About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>1 ?5 }6 w" f. n8 I
<TBODY>
" f2 {7 @+ ]4 f3 Q* c' j<TR>% U& A. x0 q+ _4 F4 _3 k' t, d
<TD><PRE>Method 01
9 W+ r$ f- @  D/ n' k* p" L/ W7 |=========/ j  Z5 B  T  j& i$ A: W% ?& c

' Q4 B9 q' f9 oThis method of detection of SoftICE (as well as the following one) is
9 R" a9 W, J. e/ pused by the majority of packers/encryptors found on Internet.3 [0 O7 }/ W) T. l+ L. X- V
It seeks the signature of BoundsChecker in SoftICE
) N* e/ X: M6 L# B5 b# n, O% N: a$ W. t6 f/ A5 l9 ^0 ^6 A
    mov     ebp, 04243484Bh        ; 'BCHK'8 j0 M8 l" |; ?5 c8 }- u
    mov     ax, 04h- D8 e- P5 o1 Q0 V) R
    int     3      
1 u2 `+ @' d$ q6 F% o    cmp     al,4
2 ]2 W0 x) i+ i3 L    jnz     SoftICE_Detected
' `7 B, a6 }" `% G8 J7 |, g2 A. W- G4 I5 Q9 H4 Y  o
___________________________________________________________________________+ Y# ]. C4 u* Y

/ o& d% }# z* O& U; }Method 026 c" o& Y6 P5 Z% n3 v  f
=========
+ F: I( a1 W# e; W  g0 Z- t. y
7 `8 B& j2 |3 Y. d3 F* W1 L0 [9 cStill a method very much used (perhaps the most frequent one).  It is used+ Z& t7 k2 v1 g
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
* |' b) Y, ~1 ~or execute SoftICE commands...* y$ E$ u( n- n2 v9 |2 u
It is also used to crash SoftICE and to force it to execute any commands
/ V: G( @: |! e: |(HBOOT...) :-((  
- k( d2 Z7 B& ?' r( g4 ^
* ]; F% Z/ n7 w6 ?' D! O% t/ GHere is a quick description:
* _3 ]; m0 y$ W-AX = 0910h   (Display string in SIce windows)
2 D. L# \5 ?! m3 H  J-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
+ W2 V' c/ N3 @" N2 @. ~8 a-AX = 0912h   (Get breakpoint infos)- A/ t, k1 J; q
-AX = 0913h   (Set Sice breakpoints)% s5 A3 z) n6 P* X$ B
-AX = 0914h   (Remove SIce breakoints)- C5 |9 s) I6 e% k, \. o  @

0 D! v/ g1 R2 p6 U- \Each time you'll meet this trick, you'll see:; g& I( V3 r0 B1 A4 ?4 K, o
-SI = 4647h
$ ^+ x- R( j7 h1 N-DI = 4A4Dh: s# C7 @" q- e, r% m
Which are the 'magic values' used by SoftIce.
1 v" d" `* ?7 R1 q5 m( ?( tFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
3 q+ K) p/ p* ]$ D3 `7 i4 a& b/ w$ s6 U2 \& A
Here is one example from the file "Haspinst.exe" which is the dongle HASP& Y0 e& H  d0 `% L% [! Y% Y
Envelope utility use to protect DOS applications:
* E, p: A5 `9 W2 Q+ y' g8 ^: J. l6 J0 p8 v' M* O
+ r& k: L  h, y3 V3 k8 n% i) J* v
4C19:0095   MOV    AX,0911  ; execute command.6 M" X" H4 V* Z$ [7 e
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).! [6 @% E) Y% v5 o% Z6 Q9 m
4C19:009A   MOV    SI,4647  ; 1st magic value.
& D1 ^) H+ _* u4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
5 f' W& r6 p7 S7 g$ E/ Y* P- e; E2 i) H4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
  Y) T6 ~9 D8 J0 O: o/ Z4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute6 W$ t; x0 Z* [
4C19:00A4   INC    CX
7 ~* U7 ^3 `' F8 e4 `) s# Z4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute1 E* z" a) ]. Y
4C19:00A8   JB     0095     ; 6 different commands.* r* e5 {3 L# N$ `  ]
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.2 c1 |4 I: d% _! K+ u+ D; O0 f
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
. B( X! h* ^9 B$ g9 M/ Y  m/ J9 {* I% r
The program will execute 6 different SIce commands located at ds:dx, which" n6 B$ T) H' m  X8 Q; w, r4 _
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
" d0 A. E: b0 m# a1 y
" ^7 c& I" w; Z  ?* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded., M( [  ~( }( c/ H# k0 p
___________________________________________________________________________$ I: \+ P. v7 P0 }- Q

* p2 ]2 h! k  t8 v$ g, `3 ^" @+ m8 y( O( Y, R4 I- g
Method 03
3 z, _/ g* z1 {2 w=========7 K2 h2 j! r# Q

4 R" W: \9 T% @) Z# c- @# O! ^  rLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h8 O8 `. ?& u; U; S/ Y1 s# E6 k
(API Get entry point)
5 b: W) P% n' n7 L        
  Z1 f: D/ D4 l+ B, y- j$ }- `: G+ v9 _) T
    xor     di,di
1 ]( w( ]6 {- Z( l+ y/ S    mov     es,di( X% N  f! }, ^/ w2 s1 C
    mov     ax, 1684h      
5 b) w) X' _: W- q) L1 r1 O) c& H    mov     bx, 0202h       ; VxD ID of winice/ L( l6 d2 s2 {* o; C* s
    int     2Fh- W" g: F$ ~- S& o; ~5 B: L% l! K
    mov     ax, es          ; ES:DI -&gt; VxD API entry point/ |: t% Z. i8 k9 p) o! {% y7 }
    add     ax, di" z1 c5 J: w7 U& v! r
    test    ax,ax3 y! M2 p) E: U. M- {2 t
    jnz     SoftICE_Detected( u- \3 \- X4 v

& |# Z0 ^8 H4 q2 ?3 C- O% a, c2 b___________________________________________________________________________- F/ \- y, k0 _: }$ r6 }1 q
. A1 ^* E6 B# t- ?; @' q
Method 04
2 @2 O$ e0 A9 i; X+ E=========
  w! N# z% W- v4 D' L0 c, o2 I) @) O/ o" g
Method identical to the preceding one except that it seeks the ID of SoftICE0 r/ B2 g. |. ^; j6 W0 \- T
GFX VxD.9 m/ D' u% g5 K3 j5 s! _) o* {4 d
, Q/ v# B7 D4 x- Z
    xor     di,di
' r8 T8 A- B& n9 t: f5 p/ t    mov     es,di7 p! S& A" |$ @2 G
    mov     ax, 1684h       2 b: _3 o6 D1 |( q) n1 i
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
. d; v* k9 M* n: C- y    int     2fh
/ M" M, e$ f  B7 t& A, j    mov     ax, es          ; ES:DI -&gt; VxD API entry point  R( y5 V) \6 ^5 Y6 f6 k  s
    add     ax, di
# m  d1 J, F$ F8 }! J7 q% o% Y    test    ax,ax8 B% S4 z5 o+ F/ i
    jnz     SoftICE_Detected
) W! C- _# I. y1 ]$ u- V, C" U) B0 J6 n6 b3 x1 u' P& {0 Y: k2 a
__________________________________________________________________________6 b, y4 r: w7 S+ T5 O0 A2 f' y

" ^% o+ w* P; w1 v' q5 Q& T* [+ E/ k5 h3 ?) X! g9 e8 R
Method 05
/ m1 N) J0 Y+ E! b4 i=========+ f& G7 [% q. |0 E0 Y6 d. {

+ D6 d- i# T) O3 }0 d1 e$ aMethod seeking the 'magic number' 0F386h returned (in ax) by all system
9 L* e0 ?6 G) U' D4 R! [7 Hdebugger. It calls the int 41h, function 4Fh.
3 ~& B+ J# i& ?) @  YThere are several alternatives.  / H4 S4 i6 o0 s' L- o
& \6 \! X: K* ]  E& x
The following one is the simplest:
' l0 `! V1 S, B& L% U# i% G
+ F8 J6 B' b8 w  D- s8 }& j    mov     ax,4fh
, `$ S" e4 m4 `1 R8 i, x    int     41h+ o, G8 X5 {; \
    cmp     ax, 0F386
8 i. G: W5 W, c6 k- U; W    jz      SoftICE_detected
) d, ]- H" v/ U& \( ~5 E% b/ P
6 P9 ]7 `, f9 R- r/ s  ?6 b  _' A9 a$ ?" a- J$ D8 V
Next method as well as the following one are 2 examples from Stone's 6 p2 Q1 l8 ^" B. |
"stn-wid.zip" (www.cracking.net):
) r5 \2 d( j' `3 D9 F$ g0 j" v4 r$ g9 x8 N) J6 Q9 Q
    mov     bx, cs9 a& N6 E  K6 }
    lea     dx, int41handler2
) `5 Z8 j2 M- H2 v# E+ n( M% C7 [    xchg    dx, es:[41h*4]
# p8 s" ?( k% O& Y- G/ P    xchg    bx, es:[41h*4+2]$ |/ F4 N0 U* Q6 w2 {) _; m6 W
    mov     ax,4fh
* ~* k, L5 t+ a2 r" m# _" y' y    int     41h5 X! x- @& w: \6 d: t
    xchg    dx, es:[41h*4]
( G4 R/ q. b6 F! V! i3 ?- S0 \: i    xchg    bx, es:[41h*4+2]
' B- P; l  d, H  G    cmp     ax, 0f386h
  ~( ^+ v& [* \( \8 n  e    jz      SoftICE_detected
/ b" i8 R- W# U' }" {) t
3 N# x1 J# `) Z* S# iint41handler2 PROC
7 v! O# k. f! _- J: k5 |* n4 ]    iret
# k3 h1 n/ @+ w- H% H4 \- Rint41handler2 ENDP
* ]; s& `) K1 U7 D
, j( M- ]+ P; Z0 P. {* q, t! x8 G8 A  A: `& a" x1 k
_________________________________________________________________________: c, [4 j0 D0 G8 i

1 ~9 B5 B, S: W8 S# q4 V4 S# v5 L2 ]$ p$ M
Method 060 M4 X- V6 X) M2 {4 [1 n# E
=========, t9 d  p& u2 V1 t3 i
; _) C  S7 T4 q4 c

, k& |! M& l3 v$ V, z2nd method similar to the preceding one but more difficult to detect:
  |9 n1 F0 Y  l( j
1 u  W0 O9 D, q8 x" R  b+ F) e( \& t" K0 S% D
int41handler PROC
/ s) C, x" d- Q& z    mov     cl,al
, ^! r  D. k/ Y( ~    iret
) ]& I/ M% C2 V& j/ Z8 v& {0 @0 aint41handler ENDP8 |9 H; h% M4 I/ r
# |/ j$ {0 c: q4 Q
" [6 h& W3 _$ W* s) K8 b' T
    xor     ax,ax
9 R/ L3 u3 D" a  \    mov     es,ax
, x2 J% S, w3 ^0 h0 j- R: o    mov     bx, cs" w. E* L* j$ C5 e
    lea     dx, int41handler: c* P+ e3 O8 a, Z: _( r4 b
    xchg    dx, es:[41h*4]# `4 t9 u" O' k1 k
    xchg    bx, es:[41h*4+2]
7 U; G$ W: n3 p8 k- c    in      al, 40h8 }: W0 u+ m! }( W% _
    xor     cx,cx1 O8 P- I" N" S2 O4 U; I5 F8 T
    int     41h
0 r: I0 Q/ Q, S# e    xchg    dx, es:[41h*4]
% s$ \; |# o; W: n) p5 \" J    xchg    bx, es:[41h*4+2]2 B/ J7 y) \& x: U7 M5 B( l0 r! y& _
    cmp     cl,al- h* U  w8 w5 [
    jnz     SoftICE_detected- B1 z% W3 }5 V) N

  g! \" h. ~$ h% ]- s1 z+ q3 ]_________________________________________________________________________
0 ^5 h# `7 z6 z' ]( a  Y* P$ ?6 H, l/ i/ I* _* u, l- l% x# n& T3 A
Method 07
' `; i( G! Q* A! H=========9 l* Q8 {) W  ]! P" g  W3 Z3 x# l
- f/ x6 z: g! t7 I
Method of detection of the WinICE handler in the int68h (V86)5 I6 r7 A7 e; N0 z- e$ t

7 h$ y1 ^3 Y8 u3 @) v8 Z4 Q5 C* f    mov     ah,43h
; Q. ~- {' ?  ?2 E  ]  p1 K# K) I    int     68h" i$ Y2 H, \; [, A, J/ }
    cmp     ax,0F386h
8 p1 v8 B% _1 B: ]7 u2 {+ a& u+ D    jz      SoftICE_Detected
8 m* N: b/ x( j4 q
% r' ?9 X5 `1 g! g2 H
9 X) O. b1 V9 A5 B' y1 }6 W8 T  n=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit* A) w1 |# |9 ]7 V1 a, M: ]
   app like this:
1 o) a% X; w) V- h- G, a; `1 Z7 b: A5 f# P$ A
   BPX exec_int if ax==68
4 C: W' Y8 z" r   (function called is located at byte ptr [ebp+1Dh] and client eip is
% w2 W" [% N: I' K9 N: X: a   located at [ebp+48h] for 32Bit apps)
3 r5 F# y# n+ Q1 G$ u$ S" N( t8 u7 e! I__________________________________________________________________________
2 O; c" x! h/ N
/ [2 I0 l! ~3 ?7 I# F. m; G
. o, K% }/ \$ H  @Method 08  P2 B# k4 ^2 h( m( h& B: e. ~
=========% \- C& u: P/ n0 q  B0 x

5 `; F$ r' {) N) C4 }It is not a method of detection of SoftICE but a possibility to crash the( }% _, {, y5 M4 ?: E. ?
system by intercepting int 01h and int 03h and redirecting them to another7 l9 q: A% _1 v& W! Y5 \
routine.6 k, e; t8 R4 B8 f' }$ }
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
" |2 g5 A" p, {7 M0 fto the new routine to execute (hangs computer...)' Y! |# l' n( b

* v! _  F9 k. n    mov     ah, 25h
7 C% P. e4 R/ m( H    mov     al, Int_Number (01h or 03h)  c6 D: N* a, F: L2 ~' T  Z/ L) |) I( [' e
    mov     dx, offset New_Int_Routine
! e% g4 d/ P& ^  p  t! Z* w    int     21h- [9 `, I. }) U

& }: \3 @( P) `' y: V3 i: c__________________________________________________________________________, \- f: y9 F9 H# i5 j/ m
8 Z6 c& N8 v' `; _
Method 09
( \' v' ]& `0 a4 \! T- L4 M4 G0 U=========5 [$ x1 q  m* j- }% e4 e+ m% a

0 P% }# f$ o3 aThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
8 `% n% m% o9 Kperformed in ring0 (VxD or a ring3 app using the VxdCall).+ u& a0 N; g+ ?& F4 d) t3 R
The Get_DDB service is used to determine whether or not a VxD is installed6 a+ r. W8 z7 m! e2 Q
for the specified device and returns a Device Description Block (in ecx) for. N( Q0 k( @( F/ |% E3 V1 u& V. l
that device if it is installed.5 \0 ^, d1 l& P+ y
4 M4 G( M* Q, v0 r6 D+ K
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID5 ?  @) B2 @% D, v( k  r# a' s
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
. Y* M, o" o* Z! o* r7 t* X5 |   VMMCall Get_DDB
, x; _2 n6 l7 k8 T9 g8 c   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
$ H, p8 C7 Y, H
+ r$ I' ?5 ?  L/ E  `+ N2 }Note as well that you can easily detect this method with SoftICE:! t# X  _# t) q5 y# O! s, C' ]
   bpx Get_DDB if ax==0202 || ax==7a5fh4 k+ u; w# f6 y1 h, ?  T1 [# k" p" r

: {% S" \) O: p# Q__________________________________________________________________________
: k* o3 j) O; m) F/ y. ^
% |# F7 G. Y: t0 Y5 q5 |Method 10
6 `6 l- l. b7 C& U3 X; F; B3 L=========9 e5 }* ?2 B) T! {* E0 B+ Z, _
7 C6 [( i; E1 V* F5 ~  U
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
/ q4 @% `2 @2 w' O  SoftICE while the option is enable!!
- t; }6 N8 |1 X/ ^6 L6 o' \2 J  N. v4 P" I3 ?
This trick is very efficient:" ~! p) b$ F, b
by checking the Debug Registers, you can detect if SoftICE is loaded
3 b  w: D- E+ Q1 t$ R. I(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
: ?+ k/ f0 H' Othere are some memory breakpoints set (dr0 to dr3) simply by reading their  s* o3 f0 X; x3 S* a0 \
value (in ring0 only). Values can be manipulated and or changed as well
8 `5 a+ ^% b, l7 v  ~3 ~) C(clearing BPMs for instance), T& Y' w/ z4 l4 _) r9 U
6 b% _% i5 {* q5 v) g/ o+ O% K
__________________________________________________________________________
6 ^4 a( m0 ]1 i5 Y
9 I: K/ s0 Q6 X. @Method 11# c0 e9 A& N1 m% e  o
=========
. s8 p3 b# U0 |; m0 n# Z
: g5 j; W8 b. [. j+ n8 B' v/ {" RThis method is most known as 'MeltICE' because it has been freely distributed; n  ]6 Q" d* v5 _1 D
via www.winfiles.com. However it was first used by NuMega people to allow
/ x+ j2 W; F6 t# R5 t5 `$ sSymbol Loader to check if SoftICE was active or not (the code is located% ?. U5 Q- k$ F: b
inside nmtrans.dll).
( [9 y7 V9 f1 A4 w/ e" n
3 Z9 r" ^: O& q! O- g% G7 p1 X/ ]5 bThe way it works is very simple:
) M0 U. K' w% }5 C; BIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
) z3 D6 w$ L8 G7 P+ k& VWinNT) with the CreateFileA API.
& q' q8 G, Y6 A1 F5 j
; b( s8 v. D: L7 Q5 F. hHere is a sample (checking for 'SICE'):* \: c0 Q+ F8 L* A' T! G

9 }& }! {8 q; }3 H2 \BOOL IsSoftIce95Loaded()
# [) n+ D, S9 ?- s4 P{
: ]0 n+ k) h: N: s: _   HANDLE hFile;  7 y. y1 |: ^/ R/ U" z
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
9 c7 n* P% z6 B7 D! L) w                      FILE_SHARE_READ | FILE_SHARE_WRITE,' k9 |5 }* V4 \9 K
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);$ V$ K; c: ^8 R/ @! z3 Z  s
   if( hFile != INVALID_HANDLE_VALUE )
6 J/ o0 ~6 |9 f7 q9 v   {5 o5 \, D/ V9 S7 T% s) q5 l
      CloseHandle(hFile);# v" h- L' V$ z) Z* g! ^
      return TRUE;. @$ x" f# z+ f9 k# `1 |
   }# k  t% U) a7 R' G. ~% r2 d
   return FALSE;
9 @/ L% |2 ]7 d! A8 m6 f}
/ Q4 r8 _- v9 h+ z" @7 A
( c0 E& U! J( ^! y4 AAlthough this trick calls the CreateFileA function, don't even expect to be
1 T# \$ w" v% ]; y, f+ d+ Wable to intercept it by installing a IFS hook: it will not work, no way!
1 _! j( M" R2 K9 ^' m7 `In fact, after the call to CreateFileA it will get through VWIN32 0x001F% r# U5 x0 g) k; T- i
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)4 a% q* l/ m. n5 S7 m# i- L
and then browse the DDB list until it find the VxD and its DDB_Control_Proc$ ^. t& L) n7 |' H- A/ @2 m- X
field.
* X! k+ p5 t+ B! N' kIn fact, its purpose is not to load/unload VxDs but only to send a # D9 e2 {( j% l: n( ?
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
( T, `7 w% g5 D3 ?: ?1 ]to the VxD Control_Dispatch proc (how the hell a shareware soft could try
5 |% [  n* d0 J" ~to load/unload a non-dynamically loadable driver such as SoftICE ;-).! ]( M% b7 ]' ?$ e) @
If the VxD is loaded, it will always clear eax and the Carry flag to allow
' F/ f+ ?% }! H8 ~, rits handle to be opened and then, will be detected.
2 D+ A1 `1 _/ g" K1 }0 |5 LYou can check that simply by hooking Winice.exe control proc entry point& q- a& z4 \. B' Z' v: v3 q' b
while running MeltICE.
4 w+ v/ U+ U( y7 b; S* `" U5 g' ?# x- n, a. c  y# G# n

3 l. Z9 x. R& T0 B; f; v: q. u  00401067:  push      00402025    ; \\.\SICE
. S1 \9 C6 Z4 n7 y8 W  0040106C:  call      CreateFileA0 p( M0 K* i1 l& a+ z" P
  00401071:  cmp       eax,-001* K1 E+ f+ k* `" h
  00401074:  je        00401091
4 ^" E* ?+ L7 ], }4 |: \# j- e9 X# c- i( \7 o& z- u  h

. F4 E$ Q+ [) U1 GThere could be hundreds of BPX you could use to detect this trick." c' ^# o  D& [
-The most classical one is:
! y: d7 }" W# E; V# c- v  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||2 M# v- e1 s; n8 p
    *(esp-&gt;4+4)=='NTIC'
3 k% m- A" T4 y. O' E) L
3 a7 M: m: F" `  e' ]9 K% t8 y-The most exotic ones (could be very slooooow :-(1 [' q. b: \0 o, L4 v% C
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
* _9 s" ~7 X& N, ?. v; ^     ;will break 3 times :-(/ {8 h; w/ ]3 z( e  p! y  M

* j9 v# X3 V3 O& j3 c7 y, V-or (a bit) faster:
* Y! l2 r6 H" M3 z$ t6 o% g   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')% W8 R- r6 N7 B7 C
( ]7 V/ T3 `1 v- E. b! Z
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  4 m* c5 W( \& k" O/ U4 E
     ;will break 3 times :-(
5 i2 K" p' A2 ~- L6 }1 @. ?5 A& ~/ J6 {, i% y. p) j& }8 A% `1 e- |
-Much faster:2 f# Q, v( w- H
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
9 u: R/ \) h  _1 `! o: N: M, }5 Q4 P8 X* a# z& y# M% s
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
1 C: }* [: F- p3 S+ O0 ^function to do the same job:6 v3 r$ E+ C! s/ a

1 [: z5 I. ~, R; _6 F, ^. ?& X& h   push    00                        ; OF_READ
4 q# i1 o4 W$ u6 A2 z0 ]2 Q   mov     eax,[00656634]            ; '\\.\SICE',0/ X, S) {  _$ E8 M; r5 O: |+ @0 x; |# g
   push    eax
2 P" V+ d' N5 k* }, E2 ~$ j   call    KERNEL32!_lopen
$ |/ M% l! s' q; u) M5 X   inc     eax" C: M( |2 d; N- p
   jnz     00650589                  ; detected
- p3 e1 J. E: \& ]2 L+ a   push    00                        ; OF_READ5 \1 S* B' L, a" _) }9 ]
   mov     eax,[00656638]            ; '\\.\SICE'
' x* r# o; I/ g% A* Q) U   push    eax- L( S6 }* J# [) F+ [8 @- ?
   call    KERNEL32!_lopen
* K7 H+ \3 Q( Q/ Z7 e" e   inc     eax- L9 B1 N: Q$ @/ F
   jz      006505ae                  ; not detected
4 I7 o1 B" D5 h$ V7 |" d
; f; J- O4 L2 l6 e' ^* Q1 u0 h' `3 n8 n8 m- V
__________________________________________________________________________9 |0 L+ j& ?+ u: D9 Q2 N1 j

2 A; I. Q6 d9 A4 r0 M9 r. jMethod 12
' A& t! i  w, z! g=========
  V2 O+ g. p/ D+ @
) e  g3 z6 @2 A" x& x$ \& XThis trick is similar to int41h/4fh Debugger installation check (code 05
  a* ], d9 M! T% G1 y! ^/ s6 V&amp; 06) but very limited because it's only available for Win95/98 (not NT)
2 P; M3 y& D) L$ Oas it uses the VxDCall backdoor. This detection was found in Bleem Demo.1 X* j; E% [5 T. l/ S6 x/ \6 Z3 a! _
7 @% h8 R/ I) L( l0 y4 v# ^
   push  0000004fh         ; function 4fh  ~9 Y( U: j; g" ?) n6 W$ s4 T
   push  002a002ah         ; high word specifies which VxD (VWIN32)& w, l4 E$ Q5 u2 H3 s
                           ; low word specifies which service+ u' k* V; ?- @
                             (VWIN32_Int41Dispatch)9 X+ l; k4 n2 w) a+ X! h4 D
   call  Kernel32!ORD_001  ; VxdCall  q/ H4 H& }5 X$ F
   cmp   ax, 0f386h        ; magic number returned by system debuggers
: ]! M. @- v# n   jz    SoftICE_detected2 X+ K8 J. {8 q2 z: t5 u

2 c: b6 U( _& F' V2 Y% OHere again, several ways to detect it:. T  {. ^* A+ ?/ V- S7 b0 l# U8 J
$ n* o# m, T2 q5 n) ~' w) v
    BPINT 41 if ax==4f
" j4 o6 F5 R* Z" [- H
4 H8 J9 U: p; x% D9 M    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
. Y) X3 t8 t, M
" Q1 N/ i- N7 {8 [& S) G    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
0 x, m2 t* p& F% r
6 a; I& k( Z$ E, @  R0 K8 |# G    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!/ x" |& M/ M3 A4 k

& V) D" b, M/ b3 A& a__________________________________________________________________________4 N( h* j  l) B% h1 Q" Y
# S0 {1 i- M( g% G# C( ~  p
Method 13; o( J% z. x# l3 g
=========
# ^: Y9 W- J" }# H* a9 R5 t4 a: M" `) d8 z/ q& C# `
Not a real method of detection, but a good way to know if SoftICE is
" Z/ C! I1 f8 w# t" Tinstalled on a computer and to locate its installation directory.' s+ x; |$ p9 e: R7 B  q
It is used by few softs which access the following registry keys (usually #2) :: L4 `5 R, ?. P* V# i# S' D

! \, D3 p* ]- R( _-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
, s+ a% `8 s  ]7 R- X\Uninstall\SoftICE
1 n* l0 R. A9 B  ]; n5 K1 ^-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
  Z$ f6 G& f' q* {& @; @-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
2 D4 f" q8 z  n, s' Y7 U) W\App Paths\Loader32.Exe
- I1 U6 q: K* x7 i3 R( k- [6 [$ }0 l0 R1 L6 D4 k8 z

% P( ?+ B* P! Y& K& fNote that some nasty apps could then erase all files from SoftICE directory( _0 |) `" J5 g# n0 W9 s
(I faced that once :-(
  E, y1 t. b$ f9 u% T1 R2 ?
% `* ^; M) x, y: [& v6 UUseful breakpoint to detect it:
) P+ d% N$ l) X& R# B( z  O- `: X# _  f( x' p
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
% ?: r% D, Z+ L- L. P+ O
" ?7 _7 g2 q/ ?# {  I3 A, b__________________________________________________________________________8 I$ |/ X! C/ I% q* [; @8 i
" w2 \6 k0 V, k, M7 W

" |0 [! A& r, Q( XMethod 14
) B7 q5 R  w; A; [=========: R1 o* W9 W% V( g! m

0 u8 h0 n5 c8 B: w$ T1 r. t2 RA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose3 N1 D, r& l& M  S
is to determines whether a debugger is running on your system (ring0 only).
' F- V5 |5 h# D2 ], k
" H4 u# P, ~  `   VMMCall Test_Debug_Installed
! o4 d. T; x0 b   je      not_installed! R7 o7 J0 b  `# @5 y4 v

  o4 |% |: ]: D% _% [This service just checks a flag.
# R# g* M! m# `1 a7 x</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部