About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
  Y. `# P" r0 M8 R% H/ w<TBODY>) ^( w7 Q9 @  C& s3 }- q
<TR>
* o& E0 {$ T# i, ^6 P& K# V<TD><PRE>Method 01
1 s9 U. V9 M& X$ r  q" ^=========' U0 [2 w1 m- T4 t) q0 k) s4 ~% A

% z0 |, {5 o- g2 w6 p7 \This method of detection of SoftICE (as well as the following one) is" ]5 D1 G; Q, g. [) ?  M
used by the majority of packers/encryptors found on Internet.7 E9 C" s" d# z/ U  e* N) D- e7 D
It seeks the signature of BoundsChecker in SoftICE
5 O, s& B) u0 p2 S
' j( d  y8 v# U$ d  D* r    mov     ebp, 04243484Bh        ; 'BCHK'
, V+ d3 R$ w5 [, {! b# c2 M' S    mov     ax, 04h9 K, Q/ o( a1 y  [" t
    int     3      
; W( q3 ^8 G0 u* \    cmp     al,4
8 ]2 _& C4 n. d    jnz     SoftICE_Detected
  {1 Z/ `: ?: i" @  e8 o
1 {" z; j4 t+ g/ j+ K___________________________________________________________________________
! X3 r7 I0 t' [' k! S4 R8 `. P  @, F0 u
; o0 z7 y3 P* h% ]; r5 YMethod 02! K& {9 [6 F7 D7 E0 o
=========
8 R6 L* F& O& Z; Y' O8 s' H, K+ F, H1 a5 N
Still a method very much used (perhaps the most frequent one).  It is used/ ~- w' y8 P. x* L: h7 A# r2 [4 {
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,- ]! z3 ~, x/ C/ V
or execute SoftICE commands...9 Z% X! `5 F( _  `) i, l# ^
It is also used to crash SoftICE and to force it to execute any commands! L' c# g$ G% _0 O* [) m
(HBOOT...) :-((  ! J- A0 |8 q+ z4 u7 U2 O$ E

7 z. B. C7 f! C- V7 O. L1 k5 z2 oHere is a quick description:! e% E* h# X: h& A5 o) B, S
-AX = 0910h   (Display string in SIce windows)1 M7 v/ b& l  g3 W$ j
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
4 ^! h; g# n3 S-AX = 0912h   (Get breakpoint infos), U4 Y' g  w& D! T
-AX = 0913h   (Set Sice breakpoints)
/ n% H0 C  ]: I! g-AX = 0914h   (Remove SIce breakoints)% G8 {" B  f3 b$ Q# J! t1 i$ ?6 ^( r
1 z! t7 T- M7 U% [! `
Each time you'll meet this trick, you'll see:
1 a7 J! g# q0 o9 U: e9 G0 Q+ u-SI = 4647h( {8 q: R7 F" E3 f9 S
-DI = 4A4Dh
5 E8 O6 e1 X6 N' l2 mWhich are the 'magic values' used by SoftIce.
8 v5 ]6 G" K7 _) J8 w  W. s9 tFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.; G" H5 N, o5 g- m

% @! B; @1 @: w, a/ B5 vHere is one example from the file "Haspinst.exe" which is the dongle HASP
; S( i- U3 l$ W+ @# ^, E9 AEnvelope utility use to protect DOS applications:
, n, I: r- W! ^+ S- W3 b
+ f9 w0 n% N3 [8 K# _( t7 p8 E; [; h% ^; ^6 L
4C19:0095   MOV    AX,0911  ; execute command.1 q# a0 U7 U! l: [9 h& u, H
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).5 e9 s! d# p* f% g: f8 ]
4C19:009A   MOV    SI,4647  ; 1st magic value.+ ?4 c2 z0 c& o+ H% E! ^# v
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
! Y# `% C& `- g7 r4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
0 s4 J- U7 ~! \7 u& _+ c4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute; e8 j% Y  g% B5 N* V
4C19:00A4   INC    CX: E6 r  [: f+ k7 }- z% o( s& H
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute; a; w# e- m3 g: m  U
4C19:00A8   JB     0095     ; 6 different commands.. J7 m# a$ T; i/ x4 x- @0 N/ A
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.7 I2 s# M0 d5 O  \& p" O
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
6 z7 |; w) v/ d' ~# h. n- v) r6 n3 A2 O
The program will execute 6 different SIce commands located at ds:dx, which! M% x( S) ~& j7 I8 M, O" d
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.& z) |+ a) w4 j! {3 k
0 |0 e! D7 G5 P1 @# C) k
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.( V6 w6 B* h2 s5 L) C% I
___________________________________________________________________________; `" n! @) h& T
$ |: W2 J! ^' p6 t2 N
5 H' @! ^) v7 r* R( l! ^; U
Method 03
2 Z# z/ [: H& c- e=========1 d! z0 b; m& Z7 l: h+ P. @

9 j8 |* k2 t4 z# N! t( OLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
- I  K% n( Z4 g: \: o- K) D(API Get entry point)5 W$ J) }( m/ P5 L0 u
        
- r$ C1 v. t3 W. `% f1 P2 ~8 y. [+ b7 K7 W; h" h
    xor     di,di# [# N" L+ O. P0 Z( h2 ^4 [( h8 m
    mov     es,di& l, d: R) H) R( M4 K2 K" z
    mov     ax, 1684h       9 Y# j; S- u4 [1 A( ^0 |6 V
    mov     bx, 0202h       ; VxD ID of winice7 P6 k( c5 |4 Y# j# z
    int     2Fh
* j! x& P! N/ U8 A& Z* F/ ?$ t    mov     ax, es          ; ES:DI -&gt; VxD API entry point
3 C% U1 |! g( k5 k# o    add     ax, di9 N2 H& I% j' |# c- x
    test    ax,ax2 k2 Y4 G% S- h! m1 [& O. i
    jnz     SoftICE_Detected
; F' T5 C. c0 `! o6 D4 k) s& `! C5 K: q8 a
___________________________________________________________________________8 L0 ^8 _5 S  O

- |2 `! x3 K! o7 MMethod 04
0 `" I& \# n& W- Z/ r' T5 Y; j' s- ]+ J=========) B# g3 i, o+ B& Y0 v& G' z

* ^. F6 f+ u; |3 Z* y0 b9 ^Method identical to the preceding one except that it seeks the ID of SoftICE8 |2 G4 M! O4 |4 V7 d. v
GFX VxD.5 H( H4 D5 r$ z) b
% }, H. W$ c6 n2 p+ L% w
    xor     di,di
: u0 V& x1 F6 P/ T* V4 z    mov     es,di
  z5 l4 u! `1 H& e, ~, ]$ l4 Y0 w    mov     ax, 1684h      
2 t: ^$ B: \  _  J9 q: z    mov     bx, 7a5Fh       ; VxD ID of SIWVID- F" Y+ F) F$ h5 m' r
    int     2fh' |% \3 l, }6 ?; A
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
' {+ B+ O: v' i% y    add     ax, di
; a4 {" ~2 e# J( x% a$ \: i    test    ax,ax/ t; x( n  T" w  U; [) H0 t
    jnz     SoftICE_Detected
& F) R; z8 U* S$ F0 L& C2 Y
' @6 z0 J) a8 b: B% X: D__________________________________________________________________________8 a8 s9 P. R4 Q

* k1 p5 X+ m1 ]2 N4 q- B( T2 T, }1 M: [
Method 05
( g* ~( f% I4 B* H7 G=========
' C- B3 u/ m2 {4 J. q3 t( t( L. V$ D' F) P8 y+ N
Method seeking the 'magic number' 0F386h returned (in ax) by all system% J# M0 o5 X" ~' P. b6 q
debugger. It calls the int 41h, function 4Fh.
7 L. b" H1 t) VThere are several alternatives.  
) k" y4 S9 x, i& |& c1 n' }2 a1 Y/ f1 L1 q; `+ U, n& [
The following one is the simplest:# X2 d! a9 o4 A- g' ]; j9 E

* t* `' T2 {9 Y& Q( ^+ Y3 c3 S9 U    mov     ax,4fh
- Q3 L. K; B  N% q- Z" W    int     41h
. q; h3 W1 R: r+ D0 |, g6 `    cmp     ax, 0F386( ?8 P7 S( b9 k" R/ n8 q
    jz      SoftICE_detected/ \9 s8 R/ l4 W- M0 D9 L

- b0 y$ ]' M7 q" H8 U- \" [4 A9 L6 c
Next method as well as the following one are 2 examples from Stone's   z2 ~/ Z* w! [; v
"stn-wid.zip" (www.cracking.net):
7 j9 ?6 i# e' ~+ W" L  f# z# g- w) T  c
    mov     bx, cs4 h# \5 \8 h6 L5 ^: Y9 s
    lea     dx, int41handler2
/ V$ s) y& Q: E4 p4 x    xchg    dx, es:[41h*4]
7 q! e2 B! E2 i' u6 z    xchg    bx, es:[41h*4+2]7 d8 j$ }1 r7 k9 I: s2 e
    mov     ax,4fh: s! b( F: w* O& @% r+ `
    int     41h! f" r  T: @5 @# y2 }; @
    xchg    dx, es:[41h*4]! B* C5 A9 H4 V% U) a6 S
    xchg    bx, es:[41h*4+2], e) w. a0 R) i  ], H+ B5 w. n
    cmp     ax, 0f386h- a1 l# B" l& Y
    jz      SoftICE_detected
3 p! h$ X7 L% n* _9 w; X. p* P& G
int41handler2 PROC  i; V3 s: K3 H; ^$ {
    iret; z7 F5 a3 Q, ?# ?9 `9 [
int41handler2 ENDP
( Q, R- C/ o& B, t, R: _5 I& O  K# e0 K9 B6 D

; l  u: L3 h5 @: j6 u! h5 W0 }$ k% {_________________________________________________________________________9 M3 b& @2 I4 J) n
' s- c$ U  K0 n, K3 I" \
6 s, ]: [: T8 [
Method 06
* F  t/ ?+ g9 h* p6 X& B0 y=========
: A% A, W' p+ c: B. p, }6 G8 e9 N7 ^+ \5 l* c1 v

9 A1 e2 V( A2 ?# J4 p) \. m7 T6 w4 x2nd method similar to the preceding one but more difficult to detect:
; \6 W, e: Q, @% _/ {9 s  l6 u5 g2 I2 S6 g  a0 \1 v! Q
& _# J5 b, j- R- F3 A
int41handler PROC( g" s* {  i% [& k' z6 ~4 g0 f
    mov     cl,al
$ i0 [9 N- K  f' K7 I    iret. T! K8 ]! M1 R
int41handler ENDP
% n+ v* s0 c% T; u6 q# K) h3 w2 S. x6 y# h# L9 C  |

- i8 D# S$ S  g; E    xor     ax,ax% j6 T6 p) o; q. D! s- \, ?
    mov     es,ax" [. r% R* [- g2 ~- g# l$ W% q% w2 k" l
    mov     bx, cs
3 g$ Z" l1 S7 C/ I( Y    lea     dx, int41handler
5 j+ B$ j) q! u4 _: S4 W    xchg    dx, es:[41h*4]
% g5 }9 D3 h/ l$ b    xchg    bx, es:[41h*4+2]  w  l/ v" m: n+ X4 s5 J& E6 R- k
    in      al, 40h
( q0 w( j# k2 q* L3 A# H) X' \/ _    xor     cx,cx
) \! e  \( M8 F7 T: s, J    int     41h( y7 |6 J0 S5 r. X; ^( g
    xchg    dx, es:[41h*4]
; ]: e. f. ]1 B9 Z+ O% }    xchg    bx, es:[41h*4+2]
- X/ {2 n+ {; e9 ~# ~1 s( k    cmp     cl,al* B, H4 q: z: f4 N" g* ?: H( x% s
    jnz     SoftICE_detected2 E$ H2 ?, C1 B

9 E/ ~5 y0 r. O( L_________________________________________________________________________
: P+ d3 }! l# A1 F2 q( z* O
$ D; P% g" Y5 Q! F4 PMethod 07* O3 U" E! t" Z2 T0 c6 T1 E4 N
=========
( E, Z& M, J3 q% a* r
/ ~- N% n9 L0 OMethod of detection of the WinICE handler in the int68h (V86)9 ?' t7 U# E2 E' ~5 T
+ G+ T4 g! G# v! D/ t
    mov     ah,43h, N6 |$ b8 M- o  s0 H
    int     68h
8 E9 o4 R; H9 f5 K7 O, b    cmp     ax,0F386h
0 d6 M2 m' Y! x    jz      SoftICE_Detected5 w7 H7 e2 f$ s0 g, \; a

2 g2 C$ F$ Y1 P1 ^: K1 ?# Z- p* U
  X+ r" X- x- }- P=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
) }" v% a2 t6 r6 [5 U$ T   app like this:
- T8 C; m3 H8 z3 ^" R1 ^4 e! s2 s9 Z' h3 P) e' u# }, q% }7 |
   BPX exec_int if ax==68& y) J3 ~5 l* \1 Z' P2 g5 {
   (function called is located at byte ptr [ebp+1Dh] and client eip is
9 P2 `( `% s( S6 \( W" I   located at [ebp+48h] for 32Bit apps)
6 [- ]$ N; z: e- r4 s4 ~__________________________________________________________________________
% B1 v, v. N3 V
8 B1 n% j7 \3 G4 x( D, H
- {* G) Z! L# ~8 G0 d, @  [% yMethod 08
, e1 x2 f' E/ W: A. _6 l0 n% R) ~=========  W0 S1 H) I: X7 u

* A3 l1 L. ]0 d+ dIt is not a method of detection of SoftICE but a possibility to crash the
" d! p2 Y$ o. {2 U- Psystem by intercepting int 01h and int 03h and redirecting them to another
2 u; s) B% b/ w7 Rroutine.
. r) c5 F$ C/ Z' c3 o* WIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points3 n; u9 J: Z# \4 |% @( P- ~
to the new routine to execute (hangs computer...)! m& R/ E1 k1 i  T$ L/ j
6 s0 M' \3 ?2 I0 Z& j
    mov     ah, 25h
5 {0 O! h' l3 G, d4 t, H, i    mov     al, Int_Number (01h or 03h)
- y' L0 X: e5 `( K+ n+ c1 K4 v* K- |4 ^    mov     dx, offset New_Int_Routine
! N! g& f6 ]% Z& \' f    int     21h
/ W9 E8 F3 a3 ?' a% [, L9 D) |5 g
* h8 W: c: L% h1 _2 b__________________________________________________________________________% I# i: j1 K2 m/ H- N$ D

4 l; u! o+ r  @. g# vMethod 09
) t& }0 A/ X6 y/ Q1 G4 y=========
1 j* J9 s6 T9 Y! H# U2 `4 E% D- J! s2 G2 x3 h
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only) i3 V( d7 y( B; J( D, X
performed in ring0 (VxD or a ring3 app using the VxdCall).
% v. c2 ?; w$ Z, p# J$ PThe Get_DDB service is used to determine whether or not a VxD is installed
6 F; c* s- a! P5 Z$ jfor the specified device and returns a Device Description Block (in ecx) for) t& @. i7 F- L( u$ v* e% @( I
that device if it is installed.9 s' E) f* t- R( l

. ?7 s8 V. a  Q( V   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID' ]: k+ ^7 z1 G  F2 G4 q& a5 q
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)8 p  J3 z9 c+ t
   VMMCall Get_DDB3 P% @& ?" z0 R
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed7 f% o" ?( i' G& e

9 }( ~9 P& B1 P% Z! XNote as well that you can easily detect this method with SoftICE:: e7 J( v0 O/ c3 h9 d/ v$ ]9 K
   bpx Get_DDB if ax==0202 || ax==7a5fh
4 l  @/ z; O5 |* _( G  u) a6 I$ P
. x1 l5 |; ]7 V* n, x  U7 ?6 B8 \  b* u__________________________________________________________________________
# y2 F* w  h6 [% j" O) Y. \
: {# S/ ^' J9 N  N2 wMethod 10
2 A" t- R0 \# U) T* e4 Y=========
  w9 b) V7 }/ c! k0 {& F
* }3 ]: n: t7 b' Y' _+ m" a4 \=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
8 B' c4 o9 r' \* B! _5 ^0 z  SoftICE while the option is enable!!
5 [' w5 A5 t7 {- a8 U: ~8 C: e) \
This trick is very efficient:7 g5 a! |; B! ^
by checking the Debug Registers, you can detect if SoftICE is loaded  e4 C) b) P' T+ q
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if3 Z' ^: h* A+ u: D! ]8 X  R
there are some memory breakpoints set (dr0 to dr3) simply by reading their
" J; `9 S3 u. D0 \6 [value (in ring0 only). Values can be manipulated and or changed as well
  m8 W7 J2 H) ?" |& J1 f(clearing BPMs for instance)
0 S$ D2 h+ z- {6 _
9 [3 t, g7 b, p- D% c8 Z4 V# a__________________________________________________________________________
( [4 I/ b1 D4 u  s. k& o/ i" U# Q( f5 i) I. W+ H$ ]
Method 11
9 @: o; g7 x5 F3 e+ K=========
% g0 c8 e0 a& q/ X* G% }% b! S1 N) I+ ?; M3 T
This method is most known as 'MeltICE' because it has been freely distributed
) y0 e& H: G" I: h' E  K; D: ^via www.winfiles.com. However it was first used by NuMega people to allow
# v5 d. @" E0 USymbol Loader to check if SoftICE was active or not (the code is located
* H2 w! \, @6 _2 F4 @; I4 M% d$ Qinside nmtrans.dll).5 S3 r- y7 P' N6 t. E
' z: ~6 |! ?; J' q" w& W0 h* k* {% R
The way it works is very simple:
* Y  @. t: e  x9 L' L9 f! M& sIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
6 ]+ f5 |' K( W0 fWinNT) with the CreateFileA API.
% z( V8 Z( \. n8 B) \9 h0 V& r0 X
Here is a sample (checking for 'SICE'):( M0 G4 a, U/ ]* H' h/ ?) V& D& z' D

7 e  ~' O( P# B9 O% SBOOL IsSoftIce95Loaded()/ S3 F  v$ `) @* p$ [$ _6 c" @5 M
{. f0 w; l0 y" }; I3 ~
   HANDLE hFile;  % E0 X' g  P3 h0 i4 I) z: f
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
  N! }( r8 p/ I* x# d$ e                      FILE_SHARE_READ | FILE_SHARE_WRITE,$ b& a: m  Q0 z% L+ U  X
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);0 o3 d0 x# T6 w# Z
   if( hFile != INVALID_HANDLE_VALUE )) j2 d( }$ \( T2 r
   {
: [; {. v4 G. N  o- c' X      CloseHandle(hFile);
6 ~, O7 m* _) w4 g      return TRUE;' W. g0 i% k9 U4 O. i
   }9 i+ h2 Y$ n& D. _+ j' r
   return FALSE;
' @/ e8 d. G5 _/ q& h}+ ~+ t; h- L3 }

! `$ M. `% k8 E5 gAlthough this trick calls the CreateFileA function, don't even expect to be
/ u0 c5 t& E8 ?; P1 K- jable to intercept it by installing a IFS hook: it will not work, no way!
& ^: o; T* O& Q/ y: J7 e9 E- K' eIn fact, after the call to CreateFileA it will get through VWIN32 0x001F% e; G0 Y% C9 ^4 F+ ~8 }/ ~
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
2 U8 `' i  x6 o/ ?/ S- eand then browse the DDB list until it find the VxD and its DDB_Control_Proc1 d5 t% X& e3 n! U0 _
field.6 ~/ v3 T' b5 `9 ]3 L9 ^  K/ [  x
In fact, its purpose is not to load/unload VxDs but only to send a + s# o0 T  v+ T5 c4 K* B$ _3 [" j
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
0 F0 \2 ?- M; Pto the VxD Control_Dispatch proc (how the hell a shareware soft could try
0 L' G& Q- l7 n" i. M: z; R. d7 H7 wto load/unload a non-dynamically loadable driver such as SoftICE ;-).
% I8 U1 ~2 a. P: [1 lIf the VxD is loaded, it will always clear eax and the Carry flag to allow  ]- @' v8 ^' x3 z2 X
its handle to be opened and then, will be detected.
, L2 U3 G1 k& b* X+ I9 d8 RYou can check that simply by hooking Winice.exe control proc entry point2 ]# K# X" u9 K. E
while running MeltICE.
% X$ u' h  i; j7 @9 }1 J" d
' G4 c2 Y3 _* z/ Y0 [$ |9 k
9 J1 }- E* a; [- ]- |- a1 d) J" e  00401067:  push      00402025    ; \\.\SICE
/ I# o: q, ^# n" r4 B  0040106C:  call      CreateFileA. S: R8 B& j, F. y& E
  00401071:  cmp       eax,-001
0 [% {# }1 |* H! p) P  00401074:  je        00401091
- j3 X; k* \0 U* x  [  g/ k, F! c( S, T4 y* K3 T

4 V% y+ Y, ^6 i9 N4 }There could be hundreds of BPX you could use to detect this trick.! n& `9 v5 B5 X9 P: ^
-The most classical one is:& |4 U' r/ T4 q( @
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||) i5 c9 U6 _( w+ G
    *(esp-&gt;4+4)=='NTIC'+ B4 |2 c' Z1 F! m4 Z
" E4 F6 p1 V6 L  n6 I
-The most exotic ones (could be very slooooow :-(3 a/ N7 v- m$ k! U, w* q" X
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  # q, H6 w) H4 q# i$ F5 `! R) W
     ;will break 3 times :-(4 J+ B* h' v+ Z, q" J% t" e

) _, v" y: f) ?4 Y1 B-or (a bit) faster: ( ]3 W; L% H% ?' S& f  ~) b
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV'); S& e5 y1 c- \
, s9 r, B$ \' r6 _4 o' c2 `9 t
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
: P1 O; f: f* [* A. X5 A5 d) i     ;will break 3 times :-() d( j3 y7 z1 F6 [5 s
. B5 r/ `; A8 Q9 I" p
-Much faster:
3 J. e% q, P7 o( [9 }' @! w   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'! t% ?5 a4 T5 S0 M9 p: S
4 t# @( E5 n# H' C8 g# n2 `* e
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
+ \" i" Q4 V' L; pfunction to do the same job:3 K2 q! r9 V- ?- b' V4 {  e
' ?  p% t- P6 U. ~% H7 N- j
   push    00                        ; OF_READ2 L5 I) f4 @( l& s$ `2 l6 b* k! @
   mov     eax,[00656634]            ; '\\.\SICE',0+ a! ]( x8 |+ f4 i& [, d8 B2 ^
   push    eax4 O2 R) o1 c; f* M1 m) t5 |
   call    KERNEL32!_lopen- n% a/ H0 {+ C
   inc     eax
, K7 R+ v/ G! ~   jnz     00650589                  ; detected
) K: L# v2 D2 H4 t/ p   push    00                        ; OF_READ& b7 U, A& o& k; s4 Y' F: [
   mov     eax,[00656638]            ; '\\.\SICE'
2 n2 ^! |, h0 c* Q- V5 }/ I& ]6 r, }   push    eax
, D, K! W5 q  b* n" c8 k   call    KERNEL32!_lopen+ v' {" E, a, S# @
   inc     eax# c* z) p: Q- x
   jz      006505ae                  ; not detected# T7 i/ w' x! ?4 j5 K# _( T
( S, }% q/ K7 e$ G) K7 o4 N6 I

- `$ u# o  E( i$ S  [7 @__________________________________________________________________________
, B* `- l& y  l$ O
0 q: C1 c/ \3 G2 \% Q/ O4 M0 bMethod 12  {8 w5 O: g1 F+ q- V5 m) z( c8 G
=========! d3 p5 n/ |1 G" g( \  U

3 ^" \, k4 `/ C9 [$ ^9 D" LThis trick is similar to int41h/4fh Debugger installation check (code 05- Y& M$ q; G! o- T' [! L6 M& M
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
+ }6 l; R+ {. B7 ~, Jas it uses the VxDCall backdoor. This detection was found in Bleem Demo.' B) j0 x) P" n$ w, C% Y
3 x/ H% n- G6 P9 G9 V# G
   push  0000004fh         ; function 4fh- ~" C/ s  [+ e" v
   push  002a002ah         ; high word specifies which VxD (VWIN32)- k# A9 l( d9 V7 J$ P' z
                           ; low word specifies which service4 ?% t4 \$ K# B1 o& {
                             (VWIN32_Int41Dispatch)
  f" z/ X0 h( E4 Y/ `, ?: Q   call  Kernel32!ORD_001  ; VxdCall) e# P. n5 `; l2 m
   cmp   ax, 0f386h        ; magic number returned by system debuggers4 q' c$ w' R  g$ K+ X/ Q1 ]
   jz    SoftICE_detected) M5 ~0 g0 @) {4 P$ T+ n

5 \8 x1 K: V7 x5 m1 k" lHere again, several ways to detect it:
+ J; p3 W8 b  W' }6 ~; {
! x- w0 C/ @$ M$ x% i    BPINT 41 if ax==4f
, q9 R: P0 T% L! A2 t5 X4 F. O9 J, e( e+ y% S0 }3 d
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one" r/ s: |3 @* Y# _$ i- J

( }. T6 ?" V% O* j    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A" H! |  X: _% Z5 ~

. C* Z* N7 w: J7 U' Y- l0 A2 _    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
: D$ y# o: m, Q) R
. J/ f' h8 D. M! {- ~3 I6 F__________________________________________________________________________# d0 Q6 d: D" a! j( }9 A) o, U. M
" ~3 `1 ?: w6 _% f+ K
Method 13
9 e" {/ c) f  [1 |=========
. d6 r6 M  |5 p4 D: u6 F( `; N6 f2 p- J7 H$ H7 j* T' E2 n, R
Not a real method of detection, but a good way to know if SoftICE is3 P: N  J; x. l# c
installed on a computer and to locate its installation directory.5 W, {9 ^8 {" w$ E7 d& e6 I
It is used by few softs which access the following registry keys (usually #2) :/ {+ V+ v6 U5 s0 G" V
4 G4 Y7 s  [7 X) O3 U
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion; [4 C) U# Q7 Y9 A& r7 Q$ P- X
\Uninstall\SoftICE
/ _5 ~4 M& e4 u) H4 s2 Z7 _) S-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE3 t9 G$ t/ s( ^4 R/ i* X. ]: [" D
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion& M& s% F: H. P2 N
\App Paths\Loader32.Exe( i0 i0 r+ M8 e; L

6 i  i* Z( J! H8 q
4 o1 I2 s. S. F6 v/ O4 h# mNote that some nasty apps could then erase all files from SoftICE directory
7 A; g! k# ^; R(I faced that once :-(
$ F. A" O2 C% A4 ?6 `' j1 Q  `' T, y6 A
Useful breakpoint to detect it:
% ~! z) V: s9 L* _
  ]% Z4 x! l6 e1 e6 G     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
, ^- s4 z% h. t$ O/ n( I; S# ^6 U; R& O
__________________________________________________________________________$ o! \# f' v3 |( V1 o

/ B# ?8 W. \9 A' _) `, G  w/ i" Y  e! k
Method 14 ; S6 ~" i/ M) P3 _
=========) m8 p1 g, l8 ]- P1 s" c
: r4 S2 G: W/ Z- g
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose. O, `9 w6 o  V# C" d! q8 W
is to determines whether a debugger is running on your system (ring0 only).4 j3 b+ V. W& D% [1 |2 }7 [
9 K5 o- v+ `+ @8 V" w
   VMMCall Test_Debug_Installed
0 \% m! k+ ?: t8 w6 q   je      not_installed
6 T" }1 d; t: b2 P% S9 y* x$ J5 G2 W! ^; ~
This service just checks a flag.
; f( h3 c( ]/ h5 c% `& j& e9 s</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部