About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>
1 E2 V$ b0 a! z! C7 L: M6 H<TBODY>7 o, e( s0 e5 Y4 n, M4 ]0 c: |2 D
<TR>
4 T0 a; J9 Y" T* x4 {<TD><PRE>Method 01 5 z' ]1 B. h4 n
=========$ c. W! L5 f3 @) L3 m, F" j2 b

9 g+ Q1 D* O  }3 G; j$ |2 QThis method of detection of SoftICE (as well as the following one) is; U  a2 y% w. |. q& E! S  H3 v+ p
used by the majority of packers/encryptors found on Internet." h- ^& n! Z# a# i1 I* E
It seeks the signature of BoundsChecker in SoftICE" Y, {" j2 f) ^3 @8 F/ W0 [- M0 M

8 g: t3 a: \# r1 w+ r    mov     ebp, 04243484Bh        ; 'BCHK'0 m) `3 w) I- }- W, X: V1 d
    mov     ax, 04h
8 C& d) ?6 b, o3 ]7 R( d5 |# E    int     3       6 B: j* a5 `5 w2 Y
    cmp     al,41 e$ m" D$ a6 f, S% R  P
    jnz     SoftICE_Detected
3 @* [6 G9 b5 p; }5 n4 w4 s
- g" L! n$ O$ E___________________________________________________________________________/ g1 i0 X  `) R7 N
7 h: F  q6 H, }8 ?& o1 U8 M
Method 02
% I. {9 }4 ]9 C- q5 G6 X* Z=========' U  K7 g1 {, Z$ J1 _

, s7 S5 `2 u+ V/ _3 P# z& YStill a method very much used (perhaps the most frequent one).  It is used
! U; e0 i% l4 A$ H% Mto get SoftICE 'Back Door commands' which gives infos on Breakpoints,
5 l5 L) J$ u. s7 L% }3 j9 ]- @7 yor execute SoftICE commands...
4 J5 J& v1 N7 P2 ~0 }It is also used to crash SoftICE and to force it to execute any commands/ s* Z0 u) i, ^8 d: p, m- t
(HBOOT...) :-((  9 r# I4 z, j& N7 d" t* y

& n) z' x% p0 n, e$ ^9 nHere is a quick description:/ g' `0 A7 G% B
-AX = 0910h   (Display string in SIce windows)
* [9 z. ^! \. B2 Z! ^( L6 v8 P-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)" w, X9 e( L- [
-AX = 0912h   (Get breakpoint infos)" X4 E2 T& H5 O0 |; I
-AX = 0913h   (Set Sice breakpoints)
6 M- J) o) s' u, }. F. I-AX = 0914h   (Remove SIce breakoints)  Q! `' e+ w2 b! _
) Q* y, o) y8 ^/ `% I" y1 i
Each time you'll meet this trick, you'll see:' \0 e" \6 Y3 ]8 T$ q  Y
-SI = 4647h4 k9 {; f& k- K/ F: K4 S
-DI = 4A4Dh% |( C* {6 S) [: Q, S
Which are the 'magic values' used by SoftIce., ^* ?! U* i$ K  C
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.
( R9 L! I% V/ \. |1 ]/ q4 I$ L& F- d' t: c
Here is one example from the file "Haspinst.exe" which is the dongle HASP/ @+ U* H6 H' a- g) P
Envelope utility use to protect DOS applications:
  r9 A# E7 G& ?
( Z& r' {' L4 @2 ~. m
# Y! O) d# l0 L+ |9 Y( t4C19:0095   MOV    AX,0911  ; execute command.9 ]# e* |" O# ~7 Q% _% E3 c: `5 ^
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
7 t! b2 U% C3 I2 h' M' X7 o" i4C19:009A   MOV    SI,4647  ; 1st magic value.$ c/ ~8 C& B0 b4 [9 T) K# l
4C19:009D   MOV    DI,4A4D  ; 2nd magic value.# {6 G5 E7 k# U
4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
8 C5 q) v; e* W; J: ]7 |4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute
$ L, ?4 S* i4 b8 K, K% p4C19:00A4   INC    CX' q9 T5 A* g% x
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute: {. L7 l5 D# K  Z
4C19:00A8   JB     0095     ; 6 different commands.
7 f4 h9 k7 a8 h) d; r; f4C19:00AA   JMP    0002     ; Bad_Guy jmp back.4 K7 n. t  O3 L
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
6 A1 T* x* V! F. B+ ]: M5 z9 W: m0 Y- M* E' u
The program will execute 6 different SIce commands located at ds:dx, which8 p, Y4 d# L8 a7 [. p1 x2 W
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.! Y) a- L% B& q0 ]  O/ s! s, N4 J1 M; ^  o

  C* b, |3 Y" d' D9 a* i; b3 l& K, m* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.* T8 P% H8 g, _& Y
___________________________________________________________________________
, Z- M  p, b' ]. b. |1 [' |7 W1 `
! G( x. J) {" E% D% S
( t: X8 B7 C- ~9 ^' [- \: R! |3 dMethod 03
* s) N+ j/ C: @8 y=========
/ D; }; J8 f) D* E6 h2 [6 C6 J$ |4 p9 C" ^% M6 f8 O
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h3 m% T) o$ }4 j# T
(API Get entry point)9 U; ~1 g: I6 |
        4 K0 P; j: v* e; H5 @% L1 n

( w" c$ u4 g, e! \& k# T+ }    xor     di,di
2 i9 Z1 W5 t( D' n! V* [3 C5 ?    mov     es,di% b$ w; |$ s3 p$ F, Q% N
    mov     ax, 1684h       2 w5 v. G5 m# M' S" S
    mov     bx, 0202h       ; VxD ID of winice+ G! D1 i. U9 ]. K4 _
    int     2Fh
  Y# l4 K$ ?0 D3 I) D    mov     ax, es          ; ES:DI -&gt; VxD API entry point6 e- h/ ?' d6 h! w: A  n
    add     ax, di# e) Z+ ?' @+ j# K5 @% o+ k
    test    ax,ax- W7 c3 L$ f" ?& F# a# \# c
    jnz     SoftICE_Detected  g) P! L7 {4 c  I) T" i/ v% C
4 s$ e: v! V" m: @
___________________________________________________________________________
. w- c) K9 @; m# _9 I+ ]- O4 |8 ?7 K$ ^% e+ ~, v2 \
Method 04
1 \7 Q5 M8 v' q8 k: D=========3 O) Z9 D0 }% K6 t

0 B2 v" q; y/ L4 L9 VMethod identical to the preceding one except that it seeks the ID of SoftICE! _* B8 e$ `0 v  J: V5 b
GFX VxD.
4 T/ F: G( ?) D+ x$ X( c- q
4 M0 L# a6 e# \) A    xor     di,di1 K6 ^3 F) q& p& a
    mov     es,di
1 E/ P7 j" B' g& D3 \* q$ H    mov     ax, 1684h       $ \2 Y. ]0 n; O& f/ a) l2 s
    mov     bx, 7a5Fh       ; VxD ID of SIWVID
( F( A, G2 y6 o: H8 F4 x; s" ~0 c% F" l    int     2fh
& b! Z$ W4 e! I- v$ p- `    mov     ax, es          ; ES:DI -&gt; VxD API entry point& U' c" L, d" U
    add     ax, di
' u7 A; w# q& t" O- I! X! @5 w    test    ax,ax
% s/ b- ~% K  i% b! ]$ @: q    jnz     SoftICE_Detected/ u1 q( F+ c, z4 b
: W7 z  f" Z( \( y2 P: Q. s
__________________________________________________________________________
/ }7 z+ l# i9 q5 K& q$ X' u* i  r9 j

3 Z. C  j% h  X1 ?2 m$ }Method 055 \! ?) O3 k1 c9 z, h; y5 [: N
=========) z& e" S* G1 S% m4 \4 D+ C
. s& A8 b% V# U  `
Method seeking the 'magic number' 0F386h returned (in ax) by all system
, |5 s( a/ u1 Z- u& P1 l! x) Odebugger. It calls the int 41h, function 4Fh.
( w9 J4 p# n7 m6 ?2 \8 I; PThere are several alternatives.  
' M: u6 ~1 t- ~% u0 O! i7 o, M6 H% q' a+ d/ k- n5 @! b
The following one is the simplest:. _7 A9 K6 o9 O: _# a5 R  s- p
3 p9 Q+ F6 R# d! d6 P
    mov     ax,4fh
) b2 ]7 p% q, l: b, o    int     41h) F& P1 b: \! j
    cmp     ax, 0F3865 N  o+ v2 t& D2 K4 @4 O  \8 x0 U
    jz      SoftICE_detected0 w- a" P% r  W" y5 ?
# w* o/ z- m2 x

5 m) Q- W% Q$ y- x( H" ?& vNext method as well as the following one are 2 examples from Stone's
3 p3 Z/ G( f* A"stn-wid.zip" (www.cracking.net):
3 }# ~4 O4 K9 {* P& S- u9 o
. x" q) v4 ]5 v) C9 ]    mov     bx, cs
8 h# ^: d! F" H4 U5 R$ B    lea     dx, int41handler2
; C( |# R6 B$ \5 G' `# ^: Z7 @    xchg    dx, es:[41h*4]" M% P* \1 y& Y9 s3 Q
    xchg    bx, es:[41h*4+2]3 T, q7 v4 R+ t5 V% ?  w
    mov     ax,4fh
; Z0 J- s- Y# ^    int     41h
4 K4 x+ |6 z- N7 G' y+ h    xchg    dx, es:[41h*4]+ }1 I9 B' }' u6 r. _
    xchg    bx, es:[41h*4+2]
. J8 c7 B4 e' b% o- X/ }    cmp     ax, 0f386h
# K4 G2 D2 W; ]$ i) R    jz      SoftICE_detected/ R3 B3 J) }" ]) g) g  n

$ J' w8 _# ~+ t9 Q% t8 Qint41handler2 PROC
/ i/ V- S6 \% S    iret
# `2 u5 F  t) n  U' u# Aint41handler2 ENDP
$ @: P. [* \  N. @3 _4 h" @+ g8 ^
7 w6 v, k1 m; w  f5 C
_________________________________________________________________________3 O7 ]: n2 }! t+ ^; j" W6 G
% R& [' T4 ~5 U* @

# {  \* n2 t  p% m; ?! xMethod 06; ^% |3 ~& b' l/ f- Q# h
=========  X) U# H9 J; [  Q- ^

% [% e, p* M) J1 W  H, @
5 l) D1 M8 ]5 i& e- [0 w  v( b% I& L2nd method similar to the preceding one but more difficult to detect:
' S7 C0 V: W: D# q( v: c# r" p2 A) W
7 w4 C" J4 t0 ^
int41handler PROC( L0 ?8 h+ `/ P3 t2 ~$ R9 m" g
    mov     cl,al
* ~+ r6 M( b  X! n    iret
! E" ^; \% e5 v& ]0 X" ~int41handler ENDP
# A( |6 i; J! p/ o7 V
4 M0 U6 c6 Z- G1 j" e* ?9 b$ V9 ]; \9 p" \& |* g; S
    xor     ax,ax% K$ k8 p& A- Y# b, r
    mov     es,ax7 [/ V  F) l9 I$ i
    mov     bx, cs
- q' a2 K4 [  [: ]; s    lea     dx, int41handler; L- F* Z: g1 w* A6 e8 }
    xchg    dx, es:[41h*4]
5 X4 P$ p; R# U' Y9 n    xchg    bx, es:[41h*4+2]- Q4 ]" {  F* E* X0 B8 H* d
    in      al, 40h( Z2 u& Q1 m( X
    xor     cx,cx# B8 n! W& h1 }) R, }" X
    int     41h
! C! T, @6 [7 L+ k) B6 l  K    xchg    dx, es:[41h*4]% r% T6 ]5 }0 s- b/ M% `/ l
    xchg    bx, es:[41h*4+2]4 g3 c, k8 q) C2 \5 c! L; @
    cmp     cl,al; D. l' Q& f1 N! i8 }0 P
    jnz     SoftICE_detected, ?1 ]: Z! @5 h" s8 m
- G; R" D( _) ~9 }7 f
_________________________________________________________________________  _4 s9 d+ g6 E# @, k; r- k$ H
; ^: t, @8 p) Q4 R' N# Y0 G
Method 07
: `- `4 a: T* ]=========% ?* B2 H. `1 W: O1 J9 d

$ _( G! X. [0 O2 GMethod of detection of the WinICE handler in the int68h (V86)
8 V  J7 E3 ?! t( w$ y3 }; Q) _: ^6 i; K6 X% k2 w8 M! W9 ^# P- ]3 H2 D- R
    mov     ah,43h
8 z: w3 H$ U  C+ I! c$ q, |    int     68h1 l* T2 K* k# I: e! e/ o
    cmp     ax,0F386h7 M$ ]0 z, f- V2 H
    jz      SoftICE_Detected/ v9 ?# @/ v2 [( T( [/ O  x4 h
8 \" @  b7 \9 l) h$ b

' V  m, o" P( ~' D* D( s# L=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
, |; y) v& _: X/ m5 O+ [7 e) x- ]- {   app like this:' [( R, l5 S6 L  _( o7 w
- q& K4 h5 z9 x( D  K8 ?. ^
   BPX exec_int if ax==68
1 ~. q" ^' T# l1 z6 o. g   (function called is located at byte ptr [ebp+1Dh] and client eip is
$ Z, i+ H; u, F7 x! N/ ?1 w   located at [ebp+48h] for 32Bit apps)
% r/ `' k4 V4 h" Z% g2 a__________________________________________________________________________: X1 D7 S, q6 k. Y3 j& S, n' N

! _. Y3 D2 I, P  Q4 P
2 G! f3 r" m+ T/ r5 o. B3 t& \2 d  VMethod 081 M: N$ B; y: j1 I4 q# L$ ^
=========
+ e0 f4 ^, w6 ]! ^/ _" j$ }
% D6 U0 ?5 u% S1 X2 k' `It is not a method of detection of SoftICE but a possibility to crash the  `1 l# w& ?( e8 k, i" H/ e
system by intercepting int 01h and int 03h and redirecting them to another* ^! \: q8 l9 Y3 z( A2 ?6 ?) x1 K4 p
routine./ M# H  y: f" Q; }
It calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points9 X7 V$ c! i/ ^0 ?4 h
to the new routine to execute (hangs computer...), u& y5 n+ `& ?2 h% Q1 Y

# I' T5 W" ]  F8 U: Q2 \% }    mov     ah, 25h
$ y2 j% c7 \# I% C$ D4 p; D    mov     al, Int_Number (01h or 03h)
& U: E' g: e4 R$ p4 B    mov     dx, offset New_Int_Routine
! N, Y* Q- H" |. X( z    int     21h
/ d: T" {! I$ v" @( O' M2 ~
; z1 E: X4 T# W; }__________________________________________________________________________/ D( B3 I1 J' C8 d

% Z( r+ y0 G2 J/ D) HMethod 090 e  m# w' @) Y: u6 w
=========; u2 _6 Y. o6 e4 r* c- T
- l, L" }! N* S) q0 I0 h5 w$ s
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only
& }: ]' C5 z6 l7 G" t, C0 yperformed in ring0 (VxD or a ring3 app using the VxdCall).! Y! }# _& p7 h" v
The Get_DDB service is used to determine whether or not a VxD is installed- e* l( y+ F% R& |! q
for the specified device and returns a Device Description Block (in ecx) for* o5 n; _$ J' V" [7 J# g
that device if it is installed.: v  I/ F2 }/ a* @: [! c4 ?
) G9 `' o& d1 [9 V/ s3 R# Q* w3 Q
   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID% D, I# u, f; X& M6 H" s
   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
8 c# r( t! }9 L& e" X   VMMCall Get_DDB
* p  j8 F1 F4 ?7 M8 D  H   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed7 R7 {7 _5 h; |/ B: e
" |7 j5 M7 ^! Q
Note as well that you can easily detect this method with SoftICE:* \4 y  i  I% E3 g& a' y4 G
   bpx Get_DDB if ax==0202 || ax==7a5fh8 l. a+ ~3 h) y' `
4 p- s1 G  N; V: Q& c$ Z9 }
__________________________________________________________________________/ S/ _" s+ Z( Y9 G, o; R

" V- s! W- Q9 e1 J# c1 r4 XMethod 10* i1 P) J5 I/ d  j& y9 N* Q9 X4 K
=========
' \9 U) C/ K7 n; m- g$ l% A) t# J. A% I' u( N
=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
. t5 c; n- A: ]  W7 M+ B. W  SoftICE while the option is enable!!  X+ Z: A  h7 P$ |5 I

6 z. G- Z# v! }5 \, J1 vThis trick is very efficient:
" L1 |$ M" j' B* d, W" u( cby checking the Debug Registers, you can detect if SoftICE is loaded8 L. f" C! q6 w2 s; f* n. G
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if
! C- f* p) {7 lthere are some memory breakpoints set (dr0 to dr3) simply by reading their! Y0 j3 ]  ~( c$ h' T3 \1 n
value (in ring0 only). Values can be manipulated and or changed as well
" u( V9 }* J7 P, J. y" a& [7 z(clearing BPMs for instance)" L$ H- A; \0 V1 I. M# u! [- H

0 b. O) X8 Q5 U' P) S& N__________________________________________________________________________* R0 y: z- F9 P
! W" p, ]# j3 p
Method 11
0 H# ?) H0 I& `6 K3 N=========6 c5 I- S2 M' s9 u, u8 O
: T; X0 W$ D( g
This method is most known as 'MeltICE' because it has been freely distributed
8 Z' w0 g: W, {' r. \! b  O3 p9 Uvia www.winfiles.com. However it was first used by NuMega people to allow  N" @/ d3 _+ d) X7 [) e
Symbol Loader to check if SoftICE was active or not (the code is located
* S# i0 Q1 `3 P/ X3 A8 Dinside nmtrans.dll).
0 {/ |: m  o0 l' k; F- @5 C  B9 c) r9 R- X. V
The way it works is very simple:7 n7 u/ s* B+ l8 \$ D; F
It tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for# X4 b" }! W9 M
WinNT) with the CreateFileA API.6 y: p/ p! F! l- Q: Q1 t. b; V6 [
; N. E9 F: S+ w( Q7 k1 c+ _4 R. s
Here is a sample (checking for 'SICE'):
3 u+ R1 ?# p3 D: J  G
8 }/ t* u* O1 S4 O" ABOOL IsSoftIce95Loaded(): g. L, u0 X$ E3 N; L
{
: `; D* |! _) i5 E% ?  T6 Z5 e   HANDLE hFile;  : ^$ B0 s6 c* f3 p' w' o
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,
! S: w  p9 H7 V% i, C8 |                      FILE_SHARE_READ | FILE_SHARE_WRITE,/ a; x0 P% u! U7 p- M8 a2 ]( H, H6 d
                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);. f$ F' ^" K1 |
   if( hFile != INVALID_HANDLE_VALUE )
, A% o  Y; j! E   {
# H1 }- N) a% T5 j( f% A) F      CloseHandle(hFile);& _' j# m$ E$ l1 j6 V: e( M% t
      return TRUE;: y- A# i& G' g) x8 g# C$ g9 A
   }0 U5 M. I8 f) _5 y& c3 w+ `
   return FALSE;
$ h4 j5 [1 N% O4 |}
- T2 ?. b. T. F6 a( @' ~' g  D- J1 t" A3 N. P8 }6 n9 ~+ s& A5 Z
Although this trick calls the CreateFileA function, don't even expect to be
" ]4 T' D& S4 N, Gable to intercept it by installing a IFS hook: it will not work, no way!
. W& r( M8 u! O8 SIn fact, after the call to CreateFileA it will get through VWIN32 0x001F
7 F0 l- E' o8 F& m. bservice _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function); G. j' \. g8 {' K% |+ L
and then browse the DDB list until it find the VxD and its DDB_Control_Proc; F9 d+ D+ A' P
field.2 T8 c- w  R3 a
In fact, its purpose is not to load/unload VxDs but only to send a 4 L  c# t0 Y6 ^) \' h$ e
W32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE)
' B5 `- R* u6 W' s9 Sto the VxD Control_Dispatch proc (how the hell a shareware soft could try
5 U! j% P) v6 r: r- x( hto load/unload a non-dynamically loadable driver such as SoftICE ;-).
, ^. V( s5 V4 `, J0 GIf the VxD is loaded, it will always clear eax and the Carry flag to allow$ U! V+ N# X- K/ @
its handle to be opened and then, will be detected.
- w5 c' L* @3 A* \6 C3 MYou can check that simply by hooking Winice.exe control proc entry point
* `- [9 I0 ~% s9 S! P% Rwhile running MeltICE.
1 H4 F$ X/ M5 e6 \0 u7 U& l/ w6 c1 h& t8 j4 r" M( P
! H. G4 H- h4 ~. l# \' U3 B. j
  00401067:  push      00402025    ; \\.\SICE" w2 z- R# P$ I6 }/ I! n
  0040106C:  call      CreateFileA
" {$ k* O* u, X3 h  00401071:  cmp       eax,-0015 i3 D' C/ G* {; e( t
  00401074:  je        00401091
) L( w1 n( ?! q
: G) [; K: i+ W7 }8 d" ^4 J# Y% A# Z
; L; e$ e/ b  R' mThere could be hundreds of BPX you could use to detect this trick.$ ?) W2 B# x$ Z, o, Y6 e  }3 l
-The most classical one is:
- y1 T9 |; |! y8 p  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||
' h: ~: k0 S. ~+ k( k# s3 N6 |    *(esp-&gt;4+4)=='NTIC'
& e, Q. s3 |! \6 a) U1 S( P; Z; R4 W/ Z) Q+ k' p
-The most exotic ones (could be very slooooow :-(4 K8 e% w$ _9 o4 K; j5 ^
   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  ! |7 k5 |' h' y' Z5 B6 f
     ;will break 3 times :-(- t- u) p( |% v) X$ h& }% Y% U
, D- ^, X  `+ n/ ]; n1 r' v
-or (a bit) faster: $ S" L( ^: Z, J5 W
   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')' L3 N! t/ I6 D. L$ p6 a/ N* m6 y4 X

" T9 Z% }5 A0 J# a   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  / X$ h* M# F0 n+ P4 B, @& s( \& Z" i8 x
     ;will break 3 times :-(% a4 ?- g: Y) l  O
. w' Z2 L+ u8 B6 k% D# [9 J
-Much faster:, N! w+ H! D" ^' U, @
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'$ Q. e( L8 D& ^
# c1 O) Q, O' b1 d
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen+ h- N$ j0 e1 v. R' `8 ^
function to do the same job:
) _" k$ X+ }" r3 [4 A) _; E$ P
   push    00                        ; OF_READ0 i. B5 X4 E: n. o* N  s+ m0 u
   mov     eax,[00656634]            ; '\\.\SICE',0: Y0 ^$ T& B* E$ k, v
   push    eax+ B: S) P# I( H3 X5 Q  X
   call    KERNEL32!_lopen3 J4 t. R$ z& T5 ]9 z9 G
   inc     eax/ |5 ~. N. K+ Q  F0 p; g$ z. s
   jnz     00650589                  ; detected
" ~3 }  c0 f0 ?6 D$ X2 y. p7 d   push    00                        ; OF_READ6 L( }( n* G+ B* W7 |8 S
   mov     eax,[00656638]            ; '\\.\SICE'8 U" G/ s3 C7 d* {" }4 _  s; z
   push    eax
5 Z1 r: K2 `  l7 ~7 d7 m   call    KERNEL32!_lopen
; r: H  y8 u& a8 a   inc     eax, z& }  k+ B3 O& d, A" C
   jz      006505ae                  ; not detected
; b* T* e2 S8 D& a% D7 h
$ R! Q) _& W& b
* l) r: x& R; p' p2 \__________________________________________________________________________
+ i/ S$ v( o9 Y# B9 {8 a. E+ `3 Z/ f8 g
Method 12
4 M& ^9 T( A' ^& p; G% P6 r& g  p=========' z9 N0 |7 L3 t1 R0 g# g7 G
* u: ]1 ~3 i( H
This trick is similar to int41h/4fh Debugger installation check (code 05
) Q" Z0 i0 p$ d' V&amp; 06) but very limited because it's only available for Win95/98 (not NT)( q3 K) d6 u  E
as it uses the VxDCall backdoor. This detection was found in Bleem Demo.8 n/ S; g1 G$ J7 f4 b
* ]  }. m/ ?3 F+ x' E
   push  0000004fh         ; function 4fh
. Q7 ?3 d) |# ~0 T6 [% C   push  002a002ah         ; high word specifies which VxD (VWIN32)
+ q/ M0 t% e5 Q# S0 f. ]9 @' o                           ; low word specifies which service
2 j# M; L. |( D( f" z                             (VWIN32_Int41Dispatch)0 |& m4 p* E7 }$ n. p. g3 ^5 C
   call  Kernel32!ORD_001  ; VxdCall9 b" @% @/ Z: M
   cmp   ax, 0f386h        ; magic number returned by system debuggers
, {- l1 y3 L: U2 c+ v  G( N8 v   jz    SoftICE_detected
, T, M; b3 ^" l" a: l+ P
+ X8 M# x- L' T$ hHere again, several ways to detect it:
/ _* D+ j  s' z5 O: o, W* W5 n4 T" g- q$ ]$ X: ?& V
    BPINT 41 if ax==4f) w5 [% a2 K. @. z1 P2 ?8 x; {
" u2 t8 D8 X) [$ C& c
    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one* i/ l  e  a* _' X5 @  e2 m+ X

) k: C" S, O# I, Q    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A2 F) N1 d. |) G$ ]! G' k; f* _0 T" \

* o9 w5 a0 t% }! `2 q7 t5 i; q; u* j    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!! G$ b+ x" M# `% A# O! G% V
2 r4 t% _5 `6 t4 ~( T/ L0 v# R
__________________________________________________________________________" f4 ^* F$ |4 f$ c7 {/ U

* \% c! T$ T" }  VMethod 13
. n# w9 y9 C; c) F1 x=========
- Z6 k0 M" t2 l  B& |
' z" i, Z' u( U6 ^Not a real method of detection, but a good way to know if SoftICE is- h+ {, P* V; V, b% R( A) V
installed on a computer and to locate its installation directory.: Q/ S6 Y/ Y1 |3 U+ H
It is used by few softs which access the following registry keys (usually #2) :  ~, r$ y1 y3 I7 D& t$ q/ x7 T

/ E. K- m" ?3 v, A-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
! ^* H+ P2 @; D4 y4 G! O: ]\Uninstall\SoftICE; i, @8 O/ F; M% H" k6 z5 ?6 _5 y; K1 h
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
9 r( {8 o+ f4 H" t. h4 f% X-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
5 l" g& ?9 W3 b$ \6 D3 w5 `- n\App Paths\Loader32.Exe
% f9 u+ I+ j+ `: ^7 @( Y/ E6 S  T* Q% K# t
8 m9 X: ?- w. ^3 |$ ]
Note that some nasty apps could then erase all files from SoftICE directory% A6 [1 B5 t* @0 K2 _6 M5 @* i1 }  h
(I faced that once :-(
+ ~. N, i6 n" ^' i  c3 D5 l
' K8 y) u/ Y4 h8 `; C. C5 s3 MUseful breakpoint to detect it:
* V. |  W3 K, h' T, @- d3 Q3 m
: _( \) u$ c0 U( C  U6 G8 c     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE') l3 B, E' ^8 d/ Z
1 S0 ~% d+ d3 x' P6 A( T7 h
__________________________________________________________________________" T0 S4 N  ^# y. ]) z8 `3 ?1 q* ]/ O

% H, n/ K6 y  `- t+ |5 Q6 I6 U0 ]2 \& R# d) C% l! M7 t
Method 14
, J! ]5 Q# v$ O! n=========5 H% K, y. r1 Q6 A* t8 z  ?
; ^. p% X. ~9 {3 ]
A call to VMM 'Test_Debug_Installed' service. As the name says, its purpose: Y- I/ ]" R* j2 _
is to determines whether a debugger is running on your system (ring0 only).- z+ T( l  Q$ |" G! C& {- b8 F

6 l2 a9 S: ]* a   VMMCall Test_Debug_Installed# W) a3 T, ^" |! }2 o4 Q. b
   je      not_installed
, M- q5 A$ J6 W' ~  H
3 h" J% W8 E" {4 C; Z: d: `& lThis service just checks a flag.
4 {/ t7 i# K: l/ u& D3 }- i( z</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部