About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>$ [7 f, f, v" j% D$ s
<TBODY>( X4 P4 p: e/ M; ~7 R- a
<TR>, F6 d. _% T# ~1 X8 [
<TD><PRE>Method 01
8 g, l& K9 x3 h0 T* b5 H" i* K4 ~=========" |1 w* a3 E1 V) W% M

( ~2 p. Q2 D* A; W  _3 F4 z/ PThis method of detection of SoftICE (as well as the following one) is
" ~3 Q" ]1 ~! H8 ~1 X' @* uused by the majority of packers/encryptors found on Internet.
5 n5 e/ ]' h* a! T0 ^3 P2 uIt seeks the signature of BoundsChecker in SoftICE
* ^1 j. j6 C5 c: y) d$ h2 T
) e6 L3 o7 f+ S- {    mov     ebp, 04243484Bh        ; 'BCHK'
1 i; |  ]" a5 @, v/ O0 p    mov     ax, 04h
' m! R9 e- w' b% L    int     3       ! |: n7 E3 N& t: j' ^* Y
    cmp     al,4
, z& g2 L; p, N) k    jnz     SoftICE_Detected
5 w+ g; T- F$ R; \" e  r& G. C, h$ ^8 O7 h& X
___________________________________________________________________________
/ ?% B# S; r! Q# {* i( I9 S3 q0 N. d! w5 G$ ^  }% x$ k6 F7 {
Method 02
; ^  p: c* H1 N9 H$ u+ t=========& W5 v5 U5 |0 T' q' W

$ ]% m* N4 }2 U3 xStill a method very much used (perhaps the most frequent one).  It is used& e" x; ]! x5 o7 y2 Z
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,9 W9 `) z" m5 ^8 ^' H* k
or execute SoftICE commands...
( `: a/ }+ K6 bIt is also used to crash SoftICE and to force it to execute any commands) ?0 g, t. b" F" Z% @  y% W, U
(HBOOT...) :-((  * G$ c# ?, ?- b% h( v/ g# j

2 ~" g1 D5 }0 |1 L& L6 qHere is a quick description:
+ h. R' L  ?$ a/ `-AX = 0910h   (Display string in SIce windows)
  v3 V9 P- I/ X1 V  Y+ ]3 L. u5 N. l-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)1 s# t  `# |" R. R9 E: O# R6 N3 C5 f
-AX = 0912h   (Get breakpoint infos)
  u6 c( x! d  [3 Q2 ]* u7 d7 k. N-AX = 0913h   (Set Sice breakpoints)/ ^) M1 u: K7 {. Q/ ^
-AX = 0914h   (Remove SIce breakoints); }& f/ K5 l1 k" H) b

# K5 B& y$ v% W, MEach time you'll meet this trick, you'll see:6 n7 y! w( I, p" R2 t# N/ j
-SI = 4647h/ ^) f# X# Q1 X7 ]* ^! V% D; P, P: c
-DI = 4A4Dh4 g, p/ N9 p9 r/ p7 d
Which are the 'magic values' used by SoftIce.8 J& Q9 }2 V, f  g8 N) }
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.( P8 I* A$ ]! L8 _7 Q

; N# F6 X- @: z6 K. w. ZHere is one example from the file "Haspinst.exe" which is the dongle HASP
' o& y3 u0 Y: l, WEnvelope utility use to protect DOS applications:
9 }& z+ V- X. H, \0 d  b; c9 `3 Q; Y" j9 N5 d% D/ b# R

# A! a0 M, Y9 `1 T" D) {4C19:0095   MOV    AX,0911  ; execute command.; w9 V5 \& Z  K& |
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
2 b+ S3 Q4 \, K4C19:009A   MOV    SI,4647  ; 1st magic value.4 S4 C7 E; ~" V
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.0 h& e* k1 a7 F2 I! r
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
) E4 X0 _# Q7 w! _4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute) q6 R6 g2 u$ p" E$ }! Y9 L+ a: `
4C19:00A4   INC    CX
. i+ Z( f8 j& y" J# i4 v/ k, b4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
2 f' ~! h1 p" O' g3 J4C19:00A8   JB     0095     ; 6 different commands.
) n+ b# @' o' F0 k4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
5 _" _. i& u8 C- q, Q; u" H) P  i4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)" a: G/ v5 b( F; @$ G# u1 X
! K1 `, m$ o, v
The program will execute 6 different SIce commands located at ds:dx, which; M$ N8 u, m: P7 e" |' ]
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
' x2 |) D" J- ~6 ~" p8 S* E
7 t0 ?# E8 k+ T+ m& a+ d* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
: J; C7 G$ \% O8 S___________________________________________________________________________
) I2 n( [: Q: B0 Q1 i3 i
  U  }' L) l; l$ B% ^3 h4 K: \! d! L6 F3 u3 C
Method 03
5 k: n, h- [8 o0 X* C=========! M4 k5 I0 C8 y  d
4 c( }! k  D3 t% y0 X4 m
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h' v: n2 p  O9 q7 O
(API Get entry point)8 O% Z: f: U; L/ u
        9 H% `4 @5 t, O* T2 Z7 |% P/ T" ]

* @8 Y. z6 L3 l0 e, I# {    xor     di,di! n0 B3 u4 X# s* C+ \
    mov     es,di1 R2 U& d" m- p& Z) \: T1 O3 i. n2 B* y
    mov     ax, 1684h       9 b  g/ \# O% }( s
    mov     bx, 0202h       ; VxD ID of winice
* v# g( t, L5 C( z. r    int     2Fh
: m6 u" Z. M5 n2 x, v) F    mov     ax, es          ; ES:DI -&gt; VxD API entry point2 ~$ t0 p, A1 F7 w0 v
    add     ax, di; c* U; h0 O$ Y/ w
    test    ax,ax
! C+ Q, `. T8 V" o/ W    jnz     SoftICE_Detected
8 l* l2 b0 w" A* m7 I; p( @$ ]4 ~7 e7 ~
___________________________________________________________________________
) E4 `# X; J, ~1 X
, E$ i/ P/ A6 k: e! X. XMethod 04
+ F4 Y% c/ A/ w2 S=========" f. v3 v4 M6 i* Y; K* l3 s) m
/ C( q0 ^; w3 D% U
Method identical to the preceding one except that it seeks the ID of SoftICE
$ j4 k/ ]% }! y6 \GFX VxD.; i. u( p2 {' M5 _  I+ X

$ e' w' }) S  V, L, b( |    xor     di,di
; |1 ~& l2 W$ U# Z: O* R    mov     es,di# F6 j. S  L" [7 n; P9 b
    mov     ax, 1684h       1 K! L. K5 d5 q
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
+ c, X1 o0 |6 @  O+ I/ y    int     2fh
+ C: N- r7 E% C, v5 S$ `6 [    mov     ax, es          ; ES:DI -&gt; VxD API entry point
: e( ^, _0 k* L* k0 M    add     ax, di5 M4 m0 b3 H: R  |
    test    ax,ax
! U# J0 u4 L4 h; [; m- E    jnz     SoftICE_Detected
$ {! D, l1 L/ b+ }7 H
( T5 F  W  a2 a7 {7 ?__________________________________________________________________________; l7 B( O  h4 ^

5 s8 I" a8 U! |: P
8 d* N1 O/ p9 z1 B3 s- J6 VMethod 05
4 Q& M) l& Z4 k6 n5 [=========
2 `2 g7 O7 K7 l. j& e, j9 T' R) f% f5 i, d5 G/ y7 U
Method seeking the 'magic number' 0F386h returned (in ax) by all system
; [; |4 o. v' Z- T2 B$ a' i9 A: f7 e6 Gdebugger. It calls the int 41h, function 4Fh.
0 T+ J# p  n, _There are several alternatives.  * f# b6 Y( W- _8 |: {- J( A
8 U8 `( E/ Z  q
The following one is the simplest:% A# o, S( k" i/ h' t7 N

( b" t' `/ W, s% L) R    mov     ax,4fh
& i0 b3 X: Y6 g) r( q# `' M    int     41h
) q0 q; P2 V; x5 m) q, w+ {* H    cmp     ax, 0F386' j6 l: {. p& T" `
    jz      SoftICE_detected) f' u0 K8 R) v

* P8 X6 R# `- C2 q% W, W" _5 Q, t. H0 e) T2 C" M" Z
Next method as well as the following one are 2 examples from Stone's 9 ?3 w2 }3 b% \8 `) ?
"stn-wid.zip" (www.cracking.net):
: Q- e" H% Z+ Z7 V/ P: b4 m  E- u) \+ M& ~# I5 m# J
    mov     bx, cs
% d+ ]& M* Z9 D9 b# M! R    lea     dx, int41handler2
8 t" f% e$ j7 K) z: \9 {' \    xchg    dx, es:[41h*4]1 }9 {. z" f( d' [' A2 y
    xchg    bx, es:[41h*4+2]
# b, v! s8 Y: V3 J0 ~* C) l0 [3 y    mov     ax,4fh
4 Z% Z7 [# F& E+ a+ K& ~! a! o. Z% u3 c    int     41h
2 P2 E! T% \/ l  J& y3 x0 ?    xchg    dx, es:[41h*4]
- T9 R* E+ k4 |- n9 h1 Z* B    xchg    bx, es:[41h*4+2]/ F  y/ [, g1 a- L7 l
    cmp     ax, 0f386h
0 I  b& w* B  }; B0 @- l% u* {/ r; P! P    jz      SoftICE_detected
1 w/ I+ k0 E8 G. J* _- ]) C5 [
' x- z7 X: H' A, S% a9 |int41handler2 PROC
: ~: X" Z4 }$ O& u    iret% f, m7 ^2 a! Z$ s6 `; \& U7 M
int41handler2 ENDP% f6 h  B! o! Y  [0 C
# b( E6 `8 ^2 p1 x4 P( g
( Z: t! B5 I% m7 R: b3 B1 `
_________________________________________________________________________" [; X% @. o# r

6 N, r& i$ Y* o7 G/ ~* y3 o3 @+ p) r0 f- g& M1 N0 p! l  ^  u
Method 060 P+ d" H7 s/ z+ M$ q
=========3 {/ I* R7 y/ r" V* s

6 |/ ^" w5 k* K, t7 O# [
+ Y$ C) O; L  S3 q, E: V- f2 x% p6 E2nd method similar to the preceding one but more difficult to detect:
$ i. P$ W9 ]+ h. L( S: X
# V1 D/ X; G. q+ a* O; X/ F& b% Y$ T, q1 T; b0 U2 f  A
int41handler PROC5 r* F1 k  L* O3 g/ p& B
    mov     cl,al
6 D4 y$ j4 r# B1 |* V2 B    iret# W9 ~  W- S* z
int41handler ENDP
6 Y0 p( }  m5 T! M, i, v8 w$ W" U5 Y) K( t+ ^" ]* ~- L8 X) w

0 X0 [5 L$ w- ~2 ?# E4 T    xor     ax,ax2 u  h5 s/ U* L4 S2 Q4 S8 b
    mov     es,ax/ |5 D5 R% M" g2 s5 i! A7 x7 M( j
    mov     bx, cs
: \5 K( l! |- d    lea     dx, int41handler7 I8 j9 q+ X  c6 G
    xchg    dx, es:[41h*4]
; {' a/ m" v3 t    xchg    bx, es:[41h*4+2]2 t$ h* d' h% ?; r- R" p% L
    in      al, 40h  Q0 U+ u! {! l& D9 p& r
    xor     cx,cx9 X) y) x* j6 d  p! m3 K
    int     41h% i* m: ?6 Y6 C$ n: ~6 t
    xchg    dx, es:[41h*4]
% g: B; z# q( s& _  p: U    xchg    bx, es:[41h*4+2]8 B( {2 }$ ^6 T1 ]; a, ]  m& C
    cmp     cl,al
' K' u6 ^$ b- o( ]/ d' ]    jnz     SoftICE_detected+ ~9 C9 X9 C% }" N2 \
6 E) \" Q9 j# I# X3 r0 d
_________________________________________________________________________  N. v8 \* Z) k& p3 M5 T

* X- Y9 }% a. j6 ]: K+ KMethod 07* C( B  F9 d/ i2 N$ }3 W6 {( K
=========
- ^& ~* x4 [. L# w4 d; Y0 W, u9 E3 F$ K0 K! `8 y) e
Method of detection of the WinICE handler in the int68h (V86): x. C. f, S4 x/ g
+ u6 X( _3 N5 `
    mov     ah,43h7 s2 d* u4 B1 f
    int     68h" I2 U. l' w1 R% c3 y
    cmp     ax,0F386h$ I, F" \- @5 p, Y/ s9 O' _, T
    jz      SoftICE_Detected; F3 C2 [2 N2 F( b

, A0 f0 _1 b' m; h: Y1 Q0 d5 O! r  s2 T
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit* ^8 G! V7 X) j8 R9 v
   app like this:" l: v: h! v& i2 A4 `, {- u- w/ k
* P4 m, D* ]% F) f" n9 j+ i2 y
   BPX exec_int if ax==685 h% f6 E. h! K+ z# [' T. a
   (function called is located at byte ptr [ebp+1Dh] and client eip is
" v( W. m2 R0 Q; f% @, S0 f   located at [ebp+48h] for 32Bit apps)
# o% U! N5 f$ @( h! {__________________________________________________________________________
; l3 V8 p  z1 y* D0 G" t& K& M8 g; D& Z" K0 A: ^. c. r9 i
. x; e* r2 p- N3 h8 q, k0 s
Method 08
) X. t7 h& b, J6 f0 [6 {=========8 P. t1 j/ Y- e+ U0 k' x

- t2 `% b! v3 b) KIt is not a method of detection of SoftICE but a possibility to crash the2 Z/ e" @% W: j3 R5 D
system by intercepting int 01h and int 03h and redirecting them to another$ a/ N% _  o8 D# c
routine.
/ h. E7 D% o3 Z  g, ~7 ?1 RIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points  @" N/ N' a4 R$ z  x$ ?3 d, S. F
to the new routine to execute (hangs computer...)6 f2 W  O" T: y1 H; ]* D7 i/ B4 \

( n+ r2 X& \$ x' D    mov     ah, 25h
9 Z8 T, L- u# T/ H' D    mov     al, Int_Number (01h or 03h)3 v. Y4 e7 Z! M7 ^- C
    mov     dx, offset New_Int_Routine$ l/ Y3 E: v" G
    int     21h0 u) n, C8 ?3 M, A9 H2 q2 F) ?" r  O; g

; U% ^/ ?# e. G  t: T6 I__________________________________________________________________________
/ R9 P/ Y6 t3 B$ i# a. I! `
2 M" \+ i2 F3 zMethod 09" h4 h  f' I# x* m
=========
8 s$ }* b7 q5 D3 Z' a1 ]% D& e' C. M' g! {" D" y
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
) N& z) a9 ?! I4 B$ Operformed in ring0 (VxD or a ring3 app using the VxdCall)., Z) Q' n  s" x& n
The Get_DDB service is used to determine whether or not a VxD is installed
: [/ X) H$ H% }( T+ ~0 Q9 Lfor the specified device and returns a Device Description Block (in ecx) for
# o7 X- i' }( |* _' v0 Vthat device if it is installed.- J/ j9 u: L) q. O8 O
, c: h" W% `- e- F
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID& u& ?7 W" Y: _
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
, i% i4 H8 a0 k! ]. o   VMMCall Get_DDB# M) G$ h8 [4 X) a3 E
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
% C5 T1 l9 b6 ]% }+ x8 Y5 n* U( n% Y
Note as well that you can easily detect this method with SoftICE:1 p6 ?! s8 k9 q8 U8 ?
   bpx Get_DDB if ax==0202 || ax==7a5fh
+ H  x" y3 I6 ~! {( J8 K& V+ w! T% x( |
__________________________________________________________________________
! `% k' O) Y5 c/ N0 u
( u* c  l; W: c& xMethod 10  V: z. K* |1 H+ A# L7 l& _6 n
=========
# {2 v9 A4 P4 H% u( ]+ ]
* U" `) m; E% t: k8 Z( }/ B- L; W=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with& ?0 ^5 q7 i  D/ L4 K! {; K
  SoftICE while the option is enable!!2 Q2 w, e# R! P' K6 q* }% F

! R/ B3 r( \/ K6 G6 r$ I! wThis trick is very efficient:3 \3 ~' K. j$ P* q) ^2 @6 T
by checking the Debug Registers, you can detect if SoftICE is loaded3 O# W3 C7 ?$ ?3 f! X" G
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if) |: w# E  P, H% |8 j$ ~) j3 h
there are some memory breakpoints set (dr0 to dr3) simply by reading their7 B, F* S9 S1 n$ h1 m: c6 i2 b: v+ D
value (in ring0 only). Values can be manipulated and or changed as well
+ m$ v" C0 d! z+ ^6 q(clearing BPMs for instance)) X. A2 V  g; n3 [. p2 y

0 f; G, U" {4 ?% v__________________________________________________________________________
% d+ F  Q* S! T: ]; }& s# Y% n- m" \' l$ Q* J& f+ k
Method 11
- A' [* a6 E- Y; |8 k=========
7 Q+ A  k2 b  n9 z5 K7 e! B! E/ i$ ^2 b! T- p! k
This method is most known as 'MeltICE' because it has been freely distributed
7 e& p& X9 u, f6 ?3 Rvia www.winfiles.com. However it was first used by NuMega people to allow+ i* }% c: U  U2 Y
Symbol Loader to check if SoftICE was active or not (the code is located" O  v; \  A# B! _+ |! M$ W
inside nmtrans.dll).1 p. @2 o, o5 u

: O( A& A$ o/ E9 hThe way it works is very simple:/ ]. o8 D+ }/ f- a9 C& h! K* y1 [
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
3 ^6 w0 T3 `( q  kWinNT) with the CreateFileA API.1 K9 Z. i# [% v8 y9 B" }
6 R7 P1 B0 T6 M2 b3 t; O0 a, r) {, A( v
Here is a sample (checking for 'SICE'):) b2 v' O$ U& u

( `" s3 C9 ]; }: I. cBOOL IsSoftIce95Loaded()
. [3 f6 N2 K3 Z{
  V0 {' M1 d9 {0 |  J5 L0 T, Q9 u   HANDLE hFile;  2 r5 h, G. X0 I2 P6 v8 @
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
' {) c7 \; |: p4 V/ \( n3 e0 h+ Q                      FILE_SHARE_READ | FILE_SHARE_WRITE,4 u4 K3 T' E! H( P1 ?/ r5 [. P
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);: ?3 ]7 [# g, Q( W6 r* {, O/ l
   if( hFile != INVALID_HANDLE_VALUE )
2 ?1 k, W! u1 d! }# A  S: u: b   {! N7 }0 g3 T  _4 c) Q! m+ ^7 C
      CloseHandle(hFile);
) P" p# A+ \, w* Z2 V      return TRUE;
/ ^! W$ t9 e7 c   }+ v+ J( F  v1 ?
   return FALSE;
8 F9 D5 w2 G4 ~! z  ]' R8 U# N) F}
7 T, n; p9 Y' ~9 c  @! `' w) j, u: ]/ N+ t9 _9 A  K, L
Although this trick calls the CreateFileA function, don't even expect to be
2 l5 |5 o  ?6 Uable to intercept it by installing a IFS hook: it will not work, no way!$ _! D5 [( Z  ~! M% a
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
6 ^' y5 Y5 T' f$ h) W& o; h: Hservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function); |* p$ S7 c. X' o. c
and then browse the DDB list until it find the VxD and its DDB_Control_Proc# p+ o1 A! ^8 G. ?5 ]1 V
field.
7 b' r' S5 O' ~, g1 h3 TIn fact, its purpose is not to load/unload VxDs but only to send a . @# y) B6 @% x
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE). c: I2 k, B  P6 N. i  d  M
to the VxD Control_Dispatch proc (how the hell a shareware soft could try: j3 G1 P/ H' I0 n
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
4 B5 B( M, }6 n/ fIf the VxD is loaded, it will always clear eax and the Carry flag to allow
5 U  E) O* f* ?its handle to be opened and then, will be detected.3 w" ~  v6 m2 |3 p( a' Z1 V, N
You can check that simply by hooking Winice.exe control proc entry point
! H- x' Z! s5 wwhile running MeltICE.
1 @/ w) L$ k; T5 v! J. k) ^5 U0 o& ^- y! Q& d
+ ~; e& X; s9 E; F, U' F
  00401067:  push      00402025    ; \\.\SICE- a+ a. q  k% r. J, V- h
  0040106C:  call      CreateFileA! |7 q8 V& l' I7 S
  00401071:  cmp       eax,-001
0 d* [3 Z3 }5 l- g, D" {. c- r( F  00401074:  je        00401091
- K0 U- T1 I5 n: A4 E* Q2 n" L

# K5 i* q# e* O1 r- xThere could be hundreds of BPX you could use to detect this trick.4 q$ W1 C' p$ r7 j' [- j
-The most classical one is:. p2 N' X% ?4 Y9 w* m1 f; t
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||% R  i7 C6 F3 x* y
    *(esp-&gt;4+4)=='NTIC'$ w, x/ m* T  z0 I) Z" k2 x

" y; S$ N! D+ X  \" u-The most exotic ones (could be very slooooow :-(1 ?/ t0 p2 y9 U9 L* o/ L/ |! N7 b6 @
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  " _! {. c; H% B, X3 P
     ;will break 3 times :-(- r& ~0 ]5 \& ~* a4 U% P* \
$ Y1 b+ k3 M7 t+ M3 w
-or (a bit) faster:
* b# k9 V& H3 B7 h) C   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')) d' W7 ]7 I' O! }6 I6 P# T( L5 @
. p0 Q# o0 l( p" ~; B
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
+ h1 i+ ^$ w- A; T) {4 J     ;will break 3 times :-(0 {) g& Z0 @) q9 B7 S  p2 F
) t, \# c) S/ m) X* \/ j
-Much faster:5 W9 R5 ]4 Y, |, ~& F
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'% _! d' P, o/ z/ B; V

5 h( T9 |9 m' E1 uNote also that some programs (like AZPR3.00) use de old 16-bit _lopen4 E1 @/ Y* Y1 T) c. [; H
function to do the same job:
9 O7 g; _  J" ~$ V0 M4 w5 Q6 [; V  h$ ~+ G# A8 W
   push    00                        ; OF_READ
2 \7 S" u; J$ N8 [5 `   mov     eax,[00656634]            ; '\\.\SICE',0
# @& \+ {9 ^, E( t: w1 H   push    eax, y# I: q4 `- O1 }2 x
   call    KERNEL32!_lopen
& Y: J  w" @+ }- k   inc     eax9 H2 C) E  m( L: @( I0 n. y
   jnz     00650589                  ; detected
( u/ [/ d, C" f; |' C   push    00                        ; OF_READ5 {& ?3 J0 u* c' D  |0 a' P, @* N/ _
   mov     eax,[00656638]            ; '\\.\SICE') F. X, o4 T- y8 L% s- ^& P9 y
   push    eax
6 P0 V( P( E; r9 L' m- d, R   call    KERNEL32!_lopen
" q+ \! a* H9 J' C8 t7 O' D   inc     eax3 V# n% N( }! n: n
   jz      006505ae                  ; not detected
% e% g5 a2 j5 }
+ P6 l- B& n5 y! l, }
) ?% G8 _% K% R# D2 l__________________________________________________________________________' Q& X+ w3 l* S# G0 P  D. l3 f

& ]7 ?3 s- I( Q+ wMethod 12, ?4 W% u/ }5 y, w
=========
. U& s  X9 Q" J( `% e% v, m$ @3 j; I* m5 f
This trick is similar to int41h/4fh Debugger installation check (code 05
. F- x* r: k( o4 Z: a$ y6 W5 d1 o&amp; 06) but very limited because it's only available for Win95/98 (not NT): ~5 }* Z& T$ G0 O
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
( B+ K' _% Z; S) n( `, j% D! {/ ?1 d) a7 _' y: @, f
   push  0000004fh         ; function 4fh# P% \2 ?# s( V6 F) O1 O0 v
   push  002a002ah         ; high word specifies which VxD (VWIN32)! _& [: H4 m. G# Z' Q
                           ; low word specifies which service
  s. z% k. l5 _% H) |                             (VWIN32_Int41Dispatch)
6 v: o8 S& g* b   call  Kernel32!ORD_001  ; VxdCall: H7 @& t2 |6 |# v
   cmp   ax, 0f386h        ; magic number returned by system debuggers
( z1 {7 U" B8 E3 G- U! o   jz    SoftICE_detected
  u5 W+ u7 v# K% C* ^
& m" f3 {& E, q% u. d, c% e" E5 HHere again, several ways to detect it:. y. g5 `( C1 N, @8 n8 O* V" V

0 S" m/ a  i0 X% B! c( U4 a1 T    BPINT 41 if ax==4f; u: A. t# S9 R" a# h
3 x/ X6 T/ d  u! K4 ?) s+ X; B
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
6 D1 Q; I1 j$ B6 M4 W. g* @
/ g5 O8 _' [$ T    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
/ z+ Y& t* m$ R: \" Z4 s0 m+ ]6 W! F4 E* A; o
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
$ I) M9 Q9 i# V/ B* [& o2 J" x; z5 f$ B: ?) R* K' d" y
__________________________________________________________________________
+ M# ?% v1 g9 U# e& v: o4 O$ c/ p% U7 H( s0 M' j
Method 13
5 V* L5 M! }9 h=========
( C2 x1 f; r0 D( U: ?' M% Q* i$ B3 e9 o0 |- t$ j+ u; x& C6 t
Not a real method of detection, but a good way to know if SoftICE is
) l2 g, O& R2 s* g7 W% V: @* F) Minstalled on a computer and to locate its installation directory.
# l: z  B9 C- [/ \, AIt is used by few softs which access the following registry keys (usually #2) :
7 j' j1 R( _. w* S# g6 _# q, G$ L  I/ R9 y
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion/ P: r6 ?! b) G, b2 u# [
\Uninstall\SoftICE
' z- `7 L" |* f1 G-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
0 l' k# J6 j+ t: g; I-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion$ A3 j* _# I' D  a
\App Paths\Loader32.Exe
8 e5 u+ X  d1 n- y: q8 i* Z: N/ S( x7 l* E5 o
; e. F' @' F+ q7 l/ _
Note that some nasty apps could then erase all files from SoftICE directory
. ?! U- K3 |/ D(I faced that once :-(  m; ~$ F7 p; Z% E

9 u: _. }+ j7 f" h% `Useful breakpoint to detect it:
1 h8 j: F, T: m' @0 w+ A9 t3 r2 _
6 b6 F" T2 w- X, h. G7 z4 x6 z     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'( c% w1 @/ p- G. B
5 `, t6 c! V1 K0 q4 {
__________________________________________________________________________
- f9 [' H! ?) P$ [5 O, t3 \
4 E3 {; C0 G, G' x1 Z# C) [
; T! e( c9 I! l, D3 i, L8 p8 j; g/ ]5 bMethod 14 / q& ^8 e+ j$ ]0 }3 o2 ~
=========& @  N9 M7 n0 p! B
: D/ _+ N; X* _+ G# }
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose" r/ ~! c; ]2 l
is to determines whether a debugger is running on your system (ring0 only).
6 n# m/ \$ A/ K$ Z" M8 K
; {- E8 E) R, O& L4 o. \; d   VMMCall Test_Debug_Installed) P0 [; F0 }! ?- x# J
   je      not_installed
5 @" A/ [6 L$ A) ~, k( p& ~8 [
0 N: C4 A% ~7 ]* n1 lThis service just checks a flag." i, j! q% U6 L4 E1 k- Z  {
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部