About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500># h6 z+ U$ o$ E+ M0 f1 K' N
<TBODY>$ V6 W$ N# e8 |& m
<TR>
! b+ p/ v0 O3 f! T9 N<TD><PRE>Method 01 1 H: G- O+ [- {, f7 F8 P0 T" j
=========8 @) l: a9 \2 B3 H4 v- r  N( S

+ \1 z8 i3 x& h0 w# @, @This method of detection of SoftICE (as well as the following one) is
+ a8 O* Q; Q: H# m4 i9 U5 Zused by the majority of packers/encryptors found on Internet.
5 r2 m+ a, z4 |- q) {It seeks the signature of BoundsChecker in SoftICE1 b: Q- f& _" }# D+ Z6 R9 c% w  m

2 K3 L& A6 W1 n: A) D! d    mov     ebp, 04243484Bh        ; 'BCHK') ?9 ], l; X: I2 q$ J
    mov     ax, 04h7 K$ `+ j* g- g0 S. E$ C
    int     3      
5 c) s1 V& l+ w) e, ^9 o, p( d    cmp     al,4
6 U1 \0 Y6 {. G6 {. i5 d  \    jnz     SoftICE_Detected0 o/ `% ~* C5 |  s2 O+ D
, I9 T# m. d3 ^8 }( q6 Y
___________________________________________________________________________
' Q* u7 ?! P" i: `, ^# ~6 `' i4 G/ G0 q# _, W9 t+ L
Method 02
$ x' {9 u, C8 k  t# g$ F=========6 H2 s. F' h- a

" x5 v2 \3 L" hStill a method very much used (perhaps the most frequent one).  It is used% H+ J7 S/ r- E# O% ~. f; H
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
( A4 e8 ~& u6 b( f9 cor execute SoftICE commands...' u1 W" Q2 j! _0 A! I
It is also used to crash SoftICE and to force it to execute any commands- \) G( C& n8 t; X( c5 h
(HBOOT...) :-((  1 a0 P/ e, [7 b2 A" I$ E- Z  V/ J

( H7 l8 G, Z  m9 q" R& x- P% ]Here is a quick description:
8 Y- Q5 I5 A8 p5 f6 K-AX = 0910h   (Display string in SIce windows)
; F# @2 R6 i7 g+ D+ o8 u3 S-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
7 d( z- V( E* |* m+ a( T$ o-AX = 0912h   (Get breakpoint infos)
1 X6 S6 v+ m9 j* u) m-AX = 0913h   (Set Sice breakpoints)
/ I2 |* N3 |. F9 J- _( x5 c-AX = 0914h   (Remove SIce breakoints)
9 B9 I% U3 x9 F! T$ Y
* z" l' L* p1 C7 o7 F, jEach time you'll meet this trick, you'll see:) W3 i( i9 y* ~* h
-SI = 4647h, n5 D# }- e( t( I
-DI = 4A4Dh$ O# i0 A! q7 M
Which are the 'magic values' used by SoftIce., l$ R" d6 D* }3 r" j
For more informations, see "Ralf Brown Interrupt list" chapter int 03h./ X8 ^  o; T9 W, E4 E

4 p; c& i& `# ]: v' O: ?( [Here is one example from the file "Haspinst.exe" which is the dongle HASP$ ]% N0 o* Q+ k! X6 R) u
Envelope utility use to protect DOS applications:9 X- e  K# |; P$ }  Y4 o
) Y, G& J# b3 P3 [, w
6 S7 L0 @$ n! y4 U- m2 D
4C19:0095   MOV    AX,0911  ; execute command.  U; n/ k) ]8 N
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).. Y3 R9 M- z. o- i* P" ^
4C19:009A   MOV    SI,4647  ; 1st magic value.
: ?- x+ D1 c1 _( L4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
; \9 O* n0 Y1 D& r4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
# i2 G( r; ]) V* z: _  R5 {4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute8 o) r" n# p( c" I7 W7 J* `
4C19:00A4   INC    CX! N( `; m, n) R2 G5 ~
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
+ H6 N, z) t2 J4 u! C+ O$ {8 e4C19:00A8   JB     0095     ; 6 different commands.
4 B6 {/ _4 y# m0 B4C19:00AA   JMP    0002     ; Bad_Guy jmp back.1 r' s& M% R' ~0 E
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)& P8 L# K& F2 U! P' a% i

" j6 y' E8 S& L5 Q$ a- pThe program will execute 6 different SIce commands located at ds:dx, which
" k) ?) c( t& O0 Care: LDT, IDT, GDT, TSS, RS, and ...HBOOT.7 w% {/ `! G! s" e5 c

% D+ p/ }. |+ b( h" Z0 H7 U* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
) }1 ?) p6 Q; l$ x& R' K1 }% ]/ b/ Z5 g___________________________________________________________________________
, C3 X) M# N5 L8 G( x
% e+ g3 n" |- t: L( C  w! M
- T  b9 ?* C% }Method 03
$ V+ k8 t" [8 o$ t. V; A+ S! r0 ?=========
% V% ^; a- C  S. Z+ a0 @
$ B: i! W4 w) ~8 w; s- |Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h+ _; M! m) {7 l8 h
(API Get entry point)
; v8 N/ a& [+ `4 D! }: l        , O/ d6 n! V4 N) k7 z9 w! {

0 _" b3 v$ ~) Z3 u0 j% |- l" \, _    xor     di,di
6 ]4 h9 P% x* A8 L    mov     es,di) g* }, k1 Y  d0 u( B1 h! L7 r3 _
    mov     ax, 1684h       4 Q7 R; Q0 B. p# A0 \7 A" {
    mov     bx, 0202h       ; VxD ID of winice! m' o$ e/ H6 i0 A% {. D
    int     2Fh
+ W1 `6 ]/ Z$ D! w5 L    mov     ax, es          ; ES:DI -&gt; VxD API entry point
6 l5 d0 `! a5 K7 L1 C8 o  _    add     ax, di
9 Z* I+ X" x  f, r3 A    test    ax,ax9 s3 K8 H/ N, u' D& |8 G6 g
    jnz     SoftICE_Detected
5 J# ], ^! {# K. F2 l2 d: a& ^
& N4 L  p0 v( C1 ~  i4 i0 B___________________________________________________________________________
7 |: b  O- x7 Q& d9 k+ J$ u
) B$ \7 h9 e/ Z2 ]( F' bMethod 045 p# o: b( E. S" W" m' s6 V* C7 J
=========8 u; d* L! C  ^. i5 _  h! j( j
+ t$ c; ^4 V) t; L" z, z& R
Method identical to the preceding one except that it seeks the ID of SoftICE
$ V; _, h* S, t5 c6 J4 PGFX VxD.! m( G  m: v; f0 ^) _

/ ~+ f1 W& M' k    xor     di,di
' w+ m$ k3 F+ h1 T4 I    mov     es,di6 V* x$ n; o3 f
    mov     ax, 1684h      
% |, o# b( V$ U. t    mov     bx, 7a5Fh       ; VxD ID of SIWVID6 {' T4 D6 L$ k, h; ?9 W
    int     2fh* R8 P( s% T# ~( {/ c3 ]
    mov     ax, es          ; ES:DI -&gt; VxD API entry point/ i3 A8 L! t8 |( w
    add     ax, di# c9 t: y6 Q; {' s; e# {$ U
    test    ax,ax5 {: q; _, v% `- ?; B6 U$ v
    jnz     SoftICE_Detected3 P' ^3 k! A9 U5 f& n3 _+ ~

5 D- D6 q$ d7 v: c# ~' b! c6 @__________________________________________________________________________
4 C* }! ?& i& \% F( t% Q) n% r
/ W8 x( G$ s; D# T, _" D. Q; u7 ]- ]& G
Method 05
1 J" |5 Z9 Z1 |) a# B8 l0 C, V+ R=========
. d- _9 l8 G) d( \1 _: O, ]3 @% O
% J5 X. h' f% c2 k- g  RMethod seeking the 'magic number' 0F386h returned (in ax) by all system
' s/ \: K6 J6 c* q7 |' j+ `debugger. It calls the int 41h, function 4Fh.
" ?# `9 G- J  l1 t( ^There are several alternatives.  
7 S+ i% \8 m6 v+ k$ N# @5 Z- h1 R
The following one is the simplest:  I  d- e' W* S. I( i9 `

2 B" G  {5 ]2 g5 W% i    mov     ax,4fh& O$ {2 I. f! i
    int     41h
4 B5 K9 j1 L9 p# O* O8 Q% ?    cmp     ax, 0F386
0 \- M1 [/ ^5 l2 N7 v    jz      SoftICE_detected
7 q4 \/ l6 G& ~2 e) o. V3 u; A# E4 ?, s9 a, |6 n* q0 _
& u& l; l* X2 t# Y0 e8 V
Next method as well as the following one are 2 examples from Stone's
1 ~9 ]# u7 L! S8 H& J"stn-wid.zip" (www.cracking.net):
' B" n* A  k8 r1 @
+ Q( e. C3 U: }  E% s% K, ?    mov     bx, cs
9 C- i5 [7 n$ L4 a8 K    lea     dx, int41handler2
6 ?% i& \7 U0 J: c$ v4 q# S$ _    xchg    dx, es:[41h*4]! _+ Q- G* N7 N6 r9 ^
    xchg    bx, es:[41h*4+2]- m8 b" N, T9 B" ^" Z
    mov     ax,4fh) @  c, S; v" W  Q
    int     41h3 D$ t  X- N) k/ b6 x! j
    xchg    dx, es:[41h*4]8 A/ n) C+ A2 k2 T7 F2 n, Y+ H
    xchg    bx, es:[41h*4+2]
' G4 c* A' G0 Y! ]( E. V    cmp     ax, 0f386h1 o# p, q8 ]* j" ?! i- z
    jz      SoftICE_detected! L( Q& ^" n, Q2 B3 q

; o( r& k  b" c; e9 z7 |int41handler2 PROC
1 c7 Q' N. ]; ~- J! y    iret
$ S; ?7 u' V! ~+ U" xint41handler2 ENDP
& ?/ M6 {! q3 P: N$ t7 r+ h: o8 d' j4 p

8 e# w8 p, H$ G! G_________________________________________________________________________
/ {) s7 c. @$ R7 l& W. w2 \
$ S2 V; n( Y: n6 X  W; w# w7 V+ ]* B5 ]" T1 }6 X  V
Method 06
# Y1 c( F! S% O3 l  m! h=========
5 f: L# c8 W$ U7 h
1 q3 x* S/ ^. c- z1 v* O
" R; M! A: J: x! ^; |( I! Y) g2nd method similar to the preceding one but more difficult to detect:
$ q5 D+ z8 J( U* z  n) f) J/ `% j2 D0 `1 `# ?  D
5 E) q& @' w% ~" g  r9 E
int41handler PROC
$ t" V0 }' Y) e$ G# x, I    mov     cl,al
& v" y4 L/ {  U* X( m3 Z    iret
9 C  R% l1 _( U( ~) v4 y, {7 M- xint41handler ENDP+ {) |$ @! O6 @! E0 M: f; I% c9 q5 P

+ H, I# X5 i; c( H" j. ?1 |7 t5 t4 d$ |- _8 _$ u
    xor     ax,ax
. V# q' p$ T/ T6 o* Q) q    mov     es,ax; \8 H: u* r' r# V  j! u4 B
    mov     bx, cs# R- K' B# P: z7 l5 ^9 v2 c0 B! {6 y
    lea     dx, int41handler, R/ t' Q8 k# w: s  s3 Y
    xchg    dx, es:[41h*4]
' ?$ a& S: u5 L6 R- `4 a$ J    xchg    bx, es:[41h*4+2]
( Q* D! [, \5 n# E: n" W$ f9 A5 Y    in      al, 40h$ ^8 {7 a4 l9 E! u. m4 ]
    xor     cx,cx' E! L) ]7 J3 B  D4 f/ M
    int     41h
0 j5 \$ {, e5 x, ]7 q    xchg    dx, es:[41h*4]( e- P. N8 B7 D' W9 i
    xchg    bx, es:[41h*4+2]
% p1 E! T3 }+ a- A  p* @8 B# C    cmp     cl,al
  d8 R# `! g( v: @' m    jnz     SoftICE_detected9 G$ U3 }! ~" S- }' D8 d
" x8 V! |7 S  q- X! ]5 {
_________________________________________________________________________
4 m' U  f# ?' ?, {' w
; A( h$ ?5 d; A/ QMethod 07
% n& T5 @+ S$ `- O* N$ f& z=========
2 D8 |1 _/ E. W4 g9 E5 V- H/ R/ }4 K5 t7 ?
Method of detection of the WinICE handler in the int68h (V86)
) n, e5 I3 C" S8 q5 P3 c0 f1 O4 [7 O9 D' v
    mov     ah,43h
0 @' i/ g2 I" O3 S/ w    int     68h" C/ h3 A3 r2 `) u8 Z
    cmp     ax,0F386h
8 R: V* ^) r, J* ]; a% M3 h    jz      SoftICE_Detected
3 e+ i; `# h, Q1 u" M; W7 ]4 ^8 l! \; e- |" h
9 d$ j7 \  ^; B
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit/ ]; ~* {2 B; {  f
   app like this:
4 F% Z0 d/ g- y3 \5 |( X
2 o6 f6 ?' }, c/ I: d/ t/ W& O   BPX exec_int if ax==683 m7 P% ?7 y. W8 O' t6 q
   (function called is located at byte ptr [ebp+1Dh] and client eip is1 @) U) K. b+ j" }- X( {
   located at [ebp+48h] for 32Bit apps)
8 u9 f! u4 _& o9 f8 i* _" P__________________________________________________________________________0 i# Z* W- h" `7 i
: G: W& A9 o8 O: v5 Q$ N
  A1 B8 t3 \$ [0 z
Method 08# _" k, k- m- B+ e4 C0 d' n
=========
5 N1 ]* \# e3 D, L' G& Y7 Y: a+ R3 @( G- g& j1 u4 B
It is not a method of detection of SoftICE but a possibility to crash the
, K! D2 P, z: Msystem by intercepting int 01h and int 03h and redirecting them to another
0 \+ t( }- Q  l. ~routine.4 k* F1 H% }# r6 m7 g
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
& \+ r' @( A% |( Eto the new routine to execute (hangs computer...)5 r+ |7 c, w6 e

" K) y/ w% ~5 j1 U. e    mov     ah, 25h
: F! k# _- l' O7 h- f    mov     al, Int_Number (01h or 03h)* f# u4 D% s3 T4 l3 n( b
    mov     dx, offset New_Int_Routine. \5 m. T) t9 S, |3 h3 o
    int     21h- a5 N1 M/ D( p

# A* k& {4 l4 }. |* C__________________________________________________________________________( l& ^0 @, a1 R" `0 _, ]

6 r. H" J# i' T7 }5 vMethod 09
3 @) Q" Q+ O# n, X- b=========
5 r$ X" L$ l7 w! Z$ Y! j2 d! v; F1 [  i6 Y
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
/ \0 _% ~8 [! Q$ mperformed in ring0 (VxD or a ring3 app using the VxdCall).
) [/ z" b7 C% g2 q2 P) K4 D$ WThe Get_DDB service is used to determine whether or not a VxD is installed
7 E( s. i5 @- @' f# ?4 @9 Lfor the specified device and returns a Device Description Block (in ecx) for
) W- K/ n: [" P' nthat device if it is installed.
' y* l0 D; F  \4 ^" L' D2 ^7 t+ t
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID0 `3 K1 I: N2 C9 X
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)  \& s) i6 h8 t  g# d, F
   VMMCall Get_DDB
7 |, N4 _8 ?5 M! x& y& n1 t3 K   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed2 y  w- \, h, G$ c
4 \* \& y0 }+ G: H) r" {# ?$ Q
Note as well that you can easily detect this method with SoftICE:3 x- t) X; t' a$ ^3 O; m& }1 I8 K, F
   bpx Get_DDB if ax==0202 || ax==7a5fh' N7 V4 v4 D" c' w

8 j% v7 A* k; o2 l: r__________________________________________________________________________
6 l7 B6 Y5 d' [: O- }9 ?( a- d
# y2 {: B9 f0 J9 n$ X( vMethod 10
) @, O! F; G$ J5 e; l1 i=========5 [; m, ^6 j) g" C

4 E; {/ ?, q+ C/ p! \9 k=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
# ]& ?+ r3 w8 s  SoftICE while the option is enable!!' x; K8 ^& H- o
! m% t$ S) [* z4 }, M- y2 D
This trick is very efficient:
  g, H% S8 i* ^( C5 @( C; ~& `by checking the Debug Registers, you can detect if SoftICE is loaded
" x5 `$ z- n5 B7 [7 g, ](dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if2 {2 Z. c6 ]: X  ^1 _  y
there are some memory breakpoints set (dr0 to dr3) simply by reading their
: O) B; i9 k5 V$ i; |: [8 Hvalue (in ring0 only). Values can be manipulated and or changed as well! c1 L5 t! A7 f! a% X- Q/ Z6 R$ h
(clearing BPMs for instance); n% `! i8 {) N7 r" ^

% g1 c7 L; f$ J8 r+ v( j__________________________________________________________________________
" U) G- |2 v& x+ K7 B
" ^' \; m& M8 Q6 m7 YMethod 11
( L8 n0 a* M3 r* V: P4 g( I1 j3 ]=========0 y+ q: z! ?, u- ]& Q4 U

, I4 x/ J  @6 v  U, fThis method is most known as 'MeltICE' because it has been freely distributed
6 x' E( R9 A6 H/ \( u2 n! I2 Gvia www.winfiles.com. However it was first used by NuMega people to allow
; `1 J+ n9 j5 P; J$ R% T/ KSymbol Loader to check if SoftICE was active or not (the code is located
- c% Z+ x  s8 i4 D5 Qinside nmtrans.dll).
2 T& `- m/ {0 }: s
/ {' x! E1 O& DThe way it works is very simple:, L) V2 F& `2 w* _* s
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for8 X: N* Q1 x- `4 |, ^8 ~7 @& B6 E: P* E
WinNT) with the CreateFileA API." N  c/ Q; d$ @5 T, K3 \

; O, Q: v! K8 sHere is a sample (checking for 'SICE'):
; n0 d; q2 @/ M: [: @+ t
: v; i9 x: M: T" A9 }BOOL IsSoftIce95Loaded()
: e: x0 m0 t1 t{8 y9 m" w* [) h8 |0 K8 S9 Z
   HANDLE hFile;  $ P9 Z8 L& H% c" W) i
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,4 I& E! j  C$ P. N' t1 P$ N4 X% B: B& F
                      FILE_SHARE_READ | FILE_SHARE_WRITE,/ u+ B* ], W1 j. f8 e2 |3 F  D* B6 W0 ]
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);: g( S; k  x  g) {; v
   if( hFile != INVALID_HANDLE_VALUE )7 p) ]& t  b; `* c5 w( ]# f
   {; q' y3 Q0 i. g: t
      CloseHandle(hFile);
6 j/ ]5 I1 r& ~4 w0 \      return TRUE;
+ |: I+ D6 H8 E   }
3 p" t7 Q( r0 E3 f0 ]. M   return FALSE;' F4 f6 K7 W. F
}
) M) N; \9 d8 ~( Z
& R( o# L6 W1 ~* vAlthough this trick calls the CreateFileA function, don't even expect to be0 p- ~3 d4 A5 L$ C; h9 f& a: X. x
able to intercept it by installing a IFS hook: it will not work, no way!
$ H/ O( `. ?+ S8 r2 `3 EIn fact, after the call to CreateFileA it will get through VWIN32 0x001F8 q% v+ f. W0 |# J2 v; X9 M" h0 \- \
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
$ n! ^2 d9 K; Z5 i: x/ Uand then browse the DDB list until it find the VxD and its DDB_Control_Proc3 k) u; ]. |* n
field.) X0 w# D! Q0 l/ ~! T$ b- L8 j# |
In fact, its purpose is not to load/unload VxDs but only to send a 7 E. [- ]: W) X' S5 {! N$ y/ o
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)) N9 D& {' A. D" v, T9 I
to the VxD Control_Dispatch proc (how the hell a shareware soft could try- w% N; Y3 T1 d0 q! @) @! R
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
$ L. F# O- M0 PIf the VxD is loaded, it will always clear eax and the Carry flag to allow
" U+ D% R) s2 Q; J) U" S: Lits handle to be opened and then, will be detected.3 a. E/ T! ?* a
You can check that simply by hooking Winice.exe control proc entry point
( n7 ^& f0 O1 E1 Dwhile running MeltICE.
3 U6 c) k: v5 W' Q1 q5 V2 f8 O: {" I* R+ S
9 m. _# \/ H' G6 P+ O, b
  00401067:  push      00402025    ; \\.\SICE
8 J" Q8 Q& P5 x: a7 V# b( l& N7 ]  0040106C:  call      CreateFileA4 |6 g/ E8 Q( N0 t) x/ y& R
  00401071:  cmp       eax,-0016 }* ^$ ?2 j; h, B  d
  00401074:  je        00401091
! o( i. l; W6 P- E+ f* p% a
3 T9 S8 N; q: `; x( c# |, G- @9 s7 T5 a- n4 n* h" g
There could be hundreds of BPX you could use to detect this trick.
6 v4 w+ m* c+ f3 J& ?8 v-The most classical one is:
! z- U6 J( \1 m7 x6 j& }  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
, x/ ^$ p" P% _! |: d$ B; @    *(esp-&gt;4+4)=='NTIC'
  b! Z7 F8 F3 }6 P, v  `' {( A, i
: n$ g& q+ A1 K0 S3 S/ K-The most exotic ones (could be very slooooow :-(
  @/ s% u# y% q' J   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
" K: R- m- z! `     ;will break 3 times :-(
" R1 R$ W- P5 E8 ~; |1 n, l! c
7 A! h/ I2 N$ I- Q-or (a bit) faster:
" r0 V4 |0 w  a9 M) Y   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
0 |) _' ~1 |$ H/ j* Q3 K- D+ @
' g. v% Y4 Y4 s' _) j/ H$ p7 }* H   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
2 @0 v/ S) Y, [) b& Z) l! i     ;will break 3 times :-(
8 h; i8 F, r- T8 j) F( p4 Q( B( p0 p3 d- H  {3 s1 w
-Much faster:
" w5 d$ L* h. e( U  n- [' r0 B   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'7 J3 D4 G  o+ ]
6 E+ z' Z! O$ y3 }5 Q
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen! K( i8 d" r$ R2 h4 o& ?0 _  a3 s4 D
function to do the same job:
& N$ R  w% }7 r6 M) V% c- t6 m2 r7 L. h7 B7 Z
   push    00                        ; OF_READ' d* V" |: @4 T0 D
   mov     eax,[00656634]            ; '\\.\SICE',0
+ R* b# I9 B5 k& z! }0 t   push    eax+ w6 k0 i3 T- L, L
   call    KERNEL32!_lopen
) Y6 W( y# [4 S3 D9 x) A9 w   inc     eax
, U# V; T# S' a' f* e$ l   jnz     00650589                  ; detected3 y( h# b' I) b* a, Q# g
   push    00                        ; OF_READ
& g; C' {3 G8 b# k   mov     eax,[00656638]            ; '\\.\SICE'( ?& f3 W  |& A4 }3 i
   push    eax* ]4 O  ~! n' B3 H, F
   call    KERNEL32!_lopen
( r# w( f6 k9 J" b   inc     eax
# a$ }7 F0 Y/ v0 V' X: R& u   jz      006505ae                  ; not detected  x& B8 S9 x  H' U* H" A' q
$ r6 s. I# z6 T! G0 U. z9 ^" g3 q. L
/ S4 K% z- ?6 ~) V' N. d
__________________________________________________________________________: G' ^% _, `5 v+ Q; Z
% T8 I' G4 i! l, t2 i
Method 12
4 D/ Y; j( V9 f1 {=========7 U0 s5 E# l0 Z

2 Y4 B" d0 ^, g" zThis trick is similar to int41h/4fh Debugger installation check (code 05
- J+ x, B& k1 f0 |7 m&amp; 06) but very limited because it's only available for Win95/98 (not NT)
. f# C& P/ p5 W# oas it uses the VxDCall backdoor. This detection was found in Bleem Demo.8 v1 W4 v, l, ?/ L

& u4 g! a; m' E, Y& E   push  0000004fh         ; function 4fh
% q9 J3 r( a: b   push  002a002ah         ; high word specifies which VxD (VWIN32)
% H$ u0 I% i. S- V/ q' d9 K                           ; low word specifies which service$ D! t8 n9 K# v8 h6 g. I; ]
                             (VWIN32_Int41Dispatch)
$ R* Y! T" `1 _- J   call  Kernel32!ORD_001  ; VxdCall" Z- g* |2 p- ^9 r, [
   cmp   ax, 0f386h        ; magic number returned by system debuggers
" s: l% j5 {6 B$ \5 m$ ~   jz    SoftICE_detected4 E0 s. ]+ R2 f9 q
* _5 t, j3 p: C5 L- T
Here again, several ways to detect it:
( v7 J0 b0 \7 J) O. B# o1 W6 m0 v5 ~" f
    BPINT 41 if ax==4f& k9 M% h! `# i& v# e, i
$ \8 m5 I9 N1 A8 ~, G
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
% F6 _3 D* f4 _' v. q  |# _9 z& A. h8 A9 x/ g$ K. w1 y
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
( a( B* m, o$ E9 Y: t3 F6 i1 V& Y! m3 f
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
- U. k0 }) v' w3 \7 R3 [5 Y8 f, S/ j8 Q0 g5 P1 b9 D
__________________________________________________________________________' i8 x  b3 w6 t$ |- ~

/ T& k: z: u, u+ L5 kMethod 136 i* R, {5 R$ T4 @9 \8 B4 d
=========
+ ]; y4 V7 P9 G- J* v" C( p3 U1 m7 i: S1 m2 R
Not a real method of detection, but a good way to know if SoftICE is" Z/ L9 H' Y9 m* O
installed on a computer and to locate its installation directory.
* b. _2 D# e5 o0 `0 p% V0 wIt is used by few softs which access the following registry keys (usually #2) :
7 K& o, l5 l8 q  D
+ K& h6 R/ H. z* ~-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
" S0 O6 g0 S7 S\Uninstall\SoftICE
+ R+ {; S) y; B6 l: F  J8 N-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
" c( [1 S- p# E/ t8 `1 p& ]-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion, z2 J, `: s  `, ^1 n2 I, W* W
\App Paths\Loader32.Exe$ L$ i* v: u* ]" r9 I2 H0 c
: j9 [, i0 v3 D8 e- Q9 F: z
/ ]6 O- V3 Q- c4 _
Note that some nasty apps could then erase all files from SoftICE directory
/ v- Q8 @/ N. D/ y3 H  A9 V(I faced that once :-(
( V# @/ V7 ~9 A* L8 x
/ p# b1 T! R9 `" I9 o( [Useful breakpoint to detect it:# A9 T  ~, K1 e/ a6 B& e

: Z. X. c$ O; n9 c& Q     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
9 t# K. N& \& f& L& c( T& \1 P/ c  A4 s, i8 ]
__________________________________________________________________________
; Y( v4 k  w2 \
! @! I0 V4 ?7 W: [4 m3 |; Y- o/ x0 @( z3 N- D! H  P) D' J. |
Method 14 # I1 ^: V8 e0 S, _/ {
=========3 G) W8 f* E8 c0 _, v3 S& Q! \# R; ~

+ j  c: L& \1 d) r( O  Q) a! tA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose2 C8 n' l$ _' f% R* C
is to determines whether a debugger is running on your system (ring0 only).
2 [) \5 V: m0 J4 c, }3 [  X; G4 K4 j
   VMMCall Test_Debug_Installed/ ~, i- E4 n; ~4 R1 V# a7 {
   je      not_installed+ Z7 k. Z+ c" q; c6 G" a0 t" |
1 R$ g) {) Y9 t7 n
This service just checks a flag.
, f* T3 A! K$ j</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部