives.  
3 h: v' S- p: Q5 P* P$ ?4 w
% a! @, h5 v4 N5 o2 ^The following one is the simplest:
, ?" Q/ N4 B& {3 @
2 w* e! d0 o/ H. F& S    mov     ax,4fh
5 L& G$ B/ G0 j9 `, A4 s    int     41h
& }7 R% z, q% a$ N! h2 F6 g    cmp     ax, 0F386/ E3 }6 L, L$ T5 n  n, b) v
    jz      SoftICE_detected
+ m3 o% v( m& z1 {+ r0 e1 l3 r' v0 h5 Y" C1 V) w4 s
! P+ X! ^: {2 W
Next method as well as the following one are 2 examples from Stone's 2 i5 s4 T( e; e# D/ K# R
"stn-wid.zip" (www.cracking.net):
9 p' s: N/ V( t. J! B# m
& O8 T- h9 M2 ]4 d8 v    mov     bx, cs
6 u  A" e5 g4 Z* n    lea     dx, int41handler2
/ l7 B/ p1 e  X" W4 s4 W    xchg    dx, es:[41h*4]0 s8 V7 I/ ~- Y& b9 ?3 o
    xchg    bx, es:[41h*4+2]. c% j1 v. r+ G& c) P! W
    mov     ax,4fh
# w( m: T" @$ R1 \% k+ g1 s# S    int     41h
6 l2 c- J+ Z- V% G6 u1 d, ^    xchg    dx, es:[41h*4]
: A% Y0 }; w, K2 L2 I, e  M    xchg    bx, es:[41h*4+2]
2 K4 B, U0 j* g' D. F    cmp     ax, 0f386h
: L* |" K! C5 p/ C; K    jz      SoftICE_detected6 ^  Z1 o5 `4 q( B% {
9 ^+ Z# A& U; d4 z% z
int41handler2 PROC1 d, n! P4 _  N# \+ p
    iret
) ~4 s; N, |7 Q1 b. D) {5 }" _3 Qint41handler2 ENDP" E! y. q8 D8 s* V- D* I

6 R2 O" s8 }2 b; p" v! F( i7 n# z  ~& y9 t  H6 R4 R# J; H8 K
_________________________________________________________________________
/ I3 s5 g+ m9 o* S- K. f. Q* x) D" o# D
9 T: h+ S7 l" E5 a5 r
Method 06
; o1 t& x4 m- W  G, U+ V0 j=========' c2 p% }" P1 j3 v: Q6 O! R  s0 Y' r
5 J; W* o2 d1 E$ W
+ b' n! c: W& A3 ]- V# B( T% y& N
2nd method similar to the preceding one but more difficult to detect:
5 S3 }; D; {: U5 N
4 x7 g2 M) C6 s9 P- u* L5 }
# @+ j3 r3 A; s1 E0 Q# dint41handler PROC
1 a, h. ]# N( w( b    mov     cl,al! {& N. |( m( n2 w, g' i- ?3 B
    iret3 ]+ a2 Z  ~  v, m! Y
int41handler ENDP
! J. K6 ^/ Z6 X! K7 \0 @" F3 e  ?2 l1 z

$ V2 K  h; i1 f* j    xor     ax,ax- X9 i5 l, L& ?: b! O: k
    mov     es,ax4 V' X% [+ k6 H8 h/ O
    mov     bx, cs% o, J7 _+ C6 F+ c6 |" W) l
    lea     dx, int41handler
& T) I& a9 k% ^3 A' s: _    xchg    dx, es:[41h*4]% f" }: O8 Z6 x& |! e
    xchg    bx, es:[41h*4+2]
. y. S' C$ c/ R" N( E: N    in      al, 40h- E" w; j0 l' H. z( t) Z
    xor     cx,cx8 m) C9 \4 ^' q; z, q4 U* U7 `  f
    int     41h
6 p( h0 C! P3 w) ^) d    xchg    dx, es:[41h*4]
0 C: y! e5 U( J# W    xchg    bx, es:[41h*4+2]
% y. a9 p! R; ~# q9 u0 g- z. @    cmp     cl,al
+ P$ m7 b# K2 J1 z, {    jnz     SoftICE_detected: u, L' U" C# P

9 Z" r; d- F5 Z) @, c! |/ D0 _- j_________________________________________________________________________9 Z2 g9 W) d2 H# ?5 d, f
# |$ _4 g$ H" ?- _) r
Method 07' ]( `$ w( o$ n
=========& B; t6 i- v: u0 x9 c; M0 s" f
4 l. }* @3 l+ m6 f/ M# W0 u
Method of detection of the WinICE handler in the int68h (V86)
6 S& ], M: M( {! f6 N3 L& c& T& ^' s4 C6 C! M' r$ x) T
    mov     ah,43h
- H2 W2 K7 O! B! J6 c2 D( W    int     68h6 t1 r4 S% a4 H8 w+ a3 X
    cmp     ax,0F386h1 m& a6 E8 q# C" {
    jz      SoftICE_Detected
5 L" y, h0 I% K! u* c4 u5 v6 \3 s
+ j2 Y5 p7 W- d. P  Z
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit3 r  ~5 J$ M% n3 F
   app like this:. s! H7 [$ ]- I6 k7 W0 l
; D2 E( ^- t# y
   BPX exec_int if ax==68* A' |- W1 i: W1 L1 r# c3 z; K
   (function called is located at byte ptr [ebp+1Dh] and client eip is
1 j; M3 d; N# T) g8 [# S   located at [ebp+48h] for 32Bit apps)- s0 u9 p& D' R# _2 s  J
__________________________________________________________________________, S& L; ~3 V6 @, m) l$ t
5 }. O1 u  p8 A5 R0 h

5 ^' C' V% p' {7 p0 y. ~' n7 PMethod 08/ [9 r; f6 U- f( E" U4 @8 }
=========; k9 \0 }# C) K5 N- {8 G
, O, I4 F* W8 V! Z. z
It is not a method of detection of SoftICE but a possibility to crash the1 i' B# Q8 o! O7 ^( [0 I8 L
system by intercepting int 01h and int 03h and redirecting them to another) g" l6 N, T9 y& L, E- T. H
routine.
/ p6 T5 k& u9 o0 h2 T, XIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
, ^% Y1 m: j1 z, |3 o" P* Yto the new routine to execute (hangs computer...)
: t5 W/ ~; E3 w0 v4 ]# ^" F' O4 Q8 u3 R) B
    mov     ah, 25h
. p2 z/ @  ~! T  D+ F; D    mov     al, Int_Number (01h or 03h)7 B0 S5 C* S! k" C( B. o; I
    mov     dx, offset New_Int_Routine
2 _, g6 t( ?4 x: Z2 Q    int     21h4 p! u; V* d" }
! N, [9 r  h. P6 y* a
__________________________________________________________________________, e- E6 s5 I. w: N8 K- V
) E/ O9 \- G$ h' x, H8 @* j
Method 09
, a8 L. a  {! f=========! X5 V: c, K2 I$ F7 X3 E4 G

! s  f- F4 j, }$ C6 r' aThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
& \/ f6 k2 m& ^$ @performed in ring0 (VxD or a ring3 app using the VxdCall).' k- G7 `! T( u  ~* F! |3 A: d
The Get_DDB service is used to determine whether or not a VxD is installed
% N. v9 x" K( K5 _for the specified device and returns a Device Description Block (in ecx) for
" w  i$ m4 a. athat device if it is installed.! y3 `. u6 s0 A
' d. T( n6 K; Z8 @" J9 p  R4 r' f+ j
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
$ O5 X8 |$ N4 H2 ~! R% p4 R   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
: e) f; ^4 I8 V( K# ?7 A  Y7 J   VMMCall Get_DDB
' ^# T  X) e. j% S7 f( [! ]+ E   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed5 Y7 ]. K! A2 s% I& u

5 |$ m8 l+ P8 s& f- KNote as well that you can easily detect this method with SoftICE:
9 c7 k# o+ G$ J6 e; n8 @' L   bpx Get_DDB if ax==0202 || ax==7a5fh
, U5 f4 C1 }& H
% i. d2 k  E7 l* a2 {( ~__________________________________________________________________________
/ t/ J" g) D3 ^6 p5 l
& i2 H( B8 r+ HMethod 10, s) a& }$ H& P( N2 U
=========, D& u6 K; a4 n5 p9 {
+ u+ K6 a7 p2 i; h( o
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with% N9 ^: m% h2 N" T( j6 ^" z9 K" w
  SoftICE while the option is enable!!
" y+ {4 {. \/ l. i
4 K7 I& n$ i* ?) a3 B5 @/ mThis trick is very efficient:
( P$ l, n+ _8 {by checking the Debug Registers, you can detect if SoftICE is loaded( e2 L0 G1 t' V% m  k% y
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if9 `! _+ J* q  t
there are some memory breakpoints set (dr0 to dr3) simply by reading their3 C' n. o* |" L2 d% W/ V
value (in ring0 only). Values can be manipulated and or changed as well
' \' o; I  a& Y/ W; W. ?" s% D(clearing BPMs for instance)
) e, E4 \; A' i9 z  H: L2 w( n. W
8 F: `2 O1 l1 q$ \! k: L: F__________________________________________________________________________# n3 _4 e3 k- d) w
+ C2 g9 f) O* Q& B4 i, i" B
Method 11& J$ L* j1 Z+ h; L2 X  `
=========
! Y& i8 r! o2 ^6 V# c& j2 o% r, z' }$ W9 `* i" f8 c. @" q" ]
This method is most known as 'MeltICE' because it has been freely distributed: [6 K: @4 r$ l+ o6 t- Z
via www.winfiles.com. However it was first used by NuMega people to allow- d/ H( n4 p6 a6 ]3 O% W
Symbol Loader to check if SoftICE was active or not (the code is located& B9 ?  t4 ?  d: H7 X% ~! }6 u2 C
inside nmtrans.dll).( j' J, `) V9 I* p* H; w+ D
2 B. [( |( M/ M# P% I8 ?. d6 X
The way it works is very simple:3 }: W& V, }  T1 C8 W. e4 u
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
3 i0 }/ w5 \& f; [# FWinNT) with the CreateFileA API.  U/ N# r$ ]  ]: z5 r

* m" B6 d4 @& m/ PHere is a sample (checking for 'SICE'):9 I! V$ e2 b6 [9 u& q
. |3 R0 L. G6 j/ _' p3 @
BOOL IsSoftIce95Loaded()
2 J: X3 q: ~5 J8 F! g1 i& q* |) i{4 }" |5 O$ }: N! T8 q4 `
   HANDLE hFile;  # x- q# c3 E5 c  c8 B, I4 t7 H
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,; b1 [( q  F' V% ~+ f" |/ x) m2 c
                      FILE_SHARE_READ | FILE_SHARE_WRITE,4 S* p$ Y0 g' |# z9 e4 o
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
1 [' S* o# @2 I  ]   if( hFile != INVALID_HANDLE_VALUE )
9 s/ ^6 J: j8 {   {. E9 C. U1 z" _6 Z5 ?  `7 q! L
      CloseHandle(hFile);0 O2 t7 D0 d& ^
      return TRUE;
5 F; s; V7 b) k% k! L3 R   }
' {, r2 \3 M4 I" o) k+ n   return FALSE;
. i1 q2 H# b# w; {5 Y( j6 H}
2 O8 q# U( ]  m2 m
) B% W: ^  O: w/ ~Although this trick calls the CreateFileA function, don't even expect to be
0 f) c1 `7 H; wable to intercept it by installing a IFS hook: it will not work, no way!$ j7 r1 j6 Y  Y# x9 Z
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
- T, D% n; d0 }  X/ R. Lservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)3 p2 i) Q+ r. d  M; Y
and then browse the DDB list until it find the VxD and its DDB_Control_Proc" x# _- d3 C9 S6 b3 c7 f
field.+ S9 j' T% e* f  A, E# G
In fact, its purpose is not to load/unload VxDs but only to send a 4 v. l2 Q# p4 H! O0 r8 }% P, F5 {
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)% Q% G  Y- g8 P4 U: J
to the VxD Control_Dispatch proc (how the hell a shareware soft could try/ v/ S9 ^- \/ H( d6 k  J2 Q
to load/unload a non-dynamically loadable driver such as SoftICE ;-).! [" ~! K/ r( U2 I( D0 \
If the VxD is loaded, it will always clear eax and the Carry flag to allow% ^. q( ~* B, i% ?. x. [& L/ x5 s7 r
its handle to be opened and then, will be detected.9 B. y7 l. l- ~1 B) z3 w* {7 Z& t, @
You can check that simply by hooking Winice.exe control proc entry point
; I  r/ ~! ]2 i5 Y/ c2 Ewhile running MeltICE.
  I0 E% T6 N0 K$ n" |3 ^( ~$ B3 D3 L4 {% N8 U0 b% x1 C% L  g

' g2 q& I7 L# t+ Y# d7 p: ~1 t; I, v  00401067:  push      00402025    ; \\.\SICE' s- B6 X3 N& x; C
  0040106C:  call      CreateFileA! R9 O2 _0 H3 g$ S) i# W6 t2 x, G
  00401071:  cmp       eax,-001
: J/ F+ H% @. @$ Z# @( m- R1 g  00401074:  je        00401091! A% Q4 L% T; h" C- U( Q5 ?
% x0 W) E7 [* B) y. Z* C
+ A7 ^* M1 t# A& t* d. s9 x6 g$ P
There could be hundreds of BPX you could use to detect this trick.
. r/ O- L2 Y1 ^. ^- h$ S-The most classical one is:
, d, I+ Z5 X% P9 {2 @) |* ^  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
" z6 P; C0 i+ E6 M. k# [* |    *(esp-&gt;4+4)=='NTIC', D2 G, f7 L% X/ H; N

% _: G* k5 n$ m# B0 h; Y-The most exotic ones (could be very slooooow :-(
! q& x+ v' A! s   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
7 R& K5 h+ g1 e- A# L  r     ;will break 3 times :-(
; }" @1 }2 _7 Q( O2 H3 r" R! O3 [6 N* b- d
-or (a bit) faster:
0 Z" E+ ^& K/ g. O- c8 M( A( ~   BPINT 30 if (*edi=='SICE' || *edi=='SIWV'): G5 g( @# z' F& v6 T1 y
- y" x/ [4 f# N% O0 q2 T( C( B5 T
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  & F2 Q! P0 G& p7 d. _! B1 f
     ;will break 3 times :-(
0 X) o. K  p, J( u: @, Q: \2 n+ t
-Much faster:
0 {) W+ d/ w) T# G   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'+ J, G) |# w5 ?

" A  Q* _6 c4 s. _Note also that some programs (like AZPR3.00) use de old 16-bit _lopen) q/ k! `) I. [! l2 I7 j: @2 L9 }
function to do the same job:
8 L+ M* k. ^* y0 i6 X/ N2 f
. }+ V) C0 Q4 G: P  r7 A2 q1 w9 ]   push    00                        ; OF_READ
/ S- W6 I/ d7 j   mov     eax,[00656634]            ; '\\.\SICE',0, c: W' U2 i. p; u; t
   push    eax- x9 T7 @+ G* `) m/ B' [6 T. D
   call    KERNEL32!_lopen
+ w$ K5 p  i8 G8 `! p   inc     eax( j/ D; G- k6 Z, I
   jnz     00650589                  ; detected
: I( N5 y4 |. {) Y   push    00                        ; OF_READ
" v, l6 `6 c  P3 N   mov     eax,[00656638]            ; '\\.\SICE'
  m/ t# x2 e6 t  x   push    eax
' n# X  f9 }0 a3 S4 V! \" b   call    KERNEL32!_lopen4 A0 j# a8 r+ H) x8 k1 K# {
   inc     eax1 q4 J: l( |9 k: |0 D" m4 f
   jz      006505ae                  ; not detected
" E0 O; v, w  \0 h1 Z
8 N; O- P5 Q8 c& S2 j$ Y+ J3 K: G/ Y/ |
2 w: h% _* z: c4 f; R2 J& l) t__________________________________________________________________________, o2 T6 C% L, z
8 t) Q+ t- ?1 Y8 B
Method 12' N9 r5 {3 A3 c. `# f" M+ Y* i# S
=========
* l3 [( e/ |1 s% g( B0 Y
. h% W/ i- [- T7 uThis trick is similar to int41h/4fh Debugger installation check (code 05
9 W" I/ W# q, X&amp; 06) but very limited because it's only available for Win95/98 (not NT)
, h8 f: o" d- p2 D+ ~; H# mas it uses the VxDCall backdoor. This detection was found in Bleem Demo.6 u3 T4 @- z- p
/ h, s8 u4 N( @8 G8 g
   push  0000004fh         ; function 4fh
9 z2 k, K8 ^- m   push  002a002ah         ; high word specifies which VxD (VWIN32)' @0 K; b6 A5 W8 y9 i3 d
                           ; low word specifies which service
2 t* ]3 ~% b% T4 D% q                             (VWIN32_Int41Dispatch)
. K7 \5 o; r, X) A2 P  Z, W   call  Kernel32!ORD_001  ; VxdCall
9 L8 i4 d0 q' Y" d/ _2 R6 r& ^+ B   cmp   ax, 0f386h        ; magic number returned by system debuggers
1 O9 [: |! v" Q6 n/ c9 E$ O   jz    SoftICE_detected& q7 x* q# j" |# L6 X: L" g- z
2 p- ^5 D; E. S& a0 R
Here again, several ways to detect it:( u( b3 d" O) b* a5 h( W  X3 V

$ N5 L2 v) Q6 |! \  e1 o) G1 c    BPINT 41 if ax==4f
/ z! N) N# D4 ?) N  _/ _, t/ J+ M( v  r. C) I
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
: W- i4 F" ?1 r3 U9 \) I. E) x$ y/ T
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
7 v7 v' a* N% a* P8 ]( o( c6 E! J
- V6 Y8 c+ Z$ [* l    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
/ M- t8 D: Z, T$ T  D( W9 x% V4 w( O4 T
__________________________________________________________________________
" s! f# X' D) e
& y. O' _2 E3 y" Z2 y) F7 SMethod 13
+ a  w- [% [* p) m: U+ J; U, q% @=========
3 |/ M3 b2 ]' L" [
3 ~$ |7 x1 |$ J3 T1 f) LNot a real method of detection, but a good way to know if SoftICE is( c* ~* j) s* d8 N9 o
installed on a computer and to locate its installation directory.
4 N1 {3 {6 z) Z! dIt is used by few softs which access the following registry keys (usually #2) :6 L8 c2 t- b7 {: A! w

) x! ~5 O9 h1 h$ R-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
8 P, B, Y# R7 x' X\Uninstall\SoftICE
! @* I) J8 d2 Y  V/ r-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE3 l) n1 _- \/ \9 p8 h& Y  Z
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
  {7 Q: e& b' V5 q; j- r8 o, U) h3 k\App Paths\Loader32.Exe4 }+ d2 Z* U  X5 c3 J6 D4 j

$ q( Z/ }( f6 g- j- B  S
; m9 _, E( \* t& _2 K+ o5 |Note that some nasty apps could then erase all files from SoftICE directory
. S3 |: \4 B( u4 s. H! ](I faced that once :-(
1 X9 Z. v% b1 t
( X. I: @; E8 l/ l4 z, OUseful breakpoint to detect it:: P  X6 Q% H  r# A5 a" O! q: V
* F5 f+ W; d2 s4 X! b9 |
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'  H& Q( n; M; f9 N$ n* b# W0 b& Q
/ E' d8 B* ]8 Y, I
__________________________________________________________________________
4 c: a2 j! J7 E8 T/ |
% B! x: H- p& o8 N6 P# p7 X' a5 M6 \  Q! e4 a; h( G  O
Method 14
# X, Z' O! b$ N/ d# @=========
% ^0 ~/ c& ?$ Y' _% O- ?% r3 w
" |; R1 F' O- L9 h9 BA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose4 o; [4 x& {1 y, I
is to determines whether a debugger is running on your system (ring0 only).- D+ A# H% L* h' H. \7 M( |

6 `4 R  w7 d: O, m+ r   VMMCall Test_Debug_Installed" g5 Y6 @; r1 P9 ~
   je      not_installed7 x0 L8 N5 ^2 @  }+ d6 ]; J+ u& U
+ H/ O5 q8 c4 k. m/ K5 [, F
This service just checks a flag.1 n; X' n0 d8 ]+ }- L$ s
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部