About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
$ c  G! D) O; d2 H" }! q, G  q<TBODY>
5 v& y( S% r* _' D<TR>7 C4 T* e* }* G9 l- U# _
<TD><PRE>Method 01
8 k) S3 g( A2 @5 L5 Z=========, E) c9 i/ ?0 O. }9 g
) S  C- ?3 S  C
This method of detection of SoftICE (as well as the following one) is
! S$ o  S, ]% d6 m# Q+ xused by the majority of packers/encryptors found on Internet.
% J- [. _( v# R# UIt seeks the signature of BoundsChecker in SoftICE* @8 q! B) |7 l7 h# Y

4 m4 X7 R+ k3 b! T+ D    mov     ebp, 04243484Bh        ; 'BCHK'
* G6 S0 W/ b" z/ |! m! U    mov     ax, 04h
; m! _3 {5 ~" I) e0 ]9 }! `9 A1 `7 u3 K    int     3      
# P/ M$ D+ ^- v    cmp     al,4; A+ {& ?( e2 q4 r' W( t8 D
    jnz     SoftICE_Detected
: l2 w" `8 s- e4 M* p; ^
9 u! u3 U* R# q7 `0 N+ ^___________________________________________________________________________
+ X1 A+ H4 g9 q3 F6 h5 r6 [9 H! h7 w$ e
Method 02
) r. m: q' _! |1 L=========: L% o3 q! k* X/ [. I
4 D$ w$ f& q7 b$ {5 Q( h
Still a method very much used (perhaps the most frequent one).  It is used2 e) k% L% Y; \/ N2 x9 M9 J6 g! a
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,+ d  E5 `0 Y( r% z' D* Q" g
or execute SoftICE commands...
; G' d$ G" ~- _/ N4 }5 F1 R5 q9 SIt is also used to crash SoftICE and to force it to execute any commands
1 c! X' d( O4 [7 e! I# \, z(HBOOT...) :-((  9 }( x( {9 ]9 r; Z( D( `# \
0 g6 I; b7 q$ w) Z
Here is a quick description:2 E2 X) j: w4 r" [1 Z0 }# z) M% U0 D
-AX = 0910h   (Display string in SIce windows); R$ M. \. U" }5 `' a1 L
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)7 B- u- f# p! r6 v% j( `  Y1 v
-AX = 0912h   (Get breakpoint infos)8 X6 u# _5 z/ n& q8 l* c9 ]
-AX = 0913h   (Set Sice breakpoints): u& s4 A' y  w2 O) b( i+ Q
-AX = 0914h   (Remove SIce breakoints)
; F5 E5 u6 d' J2 t
$ [8 F+ r6 P  I2 k+ nEach time you'll meet this trick, you'll see:4 Y7 q7 J# f, a) b2 }! Y
-SI = 4647h
# d$ K$ d3 d) M2 p5 X; [1 V4 ^; Q5 O" }-DI = 4A4Dh) {' P$ x4 y6 x: }
Which are the 'magic values' used by SoftIce.; i- b8 H+ P. A
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.3 x" W/ \+ w7 R9 z' `: z0 `+ N
+ ^4 W) r/ F: ]. `
Here is one example from the file "Haspinst.exe" which is the dongle HASP
) Z! q+ [9 x7 H  E% }  Z  b* [Envelope utility use to protect DOS applications:3 h) v/ R3 D8 g5 R/ Q2 L( U# O
. M! }9 t5 y- Q0 c

; u8 _9 M: C# H  u2 _1 `4C19:0095   MOV    AX,0911  ; execute command.; ]9 r- A9 Y# n% `+ t, q* }5 g
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).) F4 J9 _/ X, x2 c
4C19:009A   MOV    SI,4647  ; 1st magic value.
) o: p3 s9 W: e8 s3 D+ I4C19:009D   MOV    DI,4A4D  ; 2nd magic value.$ N  y" s# |$ _
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)) b+ ]. F+ v& T; t. Y
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
1 X! D4 m0 x9 A$ q9 W5 y4 K4C19:00A4   INC    CX
: E" h0 Q1 k9 S  N0 ^! {4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
% f' w" L6 {5 }# Y5 N0 I  R4C19:00A8   JB     0095     ; 6 different commands.
0 f- d# o) o0 }2 P4C19:00AA   JMP    0002     ; Bad_Guy jmp back.& O, R2 {, l6 D0 c
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
. `- e# q2 F& l8 d; v, d# ?1 H$ D. g9 \
The program will execute 6 different SIce commands located at ds:dx, which
5 P5 a4 u1 |3 u7 Q" l/ Kare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.9 z7 B" m" S: Y, H4 U( ]* Y
/ C3 V* ]  I. _
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
# t4 `. Z( ?( }$ c___________________________________________________________________________
. k& W; A" _3 E5 }1 d5 r1 @
# p4 X) C( \" z/ ~5 y( q- ]- x" O
Method 03
2 g. t4 N& u5 O) y: c9 I=========4 k8 B6 U6 J  X: |% i% b  Z

" Z) B' |; }8 O8 o2 c( NLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h8 J6 p' }2 O; _  V
(API Get entry point)! P  U& j2 \& _+ k7 f
        6 d1 f( t2 B+ ]: J/ y- [5 n6 p

( ]2 T2 U+ v; d, g& I5 M    xor     di,di7 W* E1 |2 X  s! m) T+ \
    mov     es,di
/ `9 ]3 `: F' D8 }. U- b) t5 j    mov     ax, 1684h      
$ j* V7 w7 o7 U" j  ~    mov     bx, 0202h       ; VxD ID of winice4 [$ r& c! ^# Z+ L# ^# v# M
    int     2Fh; l( [3 ?. y# H+ N) H+ \
    mov     ax, es          ; ES:DI -&gt; VxD API entry point5 w, `+ Q3 r0 l8 b9 M; _  y
    add     ax, di
/ f' U5 s6 K1 \& `' m    test    ax,ax5 J8 y  c0 L" u
    jnz     SoftICE_Detected& ]5 D2 ^* Y+ I# K6 ?$ e4 f

4 j! W( A4 }' Z' j( x5 B7 e___________________________________________________________________________! E2 n( i0 }7 h3 U: v$ s5 h

- n8 y- j6 }: ~# p9 eMethod 04  E7 z, I# P: M7 n( u: J
=========  b# {: Y7 ~. P# y! R7 }9 a
+ k) v* J9 h, P+ n
Method identical to the preceding one except that it seeks the ID of SoftICE/ k4 W3 Y% F6 G. q( F3 |: R
GFX VxD.
0 _3 i8 o& R" l* q' D" U4 {8 @9 [) S! t: R
    xor     di,di3 d4 o: y% d5 h0 ]8 V! H. T
    mov     es,di
$ R& P* c$ t" A9 l9 p# g    mov     ax, 1684h      
2 s. _) Y# C3 O    mov     bx, 7a5Fh       ; VxD ID of SIWVID
- g& Q) B: {7 D0 L, \    int     2fh
( f1 C' b. U" S5 q9 O9 g2 G" O& t    mov     ax, es          ; ES:DI -&gt; VxD API entry point& |9 A, G& d, G) n  S
    add     ax, di
6 o- }+ h) Z0 C7 {; s$ |) h% M    test    ax,ax
/ ?+ {# A2 B, {! |) v/ p    jnz     SoftICE_Detected! K/ O! D: Q* X5 t" G
, \5 |/ |! D* _3 |2 {9 ]' Y
__________________________________________________________________________
* R, ]- k8 U" E2 b1 v2 `' s; a" F* @( K7 T0 P7 J0 U

9 H5 _( D5 G/ s' K3 B/ hMethod 05+ m2 r1 y0 f# I" E( {: m
=========) `0 q; n, t: F7 [% a$ W2 ?, }
. Q, L" ~5 H; t4 D  m# @
Method seeking the 'magic number' 0F386h returned (in ax) by all system
/ @  m6 K+ s+ Vdebugger. It calls the int 41h, function 4Fh.% I/ e2 R/ ]& M2 G" b* p, u
There are several alternatives.  
3 n- Y8 P1 f; Y/ [9 G! Y# ^! a6 i, c4 _' G; W% X2 i/ `% j
The following one is the simplest:; P; ]# c+ O; O4 B
+ O; ^# J' H' D- B9 M
    mov     ax,4fh" b% ^* R' Z2 T& V  O; D3 ?: C2 `
    int     41h) Q) ^  j" R7 R+ C" L+ I
    cmp     ax, 0F3864 u8 }* q; O! J7 Q7 I! W0 h" H
    jz      SoftICE_detected
- Z7 {. t0 F& r" L2 I2 C
. S6 {0 e5 T" i: M7 f5 W
0 Y0 B+ j, e, O/ l0 F8 T* ANext method as well as the following one are 2 examples from Stone's 2 C3 y5 Q5 T. i9 e6 T1 h7 h& a
"stn-wid.zip" (www.cracking.net):, `- c1 `; t. E4 Y! W

$ k) z$ r" `8 [' v5 Z& K& Z    mov     bx, cs
5 P( x2 E5 S; _7 I& _6 S    lea     dx, int41handler2; _+ f; t6 M2 _' b
    xchg    dx, es:[41h*4]& C7 {1 `% ~8 g7 e+ W* H5 ~+ n$ Y
    xchg    bx, es:[41h*4+2]
4 K% d2 ?1 X7 f( z$ N0 d' Q    mov     ax,4fh3 F" ^) }" N9 z9 _9 ?# |$ D% E( W
    int     41h
5 ]  k& r+ q4 I& m% w# q9 g    xchg    dx, es:[41h*4]
+ k8 ?$ _7 Q) I' Q+ v4 h    xchg    bx, es:[41h*4+2]3 Y; G$ F. L$ x$ S" o
    cmp     ax, 0f386h! N0 v7 k9 f; r5 k4 d0 ~( ^: W! z' ^
    jz      SoftICE_detected
1 @0 A6 b+ j* ^/ L) }: D+ n
. ^7 B, E9 @6 s* T' o' @int41handler2 PROC
3 z3 G7 o1 g& _    iret% L6 r5 a) o( C% u
int41handler2 ENDP
8 {( V0 N$ M( O+ b* H- }7 Q+ [% W4 c1 p% Y- ?) [' E( p" ?# o$ O
2 m0 y, p, V, T! z) ?0 ?! ]2 z
_________________________________________________________________________+ \) R9 e( ^; w% g7 ^" @) k/ i
% q$ p" C9 L" t9 F; z

4 Z) j% o6 b4 F9 @. j" s2 TMethod 06
# r5 M0 b! ^1 @2 m1 R3 C2 B! ?=========
& }+ T& r( s2 _' D: @6 b( l3 ~( J  w/ p
0 Y1 v. a) F. ~# Z
2nd method similar to the preceding one but more difficult to detect:. W3 h1 l4 s+ T3 {: ]- ]" f0 @4 _" O; \

8 C% c4 _4 H( M$ s  D  h" m* G3 Y) e9 k" e: h
int41handler PROC
! K2 J% _+ E- R    mov     cl,al
; f% c' S4 K) u( m% G    iret
+ D8 P+ I5 o" C. P& f5 P1 e' E/ z( ?int41handler ENDP: Y( U# _1 T/ ^  m5 p& R& h7 `

6 z, O! Q! D  h2 l- f+ `7 L* ^: m' B; v& ^2 z
    xor     ax,ax
# h, j, A: Y% E. M: o/ Y+ a* r    mov     es,ax5 L( _7 ]) M- p$ m
    mov     bx, cs
- Y, Y+ X7 H+ x1 t% E* T    lea     dx, int41handler
! b/ U( B& V7 ^8 c. N5 B9 j    xchg    dx, es:[41h*4]
$ I! p5 x' Y$ R2 A& A0 w/ {& k    xchg    bx, es:[41h*4+2]
6 W7 X) V# [2 V    in      al, 40h+ `7 V+ ~8 U/ T% [: f& j
    xor     cx,cx# d" P" B! f, x
    int     41h
+ \7 o! R. ^% D, a    xchg    dx, es:[41h*4]
% E% u% H& S% d: V6 t: u    xchg    bx, es:[41h*4+2]; f7 l) d: b& l# B  O
    cmp     cl,al6 ~' Z; x, Q& B6 Z3 C4 D3 k" V9 K  B% E( q
    jnz     SoftICE_detected( K8 R& S8 T! j, O" h# J8 }" Z

) F: |$ k5 d. Z6 h0 @+ i7 {_________________________________________________________________________
, ]! a" r" V$ E- H6 {' L5 w  r; }
7 o; g8 {1 f0 d' t: ]Method 07
7 H" S$ r2 R9 [=========
3 y, e3 }2 L6 i" q8 B* `. Y3 c7 N- s
Method of detection of the WinICE handler in the int68h (V86), w7 H8 q5 L% A4 }8 ?9 ]* v" p

9 |9 h. ]! J, W) ]* T& }( K    mov     ah,43h
$ G' ]9 I4 n" W3 c5 S1 @    int     68h. P3 `6 t# d6 D" y+ E4 Q' n
    cmp     ax,0F386h
5 M* Z" d8 M7 G* F% f4 [* |    jz      SoftICE_Detected
  r* a( i" I5 ~2 I6 }
8 |. D7 y+ b, _3 U+ Q  U4 r* r( \
& v" o" Q0 K* c" j: k, |# N5 p/ s=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit& F* I& l  o( o  O% P8 A% g
   app like this:
( U0 Y% O1 M% E  ^$ V9 A  s: ]; T: ]. b7 G1 W0 g
   BPX exec_int if ax==683 n  q% _/ B  R3 M
   (function called is located at byte ptr [ebp+1Dh] and client eip is
# B- F9 Y' X: G: W4 x- Y   located at [ebp+48h] for 32Bit apps)
/ a7 ?" B0 p" Z6 t  n+ h__________________________________________________________________________% U7 u8 g. b" u5 X7 j
, @# A* {8 p1 B$ S" m, b0 d

3 O+ r& P! |$ ?. E6 J& CMethod 08
) {, e( n. n/ P( q) {=========& Y  p$ C# H/ w2 }- {, v
  n# t7 x. f1 |/ \/ |/ {6 [2 b/ H
It is not a method of detection of SoftICE but a possibility to crash the
) p6 r5 G/ Z* B; j+ p9 a7 \system by intercepting int 01h and int 03h and redirecting them to another/ v! O* A9 s, @
routine.
/ s* {) q0 q) h$ ^" _& h' c" |It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points) q( \: k8 }5 |
to the new routine to execute (hangs computer...)
: _" r- q' i; K( U/ n1 h& i% @4 }5 |9 V$ o4 H
    mov     ah, 25h
, h3 O9 `: S9 M# s) ]    mov     al, Int_Number (01h or 03h)
. L4 B& |5 ~' e  V' \    mov     dx, offset New_Int_Routine% l& A2 ^5 H; Z( Y" W; _  K
    int     21h/ s- p+ h; g5 u! N3 E  m$ p
; b8 w5 q- ?, s
__________________________________________________________________________3 i& R4 p  c6 T0 h7 y! `1 y

. N: n8 ~$ a! f  \6 T) `  R- WMethod 09
- @5 r  ]% s! i5 R9 `5 E$ S: G$ ]=========
9 Y* M4 V5 U2 d( F+ z: N9 g
5 n/ B. Z3 y# e1 P: LThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
0 M7 r% a9 Y& V+ mperformed in ring0 (VxD or a ring3 app using the VxdCall).6 M  {' e: q) ^* ^  H8 s  L5 x
The Get_DDB service is used to determine whether or not a VxD is installed
7 f; x* g/ f* C+ O  x! Z9 U! lfor the specified device and returns a Device Description Block (in ecx) for
8 l7 [4 e5 o( _9 ?0 b& h6 Rthat device if it is installed.
# K6 E7 m+ c4 F# G/ P$ }( P4 }! p/ l# @, Y$ j3 H3 a
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID6 z" F, o7 W! ?- N8 y5 z# T+ N
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)2 f8 v: K: l0 w1 i! S; i* i. J/ M: a
   VMMCall Get_DDB+ u' o- f% }+ @2 ~* D+ ^$ r4 F4 y+ T
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
! Q7 @8 e& k; y
8 B6 L9 @9 ^! cNote as well that you can easily detect this method with SoftICE:3 M+ S  [1 I* _- ~- u% J- r
   bpx Get_DDB if ax==0202 || ax==7a5fh
; R4 W' Z$ @6 K. _" D' ~- d8 Z
. L% L# z. \" \5 R1 ^__________________________________________________________________________
% H: x% g- ^+ n( ]
% e1 c1 Z3 Z. |- h; QMethod 10/ t! i, o6 z2 L
=========) G6 n2 b, [' C# q0 w; a' {
- R0 I2 x& q/ d  X
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with- b2 W: p9 e9 S* o) u" `4 B7 Q; h
  SoftICE while the option is enable!!9 U0 Z. f+ y+ h  k

  d* u; x5 p* E* M8 D  jThis trick is very efficient:
& b$ D. P4 p) \2 eby checking the Debug Registers, you can detect if SoftICE is loaded' g8 H% [1 G$ C1 c" _
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
  c3 F6 J  T# L$ k' \2 k5 Jthere are some memory breakpoints set (dr0 to dr3) simply by reading their4 H7 I2 e, z* i- y' M3 ~
value (in ring0 only). Values can be manipulated and or changed as well
9 o9 P8 y' P  h" ^" O(clearing BPMs for instance)
( c; @1 n( J1 e9 ], x6 k, E- C+ D1 M6 y8 F2 S% B
__________________________________________________________________________/ `1 [9 m* P1 G' Z0 v5 n
6 b1 R* Y: k# O- k
Method 11
; G8 Z7 U, T/ @# Z4 H=========
% q5 y" H4 ]9 }" p! G9 y" _* s8 f: b1 Z& \4 h& |3 x
This method is most known as 'MeltICE' because it has been freely distributed
! G2 z' L  P7 T" {: z! }via www.winfiles.com. However it was first used by NuMega people to allow, o9 l, y2 V6 v: n7 {
Symbol Loader to check if SoftICE was active or not (the code is located: j. R( v. r3 {& [+ u4 ]2 X4 Q
inside nmtrans.dll).
, F7 N0 N1 H& u& x/ G/ o; F! ^' a: F
% t9 u  \) I+ b) u* D1 \, t; NThe way it works is very simple:
# R4 p0 ~: m* f' c# p2 M9 j" bIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
% ?, {  E8 u8 Y% N- @WinNT) with the CreateFileA API.6 I  u- v; q6 T  |% M. S: a

' ^' b, c5 z# W- S$ W2 b. qHere is a sample (checking for 'SICE'):
/ u, }7 a/ m/ V* G+ n) A# V3 x/ D. E+ `1 W
BOOL IsSoftIce95Loaded()5 i: ]+ A4 Z# c/ Q% o$ G# ?* o, @
{
, [/ ]$ |8 b: w& _   HANDLE hFile;  3 ^1 z; y: Z8 r9 K7 R) ^3 e+ {
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,8 L: a' o# Q! _! h; _/ i
                      FILE_SHARE_READ | FILE_SHARE_WRITE,' w0 x9 _! R+ X- m7 d. M0 m* e
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);0 ~3 [1 R8 M; A7 U6 |( v
   if( hFile != INVALID_HANDLE_VALUE )4 F" \7 v6 t6 B1 Y# b
   {
; o! `- v" Y1 t/ P0 u      CloseHandle(hFile);0 |% I/ |2 H& e
      return TRUE;
1 N: }) H7 d- f! r9 b/ ~   }
. }" K. z# h. O   return FALSE;
1 e2 u* k2 Q. ^' M6 J0 b$ Q1 ~}$ m  q8 ?! N% ^6 M) Y+ ]) a

0 T  ^, w" g$ S2 M: A$ LAlthough this trick calls the CreateFileA function, don't even expect to be3 I3 L. m' ?6 r) P- H
able to intercept it by installing a IFS hook: it will not work, no way!
& x! U# k: S3 {' bIn fact, after the call to CreateFileA it will get through VWIN32 0x001F# _9 h! q3 ^# W3 ]% U  j5 t8 Y
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)( U0 l0 Z% Q* c' U; ~! h
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
! \9 k7 r5 G/ f* zfield.
0 ~& u) a( E: @! DIn fact, its purpose is not to load/unload VxDs but only to send a
- y+ f4 a3 w8 _5 U9 I8 pW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)# C9 Q( T8 P; P
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
! R1 L! I: c# ^. B" a! w) Oto load/unload a non-dynamically loadable driver such as SoftICE ;-).- m; |, z: r8 f$ @: f) y7 a
If the VxD is loaded, it will always clear eax and the Carry flag to allow
$ \  w# t; a# W/ G' z+ n3 I0 Fits handle to be opened and then, will be detected.
" N( s: _- X% J! h% o3 DYou can check that simply by hooking Winice.exe control proc entry point, c  ~& }3 @6 _6 E' M$ ~
while running MeltICE.* a# t# M/ `& V! j- K
2 {/ V) @6 S+ ?2 q; I

, w! v; T& f! k1 o4 ?$ g  00401067:  push      00402025    ; \\.\SICE, G$ P& P6 ~. k' b) V" Q
  0040106C:  call      CreateFileA( R8 j% D2 q( @
  00401071:  cmp       eax,-001
$ _" D  F* y4 j) I) b5 [  00401074:  je        00401091
+ E$ W! U/ _% l1 V: g$ x
) g2 \% n/ G$ ?& d  o( ]. C) N3 c* k- W$ b. z, H3 {* J
There could be hundreds of BPX you could use to detect this trick.
! g/ {7 V' a/ L-The most classical one is:
& n  A9 @4 w1 O  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
% a) C( p4 c( D/ ?* P2 K. C    *(esp-&gt;4+4)=='NTIC'
& t( [4 X- s0 X2 p+ J, K& u; }5 S: B3 \# [9 A$ X& I
-The most exotic ones (could be very slooooow :-(, I/ t) Y% S) X! S: x
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  8 g" G  Z9 T, \& t
     ;will break 3 times :-(
, F6 u! W; G3 D; B5 v# n$ l. T
-or (a bit) faster: / A% M+ R: I4 f9 H" ?! z; l
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV'): a$ {9 Y2 R# E# X& Z, _' Z6 a% n8 V
5 A; w. @, s) v' Q9 m  \
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
' X- F9 j5 I5 d6 z     ;will break 3 times :-(2 R. Y5 G; L- _% O

0 D5 @* F1 n! q; F& v6 H-Much faster:) T. `1 n  `& U$ T5 A
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'; n/ U6 L0 B& T1 S; n

* k; J* K, W( [- d: PNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
) s. Q5 ]) H& m9 D& b9 o2 W6 Qfunction to do the same job:1 ^+ ]* g" A4 @/ Q4 z

3 m7 g/ R: m3 t8 _$ \   push    00                        ; OF_READ
' W! W  @2 ]5 T; ]- h& J   mov     eax,[00656634]            ; '\\.\SICE',07 m6 f+ c, k7 Q
   push    eax
1 |$ O7 v, }$ F! k& q  F   call    KERNEL32!_lopen
3 I0 i7 O+ O, @2 M   inc     eax6 i+ c# b" r  _" B. W+ J
   jnz     00650589                  ; detected& @/ a( y2 m. S1 ]
   push    00                        ; OF_READ
: k6 F' N. E+ ~, }- A+ g4 G2 W   mov     eax,[00656638]            ; '\\.\SICE'
( Q% X  R+ I7 J! l   push    eax
* r8 U. P3 H9 e   call    KERNEL32!_lopen( i5 b# A# O" Y. K3 t
   inc     eax* @2 y3 M; l  P4 m2 g& _/ W
   jz      006505ae                  ; not detected
6 F' W) ^" n& z. X8 K2 d7 p
# r& O. n; g" C- X+ l
) e0 w8 y* `& T3 l% m) q__________________________________________________________________________
5 n: y% k# t( C1 l6 V* d1 w% I
- K2 W1 z9 a& EMethod 12: V& }8 O; i; E& {
=========; w: t% e9 O, O

, Q8 {6 t$ }9 `2 r! e7 z: h) R3 DThis trick is similar to int41h/4fh Debugger installation check (code 05
! G4 z4 b: ~+ w$ m+ G&amp; 06) but very limited because it's only available for Win95/98 (not NT), I0 f1 f4 E! L0 m6 a& {# P
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.. L& e' P0 b! A; \
/ R  L7 J% W3 B$ p# q+ e0 [
   push  0000004fh         ; function 4fh- u: _* R5 I: B' Y! c
   push  002a002ah         ; high word specifies which VxD (VWIN32)) d: A4 o1 P1 T) k5 C5 e. p2 o" S2 k* I
                           ; low word specifies which service& G8 d% a6 l  C1 _0 T/ n) R6 E
                             (VWIN32_Int41Dispatch)
" [* F" e4 S% h& |# @9 ]4 e   call  Kernel32!ORD_001  ; VxdCall, G- @& f8 ]  ^3 d: _5 z4 v) M& U
   cmp   ax, 0f386h        ; magic number returned by system debuggers
+ w# A% {& v5 r, B* r5 k   jz    SoftICE_detected
! m$ e, ~' J7 F0 y0 s
( A  x/ d& Q/ e- H( Q! cHere again, several ways to detect it:
9 Y" B0 \3 b' w7 c+ t; c5 S9 y* ?& N- L" x
    BPINT 41 if ax==4f
' k+ }* p6 k! N( E' N4 T, y' c" ^) w
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
. O0 ^) g: j1 w" @" d2 P5 t( X# t5 r$ t0 q. f7 L+ j0 ]1 T
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A; \( p" _% {8 m' T" g% i, g
2 g9 T1 L$ A' Y9 S4 V% K4 t& @- M$ k
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!3 [+ a, J1 C- h
: A0 d8 \& O; @( Q* Z! x
__________________________________________________________________________
  w9 A2 e+ X) C; D: h! _
, P% d$ a4 l4 ]/ PMethod 13
5 ]8 C9 e! d' Y$ m8 T7 j. j=========
! ~1 y4 T3 V* P. M7 m1 r6 G3 d# U0 R% A
Not a real method of detection, but a good way to know if SoftICE is
3 l1 W: }# m+ K4 m4 A: rinstalled on a computer and to locate its installation directory.
8 h+ A7 D4 `: ]2 V' }It is used by few softs which access the following registry keys (usually #2) :0 q( c& S, H$ m1 ]
4 j6 U+ z, a' m5 S" A- @; Q" o
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 L0 q! e4 ]1 v) {4 i/ H
\Uninstall\SoftICE9 U/ _% \* w  |# J, q6 a0 m: I1 v
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE. H( }3 V0 k; @, J0 R4 f8 q$ w3 G
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion0 v& K/ p( W1 g  p' n
\App Paths\Loader32.Exe5 [! O$ v. q) I2 [

: E1 S9 E" B; o8 h
7 H# U6 z2 J$ S! DNote that some nasty apps could then erase all files from SoftICE directory
3 K; d9 K  |* m) w. M* ?2 q(I faced that once :-(2 C: ^! X" w' A( N8 Q. a. x0 T
# s3 ~# X7 P) i- M9 b7 u
Useful breakpoint to detect it:
: j8 n2 B6 T$ Q7 \  j. J; ~* k, R1 m% }/ ]
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE': E) c5 l; T, }% y( `4 c8 w+ m8 H6 h+ ?

6 {. U8 {4 u4 d5 m: `" _3 i__________________________________________________________________________8 z% y+ @( s: I) }3 m8 U" r
: u& X$ V- X/ H5 x

5 G5 T5 H" V" [* R- J1 ^) v: K% m7 DMethod 14
* `, G7 d. P2 \- j$ g=========
0 F* J5 X2 Z7 d; N" `- X0 ]. E8 Q, e
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose/ D4 g2 K( ~' j" w# L
is to determines whether a debugger is running on your system (ring0 only).0 }" m# w6 L" D5 Q
% @5 w9 r8 t5 U# I' E* D0 V0 D1 A
   VMMCall Test_Debug_Installed" D# W; c6 T2 y$ f* ?6 c
   je      not_installed
# T2 O- L% Y/ d+ v8 B5 F
1 _( u4 l- t2 x8 n, JThis service just checks a flag.
% a; \, t( Y% @* ^; o% I, H</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部