About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
4 J4 ^5 j& F1 s& w2 x<TBODY>1 X" p( l) r; w& [& o
<TR>
" m7 W) c2 R3 X% P0 W2 \& s<TD><PRE>Method 01
' K9 c  k- D( W=========2 x2 J2 ]% c% k; \$ }

, L# Z* w8 l" [4 CThis method of detection of SoftICE (as well as the following one) is
' m& Q8 i' w8 Vused by the majority of packers/encryptors found on Internet." H1 s# Z# b/ `6 X) a* y. d3 V& l4 l
It seeks the signature of BoundsChecker in SoftICE
- E& c; }) U6 W+ C
: h8 R6 H+ G; c  q) M0 T    mov     ebp, 04243484Bh        ; 'BCHK'; T4 n5 y2 [1 T, W4 T
    mov     ax, 04h
/ Y# h/ x6 T. h/ \/ i    int     3         z2 t' ]. d# z; c
    cmp     al,4
: h) J* F' k! z  h/ }! t( G    jnz     SoftICE_Detected- C. x: f) C2 N5 `% m2 T! m

) E; _! @6 v4 }+ A/ X* X# }___________________________________________________________________________
. P; i8 U. N1 X# _' H8 k( W4 G8 h) c! l; G! J
Method 02
: {% `8 A" a; r2 H7 g0 H6 g=========
' U1 Y9 I: Y, h5 H& c: [$ z0 b" R. i+ M3 F. e2 b4 v7 {7 l
Still a method very much used (perhaps the most frequent one).  It is used
6 M- W9 |! m; L5 wto get SoftICE 'Back Door commands' which gives infos on Breakpoints,$ @; t. `/ V+ ~# s. N6 `; H
or execute SoftICE commands...
: @8 e  L# U" J% _  xIt is also used to crash SoftICE and to force it to execute any commands( |& z+ x; C4 |% `9 c. s" `" ?( ]
(HBOOT...) :-((  : h; _3 O8 U5 a

6 w( R$ Y" ^& B* N: nHere is a quick description:
' @+ H+ c. {* ?1 N-AX = 0910h   (Display string in SIce windows)" K6 u. u  y8 ?  ?* @
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)" V  c/ i: ~0 v0 L3 |1 ~
-AX = 0912h   (Get breakpoint infos)% a9 Z1 U) s5 c
-AX = 0913h   (Set Sice breakpoints)2 E! a6 c8 l" N" V- d
-AX = 0914h   (Remove SIce breakoints)3 G  f! o  I+ N2 w
- D3 X% }1 {' J: l
Each time you'll meet this trick, you'll see:) K9 _$ j2 K( s8 E
-SI = 4647h# d3 B6 z8 R+ E4 o
-DI = 4A4Dh
2 A+ T4 ?$ H  w- X) {; q# D. W3 `Which are the 'magic values' used by SoftIce.
% T, ~  Q1 R4 B8 {% Y; kFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
2 M0 H+ U! i$ }9 l; E/ M5 l" ^3 x) {1 l3 i# ?
Here is one example from the file "Haspinst.exe" which is the dongle HASP
( U* d9 ^3 E9 s+ bEnvelope utility use to protect DOS applications:  u# n) n: c2 R" u7 L2 _8 r
; o8 Y" N4 c) M

  h$ J- B' e* y8 [4C19:0095   MOV    AX,0911  ; execute command.
4 S4 V/ e# ^8 G( \4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
& {9 n$ J+ |4 V# A* V- ~! I# q4C19:009A   MOV    SI,4647  ; 1st magic value.
2 ]  T  E9 `; m; W5 N; I) K3 i0 W4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
- x3 C/ _$ y2 v% U0 v& A* y4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)7 |* G2 a% m2 o" ~6 i
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute( Q; V# a. s, ~0 H. S. _4 N
4C19:00A4   INC    CX0 g6 j8 a4 t- U
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
) }, r0 T. F& J. N/ x% g% ~4C19:00A8   JB     0095     ; 6 different commands.
! J' B' d( ?9 Z2 W2 i& e4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
5 }3 l0 v- g' |7 y* S5 `. ]4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)2 x( P% x6 ^1 F. ]& Q! ~. ^

* t& w' ~, s! c$ F% H% r* }& S; z6 dThe program will execute 6 different SIce commands located at ds:dx, which
3 |+ j, u+ \1 X! t# U+ Gare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.1 j& g. p2 A- o( F! u

2 x+ f, P$ J  {. I: d# I( q* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
4 }# O* I, t# S1 X( N2 L___________________________________________________________________________
/ V/ ?$ k* y9 G0 h+ L4 S! C, f1 T1 }  o! }/ }/ \

: C0 `+ D, A3 q7 o; {Method 03
' z, ]* ?5 _6 V2 i/ @8 i9 e( c=========  {# y' ~5 f5 R7 t" }

* G! o2 j; K3 ~% U. {Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
2 c' }6 [' e, z7 Q& P+ u* {  U(API Get entry point)
2 }$ r% a4 g+ n        - u0 Z8 Z% R2 x- ^+ V2 e3 x
* }2 k# z+ @) }9 }4 ^0 \5 k, \
    xor     di,di
# S+ f/ N1 n# b; r$ ]0 A    mov     es,di
% ^% B4 d) N, D7 b% y! h    mov     ax, 1684h      
' Y* I5 i  M# G: e    mov     bx, 0202h       ; VxD ID of winice2 h: [- g7 m# N  ?; m7 ~
    int     2Fh6 }; \# `, \/ Z
    mov     ax, es          ; ES:DI -&gt; VxD API entry point3 ]! e1 O/ L8 }3 b8 @: w# I
    add     ax, di
$ Q4 o! w+ l8 j6 j& y, w7 G    test    ax,ax6 L1 I& R+ v4 \) V* y, H
    jnz     SoftICE_Detected
/ Y% ]! u% m$ z1 H6 i5 \' p" m: N$ q' z1 x
___________________________________________________________________________
+ ^9 L7 g( q. H7 n1 F
7 q8 R) O4 B, J# x6 s% X6 xMethod 04
5 S6 y) I9 p+ w) [0 Q4 T# I1 L=========; p" |6 w9 o0 O. z& X/ s

, C0 i# S5 C7 K4 \1 I2 QMethod identical to the preceding one except that it seeks the ID of SoftICE
& B) b# n7 u2 c2 a% ~8 p, N+ Q) o& d- vGFX VxD.
2 `- Q- Q! t: E1 ^, X4 j  x/ t' s0 o7 q4 l- Z" Q0 R# b
    xor     di,di8 R0 W# @/ Q- M: c* |: A& H
    mov     es,di1 `' l4 _2 O( L1 P9 X
    mov     ax, 1684h      
- q  U2 w; {/ n% r" L% Q    mov     bx, 7a5Fh       ; VxD ID of SIWVID; \. B% }/ X: l( e/ [" [
    int     2fh
0 V1 B7 V- W2 ~+ X5 n$ ?    mov     ax, es          ; ES:DI -&gt; VxD API entry point( t( E" T& f+ G8 ]( |/ m- Z0 X* n
    add     ax, di: q1 L9 C+ J. R7 c8 J  Y% M
    test    ax,ax* v( A8 V8 Y1 O
    jnz     SoftICE_Detected
2 [- i( v+ u: A& Q  z! e( R
* }3 @1 Q. F2 e! p2 T) y__________________________________________________________________________
) z% x0 @% j! b2 z7 Z& p1 W& w+ i% H" ?/ ^
. S/ O& r: w' M$ L
Method 05
4 X8 M) q  H+ x  _; o4 X5 b- T9 B=========
# B, L. Y) j! H- T- {# B  P; U
4 [) Y5 t+ @0 t& c* ?/ N6 k1 YMethod seeking the 'magic number' 0F386h returned (in ax) by all system
9 w' G; p& J, U+ Z/ [3 Xdebugger. It calls the int 41h, function 4Fh.9 b( V% Y7 X- ~2 n9 j! u5 y; j+ R
There are several alternatives.  % v& B0 K+ Q5 U9 m' S* ]+ h0 q% h8 @
# I1 h! |' n5 z  R; s, U6 a
The following one is the simplest:
& o) a" M$ ]6 V; }! ^7 T
, h4 K4 a5 i2 N  o! K    mov     ax,4fh
7 v; [4 [! f/ X2 F4 i+ S    int     41h
* X3 I9 D! T) I$ M, x+ w$ `" y/ \    cmp     ax, 0F386
( j. o# v* Q, }: W    jz      SoftICE_detected! C7 r! N% b9 k" ?- ?- H! h
7 S& N6 f6 W( F! I

) d6 v  I2 {8 R3 mNext method as well as the following one are 2 examples from Stone's ' k$ P$ O% L2 C* U; D3 d5 N4 K- W
"stn-wid.zip" (www.cracking.net):
7 |7 m/ k, Y- u* _$ ?9 l- {+ h4 P- _- u
    mov     bx, cs6 C( F! H. y% a8 T3 w; Z3 A% G: Z; M
    lea     dx, int41handler2) O0 ~" L; M) _& L% I
    xchg    dx, es:[41h*4]% Y$ l; T' f/ o$ c1 E
    xchg    bx, es:[41h*4+2]
3 }# n! w* h: o  h+ f    mov     ax,4fh6 X1 N$ w( a8 a5 p" ?3 L
    int     41h
4 y; o7 }2 y1 [0 @    xchg    dx, es:[41h*4]' ?0 b+ Z$ N  k7 A, U
    xchg    bx, es:[41h*4+2]* n" v4 T7 h( P0 L( |
    cmp     ax, 0f386h' a6 o6 n. Y/ ^! M
    jz      SoftICE_detected
5 m5 h% ~0 [: o! u
7 @! P) ]+ a3 @; R2 R9 r, Tint41handler2 PROC
% `+ l3 C" |8 b2 h& L; \3 z6 W: F    iret
; e: _/ Q& Z1 o' _1 c* |int41handler2 ENDP
+ Z# T7 }: c9 s4 M
0 W* e  n1 J" |9 E# B! E5 y) K' P/ p  m
( ]5 d) U$ R% A' }/ {_________________________________________________________________________
- H! o$ `# d& Z- K+ T6 J5 B/ G& y$ G; ^: q4 w- X( S, @+ W
9 j) O; P7 y6 U, d# H! c. \
Method 06  u& U) R5 Z0 W5 q/ f
=========
1 e6 l, p0 M2 ?) P9 F* i/ y
% F; Y! R5 x0 F. Z: C0 s9 \1 _7 \( H5 E, G% S$ e; F
2nd method similar to the preceding one but more difficult to detect:
' u1 Q3 p' X' F0 f7 \
; d- M# H9 o/ w3 f
  ^5 C, E- o1 L6 }1 c: Xint41handler PROC9 u5 D5 W9 c5 b3 f+ c* ~* O8 {
    mov     cl,al
" c2 h- c" X( f8 L0 Y    iret( {  o3 h( W& Z( T2 i0 \
int41handler ENDP' {7 g5 y7 v% N' ^! ~7 e1 y

7 ^% z1 p  h  a8 G0 t. W7 X9 F4 U& e& S0 w
3 [! f# J$ G( T+ d7 v3 _    xor     ax,ax- V, w# A9 {* Y4 X  o  a
    mov     es,ax
+ n5 r9 ~# |% }2 [    mov     bx, cs
9 P8 y) Y1 X6 C. v    lea     dx, int41handler
) S- p8 Q6 n) j( Z% i( f. N    xchg    dx, es:[41h*4]
) i. O2 K* G- m2 E' ?7 L2 v    xchg    bx, es:[41h*4+2]
/ L" j3 |2 E8 u! g, D  m$ z    in      al, 40h
* i8 o$ o/ k6 T. I; C! s. d    xor     cx,cx8 R# {6 q& I6 c) E
    int     41h3 P; E4 S/ _, s; k3 h% V
    xchg    dx, es:[41h*4]
# r! A  L" Y9 k/ X    xchg    bx, es:[41h*4+2]0 F1 _' }' Q, ], @
    cmp     cl,al
6 M6 |+ Z0 x' n3 @1 v    jnz     SoftICE_detected% u. P/ H1 ~2 |: W: L
6 }- l# Z$ Z! J4 e; }0 C
_________________________________________________________________________
6 I2 f7 W0 \& }. i5 o% u5 R' r( ^& Z' Z4 h# u# o& d
Method 07$ F! y* e. ~) f& `( q% O$ g- ?
=========* ?3 b2 N* L1 L6 ^' ^0 [1 Y. G
1 B3 C9 O. ]- o. I+ Z) h( a
Method of detection of the WinICE handler in the int68h (V86)
, [3 t# ~" K  e, q, T  }4 i$ u1 z
    mov     ah,43h
0 S/ n, L% U4 ?: B8 n    int     68h, O3 U- Q: K7 \- T8 G! G
    cmp     ax,0F386h
, ~5 t9 k6 M0 J+ w( }& q# B7 ~    jz      SoftICE_Detected
1 u# G- }5 O# p: [3 d, l5 \5 H+ ^0 y- r- }' V4 W
! O0 a# `! w# e! i! o3 C
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit' ~: [' S+ H7 v' j) ^
   app like this:" \( r& [* d& N5 _# I1 F$ l, }+ A

! p! @5 P1 Q- l" G- r; b4 |   BPX exec_int if ax==68/ ~5 S4 a% Z. m
   (function called is located at byte ptr [ebp+1Dh] and client eip is5 ?( U# S5 U/ b1 s9 q5 }8 u3 l
   located at [ebp+48h] for 32Bit apps)
5 z/ E* G$ @& s" u+ Q7 t0 q__________________________________________________________________________
) o8 N- W* [$ D; x6 e: r3 D; T% P! ~7 U/ _( I1 k! k

+ Y* y" x* B, D6 p, }Method 083 i5 S$ p: t7 {# `- ]+ T
=========
0 h+ a, S: P. n* g+ P+ V7 ^
2 G" G5 t8 z" h+ cIt is not a method of detection of SoftICE but a possibility to crash the9 M# e& q- M1 p- N+ s
system by intercepting int 01h and int 03h and redirecting them to another
& \8 t" K$ z1 D8 @9 T" a9 eroutine.
, m. J; O# W8 O$ b) `$ W6 BIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points  x1 p' ~7 h6 b: v  a1 u
to the new routine to execute (hangs computer...)
2 C3 T( B- l" k
1 [6 J/ W: z, C3 _    mov     ah, 25h
0 V; p2 b  w8 l& [7 b- A1 C    mov     al, Int_Number (01h or 03h)2 i* @2 w& a$ \3 X2 @) k" F4 Q' b- W
    mov     dx, offset New_Int_Routine
2 e5 x1 I! f5 E" U8 O/ G    int     21h6 k6 x) `$ D7 w/ n+ b! i" u. F0 [
, t' U0 H2 Z9 q1 u7 C
__________________________________________________________________________) o9 l) v% ~6 z4 X
3 \' H$ r  u) s3 {5 C
Method 09& t* K/ K/ Z" \
=========3 L' K8 X/ Q1 m# z& ]( `5 \

+ ~+ B! C5 ~$ Q) j& x  KThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
/ e. Z5 h: v! |0 sperformed in ring0 (VxD or a ring3 app using the VxdCall).
2 I% q! e2 q3 ]The Get_DDB service is used to determine whether or not a VxD is installed/ w  m8 |- H3 O0 D0 n( ]) M& u* b
for the specified device and returns a Device Description Block (in ecx) for
/ W2 V- K) C5 x* j/ `/ `  ythat device if it is installed.
7 W* a% I, B: E- V# O+ _
7 C  G9 Z7 H" `7 H   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID* H3 e( c1 y& h/ Q; ~2 M9 T# {$ p
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
4 h9 h  [, j" q. r* f4 u   VMMCall Get_DDB( x" @* Z! L  J" i& P
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
) x3 }  o) y1 W0 K& P# ~+ i7 u; ]" W. \4 a. v: {3 L# p# t7 T
Note as well that you can easily detect this method with SoftICE:, e* ^3 P" n! h" X4 s3 P
   bpx Get_DDB if ax==0202 || ax==7a5fh8 g" H8 J( ?! t, o% K  [

0 ^0 i3 O) {: C/ {; i7 c__________________________________________________________________________
- K( [! X) _1 S7 E+ g+ h* w6 L6 {# a( |$ a0 y- q. S* m: {
Method 107 P7 I& d9 E1 o% n# k2 ?
=========& l9 E& Y& N( R

4 i- T8 c0 p5 i# p=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with: p, b6 ~: [: @- p2 d
  SoftICE while the option is enable!!
( I1 B1 J! N* q# @
6 W* t& E8 x9 i. d* g, @This trick is very efficient:; K! h$ b* d6 o( T
by checking the Debug Registers, you can detect if SoftICE is loaded+ F1 h& q9 M1 x  Q" n: N
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if0 I( S* M9 _& {' u) h  m& e
there are some memory breakpoints set (dr0 to dr3) simply by reading their
6 O* J; W6 z4 I% X) Q9 svalue (in ring0 only). Values can be manipulated and or changed as well
/ d5 X6 S3 m, q) f9 S7 Y(clearing BPMs for instance)3 n5 o6 @  T( e" _
$ x5 v7 d! P3 c2 L8 x
__________________________________________________________________________
- x+ A2 ]4 F0 d: W  y! Q6 M" O' ]
2 X3 x8 G' c0 ~Method 11
# [& |" j4 o3 F: a+ Z+ F=========% l) A. B9 P+ W( d% o6 `! o

# @8 h! G% c4 S( ]& s) F- [This method is most known as 'MeltICE' because it has been freely distributed
8 H6 X3 o; D8 M2 Gvia www.winfiles.com. However it was first used by NuMega people to allow4 f& [5 P  M+ o1 q
Symbol Loader to check if SoftICE was active or not (the code is located
& P. I5 O& R( z' v/ Binside nmtrans.dll).: P0 S3 f7 i' g0 g/ ^5 I( j' Q
! Y6 u2 V. [1 v- ?  a
The way it works is very simple:
$ y7 b! n( C) d; l; C* E7 u/ |It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for0 N4 q; c) l4 B3 {
WinNT) with the CreateFileA API.
9 P; `: h: o3 l8 \
7 z" }1 B8 Q) VHere is a sample (checking for 'SICE'):9 Z( f5 g6 d; M( m

  R# [  \. }. _  a$ s1 g$ dBOOL IsSoftIce95Loaded()  B3 \! g2 Q/ S
{
: Q! J. O* N( i   HANDLE hFile;  
& ?9 o# Z! M' D/ P" R  L1 @- A   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
7 h( H% n/ e9 I# b* T+ t                      FILE_SHARE_READ | FILE_SHARE_WRITE,
7 V% J. x! F+ ?% y" q1 R- t* k                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);3 _% C: O1 B( ]) Q. w- b
   if( hFile != INVALID_HANDLE_VALUE )
# |; P* i7 p% ?) P   {: W$ s% Z& \* e5 `
      CloseHandle(hFile);
8 W3 o+ z+ j0 k      return TRUE;
) L, w- }* c+ }4 t6 ?   }9 t0 A( p# ~+ C1 X
   return FALSE;
3 W) ?7 R. p/ d3 t}
3 c5 y, R; f6 m7 B0 W7 @1 V/ E& o7 g! u+ @# L2 i
Although this trick calls the CreateFileA function, don't even expect to be
) F5 @* P5 X9 j$ i; N8 @3 J! n# wable to intercept it by installing a IFS hook: it will not work, no way!
* M( q1 z& @# ]: S3 {$ k% s  oIn fact, after the call to CreateFileA it will get through VWIN32 0x001F! q1 L! u* T; Y, d8 ]$ v
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)3 L4 M2 Y, t, w! J% R+ M$ t) w# N) n
and then browse the DDB list until it find the VxD and its DDB_Control_Proc& k( y6 _8 I, D$ @0 f  ]) u! [
field.% R# l) n/ m6 L  Z+ L
In fact, its purpose is not to load/unload VxDs but only to send a 4 V1 D. U$ v: @) |0 J
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)) m" y4 H& r, u9 \5 H1 _1 D
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
% k: B- H: o+ z5 N/ Dto load/unload a non-dynamically loadable driver such as SoftICE ;-).9 J' P* G; F9 H3 a5 B
If the VxD is loaded, it will always clear eax and the Carry flag to allow+ m7 o- y" X! v8 f8 C
its handle to be opened and then, will be detected.2 |& {2 q# ~$ t" B5 P7 k
You can check that simply by hooking Winice.exe control proc entry point
! `* y$ I- W" |5 G" K+ |0 H; ewhile running MeltICE.
: @) R& M8 \* n: J+ |7 x9 ^5 d% c: S, v5 m" w/ |
& K' d4 }+ ], Y' o
  00401067:  push      00402025    ; \\.\SICE
, b6 N+ `/ t2 z  N0 `7 U  0040106C:  call      CreateFileA
$ @) G# |: T* f5 B, W. m/ C7 Q) q' s2 {  00401071:  cmp       eax,-0018 d. K1 m( d$ b1 W0 q! U
  00401074:  je        004010916 O6 U0 [- z. C4 v' j

8 b1 O2 w1 y+ s  m% V# x9 `. m, e- P/ E7 V: Z6 U6 Z
There could be hundreds of BPX you could use to detect this trick.
& q0 V3 U; o+ g" J-The most classical one is:
: A/ y; {. O! i, K' B  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||5 ^2 y# D) U( ^+ ~- h. A# N3 i/ m- \
    *(esp-&gt;4+4)=='NTIC'
% F, f8 Q/ `4 d; X+ {# b; s
( J" s3 ~- J8 r0 j- e5 M-The most exotic ones (could be very slooooow :-(
( c* {; O- F- s. |6 f   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  0 B. h: Z% T$ E4 X, Q! d0 \
     ;will break 3 times :-(
. ^8 q0 {" [* g: O, r0 \+ j. {
" K+ e! Q" [7 @3 }-or (a bit) faster: 6 }; \  F! _  u- r. u
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
7 N- D# j% s% }1 Y6 C( R8 |3 O# J+ |4 y/ o' r+ m5 q
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  ) ?$ i/ b& d' Q+ x) R0 g  B: o. W+ d
     ;will break 3 times :-(
5 h" k. M& C- E1 L& R4 a7 x" X$ b  D
-Much faster:  `, d' X1 j  n$ \. |
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'- @/ G. p; L, g

9 D1 A6 v0 o2 J) }Note also that some programs (like AZPR3.00) use de old 16-bit _lopen; [* O, f1 k, B' f* W1 x+ m
function to do the same job:
: s" P9 b" c0 L& D0 N, s, y
$ Z, n  m  Q" ]5 n1 O   push    00                        ; OF_READ
1 o, K  @3 ^+ _   mov     eax,[00656634]            ; '\\.\SICE',0  k$ [9 V; W7 B5 g4 Q% A1 x
   push    eax7 h+ Q4 Q9 {7 j, ^! {/ @" a
   call    KERNEL32!_lopen
3 v. F( B5 M# m! g7 N: L) k   inc     eax: p6 n" @- @+ n# `
   jnz     00650589                  ; detected+ V' F7 y0 c- Z' X
   push    00                        ; OF_READ
3 J- G0 g/ [2 Y( k$ x! d  v   mov     eax,[00656638]            ; '\\.\SICE'
0 d2 w. s# E7 t+ s) m5 g   push    eax# h8 e+ Z. ^7 y- g# \
   call    KERNEL32!_lopen4 f* @% D0 p+ B4 j& p* `% \  r7 U
   inc     eax
9 q& x: K. m8 x& v& O9 W   jz      006505ae                  ; not detected
* @9 x+ ~' i' Y2 N% H% k/ O3 \3 n# K' u4 M
! g0 t, I: `/ k& z
__________________________________________________________________________# x1 d& N) B) K: ]7 `

/ {5 g" F9 ]4 ~: X" U9 y1 p9 WMethod 12
+ c$ v2 R# |/ i! m=========1 ^6 s3 ~% e/ v$ [  o* E0 T, q  E

9 @& Q! L" A  |/ J1 B: T' O1 Y2 sThis trick is similar to int41h/4fh Debugger installation check (code 05
( A# ]8 Q2 D8 E) {5 n) n. B; @&amp; 06) but very limited because it's only available for Win95/98 (not NT); [0 N3 x5 G4 Z7 R5 D" q
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
# f% E  I2 `8 J2 d( ?: w
- L" m2 }7 L" k2 C   push  0000004fh         ; function 4fh
4 C/ h  V" X3 J+ P: }% r/ X   push  002a002ah         ; high word specifies which VxD (VWIN32)
/ I/ e& j. U% |% y                           ; low word specifies which service0 \) P( ^7 B  U/ l5 l' p- a3 \' A( I
                             (VWIN32_Int41Dispatch)1 y' K, t) Q* u$ v2 {8 V
   call  Kernel32!ORD_001  ; VxdCall
0 X) t5 s1 I9 n7 p   cmp   ax, 0f386h        ; magic number returned by system debuggers
. W: ~3 f  L2 H  R0 A; O9 S/ I   jz    SoftICE_detected4 ]9 b, N* f  k) U4 J. f

' g/ h0 e6 r2 l, ^' k! U# Z/ QHere again, several ways to detect it:3 W* X& Y* e: C; r) W# V

! s; E  d1 H2 P    BPINT 41 if ax==4f5 T& ~! e$ }+ z& ?, w

7 w4 f* V. X9 D    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
" ]* v1 Y& o$ ~) \6 R
3 f9 x9 C" w! a% G% L    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A6 }4 p( S9 d8 c: g  y

5 ]6 V( ^9 ]" k' `( m6 X    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
: Y+ M9 C, m) K2 E6 J# x* C6 T5 n# _6 y- @( F6 n# k
__________________________________________________________________________
1 S7 W7 F, D: H3 g2 a+ q" u; v  c/ |: N9 |  f/ @' l9 t
Method 13
' J/ g- g5 |7 ^' _=========& E7 u$ o' L$ X/ c* W

% x- d( C/ ~2 I+ |1 y% k, UNot a real method of detection, but a good way to know if SoftICE is
! w! s, h" G: _installed on a computer and to locate its installation directory.; s" K/ K5 u& O9 K* {( T6 W1 ~9 |+ F" Z
It is used by few softs which access the following registry keys (usually #2) :3 I, Q3 [1 x5 g6 w
3 _7 A/ L, E% s: G0 A3 L$ ]
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion. u$ M4 x+ R' ^& b
\Uninstall\SoftICE
9 C" z& P- h  D5 b1 {1 Q: N, ?-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- G' y7 e* n) n2 U-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
" [! m. ^- d8 z! T/ U% a2 s4 g\App Paths\Loader32.Exe
  M, L2 Z/ A1 j' _  M+ [7 F; J: b1 W, R7 [1 V8 C

$ U6 {7 L6 ]" e0 W, a( R% M. w7 N5 nNote that some nasty apps could then erase all files from SoftICE directory
6 R% I8 c8 Q1 S+ h4 U4 o9 J(I faced that once :-(. v& {% v) \# `/ {# r- s
& u/ J# j- B0 Q: u- X: g5 ]; r
Useful breakpoint to detect it:4 ~0 p- a; D/ U! `! w8 G
, }: Q& j' C9 ~3 ]! h
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
6 Z3 H- f' m# e+ u2 j! Z7 Q/ U) ]  n2 t( U. F
__________________________________________________________________________
# k9 y1 E+ V1 J. i' J, j
$ v8 }% ]' R5 a$ l4 I. M4 d/ d) }* }) m' B* o+ r0 w
Method 14 5 A$ }- x+ ]5 `: _
=========" o$ @$ e  `, x' {% G6 g& h
- |6 N/ `3 ]. H
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose- Q/ W: H* ^# n4 n, x! R
is to determines whether a debugger is running on your system (ring0 only).+ t8 n  {% n) X; Y

7 O- v- h. N" ~5 L# w1 d   VMMCall Test_Debug_Installed2 f1 `! b7 h7 ?) }
   je      not_installed
! M: m2 F  }" n, o/ D) ~# U/ T5 c$ B  X# p0 C( r
This service just checks a flag.+ P; m8 g" V$ d5 D; d8 u7 R4 w* U
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部