About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>4 H; X  F, j, A. P6 U) k/ v
<TBODY>
7 r4 ^9 ^) |& y3 d6 w' y6 I<TR>
. |3 C" f% i# o! T9 A5 \<TD><PRE>Method 01 : v  ]! G9 ?% Y1 ^
=========
+ d, h! |3 w) x$ E( {
- b; x" |9 J9 E. _: s9 K- JThis method of detection of SoftICE (as well as the following one) is
& [4 b( A5 `8 U: L* b* [  gused by the majority of packers/encryptors found on Internet.% f6 m1 }/ ~4 y+ N3 E! b# @4 k% A
It seeks the signature of BoundsChecker in SoftICE* b3 }# ~+ s) d% Y9 p
9 f# S( g) l4 L
    mov     ebp, 04243484Bh        ; 'BCHK'# c+ z% T9 D" U/ I# A( O
    mov     ax, 04h
( b6 ]. I% a# N  z) k    int     3      
" K: I+ R" B1 Z, t1 H% a    cmp     al,49 O* X  h, Y* t' f0 I
    jnz     SoftICE_Detected
+ ]8 g, Z: p% n, @% Y
7 h% @$ [4 t8 N& }1 m2 S___________________________________________________________________________
6 J3 k" {2 ~  {( b1 R5 t7 V6 }0 [
1 t; t+ }/ E- c* o$ d7 r/ \% tMethod 02; v3 K& b0 h- n. u+ G. w8 c3 }
=========, I* r- o+ Z5 G
7 _: m0 h/ e" e6 b% [( L. U
Still a method very much used (perhaps the most frequent one).  It is used
' k5 ]& z  i' V! z" z1 Kto get SoftICE 'Back Door commands' which gives infos on Breakpoints,, R. |1 `) N, t' `1 w+ x3 F
or execute SoftICE commands...: s5 M! g7 ]/ }. P6 O4 B
It is also used to crash SoftICE and to force it to execute any commands
: \( G5 t6 f2 ~1 y! X3 A  m1 r- }(HBOOT...) :-((  ' |0 ]: X( z) W8 Z3 Q6 p# |, n* x0 Y
& d( i7 h% k+ q, b
Here is a quick description:- F7 I  K$ s5 U) Z) w* Y
-AX = 0910h   (Display string in SIce windows); @5 v8 W0 Q. j  a% a; m
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)" A4 z$ a. M  }( z: c4 |) J
-AX = 0912h   (Get breakpoint infos)7 Q; K  ~5 i) C
-AX = 0913h   (Set Sice breakpoints)! A) }4 s7 g$ S& Q* h* Y5 R
-AX = 0914h   (Remove SIce breakoints)4 e0 q0 W5 O$ G& i
5 L  V  U6 ]3 V( }5 C
Each time you'll meet this trick, you'll see:
% A" Z( z9 D- p4 f-SI = 4647h) {' L4 y) w+ v/ N% A" K
-DI = 4A4Dh
6 U7 M+ F7 Z' e" p! EWhich are the 'magic values' used by SoftIce.
4 w1 }! D4 k, C1 j8 r0 \For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
4 d" Q* G  J$ c
9 K. b9 |% V' p, MHere is one example from the file "Haspinst.exe" which is the dongle HASP# ~, H- w4 |  }/ R" k* M1 l$ [
Envelope utility use to protect DOS applications:
( r9 I% ]+ u. G8 `* `3 D) w; L  G% Y% s7 H1 d

! L4 a. ]: v& h4C19:0095   MOV    AX,0911  ; execute command.: R0 e6 Z0 B& g4 E2 E" \
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).  `- P5 d8 W# F8 _. n" I# u0 e
4C19:009A   MOV    SI,4647  ; 1st magic value.4 a1 ]+ Z$ u, z
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.4 c6 ~" ?1 b- R& W3 k( q
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)1 I- G& i( o, }. _  g5 f! Y1 @
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute+ X2 p8 }0 ]( L- e' a4 _
4C19:00A4   INC    CX
7 A8 ~) q; V/ d; _/ W2 n) f0 [* C4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
: @$ ~8 y. V. H/ m4C19:00A8   JB     0095     ; 6 different commands.8 u' u+ L9 u0 s6 C
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.# u3 E- i$ }, H* b. i2 ?$ j
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)* d! r: R, G, x! X& T$ o

$ D4 S1 D7 O0 q: e* \, P. SThe program will execute 6 different SIce commands located at ds:dx, which
. Q+ \- j# ~  B( }6 A! I1 Qare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.$ x% [7 H% G1 d0 a( `

6 s- T& v$ P' E* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
7 x7 Q' q/ Z% q) I___________________________________________________________________________
8 y. M8 u& G5 S0 j9 V* z+ ^- V3 p& m
' d, w8 W5 F- F8 i
Method 03; a- f% M+ o$ m9 ?
=========# J4 n- I8 A4 d' l( {! J
, x5 b# H3 _" }, @; e2 N
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h+ b& c$ B/ U+ O7 w
(API Get entry point)& G. k2 f' T; k% z$ q
        
3 t4 D( D7 K) E: H7 Q
, M% `* @; M* Q8 j) M    xor     di,di
; X; T9 j5 [+ U; s7 L) b4 i    mov     es,di7 f4 Y7 B, Z! p- e
    mov     ax, 1684h      
; h- ~3 \) g/ S' f- k% h* G& `* y- a    mov     bx, 0202h       ; VxD ID of winice
$ k% ^) S8 w) |! s. ~. S% B! W    int     2Fh* |8 M" Z, }  ?* h
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
) I: J" P5 ~, f6 Z0 `" B# g    add     ax, di
! {6 ?8 R3 ~$ {" c$ i2 u, g7 ?    test    ax,ax) g; ]& M# y8 v. ~6 c
    jnz     SoftICE_Detected
  J5 C0 K3 b0 q5 [4 S. ~$ s0 H
2 ]. A. [' L# t; ~* U___________________________________________________________________________
3 Y2 I3 L0 I* d. J$ A7 k0 y  x
6 ?' `7 C' ~6 k. s, x8 uMethod 04/ y2 l. t3 P, ^
=========; a4 U* C3 Y: T; ^& f1 A7 ^

1 s/ ?; B' z/ F' XMethod identical to the preceding one except that it seeks the ID of SoftICE3 W# `' d$ v  Q1 \7 }( M* ^. P1 c
GFX VxD." ]* |* a* [; O& A2 R- p6 [. L* ?

1 ^1 j) ?% U' r- B' o: I, a    xor     di,di
% d4 b5 c/ q. @    mov     es,di  v: _6 ^  r$ s9 |
    mov     ax, 1684h       4 T" s$ J' ]# Q# k
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
9 G6 X( h# W$ {9 A0 y& S0 p* ~    int     2fh
4 l2 p3 x8 y: E$ Z! |    mov     ax, es          ; ES:DI -&gt; VxD API entry point
9 r2 ^( `. f, s$ r    add     ax, di
4 c/ p6 V% W0 i$ r2 W    test    ax,ax# K8 H% N5 u2 c8 ]7 Q
    jnz     SoftICE_Detected5 O! r; A5 k, q) H( E

- ^$ M3 C( X$ i" E, D__________________________________________________________________________
2 }8 I4 h/ \8 d& R$ D+ h6 l
1 l8 O, B; J* ^
# Q* i) B8 H- wMethod 05/ a+ H' V; m1 \  S, R3 v
=========& j" \; F4 |1 d6 o  f& k% |0 \7 x

: h. L: M+ |9 T' u: QMethod seeking the 'magic number' 0F386h returned (in ax) by all system
4 s0 P4 U' V4 E) ^1 Y. j, S3 wdebugger. It calls the int 41h, function 4Fh.
( e! n5 w  I  r0 @  p& eThere are several alternatives.  7 j' n% }' u, z
3 T& ]5 s+ f  E# Z( p# @7 a/ Y
The following one is the simplest:
8 ~9 m/ b! }5 s7 Y0 H4 n( v) s* u' u! K. X
    mov     ax,4fh
5 e6 O8 R5 f) W    int     41h
& [% w; E7 Z1 i" U2 ]8 h) x    cmp     ax, 0F386# r. L% w5 v! M+ W) `
    jz      SoftICE_detected4 e% u8 }  ]* H2 i$ s9 n% A$ o

* t9 ~# ?' |9 \; X! l2 Y' w" E
7 C  i! c8 k. n, TNext method as well as the following one are 2 examples from Stone's
9 ]* ~1 J/ V) O, f4 L& |6 ^  R"stn-wid.zip" (www.cracking.net):6 B2 k9 d8 m4 A1 B4 j0 Z! k0 t; ?; m! c

9 n8 D+ C1 g6 `5 P    mov     bx, cs# e/ S4 |: d9 f: {$ e7 U
    lea     dx, int41handler2
5 b8 [4 q) o# t1 o1 Z7 D    xchg    dx, es:[41h*4]7 N1 Z! ?( C8 d3 n" z
    xchg    bx, es:[41h*4+2]7 }" e7 @* Y5 z$ X" t4 E
    mov     ax,4fh- y: w# O% |( ^" r3 E( H, c& `5 ]
    int     41h' `. D! c0 p4 t8 r9 u
    xchg    dx, es:[41h*4]" _  ]& C4 B- o5 W, X8 B
    xchg    bx, es:[41h*4+2]
! x) C* j! m; O    cmp     ax, 0f386h
8 K: ], F. t+ R4 w- u1 l' E# }) v4 s5 K    jz      SoftICE_detected8 t7 j3 F) l& u7 f3 J
6 Z, Y1 ?. ~% {
int41handler2 PROC
( t8 }2 e1 _! {7 _) R( n2 E% \6 Q    iret
; \9 e- X2 }% pint41handler2 ENDP
7 {; g! z6 `5 q+ C
6 k+ N6 Z. X& B, e0 x9 i2 E$ @7 M: M/ P2 s/ |% c  m
_________________________________________________________________________
& X& H8 Y3 u3 c0 c: o- Y+ S2 E
! u1 y! R( X' K, `, c2 \7 I  {1 J! a8 S/ h
Method 062 Q  b% ?8 `, I- }
=========
8 k+ E" u4 U8 B: s/ f( {7 T7 L( b. w: L: }7 r, R1 z

; z3 f( m5 s  G1 F2 C& ?2nd method similar to the preceding one but more difficult to detect:
2 |& b6 r$ X# H
# P( V  l( C: t2 l6 L3 X5 Y; R* [+ ?* [3 m9 s# ]& ^
int41handler PROC$ x" O) W2 e" F% y
    mov     cl,al/ X; y) z6 `' O1 k
    iret9 b  V) d4 V' F' y4 k/ }
int41handler ENDP3 _; m2 @& t$ T& X

" J% ^' u1 \! a' x* T% }# g8 W9 ^& h
    xor     ax,ax/ p, \! x: @2 F7 e: t* G/ B
    mov     es,ax3 \' O/ B: X0 I. x4 ?/ c
    mov     bx, cs
# R4 S; t; s, f8 _0 u' a    lea     dx, int41handler
& W7 t( @9 M% R9 t4 w: q6 w  N2 y    xchg    dx, es:[41h*4]
3 e/ j' x! s. q$ _7 ^; h5 R    xchg    bx, es:[41h*4+2]
9 F/ q) d. m; c, @    in      al, 40h
, j( n  X5 [, s% I8 f# C    xor     cx,cx3 h' `6 ?. ^7 S' F) c  I+ x
    int     41h( [9 i2 r1 n/ `+ L* `) m
    xchg    dx, es:[41h*4]
  W1 D  y8 N; {$ r2 H% i/ H    xchg    bx, es:[41h*4+2]# C, ?* e! |3 C4 }1 `
    cmp     cl,al
) s; x( a6 U  q8 A! B    jnz     SoftICE_detected# n# s- ^9 }* H3 x" {8 m, s. |

1 r  X# s) J2 g- d) l- e8 i_________________________________________________________________________8 R1 _$ M$ g& i1 P
8 s/ S) x0 {" |+ ^& u8 T& V
Method 07
9 ?2 t2 L( S+ |# O9 |' K& ^" O=========  j2 W) W. W4 l/ v1 o

% d  k# X9 o) r: d6 SMethod of detection of the WinICE handler in the int68h (V86)& H5 t4 P% q) C
: p! k( E: ]* F# A) g' F/ M
    mov     ah,43h
/ `) {( [/ X: {) J    int     68h, H/ T2 x2 F, V. y" A3 E5 }# j+ J$ K
    cmp     ax,0F386h
. p4 w7 q) n& x    jz      SoftICE_Detected
. ~, c( |$ j4 V1 U. z) u1 \+ q* \
- ]$ r9 z% y0 }# R8 l" Q
7 n) v' y4 e5 ^% \5 k=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
- h6 X" I3 p, J( Y0 h$ R- _   app like this:
5 F3 p2 ^$ t/ G7 f$ G' I/ h$ R5 k' @
- l! j- D+ I6 e) K( s! U$ Y   BPX exec_int if ax==68$ \* |. Y# Z1 c: n& ?" O1 v
   (function called is located at byte ptr [ebp+1Dh] and client eip is; D3 Q& _& a, A% p& }
   located at [ebp+48h] for 32Bit apps)) {: ~% O7 H; z) G- Q) X
__________________________________________________________________________# A+ c; L8 z: K5 i

% D- ^( F0 l6 K4 [+ F2 L+ q3 r1 M- P3 W3 N% y8 Y
Method 08
6 `/ ~, o0 d9 F! u- ]3 P1 y=========$ F  \2 R. ^" ~1 h+ {2 z: a" }
/ E+ J. R2 E* v
It is not a method of detection of SoftICE but a possibility to crash the
% u8 z$ {/ Y3 C: wsystem by intercepting int 01h and int 03h and redirecting them to another
2 \1 o, w) F0 l$ s3 E6 D8 sroutine.9 ~4 ]; L2 h# u
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points+ z6 A5 X  H0 y5 h8 l( G/ o3 d
to the new routine to execute (hangs computer...)0 c6 Z. u# I1 j1 W* H  e* P

( Y8 C  h# H* L+ T; U3 x    mov     ah, 25h
# h- h! L+ O5 {2 G* q+ C" D& {    mov     al, Int_Number (01h or 03h)$ D  F0 j; `0 p+ ~
    mov     dx, offset New_Int_Routine/ z; J+ B) T2 m* H, j+ ?  J7 K! J
    int     21h1 s# d2 G# _- o7 |* a) J
2 |5 b& V0 a  L* q% J1 E$ }
__________________________________________________________________________1 P1 C, Q( w5 ^
3 |# q7 c1 u4 m" C
Method 09
  V* C, q/ O$ N7 v8 O8 B: b7 D=========
8 p( e& U& a# g, r) E  w& W4 a8 t3 O3 k; l$ c
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
7 r6 r1 o, y- b" Lperformed in ring0 (VxD or a ring3 app using the VxdCall).
' Y0 ?! Y, S8 o" s' {The Get_DDB service is used to determine whether or not a VxD is installed
; y, c- @, ~! a  T; Ifor the specified device and returns a Device Description Block (in ecx) for; l  Q4 t  M3 I/ b
that device if it is installed.
# b; h+ M( D+ H, \1 d, q& ]4 t% l$ E7 @
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
5 Z1 e4 p" b6 |! K' J# c! v( V. f   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)5 @4 H/ ]! z& L& g/ |. k. ~
   VMMCall Get_DDB: u8 u3 O9 x, }
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed+ f4 x0 A, |! m/ e* w
4 z1 [' d8 t- A
Note as well that you can easily detect this method with SoftICE:& P. U, m3 _3 E; |  m
   bpx Get_DDB if ax==0202 || ax==7a5fh; |& |% _5 l+ a" p
1 j. U- m+ _) Z+ L  ~2 |! t( J
__________________________________________________________________________& g+ Z' q9 n1 w' c) ^# I

) r$ S3 ^& b' M1 p7 v* wMethod 10
+ f; x' Z* g9 K1 f=========
6 R) Y0 o. `/ R& h* U; J* y. L$ H* W+ L' a4 E
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with' U% Q' m9 l! w8 ~6 E
  SoftICE while the option is enable!!7 D, i0 r4 s* B6 x
' D4 G' Y! B' b% l  f" w; J
This trick is very efficient:
1 z6 H1 ?" E/ z: Z; tby checking the Debug Registers, you can detect if SoftICE is loaded/ {$ E/ l( t% I! {/ o
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
. E8 ]  g- N. O  O- Q* {there are some memory breakpoints set (dr0 to dr3) simply by reading their
% o5 Z% T* Y' x4 y' `$ D! o, _0 b# Svalue (in ring0 only). Values can be manipulated and or changed as well, J, ^+ k& s3 q9 [! r7 V& n  F
(clearing BPMs for instance)
# N) ?1 i( ]6 E3 S7 E9 d% W1 j
1 t4 h# f- z4 o& e__________________________________________________________________________( Z$ \* e1 M: S' a2 T4 H
% B7 r) d3 k# t! |7 c5 u
Method 11
9 X+ ], w" J6 i$ |2 _& S4 }. Z) g=========3 L3 `5 w8 h  Z9 r( w

7 ^. {* O1 X5 o$ QThis method is most known as 'MeltICE' because it has been freely distributed! f" [1 T# R# Z" `$ ]
via www.winfiles.com. However it was first used by NuMega people to allow3 [( b. l" L5 }% r/ N' J  _
Symbol Loader to check if SoftICE was active or not (the code is located
: Q* y, \$ t% X: q  x' Winside nmtrans.dll).
% ]$ h/ V7 A; \/ ^+ [$ r8 X" s: I, R( T' X! Y  t% i+ }
The way it works is very simple:
8 y4 |* X1 I; x1 |" x4 n2 b* X0 cIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for; H5 Z4 ^, m& R1 {/ H
WinNT) with the CreateFileA API.. z- O; u) h: |: Y# b" F9 x
, R4 ?/ H- T$ O. }8 I% Z* _/ M
Here is a sample (checking for 'SICE'):
" ^8 e# W/ ~& O$ E
# `) Y. }  ?2 O: {- C0 w, H' SBOOL IsSoftIce95Loaded()
' h$ ^1 T2 p4 K/ R& E3 ?{
7 T8 F! V0 ]: {. q6 ?   HANDLE hFile;  9 u# ~) i0 G2 @0 T- l* N  d5 x; m
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,+ e$ z. J( e2 g. P# k! [+ i
                      FILE_SHARE_READ | FILE_SHARE_WRITE,; H3 b- m, n/ R) q8 z
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);; J9 o" ]: o, w: ^& I
   if( hFile != INVALID_HANDLE_VALUE )
1 `3 `4 O( z0 X   {
/ A9 M/ ^. {9 y/ O' B1 C      CloseHandle(hFile);
, ^# m* O4 R! T1 L      return TRUE;
2 R5 s9 H, g  k9 p6 n+ m! w" P   }
9 S! F% n. [' A7 ]& t" W   return FALSE;/ J# A/ }2 c0 A$ B+ @1 l
}* y( Q4 F( U" L4 o: Q

! }9 n; y2 o( N5 _6 _' `7 ]Although this trick calls the CreateFileA function, don't even expect to be, v! o2 L  F; _2 V+ X( k- Y" t  m
able to intercept it by installing a IFS hook: it will not work, no way!- e. N6 ^2 C/ ~( P- P. S# m0 D
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
: s! o' q: X, E9 ?service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)1 U& Y6 t( ^4 ^6 G6 W  F% I# g
and then browse the DDB list until it find the VxD and its DDB_Control_Proc# f' W7 S/ |4 J7 o& l! X
field.+ I  {5 \, Q- \: O4 O2 [
In fact, its purpose is not to load/unload VxDs but only to send a 6 F% G7 U, O( v% z
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)5 V' Z3 d4 h- n, F0 B7 ]; Q
to the VxD Control_Dispatch proc (how the hell a shareware soft could try, B( y- P9 v( e
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
) t. R1 j1 \  f- Z/ F! ^If the VxD is loaded, it will always clear eax and the Carry flag to allow
3 t# C$ y- C& M+ p, m: b* `) tits handle to be opened and then, will be detected.
' w/ \% g, s, n8 h) V0 ?+ TYou can check that simply by hooking Winice.exe control proc entry point
! o2 }+ Z! P. @while running MeltICE.
5 f5 @4 C" S( ^4 @% {9 P, T+ ~0 X9 E5 o8 e3 w

2 ]! f- Y# J3 ~  00401067:  push      00402025    ; \\.\SICE
& E7 Z8 F! F( e1 U  0040106C:  call      CreateFileA
. Y' l8 ^; F- _' v. J0 @' y# @  00401071:  cmp       eax,-001
3 ~9 F8 I% o* ^! z! w  00401074:  je        004010910 l0 C5 l7 X0 A& y

1 z, N8 M  V: G2 t$ V+ q$ D2 a
$ Q* T  o: H; M( R/ J: K' q4 bThere could be hundreds of BPX you could use to detect this trick.
; z/ [3 @8 \: D! z3 S-The most classical one is:. J6 G, D  n5 V4 r) m
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||9 V& O7 L8 q7 Z4 J7 {) a- H  V
    *(esp-&gt;4+4)=='NTIC'7 X$ a& d( N1 ]5 q
" s+ J# l0 O2 t8 A8 u
-The most exotic ones (could be very slooooow :-(
0 x" Z$ h5 s4 a! o* ]4 S   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  / R1 }8 Z2 e' ^+ d- D
     ;will break 3 times :-(1 p2 J: ^, ?0 y% z5 `* x
& Z, R1 `! a9 P. l9 z+ K: a
-or (a bit) faster:
: |& q8 {1 ~2 P. b7 s% N   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
' @& `. j: d0 V/ }5 F8 Y/ Q( f  l( Q, d! v+ e; t  f
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'    B, @% J- V$ P4 W/ m/ M
     ;will break 3 times :-(* ]% N6 @* ?8 g3 |
* N  A" d, e0 E- K
-Much faster:
" g) X  g+ ]8 u) e, H   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
! e/ s/ Q! P5 G- I
4 q& [" o: L8 PNote also that some programs (like AZPR3.00) use de old 16-bit _lopen: h1 i) G( t2 F% p* I  Z8 d
function to do the same job:8 y8 F* w/ y& D/ o2 o2 f0 M$ \" V
" S! v" ]" {- K1 Y
   push    00                        ; OF_READ
( Z4 S/ j  }0 o; V1 ?7 X   mov     eax,[00656634]            ; '\\.\SICE',0
1 l$ Y! x& q8 P$ s" l3 X: z. `   push    eax$ c$ ]+ V) ~" c% ], |9 r- Y
   call    KERNEL32!_lopen, i2 w+ g% @. {4 u  x7 {/ F
   inc     eax# Z  X$ v7 ?* l: V9 i% t! N2 R& u
   jnz     00650589                  ; detected
$ J5 q* C/ @" n4 E   push    00                        ; OF_READ& n4 s1 |$ ]2 h0 x/ M% B
   mov     eax,[00656638]            ; '\\.\SICE'
- X+ e. ^" W( \- K% s   push    eax
6 j3 }- r/ X* e% P$ q" R9 ]   call    KERNEL32!_lopen& @( D9 l1 |9 G
   inc     eax1 h  A3 f( g, d/ S( I
   jz      006505ae                  ; not detected
+ ]" x* x. @$ A: f/ L3 B$ @
6 w. m; X4 d! T! }5 v! X4 L* k/ ^& Q1 |& I
__________________________________________________________________________
% r$ A9 w  h) S( d. P
6 T! Q6 U# \" U( e2 oMethod 12; \3 s) }( ]3 r
=========- v: \0 i1 m( M% I! h
% w, b" K' u6 q% _' i
This trick is similar to int41h/4fh Debugger installation check (code 058 `# v, l7 @! s6 n& X6 y. r' w
&amp; 06) but very limited because it's only available for Win95/98 (not NT)0 i& j$ n5 s  h. O6 q1 g. C
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.1 R% f' l# d% l) A/ b) Q
: n( U+ k1 J* @: h3 D; k4 y2 y
   push  0000004fh         ; function 4fh
0 G# `3 N9 c% X% H   push  002a002ah         ; high word specifies which VxD (VWIN32)) b. k" C% @" @" c& C0 }
                           ; low word specifies which service
' z4 g( ?4 p' b6 @, h1 j                             (VWIN32_Int41Dispatch). [- U# h3 a' c* O
   call  Kernel32!ORD_001  ; VxdCall  k9 t1 T5 ^* r
   cmp   ax, 0f386h        ; magic number returned by system debuggers* b5 T0 u( Z: W4 ?0 A( u1 ^
   jz    SoftICE_detected
1 t6 R+ f0 g2 H0 T! E7 R* _! i5 [6 f4 h; g- U' R
Here again, several ways to detect it:
, t  ~* ?- S) {" o, R9 P! t# H( z, R5 L; j) z* \2 U
    BPINT 41 if ax==4f4 e6 B( O$ D. |, P+ a7 F) y
1 Y" ~; e2 B+ }1 I) n; j! R; `
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
7 {  P0 J: W. B3 J
1 R) s8 {$ M/ q# T2 [    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
0 }, v- t* T0 C* E5 j
7 B% o0 ]+ q  d# p    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
- N9 K4 |1 o4 I1 k4 q, g6 g* y5 w- N9 O+ D8 M
__________________________________________________________________________
; {" b, m$ |6 c1 O8 X, E2 O
& m0 U: D& N/ m& Z9 ]! LMethod 133 ]/ k( I, [  f5 H% b
=========/ }* S' A( x3 L
& i4 \2 \$ u" g! ?& P# n& \
Not a real method of detection, but a good way to know if SoftICE is
+ i4 ?; A* g# I* N- ~$ \7 J  X; \installed on a computer and to locate its installation directory.3 [; D! c4 \& c* I
It is used by few softs which access the following registry keys (usually #2) :& ]( T' L. Q7 b
# N( U1 q3 ]' m
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion! U+ }' i! i) [# M( a% L( _) V" D# i3 G
\Uninstall\SoftICE, Y/ F( o: o! v9 M7 t
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE* ]5 A' l8 d, Z; B0 E+ M* S9 r' M1 u
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion0 t( J$ z/ _3 h& a* S( ?. p4 d  q
\App Paths\Loader32.Exe
: Q  s$ I0 C5 h! P9 o
5 Z2 c# m7 P+ E' A, [; n1 A0 F9 n5 G+ W9 r  s/ P! T% |
Note that some nasty apps could then erase all files from SoftICE directory( C. p* d8 T5 J! B- ~4 _- o. ^# l
(I faced that once :-(! o: P/ _/ w! p, m% L( w! {/ C

: C0 i2 a% G2 [: H3 D* [& r) QUseful breakpoint to detect it:
3 L9 D& @! N! y" n( t; _. Z6 H! A7 o% M9 g+ d
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
) v1 e2 R7 ~: r- k; C4 d; J4 e* p# o: X0 }, z  A
__________________________________________________________________________
' w* N# m7 z, `9 C; Z2 N: V1 W
9 w  N5 q) @1 D
3 |" d" c( q6 Q& e; dMethod 14
) g( S. `+ g: x6 V7 o  g=========
! \3 u9 [: K, m! F' Y' J" @7 J) T0 ?8 W& Q6 J$ V" ~3 U6 x
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
: ?- b% B1 J# \# z& q$ H' Zis to determines whether a debugger is running on your system (ring0 only).$ Y8 z- {; C9 q9 W& ?, G! M8 n
9 g2 R% w$ B- n2 C
   VMMCall Test_Debug_Installed
5 M3 ~( A; e) Y# r; P# @0 Z   je      not_installed; r+ P4 V  T# i( S0 |5 K% S" P

0 r4 l" j4 Y& e% HThis service just checks a flag.
+ T1 |6 w( E/ R3 U; H# K" @, U</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部