About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>7 ?: q/ {, J7 x% z
<TBODY>
& x6 e. j2 }* ^# ?8 r$ @" ^<TR>
  m$ Y; V! A) a4 a<TD><PRE>Method 01
" F) D& I" l6 Q" g8 o* B4 R=========
! ?' y; x$ R* k6 F* Z" n& P6 \9 v3 {0 j: T* W; N+ @& K: Y0 h# H
This method of detection of SoftICE (as well as the following one) is
8 |$ K, M- S6 O1 e& _$ r( iused by the majority of packers/encryptors found on Internet.
) A/ T7 ^( o+ MIt seeks the signature of BoundsChecker in SoftICE$ N! d! b/ U/ l& d' |

+ H5 B* s1 U* [, @" ]7 M  r    mov     ebp, 04243484Bh        ; 'BCHK'/ W0 r$ F5 G  o7 F4 E
    mov     ax, 04h
0 O# _% O5 f: y  N    int     3      
. U) U' M0 L! P0 g8 B8 i0 n! U    cmp     al,4# I, c# n; O- w8 q7 k8 c8 C# o
    jnz     SoftICE_Detected% g3 `3 }' r4 }0 m+ \. U

3 f) N. P$ C% n6 i& D* Z% h___________________________________________________________________________
2 J8 h" z' d5 g1 Y) ~. R+ l: z/ P% n$ ]+ }- [9 a  E
Method 022 Q' ]6 Z6 J1 H2 l9 `/ \% Z) F  @
=========
7 q# R2 _0 w1 e, Q. F2 J% L( T, f- ]1 U* i
Still a method very much used (perhaps the most frequent one).  It is used. V" y. y4 z: J2 B7 X7 s
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,( C6 N: G, B% K; o0 t2 Y! g1 D
or execute SoftICE commands...
4 V+ R1 J& s. M7 J& Z& ?& eIt is also used to crash SoftICE and to force it to execute any commands1 I, n/ n9 [; l
(HBOOT...) :-((  1 R5 v1 k3 V2 G0 x/ c' P/ R2 E

6 `; o- Q: ]+ f2 U/ F  b/ }Here is a quick description:
% w7 b3 e3 s; Y# G: a; p8 S( D-AX = 0910h   (Display string in SIce windows)9 E# c( L3 F8 d$ I4 F! w+ P  A
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)! _4 G; f3 E. N- l3 O
-AX = 0912h   (Get breakpoint infos)* e5 i! v3 x" E: t
-AX = 0913h   (Set Sice breakpoints)
; `; }1 K# r, O+ u, K. m-AX = 0914h   (Remove SIce breakoints)( Z8 r( q+ I$ l! M, c+ H) j

5 M) Z& s$ K# C$ o- x( t6 j1 K; F+ s4 IEach time you'll meet this trick, you'll see:
+ O5 f2 f. o, {: d; S& K! b7 |7 E-SI = 4647h
9 p9 I0 w) Q% I2 A% i9 d-DI = 4A4Dh
9 d( p( b. E" M, B0 EWhich are the 'magic values' used by SoftIce.
7 k2 J8 B) }. d8 q3 G7 [For more informations, see "Ralf Brown Interrupt list" chapter int 03h.+ u& t$ d3 h; x( `- b8 {

9 @, m. n- \' F+ K7 gHere is one example from the file "Haspinst.exe" which is the dongle HASP
  D; H) \+ X; f% P, SEnvelope utility use to protect DOS applications:
' Y) m; D+ R; ]/ [8 `3 k) I+ {+ \0 i
4 W/ b+ k0 i, I1 n. c* x. y" q+ f' Y9 F; }# [
4C19:0095   MOV    AX,0911  ; execute command.
: O* G4 G$ u( @4 h- K* u4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
! a" j( b! X) T3 v8 l2 i4C19:009A   MOV    SI,4647  ; 1st magic value.
8 U' r. V8 }- t+ O3 F' U$ U/ A1 X6 D  T4C19:009D   MOV    DI,4A4D  ; 2nd magic value.; Q5 P+ ~/ U9 z% H
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
2 L- I  |& K: ^3 ~% [5 w4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
3 A$ X1 k9 g7 G4C19:00A4   INC    CX6 z4 O4 s5 u# w6 ~( O6 w: L
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute! u% S2 A9 A" M" B! E) l: n
4C19:00A8   JB     0095     ; 6 different commands.2 i. g1 e& K0 w: N. ~
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
' J7 A& ?  R/ u9 i/ r9 R5 b4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
$ T7 R% v, g2 N- h) {& `) D9 _. [/ G6 V% b
The program will execute 6 different SIce commands located at ds:dx, which
$ t3 x. Q1 F+ Fare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
  v# R* t3 \; v& f- D! k; T4 E& A! _, a' E  ]2 u7 X; ?
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.* J0 A' C/ I5 Y% c* F; H2 x0 l% s( C
___________________________________________________________________________: v! u3 p( `) k$ I- ?/ j9 r7 X. ^
+ b' f7 \% D9 l8 Q! ~

; b! l; @; v; }Method 03' e3 a7 P! P/ s# `1 A
=========, f. j, }# r* j3 A+ \4 O, ~

- z9 G0 F* P; d. QLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h& j8 Q4 f# K" D  G
(API Get entry point)
0 X. {8 l2 {  k6 u) u$ k        7 ^- A* E3 Y$ D3 X; m/ @2 _; K

4 A1 Z6 f: X& [" g: Q9 d4 n% P    xor     di,di  N9 E" N$ I! w: j0 ]
    mov     es,di
+ e0 Y+ O0 S. \0 h' Y    mov     ax, 1684h      
1 Y8 ~- v6 l4 C  s. |/ ]3 p    mov     bx, 0202h       ; VxD ID of winice
8 C. U8 e; U6 k9 H    int     2Fh
2 O/ y/ V& q' T; m) A0 h    mov     ax, es          ; ES:DI -&gt; VxD API entry point
3 s% P4 D' ~& r# k    add     ax, di6 U, z- a* ?- j; A4 D! u4 P$ V' `
    test    ax,ax
  l4 U; n. q3 M+ Q. b    jnz     SoftICE_Detected! f, P; c% J- ~$ w* T, U
# |$ x+ l4 o1 j4 ]4 E
___________________________________________________________________________
( h& ?# |8 u" V- E( {. h' [$ u$ o: D# C2 `
Method 04" s0 Y+ k& A$ H' O
=========
# C) _: A0 c/ n' \" x( n9 l
& G2 X5 _' J8 s3 M( aMethod identical to the preceding one except that it seeks the ID of SoftICE  q, P& |; Q3 G3 O3 S; g6 c& n& |
GFX VxD.
% L8 p' f% u- i! L
, O4 w+ b; e( j- V    xor     di,di
4 G5 e  ?2 K( b2 p& x: G    mov     es,di, N5 {9 H& _/ d' o% ?
    mov     ax, 1684h      
4 |, ?4 X" y: ]- a! d% T+ m0 y    mov     bx, 7a5Fh       ; VxD ID of SIWVID
& u, I! b1 ?" m) q! I4 V( e    int     2fh
/ G) S9 H) d- Y8 L/ q    mov     ax, es          ; ES:DI -&gt; VxD API entry point( g% d9 B8 O. s* y. R5 ]" y2 K; p: g: I1 o
    add     ax, di7 j! f( j1 X8 E
    test    ax,ax% T4 z. p+ f7 W; k# c/ p4 I, {
    jnz     SoftICE_Detected
* p, |( Y; C4 }' p9 [4 i4 q0 y7 Y+ N
__________________________________________________________________________
7 i" g8 A, S0 D' X% V# R5 B9 y7 V( x) l5 c

% ]) u' K3 Y9 u9 d; `Method 05
$ |5 {2 {3 y3 v/ u=========
0 V# O0 J4 N+ [- a) F+ y
5 {7 Y( S2 a4 A0 QMethod seeking the 'magic number' 0F386h returned (in ax) by all system
0 M9 |! [$ W1 A; U4 W8 f" I8 k3 tdebugger. It calls the int 41h, function 4Fh.
& V$ v  o* N7 I; e  t0 jThere are several alternatives.  
: [4 r( B4 l* {; E8 r* {2 q3 e
  Q) }# |& D/ |The following one is the simplest:8 K% @' M/ i8 p
- S# H, o# i' ?& K
    mov     ax,4fh8 e* O' O* ?; E7 I0 U  B
    int     41h  L4 i* ~, r( h# d3 M! R
    cmp     ax, 0F386
8 y5 s) ~. l0 o, a5 e    jz      SoftICE_detected6 M# Q; H# M8 l7 Y. A, d- F/ I

: z, F! o  v) A
0 ^3 y0 U, i! Y! ONext method as well as the following one are 2 examples from Stone's " C8 |. T+ W2 `9 Q
"stn-wid.zip" (www.cracking.net):, X; N0 Z/ R0 z4 q
: W0 m' L3 W, E! }5 s- ]/ E
    mov     bx, cs
2 q9 N6 h5 E; m2 ?4 _    lea     dx, int41handler2
3 ^9 h. |8 y9 O5 t    xchg    dx, es:[41h*4]: l0 r9 q3 R+ e" `2 q! U! O" T2 A
    xchg    bx, es:[41h*4+2]
- J" j3 V2 m) M    mov     ax,4fh
0 z& e& ?6 Y3 n; K0 L8 h' A    int     41h3 t; \9 r' h  D
    xchg    dx, es:[41h*4]
' W2 K$ h/ K8 K7 w9 C( Y    xchg    bx, es:[41h*4+2]+ ^9 k, k$ P- J3 r) e/ {0 @( c1 C
    cmp     ax, 0f386h
. M9 F$ @6 d3 i. w& T4 B1 u    jz      SoftICE_detected4 i7 U3 s% T3 J8 n( a; ]4 n0 G7 n
0 Y2 ~1 T  c7 ~) b" z
int41handler2 PROC. B2 y8 u7 O, Y: N, u3 i0 d  h, F
    iret/ E" O. ~! s3 o+ k
int41handler2 ENDP
0 K* H- R, }* C2 P4 a& o4 x4 G' t
  I- x$ M( B" y. g; r' c% W3 j- u; S
_________________________________________________________________________2 g2 l! K( ^  ?$ Z( \

' n! d7 l4 Z: m6 S$ O7 N& Y  V* n4 r9 \7 ]! i2 C3 [5 n0 c
Method 06
" x0 \5 ~8 p2 Y9 k  c+ f, w=========- H( ]5 ?/ ]9 V, ~! J, F2 ~2 q
; ^2 [1 R' ?3 Z8 T1 `  B( ^
9 y, @2 }6 R! D& w" N; k, _( |' b0 L
2nd method similar to the preceding one but more difficult to detect:
$ G1 H0 L" R# L) x3 n( e
0 H& x* f5 v1 R$ `; J* Q) D! k+ F4 i1 B* v8 m3 {
int41handler PROC
5 R+ y! s5 ?* g" @+ ~    mov     cl,al. U8 w1 J- m6 ?) u
    iret* A0 ?" r2 a3 W( {7 h2 N# t
int41handler ENDP, Q% S9 f2 @$ D" E: X, W+ ?+ r$ o: w

, s" \' F$ M5 j  f9 y5 C: S8 T3 \
. P! _; X4 i) ~0 a' W7 E9 E3 `, Y    xor     ax,ax
5 \: c7 r2 u2 q( V    mov     es,ax
& Z4 N& l1 |. `$ X) n    mov     bx, cs/ G- V; {6 g! V/ I# z) A; a
    lea     dx, int41handler
( }$ X1 ?2 g' v& R% g    xchg    dx, es:[41h*4]# t, j0 N5 X2 x4 f+ P
    xchg    bx, es:[41h*4+2]
* P" o6 U. }. {8 q/ U    in      al, 40h6 z3 ?! p! n0 s; l9 y4 B1 C& j2 S( K4 P
    xor     cx,cx
" a3 D  t$ x9 Q  J, _: {8 N    int     41h
2 b% V+ u: d' F* ^% B. X: ?    xchg    dx, es:[41h*4]
1 O8 t, |! A( e, q' A9 u    xchg    bx, es:[41h*4+2]# o& V9 V2 @- V/ a, u! M4 b
    cmp     cl,al
* k' j3 \( t6 J. W4 I/ B- W5 _    jnz     SoftICE_detected" \; x6 ~& u3 ~: }5 M  I0 S& o

! f5 i% S, l' ~) f" |. D_________________________________________________________________________
% _# h4 {4 M7 z# [6 I, X2 _
: F3 G7 i8 r9 G& `3 Y5 V7 nMethod 07
- O+ a; e5 w$ n" e# C* p=========
2 g! H4 T0 x4 f/ _$ B* T: |- }0 j  B2 I# s$ L
Method of detection of the WinICE handler in the int68h (V86)
+ ]) k( p: [/ |& b7 i! [8 a5 U6 l: I6 l5 J  _- V+ O+ Q1 k
    mov     ah,43h
) L; t) z' O) [; j( o- U    int     68h% Y5 a7 M% Y# H
    cmp     ax,0F386h
! l) r) E* q! _' g" U2 r/ y1 H; v* c    jz      SoftICE_Detected
3 B- ?2 H) T1 P
- @# |% v! l9 E% u) j; k' [
4 f. E; I" [/ y) U' a% T5 c' G* W=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
( F; S: K/ b: C' p6 H/ D   app like this:
( Z7 E! g1 L3 Z+ m  v  P" d; ~% ^" ^3 B3 T
   BPX exec_int if ax==68
5 i4 _0 ?* |* T/ L   (function called is located at byte ptr [ebp+1Dh] and client eip is
" R; ]0 ]* {* M- V' E& x# ]2 H   located at [ebp+48h] for 32Bit apps)% g4 C5 s, F* q8 W" S. G  B
__________________________________________________________________________
, R) T7 A9 X9 n( @4 Q$ _, E# O
1 D4 S, w: ~2 X# A* Z9 P8 ]
: ~' w6 w! B* i6 }9 pMethod 08$ |" W: Q0 Z8 [- Q, G# M# r4 n
=========
! V$ l5 K0 _6 i2 E+ \
( X9 p- }3 L# }; Y( G+ cIt is not a method of detection of SoftICE but a possibility to crash the
1 y! |4 J2 j* ~+ S; |system by intercepting int 01h and int 03h and redirecting them to another
6 Z+ j4 `/ M8 h- q/ q( m9 p& zroutine.
, y4 {' G0 S8 l6 t, |It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
* i8 d2 J# D7 \/ L# O: v1 f7 dto the new routine to execute (hangs computer...); N! h6 V6 y* A2 L

+ X* p# Y2 o# k    mov     ah, 25h7 n5 B& ]8 u6 t& B8 q# t9 j
    mov     al, Int_Number (01h or 03h)- K% U2 h% n( y( I3 H
    mov     dx, offset New_Int_Routine9 E0 D4 F7 k* R& R
    int     21h4 [0 T3 S) ^" e4 k
/ k! o% I8 r/ w# S1 E9 T
__________________________________________________________________________) e1 k# u+ e: z# ?

+ x* `7 @, v8 ]3 ]5 TMethod 09
5 O8 O( V4 [* g0 _7 A: c=========. {5 J3 H/ u; p2 N& [
' a& H6 N, j) I6 T7 B0 z
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only  z2 a& g, S7 M& D) b" z: b
performed in ring0 (VxD or a ring3 app using the VxdCall).
! v1 D& W# ~% ?: o( G8 eThe Get_DDB service is used to determine whether or not a VxD is installed* V* X7 A6 c3 N; ?) q
for the specified device and returns a Device Description Block (in ecx) for. W3 n  y" X7 g/ I" L
that device if it is installed.
7 z  S% J. Q; n5 |# Z  M/ r/ b; B4 k. ?4 I; Q6 B) ~* E
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
+ K# _# w; D. H. k   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
# R: L) Y$ N( ^  [) u- P, _   VMMCall Get_DDB
6 `4 Q' r7 D8 X1 |4 e+ h. U   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed; s" f# A$ U  ^4 @( e( o
+ R, P/ P, e: r  W. V* t# Y, I
Note as well that you can easily detect this method with SoftICE:( ?" K' n; O' O# J! s! G. H+ Q& q6 @
   bpx Get_DDB if ax==0202 || ax==7a5fh
3 j2 Z% M7 i# f5 E: V" x* ~, N$ F' B2 n% T4 S5 `
__________________________________________________________________________) A* v5 Y# e, Q9 g) `( q/ N6 {9 J

. U% h6 g$ I+ s" i  H$ ^Method 10
5 G9 w( `; A0 K( \=========
4 ], V" j; a- a  S! J6 v
6 d, P& `9 S* A=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with. Q/ e- I. x7 ^# y! i# M3 P
  SoftICE while the option is enable!!5 q0 y$ f3 F* E- T2 X* u

, O2 y) B6 v* O# cThis trick is very efficient:6 t( W5 d) V2 R/ o6 k* z
by checking the Debug Registers, you can detect if SoftICE is loaded6 L; U: ?. z" }) ]( s  w3 m
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if2 F& I9 f9 ^0 o, D
there are some memory breakpoints set (dr0 to dr3) simply by reading their9 [; C7 d% O$ g1 t2 l
value (in ring0 only). Values can be manipulated and or changed as well
( \' s( x/ P2 {; L3 C(clearing BPMs for instance)' q8 b$ ^0 j% b* Y# w( G
4 H- E: s0 S2 Q7 M2 ?
__________________________________________________________________________5 j+ m' j# k$ }' L4 i9 p: N' y% v7 ^

: l" m2 r! A0 KMethod 11
! R1 L  H! F/ y+ {=========
' E- @+ n" n, [* u; D, ~$ Q" G# I" b4 D+ s
This method is most known as 'MeltICE' because it has been freely distributed
5 g8 Z) x0 |2 \; k% b. W2 }( pvia www.winfiles.com. However it was first used by NuMega people to allow
7 z1 W$ y+ ]* y- h* Z  i1 l6 PSymbol Loader to check if SoftICE was active or not (the code is located
& z5 m1 \9 y' X* q! ^. Q8 Q* Einside nmtrans.dll).; v8 g8 d' j0 ]
# I& B  U0 j1 Z3 ?# y' S3 V+ G# B4 U. `
The way it works is very simple:
' ^* c3 [( E6 q  M$ T5 n/ wIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for( n9 s9 r9 `) S) j8 F5 l$ W* O
WinNT) with the CreateFileA API.
% w2 S8 }, X: B6 r2 g# \; `5 P0 w: C( U6 S4 `
Here is a sample (checking for 'SICE'):9 s9 v+ |6 K6 C: ?

) t3 ^. k$ W* gBOOL IsSoftIce95Loaded()
" J, G. X$ n9 Z  ~/ a8 c{
" [7 V" z9 ?/ Y- ?   HANDLE hFile;  
# z8 z* b4 d& O) ~3 Z   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
1 h5 a- a8 j. x. f% I9 n9 b' C, M                      FILE_SHARE_READ | FILE_SHARE_WRITE,
" _9 a! a, e: P' D) P                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);2 P8 \! ~& Z, f1 Q; u5 e
   if( hFile != INVALID_HANDLE_VALUE ): z6 @3 h" {5 d6 Q
   {1 m) N" H" `2 A/ ]) C7 u8 p
      CloseHandle(hFile);
! [8 s* [1 S- x; k1 m      return TRUE;
7 @9 h; ^+ S8 b   }
! Q) t5 c, G! S  [) `7 j4 w   return FALSE;3 b$ ]. W  r+ M5 d( O
}
% O" p3 S$ H7 C+ d" t) x6 N! i# B; ?/ {: K, Q5 h
Although this trick calls the CreateFileA function, don't even expect to be* J0 L- O' l" f7 V
able to intercept it by installing a IFS hook: it will not work, no way!7 @( c# X( j. h2 k  `! m5 A4 f
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
( i8 e* a" o. y. U  n" M0 |service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)4 f1 z1 O5 T' h
and then browse the DDB list until it find the VxD and its DDB_Control_Proc5 K$ p8 D/ F6 P7 o8 U* P
field.4 B5 z+ {2 w; d
In fact, its purpose is not to load/unload VxDs but only to send a
8 k. p/ c& M% T9 bW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
  X+ D- @. j9 r" H* ato the VxD Control_Dispatch proc (how the hell a shareware soft could try. I0 d: J+ [. L, r$ k
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
  ?* ^( x* X1 L; D: d) u' SIf the VxD is loaded, it will always clear eax and the Carry flag to allow
! s0 F7 {1 g) {( i; k/ {5 U7 ~; @8 xits handle to be opened and then, will be detected.0 q+ Y5 @0 Y  X) ]4 f0 R* J
You can check that simply by hooking Winice.exe control proc entry point& \" G1 D1 P1 F6 m0 B
while running MeltICE.
/ a2 G8 K9 \* U( `% Y
3 B0 u! T/ ?- \/ v/ @( o% i6 U
- C6 h% ~$ W3 n) ^/ E: ~- C0 U  00401067:  push      00402025    ; \\.\SICE
/ q# ^! ?& j# W& R  0040106C:  call      CreateFileA
  e$ Z/ s3 a2 D  A. R  00401071:  cmp       eax,-001; T' _) D  H+ v. c- H1 }6 z
  00401074:  je        00401091* _4 k; p- \9 U& V( L
- X  T5 Q) r; O( \- H( d3 L! s
/ i$ I- D( ~  f4 n0 @% l! W! F
There could be hundreds of BPX you could use to detect this trick.
* H3 L7 C( N. k-The most classical one is:
! [3 Q/ I; M8 }& p  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
1 p& v: c1 O6 l; m. Z    *(esp-&gt;4+4)=='NTIC'
2 M1 b- [$ I+ E, n, {8 U1 G- C4 a: y: X! h, r: A! g' i
-The most exotic ones (could be very slooooow :-(7 e$ M6 M3 h) G0 s
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
& G9 I% u9 ?0 \& b' I+ s     ;will break 3 times :-(( v! M$ [/ g4 z
& [7 v& X+ Y. @4 t9 @" ~" y
-or (a bit) faster:
6 ~: P- k. r0 R3 y8 ?   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')0 Z5 r( W) s, F8 A3 y, T$ U+ `

9 Y3 Z1 v. j$ i( h: t- `5 E7 v   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
6 i  A5 B- g' ^+ H     ;will break 3 times :-(6 l* [9 E' M, B6 h' m' h
5 u6 Y4 R. N% ?0 L
-Much faster:
* {+ n0 t4 G+ o3 H+ d5 F7 c7 n   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
. _, ^# Q8 i0 I* s% m
/ h1 J* e9 c/ ^6 _! j* mNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
" B& t- p) z( hfunction to do the same job:% `! ?- O& N& g/ Y: f6 x( z2 d
8 K3 {# K0 k; {% M: ~2 f/ A
   push    00                        ; OF_READ
$ d& a0 M# n# Q' T+ D   mov     eax,[00656634]            ; '\\.\SICE',06 X2 e+ r8 }& i' `+ s
   push    eax
6 b+ d4 A8 G7 Y2 Q   call    KERNEL32!_lopen
6 f* z( R/ o% A# j6 L   inc     eax9 D6 M8 A9 O7 w" R
   jnz     00650589                  ; detected
& j+ N: ~$ p' V' I5 e4 h4 N% [   push    00                        ; OF_READ
8 w1 T2 f, E4 k- o; Z   mov     eax,[00656638]            ; '\\.\SICE'$ \. B3 g/ l  f9 m" t& K: b' L
   push    eax1 r$ A2 _, [5 I  B& m( ^- a0 \* c
   call    KERNEL32!_lopen/ O5 B! A2 m& g- M6 Q
   inc     eax" N# y- t! {& U$ O
   jz      006505ae                  ; not detected
+ [; ^* ~4 {: L
4 N+ A9 \! H; c0 ~" ?7 T! ~: Y) o) p( Y' _# t
__________________________________________________________________________4 w6 T) z8 ~2 e- m: s% Z. r  G

" b! D5 W! Y7 I6 N" v: ^Method 12
: M* O% F0 M$ M+ b$ N, ~=========
3 U1 c2 R" k3 p* m3 _' r
' Q7 y, G7 T2 l* ~This trick is similar to int41h/4fh Debugger installation check (code 05
3 R+ |4 |2 _& T$ F&amp; 06) but very limited because it's only available for Win95/98 (not NT)
+ @; G2 r: [+ I) U/ Zas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
% Q- D2 `# C. Z: Z4 I% U  T; ]% N1 U" v4 U5 b& D  k- v2 \: ]
   push  0000004fh         ; function 4fh5 k7 L. ?. S* Z( O# y% R
   push  002a002ah         ; high word specifies which VxD (VWIN32)
! Z, l: \; k- n* B- L! Y( K# q                           ; low word specifies which service
' L) P  T8 |6 e; c9 p; ~, B                             (VWIN32_Int41Dispatch)! P% q8 W4 U/ c4 }
   call  Kernel32!ORD_001  ; VxdCall
4 s2 b3 A- z$ {' D5 g1 w! G   cmp   ax, 0f386h        ; magic number returned by system debuggers6 M+ G2 A) d. |, G4 r" y5 E
   jz    SoftICE_detected. v, n2 s4 C8 Q5 x: `0 j

& u6 Y0 k+ v2 {Here again, several ways to detect it:
  \' x5 T& g* `' G. I$ R& R) ~- b  `* ?; N3 i
    BPINT 41 if ax==4f
) w, O6 ^; {' n! M+ Y- ~  p8 G
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
/ ~* n2 N$ |$ e; [" H, Z
4 V  {' Z# `8 f% @3 B    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A; G0 L/ B7 Y  Z2 ^, a- J$ M6 E
( M0 C: M8 O0 w/ O2 {7 O: e, f
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!; T* K/ l2 R: u, J0 S+ Q0 J" Z
* U5 l" R/ E- x- }
__________________________________________________________________________5 R0 |9 W! E7 c: ~( Y* J
7 n3 \/ ?. ]  d
Method 13: d/ f0 f+ `( v& _# h# B- L
=========- A) s4 F; S$ }# ?/ t/ D

, e! ^# g5 K/ fNot a real method of detection, but a good way to know if SoftICE is
* w: k! I: H0 e+ U0 V7 g: Kinstalled on a computer and to locate its installation directory.9 D5 u7 g7 O% o3 @  N; Y3 T  W' R
It is used by few softs which access the following registry keys (usually #2) :' P* u6 P% `/ y# ^# d2 L3 q
: v$ H) x2 z6 r) l* `
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
: Z/ D, J1 {) T1 I\Uninstall\SoftICE9 O  y9 m# @: M4 {: f
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE1 E( i2 ?# g/ t2 Q4 E3 h
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion* r- @4 b$ h# D9 m  |3 \
\App Paths\Loader32.Exe3 \" D) R3 V6 X6 L
0 s5 [- a3 v4 T: Z

6 [% Z' p2 X5 O- }* \/ A' \2 MNote that some nasty apps could then erase all files from SoftICE directory
1 B0 y( o8 ?' P* k% e7 {9 `(I faced that once :-(
7 W' ^$ a% ?# |" m6 P$ T0 U4 r/ Y9 r% q  S9 _4 X3 c* P  G
Useful breakpoint to detect it:$ g. R6 [: m! J& c# R0 s2 A5 m- S
; O& l, x; h/ j8 ]' e
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'2 N+ j* h5 {: {' q/ p

6 s. T+ X2 q. z2 K, L__________________________________________________________________________
  U8 \5 w* n- l) T' v0 ]* z
& H+ h, U3 w( ?5 a) y0 \+ ]* r0 X, {: g& X) ~4 ]" G6 q" O) k
Method 14
8 ]% S" f$ t( Q& y# b; f=========0 A0 M4 T1 a" b3 G# u% Y* O# ]

3 y4 B" F! Y1 v$ i4 S- S& P3 V4 C4 wA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose3 T) Z+ j3 Q+ M2 f+ t  O' H
is to determines whether a debugger is running on your system (ring0 only).
7 Y9 R5 k% [- g" T
- j6 `; T/ c+ u   VMMCall Test_Debug_Installed
3 N. e- X  ?0 O3 T1 S   je      not_installed" u. p* l, S  J! n4 Q& [

3 a4 A# ?7 K8 @4 ?5 o5 ~( t* f4 L7 tThis service just checks a flag.
0 b7 v& |7 K% @; U7 Z* }7 X1 K</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部