About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
( R* O1 K" d: ^5 d' i' k<TBODY>- U  m4 P( i0 S- d2 ]1 O
<TR>4 A4 {8 v% {  {& V2 x6 b! y. Y
<TD><PRE>Method 01
3 {$ Y) }" m/ w9 s" M9 |=========5 R1 I9 a; U3 t7 Z4 |: q; k
. F6 ]$ M$ n. x% O! t+ \
This method of detection of SoftICE (as well as the following one) is
1 O7 x/ {6 \" o9 o4 j2 B0 Yused by the majority of packers/encryptors found on Internet.  G$ h8 C3 C0 S7 l5 X5 m
It seeks the signature of BoundsChecker in SoftICE; \( \$ K( w' y+ P( {( X+ V

/ }8 h# U) e% x2 y- t: k    mov     ebp, 04243484Bh        ; 'BCHK'% U; x& V0 b  I9 A
    mov     ax, 04h
' ~3 M, r1 h  T0 M% ~. ~% N    int     3      
2 g+ M( g/ b1 i; K    cmp     al,44 \, L. R2 c+ J, X7 B# D3 D! M
    jnz     SoftICE_Detected
( f/ A# L* u2 A8 p0 _
$ x) G2 k6 X* U% E) s___________________________________________________________________________
  v- r) r8 R: R6 t2 k8 K3 ?8 H2 g) Z. u
Method 02' U1 S/ |* E. l8 x+ E  [
=========/ C0 N0 N4 b' a) \5 Y; N7 j2 N/ I

' x( v; C; @# e( WStill a method very much used (perhaps the most frequent one).  It is used
3 y5 H& S& A* E4 N* [( H+ xto get SoftICE 'Back Door commands' which gives infos on Breakpoints,  g! k  o+ F6 H7 O7 w$ ~6 Y- a
or execute SoftICE commands...2 s: J2 r* ]  ?& W
It is also used to crash SoftICE and to force it to execute any commands
8 c' ~- c4 \: m& U& V; I" U0 s(HBOOT...) :-((  
' j  q& I0 b! o4 E1 P7 [
  R# r1 R. A* w' K1 l* h9 a; uHere is a quick description:+ ]8 I7 l! f3 i) I, \9 b$ c
-AX = 0910h   (Display string in SIce windows)
) |/ ]& T$ @1 p2 E9 H# y6 e- |-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)7 P) x; I4 c. g
-AX = 0912h   (Get breakpoint infos)
$ V/ J+ h2 a: K+ n. v! l-AX = 0913h   (Set Sice breakpoints)
! v& S3 @4 l. [-AX = 0914h   (Remove SIce breakoints)
$ y0 D3 v0 @( o: k/ ?4 s5 i- O; _. I
Each time you'll meet this trick, you'll see:
4 s! R$ P4 D, A" N- s-SI = 4647h
  U0 U) t; f9 b8 M-DI = 4A4Dh
- z' I/ x& y2 ]8 k/ }1 RWhich are the 'magic values' used by SoftIce.& z/ e) P% H; [( ?1 G
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.8 \# y* R& r6 E1 a

4 b% y" \) W0 D3 ~( T8 \, yHere is one example from the file "Haspinst.exe" which is the dongle HASP5 t2 Z* c' G% F2 o8 U# |
Envelope utility use to protect DOS applications:
; o8 K' u8 H( M% h. c! C
' O6 d& z: x3 X5 x3 P5 \% J/ K& Y) v/ I! R- N8 m/ V0 D
4C19:0095   MOV    AX,0911  ; execute command.1 |' Y4 M9 _  A& Q
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).: Q1 d# H7 V" A0 q! y: e4 {) Q
4C19:009A   MOV    SI,4647  ; 1st magic value.* L, l) B4 S6 c+ f) z/ N+ l7 ]
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
6 j3 L& V3 S/ W  F2 [) q; a9 R4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)* L0 l* p* z/ G# f3 |9 R
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute6 F" W" c5 B4 Q) V2 Q5 l
4C19:00A4   INC    CX
5 ]. ?( ]4 h" P9 Z# ]& _4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
+ ^1 L/ w; R* R; h# Q$ [( W; u4C19:00A8   JB     0095     ; 6 different commands., r7 G4 D( u0 A; F
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
) \& X; A8 D; M7 c2 z$ F4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)& A" y) q) c! b5 B9 ?' i  P  D
6 ?7 M! M% n, H1 j. }( E# T$ e/ x% \
The program will execute 6 different SIce commands located at ds:dx, which
; {: I0 N! U. u) T$ ~2 |1 e3 Sare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
! k' J' S! L2 r! K! y3 g6 {+ _& ?# U
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.2 A9 S) R* d: ]( m2 [) s( c
___________________________________________________________________________; d# U+ ]+ Y7 Q

$ {) e2 L, k. p% {3 ~/ [: B3 F& @8 L- ?( q! B
Method 03
. z" h: H6 @/ L. |=========1 E& g% p5 p0 s5 q* V3 d+ h

; J7 N" i# ?, e5 S) y- JLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
$ j4 w; r% ?. Z8 s" k# x7 l(API Get entry point)
+ ]+ ~, ~7 ^  ?. G/ e+ c( V  T" a        
6 E; j9 d1 W$ {$ ^' B4 k7 E( q7 v% o; N/ S
    xor     di,di/ m" w! d- q1 W5 S- m& R7 a
    mov     es,di: s) q$ `7 d) i8 z" n2 M. e
    mov     ax, 1684h       + H& K# e3 Z2 z1 I1 c2 o
    mov     bx, 0202h       ; VxD ID of winice6 B4 ]1 {" p% E5 W2 a* }; v" H+ _
    int     2Fh
" ^2 ^% _/ T! y    mov     ax, es          ; ES:DI -&gt; VxD API entry point
% r. g* b- w  I! G: Z    add     ax, di9 {0 f- D. }# y, i" ~6 U
    test    ax,ax
- O  x3 @* y- n- Q& h) r9 B# ]# I    jnz     SoftICE_Detected
5 X2 y- p5 ]' `9 _6 b8 N8 ?" x* M8 h$ v& I  v" f2 z5 v
___________________________________________________________________________
0 A6 p! o+ e! S" _* C" N* }0 m/ X4 D
* K0 A' k  }7 C6 r. I! tMethod 04' Q6 O7 U- M! M" E
=========! O5 ^8 r/ m) c9 @

- D! W! j1 M- v( Q* N$ jMethod identical to the preceding one except that it seeks the ID of SoftICE. s+ _! K5 D7 G# R) l! O, q
GFX VxD.
6 M2 Z$ k$ }! @- o/ V- P/ p8 Y; g1 |( `
    xor     di,di. D0 w: t* a: A5 t) w( j5 d
    mov     es,di+ R: R' i! w, q! @2 T9 ]% d7 j1 Q' d
    mov     ax, 1684h      
9 [; _. E# b* x    mov     bx, 7a5Fh       ; VxD ID of SIWVID
' @( C- h) T: D/ ~: c    int     2fh
: P* ~: Q1 ^4 @4 e! i4 {8 |# t. F2 g    mov     ax, es          ; ES:DI -&gt; VxD API entry point' y! I* z% M9 e& [( R
    add     ax, di
/ u5 {  X& ]$ v7 G. t* n: X3 [    test    ax,ax
! l1 |2 c9 X5 t" y; A; q    jnz     SoftICE_Detected$ t: u" e' ?/ q0 w

) K- r" _2 D* Z  y+ ~& a  G' G__________________________________________________________________________
* A7 }- u6 [, U) N/ ~
" r/ f% F6 U8 T, ?5 s; l$ m5 x; D0 h0 o$ {' H
Method 058 j( `" e4 T* e- o/ y/ {: L
=========$ J0 _- M" X" j, @
, s" v7 m' g$ v* @* }& A# `7 l
Method seeking the 'magic number' 0F386h returned (in ax) by all system
6 K; }) a& i- ]: ?debugger. It calls the int 41h, function 4Fh.
. Z7 h" u/ Q7 C& D0 R8 wThere are several alternatives.  
8 k$ k5 J# c5 n
* ]  ~% C; g+ eThe following one is the simplest:0 {+ M3 @  u6 h7 A

& I7 W$ H& e7 o5 v/ b3 i' s    mov     ax,4fh" `0 X( O& u+ G1 `
    int     41h! o7 J& D* Y5 ]0 N' I
    cmp     ax, 0F386
' @: a4 I# W* H  t    jz      SoftICE_detected
/ [  u4 V- ?% [" [6 |: ^1 G* t# G/ S- n9 C9 |2 W

2 O. R0 O! D7 u4 W4 J2 p7 xNext method as well as the following one are 2 examples from Stone's
/ r1 J* H  D% l. T"stn-wid.zip" (www.cracking.net):
; v& Z) V2 Q5 k; r- z9 ^- S4 Y: O" A' A7 D# m5 z9 w
    mov     bx, cs  C# A/ X% U& z: Q% x: [3 Q
    lea     dx, int41handler24 X9 H, l4 b% d) }0 G' D+ S1 W: t7 H4 k
    xchg    dx, es:[41h*4]
) |# J4 I6 t+ s/ H/ F4 J    xchg    bx, es:[41h*4+2]
0 y3 ~  q6 B+ t/ T: M6 ?    mov     ax,4fh2 z/ ^/ z6 m/ z( w1 U- v+ Y
    int     41h5 I: A; ?# w0 \: L5 ~9 S. C) k, F
    xchg    dx, es:[41h*4]* x' i* ?0 c1 F6 ~, l
    xchg    bx, es:[41h*4+2]
# L& W) `5 U5 ]0 ~% C    cmp     ax, 0f386h. A! a; ~3 Y$ v( ^* @
    jz      SoftICE_detected
  r; }& F3 X6 b& k
- o3 d' e# i8 eint41handler2 PROC( @9 \0 p' v, A/ N" W
    iret8 x4 a( q; |8 I3 o# Z
int41handler2 ENDP" j; D( I0 v" O
0 I. @& X+ i7 ]4 y* h) R  @- W

- c; Q3 ^5 Y. k7 f/ P_________________________________________________________________________
& y4 ?& w3 N8 J
0 v. \* l# x5 d$ z# q. {& Y; x
. `7 O' i' G( m1 I4 t- z& @; ]Method 06; L1 {2 Q1 J7 R5 Y
=========
* Y, A. m4 K5 L' W
8 k. s5 N: r  @  }& t( l( y5 T# ~; ]
2nd method similar to the preceding one but more difficult to detect:
% o' E4 t4 o1 s) q" A! B3 l3 V! B& \. [
1 J' V" a# X2 K, o" P
- b$ u# G7 B$ ]6 N! iint41handler PROC0 e2 B* \  ~: Q! L& `
    mov     cl,al
7 |+ W+ G/ ?2 Q$ M' T    iret
1 V" R) v& Z+ u8 J& {! `1 Xint41handler ENDP
: z5 F* S2 h, J0 S: v, G8 _8 @) C. u) K( o' n

/ n) y) g& ~4 Q    xor     ax,ax
' d7 M/ }! o8 D0 x1 w0 F) R1 w    mov     es,ax( U# \7 J1 T# S9 I& y+ _4 |
    mov     bx, cs; U) o+ _+ J% ?2 |7 v0 ^
    lea     dx, int41handler
( a, R7 V6 E8 |% B    xchg    dx, es:[41h*4]
, @4 P1 D& ?! Z. s& J    xchg    bx, es:[41h*4+2]
' t- j. K) e" z( r& P: y* v# p    in      al, 40h
4 `, G  `- r/ u( }0 h  p$ y    xor     cx,cx  R9 a. I1 I% X
    int     41h3 T+ L! {$ w9 k6 d/ n$ }. M& C
    xchg    dx, es:[41h*4]# l( k/ Y6 |1 I3 @) L) ^! v- Z
    xchg    bx, es:[41h*4+2]
, D+ w( x4 D* K( y, Y/ G  q    cmp     cl,al
6 S: L- u+ |! ?    jnz     SoftICE_detected( g' g7 E, }! ?; z& @5 x

# ^& a% I& k* M_________________________________________________________________________! D  x$ D# Z; o0 F6 t+ c
) q! n6 E6 O/ f
Method 07
8 ^5 y6 ~3 s. ^7 P- y( ~=========& [/ \. j: Q1 L3 U' K' D. o3 c
2 _+ P4 y8 J$ D& v8 J
Method of detection of the WinICE handler in the int68h (V86)
* ]- }1 H# T5 z5 S4 G! Q% [/ `! U  G4 x9 t! k  t
    mov     ah,43h
. O4 ^' e' b+ O, P, u    int     68h* \9 \* B. N) ^, y  k8 v% V
    cmp     ax,0F386h
% R  F8 k  C; ?    jz      SoftICE_Detected
4 L0 F5 k( K5 |4 a0 q) q& N
  p6 r: O3 X& D# P# \' n7 @) J: Q/ v9 O( X" \# {
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit+ A! _, Q; v4 G$ |+ J- S7 ?
   app like this:* Z6 h$ v) i. [/ f- H( P% }

' h; G, L/ `& ?0 \   BPX exec_int if ax==68
# m1 D! Y1 S2 C8 ?5 p3 b- K8 I   (function called is located at byte ptr [ebp+1Dh] and client eip is
) y! F2 W: m$ {# A7 l) p7 M   located at [ebp+48h] for 32Bit apps)
, I" I5 Q% m/ w; D; ?__________________________________________________________________________
$ v! [% c' D: k/ a  v4 u
4 m2 A0 u: F3 |+ _) x+ ^0 Y4 s" R$ t! ^/ n9 }' ]5 w8 ~% U$ J- y3 E
Method 08
5 [0 E: Z: J$ N( ^7 P- p=========
7 B8 s; l4 U7 d. C" M* s/ d+ Q& }
% z) F" D0 O+ _) v2 ^7 rIt is not a method of detection of SoftICE but a possibility to crash the/ C( [9 D) \3 ?% e' k" H( [
system by intercepting int 01h and int 03h and redirecting them to another' t' m" M  w$ {! L/ b, p1 y
routine./ v( l8 |$ v! S; _8 h
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
( W' [! O6 x! Y* A5 `- I' @* Tto the new routine to execute (hangs computer...)# w* H' \9 D( V6 R+ _! d
6 d  x5 C( [; V! G
    mov     ah, 25h2 H- C; [* C- e0 K$ E
    mov     al, Int_Number (01h or 03h)5 G  t: `+ i- r- `) i/ g, C8 V( }
    mov     dx, offset New_Int_Routine) B! {- A. |. p; x, C! N
    int     21h0 M0 f" q7 L9 ^) W1 ?$ {# ~

( r4 d* I6 f$ z__________________________________________________________________________+ ?) s2 L" w7 W! v! O7 U  x6 k

) Y/ c2 r/ P9 z- |; x. c3 U8 EMethod 09
! r! v* S, t7 ~! @. j=========
: w8 B  u. X& k9 L7 u+ r5 ?& \" C3 S
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
7 z) f: m1 g; B; V* v. s, hperformed in ring0 (VxD or a ring3 app using the VxdCall).
0 f% G/ S4 I$ m8 F: m. H! N+ kThe Get_DDB service is used to determine whether or not a VxD is installed
/ k4 E9 z3 `8 A& Mfor the specified device and returns a Device Description Block (in ecx) for- s0 ?3 s  l; D& s
that device if it is installed.6 j+ s' ^. B5 S7 E/ J) f2 }9 U
+ ^; T+ {# d- I
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
2 |  u; W. I3 C   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)- d) k* P. U  Q7 y# n& U' ?5 J
   VMMCall Get_DDB# [  N9 g/ O" Y, v9 S# e# r! f
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed" ]+ a  f8 g' z

2 [/ a( K' I) ?1 J5 G" j' m. YNote as well that you can easily detect this method with SoftICE:, }/ s/ O! I  `( Y8 I6 i. o
   bpx Get_DDB if ax==0202 || ax==7a5fh
. [* ~( R$ p- c. |0 g
2 i* s% R8 z% X__________________________________________________________________________3 n8 E# R. `5 }3 P2 _, L

7 N2 i# x% N+ ~5 m6 B- bMethod 10
/ [# O, `* Q* |- H5 I0 K0 D* K=========
% K. j, X' X* {, i6 l1 m. J  H# H; K& W* B1 f+ o9 w
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with) I! p; A  J: g5 m# r
  SoftICE while the option is enable!!" J+ v. O* i% z) E
1 i6 N( \8 x' E  m
This trick is very efficient:4 f3 v" l1 [' X& ~# Z1 C
by checking the Debug Registers, you can detect if SoftICE is loaded* T2 e9 O$ o9 i! p
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if8 e4 b( {- b9 w6 F
there are some memory breakpoints set (dr0 to dr3) simply by reading their/ v4 H6 t( T8 N. Q
value (in ring0 only). Values can be manipulated and or changed as well
2 {2 d) d5 C% J' H" h2 k(clearing BPMs for instance)9 ?9 W0 c7 p1 I+ P/ q% O

" D- r& b; A9 p& A" ^__________________________________________________________________________
0 D  I3 `. j; P9 }6 Q6 m8 V# @' U% J3 J
Method 11; l) w2 r# s: H
=========
4 D6 G& H0 I9 n0 ~0 n7 P
% t4 q! }! U: I( h& g9 I' XThis method is most known as 'MeltICE' because it has been freely distributed
/ G- `6 k1 t8 f" w0 Z/ G; A% ivia www.winfiles.com. However it was first used by NuMega people to allow
( }  u. d. [$ \7 z2 Z! G- w8 cSymbol Loader to check if SoftICE was active or not (the code is located1 Z: C7 @: @, U/ v- K
inside nmtrans.dll).2 \1 I8 s3 X  `) @0 ?

8 ^) H; u5 G; K" WThe way it works is very simple:8 i. W3 j8 l' O+ p! O# Q+ K' b
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for( T# Q) z  y- l# f- J! Y4 E
WinNT) with the CreateFileA API.
  m2 b7 Z) t' ]3 ~& V0 _; R2 g
, L" q1 r8 P0 s+ `1 J5 E$ SHere is a sample (checking for 'SICE'):( n& x" O# @" S+ M8 x
& J  ?2 C8 x& ^* c$ x/ V6 j' Z: w9 j
BOOL IsSoftIce95Loaded()" x. j5 ]- @7 |! g' |/ \
{8 I1 i  ]! {5 w- c5 V
   HANDLE hFile;  2 B2 X+ _( i: a6 K, A* t
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,2 |; _9 t+ B3 _" z
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
& q, G% O* C( F0 ?                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
/ o/ N2 Y3 Y% k: ^4 c3 h; l  j   if( hFile != INVALID_HANDLE_VALUE )
6 u# G; o1 U6 I4 b6 j) j  E! J5 C   {; ^8 }# d/ \# u1 S: Y* h" p7 t
      CloseHandle(hFile);
( Q$ [! ~! o, b5 C; L+ J5 N' R4 h      return TRUE;; |# d- c# C( G$ L; I
   }
# @2 f  N6 O" N/ M8 m: x   return FALSE;9 ~( F" P! l& y6 [% p
}
% i6 B3 ?2 A! B. D/ R& l$ B, i8 s" I9 D& w6 g5 E+ ^9 z$ h
Although this trick calls the CreateFileA function, don't even expect to be
- V- ^9 c; M2 B8 L7 bable to intercept it by installing a IFS hook: it will not work, no way!
, [( p8 ?  @' b3 r- @) yIn fact, after the call to CreateFileA it will get through VWIN32 0x001F  ~5 L1 V; x0 p8 }0 v; e$ a+ o* U
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
" P, q4 S* X: t9 d; ^6 Cand then browse the DDB list until it find the VxD and its DDB_Control_Proc
7 E" W- N; ?/ l- y; m& F6 T( ffield.
3 Z7 E7 M6 n* ?2 L" D7 X) eIn fact, its purpose is not to load/unload VxDs but only to send a
6 N* T2 N, X9 `+ a7 {4 G5 b; KW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE), t) |% E9 W* y2 q; n4 b  H1 Z' z
to the VxD Control_Dispatch proc (how the hell a shareware soft could try  C$ q1 [8 ~2 k: ~" D; [' L9 k
to load/unload a non-dynamically loadable driver such as SoftICE ;-).* e+ U6 C: Y+ w$ i4 O
If the VxD is loaded, it will always clear eax and the Carry flag to allow
: o- q* Q" e! c( b  P7 Bits handle to be opened and then, will be detected.& h/ a3 H; I- I) O9 B; [
You can check that simply by hooking Winice.exe control proc entry point
6 R5 }# D1 g0 N, v% s+ g+ x& i) Lwhile running MeltICE.- Q2 t2 v$ M$ Z- g- e! K2 m- B/ b

, T7 z: n5 v2 I( G$ w/ b% q( p  Z% e4 ?
  00401067:  push      00402025    ; \\.\SICE6 x5 t, h; M6 _, t
  0040106C:  call      CreateFileA6 m  e4 n8 x- N& N- `' F# S% n2 T
  00401071:  cmp       eax,-001( z2 Q, J( R/ }7 [8 O1 d
  00401074:  je        00401091
+ X. X- n; P1 v
5 I# o/ l5 r$ n3 m& o
- b. N% r8 F( L) [0 XThere could be hundreds of BPX you could use to detect this trick." u, F2 W9 l. J8 A9 r( u
-The most classical one is:, H! h+ w3 U5 w, _+ Q3 J* @0 ]
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
& y. I- s+ _1 b3 H( R    *(esp-&gt;4+4)=='NTIC'6 N; O* d, v# N; _- n% g
/ K# T% A1 G4 o0 p
-The most exotic ones (could be very slooooow :-(* m& D% }' N4 D" B2 c7 V
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  5 o6 F+ O& {. \2 Q$ s
     ;will break 3 times :-(
# p' M, X6 X9 o7 \/ J5 W) Z+ r4 n, K5 x; m3 R) G; ^
-or (a bit) faster:
- f' h' J* ], S1 O  a- m- V" S   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')& e0 H/ J! W, r9 |# O
+ q" G# a) I$ q2 A' N  j! c
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
% p% w1 N, r4 r9 n9 q1 F     ;will break 3 times :-() X) M9 t+ a5 b! c4 R7 b

! `$ Y, U1 D, v5 e-Much faster:1 P5 D" l  O/ b
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'# x: O+ j# B: |0 E0 q: q
% {5 P2 q$ j( F. d) D' V
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
4 ^4 p; M/ Y/ r' ]3 s4 q0 ofunction to do the same job:
4 p( }4 O. z, y5 Y" ~
# m( E  L0 R+ o/ E& k- d   push    00                        ; OF_READ
# G3 x+ N/ Q) a; f6 [   mov     eax,[00656634]            ; '\\.\SICE',0
: K+ c, j% }) ~! S9 J5 Y   push    eax
6 a  u! i6 [% B7 M# A/ v; s4 G/ p   call    KERNEL32!_lopen
0 L* w0 X. v8 J   inc     eax) x! M4 |! F! M- s( @$ b. l
   jnz     00650589                  ; detected* j8 s! v4 o. T$ h* O
   push    00                        ; OF_READ0 Z7 L4 z8 G# R1 s
   mov     eax,[00656638]            ; '\\.\SICE'
" U; w- \. F2 e1 Q   push    eax
2 `" e: ?' d* q3 m0 J0 X   call    KERNEL32!_lopen
6 Z1 N- K0 V  n: R6 c' K0 o9 O6 H   inc     eax; L; u: d: n5 A( h. h
   jz      006505ae                  ; not detected
, r. H, {) f: M6 _. k/ ^% o! L7 @- e9 H3 V& z
) g# V1 |! R. }
__________________________________________________________________________8 ^: v3 b6 g2 ?$ k4 p
: G  i$ a  J/ y/ S) I4 Z' q
Method 12& A* j: g. s, A5 b, _' Y% B
=========5 e, n3 h7 {8 R' z
# f5 V7 F2 @5 j
This trick is similar to int41h/4fh Debugger installation check (code 05: C' ^8 J% Z$ s
&amp; 06) but very limited because it's only available for Win95/98 (not NT)% g9 t& _. }% Y
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.+ l* }  s2 }* M! i

: x# r( B5 s5 C1 d2 @5 M   push  0000004fh         ; function 4fh+ K3 m0 t; L& I
   push  002a002ah         ; high word specifies which VxD (VWIN32): q$ Z9 l3 o4 }+ n
                           ; low word specifies which service% D' r8 d3 @+ y* Y; }! ^; B$ `; }
                             (VWIN32_Int41Dispatch)4 K9 V' U4 P, V0 v
   call  Kernel32!ORD_001  ; VxdCall
$ D6 O0 u2 j/ v: q, h( @% N   cmp   ax, 0f386h        ; magic number returned by system debuggers8 _# ^( j& V0 @: j( m# s: A
   jz    SoftICE_detected# s% @7 z) ?  ^

, u/ D4 l+ {$ I6 I# eHere again, several ways to detect it:; [: C' G! \4 I$ ^
- D3 A+ t1 d) E5 @; k
    BPINT 41 if ax==4f
- r5 F& n; ?' B# ^! W6 s. R8 t4 T3 l) `0 q' l5 m! A* o& j* B
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one& v$ M* i6 S/ F4 i/ P2 ~
1 c" B" f. B( @; U
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A& _6 m0 X0 u" Z1 S; ~" I5 ^. ]
  f7 w- T- ]( j6 @7 ?
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
/ R. v) v* P* `8 \1 q( g( A  j# [
__________________________________________________________________________
% O. [( ^3 ~6 G* k6 i" ~3 S  t, I& i/ k$ w6 W
Method 13
) }) C- V2 I9 J& O4 f( W=========: A1 |1 q6 T6 @/ e+ E7 E" P+ W* l
# c; Z+ l5 S: @, w8 j7 E( C, \3 n
Not a real method of detection, but a good way to know if SoftICE is, I* n3 A& m3 F9 X
installed on a computer and to locate its installation directory./ \! a: S2 T' O* V3 E& ]
It is used by few softs which access the following registry keys (usually #2) :
* o* e/ I' N& J& F6 R0 I
9 e- c$ p5 _: S$ Z8 J-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( Y6 N& |7 s2 G' |6 H) s
\Uninstall\SoftICE
$ V. w2 t0 i0 Y; |/ v-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
9 {5 m+ I, N1 j  q' v# ]+ L* o$ Q-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion3 V7 r. X2 q6 X0 B1 }" M/ ~2 R
\App Paths\Loader32.Exe
" d9 z5 A/ L( M* ^) ^& _4 b
& a2 t4 c# f( M9 I
/ ?5 j1 J" _2 t8 g& QNote that some nasty apps could then erase all files from SoftICE directory3 p& J+ v. n/ ~
(I faced that once :-(4 O- p8 H; D& l  K

# V1 J+ {) j! N: n7 s5 e. A7 RUseful breakpoint to detect it:6 U4 M: x0 s! b

, b' f- T& a; B$ s8 I% L/ |     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'8 F0 V7 \4 U0 e4 G4 R
. _) G) g9 }1 v2 s6 t: b+ b1 R* {
__________________________________________________________________________
; k( p8 e% F; D/ r$ ^9 A5 g) m* m7 z+ c5 j, Q2 V' ^) c0 C

/ J- a; s4 O$ W* O7 C/ kMethod 14 + H. T0 ~) n# z9 d9 U* K" G" R, y
=========
# \+ v7 H: C: A( F3 ^
0 V! H; V' x+ d& yA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose1 i3 u) Z0 Y  V' N: M2 T
is to determines whether a debugger is running on your system (ring0 only).
$ F8 R: B/ M2 y! M# p8 c# T- [7 x4 z% w
4 c0 E$ U' z  v" I   VMMCall Test_Debug_Installed* d) `( m" B' k. m, j8 X. z8 c% Z
   je      not_installed
: g% E% z+ y! w# L1 `
  J! n1 O& x! x. O' {" J+ TThis service just checks a flag.
! E8 g( N/ A( B! i</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部