About anti-SoftICE tricks

[复制链接]
发表于 2008-9-28 16:34:50 | 显示全部楼层 |阅读模式
<TABLE width=500>' G) O* H9 `2 L+ n$ {5 y+ q
<TBODY>( |! x( r: ^" d+ C3 S, R
<TR>& Z( J5 F& w2 }, k
<TD><PRE>Method 01
1 q7 J$ t! {$ v$ v1 n% |) M) C=========& f. U3 G9 a1 m' k, U! x4 d& w
# w7 x# K% @  c0 A) C4 N
This method of detection of SoftICE (as well as the following one) is4 z8 W- w% L- y# L: ]
used by the majority of packers/encryptors found on Internet.
: B/ k+ e2 z" d* l0 f; IIt seeks the signature of BoundsChecker in SoftICE
$ z3 `" E2 m$ W( P! h
. a& u+ u, I. w5 }    mov     ebp, 04243484Bh        ; 'BCHK'
! p$ X! p' r5 J8 _% P0 o    mov     ax, 04h
, t1 D5 |3 ^8 n$ _/ X: x    int     3       % `* _$ M3 e2 q3 m/ S/ {
    cmp     al,4; @. Z; l5 I% f6 j
    jnz     SoftICE_Detected, w4 d; {' l+ N" Q' [+ |$ Q& p  M1 R5 i) x

. J% ]4 f* c6 C2 B% `% E___________________________________________________________________________, ^1 n* R) d( m% G0 B$ u) l2 z
! W7 i+ ~$ \) Z' ?% L
Method 024 D! U0 ?' y8 Z) m" i: ~
=========
4 s& ^0 U* R7 f+ Y1 Y/ z6 f* M5 }- @6 z  t$ [* y
Still a method very much used (perhaps the most frequent one).  It is used) K% L! u) b4 z7 W
to get SoftICE 'Back Door commands' which gives infos on Breakpoints,0 E  ?9 y& [0 f5 N' O+ S6 B
or execute SoftICE commands...- H6 _% a, I& H/ N' ]* k) A
It is also used to crash SoftICE and to force it to execute any commands" O2 `7 J) L7 L: @' ?) _  `8 |
(HBOOT...) :-((  2 A2 b+ c3 U; G7 m' J# }+ |# S
/ |  \: V) L2 z$ b) ?6 P& E  M) |
Here is a quick description:
  Q+ K# p0 U! v-AX = 0910h   (Display string in SIce windows)
$ O# \; T: ~6 ~; k7 _% f- [$ y% q-AX = 0911h   (Execute SIce commands -command is displayed is ds:dx)
" o1 i  X; {- m3 L; b+ X-AX = 0912h   (Get breakpoint infos)' R+ ~+ [& ^( k% i7 |; K' V7 j- M
-AX = 0913h   (Set Sice breakpoints)
9 X7 R, f9 q9 a: r; @! T$ H-AX = 0914h   (Remove SIce breakoints)
# Q: y# C7 q1 U4 F7 r6 D. P4 \! Z/ {% i6 H
* y  I- U8 M: F, P7 F! |Each time you'll meet this trick, you'll see:
* Z* J3 {$ ~; R8 K" d- b-SI = 4647h
# D6 v% l( ~! r& Z( _- ?7 @( r& I) {* c4 a8 J-DI = 4A4Dh! T+ M( Z# I/ z! X9 }7 R( S& ~
Which are the 'magic values' used by SoftIce.1 k5 b- v6 a" [, w+ K; R% V2 _
For more informations, see "Ralf Brown Interrupt list" chapter int 03h.) K* W% t! X2 d7 v1 q
( E) z1 t1 s; I
Here is one example from the file "Haspinst.exe" which is the dongle HASP
+ S7 A% C7 w2 ?  R" i' ?: M6 QEnvelope utility use to protect DOS applications:
8 l: _3 m0 p9 [5 E. C3 q2 V! @$ M# N2 f% p) n
7 @+ \. K* I. A, l( P5 y
4C19:0095   MOV    AX,0911  ; execute command.- a( E: }' S( |' `0 f. G- G
4C19:0098   MOV    DX,[BX]  ; ds:dx point to the command (see below).
+ j: ~' g3 x( y$ F) @# v/ K4C19:009A   MOV    SI,4647  ; 1st magic value.
* p) x; X, P2 H8 s' Y0 _/ I( i7 B0 q) f4C19:009D   MOV    DI,4A4D  ; 2nd magic value.
. E; b/ L: r# P: F; N* G$ u/ }4C19:00A0   INT    3        ; Int call.(if SIce is not loaded, jmp to 00AD*)
$ W4 h" {( a1 E" a+ [4C19:00A1   ADD    BX,02    ; BX+2 to point to next command to execute# O! G: B. Z! Z. M' i
4C19:00A4   INC    CX3 y2 E5 x% t# ^# N0 l  k0 G% _3 @5 X
4C19:00A5   CMP    CX,06    ; Repeat 6 times  to execute
7 Y/ Q; k% ^; B( h* R0 B6 h" g+ F4C19:00A8   JB     0095     ; 6 different commands.! E7 z* {- T2 _% p
4C19:00AA   JMP    0002     ; Bad_Guy jmp back.9 m9 s' g% H. V) a
4C19:00AD   MOV    BX,SP    ; Good_Guy go ahead :)
3 e. J  z* G" Q9 Y% W7 v8 T/ L3 q" E" x8 X' M
The program will execute 6 different SIce commands located at ds:dx, which8 W' D- J( R- T/ o5 T
are: LDT, IDT, GDT, TSS, RS, and ...HBOOT.
8 y4 {8 m% @! [9 R( G
* u5 J2 d$ g, X! l9 @* the "jmp to 00ADh" is performed via an SEH if the debugger is not loaded.7 I/ D2 }2 H4 }1 V
___________________________________________________________________________
( T. c# y3 {  W* n9 n; ~* @9 p) T" s+ d! X( }% O

/ C4 _( \  {7 LMethod 036 a% a  {- M4 c7 `- x5 B4 W8 H, p
=========
, p9 f7 m: s+ a  [. s5 F! e" _; w1 t2 t& V% W# c1 e
Less used method.  It seeks the ID of SoftICE VxD via the int 2Fh/1684h
) Q. y9 G% l" B, Q1 v' G( D(API Get entry point)
) b: G/ Q( q8 O/ [* y7 E- t        
4 W6 r5 K" T" |5 P& D
) p# X( a/ N1 _0 A4 d    xor     di,di
3 q: y: h5 w; b  H$ a/ g    mov     es,di
+ r1 i+ \: K2 f9 w1 e    mov     ax, 1684h       ! c* r! ]( [- x: h7 @. {3 f0 |
    mov     bx, 0202h       ; VxD ID of winice
+ C$ j9 z" j5 y3 t    int     2Fh. E' l9 j& Z( x
    mov     ax, es          ; ES:DI -&gt; VxD API entry point
/ W2 }  s& K- k0 O$ \0 G& e0 P/ C) x    add     ax, di
) }4 u7 T$ Y) u3 q    test    ax,ax
' [9 Y8 Q: ^. D9 E# s' O* q    jnz     SoftICE_Detected
6 }+ M( H4 R( z
" x+ f% E4 G1 K. s___________________________________________________________________________
7 |* c) f2 \" \( G0 w9 ~/ X) V+ \) \3 M5 f
Method 04" I- g* Y9 F% {. B- r6 \) G; C1 l
=========
0 W" ], X, M- H5 I; M* K0 s* E& D/ J3 V$ a! S0 o" B& `7 O* u7 [
Method identical to the preceding one except that it seeks the ID of SoftICE
4 e0 ~) M4 R$ I  h! C9 d0 oGFX VxD.3 D8 u) D$ M6 k: @' v
6 T8 a0 ?. M3 }. U* Y% b9 R, f
    xor     di,di
9 o- q0 z: l" J! C    mov     es,di/ I* {1 g2 q4 J  {) k
    mov     ax, 1684h      
/ j$ G6 _8 X1 u    mov     bx, 7a5Fh       ; VxD ID of SIWVID: d# z# X) e8 i3 Z- a- j0 l. r
    int     2fh
. W- `1 [, A/ [8 o7 v4 z    mov     ax, es          ; ES:DI -&gt; VxD API entry point
9 ?& c4 F+ p% N' g- C    add     ax, di, w% A. p  F" F3 P; e. c; U/ p
    test    ax,ax
/ p; D/ ~) R( Z5 R/ Q/ B! j- L8 _    jnz     SoftICE_Detected$ D1 \( P' R3 o% l4 W
5 V' E' X( a6 K5 h# P% i
__________________________________________________________________________/ N9 z. A" k: ?7 F' w: X- t

7 e# p$ X! S2 m/ |$ i$ `2 N3 D  [9 `9 L/ J
Method 05
) {; i7 R- q* H2 [/ j5 ^! U5 u=========: k" y4 U4 [3 y" T$ a

/ u# u* z+ x# I% ^4 JMethod seeking the 'magic number' 0F386h returned (in ax) by all system
! R# d! F6 C9 p3 G- Fdebugger. It calls the int 41h, function 4Fh.) K/ \: z1 \6 R5 W" u0 _2 c
There are several alternatives.  
3 {9 o- D- `: u9 M7 s7 {( e$ `+ g5 o2 g# H8 @9 d: u, L9 C
The following one is the simplest:' r& n- R$ b7 g# S- L/ Z1 e

, w2 j  x6 E1 Y; v" ~) X5 u3 p4 y    mov     ax,4fh" H: A8 U2 b! j, m6 q, b* i( e2 g
    int     41h
2 _4 x0 H* w8 h+ e    cmp     ax, 0F3867 w9 A1 s, i( p8 u% U
    jz      SoftICE_detected, A6 Q0 ]9 N. G* z! [

$ N; c7 n# m* D$ x/ r5 H9 V( g8 S$ r7 q, @
Next method as well as the following one are 2 examples from Stone's
$ m( x  G  w; ^"stn-wid.zip" (www.cracking.net):" X; }$ `% r$ _) G7 U8 @

8 b0 r2 {4 h' p6 u+ _* X1 L" D, l" m    mov     bx, cs' |6 x. r7 z, p
    lea     dx, int41handler29 [" ]" S$ c3 _  w& J* k$ F
    xchg    dx, es:[41h*4]3 m( k% k2 ?7 E9 L! ?
    xchg    bx, es:[41h*4+2]# t6 V; Q  V; U* ~/ u( m8 _$ [
    mov     ax,4fh
( \& u4 z- \9 O. a- f5 |  e    int     41h* C+ O  C+ B% O9 F5 W
    xchg    dx, es:[41h*4]
3 I0 ~1 n4 v$ U+ i% W/ N0 p6 \' y    xchg    bx, es:[41h*4+2]) z* Q+ e0 |/ g/ r  @0 N' d5 u
    cmp     ax, 0f386h
% x+ S- y& v1 @7 [* i    jz      SoftICE_detected
$ K* ^: d  J) s0 M9 y
4 x6 v# z( G2 F: E- P# iint41handler2 PROC
( h0 M% [6 _, L, C9 N- d    iret& t9 ]5 N; O9 c3 p, T8 h8 Y
int41handler2 ENDP
2 W: o4 y  ]7 m/ F7 ~$ X
6 ^( {$ |. I3 C0 g3 e
* n/ D2 d2 ?5 V7 b8 U% n_________________________________________________________________________+ _4 P8 b) n5 @2 h& P' z+ _% m1 B
: x% m- z& y: Z# H6 ^0 [
$ I9 ^0 N3 D6 ]2 U% C& P& d
Method 067 a1 o* V$ W/ e! X5 O
=========
# A. \1 `% S1 z1 @# x8 ~$ K4 p* C& K8 {( c7 m
+ W" V  I# y2 x' d
2nd method similar to the preceding one but more difficult to detect:2 H  s( n0 i& t- |7 ], W

4 g' W3 X  g4 }
  f$ l" j- X1 m; {+ n% Fint41handler PROC
- W/ `+ N- v; y% U3 j& Y4 x    mov     cl,al  K% d  C9 q) U  Z
    iret2 O# \. v0 _  N% ~
int41handler ENDP/ E2 \- o# H* f: F% c: I( V% N

9 |5 R9 U/ c" y! b6 ~8 @5 G6 e  B& |/ j+ e) C
    xor     ax,ax
  d5 m% D2 n$ f    mov     es,ax* o8 k% }6 G" D! m& v
    mov     bx, cs
6 A( [- a- N6 _8 z* l  _    lea     dx, int41handler* N# W- i3 N8 E
    xchg    dx, es:[41h*4]
+ J3 v! d' ^1 j4 q: j    xchg    bx, es:[41h*4+2]
; @  v9 p2 n7 t) ?6 w& M    in      al, 40h
& a# \4 N% ^1 J# W    xor     cx,cx, s- c2 }3 a1 m7 N
    int     41h& A. [8 \9 J: h% R' j" i7 x* A* w
    xchg    dx, es:[41h*4]+ X. r2 K; F) V  h  V& n
    xchg    bx, es:[41h*4+2]" B2 k: L2 p( i, k! K) O$ E
    cmp     cl,al
: `! v9 \  i- T% G2 n    jnz     SoftICE_detected
& I% q- W4 X8 r7 y! _4 n% H' B6 v6 N0 k
_________________________________________________________________________
) H  f% A' B# U3 u% X& v( e) i( N$ w8 O% B7 i8 |7 Z7 \
Method 078 A: C: J2 b. D+ E& j
=========4 l( t# X# Q. G" P( _, v

& N8 |: u% J, c& b" X- d9 NMethod of detection of the WinICE handler in the int68h (V86)2 E7 k4 {7 Y7 P
1 t! e9 z' G5 j, R8 Q6 g6 f
    mov     ah,43h& |5 p0 @) N4 A* Z4 R
    int     68h, H- ]7 o! J5 C+ W+ K( X
    cmp     ax,0F386h
* J, R3 K& n+ w    jz      SoftICE_Detected7 t' q5 W7 B- k
" b9 A* A( f- @/ F! f/ c/ \" t

3 D6 r3 G; d- r6 T=&gt; it is not possible to set a BPINT 68 with softice but you can hook a 32Bit
. ~" x* T, Q  E: ^1 w" e' o+ s   app like this:
9 @8 Q8 o# U0 V9 L/ w, L1 c
4 C8 S8 y) `% ]8 g, a) \0 N. j' {   BPX exec_int if ax==68  y8 j( B* D% q: S! U* H9 q
   (function called is located at byte ptr [ebp+1Dh] and client eip is; F# g5 u$ ]3 R- @+ o0 r; I
   located at [ebp+48h] for 32Bit apps)0 W9 Q  _4 j$ Y: n
__________________________________________________________________________
; c6 i! {  T# ?3 C' w
; P9 [0 Z$ _- w/ i( E3 X7 V7 r: i2 i) _2 V
5 L1 Q7 u9 a0 d/ O( E8 pMethod 08
% l" L4 Q+ ~& f* R5 p6 X=========& F& ~' E4 {+ L+ a
+ S8 ]& w* B4 T7 c0 M7 O, }3 r
It is not a method of detection of SoftICE but a possibility to crash the
; P! b8 [3 Y( R3 B# A2 w( Fsystem by intercepting int 01h and int 03h and redirecting them to another
9 w0 e  W) s5 `. ^% Groutine.
4 B9 k: w+ y% a1 V9 A/ c5 oIt calls int 21h functions 25h and 35h (set/get int vector) and ds:dx points
5 C* h! E. p: Q5 Q0 J# k" V8 {to the new routine to execute (hangs computer...)8 ?6 U  b- i9 U1 _/ J

9 A2 D- u+ G% s* ]; @- A& V    mov     ah, 25h" k7 ~" C" C# m. h! p
    mov     al, Int_Number (01h or 03h)9 E9 p" x. Z/ D* [
    mov     dx, offset New_Int_Routine
' i! T% a4 {  i4 S    int     21h
! n% W' o- u3 {' q; j, \' Z; D* R! |6 I, y( K% H5 v8 N1 X; B: N
__________________________________________________________________________
( V$ D6 h$ r  j& r. `+ Y
3 @- H  a- N1 N# M2 s, KMethod 09( {( I& p$ [8 t7 @
=========
  n0 N6 ^& J7 E- U' ^/ O2 q8 F9 j3 f  e# S3 ^
This method is closed to methods 03 and 04 (int 2Fh/1684h) but it is only  h+ D. b4 s- |$ j$ Z
performed in ring0 (VxD or a ring3 app using the VxdCall).
, R& K. `, @; NThe Get_DDB service is used to determine whether or not a VxD is installed
4 q+ |) h. w+ s0 K2 s  `for the specified device and returns a Device Description Block (in ecx) for5 Y: [& }8 c5 d8 n
that device if it is installed.# M. f* R. Z$ u. j4 f# L

; D; q: N( \; W   mov     eax, Device_ID   ; 202h for SICE or 7a5Fh for SIWVID VxD ID
, |7 t0 o6 T3 ]/ d: L   mov     edi, Device_Name ; only used if no VxD ID (useless in our case ;-)
0 @8 J* X$ T0 S1 j; E   VMMCall Get_DDB9 E" q1 q. u# F
   mov     [DDB], ecx       ; ecx=DDB or 0 if the VxD is not installed- s* v  _) A# @/ A

8 H1 u! O& u  K5 i1 ^% M: }9 g% hNote as well that you can easily detect this method with SoftICE:1 W: v: C7 l5 B( E' z- z* U
   bpx Get_DDB if ax==0202 || ax==7a5fh. Y7 R. m2 @  h8 T5 N* @

& G7 L* ^0 y" \1 d__________________________________________________________________________
& I8 W( ^3 z- Y& l, d
1 I3 T$ M! v5 t* H  @+ YMethod 106 q; y, P2 O: N( o5 [& [. }/ E
=========
# F( J& f: Z0 t4 \2 p: s
% K# x; f  P2 {$ y2 Y) T2 F1 {=&gt;Disable or clear breakpoints before using this feature. DO NOT trace with
0 {) d$ ?6 A( s1 v- s4 ?3 X9 ]  ~  SoftICE while the option is enable!!) r0 q8 ?. S; b( B$ B; U8 P
( z/ k( P& J9 g
This trick is very efficient:
, O9 l. W  F0 lby checking the Debug Registers, you can detect if SoftICE is loaded/ B5 D, ?. u1 e, A8 U7 ~6 }( U9 w
(dr7=0x700 if you loaded the soft with SoftICE loader, 0x400 otherwise) or if) m' `: y; f/ c6 E
there are some memory breakpoints set (dr0 to dr3) simply by reading their
8 t! `. n0 i$ y+ U6 ~( V- U8 Vvalue (in ring0 only). Values can be manipulated and or changed as well
3 Y. Y+ _& Y- P& h1 F$ H7 d(clearing BPMs for instance); S3 @/ r1 ?% c
  [1 z4 k1 r, J( B
__________________________________________________________________________
% s- y0 Q  ?/ ]' g! L$ L
- k& |: L, L9 o4 f) c  F+ qMethod 114 N8 @$ [" R: N2 u" w; c
=========" f3 W# z9 j5 A3 g; q& {# i

; P3 }4 Y; g& |: mThis method is most known as 'MeltICE' because it has been freely distributed
" \' y) U7 g) ^& ?, \% }5 W0 S$ cvia www.winfiles.com. However it was first used by NuMega people to allow
7 h, y8 \" F* Q3 ^( U" I: C8 N( HSymbol Loader to check if SoftICE was active or not (the code is located$ n$ [$ o) ]* k" @2 f
inside nmtrans.dll).
- W( g8 J/ c( q. Z$ m) M& G  ]7 A) O4 o3 D
The way it works is very simple:
# {6 o; m% r# H' Q9 A- hIt tries to open SoftICE drivers handles (SICE, SIWVID for Win9x, NTICE for. b9 e& E  T* _) P8 p
WinNT) with the CreateFileA API.7 U- t: T* w! N% f. |$ W7 H
& i" S& N! A9 g' S3 x2 }0 r8 Z
Here is a sample (checking for 'SICE'):- X/ z. @$ b* ~% q- y1 z* V

0 P' J: v6 g, f1 o' JBOOL IsSoftIce95Loaded()
, e3 |# V' c7 {{9 F/ K6 p; P. e7 A2 p& y
   HANDLE hFile;  1 _3 P+ _3 V; G( C# H! @! f
   hFile = CreateFile( "\\\\.\\SICE", GENERIC_READ | GENERIC_WRITE,4 r7 w* `' ~( b+ E( v$ u
                      FILE_SHARE_READ | FILE_SHARE_WRITE,
! h/ z, T- G1 T6 b1 B2 Y                      NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL);
6 E4 q  Y. x+ y: a   if( hFile != INVALID_HANDLE_VALUE )
6 r- C' {* @: _0 b   {
) O5 ~- J3 E. @- q/ ^      CloseHandle(hFile);
: d) r" x4 d, ^      return TRUE;( a. g4 D1 y1 ?
   }0 t& Q5 G/ F7 t) T& m4 t% S
   return FALSE;  o8 x* x) F+ t& O7 T
}
- C3 i* p- O) ]$ K. A, B8 J
! z) [2 i3 p8 r  ~+ [5 NAlthough this trick calls the CreateFileA function, don't even expect to be
  ?# O9 u' a5 X! L8 Xable to intercept it by installing a IFS hook: it will not work, no way!
  [; M* w* {6 z- Q# F  ^8 M! SIn fact, after the call to CreateFileA it will get through VWIN32 0x001F& S5 m" r1 p3 M% c8 U  e" k5 B
service _VWIN32_ReleaseWin32Mutex (via Kernel32!ORD_0001/VxDCall function)
. Q4 |6 ~, s) Y6 Yand then browse the DDB list until it find the VxD and its DDB_Control_Proc; H- A9 c3 V: ~) {
field.$ G4 E% v8 o5 l% I9 N
In fact, its purpose is not to load/unload VxDs but only to send a
& B! h; j1 V( c$ PW32_DEVICEIOCONTROL (0x23) control message (DIOC_OPEN and DIOC_CLOSEHANDLE), `6 f6 R$ j4 T6 q1 f0 ?
to the VxD Control_Dispatch proc (how the hell a shareware soft could try) q9 S3 s& j9 V! ^" l
to load/unload a non-dynamically loadable driver such as SoftICE ;-).2 B3 R, T3 ]+ A% ?  K" l% ]5 h
If the VxD is loaded, it will always clear eax and the Carry flag to allow9 U% `- `0 K8 h$ P1 X- K
its handle to be opened and then, will be detected.
" l! F0 g8 f' L0 q" _( V2 ZYou can check that simply by hooking Winice.exe control proc entry point" E9 Z4 D$ S3 Y) H7 D
while running MeltICE.5 P1 s$ m! z8 M

* ~. A2 E9 h1 R1 m6 S( g' N& i, G, S/ l) G1 T. F2 ?- a& V
  00401067:  push      00402025    ; \\.\SICE
9 \1 F% M1 R. I9 E6 c$ R  0040106C:  call      CreateFileA
* b" s9 T1 ~& C5 K  00401071:  cmp       eax,-001
3 y  F5 A' y0 K7 g2 `1 K  00401074:  je        00401091
- ~* w; b. x: I- r2 k0 Z3 r7 @2 a( ~9 e0 h

# V- s4 _8 T4 B) ?& u7 `There could be hundreds of BPX you could use to detect this trick.
1 T& F0 X6 _+ k7 V! b/ c-The most classical one is:* G4 G. }. F4 e  `! B6 B' W
  BPX CreateFileA if *(esp-&gt;4+4)=='SICE' || *(esp-&gt;4+4)=='SIWV' ||% ?; n6 g" X( M  n
    *(esp-&gt;4+4)=='NTIC'
1 Z0 J8 {- k0 d" L- `  |, {  j
0 `: R4 h- C- T; J7 Z7 H! y-The most exotic ones (could be very slooooow :-(
2 s* e( z# Y. S& ^8 F) \   BPINT 30 if eax==002A001F &amp;&amp; (*edi=='SICE' || *edi=='SIWV')  
/ R4 I* n6 G& g  a* R6 [) D     ;will break 3 times :-() T! d+ H/ r4 h

5 |- i+ X: j- [1 U& X3 ~-or (a bit) faster:
4 D2 R' e0 Q" m! w, w; X   BPINT 30 if (*edi=='SICE' || *edi=='SIWV')4 d/ _; A4 g9 Y: c( v

0 v5 ]! q8 B% p0 M. T5 T" l: B8 `   BPX KERNEL32!ORD_0001 if *edi=='SICE' || *edi=='SIWV'  
* [9 Y6 t* i9 v- H: }     ;will break 3 times :-(
& A8 _% s3 I- I+ N$ H6 T0 c9 M  n  G! s" w) s. u" U0 H
-Much faster:* ]% R: q  g  K+ y
   BPX VMM_GetDDBList if eax-&gt;3=='SICE' || eax-&gt;3=='SIWV'4 M9 M3 y0 G; P9 ?9 z: |
8 V3 f/ J/ Z$ b) {
Note also that some programs (like AZPR3.00) use de old 16-bit _lopen& a" I; C, Y% k1 l4 [! Q6 Y4 |
function to do the same job:! n" O* p( l3 e' t
& Y1 z' s& E1 D. I! s
   push    00                        ; OF_READ
9 C- l! ?- C, n! p0 C   mov     eax,[00656634]            ; '\\.\SICE',0
$ f$ E' [0 y' X   push    eax- O& F' v. ^& H1 C6 R1 o) Y
   call    KERNEL32!_lopen! S+ x1 L, w6 K! W: {7 l" I# l. ?) m
   inc     eax
' U& o! ^; K9 Y8 q& a   jnz     00650589                  ; detected  q- C, A1 Q- B1 ?0 \% s
   push    00                        ; OF_READ
4 w; a  C9 x/ o5 M: `1 a" V% s   mov     eax,[00656638]            ; '\\.\SICE'
) G+ m8 n! Y4 ~/ K8 [   push    eax( i& q! W/ V& q9 J8 t
   call    KERNEL32!_lopen
7 U$ O& z$ r! c# x$ |9 O   inc     eax4 _) y1 Z0 `2 w8 s" y5 {
   jz      006505ae                  ; not detected  ]  s: Q) V5 u% s6 _
1 g+ N3 ?7 y, U: _# H5 Z' j
- F% L, \/ x# `4 ^# O
__________________________________________________________________________
! Z6 D5 v( d  {7 L6 x
- W( D$ @8 C' U% M# b( }5 ?Method 129 m- o- Y2 W( c8 g; X
=========
' I% l# V! Y5 m1 S! h7 c% s+ z! R8 |( e; R2 B( q
This trick is similar to int41h/4fh Debugger installation check (code 056 z2 I" |6 D$ y1 J* O$ ~
&amp; 06) but very limited because it's only available for Win95/98 (not NT)
( Y; u9 C3 J, s! \) das it uses the VxDCall backdoor. This detection was found in Bleem Demo.2 ~; E6 ^% {. r0 A- |

- ?, g" L4 |; I   push  0000004fh         ; function 4fh  j9 k9 r8 a$ j! g0 H+ S
   push  002a002ah         ; high word specifies which VxD (VWIN32)
3 h+ _8 ?" s- s                           ; low word specifies which service
5 a, }; {0 o8 c0 \3 S                             (VWIN32_Int41Dispatch)
6 k" n( c; |7 @+ D4 K   call  Kernel32!ORD_001  ; VxdCall+ Z. r: H% n) Q/ g( y  I
   cmp   ax, 0f386h        ; magic number returned by system debuggers" i+ O# Z; ^( a4 |3 n4 N
   jz    SoftICE_detected6 j9 ^& Z& m9 \+ V4 _
, z' g7 w' ?* w9 i: P
Here again, several ways to detect it:5 ?+ W" _, a9 R, N1 W& V8 f
! H+ V  P# A$ _" W
    BPINT 41 if ax==4f3 C: h5 Q3 e; l1 h$ x: ~2 s

- O7 `8 E3 L, I" p, I    BPINT 30 if ax==0xF386   ; SoftICE must be loaded for this one
3 @" @1 v# g0 `4 [; p
! }2 t1 o  Y5 u2 \4 F0 ^    BPX Exec_PM_Int if eax==41 &amp;&amp; edx-&gt;1c==4f &amp;&amp; edx-&gt;10==002A002A- ~7 m. y/ h6 C0 N

& l. l) H# L  H0 a; n    BPX Kernel32!ord_0001 if esp-&gt;4==002A002A &amp;&amp; esp-&gt;8==4f   ; slooooow!
# z  G0 r# I- Z  z8 q0 B
. p. Y. r4 P) O  A3 a+ h* W__________________________________________________________________________0 I. o# L# z4 T: s# I0 q2 o% k9 k
. _7 P! s: H* }# o  ?3 l0 j
Method 13
8 y) z5 V7 @5 e1 G=========& |! S; x1 ]6 ]7 O0 e$ c0 a0 Z
9 g# a/ [$ j( W& A
Not a real method of detection, but a good way to know if SoftICE is
) y7 W) s6 o# K; I$ {, W* H; @installed on a computer and to locate its installation directory.7 T  W: U7 B# w& }: d. A
It is used by few softs which access the following registry keys (usually #2) :! \& r$ M% C# f/ @$ k

+ i( R1 b4 q8 b5 ]$ p& V0 w9 S-#1: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
! c: j6 I+ ?2 a; `\Uninstall\SoftICE/ z1 f+ ?& _. C' q
-#2: HKEY_LOCAL_MACHINE\Software\NuMega\SoftICE
' n3 n" j% D- _; P. R2 d  X: H. |% B- q-#3: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion) \3 Z& V4 I( ^" g! G6 z# @9 d
\App Paths\Loader32.Exe$ h1 b3 e$ A* F4 k/ [" }
6 T: }- l) S! L. x* s
+ H& Q/ X9 [: |0 F* X0 H. C3 _3 I* c
Note that some nasty apps could then erase all files from SoftICE directory
/ n4 Y- G" z2 f, ^$ A( K! J(I faced that once :-(0 O; ]" b# k+ h/ G. _

  h* Q$ Q5 g+ ?: x- n6 x. eUseful breakpoint to detect it:
2 W1 X$ k+ U) u. P4 G2 W/ P; V! J' l. A2 L
     BPX _regopenkey if *(esp-&gt;8+0x13)=='tICE' || *(esp-&gt;8+0x37)=='tICE'
' K# Y2 x" F: P6 `  M& R% X; Q# c6 W3 B
__________________________________________________________________________9 M1 b# q0 k& i+ R) \3 I

( B) y3 `7 J( H/ D6 I5 H( Z; M
Method 14 : x  Y, M& Y6 T5 Y" o9 s: B
=========- m7 \) F5 L+ E9 r

3 L/ ~( f1 _( [$ I. @( dA call to VMM 'Test_Debug_Installed' service. As the name says, its purpose
+ O% U6 W, L1 B1 G- Z2 X1 l- A( yis to determines whether a debugger is running on your system (ring0 only)./ T3 A# U) R! j6 O, h) t) r) H2 w

; S; ~& }6 R) p9 X3 u, U% v   VMMCall Test_Debug_Installed
2 T( Y$ Y' b( d   je      not_installed
$ q6 l# l% o+ i$ a, ]3 w. k0 N5 I1 f& t8 a. _" |
This service just checks a flag.
$ E9 C/ z7 C; ?7 @2 R</PRE></TD></TR></TBODY></TABLE>
您需要登录后才可以回帖 登录 | 注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.|鲁ICP备19052200号-1

在本版发帖
关注公众号
QQ客服返回顶部