About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>& B: e- Q4 _* P8 \: _" d( j# G. M4 H
<TBODY>' t3 e# }  Z+ Y
<TR>+ v/ R7 q9 N5 x* I, z
<TD><PRE>Method 01
( y' D0 L! c7 ]=========% P8 G2 k) x2 M! [0 n
9 s& V: J+ @3 @3 U: u$ X
This method of detection of SoftICE (as well as the following one) is
, t3 ]6 Y5 \. ^1 sused by the majority of packers/encryptors found on Internet.: S) N4 g( M: E7 d5 |, M
It seeks the signature of BoundsChecker in SoftICE
4 z/ F4 }9 g/ a( o3 x
7 T1 O6 w% L( K3 z    mov     ebp, 04243484Bh        ; 'BCHK'
1 a3 a6 U8 [- m; M  F. n    mov     ax, 04h
+ o1 x7 @& a* v0 D3 f- ]/ i  o9 t    int     3      
, C0 f4 M% h2 |* q* c  g    cmp     al,4" ]/ \( ^9 T+ Y. D
    jnz     SoftICE_Detected! Y1 H; h7 O* i2 ]+ n0 ^- M

" _4 L/ ]0 K# a8 }( `5 ]. w___________________________________________________________________________
8 u! E7 v( f. y2 n6 e. y
  `! V- H5 f& XMethod 02) _* h9 `, n" m4 [, }
=========3 i; F' R6 k$ t9 Z
, n- T0 Q' `: H: f
Still a method very much used (perhaps the most frequent one).  It is used, J- T% V* l6 P+ K2 K
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
/ X, @% h$ \" j# u1 a3 V8 |9 w4 d* _or execute SoftICE commands...
3 _! C1 ^& |5 p+ H  }It is also used to crash SoftICE and to force it to execute any commands
# [2 L1 Q: ?. V! N(HBOOT...) :-((  0 Y- g% Y+ J8 Y5 H& \% C' x0 e

% v2 a; O& ]/ [$ r9 X! L- gHere is a quick description:* W0 C+ m8 N9 }
-AX = 0910h   (Display string in SIce windows)
1 _& L  ]- R! _* R-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
5 o8 s! K+ G: J) t8 G-AX = 0912h   (Get breakpoint infos)- f9 x# R$ l4 b5 [  @' a
-AX = 0913h   (Set Sice breakpoints)9 W, W. ^  ?6 ^' i9 t4 @& A
-AX = 0914h   (Remove SIce breakoints): k' c" R) }) q. j" u

( X6 W; J" S, @7 l9 m5 S6 hEach time you'll meet this trick, you'll see:
! }5 t( r# D: M% @7 t-SI = 4647h% X! K% d( ~9 [! G; U
-DI = 4A4Dh
) l) r$ D/ [& cWhich are the 'magic values' used by SoftIce.' I/ z* r0 k, @7 p# m* Y
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
: n4 A2 f" E) ]3 H5 ^% ^" V5 g8 i' g# T$ Y- A' P! D
Here is one example from the file "Haspinst.exe" which is the dongle HASP3 J6 @9 E  b6 b5 {& u$ ?9 _
Envelope utility use to protect DOS applications:
2 l& E/ {8 j0 x/ q" V" F: v0 d
& i) |$ `- R0 c  V7 n; R) ~; ^+ b) d0 I3 d
4C19:0095   MOV    AX,0911  ; execute command.
# X% ]$ I0 T- k4 ]8 O8 }4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
( S) w/ V! E9 n" O! h4C19:009A   MOV    SI,4647  ; 1st magic value.
  ?0 K/ g6 }6 D) ]0 n2 {4C19:009D   MOV    DI,4A4D  ; 2nd magic value.0 Y  r. D% D! t# M/ G3 p
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)( M# Q$ ^6 ?* T6 m* M% ^
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
3 ^/ s8 W; M# u5 s8 \4C19:00A4   INC    CX& w  N& Z! f7 r3 @' ~- }. z( K& S; \1 R
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute- \, a7 x& ^6 `
4C19:00A8   JB     0095     ; 6 different commands.6 b* {( L7 ?& @3 @4 O: M( o/ X+ o
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
/ A) w# N+ A# `+ _: l! J4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
6 d2 c6 B  l6 t' o
2 l: x3 Q5 z9 q: TThe program will execute 6 different SIce commands located at ds:dx, which5 c' n- D+ ]3 X  Z( V$ @
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
8 m9 Z/ U3 ~, P7 Y+ X' Y2 N* h5 x+ k7 l$ u, z- }+ ]: ]/ D6 j4 Z
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
) m% L+ _/ q" I, Q6 r, u. C* p9 W___________________________________________________________________________
; l' t* `5 O  O! T; Z0 v* O- q  I5 g- e$ _) I2 Q
: t$ G# I/ T5 ^! I# H
Method 03# I, f% s( b, t1 r5 U% s& {  j* B
=========- F) k1 [0 P% y/ k* b" |* c

1 z! ^# _$ l) ^Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
8 r. m( q5 [( b$ I- ]3 F' I9 I) Z(API Get entry point)8 W% A; Z: K7 \( m. y9 T$ c3 N. K' d2 d& |3 w
        & ~" W* Q+ {& u! o, a

4 U, ]  d" P1 |    xor     di,di1 e7 `" Z8 Q1 R/ p* Q0 c+ X6 E
    mov     es,di% V4 v" T& n3 _) Z, [6 i/ \7 \
    mov     ax, 1684h       ) y! T. @: H: }/ h
    mov     bx, 0202h       ; VxD ID of winice
" h) K6 C2 J# U- Y    int     2Fh
7 |' E+ U4 @5 Q& P    mov     ax, es          ; ES:DI -&gt; VxD API entry point" o% f- \  K% S* @
    add     ax, di
% R# c  n$ v+ {8 Z& t8 R% h( O    test    ax,ax
/ Y) C6 q; W8 {    jnz     SoftICE_Detected  W4 @6 B! d- v

, A+ k- i6 C- W8 ^/ ^6 I- A7 X___________________________________________________________________________
# c/ g$ O8 \1 w! R0 [# b( g% F, @7 G3 ]7 K3 r6 k
Method 047 g, |' Q( s, |) M# S
=========
5 s4 d& G1 |; t& I% }" H5 d( \+ O/ H. C' [# G! c( [
Method identical to the preceding one except that it seeks the ID of SoftICE
" a% @: C# O/ d, X4 w8 kGFX VxD.- G2 ^0 r) ]; R; S$ W& u: h/ N" s

4 C! e2 f: \- o  p9 b    xor     di,di
" C5 N2 [5 ~( j8 g$ z    mov     es,di. f& Z$ |; N% r/ R
    mov     ax, 1684h       ) U1 E0 z3 x% n0 U0 W
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
# q* r4 Q2 m# `. ~    int     2fh: _" M5 e  Q# K8 {5 h
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
, y$ O" @5 O; N' e4 j& `    add     ax, di
4 t2 w. ^/ C$ t9 P$ ^9 c  v7 F3 ?, {    test    ax,ax& H4 `& j1 }! U
    jnz     SoftICE_Detected( `5 O; @; `! ~2 ]" z/ d7 k7 Z1 P7 O$ o

' F. J% g8 V4 @/ H5 x1 @0 D; ~3 n# U__________________________________________________________________________* n: T- m$ {# F2 ^7 A* q) A
0 W) b0 S( e6 I- s( g
, E4 q; S& V0 R$ j2 V) [& m' ]8 e
Method 05
/ e4 l8 T7 J. G5 }' n) [) e=========
, S+ f) X! n6 B* i! t& j$ J. x; q% U
Method seeking the 'magic number' 0F386h returned (in ax) by all system
+ B- C9 W" z. U. Pdebugger. It calls the int 41h, function 4Fh.3 ~. E& Z0 G& M' k- k7 N, @0 {& Y
There are several alternatives.  
7 q2 M* o) T: c8 `/ y: o
1 U- ~/ X6 Q& ^0 C; h/ jThe following one is the simplest:
8 b+ U% h( [4 s" V8 H, Y0 h# w9 C/ u% V7 ]- Y8 s
    mov     ax,4fh
7 X( z$ o, d' U4 q    int     41h3 }* @( W" A7 c  e! H
    cmp     ax, 0F386+ K- X8 W+ [( W$ h5 [8 }  R  Z
    jz      SoftICE_detected, x; j9 b0 n6 c

9 v' z; v) M. `1 e- l0 B( ?
2 }5 |9 F( _5 E* R* m. o, wNext method as well as the following one are 2 examples from Stone's 9 g' o; B5 o9 j
"stn-wid.zip" (www.cracking.net):& Q6 ^* x. P7 @; B& P, H2 x! E" K. |% U
! r# l4 D2 z0 X
    mov     bx, cs
6 G. v4 e; u/ ~0 K" X& x    lea     dx, int41handler2
: N- J# T" Q3 h! `- |% I( |$ ]    xchg    dx, es:[41h*4]
5 H1 E8 h4 \) j) F4 ~+ Z" X# \0 m7 ]    xchg    bx, es:[41h*4+2]
1 c* a+ r& b- \1 W9 Z- m    mov     ax,4fh/ z: J0 }, d1 N; L5 d) w  t4 T! S
    int     41h
5 T  M' {& E5 J4 E# v  }    xchg    dx, es:[41h*4]
* u7 S9 X! \; T" i1 U7 s    xchg    bx, es:[41h*4+2]
. S$ u! K& f2 j1 N    cmp     ax, 0f386h
- L3 v' O" Q0 n) E, `! S    jz      SoftICE_detected
; I' _2 [3 E  K9 g
, j7 Q. H6 G8 r# t# w/ H/ ^0 Gint41handler2 PROC
9 m# ^7 e$ o) X    iret5 v0 @, y: M" o" D- G0 M
int41handler2 ENDP- J) P, e2 x5 {& ]! @- S4 l
1 w4 `& ~3 P6 b1 F' m8 n/ j& }  u5 \
. ^" A. d( [- K. Y
_________________________________________________________________________
0 C' i/ J4 U% U$ v& k( k3 T' U7 @7 B# Z9 M" f. Y* L' g! W9 G, r) L* y! t
/ P$ |8 [( c/ H$ G" v& ?6 ?1 Y
Method 06% n6 X5 k0 o9 A0 R( D' j7 M3 @
=========
) m, ]3 F7 h0 {" h; n  ]: b$ n& T5 ^1 L" J9 K) n

! m  B. e' z; r- w8 _0 n1 i! H2nd method similar to the preceding one but more difficult to detect:
. h+ P. b( m8 d& ?( p9 h, X' W4 \
7 G$ B5 z% G) }# b* x% r* e. _/ \8 N# K! y0 F' M
int41handler PROC
* N$ x5 Q+ `" b# @4 G    mov     cl,al
+ C' b! ^9 N4 w+ I    iret, t" I: l1 f0 \  v7 w
int41handler ENDP* H3 @, m3 N+ P  H+ U
4 n+ Z! c) c8 m0 D% g

1 }( F8 z  _, l5 j# {    xor     ax,ax$ \3 n- ^" B' j! A
    mov     es,ax
7 V) y2 k. x* H9 Q6 ^) E% r. S8 G    mov     bx, cs( F. P# @7 D7 c% O
    lea     dx, int41handler3 L- |# E7 ~" ~# G
    xchg    dx, es:[41h*4]1 z7 Q2 E7 @' B1 s0 E/ }
    xchg    bx, es:[41h*4+2]
4 B# j# |! c3 a) e    in      al, 40h
+ c' J# F" y' k2 K- |1 N    xor     cx,cx& a) C! h! Z  r: w3 s
    int     41h4 P  \# E, }& p) ?# k4 w
    xchg    dx, es:[41h*4]
1 B: c# d$ r2 N7 J/ ]- \% B    xchg    bx, es:[41h*4+2]) W6 Z( L+ n" f
    cmp     cl,al4 m1 I8 ~4 D" r" J
    jnz     SoftICE_detected! s* J, B: o3 X/ `) F. M+ t
  j& z% @- ]# I9 U, v
_________________________________________________________________________6 k4 F1 ?5 S1 {3 l& d  ~( ~

, i! Q3 D8 w  d. U; N* f. B" d+ {Method 07, ^9 ?9 p2 ]7 J) l, F# f
=========
- b4 R8 C2 S2 M: s
( d- B; a8 z" D& E* u2 oMethod of detection of the WinICE handler in the int68h (V86)# X, {! Q3 i/ m4 `  [$ U
5 c8 o& S; e. F: u) t) W6 ~+ U
    mov     ah,43h; C( p( I% H# W4 h5 Z
    int     68h& L( i% N" E, n" _( G, Z
    cmp     ax,0F386h) j1 j/ k5 Q- S% _: U+ ~
    jz      SoftICE_Detected
5 |( Y1 Y) q8 W: K0 p1 E/ F/ ^+ H6 {( C

: q0 ~* ~' P  E$ `=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
. W" x1 j4 V+ t0 ^' I7 K   app like this:
$ J- i: ~. Y$ i$ Q/ s7 M1 r( i. Q  E+ i: y4 [* z) t; e  R
   BPX exec_int if ax==68' n/ ]# |; H9 P2 b3 @9 a" `. g' a
   (function called is located at byte ptr [ebp+1Dh] and client eip is: C6 W  H3 X/ I1 ^4 x' s* ]/ W! v5 s
   located at [ebp+48h] for 32Bit apps)$ d+ q+ A  _6 ?4 e, |/ \1 t6 L
__________________________________________________________________________
1 t2 i4 ~$ k3 Z$ ?- F+ h# r6 o9 }! ]! a: G

, l% F# W2 p7 @4 ?$ k* [. V3 DMethod 08
) `9 e% W  ^; r4 h1 U2 I=========5 O1 Q" \8 I" E; V. w* o

' \+ c( t/ P1 w1 }+ T- z# Z& iIt is not a method of detection of SoftICE but a possibility to crash the
  o3 f3 x& g6 z7 Usystem by intercepting int 01h and int 03h and redirecting them to another" v$ \1 e& X: V  N
routine.
4 k# ?/ ?0 [* }, T/ A- oIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
. l9 r; c3 \7 Fto the new routine to execute (hangs computer...)1 h4 }2 Q5 I, m" E( V9 G
0 ^) r$ _2 j  r: s* k7 w
    mov     ah, 25h6 B, i9 C" I% o  L6 ?
    mov     al, Int_Number (01h or 03h)& q- i. n- ?+ ~, s9 n# a  F$ M/ K+ K4 U
    mov     dx, offset New_Int_Routine
8 q8 s; A# I% s    int     21h
% V9 T% H' m! a2 O2 ^+ m6 A9 @& l! }* [- C
__________________________________________________________________________8 h$ i  _- M4 n2 G; q7 E

! L9 e) E/ K/ ]5 v& EMethod 093 f9 F$ F0 S4 \, Z  i/ X) G
=========
' q/ v! n& d* b+ y4 W* q; h5 O) a8 w9 I8 k) d( j
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
7 ~% M7 M! l. G7 N3 B# S0 R* x0 L$ uperformed in ring0 (VxD or a ring3 app using the VxdCall).
( F. i2 v8 A( }& i8 z% X' rThe Get_DDB service is used to determine whether or not a VxD is installed
, G# i  F" M& k7 F4 Y& r) }for the specified device and returns a Device Description Block (in ecx) for9 {+ b4 [: w& B9 i1 ^9 X8 Y
that device if it is installed.0 k7 u' D4 M8 n8 I6 i

! P+ y: j7 \0 {$ r1 G0 w   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID' T5 a" W9 p1 B( ~8 }' C* C" l; C
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
6 }# M; e& K! Y1 |" n( g5 C  e7 ?   VMMCall Get_DDB/ m$ u; `% e7 p- X' d
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
8 G2 g7 L  N0 n; R/ i  m9 L7 A3 v2 c1 M) Q4 `2 ^8 k0 c
Note as well that you can easily detect this method with SoftICE:
$ }5 A' ]0 ^  R1 y) d. p0 o   bpx Get_DDB if ax==0202 || ax==7a5fh& E% y7 a- X8 K  [' F2 p) a5 c
7 x" i4 {- M) L! G7 Z0 J+ [
__________________________________________________________________________
5 ~& R3 s- J$ T0 L6 l$ \- _- n  v1 P3 O! h0 t/ T: L: I
Method 10
; b4 o8 U$ L* [, I; }# g- M$ |=========
; c- j  }5 a8 y! O& Y: y
5 M. X& @8 @2 P/ L=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with- q; b5 j* ^, O, D7 ]0 A
  SoftICE while the option is enable!!9 T8 F/ W/ u+ h: c" ?  e! C' q

" V7 u! {+ z3 hThis trick is very efficient:
% N$ r% b8 W' q  Fby checking the Debug Registers, you can detect if SoftICE is loaded. ~$ [5 t+ t) t5 c3 @
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if& I, P; x7 S  S2 |* @' i" d: `
there are some memory breakpoints set (dr0 to dr3) simply by reading their
: @/ X9 w7 Q6 H. fvalue (in ring0 only). Values can be manipulated and or changed as well
( R: O" L6 \2 L3 W1 f9 W(clearing BPMs for instance)* I3 f/ s8 A9 V3 z8 s) j

4 {) S1 j% B$ W__________________________________________________________________________
' k/ [" l0 Q. \. X5 n$ x7 y6 }1 t5 b) d4 s8 v, E, D- g9 z
Method 11& t' ?% E! n1 s2 [8 j, C
=========3 I4 s8 Q# r9 s8 Y$ {! p% ^
3 |; F) u1 i& r% ?' @1 E2 r1 L
This method is most known as 'MeltICE' because it has been freely distributed+ v9 z) W1 B! e4 x
via www.winfiles.com. However it was first used by NuMega people to allow
& S$ f& f4 o7 O' RSymbol Loader to check if SoftICE was active or not (the code is located1 x8 k$ c5 z. k/ s  c. @
inside nmtrans.dll).; `3 h/ E# T; W4 a# u" u

+ |4 H3 r' c* T( `) R2 t2 xThe way it works is very simple:+ c/ L0 I. z4 e5 V! o* ]3 j0 m" E9 V
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for: ?/ ]+ o& p' W9 Z2 K) l
WinNT) with the CreateFileA API.
( S$ b$ h3 t* M& }! X3 N8 ^9 |# n2 T/ Z- N" ^& d8 k6 |
Here is a sample (checking for 'SICE'):
& x; k* U# j. D: u' X! L& o$ D0 E" a& U/ w0 Y1 p+ F
BOOL IsSoftIce95Loaded()3 J+ {, D6 J4 Z
{
0 C. N! Q) J; }& u6 k, m. Q   HANDLE hFile;  
, N, J6 @  V% J* e   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
/ \# d' y* Y: e* y3 L                      FILE_SHARE_READ | FILE_SHARE_WRITE,
: j# z4 H; l* O0 F  k                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
; O4 \0 y+ ^  T8 D- ]: x. X( Y   if( hFile != INVALID_HANDLE_VALUE )/ }, [( o  e# j+ u
   {
5 r& V- N) Q6 D      CloseHandle(hFile);$ V+ _! C! H8 L2 f9 K
      return TRUE;5 F! e; `0 f. u$ s( k5 R: s
   }
" r: X$ k, p7 j4 p! y2 U% W   return FALSE;3 X4 d- X9 i$ d
}( P9 M( T, @* V8 I' b& b7 E
! X$ V; Y9 _# k% C7 b% a: a+ o
Although this trick calls the CreateFileA function, don't even expect to be
1 t+ M% c, F, y; k+ w$ Lable to intercept it by installing a IFS hook: it will not work, no way!
, E* E8 A* j. ]$ pIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
' M* X# b. W7 R' `2 L5 h) Tservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
# u$ r' W* F1 z% F- Y9 v5 q' P' ?, k5 Pand then browse the DDB list until it find the VxD and its DDB_Control_Proc9 C5 b, C/ @# e8 z5 T& i. H$ C
field.1 U6 G; h) J' z$ O
In fact, its purpose is not to load/unload VxDs but only to send a 6 ?1 J9 y. R* G4 U9 E1 d
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
4 W, Y# q  p4 i/ yto the VxD Control_Dispatch proc (how the hell a shareware soft could try/ G/ x, j/ [6 c$ J0 v2 P+ h% v- y# L
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
2 L2 U1 [6 }! pIf the VxD is loaded, it will always clear eax and the Carry flag to allow& ~2 g$ f3 m5 ^9 l. T7 M8 {
its handle to be opened and then, will be detected.
" i) r/ {) ?$ J# {* b: ]" q0 xYou can check that simply by hooking Winice.exe control proc entry point, i5 e/ b6 Z; }# J) \( g# ]
while running MeltICE.
" ~) E8 s) k  V; V
- ~, j( Z+ m4 H6 b  t! q0 X% N7 N4 v9 ~: ^$ o4 y
  00401067:  push      00402025    ; \\.\SICE
0 a9 {. w% @: I3 h6 \6 l$ T  0040106C:  call      CreateFileA
8 O4 B" \) y1 b1 B  00401071:  cmp       eax,-001
  D8 r$ y" u3 i" l# d$ E' A  00401074:  je        00401091
: `8 A- W  S8 t( G$ z4 T, K6 [. n8 L/ R
3 d$ t3 q! r  O# h# z* u4 M' i
There could be hundreds of BPX you could use to detect this trick.
3 I& `* ]# D4 K) w, ?  i-The most classical one is:& b4 c/ m1 L2 D  q* Z  ]
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
5 ^+ K+ I$ P3 f9 f. r9 C9 t, i    *(esp-&gt;4+4)=='NTIC'  Z5 `# q- [$ X2 T+ M0 d- D5 q
  T: O7 E! J# }+ c4 p
-The most exotic ones (could be very slooooow :-(. u- I$ l% r1 [2 g( F) R
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
& Y3 P) s, T% S/ W     ;will break 3 times :-(; h0 E1 z. C8 f3 q& \

4 Z2 D# v. W# Y6 u2 H3 k$ Z' F+ j-or (a bit) faster: 5 D& H( L: F7 e, X
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')& `5 W3 ^$ v& w% y+ i4 r' n

! V" F1 \3 |5 [% N4 H   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
. e  k6 u- F$ r' P$ ]0 L     ;will break 3 times :-(( f, ^/ Z# _8 B5 }2 J

  b7 ^- O$ Q4 p  J0 K- |-Much faster:
2 C# S+ `/ {1 d* `   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'+ R+ C. f4 M, ?2 s6 b
. Z9 B6 g+ b& e
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen: ~. C5 b) z: s1 w7 F* W
function to do the same job:
  m3 x6 @; }  o3 v: C+ I0 ?: L! U1 W2 c% N% X3 v7 l* M: D
   push    00                        ; OF_READ
( W; F! t* F) u& ?   mov     eax,[00656634]            ; '\\.\SICE',0
6 }2 Y6 _* b3 @4 k; ], z+ W# x   push    eax& V& l4 q. b& a
   call    KERNEL32!_lopen
( J5 s- S. q$ S- i1 @/ v7 u   inc     eax5 l, L2 h- j7 ]& k$ o# r
   jnz     00650589                  ; detected
; `4 x# M7 b/ y' e( w% m7 Y   push    00                        ; OF_READ) P: E" ~5 m7 R+ O
   mov     eax,[00656638]            ; '\\.\SICE', @" F; x0 }4 h8 ]
   push    eax
2 S3 N; P2 ?% O  s& {6 ?   call    KERNEL32!_lopen
/ w; `" F2 g0 W/ Q' l   inc     eax0 ~/ @! A- t! `/ _0 q
   jz      006505ae                  ; not detected
. n- J5 X# E( c/ k4 G3 Q/ J- V
5 g6 w4 i8 S3 I7 S
! _: v5 W# ]) {__________________________________________________________________________  B; G; e7 Q' f. u

3 ]+ J2 ]0 ~2 u( RMethod 12
& }. i# ?9 c8 X6 {) t0 W=========
' j+ K: Z  ^/ L/ J) B7 D
! o8 D, x( ^' ]This trick is similar to int41h/4fh Debugger installation check (code 05
& a+ [0 s, H$ M0 y) V&amp; 06) but very limited because it's only available for Win95/98 (not NT)
; Y7 J. C# {; c0 Das it uses the VxDCall backdoor. This detection was found in Bleem Demo.# @# }6 A9 N; x. d5 i# S, K

3 \3 b& Z& i( Q. L5 R+ d   push  0000004fh         ; function 4fh3 v9 d& G+ `0 k# [5 v! Y
   push  002a002ah         ; high word specifies which VxD (VWIN32)/ @7 H) x$ Z+ Z* Y- O
                           ; low word specifies which service
" @, l4 R& S4 r- n, _& i  w& B, ^( l% n                             (VWIN32_Int41Dispatch)
. L& D+ U7 x- B3 q2 b% S   call  Kernel32!ORD_001  ; VxdCall: z8 @2 C$ ?& d, ^/ n3 f
   cmp   ax, 0f386h        ; magic number returned by system debuggers
7 ^9 Z) K4 o) [   jz    SoftICE_detected" E$ Y' M& ~% c( c" n

& N- U0 {2 B4 _Here again, several ways to detect it:
5 p' W7 n; `4 Y! @; J
, @. e) N! T1 G    BPINT 41 if ax==4f
* `* j" _5 d+ _, {; B$ {; D, B' Q* z" r3 {# z
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
! x3 X, I: |% V( h. O5 Q2 l. @. }% j& R
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
6 k$ Q8 k; A: J3 T1 o. D
* d3 V2 O# K* T    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!# Z1 y" F8 q1 q1 u; U0 M/ O" S& F
  k+ _; d. J- T7 ]+ k9 ^; F  `
__________________________________________________________________________
' S5 ]3 r, {& Z6 p6 Y6 K% n8 U, u/ j3 j( R  m8 I
Method 13, {, m: }* S' G5 M
=========4 P" u* z/ e  w0 [( U: g/ H

1 C$ i4 T& M  X6 X0 ]Not a real method of detection, but a good way to know if SoftICE is
9 Z( ?, b' y0 R/ o# O  o6 Ginstalled on a computer and to locate its installation directory.
) X( N/ ^5 Y% M% VIt is used by few softs which access the following registry keys (usually #2) :
- k7 `! N+ d6 N1 `" P
, `8 ]/ }3 z! j5 y& e. k-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( Q/ [. G) y- I4 _" J  g& y
\Uninstall\SoftICE
# R  M& m2 `8 G; s4 {. ^$ J-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE' V& }- J. U8 c2 T* W+ ^4 ?  R
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
, r' O- H. t5 u! c- {\App Paths\Loader32.Exe, M/ Y6 s5 ?5 u  ^* J7 ~  }8 V4 @
+ `# W9 y4 {& A+ `
* n/ Z2 s- L& Z& k: c' b& _6 ]) H
Note that some nasty apps could then erase all files from SoftICE directory1 G: }8 t9 b& |/ h% k# u9 w* C
(I faced that once :-(
" Y3 q% b& w2 D: w1 M4 R% r' y/ B2 X, B" @# a. `$ P& M
Useful breakpoint to detect it:& r) P: ]' D# c, P, h
- H3 m2 a" S6 E- J5 U
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'( D9 q, W6 ]* G" u9 v. N/ H8 b

  I9 J0 e$ }, I/ S/ a$ C; n__________________________________________________________________________
% ]* }7 ?; t/ D0 K8 K* w9 l4 A
1 ]. ?- K. z: _' A2 c: x" j; B) o% Q2 i/ t0 _  R
Method 14 + b4 ]% `- U! a8 Q
=========; T. ~! I8 r' c" u9 Z, \; Y& L. ^

4 i5 _  w2 I3 ?4 }5 Y5 @& [- O8 pA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose; B) [( K6 ^$ f4 T
is to determines whether a debugger is running on your system (ring0 only).
7 H' `( H' h/ [  Q' _5 w- O. d' Q' a8 F
   VMMCall Test_Debug_Installed; ?" R" }7 G  Q* e! T" k8 c* }
   je      not_installed
' s+ ?5 z' U" a/ b# A0 }& \  u5 B7 q& [! I9 @) |9 r7 Z; a
This service just checks a flag.3 C7 k: y( ?! o5 L6 V
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部