About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
8 k/ \7 c' ?  x3 |  ?4 M" c, @# Y<TBODY>
# I* e  h5 [4 ^  ]<TR>4 z- J: Z- H% m4 [
<TD><PRE>Method 01 7 E+ }$ f% n3 D: D6 r; }" X0 L  H/ b
=========3 C& i7 K5 r! @/ c" \. i
; ~/ D/ d2 L% W' ?/ j/ u+ ]4 [
This method of detection of SoftICE (as well as the following one) is7 |# |0 P* a9 ~1 d3 t
used by the majority of packers/encryptors found on Internet.3 m5 I& M/ ^) @( `4 T9 ]) g
It seeks the signature of BoundsChecker in SoftICE# q) u1 T. l' P2 [

' t, \3 |7 |8 V" u& i    mov     ebp, 04243484Bh        ; 'BCHK'
6 n; v& u* D8 D+ g    mov     ax, 04h4 B+ P. {2 z8 o9 Q
    int     3       8 f" o5 F. g( [# A0 v0 m
    cmp     al,4' d2 w9 R0 y( X0 z* X, p
    jnz     SoftICE_Detected
1 A2 O$ n% e3 O# e! _5 j
# X, z6 N' L) u9 `___________________________________________________________________________
& m1 g. d2 \2 D6 C) ?, S0 f2 k' C6 E7 A) \4 ~7 T/ Z* ~. B# C
Method 02
2 o; u7 o$ F0 ~4 N$ R/ M  l/ O=========
& [& D8 q2 h! \2 f, F6 b5 ~; c" W7 t+ p9 {1 t
Still a method very much used (perhaps the most frequent one).  It is used
$ `& J( s8 o' f% M( ?& Ato get SoftICE 'Back Door commands' which gives infos on Breakpoints,
/ J6 _, n5 B  B  ]/ J" u" K( qor execute SoftICE commands...
3 T! k- ~: q% M) a0 J6 vIt is also used to crash SoftICE and to force it to execute any commands- [: ]1 Q* Z& l8 A5 u: X1 R
(HBOOT...) :-((  
7 B; |( s/ \( F2 H
8 P: X3 ^+ i" {1 W# _1 d' SHere is a quick description:
$ ~/ m) ~. q( h# K4 `9 o; C-AX = 0910h   (Display string in SIce windows)
. R3 q3 H9 f  g4 T2 O3 }-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
" V& y. u; E) e% g-AX = 0912h   (Get breakpoint infos)7 E; B/ Q1 A; q9 S) [
-AX = 0913h   (Set Sice breakpoints)
1 Z( P) U2 \8 F8 I+ k6 A! A-AX = 0914h   (Remove SIce breakoints)
! G- a* A, U  m9 |! I) {$ E! l# F& t$ r! {
Each time you'll meet this trick, you'll see:
9 x% C. s7 V. ~/ Q-SI = 4647h0 z0 N9 S2 X5 E9 \# o# b+ I
-DI = 4A4Dh
- Y7 @6 t0 k& g) X; s0 X$ w, o: |Which are the 'magic values' used by SoftIce.# u5 a0 T5 Y* Z4 C
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
( t! A% f) `3 h  ^2 p1 J8 g  Q/ e
Here is one example from the file "Haspinst.exe" which is the dongle HASP
4 c9 A% I, u! A3 qEnvelope utility use to protect DOS applications:
4 c7 K$ D: L4 ~* o5 X2 }
5 K# d/ g  @# z* s
0 N/ O2 z( ]9 h. h6 s4C19:0095   MOV    AX,0911  ; execute command.1 f/ @/ Y" h6 V2 E# K" K7 T
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
2 Y" [8 r. \! Y3 P4C19:009A   MOV    SI,4647  ; 1st magic value.
8 v$ n" C) e  P/ t3 f& @2 s4C19:009D   MOV    DI,4A4D  ; 2nd magic value.1 l+ B" X6 U4 B2 C5 ]7 @2 M' R9 p1 c
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
# E5 s- z% p# V4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute% V+ ]) I8 a9 |5 G' b
4C19:00A4   INC    CX- \& g" M* q* `6 ?% g6 n
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute/ K% O+ `" P& l% h, R
4C19:00A8   JB     0095     ; 6 different commands.9 u0 ?/ ~# J" U9 c2 q  w/ c9 R
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
7 h4 Z3 E% F$ U& r- H, A/ s4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
" p7 G/ A1 H. g5 n0 `3 }  s9 I& s9 e3 J! G& z, C! |
The program will execute 6 different SIce commands located at ds:dx, which
1 |: k5 s' {; j% K" I: B& R: g# Oare: LDT, IDT, GDT, TSS, RS, and ...HBOOT./ P! \; s$ g3 V
' C4 x. l6 n) S$ B( U" ]' i
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded./ s- v, d9 h, W6 ]9 M/ I) _% l( c
___________________________________________________________________________
, i# T% V4 x* K1 Y1 I6 }: z/ B9 O6 x* }" O. X
$ C! M* [. C& n; s8 K
Method 03
1 E8 u7 x4 g  ?5 J3 N4 K=========4 B- d7 i4 i5 R1 O7 o

; K# m) o" f6 A5 |2 }Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h0 b: o' A( v8 o2 L* \7 O, Q' n0 J3 \
(API Get entry point)
' C; U+ T+ O, H1 c# ]1 D        
8 p( @+ \% B# }, g' ^+ ~
- o# F% V' {# g! o8 V; f3 z    xor     di,di6 ~8 j+ l- r1 [- Q( E
    mov     es,di
' m- G# M) j4 [1 M" G: r    mov     ax, 1684h       ( g( x" ^. @( {& D# R" a2 A
    mov     bx, 0202h       ; VxD ID of winice  k& k* X5 W  ]3 o" ]
    int     2Fh
* h2 ~: o$ w  c    mov     ax, es          ; ES:DI -&gt; VxD API entry point+ [, |9 m7 c0 o0 m/ s1 i$ |9 `
    add     ax, di
. X# m- s6 ~1 \8 n/ N    test    ax,ax* o9 Q) `9 `0 O0 X
    jnz     SoftICE_Detected- q0 H0 h1 S) a7 a# d8 z

, C# V, \+ w# ?5 l___________________________________________________________________________: I0 d/ p+ T! Z" L  A

6 I* {" U: ]' w) g1 h% OMethod 04  b; ^4 C' X; r9 e! I# d
=========/ E: c- d- `4 U6 J/ m6 f. k
  c5 F& W4 g$ v% {4 L4 G' R
Method identical to the preceding one except that it seeks the ID of SoftICE
  a% o- ~: L+ U4 Y; ?( F: WGFX VxD.
7 V# [9 U6 E7 w& A6 [6 [: _7 j! O; P4 [
    xor     di,di
4 x& ~# a* l+ ]+ a4 x: m) C    mov     es,di2 t; G+ c$ w" K0 U: i3 p
    mov     ax, 1684h      
& f* S- N5 I& p3 u, H( Q5 d    mov     bx, 7a5Fh       ; VxD ID of SIWVID
9 J& t) X1 L2 f$ }    int     2fh: `3 w/ q3 N! H' }$ D6 p9 ?
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
* T/ C. R" R! J; Z; A    add     ax, di; z! B  s4 f- N* W+ X! p- n2 b
    test    ax,ax
% S9 U) s( T& k; H8 N1 F    jnz     SoftICE_Detected  _/ K* c& u0 w) _
% g( Y( _& A2 I, d" q
__________________________________________________________________________0 Q( b% t0 e0 Y
3 G$ A, \7 T1 N: B

8 H$ P5 }( \# A& I/ N" @/ dMethod 05
! h& v# Q* a0 Z=========5 d. Z' Q& D& v+ D4 u4 }" j

/ {5 Y. y/ k' X* w3 ~# Z1 KMethod seeking the 'magic number' 0F386h returned (in ax) by all system/ C3 c# `" F5 r3 \! ^
debugger. It calls the int 41h, function 4Fh.4 U* M' }7 Y0 C" T3 q4 E
There are several alternatives.  3 x* k+ [/ i. W$ _
: q0 r3 F: p. M, [5 p) S$ n9 F
The following one is the simplest:- }& h, [" B/ V8 y. C" _8 s  [' V
' t2 m+ q! K& f+ T" I
    mov     ax,4fh- X! Z& N* ^" q+ U. u. \1 s, j: y
    int     41h
: j( N2 s5 K' J0 I0 e    cmp     ax, 0F386$ a. E' c0 A9 p3 T1 x9 r( H( j. P
    jz      SoftICE_detected
, k/ L' }3 {( n- [7 T' \& D0 J) N9 Q& g4 w' V- v1 t

% c2 H$ s& r4 e: \" e8 Y$ g/ cNext method as well as the following one are 2 examples from Stone's
: q$ ]. R9 p5 }/ L, Q$ l/ T"stn-wid.zip" (www.cracking.net):
1 h+ y2 D5 b, M0 H( o# f5 F+ K- ]9 _, K% l) J9 v
    mov     bx, cs
& c* r2 E; X) A0 P/ t: A    lea     dx, int41handler2
) M8 E4 r" f( T) w9 T: Y    xchg    dx, es:[41h*4]6 Q# E  D. {6 j+ L6 J. i
    xchg    bx, es:[41h*4+2]. Z3 d( ], n/ N4 G, A
    mov     ax,4fh
, y! Z3 y; l% Y. E    int     41h- J" N: n; t  p+ J
    xchg    dx, es:[41h*4]+ Z: ?3 c/ ~* u- k* _. L: d/ |
    xchg    bx, es:[41h*4+2]
( y5 R2 C( t9 {/ T! q) m    cmp     ax, 0f386h
; X# U. i4 y: P3 k, m' h! x$ C    jz      SoftICE_detected
5 q& R) S) Y- Y7 [3 L
  |0 ~2 p4 a& l+ w5 {int41handler2 PROC  Q, ?7 @9 U, H7 p% p% ^! n3 S+ p& z
    iret
. Y0 R/ {1 M$ a( Fint41handler2 ENDP
% D  ?4 ~" `& H9 R# r4 E' x' H! b' P5 T
- V5 r1 g; J/ j. d$ X, p
_________________________________________________________________________0 b9 L) L& X: O) C: K$ I$ P
0 o& m6 y# K. B" M8 {! y3 p7 W2 v
0 {( j/ L/ I4 B, n
Method 06
3 f9 R2 _9 K* b=========
  f7 S0 `* M' I! }2 o0 o% o3 ~
8 M. I6 U, W8 p3 m; u) t0 w( f* C0 L, U
2nd method similar to the preceding one but more difficult to detect:: D( h) T5 }& E# @9 L
4 ?1 S/ S3 k. R, W1 p. F
+ H5 x7 d$ e& w  Y/ B
int41handler PROC9 g1 e" o- l: o1 p4 z- B* G8 u( z6 m- O
    mov     cl,al
) O/ j1 ~# |4 G3 O3 j  y) D    iret0 C2 _3 h- c# ~$ D2 [2 T
int41handler ENDP
* ?5 X: A" C1 @! a3 E: |* G4 p& N& I$ T5 `& |  g
" ?% ]! Q% `! s' S# i- s$ R
    xor     ax,ax4 U* y7 e2 a( F0 O
    mov     es,ax
2 D& ?. E" w3 x: w4 Z    mov     bx, cs
/ K7 x4 E, _) ~: m; s7 R; [% p( G    lea     dx, int41handler
- U! G: g' G" A7 ]# d1 _+ J    xchg    dx, es:[41h*4]
' ?4 J: |, S4 T! u( R% Y    xchg    bx, es:[41h*4+2], O  R4 b  \! K
    in      al, 40h
: Q  B" p* X( G. S    xor     cx,cx) U# H* j" D8 r( b# |; S- B5 K7 d
    int     41h: z5 T- r% D; i7 d0 l& r
    xchg    dx, es:[41h*4]
  _4 `" ]; A: K    xchg    bx, es:[41h*4+2]
, N) [, t( a$ q    cmp     cl,al
: M* s% p1 V8 Y# O, X    jnz     SoftICE_detected
6 |4 w' `0 F1 g  F5 u
! O. b: X  E7 |3 i_________________________________________________________________________) g- \5 a* p9 K' E: s" Q
; F2 j0 U  n# T! R: C: u' U* @. O
Method 07
" U. H( [$ Q% `1 e) r=========
: p% j# I( r+ S2 U
) k2 W2 l) v$ `8 T+ kMethod of detection of the WinICE handler in the int68h (V86)
1 k! P, _4 _+ l" {; D& L
; k8 w' J, t" Y/ I% m    mov     ah,43h8 b, V% }6 i4 |! h' f. A2 h# {
    int     68h
, e5 J: n6 R  k/ b+ k1 X5 v    cmp     ax,0F386h2 [1 D  [. j  Q9 F; v3 U
    jz      SoftICE_Detected
" ]# c0 |& ?$ w+ m. R2 S# b
, n2 A  D# ]0 l/ V
7 i5 _8 U# u$ i; @6 P4 n( I0 n=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit9 e& [; p2 i/ a+ M  @; J% v
   app like this:) g* Y- @: D6 Y+ J
, b6 N) \, a  J  R9 {) r
   BPX exec_int if ax==68
: m7 N8 t: x1 B; n3 c! v# Z   (function called is located at byte ptr [ebp+1Dh] and client eip is; l  m( B* j8 s( J) `
   located at [ebp+48h] for 32Bit apps)4 {& V0 g: m7 a3 V" g# x2 W5 w
__________________________________________________________________________
! ?! ]5 G3 V" X- N6 t" k/ p/ \* K3 `2 q4 k& t/ N

/ Q6 \6 Q5 ~. D8 JMethod 08
$ r/ {* s: S( J( w# l$ R  q% J=========
2 F) o% ^; a! ~
5 j& J* M* ?9 s2 E" z( LIt is not a method of detection of SoftICE but a possibility to crash the+ o( Q5 h, W& ?% ~8 c- Y
system by intercepting int 01h and int 03h and redirecting them to another
, Z" R) h- \7 o" k1 J- _routine.' e" s+ o8 G" q, K
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points* g, d8 c8 t* O, I8 c. o& u
to the new routine to execute (hangs computer...)+ s% U/ s: H' _1 a7 H8 G% o7 q

: w" B; W) C1 O    mov     ah, 25h
! w3 u2 n' F& H  j    mov     al, Int_Number (01h or 03h)
; c3 p* X. c, [2 ]1 {    mov     dx, offset New_Int_Routine6 B6 t# o( Y7 B' F8 }8 E
    int     21h
9 S7 @% E, o% ~3 Y! Q2 \2 n% y+ s5 e, W
__________________________________________________________________________
* V/ K' L, G% M) r8 }
- ?8 b: H  |: S6 ~, Q; }1 U. VMethod 09
6 Q& ^# ~+ K% C% ^9 Q; K=========( W7 R6 s7 R% ?" o; E
) I9 H# C" g- ^* A1 W3 F3 m
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only6 l  G8 V2 c8 Q, R
performed in ring0 (VxD or a ring3 app using the VxdCall).
; A" \2 }! e1 E8 zThe Get_DDB service is used to determine whether or not a VxD is installed' T6 \5 t# O. a+ P
for the specified device and returns a Device Description Block (in ecx) for
$ n4 W& r$ h+ [$ I1 r9 bthat device if it is installed.
- Z9 X1 }. u% Q. ?1 e, U
9 k$ d; u6 _; g   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID" x! L. L/ q1 ^3 R1 R! V/ o- |
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
  A+ E! Z0 S$ m6 F2 x8 Z   VMMCall Get_DDB. r, e; D3 n3 x" g3 Q1 P. {
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed3 S3 `) E3 M* A! I

$ Q8 K0 Q2 Y- oNote as well that you can easily detect this method with SoftICE:
0 S) u2 L/ U( e   bpx Get_DDB if ax==0202 || ax==7a5fh' i" C' J! s5 A

5 [& s& ~) R! ^/ O& j( ?7 F5 k6 M/ w__________________________________________________________________________
/ }7 Z' p! R7 @5 P  H
' J0 i' N9 q2 D5 e9 lMethod 102 t  k, f# ~5 i9 a
=========
! Z9 g; {8 N1 D; e# w$ E3 d( Z# r( C& Y+ m
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
& n6 k% H- t2 J, K4 }: O, i  SoftICE while the option is enable!!+ L) ~2 Y5 W5 Z! {5 T2 _% E
4 E5 W& d: V$ j& u% w" w+ Y  O/ L
This trick is very efficient:% C: ^2 V+ q' l: O
by checking the Debug Registers, you can detect if SoftICE is loaded% y) X" ?3 N' f$ h) |
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if9 D9 S1 i9 ~- \5 N# C2 O  A
there are some memory breakpoints set (dr0 to dr3) simply by reading their$ X8 @" ]& g5 J% }7 B# K8 ]
value (in ring0 only). Values can be manipulated and or changed as well
7 E( T, s: r: U, O( ?(clearing BPMs for instance)
' o4 J5 }' l# U8 f- |( {
4 r2 T. y$ K. {$ |) E__________________________________________________________________________6 M+ d& U( l( X/ }- D

1 {4 Z5 N( S* M) D8 p, i; m4 I9 j4 NMethod 11
' ?+ A$ X' f- r7 \, p& j; w6 p- Z2 y=========. Z$ `8 ^5 b+ w1 E. @$ Q9 ?

/ e. e4 z! |& }This method is most known as 'MeltICE' because it has been freely distributed
, v1 P: w* a# ?/ F! n2 uvia www.winfiles.com. However it was first used by NuMega people to allow
0 a% k7 }1 Y) q9 I- C1 V" C- Y# ?Symbol Loader to check if SoftICE was active or not (the code is located0 k8 _8 _& v, v0 }
inside nmtrans.dll).
: Z) B9 |7 Y. X. F. c" |2 J3 S# w3 l! P) d( J, i
The way it works is very simple:
* u) u; _9 `1 a) G3 ^9 b6 yIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
; k. {& T7 d% u7 ?# t/ S1 V/ E% FWinNT) with the CreateFileA API.( `$ V5 n* A) X. b

# V( k/ X* k$ ?4 y; }3 v; X/ u# xHere is a sample (checking for 'SICE'):
, C  g$ Q4 m' n2 N. \% L& D3 s3 K7 j1 n( W' h/ s. k( B
BOOL IsSoftIce95Loaded()9 p5 H; p6 O5 T1 `
{
# G$ r8 i- _3 b4 ^/ \6 v8 [3 C   HANDLE hFile;  0 a& v& J4 K! J0 ?$ r! ]4 ]3 B- D; E
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,/ J' W" [/ X6 \- K
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
  s( L2 q- @! k& D- Z  p" l                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
0 ]( F9 t  E, b' z/ [" \1 B' h; c   if( hFile != INVALID_HANDLE_VALUE )
2 t: ]. A" s' C: e   {! \; z! I* D5 z  V
      CloseHandle(hFile);
' Z2 L. t9 R* a1 q      return TRUE;
  R0 z, t! j5 x2 w- N8 {" r   }* O% c5 B* f8 R6 ~0 ?
   return FALSE;/ @0 k9 c, l6 [- c% [+ p
}/ E& i1 A& a, G8 U) ]
" }5 `0 g* p4 D3 f, N: x5 F7 C( p
Although this trick calls the CreateFileA function, don't even expect to be9 G; w: ]3 ], ?7 S& m1 Z  N) m7 R7 S
able to intercept it by installing a IFS hook: it will not work, no way!  V9 t! C: j% d5 y2 C" H& j* m2 @
In fact, after the call to CreateFileA it will get through VWIN32 0x001F. X% D/ a2 Q/ I8 C; [
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
2 k' S) Q7 w/ \) M" X+ @and then browse the DDB list until it find the VxD and its DDB_Control_Proc$ c) W1 p  I( I  u6 F9 U6 N& B
field.: d4 I* f+ ]/ D1 D+ Q& S
In fact, its purpose is not to load/unload VxDs but only to send a * L4 U( y3 l) l! z: E- K
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
4 s8 P" [* W' ?9 Hto the VxD Control_Dispatch proc (how the hell a shareware soft could try
. U, ?+ Z0 P/ H0 M; H( Cto load/unload a non-dynamically loadable driver such as SoftICE ;-).
% t" y) R5 y3 K# I. r1 ]/ o7 WIf the VxD is loaded, it will always clear eax and the Carry flag to allow
# K. {7 q9 ]( q! o+ I- ?: sits handle to be opened and then, will be detected.
% G2 w: l* \' r  H7 S2 V( B" Z0 ]You can check that simply by hooking Winice.exe control proc entry point
% d& H4 z; U' g; ^, I, kwhile running MeltICE.# J/ h  I$ M6 \" L" P- t

( O" i5 [: A; y) [5 ?, O& t/ E  J# G
  00401067:  push      00402025    ; \\.\SICE
; N: E: ?: C7 ~3 y  0040106C:  call      CreateFileA0 m( x9 I0 L- P% R3 G
  00401071:  cmp       eax,-001
& d4 n) }( W. S  00401074:  je        00401091, u& A$ H8 ~' w
# E3 _! p; p4 F) f. t
( k+ Y: b5 q0 S
There could be hundreds of BPX you could use to detect this trick.
- Y# t) E& i) j" V  r4 }-The most classical one is:9 [% I* [. z9 s; V
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
/ K% T' ^- F- i* X    *(esp-&gt;4+4)=='NTIC'
7 E6 A3 `2 E6 T+ `0 X$ {
$ |8 H2 a. T- n-The most exotic ones (could be very slooooow :-(
- [5 g& d4 M; I' s3 j) B: c+ T% j   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
8 O( o* x3 [2 Q& F     ;will break 3 times :-(
7 N4 L' r, K% a& D. Q1 a$ k
# G- w! B- W0 p8 `( G/ R* @5 s-or (a bit) faster:
* X3 y4 j/ a1 Y1 i4 m: C   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')8 J$ \* X, z5 P: r. i
" l! g" }$ h. n  J  S# E
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  9 ]. R7 I+ F9 ?0 {3 {+ b. N2 K
     ;will break 3 times :-(  c, b% t" ~$ a6 \+ Q& b
/ C) \/ n; ?! X' {7 _: H) P' ^% R4 V
-Much faster:
" V; @! Z) m" b! i" Q   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
: Z% t+ D0 C/ R# e
7 k8 A$ I. z! M. p, i- [9 w0 i: ^Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
& I& D0 e' i8 I# E2 Ofunction to do the same job:
" a5 m" N7 _; a5 l- w& H2 Z, Q  x. T
   push    00                        ; OF_READ; s: W; V4 Q. o/ D3 Z
   mov     eax,[00656634]            ; '\\.\SICE',03 ^2 I- Z9 U0 @! O7 t# k8 ?
   push    eax
+ R) G+ f2 K7 p1 O/ E& Q   call    KERNEL32!_lopen& Z( _7 W! z& ~6 p  D4 m. ^
   inc     eax8 F( r( B2 T% i7 j9 }
   jnz     00650589                  ; detected
5 w( S# d( B3 I& e6 |$ s: j   push    00                        ; OF_READ8 l, i- d  i6 D1 S% I
   mov     eax,[00656638]            ; '\\.\SICE'
# K! B. _; c; j, H   push    eax
. c7 Q- \0 d, N2 i   call    KERNEL32!_lopen1 o2 H) M: @, o
   inc     eax
4 a' R6 T- W: `+ P5 ^   jz      006505ae                  ; not detected+ e9 b% n# N$ G
+ `9 ^+ r  C6 x/ j" U8 {) _

" K, A' t4 i+ _. @3 ~* x7 u+ M__________________________________________________________________________
: }6 E- F2 d; o3 `* U; I4 e# T$ }4 a/ K9 y7 A
Method 12" ]+ f+ m9 r0 c! S6 b9 I
=========% d5 y& j9 o2 [& R0 U9 @: K
% g2 j3 \/ v, K# h" S5 A; ~4 {
This trick is similar to int41h/4fh Debugger installation check (code 05
! }1 x5 P( }5 i( H&amp; 06) but very limited because it's only available for Win95/98 (not NT)
4 H" Z8 r" C; \( F, yas it uses the VxDCall backdoor. This detection was found in Bleem Demo.; K  R5 t& _9 F9 V

, \# A+ z8 z( Q* W   push  0000004fh         ; function 4fh
: A2 q/ V4 j% ~9 f   push  002a002ah         ; high word specifies which VxD (VWIN32)
9 i  _$ A7 ]: g8 U! a/ C                           ; low word specifies which service
& P0 c2 x) S) K. F: h                             (VWIN32_Int41Dispatch)  z& R& K2 m3 w6 e# D7 g# b5 _
   call  Kernel32!ORD_001  ; VxdCall
( y" I, V( j" t; l- X- r/ M   cmp   ax, 0f386h        ; magic number returned by system debuggers
/ G2 {9 \0 Z9 E& {   jz    SoftICE_detected6 D* h1 v! D* K- b+ ]
" z4 }+ X6 ~1 y4 I
Here again, several ways to detect it:/ U% y1 r! O1 @2 `3 F, i

3 X* H. x  X! _8 M$ a  E0 v0 h    BPINT 41 if ax==4f2 p* s8 a, J5 L4 B! c% B$ a: h$ `- \

3 H8 Z: q4 T* d" V, H' o    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one, H/ Y$ \) m2 K  T

' Q' ?; c# c3 g; e+ X  g5 E# g    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A! H# T) ]  E  {6 \" o
5 |& l1 X0 N# M! x6 V+ y' n  d
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
# l; a, X. W+ F$ v
: Q+ M+ w3 V/ H% O# w" {" [# m/ _. r7 U__________________________________________________________________________
) h' e0 s  I& U$ W" i8 v  P* s; a9 t2 F/ Y. ]% W2 v( L) b; ^
Method 13
, C" ]' J, s6 N3 d=========0 v* k0 T' y! Y

3 R% I& U2 n" S' w) cNot a real method of detection, but a good way to know if SoftICE is- j9 ~# F1 n4 M2 K3 o
installed on a computer and to locate its installation directory.( K+ c; U" S0 i  Q( i7 g1 a4 b
It is used by few softs which access the following registry keys (usually #2) :% `7 V3 u1 r& [6 I- Y

" e& V+ K/ ?, {" d-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
) N, M- }- |; y) A" N" h& _8 ~" v) o\Uninstall\SoftICE: E  M8 |) [; A+ E8 p- O- y
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
$ ]  Q; S& D  g, N/ \1 E$ l-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
) |, C& L7 I7 O& N  A/ I\App Paths\Loader32.Exe, B- }6 i  C. t/ O9 R
7 z* B) t/ L1 g8 v0 `( X: ?

' C( ^; q9 Y9 a* B3 M: hNote that some nasty apps could then erase all files from SoftICE directory
  n2 ?% E7 s: U( Z+ ^7 ?% C(I faced that once :-(1 ~; c5 ?6 i; l/ ~  n% M/ m

% D; G' b4 C. H/ o' c0 MUseful breakpoint to detect it:* u& x) `# |, e, l& B

$ ^& E: N+ i$ f     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'3 ~& m: r3 p/ [3 z
8 L4 @) i0 V/ d) r& ~
__________________________________________________________________________
: O8 [2 x' J, u* P7 c3 F. G  P" L9 B8 e8 c6 \
3 q! i4 J- w. k7 t  x
Method 14
! ^7 T6 M$ b! E  {=========# R8 T( e1 l: y7 A# |2 N: Z
: n  ~% t( M) c, l5 E/ N5 d
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose/ @% X8 c) e7 A5 ^, [: ?) e
is to determines whether a debugger is running on your system (ring0 only).
$ ^& R" T  [1 _' l; W$ ?% D) y& \4 M* A( Z8 F
   VMMCall Test_Debug_Installed
1 n2 S6 l" H: p( F. R! e) z   je      not_installed4 s, g5 c  {# Y* C' T

; ?: z/ o& t: u8 t  }  E: AThis service just checks a flag.
( _$ f1 H8 S/ y1 {, C$ \/ \</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部