About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>  n7 \1 y; \; I
<TBODY>
$ _# A/ \5 i2 m0 e<TR>. j( r3 t1 Y/ R. C' l, }5 J
<TD><PRE>Method 01
/ n" U* t4 C7 q+ F: k=========
8 f) x/ U9 W/ r9 D
. t2 c$ J* E5 m  uThis method of detection of SoftICE (as well as the following one) is
6 [) {& H7 C$ j0 ^! A0 Zused by the majority of packers/encryptors found on Internet.
7 W2 d5 w0 T, h1 a' ~- xIt seeks the signature of BoundsChecker in SoftICE
+ J4 Z, E1 T  ^$ m0 ~; |1 ^4 l8 x! T% F9 d! K5 H$ s7 T' K. v. m
    mov     ebp, 04243484Bh        ; 'BCHK'
, @3 u4 W0 H) K6 ?    mov     ax, 04h5 S" I9 N! {0 x& _0 Y
    int     3      
2 P4 k( B- m* {- q0 Q    cmp     al,4/ V8 A( s0 q4 C$ a) Q5 {
    jnz     SoftICE_Detected8 i  f8 d# x8 u

/ x* h8 T/ U' ~7 h9 n% C___________________________________________________________________________2 @* F/ t* f& E4 S. s
: E( T( ^+ G$ a, e4 I; L
Method 02) u* p* v8 c& N5 u0 r0 a
=========7 e& T! c( g9 u2 m0 \3 A3 R6 X' ~( y
% r0 \$ F) V0 ~
Still a method very much used (perhaps the most frequent one).  It is used
  z( [0 `! C, L; r& a1 \% Z+ uto get SoftICE 'Back Door commands' which gives infos on Breakpoints,9 c/ v+ r7 O( S; O. U* n* U
or execute SoftICE commands...+ X5 I; m2 D* S
It is also used to crash SoftICE and to force it to execute any commands, c9 A* Y; B- [) t
(HBOOT...) :-((  5 V/ u( V: v' o* r+ O7 u

& ^5 h8 T8 I+ W+ R2 u* _& O# jHere is a quick description:
+ A: ?$ w# L' \5 f9 d  s-AX = 0910h   (Display string in SIce windows): @- ^+ u6 M" U0 P
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx): W) k/ I. ^$ u
-AX = 0912h   (Get breakpoint infos)5 T$ b3 ^$ w% o# A
-AX = 0913h   (Set Sice breakpoints)% x6 e2 B- O% a1 d: j
-AX = 0914h   (Remove SIce breakoints)' i# W- T# {3 z+ `3 N% S

$ J8 n3 c2 O& m' {: z  Q- `Each time you'll meet this trick, you'll see:1 t/ d% f4 i7 ]% Y4 R2 ^: C
-SI = 4647h/ g- M9 r" C3 }# u7 \* T
-DI = 4A4Dh) V* c* p6 U9 R% x: r: I
Which are the 'magic values' used by SoftIce.+ O' N  w9 m& C( ^8 |5 j
For more informations, see "Ralf Brown Interrupt list" chapter int 03h., c# X9 H6 c& E( @. {$ y, T. l3 j

2 j4 u7 ?9 }( [, X' x: mHere is one example from the file "Haspinst.exe" which is the dongle HASP
. P2 u4 Q& b+ w. E7 m2 vEnvelope utility use to protect DOS applications:$ G* Y: r, j- B9 o( ]
& w  b2 A. P* F$ \9 F! k/ T

1 n5 a; P3 n0 I# y4C19:0095   MOV    AX,0911  ; execute command.
$ b$ ^/ h, _7 p& Y" E: b+ u4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).  o& Q, g  s6 p
4C19:009A   MOV    SI,4647  ; 1st magic value.
& l5 l' |3 s$ |: H3 O' X/ M4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
0 B( ^; H$ M. k4 j! T2 r5 X) C8 k4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)+ v2 c. p: o+ l! Z7 Q0 J5 @6 Z
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
, A* P8 W6 J4 \; u' d( ]6 j9 B4C19:00A4   INC    CX
) x& g3 o* r# M* U* V1 k4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute; q* a) K% x8 M8 {7 E
4C19:00A8   JB     0095     ; 6 different commands.; L# L+ e1 Y" |( c2 m: I6 [
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
3 ^. a' ]5 t/ w: D' S4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
3 @- |, a: f3 j# \! h" z( L
) C% G0 \% l! P  i2 }% R8 \The program will execute 6 different SIce commands located at ds:dx, which: s6 ?% x2 h8 s9 i
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
- ?' P1 X; h  W: O
9 N; y3 w9 n+ ]" _2 e5 T* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
/ M) ]+ p" f' @( ]) ^( ____________________________________________________________________________' k. o1 n3 v$ Z" u
+ _% w5 p, w' _8 z; O

( V+ }! m2 G  w" m+ n5 v8 HMethod 03
7 r) a' t$ Q" Y" l=========( |" a% f7 }; H. w4 Q0 n8 y
" }9 a+ E* s# i
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
5 \' _; T; r0 R+ z% [/ T) D0 Q(API Get entry point)
" t% e8 I( o( T% H4 H" a        ) h- d: k! o1 b! B; a2 S/ E
# J' u6 b" n1 M/ Z0 A
    xor     di,di9 \, M, p9 b: O) o' B( _
    mov     es,di8 Z+ M/ x$ n: d2 e  `1 {5 a/ z6 C
    mov     ax, 1684h      
% K$ |  {0 y/ L( C9 i    mov     bx, 0202h       ; VxD ID of winice+ b; h, v' E; f8 p. ~
    int     2Fh7 j, }% `% `6 ]4 v" b
    mov     ax, es          ; ES:DI -&gt; VxD API entry point1 b2 E3 V2 m% G/ v7 h! e% K" o
    add     ax, di! c" e+ H. h8 X* c6 _8 ^6 l
    test    ax,ax
: |( t9 A- I( j1 ]* l    jnz     SoftICE_Detected
; C" ^. I( g( `, E
4 q0 K/ c; w1 u___________________________________________________________________________( B! k7 K  C3 C: B# o+ u
8 u, {( j3 R  K! M8 h
Method 04
4 }% c9 }/ T& a. w& z  v=========
3 _  G! Z2 A/ m6 k; I7 [8 K# s" c6 t/ d# {; {. z* b" e
Method identical to the preceding one except that it seeks the ID of SoftICE- E6 ?  G0 X3 L% x2 I, E3 A
GFX VxD./ @+ b% n- g, H7 g9 v
, i0 R3 x  }1 b% F2 o- E' V
    xor     di,di, c# u6 v$ f$ Q  E& M: f2 |) S, m! F
    mov     es,di1 ^9 Q* w! A% V* G/ Q8 {4 O" M$ C
    mov     ax, 1684h      
7 k0 C# u  h- B9 ]    mov     bx, 7a5Fh       ; VxD ID of SIWVID
7 V) j4 i: X0 M% ~7 g    int     2fh3 X0 T# c# c9 j4 X/ B
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
. |0 g3 r6 I' P: T# D+ _    add     ax, di+ _5 e2 i! p! T& a1 r  q$ j
    test    ax,ax
- Z9 c/ E. @/ ?  U1 B    jnz     SoftICE_Detected
4 f# K) j9 ]5 B) G* O& @
4 }5 F5 p5 _0 |9 W1 F4 q8 c! ^( c+ J* t__________________________________________________________________________% d3 w# U, O8 d) O+ k. Y
# a8 y( P, K  j6 H/ X

& N% X; E9 W% X" e9 h( Z: XMethod 05
/ `7 p3 i5 [- o- ~) ~=========7 x0 i; F0 m8 v( N1 M" F
$ ]$ P) i7 P! e& ]$ o' K
Method seeking the 'magic number' 0F386h returned (in ax) by all system3 |8 [1 _# d- [
debugger. It calls the int 41h, function 4Fh.
/ N" x/ U3 v4 J( L: `* xThere are several alternatives.  : y( ]7 E5 ]4 y3 P6 ]

/ t, L1 w" ~/ Y& y$ d5 z1 V. NThe following one is the simplest:$ L0 x3 \0 B  }, O% d

! ]8 W& ~2 h8 P5 W% G( o+ V    mov     ax,4fh3 a1 y7 ]( t8 z; F- O
    int     41h
) K& b; X% h: j0 Z2 ~! j% u$ G* Y5 W    cmp     ax, 0F3869 e( d( M0 s0 |) i+ r
    jz      SoftICE_detected" R1 C: l/ v8 H8 O% _
, B( t: T- c, t4 d% U1 C2 |

/ H8 o4 m4 ]0 A5 D0 _) vNext method as well as the following one are 2 examples from Stone's
8 J7 w& K  Y! g4 V"stn-wid.zip" (www.cracking.net):; @+ T" a/ k5 {  i3 S% B" Z8 f0 X7 \" D
8 A4 l' w1 I& o+ a( f) m. R
    mov     bx, cs0 ^4 c+ U  w% }  J7 b& G
    lea     dx, int41handler27 q. n! U1 i% e
    xchg    dx, es:[41h*4]+ [7 e* X* C5 `* `
    xchg    bx, es:[41h*4+2]% Y1 g. V1 |' d' ^( O8 F+ j
    mov     ax,4fh  c; H+ c; H) g  ?7 j- n; ]
    int     41h
1 N# s# L# w  L  W9 i5 C    xchg    dx, es:[41h*4]2 C6 M; \' d- n' `5 l4 \
    xchg    bx, es:[41h*4+2]
& t5 d4 c6 N# s- c5 G) D% W& t    cmp     ax, 0f386h. ?0 D! w5 Z9 G$ M4 W4 G
    jz      SoftICE_detected1 w- C& S8 J, U" ?( \0 t

7 M6 V' a" K5 ~int41handler2 PROC1 O" E! Q0 P0 z" _" H
    iret
+ {  Z  `( V0 D- `3 a" H5 Sint41handler2 ENDP
/ r% _* U4 t' {' w% A, \
, `1 d4 S7 t& ]1 h0 o0 J5 c6 I
, ^( I0 [! i. y% ?1 {8 n! K_________________________________________________________________________
/ W  N2 j8 i" G1 ^$ Q/ A& c. c6 x* ?0 y4 t% v. x/ P% M# k- t: k) \% x
, o; Z' Y7 a4 }/ b3 z
Method 06
# G. z( L9 m  n+ b) D=========- M2 B+ _  ~7 e
, f' T. J) D4 W  x$ Y) a, n

6 w5 g0 I& d& S& \: Y$ I7 a2nd method similar to the preceding one but more difficult to detect:( e1 T' X7 y& c$ ]

7 g3 |$ y& j  G" X1 ]' }: t4 [5 h3 W8 `* r+ p) \
int41handler PROC
# X0 z0 l; W) `" a4 Z    mov     cl,al
( {' }/ v7 g0 Y& m    iret
' \0 c6 |* q. N( E6 l4 d+ {- Hint41handler ENDP3 Q  h; G) `0 Z0 C6 {2 @
) I4 x3 s1 }  ?* r. F  _9 c
; B# ?; p# v$ z" k
    xor     ax,ax0 b5 ^/ L  i9 c  V" v( o2 Q& h2 ]
    mov     es,ax; O' B, e8 E; M! j1 m5 u
    mov     bx, cs
. I& F! J: y5 K8 z5 u) @/ \    lea     dx, int41handler9 r5 s" z5 n& j& r9 ?: E& v
    xchg    dx, es:[41h*4]/ ?* V# r: z% |$ D
    xchg    bx, es:[41h*4+2]( Z% Q- v: I8 c& a% @% I6 k
    in      al, 40h$ ?6 a1 k1 {3 T( k8 H/ j
    xor     cx,cx
; S8 [# H/ w- G& n  X; l( J    int     41h
8 e. O7 [9 D  W& T, f) P0 o    xchg    dx, es:[41h*4]
; f9 n* u) h3 I- \: e    xchg    bx, es:[41h*4+2]
2 I; c% p! g; G2 m# }; e! v    cmp     cl,al* I  ~& r3 W4 C
    jnz     SoftICE_detected
& G/ P% a! P1 l' f2 u
6 ]& Q- y; d/ }0 N_________________________________________________________________________; V3 O  h( K) g% ~, i' W+ s
3 [9 E9 F% |1 |0 T. a5 I: f4 ^
Method 077 m& _. }8 z* i$ |
=========
) M& v- P) _* ^/ r! R7 s+ P+ L, W* c
Method of detection of the WinICE handler in the int68h (V86)) ^! @1 n# `9 H1 \! F6 B7 b

& X2 o$ W2 p) L    mov     ah,43h) s) e: F4 z" M
    int     68h% [# s9 j. ~2 m% Q; E
    cmp     ax,0F386h7 s" y5 H: M" _8 a( R/ S
    jz      SoftICE_Detected
/ r& l& `6 k8 j; Y; Q% ]' P: m8 R8 O+ }# W# Y, `! B

3 V, q# V' L# s% K=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
5 o% ^8 S2 B3 a- k3 N1 l% [   app like this:
+ D8 N: l3 i+ g  ^  ]0 ~& ~1 p1 P& J3 }
   BPX exec_int if ax==68. N$ I3 B1 k) t4 `( O) \  }# a; w$ F
   (function called is located at byte ptr [ebp+1Dh] and client eip is) L8 D* O/ J7 \* s) e
   located at [ebp+48h] for 32Bit apps)1 g! J9 G; j# i: R
__________________________________________________________________________/ @. W  Q: R& {: P
$ H+ u* J0 D% V0 p2 ^8 y
  l# F0 {8 c  j3 o: x
Method 08: M( Y0 C3 Q9 l, h* x6 i$ n
=========
; L* N/ ~2 ]' f" e0 [" a
6 ^1 R; W0 J8 _4 mIt is not a method of detection of SoftICE but a possibility to crash the; |% y, q8 T6 q5 U+ e' Z
system by intercepting int 01h and int 03h and redirecting them to another7 `2 |$ P, _# T  V+ U
routine.. G+ b! o/ }6 h+ |7 ]
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
  ?% a% M& o: r. j. q3 n  h/ wto the new routine to execute (hangs computer...)
8 w$ {0 x* m/ O/ m, w# j" P- u
3 h" ^( K1 E! P& i) x% B8 @    mov     ah, 25h
& b) e; I; O  w: O1 N0 }    mov     al, Int_Number (01h or 03h)
3 M. b: _4 ~1 G& t( Q# p    mov     dx, offset New_Int_Routine  A! U8 N2 \; g2 l$ f1 W' D
    int     21h
; k* ^& S  q7 _+ e: j8 s6 g9 [) k% [
__________________________________________________________________________( ]4 u" I6 J0 j

) M4 s% C9 ]+ q' b& b: ~- p% n3 zMethod 09
0 i3 H" T1 Z1 B=========9 ^# i7 ^# U, b/ i7 H8 H
( h2 R' |( \/ e* j, k
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only  E3 n' [6 P6 Q5 i: L" c4 {1 A7 F
performed in ring0 (VxD or a ring3 app using the VxdCall).: X/ h$ b2 k, F, h0 L% w+ ^# x8 o
The Get_DDB service is used to determine whether or not a VxD is installed
# k- [* D7 |& T" c( p1 z. o' O% jfor the specified device and returns a Device Description Block (in ecx) for
  G- k4 z, q7 w. ?that device if it is installed.
8 M9 B; K& g% j; o) G: z
1 H0 ^5 g; Y8 n- D& p2 Z0 w+ U   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID" w: s2 A. l8 w# a. V) h/ r0 q! k6 q
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
- V4 R2 C' h, Q, a( O8 ]: C   VMMCall Get_DDB3 e. g1 C' M: t" i0 X7 t& B
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
" L1 w' E& E% l: Z# x3 s0 g4 o4 |: y6 K
Note as well that you can easily detect this method with SoftICE:
  Q3 U9 D3 j6 D  k5 v   bpx Get_DDB if ax==0202 || ax==7a5fh
8 T* q& r6 F1 I! ~4 X% u" `& R
" Y) Z2 o4 R* c3 `. j  D/ ^/ Z' }__________________________________________________________________________
. L1 d8 E, V5 _/ ?9 H
6 M- P# E6 g. z! ]  N! n; e/ Y  VMethod 10
9 p0 d) W" K, C, t7 p0 x. e=========  u" A4 U( }5 \3 S

+ u. o2 k( Y% d5 i7 A# _=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
2 ^. U' V& K9 Z! f% x. J1 N$ b  SoftICE while the option is enable!!
/ d; j3 i* b. Q: i  ~. U5 }5 C
( e) C- v5 b/ e. `. `" @4 S3 CThis trick is very efficient:
( |  Z9 c4 w$ N+ w. xby checking the Debug Registers, you can detect if SoftICE is loaded
* I* Y, c5 j' }! [(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if% K7 V8 a2 w; p5 W
there are some memory breakpoints set (dr0 to dr3) simply by reading their3 [- b$ t: r! M' v- A* ~/ H( r
value (in ring0 only). Values can be manipulated and or changed as well
! z, [* W# w: h5 w6 k) r3 Z/ V- [(clearing BPMs for instance)- {) e4 j$ j- K
( l  \7 t- ]9 t  s( m( ?9 B
__________________________________________________________________________% \, A/ s1 Q9 @7 L
5 Y! ?5 t, d" o9 A0 Q
Method 11
# T2 N8 Z1 H% [' m5 ]$ @=========( `: |5 Z) E2 K& _9 {

" O/ B! D# z, q$ vThis method is most known as 'MeltICE' because it has been freely distributed
9 V6 W! G7 Q0 X& R% i2 Gvia www.winfiles.com. However it was first used by NuMega people to allow
4 `! S9 I! t; N/ {1 y) `Symbol Loader to check if SoftICE was active or not (the code is located
- G) V; h! L1 I1 Ninside nmtrans.dll).5 f6 r$ C- a6 A, z' S$ C& C
, D( i+ ^! m) S* Z* E
The way it works is very simple:' r4 D, F0 p' m; c7 f( z- D
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
! r* S( A  G) j+ B4 I5 ~WinNT) with the CreateFileA API.
2 B5 o; `* W7 e* D8 A2 ~# Q# q# L- \" Q" j+ E  a0 [" Q
Here is a sample (checking for 'SICE'):
0 y3 o5 I. v' l5 N8 |1 L! V3 c
, H! w% O; b3 b+ o8 v) [9 BBOOL IsSoftIce95Loaded()% Q. h# t* \9 i/ V, o
{, ]0 E* u# h2 Q* A! E
   HANDLE hFile;  ( o! Y6 M/ A4 `- Z+ K! _( ]9 d
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,+ _9 B: n* d2 _: s
                      FILE_SHARE_READ | FILE_SHARE_WRITE,+ f& ]2 a7 w. u; h0 M
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
. r! I; I* d* @! `; @" C' o+ l& o   if( hFile != INVALID_HANDLE_VALUE ). c$ H9 r! s3 d7 |3 u2 ~
   {
  T+ `/ y3 b1 v      CloseHandle(hFile);1 L% F3 G$ x% r% L: b
      return TRUE;2 {6 Y4 @3 h% k( _
   }1 @+ j9 ~  ]: m
   return FALSE;
: Q: n1 v9 o# D3 O$ g8 \}
+ b( q( y, I2 R) J5 `/ [4 K0 X5 z5 V) f- ~6 s% Y4 @( Y
Although this trick calls the CreateFileA function, don't even expect to be# z8 D+ C4 B# m/ g
able to intercept it by installing a IFS hook: it will not work, no way!, |9 ?  `: \; l7 w( V: O
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
* o" ^/ s; t: {8 o3 j# sservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)( B9 q% ~% H1 q6 @4 C/ _/ c
and then browse the DDB list until it find the VxD and its DDB_Control_Proc3 N) P& f$ n, Z- E) C
field.' L* V) W) s0 Q* k! e7 y9 K' d; ]
In fact, its purpose is not to load/unload VxDs but only to send a
) s7 T5 O! H7 q5 b2 qW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
0 M1 N; k4 i# |2 Gto the VxD Control_Dispatch proc (how the hell a shareware soft could try* n) n' \( h6 X; G. b; q4 @' z% i/ G
to load/unload a non-dynamically loadable driver such as SoftICE ;-).; O& L2 @' M2 c. v
If the VxD is loaded, it will always clear eax and the Carry flag to allow
- U, y& C; u7 e6 ~its handle to be opened and then, will be detected.0 ^, X" \1 Z* k$ X& d6 C* v1 C& T
You can check that simply by hooking Winice.exe control proc entry point
' P( o/ ?) z5 E- ywhile running MeltICE.
0 K0 |. |+ r0 C0 L0 \* y% m8 `! N8 j6 O, \7 ]
. i1 E: |6 e( K: R% s: G
  00401067:  push      00402025    ; \\.\SICE+ D! P/ s: x+ q  N. V2 V: M
  0040106C:  call      CreateFileA
  |6 C4 h6 X9 Y$ {5 ^8 ?  00401071:  cmp       eax,-001
; [) [; f3 t: E( l* ^3 f* `  00401074:  je        00401091
( r; \+ ^0 c% b  s+ _
# X* M' H# }+ M6 G$ i4 @4 f! H1 d5 E1 U* d# [3 ]1 ]1 \; i
There could be hundreds of BPX you could use to detect this trick.4 t4 A4 W5 l, o  ]
-The most classical one is:8 H& G. _& @, F' ^# ^7 H
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
- R" Z3 u0 q: G    *(esp-&gt;4+4)=='NTIC'; k7 c4 r0 }4 d

  _7 Z. f- E# {5 a" \8 J, N-The most exotic ones (could be very slooooow :-(
& b: }! D) y' m/ q   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  % L& H3 h8 i5 F* L
     ;will break 3 times :-(
8 J7 R& P) U/ w3 D/ o6 w
* X5 D- Y4 N5 k! z: X5 ?3 n-or (a bit) faster: 3 t0 T1 c* d( U
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV'): g- W# D, f& {' }
. z5 r& q) n" e4 P1 _# ^/ p% t* {
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  4 q' P7 a; D7 c" i
     ;will break 3 times :-(
/ |) _' g4 }5 s! P0 M& V6 z8 I0 S/ }2 f) D/ v2 e- X
-Much faster:
( [, H, u3 ^. l% V   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'6 n$ H0 F5 T. Z

* N' ]( E8 w5 K+ i$ y$ ~Note also that some programs (like AZPR3.00) use de old 16-bit _lopen2 }4 O% m+ ~1 Y& U
function to do the same job:8 A8 G6 [  j4 |

% e  t' B4 |% x   push    00                        ; OF_READ% o- v; K3 p. R4 G
   mov     eax,[00656634]            ; '\\.\SICE',0- Q0 q5 O8 y1 [. E' J0 b8 k
   push    eax; }, E) Z3 k4 K. w4 K
   call    KERNEL32!_lopen
' Y' \2 a  d6 W, `3 m: ?% N   inc     eax0 Y+ C7 F# Z3 w
   jnz     00650589                  ; detected
! W6 N, |, K; ^, S. x; }/ L   push    00                        ; OF_READ8 c( A% p& ^* I1 ?3 I0 X0 ?1 Q9 R9 t
   mov     eax,[00656638]            ; '\\.\SICE'
% d1 S$ ?. ?8 q   push    eax
+ Z6 |, @% E, y" x1 x3 k0 g   call    KERNEL32!_lopen) R: [/ C& `5 F( ?2 }
   inc     eax% L1 T' I; m; M" Y
   jz      006505ae                  ; not detected
- @( X9 G6 `" ^$ J
4 l: `  g$ ~" h- s. l5 `$ h) ^- u( t, Q% m5 M
__________________________________________________________________________; x" D; `+ m' Z4 T

. d* [# v" I1 Q5 A% n, c  JMethod 12
5 T- m, ~; y' c' B3 h=========- g; F1 K; p1 D: Q  \' j' t2 u
9 I& ^4 R, y8 z9 R7 x
This trick is similar to int41h/4fh Debugger installation check (code 051 b6 @4 S; d) x# i% H8 A( T
&amp; 06) but very limited because it's only available for Win95/98 (not NT)- `* m' ^( {( ?0 `7 S- O$ }
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
' X- l+ t7 M: v# M' @8 @5 Q- ]9 r* d, j
: o  u& c- C% x2 {   push  0000004fh         ; function 4fh/ Y& i( \" y- i. ]: ]
   push  002a002ah         ; high word specifies which VxD (VWIN32)
8 n, G6 ?* m( ~7 J) {3 S% h                           ; low word specifies which service8 W9 Q0 d5 V+ E* v, V
                             (VWIN32_Int41Dispatch)
8 G8 I$ F3 y0 G( h+ B. s4 D$ ]8 B   call  Kernel32!ORD_001  ; VxdCall4 p" q0 O! e! z  W& f3 V
   cmp   ax, 0f386h        ; magic number returned by system debuggers: M% g8 G8 i/ w* G( O8 p9 K' E* O
   jz    SoftICE_detected3 u$ B, z) m( y6 }1 V: o# U' s

- a* f* o+ J; l/ u- @Here again, several ways to detect it:9 e; G# v0 u8 f! n

& i; n. `8 ]: e  e& O* L0 @/ _    BPINT 41 if ax==4f% m! m& V% T0 z* V# t  C7 ~+ ^/ K

7 y6 S3 r) r6 D7 b7 o% Y& J9 B    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
2 A6 r, }. g0 h2 _( H1 z- Y. V) m8 P' b6 s; g7 o6 g
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
0 ^. t5 G6 U6 r+ q5 o1 n+ Y3 k- ]8 S9 b" Y  S+ x/ P/ x
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!9 L7 Q0 N& y- K7 M3 {1 ~

+ C- M# s: l7 O& h! ~. [. v__________________________________________________________________________$ i) [7 K5 w+ L  A, S

7 \* T  C9 `3 M  a  z8 e  B1 j: xMethod 13
6 t+ A% t6 x) ]  Q  u=========$ X/ j/ w* i' Q* ~6 l3 ^9 X: `
+ @9 m. e! ^) @: p& r6 _. ~
Not a real method of detection, but a good way to know if SoftICE is
. C& _) F, A4 Cinstalled on a computer and to locate its installation directory.
6 |, h* s7 T' J4 B6 M. nIt is used by few softs which access the following registry keys (usually #2) :5 }" |! m. F2 g. d5 C
9 |' s/ `; K$ w. U4 ?+ S& w- }" Q
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion9 ~4 \8 X! C$ T
\Uninstall\SoftICE7 K! E2 y  c1 S( U: |
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
, \- i' ~, T+ G% d; q; v  v-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion8 v: W; X2 J! p5 i
\App Paths\Loader32.Exe$ J" X' n- K) N0 f- T$ R/ C
2 _6 |" N, X6 h- D4 g8 o
: I& j, N' ]+ l( R# q6 f
Note that some nasty apps could then erase all files from SoftICE directory
/ K& S' I' m# a9 D( ^* w  i7 }(I faced that once :-(
' O( r+ j" f3 s/ x% ^: ^  ~1 x$ }. ]) R* x6 r9 P8 z% Q) w5 {8 _- g
Useful breakpoint to detect it:& O0 y7 y; R5 n8 }' z) [

$ V$ w. s& \8 m4 S$ n3 Q9 E     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'6 Q! S7 `) `9 D/ o3 {

: C8 P9 k8 r/ p. w9 H1 N% V' Y__________________________________________________________________________0 L, M- i; f( N0 c$ `
( b  }& {/ p* i- s9 r

( m& P& ~3 g8 t+ T% R) e1 L* PMethod 14 . E9 I% w0 b6 A2 R; U9 m
=========4 D$ w* x; p2 U) q# t  q5 S4 q, c
9 r& |3 j: `2 g# R) l
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose/ H$ v; L. \! n/ X& A: T
is to determines whether a debugger is running on your system (ring0 only).6 G- h) ~8 y" y9 j% D. j
) V/ q/ Q5 E3 F
   VMMCall Test_Debug_Installed6 B6 t& r8 l. c* D& Q
   je      not_installed9 i6 o8 X; e' ~0 ]: T
1 [/ k9 D8 L+ Y7 }) H/ y
This service just checks a flag.
' {3 ?4 H: ?1 A5 r2 g</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部