About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
( Q8 [+ G3 ]* \" L7 E<TBODY>
+ G3 T5 D/ `4 B/ ?) [! c7 [1 v<TR>
. N0 ^, [1 u8 t<TD><PRE>Method 01
6 X9 q, }/ L2 V% R=========+ ^; j! U1 L1 a' |' D2 A

* e: ]# Y, a  E6 qThis method of detection of SoftICE (as well as the following one) is
6 X8 {2 z, w6 W9 a1 e" |used by the majority of packers/encryptors found on Internet.
8 s/ r9 A; w1 [; H% Z! p  }It seeks the signature of BoundsChecker in SoftICE
* h0 K# d: b  |, k' M- G
/ S4 k2 I1 p; F4 n) A& h    mov     ebp, 04243484Bh        ; 'BCHK'/ |$ ]( J' w' ]
    mov     ax, 04h$ A# M' W- R2 u  O
    int     3      
/ L6 a. C+ O7 e. z( \+ Y    cmp     al,4
# F( A+ X! B, T' B( s0 i    jnz     SoftICE_Detected
1 S3 m, H1 A' q# V1 W2 Z# S1 o* O; ?7 U
___________________________________________________________________________
, B; n0 R8 W6 g8 b+ Q6 z  Q' F* a6 D$ k1 x
Method 02
, P5 v' B- a5 F4 e9 P& J; N' T7 }=========
% ]+ l" e* v! D. ~! H3 o+ L1 F- [% }; y) h: U! c
Still a method very much used (perhaps the most frequent one).  It is used; i9 J/ m  O; @( u
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,2 _# `, r# {, V" `# r% i
or execute SoftICE commands...
$ C1 R0 g% ?( X# G$ {It is also used to crash SoftICE and to force it to execute any commands, }9 f- x" c8 w+ U: n, x
(HBOOT...) :-((  ' ?7 V2 e# V" u: d) Y) N3 Z

4 T3 e( I3 v5 \: lHere is a quick description:2 k( }7 K3 h6 r* I- R( J
-AX = 0910h   (Display string in SIce windows)4 Y# P4 {) h$ z
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)& N. \9 p: v6 v6 S& U
-AX = 0912h   (Get breakpoint infos)
" t, K3 Y- ~+ v. z0 ~-AX = 0913h   (Set Sice breakpoints)
! P: J# [. H- d- Y1 S0 c( R2 W3 ^' l-AX = 0914h   (Remove SIce breakoints). Z+ @* P# v" d& b$ ?

: x; t/ y9 ^( c  eEach time you'll meet this trick, you'll see:/ Y' P. y  X5 f  j5 y5 f# D
-SI = 4647h
' w7 Q6 y  }2 c-DI = 4A4Dh
( Q: j3 t+ |$ L& qWhich are the 'magic values' used by SoftIce.! b) G  `, \( m% s
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.8 t9 A  Y2 t' Y( T/ K
* B4 n4 i3 Z6 m4 X
Here is one example from the file "Haspinst.exe" which is the dongle HASP
8 e/ D% t) b/ F6 X$ |' hEnvelope utility use to protect DOS applications:+ w. H+ z# g! I/ ]# u" f/ F! v9 v
2 E% @, B7 \# h/ W& h5 v/ y
! s4 d5 T6 L, B, r& ^6 z' \6 \
4C19:0095   MOV    AX,0911  ; execute command." z! n3 O  V1 P7 L) C/ z/ p; i; o# w
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
( _% e: S* v: S3 A  X% t4C19:009A   MOV    SI,4647  ; 1st magic value.
. G8 K& Q& I1 G4 S) A0 d( B0 G1 a4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
& z0 |$ w4 B/ y* R, p4 e' L, [4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
: g8 ]2 ], R5 B$ ^2 c4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute9 a$ Z* {: @) R
4C19:00A4   INC    CX
' c5 i- |# r$ h! e2 a5 p4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute4 e0 T" [' \1 W) a
4C19:00A8   JB     0095     ; 6 different commands.% Q7 j8 d/ g' f; a2 p9 d
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.4 h* E8 ?* h6 U
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
# u  U5 P; [& x  m+ y$ f  Q. T7 U1 p5 b6 H$ b, U  U' j
The program will execute 6 different SIce commands located at ds:dx, which# K6 R9 P9 C" u& Y3 y2 y' e- q5 L
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.! {) a* Y# L7 q- }
4 J! D, h2 i7 f" m; j
* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.
; G3 Q0 x8 ~$ g___________________________________________________________________________: u5 @; U0 G: z5 x: O% F
7 D! ~/ G0 G3 |, X! d# a
# S& a$ A. S3 a0 B8 q/ c5 l% u9 m
Method 03
. V7 @3 R8 A: P3 ~# b=========
' t, H7 I, V3 N# }/ t
, B% V8 \3 x# e. hLess used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
# }: Q5 Z% h1 a5 ?; W! b9 t(API Get entry point)
* z/ _" R7 Z" E, H        ' f) {4 B  o) o) K7 B* V) P: u
9 b3 d3 b9 A1 [0 ?/ {9 f
    xor     di,di
9 \3 N0 Z4 c6 U1 E1 N$ V    mov     es,di
' Z! O. r' Y, |( R* g0 [& y    mov     ax, 1684h       . Q8 j8 A8 }9 k1 r9 G: y' O
    mov     bx, 0202h       ; VxD ID of winice
8 C2 Q- k/ ]9 l( G3 y# T    int     2Fh
; Q" n; \$ V3 X( a. v6 G& \    mov     ax, es          ; ES:DI -&gt; VxD API entry point" d5 T, S3 g# }+ L5 J6 I/ C
    add     ax, di
9 z( d- {6 ?5 F$ }    test    ax,ax* B# ^; P9 O/ y
    jnz     SoftICE_Detected4 ]) D  t, e$ \9 e
/ m& y1 R+ _9 c7 B! U6 `% j/ |# \  [
___________________________________________________________________________
* Y4 w! q( f+ R; i
" y! |0 \0 k- _' kMethod 04
- T- z: W. |4 A' r+ g. Y0 W=========1 l5 r; S  f; E2 P+ L

0 V  x; x/ P# J& }$ ~/ @1 e* SMethod identical to the preceding one except that it seeks the ID of SoftICE, p5 [  v' f* ]1 C
GFX VxD., q% ]" x$ n* ^7 a3 E2 R3 T: A
- ^! s4 ^8 R  p" W# D
    xor     di,di
$ H: X% a5 o# Z' ]9 b$ D    mov     es,di8 A' ?  m# U6 a6 H1 [
    mov     ax, 1684h       - O2 A; w* i. Q% ?
    mov     bx, 7a5Fh       ; VxD ID of SIWVID- }; G; C+ y/ X6 Z
    int     2fh1 o3 J7 s. ^6 |% G
    mov     ax, es          ; ES:DI -&gt; VxD API entry point! U% @! P% S* f+ M
    add     ax, di
) U2 u0 `2 w  K3 D; Q6 }. Q    test    ax,ax* F3 Z2 T; z, E. X
    jnz     SoftICE_Detected
% [; W( u7 x' A$ e! y+ D
6 v( f) u+ H' A5 a9 D. h6 B4 E: a__________________________________________________________________________' o; X! o# P, o6 w5 o4 a( g9 d
! A1 ]+ x) j0 [2 [8 x9 J6 N0 M
+ r4 X5 H5 {$ K! \( u6 Q
Method 05/ D+ v/ r1 T. n; r
=========
7 Y, c% k8 t' S5 F7 O0 D0 C" E# P9 [" ?) ]# {! p/ c+ t- S
Method seeking the 'magic number' 0F386h returned (in ax) by all system
! Q, u, j* F& l' Bdebugger. It calls the int 41h, function 4Fh.
: t% p1 s2 K/ M/ S2 O# \There are several alternatives.  & r( r/ e- @1 w  w* M1 p1 I; y
/ L/ V2 ^) c7 P3 U% p
The following one is the simplest:
5 J5 u* o9 k% P  c0 P* }( ]
3 U; ]- M0 r" m0 k! Q9 {    mov     ax,4fh! Z/ m1 V$ _, y" f
    int     41h
  Y7 u) e) d. {    cmp     ax, 0F386
9 W3 L- T/ y! Y    jz      SoftICE_detected8 i6 ^0 o0 w  w8 Y- A1 [6 d' y

- R: K/ D& B( K7 F5 k3 j% S! O9 U" K* }+ h) t
Next method as well as the following one are 2 examples from Stone's
. A3 @- q2 B& k" t"stn-wid.zip" (www.cracking.net):
* v3 K9 l7 n. i( r3 c5 l- Z! U0 C$ Z+ A- y/ n% E' J$ @
    mov     bx, cs0 M% U; v: g6 y
    lea     dx, int41handler2) o" W7 |1 C! G' y# S
    xchg    dx, es:[41h*4]
+ [$ |' Z! \+ d) H1 }    xchg    bx, es:[41h*4+2]
4 |3 e! i2 U3 g: U    mov     ax,4fh
+ |. M! ^* X# I- j3 W8 I    int     41h
) M! a0 _5 I/ g    xchg    dx, es:[41h*4]
8 j) D! ~% j4 n! f9 j# f  m    xchg    bx, es:[41h*4+2]
, A3 ]3 C; g" j0 Y; A9 }+ f! X) x    cmp     ax, 0f386h; j3 |+ \  N4 O& @  p! a
    jz      SoftICE_detected
2 |/ m* t# E( N9 o
  F; ?4 O2 o6 o% C9 B" o; mint41handler2 PROC7 ?" k9 N; b$ z; ]4 u& m8 x, |
    iret" s0 w; K5 j3 d; P: f
int41handler2 ENDP
6 ?" y5 l, S# c& D) N5 x5 z- i: ^$ d/ Q

. b/ m7 F9 ~+ u1 L_________________________________________________________________________9 ^5 `% f7 G. t8 G; {
/ {. G. X% \5 n* Q

# |1 L2 _, T& Z4 a& O1 B0 U7 sMethod 06
4 P. e+ u/ e  c=========
" [! w6 z  w% l" P# L6 \# i) F# ]; }. L  I! ], b' n8 e! V4 G
8 q  [! T( B/ C: p  W& l% C( g
2nd method similar to the preceding one but more difficult to detect:
0 O* ?) O$ I2 d$ z; R0 I& F# P- e1 x4 R3 |. L0 g5 }3 S% u$ @

% u8 Y+ c1 m7 ]" M9 vint41handler PROC& C$ _9 w9 t/ L) }" e, J, ?
    mov     cl,al' f* R! o7 A) w# R
    iret
/ H: b. [5 k5 k/ m9 E% a( Fint41handler ENDP
0 |6 G, s& {4 G2 b, o
" R- E3 B! H  A% R1 s& S4 i7 q4 u8 O
    xor     ax,ax3 q2 i# c) n3 o9 p; P
    mov     es,ax9 {3 q! N$ [( ?9 Q* [; }
    mov     bx, cs+ L" ]9 c4 K# V7 V4 I) }4 L
    lea     dx, int41handler
% P# z2 g) q; ]/ Z# A    xchg    dx, es:[41h*4]0 V3 i* c3 F  |2 F4 |3 K6 p
    xchg    bx, es:[41h*4+2]
5 h4 H8 [1 J! I8 d0 c+ ?    in      al, 40h
/ v% E& w3 k+ f; P; t    xor     cx,cx2 A$ H! f. `7 E, A6 B
    int     41h% \- u5 O1 Z% `- |5 k
    xchg    dx, es:[41h*4]0 m& ^4 P" ^& D5 R* M' K0 t
    xchg    bx, es:[41h*4+2]
* s" D% P! g, f7 a* G# @% |    cmp     cl,al8 T6 J/ Z% P* P1 Q6 S7 @. m
    jnz     SoftICE_detected
3 n( c: K( q0 d7 ^. y1 K' t! `1 S! y, E* T1 G5 ?
_________________________________________________________________________/ ?+ {/ x- m+ A, a9 Q6 {3 S3 K" @
7 d0 y$ T: B! b1 l6 ~
Method 07
4 Y) t4 P* e* A7 f/ J# _/ G" X=========+ Y  I# Q2 W" @0 j% q# U
9 D1 r$ H" C0 ]* m9 Q, V
Method of detection of the WinICE handler in the int68h (V86)
+ z, o. {) J+ }, y, r3 t) j( m7 Y/ t$ H% [
    mov     ah,43h! k$ S9 X6 g0 }( B1 Y
    int     68h0 _- ]2 ?- f; ]7 Z3 _% y! k- K
    cmp     ax,0F386h& W% E) m% e- g; G
    jz      SoftICE_Detected3 L7 C9 b* a& K. c- y

2 K4 W9 e  z) q* w; p$ e8 p4 N
) j- [/ C2 w4 o8 r; x=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit% i# P* N& p1 I2 E0 ~; E
   app like this:
: U3 E4 O$ C- v
# a6 j& A2 m) I! o, e$ W6 x* |+ Q   BPX exec_int if ax==68
# j. J* t" Q" M2 n3 _" r" k   (function called is located at byte ptr [ebp+1Dh] and client eip is
6 \, t! C1 h  @   located at [ebp+48h] for 32Bit apps)
5 S; |! i6 P/ f# `/ o- C: X__________________________________________________________________________
- d) d* \5 M& a, f, V0 a- h
9 W1 G" l- ?- X# B' u1 A3 m9 v) |; i4 H. n
Method 082 r3 A$ K- o# i1 K& k6 X
=========6 O8 v: ^) N9 V- D) M" g! g9 r

7 N" B+ g8 k, w1 g' fIt is not a method of detection of SoftICE but a possibility to crash the  N* _5 K# Y9 r. d- C
system by intercepting int 01h and int 03h and redirecting them to another- w* s/ T& q; G) T& X6 H3 n
routine.
3 z3 f( a- O4 ~, j6 T7 WIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points+ M3 g8 q6 p9 E0 J3 Q' l; ?
to the new routine to execute (hangs computer...)& @/ L  }: ?7 G& M9 C/ r
5 @+ \$ E! ^: |# D
    mov     ah, 25h* a! I/ ]: n2 |1 [
    mov     al, Int_Number (01h or 03h)0 c8 c+ `- }$ a3 c/ h
    mov     dx, offset New_Int_Routine
$ w' H$ n5 ^  [: G7 T% n6 h    int     21h
$ I: p' x, d6 a! `2 w5 K* ^- Z9 L( i0 g( Z
__________________________________________________________________________
. R8 b8 n3 ~" |7 H5 C4 S, q: F- u
8 p& u& f3 i/ H/ u3 m; C8 gMethod 09- N" \, i$ |7 d, K
=========$ x% K. J; q% d7 A/ Z9 k, b( h- B

$ H+ X, e- }) ^5 Z$ e" {0 U  MThis method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only0 E! a8 ?. r' c% o# m0 j: Y
performed in ring0 (VxD or a ring3 app using the VxdCall).
" C9 U0 q3 I: W! h3 a, n5 c; F6 {+ FThe Get_DDB service is used to determine whether or not a VxD is installed
. k$ I& j2 ~7 k/ U. @for the specified device and returns a Device Description Block (in ecx) for3 n- {9 J* A: v5 d6 u: G
that device if it is installed.
3 ?% a$ C. O; ~8 Z0 p
7 [7 B9 D0 _; W$ s- p   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID2 h+ P% L; Y- t& ^
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)1 l* U9 X7 K, y1 C6 r7 h
   VMMCall Get_DDB
( `& Q3 ~! w5 F, s   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed& B1 ~: a5 Y8 p, [1 p5 z
# ?/ @) }  @5 r
Note as well that you can easily detect this method with SoftICE:
1 z: M% i9 Q" }0 e/ q; t/ ]   bpx Get_DDB if ax==0202 || ax==7a5fh
% l5 E: U0 W6 d. {0 |
1 W0 u% l/ E& P3 m3 S__________________________________________________________________________
" K7 [6 s5 Z. L6 d6 f) W" G! z9 b4 U2 C2 e& v" _+ L% r+ Y
Method 109 p, O! V3 i0 h+ E9 E
=========
3 R4 h4 ~9 f# x9 ?$ E0 p" D+ }8 c2 T" U. Z8 J4 Q, |9 n2 Q. l
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
7 N$ F4 x; m+ v  SoftICE while the option is enable!!
& c' E. ^7 h; w% \: h
$ D( N  S8 ^$ z2 xThis trick is very efficient:4 G! I4 d$ \& J3 y4 `) B8 j
by checking the Debug Registers, you can detect if SoftICE is loaded
$ m; {5 f4 r! k* }' K% G(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if* q  L+ m' ]9 K! P
there are some memory breakpoints set (dr0 to dr3) simply by reading their
3 J3 ~6 h  b- {, I: Fvalue (in ring0 only). Values can be manipulated and or changed as well
) Q2 q! O' z; o& O9 x(clearing BPMs for instance)0 v3 E4 e5 w- \7 [% p+ }% b
9 G( G" v1 f4 O
__________________________________________________________________________
0 o: P2 m7 c% k0 L& d2 }; F2 W
- w+ ~8 j; ~7 Q: q4 I( KMethod 11; x2 A+ @( @1 j3 n! `6 d8 [
=========! e5 j  t$ Z9 j4 `- M# x2 l7 K% x

! \; W, W, K7 @& g- U, r; B2 M# eThis method is most known as 'MeltICE' because it has been freely distributed7 y9 Q% W0 j/ ~$ U( `
via www.winfiles.com. However it was first used by NuMega people to allow
. i" H* u. m$ a' p$ L* i) `Symbol Loader to check if SoftICE was active or not (the code is located+ r* y! C* @. o2 X0 `6 q
inside nmtrans.dll).% E6 h; b9 F/ ^6 S$ g

' s% S0 S4 W/ B  pThe way it works is very simple:
/ R7 Q9 ]! c- y) S  ~' A6 sIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
7 @; X0 O, v/ w( }WinNT) with the CreateFileA API.( q$ z; S- z( C! a( z) ?) I

4 _( i* W* J3 dHere is a sample (checking for 'SICE'):
& h% c1 S( ^( c! ?3 g9 h4 v
1 V; T) z; }. k  Y* a9 F3 v; M4 GBOOL IsSoftIce95Loaded()
0 M; @! i2 d+ `{1 R; w4 O. R/ C9 G2 X. O' E
   HANDLE hFile;  
* m% u) ^9 k7 b( L2 _2 f8 X" d5 m   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE," Z4 u3 M# A3 H  k
                      FILE_SHARE_READ | FILE_SHARE_WRITE,  O1 F; Q% e( `
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
$ h2 g  ~2 F) S2 H   if( hFile != INVALID_HANDLE_VALUE )% k5 ]+ T" V7 a% w$ ?- }
   {
, M0 e8 h& f$ c4 c; b( J$ q      CloseHandle(hFile);/ T, J+ K( p* P; Z: }
      return TRUE;- T6 {7 o1 F; l1 C1 t/ T
   }8 l7 s. Z9 ]0 T/ W! R# L) ^& Q. @
   return FALSE;3 l. ]# x2 w- j8 K; j8 ^2 `! d
}
9 _, U4 _9 j" ?( M: |
; f! [. V( y& X2 ~. cAlthough this trick calls the CreateFileA function, don't even expect to be
4 b* R7 Y  z% d( G2 A2 qable to intercept it by installing a IFS hook: it will not work, no way!) J) Z3 T( O" N# T4 e# N% A
In fact, after the call to CreateFileA it will get through VWIN32 0x001F' R4 J% m; I! K4 [; |! H' J
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
* y, j) Q5 B# J) W5 jand then browse the DDB list until it find the VxD and its DDB_Control_Proc. K. h$ f! x" m# p
field.% e1 g0 i. V1 V/ V1 Q2 X) W- K
In fact, its purpose is not to load/unload VxDs but only to send a
* Y  ]) X) j5 X3 t$ y" i8 ~( zW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
, K4 A$ l+ ~7 b2 o2 H3 Dto the VxD Control_Dispatch proc (how the hell a shareware soft could try
- ~8 T9 `& Y" G0 {9 l+ s' J$ \to load/unload a non-dynamically loadable driver such as SoftICE ;-).( v: U" F0 X( L+ p8 c, C
If the VxD is loaded, it will always clear eax and the Carry flag to allow
1 g% t0 ~! Y+ [: dits handle to be opened and then, will be detected.. M* o, u2 H# v7 F# J. ]
You can check that simply by hooking Winice.exe control proc entry point1 _) d) a2 X- ]* V& ^
while running MeltICE.
" V, ]* @3 j7 F" I' J* }) |8 g# N6 y$ j8 U$ r3 j0 Z9 v! t

. m; |6 B0 X1 A& Z0 W2 a, b  00401067:  push      00402025    ; \\.\SICE
: a. B, K7 @% m4 D9 R" v0 e+ X  0040106C:  call      CreateFileA
7 H+ G$ u; y- z' u* ]6 C+ V3 C  00401071:  cmp       eax,-001
8 Y( S$ J4 S0 g) g- j: m3 S  00401074:  je        00401091$ |1 t' O/ e) |" V
* R6 `& ^: g: ?# P( b4 C* P

1 E# o# v% u( `7 h6 y. D" C$ kThere could be hundreds of BPX you could use to detect this trick.  y3 E8 {: S! }) D$ D
-The most classical one is:. {1 h& ]! E" w4 o" k
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||' ~7 s/ u, f( I! n# t' i1 j- L
    *(esp-&gt;4+4)=='NTIC'& Z7 I. V6 Y" N

& |( b2 I% C. H# B3 j5 I-The most exotic ones (could be very slooooow :-(
2 J( ?' d& B2 Q' ?) B+ N# p   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  ; J8 |& b; m# u
     ;will break 3 times :-(
6 I" R# x2 ^; V# G" c) ]4 X+ O9 c
-or (a bit) faster: 9 C0 h9 B$ p6 Z9 D
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
4 |7 L/ E' {% h% W6 ~0 Y6 W0 T' |: ~0 s8 B
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
5 w' y  x9 r9 }9 O( \6 f     ;will break 3 times :-(1 p- r0 u% x8 [. O# W& V3 [5 d

" O) X/ i5 B4 h- C1 O, j0 b-Much faster:, x( P* b- A1 j# z
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'& Y: j6 u9 B2 q: J
5 G) Z# Q9 b6 B( R  g
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen
) o5 Y0 g8 O! O; c, M* Ifunction to do the same job:
+ s* h& I% Y) F; T
" @, O- Q# x- d0 |* j6 H$ J   push    00                        ; OF_READ3 v0 J: g2 c" m
   mov     eax,[00656634]            ; '\\.\SICE',0) K* L' r' K$ G; D& h) j! L
   push    eax4 V: W5 a4 ?. |/ C+ F# f1 S
   call    KERNEL32!_lopen8 J& z& r$ T; R, s# F. W
   inc     eax
9 ?7 X8 c7 }! x   jnz     00650589                  ; detected
5 n; R" r; A. v; j0 @   push    00                        ; OF_READ; L' ]- K5 q2 [! _
   mov     eax,[00656638]            ; '\\.\SICE'/ o7 G4 e2 o; U
   push    eax
& w$ |2 @/ x+ S   call    KERNEL32!_lopen
. z' _: q8 U1 q! K2 H2 P: C* M   inc     eax
6 C7 H! d" d4 Y  l) F/ W) L$ h   jz      006505ae                  ; not detected
3 ^+ h& i* [) |- D4 `
( Y3 Z  W2 ?: B- I) r* A6 y2 a% F0 B: s2 ^8 G* M
__________________________________________________________________________
7 j% R; |% _! A9 ?9 [1 V2 a' {) Y: N& f9 ]  l
Method 12
9 U, u) i0 s: H) y" F4 A=========+ u+ x+ R5 v# j( X

1 X* f8 z& y0 iThis trick is similar to int41h/4fh Debugger installation check (code 05# k* P1 L. e6 b4 p
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
! K4 H: X2 J4 n. Y3 n& |3 Yas it uses the VxDCall backdoor. This detection was found in Bleem Demo.
1 ]1 y2 n; T! Y- r/ P: l6 ?; f5 `$ |8 \+ j8 i3 V4 M
   push  0000004fh         ; function 4fh% P/ }4 v4 [: J* i
   push  002a002ah         ; high word specifies which VxD (VWIN32)1 e) g- P' z+ h4 f. e4 z& a
                           ; low word specifies which service
0 R9 f6 q( x4 ?                             (VWIN32_Int41Dispatch)/ e! y* A0 e& E$ R9 ?
   call  Kernel32!ORD_001  ; VxdCall, [9 G2 @' [( o1 g
   cmp   ax, 0f386h        ; magic number returned by system debuggers
, s1 w# i! j6 u   jz    SoftICE_detected* O5 K1 F' g4 [8 H" ]

1 L8 }1 Q# J+ I8 w; q; FHere again, several ways to detect it:" Z+ @  u! q2 I

" h2 T, ?8 g  T8 S$ y    BPINT 41 if ax==4f
  p4 X: z# H2 x& I. u! Z6 f% w6 @- v8 B
5 F9 ]& b! _# V    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
& \. `! b2 g% @( I2 C6 {, g* {
9 D/ g7 e9 t4 n& \' H8 ?0 R    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A
2 G# `1 e$ `2 x
& T! p' ~, V" Z5 S# L% z- j9 ~    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!1 z! \8 n4 x  W6 @

, ]5 r3 U" E4 [7 H) ^2 K2 @5 s__________________________________________________________________________
( a  R% C" C& v. q/ ?) c* y2 U0 d
2 r6 y, s4 a! ]) _( q/ rMethod 13# j4 @+ P7 x! Z6 t% V2 `) e
=========+ c% Y% q$ P9 T( u8 J! I8 }
2 h% e+ G9 P2 M7 M: k; d
Not a real method of detection, but a good way to know if SoftICE is0 C; L9 b: g/ e% B1 z, r) F% u
installed on a computer and to locate its installation directory.8 O2 k# }( g8 ]+ t
It is used by few softs which access the following registry keys (usually #2) :$ a4 x& y* Y( G  f

" M2 h0 d4 u  A8 O: M: I( }" B2 r-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion7 i; ^# f0 f( F' J
\Uninstall\SoftICE6 e; I5 ?( d  A' G3 z9 \
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE# D( }9 w& E: B
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion0 h* Z, g$ k; c, M* {$ [
\App Paths\Loader32.Exe" j6 p. ?% c" b, |; G  E

0 U+ V' N; L8 M: B  D
& ~# x* H$ S" Y# X& a3 ]; HNote that some nasty apps could then erase all files from SoftICE directory3 T: |& @3 O1 H. N- [
(I faced that once :-(# s8 d- p2 E4 i' h3 R) i

0 l( k- T/ R6 D/ _3 mUseful breakpoint to detect it:9 O& M6 ?7 A2 w* W* p- _# \

: i0 S, t1 I# z$ O( S) ]' {8 Q     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
, h0 K# @# a% t. X, R. Z  C- A5 Y1 r1 h/ U6 H* s( B- g
__________________________________________________________________________) J' q9 y; _5 [$ U

- C4 ~1 b7 C/ ]8 c( Q8 M
3 ^2 _, ~" u+ b$ e: u& KMethod 14
5 B7 h! |3 b2 K0 q, R% u$ y2 c=========- F( q" ^+ r: x" [9 L
% t) V0 U. K2 N% C
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose3 R( j3 ?) U; d2 ]
is to determines whether a debugger is running on your system (ring0 only).
& _" @9 p! M, U- C' m
& S. I4 V# `5 N5 T   VMMCall Test_Debug_Installed* n! i0 M5 G. @4 v
   je      not_installed! n" v2 H0 _3 Z4 X3 {4 l0 h" v
4 y* i+ d5 H6 M! F' s
This service just checks a flag.; s. e4 |4 ?# _
</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部