About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500># ^, e7 T3 U- [
<TBODY>
5 w: n8 Z# Q1 h5 z: ]<TR>) j( O7 n2 H/ m
<TD><PRE>Method 01 9 s' S. a, Z0 W% C; f) I
=========
* c# C8 l" P, X1 l" C! Q5 t3 _# w) g# G, {
This method of detection of SoftICE (as well as the following one) is
( j7 ^# M# R4 t  a  iused by the majority of packers/encryptors found on Internet.* D! L' v: m! D! Y+ R
It seeks the signature of BoundsChecker in SoftICE
. l6 V/ @# V( q
1 S0 r; s5 W/ z8 P, t0 O8 Y1 E    mov     ebp, 04243484Bh        ; 'BCHK'
. J7 p2 }4 L) }    mov     ax, 04h+ h+ ^+ n( S, ~# V4 G: T' x
    int     3       " f6 p3 ?9 C  Z7 p8 H
    cmp     al,4
' b# ~. S& }+ W/ X    jnz     SoftICE_Detected
% Z  Y, @! t$ q2 l. V2 ^- x9 k  `2 ~9 M
___________________________________________________________________________5 x, {$ x6 o. N2 z& Z6 X
) T/ P1 z. M+ h+ B  u
Method 02
* s0 A: L4 z( y9 W=========
" g% A8 {! W/ [: b. i* F& i4 ~  ?& N; v
Still a method very much used (perhaps the most frequent one).  It is used: B  \+ ]1 u; U* |- y! P9 u
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
9 T2 o5 F* e$ l, a* I/ z( n5 i" q/ kor execute SoftICE commands...! x6 k# L, y2 P2 D
It is also used to crash SoftICE and to force it to execute any commands, {7 \  i% s- ^) e& g
(HBOOT...) :-((  
# \& {) Q4 d; ]: ?' k" O  ?  D4 j  {9 m. [( `; x, q& N4 |
Here is a quick description:
# G2 X8 R) S5 t3 A; y# @-AX = 0910h   (Display string in SIce windows); Q  M8 J2 }& {/ I& m
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)+ M: _2 F# d1 J' A# e
-AX = 0912h   (Get breakpoint infos)
6 B1 n5 G1 U2 [! N9 Q: P-AX = 0913h   (Set Sice breakpoints)
8 P) W3 M' H( t/ G' r-AX = 0914h   (Remove SIce breakoints)$ Z7 y" c! s6 _5 O' J5 P

9 ~: H  Z8 `: A5 d$ W. HEach time you'll meet this trick, you'll see:
$ C  X4 H% `  \5 s  B. ~5 B-SI = 4647h
; a0 p/ ]: i. W3 E7 O1 k-DI = 4A4Dh
$ x$ u! M' f) @, I3 q9 X' x8 dWhich are the 'magic values' used by SoftIce.0 u, ?  I8 b2 W" z. l1 e
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
# c/ ]  P. O6 f# X6 A. [. m8 G& W) R0 r
Here is one example from the file "Haspinst.exe" which is the dongle HASP5 j  `" L$ T0 T& x. i; c  p8 S
Envelope utility use to protect DOS applications:* \5 @) O8 V3 p; z: o

! a( K: o" U. ~4 Q. C8 E: w$ [  N
& w$ j: y  g, S6 z+ C' @4C19:0095   MOV    AX,0911  ; execute command.
3 ]( p$ Z0 [) m' e& C4 s7 E4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).& z4 E7 K# t$ o. j7 f
4C19:009A   MOV    SI,4647  ; 1st magic value.2 L, p* {( q. U# @: j
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.: j& J  d3 e1 h! R- R- Z% x
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)6 j. G; F/ e" N! Y) j. s
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute8 K# o/ i8 R2 w& ]' g
4C19:00A4   INC    CX3 D- f# f" s& H/ J& b$ F- m. l5 D
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
; A, {' u' g& q4C19:00A8   JB     0095     ; 6 different commands.' m. G: a3 P! {* m: k
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
6 ~5 C" Q0 Q6 D; }, A# M6 J4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
9 E* M" x6 f" o, S) `2 G+ e! p8 d- {1 W$ ]
The program will execute 6 different SIce commands located at ds:dx, which
! @2 g2 q7 Z- N7 hare: LDT, IDT, GDT, TSS, RS, and ...HBOOT.' q( T9 T  w4 Y+ @3 _

0 T6 v. z9 ~! ~* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
6 m% S7 U; l/ b2 `0 H% h1 x. v5 e___________________________________________________________________________
3 y' O4 \# `8 J# A4 ?' j# _8 R1 S5 @
. Z3 S( u$ `3 ]8 k+ q- E
Method 03- A% L+ {/ F; E0 ]) T9 n
=========
# J& e& K9 U- J, Z1 D% O! n% v2 S) |+ f: z, ~) t
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h  t) k# `# V7 ~( c% H7 X
(API Get entry point)
/ H8 K7 ^1 E# P% V6 T% r* o$ J        
- p0 G) C. Y$ U& u9 c2 N8 i' I: A9 E# ~; d
    xor     di,di8 u4 Q2 K4 U% F( j  g% e/ z) v! D
    mov     es,di8 S1 `4 D- d$ A* p, C8 O
    mov     ax, 1684h       4 n, ~$ @/ C2 r8 e% v3 P, J
    mov     bx, 0202h       ; VxD ID of winice
/ J9 U6 Q# X# }; x6 i$ ?    int     2Fh
" B& K. N+ b8 {! c8 ]    mov     ax, es          ; ES:DI -&gt; VxD API entry point
: `% U" F! t) J" b- {    add     ax, di$ S# R' l' a& s, X+ |; `1 {& F
    test    ax,ax
" U( }  S2 b4 p8 \; I    jnz     SoftICE_Detected
" [. A' _8 o. P9 k, _. A& J% o1 U* @; j2 n
___________________________________________________________________________7 t+ `  Z. H# b, R3 ?) v3 W/ u" H

3 u7 I0 B1 C7 hMethod 04
& N% _& k1 S. y+ w1 n=========' x6 }2 x' L$ _0 T/ Y
3 i! c2 }$ N4 F; l, |& |
Method identical to the preceding one except that it seeks the ID of SoftICE) l( u' D- K- s8 V/ h/ t2 H4 l1 Q
GFX VxD.
+ r& X" i& x) Z/ s( J* V9 a
  K& O; q( _) i: n0 S& {  q    xor     di,di
, m- ]6 w8 l" x! |    mov     es,di
# Y. n4 K4 z' Y3 b6 G    mov     ax, 1684h       3 }4 U2 t! T5 d% \1 z: t
    mov     bx, 7a5Fh       ; VxD ID of SIWVID( ?4 F5 w/ u  w2 Q, a
    int     2fh
$ A% j: p8 t& H    mov     ax, es          ; ES:DI -&gt; VxD API entry point5 ?6 K- E$ p& o# x$ i, n, T
    add     ax, di
  p+ O; U3 @. T' A% y7 D4 S0 k    test    ax,ax7 r% f% w; M2 N' A0 h/ i
    jnz     SoftICE_Detected
" x- u8 ~4 B% ?+ ^
# l7 b3 Z4 J! |7 }; {+ K__________________________________________________________________________3 w% O/ R1 T& b. i. m3 d
" n% b5 b# E( ^* _7 K6 \& O

6 I9 i) r" S2 z2 y8 `" \Method 05
) l9 C% w- I$ r. m$ C=========9 }4 V. y. `# h( m

1 ?5 t1 s+ V4 I$ n/ C: WMethod seeking the 'magic number' 0F386h returned (in ax) by all system
9 z, g2 y1 ?- T/ B3 Fdebugger. It calls the int 41h, function 4Fh.7 Q. P# v* l$ y4 ]4 A
There are several alternatives.  
; _# g% G' J8 m! N# n- B% i- ?
* ^% n0 o( p+ ?) W6 PThe following one is the simplest:, I8 _* Y5 N2 V5 f
) |6 J. i; R& {6 @: u! [. A
    mov     ax,4fh3 u; B( d6 S7 J
    int     41h. D* i3 @' v  ]
    cmp     ax, 0F386( y" E% ]4 V( a% R6 D7 [) O0 R
    jz      SoftICE_detected0 e& ?: c9 E3 I5 S1 Y0 v% |3 D$ w0 p

# ~! y6 Q# f9 w* h) G: S9 Z9 e2 C$ c" @+ u& y; l6 c
Next method as well as the following one are 2 examples from Stone's
; A9 D& G& ^7 m/ t" d" L; y"stn-wid.zip" (www.cracking.net):$ D  ~6 n  W1 q1 Z, b

9 [7 x3 h3 j# L* E. b; a    mov     bx, cs9 h: D( i' e  D7 L' W) y" e
    lea     dx, int41handler2
$ \7 T6 H7 f9 E. R    xchg    dx, es:[41h*4]+ n% J' d# ]1 t0 }( K7 `  s
    xchg    bx, es:[41h*4+2]
  f  Q8 C, e0 Q- X9 m    mov     ax,4fh
* [1 ?* W' F0 \# C- ^) h; e. X    int     41h
; w% k$ m; D1 ~# E    xchg    dx, es:[41h*4]' e7 Z9 Q5 f- |
    xchg    bx, es:[41h*4+2]6 a) Z4 o; ~) j9 l6 i* z2 y  W5 @
    cmp     ax, 0f386h% `; m% L, F- K- J
    jz      SoftICE_detected" U9 |! g8 n$ U) n! D

( V7 Y; V7 c3 v+ p. Yint41handler2 PROC$ o) G) }& k; c- |6 m
    iret
' V' b/ \3 A/ [2 cint41handler2 ENDP
. {1 x9 c* J- j- p0 k8 l
4 T, ~! f; L/ v! @% M4 }: F8 A: f% p7 o1 o
_________________________________________________________________________. d& n6 m8 H' j" s
% N, P% \; L8 K/ F% x) ~1 F9 N7 z
- K. f# Z# n+ ^2 t  P9 |
Method 06+ i! w. }2 Y, l" B% T* z
=========
4 M# t* M( k0 L6 i
) c' G% E# a4 H2 G" P- d. q* f6 K% z, y, K! q$ {6 A& w
2nd method similar to the preceding one but more difficult to detect:
1 P+ Q) ?, v  k; h
! c2 F1 ^; B7 S7 h8 h0 x
! c: t# S/ ^. ~int41handler PROC
7 f. J' |; W, D1 E4 o    mov     cl,al
* w/ m- l% F2 m! k. s- ~1 S    iret% Y) n3 P* ~+ C9 ~6 E4 D* I
int41handler ENDP
% s6 {1 Z- f+ Y! v- A1 G3 R7 U* C( ]  [# B3 r0 q% \8 S$ o3 u, r

% J3 Y# Y$ x4 I" _5 \    xor     ax,ax
2 G( S2 p0 Q6 h$ a$ j  ^7 e    mov     es,ax
' x0 z* W8 w; d7 Z: e6 Z$ B    mov     bx, cs9 {: C- p$ q  P
    lea     dx, int41handler' @/ h6 ~2 F, i0 _# ]: m( [
    xchg    dx, es:[41h*4]0 }: ?# M# K0 b0 `! f6 Q
    xchg    bx, es:[41h*4+2]; n' K7 m9 U5 p$ P# l1 q
    in      al, 40h
8 i4 g5 b+ O2 @/ {    xor     cx,cx$ r1 x6 M7 ^' R7 E& ?9 P7 d
    int     41h  n5 P' w) q9 P# P9 ^3 V
    xchg    dx, es:[41h*4]
) f- N1 k* l  t* F; b  }  X    xchg    bx, es:[41h*4+2]8 j5 |7 y% e3 W8 N' g& }0 I
    cmp     cl,al
- ^+ v( b2 {1 \, H8 o8 a    jnz     SoftICE_detected
( I6 A6 }  {$ @; J: d6 @& z$ J3 f' K3 m0 Q3 i. c* e, |* r
_________________________________________________________________________6 _. R6 l* D5 x# X6 d

5 b0 Y( F* A' U/ k% J: fMethod 07
* J4 G1 t, H4 `- v=========% w1 g+ b+ o+ S' U3 N
; B' q3 K. u# p9 Z5 R
Method of detection of the WinICE handler in the int68h (V86); A* |( R/ F$ v% {
0 F! C9 p. {# @+ e  J. p
    mov     ah,43h& r: {5 _' b( o) q) u7 I  R. H3 C! x
    int     68h% {0 H2 D( @" U/ s
    cmp     ax,0F386h1 n9 t2 ]# Z8 |6 E' Y( I. F& q% q
    jz      SoftICE_Detected
. e/ g8 P4 K$ C( A& y5 q: J2 r
! Q! b. [2 N7 D% W$ x! Z2 ?
# r6 r; X$ Q% ~' g/ j9 ]/ {=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
7 }* p/ \7 Q+ g' ~* {  R   app like this:! o: N: ]4 Q1 V
. y1 L- a5 ]6 ~0 v
   BPX exec_int if ax==68
8 M. R" `4 a- O6 o" }6 e   (function called is located at byte ptr [ebp+1Dh] and client eip is. g/ g4 S, X, j7 l/ E6 Q- w
   located at [ebp+48h] for 32Bit apps)
8 R* Q$ b! z' c( K__________________________________________________________________________
8 S  \; ?) U( n* L, Z0 p3 l+ N$ K) [- Q# J+ }9 C7 n% @
* g% o' T. v2 a( v9 B
Method 082 y! e7 y6 [* T2 a7 t
=========) r# B6 J+ N: w

: x( X* c) S: zIt is not a method of detection of SoftICE but a possibility to crash the
: l' s5 Z. k  g+ l9 jsystem by intercepting int 01h and int 03h and redirecting them to another  q0 x: w) u2 T! v7 n. O  f
routine.5 `2 u; {4 ]& t3 o' A, G! F
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
* [' b  B/ `3 d5 `% ?7 qto the new routine to execute (hangs computer...)
) s! k# j* H5 U- F2 |2 _' O0 Q- C6 K# n7 N: }+ J! W" K
    mov     ah, 25h" I/ ?: B2 Q0 N$ B# E6 h6 `  }* a& T
    mov     al, Int_Number (01h or 03h)( W6 t" Y8 F( ?& o( |1 g; o7 N
    mov     dx, offset New_Int_Routine
' |( P4 }& M! O- H$ R8 l5 S; C# r* E    int     21h! t4 Z# y. D/ s: A, O9 f
, T. Q/ a7 Q' i6 K, t
__________________________________________________________________________- a$ a- F% o# P/ d5 i" R7 B
" Y" r9 L: i; a& o% l0 L
Method 09: `5 `+ o5 i7 D5 a9 v
=========
( }, a# Q' q6 j& [& c) p# b
% @( j. L" m- B- A2 e; a. WThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only# z  A  K8 g) d
performed in ring0 (VxD or a ring3 app using the VxdCall).
( z' c: i: D. h8 X3 vThe Get_DDB service is used to determine whether or not a VxD is installed
4 t7 M$ ]! Q2 ]) O2 Jfor the specified device and returns a Device Description Block (in ecx) for5 A1 y9 F+ a* `4 t/ ^: X8 l
that device if it is installed.
5 }# {* H& A( ^# X, ?3 F# }3 T* X1 b( ]' i4 a5 X8 Z5 G
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
& |, s( z" M0 Z' M- k: v   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)0 O' o/ b0 o1 D* [- y9 e
   VMMCall Get_DDB
0 V; O, E1 C) r) a8 v   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed) ]! s! t& ~, J8 Y: J

" k: @+ r- X! z& S- X$ tNote as well that you can easily detect this method with SoftICE:
& }, M) v6 q; {% l- b, k  B+ A9 _   bpx Get_DDB if ax==0202 || ax==7a5fh8 g  S, h9 i. q

1 Y' `) z3 b: X" ]__________________________________________________________________________7 v9 A; ~0 R; h; E+ a) r9 B8 u6 L
' a' H, V5 r7 f- e6 E
Method 10
" Q2 W& z8 [! ]  ]3 J( {% d=========
8 S& b+ J9 ~2 ~" ^  N) i. e
1 \* u8 |3 y- p8 d/ P0 c6 ]0 ~=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with" Y4 B" Q6 e: y- u  j
  SoftICE while the option is enable!!
9 h) X/ }. @6 C- _. |$ |- F* ^
" U6 M: z! m$ _0 t5 KThis trick is very efficient:% Y; ?) J. ^6 I+ {  C/ w5 F
by checking the Debug Registers, you can detect if SoftICE is loaded/ u! ?: a/ U4 x3 u
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
+ H# @- x! E5 }there are some memory breakpoints set (dr0 to dr3) simply by reading their
; C; o; }2 H9 Y, l' Nvalue (in ring0 only). Values can be manipulated and or changed as well  q" s' T9 @1 Z' |! C
(clearing BPMs for instance)
. E6 R; a; [$ b$ N! s
0 Y+ e7 b8 |: f0 z8 g$ M__________________________________________________________________________$ D: P3 Z$ U, O) E( V9 W
- x) N) A- f& o7 x' c5 O! n
Method 11; X8 o# t- s5 m2 K6 p
=========
, B2 l/ C& d* G' z5 x* [
5 B  c0 \- M, WThis method is most known as 'MeltICE' because it has been freely distributed
+ U: X4 r- N+ C7 N# xvia www.winfiles.com. However it was first used by NuMega people to allow
1 H" b% R% F' i  K  ESymbol Loader to check if SoftICE was active or not (the code is located/ d8 `. ~7 I  p- \7 |* u
inside nmtrans.dll).
$ L  K' |2 N1 u# `6 r1 k' P) _/ Q4 L
The way it works is very simple:
" M/ Q/ s! f1 i5 g, a. ?7 T( UIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
/ c( x  H( n5 PWinNT) with the CreateFileA API.
- |7 T8 X; `4 z9 Q$ f# F/ ?" Q+ N3 d# m- C. f7 K3 U
Here is a sample (checking for 'SICE'):7 A7 E4 n$ u% Q' E7 |3 U
/ {- ^5 O+ d" f
BOOL IsSoftIce95Loaded()
& U* o- Z+ ]( f1 W: E9 T6 d{9 A; o  a2 _: y/ t( O, `
   HANDLE hFile;  2 g3 S0 ^- Z0 I9 \8 Y9 s% g9 ?
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,, {8 K' f: J6 _- c/ w" ^
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
% p( ^. k9 H+ N* c/ v5 b& I                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);. V# T- O6 L3 A1 G
   if( hFile != INVALID_HANDLE_VALUE )- \* B8 P! p$ n# O; x2 X4 D8 [
   {# |/ L* @! Z* [. g# G
      CloseHandle(hFile);; r# p0 x' Y4 c3 j* _+ k
      return TRUE;
) D" J# M# N7 L& `: I  l6 T   }
' o; v- _) t5 p  U- x0 Q   return FALSE;: M1 M2 D1 p! M3 I- ?/ L2 i
}( Y9 q8 E) l6 R: b

9 B2 Y4 _; [6 V! dAlthough this trick calls the CreateFileA function, don't even expect to be! I2 ~+ L: k; i7 Y  ~& y! O& [: W' V1 V
able to intercept it by installing a IFS hook: it will not work, no way!$ `9 r+ |7 Z, g% C
In fact, after the call to CreateFileA it will get through VWIN32 0x001F' V, n" D! ^2 E( C, A9 Q! W( {
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)* }9 p6 L+ q* P& p) N
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
- L0 o4 \" Y( o+ j) l. r5 B+ yfield.
0 F$ ]) y$ F/ e4 S; d7 M; WIn fact, its purpose is not to load/unload VxDs but only to send a
5 o+ S/ T0 J8 N, ?: K5 ~0 |; Y! K/ q" mW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
; B5 {+ x1 M, Mto the VxD Control_Dispatch proc (how the hell a shareware soft could try
6 N6 }6 b  d% J& w& B% ]' z; o+ Y3 Uto load/unload a non-dynamically loadable driver such as SoftICE ;-).5 X' X9 M/ T7 F" C' H; p! W
If the VxD is loaded, it will always clear eax and the Carry flag to allow9 N* b, ~, x9 K( M6 e
its handle to be opened and then, will be detected.
1 }- f2 f2 h+ L: ^, qYou can check that simply by hooking Winice.exe control proc entry point
/ P. q) s+ v& _, R8 K# }while running MeltICE.3 c4 U% E! p1 N, ^' X3 M/ A
- h7 ?1 w6 |; G6 O4 [
% ?+ O5 {' o; p. m7 T" c" `% G
  00401067:  push      00402025    ; \\.\SICE3 {, I; z+ J5 c# b" t1 _
  0040106C:  call      CreateFileA( O# u9 }, V0 n5 |$ u  k
  00401071:  cmp       eax,-001
; l7 D: d! b$ v0 r: L3 ?, _* ~% R! X: ]  00401074:  je        00401091
' ^; w; ]! A0 ~6 p7 T! ?! `
& i  a5 `& j9 @# L9 D1 f1 n" e4 o+ h! |' v- F! Y6 E
There could be hundreds of BPX you could use to detect this trick.! l2 T5 a# J0 m  ?8 O
-The most classical one is:
7 \6 |! I- V# x/ P8 g6 S  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||4 r+ ?* a2 H4 [6 F6 H
    *(esp-&gt;4+4)=='NTIC'9 n3 G3 J4 D! t. e& q7 n
, R! y% D. n- C% A2 `; m% V/ \
-The most exotic ones (could be very slooooow :-(9 ^/ W  A/ k4 N  _7 r$ P$ M
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
4 e* u9 M' P5 E0 ]& }, V; u     ;will break 3 times :-(% R+ \( i% x8 W1 Y- n' l( S
' ?" ~; L  M9 K1 K$ E* Z! h  @
-or (a bit) faster:
" g" V$ }# F. c: c/ J4 _8 a8 c   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
; G4 |3 Z+ L9 O3 Q! J
/ N6 v& T2 [4 {) G2 p   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
' S) M" f/ i; k     ;will break 3 times :-(& O( z( m- m+ o/ v

; |- j$ @* d) t, p' ?2 o* `1 Y-Much faster:
, F) a$ e, v3 Z   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'  F7 w8 Z+ `4 H; O( B1 n0 G/ E9 r
1 G2 I3 j" p3 \3 t3 K9 U7 q$ R" i
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen" E+ s0 j+ `+ h$ g: c' q
function to do the same job:- O" C7 O2 P, l! B

* M) o) J4 L) F3 R$ g8 b9 _   push    00                        ; OF_READ7 j4 a. M7 _+ \3 m7 o) h2 R. u
   mov     eax,[00656634]            ; '\\.\SICE',0# R; R7 v4 [) x; o
   push    eax
( G8 Q7 I1 f  N) {+ b$ l, F   call    KERNEL32!_lopen  R# Z4 c- X# U
   inc     eax1 p9 f: N0 e& w
   jnz     00650589                  ; detected9 ?! n  u: [/ }6 |: `5 D2 H
   push    00                        ; OF_READ
1 C3 S# G6 U! z' ~* B: Z; o   mov     eax,[00656638]            ; '\\.\SICE'
& u: C7 D# H; M2 x3 Q) P   push    eax
# F6 g. c, P4 ^2 G. ~   call    KERNEL32!_lopen
) w( S. V- Q/ H9 ]0 `   inc     eax; A+ P2 S3 k  Y. Z$ `4 f6 ~4 a
   jz      006505ae                  ; not detected7 j. C% d! n5 a

5 U- i0 I( I9 Y5 T% O: J& u' ^8 v% X+ V
__________________________________________________________________________
3 f5 s' o7 c  g8 A) _
0 [3 W' t& H+ n" t  i  bMethod 12; t  B8 g8 n: x8 f
=========6 F3 C4 f6 A* E; J( `8 a2 z8 ~

$ W/ f1 \8 u. Q+ ^2 sThis trick is similar to int41h/4fh Debugger installation check (code 05
  ~$ y6 o2 ]4 w9 p4 z( u* Q( N&amp; 06) but very limited because it's only available for Win95/98 (not NT)" U/ Q1 L0 U" |% B6 e" F6 R6 g
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.
) d. J0 \: [4 ?; f5 f! F- h& S# R
+ s1 A7 m/ l3 s. o3 Z4 ^   push  0000004fh         ; function 4fh
' D; u$ e: `3 |3 `/ b+ p5 e   push  002a002ah         ; high word specifies which VxD (VWIN32)+ c* n/ p: g$ {' h4 e2 F/ \% y
                           ; low word specifies which service
/ w  f. o7 ?, Y0 S                             (VWIN32_Int41Dispatch)
/ Q" W% p- e" x, Z- q5 q   call  Kernel32!ORD_001  ; VxdCall
3 \8 E' j1 l% s5 [( c4 k   cmp   ax, 0f386h        ; magic number returned by system debuggers- L. F- j% p# [6 o$ T& {
   jz    SoftICE_detected2 C! _$ s) P3 C' q. \
& n! {3 ]9 q+ y" n$ z3 l
Here again, several ways to detect it:
, W; L8 \0 G$ k( L  \; S( X8 _$ G: d' {6 |
    BPINT 41 if ax==4f
: z7 n/ a3 U# u1 B* T0 n- x. i, T& O, D% z* d) X
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one# _) }3 y" Z9 G# G

4 o) y2 C. i5 r& v0 Z9 p    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A: S2 P5 H2 F& }* M% k6 Y) C. a6 L/ \

* G, v$ Y) p* C( _7 X  b  H    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!% X2 a( Q9 ^9 b' ]) m

1 ]% B7 B  X3 H+ ?$ \__________________________________________________________________________
* _( _1 @+ v+ ^. ?' y5 W4 T" W8 y. i, T: H4 M: y9 S
Method 137 U  f2 r8 j5 R3 Y  ^* M
=========
8 P4 S  M  M0 q) x% ?, N; U3 [5 @, K* }1 t8 }+ s/ b
Not a real method of detection, but a good way to know if SoftICE is! P# p0 q3 u& f! K* a0 Z9 D$ p
installed on a computer and to locate its installation directory.% G1 n3 b5 D7 e2 B% R! R# R- ?
It is used by few softs which access the following registry keys (usually #2) :& E4 u+ Z" I- R/ P* |7 J* @

9 ^( a) `2 J5 ?* h-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion' s# A, E: G' t- ^; ~. \! q. R
\Uninstall\SoftICE
4 w1 I- o1 }) w" r8 Y-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
/ v2 H; T/ u2 V2 Q-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
- I0 Z/ W/ J& o+ e( v% `\App Paths\Loader32.Exe
; Q1 w& I4 Z( _7 e( M2 {+ W( n$ \" g8 m( L  x3 }

$ p) e6 p/ R2 d# r- V+ gNote that some nasty apps could then erase all files from SoftICE directory- ~, h+ ~. G- w0 w5 l: q) U
(I faced that once :-(7 G* s: m) h  e8 r6 K
' _7 D: H) V9 R/ n9 ?6 I
Useful breakpoint to detect it:
' ~( _& w% l! B7 ^
$ f+ T) R7 C  _$ n" Z     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
9 G! j$ x% x2 V2 m
0 r& g, p) _! K3 p' x3 I3 W__________________________________________________________________________. Q& u$ u2 w( X
1 p* l$ s2 ~& k5 ^# w
! q8 w1 i- E/ M/ R1 c! K
Method 14
, c3 P/ P1 Z6 t- w% n& R. r. c* u=========$ ]6 Y. w. t4 \, l
8 M5 B" a* a- s- ]9 K! S* s8 y
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose! a; O7 Z( T1 b2 `) a
is to determines whether a debugger is running on your system (ring0 only).8 w9 ^7 y7 a7 z' p1 `* D% e
) P* I( E+ k2 B; H) x" l! _
   VMMCall Test_Debug_Installed2 R+ D0 ]3 n2 m6 s0 s' n* O) Z: ?
   je      not_installed
9 M1 c# M" m! d, q! ~& I9 Q; c' ^3 x! v) ]6 U
This service just checks a flag.
6 s7 W4 X6 i2 s2 P, w( N5 ~</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部