About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>% G  x1 F6 _$ j; T, G6 p0 Z+ R
<TBODY>& V9 a5 p) d$ ~$ x% L" s: Z" I
<TR>
( P7 S. i' Z2 u" }; I<TD><PRE>Method 01   [$ K4 n+ W' S1 \* \& R8 k
=========
( F, h% p' c$ k. A- m5 ?  Y' w
This method of detection of SoftICE (as well as the following one) is0 N% E) n9 R; A! [' Y+ A
used by the majority of packers/encryptors found on Internet.# ~4 f4 C2 ~' _. e" d, t6 B
It seeks the signature of BoundsChecker in SoftICE9 S, n: K3 j3 ]! v

' m  y0 v: Y. H( H6 P% W4 Q9 J0 C    mov     ebp, 04243484Bh        ; 'BCHK'; s$ N2 |8 Q, M7 w4 A. }
    mov     ax, 04h
: x2 W4 z) L! Q  n* o5 C, K    int     3       0 V0 Y2 W; C- {. R* K0 S, U
    cmp     al,4
2 i, m) i  J- j1 \& m    jnz     SoftICE_Detected# [( b) c0 a  t( K

; _/ B& s' _: H5 C) n; E7 G. b___________________________________________________________________________
/ D( g; @- p9 g8 O8 Q- P" u) g
/ u5 d+ @- m2 o+ k& _7 UMethod 02
/ [6 r8 l/ ^/ b* I1 m=========
) I- n$ O5 @3 y1 C* f  }9 S0 w, I7 [. N2 u5 ?3 y
Still a method very much used (perhaps the most frequent one).  It is used
/ U+ v  R5 C$ J$ D, Nto get SoftICE 'Back Door commands' which gives infos on Breakpoints,8 R; q$ I1 z5 |# ^3 U% n1 ?1 x* j
or execute SoftICE commands...
2 S' x: e/ E6 e( }$ z/ EIt is also used to crash SoftICE and to force it to execute any commands2 p/ V" t( U: Z( o. s
(HBOOT...) :-((  # L- ?9 M5 r: ?8 M& e9 Z

3 Y. V' h( F9 }) c$ I: j. eHere is a quick description:
1 f& _. V( v0 V- j* }9 G/ J7 C- e# q-AX = 0910h   (Display string in SIce windows)
# m# O4 O6 B$ }5 \: I-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
# P7 V" |4 P8 G4 i' ]-AX = 0912h   (Get breakpoint infos)
$ K# U% l/ w$ Q-AX = 0913h   (Set Sice breakpoints)
' A% }4 b% w- d' ^9 T2 m-AX = 0914h   (Remove SIce breakoints)
1 I7 g# C& q0 k, Q0 U! O  H* ]3 J$ d
6 c6 h0 S1 C7 B5 T* U) w' dEach time you'll meet this trick, you'll see:
' w, ?5 m0 Q+ c- d( r-SI = 4647h# ?/ {: U+ q- w
-DI = 4A4Dh5 ^1 ]) d* q- D, c3 _- m7 |
Which are the 'magic values' used by SoftIce.
7 j4 W  r5 s- d+ A5 J6 j) k: R; zFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.2 ~* J7 e, E% \" x; O

2 Q7 z& |$ s: p& a) }. \$ q1 [Here is one example from the file "Haspinst.exe" which is the dongle HASP( |4 F6 {" o( R3 o3 N0 R  N6 U
Envelope utility use to protect DOS applications:5 O( Z8 u8 V- b! Y

& Y% X- w! Y) w' j; N
7 z' H( p, y; P/ S# C6 R4C19:0095   MOV    AX,0911  ; execute command.
4 e- s0 g4 i% Y: m" @$ K% v" E, }" x4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).6 r5 H# Z/ C8 }: S1 t3 v. c& R" G
4C19:009A   MOV    SI,4647  ; 1st magic value.) \. C! A3 |2 J% D
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.3 T6 \. `5 r; `6 x; k7 S- N+ B
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)# L6 G' D5 [& g. ]5 V( C
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute7 M4 T, ]1 _- |' R) B
4C19:00A4   INC    CX2 `, s' |- X; K' R) y2 L
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
/ O) q$ |5 j( H8 {! k) D3 t( E4C19:00A8   JB     0095     ; 6 different commands.  n4 V+ N+ a: k0 l% K. |% a
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
; E& z3 i( D4 K. m" [4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)" a4 U  b: G9 i4 y- x: s+ X

4 \* m, @2 P6 O/ U0 c2 A3 [0 x! E0 o8 OThe program will execute 6 different SIce commands located at ds:dx, which5 M2 D: R0 ?8 Y: p7 E8 j3 T( y
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.; u: |. Y! e. X3 Y" W

4 E4 d. k% k$ p* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.! O( Y- D! B* F  u' c
___________________________________________________________________________
" N# x) j) s% {1 u( {8 X" V4 q6 e$ l$ ]  n+ g* ^3 {: c

3 g: M; R: F* U6 wMethod 03+ ~4 [( j9 A. x6 T' p( b" l' Y
=========
' A& I" e$ P0 L) ^$ t" q/ U1 Q
! }& l' L1 w# h; iLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h% p/ p* t+ U  B9 a
(API Get entry point)+ q% ?" ~3 d. O5 Y, `4 x
        
# T$ {6 Y" [% ~. i# _
! ~8 J2 {4 p" N/ n2 n    xor     di,di+ T$ P$ b3 n* i0 ?. `3 A
    mov     es,di: e4 ?. o" C$ H, e- @
    mov     ax, 1684h      
- g, h) J) g0 ~" H0 a    mov     bx, 0202h       ; VxD ID of winice
& `- ~! V& A3 t/ s/ e' y    int     2Fh; R/ R2 A1 _. V, p" L
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
0 S/ P& N! p6 |: F2 L1 z3 t& e    add     ax, di5 d0 d8 L  F9 [. F
    test    ax,ax
/ M4 x7 d* k" o( Q# \    jnz     SoftICE_Detected. X0 ^1 Y% n, x+ k

+ C2 s( _9 f; [2 T, L( S___________________________________________________________________________3 Z3 [' m5 h% J8 d( p

+ y- u0 U- B4 v9 L6 u' B* H0 zMethod 04, H$ Z& l# d% d+ H+ E
=========
# S% M, v' f( h% i2 K! L
4 X0 t. }% {3 o8 Y( J3 q+ ~* e( _" b7 kMethod identical to the preceding one except that it seeks the ID of SoftICE
3 |2 _% C0 T2 x9 gGFX VxD.
9 q  P+ G1 G& e/ `/ L3 [) t4 W4 s3 W/ s$ _5 E* k! S
    xor     di,di
5 C" Q. Q1 R3 Y    mov     es,di# u8 ]+ {4 O0 \5 I3 j
    mov     ax, 1684h       ! l/ G% ^2 h' {" D2 o- B, }
    mov     bx, 7a5Fh       ; VxD ID of SIWVID  e9 p9 c  z; i) m
    int     2fh) q- P! N; S! q4 D/ n& x
    mov     ax, es          ; ES:DI -&gt; VxD API entry point- U! t9 T; D$ A  o' v7 L
    add     ax, di2 L, q+ @2 E9 D% G+ f2 i$ n
    test    ax,ax
3 n' K4 K( L& B  ~( T, _6 m    jnz     SoftICE_Detected0 h" X, k8 l+ z) q2 ?$ \

5 Y, r4 l) j1 d% z0 C; U6 e__________________________________________________________________________- y& L4 W; c& m% \* Z0 N( J) K
- `$ C9 M- F6 x. A3 F$ p; ?
. ]* j- C( [/ L/ L8 D' C: M. B
Method 052 V* h( R1 N& [1 U  }
=========
; I/ I$ g2 j4 ~) {' V5 X9 a$ {) Z/ t: H+ Y8 f' x
Method seeking the 'magic number' 0F386h returned (in ax) by all system6 T2 [+ c( N, u/ u* _5 P
debugger. It calls the int 41h, function 4Fh.
1 g  `. P8 A  p, d2 D2 [0 rThere are several alternatives.  
; w; W0 d7 u$ r( `( a8 e. C5 t6 Z0 n' L. p
The following one is the simplest:
: ^# L) `8 O2 S3 q, }* _
, V; `. _3 Q( y1 H/ N* F# `0 L& |    mov     ax,4fh
, [; G4 B: G# }/ r9 E    int     41h
0 I$ I$ \  @& N9 a0 h& e    cmp     ax, 0F386
& Q- O8 |* O7 H' X  }& q* k    jz      SoftICE_detected
7 N) m+ u( g2 Y- y* R
$ `4 u5 b4 [% @+ y0 B' {& F
7 Q6 Q* I) {3 I/ d/ A! |Next method as well as the following one are 2 examples from Stone's 0 C+ P2 P8 p( X7 W& A7 f
"stn-wid.zip" (www.cracking.net):
0 ^( D  t! X- k5 ?* n' j4 ?& Q4 q/ h! [
2 f7 g( R' x. M9 K    mov     bx, cs
- l- u( O6 d9 s# y0 Z. G    lea     dx, int41handler25 f1 j# t- l- m, z# k: S) G
    xchg    dx, es:[41h*4]
& o# @( o- `% I! \6 ^3 a# u8 y    xchg    bx, es:[41h*4+2]- I, H& @/ h# u! }, X4 e& W7 I; C
    mov     ax,4fh# h& c3 x1 E# c: f/ G* m1 _6 K' M5 s
    int     41h! t- c! V# x( P* h7 _
    xchg    dx, es:[41h*4]+ m& ~& Z9 q/ O6 l8 E
    xchg    bx, es:[41h*4+2]
4 T- B" I0 v. L% P2 ^0 r: p8 V    cmp     ax, 0f386h/ E. `: M; F2 b8 a# f' v: A
    jz      SoftICE_detected. b8 z" L8 p" K  j3 h7 o

% P0 w0 L/ [" fint41handler2 PROC6 _6 m: F& @3 t  Z$ w
    iret
$ r* Q. G+ N& |6 _* i$ gint41handler2 ENDP
+ I/ i4 Y7 w7 {2 O( r
) H6 G2 e! S3 o: z: J/ I2 F7 M" e! l) [  C% S: y1 J) H8 a! ?
_________________________________________________________________________
' o! f1 ]! M: p2 m- Z  m2 g/ Z) p% z) P2 }5 V5 Z
' K, _5 i" a; p: j( {
Method 06
( y! i, \1 ~4 `/ y! B, W0 {0 X, c=========
5 c) I7 c+ N' G" y
' V) Q' T3 n4 K$ n8 Z' Q6 C8 M; U4 u, m( d1 Q* p+ i
2nd method similar to the preceding one but more difficult to detect:
) v) T5 e2 Z! X0 g1 b; o' H; Y4 Z5 t: g2 q# H
2 p, c5 L- M& X
int41handler PROC! K; o( ?! V. ]) \$ r- u' u7 M
    mov     cl,al6 P2 Q2 M, x3 K% B( M
    iret. c! X( f( v2 C5 O$ v0 A2 ?. @
int41handler ENDP9 j+ [, i0 K6 F& {

( x, l7 U8 |$ x2 z5 |: o
- n& I* u8 C& {9 m    xor     ax,ax
; i# I( y, u1 ?. I2 `' @    mov     es,ax! J# w5 ~9 Z2 E1 K' S& F
    mov     bx, cs3 k% d8 a  m- y+ g/ @- F
    lea     dx, int41handler$ B) s/ O. s5 a5 v
    xchg    dx, es:[41h*4]
+ e% {& i9 U6 u' [. E0 B    xchg    bx, es:[41h*4+2]4 I. e3 Z: r$ o/ V$ E! ?
    in      al, 40h; h6 r8 N1 M0 e1 N: d) p0 |
    xor     cx,cx) e: s( q. Y* B9 ^" Y
    int     41h% v  F9 W5 P% G+ Z
    xchg    dx, es:[41h*4]- O" u$ b1 D) U0 p# S6 ]* |$ g
    xchg    bx, es:[41h*4+2]
/ L) S: c( n0 E6 R, K    cmp     cl,al
& U" o- e* {) n: e3 F    jnz     SoftICE_detected
1 i3 T9 w7 N1 r$ x* i! J4 n( ~$ k9 n+ Y; K+ @
_________________________________________________________________________- O+ \4 C/ q! y( M, Y2 I% z

* u* V8 i0 B4 O0 iMethod 07, f. ~- H+ J/ P
=========. }3 V- E( J: B  j# P1 a" g
% N& q% ]8 Z8 c% R! O" n: ~! Q
Method of detection of the WinICE handler in the int68h (V86)
7 A1 O0 W7 G3 I; \6 z3 r& U+ D% e) E- J8 H9 u5 W
    mov     ah,43h
* w( O1 T+ W: l    int     68h
1 Q7 t" j8 h* N0 U7 w! O& I    cmp     ax,0F386h$ Y! S1 g2 g: x
    jz      SoftICE_Detected& U2 c9 W3 m: G
% b& V( K! z  n( o  ?
: l" V$ m0 f. @5 H6 \, v, w
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
% u( ^1 W: D" E4 `0 C" E$ n3 B4 G   app like this:5 _3 ~: ^/ q" m* j- Y& M, M! C

2 c  b5 ]* \! n' ^7 Z   BPX exec_int if ax==68
, G4 }- B1 X2 ~- z- V$ ?# |7 b   (function called is located at byte ptr [ebp+1Dh] and client eip is
- w7 Q) |5 J- }2 M9 f   located at [ebp+48h] for 32Bit apps)
0 u2 D7 f' m/ ?) ^  q" @__________________________________________________________________________! |7 D5 B8 ?% k: l, P4 V

, P7 Y# L/ `: u; A
6 P2 W, e" q9 |Method 08
: E$ o" n2 @+ m, O( h! w0 _=========7 Z" L0 i* G' D6 ~) R
* U3 A8 ~. i  Z- U6 t
It is not a method of detection of SoftICE but a possibility to crash the
5 U9 @# e9 Z5 B) q; G' x$ @' Wsystem by intercepting int 01h and int 03h and redirecting them to another7 X) d, B6 P) J9 _7 A, _
routine.: H5 R3 g  S, q; r
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points: _( i" j0 d; @& }, c0 l5 h
to the new routine to execute (hangs computer...)
0 g' Q1 U5 L) j1 L$ L( b2 m. d' v1 }9 U" H. ?; y% K/ T
    mov     ah, 25h
& x" Z0 l3 c5 `+ r    mov     al, Int_Number (01h or 03h)
. L& a1 M' r0 I0 T  R    mov     dx, offset New_Int_Routine4 U3 I4 R$ \& n9 X2 |! r
    int     21h1 M0 e4 ]: A( H7 E

' ^6 c- u! }+ V- z& z9 L. C__________________________________________________________________________
! R( H) L0 c* N, b5 i  E4 v, g3 g  ], L4 _6 s; {6 }! i6 ?* w8 H
Method 09
# F- W5 E9 y% _% U# s( X  s=========
6 T" @$ M1 B; ^' x$ n
, v' q% L9 ~8 G# z- A* fThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only& B. Z. `3 Y! Y2 R, H. y2 ?
performed in ring0 (VxD or a ring3 app using the VxdCall).
) L$ c, R0 z( G6 j4 J$ P( U3 iThe Get_DDB service is used to determine whether or not a VxD is installed/ B% B: d$ i, i) y8 `
for the specified device and returns a Device Description Block (in ecx) for
  |+ W8 @1 ?6 x8 Q# Sthat device if it is installed.
, ?; b- ]/ E1 g" l5 r; `7 w2 Q+ h- d4 r) j  r) m- U; `
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID0 J4 J+ f$ e8 S
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)- X: D+ q. y( U' m/ D; R* E5 D
   VMMCall Get_DDB4 G; X: ]+ ?4 O1 \1 Q8 u
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed- D( W6 k5 O5 C, Q* Z" _

6 G& U% I1 \0 }9 s7 BNote as well that you can easily detect this method with SoftICE:/ K, Y6 h" Y5 {2 i
   bpx Get_DDB if ax==0202 || ax==7a5fh
" n/ g1 j4 f; N; r* u3 W. }; F4 t. _. x
__________________________________________________________________________; c9 F9 v: ?% l2 M  W& W

; k4 z( Q1 l# k( @9 ]Method 10
& v" U7 r" C5 ^) P0 ?! j=========
7 n4 K8 V% [, ^# a4 J& r( f: a' \
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with# c8 l0 b2 ?) z' Y4 b# ]
  SoftICE while the option is enable!!& C* S: }, ^: Y, ]1 y  b

  n5 q( i) u) LThis trick is very efficient:
% e$ |# J1 ^) A  O$ y: qby checking the Debug Registers, you can detect if SoftICE is loaded# p: S, }) M4 x0 v" v5 x  t  X+ ~
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if' \9 p( v/ b) C7 x. f9 V2 m" H
there are some memory breakpoints set (dr0 to dr3) simply by reading their
  \: m/ _' P8 M5 i$ @value (in ring0 only). Values can be manipulated and or changed as well
) B# r  X, Z. o3 }/ s9 p9 o9 S# c(clearing BPMs for instance)
1 |. S8 ?* ~! l) G1 U& I" }
( l/ s" H! I% h- g& o/ Y__________________________________________________________________________7 c, }+ p* G9 \/ L+ F! ^

. @( T- w/ A' ?$ L% D5 _, dMethod 11( b$ ~. B5 _+ W7 |
=========
: K- e/ n7 ^) s! L+ i2 V# h- q7 I/ D0 p
This method is most known as 'MeltICE' because it has been freely distributed
- _5 F8 i9 ]$ Pvia www.winfiles.com. However it was first used by NuMega people to allow
; e% ^6 F6 @! q! R6 s4 CSymbol Loader to check if SoftICE was active or not (the code is located. X4 T- x$ c( R  X, g
inside nmtrans.dll).# X. _. U# ^+ ^" B5 O; ?

# T5 x1 x  c& X; s0 XThe way it works is very simple:
; u6 c" @( B4 [: P3 a4 O. [7 ]% MIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
1 `8 B4 T- V2 Z* F; vWinNT) with the CreateFileA API.- i! q, @; @/ |! f

, u- E, P0 w5 @7 xHere is a sample (checking for 'SICE'):
5 z7 m/ |0 z: }# o6 E
& U; W$ F- |& n2 P) D4 g+ J- fBOOL IsSoftIce95Loaded()5 c+ M0 }# n  k5 p
{$ b: B/ D; J- M. K& u( J- \
   HANDLE hFile;  
+ e% b9 S4 m9 f' X   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
8 q1 R3 t! U0 G4 V                      FILE_SHARE_READ | FILE_SHARE_WRITE,
9 M/ F/ i) f' z7 }5 B                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
! h0 k( g+ {# P) [5 `- p   if( hFile != INVALID_HANDLE_VALUE )% j! R0 }+ q, w7 f
   {' @) [0 c- x$ G: t) [9 U
      CloseHandle(hFile);' D9 v" {' K( f7 r- D3 x
      return TRUE;7 g. Q0 Q( o$ A9 C, i( K# D
   }
! Y7 e% X7 e. J% R9 a9 m+ }   return FALSE;3 x: {. b; r$ ]$ ^6 h
}
+ f* b1 r: E8 c3 |  [$ l# k9 L& ?+ E1 x# e/ K
Although this trick calls the CreateFileA function, don't even expect to be) {/ f4 ?9 k  E  `7 r  S
able to intercept it by installing a IFS hook: it will not work, no way!3 d+ G2 d! Q7 M4 E- l: c
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
2 W1 d8 O' i  h* j7 w& ]+ Uservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
: o7 O! v% b5 B" Wand then browse the DDB list until it find the VxD and its DDB_Control_Proc
9 Y* n6 _7 @% `0 c1 a( wfield.
9 N0 {  D. _+ \8 z9 \, I- T$ v# ^In fact, its purpose is not to load/unload VxDs but only to send a
& d3 i3 o+ u( B9 W3 a) vW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)* h- {/ ~1 x1 Z/ j+ a, T( R, N
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
& @, D5 H/ y  Q* v7 \to load/unload a non-dynamically loadable driver such as SoftICE ;-).
) a: m% Y( M# ~- tIf the VxD is loaded, it will always clear eax and the Carry flag to allow
1 P- k$ J8 A% s  q# h" _its handle to be opened and then, will be detected.; D# x( P7 X2 t3 r% }) l7 N
You can check that simply by hooking Winice.exe control proc entry point
- c% b5 {$ O" R& }# _+ {8 C! hwhile running MeltICE.. ?; ^$ ^. ~9 ]) u, M- H+ B
) G1 Y% s! b& w. q- D
4 w. N: O) X" F+ [; r, ^" y
  00401067:  push      00402025    ; \\.\SICE8 N( `, W: N( j2 ~
  0040106C:  call      CreateFileA- a' q/ n: Y8 t
  00401071:  cmp       eax,-001* {% n* `$ H% u) \) o
  00401074:  je        00401091( h; E; R; w" o9 S$ L7 _; C
1 P0 v9 }. Z1 [/ k2 W

, L- P2 m. B) y2 q$ Q  `4 hThere could be hundreds of BPX you could use to detect this trick.
+ x/ I/ O9 X/ l. {; T7 D9 V-The most classical one is:
, C6 @" q# R2 n0 |, v! `# ?  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||! l/ Z& V6 O4 j' X8 ^7 b2 B8 \" z
    *(esp-&gt;4+4)=='NTIC'
5 f- m! g3 }( P5 }7 D3 g! V9 H4 |: v) h  @
-The most exotic ones (could be very slooooow :-(
9 B) K, N1 v5 o( d! a  |   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
2 V1 p8 ~9 o$ U  x( Z4 w- K9 Q     ;will break 3 times :-(  N0 ~% [. s* m$ h* n5 G* c

# G1 `" `. a4 F! g$ a- d; o-or (a bit) faster:
( B# w. Z% \1 J6 A: S8 `. s   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
3 K/ @$ u6 F8 ~7 G8 T% B9 P$ S+ \" ^+ S
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  ; Q9 [* ]& x# r" A; ?
     ;will break 3 times :-(
  e8 o0 i, i; X- `8 p4 Q% j$ W4 [6 _) N* j0 r( v. V2 Y% H
-Much faster:  X$ t# d9 Q' [" ]2 d$ g: X
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
% q% E  i9 g0 r
% P, U# K2 Y* j( N" @; aNote also that some programs (like AZPR3.00) use de old 16-bit _lopen* D& ~' S9 }- u( k
function to do the same job:
' X. t- y3 p& y* N) P
/ d- `0 I: T) c, T$ r. S) x7 B   push    00                        ; OF_READ
5 ^. E' E: ^0 z& m9 S7 e+ |   mov     eax,[00656634]            ; '\\.\SICE',0' x/ D8 p4 Z$ k; ]
   push    eax
) ]0 B% t' H# y) S   call    KERNEL32!_lopen
* ^+ A6 t+ S9 `! n" c: n7 z   inc     eax6 g0 x1 J/ B0 j3 N- w( V" q* K% o3 ?
   jnz     00650589                  ; detected. _- K; n5 E. Y. G9 U/ [
   push    00                        ; OF_READ
0 r( `% t) _' E% X! G5 D" q+ u. t/ ^5 C   mov     eax,[00656638]            ; '\\.\SICE'$ }5 |* f# F) ?% r- G
   push    eax
+ {7 p( w/ }- a0 y( a: c   call    KERNEL32!_lopen. K9 W7 l7 ^! M) U3 y7 h  @  U
   inc     eax8 u3 \1 x3 K+ u; _
   jz      006505ae                  ; not detected
, r8 [5 R) v7 H' v5 |+ @
5 x: e! b% a, A1 }# d: n+ v: D4 O& H9 Z( S% V) m2 B
__________________________________________________________________________
: [! E2 |/ b2 Y# ^2 H
# w8 l& ]' e+ J! ~) M  V* ]) YMethod 12
, \( E$ \+ l: o4 K4 d. T9 |=========8 M; ~. J4 Q9 c% A5 c: g
: L7 K2 m' r1 {: |# j
This trick is similar to int41h/4fh Debugger installation check (code 05
: l5 N/ s9 a& S6 _&amp; 06) but very limited because it's only available for Win95/98 (not NT)
3 s6 Q. x% L( g% mas it uses the VxDCall backdoor. This detection was found in Bleem Demo., \9 T" M& _! F+ j# U
6 @) r2 m9 v* T$ @" x# S
   push  0000004fh         ; function 4fh
; F. q6 e9 @/ v6 H  ]% h" J   push  002a002ah         ; high word specifies which VxD (VWIN32)
' u9 m$ P6 d# z; n" {  Q# g! I2 V                           ; low word specifies which service+ O3 R" z& B5 X; _
                             (VWIN32_Int41Dispatch)' `4 A0 ?' J1 t& G
   call  Kernel32!ORD_001  ; VxdCall
- N5 _' @2 C$ W5 W   cmp   ax, 0f386h        ; magic number returned by system debuggers
! @/ D8 A& S: b: a' Y   jz    SoftICE_detected. j1 k# h# f; Q( l

3 m' V. ~( m5 }5 J9 I; E/ C  oHere again, several ways to detect it:. `8 ~% f3 r2 ?# a& D: ]
( V& k$ |2 B. r4 ^( r2 S: V, j) D
    BPINT 41 if ax==4f
4 l; ^3 E& t6 B0 m+ M+ M* E- w4 S2 g9 O* T; H
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
) A7 ]# R) L/ J- j- w, k& c8 I. Y, V, b% ~, ^/ k5 m
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A, n4 \1 E$ _% |/ }" u6 Y% w
: e6 d1 ]$ \8 `% V. P% X
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
0 Z8 O# i- b( P8 m
; o' u+ i$ {( W) m) ?8 G4 n__________________________________________________________________________# q  U3 G7 Q# q) f3 Z. a3 Y
8 }3 f" x% t0 d: h1 X: r3 [! N: ]8 t
Method 130 Z$ S. q3 [& k' k1 |! d% Z
=========. B% k6 m6 d" Z4 [

2 Q$ v6 R+ }  n  INot a real method of detection, but a good way to know if SoftICE is- n. J, J2 S. x# o! @9 J0 h
installed on a computer and to locate its installation directory.
) N! X* [; K- K' d8 T' a, SIt is used by few softs which access the following registry keys (usually #2) :3 z$ Y9 h( T+ L! n

6 [. @# |) ?3 `! a" u-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion  Y9 W; O, \- i9 u" D
\Uninstall\SoftICE# E; c) H, \% w" c1 S, `
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
) D$ w/ r' q' E0 }: n  A-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 u' N3 |2 I! e9 J
\App Paths\Loader32.Exe
& ?+ a; E1 K. }' t( B0 i
4 V# ]9 n, G% N5 H  n0 g8 M9 T" f* ]9 F, F8 x% Y4 K! y
Note that some nasty apps could then erase all files from SoftICE directory
8 F3 V* n5 A- z9 |. _( A(I faced that once :-(
" Q9 `/ ^( o# S' }) G% }' ?; \+ U+ y4 k) s  g
Useful breakpoint to detect it:
. a2 V9 c  _$ d" |# P% c9 B6 ^/ T. I2 ]: g" l0 C* T3 P
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'& j" a5 p6 q* s* Z$ z

7 B- A* a4 A8 O9 I9 g1 Z+ K__________________________________________________________________________
% m  V. U( j2 W) r
: K/ H/ A# B( v+ m
; T5 ]  H3 L$ V3 CMethod 14 ( B, u7 g" s# ~8 e
=========& A- Z$ M$ X4 U, r+ u6 i
9 l! o+ j! ^) ]( r% }( H) z: W
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose: P$ K# O) q3 n/ X1 M7 n
is to determines whether a debugger is running on your system (ring0 only).% M' m4 ^- |' V; D

. _4 \- A6 t& K' Q4 n+ E7 u   VMMCall Test_Debug_Installed
9 W( F7 C; v3 Q   je      not_installed+ a4 @" N/ r" W1 T
: \& g: a+ q: X9 x4 X% o/ e, f
This service just checks a flag.
; f0 N* ^/ q8 j& v9 N- F5 a</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部