About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>( W9 U$ o. b/ \" A/ c
<TBODY>9 i# U* f) s0 d) m
<TR>% U! D' n( A+ H, N* l. t- M/ }
<TD><PRE>Method 01
# Z/ _- Q1 Q2 i=========
+ ^0 x  e5 T3 l, U3 _9 |. A6 H5 y
This method of detection of SoftICE (as well as the following one) is
. X: V3 O7 ^# X! cused by the majority of packers/encryptors found on Internet.
" i  c9 |. G: \+ Q% PIt seeks the signature of BoundsChecker in SoftICE6 F) d2 O& s8 Z& e6 c3 a

; d3 @/ K( g, n# [" \    mov     ebp, 04243484Bh        ; 'BCHK'. ^9 T- ]* S* l( s
    mov     ax, 04h
! ]9 Z" i  N  J* N  F    int     3      
+ ]! D! f0 F, x/ P# q' z) A; c$ m    cmp     al,4
7 Q6 A& i/ p* u; u1 G! g. ^    jnz     SoftICE_Detected( V7 {' L$ `# @# ]

7 w7 W3 ]# c  K/ j2 [___________________________________________________________________________! j" {  R, k4 Q2 |  t3 n) }  S

3 ?& r- O6 z7 R: SMethod 021 X' @) ^1 [, }0 n& T
=========
" |; V8 ]3 u$ [8 b+ G3 A+ D' z: }3 q6 [2 o, s8 ?. d
Still a method very much used (perhaps the most frequent one).  It is used  K* f4 k- {0 F1 G0 L3 y
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,( o+ e* ]& e) _3 s8 h+ I$ F% h
or execute SoftICE commands...
& q( S' p1 v$ W# hIt is also used to crash SoftICE and to force it to execute any commands9 X& A! P9 W* V4 K1 v' p6 G
(HBOOT...) :-((  
) L- N: o2 j8 H6 T& V8 q# m% M) ?# X9 y3 L5 h$ X6 |6 ]
Here is a quick description:, O/ W$ E/ J1 y* z
-AX = 0910h   (Display string in SIce windows)
6 N0 x, z  Z+ S: v0 e  w-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)' H, g: |* z8 Z$ L  O+ Q, E
-AX = 0912h   (Get breakpoint infos)0 s/ ]2 w4 G2 C5 \0 z; l' q4 \3 a/ U
-AX = 0913h   (Set Sice breakpoints)
0 u( D- h7 w, L$ b) p-AX = 0914h   (Remove SIce breakoints)& d! y% y8 ^. w8 B9 P3 i

; t6 w- q$ ]/ n" L" D2 F, [Each time you'll meet this trick, you'll see:$ V' b: H) Q6 D0 e) h! K, C( v  g
-SI = 4647h
: F* I* w$ A4 L4 k-DI = 4A4Dh
( i- l4 z% X( R/ Z: a3 p! {Which are the 'magic values' used by SoftIce.
: c6 j9 u4 [3 L& v# oFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.5 I1 g/ m9 B4 X+ {" J2 R9 N

+ O8 t2 ~5 A4 k& t: yHere is one example from the file "Haspinst.exe" which is the dongle HASP
- [% o* r$ w: {( R- jEnvelope utility use to protect DOS applications:
2 M1 l7 L( G/ N7 [; X  ^
& e; P# ]& g* T: f) I/ z
; K. `* E0 s6 t) L8 {; k$ R3 b4C19:0095   MOV    AX,0911  ; execute command.6 S9 N+ K$ z9 i- U$ R9 Q" m
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
* ?2 ^$ F' u9 k( k7 H2 l- Y9 @2 J4C19:009A   MOV    SI,4647  ; 1st magic value.
% u* ]( M5 M. G( ]- ^% A4C19:009D   MOV    DI,4A4D  ; 2nd magic value.1 o3 y6 l) B8 ?0 h
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)9 A+ X7 p9 r+ B( a: K# \
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
" B; n" {' T% `' b" b4C19:00A4   INC    CX1 M: O  |* Q$ h1 b6 i" w; y
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute0 O7 w$ a7 Q; R. p. N/ z* d
4C19:00A8   JB     0095     ; 6 different commands.
( C3 }4 k' M& A- R4C19:00AA   JMP    0002     ; Bad_Guy jmp back.5 c/ C5 h. E% A+ l: y3 N
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
5 E) x3 Z/ }$ M# R7 s
. A; N4 g; Z& i# }1 E6 N% A3 \8 DThe program will execute 6 different SIce commands located at ds:dx, which' t" M" d7 V# i) g
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
/ V3 A8 B* y( G  o  A' q" [% Y/ P+ C$ q2 j
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.$ l: z  A+ D, f6 {
___________________________________________________________________________
' I# b! a" [0 Q' q/ ]8 K$ A# W( z9 ~( _
# e* L" N$ c: w% g
# G" L+ H5 N8 u/ \Method 03
0 l1 S. _) L# F* s; _! u; h=========
! @4 R; j/ L4 Y4 a3 O/ B4 Q% Y+ `3 `* R9 e4 A
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
% H; _# S# `" E% ]  u(API Get entry point)
, m- m: w% w8 I3 ~$ p        ; W' w9 t4 M& A6 ~/ m

+ s6 B' A& C2 C4 b    xor     di,di
+ q5 l4 e6 O1 I4 y  s' t    mov     es,di( k" V0 z" h2 o$ \" I
    mov     ax, 1684h      
) z( T+ F5 b- t1 R    mov     bx, 0202h       ; VxD ID of winice5 N  I3 |( \/ h" {# @" m
    int     2Fh8 a& T7 I' K5 I/ f, J
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
- ?0 ?" {$ |% N, W    add     ax, di. f- d5 i* |( I& U' [+ ]
    test    ax,ax2 _* D$ B2 _1 l- Q% H1 ?9 ?! p
    jnz     SoftICE_Detected% z+ n7 q, x1 q( w# Z! j4 Q+ _

3 L6 {0 X6 @' G___________________________________________________________________________
& Q; G& c! d+ H! O, n
/ f; p9 P8 o9 m, h+ nMethod 04
6 A8 e: E4 _2 r6 v0 j=========
/ v1 d% q9 w6 u/ v* |) Y2 @. f% f% l% [
Method identical to the preceding one except that it seeks the ID of SoftICE2 z/ ?7 O; i) G! y$ a' ]
GFX VxD., k- \8 [9 m' u2 e$ o
9 u# u0 ~7 ^! C, g! u- E0 E
    xor     di,di/ g/ V- O. e& n/ S% @
    mov     es,di" G* ?& q" @2 L$ i3 x  A
    mov     ax, 1684h         r; Q% H% t2 h2 m* z
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
$ @$ t) x0 o9 l, |# L    int     2fh& d3 @  x2 v( [
    mov     ax, es          ; ES:DI -&gt; VxD API entry point6 o4 k$ K4 H1 \4 z
    add     ax, di  G% p5 K# i+ `, G
    test    ax,ax
5 |0 q% |; i; d# x0 c    jnz     SoftICE_Detected! v2 u+ X6 g6 A: C  X1 o/ d
- N$ v4 c5 o, c3 }5 [' _8 p& F8 W
__________________________________________________________________________
8 o- c# c5 B1 v/ f! \. s* o8 ?( ~: ^' D
2 Q0 g3 P) Q2 b. P, \8 f1 ~8 _. Y4 m2 w* Q$ ]
Method 05
6 N  c+ B" O3 o8 ?) B& ]$ D6 U=========
) L' h* }% Q) w2 w9 R; F
0 h) e! m  M: X# ?3 iMethod seeking the 'magic number' 0F386h returned (in ax) by all system
8 k; y6 y* h0 hdebugger. It calls the int 41h, function 4Fh.9 o/ C( t3 k8 x2 r4 m. m6 u
There are several alternatives.  ' z" X- [1 h" r
; w, Q" A: M8 `9 t2 H/ y
The following one is the simplest:
6 e) M7 _( ^5 R
7 s  o" m. L- x2 u, `/ Z/ d) C    mov     ax,4fh
% P: z" P) t; v4 T' g$ |  l4 O    int     41h
$ K, i* \6 s. b    cmp     ax, 0F386" E! o# d; r6 \5 {1 x( e1 V0 k  T5 o
    jz      SoftICE_detected7 f& V1 ~( e9 o- k9 O

# A9 ?+ y4 ~+ R) U1 t0 C( x% @% Z. B, @
Next method as well as the following one are 2 examples from Stone's 7 Q) r1 x' d' ]# T
"stn-wid.zip" (www.cracking.net):# a0 v6 ^, I1 g4 x7 N6 d. S# q5 O/ j  j

( R! W7 {: z, n7 s4 }    mov     bx, cs
' w+ o, n  S) d9 ]- F3 P, L    lea     dx, int41handler20 c3 Q" |. k0 O
    xchg    dx, es:[41h*4]
7 I! _, A- N* V+ p3 }5 n& Z3 L" U    xchg    bx, es:[41h*4+2]
2 ~+ V) N0 e' d1 L    mov     ax,4fh
. ?( \4 x4 L9 X3 h) }    int     41h
9 Z  k6 k( {4 @9 ~- Y' Y    xchg    dx, es:[41h*4]
3 \* a5 S- h0 `" A6 c    xchg    bx, es:[41h*4+2]" X. C2 G# Z0 b7 D( Z
    cmp     ax, 0f386h) [8 c6 w+ P1 u( F$ o
    jz      SoftICE_detected! ?" H: H5 ?4 c1 @

' }- g2 v  L: D" w! C+ B9 Y' @+ i: n5 jint41handler2 PROC
3 v! ~8 c, d2 T/ k" U    iret
6 u  a. X0 `) L: r* [5 t/ U3 aint41handler2 ENDP
( @* j% x1 M- m" \: S  X  f2 @0 q3 v

; M* b5 B# q1 w7 n" e3 o5 N' G_________________________________________________________________________- O& r3 B' `! b4 w- W; y! `

2 @& O$ c) S$ Y1 X1 `& U$ E7 @3 t4 G) W/ a
Method 06
6 a0 {" n# i* J0 W* Z9 v( A0 t) T" G; E=========1 V$ X4 R/ q6 m( n$ V, S2 i) l

, x& P. [  f# O
4 y1 e  A9 p5 V, K8 p2nd method similar to the preceding one but more difficult to detect:. [& N  E" P  W3 a. ]

8 F+ I8 O# T3 `: c# O2 R% q
( c" p4 u; a. I4 f* ?4 z( U' m9 Uint41handler PROC* D  J' @9 V! U7 A" O; M. V
    mov     cl,al; h4 P: a6 N2 [( E, M4 X
    iret& Z( W  k/ G9 ]5 k2 H: u
int41handler ENDP! z; m1 y/ S1 I1 v4 {- ?8 [

( S$ z, a/ \1 @* ?# Y) r2 O, H% d1 p$ b/ P
    xor     ax,ax5 b+ ]0 J; w/ u7 c3 ]
    mov     es,ax
6 a" u9 M  U: t* x( j& i) t+ C  r    mov     bx, cs+ k0 y8 T, y3 _% v! `) l  M
    lea     dx, int41handler( J1 f6 s4 W) g' J( {( }0 j& v, W# f+ p
    xchg    dx, es:[41h*4]6 i5 U! s0 n% y, a1 y6 k# o/ Q
    xchg    bx, es:[41h*4+2]
0 |& x; Z/ ?  p' m; `7 t. p/ l    in      al, 40h" x9 P$ N1 a/ c% k9 A/ m8 R
    xor     cx,cx, e! A" w5 r7 ]
    int     41h/ O2 N% D+ J, Q6 Q
    xchg    dx, es:[41h*4]
* R, k3 s, [& e& h% k, C- l# g    xchg    bx, es:[41h*4+2]/ N* R4 f) i' }1 r9 d5 H+ l
    cmp     cl,al
5 I; p! j4 G6 N+ I; N6 I    jnz     SoftICE_detected
$ m' c, ^+ P* J2 i/ o$ N: R
2 \3 j. L" K2 z5 h: @_________________________________________________________________________
2 ?+ B! \9 h+ M4 _! Z% \' r
. E8 B3 B  U0 O" T% x! ]Method 07; I% [$ `" ^/ v% v5 S
=========
/ A1 R( s: F4 @$ `/ I* s
7 k2 E% \1 f7 b( E5 x$ Z4 G' X6 a4 Y: fMethod of detection of the WinICE handler in the int68h (V86)
6 j; s0 a/ m7 J. O  _" v+ @& K- [- M5 c9 R! ]& J/ A
    mov     ah,43h( @  m. B+ h# @: F! t$ X9 r4 J* G
    int     68h
) t, v  y( W/ [# y    cmp     ax,0F386h
# j: w3 {1 V8 o. N    jz      SoftICE_Detected& S; _0 t) I" y, n+ R8 m! q' A1 ^

% P9 n# l, Y1 _* B3 P7 w  K" n8 y
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
- |7 N3 m0 N8 {0 Z   app like this:2 M0 C* ^: n* i

: l/ m2 y( K2 e6 f8 r   BPX exec_int if ax==68
; E; i3 c1 b! X   (function called is located at byte ptr [ebp+1Dh] and client eip is; v! @" E5 Y$ G
   located at [ebp+48h] for 32Bit apps)
. ?7 l1 d- h: U% }& [__________________________________________________________________________: V; [# P5 e6 O  L% @
7 B1 K4 G3 l. N8 n( \& E
& U; [/ U0 ~' |- s
Method 082 z9 J$ P4 ^# c: _7 k: I2 {
=========( a' V, ]3 K7 Z' t$ K, f
$ ~8 F5 R/ E) z% M
It is not a method of detection of SoftICE but a possibility to crash the9 f7 L9 o3 g! ]9 I; ?2 ], A
system by intercepting int 01h and int 03h and redirecting them to another
) P; M: d) B4 Y7 aroutine.1 X, D5 G0 l) Y7 S+ z; e8 j' Y
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points* h/ y6 C' x9 h# v
to the new routine to execute (hangs computer...)
1 j+ i+ ^, h8 h0 |- o; h- ]1 Z/ d. r* G' b- }& N0 L
    mov     ah, 25h1 C. x0 r# s, U" h" U
    mov     al, Int_Number (01h or 03h)
6 P/ k0 Z4 S# n( @, I    mov     dx, offset New_Int_Routine3 z& K* D7 i- N" j  G
    int     21h
4 w$ h% N) u- r+ q
& S# G. o1 g+ u4 s7 M( g__________________________________________________________________________
* `; [: Q( Y; R- x' L1 H. ?' f6 k1 _+ v4 o9 F7 [
Method 096 S) d% {5 O! V) E1 }" P
=========
# V9 z) c! K" k2 `3 q. C
4 K6 h. m1 [: ^$ |1 sThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only& C- b* b2 A* R8 g) P) A+ G
performed in ring0 (VxD or a ring3 app using the VxdCall).2 q- a* o8 R! g/ a$ Y! M4 Z
The Get_DDB service is used to determine whether or not a VxD is installed  W+ u; s1 }0 X% f0 d4 C7 O
for the specified device and returns a Device Description Block (in ecx) for
. U4 M8 \3 }: T: x$ d1 Y" h* P4 zthat device if it is installed.9 e! a4 P0 F" \. M  L

$ i& _5 g7 D& C/ f6 A   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID/ Q; Z: T8 _5 F3 ]+ p, C
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)2 I; M6 ]# F- K9 M: u! m- o; k! A+ x8 \" _
   VMMCall Get_DDB' s3 H7 E4 N7 y( \8 ]) G4 ?
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed9 O9 z2 W( t6 [) ]
7 t# y! O. [* c+ j# B  t
Note as well that you can easily detect this method with SoftICE:
. g7 |9 {0 L6 F9 }   bpx Get_DDB if ax==0202 || ax==7a5fh
+ F2 X) U! ]. u' n* I3 I- v# h2 y  K% ~1 U, h3 _
__________________________________________________________________________; s1 y- w9 [# X3 w7 [2 Y- @

  [! A1 e3 n+ C* Q5 @Method 10, v9 |+ t' D/ [$ b8 ~$ z' a
=========: m; |6 `% n( R* ]3 i, p
/ m+ L/ x1 n7 o9 ?- f; |
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with% b  A6 v0 I1 W6 \+ F  U1 Z( y
  SoftICE while the option is enable!!' R- Y9 X- r1 X7 n

# H$ `, }$ J6 n1 {9 K: ]3 w5 MThis trick is very efficient:
1 i5 ^2 p6 G! s) yby checking the Debug Registers, you can detect if SoftICE is loaded
# l1 d1 o; m2 U* C( q( d  i: T(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
3 J5 m, @+ ^4 ?4 g4 nthere are some memory breakpoints set (dr0 to dr3) simply by reading their
! P2 T6 m, F0 F7 \7 E7 |8 Nvalue (in ring0 only). Values can be manipulated and or changed as well' C* i) v. i' t. i" y- a# Y4 w
(clearing BPMs for instance)
/ E: A& R! u- i; N% j' X
1 a. _6 R, D5 ]0 U9 E4 p% C; G6 m__________________________________________________________________________8 u$ O$ L6 g/ _( O

/ M. v* M3 ]% n% iMethod 11# I6 }1 x% _5 M. m- L  {0 b; m/ ^
=========
3 O( f# Y" _, p. e& `, R/ c2 u1 ]2 t7 x) E) J: _' u
This method is most known as 'MeltICE' because it has been freely distributed
! j8 y# k0 l0 G4 R6 kvia www.winfiles.com. However it was first used by NuMega people to allow- z& V5 U6 y( n  O0 w
Symbol Loader to check if SoftICE was active or not (the code is located6 ^4 s- n: u" [* d1 m" s$ H0 C
inside nmtrans.dll)." ]6 P7 h8 [4 o; ]# p& F& d

6 k, F8 l8 L* C- `The way it works is very simple:3 _3 T" D3 e. W0 ?& J
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
8 }1 y0 c0 e" h& `* bWinNT) with the CreateFileA API.4 ?6 D$ i+ B2 h7 c) \2 {( \

8 a% }5 b0 t- D6 WHere is a sample (checking for 'SICE'):
' s& D$ T+ P$ _! o% f% y- |6 D5 p4 r" [
BOOL IsSoftIce95Loaded()5 s/ {6 [; G' a6 v' d0 @$ Q8 {
{  X6 p9 h' [# a2 h
   HANDLE hFile;  & G& P% t2 v8 r- s
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,9 f) ^) o" Y$ j+ U$ C3 M
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
1 u* c" _% C9 j8 c+ N- H                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);7 k4 r2 }# y: r* }8 J
   if( hFile != INVALID_HANDLE_VALUE )
& Z. S* `( @; y' ]' u  \0 k' m   {
2 N( e: Q" k/ J3 ]      CloseHandle(hFile);
  ^" [' k  o. R      return TRUE;
5 {. ^% ?* Z  b- ^- p! U   }
  H4 {, d3 V# n; C5 d   return FALSE;+ j( ^. K5 z; C& {$ J
}) u1 G$ W" ?4 z, ^- Z% q2 S2 Q9 b% {- `

8 U8 G+ S0 B( K" R, f7 IAlthough this trick calls the CreateFileA function, don't even expect to be
( I$ D' j) M, [2 i) Nable to intercept it by installing a IFS hook: it will not work, no way!# v8 a+ B* _1 u8 F) @0 c8 c) |
In fact, after the call to CreateFileA it will get through VWIN32 0x001F# C. u+ m3 o% `' }' p6 ~
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function); U9 v! U) ^. k* E4 H! e
and then browse the DDB list until it find the VxD and its DDB_Control_Proc0 m# Z& T2 V; E7 O/ k6 R) N' U
field.1 d: b2 f9 j3 K, z7 D
In fact, its purpose is not to load/unload VxDs but only to send a " ^( Z9 ~; ^8 u0 r  y
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE). i0 ~' Z- I) N3 k( O' p" A
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
* v7 D) p- t  d! r8 ^7 ~to load/unload a non-dynamically loadable driver such as SoftICE ;-).
6 P( h4 P( M; Y6 V/ v$ F5 QIf the VxD is loaded, it will always clear eax and the Carry flag to allow" |, i5 n% O+ g. M7 f& a1 D
its handle to be opened and then, will be detected.. I" f" ~7 e, j9 R% E. f
You can check that simply by hooking Winice.exe control proc entry point
3 D2 s5 h7 d5 R8 \; |. Mwhile running MeltICE.
- q& L( L5 m2 Y- K  Z0 g' j" _  d6 ?  o/ a9 t

/ G3 `/ I% A: R: `" P- I& T4 r  00401067:  push      00402025    ; \\.\SICE
6 N' Q7 |2 X; j' L  0040106C:  call      CreateFileA- Q/ v2 e1 @) e$ j1 N
  00401071:  cmp       eax,-001& ~  j0 Y. }, l2 v" M; n2 d
  00401074:  je        00401091
$ c$ g9 H8 A# ~3 f- M8 T8 ]" a3 n: b  A* d& \

1 z- s# B  `* MThere could be hundreds of BPX you could use to detect this trick.
# R  I/ X, n) i9 R* x: t9 u-The most classical one is:
/ F& V4 b5 l" S0 Q0 @8 p  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||) t8 X: |! ?" s' I1 l1 k
    *(esp-&gt;4+4)=='NTIC'
# l1 ]+ A8 x: ?6 }: s+ e! q+ r) h  i* _8 I, x6 |* N( `7 V% a
-The most exotic ones (could be very slooooow :-(7 }5 l" x$ ~* ^, G# h* K
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
) ~3 x8 p- t9 Q7 ]4 ]     ;will break 3 times :-(8 e, G( u3 _0 b7 n; H1 g% O$ o9 o9 O9 r
& `3 d( A- [2 D8 T! U6 }
-or (a bit) faster:
+ n5 |. ]( b6 I) H% _   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')5 v/ k7 l$ a7 L# d% N& A+ ~
& u6 J0 `- f0 S# z
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
- L( b9 f0 q+ D7 Y# i+ v: B2 [     ;will break 3 times :-(
; Q- u% z0 N# B4 ]9 w3 B$ d+ i' P* d1 S3 B6 w' h0 Z7 X! c7 e
-Much faster:2 ^7 E0 d8 J- X
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'2 R5 W9 ?/ C; T
. y" K/ F6 z- D4 P
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
" `8 q8 v2 Y5 M" Lfunction to do the same job:
, R4 i/ x+ B1 d8 q. N, u5 m/ o! @( r% r6 Q6 D9 t
   push    00                        ; OF_READ
, p6 k/ W* B9 r& d2 n   mov     eax,[00656634]            ; '\\.\SICE',0
( O* {4 f; ]  ?+ d   push    eax. j. d0 @; w4 @) y5 b
   call    KERNEL32!_lopen  c( |- |7 P- E2 ]; V6 o% u  J
   inc     eax
) W& b) O2 A( Z' p: z   jnz     00650589                  ; detected
2 l2 t- E5 i( N9 r5 W   push    00                        ; OF_READ3 _. r* p5 k7 {& V$ K  w2 k
   mov     eax,[00656638]            ; '\\.\SICE'
+ p/ C5 L. v; `1 Z6 V   push    eax; J5 I3 K6 ?5 q4 [
   call    KERNEL32!_lopen/ g! N' }$ o- q7 l; k- N4 r+ h  J  H
   inc     eax5 t+ s& h% \1 Y5 Q/ o; r
   jz      006505ae                  ; not detected
( @$ _4 K" _& U0 i8 G6 D
9 U0 i' n6 L3 ^4 x/ S5 K  [2 C
9 x: i( D$ _% h, T, ^% m4 r__________________________________________________________________________4 |: f; t6 O, ^$ y
' c+ f$ l& ]7 X) F
Method 12/ D9 ?! C; X/ ^$ u+ l& ?
=========' N! y$ a, M' v! Q

, V# L; f, H! X6 x6 e6 ?& dThis trick is similar to int41h/4fh Debugger installation check (code 05
& y, P& `- W% A3 l1 U6 J&amp; 06) but very limited because it's only available for Win95/98 (not NT)6 h/ H5 p7 Q# d" n; I- i* M4 W
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.8 @% v- O* o( _- |  x

! F/ P' r- g" j3 u   push  0000004fh         ; function 4fh
- g% Y5 z8 a6 L( v# u   push  002a002ah         ; high word specifies which VxD (VWIN32), l: f# W- M5 P( k( A6 G
                           ; low word specifies which service
7 B. ^( q0 Q3 L! p' d9 E8 w: I                             (VWIN32_Int41Dispatch)9 i- g8 s* x; u+ q/ u- y& @7 [
   call  Kernel32!ORD_001  ; VxdCall  u+ C/ n) _2 {+ `7 z2 S, m
   cmp   ax, 0f386h        ; magic number returned by system debuggers
. g7 x4 D- A% p' Z; D) K( ~   jz    SoftICE_detected
- ]' b: S  h5 y
# X5 A! g. k* B' l3 ~8 B' _Here again, several ways to detect it:, {5 a2 G) {  z) m0 e, \
5 Z* l; ^' O# u0 o8 Q1 e. o
    BPINT 41 if ax==4f4 y9 e" t, k* O) E

( R7 Z- M4 L  C, E' c3 j    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one$ k2 m0 w8 v, m' N- Z
' F$ N  G+ B7 t9 Y1 k/ k  U
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
, U) ?7 }, U- p6 R0 C$ @$ D% q: H4 |  @7 v! i0 B, W
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!* j! D% W- w  m, q' m* z# d6 R
" v; E4 k* \) k7 T
__________________________________________________________________________
  g7 O1 Y1 U1 C  |4 }
8 K) V8 P5 O, B" c4 j* xMethod 13+ j: G; L. q- \& I; Z* }' J/ u
=========
- b) P# h. L) A+ X% _
( I/ \: {. V" Z( s; j0 b- T" PNot a real method of detection, but a good way to know if SoftICE is
9 d2 d6 E0 I4 l, n' A% n* xinstalled on a computer and to locate its installation directory.
& N& m9 q2 Z  M( Y) R+ TIt is used by few softs which access the following registry keys (usually #2) :- h0 a7 m% ^, l' p8 ~
% Z4 l7 N% N8 R' S) `
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 u* ?" L% J* B2 x
\Uninstall\SoftICE8 F8 Z6 \6 W9 ~5 D# p) K2 X
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE/ y% S# c3 u) `
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
# D$ M/ i5 i7 f* r; n$ Y" |  \% Y\App Paths\Loader32.Exe
" C4 r9 z' @/ D9 Q9 g% D5 h: _, d# v  J4 D

0 T& N; [( u8 m. [* {7 ?% BNote that some nasty apps could then erase all files from SoftICE directory
: ^+ `; F- H) X$ g; s(I faced that once :-(8 J$ E- A4 J& Q( f
' G4 @5 M  v2 d$ i* s
Useful breakpoint to detect it:, s4 a5 J  b2 ]7 S( \( m5 e4 j
# _5 Q9 b- A, g5 _8 V
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
5 y4 Q& ?1 s. }7 G2 G5 h5 T' u4 v, F7 x; f
__________________________________________________________________________1 Y3 ]/ @4 v8 M' f
* L7 O8 Y7 f4 @% V0 [; W
9 [  g9 M) i" f2 i3 |+ S6 c
Method 14
2 Z7 u/ o" N* W+ c=========' E4 l& E. x6 F) n

3 @# e6 G" k+ h" K( \7 MA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
+ i" Y5 g6 d4 ?4 v* Dis to determines whether a debugger is running on your system (ring0 only).( D/ U: X. O3 I4 J: v; g

( |  m; ~  |9 g6 ^: P" @9 x   VMMCall Test_Debug_Installed* o9 G9 L: Y) {  I3 C9 z# ~
   je      not_installed
9 P) s- `+ {2 T( i% K7 z6 V
9 Y- k! E- B2 c! V/ DThis service just checks a flag.3 X, `2 p. ]/ j, j, f. ^9 G4 a" {
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部