About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>8 r3 d! c" _- _
<TBODY>5 |: b1 X1 ]$ Q8 Q
<TR>* E3 f- C/ N! r% m% s
<TD><PRE>Method 01 6 T& i  {: @$ E
=========
5 r; @: d& F9 D  p5 I2 g! {1 f' u+ D. j1 S, S! t1 ?+ w: ?3 r5 w3 A
This method of detection of SoftICE (as well as the following one) is
: h( K2 [! W# m* n: z2 B( xused by the majority of packers/encryptors found on Internet.+ b, ~% O3 H) m3 P. i- H
It seeks the signature of BoundsChecker in SoftICE
- r) f0 G$ k: X& J
3 Q4 r2 T2 S6 z7 C; w) `9 L    mov     ebp, 04243484Bh        ; 'BCHK'. V7 `8 g6 [1 ]: ^! W6 x
    mov     ax, 04h; R( P: f$ R" b& ^0 n4 p
    int     3       5 @' r  {& z8 w# v1 r% D
    cmp     al,4
. U6 B7 }& m" \) f7 G: E  m    jnz     SoftICE_Detected" a6 F9 B0 f- W1 }( b! V/ u

8 _" Z+ r5 ?. X' A* ^___________________________________________________________________________( l8 ]7 b$ ~& I) `

) \, h$ E* X  ^3 l) HMethod 02. t2 Q7 V, |) L8 c! F2 M! R' L, x
=========
# d: @- l% p/ |' s6 V2 U' b
9 j. v3 F9 Y4 n* i# N( iStill a method very much used (perhaps the most frequent one).  It is used
" p% K! r8 F$ }6 eto get SoftICE 'Back Door commands' which gives infos on Breakpoints,* H5 v. \& M! u4 U' O& J
or execute SoftICE commands...
  U) w$ m0 ~( j; ~! FIt is also used to crash SoftICE and to force it to execute any commands
1 B7 N6 P* E$ h1 N. X(HBOOT...) :-((  
5 J3 f9 Q8 K$ J( @
" r8 I* w4 R% ~' [7 E" {4 o& l- HHere is a quick description:
! D2 E$ f2 O: j( k6 _  _: r9 `-AX = 0910h   (Display string in SIce windows)
" h1 y7 i& ]5 q) q8 l! C2 K-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
# k  h+ G- s) @( l-AX = 0912h   (Get breakpoint infos)
% s3 Q" `) H( O# J-AX = 0913h   (Set Sice breakpoints)
' q' a* t. k; _$ R- k+ V. c# S-AX = 0914h   (Remove SIce breakoints)
* J) |. a! c4 F6 g) O# t! Q
( D/ E! e- s+ E2 ]. MEach time you'll meet this trick, you'll see:* b( s2 A- W; X
-SI = 4647h
, ?  m1 |2 L' h2 S( j/ j; I5 K-DI = 4A4Dh2 M* _# l' `5 }2 l' R* q  h
Which are the 'magic values' used by SoftIce.' x% j  \" P  h* r( [* L" A
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
2 s  D3 {# b8 C! u9 ?1 [8 x% F5 K, ^  P7 {1 A
Here is one example from the file "Haspinst.exe" which is the dongle HASP
: s/ P6 V5 h- E9 \* b- SEnvelope utility use to protect DOS applications:+ R4 v- M* F. s& ]9 e
/ M% _, Z7 E! g( c# e2 L+ T
- c& [- {  z8 d  ~4 _% d6 k( v
4C19:0095   MOV    AX,0911  ; execute command.
5 X# {1 `/ I! F$ l- Y6 L4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).3 Y/ N, P/ o, R% `3 u" F+ i) o% _! d
4C19:009A   MOV    SI,4647  ; 1st magic value.
( y5 Q( o2 j: j. }. z4C19:009D   MOV    DI,4A4D  ; 2nd magic value.3 U3 d/ z7 {% E5 {
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
2 `! U9 V+ ~2 r$ D- D0 E4 X4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
# K4 }4 @" L3 O- I4C19:00A4   INC    CX
) O$ W; J4 h( u& L/ l0 m; A& K3 }2 m4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute+ E& }3 q" g7 C. J, r: ?
4C19:00A8   JB     0095     ; 6 different commands.
" o! b( _/ c" k4C19:00AA   JMP    0002     ; Bad_Guy jmp back.% Y# Y- I2 X( |( Z: ?' X
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
! t5 q7 c' Q: k/ N0 j* ^: j3 E( P. [/ B& [# i7 e
The program will execute 6 different SIce commands located at ds:dx, which1 j: s! ~' x* m6 t& h/ J0 y7 |5 E
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
9 Z7 H- n+ A! ^9 }. ^1 n1 X( s4 R! w/ b. u$ m
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
2 S/ V0 {8 z; B/ d6 H! t# }___________________________________________________________________________8 e3 K5 b2 ^" d+ f6 q+ ^

" b' P' u% j+ X9 ]8 y" P5 f: Q5 p0 |, J" a, L4 \6 O3 }
Method 03' j$ o/ w* I8 G/ c+ U8 d; Y
=========
8 G7 A4 N) T7 F1 \( L* N4 S2 t0 S4 a% A6 |; y
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
) ~! b+ S; t  ~! D(API Get entry point)  r9 O' t, X) \* S/ `  B! m
        : A, O7 c4 `* `' [# d

9 c% ]6 Q# q. ^/ J) `    xor     di,di
: g" h8 ]5 d2 ]4 F9 r. c  X& ?' W: C    mov     es,di7 C4 g, H. F1 P) b5 u* ]
    mov     ax, 1684h       : W( d5 U& b$ h0 D, ]( f) K8 z' Q
    mov     bx, 0202h       ; VxD ID of winice
3 r/ B/ e: R0 n8 g! J7 ^; ~    int     2Fh* ]$ x# w' Q6 x. u6 D$ j" X
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
' b# M4 h/ z, ^; F$ z    add     ax, di
& e0 x1 u9 a: i8 E! L    test    ax,ax
! G* N/ B# O) n+ T    jnz     SoftICE_Detected
: P: Y& Q4 ^7 J( _* X
6 Q) T; B* l/ {( R___________________________________________________________________________; s2 w* @" b2 O4 B8 b3 z

* [: [( C9 l- H" JMethod 04+ m4 t5 {0 t, h- [0 U% `
=========# a, h7 X4 W+ w$ v
0 [& Z; Z/ o0 D7 P9 [
Method identical to the preceding one except that it seeks the ID of SoftICE
/ H8 V8 x3 s4 \# _" p/ {GFX VxD.
7 P1 _! {! T. P# ^7 K% j& J' v: _
5 ^: v5 n( a2 B    xor     di,di5 j9 S/ n- M/ n/ F
    mov     es,di, D0 \3 Q- i; Q
    mov     ax, 1684h       ' q  O" f5 X- c7 P- I) W) q
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
% ?1 }# Z: M" A1 g$ d9 l4 C8 x    int     2fh
. f$ f5 w/ I9 f% I    mov     ax, es          ; ES:DI -&gt; VxD API entry point
- V) s# |- e; l9 O7 Q' G    add     ax, di
: {4 Y( B# j: w# R8 j    test    ax,ax, I6 c% e" M5 [6 R2 {6 U
    jnz     SoftICE_Detected
& d! H- F- c' ^. A) L8 q% d  C; y5 a) _6 }
__________________________________________________________________________
" a7 H8 \, ^& L: N& @8 s. G' Y3 a1 K3 U3 Q2 h) y+ [) `: I

2 X; j8 Z4 e% T6 f; rMethod 05
, h  V( i. i2 V3 F* G6 ^  Z. O4 d=========( D7 X3 c4 B. e( }* u6 ?

; F( N4 k9 h$ c5 |# u6 c2 FMethod seeking the 'magic number' 0F386h returned (in ax) by all system
# _7 ^9 w" B! z2 }3 fdebugger. It calls the int 41h, function 4Fh.3 ?: w& A/ k5 k' X6 I6 x  s7 w
There are several alternatives.  0 V" i3 y7 w* i1 }/ L
" Z3 S  o" z7 P# x4 k! I3 B' \9 q
The following one is the simplest:
" k( Q2 v- L2 T1 r% v, X1 b8 Q. e% q+ |* }; X. R' n* b
    mov     ax,4fh
! a( U6 t, v1 N5 l* `) v    int     41h- l9 M5 [% r. p( h" y* ?
    cmp     ax, 0F386
% _; o  M5 C7 Y    jz      SoftICE_detected
6 ^% }1 ]6 a$ w0 @- w
# C; @/ k0 l& f
/ K3 e; }/ q9 z) n6 K  m2 CNext method as well as the following one are 2 examples from Stone's ' ]7 G/ ?# F+ f+ B2 ?* R9 S& c# o
"stn-wid.zip" (www.cracking.net):+ O1 r; I8 @7 W1 k( |5 o( a
1 |/ g. o& }" t* x0 Z) t
    mov     bx, cs& y1 z2 v! P3 Z" U, L0 b; w
    lea     dx, int41handler20 |+ O& o9 B% c/ r
    xchg    dx, es:[41h*4]$ Q: C0 @( b3 Y' b! G8 l! |4 i
    xchg    bx, es:[41h*4+2]
) _  P0 A2 b4 O! Q  x4 x( y    mov     ax,4fh
1 n' Q! \1 s# ~9 I% X    int     41h
; _) a, V# }( u+ x! m    xchg    dx, es:[41h*4]
, i8 \. @0 c, P7 @- C    xchg    bx, es:[41h*4+2]- f. ~; T6 e( K4 [! o
    cmp     ax, 0f386h4 s/ y0 a4 N# u5 x2 W; m) A
    jz      SoftICE_detected: c1 Y2 i+ O! M4 J8 [( l, v

' Y; x% K4 h0 zint41handler2 PROC
- g% ^- O  \7 b! n    iret, @5 x7 U6 U" f( B: `$ Z
int41handler2 ENDP- t/ }  W; t7 Z/ P( i7 K! m

4 x" m' z" P  g. r2 k( c- V5 G, E* ~) D  q; d
_________________________________________________________________________0 n  k; S% s& O  V/ I# ^
- B% }; T6 T1 v( Q5 U* G

' g, @. @8 b3 u. eMethod 06
: t/ M; ]( c3 m* k: W=========/ \2 e# ^5 w" p! l

- C9 v. t8 V/ f$ `: t% ^- A( |8 c7 s- _$ r8 s, v- T
2nd method similar to the preceding one but more difficult to detect:
! R1 ?- o" M6 J# Y; K0 f$ [$ B, V

" Q% \' |" o1 H& ^- i8 Jint41handler PROC
5 m3 ?3 Y+ G7 f# m2 A3 _    mov     cl,al
5 E% \7 L0 f: I    iret0 K8 i& v) J, g
int41handler ENDP
1 v. W$ ^) G; w5 R" }. ]
" }  v/ V; y/ r4 e$ w5 _# K7 l" b% l. \/ i$ W& [
    xor     ax,ax
9 s+ c" I  f9 T9 u) e    mov     es,ax! b& L, K: B2 a
    mov     bx, cs3 w  g0 ^7 ^5 ?( Z( U
    lea     dx, int41handler0 }4 q5 K0 |. c  k3 A2 v
    xchg    dx, es:[41h*4]$ n1 P2 r/ i/ F& `! z* b
    xchg    bx, es:[41h*4+2]
: ^+ l% x. Z" [9 |9 E# {) n( l1 i    in      al, 40h
: }6 s& w: y* [  T5 w    xor     cx,cx5 ~& O" A* V$ S% Q5 B
    int     41h( W# K. Z0 B/ V7 j
    xchg    dx, es:[41h*4]3 C) I- \! X- j
    xchg    bx, es:[41h*4+2]; f/ |0 O) p: O3 u( L4 {
    cmp     cl,al  R' r7 G# E6 }. Q) a+ ^
    jnz     SoftICE_detected
( S% }) V8 t2 q( j5 H
& i3 s7 J' ^- [! T/ x5 ]" A_________________________________________________________________________
5 b: V3 l0 R, G, w+ e0 _5 n+ O' O0 ^9 V7 n/ _
Method 07
* A9 b0 m, s& L, \  m% p) p1 K4 T=========1 p9 z* n( T+ N& ?

. Y; ]7 f9 a6 W' ]Method of detection of the WinICE handler in the int68h (V86)
6 D: ~% V$ ~; X- {  q8 \, \1 S, V, E% H+ r9 R( W
    mov     ah,43h
) w) Y+ ?1 z. [, d' L+ U) m% q4 t    int     68h
& S+ k' @4 c4 d$ P4 h# K% v: G    cmp     ax,0F386h. W% [8 J2 m3 u! W) @# q: A5 E
    jz      SoftICE_Detected+ `1 x2 _! q0 M
1 s5 p- h; R- x+ v9 D

2 ^8 v+ ]8 q% \% u5 A2 k=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit! m7 g+ X0 z3 j5 p
   app like this:
  \6 U* L, l# T# m9 G" I4 N; r2 i0 _
   BPX exec_int if ax==68
9 D# b2 N0 E. w0 p( Q- k5 ?( ~   (function called is located at byte ptr [ebp+1Dh] and client eip is* a! B+ W1 ?, ~0 @$ x# @3 G
   located at [ebp+48h] for 32Bit apps): i& M! v7 x- r, G* l6 q
__________________________________________________________________________7 n( p) }6 B1 v4 n' a' w9 \
( }0 ]% c* A6 o
% m3 U, h7 |* ^& H& u* y
Method 08
. z  ?0 [- ~0 U9 g- M. G" l=========
) m0 \% c6 c5 l4 Q& T- R( F7 ^( m% }) I0 Y9 w2 ^( n( t" @) D; \
It is not a method of detection of SoftICE but a possibility to crash the
2 }4 H( _. g# w8 s5 ^  Bsystem by intercepting int 01h and int 03h and redirecting them to another
- N" ?3 }; q) I: ^) {' `3 N: {! ]routine.
. N5 G( }0 K2 z; Q7 [! dIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points# ^/ i0 n0 s' ^5 e
to the new routine to execute (hangs computer...)
  [7 v, S4 }/ y' S$ Q# p
* ~" N# a' j. m8 n    mov     ah, 25h. |- _4 w# I3 I- f
    mov     al, Int_Number (01h or 03h)
" A, v" \9 B; |# N3 Y    mov     dx, offset New_Int_Routine
; I; @; T# I  G0 ?4 C9 ?% L, N    int     21h; J' a8 Y6 M$ T' F3 L0 b& d/ T

- C  w; s! _4 I: P: q__________________________________________________________________________
/ l" k7 {1 b5 C6 @5 A8 ?. U# y$ \1 f+ C5 t. C) Z1 Q. [
Method 095 `! O; u1 H7 M
=========
% S+ i- J& _2 K* z
( N4 i7 w' z  v2 M* o4 Q; G9 j# zThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
: T, ]5 \. D- k6 `' ]5 q) uperformed in ring0 (VxD or a ring3 app using the VxdCall).
0 y* B( X  f1 _- {* NThe Get_DDB service is used to determine whether or not a VxD is installed
- `1 u& t8 {( Zfor the specified device and returns a Device Description Block (in ecx) for
' V& ~) k  P7 I& S- Z8 T/ b5 rthat device if it is installed.+ @& M9 ~! U) ~0 @& {
: n- g% V& S% ]) R! O$ H  m
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID4 g8 H3 ?  ^; U
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)% @/ J5 w( c' ~- P( G8 ~
   VMMCall Get_DDB1 E0 z$ \; y- ?9 ~# e
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed3 a' c. N, a/ ]
9 G  L5 Q+ r/ X% U4 T
Note as well that you can easily detect this method with SoftICE:) F: J7 |$ L5 B& y8 S3 H$ X' O
   bpx Get_DDB if ax==0202 || ax==7a5fh) t+ Z' A! t3 R2 f$ W/ P
. p% i. Y; s! e2 j9 k2 F/ {
__________________________________________________________________________! j" L5 L, [2 W( y: L4 F) f

, Y9 K$ O4 ?) Q; B7 ]Method 10
* z. `4 K" `& r1 y' I=========3 B2 Z+ i! y) I. f
4 }: q8 X+ h* W& ~+ z9 Y
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with9 k; H' m2 C% k' n8 l1 u
  SoftICE while the option is enable!!
: P  f+ F& c, [& K0 p( ~: F8 w" L: ?  C" I4 G1 N
This trick is very efficient:
5 j, n* h+ O! O9 n. Q, O8 I4 V! b* N; cby checking the Debug Registers, you can detect if SoftICE is loaded
: v8 \0 X% ^! O$ k# Z(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if% {% z) c+ M8 f" P$ o8 l! x0 C
there are some memory breakpoints set (dr0 to dr3) simply by reading their$ j. D, A) b$ C5 e+ c
value (in ring0 only). Values can be manipulated and or changed as well! h, o- t/ q' I1 z/ g2 ~+ D4 w
(clearing BPMs for instance)
- r, w) C1 O# H( u
" [  H# p3 V( |4 b% ~9 u__________________________________________________________________________
* j  c, ^1 P/ N3 ?/ }; h# W" M
* D& c: ]3 f- C2 [' y6 dMethod 11
7 Y+ u* A5 p) I  i& u: b1 {=========8 p# {! i) i* y. |
# q2 N# L5 {* R, Q; o! J3 {
This method is most known as 'MeltICE' because it has been freely distributed, w& G' n  h! a6 _' }
via www.winfiles.com. However it was first used by NuMega people to allow
2 ]) O0 N; t  M  _. u9 |. C2 ASymbol Loader to check if SoftICE was active or not (the code is located
* w& B1 e+ S7 X* h+ Hinside nmtrans.dll).& v& j* x1 c+ T* a8 t" U+ q

+ H4 ^( T# F7 I+ y& yThe way it works is very simple:
. \2 ^6 Y6 v1 c" K& ]It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
) w6 ?' I- J8 r1 V8 V* @WinNT) with the CreateFileA API.
: ~) O. a( g4 {! L& A3 S" I* G* b& B: ^0 ]- O
Here is a sample (checking for 'SICE'):
9 n- ~7 M' J; a/ i* H3 ?
: b; R) e/ p9 B6 p3 h- O  ]  ]BOOL IsSoftIce95Loaded(); a2 I' d5 e- C# L& E8 S! v
{, k% S, ^2 h4 j9 k3 M
   HANDLE hFile;  
1 z0 j( g7 \1 a, x   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,1 D9 f3 b* k) X
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
& E% \/ z$ ~3 _# W9 C                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
$ O1 q) t. s5 ~  g  b& S   if( hFile != INVALID_HANDLE_VALUE )- H: s* O% N* t4 F7 v& h
   {, t8 D7 ~& X% M9 \8 \, B5 e
      CloseHandle(hFile);& W: o' b2 g* O* L1 Z, O0 a9 M
      return TRUE;& n5 ]' u: U7 V2 _$ j
   }
; n1 k: v. h8 T& ~0 U9 G   return FALSE;
. ^: L: |9 v: i# {1 t/ x) a}) _  v7 `  q% w
1 |' B( j* [% H/ U, f7 \3 B
Although this trick calls the CreateFileA function, don't even expect to be( g  F6 j% x, b: H
able to intercept it by installing a IFS hook: it will not work, no way!7 O& L; a: m( N6 b/ c
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
& i) L) V4 }, R* i! a0 H# [service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
7 B, V6 c% B) P( _and then browse the DDB list until it find the VxD and its DDB_Control_Proc% O) ?, J, D  I' e8 b
field.
3 K; U) t+ b: WIn fact, its purpose is not to load/unload VxDs but only to send a
; G( p4 y" ^; P7 s7 u; Z, y- `W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)/ R" L6 v! m( U( b0 _2 V" i
to the VxD Control_Dispatch proc (how the hell a shareware soft could try+ I9 v# ^2 }4 P
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
2 Y+ c2 |8 H4 [: C( rIf the VxD is loaded, it will always clear eax and the Carry flag to allow3 |- r/ U+ E1 m4 w. f0 q+ g: |
its handle to be opened and then, will be detected.6 I1 d/ D- d0 i8 k" I# B! b
You can check that simply by hooking Winice.exe control proc entry point
+ ]7 s, T1 T+ f2 p: }while running MeltICE.8 F6 t& A9 ]8 x" ]
" P( T+ i0 e" {6 d) R0 n

9 X0 p5 B) i# H) h. y( b, W2 }) Q  00401067:  push      00402025    ; \\.\SICE
  R1 ^: J" D" X7 |  0040106C:  call      CreateFileA" T. z4 W  t& n3 c5 I% T+ G
  00401071:  cmp       eax,-001$ K4 K; P7 \/ w
  00401074:  je        00401091% p! A0 ?$ I6 p9 ]- j+ X! l$ f1 J
' u9 g8 H6 x7 n( j: c

" u" S+ _' }7 n+ V& B& FThere could be hundreds of BPX you could use to detect this trick.% g2 s& @6 L9 R( {+ T+ M- T
-The most classical one is:( @. U/ C8 U( T- i0 ]9 ?9 h
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||) R" L1 u7 i9 [# Q
    *(esp-&gt;4+4)=='NTIC'
5 {: D6 f- X8 @. C+ j4 b% k+ A) R8 X. F' }2 t1 D4 \) U, p8 ^7 O
-The most exotic ones (could be very slooooow :-(
" \8 u& s) m" x( j   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  4 l6 U7 H) S/ O; O  J" p2 k) L7 q; F
     ;will break 3 times :-(- K* H7 w3 y! d! f9 T
- y) Y* q! s; z) Z: ^" O6 m
-or (a bit) faster:
" k$ _* L. g, E- k4 l; A: p& x; W. `. _   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
2 ^+ Z: l3 b. J9 w% b( M7 ~( f) s3 K' L' f7 N* ?; V$ S' f
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  " C, g) M5 b9 l7 y1 c
     ;will break 3 times :-(
- d# t- e" [  q% o- U" z* h8 u
5 W3 L7 y7 W: C! M: q9 Z-Much faster:; K) ?% e8 V- e: J/ d, M" C! a. A
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
2 b" y, X7 P& ^: Q7 [6 o/ B- f- {9 d# R  x% ?. A. h: w
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
2 ^7 ^. T6 u7 a1 \, s6 W8 Sfunction to do the same job:
+ j6 i$ e9 `7 L5 Z7 D7 g+ Q& W) S
   push    00                        ; OF_READ+ o9 K% G* d8 x" p$ H1 n
   mov     eax,[00656634]            ; '\\.\SICE',0' m4 [( Y2 w, p( h4 E
   push    eax
# P5 q; Z- h& A) Z; x" F  O& N; g   call    KERNEL32!_lopen- w/ Z  L. T8 T6 o- v1 ~: I
   inc     eax
) N7 d$ ?" \1 U. O) s- `4 y   jnz     00650589                  ; detected
, d# I2 H4 v* a   push    00                        ; OF_READ  s0 b" e) _7 B6 T0 ]  G7 {
   mov     eax,[00656638]            ; '\\.\SICE'! ^  X! n: S$ }2 O
   push    eax) }' l9 M' I) n4 e
   call    KERNEL32!_lopen  V/ O% a  `, A6 Q
   inc     eax
  M& D! D1 a- z% @( F; n- G" N6 M   jz      006505ae                  ; not detected1 g9 e- U" `# S% T

! O- ~) m$ o  J- k" J, J* n" K8 n; l
- ?$ `2 e' M7 m  U, a7 z__________________________________________________________________________' u" W# j% b& z; p
3 {" ^. Z; s  P2 Z
Method 12
; ]! w) g: z6 A/ g/ _=========
1 q: D" O  `* U: `/ b! t4 X
! v; G. G/ a' v' OThis trick is similar to int41h/4fh Debugger installation check (code 05
1 Y( m# Z9 @0 {: ]' S&amp; 06) but very limited because it's only available for Win95/98 (not NT)
* ]/ ^( ]6 U* k% [( vas it uses the VxDCall backdoor. This detection was found in Bleem Demo.% t# Q0 L8 P; q2 T: L
' _, ]- {$ r) ]/ o) s4 E: I
   push  0000004fh         ; function 4fh
1 k1 p. {( ?: b% C5 K$ O& V2 E   push  002a002ah         ; high word specifies which VxD (VWIN32)
! @7 y/ g) {0 _                           ; low word specifies which service1 P  q) _1 t2 p- B* [* z
                             (VWIN32_Int41Dispatch)
# Q/ \! _2 C! b! j   call  Kernel32!ORD_001  ; VxdCall
7 f' f5 X* W  Q: A  G   cmp   ax, 0f386h        ; magic number returned by system debuggers* t" i; s' Y) v/ i
   jz    SoftICE_detected
6 F: f1 u* O; B9 g7 J- k
- P! G/ m8 U: H7 X; WHere again, several ways to detect it:
# T+ `  T' @3 X0 D0 ]3 `2 a
3 R- D5 k' W! ^3 R8 }9 W. P    BPINT 41 if ax==4f
* {! J! ]  l( f# [' W% p) s1 n3 G  y. P" T( P: y0 [
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
! ^2 C3 v. L* ]3 H- e  s# q3 ]& S
" I: a- K. t& ^1 c8 P; T0 @    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A2 d% I& s& O5 v  f

3 v/ t& G1 u; ^. x+ w8 B, E* Q" b    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!2 h: ~6 z- f5 d: y: R1 ]" }- [
+ y" Z  W( X- j9 u
__________________________________________________________________________3 f+ K2 @3 J9 r: s" x4 {

! M% [1 A. ^6 ]6 D; QMethod 13, Q& \3 B# B3 B7 V7 e6 W5 W! Y  C
=========
& ^& {7 A" k2 y, f; Q/ A
8 @+ w& U4 m- l) l6 D/ D/ V0 lNot a real method of detection, but a good way to know if SoftICE is
4 P0 X: ?* q* m9 {. [7 k+ f3 vinstalled on a computer and to locate its installation directory.. f: s, j5 f% J! y/ Q. {( s, e
It is used by few softs which access the following registry keys (usually #2) :5 N" S) V! Y2 X* ?
2 G+ a! I4 u. N1 Q. x3 K
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion- y5 W/ z; ?4 H) r( t$ v! A4 M
\Uninstall\SoftICE9 `7 j! D8 e8 |* R' t/ z
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
! p& \; A- G4 V) a-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
7 W- Y  t( F5 Q9 }\App Paths\Loader32.Exe& O! Q' O$ D' q, H& O, E# A

5 L2 T2 m' v5 z3 J0 y
9 H! f. R! Z& Z/ T  h2 xNote that some nasty apps could then erase all files from SoftICE directory
( d; e" e! q  {7 \+ {  M(I faced that once :-(
; i( p1 b! L& ^1 \
  V2 g+ G& E' y; Z3 x8 eUseful breakpoint to detect it:0 h4 W- c0 p* {* i8 b

% E. ^; `. ?& Y( H. h: B     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
7 Q# C# q& T" q3 F
3 i! Q4 {% W$ R/ D$ }( l4 K__________________________________________________________________________4 L2 m+ q1 f4 ^9 i! \# {5 d) h3 r

& h; K7 S' k& g% L2 @
, l1 d( y( S3 ^0 X6 c, nMethod 14 3 ^  ~- p5 g: V2 p4 s7 c
=========* Z9 ?6 U) ~! v. q. {" A( _
5 s+ I+ Z8 S2 Y( O! k- Y' j: L& ~! R- s
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
4 h* j* g5 j4 y7 a. z# V/ ]is to determines whether a debugger is running on your system (ring0 only).5 ?% A9 W+ e: q8 z7 S( H( O
4 R" T  w: d- Q+ k+ u0 A3 T
   VMMCall Test_Debug_Installed
3 B( k2 `3 m8 Y   je      not_installed9 p. A- v1 k" [" [- @: H

" d  b9 b9 k# g. KThis service just checks a flag.3 x2 F3 `: q; d* u1 E
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部