About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
, q; n/ w1 F9 y2 w( b6 }5 @<TBODY>
; T( S3 b, D( o" Z7 t<TR>  ~* \) _$ I& g7 q" X% O
<TD><PRE>Method 01
& q5 d1 Y* I1 U7 a4 G=========
/ p- v) s5 A2 T, x. u# c% N& S* ~1 Z2 J% }) `( C" ~
This method of detection of SoftICE (as well as the following one) is
8 l# E- _: h8 |7 v% hused by the majority of packers/encryptors found on Internet.
4 k" g& {) u4 l3 [1 _6 a, TIt seeks the signature of BoundsChecker in SoftICE# ?( @8 _4 f" q3 _' s6 [6 H+ f0 }

2 \* m$ N/ o9 [8 i, y& j9 W    mov     ebp, 04243484Bh        ; 'BCHK'! I3 @: w0 f, p# X$ T
    mov     ax, 04h
) _9 D5 E3 L' _5 n9 U5 d% U0 n; p    int     3       " r! p3 l9 P$ n; z6 @! i  q) N$ {
    cmp     al,4
  Y% t0 V5 D* }5 w& h    jnz     SoftICE_Detected+ ?3 C% [/ A+ e. F
7 d0 l6 E! c7 ?) l  u$ p  O
___________________________________________________________________________- q; f5 H5 m- X- x5 j3 h4 \

2 J/ t& G+ R% O7 i, o& XMethod 02" n( f+ p0 F) c% h) V3 q% V- x$ i
=========! i! t, g2 M: B( i' ?8 c
9 E8 X* V' q! c5 T
Still a method very much used (perhaps the most frequent one).  It is used% \$ p# i4 R$ j
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,
" Z4 x9 T# [) q. y  eor execute SoftICE commands...! F( V9 U. a4 z+ ~
It is also used to crash SoftICE and to force it to execute any commands
9 l# }0 w1 u+ G% O/ ?% Z- e5 H(HBOOT...) :-((  & q& j+ L$ ^8 v7 N# D# B) V- p
! S+ s) Y2 O: Q; J
Here is a quick description:" {! ]6 @" g4 V' C/ H& M9 q* e
-AX = 0910h   (Display string in SIce windows)0 Y3 ?0 s3 t. x  X. _
-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)/ v# x1 v# }8 E7 z# X, u
-AX = 0912h   (Get breakpoint infos)
  a+ g6 M4 ]" q) ~. ~-AX = 0913h   (Set Sice breakpoints)2 ^9 C5 _& P! I* c) A3 W
-AX = 0914h   (Remove SIce breakoints)% |' c$ a+ j$ I" B5 R
% F5 r" A: n" d9 k( U/ c9 j
Each time you'll meet this trick, you'll see:! W8 |2 J2 d( t
-SI = 4647h
, Q6 B" A, s2 a  q7 u-DI = 4A4Dh
. W3 M4 o( F4 ]+ L# ~Which are the 'magic values' used by SoftIce.! I. X8 \8 c0 \% y2 Z7 f, C) C
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.4 r2 ^  ~( t; H) K: w
% x+ |$ j9 `  g  A0 ?7 Y7 P: G' q. S6 r
Here is one example from the file "Haspinst.exe" which is the dongle HASP8 r7 J. a2 q, `, X
Envelope utility use to protect DOS applications:( G8 m( J* i7 B+ ]8 m8 O

  z7 K# n, |4 b' T( Q. d
" N1 P3 Q! C) y7 a$ g6 y) F4C19:0095   MOV    AX,0911  ; execute command.- [5 T1 ^: r3 w" m
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below)., W7 q8 k" }  {" D( D/ N
4C19:009A   MOV    SI,4647  ; 1st magic value.
# Z+ O8 J7 l( P. L4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
+ v) @: x1 s. Y( w1 p# y* c4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)+ Z7 A3 \7 P- n( _1 x
4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute: p; n' g9 C( W. Y
4C19:00A4   INC    CX8 ]8 R2 g( {% [
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
& B/ n' A. z$ Y4 n, @8 |& N5 q4C19:00A8   JB     0095     ; 6 different commands.
# G! q4 s5 A, v4 ?! }, E" F4C19:00AA   JMP    0002     ; Bad_Guy jmp back.
3 i7 B! }. a7 l) ]) I( _4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
) |! i  N$ ?& I0 o- @" q4 k9 a5 g- ]
8 Y2 k4 h, G6 u+ B6 A% L" ~The program will execute 6 different SIce commands located at ds:dx, which: S# M0 A( W5 H4 J; a
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
' f. O) F& }- Q# E
/ U6 {# K+ d$ ]+ j+ @) T4 j* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded." v5 p: F: @  {5 p) Z8 E; ~3 r
___________________________________________________________________________
% a* `% [7 u2 j! @4 p3 @7 n. ~5 e( f0 O: e

5 s, V1 K* O8 dMethod 030 d9 {- Z+ R# ^0 W
=========: C; l7 M4 z' T2 V- @8 k) @
' |8 l- ^+ u9 U2 m9 @+ a( O
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h/ N" W- H1 S( Y- J8 u- F- {
(API Get entry point)7 I, H7 |7 N) S8 P5 M' [/ U! c
        
0 }: f6 `$ c9 T' r5 O+ X. M/ ^2 T6 m; W1 v0 G
    xor     di,di
1 v/ j) Y) ^1 H9 W0 @( s1 g    mov     es,di( o* s# e3 E$ U: e& j" ]3 L
    mov     ax, 1684h       1 Y( Q5 C3 ]( i! O
    mov     bx, 0202h       ; VxD ID of winice
6 d8 r6 y3 G) a/ a, J: |& k    int     2Fh
; P$ ?; y# j# m" P5 d# u    mov     ax, es          ; ES:DI -&gt; VxD API entry point
0 B/ @% S8 f* a& X; e    add     ax, di0 d4 l2 e5 _# x, s4 V) |0 y
    test    ax,ax# X: w4 y' T, z3 f) l
    jnz     SoftICE_Detected  S: a/ y1 o: Y. @' k
/ x7 K- x4 b1 v. ^, p
___________________________________________________________________________: ^8 a$ W9 d: ~7 e

+ s' X# [1 V: w* M0 Q$ d$ n# I" wMethod 04/ _8 C, H& G6 g
=========- y8 D& A1 |# S% o+ ]! `% N
  x2 y- ]7 \* x5 c  p! W
Method identical to the preceding one except that it seeks the ID of SoftICE4 B) T5 M; [: `  ?4 O$ r
GFX VxD.
3 ^4 K/ B! n; {& E
0 g+ _; z* e5 B6 X  O    xor     di,di
1 t2 U- n2 y; x, N6 t    mov     es,di+ L% K  m& U" G- ~& Y! V" K
    mov     ax, 1684h      
$ R" ~/ x7 n5 Q2 {$ E    mov     bx, 7a5Fh       ; VxD ID of SIWVID
; U0 P( C9 e5 o- h. t    int     2fh5 V8 m: p4 w; f* J% I
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
) k0 `$ ~4 H/ A" s  G    add     ax, di, L+ O0 |/ k& c0 }! b1 x
    test    ax,ax
7 ?- |7 L; K) `4 q0 k; s    jnz     SoftICE_Detected/ ~1 I$ k2 m- @! n1 W
& u) P. `! L$ T+ D' o, V
__________________________________________________________________________& U( h3 N( v* _& L; m( Z
3 K8 I- F3 v/ T% U
% z2 v8 h+ q2 l6 u# ~, G
Method 05
" ]5 H) M. U7 O8 Z$ a) ?6 G0 p2 F' O=========, E$ l+ v6 K$ b2 ]
( K- H7 A4 _! V' V2 U2 O
Method seeking the 'magic number' 0F386h returned (in ax) by all system- P2 Q( V  p7 v  `# R4 Q7 B
debugger. It calls the int 41h, function 4Fh.
/ ~% g$ `; U* m* |There are several alternatives.  0 ?0 G+ ^# r* r& \+ Q' v/ h
3 ]. P6 [& c, H; q$ m* B6 i, j
The following one is the simplest:
- g, f! P3 r* U: x/ P. `" ?/ C* u. t& M% n1 @* N
    mov     ax,4fh% Y' d  b2 k$ Z6 r$ S
    int     41h3 m& r% N5 z0 g$ ?6 D' j1 }( I
    cmp     ax, 0F386
% X' S' T! s3 K* C1 `    jz      SoftICE_detected
4 k' F8 y* p, u
) }$ _: R: j8 G# o' y" k" S7 A! u/ Q+ G4 u% M
Next method as well as the following one are 2 examples from Stone's 4 @- S; ?; o, S
"stn-wid.zip" (www.cracking.net):: p& N$ k& }) H8 M) F5 p4 I
# r4 L6 M6 N: @0 g( R; o3 d: B% Q0 W
    mov     bx, cs: ^* j8 s# e+ j1 R3 a
    lea     dx, int41handler2
' u2 J% u% H  b    xchg    dx, es:[41h*4]! d8 i4 g4 R2 `
    xchg    bx, es:[41h*4+2]/ b% f" Q% n7 }( n2 D) z
    mov     ax,4fh
. G& v8 e. j* J" F8 q1 r    int     41h8 }) R- @- ?4 l: e* l
    xchg    dx, es:[41h*4]
9 n! Y4 U6 ?: b- j3 E3 |9 J: N2 e    xchg    bx, es:[41h*4+2]+ F! ^3 v  {* s' Z8 x7 D3 X2 h
    cmp     ax, 0f386h& F( Q( O& W( s0 b
    jz      SoftICE_detected: k' G* r1 r/ E8 @! Z

. L; K  E/ O: l5 d6 r* Eint41handler2 PROC
! ~1 z/ F8 J+ c    iret+ Z+ K0 I; Z$ j: J, S$ g9 X1 n  i
int41handler2 ENDP( X2 I8 A; v- U, I
+ J* `" {5 k. x+ l) j4 S8 A
1 D% p+ i6 Q( ]! z6 i
_________________________________________________________________________+ r- R3 k2 [/ _. J0 A% g
9 ]. D0 J0 }6 P( A8 Z

# n4 B# M" y: vMethod 06. s/ `9 E1 h4 g; A3 m" {5 y, H
=========
% c3 B% v# n5 P% k2 v/ q* \  x8 C( o4 m9 |6 w+ \& f3 g

" s' I/ S  y0 r! y2nd method similar to the preceding one but more difficult to detect:
6 m7 C9 I! `' I& X+ f0 }7 a% [3 o3 l1 M+ a2 X" L) [

* T$ a: T3 q* h5 n& |  R) W7 |* Oint41handler PROC% H1 o$ \0 s2 \0 `6 h
    mov     cl,al
+ ?% k6 e  t2 m( W6 D    iret6 Y& Y' |5 D7 `0 t% x4 z# v
int41handler ENDP/ w0 v0 [2 ^- h( D1 L* i
" m5 \6 y$ A5 e& s% |- I" Y0 l5 C# b

1 {3 Q$ W" }& C% u  G  h5 M    xor     ax,ax; `* E8 [- C+ r! Q7 M3 u+ ^
    mov     es,ax6 c& W" _5 Y& ]5 v) R% e
    mov     bx, cs
3 i: D) W/ ?8 O* S) F    lea     dx, int41handler
6 C- t: d2 _) x' c    xchg    dx, es:[41h*4]
" y7 W) |4 [3 k% j$ o# J* ^    xchg    bx, es:[41h*4+2]) G" J' Q& x  Y- a
    in      al, 40h
! w* {% D: w+ o5 d' y    xor     cx,cx! N, G- n& P3 W2 n8 ]  ]
    int     41h
6 L$ J- ?" z) a$ k$ W, s    xchg    dx, es:[41h*4]
7 N  U" u" Q" L5 Y3 d; i9 a    xchg    bx, es:[41h*4+2]& p3 Z- F0 u! e6 f0 w
    cmp     cl,al
: A. I' r+ `- F4 ^. S) d$ ~    jnz     SoftICE_detected6 U+ p$ C5 d0 m# a$ f' L; w5 t3 q# h
/ h) _( {6 y4 |! `) T/ b
_________________________________________________________________________
# _) c/ Z+ U, x8 B* k, q5 \& ]; G5 J& D. o6 G# g
Method 07/ _( Q6 F; Y' h1 r
=========1 T2 C% d, Z2 x) M( W- ~

& j+ m) o8 F& _: l8 MMethod of detection of the WinICE handler in the int68h (V86)2 _0 @" z5 J/ q
6 w$ G  y6 H- a4 ^
    mov     ah,43h
7 W8 t8 h! ^2 H( e    int     68h
& r4 U/ z* Q4 r# H    cmp     ax,0F386h- e) o% ^1 H& G! G$ o* X
    jz      SoftICE_Detected  ]( a: D# X" t% ?
. T6 c$ U( W  p- Y  D5 O% |
0 ~$ o. x$ [: P2 A3 G
=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit! ], \- f" E7 ~" x; ?
   app like this:. k" {; T7 h5 J+ d) |1 o

. w8 d7 A$ d9 ~$ K& P; o   BPX exec_int if ax==68% b& |/ N8 ]0 z' t- w
   (function called is located at byte ptr [ebp+1Dh] and client eip is
# O  o( x" W* _! Q: `/ j   located at [ebp+48h] for 32Bit apps)0 [, i5 }. D! x' P+ Y
__________________________________________________________________________
: h0 M7 C( p) [. T) V. I8 `/ ?9 y9 o" z( K5 @% l0 N7 t: ^$ e& P( h5 D9 ^

: W4 d4 H  R, A1 n+ K+ U9 jMethod 08
. B8 L1 g# F0 l7 a% g=========/ \' c. M# P" Y; d0 Y& h4 S

% }2 Y- ^3 y1 jIt is not a method of detection of SoftICE but a possibility to crash the
& A$ A; T, K3 `system by intercepting int 01h and int 03h and redirecting them to another
* z- V2 j7 K: B+ ]routine.
6 }6 e1 x$ ?  R6 U. S8 F1 LIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points# _9 Q( C6 c1 b" I
to the new routine to execute (hangs computer...)
% y% L  m/ a0 t; t/ b  h% K
5 A, _, w) ~* Y0 h% p    mov     ah, 25h
( N- A9 O9 I7 K: t" V* D  c' U: n    mov     al, Int_Number (01h or 03h): I/ z' R- w8 I$ K8 Q1 ^
    mov     dx, offset New_Int_Routine+ B" f. u1 R/ @+ X. F) g1 f
    int     21h
( t2 R: [  x1 Y7 E' }) ^: F
+ D3 z) Y+ V* [8 w. e- ^__________________________________________________________________________
+ Z. J& Z! @( v) \# i% f8 d: Z; f7 T) C* ]  W
Method 09
5 e  m) r2 V$ u=========9 q) `2 r3 t; ^9 x8 \6 _
8 E7 F) v; r9 ?3 N$ V% x* A; A3 t
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only) q7 [' p/ _9 `  z/ `. o' h
performed in ring0 (VxD or a ring3 app using the VxdCall).4 O$ I2 V- W5 F. p; d* D
The Get_DDB service is used to determine whether or not a VxD is installed" ]$ {6 o: K8 g$ [2 [6 [: t
for the specified device and returns a Device Description Block (in ecx) for
% [/ {) H/ D3 ^6 m" l  Q( F1 ythat device if it is installed.5 V! B3 e" y9 x; s

8 n' d  z/ v" N! [& r* p, t   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID6 ]$ C* S6 r& C; f0 @" S2 m- h! |
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
* l/ H; [- f0 F: z   VMMCall Get_DDB; O7 B7 S0 i$ r) a8 Q5 j: A. B" @8 ]
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed
2 X  x, f- ~9 z8 l% s- s' ~9 M& J- v3 N4 s$ I
Note as well that you can easily detect this method with SoftICE:+ k1 ]$ P3 H0 R1 X+ v6 X' h3 v6 R
   bpx Get_DDB if ax==0202 || ax==7a5fh9 L* ]7 t9 L+ a; p" ~
5 h7 `% @3 l, O1 S  M0 U3 Z
__________________________________________________________________________: K6 F, }, A! `" H# q! m6 x4 W
  d1 x& L& Y- p3 d
Method 10
' _7 D8 ]3 j5 b3 h& ~) t( \5 ^=========
' Z5 H9 _- H. o& i6 a4 }
) E3 i4 M% h1 R! R7 B=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
+ G* a8 B; o% L! J* T( X0 R  SoftICE while the option is enable!!5 |( v  m/ ?4 ^+ V' L
5 D2 D' y1 O1 p5 |" a% r1 W6 _
This trick is very efficient:
$ r$ _6 j$ `4 E. q  x2 l. u! mby checking the Debug Registers, you can detect if SoftICE is loaded
5 n" s0 c" k% D9 [, i* A  d(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
& K3 O9 V) g% H$ B' C: Bthere are some memory breakpoints set (dr0 to dr3) simply by reading their
! X% s6 j! h- d6 X9 }value (in ring0 only). Values can be manipulated and or changed as well
1 k6 Q* z, s  z7 y6 T(clearing BPMs for instance)" Q$ ]+ W  w  v: ~

  Q, h+ D3 Z4 c" e* d__________________________________________________________________________% q& w& F, s1 J/ f

) Y0 L9 b1 k% AMethod 11
# J5 t- Y* p: m0 t, v8 f% Q3 Z=========3 R, q: ~7 u, S0 y  K1 i+ R  I
- X) M9 m/ @8 w1 N4 m$ f
This method is most known as 'MeltICE' because it has been freely distributed% S! N& P8 y( H) j
via www.winfiles.com. However it was first used by NuMega people to allow
& I6 F) f6 D9 k' A5 cSymbol Loader to check if SoftICE was active or not (the code is located5 o# ?$ K" n8 m
inside nmtrans.dll).
9 A7 |, k; k( w3 @+ o! ^- `$ |$ _3 E; M9 ~+ c4 k& s' {
The way it works is very simple:
7 [" G' I" C- ^: v# A, L: @It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for
( n" M& R2 h% [WinNT) with the CreateFileA API.
5 e5 q3 ~$ ~* D, c$ s6 y' R2 h4 S# r8 G# ?# x, F" T0 {
Here is a sample (checking for 'SICE'):8 M% T+ I, q/ |$ d
5 B, V7 x* O: p' T6 B; m: f: T
BOOL IsSoftIce95Loaded()' c* D! A. X* h1 y
{% `4 O2 P4 }4 N0 G
   HANDLE hFile;  
: b+ F/ B+ n' t4 W   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,$ `, `2 P5 K: W' D
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
" O7 A& j& T, ?+ t3 K1 E                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);( m! @7 {2 `: [2 v# e9 [1 A
   if( hFile != INVALID_HANDLE_VALUE )9 m: N; f) E, I- p
   {  @+ N" x7 v# {: |: z, X! V" c
      CloseHandle(hFile);
! T( D: `7 P: y! m( A      return TRUE;& b( ^8 G5 S, u2 Y7 z6 h
   }
+ L0 {6 X% W. y, g   return FALSE;4 A# M3 ^  i7 b1 g5 w) A
}
* y7 G0 f; C' \4 v& x9 b6 d) K. v2 F: E- E; O8 Q# E
Although this trick calls the CreateFileA function, don't even expect to be
% F4 W; R7 w3 y( M! z# x4 _8 b, }able to intercept it by installing a IFS hook: it will not work, no way!) C( r8 Q/ S* x) S. C" O: _* p; t
In fact, after the call to CreateFileA it will get through VWIN32 0x001F: H% g7 [! {9 B1 z; z3 f& |
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
! T& w3 h1 v4 A! C8 }" Z8 oand then browse the DDB list until it find the VxD and its DDB_Control_Proc
7 j3 _( e. l  {* b( f0 T, F/ nfield.
7 r" P' j# c. ?# V( w, ^, Q" HIn fact, its purpose is not to load/unload VxDs but only to send a
: ]+ R  d$ j/ F3 e7 ?- q' H1 F+ ^W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
8 E: U! w4 C! @to the VxD Control_Dispatch proc (how the hell a shareware soft could try
/ [* a: Q% Q3 }& @8 ^7 Eto load/unload a non-dynamically loadable driver such as SoftICE ;-).' R: G0 z; Y- ~! x1 X1 B" @4 x
If the VxD is loaded, it will always clear eax and the Carry flag to allow7 ]1 D" B  z+ v8 B/ z0 E% y
its handle to be opened and then, will be detected.
5 E! X% J  n7 fYou can check that simply by hooking Winice.exe control proc entry point
2 n- b6 B) L2 r6 c" _while running MeltICE.
  E8 r3 U+ v+ {6 O" X! A* c6 u$ H& r, _
) ^# l' c6 d2 E( O! q
  00401067:  push      00402025    ; \\.\SICE1 j( U; f8 j+ Z1 y% p3 B
  0040106C:  call      CreateFileA( w- _5 k8 Q0 l- _7 y
  00401071:  cmp       eax,-001
9 E* @7 z5 r+ [# o  00401074:  je        00401091# p$ w) c% u" |5 M, q% g$ b4 m

! ^4 N& T) N# c, A2 C5 b( G! k: s( A+ N% a: c; \
There could be hundreds of BPX you could use to detect this trick.  ]$ s- I' [( a' v/ N4 I
-The most classical one is:- i3 n. p( Z2 A
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||5 |; V9 z& X2 T. t
    *(esp-&gt;4+4)=='NTIC'5 ?! b$ X6 R& g5 q9 n2 X: j3 i( [

) z" O9 y5 a! g" _, s4 Z( a-The most exotic ones (could be very slooooow :-(
# E3 l/ Q, l8 E   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
* v4 b5 Y' A, X     ;will break 3 times :-(( Z7 J+ k  r/ p* b9 d! B! ]

* e+ ?1 q$ R1 h  y-or (a bit) faster: 9 \7 ]0 {: t- w5 E; o. W& t
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')
9 D- ?  ^: f6 m, d" Y0 F& H' |* L; Q' q. I1 V+ ^) @: M
   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  " a9 D) p2 P/ o9 f
     ;will break 3 times :-(
" o% y+ `" X9 a! \7 q& i" Z, u6 A6 @
-Much faster:. L5 D; w6 D% x8 T0 n
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'! J! R/ v* U9 r' x
# T3 a* J  h0 {
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen4 K/ B" q0 n* U9 Q
function to do the same job:
  a* B  [5 t- M8 z7 c* T( ~0 w" i  B4 H0 @" H$ a
   push    00                        ; OF_READ4 {5 R. R$ {: S1 V
   mov     eax,[00656634]            ; '\\.\SICE',0: R9 G3 M8 a4 {- W
   push    eax  T! B1 Q- k! ~3 f2 b; D, c
   call    KERNEL32!_lopen
# `- _* Y% {! A   inc     eax1 h) C' h3 B7 [) j9 z+ q
   jnz     00650589                  ; detected
/ u; r2 }$ v% Q   push    00                        ; OF_READ
. g0 g0 A/ ]/ p4 p. h   mov     eax,[00656638]            ; '\\.\SICE') n2 p$ t5 i% j: z9 }
   push    eax
" s8 E8 M& y( Z* A1 f   call    KERNEL32!_lopen0 [5 l2 I2 f! l" {& Q
   inc     eax
" a4 _& ^2 U2 n   jz      006505ae                  ; not detected. `1 @& D! k' W1 b0 A6 ~& x. V0 q
) |4 c% E( n& o/ D% Q' a0 O3 I

1 v, ~+ E) L8 f4 w__________________________________________________________________________/ Q3 X' d" a* d" Y: ]. `

5 J9 z) K- t  f3 s/ c6 _* uMethod 12
) s: o: r) P3 s  q3 G4 a( r0 W=========
8 u5 j- G% g8 U6 P% ^" A2 Z3 N1 @6 X! F3 A
This trick is similar to int41h/4fh Debugger installation check (code 05! T* w- S% K# W9 g& s/ C# a# v- {
&amp; 06) but very limited because it's only available for Win95/98 (not NT)" I  c8 Y5 V! c8 Q( v3 T! q
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.9 M$ h$ `5 k! z( L: A& D  Y

0 {9 g  \: _5 h! p" n; P" h* n* t: q/ l   push  0000004fh         ; function 4fh
7 ]6 C  @; H, _$ P6 `& w( g   push  002a002ah         ; high word specifies which VxD (VWIN32)
# R7 a( b. }6 F, N; z/ _                           ; low word specifies which service0 q4 r  b9 H5 v; D) X6 [$ [$ P* p
                             (VWIN32_Int41Dispatch)
; r+ Q. ?) u9 P( l( w$ e: |   call  Kernel32!ORD_001  ; VxdCall: T6 d' U( M- @* b
   cmp   ax, 0f386h        ; magic number returned by system debuggers
6 d  S& w6 _2 X# }% t   jz    SoftICE_detected
4 y" _. P: w4 a& F# N9 s! s8 a; a" ~$ j! |
Here again, several ways to detect it:
% v! }: I5 c- [& {: @2 \) T. t
7 N# M! E1 Z/ J& Y$ o    BPINT 41 if ax==4f
$ B6 x0 Q) M' T7 T- E8 q4 d
) M9 d- q. Q# f; B$ v! B2 K    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
- y) a& a5 u1 f! o- l* e' X6 Z* _3 `
    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A' Y4 n3 W  _5 V- t5 V$ e

5 V& b# `+ i, n( Q: e: H& d    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
. J: V- X3 P2 D) y$ F' B& T
% `' ~9 q) h3 j. V5 l/ m& ___________________________________________________________________________
/ p- [2 L" L# B7 A4 S( s: e
2 v1 A; B9 _6 r5 y- G  qMethod 13
% a4 h. I9 k, [=========% v. ^; C0 o! E+ C+ K
+ a, t! O& Z, v( T, H$ Y8 J( O
Not a real method of detection, but a good way to know if SoftICE is4 t. k9 y9 D4 \
installed on a computer and to locate its installation directory.
7 h: g5 O) {) A" _It is used by few softs which access the following registry keys (usually #2) :
& t9 C8 p5 U5 ?; r! `0 \$ }* O# R+ _' Y* ]( u1 h* f
-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
' U" Q9 K3 w4 S8 N8 l5 h: T" ?) E( ?0 F\Uninstall\SoftICE
6 V0 B* p' y) D-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE4 n+ J" P9 F+ x: A
-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion( ]- J' h; K1 N  K/ G
\App Paths\Loader32.Exe, k% t4 @9 @0 e" }+ C- a, J

8 c+ }- c) j; Q( H- d
+ N; y2 u# O% z9 pNote that some nasty apps could then erase all files from SoftICE directory
3 ], O% L. K* V: i1 G8 z(I faced that once :-(6 S, ~3 k" g2 I0 l

2 @$ f3 c* O0 a- \  [- e+ \Useful breakpoint to detect it:# o& u; |. f0 K$ ?4 p( i% ]
) O# ^& X. v6 s2 w6 J
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
9 c3 b1 |1 Y( t& a" w7 @& W5 X2 h5 N# |, k6 ?/ K
__________________________________________________________________________
' E5 J. H9 A5 Z. N, k3 m; {2 x
0 x8 M$ x, g% \! D7 g& Q! D$ M; ?5 N6 r
Method 14
- w6 x! e) Q& ~$ G  |/ O=========" A0 b/ S# a8 m0 T$ f; P( l

$ {: ?( q5 X0 [$ lA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose# H) ?( E  w( }$ G$ @9 K6 X
is to determines whether a debugger is running on your system (ring0 only).9 S/ `( v! o2 ~& f
2 S# `- I# S3 N! U' e
   VMMCall Test_Debug_Installed
/ m5 h  P$ T# p   je      not_installed
3 w4 n4 i  n4 V. ^" F' U
$ w( P; \+ ]" VThis service just checks a flag.
8 v4 Z1 P: W2 S* G! U</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部