About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>8 s; V$ g" Y( h2 S! U" Y3 z
<TBODY>
7 Q5 K- l% V) t/ ], W+ H<TR>
  M: C0 l* [7 j; O' j<TD><PRE>Method 01 2 E- Z; s, A" b8 c; _/ i( W3 x
=========
' O4 k* ]2 h7 |2 G, U3 _
2 N# \$ B" W6 f3 z" vThis method of detection of SoftICE (as well as the following one) is" t( r0 H) L! j5 j- [
used by the majority of packers/encryptors found on Internet.
/ o' u4 T, K# t) R# u- Q- ^3 ^It seeks the signature of BoundsChecker in SoftICE
% a. z& h, k5 b8 n% [: K, a
* |0 @% ^! C( }9 W' [% U; t    mov     ebp, 04243484Bh        ; 'BCHK'
3 U0 u/ B$ |  V5 a    mov     ax, 04h
, o, o5 o8 Y8 t' u    int     3       # i5 o7 o8 j( g- O) k
    cmp     al,4
& I* n/ F/ N( ?. W; r    jnz     SoftICE_Detected
0 V4 `3 G, R5 P! B; G; [% i& r; g, |9 I2 k3 f/ p& ~: Y% ^
___________________________________________________________________________) B0 a& l% A+ D& c' f

, c) R3 `# W* PMethod 02
5 x  E* Y4 I/ ~, T=========
( A3 D" D3 y$ N+ S2 p' T8 R+ y$ e! D3 J1 [. Q  s
Still a method very much used (perhaps the most frequent one).  It is used) d1 Q2 ~" B9 p# N( j. S
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
0 B6 u! H. W8 V5 h' `or execute SoftICE commands...8 \; N! V) L7 X) A5 i! w
It is also used to crash SoftICE and to force it to execute any commands/ u$ P7 j3 }  ]; I, }$ S
(HBOOT...) :-((  ; c& V# M4 d& ~. ?& B! f5 M

5 y3 B( d' |: K/ ?Here is a quick description:# P: L* v! E/ R7 O: Z
-AX = 0910h   (Display string in SIce windows)8 y3 D7 H0 ?9 P. `' {
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
! |2 z/ _4 l8 |9 ^# k! N: E9 V4 I-AX = 0912h   (Get breakpoint infos)9 P/ q1 x# C8 b7 @& ?
-AX = 0913h   (Set Sice breakpoints)2 L3 B, S( K5 G! K, a; f
-AX = 0914h   (Remove SIce breakoints)
, s, \7 _: k" z! ~, c; P- c. ~% o/ a0 ~6 Q$ f( V* ]1 {
Each time you'll meet this trick, you'll see:
" }) F6 ?2 L2 w" |+ e2 g-SI = 4647h
" D9 D; J7 Q" T! W  f-DI = 4A4Dh
2 N3 O8 M: H1 ^2 [' q) f: z# LWhich are the 'magic values' used by SoftIce.
& f! C8 M# w, ?; Q* v- Z  H9 m6 P, FFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
, H' E- b: E- r( `3 ^
. v5 \1 j% U9 |  A  E) ZHere is one example from the file "Haspinst.exe" which is the dongle HASP
. e/ v4 z; p, bEnvelope utility use to protect DOS applications:
5 R% ]. [1 ?1 C7 |7 H5 q4 Q  \$ e7 @1 ~1 [

1 k$ x5 p7 H; |) P. x, R4C19:0095   MOV    AX,0911  ; execute command.
8 A3 \( F8 M7 D/ w4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).$ Z- \" Y- T: Z( j
4C19:009A   MOV    SI,4647  ; 1st magic value.
; v6 g* ^" K' m( k4C19:009D   MOV    DI,4A4D  ; 2nd magic value.5 q! _4 i, f: c
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
% N8 v' F% O; P( `, ^& ]) e- _4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
* }# X3 Q* R  L" E1 h$ ~1 Y4C19:00A4   INC    CX
8 K9 V; x# r. g, V; d  O9 g$ c4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute' w7 F: Q% [. i+ G
4C19:00A8   JB     0095     ; 6 different commands.; J- y) ]( N* p% s5 r" p/ k% l
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
% h5 f# G" m% ~& p0 R; ?) f4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
0 b) X$ u1 E) r  R2 V# t& m1 z% o: _/ z
The program will execute 6 different SIce commands located at ds:dx, which/ j  \7 b4 p9 i
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.  e8 Z. J. T  i! z+ E) B
  f4 W$ q0 J$ ?% C4 g$ v8 m6 v* I
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.4 Y# q0 r& t" M. X$ l7 @
___________________________________________________________________________
, E; e) G9 e& a+ D/ r5 t  o! U$ I; F! D6 l: a2 y: k  }2 w

: k! I+ Y+ h# {- {0 ^, iMethod 03
3 k+ l8 `2 N4 S% d=========
2 |9 ]8 y( n: }0 [& K) i7 s% J: l: H# `* f, J
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h+ ]1 _$ [) \  ^9 q
(API Get entry point)! @" Y/ i2 {2 I% Q* j
        
8 L+ c$ f- Z/ Q5 N
. x( o2 j0 B( a) V    xor     di,di. @; @) \9 ?: E' x! Q
    mov     es,di
. E$ s. D, T4 N9 I    mov     ax, 1684h      
& K$ g2 B, M3 N: h9 y    mov     bx, 0202h       ; VxD ID of winice4 p3 W  @- E& }# Q, \6 A0 U; [
    int     2Fh3 G# _5 h4 j( _6 Y# p3 t
    mov     ax, es          ; ES:DI -&gt; VxD API entry point( p* d! C, n( ]- ~$ Q- E
    add     ax, di3 P0 ~# e+ ^: R' S
    test    ax,ax
; w% l* q3 G3 o* ?' y) E  S: ~2 E    jnz     SoftICE_Detected. V3 w. s5 s7 @3 S. t9 D
' K: `# [& L6 B- f+ P5 U
___________________________________________________________________________0 ]. W" U, [+ R3 G- V5 t( g
4 y, ]2 x, s! H  [( I
Method 04
, o1 k% w1 y6 k5 t/ r& _=========9 [% d  |" u! z
4 {" A: m7 x! Z& r
Method identical to the preceding one except that it seeks the ID of SoftICE
+ O6 S3 I& h, r9 b6 z- r/ LGFX VxD.* u, H8 {2 A3 g! i

0 X8 A" H/ ]4 k& j    xor     di,di
- c# D! \0 O) @5 b6 L! Z' r5 b. T8 i    mov     es,di
! G/ H6 |$ h! D1 ~% \4 s    mov     ax, 1684h       , T+ M$ w7 l& D' r  T/ h0 ^. `. o
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
) ]5 r! v  n6 Y3 L; f$ K, V$ E    int     2fh
0 S) z) x$ H0 n1 B* g7 E' S    mov     ax, es          ; ES:DI -&gt; VxD API entry point2 m9 @% j4 I' Q% V
    add     ax, di
* j1 o  u1 F1 S1 O    test    ax,ax( _% L* c3 y) Q1 R; w1 ^
    jnz     SoftICE_Detected  G8 {( E: l2 f0 O: f3 z$ _' m

2 A, c( }8 m- v( Y% P* @4 C__________________________________________________________________________6 l+ |1 i1 U0 M& g

5 J1 {5 ^7 ^" G1 u4 ?
+ X* ?3 @" {% v6 L8 D; v3 r5 gMethod 05
! `7 q# d, ~& w=========, d$ y8 ]9 U0 k5 [4 g9 U8 L! \

, m5 O3 u4 u7 z# I& g- I! ~: ^& C0 IMethod seeking the 'magic number' 0F386h returned (in ax) by all system
# \1 t! |* s& \3 \debugger. It calls the int 41h, function 4Fh.
' h6 H7 C, T6 k# N9 r. xThere are several alternatives.  
; J4 _; C0 }9 r/ O, @) l- R. a3 J1 _+ \. Q  F
The following one is the simplest:
3 R1 j; K6 u- \2 o$ B: H( E5 s1 k, a6 E1 B- @7 n
    mov     ax,4fh
. M( Y* U3 {: N7 n& c. A    int     41h0 A! ?; G8 r+ I" \# I
    cmp     ax, 0F386- m  d# Y, ?3 [- ^$ Y
    jz      SoftICE_detected
4 G: \: z, Q1 X5 L0 E' q4 r2 S% Z
+ X6 e/ e, O# Z: W: @  m  w7 R
8 H* i& v( B# r. K9 n- x3 uNext method as well as the following one are 2 examples from Stone's 4 B7 }. Y) d& v
"stn-wid.zip" (www.cracking.net):
. h: A) {6 {1 Q. m# j6 y4 @( @. t4 \; ^6 d8 R$ t
    mov     bx, cs
5 p* P, v/ @; y, U! @    lea     dx, int41handler2$ g. I+ n; p$ Z. k! c
    xchg    dx, es:[41h*4]5 k3 Q. V% c7 q  q0 ^$ v, _  r
    xchg    bx, es:[41h*4+2]
9 i# \# }; h  K! R  m% D    mov     ax,4fh1 \2 ~2 M& e$ x2 `. V8 g4 D7 ^+ v9 ^
    int     41h# L9 w) @) j7 }/ i: l
    xchg    dx, es:[41h*4]9 e8 n7 R+ E$ {
    xchg    bx, es:[41h*4+2]
+ R2 c) q& \& p0 J9 h    cmp     ax, 0f386h
. [' N; j- v! W$ c6 K( J! u    jz      SoftICE_detected" @! n. D  Y* a" n$ ]& W5 ^
# v& @4 T  o& D
int41handler2 PROC
) G+ z0 R2 L+ t, n4 p, _: m; v    iret
. k$ w& c+ y- I$ }int41handler2 ENDP
# k* y0 F( P) K2 `3 m- y, _; e
& v$ t( r( E8 _6 A
+ g$ f& q+ Y! ~! x1 b4 X_________________________________________________________________________
2 E% E/ s' j7 ~& O- B: F- i5 H4 q& ?! o% p; P9 \: S

9 L2 ]( h. \, `0 D4 YMethod 064 }" h2 Y. r+ z& \- N
=========
4 F# c2 v" c3 H, p
$ _; e  n9 e# Z  u) t  w. E3 T8 k# c9 ^" l) v4 Q  ^4 V
2nd method similar to the preceding one but more difficult to detect:4 ]3 m& y7 K$ @4 ~1 f/ M( Y# A, l. ^
) @( a* q- a1 P' [

3 [+ ^+ `+ B1 M# N& p% {$ Bint41handler PROC
3 X* x) V1 c$ A! w: Q    mov     cl,al
* t9 K( k8 h: u8 o% Q# \" ?8 A    iret; J  X9 I* k, |7 U! Y( {
int41handler ENDP0 p0 k, q  j; k6 ]. i2 k2 L
$ R9 j* y/ i* |  {
8 i, d% M4 o- t5 e4 z' O0 d
    xor     ax,ax
; W6 P1 g" w: k    mov     es,ax
6 B9 j" x0 d6 ?7 F7 L    mov     bx, cs5 I% K) ~$ I2 A/ z. Q  }
    lea     dx, int41handler
1 a1 h+ s2 q/ G# z7 S6 J    xchg    dx, es:[41h*4]5 k8 x, K; v) G% I9 }1 d' A2 U- {* Q
    xchg    bx, es:[41h*4+2]4 `+ n  S4 a( {! H+ q
    in      al, 40h' z) z# U) U# |1 g
    xor     cx,cx
' c% Y# o- w. j$ }    int     41h
6 d; K1 P7 X9 A) v; U6 ]    xchg    dx, es:[41h*4]
4 y* u+ W) {! ^* j# ?  e    xchg    bx, es:[41h*4+2]! Y4 J' p, y* S" Z- b
    cmp     cl,al0 K3 d5 u! B1 g# }. T8 \+ D
    jnz     SoftICE_detected
& ?% ?. j) }6 Z9 Z& f) f1 R8 y! j# ~! ~2 a! z9 V) n" C
_________________________________________________________________________& y9 g- a2 \+ h/ O! A7 D

6 L1 s3 G$ m5 x1 Q# z: zMethod 07! ?4 |; k  q+ v* N2 c
=========
+ ^! o+ q1 m1 ^9 S8 w
) q$ g) k1 g2 o. J& j2 P4 n- \Method of detection of the WinICE handler in the int68h (V86). O7 ?- G) p7 L* ]* y

% g! L4 W& V% F# s: ^9 D; h; y    mov     ah,43h
  W0 C0 v# @; h" X    int     68h; N8 u- Z' X6 {. [
    cmp     ax,0F386h
9 o" ^4 K9 T* U" C& f' a    jz      SoftICE_Detected
0 v) ?  M% ~: w/ c5 _
7 }, {$ O4 E' v8 Z5 E% r3 ^
! Y. U, L+ Y2 Y& d* Q=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
0 D$ B/ x3 g' T# M+ u9 u& @. e   app like this:$ [2 U1 C: A  E6 W6 y9 R  t
! C! G- G( j$ b7 g* B
   BPX exec_int if ax==68& r2 _6 p  x$ `$ y
   (function called is located at byte ptr [ebp+1Dh] and client eip is
! W7 t  ?, G8 n6 W$ W   located at [ebp+48h] for 32Bit apps)
; s& L3 A& z$ j, @+ X: C/ l__________________________________________________________________________. S# _- s5 u. b2 K4 m

/ i2 h6 i: O8 S0 n1 Z  S, m4 }8 c" W. j2 T' U; c
Method 08
7 n$ c) s, ?! F% T=========
3 |( i/ f* x0 Q; ^. C' |0 V/ d  p0 q5 b! S3 p( ]
It is not a method of detection of SoftICE but a possibility to crash the& l  O5 V  w% i- C: N
system by intercepting int 01h and int 03h and redirecting them to another
' f) Z9 v# U. Y; I2 _7 wroutine.
9 O4 m6 E6 Z8 m0 f& k& gIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points( z3 e% B; i  S  O7 O' L
to the new routine to execute (hangs computer...)" D) {+ u# S2 J$ H; b
: H* @# y# }% _7 Q, }4 e6 @
    mov     ah, 25h
/ ?/ p0 J1 ?9 D/ Y8 s0 C5 W    mov     al, Int_Number (01h or 03h)
; I1 j; Q+ |2 c" w8 Q' \7 K    mov     dx, offset New_Int_Routine2 T( u- F. W4 `8 Q( E( i
    int     21h
, h6 `. [+ z* Q2 x0 F0 e# s: `% ], Y
2 D; p9 t5 j$ R$ L2 t__________________________________________________________________________2 Q9 [6 S/ T* k: Z5 n

6 g. O! \5 p& |' {* Z) K! Y: xMethod 09
6 {4 L6 ?* f, V9 C=========
4 u0 N8 a1 }' u# l5 ^7 d, u: i$ d4 Y# t9 c
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
) a# i/ B1 h! j3 u) f- S) O* Gperformed in ring0 (VxD or a ring3 app using the VxdCall).
5 }/ H, K9 {+ F3 E% w& H% jThe Get_DDB service is used to determine whether or not a VxD is installed% x) h" Q. b* z
for the specified device and returns a Device Description Block (in ecx) for( k1 o% q- E/ ]( S$ [  @
that device if it is installed.* d0 V6 c/ ?4 s  p5 B& z  ]7 D! N( G

: V+ f2 D$ j8 R' k2 F; O   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID( t  T  F7 Y. q0 c
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
6 v: s5 x' D4 I/ \6 j* I   VMMCall Get_DDB$ n" Q, [" k# O. P
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed& _2 V4 R! l" y$ C
' Q. d6 |* q" r2 X4 g/ a$ K
Note as well that you can easily detect this method with SoftICE:& ?, h2 z, w( u6 K4 {3 A
   bpx Get_DDB if ax==0202 || ax==7a5fh
2 q, m- X0 B! k; ]
" V1 T/ L4 ]- `9 l% W! c' F__________________________________________________________________________
! \) J, f% f. H( c! K, }: \1 T3 x4 Q3 Y, ?# [" k1 a
Method 108 ]* B0 N2 f) r. s6 ^& q4 a' Q$ y
=========
) }9 c( [9 p( x' n7 j
9 A; F  P. e. {0 [! _% Z1 z=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with9 ^2 u  {+ ?' b0 R, U2 d
  SoftICE while the option is enable!!
2 U: }! N5 T0 J1 {" G, v8 V% L! y! A6 K
This trick is very efficient:
  B( R! \$ p) q9 Wby checking the Debug Registers, you can detect if SoftICE is loaded3 o8 t. E5 {* ^( M) u
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
' j7 ^. Q% U" L- D/ zthere are some memory breakpoints set (dr0 to dr3) simply by reading their: M5 B9 o* Q) s( l7 ~4 A
value (in ring0 only). Values can be manipulated and or changed as well
% {, c- x+ H6 Z: F4 x& q' }/ ](clearing BPMs for instance): M# G) Q/ {' G! P1 c2 y1 j6 b1 P4 L

% \$ m+ o: {; y" Y" {4 v" K__________________________________________________________________________' h0 \3 S- D; c
# d0 s4 P! @! j0 [7 g
Method 11
- Q: O2 x+ j* G) I- O  u=========
6 Y; i1 [8 w4 a* l' b1 z$ p/ S6 G: w4 w* {; a4 `' |7 m
This method is most known as 'MeltICE' because it has been freely distributed3 U9 C2 B# [+ i  \: j
via www.winfiles.com. However it was first used by NuMega people to allow1 V- S- o, a! l9 T4 S  e, J
Symbol Loader to check if SoftICE was active or not (the code is located
4 f' S. w- M7 S4 Z, D4 N) H9 g# C# S; einside nmtrans.dll).0 }$ o2 n2 u# W8 {
7 A! u1 W0 H! g
The way it works is very simple:
4 p" y8 P4 V* ^0 r" h  iIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
$ h/ O. n' C' s6 @WinNT) with the CreateFileA API.
8 y: }5 ]1 `  t% V  k; `9 m0 i  s' k( E0 Z3 ]
Here is a sample (checking for 'SICE'):$ ^$ d2 F6 X% `

; i- K" G# z1 G; i5 D+ kBOOL IsSoftIce95Loaded()
7 A1 V/ f$ M* Y{
, s* {: C6 T. k" d- u+ b$ w& f3 [+ G8 f$ K   HANDLE hFile;  ' F% u5 q5 s4 V! q1 O( D
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,% |# V5 n' {! o& w1 o
                      FILE_SHARE_READ | FILE_SHARE_WRITE,6 B+ j% k- a) J- p  ^4 G4 B4 i
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);( f; Y& O. p6 C* U% g* ]. P
   if( hFile != INVALID_HANDLE_VALUE ). r; i8 D: @& l  J
   {0 E( @; W3 X7 _/ B; N' N
      CloseHandle(hFile);
) j9 u5 Z# q2 r, e. x      return TRUE;! o+ p% g& l* y2 J! E7 c
   }
4 v$ J5 L7 h7 E% {0 d   return FALSE;
0 A+ M  V  X( A% s/ r}
. z- R. ]8 e' s7 C+ A# X7 `, B8 i' n9 ]- ^/ X# L4 C# r" l0 B1 J
Although this trick calls the CreateFileA function, don't even expect to be- X, J* k& \' E1 k/ d5 t
able to intercept it by installing a IFS hook: it will not work, no way!8 [) a8 |& U/ U6 E& W
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
- G+ d7 e4 h, M( Y& Kservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)% W+ V; L1 L3 ^4 `9 Q7 v5 L
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
8 K6 g+ @# S3 }* A- X- G% ?  h6 xfield.
7 O; P* S7 s4 z2 V  m/ u4 I: GIn fact, its purpose is not to load/unload VxDs but only to send a
" g1 v5 h! q3 f5 B/ J3 hW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)# Q  D6 x2 A9 F) U; t6 h- F' e8 i
to the VxD Control_Dispatch proc (how the hell a shareware soft could try, D% Z1 ~# _: A2 f  G$ r6 S+ }4 d
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
; a) k( s; A. W. f5 r5 GIf the VxD is loaded, it will always clear eax and the Carry flag to allow
- P4 S. A/ n9 y! K, c5 J. h8 cits handle to be opened and then, will be detected.
* Y3 Z3 H; v9 u$ MYou can check that simply by hooking Winice.exe control proc entry point, I) H# d( U" b+ e. f6 n( x/ R0 C7 T3 e% B
while running MeltICE.
* z. U: z# @) q" e1 l1 f/ _2 ^9 \2 r6 x. J! R5 g& e7 W* i

2 x& l. C- W+ o% N6 H4 ]  00401067:  push      00402025    ; \\.\SICE
9 ^* H9 P! P1 m" _$ R  0040106C:  call      CreateFileA
! M) }& g* j" k! a( J0 ]  00401071:  cmp       eax,-0011 \! x( f! P4 m' l* w
  00401074:  je        00401091
) Z1 z; B2 U. I0 i$ T' s9 U* F# O+ X! D/ D2 ~

; `$ |( ]5 S! K) N) iThere could be hundreds of BPX you could use to detect this trick.
" k: X( r3 r! A4 Z-The most classical one is:
$ ^! j: f9 w/ p/ t% x  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
( P8 q& B7 Z" H- {    *(esp-&gt;4+4)=='NTIC'
+ Z7 \3 ?" Z) f# V$ b* n( y, ^) T$ m+ d' r! I
-The most exotic ones (could be very slooooow :-(
% z% f: c' }' Z  R8 C. |; X; y   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  7 S  _4 a! J" L
     ;will break 3 times :-(4 P4 u) D" H/ M( \: n4 }6 r

& L' F. j; d$ `4 i-or (a bit) faster: % U. q6 _- \# Q, \( x+ D0 J
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
7 C# J" {' g( y1 p. L  u( D' `' P. `. k5 {! _7 B. w+ K
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
+ Y$ X. q% q. F6 j; u5 R     ;will break 3 times :-(1 v" f% U0 @1 g( i4 P( ]
7 \0 G6 k* ~. @8 M5 F* c8 h; T
-Much faster:
2 C& k0 o+ s* I0 L; ^- j: D   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
/ c3 y% v6 q$ x8 O& }  Z5 [
. `  U) P' g7 |! xNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
# G' J+ ^% Z3 ffunction to do the same job:
+ N/ ^- m3 a7 r! K; q9 F  K( z! R. R" g
   push    00                        ; OF_READ$ Z- T5 R8 j: F1 f2 {0 D
   mov     eax,[00656634]            ; '\\.\SICE',0
& C1 g. F/ A6 d# [# E4 r' `   push    eax
6 i4 v2 _6 }& p! w* t3 R) Y   call    KERNEL32!_lopen
- ~8 Y; b1 `9 p- P   inc     eax& C, b; b, P4 F# {. Y8 l
   jnz     00650589                  ; detected' \" V. a7 X; Y+ o3 i) R
   push    00                        ; OF_READ# L7 [& u6 X3 }" W. {
   mov     eax,[00656638]            ; '\\.\SICE'* `$ e9 A7 f" V: t1 K
   push    eax% G( o5 D* B' i) _, h+ p
   call    KERNEL32!_lopen
+ Z, ?5 H8 F* L, `+ N8 s' Y   inc     eax! I7 t* Y  Z# J
   jz      006505ae                  ; not detected
" Q% R  p/ k. ?; @3 S) x, A5 @% A: w0 ~
- Z8 p1 e% @% S5 p/ ~4 \
__________________________________________________________________________
* [8 q3 Z5 I% e- ?  P5 G1 E. ]8 E  \+ |  Z- k
Method 12
1 [" L( L0 b7 N. u# o=========) h# x7 ~! F4 O( B+ j
9 s! t! e( d$ \
This trick is similar to int41h/4fh Debugger installation check (code 05/ k* N0 G) |6 `* o, v7 m
&amp; 06) but very limited because it's only available for Win95/98 (not NT); z( ^7 {5 [( ]: U! F
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
  R1 @' Q6 D6 n+ h: _* d: D
4 d6 @4 a. p4 w) e   push  0000004fh         ; function 4fh
3 r! I, J4 j* Z0 N/ U   push  002a002ah         ; high word specifies which VxD (VWIN32)
1 P# D. [1 K! p                           ; low word specifies which service* w" d9 Z7 @% R! W2 a! `
                             (VWIN32_Int41Dispatch)
% `' J9 V' D$ c% P7 y- o( o   call  Kernel32!ORD_001  ; VxdCall
+ J( E1 F$ a  `  x: }, A   cmp   ax, 0f386h        ; magic number returned by system debuggers' W* \, E5 s- Z: Y, j
   jz    SoftICE_detected
) h$ A! h$ q1 g4 G  v: v" i4 o1 W3 d1 x  e$ X- {9 ^
Here again, several ways to detect it:
5 d# r, p, A$ S" f1 U7 T8 F& k! f$ i0 W( v+ E& a7 C) y
    BPINT 41 if ax==4f: Y: D' E: g4 k* T

0 y7 C. E& x2 t$ x# ^    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
* H! X4 S" p2 u, J6 m# T2 i9 t
+ C% a, }" C' B    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
* G! p3 E3 z" o# C8 }
/ n1 A6 @6 a/ ]5 G0 Z  r. \+ n+ _    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!; G  J4 K! F+ e4 U8 Y

7 o& t/ V5 g( d, m__________________________________________________________________________
& c# S0 [6 ^3 b$ r1 {% e3 g1 g- O# L" [2 w2 S' a, t; G. M- R) B$ q6 {8 l
Method 13
! M% y6 ^* J. `- T=========3 |- }* c& }, Q9 O# i
' d5 \3 T1 R# K1 e- t
Not a real method of detection, but a good way to know if SoftICE is, M! y5 @& r1 N* ^# h
installed on a computer and to locate its installation directory.
. C4 K5 N+ S" V' E: {+ eIt is used by few softs which access the following registry keys (usually #2) :# m+ X/ X, }- O1 Y2 z% h) b7 ^8 L5 a

+ G) B: n- x( e- \-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion9 T. _& k! p# Q( W1 S
\Uninstall\SoftICE
# r2 T) r+ \7 Y' J  v-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
* d7 ~3 q% I; |6 W& t-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
% F- h7 ^5 S/ k) q! E# _+ ^\App Paths\Loader32.Exe, C- t* j6 b( S' }* V4 e. q

; A, t3 S" e( ^+ Y5 Y) w/ R( e0 ?& z2 c1 ]8 {8 ~  H/ c
Note that some nasty apps could then erase all files from SoftICE directory
$ s1 O% {8 r* G' P" b5 S& f8 s(I faced that once :-(
$ |# z* E0 l: P  n- Q
" n5 x+ t2 b3 }7 V9 G' jUseful breakpoint to detect it:
  R* R( x. y6 L4 @/ o
( g6 e5 u* g, F     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
: m0 b# R9 p# R7 B3 U6 ^- x1 T) W7 m" T5 t8 U
__________________________________________________________________________3 E5 o# F8 j6 N* }) B
: {: l: [7 Y. V1 b  z! |) Q

5 a! J9 M! a9 d+ H5 R+ V; CMethod 14
9 i6 ]& V$ M7 I% p=========3 S; k3 ~$ l. Q! l0 l! a

" V2 G# Y- A. W' WA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
; g$ B5 v# X% g+ p* mis to determines whether a debugger is running on your system (ring0 only).
! z, P2 S( K: b+ S( U: t: I7 n. K$ |
   VMMCall Test_Debug_Installed
% x: f& j+ B8 o- z! A: b8 z  Q: O   je      not_installed7 T# i" S# H, `9 j

# I" I# N1 r+ g. O. yThis service just checks a flag.$ A# K" ^9 @$ _, }
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部