About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>: u( f1 v, R: G/ ~2 Y
<TBODY>
+ E3 a% m. W( I- r/ Z<TR>9 o7 \/ @4 a0 [9 q) Y
<TD><PRE>Method 01
$ p( S( g; m! Y, R0 h6 h5 g8 b1 L=========
6 ]# P0 F8 S; m  p- y  d7 ]
. P. ^. ^# a* c) _5 z: FThis method of detection of SoftICE (as well as the following one) is
; [$ e1 y# {' r2 r/ @- ]! o; {" ~; Aused by the majority of packers/encryptors found on Internet.. e4 f1 o% T$ A. x
It seeks the signature of BoundsChecker in SoftICE
7 o2 L( ]4 ]. _* w9 ^( @5 d9 ^7 A" H/ l; E
    mov     ebp, 04243484Bh        ; 'BCHK': P* Y# p8 r/ @' B2 w$ L8 F
    mov     ax, 04h/ i& d3 _2 m  M, L  _' o, _1 {
    int     3      
2 e5 w. J, t9 V4 i+ W: E    cmp     al,44 Y) J4 @$ @4 \8 H# L  u
    jnz     SoftICE_Detected
/ o- q; l0 c* E- p
0 f% _0 A3 [, C2 e4 R  |___________________________________________________________________________- m: J4 a( t5 p5 X: e# k
% q2 U, \( l3 T! ?& q
Method 02
4 }) \1 d% h9 C. `* U8 c  b=========$ k7 p) [# {! C. b& e; D5 D% W

% Q9 G1 W1 j7 [- e% X/ [. dStill a method very much used (perhaps the most frequent one).  It is used
, f$ c/ k: n1 Kto get SoftICE 'Back Door commands' which gives infos on Breakpoints,$ F; a& {' }" v7 K' e2 n& [5 V0 Q
or execute SoftICE commands...
. p. _" t! [( m  j) D# aIt is also used to crash SoftICE and to force it to execute any commands
( @9 s9 m% V. p' }8 a, Z$ k2 t(HBOOT...) :-((  
6 z# r8 a, s0 X. N; c  w4 H7 l2 y1 p  |  b+ q
Here is a quick description:, \" {* o" A* ~: d
-AX = 0910h   (Display string in SIce windows)
+ b; a2 T; e8 D3 k( {# E# Y-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
( l5 H% v0 v! V' |7 u: I' @0 W-AX = 0912h   (Get breakpoint infos)
9 ~. |. S& e" z  \" K-AX = 0913h   (Set Sice breakpoints)+ g0 N6 {+ M5 m" i- H9 |) p' F2 D
-AX = 0914h   (Remove SIce breakoints)) c* L+ y( D" J: Q' ~
* j6 `: S/ P0 b' _* \
Each time you'll meet this trick, you'll see:
# e3 A# }7 ?' i& ~- `# O: q-SI = 4647h. S# b* B' f! a3 q7 g3 V
-DI = 4A4Dh$ n7 A( n# P: }( L. R4 g2 |# U  g
Which are the 'magic values' used by SoftIce.! n; O" g5 k2 D- Q4 b! o: h
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
( W9 i7 h7 E: L% H$ ?1 s
; C" ?: h1 W4 Z1 Q9 A+ hHere is one example from the file "Haspinst.exe" which is the dongle HASP
6 e- j; M& S! v) o- H( O5 pEnvelope utility use to protect DOS applications:
9 E! I9 l% o7 {# J7 b9 t& \9 H" @( _5 U* y9 D; e- a0 F
2 D& ~9 J5 z+ c2 _  w( z0 \$ b
4C19:0095   MOV    AX,0911  ; execute command.! ~- ]1 `6 |! B6 m& v: t# ]# ?
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).$ P1 u% `8 x9 z2 i0 z) F6 b
4C19:009A   MOV    SI,4647  ; 1st magic value.  E% U3 |5 Z  ^" F( l# l
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.  u8 [7 d) Q" f9 t) w1 l
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)# G0 T9 l( W0 {! d
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute& i+ f$ ^% J3 ?7 e
4C19:00A4   INC    CX, W& Z, S5 |: w* ?
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute* H" i0 j2 g4 n
4C19:00A8   JB     0095     ; 6 different commands.
; d9 h4 f4 N: C" E  y: a: A4 T4C19:00AA   JMP    0002     ; Bad_Guy jmp back.& F, k" G% I2 `" r. R
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :): u) q3 o& \) F) M2 L% x8 P
* {$ J: M* d8 t$ M9 ?
The program will execute 6 different SIce commands located at ds:dx, which
; i6 T* E* C# q0 r0 Qare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
* {6 R% o* q5 P) L% K7 W- R/ K+ q& S7 U3 c8 e. M
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
7 y1 k) i+ e0 U7 J; A: K: s___________________________________________________________________________9 g- O2 v, Q  q! Y$ t# |7 z
: K9 F6 e: y4 ?

" A* C! v8 `% HMethod 034 O# r! k+ N, Y$ L" v
=========3 J6 H( d/ S5 y, l# d* S. c

) U' T% D# u- h5 M: uLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
2 b* x' f& i% b1 ?$ d1 N(API Get entry point)
1 c- v' x7 u& k9 h        
1 b: Q8 d) A# |; ~$ K0 s/ Z  }/ j3 i; ]* K
    xor     di,di
  N( |8 `  a( Z, c! l( _' D8 V4 H    mov     es,di) C! u. {+ Q# `" s! @5 E
    mov     ax, 1684h      
+ y, [$ N2 d9 ~: O    mov     bx, 0202h       ; VxD ID of winice  ^/ k' e' Z# g' Z
    int     2Fh. O: Y9 D$ A2 B: e# p
    mov     ax, es          ; ES:DI -&gt; VxD API entry point# s2 K4 c% h; J! ^: \1 H
    add     ax, di
' P+ @. u( a: v" v! a    test    ax,ax
0 K! U, k# x' R    jnz     SoftICE_Detected
  v+ I! l" x( z0 g) Y: S, P$ \' ?1 N( x7 V; T, I
___________________________________________________________________________  x, h( b3 r4 D& n! q1 Z
- \8 `: u3 Q4 h% h0 T
Method 04
- t1 Z. p6 A  q6 m! }4 S5 Y=========
, l7 G% v8 k! d/ D6 C, \$ S' \, w: h" `" O/ U0 y
Method identical to the preceding one except that it seeks the ID of SoftICE- s* l' ?1 k2 o: g* o2 R) `
GFX VxD.2 x7 E, U( [, e! N$ |

% N, c+ U' T6 {  S4 X6 h    xor     di,di
1 v- n; t' e# E$ e& `; s* z    mov     es,di
* T) _/ e4 O/ v$ B; G. u: K    mov     ax, 1684h      
# ~2 l8 C4 t& B3 W+ s0 j& G    mov     bx, 7a5Fh       ; VxD ID of SIWVID( J7 ~, x4 `+ [+ c5 \8 I
    int     2fh6 a( W& ~. D: H5 u
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
" b! ?5 {+ @- z7 C) C  {    add     ax, di- P" C$ b) L, a" s; G5 o0 L" z
    test    ax,ax
' J# l' M" T. p! V& H4 ~    jnz     SoftICE_Detected* `4 x5 B) y' V6 S& W, r% E+ r3 m8 A' F1 X

) j( X+ D1 ?& K8 E, g( S7 ___________________________________________________________________________
: I, E* y' \/ m/ Y
8 _4 Z% o" q8 Z' N/ K6 x. x9 w7 O5 j$ [2 a3 @+ j  S) w7 w+ }  x
Method 05
0 h2 `$ H# W: ]" N7 c=========
4 k3 g9 B' Q( a; f4 ?
- ^/ E& u/ j& \# b+ |; pMethod seeking the 'magic number' 0F386h returned (in ax) by all system6 y4 N$ F: A" ]0 @( R. S
debugger. It calls the int 41h, function 4Fh.
3 N  u0 i: ?7 [6 H9 _( ]There are several alternatives.  0 B! h( `1 z# [8 B& x
! x/ W# m* Q- S, Q2 g
The following one is the simplest:( e+ _% d" S1 a9 @& W

+ O+ q- t7 n+ c    mov     ax,4fh2 C: n# b- w' w$ ?
    int     41h
' a7 K) `9 k- p0 S) \& O    cmp     ax, 0F386
, f, G$ u+ E, z! U/ F    jz      SoftICE_detected3 u/ G( H; A8 {- {; T. j! e
0 \* s, D* c* v

5 Z) w5 }: B) g8 G% W; cNext method as well as the following one are 2 examples from Stone's $ I' H& z! S5 F; @2 h( k
"stn-wid.zip" (www.cracking.net):
0 U! Y/ {! P! A' h( A/ ], z) i0 \! N3 z2 v+ q" ], R0 j. v
    mov     bx, cs
: q. n6 y- p0 h) Z    lea     dx, int41handler2
4 j% J6 _9 D9 D8 p- B3 \    xchg    dx, es:[41h*4]
6 O" q; ]# |- m    xchg    bx, es:[41h*4+2]
  D" u1 a: F: n' w5 _$ z( K    mov     ax,4fh
& x/ r" Y. [3 a% A; f* }    int     41h
% \2 f6 B+ h5 T- `    xchg    dx, es:[41h*4]
  K$ R& r3 M, j* V4 q6 G    xchg    bx, es:[41h*4+2]
# A( M9 G! j: t, y# r& p    cmp     ax, 0f386h
/ Y" A4 ~9 p3 f2 R4 ^0 Y    jz      SoftICE_detected* ]' J3 p, N$ s- r
% y. {4 {# L3 F$ O. m$ z
int41handler2 PROC
. z' {& I7 N5 o+ R& ?+ N    iret
  w* P1 g+ H+ \4 n/ C1 c6 L/ ~int41handler2 ENDP+ y5 Q! d" X4 ?% N$ O3 o

' M; N% F! Y5 Q  C% g6 ~3 N; Q4 y/ @3 b, f4 b' U  ~
_________________________________________________________________________% |( R) [& D8 P# I0 D) \
  ^% b$ |# Q1 T* F# ]% u* f. K
' s6 E) z# \9 n
Method 063 O1 s( ]( d5 d2 K6 E9 f; Z
=========
- H8 }0 u+ p# `8 r: a4 @! |  o) C' z1 h$ w* J1 k/ ~9 }

! J! x% |2 t) j  n, u2nd method similar to the preceding one but more difficult to detect:8 t  [4 g  j4 ], S7 f% a
2 @$ _' E& L8 b& o, C7 b# M, ?

# p, @$ T5 h( R2 mint41handler PROC; z5 A2 v7 y6 i( \/ v5 l7 {
    mov     cl,al
. Q) j9 T/ ~) R0 O' g  M    iret
; d+ f& Y- m( ?; z' `* @  Iint41handler ENDP/ K4 D: I( x+ }6 n
+ B) \) G1 Y8 T# X7 _- B

+ s+ W+ x9 M+ Q& B1 f# ^  b    xor     ax,ax2 _* L9 I: s  L5 O- R
    mov     es,ax
0 H: Z* v8 V  l! x0 @  E0 b  m% i& k    mov     bx, cs! P7 S' q, u5 G5 x# _4 v
    lea     dx, int41handler
# `# G, g+ Y) s8 b, I2 F+ l( Z    xchg    dx, es:[41h*4]
4 a8 s; v* z( \  s6 I: L: P# L    xchg    bx, es:[41h*4+2]
# f, D3 @) N5 J    in      al, 40h4 X( |% @4 `1 X& _& q( E
    xor     cx,cx
$ a5 S% w% y: T* b- n    int     41h
  V) v- L3 t. n; `, `    xchg    dx, es:[41h*4]
2 k) n+ D5 ~, w" K3 O    xchg    bx, es:[41h*4+2]
: m$ Z8 |, o: z' k/ [6 ?    cmp     cl,al2 @# i' x* m; N! ^$ v1 y
    jnz     SoftICE_detected% }3 ?6 X/ c4 L4 D0 \+ l

/ u. Q6 S7 u2 Y, f# X3 G) o$ O_________________________________________________________________________
) l; c0 r# ]1 Z( q; T. G& f; R! R5 j
1 K5 N' _2 Y+ i: I/ [1 WMethod 07, T/ }; V# i& R
=========
: ?+ K% ~2 `+ {/ @( Q0 _) Y4 Y) C
5 a9 x% B* K* f- j$ p3 W+ n1 W) ZMethod of detection of the WinICE handler in the int68h (V86)3 Z7 \2 t: S/ P
& B: l& ?; e7 m: J1 `
    mov     ah,43h, {* x+ q0 w" D+ Q# _5 \
    int     68h
. X' T; c- w7 Q7 Q; F3 K    cmp     ax,0F386h
" O( j% h9 u" u% @8 c* Z( [    jz      SoftICE_Detected# A( p) s& i9 P
' F1 M+ n. G+ _+ W
# a+ q; p$ Z& ]
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit. y% B4 Y/ H+ s6 z, f3 M9 l
   app like this:
7 \0 P8 I% z: I# H8 j* @+ z/ O4 ?3 j( F; W9 `
   BPX exec_int if ax==68
9 R9 @3 a2 l! Y   (function called is located at byte ptr [ebp+1Dh] and client eip is! U/ V  Y; F5 |. b) P. g/ D
   located at [ebp+48h] for 32Bit apps)+ M4 y' ^: l* t9 |5 F" ?& g6 J( f5 D
__________________________________________________________________________
9 V! L$ }' a, ^5 x# s3 S, t' w2 S- v! l- Y, _
; H( Z' {; S, s/ D: K
Method 08
, z' d& V- u; y4 y2 d7 V5 T=========
' b6 z# y0 M9 g3 n' ?4 @- W8 ?* f8 `8 }/ }, i( E9 Y1 y% G7 x/ o6 \0 o# G
It is not a method of detection of SoftICE but a possibility to crash the
6 }8 l& J, p+ |5 I$ \1 u/ ^$ msystem by intercepting int 01h and int 03h and redirecting them to another
( B- Z4 g+ K$ s* u9 rroutine.9 ?" E0 O" ~! N2 o+ z
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
# Y2 f+ O0 W* \) ?to the new routine to execute (hangs computer...)
* H! e4 q: e( V
4 c* u6 N5 o& o8 F    mov     ah, 25h3 C; `& \" Q9 g: }+ M
    mov     al, Int_Number (01h or 03h)* n5 E8 u+ g0 J) c- O; z
    mov     dx, offset New_Int_Routine
! @# V/ V$ J0 x- X    int     21h
. |" E; `( u3 p0 {8 h+ F7 p
6 q5 {* W: N. }8 G$ X__________________________________________________________________________
) z. U/ s& e6 n' k. F$ n0 Q) e+ \3 t2 j) A9 Z
Method 09
/ W0 ]! x6 ^0 o) n9 S0 t$ P=========
7 v# h9 L2 _; }. L; d: S9 n0 s0 s2 X; v& @6 L
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only1 p; p0 @8 ?- F, V( G1 @
performed in ring0 (VxD or a ring3 app using the VxdCall).+ z- Z& g2 t5 y+ x; O
The Get_DDB service is used to determine whether or not a VxD is installed7 a# i  i) Y! z4 |' m, }, X
for the specified device and returns a Device Description Block (in ecx) for
% u7 [, y0 g4 Rthat device if it is installed.$ O* Q. W, \! \  y
) D% K8 z) l! b( Y  G! M4 I0 W
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID' j4 n- g) f, ^
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
  p6 I* e4 ?1 o2 {   VMMCall Get_DDB
2 g& f5 D: a" U, I$ _, c  y: c   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
& c# s' T/ S4 V1 v. _8 s( F  g! s2 I9 A# t3 L
Note as well that you can easily detect this method with SoftICE:% k1 S/ Q" m: Z4 G8 T
   bpx Get_DDB if ax==0202 || ax==7a5fh
7 I5 H- ?! E( w! m: G. G- o3 b% \/ G1 u6 u- y; [
__________________________________________________________________________
2 T( I1 E! a1 ]7 z/ V- |% X3 k9 I
7 s/ C* u. r4 G. u+ f% K8 }Method 10
0 O6 a/ Q8 p! T3 t=========
9 \; T! i: ]# G/ Q( {5 X/ o8 ~7 i, T0 d: g
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with0 @) z" v1 v# M% S, K+ O
  SoftICE while the option is enable!!
' x* p. J. a- q
) N" ?: D, }$ D2 R2 |This trick is very efficient:
( a" x. q" _' z8 Q. kby checking the Debug Registers, you can detect if SoftICE is loaded; H* H6 k1 }' ~. V7 g' B+ T; ~' @
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if7 Q! _6 \! x) X% l
there are some memory breakpoints set (dr0 to dr3) simply by reading their
/ t2 m. Y" U! V' Yvalue (in ring0 only). Values can be manipulated and or changed as well
* d+ d! D5 N5 g8 ?2 Q4 s(clearing BPMs for instance)
: r$ Z2 r) X, F
9 Y1 E. F9 y. P. u' ~__________________________________________________________________________) L0 q/ a( }$ V. h5 v
$ T/ D: f& ?" P( [. p4 {" P
Method 11
( {9 c; f6 \6 L: G4 q=========
- K2 ^5 }3 ?1 D! N, {( J# K2 M; i2 I. d1 @' L3 \
This method is most known as 'MeltICE' because it has been freely distributed' Y* n* e0 ?: L+ @8 g2 o, H- U8 F
via www.winfiles.com. However it was first used by NuMega people to allow! n: ~7 w! T% R# g4 i
Symbol Loader to check if SoftICE was active or not (the code is located
9 X! y) b! E- L. g. q6 I% y9 N( Dinside nmtrans.dll).; _! Z. E9 U. l5 ?  [
4 h. Z  {( e/ M! s
The way it works is very simple:) i) r3 o2 [+ `9 }% I! {6 B9 T
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for9 J9 W$ ~* a1 L! x7 ?8 C% B" r4 Y
WinNT) with the CreateFileA API.' ?2 ~4 ]: M4 w, W/ ~9 Y% P

5 n3 j6 f+ [* q3 GHere is a sample (checking for 'SICE'):
- t  _" z. M3 w% J& e
, w: e. m+ R) ~+ y; D; `( IBOOL IsSoftIce95Loaded()  Y1 W6 x2 L7 |4 B
{
) j+ A2 ^8 u7 [. R   HANDLE hFile;  7 x8 X7 r% I" a# B# p$ k2 g9 D
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,; P6 G4 d' F3 _5 z  E6 M# \, S
                      FILE_SHARE_READ | FILE_SHARE_WRITE,. u  ~$ Q% j/ ?9 y* s6 e; H
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);2 g  J; t6 Y2 o* L5 N' j. W
   if( hFile != INVALID_HANDLE_VALUE )
- V' M4 _8 x- p* p   {% y0 U/ X8 c3 i- l
      CloseHandle(hFile);
; Y$ u6 s5 m9 v$ U' r0 C" g      return TRUE;7 A* Y6 k' E8 b* s
   }
( c* `  D3 C9 w! w4 n8 ~6 T" o   return FALSE;
6 @* ?+ M- e0 d; F  j4 J4 z}
& q' T8 O$ l4 Z# k9 R7 ?3 e/ V& C  Z8 d
; [( T7 D5 z7 p. W1 d, QAlthough this trick calls the CreateFileA function, don't even expect to be- n; x+ v, {+ g
able to intercept it by installing a IFS hook: it will not work, no way!
4 s. W, r1 S+ {3 |' Z+ BIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
. q9 h& W7 Z0 Yservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
# {8 h" R# h( _+ A1 i3 Oand then browse the DDB list until it find the VxD and its DDB_Control_Proc
$ p% x. P$ N+ A/ e5 x( Bfield.  ^9 v4 e( F* g4 t, a
In fact, its purpose is not to load/unload VxDs but only to send a $ |; C. ?5 F4 i8 f# ^' l& o1 k; _! [
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)7 I" B  p& y, W* Y' C. k. u
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
; b4 D1 ]' [9 u9 p# Dto load/unload a non-dynamically loadable driver such as SoftICE ;-).
$ O5 i# M  x4 p' T. u' Z9 CIf the VxD is loaded, it will always clear eax and the Carry flag to allow
4 V" D7 A+ K) ^/ S- `% v9 I* Eits handle to be opened and then, will be detected.9 _3 b9 q( G* K; z( y' j) Z
You can check that simply by hooking Winice.exe control proc entry point  f4 F. I& {  X! h' \0 k
while running MeltICE.6 b2 ^! S4 N( m" C
2 t+ e2 [: I2 j& `' j3 s8 Y! R8 Z
# B5 w  \# C4 L$ ?9 R
  00401067:  push      00402025    ; \\.\SICE
% c! B' o6 Q# i  0040106C:  call      CreateFileA
% o. W) f! C8 U  Z: {5 _  00401071:  cmp       eax,-001! b. O& u- B- B
  00401074:  je        004010912 l4 t+ J; p8 b+ r) v- x2 J% ^9 S' N- B
# C1 l) X- R5 T* Q2 c

+ T0 X: ]+ w( T. gThere could be hundreds of BPX you could use to detect this trick.
! T5 a; S4 b$ P; J6 d: ~" J-The most classical one is:1 }+ ]5 n  T+ d8 [6 X
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||+ E8 m) O2 p$ n8 N) ~. D* ?2 ~
    *(esp-&gt;4+4)=='NTIC'9 G4 V  d8 ~& h/ }
% H' u8 y8 C$ H8 a5 U- t
-The most exotic ones (could be very slooooow :-(
1 A2 _- @, n3 Q5 G# U9 R   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
; ^% X3 N& D. i  T, ?     ;will break 3 times :-(: I9 C# J  |4 z" H5 N4 O

7 u5 }4 l* i* e" _4 `7 ^, _-or (a bit) faster: / W" I) I  s8 u8 \( Y+ i
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
/ o( Q* Y7 R* o5 i3 g4 n, M) h  \( f( y9 b0 h1 H# _9 I: `$ p
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  ; g* ~& E5 |! e" `# M, Z4 j
     ;will break 3 times :-(2 b2 r+ Z4 w8 z6 Z3 y

3 c( ^; m0 T( j) C2 f6 |  f-Much faster:3 J( ]0 M% r& z# s
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'( {! E: I4 @! q/ N
5 [% U/ I+ x* F% R
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
. B6 M, J- E9 j. _8 ]function to do the same job:) e  t  ]( w4 ~" s, K9 X6 \
0 b! O4 g5 `5 p2 V4 X, c
   push    00                        ; OF_READ# J0 L5 f8 @. ~9 b4 R
   mov     eax,[00656634]            ; '\\.\SICE',03 w4 @* M8 g' |/ G5 \8 z
   push    eax% H6 ]6 X6 Q$ A3 S" S& w. m; Q( z7 D- F
   call    KERNEL32!_lopen4 L. h5 Q" H! T, h7 u" _
   inc     eax
* P* ]$ V# d, s6 h4 b  W' X   jnz     00650589                  ; detected
  M: n/ z3 T7 f9 j- I0 A   push    00                        ; OF_READ
! P# @1 U6 o; l+ N2 _   mov     eax,[00656638]            ; '\\.\SICE'
/ U, M) A$ Y. i. i, ~1 n' }   push    eax
" x7 A* A" c& p4 M; @& k7 S8 ~   call    KERNEL32!_lopen0 w  A- }9 q. y& D( P
   inc     eax
$ H4 X2 w2 \  Q4 t7 M& p3 J   jz      006505ae                  ; not detected
; ^6 ^% l9 q+ g0 _. T( @. V
7 ^( S1 l  }* U' G4 a( R: J! Y7 j# c2 n) w
__________________________________________________________________________7 p$ ?+ T0 Z% M

; e4 h' e4 ?6 _0 A9 ZMethod 12
. t0 v) f1 k  A  e=========
1 F8 k. D. j/ a5 h! ], \* D* f8 {
This trick is similar to int41h/4fh Debugger installation check (code 05; O; A0 h/ v  H! W& q
&amp; 06) but very limited because it's only available for Win95/98 (not NT)9 c. X( w  p0 o, l7 A' o) h
as it uses the VxDCall backdoor. This detection was found in Bleem Demo./ k7 b4 J  A7 @* g
4 A( D/ b5 i/ y4 F! q3 Q0 b
   push  0000004fh         ; function 4fh5 F3 k& j" N9 ]) i- _% K
   push  002a002ah         ; high word specifies which VxD (VWIN32)6 S0 f$ c7 J1 n3 C' d8 n9 Y
                           ; low word specifies which service8 T  H" \+ W! Q  g# _' x
                             (VWIN32_Int41Dispatch)
. C! `7 S6 u, v/ v; t   call  Kernel32!ORD_001  ; VxdCall
$ `* q. P. ?0 L2 x   cmp   ax, 0f386h        ; magic number returned by system debuggers7 w) c; D/ p% O8 i0 i
   jz    SoftICE_detected& g5 w9 J& W2 M( [1 R1 R
- a: B) o, ~' `
Here again, several ways to detect it:& d( ]% a5 G8 q( D' {/ l9 D

4 W$ Z, `/ O; K3 O. z  C8 j7 E    BPINT 41 if ax==4f
$ L2 c9 u7 i8 f
% ?0 _2 o3 i" G6 r3 I' f& [1 ~: J    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one' M' O# ]) g1 A3 ^- {/ Z

* v' V4 r0 _/ s9 F4 l* a    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
* e( a' N0 C  W. M- t0 l
# q5 A9 M' D+ a5 Q! Q+ ]    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
6 V" d) z2 Q  a8 V  x  J2 p$ D" K7 Z6 K" ~1 L9 |8 {1 a8 }! ]: y7 H
__________________________________________________________________________
9 N! D$ Q$ X! J" N
% y! @$ Z! e2 `) x6 O7 yMethod 13
2 n" _$ j$ N; y# m=========8 ?! e* L; T' }+ y) {9 ?6 H' ~
& j8 v+ }% P- p  L4 I% G9 D
Not a real method of detection, but a good way to know if SoftICE is
: O, q8 t! R+ [9 T/ j" \installed on a computer and to locate its installation directory.' M$ v' H/ s# o) p# y0 o6 d
It is used by few softs which access the following registry keys (usually #2) :8 p6 f1 ~- n9 s% \$ M+ h  G
) e) h( Z1 E3 i- ^3 J; s1 M; _& |
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& f5 o+ T8 @6 g0 ~, u( ]0 T1 g
\Uninstall\SoftICE  K& O8 O: [; X  N0 j1 W0 q
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
9 r* L5 T8 H: K1 R" V7 M; w9 ~-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion, v; H2 y7 v& H
\App Paths\Loader32.Exe
2 n* |9 U# l9 t4 u) F$ ]
1 B2 `5 Q5 ?, _
" N$ _" ?/ F% N5 nNote that some nasty apps could then erase all files from SoftICE directory
2 h. G3 l1 l& n7 U# b3 J(I faced that once :-(
& T; `# Z* ^4 x% n1 g
# p  Q8 Z4 Z  |4 `0 _9 n$ tUseful breakpoint to detect it:
7 P0 L/ P. t; P: {+ k' Z- J/ b4 Q) f5 o' A0 L6 ?' ]
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
5 U8 y6 `- ~8 p2 K9 }$ L
, G% j2 Y8 O; i8 {__________________________________________________________________________
+ q0 |1 i2 l! Z% T2 J# r3 `! l3 ^3 Q: Z$ L' F9 X; n/ F3 d

1 C0 G. S: J8 Z  s& {, `Method 14
2 w' d: n" W2 X; e7 V1 J2 X1 c=========
' o3 a8 m6 Q5 M
- A+ d4 [, @  }. ]: q( i2 a, X& ?# {A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose2 h# w6 D% f) U0 ]" a- O' M
is to determines whether a debugger is running on your system (ring0 only).  N9 R6 S, l% c4 I( p' R+ Z; j

0 }/ X8 J& o  T3 c& N$ p8 _1 k/ @; t   VMMCall Test_Debug_Installed# G& `. s8 x! p
   je      not_installed
. H" b: L( {+ X( a$ j5 S! Y0 G3 I
This service just checks a flag.
8 G0 |4 e( r, b3 C  m/ o/ _</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部