About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
6 A4 l' ?' y; A<TBODY>+ W5 G6 u( b7 C: t5 i& H% [- K) v
<TR>9 i1 F# d# p- O6 k2 m1 q
<TD><PRE>Method 01 " S; w( ]# M  @* p
=========
* K/ r6 x) n3 [
4 j+ e' l" Q- m# f/ C9 I: lThis method of detection of SoftICE (as well as the following one) is+ X% b; f3 b: G; l( _/ F& `" x
used by the majority of packers/encryptors found on Internet.
$ ?% L6 Y% U2 q& FIt seeks the signature of BoundsChecker in SoftICE
/ V# q. z/ C( m) L. i) Q2 I% k- M9 q0 r+ Z
    mov     ebp, 04243484Bh        ; 'BCHK'6 K& b; F- t& P( z. f6 y
    mov     ax, 04h
2 d# m0 ^, @' D; z    int     3       7 J  O  A/ l* K" C+ E7 E) k
    cmp     al,49 _8 Z- d: j& ?4 x8 P0 ?8 n$ s
    jnz     SoftICE_Detected
* h$ n8 X. a4 D/ g5 ?4 y; H7 ^2 T+ h& x+ ]
___________________________________________________________________________2 @) e7 o/ u* z. s4 {/ n4 Z) A; G
3 X1 P, n2 @- |
Method 02+ B1 I" ^2 S0 T) a# `! Q
=========, \2 q- J, C& l% ^' Y9 s9 T# ]

. n$ f/ z* Q, a' J7 Y. R, u6 }8 _Still a method very much used (perhaps the most frequent one).  It is used2 d$ o6 p8 t4 i) e8 {
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,6 y$ |" H: z0 Q: ]4 `
or execute SoftICE commands...3 v& ~) ^& N$ w/ o
It is also used to crash SoftICE and to force it to execute any commands8 ?4 C3 h7 b+ o* e' B8 {/ r" c- j
(HBOOT...) :-((  . H" C7 b6 h: O% Q, C* f' t

, {2 V3 h/ z/ C" X8 Q) W6 R9 jHere is a quick description:
: c" a( t6 V  p2 u' ^-AX = 0910h   (Display string in SIce windows)
, j% G% P  ]1 y( |, k' x-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)* q" W* b( ], O  ?# g7 K( @
-AX = 0912h   (Get breakpoint infos)6 I9 e7 H6 L, \: U: ?6 s+ z5 w
-AX = 0913h   (Set Sice breakpoints)! r' N* }: O0 s* j; t
-AX = 0914h   (Remove SIce breakoints)
9 V0 s& `4 b& O1 X& M) r( s2 V! v+ k; V: T; @
Each time you'll meet this trick, you'll see:( ^; V2 ^3 j+ [. F+ z
-SI = 4647h
3 u3 P% z0 d  T3 j-DI = 4A4Dh* \& v4 p( G" X! E
Which are the 'magic values' used by SoftIce.
$ p2 o) e9 q, m& a" {5 qFor more informations, see "Ralf Brown Interrupt list" chapter int 03h.
! N3 C" Y  {- \$ p  M/ B) q% h8 O- C
Here is one example from the file "Haspinst.exe" which is the dongle HASP# n; S5 E7 J# p: Q. B
Envelope utility use to protect DOS applications:2 K; n) M0 ]$ ]3 M) b* R) H5 L

% `- E$ u, t0 [* v7 X/ H2 j) d( x! [" O7 Z. [! ~% |$ e; M
4C19:0095   MOV    AX,0911  ; execute command.; z3 E7 l, o8 r: C/ |* B. e
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).7 v( b/ p# R$ m( }( D
4C19:009A   MOV    SI,4647  ; 1st magic value.
% P1 w  p; K- y8 ~4C19:009D   MOV    DI,4A4D  ; 2nd magic value., h6 l# k, x# G# j! k4 N& d4 Y
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
- w$ [1 B  S: `4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
- w" k. t4 Y; U& t3 I4C19:00A4   INC    CX
5 _8 B. m! b2 ?( g) y2 K4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
0 y$ y3 h( d( K, A# B% x- j4C19:00A8   JB     0095     ; 6 different commands.5 V2 E: T, H8 M1 g. x- d3 |
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.3 x' j, c% a) J0 i" J
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)$ ]2 J. f# T! @- m- b

' n9 |& Z) {# \2 HThe program will execute 6 different SIce commands located at ds:dx, which0 d# g1 A0 ?8 p6 h! s- d  |( z. e
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
: I) R7 {$ B- q0 l8 A+ x  D% o. ]& P( [7 b3 U
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.9 x; I2 U6 w2 l( P* D  T9 z
___________________________________________________________________________4 F# y$ l2 X: J$ Z

1 x5 ^6 d$ Y. S: f  b/ C% m" H+ t5 t3 y6 E
Method 039 r4 C& ^' ]( o2 K' J) F/ o7 x2 l
=========
* @- z* G1 Y; `, i/ G& I% N$ d' J1 a  E: P" G, O
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h7 K$ K! Q) c3 `4 j$ T# V1 _4 p
(API Get entry point)
, M) n  V0 s/ m( M1 C        
# J1 W" y" x- |: O
2 O5 q( {1 \+ y" ?& ]- r    xor     di,di  {# q% ?0 P1 M. B& z
    mov     es,di
# g- U8 k4 K# m" h, v# _    mov     ax, 1684h       * l6 Z$ [! L! z8 v. R
    mov     bx, 0202h       ; VxD ID of winice
1 n- K! q: C% b. Y+ O% I9 \1 o5 k( x4 x    int     2Fh
& C& V! b) A* y% z0 Z# Q% W    mov     ax, es          ; ES:DI -&gt; VxD API entry point9 w; A) n$ ^# j9 ]  f: Y' u
    add     ax, di+ M5 v9 h; n) [+ L1 t4 q  C
    test    ax,ax# |- U1 I8 l' V1 B9 R- }
    jnz     SoftICE_Detected! m; A. I/ p, b' x+ v3 s# K+ s

( }1 m- y: c1 u1 O1 s/ i___________________________________________________________________________0 e" W$ Y/ Q& A8 R
6 f$ U( N# a2 Q. i& f9 U( H
Method 04) |, E8 V8 Y7 `/ g7 p. T
=========. f+ o7 o, d6 z! }! ?

! I) H, b# H; }2 q& G- [$ aMethod identical to the preceding one except that it seeks the ID of SoftICE8 i: X1 @8 ^, w
GFX VxD.
, @! B& }8 \$ t0 `# U; f
3 z+ U. u) ]( \2 {    xor     di,di
4 N& M# ?+ v0 [4 g) H    mov     es,di
, @1 M7 m' N( B3 k) [  T/ }! |2 I    mov     ax, 1684h      
0 N- V5 U5 Z+ a0 d0 r: J# I: P    mov     bx, 7a5Fh       ; VxD ID of SIWVID7 |7 F1 D+ K( ?6 ?- a* K# W" p) z/ c
    int     2fh
, |; E* m+ F' j. U2 l0 A) L    mov     ax, es          ; ES:DI -&gt; VxD API entry point
' Y9 S- E3 i$ C0 S# A1 d7 ^7 I    add     ax, di- K4 Q& a+ o1 ~$ S5 G: `
    test    ax,ax
0 O( z* y6 M, h/ y    jnz     SoftICE_Detected
5 ?2 L$ D  Z4 i; G4 b5 M. K. O
__________________________________________________________________________( k  v+ @) e/ F% v6 R& W; V
0 I; Q8 W, _4 C0 w$ _) m2 j; r
0 R! \7 B, f4 Q( R% `- {1 Y7 g* y
Method 05
! |) d: }) ?0 m9 _2 s- ^. |! `=========
) h' F2 J) a/ s' W: `# L& s: L4 e0 ]( Q
Method seeking the 'magic number' 0F386h returned (in ax) by all system! `( U) d" I* s0 o; F6 i
debugger. It calls the int 41h, function 4Fh.& u2 }% t. \  `* u0 s! ?+ [  F
There are several alternatives.  ! M, d0 c& c) W( E

7 J, _. ?! K3 U# F% R5 @The following one is the simplest:# n! @+ W) P: }+ [

% U8 ~3 t, d2 a! ^$ V    mov     ax,4fh
4 g( U* V6 Z" i/ J5 h1 Q5 w    int     41h* N4 J) B5 b* X# I4 W& L3 [
    cmp     ax, 0F386
9 w" B/ P; H1 f    jz      SoftICE_detected
2 u. M5 h$ k8 a' _: k, s- w2 D) j" s1 Q5 V
2 J9 i6 {/ a9 j2 z; y
Next method as well as the following one are 2 examples from Stone's
( r& y# E2 {0 Y"stn-wid.zip" (www.cracking.net):5 _9 ]* Z; h2 v  N7 |; g) [0 }
+ o/ o9 a: Y2 N
    mov     bx, cs
* r4 [" d) p0 `, R" }( Z0 a    lea     dx, int41handler2
& g  I! _- @2 [# f8 q2 x& s  k' \    xchg    dx, es:[41h*4]; T( j/ y) G3 g+ A
    xchg    bx, es:[41h*4+2]) m7 [3 _1 L9 d5 M6 p
    mov     ax,4fh
7 g9 f7 m  r) P" X; V% S) W    int     41h
/ c& A7 G$ q% p/ H' j4 M    xchg    dx, es:[41h*4]
4 @; A7 g$ d9 D: D  {    xchg    bx, es:[41h*4+2]
* X) O, O- ]6 b" m5 W    cmp     ax, 0f386h2 u* B5 s2 b, j& r4 G
    jz      SoftICE_detected9 K3 T. n/ v3 E1 ~& p3 \

: L) C5 [: q* C4 R4 y" q9 O9 Fint41handler2 PROC1 D4 S8 R  I" l
    iret
5 c. M  u$ e4 Nint41handler2 ENDP# Q. T; |! P- u. l7 L) [7 c  X
( z8 l# N4 D* a; T) ~* \; r

& W2 P+ J: K: s/ Y3 ]+ G# q3 j/ d_________________________________________________________________________
) Z* q2 X; N/ l! M, f5 ^$ s/ P' H+ n! ~) g0 ]% H9 z! r* S
- {" `6 E1 d( f' n8 {. L
Method 06
  b% F. T0 m+ C& w  s2 X4 A=========
3 S6 }0 f& r5 f3 r5 g: H, v; A3 ~7 \& ~3 k* G
" q! d, Q+ o8 J
2nd method similar to the preceding one but more difficult to detect:: r- u) e+ \/ _2 d& r) Z
- t- |  c- q7 }6 K3 r
& N+ }8 A" D  P! `
int41handler PROC7 l3 I3 A4 _5 c1 B
    mov     cl,al
4 j3 X6 i, V& }+ `% S! i    iret! U8 H8 X* p+ T0 d
int41handler ENDP
7 _- }+ J# i5 w6 h
+ V) N! h  t* F4 l/ i, ?2 \! I
. z( H) ?. `: o" T  ?! K8 u    xor     ax,ax
. b+ y! S! j9 v0 f, X* J$ G    mov     es,ax. o2 H9 j9 c( [, H0 x" \8 {. l
    mov     bx, cs
, q+ d, z  A8 L" d6 Q( d0 R    lea     dx, int41handler
( P* E! A9 N* ]3 C# ?" V    xchg    dx, es:[41h*4]; o8 E  u% R$ Z. W2 _2 L9 Z
    xchg    bx, es:[41h*4+2]  |; m- h( d! ^2 n, a0 t
    in      al, 40h, z; v  u5 O5 Z0 q) B
    xor     cx,cx
1 i8 ~1 X4 e$ O- n% U    int     41h1 U3 \0 \9 g7 Q# M; V+ E, z
    xchg    dx, es:[41h*4]
% b. m# D2 a$ M2 u    xchg    bx, es:[41h*4+2]% M" ]) k( b* m5 o* k: R
    cmp     cl,al5 a  C9 _" \# A9 J- }3 l7 t
    jnz     SoftICE_detected0 J5 A2 B8 P( D

2 e2 E. e1 g) q! m0 \" a# d1 q_________________________________________________________________________
% ^* J; l7 T* J! r6 S0 `
2 b) y" u8 j# l. jMethod 07  W' X, r! z7 M$ [7 w. f2 z; x: X# h
=========
5 I' F; O# P6 N1 p" l
4 n! g' x  s0 @/ q- _Method of detection of the WinICE handler in the int68h (V86)3 W, x; n+ K  Y& y, l
/ C2 @" o3 x0 W' t4 R! ^
    mov     ah,43h" Z  p- W$ W: i2 y) L
    int     68h
7 b3 c: x* U1 a+ r. g  U# w3 L    cmp     ax,0F386h$ |* d, D+ `1 I; m( R4 t2 p4 ?
    jz      SoftICE_Detected
* v" Y, }$ o6 i1 u' ~/ U, S3 J0 u1 P3 N" f3 y" \9 |
, R5 p2 _/ W* L  O2 {+ j
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
/ i" X4 k* s' U3 U' B) }   app like this:
9 [9 q: ?+ }/ l5 T- r( J/ T; h9 ^) Y$ }' |5 z4 l
   BPX exec_int if ax==681 |$ F1 D2 x( Z& Q! T
   (function called is located at byte ptr [ebp+1Dh] and client eip is
5 Z/ r4 M. J$ `   located at [ebp+48h] for 32Bit apps)5 N4 I2 j) `9 Q( b) T0 U
__________________________________________________________________________7 B9 l+ y. o: X

" G: u! o$ q# y. `) }4 e3 H- N  a3 ~0 n* x' k) Z
Method 08' u0 M+ S9 N- B* ^4 X
=========- N$ x5 g; x; t3 F: H4 a* E9 D

2 Q3 r( p; L7 g" b1 TIt is not a method of detection of SoftICE but a possibility to crash the$ u/ T+ n* K- |$ e( ~
system by intercepting int 01h and int 03h and redirecting them to another
' Z/ A* K+ o+ X( _8 groutine.( {4 t$ }( m( U, n6 Y9 X. r% D& J* Z
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points( P. |7 ~$ @0 F/ Q$ `# @- Z) M3 B
to the new routine to execute (hangs computer...)
0 {0 w% M! y+ F; Z' \- y
/ k5 j) C: g" P; g1 y3 x  B    mov     ah, 25h
( t9 y. R/ A+ D* E! e  h/ s    mov     al, Int_Number (01h or 03h)
/ f$ N% l3 v; K$ u  [* ~    mov     dx, offset New_Int_Routine  Q3 q2 |5 o' X
    int     21h
/ A$ M# r. B/ Y( ?% z8 O4 R
4 |' ?, o" r0 B, v' @3 c; S__________________________________________________________________________
# b* {9 F5 z# U% N" F) K4 Q2 z$ `1 y1 J4 S* t
Method 090 w% w9 g4 x1 {) t4 l
=========
: l! R8 X3 F) {; u$ {* t# J, C/ H. F5 m. f* F3 e$ T/ h
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
; I4 }1 S3 W  R# ?8 ?. u/ N6 v9 kperformed in ring0 (VxD or a ring3 app using the VxdCall).
4 F9 S& y# b! D) W. Q( Q& A9 aThe Get_DDB service is used to determine whether or not a VxD is installed
) I4 r2 V5 N; F8 Gfor the specified device and returns a Device Description Block (in ecx) for
& u( L: ?; h/ N; L4 ?that device if it is installed.8 f/ o" f! O5 N0 s' v

" ^* O+ s, F% q* Z! ^   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
8 H6 J2 i7 _4 \8 O. `   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
3 T- g( [$ n1 w' z5 Y+ F; S5 Y- e   VMMCall Get_DDB6 i! l( K  J  w1 w
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
  r9 W. d: _+ t& z* ]7 Y
1 H+ q0 I9 Y/ x  D4 J1 L  }6 LNote as well that you can easily detect this method with SoftICE:
" ~3 o% m0 I4 i   bpx Get_DDB if ax==0202 || ax==7a5fh9 i; Z! z" [  O" r2 T; E

! Y& S6 o' N' f9 x( ~7 V__________________________________________________________________________2 T9 m; h, n# N5 P$ v
; I9 m7 a6 i" @3 l+ ?  t9 Z$ ]
Method 104 {2 [8 c- U% `, c$ a
=========" a& u6 }1 M- J- T2 X. R

  l* l5 A2 g. J=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with1 {3 G0 e* ~2 R8 C8 r" t8 ~
  SoftICE while the option is enable!!
# M% k7 Y: @) H! N8 B1 u& s3 Z1 M, Z! Z( ?* _
This trick is very efficient:0 p, @( P( N' j$ F3 [
by checking the Debug Registers, you can detect if SoftICE is loaded" |$ P- w% [! u
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if. t9 @+ j7 G! S* C# y
there are some memory breakpoints set (dr0 to dr3) simply by reading their
* r8 }' J) v# M2 S: p( S& O' q% Yvalue (in ring0 only). Values can be manipulated and or changed as well: }+ `9 w9 ?0 H! S' v) V& C+ V9 `
(clearing BPMs for instance)) x' M  x- H" ^. Z  ]+ T
+ ~; B7 Z9 {, |& h5 i; S
__________________________________________________________________________5 _& W8 L6 v, m2 @- A3 V) E) z

- t5 N* I! b4 G6 o  H: pMethod 11
8 n% R5 S* t$ ]=========' s+ @3 X& e1 j$ L0 ^+ r) i) o  t9 S

; J. z; o! h5 b5 k) O8 {* ]& tThis method is most known as 'MeltICE' because it has been freely distributed6 m5 R' C) P; E# K5 V6 q7 j( s( P
via www.winfiles.com. However it was first used by NuMega people to allow, G6 r& [, E4 c& t0 O/ s0 ?+ K
Symbol Loader to check if SoftICE was active or not (the code is located
: {: ?1 I- T% c# \' Q* R1 Q' E* Vinside nmtrans.dll).+ B! A/ |/ N& q
$ ]6 n3 l" E% {& `; X
The way it works is very simple:
& C' B6 u# z, O# tIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
% G: P! a! `6 T* [WinNT) with the CreateFileA API.
6 @2 }1 _) l8 s- h& P# Z0 k0 m2 [! k
Here is a sample (checking for 'SICE'):
4 E5 e* g; I- z( Z2 b  F- k9 q
# a; u* O5 Z/ M$ W9 j/ v! f0 uBOOL IsSoftIce95Loaded()7 h9 t& {: S5 n9 i
{
% Y, \: _4 v$ g, Q+ P# z' `   HANDLE hFile;  
9 T+ K+ P# c4 |% }: Z; L   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,# f" H0 ]: @# X3 F- |3 |
                      FILE_SHARE_READ | FILE_SHARE_WRITE,9 R7 X+ x) p) I+ `! x& S
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);1 T4 V* o4 P; U
   if( hFile != INVALID_HANDLE_VALUE )
+ P' L7 b  S8 c% t! H  t   {5 c5 s" s# b) ~. _- k7 |
      CloseHandle(hFile);3 Y! S' K! N+ d0 J3 ]
      return TRUE;' x! \. z# A: h
   }: P$ q' ~5 U' `
   return FALSE;
8 |# A5 U$ i0 C) ^}
( I2 a1 H6 N' i, O$ }0 q! H& C. s- E9 `
2 a# h! U) \: s' u' |) M3 xAlthough this trick calls the CreateFileA function, don't even expect to be) i; ^) W. b: r- f8 t) g2 b$ X
able to intercept it by installing a IFS hook: it will not work, no way!
0 X$ B' I+ U7 I" a! vIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
  Z  G8 G$ t; w: {+ r0 y, q* y# o; Oservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
1 a' i) M, b! K; l% Fand then browse the DDB list until it find the VxD and its DDB_Control_Proc0 ]) H4 ?" M5 E; M& H  Z
field.
8 @9 p# s+ w, cIn fact, its purpose is not to load/unload VxDs but only to send a " A8 X# w2 F: u7 J+ T2 [
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)1 b) j5 `( x# d$ \' ^/ t
to the VxD Control_Dispatch proc (how the hell a shareware soft could try+ j+ ]. V( r5 ]5 x2 |, c
to load/unload a non-dynamically loadable driver such as SoftICE ;-).
+ f6 @3 F5 W1 r- ^& j) XIf the VxD is loaded, it will always clear eax and the Carry flag to allow& ~# q5 R: r4 S( |* h, F, C# q* v
its handle to be opened and then, will be detected.$ d: N; q, P5 E! e# ?& K# W. c
You can check that simply by hooking Winice.exe control proc entry point  H, D  L- P! R/ v- @, c( K
while running MeltICE.
) o9 ]& C8 [5 e# l
- p& R9 J# e/ w4 h) L5 [3 Y3 o; m, F/ l8 s: i  B! `" s& l
  00401067:  push      00402025    ; \\.\SICE
9 w6 |3 R8 a/ z: @" a  0040106C:  call      CreateFileA  w# q  \% a8 [0 D
  00401071:  cmp       eax,-001
- ^; Y8 x! W5 z6 u/ a' G% R  00401074:  je        00401091
  Q( R' ~0 t, u/ }6 T9 X% k
- [: t$ J# U% d9 |' t1 h5 F' Y4 S8 ^- p6 I
There could be hundreds of BPX you could use to detect this trick.) r" a) W  o6 v' l% s4 r6 l
-The most classical one is:# u, N+ L4 ]/ K! \0 `  w4 J
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
% _2 d- B' ?9 a# ~    *(esp-&gt;4+4)=='NTIC'
1 y1 i( K5 y1 i" e- @- O8 [
4 j) B0 |0 K2 j$ q% ^-The most exotic ones (could be very slooooow :-(
& y3 A9 g; {. R- D, R9 f   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  8 q2 a  V* Z% A% m( Z, _6 o/ }
     ;will break 3 times :-(  Q6 }' |% w4 }; C. K( H+ V
! U5 ^4 x5 t3 k: z
-or (a bit) faster:
1 m: E0 O# o$ {; K   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')( r& l4 E( \- \) d/ T0 ]/ D

7 t3 d% x4 i4 ?   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  5 N8 N& j) u, S# N
     ;will break 3 times :-(- P  l# A! w0 ?) b" X* B' d
  p4 R- a( x. f- Z+ q& q' T% W* E
-Much faster:
7 e$ B. f5 p5 S# E; J   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'/ v/ J, h8 [' ?- L' f  L8 f5 f3 i

% C3 T4 l& m+ s% i% ^) yNote also that some programs (like AZPR3.00) use de old 16-bit _lopen# a* p2 g. W7 {  f6 B9 ^9 ]
function to do the same job:3 S& W1 s7 Z$ q) X. s- o0 ~7 D4 G: Y
. d' b" _. u6 [1 Z0 ?' @
   push    00                        ; OF_READ4 D( D  |) [5 U/ K# M( a" v
   mov     eax,[00656634]            ; '\\.\SICE',0. c% r9 y0 G6 W: W0 N, w
   push    eax
0 n5 k, `( T& W3 G   call    KERNEL32!_lopen
: x/ G% _( }$ |' H/ y   inc     eax
- D5 |5 a1 C6 y' k: e   jnz     00650589                  ; detected
6 r$ _; ]/ ~5 o) r) p- K4 P/ \   push    00                        ; OF_READ+ }2 a  S" s, |' Z4 |2 U2 {
   mov     eax,[00656638]            ; '\\.\SICE'. s# M8 C, Z$ H
   push    eax6 `( p% X& M& y" @+ }. j. R
   call    KERNEL32!_lopen
9 {! ]& E# T0 s" ^+ e& @   inc     eax# X) c3 F, L- k- l
   jz      006505ae                  ; not detected
% ~2 y2 c4 {# D! V+ v7 t% I8 D0 B
/ p. D. a2 q* m- W' }
__________________________________________________________________________/ I, `/ E4 V2 f  D
- H8 L6 D8 Q  R/ ?9 U( ^; S
Method 12; ~: t& U4 }  F) ]) R! P- A
=========4 Q/ W, a: d1 \' E/ |
' [/ t, g) ]+ S  |
This trick is similar to int41h/4fh Debugger installation check (code 05
0 K, i/ L. Q7 Q# B8 L% @$ L* q&amp; 06) but very limited because it's only available for Win95/98 (not NT)0 ?: ^% l) V9 ]! ?
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.7 X4 k0 X+ @2 X, l6 [1 V( z3 c

3 b5 Q& l4 [* z   push  0000004fh         ; function 4fh
; t! H+ q; f( W% I; P   push  002a002ah         ; high word specifies which VxD (VWIN32)& ?* h9 g, h+ U! o" U  C
                           ; low word specifies which service' h0 L% F8 T( f
                             (VWIN32_Int41Dispatch)+ d" [$ z4 {) l
   call  Kernel32!ORD_001  ; VxdCall! \: c1 C* E; O! V7 Y
   cmp   ax, 0f386h        ; magic number returned by system debuggers
+ i- v( n; `5 h+ B$ w, h+ K   jz    SoftICE_detected
. r' W- n8 ~$ B0 _! U) G% x5 g3 K6 e8 ~
Here again, several ways to detect it:
+ }1 W$ G* V, d8 N9 A
4 c& O  t0 G/ T$ t2 p) S4 z" i8 U" \    BPINT 41 if ax==4f- G0 e1 }7 n8 o5 z% f" m
) Y' ]4 A5 j; L0 Y* |
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one1 L: [7 t8 x, T# P( T& F8 q
* U* w- r3 y0 Q7 B2 R& Q
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
8 W( k. E3 W5 C9 j$ l: v$ ]1 S* F+ M7 o. n
    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!% h- m" [" e7 H5 L( q. A

/ h- e- @' X4 k: P! c! k__________________________________________________________________________, R7 k- c3 b/ G( L
1 f. Q9 h$ c( r  V6 }* r# @+ V1 Y
Method 13# K5 `: |, ?, ?
=========
" O0 }; [: i$ @& z
. [* G$ w9 B* r" cNot a real method of detection, but a good way to know if SoftICE is1 \+ T4 ]' _4 F
installed on a computer and to locate its installation directory.
( `; u5 U1 \! Y4 J5 ^3 N; O2 ~5 [8 gIt is used by few softs which access the following registry keys (usually #2) :
$ L) f+ g* z$ J# H
% T. R4 a* E; N% ~  f/ c-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
1 M0 h* ]* l" a* Y$ z) L\Uninstall\SoftICE. w/ {# u! ~7 e4 Y9 K0 ~3 Y% O
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
% D  ^- \6 I9 s2 e-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
0 [/ ^5 n# ?( e( N" Y  C' _\App Paths\Loader32.Exe  N" ^/ |1 e9 I+ _
+ P9 h: Q7 K3 D! c9 P+ w( o
* d( ^! G7 g  ~# B
Note that some nasty apps could then erase all files from SoftICE directory
6 ^7 w& Z) K4 Q# `% o' I/ C$ i* J(I faced that once :-(# a) l% N+ \3 A# C" g

0 f! z+ A; z8 K% g" mUseful breakpoint to detect it:
% H% K& ~6 X+ h1 C* A) ~: b/ }2 c$ t) {- F4 y- c# S8 h
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'+ g/ g8 R  q- b$ X

5 h. c( R4 P' D# q- P8 e4 d7 A__________________________________________________________________________' ?$ D) m* q8 _6 J$ _+ @
* x# X7 L! e& ?/ H
* }' w3 T; G- R
Method 14
2 D% T% d1 G- S) V4 O=========9 @. h5 d+ V/ Y- c: W! p5 X2 Z

. ?1 G' B0 A0 w+ |A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
! h7 r+ A1 }4 J. Vis to determines whether a debugger is running on your system (ring0 only).
& @. j8 B1 [! J7 n0 o- S2 G9 m7 A, `% j" Q8 e' s) a
   VMMCall Test_Debug_Installed8 d2 v* n) W0 @% V8 A
   je      not_installed
& {7 t4 o  T! e1 I) {) e1 l  y
This service just checks a flag.
! v. @4 `0 l: z1 a9 f</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部