About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>. F% h: l' A. P6 l; b- q
<TBODY>
( u, C3 F1 B$ ?' N5 b<TR>& z2 Y$ n' X6 \  y7 k  p6 N
<TD><PRE>Method 01 " Z* Z% I2 x( l) ?( ~9 {
=========( l+ Q) w: T" Y( Y% T

  b3 s1 g9 A9 A" u$ yThis method of detection of SoftICE (as well as the following one) is
$ H: b' P, e9 q. @% j4 w# e) Rused by the majority of packers/encryptors found on Internet., m6 U; c. f$ b/ t+ U5 u' m
It seeks the signature of BoundsChecker in SoftICE
6 E# i+ i4 f$ ~6 [/ `
! t3 M/ J8 N9 i/ x    mov     ebp, 04243484Bh        ; 'BCHK'
0 U2 D6 E; F8 M    mov     ax, 04h- b- y( i- M# }
    int     3       9 Z: b" ~7 a+ }7 `  ^' k
    cmp     al,4
7 G9 B9 s+ V* Q8 u    jnz     SoftICE_Detected
- ^& t1 @# u4 m2 w+ h0 H- I5 R
* A: w6 I; ~6 D3 g% X5 s0 _' |___________________________________________________________________________  ]( |1 T) l; `' t. ~, ]) ]7 y/ U( ~

  ?/ n: h" ~9 Z* [! gMethod 02  u# [* B1 I+ Q  i/ O# l3 d
=========
9 ]. u5 R! [# v- Y; s) z4 `$ [: g! L* R: Y
Still a method very much used (perhaps the most frequent one).  It is used; w+ O7 I# T! T* v3 U& p
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,( Z" v/ a% p/ N% u
or execute SoftICE commands...
+ v+ [7 Z/ ]$ V8 ^" k/ M8 zIt is also used to crash SoftICE and to force it to execute any commands
2 l/ l1 d" ?# R(HBOOT...) :-((  8 I+ T* L* o9 E* r/ ?& l

1 w0 G  f1 s% Y) N1 }0 Z* GHere is a quick description:
" N5 N( D; i' z6 S, E-AX = 0910h   (Display string in SIce windows)
0 N) `5 @9 j0 [+ e-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx); l3 G7 i5 I: B' J
-AX = 0912h   (Get breakpoint infos)
# z  x! |# z+ p-AX = 0913h   (Set Sice breakpoints)
8 w( l+ a8 e8 `4 {# B4 Z( l-AX = 0914h   (Remove SIce breakoints)- c0 m. l1 ^/ o& F' `

$ k3 t. p4 ~$ J& w8 j$ Y3 yEach time you'll meet this trick, you'll see:
' M/ \8 S6 a/ `) i* I  E' i-SI = 4647h
. {1 E3 g1 ^; t$ r$ H! i% v-DI = 4A4Dh
/ S9 s/ [5 u/ P  ^0 V$ SWhich are the 'magic values' used by SoftIce., X$ U* U# M  i3 x0 X8 b
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
7 X/ |* i4 j6 j3 S; L& G  y% S& m+ H; z1 [! ~: W$ s
Here is one example from the file "Haspinst.exe" which is the dongle HASP
5 P7 e3 q8 x4 ?; U2 Z/ c' vEnvelope utility use to protect DOS applications:
# b' ~! F1 Y! i6 G* n+ x; z4 {' s1 A) x' N" w* w
  G7 t" O/ K+ _
4C19:0095   MOV    AX,0911  ; execute command.
" a# _# C2 }6 O. E0 W; ^0 l4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).8 m* F  y# H( I# V5 e$ \7 T
4C19:009A   MOV    SI,4647  ; 1st magic value.' T5 V& G; {; f
4C19:009D   MOV    DI,4A4D  ; 2nd magic value., Z  B7 ~9 s1 v# ~
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)" g3 z! h& D4 B3 `  T7 C8 d
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute7 [! ?7 z7 y, h
4C19:00A4   INC    CX5 v6 R! N' p5 p
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute* i" o' G' @! s2 k- E; B
4C19:00A8   JB     0095     ; 6 different commands./ @( G5 S; F3 V% F
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.( M: B' V) x1 e9 r! J1 T
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
6 g  ~3 s+ g: {$ a3 d% g" f
5 @" n7 x; l' `4 W" i5 vThe program will execute 6 different SIce commands located at ds:dx, which
; L8 [1 y! z9 |$ K6 ~are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.* k0 i! h$ e8 N5 P4 R: r
% j7 T8 V0 H5 f( {5 q+ e2 P% g
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.( F$ u: a4 }$ P$ \/ D
___________________________________________________________________________
* {4 Q" i- l  c# O- y
0 J  u: M0 _4 _, D7 s; f; t
) V$ r9 f- b, c- J- E! V! ~Method 03* j. q! h' I) r. u3 \) h
=========
1 y! N: A: y  B& x+ h
4 ?6 f9 g$ b/ m% j+ p: \& S9 j+ |Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
' K: z" r# _* _. E  I3 b(API Get entry point)" c! D* X* t& }9 b) O7 ~/ q
        5 t( Y& @! p* F8 g; S

& v, W  X( ?( i. J! B' Z    xor     di,di
( ^% {2 x! s5 h7 I  ~    mov     es,di
* U8 ]* P( p7 `9 J: h2 h    mov     ax, 1684h      
" f9 s: ^7 d. q1 V( M9 p% T  j2 w+ S    mov     bx, 0202h       ; VxD ID of winice
( h+ u# i* D- _2 k$ J" u+ ^- u$ r    int     2Fh" [' @. K; ?8 _6 y: ~% O
    mov     ax, es          ; ES:DI -&gt; VxD API entry point& ]! X5 E' d. o9 ?+ \
    add     ax, di' @5 B! S$ y! O) Q3 @6 Z/ [3 `
    test    ax,ax+ k6 ]& Q8 F& X2 U
    jnz     SoftICE_Detected( U& k9 E4 h5 m$ ]
# K  M5 D8 v$ l- q3 Q9 q
___________________________________________________________________________
, {4 x& X- W: F0 X! i# x5 {2 l: F$ e4 R+ D
Method 04) X' C: F( K; t0 v1 W7 e$ ~+ W# @
=========
; z) S! ^  T' b$ f
! T! M9 T0 c5 n8 rMethod identical to the preceding one except that it seeks the ID of SoftICE% J8 R& Y$ ]0 l# `; c" G2 P
GFX VxD.
7 y; e, c9 L# d, d; M) d7 U1 w; U& K( w3 D3 Z, V6 P
    xor     di,di
! o+ V& P; M  V' @    mov     es,di8 D: e* U" w& j- G: k
    mov     ax, 1684h       7 i8 a- ^! ~" Q' }0 v3 ]" n
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
) H9 _7 O2 e: C% F    int     2fh  L; p8 r6 W- e1 p( n
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
3 p. n- H4 T" v: B: m) y    add     ax, di+ |) r( _0 w+ I2 n3 |% i
    test    ax,ax
7 R! U9 R  i; B; X0 l" |% Z    jnz     SoftICE_Detected
& l$ |, l$ m) o9 U8 f  O$ A5 F9 W5 ~: M
__________________________________________________________________________
) {9 Y0 G+ W6 ]& j  |7 w2 }2 v
# n7 @. w  u. r$ B+ A) X; i; P
9 G, a) z) h9 Y2 _: IMethod 050 J6 r5 G( J' E6 ?
=========) ?# t) c( @( |

- s2 T) k5 W. g& ]+ j% lMethod seeking the 'magic number' 0F386h returned (in ax) by all system9 Q, Z, w7 h: w5 X2 @8 R
debugger. It calls the int 41h, function 4Fh.6 _% |* P# K' S( o
There are several alternatives.  ( |% ^' `; A3 n; \/ w3 U
7 Z/ u4 f  t- {$ V
The following one is the simplest:
) [8 f7 r9 y! N+ i
" |  B: Q, f. [/ s$ L) m2 W    mov     ax,4fh
* r0 W# U& q7 x$ U+ D    int     41h
! c9 z! }7 N0 P( J4 K( [& Q, j    cmp     ax, 0F386: n# R$ P+ X; h" M
    jz      SoftICE_detected
8 g' Y6 l, s6 ^* G( K- U2 i$ \* b4 t9 [: @2 N4 q

7 }/ r' k8 S, c: r( [# ENext method as well as the following one are 2 examples from Stone's
" c* {% l6 a$ p- o4 a"stn-wid.zip" (www.cracking.net):
* K* o: |: w$ |1 }7 E( Z: F/ m+ T. d* Q
    mov     bx, cs
6 J1 Y8 e( `9 S: L" `    lea     dx, int41handler2
% N3 k, i; q% R. s1 i    xchg    dx, es:[41h*4]
: v) w- W5 i( }& A    xchg    bx, es:[41h*4+2]1 h/ E0 _4 \/ O8 ~2 d
    mov     ax,4fh
0 ~# v* f- k4 ^# e% Y    int     41h
2 U( [" ], A) @" R+ ]6 E/ R    xchg    dx, es:[41h*4]
# r( E# P& E2 r/ ?4 L  A    xchg    bx, es:[41h*4+2]
8 i( c3 U& S7 T! }5 S- Y    cmp     ax, 0f386h
# s3 s9 @0 F1 J; ~6 W    jz      SoftICE_detected
- R# G, i+ D& E" r. R2 w9 c, T+ X
int41handler2 PROC
- W1 S- b5 [1 n    iret
( \6 D4 M1 f: C$ s! s1 F0 Tint41handler2 ENDP
- |3 X* w0 r$ r9 }1 L9 F8 a2 f+ z
3 z9 t3 Y# b* t% B; q. k
_________________________________________________________________________; ?; I; z! D! c6 {) z: t0 V& Y
4 t! b4 E- w6 @# d7 m
& U0 o2 A. @6 m: J; u; j) k5 }
Method 068 Y* w+ A: g) [8 @4 V% {$ N; S) p
=========
8 s# [, c+ w5 l# v
1 [; e0 \9 S+ m7 V, U$ e* U& }! P
/ [: {  N+ `3 O% n5 ?3 H2nd method similar to the preceding one but more difficult to detect:+ |% i$ ?) D) X) t
9 [% f! q2 V: {8 p
$ v7 [9 F, Y8 f7 z
int41handler PROC
+ O0 m* M3 i. {9 S    mov     cl,al
  B6 ~; {9 @8 M! e3 Z+ [* d    iret9 I2 @: l6 N& T1 T' R7 t1 c
int41handler ENDP8 ?2 E% `4 f3 }# O
& G3 H: X( T' N9 x# t$ J' Q- F3 c5 d  H
" e$ {- x+ k! \0 W: z1 e
    xor     ax,ax
* @1 v( X/ b. V' [* {7 Z    mov     es,ax
1 m5 A# i% n/ m+ n5 d/ A+ [    mov     bx, cs% X8 W/ M7 c6 P  B9 Q+ l
    lea     dx, int41handler
5 e1 ?, j! W8 e( P; b8 r6 d. ]* E    xchg    dx, es:[41h*4], `8 A2 g, \1 X" l8 \- k; {
    xchg    bx, es:[41h*4+2]: R/ a) {2 q/ t: r3 P
    in      al, 40h
7 E, [1 h2 Z: A8 R. V: I; N    xor     cx,cx
4 j( u/ z0 \2 t, {. e8 n  n$ l    int     41h  l) ]7 r1 S: K
    xchg    dx, es:[41h*4]; m+ `9 b) P* {# d3 A6 `8 z
    xchg    bx, es:[41h*4+2]& ~  S' @7 Y. \2 R) z" P# q
    cmp     cl,al
+ }, x7 B8 ?/ P. u& x5 {* H& q    jnz     SoftICE_detected$ K6 X  J9 I, r, M+ `$ S
; V* Y" x! v- ]* l/ j+ f
_________________________________________________________________________! ]8 s7 d+ t% n& g& P  e  u( ~

3 X( K3 P, g& f; |- q9 xMethod 07. _1 O& E' V; ?7 s; K
=========
* W5 c2 k) E7 b/ S1 ?; z( C) Q7 w/ o2 n: n6 j6 C4 l
Method of detection of the WinICE handler in the int68h (V86)+ P: V' n( Q, T6 ?
2 n9 F! R% w* b2 w# S
    mov     ah,43h2 h2 G/ F' O/ p" P9 ~
    int     68h
# C2 ^; H, I: n7 ]3 v2 J) S    cmp     ax,0F386h
5 `. u+ Z8 T% u! E+ m; q6 h9 H    jz      SoftICE_Detected0 h% [/ l: V5 X7 }

3 ^% T  b( d1 o, ~0 J: I. z; o) \! B# I3 z' C1 b
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit9 W4 Q2 g7 S) ?9 Y. \
   app like this:, ^* A0 ^2 f4 T7 m$ |5 h# f

7 p2 H+ N; s) Z" W( l0 ?, X2 a   BPX exec_int if ax==68
; q# k9 W- p( o. s- N7 I3 P   (function called is located at byte ptr [ebp+1Dh] and client eip is
1 ^5 ~! r" T0 q+ Q" C2 e   located at [ebp+48h] for 32Bit apps)' z: `1 o. p! D- P! X
__________________________________________________________________________
+ \: l2 f. T0 k5 D
% ?% ?6 n/ A% H7 r: Y  W$ ~3 h' R1 Z+ C* i/ b
Method 08
9 o) f! |! A4 i, y+ Z# Z) }$ ?0 E=========
; a" V$ n$ \1 z7 e. s6 e* i. k1 [7 @2 ?" z1 B4 `; g
It is not a method of detection of SoftICE but a possibility to crash the7 G* J: ?, D5 [
system by intercepting int 01h and int 03h and redirecting them to another& c% d4 s! W3 n% U
routine.
+ I9 @9 O8 g& c+ E; E! H2 s' B& BIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
$ z3 z# |0 P* K1 Sto the new routine to execute (hangs computer...); h; P6 ^' R7 B$ ~" ]
* A+ M3 P0 t  c. M
    mov     ah, 25h7 o0 D! |% Y0 u& E; i5 z: i
    mov     al, Int_Number (01h or 03h)* W: F8 V% a6 n7 G; ~
    mov     dx, offset New_Int_Routine
* J" n5 t3 b  ~, ^2 L4 R    int     21h8 q1 c! \& E- ~/ t% r2 n5 k9 T

$ H2 d& E& X2 `- k9 `__________________________________________________________________________
$ Z' M7 {) ~8 c
  ~9 j) D) E! A) D' L9 ^Method 09
' V4 H! a8 _# X9 o+ T=========
$ C! e, E3 I& U2 R% O2 t* h; ^/ T; N- i
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
0 n1 g- J* G4 h" G) n) M5 yperformed in ring0 (VxD or a ring3 app using the VxdCall).) e( z+ l! p' f! K7 X
The Get_DDB service is used to determine whether or not a VxD is installed
. f3 P8 W& k3 S2 Ufor the specified device and returns a Device Description Block (in ecx) for
( u* ^! j% x7 F4 h# @" l( Pthat device if it is installed.
" }" r; o% Y" |" v) m: j
9 r7 b: G! O' `2 B8 W   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID9 A) \& d( e2 k9 e
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-). j8 r$ ?6 z1 g! [
   VMMCall Get_DDB' h/ b! I$ o1 z* Q5 Q8 ?* N
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
- p7 v! }! S, `9 [3 A. S* @
$ t0 v0 E3 ^! Y$ ANote as well that you can easily detect this method with SoftICE:
/ \/ b% g7 T: _8 ~5 T   bpx Get_DDB if ax==0202 || ax==7a5fh1 J- l0 J9 l# P1 ^% w" f. ^+ k! K- I
; Q5 d" _9 r& J3 r8 F
__________________________________________________________________________
  @8 @5 |: U4 M" Q" l
( G* f4 X6 O: y6 h" E8 w7 aMethod 103 L; [8 j' b7 j0 Q& T. c; O( G+ p
=========% z+ ]% X1 q, B

+ h; \1 ^3 E( n7 ]=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with- k6 O( F9 I0 ~4 r  r/ r) I
  SoftICE while the option is enable!!
& f/ C; R% N4 F% L+ ]& P
  B7 W5 C5 K  G* \9 bThis trick is very efficient:
% p+ q$ g+ g9 f3 b; sby checking the Debug Registers, you can detect if SoftICE is loaded
' H" T0 _9 @! ?6 I9 L5 {(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if/ N, W* b# z# |2 ]4 r! X& [
there are some memory breakpoints set (dr0 to dr3) simply by reading their
0 B. g2 W6 p: v6 Evalue (in ring0 only). Values can be manipulated and or changed as well  I- N) Q  L& y2 T3 M- g
(clearing BPMs for instance)/ T, y' x1 ^0 R* g7 {

5 G# Y; d& j% R9 f3 @! o8 U6 ~& l4 d8 l__________________________________________________________________________+ A3 b4 I7 w( u" S) ]) ~7 k5 |
9 Z6 m0 l" U6 x' {) v7 ?5 l
Method 112 t. f" k' A, F9 I2 l
=========
" ?7 Y7 \( C, G" {8 H5 b5 _" m
1 [4 k6 e6 h  jThis method is most known as 'MeltICE' because it has been freely distributed
# F- W5 `6 I! ^$ [) F6 ^via www.winfiles.com. However it was first used by NuMega people to allow, m# \2 S5 ~3 G2 C! ]& [2 ?" V
Symbol Loader to check if SoftICE was active or not (the code is located% ^% K( |8 b% N7 t- O/ b3 {
inside nmtrans.dll).  T# j9 T  D: }) G

) b1 R7 Y. o! p3 ]. t! {The way it works is very simple:
& O9 C8 [7 ~- |& R5 V0 W; WIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
3 [6 B) c" D: {: l  _WinNT) with the CreateFileA API.
8 i  q8 S2 X# O, K/ R( K
# y  z% L& T. n9 E% WHere is a sample (checking for 'SICE'):1 X5 A5 T- I! f# X3 C
2 y( [! M5 \* k2 _  H; _! f  ]
BOOL IsSoftIce95Loaded()- F+ ~& X6 J' Q7 q
{
/ ^; O8 X& K; d6 _/ R# D   HANDLE hFile;  4 X% W8 b0 C- X' A( ~0 j; m: O
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,& P5 U& L1 J' B+ f5 {
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
( N+ J: {% k7 B$ t% w                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
" G3 w3 ~- D, V   if( hFile != INVALID_HANDLE_VALUE )
* U) X0 V. s: B9 J: i$ b2 @   {9 S; I, D/ a8 c9 @
      CloseHandle(hFile);+ O# k1 j4 f" a5 }( ~
      return TRUE;5 m+ q* ?$ Z8 e; N6 ?/ t
   }
- t: _2 I1 Y2 F- r8 W7 Z   return FALSE;
4 l3 y5 l1 F8 c& }, M* Z}4 i" o4 l9 T2 B4 [/ A% D
6 c3 j( z. P; u- n3 U, c( |8 {
Although this trick calls the CreateFileA function, don't even expect to be
: a4 Y/ J; j0 K7 Aable to intercept it by installing a IFS hook: it will not work, no way!
$ g( @* }$ s+ u0 lIn fact, after the call to CreateFileA it will get through VWIN32 0x001F& F) f) G9 v7 n" [
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)* R. ]' x. N$ t$ K: a' J
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
; i; O& y4 c! ?6 Rfield.
. F' N3 s1 O% f' l6 IIn fact, its purpose is not to load/unload VxDs but only to send a 1 i5 Y( z: H) f6 _
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)! y: C& d' u! W
to the VxD Control_Dispatch proc (how the hell a shareware soft could try$ \5 v$ _  }# J- D
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
+ _: S" h5 A3 S! qIf the VxD is loaded, it will always clear eax and the Carry flag to allow* D3 N7 g3 F* K* ^" G  x; s; J# m
its handle to be opened and then, will be detected.
) c8 H0 x* v( h6 U) Y1 l1 ?You can check that simply by hooking Winice.exe control proc entry point
5 G  D' s+ n% ^; t* H0 n: Ewhile running MeltICE.
; h8 b8 U% R/ v$ W. x! k5 ~3 R% I2 a8 ~, s# m3 @5 h  g3 i
, L& @4 d3 d% }7 [) J, t
  00401067:  push      00402025    ; \\.\SICE
7 t8 P# h. {+ e. E7 x1 m6 i) x  0040106C:  call      CreateFileA6 j" O- a. X2 X1 W: ]& ]: ^: N
  00401071:  cmp       eax,-001
+ |7 }' P2 v6 @7 }. Z4 N. ?! a" s  00401074:  je        00401091; ]3 h) E# o. B8 l4 f0 f

' j; f7 p3 t9 y2 J8 B" W4 U) g( N" _9 ~; e' M# |  S7 c! u
There could be hundreds of BPX you could use to detect this trick.
: v6 n" P' P/ `6 I6 I-The most classical one is:8 ?/ u8 c$ ~9 s
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||$ d1 }1 W9 H- s) Y' O4 U; a0 B
    *(esp-&gt;4+4)=='NTIC'% W( L8 b, u1 R6 d" l8 z1 m' X8 `

. H$ K/ ~: l4 ]" K# c. m7 m-The most exotic ones (could be very slooooow :-(% \, E# W5 }+ L- n7 _
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
' v  t+ q" }: Z$ ^& n     ;will break 3 times :-(
6 `& d( R: e/ x( Z1 j: C
6 @/ \! w6 _6 n7 z4 |! i; J-or (a bit) faster:
1 Z* ?+ Y  T% V. x' y7 w   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')1 A$ q" Y; z) o( N; K( k7 z+ Y0 s

6 q; ]/ k: n( l7 A2 N   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
4 a( ^- ?4 \" M1 K6 M. T/ x     ;will break 3 times :-(
# X: }7 W* N# c9 `& r# ~) v6 j# r& D( X# K& Y) b
-Much faster:  m, m  w# o' {
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'- L5 x8 I: m4 t- {
- f" Q! g! S4 S  C% D7 {8 L
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
8 v1 Z. s3 r! H( `1 Ffunction to do the same job:* q3 e. a" v3 G% m

) K, n9 p. o4 r7 t7 v+ E4 f   push    00                        ; OF_READ
% R3 G. C- D4 H0 H( ?$ [4 @   mov     eax,[00656634]            ; '\\.\SICE',0: v5 c! x- u8 t* K; c% z
   push    eax( ^( |& D1 f. j7 K8 }
   call    KERNEL32!_lopen
# ^- Z4 |* ~5 ?* I   inc     eax
0 U% d& ~* H% _* B2 n   jnz     00650589                  ; detected
0 X0 k9 d; h# x6 B# b% Z' p) p% @   push    00                        ; OF_READ
/ A: y4 C" t7 }) x5 J. d   mov     eax,[00656638]            ; '\\.\SICE'
8 e- R0 }* E/ Q* V8 y5 L/ ]   push    eax$ e7 O4 `8 A" @; w
   call    KERNEL32!_lopen& G- ]# J( |& `, F* C
   inc     eax
# Q7 y6 X2 e" x# K: }) F" i   jz      006505ae                  ; not detected
6 F  s& ~2 Y  N6 W* z$ P# J5 b! p/ E4 t" O& o

6 i) e: }, p- u. `4 n9 Q5 i0 D__________________________________________________________________________; f* M- |: {+ B+ O) r* ^3 X0 ]( S

# \& a2 L; I$ KMethod 121 _1 G* ^( X# e7 s$ l. d/ J
=========9 M* z7 A4 }/ W) D

: m2 w- U# x) D7 i% X& OThis trick is similar to int41h/4fh Debugger installation check (code 05% f$ h6 s% N* L- e- k& A- M
&amp; 06) but very limited because it's only available for Win95/98 (not NT)' q9 T& a8 Z! X
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.( S2 T$ @9 f7 ]" B8 q, C( l
7 _" Z3 J. K$ w' @" C; `% \5 s
   push  0000004fh         ; function 4fh
: b; t) D& q! o( P. v& U5 l   push  002a002ah         ; high word specifies which VxD (VWIN32)5 t. r6 n! x2 v5 R( R
                           ; low word specifies which service/ H: R" w. R- Y# z) Y: X
                             (VWIN32_Int41Dispatch)
- S, C6 v4 c6 L4 A' y   call  Kernel32!ORD_001  ; VxdCall
# v# F( p/ o  z; m   cmp   ax, 0f386h        ; magic number returned by system debuggers; C' h1 d* A! ?$ p
   jz    SoftICE_detected
* n. Z' ^( D3 f4 K# F- e! U+ X& p# [3 ^
Here again, several ways to detect it:
: U+ J5 g/ K8 {0 R( |1 K# V* C6 }1 W
    BPINT 41 if ax==4f2 {  o9 I' t$ c, i  [" ?

1 [$ i" N! G: w; I1 z5 p+ Q    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
, h1 F! v1 L0 v9 r& l$ G. X& {5 j7 I) [' p- T  X, q
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
6 s5 @: A! j3 U7 W5 T
5 x* g: ?8 i0 x' m( ]% Y1 I    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
8 U' `9 r6 K% [5 A  v  f
6 `6 K; L4 Q9 m( F9 ~__________________________________________________________________________7 j3 d! E; y1 H

! o+ `$ n, t8 D; `  uMethod 13
  m+ z" x5 m5 p: [$ _" e3 t2 ~=========
! H" i+ @( w( N& e# U% e  s' ?1 Z; b" }# }+ ~. N7 ^
Not a real method of detection, but a good way to know if SoftICE is
. |" K% n7 X. c  M" vinstalled on a computer and to locate its installation directory.
7 g0 s2 @& P# @# _+ E3 JIt is used by few softs which access the following registry keys (usually #2) :) D) O  c9 x/ J) `: P# O9 W2 R

& T) s9 }* f. r-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
$ U& m& E9 Y4 E% ]\Uninstall\SoftICE; n5 ^9 W, ^  l
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE! L# Z9 I8 a8 q7 @8 D; C5 ?
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion/ c0 K' Z8 b+ s% J  D' C" A2 \
\App Paths\Loader32.Exe5 t1 f, j+ B- ~8 }6 t2 m
2 A: O3 `, Q* k' j
: W9 d0 m4 M6 |0 `$ x) H! F4 v
Note that some nasty apps could then erase all files from SoftICE directory
; U: `1 N' r+ G6 S(I faced that once :-(
/ d8 V, b/ M% z4 S) G) u8 T. }2 F' D( s; g% y
Useful breakpoint to detect it:1 C% ?2 w  u/ a) l# `+ c
  @9 a4 n: Q* P6 n) a/ G& K
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
% j5 O5 A" y1 x- c1 x2 J" M1 x
6 |2 {* o4 g4 d7 {, w__________________________________________________________________________
% l# c5 I7 z- y+ k2 i* r2 G
: _6 m/ D3 }( X1 v/ E6 c7 f
& G5 U1 P! M4 B; a, W8 `Method 14
$ ~7 A" K* q0 ?, G% f=========
( Z) J% {: E1 F8 f) x$ D3 g$ K  T3 a1 ]! `% W8 g
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose8 m& n, f- Q$ F+ X1 g
is to determines whether a debugger is running on your system (ring0 only).
0 c8 A1 k( N! v  v) S
2 q0 A2 s$ k: j+ e6 q% q   VMMCall Test_Debug_Installed
  Z" M) a3 h8 B   je      not_installed2 b  c& x3 T. e# E* \  y' B1 q6 b4 q& m

3 K& @' g- Z; `$ [( ]" D7 X  PThis service just checks a flag.- u/ Z8 c& C* y7 M
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部