About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>1 B( R# I3 S+ T
<TBODY>" h+ R6 A4 a+ ^7 Y
<TR>8 S! W* s2 a  y: m8 l$ u
<TD><PRE>Method 01
1 ~. H  d3 ]+ A5 ^- j/ z=========9 Q$ ?' b7 Z" b: @

% j: \( }/ q6 ]  aThis method of detection of SoftICE (as well as the following one) is* C+ K4 H" B3 A" S/ u# O* R
used by the majority of packers/encryptors found on Internet.
. c/ w) B4 N' K2 z" e0 g. s1 ?It seeks the signature of BoundsChecker in SoftICE  ]; W2 ?+ _3 W/ E4 o. z
. v% i( a( s% q, E& U: _  _
    mov     ebp, 04243484Bh        ; 'BCHK'
& I. h+ r  B) H) D! |: C( m    mov     ax, 04h
" o9 p, b5 {6 }9 ~( F3 z- y    int     3       # O1 F8 D9 J$ B8 y, n9 Y
    cmp     al,41 e* y4 Z1 o# c
    jnz     SoftICE_Detected0 U2 Z6 W9 C) m1 ~( O
7 `: \- @& `1 P7 z0 S
___________________________________________________________________________
, y! T. d4 u& E: R: }# d* f) ~: v2 g
* R1 T7 B7 d5 QMethod 02
. o: A3 u8 V, t* ]=========4 ]/ `, I5 W9 M5 r( }9 O. S  E8 ^

$ D9 c' u: W: z" vStill a method very much used (perhaps the most frequent one).  It is used/ Z( w8 o2 e6 I# w. g, f; J& j9 f' Q
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
6 U, q. @- j& `or execute SoftICE commands...% W- ~, U+ F* \
It is also used to crash SoftICE and to force it to execute any commands! W( B( i4 Q" X9 X! f: P
(HBOOT...) :-((  
, l( W4 ]. Q. M9 b4 ~3 z5 ?5 Y2 q2 D2 O; |. l4 {0 c) y
Here is a quick description:
; B3 B; x6 x. x' y-AX = 0910h   (Display string in SIce windows)
- O% x7 n- |9 d0 v3 X  s" v-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)2 g9 O) B1 ^9 \
-AX = 0912h   (Get breakpoint infos)/ Q; `1 Q$ L) {. j$ w: J
-AX = 0913h   (Set Sice breakpoints)" o- o" s5 d, d  ~$ I, s( {5 E" x; y
-AX = 0914h   (Remove SIce breakoints)1 B: {7 s8 h4 v, F, ]) k; ]+ X

; z7 F& d- a) Z- K, w/ R# tEach time you'll meet this trick, you'll see:
. W5 e+ x$ e# B+ {-SI = 4647h: {# y& B, i) t% ?+ k
-DI = 4A4Dh  `4 X3 Z# ]7 u+ D0 m5 l
Which are the 'magic values' used by SoftIce.5 A0 f: v( i& y! S' V" l
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
$ e9 n( d' x! V& e+ [; s6 t4 Z/ a0 X9 Z- P$ n- T5 |" j9 ^1 l
Here is one example from the file "Haspinst.exe" which is the dongle HASP
- p! h- X% n3 y2 [8 UEnvelope utility use to protect DOS applications:
5 r8 v+ y* g) W: \  u% m7 c2 x  o0 \8 M, W% Y

+ J9 l6 X$ e0 Z9 f/ z4C19:0095   MOV    AX,0911  ; execute command.
/ Y/ D& `; T7 ~  G; N4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).. A+ x: d: h+ c, q1 d+ J0 S
4C19:009A   MOV    SI,4647  ; 1st magic value.
2 T# D4 z2 Y$ _4C19:009D   MOV    DI,4A4D  ; 2nd magic value.) T: `2 I1 @; g# j; e4 w8 f3 z
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)5 D( K/ Z/ ]0 X! E* x
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute+ n  b1 S1 J" H8 t6 [' p9 {, ]
4C19:00A4   INC    CX; G! K/ v( j% X* d! @" S9 }/ `- o) t
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute4 ?9 p( L, N1 t' j. H
4C19:00A8   JB     0095     ; 6 different commands.
9 U" G+ D% S1 X3 G3 J1 I# m/ n4C19:00AA   JMP    0002     ; Bad_Guy jmp back.4 c" [6 |- G3 l9 P2 f4 X5 J6 j  `
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
, x8 ^* @) o2 C5 A' T" d. q6 ^$ f7 ^$ w# h+ H3 {
The program will execute 6 different SIce commands located at ds:dx, which: E0 r5 Y. c& j4 w. _
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
( M5 H6 y" K, \+ C, N. O1 K5 Y
, K# ~5 J2 `4 G* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.( x) A8 ?' ~& b7 a% q- S9 ]
___________________________________________________________________________9 `  d) _$ Q1 R
( f' h. _+ A+ a" Z

( s2 m' _7 ^8 N# w. n7 PMethod 03# S" x7 o6 y2 {) K/ o8 G
=========7 z4 d9 h# G( {9 g
+ T- Z, |: B6 C% l- I2 Y/ T
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
% H+ b: H! ]4 _, M8 [& P- a% r(API Get entry point)
- [: @9 M6 Z+ d) `" f        
! `: R/ M( d9 l. ~7 Z& t. `9 D, U9 K  v* I: G( T1 o! y2 `
    xor     di,di
/ t! q# q5 O3 m$ p) A0 X$ _    mov     es,di- r( p$ Z- E6 ?: Q9 E! s$ C; X4 [
    mov     ax, 1684h      
1 j! O4 |$ ?2 D, j  B' K6 g    mov     bx, 0202h       ; VxD ID of winice
5 }0 t) p, T4 S    int     2Fh" l1 t' m" Y6 l: c2 q
    mov     ax, es          ; ES:DI -&gt; VxD API entry point4 c4 e1 d6 n- W, f. @) [: `7 _) U
    add     ax, di# M, P/ w# e) ]$ o( v( V0 D
    test    ax,ax2 M; x9 }2 y" U" {& \
    jnz     SoftICE_Detected
) u3 g0 k1 x# o( `/ r
! X" P3 S! W3 w; S! t* v8 i, U0 R___________________________________________________________________________
% x3 _, T  q8 f8 P
: A  v7 B) z3 F7 v; N% r" [* yMethod 04$ ^) O. K7 r" F3 V) L. o* J# |
=========
! r) ]: }6 r5 M; l3 y
& v9 s8 c7 r7 o: tMethod identical to the preceding one except that it seeks the ID of SoftICE( Y! o# _- i6 h& A
GFX VxD.$ J7 Z% d* ?5 w; x* t, ]' S

! \) v* I1 r2 d    xor     di,di. E; z# h) D# {1 w7 e. E. ?3 m
    mov     es,di6 S" x# ^4 |- Z# M2 K1 Y* m2 Z# b
    mov     ax, 1684h      
, v9 }  u' y" e    mov     bx, 7a5Fh       ; VxD ID of SIWVID
: w; c' s8 v/ T# U( X* y4 V0 J# ]    int     2fh
7 _; y, ~: \: r7 P# P) ?    mov     ax, es          ; ES:DI -&gt; VxD API entry point8 R! n4 \0 ~  P8 j. O
    add     ax, di. s' x. b. Q; Q7 `& Q, V& j
    test    ax,ax  ?& h, }& k% q" J9 q6 S- m
    jnz     SoftICE_Detected
6 P8 K* K6 G6 _+ P5 b% q
- i% k) x* F- F) R! k8 [__________________________________________________________________________4 y- c" f! r3 d4 ]
0 S! Z% ?( G" p  R

" v% w$ f" w8 e+ U8 e7 ?. JMethod 05; p7 D. [0 e) d3 M2 y: }$ v
=========
8 h$ @4 G8 i; A  X
3 E' e3 k5 z: wMethod seeking the 'magic number' 0F386h returned (in ax) by all system/ X) e/ `$ t5 v) T9 L7 X
debugger. It calls the int 41h, function 4Fh./ c& ~0 k' Z' ^; f/ Y
There are several alternatives.  7 N/ Q1 I0 z, s$ C& P+ D
& M9 l) n  E( n) T5 f
The following one is the simplest:
, N$ ?% G, v  Q. u: X* P9 d' Q% }( Y2 V$ Q
    mov     ax,4fh" P$ G* p: I* D0 d7 o( b
    int     41h
' K9 @( z" U1 G) T* h% m/ u    cmp     ax, 0F386+ S; H6 ^, f# o9 j% v5 D& P+ i, r1 W
    jz      SoftICE_detected
. w6 T3 c: l+ g8 M" X) e( |6 o& @3 P

8 U+ i4 i/ Y1 M4 y7 _) uNext method as well as the following one are 2 examples from Stone's
% X, ^4 E, x- N" P. Z"stn-wid.zip" (www.cracking.net):' E/ e4 P: T! m1 \' K
$ e# `$ E3 R2 g- c
    mov     bx, cs
% R- M1 c) ?$ L7 h% ?' {4 B    lea     dx, int41handler2
! N7 j( M9 [+ k+ X' e% x1 r    xchg    dx, es:[41h*4]
' s1 G0 u: z& l- A2 W    xchg    bx, es:[41h*4+2]) C2 \$ |& h4 D$ a
    mov     ax,4fh
+ S4 E( `& q+ W2 g: M" V    int     41h; d( n8 P4 ?* p5 E: H9 F' V" h
    xchg    dx, es:[41h*4]
4 J' c2 k7 E" c& H    xchg    bx, es:[41h*4+2]
( j/ r, O- g+ F8 t! A7 q5 {    cmp     ax, 0f386h
, U$ M6 O, k  k: [8 d    jz      SoftICE_detected
8 U5 q- L# m  E: \' z0 I( P* V+ o* S% U# K
int41handler2 PROC5 b2 Z+ T* j; `
    iret9 u" s' s$ U! i4 k& V! Y8 u
int41handler2 ENDP
5 ~9 O' ~7 [+ a' ~. |$ Y! L& i; b
0 H) \: V1 y7 a) y' u$ H- b9 w) Q" f2 ^3 T
_________________________________________________________________________
7 d- f/ E8 w) s; v' A3 a
; W# q; J4 V( C  w& ]5 K1 [, O8 K
/ h2 u1 ]3 X+ |) {" LMethod 062 ]; b, Y" J+ U& F0 s- G1 K
=========$ }4 }6 Y7 m3 Z; A" h. D  m& S

& n4 {$ u! I0 y
6 M8 O' E: ?5 B% _0 N1 x, D7 _$ @! v2nd method similar to the preceding one but more difficult to detect:
8 o+ x' k" ?5 `6 W  y
- `0 D( u; M9 Z  s. n/ a2 a) c  e0 e- q# p; S& y( d
int41handler PROC  A8 C( M0 R! ?" z7 t4 M' `! O' q
    mov     cl,al
; `- C' n7 u1 F4 t    iret& i1 j5 U* I* U. x
int41handler ENDP
) s/ L3 `+ Z- u% j2 {/ s+ S! e; G8 [6 @, ]3 A

  s' Q) I- O" u    xor     ax,ax
: }) p3 L1 a$ A" S* q5 O! u6 s+ ~    mov     es,ax
9 p, s( n  x0 x    mov     bx, cs
) K$ b* G1 `# I6 s+ n    lea     dx, int41handler: h2 p/ V7 N, D& B
    xchg    dx, es:[41h*4]
' ]4 M: w: D! g9 |, \) ]! r0 B    xchg    bx, es:[41h*4+2]
9 I; D7 K5 T) }! L    in      al, 40h
' j  p! P: A) x, n! E) t) _    xor     cx,cx: ^$ N  x" ~3 w: Q; H5 K$ S% U4 r
    int     41h2 U4 T9 r. ^2 S7 |. T
    xchg    dx, es:[41h*4]9 Y3 A4 X' _/ c0 D! {4 Z, Z, m: e
    xchg    bx, es:[41h*4+2]
# P% H- l0 x2 S* Y4 H' C# P" B4 R    cmp     cl,al, G4 v) A* n* a& z
    jnz     SoftICE_detected
% T; k$ x) z6 ]! J" E+ ^5 m& D! }* g8 t3 n* u7 G" k: W6 N
_________________________________________________________________________' e$ x5 [' w0 G6 T" R8 k, U
# x  T" k8 X, @6 h1 S% C# Y4 A/ Y
Method 07
5 y' v% S' i3 L9 k) K* W=========
" N& M/ q' t# g& T6 L
2 D' W3 O; Q& y) s3 G, E) f! M$ u+ w) U+ CMethod of detection of the WinICE handler in the int68h (V86)5 m4 p) N2 W. x8 ]$ @
5 w; b1 ]! q* G: o5 D+ ?3 V$ k" `
    mov     ah,43h
; I& p# e1 g, o  _! a    int     68h7 H) X9 |6 N& ~! B9 O
    cmp     ax,0F386h% ]( l" U2 \/ Q; b& A
    jz      SoftICE_Detected! z" ^1 `) U  l6 n# a

6 g2 X$ _+ d% q$ v" }# @6 G5 L4 W2 ^3 R! M8 s' {: ]' G, E
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
) |3 O2 P) d" G" i6 k7 P2 S   app like this:
" G4 N2 j3 N. k- |; }9 J/ a9 R/ K8 C, w/ l  s3 i' ]
   BPX exec_int if ax==68# I; `& R5 T5 a, ?0 c* ]( {8 s3 |
   (function called is located at byte ptr [ebp+1Dh] and client eip is% X0 t# J# J. |9 T& L/ n  ^7 R0 S2 A
   located at [ebp+48h] for 32Bit apps)! y3 _( S) s  [9 a; Q9 v
__________________________________________________________________________9 m6 {1 J" O6 ^) X6 O+ e* U
9 ~# j' F( T8 y/ |
" f# u0 Q+ i( S9 X
Method 08, @  l: p0 f" c; R8 M3 F! w+ x$ u
=========. r2 Y3 F/ m) z
5 K. J- {: w* E
It is not a method of detection of SoftICE but a possibility to crash the' N) f! x  e7 z; }* b
system by intercepting int 01h and int 03h and redirecting them to another
# Y4 z4 |) J  j8 Vroutine.9 _$ a7 V9 w! H
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points+ E+ b, b3 W$ v  J% F0 ^1 e
to the new routine to execute (hangs computer...)
. h# X5 G' j5 s) S, b- \1 h
  l8 K" I: _" {, S7 }! H    mov     ah, 25h
: c; u7 t& q9 u% I    mov     al, Int_Number (01h or 03h)$ e& c% I$ [% x! A7 }
    mov     dx, offset New_Int_Routine
& q, D2 U. e% j! w% w    int     21h
! Z/ n% J1 s2 `0 E8 B  k( J( s2 p/ R  m
__________________________________________________________________________
6 I$ u" P3 m, y
' n  K7 V" g9 T0 C8 A* lMethod 09
4 S* E3 @% T. T( ~- J+ c. d3 X4 n=========
7 {9 d: V5 x6 N9 r' c! U4 L) Z5 p2 u( W2 {% e4 ?9 G& B  c
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
# @* r/ c) O& D. iperformed in ring0 (VxD or a ring3 app using the VxdCall).0 y7 b3 X1 M; ~( c" C' V4 J' }
The Get_DDB service is used to determine whether or not a VxD is installed2 Z5 f. ^$ B3 D2 y6 R3 [. @
for the specified device and returns a Device Description Block (in ecx) for& {9 g1 ^. Y% l
that device if it is installed.+ @1 _- K8 ]. e# u2 v" J% |. ^

3 O. a; r. c9 B; [1 i( W' w5 b, ]$ k   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
* l# u) n2 V/ L! d2 d. u" Y   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
3 T$ V8 F7 T7 @1 t; h; d   VMMCall Get_DDB
9 S: }6 q0 h" B! i1 z+ R5 U   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed' t3 g* L+ r+ r3 y+ R/ s$ E0 G

3 C  x  X7 Q9 I$ T4 E7 ^% bNote as well that you can easily detect this method with SoftICE:! x6 F7 _5 N9 J/ j! Y( U2 O
   bpx Get_DDB if ax==0202 || ax==7a5fh2 @+ y4 Y) t8 \: ~4 g

' e+ K2 G+ Z, S1 {# O- C# c0 l- ?2 Y__________________________________________________________________________
8 k& A4 R/ v! G/ @
% ~3 a( B3 I# j" |. Z& [5 x  ^$ w' kMethod 10
+ q/ `" b5 d% F1 d3 s& {6 P=========
3 |1 k/ y* F3 \1 c" }# |8 {( f& z; S* j5 n- ?. g( m
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
; x* A) N" S! \4 ~' \  SoftICE while the option is enable!!
' `/ w7 I8 y* m! p+ `1 G( \+ K0 A  |2 Q9 N% w( S9 t
This trick is very efficient:
# \: g/ A/ X0 C& b5 ?by checking the Debug Registers, you can detect if SoftICE is loaded
& `( T# l* g. a0 }& S8 `- T) P(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if( W4 x" x- `) r5 {' ]2 Q: q/ c
there are some memory breakpoints set (dr0 to dr3) simply by reading their% s7 J: v2 K1 l& ^' I4 `* \
value (in ring0 only). Values can be manipulated and or changed as well' o) @2 ^* i9 h+ W$ {
(clearing BPMs for instance): w" _# X0 m7 ^7 x" C; P
" k9 t4 G( _; J- [
__________________________________________________________________________
& R5 A0 w6 Q) L- M; m, T0 z  j& |8 }
Method 117 d: s0 C8 a! _) s' ?
=========
. s$ V7 j6 q+ U; A. b
: x/ [# H8 L& e; @This method is most known as 'MeltICE' because it has been freely distributed
+ u5 @; v* O7 W1 [; V5 ovia www.winfiles.com. However it was first used by NuMega people to allow
  z& u+ x# m" c, L# ySymbol Loader to check if SoftICE was active or not (the code is located
: s2 C+ `  k' J/ W* G) Jinside nmtrans.dll).
1 Z! K9 V) [) K1 K: V! l/ G; [" h
. c1 ^# a( g3 O. @The way it works is very simple:% W. |( k* E. b) d1 E
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for# R, k' K. m3 X
WinNT) with the CreateFileA API.$ v4 d: ^% A/ C& L+ z: t: m
3 C9 k/ t4 n, Y/ W
Here is a sample (checking for 'SICE'):
  x! P  v& w1 j6 |6 t. E+ }) b$ t8 @+ u+ S" V$ u
BOOL IsSoftIce95Loaded()
' d# y" ]7 F1 w$ L" {{( d; z4 j  y/ r: R
   HANDLE hFile;  
2 S! M3 I2 |" A/ D: L9 _  f   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
  x. h0 O- ~, A( h. c% \" B                      FILE_SHARE_READ | FILE_SHARE_WRITE," H$ U2 c$ u4 n" J- J$ ]7 Z
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);4 |5 O9 t+ L: G1 Z
   if( hFile != INVALID_HANDLE_VALUE )
4 G/ w6 L  H) [) ?   {9 s; l5 `1 A* A+ A) ~$ G
      CloseHandle(hFile);! i; K0 a/ t: I- c3 d- r( E
      return TRUE;  g2 B$ [3 b5 Y
   }: D/ o; ~# h# e8 j% n6 n+ @* I% \
   return FALSE;
( p% w" {( C9 P}
# Z0 ^/ r  T9 Z+ \. N( V9 T5 d& L" w  O) c  t
Although this trick calls the CreateFileA function, don't even expect to be, q3 L- ~, V, C
able to intercept it by installing a IFS hook: it will not work, no way!
% N6 _: t/ W' o- p* fIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
; o- s* E+ p7 Uservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
* R* z0 j  ~7 G: A% e$ j  g$ c$ Land then browse the DDB list until it find the VxD and its DDB_Control_Proc: U. M2 C* x3 \1 _- s7 e" g
field.
' j- k: ~' i* w, P7 j  {In fact, its purpose is not to load/unload VxDs but only to send a
3 A  X$ ^! |! r; w: GW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
' o9 A! ?/ v) k* `5 r3 yto the VxD Control_Dispatch proc (how the hell a shareware soft could try6 r* U+ ?% [8 j; N6 p* Q. U  u2 G+ s
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
8 `$ x7 k2 ]0 Z9 NIf the VxD is loaded, it will always clear eax and the Carry flag to allow
. Q; t$ n, s; }. O/ wits handle to be opened and then, will be detected.
( m1 b5 _9 F! x% L* A+ T" m4 {. |You can check that simply by hooking Winice.exe control proc entry point
% T( ~0 q6 v) ^8 s8 q% Lwhile running MeltICE.6 D) L. l7 R$ ]4 t* ^+ }8 }. o
' q3 b9 K3 B9 U

0 }7 ]3 \/ w7 [: d6 A; P  00401067:  push      00402025    ; \\.\SICE
4 m  J  `' i2 N0 B- D  0040106C:  call      CreateFileA" L5 g) t; K8 v/ H
  00401071:  cmp       eax,-001) o, B9 d! o2 M, M# B+ `" h5 X' ^
  00401074:  je        00401091
$ p1 n) @2 ^! d, t1 f4 W, E' D3 X7 `
# v* O+ O2 _; [! B0 L
+ Y3 c/ N) u2 A# b8 @There could be hundreds of BPX you could use to detect this trick.6 \4 m, t  G( c2 Z
-The most classical one is:
( |) I0 U/ n8 v6 I! u  F! @) L& I  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||- }) A) B3 i, r
    *(esp-&gt;4+4)=='NTIC'
3 e9 R# l7 [# p' Y
, Q9 y6 l8 z, G. Z/ [& `: q- n6 Z-The most exotic ones (could be very slooooow :-(
7 G$ m0 h; n/ J+ q' ]& Q   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  : v9 R8 S4 ~+ k# i/ ?) _2 i1 b
     ;will break 3 times :-(! ^/ p, [3 o7 G' b
# a& r. L8 `& E, s7 N+ L
-or (a bit) faster:
+ N& B* T4 L5 _2 C: e7 G   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
  A$ p0 |3 p( E  T. F; V* X! X0 U7 Z4 y' G8 t0 j: B- ]5 I/ Q- J
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
# Z! }" Z# }( m8 q     ;will break 3 times :-(; f* T8 K+ u  O% x1 W! A: Z  t

: _9 X( W3 I- _2 o* g5 p5 |6 ]9 s' W! x-Much faster:- r. o# o7 a3 ]0 o
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'& ?0 K! J) N/ y' S% Q+ p" Q  y+ T

6 s$ r1 f9 \4 \& lNote also that some programs (like AZPR3.00) use de old 16-bit _lopen; a% ]+ ^% G- o
function to do the same job:
, d7 `* b1 ~) [9 C+ F( E- z: F8 Q9 ~4 O& c2 G! K+ z9 e! B3 F
   push    00                        ; OF_READ
. m; x1 }) j0 N! ?1 X& m   mov     eax,[00656634]            ; '\\.\SICE',0
$ V% i, \  x6 t/ U   push    eax' U! c, L* n2 v1 V: j" D1 n
   call    KERNEL32!_lopen3 H* t' c' n9 w* ~/ f& L7 P
   inc     eax* ]) \: ^: r( Y) ~$ G; U0 D* R
   jnz     00650589                  ; detected
- z. @, x9 u+ S4 h& e- t   push    00                        ; OF_READ
4 a7 l  M. X- n0 B, J, q5 |% L   mov     eax,[00656638]            ; '\\.\SICE'# U. F( N$ g5 I
   push    eax! c  X3 O" a$ G0 ^7 J: e* k# s! y" M
   call    KERNEL32!_lopen  ^1 p8 K, T8 `8 B. i! }5 `
   inc     eax3 u4 N0 q) z* O4 p% l6 ~& k
   jz      006505ae                  ; not detected6 w7 j& J% L. |3 Y; N

0 F, J! \4 o/ l9 u) ~
3 k: t( X" o/ B1 D__________________________________________________________________________! @9 o. I. j0 y7 Z/ q
- l& W5 v& u* q# u+ P) {
Method 12% h9 L" `  m+ i8 ]! h* n
=========  ^8 T/ k; N) R6 J- O) u' J
( B/ Y/ P; _! `. i- a7 [+ [# P
This trick is similar to int41h/4fh Debugger installation check (code 05
6 }1 z" [5 ^) f# `1 k+ t&amp; 06) but very limited because it's only available for Win95/98 (not NT)
3 o' \4 A8 _  k  w4 @as it uses the VxDCall backdoor. This detection was found in Bleem Demo.: v- Z) x+ m% d- N! M

' b5 [# l+ D  A' ?7 W   push  0000004fh         ; function 4fh; W: G! H2 H9 p' n7 f% l
   push  002a002ah         ; high word specifies which VxD (VWIN32)
) C" W1 o' `! |8 S+ I/ H                           ; low word specifies which service
% H% z1 i7 w) e7 ?) z; v6 P                             (VWIN32_Int41Dispatch)
# Y5 U$ L$ n+ s' f/ K! A9 w" t: f   call  Kernel32!ORD_001  ; VxdCall3 x, l" h/ m! W; v! O1 Z; c/ B$ Z
   cmp   ax, 0f386h        ; magic number returned by system debuggers
* L  b: Y- M( R, `. {8 v2 Q4 p& U* Z   jz    SoftICE_detected' _% X5 R* E. K. [& j' I. ~8 m
; B6 n- ]* _1 q1 M/ q3 W+ ]6 e
Here again, several ways to detect it:8 `5 W3 E; t4 P$ ?( J- S# f, S

1 t( {) ], P6 o2 e, u7 f' s    BPINT 41 if ax==4f, y5 y; Q2 A9 A7 Y

: v9 t- U' H; F/ z# h& z6 C( ?- z5 H    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
" {, D* }( i) I7 ?2 i
9 Q/ M+ X1 t) S4 j' [$ D2 V% A$ B- Y    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A/ {# k$ g# v4 l0 y6 {  }0 C
1 ]3 D% J) U; L% M
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
' e( Q: X- V4 E& J2 T6 T7 G. Z8 |; W$ l+ b
__________________________________________________________________________0 x; g; L. i4 I, d. o4 @
. H) b) u/ w. F+ [# {) A4 o1 V) N
Method 13
4 |% l* y. N1 T+ H=========
# v: M  V5 _- g0 n( |; l' q
, ^5 R$ S' R' ~Not a real method of detection, but a good way to know if SoftICE is5 J: L6 T( ^$ k
installed on a computer and to locate its installation directory.
2 v2 b  C# j4 {It is used by few softs which access the following registry keys (usually #2) :
  |: q* L" H" r
3 a2 K  `) I8 d7 f  @1 m+ o-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
: q  a* M- T1 b# N\Uninstall\SoftICE
2 P' ^, V. C& j) z4 E* V-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
& i, l+ b; p( C6 Q-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
, I! {: f  r) Q& q\App Paths\Loader32.Exe. R+ S& P+ U  _* H3 i$ ]

" I# N7 F2 i) J3 h0 X; J" u3 N
Note that some nasty apps could then erase all files from SoftICE directory% r% m2 J  ?. g) x  N% {1 K$ J
(I faced that once :-(& p3 E+ P5 j" t5 d

( ]) D, [' u! H7 Q2 Q! y. K: LUseful breakpoint to detect it:! }! c1 \: z' P3 m
( U! m) H1 Z9 k' V4 i
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'1 r. J, {7 B& Y" B

8 d6 g  e3 z% F( z% p# d2 n__________________________________________________________________________6 c2 ~! _* G1 |; ?
& a0 ^, ^; y4 d3 `2 n

$ s4 ^' p( c* \' E; {( t6 qMethod 14 9 |' _8 }1 }2 ^2 ?) V
=========
9 F% l, }" A6 H
' ^6 {% y" J. o" `A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose. ?4 o( _: }3 R" D
is to determines whether a debugger is running on your system (ring0 only).
* T; ^- V# z2 H: V1 S% r! @
. s5 h* J7 K( y# k* M% }3 u   VMMCall Test_Debug_Installed
8 Z" c' P2 r# @+ ~' x   je      not_installed/ C. C! V! S# V. ?1 F& S7 w  N+ K

6 D4 T  @/ ~' Q/ K) IThis service just checks a flag.
3 u6 M3 t/ L3 `& x" Z/ ~; \$ R1 X</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部