About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
8 u& ]9 U7 s, v* q  R* U' i9 {<TBODY>. Q# F2 o% c' r( \$ D4 ~
<TR>4 L, v6 b& [' B
<TD><PRE>Method 01
' y+ D- k1 b( g2 ]; H/ t4 y- m=========
4 c, m& J4 n: u) d$ L* A  I/ P0 t; q
! ?7 D, `% C, H+ b3 |! UThis method of detection of SoftICE (as well as the following one) is( ], R  j) Z1 f$ ^- x
used by the majority of packers/encryptors found on Internet.6 ]& T2 p4 P. g- g  C
It seeks the signature of BoundsChecker in SoftICE
" a7 @4 S; p+ y& _& X
% L" ]' A4 P4 O" N+ S( A* r    mov     ebp, 04243484Bh        ; 'BCHK', |2 g) f" L# L
    mov     ax, 04h
. V. |  v5 S5 _$ ^$ d3 A2 X' O" }    int     3       8 H& U( W5 H5 j& ^3 l0 Y( ?
    cmp     al,44 J7 ?5 e& w$ v$ H; F* F  R
    jnz     SoftICE_Detected
* V  p( ?  T4 z- j: I; S6 Q
8 K1 }, g& [5 e" v: [1 ~___________________________________________________________________________8 E; H+ q3 e+ }; E
* R" `& }+ H. ~
Method 02) l# u9 u+ R% Z$ k
=========
! v! E" J! P8 {, U* y  I1 d' B: S
  V8 a  o6 w! H0 M5 gStill a method very much used (perhaps the most frequent one).  It is used
( b7 r% z/ c9 l4 eto get SoftICE 'Back Door commands' which gives infos on Breakpoints,4 {# x1 {8 o* S. f0 I, e0 N
or execute SoftICE commands...+ s9 z/ P, D1 L, q/ U
It is also used to crash SoftICE and to force it to execute any commands
3 v# m9 p/ }/ J( ?, M& J(HBOOT...) :-((  
# o: b: y  |2 Z; R& G4 A6 z9 D2 G5 n' F4 g, M) I
Here is a quick description:
5 t* p1 W1 Q0 J-AX = 0910h   (Display string in SIce windows)1 ]* G, }: `1 x" n" c- Y
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
/ i- E5 F+ @! I! B7 O$ ^-AX = 0912h   (Get breakpoint infos)
* _/ F3 p, i2 i0 Y+ e5 }& }-AX = 0913h   (Set Sice breakpoints)
! Z- O* U+ D, {$ E/ D7 ^-AX = 0914h   (Remove SIce breakoints)8 s  ~! H! d. M

  o+ v) S& {5 [$ J3 @* cEach time you'll meet this trick, you'll see:
2 r. C; i& A! y, A-SI = 4647h
# O# a8 t. C: l( k-DI = 4A4Dh
. f, G& P9 d0 o/ u( M% B2 Z2 cWhich are the 'magic values' used by SoftIce.
$ V+ t% E3 o7 FFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.4 Q+ G  \; R- a6 a+ K# R' ]

2 `; j5 c; o1 e' Z2 e5 {Here is one example from the file "Haspinst.exe" which is the dongle HASP9 d+ b0 {! `3 }$ }& L9 [
Envelope utility use to protect DOS applications:
$ p( v# h% ~2 P2 M* B. s  j4 U
' n' {" {, H$ F$ w6 ?( J
4 e4 V+ \8 d# V, X4C19:0095   MOV    AX,0911  ; execute command.4 k% \; J8 n8 `' f% k1 r  O
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
9 O( l# u- Z: T( R3 L2 W& W9 a+ p& D4C19:009A   MOV    SI,4647  ; 1st magic value.
4 Y( @1 ~+ _+ e' u% @% e, S4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
; R& M5 N* N4 S" E! f4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*); l& O9 h' m* q4 j7 T
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
. H. U7 q: X$ ]# j4C19:00A4   INC    CX
- B! v- s; n8 L! `) b4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute/ a0 i( l, H" d$ o% {
4C19:00A8   JB     0095     ; 6 different commands.
" c6 H) [9 j. P) q; R+ d8 d4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
# |* Z3 C9 g2 P8 O6 m3 Z. P4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)& Z6 n  C# r1 j8 c- G' K
7 @, s5 T- w. }' V% {. W. r
The program will execute 6 different SIce commands located at ds:dx, which
$ C0 N3 o: U6 [8 F  @are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
5 s: |( o" v1 x/ `- g/ j, {0 V2 e$ ~  G( ^+ K. L
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
( }4 d, O% C& K# _* p___________________________________________________________________________8 Q/ X$ E* u( s1 S
% g& r/ k" G8 B1 M# o+ x

  z; ?% M7 P- y4 QMethod 03
5 }0 s# y' \% @2 R0 E3 s=========
2 j, M. p# Z) C  z& j- V
0 s/ y! F$ O  P2 [4 PLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h2 o* s8 F; x, `/ m- k: ?
(API Get entry point)5 z/ Z* w2 k9 r% ?% J
        
4 V4 h3 \% k% x  n) q
" n8 j' G( \6 ^# B6 [! P    xor     di,di
. a0 T. U0 a# D; T6 s) R* Y    mov     es,di* {6 q$ I( q2 @. q" s/ ~. {
    mov     ax, 1684h       # \3 ]# ]3 Y2 G- K
    mov     bx, 0202h       ; VxD ID of winice% P5 y1 Z( Q7 w! j
    int     2Fh
6 G' y, g/ H* n9 \    mov     ax, es          ; ES:DI -&gt; VxD API entry point
& X3 u4 i# c6 Z! I2 ~/ J( m    add     ax, di2 R# ~+ ~, W; l2 t& `
    test    ax,ax8 H; }  j: A* V2 p8 {& e
    jnz     SoftICE_Detected: H" U" Z7 S! q3 w7 a" Q5 l1 T% A
* y9 R( T8 H0 `% U/ m
___________________________________________________________________________
  o3 b2 q1 T) k  n2 }% k
' J% f9 s" x2 S5 qMethod 04
. l) d, n3 U. W* k; ?; m  t=========
& ^6 W; r. o% I8 d3 [0 M: I. g- s, }3 k
Method identical to the preceding one except that it seeks the ID of SoftICE
# ~% U/ Q, Y* `GFX VxD.
  C  K) o. D* n1 Z" P4 e8 b5 P# H9 U, ]  O2 P5 K: `7 N
    xor     di,di
! C( K% B1 T. K    mov     es,di8 a( ^7 b& q  H+ l' L- L# I
    mov     ax, 1684h       , Q0 O0 F# M2 {6 [) G
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
5 L& M( Q9 O& @8 i    int     2fh+ N; N9 @, W) g3 N) i" T/ e
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
- _5 B7 Q6 T0 K. U8 R: K0 b    add     ax, di/ C; A0 S* _4 B
    test    ax,ax+ k1 k6 A) U8 [' ~' q: f  k
    jnz     SoftICE_Detected. N6 |5 G8 z$ V

5 P0 U! H, Z$ F$ ^* r__________________________________________________________________________2 h3 L7 w: Q, S/ r2 L
& D' S9 L* s1 m- x# k
% S' B) B7 C( G$ ~) q
Method 05/ F3 {! y) w+ T
=========" J! k# m6 j: b7 r1 T# v8 D# C
2 q" ~, |( R' @0 g
Method seeking the 'magic number' 0F386h returned (in ax) by all system
7 T- s( u# n3 f. g* ?debugger. It calls the int 41h, function 4Fh.
! @& n0 |- D' {2 K( Y& E  y; ^) U7 ]There are several alternatives.  
' \2 T/ r! h, j" G! J" M9 R# P, y8 F+ F1 Z' H; |- f# k7 ]2 a6 A
The following one is the simplest:% v2 P6 ^& _$ v" Q# r9 t

3 Z+ S( q( M6 J+ J/ h# L    mov     ax,4fh
3 x8 l& S* y: H; E8 ?% O# c. w    int     41h2 \2 y9 x9 [$ e) `
    cmp     ax, 0F386
+ f6 n2 i! V  F5 N- O. j: x    jz      SoftICE_detected( L' z3 W3 {3 O
9 s9 O) {/ g) |( ~3 Y2 F8 P

$ z1 H% v( Z* D; q3 i- C9 SNext method as well as the following one are 2 examples from Stone's 1 _$ d- x3 [$ r: \/ p# i$ d. L. N
"stn-wid.zip" (www.cracking.net):
2 e# r" f' Y6 T3 Y# X: W/ S# V( s. K# v) p3 K) e) L% |; V
    mov     bx, cs1 \/ j0 l1 m  }/ W7 z
    lea     dx, int41handler2
) |8 W( j$ D* I* y8 R" b6 p  }    xchg    dx, es:[41h*4]
, q% u) }  V) }6 x4 |    xchg    bx, es:[41h*4+2]
2 b# o8 `5 J+ n  H: H! T- [5 f    mov     ax,4fh
! x5 ]2 F  W5 ^0 |" r1 p# y    int     41h
# }! w: j; ~; h3 ^    xchg    dx, es:[41h*4]: M5 ]- Z" d2 h- L4 M
    xchg    bx, es:[41h*4+2]! p2 C+ @/ X! \( Q- Q7 d' W
    cmp     ax, 0f386h! P) ~8 s0 y0 N+ W3 `; @1 l/ N  k
    jz      SoftICE_detected: \$ H$ \$ O1 i% L: R# A

3 C5 T; @. A. Q8 {; ?int41handler2 PROC
' h5 m" v- K  W    iret$ V# [8 H( e' r0 s# V
int41handler2 ENDP5 A  Y4 d8 D# E6 [

% W9 L: f$ s0 A* K
# F9 z1 o1 ~8 D+ Y_________________________________________________________________________
9 [9 |# g' V1 a! T4 _+ u( M7 J7 y3 ]% ^* Z- r2 F
  }$ I& N; n, R3 \
Method 06
4 a. u7 D7 i1 s1 p& T/ n8 |=========
# n1 r# A+ q7 t! u' e
( Y) {, G/ f3 @' [$ ?7 ~5 L+ I1 [; F/ P/ [& I1 `
2nd method similar to the preceding one but more difficult to detect:
3 E3 }( M0 c4 B; x1 u2 S
1 ]; X9 n" L& U% v% W( \: N  [3 p1 F( z# w" l. ~
int41handler PROC9 {( y. j3 {2 J, w4 H: e1 k
    mov     cl,al
( ]* m* j: X& j- _3 V' w( H) Q    iret; N9 D* n) @0 T+ R& F
int41handler ENDP
4 J8 Z: f: d  }4 c
: k9 Z: n8 I, M1 C4 V% h" B, E# Z8 N2 |7 F1 V
    xor     ax,ax$ Z2 P1 F8 p  P% b/ q" P  x* U
    mov     es,ax; W  ]& l1 Y! j0 J8 A; A* \
    mov     bx, cs$ O( t& E* S( {
    lea     dx, int41handler5 ^$ {+ M! z, e; `; D0 h
    xchg    dx, es:[41h*4]
7 s3 q. M) b  O; L, p7 M% v    xchg    bx, es:[41h*4+2]
# T: _: K: }, [! ^4 K8 j/ C    in      al, 40h4 Q% Y3 L0 t' Z) I! x* x) M
    xor     cx,cx$ h; t3 `5 X6 L$ a' C! d; e
    int     41h
. Z/ [/ [* x: }. I7 \    xchg    dx, es:[41h*4]
' S  ]( f& U8 o% ?! g1 \    xchg    bx, es:[41h*4+2]  m0 Y3 v+ I$ E" M. S! H
    cmp     cl,al& x/ G( }0 W# X! X; W
    jnz     SoftICE_detected
* h' G+ V: g% c. O' b$ e) ]- ]! h' R
  {5 s- H) P8 @7 E1 b: E_________________________________________________________________________- n: M7 I1 v& x, [
2 Z5 y* Y+ Y+ _; y8 f7 j* g
Method 07# V- i' I0 _% s
=========, l( H- d7 [) ~( N  v" t- D' Z  H2 J
3 O. B5 h& Q" \1 d  L
Method of detection of the WinICE handler in the int68h (V86)+ b; o9 d$ k; z, P( S+ L4 [  A& z, [
/ }3 P7 t. W- A
    mov     ah,43h
6 T$ L0 p# e: G: u# {6 g    int     68h
! r; N2 T+ v$ K9 c- G% w1 e    cmp     ax,0F386h
) a& c/ v( \5 l" z1 O! ?    jz      SoftICE_Detected
& m, [, e" D- w4 p
! J, v/ Y1 M% H
0 b! r' w" i0 m+ M/ V3 Z=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit% o- H+ Y7 _. y2 z2 Q4 s
   app like this:  k6 O0 g. F$ a! u1 u" E1 Q
; \8 l) o3 [/ n5 n: T7 }4 h
   BPX exec_int if ax==68$ ?& T+ d* N) k* D, w/ M9 C! d
   (function called is located at byte ptr [ebp+1Dh] and client eip is
' b( q3 g4 S3 d7 A4 _+ p   located at [ebp+48h] for 32Bit apps)4 `3 W" Z0 R0 L; n
__________________________________________________________________________' m) `: e8 b5 m2 |6 Z
5 x5 n- {6 S  k9 F
. N  v2 Z+ D( ~$ G0 h
Method 08
0 G( S! [, h* u& g1 @' n=========
4 y' {: l) r1 c/ h/ ]; ]) V1 {+ J# U( A3 v& J3 l  }9 O
It is not a method of detection of SoftICE but a possibility to crash the
2 k2 Z* ?- A% _system by intercepting int 01h and int 03h and redirecting them to another( u; w3 A- H) ?
routine.
4 U  E" _* e' @7 H6 O! nIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
. y' |/ q8 f! w! d. P5 vto the new routine to execute (hangs computer...)
$ h/ W% H9 t; o' V- b0 h: ~7 s2 M3 H7 O& t$ \, F3 k1 d! |
    mov     ah, 25h8 ~- \5 I  V# N& J7 Z* m' Z
    mov     al, Int_Number (01h or 03h)
3 z. S  Z3 w  D    mov     dx, offset New_Int_Routine
8 G2 d/ q0 ~# O/ I9 `    int     21h# d5 H1 G/ i( y/ F! g3 M6 N

8 U, A2 o; a# I$ e, f__________________________________________________________________________
: H( |$ E* Q8 ]. w7 }( l% c8 }  s% c, P% @/ e! S
Method 09: m) Y3 w% C8 A( N0 a$ u. b6 x: ?
=========
( M/ B+ K# m* y7 A# p
8 Z; q' {4 T: e" RThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only! {. y8 @3 ~5 w1 k
performed in ring0 (VxD or a ring3 app using the VxdCall).
) ^  q9 ]0 m5 X5 y/ V" h! QThe Get_DDB service is used to determine whether or not a VxD is installed5 J9 h2 W, c# }: W( `
for the specified device and returns a Device Description Block (in ecx) for
- a; N( l7 P6 b; y. I8 n1 Q# jthat device if it is installed.
2 K5 ?( t0 [. l2 a. D! X- v6 I
; b8 o9 X8 H0 Y" k+ j* @/ N   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID7 @) l" Z# ?2 n* J- R2 g
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)( \# n( P8 C/ y# u
   VMMCall Get_DDB7 E7 q8 s) I5 j
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
+ Q! V& ~$ M- H4 @3 \) [' p8 O4 B" o) u- u7 q8 K0 A; P3 B
Note as well that you can easily detect this method with SoftICE:
! E! F- _  a/ o; r: w, l   bpx Get_DDB if ax==0202 || ax==7a5fh& R9 R- D6 {( H
/ d$ P  T. D6 Y) K' H9 B: W
__________________________________________________________________________
0 M9 T" _/ M1 w2 Y5 N/ Z5 f  a7 J3 Y. K1 ?1 @& S/ c
Method 10
5 g$ T& O2 j0 L. E& T=========
1 t# O0 g$ \2 y; M' X1 s! ]) w- N, g# v, C
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
3 |+ i: S* e) G5 `' g8 I7 y  SoftICE while the option is enable!!
, _$ q7 C- k' X/ t" u" ^3 e* N$ h5 N* x2 I4 G+ E2 X
This trick is very efficient:& }6 n% y7 Z, B$ Q0 u
by checking the Debug Registers, you can detect if SoftICE is loaded
9 B  H% B8 r2 k4 k. p! N* O% [(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if) m  B) }% g/ ]7 Y
there are some memory breakpoints set (dr0 to dr3) simply by reading their- ?7 F& G3 y+ G5 j& Q" W- ~
value (in ring0 only). Values can be manipulated and or changed as well. z2 h5 e. K/ V* j. e9 k
(clearing BPMs for instance)% W" o& q" g. t! X! r) n; F: N

4 r. R+ i; u" k' `& M4 [! b3 v1 c__________________________________________________________________________
9 C4 I# A+ P% D3 q: j8 N9 E8 o) g: c  \& u8 Q9 s8 }3 q
Method 11) u: d6 b# S' t4 |: ?2 }+ R
=========
. C1 |0 t2 W) X
; `7 p( r4 E* QThis method is most known as 'MeltICE' because it has been freely distributed6 E9 a3 |  R9 c& \
via www.winfiles.com. However it was first used by NuMega people to allow
5 J* H* g0 d5 \% fSymbol Loader to check if SoftICE was active or not (the code is located
+ E& K$ G2 P* ~( W- Y. d! _4 \inside nmtrans.dll).# y  Z1 i# V" \( [4 `
% l/ w5 y7 R0 `9 Y# ~
The way it works is very simple:+ }8 p' g" ~0 w; {1 ~
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
4 V; {. o. r$ C( F+ h6 pWinNT) with the CreateFileA API.  s- ^4 G$ }* K& k4 c6 ?. D
% _6 u( S" E1 V* t/ P
Here is a sample (checking for 'SICE'):
0 ?. \0 j( y/ P1 F* j' r6 ^& A/ I: X4 v- T% Q. I' C& ^3 Z; t
BOOL IsSoftIce95Loaded()6 \. C) l) _$ i
{
$ O- A; k1 m: b% R   HANDLE hFile;  , o& _) Q  j/ e# k
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,3 ~$ Y1 g! B" L3 d7 ~
                      FILE_SHARE_READ | FILE_SHARE_WRITE,, z* P6 h0 f) V" g. c
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
- W/ f" p; c; O- I1 a  v   if( hFile != INVALID_HANDLE_VALUE )
! R9 c) n0 ^* m3 f- u# Y: Q9 r+ V   {+ R# V' {2 ?8 B+ ?! M4 [4 `1 V$ R" R
      CloseHandle(hFile);
+ E: P, g% B1 B7 a! z      return TRUE;
, [9 e/ N7 n$ W& ?* b. [5 _   }
0 ~/ Y! ?4 C& g$ _+ w   return FALSE;5 E5 \; j9 d* l. b9 s( w0 I/ x
}: s# k) D: r. K6 q  G3 U

8 `1 M# h) r, O7 BAlthough this trick calls the CreateFileA function, don't even expect to be" E) t- P$ @6 @9 V
able to intercept it by installing a IFS hook: it will not work, no way!: ]' |; R6 s3 @) [
In fact, after the call to CreateFileA it will get through VWIN32 0x001F
" X1 e6 K4 B( E1 z% {* W1 i: Qservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)- ]0 }* E& o0 n0 e3 C/ @
and then browse the DDB list until it find the VxD and its DDB_Control_Proc
2 N5 e1 F5 I' M. t7 b! gfield.: v4 h9 [- w! R1 t9 e. {7 L8 h8 [
In fact, its purpose is not to load/unload VxDs but only to send a 5 I  q, z* B0 f0 w3 _  s4 ^
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
1 x) i' Y3 J5 B+ h9 Q$ X2 Pto the VxD Control_Dispatch proc (how the hell a shareware soft could try1 L" q1 ~0 d9 g% c
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
! o$ f( {" u) y. m. @If the VxD is loaded, it will always clear eax and the Carry flag to allow4 D3 C6 X3 [0 U
its handle to be opened and then, will be detected.
2 {1 p( v# B6 V( `) d8 [You can check that simply by hooking Winice.exe control proc entry point
8 I5 w0 v, i1 Bwhile running MeltICE.% x, H# g) e( J' D3 N6 t4 @

+ \" _2 @9 |5 D; X
& w/ C+ J( B2 [  B. `+ M; v  00401067:  push      00402025    ; \\.\SICE( ?9 o7 r% }3 G! p: j: B7 E2 [
  0040106C:  call      CreateFileA
$ r3 Q8 W' ~4 x  00401071:  cmp       eax,-001! [( N$ B7 r% e2 U1 p0 G
  00401074:  je        00401091- i0 ]7 `4 q3 U7 Z, A4 Z, H4 v
0 j. r2 J4 H2 O# G# Q
1 w7 T! E) k8 |& }2 H" M9 I8 k
There could be hundreds of BPX you could use to detect this trick.$ u. O4 A3 V& A! v, i' B+ f. F
-The most classical one is:
6 Q3 g4 j$ V; k  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
7 G! I# I! J/ I3 S; P8 _( K$ {    *(esp-&gt;4+4)=='NTIC'
6 u$ L$ H4 I: e7 w  j( b* y/ t1 ?/ T' Y3 O/ E0 R) U$ P3 y
-The most exotic ones (could be very slooooow :-(- Y% i6 k0 E# [6 Q# _% j+ }9 I
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
. n4 O1 P' i  \0 C     ;will break 3 times :-(0 F4 H6 }& F- T  k2 ~- p) b, q

# f. n4 O% K/ `9 u2 |6 G# o-or (a bit) faster:
% V+ N0 q2 X5 |$ T# p; |   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
) z+ ?6 T8 G, |' [) x; C, F1 ]' c6 W9 n$ s1 m7 J1 q! |- W
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
) `$ H" A# B; D% x/ k2 V$ Z: H     ;will break 3 times :-(
! F& L  Q. c: c
3 @3 }, O+ H. {; M" ?8 s- c( I% i-Much faster:2 S  R" z. f: {4 b
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'
- @1 e( f' Q& u* ^. }* _/ p+ S$ T! A7 h! _" L) f8 r
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
; [% c2 B7 |! C; b. q1 f1 t7 Lfunction to do the same job:3 E# S0 X1 ?2 L. h* E+ V$ F

% ]; Y# z$ V+ z* ~   push    00                        ; OF_READ" y& l7 F/ d) E3 g# P2 x
   mov     eax,[00656634]            ; '\\.\SICE',0
9 T" Q2 J9 |  Q) O& f0 F- |0 O6 U' h   push    eax( Z9 `" H. h+ f% ]) i$ A# x
   call    KERNEL32!_lopen
4 R- S# Q/ s3 [2 w  W! ^   inc     eax9 ~/ t+ ^1 _/ p2 ]
   jnz     00650589                  ; detected6 f. Z6 o8 E0 v. o- B, s& U4 B7 Y
   push    00                        ; OF_READ) d( R1 O5 R% ^1 v2 F
   mov     eax,[00656638]            ; '\\.\SICE'
0 y# r* h2 c) o0 ~: q   push    eax; ^" `* W+ y* ]' J" r
   call    KERNEL32!_lopen
# Z# E$ r. i9 }, L$ t( |, l9 y" A   inc     eax
4 u2 ]4 E7 B: F' @2 G5 _! L' [   jz      006505ae                  ; not detected" {+ d# ~$ d$ A

8 a! O0 {+ I8 ^) L- I& @
$ N$ s0 P, _, T- P2 \- {0 y/ b7 t$ O4 J! @__________________________________________________________________________( y  K) l, ~% g, R
( [/ R. Y8 z5 J3 u$ L/ l8 [
Method 12
- E2 G$ {; A) Q! d/ _" R2 n=========
' d7 C* r% m" H. V
; M- D3 O% e& F8 I1 }This trick is similar to int41h/4fh Debugger installation check (code 05
) ]" b9 t& n  i+ c/ R&amp; 06) but very limited because it's only available for Win95/98 (not NT)
* e7 }$ D: }5 uas it uses the VxDCall backdoor. This detection was found in Bleem Demo.2 d9 I/ k* o$ F1 }, {

3 e* o, y  Q+ J- t2 H  h$ P+ \, t7 P   push  0000004fh         ; function 4fh
2 Z2 h, l9 F/ h+ u/ }$ ?   push  002a002ah         ; high word specifies which VxD (VWIN32)$ S6 q$ e3 Y$ C+ |' F
                           ; low word specifies which service
- o% Z, ~0 {* k6 P                             (VWIN32_Int41Dispatch)/ d( t' \7 B" J' v2 t' v
   call  Kernel32!ORD_001  ; VxdCall0 i0 S% x2 `( a! d
   cmp   ax, 0f386h        ; magic number returned by system debuggers( ]0 h" Z: r% d8 y  \/ C
   jz    SoftICE_detected
4 `) g+ x6 g$ d2 i
5 b, O% e9 Y+ d# NHere again, several ways to detect it:, d" r9 I& L; ~9 }
% V' G# T1 y" U
    BPINT 41 if ax==4f* F# D9 i, `; z7 i. v% b( H3 L6 s
8 }% i! R2 ~" g. E  V5 q/ g, Y+ C
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
& l5 N( K" {5 @) S4 H# A
/ k. x8 X6 ^! M' U2 I" S" J( Q    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
* u( e/ f$ G2 }- e  L8 C9 ^8 H2 X4 P$ e3 H* F
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!, u/ ~! y( ~- S0 S

% n! W9 m4 V5 I& e__________________________________________________________________________8 S2 Y: N# s  R2 }

6 g8 y; U  a) f; Z/ [Method 13$ h) S4 A  |9 g/ V2 V& j
=========
6 [3 q, @. l6 D, V4 s1 Y, }) j1 C6 ?- \6 ^
Not a real method of detection, but a good way to know if SoftICE is. U2 a+ Z: t  j, C" X6 D
installed on a computer and to locate its installation directory.8 ]) z! a- \7 N' b
It is used by few softs which access the following registry keys (usually #2) :
; J  t; i2 w( g( d9 T# k7 C" c) x" w( M- {1 M! `
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
+ o7 t: M7 d9 h6 B8 P! k! H\Uninstall\SoftICE
- ?+ F4 p; i% E4 c/ p4 ?-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE* q; _& ]: e) p2 w& `3 u
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion. W& y& W' K! h8 n$ S: p  P
\App Paths\Loader32.Exe
# o: M; n9 s% o7 G. u6 E
& a9 h, b+ c* s8 X9 a# E5 r1 V$ q# v4 I0 F
Note that some nasty apps could then erase all files from SoftICE directory
. p0 _2 {4 }& n(I faced that once :-(3 ~  w1 J0 p) z

, L% k; o& b; r- T% eUseful breakpoint to detect it:) k5 e$ v( F$ Z
* s2 J/ e  Y$ q. Z
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
$ D7 C7 H) v: J5 u+ a" O/ R  w: }4 j! t# `8 @# l4 G
__________________________________________________________________________
! b4 Q7 ]- ?/ O. }3 t$ L/ P" |  u) ?9 F& D2 X. \
/ h+ Z  e+ W7 L* Y% \
Method 14
% q. [9 Q. p* t% q. E0 K6 c* D=========9 w5 @# p- g- @+ [% `0 }
& h8 Q. G3 ?( p+ `! Q' u2 W
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
" P) c! _& e) k/ a: }is to determines whether a debugger is running on your system (ring0 only).
5 i, w8 I8 K7 z  z7 s$ D- J/ u9 ?7 j, h
   VMMCall Test_Debug_Installed
& O6 x9 F1 S' [6 }   je      not_installed: a# l, @" P; m" J' ]( F2 L" H' H
4 H4 a: @1 X# V- b6 l( \5 J( o2 z: k
This service just checks a flag.
1 q6 m& Y! k6 l  {</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部