About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
  _/ g/ N9 O% h+ p% g<TBODY>
2 v% ^0 z" k' q5 l* |( F" @/ B<TR>
% U6 }- ?( {7 s3 D* c" K<TD><PRE>Method 01
  l. }" p; O  P5 N( N=========4 A! c3 a3 T! x9 `* Y. b' K

# z' O; K/ z! f2 L8 x6 F0 eThis method of detection of SoftICE (as well as the following one) is; c; s8 u2 ]% T4 g
used by the majority of packers/encryptors found on Internet.
, q4 }+ c# Q: [. a0 zIt seeks the signature of BoundsChecker in SoftICE
& @; V3 R7 L% {0 \2 B8 [+ S  I  x) T" j8 Q% {+ i
    mov     ebp, 04243484Bh        ; 'BCHK'
' S" c2 L4 W. {4 b- d/ n    mov     ax, 04h  q- F# H$ O( X: T; F% O" N
    int     3       8 p4 R; Q1 t6 t" q- T% o
    cmp     al,4" l1 H# X* c& N
    jnz     SoftICE_Detected. b* a- t/ d! g$ @) ^

; p/ a; M2 e3 d1 Y___________________________________________________________________________9 N! [( x" _, w. L9 |3 c0 Q
4 _( F( Y. x1 e& S) K
Method 02
2 |# t0 y1 Y8 @=========
& w- b% i9 m8 m, O- M! l
' w9 [* }) r+ B" BStill a method very much used (perhaps the most frequent one).  It is used) ~$ D9 q6 Q' R$ h
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,- [! i4 @( D- ^* m6 m6 g
or execute SoftICE commands...
4 ]4 d6 S. M% O4 L6 ]  sIt is also used to crash SoftICE and to force it to execute any commands
9 \% t* @  n% D. B" l/ b9 J(HBOOT...) :-((  5 ~5 ?1 v, a; x" E1 [

6 b7 ~: s3 q, B% X/ |  VHere is a quick description:3 ?- z' W$ K+ E( y, `* p
-AX = 0910h   (Display string in SIce windows)2 @) P- N! a* o% Z
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
! V8 a  g& H! |' U  J-AX = 0912h   (Get breakpoint infos)
+ O3 C/ F" P8 F! l  k/ e-AX = 0913h   (Set Sice breakpoints)) G5 L. \9 ~4 z& E
-AX = 0914h   (Remove SIce breakoints)
* J+ m+ M) i4 Y3 ^" f/ ?5 b( q# O
Each time you'll meet this trick, you'll see:. t( T3 P- _5 \% d3 j2 E) a
-SI = 4647h) a  T* O0 [& ?/ H5 B' l9 Z, ?1 s# `9 y
-DI = 4A4Dh
0 O! @3 z- W9 I1 z: Y; gWhich are the 'magic values' used by SoftIce.( Y$ A- L4 c+ l& K0 y: M+ ~$ i
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.& }; J5 u  @1 J% H7 u
7 d, N0 O+ D3 g7 `! C1 a  {
Here is one example from the file "Haspinst.exe" which is the dongle HASP
, e& E  I5 i( b8 hEnvelope utility use to protect DOS applications:
7 v3 A  F8 i0 p: _  W! \( o* ?
1 d5 Q% g2 ]- m: x5 v3 [
2 [$ A: a- \8 q/ @  r4C19:0095   MOV    AX,0911  ; execute command.
! c% n+ U8 W% Z" O9 |. B4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).1 @9 T% ]/ R: z9 f+ Z  O
4C19:009A   MOV    SI,4647  ; 1st magic value.
2 m5 |, P* j% N7 @4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
1 p, d5 g9 V# l1 O3 c) I; C8 n4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
. L" k: Z( y. p" @4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
' i7 O# m- `9 C: W! ]* k4C19:00A4   INC    CX
! n8 J0 \) T- R% U& P/ }4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute( L2 g; g& o7 B& b9 R
4C19:00A8   JB     0095     ; 6 different commands.
- ?( [1 k/ c  m* q: f# e; A4C19:00AA   JMP    0002     ; Bad_Guy jmp back.  h; L  ^0 j: a5 G! ~4 n! q
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
( K7 E% v& X' E, b5 v2 W7 p! G, [
3 g' K% f5 {1 U! @4 k" X$ lThe program will execute 6 different SIce commands located at ds:dx, which
5 ^$ M  |3 ^% D7 n; Eare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
$ [9 W" ~' D9 f: B+ g( p+ K+ ]! B" @. {( P$ V! `: p
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
: K+ R) P) R% d: |0 W( a___________________________________________________________________________  N1 P% G1 c* [2 [( O

5 r9 c6 z. i" w1 e( u/ |( C1 M& N; ~9 {% a1 ^! ]4 Z# ~- B
Method 03
9 c: X' {6 n) x; N1 ?  d=========; m' A1 G" l* ~* d6 Y7 \2 V# N) x
6 a2 U( V" S3 W/ |' B
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h# a& H' G7 ]. U1 W& x) {
(API Get entry point). k1 X" Y! ]- r: J& y
        
5 \3 \; P% D9 C4 u# \8 |6 J, q' |# J( G2 i2 A
    xor     di,di1 i3 ^1 x' t& R0 o
    mov     es,di1 }3 b" U6 W! A: R0 E! n0 Y: a( E
    mov     ax, 1684h       3 @0 ]1 `  ~$ N2 _: c" p/ L4 r9 N
    mov     bx, 0202h       ; VxD ID of winice
) X# A8 E' p2 a2 \' `/ X# Q    int     2Fh. [: l& o% T# M; ~" I. s1 @
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
2 X% _% B8 e, {6 v" w    add     ax, di
/ [3 u8 V' m/ c2 f. T- j    test    ax,ax
+ f, Z1 N$ u) w! K6 @    jnz     SoftICE_Detected% z% X, l/ ?' l: R$ S' v/ T

, E8 f* ~7 c3 ~0 \% @; c3 W___________________________________________________________________________. [7 E% `7 _) H+ y! j

8 S' v* Y" W. AMethod 04
6 O* A9 U& \  u7 l=========1 M7 r7 O7 U! `) l+ H" m" n

) {8 p. N% C2 g; K5 S: O, }/ RMethod identical to the preceding one except that it seeks the ID of SoftICE
! W4 |& l( b7 \$ g, A" uGFX VxD.  r0 x- b5 H9 }) Y

$ M+ _1 N/ p1 S3 h! v: s/ u) U    xor     di,di
: G& r. W0 z. E( S2 d6 Z    mov     es,di
4 x" }( ]; {& X$ y2 `# F    mov     ax, 1684h       : H7 N0 T$ R" ~5 _7 ^/ H! A
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
6 r2 }# i- S) a1 N: {    int     2fh
" I1 i* J# O& u9 x- s* S: d" e    mov     ax, es          ; ES:DI -&gt; VxD API entry point
9 R% V6 z# ^- U- h) T2 W    add     ax, di
' Y% l2 g% m5 `1 O% a& y: b    test    ax,ax: s* z( f5 @( r6 u' B$ e& J2 K" J
    jnz     SoftICE_Detected# _) Y9 f* ^3 }5 @, k
1 x; S9 u7 S% [% X+ _5 C) X
__________________________________________________________________________( \: I3 r6 T3 K( ], C( U9 t

% {7 Z  g7 }6 q$ w
, i& k5 C0 H6 ^, nMethod 05$ |) [' Y6 h. F2 V2 `' @6 J
=========' U0 r7 b: T, t

# _! Z: X% T! L$ |; `' C8 rMethod seeking the 'magic number' 0F386h returned (in ax) by all system
6 S$ \% F! ^6 L4 F$ j/ O! @debugger. It calls the int 41h, function 4Fh.) E5 T3 K; N9 P( r
There are several alternatives.  
6 f! T: v! O# n0 ]/ a' k5 E* x
7 f1 E  ^5 ]. y+ H% tThe following one is the simplest:
, U1 X: E" C1 W4 P( b0 D  m  R2 i! }  V0 L: n- q$ w
    mov     ax,4fh
$ ], x7 c) K2 M7 z: U    int     41h
6 I( f  _/ m/ k5 I  f9 e, H5 T    cmp     ax, 0F386
' Z6 z$ `, T1 c    jz      SoftICE_detected
( M- [. q  d3 p' \1 w: `, `1 |  j0 R3 {7 s) S

$ ~5 T( S8 V/ t" o/ C# c+ j' GNext method as well as the following one are 2 examples from Stone's 5 {2 L& Y- [% P, ~! A) X- B7 W
"stn-wid.zip" (www.cracking.net):; Y! b. O, t& |; X' B+ b
$ b4 w. w& g! r$ O
    mov     bx, cs
0 h1 E6 w- t% K1 Q+ {; o, `: q    lea     dx, int41handler29 O0 d) I3 G7 a: m
    xchg    dx, es:[41h*4]
0 t  H3 f4 R0 c* d    xchg    bx, es:[41h*4+2]
1 w6 q7 p. M( ?* p0 f+ ?* [    mov     ax,4fh, c0 c) U8 T+ w
    int     41h( b9 `  u6 B5 u. F2 Z
    xchg    dx, es:[41h*4]
$ V( B* F+ s$ @& o  I    xchg    bx, es:[41h*4+2]4 O3 r% d3 Z) \0 O* j
    cmp     ax, 0f386h
! d6 T  m% M: {5 k) W' m    jz      SoftICE_detected! }* l: A- \4 Q% I6 _
) H1 U1 `$ I& ]4 B* u$ C
int41handler2 PROC
% u2 f4 ]9 N& {) N; X7 f0 G( v    iret7 p3 F5 t/ ^) }! F) `
int41handler2 ENDP
5 G0 x' E! u3 c
6 |/ i! {+ ?6 ?$ Y1 K! z
8 G2 q, x9 x' A3 d6 s% w_________________________________________________________________________
3 G+ Q* m1 A2 Y0 J
. _& R' N* J9 W% e( p+ _9 o- F3 |9 a' u, m# m+ E) R) K5 c
Method 065 y( ^. h& T( `( x! u. u5 T
=========  H' }0 N% w  i/ O2 M4 W  l+ M
3 l1 f$ t" Y1 h% o( L
3 u& m* k, ~% o" N. Y
2nd method similar to the preceding one but more difficult to detect:! V; q* n& L+ r  P% U& r

7 h! e0 R0 C5 j4 x4 k
) C& A4 I) O- s# F8 vint41handler PROC% t' `* V4 j* Y
    mov     cl,al6 ?8 Q. L( Y5 j3 q
    iret$ a* E* P* a/ O$ u$ d
int41handler ENDP
9 O: R4 r- N$ O+ n! w$ u
: ]5 {9 D2 G2 P; e; v. S. |+ N  U2 h" D2 O( k' z4 ?8 k
    xor     ax,ax
9 M" P  C; y: a6 v- H7 q    mov     es,ax4 h5 J, r$ `; f& C6 N$ R
    mov     bx, cs- e* r1 S  ~; U$ h) H' k9 y) ?' N8 b, s
    lea     dx, int41handler
- s6 L. y2 k) z0 J  Q    xchg    dx, es:[41h*4], |8 h* o0 h( H5 s
    xchg    bx, es:[41h*4+2]
! d! |8 v1 W8 _( `8 B* K    in      al, 40h
/ ^$ j8 A- c+ n, _' F3 W+ ~( Q) W    xor     cx,cx
/ E1 G+ R. \( f8 W    int     41h
# d& j3 q4 @: c    xchg    dx, es:[41h*4]
. C& H) p! T9 }6 j& n! Q( C0 z    xchg    bx, es:[41h*4+2]
# I8 A1 s6 l( v/ y    cmp     cl,al
* l0 [1 z) b( N- v3 ?3 p4 G    jnz     SoftICE_detected' A; q* C. K8 t! |3 F
+ k( z4 M! j7 S: |, z+ }, h' u
_________________________________________________________________________
( p- I. I: D9 t/ ?  _( @0 A  b) s" _. ^6 ?9 G0 [5 h+ M% _7 v6 Q
Method 07
, c0 ^2 l! X+ B; |=========
; E' @7 w  b0 Z1 K; K" t5 ~/ B) f& f$ l  Y& b) ^' G
Method of detection of the WinICE handler in the int68h (V86)
2 L, E6 _) P2 S  }- C3 B7 m: E) ]/ m4 s) f, f2 y
    mov     ah,43h
/ D' C3 |- ^6 [* a" E    int     68h" ^/ x$ Z3 r& {: o
    cmp     ax,0F386h( \. a9 T0 {. y  G/ r
    jz      SoftICE_Detected( h5 p& h! j7 R7 A$ C
( }' D$ n) E( O6 Z0 @
9 y7 L3 M# d- \: k' u
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit- I& _' d! F1 `0 p
   app like this:+ `* G9 `) J5 V/ e
3 x/ @, a4 t# |' y* }7 g. [
   BPX exec_int if ax==68
9 @) [7 @* ^# K; o, [5 z, B' X   (function called is located at byte ptr [ebp+1Dh] and client eip is
+ g8 \# ?$ U9 x5 T   located at [ebp+48h] for 32Bit apps), A% v! }4 z$ l# P, t  A
__________________________________________________________________________
7 h+ Z3 J* Q6 _2 O, [" c. [
4 }' t2 i  l, Z6 m6 E6 b: {: F& T  e& a
Method 08
9 F$ K  y4 q- o5 Z( F1 e# |=========: q, N0 J( x9 b. T
4 |6 X8 P& o- ^$ H* H
It is not a method of detection of SoftICE but a possibility to crash the" K9 R) R9 e% j
system by intercepting int 01h and int 03h and redirecting them to another
4 a5 y: E" N4 G; ?$ J  `routine.
3 @: T: C8 p! n8 n6 P8 v8 O# e. NIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
0 F( K6 b+ v& X6 g& qto the new routine to execute (hangs computer...)
5 `) X1 H+ L! e7 x/ a
: T/ p4 q7 `% L) Z" b    mov     ah, 25h6 S9 n. E, ]8 Q# B# L
    mov     al, Int_Number (01h or 03h)
( Q  l8 T7 r4 {: v+ G$ J6 S3 q    mov     dx, offset New_Int_Routine- v. \& r7 J* [: s2 h: [
    int     21h$ z+ ]. \& V" ?- K4 v! Y4 [; |3 u! v
' @" a+ R# }$ Y3 N& i: W6 Y6 C- t9 z
__________________________________________________________________________( e) U* u/ f( ?# r8 e. ?' G

/ v! D1 l: [( \+ i4 ~- s! K: z1 vMethod 09
& H  q3 W5 Z1 }8 J) B=========
4 V) [+ }" ?/ z" ^
: S8 |! }2 h- m* Z+ {* r& o! q8 mThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
0 t4 g4 c2 K0 f  f: `+ rperformed in ring0 (VxD or a ring3 app using the VxdCall).
# S1 [9 o/ |! N# EThe Get_DDB service is used to determine whether or not a VxD is installed& Q8 L8 _* ?2 N5 A' `+ \7 Q
for the specified device and returns a Device Description Block (in ecx) for
# i# w4 K) Z  Z" tthat device if it is installed.- O) }7 ^4 a$ K7 n$ v8 x2 x
9 W! x# E3 d& |5 b' ~! [
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID3 X' v5 R4 g; r8 p) U$ `7 j
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-); F7 o' o- [0 l% H- {
   VMMCall Get_DDB
( e( y, {. Q4 u9 P# X' R: J   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
. C3 D4 Q& S' f2 d  T4 `
$ q3 H- b* _/ Y/ eNote as well that you can easily detect this method with SoftICE:, e- S( R* X9 o% I% Z7 R) L9 {, p
   bpx Get_DDB if ax==0202 || ax==7a5fh. ^; K: p1 D7 q; R9 l9 h* Y# b" t
( i0 A( X/ J, T# b6 R' Q
__________________________________________________________________________
7 {) s( {4 c' {2 b9 @9 O) V/ Z" g! R& B5 P) x
Method 101 h3 Z. [4 W* ~9 H) ]- N
=========# ~# @% X) e& g( W/ Z+ d

4 {4 K: i* ?5 t  X=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with  [. ^' t/ q- A$ v1 Z7 m
  SoftICE while the option is enable!!# a9 L: x4 Q; a
+ l1 B; ~7 U/ C
This trick is very efficient:
/ \6 i3 X# b  ^( ]; Gby checking the Debug Registers, you can detect if SoftICE is loaded4 }6 O, K, i" c* z6 @' F
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if, C7 ]4 c2 }. _: q3 n
there are some memory breakpoints set (dr0 to dr3) simply by reading their2 x6 L- c$ Q9 O: I0 T& k2 ^
value (in ring0 only). Values can be manipulated and or changed as well# P$ w3 e5 R5 l! W' B' s
(clearing BPMs for instance)
- I) t% K2 t$ E* ^* C. ]6 @" e
2 `" l3 M2 s; P) O9 D# O__________________________________________________________________________
: B+ e+ H: w. `' }8 Y6 O, g9 F' k# |% I# S0 Z5 }  |: X: a
Method 11
  D% ]; `3 d# }& ]% @) ~& Y$ W=========3 K* ?% e8 u3 L, m

: A2 C% J# h& w* S# H" W( m$ DThis method is most known as 'MeltICE' because it has been freely distributed
+ f( \1 k: K4 M. gvia www.winfiles.com. However it was first used by NuMega people to allow% W3 N6 r% ^* {) u2 M4 \9 F
Symbol Loader to check if SoftICE was active or not (the code is located! h* i+ x0 ?3 t$ P- [
inside nmtrans.dll).- X2 k( y$ u+ \* A; d

! j7 [) s0 y& d, b  Z) NThe way it works is very simple:
# F; |5 [8 r* x: \It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for5 C7 ]7 R6 I1 H$ g
WinNT) with the CreateFileA API.
: M/ D3 v( K; a. k/ A+ g' J
* \. V. u! s' U0 DHere is a sample (checking for 'SICE'):/ b& D) z7 v  q- }9 q$ q8 I
# o9 x* h2 f9 Q6 p0 m. Z. A
BOOL IsSoftIce95Loaded()7 M- b5 S  ]# w- y+ B) T
{
' U* d+ s* b2 Y3 u2 N   HANDLE hFile;  
$ a; [8 m& p9 R   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
+ m6 R5 @1 U$ R4 m* B, r, E  M$ Q                      FILE_SHARE_READ | FILE_SHARE_WRITE,
$ M+ [, ?$ l, S5 f. C! ~, A+ }                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
" D: @+ }; C2 x7 q   if( hFile != INVALID_HANDLE_VALUE )
" z6 r7 z$ T" }& R7 ~   {
8 j/ e4 D* x- M5 N* x# n- V      CloseHandle(hFile);
. J! l9 @3 G% ]4 Y# ^      return TRUE;
& ^) z+ a7 o7 H) l   }! V2 H, n" S9 J' P7 v
   return FALSE;
- [+ X  U7 [. M& ^/ M+ i8 A}6 t' v/ p1 B# x, ~9 r

' ~5 _$ o, w, _# q5 u' J+ {Although this trick calls the CreateFileA function, don't even expect to be
* s6 ~9 i' [& p- |) ]able to intercept it by installing a IFS hook: it will not work, no way!0 b6 c' L$ V3 \
In fact, after the call to CreateFileA it will get through VWIN32 0x001F8 F+ N* u* G  @; E' {1 Z6 ?
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
5 |* g; B1 v, {5 N8 kand then browse the DDB list until it find the VxD and its DDB_Control_Proc
, e3 p% S( I( Jfield.
$ `/ w- F2 z' U; [; W- S2 DIn fact, its purpose is not to load/unload VxDs but only to send a 4 C+ y1 ^6 u7 o% Q2 M( a
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
" \5 P3 ~% `0 d- @5 x% yto the VxD Control_Dispatch proc (how the hell a shareware soft could try) K3 I: \$ Y5 ~( {5 z* ?9 W
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
8 H( J% E8 f4 B/ G# c0 YIf the VxD is loaded, it will always clear eax and the Carry flag to allow* U" k( r& Q  I- ]: Y& g+ O
its handle to be opened and then, will be detected., q9 n" e5 {" D; V2 g
You can check that simply by hooking Winice.exe control proc entry point
& t2 U; e8 K9 |' vwhile running MeltICE.! B/ P8 Y% g% ?( w
* ^6 `4 c/ a) r0 V- j( M' l. o) n9 q

) |# Q0 @+ J$ \8 s" `: X: ~  00401067:  push      00402025    ; \\.\SICE
( j7 A+ x) S8 F3 z; ^  0040106C:  call      CreateFileA  N) H& @3 d, C) x/ B- ]
  00401071:  cmp       eax,-001
: x9 x$ o: q' n+ W5 l7 y  00401074:  je        00401091
- M7 x" _% T( s  G2 G: `+ @' t& y* W% g
8 g- e2 h$ x: c
There could be hundreds of BPX you could use to detect this trick.6 X* Z$ l) J: v- d5 J2 l6 O/ x
-The most classical one is:) ~( `# m4 _- w: n3 ]3 o5 a
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
- f0 e' t7 S6 G  q2 V4 P8 J    *(esp-&gt;4+4)=='NTIC'
0 T9 c& ?. J9 F4 B3 {' M% X5 \0 T8 @$ C: N* p6 E, h, `% q: E
-The most exotic ones (could be very slooooow :-(9 y+ I) o0 m5 K3 [$ ]% G/ q
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
$ [' X$ ]) v3 C* W( @5 M( ]0 P0 _, u     ;will break 3 times :-(. R  I/ J8 I& A
3 d2 Y0 B  b& C3 d) ?
-or (a bit) faster:
4 T' E6 [6 j( [" q- o. q0 _" F5 w, y' g   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
% w, m2 p. e5 ^3 a9 T
$ `6 F2 u2 w6 R   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
2 x6 P  r; e% o+ T5 V$ c. o6 r2 r     ;will break 3 times :-(
" E* l( _0 `1 r. r. E0 O. L4 a2 G, N( P  r/ W7 X# t
-Much faster:
0 {2 ~, f& B* c1 D6 y6 ^" T   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'1 y' c3 o/ |! J
  ]9 W& F$ J* f
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen4 E6 S; {" K3 N
function to do the same job:% H+ v( B9 J7 H+ B, B3 [
# B9 p( Z% V5 f8 F3 ~0 V
   push    00                        ; OF_READ
4 _/ w9 E9 x( D  E  D2 R   mov     eax,[00656634]            ; '\\.\SICE',04 H) q; r" X/ }# P/ u. d
   push    eax' E7 _0 p4 p0 s
   call    KERNEL32!_lopen
! O- p7 M8 C# s6 f  L/ h5 }2 L  u. o2 ~   inc     eax+ f) s, l/ r) R2 h
   jnz     00650589                  ; detected
3 o6 H- ?! |# a6 d5 E4 o   push    00                        ; OF_READ' u# B* Z$ n8 @! ~$ c
   mov     eax,[00656638]            ; '\\.\SICE'
' I$ q# L- f& A& i) G! ~8 M8 |* Y3 q   push    eax) `9 e5 e. V2 h) q
   call    KERNEL32!_lopen5 Q% c! K& Q$ p
   inc     eax
0 u: F1 H) P9 V   jz      006505ae                  ; not detected: {' j: B, Y0 I! y1 a: x
' T$ H6 l5 G5 C0 A1 S' R
  k9 s! G* s! e& o- E& S( r$ v
__________________________________________________________________________5 G4 k( o: M0 j6 l7 r
" p' Q, w5 h) P
Method 12
; y4 C1 _- }/ b=========0 _& L4 L4 y' q5 W! I  Q
" q% B/ @: J9 \) m
This trick is similar to int41h/4fh Debugger installation check (code 056 c, K3 I& ]' o8 U
&amp; 06) but very limited because it's only available for Win95/98 (not NT)- @' y2 m4 o3 \# {. n1 o
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.+ m' h3 x+ @, L1 x# D/ A' V

* z+ ~% P3 h, x1 {. g$ ~   push  0000004fh         ; function 4fh& b+ I5 |8 a; ~* ^
   push  002a002ah         ; high word specifies which VxD (VWIN32)3 w3 I  _: A, K8 n
                           ; low word specifies which service; S7 n1 M; r( n/ A
                             (VWIN32_Int41Dispatch)8 b4 {6 n# o5 A9 N) |& L& z4 T9 m
   call  Kernel32!ORD_001  ; VxdCall
# }5 _  p1 K2 |+ E& M+ d) s# h$ G   cmp   ax, 0f386h        ; magic number returned by system debuggers
4 s0 f  S8 T; M   jz    SoftICE_detected
7 M0 ~; h( }- j7 w0 H3 T* U
$ @, ?( ]5 K& H5 O% X5 [" _9 SHere again, several ways to detect it:
! z! b  C. l% P' X1 X( z: B/ V! X
9 a+ S) X8 X0 u. Z: @: [; q/ _    BPINT 41 if ax==4f
4 O2 c" f5 L* m7 f) Y) R! r+ X5 ~/ Z( N# F$ S- A8 P1 s& |7 Y
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one7 J" k! o- w8 \2 W4 K4 o) K

2 b: t5 Z! n3 H8 H/ g. E9 s+ D    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
$ u/ o% a/ s3 q+ b3 g' o+ l) m8 F) v! J3 J3 }" R: V/ ?
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
/ ~5 R7 C- y* X: J, g1 x% k- k9 X4 {! J
__________________________________________________________________________
6 w; F7 y0 |% ?: r
* _" ~) m# W; q! t3 e, o7 jMethod 13
3 H# _9 Z& z" R8 T  T+ I* r3 e' j=========, T0 J9 A( I6 {; J7 t: m

! E1 O7 m, L0 b  u7 u  G$ dNot a real method of detection, but a good way to know if SoftICE is
4 |0 i- ?- ^- O, q4 U3 qinstalled on a computer and to locate its installation directory.
8 v4 L) X% O: B# M8 zIt is used by few softs which access the following registry keys (usually #2) :
# ~6 L  I& G8 p1 D; p7 q& k( w! U% v
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
0 u" n+ n' a" }1 D2 ?0 d, R- g7 U\Uninstall\SoftICE5 Y* `7 o5 Z' Y/ z: h
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
- c% n  r% ~9 l6 @-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( j% c, n4 E6 R; b
\App Paths\Loader32.Exe' j) M6 x# H: p

, V, U, b5 h5 i" b. V8 n6 r
" M- _* c  t7 Q) g! {Note that some nasty apps could then erase all files from SoftICE directory
1 r( w+ ^1 T7 ](I faced that once :-() Q' x+ `, m* r4 m8 P

2 ?. T: f3 C0 j7 {' tUseful breakpoint to detect it:
  j% H/ o- V* B$ Q$ r5 f- L, k9 t8 P8 g* @; b
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
' n5 l1 o. J: C! k" M+ X- V
+ Z( ~$ w. p8 q- x& x2 ~__________________________________________________________________________
7 D# X% A3 X2 T+ d) I. I2 f$ z/ p! ?8 U( U9 |. {

0 l2 H) G  X  ~. v  O/ ~* \Method 14 * j: k1 B, a0 a, D+ ]: ?2 N  F
=========
" G& H5 x$ K& g# m! }8 x! Z
) g. L* c0 `4 w  Z7 IA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose6 J; [* \6 z' c/ T* V$ o9 p7 O9 m& U
is to determines whether a debugger is running on your system (ring0 only).- @( l. l- e& K0 R5 p
# I4 o+ E+ s6 O; O$ V# J
   VMMCall Test_Debug_Installed
% A& g0 q1 b6 t# n   je      not_installed# _9 p, D2 R; K
7 K) M  q% G! g" l2 U, T; c0 A
This service just checks a flag.3 @9 O/ P& }. s! B! O" V
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部