About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>+ ]( g7 J# q- ]
<TBODY>8 B; W7 U% ]# [2 L+ }- j; o
<TR>1 }" E+ K- P: D7 y1 s, Y
<TD><PRE>Method 01 ! A: P2 B7 E, P: c1 V  N1 H
=========
# ?  ~+ Q& J( z5 x. X3 I: |+ I/ ]# u
$ c9 J$ D3 m2 M5 FThis method of detection of SoftICE (as well as the following one) is1 f2 X& L$ d! l# H: G
used by the majority of packers/encryptors found on Internet.
/ ]5 a8 E2 Q' |( [4 T& f! JIt seeks the signature of BoundsChecker in SoftICE
0 Y1 W) u7 F- z. [0 T8 b- z, [" q' g( M  o/ ]5 e
    mov     ebp, 04243484Bh        ; 'BCHK'
5 T4 s: f0 d, P0 X; A6 m    mov     ax, 04h
; g6 X. p* I# S9 x    int     3       % R+ @. B5 V: T0 y' ?
    cmp     al,4
! d* w4 x3 A/ y. h% y    jnz     SoftICE_Detected: q8 ^1 S' O/ G' E1 L

% ?& C8 p3 [" T1 H7 k9 S+ b___________________________________________________________________________# `8 W/ I: {$ [! }8 [* v) h

6 `; |9 r8 C) U3 o6 V1 g: M/ cMethod 02: K; `# D( g1 w- Z2 M3 v$ ?( A6 C
=========! Y* c2 B( D7 }1 A8 {* k& J: H, _
2 Q8 E" w6 O8 l5 Z0 t6 d) R
Still a method very much used (perhaps the most frequent one).  It is used
4 X2 q6 m- K+ @8 l0 N7 uto get SoftICE 'Back Door commands' which gives infos on Breakpoints,/ `+ `4 p3 I3 V; m
or execute SoftICE commands...
' [. h0 a5 K. Z  S5 {4 u' CIt is also used to crash SoftICE and to force it to execute any commands
7 c" O4 e. R0 H3 L* T* ?0 c4 j1 v(HBOOT...) :-((  
0 V3 t6 _2 ]2 ~0 n3 S0 d
& z# \* t7 K* qHere is a quick description:% h. K# }9 N' v( ]/ O. M
-AX = 0910h   (Display string in SIce windows)
0 M' k4 N+ Z" L# \' c( m-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)" q6 G2 I% E# k* V
-AX = 0912h   (Get breakpoint infos)
, |% o. u- h/ l% s$ l3 P-AX = 0913h   (Set Sice breakpoints), @3 ]  i; c- H/ D+ R1 u9 f6 W
-AX = 0914h   (Remove SIce breakoints)
- n! q7 H( K* v/ q1 q0 p9 _9 h# n
6 Q; [- x; ~( j* k! k; p/ [6 iEach time you'll meet this trick, you'll see:
3 U: D" ]7 m. _2 X% y( z' ]-SI = 4647h  o; p; _9 _' R, H$ e  E
-DI = 4A4Dh
! S5 F2 V) P4 I9 k2 z: \" h1 |Which are the 'magic values' used by SoftIce.
9 l- \+ ?0 s  t. bFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
! e: j/ }/ `/ w# M9 r$ a" f& ?( a6 f) P5 g3 N5 S  v! {/ X* d7 e/ @
Here is one example from the file "Haspinst.exe" which is the dongle HASP1 W4 `/ A. m$ H
Envelope utility use to protect DOS applications:1 x. `; ^' W; E# H

9 [+ e; P, H. K7 f7 o- [/ g
* D: V6 L0 {( g9 K1 R4 y7 @4C19:0095   MOV    AX,0911  ; execute command.8 Z# S4 ?7 \  O9 Z( {
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
: z$ Z# g7 T% D) B4C19:009A   MOV    SI,4647  ; 1st magic value.' D7 y/ a$ [2 f' n9 T
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.' [8 L' Q7 y. s5 k" ]' D, R4 _7 z
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
& ]$ A  j& O: t% w" g/ l4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute* h' c5 T# g/ r8 _
4C19:00A4   INC    CX
' b. h8 w6 M1 g3 r9 Z4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute* M. Q( ]- _$ E
4C19:00A8   JB     0095     ; 6 different commands.
4 }- v$ [2 [; r9 x/ A/ v& X4C19:00AA   JMP    0002     ; Bad_Guy jmp back./ H, b( s4 L3 g& c4 ]% F4 v6 x( h
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)) b5 E& [2 u7 L9 B1 S( _7 Y

$ r: o/ {, W! J! `0 e2 z7 t; {! |The program will execute 6 different SIce commands located at ds:dx, which
- c6 k) a* L$ W! ^1 eare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.$ w& p) O+ I# i2 }  }* V% c
! c3 @( v: v6 i4 c7 Y8 N! M' c
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
+ ^; B2 z2 y( y' g9 T___________________________________________________________________________
% K. i! j% D: Z* R) ?
1 q0 B/ c' t5 `8 _6 Y: _# \  l7 ^8 K( W1 X* x$ w& p, F# s! Y
Method 03
( r; }# I2 d+ [  E; Q=========. ^% @: M7 k1 q$ ^( ~- B6 p

5 X& [* L4 H, k9 m7 wLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h% ]0 w( C0 E! d2 I; U& _
(API Get entry point)8 F9 }. K6 |9 Z+ C
        + U  R5 U# |2 S$ t$ Q
4 [" _1 b0 h4 R6 j# E" k
    xor     di,di" ~  L3 \$ ^" Z; p" [  N4 U1 ^
    mov     es,di2 k9 j1 b7 g; H# X, f" K' y+ x
    mov     ax, 1684h      
+ E( y- n' _) R& |1 K    mov     bx, 0202h       ; VxD ID of winice/ \9 g( p8 [. x6 i  X" n
    int     2Fh
- B% h* H2 K4 ~& h( v) g: J    mov     ax, es          ; ES:DI -&gt; VxD API entry point
; C' k" N3 N. s/ ^* p    add     ax, di! C6 @/ D( F# e, h
    test    ax,ax
5 }" \- {/ Y$ [( q0 W    jnz     SoftICE_Detected* e2 ~) }: ]; f/ ]

- K7 U) D6 A: `) \4 C% J___________________________________________________________________________
7 N2 |! u7 y8 |- G1 v0 R4 s, w! u3 q
Method 04
- C) b) G4 {% x" G2 u5 w% d=========, Z* J5 R* Z  ~0 |: |! ~% C) e3 i

$ I( i" M) E0 c' L1 kMethod identical to the preceding one except that it seeks the ID of SoftICE& t6 X( p  \1 ^9 k8 |  F6 s; P
GFX VxD.7 N+ U$ S! G+ l0 T) Q

3 [& L, ]+ n; c# L8 t" @    xor     di,di9 a* i& H3 y; b' ~4 z
    mov     es,di5 S9 `, [: J' S3 {
    mov     ax, 1684h      
, I! N2 C( N0 I# V$ V    mov     bx, 7a5Fh       ; VxD ID of SIWVID
$ Y- K* T: p7 B  Y5 v6 _    int     2fh! B5 A* H/ C: ^- k
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
# K5 C1 C, h9 }8 Y1 Y4 t5 W    add     ax, di3 H2 K1 _6 Z* y3 t4 \
    test    ax,ax
5 }- l$ h- D2 s0 R+ G    jnz     SoftICE_Detected8 u* m( M. a1 F. F9 y5 Z5 B
: A  T% I+ k$ S+ `% V' ], E
__________________________________________________________________________
7 g) }0 B6 }- x7 q8 `6 z
2 Z- l* {" v- u2 d$ q( ?+ j  s, B; I; x/ ^8 `0 A9 l% n- L
Method 05. B7 p! [; Y) A- n" m5 L
=========
5 F4 g3 B( p# B4 w, a0 y& J" P4 `/ ]! y5 z8 C
Method seeking the 'magic number' 0F386h returned (in ax) by all system8 b" p* H' D. e# u- y. ]. E9 t
debugger. It calls the int 41h, function 4Fh.
! f# J7 g$ ?: lThere are several alternatives.  0 M3 i9 H3 Q+ F8 S# X( I* {; D: v
3 g3 X2 K* s% D
The following one is the simplest:
$ Q1 p! H/ p0 |1 [, D1 m* s
6 V& C( {/ E* I* a6 C" Z    mov     ax,4fh' w1 z4 D& C# O8 i
    int     41h1 A9 [* H6 Y3 M# s
    cmp     ax, 0F386
0 j- ]- U% e+ M0 m    jz      SoftICE_detected1 q2 ], D$ H! S) N

  u& w) P  A: m  l5 D/ ~, H9 M& C3 Z, ]' z0 q4 A0 Z
Next method as well as the following one are 2 examples from Stone's
0 R$ u+ Y5 p" ?; e6 S, w"stn-wid.zip" (www.cracking.net):) F! q5 T  E& y0 N  m; ]. S6 N3 k  Q
4 d9 @" N+ @) o( O, i
    mov     bx, cs
$ {: \* k  U; J3 b  }    lea     dx, int41handler2
; W, m- }# z3 a& F. Q    xchg    dx, es:[41h*4]
3 z9 }1 u: G  H/ Q! B    xchg    bx, es:[41h*4+2]  V0 J# x$ L" i5 X( u
    mov     ax,4fh7 |3 M' @! t6 W& o  L
    int     41h) C. {, @3 Q  e5 f) w1 m2 U& ^
    xchg    dx, es:[41h*4]
( x5 A; {% ]; T9 q9 [    xchg    bx, es:[41h*4+2]
; G; P7 V  h/ J6 [1 w    cmp     ax, 0f386h
2 o: C$ K) h/ M3 M- h    jz      SoftICE_detected
0 x0 U  s# [, t( }# E( o6 E0 }* Y  X
( O# w1 Q4 D1 ^/ x, jint41handler2 PROC9 F% Z" ]9 ]7 [6 x
    iret
. @) o2 h4 u5 T" N1 }1 Jint41handler2 ENDP
) K  p; ]" k9 m, F# B- [$ s# e7 {# @

6 p$ L+ H% H& _/ C* u9 B2 q' D3 V_________________________________________________________________________+ F3 H: `9 D. O- M# G. O' q; B

$ P% ?3 |, ]1 {# T- P( Q: L; I, s% y! q3 H3 e. }8 O1 K2 i9 o% X( x- g3 `/ \
Method 06
: \9 B0 y  b$ d& }! a, h=========% N+ O5 K2 t1 D6 c: P' ?% m$ P1 c
( w3 K! v) S* D' W

1 n/ x+ c* ^, f0 t) C; s/ h2nd method similar to the preceding one but more difficult to detect:
' p% i/ t( s! `) j+ R9 c# |% i3 {1 W7 s# h: x8 G. s4 a9 X
( A, p+ _/ W1 J# _! d$ g( @' M# x
int41handler PROC) S* s6 i' G+ d( `8 z
    mov     cl,al* l5 ~- t) Y  B+ `* t9 `; x
    iret
2 u. v! Q  ~$ P9 a4 G" K; N4 |  ?int41handler ENDP
  }) R4 [$ A' U
0 r9 q4 ^5 S9 P8 Z$ ?& k/ V% o" Q. K6 |$ ~1 K
    xor     ax,ax
4 ^' T' P4 D& S' J  o8 `    mov     es,ax
; x) k3 r9 P% P% b1 m9 ^    mov     bx, cs
- I0 G$ [6 g; H' P    lea     dx, int41handler  _5 e4 P7 u( S+ H; Y  d& n! R
    xchg    dx, es:[41h*4]% J% o) c$ \7 X/ l0 w; L- x7 l
    xchg    bx, es:[41h*4+2]
$ Q. V- l% v$ L2 P2 o. a/ @1 ^1 C$ b    in      al, 40h; ^: Y5 [6 v/ C4 M! w8 E- G
    xor     cx,cx
' @' _4 f' \* |, T    int     41h8 R& V' A6 F8 [
    xchg    dx, es:[41h*4]
& t% a3 E$ ?& T4 g    xchg    bx, es:[41h*4+2]
& x+ _* g% W3 h. u4 Q    cmp     cl,al
6 z5 E( H* v/ B0 e9 g" q/ ]4 {; q    jnz     SoftICE_detected* Y8 Q; V! O; F6 |1 E, M& L- C* q& B; y' ~

/ y: e; }9 o3 ~% S* \_________________________________________________________________________  t" K! v' y. c9 o
' s7 h+ I: f% d$ H, @8 k- ]
Method 07% B7 J- X, a* u' K3 i: l
=========1 `+ Q# V$ ~0 @( G
; F( B( d' ^: B" _: m2 ~  ?% r  y$ l# r; {
Method of detection of the WinICE handler in the int68h (V86)
# T1 Y) R1 [2 P9 g) L2 r) U  G0 j& U7 W6 I) C" r. g+ _
    mov     ah,43h
. @7 m% {6 Q9 I5 j8 w7 s4 l0 X- ~    int     68h) K+ Q8 K4 G/ V, e
    cmp     ax,0F386h! C0 ^9 G. K+ n3 T8 e( X! b
    jz      SoftICE_Detected1 J: m) k- V/ a! z- l2 Q+ m

' X0 |4 L! `$ U: l" f7 t1 ^5 W7 @  c6 n! V% k/ f
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
" t! m# u% ]) u' r1 X/ S: Q   app like this:
4 g8 C/ s9 p7 d  F
* t' H0 B) v# \) f9 v8 w4 L, r6 z: }   BPX exec_int if ax==68
, l3 `5 e( _3 a  o& r   (function called is located at byte ptr [ebp+1Dh] and client eip is9 z* m" F( e! f
   located at [ebp+48h] for 32Bit apps)
6 ?* E$ x- [0 }7 c! f__________________________________________________________________________& D# B9 e: @+ s& A

7 L' z7 B* s  g( z0 V  Z+ Y) a- e9 s4 l. G" C/ ~0 e+ C
Method 08
/ z. a! ^2 v% R2 r7 s=========# W, B; ~0 g3 ~% t' x  b
, t! w0 n( b: N: H
It is not a method of detection of SoftICE but a possibility to crash the; ?: x0 v! T9 X3 S
system by intercepting int 01h and int 03h and redirecting them to another
+ P: @9 W* O" j9 Z3 B9 Aroutine.& |  `$ |. N) P
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
5 S' O- t1 A6 Z; o! ?1 x/ p1 Jto the new routine to execute (hangs computer...)
1 ^' G. ]1 Y6 b3 E. ~1 k
, B& ?& }! s4 q% |    mov     ah, 25h" C- l+ V- o: C# h
    mov     al, Int_Number (01h or 03h)
- f# y3 D2 ]9 N. ?8 \    mov     dx, offset New_Int_Routine+ V( O! L- b7 D# H. f5 u/ b
    int     21h0 C# H3 k# q/ M2 ]4 d' n
1 o( {0 P$ ~0 N, \( N& [+ u
__________________________________________________________________________
0 C" [; u: c2 |( h( ]. U
3 O& _) Z2 ^! n  h  }5 h: bMethod 09# z- h# x0 ~5 S# |& J; Z0 f
=========
& L1 s. }0 }: _6 s$ x7 ^
- w$ s- M% c# f3 C2 ^/ u: P. r* A2 UThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only3 i; d9 u% R, p2 _- T- n
performed in ring0 (VxD or a ring3 app using the VxdCall).
& b% O0 K- E( W. O) p8 Z; {The Get_DDB service is used to determine whether or not a VxD is installed& J% s4 u3 Q' b; S8 ?0 `/ c
for the specified device and returns a Device Description Block (in ecx) for4 U6 N3 z! a. z. l+ F3 A8 g) |" T
that device if it is installed.
3 M+ R" E8 a9 k% w& K: J5 Y' w: o# n% u' y: k) Q# p$ h
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID0 r% O( Q& R3 {2 @4 ^( J" x
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)* m; T! c0 M; c7 Y
   VMMCall Get_DDB' {( }  L' T  [# k+ z- k
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed$ k/ p# }& c, h6 t
% o/ [$ p, b+ i9 x) A/ ]6 p
Note as well that you can easily detect this method with SoftICE:
1 m  l6 t. S7 o5 ^3 r   bpx Get_DDB if ax==0202 || ax==7a5fh
9 a! h; I$ B& R/ k! R  w  m
  S! \1 q- i; Y% C. v# s__________________________________________________________________________3 P9 c4 k9 R- _) L: K5 }! o0 f. C
' C1 d% Q$ e" O' ~& ^0 ?. `9 q
Method 10
/ h( @1 w- s8 d* F=========
, n1 l% b; Q* m, V, C4 J8 p: b: y% T- {1 p
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
: S" v; G+ o: d' [1 ^) [  SoftICE while the option is enable!!) ^6 P, q0 m8 d. i5 m* x& `4 f
: K) a% `* A# x# {- Z
This trick is very efficient:; Y/ i5 L# Z! E- v! X+ S2 `# T- @
by checking the Debug Registers, you can detect if SoftICE is loaded
5 X0 V5 y+ `, t(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if- q( B' ?7 B; J+ l
there are some memory breakpoints set (dr0 to dr3) simply by reading their) ~5 \( n8 T& {( C* n( U4 [
value (in ring0 only). Values can be manipulated and or changed as well
  _& n: C" O- y. U$ L& S(clearing BPMs for instance)
! N- c! y5 q3 o# {/ e* l* _3 c! V, w3 s* k4 g- Q
__________________________________________________________________________  H3 J' v3 c2 }9 Z4 ?# K6 a7 p

; G! S, h' y1 E( YMethod 116 [2 }2 d& Z; A8 R7 O6 ?  {% X# k
=========$ L& w' k; D! T% x8 |  E

& P$ ]4 J$ \, V- m3 RThis method is most known as 'MeltICE' because it has been freely distributed
' @9 o) i8 p3 f% ]' L. N" ?via www.winfiles.com. However it was first used by NuMega people to allow
2 y1 X0 L; m% lSymbol Loader to check if SoftICE was active or not (the code is located4 O( o+ P! I, U2 B! l& V# e2 v
inside nmtrans.dll).9 A$ O1 G( y! a/ q+ q( B& R  C

' E. B9 ^, l* O( I* {  f6 s  Y; rThe way it works is very simple:' i1 V! l! a$ {% H7 Q9 a: a( M3 n
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
) y6 R8 d" u  f3 uWinNT) with the CreateFileA API.  n) f" W+ e" i* _. j" _

1 \; ?4 Z/ t* Q$ T2 j. mHere is a sample (checking for 'SICE'):3 }* g# d: X, _, j! H* X7 }/ ?

/ y& t2 M& {8 D' h" F! FBOOL IsSoftIce95Loaded()+ u, P6 i5 y1 B4 s
{
* C; J6 B6 r' f% B: A  l   HANDLE hFile;  5 \" I" h0 ^* r6 ?/ {8 X
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,! R% q: H+ r/ ?: W7 n
                      FILE_SHARE_READ | FILE_SHARE_WRITE,- g+ K& W! f0 y* E2 R! m4 v+ [
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);% I' _+ G6 Z) {/ n% c2 ~
   if( hFile != INVALID_HANDLE_VALUE )
2 X  S* ?6 v) z4 K) @/ u; O( b% X% @$ Q   {
- z4 {. W9 g; S, s4 W2 x* n      CloseHandle(hFile);- X+ A7 r7 T# \! q
      return TRUE;
4 ?& [2 s$ N# v2 C$ y   }% z' N/ q* N" E
   return FALSE;5 h7 _& v5 ]8 K7 @" w
}$ b6 Z$ F$ X7 z; F
$ o6 _5 Z) j6 Q, s
Although this trick calls the CreateFileA function, don't even expect to be
1 R$ {; j" F9 m' X6 V! `able to intercept it by installing a IFS hook: it will not work, no way!# v% f0 N9 s8 p  I# h
In fact, after the call to CreateFileA it will get through VWIN32 0x001F3 U+ R0 @3 j. @' I3 i" m. B4 J
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function). G8 X3 p3 m& n/ P& |. j
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
% w, y2 ]& l, m8 zfield.
0 k' X+ [* R9 d* z$ h- {* Z' c6 DIn fact, its purpose is not to load/unload VxDs but only to send a
) |+ L& l: C7 T6 r: wW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)" f& m+ U/ N; V# g2 b, I
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
* C0 Q1 K( Z, `* g% r0 y0 M- C$ Tto load/unload a non-dynamically loadable driver such as SoftICE ;-).9 [0 j* v  K1 c; |1 y( C) Y
If the VxD is loaded, it will always clear eax and the Carry flag to allow
2 o1 e1 ^5 m6 a$ @, ^its handle to be opened and then, will be detected.
5 X! `4 J; [' [7 CYou can check that simply by hooking Winice.exe control proc entry point
/ H. J. V3 B1 g" @while running MeltICE.- p4 G2 _( `1 k  L) N. f  {
+ z2 p4 C* d6 q# t2 [# W

3 ~' b  E& p$ C+ M, Y; v  00401067:  push      00402025    ; \\.\SICE
# F1 B# Z3 e( S" J4 k+ r( G  0040106C:  call      CreateFileA
' Z; B& }# W# e# X5 H  C  00401071:  cmp       eax,-001
4 Y: P" p/ m: o0 G' E  00401074:  je        00401091$ C8 A4 h% Z/ o2 N+ [8 z

& H: X; a. |# S0 @' p4 b2 v9 _/ V! s( d' |; B' B0 y6 u+ H% G
There could be hundreds of BPX you could use to detect this trick.
0 w8 Y& y8 u2 m3 e2 w1 j. x' s' x-The most classical one is:
7 n8 s# R6 y! Q  @% \  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||- s& X0 Q, D" e* W0 v
    *(esp-&gt;4+4)=='NTIC'
8 u) V( h3 {% r& l3 N; }
9 h: b: ~. |) ^: {7 a3 U, T-The most exotic ones (could be very slooooow :-(
7 r" g, W4 [2 X5 Q) X' |   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
5 C+ i2 f7 A+ {4 k, U     ;will break 3 times :-(
/ o2 s: Y, a- R4 w: k: I
$ i  k& f2 U0 z8 ?5 k* F4 w-or (a bit) faster:
1 ^* o9 m# o' z9 D0 [+ E& R   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
* Y7 N8 {* D+ f2 b1 \
/ J& T" C, f2 k$ ~4 F3 w   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  5 u4 b# k, U1 s( Q& f
     ;will break 3 times :-(8 H2 v" S! b+ j) S9 o4 i
$ f" b) h" g$ ?3 E% G4 U' U2 F
-Much faster:% S  q* B  n. ?. u, K) }; t
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
$ P+ v8 k* d- n& `" g; C" N  |/ {+ X' C" _5 C) T
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen( h) z2 N" T- r8 p' p; ?& C
function to do the same job:7 o5 M( k4 S; c# N9 U% B

; a" m7 C; O( Z7 l* s5 O( ?   push    00                        ; OF_READ7 M9 }2 }0 U- Z/ w: \+ h
   mov     eax,[00656634]            ; '\\.\SICE',0  C& g# n* ?( \1 U! V6 g
   push    eax; X- {/ b4 P7 v6 s7 E4 K, ~- u
   call    KERNEL32!_lopen
! e2 c6 f, v$ [/ s' v2 D   inc     eax
* E- [4 y- X& c* f/ c2 D0 ^, j3 ^   jnz     00650589                  ; detected
+ E, n" n% N2 a6 y( J8 Z2 a* ?' b! s   push    00                        ; OF_READ
1 [# m$ q" t# g3 ]" ?0 L, ^- @   mov     eax,[00656638]            ; '\\.\SICE'( V" `) |+ L7 r8 n3 t+ H) ~
   push    eax
- @' O' r7 ]( |- Q+ h   call    KERNEL32!_lopen* Q" u* Y# E7 k5 e% I
   inc     eax( P  O  Z1 a5 K$ F# ]; l
   jz      006505ae                  ; not detected" J* q6 @9 @) |8 [* O7 n

0 f! Q- A9 A/ R' p9 h# B" C) c! ]8 h6 V- A. A; q9 t8 J3 f6 f3 E7 `6 `6 P0 W
__________________________________________________________________________
/ n) a2 i; E9 J- H6 h6 a! r1 O$ @  ?% D
Method 12, @6 W& W5 d/ z
=========$ I/ s: U/ l. ~0 g  c! L6 O
& V7 S; ?. c  U! h1 `
This trick is similar to int41h/4fh Debugger installation check (code 059 o1 c, z: P6 h
&amp; 06) but very limited because it's only available for Win95/98 (not NT)  M- E7 C% p: I+ K) o
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
" N, `7 `  O5 w3 {" g  @
& l: D# J1 ]2 t# j% U   push  0000004fh         ; function 4fh, e# a5 X5 R; {3 r8 Y
   push  002a002ah         ; high word specifies which VxD (VWIN32)
9 J" P+ G  `# L, o; \* E                           ; low word specifies which service
+ B: p) O5 c. }% a                             (VWIN32_Int41Dispatch)/ e9 P4 m. E+ I! o* g5 }4 F3 t! m$ ~# W
   call  Kernel32!ORD_001  ; VxdCall$ J) H" p8 m3 l: `6 E' @0 M7 w. X% H
   cmp   ax, 0f386h        ; magic number returned by system debuggers
4 }" z; g5 M8 i( I! B% f   jz    SoftICE_detected
# r8 Y: s* Z# B4 e# d. v" d; g& A8 ^. R1 t
Here again, several ways to detect it:' q5 f. G/ J$ U

0 ~1 N5 J+ K9 F6 Y8 @    BPINT 41 if ax==4f. |5 Q* f* K# _3 }& S. T) Q) S

: Q6 j8 g; a6 k% G7 `3 Y    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
. w7 v& S, k2 j& b9 d
- p3 G% N) Y3 i" D$ f+ G- |    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
; J% x6 g9 N% n2 ^- _  d8 h
- p# q5 q3 _1 w- `8 ]' h0 Y    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!( M) O5 n6 v7 N1 [0 m# U- q/ K1 o
5 p, B8 j/ L( D; }
__________________________________________________________________________3 U; E* a+ Y# k  c. r+ ^
$ v: k7 [+ P  j# m4 r; [
Method 13, H5 I* p  U* {! z/ |/ P4 n
=========
' p4 Z4 }. j! l) o! N6 l+ e( Y% I$ ~& `( G" C8 F# p9 {; [; t
Not a real method of detection, but a good way to know if SoftICE is
8 [8 C" v+ U& ^& F7 P4 Ninstalled on a computer and to locate its installation directory.1 c' c0 ?, E4 L6 X
It is used by few softs which access the following registry keys (usually #2) :
. L6 {8 x/ U, h* z' _: `3 M- J' D( U" ~' c
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
9 r  S. D* c' ~$ k\Uninstall\SoftICE
7 M  X1 X0 N$ R, s$ E3 z-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- {+ _* R$ k( K' L& j. |6 ]5 u2 y-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion/ [2 b3 e5 e( t" Z
\App Paths\Loader32.Exe
" |3 b* S  d/ W: R
4 m$ ]3 K* ~# K; z& t$ f4 m8 ^( ]/ Z
' T' |6 ?& t- c1 QNote that some nasty apps could then erase all files from SoftICE directory
, M* s6 C( W+ B8 T(I faced that once :-(
. U$ {$ I, ]$ }5 x) P; a" i2 t( \, h6 j7 ]# }# H
Useful breakpoint to detect it:) _2 W) }2 q" m- K# ?+ [% P' K
0 N1 \; S" P- Q1 @6 d) l9 s+ q
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'  Z3 c& `# p% W8 `0 D0 s# `
/ X( m- K" |' J6 ]5 b, K
__________________________________________________________________________
2 f. m) b% t: F9 n) U1 U3 s: G' g. S4 y) ?% m2 `* [
; O, c/ g$ J% r
Method 14
* t& ]* }1 g2 J; G& u=========* P( E0 E' G7 v

: i- i9 n9 a- P5 k7 g! cA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
& M7 F& n) V  jis to determines whether a debugger is running on your system (ring0 only).8 E# ]* @4 W; a
& V1 C' q# ]4 l  Z0 K
   VMMCall Test_Debug_Installed
! b8 o4 @: a: |, L   je      not_installed
' ^; g9 g9 E0 f; ?4 D, k' r
2 }* h, c5 B8 ]. T% {. K# rThis service just checks a flag.( \6 \" h6 v1 y; t
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部