About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>' j# Z8 B4 f( Z3 U9 d/ _5 h
<TBODY>
, E4 v0 N3 n5 h" r; o) a& i( L# g<TR>
' y& P' g) U* u: E' x4 O, P<TD><PRE>Method 01
/ |( W7 M3 K/ M: z& O5 Q5 x5 I! `=========3 S6 x7 T, R2 R5 G7 b5 U. y! o

7 [+ t# Z) P5 A/ PThis method of detection of SoftICE (as well as the following one) is
% J$ h8 p2 ~- `$ ^used by the majority of packers/encryptors found on Internet.
( m: j- x1 A: O0 W0 k3 t( O/ `* }' \It seeks the signature of BoundsChecker in SoftICE
' C& O4 S( V7 ^0 W) v" N% @
& Q$ Y& o0 C. O' G7 O+ F1 k+ G+ n    mov     ebp, 04243484Bh        ; 'BCHK') h" q: @. r* H6 R# i
    mov     ax, 04h
$ ^- r  {% u* c- [* U$ ?, ?& u    int     3       9 C+ u- L% ?2 g- J6 l& q
    cmp     al,4
& X3 F, N6 P. D: ]6 E$ n9 q    jnz     SoftICE_Detected( D; v8 a2 L8 l- Q$ L  a) m( e
: ]0 l+ Z2 ?: q5 D5 s8 Z
___________________________________________________________________________
( i# E7 @* e" n1 r- U2 s9 T, s; T) B/ M1 F
Method 024 z* d' k. j. i: p4 f% X
=========
# t, E% }' ^/ \3 C9 m8 W$ v- Z/ T' d" f! n$ V7 x" r
Still a method very much used (perhaps the most frequent one).  It is used
0 F* V1 H. _1 `to get SoftICE 'Back Door commands' which gives infos on Breakpoints,5 F% H2 \" w* }8 w5 @8 ?/ |
or execute SoftICE commands...
0 ]" i) F7 e+ s9 F& VIt is also used to crash SoftICE and to force it to execute any commands
. A% W/ O- }" P(HBOOT...) :-((  # X' l+ E' l) |1 u5 [, r2 d

4 Z- s0 q. f2 v) u# v& _Here is a quick description:- |+ f- _% ]' e. {7 J1 `7 ~0 W
-AX = 0910h   (Display string in SIce windows)( {: d1 k: C4 D: J
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx); ~3 Q+ A& U( k* }0 Z6 Q0 R& U7 M
-AX = 0912h   (Get breakpoint infos): L8 u0 p9 X, M3 L# c" e2 R! y( C$ H  v
-AX = 0913h   (Set Sice breakpoints)* z% o* O0 k! d$ \# s
-AX = 0914h   (Remove SIce breakoints)/ m8 {  Q8 t# N: _  h$ P

' A2 M. T4 I) M; X; b% d( [1 ZEach time you'll meet this trick, you'll see:4 G$ V4 z  R7 B0 s  h5 c0 {8 k
-SI = 4647h+ y# l. w7 {, j9 w0 q: R
-DI = 4A4Dh% c9 \  Z7 \2 R. v' e
Which are the 'magic values' used by SoftIce.
+ z6 b  g1 y( Z+ J4 @For more informations, see "Ralf Brown Interrupt list" chapter int 03h.* k$ B  q) l. W# J/ s% z1 F
$ ^$ P7 m7 \7 b6 O7 \
Here is one example from the file "Haspinst.exe" which is the dongle HASP9 W: d* m, ?" S5 _( F2 y5 M7 C
Envelope utility use to protect DOS applications:! f8 O3 K$ O+ K; ~
5 ?5 P9 i' L) |. U. n7 V$ B& J% L

, C5 w9 V  x2 b4C19:0095   MOV    AX,0911  ; execute command.
* @8 _& V. _2 ?. M: I4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).- v, b% D+ l8 `
4C19:009A   MOV    SI,4647  ; 1st magic value.# ?9 c; }; p% m, T
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
# o6 r: a! k/ w: V4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)6 p0 K$ N2 t. S: W' R' {% D; x
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
. U7 }% G+ Q7 ]: f" m4C19:00A4   INC    CX
  [& s3 P! c9 D% j- s4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
5 \% g) @" _3 M; X4C19:00A8   JB     0095     ; 6 different commands.
9 j# `2 }$ w* p1 j+ `4C19:00AA   JMP    0002     ; Bad_Guy jmp back.0 J9 \7 i) j: F! P5 `2 i8 I
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
9 D& \+ j) Y" j, S3 s, J& l$ d6 T/ i6 o
The program will execute 6 different SIce commands located at ds:dx, which' o; R# r9 c, }# e3 d
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.+ G* d+ ^9 G% Y$ o2 H. {
( y& Z" a& G  D: `/ ^" w
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
$ o/ H- k1 M" u) B___________________________________________________________________________' u* V+ g$ P' I! j# g, m
& y4 b4 i! x6 |# c/ |

4 P. U  z9 q) jMethod 03- N( k$ U8 Q' S- K/ [
=========6 t" W  r+ c9 J) S

* c* f( M( `* G) [! S8 s% Y3 }% jLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h' v" q$ i" ^; q; k
(API Get entry point)
3 b6 e2 E0 y! q5 S/ p        
* ]$ E1 f! `7 _: W; z) h% W7 X2 t/ ?1 q2 g+ s1 k
    xor     di,di
# F4 j0 m* ^( V- k+ m    mov     es,di" q/ h" l  y% _6 R- u
    mov     ax, 1684h      
; k4 V) b( Z; R1 F    mov     bx, 0202h       ; VxD ID of winice% S8 w$ S, J2 C0 P% u3 `' D
    int     2Fh
/ F$ V, U/ j0 U! r    mov     ax, es          ; ES:DI -&gt; VxD API entry point6 D# S/ }( ~. ?& R4 G( [2 Z
    add     ax, di5 U$ r0 I, d) E/ ~7 ]
    test    ax,ax( U! G" a" t0 P1 z1 V9 P
    jnz     SoftICE_Detected0 K. L! Z+ Q+ |4 O1 ?1 [, [
; \& F* e* o4 a2 L) v4 w& N: m3 e  ]
___________________________________________________________________________" \) ~2 Y9 s' v3 e
& P7 a8 h/ @' q' e" H
Method 04( @0 J5 [, F% J: o
=========
. t, Y0 r" s# M4 J; Q1 H: m) @6 ?  |& O$ l6 ^1 g
Method identical to the preceding one except that it seeks the ID of SoftICE
" d9 A# L8 p; ^, }/ ]GFX VxD.
* i$ P0 q0 ~7 Z8 L; V
% [0 z! _2 j2 S( T* C+ ^    xor     di,di. u7 ~( t' L# ?' v
    mov     es,di
% i# @5 \' s" s, Z! k) [- Z0 E: z    mov     ax, 1684h      
, g# t  j0 l$ r/ L0 M! T    mov     bx, 7a5Fh       ; VxD ID of SIWVID
. [4 F" _/ u. ^6 K# J    int     2fh
9 I  G* W$ s& p+ I' K5 ^- G    mov     ax, es          ; ES:DI -&gt; VxD API entry point
1 O; c6 }% I# V. T' ]% h    add     ax, di
6 N2 M! B) U& p7 V    test    ax,ax( G# e4 q3 i* a# H  E
    jnz     SoftICE_Detected7 G, _( G5 i8 }) d4 I
; p. l7 g) L" Y3 [
__________________________________________________________________________
, h' S2 x+ j! Q5 f% K$ ~/ ]
) ]" x9 m+ Z. z+ A, u$ `2 J+ w' Q, w2 v* V* H9 ]* L* X
Method 05
( m; I+ {+ |! x" n=========
0 ]0 ?" E2 D2 u. L. Y4 R+ H  d: f2 m  y7 y
Method seeking the 'magic number' 0F386h returned (in ax) by all system
5 F3 j3 i* B( |  qdebugger. It calls the int 41h, function 4Fh.; g8 S5 j$ |) g4 ~
There are several alternatives.  ; M0 ~+ g- g0 o- S

# b+ q9 N' J7 i2 F7 c6 j7 \The following one is the simplest:2 x( R  t. v5 l6 o9 k6 a6 f
! E- J# \% b1 @
    mov     ax,4fh4 N# t& ?2 R- H9 a! s3 P4 F
    int     41h0 E: d) e8 b8 L% A: x
    cmp     ax, 0F386
6 e" p! f$ o4 v    jz      SoftICE_detected1 V4 M2 y4 `5 K! t  F
( |/ L6 w6 {- ], X  y; p
, D+ k3 \/ W1 x" Z% d
Next method as well as the following one are 2 examples from Stone's : k( b' B& W! K' L9 s
"stn-wid.zip" (www.cracking.net):: ]6 G+ w3 n( i# `' C1 T
& B7 x# z7 h  T5 T/ d" F
    mov     bx, cs
( V1 B& s; H+ M1 X    lea     dx, int41handler2
: w$ G" ^  q( A    xchg    dx, es:[41h*4]; {* I7 d# R8 ^, `  j3 L, l4 C. S
    xchg    bx, es:[41h*4+2]& x5 ]$ x5 U8 a2 Z9 [
    mov     ax,4fh8 k* p4 c3 i! v7 B, ~$ h
    int     41h' Y0 U$ l8 l/ e" c
    xchg    dx, es:[41h*4]
1 J5 `' s) W& _% A1 V- h7 w    xchg    bx, es:[41h*4+2]9 `0 w$ m$ f' }; J" |7 y+ K! L
    cmp     ax, 0f386h4 A# }0 ~' _  [* I. J( e5 }  i
    jz      SoftICE_detected: [; I( L' U/ V4 ?& P+ W

% B" J4 j9 T) }6 O" k8 p% K& G4 S0 J+ Uint41handler2 PROC! K; X# \- |+ t  W( p
    iret/ @7 }# ~% N8 a: T+ N' X
int41handler2 ENDP
4 k1 K' z+ S+ Y4 d( y" C" P2 ?
1 P/ K3 y  z* {( s' u
2 R& z# f% j" Y, p# L! N$ Y_________________________________________________________________________
4 o7 T! |9 Q: H% c+ S. I! V4 {9 s" Z

/ I& D: J% H7 A2 HMethod 06; T  W# k3 N6 P4 p( d
=========
% r: k' z5 {' z* O
. ~: `4 h8 e/ g$ {2 L" U' V& n" l$ `3 @2 z
2nd method similar to the preceding one but more difficult to detect:
+ W3 m8 _, S) A: h" Q7 O2 Z7 U) J4 x2 a- x/ y3 d
: i! f$ j5 E+ b$ c
int41handler PROC: H; O( {% C* \2 S2 i# x8 t; E
    mov     cl,al
6 ?7 j; L7 t7 d- g1 k    iret
* L2 J1 `' E: c' B! P; s6 O6 oint41handler ENDP
1 f# X! x. |/ v  Q% F1 F2 c- S: S/ Z) X# v" E
$ i9 o5 R; ^& `% `5 R; a
    xor     ax,ax
8 k; t. _* T8 H: p3 Q8 Q3 T    mov     es,ax9 d+ _; g/ k0 i3 A0 ~& J
    mov     bx, cs. w* c: g2 J1 X: T
    lea     dx, int41handler- N; D9 Z) C. c! J
    xchg    dx, es:[41h*4]
  X% Y2 ]+ V4 H4 a    xchg    bx, es:[41h*4+2]- ~- r. X" O* O; k0 C/ u) t* G% y7 c
    in      al, 40h
+ H2 j2 P2 L) A& i4 I- A; K3 m1 f! G    xor     cx,cx: y" C# M* u9 A
    int     41h4 z8 `, Q! ]' o/ ?. A$ Y3 N$ l
    xchg    dx, es:[41h*4]* D/ Y0 d1 f" a8 I; W: Q
    xchg    bx, es:[41h*4+2]
8 c$ _) b- N$ ?3 o3 Z    cmp     cl,al+ U; y; F  Z3 B- V2 b
    jnz     SoftICE_detected2 o/ N5 N: Q( c+ ?! k7 \% J

" |( F0 p0 |; ?) F_________________________________________________________________________
; Y0 A2 @, |$ i6 o# d
4 g" H' f: O6 A. D2 Q9 fMethod 07
5 T' F: z+ z5 A7 @6 I=========. c6 a+ @2 Q5 ^
% @  {: U' h* K
Method of detection of the WinICE handler in the int68h (V86)
; `- P# ?; ^" g' G  x# J1 [  X4 D! {1 M7 R$ T
    mov     ah,43h
3 t* e* m, S/ j, Q    int     68h5 O- Y& @: z' [3 l( S5 k( C
    cmp     ax,0F386h
9 X% q' J6 ]/ L- k2 r. l    jz      SoftICE_Detected' j) [: {. E. o$ H/ m6 s5 h5 I

4 u# z9 I" b) w! Z, L
0 n' \$ s" {! M. J=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
  Z/ h$ j# A5 z1 @0 c- m   app like this:
/ q, M% E7 F0 r( z$ i3 i/ M0 L" Q& F6 n% i) @. m7 }
   BPX exec_int if ax==68
9 x* K+ e* Z/ j   (function called is located at byte ptr [ebp+1Dh] and client eip is
) J) _7 D2 F) @' p6 _/ ]+ m   located at [ebp+48h] for 32Bit apps)
1 K( }  b" U# e* x+ |! V- v; c1 }__________________________________________________________________________! C! `5 z% f# c' f% Q3 G' G$ Z

1 C7 }0 |/ |: T8 {1 M/ ~  w* D2 ^
/ a; K) a4 v% \7 NMethod 08
/ Y9 e5 E% t5 n  ^4 p" Q=========6 L3 [) a7 m: ^% r! l( K8 u
& j% u$ h5 n2 C% g9 C0 Y8 k
It is not a method of detection of SoftICE but a possibility to crash the
! e5 M% i; q+ j; C* }% G* z5 Asystem by intercepting int 01h and int 03h and redirecting them to another
4 o7 Z  Y4 X! V# yroutine.
% O9 B7 v5 S* @8 f: wIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points3 Y+ ]2 ^- o- B8 V" O
to the new routine to execute (hangs computer...)+ b3 O0 E! L, D" Q1 Y
2 m) z3 S" u% A: {/ }
    mov     ah, 25h
/ {4 V+ A% E3 Y4 A3 h: D" Q    mov     al, Int_Number (01h or 03h)
' W5 ^  v) t& }) e    mov     dx, offset New_Int_Routine2 w2 @# S6 Y/ p1 B: K
    int     21h
8 d" C- x4 h* h9 F$ p2 u/ ?2 I; `, L% _4 U
__________________________________________________________________________2 D! [3 M3 S+ J7 {2 C6 T) r( u% a+ w7 ?! l
/ d( n! m) F( ]! w. O2 A8 u2 O
Method 09
1 [$ R# M6 P" L2 X% O/ G=========
7 Q! V! k8 `: h! y" o0 v* X9 g) M1 X7 C) I5 j3 W
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
+ v! c. ^; m0 e$ B; ~performed in ring0 (VxD or a ring3 app using the VxdCall).
8 w' }/ t' W# t, j* k. z/ s# U9 f' WThe Get_DDB service is used to determine whether or not a VxD is installed: J) o& V% A2 Z1 z1 e3 ~: K
for the specified device and returns a Device Description Block (in ecx) for- J6 S" K" l! {+ ?$ q9 U
that device if it is installed.8 y6 u2 |# C; |2 P3 |% `# R9 Y
& j) w9 }% V3 M8 z
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
2 ~: `2 O' {% v& [5 @   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-): H  g; `2 q  v8 U6 k% B
   VMMCall Get_DDB% B+ Q9 P# S9 ?, y) F4 Z
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
! V7 O! l9 k' R1 X& ~4 B, m% k+ {+ I/ d3 l6 J$ q5 R+ a7 r+ R4 T5 C
Note as well that you can easily detect this method with SoftICE:
9 V$ p9 f* K& U3 j0 [" Z  r5 h9 ^% g   bpx Get_DDB if ax==0202 || ax==7a5fh
! B. l, |7 p& _# A
* B0 D- f, e: X# s5 p' w: \__________________________________________________________________________
! P+ F5 p2 l- P8 e6 ^
- H, c% p* ?( A) S  H! ^Method 10
: W. L4 A$ U5 a/ @$ i) t=========# A( k# S  m* B& r  m! i4 ?; z0 j
1 u, c7 O* A* h- b0 p2 I" Q
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with7 C8 j7 t$ J3 B1 z1 |
  SoftICE while the option is enable!!  t( l" P8 w$ l/ N

! d  C' G+ k" Z3 Z: |This trick is very efficient:. S  P# |; E- e% y4 x
by checking the Debug Registers, you can detect if SoftICE is loaded  s& l3 G' Y' _8 c6 @( z
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
! G2 E* F3 ]" c1 V8 q- ?: E9 ithere are some memory breakpoints set (dr0 to dr3) simply by reading their
, M. |* ?( \, o- i! a# d; z- ovalue (in ring0 only). Values can be manipulated and or changed as well
5 V: x& J, d' a+ c( d(clearing BPMs for instance)- x0 r" L8 j3 c
! T! Q) K- X; ~% `- C- ]2 `' i
__________________________________________________________________________( E  j! m5 ^( M% c9 M$ V
% w- R/ y! u0 G
Method 11
9 K7 _- u  M9 I' L=========' B: c, R0 ?2 z; V4 U& U2 s1 X, R# H1 z
- e' ~5 G: ~) q" T5 V, K" _0 K: m9 u
This method is most known as 'MeltICE' because it has been freely distributed
) {9 o8 N: o1 i/ ^+ X% M# _% p) mvia www.winfiles.com. However it was first used by NuMega people to allow
- ^0 b& n8 s9 @, d0 n  `Symbol Loader to check if SoftICE was active or not (the code is located
6 }% _5 o4 x- H) v6 z4 P) M$ C- i9 ]& qinside nmtrans.dll).3 U  d: x9 B, g9 H" X

( y9 s" x; M3 FThe way it works is very simple:
( ^5 g% Z- t# e& e3 `It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for* u2 E( x' B3 ^! E' C7 h" G
WinNT) with the CreateFileA API.
- s* h  u; K* \4 N# S* g; d% a4 l5 S  |  n+ \8 E7 S- Y& h! G
Here is a sample (checking for 'SICE'):
, b; ~% V8 n0 M) w5 ?/ s$ q3 W$ Q6 P) T/ }, W, E
BOOL IsSoftIce95Loaded()
0 r. w4 B) n5 a; u4 l9 H  Q- C! t{
) l! j, {2 V9 {& o3 A   HANDLE hFile;  
# Z/ {% k7 b: b6 {4 m3 N   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
3 K/ T1 W; h8 w; M+ k                      FILE_SHARE_READ | FILE_SHARE_WRITE,( d5 U2 j6 ^* J8 N! d* B
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
4 ^/ e1 a1 ]6 |1 i   if( hFile != INVALID_HANDLE_VALUE ); m! w2 y/ V$ c  G5 Y7 k. _; F
   {- W3 Y/ |! T7 `# n# _. O
      CloseHandle(hFile);" K+ I/ m0 f: W
      return TRUE;
8 h( M3 T2 R) o* d7 t4 N" X, L, f   }7 o+ a0 N. [5 P( X' H; e- K1 z! j
   return FALSE;
7 W& A- ?0 w- [5 R, P}1 y$ m; e& B1 {: }# R
. S) n0 f: Q3 G' I! U0 j' f
Although this trick calls the CreateFileA function, don't even expect to be) T9 O8 c0 Q5 T; [  H% }. d5 v
able to intercept it by installing a IFS hook: it will not work, no way!9 i# e2 D1 K0 Y
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
0 l( M' B# X5 O! o# l; Tservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
, n( c2 j, y) l6 ~9 iand then browse the DDB list until it find the VxD and its DDB_Control_Proc
: `% D6 A* a& @2 tfield.
( O/ s: g% t% ?: g% cIn fact, its purpose is not to load/unload VxDs but only to send a 7 C9 f- {. ?  F) D2 I* W
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE), \; ~/ u- V1 ~9 M7 Q, k
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
/ e/ L/ l. X+ w" v" ?5 vto load/unload a non-dynamically loadable driver such as SoftICE ;-).
/ K+ D2 N3 {" v- U. H  Z8 dIf the VxD is loaded, it will always clear eax and the Carry flag to allow
0 o9 p* |- K# j9 G/ t3 u+ H; ^" z) yits handle to be opened and then, will be detected.5 H. a3 n' |" g4 `; V% s7 L0 d
You can check that simply by hooking Winice.exe control proc entry point+ _4 e1 t. _0 A3 f3 F4 L! [
while running MeltICE.
8 b- z+ y. X/ v0 V" b* e1 M2 p7 N5 d
: S) _9 e2 B7 H, Z+ _$ v* P9 `
" @/ a+ `: }. v  00401067:  push      00402025    ; \\.\SICE
1 G/ J2 |( r: t- }; B; @0 C  0040106C:  call      CreateFileA; z  p, M# R. ~- j2 \
  00401071:  cmp       eax,-001
3 m3 K3 }5 z9 ~; I1 D/ b. R5 Q2 M  00401074:  je        00401091
) c8 ~1 I3 P8 ~+ A8 B; N. I6 c% q8 \
* T$ a' l5 w" p( A
There could be hundreds of BPX you could use to detect this trick.
6 W# p, }" |) v7 {4 v3 @-The most classical one is:" a9 x+ k/ y1 i- c: Z4 \. m8 S
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||8 Q' g: v6 l) j( J$ f- q- Y3 P
    *(esp-&gt;4+4)=='NTIC'
8 |& |( c; ]; `3 X) i- ~! g, r: W: a; [: p- _# ~+ M
-The most exotic ones (could be very slooooow :-(
/ \6 Z9 i. A8 |5 b7 q) z   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
& f, l; o" d0 p5 B' ]0 G     ;will break 3 times :-(: h+ \0 Y, A/ h7 ~* ]% `; H- u
* f4 {' Z) i) C* A: [2 _' ^( M
-or (a bit) faster:
9 T4 r$ ~4 q% t) J9 B8 P0 H   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
( u6 w# z9 i2 {; R( N# \1 ~5 Y
2 [1 K+ q1 O: l* K   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
' P! E; b' E1 s' a$ U, g; ~     ;will break 3 times :-(
9 U! Q5 z- q) U' {3 m. A' o0 v0 U1 n( }, M0 k) s
-Much faster:
7 [* \. m4 y- |. h   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'- W5 o7 _6 Z3 p. O9 @6 C
- ~: t' G; T( X% r8 }# D
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
# K7 M) i# F, Zfunction to do the same job:
" }3 m, C8 s, n7 R, D  N
/ k% ]+ o# i/ v7 b- t# `   push    00                        ; OF_READ$ u4 @' _8 B3 B! s, c) P
   mov     eax,[00656634]            ; '\\.\SICE',0
' z5 e- g9 J/ j% W   push    eax$ N' o6 O: E7 M4 @, |& ]
   call    KERNEL32!_lopen
$ z6 l' \( S1 C5 k   inc     eax
( G; t/ i" N! |5 O! ^% w" v   jnz     00650589                  ; detected
  ?7 v+ T2 H0 ~0 S; w) a0 w   push    00                        ; OF_READ; L% p1 q8 F' P  J; L3 F9 P5 X! X4 g4 p
   mov     eax,[00656638]            ; '\\.\SICE'+ m; A7 ]/ F9 R3 _2 j2 d" R
   push    eax5 O8 O8 {$ @3 V/ k( q
   call    KERNEL32!_lopen
+ n) F. z& u0 G8 T/ M9 N   inc     eax
# \; j3 a: L8 r' K- `   jz      006505ae                  ; not detected
8 c' t/ |4 l3 [  H
5 j" O$ k/ r4 f) N
# G: Q' k( {& ~+ o* J__________________________________________________________________________
; H& p) x4 S& a, [: N  K! l! z% {9 s, p7 K* J" ]
Method 12
. L, w# P* q3 b2 X0 r0 C0 q5 }4 m=========/ g- a4 y& V( ?. A! K

2 G2 ?& u0 z. ]' B  |/ jThis trick is similar to int41h/4fh Debugger installation check (code 05: i3 ^6 i3 L$ h# }& h) E: [1 l
&amp; 06) but very limited because it's only available for Win95/98 (not NT)' ], D4 o9 E  ~/ X5 R+ `. I4 I7 ~; {3 L' z
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
$ L3 ^/ v2 H; b" w4 W+ @8 ?8 \' ?- f7 k* j' Z) Z# s; \5 k
   push  0000004fh         ; function 4fh5 `- N  a" W& N8 x  z; b9 M
   push  002a002ah         ; high word specifies which VxD (VWIN32)8 H4 `" v9 f* o( S5 H8 e
                           ; low word specifies which service  O, t3 U1 j! S8 a  t" Y
                             (VWIN32_Int41Dispatch): u* U( t# a4 l. i: i8 F
   call  Kernel32!ORD_001  ; VxdCall) T$ c9 N/ k6 X9 Q2 o! M
   cmp   ax, 0f386h        ; magic number returned by system debuggers$ j* ~' ^" T( I! V. f3 {( M
   jz    SoftICE_detected/ O% j: v. Y, \0 Q
2 N$ s0 L3 H7 m4 o( Y% i4 O
Here again, several ways to detect it:
3 Z8 |. j3 d; O) H! }4 T- A3 N* U4 F* m. |
    BPINT 41 if ax==4f4 H; r6 e& O/ x: O7 D4 t, y

2 P; a! B* \9 }% r) b2 S    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one2 n" w- O3 J9 J5 r! G

' \8 g+ ~( ]4 H  `9 Y1 W/ E    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A% ^; I! x- ^/ S; b% A
( n- Q0 {+ N: r' J  N7 N4 K4 d3 y! O
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
5 z$ w, o" x8 k! r% t
" s- [0 P" F% j6 F$ f__________________________________________________________________________9 Q$ v8 U+ ^) [8 }- Z. q7 G  b* K
' i6 R, C! J7 N+ U# T  [
Method 13
" e- D# v+ [" d7 G9 W! b=========
' }" `4 R( [: [+ M, r% n. S" l0 D; k1 S
Not a real method of detection, but a good way to know if SoftICE is
. J& v0 a' V; n& V8 Q" X# K( V! ninstalled on a computer and to locate its installation directory.* [$ h' g8 u: F& e) ^0 H* x+ |
It is used by few softs which access the following registry keys (usually #2) :
, }/ r/ u1 c. [# e' ^# F8 Z* X' g0 k
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( e+ [$ H) Y6 q, Y  c8 c7 M" ^- s
\Uninstall\SoftICE
2 u0 y0 f0 I6 ]" |1 ]: ~" ^-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE7 i3 n% c1 b% F7 u, I+ b
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
7 G& ]# W5 b# H8 Z4 J' ?\App Paths\Loader32.Exe
3 N0 O7 f8 q! R) `5 Y- Y$ f% U; F+ x5 k0 l

% f" i; t8 F- ]8 n+ Z( ?5 GNote that some nasty apps could then erase all files from SoftICE directory; n; k4 H0 d6 I3 F! z5 p0 A, x
(I faced that once :-(
+ d  q7 p, N* B
9 ?; p  L  x" j' f' dUseful breakpoint to detect it:7 z, _2 o3 y) m; d$ A$ m
( e# B) ?8 l7 P3 l; o- M) C
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
$ U( G) F9 Z: f+ a/ E- R* J: }& M5 b0 X' o6 H2 _3 `8 C
__________________________________________________________________________
4 w" i% j7 Z5 c
8 u5 Z( E1 X; x+ Y
0 y* T. q! S) F/ WMethod 14
. A7 @; A3 u2 c- y* I) G* a" p=========( S9 X  x6 a* u! t3 K9 G
9 I; |) F: x# Z  j- V
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose, Q* X3 ~* _4 ~) s. e8 t& b
is to determines whether a debugger is running on your system (ring0 only).4 Q" _6 l) Z3 _: w% Z2 E8 X

$ _4 p2 P& ^) S3 g   VMMCall Test_Debug_Installed
8 x' Z3 I, V9 [' z$ A/ b   je      not_installed
3 r" p3 Y& `" `( d/ r8 E9 m1 t+ o6 n# n& _) @' W: l4 s! e
This service just checks a flag.3 }+ ]. M' C  I6 E3 g, k2 V" r' f
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部