About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
8 j8 X$ A8 l8 P7 p6 S1 c$ _; f<TBODY>* a3 ]- L0 L7 Z# [" O( R
<TR>' }$ E' i/ f" @7 \
<TD><PRE>Method 01
7 U; D3 l, t& [& x=========
1 A8 e: b7 J' L5 I9 H4 z  @  r# F0 |& W1 X
This method of detection of SoftICE (as well as the following one) is
0 I$ O; q3 O) g  rused by the majority of packers/encryptors found on Internet.
1 Z: E6 X, J/ S0 B0 \, jIt seeks the signature of BoundsChecker in SoftICE9 g# B' @. |( x  r3 E6 S+ P5 V
# {3 T! E9 a% q1 A7 T4 J0 q6 q4 t
    mov     ebp, 04243484Bh        ; 'BCHK'
, o* W9 n1 i9 Q: [: j- h6 ^6 Z9 E$ {    mov     ax, 04h! U; C. Q% j( c4 ~
    int     3       1 a2 w% T! E" H+ c: L5 K
    cmp     al,4
5 m+ T. h, n2 s  F' v    jnz     SoftICE_Detected# ^0 D$ f6 I# S

! q8 G9 G: W. T3 {___________________________________________________________________________
; G2 [% x" U+ Z0 M# u- R* Y# U3 U6 M0 j$ x. a0 ?; ^8 b
Method 02' x! J7 ?& U7 H
=========: `2 u1 G/ ?4 }; E7 Z1 B/ y
  e( o5 J# l: `7 Y0 n# h
Still a method very much used (perhaps the most frequent one).  It is used
9 A( C' K! n/ ]/ [1 J- d2 Ato get SoftICE 'Back Door commands' which gives infos on Breakpoints,0 {9 ]+ H: S  o, d: b
or execute SoftICE commands...$ b3 `$ g- m; }3 H- |8 q, U
It is also used to crash SoftICE and to force it to execute any commands
3 x9 e& X. u8 ^0 u; v(HBOOT...) :-((  ! Y: a& J7 [; g# W/ ^( V
2 {0 C1 _3 R# i' v3 r9 g
Here is a quick description:' c6 f8 U& ^, |! G" Y
-AX = 0910h   (Display string in SIce windows)' q9 W0 h) W1 Z8 b# ~
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
+ J: h5 w5 q* C2 x-AX = 0912h   (Get breakpoint infos)
& b( ~; g9 d. J5 i: p-AX = 0913h   (Set Sice breakpoints)4 w6 j- U$ s. \* R5 l* e
-AX = 0914h   (Remove SIce breakoints)7 s. w/ R* W" Y3 L% P4 E' j7 z

1 T$ G- W- t: l6 XEach time you'll meet this trick, you'll see:+ C. p% f$ f3 v% Q  R0 Q6 M
-SI = 4647h
. a% s: W+ T# m& ]-DI = 4A4Dh7 `$ w4 c+ b" v# `
Which are the 'magic values' used by SoftIce.+ ^1 y2 k9 x# ?) N3 ?
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
% J" ~. ^0 K2 {7 F( i
% t/ Y: U/ B1 Y9 b" K8 h7 zHere is one example from the file "Haspinst.exe" which is the dongle HASP) q( ^' c2 i) f6 _
Envelope utility use to protect DOS applications:) l/ |8 O0 p( o( Y# @- x6 \
1 L* m) M0 w1 p2 u
: Q3 o7 {% I; X' D" y
4C19:0095   MOV    AX,0911  ; execute command.* U$ D3 Y, P' G+ p/ y2 |4 t
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
+ I" A7 L4 I) A- p4C19:009A   MOV    SI,4647  ; 1st magic value.
  w+ v; \/ ?/ H$ d( _3 V4C19:009D   MOV    DI,4A4D  ; 2nd magic value.8 Q, x& C  e! R
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)* \5 S: r4 Q) `
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
/ S% H; C: m$ q9 I* A4C19:00A4   INC    CX( J/ @5 o3 |8 ^2 N* O) z7 b9 Z
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
0 v! d* p) l/ n, W& g' ^; U4C19:00A8   JB     0095     ; 6 different commands.
5 ~" q+ r) V4 ^! R3 ~& U, A! S0 N4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
0 @0 e" G+ e5 @  d4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
- |0 j6 i; K. [5 ?. Y7 K
( e) ^/ s2 s3 F3 d' ?The program will execute 6 different SIce commands located at ds:dx, which
/ g6 A8 a( B/ U' b9 Xare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
) R9 V8 I9 f4 o" \) d
) w9 i, m9 a+ x1 r- O5 S" g* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
. b  g  q# z5 D. I: X___________________________________________________________________________  m, I: g6 v  e2 S
1 o" S# F7 B8 Y1 l' x
: _, t! O+ q, ?' n9 [
Method 03
8 F4 ^5 k5 W. d" G6 c! k=========
5 P5 }# D  x/ n$ ~. j3 w
  E  \* j5 p* O  o0 dLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h" j9 |+ x7 Z6 c' d! ]' U) g
(API Get entry point)* w8 ~$ Z# [/ \
        8 X2 N- W) ~5 A6 P

5 g; P( M" D5 Y) y5 L    xor     di,di
! e4 z& P* i7 N$ k8 z1 R. D* W    mov     es,di" v$ ]5 l9 q3 L' }) Z& J
    mov     ax, 1684h      
/ e3 T* U+ _, i    mov     bx, 0202h       ; VxD ID of winice
0 E0 e9 ^2 ^5 j- Q/ d' @    int     2Fh" X& i; P" f( k$ b5 I
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
  Q) j& M1 ]7 w, {  H    add     ax, di' C/ v2 ]# v4 x7 s% r& Y% u
    test    ax,ax- d, x$ S, `0 u" y6 e- X2 f: {& L
    jnz     SoftICE_Detected7 [) a7 @3 o( y) K* C( f$ a( _: q

2 N; T+ r* r: B/ G___________________________________________________________________________3 S! F1 v- d0 ^% a- D% K. [
- J( U1 P, t5 B& g9 }
Method 04
& w# Y$ P' P: A* j- D2 ?+ `=========
9 \# t5 w6 ~. f! ]# e$ T. p9 ^* d( F/ F5 b9 L7 Y
Method identical to the preceding one except that it seeks the ID of SoftICE
, R0 O! h' z$ XGFX VxD.) n. h) w% O- ?8 u

) }* D7 A' S. a! a# `) Y    xor     di,di
; H6 t8 y- k0 S, h    mov     es,di
/ U4 I9 G( Y( O! i' M* x+ m    mov     ax, 1684h       1 g7 X" U. t" \  t+ z! _1 W
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
; A9 E" B- Q& f0 y5 I" S$ k5 X0 b    int     2fh
) g) _+ b3 A  l    mov     ax, es          ; ES:DI -&gt; VxD API entry point
% V* K* `7 ~! e4 F. e    add     ax, di
9 M  I9 O( w( v3 r. o; g    test    ax,ax1 t- }1 Z$ [3 C! l8 `+ v7 T
    jnz     SoftICE_Detected: E0 C7 L0 v" i2 H
/ h/ Q* s* q' l2 s+ n& o( O
__________________________________________________________________________
2 ~5 N' M* f8 j( }
6 U$ I  q7 U. ?% d' A* ^6 O8 z: R
Method 05$ r4 e8 r( d0 w7 ]: s, A
=========
5 }' T+ {& H' a! q+ b
8 M. O# @) {! A2 {/ PMethod seeking the 'magic number' 0F386h returned (in ax) by all system
3 e% @4 X: x" a# Z9 ?debugger. It calls the int 41h, function 4Fh.7 g5 e, C( p; l4 m" O1 C
There are several alternatives.  
2 s6 |& A1 R7 i7 T- ?$ g) Y: F1 b) ~
The following one is the simplest:9 {8 z) N0 |; c1 {. G
3 X& v1 i4 P$ W2 d3 x
    mov     ax,4fh, ^: G! Y9 t% E6 B) m1 P& |! V
    int     41h" A2 i% g! \2 F0 S8 ^
    cmp     ax, 0F3863 m4 a  t' V5 k( B* {1 @8 G+ Z
    jz      SoftICE_detected( ?4 |$ l- C( A9 O5 h3 S

  S- I9 f9 v" P( j- f/ M1 @* W4 q
/ U9 ?+ \: X: H) A3 a: r; TNext method as well as the following one are 2 examples from Stone's
) D6 T8 M) {. U% c6 j"stn-wid.zip" (www.cracking.net):
: M6 R/ Z: Y! `; ]6 |" h: W/ i+ `! X7 l* @. I/ g" I+ o
    mov     bx, cs
/ y9 F( f6 \& j2 x+ \$ A6 }    lea     dx, int41handler2
  b$ n) ]; C' M& N0 N  D    xchg    dx, es:[41h*4]- S2 N. w- }0 P; l! u, L1 z( _
    xchg    bx, es:[41h*4+2]
) Z( V, h! Y: Y0 L    mov     ax,4fh
$ n! A: k" q. M% y    int     41h5 K- ]# G( N9 h2 a
    xchg    dx, es:[41h*4]
* V' u" z" }$ e$ p+ |8 Q9 r, C    xchg    bx, es:[41h*4+2]
% a# p  B* V# @! I( H    cmp     ax, 0f386h& y8 @7 V0 V! h$ u% m
    jz      SoftICE_detected
2 E3 t: T+ v2 \/ H, J2 P2 B
. j2 W0 o4 V! Y. f% S6 _3 rint41handler2 PROC
& i7 }% x% O0 d/ o7 a8 t3 V- v) e    iret' O! A  r, H, Q' a: d+ Y; E
int41handler2 ENDP8 q8 V% V, F& [* j9 P

( h7 y7 d6 Q  l3 ~6 H1 ]4 H9 d0 d8 C. P1 K5 P
_________________________________________________________________________
* d; r! k9 A" `* o
3 b  i7 l$ S1 l
' q2 p. W9 \& O8 u, zMethod 06( L2 O* H0 E2 U6 x( V
=========
9 p) Q8 }) D' X5 Z! {7 @" O
  u1 S" E. e, i8 ?2 A( _
; w' [6 p8 Z. k2nd method similar to the preceding one but more difficult to detect:: r. i% ?  _% r  S/ u

' n( y, ]; |* Z5 X) Q: }$ h2 a/ y& a( w6 g2 p8 ~
int41handler PROC* Y7 b' ^. u3 Y
    mov     cl,al; `5 P) \5 `# C* z( O0 ~( {% \
    iret! `- H4 \4 O0 i0 R# ]( u
int41handler ENDP
+ z2 C# L& |1 p) Z# R
  i! g5 B9 k+ c( z
! Z+ Z( C8 D2 T) f, s7 \    xor     ax,ax
  j* N  @+ |& T  ?. r, _! O    mov     es,ax
) h& d0 J6 ]- _8 p5 z4 ^    mov     bx, cs! a8 f' ?7 l: ^# \0 P
    lea     dx, int41handler
' g  F  B, f7 ^: e    xchg    dx, es:[41h*4]9 ]7 j: r0 J; q3 {& I- T
    xchg    bx, es:[41h*4+2]
; X0 r+ z0 r# B. C; d    in      al, 40h3 E$ y$ }5 s/ j. r/ @; B! B' |
    xor     cx,cx/ b/ ^; F2 ^$ `; o& v; P" V/ f
    int     41h
/ }" v, |9 ?2 C  @: l$ [    xchg    dx, es:[41h*4]" p! \* ^- v/ B. H* y
    xchg    bx, es:[41h*4+2]. m6 T% ]9 D/ s" M9 O
    cmp     cl,al
/ D8 O8 i6 S+ N6 i, T: D    jnz     SoftICE_detected) M! o: }8 l$ @% ]4 x

2 e2 H3 ^" n3 V+ F* u8 F2 k  X+ }_________________________________________________________________________1 q8 E5 r' k8 H9 h! i7 T$ k' l! J* r

; q' a* s1 L' j0 n* B. t. JMethod 07
+ o/ P  X) {8 o! t$ N9 I=========$ p& o& N, a- g" f9 R7 a

  ~! l- o- f; b9 ?Method of detection of the WinICE handler in the int68h (V86)
( _4 G0 n7 `# B4 q
& K2 h9 G. I; A8 a3 X    mov     ah,43h
! Q2 x$ j5 B  m5 s' R# k2 d    int     68h4 ^( ^1 v7 R$ A
    cmp     ax,0F386h' z. K! b% M- W2 h% _5 V
    jz      SoftICE_Detected2 }* Q, ?! w  e1 g, q

+ p8 N; z; Q3 e' h  @9 e8 y2 Y3 Z6 Y! \, a# I/ c
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
/ f# ^! c. ^$ ?: V2 J4 x9 V   app like this:2 Y4 E# C5 p& E$ D

  G0 ^3 T$ [8 f3 |! w" A, S% J   BPX exec_int if ax==68
) d# z) n; k+ S0 _) q+ F$ T- G   (function called is located at byte ptr [ebp+1Dh] and client eip is8 e1 F3 ]; k4 p
   located at [ebp+48h] for 32Bit apps)
- [+ M& L& t; i' N: |% F) V5 L__________________________________________________________________________
& I8 H5 ^2 O0 q- M4 F5 d+ _( z/ A1 L) N5 g; S/ S0 ^4 ^" w; |

3 @2 D% Q, \/ ]Method 083 R/ ?- A9 G- Z6 _
=========4 u+ i3 b6 g. q. A# K
" N! W* \  d5 k9 [1 K+ \
It is not a method of detection of SoftICE but a possibility to crash the+ S- y8 B) ]" W" }/ a
system by intercepting int 01h and int 03h and redirecting them to another
* J* O+ ?3 x) ~5 [" c* r( i' ^routine.4 k4 m$ O8 r. }9 U* H0 ?
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
. l' ^+ V4 D8 o$ G6 l! hto the new routine to execute (hangs computer...)
" K: t$ T3 x8 h* A" N7 p) Z& W' N! n4 g7 S, a1 W
    mov     ah, 25h+ `: B! I7 o8 t0 J
    mov     al, Int_Number (01h or 03h)# n  ~* e8 G! S! J
    mov     dx, offset New_Int_Routine
/ _, @* {( b+ @! ]% f    int     21h; h+ ?8 M/ I' x3 ?; P5 d6 F  B

8 \$ L2 i1 b6 i( ~- P. ~. c__________________________________________________________________________
1 B0 w: U, B6 Z7 @
/ f* m( _/ H) [( P7 M( HMethod 09
) S& S5 N0 \4 l: N. n9 G/ a+ x1 r+ G=========. _6 {" }; [# z( N+ X, z
; o+ d' I( i% z# z7 b1 x7 o) B
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only7 L' a/ L+ n: E" J9 g
performed in ring0 (VxD or a ring3 app using the VxdCall).
; [+ Q& I7 h% M$ y; N$ tThe Get_DDB service is used to determine whether or not a VxD is installed8 b+ P- S* a4 i2 V) ^0 j( Y
for the specified device and returns a Device Description Block (in ecx) for
6 }. H( x: N2 j* C/ O0 L( l" d, nthat device if it is installed./ p  e% p! Y+ H

- Q0 U7 W5 {0 o. g  E& L( d; q   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID: a' q& ?0 N/ @9 q. e1 P
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
$ w- H: s8 p0 G   VMMCall Get_DDB
" R9 d6 k5 c" a  J( |( }5 \- w& ~   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed; \1 e# o2 N4 b8 t' e

. o; `; B+ D5 X1 ~: ^Note as well that you can easily detect this method with SoftICE:" \- B4 e8 \1 t8 l  ^
   bpx Get_DDB if ax==0202 || ax==7a5fh
; B* n! m' p3 s9 {; k. `
( F4 _8 F* K$ j4 e: {8 a! L* _, t__________________________________________________________________________
1 Z6 R3 I. J4 _5 [
8 h9 w" H" L0 r0 D( L! l9 \Method 10
3 c( u5 A% h+ y=========
  Y2 O) A- f/ p. a: n- x
  l" ]5 m/ I9 v" |6 @; K=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
1 z/ a8 `; k1 l  SoftICE while the option is enable!!
4 @3 l' Q- u' e0 W2 {9 Z( U1 T. \3 p
This trick is very efficient:
" t; C) z7 Z8 E1 [by checking the Debug Registers, you can detect if SoftICE is loaded1 m+ a2 q- v4 K3 `2 m5 F6 ^6 f
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if8 f1 A, b! I7 |
there are some memory breakpoints set (dr0 to dr3) simply by reading their; b6 h. O0 F3 I4 M. {. ?9 x- S  {$ y& P
value (in ring0 only). Values can be manipulated and or changed as well
# p- p/ S% g  f' f% L5 n4 X* `5 I(clearing BPMs for instance)
/ s0 j' U; S8 h) d+ O) H  S$ i- f( E5 K- L4 j9 j
__________________________________________________________________________( x$ N6 P) J' Q$ I4 H

; M. R  X/ S- c/ Z! x( C7 f4 B% f4 AMethod 11/ T: i8 `6 u. c/ \" Q- @
=========
( R" {2 P5 G$ x! T# ?% o
7 I7 O) T% `8 E! BThis method is most known as 'MeltICE' because it has been freely distributed
/ L0 Y% J% C6 H$ {2 e1 bvia www.winfiles.com. However it was first used by NuMega people to allow
/ U  g# g; ^( T! i; pSymbol Loader to check if SoftICE was active or not (the code is located4 p' u! w9 J: l5 J3 L& L& b. E- I
inside nmtrans.dll).) Z% D( P) Y* N; c% i5 X

0 U$ l8 c- t7 B& c; p6 c- ?The way it works is very simple:3 }3 j1 O" a0 d# t5 L6 I* @
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for! M3 R% V, x( B& g' i
WinNT) with the CreateFileA API.
& E9 f: u* f/ k4 M4 p8 l$ `9 X$ h  e" X7 x$ Q3 ~8 K- T
Here is a sample (checking for 'SICE'):
* S$ o% l6 G) c7 K9 R/ z5 ~2 D# b' ~6 l0 D& E/ q& W$ a7 N7 M6 }# F
BOOL IsSoftIce95Loaded()3 |9 ?! W/ [1 F9 w* w- F7 }* r
{% S8 V- A5 l3 T, m
   HANDLE hFile;  
; M4 F1 _( C4 V1 p; \1 G   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
6 B; Z# h4 O  ], S$ ]                      FILE_SHARE_READ | FILE_SHARE_WRITE,) t, o/ x6 ?+ n& K
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
  R7 D( i: E' c  R4 R7 D9 g% [   if( hFile != INVALID_HANDLE_VALUE )  e* L6 y, P" f) }8 w7 s1 T
   {; A! n$ J2 W9 o3 w$ I7 x
      CloseHandle(hFile);
" Q) j6 o0 @7 n" x; z3 ~; M/ F9 ?0 T      return TRUE;
+ f# a; w, I& ^/ b1 @' W   }, e* E; D1 k  v- y) J# b8 V
   return FALSE;( p* U! ?9 H+ `: p3 j: `
}
# m) W% K5 ]2 H. q7 O" u
7 w7 R! ]8 P  O0 t, b0 k+ w& D# EAlthough this trick calls the CreateFileA function, don't even expect to be. H4 \* V9 g0 L# T  X/ `
able to intercept it by installing a IFS hook: it will not work, no way!
) T& k' ?& @( E+ o% _In fact, after the call to CreateFileA it will get through VWIN32 0x001F3 G8 R+ G4 f- g; `* T
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)$ @, C" L9 U1 V2 q" Q8 o6 A
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
) {7 X# B0 J9 ?; E7 Rfield.$ t6 M1 D' t$ k
In fact, its purpose is not to load/unload VxDs but only to send a / V5 }: m4 }6 v
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
- J0 H; s. N- U8 |/ a" p, O) T: f0 sto the VxD Control_Dispatch proc (how the hell a shareware soft could try; K9 Y, n, D2 `
to load/unload a non-dynamically loadable driver such as SoftICE ;-).! Z9 r$ u2 Z2 |. Q
If the VxD is loaded, it will always clear eax and the Carry flag to allow* Z# D1 ~! I, I2 N2 w3 S1 ]
its handle to be opened and then, will be detected.9 N) S+ v( a5 f5 Q) a. a' O$ G  U
You can check that simply by hooking Winice.exe control proc entry point
/ h, K+ F) N, u, t5 ]1 Hwhile running MeltICE.
7 _( l6 T$ v& L: _
& @# x  a+ b: Z' z. v' m  l2 G, c
  00401067:  push      00402025    ; \\.\SICE: h) P+ E' Q' K! q- y4 F
  0040106C:  call      CreateFileA  N! H' r7 ?) f$ ]/ P+ Y# T
  00401071:  cmp       eax,-001: ]2 l5 E, Z4 J4 `+ t6 W& F
  00401074:  je        00401091
" J0 y, I: B$ c) P# |! Y8 ~- l
8 c) H: z. `2 o1 E6 T7 }6 Z, v% R! y+ ~/ S  n
There could be hundreds of BPX you could use to detect this trick.+ \! u) X4 y3 K/ n  `
-The most classical one is:
# I4 a' s$ ~3 ^$ \3 u3 D7 R  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
9 G/ C3 m" r) [( m# @, ~9 [/ }$ [" Z    *(esp-&gt;4+4)=='NTIC'3 Q) {( P! M+ e7 v5 b6 S
" s" T) j; \: p
-The most exotic ones (could be very slooooow :-(
6 K( i& d& i$ J+ O   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  7 O" [4 |  t) m) |5 B7 w5 G
     ;will break 3 times :-(
0 H( |5 W+ b. V4 R6 I
, F" p1 w- N, k1 p  a, |4 x7 t% Q! {5 ^* S-or (a bit) faster:
. I2 ]4 W: y: s7 W$ ]   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')# @& t* U; L* O6 g

% P/ c) d% G6 w/ [& q1 L: B, m   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
* Q* e( U) X2 W& u+ g     ;will break 3 times :-(
, l3 M. o- z' o. A4 Z" ~
! I- ~- K& n) l* C-Much faster:
0 q/ d% K! W9 ~   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
0 O3 F2 M, K% u4 L( _! m- k: f  J; `
+ ^( h6 f7 j; k8 C* v" ~1 lNote also that some programs (like AZPR3.00) use de old 16-bit _lopen7 l, ~& {" n, Z! {
function to do the same job:4 _7 v/ P% k" B) T( i$ Q( f
1 |: l8 B5 q6 F  H
   push    00                        ; OF_READ# w8 \. S( [; S+ m8 I+ B
   mov     eax,[00656634]            ; '\\.\SICE',0
3 V7 j, N) C/ l$ r   push    eax$ s4 g$ \4 ]2 J: b2 I+ l) a& v
   call    KERNEL32!_lopen
0 p3 M0 O9 R8 v0 m0 O: t+ E- I   inc     eax
% g1 T/ n# @! i$ s5 \. X   jnz     00650589                  ; detected
: L% ~1 T) Y$ {( b   push    00                        ; OF_READ
- p5 ^0 v. `& U& K% s1 I   mov     eax,[00656638]            ; '\\.\SICE'
& F* d8 {0 ?/ I& U   push    eax; N% }2 l1 Z+ S: e% ?& s5 A1 n! `
   call    KERNEL32!_lopen( R, k% X; @2 ~; E; ]! H2 r1 A
   inc     eax; O8 q- |& \) ]' m4 \
   jz      006505ae                  ; not detected
9 D# z) o" ^( T$ P: h6 q8 K7 R- w. P" j$ A5 O! B1 e6 R7 j

# [. J; U. H* Y1 C4 W8 G- g. Z, N__________________________________________________________________________7 ~$ ?0 k$ Z; X9 z6 f, l

' I) X1 _% b. y/ IMethod 12
1 Y0 W9 R, O$ X& ^! z=========
1 k: j, i0 J* b- X: _6 Y: k, l1 c; D& U# _/ T) D
This trick is similar to int41h/4fh Debugger installation check (code 05
9 N: @; A5 V; ~" l& `) w. L&amp; 06) but very limited because it's only available for Win95/98 (not NT)
0 f; a; _4 A. F( s/ Pas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
. Z$ y: F' d8 n2 u( _3 c: T/ d. K/ W% W
   push  0000004fh         ; function 4fh
3 v, u) y2 g0 Q* y# J   push  002a002ah         ; high word specifies which VxD (VWIN32)
% ~) M' b$ b6 _! N; h$ f1 {                           ; low word specifies which service
4 F) o# b+ Q6 \4 Q' t$ D                             (VWIN32_Int41Dispatch)
  l( b+ h" u9 e2 M' [; Q) z6 w   call  Kernel32!ORD_001  ; VxdCall
8 `  n' ?% O* i$ P" {% j* c( ^+ n   cmp   ax, 0f386h        ; magic number returned by system debuggers
3 N: k& [% ^: y/ S/ a2 n4 O   jz    SoftICE_detected$ i0 t1 V( s, D0 q( t
# R# c9 e* _/ O+ ]  x
Here again, several ways to detect it:
6 ~% ^4 y; K6 B$ E" B" u% _7 d
  j/ U7 `% A& v, K7 w3 q' P    BPINT 41 if ax==4f
! h/ L: N3 S+ d' Y& ?
2 u/ |7 J  b5 {4 D    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
6 ?7 {) t6 V& m! Y5 I2 B
: H6 l) g2 u% N2 U( ]8 T  \    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
: i) u# q5 o7 z* @
! ]" U; r/ n& ]    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!" |8 ]/ G6 r1 H3 \9 F$ E/ o
3 v+ ]% e# J" |: f# _/ i( W
__________________________________________________________________________1 X( [) n. z" N7 ~
8 Y: \" ]- M, h& [" O
Method 13
7 P! S) ^: R  L# U1 }. c$ }- Y=========
' f3 a  u/ Z& ]8 q/ R
- M  z1 ~9 L) l- G. ONot a real method of detection, but a good way to know if SoftICE is+ v- @2 h5 _6 M
installed on a computer and to locate its installation directory.
% V$ z( a! `+ M' B4 MIt is used by few softs which access the following registry keys (usually #2) :
/ |* _- U1 \; O& [7 x: N5 v5 Y2 N- J/ p, }
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
, O- N5 d: u7 @6 X4 y# `- Y\Uninstall\SoftICE
+ c" D! w2 O- u! S; l( J8 X6 c-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE1 y+ l" g; O; H$ A( B; J; y; N' V
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion! b8 T+ \0 e4 M3 t/ y% M( d3 j
\App Paths\Loader32.Exe! n" a+ C# Q' Q" P$ [

  Y* y7 p$ H" B0 g0 O, z) q) c" j" }- {: _2 V% [- P
Note that some nasty apps could then erase all files from SoftICE directory* y, O; U+ p$ u$ Y2 o4 H
(I faced that once :-(
# L" F. e8 b3 j& r0 C; i- E7 s$ }4 u. q- ?$ C5 E
Useful breakpoint to detect it:# W+ s6 F; j9 a/ j0 r

9 T7 F- g3 Q! f7 s" B     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'1 k6 U. I1 H, \5 U- r
( {$ p. _0 r/ A
__________________________________________________________________________
( @$ E! k6 l  S6 P% P3 Y
3 T8 `4 I7 p7 @* x
1 P/ E( I, b5 o# n, fMethod 14
6 p( e. L' ^/ M; O=========
& ^2 P5 [8 X" r  [; h$ [
* [2 i. i. v4 N6 P1 a) wA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose, t/ P' M4 ?$ A
is to determines whether a debugger is running on your system (ring0 only).
9 p2 B. c$ Y* m1 f
% n$ Q" t* ?0 S' r& ?0 l( [   VMMCall Test_Debug_Installed; [) `2 T9 _( F& Q
   je      not_installed3 {$ `2 v- q" X: u1 f

  x, \. \4 ~1 E% p8 pThis service just checks a flag.
$ c8 |1 ^/ w; ?, q8 |6 f</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部