About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
* n4 m* P8 w0 e/ p<TBODY>; u* Y( _2 Q4 p2 E  t8 Y* z4 l
<TR>
0 G' g. M; f4 {! ?$ f<TD><PRE>Method 01
2 ~4 }: v9 @/ c# K. b! V& m=========6 O  ~% I+ T' U! p0 [$ A" c

" ^, j$ U0 s, GThis method of detection of SoftICE (as well as the following one) is
, l( k" X/ B& D6 f" A5 Vused by the majority of packers/encryptors found on Internet.+ |8 `; C8 i( P/ T! x+ Z
It seeks the signature of BoundsChecker in SoftICE
+ h2 c" q- h- s) g
( S6 o, m6 Q0 s: G- x! M2 K+ F3 R7 p    mov     ebp, 04243484Bh        ; 'BCHK'. o; `  Z' B; a9 |  J" s
    mov     ax, 04h
% n3 A7 H* F# L- z2 g' a    int     3      
* O$ J, t6 Y- g; Y6 F    cmp     al,4: n; p1 a; h8 ]5 Y7 Y
    jnz     SoftICE_Detected
' J( W2 B- }0 P, |, T6 ?! F' b" {; z
___________________________________________________________________________/ }2 z) l! G7 N4 z9 z
. o; q( s6 V0 F* g" Z9 B
Method 02+ ~1 f9 o; Z2 u4 h" i* k( b- k
=========* {! l2 D$ G2 E4 ~  u

& a" ^6 U/ {& U( ]3 mStill a method very much used (perhaps the most frequent one).  It is used- V5 k; a' }/ a3 L/ J5 i
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,6 n4 N8 [4 U! i$ v# c4 I9 e
or execute SoftICE commands...* v1 }/ j+ q7 q* \
It is also used to crash SoftICE and to force it to execute any commands& ~. N* [) p- [* _1 o
(HBOOT...) :-((  3 H# b+ B' @1 L) f+ Q
# m$ h. {0 m) K; j5 x0 Z- W
Here is a quick description:0 }" @6 o; q- Q. i( u  Z
-AX = 0910h   (Display string in SIce windows)
4 n" ?8 X- r% o# Z( B-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
7 T. E+ i: X/ Y; |6 z& H* H-AX = 0912h   (Get breakpoint infos)& a- b  l+ x! s8 `4 [
-AX = 0913h   (Set Sice breakpoints)% b% Q/ h9 Z" H3 t% o' S% ~7 t. j
-AX = 0914h   (Remove SIce breakoints): ]; e* B$ x5 D
3 _. g# c) |5 V- m  Z! V; Z
Each time you'll meet this trick, you'll see:
& ^& s$ ]* y8 m$ ?* b-SI = 4647h2 }, M2 y6 }  O& t# X, D: Y9 B% ^
-DI = 4A4Dh
5 n% J5 S# S3 W9 yWhich are the 'magic values' used by SoftIce.
3 R  J# l+ s: {9 iFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.6 g6 B2 C3 B5 s' }6 N9 k) t+ d0 q

; t- s# L- l! ]; `5 THere is one example from the file "Haspinst.exe" which is the dongle HASP" ^: z+ A8 a" n9 q
Envelope utility use to protect DOS applications:
$ W0 M! t& }/ z
$ e9 M5 O: \7 `: Y/ S* C) c' g) _$ a! l9 N, m  Z! x
4C19:0095   MOV    AX,0911  ; execute command.
% |; v- g- Z* M3 @+ y" V6 d" S4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
( e/ Z3 y" H  s( T/ E1 X4C19:009A   MOV    SI,4647  ; 1st magic value.& l. q2 _+ D& N  R9 {) o) B: F
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
0 n& Q+ L; H; }! ?5 y) g* z% b2 Q4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
! s5 C* {" C0 o; w) J8 U( {4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
( E- t& S+ O* |3 M4C19:00A4   INC    CX. t. k0 ?; C+ X; o
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute% `8 {7 {. T# _5 U. `
4C19:00A8   JB     0095     ; 6 different commands.
6 u5 t$ O7 O/ c, ^2 ?+ A  O' s4 y6 C4C19:00AA   JMP    0002     ; Bad_Guy jmp back.3 H" H! T9 L( `* P
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
: R9 t' h7 L# e4 a) t* U, b0 r$ g$ f/ _7 \2 n7 O3 I
The program will execute 6 different SIce commands located at ds:dx, which
5 b0 z9 ?8 k2 p; r% ?: aare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
  J% ?! b6 \. l# o2 J9 Y; c/ L/ K+ b7 O- O4 ~
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
" N4 V0 ^5 R. B2 q___________________________________________________________________________) N; G: F9 }4 M2 R! O* k* R1 ^
6 C* D& M3 {3 g; S

) @5 D! u5 {! s' ~7 t7 N" mMethod 03
8 g3 m6 Q' M+ S. p3 W=========
8 W! n, f2 o1 m% @
3 D- P7 p0 r" ILess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
+ K0 X9 s! X( r1 X: S  l(API Get entry point)( e8 ~& Y( o5 R0 P" u" x; g7 d
        ( Y4 T4 S, f! ~

- S; i' X1 N  I* W, Z1 I# h    xor     di,di& N- o9 K6 U  N7 i  n. A
    mov     es,di
6 W6 z& N0 u  I, `    mov     ax, 1684h       & n" |& t3 D& w- S8 K4 m
    mov     bx, 0202h       ; VxD ID of winice
' G/ x  _  B  M0 i4 P  L  O) U/ ~    int     2Fh+ j+ X, L4 Y* a( L% P
    mov     ax, es          ; ES:DI -&gt; VxD API entry point5 |9 {5 [6 Z* f
    add     ax, di! D* L: c9 x/ _* s
    test    ax,ax
7 i& V4 ^- L+ J4 p, \- \    jnz     SoftICE_Detected$ x9 d4 I8 p5 }! x# [

' S# g! X3 V$ h# u; K0 A___________________________________________________________________________9 g" }2 o( z& A4 @4 K7 h. C

, @3 z2 l, w% w' i+ m& a7 F, mMethod 04
: _: A: }3 t0 M7 P/ F=========: Z. [+ i8 h) w2 ^

( Q0 l1 W  s2 D- N8 ]' cMethod identical to the preceding one except that it seeks the ID of SoftICE6 V+ @+ {! p( J- P" t
GFX VxD." ~! O) v& C! A7 `- }7 i* R2 a5 I
+ _3 ~' i3 S( i9 t  p
    xor     di,di# ^, L2 G9 C' }" `
    mov     es,di
  a+ J7 F5 M2 Y    mov     ax, 1684h      
2 l6 f% T0 O9 l" z% [    mov     bx, 7a5Fh       ; VxD ID of SIWVID
5 I/ G& A8 q: _* |6 @. u    int     2fh1 x- L% S$ t: }! _. z6 x" i; d2 O
    mov     ax, es          ; ES:DI -&gt; VxD API entry point5 v- j, S8 Q* |" |9 F) q
    add     ax, di
  Z+ ~6 `9 }5 y* J; ?  _    test    ax,ax
/ d6 f0 |) X/ k) ^: i7 H    jnz     SoftICE_Detected
- k; U8 S% q) f. x% C! C& q
; |1 N; a4 C2 q; v1 w2 S( w__________________________________________________________________________3 f% y$ n) W0 v2 V) d6 `

5 K' E% X: {( r( ^
3 u( F7 I3 @' @5 F" V5 M' U* [Method 05
# w( j1 I; w. U  @( O/ `=========
) G; X+ k5 Z; N$ z
0 |& I0 S6 G; a) L; yMethod seeking the 'magic number' 0F386h returned (in ax) by all system  w5 F, t3 c( \: Z
debugger. It calls the int 41h, function 4Fh.
- z  U6 p* Y* ~$ O* P; GThere are several alternatives.  8 P6 f# `7 b' k1 Y5 N2 _
' t" v: B" Q- s& Y
The following one is the simplest:
. v* Z# f, J9 B1 [( t$ B9 x# ?$ L: ~/ d/ ]. {, X+ T2 `
    mov     ax,4fh; H7 [+ |: S2 r+ D* B
    int     41h
2 q3 \( Q, w) m  p. L- e  D    cmp     ax, 0F386
0 [  L8 j  j! u7 l: Q    jz      SoftICE_detected
* K0 _) N6 ~3 T4 J
- P3 H2 z) y/ Z& g8 q* u" ~: q, i! [: y  }) S: M
Next method as well as the following one are 2 examples from Stone's " P7 B$ ~* j: l0 `
"stn-wid.zip" (www.cracking.net):
3 S: c) y( C- U; u, V) }+ x% P
+ T% j# f; v8 @    mov     bx, cs, x3 S: s! ?7 p( S9 i. o7 e
    lea     dx, int41handler2: W, G9 U7 c- w# u
    xchg    dx, es:[41h*4]
) F! N+ p8 c. `5 x1 G    xchg    bx, es:[41h*4+2]
  o4 z, V+ T( O: d& Q" R    mov     ax,4fh) ~& b; K( L+ `, ?0 X8 j
    int     41h# _; u! l! g6 ~
    xchg    dx, es:[41h*4]
. o9 E- G4 {6 _    xchg    bx, es:[41h*4+2]
1 o3 p, F! P1 B* `% {% T7 q    cmp     ax, 0f386h
' A7 O1 R- \3 N, S: L, \4 Q    jz      SoftICE_detected
; j( M% E: U3 ~7 |7 p, d$ K9 N' L, H4 }1 n, Z, y
int41handler2 PROC/ h! ]8 P, N9 {3 B8 v' C
    iret
- W$ l1 w' ^( ~9 Z' oint41handler2 ENDP
% E, I6 I* M2 c# m
1 D0 ^" `/ S8 j% k3 o7 d) ^) a# U3 }
+ q9 P  @! m( g( D/ |: W4 ^_________________________________________________________________________
) Z# U9 M( E7 C7 r9 e, t1 y
- M7 _( U" Z, h. s1 R# c" g7 Y* _6 T1 Q! F& T- U$ K7 z3 o
Method 06
" a/ Q! e$ n) i=========
. y- C7 d: i3 w* d! w8 A  r  h: r# K6 Y0 d* f4 c- B6 p
. o! }8 v8 A8 i1 v2 A0 z
2nd method similar to the preceding one but more difficult to detect:0 Z7 I& ?+ M; I8 Y7 E6 L+ Q( c! H

; f2 \! H3 W7 X' j2 q8 h4 f3 |
5 ~5 ]1 Q' Y. a+ j" Jint41handler PROC* U9 u1 s) `% N2 w
    mov     cl,al, O" J7 ^, S% Q5 |1 w
    iret
0 ?  Q! w) e  A( f' J% r% z4 ?' Cint41handler ENDP6 W/ ]' x! Z. r
/ {+ E3 c0 X; `7 ^1 g! z

" R9 S  O, p8 u( O3 X5 H    xor     ax,ax9 }6 X! f; G5 J0 A
    mov     es,ax
* i) d+ u5 E( g7 m, ~: @% ?+ T  n    mov     bx, cs
* L2 F7 `, g4 x9 @    lea     dx, int41handler& E# p( l- t) R, x9 u& Y
    xchg    dx, es:[41h*4]
: {# n7 S3 ~% _2 k8 o    xchg    bx, es:[41h*4+2]6 l9 r( l$ m/ |! G/ Y
    in      al, 40h$ h; k; |% t3 [) C, f, E: {% t
    xor     cx,cx
0 L- A3 G1 h- G7 J2 s6 X    int     41h
, M  _) t: L9 Z* S: n9 l0 s    xchg    dx, es:[41h*4]9 j. o) Q# l) ]7 o/ r
    xchg    bx, es:[41h*4+2]1 Y% Q* A% u( U8 P9 W" u
    cmp     cl,al
5 D4 i1 K% N+ b0 \7 I5 G7 E1 x: y    jnz     SoftICE_detected
/ Q3 K" F6 @  H4 p! h: F$ I9 N  u2 T+ b
_________________________________________________________________________! y% S  z% B6 X7 e. i
8 [* m* c( r1 q6 Z7 h0 }2 {8 r' [9 }
Method 07- ]( m+ A) k: J$ \+ M
=========
. C* A: I0 X6 H; ^, y2 Q8 V
2 B  Z8 ]# I! q# N( LMethod of detection of the WinICE handler in the int68h (V86)
( B/ y( A5 W0 T
( |/ U1 r  L, w# f% H0 V    mov     ah,43h
! y7 l9 c4 S* k    int     68h, G: o7 k: j' q: `( U
    cmp     ax,0F386h
3 [8 ~) c4 Y/ Q: L  S" P; c7 q- E    jz      SoftICE_Detected/ b* @+ L$ u4 F

8 P: Z& b3 Q8 M3 ]5 A  l" h1 L1 m/ b- C" ]  ]
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit1 x5 w4 |4 `" s& b4 E
   app like this:
: H: Z" t9 c5 l! I8 d# g1 ~, m6 [: ]& k" [+ `: Q* I4 V& L( V8 Q
   BPX exec_int if ax==68
! d. w& v, p! m$ l   (function called is located at byte ptr [ebp+1Dh] and client eip is! J7 U$ a# v! `2 f8 b: Q$ r) U
   located at [ebp+48h] for 32Bit apps)  _$ h& q  _* y$ b6 |7 {
__________________________________________________________________________
% R. c' Z# o% ?/ T, b' M
4 e5 t) b. T# {% \8 E6 _
" X  ~8 _$ c; l: U2 d* p8 d+ i4 ]0 kMethod 088 J% ?/ N7 q2 u1 @- T6 X
=========/ D, \6 w8 U- V/ ~

' \4 ^0 ?) e' c5 c$ ~- j1 ]It is not a method of detection of SoftICE but a possibility to crash the
& S: \/ w, v* o: Y3 usystem by intercepting int 01h and int 03h and redirecting them to another
- M+ b& A( H8 f9 E7 x% nroutine.
) J5 D: g6 l8 V8 U/ ?It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points+ V1 f+ F# J& ]7 V
to the new routine to execute (hangs computer...)
' m* m5 H* H  k7 V( R7 g# }2 t- r& I7 A
    mov     ah, 25h
6 {5 O8 m7 H$ \/ h) Y) i    mov     al, Int_Number (01h or 03h)
$ l# ^! ~9 D4 L. E, u8 \3 Z( K: W    mov     dx, offset New_Int_Routine
5 a* V8 L# y$ E0 f  w' j/ u1 i7 p2 _6 C    int     21h
9 {6 x9 r7 F3 |1 j) M4 d+ e" ~
  D! h0 ~# t: N( X/ z/ J+ k__________________________________________________________________________
; a. h5 `) V( G% T9 _( v$ a+ F
/ |3 |4 M! I4 x3 NMethod 09
+ _4 U' q2 }0 e0 ^+ R2 {6 j' }=========
1 u4 y% P4 E0 x# i
4 Y8 x+ k9 z% O4 l8 n' {5 M# WThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only) [* K. P( e: k: q2 f
performed in ring0 (VxD or a ring3 app using the VxdCall).
5 w7 a3 ?" ^- D/ J" {The Get_DDB service is used to determine whether or not a VxD is installed
9 N8 D, y7 E, h5 ]( k7 Lfor the specified device and returns a Device Description Block (in ecx) for
) R( M9 M) }3 `& M( B$ w4 v* pthat device if it is installed.
& P" E3 ^0 i/ t* ]2 r# }- K7 O, R* D, @# L" {+ g
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
& i4 d2 m3 n  y  `   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)  x+ b! z; D& {$ g4 j
   VMMCall Get_DDB
. d. c9 o- s* H% L   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed  M9 {$ J5 }1 N% D: r6 U$ j( p% ]: j

! O  I. R/ X, h  N2 ]Note as well that you can easily detect this method with SoftICE:; I. k& K6 K& B
   bpx Get_DDB if ax==0202 || ax==7a5fh
: }; N+ t$ v) V3 k
  f# G  E8 D1 l( \" C__________________________________________________________________________
4 ?& H  [5 z( X( D6 Q9 ~
2 _7 c) l& R# M) U1 S! x+ x# SMethod 101 \& ^4 h1 N- r% i; I1 W, c
=========, R8 M+ x$ B$ ~) V( r0 y. G
- g# {$ |% y: p* t- X/ H! u
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
( B: l! j3 H. @- Q  SoftICE while the option is enable!!+ K$ R% A& u) R; G- ^& v9 @
2 y  |5 J* Z  y: w6 z  |
This trick is very efficient:# P4 [2 R% N! F6 \" _
by checking the Debug Registers, you can detect if SoftICE is loaded
) b) x7 `9 m* Q" U(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
+ [8 j4 _- C; F5 Mthere are some memory breakpoints set (dr0 to dr3) simply by reading their5 N1 M$ `" R1 h  U  y8 x
value (in ring0 only). Values can be manipulated and or changed as well! h" e) |& E  }1 [
(clearing BPMs for instance)+ t7 e# r& u! E8 m" B5 a5 C
$ O7 v9 g/ N% M5 T7 a6 ?8 c
__________________________________________________________________________
; C( f, u: ~' A5 |; d9 X! y6 B, W$ _: v+ h4 L) s2 @" A
Method 11
, |/ j  @2 b$ U! H3 B. i, l# H4 }=========
; ?- g! d1 g4 B) M: o* T, C; [1 J
9 @! N( T/ ]% m1 d3 ^This method is most known as 'MeltICE' because it has been freely distributed
. D" J% X: P' c$ y& I* y" Fvia www.winfiles.com. However it was first used by NuMega people to allow
, `- k9 @  q9 i, Z* j. O5 ySymbol Loader to check if SoftICE was active or not (the code is located
( H3 q/ W. y- Einside nmtrans.dll).
$ y9 G: I) u( a. |
5 U. I: L0 R5 ]! XThe way it works is very simple:. {# d" l5 D. `6 ^9 y- Z
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
6 \3 m* _3 ?& bWinNT) with the CreateFileA API.
) t6 c2 D0 e8 l/ F# p+ ?/ L  C" ]- y" d
Here is a sample (checking for 'SICE'):; N0 z" d# B- B$ Q9 e. P
& D* s+ {5 @: ~7 _# ~" F0 Q
BOOL IsSoftIce95Loaded()
3 u1 Z4 ^+ B, E{
1 h3 {5 }6 C+ h8 D4 t   HANDLE hFile;  8 I6 a9 P$ N- T0 J3 p
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,' w8 R4 g( R9 f+ R, o3 e  E- X
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
' U- s" r2 i2 A" j0 q                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);* D0 _: d, R6 o2 I7 S- l6 P
   if( hFile != INVALID_HANDLE_VALUE )( s! V3 G1 Q" J& w$ s0 J/ u0 S  P8 z
   {
6 S! j  E& e4 z# L- Y      CloseHandle(hFile);
* f! J6 @$ I0 i2 i( {      return TRUE;2 K. E. W6 x" K% ~9 R) M7 n
   }- c% k- D6 u- f  h* }6 U2 e
   return FALSE;; c' K5 A, W4 g& {8 h* ^
}2 S* f+ T' _9 H8 A

) N0 U0 V6 b. cAlthough this trick calls the CreateFileA function, don't even expect to be* i0 J3 r( [& b; D3 j& ^: f
able to intercept it by installing a IFS hook: it will not work, no way!  M/ p% B; m& X
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
0 p# T' J& [1 @' pservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
. r( C6 O4 V3 K9 D& E# w3 t7 w8 u8 B" {and then browse the DDB list until it find the VxD and its DDB_Control_Proc
* l* i( i+ Z9 H3 nfield.& t; U9 G  w4 d2 w, t9 u$ t
In fact, its purpose is not to load/unload VxDs but only to send a
% ^) n6 T  N4 y0 J3 H+ Y) JW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
* [0 _+ f8 P1 v0 h. {( Vto the VxD Control_Dispatch proc (how the hell a shareware soft could try
8 Y( p0 G$ U- [) ~; ~/ o4 V/ d  I$ \to load/unload a non-dynamically loadable driver such as SoftICE ;-)./ [9 U0 h" l5 G5 O
If the VxD is loaded, it will always clear eax and the Carry flag to allow
+ S0 }* a' [; W7 w  ?3 I4 `' E# uits handle to be opened and then, will be detected.2 U# V7 R! s% y+ s3 j; m# ?& P
You can check that simply by hooking Winice.exe control proc entry point
+ L# T6 e: L9 F0 twhile running MeltICE.& t6 s/ l8 ~/ B) u5 r! C, y

) g+ r$ T0 G5 ~- W. q! M. @1 P+ Y& t/ L$ }
  00401067:  push      00402025    ; \\.\SICE& Q) @  [8 k3 l6 Q2 I1 y( [4 Y8 z. [6 k
  0040106C:  call      CreateFileA5 u. T  Z2 c; \! E
  00401071:  cmp       eax,-001
1 {4 P* f, M" X2 W7 `  00401074:  je        004010914 ?5 Y9 M" R; c% j! i$ ~6 q/ m

+ I! r# A8 T& r  A3 B) @* h- D( w( m$ t0 L3 v+ z
There could be hundreds of BPX you could use to detect this trick.
1 a# L) G" N& \" x" Y5 {1 A& X-The most classical one is:5 k8 z4 `! r2 X8 Y
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||, ~. C& a# V7 a, V* w
    *(esp-&gt;4+4)=='NTIC'
9 k) N4 B7 t# w% \5 h
" h+ G" T9 M$ Q2 J  `" |8 i6 ^1 Y-The most exotic ones (could be very slooooow :-(
% {( g) k- ]! c; b  C: Q- X: J   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
2 n1 h$ }8 J" b# O! `- w9 B" l     ;will break 3 times :-(3 T+ C/ r2 i' @% j# s( a3 X
" K2 @3 ?4 ^# N; G+ g4 N
-or (a bit) faster:
2 s0 Q% v3 K2 ^8 x& E6 U* k3 g   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')! H! j  }4 m2 w, I# T; Q

% F+ c. c8 Q; e6 \! k5 b$ F   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
( R, B+ _. m- D2 {! K+ R     ;will break 3 times :-(
) W! Z8 h; I2 x% e4 p0 b
, s- k  \6 n, P+ b' N% E-Much faster:
  {+ X9 x  T' T- c: `   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
$ d' Q/ W, K  \- |% t# z( q; }6 _$ W* [! {
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen8 i" \8 o4 @* h
function to do the same job:
, K" f, F  r1 A* L1 Q+ T
+ s7 n6 D7 ~& b   push    00                        ; OF_READ
1 n9 n5 }& X, Z1 \   mov     eax,[00656634]            ; '\\.\SICE',0
/ T; g6 w8 ~; H0 A8 o8 d   push    eax
6 k- R* l4 {, `1 R   call    KERNEL32!_lopen
+ {/ C$ p8 q/ J, V   inc     eax, X' q# G2 Y( {' `$ }6 \
   jnz     00650589                  ; detected
6 H' L6 L# }: C) `' Q% ?% v/ r" K   push    00                        ; OF_READ
$ T: L! M4 X4 g5 v* J9 G; Z$ h   mov     eax,[00656638]            ; '\\.\SICE'$ w9 {) n3 }# O4 _$ _
   push    eax
( p% m& a2 G' ?+ B$ N   call    KERNEL32!_lopen
+ s4 ]8 W7 Q$ w7 M& ]   inc     eax5 v: E5 n0 t5 a9 [7 h% q1 _
   jz      006505ae                  ; not detected
/ U& D" a! A9 f. [9 G1 z* N2 ?8 E/ H' h" U$ B% Y0 \
3 K5 ]- m& y) c- c9 H
__________________________________________________________________________
. S4 H+ t/ U/ f6 L! F$ {8 C* r/ A" H  W
Method 12
; b9 k. a9 A6 A# X, [=========; J6 ?/ I( n" z5 ~
. z) [. i0 V9 J' c9 q0 v9 l" |
This trick is similar to int41h/4fh Debugger installation check (code 05
3 y6 ^, @; U! T" [' @9 O&amp; 06) but very limited because it's only available for Win95/98 (not NT)& W9 B. E; q5 c  ^
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.- `' D* C/ X& q7 Z1 J! R( S; Y
6 [* o5 z; D" x
   push  0000004fh         ; function 4fh
: G/ H4 L( O" \( O; Y3 n: r. X   push  002a002ah         ; high word specifies which VxD (VWIN32)7 S$ U: @, q5 f/ o' z8 i& f0 \% M, S
                           ; low word specifies which service
  a+ j( ~( |' F6 M  R' q                             (VWIN32_Int41Dispatch)4 ]; A# |2 u6 Z' |0 F0 ^9 h
   call  Kernel32!ORD_001  ; VxdCall
6 l9 u, T' k  N0 L% D1 v0 m0 w   cmp   ax, 0f386h        ; magic number returned by system debuggers
5 L' u6 {7 ~7 i, _* |, \; R1 V   jz    SoftICE_detected
- r& \! x7 y( h  z
; o- r7 ~! z7 D0 @1 _/ ^- [7 c* THere again, several ways to detect it:! D1 _& }1 M  D, T

" g; i2 R+ z, I. p( x8 l    BPINT 41 if ax==4f1 j% ^5 K! q: ]6 h7 I
7 `  P0 U2 a* b; q' O. S
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one  a2 y& q7 j2 s1 F6 S

6 q3 p9 N7 _4 c4 ^& [    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A* F% w+ Y+ {- h, D8 X, u4 k  O- I7 S' F

, O  f1 \7 R9 n2 [, q" d0 ~    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!4 P- m  t3 W+ k# W% e8 W5 _- K; Z' W
9 v: W& f" r: s
__________________________________________________________________________% x4 n& w, h+ _; X& g
! r' x5 Q6 z: D7 z
Method 13: h- ]4 T* v- t2 J
=========" H# r9 \5 S+ H; P7 i, V

. @. A; z1 `$ j0 UNot a real method of detection, but a good way to know if SoftICE is& ?- a9 f# F9 E6 J
installed on a computer and to locate its installation directory.
& h' j$ f9 U$ x# h8 y! X/ yIt is used by few softs which access the following registry keys (usually #2) :
% a6 c3 J$ |( w. A
- {0 a( a# K1 }9 f-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& \& ?6 ^+ e4 S
\Uninstall\SoftICE  c/ o, B5 P5 C: v& B+ D  w
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
, P% P2 R$ M# @, g-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
+ l. Q9 Y! A4 b- Z* F\App Paths\Loader32.Exe
$ r4 {7 H) K6 m. g8 X1 h
" R& ]- J: p; r/ v# G& i- a; V& ]6 P: F" Z8 @# P3 c
Note that some nasty apps could then erase all files from SoftICE directory
+ R  j8 T) z' b) D(I faced that once :-(9 T4 V7 f+ _3 _4 V, x! e% N+ N% V
  j% Z: \" a& M! M5 m4 M" b
Useful breakpoint to detect it:
( E5 {+ g$ W5 g( Z( {$ S. J$ Q8 R2 k5 ?; S% |
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
3 T/ [  U, S5 v, `5 M
' A0 w+ K5 @# F__________________________________________________________________________
( u0 O* l! f' I: L( f7 J
! H( [6 G1 F: C2 n% `
" g1 ?: S( J0 p( O% sMethod 14
& ^1 k7 g# L5 G2 [# Y0 H1 L=========
; Q6 N. _8 i- `) R2 J4 }
$ d" N* j( G1 kA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose6 H. e, x. h% T; @% b$ L1 T
is to determines whether a debugger is running on your system (ring0 only).: p7 i% n% f" e! y! F' F' L1 C& J) Q
$ @: m' s1 u8 Z" c% e: Z: _6 a
   VMMCall Test_Debug_Installed
) b# D& q% s: t' z& |4 k$ g   je      not_installed9 k' t; Q  x! `5 L1 g

/ [7 r$ x9 u$ N, k0 ^: V5 A, L3 lThis service just checks a flag.' T8 B( [2 e5 L
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部