About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
5 n7 j' u7 y! G5 t4 z<TBODY>& J' K3 D- s/ M# P0 t# y5 v- i1 a
<TR>, C! B- O; |5 z6 ]' g
<TD><PRE>Method 01
4 D) {6 R0 _$ W- J9 }- @2 s# a=========
# R' _& N) d# [7 a. A5 x
/ ]/ C# ~* X& {. P& \% BThis method of detection of SoftICE (as well as the following one) is
7 }! L! V$ B2 P& R! Fused by the majority of packers/encryptors found on Internet.
) l" X' R  H$ W% t3 XIt seeks the signature of BoundsChecker in SoftICE: n9 j! b) U+ z
! l9 C) _/ O. @4 ^8 \; g5 p+ j7 J$ E
    mov     ebp, 04243484Bh        ; 'BCHK'& P$ K* X6 Q. B5 @0 u6 c% `
    mov     ax, 04h' t0 [3 t0 h4 G! w; I$ B6 W
    int     3       6 ]  T1 L( c+ K1 v- f. ]9 R: K
    cmp     al,4
' |  b& I0 ^' [; Y/ h( p& y+ \    jnz     SoftICE_Detected
; j5 s- `" |9 _9 u" C2 o, x% D/ W2 m( |1 H" Y7 z5 K) m1 o5 x3 t' t
___________________________________________________________________________. X( g* ^4 C* E' X
9 h" l" J2 w' [5 J
Method 02& L4 E: ]) L! T5 z7 @
=========# r8 W0 f7 d3 ^6 [) S
- {5 ]- O" {- y$ H8 Q- w, u
Still a method very much used (perhaps the most frequent one).  It is used
2 T6 S& f$ z# X( n( z) Q; n! pto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
- r' I  [# O3 c1 f7 yor execute SoftICE commands...
. c9 x' N. H/ g2 [. o9 h5 D+ d: ^It is also used to crash SoftICE and to force it to execute any commands6 r! c2 G+ d" `! H
(HBOOT...) :-((  # s2 o0 Z5 g' M$ t0 o
5 V$ |  M6 D6 _0 T& L6 q
Here is a quick description:+ w1 |" z2 Y9 R. C" J4 `
-AX = 0910h   (Display string in SIce windows)  k* r/ [' u6 N, E( B. R4 E
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
4 y( x! [6 m8 A-AX = 0912h   (Get breakpoint infos)
1 Z# ?  k" H  _- U/ @-AX = 0913h   (Set Sice breakpoints)2 h: e& t$ d( N* n" R4 P1 H4 `
-AX = 0914h   (Remove SIce breakoints)% Z% i* l& p5 D! P" i
9 u* X/ v7 n2 p: v. E
Each time you'll meet this trick, you'll see:
1 Z8 r& t+ x/ S0 H2 e-SI = 4647h
1 }: A1 M5 t# `( l: z-DI = 4A4Dh
& Q; Q  O( e2 J' FWhich are the 'magic values' used by SoftIce.
: o( }9 R4 R4 u, z  X% T& u. `5 j& [For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
" z2 P! q: E: p& _) N2 E7 M0 y7 c" u( S+ w
Here is one example from the file "Haspinst.exe" which is the dongle HASP: B2 ]. b+ D2 ~/ w
Envelope utility use to protect DOS applications:* k; l: w' f) f& Q; [8 q
- C& F$ [5 M, p/ K6 Z) X4 I: O

. ?7 J1 m' i4 Y* ^' v& \4C19:0095   MOV    AX,0911  ; execute command.
' H; }& f0 p% z5 g4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
/ o* F8 @. H4 L5 W  r4C19:009A   MOV    SI,4647  ; 1st magic value.
. }' V0 g  ^# R4 F5 R3 I4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
, m# f% {& D( ]9 A3 y4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)# C$ S( k& a+ d# l
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
7 T' Z, f! R& R) q+ U- g4C19:00A4   INC    CX/ L% u) Q% K: e# G7 A
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute/ R' e: Z$ S7 _' ]' g" z
4C19:00A8   JB     0095     ; 6 different commands.* }+ x9 g. t1 n6 k
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.9 r) G  W; }5 N
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
7 c$ j1 q8 E8 p" x, B0 |( A
" m/ l' t, E+ J3 _7 q7 jThe program will execute 6 different SIce commands located at ds:dx, which
( Y6 \0 N2 _! d; {. Y7 Z" oare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
# d& v: I- X+ q" z, c
2 t5 t2 a: ]% r7 f( {) j2 b- R5 f* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.: Y% Q& M- ^) A1 D: U* O( G, K. c# M
___________________________________________________________________________( M: M& g: s& O. D# h) D7 Z/ x
( v& r5 @0 d* q, @, }* z

1 a, o2 `. ^% H3 YMethod 03
) U* P1 {% p5 n3 d=========
9 G# B3 Q8 |' ]- i% Y2 B5 R2 O& x. }2 n& y* U" t
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
1 Z0 X# i' c- u/ q' E& G(API Get entry point)
& B8 }) P+ m/ f& ~5 t        , w9 w. j! R7 s5 P; N7 Y
$ R8 X2 a; j) H% p3 Q& \2 H" q
    xor     di,di
- o! z8 _3 ^. ~& Y4 [3 f* f    mov     es,di
- Z9 T6 X. s* \% z/ Y    mov     ax, 1684h      
8 ^6 h, |! b0 n9 X0 A  [    mov     bx, 0202h       ; VxD ID of winice
2 ]: G- l6 u7 d& y1 Q: {    int     2Fh/ B7 F! o3 |, |
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
* I  d4 F* p9 N: K3 u4 E' t    add     ax, di# v  ~, ?3 m' a' g8 z% m7 d: C8 D' C
    test    ax,ax3 L- Q% w% [6 j' J( n+ }* a
    jnz     SoftICE_Detected
& I" X/ f5 s( _1 [( ?, N' Y4 u" {9 p$ U  m" k8 a4 l
___________________________________________________________________________- u/ r! F' A, M5 a. W% D( a0 P$ ~& N

4 S& O5 f( K' R0 j5 [7 M- PMethod 045 s* J, N8 S8 {1 S  Y6 c  Q
=========
* z- Q0 J- Z( H9 p5 ?0 j4 w4 d8 Z, r- ]4 J) [% [! G0 K# Q$ _% s1 [" i
Method identical to the preceding one except that it seeks the ID of SoftICE8 n+ M' ?# a5 R* o2 p7 t" V+ |
GFX VxD.
$ n. ]2 n3 t. H' c+ d
) S& y6 V) _1 A5 \0 r/ F+ |" S1 Q3 h3 T    xor     di,di; V0 \9 a  c4 T+ O% c2 \" H
    mov     es,di
4 m% h! F) g/ {: P( u8 b: G' Q% l    mov     ax, 1684h      
. @6 K/ R, ^- q+ J    mov     bx, 7a5Fh       ; VxD ID of SIWVID
4 ^8 f. M& _: I* W" J    int     2fh
8 h% f# E. q  p5 z/ ^0 F6 R    mov     ax, es          ; ES:DI -&gt; VxD API entry point
+ u( c0 b, G! n  o0 K    add     ax, di
7 A) O, R! V- U4 _: m& U    test    ax,ax
+ h! n; Y: s8 h) q. b    jnz     SoftICE_Detected/ r) ~3 w- U; O
$ D3 r4 ?  O0 s4 a- B: g6 }
__________________________________________________________________________
# v4 ?" _! v' V5 y$ [8 U, A8 Z& H% Q) ]. S

; |! X* u8 L1 c/ ]& ^Method 05
8 J6 U& E/ P1 e* Y# }) H=========
# K  ]) _2 B! A0 D4 ]! ~! ^5 ~; ~8 t9 i9 W! W# d, H( D
Method seeking the 'magic number' 0F386h returned (in ax) by all system
$ [$ d5 z9 D8 t4 W; s, @$ udebugger. It calls the int 41h, function 4Fh.
, V2 t0 h9 l3 DThere are several alternatives.  : [' ]4 ~7 L# f7 `/ Q

0 w) [) p& o. {7 RThe following one is the simplest:
' K6 H8 C2 m; C' k0 h" D0 B2 K" ]  I2 p$ L' Y8 u7 T
    mov     ax,4fh8 ]8 }; h( j/ V: g9 X8 u5 F9 z2 [
    int     41h
% x2 T( S6 s0 k9 Q' t( X# _) s    cmp     ax, 0F386
7 [( L3 t( _, M# C# K' d( q5 N% t    jz      SoftICE_detected7 w  S5 n7 I6 w. V& H! O

& w' i. t. N6 I' K/ r
' G4 }; \2 D$ T' l, i6 f: tNext method as well as the following one are 2 examples from Stone's
8 G* W0 ^/ F2 Y4 t- E9 c"stn-wid.zip" (www.cracking.net):
6 N" @! K: |" @. i, D# Z
$ j" T; W3 W# x9 U$ s& O3 D    mov     bx, cs
" X- s9 q' [6 q    lea     dx, int41handler2
' ^7 _4 f) A) K5 N' C    xchg    dx, es:[41h*4]
: |* h- {- v8 |4 X# g% K    xchg    bx, es:[41h*4+2]
4 G, J! F, z3 c1 x; v2 B) n; Z! e) S    mov     ax,4fh& {/ ]+ k. k, i) X5 \
    int     41h
# P3 [: Q6 H7 ~0 K, C- }" K    xchg    dx, es:[41h*4]
5 L! K1 P$ |7 `& v  U    xchg    bx, es:[41h*4+2]+ W$ X+ J9 A9 ~2 A
    cmp     ax, 0f386h
: g/ M2 D* r7 A* B    jz      SoftICE_detected
  C% c8 f+ L& h" @0 G
! i  H  ^$ c, L  p% ]* Vint41handler2 PROC+ T4 A3 x$ @# y+ Q' |6 [
    iret4 u' e  Q+ ?  l/ \
int41handler2 ENDP% q+ w8 I  m; h/ V
; H" @5 w- a% V8 L
& A6 u' f: y2 ^) s
_________________________________________________________________________8 P+ L9 Y0 i$ p% E& o! B/ f  x

" d0 w; Y0 g( _" ^
& D: L/ q/ A+ \2 UMethod 06, D5 X& Y+ h  x# g
=========  i% Y! M/ Y* q5 u, q3 @

- p1 S+ H! o! @( K7 z5 V
, c2 m& u5 m: E& I- n4 g5 \2nd method similar to the preceding one but more difficult to detect:6 R* [7 z  R: T& ^  K1 V7 m) `

1 n2 f& Q4 c$ s! [0 J
9 W0 M, W3 E0 z  h+ wint41handler PROC% w) q* ]" k( E
    mov     cl,al
* @5 f- s  R" }9 a8 A    iret1 n2 O. s: O) o6 ]/ v0 f
int41handler ENDP/ P$ c! ^. J3 {4 W# m" y/ G

. M. ]' _- z# N# Z" }* V
0 X/ y* `! j' G) s1 F. x6 E; S    xor     ax,ax
% T+ N7 ^0 u8 U0 P1 U: Q0 D    mov     es,ax
" n  g: |7 [* o, L4 t5 N0 \$ F5 C    mov     bx, cs
* o8 D+ ^  n+ R! ^  G0 U# |1 d0 Y    lea     dx, int41handler
. O" t/ Y7 N& U    xchg    dx, es:[41h*4]. s# v6 u" _+ S2 s% C& V
    xchg    bx, es:[41h*4+2]
& U' {. e7 I, ]/ ~    in      al, 40h5 o9 M- x; |* s, H; w+ C9 \
    xor     cx,cx
0 [  E2 L0 M1 x, o+ A9 \$ u% X2 o    int     41h& `! }. r5 z" u) X
    xchg    dx, es:[41h*4]0 y' X2 ~/ u; R3 n. f
    xchg    bx, es:[41h*4+2]' v0 J/ [3 a# E6 ]/ x6 }  ]( B
    cmp     cl,al
8 J. ~6 Y2 X# C; e% _    jnz     SoftICE_detected
/ \1 X3 ^5 ~  y; j# R' ~! Y8 M0 e& v( X5 V8 ]3 ?7 u8 v; i, R& W. z
_________________________________________________________________________
+ c% a% g, [1 K6 V. R# {& T( R6 ^' _3 G: w
Method 07
2 v* i4 z1 F2 l0 G( U5 U2 b; S=========
0 `/ H2 ^1 d8 Y( d6 ?2 R1 _# o9 x4 |1 B/ _. l# E" b
Method of detection of the WinICE handler in the int68h (V86)
8 h/ [& D6 J1 v& X  E; S% s* m& G( n, K! w/ Z
    mov     ah,43h3 V' ]' n' e- T0 v
    int     68h  j4 N  E. z) o, t9 x* O
    cmp     ax,0F386h
- Q% a# u7 X, P7 l    jz      SoftICE_Detected
. I9 r' R( a  _0 Z0 F
9 i) {. ?2 Q9 K6 t1 F/ K/ H* j6 V) ?% Z# f% i3 w. u2 b
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit& e# A; g1 a( _8 l
   app like this:
! s7 g7 {6 S7 |3 B0 X( E
5 w) n( s. x6 y" Y/ B   BPX exec_int if ax==684 @1 q4 c- u! v
   (function called is located at byte ptr [ebp+1Dh] and client eip is/ R7 C+ d6 H- s
   located at [ebp+48h] for 32Bit apps)% d" e- X" X* i' M9 b  J- @2 Y
__________________________________________________________________________
: n3 z( |4 d' S. |1 ]& b) H6 [( |8 O1 e3 X! Y

; B6 v2 L3 s, B7 ]* {4 DMethod 08
0 M* R  X( T' L& n* I4 c6 {=========2 W# }( H- \9 L
: a; N1 I, L. J9 e2 N: J
It is not a method of detection of SoftICE but a possibility to crash the
4 i! K5 d/ X5 C$ P. Bsystem by intercepting int 01h and int 03h and redirecting them to another
" f: t) s1 V) E" m2 O1 `routine.
4 o4 G7 D' V7 ZIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points% y8 l( T- l) \9 X, S/ ^
to the new routine to execute (hangs computer...)/ q: L$ U! B3 v5 d: F  M
8 L0 V, p& ^% ?- Y4 v1 [4 S
    mov     ah, 25h
# U1 j! f7 k: h( C2 {: H. g( h  j    mov     al, Int_Number (01h or 03h)8 w, E# w" E6 p/ m$ l
    mov     dx, offset New_Int_Routine
" y9 P% L" c+ B- K  W* w    int     21h7 T% V1 m# A' q+ l. R' L

7 c7 R+ z- l3 A* \8 O__________________________________________________________________________
/ o! X/ s5 ^  H7 h* O) M
  d/ B- E) c7 x% ^% D0 {Method 09
' R8 j1 ]8 W6 g5 |=========7 s8 _8 @5 Q9 `* c

4 m5 t5 f" R8 X3 hThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
8 C1 H) l5 x, J% b2 pperformed in ring0 (VxD or a ring3 app using the VxdCall).! U1 S( }$ L" S* u! f
The Get_DDB service is used to determine whether or not a VxD is installed
& n4 r5 D/ O! \# d0 [, hfor the specified device and returns a Device Description Block (in ecx) for
5 G0 f2 a6 c8 ^; ?3 tthat device if it is installed.
7 W  G1 q" F2 ^7 L
6 W% V; I1 [4 ~   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID3 \. k5 k9 q2 ~- c
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-), O4 }- u1 e  g
   VMMCall Get_DDB
/ c- M' `; k1 M: y* f' D   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed* [+ K4 l; E3 u# [

% f" Q8 ?6 A2 K5 iNote as well that you can easily detect this method with SoftICE:% U4 z* k0 q7 l
   bpx Get_DDB if ax==0202 || ax==7a5fh
) p1 y6 d% w9 l# l4 B* |9 C4 e
__________________________________________________________________________
" Z. X1 w5 ]8 b. Q. y  N9 S
( |! T  U0 l3 W) h. XMethod 10
. p' a( m; C. k7 ^4 ?* s0 }! _=========: ~; l  L& L" |5 D/ X; r

. z- h6 a/ I; |7 g) g; @+ Q# l=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with  m. y1 u6 d  X* S
  SoftICE while the option is enable!!0 h9 W1 N3 b9 i+ W
* u% U# c; u; E
This trick is very efficient:
6 u3 ]8 H0 x7 b+ ~: q5 Gby checking the Debug Registers, you can detect if SoftICE is loaded8 }& F% M* N* H, _" i: n, r  Y; D
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if2 T; B1 v2 E" r! ]" ^
there are some memory breakpoints set (dr0 to dr3) simply by reading their, U1 s/ ~6 I( @2 |- I* U& }
value (in ring0 only). Values can be manipulated and or changed as well
3 F4 k: M! i3 x& Q8 _3 i- p# d(clearing BPMs for instance)/ W3 H1 R6 B' x3 L, Q: U
- i! k5 f6 @0 r! S- E5 u3 I
__________________________________________________________________________5 V# }5 Y& _6 q5 _; X8 C7 _" P
- u! h5 i, x9 u5 \
Method 113 y! N2 A; l0 W8 f: r; D  @
=========
+ }& A9 v& o' r
8 ]4 R$ |; y4 ?* v: LThis method is most known as 'MeltICE' because it has been freely distributed
! p+ |1 J0 g' B9 e- F; Wvia www.winfiles.com. However it was first used by NuMega people to allow% A* `7 u0 l6 ^7 P# F! g6 G
Symbol Loader to check if SoftICE was active or not (the code is located
5 m' Z7 s3 [2 b9 K" z7 u: N6 Einside nmtrans.dll).
" p( i# T# g& b* D7 x1 k3 i& X1 F- x3 r' Z" {
The way it works is very simple:' v4 t1 Y, k, O# N$ p8 ?+ l- [
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for  `3 V! J* H  A
WinNT) with the CreateFileA API.
' Y' {3 r# l. _) K+ u5 I9 ~" h( |5 E: y- @! `
Here is a sample (checking for 'SICE'):7 i0 @2 A9 g. U

1 f/ Z6 o: {+ X2 v' YBOOL IsSoftIce95Loaded()$ S0 D' T1 f0 C
{
+ g3 s4 M# d9 r: k+ h) ]3 s. ]   HANDLE hFile;  ! s) {$ y3 h4 l- W/ q0 ?+ Z7 z" Q
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,9 R) X9 M, [, Z) @  D
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
! P/ N; K; L1 e                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
/ G/ o$ K! p8 @7 Y* U$ w: _   if( hFile != INVALID_HANDLE_VALUE )2 W* @! D7 s0 y/ L6 d# {
   {# a% f; `& X3 X
      CloseHandle(hFile);
1 m6 O; o2 _- L- Q( O/ O# ?# e% L      return TRUE;
" r" m" Y1 p2 c: c4 R( t5 \( {   }9 L  F  j4 r! C
   return FALSE;
, O* T$ d3 k! H6 {}7 ~+ v8 F$ W. {/ x9 ?" k
6 f0 J2 J+ r, d& N1 p) J
Although this trick calls the CreateFileA function, don't even expect to be
  u% H5 U* a. m, Yable to intercept it by installing a IFS hook: it will not work, no way!1 M# v$ |: Q  F1 l3 ~
In fact, after the call to CreateFileA it will get through VWIN32 0x001F! J2 A% D, r1 n9 Z% v1 s5 U
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)! U: D3 [6 [/ ~+ ^) Q8 ^
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
8 P. ]1 J2 _& ffield.
) ^8 |; {6 y% g1 g  D* iIn fact, its purpose is not to load/unload VxDs but only to send a   T6 {/ @4 p. n( o/ C
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
' s& H2 Y9 A; ?) l3 X6 `to the VxD Control_Dispatch proc (how the hell a shareware soft could try3 z+ r; l* R( C' i0 U/ B# G
to load/unload a non-dynamically loadable driver such as SoftICE ;-).# U' s( t3 D' D' j/ R
If the VxD is loaded, it will always clear eax and the Carry flag to allow# Y/ v7 \2 V9 b- S/ m- e8 F
its handle to be opened and then, will be detected.
4 G. y' j0 Y, b9 d- E; j# yYou can check that simply by hooking Winice.exe control proc entry point. ^' y7 T! m6 I, l; K
while running MeltICE.( [, J4 V  R" N4 A3 Z' i/ k8 `
7 I& k9 H. w  `" i: f* q( @8 {' W* O

9 l7 C- ]* Y0 J( }: @  00401067:  push      00402025    ; \\.\SICE  {- f! L' c. ~+ b  J) T
  0040106C:  call      CreateFileA' _/ T' F$ e+ @6 m; H
  00401071:  cmp       eax,-0012 h+ I$ z# P4 Q' A
  00401074:  je        00401091
! w4 [: D/ i' @6 G: S
& f1 \* d7 e! }. Y, |7 v
1 ?5 m0 ^  @8 h3 L, c; N( G+ SThere could be hundreds of BPX you could use to detect this trick.
6 q! U% p8 |- Z# M& |* c) f/ d-The most classical one is:
7 `0 z& D; N1 x) b- W0 F+ _3 p3 C  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
+ }- p, {" Y# h) a# Y    *(esp-&gt;4+4)=='NTIC'
3 y9 X& {4 {) n) y! \
: I' u3 S6 y; z1 C- n& D" g-The most exotic ones (could be very slooooow :-(( b$ y0 _3 ^. |5 m: A
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
7 g# x' u5 p" B     ;will break 3 times :-(
3 [( q9 k  `4 U7 z2 U
/ p! p; M' c) m-or (a bit) faster:
$ t- g, \# t* r7 t! ^% A   BPINT 30 if (*edi=='SICE' || *edi=='SIWV'): V" i! ]/ F, R  Y* V: x4 r

8 F, H5 U; h5 I7 `2 ~   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  ' U5 u, v' o  b. G
     ;will break 3 times :-(7 f8 m! ^4 I9 ^$ c% g
$ ?( p. p6 o6 U9 P6 Z
-Much faster:
# Q( h' i+ C. K2 F/ b, m1 A3 C: _   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'$ C7 E! A. h8 j' ], a
& h2 C; k9 q. g; ?
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen( T2 G, ]7 {5 r; T3 x9 n6 c; v
function to do the same job:
- C5 B! Y' ]9 ~' p8 O! Y4 Y; u, |  k0 L( Z/ l. @
   push    00                        ; OF_READ# Z, I- S5 X7 ~5 R2 c/ \7 t+ ~
   mov     eax,[00656634]            ; '\\.\SICE',03 y  `, y) y+ F/ {' S8 P9 o
   push    eax6 h! n9 @! |: u& b) D0 Q' U
   call    KERNEL32!_lopen
" b( f; q+ {- F1 c   inc     eax
* L/ a1 j) h) p6 ?   jnz     00650589                  ; detected8 a& b7 i; _( d( w# J
   push    00                        ; OF_READ
# S  U3 l2 D+ ?0 _( ]   mov     eax,[00656638]            ; '\\.\SICE'
0 V7 e+ t% r" h9 v' R   push    eax
/ Z4 i5 t; b* a- x" {, t+ x   call    KERNEL32!_lopen8 \+ B* O! R- q+ t( B
   inc     eax
" O+ h( C+ J4 U6 L3 [6 w   jz      006505ae                  ; not detected
: R' w1 x8 u1 U" Z! W& g; w( w" }. b, W* b- d% A$ \1 H  i

8 s* b1 t* B/ y* j3 H7 k__________________________________________________________________________  C% C4 A. {, d6 p  P5 |% ~
' P$ n5 m2 V  I
Method 12! t& X& e9 Y. a1 v8 T
=========2 A5 |1 b7 x! C
" y9 E  ?/ k/ O4 _) p
This trick is similar to int41h/4fh Debugger installation check (code 05/ b  I/ J( r! y; i0 g# d
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
9 ~# x& Y* ^6 U& Q- p$ ]as it uses the VxDCall backdoor. This detection was found in Bleem Demo.. z+ `" L$ P4 y* @' G' L
4 ^% b% y) ^, B  r/ d  z  A
   push  0000004fh         ; function 4fh' G, k: Y6 F" d; `% F: K
   push  002a002ah         ; high word specifies which VxD (VWIN32)4 X9 a5 F& N8 V" z8 t; f, s
                           ; low word specifies which service- K3 w) o7 Y. b. |
                             (VWIN32_Int41Dispatch)
; J8 r9 L/ j9 M   call  Kernel32!ORD_001  ; VxdCall) r# R+ J  u9 P! [
   cmp   ax, 0f386h        ; magic number returned by system debuggers
4 u0 |6 G. G/ b2 ~   jz    SoftICE_detected# z+ u0 `2 ?! ?
; {3 J+ `' M/ J
Here again, several ways to detect it:4 b& k/ g% j/ h

: L# m1 G; c+ G- p5 G    BPINT 41 if ax==4f
8 R% p) M* j$ D
* m/ R" n- I0 e& ^% g; n; K    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one/ @1 ^" u1 J- j, k1 g

. J* G; p8 o! }; R+ E8 L, s    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A/ C8 h0 r( a) j! x3 z
7 l: _! m- _$ d2 u7 l( [7 h
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
3 I+ z9 Q' ~: a. f6 b
2 q/ D$ r; ]4 U3 A7 o__________________________________________________________________________% g# W; i7 A8 h" a0 D* V

/ M# {' e. {5 qMethod 13
3 S+ L; V3 o) }1 C. k=========* a3 A8 d$ \/ l+ M/ [7 ^
1 [' x. f  U" A
Not a real method of detection, but a good way to know if SoftICE is# K7 Z7 r1 W" N6 |' f  @6 D6 g- x
installed on a computer and to locate its installation directory.- z6 t- @0 y) J* j7 K
It is used by few softs which access the following registry keys (usually #2) :
7 f5 F: w5 T" [7 m; _# S' a% f
$ X- D+ O$ s4 h6 ?* j* j. O' @2 [-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion6 w9 l  H. Z6 _' N
\Uninstall\SoftICE$ D4 f; Q0 N8 k/ d9 f" z+ ~, V3 l
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE" S' N- P4 O! h
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
" I7 d$ Y: t+ o/ h\App Paths\Loader32.Exe% F8 B/ b  r8 ~8 W

7 r* ^. `" M/ G( J9 k! ~7 M1 q# x% N! c! |2 i/ `
Note that some nasty apps could then erase all files from SoftICE directory
  G. |2 {1 Y$ U( g+ _, V(I faced that once :-(9 p' L& l; i, S. C  @) h

0 ~$ N7 B: }( n/ g9 R3 xUseful breakpoint to detect it:
$ F6 W, i) E, q; N5 |, C3 L/ `5 q0 F* ^* J( b" F4 K
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
& |. p3 N$ p8 v* \# ^2 `) F( N. x- f& Q8 k# H
__________________________________________________________________________
1 x8 ~2 C: y  T1 C+ ]! D# e$ _+ Y$ S  X
5 g8 c5 Q. F6 F1 v, h9 f1 _
Method 14
$ {% k: J# ^8 S+ W- ?=========: @& {* ?4 n0 x! c) e  D3 n) d6 f

) `6 M* f) b3 r  L& U7 iA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose' W- r- M, |; h$ R
is to determines whether a debugger is running on your system (ring0 only).
. H. Y, x$ s3 s8 F9 @3 t' I' k4 H+ r) {
   VMMCall Test_Debug_Installed
$ b$ s2 ^9 s% t" r8 H, c8 `; |7 g   je      not_installed
9 v' `# N  }/ [% `: H% w: [" H
9 i5 e6 e* k) Q- [/ B7 A7 W, |, \This service just checks a flag.
6 a8 y. `& h+ v9 H</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部