About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>0 ]/ d9 ^1 m2 O0 `
<TBODY>
1 X/ c! a2 t, w- \% `. q8 m4 r( `<TR>8 W# t5 Z6 E1 l
<TD><PRE>Method 01 1 k+ Z/ g1 |: _! X1 g. \
=========7 D7 C# s) q9 N, ?2 j
, m- }; D% |! Y
This method of detection of SoftICE (as well as the following one) is
8 D6 N6 a8 @9 v5 L6 e% aused by the majority of packers/encryptors found on Internet.
8 x6 i" ]8 @9 H: c. CIt seeks the signature of BoundsChecker in SoftICE
6 H7 x5 d0 P, i! }9 }9 y$ ?
( w3 J6 s0 r) `& ?6 m$ X    mov     ebp, 04243484Bh        ; 'BCHK'
/ O% l) B/ b; r: N* Y5 J. {    mov     ax, 04h) I& \/ R( t9 O5 [2 u+ Y1 j# C
    int     3      
$ P- S2 |; r0 R  e' ~    cmp     al,4) ?% L; q$ `) P6 b+ `+ h7 k7 I& w
    jnz     SoftICE_Detected
' M8 Z5 _& k+ u3 y# F% O6 x
0 U+ w( `8 q  v___________________________________________________________________________
& _1 G7 O  I6 f$ I" A) t  l" Q. a- J* y7 S$ v! i1 L' R# `5 _0 O: d
Method 02
$ z6 D# x( n0 ?6 @: }' E$ w=========
" q/ x, t4 O6 t3 w
4 M$ a) w+ i2 ]7 ~Still a method very much used (perhaps the most frequent one).  It is used7 S9 O/ B5 ~' ?$ Y$ h
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
; q0 t! P! h' d* \  g3 N' Dor execute SoftICE commands..., i( |8 C6 V7 ~, D. v0 p4 t
It is also used to crash SoftICE and to force it to execute any commands1 p) N( t5 f1 {) t
(HBOOT...) :-((  
0 U/ j# V3 [2 S0 q! G- ^2 ~
1 r: |4 j' t" T, _, T% FHere is a quick description:
9 O2 i% Z8 z& V7 ]$ W-AX = 0910h   (Display string in SIce windows)
0 ~/ D7 l1 Z. ~  N: [$ M9 w! w-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)+ Y! N+ @/ Q: A
-AX = 0912h   (Get breakpoint infos): Y; F" H9 d5 [( s* x( \6 o
-AX = 0913h   (Set Sice breakpoints)
& v3 E4 G, f$ I1 L3 {3 e-AX = 0914h   (Remove SIce breakoints)# A) c! ~, q( F4 `, B: b5 ]
# n% ?$ h4 d% P5 ]4 D
Each time you'll meet this trick, you'll see:
- ^+ g/ z, c* K' j4 K" ]-SI = 4647h
8 a/ x% g: g7 l8 B: r$ h' Y& m-DI = 4A4Dh/ Q0 {: h5 q2 b' k
Which are the 'magic values' used by SoftIce.+ a+ a# C, m$ A
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
: C, Z( p9 w. G" N4 p" ~2 G0 y( c5 ^0 r4 b, Z  C0 j
Here is one example from the file "Haspinst.exe" which is the dongle HASP
2 s" U/ D6 Z: \8 R* t6 X$ \! _3 `  aEnvelope utility use to protect DOS applications:$ N8 N; q* `2 s) r
* ~# E) x9 \$ i+ J. g" B

8 C5 ?( T9 y# ?1 [& b4C19:0095   MOV    AX,0911  ; execute command.. e' J) t. ^2 P5 c
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
8 F* p( u3 T( v7 x7 a* v4C19:009A   MOV    SI,4647  ; 1st magic value.
. Y( W; @; t# u. \8 F( {( e4C19:009D   MOV    DI,4A4D  ; 2nd magic value.* E; v  F# t/ ]4 Z
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
  [( O# E0 h6 a5 X& r8 t. z& p4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
. h/ L$ T5 l+ Q* _# F: i4C19:00A4   INC    CX
& ]7 ]3 W# x! B+ D4 F2 [+ y. |, X4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
4 E  N0 [' y( l7 Q4C19:00A8   JB     0095     ; 6 different commands.7 E# a, t; _; g5 @7 T; g
4C19:00AA   JMP    0002     ; Bad_Guy jmp back." O) e+ w4 U2 @' |/ f# \  V) w
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
( ], u8 E# a: H/ N
. p7 x; D6 ?, d3 G5 eThe program will execute 6 different SIce commands located at ds:dx, which
9 V& b1 M0 P9 d9 [/ tare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
  @1 q$ O! R% e6 \$ j7 N/ q' ?; A0 C5 u. Z: m& t: O- W- x
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.0 T- m) R: M6 j
___________________________________________________________________________
" @4 ]; }% k9 y. l5 u" R! G+ U& Z3 t+ V' d5 Y$ d) E8 w
3 f1 S/ f( r/ L3 H( m& n, x
Method 03
- Y7 Q; K. A7 \. Y, \) k" g0 Y2 @=========
1 d) h3 o8 ^' d/ O' p  X1 U1 @. r" R$ n6 n2 }
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h: ]: y7 A3 ^$ M9 p2 H% U
(API Get entry point)( @: ?3 s! R4 `: x
        0 }5 `3 {* i, H4 u7 Q
1 f- T  s0 D6 Z8 F0 g
    xor     di,di
% {/ x: g7 w9 g( ^9 B( `$ ?    mov     es,di" X" L3 ?2 a, Q8 h) r* z2 }
    mov     ax, 1684h       , m4 O1 M3 n0 J2 p4 @" n
    mov     bx, 0202h       ; VxD ID of winice, G. K& {* E, z2 d6 S' i
    int     2Fh
6 x$ M" p7 a6 h    mov     ax, es          ; ES:DI -&gt; VxD API entry point6 T% o1 u' J0 e( H; o9 M
    add     ax, di
; H! n0 H% x# t7 J* o, p( x    test    ax,ax
7 g! v  M" r  d9 l, C. n; M& J: |    jnz     SoftICE_Detected9 j2 I! U1 X1 \' q; _
. M. V- i- V- {4 X* l8 T$ {* `- y
___________________________________________________________________________
- s9 Z8 P2 K! y8 a5 M8 K, g
1 z; C- T) C3 e/ a5 O" c3 I8 OMethod 041 V' \- K2 V$ x( g
=========5 X; a4 z+ \2 t1 Z5 {# w0 G
& O  z9 |( j3 k5 e# H, q% l
Method identical to the preceding one except that it seeks the ID of SoftICE
; s7 {5 g: M% v$ e' X! ]/ W) Q. O, eGFX VxD.* ^! s* Z* L8 k3 L6 E& f

% X9 K7 K# @6 |* [9 [    xor     di,di% B$ O* E3 _8 A; ^! F
    mov     es,di
& C# j6 }; ]3 I2 U- J0 ~    mov     ax, 1684h       & G( q) Y# B: ]* H
    mov     bx, 7a5Fh       ; VxD ID of SIWVID3 S2 C4 u; s/ e6 y* g' U3 `
    int     2fh
8 ^+ j1 b. D& o3 ^8 v& I% m+ ?    mov     ax, es          ; ES:DI -&gt; VxD API entry point" q4 l, ]0 C! t& @4 x
    add     ax, di3 v- i: t; i& x
    test    ax,ax
9 C. v  F/ y! N5 Z% ]    jnz     SoftICE_Detected
: w& ^9 O; }+ Z3 e; r. X9 Q& Y1 E/ ?' F. J/ D* J4 k
__________________________________________________________________________
) ?6 H# A5 a# m4 H  _$ k$ b# E& k2 p7 t( r3 t* v9 D

# m2 ?* E1 z- I( p- J% p; RMethod 05
" ^0 ]6 p1 V( ?& r5 k, V. U! Y=========' T. _0 G" t0 s; g

+ T. j9 Q( u! s1 K2 z3 M2 Y: W( p) VMethod seeking the 'magic number' 0F386h returned (in ax) by all system) `# j4 g9 _: F. r' Z, R! M% t6 A
debugger. It calls the int 41h, function 4Fh.
( Q0 o  Q/ ]! {' I( [; C* MThere are several alternatives.  
  X' W- A# U0 j* J
$ L5 G! i+ u3 T# [5 _6 aThe following one is the simplest:
6 ]" m5 F+ ~- u. N9 x: ~
" q6 T4 y/ c* J    mov     ax,4fh
# p$ |' |. G* L+ {    int     41h9 C4 i/ f% q8 W1 d1 Z  Z
    cmp     ax, 0F386
; O2 A3 C- H$ |. D8 F% W5 K0 C    jz      SoftICE_detected) z5 ~5 ^) @$ w9 O3 G6 d. Y2 X

# ^6 x# |# |$ p3 `/ T
9 H. e4 {" w+ K0 r! u/ @Next method as well as the following one are 2 examples from Stone's + H2 Q0 i0 ?1 [  N: x( ^0 N
"stn-wid.zip" (www.cracking.net):
- I+ u8 a, \: [1 I& S" D$ r+ A: K7 e: H1 s' o8 i
    mov     bx, cs: L4 r" O6 P3 s& v2 h
    lea     dx, int41handler2- J4 w8 T7 E" m1 E: ]
    xchg    dx, es:[41h*4]" J: S8 H  ]* T4 p
    xchg    bx, es:[41h*4+2]5 k2 F' T- {7 E
    mov     ax,4fh! Y9 m: ^! _: n2 `
    int     41h* x" p- C$ d% o& R
    xchg    dx, es:[41h*4]
3 H0 U% j/ G: n; ?; u. h3 J0 x    xchg    bx, es:[41h*4+2]
' Y1 h% [& x; I* w5 f9 L    cmp     ax, 0f386h
, U* T$ r- m& W" ]/ ^    jz      SoftICE_detected
$ ^& t4 R7 ^9 r3 l# C9 K! b6 b1 `2 \2 m. n5 P
int41handler2 PROC4 T7 O4 y! o' Y3 E+ f$ n
    iret  g' q' j$ O1 M' ?2 m) j' A- f
int41handler2 ENDP( Y$ I. }, T! p( v

" {% s& R" ^, _7 J4 |5 X! g- E8 w
, X" d, f" y5 `; i5 x& U  V! F  I_________________________________________________________________________, y  N! C* l/ g: m3 S# R

! P. k3 h1 ]$ X4 D6 N& d1 {2 P$ z' R' Y1 D6 |
Method 06# R6 R; `' Y8 Y% n+ r  g
=========
- l" W  c- @. o& }+ J* I& ^) q! d! ^3 x$ Q
7 L, V+ U+ }6 U& F$ z
2nd method similar to the preceding one but more difficult to detect:( K3 x, g# J. s: A& v! k; [
* B; m  o9 l2 M8 ]+ G) D

/ a% }2 Y! h# K7 g- w  bint41handler PROC1 ]0 K! `2 H4 h7 O% J$ J% m9 B9 g
    mov     cl,al
& k+ P) c% n+ w8 p5 K* S$ ^    iret
% {# F) ^# K* d! O5 u/ [3 xint41handler ENDP% j* j5 |4 h- G. A, P" l

- V7 T  o* i$ a! w0 P) H  R7 m6 D5 X$ h/ W
    xor     ax,ax
8 H5 Z$ f( s8 i! O" P6 F8 V    mov     es,ax; j, Y, @$ ], P/ t+ p" `# j$ e# Z
    mov     bx, cs1 i1 @; M4 r" j$ }, n4 Q
    lea     dx, int41handler
$ B0 Q% V6 i  j7 p$ N0 j: p    xchg    dx, es:[41h*4]
; J! A, o& m4 z/ o1 ^7 T  [    xchg    bx, es:[41h*4+2]
/ u% `+ z; X* J" A& j: S    in      al, 40h
+ G# E4 f3 b# q9 h    xor     cx,cx! h4 V9 v# b2 D; J8 N( X  a( w
    int     41h3 q9 {/ C0 x$ j& l& w: t
    xchg    dx, es:[41h*4]
: ]+ v) K" i: z. E3 M) ]    xchg    bx, es:[41h*4+2]
& G  X2 D( k4 c( K    cmp     cl,al; i. k, n1 o( o9 C' X, d
    jnz     SoftICE_detected
4 G; M6 |9 E& I1 K
- \  L  o7 A9 R9 Z+ w' [_________________________________________________________________________
# c5 c4 V+ s5 h) x- J
2 Z3 {5 |6 }, fMethod 07" j  x. e- p' ]: r5 L
=========
5 C" c( n( e5 |% A8 `' ]5 f) j' n/ @  v* r$ Z) t9 P( q1 k8 k
Method of detection of the WinICE handler in the int68h (V86)1 r1 Z3 r; @' e, x- l* U7 `  K
) E4 O$ z/ D4 L0 C/ e% E& v
    mov     ah,43h
! ?1 B* z8 f9 @    int     68h
8 q7 f0 U5 K) h+ ?    cmp     ax,0F386h& v8 K; _3 H& ^7 ]
    jz      SoftICE_Detected
- C% s0 l/ X4 p0 ]* q( H! J5 i- L
) K, d, E" q. F2 `" R  N7 i3 R5 N7 z5 x' @" }+ c7 a1 |
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit5 u6 f/ W8 i9 S7 J0 L  N
   app like this:, T! f; A$ {2 b( k6 z

+ y3 E! O5 r7 b3 x! J! G5 R; [( K; [  ~   BPX exec_int if ax==68
. y# \) h" u% M! l   (function called is located at byte ptr [ebp+1Dh] and client eip is
. Q  I) K9 l- D1 ]! J5 A2 P$ W   located at [ebp+48h] for 32Bit apps)0 R0 b: e  p. P
__________________________________________________________________________
0 I2 c' W: J$ V( P- v' I- C9 I: f: F; e. Z: s* ~$ ?" ^# Y

/ O; L# N7 D5 e+ E* m! IMethod 08
- J+ O7 I. Z0 ^& h=========
; u; n, P4 m" }% q$ L# d3 o* j; l
It is not a method of detection of SoftICE but a possibility to crash the
% D. o8 I, H) Y7 Y, Q) H0 f; Rsystem by intercepting int 01h and int 03h and redirecting them to another; s6 _( V# Z8 P/ P. r8 z. s5 s
routine." ?3 G/ y  T( L3 q3 i
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
; e3 l3 W3 L  n5 V; ?to the new routine to execute (hangs computer...)! e1 Q  r" g* T# Q

- R: [( o2 R) E1 G; D2 Q    mov     ah, 25h
# n$ Z5 o* h: q* L, w    mov     al, Int_Number (01h or 03h)
; t; ]  F; a0 d  x+ L    mov     dx, offset New_Int_Routine0 ]$ a1 T6 D, n- q8 H* z
    int     21h
9 b4 F4 k& X. s; I. o- y+ y& I: l3 _6 u# T* X
__________________________________________________________________________
6 [+ P* n0 X7 q% H& S2 t) N% X2 I
: j" [  R) L- q6 `/ M0 G; vMethod 09
4 k# M- R0 z* C/ [& B# S=========$ T+ f7 C/ h1 I+ A
1 V3 q* r9 n/ |# i! U
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
. ]. `- a/ P  ^, y2 k& h. Rperformed in ring0 (VxD or a ring3 app using the VxdCall).) s+ K1 x' u; O% _) j
The Get_DDB service is used to determine whether or not a VxD is installed
' s9 ~5 L" O# M* I* jfor the specified device and returns a Device Description Block (in ecx) for" Z- F2 M8 J9 P% v" c6 L
that device if it is installed.
6 m  A. \; {0 I+ C* z" t
2 l8 i' S8 v- d" ^( D   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
8 Y2 A( @; C2 {- _( |   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
8 T4 U; T7 D: u& x2 w& l9 m   VMMCall Get_DDB( J1 v' `; A! ?. G
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
' h* Y1 h  }* {8 b: q( s' f0 C7 f
( C7 n4 Z# p4 |: yNote as well that you can easily detect this method with SoftICE:
2 O4 i$ A3 C: N( |   bpx Get_DDB if ax==0202 || ax==7a5fh
$ r6 @8 k! w$ y
7 x, q8 f, v9 D# h__________________________________________________________________________% X1 x9 n( G+ O3 H( |$ c6 m; Z; d

: Z$ X8 V. M: w/ M% J& E" mMethod 10
9 P* P1 E! O, J% Z2 j+ k( p4 I=========4 W2 G. k( w3 G, b/ s

: u( |' o! a3 p* b=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
. u7 N( i7 {, [  SoftICE while the option is enable!!
) f! f" b8 c) v. V
% y8 a( |  {3 ~5 hThis trick is very efficient:
" a% B4 A* M5 l* Cby checking the Debug Registers, you can detect if SoftICE is loaded. h2 e* \3 h8 i- d0 Y2 F5 V  B4 m
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
; H; L* H3 p' l# b* {! S& Athere are some memory breakpoints set (dr0 to dr3) simply by reading their
( z% C' e  u5 s& S# ^0 Kvalue (in ring0 only). Values can be manipulated and or changed as well, [6 G$ V0 ^( s
(clearing BPMs for instance)) K- o  b; E( y4 ^

& E; K( t* l2 I- h+ o) w__________________________________________________________________________9 n6 x6 U: b' m
. @! V$ H0 V! f! `. Q4 I
Method 11
8 }" M8 m+ v% x% r=========
# J" G7 m; Y' i5 y+ e; N8 \; p1 x1 U- a# F( H- O! [8 \0 H- b
This method is most known as 'MeltICE' because it has been freely distributed
& t2 m2 y( ?; p& U+ ]( H: gvia www.winfiles.com. However it was first used by NuMega people to allow
: W5 H% I, [5 E% Y: wSymbol Loader to check if SoftICE was active or not (the code is located
( ~! Y6 V& X- R( z* K3 a% o6 _0 Minside nmtrans.dll).
) U8 a# T% Y1 d7 g2 j
& Y+ x: [. j9 b* I* QThe way it works is very simple:$ ^, f  e0 y; X  E8 A& E* A
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for* F; `; s' t* i. |% d
WinNT) with the CreateFileA API.8 a' n4 i! J, j6 G2 b# F
' f: t' T6 A: [7 K
Here is a sample (checking for 'SICE'):
! V( _: `3 n3 q$ \2 W: s0 B+ F
! x% H  G" `2 k4 J/ z" E# s- JBOOL IsSoftIce95Loaded(); _9 h4 J9 F8 |0 g! p7 s
{$ X8 L5 ?9 a7 f% l9 n0 z0 r  r' V
   HANDLE hFile;  
! s; p! K; i1 e' @4 q! I   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
; |$ Z# b: O* ?  ^) s: n                      FILE_SHARE_READ | FILE_SHARE_WRITE,
; Q! C8 d& `) Z$ S6 d! p                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
$ I2 I9 ^8 F0 P& y7 W   if( hFile != INVALID_HANDLE_VALUE )
0 r% Q" l) u5 c) P! h   {
: O1 _( m7 _, ]9 T# x( f- k; r      CloseHandle(hFile);2 f) |* \' C: W
      return TRUE;
2 d+ e& n3 E5 @3 p' P, U+ K, `   }: w6 ?) j$ p8 a$ J3 E
   return FALSE;& H/ A7 W+ ?! y6 k$ z9 `
}2 o: s- @7 h  h: |; j2 q
2 Q, ]7 D/ D: |
Although this trick calls the CreateFileA function, don't even expect to be
! o. u+ i: h* R# |* Q, qable to intercept it by installing a IFS hook: it will not work, no way!1 M4 L% u0 }& h6 I
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
! j% S8 `  c! r7 y' uservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)6 W) b: f4 m0 E( c
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
* T& d& \# t$ y- S. Tfield.
; a2 p0 }* K2 c( {5 N6 cIn fact, its purpose is not to load/unload VxDs but only to send a
/ l  D7 O2 Y8 \2 p, iW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)  c. M0 V% I+ M8 i# G
to the VxD Control_Dispatch proc (how the hell a shareware soft could try% H2 ~; H6 i/ @# P! j2 U! r# Y1 A# r6 v1 e
to load/unload a non-dynamically loadable driver such as SoftICE ;-).3 F5 I3 W. x7 u* m# G; U$ t
If the VxD is loaded, it will always clear eax and the Carry flag to allow
+ ~- s4 K, _3 x; s" N6 t+ f% ]its handle to be opened and then, will be detected.. A3 o4 Z- F& s/ ]7 Y; T; W" |
You can check that simply by hooking Winice.exe control proc entry point
3 k. S! B( z/ D: ?: ^while running MeltICE.9 ]: o- H2 ^) O2 b# ~" v8 R

9 P6 g' m& o4 X( b' F
1 [% u/ m8 u. g% g  00401067:  push      00402025    ; \\.\SICE
" f" l0 U8 p8 C- b/ ?  0040106C:  call      CreateFileA9 Y2 `, Q* p* A
  00401071:  cmp       eax,-001& L3 k$ A+ F8 \: M+ ]8 _6 w
  00401074:  je        004010915 g0 U1 y$ ^) O% P
+ ]) t  Z, D$ ]6 p% ?
. }1 M8 `2 j: J1 U
There could be hundreds of BPX you could use to detect this trick.7 z+ S* B& k7 F/ J
-The most classical one is:
/ ~' @) B- I' P  S3 i% ]4 L  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||7 H+ h. Q( [# \
    *(esp-&gt;4+4)=='NTIC'
' e$ v6 F' @2 h3 l" r1 T8 {3 T3 b/ C! A9 @
-The most exotic ones (could be very slooooow :-(
" z* S/ p1 [, f; Y5 v   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
+ O$ N; S. l- Q9 r2 Z& i/ k5 h     ;will break 3 times :-($ b7 {: s+ U4 {$ }2 G; _- U

# N7 \: v5 v* v; q% ~3 H  ^-or (a bit) faster: - M, a& L3 T5 v/ n9 t& A% U
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
4 u: @6 U4 W) Z2 k1 k
+ q/ }' F0 J  o! M) a' z   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
# y2 X9 I4 w) V3 B# s7 U+ x     ;will break 3 times :-(
" p0 c7 |' d% r; Z
" Z6 a/ x- B  ]) e; s8 m( \-Much faster:
9 C; l+ a% L. ]$ ?' I- |. g   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
5 \4 F  Z' \9 \3 ?  S1 _& E+ J
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen2 Y8 o) s+ L& ]9 k  w
function to do the same job:# h& W0 T2 p- q* z6 E9 f

1 o4 k3 U; U; h$ j- f   push    00                        ; OF_READ
/ B3 R- \# s" Z& V9 Y8 U   mov     eax,[00656634]            ; '\\.\SICE',0
% Q( l* r* @$ d1 C( e) X   push    eax4 v  D# f: r7 W8 n3 s2 _  k( Z
   call    KERNEL32!_lopen) Z) @7 C- k, J" j1 g
   inc     eax5 B! V1 M) A6 ~& `
   jnz     00650589                  ; detected
3 Q/ N& T- r! z. }: e( y- N0 V. v8 F   push    00                        ; OF_READ
0 l+ \8 S7 q% [/ y7 p2 e* `   mov     eax,[00656638]            ; '\\.\SICE'' D# T1 a7 H( V+ M% O# R
   push    eax! i2 N. d! z) h- s, T# Q; J
   call    KERNEL32!_lopen5 s& X# ]5 x, H2 [( @
   inc     eax
2 G6 y4 C1 \0 W& x/ V( l   jz      006505ae                  ; not detected) @( p' b8 g! u- h) N; h. V

; I( F0 l) y# ?# L4 t1 e
- ?9 s2 f- h( }__________________________________________________________________________
' p9 x' u, X$ S  G& [
) P& ~; u5 e& k4 h7 hMethod 12
$ O; T2 ^, r( H  a=========
% c) }9 x9 _- W9 J. g% f
5 [% W, x" u$ O8 uThis trick is similar to int41h/4fh Debugger installation check (code 059 C# k1 Z/ v2 Q, {" B) }! k1 l
&amp; 06) but very limited because it's only available for Win95/98 (not NT); N0 C# |2 [. C6 @- R0 S7 T
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
; Y0 s9 y$ P) _( T" S2 @" y5 e$ [2 X# N: d7 k
   push  0000004fh         ; function 4fh
, [: P6 p, Z* K/ L6 @   push  002a002ah         ; high word specifies which VxD (VWIN32)6 l1 p/ o( l: G* K
                           ; low word specifies which service  \% ?5 S- L0 |  ]& }5 S5 T
                             (VWIN32_Int41Dispatch)4 R( _  g! m, K  n$ F6 _* m9 y6 _
   call  Kernel32!ORD_001  ; VxdCall
7 b: }$ q  A& F0 a$ u& d5 o. ^* P/ r   cmp   ax, 0f386h        ; magic number returned by system debuggers
, K  D9 y' _, c$ V& k   jz    SoftICE_detected% V: v# a" |+ k
. Z" r2 I+ }) `8 s# Z% k
Here again, several ways to detect it:
4 W. x' N  G' J. d) P9 z- \. Y: v+ ?# o6 G. g2 B7 t! `
    BPINT 41 if ax==4f
- v, _' b- r, t0 X& `- B: K( Y
* [! b8 B" r1 D" H$ B! b    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one0 \2 b5 d, h$ J6 D8 E9 L+ D# ?! h

3 E: Z4 S- O4 x( E    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
8 N7 p3 H: e, x; t. {* Q
5 k6 b2 l8 D2 Y" o+ ]    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!  X$ m6 o7 w) C2 K) q. i/ S

0 c. i6 S3 ?$ r__________________________________________________________________________: F9 s* r1 F" G3 ], C7 r

& u/ m/ _8 y* _. fMethod 138 U1 n+ v7 f3 q9 M9 x; N8 [5 ^
=========/ p+ \, @1 l% {! E
& v8 C% F. u# i, e! ~- N
Not a real method of detection, but a good way to know if SoftICE is. d6 }/ Q. Y5 A5 O# h
installed on a computer and to locate its installation directory.
$ m- d, K  S; ^: H8 J# f) L, d5 YIt is used by few softs which access the following registry keys (usually #2) :( ]/ {1 S& t; a( J

# ?% V( o" Y+ V; v2 y. f3 d; [% P-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion) x9 c2 }0 y- N$ I3 ?/ [
\Uninstall\SoftICE
; k: q- J( T  t4 n: T0 ?1 O( r-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
0 Q+ U: [. j4 x" J-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion2 }! L  k; y$ s% Z; K1 b
\App Paths\Loader32.Exe
, j$ n8 o" L1 X! {; j
' u" k. d9 \) G) ]+ ~$ C+ D
, T  K1 A, a: X. n( i1 ~7 VNote that some nasty apps could then erase all files from SoftICE directory
5 `1 _3 w' m2 B7 x3 r9 n(I faced that once :-(: t  I) E5 W( v( I- t' a; K- o4 M' P& N
6 A" V2 L8 J3 R7 E/ K  p
Useful breakpoint to detect it:  H' J3 T8 [5 G3 L3 C0 S

7 D* m9 E+ [$ C! g6 E& v4 ?7 s; @     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'/ c3 [- v) N* g

# u" ~( J# S4 Q7 T9 t1 x( A  F8 |4 H. i__________________________________________________________________________
* L& L# {' T! b9 N8 P3 u7 X+ _4 W2 j0 C9 m: i
2 V7 j& l2 K& P. ?
Method 14 " L1 K  g; s- o8 A
=========$ M2 A6 ]  H9 Y0 I* A- L' b, q
" I" z: j! j: A0 ]& B9 x; T. H4 k
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose3 n; _/ w* j, A) X/ D
is to determines whether a debugger is running on your system (ring0 only).
) k- e. d7 T$ j  S# v0 `* W
$ L' ^0 a- N  C& N/ F1 c+ }2 u( h   VMMCall Test_Debug_Installed
) ?. I# \7 h0 k: @   je      not_installed
' j6 _( c9 p$ e9 O3 F+ z9 ^( i; C' y' f/ w$ v
This service just checks a flag.
; V! ?3 K* p; q7 ~</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部