About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>! p' L0 X6 v. `4 B& O* d
<TBODY>
8 k3 ]( ~$ K3 F$ m" ?<TR>! w2 p+ l) x' Q: g8 R& h
<TD><PRE>Method 01 $ {: Y! m- j' A6 M! H; p
=========
& ~6 W1 Z8 Y5 s  z$ y
  m1 z4 Z: A1 M# yThis method of detection of SoftICE (as well as the following one) is
, @/ m/ m- c0 n- vused by the majority of packers/encryptors found on Internet.9 y1 @' k& x7 e2 H! W2 i+ o, g
It seeks the signature of BoundsChecker in SoftICE
5 V  l$ J, H8 ?# b- _. Y
' e( ~, v* ]" p6 @, l$ d0 W    mov     ebp, 04243484Bh        ; 'BCHK'
9 ^2 o( L6 x& I3 {    mov     ax, 04h* u9 \+ N6 F1 Z# Q. z' f
    int     3      
: B. @( Y) o7 F5 Q% Z8 K8 i7 v' E    cmp     al,4: a7 i- C: Y: o- X5 J+ [
    jnz     SoftICE_Detected! k- l7 H4 x% ]: X: x; O+ q, c  A

, Z3 V; b6 _+ q( \* T" j* q___________________________________________________________________________; l$ |+ }+ R( b1 [, |+ f4 ]- R

3 {, A5 R" Q6 o  HMethod 028 [3 r1 Q5 x6 I3 l4 p
=========
8 u- ~! Y% @3 E3 i) j/ b2 L0 W: r& X( `. ^! R
Still a method very much used (perhaps the most frequent one).  It is used
; P3 e" q$ r) f9 o9 {to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
2 r2 H0 A! r- c) @" U# D: Vor execute SoftICE commands...
0 o& S- E" A! S) rIt is also used to crash SoftICE and to force it to execute any commands/ V5 f! }  C2 k1 _: e
(HBOOT...) :-((  2 t6 Z. \9 T; z

7 S! {1 f8 {, {) K9 L9 RHere is a quick description:7 L. P; |' n. A4 C! v8 d; z& w) ^
-AX = 0910h   (Display string in SIce windows)' U/ |: u1 o! \6 a- W0 |% c$ f0 s
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)8 D: c0 u3 Y8 u; h( d: ~
-AX = 0912h   (Get breakpoint infos)
6 N! R" {0 s0 y3 j-AX = 0913h   (Set Sice breakpoints)
; I+ J7 T9 P2 J5 X) k; t, }; S-AX = 0914h   (Remove SIce breakoints)  X/ \8 j0 y; G# e6 o

0 g) ?6 V. s: J4 n# A0 W# UEach time you'll meet this trick, you'll see:, q' C% B. e+ s$ a, z; j3 E
-SI = 4647h' ~$ Q7 M3 E0 L. B9 u
-DI = 4A4Dh
4 u# M2 M: P  `& G) hWhich are the 'magic values' used by SoftIce.8 |8 g; _  x+ J. D4 f- S9 Z  o$ U4 I
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.  U) d2 g2 G7 a" d

: K! H- ?, k) fHere is one example from the file "Haspinst.exe" which is the dongle HASP! B- X& ]$ M. l, n4 F. `
Envelope utility use to protect DOS applications:$ m6 [  M! v1 W! u, X, x

0 W& ]3 a: l1 f( |/ e; n+ y1 ?9 c% Y7 B  Z1 n: Q
4C19:0095   MOV    AX,0911  ; execute command.
5 Q: [5 o# z. @) J4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
3 F7 |& H' F" P6 u+ {  m4C19:009A   MOV    SI,4647  ; 1st magic value.
7 m4 p# h5 l9 U: J4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
! N- w: I7 g6 X8 S# M; w4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
* [4 N' E+ ~& [. ^, ?( Z3 J& M4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
, q- W4 K* S  k; g4C19:00A4   INC    CX
) j$ z( G7 K% X& Z6 i$ ^9 Q  H: x! M4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute% l+ w) T2 ~+ f0 I; w; h
4C19:00A8   JB     0095     ; 6 different commands.
' x  d  t- p9 I) ^7 ?4C19:00AA   JMP    0002     ; Bad_Guy jmp back.9 R3 u8 h$ C1 J
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
) M' ?1 s* v% ]- \9 X4 w
" q+ K; z0 m8 N6 f7 H2 r6 l5 s& hThe program will execute 6 different SIce commands located at ds:dx, which
! e# h% e% v: P( Rare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
/ _0 I, o7 C$ Z! D+ A3 x% w) E# o" b
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
# |/ x" {  `0 L$ `0 U7 l; u7 [: A. y___________________________________________________________________________
5 y7 u5 s; v* Z) ]! h  r0 S* ~9 U. ?
" l8 _8 ^! \# _/ `: Q/ i6 S8 F0 d' _
Method 03* ]$ m, _8 m/ `& ^3 j& B) P! M0 X
=========; R" E! w% V) m, U: B4 R
: H, k0 [0 x  O9 a4 v7 _6 F
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
( r+ E% T5 @/ y0 V6 p# n  b(API Get entry point)2 h) g1 [2 _" g  p6 |5 U- x
        
3 S0 Q5 x0 {0 M! |
+ o- i4 \4 r  }/ B$ {7 {    xor     di,di
/ g6 v% _# X5 }& y- H& J    mov     es,di
  ]) B/ c8 Y* q' ]- K2 k    mov     ax, 1684h      
9 Z7 q3 x5 \6 K* j4 a* ^    mov     bx, 0202h       ; VxD ID of winice( y0 B- u2 x. Y( c
    int     2Fh/ U3 c# j: e4 a
    mov     ax, es          ; ES:DI -&gt; VxD API entry point. a. X* q* r. Q7 d: K* ^- P
    add     ax, di/ p! N7 X# b( w" Z* O. |
    test    ax,ax
  ~; Q" y! K: L2 B: `    jnz     SoftICE_Detected& B: {# ?8 u& R3 s  Y) e  P: t# e
" l# {8 h! Q) W, M, u3 n% O
___________________________________________________________________________
" u8 o3 `3 R4 T7 t* Q/ v1 \! z# x
$ d2 ]# f( `' Q& S3 V  ZMethod 045 z- a# @# H5 G* u4 s* |+ u( x
=========6 T0 M# e/ H8 H& W* j

4 K- ^7 ^2 v) YMethod identical to the preceding one except that it seeks the ID of SoftICE
. j+ h; ]' Z6 D  s8 UGFX VxD.) \9 ]1 L9 b# \; e5 @4 V: V4 c
$ {% X) n9 v) E
    xor     di,di3 q, y) F) M& y5 `/ k
    mov     es,di9 l+ l! n, T* f
    mov     ax, 1684h      
4 I4 [) I' t4 K: f. {    mov     bx, 7a5Fh       ; VxD ID of SIWVID
/ c. ^9 k! h6 F- d* D    int     2fh
; X4 o% \4 z" V4 y7 w  ^    mov     ax, es          ; ES:DI -&gt; VxD API entry point- }: q# H0 p6 r& Q3 j3 ]
    add     ax, di1 `& \; X( a; A& `
    test    ax,ax- m, x2 I) k4 ?  h4 j- {5 y$ B
    jnz     SoftICE_Detected
/ S( C1 T) P# c7 M  F/ ^1 t$ U8 P9 D
__________________________________________________________________________7 F' N# \/ r1 X- l. B
* `  O2 a" X! p1 p# V1 k
: z8 K' |: m7 L2 I
Method 057 G5 Q5 N0 H% z" T1 Z) B
=========
4 c% m8 {+ _7 s7 Z
# x5 }. ^$ D* z: f7 ^* p! l) \Method seeking the 'magic number' 0F386h returned (in ax) by all system
, x8 W) S8 U0 `4 u* m: t' e2 u+ ldebugger. It calls the int 41h, function 4Fh.& Y& U$ [6 V3 {% E( X
There are several alternatives.  
% p$ v0 o8 M- u# W! Y/ Y: z
* ~3 _+ v& J) X$ eThe following one is the simplest:
4 D8 V' n. V9 t4 ?7 n- {) }4 t
/ c7 s$ @  T5 I" u0 T    mov     ax,4fh3 `0 \, Q) @- w' a* P
    int     41h3 c; |; j0 g2 w$ k9 X$ X# u
    cmp     ax, 0F386
& c$ x7 B2 n, z: n    jz      SoftICE_detected1 T1 r0 U  H; B/ n  ~5 f

) S9 ~3 J! w4 {7 ~8 @  y+ F
' _5 }7 p: c7 z9 ENext method as well as the following one are 2 examples from Stone's
$ ]! s8 [2 u- |"stn-wid.zip" (www.cracking.net):1 {) X& |# W( P& e, F+ d. g; V
8 I9 y; |3 z' Y: {0 G8 s9 ~
    mov     bx, cs- P; a4 ]2 V4 p5 D! _( l* p2 n& Q
    lea     dx, int41handler2- T2 L9 C1 R  \: u2 m
    xchg    dx, es:[41h*4]% e5 r+ e2 p( E2 R$ p5 z& n
    xchg    bx, es:[41h*4+2]7 h- {0 n5 a6 @% r1 }* @/ b
    mov     ax,4fh
2 w, Q# W; q) B. F    int     41h
) O5 L8 [" B0 r' s% U% v    xchg    dx, es:[41h*4]- r( i0 ~" l% R/ C! O  g
    xchg    bx, es:[41h*4+2]
9 P; ^$ e+ A. G" Q7 G( t2 j    cmp     ax, 0f386h
9 f( s- d. t8 l    jz      SoftICE_detected4 @% g3 r) j" a; S+ z# K1 y# Z; X3 J

2 F' C" S) R( C# Z; ?4 R1 Vint41handler2 PROC
+ T0 q0 z: a8 a; V1 S: f: e! T    iret$ Z6 m& n4 {8 V, B; j% t
int41handler2 ENDP
9 d, k/ s5 R( v2 h) J; i# F! ^( ~& v1 b
: _/ `) N/ {6 X, O
_________________________________________________________________________
' [9 a5 F  g% c6 L" V! s
9 Z: V) _0 ]- p
) u( `1 }0 ]( m- x9 gMethod 06; [5 N9 e. }  v
=========
) W* u+ Y3 d! K+ Z# R6 }) d
( Q  {. r% V* Y  F& b5 Z, B  l
2nd method similar to the preceding one but more difficult to detect:
! c# d# d, {* s: O8 Q& k+ V. c* l8 d- f

7 p" X. _' Z. f" A2 ~( B  u& M9 aint41handler PROC
( W" p6 `4 [6 Q1 V6 j! {9 g$ `" H$ i    mov     cl,al
, ]& b, y; B; {6 [8 L    iret1 @) ]; V& i- s
int41handler ENDP
. `: F! S/ l+ P3 R9 B$ q# ]6 X; f! `
6 O2 u( ?. j0 O' E6 [
    xor     ax,ax* w: K" g- o  `
    mov     es,ax
& M& c7 {: r  v9 a: }2 Q& _* Q+ m% s3 ^7 x    mov     bx, cs
. ?- U8 ^5 j5 I0 Y1 u1 o/ b    lea     dx, int41handler2 }8 D$ y8 N: l( X8 R
    xchg    dx, es:[41h*4]
8 J' }4 ?& p" o( f+ \! ^& P) F; f    xchg    bx, es:[41h*4+2]: J7 [" v/ z, ^$ ?
    in      al, 40h
9 L5 Z9 v4 ^  w1 H' k, ~    xor     cx,cx! a0 e& y: R: v3 X5 a0 l5 X
    int     41h
. ^% X4 K  X! B& \3 g) x- k9 [    xchg    dx, es:[41h*4]! i% Z, a  j; i, O, t
    xchg    bx, es:[41h*4+2]
+ @3 D5 w, Z- S/ d. @) c    cmp     cl,al  u# I- F! I3 U: Q9 M
    jnz     SoftICE_detected" `2 D5 V( ~1 C7 F

3 K- W: r0 l7 q: I/ Z( B# }7 x  t* g_________________________________________________________________________
3 D! a+ r( q" V8 d) B& e  W: ]0 i0 H2 b  P8 `
Method 07
' W5 a# L3 j+ h=========
5 q, X+ I" _2 d0 y1 w; s+ g" B. j  v# l% ?
Method of detection of the WinICE handler in the int68h (V86)( J+ G( K9 `0 a8 a! H
6 H" T5 M  {2 P2 q
    mov     ah,43h
1 |7 t5 [6 g+ j7 ^; F; `    int     68h/ I4 F$ z6 }* x* S. L3 X( p9 f) H
    cmp     ax,0F386h5 _% U' T( |# [4 U' C
    jz      SoftICE_Detected
) s8 ~+ `  C' c  U4 H
: b+ h) Z5 J0 A/ f
3 J8 Z3 ^9 P1 {  D3 Q! I=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit% r  N2 m0 Q3 v% _) F5 y7 H2 m# y2 i
   app like this:
) y  {8 }: R0 m+ [7 F- H% N' O2 u2 g- y% e# G# j: t/ |
   BPX exec_int if ax==68/ Y: m2 k# ?0 p4 u. K4 B
   (function called is located at byte ptr [ebp+1Dh] and client eip is
1 j* E% e1 I! {* M   located at [ebp+48h] for 32Bit apps)
" f; C# W0 }' a9 `3 P1 h__________________________________________________________________________
4 ~1 X( x- R. F% Z( h) B5 E
( I: n6 [) s9 ~- [1 {+ \4 @* m9 l0 e
Method 08" t8 V& K! `0 w5 b  O0 V  |6 J5 E) L
=========& H" d$ l, K# W3 M, T1 w

9 n, m) U4 W, r# u: }; v- EIt is not a method of detection of SoftICE but a possibility to crash the
) l$ i6 z4 ]# s# Q3 T9 K% dsystem by intercepting int 01h and int 03h and redirecting them to another
8 \4 R6 V% Z' [+ Q$ Q( Y+ Wroutine.
# x6 v! Z) G/ L5 _* aIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
, o& G* R' X" Z2 I. k6 \# D' ]to the new routine to execute (hangs computer...)  n/ `9 ]- T% G# Y7 v

: L2 X" N% J$ I2 a  C    mov     ah, 25h
7 |" i" x; g0 X    mov     al, Int_Number (01h or 03h)+ T% V5 ?+ w3 T8 o, ^
    mov     dx, offset New_Int_Routine5 a) X$ \9 ^& V! @) [
    int     21h& G0 m  S+ e" h5 X2 A
: B4 ~- ]% Z# N; W, N; s4 J" Y9 f5 {3 k
__________________________________________________________________________) A% {$ v" v, Q0 v% f

3 Q  }$ {2 e3 j: [$ e- TMethod 09
3 ], l4 L) Z% ^8 m, S=========
* S( v0 e4 E) j" Y. M3 X# Y# b9 ?3 A; J6 K2 m$ p8 n
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only4 p- r: r6 K& n( L* F4 m
performed in ring0 (VxD or a ring3 app using the VxdCall).
" M: O; Z) ?: L' ^' y+ kThe Get_DDB service is used to determine whether or not a VxD is installed' S- Z# E$ _% {+ t6 A& K
for the specified device and returns a Device Description Block (in ecx) for* M" q  S/ k+ R$ \: }- P1 }9 T
that device if it is installed.; t5 ^7 s  @7 m# A' C

3 ~+ K1 m# _: }3 e& g   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
( P% ?1 k( N; Q, `' b. B3 J   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
; L: c+ q( M. Z% l1 ?   VMMCall Get_DDB. r) ^3 p( \8 t9 [; z/ D( y) E
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed  D5 e6 S( U2 ~- m

7 H8 e1 S% l7 d% |Note as well that you can easily detect this method with SoftICE:
: {, e2 T9 A% F! t! C* O% n; N: C9 G   bpx Get_DDB if ax==0202 || ax==7a5fh
# j2 m+ b0 c: g: z1 f' S* a" e8 r& }4 `/ R& U1 S
__________________________________________________________________________
3 i) |+ ~' N7 E) }! y* N8 E& }- a$ j
6 v: L7 H' F( }! D+ AMethod 10
7 ~) W# L& L$ d6 V7 T( Y* M=========: D$ g0 `  T8 h( y0 b& {$ Y; t% b

  P- o2 G5 i5 E' n  _# E=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
! R% W- n7 {6 \9 E3 H/ ~/ h  SoftICE while the option is enable!!
2 p1 X1 H1 G% `- U! E5 M% R% l$ C5 N( H
This trick is very efficient:
! I/ M8 W8 B; ^6 T' D- P1 {' Mby checking the Debug Registers, you can detect if SoftICE is loaded
; Z% p4 R; G7 ]# l9 D! k2 {# L(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
* q" I! w$ R1 {3 }" a  v& Gthere are some memory breakpoints set (dr0 to dr3) simply by reading their
# d2 S) f( S* W# I; @0 g& b) ?7 Mvalue (in ring0 only). Values can be manipulated and or changed as well
5 P' C7 K" V2 }. D+ m(clearing BPMs for instance), B$ N: i3 O8 l( M# ]4 h

! [8 b; ^0 V1 P__________________________________________________________________________
( ~0 E: }: g) W  E$ P4 ]; O$ P5 W$ f! W6 D7 j0 j' ^
Method 11& g6 t( }# b* X9 q1 l7 [0 w
=========
, `$ m$ C7 {0 J0 U) P. |% ?- P1 `5 s& u7 }; x& p: ?
This method is most known as 'MeltICE' because it has been freely distributed
2 V. X* d. r( T  N7 `  d3 D  B/ rvia www.winfiles.com. However it was first used by NuMega people to allow1 f' K4 _# F9 C
Symbol Loader to check if SoftICE was active or not (the code is located8 l4 X  G8 \* ^5 j1 Q6 g
inside nmtrans.dll).
1 g7 t) ~; Z$ H" |1 Z( E1 N# V- F, j) [
The way it works is very simple:6 {7 p4 H$ M5 `  H  `) h& t0 j5 O
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for" ^- r0 r" W  Z5 d
WinNT) with the CreateFileA API.; o+ S% _7 q, b2 k5 G

7 i# m0 t, L2 Q, bHere is a sample (checking for 'SICE'):* Y4 a+ z0 V+ Z$ m+ D
  ?) d* o+ s  `
BOOL IsSoftIce95Loaded(): X/ ]0 x( H3 b! q  T: K. [' }
{
+ d; `+ S5 I0 C# c6 k; e- V7 Y% j   HANDLE hFile;  
; H2 [: w, Y2 c' t) q1 X# _  P   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,; p! U( `& s. H. ^1 W7 {
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
" X! k: u$ m# J6 B% Q                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);/ V- J: j. {7 k- z, [  Z
   if( hFile != INVALID_HANDLE_VALUE ); _: F+ F  V' n0 m* q
   {+ {/ K2 ^2 B5 _5 I. t; Z6 k' b
      CloseHandle(hFile);/ C8 ~) k0 j  Y' i: v
      return TRUE;* f" T4 [5 C9 A/ X
   }+ |, _* Y  W5 c( J
   return FALSE;
8 f* D) k6 d# _% r, d' P}9 L! ~, I0 j7 q. A- ^7 p

& n# S# H( r" C. J9 }Although this trick calls the CreateFileA function, don't even expect to be
9 ^4 o6 ?  _% g/ Fable to intercept it by installing a IFS hook: it will not work, no way!
2 q8 U: w9 x4 F+ t$ ?In fact, after the call to CreateFileA it will get through VWIN32 0x001F8 R; G- ^! ^7 W, R& m: i
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)' x2 r  z/ U/ d1 p& F, U  f
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
! j. i) f7 k& n6 F# F$ x  j  _field.
, E( A9 E" u0 J- C$ C4 GIn fact, its purpose is not to load/unload VxDs but only to send a - K/ D. d- U0 }' n/ W8 w6 \! o. c
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)1 f4 g) c) X0 @. ^) g) j% W
to the VxD Control_Dispatch proc (how the hell a shareware soft could try- t; P0 R6 o& t2 _
to load/unload a non-dynamically loadable driver such as SoftICE ;-).! p" G+ u) W* o# l2 Y4 |, i
If the VxD is loaded, it will always clear eax and the Carry flag to allow
8 v5 p  E  s/ Vits handle to be opened and then, will be detected.
! f$ m' u+ ?8 v& Q0 [' ]; r) p8 VYou can check that simply by hooking Winice.exe control proc entry point
$ o0 B; B* o: u; mwhile running MeltICE.
2 G% H, D& R* _" D1 h1 M( ]+ c" Q) W" W# `- m3 Y8 \  J
1 H( m  P. D; T5 O( `1 p$ S
  00401067:  push      00402025    ; \\.\SICE
$ I! v8 `8 l% u! O  0040106C:  call      CreateFileA* n0 L5 ]! W0 [
  00401071:  cmp       eax,-001( X" S: k  B6 A1 p
  00401074:  je        00401091
6 F& F* o7 M9 w8 d  e
; w: Q. C0 h% F+ u2 T% D% y
6 J5 Y, G! S6 Q: AThere could be hundreds of BPX you could use to detect this trick.
6 N9 W' y) s  R* c$ C$ f3 z-The most classical one is:
% n' X0 F3 k; g: O' i$ }8 h  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
& S7 z) l2 q4 f3 w& O    *(esp-&gt;4+4)=='NTIC'8 p; v; [$ f, L+ A, J+ ?5 v3 F2 R

7 C" d, L1 J$ O6 @1 s-The most exotic ones (could be very slooooow :-(
& I2 q2 z0 y5 x4 v4 S   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  " y: q- |; t4 g7 s
     ;will break 3 times :-(5 q. o- A0 k0 _- n' q' K
: e3 _0 x; {9 a( [
-or (a bit) faster: 9 z" Y2 Y: m' U2 e
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV'). |; w4 j7 Z+ @3 Z. f' x/ ~
. j$ S9 M6 T6 N3 E/ p! ^5 {
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  % i. s/ a) p* }" B6 G* Y
     ;will break 3 times :-(
: D" V. p' j# C! M8 q8 }
4 }' H4 g* ?; b  a: k6 P-Much faster:! j6 \/ C9 L) W5 [+ M$ w7 g
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'- {- J1 ~: {* T7 \, D
* Y, i; A: b1 `8 ]  R) s1 i
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
; G& G/ m; q8 x. f1 b2 Xfunction to do the same job:& \1 K& ~, m- i9 Y

- l5 _$ B# C6 X7 Z; T% e   push    00                        ; OF_READ( N- @, ~+ C& ~& d
   mov     eax,[00656634]            ; '\\.\SICE',0
* y, i6 _7 L  [5 _1 @. t- p! k   push    eax  j1 L! H# B& y7 {9 X: w7 K8 s
   call    KERNEL32!_lopen
* S$ I# B1 \3 \: t- ^   inc     eax9 o. z' ~9 {3 Z  ]7 q, e2 k* [
   jnz     00650589                  ; detected
. I2 i# G1 v. T) T   push    00                        ; OF_READ
. S6 r0 H# T. N  ^; a3 e5 d& E   mov     eax,[00656638]            ; '\\.\SICE'& \4 |$ ?5 C! V9 w, f, G& T
   push    eax) I8 S  @. N* x7 G; s6 X* T! u1 L
   call    KERNEL32!_lopen6 d% C! K$ q4 ?
   inc     eax$ T- r3 _2 P1 m9 A& C
   jz      006505ae                  ; not detected
+ J( J' y; w* ?. i9 R( l8 C1 A) G- ~! ~0 F1 }

2 ^  E) }% T; D* ~. Q__________________________________________________________________________
1 D7 x- P+ D! U3 z1 O, x
: f5 A; K. Y' B" u4 O1 rMethod 12' N  e" y" k/ P; t
=========
% _& e/ f- V; L  k$ L) l7 x! _' v. v( b9 M5 E. B% E; h: K! D$ |) v
This trick is similar to int41h/4fh Debugger installation check (code 05* ?- D3 _1 R* c! v
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
. J# p# q$ z8 j) j/ pas it uses the VxDCall backdoor. This detection was found in Bleem Demo.9 `8 j3 M6 i4 W+ w! l
( C. Q( b  D6 p( g
   push  0000004fh         ; function 4fh# ^. ^- c9 x) Z6 [" C' Z6 Q4 G0 S  k
   push  002a002ah         ; high word specifies which VxD (VWIN32)/ A) x  L$ i: @- I( w5 a: z
                           ; low word specifies which service# g0 q2 Q% ?: i9 @- F
                             (VWIN32_Int41Dispatch)
  o6 ?) G: P. i3 J+ v   call  Kernel32!ORD_001  ; VxdCall
+ C3 [8 t2 m6 w# J; O   cmp   ax, 0f386h        ; magic number returned by system debuggers: `% a1 K3 b; ^2 Q  H- i0 j
   jz    SoftICE_detected
. O9 Y) s" l1 y8 w  C5 c& e8 y+ J
. C; c& s0 ^1 l& UHere again, several ways to detect it:1 e% Q* N7 v) ?/ g( k  X

* _* @' @4 i' G& V' @) X) V* X, P4 q    BPINT 41 if ax==4f
3 m/ B- M% j( r  U# W( E2 E$ [" J/ B9 O* j- p$ e0 [) Q- _
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
1 I, k. }9 w3 u4 ]: I' n0 E7 p0 H! E  n0 Q: [
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A6 K5 Q- Q! _& P4 |$ l0 }8 L1 r; B
2 B; P5 Y+ N* C4 z& X" t/ d9 ~$ K
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!7 d0 m# G( x4 [+ p+ c" j, `) l1 Q

+ Q, t2 w' Y+ k  W! J__________________________________________________________________________$ \. M' V" q, l$ Q! s) v
! o0 ?3 `# y" ~9 m. F0 `6 @7 u1 o, k5 J
Method 13$ O8 J" i# P+ T5 o! e! }
=========
/ ^) h% T0 g! g, U7 B- f8 l3 t7 Y5 W( G4 c9 R8 s0 @
Not a real method of detection, but a good way to know if SoftICE is3 P- R% c3 U* }! W; g9 z1 V
installed on a computer and to locate its installation directory.4 O- m  j" H) U4 h
It is used by few softs which access the following registry keys (usually #2) :7 ?3 T2 m$ S4 E* a9 e

" L9 Y; b) q+ t8 N+ C2 ^9 Z-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion8 a1 ^% j+ v  |
\Uninstall\SoftICE
; i8 q% r! V2 Y-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE' `# j3 {: R9 H4 |+ V  M
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion5 ^. k: R2 l: [" s
\App Paths\Loader32.Exe- }+ J6 s& Y* ]% D% H: @. ~  ^( g7 `
  F# x! A. ^8 o5 j- E8 \0 R& S
3 W9 B8 Z! P) K# Y
Note that some nasty apps could then erase all files from SoftICE directory
6 a, S6 z+ K) {(I faced that once :-(
6 v  C4 T7 M, F4 [3 e( p$ ^- f. X2 j: c- E
Useful breakpoint to detect it:
" g8 T" u" R- N- _5 r6 v/ `
2 B; A$ O% F7 N7 ~     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
2 }# _1 c7 _* @2 \* I, O# K
. a4 S! Z; B$ c5 b! |- J__________________________________________________________________________  \5 r  i) g$ f% c: Y5 z# @) C& }
9 f" J' A4 ^: C

+ c( }+ ]4 _$ m. T# |: q, b. O1 \' ]Method 14
( z+ p! l; F7 N! s) ~9 S- b9 M% e=========
) V+ c' f7 f2 h# `: O+ X% ]( [3 j( u5 h' e- }+ @2 H7 g" h
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose: O) G: ]4 M9 v+ f+ k
is to determines whether a debugger is running on your system (ring0 only).
+ Z1 d/ S3 m; ~; {" Z$ [
2 a) C, G* F6 J& J9 M0 L2 M5 P' ^   VMMCall Test_Debug_Installed
  E: k5 |& t) G* Z! o( `3 T/ ]   je      not_installed
, y: m4 O" g) ]+ k! I' v% Y
* ^. P- f* l6 f5 x* Q0 ~This service just checks a flag.
2 j2 N- Z3 g- p0 v</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部