About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>/ ^$ G" s) z: Q+ g; Y
<TBODY>
9 |4 N3 o+ Q! o0 x/ }<TR>
. e$ r/ {* S5 c<TD><PRE>Method 01 + s5 g  w+ u  Y. t3 b  K/ W
=========6 r& a- {0 e7 ~) j

. S6 i# E  Y' n8 p1 B$ A* o9 k2 @" U( PThis method of detection of SoftICE (as well as the following one) is
: ]" t/ n) H: c5 zused by the majority of packers/encryptors found on Internet.4 w3 C5 U# }  i7 F7 k; Z: T. T
It seeks the signature of BoundsChecker in SoftICE- j! `6 @0 W' `9 O8 w
0 Q; L3 v9 U4 x% c) b1 U4 ^7 o; D
    mov     ebp, 04243484Bh        ; 'BCHK'' [. I. b7 t# R) ~) t3 t4 M
    mov     ax, 04h  M! h9 t9 Z8 h( d6 J% A' Q! S4 B
    int     3      
, Y, ?) I# v, ]    cmp     al,4& f6 o) x6 q! m
    jnz     SoftICE_Detected
7 P/ f% @3 `9 e1 r, c6 ]* i* Y% s' R# C& j0 T+ ]
___________________________________________________________________________
6 d, F$ T3 {0 K% i4 h
  e% N/ Q1 \$ Q+ i/ VMethod 021 O7 N, g2 A9 a5 J
=========
6 l  V8 f, K) W
/ b) n  S% T; g9 z7 TStill a method very much used (perhaps the most frequent one).  It is used0 Q/ l% w/ ^5 \, h, G+ n% o" W
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,% D+ P* x! e5 k, p) S# o. g
or execute SoftICE commands...
. C7 {) z! u4 LIt is also used to crash SoftICE and to force it to execute any commands' C  j9 [( z( i5 W+ a9 P$ k" G
(HBOOT...) :-((  
: ~6 L1 A3 K* F
3 C1 v1 V* [3 EHere is a quick description:
; Y* a( o7 V7 P4 J0 N-AX = 0910h   (Display string in SIce windows)
1 W6 y  N* x6 h9 E7 A8 T-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
: k: R3 Q2 [$ f$ w& Y-AX = 0912h   (Get breakpoint infos)2 G: N$ ^7 @6 P4 e9 w
-AX = 0913h   (Set Sice breakpoints)
" O; z) i; ~* L8 A+ s8 J-AX = 0914h   (Remove SIce breakoints)" d* x8 b3 B4 g2 D
1 Z' L, d) F: ?  d
Each time you'll meet this trick, you'll see:% x4 e; K% ?; ?) m  A& I
-SI = 4647h
, u, c; ]# T& j& f-DI = 4A4Dh
7 p4 p; v: a5 y1 }- x0 LWhich are the 'magic values' used by SoftIce.3 H# `  k/ A' C$ d6 G; Q
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
% Z6 ~, h2 y" a! Y* Y1 y
' U, k3 n  M  `0 ^6 V0 e6 QHere is one example from the file "Haspinst.exe" which is the dongle HASP. b& B  [# y, z" L% O0 y! H5 M  \
Envelope utility use to protect DOS applications:2 w- m6 M( Z9 v: I& c9 K! j

; w. X8 Y: [; i3 U- e& |. E% w7 b( ?- F1 d, D  c! t: W
4C19:0095   MOV    AX,0911  ; execute command.& b& b; ~, |! @3 J& K5 e# u  [. D
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
( j/ i4 i1 @' c' v  m% Y* f! I; K4C19:009A   MOV    SI,4647  ; 1st magic value.
% d* P- O) s" d+ B& S( `# {6 q& |4C19:009D   MOV    DI,4A4D  ; 2nd magic value.4 D, E! k3 C/ X. F0 K+ C4 d
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
! N  ~- K4 B4 k( H& ]4 D9 R9 J2 x! g4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute0 q8 \0 P, S: `. `" ~5 W
4C19:00A4   INC    CX0 \8 s  @" ^, \3 e, C- {
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
/ i% Q. F  R) M( G4C19:00A8   JB     0095     ; 6 different commands.
- G  A- \5 _6 g4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
; H! ^  Y  g! X$ }2 c5 ]) A) Q4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)# f  p1 o8 n" t; G  g/ J9 {  M
( W6 g* f8 r0 d4 T0 H' M
The program will execute 6 different SIce commands located at ds:dx, which
+ {  u9 B4 z* f7 x) B7 pare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
1 D3 K+ E+ N( _7 B, ~/ @7 u. l) h  e
$ l' r/ J5 y6 Q0 }; f8 w* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.( E- r' z; c4 j' I! K! h! N
___________________________________________________________________________
; R) A/ ~9 Y0 s2 L, z
$ W% G: v- P# C* O* u; G7 i' D
Method 034 H: C' h! X5 }
=========7 E# \4 f2 C* K2 h" M# D' H6 x6 L

6 V2 @* \- M: {1 }) f* o6 V: M: ?Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
5 a/ M8 o  r7 I(API Get entry point)
1 B6 ]$ q% d- R        
2 Z# y" i* b. y, T( |6 p7 `6 Q0 o
    xor     di,di5 |* D3 v" q- \" _" I4 i
    mov     es,di( f( Y- F+ Y8 X/ {/ d3 d9 n
    mov     ax, 1684h       - Y( S/ J' b( r; P
    mov     bx, 0202h       ; VxD ID of winice+ e' U( M! ^( [9 }7 h% F
    int     2Fh
- n) i4 I/ p1 J. v    mov     ax, es          ; ES:DI -&gt; VxD API entry point
! a5 l/ j; J1 U- y3 ]$ t    add     ax, di2 S; t) ]( F0 w5 M: R9 f' V
    test    ax,ax
. a$ y. y$ Y# f0 Q  J    jnz     SoftICE_Detected2 @3 k% A; d+ [, q+ o8 l+ _
; c- G& ]7 t+ l
___________________________________________________________________________
  f0 G- F% A% l" I# Y9 F; u' Y. ]
9 u* Q( i) }' O. b( m+ P% c3 XMethod 04
- ^6 H. ]# T2 h) O! A* m=========& Z% S; s9 V" L1 N, D: a1 E

3 V  a; l. b: W6 P! Y# L. dMethod identical to the preceding one except that it seeks the ID of SoftICE
+ Y/ }. B) B% @" J, WGFX VxD.; H* i) a9 A. N2 N6 E1 e

4 R6 C2 C  d* V    xor     di,di$ d( T* O$ q) L  [5 i- h. E+ `; ]  t& T
    mov     es,di
8 s6 y, f! b# Z/ w5 G/ B    mov     ax, 1684h      
( o- \4 }; g" [    mov     bx, 7a5Fh       ; VxD ID of SIWVID
& p( c0 x4 z4 R) x# e- H2 W- b! ]' E    int     2fh
& F+ M, T; R) P4 |( g2 S    mov     ax, es          ; ES:DI -&gt; VxD API entry point
0 g+ g# k( G/ m# x) v    add     ax, di
: L/ S( U  j4 g1 _. k/ D    test    ax,ax" R. T9 [3 w4 D7 K" h
    jnz     SoftICE_Detected
( P) N9 w& I* q6 J/ w1 f& ~5 B
( ]8 x! H: H! y% M* Q- y- J1 |  M__________________________________________________________________________
6 s6 b! C6 [: }$ w# C
  x+ |9 t" _+ l) U8 {/ `' }& B7 C- A" v% D5 i, o* I6 a
Method 05
$ a2 p8 M% R& E0 u( Z; g* K=========7 i3 `0 ^1 [7 q! S" }
# t/ g. k: p. z( O- j" ^
Method seeking the 'magic number' 0F386h returned (in ax) by all system
; a" I! l, l- d9 h' g+ ]2 P9 _+ mdebugger. It calls the int 41h, function 4Fh.8 b1 O8 N" e# B& t3 Z
There are several alternatives.  9 y2 k1 H+ w* r8 H1 j5 v8 l
! y& P6 d+ Y2 A# H  N3 o
The following one is the simplest:3 g# J# l$ R% W: K
9 k7 V7 l/ P9 D! e
    mov     ax,4fh5 d- p: N' i/ I: y! A* b* V
    int     41h$ F, T. u1 ?2 M! _4 i7 O
    cmp     ax, 0F3868 b- @2 f9 n4 Z) E3 R' x( ~
    jz      SoftICE_detected
$ _6 G. Z% X4 q& K
2 D, }; c, w3 H/ h% g
2 d' g3 I' h1 }6 E" w; U( c7 }- j. XNext method as well as the following one are 2 examples from Stone's 1 ]- r; f/ _: e$ v: ^/ Y8 ?
"stn-wid.zip" (www.cracking.net):: o2 v3 T5 o- w0 @7 o) e. U; ^4 r
( z8 `$ {; I* z0 d& F
    mov     bx, cs0 ]6 H2 Y# p5 r1 C& A( _! X6 a
    lea     dx, int41handler2
6 ~! ?( b4 l+ g$ ^: a1 l9 q4 l    xchg    dx, es:[41h*4]
( S+ M$ X) Z9 ?% ?8 v/ x6 M# o    xchg    bx, es:[41h*4+2]5 R3 N4 }0 m& n9 h
    mov     ax,4fh
) u2 ], F2 o6 D' G# h    int     41h
( D8 Y- z/ o7 t; N: }* @    xchg    dx, es:[41h*4]
: o* S; t6 z- Y2 J1 v# ]& a1 Y) s    xchg    bx, es:[41h*4+2]& s, o( E" z  P' t
    cmp     ax, 0f386h
5 O- Y  F* K( A+ s    jz      SoftICE_detected5 _. Y4 l8 F# t; ^, E4 _

7 F; ]+ C1 n0 A& U2 zint41handler2 PROC
# v3 O" C) H7 p    iret* ~/ F! ?$ E( a1 S
int41handler2 ENDP0 N# [6 I- M# d/ S, P& [3 ^/ ^

* s8 j  z$ v. [: R$ s9 e( x! F  z2 m9 S; f) L/ N
_________________________________________________________________________
# n  j3 M" u2 D6 U8 K4 U: S& p7 }( N) D) X' a. c9 e2 V) U/ X
# [6 q5 B& U! S1 r6 W  o
Method 067 r/ l# ^3 E* V# q1 J, \
=========3 D8 z0 f- W: l5 _

4 v8 U4 [! H+ A& r9 y/ T7 v6 }! _
2nd method similar to the preceding one but more difficult to detect:
  `6 L/ D8 q) A) ?
2 M7 x7 X) ^" P2 [% w; D5 S! ~
- F6 C, |* Y. E7 d7 ^# f! x$ y  q  n' @int41handler PROC( F0 F, a: i6 C5 M  ^$ B. k
    mov     cl,al( z% S3 H/ r# W5 F- T4 ^. p9 G
    iret+ [" N% Y/ C5 W: _% c! e! {
int41handler ENDP& e% h4 y8 S* j0 v1 i

! i9 c; g# N" D# X" i# a$ J+ a! O, i/ O. w
    xor     ax,ax& }. \/ S, {3 Z- n
    mov     es,ax: A0 R; I7 ^' f' {' f0 N
    mov     bx, cs4 O! t' E' r" s: S
    lea     dx, int41handler) z' O6 w2 X$ ?  u
    xchg    dx, es:[41h*4]
- o+ y! m, o! Q; C: W    xchg    bx, es:[41h*4+2]9 ?" C6 F& L' z
    in      al, 40h1 f, i' J6 l! c/ C& e: U
    xor     cx,cx
$ r) z" O- f7 R5 ~6 s    int     41h
+ \0 ?3 n: P' F( p+ }5 G  `/ X2 ]    xchg    dx, es:[41h*4]
* \) S- R: {; d- S5 Q8 k    xchg    bx, es:[41h*4+2]
3 \. F* f3 A" B9 t& i    cmp     cl,al$ X' q) V5 }: R  D" Y6 V1 L9 n! u
    jnz     SoftICE_detected. k: T. s3 r6 L% C( `7 l6 @
/ z( _, d6 Y7 Z% U
_________________________________________________________________________
4 a4 q9 _% K6 f! K1 S4 {
% g3 ^3 v0 |- e/ R0 YMethod 07, Q: U) M# `: ~# x0 ?
=========
: f! N! Q4 n; O' y. s
$ o; ]+ H9 Q1 }/ `% sMethod of detection of the WinICE handler in the int68h (V86)
1 q  d7 h% }( i0 [" Q, A- V+ m/ R
    mov     ah,43h
+ Z* P) l# s$ n6 O    int     68h( p# D. Z( v% ^9 F3 L. F. m
    cmp     ax,0F386h9 [  W9 t. r3 g. m. M/ y
    jz      SoftICE_Detected! k8 h7 V  N1 R) m, w

  f! |1 P. o' f# L. H5 u+ O8 G. v5 \6 b5 i. f& X% m. h: n7 O
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit3 C7 \6 K, }. L6 j1 g: t1 d
   app like this:
6 s: R/ a0 c: S3 U' O8 n' o3 q( `" o6 w- X/ _( X) }9 B" ^' t
   BPX exec_int if ax==68
7 Z7 }: N! `( I$ j5 W4 r   (function called is located at byte ptr [ebp+1Dh] and client eip is
- e+ r6 K1 a- b2 o4 _+ ?6 X: v" w   located at [ebp+48h] for 32Bit apps)
( P. x* \2 T0 _6 S" |2 A& v__________________________________________________________________________- b) r: ?6 Q3 P( M4 S+ d

' G8 R% x9 M2 u9 J, D
# E, |8 b4 O) s4 }$ bMethod 08$ b% o0 O4 q" n
=========
: m- Q0 A% R" ~& K: @8 g0 R- A1 y, D8 m6 O! |
It is not a method of detection of SoftICE but a possibility to crash the
# n. j2 ]' E5 j' R* J. rsystem by intercepting int 01h and int 03h and redirecting them to another
5 a7 {; ?! X. B/ ^8 X) p6 troutine.
5 r% `& t+ D7 }9 w6 w+ u' dIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points* m( @( {0 |8 P( Z) v
to the new routine to execute (hangs computer...)
1 J/ W+ e* F& X1 z
3 e% S' D% N. k' u0 a    mov     ah, 25h
' O' V+ D' V' R1 \    mov     al, Int_Number (01h or 03h)* F  P0 t2 y; q
    mov     dx, offset New_Int_Routine2 N; E+ T1 i, y  X: G+ v; R) {/ v
    int     21h; B1 ^5 i; ~5 g: h$ Y- E

0 x0 J* m$ D. g; a__________________________________________________________________________
  k4 m4 f: K9 f, c, t* p  t
& k# E! h1 K: RMethod 09' `$ L/ ^) Z# i( V6 E! D
=========
# d) u. E+ y$ m: `& K; X: J8 c& N# n, N
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only4 W6 K, t$ V( t/ Z2 V
performed in ring0 (VxD or a ring3 app using the VxdCall).+ F5 y1 k! t# C9 P
The Get_DDB service is used to determine whether or not a VxD is installed
8 }; C8 Z- |$ {4 @for the specified device and returns a Device Description Block (in ecx) for
) H) x; c% |4 O7 ]5 Cthat device if it is installed.$ X  a( x+ t' N3 L8 B/ m3 C: z

8 S% z, i* F+ \6 P9 `; m0 E$ D7 _   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID& {/ [0 C* B! F" b9 @
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)/ F6 u$ B) x2 f2 F
   VMMCall Get_DDB  L$ B. N6 t2 \' }+ A" D8 j
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
: n/ P" u: [9 {' A. g) P3 F! g8 n. ?; J5 k
Note as well that you can easily detect this method with SoftICE:
$ U# M2 [# a! a8 C( v" [/ N   bpx Get_DDB if ax==0202 || ax==7a5fh
+ m8 ~* ^+ n' \# m! h, a
' e3 @) p& \8 V/ k) z! ]__________________________________________________________________________
5 C, r( q* w0 H0 ~, ^4 |( h% b7 o$ Q: F6 q$ B# T+ O% C
Method 10
, A5 y7 d1 L2 ^1 `+ g2 k=========
+ P( L, O* o# _% X4 h2 V) e
: V/ @5 U6 E* X1 \3 x& r=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with3 z# h' Z$ ^; j5 H3 v
  SoftICE while the option is enable!!
( x9 e) h% x: D' i" `2 Z* k5 Q2 X, {+ g
2 @5 z$ M; f9 Z) Z- ^This trick is very efficient:" X+ H2 N4 y1 P  G
by checking the Debug Registers, you can detect if SoftICE is loaded
8 ]$ X! Q% n6 N3 ~# B(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
1 K/ m' P  d; Q+ ]" P( t, x! nthere are some memory breakpoints set (dr0 to dr3) simply by reading their
3 Y) {" t" G# p8 Q9 Ivalue (in ring0 only). Values can be manipulated and or changed as well
- o! [" r9 A* c, M" h* \# N3 Z(clearing BPMs for instance)
9 }* Q( \) j; q2 z8 r# S' A+ U  f5 I: O" |
__________________________________________________________________________0 i7 _# [: k3 H% `. f, \0 w

3 Q4 G8 _, l  jMethod 112 s9 V9 _5 M' i& M& r0 G
=========
+ \  j9 v/ ]1 X& |& ~5 X9 l
: A1 V0 M, T  ~- O1 m* uThis method is most known as 'MeltICE' because it has been freely distributed; x8 Q, R1 s3 [8 T: Y
via www.winfiles.com. However it was first used by NuMega people to allow
/ w/ s. }) ]' I4 ]- p' h7 ISymbol Loader to check if SoftICE was active or not (the code is located1 ]  v! x0 G3 E- C! B7 A5 k, S
inside nmtrans.dll).9 r7 o" |( r1 X& ]; ]. Q: @; z& V

; L/ R/ N  Y. F2 z: e1 G+ ], j( xThe way it works is very simple:9 ^1 |6 N! C# O2 P9 {8 b: {
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
( p. B( k3 l& W  N$ |0 SWinNT) with the CreateFileA API.
3 R5 ]' k- ?% C! }& @
4 t7 h) V, }1 c# x. ^5 f5 b9 OHere is a sample (checking for 'SICE'):
/ ^( k% T0 J% m+ \. B4 `* k& G6 {' V% c. ?! O( V
BOOL IsSoftIce95Loaded()
* h! D$ ^$ e! D- S+ Z' n  _  t{
- u. u- ~9 ?  ~4 ^5 L6 _3 Y7 f   HANDLE hFile;  % b$ w# O' I# N' ]9 S! T% K3 y
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
3 A/ E% \: H& U. u                      FILE_SHARE_READ | FILE_SHARE_WRITE,
% o9 e2 C+ W$ D+ p                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);) B4 r# j; T  @' R) y
   if( hFile != INVALID_HANDLE_VALUE )# e% Y$ ~, Z4 R# ?( i
   {+ }, w! N8 H( S2 D$ G) ^
      CloseHandle(hFile);
4 F7 U, Y$ T" ^$ B1 R      return TRUE;
! h& D5 _& T0 r% [; P/ j1 v   }
; C+ m# _8 i( P   return FALSE;# W2 [% m" D5 D
}
* e, C, w2 T9 Y3 T. R% @
5 f% o- J  J0 |: `/ B& l1 M& UAlthough this trick calls the CreateFileA function, don't even expect to be
& B" D5 U3 v, _able to intercept it by installing a IFS hook: it will not work, no way!
$ Y- B+ T! p( J- AIn fact, after the call to CreateFileA it will get through VWIN32 0x001F0 R* l' I2 v; Z' S  Z  r& m0 n0 q
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
6 j( t4 V5 C7 eand then browse the DDB list until it find the VxD and its DDB_Control_Proc
6 U% z+ G3 x6 L+ ]) z! Pfield.# G0 |7 R0 |7 L) y9 U2 _8 Y* E
In fact, its purpose is not to load/unload VxDs but only to send a 9 e8 a& V0 u- K7 E4 x9 p
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)4 Q2 ~0 d* s! I/ B5 `
to the VxD Control_Dispatch proc (how the hell a shareware soft could try
" @! p" s/ A- b6 N! k' p% \4 Gto load/unload a non-dynamically loadable driver such as SoftICE ;-).
3 T" g; @5 p& _* \/ ~  xIf the VxD is loaded, it will always clear eax and the Carry flag to allow: E0 L$ @" J8 e
its handle to be opened and then, will be detected.4 A+ ]1 k6 B/ O/ K/ `2 u* ~# E. A7 U
You can check that simply by hooking Winice.exe control proc entry point
7 \" B9 R3 a% Kwhile running MeltICE.1 \! f, q$ R& j) T. j$ J
5 ~2 Z- O0 X& p- D1 n4 x
5 O/ @' p/ D; l0 d% @7 z
  00401067:  push      00402025    ; \\.\SICE
! Q* }0 {) z9 v/ P  0040106C:  call      CreateFileA
: Z5 m6 y3 e  o5 X! v  00401071:  cmp       eax,-001
$ H. Q1 K, Q/ z8 x- L6 P8 x; ~; `  00401074:  je        00401091( b; b# l2 q; p9 ^5 k3 Q4 N' @; l

/ v6 Y, C( X6 }
! s1 Q: D5 j! a0 H& `There could be hundreds of BPX you could use to detect this trick./ Q+ o1 Y5 G0 N+ {/ T' _1 ^, z' Q! a
-The most classical one is:
) c6 n2 k! ^0 [  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
) L4 N! j$ j9 ^. S  o    *(esp-&gt;4+4)=='NTIC'
9 X1 \( P6 E' q6 A/ Q6 B
# u$ T9 u# Z9 U9 H. B9 F-The most exotic ones (could be very slooooow :-(
+ Q5 E/ D+ B% x$ v; k   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  / Q9 l0 T  b: |5 B% L" ?  u
     ;will break 3 times :-(
% N5 A& S2 G- g4 o
, R# c9 o9 I0 x2 t; W-or (a bit) faster: 2 o8 U! ]8 z* ?) k
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
: y( K+ {# Q7 f5 I+ _2 l& F8 a1 N+ d3 N
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
+ j8 i) C' U0 |/ d, g# n( k     ;will break 3 times :-(
  a3 f! b) o* c' k1 L9 d
# `' v5 T* u$ H1 {$ H) h: W; z-Much faster:
1 [, _% _# b6 P. \: \   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'7 ^5 t( L, j! z4 T

8 }! ~- W7 f. U7 uNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
' _$ K, |5 W! A% V7 pfunction to do the same job:4 p/ t. Y' x1 [  E4 c% M

6 T1 S$ m2 [" P) r2 u; f   push    00                        ; OF_READ
8 A& O% W5 Y7 ]: \- ?9 W   mov     eax,[00656634]            ; '\\.\SICE',0
3 H  H  j) s! p, A   push    eax5 s: {1 A& K% s- C4 W* u
   call    KERNEL32!_lopen
: c2 Q% a$ a! Q1 I7 Y   inc     eax
! W4 ^( t* v8 b" r. V   jnz     00650589                  ; detected
4 b, d, c8 u' r, R6 I: }* F   push    00                        ; OF_READ  ^: F8 `  |! z& t) N/ |' D7 ?
   mov     eax,[00656638]            ; '\\.\SICE'
' E6 b- ?2 h0 q" z' C7 z( V. T   push    eax% J5 Q7 P/ l! @: f# b
   call    KERNEL32!_lopen
1 J6 k& e- f" Q' `5 k5 y   inc     eax
) Y* z6 g( o* K$ u' ]   jz      006505ae                  ; not detected' P; r# ]' H1 S* u2 c
$ c8 k# ?5 h8 y1 b* _8 I6 l
  @8 v2 r( g' `: J+ _3 W
__________________________________________________________________________8 |7 C: c' E/ P7 A2 n
7 D, t5 q8 M( Y6 c0 R
Method 12$ R( [* l- `* w' j  d0 y3 w
=========8 i9 \& |! Q. O& p2 O

7 I6 Z& K  f* O! [1 t: RThis trick is similar to int41h/4fh Debugger installation check (code 051 S% a7 M0 Y- N0 o4 ^9 o
&amp; 06) but very limited because it's only available for Win95/98 (not NT)! j% j/ L, [+ F
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
& H) Q8 m* Z9 R+ w- W0 ]  z$ v0 @" j8 [9 P1 A; P* o
   push  0000004fh         ; function 4fh
/ H& k/ w- Z; S* c- Z1 Q   push  002a002ah         ; high word specifies which VxD (VWIN32)
7 O! V% d1 ~! M- t6 ]7 e! b                           ; low word specifies which service% t( B5 l' k  _4 K& U
                             (VWIN32_Int41Dispatch)
& C" m. `( j, w! r8 o   call  Kernel32!ORD_001  ; VxdCall! q/ J# b" h8 [% W8 y
   cmp   ax, 0f386h        ; magic number returned by system debuggers! b4 V3 y4 X# V& V
   jz    SoftICE_detected
# U. x/ j- O9 I( P3 b
6 b+ |$ h1 {1 G; zHere again, several ways to detect it:
1 L# ~6 J6 x" P9 f% i) u& |' |, Z# A- f& n: V  x" u
    BPINT 41 if ax==4f* N8 }" U" K% V" F

: m" ~. n( ]( K* A    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one2 V% j( m" \5 O! N
* f- f0 @8 [/ W4 o4 n2 r5 b
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
$ V% z$ w6 k) b1 ~  @" ?
2 j" m+ p( v1 S+ h8 E  c    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
8 H  J8 w& l7 h# `% q6 i
5 ~8 U' d  K) T- l0 j% @__________________________________________________________________________; j+ F/ n( E% X$ L

  y0 W) w3 {4 A9 T3 `( N6 QMethod 13
2 ?& m/ G. o6 m( I: F/ I8 b5 g=========
' p& \, P+ L% L) m2 O# e4 G/ P: E5 _6 f
Not a real method of detection, but a good way to know if SoftICE is
. a' Q* `9 D# Jinstalled on a computer and to locate its installation directory.
3 [/ P& C& L" Z; u6 MIt is used by few softs which access the following registry keys (usually #2) :0 g# K0 T( V  Y' V0 }2 W

5 ~* s$ g1 m: j( p% B0 b-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion% |% L5 r/ _1 v
\Uninstall\SoftICE
- i& I2 C' p9 L% R- M: d  G-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE8 m! I' w5 y/ J7 Z' l$ L, t( F* C  C
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion5 _# w4 L1 }$ T: O# l
\App Paths\Loader32.Exe
5 S' V1 u! m& `* E8 v% [7 Y% u; x" {. c& X0 s
5 n( D, {2 q: x" T) @. g1 `* W
Note that some nasty apps could then erase all files from SoftICE directory! t4 |, r) s$ Z- d
(I faced that once :-(3 Z/ H( S% v' W" }( N5 F+ z

( ?  H# S$ I; [" J. |/ R7 S! @2 [Useful breakpoint to detect it:
6 i9 L% d, ~' v8 \0 j5 o7 a/ H1 R: W$ N5 X9 m' x" S- V
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
8 T' w5 q1 X0 k2 ~% z* ]6 L# B1 B/ C  n; e- J: [1 Y& E4 Y4 j- e
__________________________________________________________________________5 o- D; L& \' }+ u3 ?; ?
& a7 J! c! J  d# T. @, F

0 k" |( |! K, RMethod 14 / w' d* J- u" ^# s) N
=========+ d$ u& c, e0 v0 ]4 M3 O+ z

3 I- F6 U, C1 QA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose- Q7 K# R. r6 s1 ^0 }
is to determines whether a debugger is running on your system (ring0 only).
3 e8 j6 M( r9 Q7 ^" }
! V- Y$ P& B0 R. U# Q" m   VMMCall Test_Debug_Installed
- z1 ^( V2 [' G$ U( {   je      not_installed/ i* u- ?; u6 @4 ?( ~. I  R& w. Q

) ?1 K+ V5 F7 [This service just checks a flag.
. ^8 C- l0 n* k  b+ w+ C2 n9 f</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部