About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
. ]% E9 P0 F4 t3 u0 h* T, d( D& Z<TBODY>
, n3 j7 `* w2 A7 A- O% E<TR>5 c, ~  a2 b2 p& w! t+ b. X
<TD><PRE>Method 01 3 W$ W) z) ?" s) _9 z4 c
=========
: o3 _% f& E; i/ `/ F* w; X- O4 g% `' X8 K% E
This method of detection of SoftICE (as well as the following one) is! c" q/ K( k$ x% K1 S  |
used by the majority of packers/encryptors found on Internet.
5 @; S4 k7 l; R8 kIt seeks the signature of BoundsChecker in SoftICE
7 C1 U( Y! ?1 u2 M9 L2 m5 L- g% f1 r3 J8 T2 i
    mov     ebp, 04243484Bh        ; 'BCHK'
* A! C2 b# [/ P3 U0 r/ E    mov     ax, 04h
& i% r6 x/ M# w% V8 p    int     3       ) M% _6 [6 k3 F+ {( T6 K
    cmp     al,4/ s8 o$ @& k7 c, z  [, W& l  a1 d
    jnz     SoftICE_Detected
0 H9 V/ F: c) m$ V; P2 s, u
0 ^  v) ~( B) i4 a; n___________________________________________________________________________0 @( P- N. L. c. L! c, c5 p

/ |! |) m# A# r5 [  DMethod 02; A: e' e+ J+ a- V
=========
6 C! K( j- I/ q! C( p5 K
/ L$ j7 h( M1 f# v# G6 E+ o7 PStill a method very much used (perhaps the most frequent one).  It is used" d0 a8 c5 D' q# J* V4 b2 O* H
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
; Y* X, v; S: nor execute SoftICE commands...
+ q* T: x. ?- C' G) qIt is also used to crash SoftICE and to force it to execute any commands6 T+ ^2 Z5 t1 D
(HBOOT...) :-((  . D$ Q; n; ~; _3 z" L! T

+ A/ S4 p6 n- w& a6 p5 z8 @Here is a quick description:
) A' j0 d9 C. k  B-AX = 0910h   (Display string in SIce windows)
$ m$ H6 s3 \" E% G0 W  J0 k% F-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)) b- {/ f# {* X* o, }# D
-AX = 0912h   (Get breakpoint infos)* E5 w. N3 B! r
-AX = 0913h   (Set Sice breakpoints), [; ]' l- u4 @0 ~9 F8 p3 M3 ?
-AX = 0914h   (Remove SIce breakoints)( k; h; I3 c: c

# J, Z- \' g: jEach time you'll meet this trick, you'll see:! S% Q) U% x1 I# m( [- t
-SI = 4647h( L) N  O; o* g- J
-DI = 4A4Dh1 K( F; k- U. ^8 h  c3 y6 i; n4 M: D
Which are the 'magic values' used by SoftIce." B. g  r8 g$ @" w$ ^$ M
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
: t! ]+ r# _: }; B& h
( l, r' N$ a8 mHere is one example from the file "Haspinst.exe" which is the dongle HASP
* I; _( ]) r1 p9 l+ gEnvelope utility use to protect DOS applications:
/ s' \1 g3 D* O/ u
6 ?% r: @9 Y- n% s: l# z4 D
8 x; S8 j4 K/ Q0 y, U' Z4C19:0095   MOV    AX,0911  ; execute command.8 F5 k1 \5 w/ p8 \
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).6 _; l  |6 u' j$ ^: J7 m1 O
4C19:009A   MOV    SI,4647  ; 1st magic value.
9 _1 p1 S: q" S0 B4C19:009D   MOV    DI,4A4D  ; 2nd magic value.% c7 J+ L$ ?+ I. h& j9 H' ^
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
  \  D# D! U: F) t/ A( F1 F, Y4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute- W9 L) X3 N& n, H3 P: h2 Q
4C19:00A4   INC    CX
' f7 D, h* u/ t; X9 [' Y4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
3 T: x  [& Y/ F- [, z4C19:00A8   JB     0095     ; 6 different commands.. D, X- s2 d7 m3 J2 k" |
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.3 g1 S% N) k" X: l( A; u/ H  z
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
5 r3 @$ a5 Q& {, g) ~1 q+ Q( u$ `( W7 d1 x% I
The program will execute 6 different SIce commands located at ds:dx, which4 w8 L$ N% j2 B4 I1 i- N/ O
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
) ^- y! V( M9 U
! q0 h7 R( m( p  ]* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.) k/ p1 h$ R, _; b$ N# t
___________________________________________________________________________, e( w, S: W8 |5 v0 F. E
& k8 s" i( g- [1 j8 e

0 ?4 R! |- f6 ^3 FMethod 03
; v6 G7 j! X8 Q6 u# p, e$ z=========: t: n4 z% Z' _4 T
( k% B4 R: |9 I- `! E  T6 y
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
( h, i& t, [; m: ](API Get entry point)
  f/ K4 W( h# g5 e5 C        
. N1 @* c& M9 j3 D: K
: Y' X" Z2 y! b- @( y9 G% U    xor     di,di3 b2 G! [. ]$ u2 l8 X2 [) c
    mov     es,di
; |5 S# K1 h0 h( Q    mov     ax, 1684h       - e  k! q5 e4 j6 c( C* ?4 L  x
    mov     bx, 0202h       ; VxD ID of winice
' Q9 v$ t5 X' }9 ?$ y& V3 p3 i    int     2Fh
: t& q% o/ q  k' O    mov     ax, es          ; ES:DI -&gt; VxD API entry point
: u( t; }0 a/ P! B/ W+ }, n( X+ U    add     ax, di0 u5 o& G8 |( k( r) L9 G( T' M9 j
    test    ax,ax
7 w: R0 R4 [5 v9 F) N  W( ?    jnz     SoftICE_Detected
5 X0 e  f; ]% m- f' o) T
7 Z2 X( @: n: _3 i8 a___________________________________________________________________________% Z, n3 u. n! u) S3 T* y2 G. f, ?
8 W, O! C. `& V9 ~% w
Method 045 \4 s4 \5 @6 ]- ~% p
=========% }# l2 O2 C: i
/ }3 v" X2 H3 j# N. |
Method identical to the preceding one except that it seeks the ID of SoftICE' n: F6 v0 f& u
GFX VxD.
0 y9 {/ B$ t! p3 f5 P  H7 ~
0 p' B: R* n8 L    xor     di,di
& o3 C6 B+ g/ L( U" Z    mov     es,di$ P# u& K) t' o0 C6 f
    mov     ax, 1684h      
8 d5 ^% x; A. E  f* P; t1 I    mov     bx, 7a5Fh       ; VxD ID of SIWVID
* f5 u0 I+ f: E- r  T" g    int     2fh
4 N: X; l+ {6 {0 O& ~% u    mov     ax, es          ; ES:DI -&gt; VxD API entry point( c% D' M# c( ]5 s1 r
    add     ax, di
1 |. ]2 m  B9 H6 x4 B5 G4 {    test    ax,ax
* B9 A  v8 M" B- z4 \    jnz     SoftICE_Detected
' G* |: [; [2 u, L+ K0 K, |
8 T8 J' ]) i, C. ?__________________________________________________________________________# H: h& n# f5 q* \7 b. a1 h

! D3 e4 Y- l, s! U  J$ v' r
: s  G! T& I7 JMethod 05
/ f5 A5 Y8 H- P; o. N! c* a( Z=========, r9 r! \; E" C1 p4 _, w

) J/ v5 @; Y8 }; L+ Z: F9 R4 ^* E- ?Method seeking the 'magic number' 0F386h returned (in ax) by all system6 y8 ?+ F6 t5 E' q3 V# ^7 n* K# P8 w
debugger. It calls the int 41h, function 4Fh.
7 M8 K9 G0 X, R. V# z; `/ h' RThere are several alternatives.  
' V# X6 X* W3 W% }4 f
( r2 B- d* N( X- d7 }4 vThe following one is the simplest:
% X# m, }" k0 w8 ^) H6 k6 u# I9 ]$ P, `, T/ c- u" ~
    mov     ax,4fh6 n4 d0 B9 G, X% p9 \
    int     41h
/ [9 d* n1 l  ]3 n. O    cmp     ax, 0F3860 i3 t* V# z1 U: n, D7 W; R
    jz      SoftICE_detected9 h  b& h9 k' B; t( K
& X7 w# N: C7 P9 u- [/ o; N* Y% a

$ v. Q$ `# z+ V; m, Q% VNext method as well as the following one are 2 examples from Stone's 8 x3 i; u& p- Z4 U9 h2 W
"stn-wid.zip" (www.cracking.net):
0 b" Q) E  ^- Y" {0 v2 ]% Y& N) l2 M! [
    mov     bx, cs
. R5 }( F! }$ z5 _    lea     dx, int41handler2+ M! _! e% {4 _3 n
    xchg    dx, es:[41h*4], R- P8 u7 ~( ^# h3 t6 Y2 k
    xchg    bx, es:[41h*4+2]
+ p" O, z  E1 |/ Q! B1 N    mov     ax,4fh
+ M5 W2 g2 k% i0 B+ b# u    int     41h6 P" g7 z: q$ z
    xchg    dx, es:[41h*4]
' l  C$ r8 C# n) D! n7 q6 `4 U    xchg    bx, es:[41h*4+2]4 y" o& D$ I7 I9 S/ A- x
    cmp     ax, 0f386h
# ~8 @  _! N6 v* A+ K; L9 a    jz      SoftICE_detected' }; Z: u. O: `; B4 G8 p8 X

. g: q- I! H8 f! E9 mint41handler2 PROC
! ?; N$ O% j# r/ S2 F" M9 c  ?9 R, B    iret
' T7 u% H9 Y' g! p# bint41handler2 ENDP9 l! _- U/ [3 K% a# D2 p7 I- P( A
  E6 h4 Z: s# Y# ?

' Y$ S5 k1 n9 J$ \* L) ~_________________________________________________________________________! e0 `2 D& U( M
, n) p& i+ X+ b) }& Z; R

* K4 i2 @8 `6 C! n& j+ y9 X5 fMethod 06, l0 S/ {# q; V( E: h
=========  J/ Y) x2 A" p; _' o
; d" d7 Q6 q2 c. J: ^# x7 R! {
3 z/ q# k+ ~; y9 K
2nd method similar to the preceding one but more difficult to detect:- P8 J( K2 s/ b, ]+ e& E

' r) P3 B6 S2 N4 K' E& J1 N
5 i7 y. M; z0 q3 E6 q  o6 B2 `/ vint41handler PROC; y" w) R5 {- b6 ~  y# c: S
    mov     cl,al7 p1 e8 p! A( P# x2 O/ _
    iret
/ W1 G& C9 C3 @2 N: Cint41handler ENDP" f/ t7 s$ M. P3 L6 `3 g

7 ~4 i8 W( H$ @  N) ]( q" R- ^, M# }: A  G3 Y, ]
    xor     ax,ax3 u1 B: Y/ @' d# n' r5 e5 O3 n
    mov     es,ax
/ G" y4 V7 q$ ~( o1 Z    mov     bx, cs3 ]1 }4 }+ y8 z" u7 X
    lea     dx, int41handler* ?2 i( R+ T$ }% j2 o8 I+ I
    xchg    dx, es:[41h*4]% v6 L5 ~& z4 o" h7 q6 }' S# z
    xchg    bx, es:[41h*4+2]
/ }) x2 ~: m, C    in      al, 40h% R. G! o3 K6 l9 C' S! {0 Z
    xor     cx,cx
6 V3 s& e  q! D    int     41h
9 T. r! |- S  l* c    xchg    dx, es:[41h*4]  M+ e9 r2 @3 F! O- P$ R8 w
    xchg    bx, es:[41h*4+2]: O; z, _- \# D
    cmp     cl,al8 D" B- J& ^1 l2 ]
    jnz     SoftICE_detected
9 N! r. x* ^/ D% p0 u
# ?8 k9 @! u- y( v. H. {# X) _% R_________________________________________________________________________* P6 x/ L$ N; l" z! z7 {; z0 i4 C2 G
1 A6 u/ j( o$ T  n& I; V: k4 M
Method 07
' j/ I  F3 @$ B- l: q% }3 |=========8 F+ @5 j+ N8 Z0 n' Z

) b& z" A' A5 mMethod of detection of the WinICE handler in the int68h (V86)' ~9 J% ~- @8 V4 |$ s1 M
' C& U; G3 `* R/ W7 p4 C
    mov     ah,43h
* f# {6 d8 t' h6 Z2 l0 P! i    int     68h/ M" O5 l- o" {9 I" Z& C* N
    cmp     ax,0F386h6 d: I* D7 G3 G2 f9 E, {+ Y
    jz      SoftICE_Detected
- k, v( k; }/ N$ N4 {
, F! n' s& f4 r, S) p/ F
) n; J  T+ u. `# o) o) w% v% Y4 D=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit# A2 j- v- x1 X: w
   app like this:6 P( A$ u/ }" L) Z

* b0 ^- r1 D! `) m   BPX exec_int if ax==68
, c1 [8 d6 d1 Z! v  j4 ~/ M   (function called is located at byte ptr [ebp+1Dh] and client eip is
- {6 n$ w% |8 v: V  t( G2 a   located at [ebp+48h] for 32Bit apps)' i' c6 O8 |. m: P5 y
__________________________________________________________________________
5 `1 Z& l8 \' }0 X$ _; X7 C9 W8 H$ ?" I! ^! W
3 o$ y7 \  P" g, y, C* s
Method 08% s3 B5 W8 x" {; N7 l# t3 R8 a1 ?
=========
: Q& s2 s4 d" A6 @* z2 Z
; @( \4 C1 t- H4 O/ M. M, M1 H$ w: r9 e( WIt is not a method of detection of SoftICE but a possibility to crash the. ?. U& L" i  N: ^
system by intercepting int 01h and int 03h and redirecting them to another# t7 H. R; Y8 v% X. z1 q7 G
routine.$ C5 C7 e' G' P6 @3 v" c
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
/ w9 R7 t5 W, H+ s  L1 `to the new routine to execute (hangs computer...)
& _! n+ |3 p  Y+ k
% ^4 R* S2 ^9 Z% J: E; w( B& |    mov     ah, 25h4 u2 U2 k) d$ W( M2 R* P
    mov     al, Int_Number (01h or 03h)% j  ~8 X6 h: ?; L# [( x: q
    mov     dx, offset New_Int_Routine
7 K2 X, ~* x& K2 t- R- D# V    int     21h# ^0 ?$ T5 `: p: C* o2 k% M

9 P7 A) |* S5 g$ u__________________________________________________________________________
! R- ?4 k" Q" }+ b. A" Z' I, s
2 K, p' H/ f8 q# SMethod 09
( h9 ~/ Z; s3 Z! i=========
& Q4 D& b2 w: z) R  H; c+ u2 r5 T' L+ q
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only3 n# H$ b3 e, y% f
performed in ring0 (VxD or a ring3 app using the VxdCall).6 `! C* W+ n* e0 q
The Get_DDB service is used to determine whether or not a VxD is installed! t- d" r" ^# Z4 v2 b2 F7 m
for the specified device and returns a Device Description Block (in ecx) for
4 s: w- W4 o8 k2 Jthat device if it is installed.
: Z) ^# B" `7 F' I5 i# E. V" {9 s& m+ D, u/ D7 I  ~
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
+ n* c9 ?' D5 Y: U) ?   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
8 ~# G% ]6 W: \: `+ c( n7 c8 b% \9 ~   VMMCall Get_DDB
) p) I$ A, B- A" O) W   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed" x; h& F3 \+ ^8 c3 B
) Q# G3 ^! v* F9 t/ i
Note as well that you can easily detect this method with SoftICE:+ R2 U6 ], V$ R/ e# p: @. ]% n
   bpx Get_DDB if ax==0202 || ax==7a5fh
1 L" [6 W. x# M! ?0 G. o, z9 i8 B2 `) w: S6 n8 Y5 J
__________________________________________________________________________& F: i7 i5 T/ o& i
( ~; e# I5 i. y" ?- b
Method 10- [, [. \. _6 n* S2 j
=========
4 w- J. \7 w5 g- O8 f% W
* S* i' H1 B0 j=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with2 A1 ^  u' Y, R" V( x
  SoftICE while the option is enable!!9 F5 c3 e6 h+ U% `
; @) n8 p/ K3 x( _* x$ h0 |. l- \0 C( H
This trick is very efficient:) P+ e3 x% P/ K$ c
by checking the Debug Registers, you can detect if SoftICE is loaded3 C# u0 g6 S* [  \
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
6 d/ j7 [, j, D9 Sthere are some memory breakpoints set (dr0 to dr3) simply by reading their% @; ^. D2 D- ~6 u! t8 t+ [6 M( z
value (in ring0 only). Values can be manipulated and or changed as well& H5 O4 V( o5 l8 ?5 v% f$ L# D
(clearing BPMs for instance)
4 d. A" Y9 \9 \( j& g0 O3 O
) q& o/ T# T4 w3 D5 M5 |1 m. u) F& h! Y__________________________________________________________________________0 C* @1 a9 s- O) j& ~3 Z0 z

. D0 k5 [# C3 y# o2 qMethod 11$ A7 Z$ N2 Z0 j3 t  ^
=========! j# h& G/ S7 R% P) t
" ~1 k3 f' E! G
This method is most known as 'MeltICE' because it has been freely distributed- [  n; L0 I, `+ D0 v* c2 m! A5 N9 K
via www.winfiles.com. However it was first used by NuMega people to allow: J. y7 y) G& Q/ P3 c! O# Y1 M! T
Symbol Loader to check if SoftICE was active or not (the code is located
8 g/ _( T% u+ l5 X" Dinside nmtrans.dll)." r& a% t2 Z5 \& a
5 H5 G0 T' I8 J+ H2 Q
The way it works is very simple:
4 M7 @2 [/ E- ]  ?/ hIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
" N! D/ x# K0 Q1 _WinNT) with the CreateFileA API.
' t* ]) F! |# b0 ^2 `' C' v0 |+ |! J, _' H) u- D
Here is a sample (checking for 'SICE'):
& b2 M2 [5 E' |$ t2 |/ d) M+ _# @  b% x' \/ P" V
BOOL IsSoftIce95Loaded()
; w3 V/ D; \3 w{
& _) F$ g9 v$ U* r3 W# X% \3 e   HANDLE hFile;  3 n' ~. ~/ ^/ a) v3 A
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,+ O- r6 ]1 c1 h: G
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
; D3 a0 f, }" X5 E7 w3 }                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);2 f1 @  B- Y! o0 ?- F9 }  s
   if( hFile != INVALID_HANDLE_VALUE )- Z# W9 E* X; q+ B8 ~/ H' q
   {
7 a2 N$ F& b: I8 Y; Q8 h      CloseHandle(hFile);
0 s8 \8 w5 T  }9 V5 z. Y7 h      return TRUE;
3 F0 b' B' Y! s8 y) A   }
; c. q7 |% G7 l* X1 d   return FALSE;1 P7 n8 H2 Y) Y; v1 K( `3 Q  U
}
' q  X- t/ x3 y+ c) N8 @4 o. ~/ a$ E* Y% t$ J9 Y$ @' ]
Although this trick calls the CreateFileA function, don't even expect to be- x+ k  w/ t; w
able to intercept it by installing a IFS hook: it will not work, no way!5 k4 i& P2 T+ j. ^4 e3 Y& l8 z% }! G
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
5 ~* q" d- F+ f! y- q% R4 eservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)9 Y. |% P* \; E3 D
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
3 K- _  V& x0 Kfield.  d0 N# W- t; u6 T0 s0 t
In fact, its purpose is not to load/unload VxDs but only to send a . S8 X, g* P# B1 H# j
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
8 ?" M1 v" ]1 K8 a, k, B1 `3 N. ato the VxD Control_Dispatch proc (how the hell a shareware soft could try
, f/ l- h2 P8 ~5 k* gto load/unload a non-dynamically loadable driver such as SoftICE ;-).0 F7 I( q$ R) _* F
If the VxD is loaded, it will always clear eax and the Carry flag to allow/ A+ h+ E" Q0 x& g2 M
its handle to be opened and then, will be detected.
/ D% Q3 H6 |0 O7 L& o) LYou can check that simply by hooking Winice.exe control proc entry point" `" s8 o/ I1 o: P6 b! |
while running MeltICE.
: P/ _1 D& E& F$ c
3 j7 \2 j- A4 q5 q0 J8 p$ M! G0 H6 d! N- K
  00401067:  push      00402025    ; \\.\SICE( E/ E0 _. r& j
  0040106C:  call      CreateFileA
) V" f. Q, S1 U; x9 K4 L, d  00401071:  cmp       eax,-001+ K( K! W* M# L. X7 B8 R: v( m
  00401074:  je        00401091
9 b2 f6 S% G- p2 l& e: z- l
9 W1 M# b$ q: Z' o% a& v2 `; _& y
0 U- A9 c3 A3 R5 oThere could be hundreds of BPX you could use to detect this trick.
0 |; j8 \6 b1 t-The most classical one is:
) S9 q2 I4 X+ n2 E' B  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
+ i0 m. A/ Y" Z1 c    *(esp-&gt;4+4)=='NTIC'9 v/ W6 R; C. ~" V- S

; k: _/ ~* M3 C& V& w$ J/ ^% G-The most exotic ones (could be very slooooow :-(
& |6 W, ?# N0 y7 V   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  : o: u  B7 H" `9 l6 r6 _
     ;will break 3 times :-(
6 e: X% R$ Y- a0 {, Z9 c2 ]
' N' y. n5 X( n$ ?-or (a bit) faster:
1 a! f% {0 ?1 E8 s1 m   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
8 `" F1 {+ f" t! t. \* G0 ^' ^& ~6 a- U* f9 b3 C3 O& }
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  , e5 \# F- ~/ x7 W+ f  W
     ;will break 3 times :-(# z1 o0 o/ w3 U2 W8 [/ a+ _
0 S  Q& y/ ~- S7 `' m) k( R& U. R
-Much faster:
, I8 w3 A8 E9 i   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'( e- L( R6 S, ~: ^6 x3 {7 A

1 C3 k4 s* S1 J! W$ ^4 ZNote also that some programs (like AZPR3.00) use de old 16-bit _lopen
/ k1 e% t$ ]2 @0 Z& T& Afunction to do the same job:
/ F3 @1 X1 m* G- H1 t
4 N  B5 e3 z% ^* f   push    00                        ; OF_READ3 V: c: L& V  S1 l
   mov     eax,[00656634]            ; '\\.\SICE',0: p! T  S+ J4 s2 r* O
   push    eax
) X' [! Q' n4 R& |0 F1 P   call    KERNEL32!_lopen
) j* l6 n& @$ B, s( g7 y7 `, o3 B   inc     eax1 J0 r2 v& R# \) T
   jnz     00650589                  ; detected
( V& [$ `2 _( Q- D% \# T! @$ c# U5 X   push    00                        ; OF_READ, V2 ^9 |& m: Y5 e! p
   mov     eax,[00656638]            ; '\\.\SICE'9 q9 N; s* l% w2 [9 W
   push    eax% O  {* u0 l8 h/ {2 g
   call    KERNEL32!_lopen) x; c! d: x1 Z: A( i
   inc     eax
8 J4 b. q2 E+ P4 _   jz      006505ae                  ; not detected
1 E; p  j. l  g% ^/ o, K) ~
7 d0 y) c0 m- E- H% H2 P6 l& }1 B
__________________________________________________________________________
+ K$ j$ Y6 u8 a' n
8 H: Q$ r1 t9 Y$ _& f8 I  YMethod 12
* M( ]( F/ ?3 S+ q) f" x8 s7 Q+ p) _=========
. l9 H5 c; g/ ?% M' O+ r- }$ O2 C& ]! l- W% }
This trick is similar to int41h/4fh Debugger installation check (code 05
* W0 L. r; I" G" O& G: A3 j&amp; 06) but very limited because it's only available for Win95/98 (not NT)& [7 m3 F: t! Z( N  m  z3 o+ z
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.! d& O3 ~2 Z8 X$ q
  \3 i7 m* o) e+ Z- t" l( S
   push  0000004fh         ; function 4fh( F2 d9 I7 P, R- h& s
   push  002a002ah         ; high word specifies which VxD (VWIN32); I/ F9 r$ v6 W$ f0 P) E' |
                           ; low word specifies which service
- P# o/ X) s6 p% K                             (VWIN32_Int41Dispatch)
9 I. p6 ^0 b+ Y* ~. L. N7 o$ z- a   call  Kernel32!ORD_001  ; VxdCall
6 i9 [! S$ c  T& S$ p1 C5 _: O/ z   cmp   ax, 0f386h        ; magic number returned by system debuggers! W- Z& F! k; [
   jz    SoftICE_detected
( r7 ]5 H0 b4 l) t% h; H* y; ]* y( T
Here again, several ways to detect it:! u1 C/ C1 Z* {* A  S! Z! N- q" e: C" z
. }; t  c) ]' r) N# |. ]/ b
    BPINT 41 if ax==4f
  X6 F: U: g: d# R
7 M' D2 N" I0 E! |8 [( H" v* ?    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
: E. R" ^3 z2 b1 Y; e3 M& _
  @$ Q1 I5 ^4 ]9 Q' q3 }    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A, @, e: `9 d5 J$ ]9 a# W2 p# q% A. S

# s" x+ w" x, x2 R9 l% l, R! l" c    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
7 ], E3 ^0 e7 E; V. Q: t
5 ^  A3 U0 Q0 u) l! j__________________________________________________________________________
! ^5 A& v* V6 V( p( r- H0 y* Y( ~" S& s, k+ V
Method 13
6 H; P  A$ m% E1 e+ l. Z8 V=========
0 r; E, H; Y1 E! e+ Q% t$ ~: X; {
3 `" V6 Q7 ^1 lNot a real method of detection, but a good way to know if SoftICE is9 P" ?- n4 W# j) B- ~
installed on a computer and to locate its installation directory.
6 k7 Q1 ]: V7 o5 pIt is used by few softs which access the following registry keys (usually #2) :
; m, n; w3 w0 [" U( `9 A/ v4 R1 w6 ~/ ^+ n( f( P& R+ M1 l: M
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion) _' ~/ Z, j1 m
\Uninstall\SoftICE, W  @- ~; [& r
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE3 S, v3 [+ B5 ?7 p; ^
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
' \" ~* r: ~3 o4 Q" c\App Paths\Loader32.Exe/ U/ h/ Z7 h/ p1 t8 V* s

6 r: B  O7 D( M& U8 x6 Z  R$ K! u1 j% R7 P5 m; `4 c: O
Note that some nasty apps could then erase all files from SoftICE directory+ u0 y2 b& [2 Q; J3 {# s$ U! I
(I faced that once :-(% B; e: G$ t0 u: f

. n( F& E% C& s  W0 z- m. @+ rUseful breakpoint to detect it:
2 c. P$ V8 s2 r$ t$ k" W7 _( {! k8 v- E8 L
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
( @" e( N5 s) r4 i/ G& c5 |# `" a6 i
__________________________________________________________________________
) M3 i& J6 O9 u$ I% {% l5 I# h3 |+ U$ g+ s
; h! Y# J" |' Y8 n
Method 14
7 m' b2 V  b+ o: F=========
8 o! h* `2 T# i& f0 Y: B9 Y* U, L% X; @& R0 F( x
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose2 ?/ J! d( U# ]: p4 {) P
is to determines whether a debugger is running on your system (ring0 only).. {, y% P2 W0 N2 A0 d! W

" I3 j) j6 b4 |  `/ p1 w   VMMCall Test_Debug_Installed
. Z- N/ D9 K3 r6 ?4 p6 Q+ ^+ c5 s   je      not_installed' F; l* M- Y1 R, J( [
- o& A& a1 a0 d# `% ]3 h
This service just checks a flag.
2 n; Y! Q, L; b1 x6 P0 {</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部